xref: /freebsd/sys/dev/mlx4/mlx4_ib/mlx4_ib_mcg.c (revision fd5e3f3ec6c6248e892c9e7b2f17da3bfe7b6837)
1 /*
2  * Copyright (c) 2012 Mellanox Technologies. All rights reserved.
3  *
4  * This software is available to you under a choice of one of two
5  * licenses.  You may choose to be licensed under the terms of the GNU
6  * General Public License (GPL) Version 2, available from the file
7  * COPYING in the main directory of this source tree, or the
8  * OpenIB.org BSD license below:
9  *
10  *     Redistribution and use in source and binary forms, with or
11  *     without modification, are permitted provided that the following
12  *     conditions are met:
13  *
14  *      - Redistributions of source code must retain the above
15  *        copyright notice, this list of conditions and the following
16  *        disclaimer.
17  *
18  *      - Redistributions in binary form must reproduce the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer in the documentation and/or other materials
21  *        provided with the distribution.
22  *
23  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
24  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
25  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
26  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
27  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
28  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
29  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30  * SOFTWARE.
31  */
32 
33 #include <rdma/ib_mad.h>
34 #include <rdma/ib_smi.h>
35 #include <rdma/ib_cache.h>
36 #include <rdma/ib_sa.h>
37 
38 #include <dev/mlx4/cmd.h>
39 #include <linux/rbtree.h>
40 #include <linux/delay.h>
41 
42 #include "mlx4_ib.h"
43 
44 #define MAX_VFS		80
45 #define MAX_PEND_REQS_PER_FUNC 4
46 #define MAD_TIMEOUT_MS	2000
47 
48 #define mcg_warn(fmt, arg...)	pr_warn("MCG WARNING: " fmt, ##arg)
49 #define mcg_error(fmt, arg...)	pr_err(fmt, ##arg)
50 #define mcg_warn_group(group, format, arg...) \
51 	pr_warn("%s-%d: %16s (port %d): WARNING: " format, __func__, __LINE__,\
52 	(group)->name, group->demux->port, ## arg)
53 
54 #define mcg_error_group(group, format, arg...) \
55 	pr_err("  %16s: " format, (group)->name, ## arg)
56 
57 
58 static union ib_gid mgid0;
59 
60 static struct workqueue_struct *clean_wq;
61 
62 enum mcast_state {
63 	MCAST_NOT_MEMBER = 0,
64 	MCAST_MEMBER,
65 };
66 
67 enum mcast_group_state {
68 	MCAST_IDLE,
69 	MCAST_JOIN_SENT,
70 	MCAST_LEAVE_SENT,
71 	MCAST_RESP_READY
72 };
73 
74 struct mcast_member {
75 	enum mcast_state state;
76 	uint8_t			join_state;
77 	int			num_pend_reqs;
78 	struct list_head	pending;
79 };
80 
81 struct ib_sa_mcmember_data {
82 	union ib_gid	mgid;
83 	union ib_gid	port_gid;
84 	__be32		qkey;
85 	__be16		mlid;
86 	u8		mtusel_mtu;
87 	u8		tclass;
88 	__be16		pkey;
89 	u8		ratesel_rate;
90 	u8		lifetmsel_lifetm;
91 	__be32		sl_flowlabel_hoplimit;
92 	u8		scope_join_state;
93 	u8		proxy_join;
94 	u8		reserved[2];
95 };
96 
97 struct mcast_group {
98 	struct ib_sa_mcmember_data rec;
99 	struct rb_node		node;
100 	struct list_head	mgid0_list;
101 	struct mlx4_ib_demux_ctx *demux;
102 	struct mcast_member	func[MAX_VFS];
103 	struct mutex		lock;
104 	struct work_struct	work;
105 	struct list_head	pending_list;
106 	int			members[3];
107 	enum mcast_group_state	state;
108 	enum mcast_group_state	prev_state;
109 	struct ib_sa_mad	response_sa_mad;
110 	__be64			last_req_tid;
111 
112 	char			name[33]; /* MGID string */
113 	struct device_attribute	dentry;
114 
115 	/* refcount is the reference count for the following:
116 	   1. Each queued request
117 	   2. Each invocation of the worker thread
118 	   3. Membership of the port at the SA
119 	*/
120 	atomic_t		refcount;
121 
122 	/* delayed work to clean pending SM request */
123 	struct delayed_work	timeout_work;
124 	struct list_head	cleanup_list;
125 };
126 
127 struct mcast_req {
128 	int			func;
129 	struct ib_sa_mad	sa_mad;
130 	struct list_head	group_list;
131 	struct list_head	func_list;
132 	struct mcast_group	*group;
133 	int			clean;
134 };
135 
136 
137 #define safe_atomic_dec(ref) \
138 	do {\
139 		if (atomic_dec_and_test(ref)) \
140 			mcg_warn_group(group, "did not expect to reach zero\n"); \
141 	} while (0)
142 
143 static const char *get_state_string(enum mcast_group_state state)
144 {
145 	switch (state) {
146 	case MCAST_IDLE:
147 		return "MCAST_IDLE";
148 	case MCAST_JOIN_SENT:
149 		return "MCAST_JOIN_SENT";
150 	case MCAST_LEAVE_SENT:
151 		return "MCAST_LEAVE_SENT";
152 	case MCAST_RESP_READY:
153 		return "MCAST_RESP_READY";
154 	}
155 	return "Invalid State";
156 }
157 
158 static struct mcast_group *mcast_find(struct mlx4_ib_demux_ctx *ctx,
159 				      union ib_gid *mgid)
160 {
161 	struct rb_node *node = ctx->mcg_table.rb_node;
162 	struct mcast_group *group;
163 	int ret;
164 
165 	while (node) {
166 		group = rb_entry(node, struct mcast_group, node);
167 		ret = memcmp(mgid->raw, group->rec.mgid.raw, sizeof *mgid);
168 		if (!ret)
169 			return group;
170 
171 		if (ret < 0)
172 			node = node->rb_left;
173 		else
174 			node = node->rb_right;
175 	}
176 	return NULL;
177 }
178 
179 static struct mcast_group *mcast_insert(struct mlx4_ib_demux_ctx *ctx,
180 					struct mcast_group *group)
181 {
182 	struct rb_node **link = &ctx->mcg_table.rb_node;
183 	struct rb_node *parent = NULL;
184 	struct mcast_group *cur_group;
185 	int ret;
186 
187 	while (*link) {
188 		parent = *link;
189 		cur_group = rb_entry(parent, struct mcast_group, node);
190 
191 		ret = memcmp(group->rec.mgid.raw, cur_group->rec.mgid.raw,
192 			     sizeof group->rec.mgid);
193 		if (ret < 0)
194 			link = &(*link)->rb_left;
195 		else if (ret > 0)
196 			link = &(*link)->rb_right;
197 		else
198 			return cur_group;
199 	}
200 	rb_link_node(&group->node, parent, link);
201 	rb_insert_color(&group->node, &ctx->mcg_table);
202 	return NULL;
203 }
204 
205 static int send_mad_to_wire(struct mlx4_ib_demux_ctx *ctx, struct ib_mad *mad)
206 {
207 	struct mlx4_ib_dev *dev = ctx->dev;
208 	struct ib_ah_attr	ah_attr;
209 
210 	spin_lock(&dev->sm_lock);
211 	if (!dev->sm_ah[ctx->port - 1]) {
212 		/* port is not yet Active, sm_ah not ready */
213 		spin_unlock(&dev->sm_lock);
214 		return -EAGAIN;
215 	}
216 	mlx4_ib_query_ah(dev->sm_ah[ctx->port - 1], &ah_attr);
217 	spin_unlock(&dev->sm_lock);
218 	return mlx4_ib_send_to_wire(dev, mlx4_master_func_num(dev->dev), ctx->port,
219 				    IB_QPT_GSI, 0, 1, IB_QP1_QKEY, &ah_attr, 0, mad);
220 }
221 
222 static int send_mad_to_slave(int slave, struct mlx4_ib_demux_ctx *ctx,
223 			     struct ib_mad *mad)
224 {
225 	struct mlx4_ib_dev *dev = ctx->dev;
226 	struct ib_mad_agent *agent = dev->send_agent[ctx->port - 1][1];
227 	struct ib_wc wc;
228 	struct ib_ah_attr ah_attr;
229 
230 	/* Our agent might not yet be registered when mads start to arrive */
231 	if (!agent)
232 		return -EAGAIN;
233 
234 	ib_query_ah(dev->sm_ah[ctx->port - 1], &ah_attr);
235 
236 	if (ib_find_cached_pkey(&dev->ib_dev, ctx->port, IB_DEFAULT_PKEY_FULL, &wc.pkey_index))
237 		return -EINVAL;
238 	wc.sl = 0;
239 	wc.dlid_path_bits = 0;
240 	wc.port_num = ctx->port;
241 	wc.slid = ah_attr.dlid;  /* opensm lid */
242 	wc.src_qp = 1;
243 	return mlx4_ib_send_to_slave(dev, slave, ctx->port, IB_QPT_GSI, &wc, NULL, mad);
244 }
245 
246 static int send_join_to_wire(struct mcast_group *group, struct ib_sa_mad *sa_mad)
247 {
248 	struct ib_sa_mad mad;
249 	struct ib_sa_mcmember_data *sa_mad_data = (struct ib_sa_mcmember_data *)&mad.data;
250 	int ret;
251 
252 	/* we rely on a mad request as arrived from a VF */
253 	memcpy(&mad, sa_mad, sizeof mad);
254 
255 	/* fix port GID to be the real one (slave 0) */
256 	sa_mad_data->port_gid.global.interface_id = group->demux->guid_cache[0];
257 
258 	/* assign our own TID */
259 	mad.mad_hdr.tid = mlx4_ib_get_new_demux_tid(group->demux);
260 	group->last_req_tid = mad.mad_hdr.tid; /* keep it for later validation */
261 
262 	ret = send_mad_to_wire(group->demux, (struct ib_mad *)&mad);
263 	/* set timeout handler */
264 	if (!ret) {
265 		/* calls mlx4_ib_mcg_timeout_handler */
266 		queue_delayed_work(group->demux->mcg_wq, &group->timeout_work,
267 				msecs_to_jiffies(MAD_TIMEOUT_MS));
268 	}
269 
270 	return ret;
271 }
272 
273 static int send_leave_to_wire(struct mcast_group *group, u8 join_state)
274 {
275 	struct ib_sa_mad mad;
276 	struct ib_sa_mcmember_data *sa_data = (struct ib_sa_mcmember_data *)&mad.data;
277 	int ret;
278 
279 	memset(&mad, 0, sizeof mad);
280 	mad.mad_hdr.base_version = 1;
281 	mad.mad_hdr.mgmt_class = IB_MGMT_CLASS_SUBN_ADM;
282 	mad.mad_hdr.class_version = 2;
283 	mad.mad_hdr.method = IB_SA_METHOD_DELETE;
284 	mad.mad_hdr.status = cpu_to_be16(0);
285 	mad.mad_hdr.class_specific = cpu_to_be16(0);
286 	mad.mad_hdr.tid = mlx4_ib_get_new_demux_tid(group->demux);
287 	group->last_req_tid = mad.mad_hdr.tid; /* keep it for later validation */
288 	mad.mad_hdr.attr_id = cpu_to_be16(IB_SA_ATTR_MC_MEMBER_REC);
289 	mad.mad_hdr.attr_mod = cpu_to_be32(0);
290 	mad.sa_hdr.sm_key = 0x0;
291 	mad.sa_hdr.attr_offset = cpu_to_be16(7);
292 	mad.sa_hdr.comp_mask = IB_SA_MCMEMBER_REC_MGID |
293 		IB_SA_MCMEMBER_REC_PORT_GID | IB_SA_MCMEMBER_REC_JOIN_STATE;
294 
295 	*sa_data = group->rec;
296 	sa_data->scope_join_state = join_state;
297 
298 	ret = send_mad_to_wire(group->demux, (struct ib_mad *)&mad);
299 	if (ret)
300 		group->state = MCAST_IDLE;
301 
302 	/* set timeout handler */
303 	if (!ret) {
304 		/* calls mlx4_ib_mcg_timeout_handler */
305 		queue_delayed_work(group->demux->mcg_wq, &group->timeout_work,
306 				msecs_to_jiffies(MAD_TIMEOUT_MS));
307 	}
308 
309 	return ret;
310 }
311 
312 static int send_reply_to_slave(int slave, struct mcast_group *group,
313 		struct ib_sa_mad *req_sa_mad, u16 status)
314 {
315 	struct ib_sa_mad mad;
316 	struct ib_sa_mcmember_data *sa_data = (struct ib_sa_mcmember_data *)&mad.data;
317 	struct ib_sa_mcmember_data *req_sa_data = (struct ib_sa_mcmember_data *)&req_sa_mad->data;
318 	int ret;
319 
320 	memset(&mad, 0, sizeof mad);
321 	mad.mad_hdr.base_version = 1;
322 	mad.mad_hdr.mgmt_class = IB_MGMT_CLASS_SUBN_ADM;
323 	mad.mad_hdr.class_version = 2;
324 	mad.mad_hdr.method = IB_MGMT_METHOD_GET_RESP;
325 	mad.mad_hdr.status = cpu_to_be16(status);
326 	mad.mad_hdr.class_specific = cpu_to_be16(0);
327 	mad.mad_hdr.tid = req_sa_mad->mad_hdr.tid;
328 	*(u8 *)&mad.mad_hdr.tid = 0; /* resetting tid to 0 */
329 	mad.mad_hdr.attr_id = cpu_to_be16(IB_SA_ATTR_MC_MEMBER_REC);
330 	mad.mad_hdr.attr_mod = cpu_to_be32(0);
331 	mad.sa_hdr.sm_key = req_sa_mad->sa_hdr.sm_key;
332 	mad.sa_hdr.attr_offset = cpu_to_be16(7);
333 	mad.sa_hdr.comp_mask = 0; /* ignored on responses, see IBTA spec */
334 
335 	*sa_data = group->rec;
336 
337 	/* reconstruct VF's requested join_state and port_gid */
338 	sa_data->scope_join_state &= 0xf0;
339 	sa_data->scope_join_state |= (group->func[slave].join_state & 0x0f);
340 	memcpy(&sa_data->port_gid, &req_sa_data->port_gid, sizeof req_sa_data->port_gid);
341 
342 	ret = send_mad_to_slave(slave, group->demux, (struct ib_mad *)&mad);
343 	return ret;
344 }
345 
346 static int check_selector(ib_sa_comp_mask comp_mask,
347 			  ib_sa_comp_mask selector_mask,
348 			  ib_sa_comp_mask value_mask,
349 			  u8 src_value, u8 dst_value)
350 {
351 	int err;
352 	u8 selector = dst_value >> 6;
353 	dst_value &= 0x3f;
354 	src_value &= 0x3f;
355 
356 	if (!(comp_mask & selector_mask) || !(comp_mask & value_mask))
357 		return 0;
358 
359 	switch (selector) {
360 	case IB_SA_GT:
361 		err = (src_value <= dst_value);
362 		break;
363 	case IB_SA_LT:
364 		err = (src_value >= dst_value);
365 		break;
366 	case IB_SA_EQ:
367 		err = (src_value != dst_value);
368 		break;
369 	default:
370 		err = 0;
371 		break;
372 	}
373 
374 	return err;
375 }
376 
377 static u16 cmp_rec(struct ib_sa_mcmember_data *src,
378 		   struct ib_sa_mcmember_data *dst, ib_sa_comp_mask comp_mask)
379 {
380 	/* src is group record, dst is request record */
381 	/* MGID must already match */
382 	/* Port_GID we always replace to our Port_GID, so it is a match */
383 
384 #define MAD_STATUS_REQ_INVALID 0x0200
385 	if (comp_mask & IB_SA_MCMEMBER_REC_QKEY && src->qkey != dst->qkey)
386 		return MAD_STATUS_REQ_INVALID;
387 	if (comp_mask & IB_SA_MCMEMBER_REC_MLID && src->mlid != dst->mlid)
388 		return MAD_STATUS_REQ_INVALID;
389 	if (check_selector(comp_mask, IB_SA_MCMEMBER_REC_MTU_SELECTOR,
390 				 IB_SA_MCMEMBER_REC_MTU,
391 				 src->mtusel_mtu, dst->mtusel_mtu))
392 		return MAD_STATUS_REQ_INVALID;
393 	if (comp_mask & IB_SA_MCMEMBER_REC_TRAFFIC_CLASS &&
394 	    src->tclass != dst->tclass)
395 		return MAD_STATUS_REQ_INVALID;
396 	if (comp_mask & IB_SA_MCMEMBER_REC_PKEY && src->pkey != dst->pkey)
397 		return MAD_STATUS_REQ_INVALID;
398 	if (check_selector(comp_mask, IB_SA_MCMEMBER_REC_RATE_SELECTOR,
399 				 IB_SA_MCMEMBER_REC_RATE,
400 				 src->ratesel_rate, dst->ratesel_rate))
401 		return MAD_STATUS_REQ_INVALID;
402 	if (check_selector(comp_mask,
403 				 IB_SA_MCMEMBER_REC_PACKET_LIFE_TIME_SELECTOR,
404 				 IB_SA_MCMEMBER_REC_PACKET_LIFE_TIME,
405 				 src->lifetmsel_lifetm, dst->lifetmsel_lifetm))
406 		return MAD_STATUS_REQ_INVALID;
407 	if (comp_mask & IB_SA_MCMEMBER_REC_SL &&
408 			(be32_to_cpu(src->sl_flowlabel_hoplimit) & 0xf0000000) !=
409 			(be32_to_cpu(dst->sl_flowlabel_hoplimit) & 0xf0000000))
410 		return MAD_STATUS_REQ_INVALID;
411 	if (comp_mask & IB_SA_MCMEMBER_REC_FLOW_LABEL &&
412 			(be32_to_cpu(src->sl_flowlabel_hoplimit) & 0x0fffff00) !=
413 			(be32_to_cpu(dst->sl_flowlabel_hoplimit) & 0x0fffff00))
414 		return MAD_STATUS_REQ_INVALID;
415 	if (comp_mask & IB_SA_MCMEMBER_REC_HOP_LIMIT &&
416 			(be32_to_cpu(src->sl_flowlabel_hoplimit) & 0x000000ff) !=
417 			(be32_to_cpu(dst->sl_flowlabel_hoplimit) & 0x000000ff))
418 		return MAD_STATUS_REQ_INVALID;
419 	if (comp_mask & IB_SA_MCMEMBER_REC_SCOPE &&
420 			(src->scope_join_state & 0xf0) !=
421 			(dst->scope_join_state & 0xf0))
422 		return MAD_STATUS_REQ_INVALID;
423 
424 	/* join_state checked separately, proxy_join ignored */
425 
426 	return 0;
427 }
428 
429 /* release group, return 1 if this was last release and group is destroyed
430  * timout work is canceled sync */
431 static int release_group(struct mcast_group *group, int from_timeout_handler)
432 {
433 	struct mlx4_ib_demux_ctx *ctx = group->demux;
434 	int nzgroup;
435 
436 	mutex_lock(&ctx->mcg_table_lock);
437 	mutex_lock(&group->lock);
438 	if (atomic_dec_and_test(&group->refcount)) {
439 		if (!from_timeout_handler) {
440 			if (group->state != MCAST_IDLE &&
441 			    !cancel_delayed_work(&group->timeout_work)) {
442 				atomic_inc(&group->refcount);
443 				mutex_unlock(&group->lock);
444 				mutex_unlock(&ctx->mcg_table_lock);
445 				return 0;
446 			}
447 		}
448 
449 		nzgroup = memcmp(&group->rec.mgid, &mgid0, sizeof mgid0);
450 		if (nzgroup)
451 			del_sysfs_port_mcg_attr(ctx->dev, ctx->port, &group->dentry.attr);
452 		if (!list_empty(&group->pending_list))
453 			mcg_warn_group(group, "releasing a group with non empty pending list\n");
454 		if (nzgroup)
455 			rb_erase(&group->node, &ctx->mcg_table);
456 		list_del_init(&group->mgid0_list);
457 		mutex_unlock(&group->lock);
458 		mutex_unlock(&ctx->mcg_table_lock);
459 		kfree(group);
460 		return 1;
461 	} else {
462 		mutex_unlock(&group->lock);
463 		mutex_unlock(&ctx->mcg_table_lock);
464 	}
465 	return 0;
466 }
467 
468 static void adjust_membership(struct mcast_group *group, u8 join_state, int inc)
469 {
470 	int i;
471 
472 	for (i = 0; i < 3; i++, join_state >>= 1)
473 		if (join_state & 0x1)
474 			group->members[i] += inc;
475 }
476 
477 static u8 get_leave_state(struct mcast_group *group)
478 {
479 	u8 leave_state = 0;
480 	int i;
481 
482 	for (i = 0; i < 3; i++)
483 		if (!group->members[i])
484 			leave_state |= (1 << i);
485 
486 	return leave_state & (group->rec.scope_join_state & 7);
487 }
488 
489 static int join_group(struct mcast_group *group, int slave, u8 join_mask)
490 {
491 	int ret = 0;
492 	u8 join_state;
493 
494 	/* remove bits that slave is already member of, and adjust */
495 	join_state = join_mask & (~group->func[slave].join_state);
496 	adjust_membership(group, join_state, 1);
497 	group->func[slave].join_state |= join_state;
498 	if (group->func[slave].state != MCAST_MEMBER && join_state) {
499 		group->func[slave].state = MCAST_MEMBER;
500 		ret = 1;
501 	}
502 	return ret;
503 }
504 
505 static int leave_group(struct mcast_group *group, int slave, u8 leave_state)
506 {
507 	int ret = 0;
508 
509 	adjust_membership(group, leave_state, -1);
510 	group->func[slave].join_state &= ~leave_state;
511 	if (!group->func[slave].join_state) {
512 		group->func[slave].state = MCAST_NOT_MEMBER;
513 		ret = 1;
514 	}
515 	return ret;
516 }
517 
518 static int check_leave(struct mcast_group *group, int slave, u8 leave_mask)
519 {
520 	if (group->func[slave].state != MCAST_MEMBER)
521 		return MAD_STATUS_REQ_INVALID;
522 
523 	/* make sure we're not deleting unset bits */
524 	if (~group->func[slave].join_state & leave_mask)
525 		return MAD_STATUS_REQ_INVALID;
526 
527 	if (!leave_mask)
528 		return MAD_STATUS_REQ_INVALID;
529 
530 	return 0;
531 }
532 
533 static void mlx4_ib_mcg_timeout_handler(struct work_struct *work)
534 {
535 	struct delayed_work *delay = to_delayed_work(work);
536 	struct mcast_group *group;
537 	struct mcast_req *req = NULL;
538 
539 	group = container_of(delay, typeof(*group), timeout_work);
540 
541 	mutex_lock(&group->lock);
542 	if (group->state == MCAST_JOIN_SENT) {
543 		if (!list_empty(&group->pending_list)) {
544 			req = list_first_entry(&group->pending_list, struct mcast_req, group_list);
545 			list_del(&req->group_list);
546 			list_del(&req->func_list);
547 			--group->func[req->func].num_pend_reqs;
548 			mutex_unlock(&group->lock);
549 			kfree(req);
550 			if (memcmp(&group->rec.mgid, &mgid0, sizeof mgid0)) {
551 				if (release_group(group, 1))
552 					return;
553 			} else {
554 				kfree(group);
555 				return;
556 			}
557 			mutex_lock(&group->lock);
558 		} else
559 			mcg_warn_group(group, "DRIVER BUG\n");
560 	} else if (group->state == MCAST_LEAVE_SENT) {
561 		if (group->rec.scope_join_state & 7)
562 			group->rec.scope_join_state &= 0xf8;
563 		group->state = MCAST_IDLE;
564 		mutex_unlock(&group->lock);
565 		if (release_group(group, 1))
566 			return;
567 		mutex_lock(&group->lock);
568 	} else
569 		mcg_warn_group(group, "invalid state %s\n", get_state_string(group->state));
570 	group->state = MCAST_IDLE;
571 	atomic_inc(&group->refcount);
572 	if (!queue_work(group->demux->mcg_wq, &group->work))
573 		safe_atomic_dec(&group->refcount);
574 
575 	mutex_unlock(&group->lock);
576 }
577 
578 static int handle_leave_req(struct mcast_group *group, u8 leave_mask,
579 			    struct mcast_req *req)
580 {
581 	u16 status;
582 
583 	if (req->clean)
584 		leave_mask = group->func[req->func].join_state;
585 
586 	status = check_leave(group, req->func, leave_mask);
587 	if (!status)
588 		leave_group(group, req->func, leave_mask);
589 
590 	if (!req->clean)
591 		send_reply_to_slave(req->func, group, &req->sa_mad, status);
592 	--group->func[req->func].num_pend_reqs;
593 	list_del(&req->group_list);
594 	list_del(&req->func_list);
595 	kfree(req);
596 	return 1;
597 }
598 
599 static int handle_join_req(struct mcast_group *group, u8 join_mask,
600 			   struct mcast_req *req)
601 {
602 	u8 group_join_state = group->rec.scope_join_state & 7;
603 	int ref = 0;
604 	u16 status;
605 	struct ib_sa_mcmember_data *sa_data = (struct ib_sa_mcmember_data *)req->sa_mad.data;
606 
607 	if (join_mask == (group_join_state & join_mask)) {
608 		/* port's membership need not change */
609 		status = cmp_rec(&group->rec, sa_data, req->sa_mad.sa_hdr.comp_mask);
610 		if (!status)
611 			join_group(group, req->func, join_mask);
612 
613 		--group->func[req->func].num_pend_reqs;
614 		send_reply_to_slave(req->func, group, &req->sa_mad, status);
615 		list_del(&req->group_list);
616 		list_del(&req->func_list);
617 		kfree(req);
618 		++ref;
619 	} else {
620 		/* port's membership needs to be updated */
621 		group->prev_state = group->state;
622 		if (send_join_to_wire(group, &req->sa_mad)) {
623 			--group->func[req->func].num_pend_reqs;
624 			list_del(&req->group_list);
625 			list_del(&req->func_list);
626 			kfree(req);
627 			ref = 1;
628 			group->state = group->prev_state;
629 		} else
630 			group->state = MCAST_JOIN_SENT;
631 	}
632 
633 	return ref;
634 }
635 
636 static void mlx4_ib_mcg_work_handler(struct work_struct *work)
637 {
638 	struct mcast_group *group;
639 	struct mcast_req *req = NULL;
640 	struct ib_sa_mcmember_data *sa_data;
641 	u8 req_join_state;
642 	int rc = 1; /* release_count - this is for the scheduled work */
643 	u16 status;
644 	u8 method;
645 
646 	group = container_of(work, typeof(*group), work);
647 
648 	mutex_lock(&group->lock);
649 
650 	/* First, let's see if a response from SM is waiting regarding this group.
651 	 * If so, we need to update the group's REC. If this is a bad response, we
652 	 * may need to send a bad response to a VF waiting for it. If VF is waiting
653 	 * and this is a good response, the VF will be answered later in this func. */
654 	if (group->state == MCAST_RESP_READY) {
655 		/* cancels mlx4_ib_mcg_timeout_handler */
656 		cancel_delayed_work(&group->timeout_work);
657 		status = be16_to_cpu(group->response_sa_mad.mad_hdr.status);
658 		method = group->response_sa_mad.mad_hdr.method;
659 		if (group->last_req_tid != group->response_sa_mad.mad_hdr.tid) {
660 			mcg_warn_group(group, "Got MAD response to existing MGID but wrong TID, dropping. Resp TID=%llx, group TID=%llx\n",
661 				(long long)be64_to_cpu(
662 				    group->response_sa_mad.mad_hdr.tid),
663 				(long long)be64_to_cpu(group->last_req_tid));
664 			group->state = group->prev_state;
665 			goto process_requests;
666 		}
667 		if (status) {
668 			if (!list_empty(&group->pending_list))
669 				req = list_first_entry(&group->pending_list,
670 						struct mcast_req, group_list);
671 			if (method == IB_MGMT_METHOD_GET_RESP) {
672 					if (req) {
673 						send_reply_to_slave(req->func, group, &req->sa_mad, status);
674 						--group->func[req->func].num_pend_reqs;
675 						list_del(&req->group_list);
676 						list_del(&req->func_list);
677 						kfree(req);
678 						++rc;
679 					} else
680 						mcg_warn_group(group, "no request for failed join\n");
681 			} else if (method == IB_SA_METHOD_DELETE_RESP && group->demux->flushing)
682 				++rc;
683 		} else {
684 			u8 resp_join_state;
685 			u8 cur_join_state;
686 
687 			resp_join_state = ((struct ib_sa_mcmember_data *)
688 						group->response_sa_mad.data)->scope_join_state & 7;
689 			cur_join_state = group->rec.scope_join_state & 7;
690 
691 			if (method == IB_MGMT_METHOD_GET_RESP) {
692 				/* successful join */
693 				if (!cur_join_state && resp_join_state)
694 					--rc;
695 			} else if (!resp_join_state)
696 					++rc;
697 			memcpy(&group->rec, group->response_sa_mad.data, sizeof group->rec);
698 		}
699 		group->state = MCAST_IDLE;
700 	}
701 
702 process_requests:
703 	/* We should now go over pending join/leave requests, as long as we are idle. */
704 	while (!list_empty(&group->pending_list) && group->state == MCAST_IDLE) {
705 		req = list_first_entry(&group->pending_list, struct mcast_req,
706 				       group_list);
707 		sa_data = (struct ib_sa_mcmember_data *)req->sa_mad.data;
708 		req_join_state = sa_data->scope_join_state & 0x7;
709 
710 		/* For a leave request, we will immediately answer the VF, and
711 		 * update our internal counters. The actual leave will be sent
712 		 * to SM later, if at all needed. We dequeue the request now. */
713 		if (req->sa_mad.mad_hdr.method == IB_SA_METHOD_DELETE)
714 			rc += handle_leave_req(group, req_join_state, req);
715 		else
716 			rc += handle_join_req(group, req_join_state, req);
717 	}
718 
719 	/* Handle leaves */
720 	if (group->state == MCAST_IDLE) {
721 		req_join_state = get_leave_state(group);
722 		if (req_join_state) {
723 			group->rec.scope_join_state &= ~req_join_state;
724 			group->prev_state = group->state;
725 			if (send_leave_to_wire(group, req_join_state)) {
726 				group->state = group->prev_state;
727 				++rc;
728 			} else
729 				group->state = MCAST_LEAVE_SENT;
730 		}
731 	}
732 
733 	if (!list_empty(&group->pending_list) && group->state == MCAST_IDLE)
734 		goto process_requests;
735 	mutex_unlock(&group->lock);
736 
737 	while (rc--)
738 		release_group(group, 0);
739 }
740 
741 static struct mcast_group *search_relocate_mgid0_group(struct mlx4_ib_demux_ctx *ctx,
742 						       __be64 tid,
743 						       union ib_gid *new_mgid)
744 {
745 	struct mcast_group *group = NULL, *cur_group;
746 	struct mcast_req *req;
747 	struct list_head *pos;
748 	struct list_head *n;
749 
750 	mutex_lock(&ctx->mcg_table_lock);
751 	list_for_each_safe(pos, n, &ctx->mcg_mgid0_list) {
752 		group = list_entry(pos, struct mcast_group, mgid0_list);
753 		mutex_lock(&group->lock);
754 		if (group->last_req_tid == tid) {
755 			if (memcmp(new_mgid, &mgid0, sizeof mgid0)) {
756 				group->rec.mgid = *new_mgid;
757 				sprintf(group->name, "%016llx%016llx",
758 						(long long)be64_to_cpu(group->rec.mgid.global.subnet_prefix),
759 						(long long)be64_to_cpu(group->rec.mgid.global.interface_id));
760 				list_del_init(&group->mgid0_list);
761 				cur_group = mcast_insert(ctx, group);
762 				if (cur_group) {
763 					/* A race between our code and SM. Silently cleaning the new one */
764 					req = list_first_entry(&group->pending_list,
765 							       struct mcast_req, group_list);
766 					--group->func[req->func].num_pend_reqs;
767 					list_del(&req->group_list);
768 					list_del(&req->func_list);
769 					kfree(req);
770 					mutex_unlock(&group->lock);
771 					mutex_unlock(&ctx->mcg_table_lock);
772 					release_group(group, 0);
773 					return NULL;
774 				}
775 
776 				atomic_inc(&group->refcount);
777 				add_sysfs_port_mcg_attr(ctx->dev, ctx->port, &group->dentry.attr);
778 				mutex_unlock(&group->lock);
779 				mutex_unlock(&ctx->mcg_table_lock);
780 				return group;
781 			} else {
782 				struct mcast_req *tmp1, *tmp2;
783 
784 				list_del(&group->mgid0_list);
785 				if (!list_empty(&group->pending_list) && group->state != MCAST_IDLE)
786 					cancel_delayed_work_sync(&group->timeout_work);
787 
788 				list_for_each_entry_safe(tmp1, tmp2, &group->pending_list, group_list) {
789 					list_del(&tmp1->group_list);
790 					kfree(tmp1);
791 				}
792 				mutex_unlock(&group->lock);
793 				mutex_unlock(&ctx->mcg_table_lock);
794 				kfree(group);
795 				return NULL;
796 			}
797 		}
798 		mutex_unlock(&group->lock);
799 	}
800 	mutex_unlock(&ctx->mcg_table_lock);
801 
802 	return NULL;
803 }
804 
805 static ssize_t sysfs_show_group(struct device *dev,
806 		struct device_attribute *attr, char *buf);
807 
808 static struct mcast_group *acquire_group(struct mlx4_ib_demux_ctx *ctx,
809 					 union ib_gid *mgid, int create,
810 					 gfp_t gfp_mask)
811 {
812 	struct mcast_group *group, *cur_group;
813 	int is_mgid0;
814 	int i;
815 
816 	is_mgid0 = !memcmp(&mgid0, mgid, sizeof mgid0);
817 	if (!is_mgid0) {
818 		group = mcast_find(ctx, mgid);
819 		if (group)
820 			goto found;
821 	}
822 
823 	if (!create)
824 		return ERR_PTR(-ENOENT);
825 
826 	group = kzalloc(sizeof *group, gfp_mask);
827 	if (!group)
828 		return ERR_PTR(-ENOMEM);
829 
830 	group->demux = ctx;
831 	group->rec.mgid = *mgid;
832 	INIT_LIST_HEAD(&group->pending_list);
833 	INIT_LIST_HEAD(&group->mgid0_list);
834 	for (i = 0; i < MAX_VFS; ++i)
835 		INIT_LIST_HEAD(&group->func[i].pending);
836 	INIT_WORK(&group->work, mlx4_ib_mcg_work_handler);
837 	INIT_DELAYED_WORK(&group->timeout_work, mlx4_ib_mcg_timeout_handler);
838 	mutex_init(&group->lock);
839 	sprintf(group->name, "%016llx%016llx",
840 			(long long)be64_to_cpu(
841 			    group->rec.mgid.global.subnet_prefix),
842 			(long long)be64_to_cpu(
843 			    group->rec.mgid.global.interface_id));
844 	sysfs_attr_init(&group->dentry.attr);
845 	group->dentry.show = sysfs_show_group;
846 	group->dentry.store = NULL;
847 	group->dentry.attr.name = group->name;
848 	group->dentry.attr.mode = 0400;
849 	group->state = MCAST_IDLE;
850 
851 	if (is_mgid0) {
852 		list_add(&group->mgid0_list, &ctx->mcg_mgid0_list);
853 		goto found;
854 	}
855 
856 	cur_group = mcast_insert(ctx, group);
857 	if (cur_group) {
858 		mcg_warn("group just showed up %s - confused\n", cur_group->name);
859 		kfree(group);
860 		return ERR_PTR(-EINVAL);
861 	}
862 
863 	add_sysfs_port_mcg_attr(ctx->dev, ctx->port, &group->dentry.attr);
864 
865 found:
866 	atomic_inc(&group->refcount);
867 	return group;
868 }
869 
870 static void queue_req(struct mcast_req *req)
871 {
872 	struct mcast_group *group = req->group;
873 
874 	atomic_inc(&group->refcount); /* for the request */
875 	atomic_inc(&group->refcount); /* for scheduling the work */
876 	list_add_tail(&req->group_list, &group->pending_list);
877 	list_add_tail(&req->func_list, &group->func[req->func].pending);
878 	/* calls mlx4_ib_mcg_work_handler */
879 	if (!queue_work(group->demux->mcg_wq, &group->work))
880 		safe_atomic_dec(&group->refcount);
881 }
882 
883 int mlx4_ib_mcg_demux_handler(struct ib_device *ibdev, int port, int slave,
884 			      struct ib_sa_mad *mad)
885 {
886 	struct mlx4_ib_dev *dev = to_mdev(ibdev);
887 	struct ib_sa_mcmember_data *rec = (struct ib_sa_mcmember_data *)mad->data;
888 	struct mlx4_ib_demux_ctx *ctx = &dev->sriov.demux[port - 1];
889 	struct mcast_group *group;
890 
891 	switch (mad->mad_hdr.method) {
892 	case IB_MGMT_METHOD_GET_RESP:
893 	case IB_SA_METHOD_DELETE_RESP:
894 		mutex_lock(&ctx->mcg_table_lock);
895 		group = acquire_group(ctx, &rec->mgid, 0, GFP_KERNEL);
896 		mutex_unlock(&ctx->mcg_table_lock);
897 		if (IS_ERR(group)) {
898 			if (mad->mad_hdr.method == IB_MGMT_METHOD_GET_RESP) {
899 				__be64 tid = mad->mad_hdr.tid;
900 				*(u8 *)(&tid) = (u8)slave; /* in group we kept the modified TID */
901 				group = search_relocate_mgid0_group(ctx, tid, &rec->mgid);
902 			} else
903 				group = NULL;
904 		}
905 
906 		if (!group)
907 			return 1;
908 
909 		mutex_lock(&group->lock);
910 		group->response_sa_mad = *mad;
911 		group->prev_state = group->state;
912 		group->state = MCAST_RESP_READY;
913 		/* calls mlx4_ib_mcg_work_handler */
914 		atomic_inc(&group->refcount);
915 		if (!queue_work(ctx->mcg_wq, &group->work))
916 			safe_atomic_dec(&group->refcount);
917 		mutex_unlock(&group->lock);
918 		release_group(group, 0);
919 		return 1; /* consumed */
920 	case IB_MGMT_METHOD_SET:
921 	case IB_SA_METHOD_GET_TABLE:
922 	case IB_SA_METHOD_GET_TABLE_RESP:
923 	case IB_SA_METHOD_DELETE:
924 		return 0; /* not consumed, pass-through to guest over tunnel */
925 	default:
926 		mcg_warn("In demux, port %d: unexpected MCMember method: 0x%x, dropping\n",
927 			port, mad->mad_hdr.method);
928 		return 1; /* consumed */
929 	}
930 }
931 
932 int mlx4_ib_mcg_multiplex_handler(struct ib_device *ibdev, int port,
933 				  int slave, struct ib_sa_mad *sa_mad)
934 {
935 	struct mlx4_ib_dev *dev = to_mdev(ibdev);
936 	struct ib_sa_mcmember_data *rec = (struct ib_sa_mcmember_data *)sa_mad->data;
937 	struct mlx4_ib_demux_ctx *ctx = &dev->sriov.demux[port - 1];
938 	struct mcast_group *group;
939 	struct mcast_req *req;
940 	int may_create = 0;
941 
942 	if (ctx->flushing)
943 		return -EAGAIN;
944 
945 	switch (sa_mad->mad_hdr.method) {
946 	case IB_MGMT_METHOD_SET:
947 		may_create = 1;
948 	case IB_SA_METHOD_DELETE:
949 		req = kzalloc(sizeof *req, GFP_KERNEL);
950 		if (!req)
951 			return -ENOMEM;
952 
953 		req->func = slave;
954 		req->sa_mad = *sa_mad;
955 
956 		mutex_lock(&ctx->mcg_table_lock);
957 		group = acquire_group(ctx, &rec->mgid, may_create, GFP_KERNEL);
958 		mutex_unlock(&ctx->mcg_table_lock);
959 		if (IS_ERR(group)) {
960 			kfree(req);
961 			return PTR_ERR(group);
962 		}
963 		mutex_lock(&group->lock);
964 		if (group->func[slave].num_pend_reqs > MAX_PEND_REQS_PER_FUNC) {
965 			mutex_unlock(&group->lock);
966 			mcg_warn_group(group, "Port %d, Func %d has too many pending requests (%d), dropping\n",
967 				       port, slave, MAX_PEND_REQS_PER_FUNC);
968 			release_group(group, 0);
969 			kfree(req);
970 			return -ENOMEM;
971 		}
972 		++group->func[slave].num_pend_reqs;
973 		req->group = group;
974 		queue_req(req);
975 		mutex_unlock(&group->lock);
976 		release_group(group, 0);
977 		return 1; /* consumed */
978 	case IB_SA_METHOD_GET_TABLE:
979 	case IB_MGMT_METHOD_GET_RESP:
980 	case IB_SA_METHOD_GET_TABLE_RESP:
981 	case IB_SA_METHOD_DELETE_RESP:
982 		return 0; /* not consumed, pass-through */
983 	default:
984 		mcg_warn("In multiplex, port %d, func %d: unexpected MCMember method: 0x%x, dropping\n",
985 			port, slave, sa_mad->mad_hdr.method);
986 		return 1; /* consumed */
987 	}
988 }
989 
990 static ssize_t sysfs_show_group(struct device *dev,
991 		struct device_attribute *attr, char *buf)
992 {
993 	struct mcast_group *group =
994 		container_of(attr, struct mcast_group, dentry);
995 	struct mcast_req *req = NULL;
996 	char pending_str[40];
997 	char state_str[40];
998 	ssize_t len = 0;
999 	int f;
1000 
1001 	if (group->state == MCAST_IDLE)
1002 		sprintf(state_str, "%s", get_state_string(group->state));
1003 	else
1004 		sprintf(state_str, "%s(TID=0x%llx)",
1005 				get_state_string(group->state),
1006 				(long long)be64_to_cpu(group->last_req_tid));
1007 	if (list_empty(&group->pending_list)) {
1008 		sprintf(pending_str, "No");
1009 	} else {
1010 		req = list_first_entry(&group->pending_list, struct mcast_req, group_list);
1011 		sprintf(pending_str, "Yes(TID=0x%llx)",
1012 				(long long)be64_to_cpu(
1013 				    req->sa_mad.mad_hdr.tid));
1014 	}
1015 	len += sprintf(buf + len, "%1d [%02d,%02d,%02d] %4d %4s %5s     ",
1016 			group->rec.scope_join_state & 0xf,
1017 			group->members[2], group->members[1], group->members[0],
1018 			atomic_read(&group->refcount),
1019 			pending_str,
1020 			state_str);
1021 	for (f = 0; f < MAX_VFS; ++f)
1022 		if (group->func[f].state == MCAST_MEMBER)
1023 			len += sprintf(buf + len, "%d[%1x] ",
1024 					f, group->func[f].join_state);
1025 
1026 	len += sprintf(buf + len, "\t\t(%4hx %4x %2x %2x %2x %2x %2x "
1027 		"%4x %4x %2x %2x)\n",
1028 		be16_to_cpu(group->rec.pkey),
1029 		be32_to_cpu(group->rec.qkey),
1030 		(group->rec.mtusel_mtu & 0xc0) >> 6,
1031 		group->rec.mtusel_mtu & 0x3f,
1032 		group->rec.tclass,
1033 		(group->rec.ratesel_rate & 0xc0) >> 6,
1034 		group->rec.ratesel_rate & 0x3f,
1035 		(be32_to_cpu(group->rec.sl_flowlabel_hoplimit) & 0xf0000000) >> 28,
1036 		(be32_to_cpu(group->rec.sl_flowlabel_hoplimit) & 0x0fffff00) >> 8,
1037 		be32_to_cpu(group->rec.sl_flowlabel_hoplimit) & 0x000000ff,
1038 		group->rec.proxy_join);
1039 
1040 	return len;
1041 }
1042 
1043 int mlx4_ib_mcg_port_init(struct mlx4_ib_demux_ctx *ctx)
1044 {
1045 	char name[20];
1046 
1047 	atomic_set(&ctx->tid, 0);
1048 	sprintf(name, "mlx4_ib_mcg%d", ctx->port);
1049 	ctx->mcg_wq = create_singlethread_workqueue(name);
1050 	if (!ctx->mcg_wq)
1051 		return -ENOMEM;
1052 
1053 	mutex_init(&ctx->mcg_table_lock);
1054 	ctx->mcg_table = RB_ROOT;
1055 	INIT_LIST_HEAD(&ctx->mcg_mgid0_list);
1056 	ctx->flushing = 0;
1057 
1058 	return 0;
1059 }
1060 
1061 static void force_clean_group(struct mcast_group *group)
1062 {
1063 	struct mcast_req *req, *tmp
1064 		;
1065 	list_for_each_entry_safe(req, tmp, &group->pending_list, group_list) {
1066 		list_del(&req->group_list);
1067 		kfree(req);
1068 	}
1069 	del_sysfs_port_mcg_attr(group->demux->dev, group->demux->port, &group->dentry.attr);
1070 	rb_erase(&group->node, &group->demux->mcg_table);
1071 	kfree(group);
1072 }
1073 
1074 static void _mlx4_ib_mcg_port_cleanup(struct mlx4_ib_demux_ctx *ctx, int destroy_wq)
1075 {
1076 	int i;
1077 	struct rb_node *p;
1078 	struct mcast_group *group;
1079 	unsigned long end;
1080 	int count;
1081 
1082 	for (i = 0; i < MAX_VFS; ++i)
1083 		clean_vf_mcast(ctx, i);
1084 
1085 	end = jiffies + msecs_to_jiffies(MAD_TIMEOUT_MS + 3000);
1086 	do {
1087 		count = 0;
1088 		mutex_lock(&ctx->mcg_table_lock);
1089 		for (p = rb_first(&ctx->mcg_table); p; p = rb_next(p))
1090 			++count;
1091 		mutex_unlock(&ctx->mcg_table_lock);
1092 		if (!count)
1093 			break;
1094 
1095 		msleep(1);
1096 	} while (time_after(end, jiffies));
1097 
1098 	flush_workqueue(ctx->mcg_wq);
1099 	if (destroy_wq)
1100 		destroy_workqueue(ctx->mcg_wq);
1101 
1102 	mutex_lock(&ctx->mcg_table_lock);
1103 	while ((p = rb_first(&ctx->mcg_table)) != NULL) {
1104 		group = rb_entry(p, struct mcast_group, node);
1105 		if (atomic_read(&group->refcount))
1106 			mcg_warn_group(group, "group refcount %d!!! (pointer %p)\n", atomic_read(&group->refcount), group);
1107 
1108 		force_clean_group(group);
1109 	}
1110 	mutex_unlock(&ctx->mcg_table_lock);
1111 }
1112 
1113 struct clean_work {
1114 	struct work_struct work;
1115 	struct mlx4_ib_demux_ctx *ctx;
1116 	int destroy_wq;
1117 };
1118 
1119 static void mcg_clean_task(struct work_struct *work)
1120 {
1121 	struct clean_work *cw = container_of(work, struct clean_work, work);
1122 
1123 	_mlx4_ib_mcg_port_cleanup(cw->ctx, cw->destroy_wq);
1124 	cw->ctx->flushing = 0;
1125 	kfree(cw);
1126 }
1127 
1128 void mlx4_ib_mcg_port_cleanup(struct mlx4_ib_demux_ctx *ctx, int destroy_wq)
1129 {
1130 	struct clean_work *work;
1131 
1132 	if (ctx->flushing)
1133 		return;
1134 
1135 	ctx->flushing = 1;
1136 
1137 	if (destroy_wq) {
1138 		_mlx4_ib_mcg_port_cleanup(ctx, destroy_wq);
1139 		ctx->flushing = 0;
1140 		return;
1141 	}
1142 
1143 	work = kmalloc(sizeof *work, GFP_KERNEL);
1144 	if (!work) {
1145 		ctx->flushing = 0;
1146 		mcg_warn("failed allocating work for cleanup\n");
1147 		return;
1148 	}
1149 
1150 	work->ctx = ctx;
1151 	work->destroy_wq = destroy_wq;
1152 	INIT_WORK(&work->work, mcg_clean_task);
1153 	queue_work(clean_wq, &work->work);
1154 }
1155 
1156 static void build_leave_mad(struct mcast_req *req)
1157 {
1158 	struct ib_sa_mad *mad = &req->sa_mad;
1159 
1160 	mad->mad_hdr.method = IB_SA_METHOD_DELETE;
1161 }
1162 
1163 
1164 static void clear_pending_reqs(struct mcast_group *group, int vf)
1165 {
1166 	struct mcast_req *req, *tmp, *group_first = NULL;
1167 	int clear;
1168 	int pend = 0;
1169 
1170 	if (!list_empty(&group->pending_list))
1171 		group_first = list_first_entry(&group->pending_list, struct mcast_req, group_list);
1172 
1173 	list_for_each_entry_safe(req, tmp, &group->func[vf].pending, func_list) {
1174 		clear = 1;
1175 		if (group_first == req &&
1176 		    (group->state == MCAST_JOIN_SENT ||
1177 		     group->state == MCAST_LEAVE_SENT)) {
1178 			clear = cancel_delayed_work(&group->timeout_work);
1179 			pend = !clear;
1180 			group->state = MCAST_IDLE;
1181 		}
1182 		if (clear) {
1183 			--group->func[vf].num_pend_reqs;
1184 			list_del(&req->group_list);
1185 			list_del(&req->func_list);
1186 			kfree(req);
1187 			atomic_dec(&group->refcount);
1188 		}
1189 	}
1190 
1191 	if (!pend && (!list_empty(&group->func[vf].pending) || group->func[vf].num_pend_reqs)) {
1192 		mcg_warn_group(group, "DRIVER BUG: list_empty %d, num_pend_reqs %d\n",
1193 			       list_empty(&group->func[vf].pending), group->func[vf].num_pend_reqs);
1194 	}
1195 }
1196 
1197 static int push_deleteing_req(struct mcast_group *group, int slave)
1198 {
1199 	struct mcast_req *req;
1200 	struct mcast_req *pend_req;
1201 
1202 	if (!group->func[slave].join_state)
1203 		return 0;
1204 
1205 	req = kzalloc(sizeof *req, GFP_KERNEL);
1206 	if (!req) {
1207 		mcg_warn_group(group, "failed allocation - may leave stall groups\n");
1208 		return -ENOMEM;
1209 	}
1210 
1211 	if (!list_empty(&group->func[slave].pending)) {
1212 		pend_req = list_entry(group->func[slave].pending.prev, struct mcast_req, group_list);
1213 		if (pend_req->clean) {
1214 			kfree(req);
1215 			return 0;
1216 		}
1217 	}
1218 
1219 	req->clean = 1;
1220 	req->func = slave;
1221 	req->group = group;
1222 	++group->func[slave].num_pend_reqs;
1223 	build_leave_mad(req);
1224 	queue_req(req);
1225 	return 0;
1226 }
1227 
1228 void clean_vf_mcast(struct mlx4_ib_demux_ctx *ctx, int slave)
1229 {
1230 	struct mcast_group *group;
1231 	struct rb_node *p;
1232 
1233 	mutex_lock(&ctx->mcg_table_lock);
1234 	for (p = rb_first(&ctx->mcg_table); p; p = rb_next(p)) {
1235 		group = rb_entry(p, struct mcast_group, node);
1236 		mutex_lock(&group->lock);
1237 		if (atomic_read(&group->refcount)) {
1238 			/* clear pending requests of this VF */
1239 			clear_pending_reqs(group, slave);
1240 			push_deleteing_req(group, slave);
1241 		}
1242 		mutex_unlock(&group->lock);
1243 	}
1244 	mutex_unlock(&ctx->mcg_table_lock);
1245 }
1246 
1247 
1248 int mlx4_ib_mcg_init(void)
1249 {
1250 	clean_wq = create_singlethread_workqueue("mlx4_ib_mcg");
1251 	if (!clean_wq)
1252 		return -ENOMEM;
1253 
1254 	return 0;
1255 }
1256 
1257 void mlx4_ib_mcg_destroy(void)
1258 {
1259 	destroy_workqueue(clean_wq);
1260 }
1261