call_object.c 20.6 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11
/* RxRPC individual remote procedure call handling
 *
 * Copyright (C) 2007 Red Hat, Inc. All Rights Reserved.
 * Written by David Howells (dhowells@redhat.com)
 *
 * This program is free software; you can redistribute it and/or
 * modify it under the terms of the GNU General Public License
 * as published by the Free Software Foundation; either version
 * 2 of the License, or (at your option) any later version.
 */

12 13
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

14
#include <linux/slab.h>
15 16
#include <linux/module.h>
#include <linux/circ_buf.h>
17
#include <linux/spinlock_types.h>
18 19 20 21
#include <net/sock.h>
#include <net/af_rxrpc.h>
#include "ar-internal.h"

22 23 24
/*
 * Maximum lifetime of a call (in jiffies).
 */
25
unsigned int rxrpc_max_call_lifetime = 60 * HZ;
26 27 28 29

/*
 * Time till dead call expires after last use (in jiffies).
 */
30
unsigned int rxrpc_dead_call_expiry = 2 * HZ;
31

32
const char *const rxrpc_call_states[NR__RXRPC_CALL_STATES] = {
33 34
	[RXRPC_CALL_UNINITIALISED]		= "Uninit",
	[RXRPC_CALL_CLIENT_AWAIT_CONN]		= "ClWtConn",
35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52
	[RXRPC_CALL_CLIENT_SEND_REQUEST]	= "ClSndReq",
	[RXRPC_CALL_CLIENT_AWAIT_REPLY]		= "ClAwtRpl",
	[RXRPC_CALL_CLIENT_RECV_REPLY]		= "ClRcvRpl",
	[RXRPC_CALL_CLIENT_FINAL_ACK]		= "ClFnlACK",
	[RXRPC_CALL_SERVER_SECURING]		= "SvSecure",
	[RXRPC_CALL_SERVER_ACCEPTING]		= "SvAccept",
	[RXRPC_CALL_SERVER_RECV_REQUEST]	= "SvRcvReq",
	[RXRPC_CALL_SERVER_ACK_REQUEST]		= "SvAckReq",
	[RXRPC_CALL_SERVER_SEND_REPLY]		= "SvSndRpl",
	[RXRPC_CALL_SERVER_AWAIT_ACK]		= "SvAwtACK",
	[RXRPC_CALL_COMPLETE]			= "Complete",
	[RXRPC_CALL_SERVER_BUSY]		= "SvBusy  ",
	[RXRPC_CALL_REMOTELY_ABORTED]		= "RmtAbort",
	[RXRPC_CALL_LOCALLY_ABORTED]		= "LocAbort",
	[RXRPC_CALL_NETWORK_ERROR]		= "NetError",
	[RXRPC_CALL_DEAD]			= "Dead    ",
};

53 54 55 56 57 58 59 60 61 62
struct kmem_cache *rxrpc_call_jar;
LIST_HEAD(rxrpc_calls);
DEFINE_RWLOCK(rxrpc_call_lock);

static void rxrpc_destroy_call(struct work_struct *work);
static void rxrpc_call_life_expired(unsigned long _call);
static void rxrpc_dead_call_expired(unsigned long _call);
static void rxrpc_ack_time_expired(unsigned long _call);
static void rxrpc_resend_time_expired(unsigned long _call);

63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
/*
 * find an extant server call
 * - called in process context with IRQs enabled
 */
struct rxrpc_call *rxrpc_find_call_by_user_ID(struct rxrpc_sock *rx,
					      unsigned long user_call_ID)
{
	struct rxrpc_call *call;
	struct rb_node *p;

	_enter("%p,%lx", rx, user_call_ID);

	read_lock(&rx->call_lock);

	p = rx->calls.rb_node;
	while (p) {
		call = rb_entry(p, struct rxrpc_call, sock_node);

		if (user_call_ID < call->user_call_ID)
			p = p->rb_left;
		else if (user_call_ID > call->user_call_ID)
			p = p->rb_right;
		else
			goto found_extant_call;
	}

	read_unlock(&rx->call_lock);
	_leave(" = NULL");
	return NULL;

found_extant_call:
	rxrpc_get_call(call);
	read_unlock(&rx->call_lock);
	_leave(" = %p [%d]", call, atomic_read(&call->usage));
	return call;
}

100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128
/*
 * allocate a new call
 */
static struct rxrpc_call *rxrpc_alloc_call(gfp_t gfp)
{
	struct rxrpc_call *call;

	call = kmem_cache_zalloc(rxrpc_call_jar, gfp);
	if (!call)
		return NULL;

	call->acks_winsz = 16;
	call->acks_window = kmalloc(call->acks_winsz * sizeof(unsigned long),
				    gfp);
	if (!call->acks_window) {
		kmem_cache_free(rxrpc_call_jar, call);
		return NULL;
	}

	setup_timer(&call->lifetimer, &rxrpc_call_life_expired,
		    (unsigned long) call);
	setup_timer(&call->deadspan, &rxrpc_dead_call_expired,
		    (unsigned long) call);
	setup_timer(&call->ack_timer, &rxrpc_ack_time_expired,
		    (unsigned long) call);
	setup_timer(&call->resend_timer, &rxrpc_resend_time_expired,
		    (unsigned long) call);
	INIT_WORK(&call->destroyer, &rxrpc_destroy_call);
	INIT_WORK(&call->processor, &rxrpc_process_call);
129
	INIT_LIST_HEAD(&call->link);
130
	INIT_LIST_HEAD(&call->chan_wait_link);
131 132 133
	INIT_LIST_HEAD(&call->accept_link);
	skb_queue_head_init(&call->rx_queue);
	skb_queue_head_init(&call->rx_oos_queue);
134
	init_waitqueue_head(&call->waitq);
135 136 137 138 139 140 141 142 143 144
	spin_lock_init(&call->lock);
	rwlock_init(&call->state_lock);
	atomic_set(&call->usage, 1);
	call->debug_id = atomic_inc_return(&rxrpc_debug_id);

	memset(&call->sock_node, 0xed, sizeof(call->sock_node));

	call->rx_data_expect = 1;
	call->rx_data_eaten = 0;
	call->rx_first_oos = 0;
145
	call->ackr_win_top = call->rx_data_eaten + 1 + rxrpc_rx_window_size;
146 147 148 149 150
	call->creation_jif = jiffies;
	return call;
}

/*
151
 * Allocate a new client call.
152
 */
153 154 155
static struct rxrpc_call *rxrpc_alloc_client_call(struct rxrpc_sock *rx,
						  struct sockaddr_rxrpc *srx,
						  gfp_t gfp)
156 157 158 159 160
{
	struct rxrpc_call *call;

	_enter("");

161
	ASSERT(rx->local != NULL);
162 163 164 165

	call = rxrpc_alloc_call(gfp);
	if (!call)
		return ERR_PTR(-ENOMEM);
166
	call->state = RXRPC_CALL_CLIENT_AWAIT_CONN;
167 168 169 170

	sock_hold(&rx->sk);
	call->socket = rx;
	call->rx_data_post = 1;
171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189
	call->service_id = srx->srx_service;

	_leave(" = %p", call);
	return call;
}

/*
 * Begin client call.
 */
static int rxrpc_begin_client_call(struct rxrpc_call *call,
				   struct rxrpc_conn_parameters *cp,
				   struct sockaddr_rxrpc *srx,
				   gfp_t gfp)
{
	int ret;

	/* Set up or get a connection record and set the protocol parameters,
	 * including channel number and call ID.
	 */
190
	ret = rxrpc_connect_call(call, cp, srx, gfp);
191 192 193 194 195
	if (ret < 0)
		return ret;

	call->state = RXRPC_CALL_CLIENT_SEND_REQUEST;

196 197 198
	spin_lock(&call->conn->params.peer->lock);
	hlist_add_head(&call->error_link, &call->conn->params.peer->error_targets);
	spin_unlock(&call->conn->params.peer->lock);
199

200
	call->lifetimer.expires = jiffies + rxrpc_max_call_lifetime;
201
	add_timer(&call->lifetimer);
202
	return 0;
203 204 205 206 207 208
}

/*
 * set up a call for the given data
 * - called in process context with IRQs enabled
 */
209
struct rxrpc_call *rxrpc_new_client_call(struct rxrpc_sock *rx,
210
					 struct rxrpc_conn_parameters *cp,
211
					 struct sockaddr_rxrpc *srx,
212 213 214
					 unsigned long user_call_ID,
					 gfp_t gfp)
{
215 216
	struct rxrpc_call *call, *xcall;
	struct rb_node *parent, **pp;
217
	int ret;
218

219
	_enter("%p,%lx", rx, user_call_ID);
220

221
	call = rxrpc_alloc_client_call(rx, srx, gfp);
222 223 224
	if (IS_ERR(call)) {
		_leave(" = %ld", PTR_ERR(call));
		return call;
225 226
	}

227
	/* Publish the call, even though it is incompletely set up as yet */
228 229
	call->user_call_ID = user_call_ID;
	__set_bit(RXRPC_CALL_HAS_USERID, &call->flags);
230 231 232 233 234 235 236

	write_lock(&rx->call_lock);

	pp = &rx->calls.rb_node;
	parent = NULL;
	while (*pp) {
		parent = *pp;
237
		xcall = rb_entry(parent, struct rxrpc_call, sock_node);
238

239
		if (user_call_ID < xcall->user_call_ID)
240
			pp = &(*pp)->rb_left;
241
		else if (user_call_ID > xcall->user_call_ID)
242 243
			pp = &(*pp)->rb_right;
		else
244
			goto found_user_ID_now_present;
245 246 247 248 249 250 251 252 253 254 255 256
	}

	rxrpc_get_call(call);

	rb_link_node(&call->sock_node, parent, pp);
	rb_insert_color(&call->sock_node, &rx->calls);
	write_unlock(&rx->call_lock);

	write_lock_bh(&rxrpc_call_lock);
	list_add_tail(&call->link, &rxrpc_calls);
	write_unlock_bh(&rxrpc_call_lock);

257
	ret = rxrpc_begin_client_call(call, cp, srx, gfp);
258 259 260
	if (ret < 0)
		goto error;

261 262 263 264 265
	_net("CALL new %d on CONN %d", call->debug_id, call->conn->debug_id);

	_leave(" = %p [new]", call);
	return call;

266 267 268 269 270 271 272
error:
	write_lock(&rx->call_lock);
	rb_erase(&call->sock_node, &rx->calls);
	write_unlock(&rx->call_lock);
	rxrpc_put_call(call);

	write_lock_bh(&rxrpc_call_lock);
273
	list_del_init(&call->link);
274 275
	write_unlock_bh(&rxrpc_call_lock);

276
	set_bit(RXRPC_CALL_RELEASED, &call->flags);
277
	call->state = RXRPC_CALL_DEAD;
278 279 280 281
	rxrpc_put_call(call);
	_leave(" = %d", ret);
	return ERR_PTR(ret);

282 283 284 285 286 287
	/* We unexpectedly found the user ID in the list after taking
	 * the call_lock.  This shouldn't happen unless the user races
	 * with itself and tries to add the same user ID twice at the
	 * same time in different threads.
	 */
found_user_ID_now_present:
288
	write_unlock(&rx->call_lock);
289
	set_bit(RXRPC_CALL_RELEASED, &call->flags);
290
	call->state = RXRPC_CALL_DEAD;
291 292 293
	rxrpc_put_call(call);
	_leave(" = -EEXIST [%p]", call);
	return ERR_PTR(-EEXIST);
294 295 296 297 298 299 300 301
}

/*
 * set up an incoming call
 * - called in process context with IRQs enabled
 */
struct rxrpc_call *rxrpc_incoming_call(struct rxrpc_sock *rx,
				       struct rxrpc_connection *conn,
302
				       struct sk_buff *skb)
303
{
304
	struct rxrpc_skb_priv *sp = rxrpc_skb(skb);
305
	struct rxrpc_call *call, *candidate;
306
	u32 call_id, chan;
307

308
	_enter(",%d", conn->debug_id);
309 310 311

	ASSERT(rx != NULL);

312
	candidate = rxrpc_alloc_call(GFP_NOIO);
313 314 315
	if (!candidate)
		return ERR_PTR(-EBUSY);

316
	chan = sp->hdr.cid & RXRPC_CHANNELMASK;
317 318
	candidate->socket	= rx;
	candidate->conn		= conn;
319
	candidate->peer		= conn->params.peer;
320 321 322 323
	candidate->cid		= sp->hdr.cid;
	candidate->call_id	= sp->hdr.callNumber;
	candidate->rx_data_post	= 0;
	candidate->state	= RXRPC_CALL_SERVER_ACCEPTING;
324
	candidate->flags	|= (1 << RXRPC_CALL_IS_SERVICE);
325 326 327
	if (conn->security_ix > 0)
		candidate->state = RXRPC_CALL_SERVER_SECURING;

328
	spin_lock(&conn->channel_lock);
329 330

	/* set the channel for this call */
331 332 333
	call = rcu_dereference_protected(conn->channels[chan].call,
					 lockdep_is_held(&conn->channel_lock));

334
	_debug("channel[%u] is %p", candidate->cid & RXRPC_CHANNELMASK, call);
335
	if (call && call->call_id == sp->hdr.callNumber) {
336 337 338 339 340 341 342
		/* already set; must've been a duplicate packet */
		_debug("extant call [%d]", call->state);
		ASSERTCMP(call->conn, ==, conn);

		read_lock(&call->state_lock);
		switch (call->state) {
		case RXRPC_CALL_LOCALLY_ABORTED:
343
			if (!test_and_set_bit(RXRPC_CALL_EV_ABORT, &call->events))
344
				rxrpc_queue_call(call);
345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361
		case RXRPC_CALL_REMOTELY_ABORTED:
			read_unlock(&call->state_lock);
			goto aborted_call;
		default:
			rxrpc_get_call(call);
			read_unlock(&call->state_lock);
			goto extant_call;
		}
	}

	if (call) {
		/* it seems the channel is still in use from the previous call
		 * - ditch the old binding if its call is now complete */
		_debug("CALL: %u { %s }",
		       call->debug_id, rxrpc_call_states[call->state]);

		if (call->state >= RXRPC_CALL_COMPLETE) {
362
			__rxrpc_disconnect_call(conn, call);
363
		} else {
364
			spin_unlock(&conn->channel_lock);
365 366 367 368 369 370 371 372
			kmem_cache_free(rxrpc_call_jar, candidate);
			_leave(" = -EBUSY");
			return ERR_PTR(-EBUSY);
		}
	}

	/* check the call number isn't duplicate */
	_debug("check dup");
373
	call_id = sp->hdr.callNumber;
374 375 376 377 378 379

	/* We just ignore calls prior to the current call ID.  Terminated calls
	 * are handled via the connection.
	 */
	if (call_id <= conn->channels[chan].call_counter)
		goto old_call; /* TODO: Just drop packet */
380 381 382 383 384

	/* make the call available */
	_debug("new call");
	call = candidate;
	candidate = NULL;
385 386
	conn->channels[chan].call_counter = call_id;
	rcu_assign_pointer(conn->channels[chan].call, call);
387
	sock_hold(&rx->sk);
388
	rxrpc_get_connection(conn);
389
	rxrpc_get_peer(call->peer);
390
	spin_unlock(&conn->channel_lock);
391

392 393 394
	spin_lock(&conn->params.peer->lock);
	hlist_add_head(&call->error_link, &conn->params.peer->error_targets);
	spin_unlock(&conn->params.peer->lock);
395 396 397 398 399

	write_lock_bh(&rxrpc_call_lock);
	list_add_tail(&call->link, &rxrpc_calls);
	write_unlock_bh(&rxrpc_call_lock);

400
	call->service_id = conn->params.service_id;
401

402 403
	_net("CALL incoming %d on CONN %d", call->debug_id, call->conn->debug_id);

404
	call->lifetimer.expires = jiffies + rxrpc_max_call_lifetime;
405 406 407 408 409
	add_timer(&call->lifetimer);
	_leave(" = %p {%d} [new]", call, call->debug_id);
	return call;

extant_call:
410
	spin_unlock(&conn->channel_lock);
411 412 413 414 415
	kmem_cache_free(rxrpc_call_jar, candidate);
	_leave(" = %p {%d} [extant]", call, call ? call->debug_id : -1);
	return call;

aborted_call:
416
	spin_unlock(&conn->channel_lock);
417 418 419 420 421
	kmem_cache_free(rxrpc_call_jar, candidate);
	_leave(" = -ECONNABORTED");
	return ERR_PTR(-ECONNABORTED);

old_call:
422
	spin_unlock(&conn->channel_lock);
423 424 425 426 427 428 429 430 431 432
	kmem_cache_free(rxrpc_call_jar, candidate);
	_leave(" = -ECONNRESET [old]");
	return ERR_PTR(-ECONNRESET);
}

/*
 * detach a call from a socket and set up for release
 */
void rxrpc_release_call(struct rxrpc_call *call)
{
433
	struct rxrpc_connection *conn = call->conn;
434 435 436 437 438 439 440 441 442 443 444 445 446 447 448
	struct rxrpc_sock *rx = call->socket;

	_enter("{%d,%d,%d,%d}",
	       call->debug_id, atomic_read(&call->usage),
	       atomic_read(&call->ackr_not_idle),
	       call->rx_first_oos);

	spin_lock_bh(&call->lock);
	if (test_and_set_bit(RXRPC_CALL_RELEASED, &call->flags))
		BUG();
	spin_unlock_bh(&call->lock);

	/* dissociate from the socket
	 * - the socket's ref on the call is passed to the death timer
	 */
449
	_debug("RELEASE CALL %p (%d CONN %p)", call, call->debug_id, conn);
450

451 452 453 454
	spin_lock(&conn->params.peer->lock);
	hlist_del_init(&call->error_link);
	spin_unlock(&conn->params.peer->lock);

455 456 457 458 459 460 461 462 463 464 465 466 467 468 469
	write_lock_bh(&rx->call_lock);
	if (!list_empty(&call->accept_link)) {
		_debug("unlinking once-pending call %p { e=%lx f=%lx }",
		       call, call->events, call->flags);
		ASSERT(!test_bit(RXRPC_CALL_HAS_USERID, &call->flags));
		list_del_init(&call->accept_link);
		sk_acceptq_removed(&rx->sk);
	} else if (test_bit(RXRPC_CALL_HAS_USERID, &call->flags)) {
		rb_erase(&call->sock_node, &rx->calls);
		memset(&call->sock_node, 0xdd, sizeof(call->sock_node));
		clear_bit(RXRPC_CALL_HAS_USERID, &call->flags);
	}
	write_unlock_bh(&rx->call_lock);

	/* free up the channel for reuse */
470
	write_lock_bh(&call->state_lock);
471

472 473 474 475
	if (call->state < RXRPC_CALL_COMPLETE &&
	    call->state != RXRPC_CALL_CLIENT_FINAL_ACK) {
		_debug("+++ ABORTING STATE %d +++\n", call->state);
		call->state = RXRPC_CALL_LOCALLY_ABORTED;
476
		call->local_abort = RX_CALL_DEAD;
477
	}
478
	write_unlock_bh(&call->state_lock);
479

480 481
	rxrpc_disconnect_call(call);

482
	/* clean up the Rx queue */
483 484 485 486 487 488 489 490 491 492 493 494
	if (!skb_queue_empty(&call->rx_queue) ||
	    !skb_queue_empty(&call->rx_oos_queue)) {
		struct rxrpc_skb_priv *sp;
		struct sk_buff *skb;

		_debug("purge Rx queues");

		spin_lock_bh(&call->lock);
		while ((skb = skb_dequeue(&call->rx_queue)) ||
		       (skb = skb_dequeue(&call->rx_oos_queue))) {
			spin_unlock_bh(&call->lock);

495
			sp = rxrpc_skb(skb);
496 497
			_debug("- zap %s %%%u #%u",
			       rxrpc_pkts[sp->hdr.type],
498
			       sp->hdr.serial, sp->hdr.seq);
499 500 501 502 503 504 505 506 507 508 509
			rxrpc_free_skb(skb);
			spin_lock_bh(&call->lock);
		}
		spin_unlock_bh(&call->lock);

		ASSERTCMP(call->state, !=, RXRPC_CALL_COMPLETE);
	}

	del_timer_sync(&call->resend_timer);
	del_timer_sync(&call->ack_timer);
	del_timer_sync(&call->lifetimer);
510
	call->deadspan.expires = jiffies + rxrpc_dead_call_expiry;
511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544
	add_timer(&call->deadspan);

	_leave("");
}

/*
 * handle a dead call being ready for reaping
 */
static void rxrpc_dead_call_expired(unsigned long _call)
{
	struct rxrpc_call *call = (struct rxrpc_call *) _call;

	_enter("{%d}", call->debug_id);

	write_lock_bh(&call->state_lock);
	call->state = RXRPC_CALL_DEAD;
	write_unlock_bh(&call->state_lock);
	rxrpc_put_call(call);
}

/*
 * mark a call as to be released, aborting it if it's still in progress
 * - called with softirqs disabled
 */
static void rxrpc_mark_call_released(struct rxrpc_call *call)
{
	bool sched;

	write_lock(&call->state_lock);
	if (call->state < RXRPC_CALL_DEAD) {
		sched = false;
		if (call->state < RXRPC_CALL_COMPLETE) {
			_debug("abort call %p", call);
			call->state = RXRPC_CALL_LOCALLY_ABORTED;
545
			call->local_abort = RX_CALL_DEAD;
546
			if (!test_and_set_bit(RXRPC_CALL_EV_ABORT, &call->events))
547 548
				sched = true;
		}
549
		if (!test_and_set_bit(RXRPC_CALL_EV_RELEASE, &call->events))
550 551
			sched = true;
		if (sched)
552
			rxrpc_queue_call(call);
553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577
	}
	write_unlock(&call->state_lock);
}

/*
 * release all the calls associated with a socket
 */
void rxrpc_release_calls_on_socket(struct rxrpc_sock *rx)
{
	struct rxrpc_call *call;
	struct rb_node *p;

	_enter("%p", rx);

	read_lock_bh(&rx->call_lock);

	/* kill the not-yet-accepted incoming calls */
	list_for_each_entry(call, &rx->secureq, accept_link) {
		rxrpc_mark_call_released(call);
	}

	list_for_each_entry(call, &rx->acceptq, accept_link) {
		rxrpc_mark_call_released(call);
	}

578 579 580 581 582 583
	/* mark all the calls as no longer wanting incoming packets */
	for (p = rb_first(&rx->calls); p; p = rb_next(p)) {
		call = rb_entry(p, struct rxrpc_call, sock_node);
		rxrpc_mark_call_released(call);
	}

584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600
	read_unlock_bh(&rx->call_lock);
	_leave("");
}

/*
 * release a call
 */
void __rxrpc_put_call(struct rxrpc_call *call)
{
	ASSERT(call != NULL);

	_enter("%p{u=%d}", call, atomic_read(&call->usage));

	ASSERTCMP(atomic_read(&call->usage), >, 0);

	if (atomic_dec_and_test(&call->usage)) {
		_debug("call %d dead", call->debug_id);
601
		WARN_ON(atomic_read(&call->skb_count) != 0);
602
		ASSERTCMP(call->state, ==, RXRPC_CALL_DEAD);
603
		rxrpc_queue_work(&call->destroyer);
604 605 606 607
	}
	_leave("");
}

608 609 610 611 612 613 614 615
/*
 * Final call destruction under RCU.
 */
static void rxrpc_rcu_destroy_call(struct rcu_head *rcu)
{
	struct rxrpc_call *call = container_of(rcu, struct rxrpc_call, rcu);

	rxrpc_purge_queue(&call->rx_queue);
616
	rxrpc_put_peer(call->peer);
617 618 619
	kmem_cache_free(rxrpc_call_jar, call);
}

620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639
/*
 * clean up a call
 */
static void rxrpc_cleanup_call(struct rxrpc_call *call)
{
	_net("DESTROY CALL %d", call->debug_id);

	ASSERT(call->socket);

	memset(&call->sock_node, 0xcd, sizeof(call->sock_node));

	del_timer_sync(&call->lifetimer);
	del_timer_sync(&call->deadspan);
	del_timer_sync(&call->ack_timer);
	del_timer_sync(&call->resend_timer);

	ASSERT(test_bit(RXRPC_CALL_RELEASED, &call->flags));
	ASSERTCMP(call->events, ==, 0);
	if (work_pending(&call->processor)) {
		_debug("defer destroy");
640
		rxrpc_queue_work(&call->destroyer);
641 642 643
		return;
	}

644
	ASSERTCMP(call->conn, ==, NULL);
645 646 647 648 649 650 651 652 653 654 655 656

	if (call->acks_window) {
		_debug("kill Tx window %d",
		       CIRC_CNT(call->acks_head, call->acks_tail,
				call->acks_winsz));
		smp_mb();
		while (CIRC_CNT(call->acks_head, call->acks_tail,
				call->acks_winsz) > 0) {
			struct rxrpc_skb_priv *sp;
			unsigned long _skb;

			_skb = call->acks_window[call->acks_tail] & ~1;
657 658 659
			sp = rxrpc_skb((struct sk_buff *)_skb);
			_debug("+++ clear Tx %u", sp->hdr.seq);
			rxrpc_free_skb((struct sk_buff *)_skb);
660 661 662 663 664 665 666 667 668 669 670 671
			call->acks_tail =
				(call->acks_tail + 1) & (call->acks_winsz - 1);
		}

		kfree(call->acks_window);
	}

	rxrpc_free_skb(call->tx_pending);

	rxrpc_purge_queue(&call->rx_queue);
	ASSERT(skb_queue_empty(&call->rx_oos_queue));
	sock_put(&call->socket->sk);
672
	call_rcu(&call->rcu, rxrpc_rcu_destroy_call);
673 674 675 676 677 678 679 680 681 682
}

/*
 * destroy a call
 */
static void rxrpc_destroy_call(struct work_struct *work)
{
	struct rxrpc_call *call =
		container_of(work, struct rxrpc_call, destroyer);

683 684
	_enter("%p{%d,%x,%p}",
	       call, atomic_read(&call->usage), call->cid, call->conn);
685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723

	ASSERTCMP(call->state, ==, RXRPC_CALL_DEAD);

	write_lock_bh(&rxrpc_call_lock);
	list_del_init(&call->link);
	write_unlock_bh(&rxrpc_call_lock);

	rxrpc_cleanup_call(call);
	_leave("");
}

/*
 * preemptively destroy all the call records from a transport endpoint rather
 * than waiting for them to time out
 */
void __exit rxrpc_destroy_all_calls(void)
{
	struct rxrpc_call *call;

	_enter("");
	write_lock_bh(&rxrpc_call_lock);

	while (!list_empty(&rxrpc_calls)) {
		call = list_entry(rxrpc_calls.next, struct rxrpc_call, link);
		_debug("Zapping call %p", call);

		list_del_init(&call->link);

		switch (atomic_read(&call->usage)) {
		case 0:
			ASSERTCMP(call->state, ==, RXRPC_CALL_DEAD);
			break;
		case 1:
			if (del_timer_sync(&call->deadspan) != 0 &&
			    call->state != RXRPC_CALL_DEAD)
				rxrpc_dead_call_expired((unsigned long) call);
			if (call->state != RXRPC_CALL_DEAD)
				break;
		default:
724
			pr_err("Call %p still in use (%d,%d,%s,%lx,%lx)!\n",
725 726 727 728 729
			       call, atomic_read(&call->usage),
			       atomic_read(&call->ackr_not_idle),
			       rxrpc_call_states[call->state],
			       call->flags, call->events);
			if (!skb_queue_empty(&call->rx_queue))
730
				pr_err("Rx queue occupied\n");
731
			if (!skb_queue_empty(&call->rx_oos_queue))
732
				pr_err("OOS queue occupied\n");
733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757
			break;
		}

		write_unlock_bh(&rxrpc_call_lock);
		cond_resched();
		write_lock_bh(&rxrpc_call_lock);
	}

	write_unlock_bh(&rxrpc_call_lock);
	_leave("");
}

/*
 * handle call lifetime being exceeded
 */
static void rxrpc_call_life_expired(unsigned long _call)
{
	struct rxrpc_call *call = (struct rxrpc_call *) _call;

	if (call->state >= RXRPC_CALL_COMPLETE)
		return;

	_enter("{%d}", call->debug_id);
	read_lock_bh(&call->state_lock);
	if (call->state < RXRPC_CALL_COMPLETE) {
758
		set_bit(RXRPC_CALL_EV_LIFE_TIMER, &call->events);
759
		rxrpc_queue_call(call);
760 761 762 763 764 765
	}
	read_unlock_bh(&call->state_lock);
}

/*
 * handle resend timer expiry
766
 * - may not take call->state_lock as this can deadlock against del_timer_sync()
767 768 769 770 771 772 773 774 775 776 777
 */
static void rxrpc_resend_time_expired(unsigned long _call)
{
	struct rxrpc_call *call = (struct rxrpc_call *) _call;

	_enter("{%d}", call->debug_id);

	if (call->state >= RXRPC_CALL_COMPLETE)
		return;

	clear_bit(RXRPC_CALL_RUN_RTIMER, &call->flags);
778
	if (!test_and_set_bit(RXRPC_CALL_EV_RESEND_TIMER, &call->events))
779
		rxrpc_queue_call(call);
780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795
}

/*
 * handle ACK timer expiry
 */
static void rxrpc_ack_time_expired(unsigned long _call)
{
	struct rxrpc_call *call = (struct rxrpc_call *) _call;

	_enter("{%d}", call->debug_id);

	if (call->state >= RXRPC_CALL_COMPLETE)
		return;

	read_lock_bh(&call->state_lock);
	if (call->state < RXRPC_CALL_COMPLETE &&
796
	    !test_and_set_bit(RXRPC_CALL_EV_ACK, &call->events))
797
		rxrpc_queue_call(call);
798 799
	read_unlock_bh(&call->state_lock);
}