xref: /openbmc/linux/drivers/net/hyperv/netvsc.c (revision 6197e5b7)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * Copyright (c) 2009, Microsoft Corporation.
4  *
5  * Authors:
6  *   Haiyang Zhang <haiyangz@microsoft.com>
7  *   Hank Janssen  <hjanssen@microsoft.com>
8  */
9 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
10 
11 #include <linux/kernel.h>
12 #include <linux/sched.h>
13 #include <linux/wait.h>
14 #include <linux/mm.h>
15 #include <linux/delay.h>
16 #include <linux/io.h>
17 #include <linux/slab.h>
18 #include <linux/netdevice.h>
19 #include <linux/if_ether.h>
20 #include <linux/vmalloc.h>
21 #include <linux/rtnetlink.h>
22 #include <linux/prefetch.h>
23 
24 #include <asm/sync_bitops.h>
25 
26 #include "hyperv_net.h"
27 #include "netvsc_trace.h"
28 
29 /*
30  * Switch the data path from the synthetic interface to the VF
31  * interface.
32  */
33 void netvsc_switch_datapath(struct net_device *ndev, bool vf)
34 {
35 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
36 	struct hv_device *dev = net_device_ctx->device_ctx;
37 	struct netvsc_device *nv_dev = rtnl_dereference(net_device_ctx->nvdev);
38 	struct nvsp_message *init_pkt = &nv_dev->channel_init_pkt;
39 
40 	/* Block sending traffic to VF if it's about to be gone */
41 	if (!vf)
42 		net_device_ctx->data_path_is_vf = vf;
43 
44 	memset(init_pkt, 0, sizeof(struct nvsp_message));
45 	init_pkt->hdr.msg_type = NVSP_MSG4_TYPE_SWITCH_DATA_PATH;
46 	if (vf)
47 		init_pkt->msg.v4_msg.active_dp.active_datapath =
48 			NVSP_DATAPATH_VF;
49 	else
50 		init_pkt->msg.v4_msg.active_dp.active_datapath =
51 			NVSP_DATAPATH_SYNTHETIC;
52 
53 	trace_nvsp_send(ndev, init_pkt);
54 
55 	vmbus_sendpacket(dev->channel, init_pkt,
56 			       sizeof(struct nvsp_message),
57 			       (unsigned long)init_pkt,
58 			       VM_PKT_DATA_INBAND,
59 			       VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED);
60 	wait_for_completion(&nv_dev->channel_init_wait);
61 	net_device_ctx->data_path_is_vf = vf;
62 }
63 
64 /* Worker to setup sub channels on initial setup
65  * Initial hotplug event occurs in softirq context
66  * and can't wait for channels.
67  */
68 static void netvsc_subchan_work(struct work_struct *w)
69 {
70 	struct netvsc_device *nvdev =
71 		container_of(w, struct netvsc_device, subchan_work);
72 	struct rndis_device *rdev;
73 	int i, ret;
74 
75 	/* Avoid deadlock with device removal already under RTNL */
76 	if (!rtnl_trylock()) {
77 		schedule_work(w);
78 		return;
79 	}
80 
81 	rdev = nvdev->extension;
82 	if (rdev) {
83 		ret = rndis_set_subchannel(rdev->ndev, nvdev, NULL);
84 		if (ret == 0) {
85 			netif_device_attach(rdev->ndev);
86 		} else {
87 			/* fallback to only primary channel */
88 			for (i = 1; i < nvdev->num_chn; i++)
89 				netif_napi_del(&nvdev->chan_table[i].napi);
90 
91 			nvdev->max_chn = 1;
92 			nvdev->num_chn = 1;
93 		}
94 	}
95 
96 	rtnl_unlock();
97 }
98 
99 static struct netvsc_device *alloc_net_device(void)
100 {
101 	struct netvsc_device *net_device;
102 
103 	net_device = kzalloc(sizeof(struct netvsc_device), GFP_KERNEL);
104 	if (!net_device)
105 		return NULL;
106 
107 	init_waitqueue_head(&net_device->wait_drain);
108 	net_device->destroy = false;
109 	net_device->tx_disable = true;
110 
111 	net_device->max_pkt = RNDIS_MAX_PKT_DEFAULT;
112 	net_device->pkt_align = RNDIS_PKT_ALIGN_DEFAULT;
113 
114 	init_completion(&net_device->channel_init_wait);
115 	init_waitqueue_head(&net_device->subchan_open);
116 	INIT_WORK(&net_device->subchan_work, netvsc_subchan_work);
117 
118 	return net_device;
119 }
120 
121 static void free_netvsc_device(struct rcu_head *head)
122 {
123 	struct netvsc_device *nvdev
124 		= container_of(head, struct netvsc_device, rcu);
125 	int i;
126 
127 	kfree(nvdev->extension);
128 	vfree(nvdev->recv_buf);
129 	vfree(nvdev->send_buf);
130 	kfree(nvdev->send_section_map);
131 
132 	for (i = 0; i < VRSS_CHANNEL_MAX; i++) {
133 		xdp_rxq_info_unreg(&nvdev->chan_table[i].xdp_rxq);
134 		kfree(nvdev->chan_table[i].recv_buf);
135 		vfree(nvdev->chan_table[i].mrc.slots);
136 	}
137 
138 	kfree(nvdev);
139 }
140 
141 static void free_netvsc_device_rcu(struct netvsc_device *nvdev)
142 {
143 	call_rcu(&nvdev->rcu, free_netvsc_device);
144 }
145 
146 static void netvsc_revoke_recv_buf(struct hv_device *device,
147 				   struct netvsc_device *net_device,
148 				   struct net_device *ndev)
149 {
150 	struct nvsp_message *revoke_packet;
151 	int ret;
152 
153 	/*
154 	 * If we got a section count, it means we received a
155 	 * SendReceiveBufferComplete msg (ie sent
156 	 * NvspMessage1TypeSendReceiveBuffer msg) therefore, we need
157 	 * to send a revoke msg here
158 	 */
159 	if (net_device->recv_section_cnt) {
160 		/* Send the revoke receive buffer */
161 		revoke_packet = &net_device->revoke_packet;
162 		memset(revoke_packet, 0, sizeof(struct nvsp_message));
163 
164 		revoke_packet->hdr.msg_type =
165 			NVSP_MSG1_TYPE_REVOKE_RECV_BUF;
166 		revoke_packet->msg.v1_msg.
167 		revoke_recv_buf.id = NETVSC_RECEIVE_BUFFER_ID;
168 
169 		trace_nvsp_send(ndev, revoke_packet);
170 
171 		ret = vmbus_sendpacket(device->channel,
172 				       revoke_packet,
173 				       sizeof(struct nvsp_message),
174 				       VMBUS_RQST_ID_NO_RESPONSE,
175 				       VM_PKT_DATA_INBAND, 0);
176 		/* If the failure is because the channel is rescinded;
177 		 * ignore the failure since we cannot send on a rescinded
178 		 * channel. This would allow us to properly cleanup
179 		 * even when the channel is rescinded.
180 		 */
181 		if (device->channel->rescind)
182 			ret = 0;
183 		/*
184 		 * If we failed here, we might as well return and
185 		 * have a leak rather than continue and a bugchk
186 		 */
187 		if (ret != 0) {
188 			netdev_err(ndev, "unable to send "
189 				"revoke receive buffer to netvsp\n");
190 			return;
191 		}
192 		net_device->recv_section_cnt = 0;
193 	}
194 }
195 
196 static void netvsc_revoke_send_buf(struct hv_device *device,
197 				   struct netvsc_device *net_device,
198 				   struct net_device *ndev)
199 {
200 	struct nvsp_message *revoke_packet;
201 	int ret;
202 
203 	/* Deal with the send buffer we may have setup.
204 	 * If we got a  send section size, it means we received a
205 	 * NVSP_MSG1_TYPE_SEND_SEND_BUF_COMPLETE msg (ie sent
206 	 * NVSP_MSG1_TYPE_SEND_SEND_BUF msg) therefore, we need
207 	 * to send a revoke msg here
208 	 */
209 	if (net_device->send_section_cnt) {
210 		/* Send the revoke receive buffer */
211 		revoke_packet = &net_device->revoke_packet;
212 		memset(revoke_packet, 0, sizeof(struct nvsp_message));
213 
214 		revoke_packet->hdr.msg_type =
215 			NVSP_MSG1_TYPE_REVOKE_SEND_BUF;
216 		revoke_packet->msg.v1_msg.revoke_send_buf.id =
217 			NETVSC_SEND_BUFFER_ID;
218 
219 		trace_nvsp_send(ndev, revoke_packet);
220 
221 		ret = vmbus_sendpacket(device->channel,
222 				       revoke_packet,
223 				       sizeof(struct nvsp_message),
224 				       VMBUS_RQST_ID_NO_RESPONSE,
225 				       VM_PKT_DATA_INBAND, 0);
226 
227 		/* If the failure is because the channel is rescinded;
228 		 * ignore the failure since we cannot send on a rescinded
229 		 * channel. This would allow us to properly cleanup
230 		 * even when the channel is rescinded.
231 		 */
232 		if (device->channel->rescind)
233 			ret = 0;
234 
235 		/* If we failed here, we might as well return and
236 		 * have a leak rather than continue and a bugchk
237 		 */
238 		if (ret != 0) {
239 			netdev_err(ndev, "unable to send "
240 				   "revoke send buffer to netvsp\n");
241 			return;
242 		}
243 		net_device->send_section_cnt = 0;
244 	}
245 }
246 
247 static void netvsc_teardown_recv_gpadl(struct hv_device *device,
248 				       struct netvsc_device *net_device,
249 				       struct net_device *ndev)
250 {
251 	int ret;
252 
253 	if (net_device->recv_buf_gpadl_handle) {
254 		ret = vmbus_teardown_gpadl(device->channel,
255 					   net_device->recv_buf_gpadl_handle);
256 
257 		/* If we failed here, we might as well return and have a leak
258 		 * rather than continue and a bugchk
259 		 */
260 		if (ret != 0) {
261 			netdev_err(ndev,
262 				   "unable to teardown receive buffer's gpadl\n");
263 			return;
264 		}
265 		net_device->recv_buf_gpadl_handle = 0;
266 	}
267 }
268 
269 static void netvsc_teardown_send_gpadl(struct hv_device *device,
270 				       struct netvsc_device *net_device,
271 				       struct net_device *ndev)
272 {
273 	int ret;
274 
275 	if (net_device->send_buf_gpadl_handle) {
276 		ret = vmbus_teardown_gpadl(device->channel,
277 					   net_device->send_buf_gpadl_handle);
278 
279 		/* If we failed here, we might as well return and have a leak
280 		 * rather than continue and a bugchk
281 		 */
282 		if (ret != 0) {
283 			netdev_err(ndev,
284 				   "unable to teardown send buffer's gpadl\n");
285 			return;
286 		}
287 		net_device->send_buf_gpadl_handle = 0;
288 	}
289 }
290 
291 int netvsc_alloc_recv_comp_ring(struct netvsc_device *net_device, u32 q_idx)
292 {
293 	struct netvsc_channel *nvchan = &net_device->chan_table[q_idx];
294 	int node = cpu_to_node(nvchan->channel->target_cpu);
295 	size_t size;
296 
297 	size = net_device->recv_completion_cnt * sizeof(struct recv_comp_data);
298 	nvchan->mrc.slots = vzalloc_node(size, node);
299 	if (!nvchan->mrc.slots)
300 		nvchan->mrc.slots = vzalloc(size);
301 
302 	return nvchan->mrc.slots ? 0 : -ENOMEM;
303 }
304 
305 static int netvsc_init_buf(struct hv_device *device,
306 			   struct netvsc_device *net_device,
307 			   const struct netvsc_device_info *device_info)
308 {
309 	struct nvsp_1_message_send_receive_buffer_complete *resp;
310 	struct net_device *ndev = hv_get_drvdata(device);
311 	struct nvsp_message *init_packet;
312 	unsigned int buf_size;
313 	size_t map_words;
314 	int i, ret = 0;
315 
316 	/* Get receive buffer area. */
317 	buf_size = device_info->recv_sections * device_info->recv_section_size;
318 	buf_size = roundup(buf_size, PAGE_SIZE);
319 
320 	/* Legacy hosts only allow smaller receive buffer */
321 	if (net_device->nvsp_version <= NVSP_PROTOCOL_VERSION_2)
322 		buf_size = min_t(unsigned int, buf_size,
323 				 NETVSC_RECEIVE_BUFFER_SIZE_LEGACY);
324 
325 	net_device->recv_buf = vzalloc(buf_size);
326 	if (!net_device->recv_buf) {
327 		netdev_err(ndev,
328 			   "unable to allocate receive buffer of size %u\n",
329 			   buf_size);
330 		ret = -ENOMEM;
331 		goto cleanup;
332 	}
333 
334 	net_device->recv_buf_size = buf_size;
335 
336 	/*
337 	 * Establish the gpadl handle for this buffer on this
338 	 * channel.  Note: This call uses the vmbus connection rather
339 	 * than the channel to establish the gpadl handle.
340 	 */
341 	ret = vmbus_establish_gpadl(device->channel, net_device->recv_buf,
342 				    buf_size,
343 				    &net_device->recv_buf_gpadl_handle);
344 	if (ret != 0) {
345 		netdev_err(ndev,
346 			"unable to establish receive buffer's gpadl\n");
347 		goto cleanup;
348 	}
349 
350 	/* Notify the NetVsp of the gpadl handle */
351 	init_packet = &net_device->channel_init_pkt;
352 	memset(init_packet, 0, sizeof(struct nvsp_message));
353 	init_packet->hdr.msg_type = NVSP_MSG1_TYPE_SEND_RECV_BUF;
354 	init_packet->msg.v1_msg.send_recv_buf.
355 		gpadl_handle = net_device->recv_buf_gpadl_handle;
356 	init_packet->msg.v1_msg.
357 		send_recv_buf.id = NETVSC_RECEIVE_BUFFER_ID;
358 
359 	trace_nvsp_send(ndev, init_packet);
360 
361 	/* Send the gpadl notification request */
362 	ret = vmbus_sendpacket(device->channel, init_packet,
363 			       sizeof(struct nvsp_message),
364 			       (unsigned long)init_packet,
365 			       VM_PKT_DATA_INBAND,
366 			       VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED);
367 	if (ret != 0) {
368 		netdev_err(ndev,
369 			"unable to send receive buffer's gpadl to netvsp\n");
370 		goto cleanup;
371 	}
372 
373 	wait_for_completion(&net_device->channel_init_wait);
374 
375 	/* Check the response */
376 	resp = &init_packet->msg.v1_msg.send_recv_buf_complete;
377 	if (resp->status != NVSP_STAT_SUCCESS) {
378 		netdev_err(ndev,
379 			   "Unable to complete receive buffer initialization with NetVsp - status %d\n",
380 			   resp->status);
381 		ret = -EINVAL;
382 		goto cleanup;
383 	}
384 
385 	/* Parse the response */
386 	netdev_dbg(ndev, "Receive sections: %u sub_allocs: size %u count: %u\n",
387 		   resp->num_sections, resp->sections[0].sub_alloc_size,
388 		   resp->sections[0].num_sub_allocs);
389 
390 	/* There should only be one section for the entire receive buffer */
391 	if (resp->num_sections != 1 || resp->sections[0].offset != 0) {
392 		ret = -EINVAL;
393 		goto cleanup;
394 	}
395 
396 	net_device->recv_section_size = resp->sections[0].sub_alloc_size;
397 	net_device->recv_section_cnt = resp->sections[0].num_sub_allocs;
398 
399 	/* Ensure buffer will not overflow */
400 	if (net_device->recv_section_size < NETVSC_MTU_MIN || (u64)net_device->recv_section_size *
401 	    (u64)net_device->recv_section_cnt > (u64)buf_size) {
402 		netdev_err(ndev, "invalid recv_section_size %u\n",
403 			   net_device->recv_section_size);
404 		ret = -EINVAL;
405 		goto cleanup;
406 	}
407 
408 	for (i = 0; i < VRSS_CHANNEL_MAX; i++) {
409 		struct netvsc_channel *nvchan = &net_device->chan_table[i];
410 
411 		nvchan->recv_buf = kzalloc(net_device->recv_section_size, GFP_KERNEL);
412 		if (nvchan->recv_buf == NULL) {
413 			ret = -ENOMEM;
414 			goto cleanup;
415 		}
416 	}
417 
418 	/* Setup receive completion ring.
419 	 * Add 1 to the recv_section_cnt because at least one entry in a
420 	 * ring buffer has to be empty.
421 	 */
422 	net_device->recv_completion_cnt = net_device->recv_section_cnt + 1;
423 	ret = netvsc_alloc_recv_comp_ring(net_device, 0);
424 	if (ret)
425 		goto cleanup;
426 
427 	/* Now setup the send buffer. */
428 	buf_size = device_info->send_sections * device_info->send_section_size;
429 	buf_size = round_up(buf_size, PAGE_SIZE);
430 
431 	net_device->send_buf = vzalloc(buf_size);
432 	if (!net_device->send_buf) {
433 		netdev_err(ndev, "unable to allocate send buffer of size %u\n",
434 			   buf_size);
435 		ret = -ENOMEM;
436 		goto cleanup;
437 	}
438 
439 	/* Establish the gpadl handle for this buffer on this
440 	 * channel.  Note: This call uses the vmbus connection rather
441 	 * than the channel to establish the gpadl handle.
442 	 */
443 	ret = vmbus_establish_gpadl(device->channel, net_device->send_buf,
444 				    buf_size,
445 				    &net_device->send_buf_gpadl_handle);
446 	if (ret != 0) {
447 		netdev_err(ndev,
448 			   "unable to establish send buffer's gpadl\n");
449 		goto cleanup;
450 	}
451 
452 	/* Notify the NetVsp of the gpadl handle */
453 	init_packet = &net_device->channel_init_pkt;
454 	memset(init_packet, 0, sizeof(struct nvsp_message));
455 	init_packet->hdr.msg_type = NVSP_MSG1_TYPE_SEND_SEND_BUF;
456 	init_packet->msg.v1_msg.send_send_buf.gpadl_handle =
457 		net_device->send_buf_gpadl_handle;
458 	init_packet->msg.v1_msg.send_send_buf.id = NETVSC_SEND_BUFFER_ID;
459 
460 	trace_nvsp_send(ndev, init_packet);
461 
462 	/* Send the gpadl notification request */
463 	ret = vmbus_sendpacket(device->channel, init_packet,
464 			       sizeof(struct nvsp_message),
465 			       (unsigned long)init_packet,
466 			       VM_PKT_DATA_INBAND,
467 			       VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED);
468 	if (ret != 0) {
469 		netdev_err(ndev,
470 			   "unable to send send buffer's gpadl to netvsp\n");
471 		goto cleanup;
472 	}
473 
474 	wait_for_completion(&net_device->channel_init_wait);
475 
476 	/* Check the response */
477 	if (init_packet->msg.v1_msg.
478 	    send_send_buf_complete.status != NVSP_STAT_SUCCESS) {
479 		netdev_err(ndev, "Unable to complete send buffer "
480 			   "initialization with NetVsp - status %d\n",
481 			   init_packet->msg.v1_msg.
482 			   send_send_buf_complete.status);
483 		ret = -EINVAL;
484 		goto cleanup;
485 	}
486 
487 	/* Parse the response */
488 	net_device->send_section_size = init_packet->msg.
489 				v1_msg.send_send_buf_complete.section_size;
490 	if (net_device->send_section_size < NETVSC_MTU_MIN) {
491 		netdev_err(ndev, "invalid send_section_size %u\n",
492 			   net_device->send_section_size);
493 		ret = -EINVAL;
494 		goto cleanup;
495 	}
496 
497 	/* Section count is simply the size divided by the section size. */
498 	net_device->send_section_cnt = buf_size / net_device->send_section_size;
499 
500 	netdev_dbg(ndev, "Send section size: %d, Section count:%d\n",
501 		   net_device->send_section_size, net_device->send_section_cnt);
502 
503 	/* Setup state for managing the send buffer. */
504 	map_words = DIV_ROUND_UP(net_device->send_section_cnt, BITS_PER_LONG);
505 
506 	net_device->send_section_map = kcalloc(map_words, sizeof(ulong), GFP_KERNEL);
507 	if (net_device->send_section_map == NULL) {
508 		ret = -ENOMEM;
509 		goto cleanup;
510 	}
511 
512 	goto exit;
513 
514 cleanup:
515 	netvsc_revoke_recv_buf(device, net_device, ndev);
516 	netvsc_revoke_send_buf(device, net_device, ndev);
517 	netvsc_teardown_recv_gpadl(device, net_device, ndev);
518 	netvsc_teardown_send_gpadl(device, net_device, ndev);
519 
520 exit:
521 	return ret;
522 }
523 
524 /* Negotiate NVSP protocol version */
525 static int negotiate_nvsp_ver(struct hv_device *device,
526 			      struct netvsc_device *net_device,
527 			      struct nvsp_message *init_packet,
528 			      u32 nvsp_ver)
529 {
530 	struct net_device *ndev = hv_get_drvdata(device);
531 	int ret;
532 
533 	memset(init_packet, 0, sizeof(struct nvsp_message));
534 	init_packet->hdr.msg_type = NVSP_MSG_TYPE_INIT;
535 	init_packet->msg.init_msg.init.min_protocol_ver = nvsp_ver;
536 	init_packet->msg.init_msg.init.max_protocol_ver = nvsp_ver;
537 	trace_nvsp_send(ndev, init_packet);
538 
539 	/* Send the init request */
540 	ret = vmbus_sendpacket(device->channel, init_packet,
541 			       sizeof(struct nvsp_message),
542 			       (unsigned long)init_packet,
543 			       VM_PKT_DATA_INBAND,
544 			       VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED);
545 
546 	if (ret != 0)
547 		return ret;
548 
549 	wait_for_completion(&net_device->channel_init_wait);
550 
551 	if (init_packet->msg.init_msg.init_complete.status !=
552 	    NVSP_STAT_SUCCESS)
553 		return -EINVAL;
554 
555 	if (nvsp_ver == NVSP_PROTOCOL_VERSION_1)
556 		return 0;
557 
558 	/* NVSPv2 or later: Send NDIS config */
559 	memset(init_packet, 0, sizeof(struct nvsp_message));
560 	init_packet->hdr.msg_type = NVSP_MSG2_TYPE_SEND_NDIS_CONFIG;
561 	init_packet->msg.v2_msg.send_ndis_config.mtu = ndev->mtu + ETH_HLEN;
562 	init_packet->msg.v2_msg.send_ndis_config.capability.ieee8021q = 1;
563 
564 	if (nvsp_ver >= NVSP_PROTOCOL_VERSION_5) {
565 		init_packet->msg.v2_msg.send_ndis_config.capability.sriov = 1;
566 
567 		/* Teaming bit is needed to receive link speed updates */
568 		init_packet->msg.v2_msg.send_ndis_config.capability.teaming = 1;
569 	}
570 
571 	if (nvsp_ver >= NVSP_PROTOCOL_VERSION_61)
572 		init_packet->msg.v2_msg.send_ndis_config.capability.rsc = 1;
573 
574 	trace_nvsp_send(ndev, init_packet);
575 
576 	ret = vmbus_sendpacket(device->channel, init_packet,
577 				sizeof(struct nvsp_message),
578 				VMBUS_RQST_ID_NO_RESPONSE,
579 				VM_PKT_DATA_INBAND, 0);
580 
581 	return ret;
582 }
583 
584 static int netvsc_connect_vsp(struct hv_device *device,
585 			      struct netvsc_device *net_device,
586 			      const struct netvsc_device_info *device_info)
587 {
588 	struct net_device *ndev = hv_get_drvdata(device);
589 	static const u32 ver_list[] = {
590 		NVSP_PROTOCOL_VERSION_1, NVSP_PROTOCOL_VERSION_2,
591 		NVSP_PROTOCOL_VERSION_4, NVSP_PROTOCOL_VERSION_5,
592 		NVSP_PROTOCOL_VERSION_6, NVSP_PROTOCOL_VERSION_61
593 	};
594 	struct nvsp_message *init_packet;
595 	int ndis_version, i, ret;
596 
597 	init_packet = &net_device->channel_init_pkt;
598 
599 	/* Negotiate the latest NVSP protocol supported */
600 	for (i = ARRAY_SIZE(ver_list) - 1; i >= 0; i--)
601 		if (negotiate_nvsp_ver(device, net_device, init_packet,
602 				       ver_list[i])  == 0) {
603 			net_device->nvsp_version = ver_list[i];
604 			break;
605 		}
606 
607 	if (i < 0) {
608 		ret = -EPROTO;
609 		goto cleanup;
610 	}
611 
612 	pr_debug("Negotiated NVSP version:%x\n", net_device->nvsp_version);
613 
614 	/* Send the ndis version */
615 	memset(init_packet, 0, sizeof(struct nvsp_message));
616 
617 	if (net_device->nvsp_version <= NVSP_PROTOCOL_VERSION_4)
618 		ndis_version = 0x00060001;
619 	else
620 		ndis_version = 0x0006001e;
621 
622 	init_packet->hdr.msg_type = NVSP_MSG1_TYPE_SEND_NDIS_VER;
623 	init_packet->msg.v1_msg.
624 		send_ndis_ver.ndis_major_ver =
625 				(ndis_version & 0xFFFF0000) >> 16;
626 	init_packet->msg.v1_msg.
627 		send_ndis_ver.ndis_minor_ver =
628 				ndis_version & 0xFFFF;
629 
630 	trace_nvsp_send(ndev, init_packet);
631 
632 	/* Send the init request */
633 	ret = vmbus_sendpacket(device->channel, init_packet,
634 				sizeof(struct nvsp_message),
635 				VMBUS_RQST_ID_NO_RESPONSE,
636 				VM_PKT_DATA_INBAND, 0);
637 	if (ret != 0)
638 		goto cleanup;
639 
640 
641 	ret = netvsc_init_buf(device, net_device, device_info);
642 
643 cleanup:
644 	return ret;
645 }
646 
647 /*
648  * netvsc_device_remove - Callback when the root bus device is removed
649  */
650 void netvsc_device_remove(struct hv_device *device)
651 {
652 	struct net_device *ndev = hv_get_drvdata(device);
653 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
654 	struct netvsc_device *net_device
655 		= rtnl_dereference(net_device_ctx->nvdev);
656 	int i;
657 
658 	/*
659 	 * Revoke receive buffer. If host is pre-Win2016 then tear down
660 	 * receive buffer GPADL. Do the same for send buffer.
661 	 */
662 	netvsc_revoke_recv_buf(device, net_device, ndev);
663 	if (vmbus_proto_version < VERSION_WIN10)
664 		netvsc_teardown_recv_gpadl(device, net_device, ndev);
665 
666 	netvsc_revoke_send_buf(device, net_device, ndev);
667 	if (vmbus_proto_version < VERSION_WIN10)
668 		netvsc_teardown_send_gpadl(device, net_device, ndev);
669 
670 	RCU_INIT_POINTER(net_device_ctx->nvdev, NULL);
671 
672 	/* Disable NAPI and disassociate its context from the device. */
673 	for (i = 0; i < net_device->num_chn; i++) {
674 		/* See also vmbus_reset_channel_cb(). */
675 		napi_disable(&net_device->chan_table[i].napi);
676 		netif_napi_del(&net_device->chan_table[i].napi);
677 	}
678 
679 	/*
680 	 * At this point, no one should be accessing net_device
681 	 * except in here
682 	 */
683 	netdev_dbg(ndev, "net device safe to remove\n");
684 
685 	/* Now, we can close the channel safely */
686 	vmbus_close(device->channel);
687 
688 	/*
689 	 * If host is Win2016 or higher then we do the GPADL tear down
690 	 * here after VMBus is closed.
691 	*/
692 	if (vmbus_proto_version >= VERSION_WIN10) {
693 		netvsc_teardown_recv_gpadl(device, net_device, ndev);
694 		netvsc_teardown_send_gpadl(device, net_device, ndev);
695 	}
696 
697 	/* Release all resources */
698 	free_netvsc_device_rcu(net_device);
699 }
700 
701 #define RING_AVAIL_PERCENT_HIWATER 20
702 #define RING_AVAIL_PERCENT_LOWATER 10
703 
704 static inline void netvsc_free_send_slot(struct netvsc_device *net_device,
705 					 u32 index)
706 {
707 	sync_change_bit(index, net_device->send_section_map);
708 }
709 
710 static void netvsc_send_tx_complete(struct net_device *ndev,
711 				    struct netvsc_device *net_device,
712 				    struct vmbus_channel *channel,
713 				    const struct vmpacket_descriptor *desc,
714 				    int budget)
715 {
716 	struct net_device_context *ndev_ctx = netdev_priv(ndev);
717 	struct sk_buff *skb;
718 	u16 q_idx = 0;
719 	int queue_sends;
720 	u64 cmd_rqst;
721 
722 	cmd_rqst = vmbus_request_addr(&channel->requestor, (u64)desc->trans_id);
723 	if (cmd_rqst == VMBUS_RQST_ERROR) {
724 		netdev_err(ndev, "Incorrect transaction id\n");
725 		return;
726 	}
727 
728 	skb = (struct sk_buff *)(unsigned long)cmd_rqst;
729 
730 	/* Notify the layer above us */
731 	if (likely(skb)) {
732 		const struct hv_netvsc_packet *packet
733 			= (struct hv_netvsc_packet *)skb->cb;
734 		u32 send_index = packet->send_buf_index;
735 		struct netvsc_stats *tx_stats;
736 
737 		if (send_index != NETVSC_INVALID_INDEX)
738 			netvsc_free_send_slot(net_device, send_index);
739 		q_idx = packet->q_idx;
740 
741 		tx_stats = &net_device->chan_table[q_idx].tx_stats;
742 
743 		u64_stats_update_begin(&tx_stats->syncp);
744 		tx_stats->packets += packet->total_packets;
745 		tx_stats->bytes += packet->total_bytes;
746 		u64_stats_update_end(&tx_stats->syncp);
747 
748 		napi_consume_skb(skb, budget);
749 	}
750 
751 	queue_sends =
752 		atomic_dec_return(&net_device->chan_table[q_idx].queue_sends);
753 
754 	if (unlikely(net_device->destroy)) {
755 		if (queue_sends == 0)
756 			wake_up(&net_device->wait_drain);
757 	} else {
758 		struct netdev_queue *txq = netdev_get_tx_queue(ndev, q_idx);
759 
760 		if (netif_tx_queue_stopped(txq) && !net_device->tx_disable &&
761 		    (hv_get_avail_to_write_percent(&channel->outbound) >
762 		     RING_AVAIL_PERCENT_HIWATER || queue_sends < 1)) {
763 			netif_tx_wake_queue(txq);
764 			ndev_ctx->eth_stats.wake_queue++;
765 		}
766 	}
767 }
768 
769 static void netvsc_send_completion(struct net_device *ndev,
770 				   struct netvsc_device *net_device,
771 				   struct vmbus_channel *incoming_channel,
772 				   const struct vmpacket_descriptor *desc,
773 				   int budget)
774 {
775 	const struct nvsp_message *nvsp_packet;
776 	u32 msglen = hv_pkt_datalen(desc);
777 	struct nvsp_message *pkt_rqst;
778 	u64 cmd_rqst;
779 
780 	/* First check if this is a VMBUS completion without data payload */
781 	if (!msglen) {
782 		cmd_rqst = vmbus_request_addr(&incoming_channel->requestor,
783 					      (u64)desc->trans_id);
784 		if (cmd_rqst == VMBUS_RQST_ERROR) {
785 			netdev_err(ndev, "Invalid transaction id\n");
786 			return;
787 		}
788 
789 		pkt_rqst = (struct nvsp_message *)(uintptr_t)cmd_rqst;
790 		switch (pkt_rqst->hdr.msg_type) {
791 		case NVSP_MSG4_TYPE_SWITCH_DATA_PATH:
792 			complete(&net_device->channel_init_wait);
793 			break;
794 
795 		default:
796 			netdev_err(ndev, "Unexpected VMBUS completion!!\n");
797 		}
798 		return;
799 	}
800 
801 	/* Ensure packet is big enough to read header fields */
802 	if (msglen < sizeof(struct nvsp_message_header)) {
803 		netdev_err(ndev, "nvsp_message length too small: %u\n", msglen);
804 		return;
805 	}
806 
807 	nvsp_packet = hv_pkt_data(desc);
808 	switch (nvsp_packet->hdr.msg_type) {
809 	case NVSP_MSG_TYPE_INIT_COMPLETE:
810 		if (msglen < sizeof(struct nvsp_message_header) +
811 				sizeof(struct nvsp_message_init_complete)) {
812 			netdev_err(ndev, "nvsp_msg length too small: %u\n",
813 				   msglen);
814 			return;
815 		}
816 		fallthrough;
817 
818 	case NVSP_MSG1_TYPE_SEND_RECV_BUF_COMPLETE:
819 		if (msglen < sizeof(struct nvsp_message_header) +
820 				sizeof(struct nvsp_1_message_send_receive_buffer_complete)) {
821 			netdev_err(ndev, "nvsp_msg1 length too small: %u\n",
822 				   msglen);
823 			return;
824 		}
825 		fallthrough;
826 
827 	case NVSP_MSG1_TYPE_SEND_SEND_BUF_COMPLETE:
828 		if (msglen < sizeof(struct nvsp_message_header) +
829 				sizeof(struct nvsp_1_message_send_send_buffer_complete)) {
830 			netdev_err(ndev, "nvsp_msg1 length too small: %u\n",
831 				   msglen);
832 			return;
833 		}
834 		fallthrough;
835 
836 	case NVSP_MSG5_TYPE_SUBCHANNEL:
837 		if (msglen < sizeof(struct nvsp_message_header) +
838 				sizeof(struct nvsp_5_subchannel_complete)) {
839 			netdev_err(ndev, "nvsp_msg5 length too small: %u\n",
840 				   msglen);
841 			return;
842 		}
843 		/* Copy the response back */
844 		memcpy(&net_device->channel_init_pkt, nvsp_packet,
845 		       sizeof(struct nvsp_message));
846 		complete(&net_device->channel_init_wait);
847 		break;
848 
849 	case NVSP_MSG1_TYPE_SEND_RNDIS_PKT_COMPLETE:
850 		netvsc_send_tx_complete(ndev, net_device, incoming_channel,
851 					desc, budget);
852 		break;
853 
854 	default:
855 		netdev_err(ndev,
856 			   "Unknown send completion type %d received!!\n",
857 			   nvsp_packet->hdr.msg_type);
858 	}
859 }
860 
861 static u32 netvsc_get_next_send_section(struct netvsc_device *net_device)
862 {
863 	unsigned long *map_addr = net_device->send_section_map;
864 	unsigned int i;
865 
866 	for_each_clear_bit(i, map_addr, net_device->send_section_cnt) {
867 		if (sync_test_and_set_bit(i, map_addr) == 0)
868 			return i;
869 	}
870 
871 	return NETVSC_INVALID_INDEX;
872 }
873 
874 static void netvsc_copy_to_send_buf(struct netvsc_device *net_device,
875 				    unsigned int section_index,
876 				    u32 pend_size,
877 				    struct hv_netvsc_packet *packet,
878 				    struct rndis_message *rndis_msg,
879 				    struct hv_page_buffer *pb,
880 				    bool xmit_more)
881 {
882 	char *start = net_device->send_buf;
883 	char *dest = start + (section_index * net_device->send_section_size)
884 		     + pend_size;
885 	int i;
886 	u32 padding = 0;
887 	u32 page_count = packet->cp_partial ? packet->rmsg_pgcnt :
888 		packet->page_buf_cnt;
889 	u32 remain;
890 
891 	/* Add padding */
892 	remain = packet->total_data_buflen & (net_device->pkt_align - 1);
893 	if (xmit_more && remain) {
894 		padding = net_device->pkt_align - remain;
895 		rndis_msg->msg_len += padding;
896 		packet->total_data_buflen += padding;
897 	}
898 
899 	for (i = 0; i < page_count; i++) {
900 		char *src = phys_to_virt(pb[i].pfn << HV_HYP_PAGE_SHIFT);
901 		u32 offset = pb[i].offset;
902 		u32 len = pb[i].len;
903 
904 		memcpy(dest, (src + offset), len);
905 		dest += len;
906 	}
907 
908 	if (padding)
909 		memset(dest, 0, padding);
910 }
911 
912 static inline int netvsc_send_pkt(
913 	struct hv_device *device,
914 	struct hv_netvsc_packet *packet,
915 	struct netvsc_device *net_device,
916 	struct hv_page_buffer *pb,
917 	struct sk_buff *skb)
918 {
919 	struct nvsp_message nvmsg;
920 	struct nvsp_1_message_send_rndis_packet *rpkt =
921 		&nvmsg.msg.v1_msg.send_rndis_pkt;
922 	struct netvsc_channel * const nvchan =
923 		&net_device->chan_table[packet->q_idx];
924 	struct vmbus_channel *out_channel = nvchan->channel;
925 	struct net_device *ndev = hv_get_drvdata(device);
926 	struct net_device_context *ndev_ctx = netdev_priv(ndev);
927 	struct netdev_queue *txq = netdev_get_tx_queue(ndev, packet->q_idx);
928 	u64 req_id;
929 	int ret;
930 	u32 ring_avail = hv_get_avail_to_write_percent(&out_channel->outbound);
931 
932 	memset(&nvmsg, 0, sizeof(struct nvsp_message));
933 	nvmsg.hdr.msg_type = NVSP_MSG1_TYPE_SEND_RNDIS_PKT;
934 	if (skb)
935 		rpkt->channel_type = 0;		/* 0 is RMC_DATA */
936 	else
937 		rpkt->channel_type = 1;		/* 1 is RMC_CONTROL */
938 
939 	rpkt->send_buf_section_index = packet->send_buf_index;
940 	if (packet->send_buf_index == NETVSC_INVALID_INDEX)
941 		rpkt->send_buf_section_size = 0;
942 	else
943 		rpkt->send_buf_section_size = packet->total_data_buflen;
944 
945 	req_id = (ulong)skb;
946 
947 	if (out_channel->rescind)
948 		return -ENODEV;
949 
950 	trace_nvsp_send_pkt(ndev, out_channel, rpkt);
951 
952 	if (packet->page_buf_cnt) {
953 		if (packet->cp_partial)
954 			pb += packet->rmsg_pgcnt;
955 
956 		ret = vmbus_sendpacket_pagebuffer(out_channel,
957 						  pb, packet->page_buf_cnt,
958 						  &nvmsg, sizeof(nvmsg),
959 						  req_id);
960 	} else {
961 		ret = vmbus_sendpacket(out_channel,
962 				       &nvmsg, sizeof(nvmsg),
963 				       req_id, VM_PKT_DATA_INBAND,
964 				       VMBUS_DATA_PACKET_FLAG_COMPLETION_REQUESTED);
965 	}
966 
967 	if (ret == 0) {
968 		atomic_inc_return(&nvchan->queue_sends);
969 
970 		if (ring_avail < RING_AVAIL_PERCENT_LOWATER) {
971 			netif_tx_stop_queue(txq);
972 			ndev_ctx->eth_stats.stop_queue++;
973 		}
974 	} else if (ret == -EAGAIN) {
975 		netif_tx_stop_queue(txq);
976 		ndev_ctx->eth_stats.stop_queue++;
977 	} else {
978 		netdev_err(ndev,
979 			   "Unable to send packet pages %u len %u, ret %d\n",
980 			   packet->page_buf_cnt, packet->total_data_buflen,
981 			   ret);
982 	}
983 
984 	if (netif_tx_queue_stopped(txq) &&
985 	    atomic_read(&nvchan->queue_sends) < 1 &&
986 	    !net_device->tx_disable) {
987 		netif_tx_wake_queue(txq);
988 		ndev_ctx->eth_stats.wake_queue++;
989 		if (ret == -EAGAIN)
990 			ret = -ENOSPC;
991 	}
992 
993 	return ret;
994 }
995 
996 /* Move packet out of multi send data (msd), and clear msd */
997 static inline void move_pkt_msd(struct hv_netvsc_packet **msd_send,
998 				struct sk_buff **msd_skb,
999 				struct multi_send_data *msdp)
1000 {
1001 	*msd_skb = msdp->skb;
1002 	*msd_send = msdp->pkt;
1003 	msdp->skb = NULL;
1004 	msdp->pkt = NULL;
1005 	msdp->count = 0;
1006 }
1007 
1008 /* RCU already held by caller */
1009 int netvsc_send(struct net_device *ndev,
1010 		struct hv_netvsc_packet *packet,
1011 		struct rndis_message *rndis_msg,
1012 		struct hv_page_buffer *pb,
1013 		struct sk_buff *skb,
1014 		bool xdp_tx)
1015 {
1016 	struct net_device_context *ndev_ctx = netdev_priv(ndev);
1017 	struct netvsc_device *net_device
1018 		= rcu_dereference_bh(ndev_ctx->nvdev);
1019 	struct hv_device *device = ndev_ctx->device_ctx;
1020 	int ret = 0;
1021 	struct netvsc_channel *nvchan;
1022 	u32 pktlen = packet->total_data_buflen, msd_len = 0;
1023 	unsigned int section_index = NETVSC_INVALID_INDEX;
1024 	struct multi_send_data *msdp;
1025 	struct hv_netvsc_packet *msd_send = NULL, *cur_send = NULL;
1026 	struct sk_buff *msd_skb = NULL;
1027 	bool try_batch, xmit_more;
1028 
1029 	/* If device is rescinded, return error and packet will get dropped. */
1030 	if (unlikely(!net_device || net_device->destroy))
1031 		return -ENODEV;
1032 
1033 	nvchan = &net_device->chan_table[packet->q_idx];
1034 	packet->send_buf_index = NETVSC_INVALID_INDEX;
1035 	packet->cp_partial = false;
1036 
1037 	/* Send a control message or XDP packet directly without accessing
1038 	 * msd (Multi-Send Data) field which may be changed during data packet
1039 	 * processing.
1040 	 */
1041 	if (!skb || xdp_tx)
1042 		return netvsc_send_pkt(device, packet, net_device, pb, skb);
1043 
1044 	/* batch packets in send buffer if possible */
1045 	msdp = &nvchan->msd;
1046 	if (msdp->pkt)
1047 		msd_len = msdp->pkt->total_data_buflen;
1048 
1049 	try_batch =  msd_len > 0 && msdp->count < net_device->max_pkt;
1050 	if (try_batch && msd_len + pktlen + net_device->pkt_align <
1051 	    net_device->send_section_size) {
1052 		section_index = msdp->pkt->send_buf_index;
1053 
1054 	} else if (try_batch && msd_len + packet->rmsg_size <
1055 		   net_device->send_section_size) {
1056 		section_index = msdp->pkt->send_buf_index;
1057 		packet->cp_partial = true;
1058 
1059 	} else if (pktlen + net_device->pkt_align <
1060 		   net_device->send_section_size) {
1061 		section_index = netvsc_get_next_send_section(net_device);
1062 		if (unlikely(section_index == NETVSC_INVALID_INDEX)) {
1063 			++ndev_ctx->eth_stats.tx_send_full;
1064 		} else {
1065 			move_pkt_msd(&msd_send, &msd_skb, msdp);
1066 			msd_len = 0;
1067 		}
1068 	}
1069 
1070 	/* Keep aggregating only if stack says more data is coming
1071 	 * and not doing mixed modes send and not flow blocked
1072 	 */
1073 	xmit_more = netdev_xmit_more() &&
1074 		!packet->cp_partial &&
1075 		!netif_xmit_stopped(netdev_get_tx_queue(ndev, packet->q_idx));
1076 
1077 	if (section_index != NETVSC_INVALID_INDEX) {
1078 		netvsc_copy_to_send_buf(net_device,
1079 					section_index, msd_len,
1080 					packet, rndis_msg, pb, xmit_more);
1081 
1082 		packet->send_buf_index = section_index;
1083 
1084 		if (packet->cp_partial) {
1085 			packet->page_buf_cnt -= packet->rmsg_pgcnt;
1086 			packet->total_data_buflen = msd_len + packet->rmsg_size;
1087 		} else {
1088 			packet->page_buf_cnt = 0;
1089 			packet->total_data_buflen += msd_len;
1090 		}
1091 
1092 		if (msdp->pkt) {
1093 			packet->total_packets += msdp->pkt->total_packets;
1094 			packet->total_bytes += msdp->pkt->total_bytes;
1095 		}
1096 
1097 		if (msdp->skb)
1098 			dev_consume_skb_any(msdp->skb);
1099 
1100 		if (xmit_more) {
1101 			msdp->skb = skb;
1102 			msdp->pkt = packet;
1103 			msdp->count++;
1104 		} else {
1105 			cur_send = packet;
1106 			msdp->skb = NULL;
1107 			msdp->pkt = NULL;
1108 			msdp->count = 0;
1109 		}
1110 	} else {
1111 		move_pkt_msd(&msd_send, &msd_skb, msdp);
1112 		cur_send = packet;
1113 	}
1114 
1115 	if (msd_send) {
1116 		int m_ret = netvsc_send_pkt(device, msd_send, net_device,
1117 					    NULL, msd_skb);
1118 
1119 		if (m_ret != 0) {
1120 			netvsc_free_send_slot(net_device,
1121 					      msd_send->send_buf_index);
1122 			dev_kfree_skb_any(msd_skb);
1123 		}
1124 	}
1125 
1126 	if (cur_send)
1127 		ret = netvsc_send_pkt(device, cur_send, net_device, pb, skb);
1128 
1129 	if (ret != 0 && section_index != NETVSC_INVALID_INDEX)
1130 		netvsc_free_send_slot(net_device, section_index);
1131 
1132 	return ret;
1133 }
1134 
1135 /* Send pending recv completions */
1136 static int send_recv_completions(struct net_device *ndev,
1137 				 struct netvsc_device *nvdev,
1138 				 struct netvsc_channel *nvchan)
1139 {
1140 	struct multi_recv_comp *mrc = &nvchan->mrc;
1141 	struct recv_comp_msg {
1142 		struct nvsp_message_header hdr;
1143 		u32 status;
1144 	}  __packed;
1145 	struct recv_comp_msg msg = {
1146 		.hdr.msg_type = NVSP_MSG1_TYPE_SEND_RNDIS_PKT_COMPLETE,
1147 	};
1148 	int ret;
1149 
1150 	while (mrc->first != mrc->next) {
1151 		const struct recv_comp_data *rcd
1152 			= mrc->slots + mrc->first;
1153 
1154 		msg.status = rcd->status;
1155 		ret = vmbus_sendpacket(nvchan->channel, &msg, sizeof(msg),
1156 				       rcd->tid, VM_PKT_COMP, 0);
1157 		if (unlikely(ret)) {
1158 			struct net_device_context *ndev_ctx = netdev_priv(ndev);
1159 
1160 			++ndev_ctx->eth_stats.rx_comp_busy;
1161 			return ret;
1162 		}
1163 
1164 		if (++mrc->first == nvdev->recv_completion_cnt)
1165 			mrc->first = 0;
1166 	}
1167 
1168 	/* receive completion ring has been emptied */
1169 	if (unlikely(nvdev->destroy))
1170 		wake_up(&nvdev->wait_drain);
1171 
1172 	return 0;
1173 }
1174 
1175 /* Count how many receive completions are outstanding */
1176 static void recv_comp_slot_avail(const struct netvsc_device *nvdev,
1177 				 const struct multi_recv_comp *mrc,
1178 				 u32 *filled, u32 *avail)
1179 {
1180 	u32 count = nvdev->recv_completion_cnt;
1181 
1182 	if (mrc->next >= mrc->first)
1183 		*filled = mrc->next - mrc->first;
1184 	else
1185 		*filled = (count - mrc->first) + mrc->next;
1186 
1187 	*avail = count - *filled - 1;
1188 }
1189 
1190 /* Add receive complete to ring to send to host. */
1191 static void enq_receive_complete(struct net_device *ndev,
1192 				 struct netvsc_device *nvdev, u16 q_idx,
1193 				 u64 tid, u32 status)
1194 {
1195 	struct netvsc_channel *nvchan = &nvdev->chan_table[q_idx];
1196 	struct multi_recv_comp *mrc = &nvchan->mrc;
1197 	struct recv_comp_data *rcd;
1198 	u32 filled, avail;
1199 
1200 	recv_comp_slot_avail(nvdev, mrc, &filled, &avail);
1201 
1202 	if (unlikely(filled > NAPI_POLL_WEIGHT)) {
1203 		send_recv_completions(ndev, nvdev, nvchan);
1204 		recv_comp_slot_avail(nvdev, mrc, &filled, &avail);
1205 	}
1206 
1207 	if (unlikely(!avail)) {
1208 		netdev_err(ndev, "Recv_comp full buf q:%hd, tid:%llx\n",
1209 			   q_idx, tid);
1210 		return;
1211 	}
1212 
1213 	rcd = mrc->slots + mrc->next;
1214 	rcd->tid = tid;
1215 	rcd->status = status;
1216 
1217 	if (++mrc->next == nvdev->recv_completion_cnt)
1218 		mrc->next = 0;
1219 }
1220 
1221 static int netvsc_receive(struct net_device *ndev,
1222 			  struct netvsc_device *net_device,
1223 			  struct netvsc_channel *nvchan,
1224 			  const struct vmpacket_descriptor *desc)
1225 {
1226 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
1227 	struct vmbus_channel *channel = nvchan->channel;
1228 	const struct vmtransfer_page_packet_header *vmxferpage_packet
1229 		= container_of(desc, const struct vmtransfer_page_packet_header, d);
1230 	const struct nvsp_message *nvsp = hv_pkt_data(desc);
1231 	u32 msglen = hv_pkt_datalen(desc);
1232 	u16 q_idx = channel->offermsg.offer.sub_channel_index;
1233 	char *recv_buf = net_device->recv_buf;
1234 	u32 status = NVSP_STAT_SUCCESS;
1235 	int i;
1236 	int count = 0;
1237 
1238 	/* Ensure packet is big enough to read header fields */
1239 	if (msglen < sizeof(struct nvsp_message_header)) {
1240 		netif_err(net_device_ctx, rx_err, ndev,
1241 			  "invalid nvsp header, length too small: %u\n",
1242 			  msglen);
1243 		return 0;
1244 	}
1245 
1246 	/* Make sure this is a valid nvsp packet */
1247 	if (unlikely(nvsp->hdr.msg_type != NVSP_MSG1_TYPE_SEND_RNDIS_PKT)) {
1248 		netif_err(net_device_ctx, rx_err, ndev,
1249 			  "Unknown nvsp packet type received %u\n",
1250 			  nvsp->hdr.msg_type);
1251 		return 0;
1252 	}
1253 
1254 	/* Validate xfer page pkt header */
1255 	if ((desc->offset8 << 3) < sizeof(struct vmtransfer_page_packet_header)) {
1256 		netif_err(net_device_ctx, rx_err, ndev,
1257 			  "Invalid xfer page pkt, offset too small: %u\n",
1258 			  desc->offset8 << 3);
1259 		return 0;
1260 	}
1261 
1262 	if (unlikely(vmxferpage_packet->xfer_pageset_id != NETVSC_RECEIVE_BUFFER_ID)) {
1263 		netif_err(net_device_ctx, rx_err, ndev,
1264 			  "Invalid xfer page set id - expecting %x got %x\n",
1265 			  NETVSC_RECEIVE_BUFFER_ID,
1266 			  vmxferpage_packet->xfer_pageset_id);
1267 		return 0;
1268 	}
1269 
1270 	count = vmxferpage_packet->range_cnt;
1271 
1272 	/* Check count for a valid value */
1273 	if (NETVSC_XFER_HEADER_SIZE(count) > desc->offset8 << 3) {
1274 		netif_err(net_device_ctx, rx_err, ndev,
1275 			  "Range count is not valid: %d\n",
1276 			  count);
1277 		return 0;
1278 	}
1279 
1280 	/* Each range represents 1 RNDIS pkt that contains 1 ethernet frame */
1281 	for (i = 0; i < count; i++) {
1282 		u32 offset = vmxferpage_packet->ranges[i].byte_offset;
1283 		u32 buflen = vmxferpage_packet->ranges[i].byte_count;
1284 		void *data;
1285 		int ret;
1286 
1287 		if (unlikely(offset > net_device->recv_buf_size ||
1288 			     buflen > net_device->recv_buf_size - offset)) {
1289 			nvchan->rsc.cnt = 0;
1290 			status = NVSP_STAT_FAIL;
1291 			netif_err(net_device_ctx, rx_err, ndev,
1292 				  "Packet offset:%u + len:%u too big\n",
1293 				  offset, buflen);
1294 
1295 			continue;
1296 		}
1297 
1298 		/* We're going to copy (sections of) the packet into nvchan->recv_buf;
1299 		 * make sure that nvchan->recv_buf is large enough to hold the packet.
1300 		 */
1301 		if (unlikely(buflen > net_device->recv_section_size)) {
1302 			nvchan->rsc.cnt = 0;
1303 			status = NVSP_STAT_FAIL;
1304 			netif_err(net_device_ctx, rx_err, ndev,
1305 				  "Packet too big: buflen=%u recv_section_size=%u\n",
1306 				  buflen, net_device->recv_section_size);
1307 
1308 			continue;
1309 		}
1310 
1311 		data = recv_buf + offset;
1312 
1313 		nvchan->rsc.is_last = (i == count - 1);
1314 
1315 		trace_rndis_recv(ndev, q_idx, data);
1316 
1317 		/* Pass it to the upper layer */
1318 		ret = rndis_filter_receive(ndev, net_device,
1319 					   nvchan, data, buflen);
1320 
1321 		if (unlikely(ret != NVSP_STAT_SUCCESS)) {
1322 			/* Drop incomplete packet */
1323 			nvchan->rsc.cnt = 0;
1324 			status = NVSP_STAT_FAIL;
1325 		}
1326 	}
1327 
1328 	enq_receive_complete(ndev, net_device, q_idx,
1329 			     vmxferpage_packet->d.trans_id, status);
1330 
1331 	return count;
1332 }
1333 
1334 static void netvsc_send_table(struct net_device *ndev,
1335 			      struct netvsc_device *nvscdev,
1336 			      const struct nvsp_message *nvmsg,
1337 			      u32 msglen)
1338 {
1339 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
1340 	u32 count, offset, *tab;
1341 	int i;
1342 
1343 	/* Ensure packet is big enough to read send_table fields */
1344 	if (msglen < sizeof(struct nvsp_message_header) +
1345 		     sizeof(struct nvsp_5_send_indirect_table)) {
1346 		netdev_err(ndev, "nvsp_v5_msg length too small: %u\n", msglen);
1347 		return;
1348 	}
1349 
1350 	count = nvmsg->msg.v5_msg.send_table.count;
1351 	offset = nvmsg->msg.v5_msg.send_table.offset;
1352 
1353 	if (count != VRSS_SEND_TAB_SIZE) {
1354 		netdev_err(ndev, "Received wrong send-table size:%u\n", count);
1355 		return;
1356 	}
1357 
1358 	/* If negotiated version <= NVSP_PROTOCOL_VERSION_6, the offset may be
1359 	 * wrong due to a host bug. So fix the offset here.
1360 	 */
1361 	if (nvscdev->nvsp_version <= NVSP_PROTOCOL_VERSION_6 &&
1362 	    msglen >= sizeof(struct nvsp_message_header) +
1363 	    sizeof(union nvsp_6_message_uber) + count * sizeof(u32))
1364 		offset = sizeof(struct nvsp_message_header) +
1365 			 sizeof(union nvsp_6_message_uber);
1366 
1367 	/* Boundary check for all versions */
1368 	if (msglen < count * sizeof(u32) || offset > msglen - count * sizeof(u32)) {
1369 		netdev_err(ndev, "Received send-table offset too big:%u\n",
1370 			   offset);
1371 		return;
1372 	}
1373 
1374 	tab = (void *)nvmsg + offset;
1375 
1376 	for (i = 0; i < count; i++)
1377 		net_device_ctx->tx_table[i] = tab[i];
1378 }
1379 
1380 static void netvsc_send_vf(struct net_device *ndev,
1381 			   const struct nvsp_message *nvmsg,
1382 			   u32 msglen)
1383 {
1384 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
1385 
1386 	/* Ensure packet is big enough to read its fields */
1387 	if (msglen < sizeof(struct nvsp_message_header) +
1388 		     sizeof(struct nvsp_4_send_vf_association)) {
1389 		netdev_err(ndev, "nvsp_v4_msg length too small: %u\n", msglen);
1390 		return;
1391 	}
1392 
1393 	net_device_ctx->vf_alloc = nvmsg->msg.v4_msg.vf_assoc.allocated;
1394 	net_device_ctx->vf_serial = nvmsg->msg.v4_msg.vf_assoc.serial;
1395 	netdev_info(ndev, "VF slot %u %s\n",
1396 		    net_device_ctx->vf_serial,
1397 		    net_device_ctx->vf_alloc ? "added" : "removed");
1398 }
1399 
1400 static void netvsc_receive_inband(struct net_device *ndev,
1401 				  struct netvsc_device *nvscdev,
1402 				  const struct vmpacket_descriptor *desc)
1403 {
1404 	const struct nvsp_message *nvmsg = hv_pkt_data(desc);
1405 	u32 msglen = hv_pkt_datalen(desc);
1406 
1407 	/* Ensure packet is big enough to read header fields */
1408 	if (msglen < sizeof(struct nvsp_message_header)) {
1409 		netdev_err(ndev, "inband nvsp_message length too small: %u\n", msglen);
1410 		return;
1411 	}
1412 
1413 	switch (nvmsg->hdr.msg_type) {
1414 	case NVSP_MSG5_TYPE_SEND_INDIRECTION_TABLE:
1415 		netvsc_send_table(ndev, nvscdev, nvmsg, msglen);
1416 		break;
1417 
1418 	case NVSP_MSG4_TYPE_SEND_VF_ASSOCIATION:
1419 		netvsc_send_vf(ndev, nvmsg, msglen);
1420 		break;
1421 	}
1422 }
1423 
1424 static int netvsc_process_raw_pkt(struct hv_device *device,
1425 				  struct netvsc_channel *nvchan,
1426 				  struct netvsc_device *net_device,
1427 				  struct net_device *ndev,
1428 				  const struct vmpacket_descriptor *desc,
1429 				  int budget)
1430 {
1431 	struct vmbus_channel *channel = nvchan->channel;
1432 	const struct nvsp_message *nvmsg = hv_pkt_data(desc);
1433 
1434 	trace_nvsp_recv(ndev, channel, nvmsg);
1435 
1436 	switch (desc->type) {
1437 	case VM_PKT_COMP:
1438 		netvsc_send_completion(ndev, net_device, channel, desc, budget);
1439 		break;
1440 
1441 	case VM_PKT_DATA_USING_XFER_PAGES:
1442 		return netvsc_receive(ndev, net_device, nvchan, desc);
1443 		break;
1444 
1445 	case VM_PKT_DATA_INBAND:
1446 		netvsc_receive_inband(ndev, net_device, desc);
1447 		break;
1448 
1449 	default:
1450 		netdev_err(ndev, "unhandled packet type %d, tid %llx\n",
1451 			   desc->type, desc->trans_id);
1452 		break;
1453 	}
1454 
1455 	return 0;
1456 }
1457 
1458 static struct hv_device *netvsc_channel_to_device(struct vmbus_channel *channel)
1459 {
1460 	struct vmbus_channel *primary = channel->primary_channel;
1461 
1462 	return primary ? primary->device_obj : channel->device_obj;
1463 }
1464 
1465 /* Network processing softirq
1466  * Process data in incoming ring buffer from host
1467  * Stops when ring is empty or budget is met or exceeded.
1468  */
1469 int netvsc_poll(struct napi_struct *napi, int budget)
1470 {
1471 	struct netvsc_channel *nvchan
1472 		= container_of(napi, struct netvsc_channel, napi);
1473 	struct netvsc_device *net_device = nvchan->net_device;
1474 	struct vmbus_channel *channel = nvchan->channel;
1475 	struct hv_device *device = netvsc_channel_to_device(channel);
1476 	struct net_device *ndev = hv_get_drvdata(device);
1477 	int work_done = 0;
1478 	int ret;
1479 
1480 	/* If starting a new interval */
1481 	if (!nvchan->desc)
1482 		nvchan->desc = hv_pkt_iter_first(channel);
1483 
1484 	while (nvchan->desc && work_done < budget) {
1485 		work_done += netvsc_process_raw_pkt(device, nvchan, net_device,
1486 						    ndev, nvchan->desc, budget);
1487 		nvchan->desc = hv_pkt_iter_next(channel, nvchan->desc);
1488 	}
1489 
1490 	/* Send any pending receive completions */
1491 	ret = send_recv_completions(ndev, net_device, nvchan);
1492 
1493 	/* If it did not exhaust NAPI budget this time
1494 	 *  and not doing busy poll
1495 	 * then re-enable host interrupts
1496 	 *  and reschedule if ring is not empty
1497 	 *   or sending receive completion failed.
1498 	 */
1499 	if (work_done < budget &&
1500 	    napi_complete_done(napi, work_done) &&
1501 	    (ret || hv_end_read(&channel->inbound)) &&
1502 	    napi_schedule_prep(napi)) {
1503 		hv_begin_read(&channel->inbound);
1504 		__napi_schedule(napi);
1505 	}
1506 
1507 	/* Driver may overshoot since multiple packets per descriptor */
1508 	return min(work_done, budget);
1509 }
1510 
1511 /* Call back when data is available in host ring buffer.
1512  * Processing is deferred until network softirq (NAPI)
1513  */
1514 void netvsc_channel_cb(void *context)
1515 {
1516 	struct netvsc_channel *nvchan = context;
1517 	struct vmbus_channel *channel = nvchan->channel;
1518 	struct hv_ring_buffer_info *rbi = &channel->inbound;
1519 
1520 	/* preload first vmpacket descriptor */
1521 	prefetch(hv_get_ring_buffer(rbi) + rbi->priv_read_index);
1522 
1523 	if (napi_schedule_prep(&nvchan->napi)) {
1524 		/* disable interrupts from host */
1525 		hv_begin_read(rbi);
1526 
1527 		__napi_schedule_irqoff(&nvchan->napi);
1528 	}
1529 }
1530 
1531 /*
1532  * netvsc_device_add - Callback when the device belonging to this
1533  * driver is added
1534  */
1535 struct netvsc_device *netvsc_device_add(struct hv_device *device,
1536 				const struct netvsc_device_info *device_info)
1537 {
1538 	int i, ret = 0;
1539 	struct netvsc_device *net_device;
1540 	struct net_device *ndev = hv_get_drvdata(device);
1541 	struct net_device_context *net_device_ctx = netdev_priv(ndev);
1542 
1543 	net_device = alloc_net_device();
1544 	if (!net_device)
1545 		return ERR_PTR(-ENOMEM);
1546 
1547 	for (i = 0; i < VRSS_SEND_TAB_SIZE; i++)
1548 		net_device_ctx->tx_table[i] = 0;
1549 
1550 	/* Because the device uses NAPI, all the interrupt batching and
1551 	 * control is done via Net softirq, not the channel handling
1552 	 */
1553 	set_channel_read_mode(device->channel, HV_CALL_ISR);
1554 
1555 	/* If we're reopening the device we may have multiple queues, fill the
1556 	 * chn_table with the default channel to use it before subchannels are
1557 	 * opened.
1558 	 * Initialize the channel state before we open;
1559 	 * we can be interrupted as soon as we open the channel.
1560 	 */
1561 
1562 	for (i = 0; i < VRSS_CHANNEL_MAX; i++) {
1563 		struct netvsc_channel *nvchan = &net_device->chan_table[i];
1564 
1565 		nvchan->channel = device->channel;
1566 		nvchan->net_device = net_device;
1567 		u64_stats_init(&nvchan->tx_stats.syncp);
1568 		u64_stats_init(&nvchan->rx_stats.syncp);
1569 
1570 		ret = xdp_rxq_info_reg(&nvchan->xdp_rxq, ndev, i, 0);
1571 
1572 		if (ret) {
1573 			netdev_err(ndev, "xdp_rxq_info_reg fail: %d\n", ret);
1574 			goto cleanup2;
1575 		}
1576 
1577 		ret = xdp_rxq_info_reg_mem_model(&nvchan->xdp_rxq,
1578 						 MEM_TYPE_PAGE_SHARED, NULL);
1579 
1580 		if (ret) {
1581 			netdev_err(ndev, "xdp reg_mem_model fail: %d\n", ret);
1582 			goto cleanup2;
1583 		}
1584 	}
1585 
1586 	/* Enable NAPI handler before init callbacks */
1587 	netif_napi_add(ndev, &net_device->chan_table[0].napi,
1588 		       netvsc_poll, NAPI_POLL_WEIGHT);
1589 
1590 	/* Open the channel */
1591 	device->channel->rqstor_size = netvsc_rqstor_size(netvsc_ring_bytes);
1592 	ret = vmbus_open(device->channel, netvsc_ring_bytes,
1593 			 netvsc_ring_bytes,  NULL, 0,
1594 			 netvsc_channel_cb, net_device->chan_table);
1595 
1596 	if (ret != 0) {
1597 		netdev_err(ndev, "unable to open channel: %d\n", ret);
1598 		goto cleanup;
1599 	}
1600 
1601 	/* Channel is opened */
1602 	netdev_dbg(ndev, "hv_netvsc channel opened successfully\n");
1603 
1604 	napi_enable(&net_device->chan_table[0].napi);
1605 
1606 	/* Connect with the NetVsp */
1607 	ret = netvsc_connect_vsp(device, net_device, device_info);
1608 	if (ret != 0) {
1609 		netdev_err(ndev,
1610 			"unable to connect to NetVSP - %d\n", ret);
1611 		goto close;
1612 	}
1613 
1614 	/* Writing nvdev pointer unlocks netvsc_send(), make sure chn_table is
1615 	 * populated.
1616 	 */
1617 	rcu_assign_pointer(net_device_ctx->nvdev, net_device);
1618 
1619 	return net_device;
1620 
1621 close:
1622 	RCU_INIT_POINTER(net_device_ctx->nvdev, NULL);
1623 	napi_disable(&net_device->chan_table[0].napi);
1624 
1625 	/* Now, we can close the channel safely */
1626 	vmbus_close(device->channel);
1627 
1628 cleanup:
1629 	netif_napi_del(&net_device->chan_table[0].napi);
1630 
1631 cleanup2:
1632 	free_netvsc_device(&net_device->rcu);
1633 
1634 	return ERR_PTR(ret);
1635 }
1636