xref: /openbmc/linux/net/sunrpc/xprtrdma/backchannel.c (revision 13650c23f10603154d989cff70b5c8a889e69fc2)
1f531a5dbSChuck Lever /*
2f531a5dbSChuck Lever  * Copyright (c) 2015 Oracle.  All rights reserved.
3f531a5dbSChuck Lever  *
4f531a5dbSChuck Lever  * Support for backward direction RPCs on RPC/RDMA.
5f531a5dbSChuck Lever  */
6f531a5dbSChuck Lever 
7f531a5dbSChuck Lever #include <linux/module.h>
863cae470SChuck Lever #include <linux/sunrpc/xprt.h>
963cae470SChuck Lever #include <linux/sunrpc/svc.h>
1076566773SChuck Lever #include <linux/sunrpc/svc_xprt.h>
11f531a5dbSChuck Lever 
12f531a5dbSChuck Lever #include "xprt_rdma.h"
13f531a5dbSChuck Lever 
14f531a5dbSChuck Lever #if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
15f531a5dbSChuck Lever # define RPCDBG_FACILITY	RPCDBG_TRANS
16f531a5dbSChuck Lever #endif
17f531a5dbSChuck Lever 
18c8bbe0c7SChuck Lever #undef RPCRDMA_BACKCHANNEL_DEBUG
1963cae470SChuck Lever 
20f531a5dbSChuck Lever static void rpcrdma_bc_free_rqst(struct rpcrdma_xprt *r_xprt,
21f531a5dbSChuck Lever 				 struct rpc_rqst *rqst)
22f531a5dbSChuck Lever {
23f531a5dbSChuck Lever 	struct rpcrdma_buffer *buf = &r_xprt->rx_buf;
24f531a5dbSChuck Lever 	struct rpcrdma_req *req = rpcr_to_rdmar(rqst);
25f531a5dbSChuck Lever 
26f531a5dbSChuck Lever 	spin_lock(&buf->rb_reqslock);
27f531a5dbSChuck Lever 	list_del(&req->rl_all);
28f531a5dbSChuck Lever 	spin_unlock(&buf->rb_reqslock);
29f531a5dbSChuck Lever 
30*13650c23SChuck Lever 	rpcrdma_destroy_req(req);
31f531a5dbSChuck Lever 
32f531a5dbSChuck Lever 	kfree(rqst);
33f531a5dbSChuck Lever }
34f531a5dbSChuck Lever 
35f531a5dbSChuck Lever static int rpcrdma_bc_setup_rqst(struct rpcrdma_xprt *r_xprt,
36f531a5dbSChuck Lever 				 struct rpc_rqst *rqst)
37f531a5dbSChuck Lever {
38f531a5dbSChuck Lever 	struct rpcrdma_regbuf *rb;
39f531a5dbSChuck Lever 	struct rpcrdma_req *req;
40f531a5dbSChuck Lever 	size_t size;
41f531a5dbSChuck Lever 
42f531a5dbSChuck Lever 	req = rpcrdma_create_req(r_xprt);
43abfb6897SDan Carpenter 	if (IS_ERR(req))
44abfb6897SDan Carpenter 		return PTR_ERR(req);
45f531a5dbSChuck Lever 	req->rl_backchannel = true;
46f531a5dbSChuck Lever 
47*13650c23SChuck Lever 	rb = rpcrdma_alloc_regbuf(RPCRDMA_HDRBUF_SIZE,
4899ef4db3SChuck Lever 				  DMA_TO_DEVICE, GFP_KERNEL);
49f531a5dbSChuck Lever 	if (IS_ERR(rb))
50f531a5dbSChuck Lever 		goto out_fail;
51f531a5dbSChuck Lever 	req->rl_rdmabuf = rb;
52f531a5dbSChuck Lever 
5308cf2efdSChuck Lever 	size = r_xprt->rx_data.inline_rsize;
54*13650c23SChuck Lever 	rb = rpcrdma_alloc_regbuf(size, DMA_TO_DEVICE, GFP_KERNEL);
55f531a5dbSChuck Lever 	if (IS_ERR(rb))
56f531a5dbSChuck Lever 		goto out_fail;
57f531a5dbSChuck Lever 	req->rl_sendbuf = rb;
585a6d1db4SChuck Lever 	xdr_buf_init(&rqst->rq_snd_buf, rb->rg_base, size);
595a6d1db4SChuck Lever 	rpcrdma_set_xprtdata(rqst, req);
60f531a5dbSChuck Lever 	return 0;
61f531a5dbSChuck Lever 
62f531a5dbSChuck Lever out_fail:
63f531a5dbSChuck Lever 	rpcrdma_bc_free_rqst(r_xprt, rqst);
64f531a5dbSChuck Lever 	return -ENOMEM;
65f531a5dbSChuck Lever }
66f531a5dbSChuck Lever 
67f531a5dbSChuck Lever /* Allocate and add receive buffers to the rpcrdma_buffer's
68f531a5dbSChuck Lever  * existing list of rep's. These are released when the
69f531a5dbSChuck Lever  * transport is destroyed.
70f531a5dbSChuck Lever  */
71f531a5dbSChuck Lever static int rpcrdma_bc_setup_reps(struct rpcrdma_xprt *r_xprt,
72f531a5dbSChuck Lever 				 unsigned int count)
73f531a5dbSChuck Lever {
74f531a5dbSChuck Lever 	struct rpcrdma_rep *rep;
75f531a5dbSChuck Lever 	int rc = 0;
76f531a5dbSChuck Lever 
77f531a5dbSChuck Lever 	while (count--) {
78f531a5dbSChuck Lever 		rep = rpcrdma_create_rep(r_xprt);
79f531a5dbSChuck Lever 		if (IS_ERR(rep)) {
80f531a5dbSChuck Lever 			pr_err("RPC:       %s: reply buffer alloc failed\n",
81f531a5dbSChuck Lever 			       __func__);
82f531a5dbSChuck Lever 			rc = PTR_ERR(rep);
83f531a5dbSChuck Lever 			break;
84f531a5dbSChuck Lever 		}
85f531a5dbSChuck Lever 
869b06688bSChuck Lever 		rpcrdma_recv_buffer_put(rep);
87f531a5dbSChuck Lever 	}
88f531a5dbSChuck Lever 
89f531a5dbSChuck Lever 	return rc;
90f531a5dbSChuck Lever }
91f531a5dbSChuck Lever 
92f531a5dbSChuck Lever /**
93f531a5dbSChuck Lever  * xprt_rdma_bc_setup - Pre-allocate resources for handling backchannel requests
94f531a5dbSChuck Lever  * @xprt: transport associated with these backchannel resources
95f531a5dbSChuck Lever  * @reqs: number of concurrent incoming requests to expect
96f531a5dbSChuck Lever  *
97f531a5dbSChuck Lever  * Returns 0 on success; otherwise a negative errno
98f531a5dbSChuck Lever  */
99f531a5dbSChuck Lever int xprt_rdma_bc_setup(struct rpc_xprt *xprt, unsigned int reqs)
100f531a5dbSChuck Lever {
101f531a5dbSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
102f531a5dbSChuck Lever 	struct rpcrdma_buffer *buffer = &r_xprt->rx_buf;
103f531a5dbSChuck Lever 	struct rpc_rqst *rqst;
104f531a5dbSChuck Lever 	unsigned int i;
105f531a5dbSChuck Lever 	int rc;
106f531a5dbSChuck Lever 
107f531a5dbSChuck Lever 	/* The backchannel reply path returns each rpc_rqst to the
108f531a5dbSChuck Lever 	 * bc_pa_list _after_ the reply is sent. If the server is
109f531a5dbSChuck Lever 	 * faster than the client, it can send another backward
110f531a5dbSChuck Lever 	 * direction request before the rpc_rqst is returned to the
111f531a5dbSChuck Lever 	 * list. The client rejects the request in this case.
112f531a5dbSChuck Lever 	 *
113f531a5dbSChuck Lever 	 * Twice as many rpc_rqsts are prepared to ensure there is
114f531a5dbSChuck Lever 	 * always an rpc_rqst available as soon as a reply is sent.
115f531a5dbSChuck Lever 	 */
116124fa17dSChuck Lever 	if (reqs > RPCRDMA_BACKWARD_WRS >> 1)
117124fa17dSChuck Lever 		goto out_err;
118124fa17dSChuck Lever 
119f531a5dbSChuck Lever 	for (i = 0; i < (reqs << 1); i++) {
120f531a5dbSChuck Lever 		rqst = kzalloc(sizeof(*rqst), GFP_KERNEL);
121f531a5dbSChuck Lever 		if (!rqst) {
122f531a5dbSChuck Lever 			pr_err("RPC:       %s: Failed to create bc rpc_rqst\n",
123f531a5dbSChuck Lever 			       __func__);
124f531a5dbSChuck Lever 			goto out_free;
125f531a5dbSChuck Lever 		}
126c8bbe0c7SChuck Lever 		dprintk("RPC:       %s: new rqst %p\n", __func__, rqst);
127f531a5dbSChuck Lever 
128f531a5dbSChuck Lever 		rqst->rq_xprt = &r_xprt->rx_xprt;
129f531a5dbSChuck Lever 		INIT_LIST_HEAD(&rqst->rq_list);
130f531a5dbSChuck Lever 		INIT_LIST_HEAD(&rqst->rq_bc_list);
131f531a5dbSChuck Lever 
132f531a5dbSChuck Lever 		if (rpcrdma_bc_setup_rqst(r_xprt, rqst))
133f531a5dbSChuck Lever 			goto out_free;
134f531a5dbSChuck Lever 
135f531a5dbSChuck Lever 		spin_lock_bh(&xprt->bc_pa_lock);
136f531a5dbSChuck Lever 		list_add(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
137f531a5dbSChuck Lever 		spin_unlock_bh(&xprt->bc_pa_lock);
138f531a5dbSChuck Lever 	}
139f531a5dbSChuck Lever 
140f531a5dbSChuck Lever 	rc = rpcrdma_bc_setup_reps(r_xprt, reqs);
141f531a5dbSChuck Lever 	if (rc)
142f531a5dbSChuck Lever 		goto out_free;
143f531a5dbSChuck Lever 
144f531a5dbSChuck Lever 	rc = rpcrdma_ep_post_extra_recv(r_xprt, reqs);
145f531a5dbSChuck Lever 	if (rc)
146f531a5dbSChuck Lever 		goto out_free;
147f531a5dbSChuck Lever 
148f531a5dbSChuck Lever 	buffer->rb_bc_srv_max_requests = reqs;
149f531a5dbSChuck Lever 	request_module("svcrdma");
150f531a5dbSChuck Lever 
151f531a5dbSChuck Lever 	return 0;
152f531a5dbSChuck Lever 
153f531a5dbSChuck Lever out_free:
154f531a5dbSChuck Lever 	xprt_rdma_bc_destroy(xprt, reqs);
155f531a5dbSChuck Lever 
156124fa17dSChuck Lever out_err:
157f531a5dbSChuck Lever 	pr_err("RPC:       %s: setup backchannel transport failed\n", __func__);
158f531a5dbSChuck Lever 	return -ENOMEM;
159f531a5dbSChuck Lever }
160f531a5dbSChuck Lever 
161f531a5dbSChuck Lever /**
16276566773SChuck Lever  * xprt_rdma_bc_up - Create transport endpoint for backchannel service
16376566773SChuck Lever  * @serv: server endpoint
16476566773SChuck Lever  * @net: network namespace
16576566773SChuck Lever  *
16676566773SChuck Lever  * The "xprt" is an implied argument: it supplies the name of the
16776566773SChuck Lever  * backchannel transport class.
16876566773SChuck Lever  *
16976566773SChuck Lever  * Returns zero on success, negative errno on failure
17076566773SChuck Lever  */
17176566773SChuck Lever int xprt_rdma_bc_up(struct svc_serv *serv, struct net *net)
17276566773SChuck Lever {
17376566773SChuck Lever 	int ret;
17476566773SChuck Lever 
17576566773SChuck Lever 	ret = svc_create_xprt(serv, "rdma-bc", net, PF_INET, 0, 0);
17676566773SChuck Lever 	if (ret < 0)
17776566773SChuck Lever 		return ret;
17876566773SChuck Lever 	return 0;
17976566773SChuck Lever }
18076566773SChuck Lever 
18176566773SChuck Lever /**
1826b26cc8cSChuck Lever  * xprt_rdma_bc_maxpayload - Return maximum backchannel message size
1836b26cc8cSChuck Lever  * @xprt: transport
1846b26cc8cSChuck Lever  *
1856b26cc8cSChuck Lever  * Returns maximum size, in bytes, of a backchannel message
1866b26cc8cSChuck Lever  */
1876b26cc8cSChuck Lever size_t xprt_rdma_bc_maxpayload(struct rpc_xprt *xprt)
1886b26cc8cSChuck Lever {
1896b26cc8cSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
1906b26cc8cSChuck Lever 	struct rpcrdma_create_data_internal *cdata = &r_xprt->rx_data;
1916b26cc8cSChuck Lever 	size_t maxmsg;
1926b26cc8cSChuck Lever 
1936b26cc8cSChuck Lever 	maxmsg = min_t(unsigned int, cdata->inline_rsize, cdata->inline_wsize);
1946b26cc8cSChuck Lever 	return maxmsg - RPCRDMA_HDRLEN_MIN;
1956b26cc8cSChuck Lever }
1966b26cc8cSChuck Lever 
1976b26cc8cSChuck Lever /**
19883128a60SChuck Lever  * rpcrdma_bc_marshal_reply - Send backwards direction reply
19983128a60SChuck Lever  * @rqst: buffer containing RPC reply data
20083128a60SChuck Lever  *
20183128a60SChuck Lever  * Returns zero on success.
20283128a60SChuck Lever  */
20383128a60SChuck Lever int rpcrdma_bc_marshal_reply(struct rpc_rqst *rqst)
20483128a60SChuck Lever {
20583128a60SChuck Lever 	struct rpc_xprt *xprt = rqst->rq_xprt;
20683128a60SChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
20783128a60SChuck Lever 	struct rpcrdma_req *req = rpcr_to_rdmar(rqst);
20883128a60SChuck Lever 	struct rpcrdma_msg *headerp;
20983128a60SChuck Lever 	size_t rpclen;
21083128a60SChuck Lever 
21183128a60SChuck Lever 	headerp = rdmab_to_msg(req->rl_rdmabuf);
21283128a60SChuck Lever 	headerp->rm_xid = rqst->rq_xid;
21383128a60SChuck Lever 	headerp->rm_vers = rpcrdma_version;
21483128a60SChuck Lever 	headerp->rm_credit =
21583128a60SChuck Lever 			cpu_to_be32(r_xprt->rx_buf.rb_bc_srv_max_requests);
21683128a60SChuck Lever 	headerp->rm_type = rdma_msg;
21783128a60SChuck Lever 	headerp->rm_body.rm_chunks[0] = xdr_zero;
21883128a60SChuck Lever 	headerp->rm_body.rm_chunks[1] = xdr_zero;
21983128a60SChuck Lever 	headerp->rm_body.rm_chunks[2] = xdr_zero;
22083128a60SChuck Lever 
22183128a60SChuck Lever 	rpclen = rqst->rq_svec[0].iov_len;
22283128a60SChuck Lever 
223c8bbe0c7SChuck Lever #ifdef RPCRDMA_BACKCHANNEL_DEBUG
22483128a60SChuck Lever 	pr_info("RPC:       %s: rpclen %zd headerp 0x%p lkey 0x%x\n",
22583128a60SChuck Lever 		__func__, rpclen, headerp, rdmab_lkey(req->rl_rdmabuf));
22683128a60SChuck Lever 	pr_info("RPC:       %s: RPC/RDMA: %*ph\n",
22783128a60SChuck Lever 		__func__, (int)RPCRDMA_HDRLEN_MIN, headerp);
22883128a60SChuck Lever 	pr_info("RPC:       %s:      RPC: %*ph\n",
22983128a60SChuck Lever 		__func__, (int)rpclen, rqst->rq_svec[0].iov_base);
230c8bbe0c7SChuck Lever #endif
23183128a60SChuck Lever 
23254cbd6b0SChuck Lever 	if (!rpcrdma_dma_map_regbuf(&r_xprt->rx_ia, req->rl_rdmabuf))
23354cbd6b0SChuck Lever 		goto out_map;
23483128a60SChuck Lever 	req->rl_send_iov[0].addr = rdmab_addr(req->rl_rdmabuf);
23583128a60SChuck Lever 	req->rl_send_iov[0].length = RPCRDMA_HDRLEN_MIN;
23683128a60SChuck Lever 	req->rl_send_iov[0].lkey = rdmab_lkey(req->rl_rdmabuf);
23783128a60SChuck Lever 
23854cbd6b0SChuck Lever 	if (!rpcrdma_dma_map_regbuf(&r_xprt->rx_ia, req->rl_sendbuf))
23954cbd6b0SChuck Lever 		goto out_map;
24083128a60SChuck Lever 	req->rl_send_iov[1].addr = rdmab_addr(req->rl_sendbuf);
24183128a60SChuck Lever 	req->rl_send_iov[1].length = rpclen;
24283128a60SChuck Lever 	req->rl_send_iov[1].lkey = rdmab_lkey(req->rl_sendbuf);
24383128a60SChuck Lever 
24483128a60SChuck Lever 	req->rl_niovs = 2;
24583128a60SChuck Lever 	return 0;
24654cbd6b0SChuck Lever 
24754cbd6b0SChuck Lever out_map:
24854cbd6b0SChuck Lever 	pr_err("rpcrdma: failed to DMA map a Send buffer\n");
24954cbd6b0SChuck Lever 	return -EIO;
25083128a60SChuck Lever }
25183128a60SChuck Lever 
25283128a60SChuck Lever /**
253f531a5dbSChuck Lever  * xprt_rdma_bc_destroy - Release resources for handling backchannel requests
254f531a5dbSChuck Lever  * @xprt: transport associated with these backchannel resources
255f531a5dbSChuck Lever  * @reqs: number of incoming requests to destroy; ignored
256f531a5dbSChuck Lever  */
257f531a5dbSChuck Lever void xprt_rdma_bc_destroy(struct rpc_xprt *xprt, unsigned int reqs)
258f531a5dbSChuck Lever {
259f531a5dbSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
260f531a5dbSChuck Lever 	struct rpc_rqst *rqst, *tmp;
261f531a5dbSChuck Lever 
262f531a5dbSChuck Lever 	spin_lock_bh(&xprt->bc_pa_lock);
263f531a5dbSChuck Lever 	list_for_each_entry_safe(rqst, tmp, &xprt->bc_pa_list, rq_bc_pa_list) {
264f531a5dbSChuck Lever 		list_del(&rqst->rq_bc_pa_list);
265f531a5dbSChuck Lever 		spin_unlock_bh(&xprt->bc_pa_lock);
266f531a5dbSChuck Lever 
267f531a5dbSChuck Lever 		rpcrdma_bc_free_rqst(r_xprt, rqst);
268f531a5dbSChuck Lever 
269f531a5dbSChuck Lever 		spin_lock_bh(&xprt->bc_pa_lock);
270f531a5dbSChuck Lever 	}
271f531a5dbSChuck Lever 	spin_unlock_bh(&xprt->bc_pa_lock);
272f531a5dbSChuck Lever }
273f531a5dbSChuck Lever 
274f531a5dbSChuck Lever /**
275f531a5dbSChuck Lever  * xprt_rdma_bc_free_rqst - Release a backchannel rqst
276f531a5dbSChuck Lever  * @rqst: request to release
277f531a5dbSChuck Lever  */
278f531a5dbSChuck Lever void xprt_rdma_bc_free_rqst(struct rpc_rqst *rqst)
279f531a5dbSChuck Lever {
280f531a5dbSChuck Lever 	struct rpc_xprt *xprt = rqst->rq_xprt;
281f531a5dbSChuck Lever 
282c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: freeing rqst %p (req %p)\n",
283c8bbe0c7SChuck Lever 		__func__, rqst, rpcr_to_rdmar(rqst));
284c8bbe0c7SChuck Lever 
285f531a5dbSChuck Lever 	smp_mb__before_atomic();
286f531a5dbSChuck Lever 	WARN_ON_ONCE(!test_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state));
287f531a5dbSChuck Lever 	clear_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state);
288f531a5dbSChuck Lever 	smp_mb__after_atomic();
289f531a5dbSChuck Lever 
290f531a5dbSChuck Lever 	spin_lock_bh(&xprt->bc_pa_lock);
291f531a5dbSChuck Lever 	list_add_tail(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
292f531a5dbSChuck Lever 	spin_unlock_bh(&xprt->bc_pa_lock);
293f531a5dbSChuck Lever }
29463cae470SChuck Lever 
29563cae470SChuck Lever /**
29663cae470SChuck Lever  * rpcrdma_bc_receive_call - Handle a backward direction call
29763cae470SChuck Lever  * @xprt: transport receiving the call
29863cae470SChuck Lever  * @rep: receive buffer containing the call
29963cae470SChuck Lever  *
30063cae470SChuck Lever  * Called in the RPC reply handler, which runs in a tasklet.
30163cae470SChuck Lever  * Be quick about it.
30263cae470SChuck Lever  *
30363cae470SChuck Lever  * Operational assumptions:
30463cae470SChuck Lever  *    o Backchannel credits are ignored, just as the NFS server
30563cae470SChuck Lever  *      forechannel currently does
30663cae470SChuck Lever  *    o The ULP manages a replay cache (eg, NFSv4.1 sessions).
30763cae470SChuck Lever  *      No replay detection is done at the transport level
30863cae470SChuck Lever  */
30963cae470SChuck Lever void rpcrdma_bc_receive_call(struct rpcrdma_xprt *r_xprt,
31063cae470SChuck Lever 			     struct rpcrdma_rep *rep)
31163cae470SChuck Lever {
31263cae470SChuck Lever 	struct rpc_xprt *xprt = &r_xprt->rx_xprt;
31363cae470SChuck Lever 	struct rpcrdma_msg *headerp;
31463cae470SChuck Lever 	struct svc_serv *bc_serv;
31563cae470SChuck Lever 	struct rpcrdma_req *req;
31663cae470SChuck Lever 	struct rpc_rqst *rqst;
31763cae470SChuck Lever 	struct xdr_buf *buf;
31863cae470SChuck Lever 	size_t size;
31963cae470SChuck Lever 	__be32 *p;
32063cae470SChuck Lever 
32163cae470SChuck Lever 	headerp = rdmab_to_msg(rep->rr_rdmabuf);
32263cae470SChuck Lever #ifdef RPCRDMA_BACKCHANNEL_DEBUG
32363cae470SChuck Lever 	pr_info("RPC:       %s: callback XID %08x, length=%u\n",
32463cae470SChuck Lever 		__func__, be32_to_cpu(headerp->rm_xid), rep->rr_len);
32563cae470SChuck Lever 	pr_info("RPC:       %s: %*ph\n", __func__, rep->rr_len, headerp);
32663cae470SChuck Lever #endif
32763cae470SChuck Lever 
32863cae470SChuck Lever 	/* Sanity check:
32963cae470SChuck Lever 	 * Need at least enough bytes for RPC/RDMA header, as code
33063cae470SChuck Lever 	 * here references the header fields by array offset. Also,
33163cae470SChuck Lever 	 * backward calls are always inline, so ensure there
33263cae470SChuck Lever 	 * are some bytes beyond the RPC/RDMA header.
33363cae470SChuck Lever 	 */
33463cae470SChuck Lever 	if (rep->rr_len < RPCRDMA_HDRLEN_MIN + 24)
33563cae470SChuck Lever 		goto out_short;
33663cae470SChuck Lever 	p = (__be32 *)((unsigned char *)headerp + RPCRDMA_HDRLEN_MIN);
33763cae470SChuck Lever 	size = rep->rr_len - RPCRDMA_HDRLEN_MIN;
33863cae470SChuck Lever 
33963cae470SChuck Lever 	/* Grab a free bc rqst */
34063cae470SChuck Lever 	spin_lock(&xprt->bc_pa_lock);
34163cae470SChuck Lever 	if (list_empty(&xprt->bc_pa_list)) {
34263cae470SChuck Lever 		spin_unlock(&xprt->bc_pa_lock);
34363cae470SChuck Lever 		goto out_overflow;
34463cae470SChuck Lever 	}
34563cae470SChuck Lever 	rqst = list_first_entry(&xprt->bc_pa_list,
34663cae470SChuck Lever 				struct rpc_rqst, rq_bc_pa_list);
34763cae470SChuck Lever 	list_del(&rqst->rq_bc_pa_list);
34863cae470SChuck Lever 	spin_unlock(&xprt->bc_pa_lock);
349c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: using rqst %p\n", __func__, rqst);
35063cae470SChuck Lever 
35163cae470SChuck Lever 	/* Prepare rqst */
35263cae470SChuck Lever 	rqst->rq_reply_bytes_recvd = 0;
35363cae470SChuck Lever 	rqst->rq_bytes_sent = 0;
35463cae470SChuck Lever 	rqst->rq_xid = headerp->rm_xid;
3559f74660bSChuck Lever 
3569f74660bSChuck Lever 	rqst->rq_private_buf.len = size;
35763cae470SChuck Lever 	set_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state);
35863cae470SChuck Lever 
35963cae470SChuck Lever 	buf = &rqst->rq_rcv_buf;
36063cae470SChuck Lever 	memset(buf, 0, sizeof(*buf));
36163cae470SChuck Lever 	buf->head[0].iov_base = p;
36263cae470SChuck Lever 	buf->head[0].iov_len = size;
36363cae470SChuck Lever 	buf->len = size;
36463cae470SChuck Lever 
36563cae470SChuck Lever 	/* The receive buffer has to be hooked to the rpcrdma_req
36663cae470SChuck Lever 	 * so that it can be reposted after the server is done
36763cae470SChuck Lever 	 * parsing it but just before sending the backward
36863cae470SChuck Lever 	 * direction reply.
36963cae470SChuck Lever 	 */
37063cae470SChuck Lever 	req = rpcr_to_rdmar(rqst);
371c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: attaching rep %p to req %p\n",
37263cae470SChuck Lever 		__func__, rep, req);
37363cae470SChuck Lever 	req->rl_reply = rep;
37463cae470SChuck Lever 
37563cae470SChuck Lever 	/* Defeat the retransmit detection logic in send_request */
37663cae470SChuck Lever 	req->rl_connect_cookie = 0;
37763cae470SChuck Lever 
37863cae470SChuck Lever 	/* Queue rqst for ULP's callback service */
37963cae470SChuck Lever 	bc_serv = xprt->bc_serv;
38063cae470SChuck Lever 	spin_lock(&bc_serv->sv_cb_lock);
38163cae470SChuck Lever 	list_add(&rqst->rq_bc_list, &bc_serv->sv_cb_list);
38263cae470SChuck Lever 	spin_unlock(&bc_serv->sv_cb_lock);
38363cae470SChuck Lever 
38463cae470SChuck Lever 	wake_up(&bc_serv->sv_cb_waitq);
38563cae470SChuck Lever 
38663cae470SChuck Lever 	r_xprt->rx_stats.bcall_count++;
38763cae470SChuck Lever 	return;
38863cae470SChuck Lever 
38963cae470SChuck Lever out_overflow:
39063cae470SChuck Lever 	pr_warn("RPC/RDMA backchannel overflow\n");
39163cae470SChuck Lever 	xprt_disconnect_done(xprt);
39263cae470SChuck Lever 	/* This receive buffer gets reposted automatically
39363cae470SChuck Lever 	 * when the connection is re-established.
39463cae470SChuck Lever 	 */
39563cae470SChuck Lever 	return;
39663cae470SChuck Lever 
39763cae470SChuck Lever out_short:
39863cae470SChuck Lever 	pr_warn("RPC/RDMA short backward direction call\n");
39963cae470SChuck Lever 
40063cae470SChuck Lever 	if (rpcrdma_ep_post_recv(&r_xprt->rx_ia, &r_xprt->rx_ep, rep))
40163cae470SChuck Lever 		xprt_disconnect_done(xprt);
40263cae470SChuck Lever 	else
40363cae470SChuck Lever 		pr_warn("RPC:       %s: reposting rep %p\n",
40463cae470SChuck Lever 			__func__, rep);
40563cae470SChuck Lever }
406