xref: /linux/fs/smb/server/transport_rdma.c (revision 382bd6a792836875da555fe9a2b51222b813fed1)
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  *   Copyright (C) 2017, Microsoft Corporation.
4  *   Copyright (C) 2018, LG Electronics.
5  *
6  *   Author(s): Long Li <longli@microsoft.com>,
7  *		Hyunchul Lee <hyc.lee@gmail.com>
8  */
9 
10 #define SUBMOD_NAME	"smb_direct"
11 
12 #include <linux/kthread.h>
13 #include <linux/list.h>
14 #include <linux/mempool.h>
15 #include <linux/highmem.h>
16 #include <linux/scatterlist.h>
17 #include <linux/string_choices.h>
18 #include <rdma/ib_verbs.h>
19 #include <rdma/rdma_cm.h>
20 #include <rdma/rw.h>
21 
22 #include "glob.h"
23 #include "connection.h"
24 #include "smb_common.h"
25 #include "../common/smb2status.h"
26 #include "../common/smbdirect/smbdirect.h"
27 #include "../common/smbdirect/smbdirect_pdu.h"
28 #include "../common/smbdirect/smbdirect_socket.h"
29 #include "transport_rdma.h"
30 
31 #define SMB_DIRECT_PORT_IWARP		5445
32 #define SMB_DIRECT_PORT_INFINIBAND	445
33 
34 #define SMB_DIRECT_VERSION_LE		cpu_to_le16(SMBDIRECT_V1)
35 
36 /* SMB_DIRECT negotiation timeout (for the server) in seconds */
37 #define SMB_DIRECT_NEGOTIATE_TIMEOUT		5
38 
39 /* The timeout to wait for a keepalive message from peer in seconds */
40 #define SMB_DIRECT_KEEPALIVE_SEND_INTERVAL	120
41 
42 /* The timeout to wait for a keepalive message from peer in seconds */
43 #define SMB_DIRECT_KEEPALIVE_RECV_TIMEOUT	5
44 
45 /*
46  * Default maximum number of RDMA read/write outstanding on this connection
47  * This value is possibly decreased during QP creation on hardware limit
48  */
49 #define SMB_DIRECT_CM_INITIATOR_DEPTH		8
50 
51 /* Maximum number of retries on data transfer operations */
52 #define SMB_DIRECT_CM_RETRY			6
53 /* No need to retry on Receiver Not Ready since SMB_DIRECT manages credits */
54 #define SMB_DIRECT_CM_RNR_RETRY		0
55 
56 /*
57  * User configurable initial values per SMB_DIRECT transport connection
58  * as defined in [MS-SMBD] 3.1.1.1
59  * Those may change after a SMB_DIRECT negotiation
60  */
61 
62 /* Set 445 port to SMB Direct port by default */
63 static int smb_direct_port = SMB_DIRECT_PORT_INFINIBAND;
64 
65 /* The local peer's maximum number of credits to grant to the peer */
66 static int smb_direct_receive_credit_max = 255;
67 
68 /* The remote peer's credit request of local peer */
69 static int smb_direct_send_credit_target = 255;
70 
71 /* The maximum single message size can be sent to remote peer */
72 static int smb_direct_max_send_size = 1364;
73 
74 /*  The maximum fragmented upper-layer payload receive size supported */
75 static int smb_direct_max_fragmented_recv_size = 1024 * 1024;
76 
77 /*  The maximum single-message size which can be received */
78 static int smb_direct_max_receive_size = 1364;
79 
80 static int smb_direct_max_read_write_size = SMBD_DEFAULT_IOSIZE;
81 
82 static LIST_HEAD(smb_direct_device_list);
83 static DEFINE_RWLOCK(smb_direct_device_lock);
84 
85 struct smb_direct_device {
86 	struct ib_device	*ib_dev;
87 	struct list_head	list;
88 };
89 
90 static struct smb_direct_listener {
91 	struct rdma_cm_id	*cm_id;
92 } smb_direct_listener;
93 
94 static struct workqueue_struct *smb_direct_wq;
95 
96 struct smb_direct_transport {
97 	struct ksmbd_transport	transport;
98 
99 	struct smbdirect_socket socket;
100 };
101 
102 #define KSMBD_TRANS(t) (&(t)->transport)
103 #define SMBD_TRANS(t)	(container_of(t, \
104 				struct smb_direct_transport, transport))
105 
106 static const struct ksmbd_transport_ops ksmbd_smb_direct_transport_ops;
107 
108 void init_smbd_max_io_size(unsigned int sz)
109 {
110 	sz = clamp_val(sz, SMBD_MIN_IOSIZE, SMBD_MAX_IOSIZE);
111 	smb_direct_max_read_write_size = sz;
112 }
113 
114 unsigned int get_smbd_max_read_write_size(struct ksmbd_transport *kt)
115 {
116 	struct smb_direct_transport *t;
117 	struct smbdirect_socket *sc;
118 	struct smbdirect_socket_parameters *sp;
119 
120 	if (kt->ops != &ksmbd_smb_direct_transport_ops)
121 		return 0;
122 
123 	t = SMBD_TRANS(kt);
124 	sc = &t->socket;
125 	sp = &sc->parameters;
126 
127 	return sp->max_read_write_size;
128 }
129 
130 static inline int get_buf_page_count(void *buf, int size)
131 {
132 	return DIV_ROUND_UP((uintptr_t)buf + size, PAGE_SIZE) -
133 		(uintptr_t)buf / PAGE_SIZE;
134 }
135 
136 static void smb_direct_destroy_pools(struct smbdirect_socket *sc);
137 static void smb_direct_post_recv_credits(struct work_struct *work);
138 static int smb_direct_post_send_data(struct smbdirect_socket *sc,
139 				     struct smbdirect_send_batch *send_ctx,
140 				     struct kvec *iov, int niov,
141 				     int remaining_data_length);
142 
143 static inline void
144 *smbdirect_recv_io_payload(struct smbdirect_recv_io *recvmsg)
145 {
146 	return (void *)recvmsg->packet;
147 }
148 
149 static struct
150 smbdirect_recv_io *get_free_recvmsg(struct smbdirect_socket *sc)
151 {
152 	struct smbdirect_recv_io *recvmsg = NULL;
153 	unsigned long flags;
154 
155 	spin_lock_irqsave(&sc->recv_io.free.lock, flags);
156 	if (!list_empty(&sc->recv_io.free.list)) {
157 		recvmsg = list_first_entry(&sc->recv_io.free.list,
158 					   struct smbdirect_recv_io,
159 					   list);
160 		list_del(&recvmsg->list);
161 	}
162 	spin_unlock_irqrestore(&sc->recv_io.free.lock, flags);
163 	return recvmsg;
164 }
165 
166 static void put_recvmsg(struct smbdirect_socket *sc,
167 			struct smbdirect_recv_io *recvmsg)
168 {
169 	unsigned long flags;
170 
171 	if (likely(recvmsg->sge.length != 0)) {
172 		ib_dma_unmap_single(sc->ib.dev,
173 				    recvmsg->sge.addr,
174 				    recvmsg->sge.length,
175 				    DMA_FROM_DEVICE);
176 		recvmsg->sge.length = 0;
177 	}
178 
179 	spin_lock_irqsave(&sc->recv_io.free.lock, flags);
180 	list_add(&recvmsg->list, &sc->recv_io.free.list);
181 	spin_unlock_irqrestore(&sc->recv_io.free.lock, flags);
182 
183 	queue_work(sc->workqueue, &sc->recv_io.posted.refill_work);
184 }
185 
186 static void enqueue_reassembly(struct smbdirect_socket *sc,
187 			       struct smbdirect_recv_io *recvmsg,
188 			       int data_length)
189 {
190 	unsigned long flags;
191 
192 	spin_lock_irqsave(&sc->recv_io.reassembly.lock, flags);
193 	list_add_tail(&recvmsg->list, &sc->recv_io.reassembly.list);
194 	sc->recv_io.reassembly.queue_length++;
195 	/*
196 	 * Make sure reassembly_data_length is updated after list and
197 	 * reassembly_queue_length are updated. On the dequeue side
198 	 * reassembly_data_length is checked without a lock to determine
199 	 * if reassembly_queue_length and list is up to date
200 	 */
201 	virt_wmb();
202 	sc->recv_io.reassembly.data_length += data_length;
203 	spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
204 }
205 
206 static struct smbdirect_recv_io *get_first_reassembly(struct smbdirect_socket *sc)
207 {
208 	if (!list_empty(&sc->recv_io.reassembly.list))
209 		return list_first_entry(&sc->recv_io.reassembly.list,
210 				struct smbdirect_recv_io, list);
211 	else
212 		return NULL;
213 }
214 
215 static void smb_direct_disconnect_wake_up_all(struct smbdirect_socket *sc)
216 {
217 	/*
218 	 * Wake up all waiters in all wait queues
219 	 * in order to notice the broken connection.
220 	 */
221 	wake_up_all(&sc->status_wait);
222 	wake_up_all(&sc->send_io.lcredits.wait_queue);
223 	wake_up_all(&sc->send_io.credits.wait_queue);
224 	wake_up_all(&sc->send_io.pending.zero_wait_queue);
225 	wake_up_all(&sc->recv_io.reassembly.wait_queue);
226 	wake_up_all(&sc->rw_io.credits.wait_queue);
227 }
228 
229 static void smb_direct_disconnect_rdma_work(struct work_struct *work)
230 {
231 	struct smbdirect_socket *sc =
232 		container_of(work, struct smbdirect_socket, disconnect_work);
233 
234 	/*
235 	 * make sure this and other work is not queued again
236 	 * but here we don't block and avoid
237 	 * disable[_delayed]_work_sync()
238 	 */
239 	disable_work(&sc->disconnect_work);
240 	disable_work(&sc->recv_io.posted.refill_work);
241 	disable_delayed_work(&sc->idle.timer_work);
242 	disable_work(&sc->idle.immediate_work);
243 
244 	if (sc->first_error == 0)
245 		sc->first_error = -ECONNABORTED;
246 
247 	switch (sc->status) {
248 	case SMBDIRECT_SOCKET_NEGOTIATE_NEEDED:
249 	case SMBDIRECT_SOCKET_NEGOTIATE_RUNNING:
250 	case SMBDIRECT_SOCKET_NEGOTIATE_FAILED:
251 	case SMBDIRECT_SOCKET_CONNECTED:
252 	case SMBDIRECT_SOCKET_ERROR:
253 		sc->status = SMBDIRECT_SOCKET_DISCONNECTING;
254 		rdma_disconnect(sc->rdma.cm_id);
255 		break;
256 
257 	case SMBDIRECT_SOCKET_CREATED:
258 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_NEEDED:
259 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_RUNNING:
260 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_FAILED:
261 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_NEEDED:
262 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_RUNNING:
263 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_FAILED:
264 	case SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED:
265 	case SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING:
266 	case SMBDIRECT_SOCKET_RDMA_CONNECT_FAILED:
267 		/*
268 		 * rdma_accept() never reached
269 		 * RDMA_CM_EVENT_ESTABLISHED
270 		 */
271 		sc->status = SMBDIRECT_SOCKET_DISCONNECTED;
272 		break;
273 
274 	case SMBDIRECT_SOCKET_DISCONNECTING:
275 	case SMBDIRECT_SOCKET_DISCONNECTED:
276 	case SMBDIRECT_SOCKET_DESTROYED:
277 		break;
278 	}
279 
280 	/*
281 	 * Wake up all waiters in all wait queues
282 	 * in order to notice the broken connection.
283 	 */
284 	smb_direct_disconnect_wake_up_all(sc);
285 }
286 
287 static void
288 smb_direct_disconnect_rdma_connection(struct smbdirect_socket *sc)
289 {
290 	/*
291 	 * make sure other work (than disconnect_work) is
292 	 * not queued again but here we don't block and avoid
293 	 * disable[_delayed]_work_sync()
294 	 */
295 	disable_work(&sc->recv_io.posted.refill_work);
296 	disable_work(&sc->idle.immediate_work);
297 	disable_delayed_work(&sc->idle.timer_work);
298 
299 	if (sc->first_error == 0)
300 		sc->first_error = -ECONNABORTED;
301 
302 	switch (sc->status) {
303 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_FAILED:
304 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_FAILED:
305 	case SMBDIRECT_SOCKET_RDMA_CONNECT_FAILED:
306 	case SMBDIRECT_SOCKET_NEGOTIATE_FAILED:
307 	case SMBDIRECT_SOCKET_ERROR:
308 	case SMBDIRECT_SOCKET_DISCONNECTING:
309 	case SMBDIRECT_SOCKET_DISCONNECTED:
310 	case SMBDIRECT_SOCKET_DESTROYED:
311 		/*
312 		 * Keep the current error status
313 		 */
314 		break;
315 
316 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_NEEDED:
317 	case SMBDIRECT_SOCKET_RESOLVE_ADDR_RUNNING:
318 		sc->status = SMBDIRECT_SOCKET_RESOLVE_ADDR_FAILED;
319 		break;
320 
321 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_NEEDED:
322 	case SMBDIRECT_SOCKET_RESOLVE_ROUTE_RUNNING:
323 		sc->status = SMBDIRECT_SOCKET_RESOLVE_ROUTE_FAILED;
324 		break;
325 
326 	case SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED:
327 	case SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING:
328 		sc->status = SMBDIRECT_SOCKET_RDMA_CONNECT_FAILED;
329 		break;
330 
331 	case SMBDIRECT_SOCKET_NEGOTIATE_NEEDED:
332 	case SMBDIRECT_SOCKET_NEGOTIATE_RUNNING:
333 		sc->status = SMBDIRECT_SOCKET_NEGOTIATE_FAILED;
334 		break;
335 
336 	case SMBDIRECT_SOCKET_CREATED:
337 	case SMBDIRECT_SOCKET_CONNECTED:
338 		sc->status = SMBDIRECT_SOCKET_ERROR;
339 		break;
340 	}
341 
342 	/*
343 	 * Wake up all waiters in all wait queues
344 	 * in order to notice the broken connection.
345 	 */
346 	smb_direct_disconnect_wake_up_all(sc);
347 
348 	queue_work(sc->workqueue, &sc->disconnect_work);
349 }
350 
351 static void smb_direct_send_immediate_work(struct work_struct *work)
352 {
353 	struct smbdirect_socket *sc =
354 		container_of(work, struct smbdirect_socket, idle.immediate_work);
355 
356 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
357 		return;
358 
359 	smb_direct_post_send_data(sc, NULL, NULL, 0, 0);
360 }
361 
362 static void smb_direct_idle_connection_timer(struct work_struct *work)
363 {
364 	struct smbdirect_socket *sc =
365 		container_of(work, struct smbdirect_socket, idle.timer_work.work);
366 	struct smbdirect_socket_parameters *sp = &sc->parameters;
367 
368 	if (sc->idle.keepalive != SMBDIRECT_KEEPALIVE_NONE) {
369 		smb_direct_disconnect_rdma_connection(sc);
370 		return;
371 	}
372 
373 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
374 		return;
375 
376 	/*
377 	 * Now use the keepalive timeout (instead of keepalive interval)
378 	 * in order to wait for a response
379 	 */
380 	sc->idle.keepalive = SMBDIRECT_KEEPALIVE_PENDING;
381 	mod_delayed_work(sc->workqueue, &sc->idle.timer_work,
382 			 msecs_to_jiffies(sp->keepalive_timeout_msec));
383 	queue_work(sc->workqueue, &sc->idle.immediate_work);
384 }
385 
386 static struct smb_direct_transport *alloc_transport(struct rdma_cm_id *cm_id)
387 {
388 	struct smb_direct_transport *t;
389 	struct smbdirect_socket *sc;
390 	struct smbdirect_socket_parameters *sp;
391 	struct ksmbd_conn *conn;
392 
393 	t = kzalloc(sizeof(*t), KSMBD_DEFAULT_GFP);
394 	if (!t)
395 		return NULL;
396 	sc = &t->socket;
397 	smbdirect_socket_init(sc);
398 	sp = &sc->parameters;
399 
400 	sc->workqueue = smb_direct_wq;
401 
402 	INIT_WORK(&sc->disconnect_work, smb_direct_disconnect_rdma_work);
403 
404 	sp->negotiate_timeout_msec = SMB_DIRECT_NEGOTIATE_TIMEOUT * 1000;
405 	sp->initiator_depth = SMB_DIRECT_CM_INITIATOR_DEPTH;
406 	sp->responder_resources = 1;
407 	sp->recv_credit_max = smb_direct_receive_credit_max;
408 	sp->send_credit_target = smb_direct_send_credit_target;
409 	sp->max_send_size = smb_direct_max_send_size;
410 	sp->max_fragmented_recv_size = smb_direct_max_fragmented_recv_size;
411 	sp->max_recv_size = smb_direct_max_receive_size;
412 	sp->max_read_write_size = smb_direct_max_read_write_size;
413 	sp->keepalive_interval_msec = SMB_DIRECT_KEEPALIVE_SEND_INTERVAL * 1000;
414 	sp->keepalive_timeout_msec = SMB_DIRECT_KEEPALIVE_RECV_TIMEOUT * 1000;
415 
416 	sc->rdma.cm_id = cm_id;
417 	cm_id->context = sc;
418 
419 	sc->ib.dev = sc->rdma.cm_id->device;
420 
421 	INIT_WORK(&sc->recv_io.posted.refill_work,
422 		  smb_direct_post_recv_credits);
423 	INIT_WORK(&sc->idle.immediate_work, smb_direct_send_immediate_work);
424 	INIT_DELAYED_WORK(&sc->idle.timer_work, smb_direct_idle_connection_timer);
425 
426 	conn = ksmbd_conn_alloc();
427 	if (!conn)
428 		goto err;
429 
430 	down_write(&conn_list_lock);
431 	hash_add(conn_list, &conn->hlist, 0);
432 	up_write(&conn_list_lock);
433 
434 	conn->transport = KSMBD_TRANS(t);
435 	KSMBD_TRANS(t)->conn = conn;
436 	KSMBD_TRANS(t)->ops = &ksmbd_smb_direct_transport_ops;
437 	return t;
438 err:
439 	kfree(t);
440 	return NULL;
441 }
442 
443 static void smb_direct_free_transport(struct ksmbd_transport *kt)
444 {
445 	kfree(SMBD_TRANS(kt));
446 }
447 
448 static void free_transport(struct smb_direct_transport *t)
449 {
450 	struct smbdirect_socket *sc = &t->socket;
451 	struct smbdirect_recv_io *recvmsg;
452 
453 	disable_work_sync(&sc->disconnect_work);
454 	if (sc->status < SMBDIRECT_SOCKET_DISCONNECTING)
455 		smb_direct_disconnect_rdma_work(&sc->disconnect_work);
456 	if (sc->status < SMBDIRECT_SOCKET_DISCONNECTED)
457 		wait_event(sc->status_wait, sc->status == SMBDIRECT_SOCKET_DISCONNECTED);
458 
459 	/*
460 	 * Wake up all waiters in all wait queues
461 	 * in order to notice the broken connection.
462 	 *
463 	 * Most likely this was already called via
464 	 * smb_direct_disconnect_rdma_work(), but call it again...
465 	 */
466 	smb_direct_disconnect_wake_up_all(sc);
467 
468 	disable_work_sync(&sc->recv_io.posted.refill_work);
469 	disable_delayed_work_sync(&sc->idle.timer_work);
470 	disable_work_sync(&sc->idle.immediate_work);
471 
472 	if (sc->ib.qp) {
473 		ib_drain_qp(sc->ib.qp);
474 		sc->ib.qp = NULL;
475 		rdma_destroy_qp(sc->rdma.cm_id);
476 	}
477 
478 	ksmbd_debug(RDMA, "drain the reassembly queue\n");
479 	do {
480 		unsigned long flags;
481 
482 		spin_lock_irqsave(&sc->recv_io.reassembly.lock, flags);
483 		recvmsg = get_first_reassembly(sc);
484 		if (recvmsg) {
485 			list_del(&recvmsg->list);
486 			spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
487 			put_recvmsg(sc, recvmsg);
488 		} else {
489 			spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
490 		}
491 	} while (recvmsg);
492 	sc->recv_io.reassembly.data_length = 0;
493 
494 	if (sc->ib.send_cq)
495 		ib_free_cq(sc->ib.send_cq);
496 	if (sc->ib.recv_cq)
497 		ib_free_cq(sc->ib.recv_cq);
498 	if (sc->ib.pd)
499 		ib_dealloc_pd(sc->ib.pd);
500 	if (sc->rdma.cm_id)
501 		rdma_destroy_id(sc->rdma.cm_id);
502 
503 	smb_direct_destroy_pools(sc);
504 	ksmbd_conn_free(KSMBD_TRANS(t)->conn);
505 }
506 
507 static struct smbdirect_send_io
508 *smb_direct_alloc_sendmsg(struct smbdirect_socket *sc)
509 {
510 	struct smbdirect_send_io *msg;
511 
512 	msg = mempool_alloc(sc->send_io.mem.pool, KSMBD_DEFAULT_GFP);
513 	if (!msg)
514 		return ERR_PTR(-ENOMEM);
515 	msg->socket = sc;
516 	INIT_LIST_HEAD(&msg->sibling_list);
517 	msg->num_sge = 0;
518 	return msg;
519 }
520 
521 static void smb_direct_free_sendmsg(struct smbdirect_socket *sc,
522 				    struct smbdirect_send_io *msg)
523 {
524 	int i;
525 
526 	/*
527 	 * The list needs to be empty!
528 	 * The caller should take care of it.
529 	 */
530 	WARN_ON_ONCE(!list_empty(&msg->sibling_list));
531 
532 	if (msg->num_sge > 0) {
533 		ib_dma_unmap_single(sc->ib.dev,
534 				    msg->sge[0].addr, msg->sge[0].length,
535 				    DMA_TO_DEVICE);
536 		for (i = 1; i < msg->num_sge; i++)
537 			ib_dma_unmap_page(sc->ib.dev,
538 					  msg->sge[i].addr, msg->sge[i].length,
539 					  DMA_TO_DEVICE);
540 	}
541 	mempool_free(msg, sc->send_io.mem.pool);
542 }
543 
544 static int smb_direct_check_recvmsg(struct smbdirect_recv_io *recvmsg)
545 {
546 	struct smbdirect_socket *sc = recvmsg->socket;
547 
548 	switch (sc->recv_io.expected) {
549 	case SMBDIRECT_EXPECT_DATA_TRANSFER: {
550 		struct smbdirect_data_transfer *req =
551 			(struct smbdirect_data_transfer *)recvmsg->packet;
552 		struct smb2_hdr *hdr = (struct smb2_hdr *)(recvmsg->packet
553 				+ le32_to_cpu(req->data_offset));
554 		ksmbd_debug(RDMA,
555 			    "CreditGranted: %u, CreditRequested: %u, DataLength: %u, RemainingDataLength: %u, SMB: %x, Command: %u\n",
556 			    le16_to_cpu(req->credits_granted),
557 			    le16_to_cpu(req->credits_requested),
558 			    req->data_length, req->remaining_data_length,
559 			    hdr->ProtocolId, hdr->Command);
560 		return 0;
561 	}
562 	case SMBDIRECT_EXPECT_NEGOTIATE_REQ: {
563 		struct smbdirect_negotiate_req *req =
564 			(struct smbdirect_negotiate_req *)recvmsg->packet;
565 		ksmbd_debug(RDMA,
566 			    "MinVersion: %u, MaxVersion: %u, CreditRequested: %u, MaxSendSize: %u, MaxRecvSize: %u, MaxFragmentedSize: %u\n",
567 			    le16_to_cpu(req->min_version),
568 			    le16_to_cpu(req->max_version),
569 			    le16_to_cpu(req->credits_requested),
570 			    le32_to_cpu(req->preferred_send_size),
571 			    le32_to_cpu(req->max_receive_size),
572 			    le32_to_cpu(req->max_fragmented_size));
573 		if (le16_to_cpu(req->min_version) > 0x0100 ||
574 		    le16_to_cpu(req->max_version) < 0x0100)
575 			return -EOPNOTSUPP;
576 		if (le16_to_cpu(req->credits_requested) <= 0 ||
577 		    le32_to_cpu(req->max_receive_size) <= 128 ||
578 		    le32_to_cpu(req->max_fragmented_size) <=
579 					128 * 1024)
580 			return -ECONNABORTED;
581 
582 		return 0;
583 	}
584 	case SMBDIRECT_EXPECT_NEGOTIATE_REP:
585 		/* client only */
586 		break;
587 	}
588 
589 	/* This is an internal error */
590 	return -EINVAL;
591 }
592 
593 static void recv_done(struct ib_cq *cq, struct ib_wc *wc)
594 {
595 	struct smbdirect_recv_io *recvmsg;
596 	struct smbdirect_socket *sc;
597 	struct smbdirect_socket_parameters *sp;
598 
599 	recvmsg = container_of(wc->wr_cqe, struct smbdirect_recv_io, cqe);
600 	sc = recvmsg->socket;
601 	sp = &sc->parameters;
602 
603 	if (wc->status != IB_WC_SUCCESS || wc->opcode != IB_WC_RECV) {
604 		put_recvmsg(sc, recvmsg);
605 		if (wc->status != IB_WC_WR_FLUSH_ERR) {
606 			pr_err("Recv error. status='%s (%d)' opcode=%d\n",
607 			       ib_wc_status_msg(wc->status), wc->status,
608 			       wc->opcode);
609 			smb_direct_disconnect_rdma_connection(sc);
610 		}
611 		return;
612 	}
613 
614 	ksmbd_debug(RDMA, "Recv completed. status='%s (%d)', opcode=%d\n",
615 		    ib_wc_status_msg(wc->status), wc->status,
616 		    wc->opcode);
617 
618 	ib_dma_sync_single_for_cpu(wc->qp->device, recvmsg->sge.addr,
619 				   recvmsg->sge.length, DMA_FROM_DEVICE);
620 
621 	/*
622 	 * Reset timer to the keepalive interval in
623 	 * order to trigger our next keepalive message.
624 	 */
625 	sc->idle.keepalive = SMBDIRECT_KEEPALIVE_NONE;
626 	mod_delayed_work(sc->workqueue, &sc->idle.timer_work,
627 			 msecs_to_jiffies(sp->keepalive_interval_msec));
628 
629 	switch (sc->recv_io.expected) {
630 	case SMBDIRECT_EXPECT_NEGOTIATE_REQ:
631 		if (wc->byte_len < sizeof(struct smbdirect_negotiate_req)) {
632 			put_recvmsg(sc, recvmsg);
633 			smb_direct_disconnect_rdma_connection(sc);
634 			return;
635 		}
636 		sc->recv_io.reassembly.full_packet_received = true;
637 		WARN_ON_ONCE(sc->status != SMBDIRECT_SOCKET_NEGOTIATE_NEEDED);
638 		sc->status = SMBDIRECT_SOCKET_NEGOTIATE_RUNNING;
639 		enqueue_reassembly(sc, recvmsg, 0);
640 		wake_up(&sc->status_wait);
641 		return;
642 	case SMBDIRECT_EXPECT_DATA_TRANSFER: {
643 		struct smbdirect_data_transfer *data_transfer =
644 			(struct smbdirect_data_transfer *)recvmsg->packet;
645 		u32 remaining_data_length, data_offset, data_length;
646 		u16 old_recv_credit_target;
647 
648 		if (wc->byte_len <
649 		    offsetof(struct smbdirect_data_transfer, padding)) {
650 			put_recvmsg(sc, recvmsg);
651 			smb_direct_disconnect_rdma_connection(sc);
652 			return;
653 		}
654 
655 		remaining_data_length = le32_to_cpu(data_transfer->remaining_data_length);
656 		data_length = le32_to_cpu(data_transfer->data_length);
657 		data_offset = le32_to_cpu(data_transfer->data_offset);
658 		if (wc->byte_len < data_offset ||
659 		    wc->byte_len < (u64)data_offset + data_length) {
660 			put_recvmsg(sc, recvmsg);
661 			smb_direct_disconnect_rdma_connection(sc);
662 			return;
663 		}
664 		if (remaining_data_length > sp->max_fragmented_recv_size ||
665 		    data_length > sp->max_fragmented_recv_size ||
666 		    (u64)remaining_data_length + (u64)data_length >
667 		    (u64)sp->max_fragmented_recv_size) {
668 			put_recvmsg(sc, recvmsg);
669 			smb_direct_disconnect_rdma_connection(sc);
670 			return;
671 		}
672 
673 		if (data_length) {
674 			if (sc->recv_io.reassembly.full_packet_received)
675 				recvmsg->first_segment = true;
676 
677 			if (le32_to_cpu(data_transfer->remaining_data_length))
678 				sc->recv_io.reassembly.full_packet_received = false;
679 			else
680 				sc->recv_io.reassembly.full_packet_received = true;
681 		}
682 
683 		atomic_dec(&sc->recv_io.posted.count);
684 		atomic_dec(&sc->recv_io.credits.count);
685 
686 		old_recv_credit_target = sc->recv_io.credits.target;
687 		sc->recv_io.credits.target =
688 				le16_to_cpu(data_transfer->credits_requested);
689 		sc->recv_io.credits.target =
690 			min_t(u16, sc->recv_io.credits.target, sp->recv_credit_max);
691 		sc->recv_io.credits.target =
692 			max_t(u16, sc->recv_io.credits.target, 1);
693 		atomic_add(le16_to_cpu(data_transfer->credits_granted),
694 			   &sc->send_io.credits.count);
695 
696 		if (le16_to_cpu(data_transfer->flags) &
697 		    SMBDIRECT_FLAG_RESPONSE_REQUESTED)
698 			queue_work(sc->workqueue, &sc->idle.immediate_work);
699 
700 		if (atomic_read(&sc->send_io.credits.count) > 0)
701 			wake_up(&sc->send_io.credits.wait_queue);
702 
703 		if (data_length) {
704 			if (sc->recv_io.credits.target > old_recv_credit_target)
705 				queue_work(sc->workqueue, &sc->recv_io.posted.refill_work);
706 
707 			enqueue_reassembly(sc, recvmsg, (int)data_length);
708 			wake_up(&sc->recv_io.reassembly.wait_queue);
709 		} else
710 			put_recvmsg(sc, recvmsg);
711 
712 		return;
713 	}
714 	case SMBDIRECT_EXPECT_NEGOTIATE_REP:
715 		/* client only */
716 		break;
717 	}
718 
719 	/*
720 	 * This is an internal error!
721 	 */
722 	WARN_ON_ONCE(sc->recv_io.expected != SMBDIRECT_EXPECT_DATA_TRANSFER);
723 	put_recvmsg(sc, recvmsg);
724 	smb_direct_disconnect_rdma_connection(sc);
725 }
726 
727 static int smb_direct_post_recv(struct smbdirect_socket *sc,
728 				struct smbdirect_recv_io *recvmsg)
729 {
730 	struct smbdirect_socket_parameters *sp = &sc->parameters;
731 	struct ib_recv_wr wr;
732 	int ret;
733 
734 	recvmsg->sge.addr = ib_dma_map_single(sc->ib.dev,
735 					      recvmsg->packet,
736 					      sp->max_recv_size,
737 					      DMA_FROM_DEVICE);
738 	ret = ib_dma_mapping_error(sc->ib.dev, recvmsg->sge.addr);
739 	if (ret)
740 		return ret;
741 	recvmsg->sge.length = sp->max_recv_size;
742 	recvmsg->sge.lkey = sc->ib.pd->local_dma_lkey;
743 	recvmsg->cqe.done = recv_done;
744 
745 	wr.wr_cqe = &recvmsg->cqe;
746 	wr.next = NULL;
747 	wr.sg_list = &recvmsg->sge;
748 	wr.num_sge = 1;
749 
750 	ret = ib_post_recv(sc->ib.qp, &wr, NULL);
751 	if (ret) {
752 		pr_err("Can't post recv: %d\n", ret);
753 		ib_dma_unmap_single(sc->ib.dev,
754 				    recvmsg->sge.addr, recvmsg->sge.length,
755 				    DMA_FROM_DEVICE);
756 		recvmsg->sge.length = 0;
757 		smb_direct_disconnect_rdma_connection(sc);
758 		return ret;
759 	}
760 	return ret;
761 }
762 
763 static int smb_direct_read(struct ksmbd_transport *t, char *buf,
764 			   unsigned int size, int unused)
765 {
766 	struct smbdirect_recv_io *recvmsg;
767 	struct smbdirect_data_transfer *data_transfer;
768 	int to_copy, to_read, data_read, offset;
769 	u32 data_length, remaining_data_length, data_offset;
770 	int rc;
771 	struct smb_direct_transport *st = SMBD_TRANS(t);
772 	struct smbdirect_socket *sc = &st->socket;
773 
774 again:
775 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED) {
776 		pr_err("disconnected\n");
777 		return -ENOTCONN;
778 	}
779 
780 	/*
781 	 * No need to hold the reassembly queue lock all the time as we are
782 	 * the only one reading from the front of the queue. The transport
783 	 * may add more entries to the back of the queue at the same time
784 	 */
785 	if (sc->recv_io.reassembly.data_length >= size) {
786 		int queue_length;
787 		int queue_removed = 0;
788 		unsigned long flags;
789 
790 		/*
791 		 * Need to make sure reassembly_data_length is read before
792 		 * reading reassembly_queue_length and calling
793 		 * get_first_reassembly. This call is lock free
794 		 * as we never read at the end of the queue which are being
795 		 * updated in SOFTIRQ as more data is received
796 		 */
797 		virt_rmb();
798 		queue_length = sc->recv_io.reassembly.queue_length;
799 		data_read = 0;
800 		to_read = size;
801 		offset = sc->recv_io.reassembly.first_entry_offset;
802 		while (data_read < size) {
803 			recvmsg = get_first_reassembly(sc);
804 			data_transfer = smbdirect_recv_io_payload(recvmsg);
805 			data_length = le32_to_cpu(data_transfer->data_length);
806 			remaining_data_length =
807 				le32_to_cpu(data_transfer->remaining_data_length);
808 			data_offset = le32_to_cpu(data_transfer->data_offset);
809 
810 			/*
811 			 * The upper layer expects RFC1002 length at the
812 			 * beginning of the payload. Return it to indicate
813 			 * the total length of the packet. This minimize the
814 			 * change to upper layer packet processing logic. This
815 			 * will be eventually remove when an intermediate
816 			 * transport layer is added
817 			 */
818 			if (recvmsg->first_segment && size == 4) {
819 				unsigned int rfc1002_len =
820 					data_length + remaining_data_length;
821 				*((__be32 *)buf) = cpu_to_be32(rfc1002_len);
822 				data_read = 4;
823 				recvmsg->first_segment = false;
824 				ksmbd_debug(RDMA,
825 					    "returning rfc1002 length %d\n",
826 					    rfc1002_len);
827 				goto read_rfc1002_done;
828 			}
829 
830 			to_copy = min_t(int, data_length - offset, to_read);
831 			memcpy(buf + data_read, (char *)data_transfer + data_offset + offset,
832 			       to_copy);
833 
834 			/* move on to the next buffer? */
835 			if (to_copy == data_length - offset) {
836 				queue_length--;
837 				/*
838 				 * No need to lock if we are not at the
839 				 * end of the queue
840 				 */
841 				if (queue_length) {
842 					list_del(&recvmsg->list);
843 				} else {
844 					spin_lock_irqsave(&sc->recv_io.reassembly.lock, flags);
845 					list_del(&recvmsg->list);
846 					spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
847 				}
848 				queue_removed++;
849 				put_recvmsg(sc, recvmsg);
850 				offset = 0;
851 			} else {
852 				offset += to_copy;
853 			}
854 
855 			to_read -= to_copy;
856 			data_read += to_copy;
857 		}
858 
859 		spin_lock_irqsave(&sc->recv_io.reassembly.lock, flags);
860 		sc->recv_io.reassembly.data_length -= data_read;
861 		sc->recv_io.reassembly.queue_length -= queue_removed;
862 		spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
863 
864 		sc->recv_io.reassembly.first_entry_offset = offset;
865 		ksmbd_debug(RDMA,
866 			    "returning to thread data_read=%d reassembly_data_length=%d first_entry_offset=%d\n",
867 			    data_read, sc->recv_io.reassembly.data_length,
868 			    sc->recv_io.reassembly.first_entry_offset);
869 read_rfc1002_done:
870 		return data_read;
871 	}
872 
873 	ksmbd_debug(RDMA, "wait_event on more data\n");
874 	rc = wait_event_interruptible(sc->recv_io.reassembly.wait_queue,
875 				      sc->recv_io.reassembly.data_length >= size ||
876 				       sc->status != SMBDIRECT_SOCKET_CONNECTED);
877 	if (rc)
878 		return -EINTR;
879 
880 	goto again;
881 }
882 
883 static void smb_direct_post_recv_credits(struct work_struct *work)
884 {
885 	struct smbdirect_socket *sc =
886 		container_of(work, struct smbdirect_socket, recv_io.posted.refill_work);
887 	struct smbdirect_recv_io *recvmsg;
888 	int credits = 0;
889 	int ret;
890 
891 	if (atomic_read(&sc->recv_io.credits.count) < sc->recv_io.credits.target) {
892 		while (true) {
893 			recvmsg = get_free_recvmsg(sc);
894 			if (!recvmsg)
895 				break;
896 
897 			recvmsg->first_segment = false;
898 
899 			ret = smb_direct_post_recv(sc, recvmsg);
900 			if (ret) {
901 				pr_err("Can't post recv: %d\n", ret);
902 				put_recvmsg(sc, recvmsg);
903 				break;
904 			}
905 			credits++;
906 
907 			atomic_inc(&sc->recv_io.posted.count);
908 		}
909 	}
910 
911 	if (credits)
912 		queue_work(sc->workqueue, &sc->idle.immediate_work);
913 }
914 
915 static void send_done(struct ib_cq *cq, struct ib_wc *wc)
916 {
917 	struct smbdirect_send_io *sendmsg, *sibling, *next;
918 	struct smbdirect_socket *sc;
919 	int lcredits = 0;
920 
921 	sendmsg = container_of(wc->wr_cqe, struct smbdirect_send_io, cqe);
922 	sc = sendmsg->socket;
923 
924 	ksmbd_debug(RDMA, "Send completed. status='%s (%d)', opcode=%d\n",
925 		    ib_wc_status_msg(wc->status), wc->status,
926 		    wc->opcode);
927 
928 	/*
929 	 * Free possible siblings and then the main send_io
930 	 */
931 	list_for_each_entry_safe(sibling, next, &sendmsg->sibling_list, sibling_list) {
932 		list_del_init(&sibling->sibling_list);
933 		smb_direct_free_sendmsg(sc, sibling);
934 		lcredits += 1;
935 	}
936 	/* Note this frees wc->wr_cqe, but not wc */
937 	smb_direct_free_sendmsg(sc, sendmsg);
938 	lcredits += 1;
939 
940 	if (wc->status != IB_WC_SUCCESS || wc->opcode != IB_WC_SEND) {
941 		pr_err("Send error. status='%s (%d)', opcode=%d\n",
942 		       ib_wc_status_msg(wc->status), wc->status,
943 		       wc->opcode);
944 		smb_direct_disconnect_rdma_connection(sc);
945 		return;
946 	}
947 
948 	atomic_add(lcredits, &sc->send_io.lcredits.count);
949 	wake_up(&sc->send_io.lcredits.wait_queue);
950 
951 	if (atomic_dec_and_test(&sc->send_io.pending.count))
952 		wake_up(&sc->send_io.pending.zero_wait_queue);
953 }
954 
955 static int manage_credits_prior_sending(struct smbdirect_socket *sc)
956 {
957 	int new_credits;
958 
959 	if (atomic_read(&sc->recv_io.credits.count) >= sc->recv_io.credits.target)
960 		return 0;
961 
962 	new_credits = atomic_read(&sc->recv_io.posted.count);
963 	if (new_credits == 0)
964 		return 0;
965 
966 	new_credits -= atomic_read(&sc->recv_io.credits.count);
967 	if (new_credits <= 0)
968 		return 0;
969 
970 	atomic_add(new_credits, &sc->recv_io.credits.count);
971 	return new_credits;
972 }
973 
974 static int manage_keep_alive_before_sending(struct smbdirect_socket *sc)
975 {
976 	struct smbdirect_socket_parameters *sp = &sc->parameters;
977 
978 	if (sc->idle.keepalive == SMBDIRECT_KEEPALIVE_PENDING) {
979 		sc->idle.keepalive = SMBDIRECT_KEEPALIVE_SENT;
980 		/*
981 		 * Now use the keepalive timeout (instead of keepalive interval)
982 		 * in order to wait for a response
983 		 */
984 		mod_delayed_work(sc->workqueue, &sc->idle.timer_work,
985 				 msecs_to_jiffies(sp->keepalive_timeout_msec));
986 		return 1;
987 	}
988 	return 0;
989 }
990 
991 static int smb_direct_post_send(struct smbdirect_socket *sc,
992 				struct ib_send_wr *wr)
993 {
994 	int ret;
995 
996 	atomic_inc(&sc->send_io.pending.count);
997 	ret = ib_post_send(sc->ib.qp, wr, NULL);
998 	if (ret) {
999 		pr_err("failed to post send: %d\n", ret);
1000 		smb_direct_disconnect_rdma_connection(sc);
1001 	}
1002 	return ret;
1003 }
1004 
1005 static void smb_direct_send_ctx_init(struct smbdirect_send_batch *send_ctx,
1006 				     bool need_invalidate_rkey,
1007 				     unsigned int remote_key)
1008 {
1009 	INIT_LIST_HEAD(&send_ctx->msg_list);
1010 	send_ctx->wr_cnt = 0;
1011 	send_ctx->need_invalidate_rkey = need_invalidate_rkey;
1012 	send_ctx->remote_key = remote_key;
1013 }
1014 
1015 static int smb_direct_flush_send_list(struct smbdirect_socket *sc,
1016 				      struct smbdirect_send_batch *send_ctx,
1017 				      bool is_last)
1018 {
1019 	struct smbdirect_send_io *first, *last;
1020 	int ret;
1021 
1022 	if (list_empty(&send_ctx->msg_list))
1023 		return 0;
1024 
1025 	first = list_first_entry(&send_ctx->msg_list,
1026 				 struct smbdirect_send_io,
1027 				 sibling_list);
1028 	last = list_last_entry(&send_ctx->msg_list,
1029 			       struct smbdirect_send_io,
1030 			       sibling_list);
1031 
1032 	if (send_ctx->need_invalidate_rkey) {
1033 		first->wr.opcode = IB_WR_SEND_WITH_INV;
1034 		first->wr.ex.invalidate_rkey = send_ctx->remote_key;
1035 		send_ctx->need_invalidate_rkey = false;
1036 		send_ctx->remote_key = 0;
1037 	}
1038 
1039 	last->wr.send_flags = IB_SEND_SIGNALED;
1040 	last->wr.wr_cqe = &last->cqe;
1041 
1042 	/*
1043 	 * Remove last from send_ctx->msg_list
1044 	 * and splice the rest of send_ctx->msg_list
1045 	 * to last->sibling_list.
1046 	 *
1047 	 * send_ctx->msg_list is a valid empty list
1048 	 * at the end.
1049 	 */
1050 	list_del_init(&last->sibling_list);
1051 	list_splice_tail_init(&send_ctx->msg_list, &last->sibling_list);
1052 	send_ctx->wr_cnt = 0;
1053 
1054 	ret = smb_direct_post_send(sc, &first->wr);
1055 	if (ret) {
1056 		struct smbdirect_send_io *sibling, *next;
1057 
1058 		list_for_each_entry_safe(sibling, next, &last->sibling_list, sibling_list) {
1059 			list_del_init(&sibling->sibling_list);
1060 			smb_direct_free_sendmsg(sc, sibling);
1061 		}
1062 		smb_direct_free_sendmsg(sc, last);
1063 	}
1064 
1065 	return ret;
1066 }
1067 
1068 static int wait_for_credits(struct smbdirect_socket *sc,
1069 			    wait_queue_head_t *waitq, atomic_t *total_credits,
1070 			    int needed)
1071 {
1072 	int ret;
1073 
1074 	do {
1075 		if (atomic_sub_return(needed, total_credits) >= 0)
1076 			return 0;
1077 
1078 		atomic_add(needed, total_credits);
1079 		ret = wait_event_interruptible(*waitq,
1080 					       atomic_read(total_credits) >= needed ||
1081 					       sc->status != SMBDIRECT_SOCKET_CONNECTED);
1082 
1083 		if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
1084 			return -ENOTCONN;
1085 		else if (ret < 0)
1086 			return ret;
1087 	} while (true);
1088 }
1089 
1090 static int wait_for_send_lcredit(struct smbdirect_socket *sc,
1091 				 struct smbdirect_send_batch *send_ctx)
1092 {
1093 	if (send_ctx && (atomic_read(&sc->send_io.lcredits.count) <= 1)) {
1094 		int ret;
1095 
1096 		ret = smb_direct_flush_send_list(sc, send_ctx, false);
1097 		if (ret)
1098 			return ret;
1099 	}
1100 
1101 	return wait_for_credits(sc,
1102 				&sc->send_io.lcredits.wait_queue,
1103 				&sc->send_io.lcredits.count,
1104 				1);
1105 }
1106 
1107 static int wait_for_send_credits(struct smbdirect_socket *sc,
1108 				 struct smbdirect_send_batch *send_ctx)
1109 {
1110 	int ret;
1111 
1112 	if (send_ctx &&
1113 	    (send_ctx->wr_cnt >= 16 || atomic_read(&sc->send_io.credits.count) <= 1)) {
1114 		ret = smb_direct_flush_send_list(sc, send_ctx, false);
1115 		if (ret)
1116 			return ret;
1117 	}
1118 
1119 	return wait_for_credits(sc, &sc->send_io.credits.wait_queue, &sc->send_io.credits.count, 1);
1120 }
1121 
1122 static int wait_for_rw_credits(struct smbdirect_socket *sc, int credits)
1123 {
1124 	return wait_for_credits(sc,
1125 				&sc->rw_io.credits.wait_queue,
1126 				&sc->rw_io.credits.count,
1127 				credits);
1128 }
1129 
1130 static int calc_rw_credits(struct smbdirect_socket *sc,
1131 			   char *buf, unsigned int len)
1132 {
1133 	return DIV_ROUND_UP(get_buf_page_count(buf, len),
1134 			    sc->rw_io.credits.num_pages);
1135 }
1136 
1137 static int smb_direct_create_header(struct smbdirect_socket *sc,
1138 				    int size, int remaining_data_length,
1139 				    struct smbdirect_send_io **sendmsg_out)
1140 {
1141 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1142 	struct smbdirect_send_io *sendmsg;
1143 	struct smbdirect_data_transfer *packet;
1144 	int header_length;
1145 	int ret;
1146 
1147 	sendmsg = smb_direct_alloc_sendmsg(sc);
1148 	if (IS_ERR(sendmsg))
1149 		return PTR_ERR(sendmsg);
1150 
1151 	/* Fill in the packet header */
1152 	packet = (struct smbdirect_data_transfer *)sendmsg->packet;
1153 	packet->credits_requested = cpu_to_le16(sp->send_credit_target);
1154 	packet->credits_granted = cpu_to_le16(manage_credits_prior_sending(sc));
1155 
1156 	packet->flags = 0;
1157 	if (manage_keep_alive_before_sending(sc))
1158 		packet->flags |= cpu_to_le16(SMBDIRECT_FLAG_RESPONSE_REQUESTED);
1159 
1160 	packet->reserved = 0;
1161 	if (!size)
1162 		packet->data_offset = 0;
1163 	else
1164 		packet->data_offset = cpu_to_le32(24);
1165 	packet->data_length = cpu_to_le32(size);
1166 	packet->remaining_data_length = cpu_to_le32(remaining_data_length);
1167 	packet->padding = 0;
1168 
1169 	ksmbd_debug(RDMA,
1170 		    "credits_requested=%d credits_granted=%d data_offset=%d data_length=%d remaining_data_length=%d\n",
1171 		    le16_to_cpu(packet->credits_requested),
1172 		    le16_to_cpu(packet->credits_granted),
1173 		    le32_to_cpu(packet->data_offset),
1174 		    le32_to_cpu(packet->data_length),
1175 		    le32_to_cpu(packet->remaining_data_length));
1176 
1177 	/* Map the packet to DMA */
1178 	header_length = sizeof(struct smbdirect_data_transfer);
1179 	/* If this is a packet without payload, don't send padding */
1180 	if (!size)
1181 		header_length =
1182 			offsetof(struct smbdirect_data_transfer, padding);
1183 
1184 	sendmsg->sge[0].addr = ib_dma_map_single(sc->ib.dev,
1185 						 (void *)packet,
1186 						 header_length,
1187 						 DMA_TO_DEVICE);
1188 	ret = ib_dma_mapping_error(sc->ib.dev, sendmsg->sge[0].addr);
1189 	if (ret) {
1190 		smb_direct_free_sendmsg(sc, sendmsg);
1191 		return ret;
1192 	}
1193 
1194 	sendmsg->num_sge = 1;
1195 	sendmsg->sge[0].length = header_length;
1196 	sendmsg->sge[0].lkey = sc->ib.pd->local_dma_lkey;
1197 
1198 	*sendmsg_out = sendmsg;
1199 	return 0;
1200 }
1201 
1202 static int get_sg_list(void *buf, int size, struct scatterlist *sg_list, int nentries)
1203 {
1204 	bool high = is_vmalloc_addr(buf);
1205 	struct page *page;
1206 	int offset, len;
1207 	int i = 0;
1208 
1209 	if (size <= 0 || nentries < get_buf_page_count(buf, size))
1210 		return -EINVAL;
1211 
1212 	offset = offset_in_page(buf);
1213 	buf -= offset;
1214 	while (size > 0) {
1215 		len = min_t(int, PAGE_SIZE - offset, size);
1216 		if (high)
1217 			page = vmalloc_to_page(buf);
1218 		else
1219 			page = kmap_to_page(buf);
1220 
1221 		if (!sg_list)
1222 			return -EINVAL;
1223 		sg_set_page(sg_list, page, len, offset);
1224 		sg_list = sg_next(sg_list);
1225 
1226 		buf += PAGE_SIZE;
1227 		size -= len;
1228 		offset = 0;
1229 		i++;
1230 	}
1231 	return i;
1232 }
1233 
1234 static int get_mapped_sg_list(struct ib_device *device, void *buf, int size,
1235 			      struct scatterlist *sg_list, int nentries,
1236 			      enum dma_data_direction dir)
1237 {
1238 	int npages;
1239 
1240 	npages = get_sg_list(buf, size, sg_list, nentries);
1241 	if (npages < 0)
1242 		return -EINVAL;
1243 	return ib_dma_map_sg(device, sg_list, npages, dir);
1244 }
1245 
1246 static int post_sendmsg(struct smbdirect_socket *sc,
1247 			struct smbdirect_send_batch *send_ctx,
1248 			struct smbdirect_send_io *msg)
1249 {
1250 	int i;
1251 
1252 	for (i = 0; i < msg->num_sge; i++)
1253 		ib_dma_sync_single_for_device(sc->ib.dev,
1254 					      msg->sge[i].addr, msg->sge[i].length,
1255 					      DMA_TO_DEVICE);
1256 
1257 	msg->cqe.done = send_done;
1258 	msg->wr.opcode = IB_WR_SEND;
1259 	msg->wr.sg_list = &msg->sge[0];
1260 	msg->wr.num_sge = msg->num_sge;
1261 	msg->wr.next = NULL;
1262 
1263 	if (send_ctx) {
1264 		msg->wr.wr_cqe = NULL;
1265 		msg->wr.send_flags = 0;
1266 		if (!list_empty(&send_ctx->msg_list)) {
1267 			struct smbdirect_send_io *last;
1268 
1269 			last = list_last_entry(&send_ctx->msg_list,
1270 					       struct smbdirect_send_io,
1271 					       sibling_list);
1272 			last->wr.next = &msg->wr;
1273 		}
1274 		list_add_tail(&msg->sibling_list, &send_ctx->msg_list);
1275 		send_ctx->wr_cnt++;
1276 		return 0;
1277 	}
1278 
1279 	msg->wr.wr_cqe = &msg->cqe;
1280 	msg->wr.send_flags = IB_SEND_SIGNALED;
1281 	return smb_direct_post_send(sc, &msg->wr);
1282 }
1283 
1284 static int smb_direct_post_send_data(struct smbdirect_socket *sc,
1285 				     struct smbdirect_send_batch *send_ctx,
1286 				     struct kvec *iov, int niov,
1287 				     int remaining_data_length)
1288 {
1289 	int i, j, ret;
1290 	struct smbdirect_send_io *msg;
1291 	int data_length;
1292 	struct scatterlist sg[SMBDIRECT_SEND_IO_MAX_SGE - 1];
1293 
1294 	ret = wait_for_send_lcredit(sc, send_ctx);
1295 	if (ret)
1296 		goto lcredit_failed;
1297 
1298 	ret = wait_for_send_credits(sc, send_ctx);
1299 	if (ret)
1300 		goto credit_failed;
1301 
1302 	data_length = 0;
1303 	for (i = 0; i < niov; i++)
1304 		data_length += iov[i].iov_len;
1305 
1306 	ret = smb_direct_create_header(sc, data_length, remaining_data_length,
1307 				       &msg);
1308 	if (ret)
1309 		goto header_failed;
1310 
1311 	for (i = 0; i < niov; i++) {
1312 		struct ib_sge *sge;
1313 		int sg_cnt;
1314 
1315 		sg_init_table(sg, SMBDIRECT_SEND_IO_MAX_SGE - 1);
1316 		sg_cnt = get_mapped_sg_list(sc->ib.dev,
1317 					    iov[i].iov_base, iov[i].iov_len,
1318 					    sg, SMBDIRECT_SEND_IO_MAX_SGE - 1,
1319 					    DMA_TO_DEVICE);
1320 		if (sg_cnt <= 0) {
1321 			pr_err("failed to map buffer\n");
1322 			ret = -ENOMEM;
1323 			goto err;
1324 		} else if (sg_cnt + msg->num_sge > SMBDIRECT_SEND_IO_MAX_SGE) {
1325 			pr_err("buffer not fitted into sges\n");
1326 			ret = -E2BIG;
1327 			ib_dma_unmap_sg(sc->ib.dev, sg, sg_cnt,
1328 					DMA_TO_DEVICE);
1329 			goto err;
1330 		}
1331 
1332 		for (j = 0; j < sg_cnt; j++) {
1333 			sge = &msg->sge[msg->num_sge];
1334 			sge->addr = sg_dma_address(&sg[j]);
1335 			sge->length = sg_dma_len(&sg[j]);
1336 			sge->lkey  = sc->ib.pd->local_dma_lkey;
1337 			msg->num_sge++;
1338 		}
1339 	}
1340 
1341 	ret = post_sendmsg(sc, send_ctx, msg);
1342 	if (ret)
1343 		goto err;
1344 	return 0;
1345 err:
1346 	smb_direct_free_sendmsg(sc, msg);
1347 header_failed:
1348 	atomic_inc(&sc->send_io.credits.count);
1349 credit_failed:
1350 	atomic_inc(&sc->send_io.lcredits.count);
1351 lcredit_failed:
1352 	return ret;
1353 }
1354 
1355 static int smb_direct_writev(struct ksmbd_transport *t,
1356 			     struct kvec *iov, int niovs, int buflen,
1357 			     bool need_invalidate, unsigned int remote_key)
1358 {
1359 	struct smb_direct_transport *st = SMBD_TRANS(t);
1360 	struct smbdirect_socket *sc = &st->socket;
1361 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1362 	size_t remaining_data_length;
1363 	size_t iov_idx;
1364 	size_t iov_ofs;
1365 	size_t max_iov_size = sp->max_send_size -
1366 			sizeof(struct smbdirect_data_transfer);
1367 	int ret;
1368 	struct smbdirect_send_batch send_ctx;
1369 	int error = 0;
1370 
1371 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
1372 		return -ENOTCONN;
1373 
1374 	//FIXME: skip RFC1002 header..
1375 	if (WARN_ON_ONCE(niovs <= 1 || iov[0].iov_len != 4))
1376 		return -EINVAL;
1377 	buflen -= 4;
1378 	iov_idx = 1;
1379 	iov_ofs = 0;
1380 
1381 	remaining_data_length = buflen;
1382 	ksmbd_debug(RDMA, "Sending smb (RDMA): smb_len=%u\n", buflen);
1383 
1384 	smb_direct_send_ctx_init(&send_ctx, need_invalidate, remote_key);
1385 	while (remaining_data_length) {
1386 		struct kvec vecs[SMBDIRECT_SEND_IO_MAX_SGE - 1]; /* minus smbdirect hdr */
1387 		size_t possible_bytes = max_iov_size;
1388 		size_t possible_vecs;
1389 		size_t bytes = 0;
1390 		size_t nvecs = 0;
1391 
1392 		/*
1393 		 * For the last message remaining_data_length should be
1394 		 * have been 0 already!
1395 		 */
1396 		if (WARN_ON_ONCE(iov_idx >= niovs)) {
1397 			error = -EINVAL;
1398 			goto done;
1399 		}
1400 
1401 		/*
1402 		 * We have 2 factors which limit the arguments we pass
1403 		 * to smb_direct_post_send_data():
1404 		 *
1405 		 * 1. The number of supported sges for the send,
1406 		 *    while one is reserved for the smbdirect header.
1407 		 *    And we currently need one SGE per page.
1408 		 * 2. The number of negotiated payload bytes per send.
1409 		 */
1410 		possible_vecs = min_t(size_t, ARRAY_SIZE(vecs), niovs - iov_idx);
1411 
1412 		while (iov_idx < niovs && possible_vecs && possible_bytes) {
1413 			struct kvec *v = &vecs[nvecs];
1414 			int page_count;
1415 
1416 			v->iov_base = ((u8 *)iov[iov_idx].iov_base) + iov_ofs;
1417 			v->iov_len = min_t(size_t,
1418 					   iov[iov_idx].iov_len - iov_ofs,
1419 					   possible_bytes);
1420 			page_count = get_buf_page_count(v->iov_base, v->iov_len);
1421 			if (page_count > possible_vecs) {
1422 				/*
1423 				 * If the number of pages in the buffer
1424 				 * is to much (because we currently require
1425 				 * one SGE per page), we need to limit the
1426 				 * length.
1427 				 *
1428 				 * We know possible_vecs is at least 1,
1429 				 * so we always keep the first page.
1430 				 *
1431 				 * We need to calculate the number extra
1432 				 * pages (epages) we can also keep.
1433 				 *
1434 				 * We calculate the number of bytes in the
1435 				 * first page (fplen), this should never be
1436 				 * larger than v->iov_len because page_count is
1437 				 * at least 2, but adding a limitation feels
1438 				 * better.
1439 				 *
1440 				 * Then we calculate the number of bytes (elen)
1441 				 * we can keep for the extra pages.
1442 				 */
1443 				size_t epages = possible_vecs - 1;
1444 				size_t fpofs = offset_in_page(v->iov_base);
1445 				size_t fplen = min_t(size_t, PAGE_SIZE - fpofs, v->iov_len);
1446 				size_t elen = min_t(size_t, v->iov_len - fplen, epages*PAGE_SIZE);
1447 
1448 				v->iov_len = fplen + elen;
1449 				page_count = get_buf_page_count(v->iov_base, v->iov_len);
1450 				if (WARN_ON_ONCE(page_count > possible_vecs)) {
1451 					/*
1452 					 * Something went wrong in the above
1453 					 * logic...
1454 					 */
1455 					error = -EINVAL;
1456 					goto done;
1457 				}
1458 			}
1459 			possible_vecs -= page_count;
1460 			nvecs += 1;
1461 			possible_bytes -= v->iov_len;
1462 			bytes += v->iov_len;
1463 
1464 			iov_ofs += v->iov_len;
1465 			if (iov_ofs >= iov[iov_idx].iov_len) {
1466 				iov_idx += 1;
1467 				iov_ofs = 0;
1468 			}
1469 		}
1470 
1471 		remaining_data_length -= bytes;
1472 
1473 		ret = smb_direct_post_send_data(sc, &send_ctx,
1474 						vecs, nvecs,
1475 						remaining_data_length);
1476 		if (unlikely(ret)) {
1477 			error = ret;
1478 			goto done;
1479 		}
1480 	}
1481 
1482 done:
1483 	ret = smb_direct_flush_send_list(sc, &send_ctx, true);
1484 	if (unlikely(!ret && error))
1485 		ret = error;
1486 
1487 	/*
1488 	 * As an optimization, we don't wait for individual I/O to finish
1489 	 * before sending the next one.
1490 	 * Send them all and wait for pending send count to get to 0
1491 	 * that means all the I/Os have been out and we are good to return
1492 	 */
1493 
1494 	wait_event(sc->send_io.pending.zero_wait_queue,
1495 		   atomic_read(&sc->send_io.pending.count) == 0 ||
1496 		   sc->status != SMBDIRECT_SOCKET_CONNECTED);
1497 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED && ret == 0)
1498 		ret = -ENOTCONN;
1499 
1500 	return ret;
1501 }
1502 
1503 static void smb_direct_free_rdma_rw_msg(struct smb_direct_transport *t,
1504 					struct smbdirect_rw_io *msg,
1505 					enum dma_data_direction dir)
1506 {
1507 	struct smbdirect_socket *sc = &t->socket;
1508 
1509 	rdma_rw_ctx_destroy(&msg->rdma_ctx, sc->ib.qp, sc->ib.qp->port,
1510 			    msg->sgt.sgl, msg->sgt.nents, dir);
1511 	sg_free_table_chained(&msg->sgt, SG_CHUNK_SIZE);
1512 	kfree(msg);
1513 }
1514 
1515 static void read_write_done(struct ib_cq *cq, struct ib_wc *wc,
1516 			    enum dma_data_direction dir)
1517 {
1518 	struct smbdirect_rw_io *msg =
1519 		container_of(wc->wr_cqe, struct smbdirect_rw_io, cqe);
1520 	struct smbdirect_socket *sc = msg->socket;
1521 
1522 	if (wc->status != IB_WC_SUCCESS) {
1523 		msg->error = -EIO;
1524 		pr_err("read/write error. opcode = %d, status = %s(%d)\n",
1525 		       wc->opcode, ib_wc_status_msg(wc->status), wc->status);
1526 		if (wc->status != IB_WC_WR_FLUSH_ERR)
1527 			smb_direct_disconnect_rdma_connection(sc);
1528 	}
1529 
1530 	complete(msg->completion);
1531 }
1532 
1533 static void read_done(struct ib_cq *cq, struct ib_wc *wc)
1534 {
1535 	read_write_done(cq, wc, DMA_FROM_DEVICE);
1536 }
1537 
1538 static void write_done(struct ib_cq *cq, struct ib_wc *wc)
1539 {
1540 	read_write_done(cq, wc, DMA_TO_DEVICE);
1541 }
1542 
1543 static int smb_direct_rdma_xmit(struct smb_direct_transport *t,
1544 				void *buf, int buf_len,
1545 				struct smbdirect_buffer_descriptor_v1 *desc,
1546 				unsigned int desc_len,
1547 				bool is_read)
1548 {
1549 	struct smbdirect_socket *sc = &t->socket;
1550 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1551 	struct smbdirect_rw_io *msg, *next_msg;
1552 	int i, ret;
1553 	DECLARE_COMPLETION_ONSTACK(completion);
1554 	struct ib_send_wr *first_wr;
1555 	LIST_HEAD(msg_list);
1556 	char *desc_buf;
1557 	int credits_needed;
1558 	unsigned int desc_buf_len, desc_num = 0;
1559 
1560 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
1561 		return -ENOTCONN;
1562 
1563 	if (buf_len > sp->max_read_write_size)
1564 		return -EINVAL;
1565 
1566 	/* calculate needed credits */
1567 	credits_needed = 0;
1568 	desc_buf = buf;
1569 	for (i = 0; i < desc_len / sizeof(*desc); i++) {
1570 		if (!buf_len)
1571 			break;
1572 
1573 		desc_buf_len = le32_to_cpu(desc[i].length);
1574 		if (!desc_buf_len)
1575 			return -EINVAL;
1576 
1577 		if (desc_buf_len > buf_len) {
1578 			desc_buf_len = buf_len;
1579 			desc[i].length = cpu_to_le32(desc_buf_len);
1580 			buf_len = 0;
1581 		}
1582 
1583 		credits_needed += calc_rw_credits(sc, desc_buf, desc_buf_len);
1584 		desc_buf += desc_buf_len;
1585 		buf_len -= desc_buf_len;
1586 		desc_num++;
1587 	}
1588 
1589 	ksmbd_debug(RDMA, "RDMA %s, len %#x, needed credits %#x\n",
1590 		    str_read_write(is_read), buf_len, credits_needed);
1591 
1592 	ret = wait_for_rw_credits(sc, credits_needed);
1593 	if (ret < 0)
1594 		return ret;
1595 
1596 	/* build rdma_rw_ctx for each descriptor */
1597 	desc_buf = buf;
1598 	for (i = 0; i < desc_num; i++) {
1599 		msg = kzalloc(struct_size(msg, sg_list, SG_CHUNK_SIZE),
1600 			      KSMBD_DEFAULT_GFP);
1601 		if (!msg) {
1602 			ret = -ENOMEM;
1603 			goto out;
1604 		}
1605 
1606 		desc_buf_len = le32_to_cpu(desc[i].length);
1607 
1608 		msg->socket = sc;
1609 		msg->cqe.done = is_read ? read_done : write_done;
1610 		msg->completion = &completion;
1611 
1612 		msg->sgt.sgl = &msg->sg_list[0];
1613 		ret = sg_alloc_table_chained(&msg->sgt,
1614 					     get_buf_page_count(desc_buf, desc_buf_len),
1615 					     msg->sg_list, SG_CHUNK_SIZE);
1616 		if (ret) {
1617 			ret = -ENOMEM;
1618 			goto free_msg;
1619 		}
1620 
1621 		ret = get_sg_list(desc_buf, desc_buf_len,
1622 				  msg->sgt.sgl, msg->sgt.orig_nents);
1623 		if (ret < 0)
1624 			goto free_table;
1625 
1626 		ret = rdma_rw_ctx_init(&msg->rdma_ctx, sc->ib.qp, sc->ib.qp->port,
1627 				       msg->sgt.sgl,
1628 				       get_buf_page_count(desc_buf, desc_buf_len),
1629 				       0,
1630 				       le64_to_cpu(desc[i].offset),
1631 				       le32_to_cpu(desc[i].token),
1632 				       is_read ? DMA_FROM_DEVICE : DMA_TO_DEVICE);
1633 		if (ret < 0) {
1634 			pr_err("failed to init rdma_rw_ctx: %d\n", ret);
1635 			goto free_table;
1636 		}
1637 
1638 		list_add_tail(&msg->list, &msg_list);
1639 		desc_buf += desc_buf_len;
1640 	}
1641 
1642 	/* concatenate work requests of rdma_rw_ctxs */
1643 	first_wr = NULL;
1644 	list_for_each_entry_reverse(msg, &msg_list, list) {
1645 		first_wr = rdma_rw_ctx_wrs(&msg->rdma_ctx, sc->ib.qp, sc->ib.qp->port,
1646 					   &msg->cqe, first_wr);
1647 	}
1648 
1649 	ret = ib_post_send(sc->ib.qp, first_wr, NULL);
1650 	if (ret) {
1651 		pr_err("failed to post send wr for RDMA R/W: %d\n", ret);
1652 		goto out;
1653 	}
1654 
1655 	msg = list_last_entry(&msg_list, struct smbdirect_rw_io, list);
1656 	wait_for_completion(&completion);
1657 	ret = msg->error;
1658 out:
1659 	list_for_each_entry_safe(msg, next_msg, &msg_list, list) {
1660 		list_del(&msg->list);
1661 		smb_direct_free_rdma_rw_msg(t, msg,
1662 					    is_read ? DMA_FROM_DEVICE : DMA_TO_DEVICE);
1663 	}
1664 	atomic_add(credits_needed, &sc->rw_io.credits.count);
1665 	wake_up(&sc->rw_io.credits.wait_queue);
1666 	return ret;
1667 
1668 free_table:
1669 	sg_free_table_chained(&msg->sgt, SG_CHUNK_SIZE);
1670 free_msg:
1671 	kfree(msg);
1672 	goto out;
1673 }
1674 
1675 static int smb_direct_rdma_write(struct ksmbd_transport *t,
1676 				 void *buf, unsigned int buflen,
1677 				 struct smbdirect_buffer_descriptor_v1 *desc,
1678 				 unsigned int desc_len)
1679 {
1680 	return smb_direct_rdma_xmit(SMBD_TRANS(t), buf, buflen,
1681 				    desc, desc_len, false);
1682 }
1683 
1684 static int smb_direct_rdma_read(struct ksmbd_transport *t,
1685 				void *buf, unsigned int buflen,
1686 				struct smbdirect_buffer_descriptor_v1 *desc,
1687 				unsigned int desc_len)
1688 {
1689 	return smb_direct_rdma_xmit(SMBD_TRANS(t), buf, buflen,
1690 				    desc, desc_len, true);
1691 }
1692 
1693 static void smb_direct_disconnect(struct ksmbd_transport *t)
1694 {
1695 	struct smb_direct_transport *st = SMBD_TRANS(t);
1696 	struct smbdirect_socket *sc = &st->socket;
1697 
1698 	ksmbd_debug(RDMA, "Disconnecting cm_id=%p\n", sc->rdma.cm_id);
1699 
1700 	free_transport(st);
1701 }
1702 
1703 static void smb_direct_shutdown(struct ksmbd_transport *t)
1704 {
1705 	struct smb_direct_transport *st = SMBD_TRANS(t);
1706 	struct smbdirect_socket *sc = &st->socket;
1707 
1708 	ksmbd_debug(RDMA, "smb-direct shutdown cm_id=%p\n", sc->rdma.cm_id);
1709 
1710 	smb_direct_disconnect_rdma_work(&sc->disconnect_work);
1711 }
1712 
1713 static int smb_direct_cm_handler(struct rdma_cm_id *cm_id,
1714 				 struct rdma_cm_event *event)
1715 {
1716 	struct smbdirect_socket *sc = cm_id->context;
1717 
1718 	ksmbd_debug(RDMA, "RDMA CM event. cm_id=%p event=%s (%d)\n",
1719 		    cm_id, rdma_event_msg(event->event), event->event);
1720 
1721 	switch (event->event) {
1722 	case RDMA_CM_EVENT_ESTABLISHED: {
1723 		WARN_ON_ONCE(sc->status != SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING);
1724 		sc->status = SMBDIRECT_SOCKET_NEGOTIATE_NEEDED;
1725 		wake_up(&sc->status_wait);
1726 		break;
1727 	}
1728 	case RDMA_CM_EVENT_DEVICE_REMOVAL:
1729 	case RDMA_CM_EVENT_DISCONNECTED: {
1730 		ib_drain_qp(sc->ib.qp);
1731 
1732 		sc->status = SMBDIRECT_SOCKET_DISCONNECTED;
1733 		smb_direct_disconnect_rdma_work(&sc->disconnect_work);
1734 		break;
1735 	}
1736 	case RDMA_CM_EVENT_CONNECT_ERROR: {
1737 		sc->status = SMBDIRECT_SOCKET_DISCONNECTED;
1738 		smb_direct_disconnect_rdma_work(&sc->disconnect_work);
1739 		break;
1740 	}
1741 	default:
1742 		pr_err("Unexpected RDMA CM event. cm_id=%p, event=%s (%d)\n",
1743 		       cm_id, rdma_event_msg(event->event),
1744 		       event->event);
1745 		break;
1746 	}
1747 	return 0;
1748 }
1749 
1750 static void smb_direct_qpair_handler(struct ib_event *event, void *context)
1751 {
1752 	struct smbdirect_socket *sc = context;
1753 
1754 	ksmbd_debug(RDMA, "Received QP event. cm_id=%p, event=%s (%d)\n",
1755 		    sc->rdma.cm_id, ib_event_msg(event->event), event->event);
1756 
1757 	switch (event->event) {
1758 	case IB_EVENT_CQ_ERR:
1759 	case IB_EVENT_QP_FATAL:
1760 		smb_direct_disconnect_rdma_connection(sc);
1761 		break;
1762 	default:
1763 		break;
1764 	}
1765 }
1766 
1767 static int smb_direct_send_negotiate_response(struct smbdirect_socket *sc,
1768 					      int failed)
1769 {
1770 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1771 	struct smbdirect_send_io *sendmsg;
1772 	struct smbdirect_negotiate_resp *resp;
1773 	int ret;
1774 
1775 	sendmsg = smb_direct_alloc_sendmsg(sc);
1776 	if (IS_ERR(sendmsg))
1777 		return -ENOMEM;
1778 
1779 	resp = (struct smbdirect_negotiate_resp *)sendmsg->packet;
1780 	if (failed) {
1781 		memset(resp, 0, sizeof(*resp));
1782 		resp->min_version = SMB_DIRECT_VERSION_LE;
1783 		resp->max_version = SMB_DIRECT_VERSION_LE;
1784 		resp->status = STATUS_NOT_SUPPORTED;
1785 
1786 		sc->status = SMBDIRECT_SOCKET_NEGOTIATE_FAILED;
1787 	} else {
1788 		resp->status = STATUS_SUCCESS;
1789 		resp->min_version = SMB_DIRECT_VERSION_LE;
1790 		resp->max_version = SMB_DIRECT_VERSION_LE;
1791 		resp->negotiated_version = SMB_DIRECT_VERSION_LE;
1792 		resp->reserved = 0;
1793 		resp->credits_requested =
1794 				cpu_to_le16(sp->send_credit_target);
1795 		resp->credits_granted = cpu_to_le16(manage_credits_prior_sending(sc));
1796 		resp->max_readwrite_size = cpu_to_le32(sp->max_read_write_size);
1797 		resp->preferred_send_size = cpu_to_le32(sp->max_send_size);
1798 		resp->max_receive_size = cpu_to_le32(sp->max_recv_size);
1799 		resp->max_fragmented_size =
1800 				cpu_to_le32(sp->max_fragmented_recv_size);
1801 
1802 		sc->recv_io.expected = SMBDIRECT_EXPECT_DATA_TRANSFER;
1803 		sc->status = SMBDIRECT_SOCKET_CONNECTED;
1804 	}
1805 
1806 	sendmsg->sge[0].addr = ib_dma_map_single(sc->ib.dev,
1807 						 (void *)resp, sizeof(*resp),
1808 						 DMA_TO_DEVICE);
1809 	ret = ib_dma_mapping_error(sc->ib.dev, sendmsg->sge[0].addr);
1810 	if (ret) {
1811 		smb_direct_free_sendmsg(sc, sendmsg);
1812 		return ret;
1813 	}
1814 
1815 	sendmsg->num_sge = 1;
1816 	sendmsg->sge[0].length = sizeof(*resp);
1817 	sendmsg->sge[0].lkey = sc->ib.pd->local_dma_lkey;
1818 
1819 	ret = post_sendmsg(sc, NULL, sendmsg);
1820 	if (ret) {
1821 		smb_direct_free_sendmsg(sc, sendmsg);
1822 		return ret;
1823 	}
1824 
1825 	wait_event(sc->send_io.pending.zero_wait_queue,
1826 		   atomic_read(&sc->send_io.pending.count) == 0 ||
1827 		   sc->status != SMBDIRECT_SOCKET_CONNECTED);
1828 	if (sc->status != SMBDIRECT_SOCKET_CONNECTED)
1829 		return -ENOTCONN;
1830 
1831 	return 0;
1832 }
1833 
1834 static int smb_direct_accept_client(struct smbdirect_socket *sc)
1835 {
1836 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1837 	struct rdma_conn_param conn_param;
1838 	__be32 ird_ord_hdr[2];
1839 	int ret;
1840 
1841 	/*
1842 	 * smb_direct_handle_connect_request()
1843 	 * already negotiated sp->initiator_depth
1844 	 * and sp->responder_resources
1845 	 */
1846 	memset(&conn_param, 0, sizeof(conn_param));
1847 	conn_param.initiator_depth = sp->initiator_depth;
1848 	conn_param.responder_resources = sp->responder_resources;
1849 
1850 	if (sc->rdma.legacy_iwarp) {
1851 		ird_ord_hdr[0] = cpu_to_be32(conn_param.responder_resources);
1852 		ird_ord_hdr[1] = cpu_to_be32(conn_param.initiator_depth);
1853 		conn_param.private_data = ird_ord_hdr;
1854 		conn_param.private_data_len = sizeof(ird_ord_hdr);
1855 	} else {
1856 		conn_param.private_data = NULL;
1857 		conn_param.private_data_len = 0;
1858 	}
1859 	conn_param.retry_count = SMB_DIRECT_CM_RETRY;
1860 	conn_param.rnr_retry_count = SMB_DIRECT_CM_RNR_RETRY;
1861 	conn_param.flow_control = 0;
1862 
1863 	/*
1864 	 * start with the negotiate timeout and SMBDIRECT_KEEPALIVE_PENDING
1865 	 * so that the timer will cause a disconnect.
1866 	 */
1867 	sc->idle.keepalive = SMBDIRECT_KEEPALIVE_PENDING;
1868 	mod_delayed_work(sc->workqueue, &sc->idle.timer_work,
1869 			 msecs_to_jiffies(sp->negotiate_timeout_msec));
1870 
1871 	WARN_ON_ONCE(sc->status != SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED);
1872 	sc->status = SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING;
1873 	ret = rdma_accept(sc->rdma.cm_id, &conn_param);
1874 	if (ret) {
1875 		pr_err("error at rdma_accept: %d\n", ret);
1876 		return ret;
1877 	}
1878 	return 0;
1879 }
1880 
1881 static int smb_direct_prepare_negotiation(struct smbdirect_socket *sc)
1882 {
1883 	struct smbdirect_recv_io *recvmsg;
1884 	int ret;
1885 
1886 	WARN_ON_ONCE(sc->status != SMBDIRECT_SOCKET_CREATED);
1887 	sc->status = SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED;
1888 
1889 	sc->recv_io.expected = SMBDIRECT_EXPECT_NEGOTIATE_REQ;
1890 
1891 	recvmsg = get_free_recvmsg(sc);
1892 	if (!recvmsg)
1893 		return -ENOMEM;
1894 
1895 	ret = smb_direct_post_recv(sc, recvmsg);
1896 	if (ret) {
1897 		pr_err("Can't post recv: %d\n", ret);
1898 		goto out_err;
1899 	}
1900 
1901 	ret = smb_direct_accept_client(sc);
1902 	if (ret) {
1903 		pr_err("Can't accept client\n");
1904 		goto out_err;
1905 	}
1906 
1907 	smb_direct_post_recv_credits(&sc->recv_io.posted.refill_work);
1908 	return 0;
1909 out_err:
1910 	put_recvmsg(sc, recvmsg);
1911 	return ret;
1912 }
1913 
1914 static int smb_direct_init_params(struct smbdirect_socket *sc)
1915 {
1916 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1917 	int max_send_sges;
1918 	unsigned int maxpages;
1919 
1920 	/* need 3 more sge. because a SMB_DIRECT header, SMB2 header,
1921 	 * SMB2 response could be mapped.
1922 	 */
1923 	max_send_sges = DIV_ROUND_UP(sp->max_send_size, PAGE_SIZE) + 3;
1924 	if (max_send_sges > SMBDIRECT_SEND_IO_MAX_SGE) {
1925 		pr_err("max_send_size %d is too large\n", sp->max_send_size);
1926 		return -EINVAL;
1927 	}
1928 
1929 	atomic_set(&sc->send_io.lcredits.count, sp->send_credit_target);
1930 
1931 	maxpages = DIV_ROUND_UP(sp->max_read_write_size, PAGE_SIZE);
1932 	sc->rw_io.credits.max = rdma_rw_mr_factor(sc->ib.dev,
1933 						  sc->rdma.cm_id->port_num,
1934 						  maxpages);
1935 	sc->rw_io.credits.num_pages = DIV_ROUND_UP(maxpages, sc->rw_io.credits.max);
1936 	/* add one extra in order to handle unaligned pages */
1937 	sc->rw_io.credits.max += 1;
1938 
1939 	sc->recv_io.credits.target = 1;
1940 
1941 	atomic_set(&sc->rw_io.credits.count, sc->rw_io.credits.max);
1942 
1943 	return 0;
1944 }
1945 
1946 static void smb_direct_destroy_pools(struct smbdirect_socket *sc)
1947 {
1948 	struct smbdirect_recv_io *recvmsg;
1949 
1950 	while ((recvmsg = get_free_recvmsg(sc)))
1951 		mempool_free(recvmsg, sc->recv_io.mem.pool);
1952 
1953 	mempool_destroy(sc->recv_io.mem.pool);
1954 	sc->recv_io.mem.pool = NULL;
1955 
1956 	kmem_cache_destroy(sc->recv_io.mem.cache);
1957 	sc->recv_io.mem.cache = NULL;
1958 
1959 	mempool_destroy(sc->send_io.mem.pool);
1960 	sc->send_io.mem.pool = NULL;
1961 
1962 	kmem_cache_destroy(sc->send_io.mem.cache);
1963 	sc->send_io.mem.cache = NULL;
1964 }
1965 
1966 static int smb_direct_create_pools(struct smbdirect_socket *sc)
1967 {
1968 	struct smbdirect_socket_parameters *sp = &sc->parameters;
1969 	char name[80];
1970 	int i;
1971 	struct smbdirect_recv_io *recvmsg;
1972 
1973 	snprintf(name, sizeof(name), "smbdirect_send_io_pool_%p", sc);
1974 	sc->send_io.mem.cache = kmem_cache_create(name,
1975 					     sizeof(struct smbdirect_send_io) +
1976 					      sizeof(struct smbdirect_negotiate_resp),
1977 					     0, SLAB_HWCACHE_ALIGN, NULL);
1978 	if (!sc->send_io.mem.cache)
1979 		return -ENOMEM;
1980 
1981 	sc->send_io.mem.pool = mempool_create(sp->send_credit_target,
1982 					    mempool_alloc_slab, mempool_free_slab,
1983 					    sc->send_io.mem.cache);
1984 	if (!sc->send_io.mem.pool)
1985 		goto err;
1986 
1987 	snprintf(name, sizeof(name), "smbdirect_recv_io_pool_%p", sc);
1988 	sc->recv_io.mem.cache = kmem_cache_create(name,
1989 					     sizeof(struct smbdirect_recv_io) +
1990 					     sp->max_recv_size,
1991 					     0, SLAB_HWCACHE_ALIGN, NULL);
1992 	if (!sc->recv_io.mem.cache)
1993 		goto err;
1994 
1995 	sc->recv_io.mem.pool =
1996 		mempool_create(sp->recv_credit_max, mempool_alloc_slab,
1997 			       mempool_free_slab, sc->recv_io.mem.cache);
1998 	if (!sc->recv_io.mem.pool)
1999 		goto err;
2000 
2001 	for (i = 0; i < sp->recv_credit_max; i++) {
2002 		recvmsg = mempool_alloc(sc->recv_io.mem.pool, KSMBD_DEFAULT_GFP);
2003 		if (!recvmsg)
2004 			goto err;
2005 		recvmsg->socket = sc;
2006 		recvmsg->sge.length = 0;
2007 		list_add(&recvmsg->list, &sc->recv_io.free.list);
2008 	}
2009 
2010 	return 0;
2011 err:
2012 	smb_direct_destroy_pools(sc);
2013 	return -ENOMEM;
2014 }
2015 
2016 static u32 smb_direct_rdma_rw_send_wrs(struct ib_device *dev, const struct ib_qp_init_attr *attr)
2017 {
2018 	/*
2019 	 * This could be split out of rdma_rw_init_qp()
2020 	 * and be a helper function next to rdma_rw_mr_factor()
2021 	 *
2022 	 * We can't check unlikely(rdma_rw_force_mr) here,
2023 	 * but that is most likely 0 anyway.
2024 	 */
2025 	u32 factor;
2026 
2027 	WARN_ON_ONCE(attr->port_num == 0);
2028 
2029 	/*
2030 	 * Each context needs at least one RDMA READ or WRITE WR.
2031 	 *
2032 	 * For some hardware we might need more, eventually we should ask the
2033 	 * HCA driver for a multiplier here.
2034 	 */
2035 	factor = 1;
2036 
2037 	/*
2038 	 * If the device needs MRs to perform RDMA READ or WRITE operations,
2039 	 * we'll need two additional MRs for the registrations and the
2040 	 * invalidation.
2041 	 */
2042 	if (rdma_protocol_iwarp(dev, attr->port_num) || dev->attrs.max_sgl_rd)
2043 		factor += 2;	/* inv + reg */
2044 
2045 	return factor * attr->cap.max_rdma_ctxs;
2046 }
2047 
2048 static int smb_direct_create_qpair(struct smbdirect_socket *sc)
2049 {
2050 	struct smbdirect_socket_parameters *sp = &sc->parameters;
2051 	int ret;
2052 	struct ib_qp_cap qp_cap;
2053 	struct ib_qp_init_attr qp_attr;
2054 	u32 max_send_wr;
2055 	u32 rdma_send_wr;
2056 
2057 	/*
2058 	 * Note that {rdma,ib}_create_qp() will call
2059 	 * rdma_rw_init_qp() if cap->max_rdma_ctxs is not 0.
2060 	 * It will adjust cap->max_send_wr to the required
2061 	 * number of additional WRs for the RDMA RW operations.
2062 	 * It will cap cap->max_send_wr to the device limit.
2063 	 *
2064 	 * +1 for ib_drain_qp
2065 	 */
2066 	qp_cap.max_send_wr = sp->send_credit_target + 1;
2067 	qp_cap.max_recv_wr = sp->recv_credit_max + 1;
2068 	qp_cap.max_send_sge = SMBDIRECT_SEND_IO_MAX_SGE;
2069 	qp_cap.max_recv_sge = SMBDIRECT_RECV_IO_MAX_SGE;
2070 	qp_cap.max_inline_data = 0;
2071 	qp_cap.max_rdma_ctxs = sc->rw_io.credits.max;
2072 
2073 	/*
2074 	 * Find out the number of max_send_wr
2075 	 * after rdma_rw_init_qp() adjusted it.
2076 	 *
2077 	 * We only do it on a temporary variable,
2078 	 * as rdma_create_qp() will trigger
2079 	 * rdma_rw_init_qp() again.
2080 	 */
2081 	memset(&qp_attr, 0, sizeof(qp_attr));
2082 	qp_attr.cap = qp_cap;
2083 	qp_attr.port_num = sc->rdma.cm_id->port_num;
2084 	rdma_send_wr = smb_direct_rdma_rw_send_wrs(sc->ib.dev, &qp_attr);
2085 	max_send_wr = qp_cap.max_send_wr + rdma_send_wr;
2086 
2087 	if (qp_cap.max_send_wr > sc->ib.dev->attrs.max_cqe ||
2088 	    qp_cap.max_send_wr > sc->ib.dev->attrs.max_qp_wr) {
2089 		pr_err("Possible CQE overrun: max_send_wr %d\n",
2090 		       qp_cap.max_send_wr);
2091 		pr_err("device %.*s reporting max_cqe %d max_qp_wr %d\n",
2092 		       IB_DEVICE_NAME_MAX,
2093 		       sc->ib.dev->name,
2094 		       sc->ib.dev->attrs.max_cqe,
2095 		       sc->ib.dev->attrs.max_qp_wr);
2096 		pr_err("consider lowering send_credit_target = %d\n",
2097 		       sp->send_credit_target);
2098 		return -EINVAL;
2099 	}
2100 
2101 	if (qp_cap.max_rdma_ctxs &&
2102 	    (max_send_wr >= sc->ib.dev->attrs.max_cqe ||
2103 	     max_send_wr >= sc->ib.dev->attrs.max_qp_wr)) {
2104 		pr_err("Possible CQE overrun: rdma_send_wr %d + max_send_wr %d = %d\n",
2105 		       rdma_send_wr, qp_cap.max_send_wr, max_send_wr);
2106 		pr_err("device %.*s reporting max_cqe %d max_qp_wr %d\n",
2107 		       IB_DEVICE_NAME_MAX,
2108 		       sc->ib.dev->name,
2109 		       sc->ib.dev->attrs.max_cqe,
2110 		       sc->ib.dev->attrs.max_qp_wr);
2111 		pr_err("consider lowering send_credit_target = %d, max_rdma_ctxs = %d\n",
2112 		       sp->send_credit_target, qp_cap.max_rdma_ctxs);
2113 		return -EINVAL;
2114 	}
2115 
2116 	if (qp_cap.max_recv_wr > sc->ib.dev->attrs.max_cqe ||
2117 	    qp_cap.max_recv_wr > sc->ib.dev->attrs.max_qp_wr) {
2118 		pr_err("Possible CQE overrun: max_recv_wr %d\n",
2119 		       qp_cap.max_recv_wr);
2120 		pr_err("device %.*s reporting max_cqe %d max_qp_wr %d\n",
2121 		       IB_DEVICE_NAME_MAX,
2122 		       sc->ib.dev->name,
2123 		       sc->ib.dev->attrs.max_cqe,
2124 		       sc->ib.dev->attrs.max_qp_wr);
2125 		pr_err("consider lowering receive_credit_max = %d\n",
2126 		       sp->recv_credit_max);
2127 		return -EINVAL;
2128 	}
2129 
2130 	if (qp_cap.max_send_sge > sc->ib.dev->attrs.max_send_sge ||
2131 	    qp_cap.max_recv_sge > sc->ib.dev->attrs.max_recv_sge) {
2132 		pr_err("device %.*s max_send_sge/max_recv_sge = %d/%d too small\n",
2133 		       IB_DEVICE_NAME_MAX,
2134 		       sc->ib.dev->name,
2135 		       sc->ib.dev->attrs.max_send_sge,
2136 		       sc->ib.dev->attrs.max_recv_sge);
2137 		return -EINVAL;
2138 	}
2139 
2140 	sc->ib.pd = ib_alloc_pd(sc->ib.dev, 0);
2141 	if (IS_ERR(sc->ib.pd)) {
2142 		pr_err("Can't create RDMA PD\n");
2143 		ret = PTR_ERR(sc->ib.pd);
2144 		sc->ib.pd = NULL;
2145 		return ret;
2146 	}
2147 
2148 	sc->ib.send_cq = ib_alloc_cq_any(sc->ib.dev, sc,
2149 					 max_send_wr,
2150 					 IB_POLL_WORKQUEUE);
2151 	if (IS_ERR(sc->ib.send_cq)) {
2152 		pr_err("Can't create RDMA send CQ\n");
2153 		ret = PTR_ERR(sc->ib.send_cq);
2154 		sc->ib.send_cq = NULL;
2155 		goto err;
2156 	}
2157 
2158 	sc->ib.recv_cq = ib_alloc_cq_any(sc->ib.dev, sc,
2159 					 qp_cap.max_recv_wr,
2160 					 IB_POLL_WORKQUEUE);
2161 	if (IS_ERR(sc->ib.recv_cq)) {
2162 		pr_err("Can't create RDMA recv CQ\n");
2163 		ret = PTR_ERR(sc->ib.recv_cq);
2164 		sc->ib.recv_cq = NULL;
2165 		goto err;
2166 	}
2167 
2168 	/*
2169 	 * We reset completely here!
2170 	 * As the above use was just temporary
2171 	 * to calc max_send_wr and rdma_send_wr.
2172 	 *
2173 	 * rdma_create_qp() will trigger rdma_rw_init_qp()
2174 	 * again if max_rdma_ctxs is not 0.
2175 	 */
2176 	memset(&qp_attr, 0, sizeof(qp_attr));
2177 	qp_attr.event_handler = smb_direct_qpair_handler;
2178 	qp_attr.qp_context = sc;
2179 	qp_attr.cap = qp_cap;
2180 	qp_attr.sq_sig_type = IB_SIGNAL_REQ_WR;
2181 	qp_attr.qp_type = IB_QPT_RC;
2182 	qp_attr.send_cq = sc->ib.send_cq;
2183 	qp_attr.recv_cq = sc->ib.recv_cq;
2184 	qp_attr.port_num = ~0;
2185 
2186 	ret = rdma_create_qp(sc->rdma.cm_id, sc->ib.pd, &qp_attr);
2187 	if (ret) {
2188 		pr_err("Can't create RDMA QP: %d\n", ret);
2189 		goto err;
2190 	}
2191 
2192 	sc->ib.qp = sc->rdma.cm_id->qp;
2193 	sc->rdma.cm_id->event_handler = smb_direct_cm_handler;
2194 
2195 	return 0;
2196 err:
2197 	if (sc->ib.qp) {
2198 		sc->ib.qp = NULL;
2199 		rdma_destroy_qp(sc->rdma.cm_id);
2200 	}
2201 	if (sc->ib.recv_cq) {
2202 		ib_destroy_cq(sc->ib.recv_cq);
2203 		sc->ib.recv_cq = NULL;
2204 	}
2205 	if (sc->ib.send_cq) {
2206 		ib_destroy_cq(sc->ib.send_cq);
2207 		sc->ib.send_cq = NULL;
2208 	}
2209 	if (sc->ib.pd) {
2210 		ib_dealloc_pd(sc->ib.pd);
2211 		sc->ib.pd = NULL;
2212 	}
2213 	return ret;
2214 }
2215 
2216 static int smb_direct_prepare(struct ksmbd_transport *t)
2217 {
2218 	struct smb_direct_transport *st = SMBD_TRANS(t);
2219 	struct smbdirect_socket *sc = &st->socket;
2220 	struct smbdirect_socket_parameters *sp = &sc->parameters;
2221 	struct smbdirect_recv_io *recvmsg;
2222 	struct smbdirect_negotiate_req *req;
2223 	unsigned long flags;
2224 	int ret;
2225 
2226 	/*
2227 	 * We are waiting to pass the following states:
2228 	 *
2229 	 * SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED
2230 	 * SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING
2231 	 * SMBDIRECT_SOCKET_NEGOTIATE_NEEDED
2232 	 *
2233 	 * To finally get to SMBDIRECT_SOCKET_NEGOTIATE_RUNNING
2234 	 * in order to continue below.
2235 	 *
2236 	 * Everything else is unexpected and an error.
2237 	 */
2238 	ksmbd_debug(RDMA, "Waiting for SMB_DIRECT negotiate request\n");
2239 	ret = wait_event_interruptible_timeout(sc->status_wait,
2240 					sc->status != SMBDIRECT_SOCKET_RDMA_CONNECT_NEEDED &&
2241 					sc->status != SMBDIRECT_SOCKET_RDMA_CONNECT_RUNNING &&
2242 					sc->status != SMBDIRECT_SOCKET_NEGOTIATE_NEEDED,
2243 					msecs_to_jiffies(sp->negotiate_timeout_msec));
2244 	if (ret <= 0 || sc->status != SMBDIRECT_SOCKET_NEGOTIATE_RUNNING)
2245 		return ret < 0 ? ret : -ETIMEDOUT;
2246 
2247 	recvmsg = get_first_reassembly(sc);
2248 	if (!recvmsg)
2249 		return -ECONNABORTED;
2250 
2251 	ret = smb_direct_check_recvmsg(recvmsg);
2252 	if (ret == -ECONNABORTED)
2253 		goto out;
2254 
2255 	req = (struct smbdirect_negotiate_req *)recvmsg->packet;
2256 	sp->max_recv_size = min_t(int, sp->max_recv_size,
2257 				  le32_to_cpu(req->preferred_send_size));
2258 	sp->max_send_size = min_t(int, sp->max_send_size,
2259 				  le32_to_cpu(req->max_receive_size));
2260 	sp->max_fragmented_send_size =
2261 		le32_to_cpu(req->max_fragmented_size);
2262 	sp->max_fragmented_recv_size =
2263 		(sp->recv_credit_max * sp->max_recv_size) / 2;
2264 	sc->recv_io.credits.target = le16_to_cpu(req->credits_requested);
2265 	sc->recv_io.credits.target = min_t(u16, sc->recv_io.credits.target, sp->recv_credit_max);
2266 	sc->recv_io.credits.target = max_t(u16, sc->recv_io.credits.target, 1);
2267 
2268 	ret = smb_direct_send_negotiate_response(sc, ret);
2269 out:
2270 	spin_lock_irqsave(&sc->recv_io.reassembly.lock, flags);
2271 	sc->recv_io.reassembly.queue_length--;
2272 	list_del(&recvmsg->list);
2273 	spin_unlock_irqrestore(&sc->recv_io.reassembly.lock, flags);
2274 	put_recvmsg(sc, recvmsg);
2275 
2276 	return ret;
2277 }
2278 
2279 static int smb_direct_connect(struct smbdirect_socket *sc)
2280 {
2281 	int ret;
2282 
2283 	ret = smb_direct_init_params(sc);
2284 	if (ret) {
2285 		pr_err("Can't configure RDMA parameters\n");
2286 		return ret;
2287 	}
2288 
2289 	ret = smb_direct_create_pools(sc);
2290 	if (ret) {
2291 		pr_err("Can't init RDMA pool: %d\n", ret);
2292 		return ret;
2293 	}
2294 
2295 	ret = smb_direct_create_qpair(sc);
2296 	if (ret) {
2297 		pr_err("Can't accept RDMA client: %d\n", ret);
2298 		return ret;
2299 	}
2300 
2301 	ret = smb_direct_prepare_negotiation(sc);
2302 	if (ret) {
2303 		pr_err("Can't negotiate: %d\n", ret);
2304 		return ret;
2305 	}
2306 	return 0;
2307 }
2308 
2309 static bool rdma_frwr_is_supported(struct ib_device_attr *attrs)
2310 {
2311 	if (!(attrs->device_cap_flags & IB_DEVICE_MEM_MGT_EXTENSIONS))
2312 		return false;
2313 	if (attrs->max_fast_reg_page_list_len == 0)
2314 		return false;
2315 	return true;
2316 }
2317 
2318 static int smb_direct_handle_connect_request(struct rdma_cm_id *new_cm_id,
2319 					     struct rdma_cm_event *event)
2320 {
2321 	struct smb_direct_transport *t;
2322 	struct smbdirect_socket *sc;
2323 	struct smbdirect_socket_parameters *sp;
2324 	struct task_struct *handler;
2325 	u8 peer_initiator_depth;
2326 	u8 peer_responder_resources;
2327 	int ret;
2328 
2329 	if (!rdma_frwr_is_supported(&new_cm_id->device->attrs)) {
2330 		ksmbd_debug(RDMA,
2331 			    "Fast Registration Work Requests is not supported. device capabilities=%llx\n",
2332 			    new_cm_id->device->attrs.device_cap_flags);
2333 		return -EPROTONOSUPPORT;
2334 	}
2335 
2336 	t = alloc_transport(new_cm_id);
2337 	if (!t)
2338 		return -ENOMEM;
2339 	sc = &t->socket;
2340 	sp = &sc->parameters;
2341 
2342 	peer_initiator_depth = event->param.conn.initiator_depth;
2343 	peer_responder_resources = event->param.conn.responder_resources;
2344 	if (rdma_protocol_iwarp(new_cm_id->device, new_cm_id->port_num) &&
2345 	    event->param.conn.private_data_len == 8) {
2346 		/*
2347 		 * Legacy clients with only iWarp MPA v1 support
2348 		 * need a private blob in order to negotiate
2349 		 * the IRD/ORD values.
2350 		 */
2351 		const __be32 *ird_ord_hdr = event->param.conn.private_data;
2352 		u32 ird32 = be32_to_cpu(ird_ord_hdr[0]);
2353 		u32 ord32 = be32_to_cpu(ird_ord_hdr[1]);
2354 
2355 		/*
2356 		 * cifs.ko sends the legacy IRD/ORD negotiation
2357 		 * event if iWarp MPA v2 was used.
2358 		 *
2359 		 * Here we check that the values match and only
2360 		 * mark the client as legacy if they don't match.
2361 		 */
2362 		if ((u32)event->param.conn.initiator_depth != ird32 ||
2363 		    (u32)event->param.conn.responder_resources != ord32) {
2364 			/*
2365 			 * There are broken clients (old cifs.ko)
2366 			 * using little endian and also
2367 			 * struct rdma_conn_param only uses u8
2368 			 * for initiator_depth and responder_resources,
2369 			 * so we truncate the value to U8_MAX.
2370 			 *
2371 			 * smb_direct_accept_client() will then
2372 			 * do the real negotiation in order to
2373 			 * select the minimum between client and
2374 			 * server.
2375 			 */
2376 			ird32 = min_t(u32, ird32, U8_MAX);
2377 			ord32 = min_t(u32, ord32, U8_MAX);
2378 
2379 			sc->rdma.legacy_iwarp = true;
2380 			peer_initiator_depth = (u8)ird32;
2381 			peer_responder_resources = (u8)ord32;
2382 		}
2383 	}
2384 
2385 	/*
2386 	 * First set what the we as server are able to support
2387 	 */
2388 	sp->initiator_depth = min_t(u8, sp->initiator_depth,
2389 				   new_cm_id->device->attrs.max_qp_rd_atom);
2390 
2391 	/*
2392 	 * negotiate the value by using the minimum
2393 	 * between client and server if the client provided
2394 	 * non 0 values.
2395 	 */
2396 	if (peer_initiator_depth != 0)
2397 		sp->initiator_depth = min_t(u8, sp->initiator_depth,
2398 					   peer_initiator_depth);
2399 	if (peer_responder_resources != 0)
2400 		sp->responder_resources = min_t(u8, sp->responder_resources,
2401 					       peer_responder_resources);
2402 
2403 	ret = smb_direct_connect(sc);
2404 	if (ret)
2405 		goto out_err;
2406 
2407 	handler = kthread_run(ksmbd_conn_handler_loop,
2408 			      KSMBD_TRANS(t)->conn, "ksmbd:r%u",
2409 			      smb_direct_port);
2410 	if (IS_ERR(handler)) {
2411 		ret = PTR_ERR(handler);
2412 		pr_err("Can't start thread\n");
2413 		goto out_err;
2414 	}
2415 
2416 	return 0;
2417 out_err:
2418 	free_transport(t);
2419 	return ret;
2420 }
2421 
2422 static int smb_direct_listen_handler(struct rdma_cm_id *cm_id,
2423 				     struct rdma_cm_event *event)
2424 {
2425 	switch (event->event) {
2426 	case RDMA_CM_EVENT_CONNECT_REQUEST: {
2427 		int ret = smb_direct_handle_connect_request(cm_id, event);
2428 
2429 		if (ret) {
2430 			pr_err("Can't create transport: %d\n", ret);
2431 			return ret;
2432 		}
2433 
2434 		ksmbd_debug(RDMA, "Received connection request. cm_id=%p\n",
2435 			    cm_id);
2436 		break;
2437 	}
2438 	default:
2439 		pr_err("Unexpected listen event. cm_id=%p, event=%s (%d)\n",
2440 		       cm_id, rdma_event_msg(event->event), event->event);
2441 		break;
2442 	}
2443 	return 0;
2444 }
2445 
2446 static int smb_direct_listen(int port)
2447 {
2448 	int ret;
2449 	struct rdma_cm_id *cm_id;
2450 	struct sockaddr_in sin = {
2451 		.sin_family		= AF_INET,
2452 		.sin_addr.s_addr	= htonl(INADDR_ANY),
2453 		.sin_port		= htons(port),
2454 	};
2455 
2456 	cm_id = rdma_create_id(&init_net, smb_direct_listen_handler,
2457 			       &smb_direct_listener, RDMA_PS_TCP, IB_QPT_RC);
2458 	if (IS_ERR(cm_id)) {
2459 		pr_err("Can't create cm id: %ld\n", PTR_ERR(cm_id));
2460 		return PTR_ERR(cm_id);
2461 	}
2462 
2463 	ret = rdma_bind_addr(cm_id, (struct sockaddr *)&sin);
2464 	if (ret) {
2465 		pr_err("Can't bind: %d\n", ret);
2466 		goto err;
2467 	}
2468 
2469 	smb_direct_listener.cm_id = cm_id;
2470 
2471 	ret = rdma_listen(cm_id, 10);
2472 	if (ret) {
2473 		pr_err("Can't listen: %d\n", ret);
2474 		goto err;
2475 	}
2476 	return 0;
2477 err:
2478 	smb_direct_listener.cm_id = NULL;
2479 	rdma_destroy_id(cm_id);
2480 	return ret;
2481 }
2482 
2483 static int smb_direct_ib_client_add(struct ib_device *ib_dev)
2484 {
2485 	struct smb_direct_device *smb_dev;
2486 
2487 	/* Set 5445 port if device type is iWARP(No IB) */
2488 	if (ib_dev->node_type != RDMA_NODE_IB_CA)
2489 		smb_direct_port = SMB_DIRECT_PORT_IWARP;
2490 
2491 	if (!rdma_frwr_is_supported(&ib_dev->attrs))
2492 		return 0;
2493 
2494 	smb_dev = kzalloc(sizeof(*smb_dev), KSMBD_DEFAULT_GFP);
2495 	if (!smb_dev)
2496 		return -ENOMEM;
2497 	smb_dev->ib_dev = ib_dev;
2498 
2499 	write_lock(&smb_direct_device_lock);
2500 	list_add(&smb_dev->list, &smb_direct_device_list);
2501 	write_unlock(&smb_direct_device_lock);
2502 
2503 	ksmbd_debug(RDMA, "ib device added: name %s\n", ib_dev->name);
2504 	return 0;
2505 }
2506 
2507 static void smb_direct_ib_client_remove(struct ib_device *ib_dev,
2508 					void *client_data)
2509 {
2510 	struct smb_direct_device *smb_dev, *tmp;
2511 
2512 	write_lock(&smb_direct_device_lock);
2513 	list_for_each_entry_safe(smb_dev, tmp, &smb_direct_device_list, list) {
2514 		if (smb_dev->ib_dev == ib_dev) {
2515 			list_del(&smb_dev->list);
2516 			kfree(smb_dev);
2517 			break;
2518 		}
2519 	}
2520 	write_unlock(&smb_direct_device_lock);
2521 }
2522 
2523 static struct ib_client smb_direct_ib_client = {
2524 	.name	= "ksmbd_smb_direct_ib",
2525 	.add	= smb_direct_ib_client_add,
2526 	.remove	= smb_direct_ib_client_remove,
2527 };
2528 
2529 int ksmbd_rdma_init(void)
2530 {
2531 	int ret;
2532 
2533 	smb_direct_listener.cm_id = NULL;
2534 
2535 	ret = ib_register_client(&smb_direct_ib_client);
2536 	if (ret) {
2537 		pr_err("failed to ib_register_client\n");
2538 		return ret;
2539 	}
2540 
2541 	/* When a client is running out of send credits, the credits are
2542 	 * granted by the server's sending a packet using this queue.
2543 	 * This avoids the situation that a clients cannot send packets
2544 	 * for lack of credits
2545 	 */
2546 	smb_direct_wq = alloc_workqueue("ksmbd-smb_direct-wq",
2547 					WQ_HIGHPRI | WQ_MEM_RECLAIM | WQ_PERCPU,
2548 					0);
2549 	if (!smb_direct_wq)
2550 		return -ENOMEM;
2551 
2552 	ret = smb_direct_listen(smb_direct_port);
2553 	if (ret) {
2554 		destroy_workqueue(smb_direct_wq);
2555 		smb_direct_wq = NULL;
2556 		pr_err("Can't listen: %d\n", ret);
2557 		return ret;
2558 	}
2559 
2560 	ksmbd_debug(RDMA, "init RDMA listener. cm_id=%p\n",
2561 		    smb_direct_listener.cm_id);
2562 	return 0;
2563 }
2564 
2565 void ksmbd_rdma_stop_listening(void)
2566 {
2567 	if (!smb_direct_listener.cm_id)
2568 		return;
2569 
2570 	ib_unregister_client(&smb_direct_ib_client);
2571 	rdma_destroy_id(smb_direct_listener.cm_id);
2572 
2573 	smb_direct_listener.cm_id = NULL;
2574 }
2575 
2576 void ksmbd_rdma_destroy(void)
2577 {
2578 	if (smb_direct_wq) {
2579 		destroy_workqueue(smb_direct_wq);
2580 		smb_direct_wq = NULL;
2581 	}
2582 }
2583 
2584 bool ksmbd_rdma_capable_netdev(struct net_device *netdev)
2585 {
2586 	struct smb_direct_device *smb_dev;
2587 	int i;
2588 	bool rdma_capable = false;
2589 
2590 	read_lock(&smb_direct_device_lock);
2591 	list_for_each_entry(smb_dev, &smb_direct_device_list, list) {
2592 		for (i = 0; i < smb_dev->ib_dev->phys_port_cnt; i++) {
2593 			struct net_device *ndev;
2594 
2595 			ndev = ib_device_get_netdev(smb_dev->ib_dev, i + 1);
2596 			if (!ndev)
2597 				continue;
2598 
2599 			if (ndev == netdev) {
2600 				dev_put(ndev);
2601 				rdma_capable = true;
2602 				goto out;
2603 			}
2604 			dev_put(ndev);
2605 		}
2606 	}
2607 out:
2608 	read_unlock(&smb_direct_device_lock);
2609 
2610 	if (rdma_capable == false) {
2611 		struct ib_device *ibdev;
2612 
2613 		ibdev = ib_device_get_by_netdev(netdev, RDMA_DRIVER_UNKNOWN);
2614 		if (ibdev) {
2615 			rdma_capable = rdma_frwr_is_supported(&ibdev->attrs);
2616 			ib_device_put(ibdev);
2617 		}
2618 	}
2619 
2620 	ksmbd_debug(RDMA, "netdev(%s) rdma capable : %s\n",
2621 		    netdev->name, str_true_false(rdma_capable));
2622 
2623 	return rdma_capable;
2624 }
2625 
2626 static const struct ksmbd_transport_ops ksmbd_smb_direct_transport_ops = {
2627 	.prepare	= smb_direct_prepare,
2628 	.disconnect	= smb_direct_disconnect,
2629 	.shutdown	= smb_direct_shutdown,
2630 	.writev		= smb_direct_writev,
2631 	.read		= smb_direct_read,
2632 	.rdma_read	= smb_direct_rdma_read,
2633 	.rdma_write	= smb_direct_rdma_write,
2634 	.free_transport = smb_direct_free_transport,
2635 };
2636