xref: /OK3568_Linux_fs/kernel/drivers/target/iscsi/iscsi_target_erl1.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*******************************************************************************
3*4882a593Smuzhiyun  * This file contains error recovery level one used by the iSCSI Target driver.
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * (c) Copyright 2007-2013 Datera, Inc.
6*4882a593Smuzhiyun  *
7*4882a593Smuzhiyun  * Author: Nicholas A. Bellinger <nab@linux-iscsi.org>
8*4882a593Smuzhiyun  *
9*4882a593Smuzhiyun  ******************************************************************************/
10*4882a593Smuzhiyun 
11*4882a593Smuzhiyun #include <linux/list.h>
12*4882a593Smuzhiyun #include <linux/slab.h>
13*4882a593Smuzhiyun #include <scsi/iscsi_proto.h>
14*4882a593Smuzhiyun #include <target/target_core_base.h>
15*4882a593Smuzhiyun #include <target/target_core_fabric.h>
16*4882a593Smuzhiyun #include <target/iscsi/iscsi_transport.h>
17*4882a593Smuzhiyun 
18*4882a593Smuzhiyun #include <target/iscsi/iscsi_target_core.h>
19*4882a593Smuzhiyun #include "iscsi_target_seq_pdu_list.h"
20*4882a593Smuzhiyun #include "iscsi_target_datain_values.h"
21*4882a593Smuzhiyun #include "iscsi_target_device.h"
22*4882a593Smuzhiyun #include "iscsi_target_tpg.h"
23*4882a593Smuzhiyun #include "iscsi_target_util.h"
24*4882a593Smuzhiyun #include "iscsi_target_erl0.h"
25*4882a593Smuzhiyun #include "iscsi_target_erl1.h"
26*4882a593Smuzhiyun #include "iscsi_target_erl2.h"
27*4882a593Smuzhiyun #include "iscsi_target.h"
28*4882a593Smuzhiyun 
29*4882a593Smuzhiyun #define OFFLOAD_BUF_SIZE	32768U
30*4882a593Smuzhiyun 
31*4882a593Smuzhiyun /*
32*4882a593Smuzhiyun  *	Used to dump excess datain payload for certain error recovery
33*4882a593Smuzhiyun  *	situations.  Receive in OFFLOAD_BUF_SIZE max of datain per rx_data().
34*4882a593Smuzhiyun  *
35*4882a593Smuzhiyun  *	dump_padding_digest denotes if padding and data digests need
36*4882a593Smuzhiyun  *	to be dumped.
37*4882a593Smuzhiyun  */
iscsit_dump_data_payload(struct iscsi_conn * conn,u32 buf_len,int dump_padding_digest)38*4882a593Smuzhiyun int iscsit_dump_data_payload(
39*4882a593Smuzhiyun 	struct iscsi_conn *conn,
40*4882a593Smuzhiyun 	u32 buf_len,
41*4882a593Smuzhiyun 	int dump_padding_digest)
42*4882a593Smuzhiyun {
43*4882a593Smuzhiyun 	char *buf;
44*4882a593Smuzhiyun 	int ret = DATAOUT_WITHIN_COMMAND_RECOVERY, rx_got;
45*4882a593Smuzhiyun 	u32 length, offset = 0, size;
46*4882a593Smuzhiyun 	struct kvec iov;
47*4882a593Smuzhiyun 
48*4882a593Smuzhiyun 	if (conn->sess->sess_ops->RDMAExtensions)
49*4882a593Smuzhiyun 		return 0;
50*4882a593Smuzhiyun 
51*4882a593Smuzhiyun 	if (dump_padding_digest) {
52*4882a593Smuzhiyun 		buf_len = ALIGN(buf_len, 4);
53*4882a593Smuzhiyun 		if (conn->conn_ops->DataDigest)
54*4882a593Smuzhiyun 			buf_len += ISCSI_CRC_LEN;
55*4882a593Smuzhiyun 	}
56*4882a593Smuzhiyun 
57*4882a593Smuzhiyun 	length = min(buf_len, OFFLOAD_BUF_SIZE);
58*4882a593Smuzhiyun 
59*4882a593Smuzhiyun 	buf = kzalloc(length, GFP_ATOMIC);
60*4882a593Smuzhiyun 	if (!buf) {
61*4882a593Smuzhiyun 		pr_err("Unable to allocate %u bytes for offload"
62*4882a593Smuzhiyun 				" buffer.\n", length);
63*4882a593Smuzhiyun 		return -1;
64*4882a593Smuzhiyun 	}
65*4882a593Smuzhiyun 	memset(&iov, 0, sizeof(struct kvec));
66*4882a593Smuzhiyun 
67*4882a593Smuzhiyun 	while (offset < buf_len) {
68*4882a593Smuzhiyun 		size = min(buf_len - offset, length);
69*4882a593Smuzhiyun 
70*4882a593Smuzhiyun 		iov.iov_len = size;
71*4882a593Smuzhiyun 		iov.iov_base = buf;
72*4882a593Smuzhiyun 
73*4882a593Smuzhiyun 		rx_got = rx_data(conn, &iov, 1, size);
74*4882a593Smuzhiyun 		if (rx_got != size) {
75*4882a593Smuzhiyun 			ret = DATAOUT_CANNOT_RECOVER;
76*4882a593Smuzhiyun 			break;
77*4882a593Smuzhiyun 		}
78*4882a593Smuzhiyun 
79*4882a593Smuzhiyun 		offset += size;
80*4882a593Smuzhiyun 	}
81*4882a593Smuzhiyun 
82*4882a593Smuzhiyun 	kfree(buf);
83*4882a593Smuzhiyun 	return ret;
84*4882a593Smuzhiyun }
85*4882a593Smuzhiyun 
86*4882a593Smuzhiyun /*
87*4882a593Smuzhiyun  *	Used for retransmitting R2Ts from a R2T SNACK request.
88*4882a593Smuzhiyun  */
iscsit_send_recovery_r2t_for_snack(struct iscsi_cmd * cmd,struct iscsi_r2t * r2t)89*4882a593Smuzhiyun static int iscsit_send_recovery_r2t_for_snack(
90*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
91*4882a593Smuzhiyun 	struct iscsi_r2t *r2t)
92*4882a593Smuzhiyun {
93*4882a593Smuzhiyun 	/*
94*4882a593Smuzhiyun 	 * If the struct iscsi_r2t has not been sent yet, we can safely
95*4882a593Smuzhiyun 	 * ignore retransmission
96*4882a593Smuzhiyun 	 * of the R2TSN in question.
97*4882a593Smuzhiyun 	 */
98*4882a593Smuzhiyun 	spin_lock_bh(&cmd->r2t_lock);
99*4882a593Smuzhiyun 	if (!r2t->sent_r2t) {
100*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->r2t_lock);
101*4882a593Smuzhiyun 		return 0;
102*4882a593Smuzhiyun 	}
103*4882a593Smuzhiyun 	r2t->sent_r2t = 0;
104*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->r2t_lock);
105*4882a593Smuzhiyun 
106*4882a593Smuzhiyun 	iscsit_add_cmd_to_immediate_queue(cmd, cmd->conn, ISTATE_SEND_R2T);
107*4882a593Smuzhiyun 
108*4882a593Smuzhiyun 	return 0;
109*4882a593Smuzhiyun }
110*4882a593Smuzhiyun 
iscsit_handle_r2t_snack(struct iscsi_cmd * cmd,unsigned char * buf,u32 begrun,u32 runlength)111*4882a593Smuzhiyun static int iscsit_handle_r2t_snack(
112*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
113*4882a593Smuzhiyun 	unsigned char *buf,
114*4882a593Smuzhiyun 	u32 begrun,
115*4882a593Smuzhiyun 	u32 runlength)
116*4882a593Smuzhiyun {
117*4882a593Smuzhiyun 	u32 last_r2tsn;
118*4882a593Smuzhiyun 	struct iscsi_r2t *r2t;
119*4882a593Smuzhiyun 
120*4882a593Smuzhiyun 	/*
121*4882a593Smuzhiyun 	 * Make sure the initiator is not requesting retransmission
122*4882a593Smuzhiyun 	 * of R2TSNs already acknowledged by a TMR TASK_REASSIGN.
123*4882a593Smuzhiyun 	 */
124*4882a593Smuzhiyun 	if ((cmd->cmd_flags & ICF_GOT_DATACK_SNACK) &&
125*4882a593Smuzhiyun 	    (begrun <= cmd->acked_data_sn)) {
126*4882a593Smuzhiyun 		pr_err("ITT: 0x%08x, R2T SNACK requesting"
127*4882a593Smuzhiyun 			" retransmission of R2TSN: 0x%08x to 0x%08x but already"
128*4882a593Smuzhiyun 			" acked to  R2TSN: 0x%08x by TMR TASK_REASSIGN,"
129*4882a593Smuzhiyun 			" protocol error.\n", cmd->init_task_tag, begrun,
130*4882a593Smuzhiyun 			(begrun + runlength), cmd->acked_data_sn);
131*4882a593Smuzhiyun 
132*4882a593Smuzhiyun 		return iscsit_reject_cmd(cmd, ISCSI_REASON_PROTOCOL_ERROR, buf);
133*4882a593Smuzhiyun 	}
134*4882a593Smuzhiyun 
135*4882a593Smuzhiyun 	if (runlength) {
136*4882a593Smuzhiyun 		if ((begrun + runlength) > cmd->r2t_sn) {
137*4882a593Smuzhiyun 			pr_err("Command ITT: 0x%08x received R2T SNACK"
138*4882a593Smuzhiyun 			" with BegRun: 0x%08x, RunLength: 0x%08x, exceeds"
139*4882a593Smuzhiyun 			" current R2TSN: 0x%08x, protocol error.\n",
140*4882a593Smuzhiyun 			cmd->init_task_tag, begrun, runlength, cmd->r2t_sn);
141*4882a593Smuzhiyun 			return iscsit_reject_cmd(cmd,
142*4882a593Smuzhiyun 					ISCSI_REASON_BOOKMARK_INVALID, buf);
143*4882a593Smuzhiyun 		}
144*4882a593Smuzhiyun 		last_r2tsn = (begrun + runlength);
145*4882a593Smuzhiyun 	} else
146*4882a593Smuzhiyun 		last_r2tsn = cmd->r2t_sn;
147*4882a593Smuzhiyun 
148*4882a593Smuzhiyun 	while (begrun < last_r2tsn) {
149*4882a593Smuzhiyun 		r2t = iscsit_get_holder_for_r2tsn(cmd, begrun);
150*4882a593Smuzhiyun 		if (!r2t)
151*4882a593Smuzhiyun 			return -1;
152*4882a593Smuzhiyun 		if (iscsit_send_recovery_r2t_for_snack(cmd, r2t) < 0)
153*4882a593Smuzhiyun 			return -1;
154*4882a593Smuzhiyun 
155*4882a593Smuzhiyun 		begrun++;
156*4882a593Smuzhiyun 	}
157*4882a593Smuzhiyun 
158*4882a593Smuzhiyun 	return 0;
159*4882a593Smuzhiyun }
160*4882a593Smuzhiyun 
161*4882a593Smuzhiyun /*
162*4882a593Smuzhiyun  *	Generates Offsets and NextBurstLength based on Begrun and Runlength
163*4882a593Smuzhiyun  *	carried in a Data SNACK or ExpDataSN in TMR TASK_REASSIGN.
164*4882a593Smuzhiyun  *
165*4882a593Smuzhiyun  *	For DataSequenceInOrder=Yes and DataPDUInOrder=[Yes,No] only.
166*4882a593Smuzhiyun  *
167*4882a593Smuzhiyun  *	FIXME: How is this handled for a RData SNACK?
168*4882a593Smuzhiyun  */
iscsit_create_recovery_datain_values_datasequenceinorder_yes(struct iscsi_cmd * cmd,struct iscsi_datain_req * dr)169*4882a593Smuzhiyun int iscsit_create_recovery_datain_values_datasequenceinorder_yes(
170*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
171*4882a593Smuzhiyun 	struct iscsi_datain_req *dr)
172*4882a593Smuzhiyun {
173*4882a593Smuzhiyun 	u32 data_sn = 0, data_sn_count = 0;
174*4882a593Smuzhiyun 	u32 pdu_start = 0, seq_no = 0;
175*4882a593Smuzhiyun 	u32 begrun = dr->begrun;
176*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
177*4882a593Smuzhiyun 
178*4882a593Smuzhiyun 	while (begrun > data_sn++) {
179*4882a593Smuzhiyun 		data_sn_count++;
180*4882a593Smuzhiyun 		if ((dr->next_burst_len +
181*4882a593Smuzhiyun 		     conn->conn_ops->MaxRecvDataSegmentLength) <
182*4882a593Smuzhiyun 		     conn->sess->sess_ops->MaxBurstLength) {
183*4882a593Smuzhiyun 			dr->read_data_done +=
184*4882a593Smuzhiyun 				conn->conn_ops->MaxRecvDataSegmentLength;
185*4882a593Smuzhiyun 			dr->next_burst_len +=
186*4882a593Smuzhiyun 				conn->conn_ops->MaxRecvDataSegmentLength;
187*4882a593Smuzhiyun 		} else {
188*4882a593Smuzhiyun 			dr->read_data_done +=
189*4882a593Smuzhiyun 				(conn->sess->sess_ops->MaxBurstLength -
190*4882a593Smuzhiyun 				 dr->next_burst_len);
191*4882a593Smuzhiyun 			dr->next_burst_len = 0;
192*4882a593Smuzhiyun 			pdu_start += data_sn_count;
193*4882a593Smuzhiyun 			data_sn_count = 0;
194*4882a593Smuzhiyun 			seq_no++;
195*4882a593Smuzhiyun 		}
196*4882a593Smuzhiyun 	}
197*4882a593Smuzhiyun 
198*4882a593Smuzhiyun 	if (!conn->sess->sess_ops->DataPDUInOrder) {
199*4882a593Smuzhiyun 		cmd->seq_no = seq_no;
200*4882a593Smuzhiyun 		cmd->pdu_start = pdu_start;
201*4882a593Smuzhiyun 		cmd->pdu_send_order = data_sn_count;
202*4882a593Smuzhiyun 	}
203*4882a593Smuzhiyun 
204*4882a593Smuzhiyun 	return 0;
205*4882a593Smuzhiyun }
206*4882a593Smuzhiyun 
207*4882a593Smuzhiyun /*
208*4882a593Smuzhiyun  *	Generates Offsets and NextBurstLength based on Begrun and Runlength
209*4882a593Smuzhiyun  *	carried in a Data SNACK or ExpDataSN in TMR TASK_REASSIGN.
210*4882a593Smuzhiyun  *
211*4882a593Smuzhiyun  *	For DataSequenceInOrder=No and DataPDUInOrder=[Yes,No] only.
212*4882a593Smuzhiyun  *
213*4882a593Smuzhiyun  *	FIXME: How is this handled for a RData SNACK?
214*4882a593Smuzhiyun  */
iscsit_create_recovery_datain_values_datasequenceinorder_no(struct iscsi_cmd * cmd,struct iscsi_datain_req * dr)215*4882a593Smuzhiyun int iscsit_create_recovery_datain_values_datasequenceinorder_no(
216*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
217*4882a593Smuzhiyun 	struct iscsi_datain_req *dr)
218*4882a593Smuzhiyun {
219*4882a593Smuzhiyun 	int found_seq = 0, i;
220*4882a593Smuzhiyun 	u32 data_sn, read_data_done = 0, seq_send_order = 0;
221*4882a593Smuzhiyun 	u32 begrun = dr->begrun;
222*4882a593Smuzhiyun 	u32 runlength = dr->runlength;
223*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
224*4882a593Smuzhiyun 	struct iscsi_seq *first_seq = NULL, *seq = NULL;
225*4882a593Smuzhiyun 
226*4882a593Smuzhiyun 	if (!cmd->seq_list) {
227*4882a593Smuzhiyun 		pr_err("struct iscsi_cmd->seq_list is NULL!\n");
228*4882a593Smuzhiyun 		return -1;
229*4882a593Smuzhiyun 	}
230*4882a593Smuzhiyun 
231*4882a593Smuzhiyun 	/*
232*4882a593Smuzhiyun 	 * Calculate read_data_done for all sequences containing a
233*4882a593Smuzhiyun 	 * first_datasn and last_datasn less than the BegRun.
234*4882a593Smuzhiyun 	 *
235*4882a593Smuzhiyun 	 * Locate the struct iscsi_seq the BegRun lies within and calculate
236*4882a593Smuzhiyun 	 * NextBurstLenghth up to the DataSN based on MaxRecvDataSegmentLength.
237*4882a593Smuzhiyun 	 *
238*4882a593Smuzhiyun 	 * Also use struct iscsi_seq->seq_send_order to determine where to start.
239*4882a593Smuzhiyun 	 */
240*4882a593Smuzhiyun 	for (i = 0; i < cmd->seq_count; i++) {
241*4882a593Smuzhiyun 		seq = &cmd->seq_list[i];
242*4882a593Smuzhiyun 
243*4882a593Smuzhiyun 		if (!seq->seq_send_order)
244*4882a593Smuzhiyun 			first_seq = seq;
245*4882a593Smuzhiyun 
246*4882a593Smuzhiyun 		/*
247*4882a593Smuzhiyun 		 * No data has been transferred for this DataIN sequence, so the
248*4882a593Smuzhiyun 		 * seq->first_datasn and seq->last_datasn have not been set.
249*4882a593Smuzhiyun 		 */
250*4882a593Smuzhiyun 		if (!seq->sent) {
251*4882a593Smuzhiyun 			pr_err("Ignoring non-sent sequence 0x%08x ->"
252*4882a593Smuzhiyun 				" 0x%08x\n\n", seq->first_datasn,
253*4882a593Smuzhiyun 				seq->last_datasn);
254*4882a593Smuzhiyun 			continue;
255*4882a593Smuzhiyun 		}
256*4882a593Smuzhiyun 
257*4882a593Smuzhiyun 		/*
258*4882a593Smuzhiyun 		 * This DataIN sequence is precedes the received BegRun, add the
259*4882a593Smuzhiyun 		 * total xfer_len of the sequence to read_data_done and reset
260*4882a593Smuzhiyun 		 * seq->pdu_send_order.
261*4882a593Smuzhiyun 		 */
262*4882a593Smuzhiyun 		if ((seq->first_datasn < begrun) &&
263*4882a593Smuzhiyun 				(seq->last_datasn < begrun)) {
264*4882a593Smuzhiyun 			pr_err("Pre BegRun sequence 0x%08x ->"
265*4882a593Smuzhiyun 				" 0x%08x\n", seq->first_datasn,
266*4882a593Smuzhiyun 				seq->last_datasn);
267*4882a593Smuzhiyun 
268*4882a593Smuzhiyun 			read_data_done += cmd->seq_list[i].xfer_len;
269*4882a593Smuzhiyun 			seq->next_burst_len = seq->pdu_send_order = 0;
270*4882a593Smuzhiyun 			continue;
271*4882a593Smuzhiyun 		}
272*4882a593Smuzhiyun 
273*4882a593Smuzhiyun 		/*
274*4882a593Smuzhiyun 		 * The BegRun lies within this DataIN sequence.
275*4882a593Smuzhiyun 		 */
276*4882a593Smuzhiyun 		if ((seq->first_datasn <= begrun) &&
277*4882a593Smuzhiyun 				(seq->last_datasn >= begrun)) {
278*4882a593Smuzhiyun 			pr_err("Found sequence begrun: 0x%08x in"
279*4882a593Smuzhiyun 				" 0x%08x -> 0x%08x\n", begrun,
280*4882a593Smuzhiyun 				seq->first_datasn, seq->last_datasn);
281*4882a593Smuzhiyun 
282*4882a593Smuzhiyun 			seq_send_order = seq->seq_send_order;
283*4882a593Smuzhiyun 			data_sn = seq->first_datasn;
284*4882a593Smuzhiyun 			seq->next_burst_len = seq->pdu_send_order = 0;
285*4882a593Smuzhiyun 			found_seq = 1;
286*4882a593Smuzhiyun 
287*4882a593Smuzhiyun 			/*
288*4882a593Smuzhiyun 			 * For DataPDUInOrder=Yes, while the first DataSN of
289*4882a593Smuzhiyun 			 * the sequence is less than the received BegRun, add
290*4882a593Smuzhiyun 			 * the MaxRecvDataSegmentLength to read_data_done and
291*4882a593Smuzhiyun 			 * to the sequence's next_burst_len;
292*4882a593Smuzhiyun 			 *
293*4882a593Smuzhiyun 			 * For DataPDUInOrder=No, while the first DataSN of the
294*4882a593Smuzhiyun 			 * sequence is less than the received BegRun, find the
295*4882a593Smuzhiyun 			 * struct iscsi_pdu of the DataSN in question and add the
296*4882a593Smuzhiyun 			 * MaxRecvDataSegmentLength to read_data_done and to the
297*4882a593Smuzhiyun 			 * sequence's next_burst_len;
298*4882a593Smuzhiyun 			 */
299*4882a593Smuzhiyun 			if (conn->sess->sess_ops->DataPDUInOrder) {
300*4882a593Smuzhiyun 				while (data_sn < begrun) {
301*4882a593Smuzhiyun 					seq->pdu_send_order++;
302*4882a593Smuzhiyun 					read_data_done +=
303*4882a593Smuzhiyun 						conn->conn_ops->MaxRecvDataSegmentLength;
304*4882a593Smuzhiyun 					seq->next_burst_len +=
305*4882a593Smuzhiyun 						conn->conn_ops->MaxRecvDataSegmentLength;
306*4882a593Smuzhiyun 					data_sn++;
307*4882a593Smuzhiyun 				}
308*4882a593Smuzhiyun 			} else {
309*4882a593Smuzhiyun 				int j;
310*4882a593Smuzhiyun 				struct iscsi_pdu *pdu;
311*4882a593Smuzhiyun 
312*4882a593Smuzhiyun 				while (data_sn < begrun) {
313*4882a593Smuzhiyun 					seq->pdu_send_order++;
314*4882a593Smuzhiyun 
315*4882a593Smuzhiyun 					for (j = 0; j < seq->pdu_count; j++) {
316*4882a593Smuzhiyun 						pdu = &cmd->pdu_list[
317*4882a593Smuzhiyun 							seq->pdu_start + j];
318*4882a593Smuzhiyun 						if (pdu->data_sn == data_sn) {
319*4882a593Smuzhiyun 							read_data_done +=
320*4882a593Smuzhiyun 								pdu->length;
321*4882a593Smuzhiyun 							seq->next_burst_len +=
322*4882a593Smuzhiyun 								pdu->length;
323*4882a593Smuzhiyun 						}
324*4882a593Smuzhiyun 					}
325*4882a593Smuzhiyun 					data_sn++;
326*4882a593Smuzhiyun 				}
327*4882a593Smuzhiyun 			}
328*4882a593Smuzhiyun 			continue;
329*4882a593Smuzhiyun 		}
330*4882a593Smuzhiyun 
331*4882a593Smuzhiyun 		/*
332*4882a593Smuzhiyun 		 * This DataIN sequence is larger than the received BegRun,
333*4882a593Smuzhiyun 		 * reset seq->pdu_send_order and continue.
334*4882a593Smuzhiyun 		 */
335*4882a593Smuzhiyun 		if ((seq->first_datasn > begrun) ||
336*4882a593Smuzhiyun 				(seq->last_datasn > begrun)) {
337*4882a593Smuzhiyun 			pr_err("Post BegRun sequence 0x%08x -> 0x%08x\n",
338*4882a593Smuzhiyun 					seq->first_datasn, seq->last_datasn);
339*4882a593Smuzhiyun 
340*4882a593Smuzhiyun 			seq->next_burst_len = seq->pdu_send_order = 0;
341*4882a593Smuzhiyun 			continue;
342*4882a593Smuzhiyun 		}
343*4882a593Smuzhiyun 	}
344*4882a593Smuzhiyun 
345*4882a593Smuzhiyun 	if (!found_seq) {
346*4882a593Smuzhiyun 		if (!begrun) {
347*4882a593Smuzhiyun 			if (!first_seq) {
348*4882a593Smuzhiyun 				pr_err("ITT: 0x%08x, Begrun: 0x%08x"
349*4882a593Smuzhiyun 					" but first_seq is NULL\n",
350*4882a593Smuzhiyun 					cmd->init_task_tag, begrun);
351*4882a593Smuzhiyun 				return -1;
352*4882a593Smuzhiyun 			}
353*4882a593Smuzhiyun 			seq_send_order = first_seq->seq_send_order;
354*4882a593Smuzhiyun 			seq->next_burst_len = seq->pdu_send_order = 0;
355*4882a593Smuzhiyun 			goto done;
356*4882a593Smuzhiyun 		}
357*4882a593Smuzhiyun 
358*4882a593Smuzhiyun 		pr_err("Unable to locate struct iscsi_seq for ITT: 0x%08x,"
359*4882a593Smuzhiyun 			" BegRun: 0x%08x, RunLength: 0x%08x while"
360*4882a593Smuzhiyun 			" DataSequenceInOrder=No and DataPDUInOrder=%s.\n",
361*4882a593Smuzhiyun 				cmd->init_task_tag, begrun, runlength,
362*4882a593Smuzhiyun 			(conn->sess->sess_ops->DataPDUInOrder) ? "Yes" : "No");
363*4882a593Smuzhiyun 		return -1;
364*4882a593Smuzhiyun 	}
365*4882a593Smuzhiyun 
366*4882a593Smuzhiyun done:
367*4882a593Smuzhiyun 	dr->read_data_done = read_data_done;
368*4882a593Smuzhiyun 	dr->seq_send_order = seq_send_order;
369*4882a593Smuzhiyun 
370*4882a593Smuzhiyun 	return 0;
371*4882a593Smuzhiyun }
372*4882a593Smuzhiyun 
iscsit_handle_recovery_datain(struct iscsi_cmd * cmd,unsigned char * buf,u32 begrun,u32 runlength)373*4882a593Smuzhiyun static int iscsit_handle_recovery_datain(
374*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
375*4882a593Smuzhiyun 	unsigned char *buf,
376*4882a593Smuzhiyun 	u32 begrun,
377*4882a593Smuzhiyun 	u32 runlength)
378*4882a593Smuzhiyun {
379*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
380*4882a593Smuzhiyun 	struct iscsi_datain_req *dr;
381*4882a593Smuzhiyun 	struct se_cmd *se_cmd = &cmd->se_cmd;
382*4882a593Smuzhiyun 
383*4882a593Smuzhiyun 	if (!(se_cmd->transport_state & CMD_T_COMPLETE)) {
384*4882a593Smuzhiyun 		pr_err("Ignoring ITT: 0x%08x Data SNACK\n",
385*4882a593Smuzhiyun 				cmd->init_task_tag);
386*4882a593Smuzhiyun 		return 0;
387*4882a593Smuzhiyun 	}
388*4882a593Smuzhiyun 
389*4882a593Smuzhiyun 	/*
390*4882a593Smuzhiyun 	 * Make sure the initiator is not requesting retransmission
391*4882a593Smuzhiyun 	 * of DataSNs already acknowledged by a Data ACK SNACK.
392*4882a593Smuzhiyun 	 */
393*4882a593Smuzhiyun 	if ((cmd->cmd_flags & ICF_GOT_DATACK_SNACK) &&
394*4882a593Smuzhiyun 	    (begrun <= cmd->acked_data_sn)) {
395*4882a593Smuzhiyun 		pr_err("ITT: 0x%08x, Data SNACK requesting"
396*4882a593Smuzhiyun 			" retransmission of DataSN: 0x%08x to 0x%08x but"
397*4882a593Smuzhiyun 			" already acked to DataSN: 0x%08x by Data ACK SNACK,"
398*4882a593Smuzhiyun 			" protocol error.\n", cmd->init_task_tag, begrun,
399*4882a593Smuzhiyun 			(begrun + runlength), cmd->acked_data_sn);
400*4882a593Smuzhiyun 
401*4882a593Smuzhiyun 		return iscsit_reject_cmd(cmd, ISCSI_REASON_PROTOCOL_ERROR, buf);
402*4882a593Smuzhiyun 	}
403*4882a593Smuzhiyun 
404*4882a593Smuzhiyun 	/*
405*4882a593Smuzhiyun 	 * Make sure BegRun and RunLength in the Data SNACK are sane.
406*4882a593Smuzhiyun 	 * Note: (cmd->data_sn - 1) will carry the maximum DataSN sent.
407*4882a593Smuzhiyun 	 */
408*4882a593Smuzhiyun 	if ((begrun + runlength) > (cmd->data_sn - 1)) {
409*4882a593Smuzhiyun 		pr_err("Initiator requesting BegRun: 0x%08x, RunLength"
410*4882a593Smuzhiyun 			": 0x%08x greater than maximum DataSN: 0x%08x.\n",
411*4882a593Smuzhiyun 				begrun, runlength, (cmd->data_sn - 1));
412*4882a593Smuzhiyun 		return iscsit_reject_cmd(cmd, ISCSI_REASON_BOOKMARK_INVALID,
413*4882a593Smuzhiyun 					 buf);
414*4882a593Smuzhiyun 	}
415*4882a593Smuzhiyun 
416*4882a593Smuzhiyun 	dr = iscsit_allocate_datain_req();
417*4882a593Smuzhiyun 	if (!dr)
418*4882a593Smuzhiyun 		return iscsit_reject_cmd(cmd, ISCSI_REASON_BOOKMARK_NO_RESOURCES,
419*4882a593Smuzhiyun 					 buf);
420*4882a593Smuzhiyun 
421*4882a593Smuzhiyun 	dr->data_sn = dr->begrun = begrun;
422*4882a593Smuzhiyun 	dr->runlength = runlength;
423*4882a593Smuzhiyun 	dr->generate_recovery_values = 1;
424*4882a593Smuzhiyun 	dr->recovery = DATAIN_WITHIN_COMMAND_RECOVERY;
425*4882a593Smuzhiyun 
426*4882a593Smuzhiyun 	iscsit_attach_datain_req(cmd, dr);
427*4882a593Smuzhiyun 
428*4882a593Smuzhiyun 	cmd->i_state = ISTATE_SEND_DATAIN;
429*4882a593Smuzhiyun 	iscsit_add_cmd_to_response_queue(cmd, conn, cmd->i_state);
430*4882a593Smuzhiyun 
431*4882a593Smuzhiyun 	return 0;
432*4882a593Smuzhiyun }
433*4882a593Smuzhiyun 
iscsit_handle_recovery_datain_or_r2t(struct iscsi_conn * conn,unsigned char * buf,itt_t init_task_tag,u32 targ_xfer_tag,u32 begrun,u32 runlength)434*4882a593Smuzhiyun int iscsit_handle_recovery_datain_or_r2t(
435*4882a593Smuzhiyun 	struct iscsi_conn *conn,
436*4882a593Smuzhiyun 	unsigned char *buf,
437*4882a593Smuzhiyun 	itt_t init_task_tag,
438*4882a593Smuzhiyun 	u32 targ_xfer_tag,
439*4882a593Smuzhiyun 	u32 begrun,
440*4882a593Smuzhiyun 	u32 runlength)
441*4882a593Smuzhiyun {
442*4882a593Smuzhiyun 	struct iscsi_cmd *cmd;
443*4882a593Smuzhiyun 
444*4882a593Smuzhiyun 	cmd = iscsit_find_cmd_from_itt(conn, init_task_tag);
445*4882a593Smuzhiyun 	if (!cmd)
446*4882a593Smuzhiyun 		return 0;
447*4882a593Smuzhiyun 
448*4882a593Smuzhiyun 	/*
449*4882a593Smuzhiyun 	 * FIXME: This will not work for bidi commands.
450*4882a593Smuzhiyun 	 */
451*4882a593Smuzhiyun 	switch (cmd->data_direction) {
452*4882a593Smuzhiyun 	case DMA_TO_DEVICE:
453*4882a593Smuzhiyun 		return iscsit_handle_r2t_snack(cmd, buf, begrun, runlength);
454*4882a593Smuzhiyun 	case DMA_FROM_DEVICE:
455*4882a593Smuzhiyun 		return iscsit_handle_recovery_datain(cmd, buf, begrun,
456*4882a593Smuzhiyun 				runlength);
457*4882a593Smuzhiyun 	default:
458*4882a593Smuzhiyun 		pr_err("Unknown cmd->data_direction: 0x%02x\n",
459*4882a593Smuzhiyun 				cmd->data_direction);
460*4882a593Smuzhiyun 		return -1;
461*4882a593Smuzhiyun 	}
462*4882a593Smuzhiyun 
463*4882a593Smuzhiyun 	return 0;
464*4882a593Smuzhiyun }
465*4882a593Smuzhiyun 
466*4882a593Smuzhiyun /* #warning FIXME: Status SNACK needs to be dependent on OPCODE!!! */
iscsit_handle_status_snack(struct iscsi_conn * conn,itt_t init_task_tag,u32 targ_xfer_tag,u32 begrun,u32 runlength)467*4882a593Smuzhiyun int iscsit_handle_status_snack(
468*4882a593Smuzhiyun 	struct iscsi_conn *conn,
469*4882a593Smuzhiyun 	itt_t init_task_tag,
470*4882a593Smuzhiyun 	u32 targ_xfer_tag,
471*4882a593Smuzhiyun 	u32 begrun,
472*4882a593Smuzhiyun 	u32 runlength)
473*4882a593Smuzhiyun {
474*4882a593Smuzhiyun 	struct iscsi_cmd *cmd = NULL;
475*4882a593Smuzhiyun 	u32 last_statsn;
476*4882a593Smuzhiyun 	int found_cmd;
477*4882a593Smuzhiyun 
478*4882a593Smuzhiyun 	if (!begrun) {
479*4882a593Smuzhiyun 		begrun = conn->exp_statsn;
480*4882a593Smuzhiyun 	} else if (conn->exp_statsn > begrun) {
481*4882a593Smuzhiyun 		pr_err("Got Status SNACK Begrun: 0x%08x, RunLength:"
482*4882a593Smuzhiyun 			" 0x%08x but already got ExpStatSN: 0x%08x on CID:"
483*4882a593Smuzhiyun 			" %hu.\n", begrun, runlength, conn->exp_statsn,
484*4882a593Smuzhiyun 			conn->cid);
485*4882a593Smuzhiyun 		return 0;
486*4882a593Smuzhiyun 	}
487*4882a593Smuzhiyun 
488*4882a593Smuzhiyun 	last_statsn = (!runlength) ? conn->stat_sn : (begrun + runlength);
489*4882a593Smuzhiyun 
490*4882a593Smuzhiyun 	while (begrun < last_statsn) {
491*4882a593Smuzhiyun 		found_cmd = 0;
492*4882a593Smuzhiyun 
493*4882a593Smuzhiyun 		spin_lock_bh(&conn->cmd_lock);
494*4882a593Smuzhiyun 		list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
495*4882a593Smuzhiyun 			if (cmd->stat_sn == begrun) {
496*4882a593Smuzhiyun 				found_cmd = 1;
497*4882a593Smuzhiyun 				break;
498*4882a593Smuzhiyun 			}
499*4882a593Smuzhiyun 		}
500*4882a593Smuzhiyun 		spin_unlock_bh(&conn->cmd_lock);
501*4882a593Smuzhiyun 
502*4882a593Smuzhiyun 		if (!found_cmd) {
503*4882a593Smuzhiyun 			pr_err("Unable to find StatSN: 0x%08x for"
504*4882a593Smuzhiyun 				" a Status SNACK, assuming this was a"
505*4882a593Smuzhiyun 				" protactic SNACK for an untransmitted"
506*4882a593Smuzhiyun 				" StatSN, ignoring.\n", begrun);
507*4882a593Smuzhiyun 			begrun++;
508*4882a593Smuzhiyun 			continue;
509*4882a593Smuzhiyun 		}
510*4882a593Smuzhiyun 
511*4882a593Smuzhiyun 		spin_lock_bh(&cmd->istate_lock);
512*4882a593Smuzhiyun 		if (cmd->i_state == ISTATE_SEND_DATAIN) {
513*4882a593Smuzhiyun 			spin_unlock_bh(&cmd->istate_lock);
514*4882a593Smuzhiyun 			pr_err("Ignoring Status SNACK for BegRun:"
515*4882a593Smuzhiyun 				" 0x%08x, RunLength: 0x%08x, assuming this was"
516*4882a593Smuzhiyun 				" a protactic SNACK for an untransmitted"
517*4882a593Smuzhiyun 				" StatSN\n", begrun, runlength);
518*4882a593Smuzhiyun 			begrun++;
519*4882a593Smuzhiyun 			continue;
520*4882a593Smuzhiyun 		}
521*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
522*4882a593Smuzhiyun 
523*4882a593Smuzhiyun 		cmd->i_state = ISTATE_SEND_STATUS_RECOVERY;
524*4882a593Smuzhiyun 		iscsit_add_cmd_to_response_queue(cmd, conn, cmd->i_state);
525*4882a593Smuzhiyun 		begrun++;
526*4882a593Smuzhiyun 	}
527*4882a593Smuzhiyun 
528*4882a593Smuzhiyun 	return 0;
529*4882a593Smuzhiyun }
530*4882a593Smuzhiyun 
iscsit_handle_data_ack(struct iscsi_conn * conn,u32 targ_xfer_tag,u32 begrun,u32 runlength)531*4882a593Smuzhiyun int iscsit_handle_data_ack(
532*4882a593Smuzhiyun 	struct iscsi_conn *conn,
533*4882a593Smuzhiyun 	u32 targ_xfer_tag,
534*4882a593Smuzhiyun 	u32 begrun,
535*4882a593Smuzhiyun 	u32 runlength)
536*4882a593Smuzhiyun {
537*4882a593Smuzhiyun 	struct iscsi_cmd *cmd = NULL;
538*4882a593Smuzhiyun 
539*4882a593Smuzhiyun 	cmd = iscsit_find_cmd_from_ttt(conn, targ_xfer_tag);
540*4882a593Smuzhiyun 	if (!cmd) {
541*4882a593Smuzhiyun 		pr_err("Data ACK SNACK for TTT: 0x%08x is"
542*4882a593Smuzhiyun 			" invalid.\n", targ_xfer_tag);
543*4882a593Smuzhiyun 		return -1;
544*4882a593Smuzhiyun 	}
545*4882a593Smuzhiyun 
546*4882a593Smuzhiyun 	if (begrun <= cmd->acked_data_sn) {
547*4882a593Smuzhiyun 		pr_err("ITT: 0x%08x Data ACK SNACK BegRUN: 0x%08x is"
548*4882a593Smuzhiyun 			" less than the already acked DataSN: 0x%08x.\n",
549*4882a593Smuzhiyun 			cmd->init_task_tag, begrun, cmd->acked_data_sn);
550*4882a593Smuzhiyun 		return -1;
551*4882a593Smuzhiyun 	}
552*4882a593Smuzhiyun 
553*4882a593Smuzhiyun 	/*
554*4882a593Smuzhiyun 	 * For Data ACK SNACK, BegRun is the next expected DataSN.
555*4882a593Smuzhiyun 	 * (see iSCSI v19: 10.16.6)
556*4882a593Smuzhiyun 	 */
557*4882a593Smuzhiyun 	cmd->cmd_flags |= ICF_GOT_DATACK_SNACK;
558*4882a593Smuzhiyun 	cmd->acked_data_sn = (begrun - 1);
559*4882a593Smuzhiyun 
560*4882a593Smuzhiyun 	pr_debug("Received Data ACK SNACK for ITT: 0x%08x,"
561*4882a593Smuzhiyun 		" updated acked DataSN to 0x%08x.\n",
562*4882a593Smuzhiyun 			cmd->init_task_tag, cmd->acked_data_sn);
563*4882a593Smuzhiyun 
564*4882a593Smuzhiyun 	return 0;
565*4882a593Smuzhiyun }
566*4882a593Smuzhiyun 
iscsit_send_recovery_r2t(struct iscsi_cmd * cmd,u32 offset,u32 xfer_len)567*4882a593Smuzhiyun static int iscsit_send_recovery_r2t(
568*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
569*4882a593Smuzhiyun 	u32 offset,
570*4882a593Smuzhiyun 	u32 xfer_len)
571*4882a593Smuzhiyun {
572*4882a593Smuzhiyun 	int ret;
573*4882a593Smuzhiyun 
574*4882a593Smuzhiyun 	spin_lock_bh(&cmd->r2t_lock);
575*4882a593Smuzhiyun 	ret = iscsit_add_r2t_to_list(cmd, offset, xfer_len, 1, 0);
576*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->r2t_lock);
577*4882a593Smuzhiyun 
578*4882a593Smuzhiyun 	return ret;
579*4882a593Smuzhiyun }
580*4882a593Smuzhiyun 
iscsit_dataout_datapduinorder_no_fbit(struct iscsi_cmd * cmd,struct iscsi_pdu * pdu)581*4882a593Smuzhiyun int iscsit_dataout_datapduinorder_no_fbit(
582*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
583*4882a593Smuzhiyun 	struct iscsi_pdu *pdu)
584*4882a593Smuzhiyun {
585*4882a593Smuzhiyun 	int i, send_recovery_r2t = 0, recovery = 0;
586*4882a593Smuzhiyun 	u32 length = 0, offset = 0, pdu_count = 0, xfer_len = 0;
587*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
588*4882a593Smuzhiyun 	struct iscsi_pdu *first_pdu = NULL;
589*4882a593Smuzhiyun 
590*4882a593Smuzhiyun 	/*
591*4882a593Smuzhiyun 	 * Get an struct iscsi_pdu pointer to the first PDU, and total PDU count
592*4882a593Smuzhiyun 	 * of the DataOUT sequence.
593*4882a593Smuzhiyun 	 */
594*4882a593Smuzhiyun 	if (conn->sess->sess_ops->DataSequenceInOrder) {
595*4882a593Smuzhiyun 		for (i = 0; i < cmd->pdu_count; i++) {
596*4882a593Smuzhiyun 			if (cmd->pdu_list[i].seq_no == pdu->seq_no) {
597*4882a593Smuzhiyun 				if (!first_pdu)
598*4882a593Smuzhiyun 					first_pdu = &cmd->pdu_list[i];
599*4882a593Smuzhiyun 				xfer_len += cmd->pdu_list[i].length;
600*4882a593Smuzhiyun 				pdu_count++;
601*4882a593Smuzhiyun 			} else if (pdu_count)
602*4882a593Smuzhiyun 				break;
603*4882a593Smuzhiyun 		}
604*4882a593Smuzhiyun 	} else {
605*4882a593Smuzhiyun 		struct iscsi_seq *seq = cmd->seq_ptr;
606*4882a593Smuzhiyun 
607*4882a593Smuzhiyun 		first_pdu = &cmd->pdu_list[seq->pdu_start];
608*4882a593Smuzhiyun 		pdu_count = seq->pdu_count;
609*4882a593Smuzhiyun 	}
610*4882a593Smuzhiyun 
611*4882a593Smuzhiyun 	if (!first_pdu || !pdu_count)
612*4882a593Smuzhiyun 		return DATAOUT_CANNOT_RECOVER;
613*4882a593Smuzhiyun 
614*4882a593Smuzhiyun 	/*
615*4882a593Smuzhiyun 	 * Loop through the ending DataOUT Sequence checking each struct iscsi_pdu.
616*4882a593Smuzhiyun 	 * The following ugly logic does batching of not received PDUs.
617*4882a593Smuzhiyun 	 */
618*4882a593Smuzhiyun 	for (i = 0; i < pdu_count; i++) {
619*4882a593Smuzhiyun 		if (first_pdu[i].status == ISCSI_PDU_RECEIVED_OK) {
620*4882a593Smuzhiyun 			if (!send_recovery_r2t)
621*4882a593Smuzhiyun 				continue;
622*4882a593Smuzhiyun 
623*4882a593Smuzhiyun 			if (iscsit_send_recovery_r2t(cmd, offset, length) < 0)
624*4882a593Smuzhiyun 				return DATAOUT_CANNOT_RECOVER;
625*4882a593Smuzhiyun 
626*4882a593Smuzhiyun 			send_recovery_r2t = length = offset = 0;
627*4882a593Smuzhiyun 			continue;
628*4882a593Smuzhiyun 		}
629*4882a593Smuzhiyun 		/*
630*4882a593Smuzhiyun 		 * Set recovery = 1 for any missing, CRC failed, or timed
631*4882a593Smuzhiyun 		 * out PDUs to let the DataOUT logic know that this sequence
632*4882a593Smuzhiyun 		 * has not been completed yet.
633*4882a593Smuzhiyun 		 *
634*4882a593Smuzhiyun 		 * Also, only send a Recovery R2T for ISCSI_PDU_NOT_RECEIVED.
635*4882a593Smuzhiyun 		 * We assume if the PDU either failed CRC or timed out
636*4882a593Smuzhiyun 		 * that a Recovery R2T has already been sent.
637*4882a593Smuzhiyun 		 */
638*4882a593Smuzhiyun 		recovery = 1;
639*4882a593Smuzhiyun 
640*4882a593Smuzhiyun 		if (first_pdu[i].status != ISCSI_PDU_NOT_RECEIVED)
641*4882a593Smuzhiyun 			continue;
642*4882a593Smuzhiyun 
643*4882a593Smuzhiyun 		if (!offset)
644*4882a593Smuzhiyun 			offset = first_pdu[i].offset;
645*4882a593Smuzhiyun 		length += first_pdu[i].length;
646*4882a593Smuzhiyun 
647*4882a593Smuzhiyun 		send_recovery_r2t = 1;
648*4882a593Smuzhiyun 	}
649*4882a593Smuzhiyun 
650*4882a593Smuzhiyun 	if (send_recovery_r2t)
651*4882a593Smuzhiyun 		if (iscsit_send_recovery_r2t(cmd, offset, length) < 0)
652*4882a593Smuzhiyun 			return DATAOUT_CANNOT_RECOVER;
653*4882a593Smuzhiyun 
654*4882a593Smuzhiyun 	return (!recovery) ? DATAOUT_NORMAL : DATAOUT_WITHIN_COMMAND_RECOVERY;
655*4882a593Smuzhiyun }
656*4882a593Smuzhiyun 
iscsit_recalculate_dataout_values(struct iscsi_cmd * cmd,u32 pdu_offset,u32 pdu_length,u32 * r2t_offset,u32 * r2t_length)657*4882a593Smuzhiyun static int iscsit_recalculate_dataout_values(
658*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
659*4882a593Smuzhiyun 	u32 pdu_offset,
660*4882a593Smuzhiyun 	u32 pdu_length,
661*4882a593Smuzhiyun 	u32 *r2t_offset,
662*4882a593Smuzhiyun 	u32 *r2t_length)
663*4882a593Smuzhiyun {
664*4882a593Smuzhiyun 	int i;
665*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
666*4882a593Smuzhiyun 	struct iscsi_pdu *pdu = NULL;
667*4882a593Smuzhiyun 
668*4882a593Smuzhiyun 	if (conn->sess->sess_ops->DataSequenceInOrder) {
669*4882a593Smuzhiyun 		cmd->data_sn = 0;
670*4882a593Smuzhiyun 
671*4882a593Smuzhiyun 		if (conn->sess->sess_ops->DataPDUInOrder) {
672*4882a593Smuzhiyun 			*r2t_offset = cmd->write_data_done;
673*4882a593Smuzhiyun 			*r2t_length = (cmd->seq_end_offset -
674*4882a593Smuzhiyun 					cmd->write_data_done);
675*4882a593Smuzhiyun 			return 0;
676*4882a593Smuzhiyun 		}
677*4882a593Smuzhiyun 
678*4882a593Smuzhiyun 		*r2t_offset = cmd->seq_start_offset;
679*4882a593Smuzhiyun 		*r2t_length = (cmd->seq_end_offset - cmd->seq_start_offset);
680*4882a593Smuzhiyun 
681*4882a593Smuzhiyun 		for (i = 0; i < cmd->pdu_count; i++) {
682*4882a593Smuzhiyun 			pdu = &cmd->pdu_list[i];
683*4882a593Smuzhiyun 
684*4882a593Smuzhiyun 			if (pdu->status != ISCSI_PDU_RECEIVED_OK)
685*4882a593Smuzhiyun 				continue;
686*4882a593Smuzhiyun 
687*4882a593Smuzhiyun 			if ((pdu->offset >= cmd->seq_start_offset) &&
688*4882a593Smuzhiyun 			   ((pdu->offset + pdu->length) <=
689*4882a593Smuzhiyun 			     cmd->seq_end_offset)) {
690*4882a593Smuzhiyun 				if (!cmd->unsolicited_data)
691*4882a593Smuzhiyun 					cmd->next_burst_len -= pdu->length;
692*4882a593Smuzhiyun 				else
693*4882a593Smuzhiyun 					cmd->first_burst_len -= pdu->length;
694*4882a593Smuzhiyun 
695*4882a593Smuzhiyun 				cmd->write_data_done -= pdu->length;
696*4882a593Smuzhiyun 				pdu->status = ISCSI_PDU_NOT_RECEIVED;
697*4882a593Smuzhiyun 			}
698*4882a593Smuzhiyun 		}
699*4882a593Smuzhiyun 	} else {
700*4882a593Smuzhiyun 		struct iscsi_seq *seq = NULL;
701*4882a593Smuzhiyun 
702*4882a593Smuzhiyun 		seq = iscsit_get_seq_holder(cmd, pdu_offset, pdu_length);
703*4882a593Smuzhiyun 		if (!seq)
704*4882a593Smuzhiyun 			return -1;
705*4882a593Smuzhiyun 
706*4882a593Smuzhiyun 		*r2t_offset = seq->orig_offset;
707*4882a593Smuzhiyun 		*r2t_length = seq->xfer_len;
708*4882a593Smuzhiyun 
709*4882a593Smuzhiyun 		cmd->write_data_done -= (seq->offset - seq->orig_offset);
710*4882a593Smuzhiyun 		if (cmd->immediate_data)
711*4882a593Smuzhiyun 			cmd->first_burst_len = cmd->write_data_done;
712*4882a593Smuzhiyun 
713*4882a593Smuzhiyun 		seq->data_sn = 0;
714*4882a593Smuzhiyun 		seq->offset = seq->orig_offset;
715*4882a593Smuzhiyun 		seq->next_burst_len = 0;
716*4882a593Smuzhiyun 		seq->status = DATAOUT_SEQUENCE_WITHIN_COMMAND_RECOVERY;
717*4882a593Smuzhiyun 
718*4882a593Smuzhiyun 		if (conn->sess->sess_ops->DataPDUInOrder)
719*4882a593Smuzhiyun 			return 0;
720*4882a593Smuzhiyun 
721*4882a593Smuzhiyun 		for (i = 0; i < seq->pdu_count; i++) {
722*4882a593Smuzhiyun 			pdu = &cmd->pdu_list[i+seq->pdu_start];
723*4882a593Smuzhiyun 
724*4882a593Smuzhiyun 			if (pdu->status != ISCSI_PDU_RECEIVED_OK)
725*4882a593Smuzhiyun 				continue;
726*4882a593Smuzhiyun 
727*4882a593Smuzhiyun 			pdu->status = ISCSI_PDU_NOT_RECEIVED;
728*4882a593Smuzhiyun 		}
729*4882a593Smuzhiyun 	}
730*4882a593Smuzhiyun 
731*4882a593Smuzhiyun 	return 0;
732*4882a593Smuzhiyun }
733*4882a593Smuzhiyun 
iscsit_recover_dataout_sequence(struct iscsi_cmd * cmd,u32 pdu_offset,u32 pdu_length)734*4882a593Smuzhiyun int iscsit_recover_dataout_sequence(
735*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
736*4882a593Smuzhiyun 	u32 pdu_offset,
737*4882a593Smuzhiyun 	u32 pdu_length)
738*4882a593Smuzhiyun {
739*4882a593Smuzhiyun 	u32 r2t_length = 0, r2t_offset = 0;
740*4882a593Smuzhiyun 
741*4882a593Smuzhiyun 	spin_lock_bh(&cmd->istate_lock);
742*4882a593Smuzhiyun 	cmd->cmd_flags |= ICF_WITHIN_COMMAND_RECOVERY;
743*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->istate_lock);
744*4882a593Smuzhiyun 
745*4882a593Smuzhiyun 	if (iscsit_recalculate_dataout_values(cmd, pdu_offset, pdu_length,
746*4882a593Smuzhiyun 			&r2t_offset, &r2t_length) < 0)
747*4882a593Smuzhiyun 		return DATAOUT_CANNOT_RECOVER;
748*4882a593Smuzhiyun 
749*4882a593Smuzhiyun 	iscsit_send_recovery_r2t(cmd, r2t_offset, r2t_length);
750*4882a593Smuzhiyun 
751*4882a593Smuzhiyun 	return DATAOUT_WITHIN_COMMAND_RECOVERY;
752*4882a593Smuzhiyun }
753*4882a593Smuzhiyun 
iscsit_allocate_ooo_cmdsn(void)754*4882a593Smuzhiyun static struct iscsi_ooo_cmdsn *iscsit_allocate_ooo_cmdsn(void)
755*4882a593Smuzhiyun {
756*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn = NULL;
757*4882a593Smuzhiyun 
758*4882a593Smuzhiyun 	ooo_cmdsn = kmem_cache_zalloc(lio_ooo_cache, GFP_ATOMIC);
759*4882a593Smuzhiyun 	if (!ooo_cmdsn) {
760*4882a593Smuzhiyun 		pr_err("Unable to allocate memory for"
761*4882a593Smuzhiyun 			" struct iscsi_ooo_cmdsn.\n");
762*4882a593Smuzhiyun 		return NULL;
763*4882a593Smuzhiyun 	}
764*4882a593Smuzhiyun 	INIT_LIST_HEAD(&ooo_cmdsn->ooo_list);
765*4882a593Smuzhiyun 
766*4882a593Smuzhiyun 	return ooo_cmdsn;
767*4882a593Smuzhiyun }
768*4882a593Smuzhiyun 
iscsit_attach_ooo_cmdsn(struct iscsi_session * sess,struct iscsi_ooo_cmdsn * ooo_cmdsn)769*4882a593Smuzhiyun static int iscsit_attach_ooo_cmdsn(
770*4882a593Smuzhiyun 	struct iscsi_session *sess,
771*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn)
772*4882a593Smuzhiyun {
773*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_tail, *ooo_tmp;
774*4882a593Smuzhiyun 
775*4882a593Smuzhiyun 	lockdep_assert_held(&sess->cmdsn_mutex);
776*4882a593Smuzhiyun 
777*4882a593Smuzhiyun 	/*
778*4882a593Smuzhiyun 	 * We attach the struct iscsi_ooo_cmdsn entry to the out of order
779*4882a593Smuzhiyun 	 * list in increasing CmdSN order.
780*4882a593Smuzhiyun 	 * This allows iscsi_execute_ooo_cmdsns() to detect any
781*4882a593Smuzhiyun 	 * additional CmdSN holes while performing delayed execution.
782*4882a593Smuzhiyun 	 */
783*4882a593Smuzhiyun 	if (list_empty(&sess->sess_ooo_cmdsn_list))
784*4882a593Smuzhiyun 		list_add_tail(&ooo_cmdsn->ooo_list,
785*4882a593Smuzhiyun 				&sess->sess_ooo_cmdsn_list);
786*4882a593Smuzhiyun 	else {
787*4882a593Smuzhiyun 		ooo_tail = list_entry(sess->sess_ooo_cmdsn_list.prev,
788*4882a593Smuzhiyun 				typeof(*ooo_tail), ooo_list);
789*4882a593Smuzhiyun 		/*
790*4882a593Smuzhiyun 		 * CmdSN is greater than the tail of the list.
791*4882a593Smuzhiyun 		 */
792*4882a593Smuzhiyun 		if (iscsi_sna_lt(ooo_tail->cmdsn, ooo_cmdsn->cmdsn))
793*4882a593Smuzhiyun 			list_add_tail(&ooo_cmdsn->ooo_list,
794*4882a593Smuzhiyun 					&sess->sess_ooo_cmdsn_list);
795*4882a593Smuzhiyun 		else {
796*4882a593Smuzhiyun 			/*
797*4882a593Smuzhiyun 			 * CmdSN is either lower than the head,  or somewhere
798*4882a593Smuzhiyun 			 * in the middle.
799*4882a593Smuzhiyun 			 */
800*4882a593Smuzhiyun 			list_for_each_entry(ooo_tmp, &sess->sess_ooo_cmdsn_list,
801*4882a593Smuzhiyun 						ooo_list) {
802*4882a593Smuzhiyun 				if (iscsi_sna_lt(ooo_tmp->cmdsn, ooo_cmdsn->cmdsn))
803*4882a593Smuzhiyun 					continue;
804*4882a593Smuzhiyun 
805*4882a593Smuzhiyun 				/* Insert before this entry */
806*4882a593Smuzhiyun 				list_add(&ooo_cmdsn->ooo_list,
807*4882a593Smuzhiyun 					ooo_tmp->ooo_list.prev);
808*4882a593Smuzhiyun 				break;
809*4882a593Smuzhiyun 			}
810*4882a593Smuzhiyun 		}
811*4882a593Smuzhiyun 	}
812*4882a593Smuzhiyun 
813*4882a593Smuzhiyun 	return 0;
814*4882a593Smuzhiyun }
815*4882a593Smuzhiyun 
816*4882a593Smuzhiyun /*
817*4882a593Smuzhiyun  *	Removes an struct iscsi_ooo_cmdsn from a session's list,
818*4882a593Smuzhiyun  *	called with struct iscsi_session->cmdsn_mutex held.
819*4882a593Smuzhiyun  */
iscsit_remove_ooo_cmdsn(struct iscsi_session * sess,struct iscsi_ooo_cmdsn * ooo_cmdsn)820*4882a593Smuzhiyun void iscsit_remove_ooo_cmdsn(
821*4882a593Smuzhiyun 	struct iscsi_session *sess,
822*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn)
823*4882a593Smuzhiyun {
824*4882a593Smuzhiyun 	list_del(&ooo_cmdsn->ooo_list);
825*4882a593Smuzhiyun 	kmem_cache_free(lio_ooo_cache, ooo_cmdsn);
826*4882a593Smuzhiyun }
827*4882a593Smuzhiyun 
iscsit_clear_ooo_cmdsns_for_conn(struct iscsi_conn * conn)828*4882a593Smuzhiyun void iscsit_clear_ooo_cmdsns_for_conn(struct iscsi_conn *conn)
829*4882a593Smuzhiyun {
830*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn;
831*4882a593Smuzhiyun 	struct iscsi_session *sess = conn->sess;
832*4882a593Smuzhiyun 
833*4882a593Smuzhiyun 	mutex_lock(&sess->cmdsn_mutex);
834*4882a593Smuzhiyun 	list_for_each_entry(ooo_cmdsn, &sess->sess_ooo_cmdsn_list, ooo_list) {
835*4882a593Smuzhiyun 		if (ooo_cmdsn->cid != conn->cid)
836*4882a593Smuzhiyun 			continue;
837*4882a593Smuzhiyun 
838*4882a593Smuzhiyun 		ooo_cmdsn->cmd = NULL;
839*4882a593Smuzhiyun 	}
840*4882a593Smuzhiyun 	mutex_unlock(&sess->cmdsn_mutex);
841*4882a593Smuzhiyun }
842*4882a593Smuzhiyun 
iscsit_execute_ooo_cmdsns(struct iscsi_session * sess)843*4882a593Smuzhiyun int iscsit_execute_ooo_cmdsns(struct iscsi_session *sess)
844*4882a593Smuzhiyun {
845*4882a593Smuzhiyun 	int ooo_count = 0;
846*4882a593Smuzhiyun 	struct iscsi_cmd *cmd = NULL;
847*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn, *ooo_cmdsn_tmp;
848*4882a593Smuzhiyun 
849*4882a593Smuzhiyun 	lockdep_assert_held(&sess->cmdsn_mutex);
850*4882a593Smuzhiyun 
851*4882a593Smuzhiyun 	list_for_each_entry_safe(ooo_cmdsn, ooo_cmdsn_tmp,
852*4882a593Smuzhiyun 				&sess->sess_ooo_cmdsn_list, ooo_list) {
853*4882a593Smuzhiyun 		if (ooo_cmdsn->cmdsn != sess->exp_cmd_sn)
854*4882a593Smuzhiyun 			continue;
855*4882a593Smuzhiyun 
856*4882a593Smuzhiyun 		if (!ooo_cmdsn->cmd) {
857*4882a593Smuzhiyun 			sess->exp_cmd_sn++;
858*4882a593Smuzhiyun 			iscsit_remove_ooo_cmdsn(sess, ooo_cmdsn);
859*4882a593Smuzhiyun 			continue;
860*4882a593Smuzhiyun 		}
861*4882a593Smuzhiyun 
862*4882a593Smuzhiyun 		cmd = ooo_cmdsn->cmd;
863*4882a593Smuzhiyun 		cmd->i_state = cmd->deferred_i_state;
864*4882a593Smuzhiyun 		ooo_count++;
865*4882a593Smuzhiyun 		sess->exp_cmd_sn++;
866*4882a593Smuzhiyun 		pr_debug("Executing out of order CmdSN: 0x%08x,"
867*4882a593Smuzhiyun 			" incremented ExpCmdSN to 0x%08x.\n",
868*4882a593Smuzhiyun 			cmd->cmd_sn, sess->exp_cmd_sn);
869*4882a593Smuzhiyun 
870*4882a593Smuzhiyun 		iscsit_remove_ooo_cmdsn(sess, ooo_cmdsn);
871*4882a593Smuzhiyun 
872*4882a593Smuzhiyun 		if (iscsit_execute_cmd(cmd, 1) < 0)
873*4882a593Smuzhiyun 			return -1;
874*4882a593Smuzhiyun 
875*4882a593Smuzhiyun 		continue;
876*4882a593Smuzhiyun 	}
877*4882a593Smuzhiyun 
878*4882a593Smuzhiyun 	return ooo_count;
879*4882a593Smuzhiyun }
880*4882a593Smuzhiyun 
881*4882a593Smuzhiyun /*
882*4882a593Smuzhiyun  *	Called either:
883*4882a593Smuzhiyun  *
884*4882a593Smuzhiyun  *	1. With sess->cmdsn_mutex held from iscsi_execute_ooo_cmdsns()
885*4882a593Smuzhiyun  *	or iscsi_check_received_cmdsn().
886*4882a593Smuzhiyun  *	2. With no locks held directly from iscsi_handle_XXX_pdu() functions
887*4882a593Smuzhiyun  *	for immediate commands.
888*4882a593Smuzhiyun  */
iscsit_execute_cmd(struct iscsi_cmd * cmd,int ooo)889*4882a593Smuzhiyun int iscsit_execute_cmd(struct iscsi_cmd *cmd, int ooo)
890*4882a593Smuzhiyun {
891*4882a593Smuzhiyun 	struct se_cmd *se_cmd = &cmd->se_cmd;
892*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
893*4882a593Smuzhiyun 	int lr = 0;
894*4882a593Smuzhiyun 
895*4882a593Smuzhiyun 	spin_lock_bh(&cmd->istate_lock);
896*4882a593Smuzhiyun 	if (ooo)
897*4882a593Smuzhiyun 		cmd->cmd_flags &= ~ICF_OOO_CMDSN;
898*4882a593Smuzhiyun 
899*4882a593Smuzhiyun 	switch (cmd->iscsi_opcode) {
900*4882a593Smuzhiyun 	case ISCSI_OP_SCSI_CMD:
901*4882a593Smuzhiyun 		/*
902*4882a593Smuzhiyun 		 * Go ahead and send the CHECK_CONDITION status for
903*4882a593Smuzhiyun 		 * any SCSI CDB exceptions that may have occurred.
904*4882a593Smuzhiyun 		 */
905*4882a593Smuzhiyun 		if (cmd->sense_reason) {
906*4882a593Smuzhiyun 			if (cmd->sense_reason == TCM_RESERVATION_CONFLICT) {
907*4882a593Smuzhiyun 				cmd->i_state = ISTATE_SEND_STATUS;
908*4882a593Smuzhiyun 				spin_unlock_bh(&cmd->istate_lock);
909*4882a593Smuzhiyun 				iscsit_add_cmd_to_response_queue(cmd, cmd->conn,
910*4882a593Smuzhiyun 						cmd->i_state);
911*4882a593Smuzhiyun 				return 0;
912*4882a593Smuzhiyun 			}
913*4882a593Smuzhiyun 			spin_unlock_bh(&cmd->istate_lock);
914*4882a593Smuzhiyun 			if (cmd->se_cmd.transport_state & CMD_T_ABORTED)
915*4882a593Smuzhiyun 				return 0;
916*4882a593Smuzhiyun 			return transport_send_check_condition_and_sense(se_cmd,
917*4882a593Smuzhiyun 					cmd->sense_reason, 0);
918*4882a593Smuzhiyun 		}
919*4882a593Smuzhiyun 		/*
920*4882a593Smuzhiyun 		 * Special case for delayed CmdSN with Immediate
921*4882a593Smuzhiyun 		 * Data and/or Unsolicited Data Out attached.
922*4882a593Smuzhiyun 		 */
923*4882a593Smuzhiyun 		if (cmd->immediate_data) {
924*4882a593Smuzhiyun 			if (cmd->cmd_flags & ICF_GOT_LAST_DATAOUT) {
925*4882a593Smuzhiyun 				spin_unlock_bh(&cmd->istate_lock);
926*4882a593Smuzhiyun 				target_execute_cmd(&cmd->se_cmd);
927*4882a593Smuzhiyun 				return 0;
928*4882a593Smuzhiyun 			}
929*4882a593Smuzhiyun 			spin_unlock_bh(&cmd->istate_lock);
930*4882a593Smuzhiyun 
931*4882a593Smuzhiyun 			if (!(cmd->cmd_flags &
932*4882a593Smuzhiyun 					ICF_NON_IMMEDIATE_UNSOLICITED_DATA)) {
933*4882a593Smuzhiyun 				if (cmd->se_cmd.transport_state & CMD_T_ABORTED)
934*4882a593Smuzhiyun 					return 0;
935*4882a593Smuzhiyun 
936*4882a593Smuzhiyun 				iscsit_set_dataout_sequence_values(cmd);
937*4882a593Smuzhiyun 				conn->conn_transport->iscsit_get_dataout(conn, cmd, false);
938*4882a593Smuzhiyun 			}
939*4882a593Smuzhiyun 			return 0;
940*4882a593Smuzhiyun 		}
941*4882a593Smuzhiyun 		/*
942*4882a593Smuzhiyun 		 * The default handler.
943*4882a593Smuzhiyun 		 */
944*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
945*4882a593Smuzhiyun 
946*4882a593Smuzhiyun 		if ((cmd->data_direction == DMA_TO_DEVICE) &&
947*4882a593Smuzhiyun 		    !(cmd->cmd_flags & ICF_NON_IMMEDIATE_UNSOLICITED_DATA)) {
948*4882a593Smuzhiyun 			if (cmd->se_cmd.transport_state & CMD_T_ABORTED)
949*4882a593Smuzhiyun 				return 0;
950*4882a593Smuzhiyun 
951*4882a593Smuzhiyun 			iscsit_set_unsolicited_dataout(cmd);
952*4882a593Smuzhiyun 		}
953*4882a593Smuzhiyun 		return transport_handle_cdb_direct(&cmd->se_cmd);
954*4882a593Smuzhiyun 
955*4882a593Smuzhiyun 	case ISCSI_OP_NOOP_OUT:
956*4882a593Smuzhiyun 	case ISCSI_OP_TEXT:
957*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
958*4882a593Smuzhiyun 		iscsit_add_cmd_to_response_queue(cmd, cmd->conn, cmd->i_state);
959*4882a593Smuzhiyun 		break;
960*4882a593Smuzhiyun 	case ISCSI_OP_SCSI_TMFUNC:
961*4882a593Smuzhiyun 		if (cmd->se_cmd.se_tmr_req->response) {
962*4882a593Smuzhiyun 			spin_unlock_bh(&cmd->istate_lock);
963*4882a593Smuzhiyun 			iscsit_add_cmd_to_response_queue(cmd, cmd->conn,
964*4882a593Smuzhiyun 					cmd->i_state);
965*4882a593Smuzhiyun 			return 0;
966*4882a593Smuzhiyun 		}
967*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
968*4882a593Smuzhiyun 
969*4882a593Smuzhiyun 		return transport_generic_handle_tmr(&cmd->se_cmd);
970*4882a593Smuzhiyun 	case ISCSI_OP_LOGOUT:
971*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
972*4882a593Smuzhiyun 		switch (cmd->logout_reason) {
973*4882a593Smuzhiyun 		case ISCSI_LOGOUT_REASON_CLOSE_SESSION:
974*4882a593Smuzhiyun 			lr = iscsit_logout_closesession(cmd, cmd->conn);
975*4882a593Smuzhiyun 			break;
976*4882a593Smuzhiyun 		case ISCSI_LOGOUT_REASON_CLOSE_CONNECTION:
977*4882a593Smuzhiyun 			lr = iscsit_logout_closeconnection(cmd, cmd->conn);
978*4882a593Smuzhiyun 			break;
979*4882a593Smuzhiyun 		case ISCSI_LOGOUT_REASON_RECOVERY:
980*4882a593Smuzhiyun 			lr = iscsit_logout_removeconnforrecovery(cmd, cmd->conn);
981*4882a593Smuzhiyun 			break;
982*4882a593Smuzhiyun 		default:
983*4882a593Smuzhiyun 			pr_err("Unknown iSCSI Logout Request Code:"
984*4882a593Smuzhiyun 				" 0x%02x\n", cmd->logout_reason);
985*4882a593Smuzhiyun 			return -1;
986*4882a593Smuzhiyun 		}
987*4882a593Smuzhiyun 
988*4882a593Smuzhiyun 		return lr;
989*4882a593Smuzhiyun 	default:
990*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->istate_lock);
991*4882a593Smuzhiyun 		pr_err("Cannot perform out of order execution for"
992*4882a593Smuzhiyun 		" unknown iSCSI Opcode: 0x%02x\n", cmd->iscsi_opcode);
993*4882a593Smuzhiyun 		return -1;
994*4882a593Smuzhiyun 	}
995*4882a593Smuzhiyun 
996*4882a593Smuzhiyun 	return 0;
997*4882a593Smuzhiyun }
998*4882a593Smuzhiyun 
iscsit_free_all_ooo_cmdsns(struct iscsi_session * sess)999*4882a593Smuzhiyun void iscsit_free_all_ooo_cmdsns(struct iscsi_session *sess)
1000*4882a593Smuzhiyun {
1001*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn, *ooo_cmdsn_tmp;
1002*4882a593Smuzhiyun 
1003*4882a593Smuzhiyun 	mutex_lock(&sess->cmdsn_mutex);
1004*4882a593Smuzhiyun 	list_for_each_entry_safe(ooo_cmdsn, ooo_cmdsn_tmp,
1005*4882a593Smuzhiyun 			&sess->sess_ooo_cmdsn_list, ooo_list) {
1006*4882a593Smuzhiyun 
1007*4882a593Smuzhiyun 		list_del(&ooo_cmdsn->ooo_list);
1008*4882a593Smuzhiyun 		kmem_cache_free(lio_ooo_cache, ooo_cmdsn);
1009*4882a593Smuzhiyun 	}
1010*4882a593Smuzhiyun 	mutex_unlock(&sess->cmdsn_mutex);
1011*4882a593Smuzhiyun }
1012*4882a593Smuzhiyun 
iscsit_handle_ooo_cmdsn(struct iscsi_session * sess,struct iscsi_cmd * cmd,u32 cmdsn)1013*4882a593Smuzhiyun int iscsit_handle_ooo_cmdsn(
1014*4882a593Smuzhiyun 	struct iscsi_session *sess,
1015*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
1016*4882a593Smuzhiyun 	u32 cmdsn)
1017*4882a593Smuzhiyun {
1018*4882a593Smuzhiyun 	int batch = 0;
1019*4882a593Smuzhiyun 	struct iscsi_ooo_cmdsn *ooo_cmdsn = NULL, *ooo_tail = NULL;
1020*4882a593Smuzhiyun 
1021*4882a593Smuzhiyun 	cmd->deferred_i_state		= cmd->i_state;
1022*4882a593Smuzhiyun 	cmd->i_state			= ISTATE_DEFERRED_CMD;
1023*4882a593Smuzhiyun 	cmd->cmd_flags			|= ICF_OOO_CMDSN;
1024*4882a593Smuzhiyun 
1025*4882a593Smuzhiyun 	if (list_empty(&sess->sess_ooo_cmdsn_list))
1026*4882a593Smuzhiyun 		batch = 1;
1027*4882a593Smuzhiyun 	else {
1028*4882a593Smuzhiyun 		ooo_tail = list_entry(sess->sess_ooo_cmdsn_list.prev,
1029*4882a593Smuzhiyun 				typeof(*ooo_tail), ooo_list);
1030*4882a593Smuzhiyun 		if (ooo_tail->cmdsn != (cmdsn - 1))
1031*4882a593Smuzhiyun 			batch = 1;
1032*4882a593Smuzhiyun 	}
1033*4882a593Smuzhiyun 
1034*4882a593Smuzhiyun 	ooo_cmdsn = iscsit_allocate_ooo_cmdsn();
1035*4882a593Smuzhiyun 	if (!ooo_cmdsn)
1036*4882a593Smuzhiyun 		return -ENOMEM;
1037*4882a593Smuzhiyun 
1038*4882a593Smuzhiyun 	ooo_cmdsn->cmd			= cmd;
1039*4882a593Smuzhiyun 	ooo_cmdsn->batch_count		= (batch) ?
1040*4882a593Smuzhiyun 					  (cmdsn - sess->exp_cmd_sn) : 1;
1041*4882a593Smuzhiyun 	ooo_cmdsn->cid			= cmd->conn->cid;
1042*4882a593Smuzhiyun 	ooo_cmdsn->exp_cmdsn		= sess->exp_cmd_sn;
1043*4882a593Smuzhiyun 	ooo_cmdsn->cmdsn		= cmdsn;
1044*4882a593Smuzhiyun 
1045*4882a593Smuzhiyun 	if (iscsit_attach_ooo_cmdsn(sess, ooo_cmdsn) < 0) {
1046*4882a593Smuzhiyun 		kmem_cache_free(lio_ooo_cache, ooo_cmdsn);
1047*4882a593Smuzhiyun 		return -ENOMEM;
1048*4882a593Smuzhiyun 	}
1049*4882a593Smuzhiyun 
1050*4882a593Smuzhiyun 	return 0;
1051*4882a593Smuzhiyun }
1052*4882a593Smuzhiyun 
iscsit_set_dataout_timeout_values(struct iscsi_cmd * cmd,u32 * offset,u32 * length)1053*4882a593Smuzhiyun static int iscsit_set_dataout_timeout_values(
1054*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
1055*4882a593Smuzhiyun 	u32 *offset,
1056*4882a593Smuzhiyun 	u32 *length)
1057*4882a593Smuzhiyun {
1058*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
1059*4882a593Smuzhiyun 	struct iscsi_r2t *r2t;
1060*4882a593Smuzhiyun 
1061*4882a593Smuzhiyun 	if (cmd->unsolicited_data) {
1062*4882a593Smuzhiyun 		*offset = 0;
1063*4882a593Smuzhiyun 		*length = (conn->sess->sess_ops->FirstBurstLength >
1064*4882a593Smuzhiyun 			   cmd->se_cmd.data_length) ?
1065*4882a593Smuzhiyun 			   cmd->se_cmd.data_length :
1066*4882a593Smuzhiyun 			   conn->sess->sess_ops->FirstBurstLength;
1067*4882a593Smuzhiyun 		return 0;
1068*4882a593Smuzhiyun 	}
1069*4882a593Smuzhiyun 
1070*4882a593Smuzhiyun 	spin_lock_bh(&cmd->r2t_lock);
1071*4882a593Smuzhiyun 	if (list_empty(&cmd->cmd_r2t_list)) {
1072*4882a593Smuzhiyun 		pr_err("cmd->cmd_r2t_list is empty!\n");
1073*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->r2t_lock);
1074*4882a593Smuzhiyun 		return -1;
1075*4882a593Smuzhiyun 	}
1076*4882a593Smuzhiyun 
1077*4882a593Smuzhiyun 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
1078*4882a593Smuzhiyun 		if (r2t->sent_r2t && !r2t->recovery_r2t && !r2t->seq_complete) {
1079*4882a593Smuzhiyun 			*offset = r2t->offset;
1080*4882a593Smuzhiyun 			*length = r2t->xfer_len;
1081*4882a593Smuzhiyun 			spin_unlock_bh(&cmd->r2t_lock);
1082*4882a593Smuzhiyun 			return 0;
1083*4882a593Smuzhiyun 		}
1084*4882a593Smuzhiyun 	}
1085*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->r2t_lock);
1086*4882a593Smuzhiyun 
1087*4882a593Smuzhiyun 	pr_err("Unable to locate any incomplete DataOUT"
1088*4882a593Smuzhiyun 		" sequences for ITT: 0x%08x.\n", cmd->init_task_tag);
1089*4882a593Smuzhiyun 
1090*4882a593Smuzhiyun 	return -1;
1091*4882a593Smuzhiyun }
1092*4882a593Smuzhiyun 
1093*4882a593Smuzhiyun /*
1094*4882a593Smuzhiyun  *	NOTE: Called from interrupt (timer) context.
1095*4882a593Smuzhiyun  */
iscsit_handle_dataout_timeout(struct timer_list * t)1096*4882a593Smuzhiyun void iscsit_handle_dataout_timeout(struct timer_list *t)
1097*4882a593Smuzhiyun {
1098*4882a593Smuzhiyun 	u32 pdu_length = 0, pdu_offset = 0;
1099*4882a593Smuzhiyun 	u32 r2t_length = 0, r2t_offset = 0;
1100*4882a593Smuzhiyun 	struct iscsi_cmd *cmd = from_timer(cmd, t, dataout_timer);
1101*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
1102*4882a593Smuzhiyun 	struct iscsi_session *sess = NULL;
1103*4882a593Smuzhiyun 	struct iscsi_node_attrib *na;
1104*4882a593Smuzhiyun 
1105*4882a593Smuzhiyun 	iscsit_inc_conn_usage_count(conn);
1106*4882a593Smuzhiyun 
1107*4882a593Smuzhiyun 	spin_lock_bh(&cmd->dataout_timeout_lock);
1108*4882a593Smuzhiyun 	if (cmd->dataout_timer_flags & ISCSI_TF_STOP) {
1109*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->dataout_timeout_lock);
1110*4882a593Smuzhiyun 		iscsit_dec_conn_usage_count(conn);
1111*4882a593Smuzhiyun 		return;
1112*4882a593Smuzhiyun 	}
1113*4882a593Smuzhiyun 	cmd->dataout_timer_flags &= ~ISCSI_TF_RUNNING;
1114*4882a593Smuzhiyun 	sess = conn->sess;
1115*4882a593Smuzhiyun 	na = iscsit_tpg_get_node_attrib(sess);
1116*4882a593Smuzhiyun 
1117*4882a593Smuzhiyun 	if (!sess->sess_ops->ErrorRecoveryLevel) {
1118*4882a593Smuzhiyun 		pr_err("Unable to recover from DataOut timeout while"
1119*4882a593Smuzhiyun 			" in ERL=0, closing iSCSI connection for I_T Nexus"
1120*4882a593Smuzhiyun 			" %s,i,0x%6phN,%s,t,0x%02x\n",
1121*4882a593Smuzhiyun 			sess->sess_ops->InitiatorName, sess->isid,
1122*4882a593Smuzhiyun 			sess->tpg->tpg_tiqn->tiqn, (u32)sess->tpg->tpgt);
1123*4882a593Smuzhiyun 		goto failure;
1124*4882a593Smuzhiyun 	}
1125*4882a593Smuzhiyun 
1126*4882a593Smuzhiyun 	if (++cmd->dataout_timeout_retries == na->dataout_timeout_retries) {
1127*4882a593Smuzhiyun 		pr_err("Command ITT: 0x%08x exceeded max retries"
1128*4882a593Smuzhiyun 			" for DataOUT timeout %u, closing iSCSI connection for"
1129*4882a593Smuzhiyun 			" I_T Nexus %s,i,0x%6phN,%s,t,0x%02x\n",
1130*4882a593Smuzhiyun 			cmd->init_task_tag, na->dataout_timeout_retries,
1131*4882a593Smuzhiyun 			sess->sess_ops->InitiatorName, sess->isid,
1132*4882a593Smuzhiyun 			sess->tpg->tpg_tiqn->tiqn, (u32)sess->tpg->tpgt);
1133*4882a593Smuzhiyun 		goto failure;
1134*4882a593Smuzhiyun 	}
1135*4882a593Smuzhiyun 
1136*4882a593Smuzhiyun 	cmd->cmd_flags |= ICF_WITHIN_COMMAND_RECOVERY;
1137*4882a593Smuzhiyun 
1138*4882a593Smuzhiyun 	if (conn->sess->sess_ops->DataSequenceInOrder) {
1139*4882a593Smuzhiyun 		if (conn->sess->sess_ops->DataPDUInOrder) {
1140*4882a593Smuzhiyun 			pdu_offset = cmd->write_data_done;
1141*4882a593Smuzhiyun 			if ((pdu_offset + (conn->sess->sess_ops->MaxBurstLength -
1142*4882a593Smuzhiyun 			     cmd->next_burst_len)) > cmd->se_cmd.data_length)
1143*4882a593Smuzhiyun 				pdu_length = (cmd->se_cmd.data_length -
1144*4882a593Smuzhiyun 					cmd->write_data_done);
1145*4882a593Smuzhiyun 			else
1146*4882a593Smuzhiyun 				pdu_length = (conn->sess->sess_ops->MaxBurstLength -
1147*4882a593Smuzhiyun 						cmd->next_burst_len);
1148*4882a593Smuzhiyun 		} else {
1149*4882a593Smuzhiyun 			pdu_offset = cmd->seq_start_offset;
1150*4882a593Smuzhiyun 			pdu_length = (cmd->seq_end_offset -
1151*4882a593Smuzhiyun 				cmd->seq_start_offset);
1152*4882a593Smuzhiyun 		}
1153*4882a593Smuzhiyun 	} else {
1154*4882a593Smuzhiyun 		if (iscsit_set_dataout_timeout_values(cmd, &pdu_offset,
1155*4882a593Smuzhiyun 				&pdu_length) < 0)
1156*4882a593Smuzhiyun 			goto failure;
1157*4882a593Smuzhiyun 	}
1158*4882a593Smuzhiyun 
1159*4882a593Smuzhiyun 	if (iscsit_recalculate_dataout_values(cmd, pdu_offset, pdu_length,
1160*4882a593Smuzhiyun 			&r2t_offset, &r2t_length) < 0)
1161*4882a593Smuzhiyun 		goto failure;
1162*4882a593Smuzhiyun 
1163*4882a593Smuzhiyun 	pr_debug("Command ITT: 0x%08x timed out waiting for"
1164*4882a593Smuzhiyun 		" completion of %sDataOUT Sequence Offset: %u, Length: %u\n",
1165*4882a593Smuzhiyun 		cmd->init_task_tag, (cmd->unsolicited_data) ? "Unsolicited " :
1166*4882a593Smuzhiyun 		"", r2t_offset, r2t_length);
1167*4882a593Smuzhiyun 
1168*4882a593Smuzhiyun 	if (iscsit_send_recovery_r2t(cmd, r2t_offset, r2t_length) < 0)
1169*4882a593Smuzhiyun 		goto failure;
1170*4882a593Smuzhiyun 
1171*4882a593Smuzhiyun 	iscsit_start_dataout_timer(cmd, conn);
1172*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->dataout_timeout_lock);
1173*4882a593Smuzhiyun 	iscsit_dec_conn_usage_count(conn);
1174*4882a593Smuzhiyun 
1175*4882a593Smuzhiyun 	return;
1176*4882a593Smuzhiyun 
1177*4882a593Smuzhiyun failure:
1178*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->dataout_timeout_lock);
1179*4882a593Smuzhiyun 	iscsit_fill_cxn_timeout_err_stats(sess);
1180*4882a593Smuzhiyun 	iscsit_cause_connection_reinstatement(conn, 0);
1181*4882a593Smuzhiyun 	iscsit_dec_conn_usage_count(conn);
1182*4882a593Smuzhiyun }
1183*4882a593Smuzhiyun 
iscsit_mod_dataout_timer(struct iscsi_cmd * cmd)1184*4882a593Smuzhiyun void iscsit_mod_dataout_timer(struct iscsi_cmd *cmd)
1185*4882a593Smuzhiyun {
1186*4882a593Smuzhiyun 	struct iscsi_conn *conn = cmd->conn;
1187*4882a593Smuzhiyun 	struct iscsi_session *sess = conn->sess;
1188*4882a593Smuzhiyun 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1189*4882a593Smuzhiyun 
1190*4882a593Smuzhiyun 	spin_lock_bh(&cmd->dataout_timeout_lock);
1191*4882a593Smuzhiyun 	if (!(cmd->dataout_timer_flags & ISCSI_TF_RUNNING)) {
1192*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->dataout_timeout_lock);
1193*4882a593Smuzhiyun 		return;
1194*4882a593Smuzhiyun 	}
1195*4882a593Smuzhiyun 
1196*4882a593Smuzhiyun 	mod_timer(&cmd->dataout_timer,
1197*4882a593Smuzhiyun 		(get_jiffies_64() + na->dataout_timeout * HZ));
1198*4882a593Smuzhiyun 	pr_debug("Updated DataOUT timer for ITT: 0x%08x",
1199*4882a593Smuzhiyun 			cmd->init_task_tag);
1200*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->dataout_timeout_lock);
1201*4882a593Smuzhiyun }
1202*4882a593Smuzhiyun 
iscsit_start_dataout_timer(struct iscsi_cmd * cmd,struct iscsi_conn * conn)1203*4882a593Smuzhiyun void iscsit_start_dataout_timer(
1204*4882a593Smuzhiyun 	struct iscsi_cmd *cmd,
1205*4882a593Smuzhiyun 	struct iscsi_conn *conn)
1206*4882a593Smuzhiyun {
1207*4882a593Smuzhiyun 	struct iscsi_session *sess = conn->sess;
1208*4882a593Smuzhiyun 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1209*4882a593Smuzhiyun 
1210*4882a593Smuzhiyun 	lockdep_assert_held(&cmd->dataout_timeout_lock);
1211*4882a593Smuzhiyun 
1212*4882a593Smuzhiyun 	if (cmd->dataout_timer_flags & ISCSI_TF_RUNNING)
1213*4882a593Smuzhiyun 		return;
1214*4882a593Smuzhiyun 
1215*4882a593Smuzhiyun 	pr_debug("Starting DataOUT timer for ITT: 0x%08x on"
1216*4882a593Smuzhiyun 		" CID: %hu.\n", cmd->init_task_tag, conn->cid);
1217*4882a593Smuzhiyun 
1218*4882a593Smuzhiyun 	cmd->dataout_timer_flags &= ~ISCSI_TF_STOP;
1219*4882a593Smuzhiyun 	cmd->dataout_timer_flags |= ISCSI_TF_RUNNING;
1220*4882a593Smuzhiyun 	mod_timer(&cmd->dataout_timer, jiffies + na->dataout_timeout * HZ);
1221*4882a593Smuzhiyun }
1222*4882a593Smuzhiyun 
iscsit_stop_dataout_timer(struct iscsi_cmd * cmd)1223*4882a593Smuzhiyun void iscsit_stop_dataout_timer(struct iscsi_cmd *cmd)
1224*4882a593Smuzhiyun {
1225*4882a593Smuzhiyun 	spin_lock_bh(&cmd->dataout_timeout_lock);
1226*4882a593Smuzhiyun 	if (!(cmd->dataout_timer_flags & ISCSI_TF_RUNNING)) {
1227*4882a593Smuzhiyun 		spin_unlock_bh(&cmd->dataout_timeout_lock);
1228*4882a593Smuzhiyun 		return;
1229*4882a593Smuzhiyun 	}
1230*4882a593Smuzhiyun 	cmd->dataout_timer_flags |= ISCSI_TF_STOP;
1231*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->dataout_timeout_lock);
1232*4882a593Smuzhiyun 
1233*4882a593Smuzhiyun 	del_timer_sync(&cmd->dataout_timer);
1234*4882a593Smuzhiyun 
1235*4882a593Smuzhiyun 	spin_lock_bh(&cmd->dataout_timeout_lock);
1236*4882a593Smuzhiyun 	cmd->dataout_timer_flags &= ~ISCSI_TF_RUNNING;
1237*4882a593Smuzhiyun 	pr_debug("Stopped DataOUT Timer for ITT: 0x%08x\n",
1238*4882a593Smuzhiyun 			cmd->init_task_tag);
1239*4882a593Smuzhiyun 	spin_unlock_bh(&cmd->dataout_timeout_lock);
1240*4882a593Smuzhiyun }
1241*4882a593Smuzhiyun EXPORT_SYMBOL(iscsit_stop_dataout_timer);
1242