target_core_sbc.c 38.4 KB
Newer Older
1 2 3
/*
 * SCSI Block Commands (SBC) parsing and emulation.
 *
4
 * (c) Copyright 2002-2013 Datera, Inc.
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
 *
 * Nicholas A. Bellinger <nab@kernel.org>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
 */

#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/ratelimit.h>
26
#include <linux/crc-t10dif.h>
27
#include <asm/unaligned.h>
28
#include <scsi/scsi_proto.h>
29
#include <scsi/scsi_tcq.h>
30 31 32 33 34 35 36

#include <target/target_core_base.h>
#include <target/target_core_backend.h>
#include <target/target_core_fabric.h>

#include "target_core_internal.h"
#include "target_core_ua.h"
37
#include "target_core_alua.h"
38

39 40
static sense_reason_t
sbc_check_prot(struct se_device *, struct se_cmd *, unsigned char *, u32, bool);
41
static sense_reason_t sbc_execute_unmap(struct se_cmd *cmd);
42

43 44
static sense_reason_t
sbc_emulate_readcapacity(struct se_cmd *cmd)
45 46
{
	struct se_device *dev = cmd->se_dev;
47
	unsigned char *cdb = cmd->t_task_cdb;
48
	unsigned long long blocks_long = dev->transport->get_blocks(dev);
49 50
	unsigned char *rbuf;
	unsigned char buf[8];
51 52
	u32 blocks;

53 54 55 56 57 58 59 60 61 62 63 64 65 66 67
	/*
	 * SBC-2 says:
	 *   If the PMI bit is set to zero and the LOGICAL BLOCK
	 *   ADDRESS field is not set to zero, the device server shall
	 *   terminate the command with CHECK CONDITION status with
	 *   the sense key set to ILLEGAL REQUEST and the additional
	 *   sense code set to INVALID FIELD IN CDB.
	 *
	 * In SBC-3, these fields are obsolete, but some SCSI
	 * compliance tests actually check this, so we might as well
	 * follow SBC-2.
	 */
	if (!(cdb[8] & 1) && !!(cdb[2] | cdb[3] | cdb[4] | cdb[5]))
		return TCM_INVALID_CDB_FIELD;

68 69 70 71 72 73 74 75 76
	if (blocks_long >= 0x00000000ffffffff)
		blocks = 0xffffffff;
	else
		blocks = (u32)blocks_long;

	buf[0] = (blocks >> 24) & 0xff;
	buf[1] = (blocks >> 16) & 0xff;
	buf[2] = (blocks >> 8) & 0xff;
	buf[3] = blocks & 0xff;
77 78 79 80
	buf[4] = (dev->dev_attrib.block_size >> 24) & 0xff;
	buf[5] = (dev->dev_attrib.block_size >> 16) & 0xff;
	buf[6] = (dev->dev_attrib.block_size >> 8) & 0xff;
	buf[7] = dev->dev_attrib.block_size & 0xff;
81

82
	rbuf = transport_kmap_data_sg(cmd);
83 84 85 86
	if (rbuf) {
		memcpy(rbuf, buf, min_t(u32, sizeof(buf), cmd->data_length));
		transport_kunmap_data_sg(cmd);
	}
87

88
	target_complete_cmd_with_length(cmd, GOOD, 8);
89 90 91
	return 0;
}

92 93
static sense_reason_t
sbc_emulate_readcapacity_16(struct se_cmd *cmd)
94 95
{
	struct se_device *dev = cmd->se_dev;
96
	struct se_session *sess = cmd->se_sess;
97 98
	int pi_prot_type = dev->dev_attrib.pi_prot_type;

99 100
	unsigned char *rbuf;
	unsigned char buf[32];
101 102
	unsigned long long blocks = dev->transport->get_blocks(dev);

103
	memset(buf, 0, sizeof(buf));
104 105 106 107 108 109 110 111
	buf[0] = (blocks >> 56) & 0xff;
	buf[1] = (blocks >> 48) & 0xff;
	buf[2] = (blocks >> 40) & 0xff;
	buf[3] = (blocks >> 32) & 0xff;
	buf[4] = (blocks >> 24) & 0xff;
	buf[5] = (blocks >> 16) & 0xff;
	buf[6] = (blocks >> 8) & 0xff;
	buf[7] = blocks & 0xff;
112 113 114 115
	buf[8] = (dev->dev_attrib.block_size >> 24) & 0xff;
	buf[9] = (dev->dev_attrib.block_size >> 16) & 0xff;
	buf[10] = (dev->dev_attrib.block_size >> 8) & 0xff;
	buf[11] = dev->dev_attrib.block_size & 0xff;
116 117 118
	/*
	 * Set P_TYPE and PROT_EN bits for DIF support
	 */
119
	if (sess->sup_prot_ops & (TARGET_PROT_DIN_PASS | TARGET_PROT_DOUT_PASS)) {
120 121 122 123 124 125 126 127 128
		/*
		 * Only override a device's pi_prot_type if no T10-PI is
		 * available, and sess_prot_type has been explicitly enabled.
		 */
		if (!pi_prot_type)
			pi_prot_type = sess->sess_prot_type;

		if (pi_prot_type)
			buf[12] = (pi_prot_type - 1) << 1 | 0x1;
129
	}
130 131 132 133 134 135 136 137 138 139

	if (dev->transport->get_lbppbe)
		buf[13] = dev->transport->get_lbppbe(dev) & 0x0f;

	if (dev->transport->get_alignment_offset_lbas) {
		u16 lalba = dev->transport->get_alignment_offset_lbas(dev);
		buf[14] = (lalba >> 8) & 0x3f;
		buf[15] = lalba & 0xff;
	}

140 141 142 143
	/*
	 * Set Thin Provisioning Enable bit following sbc3r22 in section
	 * READ CAPACITY (16) byte 14 if emulate_tpu or emulate_tpws is enabled.
	 */
144
	if (dev->dev_attrib.emulate_tpu || dev->dev_attrib.emulate_tpws)
145
		buf[14] |= 0x80;
146

147
	rbuf = transport_kmap_data_sg(cmd);
148 149 150 151
	if (rbuf) {
		memcpy(rbuf, buf, min_t(u32, sizeof(buf), cmd->data_length));
		transport_kunmap_data_sg(cmd);
	}
152

153
	target_complete_cmd_with_length(cmd, GOOD, 32);
154 155 156
	return 0;
}

157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188
static sense_reason_t
sbc_emulate_startstop(struct se_cmd *cmd)
{
	unsigned char *cdb = cmd->t_task_cdb;

	/*
	 * See sbc3r36 section 5.25
	 * Immediate bit should be set since there is nothing to complete
	 * POWER CONDITION MODIFIER 0h
	 */
	if (!(cdb[1] & 1) || cdb[2] || cdb[3])
		return TCM_INVALID_CDB_FIELD;

	/*
	 * See sbc3r36 section 5.25
	 * POWER CONDITION 0h START_VALID - process START and LOEJ
	 */
	if (cdb[4] >> 4 & 0xf)
		return TCM_INVALID_CDB_FIELD;

	/*
	 * See sbc3r36 section 5.25
	 * LOEJ 0h - nothing to load or unload
	 * START 1h - we are ready
	 */
	if (!(cdb[4] & 1) || (cdb[4] & 2) || (cdb[4] & 4))
		return TCM_INVALID_CDB_FIELD;

	target_complete_cmd(cmd, SAM_STAT_GOOD);
	return 0;
}

189
sector_t sbc_get_write_same_sectors(struct se_cmd *cmd)
190 191 192 193 194 195 196 197 198 199 200 201 202 203
{
	u32 num_blocks;

	if (cmd->t_task_cdb[0] == WRITE_SAME)
		num_blocks = get_unaligned_be16(&cmd->t_task_cdb[7]);
	else if (cmd->t_task_cdb[0] == WRITE_SAME_16)
		num_blocks = get_unaligned_be32(&cmd->t_task_cdb[10]);
	else /* WRITE_SAME_32 via VARIABLE_LENGTH_CMD */
		num_blocks = get_unaligned_be32(&cmd->t_task_cdb[28]);

	/*
	 * Use the explicit range when non zero is supplied, otherwise calculate
	 * the remaining range based on ->get_blocks() - starting LBA.
	 */
204 205
	if (num_blocks)
		return num_blocks;
206

207 208
	return cmd->se_dev->transport->get_blocks(cmd->se_dev) -
		cmd->t_task_lba + 1;
209
}
210
EXPORT_SYMBOL(sbc_get_write_same_sectors);
211

212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228
static sense_reason_t
sbc_execute_write_same_unmap(struct se_cmd *cmd)
{
	struct sbc_ops *ops = cmd->protocol_data;
	sector_t nolb = sbc_get_write_same_sectors(cmd);
	sense_reason_t ret;

	if (nolb) {
		ret = ops->execute_unmap(cmd, cmd->t_task_lba, nolb);
		if (ret)
			return ret;
	}

	target_complete_cmd(cmd, GOOD);
	return 0;
}

229
static sense_reason_t
230
sbc_emulate_noop(struct se_cmd *cmd)
231 232 233 234 235
{
	target_complete_cmd(cmd, GOOD);
	return 0;
}

236 237
static inline u32 sbc_get_size(struct se_cmd *cmd, u32 sectors)
{
238
	return cmd->se_dev->dev_attrib.block_size * sectors;
239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312
}

static inline u32 transport_get_sectors_6(unsigned char *cdb)
{
	/*
	 * Use 8-bit sector value.  SBC-3 says:
	 *
	 *   A TRANSFER LENGTH field set to zero specifies that 256
	 *   logical blocks shall be written.  Any other value
	 *   specifies the number of logical blocks that shall be
	 *   written.
	 */
	return cdb[4] ? : 256;
}

static inline u32 transport_get_sectors_10(unsigned char *cdb)
{
	return (u32)(cdb[7] << 8) + cdb[8];
}

static inline u32 transport_get_sectors_12(unsigned char *cdb)
{
	return (u32)(cdb[6] << 24) + (cdb[7] << 16) + (cdb[8] << 8) + cdb[9];
}

static inline u32 transport_get_sectors_16(unsigned char *cdb)
{
	return (u32)(cdb[10] << 24) + (cdb[11] << 16) +
		    (cdb[12] << 8) + cdb[13];
}

/*
 * Used for VARIABLE_LENGTH_CDB WRITE_32 and READ_32 variants
 */
static inline u32 transport_get_sectors_32(unsigned char *cdb)
{
	return (u32)(cdb[28] << 24) + (cdb[29] << 16) +
		    (cdb[30] << 8) + cdb[31];

}

static inline u32 transport_lba_21(unsigned char *cdb)
{
	return ((cdb[1] & 0x1f) << 16) | (cdb[2] << 8) | cdb[3];
}

static inline u32 transport_lba_32(unsigned char *cdb)
{
	return (cdb[2] << 24) | (cdb[3] << 16) | (cdb[4] << 8) | cdb[5];
}

static inline unsigned long long transport_lba_64(unsigned char *cdb)
{
	unsigned int __v1, __v2;

	__v1 = (cdb[2] << 24) | (cdb[3] << 16) | (cdb[4] << 8) | cdb[5];
	__v2 = (cdb[6] << 24) | (cdb[7] << 16) | (cdb[8] << 8) | cdb[9];

	return ((unsigned long long)__v2) | (unsigned long long)__v1 << 32;
}

/*
 * For VARIABLE_LENGTH_CDB w/ 32 byte extended CDBs
 */
static inline unsigned long long transport_lba_64_ext(unsigned char *cdb)
{
	unsigned int __v1, __v2;

	__v1 = (cdb[12] << 24) | (cdb[13] << 16) | (cdb[14] << 8) | cdb[15];
	__v2 = (cdb[16] << 24) | (cdb[17] << 16) | (cdb[18] << 8) | cdb[19];

	return ((unsigned long long)__v2) | (unsigned long long)__v1 << 32;
}

313 314
static sense_reason_t
sbc_setup_write_same(struct se_cmd *cmd, unsigned char *flags, struct sbc_ops *ops)
315
{
316 317
	struct se_device *dev = cmd->se_dev;
	sector_t end_lba = dev->transport->get_blocks(dev) + 1;
318
	unsigned int sectors = sbc_get_write_same_sectors(cmd);
319
	sense_reason_t ret;
320

321 322 323 324
	if ((flags[0] & 0x04) || (flags[0] & 0x02)) {
		pr_err("WRITE_SAME PBDATA and LBDATA"
			" bits not supported for Block Discard"
			" Emulation\n");
325
		return TCM_UNSUPPORTED_SCSI_OPCODE;
326
	}
327 328 329 330 331
	if (sectors > cmd->se_dev->dev_attrib.max_write_same_len) {
		pr_warn("WRITE_SAME sectors: %u exceeds max_write_same_len: %u\n",
			sectors, cmd->se_dev->dev_attrib.max_write_same_len);
		return TCM_INVALID_CDB_FIELD;
	}
332 333 334 335 336 337 338 339 340 341
	/*
	 * Sanity check for LBA wrap and request past end of device.
	 */
	if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
	    ((cmd->t_task_lba + sectors) > end_lba)) {
		pr_err("WRITE_SAME exceeds last lba %llu (lba %llu, sectors %u)\n",
		       (unsigned long long)end_lba, cmd->t_task_lba, sectors);
		return TCM_ADDRESS_OUT_OF_RANGE;
	}

342 343 344 345 346
	/* We always have ANC_SUP == 0 so setting ANCHOR is always an error */
	if (flags[0] & 0x10) {
		pr_warn("WRITE SAME with ANCHOR not supported\n");
		return TCM_INVALID_CDB_FIELD;
	}
347
	/*
348 349
	 * Special case for WRITE_SAME w/ UNMAP=1 that ends up getting
	 * translated into block discard requests within backend code.
350
	 */
351
	if (flags[0] & 0x08) {
352
		if (!ops->execute_unmap)
353 354
			return TCM_UNSUPPORTED_SCSI_OPCODE;

355 356 357 358 359
		if (!dev->dev_attrib.emulate_tpws) {
			pr_err("Got WRITE_SAME w/ UNMAP=1, but backend device"
			       " has emulate_tpws disabled\n");
			return TCM_UNSUPPORTED_SCSI_OPCODE;
		}
360
		cmd->execute_cmd = sbc_execute_write_same_unmap;
361
		return 0;
362
	}
363 364
	if (!ops->execute_write_same)
		return TCM_UNSUPPORTED_SCSI_OPCODE;
365

366 367 368 369
	ret = sbc_check_prot(dev, cmd, &cmd->t_task_cdb[0], sectors, true);
	if (ret)
		return ret;

370
	cmd->execute_cmd = ops->execute_write_same;
371 372 373
	return 0;
}

374 375
static sense_reason_t xdreadwrite_callback(struct se_cmd *cmd, bool success,
					   int *post_ret)
376 377 378 379
{
	unsigned char *buf, *addr;
	struct scatterlist *sg;
	unsigned int offset;
380 381
	sense_reason_t ret = TCM_NO_SENSE;
	int i, count;
382 383 384 385 386 387 388 389 390 391 392 393 394 395
	/*
	 * From sbc3r22.pdf section 5.48 XDWRITEREAD (10) command
	 *
	 * 1) read the specified logical block(s);
	 * 2) transfer logical blocks from the data-out buffer;
	 * 3) XOR the logical blocks transferred from the data-out buffer with
	 *    the logical blocks read, storing the resulting XOR data in a buffer;
	 * 4) if the DISABLE WRITE bit is set to zero, then write the logical
	 *    blocks transferred from the data-out buffer; and
	 * 5) transfer the resulting XOR data to the data-in buffer.
	 */
	buf = kmalloc(cmd->data_length, GFP_KERNEL);
	if (!buf) {
		pr_err("Unable to allocate xor_callback buf\n");
396
		return TCM_OUT_OF_RESOURCES;
397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414
	}
	/*
	 * Copy the scatterlist WRITE buffer located at cmd->t_data_sg
	 * into the locally allocated *buf
	 */
	sg_copy_to_buffer(cmd->t_data_sg,
			  cmd->t_data_nents,
			  buf,
			  cmd->data_length);

	/*
	 * Now perform the XOR against the BIDI read memory located at
	 * cmd->t_mem_bidi_list
	 */

	offset = 0;
	for_each_sg(cmd->t_bidi_data_sg, sg, cmd->t_bidi_data_nents, count) {
		addr = kmap_atomic(sg_page(sg));
415 416
		if (!addr) {
			ret = TCM_OUT_OF_RESOURCES;
417
			goto out;
418
		}
419 420 421 422 423 424 425 426 427 428

		for (i = 0; i < sg->length; i++)
			*(addr + sg->offset + i) ^= *(buf + offset + i);

		offset += sg->length;
		kunmap_atomic(addr);
	}

out:
	kfree(buf);
429
	return ret;
430 431
}

432 433 434
static sense_reason_t
sbc_execute_rw(struct se_cmd *cmd)
{
435 436 437
	struct sbc_ops *ops = cmd->protocol_data;

	return ops->execute_rw(cmd, cmd->t_data_sg, cmd->t_data_nents,
438 439 440
			       cmd->data_direction);
}

441 442
static sense_reason_t compare_and_write_post(struct se_cmd *cmd, bool success,
					     int *post_ret)
443 444 445
{
	struct se_device *dev = cmd->se_dev;

446 447 448 449 450 451
	/*
	 * Only set SCF_COMPARE_AND_WRITE_POST to force a response fall-through
	 * within target_complete_ok_work() if the command was successfully
	 * sent to the backend driver.
	 */
	spin_lock_irq(&cmd->t_state_lock);
452
	if ((cmd->transport_state & CMD_T_SENT) && !cmd->scsi_status) {
453
		cmd->se_cmd_flags |= SCF_COMPARE_AND_WRITE_POST;
454 455
		*post_ret = 1;
	}
456 457
	spin_unlock_irq(&cmd->t_state_lock);

458 459 460 461 462 463 464 465 466
	/*
	 * Unlock ->caw_sem originally obtained during sbc_compare_and_write()
	 * before the original READ I/O submission.
	 */
	up(&dev->caw_sem);

	return TCM_NO_SENSE;
}

467 468
static sense_reason_t compare_and_write_callback(struct se_cmd *cmd, bool success,
						 int *post_ret)
469 470 471
{
	struct se_device *dev = cmd->se_dev;
	struct scatterlist *write_sg = NULL, *sg;
472
	unsigned char *buf = NULL, *addr;
473 474 475 476 477 478 479 480
	struct sg_mapping_iter m;
	unsigned int offset = 0, len;
	unsigned int nlbas = cmd->t_task_nolb;
	unsigned int block_size = dev->dev_attrib.block_size;
	unsigned int compare_len = (nlbas * block_size);
	sense_reason_t ret = TCM_NO_SENSE;
	int rc, i;

481 482
	/*
	 * Handle early failure in transport_generic_request_failure(),
483
	 * which will not have taken ->caw_sem yet..
484
	 */
485
	if (!success && (!cmd->t_data_sg || !cmd->t_bidi_data_sg))
486
		return TCM_NO_SENSE;
487 488 489 490 491
	/*
	 * Handle special case for zero-length COMPARE_AND_WRITE
	 */
	if (!cmd->data_length)
		goto out;
492 493 494 495 496 497 498 499 500
	/*
	 * Immediately exit + release dev->caw_sem if command has already
	 * been failed with a non-zero SCSI status.
	 */
	if (cmd->scsi_status) {
		pr_err("compare_and_write_callback: non zero scsi_status:"
			" 0x%02x\n", cmd->scsi_status);
		goto out;
	}
501

502 503 504
	buf = kzalloc(cmd->data_length, GFP_KERNEL);
	if (!buf) {
		pr_err("Unable to allocate compare_and_write buf\n");
505 506
		ret = TCM_OUT_OF_RESOURCES;
		goto out;
507 508
	}

509
	write_sg = kmalloc(sizeof(struct scatterlist) * cmd->t_data_nents,
510 511 512 513 514 515
			   GFP_KERNEL);
	if (!write_sg) {
		pr_err("Unable to allocate compare_and_write sg\n");
		ret = TCM_OUT_OF_RESOURCES;
		goto out;
	}
516
	sg_init_table(write_sg, cmd->t_data_nents);
517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583
	/*
	 * Setup verify and write data payloads from total NumberLBAs.
	 */
	rc = sg_copy_to_buffer(cmd->t_data_sg, cmd->t_data_nents, buf,
			       cmd->data_length);
	if (!rc) {
		pr_err("sg_copy_to_buffer() failed for compare_and_write\n");
		ret = TCM_OUT_OF_RESOURCES;
		goto out;
	}
	/*
	 * Compare against SCSI READ payload against verify payload
	 */
	for_each_sg(cmd->t_bidi_data_sg, sg, cmd->t_bidi_data_nents, i) {
		addr = (unsigned char *)kmap_atomic(sg_page(sg));
		if (!addr) {
			ret = TCM_OUT_OF_RESOURCES;
			goto out;
		}

		len = min(sg->length, compare_len);

		if (memcmp(addr, buf + offset, len)) {
			pr_warn("Detected MISCOMPARE for addr: %p buf: %p\n",
				addr, buf + offset);
			kunmap_atomic(addr);
			goto miscompare;
		}
		kunmap_atomic(addr);

		offset += len;
		compare_len -= len;
		if (!compare_len)
			break;
	}

	i = 0;
	len = cmd->t_task_nolb * block_size;
	sg_miter_start(&m, cmd->t_data_sg, cmd->t_data_nents, SG_MITER_TO_SG);
	/*
	 * Currently assumes NoLB=1 and SGLs are PAGE_SIZE..
	 */
	while (len) {
		sg_miter_next(&m);

		if (block_size < PAGE_SIZE) {
			sg_set_page(&write_sg[i], m.page, block_size,
				    block_size);
		} else {
			sg_miter_next(&m);
			sg_set_page(&write_sg[i], m.page, block_size,
				    0);
		}
		len -= block_size;
		i++;
	}
	sg_miter_stop(&m);
	/*
	 * Save the original SGL + nents values before updating to new
	 * assignments, to be released in transport_free_pages() ->
	 * transport_reset_sgl_orig()
	 */
	cmd->t_data_sg_orig = cmd->t_data_sg;
	cmd->t_data_sg = write_sg;
	cmd->t_data_nents_orig = cmd->t_data_nents;
	cmd->t_data_nents = 1;

C
Christoph Hellwig 已提交
584
	cmd->sam_task_attr = TCM_HEAD_TAG;
585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619
	cmd->transport_complete_callback = compare_and_write_post;
	/*
	 * Now reset ->execute_cmd() to the normal sbc_execute_rw() handler
	 * for submitting the adjusted SGL to write instance user-data.
	 */
	cmd->execute_cmd = sbc_execute_rw;

	spin_lock_irq(&cmd->t_state_lock);
	cmd->t_state = TRANSPORT_PROCESSING;
	cmd->transport_state |= CMD_T_ACTIVE|CMD_T_BUSY|CMD_T_SENT;
	spin_unlock_irq(&cmd->t_state_lock);

	__target_execute_cmd(cmd);

	kfree(buf);
	return ret;

miscompare:
	pr_warn("Target/%s: Send MISCOMPARE check condition and sense\n",
		dev->transport->name);
	ret = TCM_MISCOMPARE_VERIFY;
out:
	/*
	 * In the MISCOMPARE or failure case, unlock ->caw_sem obtained in
	 * sbc_compare_and_write() before the original READ I/O submission.
	 */
	up(&dev->caw_sem);
	kfree(write_sg);
	kfree(buf);
	return ret;
}

static sense_reason_t
sbc_compare_and_write(struct se_cmd *cmd)
{
620
	struct sbc_ops *ops = cmd->protocol_data;
621 622 623 624 625 626 627 628
	struct se_device *dev = cmd->se_dev;
	sense_reason_t ret;
	int rc;
	/*
	 * Submit the READ first for COMPARE_AND_WRITE to perform the
	 * comparision using SGLs at cmd->t_bidi_data_sg..
	 */
	rc = down_interruptible(&dev->caw_sem);
629
	if (rc != 0) {
630 631 632
		cmd->transport_complete_callback = NULL;
		return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;
	}
633 634 635 636 637 638
	/*
	 * Reset cmd->data_length to individual block_size in order to not
	 * confuse backend drivers that depend on this value matching the
	 * size of the I/O being submitted.
	 */
	cmd->data_length = cmd->t_task_nolb * dev->dev_attrib.block_size;
639

640
	ret = ops->execute_rw(cmd, cmd->t_bidi_data_sg, cmd->t_bidi_data_nents,
641 642 643 644 645 646 647 648 649 650 651 652 653 654
			      DMA_FROM_DEVICE);
	if (ret) {
		cmd->transport_complete_callback = NULL;
		up(&dev->caw_sem);
		return ret;
	}
	/*
	 * Unlock of dev->caw_sem to occur in compare_and_write_callback()
	 * upon MISCOMPARE, or in compare_and_write_done() upon completion
	 * of WRITE instance user-data.
	 */
	return TCM_NO_SENSE;
}

655
static int
656
sbc_set_prot_op_checks(u8 protect, bool fabric_prot, enum target_prot_type prot_type,
657 658 659
		       bool is_write, struct se_cmd *cmd)
{
	if (is_write) {
660 661 662
		cmd->prot_op = fabric_prot ? TARGET_PROT_DOUT_STRIP :
			       protect ? TARGET_PROT_DOUT_PASS :
			       TARGET_PROT_DOUT_INSERT;
663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685
		switch (protect) {
		case 0x0:
		case 0x3:
			cmd->prot_checks = 0;
			break;
		case 0x1:
		case 0x5:
			cmd->prot_checks = TARGET_DIF_CHECK_GUARD;
			if (prot_type == TARGET_DIF_TYPE1_PROT)
				cmd->prot_checks |= TARGET_DIF_CHECK_REFTAG;
			break;
		case 0x2:
			if (prot_type == TARGET_DIF_TYPE1_PROT)
				cmd->prot_checks = TARGET_DIF_CHECK_REFTAG;
			break;
		case 0x4:
			cmd->prot_checks = TARGET_DIF_CHECK_GUARD;
			break;
		default:
			pr_err("Unsupported protect field %d\n", protect);
			return -EINVAL;
		}
	} else {
686 687 688
		cmd->prot_op = fabric_prot ? TARGET_PROT_DIN_INSERT :
			       protect ? TARGET_PROT_DIN_PASS :
			       TARGET_PROT_DIN_STRIP;
689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715
		switch (protect) {
		case 0x0:
		case 0x1:
		case 0x5:
			cmd->prot_checks = TARGET_DIF_CHECK_GUARD;
			if (prot_type == TARGET_DIF_TYPE1_PROT)
				cmd->prot_checks |= TARGET_DIF_CHECK_REFTAG;
			break;
		case 0x2:
			if (prot_type == TARGET_DIF_TYPE1_PROT)
				cmd->prot_checks = TARGET_DIF_CHECK_REFTAG;
			break;
		case 0x3:
			cmd->prot_checks = 0;
			break;
		case 0x4:
			cmd->prot_checks = TARGET_DIF_CHECK_GUARD;
			break;
		default:
			pr_err("Unsupported protect field %d\n", protect);
			return -EINVAL;
		}
	}

	return 0;
}

716
static sense_reason_t
717
sbc_check_prot(struct se_device *dev, struct se_cmd *cmd, unsigned char *cdb,
718
	       u32 sectors, bool is_write)
719
{
720
	u8 protect = cdb[1] >> 5;
721 722 723
	int sp_ops = cmd->se_sess->sup_prot_ops;
	int pi_prot_type = dev->dev_attrib.pi_prot_type;
	bool fabric_prot = false;
724

725
	if (!cmd->t_prot_sg || !cmd->t_prot_nents) {
726 727 728 729
		if (unlikely(protect &&
		    !dev->dev_attrib.pi_prot_type && !cmd->se_sess->sess_prot_type)) {
			pr_err("CDB contains protect bit, but device + fabric does"
			       " not advertise PROTECT=1 feature bit\n");
730 731 732 733 734
			return TCM_INVALID_CDB_FIELD;
		}
		if (cmd->prot_pto)
			return TCM_NO_SENSE;
	}
735 736 737 738 739 740

	switch (dev->dev_attrib.pi_prot_type) {
	case TARGET_DIF_TYPE3_PROT:
		cmd->reftag_seed = 0xffffffff;
		break;
	case TARGET_DIF_TYPE2_PROT:
741
		if (protect)
742
			return TCM_INVALID_CDB_FIELD;
743 744 745 746 747 748 749

		cmd->reftag_seed = cmd->t_task_lba;
		break;
	case TARGET_DIF_TYPE1_PROT:
		cmd->reftag_seed = cmd->t_task_lba;
		break;
	case TARGET_DIF_TYPE0_PROT:
750 751 752 753 754 755 756 757 758 759 760 761 762
		/*
		 * See if the fabric supports T10-PI, and the session has been
		 * configured to allow export PROTECT=1 feature bit with backend
		 * devices that don't support T10-PI.
		 */
		fabric_prot = is_write ?
			      !!(sp_ops & (TARGET_PROT_DOUT_PASS | TARGET_PROT_DOUT_STRIP)) :
			      !!(sp_ops & (TARGET_PROT_DIN_PASS | TARGET_PROT_DIN_INSERT));

		if (fabric_prot && cmd->se_sess->sess_prot_type) {
			pi_prot_type = cmd->se_sess->sess_prot_type;
			break;
		}
763 764
		if (!protect)
			return TCM_NO_SENSE;
765
		/* Fallthrough */
766
	default:
767 768 769
		pr_err("Unable to determine pi_prot_type for CDB: 0x%02x "
		       "PROTECT: 0x%02x\n", cdb[0], protect);
		return TCM_INVALID_CDB_FIELD;
770 771
	}

772
	if (sbc_set_prot_op_checks(protect, fabric_prot, pi_prot_type, is_write, cmd))
773
		return TCM_INVALID_CDB_FIELD;
774

775
	cmd->prot_type = pi_prot_type;
776
	cmd->prot_length = dev->prot_length * sectors;
777 778 779 780 781 782 783 784 785 786 787 788 789

	/**
	 * In case protection information exists over the wire
	 * we modify command data length to describe pure data.
	 * The actual transfer length is data length + protection
	 * length
	 **/
	if (protect)
		cmd->data_length = sectors * dev->dev_attrib.block_size;

	pr_debug("%s: prot_type=%d, data_length=%d, prot_length=%d "
		 "prot_op=%d prot_checks=%d\n",
		 __func__, cmd->prot_type, cmd->data_length, cmd->prot_length,
S
Sagi Grimberg 已提交
790
		 cmd->prot_op, cmd->prot_checks);
791

792
	return TCM_NO_SENSE;
793 794
}

795 796 797 798
static int
sbc_check_dpofua(struct se_device *dev, struct se_cmd *cmd, unsigned char *cdb)
{
	if (cdb[1] & 0x10) {
799 800
		/* see explanation in spc_emulate_modesense */
		if (!target_check_fua(dev)) {
801 802 803 804 805 806
			pr_err("Got CDB: 0x%02x with DPO bit set, but device"
			       " does not advertise support for DPO\n", cdb[0]);
			return -EINVAL;
		}
	}
	if (cdb[1] & 0x8) {
807
		if (!target_check_fua(dev)) {
808 809 810 811 812 813 814 815
			pr_err("Got CDB: 0x%02x with FUA bit set, but device"
			       " does not advertise support for FUA write\n",
			       cdb[0]);
			return -EINVAL;
		}
		cmd->se_cmd_flags |= SCF_FUA;
	}
	return 0;
816 817
}

818 819
sense_reason_t
sbc_parse_cdb(struct se_cmd *cmd, struct sbc_ops *ops)
820 821 822
{
	struct se_device *dev = cmd->se_dev;
	unsigned char *cdb = cmd->t_task_cdb;
823
	unsigned int size;
824
	u32 sectors = 0;
825
	sense_reason_t ret;
826

827 828
	cmd->protocol_data = ops;

829 830 831 832 833
	switch (cdb[0]) {
	case READ_6:
		sectors = transport_get_sectors_6(cdb);
		cmd->t_task_lba = transport_lba_21(cdb);
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
834
		cmd->execute_cmd = sbc_execute_rw;
835 836 837 838
		break;
	case READ_10:
		sectors = transport_get_sectors_10(cdb);
		cmd->t_task_lba = transport_lba_32(cdb);
839

840 841 842
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

843 844 845
		ret = sbc_check_prot(dev, cmd, cdb, sectors, false);
		if (ret)
			return ret;
846

847
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
848
		cmd->execute_cmd = sbc_execute_rw;
849 850 851 852
		break;
	case READ_12:
		sectors = transport_get_sectors_12(cdb);
		cmd->t_task_lba = transport_lba_32(cdb);
853

854 855 856
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

857 858 859
		ret = sbc_check_prot(dev, cmd, cdb, sectors, false);
		if (ret)
			return ret;
860

861
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
862
		cmd->execute_cmd = sbc_execute_rw;
863 864 865 866
		break;
	case READ_16:
		sectors = transport_get_sectors_16(cdb);
		cmd->t_task_lba = transport_lba_64(cdb);
867

868 869 870
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

871 872 873
		ret = sbc_check_prot(dev, cmd, cdb, sectors, false);
		if (ret)
			return ret;
874

875
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
876
		cmd->execute_cmd = sbc_execute_rw;
877 878 879 880 881
		break;
	case WRITE_6:
		sectors = transport_get_sectors_6(cdb);
		cmd->t_task_lba = transport_lba_21(cdb);
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
882
		cmd->execute_cmd = sbc_execute_rw;
883 884 885 886 887
		break;
	case WRITE_10:
	case WRITE_VERIFY:
		sectors = transport_get_sectors_10(cdb);
		cmd->t_task_lba = transport_lba_32(cdb);
888

889 890 891
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

892 893 894
		ret = sbc_check_prot(dev, cmd, cdb, sectors, true);
		if (ret)
			return ret;
895

896
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
897
		cmd->execute_cmd = sbc_execute_rw;
898 899 900 901
		break;
	case WRITE_12:
		sectors = transport_get_sectors_12(cdb);
		cmd->t_task_lba = transport_lba_32(cdb);
902

903 904 905
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

906 907 908
		ret = sbc_check_prot(dev, cmd, cdb, sectors, true);
		if (ret)
			return ret;
909

910
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
911
		cmd->execute_cmd = sbc_execute_rw;
912 913 914 915
		break;
	case WRITE_16:
		sectors = transport_get_sectors_16(cdb);
		cmd->t_task_lba = transport_lba_64(cdb);
916

917 918 919
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

920 921 922
		ret = sbc_check_prot(dev, cmd, cdb, sectors, true);
		if (ret)
			return ret;
923

924
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;
925
		cmd->execute_cmd = sbc_execute_rw;
926 927
		break;
	case XDWRITEREAD_10:
928
		if (cmd->data_direction != DMA_TO_DEVICE ||
929
		    !(cmd->se_cmd_flags & SCF_BIDI))
930
			return TCM_INVALID_CDB_FIELD;
931 932
		sectors = transport_get_sectors_10(cdb);

933 934 935
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

936 937 938 939 940 941
		cmd->t_task_lba = transport_lba_32(cdb);
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;

		/*
		 * Setup BIDI XOR callback to be run after I/O completion.
		 */
942
		cmd->execute_cmd = sbc_execute_rw;
943 944 945 946 947 948 949 950 951
		cmd->transport_complete_callback = &xdreadwrite_callback;
		break;
	case VARIABLE_LENGTH_CMD:
	{
		u16 service_action = get_unaligned_be16(&cdb[8]);
		switch (service_action) {
		case XDWRITEREAD_32:
			sectors = transport_get_sectors_32(cdb);

952 953
			if (sbc_check_dpofua(dev, cmd, cdb))
				return TCM_INVALID_CDB_FIELD;
954 955 956 957 958 959 960 961 962 963 964
			/*
			 * Use WRITE_32 and READ_32 opcodes for the emulated
			 * XDWRITE_READ_32 logic.
			 */
			cmd->t_task_lba = transport_lba_64_ext(cdb);
			cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB;

			/*
			 * Setup BIDI XOR callback to be run during after I/O
			 * completion.
			 */
965
			cmd->execute_cmd = sbc_execute_rw;
966 967 968 969 970 971 972
			cmd->transport_complete_callback = &xdreadwrite_callback;
			break;
		case WRITE_SAME_32:
			sectors = transport_get_sectors_32(cdb);
			if (!sectors) {
				pr_err("WSNZ=1, WRITE_SAME w/sectors=0 not"
				       " supported\n");
973
				return TCM_INVALID_CDB_FIELD;
974 975
			}

976
			size = sbc_get_size(cmd, 1);
977 978
			cmd->t_task_lba = get_unaligned_be64(&cdb[12]);

979
			ret = sbc_setup_write_same(cmd, &cdb[10], ops);
980
			if (ret)
981
				return ret;
982 983 984 985
			break;
		default:
			pr_err("VARIABLE_LENGTH_CMD service action"
				" 0x%04x not supported\n", service_action);
986
			return TCM_UNSUPPORTED_SCSI_OPCODE;
987 988 989
		}
		break;
	}
990 991 992 993 994 995 996 997 998 999
	case COMPARE_AND_WRITE:
		sectors = cdb[13];
		/*
		 * Currently enforce COMPARE_AND_WRITE for a single sector
		 */
		if (sectors > 1) {
			pr_err("COMPARE_AND_WRITE contains NoLB: %u greater"
			       " than 1\n", sectors);
			return TCM_INVALID_CDB_FIELD;
		}
1000 1001 1002
		if (sbc_check_dpofua(dev, cmd, cdb))
			return TCM_INVALID_CDB_FIELD;

1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013
		/*
		 * Double size because we have two buffers, note that
		 * zero is not an error..
		 */
		size = 2 * sbc_get_size(cmd, sectors);
		cmd->t_task_lba = get_unaligned_be64(&cdb[2]);
		cmd->t_task_nolb = sectors;
		cmd->se_cmd_flags |= SCF_SCSI_DATA_CDB | SCF_COMPARE_AND_WRITE;
		cmd->execute_cmd = sbc_compare_and_write;
		cmd->transport_complete_callback = compare_and_write_callback;
		break;
1014
	case READ_CAPACITY:
1015 1016
		size = READ_CAP_LEN;
		cmd->execute_cmd = sbc_emulate_readcapacity;
1017
		break;
1018
	case SERVICE_ACTION_IN_16:
1019 1020
		switch (cmd->t_task_cdb[1] & 0x1f) {
		case SAI_READ_CAPACITY_16:
1021
			cmd->execute_cmd = sbc_emulate_readcapacity_16;
1022
			break;
1023 1024 1025
		case SAI_REPORT_REFERRALS:
			cmd->execute_cmd = target_emulate_report_referrals;
			break;
1026 1027 1028
		default:
			pr_err("Unsupported SA: 0x%02x\n",
				cmd->t_task_cdb[1] & 0x1f);
1029
			return TCM_INVALID_CDB_FIELD;
1030
		}
1031
		size = (cdb[10] << 24) | (cdb[11] << 16) |
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042
		       (cdb[12] << 8) | cdb[13];
		break;
	case SYNCHRONIZE_CACHE:
	case SYNCHRONIZE_CACHE_16:
		if (cdb[0] == SYNCHRONIZE_CACHE) {
			sectors = transport_get_sectors_10(cdb);
			cmd->t_task_lba = transport_lba_32(cdb);
		} else {
			sectors = transport_get_sectors_16(cdb);
			cmd->t_task_lba = transport_lba_64(cdb);
		}
1043 1044 1045
		if (ops->execute_sync_cache) {
			cmd->execute_cmd = ops->execute_sync_cache;
			goto check_lba;
1046
		}
1047 1048
		size = 0;
		cmd->execute_cmd = sbc_emulate_noop;
1049 1050
		break;
	case UNMAP:
1051
		if (!ops->execute_unmap)
1052
			return TCM_UNSUPPORTED_SCSI_OPCODE;
1053

1054 1055 1056 1057 1058
		if (!dev->dev_attrib.emulate_tpu) {
			pr_err("Got UNMAP, but backend device has"
			       " emulate_tpu disabled\n");
			return TCM_UNSUPPORTED_SCSI_OPCODE;
		}
1059
		size = get_unaligned_be16(&cdb[7]);
1060
		cmd->execute_cmd = sbc_execute_unmap;
1061 1062 1063 1064 1065
		break;
	case WRITE_SAME_16:
		sectors = transport_get_sectors_16(cdb);
		if (!sectors) {
			pr_err("WSNZ=1, WRITE_SAME w/sectors=0 not supported\n");
1066
			return TCM_INVALID_CDB_FIELD;
1067 1068
		}

1069
		size = sbc_get_size(cmd, 1);
1070 1071
		cmd->t_task_lba = get_unaligned_be64(&cdb[2]);

1072
		ret = sbc_setup_write_same(cmd, &cdb[1], ops);
1073
		if (ret)
1074
			return ret;
1075 1076 1077 1078 1079
		break;
	case WRITE_SAME:
		sectors = transport_get_sectors_10(cdb);
		if (!sectors) {
			pr_err("WSNZ=1, WRITE_SAME w/sectors=0 not supported\n");
1080
			return TCM_INVALID_CDB_FIELD;
1081 1082
		}

1083
		size = sbc_get_size(cmd, 1);
1084 1085 1086 1087 1088 1089
		cmd->t_task_lba = get_unaligned_be32(&cdb[2]);

		/*
		 * Follow sbcr26 with WRITE_SAME (10) and check for the existence
		 * of byte 1 bit 3 UNMAP instead of original reserved field
		 */
1090
		ret = sbc_setup_write_same(cmd, &cdb[1], ops);
1091
		if (ret)
1092
			return ret;
1093 1094
		break;
	case VERIFY:
1095
		size = 0;
1096 1097
		sectors = transport_get_sectors_10(cdb);
		cmd->t_task_lba = transport_lba_32(cdb);
1098
		cmd->execute_cmd = sbc_emulate_noop;
1099
		goto check_lba;
1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111
	case REZERO_UNIT:
	case SEEK_6:
	case SEEK_10:
		/*
		 * There are still clients out there which use these old SCSI-2
		 * commands. This mainly happens when running VMs with legacy
		 * guest systems, connected via SCSI command pass-through to
		 * iSCSI targets. Make them happy and return status GOOD.
		 */
		size = 0;
		cmd->execute_cmd = sbc_emulate_noop;
		break;
1112 1113 1114 1115
	case START_STOP:
		size = 0;
		cmd->execute_cmd = sbc_emulate_startstop;
		break;
1116
	default:
1117
		ret = spc_parse_cdb(cmd, &size);
1118 1119 1120 1121 1122
		if (ret)
			return ret;
	}

	/* reject any command that we don't have a handler for */
1123
	if (!cmd->execute_cmd)
1124
		return TCM_UNSUPPORTED_SCSI_OPCODE;
1125 1126

	if (cmd->se_cmd_flags & SCF_SCSI_DATA_CDB) {
1127
		unsigned long long end_lba;
1128
check_lba:
1129
		end_lba = dev->transport->get_blocks(dev) + 1;
1130 1131
		if (((cmd->t_task_lba + sectors) < cmd->t_task_lba) ||
		    ((cmd->t_task_lba + sectors) > end_lba)) {
1132 1133 1134
			pr_err("cmd exceeds last lba %llu "
				"(lba %llu, sectors %u)\n",
				end_lba, cmd->t_task_lba, sectors);
1135
			return TCM_ADDRESS_OUT_OF_RANGE;
1136 1137
		}

1138 1139
		if (!(cmd->se_cmd_flags & SCF_COMPARE_AND_WRITE))
			size = sbc_get_size(cmd, sectors);
1140 1141
	}

1142
	return target_cmd_size_check(cmd, size);
1143 1144
}
EXPORT_SYMBOL(sbc_parse_cdb);
1145 1146 1147 1148 1149 1150

u32 sbc_get_device_type(struct se_device *dev)
{
	return TYPE_DISK;
}
EXPORT_SYMBOL(sbc_get_device_type);
1151

1152 1153
static sense_reason_t
sbc_execute_unmap(struct se_cmd *cmd)
1154
{
1155
	struct sbc_ops *ops = cmd->protocol_data;
1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218
	struct se_device *dev = cmd->se_dev;
	unsigned char *buf, *ptr = NULL;
	sector_t lba;
	int size;
	u32 range;
	sense_reason_t ret = 0;
	int dl, bd_dl;

	/* We never set ANC_SUP */
	if (cmd->t_task_cdb[1])
		return TCM_INVALID_CDB_FIELD;

	if (cmd->data_length == 0) {
		target_complete_cmd(cmd, SAM_STAT_GOOD);
		return 0;
	}

	if (cmd->data_length < 8) {
		pr_warn("UNMAP parameter list length %u too small\n",
			cmd->data_length);
		return TCM_PARAMETER_LIST_LENGTH_ERROR;
	}

	buf = transport_kmap_data_sg(cmd);
	if (!buf)
		return TCM_LOGICAL_UNIT_COMMUNICATION_FAILURE;

	dl = get_unaligned_be16(&buf[0]);
	bd_dl = get_unaligned_be16(&buf[2]);

	size = cmd->data_length - 8;
	if (bd_dl > size)
		pr_warn("UNMAP parameter list length %u too small, ignoring bd_dl %u\n",
			cmd->data_length, bd_dl);
	else
		size = bd_dl;

	if (size / 16 > dev->dev_attrib.max_unmap_block_desc_count) {
		ret = TCM_INVALID_PARAMETER_LIST;
		goto err;
	}

	/* First UNMAP block descriptor starts at 8 byte offset */
	ptr = &buf[8];
	pr_debug("UNMAP: Sub: %s Using dl: %u bd_dl: %u size: %u"
		" ptr: %p\n", dev->transport->name, dl, bd_dl, size, ptr);

	while (size >= 16) {
		lba = get_unaligned_be64(&ptr[0]);
		range = get_unaligned_be32(&ptr[8]);
		pr_debug("UNMAP: Using lba: %llu and range: %u\n",
				 (unsigned long long)lba, range);

		if (range > dev->dev_attrib.max_unmap_lba_count) {
			ret = TCM_INVALID_PARAMETER_LIST;
			goto err;
		}

		if (lba + range > dev->transport->get_blocks(dev) + 1) {
			ret = TCM_ADDRESS_OUT_OF_RANGE;
			goto err;
		}

1219
		ret = ops->execute_unmap(cmd, lba, range);
1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232
		if (ret)
			goto err;

		ptr += 16;
		size -= 16;
	}

err:
	transport_kunmap_data_sg(cmd);
	if (!ret)
		target_complete_cmd(cmd, GOOD);
	return ret;
}
1233

1234 1235 1236 1237
void
sbc_dif_generate(struct se_cmd *cmd)
{
	struct se_device *dev = cmd->se_dev;
S
Sagi Grimberg 已提交
1238
	struct t10_pi_tuple *sdt;
1239
	struct scatterlist *dsg = cmd->t_data_sg, *psg;
1240 1241 1242
	sector_t sector = cmd->t_task_lba;
	void *daddr, *paddr;
	int i, j, offset = 0;
1243
	unsigned int block_size = dev->dev_attrib.block_size;
1244

1245
	for_each_sg(cmd->t_prot_sg, psg, cmd->t_prot_nents, i) {
1246
		paddr = kmap_atomic(sg_page(psg)) + psg->offset;
1247
		daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;
1248

1249
		for (j = 0; j < psg->length;
S
Sagi Grimberg 已提交
1250
				j += sizeof(*sdt)) {
1251 1252
			__u16 crc;
			unsigned int avail;
1253

1254 1255 1256 1257 1258 1259 1260 1261 1262
			if (offset >= dsg->length) {
				offset -= dsg->length;
				kunmap_atomic(daddr - dsg->offset);
				dsg = sg_next(dsg);
				if (!dsg) {
					kunmap_atomic(paddr - psg->offset);
					return;
				}
				daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;
1263 1264
			}

1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279
			sdt = paddr + j;
			avail = min(block_size, dsg->length - offset);
			crc = crc_t10dif(daddr + offset, avail);
			if (avail < block_size) {
				kunmap_atomic(daddr - dsg->offset);
				dsg = sg_next(dsg);
				if (!dsg) {
					kunmap_atomic(paddr - psg->offset);
					return;
				}
				daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;
				offset = block_size - avail;
				crc = crc_t10dif_update(crc, daddr, offset);
			} else {
				offset += block_size;
1280 1281
			}

1282
			sdt->guard_tag = cpu_to_be16(crc);
1283
			if (cmd->prot_type == TARGET_DIF_TYPE1_PROT)
1284 1285 1286
				sdt->ref_tag = cpu_to_be32(sector & 0xffffffff);
			sdt->app_tag = 0;

1287
			pr_debug("DIF %s INSERT sector: %llu guard_tag: 0x%04x"
1288
				 " app_tag: 0x%04x ref_tag: %u\n",
1289 1290 1291 1292
				 (cmd->data_direction == DMA_TO_DEVICE) ?
				 "WRITE" : "READ", (unsigned long long)sector,
				 sdt->guard_tag, sdt->app_tag,
				 be32_to_cpu(sdt->ref_tag));
1293 1294 1295 1296

			sector++;
		}

1297 1298
		kunmap_atomic(daddr - dsg->offset);
		kunmap_atomic(paddr - psg->offset);
1299 1300 1301
	}
}

1302
static sense_reason_t
S
Sagi Grimberg 已提交
1303
sbc_dif_v1_verify(struct se_cmd *cmd, struct t10_pi_tuple *sdt,
1304
		  __u16 crc, sector_t sector, unsigned int ei_lba)
1305 1306 1307
{
	__be16 csum;

1308 1309 1310
	if (!(cmd->prot_checks & TARGET_DIF_CHECK_GUARD))
		goto check_ref;

1311
	csum = cpu_to_be16(crc);
1312 1313 1314 1315 1316 1317 1318 1319

	if (sdt->guard_tag != csum) {
		pr_err("DIFv1 checksum failed on sector %llu guard tag 0x%04x"
			" csum 0x%04x\n", (unsigned long long)sector,
			be16_to_cpu(sdt->guard_tag), be16_to_cpu(csum));
		return TCM_LOGICAL_BLOCK_GUARD_CHECK_FAILED;
	}

1320 1321 1322 1323
check_ref:
	if (!(cmd->prot_checks & TARGET_DIF_CHECK_REFTAG))
		return 0;

1324
	if (cmd->prot_type == TARGET_DIF_TYPE1_PROT &&
1325 1326 1327 1328 1329 1330 1331
	    be32_to_cpu(sdt->ref_tag) != (sector & 0xffffffff)) {
		pr_err("DIFv1 Type 1 reference failed on sector: %llu tag: 0x%08x"
		       " sector MSB: 0x%08x\n", (unsigned long long)sector,
		       be32_to_cpu(sdt->ref_tag), (u32)(sector & 0xffffffff));
		return TCM_LOGICAL_BLOCK_REF_TAG_CHECK_FAILED;
	}

1332
	if (cmd->prot_type == TARGET_DIF_TYPE2_PROT &&
1333 1334 1335 1336 1337 1338 1339 1340 1341 1342
	    be32_to_cpu(sdt->ref_tag) != ei_lba) {
		pr_err("DIFv1 Type 2 reference failed on sector: %llu tag: 0x%08x"
		       " ei_lba: 0x%08x\n", (unsigned long long)sector,
			be32_to_cpu(sdt->ref_tag), ei_lba);
		return TCM_LOGICAL_BLOCK_REF_TAG_CHECK_FAILED;
	}

	return 0;
}

1343 1344
void sbc_dif_copy_prot(struct se_cmd *cmd, unsigned int sectors, bool read,
		       struct scatterlist *sg, int sg_off)
1345 1346 1347 1348 1349
{
	struct se_device *dev = cmd->se_dev;
	struct scatterlist *psg;
	void *paddr, *addr;
	unsigned int i, len, left;
1350
	unsigned int offset = sg_off;
1351

1352 1353 1354
	if (!sg)
		return;

1355 1356 1357
	left = sectors * dev->prot_length;

	for_each_sg(cmd->t_prot_sg, psg, cmd->t_prot_nents, i) {
1358
		unsigned int psg_len, copied = 0;
1359

1360
		paddr = kmap_atomic(sg_page(psg)) + psg->offset;
1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375
		psg_len = min(left, psg->length);
		while (psg_len) {
			len = min(psg_len, sg->length - offset);
			addr = kmap_atomic(sg_page(sg)) + sg->offset + offset;

			if (read)
				memcpy(paddr + copied, addr, len);
			else
				memcpy(addr, paddr + copied, len);

			left -= len;
			offset += len;
			copied += len;
			psg_len -= len;

1376 1377
			kunmap_atomic(addr - sg->offset - offset);

1378 1379 1380 1381 1382
			if (offset >= sg->length) {
				sg = sg_next(sg);
				offset = 0;
			}
		}
1383
		kunmap_atomic(paddr - psg->offset);
1384 1385
	}
}
1386
EXPORT_SYMBOL(sbc_dif_copy_prot);
1387 1388

sense_reason_t
1389
sbc_dif_verify(struct se_cmd *cmd, sector_t start, unsigned int sectors,
1390
	       unsigned int ei_lba, struct scatterlist *psg, int psg_off)
1391 1392
{
	struct se_device *dev = cmd->se_dev;
S
Sagi Grimberg 已提交
1393
	struct t10_pi_tuple *sdt;
1394
	struct scatterlist *dsg = cmd->t_data_sg;
1395 1396
	sector_t sector = start;
	void *daddr, *paddr;
1397
	int i;
1398
	sense_reason_t rc;
1399 1400
	int dsg_off = 0;
	unsigned int block_size = dev->dev_attrib.block_size;
1401

1402
	for (; psg && sector < start + sectors; psg = sg_next(psg)) {
1403 1404 1405
		paddr = kmap_atomic(sg_page(psg)) + psg->offset;
		daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;

1406 1407
		for (i = psg_off; i < psg->length &&
				sector < start + sectors;
S
Sagi Grimberg 已提交
1408
				i += sizeof(*sdt)) {
1409 1410
			__u16 crc;
			unsigned int avail;
1411

1412 1413 1414 1415 1416 1417 1418 1419 1420
			if (dsg_off >= dsg->length) {
				dsg_off -= dsg->length;
				kunmap_atomic(daddr - dsg->offset);
				dsg = sg_next(dsg);
				if (!dsg) {
					kunmap_atomic(paddr - psg->offset);
					return 0;
				}
				daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;
1421 1422
			}

1423
			sdt = paddr + i;
1424 1425 1426 1427 1428 1429 1430

			pr_debug("DIF READ sector: %llu guard_tag: 0x%04x"
				 " app_tag: 0x%04x ref_tag: %u\n",
				 (unsigned long long)sector, sdt->guard_tag,
				 sdt->app_tag, be32_to_cpu(sdt->ref_tag));

			if (sdt->app_tag == cpu_to_be16(0xffff)) {
1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448
				dsg_off += block_size;
				goto next;
			}

			avail = min(block_size, dsg->length - dsg_off);
			crc = crc_t10dif(daddr + dsg_off, avail);
			if (avail < block_size) {
				kunmap_atomic(daddr - dsg->offset);
				dsg = sg_next(dsg);
				if (!dsg) {
					kunmap_atomic(paddr - psg->offset);
					return 0;
				}
				daddr = kmap_atomic(sg_page(dsg)) + dsg->offset;
				dsg_off = block_size - avail;
				crc = crc_t10dif_update(crc, daddr, dsg_off);
			} else {
				dsg_off += block_size;
1449 1450
			}

1451
			rc = sbc_dif_v1_verify(cmd, sdt, crc, sector, ei_lba);
1452
			if (rc) {
1453
				kunmap_atomic(daddr - dsg->offset);
1454
				kunmap_atomic(paddr - psg->offset);
1455
				cmd->bad_sector = sector;
1456 1457
				return rc;
			}
1458
next:
1459 1460 1461 1462
			sector++;
			ei_lba++;
		}

1463
		psg_off = 0;
1464
		kunmap_atomic(daddr - dsg->offset);
1465
		kunmap_atomic(paddr - psg->offset);
1466 1467 1468 1469
	}

	return 0;
}
1470
EXPORT_SYMBOL(sbc_dif_verify);