xref: /openbmc/libmctp/core.c (revision 487b31e0)
1 /* SPDX-License-Identifier: Apache-2.0 OR GPL-2.0-or-later */
2 
3 #include <assert.h>
4 #include <errno.h>
5 #include <stdarg.h>
6 #include <stddef.h>
7 #include <stdint.h>
8 #include <stdio.h>
9 #include <stdlib.h>
10 #include <string.h>
11 
12 #undef pr_fmt
13 #define pr_fmt(fmt) "core: " fmt
14 
15 #include "libmctp.h"
16 #include "libmctp-alloc.h"
17 #include "libmctp-log.h"
18 #include "libmctp-cmds.h"
19 #include "range.h"
20 
21 /* Internal data structures */
22 
23 enum mctp_bus_state {
24 	mctp_bus_state_constructed = 0,
25 	mctp_bus_state_tx_enabled,
26 	mctp_bus_state_tx_disabled,
27 };
28 
29 struct mctp_bus {
30 	mctp_eid_t eid;
31 	struct mctp_binding *binding;
32 	enum mctp_bus_state state;
33 
34 	struct mctp_pktbuf *tx_queue_head;
35 	struct mctp_pktbuf *tx_queue_tail;
36 
37 	/* todo: routing */
38 };
39 
40 struct mctp_msg_ctx {
41 	uint8_t src;
42 	uint8_t dest;
43 	uint8_t tag;
44 	uint8_t last_seq;
45 	void *buf;
46 	size_t buf_size;
47 	size_t buf_alloc_size;
48 	size_t fragment_size;
49 };
50 
51 struct mctp {
52 	int n_busses;
53 	struct mctp_bus *busses;
54 
55 	/* Message RX callback */
56 	mctp_rx_fn message_rx;
57 	void *message_rx_data;
58 
59 	/* Packet capture callback */
60 	mctp_capture_fn capture;
61 	void *capture_data;
62 
63 	/* Message reassembly.
64 	 * @todo: flexible context count
65 	 */
66 	struct mctp_msg_ctx msg_ctxs[16];
67 
68 	enum {
69 		ROUTE_ENDPOINT,
70 		ROUTE_BRIDGE,
71 	} route_policy;
72 	size_t max_message_size;
73 };
74 
75 #ifndef BUILD_ASSERT
76 #define BUILD_ASSERT(x)                                                        \
77 	do {                                                                   \
78 		(void)sizeof(char[0 - (!(x))]);                                \
79 	} while (0)
80 #endif
81 
82 #ifndef ARRAY_SIZE
83 #define ARRAY_SIZE(a) (sizeof(a) / sizeof(a[0]))
84 #endif
85 
86 /* 64kb should be sufficient for a single message. Applications
87  * requiring higher sizes can override by setting max_message_size.*/
88 #ifndef MCTP_MAX_MESSAGE_SIZE
89 #define MCTP_MAX_MESSAGE_SIZE 65536
90 #endif
91 
92 static int mctp_message_tx_on_bus(struct mctp_bus *bus, mctp_eid_t src,
93 				  mctp_eid_t dest, bool tag_owner,
94 				  uint8_t msg_tag, void *msg, size_t msg_len);
95 
96 struct mctp_pktbuf *mctp_pktbuf_alloc(struct mctp_binding *binding, size_t len)
97 {
98 	struct mctp_pktbuf *buf;
99 	size_t size;
100 
101 	size = binding->pkt_size + binding->pkt_header + binding->pkt_trailer;
102 	if (len > size) {
103 		return NULL;
104 	}
105 
106 	/* todo: pools */
107 	buf = __mctp_alloc(sizeof(*buf) + size);
108 
109 	if (!buf)
110 		return NULL;
111 
112 	buf->size = size;
113 	buf->start = binding->pkt_header;
114 	buf->end = buf->start + len;
115 	buf->mctp_hdr_off = buf->start;
116 	buf->next = NULL;
117 
118 	return buf;
119 }
120 
121 void mctp_pktbuf_free(struct mctp_pktbuf *pkt)
122 {
123 	__mctp_free(pkt);
124 }
125 
126 struct mctp_hdr *mctp_pktbuf_hdr(struct mctp_pktbuf *pkt)
127 {
128 	return (struct mctp_hdr *)(pkt->data + pkt->mctp_hdr_off);
129 }
130 
131 void *mctp_pktbuf_data(struct mctp_pktbuf *pkt)
132 {
133 	return pkt->data + pkt->mctp_hdr_off + sizeof(struct mctp_hdr);
134 }
135 
136 size_t mctp_pktbuf_size(struct mctp_pktbuf *pkt)
137 {
138 	return pkt->end - pkt->start;
139 }
140 
141 void *mctp_pktbuf_alloc_start(struct mctp_pktbuf *pkt, size_t size)
142 {
143 	assert(size <= pkt->start);
144 	pkt->start -= size;
145 	return pkt->data + pkt->start;
146 }
147 
148 void *mctp_pktbuf_alloc_end(struct mctp_pktbuf *pkt, size_t size)
149 {
150 	void *buf;
151 
152 	assert(size <= (pkt->size - pkt->end));
153 	buf = pkt->data + pkt->end;
154 	pkt->end += size;
155 	return buf;
156 }
157 
158 int mctp_pktbuf_push(struct mctp_pktbuf *pkt, void *data, size_t len)
159 {
160 	void *p;
161 
162 	if (pkt->end + len > pkt->size)
163 		return -1;
164 
165 	p = pkt->data + pkt->end;
166 
167 	pkt->end += len;
168 	memcpy(p, data, len);
169 
170 	return 0;
171 }
172 
173 void *mctp_pktbuf_pop(struct mctp_pktbuf *pkt, size_t len)
174 {
175 	if (len > mctp_pktbuf_size(pkt))
176 		return NULL;
177 
178 	pkt->end -= len;
179 	return pkt->data + pkt->end;
180 }
181 
182 /* Message reassembly */
183 static struct mctp_msg_ctx *mctp_msg_ctx_lookup(struct mctp *mctp, uint8_t src,
184 						uint8_t dest, uint8_t tag)
185 {
186 	unsigned int i;
187 
188 	/* @todo: better lookup, if we add support for more outstanding
189 	 * message contexts */
190 	for (i = 0; i < ARRAY_SIZE(mctp->msg_ctxs); i++) {
191 		struct mctp_msg_ctx *ctx = &mctp->msg_ctxs[i];
192 		if (ctx->src == src && ctx->dest == dest && ctx->tag == tag)
193 			return ctx;
194 	}
195 
196 	return NULL;
197 }
198 
199 static struct mctp_msg_ctx *mctp_msg_ctx_create(struct mctp *mctp, uint8_t src,
200 						uint8_t dest, uint8_t tag)
201 {
202 	struct mctp_msg_ctx *ctx = NULL;
203 	unsigned int i;
204 
205 	for (i = 0; i < ARRAY_SIZE(mctp->msg_ctxs); i++) {
206 		struct mctp_msg_ctx *tmp = &mctp->msg_ctxs[i];
207 		if (!tmp->src) {
208 			ctx = tmp;
209 			break;
210 		}
211 	}
212 
213 	if (!ctx)
214 		return NULL;
215 
216 	ctx->src = src;
217 	ctx->dest = dest;
218 	ctx->tag = tag;
219 	ctx->buf_size = 0;
220 
221 	return ctx;
222 }
223 
224 static void mctp_msg_ctx_drop(struct mctp_msg_ctx *ctx)
225 {
226 	ctx->src = 0;
227 }
228 
229 static void mctp_msg_ctx_reset(struct mctp_msg_ctx *ctx)
230 {
231 	ctx->buf_size = 0;
232 	ctx->fragment_size = 0;
233 }
234 
235 static int mctp_msg_ctx_add_pkt(struct mctp_msg_ctx *ctx,
236 				struct mctp_pktbuf *pkt, size_t max_size)
237 {
238 	size_t len;
239 
240 	len = mctp_pktbuf_size(pkt) - sizeof(struct mctp_hdr);
241 
242 	if (len + ctx->buf_size < ctx->buf_size) {
243 		return -1;
244 	}
245 
246 	if (ctx->buf_size + len > ctx->buf_alloc_size) {
247 		size_t new_alloc_size;
248 		void *lbuf;
249 
250 		/* @todo: finer-grained allocation */
251 		if (!ctx->buf_alloc_size) {
252 			new_alloc_size = MAX(len, 4096UL);
253 		} else {
254 			new_alloc_size = MAX(ctx->buf_alloc_size * 2,
255 					     len + ctx->buf_size);
256 		}
257 
258 		/* Don't allow heap to grow beyond a limit */
259 		if (new_alloc_size > max_size)
260 			return -1;
261 
262 		lbuf = __mctp_realloc(ctx->buf, new_alloc_size);
263 		if (lbuf) {
264 			ctx->buf = lbuf;
265 			ctx->buf_alloc_size = new_alloc_size;
266 		} else {
267 			__mctp_free(ctx->buf);
268 			return -1;
269 		}
270 	}
271 
272 	memcpy((uint8_t *)ctx->buf + ctx->buf_size, mctp_pktbuf_data(pkt), len);
273 	ctx->buf_size += len;
274 
275 	return 0;
276 }
277 
278 /* Core API functions */
279 struct mctp *mctp_init(void)
280 {
281 	struct mctp *mctp;
282 
283 	mctp = __mctp_alloc(sizeof(*mctp));
284 
285 	if (!mctp)
286 		return NULL;
287 
288 	memset(mctp, 0, sizeof(*mctp));
289 	mctp->max_message_size = MCTP_MAX_MESSAGE_SIZE;
290 
291 	return mctp;
292 }
293 
294 void mctp_set_max_message_size(struct mctp *mctp, size_t message_size)
295 {
296 	mctp->max_message_size = message_size;
297 }
298 
299 void mctp_set_capture_handler(struct mctp *mctp, mctp_capture_fn fn, void *user)
300 {
301 	mctp->capture = fn;
302 	mctp->capture_data = user;
303 }
304 
305 static void mctp_bus_destroy(struct mctp_bus *bus)
306 {
307 	while (bus->tx_queue_head) {
308 		struct mctp_pktbuf *curr = bus->tx_queue_head;
309 
310 		bus->tx_queue_head = curr->next;
311 		mctp_pktbuf_free(curr);
312 	}
313 }
314 
315 void mctp_destroy(struct mctp *mctp)
316 {
317 	size_t i;
318 
319 	/* Cleanup message assembly contexts */
320 	BUILD_ASSERT(ARRAY_SIZE(mctp->msg_ctxs) < SIZE_MAX);
321 	for (i = 0; i < ARRAY_SIZE(mctp->msg_ctxs); i++) {
322 		struct mctp_msg_ctx *tmp = &mctp->msg_ctxs[i];
323 		if (tmp->buf)
324 			__mctp_free(tmp->buf);
325 	}
326 
327 	while (mctp->n_busses--)
328 		mctp_bus_destroy(&mctp->busses[mctp->n_busses]);
329 
330 	__mctp_free(mctp->busses);
331 	__mctp_free(mctp);
332 }
333 
334 int mctp_set_rx_all(struct mctp *mctp, mctp_rx_fn fn, void *data)
335 {
336 	mctp->message_rx = fn;
337 	mctp->message_rx_data = data;
338 	return 0;
339 }
340 
341 static struct mctp_bus *find_bus_for_eid(struct mctp *mctp, mctp_eid_t dest
342 					 __attribute__((unused)))
343 {
344 	if (mctp->n_busses == 0)
345 		return NULL;
346 
347 	/* for now, just use the first bus. For full routing support,
348 	 * we will need a table of neighbours */
349 	return &mctp->busses[0];
350 }
351 
352 int mctp_register_bus(struct mctp *mctp, struct mctp_binding *binding,
353 		      mctp_eid_t eid)
354 {
355 	int rc = 0;
356 
357 	/* todo: multiple busses */
358 	assert(mctp->n_busses == 0);
359 	mctp->n_busses = 1;
360 
361 	mctp->busses = __mctp_alloc(sizeof(struct mctp_bus));
362 	if (!mctp->busses)
363 		return -ENOMEM;
364 
365 	memset(mctp->busses, 0, sizeof(struct mctp_bus));
366 	mctp->busses[0].binding = binding;
367 	mctp->busses[0].eid = eid;
368 	binding->bus = &mctp->busses[0];
369 	binding->mctp = mctp;
370 	mctp->route_policy = ROUTE_ENDPOINT;
371 
372 	if (binding->start) {
373 		rc = binding->start(binding);
374 		if (rc < 0) {
375 			mctp_prerr("Failed to start binding: %d", rc);
376 			binding->bus = NULL;
377 			__mctp_free(mctp->busses);
378 			mctp->busses = NULL;
379 			mctp->n_busses = 0;
380 		}
381 	}
382 
383 	return rc;
384 }
385 
386 void mctp_unregister_bus(struct mctp *mctp, struct mctp_binding *binding)
387 {
388 	/*
389 	 * We only support one bus right now; once the call completes we will
390 	 * have no more busses
391 	 */
392 	mctp->n_busses = 0;
393 	binding->mctp = NULL;
394 	binding->bus = NULL;
395 	__mctp_free(mctp->busses);
396 }
397 
398 int mctp_bridge_busses(struct mctp *mctp, struct mctp_binding *b1,
399 		       struct mctp_binding *b2)
400 {
401 	int rc = 0;
402 
403 	assert(mctp->n_busses == 0);
404 	mctp->busses = __mctp_alloc(2 * sizeof(struct mctp_bus));
405 	if (!mctp->busses)
406 		return -ENOMEM;
407 	memset(mctp->busses, 0, 2 * sizeof(struct mctp_bus));
408 	mctp->n_busses = 2;
409 	mctp->busses[0].binding = b1;
410 	b1->bus = &mctp->busses[0];
411 	b1->mctp = mctp;
412 	mctp->busses[1].binding = b2;
413 	b2->bus = &mctp->busses[1];
414 	b2->mctp = mctp;
415 
416 	mctp->route_policy = ROUTE_BRIDGE;
417 
418 	if (b1->start) {
419 		rc = b1->start(b1);
420 		if (rc < 0) {
421 			mctp_prerr("Failed to start bridged bus %s: %d",
422 				   b1->name, rc);
423 			goto done;
424 		}
425 	}
426 
427 	if (b2->start) {
428 		rc = b2->start(b2);
429 		if (rc < 0) {
430 			mctp_prerr("Failed to start bridged bus %s: %d",
431 				   b2->name, rc);
432 			goto done;
433 		}
434 	}
435 
436 done:
437 	return rc;
438 }
439 
440 static inline bool mctp_ctrl_cmd_is_transport(struct mctp_ctrl_msg_hdr *hdr)
441 {
442 	return ((hdr->command_code >= MCTP_CTRL_CMD_FIRST_TRANSPORT) &&
443 		(hdr->command_code <= MCTP_CTRL_CMD_LAST_TRANSPORT));
444 }
445 
446 static bool mctp_ctrl_handle_msg(struct mctp_bus *bus, mctp_eid_t src,
447 				 uint8_t msg_tag, bool tag_owner, void *buffer,
448 				 size_t length)
449 {
450 	struct mctp_ctrl_msg_hdr *msg_hdr = buffer;
451 
452 	/*
453 	 * Control message is received. If a transport control message handler
454 	 * is provided, it will called. If there is no dedicated handler, this
455 	 * function returns false and data can be handled by the generic
456 	 * message handler. The transport control message handler will be
457 	 * provided with messages in the command range 0xF0 - 0xFF.
458 	 */
459 	if (mctp_ctrl_cmd_is_transport(msg_hdr)) {
460 		if (bus->binding->control_rx != NULL) {
461 			/* MCTP bus binding handler */
462 			bus->binding->control_rx(src, msg_tag, tag_owner,
463 						 bus->binding->control_rx_data,
464 						 buffer, length);
465 			return true;
466 		}
467 	}
468 
469 	/*
470 	 * Command was not handled, due to lack of specific callback.
471 	 * It will be passed to regular message_rx handler.
472 	 */
473 	return false;
474 }
475 
476 static inline bool mctp_rx_dest_is_local(struct mctp_bus *bus, mctp_eid_t dest)
477 {
478 	return dest == bus->eid || dest == MCTP_EID_NULL ||
479 	       dest == MCTP_EID_BROADCAST;
480 }
481 
482 static inline bool mctp_ctrl_cmd_is_request(struct mctp_ctrl_msg_hdr *hdr)
483 {
484 	return hdr->ic_msg_type == MCTP_CTRL_HDR_MSG_TYPE &&
485 	       hdr->rq_dgram_inst & MCTP_CTRL_HDR_FLAG_REQUEST;
486 }
487 
488 /*
489  * Receive the complete MCTP message and route it.
490  * Asserts:
491  *     'buf' is not NULL.
492  */
493 static void mctp_rx(struct mctp *mctp, struct mctp_bus *bus, mctp_eid_t src,
494 		    mctp_eid_t dest, bool tag_owner, uint8_t msg_tag, void *buf,
495 		    size_t len)
496 {
497 	assert(buf != NULL);
498 
499 	if (mctp->route_policy == ROUTE_ENDPOINT &&
500 	    mctp_rx_dest_is_local(bus, dest)) {
501 		/* Handle MCTP Control Messages: */
502 		if (len >= sizeof(struct mctp_ctrl_msg_hdr)) {
503 			struct mctp_ctrl_msg_hdr *msg_hdr = buf;
504 
505 			/*
506 			 * Identify if this is a control request message.
507 			 * See DSP0236 v1.3.0 sec. 11.5.
508 			 */
509 			if (mctp_ctrl_cmd_is_request(msg_hdr)) {
510 				bool handled;
511 				handled = mctp_ctrl_handle_msg(
512 					bus, src, msg_tag, tag_owner, buf, len);
513 				if (handled)
514 					return;
515 			}
516 		}
517 
518 		if (mctp->message_rx)
519 			mctp->message_rx(src, tag_owner, msg_tag,
520 					 mctp->message_rx_data, buf, len);
521 	}
522 
523 	if (mctp->route_policy == ROUTE_BRIDGE) {
524 		int i;
525 
526 		for (i = 0; i < mctp->n_busses; i++) {
527 			struct mctp_bus *dest_bus = &mctp->busses[i];
528 			if (dest_bus == bus)
529 				continue;
530 
531 			mctp_message_tx_on_bus(dest_bus, src, dest, tag_owner,
532 					       msg_tag, buf, len);
533 		}
534 	}
535 }
536 
537 void mctp_bus_rx(struct mctp_binding *binding, struct mctp_pktbuf *pkt)
538 {
539 	struct mctp_bus *bus = binding->bus;
540 	struct mctp *mctp = binding->mctp;
541 	uint8_t flags, exp_seq, seq, tag;
542 	struct mctp_msg_ctx *ctx;
543 	struct mctp_hdr *hdr;
544 	bool tag_owner;
545 	size_t len;
546 	void *p;
547 	int rc;
548 
549 	assert(bus);
550 
551 	/* Drop packet if it was smaller than mctp hdr size */
552 	if (mctp_pktbuf_size(pkt) <= sizeof(struct mctp_hdr))
553 		goto out;
554 
555 	if (mctp->capture)
556 		mctp->capture(pkt, MCTP_MESSAGE_CAPTURE_INCOMING,
557 			      mctp->capture_data);
558 
559 	hdr = mctp_pktbuf_hdr(pkt);
560 
561 	/* small optimisation: don't bother reassembly if we're going to
562 	 * drop the packet in mctp_rx anyway */
563 	if (mctp->route_policy == ROUTE_ENDPOINT && hdr->dest != bus->eid)
564 		goto out;
565 
566 	flags = hdr->flags_seq_tag & (MCTP_HDR_FLAG_SOM | MCTP_HDR_FLAG_EOM);
567 	tag = (hdr->flags_seq_tag >> MCTP_HDR_TAG_SHIFT) & MCTP_HDR_TAG_MASK;
568 	seq = (hdr->flags_seq_tag >> MCTP_HDR_SEQ_SHIFT) & MCTP_HDR_SEQ_MASK;
569 	tag_owner = (hdr->flags_seq_tag >> MCTP_HDR_TO_SHIFT) &
570 		    MCTP_HDR_TO_MASK;
571 
572 	switch (flags) {
573 	case MCTP_HDR_FLAG_SOM | MCTP_HDR_FLAG_EOM:
574 		/* single-packet message - send straight up to rx function,
575 		 * no need to create a message context */
576 		len = pkt->end - pkt->mctp_hdr_off - sizeof(struct mctp_hdr);
577 		p = pkt->data + pkt->mctp_hdr_off + sizeof(struct mctp_hdr);
578 		mctp_rx(mctp, bus, hdr->src, hdr->dest, tag_owner, tag, p, len);
579 		break;
580 
581 	case MCTP_HDR_FLAG_SOM:
582 		/* start of a new message - start the new context for
583 		 * future message reception. If an existing context is
584 		 * already present, drop it. */
585 		ctx = mctp_msg_ctx_lookup(mctp, hdr->src, hdr->dest, tag);
586 		if (ctx) {
587 			mctp_msg_ctx_reset(ctx);
588 		} else {
589 			ctx = mctp_msg_ctx_create(mctp, hdr->src, hdr->dest,
590 						  tag);
591 			/* If context creation fails due to exhaution of contexts we
592 			* can support, drop the packet */
593 			if (!ctx) {
594 				mctp_prdebug("Context buffers exhausted.");
595 				goto out;
596 			}
597 		}
598 
599 		/* Save the fragment size, subsequent middle fragments
600 		 * should of the same size */
601 		ctx->fragment_size = mctp_pktbuf_size(pkt);
602 
603 		rc = mctp_msg_ctx_add_pkt(ctx, pkt, mctp->max_message_size);
604 		if (rc) {
605 			mctp_msg_ctx_drop(ctx);
606 		} else {
607 			ctx->last_seq = seq;
608 		}
609 
610 		break;
611 
612 	case MCTP_HDR_FLAG_EOM:
613 		ctx = mctp_msg_ctx_lookup(mctp, hdr->src, hdr->dest, tag);
614 		if (!ctx)
615 			goto out;
616 
617 		exp_seq = (ctx->last_seq + 1) % 4;
618 
619 		if (exp_seq != seq) {
620 			mctp_prdebug(
621 				"Sequence number %d does not match expected %d",
622 				seq, exp_seq);
623 			mctp_msg_ctx_drop(ctx);
624 			goto out;
625 		}
626 
627 		len = mctp_pktbuf_size(pkt);
628 
629 		if (len > ctx->fragment_size) {
630 			mctp_prdebug("Unexpected fragment size. Expected"
631 				     " less than %zu, received = %zu",
632 				     ctx->fragment_size, len);
633 			mctp_msg_ctx_drop(ctx);
634 			goto out;
635 		}
636 
637 		rc = mctp_msg_ctx_add_pkt(ctx, pkt, mctp->max_message_size);
638 		if (!rc)
639 			mctp_rx(mctp, bus, ctx->src, ctx->dest, tag_owner, tag,
640 				ctx->buf, ctx->buf_size);
641 
642 		mctp_msg_ctx_drop(ctx);
643 		break;
644 
645 	case 0:
646 		/* Neither SOM nor EOM */
647 		ctx = mctp_msg_ctx_lookup(mctp, hdr->src, hdr->dest, tag);
648 		if (!ctx)
649 			goto out;
650 
651 		exp_seq = (ctx->last_seq + 1) % 4;
652 		if (exp_seq != seq) {
653 			mctp_prdebug(
654 				"Sequence number %d does not match expected %d",
655 				seq, exp_seq);
656 			mctp_msg_ctx_drop(ctx);
657 			goto out;
658 		}
659 
660 		len = mctp_pktbuf_size(pkt);
661 
662 		if (len != ctx->fragment_size) {
663 			mctp_prdebug("Unexpected fragment size. Expected = %zu "
664 				     "received = %zu",
665 				     ctx->fragment_size, len);
666 			mctp_msg_ctx_drop(ctx);
667 			goto out;
668 		}
669 
670 		rc = mctp_msg_ctx_add_pkt(ctx, pkt, mctp->max_message_size);
671 		if (rc) {
672 			mctp_msg_ctx_drop(ctx);
673 			goto out;
674 		}
675 		ctx->last_seq = seq;
676 
677 		break;
678 	}
679 out:
680 	mctp_pktbuf_free(pkt);
681 }
682 
683 static int mctp_packet_tx(struct mctp_bus *bus, struct mctp_pktbuf *pkt)
684 {
685 	struct mctp *mctp = bus->binding->mctp;
686 
687 	if (bus->state != mctp_bus_state_tx_enabled)
688 		return -1;
689 
690 	if (mctp->capture)
691 		mctp->capture(pkt, MCTP_MESSAGE_CAPTURE_OUTGOING,
692 			      mctp->capture_data);
693 
694 	return bus->binding->tx(bus->binding, pkt);
695 }
696 
697 static void mctp_send_tx_queue(struct mctp_bus *bus)
698 {
699 	struct mctp_pktbuf *pkt;
700 
701 	while ((pkt = bus->tx_queue_head)) {
702 		int rc;
703 
704 		rc = mctp_packet_tx(bus, pkt);
705 		switch (rc) {
706 		/* If transmission succeded, or */
707 		case 0:
708 		/* If the packet is somehow too large */
709 		case -EMSGSIZE:
710 			/* Drop the packet */
711 			bus->tx_queue_head = pkt->next;
712 			mctp_pktbuf_free(pkt);
713 			break;
714 
715 		/* If the binding was busy, or */
716 		case -EBUSY:
717 		/* Some other unknown error occurred */
718 		default:
719 			/* Make sure the tail pointer is consistent and retry later */
720 			goto cleanup_tail;
721 		};
722 	}
723 
724 cleanup_tail:
725 	if (!bus->tx_queue_head)
726 		bus->tx_queue_tail = NULL;
727 }
728 
729 void mctp_binding_set_tx_enabled(struct mctp_binding *binding, bool enable)
730 {
731 	struct mctp_bus *bus = binding->bus;
732 
733 	switch (bus->state) {
734 	case mctp_bus_state_constructed:
735 		if (!enable)
736 			return;
737 
738 		if (binding->pkt_size < MCTP_PACKET_SIZE(MCTP_BTU)) {
739 			mctp_prerr(
740 				"Cannot start %s binding with invalid MTU: %zu",
741 				binding->name,
742 				MCTP_BODY_SIZE(binding->pkt_size));
743 			return;
744 		}
745 
746 		bus->state = mctp_bus_state_tx_enabled;
747 		mctp_prinfo("%s binding started", binding->name);
748 		return;
749 	case mctp_bus_state_tx_enabled:
750 		if (enable)
751 			return;
752 
753 		bus->state = mctp_bus_state_tx_disabled;
754 		mctp_prdebug("%s binding Tx disabled", binding->name);
755 		return;
756 	case mctp_bus_state_tx_disabled:
757 		if (!enable)
758 			return;
759 
760 		bus->state = mctp_bus_state_tx_enabled;
761 		mctp_prdebug("%s binding Tx enabled", binding->name);
762 		mctp_send_tx_queue(bus);
763 		return;
764 	}
765 }
766 
767 static int mctp_message_tx_on_bus(struct mctp_bus *bus, mctp_eid_t src,
768 				  mctp_eid_t dest, bool tag_owner,
769 				  uint8_t msg_tag, void *msg, size_t msg_len)
770 {
771 	size_t max_payload_len, payload_len, p;
772 	struct mctp_pktbuf *pkt;
773 	struct mctp_hdr *hdr;
774 	int i;
775 
776 	if (bus->state == mctp_bus_state_constructed)
777 		return -ENXIO;
778 
779 	if ((msg_tag & MCTP_HDR_TAG_MASK) != msg_tag)
780 		return -EINVAL;
781 
782 	max_payload_len = MCTP_BODY_SIZE(bus->binding->pkt_size);
783 
784 	{
785 		const bool valid_mtu = max_payload_len >= MCTP_BTU;
786 		assert(valid_mtu);
787 		if (!valid_mtu)
788 			return -EINVAL;
789 	}
790 
791 	mctp_prdebug(
792 		"%s: Generating packets for transmission of %zu byte message from %hhu to %hhu",
793 		__func__, msg_len, src, dest);
794 
795 	/* queue up packets, each of max MCTP_MTU size */
796 	for (p = 0, i = 0; p < msg_len; i++) {
797 		payload_len = msg_len - p;
798 		if (payload_len > max_payload_len)
799 			payload_len = max_payload_len;
800 
801 		pkt = mctp_pktbuf_alloc(bus->binding,
802 					payload_len + sizeof(*hdr));
803 		hdr = mctp_pktbuf_hdr(pkt);
804 
805 		hdr->ver = bus->binding->version & 0xf;
806 		hdr->dest = dest;
807 		hdr->src = src;
808 		hdr->flags_seq_tag = (tag_owner << MCTP_HDR_TO_SHIFT) |
809 				     (msg_tag << MCTP_HDR_TAG_SHIFT);
810 
811 		if (i == 0)
812 			hdr->flags_seq_tag |= MCTP_HDR_FLAG_SOM;
813 		if (p + payload_len >= msg_len)
814 			hdr->flags_seq_tag |= MCTP_HDR_FLAG_EOM;
815 		hdr->flags_seq_tag |= (i & MCTP_HDR_SEQ_MASK)
816 				      << MCTP_HDR_SEQ_SHIFT;
817 
818 		memcpy(mctp_pktbuf_data(pkt), (uint8_t *)msg + p, payload_len);
819 
820 		/* add to tx queue */
821 		if (bus->tx_queue_tail)
822 			bus->tx_queue_tail->next = pkt;
823 		else
824 			bus->tx_queue_head = pkt;
825 		bus->tx_queue_tail = pkt;
826 
827 		p += payload_len;
828 	}
829 
830 	mctp_prdebug("%s: Enqueued %d packets", __func__, i);
831 
832 	mctp_send_tx_queue(bus);
833 
834 	return 0;
835 }
836 
837 int mctp_message_tx(struct mctp *mctp, mctp_eid_t eid, bool tag_owner,
838 		    uint8_t msg_tag, void *msg, size_t msg_len)
839 {
840 	struct mctp_bus *bus;
841 
842 	/* TODO: Protect against same tag being used across
843 	 * different callers */
844 	if ((msg_tag & MCTP_HDR_TAG_MASK) != msg_tag) {
845 		mctp_prerr("Incorrect message tag %u passed.", msg_tag);
846 		return -EINVAL;
847 	}
848 
849 	bus = find_bus_for_eid(mctp, eid);
850 	if (!bus)
851 		return 0;
852 
853 	return mctp_message_tx_on_bus(bus, bus->eid, eid, tag_owner, msg_tag,
854 				      msg, msg_len);
855 }
856