xref: /linux/drivers/block/nbd.c (revision 9ffc93f203c18a70623f21950f1dd473c9ec48cd)
1 /*
2  * Network block device - make block devices work over TCP
3  *
4  * Note that you can not swap over this thing, yet. Seems to work but
5  * deadlocks sometimes - you can not swap over TCP in general.
6  *
7  * Copyright 1997-2000, 2008 Pavel Machek <pavel@ucw.cz>
8  * Parts copyright 2001 Steven Whitehouse <steve@chygwyn.com>
9  *
10  * This file is released under GPLv2 or later.
11  *
12  * (part of code stolen from loop.c)
13  */
14 
15 #include <linux/major.h>
16 
17 #include <linux/blkdev.h>
18 #include <linux/module.h>
19 #include <linux/init.h>
20 #include <linux/sched.h>
21 #include <linux/fs.h>
22 #include <linux/bio.h>
23 #include <linux/stat.h>
24 #include <linux/errno.h>
25 #include <linux/file.h>
26 #include <linux/ioctl.h>
27 #include <linux/mutex.h>
28 #include <linux/compiler.h>
29 #include <linux/err.h>
30 #include <linux/kernel.h>
31 #include <linux/slab.h>
32 #include <net/sock.h>
33 #include <linux/net.h>
34 #include <linux/kthread.h>
35 
36 #include <asm/uaccess.h>
37 #include <asm/types.h>
38 
39 #include <linux/nbd.h>
40 
41 #define LO_MAGIC 0x68797548
42 
43 #ifdef NDEBUG
44 #define dprintk(flags, fmt...)
45 #else /* NDEBUG */
46 #define dprintk(flags, fmt...) do { \
47 	if (debugflags & (flags)) printk(KERN_DEBUG fmt); \
48 } while (0)
49 #define DBG_IOCTL       0x0004
50 #define DBG_INIT        0x0010
51 #define DBG_EXIT        0x0020
52 #define DBG_BLKDEV      0x0100
53 #define DBG_RX          0x0200
54 #define DBG_TX          0x0400
55 static unsigned int debugflags;
56 #endif /* NDEBUG */
57 
58 static unsigned int nbds_max = 16;
59 static struct nbd_device *nbd_dev;
60 static int max_part;
61 
62 /*
63  * Use just one lock (or at most 1 per NIC). Two arguments for this:
64  * 1. Each NIC is essentially a synchronization point for all servers
65  *    accessed through that NIC so there's no need to have more locks
66  *    than NICs anyway.
67  * 2. More locks lead to more "Dirty cache line bouncing" which will slow
68  *    down each lock to the point where they're actually slower than just
69  *    a single lock.
70  * Thanks go to Jens Axboe and Al Viro for their LKML emails explaining this!
71  */
72 static DEFINE_SPINLOCK(nbd_lock);
73 
74 #ifndef NDEBUG
75 static const char *ioctl_cmd_to_ascii(int cmd)
76 {
77 	switch (cmd) {
78 	case NBD_SET_SOCK: return "set-sock";
79 	case NBD_SET_BLKSIZE: return "set-blksize";
80 	case NBD_SET_SIZE: return "set-size";
81 	case NBD_DO_IT: return "do-it";
82 	case NBD_CLEAR_SOCK: return "clear-sock";
83 	case NBD_CLEAR_QUE: return "clear-que";
84 	case NBD_PRINT_DEBUG: return "print-debug";
85 	case NBD_SET_SIZE_BLOCKS: return "set-size-blocks";
86 	case NBD_DISCONNECT: return "disconnect";
87 	case BLKROSET: return "set-read-only";
88 	case BLKFLSBUF: return "flush-buffer-cache";
89 	}
90 	return "unknown";
91 }
92 
93 static const char *nbdcmd_to_ascii(int cmd)
94 {
95 	switch (cmd) {
96 	case  NBD_CMD_READ: return "read";
97 	case NBD_CMD_WRITE: return "write";
98 	case  NBD_CMD_DISC: return "disconnect";
99 	}
100 	return "invalid";
101 }
102 #endif /* NDEBUG */
103 
104 static void nbd_end_request(struct request *req)
105 {
106 	int error = req->errors ? -EIO : 0;
107 	struct request_queue *q = req->q;
108 	unsigned long flags;
109 
110 	dprintk(DBG_BLKDEV, "%s: request %p: %s\n", req->rq_disk->disk_name,
111 			req, error ? "failed" : "done");
112 
113 	spin_lock_irqsave(q->queue_lock, flags);
114 	__blk_end_request_all(req, error);
115 	spin_unlock_irqrestore(q->queue_lock, flags);
116 }
117 
118 static void sock_shutdown(struct nbd_device *lo, int lock)
119 {
120 	/* Forcibly shutdown the socket causing all listeners
121 	 * to error
122 	 *
123 	 * FIXME: This code is duplicated from sys_shutdown, but
124 	 * there should be a more generic interface rather than
125 	 * calling socket ops directly here */
126 	if (lock)
127 		mutex_lock(&lo->tx_lock);
128 	if (lo->sock) {
129 		dev_warn(disk_to_dev(lo->disk), "shutting down socket\n");
130 		kernel_sock_shutdown(lo->sock, SHUT_RDWR);
131 		lo->sock = NULL;
132 	}
133 	if (lock)
134 		mutex_unlock(&lo->tx_lock);
135 }
136 
137 static void nbd_xmit_timeout(unsigned long arg)
138 {
139 	struct task_struct *task = (struct task_struct *)arg;
140 
141 	printk(KERN_WARNING "nbd: killing hung xmit (%s, pid: %d)\n",
142 		task->comm, task->pid);
143 	force_sig(SIGKILL, task);
144 }
145 
146 /*
147  *  Send or receive packet.
148  */
149 static int sock_xmit(struct nbd_device *lo, int send, void *buf, int size,
150 		int msg_flags)
151 {
152 	struct socket *sock = lo->sock;
153 	int result;
154 	struct msghdr msg;
155 	struct kvec iov;
156 	sigset_t blocked, oldset;
157 
158 	if (unlikely(!sock)) {
159 		dev_err(disk_to_dev(lo->disk),
160 			"Attempted %s on closed socket in sock_xmit\n",
161 			(send ? "send" : "recv"));
162 		return -EINVAL;
163 	}
164 
165 	/* Allow interception of SIGKILL only
166 	 * Don't allow other signals to interrupt the transmission */
167 	siginitsetinv(&blocked, sigmask(SIGKILL));
168 	sigprocmask(SIG_SETMASK, &blocked, &oldset);
169 
170 	do {
171 		sock->sk->sk_allocation = GFP_NOIO;
172 		iov.iov_base = buf;
173 		iov.iov_len = size;
174 		msg.msg_name = NULL;
175 		msg.msg_namelen = 0;
176 		msg.msg_control = NULL;
177 		msg.msg_controllen = 0;
178 		msg.msg_flags = msg_flags | MSG_NOSIGNAL;
179 
180 		if (send) {
181 			struct timer_list ti;
182 
183 			if (lo->xmit_timeout) {
184 				init_timer(&ti);
185 				ti.function = nbd_xmit_timeout;
186 				ti.data = (unsigned long)current;
187 				ti.expires = jiffies + lo->xmit_timeout;
188 				add_timer(&ti);
189 			}
190 			result = kernel_sendmsg(sock, &msg, &iov, 1, size);
191 			if (lo->xmit_timeout)
192 				del_timer_sync(&ti);
193 		} else
194 			result = kernel_recvmsg(sock, &msg, &iov, 1, size,
195 						msg.msg_flags);
196 
197 		if (signal_pending(current)) {
198 			siginfo_t info;
199 			printk(KERN_WARNING "nbd (pid %d: %s) got signal %d\n",
200 				task_pid_nr(current), current->comm,
201 				dequeue_signal_lock(current, &current->blocked, &info));
202 			result = -EINTR;
203 			sock_shutdown(lo, !send);
204 			break;
205 		}
206 
207 		if (result <= 0) {
208 			if (result == 0)
209 				result = -EPIPE; /* short read */
210 			break;
211 		}
212 		size -= result;
213 		buf += result;
214 	} while (size > 0);
215 
216 	sigprocmask(SIG_SETMASK, &oldset, NULL);
217 
218 	return result;
219 }
220 
221 static inline int sock_send_bvec(struct nbd_device *lo, struct bio_vec *bvec,
222 		int flags)
223 {
224 	int result;
225 	void *kaddr = kmap(bvec->bv_page);
226 	result = sock_xmit(lo, 1, kaddr + bvec->bv_offset, bvec->bv_len, flags);
227 	kunmap(bvec->bv_page);
228 	return result;
229 }
230 
231 /* always call with the tx_lock held */
232 static int nbd_send_req(struct nbd_device *lo, struct request *req)
233 {
234 	int result, flags;
235 	struct nbd_request request;
236 	unsigned long size = blk_rq_bytes(req);
237 
238 	request.magic = htonl(NBD_REQUEST_MAGIC);
239 	request.type = htonl(nbd_cmd(req));
240 	request.from = cpu_to_be64((u64)blk_rq_pos(req) << 9);
241 	request.len = htonl(size);
242 	memcpy(request.handle, &req, sizeof(req));
243 
244 	dprintk(DBG_TX, "%s: request %p: sending control (%s@%llu,%uB)\n",
245 			lo->disk->disk_name, req,
246 			nbdcmd_to_ascii(nbd_cmd(req)),
247 			(unsigned long long)blk_rq_pos(req) << 9,
248 			blk_rq_bytes(req));
249 	result = sock_xmit(lo, 1, &request, sizeof(request),
250 			(nbd_cmd(req) == NBD_CMD_WRITE) ? MSG_MORE : 0);
251 	if (result <= 0) {
252 		dev_err(disk_to_dev(lo->disk),
253 			"Send control failed (result %d)\n", result);
254 		goto error_out;
255 	}
256 
257 	if (nbd_cmd(req) == NBD_CMD_WRITE) {
258 		struct req_iterator iter;
259 		struct bio_vec *bvec;
260 		/*
261 		 * we are really probing at internals to determine
262 		 * whether to set MSG_MORE or not...
263 		 */
264 		rq_for_each_segment(bvec, req, iter) {
265 			flags = 0;
266 			if (!rq_iter_last(req, iter))
267 				flags = MSG_MORE;
268 			dprintk(DBG_TX, "%s: request %p: sending %d bytes data\n",
269 					lo->disk->disk_name, req, bvec->bv_len);
270 			result = sock_send_bvec(lo, bvec, flags);
271 			if (result <= 0) {
272 				dev_err(disk_to_dev(lo->disk),
273 					"Send data failed (result %d)\n",
274 					result);
275 				goto error_out;
276 			}
277 		}
278 	}
279 	return 0;
280 
281 error_out:
282 	return -EIO;
283 }
284 
285 static struct request *nbd_find_request(struct nbd_device *lo,
286 					struct request *xreq)
287 {
288 	struct request *req, *tmp;
289 	int err;
290 
291 	err = wait_event_interruptible(lo->active_wq, lo->active_req != xreq);
292 	if (unlikely(err))
293 		goto out;
294 
295 	spin_lock(&lo->queue_lock);
296 	list_for_each_entry_safe(req, tmp, &lo->queue_head, queuelist) {
297 		if (req != xreq)
298 			continue;
299 		list_del_init(&req->queuelist);
300 		spin_unlock(&lo->queue_lock);
301 		return req;
302 	}
303 	spin_unlock(&lo->queue_lock);
304 
305 	err = -ENOENT;
306 
307 out:
308 	return ERR_PTR(err);
309 }
310 
311 static inline int sock_recv_bvec(struct nbd_device *lo, struct bio_vec *bvec)
312 {
313 	int result;
314 	void *kaddr = kmap(bvec->bv_page);
315 	result = sock_xmit(lo, 0, kaddr + bvec->bv_offset, bvec->bv_len,
316 			MSG_WAITALL);
317 	kunmap(bvec->bv_page);
318 	return result;
319 }
320 
321 /* NULL returned = something went wrong, inform userspace */
322 static struct request *nbd_read_stat(struct nbd_device *lo)
323 {
324 	int result;
325 	struct nbd_reply reply;
326 	struct request *req;
327 
328 	reply.magic = 0;
329 	result = sock_xmit(lo, 0, &reply, sizeof(reply), MSG_WAITALL);
330 	if (result <= 0) {
331 		dev_err(disk_to_dev(lo->disk),
332 			"Receive control failed (result %d)\n", result);
333 		goto harderror;
334 	}
335 
336 	if (ntohl(reply.magic) != NBD_REPLY_MAGIC) {
337 		dev_err(disk_to_dev(lo->disk), "Wrong magic (0x%lx)\n",
338 				(unsigned long)ntohl(reply.magic));
339 		result = -EPROTO;
340 		goto harderror;
341 	}
342 
343 	req = nbd_find_request(lo, *(struct request **)reply.handle);
344 	if (IS_ERR(req)) {
345 		result = PTR_ERR(req);
346 		if (result != -ENOENT)
347 			goto harderror;
348 
349 		dev_err(disk_to_dev(lo->disk), "Unexpected reply (%p)\n",
350 			reply.handle);
351 		result = -EBADR;
352 		goto harderror;
353 	}
354 
355 	if (ntohl(reply.error)) {
356 		dev_err(disk_to_dev(lo->disk), "Other side returned error (%d)\n",
357 			ntohl(reply.error));
358 		req->errors++;
359 		return req;
360 	}
361 
362 	dprintk(DBG_RX, "%s: request %p: got reply\n",
363 			lo->disk->disk_name, req);
364 	if (nbd_cmd(req) == NBD_CMD_READ) {
365 		struct req_iterator iter;
366 		struct bio_vec *bvec;
367 
368 		rq_for_each_segment(bvec, req, iter) {
369 			result = sock_recv_bvec(lo, bvec);
370 			if (result <= 0) {
371 				dev_err(disk_to_dev(lo->disk), "Receive data failed (result %d)\n",
372 					result);
373 				req->errors++;
374 				return req;
375 			}
376 			dprintk(DBG_RX, "%s: request %p: got %d bytes data\n",
377 				lo->disk->disk_name, req, bvec->bv_len);
378 		}
379 	}
380 	return req;
381 harderror:
382 	lo->harderror = result;
383 	return NULL;
384 }
385 
386 static ssize_t pid_show(struct device *dev,
387 			struct device_attribute *attr, char *buf)
388 {
389 	struct gendisk *disk = dev_to_disk(dev);
390 
391 	return sprintf(buf, "%ld\n",
392 		(long) ((struct nbd_device *)disk->private_data)->pid);
393 }
394 
395 static struct device_attribute pid_attr = {
396 	.attr = { .name = "pid", .mode = S_IRUGO},
397 	.show = pid_show,
398 };
399 
400 static int nbd_do_it(struct nbd_device *lo)
401 {
402 	struct request *req;
403 	int ret;
404 
405 	BUG_ON(lo->magic != LO_MAGIC);
406 
407 	lo->pid = task_pid_nr(current);
408 	ret = device_create_file(disk_to_dev(lo->disk), &pid_attr);
409 	if (ret) {
410 		dev_err(disk_to_dev(lo->disk), "device_create_file failed!\n");
411 		lo->pid = 0;
412 		return ret;
413 	}
414 
415 	while ((req = nbd_read_stat(lo)) != NULL)
416 		nbd_end_request(req);
417 
418 	device_remove_file(disk_to_dev(lo->disk), &pid_attr);
419 	lo->pid = 0;
420 	return 0;
421 }
422 
423 static void nbd_clear_que(struct nbd_device *lo)
424 {
425 	struct request *req;
426 
427 	BUG_ON(lo->magic != LO_MAGIC);
428 
429 	/*
430 	 * Because we have set lo->sock to NULL under the tx_lock, all
431 	 * modifications to the list must have completed by now.  For
432 	 * the same reason, the active_req must be NULL.
433 	 *
434 	 * As a consequence, we don't need to take the spin lock while
435 	 * purging the list here.
436 	 */
437 	BUG_ON(lo->sock);
438 	BUG_ON(lo->active_req);
439 
440 	while (!list_empty(&lo->queue_head)) {
441 		req = list_entry(lo->queue_head.next, struct request,
442 				 queuelist);
443 		list_del_init(&req->queuelist);
444 		req->errors++;
445 		nbd_end_request(req);
446 	}
447 }
448 
449 
450 static void nbd_handle_req(struct nbd_device *lo, struct request *req)
451 {
452 	if (req->cmd_type != REQ_TYPE_FS)
453 		goto error_out;
454 
455 	nbd_cmd(req) = NBD_CMD_READ;
456 	if (rq_data_dir(req) == WRITE) {
457 		nbd_cmd(req) = NBD_CMD_WRITE;
458 		if (lo->flags & NBD_READ_ONLY) {
459 			dev_err(disk_to_dev(lo->disk),
460 				"Write on read-only\n");
461 			goto error_out;
462 		}
463 	}
464 
465 	req->errors = 0;
466 
467 	mutex_lock(&lo->tx_lock);
468 	if (unlikely(!lo->sock)) {
469 		mutex_unlock(&lo->tx_lock);
470 		dev_err(disk_to_dev(lo->disk),
471 			"Attempted send on closed socket\n");
472 		goto error_out;
473 	}
474 
475 	lo->active_req = req;
476 
477 	if (nbd_send_req(lo, req) != 0) {
478 		dev_err(disk_to_dev(lo->disk), "Request send failed\n");
479 		req->errors++;
480 		nbd_end_request(req);
481 	} else {
482 		spin_lock(&lo->queue_lock);
483 		list_add(&req->queuelist, &lo->queue_head);
484 		spin_unlock(&lo->queue_lock);
485 	}
486 
487 	lo->active_req = NULL;
488 	mutex_unlock(&lo->tx_lock);
489 	wake_up_all(&lo->active_wq);
490 
491 	return;
492 
493 error_out:
494 	req->errors++;
495 	nbd_end_request(req);
496 }
497 
498 static int nbd_thread(void *data)
499 {
500 	struct nbd_device *lo = data;
501 	struct request *req;
502 
503 	set_user_nice(current, -20);
504 	while (!kthread_should_stop() || !list_empty(&lo->waiting_queue)) {
505 		/* wait for something to do */
506 		wait_event_interruptible(lo->waiting_wq,
507 					 kthread_should_stop() ||
508 					 !list_empty(&lo->waiting_queue));
509 
510 		/* extract request */
511 		if (list_empty(&lo->waiting_queue))
512 			continue;
513 
514 		spin_lock_irq(&lo->queue_lock);
515 		req = list_entry(lo->waiting_queue.next, struct request,
516 				 queuelist);
517 		list_del_init(&req->queuelist);
518 		spin_unlock_irq(&lo->queue_lock);
519 
520 		/* handle request */
521 		nbd_handle_req(lo, req);
522 	}
523 	return 0;
524 }
525 
526 /*
527  * We always wait for result of write, for now. It would be nice to make it optional
528  * in future
529  * if ((rq_data_dir(req) == WRITE) && (lo->flags & NBD_WRITE_NOCHK))
530  *   { printk( "Warning: Ignoring result!\n"); nbd_end_request( req ); }
531  */
532 
533 static void do_nbd_request(struct request_queue *q)
534 {
535 	struct request *req;
536 
537 	while ((req = blk_fetch_request(q)) != NULL) {
538 		struct nbd_device *lo;
539 
540 		spin_unlock_irq(q->queue_lock);
541 
542 		dprintk(DBG_BLKDEV, "%s: request %p: dequeued (flags=%x)\n",
543 				req->rq_disk->disk_name, req, req->cmd_type);
544 
545 		lo = req->rq_disk->private_data;
546 
547 		BUG_ON(lo->magic != LO_MAGIC);
548 
549 		if (unlikely(!lo->sock)) {
550 			dev_err(disk_to_dev(lo->disk),
551 				"Attempted send on closed socket\n");
552 			req->errors++;
553 			nbd_end_request(req);
554 			spin_lock_irq(q->queue_lock);
555 			continue;
556 		}
557 
558 		spin_lock_irq(&lo->queue_lock);
559 		list_add_tail(&req->queuelist, &lo->waiting_queue);
560 		spin_unlock_irq(&lo->queue_lock);
561 
562 		wake_up(&lo->waiting_wq);
563 
564 		spin_lock_irq(q->queue_lock);
565 	}
566 }
567 
568 /* Must be called with tx_lock held */
569 
570 static int __nbd_ioctl(struct block_device *bdev, struct nbd_device *lo,
571 		       unsigned int cmd, unsigned long arg)
572 {
573 	switch (cmd) {
574 	case NBD_DISCONNECT: {
575 		struct request sreq;
576 
577 		dev_info(disk_to_dev(lo->disk), "NBD_DISCONNECT\n");
578 
579 		blk_rq_init(NULL, &sreq);
580 		sreq.cmd_type = REQ_TYPE_SPECIAL;
581 		nbd_cmd(&sreq) = NBD_CMD_DISC;
582 		if (!lo->sock)
583 			return -EINVAL;
584 		nbd_send_req(lo, &sreq);
585                 return 0;
586 	}
587 
588 	case NBD_CLEAR_SOCK: {
589 		struct file *file;
590 
591 		lo->sock = NULL;
592 		file = lo->file;
593 		lo->file = NULL;
594 		nbd_clear_que(lo);
595 		BUG_ON(!list_empty(&lo->queue_head));
596 		if (file)
597 			fput(file);
598 		return 0;
599 	}
600 
601 	case NBD_SET_SOCK: {
602 		struct file *file;
603 		if (lo->file)
604 			return -EBUSY;
605 		file = fget(arg);
606 		if (file) {
607 			struct inode *inode = file->f_path.dentry->d_inode;
608 			if (S_ISSOCK(inode->i_mode)) {
609 				lo->file = file;
610 				lo->sock = SOCKET_I(inode);
611 				if (max_part > 0)
612 					bdev->bd_invalidated = 1;
613 				return 0;
614 			} else {
615 				fput(file);
616 			}
617 		}
618 		return -EINVAL;
619 	}
620 
621 	case NBD_SET_BLKSIZE:
622 		lo->blksize = arg;
623 		lo->bytesize &= ~(lo->blksize-1);
624 		bdev->bd_inode->i_size = lo->bytesize;
625 		set_blocksize(bdev, lo->blksize);
626 		set_capacity(lo->disk, lo->bytesize >> 9);
627 		return 0;
628 
629 	case NBD_SET_SIZE:
630 		lo->bytesize = arg & ~(lo->blksize-1);
631 		bdev->bd_inode->i_size = lo->bytesize;
632 		set_blocksize(bdev, lo->blksize);
633 		set_capacity(lo->disk, lo->bytesize >> 9);
634 		return 0;
635 
636 	case NBD_SET_TIMEOUT:
637 		lo->xmit_timeout = arg * HZ;
638 		return 0;
639 
640 	case NBD_SET_SIZE_BLOCKS:
641 		lo->bytesize = ((u64) arg) * lo->blksize;
642 		bdev->bd_inode->i_size = lo->bytesize;
643 		set_blocksize(bdev, lo->blksize);
644 		set_capacity(lo->disk, lo->bytesize >> 9);
645 		return 0;
646 
647 	case NBD_DO_IT: {
648 		struct task_struct *thread;
649 		struct file *file;
650 		int error;
651 
652 		if (lo->pid)
653 			return -EBUSY;
654 		if (!lo->file)
655 			return -EINVAL;
656 
657 		mutex_unlock(&lo->tx_lock);
658 
659 		thread = kthread_create(nbd_thread, lo, lo->disk->disk_name);
660 		if (IS_ERR(thread)) {
661 			mutex_lock(&lo->tx_lock);
662 			return PTR_ERR(thread);
663 		}
664 		wake_up_process(thread);
665 		error = nbd_do_it(lo);
666 		kthread_stop(thread);
667 
668 		mutex_lock(&lo->tx_lock);
669 		if (error)
670 			return error;
671 		sock_shutdown(lo, 0);
672 		file = lo->file;
673 		lo->file = NULL;
674 		nbd_clear_que(lo);
675 		dev_warn(disk_to_dev(lo->disk), "queue cleared\n");
676 		if (file)
677 			fput(file);
678 		lo->bytesize = 0;
679 		bdev->bd_inode->i_size = 0;
680 		set_capacity(lo->disk, 0);
681 		if (max_part > 0)
682 			ioctl_by_bdev(bdev, BLKRRPART, 0);
683 		return lo->harderror;
684 	}
685 
686 	case NBD_CLEAR_QUE:
687 		/*
688 		 * This is for compatibility only.  The queue is always cleared
689 		 * by NBD_DO_IT or NBD_CLEAR_SOCK.
690 		 */
691 		BUG_ON(!lo->sock && !list_empty(&lo->queue_head));
692 		return 0;
693 
694 	case NBD_PRINT_DEBUG:
695 		dev_info(disk_to_dev(lo->disk),
696 			"next = %p, prev = %p, head = %p\n",
697 			lo->queue_head.next, lo->queue_head.prev,
698 			&lo->queue_head);
699 		return 0;
700 	}
701 	return -ENOTTY;
702 }
703 
704 static int nbd_ioctl(struct block_device *bdev, fmode_t mode,
705 		     unsigned int cmd, unsigned long arg)
706 {
707 	struct nbd_device *lo = bdev->bd_disk->private_data;
708 	int error;
709 
710 	if (!capable(CAP_SYS_ADMIN))
711 		return -EPERM;
712 
713 	BUG_ON(lo->magic != LO_MAGIC);
714 
715 	/* Anyone capable of this syscall can do *real bad* things */
716 	dprintk(DBG_IOCTL, "%s: nbd_ioctl cmd=%s(0x%x) arg=%lu\n",
717 			lo->disk->disk_name, ioctl_cmd_to_ascii(cmd), cmd, arg);
718 
719 	mutex_lock(&lo->tx_lock);
720 	error = __nbd_ioctl(bdev, lo, cmd, arg);
721 	mutex_unlock(&lo->tx_lock);
722 
723 	return error;
724 }
725 
726 static const struct block_device_operations nbd_fops =
727 {
728 	.owner =	THIS_MODULE,
729 	.ioctl =	nbd_ioctl,
730 };
731 
732 /*
733  * And here should be modules and kernel interface
734  *  (Just smiley confuses emacs :-)
735  */
736 
737 static int __init nbd_init(void)
738 {
739 	int err = -ENOMEM;
740 	int i;
741 	int part_shift;
742 
743 	BUILD_BUG_ON(sizeof(struct nbd_request) != 28);
744 
745 	if (max_part < 0) {
746 		printk(KERN_ERR "nbd: max_part must be >= 0\n");
747 		return -EINVAL;
748 	}
749 
750 	nbd_dev = kcalloc(nbds_max, sizeof(*nbd_dev), GFP_KERNEL);
751 	if (!nbd_dev)
752 		return -ENOMEM;
753 
754 	part_shift = 0;
755 	if (max_part > 0) {
756 		part_shift = fls(max_part);
757 
758 		/*
759 		 * Adjust max_part according to part_shift as it is exported
760 		 * to user space so that user can know the max number of
761 		 * partition kernel should be able to manage.
762 		 *
763 		 * Note that -1 is required because partition 0 is reserved
764 		 * for the whole disk.
765 		 */
766 		max_part = (1UL << part_shift) - 1;
767 	}
768 
769 	if ((1UL << part_shift) > DISK_MAX_PARTS)
770 		return -EINVAL;
771 
772 	if (nbds_max > 1UL << (MINORBITS - part_shift))
773 		return -EINVAL;
774 
775 	for (i = 0; i < nbds_max; i++) {
776 		struct gendisk *disk = alloc_disk(1 << part_shift);
777 		if (!disk)
778 			goto out;
779 		nbd_dev[i].disk = disk;
780 		/*
781 		 * The new linux 2.5 block layer implementation requires
782 		 * every gendisk to have its very own request_queue struct.
783 		 * These structs are big so we dynamically allocate them.
784 		 */
785 		disk->queue = blk_init_queue(do_nbd_request, &nbd_lock);
786 		if (!disk->queue) {
787 			put_disk(disk);
788 			goto out;
789 		}
790 		/*
791 		 * Tell the block layer that we are not a rotational device
792 		 */
793 		queue_flag_set_unlocked(QUEUE_FLAG_NONROT, disk->queue);
794 	}
795 
796 	if (register_blkdev(NBD_MAJOR, "nbd")) {
797 		err = -EIO;
798 		goto out;
799 	}
800 
801 	printk(KERN_INFO "nbd: registered device at major %d\n", NBD_MAJOR);
802 	dprintk(DBG_INIT, "nbd: debugflags=0x%x\n", debugflags);
803 
804 	for (i = 0; i < nbds_max; i++) {
805 		struct gendisk *disk = nbd_dev[i].disk;
806 		nbd_dev[i].file = NULL;
807 		nbd_dev[i].magic = LO_MAGIC;
808 		nbd_dev[i].flags = 0;
809 		INIT_LIST_HEAD(&nbd_dev[i].waiting_queue);
810 		spin_lock_init(&nbd_dev[i].queue_lock);
811 		INIT_LIST_HEAD(&nbd_dev[i].queue_head);
812 		mutex_init(&nbd_dev[i].tx_lock);
813 		init_waitqueue_head(&nbd_dev[i].active_wq);
814 		init_waitqueue_head(&nbd_dev[i].waiting_wq);
815 		nbd_dev[i].blksize = 1024;
816 		nbd_dev[i].bytesize = 0;
817 		disk->major = NBD_MAJOR;
818 		disk->first_minor = i << part_shift;
819 		disk->fops = &nbd_fops;
820 		disk->private_data = &nbd_dev[i];
821 		sprintf(disk->disk_name, "nbd%d", i);
822 		set_capacity(disk, 0);
823 		add_disk(disk);
824 	}
825 
826 	return 0;
827 out:
828 	while (i--) {
829 		blk_cleanup_queue(nbd_dev[i].disk->queue);
830 		put_disk(nbd_dev[i].disk);
831 	}
832 	kfree(nbd_dev);
833 	return err;
834 }
835 
836 static void __exit nbd_cleanup(void)
837 {
838 	int i;
839 	for (i = 0; i < nbds_max; i++) {
840 		struct gendisk *disk = nbd_dev[i].disk;
841 		nbd_dev[i].magic = 0;
842 		if (disk) {
843 			del_gendisk(disk);
844 			blk_cleanup_queue(disk->queue);
845 			put_disk(disk);
846 		}
847 	}
848 	unregister_blkdev(NBD_MAJOR, "nbd");
849 	kfree(nbd_dev);
850 	printk(KERN_INFO "nbd: unregistered device at major %d\n", NBD_MAJOR);
851 }
852 
853 module_init(nbd_init);
854 module_exit(nbd_cleanup);
855 
856 MODULE_DESCRIPTION("Network Block Device");
857 MODULE_LICENSE("GPL");
858 
859 module_param(nbds_max, int, 0444);
860 MODULE_PARM_DESC(nbds_max, "number of network block devices to initialize (default: 16)");
861 module_param(max_part, int, 0444);
862 MODULE_PARM_DESC(max_part, "number of partitions per device (default: 0)");
863 #ifndef NDEBUG
864 module_param(debugflags, int, 0644);
865 MODULE_PARM_DESC(debugflags, "flags for controlling debug output");
866 #endif
867