1 /*
2  * Network-device interface management.
3  *
4  * Copyright (c) 2004-2005, Keir Fraser
5  *
6  * This program is free software; you can redistribute it and/or
7  * modify it under the terms of the GNU General Public License version 2
8  * as published by the Free Software Foundation; or, when distributed
9  * separately from the Linux kernel or incorporated into other
10  * software packages, subject to the following license:
11  *
12  * Permission is hereby granted, free of charge, to any person obtaining a copy
13  * of this source file (the "Software"), to deal in the Software without
14  * restriction, including without limitation the rights to use, copy, modify,
15  * merge, publish, distribute, sublicense, and/or sell copies of the Software,
16  * and to permit persons to whom the Software is furnished to do so, subject to
17  * the following conditions:
18  *
19  * The above copyright notice and this permission notice shall be included in
20  * all copies or substantial portions of the Software.
21  *
22  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
23  * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
24  * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
25  * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
26  * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
27  * FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS
28  * IN THE SOFTWARE.
29  */
30 
31 #include "common.h"
32 
33 #include <linux/kthread.h>
34 #include <linux/sched/task.h>
35 #include <linux/ethtool.h>
36 #include <linux/rtnetlink.h>
37 #include <linux/if_vlan.h>
38 #include <linux/vmalloc.h>
39 
40 #include <xen/events.h>
41 #include <asm/xen/hypercall.h>
42 #include <xen/balloon.h>
43 
44 #define XENVIF_QUEUE_LENGTH 32
45 #define XENVIF_NAPI_WEIGHT  64
46 
47 /* Number of bytes allowed on the internal guest Rx queue. */
48 #define XENVIF_RX_QUEUE_BYTES (XEN_NETIF_RX_RING_SIZE/2 * PAGE_SIZE)
49 
50 /* This function is used to set SKBTX_DEV_ZEROCOPY as well as
51  * increasing the inflight counter. We need to increase the inflight
52  * counter because core driver calls into xenvif_zerocopy_callback
53  * which calls xenvif_skb_zerocopy_complete.
54  */
55 void xenvif_skb_zerocopy_prepare(struct xenvif_queue *queue,
56 				 struct sk_buff *skb)
57 {
58 	skb_shinfo(skb)->tx_flags |= SKBTX_DEV_ZEROCOPY;
59 	atomic_inc(&queue->inflight_packets);
60 }
61 
62 void xenvif_skb_zerocopy_complete(struct xenvif_queue *queue)
63 {
64 	atomic_dec(&queue->inflight_packets);
65 
66 	/* Wake the dealloc thread _after_ decrementing inflight_packets so
67 	 * that if kthread_stop() has already been called, the dealloc thread
68 	 * does not wait forever with nothing to wake it.
69 	 */
70 	wake_up(&queue->dealloc_wq);
71 }
72 
73 int xenvif_schedulable(struct xenvif *vif)
74 {
75 	return netif_running(vif->dev) &&
76 		test_bit(VIF_STATUS_CONNECTED, &vif->status) &&
77 		!vif->disabled;
78 }
79 
80 static bool xenvif_handle_tx_interrupt(struct xenvif_queue *queue)
81 {
82 	bool rc;
83 
84 	rc = RING_HAS_UNCONSUMED_REQUESTS(&queue->tx);
85 	if (rc)
86 		napi_schedule(&queue->napi);
87 	return rc;
88 }
89 
90 static irqreturn_t xenvif_tx_interrupt(int irq, void *dev_id)
91 {
92 	struct xenvif_queue *queue = dev_id;
93 	int old;
94 
95 	old = atomic_fetch_or(NETBK_TX_EOI, &queue->eoi_pending);
96 	WARN(old & NETBK_TX_EOI, "Interrupt while EOI pending\n");
97 
98 	if (!xenvif_handle_tx_interrupt(queue)) {
99 		atomic_andnot(NETBK_TX_EOI, &queue->eoi_pending);
100 		xen_irq_lateeoi(irq, XEN_EOI_FLAG_SPURIOUS);
101 	}
102 
103 	return IRQ_HANDLED;
104 }
105 
106 static int xenvif_poll(struct napi_struct *napi, int budget)
107 {
108 	struct xenvif_queue *queue =
109 		container_of(napi, struct xenvif_queue, napi);
110 	int work_done;
111 
112 	/* This vif is rogue, we pretend we've there is nothing to do
113 	 * for this vif to deschedule it from NAPI. But this interface
114 	 * will be turned off in thread context later.
115 	 */
116 	if (unlikely(queue->vif->disabled)) {
117 		napi_complete(napi);
118 		return 0;
119 	}
120 
121 	work_done = xenvif_tx_action(queue, budget);
122 
123 	if (work_done < budget) {
124 		napi_complete_done(napi, work_done);
125 		/* If the queue is rate-limited, it shall be
126 		 * rescheduled in the timer callback.
127 		 */
128 		if (likely(!queue->rate_limited))
129 			xenvif_napi_schedule_or_enable_events(queue);
130 	}
131 
132 	return work_done;
133 }
134 
135 static bool xenvif_handle_rx_interrupt(struct xenvif_queue *queue)
136 {
137 	bool rc;
138 
139 	rc = xenvif_have_rx_work(queue, false);
140 	if (rc)
141 		xenvif_kick_thread(queue);
142 	return rc;
143 }
144 
145 static irqreturn_t xenvif_rx_interrupt(int irq, void *dev_id)
146 {
147 	struct xenvif_queue *queue = dev_id;
148 	int old;
149 
150 	old = atomic_fetch_or(NETBK_RX_EOI, &queue->eoi_pending);
151 	WARN(old & NETBK_RX_EOI, "Interrupt while EOI pending\n");
152 
153 	if (!xenvif_handle_rx_interrupt(queue)) {
154 		atomic_andnot(NETBK_RX_EOI, &queue->eoi_pending);
155 		xen_irq_lateeoi(irq, XEN_EOI_FLAG_SPURIOUS);
156 	}
157 
158 	return IRQ_HANDLED;
159 }
160 
161 irqreturn_t xenvif_interrupt(int irq, void *dev_id)
162 {
163 	struct xenvif_queue *queue = dev_id;
164 	int old;
165 
166 	old = atomic_fetch_or(NETBK_COMMON_EOI, &queue->eoi_pending);
167 	WARN(old, "Interrupt while EOI pending\n");
168 
169 	/* Use bitwise or as we need to call both functions. */
170 	if ((!xenvif_handle_tx_interrupt(queue) |
171 	     !xenvif_handle_rx_interrupt(queue))) {
172 		atomic_andnot(NETBK_COMMON_EOI, &queue->eoi_pending);
173 		xen_irq_lateeoi(irq, XEN_EOI_FLAG_SPURIOUS);
174 	}
175 
176 	return IRQ_HANDLED;
177 }
178 
179 int xenvif_queue_stopped(struct xenvif_queue *queue)
180 {
181 	struct net_device *dev = queue->vif->dev;
182 	unsigned int id = queue->id;
183 	return netif_tx_queue_stopped(netdev_get_tx_queue(dev, id));
184 }
185 
186 void xenvif_wake_queue(struct xenvif_queue *queue)
187 {
188 	struct net_device *dev = queue->vif->dev;
189 	unsigned int id = queue->id;
190 	netif_tx_wake_queue(netdev_get_tx_queue(dev, id));
191 }
192 
193 static u16 xenvif_select_queue(struct net_device *dev, struct sk_buff *skb,
194 			       struct net_device *sb_dev)
195 {
196 	struct xenvif *vif = netdev_priv(dev);
197 	unsigned int size = vif->hash.size;
198 	unsigned int num_queues;
199 
200 	/* If queues are not set up internally - always return 0
201 	 * as the packet going to be dropped anyway */
202 	num_queues = READ_ONCE(vif->num_queues);
203 	if (num_queues < 1)
204 		return 0;
205 
206 	if (vif->hash.alg == XEN_NETIF_CTRL_HASH_ALGORITHM_NONE)
207 		return netdev_pick_tx(dev, skb, NULL) %
208 		       dev->real_num_tx_queues;
209 
210 	xenvif_set_skb_hash(vif, skb);
211 
212 	if (size == 0)
213 		return skb_get_hash_raw(skb) % dev->real_num_tx_queues;
214 
215 	return vif->hash.mapping[vif->hash.mapping_sel]
216 				[skb_get_hash_raw(skb) % size];
217 }
218 
219 static netdev_tx_t
220 xenvif_start_xmit(struct sk_buff *skb, struct net_device *dev)
221 {
222 	struct xenvif *vif = netdev_priv(dev);
223 	struct xenvif_queue *queue = NULL;
224 	unsigned int num_queues;
225 	u16 index;
226 	struct xenvif_rx_cb *cb;
227 
228 	BUG_ON(skb->dev != dev);
229 
230 	/* Drop the packet if queues are not set up.
231 	 * This handler should be called inside an RCU read section
232 	 * so we don't need to enter it here explicitly.
233 	 */
234 	num_queues = READ_ONCE(vif->num_queues);
235 	if (num_queues < 1)
236 		goto drop;
237 
238 	/* Obtain the queue to be used to transmit this packet */
239 	index = skb_get_queue_mapping(skb);
240 	if (index >= num_queues) {
241 		pr_warn_ratelimited("Invalid queue %hu for packet on interface %s\n",
242 				    index, vif->dev->name);
243 		index %= num_queues;
244 	}
245 	queue = &vif->queues[index];
246 
247 	/* Drop the packet if queue is not ready */
248 	if (queue->task == NULL ||
249 	    queue->dealloc_task == NULL ||
250 	    !xenvif_schedulable(vif))
251 		goto drop;
252 
253 	if (vif->multicast_control && skb->pkt_type == PACKET_MULTICAST) {
254 		struct ethhdr *eth = (struct ethhdr *)skb->data;
255 
256 		if (!xenvif_mcast_match(vif, eth->h_dest))
257 			goto drop;
258 	}
259 
260 	cb = XENVIF_RX_CB(skb);
261 	cb->expires = jiffies + vif->drain_timeout;
262 
263 	/* If there is no hash algorithm configured then make sure there
264 	 * is no hash information in the socket buffer otherwise it
265 	 * would be incorrectly forwarded to the frontend.
266 	 */
267 	if (vif->hash.alg == XEN_NETIF_CTRL_HASH_ALGORITHM_NONE)
268 		skb_clear_hash(skb);
269 
270 	xenvif_rx_queue_tail(queue, skb);
271 	xenvif_kick_thread(queue);
272 
273 	return NETDEV_TX_OK;
274 
275  drop:
276 	vif->dev->stats.tx_dropped++;
277 	dev_kfree_skb(skb);
278 	return NETDEV_TX_OK;
279 }
280 
281 static struct net_device_stats *xenvif_get_stats(struct net_device *dev)
282 {
283 	struct xenvif *vif = netdev_priv(dev);
284 	struct xenvif_queue *queue = NULL;
285 	unsigned int num_queues;
286 	u64 rx_bytes = 0;
287 	u64 rx_packets = 0;
288 	u64 tx_bytes = 0;
289 	u64 tx_packets = 0;
290 	unsigned int index;
291 
292 	rcu_read_lock();
293 	num_queues = READ_ONCE(vif->num_queues);
294 
295 	/* Aggregate tx and rx stats from each queue */
296 	for (index = 0; index < num_queues; ++index) {
297 		queue = &vif->queues[index];
298 		rx_bytes += queue->stats.rx_bytes;
299 		rx_packets += queue->stats.rx_packets;
300 		tx_bytes += queue->stats.tx_bytes;
301 		tx_packets += queue->stats.tx_packets;
302 	}
303 
304 	rcu_read_unlock();
305 
306 	vif->dev->stats.rx_bytes = rx_bytes;
307 	vif->dev->stats.rx_packets = rx_packets;
308 	vif->dev->stats.tx_bytes = tx_bytes;
309 	vif->dev->stats.tx_packets = tx_packets;
310 
311 	return &vif->dev->stats;
312 }
313 
314 static void xenvif_up(struct xenvif *vif)
315 {
316 	struct xenvif_queue *queue = NULL;
317 	unsigned int num_queues = vif->num_queues;
318 	unsigned int queue_index;
319 
320 	for (queue_index = 0; queue_index < num_queues; ++queue_index) {
321 		queue = &vif->queues[queue_index];
322 		napi_enable(&queue->napi);
323 		enable_irq(queue->tx_irq);
324 		if (queue->tx_irq != queue->rx_irq)
325 			enable_irq(queue->rx_irq);
326 		xenvif_napi_schedule_or_enable_events(queue);
327 	}
328 }
329 
330 static void xenvif_down(struct xenvif *vif)
331 {
332 	struct xenvif_queue *queue = NULL;
333 	unsigned int num_queues = vif->num_queues;
334 	unsigned int queue_index;
335 
336 	for (queue_index = 0; queue_index < num_queues; ++queue_index) {
337 		queue = &vif->queues[queue_index];
338 		disable_irq(queue->tx_irq);
339 		if (queue->tx_irq != queue->rx_irq)
340 			disable_irq(queue->rx_irq);
341 		napi_disable(&queue->napi);
342 		del_timer_sync(&queue->credit_timeout);
343 	}
344 }
345 
346 static int xenvif_open(struct net_device *dev)
347 {
348 	struct xenvif *vif = netdev_priv(dev);
349 	if (test_bit(VIF_STATUS_CONNECTED, &vif->status))
350 		xenvif_up(vif);
351 	netif_tx_start_all_queues(dev);
352 	return 0;
353 }
354 
355 static int xenvif_close(struct net_device *dev)
356 {
357 	struct xenvif *vif = netdev_priv(dev);
358 	if (test_bit(VIF_STATUS_CONNECTED, &vif->status))
359 		xenvif_down(vif);
360 	netif_tx_stop_all_queues(dev);
361 	return 0;
362 }
363 
364 static int xenvif_change_mtu(struct net_device *dev, int mtu)
365 {
366 	struct xenvif *vif = netdev_priv(dev);
367 	int max = vif->can_sg ? ETH_MAX_MTU - VLAN_ETH_HLEN : ETH_DATA_LEN;
368 
369 	if (mtu > max)
370 		return -EINVAL;
371 	dev->mtu = mtu;
372 	return 0;
373 }
374 
375 static netdev_features_t xenvif_fix_features(struct net_device *dev,
376 	netdev_features_t features)
377 {
378 	struct xenvif *vif = netdev_priv(dev);
379 
380 	if (!vif->can_sg)
381 		features &= ~NETIF_F_SG;
382 	if (~(vif->gso_mask) & GSO_BIT(TCPV4))
383 		features &= ~NETIF_F_TSO;
384 	if (~(vif->gso_mask) & GSO_BIT(TCPV6))
385 		features &= ~NETIF_F_TSO6;
386 	if (!vif->ip_csum)
387 		features &= ~NETIF_F_IP_CSUM;
388 	if (!vif->ipv6_csum)
389 		features &= ~NETIF_F_IPV6_CSUM;
390 
391 	return features;
392 }
393 
394 static const struct xenvif_stat {
395 	char name[ETH_GSTRING_LEN];
396 	u16 offset;
397 } xenvif_stats[] = {
398 	{
399 		"rx_gso_checksum_fixup",
400 		offsetof(struct xenvif_stats, rx_gso_checksum_fixup)
401 	},
402 	/* If (sent != success + fail), there are probably packets never
403 	 * freed up properly!
404 	 */
405 	{
406 		"tx_zerocopy_sent",
407 		offsetof(struct xenvif_stats, tx_zerocopy_sent),
408 	},
409 	{
410 		"tx_zerocopy_success",
411 		offsetof(struct xenvif_stats, tx_zerocopy_success),
412 	},
413 	{
414 		"tx_zerocopy_fail",
415 		offsetof(struct xenvif_stats, tx_zerocopy_fail)
416 	},
417 	/* Number of packets exceeding MAX_SKB_FRAG slots. You should use
418 	 * a guest with the same MAX_SKB_FRAG
419 	 */
420 	{
421 		"tx_frag_overflow",
422 		offsetof(struct xenvif_stats, tx_frag_overflow)
423 	},
424 };
425 
426 static int xenvif_get_sset_count(struct net_device *dev, int string_set)
427 {
428 	switch (string_set) {
429 	case ETH_SS_STATS:
430 		return ARRAY_SIZE(xenvif_stats);
431 	default:
432 		return -EINVAL;
433 	}
434 }
435 
436 static void xenvif_get_ethtool_stats(struct net_device *dev,
437 				     struct ethtool_stats *stats, u64 * data)
438 {
439 	struct xenvif *vif = netdev_priv(dev);
440 	unsigned int num_queues;
441 	int i;
442 	unsigned int queue_index;
443 
444 	rcu_read_lock();
445 	num_queues = READ_ONCE(vif->num_queues);
446 
447 	for (i = 0; i < ARRAY_SIZE(xenvif_stats); i++) {
448 		unsigned long accum = 0;
449 		for (queue_index = 0; queue_index < num_queues; ++queue_index) {
450 			void *vif_stats = &vif->queues[queue_index].stats;
451 			accum += *(unsigned long *)(vif_stats + xenvif_stats[i].offset);
452 		}
453 		data[i] = accum;
454 	}
455 
456 	rcu_read_unlock();
457 }
458 
459 static void xenvif_get_strings(struct net_device *dev, u32 stringset, u8 * data)
460 {
461 	int i;
462 
463 	switch (stringset) {
464 	case ETH_SS_STATS:
465 		for (i = 0; i < ARRAY_SIZE(xenvif_stats); i++)
466 			memcpy(data + i * ETH_GSTRING_LEN,
467 			       xenvif_stats[i].name, ETH_GSTRING_LEN);
468 		break;
469 	}
470 }
471 
472 static const struct ethtool_ops xenvif_ethtool_ops = {
473 	.get_link	= ethtool_op_get_link,
474 
475 	.get_sset_count = xenvif_get_sset_count,
476 	.get_ethtool_stats = xenvif_get_ethtool_stats,
477 	.get_strings = xenvif_get_strings,
478 };
479 
480 static const struct net_device_ops xenvif_netdev_ops = {
481 	.ndo_select_queue = xenvif_select_queue,
482 	.ndo_start_xmit	= xenvif_start_xmit,
483 	.ndo_get_stats	= xenvif_get_stats,
484 	.ndo_open	= xenvif_open,
485 	.ndo_stop	= xenvif_close,
486 	.ndo_change_mtu	= xenvif_change_mtu,
487 	.ndo_fix_features = xenvif_fix_features,
488 	.ndo_set_mac_address = eth_mac_addr,
489 	.ndo_validate_addr   = eth_validate_addr,
490 };
491 
492 struct xenvif *xenvif_alloc(struct device *parent, domid_t domid,
493 			    unsigned int handle)
494 {
495 	int err;
496 	struct net_device *dev;
497 	struct xenvif *vif;
498 	char name[IFNAMSIZ] = {};
499 
500 	snprintf(name, IFNAMSIZ - 1, "vif%u.%u", domid, handle);
501 	/* Allocate a netdev with the max. supported number of queues.
502 	 * When the guest selects the desired number, it will be updated
503 	 * via netif_set_real_num_*_queues().
504 	 */
505 	dev = alloc_netdev_mq(sizeof(struct xenvif), name, NET_NAME_UNKNOWN,
506 			      ether_setup, xenvif_max_queues);
507 	if (dev == NULL) {
508 		pr_warn("Could not allocate netdev for %s\n", name);
509 		return ERR_PTR(-ENOMEM);
510 	}
511 
512 	SET_NETDEV_DEV(dev, parent);
513 
514 	vif = netdev_priv(dev);
515 
516 	vif->domid  = domid;
517 	vif->handle = handle;
518 	vif->can_sg = 1;
519 	vif->ip_csum = 1;
520 	vif->dev = dev;
521 	vif->disabled = false;
522 	vif->drain_timeout = msecs_to_jiffies(rx_drain_timeout_msecs);
523 	vif->stall_timeout = msecs_to_jiffies(rx_stall_timeout_msecs);
524 
525 	/* Start out with no queues. */
526 	vif->queues = NULL;
527 	vif->num_queues = 0;
528 
529 	vif->xdp_headroom = 0;
530 
531 	spin_lock_init(&vif->lock);
532 	INIT_LIST_HEAD(&vif->fe_mcast_addr);
533 
534 	dev->netdev_ops	= &xenvif_netdev_ops;
535 	dev->hw_features = NETIF_F_SG |
536 		NETIF_F_IP_CSUM | NETIF_F_IPV6_CSUM |
537 		NETIF_F_TSO | NETIF_F_TSO6 | NETIF_F_FRAGLIST;
538 	dev->features = dev->hw_features | NETIF_F_RXCSUM;
539 	dev->ethtool_ops = &xenvif_ethtool_ops;
540 
541 	dev->tx_queue_len = XENVIF_QUEUE_LENGTH;
542 
543 	dev->min_mtu = ETH_MIN_MTU;
544 	dev->max_mtu = ETH_MAX_MTU - VLAN_ETH_HLEN;
545 
546 	/*
547 	 * Initialise a dummy MAC address. We choose the numerically
548 	 * largest non-broadcast address to prevent the address getting
549 	 * stolen by an Ethernet bridge for STP purposes.
550 	 * (FE:FF:FF:FF:FF:FF)
551 	 */
552 	eth_broadcast_addr(dev->dev_addr);
553 	dev->dev_addr[0] &= ~0x01;
554 
555 	netif_carrier_off(dev);
556 
557 	err = register_netdev(dev);
558 	if (err) {
559 		netdev_warn(dev, "Could not register device: err=%d\n", err);
560 		free_netdev(dev);
561 		return ERR_PTR(err);
562 	}
563 
564 	netdev_dbg(dev, "Successfully created xenvif\n");
565 
566 	__module_get(THIS_MODULE);
567 
568 	return vif;
569 }
570 
571 int xenvif_init_queue(struct xenvif_queue *queue)
572 {
573 	int err, i;
574 
575 	queue->credit_bytes = queue->remaining_credit = ~0UL;
576 	queue->credit_usec  = 0UL;
577 	timer_setup(&queue->credit_timeout, xenvif_tx_credit_callback, 0);
578 	queue->credit_window_start = get_jiffies_64();
579 
580 	queue->rx_queue_max = XENVIF_RX_QUEUE_BYTES;
581 
582 	skb_queue_head_init(&queue->rx_queue);
583 	skb_queue_head_init(&queue->tx_queue);
584 
585 	queue->pending_cons = 0;
586 	queue->pending_prod = MAX_PENDING_REQS;
587 	for (i = 0; i < MAX_PENDING_REQS; ++i)
588 		queue->pending_ring[i] = i;
589 
590 	spin_lock_init(&queue->callback_lock);
591 	spin_lock_init(&queue->response_lock);
592 
593 	/* If ballooning is disabled, this will consume real memory, so you
594 	 * better enable it. The long term solution would be to use just a
595 	 * bunch of valid page descriptors, without dependency on ballooning
596 	 */
597 	err = gnttab_alloc_pages(MAX_PENDING_REQS,
598 				 queue->mmap_pages);
599 	if (err) {
600 		netdev_err(queue->vif->dev, "Could not reserve mmap_pages\n");
601 		return -ENOMEM;
602 	}
603 
604 	for (i = 0; i < MAX_PENDING_REQS; i++) {
605 		queue->pending_tx_info[i].callback_struct = (struct ubuf_info)
606 			{ .callback = xenvif_zerocopy_callback,
607 			  { { .ctx = NULL,
608 			      .desc = i } } };
609 		queue->grant_tx_handle[i] = NETBACK_INVALID_HANDLE;
610 	}
611 
612 	return 0;
613 }
614 
615 void xenvif_carrier_on(struct xenvif *vif)
616 {
617 	rtnl_lock();
618 	if (!vif->can_sg && vif->dev->mtu > ETH_DATA_LEN)
619 		dev_set_mtu(vif->dev, ETH_DATA_LEN);
620 	netdev_update_features(vif->dev);
621 	set_bit(VIF_STATUS_CONNECTED, &vif->status);
622 	if (netif_running(vif->dev))
623 		xenvif_up(vif);
624 	rtnl_unlock();
625 }
626 
627 int xenvif_connect_ctrl(struct xenvif *vif, grant_ref_t ring_ref,
628 			unsigned int evtchn)
629 {
630 	struct net_device *dev = vif->dev;
631 	void *addr;
632 	struct xen_netif_ctrl_sring *shared;
633 	RING_IDX rsp_prod, req_prod;
634 	int err;
635 
636 	err = xenbus_map_ring_valloc(xenvif_to_xenbus_device(vif),
637 				     &ring_ref, 1, &addr);
638 	if (err)
639 		goto err;
640 
641 	shared = (struct xen_netif_ctrl_sring *)addr;
642 	rsp_prod = READ_ONCE(shared->rsp_prod);
643 	req_prod = READ_ONCE(shared->req_prod);
644 
645 	BACK_RING_ATTACH(&vif->ctrl, shared, rsp_prod, XEN_PAGE_SIZE);
646 
647 	err = -EIO;
648 	if (req_prod - rsp_prod > RING_SIZE(&vif->ctrl))
649 		goto err_unmap;
650 
651 	err = bind_interdomain_evtchn_to_irq_lateeoi(vif->domid, evtchn);
652 	if (err < 0)
653 		goto err_unmap;
654 
655 	vif->ctrl_irq = err;
656 
657 	xenvif_init_hash(vif);
658 
659 	err = request_threaded_irq(vif->ctrl_irq, NULL, xenvif_ctrl_irq_fn,
660 				   IRQF_ONESHOT, "xen-netback-ctrl", vif);
661 	if (err) {
662 		pr_warn("Could not setup irq handler for %s\n", dev->name);
663 		goto err_deinit;
664 	}
665 
666 	return 0;
667 
668 err_deinit:
669 	xenvif_deinit_hash(vif);
670 	unbind_from_irqhandler(vif->ctrl_irq, vif);
671 	vif->ctrl_irq = 0;
672 
673 err_unmap:
674 	xenbus_unmap_ring_vfree(xenvif_to_xenbus_device(vif),
675 				vif->ctrl.sring);
676 	vif->ctrl.sring = NULL;
677 
678 err:
679 	return err;
680 }
681 
682 static void xenvif_disconnect_queue(struct xenvif_queue *queue)
683 {
684 	if (queue->task) {
685 		kthread_stop(queue->task);
686 		queue->task = NULL;
687 	}
688 
689 	if (queue->dealloc_task) {
690 		kthread_stop(queue->dealloc_task);
691 		queue->dealloc_task = NULL;
692 	}
693 
694 	if (queue->napi.poll) {
695 		netif_napi_del(&queue->napi);
696 		queue->napi.poll = NULL;
697 	}
698 
699 	if (queue->tx_irq) {
700 		unbind_from_irqhandler(queue->tx_irq, queue);
701 		if (queue->tx_irq == queue->rx_irq)
702 			queue->rx_irq = 0;
703 		queue->tx_irq = 0;
704 	}
705 
706 	if (queue->rx_irq) {
707 		unbind_from_irqhandler(queue->rx_irq, queue);
708 		queue->rx_irq = 0;
709 	}
710 
711 	xenvif_unmap_frontend_data_rings(queue);
712 }
713 
714 int xenvif_connect_data(struct xenvif_queue *queue,
715 			unsigned long tx_ring_ref,
716 			unsigned long rx_ring_ref,
717 			unsigned int tx_evtchn,
718 			unsigned int rx_evtchn)
719 {
720 	struct task_struct *task;
721 	int err;
722 
723 	BUG_ON(queue->tx_irq);
724 	BUG_ON(queue->task);
725 	BUG_ON(queue->dealloc_task);
726 
727 	err = xenvif_map_frontend_data_rings(queue, tx_ring_ref,
728 					     rx_ring_ref);
729 	if (err < 0)
730 		goto err;
731 
732 	init_waitqueue_head(&queue->wq);
733 	init_waitqueue_head(&queue->dealloc_wq);
734 	atomic_set(&queue->inflight_packets, 0);
735 
736 	netif_napi_add(queue->vif->dev, &queue->napi, xenvif_poll,
737 			XENVIF_NAPI_WEIGHT);
738 
739 	queue->stalled = true;
740 
741 	task = kthread_run(xenvif_kthread_guest_rx, queue,
742 			   "%s-guest-rx", queue->name);
743 	if (IS_ERR(task))
744 		goto kthread_err;
745 	queue->task = task;
746 
747 	task = kthread_run(xenvif_dealloc_kthread, queue,
748 			   "%s-dealloc", queue->name);
749 	if (IS_ERR(task))
750 		goto kthread_err;
751 	queue->dealloc_task = task;
752 
753 	if (tx_evtchn == rx_evtchn) {
754 		/* feature-split-event-channels == 0 */
755 		err = bind_interdomain_evtchn_to_irqhandler_lateeoi(
756 			queue->vif->domid, tx_evtchn, xenvif_interrupt, 0,
757 			queue->name, queue);
758 		if (err < 0)
759 			goto err;
760 		queue->tx_irq = queue->rx_irq = err;
761 		disable_irq(queue->tx_irq);
762 	} else {
763 		/* feature-split-event-channels == 1 */
764 		snprintf(queue->tx_irq_name, sizeof(queue->tx_irq_name),
765 			 "%s-tx", queue->name);
766 		err = bind_interdomain_evtchn_to_irqhandler_lateeoi(
767 			queue->vif->domid, tx_evtchn, xenvif_tx_interrupt, 0,
768 			queue->tx_irq_name, queue);
769 		if (err < 0)
770 			goto err;
771 		queue->tx_irq = err;
772 		disable_irq(queue->tx_irq);
773 
774 		snprintf(queue->rx_irq_name, sizeof(queue->rx_irq_name),
775 			 "%s-rx", queue->name);
776 		err = bind_interdomain_evtchn_to_irqhandler_lateeoi(
777 			queue->vif->domid, rx_evtchn, xenvif_rx_interrupt, 0,
778 			queue->rx_irq_name, queue);
779 		if (err < 0)
780 			goto err;
781 		queue->rx_irq = err;
782 		disable_irq(queue->rx_irq);
783 	}
784 
785 	return 0;
786 
787 kthread_err:
788 	pr_warn("Could not allocate kthread for %s\n", queue->name);
789 	err = PTR_ERR(task);
790 err:
791 	xenvif_disconnect_queue(queue);
792 	return err;
793 }
794 
795 void xenvif_carrier_off(struct xenvif *vif)
796 {
797 	struct net_device *dev = vif->dev;
798 
799 	rtnl_lock();
800 	if (test_and_clear_bit(VIF_STATUS_CONNECTED, &vif->status)) {
801 		netif_carrier_off(dev); /* discard queued packets */
802 		if (netif_running(dev))
803 			xenvif_down(vif);
804 	}
805 	rtnl_unlock();
806 }
807 
808 void xenvif_disconnect_data(struct xenvif *vif)
809 {
810 	struct xenvif_queue *queue = NULL;
811 	unsigned int num_queues = vif->num_queues;
812 	unsigned int queue_index;
813 
814 	xenvif_carrier_off(vif);
815 
816 	for (queue_index = 0; queue_index < num_queues; ++queue_index) {
817 		queue = &vif->queues[queue_index];
818 
819 		xenvif_disconnect_queue(queue);
820 	}
821 
822 	xenvif_mcast_addr_list_free(vif);
823 }
824 
825 void xenvif_disconnect_ctrl(struct xenvif *vif)
826 {
827 	if (vif->ctrl_irq) {
828 		xenvif_deinit_hash(vif);
829 		unbind_from_irqhandler(vif->ctrl_irq, vif);
830 		vif->ctrl_irq = 0;
831 	}
832 
833 	if (vif->ctrl.sring) {
834 		xenbus_unmap_ring_vfree(xenvif_to_xenbus_device(vif),
835 					vif->ctrl.sring);
836 		vif->ctrl.sring = NULL;
837 	}
838 }
839 
840 /* Reverse the relevant parts of xenvif_init_queue().
841  * Used for queue teardown from xenvif_free(), and on the
842  * error handling paths in xenbus.c:connect().
843  */
844 void xenvif_deinit_queue(struct xenvif_queue *queue)
845 {
846 	gnttab_free_pages(MAX_PENDING_REQS, queue->mmap_pages);
847 }
848 
849 void xenvif_free(struct xenvif *vif)
850 {
851 	struct xenvif_queue *queues = vif->queues;
852 	unsigned int num_queues = vif->num_queues;
853 	unsigned int queue_index;
854 
855 	unregister_netdev(vif->dev);
856 	free_netdev(vif->dev);
857 
858 	for (queue_index = 0; queue_index < num_queues; ++queue_index)
859 		xenvif_deinit_queue(&queues[queue_index]);
860 	vfree(queues);
861 
862 	module_put(THIS_MODULE);
863 }
864