1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*******************************************************************************
3*4882a593Smuzhiyun * This file contains main functions related to iSCSI Parameter negotiation.
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * (c) Copyright 2007-2013 Datera, Inc.
6*4882a593Smuzhiyun *
7*4882a593Smuzhiyun * Author: Nicholas A. Bellinger <nab@linux-iscsi.org>
8*4882a593Smuzhiyun *
9*4882a593Smuzhiyun ******************************************************************************/
10*4882a593Smuzhiyun
11*4882a593Smuzhiyun #include <linux/ctype.h>
12*4882a593Smuzhiyun #include <linux/kthread.h>
13*4882a593Smuzhiyun #include <linux/slab.h>
14*4882a593Smuzhiyun #include <linux/sched/signal.h>
15*4882a593Smuzhiyun #include <net/sock.h>
16*4882a593Smuzhiyun #include <scsi/iscsi_proto.h>
17*4882a593Smuzhiyun #include <target/target_core_base.h>
18*4882a593Smuzhiyun #include <target/target_core_fabric.h>
19*4882a593Smuzhiyun #include <target/iscsi/iscsi_transport.h>
20*4882a593Smuzhiyun
21*4882a593Smuzhiyun #include <target/iscsi/iscsi_target_core.h>
22*4882a593Smuzhiyun #include "iscsi_target_parameters.h"
23*4882a593Smuzhiyun #include "iscsi_target_login.h"
24*4882a593Smuzhiyun #include "iscsi_target_nego.h"
25*4882a593Smuzhiyun #include "iscsi_target_tpg.h"
26*4882a593Smuzhiyun #include "iscsi_target_util.h"
27*4882a593Smuzhiyun #include "iscsi_target.h"
28*4882a593Smuzhiyun #include "iscsi_target_auth.h"
29*4882a593Smuzhiyun
30*4882a593Smuzhiyun #define MAX_LOGIN_PDUS 7
31*4882a593Smuzhiyun #define TEXT_LEN 4096
32*4882a593Smuzhiyun
convert_null_to_semi(char * buf,int len)33*4882a593Smuzhiyun void convert_null_to_semi(char *buf, int len)
34*4882a593Smuzhiyun {
35*4882a593Smuzhiyun int i;
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun for (i = 0; i < len; i++)
38*4882a593Smuzhiyun if (buf[i] == '\0')
39*4882a593Smuzhiyun buf[i] = ';';
40*4882a593Smuzhiyun }
41*4882a593Smuzhiyun
strlen_semi(char * buf)42*4882a593Smuzhiyun static int strlen_semi(char *buf)
43*4882a593Smuzhiyun {
44*4882a593Smuzhiyun int i = 0;
45*4882a593Smuzhiyun
46*4882a593Smuzhiyun while (buf[i] != '\0') {
47*4882a593Smuzhiyun if (buf[i] == ';')
48*4882a593Smuzhiyun return i;
49*4882a593Smuzhiyun i++;
50*4882a593Smuzhiyun }
51*4882a593Smuzhiyun
52*4882a593Smuzhiyun return -1;
53*4882a593Smuzhiyun }
54*4882a593Smuzhiyun
extract_param(const char * in_buf,const char * pattern,unsigned int max_length,char * out_buf,unsigned char * type)55*4882a593Smuzhiyun int extract_param(
56*4882a593Smuzhiyun const char *in_buf,
57*4882a593Smuzhiyun const char *pattern,
58*4882a593Smuzhiyun unsigned int max_length,
59*4882a593Smuzhiyun char *out_buf,
60*4882a593Smuzhiyun unsigned char *type)
61*4882a593Smuzhiyun {
62*4882a593Smuzhiyun char *ptr;
63*4882a593Smuzhiyun int len;
64*4882a593Smuzhiyun
65*4882a593Smuzhiyun if (!in_buf || !pattern || !out_buf || !type)
66*4882a593Smuzhiyun return -1;
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun ptr = strstr(in_buf, pattern);
69*4882a593Smuzhiyun if (!ptr)
70*4882a593Smuzhiyun return -1;
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun ptr = strstr(ptr, "=");
73*4882a593Smuzhiyun if (!ptr)
74*4882a593Smuzhiyun return -1;
75*4882a593Smuzhiyun
76*4882a593Smuzhiyun ptr += 1;
77*4882a593Smuzhiyun if (*ptr == '0' && (*(ptr+1) == 'x' || *(ptr+1) == 'X')) {
78*4882a593Smuzhiyun ptr += 2; /* skip 0x */
79*4882a593Smuzhiyun *type = HEX;
80*4882a593Smuzhiyun } else
81*4882a593Smuzhiyun *type = DECIMAL;
82*4882a593Smuzhiyun
83*4882a593Smuzhiyun len = strlen_semi(ptr);
84*4882a593Smuzhiyun if (len < 0)
85*4882a593Smuzhiyun return -1;
86*4882a593Smuzhiyun
87*4882a593Smuzhiyun if (len >= max_length) {
88*4882a593Smuzhiyun pr_err("Length of input: %d exceeds max_length:"
89*4882a593Smuzhiyun " %d\n", len, max_length);
90*4882a593Smuzhiyun return -1;
91*4882a593Smuzhiyun }
92*4882a593Smuzhiyun memcpy(out_buf, ptr, len);
93*4882a593Smuzhiyun out_buf[len] = '\0';
94*4882a593Smuzhiyun
95*4882a593Smuzhiyun return 0;
96*4882a593Smuzhiyun }
97*4882a593Smuzhiyun
iscsi_handle_authentication(struct iscsi_conn * conn,char * in_buf,char * out_buf,int in_length,int * out_length,unsigned char * authtype)98*4882a593Smuzhiyun static u32 iscsi_handle_authentication(
99*4882a593Smuzhiyun struct iscsi_conn *conn,
100*4882a593Smuzhiyun char *in_buf,
101*4882a593Smuzhiyun char *out_buf,
102*4882a593Smuzhiyun int in_length,
103*4882a593Smuzhiyun int *out_length,
104*4882a593Smuzhiyun unsigned char *authtype)
105*4882a593Smuzhiyun {
106*4882a593Smuzhiyun struct iscsi_session *sess = conn->sess;
107*4882a593Smuzhiyun struct iscsi_node_auth *auth;
108*4882a593Smuzhiyun struct iscsi_node_acl *iscsi_nacl;
109*4882a593Smuzhiyun struct iscsi_portal_group *iscsi_tpg;
110*4882a593Smuzhiyun struct se_node_acl *se_nacl;
111*4882a593Smuzhiyun
112*4882a593Smuzhiyun if (!sess->sess_ops->SessionType) {
113*4882a593Smuzhiyun /*
114*4882a593Smuzhiyun * For SessionType=Normal
115*4882a593Smuzhiyun */
116*4882a593Smuzhiyun se_nacl = conn->sess->se_sess->se_node_acl;
117*4882a593Smuzhiyun if (!se_nacl) {
118*4882a593Smuzhiyun pr_err("Unable to locate struct se_node_acl for"
119*4882a593Smuzhiyun " CHAP auth\n");
120*4882a593Smuzhiyun return -1;
121*4882a593Smuzhiyun }
122*4882a593Smuzhiyun iscsi_nacl = container_of(se_nacl, struct iscsi_node_acl,
123*4882a593Smuzhiyun se_node_acl);
124*4882a593Smuzhiyun if (!iscsi_nacl) {
125*4882a593Smuzhiyun pr_err("Unable to locate struct iscsi_node_acl for"
126*4882a593Smuzhiyun " CHAP auth\n");
127*4882a593Smuzhiyun return -1;
128*4882a593Smuzhiyun }
129*4882a593Smuzhiyun
130*4882a593Smuzhiyun if (se_nacl->dynamic_node_acl) {
131*4882a593Smuzhiyun iscsi_tpg = container_of(se_nacl->se_tpg,
132*4882a593Smuzhiyun struct iscsi_portal_group, tpg_se_tpg);
133*4882a593Smuzhiyun
134*4882a593Smuzhiyun auth = &iscsi_tpg->tpg_demo_auth;
135*4882a593Smuzhiyun } else {
136*4882a593Smuzhiyun iscsi_nacl = container_of(se_nacl, struct iscsi_node_acl,
137*4882a593Smuzhiyun se_node_acl);
138*4882a593Smuzhiyun
139*4882a593Smuzhiyun auth = &iscsi_nacl->node_auth;
140*4882a593Smuzhiyun }
141*4882a593Smuzhiyun } else {
142*4882a593Smuzhiyun /*
143*4882a593Smuzhiyun * For SessionType=Discovery
144*4882a593Smuzhiyun */
145*4882a593Smuzhiyun auth = &iscsit_global->discovery_acl.node_auth;
146*4882a593Smuzhiyun }
147*4882a593Smuzhiyun
148*4882a593Smuzhiyun if (strstr("CHAP", authtype))
149*4882a593Smuzhiyun strcpy(conn->sess->auth_type, "CHAP");
150*4882a593Smuzhiyun else
151*4882a593Smuzhiyun strcpy(conn->sess->auth_type, NONE);
152*4882a593Smuzhiyun
153*4882a593Smuzhiyun if (strstr("None", authtype))
154*4882a593Smuzhiyun return 1;
155*4882a593Smuzhiyun else if (strstr("CHAP", authtype))
156*4882a593Smuzhiyun return chap_main_loop(conn, auth, in_buf, out_buf,
157*4882a593Smuzhiyun &in_length, out_length);
158*4882a593Smuzhiyun /* SRP, SPKM1, SPKM2 and KRB5 are unsupported */
159*4882a593Smuzhiyun return 2;
160*4882a593Smuzhiyun }
161*4882a593Smuzhiyun
iscsi_remove_failed_auth_entry(struct iscsi_conn * conn)162*4882a593Smuzhiyun static void iscsi_remove_failed_auth_entry(struct iscsi_conn *conn)
163*4882a593Smuzhiyun {
164*4882a593Smuzhiyun kfree(conn->auth_protocol);
165*4882a593Smuzhiyun }
166*4882a593Smuzhiyun
iscsi_target_check_login_request(struct iscsi_conn * conn,struct iscsi_login * login)167*4882a593Smuzhiyun int iscsi_target_check_login_request(
168*4882a593Smuzhiyun struct iscsi_conn *conn,
169*4882a593Smuzhiyun struct iscsi_login *login)
170*4882a593Smuzhiyun {
171*4882a593Smuzhiyun int req_csg, req_nsg;
172*4882a593Smuzhiyun u32 payload_length;
173*4882a593Smuzhiyun struct iscsi_login_req *login_req;
174*4882a593Smuzhiyun
175*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
176*4882a593Smuzhiyun payload_length = ntoh24(login_req->dlength);
177*4882a593Smuzhiyun
178*4882a593Smuzhiyun switch (login_req->opcode & ISCSI_OPCODE_MASK) {
179*4882a593Smuzhiyun case ISCSI_OP_LOGIN:
180*4882a593Smuzhiyun break;
181*4882a593Smuzhiyun default:
182*4882a593Smuzhiyun pr_err("Received unknown opcode 0x%02x.\n",
183*4882a593Smuzhiyun login_req->opcode & ISCSI_OPCODE_MASK);
184*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
185*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
186*4882a593Smuzhiyun return -1;
187*4882a593Smuzhiyun }
188*4882a593Smuzhiyun
189*4882a593Smuzhiyun if ((login_req->flags & ISCSI_FLAG_LOGIN_CONTINUE) &&
190*4882a593Smuzhiyun (login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT)) {
191*4882a593Smuzhiyun pr_err("Login request has both ISCSI_FLAG_LOGIN_CONTINUE"
192*4882a593Smuzhiyun " and ISCSI_FLAG_LOGIN_TRANSIT set, protocol error.\n");
193*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
194*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
195*4882a593Smuzhiyun return -1;
196*4882a593Smuzhiyun }
197*4882a593Smuzhiyun
198*4882a593Smuzhiyun req_csg = ISCSI_LOGIN_CURRENT_STAGE(login_req->flags);
199*4882a593Smuzhiyun req_nsg = ISCSI_LOGIN_NEXT_STAGE(login_req->flags);
200*4882a593Smuzhiyun
201*4882a593Smuzhiyun if (req_csg != login->current_stage) {
202*4882a593Smuzhiyun pr_err("Initiator unexpectedly changed login stage"
203*4882a593Smuzhiyun " from %d to %d, login failed.\n", login->current_stage,
204*4882a593Smuzhiyun req_csg);
205*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
206*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
207*4882a593Smuzhiyun return -1;
208*4882a593Smuzhiyun }
209*4882a593Smuzhiyun
210*4882a593Smuzhiyun if ((req_nsg == 2) || (req_csg >= 2) ||
211*4882a593Smuzhiyun ((login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT) &&
212*4882a593Smuzhiyun (req_nsg <= req_csg))) {
213*4882a593Smuzhiyun pr_err("Illegal login_req->flags Combination, CSG: %d,"
214*4882a593Smuzhiyun " NSG: %d, ISCSI_FLAG_LOGIN_TRANSIT: %d.\n", req_csg,
215*4882a593Smuzhiyun req_nsg, (login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT));
216*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
217*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
218*4882a593Smuzhiyun return -1;
219*4882a593Smuzhiyun }
220*4882a593Smuzhiyun
221*4882a593Smuzhiyun if ((login_req->max_version != login->version_max) ||
222*4882a593Smuzhiyun (login_req->min_version != login->version_min)) {
223*4882a593Smuzhiyun pr_err("Login request changed Version Max/Nin"
224*4882a593Smuzhiyun " unexpectedly to 0x%02x/0x%02x, protocol error\n",
225*4882a593Smuzhiyun login_req->max_version, login_req->min_version);
226*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
227*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
228*4882a593Smuzhiyun return -1;
229*4882a593Smuzhiyun }
230*4882a593Smuzhiyun
231*4882a593Smuzhiyun if (memcmp(login_req->isid, login->isid, 6) != 0) {
232*4882a593Smuzhiyun pr_err("Login request changed ISID unexpectedly,"
233*4882a593Smuzhiyun " protocol error.\n");
234*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
235*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
236*4882a593Smuzhiyun return -1;
237*4882a593Smuzhiyun }
238*4882a593Smuzhiyun
239*4882a593Smuzhiyun if (login_req->itt != login->init_task_tag) {
240*4882a593Smuzhiyun pr_err("Login request changed ITT unexpectedly to"
241*4882a593Smuzhiyun " 0x%08x, protocol error.\n", login_req->itt);
242*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
243*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
244*4882a593Smuzhiyun return -1;
245*4882a593Smuzhiyun }
246*4882a593Smuzhiyun
247*4882a593Smuzhiyun if (payload_length > MAX_KEY_VALUE_PAIRS) {
248*4882a593Smuzhiyun pr_err("Login request payload exceeds default"
249*4882a593Smuzhiyun " MaxRecvDataSegmentLength: %u, protocol error.\n",
250*4882a593Smuzhiyun MAX_KEY_VALUE_PAIRS);
251*4882a593Smuzhiyun return -1;
252*4882a593Smuzhiyun }
253*4882a593Smuzhiyun
254*4882a593Smuzhiyun return 0;
255*4882a593Smuzhiyun }
256*4882a593Smuzhiyun EXPORT_SYMBOL(iscsi_target_check_login_request);
257*4882a593Smuzhiyun
iscsi_target_check_first_request(struct iscsi_conn * conn,struct iscsi_login * login)258*4882a593Smuzhiyun static int iscsi_target_check_first_request(
259*4882a593Smuzhiyun struct iscsi_conn *conn,
260*4882a593Smuzhiyun struct iscsi_login *login)
261*4882a593Smuzhiyun {
262*4882a593Smuzhiyun struct iscsi_param *param = NULL;
263*4882a593Smuzhiyun struct se_node_acl *se_nacl;
264*4882a593Smuzhiyun
265*4882a593Smuzhiyun login->first_request = 0;
266*4882a593Smuzhiyun
267*4882a593Smuzhiyun list_for_each_entry(param, &conn->param_list->param_list, p_list) {
268*4882a593Smuzhiyun if (!strncmp(param->name, SESSIONTYPE, 11)) {
269*4882a593Smuzhiyun if (!IS_PSTATE_ACCEPTOR(param)) {
270*4882a593Smuzhiyun pr_err("SessionType key not received"
271*4882a593Smuzhiyun " in first login request.\n");
272*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
273*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_MISSING_FIELDS);
274*4882a593Smuzhiyun return -1;
275*4882a593Smuzhiyun }
276*4882a593Smuzhiyun if (!strncmp(param->value, DISCOVERY, 9))
277*4882a593Smuzhiyun return 0;
278*4882a593Smuzhiyun }
279*4882a593Smuzhiyun
280*4882a593Smuzhiyun if (!strncmp(param->name, INITIATORNAME, 13)) {
281*4882a593Smuzhiyun if (!IS_PSTATE_ACCEPTOR(param)) {
282*4882a593Smuzhiyun if (!login->leading_connection)
283*4882a593Smuzhiyun continue;
284*4882a593Smuzhiyun
285*4882a593Smuzhiyun pr_err("InitiatorName key not received"
286*4882a593Smuzhiyun " in first login request.\n");
287*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
288*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_MISSING_FIELDS);
289*4882a593Smuzhiyun return -1;
290*4882a593Smuzhiyun }
291*4882a593Smuzhiyun
292*4882a593Smuzhiyun /*
293*4882a593Smuzhiyun * For non-leading connections, double check that the
294*4882a593Smuzhiyun * received InitiatorName matches the existing session's
295*4882a593Smuzhiyun * struct iscsi_node_acl.
296*4882a593Smuzhiyun */
297*4882a593Smuzhiyun if (!login->leading_connection) {
298*4882a593Smuzhiyun se_nacl = conn->sess->se_sess->se_node_acl;
299*4882a593Smuzhiyun if (!se_nacl) {
300*4882a593Smuzhiyun pr_err("Unable to locate"
301*4882a593Smuzhiyun " struct se_node_acl\n");
302*4882a593Smuzhiyun iscsit_tx_login_rsp(conn,
303*4882a593Smuzhiyun ISCSI_STATUS_CLS_INITIATOR_ERR,
304*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_TGT_NOT_FOUND);
305*4882a593Smuzhiyun return -1;
306*4882a593Smuzhiyun }
307*4882a593Smuzhiyun
308*4882a593Smuzhiyun if (strcmp(param->value,
309*4882a593Smuzhiyun se_nacl->initiatorname)) {
310*4882a593Smuzhiyun pr_err("Incorrect"
311*4882a593Smuzhiyun " InitiatorName: %s for this"
312*4882a593Smuzhiyun " iSCSI Initiator Node.\n",
313*4882a593Smuzhiyun param->value);
314*4882a593Smuzhiyun iscsit_tx_login_rsp(conn,
315*4882a593Smuzhiyun ISCSI_STATUS_CLS_INITIATOR_ERR,
316*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_TGT_NOT_FOUND);
317*4882a593Smuzhiyun return -1;
318*4882a593Smuzhiyun }
319*4882a593Smuzhiyun }
320*4882a593Smuzhiyun }
321*4882a593Smuzhiyun }
322*4882a593Smuzhiyun
323*4882a593Smuzhiyun return 0;
324*4882a593Smuzhiyun }
325*4882a593Smuzhiyun
iscsi_target_do_tx_login_io(struct iscsi_conn * conn,struct iscsi_login * login)326*4882a593Smuzhiyun static int iscsi_target_do_tx_login_io(struct iscsi_conn *conn, struct iscsi_login *login)
327*4882a593Smuzhiyun {
328*4882a593Smuzhiyun u32 padding = 0;
329*4882a593Smuzhiyun struct iscsi_login_rsp *login_rsp;
330*4882a593Smuzhiyun
331*4882a593Smuzhiyun login_rsp = (struct iscsi_login_rsp *) login->rsp;
332*4882a593Smuzhiyun
333*4882a593Smuzhiyun login_rsp->opcode = ISCSI_OP_LOGIN_RSP;
334*4882a593Smuzhiyun hton24(login_rsp->dlength, login->rsp_length);
335*4882a593Smuzhiyun memcpy(login_rsp->isid, login->isid, 6);
336*4882a593Smuzhiyun login_rsp->tsih = cpu_to_be16(login->tsih);
337*4882a593Smuzhiyun login_rsp->itt = login->init_task_tag;
338*4882a593Smuzhiyun login_rsp->statsn = cpu_to_be32(conn->stat_sn++);
339*4882a593Smuzhiyun login_rsp->exp_cmdsn = cpu_to_be32(conn->sess->exp_cmd_sn);
340*4882a593Smuzhiyun login_rsp->max_cmdsn = cpu_to_be32((u32) atomic_read(&conn->sess->max_cmd_sn));
341*4882a593Smuzhiyun
342*4882a593Smuzhiyun pr_debug("Sending Login Response, Flags: 0x%02x, ITT: 0x%08x,"
343*4882a593Smuzhiyun " ExpCmdSN; 0x%08x, MaxCmdSN: 0x%08x, StatSN: 0x%08x, Length:"
344*4882a593Smuzhiyun " %u\n", login_rsp->flags, (__force u32)login_rsp->itt,
345*4882a593Smuzhiyun ntohl(login_rsp->exp_cmdsn), ntohl(login_rsp->max_cmdsn),
346*4882a593Smuzhiyun ntohl(login_rsp->statsn), login->rsp_length);
347*4882a593Smuzhiyun
348*4882a593Smuzhiyun padding = ((-login->rsp_length) & 3);
349*4882a593Smuzhiyun /*
350*4882a593Smuzhiyun * Before sending the last login response containing the transition
351*4882a593Smuzhiyun * bit for full-feature-phase, go ahead and start up TX/RX threads
352*4882a593Smuzhiyun * now to avoid potential resource allocation failures after the
353*4882a593Smuzhiyun * final login response has been sent.
354*4882a593Smuzhiyun */
355*4882a593Smuzhiyun if (login->login_complete) {
356*4882a593Smuzhiyun int rc = iscsit_start_kthreads(conn);
357*4882a593Smuzhiyun if (rc) {
358*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
359*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_NO_RESOURCES);
360*4882a593Smuzhiyun return -1;
361*4882a593Smuzhiyun }
362*4882a593Smuzhiyun }
363*4882a593Smuzhiyun
364*4882a593Smuzhiyun if (conn->conn_transport->iscsit_put_login_tx(conn, login,
365*4882a593Smuzhiyun login->rsp_length + padding) < 0)
366*4882a593Smuzhiyun goto err;
367*4882a593Smuzhiyun
368*4882a593Smuzhiyun login->rsp_length = 0;
369*4882a593Smuzhiyun
370*4882a593Smuzhiyun return 0;
371*4882a593Smuzhiyun
372*4882a593Smuzhiyun err:
373*4882a593Smuzhiyun if (login->login_complete) {
374*4882a593Smuzhiyun if (conn->rx_thread && conn->rx_thread_active) {
375*4882a593Smuzhiyun send_sig(SIGINT, conn->rx_thread, 1);
376*4882a593Smuzhiyun complete(&conn->rx_login_comp);
377*4882a593Smuzhiyun kthread_stop(conn->rx_thread);
378*4882a593Smuzhiyun }
379*4882a593Smuzhiyun if (conn->tx_thread && conn->tx_thread_active) {
380*4882a593Smuzhiyun send_sig(SIGINT, conn->tx_thread, 1);
381*4882a593Smuzhiyun kthread_stop(conn->tx_thread);
382*4882a593Smuzhiyun }
383*4882a593Smuzhiyun spin_lock(&iscsit_global->ts_bitmap_lock);
384*4882a593Smuzhiyun bitmap_release_region(iscsit_global->ts_bitmap, conn->bitmap_id,
385*4882a593Smuzhiyun get_order(1));
386*4882a593Smuzhiyun spin_unlock(&iscsit_global->ts_bitmap_lock);
387*4882a593Smuzhiyun }
388*4882a593Smuzhiyun return -1;
389*4882a593Smuzhiyun }
390*4882a593Smuzhiyun
iscsi_target_sk_data_ready(struct sock * sk)391*4882a593Smuzhiyun static void iscsi_target_sk_data_ready(struct sock *sk)
392*4882a593Smuzhiyun {
393*4882a593Smuzhiyun struct iscsi_conn *conn = sk->sk_user_data;
394*4882a593Smuzhiyun bool rc;
395*4882a593Smuzhiyun
396*4882a593Smuzhiyun pr_debug("Entering iscsi_target_sk_data_ready: conn: %p\n", conn);
397*4882a593Smuzhiyun
398*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
399*4882a593Smuzhiyun if (!sk->sk_user_data) {
400*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
401*4882a593Smuzhiyun return;
402*4882a593Smuzhiyun }
403*4882a593Smuzhiyun if (!test_bit(LOGIN_FLAGS_READY, &conn->login_flags)) {
404*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
405*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_READY=0, conn: %p >>>>\n", conn);
406*4882a593Smuzhiyun return;
407*4882a593Smuzhiyun }
408*4882a593Smuzhiyun if (test_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags)) {
409*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
410*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_CLOSED=1, conn: %p >>>>\n", conn);
411*4882a593Smuzhiyun return;
412*4882a593Smuzhiyun }
413*4882a593Smuzhiyun if (test_and_set_bit(LOGIN_FLAGS_READ_ACTIVE, &conn->login_flags)) {
414*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
415*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_READ_ACTIVE=1, conn: %p >>>>\n", conn);
416*4882a593Smuzhiyun if (iscsi_target_sk_data_ready == conn->orig_data_ready)
417*4882a593Smuzhiyun return;
418*4882a593Smuzhiyun conn->orig_data_ready(sk);
419*4882a593Smuzhiyun return;
420*4882a593Smuzhiyun }
421*4882a593Smuzhiyun
422*4882a593Smuzhiyun rc = schedule_delayed_work(&conn->login_work, 0);
423*4882a593Smuzhiyun if (!rc) {
424*4882a593Smuzhiyun pr_debug("iscsi_target_sk_data_ready, schedule_delayed_work"
425*4882a593Smuzhiyun " got false\n");
426*4882a593Smuzhiyun }
427*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
428*4882a593Smuzhiyun }
429*4882a593Smuzhiyun
430*4882a593Smuzhiyun static void iscsi_target_sk_state_change(struct sock *);
431*4882a593Smuzhiyun
iscsi_target_set_sock_callbacks(struct iscsi_conn * conn)432*4882a593Smuzhiyun static void iscsi_target_set_sock_callbacks(struct iscsi_conn *conn)
433*4882a593Smuzhiyun {
434*4882a593Smuzhiyun struct sock *sk;
435*4882a593Smuzhiyun
436*4882a593Smuzhiyun if (!conn->sock)
437*4882a593Smuzhiyun return;
438*4882a593Smuzhiyun
439*4882a593Smuzhiyun sk = conn->sock->sk;
440*4882a593Smuzhiyun pr_debug("Entering iscsi_target_set_sock_callbacks: conn: %p\n", conn);
441*4882a593Smuzhiyun
442*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
443*4882a593Smuzhiyun sk->sk_user_data = conn;
444*4882a593Smuzhiyun conn->orig_data_ready = sk->sk_data_ready;
445*4882a593Smuzhiyun conn->orig_state_change = sk->sk_state_change;
446*4882a593Smuzhiyun sk->sk_data_ready = iscsi_target_sk_data_ready;
447*4882a593Smuzhiyun sk->sk_state_change = iscsi_target_sk_state_change;
448*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
449*4882a593Smuzhiyun
450*4882a593Smuzhiyun sk->sk_sndtimeo = TA_LOGIN_TIMEOUT * HZ;
451*4882a593Smuzhiyun sk->sk_rcvtimeo = TA_LOGIN_TIMEOUT * HZ;
452*4882a593Smuzhiyun }
453*4882a593Smuzhiyun
iscsi_target_restore_sock_callbacks(struct iscsi_conn * conn)454*4882a593Smuzhiyun static void iscsi_target_restore_sock_callbacks(struct iscsi_conn *conn)
455*4882a593Smuzhiyun {
456*4882a593Smuzhiyun struct sock *sk;
457*4882a593Smuzhiyun
458*4882a593Smuzhiyun if (!conn->sock)
459*4882a593Smuzhiyun return;
460*4882a593Smuzhiyun
461*4882a593Smuzhiyun sk = conn->sock->sk;
462*4882a593Smuzhiyun pr_debug("Entering iscsi_target_restore_sock_callbacks: conn: %p\n", conn);
463*4882a593Smuzhiyun
464*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
465*4882a593Smuzhiyun if (!sk->sk_user_data) {
466*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
467*4882a593Smuzhiyun return;
468*4882a593Smuzhiyun }
469*4882a593Smuzhiyun sk->sk_user_data = NULL;
470*4882a593Smuzhiyun sk->sk_data_ready = conn->orig_data_ready;
471*4882a593Smuzhiyun sk->sk_state_change = conn->orig_state_change;
472*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
473*4882a593Smuzhiyun
474*4882a593Smuzhiyun sk->sk_sndtimeo = MAX_SCHEDULE_TIMEOUT;
475*4882a593Smuzhiyun sk->sk_rcvtimeo = MAX_SCHEDULE_TIMEOUT;
476*4882a593Smuzhiyun }
477*4882a593Smuzhiyun
478*4882a593Smuzhiyun static int iscsi_target_do_login(struct iscsi_conn *, struct iscsi_login *);
479*4882a593Smuzhiyun
__iscsi_target_sk_check_close(struct sock * sk)480*4882a593Smuzhiyun static bool __iscsi_target_sk_check_close(struct sock *sk)
481*4882a593Smuzhiyun {
482*4882a593Smuzhiyun if (sk->sk_state == TCP_CLOSE_WAIT || sk->sk_state == TCP_CLOSE) {
483*4882a593Smuzhiyun pr_debug("__iscsi_target_sk_check_close: TCP_CLOSE_WAIT|TCP_CLOSE,"
484*4882a593Smuzhiyun "returning TRUE\n");
485*4882a593Smuzhiyun return true;
486*4882a593Smuzhiyun }
487*4882a593Smuzhiyun return false;
488*4882a593Smuzhiyun }
489*4882a593Smuzhiyun
iscsi_target_sk_check_close(struct iscsi_conn * conn)490*4882a593Smuzhiyun static bool iscsi_target_sk_check_close(struct iscsi_conn *conn)
491*4882a593Smuzhiyun {
492*4882a593Smuzhiyun bool state = false;
493*4882a593Smuzhiyun
494*4882a593Smuzhiyun if (conn->sock) {
495*4882a593Smuzhiyun struct sock *sk = conn->sock->sk;
496*4882a593Smuzhiyun
497*4882a593Smuzhiyun read_lock_bh(&sk->sk_callback_lock);
498*4882a593Smuzhiyun state = (__iscsi_target_sk_check_close(sk) ||
499*4882a593Smuzhiyun test_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags));
500*4882a593Smuzhiyun read_unlock_bh(&sk->sk_callback_lock);
501*4882a593Smuzhiyun }
502*4882a593Smuzhiyun return state;
503*4882a593Smuzhiyun }
504*4882a593Smuzhiyun
iscsi_target_sk_check_flag(struct iscsi_conn * conn,unsigned int flag)505*4882a593Smuzhiyun static bool iscsi_target_sk_check_flag(struct iscsi_conn *conn, unsigned int flag)
506*4882a593Smuzhiyun {
507*4882a593Smuzhiyun bool state = false;
508*4882a593Smuzhiyun
509*4882a593Smuzhiyun if (conn->sock) {
510*4882a593Smuzhiyun struct sock *sk = conn->sock->sk;
511*4882a593Smuzhiyun
512*4882a593Smuzhiyun read_lock_bh(&sk->sk_callback_lock);
513*4882a593Smuzhiyun state = test_bit(flag, &conn->login_flags);
514*4882a593Smuzhiyun read_unlock_bh(&sk->sk_callback_lock);
515*4882a593Smuzhiyun }
516*4882a593Smuzhiyun return state;
517*4882a593Smuzhiyun }
518*4882a593Smuzhiyun
iscsi_target_sk_check_and_clear(struct iscsi_conn * conn,unsigned int flag)519*4882a593Smuzhiyun static bool iscsi_target_sk_check_and_clear(struct iscsi_conn *conn, unsigned int flag)
520*4882a593Smuzhiyun {
521*4882a593Smuzhiyun bool state = false;
522*4882a593Smuzhiyun
523*4882a593Smuzhiyun if (conn->sock) {
524*4882a593Smuzhiyun struct sock *sk = conn->sock->sk;
525*4882a593Smuzhiyun
526*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
527*4882a593Smuzhiyun state = (__iscsi_target_sk_check_close(sk) ||
528*4882a593Smuzhiyun test_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags));
529*4882a593Smuzhiyun if (!state)
530*4882a593Smuzhiyun clear_bit(flag, &conn->login_flags);
531*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
532*4882a593Smuzhiyun }
533*4882a593Smuzhiyun return state;
534*4882a593Smuzhiyun }
535*4882a593Smuzhiyun
iscsi_target_login_drop(struct iscsi_conn * conn,struct iscsi_login * login)536*4882a593Smuzhiyun static void iscsi_target_login_drop(struct iscsi_conn *conn, struct iscsi_login *login)
537*4882a593Smuzhiyun {
538*4882a593Smuzhiyun bool zero_tsih = login->zero_tsih;
539*4882a593Smuzhiyun
540*4882a593Smuzhiyun iscsi_remove_failed_auth_entry(conn);
541*4882a593Smuzhiyun iscsi_target_nego_release(conn);
542*4882a593Smuzhiyun iscsi_target_login_sess_out(conn, zero_tsih, true);
543*4882a593Smuzhiyun }
544*4882a593Smuzhiyun
545*4882a593Smuzhiyun struct conn_timeout {
546*4882a593Smuzhiyun struct timer_list timer;
547*4882a593Smuzhiyun struct iscsi_conn *conn;
548*4882a593Smuzhiyun };
549*4882a593Smuzhiyun
iscsi_target_login_timeout(struct timer_list * t)550*4882a593Smuzhiyun static void iscsi_target_login_timeout(struct timer_list *t)
551*4882a593Smuzhiyun {
552*4882a593Smuzhiyun struct conn_timeout *timeout = from_timer(timeout, t, timer);
553*4882a593Smuzhiyun struct iscsi_conn *conn = timeout->conn;
554*4882a593Smuzhiyun
555*4882a593Smuzhiyun pr_debug("Entering iscsi_target_login_timeout >>>>>>>>>>>>>>>>>>>\n");
556*4882a593Smuzhiyun
557*4882a593Smuzhiyun if (conn->login_kworker) {
558*4882a593Smuzhiyun pr_debug("Sending SIGINT to conn->login_kworker %s/%d\n",
559*4882a593Smuzhiyun conn->login_kworker->comm, conn->login_kworker->pid);
560*4882a593Smuzhiyun send_sig(SIGINT, conn->login_kworker, 1);
561*4882a593Smuzhiyun }
562*4882a593Smuzhiyun }
563*4882a593Smuzhiyun
iscsi_target_do_login_rx(struct work_struct * work)564*4882a593Smuzhiyun static void iscsi_target_do_login_rx(struct work_struct *work)
565*4882a593Smuzhiyun {
566*4882a593Smuzhiyun struct iscsi_conn *conn = container_of(work,
567*4882a593Smuzhiyun struct iscsi_conn, login_work.work);
568*4882a593Smuzhiyun struct iscsi_login *login = conn->login;
569*4882a593Smuzhiyun struct iscsi_np *np = login->np;
570*4882a593Smuzhiyun struct iscsi_portal_group *tpg = conn->tpg;
571*4882a593Smuzhiyun struct iscsi_tpg_np *tpg_np = conn->tpg_np;
572*4882a593Smuzhiyun struct conn_timeout timeout;
573*4882a593Smuzhiyun int rc, zero_tsih = login->zero_tsih;
574*4882a593Smuzhiyun bool state;
575*4882a593Smuzhiyun
576*4882a593Smuzhiyun pr_debug("entering iscsi_target_do_login_rx, conn: %p, %s:%d\n",
577*4882a593Smuzhiyun conn, current->comm, current->pid);
578*4882a593Smuzhiyun /*
579*4882a593Smuzhiyun * If iscsi_target_do_login_rx() has been invoked by ->sk_data_ready()
580*4882a593Smuzhiyun * before initial PDU processing in iscsi_target_start_negotiation()
581*4882a593Smuzhiyun * has completed, go ahead and retry until it's cleared.
582*4882a593Smuzhiyun *
583*4882a593Smuzhiyun * Otherwise if the TCP connection drops while this is occuring,
584*4882a593Smuzhiyun * iscsi_target_start_negotiation() will detect the failure, call
585*4882a593Smuzhiyun * cancel_delayed_work_sync(&conn->login_work), and cleanup the
586*4882a593Smuzhiyun * remaining iscsi connection resources from iscsi_np process context.
587*4882a593Smuzhiyun */
588*4882a593Smuzhiyun if (iscsi_target_sk_check_flag(conn, LOGIN_FLAGS_INITIAL_PDU)) {
589*4882a593Smuzhiyun schedule_delayed_work(&conn->login_work, msecs_to_jiffies(10));
590*4882a593Smuzhiyun return;
591*4882a593Smuzhiyun }
592*4882a593Smuzhiyun
593*4882a593Smuzhiyun spin_lock(&tpg->tpg_state_lock);
594*4882a593Smuzhiyun state = (tpg->tpg_state == TPG_STATE_ACTIVE);
595*4882a593Smuzhiyun spin_unlock(&tpg->tpg_state_lock);
596*4882a593Smuzhiyun
597*4882a593Smuzhiyun if (!state) {
598*4882a593Smuzhiyun pr_debug("iscsi_target_do_login_rx: tpg_state != TPG_STATE_ACTIVE\n");
599*4882a593Smuzhiyun goto err;
600*4882a593Smuzhiyun }
601*4882a593Smuzhiyun
602*4882a593Smuzhiyun if (iscsi_target_sk_check_close(conn)) {
603*4882a593Smuzhiyun pr_debug("iscsi_target_do_login_rx, TCP state CLOSE\n");
604*4882a593Smuzhiyun goto err;
605*4882a593Smuzhiyun }
606*4882a593Smuzhiyun
607*4882a593Smuzhiyun conn->login_kworker = current;
608*4882a593Smuzhiyun allow_signal(SIGINT);
609*4882a593Smuzhiyun
610*4882a593Smuzhiyun timeout.conn = conn;
611*4882a593Smuzhiyun timer_setup_on_stack(&timeout.timer, iscsi_target_login_timeout, 0);
612*4882a593Smuzhiyun mod_timer(&timeout.timer, jiffies + TA_LOGIN_TIMEOUT * HZ);
613*4882a593Smuzhiyun pr_debug("Starting login timer for %s/%d\n", current->comm, current->pid);
614*4882a593Smuzhiyun
615*4882a593Smuzhiyun rc = conn->conn_transport->iscsit_get_login_rx(conn, login);
616*4882a593Smuzhiyun del_timer_sync(&timeout.timer);
617*4882a593Smuzhiyun destroy_timer_on_stack(&timeout.timer);
618*4882a593Smuzhiyun flush_signals(current);
619*4882a593Smuzhiyun conn->login_kworker = NULL;
620*4882a593Smuzhiyun
621*4882a593Smuzhiyun if (rc < 0)
622*4882a593Smuzhiyun goto err;
623*4882a593Smuzhiyun
624*4882a593Smuzhiyun pr_debug("iscsi_target_do_login_rx after rx_login_io, %p, %s:%d\n",
625*4882a593Smuzhiyun conn, current->comm, current->pid);
626*4882a593Smuzhiyun
627*4882a593Smuzhiyun /*
628*4882a593Smuzhiyun * LOGIN_FLAGS_READ_ACTIVE is cleared so that sk_data_ready
629*4882a593Smuzhiyun * could be triggered again after this.
630*4882a593Smuzhiyun *
631*4882a593Smuzhiyun * LOGIN_FLAGS_WRITE_ACTIVE is cleared after we successfully
632*4882a593Smuzhiyun * process a login PDU, so that sk_state_chage can do login
633*4882a593Smuzhiyun * cleanup as needed if the socket is closed. If a delayed work is
634*4882a593Smuzhiyun * ongoing (LOGIN_FLAGS_WRITE_ACTIVE or LOGIN_FLAGS_READ_ACTIVE),
635*4882a593Smuzhiyun * sk_state_change will leave the cleanup to the delayed work or
636*4882a593Smuzhiyun * it will schedule a delayed work to do cleanup.
637*4882a593Smuzhiyun */
638*4882a593Smuzhiyun if (conn->sock) {
639*4882a593Smuzhiyun struct sock *sk = conn->sock->sk;
640*4882a593Smuzhiyun
641*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
642*4882a593Smuzhiyun if (!test_bit(LOGIN_FLAGS_INITIAL_PDU, &conn->login_flags)) {
643*4882a593Smuzhiyun clear_bit(LOGIN_FLAGS_READ_ACTIVE, &conn->login_flags);
644*4882a593Smuzhiyun set_bit(LOGIN_FLAGS_WRITE_ACTIVE, &conn->login_flags);
645*4882a593Smuzhiyun }
646*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
647*4882a593Smuzhiyun }
648*4882a593Smuzhiyun
649*4882a593Smuzhiyun rc = iscsi_target_do_login(conn, login);
650*4882a593Smuzhiyun if (rc < 0) {
651*4882a593Smuzhiyun goto err;
652*4882a593Smuzhiyun } else if (!rc) {
653*4882a593Smuzhiyun if (iscsi_target_sk_check_and_clear(conn,
654*4882a593Smuzhiyun LOGIN_FLAGS_WRITE_ACTIVE))
655*4882a593Smuzhiyun goto err;
656*4882a593Smuzhiyun } else if (rc == 1) {
657*4882a593Smuzhiyun cancel_delayed_work(&conn->login_work);
658*4882a593Smuzhiyun iscsi_target_nego_release(conn);
659*4882a593Smuzhiyun iscsi_post_login_handler(np, conn, zero_tsih);
660*4882a593Smuzhiyun iscsit_deaccess_np(np, tpg, tpg_np);
661*4882a593Smuzhiyun }
662*4882a593Smuzhiyun return;
663*4882a593Smuzhiyun
664*4882a593Smuzhiyun err:
665*4882a593Smuzhiyun iscsi_target_restore_sock_callbacks(conn);
666*4882a593Smuzhiyun cancel_delayed_work(&conn->login_work);
667*4882a593Smuzhiyun iscsi_target_login_drop(conn, login);
668*4882a593Smuzhiyun iscsit_deaccess_np(np, tpg, tpg_np);
669*4882a593Smuzhiyun }
670*4882a593Smuzhiyun
iscsi_target_sk_state_change(struct sock * sk)671*4882a593Smuzhiyun static void iscsi_target_sk_state_change(struct sock *sk)
672*4882a593Smuzhiyun {
673*4882a593Smuzhiyun struct iscsi_conn *conn;
674*4882a593Smuzhiyun void (*orig_state_change)(struct sock *);
675*4882a593Smuzhiyun bool state;
676*4882a593Smuzhiyun
677*4882a593Smuzhiyun pr_debug("Entering iscsi_target_sk_state_change\n");
678*4882a593Smuzhiyun
679*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
680*4882a593Smuzhiyun conn = sk->sk_user_data;
681*4882a593Smuzhiyun if (!conn) {
682*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
683*4882a593Smuzhiyun return;
684*4882a593Smuzhiyun }
685*4882a593Smuzhiyun orig_state_change = conn->orig_state_change;
686*4882a593Smuzhiyun
687*4882a593Smuzhiyun if (!test_bit(LOGIN_FLAGS_READY, &conn->login_flags)) {
688*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_READY=0 sk_state_change conn: %p\n",
689*4882a593Smuzhiyun conn);
690*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
691*4882a593Smuzhiyun orig_state_change(sk);
692*4882a593Smuzhiyun return;
693*4882a593Smuzhiyun }
694*4882a593Smuzhiyun state = __iscsi_target_sk_check_close(sk);
695*4882a593Smuzhiyun pr_debug("__iscsi_target_sk_close_change: state: %d\n", state);
696*4882a593Smuzhiyun
697*4882a593Smuzhiyun if (test_bit(LOGIN_FLAGS_READ_ACTIVE, &conn->login_flags) ||
698*4882a593Smuzhiyun test_bit(LOGIN_FLAGS_WRITE_ACTIVE, &conn->login_flags)) {
699*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_{READ|WRITE}_ACTIVE=1"
700*4882a593Smuzhiyun " sk_state_change conn: %p\n", conn);
701*4882a593Smuzhiyun if (state)
702*4882a593Smuzhiyun set_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags);
703*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
704*4882a593Smuzhiyun orig_state_change(sk);
705*4882a593Smuzhiyun return;
706*4882a593Smuzhiyun }
707*4882a593Smuzhiyun if (test_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags)) {
708*4882a593Smuzhiyun pr_debug("Got LOGIN_FLAGS_CLOSED=1 sk_state_change conn: %p\n",
709*4882a593Smuzhiyun conn);
710*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
711*4882a593Smuzhiyun orig_state_change(sk);
712*4882a593Smuzhiyun return;
713*4882a593Smuzhiyun }
714*4882a593Smuzhiyun /*
715*4882a593Smuzhiyun * If the TCP connection has dropped, go ahead and set LOGIN_FLAGS_CLOSED,
716*4882a593Smuzhiyun * but only queue conn->login_work -> iscsi_target_do_login_rx()
717*4882a593Smuzhiyun * processing if LOGIN_FLAGS_INITIAL_PDU has already been cleared.
718*4882a593Smuzhiyun *
719*4882a593Smuzhiyun * When iscsi_target_do_login_rx() runs, iscsi_target_sk_check_close()
720*4882a593Smuzhiyun * will detect the dropped TCP connection from delayed workqueue context.
721*4882a593Smuzhiyun *
722*4882a593Smuzhiyun * If LOGIN_FLAGS_INITIAL_PDU is still set, which means the initial
723*4882a593Smuzhiyun * iscsi_target_start_negotiation() is running, iscsi_target_do_login()
724*4882a593Smuzhiyun * via iscsi_target_sk_check_close() or iscsi_target_start_negotiation()
725*4882a593Smuzhiyun * via iscsi_target_sk_check_and_clear() is responsible for detecting the
726*4882a593Smuzhiyun * dropped TCP connection in iscsi_np process context, and cleaning up
727*4882a593Smuzhiyun * the remaining iscsi connection resources.
728*4882a593Smuzhiyun */
729*4882a593Smuzhiyun if (state) {
730*4882a593Smuzhiyun pr_debug("iscsi_target_sk_state_change got failed state\n");
731*4882a593Smuzhiyun set_bit(LOGIN_FLAGS_CLOSED, &conn->login_flags);
732*4882a593Smuzhiyun state = test_bit(LOGIN_FLAGS_INITIAL_PDU, &conn->login_flags);
733*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
734*4882a593Smuzhiyun
735*4882a593Smuzhiyun orig_state_change(sk);
736*4882a593Smuzhiyun
737*4882a593Smuzhiyun if (!state)
738*4882a593Smuzhiyun schedule_delayed_work(&conn->login_work, 0);
739*4882a593Smuzhiyun return;
740*4882a593Smuzhiyun }
741*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
742*4882a593Smuzhiyun
743*4882a593Smuzhiyun orig_state_change(sk);
744*4882a593Smuzhiyun }
745*4882a593Smuzhiyun
746*4882a593Smuzhiyun /*
747*4882a593Smuzhiyun * NOTE: We check for existing sessions or connections AFTER the initiator
748*4882a593Smuzhiyun * has been successfully authenticated in order to protect against faked
749*4882a593Smuzhiyun * ISID/TSIH combinations.
750*4882a593Smuzhiyun */
iscsi_target_check_for_existing_instances(struct iscsi_conn * conn,struct iscsi_login * login)751*4882a593Smuzhiyun static int iscsi_target_check_for_existing_instances(
752*4882a593Smuzhiyun struct iscsi_conn *conn,
753*4882a593Smuzhiyun struct iscsi_login *login)
754*4882a593Smuzhiyun {
755*4882a593Smuzhiyun if (login->checked_for_existing)
756*4882a593Smuzhiyun return 0;
757*4882a593Smuzhiyun
758*4882a593Smuzhiyun login->checked_for_existing = 1;
759*4882a593Smuzhiyun
760*4882a593Smuzhiyun if (!login->tsih)
761*4882a593Smuzhiyun return iscsi_check_for_session_reinstatement(conn);
762*4882a593Smuzhiyun else
763*4882a593Smuzhiyun return iscsi_login_post_auth_non_zero_tsih(conn, login->cid,
764*4882a593Smuzhiyun login->initial_exp_statsn);
765*4882a593Smuzhiyun }
766*4882a593Smuzhiyun
iscsi_target_do_authentication(struct iscsi_conn * conn,struct iscsi_login * login)767*4882a593Smuzhiyun static int iscsi_target_do_authentication(
768*4882a593Smuzhiyun struct iscsi_conn *conn,
769*4882a593Smuzhiyun struct iscsi_login *login)
770*4882a593Smuzhiyun {
771*4882a593Smuzhiyun int authret;
772*4882a593Smuzhiyun u32 payload_length;
773*4882a593Smuzhiyun struct iscsi_param *param;
774*4882a593Smuzhiyun struct iscsi_login_req *login_req;
775*4882a593Smuzhiyun struct iscsi_login_rsp *login_rsp;
776*4882a593Smuzhiyun
777*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
778*4882a593Smuzhiyun login_rsp = (struct iscsi_login_rsp *) login->rsp;
779*4882a593Smuzhiyun payload_length = ntoh24(login_req->dlength);
780*4882a593Smuzhiyun
781*4882a593Smuzhiyun param = iscsi_find_param_from_key(AUTHMETHOD, conn->param_list);
782*4882a593Smuzhiyun if (!param)
783*4882a593Smuzhiyun return -1;
784*4882a593Smuzhiyun
785*4882a593Smuzhiyun authret = iscsi_handle_authentication(
786*4882a593Smuzhiyun conn,
787*4882a593Smuzhiyun login->req_buf,
788*4882a593Smuzhiyun login->rsp_buf,
789*4882a593Smuzhiyun payload_length,
790*4882a593Smuzhiyun &login->rsp_length,
791*4882a593Smuzhiyun param->value);
792*4882a593Smuzhiyun switch (authret) {
793*4882a593Smuzhiyun case 0:
794*4882a593Smuzhiyun pr_debug("Received OK response"
795*4882a593Smuzhiyun " from LIO Authentication, continuing.\n");
796*4882a593Smuzhiyun break;
797*4882a593Smuzhiyun case 1:
798*4882a593Smuzhiyun pr_debug("iSCSI security negotiation"
799*4882a593Smuzhiyun " completed successfully.\n");
800*4882a593Smuzhiyun login->auth_complete = 1;
801*4882a593Smuzhiyun if ((login_req->flags & ISCSI_FLAG_LOGIN_NEXT_STAGE1) &&
802*4882a593Smuzhiyun (login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT)) {
803*4882a593Smuzhiyun login_rsp->flags |= (ISCSI_FLAG_LOGIN_NEXT_STAGE1 |
804*4882a593Smuzhiyun ISCSI_FLAG_LOGIN_TRANSIT);
805*4882a593Smuzhiyun login->current_stage = 1;
806*4882a593Smuzhiyun }
807*4882a593Smuzhiyun return iscsi_target_check_for_existing_instances(
808*4882a593Smuzhiyun conn, login);
809*4882a593Smuzhiyun case 2:
810*4882a593Smuzhiyun pr_err("Security negotiation"
811*4882a593Smuzhiyun " failed.\n");
812*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
813*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_AUTH_FAILED);
814*4882a593Smuzhiyun return -1;
815*4882a593Smuzhiyun default:
816*4882a593Smuzhiyun pr_err("Received unknown error %d from LIO"
817*4882a593Smuzhiyun " Authentication\n", authret);
818*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
819*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_TARGET_ERROR);
820*4882a593Smuzhiyun return -1;
821*4882a593Smuzhiyun }
822*4882a593Smuzhiyun
823*4882a593Smuzhiyun return 0;
824*4882a593Smuzhiyun }
825*4882a593Smuzhiyun
iscsi_target_handle_csg_zero(struct iscsi_conn * conn,struct iscsi_login * login)826*4882a593Smuzhiyun static int iscsi_target_handle_csg_zero(
827*4882a593Smuzhiyun struct iscsi_conn *conn,
828*4882a593Smuzhiyun struct iscsi_login *login)
829*4882a593Smuzhiyun {
830*4882a593Smuzhiyun int ret;
831*4882a593Smuzhiyun u32 payload_length;
832*4882a593Smuzhiyun struct iscsi_param *param;
833*4882a593Smuzhiyun struct iscsi_login_req *login_req;
834*4882a593Smuzhiyun struct iscsi_login_rsp *login_rsp;
835*4882a593Smuzhiyun
836*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
837*4882a593Smuzhiyun login_rsp = (struct iscsi_login_rsp *) login->rsp;
838*4882a593Smuzhiyun payload_length = ntoh24(login_req->dlength);
839*4882a593Smuzhiyun
840*4882a593Smuzhiyun param = iscsi_find_param_from_key(AUTHMETHOD, conn->param_list);
841*4882a593Smuzhiyun if (!param)
842*4882a593Smuzhiyun return -1;
843*4882a593Smuzhiyun
844*4882a593Smuzhiyun ret = iscsi_decode_text_input(
845*4882a593Smuzhiyun PHASE_SECURITY|PHASE_DECLARATIVE,
846*4882a593Smuzhiyun SENDER_INITIATOR|SENDER_RECEIVER,
847*4882a593Smuzhiyun login->req_buf,
848*4882a593Smuzhiyun payload_length,
849*4882a593Smuzhiyun conn);
850*4882a593Smuzhiyun if (ret < 0)
851*4882a593Smuzhiyun return -1;
852*4882a593Smuzhiyun
853*4882a593Smuzhiyun if (ret > 0) {
854*4882a593Smuzhiyun if (login->auth_complete) {
855*4882a593Smuzhiyun pr_err("Initiator has already been"
856*4882a593Smuzhiyun " successfully authenticated, but is still"
857*4882a593Smuzhiyun " sending %s keys.\n", param->value);
858*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
859*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
860*4882a593Smuzhiyun return -1;
861*4882a593Smuzhiyun }
862*4882a593Smuzhiyun
863*4882a593Smuzhiyun goto do_auth;
864*4882a593Smuzhiyun } else if (!payload_length) {
865*4882a593Smuzhiyun pr_err("Initiator sent zero length security payload,"
866*4882a593Smuzhiyun " login failed\n");
867*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
868*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_AUTH_FAILED);
869*4882a593Smuzhiyun return -1;
870*4882a593Smuzhiyun }
871*4882a593Smuzhiyun
872*4882a593Smuzhiyun if (login->first_request)
873*4882a593Smuzhiyun if (iscsi_target_check_first_request(conn, login) < 0)
874*4882a593Smuzhiyun return -1;
875*4882a593Smuzhiyun
876*4882a593Smuzhiyun ret = iscsi_encode_text_output(
877*4882a593Smuzhiyun PHASE_SECURITY|PHASE_DECLARATIVE,
878*4882a593Smuzhiyun SENDER_TARGET,
879*4882a593Smuzhiyun login->rsp_buf,
880*4882a593Smuzhiyun &login->rsp_length,
881*4882a593Smuzhiyun conn->param_list,
882*4882a593Smuzhiyun conn->tpg->tpg_attrib.login_keys_workaround);
883*4882a593Smuzhiyun if (ret < 0)
884*4882a593Smuzhiyun return -1;
885*4882a593Smuzhiyun
886*4882a593Smuzhiyun if (!iscsi_check_negotiated_keys(conn->param_list)) {
887*4882a593Smuzhiyun if (conn->tpg->tpg_attrib.authentication &&
888*4882a593Smuzhiyun !strncmp(param->value, NONE, 4)) {
889*4882a593Smuzhiyun pr_err("Initiator sent AuthMethod=None but"
890*4882a593Smuzhiyun " Target is enforcing iSCSI Authentication,"
891*4882a593Smuzhiyun " login failed.\n");
892*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
893*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_AUTH_FAILED);
894*4882a593Smuzhiyun return -1;
895*4882a593Smuzhiyun }
896*4882a593Smuzhiyun
897*4882a593Smuzhiyun if (conn->tpg->tpg_attrib.authentication &&
898*4882a593Smuzhiyun !login->auth_complete)
899*4882a593Smuzhiyun return 0;
900*4882a593Smuzhiyun
901*4882a593Smuzhiyun if (strncmp(param->value, NONE, 4) && !login->auth_complete)
902*4882a593Smuzhiyun return 0;
903*4882a593Smuzhiyun
904*4882a593Smuzhiyun if ((login_req->flags & ISCSI_FLAG_LOGIN_NEXT_STAGE1) &&
905*4882a593Smuzhiyun (login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT)) {
906*4882a593Smuzhiyun login_rsp->flags |= ISCSI_FLAG_LOGIN_NEXT_STAGE1 |
907*4882a593Smuzhiyun ISCSI_FLAG_LOGIN_TRANSIT;
908*4882a593Smuzhiyun login->current_stage = 1;
909*4882a593Smuzhiyun }
910*4882a593Smuzhiyun }
911*4882a593Smuzhiyun
912*4882a593Smuzhiyun return 0;
913*4882a593Smuzhiyun do_auth:
914*4882a593Smuzhiyun return iscsi_target_do_authentication(conn, login);
915*4882a593Smuzhiyun }
916*4882a593Smuzhiyun
iscsi_target_handle_csg_one(struct iscsi_conn * conn,struct iscsi_login * login)917*4882a593Smuzhiyun static int iscsi_target_handle_csg_one(struct iscsi_conn *conn, struct iscsi_login *login)
918*4882a593Smuzhiyun {
919*4882a593Smuzhiyun int ret;
920*4882a593Smuzhiyun u32 payload_length;
921*4882a593Smuzhiyun struct iscsi_login_req *login_req;
922*4882a593Smuzhiyun struct iscsi_login_rsp *login_rsp;
923*4882a593Smuzhiyun
924*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
925*4882a593Smuzhiyun login_rsp = (struct iscsi_login_rsp *) login->rsp;
926*4882a593Smuzhiyun payload_length = ntoh24(login_req->dlength);
927*4882a593Smuzhiyun
928*4882a593Smuzhiyun ret = iscsi_decode_text_input(
929*4882a593Smuzhiyun PHASE_OPERATIONAL|PHASE_DECLARATIVE,
930*4882a593Smuzhiyun SENDER_INITIATOR|SENDER_RECEIVER,
931*4882a593Smuzhiyun login->req_buf,
932*4882a593Smuzhiyun payload_length,
933*4882a593Smuzhiyun conn);
934*4882a593Smuzhiyun if (ret < 0) {
935*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
936*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
937*4882a593Smuzhiyun return -1;
938*4882a593Smuzhiyun }
939*4882a593Smuzhiyun
940*4882a593Smuzhiyun if (login->first_request)
941*4882a593Smuzhiyun if (iscsi_target_check_first_request(conn, login) < 0)
942*4882a593Smuzhiyun return -1;
943*4882a593Smuzhiyun
944*4882a593Smuzhiyun if (iscsi_target_check_for_existing_instances(conn, login) < 0)
945*4882a593Smuzhiyun return -1;
946*4882a593Smuzhiyun
947*4882a593Smuzhiyun ret = iscsi_encode_text_output(
948*4882a593Smuzhiyun PHASE_OPERATIONAL|PHASE_DECLARATIVE,
949*4882a593Smuzhiyun SENDER_TARGET,
950*4882a593Smuzhiyun login->rsp_buf,
951*4882a593Smuzhiyun &login->rsp_length,
952*4882a593Smuzhiyun conn->param_list,
953*4882a593Smuzhiyun conn->tpg->tpg_attrib.login_keys_workaround);
954*4882a593Smuzhiyun if (ret < 0) {
955*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
956*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_INIT_ERR);
957*4882a593Smuzhiyun return -1;
958*4882a593Smuzhiyun }
959*4882a593Smuzhiyun
960*4882a593Smuzhiyun if (!login->auth_complete &&
961*4882a593Smuzhiyun conn->tpg->tpg_attrib.authentication) {
962*4882a593Smuzhiyun pr_err("Initiator is requesting CSG: 1, has not been"
963*4882a593Smuzhiyun " successfully authenticated, and the Target is"
964*4882a593Smuzhiyun " enforcing iSCSI Authentication, login failed.\n");
965*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
966*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_AUTH_FAILED);
967*4882a593Smuzhiyun return -1;
968*4882a593Smuzhiyun }
969*4882a593Smuzhiyun
970*4882a593Smuzhiyun if (!iscsi_check_negotiated_keys(conn->param_list))
971*4882a593Smuzhiyun if ((login_req->flags & ISCSI_FLAG_LOGIN_NEXT_STAGE3) &&
972*4882a593Smuzhiyun (login_req->flags & ISCSI_FLAG_LOGIN_TRANSIT))
973*4882a593Smuzhiyun login_rsp->flags |= ISCSI_FLAG_LOGIN_NEXT_STAGE3 |
974*4882a593Smuzhiyun ISCSI_FLAG_LOGIN_TRANSIT;
975*4882a593Smuzhiyun
976*4882a593Smuzhiyun return 0;
977*4882a593Smuzhiyun }
978*4882a593Smuzhiyun
iscsi_target_do_login(struct iscsi_conn * conn,struct iscsi_login * login)979*4882a593Smuzhiyun static int iscsi_target_do_login(struct iscsi_conn *conn, struct iscsi_login *login)
980*4882a593Smuzhiyun {
981*4882a593Smuzhiyun int pdu_count = 0;
982*4882a593Smuzhiyun struct iscsi_login_req *login_req;
983*4882a593Smuzhiyun struct iscsi_login_rsp *login_rsp;
984*4882a593Smuzhiyun
985*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
986*4882a593Smuzhiyun login_rsp = (struct iscsi_login_rsp *) login->rsp;
987*4882a593Smuzhiyun
988*4882a593Smuzhiyun while (1) {
989*4882a593Smuzhiyun if (++pdu_count > MAX_LOGIN_PDUS) {
990*4882a593Smuzhiyun pr_err("MAX_LOGIN_PDUS count reached.\n");
991*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
992*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_TARGET_ERROR);
993*4882a593Smuzhiyun return -1;
994*4882a593Smuzhiyun }
995*4882a593Smuzhiyun
996*4882a593Smuzhiyun switch (ISCSI_LOGIN_CURRENT_STAGE(login_req->flags)) {
997*4882a593Smuzhiyun case 0:
998*4882a593Smuzhiyun login_rsp->flags &= ~ISCSI_FLAG_LOGIN_CURRENT_STAGE_MASK;
999*4882a593Smuzhiyun if (iscsi_target_handle_csg_zero(conn, login) < 0)
1000*4882a593Smuzhiyun return -1;
1001*4882a593Smuzhiyun break;
1002*4882a593Smuzhiyun case 1:
1003*4882a593Smuzhiyun login_rsp->flags |= ISCSI_FLAG_LOGIN_CURRENT_STAGE1;
1004*4882a593Smuzhiyun if (iscsi_target_handle_csg_one(conn, login) < 0)
1005*4882a593Smuzhiyun return -1;
1006*4882a593Smuzhiyun if (login_rsp->flags & ISCSI_FLAG_LOGIN_TRANSIT) {
1007*4882a593Smuzhiyun /*
1008*4882a593Smuzhiyun * Check to make sure the TCP connection has not
1009*4882a593Smuzhiyun * dropped asynchronously while session reinstatement
1010*4882a593Smuzhiyun * was occuring in this kthread context, before
1011*4882a593Smuzhiyun * transitioning to full feature phase operation.
1012*4882a593Smuzhiyun */
1013*4882a593Smuzhiyun if (iscsi_target_sk_check_close(conn))
1014*4882a593Smuzhiyun return -1;
1015*4882a593Smuzhiyun
1016*4882a593Smuzhiyun login->tsih = conn->sess->tsih;
1017*4882a593Smuzhiyun login->login_complete = 1;
1018*4882a593Smuzhiyun iscsi_target_restore_sock_callbacks(conn);
1019*4882a593Smuzhiyun if (iscsi_target_do_tx_login_io(conn,
1020*4882a593Smuzhiyun login) < 0)
1021*4882a593Smuzhiyun return -1;
1022*4882a593Smuzhiyun return 1;
1023*4882a593Smuzhiyun }
1024*4882a593Smuzhiyun break;
1025*4882a593Smuzhiyun default:
1026*4882a593Smuzhiyun pr_err("Illegal CSG: %d received from"
1027*4882a593Smuzhiyun " Initiator, protocol error.\n",
1028*4882a593Smuzhiyun ISCSI_LOGIN_CURRENT_STAGE(login_req->flags));
1029*4882a593Smuzhiyun break;
1030*4882a593Smuzhiyun }
1031*4882a593Smuzhiyun
1032*4882a593Smuzhiyun if (iscsi_target_do_tx_login_io(conn, login) < 0)
1033*4882a593Smuzhiyun return -1;
1034*4882a593Smuzhiyun
1035*4882a593Smuzhiyun if (login_rsp->flags & ISCSI_FLAG_LOGIN_TRANSIT) {
1036*4882a593Smuzhiyun login_rsp->flags &= ~ISCSI_FLAG_LOGIN_TRANSIT;
1037*4882a593Smuzhiyun login_rsp->flags &= ~ISCSI_FLAG_LOGIN_NEXT_STAGE_MASK;
1038*4882a593Smuzhiyun }
1039*4882a593Smuzhiyun break;
1040*4882a593Smuzhiyun }
1041*4882a593Smuzhiyun
1042*4882a593Smuzhiyun return 0;
1043*4882a593Smuzhiyun }
1044*4882a593Smuzhiyun
iscsi_initiatorname_tolower(char * param_buf)1045*4882a593Smuzhiyun static void iscsi_initiatorname_tolower(
1046*4882a593Smuzhiyun char *param_buf)
1047*4882a593Smuzhiyun {
1048*4882a593Smuzhiyun char *c;
1049*4882a593Smuzhiyun u32 iqn_size = strlen(param_buf), i;
1050*4882a593Smuzhiyun
1051*4882a593Smuzhiyun for (i = 0; i < iqn_size; i++) {
1052*4882a593Smuzhiyun c = ¶m_buf[i];
1053*4882a593Smuzhiyun if (!isupper(*c))
1054*4882a593Smuzhiyun continue;
1055*4882a593Smuzhiyun
1056*4882a593Smuzhiyun *c = tolower(*c);
1057*4882a593Smuzhiyun }
1058*4882a593Smuzhiyun }
1059*4882a593Smuzhiyun
1060*4882a593Smuzhiyun /*
1061*4882a593Smuzhiyun * Processes the first Login Request..
1062*4882a593Smuzhiyun */
iscsi_target_locate_portal(struct iscsi_np * np,struct iscsi_conn * conn,struct iscsi_login * login)1063*4882a593Smuzhiyun int iscsi_target_locate_portal(
1064*4882a593Smuzhiyun struct iscsi_np *np,
1065*4882a593Smuzhiyun struct iscsi_conn *conn,
1066*4882a593Smuzhiyun struct iscsi_login *login)
1067*4882a593Smuzhiyun {
1068*4882a593Smuzhiyun char *i_buf = NULL, *s_buf = NULL, *t_buf = NULL;
1069*4882a593Smuzhiyun char *tmpbuf, *start = NULL, *end = NULL, *key, *value;
1070*4882a593Smuzhiyun struct iscsi_session *sess = conn->sess;
1071*4882a593Smuzhiyun struct iscsi_tiqn *tiqn;
1072*4882a593Smuzhiyun struct iscsi_tpg_np *tpg_np = NULL;
1073*4882a593Smuzhiyun struct iscsi_login_req *login_req;
1074*4882a593Smuzhiyun struct se_node_acl *se_nacl;
1075*4882a593Smuzhiyun u32 payload_length, queue_depth = 0;
1076*4882a593Smuzhiyun int sessiontype = 0, ret = 0, tag_num, tag_size;
1077*4882a593Smuzhiyun
1078*4882a593Smuzhiyun INIT_DELAYED_WORK(&conn->login_work, iscsi_target_do_login_rx);
1079*4882a593Smuzhiyun iscsi_target_set_sock_callbacks(conn);
1080*4882a593Smuzhiyun
1081*4882a593Smuzhiyun login->np = np;
1082*4882a593Smuzhiyun
1083*4882a593Smuzhiyun login_req = (struct iscsi_login_req *) login->req;
1084*4882a593Smuzhiyun payload_length = ntoh24(login_req->dlength);
1085*4882a593Smuzhiyun
1086*4882a593Smuzhiyun tmpbuf = kzalloc(payload_length + 1, GFP_KERNEL);
1087*4882a593Smuzhiyun if (!tmpbuf) {
1088*4882a593Smuzhiyun pr_err("Unable to allocate memory for tmpbuf.\n");
1089*4882a593Smuzhiyun return -1;
1090*4882a593Smuzhiyun }
1091*4882a593Smuzhiyun
1092*4882a593Smuzhiyun memcpy(tmpbuf, login->req_buf, payload_length);
1093*4882a593Smuzhiyun tmpbuf[payload_length] = '\0';
1094*4882a593Smuzhiyun start = tmpbuf;
1095*4882a593Smuzhiyun end = (start + payload_length);
1096*4882a593Smuzhiyun
1097*4882a593Smuzhiyun /*
1098*4882a593Smuzhiyun * Locate the initial keys expected from the Initiator node in
1099*4882a593Smuzhiyun * the first login request in order to progress with the login phase.
1100*4882a593Smuzhiyun */
1101*4882a593Smuzhiyun while (start < end) {
1102*4882a593Smuzhiyun if (iscsi_extract_key_value(start, &key, &value) < 0) {
1103*4882a593Smuzhiyun ret = -1;
1104*4882a593Smuzhiyun goto out;
1105*4882a593Smuzhiyun }
1106*4882a593Smuzhiyun
1107*4882a593Smuzhiyun if (!strncmp(key, "InitiatorName", 13))
1108*4882a593Smuzhiyun i_buf = value;
1109*4882a593Smuzhiyun else if (!strncmp(key, "SessionType", 11))
1110*4882a593Smuzhiyun s_buf = value;
1111*4882a593Smuzhiyun else if (!strncmp(key, "TargetName", 10))
1112*4882a593Smuzhiyun t_buf = value;
1113*4882a593Smuzhiyun
1114*4882a593Smuzhiyun start += strlen(key) + strlen(value) + 2;
1115*4882a593Smuzhiyun }
1116*4882a593Smuzhiyun /*
1117*4882a593Smuzhiyun * See 5.3. Login Phase.
1118*4882a593Smuzhiyun */
1119*4882a593Smuzhiyun if (!i_buf) {
1120*4882a593Smuzhiyun pr_err("InitiatorName key not received"
1121*4882a593Smuzhiyun " in first login request.\n");
1122*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
1123*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_MISSING_FIELDS);
1124*4882a593Smuzhiyun ret = -1;
1125*4882a593Smuzhiyun goto out;
1126*4882a593Smuzhiyun }
1127*4882a593Smuzhiyun /*
1128*4882a593Smuzhiyun * Convert the incoming InitiatorName to lowercase following
1129*4882a593Smuzhiyun * RFC-3720 3.2.6.1. section c) that says that iSCSI IQNs
1130*4882a593Smuzhiyun * are NOT case sensitive.
1131*4882a593Smuzhiyun */
1132*4882a593Smuzhiyun iscsi_initiatorname_tolower(i_buf);
1133*4882a593Smuzhiyun
1134*4882a593Smuzhiyun if (!s_buf) {
1135*4882a593Smuzhiyun if (!login->leading_connection)
1136*4882a593Smuzhiyun goto get_target;
1137*4882a593Smuzhiyun
1138*4882a593Smuzhiyun pr_err("SessionType key not received"
1139*4882a593Smuzhiyun " in first login request.\n");
1140*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
1141*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_MISSING_FIELDS);
1142*4882a593Smuzhiyun ret = -1;
1143*4882a593Smuzhiyun goto out;
1144*4882a593Smuzhiyun }
1145*4882a593Smuzhiyun
1146*4882a593Smuzhiyun /*
1147*4882a593Smuzhiyun * Use default portal group for discovery sessions.
1148*4882a593Smuzhiyun */
1149*4882a593Smuzhiyun sessiontype = strncmp(s_buf, DISCOVERY, 9);
1150*4882a593Smuzhiyun if (!sessiontype) {
1151*4882a593Smuzhiyun conn->tpg = iscsit_global->discovery_tpg;
1152*4882a593Smuzhiyun if (!login->leading_connection)
1153*4882a593Smuzhiyun goto get_target;
1154*4882a593Smuzhiyun
1155*4882a593Smuzhiyun sess->sess_ops->SessionType = 1;
1156*4882a593Smuzhiyun /*
1157*4882a593Smuzhiyun * Setup crc32c modules from libcrypto
1158*4882a593Smuzhiyun */
1159*4882a593Smuzhiyun if (iscsi_login_setup_crypto(conn) < 0) {
1160*4882a593Smuzhiyun pr_err("iscsi_login_setup_crypto() failed\n");
1161*4882a593Smuzhiyun ret = -1;
1162*4882a593Smuzhiyun goto out;
1163*4882a593Smuzhiyun }
1164*4882a593Smuzhiyun /*
1165*4882a593Smuzhiyun * Serialize access across the discovery struct iscsi_portal_group to
1166*4882a593Smuzhiyun * process login attempt.
1167*4882a593Smuzhiyun */
1168*4882a593Smuzhiyun if (iscsit_access_np(np, conn->tpg) < 0) {
1169*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
1170*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_SVC_UNAVAILABLE);
1171*4882a593Smuzhiyun ret = -1;
1172*4882a593Smuzhiyun goto out;
1173*4882a593Smuzhiyun }
1174*4882a593Smuzhiyun ret = 0;
1175*4882a593Smuzhiyun goto alloc_tags;
1176*4882a593Smuzhiyun }
1177*4882a593Smuzhiyun
1178*4882a593Smuzhiyun get_target:
1179*4882a593Smuzhiyun if (!t_buf) {
1180*4882a593Smuzhiyun pr_err("TargetName key not received"
1181*4882a593Smuzhiyun " in first login request while"
1182*4882a593Smuzhiyun " SessionType=Normal.\n");
1183*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
1184*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_MISSING_FIELDS);
1185*4882a593Smuzhiyun ret = -1;
1186*4882a593Smuzhiyun goto out;
1187*4882a593Smuzhiyun }
1188*4882a593Smuzhiyun
1189*4882a593Smuzhiyun /*
1190*4882a593Smuzhiyun * Locate Target IQN from Storage Node.
1191*4882a593Smuzhiyun */
1192*4882a593Smuzhiyun tiqn = iscsit_get_tiqn_for_login(t_buf);
1193*4882a593Smuzhiyun if (!tiqn) {
1194*4882a593Smuzhiyun pr_err("Unable to locate Target IQN: %s in"
1195*4882a593Smuzhiyun " Storage Node\n", t_buf);
1196*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
1197*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_SVC_UNAVAILABLE);
1198*4882a593Smuzhiyun ret = -1;
1199*4882a593Smuzhiyun goto out;
1200*4882a593Smuzhiyun }
1201*4882a593Smuzhiyun pr_debug("Located Storage Object: %s\n", tiqn->tiqn);
1202*4882a593Smuzhiyun
1203*4882a593Smuzhiyun /*
1204*4882a593Smuzhiyun * Locate Target Portal Group from Storage Node.
1205*4882a593Smuzhiyun */
1206*4882a593Smuzhiyun conn->tpg = iscsit_get_tpg_from_np(tiqn, np, &tpg_np);
1207*4882a593Smuzhiyun if (!conn->tpg) {
1208*4882a593Smuzhiyun pr_err("Unable to locate Target Portal Group"
1209*4882a593Smuzhiyun " on %s\n", tiqn->tiqn);
1210*4882a593Smuzhiyun iscsit_put_tiqn_for_login(tiqn);
1211*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
1212*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_SVC_UNAVAILABLE);
1213*4882a593Smuzhiyun ret = -1;
1214*4882a593Smuzhiyun goto out;
1215*4882a593Smuzhiyun }
1216*4882a593Smuzhiyun conn->tpg_np = tpg_np;
1217*4882a593Smuzhiyun pr_debug("Located Portal Group Object: %hu\n", conn->tpg->tpgt);
1218*4882a593Smuzhiyun /*
1219*4882a593Smuzhiyun * Setup crc32c modules from libcrypto
1220*4882a593Smuzhiyun */
1221*4882a593Smuzhiyun if (iscsi_login_setup_crypto(conn) < 0) {
1222*4882a593Smuzhiyun pr_err("iscsi_login_setup_crypto() failed\n");
1223*4882a593Smuzhiyun kref_put(&tpg_np->tpg_np_kref, iscsit_login_kref_put);
1224*4882a593Smuzhiyun iscsit_put_tiqn_for_login(tiqn);
1225*4882a593Smuzhiyun conn->tpg = NULL;
1226*4882a593Smuzhiyun ret = -1;
1227*4882a593Smuzhiyun goto out;
1228*4882a593Smuzhiyun }
1229*4882a593Smuzhiyun /*
1230*4882a593Smuzhiyun * Serialize access across the struct iscsi_portal_group to
1231*4882a593Smuzhiyun * process login attempt.
1232*4882a593Smuzhiyun */
1233*4882a593Smuzhiyun if (iscsit_access_np(np, conn->tpg) < 0) {
1234*4882a593Smuzhiyun kref_put(&tpg_np->tpg_np_kref, iscsit_login_kref_put);
1235*4882a593Smuzhiyun iscsit_put_tiqn_for_login(tiqn);
1236*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
1237*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_SVC_UNAVAILABLE);
1238*4882a593Smuzhiyun conn->tpg = NULL;
1239*4882a593Smuzhiyun ret = -1;
1240*4882a593Smuzhiyun goto out;
1241*4882a593Smuzhiyun }
1242*4882a593Smuzhiyun
1243*4882a593Smuzhiyun /*
1244*4882a593Smuzhiyun * conn->sess->node_acl will be set when the referenced
1245*4882a593Smuzhiyun * struct iscsi_session is located from received ISID+TSIH in
1246*4882a593Smuzhiyun * iscsi_login_non_zero_tsih_s2().
1247*4882a593Smuzhiyun */
1248*4882a593Smuzhiyun if (!login->leading_connection) {
1249*4882a593Smuzhiyun ret = 0;
1250*4882a593Smuzhiyun goto out;
1251*4882a593Smuzhiyun }
1252*4882a593Smuzhiyun
1253*4882a593Smuzhiyun /*
1254*4882a593Smuzhiyun * This value is required in iscsi_login_zero_tsih_s2()
1255*4882a593Smuzhiyun */
1256*4882a593Smuzhiyun sess->sess_ops->SessionType = 0;
1257*4882a593Smuzhiyun
1258*4882a593Smuzhiyun /*
1259*4882a593Smuzhiyun * Locate incoming Initiator IQN reference from Storage Node.
1260*4882a593Smuzhiyun */
1261*4882a593Smuzhiyun sess->se_sess->se_node_acl = core_tpg_check_initiator_node_acl(
1262*4882a593Smuzhiyun &conn->tpg->tpg_se_tpg, i_buf);
1263*4882a593Smuzhiyun if (!sess->se_sess->se_node_acl) {
1264*4882a593Smuzhiyun pr_err("iSCSI Initiator Node: %s is not authorized to"
1265*4882a593Smuzhiyun " access iSCSI target portal group: %hu.\n",
1266*4882a593Smuzhiyun i_buf, conn->tpg->tpgt);
1267*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_INITIATOR_ERR,
1268*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_TGT_FORBIDDEN);
1269*4882a593Smuzhiyun ret = -1;
1270*4882a593Smuzhiyun goto out;
1271*4882a593Smuzhiyun }
1272*4882a593Smuzhiyun se_nacl = sess->se_sess->se_node_acl;
1273*4882a593Smuzhiyun queue_depth = se_nacl->queue_depth;
1274*4882a593Smuzhiyun /*
1275*4882a593Smuzhiyun * Setup pre-allocated tags based upon allowed per NodeACL CmdSN
1276*4882a593Smuzhiyun * depth for non immediate commands, plus extra tags for immediate
1277*4882a593Smuzhiyun * commands.
1278*4882a593Smuzhiyun *
1279*4882a593Smuzhiyun * Also enforce a ISCSIT_MIN_TAGS to prevent unnecessary contention
1280*4882a593Smuzhiyun * in per-cpu-ida tag allocation logic + small queue_depth.
1281*4882a593Smuzhiyun */
1282*4882a593Smuzhiyun alloc_tags:
1283*4882a593Smuzhiyun tag_num = max_t(u32, ISCSIT_MIN_TAGS, queue_depth);
1284*4882a593Smuzhiyun tag_num = (tag_num * 2) + ISCSIT_EXTRA_TAGS;
1285*4882a593Smuzhiyun tag_size = sizeof(struct iscsi_cmd) + conn->conn_transport->priv_size;
1286*4882a593Smuzhiyun
1287*4882a593Smuzhiyun ret = transport_alloc_session_tags(sess->se_sess, tag_num, tag_size);
1288*4882a593Smuzhiyun if (ret < 0) {
1289*4882a593Smuzhiyun iscsit_tx_login_rsp(conn, ISCSI_STATUS_CLS_TARGET_ERR,
1290*4882a593Smuzhiyun ISCSI_LOGIN_STATUS_NO_RESOURCES);
1291*4882a593Smuzhiyun ret = -1;
1292*4882a593Smuzhiyun }
1293*4882a593Smuzhiyun out:
1294*4882a593Smuzhiyun kfree(tmpbuf);
1295*4882a593Smuzhiyun return ret;
1296*4882a593Smuzhiyun }
1297*4882a593Smuzhiyun
iscsi_target_start_negotiation(struct iscsi_login * login,struct iscsi_conn * conn)1298*4882a593Smuzhiyun int iscsi_target_start_negotiation(
1299*4882a593Smuzhiyun struct iscsi_login *login,
1300*4882a593Smuzhiyun struct iscsi_conn *conn)
1301*4882a593Smuzhiyun {
1302*4882a593Smuzhiyun int ret;
1303*4882a593Smuzhiyun
1304*4882a593Smuzhiyun if (conn->sock) {
1305*4882a593Smuzhiyun struct sock *sk = conn->sock->sk;
1306*4882a593Smuzhiyun
1307*4882a593Smuzhiyun write_lock_bh(&sk->sk_callback_lock);
1308*4882a593Smuzhiyun set_bit(LOGIN_FLAGS_READY, &conn->login_flags);
1309*4882a593Smuzhiyun set_bit(LOGIN_FLAGS_INITIAL_PDU, &conn->login_flags);
1310*4882a593Smuzhiyun write_unlock_bh(&sk->sk_callback_lock);
1311*4882a593Smuzhiyun }
1312*4882a593Smuzhiyun /*
1313*4882a593Smuzhiyun * If iscsi_target_do_login returns zero to signal more PDU
1314*4882a593Smuzhiyun * exchanges are required to complete the login, go ahead and
1315*4882a593Smuzhiyun * clear LOGIN_FLAGS_INITIAL_PDU but only if the TCP connection
1316*4882a593Smuzhiyun * is still active.
1317*4882a593Smuzhiyun *
1318*4882a593Smuzhiyun * Otherwise if TCP connection dropped asynchronously, go ahead
1319*4882a593Smuzhiyun * and perform connection cleanup now.
1320*4882a593Smuzhiyun */
1321*4882a593Smuzhiyun ret = iscsi_target_do_login(conn, login);
1322*4882a593Smuzhiyun if (!ret && iscsi_target_sk_check_and_clear(conn, LOGIN_FLAGS_INITIAL_PDU))
1323*4882a593Smuzhiyun ret = -1;
1324*4882a593Smuzhiyun
1325*4882a593Smuzhiyun if (ret < 0) {
1326*4882a593Smuzhiyun cancel_delayed_work_sync(&conn->login_work);
1327*4882a593Smuzhiyun iscsi_target_restore_sock_callbacks(conn);
1328*4882a593Smuzhiyun iscsi_remove_failed_auth_entry(conn);
1329*4882a593Smuzhiyun }
1330*4882a593Smuzhiyun if (ret != 0)
1331*4882a593Smuzhiyun iscsi_target_nego_release(conn);
1332*4882a593Smuzhiyun
1333*4882a593Smuzhiyun return ret;
1334*4882a593Smuzhiyun }
1335*4882a593Smuzhiyun
iscsi_target_nego_release(struct iscsi_conn * conn)1336*4882a593Smuzhiyun void iscsi_target_nego_release(struct iscsi_conn *conn)
1337*4882a593Smuzhiyun {
1338*4882a593Smuzhiyun struct iscsi_login *login = conn->conn_login;
1339*4882a593Smuzhiyun
1340*4882a593Smuzhiyun if (!login)
1341*4882a593Smuzhiyun return;
1342*4882a593Smuzhiyun
1343*4882a593Smuzhiyun kfree(login->req_buf);
1344*4882a593Smuzhiyun kfree(login->rsp_buf);
1345*4882a593Smuzhiyun kfree(login);
1346*4882a593Smuzhiyun
1347*4882a593Smuzhiyun conn->conn_login = NULL;
1348*4882a593Smuzhiyun }
1349