nbd.c 52.2 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6
/*
 * Network block device - make block devices work over TCP
 *
 * Note that you can not swap over this thing, yet. Seems to work but
 * deadlocks sometimes - you can not swap over TCP in general.
 * 
P
Pavel Machek 已提交
7
 * Copyright 1997-2000, 2008 Pavel Machek <pavel@ucw.cz>
L
Linus Torvalds 已提交
8 9
 * Parts copyright 2001 Steven Whitehouse <steve@chygwyn.com>
 *
10
 * This file is released under GPLv2 or later.
L
Linus Torvalds 已提交
11
 *
12
 * (part of code stolen from loop.c)
L
Linus Torvalds 已提交
13 14 15 16 17 18 19 20 21 22 23 24 25 26
 */

#include <linux/major.h>

#include <linux/blkdev.h>
#include <linux/module.h>
#include <linux/init.h>
#include <linux/sched.h>
#include <linux/fs.h>
#include <linux/bio.h>
#include <linux/stat.h>
#include <linux/errno.h>
#include <linux/file.h>
#include <linux/ioctl.h>
27
#include <linux/mutex.h>
28 29 30
#include <linux/compiler.h>
#include <linux/err.h>
#include <linux/kernel.h>
31
#include <linux/slab.h>
L
Linus Torvalds 已提交
32
#include <net/sock.h>
33
#include <linux/net.h>
34
#include <linux/kthread.h>
M
Markus Pargmann 已提交
35
#include <linux/types.h>
M
Markus Pargmann 已提交
36
#include <linux/debugfs.h>
J
Josef Bacik 已提交
37
#include <linux/blk-mq.h>
L
Linus Torvalds 已提交
38

39
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
40 41 42
#include <asm/types.h>

#include <linux/nbd.h>
J
Josef Bacik 已提交
43 44
#include <linux/nbd-netlink.h>
#include <net/genetlink.h>
L
Linus Torvalds 已提交
45

46 47
static DEFINE_IDR(nbd_index_idr);
static DEFINE_MUTEX(nbd_index_mutex);
J
Josef Bacik 已提交
48
static int nbd_total_devices = 0;
49

J
Josef Bacik 已提交
50 51 52
struct nbd_sock {
	struct socket *sock;
	struct mutex tx_lock;
J
Josef Bacik 已提交
53 54
	struct request *pending;
	int sent;
55 56
	bool dead;
	int fallback_index;
57
	int cookie;
J
Josef Bacik 已提交
58 59
};

60 61 62 63 64 65
struct recv_thread_args {
	struct work_struct work;
	struct nbd_device *nbd;
	int index;
};

66 67 68 69 70
struct link_dead_args {
	struct work_struct work;
	int index;
};

J
Josef Bacik 已提交
71 72
#define NBD_TIMEDOUT			0
#define NBD_DISCONNECT_REQUESTED	1
J
Josef Bacik 已提交
73
#define NBD_DISCONNECTED		2
74
#define NBD_HAS_PID_FILE		3
J
Josef Bacik 已提交
75 76
#define NBD_HAS_CONFIG_REF		4
#define NBD_BOUND			5
77
#define NBD_DESTROY_ON_DISCONNECT	6
J
Josef Bacik 已提交
78

79
struct nbd_config {
M
Markus Pargmann 已提交
80
	u32 flags;
J
Josef Bacik 已提交
81
	unsigned long runtime_flags;
J
Josef Bacik 已提交
82
	u64 dead_conn_timeout;
83

84
	struct nbd_sock **socks;
J
Josef Bacik 已提交
85
	int num_connections;
J
Josef Bacik 已提交
86 87
	atomic_t live_connections;
	wait_queue_head_t conn_wait;
88

J
Josef Bacik 已提交
89 90
	atomic_t recv_threads;
	wait_queue_head_t recv_wq;
91
	loff_t blksize;
M
Markus Pargmann 已提交
92
	loff_t bytesize;
M
Markus Pargmann 已提交
93 94 95
#if IS_ENABLED(CONFIG_DEBUG_FS)
	struct dentry *dbg_dir;
#endif
96 97
};

98 99 100
struct nbd_device {
	struct blk_mq_tag_set tag_set;

J
Josef Bacik 已提交
101
	int index;
102
	refcount_t config_refs;
J
Josef Bacik 已提交
103
	refcount_t refs;
104 105 106 107
	struct nbd_config *config;
	struct mutex config_lock;
	struct gendisk *disk;

J
Josef Bacik 已提交
108
	struct list_head list;
109 110 111 112
	struct task_struct *task_recv;
	struct task_struct *task_setup;
};

J
Josef Bacik 已提交
113 114
struct nbd_cmd {
	struct nbd_device *nbd;
115
	int index;
116
	int cookie;
J
Josef Bacik 已提交
117
	struct completion send_complete;
C
Christoph Hellwig 已提交
118
	int status;
J
Josef Bacik 已提交
119 120
};

M
Markus Pargmann 已提交
121 122 123 124 125 126
#if IS_ENABLED(CONFIG_DEBUG_FS)
static struct dentry *nbd_dbg_dir;
#endif

#define nbd_name(nbd) ((nbd)->disk->disk_name)

127
#define NBD_MAGIC 0x68797548
L
Linus Torvalds 已提交
128

129
static unsigned int nbds_max = 16;
L
Laurent Vivier 已提交
130
static int max_part;
131
static struct workqueue_struct *recv_workqueue;
132
static int part_shift;
L
Linus Torvalds 已提交
133

J
Josef Bacik 已提交
134 135
static int nbd_dev_dbg_init(struct nbd_device *nbd);
static void nbd_dev_dbg_close(struct nbd_device *nbd);
136
static void nbd_config_put(struct nbd_device *nbd);
J
Josef Bacik 已提交
137
static void nbd_connect_reply(struct genl_info *info, int index);
J
Josef Bacik 已提交
138
static int nbd_genl_status(struct sk_buff *skb, struct genl_info *info);
139
static void nbd_dead_link_work(struct work_struct *work);
J
Josef Bacik 已提交
140

141
static inline struct device *nbd_to_dev(struct nbd_device *nbd)
L
Linus Torvalds 已提交
142
{
143
	return disk_to_dev(nbd->disk);
L
Linus Torvalds 已提交
144 145 146 147 148 149 150 151
}

static const char *nbdcmd_to_ascii(int cmd)
{
	switch (cmd) {
	case  NBD_CMD_READ: return "read";
	case NBD_CMD_WRITE: return "write";
	case  NBD_CMD_DISC: return "disconnect";
A
Alex Bligh 已提交
152
	case NBD_CMD_FLUSH: return "flush";
P
Paul Clements 已提交
153
	case  NBD_CMD_TRIM: return "trim/discard";
L
Linus Torvalds 已提交
154 155 156 157
	}
	return "invalid";
}

158 159 160 161 162 163 164 165 166 167 168 169 170 171
static ssize_t pid_show(struct device *dev,
			struct device_attribute *attr, char *buf)
{
	struct gendisk *disk = dev_to_disk(dev);
	struct nbd_device *nbd = (struct nbd_device *)disk->private_data;

	return sprintf(buf, "%d\n", task_pid_nr(nbd->task_recv));
}

static struct device_attribute pid_attr = {
	.attr = { .name = "pid", .mode = S_IRUGO},
	.show = pid_show,
};

J
Josef Bacik 已提交
172 173 174 175 176 177 178
static void nbd_dev_remove(struct nbd_device *nbd)
{
	struct gendisk *disk = nbd->disk;
	if (disk) {
		del_gendisk(disk);
		blk_cleanup_queue(disk->queue);
		blk_mq_free_tag_set(&nbd->tag_set);
179
		disk->private_data = NULL;
J
Josef Bacik 已提交
180 181 182 183 184 185 186 187 188 189 190 191 192 193 194
		put_disk(disk);
	}
	kfree(nbd);
}

static void nbd_put(struct nbd_device *nbd)
{
	if (refcount_dec_and_mutex_lock(&nbd->refs,
					&nbd_index_mutex)) {
		idr_remove(&nbd_index_idr, nbd->index);
		mutex_unlock(&nbd_index_mutex);
		nbd_dev_remove(nbd);
	}
}

195 196 197 198 199 200 201 202
static int nbd_disconnected(struct nbd_config *config)
{
	return test_bit(NBD_DISCONNECTED, &config->runtime_flags) ||
		test_bit(NBD_DISCONNECT_REQUESTED, &config->runtime_flags);
}

static void nbd_mark_nsock_dead(struct nbd_device *nbd, struct nbd_sock *nsock,
				int notify)
203
{
204 205 206 207 208 209 210 211 212
	if (!nsock->dead && notify && !nbd_disconnected(nbd->config)) {
		struct link_dead_args *args;
		args = kmalloc(sizeof(struct link_dead_args), GFP_NOIO);
		if (args) {
			INIT_WORK(&args->work, nbd_dead_link_work);
			args->index = nbd->index;
			queue_work(system_wq, &args->work);
		}
	}
J
Josef Bacik 已提交
213
	if (!nsock->dead) {
214
		kernel_sock_shutdown(nsock->sock, SHUT_RDWR);
J
Josef Bacik 已提交
215 216
		atomic_dec(&nbd->config->live_connections);
	}
217 218 219 220 221
	nsock->dead = true;
	nsock->pending = NULL;
	nsock->sent = 0;
}

222
static void nbd_size_clear(struct nbd_device *nbd)
223
{
224 225 226 227
	if (nbd->config->bytesize) {
		set_capacity(nbd->disk, 0);
		kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE);
	}
228 229
}

230
static void nbd_size_update(struct nbd_device *nbd)
231
{
232 233 234 235
	struct nbd_config *config = nbd->config;
	blk_queue_logical_block_size(nbd->disk->queue, config->blksize);
	blk_queue_physical_block_size(nbd->disk->queue, config->blksize);
	set_capacity(nbd->disk, config->bytesize >> 9);
236 237 238
	kobject_uevent(&nbd_to_dev(nbd)->kobj, KOBJ_CHANGE);
}

239 240
static void nbd_size_set(struct nbd_device *nbd, loff_t blocksize,
			 loff_t nr_blocks)
241
{
242 243 244
	struct nbd_config *config = nbd->config;
	config->blksize = blocksize;
	config->bytesize = blocksize * nr_blocks;
245
	nbd_size_update(nbd);
246 247
}

C
Christoph Hellwig 已提交
248
static void nbd_complete_rq(struct request *req)
L
Linus Torvalds 已提交
249
{
C
Christoph Hellwig 已提交
250
	struct nbd_cmd *cmd = blk_mq_rq_to_pdu(req);
L
Linus Torvalds 已提交
251

C
Christoph Hellwig 已提交
252 253
	dev_dbg(nbd_to_dev(cmd->nbd), "request %p: %s\n", cmd,
		cmd->status ? "failed" : "done");
L
Linus Torvalds 已提交
254

C
Christoph Hellwig 已提交
255
	blk_mq_end_request(req, cmd->status);
L
Linus Torvalds 已提交
256 257
}

258 259 260
/*
 * Forcibly shutdown the socket causing all listeners to error
 */
261
static void sock_shutdown(struct nbd_device *nbd)
262
{
263
	struct nbd_config *config = nbd->config;
J
Josef Bacik 已提交
264
	int i;
M
Markus Pargmann 已提交
265

266
	if (config->num_connections == 0)
J
Josef Bacik 已提交
267
		return;
268
	if (test_and_set_bit(NBD_DISCONNECTED, &config->runtime_flags))
M
Markus Pargmann 已提交
269
		return;
M
Markus Pargmann 已提交
270

271 272
	for (i = 0; i < config->num_connections; i++) {
		struct nbd_sock *nsock = config->socks[i];
J
Josef Bacik 已提交
273
		mutex_lock(&nsock->tx_lock);
274
		nbd_mark_nsock_dead(nbd, nsock, 0);
J
Josef Bacik 已提交
275 276 277
		mutex_unlock(&nsock->tx_lock);
	}
	dev_warn(disk_to_dev(nbd->disk), "shutting down sockets\n");
278 279
}

280 281
static enum blk_eh_timer_return nbd_xmit_timeout(struct request *req,
						 bool reserved)
282
{
283 284
	struct nbd_cmd *cmd = blk_mq_rq_to_pdu(req);
	struct nbd_device *nbd = cmd->nbd;
285 286 287
	struct nbd_config *config;

	if (!refcount_inc_not_zero(&nbd->config_refs)) {
C
Christoph Hellwig 已提交
288
		cmd->status = -EIO;
289 290 291
		return BLK_EH_HANDLED;
	}

J
Josef Bacik 已提交
292 293 294 295 296 297 298 299
	/* If we are waiting on our dead timer then we could get timeout
	 * callbacks for our request.  For this we just want to reset the timer
	 * and let the queue side take care of everything.
	 */
	if (!completion_done(&cmd->send_complete)) {
		nbd_config_put(nbd);
		return BLK_EH_RESET_TIMER;
	}
300
	config = nbd->config;
M
Markus Pargmann 已提交
301

302
	if (config->num_connections > 1) {
303 304 305 306 307 308
		dev_err_ratelimited(nbd_to_dev(nbd),
				    "Connection timed out, retrying\n");
		/*
		 * Hooray we have more connections, requeue this IO, the submit
		 * path will put it on a real connection.
		 */
309 310
		if (config->socks && config->num_connections > 1) {
			if (cmd->index < config->num_connections) {
311
				struct nbd_sock *nsock =
312
					config->socks[cmd->index];
313
				mutex_lock(&nsock->tx_lock);
314 315 316 317 318 319 320 321
				/* We can have multiple outstanding requests, so
				 * we don't want to mark the nsock dead if we've
				 * already reconnected with a new socket, so
				 * only mark it dead if its the same socket we
				 * were sent out on.
				 */
				if (cmd->cookie == nsock->cookie)
					nbd_mark_nsock_dead(nbd, nsock, 1);
322 323 324
				mutex_unlock(&nsock->tx_lock);
			}
			blk_mq_requeue_request(req, true);
325
			nbd_config_put(nbd);
326 327 328 329 330 331
			return BLK_EH_NOT_HANDLED;
		}
	} else {
		dev_err_ratelimited(nbd_to_dev(nbd),
				    "Connection timed out\n");
	}
332
	set_bit(NBD_TIMEDOUT, &config->runtime_flags);
C
Christoph Hellwig 已提交
333
	cmd->status = -EIO;
J
Josef Bacik 已提交
334
	sock_shutdown(nbd);
335 336
	nbd_config_put(nbd);

337
	return BLK_EH_HANDLED;
338 339
}

L
Linus Torvalds 已提交
340 341 342
/*
 *  Send or receive packet.
 */
A
Al Viro 已提交
343
static int sock_xmit(struct nbd_device *nbd, int index, int send,
J
Josef Bacik 已提交
344
		     struct iov_iter *iter, int msg_flags, int *sent)
L
Linus Torvalds 已提交
345
{
346 347
	struct nbd_config *config = nbd->config;
	struct socket *sock = config->socks[index]->sock;
L
Linus Torvalds 已提交
348 349
	int result;
	struct msghdr msg;
350
	unsigned long pflags = current->flags;
L
Linus Torvalds 已提交
351

352
	if (unlikely(!sock)) {
353
		dev_err_ratelimited(disk_to_dev(nbd->disk),
354 355
			"Attempted %s on closed socket in sock_xmit\n",
			(send ? "send" : "recv"));
356 357 358
		return -EINVAL;
	}

A
Al Viro 已提交
359
	msg.msg_iter = *iter;
360

361
	current->flags |= PF_MEMALLOC;
L
Linus Torvalds 已提交
362
	do {
363
		sock->sk->sk_allocation = GFP_NOIO | __GFP_MEMALLOC;
L
Linus Torvalds 已提交
364 365 366 367 368 369
		msg.msg_name = NULL;
		msg.msg_namelen = 0;
		msg.msg_control = NULL;
		msg.msg_controllen = 0;
		msg.msg_flags = msg_flags | MSG_NOSIGNAL;

M
Markus Pargmann 已提交
370
		if (send)
371
			result = sock_sendmsg(sock, &msg);
M
Markus Pargmann 已提交
372
		else
373
			result = sock_recvmsg(sock, &msg, msg.msg_flags);
L
Linus Torvalds 已提交
374 375 376 377 378 379

		if (result <= 0) {
			if (result == 0)
				result = -EPIPE; /* short read */
			break;
		}
J
Josef Bacik 已提交
380 381
		if (sent)
			*sent += result;
382
	} while (msg_data_left(&msg));
L
Linus Torvalds 已提交
383

384
	current_restore_flags(pflags, PF_MEMALLOC);
L
Linus Torvalds 已提交
385 386 387 388

	return result;
}

389
/* always call with the tx_lock held */
J
Josef Bacik 已提交
390
static int nbd_send_cmd(struct nbd_device *nbd, struct nbd_cmd *cmd, int index)
L
Linus Torvalds 已提交
391
{
J
Josef Bacik 已提交
392
	struct request *req = blk_mq_rq_from_pdu(cmd);
393 394
	struct nbd_config *config = nbd->config;
	struct nbd_sock *nsock = config->socks[index];
395
	int result;
A
Al Viro 已提交
396 397 398
	struct nbd_request request = {.magic = htonl(NBD_REQUEST_MAGIC)};
	struct kvec iov = {.iov_base = &request, .iov_len = sizeof(request)};
	struct iov_iter from;
399
	unsigned long size = blk_rq_bytes(req);
400
	struct bio *bio;
C
Christoph Hellwig 已提交
401
	u32 type;
J
Josef Bacik 已提交
402
	u32 tag = blk_mq_unique_tag(req);
J
Josef Bacik 已提交
403
	int sent = nsock->sent, skip = 0;
C
Christoph Hellwig 已提交
404

A
Al Viro 已提交
405 406
	iov_iter_kvec(&from, WRITE | ITER_KVEC, &iov, 1, sizeof(request));

407 408
	switch (req_op(req)) {
	case REQ_OP_DISCARD:
C
Christoph Hellwig 已提交
409
		type = NBD_CMD_TRIM;
410 411
		break;
	case REQ_OP_FLUSH:
C
Christoph Hellwig 已提交
412
		type = NBD_CMD_FLUSH;
413 414
		break;
	case REQ_OP_WRITE:
C
Christoph Hellwig 已提交
415
		type = NBD_CMD_WRITE;
416 417
		break;
	case REQ_OP_READ:
C
Christoph Hellwig 已提交
418
		type = NBD_CMD_READ;
419 420 421 422
		break;
	default:
		return -EIO;
	}
L
Linus Torvalds 已提交
423

424
	if (rq_data_dir(req) == WRITE &&
425
	    (config->flags & NBD_FLAG_READ_ONLY)) {
426 427 428 429 430
		dev_err_ratelimited(disk_to_dev(nbd->disk),
				    "Write on read-only\n");
		return -EIO;
	}

J
Josef Bacik 已提交
431 432 433 434 435 436 437 438 439 440 441
	/* We did a partial send previously, and we at least sent the whole
	 * request struct, so just go and send the rest of the pages in the
	 * request.
	 */
	if (sent) {
		if (sent >= sizeof(request)) {
			skip = sent - sizeof(request);
			goto send_pages;
		}
		iov_iter_advance(&from, sent);
	}
442
	cmd->index = index;
443
	cmd->cookie = nsock->cookie;
C
Christoph Hellwig 已提交
444
	request.type = htonl(type);
J
Josef Bacik 已提交
445
	if (type != NBD_CMD_FLUSH) {
A
Alex Bligh 已提交
446 447 448
		request.from = cpu_to_be64((u64)blk_rq_pos(req) << 9);
		request.len = htonl(size);
	}
J
Josef Bacik 已提交
449
	memcpy(request.handle, &tag, sizeof(tag));
L
Linus Torvalds 已提交
450

451
	dev_dbg(nbd_to_dev(nbd), "request %p: sending control (%s@%llu,%uB)\n",
J
Josef Bacik 已提交
452
		cmd, nbdcmd_to_ascii(type),
453
		(unsigned long long)blk_rq_pos(req) << 9, blk_rq_bytes(req));
A
Al Viro 已提交
454
	result = sock_xmit(nbd, index, 1, &from,
J
Josef Bacik 已提交
455
			(type == NBD_CMD_WRITE) ? MSG_MORE : 0, &sent);
L
Linus Torvalds 已提交
456
	if (result <= 0) {
J
Josef Bacik 已提交
457 458 459 460 461 462 463 464 465 466 467 468
		if (result == -ERESTARTSYS) {
			/* If we havne't sent anything we can just return BUSY,
			 * however if we have sent something we need to make
			 * sure we only allow this req to be sent until we are
			 * completely done.
			 */
			if (sent) {
				nsock->pending = req;
				nsock->sent = sent;
			}
			return BLK_MQ_RQ_QUEUE_BUSY;
		}
469
		dev_err_ratelimited(disk_to_dev(nbd->disk),
470
			"Send control failed (result %d)\n", result);
471
		return -EAGAIN;
L
Linus Torvalds 已提交
472
	}
J
Josef Bacik 已提交
473
send_pages:
474
	if (type != NBD_CMD_WRITE)
J
Josef Bacik 已提交
475
		goto out;
476 477 478 479 480

	bio = req->bio;
	while (bio) {
		struct bio *next = bio->bi_next;
		struct bvec_iter iter;
481
		struct bio_vec bvec;
482 483 484

		bio_for_each_segment(bvec, bio, iter) {
			bool is_last = !next && bio_iter_last(bvec, iter);
485
			int flags = is_last ? 0 : MSG_MORE;
486

487
			dev_dbg(nbd_to_dev(nbd), "request %p: sending %d bytes data\n",
J
Josef Bacik 已提交
488
				cmd, bvec.bv_len);
A
Al Viro 已提交
489 490
			iov_iter_bvec(&from, ITER_BVEC | WRITE,
				      &bvec, 1, bvec.bv_len);
J
Josef Bacik 已提交
491 492 493 494 495 496 497 498 499
			if (skip) {
				if (skip >= iov_iter_count(&from)) {
					skip -= iov_iter_count(&from);
					continue;
				}
				iov_iter_advance(&from, skip);
				skip = 0;
			}
			result = sock_xmit(nbd, index, 1, &from, flags, &sent);
500
			if (result <= 0) {
J
Josef Bacik 已提交
501 502 503 504 505 506 507 508 509
				if (result == -ERESTARTSYS) {
					/* We've already sent the header, we
					 * have no choice but to set pending and
					 * return BUSY.
					 */
					nsock->pending = req;
					nsock->sent = sent;
					return BLK_MQ_RQ_QUEUE_BUSY;
				}
510
				dev_err(disk_to_dev(nbd->disk),
511 512
					"Send data failed (result %d)\n",
					result);
513
				return -EAGAIN;
514
			}
515 516 517 518 519 520 521 522
			/*
			 * The completion might already have come in,
			 * so break for the last one instead of letting
			 * the iterator do it. This prevents use-after-free
			 * of the bio.
			 */
			if (is_last)
				break;
L
Linus Torvalds 已提交
523
		}
524
		bio = next;
L
Linus Torvalds 已提交
525
	}
J
Josef Bacik 已提交
526 527 528
out:
	nsock->pending = NULL;
	nsock->sent = 0;
L
Linus Torvalds 已提交
529 530 531 532
	return 0;
}

/* NULL returned = something went wrong, inform userspace */
J
Josef Bacik 已提交
533
static struct nbd_cmd *nbd_read_stat(struct nbd_device *nbd, int index)
L
Linus Torvalds 已提交
534
{
535
	struct nbd_config *config = nbd->config;
L
Linus Torvalds 已提交
536 537
	int result;
	struct nbd_reply reply;
J
Josef Bacik 已提交
538 539 540
	struct nbd_cmd *cmd;
	struct request *req = NULL;
	u16 hwq;
J
Josef Bacik 已提交
541
	u32 tag;
A
Al Viro 已提交
542 543
	struct kvec iov = {.iov_base = &reply, .iov_len = sizeof(reply)};
	struct iov_iter to;
L
Linus Torvalds 已提交
544 545

	reply.magic = 0;
A
Al Viro 已提交
546
	iov_iter_kvec(&to, READ | ITER_KVEC, &iov, 1, sizeof(reply));
J
Josef Bacik 已提交
547
	result = sock_xmit(nbd, index, 0, &to, MSG_WAITALL, NULL);
L
Linus Torvalds 已提交
548
	if (result <= 0) {
549
		if (!nbd_disconnected(config))
J
Josef Bacik 已提交
550 551
			dev_err(disk_to_dev(nbd->disk),
				"Receive control failed (result %d)\n", result);
552
		return ERR_PTR(result);
L
Linus Torvalds 已提交
553
	}
554 555

	if (ntohl(reply.magic) != NBD_REPLY_MAGIC) {
556
		dev_err(disk_to_dev(nbd->disk), "Wrong magic (0x%lx)\n",
557
				(unsigned long)ntohl(reply.magic));
558
		return ERR_PTR(-EPROTO);
559 560
	}

J
Josef Bacik 已提交
561
	memcpy(&tag, reply.handle, sizeof(u32));
562

J
Josef Bacik 已提交
563 564 565 566 567 568 569 570
	hwq = blk_mq_unique_tag_to_hwq(tag);
	if (hwq < nbd->tag_set.nr_hw_queues)
		req = blk_mq_tag_to_rq(nbd->tag_set.tags[hwq],
				       blk_mq_unique_tag_to_tag(tag));
	if (!req || !blk_mq_request_started(req)) {
		dev_err(disk_to_dev(nbd->disk), "Unexpected reply (%d) %p\n",
			tag, req);
		return ERR_PTR(-ENOENT);
L
Linus Torvalds 已提交
571
	}
J
Josef Bacik 已提交
572
	cmd = blk_mq_rq_to_pdu(req);
L
Linus Torvalds 已提交
573
	if (ntohl(reply.error)) {
574
		dev_err(disk_to_dev(nbd->disk), "Other side returned error (%d)\n",
575
			ntohl(reply.error));
C
Christoph Hellwig 已提交
576
		cmd->status = -EIO;
J
Josef Bacik 已提交
577
		return cmd;
L
Linus Torvalds 已提交
578 579
	}

J
Josef Bacik 已提交
580
	dev_dbg(nbd_to_dev(nbd), "request %p: got reply\n", cmd);
C
Christoph Hellwig 已提交
581
	if (rq_data_dir(req) != WRITE) {
582
		struct req_iterator iter;
583
		struct bio_vec bvec;
584 585

		rq_for_each_segment(bvec, req, iter) {
A
Al Viro 已提交
586 587
			iov_iter_bvec(&to, ITER_BVEC | READ,
				      &bvec, 1, bvec.bv_len);
J
Josef Bacik 已提交
588
			result = sock_xmit(nbd, index, 0, &to, MSG_WAITALL, NULL);
589
			if (result <= 0) {
590
				dev_err(disk_to_dev(nbd->disk), "Receive data failed (result %d)\n",
591
					result);
592 593 594 595 596 597 598
				/*
				 * If we've disconnected or we only have 1
				 * connection then we need to make sure we
				 * complete this request, otherwise error out
				 * and let the timeout stuff handle resubmitting
				 * this request onto another connection.
				 */
599 600
				if (nbd_disconnected(config) ||
				    config->num_connections <= 1) {
C
Christoph Hellwig 已提交
601
					cmd->status = -EIO;
602 603 604
					return cmd;
				}
				return ERR_PTR(-EIO);
605
			}
606
			dev_dbg(nbd_to_dev(nbd), "request %p: got %d bytes data\n",
J
Josef Bacik 已提交
607
				cmd, bvec.bv_len);
L
Linus Torvalds 已提交
608
		}
J
Josef Bacik 已提交
609 610 611
	} else {
		/* See the comment in nbd_queue_rq. */
		wait_for_completion(&cmd->send_complete);
L
Linus Torvalds 已提交
612
	}
J
Josef Bacik 已提交
613
	return cmd;
L
Linus Torvalds 已提交
614 615
}

J
Josef Bacik 已提交
616
static void recv_work(struct work_struct *work)
L
Linus Torvalds 已提交
617
{
J
Josef Bacik 已提交
618 619 620 621
	struct recv_thread_args *args = container_of(work,
						     struct recv_thread_args,
						     work);
	struct nbd_device *nbd = args->nbd;
622
	struct nbd_config *config = nbd->config;
J
Josef Bacik 已提交
623
	struct nbd_cmd *cmd;
J
Josef Bacik 已提交
624
	int ret = 0;
L
Linus Torvalds 已提交
625

626
	while (1) {
J
Josef Bacik 已提交
627
		cmd = nbd_read_stat(nbd, args->index);
J
Josef Bacik 已提交
628
		if (IS_ERR(cmd)) {
629
			struct nbd_sock *nsock = config->socks[args->index];
630 631

			mutex_lock(&nsock->tx_lock);
632
			nbd_mark_nsock_dead(nbd, nsock, 1);
633
			mutex_unlock(&nsock->tx_lock);
J
Josef Bacik 已提交
634
			ret = PTR_ERR(cmd);
635 636 637
			break;
		}

638
		blk_mq_complete_request(blk_mq_rq_from_pdu(cmd));
639
	}
640 641 642 643
	atomic_dec(&config->recv_threads);
	wake_up(&config->recv_wq);
	nbd_config_put(nbd);
	kfree(args);
L
Linus Torvalds 已提交
644 645
}

J
Josef Bacik 已提交
646
static void nbd_clear_req(struct request *req, void *data, bool reserved)
L
Linus Torvalds 已提交
647
{
J
Josef Bacik 已提交
648
	struct nbd_cmd *cmd;
L
Linus Torvalds 已提交
649

J
Josef Bacik 已提交
650 651 652
	if (!blk_mq_request_started(req))
		return;
	cmd = blk_mq_rq_to_pdu(req);
C
Christoph Hellwig 已提交
653
	cmd->status = -EIO;
654
	blk_mq_complete_request(req);
J
Josef Bacik 已提交
655 656 657 658
}

static void nbd_clear_que(struct nbd_device *nbd)
{
659
	blk_mq_stop_hw_queues(nbd->disk->queue);
J
Josef Bacik 已提交
660
	blk_mq_tagset_busy_iter(&nbd->tag_set, nbd_clear_req, NULL);
661
	blk_mq_start_hw_queues(nbd->disk->queue);
662
	dev_dbg(disk_to_dev(nbd->disk), "queue cleared\n");
L
Linus Torvalds 已提交
663 664
}

665 666
static int find_fallback(struct nbd_device *nbd, int index)
{
667
	struct nbd_config *config = nbd->config;
668
	int new_index = -1;
669
	struct nbd_sock *nsock = config->socks[index];
670 671
	int fallback = nsock->fallback_index;

672
	if (test_bit(NBD_DISCONNECTED, &config->runtime_flags))
673 674
		return new_index;

675
	if (config->num_connections <= 1) {
676 677 678 679 680
		dev_err_ratelimited(disk_to_dev(nbd->disk),
				    "Attempted send on invalid socket\n");
		return new_index;
	}

681 682
	if (fallback >= 0 && fallback < config->num_connections &&
	    !config->socks[fallback]->dead)
683 684 685
		return fallback;

	if (nsock->fallback_index < 0 ||
686 687
	    nsock->fallback_index >= config->num_connections ||
	    config->socks[nsock->fallback_index]->dead) {
688
		int i;
689
		for (i = 0; i < config->num_connections; i++) {
690 691
			if (i == index)
				continue;
692
			if (!config->socks[i]->dead) {
693 694 695 696 697 698 699 700 701 702 703 704 705 706
				new_index = i;
				break;
			}
		}
		nsock->fallback_index = new_index;
		if (new_index < 0) {
			dev_err_ratelimited(disk_to_dev(nbd->disk),
					    "Dead connection, failed to find a fallback\n");
			return new_index;
		}
	}
	new_index = nsock->fallback_index;
	return new_index;
}
707

J
Josef Bacik 已提交
708 709 710 711 712 713 714 715 716 717 718 719 720
static int wait_for_reconnect(struct nbd_device *nbd)
{
	struct nbd_config *config = nbd->config;
	if (!config->dead_conn_timeout)
		return 0;
	if (test_bit(NBD_DISCONNECTED, &config->runtime_flags))
		return 0;
	wait_event_interruptible_timeout(config->conn_wait,
					 atomic_read(&config->live_connections),
					 config->dead_conn_timeout);
	return atomic_read(&config->live_connections);
}

J
Josef Bacik 已提交
721
static int nbd_handle_cmd(struct nbd_cmd *cmd, int index)
722
{
J
Josef Bacik 已提交
723 724
	struct request *req = blk_mq_rq_from_pdu(cmd);
	struct nbd_device *nbd = cmd->nbd;
725
	struct nbd_config *config;
J
Josef Bacik 已提交
726
	struct nbd_sock *nsock;
J
Josef Bacik 已提交
727
	int ret;
J
Josef Bacik 已提交
728

729 730 731 732 733 734 735 736
	if (!refcount_inc_not_zero(&nbd->config_refs)) {
		dev_err_ratelimited(disk_to_dev(nbd->disk),
				    "Socks array is empty\n");
		return -EINVAL;
	}
	config = nbd->config;

	if (index >= config->num_connections) {
737 738
		dev_err_ratelimited(disk_to_dev(nbd->disk),
				    "Attempted send on invalid socket\n");
739
		nbd_config_put(nbd);
J
Josef Bacik 已提交
740
		return -EINVAL;
J
Josef Bacik 已提交
741
	}
C
Christoph Hellwig 已提交
742
	cmd->status = 0;
743
again:
744
	nsock = config->socks[index];
J
Josef Bacik 已提交
745
	mutex_lock(&nsock->tx_lock);
746
	if (nsock->dead) {
J
Josef Bacik 已提交
747
		int old_index = index;
748
		index = find_fallback(nbd, index);
J
Josef Bacik 已提交
749
		mutex_unlock(&nsock->tx_lock);
750
		if (index < 0) {
J
Josef Bacik 已提交
751 752 753 754 755 756 757 758 759 760 761 762 763
			if (wait_for_reconnect(nbd)) {
				index = old_index;
				goto again;
			}
			/* All the sockets should already be down at this point,
			 * we just want to make sure that DISCONNECTED is set so
			 * any requests that come in that were queue'ed waiting
			 * for the reconnect timer don't trigger the timer again
			 * and instead just error out.
			 */
			sock_shutdown(nbd);
			nbd_config_put(nbd);
			return -EIO;
764
		}
765
		goto again;
766 767
	}

J
Josef Bacik 已提交
768 769 770 771 772 773 774 775 776
	/* Handle the case that we have a pending request that was partially
	 * transmitted that _has_ to be serviced first.  We need to call requeue
	 * here so that it gets put _after_ the request that is already on the
	 * dispatch list.
	 */
	if (unlikely(nsock->pending && nsock->pending != req)) {
		blk_mq_requeue_request(req, true);
		ret = 0;
		goto out;
777
	}
778 779 780 781
	/*
	 * Some failures are related to the link going down, so anything that
	 * returns EAGAIN can be retried on a different socket.
	 */
J
Josef Bacik 已提交
782
	ret = nbd_send_cmd(nbd, cmd, index);
783 784 785
	if (ret == -EAGAIN) {
		dev_err_ratelimited(disk_to_dev(nbd->disk),
				    "Request send failed trying another connection\n");
786
		nbd_mark_nsock_dead(nbd, nsock, 1);
787 788 789
		mutex_unlock(&nsock->tx_lock);
		goto again;
	}
J
Josef Bacik 已提交
790
out:
J
Josef Bacik 已提交
791
	mutex_unlock(&nsock->tx_lock);
792
	nbd_config_put(nbd);
J
Josef Bacik 已提交
793
	return ret;
794 795
}

J
Josef Bacik 已提交
796 797
static int nbd_queue_rq(struct blk_mq_hw_ctx *hctx,
			const struct blk_mq_queue_data *bd)
L
Linus Torvalds 已提交
798
{
J
Josef Bacik 已提交
799
	struct nbd_cmd *cmd = blk_mq_rq_to_pdu(bd->rq);
J
Josef Bacik 已提交
800
	int ret;
L
Linus Torvalds 已提交
801

J
Josef Bacik 已提交
802 803 804 805 806 807 808 809 810 811
	/*
	 * Since we look at the bio's to send the request over the network we
	 * need to make sure the completion work doesn't mark this request done
	 * before we are done doing our send.  This keeps us from dereferencing
	 * freed data if we have particularly fast completions (ie we get the
	 * completion before we exit sock_xmit on the last bvec) or in the case
	 * that the server is misbehaving (or there was an error) before we're
	 * done sending everything over the wire.
	 */
	init_completion(&cmd->send_complete);
J
Josef Bacik 已提交
812
	blk_mq_start_request(bd->rq);
J
Josef Bacik 已提交
813 814 815 816 817 818 819 820 821 822 823

	/* We can be called directly from the user space process, which means we
	 * could possibly have signals pending so our sendmsg will fail.  In
	 * this case we need to return that we are busy, otherwise error out as
	 * appropriate.
	 */
	ret = nbd_handle_cmd(cmd, hctx->queue_num);
	if (ret < 0)
		ret = BLK_MQ_RQ_QUEUE_ERROR;
	if (!ret)
		ret = BLK_MQ_RQ_QUEUE_OK;
J
Josef Bacik 已提交
824 825
	complete(&cmd->send_complete);

J
Josef Bacik 已提交
826
	return ret;
L
Linus Torvalds 已提交
827 828
}

J
Josef Bacik 已提交
829 830
static int nbd_add_socket(struct nbd_device *nbd, unsigned long arg,
			  bool netlink)
M
Markus Pargmann 已提交
831
{
832
	struct nbd_config *config = nbd->config;
J
Josef Bacik 已提交
833
	struct socket *sock;
J
Josef Bacik 已提交
834 835
	struct nbd_sock **socks;
	struct nbd_sock *nsock;
J
Josef Bacik 已提交
836 837 838 839 840
	int err;

	sock = sockfd_lookup(arg, &err);
	if (!sock)
		return err;
M
Markus Pargmann 已提交
841

J
Josef Bacik 已提交
842 843
	if (!netlink && !nbd->task_setup &&
	    !test_bit(NBD_BOUND, &config->runtime_flags))
J
Josef Bacik 已提交
844
		nbd->task_setup = current;
J
Josef Bacik 已提交
845 846 847 848

	if (!netlink &&
	    (nbd->task_setup != current ||
	     test_bit(NBD_BOUND, &config->runtime_flags))) {
J
Josef Bacik 已提交
849 850
		dev_err(disk_to_dev(nbd->disk),
			"Device being setup by another task");
J
Josef Bacik 已提交
851
		sockfd_put(sock);
J
Josef Bacik 已提交
852
		return -EBUSY;
M
Markus Pargmann 已提交
853 854
	}

855
	socks = krealloc(config->socks, (config->num_connections + 1) *
J
Josef Bacik 已提交
856
			 sizeof(struct nbd_sock *), GFP_KERNEL);
J
Josef Bacik 已提交
857 858
	if (!socks) {
		sockfd_put(sock);
J
Josef Bacik 已提交
859
		return -ENOMEM;
J
Josef Bacik 已提交
860
	}
J
Josef Bacik 已提交
861
	nsock = kzalloc(sizeof(struct nbd_sock), GFP_KERNEL);
J
Josef Bacik 已提交
862 863
	if (!nsock) {
		sockfd_put(sock);
J
Josef Bacik 已提交
864
		return -ENOMEM;
J
Josef Bacik 已提交
865
	}
J
Josef Bacik 已提交
866

867
	config->socks = socks;
M
Markus Pargmann 已提交
868

869 870
	nsock->fallback_index = -1;
	nsock->dead = false;
J
Josef Bacik 已提交
871 872
	mutex_init(&nsock->tx_lock);
	nsock->sock = sock;
J
Josef Bacik 已提交
873 874
	nsock->pending = NULL;
	nsock->sent = 0;
875
	nsock->cookie = 0;
876
	socks[config->num_connections++] = nsock;
J
Josef Bacik 已提交
877
	atomic_inc(&config->live_connections);
M
Markus Pargmann 已提交
878

J
Josef Bacik 已提交
879
	return 0;
M
Markus Pargmann 已提交
880 881
}

882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920
static int nbd_reconnect_socket(struct nbd_device *nbd, unsigned long arg)
{
	struct nbd_config *config = nbd->config;
	struct socket *sock, *old;
	struct recv_thread_args *args;
	int i;
	int err;

	sock = sockfd_lookup(arg, &err);
	if (!sock)
		return err;

	args = kzalloc(sizeof(*args), GFP_KERNEL);
	if (!args) {
		sockfd_put(sock);
		return -ENOMEM;
	}

	for (i = 0; i < config->num_connections; i++) {
		struct nbd_sock *nsock = config->socks[i];

		if (!nsock->dead)
			continue;

		mutex_lock(&nsock->tx_lock);
		if (!nsock->dead) {
			mutex_unlock(&nsock->tx_lock);
			continue;
		}
		sk_set_memalloc(sock->sk);
		atomic_inc(&config->recv_threads);
		refcount_inc(&nbd->config_refs);
		old = nsock->sock;
		nsock->fallback_index = -1;
		nsock->sock = sock;
		nsock->dead = false;
		INIT_WORK(&args->work, recv_work);
		args->index = i;
		args->nbd = nbd;
921
		nsock->cookie++;
922 923 924 925 926 927 928
		mutex_unlock(&nsock->tx_lock);
		sockfd_put(old);

		/* We take the tx_mutex in an error path in the recv_work, so we
		 * need to queue_work outside of the tx_mutex.
		 */
		queue_work(recv_workqueue, &args->work);
J
Josef Bacik 已提交
929 930 931

		atomic_inc(&config->live_connections);
		wake_up(&config->conn_wait);
932 933 934 935 936 937 938
		return 0;
	}
	sockfd_put(sock);
	kfree(args);
	return -ENOSPC;
}

939 940 941
/* Reset all properties of an NBD device */
static void nbd_reset(struct nbd_device *nbd)
{
942
	nbd->config = NULL;
943
	nbd->tag_set.timeout = 0;
944 945 946 947 948
	queue_flag_clear_unlocked(QUEUE_FLAG_DISCARD, nbd->disk->queue);
}

static void nbd_bdev_reset(struct block_device *bdev)
{
949 950
	if (bdev->bd_openers > 1)
		return;
951
	bd_set_size(bdev, 0);
952 953 954 955 956 957
	if (max_part > 0) {
		blkdev_reread_part(bdev);
		bdev->bd_invalidated = 1;
	}
}

958
static void nbd_parse_flags(struct nbd_device *nbd)
959
{
960 961
	struct nbd_config *config = nbd->config;
	if (config->flags & NBD_FLAG_READ_ONLY)
962 963 964
		set_disk_ro(nbd->disk, true);
	else
		set_disk_ro(nbd->disk, false);
965
	if (config->flags & NBD_FLAG_SEND_TRIM)
966
		queue_flag_set_unlocked(QUEUE_FLAG_DISCARD, nbd->disk->queue);
967
	if (config->flags & NBD_FLAG_SEND_FLUSH)
968
		blk_queue_write_cache(nbd->disk->queue, true, false);
969
	else
970
		blk_queue_write_cache(nbd->disk->queue, false, false);
971 972
}

J
Josef Bacik 已提交
973 974
static void send_disconnects(struct nbd_device *nbd)
{
975
	struct nbd_config *config = nbd->config;
A
Al Viro 已提交
976 977 978 979 980 981
	struct nbd_request request = {
		.magic = htonl(NBD_REQUEST_MAGIC),
		.type = htonl(NBD_CMD_DISC),
	};
	struct kvec iov = {.iov_base = &request, .iov_len = sizeof(request)};
	struct iov_iter from;
J
Josef Bacik 已提交
982 983
	int i, ret;

984
	for (i = 0; i < config->num_connections; i++) {
A
Al Viro 已提交
985
		iov_iter_kvec(&from, WRITE | ITER_KVEC, &iov, 1, sizeof(request));
J
Josef Bacik 已提交
986
		ret = sock_xmit(nbd, i, 1, &from, 0, NULL);
J
Josef Bacik 已提交
987 988 989 990 991 992
		if (ret <= 0)
			dev_err(disk_to_dev(nbd->disk),
				"Send disconnect failed %d\n", ret);
	}
}

993
static int nbd_disconnect(struct nbd_device *nbd)
J
Josef Bacik 已提交
994
{
995
	struct nbd_config *config = nbd->config;
M
Markus Pargmann 已提交
996

997
	dev_info(disk_to_dev(nbd->disk), "NBD_DISCONNECT\n");
J
Josef Bacik 已提交
998
	if (!test_and_set_bit(NBD_DISCONNECT_REQUESTED,
999
			      &config->runtime_flags))
J
Josef Bacik 已提交
1000 1001 1002 1003
		send_disconnects(nbd);
	return 0;
}

1004
static void nbd_clear_sock(struct nbd_device *nbd)
P
Pavel Machek 已提交
1005
{
J
Josef Bacik 已提交
1006 1007
	sock_shutdown(nbd);
	nbd_clear_que(nbd);
1008 1009 1010 1011 1012 1013 1014 1015 1016
	nbd->task_setup = NULL;
}

static void nbd_config_put(struct nbd_device *nbd)
{
	if (refcount_dec_and_mutex_lock(&nbd->config_refs,
					&nbd->config_lock)) {
		struct nbd_config *config = nbd->config;
		nbd_dev_dbg_close(nbd);
1017
		nbd_size_clear(nbd);
1018 1019 1020 1021
		if (test_and_clear_bit(NBD_HAS_PID_FILE,
				       &config->runtime_flags))
			device_remove_file(disk_to_dev(nbd->disk), &pid_attr);
		nbd->task_recv = NULL;
1022
		nbd_clear_sock(nbd);
1023 1024 1025 1026 1027 1028 1029 1030 1031
		if (config->num_connections) {
			int i;
			for (i = 0; i < config->num_connections; i++) {
				sockfd_put(config->socks[i]->sock);
				kfree(config->socks[i]);
			}
			kfree(config->socks);
		}
		nbd_reset(nbd);
1032

1033
		mutex_unlock(&nbd->config_lock);
J
Josef Bacik 已提交
1034
		nbd_put(nbd);
1035 1036
		module_put(THIS_MODULE);
	}
J
Josef Bacik 已提交
1037 1038
}

J
Josef Bacik 已提交
1039
static int nbd_start_device(struct nbd_device *nbd)
J
Josef Bacik 已提交
1040
{
1041 1042
	struct nbd_config *config = nbd->config;
	int num_connections = config->num_connections;
J
Josef Bacik 已提交
1043
	int error = 0, i;
P
Pavel Machek 已提交
1044

J
Josef Bacik 已提交
1045 1046
	if (nbd->task_recv)
		return -EBUSY;
1047
	if (!config->socks)
J
Josef Bacik 已提交
1048 1049
		return -EINVAL;
	if (num_connections > 1 &&
1050
	    !(config->flags & NBD_FLAG_CAN_MULTI_CONN)) {
J
Josef Bacik 已提交
1051
		dev_err(disk_to_dev(nbd->disk), "server does not support multiple connections per device.\n");
1052
		return -EINVAL;
J
Josef Bacik 已提交
1053
	}
M
Markus Pargmann 已提交
1054

1055
	blk_mq_update_nr_hw_queues(&nbd->tag_set, config->num_connections);
J
Josef Bacik 已提交
1056
	nbd->task_recv = current;
M
Markus Pargmann 已提交
1057

1058
	nbd_parse_flags(nbd);
M
Markus Pargmann 已提交
1059

J
Josef Bacik 已提交
1060 1061 1062
	error = device_create_file(disk_to_dev(nbd->disk), &pid_attr);
	if (error) {
		dev_err(disk_to_dev(nbd->disk), "device_create_file failed!\n");
1063
		return error;
P
Pavel Machek 已提交
1064
	}
1065
	set_bit(NBD_HAS_PID_FILE, &config->runtime_flags);
1066

J
Josef Bacik 已提交
1067 1068
	nbd_dev_dbg_init(nbd);
	for (i = 0; i < num_connections; i++) {
1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082
		struct recv_thread_args *args;

		args = kzalloc(sizeof(*args), GFP_KERNEL);
		if (!args) {
			sock_shutdown(nbd);
			return -ENOMEM;
		}
		sk_set_memalloc(config->socks[i]->sock->sk);
		atomic_inc(&config->recv_threads);
		refcount_inc(&nbd->config_refs);
		INIT_WORK(&args->work, recv_work);
		args->nbd = nbd;
		args->index = i;
		queue_work(recv_workqueue, &args->work);
1083
	}
J
Josef Bacik 已提交
1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100
	return error;
}

static int nbd_start_device_ioctl(struct nbd_device *nbd, struct block_device *bdev)
{
	struct nbd_config *config = nbd->config;
	int ret;

	ret = nbd_start_device(nbd);
	if (ret)
		return ret;

	bd_set_size(bdev, config->bytesize);
	if (max_part)
		bdev->bd_invalidated = 1;
	mutex_unlock(&nbd->config_lock);
	ret = wait_event_interruptible(config->recv_wq,
1101
					 atomic_read(&config->recv_threads) == 0);
J
Josef Bacik 已提交
1102
	if (ret)
1103
		sock_shutdown(nbd);
J
Josef Bacik 已提交
1104
	mutex_lock(&nbd->config_lock);
J
Josef Bacik 已提交
1105
	bd_set_size(bdev, 0);
J
Josef Bacik 已提交
1106
	/* user requested, ignore socket errors */
1107
	if (test_bit(NBD_DISCONNECT_REQUESTED, &config->runtime_flags))
J
Josef Bacik 已提交
1108
		ret = 0;
1109
	if (test_bit(NBD_TIMEDOUT, &config->runtime_flags))
J
Josef Bacik 已提交
1110 1111
		ret = -ETIMEDOUT;
	return ret;
J
Josef Bacik 已提交
1112 1113
}

1114 1115 1116
static void nbd_clear_sock_ioctl(struct nbd_device *nbd,
				 struct block_device *bdev)
{
1117
	sock_shutdown(nbd);
1118 1119
	kill_bdev(bdev);
	nbd_bdev_reset(bdev);
J
Josef Bacik 已提交
1120 1121 1122
	if (test_and_clear_bit(NBD_HAS_CONFIG_REF,
			       &nbd->config->runtime_flags))
		nbd_config_put(nbd);
1123 1124
}

J
Josef Bacik 已提交
1125 1126 1127 1128
/* Must be called with config_lock held */
static int __nbd_ioctl(struct block_device *bdev, struct nbd_device *nbd,
		       unsigned int cmd, unsigned long arg)
{
1129 1130
	struct nbd_config *config = nbd->config;

J
Josef Bacik 已提交
1131 1132
	switch (cmd) {
	case NBD_DISCONNECT:
1133
		return nbd_disconnect(nbd);
J
Josef Bacik 已提交
1134
	case NBD_CLEAR_SOCK:
1135 1136
		nbd_clear_sock_ioctl(nbd, bdev);
		return 0;
J
Josef Bacik 已提交
1137
	case NBD_SET_SOCK:
J
Josef Bacik 已提交
1138
		return nbd_add_socket(nbd, arg, false);
J
Josef Bacik 已提交
1139
	case NBD_SET_BLKSIZE:
1140
		nbd_size_set(nbd, arg,
1141
			     div_s64(config->bytesize, arg));
1142
		return 0;
L
Linus Torvalds 已提交
1143
	case NBD_SET_SIZE:
1144
		nbd_size_set(nbd, config->blksize,
1145
			     div_s64(arg, config->blksize));
1146
		return 0;
1147
	case NBD_SET_SIZE_BLOCKS:
1148
		nbd_size_set(nbd, config->blksize, arg);
1149
		return 0;
1150
	case NBD_SET_TIMEOUT:
J
Josef Bacik 已提交
1151 1152 1153 1154
		if (arg) {
			nbd->tag_set.timeout = arg * HZ;
			blk_queue_rq_timeout(nbd->disk->queue, arg * HZ);
		}
1155
		return 0;
P
Pavel Machek 已提交
1156

P
Paul Clements 已提交
1157
	case NBD_SET_FLAGS:
1158
		config->flags = arg;
P
Paul Clements 已提交
1159
		return 0;
J
Josef Bacik 已提交
1160
	case NBD_DO_IT:
J
Josef Bacik 已提交
1161
		return nbd_start_device_ioctl(nbd, bdev);
L
Linus Torvalds 已提交
1162
	case NBD_CLEAR_QUE:
1163 1164 1165 1166
		/*
		 * This is for compatibility only.  The queue is always cleared
		 * by NBD_DO_IT or NBD_CLEAR_SOCK.
		 */
L
Linus Torvalds 已提交
1167 1168
		return 0;
	case NBD_PRINT_DEBUG:
J
Josef Bacik 已提交
1169 1170 1171 1172
		/*
		 * For compatibility only, we no longer keep a list of
		 * outstanding requests.
		 */
L
Linus Torvalds 已提交
1173 1174
		return 0;
	}
P
Pavel Machek 已提交
1175 1176 1177 1178 1179 1180
	return -ENOTTY;
}

static int nbd_ioctl(struct block_device *bdev, fmode_t mode,
		     unsigned int cmd, unsigned long arg)
{
1181
	struct nbd_device *nbd = bdev->bd_disk->private_data;
J
Josef Bacik 已提交
1182 1183
	struct nbd_config *config = nbd->config;
	int error = -EINVAL;
P
Pavel Machek 已提交
1184 1185 1186 1187

	if (!capable(CAP_SYS_ADMIN))
		return -EPERM;

J
Josef Bacik 已提交
1188
	mutex_lock(&nbd->config_lock);
J
Josef Bacik 已提交
1189 1190 1191 1192 1193 1194 1195 1196 1197

	/* Don't allow ioctl operations on a nbd device that was created with
	 * netlink, unless it's DISCONNECT or CLEAR_SOCK, which are fine.
	 */
	if (!test_bit(NBD_BOUND, &config->runtime_flags) ||
	    (cmd == NBD_DISCONNECT || cmd == NBD_CLEAR_SOCK))
		error = __nbd_ioctl(bdev, nbd, cmd, arg);
	else
		dev_err(nbd_to_dev(nbd), "Cannot use ioctl interface on a netlink controlled device.\n");
J
Josef Bacik 已提交
1198
	mutex_unlock(&nbd->config_lock);
P
Pavel Machek 已提交
1199
	return error;
L
Linus Torvalds 已提交
1200 1201
}

1202 1203 1204 1205 1206 1207 1208 1209 1210
static struct nbd_config *nbd_alloc_config(void)
{
	struct nbd_config *config;

	config = kzalloc(sizeof(struct nbd_config), GFP_NOFS);
	if (!config)
		return NULL;
	atomic_set(&config->recv_threads, 0);
	init_waitqueue_head(&config->recv_wq);
J
Josef Bacik 已提交
1211
	init_waitqueue_head(&config->conn_wait);
1212
	config->blksize = 1024;
J
Josef Bacik 已提交
1213
	atomic_set(&config->live_connections, 0);
1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228
	try_module_get(THIS_MODULE);
	return config;
}

static int nbd_open(struct block_device *bdev, fmode_t mode)
{
	struct nbd_device *nbd;
	int ret = 0;

	mutex_lock(&nbd_index_mutex);
	nbd = bdev->bd_disk->private_data;
	if (!nbd) {
		ret = -ENXIO;
		goto out;
	}
J
Josef Bacik 已提交
1229 1230 1231 1232
	if (!refcount_inc_not_zero(&nbd->refs)) {
		ret = -ENXIO;
		goto out;
	}
1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247
	if (!refcount_inc_not_zero(&nbd->config_refs)) {
		struct nbd_config *config;

		mutex_lock(&nbd->config_lock);
		if (refcount_inc_not_zero(&nbd->config_refs)) {
			mutex_unlock(&nbd->config_lock);
			goto out;
		}
		config = nbd->config = nbd_alloc_config();
		if (!config) {
			ret = -ENOMEM;
			mutex_unlock(&nbd->config_lock);
			goto out;
		}
		refcount_set(&nbd->config_refs, 1);
J
Josef Bacik 已提交
1248
		refcount_inc(&nbd->refs);
1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259
		mutex_unlock(&nbd->config_lock);
	}
out:
	mutex_unlock(&nbd_index_mutex);
	return ret;
}

static void nbd_release(struct gendisk *disk, fmode_t mode)
{
	struct nbd_device *nbd = disk->private_data;
	nbd_config_put(nbd);
J
Josef Bacik 已提交
1260
	nbd_put(nbd);
1261 1262
}

1263
static const struct block_device_operations nbd_fops =
L
Linus Torvalds 已提交
1264 1265
{
	.owner =	THIS_MODULE,
1266 1267
	.open =		nbd_open,
	.release =	nbd_release,
1268
	.ioctl =	nbd_ioctl,
A
Al Viro 已提交
1269
	.compat_ioctl =	nbd_ioctl,
L
Linus Torvalds 已提交
1270 1271
};

M
Markus Pargmann 已提交
1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298
#if IS_ENABLED(CONFIG_DEBUG_FS)

static int nbd_dbg_tasks_show(struct seq_file *s, void *unused)
{
	struct nbd_device *nbd = s->private;

	if (nbd->task_recv)
		seq_printf(s, "recv: %d\n", task_pid_nr(nbd->task_recv));

	return 0;
}

static int nbd_dbg_tasks_open(struct inode *inode, struct file *file)
{
	return single_open(file, nbd_dbg_tasks_show, inode->i_private);
}

static const struct file_operations nbd_dbg_tasks_ops = {
	.open = nbd_dbg_tasks_open,
	.read = seq_read,
	.llseek = seq_lseek,
	.release = single_release,
};

static int nbd_dbg_flags_show(struct seq_file *s, void *unused)
{
	struct nbd_device *nbd = s->private;
1299
	u32 flags = nbd->config->flags;
M
Markus Pargmann 已提交
1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331

	seq_printf(s, "Hex: 0x%08x\n\n", flags);

	seq_puts(s, "Known flags:\n");

	if (flags & NBD_FLAG_HAS_FLAGS)
		seq_puts(s, "NBD_FLAG_HAS_FLAGS\n");
	if (flags & NBD_FLAG_READ_ONLY)
		seq_puts(s, "NBD_FLAG_READ_ONLY\n");
	if (flags & NBD_FLAG_SEND_FLUSH)
		seq_puts(s, "NBD_FLAG_SEND_FLUSH\n");
	if (flags & NBD_FLAG_SEND_TRIM)
		seq_puts(s, "NBD_FLAG_SEND_TRIM\n");

	return 0;
}

static int nbd_dbg_flags_open(struct inode *inode, struct file *file)
{
	return single_open(file, nbd_dbg_flags_show, inode->i_private);
}

static const struct file_operations nbd_dbg_flags_ops = {
	.open = nbd_dbg_flags_open,
	.read = seq_read,
	.llseek = seq_lseek,
	.release = single_release,
};

static int nbd_dev_dbg_init(struct nbd_device *nbd)
{
	struct dentry *dir;
1332
	struct nbd_config *config = nbd->config;
1333 1334 1335

	if (!nbd_dbg_dir)
		return -EIO;
M
Markus Pargmann 已提交
1336 1337

	dir = debugfs_create_dir(nbd_name(nbd), nbd_dbg_dir);
1338 1339 1340 1341
	if (!dir) {
		dev_err(nbd_to_dev(nbd), "Failed to create debugfs dir for '%s'\n",
			nbd_name(nbd));
		return -EIO;
M
Markus Pargmann 已提交
1342
	}
1343
	config->dbg_dir = dir;
M
Markus Pargmann 已提交
1344

1345
	debugfs_create_file("tasks", 0444, dir, nbd, &nbd_dbg_tasks_ops);
1346
	debugfs_create_u64("size_bytes", 0444, dir, &config->bytesize);
1347
	debugfs_create_u32("timeout", 0444, dir, &nbd->tag_set.timeout);
1348
	debugfs_create_u64("blocksize", 0444, dir, &config->blksize);
1349
	debugfs_create_file("flags", 0444, dir, nbd, &nbd_dbg_flags_ops);
M
Markus Pargmann 已提交
1350 1351 1352 1353 1354 1355

	return 0;
}

static void nbd_dev_dbg_close(struct nbd_device *nbd)
{
1356
	debugfs_remove_recursive(nbd->config->dbg_dir);
M
Markus Pargmann 已提交
1357 1358 1359 1360 1361 1362 1363
}

static int nbd_dbg_init(void)
{
	struct dentry *dbg_dir;

	dbg_dir = debugfs_create_dir("nbd", NULL);
1364 1365
	if (!dbg_dir)
		return -EIO;
M
Markus Pargmann 已提交
1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398

	nbd_dbg_dir = dbg_dir;

	return 0;
}

static void nbd_dbg_close(void)
{
	debugfs_remove_recursive(nbd_dbg_dir);
}

#else  /* IS_ENABLED(CONFIG_DEBUG_FS) */

static int nbd_dev_dbg_init(struct nbd_device *nbd)
{
	return 0;
}

static void nbd_dev_dbg_close(struct nbd_device *nbd)
{
}

static int nbd_dbg_init(void)
{
	return 0;
}

static void nbd_dbg_close(void)
{
}

#endif

1399 1400
static int nbd_init_request(struct blk_mq_tag_set *set, struct request *rq,
			    unsigned int hctx_idx, unsigned int numa_node)
J
Josef Bacik 已提交
1401 1402
{
	struct nbd_cmd *cmd = blk_mq_rq_to_pdu(rq);
1403
	cmd->nbd = set->driver_data;
J
Josef Bacik 已提交
1404 1405 1406
	return 0;
}

1407
static const struct blk_mq_ops nbd_mq_ops = {
J
Josef Bacik 已提交
1408
	.queue_rq	= nbd_queue_rq,
C
Christoph Hellwig 已提交
1409
	.complete	= nbd_complete_rq,
J
Josef Bacik 已提交
1410
	.init_request	= nbd_init_request,
1411
	.timeout	= nbd_xmit_timeout,
J
Josef Bacik 已提交
1412 1413
};

1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441
static int nbd_dev_add(int index)
{
	struct nbd_device *nbd;
	struct gendisk *disk;
	struct request_queue *q;
	int err = -ENOMEM;

	nbd = kzalloc(sizeof(struct nbd_device), GFP_KERNEL);
	if (!nbd)
		goto out;

	disk = alloc_disk(1 << part_shift);
	if (!disk)
		goto out_free_nbd;

	if (index >= 0) {
		err = idr_alloc(&nbd_index_idr, nbd, index, index + 1,
				GFP_KERNEL);
		if (err == -ENOSPC)
			err = -EEXIST;
	} else {
		err = idr_alloc(&nbd_index_idr, nbd, 0, 0, GFP_KERNEL);
		if (err >= 0)
			index = err;
	}
	if (err < 0)
		goto out_free_disk;

J
Josef Bacik 已提交
1442
	nbd->index = index;
1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470
	nbd->disk = disk;
	nbd->tag_set.ops = &nbd_mq_ops;
	nbd->tag_set.nr_hw_queues = 1;
	nbd->tag_set.queue_depth = 128;
	nbd->tag_set.numa_node = NUMA_NO_NODE;
	nbd->tag_set.cmd_size = sizeof(struct nbd_cmd);
	nbd->tag_set.flags = BLK_MQ_F_SHOULD_MERGE |
		BLK_MQ_F_SG_MERGE | BLK_MQ_F_BLOCKING;
	nbd->tag_set.driver_data = nbd;

	err = blk_mq_alloc_tag_set(&nbd->tag_set);
	if (err)
		goto out_free_idr;

	q = blk_mq_init_queue(&nbd->tag_set);
	if (IS_ERR(q)) {
		err = PTR_ERR(q);
		goto out_free_tags;
	}
	disk->queue = q;

	/*
	 * Tell the block layer that we are not a rotational device
	 */
	queue_flag_set_unlocked(QUEUE_FLAG_NONROT, disk->queue);
	queue_flag_clear_unlocked(QUEUE_FLAG_ADD_RANDOM, disk->queue);
	disk->queue->limits.discard_granularity = 512;
	blk_queue_max_discard_sectors(disk->queue, UINT_MAX);
1471
	blk_queue_max_segment_size(disk->queue, UINT_MAX);
1472
	blk_queue_max_segments(disk->queue, USHRT_MAX);
1473 1474 1475 1476
	blk_queue_max_hw_sectors(disk->queue, 65536);
	disk->queue->limits.max_sectors = 256;

	mutex_init(&nbd->config_lock);
1477
	refcount_set(&nbd->config_refs, 0);
J
Josef Bacik 已提交
1478 1479
	refcount_set(&nbd->refs, 1);
	INIT_LIST_HEAD(&nbd->list);
1480 1481 1482 1483 1484 1485 1486
	disk->major = NBD_MAJOR;
	disk->first_minor = index << part_shift;
	disk->fops = &nbd_fops;
	disk->private_data = nbd;
	sprintf(disk->disk_name, "nbd%d", index);
	nbd_reset(nbd);
	add_disk(disk);
J
Josef Bacik 已提交
1487
	nbd_total_devices++;
1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501
	return index;

out_free_tags:
	blk_mq_free_tag_set(&nbd->tag_set);
out_free_idr:
	idr_remove(&nbd_index_idr, index);
out_free_disk:
	put_disk(disk);
out_free_nbd:
	kfree(nbd);
out:
	return err;
}

J
Josef Bacik 已提交
1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522
static int find_free_cb(int id, void *ptr, void *data)
{
	struct nbd_device *nbd = ptr;
	struct nbd_device **found = data;

	if (!refcount_read(&nbd->config_refs)) {
		*found = nbd;
		return 1;
	}
	return 0;
}

/* Netlink interface. */
static struct nla_policy nbd_attr_policy[NBD_ATTR_MAX + 1] = {
	[NBD_ATTR_INDEX]		=	{ .type = NLA_U32 },
	[NBD_ATTR_SIZE_BYTES]		=	{ .type = NLA_U64 },
	[NBD_ATTR_BLOCK_SIZE_BYTES]	=	{ .type = NLA_U64 },
	[NBD_ATTR_TIMEOUT]		=	{ .type = NLA_U64 },
	[NBD_ATTR_SERVER_FLAGS]		=	{ .type = NLA_U64 },
	[NBD_ATTR_CLIENT_FLAGS]		=	{ .type = NLA_U64 },
	[NBD_ATTR_SOCKETS]		=	{ .type = NLA_NESTED},
J
Josef Bacik 已提交
1523
	[NBD_ATTR_DEAD_CONN_TIMEOUT]	=	{ .type = NLA_U64 },
J
Josef Bacik 已提交
1524
	[NBD_ATTR_DEVICE_LIST]		=	{ .type = NLA_NESTED},
J
Josef Bacik 已提交
1525 1526 1527 1528 1529 1530
};

static struct nla_policy nbd_sock_policy[NBD_SOCK_MAX + 1] = {
	[NBD_SOCK_FD]			=	{ .type = NLA_U32 },
};

J
Josef Bacik 已提交
1531 1532 1533 1534 1535 1536 1537 1538 1539
/* We don't use this right now since we don't parse the incoming list, but we
 * still want it here so userspace knows what to expect.
 */
static struct nla_policy __attribute__((unused))
nbd_device_policy[NBD_DEVICE_ATTR_MAX + 1] = {
	[NBD_DEVICE_INDEX]		=	{ .type = NLA_U32 },
	[NBD_DEVICE_CONNECTED]		=	{ .type = NLA_U8 },
};

J
Josef Bacik 已提交
1540 1541 1542 1543 1544 1545
static int nbd_genl_connect(struct sk_buff *skb, struct genl_info *info)
{
	struct nbd_device *nbd = NULL;
	struct nbd_config *config;
	int index = -1;
	int ret;
1546
	bool put_dev = false;
J
Josef Bacik 已提交
1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580

	if (!netlink_capable(skb, CAP_SYS_ADMIN))
		return -EPERM;

	if (info->attrs[NBD_ATTR_INDEX])
		index = nla_get_u32(info->attrs[NBD_ATTR_INDEX]);
	if (!info->attrs[NBD_ATTR_SOCKETS]) {
		printk(KERN_ERR "nbd: must specify at least one socket\n");
		return -EINVAL;
	}
	if (!info->attrs[NBD_ATTR_SIZE_BYTES]) {
		printk(KERN_ERR "nbd: must specify a size in bytes for the device\n");
		return -EINVAL;
	}
again:
	mutex_lock(&nbd_index_mutex);
	if (index == -1) {
		ret = idr_for_each(&nbd_index_idr, &find_free_cb, &nbd);
		if (ret == 0) {
			int new_index;
			new_index = nbd_dev_add(-1);
			if (new_index < 0) {
				mutex_unlock(&nbd_index_mutex);
				printk(KERN_ERR "nbd: failed to add new device\n");
				return ret;
			}
			nbd = idr_find(&nbd_index_idr, new_index);
		}
	} else {
		nbd = idr_find(&nbd_index_idr, index);
	}
	if (!nbd) {
		printk(KERN_ERR "nbd: couldn't find device at index %d\n",
		       index);
J
Josef Bacik 已提交
1581 1582 1583 1584 1585 1586 1587 1588 1589
		mutex_unlock(&nbd_index_mutex);
		return -EINVAL;
	}
	if (!refcount_inc_not_zero(&nbd->refs)) {
		mutex_unlock(&nbd_index_mutex);
		if (index == -1)
			goto again;
		printk(KERN_ERR "nbd: device at index %d is going down\n",
		       index);
J
Josef Bacik 已提交
1590 1591
		return -EINVAL;
	}
J
Josef Bacik 已提交
1592
	mutex_unlock(&nbd_index_mutex);
J
Josef Bacik 已提交
1593 1594 1595 1596

	mutex_lock(&nbd->config_lock);
	if (refcount_read(&nbd->config_refs)) {
		mutex_unlock(&nbd->config_lock);
J
Josef Bacik 已提交
1597
		nbd_put(nbd);
J
Josef Bacik 已提交
1598 1599 1600 1601 1602 1603 1604
		if (index == -1)
			goto again;
		printk(KERN_ERR "nbd: nbd%d already in use\n", index);
		return -EBUSY;
	}
	if (WARN_ON(nbd->config)) {
		mutex_unlock(&nbd->config_lock);
J
Josef Bacik 已提交
1605
		nbd_put(nbd);
J
Josef Bacik 已提交
1606 1607 1608 1609 1610
		return -EINVAL;
	}
	config = nbd->config = nbd_alloc_config();
	if (!nbd->config) {
		mutex_unlock(&nbd->config_lock);
J
Josef Bacik 已提交
1611
		nbd_put(nbd);
J
Josef Bacik 已提交
1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632
		printk(KERN_ERR "nbd: couldn't allocate config\n");
		return -ENOMEM;
	}
	refcount_set(&nbd->config_refs, 1);
	set_bit(NBD_BOUND, &config->runtime_flags);

	if (info->attrs[NBD_ATTR_SIZE_BYTES]) {
		u64 bytes = nla_get_u64(info->attrs[NBD_ATTR_SIZE_BYTES]);
		nbd_size_set(nbd, config->blksize,
			     div64_u64(bytes, config->blksize));
	}
	if (info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]) {
		u64 bsize =
			nla_get_u64(info->attrs[NBD_ATTR_BLOCK_SIZE_BYTES]);
		nbd_size_set(nbd, bsize, div64_u64(config->bytesize, bsize));
	}
	if (info->attrs[NBD_ATTR_TIMEOUT]) {
		u64 timeout = nla_get_u64(info->attrs[NBD_ATTR_TIMEOUT]);
		nbd->tag_set.timeout = timeout * HZ;
		blk_queue_rq_timeout(nbd->disk->queue, timeout * HZ);
	}
J
Josef Bacik 已提交
1633 1634 1635 1636 1637
	if (info->attrs[NBD_ATTR_DEAD_CONN_TIMEOUT]) {
		config->dead_conn_timeout =
			nla_get_u64(info->attrs[NBD_ATTR_DEAD_CONN_TIMEOUT]);
		config->dead_conn_timeout *= HZ;
	}
J
Josef Bacik 已提交
1638 1639 1640
	if (info->attrs[NBD_ATTR_SERVER_FLAGS])
		config->flags =
			nla_get_u64(info->attrs[NBD_ATTR_SERVER_FLAGS]);
1641 1642 1643 1644 1645 1646 1647 1648 1649
	if (info->attrs[NBD_ATTR_CLIENT_FLAGS]) {
		u64 flags = nla_get_u64(info->attrs[NBD_ATTR_CLIENT_FLAGS]);
		if (flags & NBD_CFLAG_DESTROY_ON_DISCONNECT) {
			set_bit(NBD_DESTROY_ON_DISCONNECT,
				&config->runtime_flags);
			put_dev = true;
		}
	}

J
Josef Bacik 已提交
1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663
	if (info->attrs[NBD_ATTR_SOCKETS]) {
		struct nlattr *attr;
		int rem, fd;

		nla_for_each_nested(attr, info->attrs[NBD_ATTR_SOCKETS],
				    rem) {
			struct nlattr *socks[NBD_SOCK_MAX+1];

			if (nla_type(attr) != NBD_SOCK_ITEM) {
				printk(KERN_ERR "nbd: socks must be embedded in a SOCK_ITEM attr\n");
				ret = -EINVAL;
				goto out;
			}
			ret = nla_parse_nested(socks, NBD_SOCK_MAX, attr,
1664
					       nbd_sock_policy, info->extack);
J
Josef Bacik 已提交
1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686
			if (ret != 0) {
				printk(KERN_ERR "nbd: error processing sock list\n");
				ret = -EINVAL;
				goto out;
			}
			if (!socks[NBD_SOCK_FD])
				continue;
			fd = (int)nla_get_u32(socks[NBD_SOCK_FD]);
			ret = nbd_add_socket(nbd, fd, true);
			if (ret)
				goto out;
		}
	}
	ret = nbd_start_device(nbd);
out:
	mutex_unlock(&nbd->config_lock);
	if (!ret) {
		set_bit(NBD_HAS_CONFIG_REF, &config->runtime_flags);
		refcount_inc(&nbd->config_refs);
		nbd_connect_reply(info, nbd->index);
	}
	nbd_config_put(nbd);
1687 1688
	if (put_dev)
		nbd_put(nbd);
J
Josef Bacik 已提交
1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706 1707
	return ret;
}

static int nbd_genl_disconnect(struct sk_buff *skb, struct genl_info *info)
{
	struct nbd_device *nbd;
	int index;

	if (!netlink_capable(skb, CAP_SYS_ADMIN))
		return -EPERM;

	if (!info->attrs[NBD_ATTR_INDEX]) {
		printk(KERN_ERR "nbd: must specify an index to disconnect\n");
		return -EINVAL;
	}
	index = nla_get_u32(info->attrs[NBD_ATTR_INDEX]);
	mutex_lock(&nbd_index_mutex);
	nbd = idr_find(&nbd_index_idr, index);
	if (!nbd) {
J
Josef Bacik 已提交
1708
		mutex_unlock(&nbd_index_mutex);
J
Josef Bacik 已提交
1709 1710 1711 1712
		printk(KERN_ERR "nbd: couldn't find device at index %d\n",
		       index);
		return -EINVAL;
	}
J
Josef Bacik 已提交
1713 1714 1715 1716 1717 1718 1719 1720 1721
	if (!refcount_inc_not_zero(&nbd->refs)) {
		mutex_unlock(&nbd_index_mutex);
		printk(KERN_ERR "nbd: device at index %d is going down\n",
		       index);
		return -EINVAL;
	}
	mutex_unlock(&nbd_index_mutex);
	if (!refcount_inc_not_zero(&nbd->config_refs)) {
		nbd_put(nbd);
J
Josef Bacik 已提交
1722
		return 0;
J
Josef Bacik 已提交
1723
	}
J
Josef Bacik 已提交
1724 1725 1726 1727 1728 1729 1730
	mutex_lock(&nbd->config_lock);
	nbd_disconnect(nbd);
	mutex_unlock(&nbd->config_lock);
	if (test_and_clear_bit(NBD_HAS_CONFIG_REF,
			       &nbd->config->runtime_flags))
		nbd_config_put(nbd);
	nbd_config_put(nbd);
J
Josef Bacik 已提交
1731
	nbd_put(nbd);
J
Josef Bacik 已提交
1732 1733 1734
	return 0;
}

1735 1736 1737 1738 1739 1740
static int nbd_genl_reconfigure(struct sk_buff *skb, struct genl_info *info)
{
	struct nbd_device *nbd = NULL;
	struct nbd_config *config;
	int index;
	int ret = -EINVAL;
1741
	bool put_dev = false;
1742 1743 1744 1745 1746 1747 1748 1749 1750 1751 1752 1753

	if (!netlink_capable(skb, CAP_SYS_ADMIN))
		return -EPERM;

	if (!info->attrs[NBD_ATTR_INDEX]) {
		printk(KERN_ERR "nbd: must specify a device to reconfigure\n");
		return -EINVAL;
	}
	index = nla_get_u32(info->attrs[NBD_ATTR_INDEX]);
	mutex_lock(&nbd_index_mutex);
	nbd = idr_find(&nbd_index_idr, index);
	if (!nbd) {
J
Josef Bacik 已提交
1754
		mutex_unlock(&nbd_index_mutex);
1755 1756 1757 1758
		printk(KERN_ERR "nbd: couldn't find a device at index %d\n",
		       index);
		return -EINVAL;
	}
J
Josef Bacik 已提交
1759 1760 1761 1762 1763 1764 1765
	if (!refcount_inc_not_zero(&nbd->refs)) {
		mutex_unlock(&nbd_index_mutex);
		printk(KERN_ERR "nbd: device at index %d is going down\n",
		       index);
		return -EINVAL;
	}
	mutex_unlock(&nbd_index_mutex);
1766 1767 1768 1769

	if (!refcount_inc_not_zero(&nbd->config_refs)) {
		dev_err(nbd_to_dev(nbd),
			"not configured, cannot reconfigure\n");
J
Josef Bacik 已提交
1770
		nbd_put(nbd);
1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787
		return -EINVAL;
	}

	mutex_lock(&nbd->config_lock);
	config = nbd->config;
	if (!test_bit(NBD_BOUND, &config->runtime_flags) ||
	    !nbd->task_recv) {
		dev_err(nbd_to_dev(nbd),
			"not configured, cannot reconfigure\n");
		goto out;
	}

	if (info->attrs[NBD_ATTR_TIMEOUT]) {
		u64 timeout = nla_get_u64(info->attrs[NBD_ATTR_TIMEOUT]);
		nbd->tag_set.timeout = timeout * HZ;
		blk_queue_rq_timeout(nbd->disk->queue, timeout * HZ);
	}
J
Josef Bacik 已提交
1788 1789 1790 1791 1792
	if (info->attrs[NBD_ATTR_DEAD_CONN_TIMEOUT]) {
		config->dead_conn_timeout =
			nla_get_u64(info->attrs[NBD_ATTR_DEAD_CONN_TIMEOUT]);
		config->dead_conn_timeout *= HZ;
	}
1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803 1804
	if (info->attrs[NBD_ATTR_CLIENT_FLAGS]) {
		u64 flags = nla_get_u64(info->attrs[NBD_ATTR_CLIENT_FLAGS]);
		if (flags & NBD_CFLAG_DESTROY_ON_DISCONNECT) {
			if (!test_and_set_bit(NBD_DESTROY_ON_DISCONNECT,
					      &config->runtime_flags))
				put_dev = true;
		} else {
			if (test_and_clear_bit(NBD_DESTROY_ON_DISCONNECT,
					       &config->runtime_flags))
				refcount_inc(&nbd->refs);
		}
	}
1805 1806 1807 1808 1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819

	if (info->attrs[NBD_ATTR_SOCKETS]) {
		struct nlattr *attr;
		int rem, fd;

		nla_for_each_nested(attr, info->attrs[NBD_ATTR_SOCKETS],
				    rem) {
			struct nlattr *socks[NBD_SOCK_MAX+1];

			if (nla_type(attr) != NBD_SOCK_ITEM) {
				printk(KERN_ERR "nbd: socks must be embedded in a SOCK_ITEM attr\n");
				ret = -EINVAL;
				goto out;
			}
			ret = nla_parse_nested(socks, NBD_SOCK_MAX, attr,
1820
					       nbd_sock_policy, info->extack);
1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836 1837 1838 1839 1840
			if (ret != 0) {
				printk(KERN_ERR "nbd: error processing sock list\n");
				ret = -EINVAL;
				goto out;
			}
			if (!socks[NBD_SOCK_FD])
				continue;
			fd = (int)nla_get_u32(socks[NBD_SOCK_FD]);
			ret = nbd_reconnect_socket(nbd, fd);
			if (ret) {
				if (ret == -ENOSPC)
					ret = 0;
				goto out;
			}
			dev_info(nbd_to_dev(nbd), "reconnected socket\n");
		}
	}
out:
	mutex_unlock(&nbd->config_lock);
	nbd_config_put(nbd);
J
Josef Bacik 已提交
1841
	nbd_put(nbd);
1842 1843
	if (put_dev)
		nbd_put(nbd);
1844 1845 1846
	return ret;
}

J
Josef Bacik 已提交
1847 1848 1849 1850 1851 1852 1853 1854 1855 1856 1857
static const struct genl_ops nbd_connect_genl_ops[] = {
	{
		.cmd	= NBD_CMD_CONNECT,
		.policy	= nbd_attr_policy,
		.doit	= nbd_genl_connect,
	},
	{
		.cmd	= NBD_CMD_DISCONNECT,
		.policy	= nbd_attr_policy,
		.doit	= nbd_genl_disconnect,
	},
1858 1859 1860 1861 1862
	{
		.cmd	= NBD_CMD_RECONFIGURE,
		.policy	= nbd_attr_policy,
		.doit	= nbd_genl_reconfigure,
	},
J
Josef Bacik 已提交
1863 1864 1865 1866 1867
	{
		.cmd	= NBD_CMD_STATUS,
		.policy	= nbd_attr_policy,
		.doit	= nbd_genl_status,
	},
J
Josef Bacik 已提交
1868 1869
};

1870 1871 1872 1873
static const struct genl_multicast_group nbd_mcast_grps[] = {
	{ .name = NBD_GENL_MCAST_GROUP_NAME, },
};

J
Josef Bacik 已提交
1874 1875 1876 1877 1878 1879 1880 1881
static struct genl_family nbd_genl_family __ro_after_init = {
	.hdrsize	= 0,
	.name		= NBD_GENL_FAMILY_NAME,
	.version	= NBD_GENL_VERSION,
	.module		= THIS_MODULE,
	.ops		= nbd_connect_genl_ops,
	.n_ops		= ARRAY_SIZE(nbd_connect_genl_ops),
	.maxattr	= NBD_ATTR_MAX,
1882 1883
	.mcgrps		= nbd_mcast_grps,
	.n_mcgrps	= ARRAY_SIZE(nbd_mcast_grps),
J
Josef Bacik 已提交
1884 1885
};

J
Josef Bacik 已提交
1886 1887 1888 1889 1890 1891 1892 1893 1894 1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920 1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964 1965 1966 1967 1968 1969 1970 1971 1972 1973 1974 1975
static int populate_nbd_status(struct nbd_device *nbd, struct sk_buff *reply)
{
	struct nlattr *dev_opt;
	u8 connected = 0;
	int ret;

	/* This is a little racey, but for status it's ok.  The
	 * reason we don't take a ref here is because we can't
	 * take a ref in the index == -1 case as we would need
	 * to put under the nbd_index_mutex, which could
	 * deadlock if we are configured to remove ourselves
	 * once we're disconnected.
	 */
	if (refcount_read(&nbd->config_refs))
		connected = 1;
	dev_opt = nla_nest_start(reply, NBD_DEVICE_ITEM);
	if (!dev_opt)
		return -EMSGSIZE;
	ret = nla_put_u32(reply, NBD_DEVICE_INDEX, nbd->index);
	if (ret)
		return -EMSGSIZE;
	ret = nla_put_u8(reply, NBD_DEVICE_CONNECTED,
			 connected);
	if (ret)
		return -EMSGSIZE;
	nla_nest_end(reply, dev_opt);
	return 0;
}

static int status_cb(int id, void *ptr, void *data)
{
	struct nbd_device *nbd = ptr;
	return populate_nbd_status(nbd, (struct sk_buff *)data);
}

static int nbd_genl_status(struct sk_buff *skb, struct genl_info *info)
{
	struct nlattr *dev_list;
	struct sk_buff *reply;
	void *reply_head;
	size_t msg_size;
	int index = -1;
	int ret = -ENOMEM;

	if (info->attrs[NBD_ATTR_INDEX])
		index = nla_get_u32(info->attrs[NBD_ATTR_INDEX]);

	mutex_lock(&nbd_index_mutex);

	msg_size = nla_total_size(nla_attr_size(sizeof(u32)) +
				  nla_attr_size(sizeof(u8)));
	msg_size *= (index == -1) ? nbd_total_devices : 1;

	reply = genlmsg_new(msg_size, GFP_KERNEL);
	if (!reply)
		goto out;
	reply_head = genlmsg_put_reply(reply, info, &nbd_genl_family, 0,
				       NBD_CMD_STATUS);
	if (!reply_head) {
		nlmsg_free(reply);
		goto out;
	}

	dev_list = nla_nest_start(reply, NBD_ATTR_DEVICE_LIST);
	if (index == -1) {
		ret = idr_for_each(&nbd_index_idr, &status_cb, reply);
		if (ret) {
			nlmsg_free(reply);
			goto out;
		}
	} else {
		struct nbd_device *nbd;
		nbd = idr_find(&nbd_index_idr, index);
		if (nbd) {
			ret = populate_nbd_status(nbd, reply);
			if (ret) {
				nlmsg_free(reply);
				goto out;
			}
		}
	}
	nla_nest_end(reply, dev_list);
	genlmsg_end(reply, reply_head);
	genlmsg_reply(reply, info);
	ret = 0;
out:
	mutex_unlock(&nbd_index_mutex);
	return ret;
}

J
Josef Bacik 已提交
1976 1977 1978 1979 1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 1991 1992 1993 1994 1995 1996 1997 1998
static void nbd_connect_reply(struct genl_info *info, int index)
{
	struct sk_buff *skb;
	void *msg_head;
	int ret;

	skb = genlmsg_new(nla_total_size(sizeof(u32)), GFP_KERNEL);
	if (!skb)
		return;
	msg_head = genlmsg_put_reply(skb, info, &nbd_genl_family, 0,
				     NBD_CMD_CONNECT);
	if (!msg_head) {
		nlmsg_free(skb);
		return;
	}
	ret = nla_put_u32(skb, NBD_ATTR_INDEX, index);
	if (ret) {
		nlmsg_free(skb);
		return;
	}
	genlmsg_end(skb, msg_head);
	genlmsg_reply(skb, info);
}
L
Linus Torvalds 已提交
1999

2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031
static void nbd_mcast_index(int index)
{
	struct sk_buff *skb;
	void *msg_head;
	int ret;

	skb = genlmsg_new(nla_total_size(sizeof(u32)), GFP_KERNEL);
	if (!skb)
		return;
	msg_head = genlmsg_put(skb, 0, 0, &nbd_genl_family, 0,
				     NBD_CMD_LINK_DEAD);
	if (!msg_head) {
		nlmsg_free(skb);
		return;
	}
	ret = nla_put_u32(skb, NBD_ATTR_INDEX, index);
	if (ret) {
		nlmsg_free(skb);
		return;
	}
	genlmsg_end(skb, msg_head);
	genlmsg_multicast(&nbd_genl_family, skb, 0, 0, GFP_KERNEL);
}

static void nbd_dead_link_work(struct work_struct *work)
{
	struct link_dead_args *args = container_of(work, struct link_dead_args,
						   work);
	nbd_mcast_index(args->index);
	kfree(args);
}

L
Linus Torvalds 已提交
2032 2033 2034 2035
static int __init nbd_init(void)
{
	int i;

2036
	BUILD_BUG_ON(sizeof(struct nbd_request) != 28);
L
Linus Torvalds 已提交
2037

L
Laurent Vivier 已提交
2038
	if (max_part < 0) {
2039
		printk(KERN_ERR "nbd: max_part must be >= 0\n");
L
Laurent Vivier 已提交
2040 2041 2042 2043
		return -EINVAL;
	}

	part_shift = 0;
2044
	if (max_part > 0) {
L
Laurent Vivier 已提交
2045 2046
		part_shift = fls(max_part);

2047 2048 2049 2050 2051 2052 2053 2054 2055 2056 2057
		/*
		 * Adjust max_part according to part_shift as it is exported
		 * to user space so that user can know the max number of
		 * partition kernel should be able to manage.
		 *
		 * Note that -1 is required because partition 0 is reserved
		 * for the whole disk.
		 */
		max_part = (1UL << part_shift) - 1;
	}

2058 2059 2060 2061 2062
	if ((1UL << part_shift) > DISK_MAX_PARTS)
		return -EINVAL;

	if (nbds_max > 1UL << (MINORBITS - part_shift))
		return -EINVAL;
2063 2064 2065 2066
	recv_workqueue = alloc_workqueue("knbd-recv",
					 WQ_MEM_RECLAIM | WQ_HIGHPRI, 0);
	if (!recv_workqueue)
		return -ENOMEM;
2067

2068 2069
	if (register_blkdev(NBD_MAJOR, "nbd")) {
		destroy_workqueue(recv_workqueue);
2070
		return -EIO;
2071
	}
L
Linus Torvalds 已提交
2072

J
Josef Bacik 已提交
2073 2074 2075 2076 2077
	if (genl_register_family(&nbd_genl_family)) {
		unregister_blkdev(NBD_MAJOR, "nbd");
		destroy_workqueue(recv_workqueue);
		return -EINVAL;
	}
M
Markus Pargmann 已提交
2078 2079
	nbd_dbg_init();

2080 2081 2082 2083 2084 2085
	mutex_lock(&nbd_index_mutex);
	for (i = 0; i < nbds_max; i++)
		nbd_dev_add(i);
	mutex_unlock(&nbd_index_mutex);
	return 0;
}
L
Linus Torvalds 已提交
2086

2087 2088
static int nbd_exit_cb(int id, void *ptr, void *data)
{
J
Josef Bacik 已提交
2089
	struct list_head *list = (struct list_head *)data;
2090
	struct nbd_device *nbd = ptr;
J
Josef Bacik 已提交
2091 2092

	list_add_tail(&nbd->list, list);
L
Linus Torvalds 已提交
2093 2094 2095 2096 2097
	return 0;
}

static void __exit nbd_cleanup(void)
{
J
Josef Bacik 已提交
2098 2099 2100
	struct nbd_device *nbd;
	LIST_HEAD(del_list);

M
Markus Pargmann 已提交
2101 2102
	nbd_dbg_close();

J
Josef Bacik 已提交
2103 2104 2105 2106
	mutex_lock(&nbd_index_mutex);
	idr_for_each(&nbd_index_idr, &nbd_exit_cb, &del_list);
	mutex_unlock(&nbd_index_mutex);

2107 2108 2109 2110
	while (!list_empty(&del_list)) {
		nbd = list_first_entry(&del_list, struct nbd_device, list);
		list_del_init(&nbd->list);
		if (refcount_read(&nbd->refs) != 1)
J
Josef Bacik 已提交
2111 2112 2113 2114
			printk(KERN_ERR "nbd: possibly leaking a device\n");
		nbd_put(nbd);
	}

2115
	idr_destroy(&nbd_index_idr);
J
Josef Bacik 已提交
2116
	genl_unregister_family(&nbd_genl_family);
2117
	destroy_workqueue(recv_workqueue);
L
Linus Torvalds 已提交
2118 2119 2120 2121 2122 2123 2124 2125 2126
	unregister_blkdev(NBD_MAJOR, "nbd");
}

module_init(nbd_init);
module_exit(nbd_cleanup);

MODULE_DESCRIPTION("Network Block Device");
MODULE_LICENSE("GPL");

2127
module_param(nbds_max, int, 0444);
L
Laurent Vivier 已提交
2128 2129 2130
MODULE_PARM_DESC(nbds_max, "number of network block devices to initialize (default: 16)");
module_param(max_part, int, 0444);
MODULE_PARM_DESC(max_part, "number of partitions per device (default: 0)");