Back to home page

OSCL-LXR

 
 

    


0001 // SPDX-License-Identifier: GPL-2.0-or-later
0002 /*
0003  * SBP2 target driver (SCSI over IEEE1394 in target mode)
0004  *
0005  * Copyright (C) 2011  Chris Boot <bootc@bootc.net>
0006  */
0007 
0008 #define KMSG_COMPONENT "sbp_target"
0009 #define pr_fmt(fmt) KMSG_COMPONENT ": " fmt
0010 
0011 #include <linux/kernel.h>
0012 #include <linux/module.h>
0013 #include <linux/init.h>
0014 #include <linux/types.h>
0015 #include <linux/string.h>
0016 #include <linux/configfs.h>
0017 #include <linux/ctype.h>
0018 #include <linux/delay.h>
0019 #include <linux/firewire.h>
0020 #include <linux/firewire-constants.h>
0021 #include <scsi/scsi_proto.h>
0022 #include <scsi/scsi_tcq.h>
0023 #include <target/target_core_base.h>
0024 #include <target/target_core_backend.h>
0025 #include <target/target_core_fabric.h>
0026 #include <asm/unaligned.h>
0027 
0028 #include "sbp_target.h"
0029 
0030 /* FireWire address region for management and command block address handlers */
0031 static const struct fw_address_region sbp_register_region = {
0032     .start  = CSR_REGISTER_BASE + 0x10000,
0033     .end    = 0x1000000000000ULL,
0034 };
0035 
0036 static const u32 sbp_unit_directory_template[] = {
0037     0x1200609e, /* unit_specifier_id: NCITS/T10 */
0038     0x13010483, /* unit_sw_version: 1155D Rev 4 */
0039     0x3800609e, /* command_set_specifier_id: NCITS/T10 */
0040     0x390104d8, /* command_set: SPC-2 */
0041     0x3b000000, /* command_set_revision: 0 */
0042     0x3c000001, /* firmware_revision: 1 */
0043 };
0044 
0045 #define SESSION_MAINTENANCE_INTERVAL HZ
0046 
0047 static atomic_t login_id = ATOMIC_INIT(0);
0048 
0049 static void session_maintenance_work(struct work_struct *);
0050 static int sbp_run_transaction(struct fw_card *, int, int, int, int,
0051         unsigned long long, void *, size_t);
0052 
0053 static int read_peer_guid(u64 *guid, const struct sbp_management_request *req)
0054 {
0055     int ret;
0056     __be32 high, low;
0057 
0058     ret = sbp_run_transaction(req->card, TCODE_READ_QUADLET_REQUEST,
0059             req->node_addr, req->generation, req->speed,
0060             (CSR_REGISTER_BASE | CSR_CONFIG_ROM) + 3 * 4,
0061             &high, sizeof(high));
0062     if (ret != RCODE_COMPLETE)
0063         return ret;
0064 
0065     ret = sbp_run_transaction(req->card, TCODE_READ_QUADLET_REQUEST,
0066             req->node_addr, req->generation, req->speed,
0067             (CSR_REGISTER_BASE | CSR_CONFIG_ROM) + 4 * 4,
0068             &low, sizeof(low));
0069     if (ret != RCODE_COMPLETE)
0070         return ret;
0071 
0072     *guid = (u64)be32_to_cpu(high) << 32 | be32_to_cpu(low);
0073 
0074     return RCODE_COMPLETE;
0075 }
0076 
0077 static struct sbp_session *sbp_session_find_by_guid(
0078     struct sbp_tpg *tpg, u64 guid)
0079 {
0080     struct se_session *se_sess;
0081     struct sbp_session *sess, *found = NULL;
0082 
0083     spin_lock_bh(&tpg->se_tpg.session_lock);
0084     list_for_each_entry(se_sess, &tpg->se_tpg.tpg_sess_list, sess_list) {
0085         sess = se_sess->fabric_sess_ptr;
0086         if (sess->guid == guid)
0087             found = sess;
0088     }
0089     spin_unlock_bh(&tpg->se_tpg.session_lock);
0090 
0091     return found;
0092 }
0093 
0094 static struct sbp_login_descriptor *sbp_login_find_by_lun(
0095         struct sbp_session *session, u32 unpacked_lun)
0096 {
0097     struct sbp_login_descriptor *login, *found = NULL;
0098 
0099     spin_lock_bh(&session->lock);
0100     list_for_each_entry(login, &session->login_list, link) {
0101         if (login->login_lun == unpacked_lun)
0102             found = login;
0103     }
0104     spin_unlock_bh(&session->lock);
0105 
0106     return found;
0107 }
0108 
0109 static int sbp_login_count_all_by_lun(
0110         struct sbp_tpg *tpg,
0111         u32 unpacked_lun,
0112         int exclusive)
0113 {
0114     struct se_session *se_sess;
0115     struct sbp_session *sess;
0116     struct sbp_login_descriptor *login;
0117     int count = 0;
0118 
0119     spin_lock_bh(&tpg->se_tpg.session_lock);
0120     list_for_each_entry(se_sess, &tpg->se_tpg.tpg_sess_list, sess_list) {
0121         sess = se_sess->fabric_sess_ptr;
0122 
0123         spin_lock_bh(&sess->lock);
0124         list_for_each_entry(login, &sess->login_list, link) {
0125             if (login->login_lun != unpacked_lun)
0126                 continue;
0127 
0128             if (!exclusive || login->exclusive)
0129                 count++;
0130         }
0131         spin_unlock_bh(&sess->lock);
0132     }
0133     spin_unlock_bh(&tpg->se_tpg.session_lock);
0134 
0135     return count;
0136 }
0137 
0138 static struct sbp_login_descriptor *sbp_login_find_by_id(
0139     struct sbp_tpg *tpg, int login_id)
0140 {
0141     struct se_session *se_sess;
0142     struct sbp_session *sess;
0143     struct sbp_login_descriptor *login, *found = NULL;
0144 
0145     spin_lock_bh(&tpg->se_tpg.session_lock);
0146     list_for_each_entry(se_sess, &tpg->se_tpg.tpg_sess_list, sess_list) {
0147         sess = se_sess->fabric_sess_ptr;
0148 
0149         spin_lock_bh(&sess->lock);
0150         list_for_each_entry(login, &sess->login_list, link) {
0151             if (login->login_id == login_id)
0152                 found = login;
0153         }
0154         spin_unlock_bh(&sess->lock);
0155     }
0156     spin_unlock_bh(&tpg->se_tpg.session_lock);
0157 
0158     return found;
0159 }
0160 
0161 static u32 sbp_get_lun_from_tpg(struct sbp_tpg *tpg, u32 login_lun, int *err)
0162 {
0163     struct se_portal_group *se_tpg = &tpg->se_tpg;
0164     struct se_lun *se_lun;
0165 
0166     rcu_read_lock();
0167     hlist_for_each_entry_rcu(se_lun, &se_tpg->tpg_lun_hlist, link) {
0168         if (se_lun->unpacked_lun == login_lun) {
0169             rcu_read_unlock();
0170             *err = 0;
0171             return login_lun;
0172         }
0173     }
0174     rcu_read_unlock();
0175 
0176     *err = -ENODEV;
0177     return login_lun;
0178 }
0179 
0180 static struct sbp_session *sbp_session_create(
0181         struct sbp_tpg *tpg,
0182         u64 guid)
0183 {
0184     struct sbp_session *sess;
0185     int ret;
0186     char guid_str[17];
0187 
0188     snprintf(guid_str, sizeof(guid_str), "%016llx", guid);
0189 
0190     sess = kmalloc(sizeof(*sess), GFP_KERNEL);
0191     if (!sess)
0192         return ERR_PTR(-ENOMEM);
0193 
0194     spin_lock_init(&sess->lock);
0195     INIT_LIST_HEAD(&sess->login_list);
0196     INIT_DELAYED_WORK(&sess->maint_work, session_maintenance_work);
0197     sess->guid = guid;
0198 
0199     sess->se_sess = target_setup_session(&tpg->se_tpg, 128,
0200                          sizeof(struct sbp_target_request),
0201                          TARGET_PROT_NORMAL, guid_str,
0202                          sess, NULL);
0203     if (IS_ERR(sess->se_sess)) {
0204         pr_err("failed to init se_session\n");
0205         ret = PTR_ERR(sess->se_sess);
0206         kfree(sess);
0207         return ERR_PTR(ret);
0208     }
0209 
0210     return sess;
0211 }
0212 
0213 static void sbp_session_release(struct sbp_session *sess, bool cancel_work)
0214 {
0215     spin_lock_bh(&sess->lock);
0216     if (!list_empty(&sess->login_list)) {
0217         spin_unlock_bh(&sess->lock);
0218         return;
0219     }
0220     spin_unlock_bh(&sess->lock);
0221 
0222     if (cancel_work)
0223         cancel_delayed_work_sync(&sess->maint_work);
0224 
0225     target_remove_session(sess->se_sess);
0226 
0227     if (sess->card)
0228         fw_card_put(sess->card);
0229 
0230     kfree(sess);
0231 }
0232 
0233 static void sbp_target_agent_unregister(struct sbp_target_agent *);
0234 
0235 static void sbp_login_release(struct sbp_login_descriptor *login,
0236     bool cancel_work)
0237 {
0238     struct sbp_session *sess = login->sess;
0239 
0240     /* FIXME: abort/wait on tasks */
0241 
0242     sbp_target_agent_unregister(login->tgt_agt);
0243 
0244     if (sess) {
0245         spin_lock_bh(&sess->lock);
0246         list_del(&login->link);
0247         spin_unlock_bh(&sess->lock);
0248 
0249         sbp_session_release(sess, cancel_work);
0250     }
0251 
0252     kfree(login);
0253 }
0254 
0255 static struct sbp_target_agent *sbp_target_agent_register(
0256     struct sbp_login_descriptor *);
0257 
0258 static void sbp_management_request_login(
0259     struct sbp_management_agent *agent, struct sbp_management_request *req,
0260     int *status_data_size)
0261 {
0262     struct sbp_tport *tport = agent->tport;
0263     struct sbp_tpg *tpg = tport->tpg;
0264     struct sbp_session *sess;
0265     struct sbp_login_descriptor *login;
0266     struct sbp_login_response_block *response;
0267     u64 guid;
0268     u32 unpacked_lun;
0269     int login_response_len, ret;
0270 
0271     unpacked_lun = sbp_get_lun_from_tpg(tpg,
0272             LOGIN_ORB_LUN(be32_to_cpu(req->orb.misc)), &ret);
0273     if (ret) {
0274         pr_notice("login to unknown LUN: %d\n",
0275             LOGIN_ORB_LUN(be32_to_cpu(req->orb.misc)));
0276 
0277         req->status.status = cpu_to_be32(
0278             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0279             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_LUN_NOTSUPP));
0280         return;
0281     }
0282 
0283     ret = read_peer_guid(&guid, req);
0284     if (ret != RCODE_COMPLETE) {
0285         pr_warn("failed to read peer GUID: %d\n", ret);
0286 
0287         req->status.status = cpu_to_be32(
0288             STATUS_BLOCK_RESP(STATUS_RESP_TRANSPORT_FAILURE) |
0289             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_UNSPECIFIED_ERROR));
0290         return;
0291     }
0292 
0293     pr_notice("mgt_agent LOGIN to LUN %d from %016llx\n",
0294         unpacked_lun, guid);
0295 
0296     sess = sbp_session_find_by_guid(tpg, guid);
0297     if (sess) {
0298         login = sbp_login_find_by_lun(sess, unpacked_lun);
0299         if (login) {
0300             pr_notice("initiator already logged-in\n");
0301 
0302             /*
0303              * SBP-2 R4 says we should return access denied, but
0304              * that can confuse initiators. Instead we need to
0305              * treat this like a reconnect, but send the login
0306              * response block like a fresh login.
0307              *
0308              * This is required particularly in the case of Apple
0309              * devices booting off the FireWire target, where
0310              * the firmware has an active login to the target. When
0311              * the OS takes control of the session it issues its own
0312              * LOGIN rather than a RECONNECT. To avoid the machine
0313              * waiting until the reconnect_hold expires, we can skip
0314              * the ACCESS_DENIED errors to speed things up.
0315              */
0316 
0317             goto already_logged_in;
0318         }
0319     }
0320 
0321     /*
0322      * check exclusive bit in login request
0323      * reject with access_denied if any logins present
0324      */
0325     if (LOGIN_ORB_EXCLUSIVE(be32_to_cpu(req->orb.misc)) &&
0326             sbp_login_count_all_by_lun(tpg, unpacked_lun, 0)) {
0327         pr_warn("refusing exclusive login with other active logins\n");
0328 
0329         req->status.status = cpu_to_be32(
0330             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0331             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_ACCESS_DENIED));
0332         return;
0333     }
0334 
0335     /*
0336      * check exclusive bit in any existing login descriptor
0337      * reject with access_denied if any exclusive logins present
0338      */
0339     if (sbp_login_count_all_by_lun(tpg, unpacked_lun, 1)) {
0340         pr_warn("refusing login while another exclusive login present\n");
0341 
0342         req->status.status = cpu_to_be32(
0343             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0344             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_ACCESS_DENIED));
0345         return;
0346     }
0347 
0348     /*
0349      * check we haven't exceeded the number of allowed logins
0350      * reject with resources_unavailable if we have
0351      */
0352     if (sbp_login_count_all_by_lun(tpg, unpacked_lun, 0) >=
0353             tport->max_logins_per_lun) {
0354         pr_warn("max number of logins reached\n");
0355 
0356         req->status.status = cpu_to_be32(
0357             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0358             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_RESOURCES_UNAVAIL));
0359         return;
0360     }
0361 
0362     if (!sess) {
0363         sess = sbp_session_create(tpg, guid);
0364         if (IS_ERR(sess)) {
0365             switch (PTR_ERR(sess)) {
0366             case -EPERM:
0367                 ret = SBP_STATUS_ACCESS_DENIED;
0368                 break;
0369             default:
0370                 ret = SBP_STATUS_RESOURCES_UNAVAIL;
0371                 break;
0372             }
0373 
0374             req->status.status = cpu_to_be32(
0375                 STATUS_BLOCK_RESP(
0376                     STATUS_RESP_REQUEST_COMPLETE) |
0377                 STATUS_BLOCK_SBP_STATUS(ret));
0378             return;
0379         }
0380 
0381         sess->node_id = req->node_addr;
0382         sess->card = fw_card_get(req->card);
0383         sess->generation = req->generation;
0384         sess->speed = req->speed;
0385 
0386         schedule_delayed_work(&sess->maint_work,
0387                 SESSION_MAINTENANCE_INTERVAL);
0388     }
0389 
0390     /* only take the latest reconnect_hold into account */
0391     sess->reconnect_hold = min(
0392         1 << LOGIN_ORB_RECONNECT(be32_to_cpu(req->orb.misc)),
0393         tport->max_reconnect_timeout) - 1;
0394 
0395     login = kmalloc(sizeof(*login), GFP_KERNEL);
0396     if (!login) {
0397         pr_err("failed to allocate login descriptor\n");
0398 
0399         sbp_session_release(sess, true);
0400 
0401         req->status.status = cpu_to_be32(
0402             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0403             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_RESOURCES_UNAVAIL));
0404         return;
0405     }
0406 
0407     login->sess = sess;
0408     login->login_lun = unpacked_lun;
0409     login->status_fifo_addr = sbp2_pointer_to_addr(&req->orb.status_fifo);
0410     login->exclusive = LOGIN_ORB_EXCLUSIVE(be32_to_cpu(req->orb.misc));
0411     login->login_id = atomic_inc_return(&login_id);
0412 
0413     login->tgt_agt = sbp_target_agent_register(login);
0414     if (IS_ERR(login->tgt_agt)) {
0415         ret = PTR_ERR(login->tgt_agt);
0416         pr_err("failed to map command block handler: %d\n", ret);
0417 
0418         sbp_session_release(sess, true);
0419         kfree(login);
0420 
0421         req->status.status = cpu_to_be32(
0422             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0423             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_RESOURCES_UNAVAIL));
0424         return;
0425     }
0426 
0427     spin_lock_bh(&sess->lock);
0428     list_add_tail(&login->link, &sess->login_list);
0429     spin_unlock_bh(&sess->lock);
0430 
0431 already_logged_in:
0432     response = kzalloc(sizeof(*response), GFP_KERNEL);
0433     if (!response) {
0434         pr_err("failed to allocate login response block\n");
0435 
0436         sbp_login_release(login, true);
0437 
0438         req->status.status = cpu_to_be32(
0439             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0440             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_RESOURCES_UNAVAIL));
0441         return;
0442     }
0443 
0444     login_response_len = clamp_val(
0445             LOGIN_ORB_RESPONSE_LENGTH(be32_to_cpu(req->orb.length)),
0446             12, sizeof(*response));
0447     response->misc = cpu_to_be32(
0448         ((login_response_len & 0xffff) << 16) |
0449         (login->login_id & 0xffff));
0450     response->reconnect_hold = cpu_to_be32(sess->reconnect_hold & 0xffff);
0451     addr_to_sbp2_pointer(login->tgt_agt->handler.offset,
0452         &response->command_block_agent);
0453 
0454     ret = sbp_run_transaction(sess->card, TCODE_WRITE_BLOCK_REQUEST,
0455         sess->node_id, sess->generation, sess->speed,
0456         sbp2_pointer_to_addr(&req->orb.ptr2), response,
0457         login_response_len);
0458     if (ret != RCODE_COMPLETE) {
0459         pr_debug("failed to write login response block: %x\n", ret);
0460 
0461         kfree(response);
0462         sbp_login_release(login, true);
0463 
0464         req->status.status = cpu_to_be32(
0465             STATUS_BLOCK_RESP(STATUS_RESP_TRANSPORT_FAILURE) |
0466             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_UNSPECIFIED_ERROR));
0467         return;
0468     }
0469 
0470     kfree(response);
0471 
0472     req->status.status = cpu_to_be32(
0473         STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0474         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_OK));
0475 }
0476 
0477 static void sbp_management_request_query_logins(
0478     struct sbp_management_agent *agent, struct sbp_management_request *req,
0479     int *status_data_size)
0480 {
0481     pr_notice("QUERY LOGINS not implemented\n");
0482     /* FIXME: implement */
0483 
0484     req->status.status = cpu_to_be32(
0485         STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0486         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
0487 }
0488 
0489 static void sbp_management_request_reconnect(
0490     struct sbp_management_agent *agent, struct sbp_management_request *req,
0491     int *status_data_size)
0492 {
0493     struct sbp_tport *tport = agent->tport;
0494     struct sbp_tpg *tpg = tport->tpg;
0495     int ret;
0496     u64 guid;
0497     struct sbp_login_descriptor *login;
0498 
0499     ret = read_peer_guid(&guid, req);
0500     if (ret != RCODE_COMPLETE) {
0501         pr_warn("failed to read peer GUID: %d\n", ret);
0502 
0503         req->status.status = cpu_to_be32(
0504             STATUS_BLOCK_RESP(STATUS_RESP_TRANSPORT_FAILURE) |
0505             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_UNSPECIFIED_ERROR));
0506         return;
0507     }
0508 
0509     pr_notice("mgt_agent RECONNECT from %016llx\n", guid);
0510 
0511     login = sbp_login_find_by_id(tpg,
0512         RECONNECT_ORB_LOGIN_ID(be32_to_cpu(req->orb.misc)));
0513 
0514     if (!login) {
0515         pr_err("mgt_agent RECONNECT unknown login ID\n");
0516 
0517         req->status.status = cpu_to_be32(
0518             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0519             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_ACCESS_DENIED));
0520         return;
0521     }
0522 
0523     if (login->sess->guid != guid) {
0524         pr_err("mgt_agent RECONNECT login GUID doesn't match\n");
0525 
0526         req->status.status = cpu_to_be32(
0527             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0528             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_ACCESS_DENIED));
0529         return;
0530     }
0531 
0532     spin_lock_bh(&login->sess->lock);
0533     if (login->sess->card)
0534         fw_card_put(login->sess->card);
0535 
0536     /* update the node details */
0537     login->sess->generation = req->generation;
0538     login->sess->node_id = req->node_addr;
0539     login->sess->card = fw_card_get(req->card);
0540     login->sess->speed = req->speed;
0541     spin_unlock_bh(&login->sess->lock);
0542 
0543     req->status.status = cpu_to_be32(
0544         STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0545         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_OK));
0546 }
0547 
0548 static void sbp_management_request_logout(
0549     struct sbp_management_agent *agent, struct sbp_management_request *req,
0550     int *status_data_size)
0551 {
0552     struct sbp_tport *tport = agent->tport;
0553     struct sbp_tpg *tpg = tport->tpg;
0554     int id;
0555     struct sbp_login_descriptor *login;
0556 
0557     id = LOGOUT_ORB_LOGIN_ID(be32_to_cpu(req->orb.misc));
0558 
0559     login = sbp_login_find_by_id(tpg, id);
0560     if (!login) {
0561         pr_warn("cannot find login: %d\n", id);
0562 
0563         req->status.status = cpu_to_be32(
0564             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0565             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_LOGIN_ID_UNKNOWN));
0566         return;
0567     }
0568 
0569     pr_info("mgt_agent LOGOUT from LUN %d session %d\n",
0570         login->login_lun, login->login_id);
0571 
0572     if (req->node_addr != login->sess->node_id) {
0573         pr_warn("logout from different node ID\n");
0574 
0575         req->status.status = cpu_to_be32(
0576             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0577             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_ACCESS_DENIED));
0578         return;
0579     }
0580 
0581     sbp_login_release(login, true);
0582 
0583     req->status.status = cpu_to_be32(
0584         STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
0585         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_OK));
0586 }
0587 
0588 static void session_check_for_reset(struct sbp_session *sess)
0589 {
0590     bool card_valid = false;
0591 
0592     spin_lock_bh(&sess->lock);
0593 
0594     if (sess->card) {
0595         spin_lock_irq(&sess->card->lock);
0596         card_valid = (sess->card->local_node != NULL);
0597         spin_unlock_irq(&sess->card->lock);
0598 
0599         if (!card_valid) {
0600             fw_card_put(sess->card);
0601             sess->card = NULL;
0602         }
0603     }
0604 
0605     if (!card_valid || (sess->generation != sess->card->generation)) {
0606         pr_info("Waiting for reconnect from node: %016llx\n",
0607                 sess->guid);
0608 
0609         sess->node_id = -1;
0610         sess->reconnect_expires = get_jiffies_64() +
0611             ((sess->reconnect_hold + 1) * HZ);
0612     }
0613 
0614     spin_unlock_bh(&sess->lock);
0615 }
0616 
0617 static void session_reconnect_expired(struct sbp_session *sess)
0618 {
0619     struct sbp_login_descriptor *login, *temp;
0620     LIST_HEAD(login_list);
0621 
0622     pr_info("Reconnect timer expired for node: %016llx\n", sess->guid);
0623 
0624     spin_lock_bh(&sess->lock);
0625     list_for_each_entry_safe(login, temp, &sess->login_list, link) {
0626         login->sess = NULL;
0627         list_move_tail(&login->link, &login_list);
0628     }
0629     spin_unlock_bh(&sess->lock);
0630 
0631     list_for_each_entry_safe(login, temp, &login_list, link) {
0632         list_del(&login->link);
0633         sbp_login_release(login, false);
0634     }
0635 
0636     sbp_session_release(sess, false);
0637 }
0638 
0639 static void session_maintenance_work(struct work_struct *work)
0640 {
0641     struct sbp_session *sess = container_of(work, struct sbp_session,
0642             maint_work.work);
0643 
0644     /* could be called while tearing down the session */
0645     spin_lock_bh(&sess->lock);
0646     if (list_empty(&sess->login_list)) {
0647         spin_unlock_bh(&sess->lock);
0648         return;
0649     }
0650     spin_unlock_bh(&sess->lock);
0651 
0652     if (sess->node_id != -1) {
0653         /* check for bus reset and make node_id invalid */
0654         session_check_for_reset(sess);
0655 
0656         schedule_delayed_work(&sess->maint_work,
0657                 SESSION_MAINTENANCE_INTERVAL);
0658     } else if (!time_after64(get_jiffies_64(), sess->reconnect_expires)) {
0659         /* still waiting for reconnect */
0660         schedule_delayed_work(&sess->maint_work,
0661                 SESSION_MAINTENANCE_INTERVAL);
0662     } else {
0663         /* reconnect timeout has expired */
0664         session_reconnect_expired(sess);
0665     }
0666 }
0667 
0668 static int tgt_agent_rw_agent_state(struct fw_card *card, int tcode, void *data,
0669         struct sbp_target_agent *agent)
0670 {
0671     int state;
0672 
0673     switch (tcode) {
0674     case TCODE_READ_QUADLET_REQUEST:
0675         pr_debug("tgt_agent AGENT_STATE READ\n");
0676 
0677         spin_lock_bh(&agent->lock);
0678         state = agent->state;
0679         spin_unlock_bh(&agent->lock);
0680 
0681         *(__be32 *)data = cpu_to_be32(state);
0682 
0683         return RCODE_COMPLETE;
0684 
0685     case TCODE_WRITE_QUADLET_REQUEST:
0686         /* ignored */
0687         return RCODE_COMPLETE;
0688 
0689     default:
0690         return RCODE_TYPE_ERROR;
0691     }
0692 }
0693 
0694 static int tgt_agent_rw_agent_reset(struct fw_card *card, int tcode, void *data,
0695         struct sbp_target_agent *agent)
0696 {
0697     switch (tcode) {
0698     case TCODE_WRITE_QUADLET_REQUEST:
0699         pr_debug("tgt_agent AGENT_RESET\n");
0700         spin_lock_bh(&agent->lock);
0701         agent->state = AGENT_STATE_RESET;
0702         spin_unlock_bh(&agent->lock);
0703         return RCODE_COMPLETE;
0704 
0705     default:
0706         return RCODE_TYPE_ERROR;
0707     }
0708 }
0709 
0710 static int tgt_agent_rw_orb_pointer(struct fw_card *card, int tcode, void *data,
0711         struct sbp_target_agent *agent)
0712 {
0713     struct sbp2_pointer *ptr = data;
0714 
0715     switch (tcode) {
0716     case TCODE_WRITE_BLOCK_REQUEST:
0717         spin_lock_bh(&agent->lock);
0718         if (agent->state != AGENT_STATE_SUSPENDED &&
0719                 agent->state != AGENT_STATE_RESET) {
0720             spin_unlock_bh(&agent->lock);
0721             pr_notice("Ignoring ORB_POINTER write while active.\n");
0722             return RCODE_CONFLICT_ERROR;
0723         }
0724         agent->state = AGENT_STATE_ACTIVE;
0725         spin_unlock_bh(&agent->lock);
0726 
0727         agent->orb_pointer = sbp2_pointer_to_addr(ptr);
0728         agent->doorbell = false;
0729 
0730         pr_debug("tgt_agent ORB_POINTER write: 0x%llx\n",
0731                 agent->orb_pointer);
0732 
0733         queue_work(system_unbound_wq, &agent->work);
0734 
0735         return RCODE_COMPLETE;
0736 
0737     case TCODE_READ_BLOCK_REQUEST:
0738         pr_debug("tgt_agent ORB_POINTER READ\n");
0739         spin_lock_bh(&agent->lock);
0740         addr_to_sbp2_pointer(agent->orb_pointer, ptr);
0741         spin_unlock_bh(&agent->lock);
0742         return RCODE_COMPLETE;
0743 
0744     default:
0745         return RCODE_TYPE_ERROR;
0746     }
0747 }
0748 
0749 static int tgt_agent_rw_doorbell(struct fw_card *card, int tcode, void *data,
0750         struct sbp_target_agent *agent)
0751 {
0752     switch (tcode) {
0753     case TCODE_WRITE_QUADLET_REQUEST:
0754         spin_lock_bh(&agent->lock);
0755         if (agent->state != AGENT_STATE_SUSPENDED) {
0756             spin_unlock_bh(&agent->lock);
0757             pr_debug("Ignoring DOORBELL while active.\n");
0758             return RCODE_CONFLICT_ERROR;
0759         }
0760         agent->state = AGENT_STATE_ACTIVE;
0761         spin_unlock_bh(&agent->lock);
0762 
0763         agent->doorbell = true;
0764 
0765         pr_debug("tgt_agent DOORBELL\n");
0766 
0767         queue_work(system_unbound_wq, &agent->work);
0768 
0769         return RCODE_COMPLETE;
0770 
0771     case TCODE_READ_QUADLET_REQUEST:
0772         return RCODE_COMPLETE;
0773 
0774     default:
0775         return RCODE_TYPE_ERROR;
0776     }
0777 }
0778 
0779 static int tgt_agent_rw_unsolicited_status_enable(struct fw_card *card,
0780         int tcode, void *data, struct sbp_target_agent *agent)
0781 {
0782     switch (tcode) {
0783     case TCODE_WRITE_QUADLET_REQUEST:
0784         pr_debug("tgt_agent UNSOLICITED_STATUS_ENABLE\n");
0785         /* ignored as we don't send unsolicited status */
0786         return RCODE_COMPLETE;
0787 
0788     case TCODE_READ_QUADLET_REQUEST:
0789         return RCODE_COMPLETE;
0790 
0791     default:
0792         return RCODE_TYPE_ERROR;
0793     }
0794 }
0795 
0796 static void tgt_agent_rw(struct fw_card *card, struct fw_request *request,
0797         int tcode, int destination, int source, int generation,
0798         unsigned long long offset, void *data, size_t length,
0799         void *callback_data)
0800 {
0801     struct sbp_target_agent *agent = callback_data;
0802     struct sbp_session *sess = agent->login->sess;
0803     int sess_gen, sess_node, rcode;
0804 
0805     spin_lock_bh(&sess->lock);
0806     sess_gen = sess->generation;
0807     sess_node = sess->node_id;
0808     spin_unlock_bh(&sess->lock);
0809 
0810     if (generation != sess_gen) {
0811         pr_notice("ignoring request with wrong generation\n");
0812         rcode = RCODE_TYPE_ERROR;
0813         goto out;
0814     }
0815 
0816     if (source != sess_node) {
0817         pr_notice("ignoring request from foreign node (%x != %x)\n",
0818                 source, sess_node);
0819         rcode = RCODE_TYPE_ERROR;
0820         goto out;
0821     }
0822 
0823     /* turn offset into the offset from the start of the block */
0824     offset -= agent->handler.offset;
0825 
0826     if (offset == 0x00 && length == 4) {
0827         /* AGENT_STATE */
0828         rcode = tgt_agent_rw_agent_state(card, tcode, data, agent);
0829     } else if (offset == 0x04 && length == 4) {
0830         /* AGENT_RESET */
0831         rcode = tgt_agent_rw_agent_reset(card, tcode, data, agent);
0832     } else if (offset == 0x08 && length == 8) {
0833         /* ORB_POINTER */
0834         rcode = tgt_agent_rw_orb_pointer(card, tcode, data, agent);
0835     } else if (offset == 0x10 && length == 4) {
0836         /* DOORBELL */
0837         rcode = tgt_agent_rw_doorbell(card, tcode, data, agent);
0838     } else if (offset == 0x14 && length == 4) {
0839         /* UNSOLICITED_STATUS_ENABLE */
0840         rcode = tgt_agent_rw_unsolicited_status_enable(card, tcode,
0841                 data, agent);
0842     } else {
0843         rcode = RCODE_ADDRESS_ERROR;
0844     }
0845 
0846 out:
0847     fw_send_response(card, request, rcode);
0848 }
0849 
0850 static void sbp_handle_command(struct sbp_target_request *);
0851 static int sbp_send_status(struct sbp_target_request *);
0852 static void sbp_free_request(struct sbp_target_request *);
0853 
0854 static void tgt_agent_process_work(struct work_struct *work)
0855 {
0856     struct sbp_target_request *req =
0857         container_of(work, struct sbp_target_request, work);
0858 
0859     pr_debug("tgt_orb ptr:0x%llx next_ORB:0x%llx data_descriptor:0x%llx misc:0x%x\n",
0860             req->orb_pointer,
0861             sbp2_pointer_to_addr(&req->orb.next_orb),
0862             sbp2_pointer_to_addr(&req->orb.data_descriptor),
0863             be32_to_cpu(req->orb.misc));
0864 
0865     if (req->orb_pointer >> 32)
0866         pr_debug("ORB with high bits set\n");
0867 
0868     switch (ORB_REQUEST_FORMAT(be32_to_cpu(req->orb.misc))) {
0869         case 0:/* Format specified by this standard */
0870             sbp_handle_command(req);
0871             return;
0872         case 1: /* Reserved for future standardization */
0873         case 2: /* Vendor-dependent */
0874             req->status.status |= cpu_to_be32(
0875                     STATUS_BLOCK_RESP(
0876                         STATUS_RESP_REQUEST_COMPLETE) |
0877                     STATUS_BLOCK_DEAD(0) |
0878                     STATUS_BLOCK_LEN(1) |
0879                     STATUS_BLOCK_SBP_STATUS(
0880                         SBP_STATUS_REQ_TYPE_NOTSUPP));
0881             sbp_send_status(req);
0882             return;
0883         case 3: /* Dummy ORB */
0884             req->status.status |= cpu_to_be32(
0885                     STATUS_BLOCK_RESP(
0886                         STATUS_RESP_REQUEST_COMPLETE) |
0887                     STATUS_BLOCK_DEAD(0) |
0888                     STATUS_BLOCK_LEN(1) |
0889                     STATUS_BLOCK_SBP_STATUS(
0890                         SBP_STATUS_DUMMY_ORB_COMPLETE));
0891             sbp_send_status(req);
0892             return;
0893         default:
0894             BUG();
0895     }
0896 }
0897 
0898 /* used to double-check we haven't been issued an AGENT_RESET */
0899 static inline bool tgt_agent_check_active(struct sbp_target_agent *agent)
0900 {
0901     bool active;
0902 
0903     spin_lock_bh(&agent->lock);
0904     active = (agent->state == AGENT_STATE_ACTIVE);
0905     spin_unlock_bh(&agent->lock);
0906 
0907     return active;
0908 }
0909 
0910 static struct sbp_target_request *sbp_mgt_get_req(struct sbp_session *sess,
0911     struct fw_card *card, u64 next_orb)
0912 {
0913     struct se_session *se_sess = sess->se_sess;
0914     struct sbp_target_request *req;
0915     int tag, cpu;
0916 
0917     tag = sbitmap_queue_get(&se_sess->sess_tag_pool, &cpu);
0918     if (tag < 0)
0919         return ERR_PTR(-ENOMEM);
0920 
0921     req = &((struct sbp_target_request *)se_sess->sess_cmd_map)[tag];
0922     memset(req, 0, sizeof(*req));
0923     req->se_cmd.map_tag = tag;
0924     req->se_cmd.map_cpu = cpu;
0925     req->se_cmd.tag = next_orb;
0926 
0927     return req;
0928 }
0929 
0930 static void tgt_agent_fetch_work(struct work_struct *work)
0931 {
0932     struct sbp_target_agent *agent =
0933         container_of(work, struct sbp_target_agent, work);
0934     struct sbp_session *sess = agent->login->sess;
0935     struct sbp_target_request *req;
0936     int ret;
0937     bool doorbell = agent->doorbell;
0938     u64 next_orb = agent->orb_pointer;
0939 
0940     while (next_orb && tgt_agent_check_active(agent)) {
0941         req = sbp_mgt_get_req(sess, sess->card, next_orb);
0942         if (IS_ERR(req)) {
0943             spin_lock_bh(&agent->lock);
0944             agent->state = AGENT_STATE_DEAD;
0945             spin_unlock_bh(&agent->lock);
0946             return;
0947         }
0948 
0949         req->login = agent->login;
0950         req->orb_pointer = next_orb;
0951 
0952         req->status.status = cpu_to_be32(STATUS_BLOCK_ORB_OFFSET_HIGH(
0953                     req->orb_pointer >> 32));
0954         req->status.orb_low = cpu_to_be32(
0955                 req->orb_pointer & 0xfffffffc);
0956 
0957         /* read in the ORB */
0958         ret = sbp_run_transaction(sess->card, TCODE_READ_BLOCK_REQUEST,
0959                 sess->node_id, sess->generation, sess->speed,
0960                 req->orb_pointer, &req->orb, sizeof(req->orb));
0961         if (ret != RCODE_COMPLETE) {
0962             pr_debug("tgt_orb fetch failed: %x\n", ret);
0963             req->status.status |= cpu_to_be32(
0964                     STATUS_BLOCK_SRC(
0965                         STATUS_SRC_ORB_FINISHED) |
0966                     STATUS_BLOCK_RESP(
0967                         STATUS_RESP_TRANSPORT_FAILURE) |
0968                     STATUS_BLOCK_DEAD(1) |
0969                     STATUS_BLOCK_LEN(1) |
0970                     STATUS_BLOCK_SBP_STATUS(
0971                         SBP_STATUS_UNSPECIFIED_ERROR));
0972             spin_lock_bh(&agent->lock);
0973             agent->state = AGENT_STATE_DEAD;
0974             spin_unlock_bh(&agent->lock);
0975 
0976             sbp_send_status(req);
0977             return;
0978         }
0979 
0980         /* check the next_ORB field */
0981         if (be32_to_cpu(req->orb.next_orb.high) & 0x80000000) {
0982             next_orb = 0;
0983             req->status.status |= cpu_to_be32(STATUS_BLOCK_SRC(
0984                         STATUS_SRC_ORB_FINISHED));
0985         } else {
0986             next_orb = sbp2_pointer_to_addr(&req->orb.next_orb);
0987             req->status.status |= cpu_to_be32(STATUS_BLOCK_SRC(
0988                         STATUS_SRC_ORB_CONTINUING));
0989         }
0990 
0991         if (tgt_agent_check_active(agent) && !doorbell) {
0992             INIT_WORK(&req->work, tgt_agent_process_work);
0993             queue_work(system_unbound_wq, &req->work);
0994         } else {
0995             /* don't process this request, just check next_ORB */
0996             sbp_free_request(req);
0997         }
0998 
0999         spin_lock_bh(&agent->lock);
1000         doorbell = agent->doorbell = false;
1001 
1002         /* check if we should carry on processing */
1003         if (next_orb)
1004             agent->orb_pointer = next_orb;
1005         else
1006             agent->state = AGENT_STATE_SUSPENDED;
1007 
1008         spin_unlock_bh(&agent->lock);
1009     }
1010 }
1011 
1012 static struct sbp_target_agent *sbp_target_agent_register(
1013         struct sbp_login_descriptor *login)
1014 {
1015     struct sbp_target_agent *agent;
1016     int ret;
1017 
1018     agent = kmalloc(sizeof(*agent), GFP_KERNEL);
1019     if (!agent)
1020         return ERR_PTR(-ENOMEM);
1021 
1022     spin_lock_init(&agent->lock);
1023 
1024     agent->handler.length = 0x20;
1025     agent->handler.address_callback = tgt_agent_rw;
1026     agent->handler.callback_data = agent;
1027 
1028     agent->login = login;
1029     agent->state = AGENT_STATE_RESET;
1030     INIT_WORK(&agent->work, tgt_agent_fetch_work);
1031     agent->orb_pointer = 0;
1032     agent->doorbell = false;
1033 
1034     ret = fw_core_add_address_handler(&agent->handler,
1035             &sbp_register_region);
1036     if (ret < 0) {
1037         kfree(agent);
1038         return ERR_PTR(ret);
1039     }
1040 
1041     return agent;
1042 }
1043 
1044 static void sbp_target_agent_unregister(struct sbp_target_agent *agent)
1045 {
1046     fw_core_remove_address_handler(&agent->handler);
1047     cancel_work_sync(&agent->work);
1048     kfree(agent);
1049 }
1050 
1051 /*
1052  * Simple wrapper around fw_run_transaction that retries the transaction several
1053  * times in case of failure, with an exponential backoff.
1054  */
1055 static int sbp_run_transaction(struct fw_card *card, int tcode, int destination_id,
1056         int generation, int speed, unsigned long long offset,
1057         void *payload, size_t length)
1058 {
1059     int attempt, ret, delay;
1060 
1061     for (attempt = 1; attempt <= 5; attempt++) {
1062         ret = fw_run_transaction(card, tcode, destination_id,
1063                 generation, speed, offset, payload, length);
1064 
1065         switch (ret) {
1066         case RCODE_COMPLETE:
1067         case RCODE_TYPE_ERROR:
1068         case RCODE_ADDRESS_ERROR:
1069         case RCODE_GENERATION:
1070             return ret;
1071 
1072         default:
1073             delay = 5 * attempt * attempt;
1074             usleep_range(delay, delay * 2);
1075         }
1076     }
1077 
1078     return ret;
1079 }
1080 
1081 /*
1082  * Wrapper around sbp_run_transaction that gets the card, destination,
1083  * generation and speed out of the request's session.
1084  */
1085 static int sbp_run_request_transaction(struct sbp_target_request *req,
1086         int tcode, unsigned long long offset, void *payload,
1087         size_t length)
1088 {
1089     struct sbp_login_descriptor *login = req->login;
1090     struct sbp_session *sess = login->sess;
1091     struct fw_card *card;
1092     int node_id, generation, speed, ret;
1093 
1094     spin_lock_bh(&sess->lock);
1095     card = fw_card_get(sess->card);
1096     node_id = sess->node_id;
1097     generation = sess->generation;
1098     speed = sess->speed;
1099     spin_unlock_bh(&sess->lock);
1100 
1101     ret = sbp_run_transaction(card, tcode, node_id, generation, speed,
1102             offset, payload, length);
1103 
1104     fw_card_put(card);
1105 
1106     return ret;
1107 }
1108 
1109 static int sbp_fetch_command(struct sbp_target_request *req)
1110 {
1111     int ret, cmd_len, copy_len;
1112 
1113     cmd_len = scsi_command_size(req->orb.command_block);
1114 
1115     req->cmd_buf = kmalloc(cmd_len, GFP_KERNEL);
1116     if (!req->cmd_buf)
1117         return -ENOMEM;
1118 
1119     memcpy(req->cmd_buf, req->orb.command_block,
1120         min_t(int, cmd_len, sizeof(req->orb.command_block)));
1121 
1122     if (cmd_len > sizeof(req->orb.command_block)) {
1123         pr_debug("sbp_fetch_command: filling in long command\n");
1124         copy_len = cmd_len - sizeof(req->orb.command_block);
1125 
1126         ret = sbp_run_request_transaction(req,
1127                 TCODE_READ_BLOCK_REQUEST,
1128                 req->orb_pointer + sizeof(req->orb),
1129                 req->cmd_buf + sizeof(req->orb.command_block),
1130                 copy_len);
1131         if (ret != RCODE_COMPLETE)
1132             return -EIO;
1133     }
1134 
1135     return 0;
1136 }
1137 
1138 static int sbp_fetch_page_table(struct sbp_target_request *req)
1139 {
1140     int pg_tbl_sz, ret;
1141     struct sbp_page_table_entry *pg_tbl;
1142 
1143     if (!CMDBLK_ORB_PG_TBL_PRESENT(be32_to_cpu(req->orb.misc)))
1144         return 0;
1145 
1146     pg_tbl_sz = CMDBLK_ORB_DATA_SIZE(be32_to_cpu(req->orb.misc)) *
1147         sizeof(struct sbp_page_table_entry);
1148 
1149     pg_tbl = kmalloc(pg_tbl_sz, GFP_KERNEL);
1150     if (!pg_tbl)
1151         return -ENOMEM;
1152 
1153     ret = sbp_run_request_transaction(req, TCODE_READ_BLOCK_REQUEST,
1154             sbp2_pointer_to_addr(&req->orb.data_descriptor),
1155             pg_tbl, pg_tbl_sz);
1156     if (ret != RCODE_COMPLETE) {
1157         kfree(pg_tbl);
1158         return -EIO;
1159     }
1160 
1161     req->pg_tbl = pg_tbl;
1162     return 0;
1163 }
1164 
1165 static void sbp_calc_data_length_direction(struct sbp_target_request *req,
1166     u32 *data_len, enum dma_data_direction *data_dir)
1167 {
1168     int data_size, direction, idx;
1169 
1170     data_size = CMDBLK_ORB_DATA_SIZE(be32_to_cpu(req->orb.misc));
1171     direction = CMDBLK_ORB_DIRECTION(be32_to_cpu(req->orb.misc));
1172 
1173     if (!data_size) {
1174         *data_len = 0;
1175         *data_dir = DMA_NONE;
1176         return;
1177     }
1178 
1179     *data_dir = direction ? DMA_FROM_DEVICE : DMA_TO_DEVICE;
1180 
1181     if (req->pg_tbl) {
1182         *data_len = 0;
1183         for (idx = 0; idx < data_size; idx++) {
1184             *data_len += be16_to_cpu(
1185                     req->pg_tbl[idx].segment_length);
1186         }
1187     } else {
1188         *data_len = data_size;
1189     }
1190 }
1191 
1192 static void sbp_handle_command(struct sbp_target_request *req)
1193 {
1194     struct sbp_login_descriptor *login = req->login;
1195     struct sbp_session *sess = login->sess;
1196     int ret, unpacked_lun;
1197     u32 data_length;
1198     enum dma_data_direction data_dir;
1199 
1200     ret = sbp_fetch_command(req);
1201     if (ret) {
1202         pr_debug("sbp_handle_command: fetch command failed: %d\n", ret);
1203         goto err;
1204     }
1205 
1206     ret = sbp_fetch_page_table(req);
1207     if (ret) {
1208         pr_debug("sbp_handle_command: fetch page table failed: %d\n",
1209             ret);
1210         goto err;
1211     }
1212 
1213     unpacked_lun = req->login->login_lun;
1214     sbp_calc_data_length_direction(req, &data_length, &data_dir);
1215 
1216     pr_debug("sbp_handle_command ORB:0x%llx unpacked_lun:%d data_len:%d data_dir:%d\n",
1217             req->orb_pointer, unpacked_lun, data_length, data_dir);
1218 
1219     /* only used for printk until we do TMRs */
1220     req->se_cmd.tag = req->orb_pointer;
1221     target_submit_cmd(&req->se_cmd, sess->se_sess, req->cmd_buf,
1222               req->sense_buf, unpacked_lun, data_length,
1223               TCM_SIMPLE_TAG, data_dir, TARGET_SCF_ACK_KREF);
1224     return;
1225 
1226 err:
1227     req->status.status |= cpu_to_be32(
1228         STATUS_BLOCK_RESP(STATUS_RESP_TRANSPORT_FAILURE) |
1229         STATUS_BLOCK_DEAD(0) |
1230         STATUS_BLOCK_LEN(1) |
1231         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_UNSPECIFIED_ERROR));
1232     sbp_send_status(req);
1233 }
1234 
1235 /*
1236  * DMA_TO_DEVICE = read from initiator (SCSI WRITE)
1237  * DMA_FROM_DEVICE = write to initiator (SCSI READ)
1238  */
1239 static int sbp_rw_data(struct sbp_target_request *req)
1240 {
1241     struct sbp_session *sess = req->login->sess;
1242     int tcode, sg_miter_flags, max_payload, pg_size, speed, node_id,
1243         generation, num_pte, length, tfr_length,
1244         rcode = RCODE_COMPLETE;
1245     struct sbp_page_table_entry *pte;
1246     unsigned long long offset;
1247     struct fw_card *card;
1248     struct sg_mapping_iter iter;
1249 
1250     if (req->se_cmd.data_direction == DMA_FROM_DEVICE) {
1251         tcode = TCODE_WRITE_BLOCK_REQUEST;
1252         sg_miter_flags = SG_MITER_FROM_SG;
1253     } else {
1254         tcode = TCODE_READ_BLOCK_REQUEST;
1255         sg_miter_flags = SG_MITER_TO_SG;
1256     }
1257 
1258     max_payload = 4 << CMDBLK_ORB_MAX_PAYLOAD(be32_to_cpu(req->orb.misc));
1259     speed = CMDBLK_ORB_SPEED(be32_to_cpu(req->orb.misc));
1260 
1261     pg_size = CMDBLK_ORB_PG_SIZE(be32_to_cpu(req->orb.misc));
1262     if (pg_size) {
1263         pr_err("sbp_run_transaction: page size ignored\n");
1264     }
1265 
1266     spin_lock_bh(&sess->lock);
1267     card = fw_card_get(sess->card);
1268     node_id = sess->node_id;
1269     generation = sess->generation;
1270     spin_unlock_bh(&sess->lock);
1271 
1272     if (req->pg_tbl) {
1273         pte = req->pg_tbl;
1274         num_pte = CMDBLK_ORB_DATA_SIZE(be32_to_cpu(req->orb.misc));
1275 
1276         offset = 0;
1277         length = 0;
1278     } else {
1279         pte = NULL;
1280         num_pte = 0;
1281 
1282         offset = sbp2_pointer_to_addr(&req->orb.data_descriptor);
1283         length = req->se_cmd.data_length;
1284     }
1285 
1286     sg_miter_start(&iter, req->se_cmd.t_data_sg, req->se_cmd.t_data_nents,
1287         sg_miter_flags);
1288 
1289     while (length || num_pte) {
1290         if (!length) {
1291             offset = (u64)be16_to_cpu(pte->segment_base_hi) << 32 |
1292                 be32_to_cpu(pte->segment_base_lo);
1293             length = be16_to_cpu(pte->segment_length);
1294 
1295             pte++;
1296             num_pte--;
1297         }
1298 
1299         sg_miter_next(&iter);
1300 
1301         tfr_length = min3(length, max_payload, (int)iter.length);
1302 
1303         /* FIXME: take page_size into account */
1304 
1305         rcode = sbp_run_transaction(card, tcode, node_id,
1306                 generation, speed,
1307                 offset, iter.addr, tfr_length);
1308 
1309         if (rcode != RCODE_COMPLETE)
1310             break;
1311 
1312         length -= tfr_length;
1313         offset += tfr_length;
1314         iter.consumed = tfr_length;
1315     }
1316 
1317     sg_miter_stop(&iter);
1318     fw_card_put(card);
1319 
1320     if (rcode == RCODE_COMPLETE) {
1321         WARN_ON(length != 0);
1322         return 0;
1323     } else {
1324         return -EIO;
1325     }
1326 }
1327 
1328 static int sbp_send_status(struct sbp_target_request *req)
1329 {
1330     int rc, ret = 0, length;
1331     struct sbp_login_descriptor *login = req->login;
1332 
1333     length = (((be32_to_cpu(req->status.status) >> 24) & 0x07) + 1) * 4;
1334 
1335     rc = sbp_run_request_transaction(req, TCODE_WRITE_BLOCK_REQUEST,
1336             login->status_fifo_addr, &req->status, length);
1337     if (rc != RCODE_COMPLETE) {
1338         pr_debug("sbp_send_status: write failed: 0x%x\n", rc);
1339         ret = -EIO;
1340         goto put_ref;
1341     }
1342 
1343     pr_debug("sbp_send_status: status write complete for ORB: 0x%llx\n",
1344             req->orb_pointer);
1345     /*
1346      * Drop the extra ACK_KREF reference taken by target_submit_cmd()
1347      * ahead of sbp_check_stop_free() -> transport_generic_free_cmd()
1348      * final se_cmd->cmd_kref put.
1349      */
1350 put_ref:
1351     target_put_sess_cmd(&req->se_cmd);
1352     return ret;
1353 }
1354 
1355 static void sbp_sense_mangle(struct sbp_target_request *req)
1356 {
1357     struct se_cmd *se_cmd = &req->se_cmd;
1358     u8 *sense = req->sense_buf;
1359     u8 *status = req->status.data;
1360 
1361     WARN_ON(se_cmd->scsi_sense_length < 18);
1362 
1363     switch (sense[0] & 0x7f) {      /* sfmt */
1364     case 0x70: /* current, fixed */
1365         status[0] = 0 << 6;
1366         break;
1367     case 0x71: /* deferred, fixed */
1368         status[0] = 1 << 6;
1369         break;
1370     case 0x72: /* current, descriptor */
1371     case 0x73: /* deferred, descriptor */
1372     default:
1373         /*
1374          * TODO: SBP-3 specifies what we should do with descriptor
1375          * format sense data
1376          */
1377         pr_err("sbp_send_sense: unknown sense format: 0x%x\n",
1378             sense[0]);
1379         req->status.status |= cpu_to_be32(
1380             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1381             STATUS_BLOCK_DEAD(0) |
1382             STATUS_BLOCK_LEN(1) |
1383             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQUEST_ABORTED));
1384         return;
1385     }
1386 
1387     status[0] |= se_cmd->scsi_status & 0x3f;/* status */
1388     status[1] =
1389         (sense[0] & 0x80) |     /* valid */
1390         ((sense[2] & 0xe0) >> 1) |  /* mark, eom, ili */
1391         (sense[2] & 0x0f);      /* sense_key */
1392     status[2] = 0;              /* XXX sense_code */
1393     status[3] = 0;              /* XXX sense_qualifier */
1394 
1395     /* information */
1396     status[4] = sense[3];
1397     status[5] = sense[4];
1398     status[6] = sense[5];
1399     status[7] = sense[6];
1400 
1401     /* CDB-dependent */
1402     status[8] = sense[8];
1403     status[9] = sense[9];
1404     status[10] = sense[10];
1405     status[11] = sense[11];
1406 
1407     /* fru */
1408     status[12] = sense[14];
1409 
1410     /* sense_key-dependent */
1411     status[13] = sense[15];
1412     status[14] = sense[16];
1413     status[15] = sense[17];
1414 
1415     req->status.status |= cpu_to_be32(
1416         STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1417         STATUS_BLOCK_DEAD(0) |
1418         STATUS_BLOCK_LEN(5) |
1419         STATUS_BLOCK_SBP_STATUS(SBP_STATUS_OK));
1420 }
1421 
1422 static int sbp_send_sense(struct sbp_target_request *req)
1423 {
1424     struct se_cmd *se_cmd = &req->se_cmd;
1425 
1426     if (se_cmd->scsi_sense_length) {
1427         sbp_sense_mangle(req);
1428     } else {
1429         req->status.status |= cpu_to_be32(
1430             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1431             STATUS_BLOCK_DEAD(0) |
1432             STATUS_BLOCK_LEN(1) |
1433             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_OK));
1434     }
1435 
1436     return sbp_send_status(req);
1437 }
1438 
1439 static void sbp_free_request(struct sbp_target_request *req)
1440 {
1441     struct se_cmd *se_cmd = &req->se_cmd;
1442     struct se_session *se_sess = se_cmd->se_sess;
1443 
1444     kfree(req->pg_tbl);
1445     kfree(req->cmd_buf);
1446 
1447     target_free_tag(se_sess, se_cmd);
1448 }
1449 
1450 static void sbp_mgt_agent_process(struct work_struct *work)
1451 {
1452     struct sbp_management_agent *agent =
1453         container_of(work, struct sbp_management_agent, work);
1454     struct sbp_management_request *req = agent->request;
1455     int ret;
1456     int status_data_len = 0;
1457 
1458     /* fetch the ORB from the initiator */
1459     ret = sbp_run_transaction(req->card, TCODE_READ_BLOCK_REQUEST,
1460         req->node_addr, req->generation, req->speed,
1461         agent->orb_offset, &req->orb, sizeof(req->orb));
1462     if (ret != RCODE_COMPLETE) {
1463         pr_debug("mgt_orb fetch failed: %x\n", ret);
1464         goto out;
1465     }
1466 
1467     pr_debug("mgt_orb ptr1:0x%llx ptr2:0x%llx misc:0x%x len:0x%x status_fifo:0x%llx\n",
1468         sbp2_pointer_to_addr(&req->orb.ptr1),
1469         sbp2_pointer_to_addr(&req->orb.ptr2),
1470         be32_to_cpu(req->orb.misc), be32_to_cpu(req->orb.length),
1471         sbp2_pointer_to_addr(&req->orb.status_fifo));
1472 
1473     if (!ORB_NOTIFY(be32_to_cpu(req->orb.misc)) ||
1474         ORB_REQUEST_FORMAT(be32_to_cpu(req->orb.misc)) != 0) {
1475         pr_err("mgt_orb bad request\n");
1476         goto out;
1477     }
1478 
1479     switch (MANAGEMENT_ORB_FUNCTION(be32_to_cpu(req->orb.misc))) {
1480     case MANAGEMENT_ORB_FUNCTION_LOGIN:
1481         sbp_management_request_login(agent, req, &status_data_len);
1482         break;
1483 
1484     case MANAGEMENT_ORB_FUNCTION_QUERY_LOGINS:
1485         sbp_management_request_query_logins(agent, req,
1486                 &status_data_len);
1487         break;
1488 
1489     case MANAGEMENT_ORB_FUNCTION_RECONNECT:
1490         sbp_management_request_reconnect(agent, req, &status_data_len);
1491         break;
1492 
1493     case MANAGEMENT_ORB_FUNCTION_SET_PASSWORD:
1494         pr_notice("SET PASSWORD not implemented\n");
1495 
1496         req->status.status = cpu_to_be32(
1497             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1498             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1499 
1500         break;
1501 
1502     case MANAGEMENT_ORB_FUNCTION_LOGOUT:
1503         sbp_management_request_logout(agent, req, &status_data_len);
1504         break;
1505 
1506     case MANAGEMENT_ORB_FUNCTION_ABORT_TASK:
1507         pr_notice("ABORT TASK not implemented\n");
1508 
1509         req->status.status = cpu_to_be32(
1510             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1511             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1512 
1513         break;
1514 
1515     case MANAGEMENT_ORB_FUNCTION_ABORT_TASK_SET:
1516         pr_notice("ABORT TASK SET not implemented\n");
1517 
1518         req->status.status = cpu_to_be32(
1519             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1520             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1521 
1522         break;
1523 
1524     case MANAGEMENT_ORB_FUNCTION_LOGICAL_UNIT_RESET:
1525         pr_notice("LOGICAL UNIT RESET not implemented\n");
1526 
1527         req->status.status = cpu_to_be32(
1528             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1529             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1530 
1531         break;
1532 
1533     case MANAGEMENT_ORB_FUNCTION_TARGET_RESET:
1534         pr_notice("TARGET RESET not implemented\n");
1535 
1536         req->status.status = cpu_to_be32(
1537             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1538             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1539 
1540         break;
1541 
1542     default:
1543         pr_notice("unknown management function 0x%x\n",
1544             MANAGEMENT_ORB_FUNCTION(be32_to_cpu(req->orb.misc)));
1545 
1546         req->status.status = cpu_to_be32(
1547             STATUS_BLOCK_RESP(STATUS_RESP_REQUEST_COMPLETE) |
1548             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_REQ_TYPE_NOTSUPP));
1549 
1550         break;
1551     }
1552 
1553     req->status.status |= cpu_to_be32(
1554         STATUS_BLOCK_SRC(1) | /* Response to ORB, next_ORB absent */
1555         STATUS_BLOCK_LEN(DIV_ROUND_UP(status_data_len, 4) + 1) |
1556         STATUS_BLOCK_ORB_OFFSET_HIGH(agent->orb_offset >> 32));
1557     req->status.orb_low = cpu_to_be32(agent->orb_offset);
1558 
1559     /* write the status block back to the initiator */
1560     ret = sbp_run_transaction(req->card, TCODE_WRITE_BLOCK_REQUEST,
1561         req->node_addr, req->generation, req->speed,
1562         sbp2_pointer_to_addr(&req->orb.status_fifo),
1563         &req->status, 8 + status_data_len);
1564     if (ret != RCODE_COMPLETE) {
1565         pr_debug("mgt_orb status write failed: %x\n", ret);
1566         goto out;
1567     }
1568 
1569 out:
1570     fw_card_put(req->card);
1571     kfree(req);
1572 
1573     spin_lock_bh(&agent->lock);
1574     agent->state = MANAGEMENT_AGENT_STATE_IDLE;
1575     spin_unlock_bh(&agent->lock);
1576 }
1577 
1578 static void sbp_mgt_agent_rw(struct fw_card *card,
1579     struct fw_request *request, int tcode, int destination, int source,
1580     int generation, unsigned long long offset, void *data, size_t length,
1581     void *callback_data)
1582 {
1583     struct sbp_management_agent *agent = callback_data;
1584     struct sbp2_pointer *ptr = data;
1585     int rcode = RCODE_ADDRESS_ERROR;
1586 
1587     if (!agent->tport->enable)
1588         goto out;
1589 
1590     if ((offset != agent->handler.offset) || (length != 8))
1591         goto out;
1592 
1593     if (tcode == TCODE_WRITE_BLOCK_REQUEST) {
1594         struct sbp_management_request *req;
1595         int prev_state;
1596 
1597         spin_lock_bh(&agent->lock);
1598         prev_state = agent->state;
1599         agent->state = MANAGEMENT_AGENT_STATE_BUSY;
1600         spin_unlock_bh(&agent->lock);
1601 
1602         if (prev_state == MANAGEMENT_AGENT_STATE_BUSY) {
1603             pr_notice("ignoring management request while busy\n");
1604             rcode = RCODE_CONFLICT_ERROR;
1605             goto out;
1606         }
1607         req = kzalloc(sizeof(*req), GFP_ATOMIC);
1608         if (!req) {
1609             rcode = RCODE_CONFLICT_ERROR;
1610             goto out;
1611         }
1612 
1613         req->card = fw_card_get(card);
1614         req->generation = generation;
1615         req->node_addr = source;
1616         req->speed = fw_get_request_speed(request);
1617 
1618         agent->orb_offset = sbp2_pointer_to_addr(ptr);
1619         agent->request = req;
1620 
1621         queue_work(system_unbound_wq, &agent->work);
1622         rcode = RCODE_COMPLETE;
1623     } else if (tcode == TCODE_READ_BLOCK_REQUEST) {
1624         addr_to_sbp2_pointer(agent->orb_offset, ptr);
1625         rcode = RCODE_COMPLETE;
1626     } else {
1627         rcode = RCODE_TYPE_ERROR;
1628     }
1629 
1630 out:
1631     fw_send_response(card, request, rcode);
1632 }
1633 
1634 static struct sbp_management_agent *sbp_management_agent_register(
1635         struct sbp_tport *tport)
1636 {
1637     int ret;
1638     struct sbp_management_agent *agent;
1639 
1640     agent = kmalloc(sizeof(*agent), GFP_KERNEL);
1641     if (!agent)
1642         return ERR_PTR(-ENOMEM);
1643 
1644     spin_lock_init(&agent->lock);
1645     agent->tport = tport;
1646     agent->handler.length = 0x08;
1647     agent->handler.address_callback = sbp_mgt_agent_rw;
1648     agent->handler.callback_data = agent;
1649     agent->state = MANAGEMENT_AGENT_STATE_IDLE;
1650     INIT_WORK(&agent->work, sbp_mgt_agent_process);
1651     agent->orb_offset = 0;
1652     agent->request = NULL;
1653 
1654     ret = fw_core_add_address_handler(&agent->handler,
1655             &sbp_register_region);
1656     if (ret < 0) {
1657         kfree(agent);
1658         return ERR_PTR(ret);
1659     }
1660 
1661     return agent;
1662 }
1663 
1664 static void sbp_management_agent_unregister(struct sbp_management_agent *agent)
1665 {
1666     fw_core_remove_address_handler(&agent->handler);
1667     cancel_work_sync(&agent->work);
1668     kfree(agent);
1669 }
1670 
1671 static int sbp_check_true(struct se_portal_group *se_tpg)
1672 {
1673     return 1;
1674 }
1675 
1676 static int sbp_check_false(struct se_portal_group *se_tpg)
1677 {
1678     return 0;
1679 }
1680 
1681 static char *sbp_get_fabric_wwn(struct se_portal_group *se_tpg)
1682 {
1683     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
1684     struct sbp_tport *tport = tpg->tport;
1685 
1686     return &tport->tport_name[0];
1687 }
1688 
1689 static u16 sbp_get_tag(struct se_portal_group *se_tpg)
1690 {
1691     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
1692     return tpg->tport_tpgt;
1693 }
1694 
1695 static u32 sbp_tpg_get_inst_index(struct se_portal_group *se_tpg)
1696 {
1697     return 1;
1698 }
1699 
1700 static void sbp_release_cmd(struct se_cmd *se_cmd)
1701 {
1702     struct sbp_target_request *req = container_of(se_cmd,
1703             struct sbp_target_request, se_cmd);
1704 
1705     sbp_free_request(req);
1706 }
1707 
1708 static u32 sbp_sess_get_index(struct se_session *se_sess)
1709 {
1710     return 0;
1711 }
1712 
1713 static int sbp_write_pending(struct se_cmd *se_cmd)
1714 {
1715     struct sbp_target_request *req = container_of(se_cmd,
1716             struct sbp_target_request, se_cmd);
1717     int ret;
1718 
1719     ret = sbp_rw_data(req);
1720     if (ret) {
1721         req->status.status |= cpu_to_be32(
1722             STATUS_BLOCK_RESP(
1723                 STATUS_RESP_TRANSPORT_FAILURE) |
1724             STATUS_BLOCK_DEAD(0) |
1725             STATUS_BLOCK_LEN(1) |
1726             STATUS_BLOCK_SBP_STATUS(
1727                 SBP_STATUS_UNSPECIFIED_ERROR));
1728         sbp_send_status(req);
1729         return ret;
1730     }
1731 
1732     target_execute_cmd(se_cmd);
1733     return 0;
1734 }
1735 
1736 static void sbp_set_default_node_attrs(struct se_node_acl *nacl)
1737 {
1738     return;
1739 }
1740 
1741 static int sbp_get_cmd_state(struct se_cmd *se_cmd)
1742 {
1743     return 0;
1744 }
1745 
1746 static int sbp_queue_data_in(struct se_cmd *se_cmd)
1747 {
1748     struct sbp_target_request *req = container_of(se_cmd,
1749             struct sbp_target_request, se_cmd);
1750     int ret;
1751 
1752     ret = sbp_rw_data(req);
1753     if (ret) {
1754         req->status.status |= cpu_to_be32(
1755             STATUS_BLOCK_RESP(STATUS_RESP_TRANSPORT_FAILURE) |
1756             STATUS_BLOCK_DEAD(0) |
1757             STATUS_BLOCK_LEN(1) |
1758             STATUS_BLOCK_SBP_STATUS(SBP_STATUS_UNSPECIFIED_ERROR));
1759         sbp_send_status(req);
1760         return ret;
1761     }
1762 
1763     return sbp_send_sense(req);
1764 }
1765 
1766 /*
1767  * Called after command (no data transfer) or after the write (to device)
1768  * operation is completed
1769  */
1770 static int sbp_queue_status(struct se_cmd *se_cmd)
1771 {
1772     struct sbp_target_request *req = container_of(se_cmd,
1773             struct sbp_target_request, se_cmd);
1774 
1775     return sbp_send_sense(req);
1776 }
1777 
1778 static void sbp_queue_tm_rsp(struct se_cmd *se_cmd)
1779 {
1780 }
1781 
1782 static void sbp_aborted_task(struct se_cmd *se_cmd)
1783 {
1784     return;
1785 }
1786 
1787 static int sbp_check_stop_free(struct se_cmd *se_cmd)
1788 {
1789     struct sbp_target_request *req = container_of(se_cmd,
1790             struct sbp_target_request, se_cmd);
1791 
1792     return transport_generic_free_cmd(&req->se_cmd, 0);
1793 }
1794 
1795 static int sbp_count_se_tpg_luns(struct se_portal_group *tpg)
1796 {
1797     struct se_lun *lun;
1798     int count = 0;
1799 
1800     rcu_read_lock();
1801     hlist_for_each_entry_rcu(lun, &tpg->tpg_lun_hlist, link)
1802         count++;
1803     rcu_read_unlock();
1804 
1805     return count;
1806 }
1807 
1808 static int sbp_update_unit_directory(struct sbp_tport *tport)
1809 {
1810     struct se_lun *lun;
1811     int num_luns, num_entries, idx = 0, mgt_agt_addr, ret;
1812     u32 *data;
1813 
1814     if (tport->unit_directory.data) {
1815         fw_core_remove_descriptor(&tport->unit_directory);
1816         kfree(tport->unit_directory.data);
1817         tport->unit_directory.data = NULL;
1818     }
1819 
1820     if (!tport->enable || !tport->tpg)
1821         return 0;
1822 
1823     num_luns = sbp_count_se_tpg_luns(&tport->tpg->se_tpg);
1824 
1825     /*
1826      * Number of entries in the final unit directory:
1827      *  - all of those in the template
1828      *  - management_agent
1829      *  - unit_characteristics
1830      *  - reconnect_timeout
1831      *  - unit unique ID
1832      *  - one for each LUN
1833      *
1834      *  MUST NOT include leaf or sub-directory entries
1835      */
1836     num_entries = ARRAY_SIZE(sbp_unit_directory_template) + 4 + num_luns;
1837 
1838     if (tport->directory_id != -1)
1839         num_entries++;
1840 
1841     /* allocate num_entries + 4 for the header and unique ID leaf */
1842     data = kcalloc((num_entries + 4), sizeof(u32), GFP_KERNEL);
1843     if (!data)
1844         return -ENOMEM;
1845 
1846     /* directory_length */
1847     data[idx++] = num_entries << 16;
1848 
1849     /* directory_id */
1850     if (tport->directory_id != -1)
1851         data[idx++] = (CSR_DIRECTORY_ID << 24) | tport->directory_id;
1852 
1853     /* unit directory template */
1854     memcpy(&data[idx], sbp_unit_directory_template,
1855             sizeof(sbp_unit_directory_template));
1856     idx += ARRAY_SIZE(sbp_unit_directory_template);
1857 
1858     /* management_agent */
1859     mgt_agt_addr = (tport->mgt_agt->handler.offset - CSR_REGISTER_BASE) / 4;
1860     data[idx++] = 0x54000000 | (mgt_agt_addr & 0x00ffffff);
1861 
1862     /* unit_characteristics */
1863     data[idx++] = 0x3a000000 |
1864         (((tport->mgt_orb_timeout * 2) << 8) & 0xff00) |
1865         SBP_ORB_FETCH_SIZE;
1866 
1867     /* reconnect_timeout */
1868     data[idx++] = 0x3d000000 | (tport->max_reconnect_timeout & 0xffff);
1869 
1870     /* unit unique ID (leaf is just after LUNs) */
1871     data[idx++] = 0x8d000000 | (num_luns + 1);
1872 
1873     rcu_read_lock();
1874     hlist_for_each_entry_rcu(lun, &tport->tpg->se_tpg.tpg_lun_hlist, link) {
1875         struct se_device *dev;
1876         int type;
1877         /*
1878          * rcu_dereference_raw protected by se_lun->lun_group symlink
1879          * reference to se_device->dev_group.
1880          */
1881         dev = rcu_dereference_raw(lun->lun_se_dev);
1882         type = dev->transport->get_device_type(dev);
1883 
1884         /* logical_unit_number */
1885         data[idx++] = 0x14000000 |
1886             ((type << 16) & 0x1f0000) |
1887             (lun->unpacked_lun & 0xffff);
1888     }
1889     rcu_read_unlock();
1890 
1891     /* unit unique ID leaf */
1892     data[idx++] = 2 << 16;
1893     data[idx++] = tport->guid >> 32;
1894     data[idx++] = tport->guid;
1895 
1896     tport->unit_directory.length = idx;
1897     tport->unit_directory.key = (CSR_DIRECTORY | CSR_UNIT) << 24;
1898     tport->unit_directory.data = data;
1899 
1900     ret = fw_core_add_descriptor(&tport->unit_directory);
1901     if (ret < 0) {
1902         kfree(tport->unit_directory.data);
1903         tport->unit_directory.data = NULL;
1904     }
1905 
1906     return ret;
1907 }
1908 
1909 static ssize_t sbp_parse_wwn(const char *name, u64 *wwn)
1910 {
1911     const char *cp;
1912     char c, nibble;
1913     int pos = 0, err;
1914 
1915     *wwn = 0;
1916     for (cp = name; cp < &name[SBP_NAMELEN - 1]; cp++) {
1917         c = *cp;
1918         if (c == '\n' && cp[1] == '\0')
1919             continue;
1920         if (c == '\0') {
1921             err = 2;
1922             if (pos != 16)
1923                 goto fail;
1924             return cp - name;
1925         }
1926         err = 3;
1927         if (isdigit(c))
1928             nibble = c - '0';
1929         else if (isxdigit(c))
1930             nibble = tolower(c) - 'a' + 10;
1931         else
1932             goto fail;
1933         *wwn = (*wwn << 4) | nibble;
1934         pos++;
1935     }
1936     err = 4;
1937 fail:
1938     printk(KERN_INFO "err %u len %zu pos %u\n",
1939             err, cp - name, pos);
1940     return -1;
1941 }
1942 
1943 static ssize_t sbp_format_wwn(char *buf, size_t len, u64 wwn)
1944 {
1945     return snprintf(buf, len, "%016llx", wwn);
1946 }
1947 
1948 static int sbp_init_nodeacl(struct se_node_acl *se_nacl, const char *name)
1949 {
1950     u64 guid = 0;
1951 
1952     if (sbp_parse_wwn(name, &guid) < 0)
1953         return -EINVAL;
1954     return 0;
1955 }
1956 
1957 static int sbp_post_link_lun(
1958         struct se_portal_group *se_tpg,
1959         struct se_lun *se_lun)
1960 {
1961     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
1962 
1963     return sbp_update_unit_directory(tpg->tport);
1964 }
1965 
1966 static void sbp_pre_unlink_lun(
1967         struct se_portal_group *se_tpg,
1968         struct se_lun *se_lun)
1969 {
1970     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
1971     struct sbp_tport *tport = tpg->tport;
1972     int ret;
1973 
1974     if (sbp_count_se_tpg_luns(&tpg->se_tpg) == 0)
1975         tport->enable = 0;
1976 
1977     ret = sbp_update_unit_directory(tport);
1978     if (ret < 0)
1979         pr_err("unlink LUN: failed to update unit directory\n");
1980 }
1981 
1982 static struct se_portal_group *sbp_make_tpg(struct se_wwn *wwn,
1983                         const char *name)
1984 {
1985     struct sbp_tport *tport =
1986         container_of(wwn, struct sbp_tport, tport_wwn);
1987 
1988     struct sbp_tpg *tpg;
1989     unsigned long tpgt;
1990     int ret;
1991 
1992     if (strstr(name, "tpgt_") != name)
1993         return ERR_PTR(-EINVAL);
1994     if (kstrtoul(name + 5, 10, &tpgt) || tpgt > UINT_MAX)
1995         return ERR_PTR(-EINVAL);
1996 
1997     if (tport->tpg) {
1998         pr_err("Only one TPG per Unit is possible.\n");
1999         return ERR_PTR(-EBUSY);
2000     }
2001 
2002     tpg = kzalloc(sizeof(*tpg), GFP_KERNEL);
2003     if (!tpg)
2004         return ERR_PTR(-ENOMEM);
2005 
2006     tpg->tport = tport;
2007     tpg->tport_tpgt = tpgt;
2008     tport->tpg = tpg;
2009 
2010     /* default attribute values */
2011     tport->enable = 0;
2012     tport->directory_id = -1;
2013     tport->mgt_orb_timeout = 15;
2014     tport->max_reconnect_timeout = 5;
2015     tport->max_logins_per_lun = 1;
2016 
2017     tport->mgt_agt = sbp_management_agent_register(tport);
2018     if (IS_ERR(tport->mgt_agt)) {
2019         ret = PTR_ERR(tport->mgt_agt);
2020         goto out_free_tpg;
2021     }
2022 
2023     ret = core_tpg_register(wwn, &tpg->se_tpg, SCSI_PROTOCOL_SBP);
2024     if (ret < 0)
2025         goto out_unreg_mgt_agt;
2026 
2027     return &tpg->se_tpg;
2028 
2029 out_unreg_mgt_agt:
2030     sbp_management_agent_unregister(tport->mgt_agt);
2031 out_free_tpg:
2032     tport->tpg = NULL;
2033     kfree(tpg);
2034     return ERR_PTR(ret);
2035 }
2036 
2037 static void sbp_drop_tpg(struct se_portal_group *se_tpg)
2038 {
2039     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2040     struct sbp_tport *tport = tpg->tport;
2041 
2042     core_tpg_deregister(se_tpg);
2043     sbp_management_agent_unregister(tport->mgt_agt);
2044     tport->tpg = NULL;
2045     kfree(tpg);
2046 }
2047 
2048 static struct se_wwn *sbp_make_tport(
2049         struct target_fabric_configfs *tf,
2050         struct config_group *group,
2051         const char *name)
2052 {
2053     struct sbp_tport *tport;
2054     u64 guid = 0;
2055 
2056     if (sbp_parse_wwn(name, &guid) < 0)
2057         return ERR_PTR(-EINVAL);
2058 
2059     tport = kzalloc(sizeof(*tport), GFP_KERNEL);
2060     if (!tport)
2061         return ERR_PTR(-ENOMEM);
2062 
2063     tport->guid = guid;
2064     sbp_format_wwn(tport->tport_name, SBP_NAMELEN, guid);
2065 
2066     return &tport->tport_wwn;
2067 }
2068 
2069 static void sbp_drop_tport(struct se_wwn *wwn)
2070 {
2071     struct sbp_tport *tport =
2072         container_of(wwn, struct sbp_tport, tport_wwn);
2073 
2074     kfree(tport);
2075 }
2076 
2077 static ssize_t sbp_wwn_version_show(struct config_item *item, char *page)
2078 {
2079     return sprintf(page, "FireWire SBP fabric module %s\n", SBP_VERSION);
2080 }
2081 
2082 CONFIGFS_ATTR_RO(sbp_wwn_, version);
2083 
2084 static struct configfs_attribute *sbp_wwn_attrs[] = {
2085     &sbp_wwn_attr_version,
2086     NULL,
2087 };
2088 
2089 static ssize_t sbp_tpg_directory_id_show(struct config_item *item, char *page)
2090 {
2091     struct se_portal_group *se_tpg = to_tpg(item);
2092     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2093     struct sbp_tport *tport = tpg->tport;
2094 
2095     if (tport->directory_id == -1)
2096         return sprintf(page, "implicit\n");
2097     else
2098         return sprintf(page, "%06x\n", tport->directory_id);
2099 }
2100 
2101 static ssize_t sbp_tpg_directory_id_store(struct config_item *item,
2102         const char *page, size_t count)
2103 {
2104     struct se_portal_group *se_tpg = to_tpg(item);
2105     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2106     struct sbp_tport *tport = tpg->tport;
2107     unsigned long val;
2108 
2109     if (tport->enable) {
2110         pr_err("Cannot change the directory_id on an active target.\n");
2111         return -EBUSY;
2112     }
2113 
2114     if (strstr(page, "implicit") == page) {
2115         tport->directory_id = -1;
2116     } else {
2117         if (kstrtoul(page, 16, &val) < 0)
2118             return -EINVAL;
2119         if (val > 0xffffff)
2120             return -EINVAL;
2121 
2122         tport->directory_id = val;
2123     }
2124 
2125     return count;
2126 }
2127 
2128 static int sbp_enable_tpg(struct se_portal_group *se_tpg, bool enable)
2129 {
2130     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2131     struct sbp_tport *tport = tpg->tport;
2132     int ret;
2133 
2134     if (enable) {
2135         if (sbp_count_se_tpg_luns(&tpg->se_tpg) == 0) {
2136             pr_err("Cannot enable a target with no LUNs!\n");
2137             return -EINVAL;
2138         }
2139     } else {
2140         /* XXX: force-shutdown sessions instead? */
2141         spin_lock_bh(&se_tpg->session_lock);
2142         if (!list_empty(&se_tpg->tpg_sess_list)) {
2143             spin_unlock_bh(&se_tpg->session_lock);
2144             return -EBUSY;
2145         }
2146         spin_unlock_bh(&se_tpg->session_lock);
2147     }
2148 
2149     tport->enable = enable;
2150 
2151     ret = sbp_update_unit_directory(tport);
2152     if (ret < 0) {
2153         pr_err("Could not update Config ROM\n");
2154         return ret;
2155     }
2156 
2157     return 0;
2158 }
2159 
2160 CONFIGFS_ATTR(sbp_tpg_, directory_id);
2161 
2162 static struct configfs_attribute *sbp_tpg_base_attrs[] = {
2163     &sbp_tpg_attr_directory_id,
2164     NULL,
2165 };
2166 
2167 static ssize_t sbp_tpg_attrib_mgt_orb_timeout_show(struct config_item *item,
2168         char *page)
2169 {
2170     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2171     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2172     struct sbp_tport *tport = tpg->tport;
2173     return sprintf(page, "%d\n", tport->mgt_orb_timeout);
2174 }
2175 
2176 static ssize_t sbp_tpg_attrib_mgt_orb_timeout_store(struct config_item *item,
2177         const char *page, size_t count)
2178 {
2179     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2180     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2181     struct sbp_tport *tport = tpg->tport;
2182     unsigned long val;
2183     int ret;
2184 
2185     if (kstrtoul(page, 0, &val) < 0)
2186         return -EINVAL;
2187     if ((val < 1) || (val > 127))
2188         return -EINVAL;
2189 
2190     if (tport->mgt_orb_timeout == val)
2191         return count;
2192 
2193     tport->mgt_orb_timeout = val;
2194 
2195     ret = sbp_update_unit_directory(tport);
2196     if (ret < 0)
2197         return ret;
2198 
2199     return count;
2200 }
2201 
2202 static ssize_t sbp_tpg_attrib_max_reconnect_timeout_show(struct config_item *item,
2203         char *page)
2204 {
2205     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2206     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2207     struct sbp_tport *tport = tpg->tport;
2208     return sprintf(page, "%d\n", tport->max_reconnect_timeout);
2209 }
2210 
2211 static ssize_t sbp_tpg_attrib_max_reconnect_timeout_store(struct config_item *item,
2212         const char *page, size_t count)
2213 {
2214     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2215     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2216     struct sbp_tport *tport = tpg->tport;
2217     unsigned long val;
2218     int ret;
2219 
2220     if (kstrtoul(page, 0, &val) < 0)
2221         return -EINVAL;
2222     if ((val < 1) || (val > 32767))
2223         return -EINVAL;
2224 
2225     if (tport->max_reconnect_timeout == val)
2226         return count;
2227 
2228     tport->max_reconnect_timeout = val;
2229 
2230     ret = sbp_update_unit_directory(tport);
2231     if (ret < 0)
2232         return ret;
2233 
2234     return count;
2235 }
2236 
2237 static ssize_t sbp_tpg_attrib_max_logins_per_lun_show(struct config_item *item,
2238         char *page)
2239 {
2240     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2241     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2242     struct sbp_tport *tport = tpg->tport;
2243     return sprintf(page, "%d\n", tport->max_logins_per_lun);
2244 }
2245 
2246 static ssize_t sbp_tpg_attrib_max_logins_per_lun_store(struct config_item *item,
2247         const char *page, size_t count)
2248 {
2249     struct se_portal_group *se_tpg = attrib_to_tpg(item);
2250     struct sbp_tpg *tpg = container_of(se_tpg, struct sbp_tpg, se_tpg);
2251     struct sbp_tport *tport = tpg->tport;
2252     unsigned long val;
2253 
2254     if (kstrtoul(page, 0, &val) < 0)
2255         return -EINVAL;
2256     if ((val < 1) || (val > 127))
2257         return -EINVAL;
2258 
2259     /* XXX: also check against current count? */
2260 
2261     tport->max_logins_per_lun = val;
2262 
2263     return count;
2264 }
2265 
2266 CONFIGFS_ATTR(sbp_tpg_attrib_, mgt_orb_timeout);
2267 CONFIGFS_ATTR(sbp_tpg_attrib_, max_reconnect_timeout);
2268 CONFIGFS_ATTR(sbp_tpg_attrib_, max_logins_per_lun);
2269 
2270 static struct configfs_attribute *sbp_tpg_attrib_attrs[] = {
2271     &sbp_tpg_attrib_attr_mgt_orb_timeout,
2272     &sbp_tpg_attrib_attr_max_reconnect_timeout,
2273     &sbp_tpg_attrib_attr_max_logins_per_lun,
2274     NULL,
2275 };
2276 
2277 static const struct target_core_fabric_ops sbp_ops = {
2278     .module             = THIS_MODULE,
2279     .fabric_name            = "sbp",
2280     .tpg_get_wwn            = sbp_get_fabric_wwn,
2281     .tpg_get_tag            = sbp_get_tag,
2282     .tpg_check_demo_mode        = sbp_check_true,
2283     .tpg_check_demo_mode_cache  = sbp_check_true,
2284     .tpg_check_demo_mode_write_protect = sbp_check_false,
2285     .tpg_check_prod_mode_write_protect = sbp_check_false,
2286     .tpg_get_inst_index     = sbp_tpg_get_inst_index,
2287     .release_cmd            = sbp_release_cmd,
2288     .sess_get_index         = sbp_sess_get_index,
2289     .write_pending          = sbp_write_pending,
2290     .set_default_node_attributes    = sbp_set_default_node_attrs,
2291     .get_cmd_state          = sbp_get_cmd_state,
2292     .queue_data_in          = sbp_queue_data_in,
2293     .queue_status           = sbp_queue_status,
2294     .queue_tm_rsp           = sbp_queue_tm_rsp,
2295     .aborted_task           = sbp_aborted_task,
2296     .check_stop_free        = sbp_check_stop_free,
2297 
2298     .fabric_make_wwn        = sbp_make_tport,
2299     .fabric_drop_wwn        = sbp_drop_tport,
2300     .fabric_make_tpg        = sbp_make_tpg,
2301     .fabric_enable_tpg      = sbp_enable_tpg,
2302     .fabric_drop_tpg        = sbp_drop_tpg,
2303     .fabric_post_link       = sbp_post_link_lun,
2304     .fabric_pre_unlink      = sbp_pre_unlink_lun,
2305     .fabric_make_np         = NULL,
2306     .fabric_drop_np         = NULL,
2307     .fabric_init_nodeacl        = sbp_init_nodeacl,
2308 
2309     .tfc_wwn_attrs          = sbp_wwn_attrs,
2310     .tfc_tpg_base_attrs     = sbp_tpg_base_attrs,
2311     .tfc_tpg_attrib_attrs       = sbp_tpg_attrib_attrs,
2312 };
2313 
2314 static int __init sbp_init(void)
2315 {
2316     return target_register_template(&sbp_ops);
2317 };
2318 
2319 static void __exit sbp_exit(void)
2320 {
2321     target_unregister_template(&sbp_ops);
2322 };
2323 
2324 MODULE_DESCRIPTION("FireWire SBP fabric driver");
2325 MODULE_LICENSE("GPL");
2326 module_init(sbp_init);
2327 module_exit(sbp_exit);