1 /*
2  * Copyright (c) 2004 Topspin Communications.  All rights reserved.
3  * Copyright (c) 2005 Sun Microsystems, Inc. All rights reserved.
4  * Copyright (c) 2004 Voltaire, Inc. All rights reserved.
5  *
6  * This software is available to you under a choice of one of two
7  * licenses.  You may choose to be licensed under the terms of the GNU
8  * General Public License (GPL) Version 2, available from the file
9  * COPYING in the main directory of this source tree, or the
10  * OpenIB.org BSD license below:
11  *
12  *     Redistribution and use in source and binary forms, with or
13  *     without modification, are permitted provided that the following
14  *     conditions are met:
15  *
16  *      - Redistributions of source code must retain the above
17  *        copyright notice, this list of conditions and the following
18  *        disclaimer.
19  *
20  *      - Redistributions in binary form must reproduce the above
21  *        copyright notice, this list of conditions and the following
22  *        disclaimer in the documentation and/or other materials
23  *        provided with the distribution.
24  *
25  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
26  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
27  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
28  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
29  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
30  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
31  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
32  * SOFTWARE.
33  */
34 
35 #include "ipoib.h"
36 
37 #include <linux/module.h>
38 
39 #include <linux/init.h>
40 #include <linux/slab.h>
41 #include <linux/kernel.h>
42 #include <linux/vmalloc.h>
43 
44 #include <linux/if_arp.h>	/* For ARPHRD_xxx */
45 
46 #include <linux/ip.h>
47 #include <linux/in.h>
48 
49 #include <linux/jhash.h>
50 #include <net/arp.h>
51 #include <net/addrconf.h>
52 #include <linux/inetdevice.h>
53 #include <rdma/ib_cache.h>
54 #include <linux/pci.h>
55 
56 #define DRV_VERSION "1.0.0"
57 
58 const char ipoib_driver_version[] = DRV_VERSION;
59 
60 MODULE_AUTHOR("Roland Dreier");
61 MODULE_DESCRIPTION("IP-over-InfiniBand net driver");
62 MODULE_LICENSE("Dual BSD/GPL");
63 MODULE_VERSION(DRV_VERSION);
64 
65 int ipoib_sendq_size __read_mostly = IPOIB_TX_RING_SIZE;
66 int ipoib_recvq_size __read_mostly = IPOIB_RX_RING_SIZE;
67 
68 module_param_named(send_queue_size, ipoib_sendq_size, int, 0444);
69 MODULE_PARM_DESC(send_queue_size, "Number of descriptors in send queue");
70 module_param_named(recv_queue_size, ipoib_recvq_size, int, 0444);
71 MODULE_PARM_DESC(recv_queue_size, "Number of descriptors in receive queue");
72 
73 #ifdef CONFIG_INFINIBAND_IPOIB_DEBUG
74 int ipoib_debug_level;
75 
76 module_param_named(debug_level, ipoib_debug_level, int, 0644);
77 MODULE_PARM_DESC(debug_level, "Enable debug tracing if > 0");
78 #endif
79 
80 struct ipoib_path_iter {
81 	struct net_device *dev;
82 	struct ipoib_path  path;
83 };
84 
85 static const u8 ipv4_bcast_addr[] = {
86 	0x00, 0xff, 0xff, 0xff,
87 	0xff, 0x12, 0x40, 0x1b,	0x00, 0x00, 0x00, 0x00,
88 	0x00, 0x00, 0x00, 0x00,	0xff, 0xff, 0xff, 0xff
89 };
90 
91 struct workqueue_struct *ipoib_workqueue;
92 
93 struct ib_sa_client ipoib_sa_client;
94 
95 static void ipoib_add_one(struct ib_device *device);
96 static void ipoib_remove_one(struct ib_device *device, void *client_data);
97 static void ipoib_neigh_reclaim(struct rcu_head *rp);
98 static struct net_device *ipoib_get_net_dev_by_params(
99 		struct ib_device *dev, u8 port, u16 pkey,
100 		const union ib_gid *gid, const struct sockaddr *addr,
101 		void *client_data);
102 static int ipoib_set_mac(struct net_device *dev, void *addr);
103 
104 static struct ib_client ipoib_client = {
105 	.name   = "ipoib",
106 	.add    = ipoib_add_one,
107 	.remove = ipoib_remove_one,
108 	.get_net_dev_by_params = ipoib_get_net_dev_by_params,
109 };
110 
111 int ipoib_open(struct net_device *dev)
112 {
113 	struct ipoib_dev_priv *priv = netdev_priv(dev);
114 
115 	ipoib_dbg(priv, "bringing up interface\n");
116 
117 	netif_carrier_off(dev);
118 
119 	set_bit(IPOIB_FLAG_ADMIN_UP, &priv->flags);
120 
121 	priv->sm_fullmember_sendonly_support = false;
122 
123 	if (ipoib_ib_dev_open(dev)) {
124 		if (!test_bit(IPOIB_PKEY_ASSIGNED, &priv->flags))
125 			return 0;
126 		goto err_disable;
127 	}
128 
129 	if (ipoib_ib_dev_up(dev))
130 		goto err_stop;
131 
132 	if (!test_bit(IPOIB_FLAG_SUBINTERFACE, &priv->flags)) {
133 		struct ipoib_dev_priv *cpriv;
134 
135 		/* Bring up any child interfaces too */
136 		down_read(&priv->vlan_rwsem);
137 		list_for_each_entry(cpriv, &priv->child_intfs, list) {
138 			int flags;
139 
140 			flags = cpriv->dev->flags;
141 			if (flags & IFF_UP)
142 				continue;
143 
144 			dev_change_flags(cpriv->dev, flags | IFF_UP);
145 		}
146 		up_read(&priv->vlan_rwsem);
147 	}
148 
149 	netif_start_queue(dev);
150 
151 	return 0;
152 
153 err_stop:
154 	ipoib_ib_dev_stop(dev);
155 
156 err_disable:
157 	clear_bit(IPOIB_FLAG_ADMIN_UP, &priv->flags);
158 
159 	return -EINVAL;
160 }
161 
162 static int ipoib_stop(struct net_device *dev)
163 {
164 	struct ipoib_dev_priv *priv = netdev_priv(dev);
165 
166 	ipoib_dbg(priv, "stopping interface\n");
167 
168 	clear_bit(IPOIB_FLAG_ADMIN_UP, &priv->flags);
169 
170 	netif_stop_queue(dev);
171 
172 	ipoib_ib_dev_down(dev);
173 	ipoib_ib_dev_stop(dev);
174 
175 	if (!test_bit(IPOIB_FLAG_SUBINTERFACE, &priv->flags)) {
176 		struct ipoib_dev_priv *cpriv;
177 
178 		/* Bring down any child interfaces too */
179 		down_read(&priv->vlan_rwsem);
180 		list_for_each_entry(cpriv, &priv->child_intfs, list) {
181 			int flags;
182 
183 			flags = cpriv->dev->flags;
184 			if (!(flags & IFF_UP))
185 				continue;
186 
187 			dev_change_flags(cpriv->dev, flags & ~IFF_UP);
188 		}
189 		up_read(&priv->vlan_rwsem);
190 	}
191 
192 	return 0;
193 }
194 
195 static void ipoib_uninit(struct net_device *dev)
196 {
197 	ipoib_dev_cleanup(dev);
198 }
199 
200 static netdev_features_t ipoib_fix_features(struct net_device *dev, netdev_features_t features)
201 {
202 	struct ipoib_dev_priv *priv = netdev_priv(dev);
203 
204 	if (test_bit(IPOIB_FLAG_ADMIN_CM, &priv->flags))
205 		features &= ~(NETIF_F_IP_CSUM | NETIF_F_TSO);
206 
207 	return features;
208 }
209 
210 static int ipoib_change_mtu(struct net_device *dev, int new_mtu)
211 {
212 	struct ipoib_dev_priv *priv = netdev_priv(dev);
213 
214 	/* dev->mtu > 2K ==> connected mode */
215 	if (ipoib_cm_admin_enabled(dev)) {
216 		if (new_mtu > ipoib_cm_max_mtu(dev))
217 			return -EINVAL;
218 
219 		if (new_mtu > priv->mcast_mtu)
220 			ipoib_warn(priv, "mtu > %d will cause multicast packet drops.\n",
221 				   priv->mcast_mtu);
222 
223 		dev->mtu = new_mtu;
224 		return 0;
225 	}
226 
227 	if (new_mtu > IPOIB_UD_MTU(priv->max_ib_mtu))
228 		return -EINVAL;
229 
230 	priv->admin_mtu = new_mtu;
231 
232 	dev->mtu = min(priv->mcast_mtu, priv->admin_mtu);
233 
234 	return 0;
235 }
236 
237 /* Called with an RCU read lock taken */
238 static bool ipoib_is_dev_match_addr_rcu(const struct sockaddr *addr,
239 					struct net_device *dev)
240 {
241 	struct net *net = dev_net(dev);
242 	struct in_device *in_dev;
243 	struct sockaddr_in *addr_in = (struct sockaddr_in *)addr;
244 	struct sockaddr_in6 *addr_in6 = (struct sockaddr_in6 *)addr;
245 	__be32 ret_addr;
246 
247 	switch (addr->sa_family) {
248 	case AF_INET:
249 		in_dev = in_dev_get(dev);
250 		if (!in_dev)
251 			return false;
252 
253 		ret_addr = inet_confirm_addr(net, in_dev, 0,
254 					     addr_in->sin_addr.s_addr,
255 					     RT_SCOPE_HOST);
256 		in_dev_put(in_dev);
257 		if (ret_addr)
258 			return true;
259 
260 		break;
261 	case AF_INET6:
262 		if (IS_ENABLED(CONFIG_IPV6) &&
263 		    ipv6_chk_addr(net, &addr_in6->sin6_addr, dev, 1))
264 			return true;
265 
266 		break;
267 	}
268 	return false;
269 }
270 
271 /**
272  * Find the master net_device on top of the given net_device.
273  * @dev: base IPoIB net_device
274  *
275  * Returns the master net_device with a reference held, or the same net_device
276  * if no master exists.
277  */
278 static struct net_device *ipoib_get_master_net_dev(struct net_device *dev)
279 {
280 	struct net_device *master;
281 
282 	rcu_read_lock();
283 	master = netdev_master_upper_dev_get_rcu(dev);
284 	if (master)
285 		dev_hold(master);
286 	rcu_read_unlock();
287 
288 	if (master)
289 		return master;
290 
291 	dev_hold(dev);
292 	return dev;
293 }
294 
295 /**
296  * Find a net_device matching the given address, which is an upper device of
297  * the given net_device.
298  * @addr: IP address to look for.
299  * @dev: base IPoIB net_device
300  *
301  * If found, returns the net_device with a reference held. Otherwise return
302  * NULL.
303  */
304 static struct net_device *ipoib_get_net_dev_match_addr(
305 		const struct sockaddr *addr, struct net_device *dev)
306 {
307 	struct net_device *upper,
308 			  *result = NULL;
309 	struct list_head *iter;
310 
311 	rcu_read_lock();
312 	if (ipoib_is_dev_match_addr_rcu(addr, dev)) {
313 		dev_hold(dev);
314 		result = dev;
315 		goto out;
316 	}
317 
318 	netdev_for_each_all_upper_dev_rcu(dev, upper, iter) {
319 		if (ipoib_is_dev_match_addr_rcu(addr, upper)) {
320 			dev_hold(upper);
321 			result = upper;
322 			break;
323 		}
324 	}
325 out:
326 	rcu_read_unlock();
327 	return result;
328 }
329 
330 /* returns the number of IPoIB netdevs on top a given ipoib device matching a
331  * pkey_index and address, if one exists.
332  *
333  * @found_net_dev: contains a matching net_device if the return value >= 1,
334  * with a reference held. */
335 static int ipoib_match_gid_pkey_addr(struct ipoib_dev_priv *priv,
336 				     const union ib_gid *gid,
337 				     u16 pkey_index,
338 				     const struct sockaddr *addr,
339 				     int nesting,
340 				     struct net_device **found_net_dev)
341 {
342 	struct ipoib_dev_priv *child_priv;
343 	struct net_device *net_dev = NULL;
344 	int matches = 0;
345 
346 	if (priv->pkey_index == pkey_index &&
347 	    (!gid || !memcmp(gid, &priv->local_gid, sizeof(*gid)))) {
348 		if (!addr) {
349 			net_dev = ipoib_get_master_net_dev(priv->dev);
350 		} else {
351 			/* Verify the net_device matches the IP address, as
352 			 * IPoIB child devices currently share a GID. */
353 			net_dev = ipoib_get_net_dev_match_addr(addr, priv->dev);
354 		}
355 		if (net_dev) {
356 			if (!*found_net_dev)
357 				*found_net_dev = net_dev;
358 			else
359 				dev_put(net_dev);
360 			++matches;
361 		}
362 	}
363 
364 	/* Check child interfaces */
365 	down_read_nested(&priv->vlan_rwsem, nesting);
366 	list_for_each_entry(child_priv, &priv->child_intfs, list) {
367 		matches += ipoib_match_gid_pkey_addr(child_priv, gid,
368 						    pkey_index, addr,
369 						    nesting + 1,
370 						    found_net_dev);
371 		if (matches > 1)
372 			break;
373 	}
374 	up_read(&priv->vlan_rwsem);
375 
376 	return matches;
377 }
378 
379 /* Returns the number of matching net_devs found (between 0 and 2). Also
380  * return the matching net_device in the @net_dev parameter, holding a
381  * reference to the net_device, if the number of matches >= 1 */
382 static int __ipoib_get_net_dev_by_params(struct list_head *dev_list, u8 port,
383 					 u16 pkey_index,
384 					 const union ib_gid *gid,
385 					 const struct sockaddr *addr,
386 					 struct net_device **net_dev)
387 {
388 	struct ipoib_dev_priv *priv;
389 	int matches = 0;
390 
391 	*net_dev = NULL;
392 
393 	list_for_each_entry(priv, dev_list, list) {
394 		if (priv->port != port)
395 			continue;
396 
397 		matches += ipoib_match_gid_pkey_addr(priv, gid, pkey_index,
398 						     addr, 0, net_dev);
399 		if (matches > 1)
400 			break;
401 	}
402 
403 	return matches;
404 }
405 
406 static struct net_device *ipoib_get_net_dev_by_params(
407 		struct ib_device *dev, u8 port, u16 pkey,
408 		const union ib_gid *gid, const struct sockaddr *addr,
409 		void *client_data)
410 {
411 	struct net_device *net_dev;
412 	struct list_head *dev_list = client_data;
413 	u16 pkey_index;
414 	int matches;
415 	int ret;
416 
417 	if (!rdma_protocol_ib(dev, port))
418 		return NULL;
419 
420 	ret = ib_find_cached_pkey(dev, port, pkey, &pkey_index);
421 	if (ret)
422 		return NULL;
423 
424 	if (!dev_list)
425 		return NULL;
426 
427 	/* See if we can find a unique device matching the L2 parameters */
428 	matches = __ipoib_get_net_dev_by_params(dev_list, port, pkey_index,
429 						gid, NULL, &net_dev);
430 
431 	switch (matches) {
432 	case 0:
433 		return NULL;
434 	case 1:
435 		return net_dev;
436 	}
437 
438 	dev_put(net_dev);
439 
440 	/* Couldn't find a unique device with L2 parameters only. Use L3
441 	 * address to uniquely match the net device */
442 	matches = __ipoib_get_net_dev_by_params(dev_list, port, pkey_index,
443 						gid, addr, &net_dev);
444 	switch (matches) {
445 	case 0:
446 		return NULL;
447 	default:
448 		dev_warn_ratelimited(&dev->dev,
449 				     "duplicate IP address detected\n");
450 		/* Fall through */
451 	case 1:
452 		return net_dev;
453 	}
454 }
455 
456 int ipoib_set_mode(struct net_device *dev, const char *buf)
457 {
458 	struct ipoib_dev_priv *priv = netdev_priv(dev);
459 
460 	/* flush paths if we switch modes so that connections are restarted */
461 	if (IPOIB_CM_SUPPORTED(dev->dev_addr) && !strcmp(buf, "connected\n")) {
462 		set_bit(IPOIB_FLAG_ADMIN_CM, &priv->flags);
463 		ipoib_warn(priv, "enabling connected mode "
464 			   "will cause multicast packet drops\n");
465 		netdev_update_features(dev);
466 		dev_set_mtu(dev, ipoib_cm_max_mtu(dev));
467 		rtnl_unlock();
468 		priv->tx_wr.wr.send_flags &= ~IB_SEND_IP_CSUM;
469 
470 		ipoib_flush_paths(dev);
471 		rtnl_lock();
472 		return 0;
473 	}
474 
475 	if (!strcmp(buf, "datagram\n")) {
476 		clear_bit(IPOIB_FLAG_ADMIN_CM, &priv->flags);
477 		netdev_update_features(dev);
478 		dev_set_mtu(dev, min(priv->mcast_mtu, dev->mtu));
479 		rtnl_unlock();
480 		ipoib_flush_paths(dev);
481 		rtnl_lock();
482 		return 0;
483 	}
484 
485 	return -EINVAL;
486 }
487 
488 static struct ipoib_path *__path_find(struct net_device *dev, void *gid)
489 {
490 	struct ipoib_dev_priv *priv = netdev_priv(dev);
491 	struct rb_node *n = priv->path_tree.rb_node;
492 	struct ipoib_path *path;
493 	int ret;
494 
495 	while (n) {
496 		path = rb_entry(n, struct ipoib_path, rb_node);
497 
498 		ret = memcmp(gid, path->pathrec.dgid.raw,
499 			     sizeof (union ib_gid));
500 
501 		if (ret < 0)
502 			n = n->rb_left;
503 		else if (ret > 0)
504 			n = n->rb_right;
505 		else
506 			return path;
507 	}
508 
509 	return NULL;
510 }
511 
512 static int __path_add(struct net_device *dev, struct ipoib_path *path)
513 {
514 	struct ipoib_dev_priv *priv = netdev_priv(dev);
515 	struct rb_node **n = &priv->path_tree.rb_node;
516 	struct rb_node *pn = NULL;
517 	struct ipoib_path *tpath;
518 	int ret;
519 
520 	while (*n) {
521 		pn = *n;
522 		tpath = rb_entry(pn, struct ipoib_path, rb_node);
523 
524 		ret = memcmp(path->pathrec.dgid.raw, tpath->pathrec.dgid.raw,
525 			     sizeof (union ib_gid));
526 		if (ret < 0)
527 			n = &pn->rb_left;
528 		else if (ret > 0)
529 			n = &pn->rb_right;
530 		else
531 			return -EEXIST;
532 	}
533 
534 	rb_link_node(&path->rb_node, pn, n);
535 	rb_insert_color(&path->rb_node, &priv->path_tree);
536 
537 	list_add_tail(&path->list, &priv->path_list);
538 
539 	return 0;
540 }
541 
542 static void path_free(struct net_device *dev, struct ipoib_path *path)
543 {
544 	struct sk_buff *skb;
545 
546 	while ((skb = __skb_dequeue(&path->queue)))
547 		dev_kfree_skb_irq(skb);
548 
549 	ipoib_dbg(netdev_priv(dev), "path_free\n");
550 
551 	/* remove all neigh connected to this path */
552 	ipoib_del_neighs_by_gid(dev, path->pathrec.dgid.raw);
553 
554 	if (path->ah)
555 		ipoib_put_ah(path->ah);
556 
557 	kfree(path);
558 }
559 
560 #ifdef CONFIG_INFINIBAND_IPOIB_DEBUG
561 
562 struct ipoib_path_iter *ipoib_path_iter_init(struct net_device *dev)
563 {
564 	struct ipoib_path_iter *iter;
565 
566 	iter = kmalloc(sizeof *iter, GFP_KERNEL);
567 	if (!iter)
568 		return NULL;
569 
570 	iter->dev = dev;
571 	memset(iter->path.pathrec.dgid.raw, 0, 16);
572 
573 	if (ipoib_path_iter_next(iter)) {
574 		kfree(iter);
575 		return NULL;
576 	}
577 
578 	return iter;
579 }
580 
581 int ipoib_path_iter_next(struct ipoib_path_iter *iter)
582 {
583 	struct ipoib_dev_priv *priv = netdev_priv(iter->dev);
584 	struct rb_node *n;
585 	struct ipoib_path *path;
586 	int ret = 1;
587 
588 	spin_lock_irq(&priv->lock);
589 
590 	n = rb_first(&priv->path_tree);
591 
592 	while (n) {
593 		path = rb_entry(n, struct ipoib_path, rb_node);
594 
595 		if (memcmp(iter->path.pathrec.dgid.raw, path->pathrec.dgid.raw,
596 			   sizeof (union ib_gid)) < 0) {
597 			iter->path = *path;
598 			ret = 0;
599 			break;
600 		}
601 
602 		n = rb_next(n);
603 	}
604 
605 	spin_unlock_irq(&priv->lock);
606 
607 	return ret;
608 }
609 
610 void ipoib_path_iter_read(struct ipoib_path_iter *iter,
611 			  struct ipoib_path *path)
612 {
613 	*path = iter->path;
614 }
615 
616 #endif /* CONFIG_INFINIBAND_IPOIB_DEBUG */
617 
618 void ipoib_mark_paths_invalid(struct net_device *dev)
619 {
620 	struct ipoib_dev_priv *priv = netdev_priv(dev);
621 	struct ipoib_path *path, *tp;
622 
623 	spin_lock_irq(&priv->lock);
624 
625 	list_for_each_entry_safe(path, tp, &priv->path_list, list) {
626 		ipoib_dbg(priv, "mark path LID 0x%04x GID %pI6 invalid\n",
627 			be16_to_cpu(path->pathrec.dlid),
628 			path->pathrec.dgid.raw);
629 		path->valid =  0;
630 	}
631 
632 	spin_unlock_irq(&priv->lock);
633 }
634 
635 struct classport_info_context {
636 	struct ipoib_dev_priv	*priv;
637 	struct completion	done;
638 	struct ib_sa_query	*sa_query;
639 };
640 
641 static void classport_info_query_cb(int status, struct ib_class_port_info *rec,
642 				    void *context)
643 {
644 	struct classport_info_context *cb_ctx = context;
645 	struct ipoib_dev_priv *priv;
646 
647 	WARN_ON(!context);
648 
649 	priv = cb_ctx->priv;
650 
651 	if (status || !rec) {
652 		pr_debug("device: %s failed query classport_info status: %d\n",
653 			 priv->dev->name, status);
654 		/* keeps the default, will try next mcast_restart */
655 		priv->sm_fullmember_sendonly_support = false;
656 		goto out;
657 	}
658 
659 	if (ib_get_cpi_capmask2(rec) &
660 	    IB_SA_CAP_MASK2_SENDONLY_FULL_MEM_SUPPORT) {
661 		pr_debug("device: %s enabled fullmember-sendonly for sendonly MCG\n",
662 			 priv->dev->name);
663 		priv->sm_fullmember_sendonly_support = true;
664 	} else {
665 		pr_debug("device: %s disabled fullmember-sendonly for sendonly MCG\n",
666 			 priv->dev->name);
667 		priv->sm_fullmember_sendonly_support = false;
668 	}
669 
670 out:
671 	complete(&cb_ctx->done);
672 }
673 
674 int ipoib_check_sm_sendonly_fullmember_support(struct ipoib_dev_priv *priv)
675 {
676 	struct classport_info_context *callback_context;
677 	int ret;
678 
679 	callback_context = kmalloc(sizeof(*callback_context), GFP_KERNEL);
680 	if (!callback_context)
681 		return -ENOMEM;
682 
683 	callback_context->priv = priv;
684 	init_completion(&callback_context->done);
685 
686 	ret = ib_sa_classport_info_rec_query(&ipoib_sa_client,
687 					     priv->ca, priv->port, 3000,
688 					     GFP_KERNEL,
689 					     classport_info_query_cb,
690 					     callback_context,
691 					     &callback_context->sa_query);
692 	if (ret < 0) {
693 		pr_info("%s failed to send ib_sa_classport_info query, ret: %d\n",
694 			priv->dev->name, ret);
695 		kfree(callback_context);
696 		return ret;
697 	}
698 
699 	/* waiting for the callback to finish before returnning */
700 	wait_for_completion(&callback_context->done);
701 	kfree(callback_context);
702 
703 	return ret;
704 }
705 
706 void ipoib_flush_paths(struct net_device *dev)
707 {
708 	struct ipoib_dev_priv *priv = netdev_priv(dev);
709 	struct ipoib_path *path, *tp;
710 	LIST_HEAD(remove_list);
711 	unsigned long flags;
712 
713 	netif_tx_lock_bh(dev);
714 	spin_lock_irqsave(&priv->lock, flags);
715 
716 	list_splice_init(&priv->path_list, &remove_list);
717 
718 	list_for_each_entry(path, &remove_list, list)
719 		rb_erase(&path->rb_node, &priv->path_tree);
720 
721 	list_for_each_entry_safe(path, tp, &remove_list, list) {
722 		if (path->query)
723 			ib_sa_cancel_query(path->query_id, path->query);
724 		spin_unlock_irqrestore(&priv->lock, flags);
725 		netif_tx_unlock_bh(dev);
726 		wait_for_completion(&path->done);
727 		path_free(dev, path);
728 		netif_tx_lock_bh(dev);
729 		spin_lock_irqsave(&priv->lock, flags);
730 	}
731 
732 	spin_unlock_irqrestore(&priv->lock, flags);
733 	netif_tx_unlock_bh(dev);
734 }
735 
736 static void path_rec_completion(int status,
737 				struct ib_sa_path_rec *pathrec,
738 				void *path_ptr)
739 {
740 	struct ipoib_path *path = path_ptr;
741 	struct net_device *dev = path->dev;
742 	struct ipoib_dev_priv *priv = netdev_priv(dev);
743 	struct ipoib_ah *ah = NULL;
744 	struct ipoib_ah *old_ah = NULL;
745 	struct ipoib_neigh *neigh, *tn;
746 	struct sk_buff_head skqueue;
747 	struct sk_buff *skb;
748 	unsigned long flags;
749 
750 	if (!status)
751 		ipoib_dbg(priv, "PathRec LID 0x%04x for GID %pI6\n",
752 			  be16_to_cpu(pathrec->dlid), pathrec->dgid.raw);
753 	else
754 		ipoib_dbg(priv, "PathRec status %d for GID %pI6\n",
755 			  status, path->pathrec.dgid.raw);
756 
757 	skb_queue_head_init(&skqueue);
758 
759 	if (!status) {
760 		struct ib_ah_attr av;
761 
762 		if (!ib_init_ah_from_path(priv->ca, priv->port, pathrec, &av))
763 			ah = ipoib_create_ah(dev, priv->pd, &av);
764 	}
765 
766 	spin_lock_irqsave(&priv->lock, flags);
767 
768 	if (!IS_ERR_OR_NULL(ah)) {
769 		path->pathrec = *pathrec;
770 
771 		old_ah   = path->ah;
772 		path->ah = ah;
773 
774 		ipoib_dbg(priv, "created address handle %p for LID 0x%04x, SL %d\n",
775 			  ah, be16_to_cpu(pathrec->dlid), pathrec->sl);
776 
777 		while ((skb = __skb_dequeue(&path->queue)))
778 			__skb_queue_tail(&skqueue, skb);
779 
780 		list_for_each_entry_safe(neigh, tn, &path->neigh_list, list) {
781 			if (neigh->ah) {
782 				WARN_ON(neigh->ah != old_ah);
783 				/*
784 				 * Dropping the ah reference inside
785 				 * priv->lock is safe here, because we
786 				 * will hold one more reference from
787 				 * the original value of path->ah (ie
788 				 * old_ah).
789 				 */
790 				ipoib_put_ah(neigh->ah);
791 			}
792 			kref_get(&path->ah->ref);
793 			neigh->ah = path->ah;
794 
795 			if (ipoib_cm_enabled(dev, neigh->daddr)) {
796 				if (!ipoib_cm_get(neigh))
797 					ipoib_cm_set(neigh, ipoib_cm_create_tx(dev,
798 									       path,
799 									       neigh));
800 				if (!ipoib_cm_get(neigh)) {
801 					ipoib_neigh_free(neigh);
802 					continue;
803 				}
804 			}
805 
806 			while ((skb = __skb_dequeue(&neigh->queue)))
807 				__skb_queue_tail(&skqueue, skb);
808 		}
809 		path->valid = 1;
810 	}
811 
812 	path->query = NULL;
813 	complete(&path->done);
814 
815 	spin_unlock_irqrestore(&priv->lock, flags);
816 
817 	if (IS_ERR_OR_NULL(ah))
818 		ipoib_del_neighs_by_gid(dev, path->pathrec.dgid.raw);
819 
820 	if (old_ah)
821 		ipoib_put_ah(old_ah);
822 
823 	while ((skb = __skb_dequeue(&skqueue))) {
824 		skb->dev = dev;
825 		if (dev_queue_xmit(skb))
826 			ipoib_warn(priv, "dev_queue_xmit failed "
827 				   "to requeue packet\n");
828 	}
829 }
830 
831 static struct ipoib_path *path_rec_create(struct net_device *dev, void *gid)
832 {
833 	struct ipoib_dev_priv *priv = netdev_priv(dev);
834 	struct ipoib_path *path;
835 
836 	if (!priv->broadcast)
837 		return NULL;
838 
839 	path = kzalloc(sizeof *path, GFP_ATOMIC);
840 	if (!path)
841 		return NULL;
842 
843 	path->dev = dev;
844 
845 	skb_queue_head_init(&path->queue);
846 
847 	INIT_LIST_HEAD(&path->neigh_list);
848 
849 	memcpy(path->pathrec.dgid.raw, gid, sizeof (union ib_gid));
850 	path->pathrec.sgid	    = priv->local_gid;
851 	path->pathrec.pkey	    = cpu_to_be16(priv->pkey);
852 	path->pathrec.numb_path     = 1;
853 	path->pathrec.traffic_class = priv->broadcast->mcmember.traffic_class;
854 
855 	return path;
856 }
857 
858 static int path_rec_start(struct net_device *dev,
859 			  struct ipoib_path *path)
860 {
861 	struct ipoib_dev_priv *priv = netdev_priv(dev);
862 
863 	ipoib_dbg(priv, "Start path record lookup for %pI6\n",
864 		  path->pathrec.dgid.raw);
865 
866 	init_completion(&path->done);
867 
868 	path->query_id =
869 		ib_sa_path_rec_get(&ipoib_sa_client, priv->ca, priv->port,
870 				   &path->pathrec,
871 				   IB_SA_PATH_REC_DGID		|
872 				   IB_SA_PATH_REC_SGID		|
873 				   IB_SA_PATH_REC_NUMB_PATH	|
874 				   IB_SA_PATH_REC_TRAFFIC_CLASS |
875 				   IB_SA_PATH_REC_PKEY,
876 				   1000, GFP_ATOMIC,
877 				   path_rec_completion,
878 				   path, &path->query);
879 	if (path->query_id < 0) {
880 		ipoib_warn(priv, "ib_sa_path_rec_get failed: %d\n", path->query_id);
881 		path->query = NULL;
882 		complete(&path->done);
883 		return path->query_id;
884 	}
885 
886 	return 0;
887 }
888 
889 static void neigh_add_path(struct sk_buff *skb, u8 *daddr,
890 			   struct net_device *dev)
891 {
892 	struct ipoib_dev_priv *priv = netdev_priv(dev);
893 	struct ipoib_path *path;
894 	struct ipoib_neigh *neigh;
895 	unsigned long flags;
896 
897 	spin_lock_irqsave(&priv->lock, flags);
898 	neigh = ipoib_neigh_alloc(daddr, dev);
899 	if (!neigh) {
900 		spin_unlock_irqrestore(&priv->lock, flags);
901 		++dev->stats.tx_dropped;
902 		dev_kfree_skb_any(skb);
903 		return;
904 	}
905 
906 	path = __path_find(dev, daddr + 4);
907 	if (!path) {
908 		path = path_rec_create(dev, daddr + 4);
909 		if (!path)
910 			goto err_path;
911 
912 		__path_add(dev, path);
913 	}
914 
915 	list_add_tail(&neigh->list, &path->neigh_list);
916 
917 	if (path->ah) {
918 		kref_get(&path->ah->ref);
919 		neigh->ah = path->ah;
920 
921 		if (ipoib_cm_enabled(dev, neigh->daddr)) {
922 			if (!ipoib_cm_get(neigh))
923 				ipoib_cm_set(neigh, ipoib_cm_create_tx(dev, path, neigh));
924 			if (!ipoib_cm_get(neigh)) {
925 				ipoib_neigh_free(neigh);
926 				goto err_drop;
927 			}
928 			if (skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE)
929 				__skb_queue_tail(&neigh->queue, skb);
930 			else {
931 				ipoib_warn(priv, "queue length limit %d. Packet drop.\n",
932 					   skb_queue_len(&neigh->queue));
933 				goto err_drop;
934 			}
935 		} else {
936 			spin_unlock_irqrestore(&priv->lock, flags);
937 			ipoib_send(dev, skb, path->ah, IPOIB_QPN(daddr));
938 			ipoib_neigh_put(neigh);
939 			return;
940 		}
941 	} else {
942 		neigh->ah  = NULL;
943 
944 		if (!path->query && path_rec_start(dev, path))
945 			goto err_path;
946 		if (skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE)
947 			__skb_queue_tail(&neigh->queue, skb);
948 		else
949 			goto err_drop;
950 	}
951 
952 	spin_unlock_irqrestore(&priv->lock, flags);
953 	ipoib_neigh_put(neigh);
954 	return;
955 
956 err_path:
957 	ipoib_neigh_free(neigh);
958 err_drop:
959 	++dev->stats.tx_dropped;
960 	dev_kfree_skb_any(skb);
961 
962 	spin_unlock_irqrestore(&priv->lock, flags);
963 	ipoib_neigh_put(neigh);
964 }
965 
966 static void unicast_arp_send(struct sk_buff *skb, struct net_device *dev,
967 			     struct ipoib_cb *cb)
968 {
969 	struct ipoib_dev_priv *priv = netdev_priv(dev);
970 	struct ipoib_path *path;
971 	unsigned long flags;
972 
973 	spin_lock_irqsave(&priv->lock, flags);
974 
975 	path = __path_find(dev, cb->hwaddr + 4);
976 	if (!path || !path->valid) {
977 		int new_path = 0;
978 
979 		if (!path) {
980 			path = path_rec_create(dev, cb->hwaddr + 4);
981 			new_path = 1;
982 		}
983 		if (path) {
984 			if (skb_queue_len(&path->queue) < IPOIB_MAX_PATH_REC_QUEUE) {
985 				__skb_queue_tail(&path->queue, skb);
986 			} else {
987 				++dev->stats.tx_dropped;
988 				dev_kfree_skb_any(skb);
989 			}
990 
991 			if (!path->query && path_rec_start(dev, path)) {
992 				spin_unlock_irqrestore(&priv->lock, flags);
993 				if (new_path)
994 					path_free(dev, path);
995 				return;
996 			} else
997 				__path_add(dev, path);
998 		} else {
999 			++dev->stats.tx_dropped;
1000 			dev_kfree_skb_any(skb);
1001 		}
1002 
1003 		spin_unlock_irqrestore(&priv->lock, flags);
1004 		return;
1005 	}
1006 
1007 	if (path->ah) {
1008 		ipoib_dbg(priv, "Send unicast ARP to %04x\n",
1009 			  be16_to_cpu(path->pathrec.dlid));
1010 
1011 		spin_unlock_irqrestore(&priv->lock, flags);
1012 		ipoib_send(dev, skb, path->ah, IPOIB_QPN(cb->hwaddr));
1013 		return;
1014 	} else if ((path->query || !path_rec_start(dev, path)) &&
1015 		   skb_queue_len(&path->queue) < IPOIB_MAX_PATH_REC_QUEUE) {
1016 		__skb_queue_tail(&path->queue, skb);
1017 	} else {
1018 		++dev->stats.tx_dropped;
1019 		dev_kfree_skb_any(skb);
1020 	}
1021 
1022 	spin_unlock_irqrestore(&priv->lock, flags);
1023 }
1024 
1025 static int ipoib_start_xmit(struct sk_buff *skb, struct net_device *dev)
1026 {
1027 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1028 	struct ipoib_neigh *neigh;
1029 	struct ipoib_cb *cb = ipoib_skb_cb(skb);
1030 	struct ipoib_header *header;
1031 	unsigned long flags;
1032 
1033 	header = (struct ipoib_header *) skb->data;
1034 
1035 	if (unlikely(cb->hwaddr[4] == 0xff)) {
1036 		/* multicast, arrange "if" according to probability */
1037 		if ((header->proto != htons(ETH_P_IP)) &&
1038 		    (header->proto != htons(ETH_P_IPV6)) &&
1039 		    (header->proto != htons(ETH_P_ARP)) &&
1040 		    (header->proto != htons(ETH_P_RARP)) &&
1041 		    (header->proto != htons(ETH_P_TIPC))) {
1042 			/* ethertype not supported by IPoIB */
1043 			++dev->stats.tx_dropped;
1044 			dev_kfree_skb_any(skb);
1045 			return NETDEV_TX_OK;
1046 		}
1047 		/* Add in the P_Key for multicast*/
1048 		cb->hwaddr[8] = (priv->pkey >> 8) & 0xff;
1049 		cb->hwaddr[9] = priv->pkey & 0xff;
1050 
1051 		neigh = ipoib_neigh_get(dev, cb->hwaddr);
1052 		if (likely(neigh))
1053 			goto send_using_neigh;
1054 		ipoib_mcast_send(dev, cb->hwaddr, skb);
1055 		return NETDEV_TX_OK;
1056 	}
1057 
1058 	/* unicast, arrange "switch" according to probability */
1059 	switch (header->proto) {
1060 	case htons(ETH_P_IP):
1061 	case htons(ETH_P_IPV6):
1062 	case htons(ETH_P_TIPC):
1063 		neigh = ipoib_neigh_get(dev, cb->hwaddr);
1064 		if (unlikely(!neigh)) {
1065 			neigh_add_path(skb, cb->hwaddr, dev);
1066 			return NETDEV_TX_OK;
1067 		}
1068 		break;
1069 	case htons(ETH_P_ARP):
1070 	case htons(ETH_P_RARP):
1071 		/* for unicast ARP and RARP should always perform path find */
1072 		unicast_arp_send(skb, dev, cb);
1073 		return NETDEV_TX_OK;
1074 	default:
1075 		/* ethertype not supported by IPoIB */
1076 		++dev->stats.tx_dropped;
1077 		dev_kfree_skb_any(skb);
1078 		return NETDEV_TX_OK;
1079 	}
1080 
1081 send_using_neigh:
1082 	/* note we now hold a ref to neigh */
1083 	if (ipoib_cm_get(neigh)) {
1084 		if (ipoib_cm_up(neigh)) {
1085 			ipoib_cm_send(dev, skb, ipoib_cm_get(neigh));
1086 			goto unref;
1087 		}
1088 	} else if (neigh->ah) {
1089 		ipoib_send(dev, skb, neigh->ah, IPOIB_QPN(cb->hwaddr));
1090 		goto unref;
1091 	}
1092 
1093 	if (skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE) {
1094 		spin_lock_irqsave(&priv->lock, flags);
1095 		__skb_queue_tail(&neigh->queue, skb);
1096 		spin_unlock_irqrestore(&priv->lock, flags);
1097 	} else {
1098 		++dev->stats.tx_dropped;
1099 		dev_kfree_skb_any(skb);
1100 	}
1101 
1102 unref:
1103 	ipoib_neigh_put(neigh);
1104 
1105 	return NETDEV_TX_OK;
1106 }
1107 
1108 static void ipoib_timeout(struct net_device *dev)
1109 {
1110 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1111 
1112 	ipoib_warn(priv, "transmit timeout: latency %d msecs\n",
1113 		   jiffies_to_msecs(jiffies - dev_trans_start(dev)));
1114 	ipoib_warn(priv, "queue stopped %d, tx_head %u, tx_tail %u\n",
1115 		   netif_queue_stopped(dev),
1116 		   priv->tx_head, priv->tx_tail);
1117 	/* XXX reset QP, etc. */
1118 }
1119 
1120 static int ipoib_hard_header(struct sk_buff *skb,
1121 			     struct net_device *dev,
1122 			     unsigned short type,
1123 			     const void *daddr, const void *saddr, unsigned len)
1124 {
1125 	struct ipoib_header *header;
1126 	struct ipoib_cb *cb = ipoib_skb_cb(skb);
1127 
1128 	header = (struct ipoib_header *) skb_push(skb, sizeof *header);
1129 
1130 	header->proto = htons(type);
1131 	header->reserved = 0;
1132 
1133 	/*
1134 	 * we don't rely on dst_entry structure,  always stuff the
1135 	 * destination address into skb->cb so we can figure out where
1136 	 * to send the packet later.
1137 	 */
1138 	memcpy(cb->hwaddr, daddr, INFINIBAND_ALEN);
1139 
1140 	return sizeof *header;
1141 }
1142 
1143 static void ipoib_set_mcast_list(struct net_device *dev)
1144 {
1145 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1146 
1147 	if (!test_bit(IPOIB_FLAG_OPER_UP, &priv->flags)) {
1148 		ipoib_dbg(priv, "IPOIB_FLAG_OPER_UP not set");
1149 		return;
1150 	}
1151 
1152 	queue_work(priv->wq, &priv->restart_task);
1153 }
1154 
1155 static int ipoib_get_iflink(const struct net_device *dev)
1156 {
1157 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1158 
1159 	/* parent interface */
1160 	if (!test_bit(IPOIB_FLAG_SUBINTERFACE, &priv->flags))
1161 		return dev->ifindex;
1162 
1163 	/* child/vlan interface */
1164 	return priv->parent->ifindex;
1165 }
1166 
1167 static u32 ipoib_addr_hash(struct ipoib_neigh_hash *htbl, u8 *daddr)
1168 {
1169 	/*
1170 	 * Use only the address parts that contributes to spreading
1171 	 * The subnet prefix is not used as one can not connect to
1172 	 * same remote port (GUID) using the same remote QPN via two
1173 	 * different subnets.
1174 	 */
1175 	 /* qpn octets[1:4) & port GUID octets[12:20) */
1176 	u32 *d32 = (u32 *) daddr;
1177 	u32 hv;
1178 
1179 	hv = jhash_3words(d32[3], d32[4], IPOIB_QPN_MASK & d32[0], 0);
1180 	return hv & htbl->mask;
1181 }
1182 
1183 struct ipoib_neigh *ipoib_neigh_get(struct net_device *dev, u8 *daddr)
1184 {
1185 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1186 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1187 	struct ipoib_neigh_hash *htbl;
1188 	struct ipoib_neigh *neigh = NULL;
1189 	u32 hash_val;
1190 
1191 	rcu_read_lock_bh();
1192 
1193 	htbl = rcu_dereference_bh(ntbl->htbl);
1194 
1195 	if (!htbl)
1196 		goto out_unlock;
1197 
1198 	hash_val = ipoib_addr_hash(htbl, daddr);
1199 	for (neigh = rcu_dereference_bh(htbl->buckets[hash_val]);
1200 	     neigh != NULL;
1201 	     neigh = rcu_dereference_bh(neigh->hnext)) {
1202 		if (memcmp(daddr, neigh->daddr, INFINIBAND_ALEN) == 0) {
1203 			/* found, take one ref on behalf of the caller */
1204 			if (!atomic_inc_not_zero(&neigh->refcnt)) {
1205 				/* deleted */
1206 				neigh = NULL;
1207 				goto out_unlock;
1208 			}
1209 
1210 			if (likely(skb_queue_len(&neigh->queue) < IPOIB_MAX_PATH_REC_QUEUE))
1211 				neigh->alive = jiffies;
1212 			goto out_unlock;
1213 		}
1214 	}
1215 
1216 out_unlock:
1217 	rcu_read_unlock_bh();
1218 	return neigh;
1219 }
1220 
1221 static void __ipoib_reap_neigh(struct ipoib_dev_priv *priv)
1222 {
1223 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1224 	struct ipoib_neigh_hash *htbl;
1225 	unsigned long neigh_obsolete;
1226 	unsigned long dt;
1227 	unsigned long flags;
1228 	int i;
1229 	LIST_HEAD(remove_list);
1230 
1231 	if (test_bit(IPOIB_STOP_NEIGH_GC, &priv->flags))
1232 		return;
1233 
1234 	spin_lock_irqsave(&priv->lock, flags);
1235 
1236 	htbl = rcu_dereference_protected(ntbl->htbl,
1237 					 lockdep_is_held(&priv->lock));
1238 
1239 	if (!htbl)
1240 		goto out_unlock;
1241 
1242 	/* neigh is obsolete if it was idle for two GC periods */
1243 	dt = 2 * arp_tbl.gc_interval;
1244 	neigh_obsolete = jiffies - dt;
1245 	/* handle possible race condition */
1246 	if (test_bit(IPOIB_STOP_NEIGH_GC, &priv->flags))
1247 		goto out_unlock;
1248 
1249 	for (i = 0; i < htbl->size; i++) {
1250 		struct ipoib_neigh *neigh;
1251 		struct ipoib_neigh __rcu **np = &htbl->buckets[i];
1252 
1253 		while ((neigh = rcu_dereference_protected(*np,
1254 							  lockdep_is_held(&priv->lock))) != NULL) {
1255 			/* was the neigh idle for two GC periods */
1256 			if (time_after(neigh_obsolete, neigh->alive)) {
1257 
1258 				ipoib_check_and_add_mcast_sendonly(priv, neigh->daddr + 4, &remove_list);
1259 
1260 				rcu_assign_pointer(*np,
1261 						   rcu_dereference_protected(neigh->hnext,
1262 									     lockdep_is_held(&priv->lock)));
1263 				/* remove from path/mc list */
1264 				list_del(&neigh->list);
1265 				call_rcu(&neigh->rcu, ipoib_neigh_reclaim);
1266 			} else {
1267 				np = &neigh->hnext;
1268 			}
1269 
1270 		}
1271 	}
1272 
1273 out_unlock:
1274 	spin_unlock_irqrestore(&priv->lock, flags);
1275 	ipoib_mcast_remove_list(&remove_list);
1276 }
1277 
1278 static void ipoib_reap_neigh(struct work_struct *work)
1279 {
1280 	struct ipoib_dev_priv *priv =
1281 		container_of(work, struct ipoib_dev_priv, neigh_reap_task.work);
1282 
1283 	__ipoib_reap_neigh(priv);
1284 
1285 	if (!test_bit(IPOIB_STOP_NEIGH_GC, &priv->flags))
1286 		queue_delayed_work(priv->wq, &priv->neigh_reap_task,
1287 				   arp_tbl.gc_interval);
1288 }
1289 
1290 
1291 static struct ipoib_neigh *ipoib_neigh_ctor(u8 *daddr,
1292 				      struct net_device *dev)
1293 {
1294 	struct ipoib_neigh *neigh;
1295 
1296 	neigh = kzalloc(sizeof *neigh, GFP_ATOMIC);
1297 	if (!neigh)
1298 		return NULL;
1299 
1300 	neigh->dev = dev;
1301 	memcpy(&neigh->daddr, daddr, sizeof(neigh->daddr));
1302 	skb_queue_head_init(&neigh->queue);
1303 	INIT_LIST_HEAD(&neigh->list);
1304 	ipoib_cm_set(neigh, NULL);
1305 	/* one ref on behalf of the caller */
1306 	atomic_set(&neigh->refcnt, 1);
1307 
1308 	return neigh;
1309 }
1310 
1311 struct ipoib_neigh *ipoib_neigh_alloc(u8 *daddr,
1312 				      struct net_device *dev)
1313 {
1314 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1315 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1316 	struct ipoib_neigh_hash *htbl;
1317 	struct ipoib_neigh *neigh;
1318 	u32 hash_val;
1319 
1320 	htbl = rcu_dereference_protected(ntbl->htbl,
1321 					 lockdep_is_held(&priv->lock));
1322 	if (!htbl) {
1323 		neigh = NULL;
1324 		goto out_unlock;
1325 	}
1326 
1327 	/* need to add a new neigh, but maybe some other thread succeeded?
1328 	 * recalc hash, maybe hash resize took place so we do a search
1329 	 */
1330 	hash_val = ipoib_addr_hash(htbl, daddr);
1331 	for (neigh = rcu_dereference_protected(htbl->buckets[hash_val],
1332 					       lockdep_is_held(&priv->lock));
1333 	     neigh != NULL;
1334 	     neigh = rcu_dereference_protected(neigh->hnext,
1335 					       lockdep_is_held(&priv->lock))) {
1336 		if (memcmp(daddr, neigh->daddr, INFINIBAND_ALEN) == 0) {
1337 			/* found, take one ref on behalf of the caller */
1338 			if (!atomic_inc_not_zero(&neigh->refcnt)) {
1339 				/* deleted */
1340 				neigh = NULL;
1341 				break;
1342 			}
1343 			neigh->alive = jiffies;
1344 			goto out_unlock;
1345 		}
1346 	}
1347 
1348 	neigh = ipoib_neigh_ctor(daddr, dev);
1349 	if (!neigh)
1350 		goto out_unlock;
1351 
1352 	/* one ref on behalf of the hash table */
1353 	atomic_inc(&neigh->refcnt);
1354 	neigh->alive = jiffies;
1355 	/* put in hash */
1356 	rcu_assign_pointer(neigh->hnext,
1357 			   rcu_dereference_protected(htbl->buckets[hash_val],
1358 						     lockdep_is_held(&priv->lock)));
1359 	rcu_assign_pointer(htbl->buckets[hash_val], neigh);
1360 	atomic_inc(&ntbl->entries);
1361 
1362 out_unlock:
1363 
1364 	return neigh;
1365 }
1366 
1367 void ipoib_neigh_dtor(struct ipoib_neigh *neigh)
1368 {
1369 	/* neigh reference count was dropprd to zero */
1370 	struct net_device *dev = neigh->dev;
1371 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1372 	struct sk_buff *skb;
1373 	if (neigh->ah)
1374 		ipoib_put_ah(neigh->ah);
1375 	while ((skb = __skb_dequeue(&neigh->queue))) {
1376 		++dev->stats.tx_dropped;
1377 		dev_kfree_skb_any(skb);
1378 	}
1379 	if (ipoib_cm_get(neigh))
1380 		ipoib_cm_destroy_tx(ipoib_cm_get(neigh));
1381 	ipoib_dbg(netdev_priv(dev),
1382 		  "neigh free for %06x %pI6\n",
1383 		  IPOIB_QPN(neigh->daddr),
1384 		  neigh->daddr + 4);
1385 	kfree(neigh);
1386 	if (atomic_dec_and_test(&priv->ntbl.entries)) {
1387 		if (test_bit(IPOIB_NEIGH_TBL_FLUSH, &priv->flags))
1388 			complete(&priv->ntbl.flushed);
1389 	}
1390 }
1391 
1392 static void ipoib_neigh_reclaim(struct rcu_head *rp)
1393 {
1394 	/* Called as a result of removal from hash table */
1395 	struct ipoib_neigh *neigh = container_of(rp, struct ipoib_neigh, rcu);
1396 	/* note TX context may hold another ref */
1397 	ipoib_neigh_put(neigh);
1398 }
1399 
1400 void ipoib_neigh_free(struct ipoib_neigh *neigh)
1401 {
1402 	struct net_device *dev = neigh->dev;
1403 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1404 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1405 	struct ipoib_neigh_hash *htbl;
1406 	struct ipoib_neigh __rcu **np;
1407 	struct ipoib_neigh *n;
1408 	u32 hash_val;
1409 
1410 	htbl = rcu_dereference_protected(ntbl->htbl,
1411 					lockdep_is_held(&priv->lock));
1412 	if (!htbl)
1413 		return;
1414 
1415 	hash_val = ipoib_addr_hash(htbl, neigh->daddr);
1416 	np = &htbl->buckets[hash_val];
1417 	for (n = rcu_dereference_protected(*np,
1418 					    lockdep_is_held(&priv->lock));
1419 	     n != NULL;
1420 	     n = rcu_dereference_protected(*np,
1421 					lockdep_is_held(&priv->lock))) {
1422 		if (n == neigh) {
1423 			/* found */
1424 			rcu_assign_pointer(*np,
1425 					   rcu_dereference_protected(neigh->hnext,
1426 								     lockdep_is_held(&priv->lock)));
1427 			/* remove from parent list */
1428 			list_del(&neigh->list);
1429 			call_rcu(&neigh->rcu, ipoib_neigh_reclaim);
1430 			return;
1431 		} else {
1432 			np = &n->hnext;
1433 		}
1434 	}
1435 }
1436 
1437 static int ipoib_neigh_hash_init(struct ipoib_dev_priv *priv)
1438 {
1439 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1440 	struct ipoib_neigh_hash *htbl;
1441 	struct ipoib_neigh __rcu **buckets;
1442 	u32 size;
1443 
1444 	clear_bit(IPOIB_NEIGH_TBL_FLUSH, &priv->flags);
1445 	ntbl->htbl = NULL;
1446 	htbl = kzalloc(sizeof(*htbl), GFP_KERNEL);
1447 	if (!htbl)
1448 		return -ENOMEM;
1449 	set_bit(IPOIB_STOP_NEIGH_GC, &priv->flags);
1450 	size = roundup_pow_of_two(arp_tbl.gc_thresh3);
1451 	buckets = kzalloc(size * sizeof(*buckets), GFP_KERNEL);
1452 	if (!buckets) {
1453 		kfree(htbl);
1454 		return -ENOMEM;
1455 	}
1456 	htbl->size = size;
1457 	htbl->mask = (size - 1);
1458 	htbl->buckets = buckets;
1459 	RCU_INIT_POINTER(ntbl->htbl, htbl);
1460 	htbl->ntbl = ntbl;
1461 	atomic_set(&ntbl->entries, 0);
1462 
1463 	/* start garbage collection */
1464 	clear_bit(IPOIB_STOP_NEIGH_GC, &priv->flags);
1465 	queue_delayed_work(priv->wq, &priv->neigh_reap_task,
1466 			   arp_tbl.gc_interval);
1467 
1468 	return 0;
1469 }
1470 
1471 static void neigh_hash_free_rcu(struct rcu_head *head)
1472 {
1473 	struct ipoib_neigh_hash *htbl = container_of(head,
1474 						    struct ipoib_neigh_hash,
1475 						    rcu);
1476 	struct ipoib_neigh __rcu **buckets = htbl->buckets;
1477 	struct ipoib_neigh_table *ntbl = htbl->ntbl;
1478 
1479 	kfree(buckets);
1480 	kfree(htbl);
1481 	complete(&ntbl->deleted);
1482 }
1483 
1484 void ipoib_del_neighs_by_gid(struct net_device *dev, u8 *gid)
1485 {
1486 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1487 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1488 	struct ipoib_neigh_hash *htbl;
1489 	unsigned long flags;
1490 	int i;
1491 
1492 	/* remove all neigh connected to a given path or mcast */
1493 	spin_lock_irqsave(&priv->lock, flags);
1494 
1495 	htbl = rcu_dereference_protected(ntbl->htbl,
1496 					 lockdep_is_held(&priv->lock));
1497 
1498 	if (!htbl)
1499 		goto out_unlock;
1500 
1501 	for (i = 0; i < htbl->size; i++) {
1502 		struct ipoib_neigh *neigh;
1503 		struct ipoib_neigh __rcu **np = &htbl->buckets[i];
1504 
1505 		while ((neigh = rcu_dereference_protected(*np,
1506 							  lockdep_is_held(&priv->lock))) != NULL) {
1507 			/* delete neighs belong to this parent */
1508 			if (!memcmp(gid, neigh->daddr + 4, sizeof (union ib_gid))) {
1509 				rcu_assign_pointer(*np,
1510 						   rcu_dereference_protected(neigh->hnext,
1511 									     lockdep_is_held(&priv->lock)));
1512 				/* remove from parent list */
1513 				list_del(&neigh->list);
1514 				call_rcu(&neigh->rcu, ipoib_neigh_reclaim);
1515 			} else {
1516 				np = &neigh->hnext;
1517 			}
1518 
1519 		}
1520 	}
1521 out_unlock:
1522 	spin_unlock_irqrestore(&priv->lock, flags);
1523 }
1524 
1525 static void ipoib_flush_neighs(struct ipoib_dev_priv *priv)
1526 {
1527 	struct ipoib_neigh_table *ntbl = &priv->ntbl;
1528 	struct ipoib_neigh_hash *htbl;
1529 	unsigned long flags;
1530 	int i, wait_flushed = 0;
1531 
1532 	init_completion(&priv->ntbl.flushed);
1533 
1534 	spin_lock_irqsave(&priv->lock, flags);
1535 
1536 	htbl = rcu_dereference_protected(ntbl->htbl,
1537 					lockdep_is_held(&priv->lock));
1538 	if (!htbl)
1539 		goto out_unlock;
1540 
1541 	wait_flushed = atomic_read(&priv->ntbl.entries);
1542 	if (!wait_flushed)
1543 		goto free_htbl;
1544 
1545 	for (i = 0; i < htbl->size; i++) {
1546 		struct ipoib_neigh *neigh;
1547 		struct ipoib_neigh __rcu **np = &htbl->buckets[i];
1548 
1549 		while ((neigh = rcu_dereference_protected(*np,
1550 				       lockdep_is_held(&priv->lock))) != NULL) {
1551 			rcu_assign_pointer(*np,
1552 					   rcu_dereference_protected(neigh->hnext,
1553 								     lockdep_is_held(&priv->lock)));
1554 			/* remove from path/mc list */
1555 			list_del(&neigh->list);
1556 			call_rcu(&neigh->rcu, ipoib_neigh_reclaim);
1557 		}
1558 	}
1559 
1560 free_htbl:
1561 	rcu_assign_pointer(ntbl->htbl, NULL);
1562 	call_rcu(&htbl->rcu, neigh_hash_free_rcu);
1563 
1564 out_unlock:
1565 	spin_unlock_irqrestore(&priv->lock, flags);
1566 	if (wait_flushed)
1567 		wait_for_completion(&priv->ntbl.flushed);
1568 }
1569 
1570 static void ipoib_neigh_hash_uninit(struct net_device *dev)
1571 {
1572 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1573 	int stopped;
1574 
1575 	ipoib_dbg(priv, "ipoib_neigh_hash_uninit\n");
1576 	init_completion(&priv->ntbl.deleted);
1577 	set_bit(IPOIB_NEIGH_TBL_FLUSH, &priv->flags);
1578 
1579 	/* Stop GC if called at init fail need to cancel work */
1580 	stopped = test_and_set_bit(IPOIB_STOP_NEIGH_GC, &priv->flags);
1581 	if (!stopped)
1582 		cancel_delayed_work(&priv->neigh_reap_task);
1583 
1584 	ipoib_flush_neighs(priv);
1585 
1586 	wait_for_completion(&priv->ntbl.deleted);
1587 }
1588 
1589 
1590 int ipoib_dev_init(struct net_device *dev, struct ib_device *ca, int port)
1591 {
1592 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1593 
1594 	/* Allocate RX/TX "rings" to hold queued skbs */
1595 	priv->rx_ring =	kzalloc(ipoib_recvq_size * sizeof *priv->rx_ring,
1596 				GFP_KERNEL);
1597 	if (!priv->rx_ring) {
1598 		printk(KERN_WARNING "%s: failed to allocate RX ring (%d entries)\n",
1599 		       ca->name, ipoib_recvq_size);
1600 		goto out;
1601 	}
1602 
1603 	priv->tx_ring = vzalloc(ipoib_sendq_size * sizeof *priv->tx_ring);
1604 	if (!priv->tx_ring) {
1605 		printk(KERN_WARNING "%s: failed to allocate TX ring (%d entries)\n",
1606 		       ca->name, ipoib_sendq_size);
1607 		goto out_rx_ring_cleanup;
1608 	}
1609 
1610 	/* priv->tx_head, tx_tail & tx_outstanding are already 0 */
1611 
1612 	if (ipoib_ib_dev_init(dev, ca, port))
1613 		goto out_tx_ring_cleanup;
1614 
1615 	/*
1616 	 * Must be after ipoib_ib_dev_init so we can allocate a per
1617 	 * device wq there and use it here
1618 	 */
1619 	if (ipoib_neigh_hash_init(priv) < 0)
1620 		goto out_dev_uninit;
1621 
1622 	return 0;
1623 
1624 out_dev_uninit:
1625 	ipoib_ib_dev_cleanup(dev);
1626 
1627 out_tx_ring_cleanup:
1628 	vfree(priv->tx_ring);
1629 
1630 out_rx_ring_cleanup:
1631 	kfree(priv->rx_ring);
1632 
1633 out:
1634 	return -ENOMEM;
1635 }
1636 
1637 void ipoib_dev_cleanup(struct net_device *dev)
1638 {
1639 	struct ipoib_dev_priv *priv = netdev_priv(dev), *cpriv, *tcpriv;
1640 	LIST_HEAD(head);
1641 
1642 	ASSERT_RTNL();
1643 
1644 	ipoib_delete_debug_files(dev);
1645 
1646 	/* Delete any child interfaces first */
1647 	list_for_each_entry_safe(cpriv, tcpriv, &priv->child_intfs, list) {
1648 		/* Stop GC on child */
1649 		set_bit(IPOIB_STOP_NEIGH_GC, &cpriv->flags);
1650 		cancel_delayed_work(&cpriv->neigh_reap_task);
1651 		unregister_netdevice_queue(cpriv->dev, &head);
1652 	}
1653 	unregister_netdevice_many(&head);
1654 
1655 	/*
1656 	 * Must be before ipoib_ib_dev_cleanup or we delete an in use
1657 	 * work queue
1658 	 */
1659 	ipoib_neigh_hash_uninit(dev);
1660 
1661 	ipoib_ib_dev_cleanup(dev);
1662 
1663 	kfree(priv->rx_ring);
1664 	vfree(priv->tx_ring);
1665 
1666 	priv->rx_ring = NULL;
1667 	priv->tx_ring = NULL;
1668 }
1669 
1670 static int ipoib_set_vf_link_state(struct net_device *dev, int vf, int link_state)
1671 {
1672 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1673 
1674 	return ib_set_vf_link_state(priv->ca, vf, priv->port, link_state);
1675 }
1676 
1677 static int ipoib_get_vf_config(struct net_device *dev, int vf,
1678 			       struct ifla_vf_info *ivf)
1679 {
1680 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1681 	int err;
1682 
1683 	err = ib_get_vf_config(priv->ca, vf, priv->port, ivf);
1684 	if (err)
1685 		return err;
1686 
1687 	ivf->vf = vf;
1688 
1689 	return 0;
1690 }
1691 
1692 static int ipoib_set_vf_guid(struct net_device *dev, int vf, u64 guid, int type)
1693 {
1694 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1695 
1696 	if (type != IFLA_VF_IB_NODE_GUID && type != IFLA_VF_IB_PORT_GUID)
1697 		return -EINVAL;
1698 
1699 	return ib_set_vf_guid(priv->ca, vf, priv->port, guid, type);
1700 }
1701 
1702 static int ipoib_get_vf_stats(struct net_device *dev, int vf,
1703 			      struct ifla_vf_stats *vf_stats)
1704 {
1705 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1706 
1707 	return ib_get_vf_stats(priv->ca, vf, priv->port, vf_stats);
1708 }
1709 
1710 static const struct header_ops ipoib_header_ops = {
1711 	.create	= ipoib_hard_header,
1712 };
1713 
1714 static const struct net_device_ops ipoib_netdev_ops_pf = {
1715 	.ndo_uninit		 = ipoib_uninit,
1716 	.ndo_open		 = ipoib_open,
1717 	.ndo_stop		 = ipoib_stop,
1718 	.ndo_change_mtu		 = ipoib_change_mtu,
1719 	.ndo_fix_features	 = ipoib_fix_features,
1720 	.ndo_start_xmit		 = ipoib_start_xmit,
1721 	.ndo_tx_timeout		 = ipoib_timeout,
1722 	.ndo_set_rx_mode	 = ipoib_set_mcast_list,
1723 	.ndo_get_iflink		 = ipoib_get_iflink,
1724 	.ndo_set_vf_link_state	 = ipoib_set_vf_link_state,
1725 	.ndo_get_vf_config	 = ipoib_get_vf_config,
1726 	.ndo_get_vf_stats	 = ipoib_get_vf_stats,
1727 	.ndo_set_vf_guid	 = ipoib_set_vf_guid,
1728 	.ndo_set_mac_address	 = ipoib_set_mac,
1729 };
1730 
1731 static const struct net_device_ops ipoib_netdev_ops_vf = {
1732 	.ndo_uninit		 = ipoib_uninit,
1733 	.ndo_open		 = ipoib_open,
1734 	.ndo_stop		 = ipoib_stop,
1735 	.ndo_change_mtu		 = ipoib_change_mtu,
1736 	.ndo_fix_features	 = ipoib_fix_features,
1737 	.ndo_start_xmit	 	 = ipoib_start_xmit,
1738 	.ndo_tx_timeout		 = ipoib_timeout,
1739 	.ndo_set_rx_mode	 = ipoib_set_mcast_list,
1740 	.ndo_get_iflink		 = ipoib_get_iflink,
1741 };
1742 
1743 void ipoib_setup(struct net_device *dev)
1744 {
1745 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1746 
1747 	if (priv->hca_caps & IB_DEVICE_VIRTUAL_FUNCTION)
1748 		dev->netdev_ops	= &ipoib_netdev_ops_vf;
1749 	else
1750 		dev->netdev_ops	= &ipoib_netdev_ops_pf;
1751 
1752 	dev->header_ops		 = &ipoib_header_ops;
1753 
1754 	ipoib_set_ethtool_ops(dev);
1755 
1756 	netif_napi_add(dev, &priv->napi, ipoib_poll, NAPI_POLL_WEIGHT);
1757 
1758 	dev->watchdog_timeo	 = HZ;
1759 
1760 	dev->flags		|= IFF_BROADCAST | IFF_MULTICAST;
1761 
1762 	dev->hard_header_len	 = IPOIB_ENCAP_LEN;
1763 	dev->addr_len		 = INFINIBAND_ALEN;
1764 	dev->type		 = ARPHRD_INFINIBAND;
1765 	dev->tx_queue_len	 = ipoib_sendq_size * 2;
1766 	dev->features		 = (NETIF_F_VLAN_CHALLENGED	|
1767 				    NETIF_F_HIGHDMA);
1768 	netif_keep_dst(dev);
1769 
1770 	memcpy(dev->broadcast, ipv4_bcast_addr, INFINIBAND_ALEN);
1771 
1772 	priv->dev = dev;
1773 
1774 	spin_lock_init(&priv->lock);
1775 
1776 	init_rwsem(&priv->vlan_rwsem);
1777 
1778 	INIT_LIST_HEAD(&priv->path_list);
1779 	INIT_LIST_HEAD(&priv->child_intfs);
1780 	INIT_LIST_HEAD(&priv->dead_ahs);
1781 	INIT_LIST_HEAD(&priv->multicast_list);
1782 
1783 	INIT_DELAYED_WORK(&priv->mcast_task,   ipoib_mcast_join_task);
1784 	INIT_WORK(&priv->carrier_on_task, ipoib_mcast_carrier_on_task);
1785 	INIT_WORK(&priv->flush_light,   ipoib_ib_dev_flush_light);
1786 	INIT_WORK(&priv->flush_normal,   ipoib_ib_dev_flush_normal);
1787 	INIT_WORK(&priv->flush_heavy,   ipoib_ib_dev_flush_heavy);
1788 	INIT_WORK(&priv->restart_task, ipoib_mcast_restart_task);
1789 	INIT_DELAYED_WORK(&priv->ah_reap_task, ipoib_reap_ah);
1790 	INIT_DELAYED_WORK(&priv->neigh_reap_task, ipoib_reap_neigh);
1791 }
1792 
1793 struct ipoib_dev_priv *ipoib_intf_alloc(const char *name)
1794 {
1795 	struct net_device *dev;
1796 
1797 	dev = alloc_netdev((int)sizeof(struct ipoib_dev_priv), name,
1798 			   NET_NAME_UNKNOWN, ipoib_setup);
1799 	if (!dev)
1800 		return NULL;
1801 
1802 	return netdev_priv(dev);
1803 }
1804 
1805 static ssize_t show_pkey(struct device *dev,
1806 			 struct device_attribute *attr, char *buf)
1807 {
1808 	struct ipoib_dev_priv *priv = netdev_priv(to_net_dev(dev));
1809 
1810 	return sprintf(buf, "0x%04x\n", priv->pkey);
1811 }
1812 static DEVICE_ATTR(pkey, S_IRUGO, show_pkey, NULL);
1813 
1814 static ssize_t show_umcast(struct device *dev,
1815 			   struct device_attribute *attr, char *buf)
1816 {
1817 	struct ipoib_dev_priv *priv = netdev_priv(to_net_dev(dev));
1818 
1819 	return sprintf(buf, "%d\n", test_bit(IPOIB_FLAG_UMCAST, &priv->flags));
1820 }
1821 
1822 void ipoib_set_umcast(struct net_device *ndev, int umcast_val)
1823 {
1824 	struct ipoib_dev_priv *priv = netdev_priv(ndev);
1825 
1826 	if (umcast_val > 0) {
1827 		set_bit(IPOIB_FLAG_UMCAST, &priv->flags);
1828 		ipoib_warn(priv, "ignoring multicast groups joined directly "
1829 				"by userspace\n");
1830 	} else
1831 		clear_bit(IPOIB_FLAG_UMCAST, &priv->flags);
1832 }
1833 
1834 static ssize_t set_umcast(struct device *dev,
1835 			  struct device_attribute *attr,
1836 			  const char *buf, size_t count)
1837 {
1838 	unsigned long umcast_val = simple_strtoul(buf, NULL, 0);
1839 
1840 	ipoib_set_umcast(to_net_dev(dev), umcast_val);
1841 
1842 	return count;
1843 }
1844 static DEVICE_ATTR(umcast, S_IWUSR | S_IRUGO, show_umcast, set_umcast);
1845 
1846 int ipoib_add_umcast_attr(struct net_device *dev)
1847 {
1848 	return device_create_file(&dev->dev, &dev_attr_umcast);
1849 }
1850 
1851 static void set_base_guid(struct ipoib_dev_priv *priv, union ib_gid *gid)
1852 {
1853 	struct ipoib_dev_priv *child_priv;
1854 	struct net_device *netdev = priv->dev;
1855 
1856 	netif_addr_lock_bh(netdev);
1857 
1858 	memcpy(&priv->local_gid.global.interface_id,
1859 	       &gid->global.interface_id,
1860 	       sizeof(gid->global.interface_id));
1861 	memcpy(netdev->dev_addr + 4, &priv->local_gid, sizeof(priv->local_gid));
1862 	clear_bit(IPOIB_FLAG_DEV_ADDR_SET, &priv->flags);
1863 
1864 	netif_addr_unlock_bh(netdev);
1865 
1866 	if (!test_bit(IPOIB_FLAG_SUBINTERFACE, &priv->flags)) {
1867 		down_read(&priv->vlan_rwsem);
1868 		list_for_each_entry(child_priv, &priv->child_intfs, list)
1869 			set_base_guid(child_priv, gid);
1870 		up_read(&priv->vlan_rwsem);
1871 	}
1872 }
1873 
1874 static int ipoib_check_lladdr(struct net_device *dev,
1875 			      struct sockaddr_storage *ss)
1876 {
1877 	union ib_gid *gid = (union ib_gid *)(ss->__data + 4);
1878 	int ret = 0;
1879 
1880 	netif_addr_lock_bh(dev);
1881 
1882 	/* Make sure the QPN, reserved and subnet prefix match the current
1883 	 * lladdr, it also makes sure the lladdr is unicast.
1884 	 */
1885 	if (memcmp(dev->dev_addr, ss->__data,
1886 		   4 + sizeof(gid->global.subnet_prefix)) ||
1887 	    gid->global.interface_id == 0)
1888 		ret = -EINVAL;
1889 
1890 	netif_addr_unlock_bh(dev);
1891 
1892 	return ret;
1893 }
1894 
1895 static int ipoib_set_mac(struct net_device *dev, void *addr)
1896 {
1897 	struct ipoib_dev_priv *priv = netdev_priv(dev);
1898 	struct sockaddr_storage *ss = addr;
1899 	int ret;
1900 
1901 	if (!(dev->priv_flags & IFF_LIVE_ADDR_CHANGE) && netif_running(dev))
1902 		return -EBUSY;
1903 
1904 	ret = ipoib_check_lladdr(dev, ss);
1905 	if (ret)
1906 		return ret;
1907 
1908 	set_base_guid(priv, (union ib_gid *)(ss->__data + 4));
1909 
1910 	queue_work(ipoib_workqueue, &priv->flush_light);
1911 
1912 	return 0;
1913 }
1914 
1915 static ssize_t create_child(struct device *dev,
1916 			    struct device_attribute *attr,
1917 			    const char *buf, size_t count)
1918 {
1919 	int pkey;
1920 	int ret;
1921 
1922 	if (sscanf(buf, "%i", &pkey) != 1)
1923 		return -EINVAL;
1924 
1925 	if (pkey <= 0 || pkey > 0xffff || pkey == 0x8000)
1926 		return -EINVAL;
1927 
1928 	/*
1929 	 * Set the full membership bit, so that we join the right
1930 	 * broadcast group, etc.
1931 	 */
1932 	pkey |= 0x8000;
1933 
1934 	ret = ipoib_vlan_add(to_net_dev(dev), pkey);
1935 
1936 	return ret ? ret : count;
1937 }
1938 static DEVICE_ATTR(create_child, S_IWUSR, NULL, create_child);
1939 
1940 static ssize_t delete_child(struct device *dev,
1941 			    struct device_attribute *attr,
1942 			    const char *buf, size_t count)
1943 {
1944 	int pkey;
1945 	int ret;
1946 
1947 	if (sscanf(buf, "%i", &pkey) != 1)
1948 		return -EINVAL;
1949 
1950 	if (pkey < 0 || pkey > 0xffff)
1951 		return -EINVAL;
1952 
1953 	ret = ipoib_vlan_delete(to_net_dev(dev), pkey);
1954 
1955 	return ret ? ret : count;
1956 
1957 }
1958 static DEVICE_ATTR(delete_child, S_IWUSR, NULL, delete_child);
1959 
1960 int ipoib_add_pkey_attr(struct net_device *dev)
1961 {
1962 	return device_create_file(&dev->dev, &dev_attr_pkey);
1963 }
1964 
1965 int ipoib_set_dev_features(struct ipoib_dev_priv *priv, struct ib_device *hca)
1966 {
1967 	priv->hca_caps = hca->attrs.device_cap_flags;
1968 
1969 	if (priv->hca_caps & IB_DEVICE_UD_IP_CSUM) {
1970 		priv->dev->hw_features = NETIF_F_IP_CSUM | NETIF_F_RXCSUM;
1971 
1972 		if (priv->hca_caps & IB_DEVICE_UD_TSO)
1973 			priv->dev->hw_features |= NETIF_F_TSO;
1974 
1975 		priv->dev->features |= priv->dev->hw_features;
1976 	}
1977 
1978 	return 0;
1979 }
1980 
1981 static struct net_device *ipoib_add_port(const char *format,
1982 					 struct ib_device *hca, u8 port)
1983 {
1984 	struct ipoib_dev_priv *priv;
1985 	struct ib_port_attr attr;
1986 	int result = -ENOMEM;
1987 
1988 	priv = ipoib_intf_alloc(format);
1989 	if (!priv)
1990 		goto alloc_mem_failed;
1991 
1992 	SET_NETDEV_DEV(priv->dev, hca->dma_device);
1993 	priv->dev->dev_id = port - 1;
1994 
1995 	result = ib_query_port(hca, port, &attr);
1996 	if (!result)
1997 		priv->max_ib_mtu = ib_mtu_enum_to_int(attr.max_mtu);
1998 	else {
1999 		printk(KERN_WARNING "%s: ib_query_port %d failed\n",
2000 		       hca->name, port);
2001 		goto device_init_failed;
2002 	}
2003 
2004 	/* MTU will be reset when mcast join happens */
2005 	priv->dev->mtu  = IPOIB_UD_MTU(priv->max_ib_mtu);
2006 	priv->mcast_mtu  = priv->admin_mtu = priv->dev->mtu;
2007 
2008 	priv->dev->neigh_priv_len = sizeof(struct ipoib_neigh);
2009 
2010 	result = ib_query_pkey(hca, port, 0, &priv->pkey);
2011 	if (result) {
2012 		printk(KERN_WARNING "%s: ib_query_pkey port %d failed (ret = %d)\n",
2013 		       hca->name, port, result);
2014 		goto device_init_failed;
2015 	}
2016 
2017 	result = ipoib_set_dev_features(priv, hca);
2018 	if (result)
2019 		goto device_init_failed;
2020 
2021 	/*
2022 	 * Set the full membership bit, so that we join the right
2023 	 * broadcast group, etc.
2024 	 */
2025 	priv->pkey |= 0x8000;
2026 
2027 	priv->dev->broadcast[8] = priv->pkey >> 8;
2028 	priv->dev->broadcast[9] = priv->pkey & 0xff;
2029 
2030 	result = ib_query_gid(hca, port, 0, &priv->local_gid, NULL);
2031 	if (result) {
2032 		printk(KERN_WARNING "%s: ib_query_gid port %d failed (ret = %d)\n",
2033 		       hca->name, port, result);
2034 		goto device_init_failed;
2035 	} else
2036 		memcpy(priv->dev->dev_addr + 4, priv->local_gid.raw, sizeof (union ib_gid));
2037 	set_bit(IPOIB_FLAG_DEV_ADDR_SET, &priv->flags);
2038 
2039 	result = ipoib_dev_init(priv->dev, hca, port);
2040 	if (result < 0) {
2041 		printk(KERN_WARNING "%s: failed to initialize port %d (ret = %d)\n",
2042 		       hca->name, port, result);
2043 		goto device_init_failed;
2044 	}
2045 
2046 	INIT_IB_EVENT_HANDLER(&priv->event_handler,
2047 			      priv->ca, ipoib_event);
2048 	result = ib_register_event_handler(&priv->event_handler);
2049 	if (result < 0) {
2050 		printk(KERN_WARNING "%s: ib_register_event_handler failed for "
2051 		       "port %d (ret = %d)\n",
2052 		       hca->name, port, result);
2053 		goto event_failed;
2054 	}
2055 
2056 	result = register_netdev(priv->dev);
2057 	if (result) {
2058 		printk(KERN_WARNING "%s: couldn't register ipoib port %d; error %d\n",
2059 		       hca->name, port, result);
2060 		goto register_failed;
2061 	}
2062 
2063 	ipoib_create_debug_files(priv->dev);
2064 
2065 	if (ipoib_cm_add_mode_attr(priv->dev))
2066 		goto sysfs_failed;
2067 	if (ipoib_add_pkey_attr(priv->dev))
2068 		goto sysfs_failed;
2069 	if (ipoib_add_umcast_attr(priv->dev))
2070 		goto sysfs_failed;
2071 	if (device_create_file(&priv->dev->dev, &dev_attr_create_child))
2072 		goto sysfs_failed;
2073 	if (device_create_file(&priv->dev->dev, &dev_attr_delete_child))
2074 		goto sysfs_failed;
2075 
2076 	return priv->dev;
2077 
2078 sysfs_failed:
2079 	ipoib_delete_debug_files(priv->dev);
2080 	unregister_netdev(priv->dev);
2081 
2082 register_failed:
2083 	ib_unregister_event_handler(&priv->event_handler);
2084 	flush_workqueue(ipoib_workqueue);
2085 	/* Stop GC if started before flush */
2086 	set_bit(IPOIB_STOP_NEIGH_GC, &priv->flags);
2087 	cancel_delayed_work(&priv->neigh_reap_task);
2088 	flush_workqueue(priv->wq);
2089 
2090 event_failed:
2091 	ipoib_dev_cleanup(priv->dev);
2092 
2093 device_init_failed:
2094 	free_netdev(priv->dev);
2095 
2096 alloc_mem_failed:
2097 	return ERR_PTR(result);
2098 }
2099 
2100 static void ipoib_add_one(struct ib_device *device)
2101 {
2102 	struct list_head *dev_list;
2103 	struct net_device *dev;
2104 	struct ipoib_dev_priv *priv;
2105 	int p;
2106 	int count = 0;
2107 
2108 	dev_list = kmalloc(sizeof *dev_list, GFP_KERNEL);
2109 	if (!dev_list)
2110 		return;
2111 
2112 	INIT_LIST_HEAD(dev_list);
2113 
2114 	for (p = rdma_start_port(device); p <= rdma_end_port(device); ++p) {
2115 		if (!rdma_protocol_ib(device, p))
2116 			continue;
2117 		dev = ipoib_add_port("ib%d", device, p);
2118 		if (!IS_ERR(dev)) {
2119 			priv = netdev_priv(dev);
2120 			list_add_tail(&priv->list, dev_list);
2121 			count++;
2122 		}
2123 	}
2124 
2125 	if (!count) {
2126 		kfree(dev_list);
2127 		return;
2128 	}
2129 
2130 	ib_set_client_data(device, &ipoib_client, dev_list);
2131 }
2132 
2133 static void ipoib_remove_one(struct ib_device *device, void *client_data)
2134 {
2135 	struct ipoib_dev_priv *priv, *tmp;
2136 	struct list_head *dev_list = client_data;
2137 
2138 	if (!dev_list)
2139 		return;
2140 
2141 	list_for_each_entry_safe(priv, tmp, dev_list, list) {
2142 		ib_unregister_event_handler(&priv->event_handler);
2143 		flush_workqueue(ipoib_workqueue);
2144 
2145 		/* mark interface in the middle of destruction */
2146 		set_bit(IPOIB_FLAG_GOING_DOWN, &priv->flags);
2147 
2148 		rtnl_lock();
2149 		dev_change_flags(priv->dev, priv->dev->flags & ~IFF_UP);
2150 		rtnl_unlock();
2151 
2152 		/* Stop GC */
2153 		set_bit(IPOIB_STOP_NEIGH_GC, &priv->flags);
2154 		cancel_delayed_work(&priv->neigh_reap_task);
2155 		flush_workqueue(priv->wq);
2156 
2157 		unregister_netdev(priv->dev);
2158 		free_netdev(priv->dev);
2159 	}
2160 
2161 	kfree(dev_list);
2162 }
2163 
2164 static int __init ipoib_init_module(void)
2165 {
2166 	int ret;
2167 
2168 	ipoib_recvq_size = roundup_pow_of_two(ipoib_recvq_size);
2169 	ipoib_recvq_size = min(ipoib_recvq_size, IPOIB_MAX_QUEUE_SIZE);
2170 	ipoib_recvq_size = max(ipoib_recvq_size, IPOIB_MIN_QUEUE_SIZE);
2171 
2172 	ipoib_sendq_size = roundup_pow_of_two(ipoib_sendq_size);
2173 	ipoib_sendq_size = min(ipoib_sendq_size, IPOIB_MAX_QUEUE_SIZE);
2174 	ipoib_sendq_size = max3(ipoib_sendq_size, 2 * MAX_SEND_CQE, IPOIB_MIN_QUEUE_SIZE);
2175 #ifdef CONFIG_INFINIBAND_IPOIB_CM
2176 	ipoib_max_conn_qp = min(ipoib_max_conn_qp, IPOIB_CM_MAX_CONN_QP);
2177 #endif
2178 
2179 	/*
2180 	 * When copying small received packets, we only copy from the
2181 	 * linear data part of the SKB, so we rely on this condition.
2182 	 */
2183 	BUILD_BUG_ON(IPOIB_CM_COPYBREAK > IPOIB_CM_HEAD_SIZE);
2184 
2185 	ret = ipoib_register_debugfs();
2186 	if (ret)
2187 		return ret;
2188 
2189 	/*
2190 	 * We create a global workqueue here that is used for all flush
2191 	 * operations.  However, if you attempt to flush a workqueue
2192 	 * from a task on that same workqueue, it deadlocks the system.
2193 	 * We want to be able to flush the tasks associated with a
2194 	 * specific net device, so we also create a workqueue for each
2195 	 * netdevice.  We queue up the tasks for that device only on
2196 	 * its private workqueue, and we only queue up flush events
2197 	 * on our global flush workqueue.  This avoids the deadlocks.
2198 	 */
2199 	ipoib_workqueue = create_singlethread_workqueue("ipoib_flush");
2200 	if (!ipoib_workqueue) {
2201 		ret = -ENOMEM;
2202 		goto err_fs;
2203 	}
2204 
2205 	ib_sa_register_client(&ipoib_sa_client);
2206 
2207 	ret = ib_register_client(&ipoib_client);
2208 	if (ret)
2209 		goto err_sa;
2210 
2211 	ret = ipoib_netlink_init();
2212 	if (ret)
2213 		goto err_client;
2214 
2215 	return 0;
2216 
2217 err_client:
2218 	ib_unregister_client(&ipoib_client);
2219 
2220 err_sa:
2221 	ib_sa_unregister_client(&ipoib_sa_client);
2222 	destroy_workqueue(ipoib_workqueue);
2223 
2224 err_fs:
2225 	ipoib_unregister_debugfs();
2226 
2227 	return ret;
2228 }
2229 
2230 static void __exit ipoib_cleanup_module(void)
2231 {
2232 	ipoib_netlink_fini();
2233 	ib_unregister_client(&ipoib_client);
2234 	ib_sa_unregister_client(&ipoib_sa_client);
2235 	ipoib_unregister_debugfs();
2236 	destroy_workqueue(ipoib_workqueue);
2237 }
2238 
2239 module_init(ipoib_init_module);
2240 module_exit(ipoib_cleanup_module);
2241