xref: /openbmc/linux/net/sunrpc/xprtrdma/backchannel.c (revision 6b26cc8c8ead3636a18bfd9489984983f4ddd6f4)
1f531a5dbSChuck Lever /*
2f531a5dbSChuck Lever  * Copyright (c) 2015 Oracle.  All rights reserved.
3f531a5dbSChuck Lever  *
4f531a5dbSChuck Lever  * Support for backward direction RPCs on RPC/RDMA.
5f531a5dbSChuck Lever  */
6f531a5dbSChuck Lever 
7f531a5dbSChuck Lever #include <linux/module.h>
863cae470SChuck Lever #include <linux/sunrpc/xprt.h>
963cae470SChuck Lever #include <linux/sunrpc/svc.h>
1076566773SChuck Lever #include <linux/sunrpc/svc_xprt.h>
11f531a5dbSChuck Lever 
12f531a5dbSChuck Lever #include "xprt_rdma.h"
13f531a5dbSChuck Lever 
14f531a5dbSChuck Lever #if IS_ENABLED(CONFIG_SUNRPC_DEBUG)
15f531a5dbSChuck Lever # define RPCDBG_FACILITY	RPCDBG_TRANS
16f531a5dbSChuck Lever #endif
17f531a5dbSChuck Lever 
18c8bbe0c7SChuck Lever #undef RPCRDMA_BACKCHANNEL_DEBUG
1963cae470SChuck Lever 
20f531a5dbSChuck Lever static void rpcrdma_bc_free_rqst(struct rpcrdma_xprt *r_xprt,
21f531a5dbSChuck Lever 				 struct rpc_rqst *rqst)
22f531a5dbSChuck Lever {
23f531a5dbSChuck Lever 	struct rpcrdma_buffer *buf = &r_xprt->rx_buf;
24f531a5dbSChuck Lever 	struct rpcrdma_req *req = rpcr_to_rdmar(rqst);
25f531a5dbSChuck Lever 
26f531a5dbSChuck Lever 	spin_lock(&buf->rb_reqslock);
27f531a5dbSChuck Lever 	list_del(&req->rl_all);
28f531a5dbSChuck Lever 	spin_unlock(&buf->rb_reqslock);
29f531a5dbSChuck Lever 
30f531a5dbSChuck Lever 	rpcrdma_destroy_req(&r_xprt->rx_ia, req);
31f531a5dbSChuck Lever 
32f531a5dbSChuck Lever 	kfree(rqst);
33f531a5dbSChuck Lever }
34f531a5dbSChuck Lever 
35f531a5dbSChuck Lever static int rpcrdma_bc_setup_rqst(struct rpcrdma_xprt *r_xprt,
36f531a5dbSChuck Lever 				 struct rpc_rqst *rqst)
37f531a5dbSChuck Lever {
38f531a5dbSChuck Lever 	struct rpcrdma_ia *ia = &r_xprt->rx_ia;
39f531a5dbSChuck Lever 	struct rpcrdma_regbuf *rb;
40f531a5dbSChuck Lever 	struct rpcrdma_req *req;
41f531a5dbSChuck Lever 	struct xdr_buf *buf;
42f531a5dbSChuck Lever 	size_t size;
43f531a5dbSChuck Lever 
44f531a5dbSChuck Lever 	req = rpcrdma_create_req(r_xprt);
45abfb6897SDan Carpenter 	if (IS_ERR(req))
46abfb6897SDan Carpenter 		return PTR_ERR(req);
47f531a5dbSChuck Lever 	req->rl_backchannel = true;
48f531a5dbSChuck Lever 
49f531a5dbSChuck Lever 	size = RPCRDMA_INLINE_WRITE_THRESHOLD(rqst);
50f531a5dbSChuck Lever 	rb = rpcrdma_alloc_regbuf(ia, size, GFP_KERNEL);
51f531a5dbSChuck Lever 	if (IS_ERR(rb))
52f531a5dbSChuck Lever 		goto out_fail;
53f531a5dbSChuck Lever 	req->rl_rdmabuf = rb;
54f531a5dbSChuck Lever 
55f531a5dbSChuck Lever 	size += RPCRDMA_INLINE_READ_THRESHOLD(rqst);
56f531a5dbSChuck Lever 	rb = rpcrdma_alloc_regbuf(ia, size, GFP_KERNEL);
57f531a5dbSChuck Lever 	if (IS_ERR(rb))
58f531a5dbSChuck Lever 		goto out_fail;
59f531a5dbSChuck Lever 	rb->rg_owner = req;
60f531a5dbSChuck Lever 	req->rl_sendbuf = rb;
61f531a5dbSChuck Lever 	/* so that rpcr_to_rdmar works when receiving a request */
62f531a5dbSChuck Lever 	rqst->rq_buffer = (void *)req->rl_sendbuf->rg_base;
63f531a5dbSChuck Lever 
64f531a5dbSChuck Lever 	buf = &rqst->rq_snd_buf;
65f531a5dbSChuck Lever 	buf->head[0].iov_base = rqst->rq_buffer;
66f531a5dbSChuck Lever 	buf->head[0].iov_len = 0;
67f531a5dbSChuck Lever 	buf->tail[0].iov_base = NULL;
68f531a5dbSChuck Lever 	buf->tail[0].iov_len = 0;
69f531a5dbSChuck Lever 	buf->page_len = 0;
70f531a5dbSChuck Lever 	buf->len = 0;
71f531a5dbSChuck Lever 	buf->buflen = size;
72f531a5dbSChuck Lever 
73f531a5dbSChuck Lever 	return 0;
74f531a5dbSChuck Lever 
75f531a5dbSChuck Lever out_fail:
76f531a5dbSChuck Lever 	rpcrdma_bc_free_rqst(r_xprt, rqst);
77f531a5dbSChuck Lever 	return -ENOMEM;
78f531a5dbSChuck Lever }
79f531a5dbSChuck Lever 
80f531a5dbSChuck Lever /* Allocate and add receive buffers to the rpcrdma_buffer's
81f531a5dbSChuck Lever  * existing list of rep's. These are released when the
82f531a5dbSChuck Lever  * transport is destroyed.
83f531a5dbSChuck Lever  */
84f531a5dbSChuck Lever static int rpcrdma_bc_setup_reps(struct rpcrdma_xprt *r_xprt,
85f531a5dbSChuck Lever 				 unsigned int count)
86f531a5dbSChuck Lever {
87f531a5dbSChuck Lever 	struct rpcrdma_rep *rep;
88f531a5dbSChuck Lever 	int rc = 0;
89f531a5dbSChuck Lever 
90f531a5dbSChuck Lever 	while (count--) {
91f531a5dbSChuck Lever 		rep = rpcrdma_create_rep(r_xprt);
92f531a5dbSChuck Lever 		if (IS_ERR(rep)) {
93f531a5dbSChuck Lever 			pr_err("RPC:       %s: reply buffer alloc failed\n",
94f531a5dbSChuck Lever 			       __func__);
95f531a5dbSChuck Lever 			rc = PTR_ERR(rep);
96f531a5dbSChuck Lever 			break;
97f531a5dbSChuck Lever 		}
98f531a5dbSChuck Lever 
999b06688bSChuck Lever 		rpcrdma_recv_buffer_put(rep);
100f531a5dbSChuck Lever 	}
101f531a5dbSChuck Lever 
102f531a5dbSChuck Lever 	return rc;
103f531a5dbSChuck Lever }
104f531a5dbSChuck Lever 
105f531a5dbSChuck Lever /**
106f531a5dbSChuck Lever  * xprt_rdma_bc_setup - Pre-allocate resources for handling backchannel requests
107f531a5dbSChuck Lever  * @xprt: transport associated with these backchannel resources
108f531a5dbSChuck Lever  * @reqs: number of concurrent incoming requests to expect
109f531a5dbSChuck Lever  *
110f531a5dbSChuck Lever  * Returns 0 on success; otherwise a negative errno
111f531a5dbSChuck Lever  */
112f531a5dbSChuck Lever int xprt_rdma_bc_setup(struct rpc_xprt *xprt, unsigned int reqs)
113f531a5dbSChuck Lever {
114f531a5dbSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
115f531a5dbSChuck Lever 	struct rpcrdma_buffer *buffer = &r_xprt->rx_buf;
116f531a5dbSChuck Lever 	struct rpc_rqst *rqst;
117f531a5dbSChuck Lever 	unsigned int i;
118f531a5dbSChuck Lever 	int rc;
119f531a5dbSChuck Lever 
120f531a5dbSChuck Lever 	/* The backchannel reply path returns each rpc_rqst to the
121f531a5dbSChuck Lever 	 * bc_pa_list _after_ the reply is sent. If the server is
122f531a5dbSChuck Lever 	 * faster than the client, it can send another backward
123f531a5dbSChuck Lever 	 * direction request before the rpc_rqst is returned to the
124f531a5dbSChuck Lever 	 * list. The client rejects the request in this case.
125f531a5dbSChuck Lever 	 *
126f531a5dbSChuck Lever 	 * Twice as many rpc_rqsts are prepared to ensure there is
127f531a5dbSChuck Lever 	 * always an rpc_rqst available as soon as a reply is sent.
128f531a5dbSChuck Lever 	 */
129124fa17dSChuck Lever 	if (reqs > RPCRDMA_BACKWARD_WRS >> 1)
130124fa17dSChuck Lever 		goto out_err;
131124fa17dSChuck Lever 
132f531a5dbSChuck Lever 	for (i = 0; i < (reqs << 1); i++) {
133f531a5dbSChuck Lever 		rqst = kzalloc(sizeof(*rqst), GFP_KERNEL);
134f531a5dbSChuck Lever 		if (!rqst) {
135f531a5dbSChuck Lever 			pr_err("RPC:       %s: Failed to create bc rpc_rqst\n",
136f531a5dbSChuck Lever 			       __func__);
137f531a5dbSChuck Lever 			goto out_free;
138f531a5dbSChuck Lever 		}
139c8bbe0c7SChuck Lever 		dprintk("RPC:       %s: new rqst %p\n", __func__, rqst);
140f531a5dbSChuck Lever 
141f531a5dbSChuck Lever 		rqst->rq_xprt = &r_xprt->rx_xprt;
142f531a5dbSChuck Lever 		INIT_LIST_HEAD(&rqst->rq_list);
143f531a5dbSChuck Lever 		INIT_LIST_HEAD(&rqst->rq_bc_list);
144f531a5dbSChuck Lever 
145f531a5dbSChuck Lever 		if (rpcrdma_bc_setup_rqst(r_xprt, rqst))
146f531a5dbSChuck Lever 			goto out_free;
147f531a5dbSChuck Lever 
148f531a5dbSChuck Lever 		spin_lock_bh(&xprt->bc_pa_lock);
149f531a5dbSChuck Lever 		list_add(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
150f531a5dbSChuck Lever 		spin_unlock_bh(&xprt->bc_pa_lock);
151f531a5dbSChuck Lever 	}
152f531a5dbSChuck Lever 
153f531a5dbSChuck Lever 	rc = rpcrdma_bc_setup_reps(r_xprt, reqs);
154f531a5dbSChuck Lever 	if (rc)
155f531a5dbSChuck Lever 		goto out_free;
156f531a5dbSChuck Lever 
157f531a5dbSChuck Lever 	rc = rpcrdma_ep_post_extra_recv(r_xprt, reqs);
158f531a5dbSChuck Lever 	if (rc)
159f531a5dbSChuck Lever 		goto out_free;
160f531a5dbSChuck Lever 
161f531a5dbSChuck Lever 	buffer->rb_bc_srv_max_requests = reqs;
162f531a5dbSChuck Lever 	request_module("svcrdma");
163f531a5dbSChuck Lever 
164f531a5dbSChuck Lever 	return 0;
165f531a5dbSChuck Lever 
166f531a5dbSChuck Lever out_free:
167f531a5dbSChuck Lever 	xprt_rdma_bc_destroy(xprt, reqs);
168f531a5dbSChuck Lever 
169124fa17dSChuck Lever out_err:
170f531a5dbSChuck Lever 	pr_err("RPC:       %s: setup backchannel transport failed\n", __func__);
171f531a5dbSChuck Lever 	return -ENOMEM;
172f531a5dbSChuck Lever }
173f531a5dbSChuck Lever 
174f531a5dbSChuck Lever /**
17576566773SChuck Lever  * xprt_rdma_bc_up - Create transport endpoint for backchannel service
17676566773SChuck Lever  * @serv: server endpoint
17776566773SChuck Lever  * @net: network namespace
17876566773SChuck Lever  *
17976566773SChuck Lever  * The "xprt" is an implied argument: it supplies the name of the
18076566773SChuck Lever  * backchannel transport class.
18176566773SChuck Lever  *
18276566773SChuck Lever  * Returns zero on success, negative errno on failure
18376566773SChuck Lever  */
18476566773SChuck Lever int xprt_rdma_bc_up(struct svc_serv *serv, struct net *net)
18576566773SChuck Lever {
18676566773SChuck Lever 	int ret;
18776566773SChuck Lever 
18876566773SChuck Lever 	ret = svc_create_xprt(serv, "rdma-bc", net, PF_INET, 0, 0);
18976566773SChuck Lever 	if (ret < 0)
19076566773SChuck Lever 		return ret;
19176566773SChuck Lever 	return 0;
19276566773SChuck Lever }
19376566773SChuck Lever 
19476566773SChuck Lever /**
195*6b26cc8cSChuck Lever  * xprt_rdma_bc_maxpayload - Return maximum backchannel message size
196*6b26cc8cSChuck Lever  * @xprt: transport
197*6b26cc8cSChuck Lever  *
198*6b26cc8cSChuck Lever  * Returns maximum size, in bytes, of a backchannel message
199*6b26cc8cSChuck Lever  */
200*6b26cc8cSChuck Lever size_t xprt_rdma_bc_maxpayload(struct rpc_xprt *xprt)
201*6b26cc8cSChuck Lever {
202*6b26cc8cSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
203*6b26cc8cSChuck Lever 	struct rpcrdma_create_data_internal *cdata = &r_xprt->rx_data;
204*6b26cc8cSChuck Lever 	size_t maxmsg;
205*6b26cc8cSChuck Lever 
206*6b26cc8cSChuck Lever 	maxmsg = min_t(unsigned int, cdata->inline_rsize, cdata->inline_wsize);
207*6b26cc8cSChuck Lever 	return maxmsg - RPCRDMA_HDRLEN_MIN;
208*6b26cc8cSChuck Lever }
209*6b26cc8cSChuck Lever 
210*6b26cc8cSChuck Lever /**
21183128a60SChuck Lever  * rpcrdma_bc_marshal_reply - Send backwards direction reply
21283128a60SChuck Lever  * @rqst: buffer containing RPC reply data
21383128a60SChuck Lever  *
21483128a60SChuck Lever  * Returns zero on success.
21583128a60SChuck Lever  */
21683128a60SChuck Lever int rpcrdma_bc_marshal_reply(struct rpc_rqst *rqst)
21783128a60SChuck Lever {
21883128a60SChuck Lever 	struct rpc_xprt *xprt = rqst->rq_xprt;
21983128a60SChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
22083128a60SChuck Lever 	struct rpcrdma_req *req = rpcr_to_rdmar(rqst);
22183128a60SChuck Lever 	struct rpcrdma_msg *headerp;
22283128a60SChuck Lever 	size_t rpclen;
22383128a60SChuck Lever 
22483128a60SChuck Lever 	headerp = rdmab_to_msg(req->rl_rdmabuf);
22583128a60SChuck Lever 	headerp->rm_xid = rqst->rq_xid;
22683128a60SChuck Lever 	headerp->rm_vers = rpcrdma_version;
22783128a60SChuck Lever 	headerp->rm_credit =
22883128a60SChuck Lever 			cpu_to_be32(r_xprt->rx_buf.rb_bc_srv_max_requests);
22983128a60SChuck Lever 	headerp->rm_type = rdma_msg;
23083128a60SChuck Lever 	headerp->rm_body.rm_chunks[0] = xdr_zero;
23183128a60SChuck Lever 	headerp->rm_body.rm_chunks[1] = xdr_zero;
23283128a60SChuck Lever 	headerp->rm_body.rm_chunks[2] = xdr_zero;
23383128a60SChuck Lever 
23483128a60SChuck Lever 	rpclen = rqst->rq_svec[0].iov_len;
23583128a60SChuck Lever 
236c8bbe0c7SChuck Lever #ifdef RPCRDMA_BACKCHANNEL_DEBUG
23783128a60SChuck Lever 	pr_info("RPC:       %s: rpclen %zd headerp 0x%p lkey 0x%x\n",
23883128a60SChuck Lever 		__func__, rpclen, headerp, rdmab_lkey(req->rl_rdmabuf));
23983128a60SChuck Lever 	pr_info("RPC:       %s: RPC/RDMA: %*ph\n",
24083128a60SChuck Lever 		__func__, (int)RPCRDMA_HDRLEN_MIN, headerp);
24183128a60SChuck Lever 	pr_info("RPC:       %s:      RPC: %*ph\n",
24283128a60SChuck Lever 		__func__, (int)rpclen, rqst->rq_svec[0].iov_base);
243c8bbe0c7SChuck Lever #endif
24483128a60SChuck Lever 
24583128a60SChuck Lever 	req->rl_send_iov[0].addr = rdmab_addr(req->rl_rdmabuf);
24683128a60SChuck Lever 	req->rl_send_iov[0].length = RPCRDMA_HDRLEN_MIN;
24783128a60SChuck Lever 	req->rl_send_iov[0].lkey = rdmab_lkey(req->rl_rdmabuf);
24883128a60SChuck Lever 
24983128a60SChuck Lever 	req->rl_send_iov[1].addr = rdmab_addr(req->rl_sendbuf);
25083128a60SChuck Lever 	req->rl_send_iov[1].length = rpclen;
25183128a60SChuck Lever 	req->rl_send_iov[1].lkey = rdmab_lkey(req->rl_sendbuf);
25283128a60SChuck Lever 
25383128a60SChuck Lever 	req->rl_niovs = 2;
25483128a60SChuck Lever 	return 0;
25583128a60SChuck Lever }
25683128a60SChuck Lever 
25783128a60SChuck Lever /**
258f531a5dbSChuck Lever  * xprt_rdma_bc_destroy - Release resources for handling backchannel requests
259f531a5dbSChuck Lever  * @xprt: transport associated with these backchannel resources
260f531a5dbSChuck Lever  * @reqs: number of incoming requests to destroy; ignored
261f531a5dbSChuck Lever  */
262f531a5dbSChuck Lever void xprt_rdma_bc_destroy(struct rpc_xprt *xprt, unsigned int reqs)
263f531a5dbSChuck Lever {
264f531a5dbSChuck Lever 	struct rpcrdma_xprt *r_xprt = rpcx_to_rdmax(xprt);
265f531a5dbSChuck Lever 	struct rpc_rqst *rqst, *tmp;
266f531a5dbSChuck Lever 
267f531a5dbSChuck Lever 	spin_lock_bh(&xprt->bc_pa_lock);
268f531a5dbSChuck Lever 	list_for_each_entry_safe(rqst, tmp, &xprt->bc_pa_list, rq_bc_pa_list) {
269f531a5dbSChuck Lever 		list_del(&rqst->rq_bc_pa_list);
270f531a5dbSChuck Lever 		spin_unlock_bh(&xprt->bc_pa_lock);
271f531a5dbSChuck Lever 
272f531a5dbSChuck Lever 		rpcrdma_bc_free_rqst(r_xprt, rqst);
273f531a5dbSChuck Lever 
274f531a5dbSChuck Lever 		spin_lock_bh(&xprt->bc_pa_lock);
275f531a5dbSChuck Lever 	}
276f531a5dbSChuck Lever 	spin_unlock_bh(&xprt->bc_pa_lock);
277f531a5dbSChuck Lever }
278f531a5dbSChuck Lever 
279f531a5dbSChuck Lever /**
280f531a5dbSChuck Lever  * xprt_rdma_bc_free_rqst - Release a backchannel rqst
281f531a5dbSChuck Lever  * @rqst: request to release
282f531a5dbSChuck Lever  */
283f531a5dbSChuck Lever void xprt_rdma_bc_free_rqst(struct rpc_rqst *rqst)
284f531a5dbSChuck Lever {
285f531a5dbSChuck Lever 	struct rpc_xprt *xprt = rqst->rq_xprt;
286f531a5dbSChuck Lever 
287c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: freeing rqst %p (req %p)\n",
288c8bbe0c7SChuck Lever 		__func__, rqst, rpcr_to_rdmar(rqst));
289c8bbe0c7SChuck Lever 
290f531a5dbSChuck Lever 	smp_mb__before_atomic();
291f531a5dbSChuck Lever 	WARN_ON_ONCE(!test_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state));
292f531a5dbSChuck Lever 	clear_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state);
293f531a5dbSChuck Lever 	smp_mb__after_atomic();
294f531a5dbSChuck Lever 
295f531a5dbSChuck Lever 	spin_lock_bh(&xprt->bc_pa_lock);
296f531a5dbSChuck Lever 	list_add_tail(&rqst->rq_bc_pa_list, &xprt->bc_pa_list);
297f531a5dbSChuck Lever 	spin_unlock_bh(&xprt->bc_pa_lock);
298f531a5dbSChuck Lever }
29963cae470SChuck Lever 
30063cae470SChuck Lever /**
30163cae470SChuck Lever  * rpcrdma_bc_receive_call - Handle a backward direction call
30263cae470SChuck Lever  * @xprt: transport receiving the call
30363cae470SChuck Lever  * @rep: receive buffer containing the call
30463cae470SChuck Lever  *
30563cae470SChuck Lever  * Called in the RPC reply handler, which runs in a tasklet.
30663cae470SChuck Lever  * Be quick about it.
30763cae470SChuck Lever  *
30863cae470SChuck Lever  * Operational assumptions:
30963cae470SChuck Lever  *    o Backchannel credits are ignored, just as the NFS server
31063cae470SChuck Lever  *      forechannel currently does
31163cae470SChuck Lever  *    o The ULP manages a replay cache (eg, NFSv4.1 sessions).
31263cae470SChuck Lever  *      No replay detection is done at the transport level
31363cae470SChuck Lever  */
31463cae470SChuck Lever void rpcrdma_bc_receive_call(struct rpcrdma_xprt *r_xprt,
31563cae470SChuck Lever 			     struct rpcrdma_rep *rep)
31663cae470SChuck Lever {
31763cae470SChuck Lever 	struct rpc_xprt *xprt = &r_xprt->rx_xprt;
31863cae470SChuck Lever 	struct rpcrdma_msg *headerp;
31963cae470SChuck Lever 	struct svc_serv *bc_serv;
32063cae470SChuck Lever 	struct rpcrdma_req *req;
32163cae470SChuck Lever 	struct rpc_rqst *rqst;
32263cae470SChuck Lever 	struct xdr_buf *buf;
32363cae470SChuck Lever 	size_t size;
32463cae470SChuck Lever 	__be32 *p;
32563cae470SChuck Lever 
32663cae470SChuck Lever 	headerp = rdmab_to_msg(rep->rr_rdmabuf);
32763cae470SChuck Lever #ifdef RPCRDMA_BACKCHANNEL_DEBUG
32863cae470SChuck Lever 	pr_info("RPC:       %s: callback XID %08x, length=%u\n",
32963cae470SChuck Lever 		__func__, be32_to_cpu(headerp->rm_xid), rep->rr_len);
33063cae470SChuck Lever 	pr_info("RPC:       %s: %*ph\n", __func__, rep->rr_len, headerp);
33163cae470SChuck Lever #endif
33263cae470SChuck Lever 
33363cae470SChuck Lever 	/* Sanity check:
33463cae470SChuck Lever 	 * Need at least enough bytes for RPC/RDMA header, as code
33563cae470SChuck Lever 	 * here references the header fields by array offset. Also,
33663cae470SChuck Lever 	 * backward calls are always inline, so ensure there
33763cae470SChuck Lever 	 * are some bytes beyond the RPC/RDMA header.
33863cae470SChuck Lever 	 */
33963cae470SChuck Lever 	if (rep->rr_len < RPCRDMA_HDRLEN_MIN + 24)
34063cae470SChuck Lever 		goto out_short;
34163cae470SChuck Lever 	p = (__be32 *)((unsigned char *)headerp + RPCRDMA_HDRLEN_MIN);
34263cae470SChuck Lever 	size = rep->rr_len - RPCRDMA_HDRLEN_MIN;
34363cae470SChuck Lever 
34463cae470SChuck Lever 	/* Grab a free bc rqst */
34563cae470SChuck Lever 	spin_lock(&xprt->bc_pa_lock);
34663cae470SChuck Lever 	if (list_empty(&xprt->bc_pa_list)) {
34763cae470SChuck Lever 		spin_unlock(&xprt->bc_pa_lock);
34863cae470SChuck Lever 		goto out_overflow;
34963cae470SChuck Lever 	}
35063cae470SChuck Lever 	rqst = list_first_entry(&xprt->bc_pa_list,
35163cae470SChuck Lever 				struct rpc_rqst, rq_bc_pa_list);
35263cae470SChuck Lever 	list_del(&rqst->rq_bc_pa_list);
35363cae470SChuck Lever 	spin_unlock(&xprt->bc_pa_lock);
354c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: using rqst %p\n", __func__, rqst);
35563cae470SChuck Lever 
35663cae470SChuck Lever 	/* Prepare rqst */
35763cae470SChuck Lever 	rqst->rq_reply_bytes_recvd = 0;
35863cae470SChuck Lever 	rqst->rq_bytes_sent = 0;
35963cae470SChuck Lever 	rqst->rq_xid = headerp->rm_xid;
3609f74660bSChuck Lever 
3619f74660bSChuck Lever 	rqst->rq_private_buf.len = size;
36263cae470SChuck Lever 	set_bit(RPC_BC_PA_IN_USE, &rqst->rq_bc_pa_state);
36363cae470SChuck Lever 
36463cae470SChuck Lever 	buf = &rqst->rq_rcv_buf;
36563cae470SChuck Lever 	memset(buf, 0, sizeof(*buf));
36663cae470SChuck Lever 	buf->head[0].iov_base = p;
36763cae470SChuck Lever 	buf->head[0].iov_len = size;
36863cae470SChuck Lever 	buf->len = size;
36963cae470SChuck Lever 
37063cae470SChuck Lever 	/* The receive buffer has to be hooked to the rpcrdma_req
37163cae470SChuck Lever 	 * so that it can be reposted after the server is done
37263cae470SChuck Lever 	 * parsing it but just before sending the backward
37363cae470SChuck Lever 	 * direction reply.
37463cae470SChuck Lever 	 */
37563cae470SChuck Lever 	req = rpcr_to_rdmar(rqst);
376c8bbe0c7SChuck Lever 	dprintk("RPC:       %s: attaching rep %p to req %p\n",
37763cae470SChuck Lever 		__func__, rep, req);
37863cae470SChuck Lever 	req->rl_reply = rep;
37963cae470SChuck Lever 
38063cae470SChuck Lever 	/* Defeat the retransmit detection logic in send_request */
38163cae470SChuck Lever 	req->rl_connect_cookie = 0;
38263cae470SChuck Lever 
38363cae470SChuck Lever 	/* Queue rqst for ULP's callback service */
38463cae470SChuck Lever 	bc_serv = xprt->bc_serv;
38563cae470SChuck Lever 	spin_lock(&bc_serv->sv_cb_lock);
38663cae470SChuck Lever 	list_add(&rqst->rq_bc_list, &bc_serv->sv_cb_list);
38763cae470SChuck Lever 	spin_unlock(&bc_serv->sv_cb_lock);
38863cae470SChuck Lever 
38963cae470SChuck Lever 	wake_up(&bc_serv->sv_cb_waitq);
39063cae470SChuck Lever 
39163cae470SChuck Lever 	r_xprt->rx_stats.bcall_count++;
39263cae470SChuck Lever 	return;
39363cae470SChuck Lever 
39463cae470SChuck Lever out_overflow:
39563cae470SChuck Lever 	pr_warn("RPC/RDMA backchannel overflow\n");
39663cae470SChuck Lever 	xprt_disconnect_done(xprt);
39763cae470SChuck Lever 	/* This receive buffer gets reposted automatically
39863cae470SChuck Lever 	 * when the connection is re-established.
39963cae470SChuck Lever 	 */
40063cae470SChuck Lever 	return;
40163cae470SChuck Lever 
40263cae470SChuck Lever out_short:
40363cae470SChuck Lever 	pr_warn("RPC/RDMA short backward direction call\n");
40463cae470SChuck Lever 
40563cae470SChuck Lever 	if (rpcrdma_ep_post_recv(&r_xprt->rx_ia, &r_xprt->rx_ep, rep))
40663cae470SChuck Lever 		xprt_disconnect_done(xprt);
40763cae470SChuck Lever 	else
40863cae470SChuck Lever 		pr_warn("RPC:       %s: reposting rep %p\n",
40963cae470SChuck Lever 			__func__, rep);
41063cae470SChuck Lever }
411