user_mad.c 28.2 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 * Copyright (c) 2004 Topspin Communications.  All rights reserved.
R
Roland Dreier 已提交
3
 * Copyright (c) 2005 Voltaire, Inc. All rights reserved.
4
 * Copyright (c) 2005 Sun Microsystems, Inc. All rights reserved.
L
Linus Torvalds 已提交
5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33
 *
 * This software is available to you under a choice of one of two
 * licenses.  You may choose to be licensed under the terms of the GNU
 * General Public License (GPL) Version 2, available from the file
 * COPYING in the main directory of this source tree, or the
 * OpenIB.org BSD license below:
 *
 *     Redistribution and use in source and binary forms, with or
 *     without modification, are permitted provided that the following
 *     conditions are met:
 *
 *      - Redistributions of source code must retain the above
 *        copyright notice, this list of conditions and the following
 *        disclaimer.
 *
 *      - Redistributions in binary form must reproduce the above
 *        copyright notice, this list of conditions and the following
 *        disclaimer in the documentation and/or other materials
 *        provided with the distribution.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
 * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
 * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
 * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
 * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
 * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
 * SOFTWARE.
 *
34
 * $Id: user_mad.c 5596 2006-03-03 01:00:07Z sean.hefty $
L
Linus Torvalds 已提交
35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51
 */

#include <linux/module.h>
#include <linux/init.h>
#include <linux/device.h>
#include <linux/err.h>
#include <linux/fs.h>
#include <linux/cdev.h>
#include <linux/pci.h>
#include <linux/dma-mapping.h>
#include <linux/poll.h>
#include <linux/rwsem.h>
#include <linux/kref.h>

#include <asm/uaccess.h>
#include <asm/semaphore.h>

52 53
#include <rdma/ib_mad.h>
#include <rdma/ib_user_mad.h>
L
Linus Torvalds 已提交
54 55 56 57 58 59 60 61 62 63 64 65 66

MODULE_AUTHOR("Roland Dreier");
MODULE_DESCRIPTION("InfiniBand userspace MAD packet access");
MODULE_LICENSE("Dual BSD/GPL");

enum {
	IB_UMAD_MAX_PORTS  = 64,
	IB_UMAD_MAX_AGENTS = 32,

	IB_UMAD_MAJOR      = 231,
	IB_UMAD_MINOR_BASE = 0
};

67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88
/*
 * Our lifetime rules for these structs are the following: each time a
 * device special file is opened, we look up the corresponding struct
 * ib_umad_port by minor in the umad_port[] table while holding the
 * port_lock.  If this lookup succeeds, we take a reference on the
 * ib_umad_port's struct ib_umad_device while still holding the
 * port_lock; if the lookup fails, we fail the open().  We drop these
 * references in the corresponding close().
 *
 * In addition to references coming from open character devices, there
 * is one more reference to each ib_umad_device representing the
 * module's reference taken when allocating the ib_umad_device in
 * ib_umad_add_one().
 *
 * When destroying an ib_umad_device, we clear all of its
 * ib_umad_ports from umad_port[] while holding port_lock before
 * dropping the module's reference to the ib_umad_device.  This is
 * always safe because any open() calls will either succeed and obtain
 * a reference before we clear the umad_port[] entries, or fail after
 * we clear the umad_port[] entries.
 */

L
Linus Torvalds 已提交
89
struct ib_umad_port {
90 91
	struct cdev           *dev;
	struct class_device   *class_dev;
L
Linus Torvalds 已提交
92

93 94
	struct cdev           *sm_dev;
	struct class_device   *sm_class_dev;
L
Linus Torvalds 已提交
95 96
	struct semaphore       sm_sem;

97 98 99
	struct rw_semaphore    mutex;
	struct list_head       file_list;

L
Linus Torvalds 已提交
100 101
	struct ib_device      *ib_dev;
	struct ib_umad_device *umad_dev;
102
	int                    dev_num;
L
Linus Torvalds 已提交
103 104 105 106 107 108 109 110 111 112
	u8                     port_num;
};

struct ib_umad_device {
	int                  start_port, end_port;
	struct kref          ref;
	struct ib_umad_port  port[0];
};

struct ib_umad_file {
113 114
	struct ib_umad_port    *port;
	struct list_head	recv_list;
115
	struct list_head	send_list;
116 117
	struct list_head	port_list;
	spinlock_t		recv_lock;
118
	spinlock_t		send_lock;
119 120 121
	wait_queue_head_t	recv_wait;
	struct ib_mad_agent    *agent[IB_UMAD_MAX_AGENTS];
	int			agents_dead;
L
Linus Torvalds 已提交
122 123 124
};

struct ib_umad_packet {
125
	struct ib_mad_send_buf *msg;
126
	struct ib_mad_recv_wc  *recv_wc;
L
Linus Torvalds 已提交
127
	struct list_head   list;
128 129
	int		   length;
	struct ib_user_mad mad;
L
Linus Torvalds 已提交
130 131
};

132 133
static struct class *umad_class;

L
Linus Torvalds 已提交
134
static const dev_t base_dev = MKDEV(IB_UMAD_MAJOR, IB_UMAD_MINOR_BASE);
135 136 137

static DEFINE_SPINLOCK(port_lock);
static struct ib_umad_port *umad_port[IB_UMAD_MAX_PORTS];
L
Linus Torvalds 已提交
138 139 140 141 142
static DECLARE_BITMAP(dev_map, IB_UMAD_MAX_PORTS * 2);

static void ib_umad_add_one(struct ib_device *device);
static void ib_umad_remove_one(struct ib_device *device);

143 144 145 146 147 148 149 150
static void ib_umad_release_dev(struct kref *ref)
{
	struct ib_umad_device *dev =
		container_of(ref, struct ib_umad_device, ref);

	kfree(dev);
}

151 152 153 154 155 156
/* caller must hold port->mutex at least for reading */
static struct ib_mad_agent *__get_agent(struct ib_umad_file *file, int id)
{
	return file->agents_dead ? NULL : file->agent[id];
}

L
Linus Torvalds 已提交
157 158 159 160 161 162
static int queue_packet(struct ib_umad_file *file,
			struct ib_mad_agent *agent,
			struct ib_umad_packet *packet)
{
	int ret = 1;

163
	down_read(&file->port->mutex);
164

165 166 167
	for (packet->mad.hdr.id = 0;
	     packet->mad.hdr.id < IB_UMAD_MAX_AGENTS;
	     packet->mad.hdr.id++)
168
		if (agent == __get_agent(file, packet->mad.hdr.id)) {
L
Linus Torvalds 已提交
169 170 171 172 173 174 175 176
			spin_lock_irq(&file->recv_lock);
			list_add_tail(&packet->list, &file->recv_list);
			spin_unlock_irq(&file->recv_lock);
			wake_up_interruptible(&file->recv_wait);
			ret = 0;
			break;
		}

177
	up_read(&file->port->mutex);
L
Linus Torvalds 已提交
178 179 180 181

	return ret;
}

182 183 184 185 186 187 188 189
static void dequeue_send(struct ib_umad_file *file,
			 struct ib_umad_packet *packet)
 {
	spin_lock_irq(&file->send_lock);
	list_del(&packet->list);
	spin_unlock_irq(&file->send_lock);
 }

L
Linus Torvalds 已提交
190 191 192 193
static void send_handler(struct ib_mad_agent *agent,
			 struct ib_mad_send_wc *send_wc)
{
	struct ib_umad_file *file = agent->context;
194
	struct ib_umad_packet *packet = send_wc->send_buf->context[0];
L
Linus Torvalds 已提交
195

196
	dequeue_send(file, packet);
197
	ib_destroy_ah(packet->msg->ah);
198
	ib_free_send_mad(packet->msg);
L
Linus Torvalds 已提交
199 200

	if (send_wc->status == IB_WC_RESP_TIMEOUT_ERR) {
201 202 203 204
		packet->length = IB_MGMT_MAD_HDR;
		packet->mad.hdr.status = ETIMEDOUT;
		if (!queue_packet(file, agent, packet))
			return;
205
	}
L
Linus Torvalds 已提交
206 207 208 209 210 211 212 213 214 215
	kfree(packet);
}

static void recv_handler(struct ib_mad_agent *agent,
			 struct ib_mad_recv_wc *mad_recv_wc)
{
	struct ib_umad_file *file = agent->context;
	struct ib_umad_packet *packet;

	if (mad_recv_wc->wc->status != IB_WC_SUCCESS)
216
		goto err1;
L
Linus Torvalds 已提交
217

218
	packet = kzalloc(sizeof *packet, GFP_KERNEL);
L
Linus Torvalds 已提交
219
	if (!packet)
220
		goto err1;
L
Linus Torvalds 已提交
221

222 223
	packet->length = mad_recv_wc->mad_len;
	packet->recv_wc = mad_recv_wc;
L
Linus Torvalds 已提交
224

225
	packet->mad.hdr.status    = 0;
226 227
	packet->mad.hdr.length    = sizeof (struct ib_user_mad) +
				    mad_recv_wc->mad_len;
228 229 230 231 232 233
	packet->mad.hdr.qpn 	  = cpu_to_be32(mad_recv_wc->wc->src_qp);
	packet->mad.hdr.lid 	  = cpu_to_be16(mad_recv_wc->wc->slid);
	packet->mad.hdr.sl  	  = mad_recv_wc->wc->sl;
	packet->mad.hdr.path_bits = mad_recv_wc->wc->dlid_path_bits;
	packet->mad.hdr.grh_present = !!(mad_recv_wc->wc->wc_flags & IB_WC_GRH);
	if (packet->mad.hdr.grh_present) {
L
Linus Torvalds 已提交
234
		/* XXX parse GRH */
235 236 237 238 239
		packet->mad.hdr.gid_index 	= 0;
		packet->mad.hdr.hop_limit 	= 0;
		packet->mad.hdr.traffic_class	= 0;
		memset(packet->mad.hdr.gid, 0, 16);
		packet->mad.hdr.flow_label	= 0;
L
Linus Torvalds 已提交
240 241 242
	}

	if (queue_packet(file, agent, packet))
243 244
		goto err2;
	return;
L
Linus Torvalds 已提交
245

246 247 248
err2:
	kfree(packet);
err1:
L
Linus Torvalds 已提交
249 250 251
	ib_free_recv_mad(mad_recv_wc);
}

252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285
static ssize_t copy_recv_mad(char __user *buf, struct ib_umad_packet *packet,
			     size_t count)
{
	struct ib_mad_recv_buf *recv_buf;
	int left, seg_payload, offset, max_seg_payload;

	/* We need enough room to copy the first (or only) MAD segment. */
	recv_buf = &packet->recv_wc->recv_buf;
	if ((packet->length <= sizeof (*recv_buf->mad) &&
	     count < sizeof (packet->mad) + packet->length) ||
	    (packet->length > sizeof (*recv_buf->mad) &&
	     count < sizeof (packet->mad) + sizeof (*recv_buf->mad)))
		return -EINVAL;

	if (copy_to_user(buf, &packet->mad, sizeof (packet->mad)))
		return -EFAULT;

	buf += sizeof (packet->mad);
	seg_payload = min_t(int, packet->length, sizeof (*recv_buf->mad));
	if (copy_to_user(buf, recv_buf->mad, seg_payload))
		return -EFAULT;

	if (seg_payload < packet->length) {
		/*
		 * Multipacket RMPP MAD message. Copy remainder of message.
		 * Note that last segment may have a shorter payload.
		 */
		if (count < sizeof (packet->mad) + packet->length) {
			/*
			 * The buffer is too small, return the first RMPP segment,
			 * which includes the RMPP message length.
			 */
			return -ENOSPC;
		}
286
		offset = ib_get_mad_data_offset(recv_buf->mad->mad_hdr.mgmt_class);
287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315
		max_seg_payload = sizeof (struct ib_mad) - offset;

		for (left = packet->length - seg_payload, buf += seg_payload;
		     left; left -= seg_payload, buf += seg_payload) {
			recv_buf = container_of(recv_buf->list.next,
						struct ib_mad_recv_buf, list);
			seg_payload = min(left, max_seg_payload);
			if (copy_to_user(buf, ((void *) recv_buf->mad) + offset,
					 seg_payload))
				return -EFAULT;
		}
	}
	return sizeof (packet->mad) + packet->length;
}

static ssize_t copy_send_mad(char __user *buf, struct ib_umad_packet *packet,
			     size_t count)
{
	ssize_t size = sizeof (packet->mad) + packet->length;

	if (count < size)
		return -EINVAL;

	if (copy_to_user(buf, &packet->mad, size))
		return -EFAULT;

	return size;
}

L
Linus Torvalds 已提交
316 317 318 319 320 321 322
static ssize_t ib_umad_read(struct file *filp, char __user *buf,
			    size_t count, loff_t *pos)
{
	struct ib_umad_file *file = filp->private_data;
	struct ib_umad_packet *packet;
	ssize_t ret;

323
	if (count < sizeof (struct ib_user_mad))
L
Linus Torvalds 已提交
324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345
		return -EINVAL;

	spin_lock_irq(&file->recv_lock);

	while (list_empty(&file->recv_list)) {
		spin_unlock_irq(&file->recv_lock);

		if (filp->f_flags & O_NONBLOCK)
			return -EAGAIN;

		if (wait_event_interruptible(file->recv_wait,
					     !list_empty(&file->recv_list)))
			return -ERESTARTSYS;

		spin_lock_irq(&file->recv_lock);
	}

	packet = list_entry(file->recv_list.next, struct ib_umad_packet, list);
	list_del(&packet->list);

	spin_unlock_irq(&file->recv_lock);

346 347
	if (packet->recv_wc)
		ret = copy_recv_mad(buf, packet, count);
L
Linus Torvalds 已提交
348
	else
349 350
		ret = copy_send_mad(buf, packet, count);

351 352 353 354 355
	if (ret < 0) {
		/* Requeue packet */
		spin_lock_irq(&file->recv_lock);
		list_add(&packet->list, &file->recv_list);
		spin_unlock_irq(&file->recv_lock);
356 357 358
	} else {
		if (packet->recv_wc)
			ib_free_recv_mad(packet->recv_wc);
359
		kfree(packet);
360
	}
L
Linus Torvalds 已提交
361 362 363
	return ret;
}

364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383
static int copy_rmpp_mad(struct ib_mad_send_buf *msg, const char __user *buf)
{
	int left, seg;

	/* Copy class specific header */
	if ((msg->hdr_len > IB_MGMT_RMPP_HDR) &&
	    copy_from_user(msg->mad + IB_MGMT_RMPP_HDR, buf + IB_MGMT_RMPP_HDR,
			   msg->hdr_len - IB_MGMT_RMPP_HDR))
		return -EFAULT;

	/* All headers are in place.  Copy data segments. */
	for (seg = 1, left = msg->data_len, buf += msg->hdr_len; left > 0;
	     seg++, left -= msg->seg_size, buf += msg->seg_size) {
		if (copy_from_user(ib_get_rmpp_segment(msg, seg), buf,
				   min(left, msg->seg_size)))
			return -EFAULT;
	}
	return 0;
}

384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428
static int same_destination(struct ib_user_mad_hdr *hdr1,
			    struct ib_user_mad_hdr *hdr2)
{
	if (!hdr1->grh_present && !hdr2->grh_present)
	   return (hdr1->lid == hdr2->lid);

	if (hdr1->grh_present && hdr2->grh_present)
	   return !memcmp(hdr1->gid, hdr2->gid, 16);

	return 0;
}

static int is_duplicate(struct ib_umad_file *file,
			struct ib_umad_packet *packet)
{
	struct ib_umad_packet *sent_packet;
	struct ib_mad_hdr *sent_hdr, *hdr;

	hdr = (struct ib_mad_hdr *) packet->mad.data;
	list_for_each_entry(sent_packet, &file->send_list, list) {
		sent_hdr = (struct ib_mad_hdr *) sent_packet->mad.data;

		if ((hdr->tid != sent_hdr->tid) ||
		    (hdr->mgmt_class != sent_hdr->mgmt_class))
			continue;

		/*
		 * No need to be overly clever here.  If two new operations have
		 * the same TID, reject the second as a duplicate.  This is more
		 * restrictive than required by the spec.
		 */
		if (!ib_response_mad((struct ib_mad *) hdr)) {
			if (!ib_response_mad((struct ib_mad *) sent_hdr))
				return 1;
			continue;
		} else if (!ib_response_mad((struct ib_mad *) sent_hdr))
			continue;

		if (same_destination(&packet->mad.hdr, &sent_packet->mad.hdr))
			return 1;
	}

	return 0;
}

L
Linus Torvalds 已提交
429 430 431 432 433 434 435
static ssize_t ib_umad_write(struct file *filp, const char __user *buf,
			     size_t count, loff_t *pos)
{
	struct ib_umad_file *file = filp->private_data;
	struct ib_umad_packet *packet;
	struct ib_mad_agent *agent;
	struct ib_ah_attr ah_attr;
436
	struct ib_ah *ah;
437
	struct ib_rmpp_mad *rmpp_mad;
438
	__be64 *tid;
439
	int ret, data_len, hdr_len, copy_offset, rmpp_active;
L
Linus Torvalds 已提交
440

441
	if (count < sizeof (struct ib_user_mad) + IB_MGMT_RMPP_HDR)
L
Linus Torvalds 已提交
442 443
		return -EINVAL;

444
	packet = kzalloc(sizeof *packet + IB_MGMT_RMPP_HDR, GFP_KERNEL);
L
Linus Torvalds 已提交
445 446 447
	if (!packet)
		return -ENOMEM;

448
	if (copy_from_user(&packet->mad, buf,
S
Sean Hefty 已提交
449
			    sizeof (struct ib_user_mad) + IB_MGMT_RMPP_HDR)) {
450 451
		ret = -EFAULT;
		goto err;
L
Linus Torvalds 已提交
452 453
	}

454 455
	if (packet->mad.hdr.id < 0 ||
	    packet->mad.hdr.id >= IB_UMAD_MAX_AGENTS) {
L
Linus Torvalds 已提交
456 457 458 459
		ret = -EINVAL;
		goto err;
	}

460
	down_read(&file->port->mutex);
L
Linus Torvalds 已提交
461

462
	agent = __get_agent(file, packet->mad.hdr.id);
L
Linus Torvalds 已提交
463 464 465 466 467 468
	if (!agent) {
		ret = -EINVAL;
		goto err_up;
	}

	memset(&ah_attr, 0, sizeof ah_attr);
469 470 471
	ah_attr.dlid          = be16_to_cpu(packet->mad.hdr.lid);
	ah_attr.sl            = packet->mad.hdr.sl;
	ah_attr.src_path_bits = packet->mad.hdr.path_bits;
L
Linus Torvalds 已提交
472
	ah_attr.port_num      = file->port->port_num;
473
	if (packet->mad.hdr.grh_present) {
L
Linus Torvalds 已提交
474
		ah_attr.ah_flags = IB_AH_GRH;
475
		memcpy(ah_attr.grh.dgid.raw, packet->mad.hdr.gid, 16);
476
		ah_attr.grh.flow_label 	   = be32_to_cpu(packet->mad.hdr.flow_label);
477 478
		ah_attr.grh.hop_limit  	   = packet->mad.hdr.hop_limit;
		ah_attr.grh.traffic_class  = packet->mad.hdr.traffic_class;
L
Linus Torvalds 已提交
479 480
	}

481 482 483
	ah = ib_create_ah(agent->qp->pd, &ah_attr);
	if (IS_ERR(ah)) {
		ret = PTR_ERR(ah);
L
Linus Torvalds 已提交
484 485 486
		goto err_up;
	}

487
	rmpp_mad = (struct ib_rmpp_mad *) packet->mad.data;
488 489 490 491 492
	hdr_len = ib_get_mad_data_offset(rmpp_mad->mad_hdr.mgmt_class);
	if (!ib_is_mad_class_rmpp(rmpp_mad->mad_hdr.mgmt_class)) {
		copy_offset = IB_MGMT_MAD_HDR;
		rmpp_active = 0;
	} else {
493 494 495
		copy_offset = IB_MGMT_RMPP_HDR;
		rmpp_active = ib_get_rmpp_flags(&rmpp_mad->rmpp_hdr) &
			      IB_MGMT_RMPP_FLAG_ACTIVE;
496 497
	}

498
	data_len = count - sizeof (struct ib_user_mad) - hdr_len;
499 500
	packet->msg = ib_create_send_mad(agent,
					 be32_to_cpu(packet->mad.hdr.qpn),
501 502
					 0, rmpp_active, hdr_len,
					 data_len, GFP_KERNEL);
503 504 505 506
	if (IS_ERR(packet->msg)) {
		ret = PTR_ERR(packet->msg);
		goto err_ah;
	}
L
Linus Torvalds 已提交
507

508 509 510 511
	packet->msg->ah 	= ah;
	packet->msg->timeout_ms = packet->mad.hdr.timeout_ms;
	packet->msg->retries 	= packet->mad.hdr.retries;
	packet->msg->context[0] = packet;
L
Linus Torvalds 已提交
512

513
	/* Copy MAD header.  Any RMPP header is already in place. */
S
Sean Hefty 已提交
514
	memcpy(packet->msg->mad, packet->mad.data, IB_MGMT_MAD_HDR);
515 516 517 518 519 520 521 522 523 524 525 526 527
	buf += sizeof (struct ib_user_mad);

	if (!rmpp_active) {
		if (copy_from_user(packet->msg->mad + copy_offset,
				   buf + copy_offset,
				   hdr_len + data_len - copy_offset)) {
			ret = -EFAULT;
			goto err_msg;
		}
	} else {
		ret = copy_rmpp_mad(packet->msg, buf);
		if (ret)
			goto err_msg;
528 529 530
	}

	/*
531 532 533
	 * Set the high-order part of the transaction ID to make MADs from
	 * different agents unique, and allow routing responses back to the
	 * original requestor.
534
	 */
535
	if (!ib_response_mad(packet->msg->mad)) {
536
		tid = &((struct ib_mad_hdr *) packet->msg->mad)->tid;
537 538
		*tid = cpu_to_be64(((u64) agent->hi_tid) << 32 |
				   (be64_to_cpup(tid) & 0xffffffff));
539 540 541 542 543 544 545 546 547 548 549
		rmpp_mad->mad_hdr.tid = *tid;
	}

	spin_lock_irq(&file->send_lock);
	ret = is_duplicate(file, packet);
	if (!ret)
		list_add_tail(&packet->list, &file->send_list);
	spin_unlock_irq(&file->send_lock);
	if (ret) {
		ret = -EINVAL;
		goto err_msg;
L
Linus Torvalds 已提交
550 551
	}

552
	ret = ib_post_send_mad(packet->msg, NULL);
553
	if (ret)
554
		goto err_send;
555

556
	up_read(&file->port->mutex);
S
Sean Hefty 已提交
557
	return count;
558

559 560
err_send:
	dequeue_send(file, packet);
561 562 563
err_msg:
	ib_free_send_mad(packet->msg);
err_ah:
564
	ib_destroy_ah(ah);
L
Linus Torvalds 已提交
565
err_up:
566
	up_read(&file->port->mutex);
L
Linus Torvalds 已提交
567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594
err:
	kfree(packet);
	return ret;
}

static unsigned int ib_umad_poll(struct file *filp, struct poll_table_struct *wait)
{
	struct ib_umad_file *file = filp->private_data;

	/* we will always be able to post a MAD send */
	unsigned int mask = POLLOUT | POLLWRNORM;

	poll_wait(filp, &file->recv_wait, wait);

	if (!list_empty(&file->recv_list))
		mask |= POLLIN | POLLRDNORM;

	return mask;
}

static int ib_umad_reg_agent(struct ib_umad_file *file, unsigned long arg)
{
	struct ib_user_mad_reg_req ureq;
	struct ib_mad_reg_req req;
	struct ib_mad_agent *agent;
	int agent_id;
	int ret;

595 596 597 598 599 600
	down_write(&file->port->mutex);

	if (!file->port->ib_dev) {
		ret = -EPIPE;
		goto out;
	}
L
Linus Torvalds 已提交
601 602 603 604 605 606 607 608 609 610 611 612

	if (copy_from_user(&ureq, (void __user *) arg, sizeof ureq)) {
		ret = -EFAULT;
		goto out;
	}

	if (ureq.qpn != 0 && ureq.qpn != 1) {
		ret = -EINVAL;
		goto out;
	}

	for (agent_id = 0; agent_id < IB_UMAD_MAX_AGENTS; ++agent_id)
613
		if (!__get_agent(file, agent_id))
L
Linus Torvalds 已提交
614 615 616 617 618 619
			goto found;

	ret = -ENOMEM;
	goto out;

found:
620 621 622 623 624 625
	if (ureq.mgmt_class) {
		req.mgmt_class         = ureq.mgmt_class;
		req.mgmt_class_version = ureq.mgmt_class_version;
		memcpy(req.method_mask, ureq.method_mask, sizeof req.method_mask);
		memcpy(req.oui,         ureq.oui,         sizeof req.oui);
	}
L
Linus Torvalds 已提交
626 627 628

	agent = ib_register_mad_agent(file->port->ib_dev, file->port->port_num,
				      ureq.qpn ? IB_QPT_GSI : IB_QPT_SMI,
629
				      ureq.mgmt_class ? &req : NULL,
630 631
				      ureq.rmpp_version,
				      send_handler, recv_handler, file);
L
Linus Torvalds 已提交
632 633 634 635 636 637 638 639
	if (IS_ERR(agent)) {
		ret = PTR_ERR(agent);
		goto out;
	}

	if (put_user(agent_id,
		     (u32 __user *) (arg + offsetof(struct ib_user_mad_reg_req, id)))) {
		ret = -EFAULT;
640 641
		ib_unregister_mad_agent(agent);
		goto out;
L
Linus Torvalds 已提交
642 643
	}

644
	file->agent[agent_id] = agent;
L
Linus Torvalds 已提交
645
	ret = 0;
646

L
Linus Torvalds 已提交
647
out:
648
	up_write(&file->port->mutex);
L
Linus Torvalds 已提交
649 650 651 652 653
	return ret;
}

static int ib_umad_unreg_agent(struct ib_umad_file *file, unsigned long arg)
{
654
	struct ib_mad_agent *agent = NULL;
L
Linus Torvalds 已提交
655 656 657
	u32 id;
	int ret = 0;

658 659
	if (get_user(id, (u32 __user *) arg))
		return -EFAULT;
L
Linus Torvalds 已提交
660

661
	down_write(&file->port->mutex);
L
Linus Torvalds 已提交
662

663
	if (id < 0 || id >= IB_UMAD_MAX_AGENTS || !__get_agent(file, id)) {
L
Linus Torvalds 已提交
664 665 666 667
		ret = -EINVAL;
		goto out;
	}

668
	agent = file->agent[id];
L
Linus Torvalds 已提交
669 670 671
	file->agent[id] = NULL;

out:
672
	up_write(&file->port->mutex);
673

674
	if (agent)
675 676
		ib_unregister_mad_agent(agent);

L
Linus Torvalds 已提交
677 678 679
	return ret;
}

680 681
static long ib_umad_ioctl(struct file *filp, unsigned int cmd,
			  unsigned long arg)
L
Linus Torvalds 已提交
682 683 684 685 686 687 688 689 690 691 692 693 694
{
	switch (cmd) {
	case IB_USER_MAD_REGISTER_AGENT:
		return ib_umad_reg_agent(filp->private_data, arg);
	case IB_USER_MAD_UNREGISTER_AGENT:
		return ib_umad_unreg_agent(filp->private_data, arg);
	default:
		return -ENOIOCTLCMD;
	}
}

static int ib_umad_open(struct inode *inode, struct file *filp)
{
695
	struct ib_umad_port *port;
L
Linus Torvalds 已提交
696
	struct ib_umad_file *file;
697
	int ret = 0;
L
Linus Torvalds 已提交
698

699 700 701 702 703 704 705 706 707
	spin_lock(&port_lock);
	port = umad_port[iminor(inode) - IB_UMAD_MINOR_BASE];
	if (port)
		kref_get(&port->umad_dev->ref);
	spin_unlock(&port_lock);

	if (!port)
		return -ENXIO;

708 709 710 711 712 713 714
	down_write(&port->mutex);

	if (!port->ib_dev) {
		ret = -ENXIO;
		goto out;
	}

S
Sean Hefty 已提交
715
	file = kzalloc(sizeof *file, GFP_KERNEL);
716 717
	if (!file) {
		kref_put(&port->umad_dev->ref, ib_umad_release_dev);
718 719
		ret = -ENOMEM;
		goto out;
720
	}
L
Linus Torvalds 已提交
721 722

	spin_lock_init(&file->recv_lock);
723
	spin_lock_init(&file->send_lock);
L
Linus Torvalds 已提交
724
	INIT_LIST_HEAD(&file->recv_list);
725
	INIT_LIST_HEAD(&file->send_list);
L
Linus Torvalds 已提交
726 727 728 729 730
	init_waitqueue_head(&file->recv_wait);

	file->port = port;
	filp->private_data = file;

731 732 733 734 735
	list_add_tail(&file->port_list, &port->file_list);

out:
	up_write(&port->mutex);
	return ret;
L
Linus Torvalds 已提交
736 737 738 739 740
}

static int ib_umad_close(struct inode *inode, struct file *filp)
{
	struct ib_umad_file *file = filp->private_data;
741
	struct ib_umad_device *dev = file->port->umad_dev;
742
	struct ib_umad_packet *packet, *tmp;
743
	int already_dead;
L
Linus Torvalds 已提交
744 745
	int i;

746 747 748 749
	down_write(&file->port->mutex);

	already_dead = file->agents_dead;
	file->agents_dead = 1;
L
Linus Torvalds 已提交
750

751 752 753
	list_for_each_entry_safe(packet, tmp, &file->recv_list, list) {
		if (packet->recv_wc)
			ib_free_recv_mad(packet->recv_wc);
754
		kfree(packet);
755
	}
756

757 758
	list_del(&file->port_list);

759 760 761 762 763 764
	downgrade_write(&file->port->mutex);

	if (!already_dead)
		for (i = 0; i < IB_UMAD_MAX_AGENTS; ++i)
			if (file->agent[i])
				ib_unregister_mad_agent(file->agent[i]);
L
Linus Torvalds 已提交
765

766 767 768
	up_read(&file->port->mutex);

	kfree(file);
769 770
	kref_put(&dev->ref, ib_umad_release_dev);

L
Linus Torvalds 已提交
771 772 773 774
	return 0;
}

static struct file_operations umad_fops = {
775 776 777 778
	.owner 	 	= THIS_MODULE,
	.read 	 	= ib_umad_read,
	.write 	 	= ib_umad_write,
	.poll 	 	= ib_umad_poll,
L
Linus Torvalds 已提交
779
	.unlocked_ioctl = ib_umad_ioctl,
780 781 782
	.compat_ioctl 	= ib_umad_ioctl,
	.open 	 	= ib_umad_open,
	.release 	= ib_umad_close
L
Linus Torvalds 已提交
783 784 785 786
};

static int ib_umad_sm_open(struct inode *inode, struct file *filp)
{
787
	struct ib_umad_port *port;
L
Linus Torvalds 已提交
788 789 790 791 792
	struct ib_port_modify props = {
		.set_port_cap_mask = IB_PORT_SM
	};
	int ret;

793 794 795 796 797 798 799 800 801
	spin_lock(&port_lock);
	port = umad_port[iminor(inode) - IB_UMAD_MINOR_BASE - IB_UMAD_MAX_PORTS];
	if (port)
		kref_get(&port->umad_dev->ref);
	spin_unlock(&port_lock);

	if (!port)
		return -ENXIO;

L
Linus Torvalds 已提交
802
	if (filp->f_flags & O_NONBLOCK) {
803 804 805 806
		if (down_trylock(&port->sm_sem)) {
			ret = -EAGAIN;
			goto fail;
		}
L
Linus Torvalds 已提交
807
	} else {
808 809 810 811
		if (down_interruptible(&port->sm_sem)) {
			ret = -ERESTARTSYS;
			goto fail;
		}
L
Linus Torvalds 已提交
812 813 814 815 816
	}

	ret = ib_modify_port(port->ib_dev, port->port_num, 0, &props);
	if (ret) {
		up(&port->sm_sem);
817
		goto fail;
L
Linus Torvalds 已提交
818 819 820 821 822
	}

	filp->private_data = port;

	return 0;
823 824 825 826

fail:
	kref_put(&port->umad_dev->ref, ib_umad_release_dev);
	return ret;
L
Linus Torvalds 已提交
827 828 829 830 831 832 833 834
}

static int ib_umad_sm_close(struct inode *inode, struct file *filp)
{
	struct ib_umad_port *port = filp->private_data;
	struct ib_port_modify props = {
		.clr_port_cap_mask = IB_PORT_SM
	};
835 836 837 838 839 840
	int ret = 0;

	down_write(&port->mutex);
	if (port->ib_dev)
		ret = ib_modify_port(port->ib_dev, port->port_num, 0, &props);
	up_write(&port->mutex);
L
Linus Torvalds 已提交
841 842 843

	up(&port->sm_sem);

844 845
	kref_put(&port->umad_dev->ref, ib_umad_release_dev);

L
Linus Torvalds 已提交
846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864
	return ret;
}

static struct file_operations umad_sm_fops = {
	.owner 	 = THIS_MODULE,
	.open 	 = ib_umad_sm_open,
	.release = ib_umad_sm_close
};

static struct ib_client umad_client = {
	.name   = "umad",
	.add    = ib_umad_add_one,
	.remove = ib_umad_remove_one
};

static ssize_t show_ibdev(struct class_device *class_dev, char *buf)
{
	struct ib_umad_port *port = class_get_devdata(class_dev);

865 866 867
	if (!port)
		return -ENODEV;

L
Linus Torvalds 已提交
868 869 870 871 872 873 874 875
	return sprintf(buf, "%s\n", port->ib_dev->name);
}
static CLASS_DEVICE_ATTR(ibdev, S_IRUGO, show_ibdev, NULL);

static ssize_t show_port(struct class_device *class_dev, char *buf)
{
	struct ib_umad_port *port = class_get_devdata(class_dev);

876 877 878
	if (!port)
		return -ENODEV;

L
Linus Torvalds 已提交
879 880 881 882 883 884 885 886 887 888 889 890 891
	return sprintf(buf, "%d\n", port->port_num);
}
static CLASS_DEVICE_ATTR(port, S_IRUGO, show_port, NULL);

static ssize_t show_abi_version(struct class *class, char *buf)
{
	return sprintf(buf, "%d\n", IB_USER_MAD_ABI_VERSION);
}
static CLASS_ATTR(abi_version, S_IRUGO, show_abi_version, NULL);

static int ib_umad_init_port(struct ib_device *device, int port_num,
			     struct ib_umad_port *port)
{
892 893 894 895
	spin_lock(&port_lock);
	port->dev_num = find_first_zero_bit(dev_map, IB_UMAD_MAX_PORTS);
	if (port->dev_num >= IB_UMAD_MAX_PORTS) {
		spin_unlock(&port_lock);
L
Linus Torvalds 已提交
896 897
		return -1;
	}
898 899
	set_bit(port->dev_num, dev_map);
	spin_unlock(&port_lock);
L
Linus Torvalds 已提交
900 901 902 903

	port->ib_dev   = device;
	port->port_num = port_num;
	init_MUTEX(&port->sm_sem);
904 905
	init_rwsem(&port->mutex);
	INIT_LIST_HEAD(&port->file_list);
L
Linus Torvalds 已提交
906

907 908
	port->dev = cdev_alloc();
	if (!port->dev)
L
Linus Torvalds 已提交
909
		return -1;
910 911 912 913
	port->dev->owner = THIS_MODULE;
	port->dev->ops   = &umad_fops;
	kobject_set_name(&port->dev->kobj, "umad%d", port->dev_num);
	if (cdev_add(port->dev, base_dev + port->dev_num, 1))
L
Linus Torvalds 已提交
914 915
		goto err_cdev;

916
	port->class_dev = class_device_create(umad_class, NULL, port->dev->dev,
917 918 919 920
					      device->dma_device,
					      "umad%d", port->dev_num);
	if (IS_ERR(port->class_dev))
		goto err_cdev;
L
Linus Torvalds 已提交
921

922
	if (class_device_create_file(port->class_dev, &class_device_attr_ibdev))
L
Linus Torvalds 已提交
923
		goto err_class;
924
	if (class_device_create_file(port->class_dev, &class_device_attr_port))
L
Linus Torvalds 已提交
925 926
		goto err_class;

927 928 929 930 931
	port->sm_dev = cdev_alloc();
	if (!port->sm_dev)
		goto err_class;
	port->sm_dev->owner = THIS_MODULE;
	port->sm_dev->ops   = &umad_sm_fops;
M
Michael S. Tsirkin 已提交
932
	kobject_set_name(&port->sm_dev->kobj, "issm%d", port->dev_num);
933 934
	if (cdev_add(port->sm_dev, base_dev + port->dev_num + IB_UMAD_MAX_PORTS, 1))
		goto err_sm_cdev;
L
Linus Torvalds 已提交
935

936
	port->sm_class_dev = class_device_create(umad_class, NULL, port->sm_dev->dev,
937 938 939
						 device->dma_device,
						 "issm%d", port->dev_num);
	if (IS_ERR(port->sm_class_dev))
L
Linus Torvalds 已提交
940 941
		goto err_sm_cdev;

942 943
	class_set_devdata(port->class_dev,    port);
	class_set_devdata(port->sm_class_dev, port);
L
Linus Torvalds 已提交
944

945
	if (class_device_create_file(port->sm_class_dev, &class_device_attr_ibdev))
L
Linus Torvalds 已提交
946
		goto err_sm_class;
947
	if (class_device_create_file(port->sm_class_dev, &class_device_attr_port))
L
Linus Torvalds 已提交
948 949
		goto err_sm_class;

950 951 952 953
	spin_lock(&port_lock);
	umad_port[port->dev_num] = port;
	spin_unlock(&port_lock);

L
Linus Torvalds 已提交
954 955 956
	return 0;

err_sm_class:
957
	class_device_destroy(umad_class, port->sm_dev->dev);
L
Linus Torvalds 已提交
958 959

err_sm_cdev:
960
	cdev_del(port->sm_dev);
L
Linus Torvalds 已提交
961 962

err_class:
963
	class_device_destroy(umad_class, port->dev->dev);
L
Linus Torvalds 已提交
964 965

err_cdev:
966 967
	cdev_del(port->dev);
	clear_bit(port->dev_num, dev_map);
L
Linus Torvalds 已提交
968 969 970 971

	return -1;
}

972 973
static void ib_umad_kill_port(struct ib_umad_port *port)
{
974 975 976
	struct ib_umad_file *file;
	int id;

977 978 979 980 981 982 983 984 985 986 987 988 989
	class_set_devdata(port->class_dev,    NULL);
	class_set_devdata(port->sm_class_dev, NULL);

	class_device_destroy(umad_class, port->dev->dev);
	class_device_destroy(umad_class, port->sm_dev->dev);

	cdev_del(port->dev);
	cdev_del(port->sm_dev);

	spin_lock(&port_lock);
	umad_port[port->dev_num] = NULL;
	spin_unlock(&port_lock);

990 991 992 993
	down_write(&port->mutex);

	port->ib_dev = NULL;

994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023
	/*
	 * Now go through the list of files attached to this port and
	 * unregister all of their MAD agents.  We need to hold
	 * port->mutex while doing this to avoid racing with
	 * ib_umad_close(), but we can't hold the mutex for writing
	 * while calling ib_unregister_mad_agent(), since that might
	 * deadlock by calling back into queue_packet().  So we
	 * downgrade our lock to a read lock, and then drop and
	 * reacquire the write lock for the next iteration.
	 *
	 * We do list_del_init() on the file's list_head so that the
	 * list_del in ib_umad_close() is still OK, even after the
	 * file is removed from the list.
	 */
	while (!list_empty(&port->file_list)) {
		file = list_entry(port->file_list.next, struct ib_umad_file,
				  port_list);

		file->agents_dead = 1;
		list_del_init(&file->port_list);

		downgrade_write(&port->mutex);

		for (id = 0; id < IB_UMAD_MAX_AGENTS; ++id)
			if (file->agent[id])
				ib_unregister_mad_agent(file->agent[id]);

		up_read(&port->mutex);
		down_write(&port->mutex);
	}
1024 1025 1026

	up_write(&port->mutex);

1027 1028 1029
	clear_bit(port->dev_num, dev_map);
}

L
Linus Torvalds 已提交
1030 1031 1032 1033 1034
static void ib_umad_add_one(struct ib_device *device)
{
	struct ib_umad_device *umad_dev;
	int s, e, i;

T
Tom Tucker 已提交
1035 1036 1037 1038
	if (rdma_node_get_transport(device->node_type) != RDMA_TRANSPORT_IB)
		return;

	if (device->node_type == RDMA_NODE_IB_SWITCH)
L
Linus Torvalds 已提交
1039 1040 1041 1042 1043 1044
		s = e = 0;
	else {
		s = 1;
		e = device->phys_port_cnt;
	}

S
Sean Hefty 已提交
1045
	umad_dev = kzalloc(sizeof *umad_dev +
L
Linus Torvalds 已提交
1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067
			   (e - s + 1) * sizeof (struct ib_umad_port),
			   GFP_KERNEL);
	if (!umad_dev)
		return;

	kref_init(&umad_dev->ref);

	umad_dev->start_port = s;
	umad_dev->end_port   = e;

	for (i = s; i <= e; ++i) {
		umad_dev->port[i - s].umad_dev = umad_dev;

		if (ib_umad_init_port(device, i, &umad_dev->port[i - s]))
			goto err;
	}

	ib_set_client_data(device, &umad_client, umad_dev);

	return;

err:
1068
	while (--i >= s)
M
Michael S. Tsirkin 已提交
1069
		ib_umad_kill_port(&umad_dev->port[i - s]);
L
Linus Torvalds 已提交
1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081

	kref_put(&umad_dev->ref, ib_umad_release_dev);
}

static void ib_umad_remove_one(struct ib_device *device)
{
	struct ib_umad_device *umad_dev = ib_get_client_data(device, &umad_client);
	int i;

	if (!umad_dev)
		return;

1082 1083
	for (i = 0; i <= umad_dev->end_port - umad_dev->start_port; ++i)
		ib_umad_kill_port(&umad_dev->port[i]);
L
Linus Torvalds 已提交
1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098

	kref_put(&umad_dev->ref, ib_umad_release_dev);
}

static int __init ib_umad_init(void)
{
	int ret;

	ret = register_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2,
				     "infiniband_mad");
	if (ret) {
		printk(KERN_ERR "user_mad: couldn't register device number\n");
		goto out;
	}

1099 1100 1101
	umad_class = class_create(THIS_MODULE, "infiniband_mad");
	if (IS_ERR(umad_class)) {
		ret = PTR_ERR(umad_class);
L
Linus Torvalds 已提交
1102 1103 1104 1105
		printk(KERN_ERR "user_mad: couldn't create class infiniband_mad\n");
		goto out_chrdev;
	}

1106
	ret = class_create_file(umad_class, &class_attr_abi_version);
L
Linus Torvalds 已提交
1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120
	if (ret) {
		printk(KERN_ERR "user_mad: couldn't create abi_version attribute\n");
		goto out_class;
	}

	ret = ib_register_client(&umad_client);
	if (ret) {
		printk(KERN_ERR "user_mad: couldn't register ib_umad client\n");
		goto out_class;
	}

	return 0;

out_class:
1121
	class_destroy(umad_class);
L
Linus Torvalds 已提交
1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132

out_chrdev:
	unregister_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2);

out:
	return ret;
}

static void __exit ib_umad_cleanup(void)
{
	ib_unregister_client(&umad_client);
1133
	class_destroy(umad_class);
L
Linus Torvalds 已提交
1134 1135 1136 1137 1138
	unregister_chrdev_region(base_dev, IB_UMAD_MAX_PORTS * 2);
}

module_init(ib_umad_init);
module_exit(ib_umad_cleanup);