target_core_user.c 43 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730
  1. /*
  2. * Copyright (C) 2013 Shaohua Li <shli@kernel.org>
  3. * Copyright (C) 2014 Red Hat, Inc.
  4. * Copyright (C) 2015 Arrikto, Inc.
  5. * Copyright (C) 2017 Chinamobile, Inc.
  6. *
  7. * This program is free software; you can redistribute it and/or modify it
  8. * under the terms and conditions of the GNU General Public License,
  9. * version 2, as published by the Free Software Foundation.
  10. *
  11. * This program is distributed in the hope it will be useful, but WITHOUT
  12. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
  13. * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
  14. * more details.
  15. *
  16. * You should have received a copy of the GNU General Public License along with
  17. * this program; if not, write to the Free Software Foundation, Inc.,
  18. * 51 Franklin St - Fifth Floor, Boston, MA 02110-1301 USA.
  19. */
  20. #include <linux/spinlock.h>
  21. #include <linux/module.h>
  22. #include <linux/idr.h>
  23. #include <linux/kernel.h>
  24. #include <linux/timer.h>
  25. #include <linux/parser.h>
  26. #include <linux/vmalloc.h>
  27. #include <linux/uio_driver.h>
  28. #include <linux/radix-tree.h>
  29. #include <linux/stringify.h>
  30. #include <linux/bitops.h>
  31. #include <linux/highmem.h>
  32. #include <linux/configfs.h>
  33. #include <linux/mutex.h>
  34. #include <linux/kthread.h>
  35. #include <net/genetlink.h>
  36. #include <scsi/scsi_common.h>
  37. #include <scsi/scsi_proto.h>
  38. #include <target/target_core_base.h>
  39. #include <target/target_core_fabric.h>
  40. #include <target/target_core_backend.h>
  41. #include <linux/target_core_user.h>
  42. /*
  43. * Define a shared-memory interface for LIO to pass SCSI commands and
  44. * data to userspace for processing. This is to allow backends that
  45. * are too complex for in-kernel support to be possible.
  46. *
  47. * It uses the UIO framework to do a lot of the device-creation and
  48. * introspection work for us.
  49. *
  50. * See the .h file for how the ring is laid out. Note that while the
  51. * command ring is defined, the particulars of the data area are
  52. * not. Offset values in the command entry point to other locations
  53. * internal to the mmap()ed area. There is separate space outside the
  54. * command ring for data buffers. This leaves maximum flexibility for
  55. * moving buffer allocations, or even page flipping or other
  56. * allocation techniques, without altering the command ring layout.
  57. *
  58. * SECURITY:
  59. * The user process must be assumed to be malicious. There's no way to
  60. * prevent it breaking the command ring protocol if it wants, but in
  61. * order to prevent other issues we must only ever read *data* from
  62. * the shared memory area, not offsets or sizes. This applies to
  63. * command ring entries as well as the mailbox. Extra code needed for
  64. * this may have a 'UAM' comment.
  65. */
  66. #define TCMU_TIME_OUT (30 * MSEC_PER_SEC)
  67. /* For cmd area, the size is fixed 8MB */
  68. #define CMDR_SIZE (8 * 1024 * 1024)
  69. /*
  70. * For data area, the block size is PAGE_SIZE and
  71. * the total size is 256K * PAGE_SIZE.
  72. */
  73. #define DATA_BLOCK_SIZE PAGE_SIZE
  74. #define DATA_BLOCK_BITS (256 * 1024)
  75. #define DATA_SIZE (DATA_BLOCK_BITS * DATA_BLOCK_SIZE)
  76. #define DATA_BLOCK_INIT_BITS 128
  77. /* The total size of the ring is 8M + 256K * PAGE_SIZE */
  78. #define TCMU_RING_SIZE (CMDR_SIZE + DATA_SIZE)
  79. /* Default maximum of the global data blocks(512K * PAGE_SIZE) */
  80. #define TCMU_GLOBAL_MAX_BLOCKS (512 * 1024)
  81. static struct device *tcmu_root_device;
  82. struct tcmu_hba {
  83. u32 host_id;
  84. };
  85. #define TCMU_CONFIG_LEN 256
  86. struct tcmu_dev {
  87. struct list_head node;
  88. struct kref kref;
  89. struct se_device se_dev;
  90. char *name;
  91. struct se_hba *hba;
  92. #define TCMU_DEV_BIT_OPEN 0
  93. #define TCMU_DEV_BIT_BROKEN 1
  94. unsigned long flags;
  95. struct uio_info uio_info;
  96. struct inode *inode;
  97. struct tcmu_mailbox *mb_addr;
  98. size_t dev_size;
  99. u32 cmdr_size;
  100. u32 cmdr_last_cleaned;
  101. /* Offset of data area from start of mb */
  102. /* Must add data_off and mb_addr to get the address */
  103. size_t data_off;
  104. size_t data_size;
  105. wait_queue_head_t wait_cmdr;
  106. struct mutex cmdr_lock;
  107. bool waiting_global;
  108. uint32_t dbi_max;
  109. uint32_t dbi_thresh;
  110. DECLARE_BITMAP(data_bitmap, DATA_BLOCK_BITS);
  111. struct radix_tree_root data_blocks;
  112. struct idr commands;
  113. spinlock_t commands_lock;
  114. struct timer_list timeout;
  115. unsigned int cmd_time_out;
  116. char dev_config[TCMU_CONFIG_LEN];
  117. };
  118. #define TCMU_DEV(_se_dev) container_of(_se_dev, struct tcmu_dev, se_dev)
  119. #define CMDR_OFF sizeof(struct tcmu_mailbox)
  120. struct tcmu_cmd {
  121. struct se_cmd *se_cmd;
  122. struct tcmu_dev *tcmu_dev;
  123. uint16_t cmd_id;
  124. /* Can't use se_cmd when cleaning up expired cmds, because if
  125. cmd has been completed then accessing se_cmd is off limits */
  126. uint32_t dbi_cnt;
  127. uint32_t dbi_cur;
  128. uint32_t *dbi;
  129. unsigned long deadline;
  130. #define TCMU_CMD_BIT_EXPIRED 0
  131. unsigned long flags;
  132. };
  133. static struct task_struct *unmap_thread;
  134. static wait_queue_head_t unmap_wait;
  135. static DEFINE_MUTEX(root_udev_mutex);
  136. static LIST_HEAD(root_udev);
  137. static atomic_t global_db_count = ATOMIC_INIT(0);
  138. static struct kmem_cache *tcmu_cmd_cache;
  139. /* multicast group */
  140. enum tcmu_multicast_groups {
  141. TCMU_MCGRP_CONFIG,
  142. };
  143. static const struct genl_multicast_group tcmu_mcgrps[] = {
  144. [TCMU_MCGRP_CONFIG] = { .name = "config", },
  145. };
  146. /* Our generic netlink family */
  147. static struct genl_family tcmu_genl_family __ro_after_init = {
  148. .module = THIS_MODULE,
  149. .hdrsize = 0,
  150. .name = "TCM-USER",
  151. .version = 1,
  152. .maxattr = TCMU_ATTR_MAX,
  153. .mcgrps = tcmu_mcgrps,
  154. .n_mcgrps = ARRAY_SIZE(tcmu_mcgrps),
  155. .netnsok = true,
  156. };
  157. #define tcmu_cmd_set_dbi_cur(cmd, index) ((cmd)->dbi_cur = (index))
  158. #define tcmu_cmd_reset_dbi_cur(cmd) tcmu_cmd_set_dbi_cur(cmd, 0)
  159. #define tcmu_cmd_set_dbi(cmd, index) ((cmd)->dbi[(cmd)->dbi_cur++] = (index))
  160. #define tcmu_cmd_get_dbi(cmd) ((cmd)->dbi[(cmd)->dbi_cur++])
  161. static void tcmu_cmd_free_data(struct tcmu_cmd *tcmu_cmd, uint32_t len)
  162. {
  163. struct tcmu_dev *udev = tcmu_cmd->tcmu_dev;
  164. uint32_t i;
  165. for (i = 0; i < len; i++)
  166. clear_bit(tcmu_cmd->dbi[i], udev->data_bitmap);
  167. }
  168. static inline bool tcmu_get_empty_block(struct tcmu_dev *udev,
  169. struct tcmu_cmd *tcmu_cmd)
  170. {
  171. struct page *page;
  172. int ret, dbi;
  173. dbi = find_first_zero_bit(udev->data_bitmap, udev->dbi_thresh);
  174. if (dbi == udev->dbi_thresh)
  175. return false;
  176. page = radix_tree_lookup(&udev->data_blocks, dbi);
  177. if (!page) {
  178. if (atomic_add_return(1, &global_db_count) >
  179. TCMU_GLOBAL_MAX_BLOCKS) {
  180. atomic_dec(&global_db_count);
  181. return false;
  182. }
  183. /* try to get new page from the mm */
  184. page = alloc_page(GFP_KERNEL);
  185. if (!page)
  186. return false;
  187. ret = radix_tree_insert(&udev->data_blocks, dbi, page);
  188. if (ret) {
  189. __free_page(page);
  190. return false;
  191. }
  192. }
  193. if (dbi > udev->dbi_max)
  194. udev->dbi_max = dbi;
  195. set_bit(dbi, udev->data_bitmap);
  196. tcmu_cmd_set_dbi(tcmu_cmd, dbi);
  197. return true;
  198. }
  199. static bool tcmu_get_empty_blocks(struct tcmu_dev *udev,
  200. struct tcmu_cmd *tcmu_cmd)
  201. {
  202. int i;
  203. udev->waiting_global = false;
  204. for (i = tcmu_cmd->dbi_cur; i < tcmu_cmd->dbi_cnt; i++) {
  205. if (!tcmu_get_empty_block(udev, tcmu_cmd))
  206. goto err;
  207. }
  208. return true;
  209. err:
  210. udev->waiting_global = true;
  211. /* Try to wake up the unmap thread */
  212. wake_up(&unmap_wait);
  213. return false;
  214. }
  215. static inline struct page *
  216. tcmu_get_block_page(struct tcmu_dev *udev, uint32_t dbi)
  217. {
  218. return radix_tree_lookup(&udev->data_blocks, dbi);
  219. }
  220. static inline void tcmu_free_cmd(struct tcmu_cmd *tcmu_cmd)
  221. {
  222. kfree(tcmu_cmd->dbi);
  223. kmem_cache_free(tcmu_cmd_cache, tcmu_cmd);
  224. }
  225. static inline size_t tcmu_cmd_get_data_length(struct tcmu_cmd *tcmu_cmd)
  226. {
  227. struct se_cmd *se_cmd = tcmu_cmd->se_cmd;
  228. size_t data_length = round_up(se_cmd->data_length, DATA_BLOCK_SIZE);
  229. if (se_cmd->se_cmd_flags & SCF_BIDI) {
  230. BUG_ON(!(se_cmd->t_bidi_data_sg && se_cmd->t_bidi_data_nents));
  231. data_length += round_up(se_cmd->t_bidi_data_sg->length,
  232. DATA_BLOCK_SIZE);
  233. }
  234. return data_length;
  235. }
  236. static inline uint32_t tcmu_cmd_get_block_cnt(struct tcmu_cmd *tcmu_cmd)
  237. {
  238. size_t data_length = tcmu_cmd_get_data_length(tcmu_cmd);
  239. return data_length / DATA_BLOCK_SIZE;
  240. }
  241. static struct tcmu_cmd *tcmu_alloc_cmd(struct se_cmd *se_cmd)
  242. {
  243. struct se_device *se_dev = se_cmd->se_dev;
  244. struct tcmu_dev *udev = TCMU_DEV(se_dev);
  245. struct tcmu_cmd *tcmu_cmd;
  246. int cmd_id;
  247. tcmu_cmd = kmem_cache_zalloc(tcmu_cmd_cache, GFP_KERNEL);
  248. if (!tcmu_cmd)
  249. return NULL;
  250. tcmu_cmd->se_cmd = se_cmd;
  251. tcmu_cmd->tcmu_dev = udev;
  252. if (udev->cmd_time_out)
  253. tcmu_cmd->deadline = jiffies +
  254. msecs_to_jiffies(udev->cmd_time_out);
  255. tcmu_cmd_reset_dbi_cur(tcmu_cmd);
  256. tcmu_cmd->dbi_cnt = tcmu_cmd_get_block_cnt(tcmu_cmd);
  257. tcmu_cmd->dbi = kcalloc(tcmu_cmd->dbi_cnt, sizeof(uint32_t),
  258. GFP_KERNEL);
  259. if (!tcmu_cmd->dbi) {
  260. kmem_cache_free(tcmu_cmd_cache, tcmu_cmd);
  261. return NULL;
  262. }
  263. idr_preload(GFP_KERNEL);
  264. spin_lock_irq(&udev->commands_lock);
  265. cmd_id = idr_alloc(&udev->commands, tcmu_cmd, 0,
  266. USHRT_MAX, GFP_NOWAIT);
  267. spin_unlock_irq(&udev->commands_lock);
  268. idr_preload_end();
  269. if (cmd_id < 0) {
  270. tcmu_free_cmd(tcmu_cmd);
  271. return NULL;
  272. }
  273. tcmu_cmd->cmd_id = cmd_id;
  274. return tcmu_cmd;
  275. }
  276. static inline void tcmu_flush_dcache_range(void *vaddr, size_t size)
  277. {
  278. unsigned long offset = offset_in_page(vaddr);
  279. size = round_up(size+offset, PAGE_SIZE);
  280. vaddr -= offset;
  281. while (size) {
  282. flush_dcache_page(virt_to_page(vaddr));
  283. size -= PAGE_SIZE;
  284. }
  285. }
  286. /*
  287. * Some ring helper functions. We don't assume size is a power of 2 so
  288. * we can't use circ_buf.h.
  289. */
  290. static inline size_t spc_used(size_t head, size_t tail, size_t size)
  291. {
  292. int diff = head - tail;
  293. if (diff >= 0)
  294. return diff;
  295. else
  296. return size + diff;
  297. }
  298. static inline size_t spc_free(size_t head, size_t tail, size_t size)
  299. {
  300. /* Keep 1 byte unused or we can't tell full from empty */
  301. return (size - spc_used(head, tail, size) - 1);
  302. }
  303. static inline size_t head_to_end(size_t head, size_t size)
  304. {
  305. return size - head;
  306. }
  307. static inline void new_iov(struct iovec **iov, int *iov_cnt,
  308. struct tcmu_dev *udev)
  309. {
  310. struct iovec *iovec;
  311. if (*iov_cnt != 0)
  312. (*iov)++;
  313. (*iov_cnt)++;
  314. iovec = *iov;
  315. memset(iovec, 0, sizeof(struct iovec));
  316. }
  317. #define UPDATE_HEAD(head, used, size) smp_store_release(&head, ((head % size) + used) % size)
  318. /* offset is relative to mb_addr */
  319. static inline size_t get_block_offset_user(struct tcmu_dev *dev,
  320. int dbi, int remaining)
  321. {
  322. return dev->data_off + dbi * DATA_BLOCK_SIZE +
  323. DATA_BLOCK_SIZE - remaining;
  324. }
  325. static inline size_t iov_tail(struct tcmu_dev *udev, struct iovec *iov)
  326. {
  327. return (size_t)iov->iov_base + iov->iov_len;
  328. }
  329. static int scatter_data_area(struct tcmu_dev *udev,
  330. struct tcmu_cmd *tcmu_cmd, struct scatterlist *data_sg,
  331. unsigned int data_nents, struct iovec **iov,
  332. int *iov_cnt, bool copy_data)
  333. {
  334. int i, dbi;
  335. int block_remaining = 0;
  336. void *from, *to = NULL;
  337. size_t copy_bytes, to_offset, offset;
  338. struct scatterlist *sg;
  339. struct page *page;
  340. for_each_sg(data_sg, sg, data_nents, i) {
  341. int sg_remaining = sg->length;
  342. from = kmap_atomic(sg_page(sg)) + sg->offset;
  343. while (sg_remaining > 0) {
  344. if (block_remaining == 0) {
  345. if (to)
  346. kunmap_atomic(to);
  347. block_remaining = DATA_BLOCK_SIZE;
  348. dbi = tcmu_cmd_get_dbi(tcmu_cmd);
  349. page = tcmu_get_block_page(udev, dbi);
  350. to = kmap_atomic(page);
  351. }
  352. copy_bytes = min_t(size_t, sg_remaining,
  353. block_remaining);
  354. to_offset = get_block_offset_user(udev, dbi,
  355. block_remaining);
  356. offset = DATA_BLOCK_SIZE - block_remaining;
  357. to = (void *)(unsigned long)to + offset;
  358. if (*iov_cnt != 0 &&
  359. to_offset == iov_tail(udev, *iov)) {
  360. (*iov)->iov_len += copy_bytes;
  361. } else {
  362. new_iov(iov, iov_cnt, udev);
  363. (*iov)->iov_base = (void __user *)to_offset;
  364. (*iov)->iov_len = copy_bytes;
  365. }
  366. if (copy_data) {
  367. memcpy(to, from + sg->length - sg_remaining,
  368. copy_bytes);
  369. tcmu_flush_dcache_range(to, copy_bytes);
  370. }
  371. sg_remaining -= copy_bytes;
  372. block_remaining -= copy_bytes;
  373. }
  374. kunmap_atomic(from - sg->offset);
  375. }
  376. if (to)
  377. kunmap_atomic(to);
  378. return 0;
  379. }
  380. static void gather_data_area(struct tcmu_dev *udev, struct tcmu_cmd *cmd,
  381. bool bidi)
  382. {
  383. struct se_cmd *se_cmd = cmd->se_cmd;
  384. int i, dbi;
  385. int block_remaining = 0;
  386. void *from = NULL, *to;
  387. size_t copy_bytes, offset;
  388. struct scatterlist *sg, *data_sg;
  389. struct page *page;
  390. unsigned int data_nents;
  391. uint32_t count = 0;
  392. if (!bidi) {
  393. data_sg = se_cmd->t_data_sg;
  394. data_nents = se_cmd->t_data_nents;
  395. } else {
  396. /*
  397. * For bidi case, the first count blocks are for Data-Out
  398. * buffer blocks, and before gathering the Data-In buffer
  399. * the Data-Out buffer blocks should be discarded.
  400. */
  401. count = DIV_ROUND_UP(se_cmd->data_length, DATA_BLOCK_SIZE);
  402. data_sg = se_cmd->t_bidi_data_sg;
  403. data_nents = se_cmd->t_bidi_data_nents;
  404. }
  405. tcmu_cmd_set_dbi_cur(cmd, count);
  406. for_each_sg(data_sg, sg, data_nents, i) {
  407. int sg_remaining = sg->length;
  408. to = kmap_atomic(sg_page(sg)) + sg->offset;
  409. while (sg_remaining > 0) {
  410. if (block_remaining == 0) {
  411. if (from)
  412. kunmap_atomic(from);
  413. block_remaining = DATA_BLOCK_SIZE;
  414. dbi = tcmu_cmd_get_dbi(cmd);
  415. page = tcmu_get_block_page(udev, dbi);
  416. from = kmap_atomic(page);
  417. }
  418. copy_bytes = min_t(size_t, sg_remaining,
  419. block_remaining);
  420. offset = DATA_BLOCK_SIZE - block_remaining;
  421. from = (void *)(unsigned long)from + offset;
  422. tcmu_flush_dcache_range(from, copy_bytes);
  423. memcpy(to + sg->length - sg_remaining, from,
  424. copy_bytes);
  425. sg_remaining -= copy_bytes;
  426. block_remaining -= copy_bytes;
  427. }
  428. kunmap_atomic(to - sg->offset);
  429. }
  430. if (from)
  431. kunmap_atomic(from);
  432. }
  433. static inline size_t spc_bitmap_free(unsigned long *bitmap, uint32_t thresh)
  434. {
  435. return DATA_BLOCK_SIZE * (thresh - bitmap_weight(bitmap, thresh));
  436. }
  437. /*
  438. * We can't queue a command until we have space available on the cmd ring *and*
  439. * space available on the data area.
  440. *
  441. * Called with ring lock held.
  442. */
  443. static bool is_ring_space_avail(struct tcmu_dev *udev, struct tcmu_cmd *cmd,
  444. size_t cmd_size, size_t data_needed)
  445. {
  446. struct tcmu_mailbox *mb = udev->mb_addr;
  447. uint32_t blocks_needed = (data_needed + DATA_BLOCK_SIZE - 1)
  448. / DATA_BLOCK_SIZE;
  449. size_t space, cmd_needed;
  450. u32 cmd_head;
  451. tcmu_flush_dcache_range(mb, sizeof(*mb));
  452. cmd_head = mb->cmd_head % udev->cmdr_size; /* UAM */
  453. /*
  454. * If cmd end-of-ring space is too small then we need space for a NOP plus
  455. * original cmd - cmds are internally contiguous.
  456. */
  457. if (head_to_end(cmd_head, udev->cmdr_size) >= cmd_size)
  458. cmd_needed = cmd_size;
  459. else
  460. cmd_needed = cmd_size + head_to_end(cmd_head, udev->cmdr_size);
  461. space = spc_free(cmd_head, udev->cmdr_last_cleaned, udev->cmdr_size);
  462. if (space < cmd_needed) {
  463. pr_debug("no cmd space: %u %u %u\n", cmd_head,
  464. udev->cmdr_last_cleaned, udev->cmdr_size);
  465. return false;
  466. }
  467. /* try to check and get the data blocks as needed */
  468. space = spc_bitmap_free(udev->data_bitmap, udev->dbi_thresh);
  469. if (space < data_needed) {
  470. unsigned long blocks_left = DATA_BLOCK_BITS - udev->dbi_thresh;
  471. unsigned long grow;
  472. if (blocks_left < blocks_needed) {
  473. pr_debug("no data space: only %lu available, but ask for %zu\n",
  474. blocks_left * DATA_BLOCK_SIZE,
  475. data_needed);
  476. return false;
  477. }
  478. /* Try to expand the thresh */
  479. if (!udev->dbi_thresh) {
  480. /* From idle state */
  481. uint32_t init_thresh = DATA_BLOCK_INIT_BITS;
  482. udev->dbi_thresh = max(blocks_needed, init_thresh);
  483. } else {
  484. /*
  485. * Grow the data area by max(blocks needed,
  486. * dbi_thresh / 2), but limited to the max
  487. * DATA_BLOCK_BITS size.
  488. */
  489. grow = max(blocks_needed, udev->dbi_thresh / 2);
  490. udev->dbi_thresh += grow;
  491. if (udev->dbi_thresh > DATA_BLOCK_BITS)
  492. udev->dbi_thresh = DATA_BLOCK_BITS;
  493. }
  494. }
  495. if (!tcmu_get_empty_blocks(udev, cmd))
  496. return false;
  497. return true;
  498. }
  499. static inline size_t tcmu_cmd_get_base_cmd_size(size_t iov_cnt)
  500. {
  501. return max(offsetof(struct tcmu_cmd_entry, req.iov[iov_cnt]),
  502. sizeof(struct tcmu_cmd_entry));
  503. }
  504. static inline size_t tcmu_cmd_get_cmd_size(struct tcmu_cmd *tcmu_cmd,
  505. size_t base_command_size)
  506. {
  507. struct se_cmd *se_cmd = tcmu_cmd->se_cmd;
  508. size_t command_size;
  509. command_size = base_command_size +
  510. round_up(scsi_command_size(se_cmd->t_task_cdb),
  511. TCMU_OP_ALIGN_SIZE);
  512. WARN_ON(command_size & (TCMU_OP_ALIGN_SIZE-1));
  513. return command_size;
  514. }
  515. static sense_reason_t
  516. tcmu_queue_cmd_ring(struct tcmu_cmd *tcmu_cmd)
  517. {
  518. struct tcmu_dev *udev = tcmu_cmd->tcmu_dev;
  519. struct se_cmd *se_cmd = tcmu_cmd->se_cmd;
  520. size_t base_command_size, command_size;
  521. struct tcmu_mailbox *mb;
  522. struct tcmu_cmd_entry *entry;
  523. struct iovec *iov;
  524. int iov_cnt, ret;
  525. uint32_t cmd_head;
  526. uint64_t cdb_off;
  527. bool copy_to_data_area;
  528. size_t data_length = tcmu_cmd_get_data_length(tcmu_cmd);
  529. if (test_bit(TCMU_DEV_BIT_BROKEN, &udev->flags))
  530. return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
  531. /*
  532. * Must be a certain minimum size for response sense info, but
  533. * also may be larger if the iov array is large.
  534. *
  535. * We prepare as many iovs as possbile for potential uses here,
  536. * because it's expensive to tell how many regions are freed in
  537. * the bitmap & global data pool, as the size calculated here
  538. * will only be used to do the checks.
  539. *
  540. * The size will be recalculated later as actually needed to save
  541. * cmd area memories.
  542. */
  543. base_command_size = tcmu_cmd_get_base_cmd_size(tcmu_cmd->dbi_cnt);
  544. command_size = tcmu_cmd_get_cmd_size(tcmu_cmd, base_command_size);
  545. mutex_lock(&udev->cmdr_lock);
  546. mb = udev->mb_addr;
  547. cmd_head = mb->cmd_head % udev->cmdr_size; /* UAM */
  548. if ((command_size > (udev->cmdr_size / 2)) ||
  549. data_length > udev->data_size) {
  550. pr_warn("TCMU: Request of size %zu/%zu is too big for %u/%zu "
  551. "cmd ring/data area\n", command_size, data_length,
  552. udev->cmdr_size, udev->data_size);
  553. mutex_unlock(&udev->cmdr_lock);
  554. return TCM_INVALID_CDB_FIELD;
  555. }
  556. while (!is_ring_space_avail(udev, tcmu_cmd, command_size, data_length)) {
  557. int ret;
  558. DEFINE_WAIT(__wait);
  559. prepare_to_wait(&udev->wait_cmdr, &__wait, TASK_INTERRUPTIBLE);
  560. pr_debug("sleeping for ring space\n");
  561. mutex_unlock(&udev->cmdr_lock);
  562. if (udev->cmd_time_out)
  563. ret = schedule_timeout(
  564. msecs_to_jiffies(udev->cmd_time_out));
  565. else
  566. ret = schedule_timeout(msecs_to_jiffies(TCMU_TIME_OUT));
  567. finish_wait(&udev->wait_cmdr, &__wait);
  568. if (!ret) {
  569. pr_warn("tcmu: command timed out\n");
  570. return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
  571. }
  572. mutex_lock(&udev->cmdr_lock);
  573. /* We dropped cmdr_lock, cmd_head is stale */
  574. cmd_head = mb->cmd_head % udev->cmdr_size; /* UAM */
  575. }
  576. /* Insert a PAD if end-of-ring space is too small */
  577. if (head_to_end(cmd_head, udev->cmdr_size) < command_size) {
  578. size_t pad_size = head_to_end(cmd_head, udev->cmdr_size);
  579. entry = (void *) mb + CMDR_OFF + cmd_head;
  580. tcmu_flush_dcache_range(entry, sizeof(*entry));
  581. tcmu_hdr_set_op(&entry->hdr.len_op, TCMU_OP_PAD);
  582. tcmu_hdr_set_len(&entry->hdr.len_op, pad_size);
  583. entry->hdr.cmd_id = 0; /* not used for PAD */
  584. entry->hdr.kflags = 0;
  585. entry->hdr.uflags = 0;
  586. UPDATE_HEAD(mb->cmd_head, pad_size, udev->cmdr_size);
  587. cmd_head = mb->cmd_head % udev->cmdr_size; /* UAM */
  588. WARN_ON(cmd_head != 0);
  589. }
  590. entry = (void *) mb + CMDR_OFF + cmd_head;
  591. tcmu_flush_dcache_range(entry, sizeof(*entry));
  592. tcmu_hdr_set_op(&entry->hdr.len_op, TCMU_OP_CMD);
  593. entry->hdr.cmd_id = tcmu_cmd->cmd_id;
  594. entry->hdr.kflags = 0;
  595. entry->hdr.uflags = 0;
  596. /* Handle allocating space from the data area */
  597. tcmu_cmd_reset_dbi_cur(tcmu_cmd);
  598. iov = &entry->req.iov[0];
  599. iov_cnt = 0;
  600. copy_to_data_area = (se_cmd->data_direction == DMA_TO_DEVICE
  601. || se_cmd->se_cmd_flags & SCF_BIDI);
  602. ret = scatter_data_area(udev, tcmu_cmd, se_cmd->t_data_sg,
  603. se_cmd->t_data_nents, &iov, &iov_cnt,
  604. copy_to_data_area);
  605. if (ret) {
  606. tcmu_cmd_free_data(tcmu_cmd, tcmu_cmd->dbi_cnt);
  607. mutex_unlock(&udev->cmdr_lock);
  608. pr_err("tcmu: alloc and scatter data failed\n");
  609. return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
  610. }
  611. entry->req.iov_cnt = iov_cnt;
  612. entry->req.iov_dif_cnt = 0;
  613. /* Handle BIDI commands */
  614. if (se_cmd->se_cmd_flags & SCF_BIDI) {
  615. iov_cnt = 0;
  616. iov++;
  617. ret = scatter_data_area(udev, tcmu_cmd,
  618. se_cmd->t_bidi_data_sg,
  619. se_cmd->t_bidi_data_nents,
  620. &iov, &iov_cnt, false);
  621. if (ret) {
  622. tcmu_cmd_free_data(tcmu_cmd, tcmu_cmd->dbi_cnt);
  623. mutex_unlock(&udev->cmdr_lock);
  624. pr_err("tcmu: alloc and scatter bidi data failed\n");
  625. return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
  626. }
  627. entry->req.iov_bidi_cnt = iov_cnt;
  628. }
  629. /*
  630. * Recalaulate the command's base size and size according
  631. * to the actual needs
  632. */
  633. base_command_size = tcmu_cmd_get_base_cmd_size(entry->req.iov_cnt +
  634. entry->req.iov_bidi_cnt);
  635. command_size = tcmu_cmd_get_cmd_size(tcmu_cmd, base_command_size);
  636. tcmu_hdr_set_len(&entry->hdr.len_op, command_size);
  637. /* All offsets relative to mb_addr, not start of entry! */
  638. cdb_off = CMDR_OFF + cmd_head + base_command_size;
  639. memcpy((void *) mb + cdb_off, se_cmd->t_task_cdb, scsi_command_size(se_cmd->t_task_cdb));
  640. entry->req.cdb_off = cdb_off;
  641. tcmu_flush_dcache_range(entry, sizeof(*entry));
  642. UPDATE_HEAD(mb->cmd_head, command_size, udev->cmdr_size);
  643. tcmu_flush_dcache_range(mb, sizeof(*mb));
  644. mutex_unlock(&udev->cmdr_lock);
  645. /* TODO: only if FLUSH and FUA? */
  646. uio_event_notify(&udev->uio_info);
  647. if (udev->cmd_time_out)
  648. mod_timer(&udev->timeout, round_jiffies_up(jiffies +
  649. msecs_to_jiffies(udev->cmd_time_out)));
  650. return TCM_NO_SENSE;
  651. }
  652. static sense_reason_t
  653. tcmu_queue_cmd(struct se_cmd *se_cmd)
  654. {
  655. struct se_device *se_dev = se_cmd->se_dev;
  656. struct tcmu_dev *udev = TCMU_DEV(se_dev);
  657. struct tcmu_cmd *tcmu_cmd;
  658. sense_reason_t ret;
  659. tcmu_cmd = tcmu_alloc_cmd(se_cmd);
  660. if (!tcmu_cmd)
  661. return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
  662. ret = tcmu_queue_cmd_ring(tcmu_cmd);
  663. if (ret != TCM_NO_SENSE) {
  664. pr_err("TCMU: Could not queue command\n");
  665. spin_lock_irq(&udev->commands_lock);
  666. idr_remove(&udev->commands, tcmu_cmd->cmd_id);
  667. spin_unlock_irq(&udev->commands_lock);
  668. tcmu_free_cmd(tcmu_cmd);
  669. }
  670. return ret;
  671. }
  672. static void tcmu_handle_completion(struct tcmu_cmd *cmd, struct tcmu_cmd_entry *entry)
  673. {
  674. struct se_cmd *se_cmd = cmd->se_cmd;
  675. struct tcmu_dev *udev = cmd->tcmu_dev;
  676. /*
  677. * cmd has been completed already from timeout, just reclaim
  678. * data area space and free cmd
  679. */
  680. if (test_bit(TCMU_CMD_BIT_EXPIRED, &cmd->flags))
  681. goto out;
  682. tcmu_cmd_reset_dbi_cur(cmd);
  683. if (entry->hdr.uflags & TCMU_UFLAG_UNKNOWN_OP) {
  684. pr_warn("TCMU: Userspace set UNKNOWN_OP flag on se_cmd %p\n",
  685. cmd->se_cmd);
  686. entry->rsp.scsi_status = SAM_STAT_CHECK_CONDITION;
  687. } else if (entry->rsp.scsi_status == SAM_STAT_CHECK_CONDITION) {
  688. memcpy(se_cmd->sense_buffer, entry->rsp.sense_buffer,
  689. se_cmd->scsi_sense_length);
  690. } else if (se_cmd->se_cmd_flags & SCF_BIDI) {
  691. /* Get Data-In buffer before clean up */
  692. gather_data_area(udev, cmd, true);
  693. } else if (se_cmd->data_direction == DMA_FROM_DEVICE) {
  694. gather_data_area(udev, cmd, false);
  695. } else if (se_cmd->data_direction == DMA_TO_DEVICE) {
  696. /* TODO: */
  697. } else if (se_cmd->data_direction != DMA_NONE) {
  698. pr_warn("TCMU: data direction was %d!\n",
  699. se_cmd->data_direction);
  700. }
  701. target_complete_cmd(cmd->se_cmd, entry->rsp.scsi_status);
  702. out:
  703. cmd->se_cmd = NULL;
  704. tcmu_cmd_free_data(cmd, cmd->dbi_cnt);
  705. tcmu_free_cmd(cmd);
  706. }
  707. static unsigned int tcmu_handle_completions(struct tcmu_dev *udev)
  708. {
  709. struct tcmu_mailbox *mb;
  710. int handled = 0;
  711. if (test_bit(TCMU_DEV_BIT_BROKEN, &udev->flags)) {
  712. pr_err("ring broken, not handling completions\n");
  713. return 0;
  714. }
  715. mb = udev->mb_addr;
  716. tcmu_flush_dcache_range(mb, sizeof(*mb));
  717. while (udev->cmdr_last_cleaned != ACCESS_ONCE(mb->cmd_tail)) {
  718. struct tcmu_cmd_entry *entry = (void *) mb + CMDR_OFF + udev->cmdr_last_cleaned;
  719. struct tcmu_cmd *cmd;
  720. tcmu_flush_dcache_range(entry, sizeof(*entry));
  721. if (tcmu_hdr_get_op(entry->hdr.len_op) == TCMU_OP_PAD) {
  722. UPDATE_HEAD(udev->cmdr_last_cleaned,
  723. tcmu_hdr_get_len(entry->hdr.len_op),
  724. udev->cmdr_size);
  725. continue;
  726. }
  727. WARN_ON(tcmu_hdr_get_op(entry->hdr.len_op) != TCMU_OP_CMD);
  728. spin_lock(&udev->commands_lock);
  729. cmd = idr_remove(&udev->commands, entry->hdr.cmd_id);
  730. spin_unlock(&udev->commands_lock);
  731. if (!cmd) {
  732. pr_err("cmd_id not found, ring is broken\n");
  733. set_bit(TCMU_DEV_BIT_BROKEN, &udev->flags);
  734. break;
  735. }
  736. tcmu_handle_completion(cmd, entry);
  737. UPDATE_HEAD(udev->cmdr_last_cleaned,
  738. tcmu_hdr_get_len(entry->hdr.len_op),
  739. udev->cmdr_size);
  740. handled++;
  741. }
  742. if (mb->cmd_tail == mb->cmd_head)
  743. del_timer(&udev->timeout); /* no more pending cmds */
  744. wake_up(&udev->wait_cmdr);
  745. return handled;
  746. }
  747. static int tcmu_check_expired_cmd(int id, void *p, void *data)
  748. {
  749. struct tcmu_cmd *cmd = p;
  750. if (test_bit(TCMU_CMD_BIT_EXPIRED, &cmd->flags))
  751. return 0;
  752. if (!time_after(jiffies, cmd->deadline))
  753. return 0;
  754. set_bit(TCMU_CMD_BIT_EXPIRED, &cmd->flags);
  755. target_complete_cmd(cmd->se_cmd, SAM_STAT_CHECK_CONDITION);
  756. cmd->se_cmd = NULL;
  757. return 0;
  758. }
  759. static void tcmu_device_timedout(unsigned long data)
  760. {
  761. struct tcmu_dev *udev = (struct tcmu_dev *)data;
  762. unsigned long flags;
  763. spin_lock_irqsave(&udev->commands_lock, flags);
  764. idr_for_each(&udev->commands, tcmu_check_expired_cmd, NULL);
  765. spin_unlock_irqrestore(&udev->commands_lock, flags);
  766. /* Try to wake up the ummap thread */
  767. wake_up(&unmap_wait);
  768. /*
  769. * We don't need to wakeup threads on wait_cmdr since they have their
  770. * own timeout.
  771. */
  772. }
  773. static int tcmu_attach_hba(struct se_hba *hba, u32 host_id)
  774. {
  775. struct tcmu_hba *tcmu_hba;
  776. tcmu_hba = kzalloc(sizeof(struct tcmu_hba), GFP_KERNEL);
  777. if (!tcmu_hba)
  778. return -ENOMEM;
  779. tcmu_hba->host_id = host_id;
  780. hba->hba_ptr = tcmu_hba;
  781. return 0;
  782. }
  783. static void tcmu_detach_hba(struct se_hba *hba)
  784. {
  785. kfree(hba->hba_ptr);
  786. hba->hba_ptr = NULL;
  787. }
  788. static struct se_device *tcmu_alloc_device(struct se_hba *hba, const char *name)
  789. {
  790. struct tcmu_dev *udev;
  791. udev = kzalloc(sizeof(struct tcmu_dev), GFP_KERNEL);
  792. if (!udev)
  793. return NULL;
  794. kref_init(&udev->kref);
  795. udev->name = kstrdup(name, GFP_KERNEL);
  796. if (!udev->name) {
  797. kfree(udev);
  798. return NULL;
  799. }
  800. udev->hba = hba;
  801. udev->cmd_time_out = TCMU_TIME_OUT;
  802. init_waitqueue_head(&udev->wait_cmdr);
  803. mutex_init(&udev->cmdr_lock);
  804. idr_init(&udev->commands);
  805. spin_lock_init(&udev->commands_lock);
  806. setup_timer(&udev->timeout, tcmu_device_timedout,
  807. (unsigned long)udev);
  808. return &udev->se_dev;
  809. }
  810. static int tcmu_irqcontrol(struct uio_info *info, s32 irq_on)
  811. {
  812. struct tcmu_dev *tcmu_dev = container_of(info, struct tcmu_dev, uio_info);
  813. mutex_lock(&tcmu_dev->cmdr_lock);
  814. tcmu_handle_completions(tcmu_dev);
  815. mutex_unlock(&tcmu_dev->cmdr_lock);
  816. return 0;
  817. }
  818. /*
  819. * mmap code from uio.c. Copied here because we want to hook mmap()
  820. * and this stuff must come along.
  821. */
  822. static int tcmu_find_mem_index(struct vm_area_struct *vma)
  823. {
  824. struct tcmu_dev *udev = vma->vm_private_data;
  825. struct uio_info *info = &udev->uio_info;
  826. if (vma->vm_pgoff < MAX_UIO_MAPS) {
  827. if (info->mem[vma->vm_pgoff].size == 0)
  828. return -1;
  829. return (int)vma->vm_pgoff;
  830. }
  831. return -1;
  832. }
  833. static struct page *tcmu_try_get_block_page(struct tcmu_dev *udev, uint32_t dbi)
  834. {
  835. struct page *page;
  836. int ret;
  837. mutex_lock(&udev->cmdr_lock);
  838. page = tcmu_get_block_page(udev, dbi);
  839. if (likely(page)) {
  840. mutex_unlock(&udev->cmdr_lock);
  841. return page;
  842. }
  843. /*
  844. * Normally it shouldn't be here:
  845. * Only when the userspace has touched the blocks which
  846. * are out of the tcmu_cmd's data iov[], and will return
  847. * one zeroed page.
  848. */
  849. pr_warn("Block(%u) out of cmd's iov[] has been touched!\n", dbi);
  850. pr_warn("Mostly it will be a bug of userspace, please have a check!\n");
  851. if (dbi >= udev->dbi_thresh) {
  852. /* Extern the udev->dbi_thresh to dbi + 1 */
  853. udev->dbi_thresh = dbi + 1;
  854. udev->dbi_max = dbi;
  855. }
  856. page = radix_tree_lookup(&udev->data_blocks, dbi);
  857. if (!page) {
  858. page = alloc_page(GFP_KERNEL | __GFP_ZERO);
  859. if (!page) {
  860. mutex_unlock(&udev->cmdr_lock);
  861. return NULL;
  862. }
  863. ret = radix_tree_insert(&udev->data_blocks, dbi, page);
  864. if (ret) {
  865. mutex_unlock(&udev->cmdr_lock);
  866. __free_page(page);
  867. return NULL;
  868. }
  869. /*
  870. * Since this case is rare in page fault routine, here we
  871. * will allow the global_db_count >= TCMU_GLOBAL_MAX_BLOCKS
  872. * to reduce possible page fault call trace.
  873. */
  874. atomic_inc(&global_db_count);
  875. }
  876. mutex_unlock(&udev->cmdr_lock);
  877. return page;
  878. }
  879. static int tcmu_vma_fault(struct vm_fault *vmf)
  880. {
  881. struct tcmu_dev *udev = vmf->vma->vm_private_data;
  882. struct uio_info *info = &udev->uio_info;
  883. struct page *page;
  884. unsigned long offset;
  885. void *addr;
  886. int mi = tcmu_find_mem_index(vmf->vma);
  887. if (mi < 0)
  888. return VM_FAULT_SIGBUS;
  889. /*
  890. * We need to subtract mi because userspace uses offset = N*PAGE_SIZE
  891. * to use mem[N].
  892. */
  893. offset = (vmf->pgoff - mi) << PAGE_SHIFT;
  894. if (offset < udev->data_off) {
  895. /* For the vmalloc()ed cmd area pages */
  896. addr = (void *)(unsigned long)info->mem[mi].addr + offset;
  897. page = vmalloc_to_page(addr);
  898. } else {
  899. uint32_t dbi;
  900. /* For the dynamically growing data area pages */
  901. dbi = (offset - udev->data_off) / DATA_BLOCK_SIZE;
  902. page = tcmu_try_get_block_page(udev, dbi);
  903. if (!page)
  904. return VM_FAULT_NOPAGE;
  905. }
  906. get_page(page);
  907. vmf->page = page;
  908. return 0;
  909. }
  910. static const struct vm_operations_struct tcmu_vm_ops = {
  911. .fault = tcmu_vma_fault,
  912. };
  913. static int tcmu_mmap(struct uio_info *info, struct vm_area_struct *vma)
  914. {
  915. struct tcmu_dev *udev = container_of(info, struct tcmu_dev, uio_info);
  916. vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
  917. vma->vm_ops = &tcmu_vm_ops;
  918. vma->vm_private_data = udev;
  919. /* Ensure the mmap is exactly the right size */
  920. if (vma_pages(vma) != (TCMU_RING_SIZE >> PAGE_SHIFT))
  921. return -EINVAL;
  922. return 0;
  923. }
  924. static int tcmu_open(struct uio_info *info, struct inode *inode)
  925. {
  926. struct tcmu_dev *udev = container_of(info, struct tcmu_dev, uio_info);
  927. /* O_EXCL not supported for char devs, so fake it? */
  928. if (test_and_set_bit(TCMU_DEV_BIT_OPEN, &udev->flags))
  929. return -EBUSY;
  930. udev->inode = inode;
  931. pr_debug("open\n");
  932. return 0;
  933. }
  934. static void tcmu_dev_call_rcu(struct rcu_head *p)
  935. {
  936. struct se_device *dev = container_of(p, struct se_device, rcu_head);
  937. struct tcmu_dev *udev = TCMU_DEV(dev);
  938. kfree(udev->uio_info.name);
  939. kfree(udev->name);
  940. kfree(udev);
  941. }
  942. static void tcmu_dev_kref_release(struct kref *kref)
  943. {
  944. struct tcmu_dev *udev = container_of(kref, struct tcmu_dev, kref);
  945. struct se_device *dev = &udev->se_dev;
  946. call_rcu(&dev->rcu_head, tcmu_dev_call_rcu);
  947. }
  948. static int tcmu_release(struct uio_info *info, struct inode *inode)
  949. {
  950. struct tcmu_dev *udev = container_of(info, struct tcmu_dev, uio_info);
  951. clear_bit(TCMU_DEV_BIT_OPEN, &udev->flags);
  952. pr_debug("close\n");
  953. /* release ref from configure */
  954. kref_put(&udev->kref, tcmu_dev_kref_release);
  955. return 0;
  956. }
  957. static int tcmu_netlink_event(enum tcmu_genl_cmd cmd, const char *name, int minor)
  958. {
  959. struct sk_buff *skb;
  960. void *msg_header;
  961. int ret = -ENOMEM;
  962. skb = genlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
  963. if (!skb)
  964. return ret;
  965. msg_header = genlmsg_put(skb, 0, 0, &tcmu_genl_family, 0, cmd);
  966. if (!msg_header)
  967. goto free_skb;
  968. ret = nla_put_string(skb, TCMU_ATTR_DEVICE, name);
  969. if (ret < 0)
  970. goto free_skb;
  971. ret = nla_put_u32(skb, TCMU_ATTR_MINOR, minor);
  972. if (ret < 0)
  973. goto free_skb;
  974. genlmsg_end(skb, msg_header);
  975. ret = genlmsg_multicast_allns(&tcmu_genl_family, skb, 0,
  976. TCMU_MCGRP_CONFIG, GFP_KERNEL);
  977. /* We don't care if no one is listening */
  978. if (ret == -ESRCH)
  979. ret = 0;
  980. return ret;
  981. free_skb:
  982. nlmsg_free(skb);
  983. return ret;
  984. }
  985. static int tcmu_configure_device(struct se_device *dev)
  986. {
  987. struct tcmu_dev *udev = TCMU_DEV(dev);
  988. struct tcmu_hba *hba = udev->hba->hba_ptr;
  989. struct uio_info *info;
  990. struct tcmu_mailbox *mb;
  991. size_t size;
  992. size_t used;
  993. int ret = 0;
  994. char *str;
  995. info = &udev->uio_info;
  996. size = snprintf(NULL, 0, "tcm-user/%u/%s/%s", hba->host_id, udev->name,
  997. udev->dev_config);
  998. size += 1; /* for \0 */
  999. str = kmalloc(size, GFP_KERNEL);
  1000. if (!str)
  1001. return -ENOMEM;
  1002. used = snprintf(str, size, "tcm-user/%u/%s", hba->host_id, udev->name);
  1003. if (udev->dev_config[0])
  1004. snprintf(str + used, size - used, "/%s", udev->dev_config);
  1005. info->name = str;
  1006. udev->mb_addr = vzalloc(CMDR_SIZE);
  1007. if (!udev->mb_addr) {
  1008. ret = -ENOMEM;
  1009. goto err_vzalloc;
  1010. }
  1011. /* mailbox fits in first part of CMDR space */
  1012. udev->cmdr_size = CMDR_SIZE - CMDR_OFF;
  1013. udev->data_off = CMDR_SIZE;
  1014. udev->data_size = DATA_SIZE;
  1015. udev->dbi_thresh = 0; /* Default in Idle state */
  1016. udev->waiting_global = false;
  1017. /* Initialise the mailbox of the ring buffer */
  1018. mb = udev->mb_addr;
  1019. mb->version = TCMU_MAILBOX_VERSION;
  1020. mb->flags = TCMU_MAILBOX_FLAG_CAP_OOOC;
  1021. mb->cmdr_off = CMDR_OFF;
  1022. mb->cmdr_size = udev->cmdr_size;
  1023. WARN_ON(!PAGE_ALIGNED(udev->data_off));
  1024. WARN_ON(udev->data_size % PAGE_SIZE);
  1025. WARN_ON(udev->data_size % DATA_BLOCK_SIZE);
  1026. INIT_RADIX_TREE(&udev->data_blocks, GFP_KERNEL);
  1027. info->version = __stringify(TCMU_MAILBOX_VERSION);
  1028. info->mem[0].name = "tcm-user command & data buffer";
  1029. info->mem[0].addr = (phys_addr_t)(uintptr_t)udev->mb_addr;
  1030. info->mem[0].size = TCMU_RING_SIZE;
  1031. info->mem[0].memtype = UIO_MEM_NONE;
  1032. info->irqcontrol = tcmu_irqcontrol;
  1033. info->irq = UIO_IRQ_CUSTOM;
  1034. info->mmap = tcmu_mmap;
  1035. info->open = tcmu_open;
  1036. info->release = tcmu_release;
  1037. ret = uio_register_device(tcmu_root_device, info);
  1038. if (ret)
  1039. goto err_register;
  1040. /* User can set hw_block_size before enable the device */
  1041. if (dev->dev_attrib.hw_block_size == 0)
  1042. dev->dev_attrib.hw_block_size = 512;
  1043. /* Other attributes can be configured in userspace */
  1044. if (!dev->dev_attrib.hw_max_sectors)
  1045. dev->dev_attrib.hw_max_sectors = 128;
  1046. dev->dev_attrib.hw_queue_depth = 128;
  1047. /*
  1048. * Get a ref incase userspace does a close on the uio device before
  1049. * LIO has initiated tcmu_free_device.
  1050. */
  1051. kref_get(&udev->kref);
  1052. ret = tcmu_netlink_event(TCMU_CMD_ADDED_DEVICE, udev->uio_info.name,
  1053. udev->uio_info.uio_dev->minor);
  1054. if (ret)
  1055. goto err_netlink;
  1056. mutex_lock(&root_udev_mutex);
  1057. list_add(&udev->node, &root_udev);
  1058. mutex_unlock(&root_udev_mutex);
  1059. return 0;
  1060. err_netlink:
  1061. kref_put(&udev->kref, tcmu_dev_kref_release);
  1062. uio_unregister_device(&udev->uio_info);
  1063. err_register:
  1064. vfree(udev->mb_addr);
  1065. err_vzalloc:
  1066. kfree(info->name);
  1067. info->name = NULL;
  1068. return ret;
  1069. }
  1070. static int tcmu_check_and_free_pending_cmd(struct tcmu_cmd *cmd)
  1071. {
  1072. if (test_bit(TCMU_CMD_BIT_EXPIRED, &cmd->flags)) {
  1073. kmem_cache_free(tcmu_cmd_cache, cmd);
  1074. return 0;
  1075. }
  1076. return -EINVAL;
  1077. }
  1078. static bool tcmu_dev_configured(struct tcmu_dev *udev)
  1079. {
  1080. return udev->uio_info.uio_dev ? true : false;
  1081. }
  1082. static void tcmu_blocks_release(struct tcmu_dev *udev)
  1083. {
  1084. int i;
  1085. struct page *page;
  1086. /* Try to release all block pages */
  1087. mutex_lock(&udev->cmdr_lock);
  1088. for (i = 0; i <= udev->dbi_max; i++) {
  1089. page = radix_tree_delete(&udev->data_blocks, i);
  1090. if (page) {
  1091. __free_page(page);
  1092. atomic_dec(&global_db_count);
  1093. }
  1094. }
  1095. mutex_unlock(&udev->cmdr_lock);
  1096. }
  1097. static void tcmu_free_device(struct se_device *dev)
  1098. {
  1099. struct tcmu_dev *udev = TCMU_DEV(dev);
  1100. struct tcmu_cmd *cmd;
  1101. bool all_expired = true;
  1102. int i;
  1103. del_timer_sync(&udev->timeout);
  1104. mutex_lock(&root_udev_mutex);
  1105. list_del(&udev->node);
  1106. mutex_unlock(&root_udev_mutex);
  1107. vfree(udev->mb_addr);
  1108. /* Upper layer should drain all requests before calling this */
  1109. spin_lock_irq(&udev->commands_lock);
  1110. idr_for_each_entry(&udev->commands, cmd, i) {
  1111. if (tcmu_check_and_free_pending_cmd(cmd) != 0)
  1112. all_expired = false;
  1113. }
  1114. idr_destroy(&udev->commands);
  1115. spin_unlock_irq(&udev->commands_lock);
  1116. WARN_ON(!all_expired);
  1117. tcmu_blocks_release(udev);
  1118. if (tcmu_dev_configured(udev)) {
  1119. tcmu_netlink_event(TCMU_CMD_REMOVED_DEVICE, udev->uio_info.name,
  1120. udev->uio_info.uio_dev->minor);
  1121. uio_unregister_device(&udev->uio_info);
  1122. }
  1123. /* release ref from init */
  1124. kref_put(&udev->kref, tcmu_dev_kref_release);
  1125. }
  1126. enum {
  1127. Opt_dev_config, Opt_dev_size, Opt_hw_block_size, Opt_hw_max_sectors,
  1128. Opt_err,
  1129. };
  1130. static match_table_t tokens = {
  1131. {Opt_dev_config, "dev_config=%s"},
  1132. {Opt_dev_size, "dev_size=%u"},
  1133. {Opt_hw_block_size, "hw_block_size=%u"},
  1134. {Opt_hw_max_sectors, "hw_max_sectors=%u"},
  1135. {Opt_err, NULL}
  1136. };
  1137. static int tcmu_set_dev_attrib(substring_t *arg, u32 *dev_attrib)
  1138. {
  1139. unsigned long tmp_ul;
  1140. char *arg_p;
  1141. int ret;
  1142. arg_p = match_strdup(arg);
  1143. if (!arg_p)
  1144. return -ENOMEM;
  1145. ret = kstrtoul(arg_p, 0, &tmp_ul);
  1146. kfree(arg_p);
  1147. if (ret < 0) {
  1148. pr_err("kstrtoul() failed for dev attrib\n");
  1149. return ret;
  1150. }
  1151. if (!tmp_ul) {
  1152. pr_err("dev attrib must be nonzero\n");
  1153. return -EINVAL;
  1154. }
  1155. *dev_attrib = tmp_ul;
  1156. return 0;
  1157. }
  1158. static ssize_t tcmu_set_configfs_dev_params(struct se_device *dev,
  1159. const char *page, ssize_t count)
  1160. {
  1161. struct tcmu_dev *udev = TCMU_DEV(dev);
  1162. char *orig, *ptr, *opts, *arg_p;
  1163. substring_t args[MAX_OPT_ARGS];
  1164. int ret = 0, token;
  1165. opts = kstrdup(page, GFP_KERNEL);
  1166. if (!opts)
  1167. return -ENOMEM;
  1168. orig = opts;
  1169. while ((ptr = strsep(&opts, ",\n")) != NULL) {
  1170. if (!*ptr)
  1171. continue;
  1172. token = match_token(ptr, tokens, args);
  1173. switch (token) {
  1174. case Opt_dev_config:
  1175. if (match_strlcpy(udev->dev_config, &args[0],
  1176. TCMU_CONFIG_LEN) == 0) {
  1177. ret = -EINVAL;
  1178. break;
  1179. }
  1180. pr_debug("TCMU: Referencing Path: %s\n", udev->dev_config);
  1181. break;
  1182. case Opt_dev_size:
  1183. arg_p = match_strdup(&args[0]);
  1184. if (!arg_p) {
  1185. ret = -ENOMEM;
  1186. break;
  1187. }
  1188. ret = kstrtoul(arg_p, 0, (unsigned long *) &udev->dev_size);
  1189. kfree(arg_p);
  1190. if (ret < 0)
  1191. pr_err("kstrtoul() failed for dev_size=\n");
  1192. break;
  1193. case Opt_hw_block_size:
  1194. ret = tcmu_set_dev_attrib(&args[0],
  1195. &(dev->dev_attrib.hw_block_size));
  1196. break;
  1197. case Opt_hw_max_sectors:
  1198. ret = tcmu_set_dev_attrib(&args[0],
  1199. &(dev->dev_attrib.hw_max_sectors));
  1200. break;
  1201. default:
  1202. break;
  1203. }
  1204. if (ret)
  1205. break;
  1206. }
  1207. kfree(orig);
  1208. return (!ret) ? count : ret;
  1209. }
  1210. static ssize_t tcmu_show_configfs_dev_params(struct se_device *dev, char *b)
  1211. {
  1212. struct tcmu_dev *udev = TCMU_DEV(dev);
  1213. ssize_t bl = 0;
  1214. bl = sprintf(b + bl, "Config: %s ",
  1215. udev->dev_config[0] ? udev->dev_config : "NULL");
  1216. bl += sprintf(b + bl, "Size: %zu\n", udev->dev_size);
  1217. return bl;
  1218. }
  1219. static sector_t tcmu_get_blocks(struct se_device *dev)
  1220. {
  1221. struct tcmu_dev *udev = TCMU_DEV(dev);
  1222. return div_u64(udev->dev_size - dev->dev_attrib.block_size,
  1223. dev->dev_attrib.block_size);
  1224. }
  1225. static sense_reason_t
  1226. tcmu_parse_cdb(struct se_cmd *cmd)
  1227. {
  1228. return passthrough_parse_cdb(cmd, tcmu_queue_cmd);
  1229. }
  1230. static ssize_t tcmu_cmd_time_out_show(struct config_item *item, char *page)
  1231. {
  1232. struct se_dev_attrib *da = container_of(to_config_group(item),
  1233. struct se_dev_attrib, da_group);
  1234. struct tcmu_dev *udev = container_of(da->da_dev,
  1235. struct tcmu_dev, se_dev);
  1236. return snprintf(page, PAGE_SIZE, "%lu\n", udev->cmd_time_out / MSEC_PER_SEC);
  1237. }
  1238. static ssize_t tcmu_cmd_time_out_store(struct config_item *item, const char *page,
  1239. size_t count)
  1240. {
  1241. struct se_dev_attrib *da = container_of(to_config_group(item),
  1242. struct se_dev_attrib, da_group);
  1243. struct tcmu_dev *udev = container_of(da->da_dev,
  1244. struct tcmu_dev, se_dev);
  1245. u32 val;
  1246. int ret;
  1247. if (da->da_dev->export_count) {
  1248. pr_err("Unable to set tcmu cmd_time_out while exports exist\n");
  1249. return -EINVAL;
  1250. }
  1251. ret = kstrtou32(page, 0, &val);
  1252. if (ret < 0)
  1253. return ret;
  1254. udev->cmd_time_out = val * MSEC_PER_SEC;
  1255. return count;
  1256. }
  1257. CONFIGFS_ATTR(tcmu_, cmd_time_out);
  1258. static struct configfs_attribute **tcmu_attrs;
  1259. static struct target_backend_ops tcmu_ops = {
  1260. .name = "user",
  1261. .owner = THIS_MODULE,
  1262. .transport_flags = TRANSPORT_FLAG_PASSTHROUGH,
  1263. .attach_hba = tcmu_attach_hba,
  1264. .detach_hba = tcmu_detach_hba,
  1265. .alloc_device = tcmu_alloc_device,
  1266. .configure_device = tcmu_configure_device,
  1267. .free_device = tcmu_free_device,
  1268. .parse_cdb = tcmu_parse_cdb,
  1269. .set_configfs_dev_params = tcmu_set_configfs_dev_params,
  1270. .show_configfs_dev_params = tcmu_show_configfs_dev_params,
  1271. .get_device_type = sbc_get_device_type,
  1272. .get_blocks = tcmu_get_blocks,
  1273. .tb_dev_attrib_attrs = NULL,
  1274. };
  1275. static int unmap_thread_fn(void *data)
  1276. {
  1277. struct tcmu_dev *udev;
  1278. loff_t off;
  1279. uint32_t start, end, block;
  1280. struct page *page;
  1281. int i;
  1282. while (1) {
  1283. DEFINE_WAIT(__wait);
  1284. prepare_to_wait(&unmap_wait, &__wait, TASK_INTERRUPTIBLE);
  1285. schedule();
  1286. finish_wait(&unmap_wait, &__wait);
  1287. if (kthread_should_stop())
  1288. break;
  1289. mutex_lock(&root_udev_mutex);
  1290. list_for_each_entry(udev, &root_udev, node) {
  1291. mutex_lock(&udev->cmdr_lock);
  1292. /* Try to complete the finished commands first */
  1293. tcmu_handle_completions(udev);
  1294. /* Skip the udevs waiting the global pool or in idle */
  1295. if (udev->waiting_global || !udev->dbi_thresh) {
  1296. mutex_unlock(&udev->cmdr_lock);
  1297. continue;
  1298. }
  1299. end = udev->dbi_max + 1;
  1300. block = find_last_bit(udev->data_bitmap, end);
  1301. if (block == udev->dbi_max) {
  1302. /*
  1303. * The last bit is dbi_max, so there is
  1304. * no need to shrink any blocks.
  1305. */
  1306. mutex_unlock(&udev->cmdr_lock);
  1307. continue;
  1308. } else if (block == end) {
  1309. /* The current udev will goto idle state */
  1310. udev->dbi_thresh = start = 0;
  1311. udev->dbi_max = 0;
  1312. } else {
  1313. udev->dbi_thresh = start = block + 1;
  1314. udev->dbi_max = block;
  1315. }
  1316. /* Here will truncate the data area from off */
  1317. off = udev->data_off + start * DATA_BLOCK_SIZE;
  1318. unmap_mapping_range(udev->inode->i_mapping, off, 0, 1);
  1319. /* Release the block pages */
  1320. for (i = start; i < end; i++) {
  1321. page = radix_tree_delete(&udev->data_blocks, i);
  1322. if (page) {
  1323. __free_page(page);
  1324. atomic_dec(&global_db_count);
  1325. }
  1326. }
  1327. mutex_unlock(&udev->cmdr_lock);
  1328. }
  1329. /*
  1330. * Try to wake up the udevs who are waiting
  1331. * for the global data pool.
  1332. */
  1333. list_for_each_entry(udev, &root_udev, node) {
  1334. if (udev->waiting_global)
  1335. wake_up(&udev->wait_cmdr);
  1336. }
  1337. mutex_unlock(&root_udev_mutex);
  1338. }
  1339. return 0;
  1340. }
  1341. static int __init tcmu_module_init(void)
  1342. {
  1343. int ret, i, len = 0;
  1344. BUILD_BUG_ON((sizeof(struct tcmu_cmd_entry) % TCMU_OP_ALIGN_SIZE) != 0);
  1345. tcmu_cmd_cache = kmem_cache_create("tcmu_cmd_cache",
  1346. sizeof(struct tcmu_cmd),
  1347. __alignof__(struct tcmu_cmd),
  1348. 0, NULL);
  1349. if (!tcmu_cmd_cache)
  1350. return -ENOMEM;
  1351. tcmu_root_device = root_device_register("tcm_user");
  1352. if (IS_ERR(tcmu_root_device)) {
  1353. ret = PTR_ERR(tcmu_root_device);
  1354. goto out_free_cache;
  1355. }
  1356. ret = genl_register_family(&tcmu_genl_family);
  1357. if (ret < 0) {
  1358. goto out_unreg_device;
  1359. }
  1360. for (i = 0; passthrough_attrib_attrs[i] != NULL; i++) {
  1361. len += sizeof(struct configfs_attribute *);
  1362. }
  1363. len += sizeof(struct configfs_attribute *) * 2;
  1364. tcmu_attrs = kzalloc(len, GFP_KERNEL);
  1365. if (!tcmu_attrs) {
  1366. ret = -ENOMEM;
  1367. goto out_unreg_genl;
  1368. }
  1369. for (i = 0; passthrough_attrib_attrs[i] != NULL; i++) {
  1370. tcmu_attrs[i] = passthrough_attrib_attrs[i];
  1371. }
  1372. tcmu_attrs[i] = &tcmu_attr_cmd_time_out;
  1373. tcmu_ops.tb_dev_attrib_attrs = tcmu_attrs;
  1374. ret = transport_backend_register(&tcmu_ops);
  1375. if (ret)
  1376. goto out_attrs;
  1377. init_waitqueue_head(&unmap_wait);
  1378. unmap_thread = kthread_run(unmap_thread_fn, NULL, "tcmu_unmap");
  1379. if (IS_ERR(unmap_thread)) {
  1380. ret = PTR_ERR(unmap_thread);
  1381. goto out_unreg_transport;
  1382. }
  1383. return 0;
  1384. out_unreg_transport:
  1385. target_backend_unregister(&tcmu_ops);
  1386. out_attrs:
  1387. kfree(tcmu_attrs);
  1388. out_unreg_genl:
  1389. genl_unregister_family(&tcmu_genl_family);
  1390. out_unreg_device:
  1391. root_device_unregister(tcmu_root_device);
  1392. out_free_cache:
  1393. kmem_cache_destroy(tcmu_cmd_cache);
  1394. return ret;
  1395. }
  1396. static void __exit tcmu_module_exit(void)
  1397. {
  1398. kthread_stop(unmap_thread);
  1399. target_backend_unregister(&tcmu_ops);
  1400. kfree(tcmu_attrs);
  1401. genl_unregister_family(&tcmu_genl_family);
  1402. root_device_unregister(tcmu_root_device);
  1403. kmem_cache_destroy(tcmu_cmd_cache);
  1404. }
  1405. MODULE_DESCRIPTION("TCM USER subsystem plugin");
  1406. MODULE_AUTHOR("Shaohua Li <shli@kernel.org>");
  1407. MODULE_AUTHOR("Andy Grover <agrover@redhat.com>");
  1408. MODULE_LICENSE("GPL");
  1409. module_init(tcmu_module_init);
  1410. module_exit(tcmu_module_exit);