xref: /freebsd/usr.sbin/ctld/kernel.cc (revision 7be913e00d79b3bf740049797fbc3f6ab8193995)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause
3  *
4  * Copyright (c) 2003, 2004 Silicon Graphics International Corp.
5  * Copyright (c) 1997-2007 Kenneth D. Merry
6  * Copyright (c) 2012 The FreeBSD Foundation
7  * Copyright (c) 2017 Jakub Wojciech Klama <jceel@FreeBSD.org>
8  * All rights reserved.
9  *
10  * Portions of this software were developed by Edward Tomasz Napierala
11  * under sponsorship from the FreeBSD Foundation.
12  *
13  * Redistribution and use in source and binary forms, with or without
14  * modification, are permitted provided that the following conditions
15  * are met:
16  * 1. Redistributions of source code must retain the above copyright
17  *    notice, this list of conditions, and the following disclaimer,
18  *    without modification.
19  * 2. Redistributions in binary form must reproduce at minimum a disclaimer
20  *    substantially similar to the "NO WARRANTY" disclaimer below
21  *    ("Disclaimer") and any redistribution must be conditioned upon
22  *    including a substantially similar Disclaimer requirement for further
23  *    binary redistribution.
24  *
25  * NO WARRANTY
26  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
27  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
28  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR
29  * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
30  * HOLDERS OR CONTRIBUTORS BE LIABLE FOR SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
31  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
32  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
33  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
34  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING
35  * IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
36  * POSSIBILITY OF SUCH DAMAGES.
37  *
38  */
39 
40 #include <sys/param.h>
41 #include <sys/capsicum.h>
42 #include <sys/callout.h>
43 #include <sys/cnv.h>
44 #include <sys/ioctl.h>
45 #include <sys/linker.h>
46 #include <sys/module.h>
47 #include <sys/queue.h>
48 #include <sys/sbuf.h>
49 #include <sys/nv.h>
50 #include <sys/stat.h>
51 #include <assert.h>
52 #include <bsdxml.h>
53 #include <capsicum_helpers.h>
54 #include <ctype.h>
55 #include <errno.h>
56 #include <fcntl.h>
57 #include <stdint.h>
58 #include <stdio.h>
59 #include <stdlib.h>
60 #include <string.h>
61 #include <strings.h>
62 #include <cam/scsi/scsi_all.h>
63 #include <cam/scsi/scsi_message.h>
64 #include <cam/ctl/ctl.h>
65 #include <cam/ctl/ctl_io.h>
66 #include <cam/ctl/ctl_backend.h>
67 #include <cam/ctl/ctl_ioctl.h>
68 #include <cam/ctl/ctl_util.h>
69 #include <cam/ctl/ctl_scsi_all.h>
70 
71 #include "ctld.hh"
72 
73 #ifdef ICL_KERNEL_PROXY
74 #include <netdb.h>
75 #endif
76 
77 #define	NVLIST_BUFSIZE	1024
78 
79 extern bool proxy_mode;
80 
81 int	ctl_fd = 0;
82 
83 void
84 kernel_init(void)
85 {
86 	int retval, saved_errno;
87 
88 	ctl_fd = open(CTL_DEFAULT_DEV, O_RDWR);
89 	if (ctl_fd < 0 && errno == ENOENT) {
90 		saved_errno = errno;
91 		retval = kldload("ctl");
92 		if (retval != -1)
93 			ctl_fd = open(CTL_DEFAULT_DEV, O_RDWR);
94 		else
95 			errno = saved_errno;
96 	}
97 	if (ctl_fd < 0)
98 		log_err(1, "failed to open %s", CTL_DEFAULT_DEV);
99 #ifdef	WANT_ISCSI
100 	else {
101 		saved_errno = errno;
102 		if (modfind("cfiscsi") == -1 && kldload("cfiscsi") == -1)
103 			log_warn("couldn't load cfiscsi");
104 		errno = saved_errno;
105 	}
106 #endif
107 }
108 
109 /*
110  * Backend LUN information.
111  */
112 struct cctl_lun {
113 	uint64_t lun_id;
114 	char *backend_type;
115 	uint8_t device_type;
116 	uint64_t size_blocks;
117 	uint32_t blocksize;
118 	char *serial_number;
119 	char *device_id;
120 	char *ctld_name;
121 	nvlist_t *attr_list;
122 	STAILQ_ENTRY(cctl_lun) links;
123 };
124 
125 struct cctl_port {
126 	uint32_t port_id;
127 	char *port_frontend;
128 	char *port_name;
129 	int pp;
130 	int vp;
131 	int cfiscsi_state;
132 	char *cfiscsi_target;
133 	uint16_t cfiscsi_portal_group_tag;
134 	char *ctld_portal_group_name;
135 	nvlist_t *attr_list;
136 	STAILQ_ENTRY(cctl_port) links;
137 };
138 
139 struct cctl_devlist_data {
140 	int num_luns;
141 	STAILQ_HEAD(,cctl_lun) lun_list;
142 	struct cctl_lun *cur_lun;
143 	int num_ports;
144 	STAILQ_HEAD(,cctl_port) port_list;
145 	struct cctl_port *cur_port;
146 	int level;
147 	struct sbuf *cur_sb[32];
148 };
149 
150 static void
151 cctl_start_element(void *user_data, const char *name, const char **attr)
152 {
153 	int i;
154 	struct cctl_devlist_data *devlist;
155 	struct cctl_lun *cur_lun;
156 
157 	devlist = (struct cctl_devlist_data *)user_data;
158 	cur_lun = devlist->cur_lun;
159 	devlist->level++;
160 	if ((u_int)devlist->level >= (sizeof(devlist->cur_sb) /
161 	    sizeof(devlist->cur_sb[0])))
162 		log_errx(1, "%s: too many nesting levels, %zd max", __func__,
163 		     nitems(devlist->cur_sb));
164 
165 	devlist->cur_sb[devlist->level] = sbuf_new_auto();
166 	if (devlist->cur_sb[devlist->level] == NULL)
167 		log_err(1, "%s: unable to allocate sbuf", __func__);
168 
169 	if (strcmp(name, "lun") == 0) {
170 		if (cur_lun != NULL)
171 			log_errx(1, "%s: improper lun element nesting",
172 			    __func__);
173 
174 		cur_lun = reinterpret_cast<struct cctl_lun *>(calloc(1, sizeof(*cur_lun)));
175 		if (cur_lun == NULL)
176 			log_err(1, "%s: cannot allocate %zd bytes", __func__,
177 			    sizeof(*cur_lun));
178 
179 		devlist->num_luns++;
180 		devlist->cur_lun = cur_lun;
181 
182 		cur_lun->attr_list = nvlist_create(0);
183 		STAILQ_INSERT_TAIL(&devlist->lun_list, cur_lun, links);
184 
185 		for (i = 0; attr[i] != NULL; i += 2) {
186 			if (strcmp(attr[i], "id") == 0) {
187 				cur_lun->lun_id = strtoull(attr[i+1], NULL, 0);
188 			} else {
189 				log_errx(1, "%s: invalid LUN attribute %s = %s",
190 				     __func__, attr[i], attr[i+1]);
191 			}
192 		}
193 	}
194 }
195 
196 static void
197 cctl_end_element(void *user_data, const char *name)
198 {
199 	struct cctl_devlist_data *devlist;
200 	struct cctl_lun *cur_lun;
201 	char *str;
202 	int error;
203 
204 	devlist = (struct cctl_devlist_data *)user_data;
205 	cur_lun = devlist->cur_lun;
206 
207 	if ((cur_lun == NULL)
208 	 && (strcmp(name, "ctllunlist") != 0))
209 		log_errx(1, "%s: cur_lun == NULL! (name = %s)", __func__, name);
210 
211 	if (devlist->cur_sb[devlist->level] == NULL)
212 		log_errx(1, "%s: no valid sbuf at level %d (name %s)", __func__,
213 		     devlist->level, name);
214 
215 	sbuf_finish(devlist->cur_sb[devlist->level]);
216 	str = checked_strdup(sbuf_data(devlist->cur_sb[devlist->level]));
217 
218 	if (strlen(str) == 0) {
219 		free(str);
220 		str = NULL;
221 	}
222 
223 	sbuf_delete(devlist->cur_sb[devlist->level]);
224 	devlist->cur_sb[devlist->level] = NULL;
225 	devlist->level--;
226 
227 	if (strcmp(name, "backend_type") == 0) {
228 		cur_lun->backend_type = str;
229 		str = NULL;
230 	} else if (strcmp(name, "lun_type") == 0) {
231 		if (str == NULL)
232 			log_errx(1, "%s: %s missing its argument", __func__, name);
233 		cur_lun->device_type = strtoull(str, NULL, 0);
234 	} else if (strcmp(name, "size") == 0) {
235 		if (str == NULL)
236 			log_errx(1, "%s: %s missing its argument", __func__, name);
237 		cur_lun->size_blocks = strtoull(str, NULL, 0);
238 	} else if (strcmp(name, "blocksize") == 0) {
239 		if (str == NULL)
240 			log_errx(1, "%s: %s missing its argument", __func__, name);
241 		cur_lun->blocksize = strtoul(str, NULL, 0);
242 	} else if (strcmp(name, "serial_number") == 0) {
243 		cur_lun->serial_number = str;
244 		str = NULL;
245 	} else if (strcmp(name, "device_id") == 0) {
246 		cur_lun->device_id = str;
247 		str = NULL;
248 	} else if (strcmp(name, "ctld_name") == 0) {
249 		cur_lun->ctld_name = str;
250 		str = NULL;
251 	} else if (strcmp(name, "lun") == 0) {
252 		devlist->cur_lun = NULL;
253 	} else if (strcmp(name, "ctllunlist") == 0) {
254 		/* Nothing. */
255 	} else {
256 		nvlist_move_string(cur_lun->attr_list, name, str);
257 		error = nvlist_error(cur_lun->attr_list);
258 		if (error != 0)
259 			log_errc(1, error, "%s: failed to add nv pair for %s",
260 			    __func__, name);
261 		str = NULL;
262 	}
263 
264 	free(str);
265 }
266 
267 static void
268 cctl_start_pelement(void *user_data, const char *name, const char **attr)
269 {
270 	int i;
271 	struct cctl_devlist_data *devlist;
272 	struct cctl_port *cur_port;
273 
274 	devlist = (struct cctl_devlist_data *)user_data;
275 	cur_port = devlist->cur_port;
276 	devlist->level++;
277 	if ((u_int)devlist->level >= (sizeof(devlist->cur_sb) /
278 	    sizeof(devlist->cur_sb[0])))
279 		log_errx(1, "%s: too many nesting levels, %zd max", __func__,
280 		     nitems(devlist->cur_sb));
281 
282 	devlist->cur_sb[devlist->level] = sbuf_new_auto();
283 	if (devlist->cur_sb[devlist->level] == NULL)
284 		log_err(1, "%s: unable to allocate sbuf", __func__);
285 
286 	if (strcmp(name, "targ_port") == 0) {
287 		if (cur_port != NULL)
288 			log_errx(1, "%s: improper port element nesting (%s)",
289 			    __func__, name);
290 
291 		cur_port = reinterpret_cast<struct cctl_port *>(calloc(1, sizeof(*cur_port)));
292 		if (cur_port == NULL)
293 			log_err(1, "%s: cannot allocate %zd bytes", __func__,
294 			    sizeof(*cur_port));
295 
296 		devlist->num_ports++;
297 		devlist->cur_port = cur_port;
298 
299 		cur_port->attr_list = nvlist_create(0);
300 		STAILQ_INSERT_TAIL(&devlist->port_list, cur_port, links);
301 
302 		for (i = 0; attr[i] != NULL; i += 2) {
303 			if (strcmp(attr[i], "id") == 0) {
304 				cur_port->port_id = strtoul(attr[i+1], NULL, 0);
305 			} else {
306 				log_errx(1, "%s: invalid LUN attribute %s = %s",
307 				     __func__, attr[i], attr[i+1]);
308 			}
309 		}
310 	}
311 }
312 
313 static void
314 cctl_end_pelement(void *user_data, const char *name)
315 {
316 	struct cctl_devlist_data *devlist;
317 	struct cctl_port *cur_port;
318 	char *str;
319 	int error;
320 
321 	devlist = (struct cctl_devlist_data *)user_data;
322 	cur_port = devlist->cur_port;
323 
324 	if ((cur_port == NULL)
325 	 && (strcmp(name, "ctlportlist") != 0))
326 		log_errx(1, "%s: cur_port == NULL! (name = %s)", __func__, name);
327 
328 	if (devlist->cur_sb[devlist->level] == NULL)
329 		log_errx(1, "%s: no valid sbuf at level %d (name %s)", __func__,
330 		     devlist->level, name);
331 
332 	sbuf_finish(devlist->cur_sb[devlist->level]);
333 	str = checked_strdup(sbuf_data(devlist->cur_sb[devlist->level]));
334 
335 	if (strlen(str) == 0) {
336 		free(str);
337 		str = NULL;
338 	}
339 
340 	sbuf_delete(devlist->cur_sb[devlist->level]);
341 	devlist->cur_sb[devlist->level] = NULL;
342 	devlist->level--;
343 
344 	if (strcmp(name, "frontend_type") == 0) {
345 		cur_port->port_frontend = str;
346 		str = NULL;
347 	} else if (strcmp(name, "port_name") == 0) {
348 		cur_port->port_name = str;
349 		str = NULL;
350 	} else if (strcmp(name, "physical_port") == 0) {
351 		if (str == NULL)
352 			log_errx(1, "%s: %s missing its argument", __func__, name);
353 		cur_port->pp = strtoul(str, NULL, 0);
354 	} else if (strcmp(name, "virtual_port") == 0) {
355 		if (str == NULL)
356 			log_errx(1, "%s: %s missing its argument", __func__, name);
357 		cur_port->vp = strtoul(str, NULL, 0);
358 	} else if (strcmp(name, "cfiscsi_target") == 0) {
359 		cur_port->cfiscsi_target = str;
360 		str = NULL;
361 	} else if (strcmp(name, "cfiscsi_state") == 0) {
362 		if (str == NULL)
363 			log_errx(1, "%s: %s missing its argument", __func__, name);
364 		cur_port->cfiscsi_state = strtoul(str, NULL, 0);
365 	} else if (strcmp(name, "cfiscsi_portal_group_tag") == 0) {
366 		if (str == NULL)
367 			log_errx(1, "%s: %s missing its argument", __func__, name);
368 		cur_port->cfiscsi_portal_group_tag = strtoul(str, NULL, 0);
369 	} else if (strcmp(name, "ctld_portal_group_name") == 0) {
370 		cur_port->ctld_portal_group_name = str;
371 		str = NULL;
372 	} else if (strcmp(name, "targ_port") == 0) {
373 		devlist->cur_port = NULL;
374 	} else if (strcmp(name, "ctlportlist") == 0) {
375 		/* Nothing. */
376 	} else {
377 		nvlist_move_string(cur_port->attr_list, name, str);
378 		error = nvlist_error(cur_port->attr_list);
379 		if (error != 0)
380 			log_errc(1, error, "%s: failed to add nv pair for %s",
381 			    __func__, name);
382 		str = NULL;
383 	}
384 
385 	free(str);
386 }
387 
388 static void
389 cctl_char_handler(void *user_data, const XML_Char *str, int len)
390 {
391 	struct cctl_devlist_data *devlist;
392 
393 	devlist = (struct cctl_devlist_data *)user_data;
394 
395 	sbuf_bcat(devlist->cur_sb[devlist->level], str, len);
396 }
397 
398 struct conf *
399 conf_new_from_kernel(struct kports &kports)
400 {
401 	struct conf *conf = NULL;
402 	struct target *targ;
403 	struct portal_group *pg;
404 	struct lun *cl;
405 	struct ctl_lun_list list;
406 	struct cctl_devlist_data devlist;
407 	struct cctl_lun *lun;
408 	struct cctl_port *port;
409 	XML_Parser parser;
410 	const char *key;
411 	char *str, *name;
412 	void *cookie;
413 	int len, retval;
414 
415 	bzero(&devlist, sizeof(devlist));
416 	STAILQ_INIT(&devlist.lun_list);
417 	STAILQ_INIT(&devlist.port_list);
418 
419 	log_debugx("obtaining previously configured CTL luns from the kernel");
420 
421 	str = NULL;
422 	len = 4096;
423 retry:
424 	str = reinterpret_cast<char *>(realloc(str, len));
425 	if (str == NULL)
426 		log_err(1, "realloc");
427 
428 	bzero(&list, sizeof(list));
429 	list.alloc_len = len;
430 	list.status = CTL_LUN_LIST_NONE;
431 	list.lun_xml = str;
432 
433 	if (ioctl(ctl_fd, CTL_LUN_LIST, &list) == -1) {
434 		log_warn("error issuing CTL_LUN_LIST ioctl");
435 		free(str);
436 		return (NULL);
437 	}
438 
439 	if (list.status == CTL_LUN_LIST_ERROR) {
440 		log_warnx("error returned from CTL_LUN_LIST ioctl: %s",
441 		    list.error_str);
442 		free(str);
443 		return (NULL);
444 	}
445 
446 	if (list.status == CTL_LUN_LIST_NEED_MORE_SPACE) {
447 		len = len << 1;
448 		goto retry;
449 	}
450 
451 	parser = XML_ParserCreate(NULL);
452 	if (parser == NULL) {
453 		log_warnx("unable to create XML parser");
454 		free(str);
455 		return (NULL);
456 	}
457 
458 	XML_SetUserData(parser, &devlist);
459 	XML_SetElementHandler(parser, cctl_start_element, cctl_end_element);
460 	XML_SetCharacterDataHandler(parser, cctl_char_handler);
461 
462 	retval = XML_Parse(parser, str, strlen(str), 1);
463 	XML_ParserFree(parser);
464 	free(str);
465 	if (retval != 1) {
466 		log_warnx("XML_Parse failed");
467 		return (NULL);
468 	}
469 
470 	str = NULL;
471 	len = 4096;
472 retry_port:
473 	str = reinterpret_cast<char *>(realloc(str, len));
474 	if (str == NULL)
475 		log_err(1, "realloc");
476 
477 	bzero(&list, sizeof(list));
478 	list.alloc_len = len;
479 	list.status = CTL_LUN_LIST_NONE;
480 	list.lun_xml = str;
481 
482 	if (ioctl(ctl_fd, CTL_PORT_LIST, &list) == -1) {
483 		log_warn("error issuing CTL_PORT_LIST ioctl");
484 		free(str);
485 		return (NULL);
486 	}
487 
488 	if (list.status == CTL_LUN_LIST_ERROR) {
489 		log_warnx("error returned from CTL_PORT_LIST ioctl: %s",
490 		    list.error_str);
491 		free(str);
492 		return (NULL);
493 	}
494 
495 	if (list.status == CTL_LUN_LIST_NEED_MORE_SPACE) {
496 		len = len << 1;
497 		goto retry_port;
498 	}
499 
500 	parser = XML_ParserCreate(NULL);
501 	if (parser == NULL) {
502 		log_warnx("unable to create XML parser");
503 		free(str);
504 		return (NULL);
505 	}
506 
507 	XML_SetUserData(parser, &devlist);
508 	XML_SetElementHandler(parser, cctl_start_pelement, cctl_end_pelement);
509 	XML_SetCharacterDataHandler(parser, cctl_char_handler);
510 
511 	retval = XML_Parse(parser, str, strlen(str), 1);
512 	XML_ParserFree(parser);
513 	free(str);
514 	if (retval != 1) {
515 		log_warnx("XML_Parse failed");
516 		return (NULL);
517 	}
518 
519 	conf = conf_new();
520 
521 	name = NULL;
522 	STAILQ_FOREACH(port, &devlist.port_list, links) {
523 		if (strcmp(port->port_frontend, "ha") == 0)
524 			continue;
525 		free(name);
526 		if (port->pp == 0 && port->vp == 0) {
527 			name = checked_strdup(port->port_name);
528 		} else if (port->vp == 0) {
529 			retval = asprintf(&name, "%s/%d",
530 			    port->port_name, port->pp);
531 			if (retval <= 0)
532 				log_err(1, "asprintf");
533 		} else {
534 			retval = asprintf(&name, "%s/%d/%d",
535 			    port->port_name, port->pp, port->vp);
536 			if (retval <= 0)
537 				log_err(1, "asprintf");
538 		}
539 
540 		if (port->cfiscsi_target == NULL) {
541 			log_debugx("CTL port %u \"%s\" wasn't managed by ctld; ",
542 			    port->port_id, name);
543 			if (!kports.has_port(name)) {
544 				if (!kports.add_port(name, port->port_id)) {
545 					log_warnx("kports::add_port failed");
546 					continue;
547 				}
548 			}
549 			continue;
550 		}
551 		if (port->cfiscsi_state != 1) {
552 			log_debugx("CTL port %ju is not active (%d); ignoring",
553 			    (uintmax_t)port->port_id, port->cfiscsi_state);
554 			continue;
555 		}
556 
557 		targ = target_find(conf, port->cfiscsi_target);
558 		if (targ == NULL) {
559 			targ = target_new(conf, port->cfiscsi_target);
560 			if (targ == NULL) {
561 				log_warnx("target_new failed");
562 				continue;
563 			}
564 		}
565 
566 		if (port->ctld_portal_group_name == NULL)
567 			continue;
568 		pg = portal_group_find(conf, port->ctld_portal_group_name);
569 		if (pg == NULL) {
570 			pg = portal_group_new(conf, port->ctld_portal_group_name);
571 			if (pg == NULL) {
572 				log_warnx("portal_group_new failed");
573 				continue;
574 			}
575 		}
576 		pg->set_tag(port->cfiscsi_portal_group_tag);
577 		if (!port_new(conf, targ, pg, port->port_id)) {
578 			log_warnx("port_new failed");
579 			continue;
580 		}
581 	}
582 	while ((port = STAILQ_FIRST(&devlist.port_list))) {
583 		STAILQ_REMOVE_HEAD(&devlist.port_list, links);
584 		free(port->port_frontend);
585 		free(port->port_name);
586 		free(port->cfiscsi_target);
587 		free(port->ctld_portal_group_name);
588 		nvlist_destroy(port->attr_list);
589 		free(port);
590 	}
591 	free(name);
592 
593 	STAILQ_FOREACH(lun, &devlist.lun_list, links) {
594 		if (lun->ctld_name == NULL) {
595 			log_debugx("CTL lun %ju wasn't managed by ctld; "
596 			    "ignoring", (uintmax_t)lun->lun_id);
597 			continue;
598 		}
599 
600 		cl = lun_find(conf, lun->ctld_name);
601 		if (cl != NULL) {
602 			log_warnx("found CTL lun %ju \"%s\", "
603 			    "also backed by CTL lun %d; ignoring",
604 			    (uintmax_t)lun->lun_id, lun->ctld_name,
605 			    cl->ctl_lun());
606 			continue;
607 		}
608 
609 		log_debugx("found CTL lun %ju \"%s\"",
610 		    (uintmax_t)lun->lun_id, lun->ctld_name);
611 
612 		cl = lun_new(conf, lun->ctld_name);
613 		if (cl == NULL) {
614 			log_warnx("lun_new failed");
615 			continue;
616 		}
617 		cl->set_backend(lun->backend_type);
618 		cl->set_device_type(lun->device_type);
619 		cl->set_blocksize(lun->blocksize);
620 		cl->set_device_id(lun->device_id);
621 		cl->set_serial(lun->serial_number);
622 		cl->set_size(lun->size_blocks * lun->blocksize);
623 		cl->set_ctl_lun(lun->lun_id);
624 
625 		cookie = NULL;
626 		while ((key = nvlist_next(lun->attr_list, NULL, &cookie)) !=
627 		    NULL) {
628 			if (strcmp(key, "file") == 0 ||
629 			    strcmp(key, "dev") == 0) {
630 				cl->set_path(cnvlist_get_string(cookie));
631 				continue;
632 			}
633 			if (!cl->add_option(key, cnvlist_get_string(cookie)))
634 				log_warnx("unable to add CTL lun option "
635 				    "%s for CTL lun %ju \"%s\"",
636 				    key, (uintmax_t)lun->lun_id,
637 				    cl->name());
638 		}
639 	}
640 	while ((lun = STAILQ_FIRST(&devlist.lun_list))) {
641 		STAILQ_REMOVE_HEAD(&devlist.lun_list, links);
642 		nvlist_destroy(lun->attr_list);
643 		free(lun);
644 	}
645 
646 	return (conf);
647 }
648 
649 bool
650 lun::kernel_add()
651 {
652 	struct ctl_lun_req req;
653 	int error;
654 
655 	bzero(&req, sizeof(req));
656 
657 	strlcpy(req.backend, l_backend.c_str(), sizeof(req.backend));
658 	req.reqtype = CTL_LUNREQ_CREATE;
659 
660 	req.reqdata.create.blocksize_bytes = l_blocksize;
661 
662 	if (l_size != 0)
663 		req.reqdata.create.lun_size_bytes = l_size;
664 
665 	if (l_ctl_lun >= 0) {
666 		req.reqdata.create.req_lun_id = l_ctl_lun;
667 		req.reqdata.create.flags |= CTL_LUN_FLAG_ID_REQ;
668 	}
669 
670 	req.reqdata.create.flags |= CTL_LUN_FLAG_DEV_TYPE;
671 	req.reqdata.create.device_type = l_device_type;
672 
673 	if (!l_serial.empty()) {
674 		strncpy((char *)req.reqdata.create.serial_num, l_serial.c_str(),
675 			sizeof(req.reqdata.create.serial_num));
676 		req.reqdata.create.flags |= CTL_LUN_FLAG_SERIAL_NUM;
677 	}
678 
679 	if (!l_device_id.empty()) {
680 		strncpy((char *)req.reqdata.create.device_id,
681 		    l_device_id.c_str(), sizeof(req.reqdata.create.device_id));
682 		req.reqdata.create.flags |= CTL_LUN_FLAG_DEVID;
683 	}
684 
685 	freebsd::nvlist_up nvl = options();
686 	req.args = nvlist_pack(nvl.get(), &req.args_len);
687 	if (req.args == NULL) {
688 		log_warn("error packing nvlist");
689 		return (false);
690 	}
691 
692 	error = ioctl(ctl_fd, CTL_LUN_REQ, &req);
693 	free(req.args);
694 
695 	if (error != 0) {
696 		log_warn("error issuing CTL_LUN_REQ ioctl");
697 		return (false);
698 	}
699 
700 	switch (req.status) {
701 	case CTL_LUN_ERROR:
702 		log_warnx("LUN creation error: %s", req.error_str);
703 		return (false);
704 	case CTL_LUN_WARNING:
705 		log_warnx("LUN creation warning: %s", req.error_str);
706 		break;
707 	case CTL_LUN_OK:
708 		break;
709 	default:
710 		log_warnx("unknown LUN creation status: %d",
711 		    req.status);
712 		return (false);
713 	}
714 
715 	l_ctl_lun = req.reqdata.create.req_lun_id;
716 	return (true);
717 }
718 
719 bool
720 lun::kernel_modify() const
721 {
722 	struct ctl_lun_req req;
723 	int error;
724 
725 	bzero(&req, sizeof(req));
726 
727 	strlcpy(req.backend, l_backend.c_str(), sizeof(req.backend));
728 	req.reqtype = CTL_LUNREQ_MODIFY;
729 
730 	req.reqdata.modify.lun_id = l_ctl_lun;
731 	req.reqdata.modify.lun_size_bytes = l_size;
732 
733 	freebsd::nvlist_up nvl = options();
734 	req.args = nvlist_pack(nvl.get(), &req.args_len);
735 	if (req.args == NULL) {
736 		log_warn("error packing nvlist");
737 		return (false);
738 	}
739 
740 	error = ioctl(ctl_fd, CTL_LUN_REQ, &req);
741 	free(req.args);
742 
743 	if (error != 0) {
744 		log_warn("error issuing CTL_LUN_REQ ioctl");
745 		return (false);
746 	}
747 
748 	switch (req.status) {
749 	case CTL_LUN_ERROR:
750 		log_warnx("LUN modification error: %s", req.error_str);
751 		return (false);
752 	case CTL_LUN_WARNING:
753 		log_warnx("LUN modification warning: %s", req.error_str);
754 		break;
755 	case CTL_LUN_OK:
756 		break;
757 	default:
758 		log_warnx("unknown LUN modification status: %d",
759 		    req.status);
760 		return (false);
761 	}
762 
763 	return (true);
764 }
765 
766 bool
767 lun::kernel_remove() const
768 {
769 	struct ctl_lun_req req;
770 
771 	bzero(&req, sizeof(req));
772 
773 	strlcpy(req.backend, l_backend.c_str(), sizeof(req.backend));
774 	req.reqtype = CTL_LUNREQ_RM;
775 
776 	req.reqdata.rm.lun_id = l_ctl_lun;
777 
778 	if (ioctl(ctl_fd, CTL_LUN_REQ, &req) == -1) {
779 		log_warn("error issuing CTL_LUN_REQ ioctl");
780 		return (false);
781 	}
782 
783 	switch (req.status) {
784 	case CTL_LUN_ERROR:
785 		log_warnx("LUN removal error: %s", req.error_str);
786 		return (false);
787 	case CTL_LUN_WARNING:
788 		log_warnx("LUN removal warning: %s", req.error_str);
789 		break;
790 	case CTL_LUN_OK:
791 		break;
792 	default:
793 		log_warnx("unknown LUN removal status: %d", req.status);
794 		return (false);
795 	}
796 
797 	return (true);
798 }
799 
800 void
801 kernel_handoff(struct ctld_connection *conn)
802 {
803 	struct portal_group *pg = conn->conn_portal->portal_group();
804 	struct ctl_iscsi req;
805 
806 	bzero(&req, sizeof(req));
807 
808 	req.type = CTL_ISCSI_HANDOFF;
809 	strlcpy(req.data.handoff.initiator_name,
810 	    conn->conn_initiator_name, sizeof(req.data.handoff.initiator_name));
811 	strlcpy(req.data.handoff.initiator_addr,
812 	    conn->conn_initiator_addr, sizeof(req.data.handoff.initiator_addr));
813 	if (conn->conn_initiator_alias != NULL) {
814 		strlcpy(req.data.handoff.initiator_alias,
815 		    conn->conn_initiator_alias, sizeof(req.data.handoff.initiator_alias));
816 	}
817 	memcpy(req.data.handoff.initiator_isid, conn->conn_initiator_isid,
818 	    sizeof(req.data.handoff.initiator_isid));
819 	strlcpy(req.data.handoff.target_name,
820 	    conn->conn_target->name(), sizeof(req.data.handoff.target_name));
821 	strlcpy(req.data.handoff.offload, pg->offload(),
822 	    sizeof(req.data.handoff.offload));
823 #ifdef ICL_KERNEL_PROXY
824 	if (proxy_mode)
825 		req.data.handoff.connection_id = conn->conn.conn_socket;
826 	else
827 		req.data.handoff.socket = conn->conn.conn_socket;
828 #else
829 	req.data.handoff.socket = conn->conn.conn_socket;
830 #endif
831 	req.data.handoff.portal_group_tag = pg->tag();
832 	if (conn->conn.conn_header_digest == CONN_DIGEST_CRC32C)
833 		req.data.handoff.header_digest = CTL_ISCSI_DIGEST_CRC32C;
834 	if (conn->conn.conn_data_digest == CONN_DIGEST_CRC32C)
835 		req.data.handoff.data_digest = CTL_ISCSI_DIGEST_CRC32C;
836 	req.data.handoff.cmdsn = conn->conn.conn_cmdsn;
837 	req.data.handoff.statsn = conn->conn.conn_statsn;
838 	req.data.handoff.max_recv_data_segment_length =
839 	    conn->conn.conn_max_recv_data_segment_length;
840 	req.data.handoff.max_send_data_segment_length =
841 	    conn->conn.conn_max_send_data_segment_length;
842 	req.data.handoff.max_burst_length = conn->conn.conn_max_burst_length;
843 	req.data.handoff.first_burst_length =
844 	    conn->conn.conn_first_burst_length;
845 	req.data.handoff.immediate_data = conn->conn.conn_immediate_data;
846 
847 	if (ioctl(ctl_fd, CTL_ISCSI, &req) == -1) {
848 		log_err(1, "error issuing CTL_ISCSI ioctl; "
849 		    "dropping connection");
850 	}
851 
852 	if (req.status != CTL_ISCSI_OK) {
853 		log_errx(1, "error returned from CTL iSCSI handoff request: "
854 		    "%s; dropping connection", req.error_str);
855 	}
856 }
857 
858 static bool
859 ctl_create_port(const char *driver, const nvlist_t *nvl, uint32_t *ctl_port)
860 {
861 	struct ctl_req req;
862 	char result_buf[NVLIST_BUFSIZE];
863 	int error;
864 
865 	bzero(&req, sizeof(req));
866 	req.reqtype = CTL_REQ_CREATE;
867 
868 	strlcpy(req.driver, driver, sizeof(req.driver));
869 	req.args = nvlist_pack(nvl, &req.args_len);
870 	if (req.args == NULL) {
871 		log_warn("error packing nvlist");
872 		return (false);
873 	}
874 
875 	req.result = result_buf;
876 	req.result_len = sizeof(result_buf);
877 	error = ioctl(ctl_fd, CTL_PORT_REQ, &req);
878 	free(req.args);
879 
880 	if (error != 0) {
881 		log_warn("error issuing CTL_PORT_REQ ioctl");
882 		return (false);
883 	}
884 	if (req.status == CTL_LUN_ERROR) {
885 		log_warnx("error returned from port creation request: %s",
886 		    req.error_str);
887 		return (false);
888 	}
889 	if (req.status != CTL_LUN_OK) {
890 		log_warnx("unknown port creation request status %d",
891 		    req.status);
892 		return (false);
893 	}
894 
895 	freebsd::nvlist_up result_nvl(nvlist_unpack(result_buf, req.result_len,
896 	    0));
897 	if (result_nvl == NULL) {
898 		log_warnx("error unpacking result nvlist");
899 		return (false);
900 	}
901 
902 	*ctl_port = nvlist_get_number(result_nvl.get(), "port_id");
903 	return (true);
904 }
905 
906 bool
907 portal_group_port::kernel_create_port()
908 {
909 	struct portal_group *pg = p_portal_group;
910 	struct target *targ = p_target;
911 
912 	freebsd::nvlist_up nvl = pg->options();
913 	nvlist_add_string(nvl.get(), "cfiscsi_target", targ->name());
914 	nvlist_add_string(nvl.get(), "ctld_portal_group_name", pg->name());
915 	nvlist_add_stringf(nvl.get(), "cfiscsi_portal_group_tag", "%u",
916 	    pg->tag());
917 
918 	if (targ->has_alias()) {
919 		nvlist_add_string(nvl.get(), "cfiscsi_target_alias",
920 		    targ->alias());
921 	}
922 
923 	return (ctl_create_port("iscsi", nvl.get(), &p_ctl_port));
924 }
925 
926 bool
927 ioctl_port::kernel_create_port()
928 {
929 	freebsd::nvlist_up nvl(nvlist_create(0));
930 	nvlist_add_stringf(nvl.get(), "pp", "%d", p_ioctl_pp);
931 	nvlist_add_stringf(nvl.get(), "vp", "%d", p_ioctl_vp);
932 
933 	return (ctl_create_port("ioctl", nvl.get(), &p_ctl_port));
934 }
935 
936 bool
937 kernel_port::kernel_create_port()
938 {
939 	struct ctl_port_entry entry;
940 	struct target *targ = p_target;
941 
942 	p_ctl_port = p_pport->ctl_port();
943 
944 	if (strncmp(targ->name(), "naa.", 4) == 0 &&
945 	    strlen(targ->name()) == 20) {
946 		bzero(&entry, sizeof(entry));
947 		entry.port_type = CTL_PORT_NONE;
948 		entry.targ_port = p_ctl_port;
949 		entry.flags |= CTL_PORT_WWNN_VALID;
950 		entry.wwnn = strtoull(targ->name() + 4, NULL, 16);
951 		if (ioctl(ctl_fd, CTL_SET_PORT_WWNS, &entry) == -1)
952 			log_warn("CTL_SET_PORT_WWNS ioctl failed");
953 	}
954 	return (true);
955 }
956 
957 bool
958 port::kernel_add()
959 {
960 	struct ctl_port_entry entry;
961 	struct ctl_lun_map lm;
962 	struct target *targ = p_target;
963 	int error, i;
964 
965 	if (!kernel_create_port())
966 		return (false);
967 
968 	/* Explicitly enable mapping to block any access except allowed. */
969 	lm.port = p_ctl_port;
970 	lm.plun = UINT32_MAX;
971 	lm.lun = 0;
972 	error = ioctl(ctl_fd, CTL_LUN_MAP, &lm);
973 	if (error != 0)
974 		log_warn("CTL_LUN_MAP ioctl failed");
975 
976 	/* Map configured LUNs */
977 	for (i = 0; i < MAX_LUNS; i++) {
978 		if (targ->lun(i) == nullptr)
979 			continue;
980 		lm.port = p_ctl_port;
981 		lm.plun = i;
982 		lm.lun = targ->lun(i)->ctl_lun();
983 		error = ioctl(ctl_fd, CTL_LUN_MAP, &lm);
984 		if (error != 0)
985 			log_warn("CTL_LUN_MAP ioctl failed");
986 	}
987 
988 	/* Enable port */
989 	bzero(&entry, sizeof(entry));
990 	entry.targ_port = p_ctl_port;
991 	error = ioctl(ctl_fd, CTL_ENABLE_PORT, &entry);
992 	if (error != 0) {
993 		log_warn("CTL_ENABLE_PORT ioctl failed");
994 		return (false);
995 	}
996 
997 	return (true);
998 }
999 
1000 bool
1001 port::kernel_update(const struct port *oport)
1002 {
1003 	struct ctl_lun_map lm;
1004 	struct target *targ = p_target;
1005 	struct target *otarg = oport->p_target;
1006 	int error, i;
1007 	uint32_t olun;
1008 
1009 	p_ctl_port = oport->p_ctl_port;
1010 
1011 	/* Map configured LUNs and unmap others */
1012 	for (i = 0; i < MAX_LUNS; i++) {
1013 		lm.port = p_ctl_port;
1014 		lm.plun = i;
1015 		if (targ->lun(i) == nullptr)
1016 			lm.lun = UINT32_MAX;
1017 		else
1018 			lm.lun = targ->lun(i)->ctl_lun();
1019 		if (otarg->lun(i) == nullptr)
1020 			olun = UINT32_MAX;
1021 		else
1022 			olun = otarg->lun(i)->ctl_lun();
1023 		if (lm.lun == olun)
1024 			continue;
1025 		error = ioctl(ctl_fd, CTL_LUN_MAP, &lm);
1026 		if (error != 0)
1027 			log_warn("CTL_LUN_MAP ioctl failed");
1028 	}
1029 	return (true);
1030 }
1031 
1032 bool
1033 ctl_remove_port(const char *driver, nvlist_t *nvl)
1034 {
1035 	struct ctl_req req;
1036 	int error;
1037 
1038 	strlcpy(req.driver, driver, sizeof(req.driver));
1039 	req.reqtype = CTL_REQ_REMOVE;
1040 	req.args = nvlist_pack(nvl, &req.args_len);
1041 	if (req.args == NULL) {
1042 		log_warn("error packing nvlist");
1043 		return (false);
1044 	}
1045 
1046 	error = ioctl(ctl_fd, CTL_PORT_REQ, &req);
1047 	free(req.args);
1048 
1049 	if (error != 0) {
1050 		log_warn("error issuing CTL_PORT_REQ ioctl");
1051 		return (false);
1052 	}
1053 	if (req.status == CTL_LUN_ERROR) {
1054 		log_warnx("error returned from port removal request: %s",
1055 		    req.error_str);
1056 		return (false);
1057 	}
1058 	if (req.status != CTL_LUN_OK) {
1059 		log_warnx("unknown port removal request status %d", req.status);
1060 		return (false);
1061 	}
1062 	return (true);
1063 }
1064 
1065 bool
1066 portal_group_port::kernel_remove_port()
1067 {
1068 	freebsd::nvlist_up nvl(nvlist_create(0));
1069 	nvlist_add_string(nvl.get(), "cfiscsi_target", p_target->name());
1070 	nvlist_add_stringf(nvl.get(), "cfiscsi_portal_group_tag", "%u",
1071 	    p_portal_group->tag());
1072 
1073 	return (ctl_remove_port("iscsi", nvl.get()));
1074 }
1075 
1076 bool
1077 ioctl_port::kernel_remove_port()
1078 {
1079 	freebsd::nvlist_up nvl(nvlist_create(0));
1080 	nvlist_add_stringf(nvl.get(), "port_id", "%d", p_ctl_port);
1081 
1082 	return (ctl_remove_port("ioctl", nvl.get()));
1083 }
1084 
1085 bool
1086 kernel_port::kernel_remove_port()
1087 {
1088 	struct ctl_lun_map lm;
1089 	int error;
1090 
1091 	/* Disable LUN mapping. */
1092 	lm.port = p_ctl_port;
1093 	lm.plun = UINT32_MAX;
1094 	lm.lun = UINT32_MAX;
1095 	error = ioctl(ctl_fd, CTL_LUN_MAP, &lm);
1096 	if (error != 0)
1097 		log_warn("CTL_LUN_MAP ioctl failed");
1098 	return (true);
1099 }
1100 
1101 bool
1102 port::kernel_remove()
1103 {
1104 	struct ctl_port_entry entry;
1105 	int error;
1106 
1107 	/* Disable port */
1108 	bzero(&entry, sizeof(entry));
1109 	entry.targ_port = p_ctl_port;
1110 	error = ioctl(ctl_fd, CTL_DISABLE_PORT, &entry);
1111 	if (error != 0) {
1112 		log_warn("CTL_DISABLE_PORT ioctl failed");
1113 		return (false);
1114 	}
1115 
1116 	return (kernel_remove_port());
1117 }
1118 
1119 #ifdef ICL_KERNEL_PROXY
1120 void
1121 kernel_listen(struct addrinfo *ai, bool iser, int portal_id)
1122 {
1123 	struct ctl_iscsi req;
1124 
1125 	bzero(&req, sizeof(req));
1126 
1127 	req.type = CTL_ISCSI_LISTEN;
1128 	req.data.listen.iser = iser;
1129 	req.data.listen.domain = ai->ai_family;
1130 	req.data.listen.socktype = ai->ai_socktype;
1131 	req.data.listen.protocol = ai->ai_protocol;
1132 	req.data.listen.addr = ai->ai_addr;
1133 	req.data.listen.addrlen = ai->ai_addrlen;
1134 	req.data.listen.portal_id = portal_id;
1135 
1136 	if (ioctl(ctl_fd, CTL_ISCSI, &req) == -1)
1137 		log_err(1, "error issuing CTL_ISCSI ioctl");
1138 
1139 	if (req.status != CTL_ISCSI_OK) {
1140 		log_errx(1, "error returned from CTL iSCSI listen: %s",
1141 		    req.error_str);
1142 	}
1143 }
1144 
1145 void
1146 kernel_accept(int *connection_id, int *portal_id,
1147     struct sockaddr *client_sa, socklen_t *client_salen)
1148 {
1149 	struct ctl_iscsi req;
1150 	struct sockaddr_storage ss;
1151 
1152 	bzero(&req, sizeof(req));
1153 
1154 	req.type = CTL_ISCSI_ACCEPT;
1155 	req.data.accept.initiator_addr = (struct sockaddr *)&ss;
1156 
1157 	if (ioctl(ctl_fd, CTL_ISCSI, &req) == -1)
1158 		log_err(1, "error issuing CTL_ISCSI ioctl");
1159 
1160 	if (req.status != CTL_ISCSI_OK) {
1161 		log_errx(1, "error returned from CTL iSCSI accept: %s",
1162 		    req.error_str);
1163 	}
1164 
1165 	*connection_id = req.data.accept.connection_id;
1166 	*portal_id = req.data.accept.portal_id;
1167 	*client_salen = req.data.accept.initiator_addrlen;
1168 	memcpy(client_sa, &ss, *client_salen);
1169 }
1170 
1171 void
1172 kernel_send(struct pdu *pdu)
1173 {
1174 	struct ctl_iscsi req;
1175 
1176 	bzero(&req, sizeof(req));
1177 
1178 	req.type = CTL_ISCSI_SEND;
1179 	req.data.send.connection_id = pdu->pdu_connection->conn_socket;
1180 	req.data.send.bhs = pdu->pdu_bhs;
1181 	req.data.send.data_segment_len = pdu->pdu_data_len;
1182 	req.data.send.data_segment = pdu->pdu_data;
1183 
1184 	if (ioctl(ctl_fd, CTL_ISCSI, &req) == -1) {
1185 		log_err(1, "error issuing CTL_ISCSI ioctl; "
1186 		    "dropping connection");
1187 	}
1188 
1189 	if (req.status != CTL_ISCSI_OK) {
1190 		log_errx(1, "error returned from CTL iSCSI send: "
1191 		    "%s; dropping connection", req.error_str);
1192 	}
1193 }
1194 
1195 void
1196 kernel_receive(struct pdu *pdu)
1197 {
1198 	struct connection *conn;
1199 	struct ctl_iscsi req;
1200 
1201 	conn = pdu->pdu_connection;
1202 	pdu->pdu_data = malloc(conn->conn_max_recv_data_segment_length);
1203 	if (pdu->pdu_data == NULL)
1204 		log_err(1, "malloc");
1205 
1206 	bzero(&req, sizeof(req));
1207 
1208 	req.type = CTL_ISCSI_RECEIVE;
1209 	req.data.receive.connection_id = conn->conn_socket;
1210 	req.data.receive.bhs = pdu->pdu_bhs;
1211 	req.data.receive.data_segment_len =
1212 	    conn->conn_max_recv_data_segment_length;
1213 	req.data.receive.data_segment = pdu->pdu_data;
1214 
1215 	if (ioctl(ctl_fd, CTL_ISCSI, &req) == -1) {
1216 		log_err(1, "error issuing CTL_ISCSI ioctl; "
1217 		    "dropping connection");
1218 	}
1219 
1220 	if (req.status != CTL_ISCSI_OK) {
1221 		log_errx(1, "error returned from CTL iSCSI receive: "
1222 		    "%s; dropping connection", req.error_str);
1223 	}
1224 
1225 }
1226 
1227 #endif /* ICL_KERNEL_PROXY */
1228 
1229 /*
1230  * XXX: I CANT INTO LATIN
1231  */
1232 void
1233 kernel_capsicate(void)
1234 {
1235 	cap_rights_t rights;
1236 	const unsigned long cmds[] = { CTL_ISCSI };
1237 
1238 	cap_rights_init(&rights, CAP_IOCTL);
1239 	if (caph_rights_limit(ctl_fd, &rights) < 0)
1240 		log_err(1, "cap_rights_limit");
1241 
1242 	if (caph_ioctls_limit(ctl_fd, cmds, nitems(cmds)) < 0)
1243 		log_err(1, "cap_ioctls_limit");
1244 
1245 	if (caph_enter() < 0)
1246 		log_err(1, "cap_enter");
1247 
1248 	if (cap_sandboxed())
1249 		log_debugx("Capsicum capability mode enabled");
1250 	else
1251 		log_warnx("Capsicum capability mode not supported");
1252 }
1253 
1254