1 /*
2  *  qla_target.c SCSI LLD infrastructure for QLogic 22xx/23xx/24xx/25xx
3  *
4  *  based on qla2x00t.c code:
5  *
6  *  Copyright (C) 2004 - 2010 Vladislav Bolkhovitin <vst@vlnb.net>
7  *  Copyright (C) 2004 - 2005 Leonid Stoljar
8  *  Copyright (C) 2006 Nathaniel Clark <nate@misrule.us>
9  *  Copyright (C) 2006 - 2010 ID7 Ltd.
10  *
11  *  Forward port and refactoring to modern qla2xxx and target/configfs
12  *
13  *  Copyright (C) 2010-2011 Nicholas A. Bellinger <nab@kernel.org>
14  *
15  *  This program is free software; you can redistribute it and/or
16  *  modify it under the terms of the GNU General Public License
17  *  as published by the Free Software Foundation, version 2
18  *  of the License.
19  *
20  *  This program is distributed in the hope that it will be useful,
21  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
22  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
23  *  GNU General Public License for more details.
24  */
25 
26 #include <linux/module.h>
27 #include <linux/init.h>
28 #include <linux/types.h>
29 #include <linux/blkdev.h>
30 #include <linux/interrupt.h>
31 #include <linux/pci.h>
32 #include <linux/delay.h>
33 #include <linux/list.h>
34 #include <linux/workqueue.h>
35 #include <asm/unaligned.h>
36 #include <scsi/scsi.h>
37 #include <scsi/scsi_host.h>
38 #include <scsi/scsi_tcq.h>
39 #include <target/target_core_base.h>
40 #include <target/target_core_fabric.h>
41 
42 #include "qla_def.h"
43 #include "qla_target.h"
44 
45 static char *qlini_mode = QLA2XXX_INI_MODE_STR_ENABLED;
46 module_param(qlini_mode, charp, S_IRUGO);
47 MODULE_PARM_DESC(qlini_mode,
48 	"Determines when initiator mode will be enabled. Possible values: "
49 	"\"exclusive\" - initiator mode will be enabled on load, "
50 	"disabled on enabling target mode and then on disabling target mode "
51 	"enabled back; "
52 	"\"disabled\" - initiator mode will never be enabled; "
53 	"\"enabled\" (default) - initiator mode will always stay enabled.");
54 
55 int ql2x_ini_mode = QLA2XXX_INI_MODE_EXCLUSIVE;
56 
57 /*
58  * From scsi/fc/fc_fcp.h
59  */
60 enum fcp_resp_rsp_codes {
61 	FCP_TMF_CMPL = 0,
62 	FCP_DATA_LEN_INVALID = 1,
63 	FCP_CMND_FIELDS_INVALID = 2,
64 	FCP_DATA_PARAM_MISMATCH = 3,
65 	FCP_TMF_REJECTED = 4,
66 	FCP_TMF_FAILED = 5,
67 	FCP_TMF_INVALID_LUN = 9,
68 };
69 
70 /*
71  * fc_pri_ta from scsi/fc/fc_fcp.h
72  */
73 #define FCP_PTA_SIMPLE      0   /* simple task attribute */
74 #define FCP_PTA_HEADQ       1   /* head of queue task attribute */
75 #define FCP_PTA_ORDERED     2   /* ordered task attribute */
76 #define FCP_PTA_ACA         4   /* auto. contingent allegiance */
77 #define FCP_PTA_MASK        7   /* mask for task attribute field */
78 #define FCP_PRI_SHIFT       3   /* priority field starts in bit 3 */
79 #define FCP_PRI_RESVD_MASK  0x80        /* reserved bits in priority field */
80 
81 /*
82  * This driver calls qla2x00_alloc_iocbs() and qla2x00_issue_marker(), which
83  * must be called under HW lock and could unlock/lock it inside.
84  * It isn't an issue, since in the current implementation on the time when
85  * those functions are called:
86  *
87  *   - Either context is IRQ and only IRQ handler can modify HW data,
88  *     including rings related fields,
89  *
90  *   - Or access to target mode variables from struct qla_tgt doesn't
91  *     cross those functions boundaries, except tgt_stop, which
92  *     additionally protected by irq_cmd_count.
93  */
94 /* Predefs for callbacks handed to qla2xxx LLD */
95 static void qlt_24xx_atio_pkt(struct scsi_qla_host *ha,
96 	struct atio_from_isp *pkt);
97 static void qlt_response_pkt(struct scsi_qla_host *ha, response_t *pkt);
98 static int qlt_issue_task_mgmt(struct qla_tgt_sess *sess, uint32_t lun,
99 	int fn, void *iocb, int flags);
100 static void qlt_send_term_exchange(struct scsi_qla_host *ha, struct qla_tgt_cmd
101 	*cmd, struct atio_from_isp *atio, int ha_locked);
102 static void qlt_reject_free_srr_imm(struct scsi_qla_host *ha,
103 	struct qla_tgt_srr_imm *imm, int ha_lock);
104 /*
105  * Global Variables
106  */
107 static struct kmem_cache *qla_tgt_cmd_cachep;
108 static struct kmem_cache *qla_tgt_mgmt_cmd_cachep;
109 static mempool_t *qla_tgt_mgmt_cmd_mempool;
110 static struct workqueue_struct *qla_tgt_wq;
111 static DEFINE_MUTEX(qla_tgt_mutex);
112 static LIST_HEAD(qla_tgt_glist);
113 
114 /* ha->hardware_lock supposed to be held on entry (to protect tgt->sess_list) */
115 static struct qla_tgt_sess *qlt_find_sess_by_port_name(
116 	struct qla_tgt *tgt,
117 	const uint8_t *port_name)
118 {
119 	struct qla_tgt_sess *sess;
120 
121 	list_for_each_entry(sess, &tgt->sess_list, sess_list_entry) {
122 		if (!memcmp(sess->port_name, port_name, WWN_SIZE))
123 			return sess;
124 	}
125 
126 	return NULL;
127 }
128 
129 /* Might release hw lock, then reaquire!! */
130 static inline int qlt_issue_marker(struct scsi_qla_host *vha, int vha_locked)
131 {
132 	/* Send marker if required */
133 	if (unlikely(vha->marker_needed != 0)) {
134 		int rc = qla2x00_issue_marker(vha, vha_locked);
135 		if (rc != QLA_SUCCESS) {
136 			ql_dbg(ql_dbg_tgt, vha, 0xe03d,
137 			    "qla_target(%d): issue_marker() failed\n",
138 			    vha->vp_idx);
139 		}
140 		return rc;
141 	}
142 	return QLA_SUCCESS;
143 }
144 
145 static inline
146 struct scsi_qla_host *qlt_find_host_by_d_id(struct scsi_qla_host *vha,
147 	uint8_t *d_id)
148 {
149 	struct qla_hw_data *ha = vha->hw;
150 	uint8_t vp_idx;
151 
152 	if ((vha->d_id.b.area != d_id[1]) || (vha->d_id.b.domain != d_id[0]))
153 		return NULL;
154 
155 	if (vha->d_id.b.al_pa == d_id[2])
156 		return vha;
157 
158 	BUG_ON(ha->tgt.tgt_vp_map == NULL);
159 	vp_idx = ha->tgt.tgt_vp_map[d_id[2]].idx;
160 	if (likely(test_bit(vp_idx, ha->vp_idx_map)))
161 		return ha->tgt.tgt_vp_map[vp_idx].vha;
162 
163 	return NULL;
164 }
165 
166 static inline
167 struct scsi_qla_host *qlt_find_host_by_vp_idx(struct scsi_qla_host *vha,
168 	uint16_t vp_idx)
169 {
170 	struct qla_hw_data *ha = vha->hw;
171 
172 	if (vha->vp_idx == vp_idx)
173 		return vha;
174 
175 	BUG_ON(ha->tgt.tgt_vp_map == NULL);
176 	if (likely(test_bit(vp_idx, ha->vp_idx_map)))
177 		return ha->tgt.tgt_vp_map[vp_idx].vha;
178 
179 	return NULL;
180 }
181 
182 void qlt_24xx_atio_pkt_all_vps(struct scsi_qla_host *vha,
183 	struct atio_from_isp *atio)
184 {
185 	switch (atio->u.raw.entry_type) {
186 	case ATIO_TYPE7:
187 	{
188 		struct scsi_qla_host *host = qlt_find_host_by_d_id(vha,
189 		    atio->u.isp24.fcp_hdr.d_id);
190 		if (unlikely(NULL == host)) {
191 			ql_dbg(ql_dbg_tgt, vha, 0xe03e,
192 			    "qla_target(%d): Received ATIO_TYPE7 "
193 			    "with unknown d_id %x:%x:%x\n", vha->vp_idx,
194 			    atio->u.isp24.fcp_hdr.d_id[0],
195 			    atio->u.isp24.fcp_hdr.d_id[1],
196 			    atio->u.isp24.fcp_hdr.d_id[2]);
197 			break;
198 		}
199 		qlt_24xx_atio_pkt(host, atio);
200 		break;
201 	}
202 
203 	case IMMED_NOTIFY_TYPE:
204 	{
205 		struct scsi_qla_host *host = vha;
206 		struct imm_ntfy_from_isp *entry =
207 		    (struct imm_ntfy_from_isp *)atio;
208 
209 		if ((entry->u.isp24.vp_index != 0xFF) &&
210 		    (entry->u.isp24.nport_handle != 0xFFFF)) {
211 			host = qlt_find_host_by_vp_idx(vha,
212 			    entry->u.isp24.vp_index);
213 			if (unlikely(!host)) {
214 				ql_dbg(ql_dbg_tgt, vha, 0xe03f,
215 				    "qla_target(%d): Received "
216 				    "ATIO (IMMED_NOTIFY_TYPE) "
217 				    "with unknown vp_index %d\n",
218 				    vha->vp_idx, entry->u.isp24.vp_index);
219 				break;
220 			}
221 		}
222 		qlt_24xx_atio_pkt(host, atio);
223 		break;
224 	}
225 
226 	default:
227 		ql_dbg(ql_dbg_tgt, vha, 0xe040,
228 		    "qla_target(%d): Received unknown ATIO atio "
229 		    "type %x\n", vha->vp_idx, atio->u.raw.entry_type);
230 		break;
231 	}
232 
233 	return;
234 }
235 
236 void qlt_response_pkt_all_vps(struct scsi_qla_host *vha, response_t *pkt)
237 {
238 	switch (pkt->entry_type) {
239 	case CTIO_TYPE7:
240 	{
241 		struct ctio7_from_24xx *entry = (struct ctio7_from_24xx *)pkt;
242 		struct scsi_qla_host *host = qlt_find_host_by_vp_idx(vha,
243 		    entry->vp_index);
244 		if (unlikely(!host)) {
245 			ql_dbg(ql_dbg_tgt, vha, 0xe041,
246 			    "qla_target(%d): Response pkt (CTIO_TYPE7) "
247 			    "received, with unknown vp_index %d\n",
248 			    vha->vp_idx, entry->vp_index);
249 			break;
250 		}
251 		qlt_response_pkt(host, pkt);
252 		break;
253 	}
254 
255 	case IMMED_NOTIFY_TYPE:
256 	{
257 		struct scsi_qla_host *host = vha;
258 		struct imm_ntfy_from_isp *entry =
259 		    (struct imm_ntfy_from_isp *)pkt;
260 
261 		host = qlt_find_host_by_vp_idx(vha, entry->u.isp24.vp_index);
262 		if (unlikely(!host)) {
263 			ql_dbg(ql_dbg_tgt, vha, 0xe042,
264 			    "qla_target(%d): Response pkt (IMMED_NOTIFY_TYPE) "
265 			    "received, with unknown vp_index %d\n",
266 			    vha->vp_idx, entry->u.isp24.vp_index);
267 			break;
268 		}
269 		qlt_response_pkt(host, pkt);
270 		break;
271 	}
272 
273 	case NOTIFY_ACK_TYPE:
274 	{
275 		struct scsi_qla_host *host = vha;
276 		struct nack_to_isp *entry = (struct nack_to_isp *)pkt;
277 
278 		if (0xFF != entry->u.isp24.vp_index) {
279 			host = qlt_find_host_by_vp_idx(vha,
280 			    entry->u.isp24.vp_index);
281 			if (unlikely(!host)) {
282 				ql_dbg(ql_dbg_tgt, vha, 0xe043,
283 				    "qla_target(%d): Response "
284 				    "pkt (NOTIFY_ACK_TYPE) "
285 				    "received, with unknown "
286 				    "vp_index %d\n", vha->vp_idx,
287 				    entry->u.isp24.vp_index);
288 				break;
289 			}
290 		}
291 		qlt_response_pkt(host, pkt);
292 		break;
293 	}
294 
295 	case ABTS_RECV_24XX:
296 	{
297 		struct abts_recv_from_24xx *entry =
298 		    (struct abts_recv_from_24xx *)pkt;
299 		struct scsi_qla_host *host = qlt_find_host_by_vp_idx(vha,
300 		    entry->vp_index);
301 		if (unlikely(!host)) {
302 			ql_dbg(ql_dbg_tgt, vha, 0xe044,
303 			    "qla_target(%d): Response pkt "
304 			    "(ABTS_RECV_24XX) received, with unknown "
305 			    "vp_index %d\n", vha->vp_idx, entry->vp_index);
306 			break;
307 		}
308 		qlt_response_pkt(host, pkt);
309 		break;
310 	}
311 
312 	case ABTS_RESP_24XX:
313 	{
314 		struct abts_resp_to_24xx *entry =
315 		    (struct abts_resp_to_24xx *)pkt;
316 		struct scsi_qla_host *host = qlt_find_host_by_vp_idx(vha,
317 		    entry->vp_index);
318 		if (unlikely(!host)) {
319 			ql_dbg(ql_dbg_tgt, vha, 0xe045,
320 			    "qla_target(%d): Response pkt "
321 			    "(ABTS_RECV_24XX) received, with unknown "
322 			    "vp_index %d\n", vha->vp_idx, entry->vp_index);
323 			break;
324 		}
325 		qlt_response_pkt(host, pkt);
326 		break;
327 	}
328 
329 	default:
330 		qlt_response_pkt(vha, pkt);
331 		break;
332 	}
333 
334 }
335 
336 static void qlt_free_session_done(struct work_struct *work)
337 {
338 	struct qla_tgt_sess *sess = container_of(work, struct qla_tgt_sess,
339 	    free_work);
340 	struct qla_tgt *tgt = sess->tgt;
341 	struct scsi_qla_host *vha = sess->vha;
342 	struct qla_hw_data *ha = vha->hw;
343 
344 	BUG_ON(!tgt);
345 	/*
346 	 * Release the target session for FC Nexus from fabric module code.
347 	 */
348 	if (sess->se_sess != NULL)
349 		ha->tgt.tgt_ops->free_session(sess);
350 
351 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf001,
352 	    "Unregistration of sess %p finished\n", sess);
353 
354 	kfree(sess);
355 	/*
356 	 * We need to protect against race, when tgt is freed before or
357 	 * inside wake_up()
358 	 */
359 	tgt->sess_count--;
360 	if (tgt->sess_count == 0)
361 		wake_up_all(&tgt->waitQ);
362 }
363 
364 /* ha->hardware_lock supposed to be held on entry */
365 void qlt_unreg_sess(struct qla_tgt_sess *sess)
366 {
367 	struct scsi_qla_host *vha = sess->vha;
368 
369 	vha->hw->tgt.tgt_ops->clear_nacl_from_fcport_map(sess);
370 
371 	list_del(&sess->sess_list_entry);
372 	if (sess->deleted)
373 		list_del(&sess->del_list_entry);
374 
375 	INIT_WORK(&sess->free_work, qlt_free_session_done);
376 	schedule_work(&sess->free_work);
377 }
378 EXPORT_SYMBOL(qlt_unreg_sess);
379 
380 /* ha->hardware_lock supposed to be held on entry */
381 static int qlt_reset(struct scsi_qla_host *vha, void *iocb, int mcmd)
382 {
383 	struct qla_hw_data *ha = vha->hw;
384 	struct qla_tgt_sess *sess = NULL;
385 	uint32_t unpacked_lun, lun = 0;
386 	uint16_t loop_id;
387 	int res = 0;
388 	struct imm_ntfy_from_isp *n = (struct imm_ntfy_from_isp *)iocb;
389 	struct atio_from_isp *a = (struct atio_from_isp *)iocb;
390 
391 	loop_id = le16_to_cpu(n->u.isp24.nport_handle);
392 	if (loop_id == 0xFFFF) {
393 #if 0 /* FIXME: Re-enable Global event handling.. */
394 		/* Global event */
395 		atomic_inc(&ha->tgt.qla_tgt->tgt_global_resets_count);
396 		qlt_clear_tgt_db(ha->tgt.qla_tgt, 1);
397 		if (!list_empty(&ha->tgt.qla_tgt->sess_list)) {
398 			sess = list_entry(ha->tgt.qla_tgt->sess_list.next,
399 			    typeof(*sess), sess_list_entry);
400 			switch (mcmd) {
401 			case QLA_TGT_NEXUS_LOSS_SESS:
402 				mcmd = QLA_TGT_NEXUS_LOSS;
403 				break;
404 			case QLA_TGT_ABORT_ALL_SESS:
405 				mcmd = QLA_TGT_ABORT_ALL;
406 				break;
407 			case QLA_TGT_NEXUS_LOSS:
408 			case QLA_TGT_ABORT_ALL:
409 				break;
410 			default:
411 				ql_dbg(ql_dbg_tgt, vha, 0xe046,
412 				    "qla_target(%d): Not allowed "
413 				    "command %x in %s", vha->vp_idx,
414 				    mcmd, __func__);
415 				sess = NULL;
416 				break;
417 			}
418 		} else
419 			sess = NULL;
420 #endif
421 	} else {
422 		sess = ha->tgt.tgt_ops->find_sess_by_loop_id(vha, loop_id);
423 	}
424 
425 	ql_dbg(ql_dbg_tgt, vha, 0xe000,
426 	    "Using sess for qla_tgt_reset: %p\n", sess);
427 	if (!sess) {
428 		res = -ESRCH;
429 		return res;
430 	}
431 
432 	ql_dbg(ql_dbg_tgt, vha, 0xe047,
433 	    "scsi(%ld): resetting (session %p from port "
434 	    "%02x:%02x:%02x:%02x:%02x:%02x:%02x:%02x, "
435 	    "mcmd %x, loop_id %d)\n", vha->host_no, sess,
436 	    sess->port_name[0], sess->port_name[1],
437 	    sess->port_name[2], sess->port_name[3],
438 	    sess->port_name[4], sess->port_name[5],
439 	    sess->port_name[6], sess->port_name[7],
440 	    mcmd, loop_id);
441 
442 	lun = a->u.isp24.fcp_cmnd.lun;
443 	unpacked_lun = scsilun_to_int((struct scsi_lun *)&lun);
444 
445 	return qlt_issue_task_mgmt(sess, unpacked_lun, mcmd,
446 	    iocb, QLA24XX_MGMT_SEND_NACK);
447 }
448 
449 /* ha->hardware_lock supposed to be held on entry */
450 static void qlt_schedule_sess_for_deletion(struct qla_tgt_sess *sess,
451 	bool immediate)
452 {
453 	struct qla_tgt *tgt = sess->tgt;
454 	uint32_t dev_loss_tmo = tgt->ha->port_down_retry_count + 5;
455 
456 	if (sess->deleted)
457 		return;
458 
459 	ql_dbg(ql_dbg_tgt, sess->vha, 0xe001,
460 	    "Scheduling sess %p for deletion\n", sess);
461 	list_add_tail(&sess->del_list_entry, &tgt->del_sess_list);
462 	sess->deleted = 1;
463 
464 	if (immediate)
465 		dev_loss_tmo = 0;
466 
467 	sess->expires = jiffies + dev_loss_tmo * HZ;
468 
469 	ql_dbg(ql_dbg_tgt, sess->vha, 0xe048,
470 	    "qla_target(%d): session for port %02x:%02x:%02x:"
471 	    "%02x:%02x:%02x:%02x:%02x (loop ID %d) scheduled for "
472 	    "deletion in %u secs (expires: %lu) immed: %d\n",
473 	    sess->vha->vp_idx,
474 	    sess->port_name[0], sess->port_name[1],
475 	    sess->port_name[2], sess->port_name[3],
476 	    sess->port_name[4], sess->port_name[5],
477 	    sess->port_name[6], sess->port_name[7],
478 	    sess->loop_id, dev_loss_tmo, sess->expires, immediate);
479 
480 	if (immediate)
481 		schedule_delayed_work(&tgt->sess_del_work, 0);
482 	else
483 		schedule_delayed_work(&tgt->sess_del_work,
484 		    jiffies - sess->expires);
485 }
486 
487 /* ha->hardware_lock supposed to be held on entry */
488 static void qlt_clear_tgt_db(struct qla_tgt *tgt, bool local_only)
489 {
490 	struct qla_tgt_sess *sess;
491 
492 	list_for_each_entry(sess, &tgt->sess_list, sess_list_entry)
493 		qlt_schedule_sess_for_deletion(sess, true);
494 
495 	/* At this point tgt could be already dead */
496 }
497 
498 static int qla24xx_get_loop_id(struct scsi_qla_host *vha, const uint8_t *s_id,
499 	uint16_t *loop_id)
500 {
501 	struct qla_hw_data *ha = vha->hw;
502 	dma_addr_t gid_list_dma;
503 	struct gid_list_info *gid_list;
504 	char *id_iter;
505 	int res, rc, i;
506 	uint16_t entries;
507 
508 	gid_list = dma_alloc_coherent(&ha->pdev->dev, qla2x00_gid_list_size(ha),
509 	    &gid_list_dma, GFP_KERNEL);
510 	if (!gid_list) {
511 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf044,
512 		    "qla_target(%d): DMA Alloc failed of %u\n",
513 		    vha->vp_idx, qla2x00_gid_list_size(ha));
514 		return -ENOMEM;
515 	}
516 
517 	/* Get list of logged in devices */
518 	rc = qla2x00_get_id_list(vha, gid_list, gid_list_dma, &entries);
519 	if (rc != QLA_SUCCESS) {
520 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf045,
521 		    "qla_target(%d): get_id_list() failed: %x\n",
522 		    vha->vp_idx, rc);
523 		res = -1;
524 		goto out_free_id_list;
525 	}
526 
527 	id_iter = (char *)gid_list;
528 	res = -1;
529 	for (i = 0; i < entries; i++) {
530 		struct gid_list_info *gid = (struct gid_list_info *)id_iter;
531 		if ((gid->al_pa == s_id[2]) &&
532 		    (gid->area == s_id[1]) &&
533 		    (gid->domain == s_id[0])) {
534 			*loop_id = le16_to_cpu(gid->loop_id);
535 			res = 0;
536 			break;
537 		}
538 		id_iter += ha->gid_list_info_size;
539 	}
540 
541 out_free_id_list:
542 	dma_free_coherent(&ha->pdev->dev, qla2x00_gid_list_size(ha),
543 	    gid_list, gid_list_dma);
544 	return res;
545 }
546 
547 /* ha->hardware_lock supposed to be held on entry */
548 static void qlt_undelete_sess(struct qla_tgt_sess *sess)
549 {
550 	BUG_ON(!sess->deleted);
551 
552 	list_del(&sess->del_list_entry);
553 	sess->deleted = 0;
554 }
555 
556 static void qlt_del_sess_work_fn(struct delayed_work *work)
557 {
558 	struct qla_tgt *tgt = container_of(work, struct qla_tgt,
559 	    sess_del_work);
560 	struct scsi_qla_host *vha = tgt->vha;
561 	struct qla_hw_data *ha = vha->hw;
562 	struct qla_tgt_sess *sess;
563 	unsigned long flags;
564 
565 	spin_lock_irqsave(&ha->hardware_lock, flags);
566 	while (!list_empty(&tgt->del_sess_list)) {
567 		sess = list_entry(tgt->del_sess_list.next, typeof(*sess),
568 		    del_list_entry);
569 		if (time_after_eq(jiffies, sess->expires)) {
570 			qlt_undelete_sess(sess);
571 
572 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf004,
573 			    "Timeout: sess %p about to be deleted\n",
574 			    sess);
575 			ha->tgt.tgt_ops->shutdown_sess(sess);
576 			ha->tgt.tgt_ops->put_sess(sess);
577 		} else {
578 			schedule_delayed_work(&tgt->sess_del_work,
579 			    jiffies - sess->expires);
580 			break;
581 		}
582 	}
583 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
584 }
585 
586 /*
587  * Adds an extra ref to allow to drop hw lock after adding sess to the list.
588  * Caller must put it.
589  */
590 static struct qla_tgt_sess *qlt_create_sess(
591 	struct scsi_qla_host *vha,
592 	fc_port_t *fcport,
593 	bool local)
594 {
595 	struct qla_hw_data *ha = vha->hw;
596 	struct qla_tgt_sess *sess;
597 	unsigned long flags;
598 	unsigned char be_sid[3];
599 
600 	/* Check to avoid double sessions */
601 	spin_lock_irqsave(&ha->hardware_lock, flags);
602 	list_for_each_entry(sess, &ha->tgt.qla_tgt->sess_list,
603 				sess_list_entry) {
604 		if (!memcmp(sess->port_name, fcport->port_name, WWN_SIZE)) {
605 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf005,
606 			    "Double sess %p found (s_id %x:%x:%x, "
607 			    "loop_id %d), updating to d_id %x:%x:%x, "
608 			    "loop_id %d", sess, sess->s_id.b.domain,
609 			    sess->s_id.b.al_pa, sess->s_id.b.area,
610 			    sess->loop_id, fcport->d_id.b.domain,
611 			    fcport->d_id.b.al_pa, fcport->d_id.b.area,
612 			    fcport->loop_id);
613 
614 			if (sess->deleted)
615 				qlt_undelete_sess(sess);
616 
617 			kref_get(&sess->se_sess->sess_kref);
618 			ha->tgt.tgt_ops->update_sess(sess, fcport->d_id, fcport->loop_id,
619 						(fcport->flags & FCF_CONF_COMP_SUPPORTED));
620 
621 			if (sess->local && !local)
622 				sess->local = 0;
623 			spin_unlock_irqrestore(&ha->hardware_lock, flags);
624 
625 			return sess;
626 		}
627 	}
628 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
629 
630 	sess = kzalloc(sizeof(*sess), GFP_KERNEL);
631 	if (!sess) {
632 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf04a,
633 		    "qla_target(%u): session allocation failed, "
634 		    "all commands from port %02x:%02x:%02x:%02x:"
635 		    "%02x:%02x:%02x:%02x will be refused", vha->vp_idx,
636 		    fcport->port_name[0], fcport->port_name[1],
637 		    fcport->port_name[2], fcport->port_name[3],
638 		    fcport->port_name[4], fcport->port_name[5],
639 		    fcport->port_name[6], fcport->port_name[7]);
640 
641 		return NULL;
642 	}
643 	sess->tgt = ha->tgt.qla_tgt;
644 	sess->vha = vha;
645 	sess->s_id = fcport->d_id;
646 	sess->loop_id = fcport->loop_id;
647 	sess->local = local;
648 
649 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf006,
650 	    "Adding sess %p to tgt %p via ->check_initiator_node_acl()\n",
651 	    sess, ha->tgt.qla_tgt);
652 
653 	be_sid[0] = sess->s_id.b.domain;
654 	be_sid[1] = sess->s_id.b.area;
655 	be_sid[2] = sess->s_id.b.al_pa;
656 	/*
657 	 * Determine if this fc_port->port_name is allowed to access
658 	 * target mode using explict NodeACLs+MappedLUNs, or using
659 	 * TPG demo mode.  If this is successful a target mode FC nexus
660 	 * is created.
661 	 */
662 	if (ha->tgt.tgt_ops->check_initiator_node_acl(vha,
663 	    &fcport->port_name[0], sess, &be_sid[0], fcport->loop_id) < 0) {
664 		kfree(sess);
665 		return NULL;
666 	}
667 	/*
668 	 * Take an extra reference to ->sess_kref here to handle qla_tgt_sess
669 	 * access across ->hardware_lock reaquire.
670 	 */
671 	kref_get(&sess->se_sess->sess_kref);
672 
673 	sess->conf_compl_supported = (fcport->flags & FCF_CONF_COMP_SUPPORTED);
674 	BUILD_BUG_ON(sizeof(sess->port_name) != sizeof(fcport->port_name));
675 	memcpy(sess->port_name, fcport->port_name, sizeof(sess->port_name));
676 
677 	spin_lock_irqsave(&ha->hardware_lock, flags);
678 	list_add_tail(&sess->sess_list_entry, &ha->tgt.qla_tgt->sess_list);
679 	ha->tgt.qla_tgt->sess_count++;
680 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
681 
682 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf04b,
683 	    "qla_target(%d): %ssession for wwn %02x:%02x:%02x:%02x:"
684 	    "%02x:%02x:%02x:%02x (loop_id %d, s_id %x:%x:%x, confirmed"
685 	    " completion %ssupported) added\n",
686 	    vha->vp_idx, local ?  "local " : "", fcport->port_name[0],
687 	    fcport->port_name[1], fcport->port_name[2], fcport->port_name[3],
688 	    fcport->port_name[4], fcport->port_name[5], fcport->port_name[6],
689 	    fcport->port_name[7], fcport->loop_id, sess->s_id.b.domain,
690 	    sess->s_id.b.area, sess->s_id.b.al_pa, sess->conf_compl_supported ?
691 	    "" : "not ");
692 
693 	return sess;
694 }
695 
696 /*
697  * Called from drivers/scsi/qla2xxx/qla_init.c:qla2x00_reg_remote_port()
698  */
699 void qlt_fc_port_added(struct scsi_qla_host *vha, fc_port_t *fcport)
700 {
701 	struct qla_hw_data *ha = vha->hw;
702 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
703 	struct qla_tgt_sess *sess;
704 	unsigned long flags;
705 
706 	if (!vha->hw->tgt.tgt_ops)
707 		return;
708 
709 	if (!tgt || (fcport->port_type != FCT_INITIATOR))
710 		return;
711 
712 	spin_lock_irqsave(&ha->hardware_lock, flags);
713 	if (tgt->tgt_stop) {
714 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
715 		return;
716 	}
717 	sess = qlt_find_sess_by_port_name(tgt, fcport->port_name);
718 	if (!sess) {
719 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
720 
721 		mutex_lock(&ha->tgt.tgt_mutex);
722 		sess = qlt_create_sess(vha, fcport, false);
723 		mutex_unlock(&ha->tgt.tgt_mutex);
724 
725 		spin_lock_irqsave(&ha->hardware_lock, flags);
726 	} else {
727 		kref_get(&sess->se_sess->sess_kref);
728 
729 		if (sess->deleted) {
730 			qlt_undelete_sess(sess);
731 
732 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf04c,
733 			    "qla_target(%u): %ssession for port %02x:"
734 			    "%02x:%02x:%02x:%02x:%02x:%02x:%02x (loop ID %d) "
735 			    "reappeared\n", vha->vp_idx, sess->local ? "local "
736 			    : "", sess->port_name[0], sess->port_name[1],
737 			    sess->port_name[2], sess->port_name[3],
738 			    sess->port_name[4], sess->port_name[5],
739 			    sess->port_name[6], sess->port_name[7],
740 			    sess->loop_id);
741 
742 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf007,
743 			    "Reappeared sess %p\n", sess);
744 		}
745 		ha->tgt.tgt_ops->update_sess(sess, fcport->d_id, fcport->loop_id,
746 					(fcport->flags & FCF_CONF_COMP_SUPPORTED));
747 	}
748 
749 	if (sess && sess->local) {
750 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf04d,
751 		    "qla_target(%u): local session for "
752 		    "port %02x:%02x:%02x:%02x:%02x:%02x:%02x:%02x "
753 		    "(loop ID %d) became global\n", vha->vp_idx,
754 		    fcport->port_name[0], fcport->port_name[1],
755 		    fcport->port_name[2], fcport->port_name[3],
756 		    fcport->port_name[4], fcport->port_name[5],
757 		    fcport->port_name[6], fcport->port_name[7],
758 		    sess->loop_id);
759 		sess->local = 0;
760 	}
761 	ha->tgt.tgt_ops->put_sess(sess);
762 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
763 }
764 
765 void qlt_fc_port_deleted(struct scsi_qla_host *vha, fc_port_t *fcport)
766 {
767 	struct qla_hw_data *ha = vha->hw;
768 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
769 	struct qla_tgt_sess *sess;
770 	unsigned long flags;
771 
772 	if (!vha->hw->tgt.tgt_ops)
773 		return;
774 
775 	if (!tgt || (fcport->port_type != FCT_INITIATOR))
776 		return;
777 
778 	spin_lock_irqsave(&ha->hardware_lock, flags);
779 	if (tgt->tgt_stop) {
780 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
781 		return;
782 	}
783 	sess = qlt_find_sess_by_port_name(tgt, fcport->port_name);
784 	if (!sess) {
785 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
786 		return;
787 	}
788 
789 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf008, "qla_tgt_fc_port_deleted %p", sess);
790 
791 	sess->local = 1;
792 	qlt_schedule_sess_for_deletion(sess, false);
793 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
794 }
795 
796 static inline int test_tgt_sess_count(struct qla_tgt *tgt)
797 {
798 	struct qla_hw_data *ha = tgt->ha;
799 	unsigned long flags;
800 	int res;
801 	/*
802 	 * We need to protect against race, when tgt is freed before or
803 	 * inside wake_up()
804 	 */
805 	spin_lock_irqsave(&ha->hardware_lock, flags);
806 	ql_dbg(ql_dbg_tgt, tgt->vha, 0xe002,
807 	    "tgt %p, empty(sess_list)=%d sess_count=%d\n",
808 	    tgt, list_empty(&tgt->sess_list), tgt->sess_count);
809 	res = (tgt->sess_count == 0);
810 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
811 
812 	return res;
813 }
814 
815 /* Called by tcm_qla2xxx configfs code */
816 void qlt_stop_phase1(struct qla_tgt *tgt)
817 {
818 	struct scsi_qla_host *vha = tgt->vha;
819 	struct qla_hw_data *ha = tgt->ha;
820 	unsigned long flags;
821 
822 	if (tgt->tgt_stop || tgt->tgt_stopped) {
823 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf04e,
824 		    "Already in tgt->tgt_stop or tgt_stopped state\n");
825 		dump_stack();
826 		return;
827 	}
828 
829 	ql_dbg(ql_dbg_tgt, vha, 0xe003, "Stopping target for host %ld(%p)\n",
830 	    vha->host_no, vha);
831 	/*
832 	 * Mutex needed to sync with qla_tgt_fc_port_[added,deleted].
833 	 * Lock is needed, because we still can get an incoming packet.
834 	 */
835 	mutex_lock(&ha->tgt.tgt_mutex);
836 	spin_lock_irqsave(&ha->hardware_lock, flags);
837 	tgt->tgt_stop = 1;
838 	qlt_clear_tgt_db(tgt, true);
839 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
840 	mutex_unlock(&ha->tgt.tgt_mutex);
841 
842 	flush_delayed_work(&tgt->sess_del_work);
843 
844 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf009,
845 	    "Waiting for sess works (tgt %p)", tgt);
846 	spin_lock_irqsave(&tgt->sess_work_lock, flags);
847 	while (!list_empty(&tgt->sess_works_list)) {
848 		spin_unlock_irqrestore(&tgt->sess_work_lock, flags);
849 		flush_scheduled_work();
850 		spin_lock_irqsave(&tgt->sess_work_lock, flags);
851 	}
852 	spin_unlock_irqrestore(&tgt->sess_work_lock, flags);
853 
854 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf00a,
855 	    "Waiting for tgt %p: list_empty(sess_list)=%d "
856 	    "sess_count=%d\n", tgt, list_empty(&tgt->sess_list),
857 	    tgt->sess_count);
858 
859 	wait_event(tgt->waitQ, test_tgt_sess_count(tgt));
860 
861 	/* Big hammer */
862 	if (!ha->flags.host_shutting_down && qla_tgt_mode_enabled(vha))
863 		qlt_disable_vha(vha);
864 
865 	/* Wait for sessions to clear out (just in case) */
866 	wait_event(tgt->waitQ, test_tgt_sess_count(tgt));
867 }
868 EXPORT_SYMBOL(qlt_stop_phase1);
869 
870 /* Called by tcm_qla2xxx configfs code */
871 void qlt_stop_phase2(struct qla_tgt *tgt)
872 {
873 	struct qla_hw_data *ha = tgt->ha;
874 	unsigned long flags;
875 
876 	if (tgt->tgt_stopped) {
877 		ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf04f,
878 		    "Already in tgt->tgt_stopped state\n");
879 		dump_stack();
880 		return;
881 	}
882 
883 	ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf00b,
884 	    "Waiting for %d IRQ commands to complete (tgt %p)",
885 	    tgt->irq_cmd_count, tgt);
886 
887 	mutex_lock(&ha->tgt.tgt_mutex);
888 	spin_lock_irqsave(&ha->hardware_lock, flags);
889 	while (tgt->irq_cmd_count != 0) {
890 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
891 		udelay(2);
892 		spin_lock_irqsave(&ha->hardware_lock, flags);
893 	}
894 	tgt->tgt_stop = 0;
895 	tgt->tgt_stopped = 1;
896 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
897 	mutex_unlock(&ha->tgt.tgt_mutex);
898 
899 	ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf00c, "Stop of tgt %p finished",
900 	    tgt);
901 }
902 EXPORT_SYMBOL(qlt_stop_phase2);
903 
904 /* Called from qlt_remove_target() -> qla2x00_remove_one() */
905 static void qlt_release(struct qla_tgt *tgt)
906 {
907 	struct qla_hw_data *ha = tgt->ha;
908 
909 	if ((ha->tgt.qla_tgt != NULL) && !tgt->tgt_stopped)
910 		qlt_stop_phase2(tgt);
911 
912 	ha->tgt.qla_tgt = NULL;
913 
914 	ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf00d,
915 	    "Release of tgt %p finished\n", tgt);
916 
917 	kfree(tgt);
918 }
919 
920 /* ha->hardware_lock supposed to be held on entry */
921 static int qlt_sched_sess_work(struct qla_tgt *tgt, int type,
922 	const void *param, unsigned int param_size)
923 {
924 	struct qla_tgt_sess_work_param *prm;
925 	unsigned long flags;
926 
927 	prm = kzalloc(sizeof(*prm), GFP_ATOMIC);
928 	if (!prm) {
929 		ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf050,
930 		    "qla_target(%d): Unable to create session "
931 		    "work, command will be refused", 0);
932 		return -ENOMEM;
933 	}
934 
935 	ql_dbg(ql_dbg_tgt_mgt, tgt->vha, 0xf00e,
936 	    "Scheduling work (type %d, prm %p)"
937 	    " to find session for param %p (size %d, tgt %p)\n",
938 	    type, prm, param, param_size, tgt);
939 
940 	prm->type = type;
941 	memcpy(&prm->tm_iocb, param, param_size);
942 
943 	spin_lock_irqsave(&tgt->sess_work_lock, flags);
944 	list_add_tail(&prm->sess_works_list_entry, &tgt->sess_works_list);
945 	spin_unlock_irqrestore(&tgt->sess_work_lock, flags);
946 
947 	schedule_work(&tgt->sess_work);
948 
949 	return 0;
950 }
951 
952 /*
953  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
954  */
955 static void qlt_send_notify_ack(struct scsi_qla_host *vha,
956 	struct imm_ntfy_from_isp *ntfy,
957 	uint32_t add_flags, uint16_t resp_code, int resp_code_valid,
958 	uint16_t srr_flags, uint16_t srr_reject_code, uint8_t srr_explan)
959 {
960 	struct qla_hw_data *ha = vha->hw;
961 	request_t *pkt;
962 	struct nack_to_isp *nack;
963 
964 	ql_dbg(ql_dbg_tgt, vha, 0xe004, "Sending NOTIFY_ACK (ha=%p)\n", ha);
965 
966 	/* Send marker if required */
967 	if (qlt_issue_marker(vha, 1) != QLA_SUCCESS)
968 		return;
969 
970 	pkt = (request_t *)qla2x00_alloc_iocbs(vha, NULL);
971 	if (!pkt) {
972 		ql_dbg(ql_dbg_tgt, vha, 0xe049,
973 		    "qla_target(%d): %s failed: unable to allocate "
974 		    "request packet\n", vha->vp_idx, __func__);
975 		return;
976 	}
977 
978 	if (ha->tgt.qla_tgt != NULL)
979 		ha->tgt.qla_tgt->notify_ack_expected++;
980 
981 	pkt->entry_type = NOTIFY_ACK_TYPE;
982 	pkt->entry_count = 1;
983 
984 	nack = (struct nack_to_isp *)pkt;
985 	nack->ox_id = ntfy->ox_id;
986 
987 	nack->u.isp24.nport_handle = ntfy->u.isp24.nport_handle;
988 	if (le16_to_cpu(ntfy->u.isp24.status) == IMM_NTFY_ELS) {
989 		nack->u.isp24.flags = ntfy->u.isp24.flags &
990 			__constant_cpu_to_le32(NOTIFY24XX_FLAGS_PUREX_IOCB);
991 	}
992 	nack->u.isp24.srr_rx_id = ntfy->u.isp24.srr_rx_id;
993 	nack->u.isp24.status = ntfy->u.isp24.status;
994 	nack->u.isp24.status_subcode = ntfy->u.isp24.status_subcode;
995 	nack->u.isp24.fw_handle = ntfy->u.isp24.fw_handle;
996 	nack->u.isp24.exchange_address = ntfy->u.isp24.exchange_address;
997 	nack->u.isp24.srr_rel_offs = ntfy->u.isp24.srr_rel_offs;
998 	nack->u.isp24.srr_ui = ntfy->u.isp24.srr_ui;
999 	nack->u.isp24.srr_flags = cpu_to_le16(srr_flags);
1000 	nack->u.isp24.srr_reject_code = srr_reject_code;
1001 	nack->u.isp24.srr_reject_code_expl = srr_explan;
1002 	nack->u.isp24.vp_index = ntfy->u.isp24.vp_index;
1003 
1004 	ql_dbg(ql_dbg_tgt, vha, 0xe005,
1005 	    "qla_target(%d): Sending 24xx Notify Ack %d\n",
1006 	    vha->vp_idx, nack->u.isp24.status);
1007 
1008 	qla2x00_start_iocbs(vha, vha->req);
1009 }
1010 
1011 /*
1012  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
1013  */
1014 static void qlt_24xx_send_abts_resp(struct scsi_qla_host *vha,
1015 	struct abts_recv_from_24xx *abts, uint32_t status,
1016 	bool ids_reversed)
1017 {
1018 	struct qla_hw_data *ha = vha->hw;
1019 	struct abts_resp_to_24xx *resp;
1020 	uint32_t f_ctl;
1021 	uint8_t *p;
1022 
1023 	ql_dbg(ql_dbg_tgt, vha, 0xe006,
1024 	    "Sending task mgmt ABTS response (ha=%p, atio=%p, status=%x\n",
1025 	    ha, abts, status);
1026 
1027 	/* Send marker if required */
1028 	if (qlt_issue_marker(vha, 1) != QLA_SUCCESS)
1029 		return;
1030 
1031 	resp = (struct abts_resp_to_24xx *)qla2x00_alloc_iocbs(vha, NULL);
1032 	if (!resp) {
1033 		ql_dbg(ql_dbg_tgt, vha, 0xe04a,
1034 		    "qla_target(%d): %s failed: unable to allocate "
1035 		    "request packet", vha->vp_idx, __func__);
1036 		return;
1037 	}
1038 
1039 	resp->entry_type = ABTS_RESP_24XX;
1040 	resp->entry_count = 1;
1041 	resp->nport_handle = abts->nport_handle;
1042 	resp->vp_index = vha->vp_idx;
1043 	resp->sof_type = abts->sof_type;
1044 	resp->exchange_address = abts->exchange_address;
1045 	resp->fcp_hdr_le = abts->fcp_hdr_le;
1046 	f_ctl = __constant_cpu_to_le32(F_CTL_EXCH_CONTEXT_RESP |
1047 	    F_CTL_LAST_SEQ | F_CTL_END_SEQ |
1048 	    F_CTL_SEQ_INITIATIVE);
1049 	p = (uint8_t *)&f_ctl;
1050 	resp->fcp_hdr_le.f_ctl[0] = *p++;
1051 	resp->fcp_hdr_le.f_ctl[1] = *p++;
1052 	resp->fcp_hdr_le.f_ctl[2] = *p;
1053 	if (ids_reversed) {
1054 		resp->fcp_hdr_le.d_id[0] = abts->fcp_hdr_le.d_id[0];
1055 		resp->fcp_hdr_le.d_id[1] = abts->fcp_hdr_le.d_id[1];
1056 		resp->fcp_hdr_le.d_id[2] = abts->fcp_hdr_le.d_id[2];
1057 		resp->fcp_hdr_le.s_id[0] = abts->fcp_hdr_le.s_id[0];
1058 		resp->fcp_hdr_le.s_id[1] = abts->fcp_hdr_le.s_id[1];
1059 		resp->fcp_hdr_le.s_id[2] = abts->fcp_hdr_le.s_id[2];
1060 	} else {
1061 		resp->fcp_hdr_le.d_id[0] = abts->fcp_hdr_le.s_id[0];
1062 		resp->fcp_hdr_le.d_id[1] = abts->fcp_hdr_le.s_id[1];
1063 		resp->fcp_hdr_le.d_id[2] = abts->fcp_hdr_le.s_id[2];
1064 		resp->fcp_hdr_le.s_id[0] = abts->fcp_hdr_le.d_id[0];
1065 		resp->fcp_hdr_le.s_id[1] = abts->fcp_hdr_le.d_id[1];
1066 		resp->fcp_hdr_le.s_id[2] = abts->fcp_hdr_le.d_id[2];
1067 	}
1068 	resp->exchange_addr_to_abort = abts->exchange_addr_to_abort;
1069 	if (status == FCP_TMF_CMPL) {
1070 		resp->fcp_hdr_le.r_ctl = R_CTL_BASIC_LINK_SERV | R_CTL_B_ACC;
1071 		resp->payload.ba_acct.seq_id_valid = SEQ_ID_INVALID;
1072 		resp->payload.ba_acct.low_seq_cnt = 0x0000;
1073 		resp->payload.ba_acct.high_seq_cnt = 0xFFFF;
1074 		resp->payload.ba_acct.ox_id = abts->fcp_hdr_le.ox_id;
1075 		resp->payload.ba_acct.rx_id = abts->fcp_hdr_le.rx_id;
1076 	} else {
1077 		resp->fcp_hdr_le.r_ctl = R_CTL_BASIC_LINK_SERV | R_CTL_B_RJT;
1078 		resp->payload.ba_rjt.reason_code =
1079 			BA_RJT_REASON_CODE_UNABLE_TO_PERFORM;
1080 		/* Other bytes are zero */
1081 	}
1082 
1083 	ha->tgt.qla_tgt->abts_resp_expected++;
1084 
1085 	qla2x00_start_iocbs(vha, vha->req);
1086 }
1087 
1088 /*
1089  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
1090  */
1091 static void qlt_24xx_retry_term_exchange(struct scsi_qla_host *vha,
1092 	struct abts_resp_from_24xx_fw *entry)
1093 {
1094 	struct ctio7_to_24xx *ctio;
1095 
1096 	ql_dbg(ql_dbg_tgt, vha, 0xe007,
1097 	    "Sending retry TERM EXCH CTIO7 (ha=%p)\n", vha->hw);
1098 	/* Send marker if required */
1099 	if (qlt_issue_marker(vha, 1) != QLA_SUCCESS)
1100 		return;
1101 
1102 	ctio = (struct ctio7_to_24xx *)qla2x00_alloc_iocbs(vha, NULL);
1103 	if (ctio == NULL) {
1104 		ql_dbg(ql_dbg_tgt, vha, 0xe04b,
1105 		    "qla_target(%d): %s failed: unable to allocate "
1106 		    "request packet\n", vha->vp_idx, __func__);
1107 		return;
1108 	}
1109 
1110 	/*
1111 	 * We've got on entrance firmware's response on by us generated
1112 	 * ABTS response. So, in it ID fields are reversed.
1113 	 */
1114 
1115 	ctio->entry_type = CTIO_TYPE7;
1116 	ctio->entry_count = 1;
1117 	ctio->nport_handle = entry->nport_handle;
1118 	ctio->handle = QLA_TGT_SKIP_HANDLE |	CTIO_COMPLETION_HANDLE_MARK;
1119 	ctio->timeout = __constant_cpu_to_le16(QLA_TGT_TIMEOUT);
1120 	ctio->vp_index = vha->vp_idx;
1121 	ctio->initiator_id[0] = entry->fcp_hdr_le.d_id[0];
1122 	ctio->initiator_id[1] = entry->fcp_hdr_le.d_id[1];
1123 	ctio->initiator_id[2] = entry->fcp_hdr_le.d_id[2];
1124 	ctio->exchange_addr = entry->exchange_addr_to_abort;
1125 	ctio->u.status1.flags =
1126 	    __constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_1 |
1127 		CTIO7_FLAGS_TERMINATE);
1128 	ctio->u.status1.ox_id = entry->fcp_hdr_le.ox_id;
1129 
1130 	qla2x00_start_iocbs(vha, vha->req);
1131 
1132 	qlt_24xx_send_abts_resp(vha, (struct abts_recv_from_24xx *)entry,
1133 	    FCP_TMF_CMPL, true);
1134 }
1135 
1136 /* ha->hardware_lock supposed to be held on entry */
1137 static int __qlt_24xx_handle_abts(struct scsi_qla_host *vha,
1138 	struct abts_recv_from_24xx *abts, struct qla_tgt_sess *sess)
1139 {
1140 	struct qla_hw_data *ha = vha->hw;
1141 	struct se_session *se_sess = sess->se_sess;
1142 	struct qla_tgt_mgmt_cmd *mcmd;
1143 	struct se_cmd *se_cmd;
1144 	u32 lun = 0;
1145 	int rc;
1146 	bool found_lun = false;
1147 
1148 	spin_lock(&se_sess->sess_cmd_lock);
1149 	list_for_each_entry(se_cmd, &se_sess->sess_cmd_list, se_cmd_list) {
1150 		struct qla_tgt_cmd *cmd =
1151 			container_of(se_cmd, struct qla_tgt_cmd, se_cmd);
1152 		if (cmd->tag == abts->exchange_addr_to_abort) {
1153 			lun = cmd->unpacked_lun;
1154 			found_lun = true;
1155 			break;
1156 		}
1157 	}
1158 	spin_unlock(&se_sess->sess_cmd_lock);
1159 
1160 	if (!found_lun)
1161 		return -ENOENT;
1162 
1163 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf00f,
1164 	    "qla_target(%d): task abort (tag=%d)\n",
1165 	    vha->vp_idx, abts->exchange_addr_to_abort);
1166 
1167 	mcmd = mempool_alloc(qla_tgt_mgmt_cmd_mempool, GFP_ATOMIC);
1168 	if (mcmd == NULL) {
1169 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf051,
1170 		    "qla_target(%d): %s: Allocation of ABORT cmd failed",
1171 		    vha->vp_idx, __func__);
1172 		return -ENOMEM;
1173 	}
1174 	memset(mcmd, 0, sizeof(*mcmd));
1175 
1176 	mcmd->sess = sess;
1177 	memcpy(&mcmd->orig_iocb.abts, abts, sizeof(mcmd->orig_iocb.abts));
1178 
1179 	rc = ha->tgt.tgt_ops->handle_tmr(mcmd, lun, TMR_ABORT_TASK,
1180 	    abts->exchange_addr_to_abort);
1181 	if (rc != 0) {
1182 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf052,
1183 		    "qla_target(%d):  tgt_ops->handle_tmr()"
1184 		    " failed: %d", vha->vp_idx, rc);
1185 		mempool_free(mcmd, qla_tgt_mgmt_cmd_mempool);
1186 		return -EFAULT;
1187 	}
1188 
1189 	return 0;
1190 }
1191 
1192 /*
1193  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
1194  */
1195 static void qlt_24xx_handle_abts(struct scsi_qla_host *vha,
1196 	struct abts_recv_from_24xx *abts)
1197 {
1198 	struct qla_hw_data *ha = vha->hw;
1199 	struct qla_tgt_sess *sess;
1200 	uint32_t tag = abts->exchange_addr_to_abort;
1201 	uint8_t s_id[3];
1202 	int rc;
1203 
1204 	if (le32_to_cpu(abts->fcp_hdr_le.parameter) & ABTS_PARAM_ABORT_SEQ) {
1205 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf053,
1206 		    "qla_target(%d): ABTS: Abort Sequence not "
1207 		    "supported\n", vha->vp_idx);
1208 		qlt_24xx_send_abts_resp(vha, abts, FCP_TMF_REJECTED, false);
1209 		return;
1210 	}
1211 
1212 	if (tag == ATIO_EXCHANGE_ADDRESS_UNKNOWN) {
1213 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf010,
1214 		    "qla_target(%d): ABTS: Unknown Exchange "
1215 		    "Address received\n", vha->vp_idx);
1216 		qlt_24xx_send_abts_resp(vha, abts, FCP_TMF_REJECTED, false);
1217 		return;
1218 	}
1219 
1220 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf011,
1221 	    "qla_target(%d): task abort (s_id=%x:%x:%x, "
1222 	    "tag=%d, param=%x)\n", vha->vp_idx, abts->fcp_hdr_le.s_id[2],
1223 	    abts->fcp_hdr_le.s_id[1], abts->fcp_hdr_le.s_id[0], tag,
1224 	    le32_to_cpu(abts->fcp_hdr_le.parameter));
1225 
1226 	s_id[0] = abts->fcp_hdr_le.s_id[2];
1227 	s_id[1] = abts->fcp_hdr_le.s_id[1];
1228 	s_id[2] = abts->fcp_hdr_le.s_id[0];
1229 
1230 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha, s_id);
1231 	if (!sess) {
1232 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf012,
1233 		    "qla_target(%d): task abort for non-existant session\n",
1234 		    vha->vp_idx);
1235 		rc = qlt_sched_sess_work(ha->tgt.qla_tgt,
1236 		    QLA_TGT_SESS_WORK_ABORT, abts, sizeof(*abts));
1237 		if (rc != 0) {
1238 			qlt_24xx_send_abts_resp(vha, abts, FCP_TMF_REJECTED,
1239 			    false);
1240 		}
1241 		return;
1242 	}
1243 
1244 	rc = __qlt_24xx_handle_abts(vha, abts, sess);
1245 	if (rc != 0) {
1246 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf054,
1247 		    "qla_target(%d): __qlt_24xx_handle_abts() failed: %d\n",
1248 		    vha->vp_idx, rc);
1249 		qlt_24xx_send_abts_resp(vha, abts, FCP_TMF_REJECTED, false);
1250 		return;
1251 	}
1252 }
1253 
1254 /*
1255  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
1256  */
1257 static void qlt_24xx_send_task_mgmt_ctio(struct scsi_qla_host *ha,
1258 	struct qla_tgt_mgmt_cmd *mcmd, uint32_t resp_code)
1259 {
1260 	struct atio_from_isp *atio = &mcmd->orig_iocb.atio;
1261 	struct ctio7_to_24xx *ctio;
1262 
1263 	ql_dbg(ql_dbg_tgt, ha, 0xe008,
1264 	    "Sending task mgmt CTIO7 (ha=%p, atio=%p, resp_code=%x\n",
1265 	    ha, atio, resp_code);
1266 
1267 	/* Send marker if required */
1268 	if (qlt_issue_marker(ha, 1) != QLA_SUCCESS)
1269 		return;
1270 
1271 	ctio = (struct ctio7_to_24xx *)qla2x00_alloc_iocbs(ha, NULL);
1272 	if (ctio == NULL) {
1273 		ql_dbg(ql_dbg_tgt, ha, 0xe04c,
1274 		    "qla_target(%d): %s failed: unable to allocate "
1275 		    "request packet\n", ha->vp_idx, __func__);
1276 		return;
1277 	}
1278 
1279 	ctio->entry_type = CTIO_TYPE7;
1280 	ctio->entry_count = 1;
1281 	ctio->handle = QLA_TGT_SKIP_HANDLE | CTIO_COMPLETION_HANDLE_MARK;
1282 	ctio->nport_handle = mcmd->sess->loop_id;
1283 	ctio->timeout = __constant_cpu_to_le16(QLA_TGT_TIMEOUT);
1284 	ctio->vp_index = ha->vp_idx;
1285 	ctio->initiator_id[0] = atio->u.isp24.fcp_hdr.s_id[2];
1286 	ctio->initiator_id[1] = atio->u.isp24.fcp_hdr.s_id[1];
1287 	ctio->initiator_id[2] = atio->u.isp24.fcp_hdr.s_id[0];
1288 	ctio->exchange_addr = atio->u.isp24.exchange_addr;
1289 	ctio->u.status1.flags = (atio->u.isp24.attr << 9) |
1290 	    __constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_1 |
1291 		CTIO7_FLAGS_SEND_STATUS);
1292 	ctio->u.status1.ox_id = swab16(atio->u.isp24.fcp_hdr.ox_id);
1293 	ctio->u.status1.scsi_status =
1294 	    __constant_cpu_to_le16(SS_RESPONSE_INFO_LEN_VALID);
1295 	ctio->u.status1.response_len = __constant_cpu_to_le16(8);
1296 	ctio->u.status1.sense_data[0] = resp_code;
1297 
1298 	qla2x00_start_iocbs(ha, ha->req);
1299 }
1300 
1301 void qlt_free_mcmd(struct qla_tgt_mgmt_cmd *mcmd)
1302 {
1303 	mempool_free(mcmd, qla_tgt_mgmt_cmd_mempool);
1304 }
1305 EXPORT_SYMBOL(qlt_free_mcmd);
1306 
1307 /* callback from target fabric module code */
1308 void qlt_xmit_tm_rsp(struct qla_tgt_mgmt_cmd *mcmd)
1309 {
1310 	struct scsi_qla_host *vha = mcmd->sess->vha;
1311 	struct qla_hw_data *ha = vha->hw;
1312 	unsigned long flags;
1313 
1314 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf013,
1315 	    "TM response mcmd (%p) status %#x state %#x",
1316 	    mcmd, mcmd->fc_tm_rsp, mcmd->flags);
1317 
1318 	spin_lock_irqsave(&ha->hardware_lock, flags);
1319 	if (mcmd->flags == QLA24XX_MGMT_SEND_NACK)
1320 		qlt_send_notify_ack(vha, &mcmd->orig_iocb.imm_ntfy,
1321 		    0, 0, 0, 0, 0, 0);
1322 	else {
1323 		if (mcmd->se_cmd.se_tmr_req->function == TMR_ABORT_TASK)
1324 			qlt_24xx_send_abts_resp(vha, &mcmd->orig_iocb.abts,
1325 			    mcmd->fc_tm_rsp, false);
1326 		else
1327 			qlt_24xx_send_task_mgmt_ctio(vha, mcmd,
1328 			    mcmd->fc_tm_rsp);
1329 	}
1330 	/*
1331 	 * Make the callback for ->free_mcmd() to queue_work() and invoke
1332 	 * target_put_sess_cmd() to drop cmd_kref to 1.  The final
1333 	 * target_put_sess_cmd() call will be made from TFO->check_stop_free()
1334 	 * -> tcm_qla2xxx_check_stop_free() to release the TMR associated se_cmd
1335 	 * descriptor after TFO->queue_tm_rsp() -> tcm_qla2xxx_queue_tm_rsp() ->
1336 	 * qlt_xmit_tm_rsp() returns here..
1337 	 */
1338 	ha->tgt.tgt_ops->free_mcmd(mcmd);
1339 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
1340 }
1341 EXPORT_SYMBOL(qlt_xmit_tm_rsp);
1342 
1343 /* No locks */
1344 static int qlt_pci_map_calc_cnt(struct qla_tgt_prm *prm)
1345 {
1346 	struct qla_tgt_cmd *cmd = prm->cmd;
1347 
1348 	BUG_ON(cmd->sg_cnt == 0);
1349 
1350 	prm->sg = (struct scatterlist *)cmd->sg;
1351 	prm->seg_cnt = pci_map_sg(prm->tgt->ha->pdev, cmd->sg,
1352 	    cmd->sg_cnt, cmd->dma_data_direction);
1353 	if (unlikely(prm->seg_cnt == 0))
1354 		goto out_err;
1355 
1356 	prm->cmd->sg_mapped = 1;
1357 
1358 	/*
1359 	 * If greater than four sg entries then we need to allocate
1360 	 * the continuation entries
1361 	 */
1362 	if (prm->seg_cnt > prm->tgt->datasegs_per_cmd)
1363 		prm->req_cnt += DIV_ROUND_UP(prm->seg_cnt -
1364 		    prm->tgt->datasegs_per_cmd, prm->tgt->datasegs_per_cont);
1365 
1366 	ql_dbg(ql_dbg_tgt, prm->cmd->vha, 0xe009, "seg_cnt=%d, req_cnt=%d\n",
1367 	    prm->seg_cnt, prm->req_cnt);
1368 	return 0;
1369 
1370 out_err:
1371 	ql_dbg(ql_dbg_tgt, prm->cmd->vha, 0xe04d,
1372 	    "qla_target(%d): PCI mapping failed: sg_cnt=%d",
1373 	    0, prm->cmd->sg_cnt);
1374 	return -1;
1375 }
1376 
1377 static inline void qlt_unmap_sg(struct scsi_qla_host *vha,
1378 	struct qla_tgt_cmd *cmd)
1379 {
1380 	struct qla_hw_data *ha = vha->hw;
1381 
1382 	BUG_ON(!cmd->sg_mapped);
1383 	pci_unmap_sg(ha->pdev, cmd->sg, cmd->sg_cnt, cmd->dma_data_direction);
1384 	cmd->sg_mapped = 0;
1385 }
1386 
1387 static int qlt_check_reserve_free_req(struct scsi_qla_host *vha,
1388 	uint32_t req_cnt)
1389 {
1390 	struct qla_hw_data *ha = vha->hw;
1391 	device_reg_t __iomem *reg = ha->iobase;
1392 	uint32_t cnt;
1393 
1394 	if (vha->req->cnt < (req_cnt + 2)) {
1395 		cnt = (uint16_t)RD_REG_DWORD(&reg->isp24.req_q_out);
1396 
1397 		ql_dbg(ql_dbg_tgt, vha, 0xe00a,
1398 		    "Request ring circled: cnt=%d, vha->->ring_index=%d, "
1399 		    "vha->req->cnt=%d, req_cnt=%d\n", cnt,
1400 		    vha->req->ring_index, vha->req->cnt, req_cnt);
1401 		if  (vha->req->ring_index < cnt)
1402 			vha->req->cnt = cnt - vha->req->ring_index;
1403 		else
1404 			vha->req->cnt = vha->req->length -
1405 			    (vha->req->ring_index - cnt);
1406 	}
1407 
1408 	if (unlikely(vha->req->cnt < (req_cnt + 2))) {
1409 		ql_dbg(ql_dbg_tgt, vha, 0xe00b,
1410 		    "qla_target(%d): There is no room in the "
1411 		    "request ring: vha->req->ring_index=%d, vha->req->cnt=%d, "
1412 		    "req_cnt=%d\n", vha->vp_idx, vha->req->ring_index,
1413 		    vha->req->cnt, req_cnt);
1414 		return -EAGAIN;
1415 	}
1416 	vha->req->cnt -= req_cnt;
1417 
1418 	return 0;
1419 }
1420 
1421 /*
1422  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
1423  */
1424 static inline void *qlt_get_req_pkt(struct scsi_qla_host *vha)
1425 {
1426 	/* Adjust ring index. */
1427 	vha->req->ring_index++;
1428 	if (vha->req->ring_index == vha->req->length) {
1429 		vha->req->ring_index = 0;
1430 		vha->req->ring_ptr = vha->req->ring;
1431 	} else {
1432 		vha->req->ring_ptr++;
1433 	}
1434 	return (cont_entry_t *)vha->req->ring_ptr;
1435 }
1436 
1437 /* ha->hardware_lock supposed to be held on entry */
1438 static inline uint32_t qlt_make_handle(struct scsi_qla_host *vha)
1439 {
1440 	struct qla_hw_data *ha = vha->hw;
1441 	uint32_t h;
1442 
1443 	h = ha->tgt.current_handle;
1444 	/* always increment cmd handle */
1445 	do {
1446 		++h;
1447 		if (h > DEFAULT_OUTSTANDING_COMMANDS)
1448 			h = 1; /* 0 is QLA_TGT_NULL_HANDLE */
1449 		if (h == ha->tgt.current_handle) {
1450 			ql_dbg(ql_dbg_tgt, vha, 0xe04e,
1451 			    "qla_target(%d): Ran out of "
1452 			    "empty cmd slots in ha %p\n", vha->vp_idx, ha);
1453 			h = QLA_TGT_NULL_HANDLE;
1454 			break;
1455 		}
1456 	} while ((h == QLA_TGT_NULL_HANDLE) ||
1457 	    (h == QLA_TGT_SKIP_HANDLE) ||
1458 	    (ha->tgt.cmds[h-1] != NULL));
1459 
1460 	if (h != QLA_TGT_NULL_HANDLE)
1461 		ha->tgt.current_handle = h;
1462 
1463 	return h;
1464 }
1465 
1466 /* ha->hardware_lock supposed to be held on entry */
1467 static int qlt_24xx_build_ctio_pkt(struct qla_tgt_prm *prm,
1468 	struct scsi_qla_host *vha)
1469 {
1470 	uint32_t h;
1471 	struct ctio7_to_24xx *pkt;
1472 	struct qla_hw_data *ha = vha->hw;
1473 	struct atio_from_isp *atio = &prm->cmd->atio;
1474 
1475 	pkt = (struct ctio7_to_24xx *)vha->req->ring_ptr;
1476 	prm->pkt = pkt;
1477 	memset(pkt, 0, sizeof(*pkt));
1478 
1479 	pkt->entry_type = CTIO_TYPE7;
1480 	pkt->entry_count = (uint8_t)prm->req_cnt;
1481 	pkt->vp_index = vha->vp_idx;
1482 
1483 	h = qlt_make_handle(vha);
1484 	if (unlikely(h == QLA_TGT_NULL_HANDLE)) {
1485 		/*
1486 		 * CTIO type 7 from the firmware doesn't provide a way to
1487 		 * know the initiator's LOOP ID, hence we can't find
1488 		 * the session and, so, the command.
1489 		 */
1490 		return -EAGAIN;
1491 	} else
1492 		ha->tgt.cmds[h-1] = prm->cmd;
1493 
1494 	pkt->handle = h | CTIO_COMPLETION_HANDLE_MARK;
1495 	pkt->nport_handle = prm->cmd->loop_id;
1496 	pkt->timeout = __constant_cpu_to_le16(QLA_TGT_TIMEOUT);
1497 	pkt->initiator_id[0] = atio->u.isp24.fcp_hdr.s_id[2];
1498 	pkt->initiator_id[1] = atio->u.isp24.fcp_hdr.s_id[1];
1499 	pkt->initiator_id[2] = atio->u.isp24.fcp_hdr.s_id[0];
1500 	pkt->exchange_addr = atio->u.isp24.exchange_addr;
1501 	pkt->u.status0.flags |= (atio->u.isp24.attr << 9);
1502 	pkt->u.status0.ox_id = swab16(atio->u.isp24.fcp_hdr.ox_id);
1503 	pkt->u.status0.relative_offset = cpu_to_le32(prm->cmd->offset);
1504 
1505 	ql_dbg(ql_dbg_tgt, vha, 0xe00c,
1506 	    "qla_target(%d): handle(cmd) -> %08x, timeout %d, ox_id %#x\n",
1507 	    vha->vp_idx, pkt->handle, QLA_TGT_TIMEOUT,
1508 	    le16_to_cpu(pkt->u.status0.ox_id));
1509 	return 0;
1510 }
1511 
1512 /*
1513  * ha->hardware_lock supposed to be held on entry. We have already made sure
1514  * that there is sufficient amount of request entries to not drop it.
1515  */
1516 static void qlt_load_cont_data_segments(struct qla_tgt_prm *prm,
1517 	struct scsi_qla_host *vha)
1518 {
1519 	int cnt;
1520 	uint32_t *dword_ptr;
1521 	int enable_64bit_addressing = prm->tgt->tgt_enable_64bit_addr;
1522 
1523 	/* Build continuation packets */
1524 	while (prm->seg_cnt > 0) {
1525 		cont_a64_entry_t *cont_pkt64 =
1526 			(cont_a64_entry_t *)qlt_get_req_pkt(vha);
1527 
1528 		/*
1529 		 * Make sure that from cont_pkt64 none of
1530 		 * 64-bit specific fields used for 32-bit
1531 		 * addressing. Cast to (cont_entry_t *) for
1532 		 * that.
1533 		 */
1534 
1535 		memset(cont_pkt64, 0, sizeof(*cont_pkt64));
1536 
1537 		cont_pkt64->entry_count = 1;
1538 		cont_pkt64->sys_define = 0;
1539 
1540 		if (enable_64bit_addressing) {
1541 			cont_pkt64->entry_type = CONTINUE_A64_TYPE;
1542 			dword_ptr =
1543 			    (uint32_t *)&cont_pkt64->dseg_0_address;
1544 		} else {
1545 			cont_pkt64->entry_type = CONTINUE_TYPE;
1546 			dword_ptr =
1547 			    (uint32_t *)&((cont_entry_t *)
1548 				cont_pkt64)->dseg_0_address;
1549 		}
1550 
1551 		/* Load continuation entry data segments */
1552 		for (cnt = 0;
1553 		    cnt < prm->tgt->datasegs_per_cont && prm->seg_cnt;
1554 		    cnt++, prm->seg_cnt--) {
1555 			*dword_ptr++ =
1556 			    cpu_to_le32(pci_dma_lo32
1557 				(sg_dma_address(prm->sg)));
1558 			if (enable_64bit_addressing) {
1559 				*dword_ptr++ =
1560 				    cpu_to_le32(pci_dma_hi32
1561 					(sg_dma_address
1562 					(prm->sg)));
1563 			}
1564 			*dword_ptr++ = cpu_to_le32(sg_dma_len(prm->sg));
1565 
1566 			ql_dbg(ql_dbg_tgt, vha, 0xe00d,
1567 			    "S/G Segment Cont. phys_addr=%llx:%llx, len=%d\n",
1568 			    (long long unsigned int)
1569 			    pci_dma_hi32(sg_dma_address(prm->sg)),
1570 			    (long long unsigned int)
1571 			    pci_dma_lo32(sg_dma_address(prm->sg)),
1572 			    (int)sg_dma_len(prm->sg));
1573 
1574 			prm->sg = sg_next(prm->sg);
1575 		}
1576 	}
1577 }
1578 
1579 /*
1580  * ha->hardware_lock supposed to be held on entry. We have already made sure
1581  * that there is sufficient amount of request entries to not drop it.
1582  */
1583 static void qlt_load_data_segments(struct qla_tgt_prm *prm,
1584 	struct scsi_qla_host *vha)
1585 {
1586 	int cnt;
1587 	uint32_t *dword_ptr;
1588 	int enable_64bit_addressing = prm->tgt->tgt_enable_64bit_addr;
1589 	struct ctio7_to_24xx *pkt24 = (struct ctio7_to_24xx *)prm->pkt;
1590 
1591 	ql_dbg(ql_dbg_tgt, vha, 0xe00e,
1592 	    "iocb->scsi_status=%x, iocb->flags=%x\n",
1593 	    le16_to_cpu(pkt24->u.status0.scsi_status),
1594 	    le16_to_cpu(pkt24->u.status0.flags));
1595 
1596 	pkt24->u.status0.transfer_length = cpu_to_le32(prm->cmd->bufflen);
1597 
1598 	/* Setup packet address segment pointer */
1599 	dword_ptr = pkt24->u.status0.dseg_0_address;
1600 
1601 	/* Set total data segment count */
1602 	if (prm->seg_cnt)
1603 		pkt24->dseg_count = cpu_to_le16(prm->seg_cnt);
1604 
1605 	if (prm->seg_cnt == 0) {
1606 		/* No data transfer */
1607 		*dword_ptr++ = 0;
1608 		*dword_ptr = 0;
1609 		return;
1610 	}
1611 
1612 	/* If scatter gather */
1613 	ql_dbg(ql_dbg_tgt, vha, 0xe00f, "%s", "Building S/G data segments...");
1614 
1615 	/* Load command entry data segments */
1616 	for (cnt = 0;
1617 	    (cnt < prm->tgt->datasegs_per_cmd) && prm->seg_cnt;
1618 	    cnt++, prm->seg_cnt--) {
1619 		*dword_ptr++ =
1620 		    cpu_to_le32(pci_dma_lo32(sg_dma_address(prm->sg)));
1621 		if (enable_64bit_addressing) {
1622 			*dword_ptr++ =
1623 			    cpu_to_le32(pci_dma_hi32(
1624 				sg_dma_address(prm->sg)));
1625 		}
1626 		*dword_ptr++ = cpu_to_le32(sg_dma_len(prm->sg));
1627 
1628 		ql_dbg(ql_dbg_tgt, vha, 0xe010,
1629 		    "S/G Segment phys_addr=%llx:%llx, len=%d\n",
1630 		    (long long unsigned int)pci_dma_hi32(sg_dma_address(
1631 		    prm->sg)),
1632 		    (long long unsigned int)pci_dma_lo32(sg_dma_address(
1633 		    prm->sg)),
1634 		    (int)sg_dma_len(prm->sg));
1635 
1636 		prm->sg = sg_next(prm->sg);
1637 	}
1638 
1639 	qlt_load_cont_data_segments(prm, vha);
1640 }
1641 
1642 static inline int qlt_has_data(struct qla_tgt_cmd *cmd)
1643 {
1644 	return cmd->bufflen > 0;
1645 }
1646 
1647 /*
1648  * Called without ha->hardware_lock held
1649  */
1650 static int qlt_pre_xmit_response(struct qla_tgt_cmd *cmd,
1651 	struct qla_tgt_prm *prm, int xmit_type, uint8_t scsi_status,
1652 	uint32_t *full_req_cnt)
1653 {
1654 	struct qla_tgt *tgt = cmd->tgt;
1655 	struct scsi_qla_host *vha = tgt->vha;
1656 	struct qla_hw_data *ha = vha->hw;
1657 	struct se_cmd *se_cmd = &cmd->se_cmd;
1658 
1659 	if (unlikely(cmd->aborted)) {
1660 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf014,
1661 		    "qla_target(%d): terminating exchange "
1662 		    "for aborted cmd=%p (se_cmd=%p, tag=%d)", vha->vp_idx, cmd,
1663 		    se_cmd, cmd->tag);
1664 
1665 		cmd->state = QLA_TGT_STATE_ABORTED;
1666 
1667 		qlt_send_term_exchange(vha, cmd, &cmd->atio, 0);
1668 
1669 		/* !! At this point cmd could be already freed !! */
1670 		return QLA_TGT_PRE_XMIT_RESP_CMD_ABORTED;
1671 	}
1672 
1673 	ql_dbg(ql_dbg_tgt, vha, 0xe011, "qla_target(%d): tag=%u\n",
1674 	    vha->vp_idx, cmd->tag);
1675 
1676 	prm->cmd = cmd;
1677 	prm->tgt = tgt;
1678 	prm->rq_result = scsi_status;
1679 	prm->sense_buffer = &cmd->sense_buffer[0];
1680 	prm->sense_buffer_len = TRANSPORT_SENSE_BUFFER;
1681 	prm->sg = NULL;
1682 	prm->seg_cnt = -1;
1683 	prm->req_cnt = 1;
1684 	prm->add_status_pkt = 0;
1685 
1686 	ql_dbg(ql_dbg_tgt, vha, 0xe012, "rq_result=%x, xmit_type=%x\n",
1687 	    prm->rq_result, xmit_type);
1688 
1689 	/* Send marker if required */
1690 	if (qlt_issue_marker(vha, 0) != QLA_SUCCESS)
1691 		return -EFAULT;
1692 
1693 	ql_dbg(ql_dbg_tgt, vha, 0xe013, "CTIO start: vha(%d)\n", vha->vp_idx);
1694 
1695 	if ((xmit_type & QLA_TGT_XMIT_DATA) && qlt_has_data(cmd)) {
1696 		if  (qlt_pci_map_calc_cnt(prm) != 0)
1697 			return -EAGAIN;
1698 	}
1699 
1700 	*full_req_cnt = prm->req_cnt;
1701 
1702 	if (se_cmd->se_cmd_flags & SCF_UNDERFLOW_BIT) {
1703 		prm->residual = se_cmd->residual_count;
1704 		ql_dbg(ql_dbg_tgt, vha, 0xe014,
1705 		    "Residual underflow: %d (tag %d, "
1706 		    "op %x, bufflen %d, rq_result %x)\n", prm->residual,
1707 		    cmd->tag, se_cmd->t_task_cdb ? se_cmd->t_task_cdb[0] : 0,
1708 		    cmd->bufflen, prm->rq_result);
1709 		prm->rq_result |= SS_RESIDUAL_UNDER;
1710 	} else if (se_cmd->se_cmd_flags & SCF_OVERFLOW_BIT) {
1711 		prm->residual = se_cmd->residual_count;
1712 		ql_dbg(ql_dbg_tgt, vha, 0xe015,
1713 		    "Residual overflow: %d (tag %d, "
1714 		    "op %x, bufflen %d, rq_result %x)\n", prm->residual,
1715 		    cmd->tag, se_cmd->t_task_cdb ? se_cmd->t_task_cdb[0] : 0,
1716 		    cmd->bufflen, prm->rq_result);
1717 		prm->rq_result |= SS_RESIDUAL_OVER;
1718 	}
1719 
1720 	if (xmit_type & QLA_TGT_XMIT_STATUS) {
1721 		/*
1722 		 * If QLA_TGT_XMIT_DATA is not set, add_status_pkt will be
1723 		 * ignored in *xmit_response() below
1724 		 */
1725 		if (qlt_has_data(cmd)) {
1726 			if (QLA_TGT_SENSE_VALID(prm->sense_buffer) ||
1727 			    (IS_FWI2_CAPABLE(ha) &&
1728 			    (prm->rq_result != 0))) {
1729 				prm->add_status_pkt = 1;
1730 				(*full_req_cnt)++;
1731 			}
1732 		}
1733 	}
1734 
1735 	ql_dbg(ql_dbg_tgt, vha, 0xe016,
1736 	    "req_cnt=%d, full_req_cnt=%d, add_status_pkt=%d\n",
1737 	    prm->req_cnt, *full_req_cnt, prm->add_status_pkt);
1738 
1739 	return 0;
1740 }
1741 
1742 static inline int qlt_need_explicit_conf(struct qla_hw_data *ha,
1743 	struct qla_tgt_cmd *cmd, int sending_sense)
1744 {
1745 	if (ha->tgt.enable_class_2)
1746 		return 0;
1747 
1748 	if (sending_sense)
1749 		return cmd->conf_compl_supported;
1750 	else
1751 		return ha->tgt.enable_explicit_conf &&
1752 		    cmd->conf_compl_supported;
1753 }
1754 
1755 #ifdef CONFIG_QLA_TGT_DEBUG_SRR
1756 /*
1757  *  Original taken from the XFS code
1758  */
1759 static unsigned long qlt_srr_random(void)
1760 {
1761 	static int Inited;
1762 	static unsigned long RandomValue;
1763 	static DEFINE_SPINLOCK(lock);
1764 	/* cycles pseudo-randomly through all values between 1 and 2^31 - 2 */
1765 	register long rv;
1766 	register long lo;
1767 	register long hi;
1768 	unsigned long flags;
1769 
1770 	spin_lock_irqsave(&lock, flags);
1771 	if (!Inited) {
1772 		RandomValue = jiffies;
1773 		Inited = 1;
1774 	}
1775 	rv = RandomValue;
1776 	hi = rv / 127773;
1777 	lo = rv % 127773;
1778 	rv = 16807 * lo - 2836 * hi;
1779 	if (rv <= 0)
1780 		rv += 2147483647;
1781 	RandomValue = rv;
1782 	spin_unlock_irqrestore(&lock, flags);
1783 	return rv;
1784 }
1785 
1786 static void qlt_check_srr_debug(struct qla_tgt_cmd *cmd, int *xmit_type)
1787 {
1788 #if 0 /* This is not a real status packets lost, so it won't lead to SRR */
1789 	if ((*xmit_type & QLA_TGT_XMIT_STATUS) && (qlt_srr_random() % 200)
1790 	    == 50) {
1791 		*xmit_type &= ~QLA_TGT_XMIT_STATUS;
1792 		ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf015,
1793 		    "Dropping cmd %p (tag %d) status", cmd, cmd->tag);
1794 	}
1795 #endif
1796 	/*
1797 	 * It's currently not possible to simulate SRRs for FCP_WRITE without
1798 	 * a physical link layer failure, so don't even try here..
1799 	 */
1800 	if (cmd->dma_data_direction != DMA_FROM_DEVICE)
1801 		return;
1802 
1803 	if (qlt_has_data(cmd) && (cmd->sg_cnt > 1) &&
1804 	    ((qlt_srr_random() % 100) == 20)) {
1805 		int i, leave = 0;
1806 		unsigned int tot_len = 0;
1807 
1808 		while (leave == 0)
1809 			leave = qlt_srr_random() % cmd->sg_cnt;
1810 
1811 		for (i = 0; i < leave; i++)
1812 			tot_len += cmd->sg[i].length;
1813 
1814 		ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf016,
1815 		    "Cutting cmd %p (tag %d) buffer"
1816 		    " tail to len %d, sg_cnt %d (cmd->bufflen %d,"
1817 		    " cmd->sg_cnt %d)", cmd, cmd->tag, tot_len, leave,
1818 		    cmd->bufflen, cmd->sg_cnt);
1819 
1820 		cmd->bufflen = tot_len;
1821 		cmd->sg_cnt = leave;
1822 	}
1823 
1824 	if (qlt_has_data(cmd) && ((qlt_srr_random() % 100) == 70)) {
1825 		unsigned int offset = qlt_srr_random() % cmd->bufflen;
1826 
1827 		ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf017,
1828 		    "Cutting cmd %p (tag %d) buffer head "
1829 		    "to offset %d (cmd->bufflen %d)", cmd, cmd->tag, offset,
1830 		    cmd->bufflen);
1831 		if (offset == 0)
1832 			*xmit_type &= ~QLA_TGT_XMIT_DATA;
1833 		else if (qlt_set_data_offset(cmd, offset)) {
1834 			ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf018,
1835 			    "qlt_set_data_offset() failed (tag %d)", cmd->tag);
1836 		}
1837 	}
1838 }
1839 #else
1840 static inline void qlt_check_srr_debug(struct qla_tgt_cmd *cmd, int *xmit_type)
1841 {}
1842 #endif
1843 
1844 static void qlt_24xx_init_ctio_to_isp(struct ctio7_to_24xx *ctio,
1845 	struct qla_tgt_prm *prm)
1846 {
1847 	prm->sense_buffer_len = min_t(uint32_t, prm->sense_buffer_len,
1848 	    (uint32_t)sizeof(ctio->u.status1.sense_data));
1849 	ctio->u.status0.flags |=
1850 	    __constant_cpu_to_le16(CTIO7_FLAGS_SEND_STATUS);
1851 	if (qlt_need_explicit_conf(prm->tgt->ha, prm->cmd, 0)) {
1852 		ctio->u.status0.flags |= __constant_cpu_to_le16(
1853 		    CTIO7_FLAGS_EXPLICIT_CONFORM |
1854 		    CTIO7_FLAGS_CONFORM_REQ);
1855 	}
1856 	ctio->u.status0.residual = cpu_to_le32(prm->residual);
1857 	ctio->u.status0.scsi_status = cpu_to_le16(prm->rq_result);
1858 	if (QLA_TGT_SENSE_VALID(prm->sense_buffer)) {
1859 		int i;
1860 
1861 		if (qlt_need_explicit_conf(prm->tgt->ha, prm->cmd, 1)) {
1862 			if (prm->cmd->se_cmd.scsi_status != 0) {
1863 				ql_dbg(ql_dbg_tgt, prm->cmd->vha, 0xe017,
1864 				    "Skipping EXPLICIT_CONFORM and "
1865 				    "CTIO7_FLAGS_CONFORM_REQ for FCP READ w/ "
1866 				    "non GOOD status\n");
1867 				goto skip_explict_conf;
1868 			}
1869 			ctio->u.status1.flags |= __constant_cpu_to_le16(
1870 			    CTIO7_FLAGS_EXPLICIT_CONFORM |
1871 			    CTIO7_FLAGS_CONFORM_REQ);
1872 		}
1873 skip_explict_conf:
1874 		ctio->u.status1.flags &=
1875 		    ~__constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_0);
1876 		ctio->u.status1.flags |=
1877 		    __constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_1);
1878 		ctio->u.status1.scsi_status |=
1879 		    __constant_cpu_to_le16(SS_SENSE_LEN_VALID);
1880 		ctio->u.status1.sense_length =
1881 		    cpu_to_le16(prm->sense_buffer_len);
1882 		for (i = 0; i < prm->sense_buffer_len/4; i++)
1883 			((uint32_t *)ctio->u.status1.sense_data)[i] =
1884 				cpu_to_be32(((uint32_t *)prm->sense_buffer)[i]);
1885 #if 0
1886 		if (unlikely((prm->sense_buffer_len % 4) != 0)) {
1887 			static int q;
1888 			if (q < 10) {
1889 				ql_dbg(ql_dbg_tgt, vha, 0xe04f,
1890 				    "qla_target(%d): %d bytes of sense "
1891 				    "lost", prm->tgt->ha->vp_idx,
1892 				    prm->sense_buffer_len % 4);
1893 				q++;
1894 			}
1895 		}
1896 #endif
1897 	} else {
1898 		ctio->u.status1.flags &=
1899 		    ~__constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_0);
1900 		ctio->u.status1.flags |=
1901 		    __constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_1);
1902 		ctio->u.status1.sense_length = 0;
1903 		memset(ctio->u.status1.sense_data, 0,
1904 		    sizeof(ctio->u.status1.sense_data));
1905 	}
1906 
1907 	/* Sense with len > 24, is it possible ??? */
1908 }
1909 
1910 /*
1911  * Callback to setup response of xmit_type of QLA_TGT_XMIT_DATA and *
1912  * QLA_TGT_XMIT_STATUS for >= 24xx silicon
1913  */
1914 int qlt_xmit_response(struct qla_tgt_cmd *cmd, int xmit_type,
1915 	uint8_t scsi_status)
1916 {
1917 	struct scsi_qla_host *vha = cmd->vha;
1918 	struct qla_hw_data *ha = vha->hw;
1919 	struct ctio7_to_24xx *pkt;
1920 	struct qla_tgt_prm prm;
1921 	uint32_t full_req_cnt = 0;
1922 	unsigned long flags = 0;
1923 	int res;
1924 
1925 	memset(&prm, 0, sizeof(prm));
1926 	qlt_check_srr_debug(cmd, &xmit_type);
1927 
1928 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe018,
1929 	    "is_send_status=%d, cmd->bufflen=%d, cmd->sg_cnt=%d, "
1930 	    "cmd->dma_data_direction=%d\n", (xmit_type & QLA_TGT_XMIT_STATUS) ?
1931 	    1 : 0, cmd->bufflen, cmd->sg_cnt, cmd->dma_data_direction);
1932 
1933 	res = qlt_pre_xmit_response(cmd, &prm, xmit_type, scsi_status,
1934 	    &full_req_cnt);
1935 	if (unlikely(res != 0)) {
1936 		if (res == QLA_TGT_PRE_XMIT_RESP_CMD_ABORTED)
1937 			return 0;
1938 
1939 		return res;
1940 	}
1941 
1942 	spin_lock_irqsave(&ha->hardware_lock, flags);
1943 
1944 	/* Does F/W have an IOCBs for this request */
1945 	res = qlt_check_reserve_free_req(vha, full_req_cnt);
1946 	if (unlikely(res))
1947 		goto out_unmap_unlock;
1948 
1949 	res = qlt_24xx_build_ctio_pkt(&prm, vha);
1950 	if (unlikely(res != 0))
1951 		goto out_unmap_unlock;
1952 
1953 
1954 	pkt = (struct ctio7_to_24xx *)prm.pkt;
1955 
1956 	if (qlt_has_data(cmd) && (xmit_type & QLA_TGT_XMIT_DATA)) {
1957 		pkt->u.status0.flags |=
1958 		    __constant_cpu_to_le16(CTIO7_FLAGS_DATA_IN |
1959 			CTIO7_FLAGS_STATUS_MODE_0);
1960 
1961 		qlt_load_data_segments(&prm, vha);
1962 
1963 		if (prm.add_status_pkt == 0) {
1964 			if (xmit_type & QLA_TGT_XMIT_STATUS) {
1965 				pkt->u.status0.scsi_status =
1966 				    cpu_to_le16(prm.rq_result);
1967 				pkt->u.status0.residual =
1968 				    cpu_to_le32(prm.residual);
1969 				pkt->u.status0.flags |= __constant_cpu_to_le16(
1970 				    CTIO7_FLAGS_SEND_STATUS);
1971 				if (qlt_need_explicit_conf(ha, cmd, 0)) {
1972 					pkt->u.status0.flags |=
1973 					    __constant_cpu_to_le16(
1974 						CTIO7_FLAGS_EXPLICIT_CONFORM |
1975 						CTIO7_FLAGS_CONFORM_REQ);
1976 				}
1977 			}
1978 
1979 		} else {
1980 			/*
1981 			 * We have already made sure that there is sufficient
1982 			 * amount of request entries to not drop HW lock in
1983 			 * req_pkt().
1984 			 */
1985 			struct ctio7_to_24xx *ctio =
1986 				(struct ctio7_to_24xx *)qlt_get_req_pkt(vha);
1987 
1988 			ql_dbg(ql_dbg_tgt, vha, 0xe019,
1989 			    "Building additional status packet\n");
1990 
1991 			memcpy(ctio, pkt, sizeof(*ctio));
1992 			ctio->entry_count = 1;
1993 			ctio->dseg_count = 0;
1994 			ctio->u.status1.flags &= ~__constant_cpu_to_le16(
1995 			    CTIO7_FLAGS_DATA_IN);
1996 
1997 			/* Real finish is ctio_m1's finish */
1998 			pkt->handle |= CTIO_INTERMEDIATE_HANDLE_MARK;
1999 			pkt->u.status0.flags |= __constant_cpu_to_le16(
2000 			    CTIO7_FLAGS_DONT_RET_CTIO);
2001 			qlt_24xx_init_ctio_to_isp((struct ctio7_to_24xx *)ctio,
2002 			    &prm);
2003 			pr_debug("Status CTIO7: %p\n", ctio);
2004 		}
2005 	} else
2006 		qlt_24xx_init_ctio_to_isp(pkt, &prm);
2007 
2008 
2009 	cmd->state = QLA_TGT_STATE_PROCESSED; /* Mid-level is done processing */
2010 
2011 	ql_dbg(ql_dbg_tgt, vha, 0xe01a,
2012 	    "Xmitting CTIO7 response pkt for 24xx: %p scsi_status: 0x%02x\n",
2013 	    pkt, scsi_status);
2014 
2015 	qla2x00_start_iocbs(vha, vha->req);
2016 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2017 
2018 	return 0;
2019 
2020 out_unmap_unlock:
2021 	if (cmd->sg_mapped)
2022 		qlt_unmap_sg(vha, cmd);
2023 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2024 
2025 	return res;
2026 }
2027 EXPORT_SYMBOL(qlt_xmit_response);
2028 
2029 int qlt_rdy_to_xfer(struct qla_tgt_cmd *cmd)
2030 {
2031 	struct ctio7_to_24xx *pkt;
2032 	struct scsi_qla_host *vha = cmd->vha;
2033 	struct qla_hw_data *ha = vha->hw;
2034 	struct qla_tgt *tgt = cmd->tgt;
2035 	struct qla_tgt_prm prm;
2036 	unsigned long flags;
2037 	int res = 0;
2038 
2039 	memset(&prm, 0, sizeof(prm));
2040 	prm.cmd = cmd;
2041 	prm.tgt = tgt;
2042 	prm.sg = NULL;
2043 	prm.req_cnt = 1;
2044 
2045 	/* Send marker if required */
2046 	if (qlt_issue_marker(vha, 0) != QLA_SUCCESS)
2047 		return -EIO;
2048 
2049 	ql_dbg(ql_dbg_tgt, vha, 0xe01b, "CTIO_start: vha(%d)",
2050 	    (int)vha->vp_idx);
2051 
2052 	/* Calculate number of entries and segments required */
2053 	if (qlt_pci_map_calc_cnt(&prm) != 0)
2054 		return -EAGAIN;
2055 
2056 	spin_lock_irqsave(&ha->hardware_lock, flags);
2057 
2058 	/* Does F/W have an IOCBs for this request */
2059 	res = qlt_check_reserve_free_req(vha, prm.req_cnt);
2060 	if (res != 0)
2061 		goto out_unlock_free_unmap;
2062 
2063 	res = qlt_24xx_build_ctio_pkt(&prm, vha);
2064 	if (unlikely(res != 0))
2065 		goto out_unlock_free_unmap;
2066 	pkt = (struct ctio7_to_24xx *)prm.pkt;
2067 	pkt->u.status0.flags |= __constant_cpu_to_le16(CTIO7_FLAGS_DATA_OUT |
2068 	    CTIO7_FLAGS_STATUS_MODE_0);
2069 	qlt_load_data_segments(&prm, vha);
2070 
2071 	cmd->state = QLA_TGT_STATE_NEED_DATA;
2072 
2073 	qla2x00_start_iocbs(vha, vha->req);
2074 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2075 
2076 	return res;
2077 
2078 out_unlock_free_unmap:
2079 	if (cmd->sg_mapped)
2080 		qlt_unmap_sg(vha, cmd);
2081 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2082 
2083 	return res;
2084 }
2085 EXPORT_SYMBOL(qlt_rdy_to_xfer);
2086 
2087 /* If hardware_lock held on entry, might drop it, then reaquire */
2088 /* This function sends the appropriate CTIO to ISP 2xxx or 24xx */
2089 static int __qlt_send_term_exchange(struct scsi_qla_host *vha,
2090 	struct qla_tgt_cmd *cmd,
2091 	struct atio_from_isp *atio)
2092 {
2093 	struct ctio7_to_24xx *ctio24;
2094 	struct qla_hw_data *ha = vha->hw;
2095 	request_t *pkt;
2096 	int ret = 0;
2097 
2098 	ql_dbg(ql_dbg_tgt, vha, 0xe01c, "Sending TERM EXCH CTIO (ha=%p)\n", ha);
2099 
2100 	pkt = (request_t *)qla2x00_alloc_iocbs(vha, NULL);
2101 	if (pkt == NULL) {
2102 		ql_dbg(ql_dbg_tgt, vha, 0xe050,
2103 		    "qla_target(%d): %s failed: unable to allocate "
2104 		    "request packet\n", vha->vp_idx, __func__);
2105 		return -ENOMEM;
2106 	}
2107 
2108 	if (cmd != NULL) {
2109 		if (cmd->state < QLA_TGT_STATE_PROCESSED) {
2110 			ql_dbg(ql_dbg_tgt, vha, 0xe051,
2111 			    "qla_target(%d): Terminating cmd %p with "
2112 			    "incorrect state %d\n", vha->vp_idx, cmd,
2113 			    cmd->state);
2114 		} else
2115 			ret = 1;
2116 	}
2117 
2118 	pkt->entry_count = 1;
2119 	pkt->handle = QLA_TGT_SKIP_HANDLE | CTIO_COMPLETION_HANDLE_MARK;
2120 
2121 	ctio24 = (struct ctio7_to_24xx *)pkt;
2122 	ctio24->entry_type = CTIO_TYPE7;
2123 	ctio24->nport_handle = cmd ? cmd->loop_id : CTIO7_NHANDLE_UNRECOGNIZED;
2124 	ctio24->timeout = __constant_cpu_to_le16(QLA_TGT_TIMEOUT);
2125 	ctio24->vp_index = vha->vp_idx;
2126 	ctio24->initiator_id[0] = atio->u.isp24.fcp_hdr.s_id[2];
2127 	ctio24->initiator_id[1] = atio->u.isp24.fcp_hdr.s_id[1];
2128 	ctio24->initiator_id[2] = atio->u.isp24.fcp_hdr.s_id[0];
2129 	ctio24->exchange_addr = atio->u.isp24.exchange_addr;
2130 	ctio24->u.status1.flags = (atio->u.isp24.attr << 9) |
2131 	    __constant_cpu_to_le16(CTIO7_FLAGS_STATUS_MODE_1 |
2132 		CTIO7_FLAGS_TERMINATE);
2133 	ctio24->u.status1.ox_id = swab16(atio->u.isp24.fcp_hdr.ox_id);
2134 
2135 	/* Most likely, it isn't needed */
2136 	ctio24->u.status1.residual = get_unaligned((uint32_t *)
2137 	    &atio->u.isp24.fcp_cmnd.add_cdb[
2138 	    atio->u.isp24.fcp_cmnd.add_cdb_len]);
2139 	if (ctio24->u.status1.residual != 0)
2140 		ctio24->u.status1.scsi_status |= SS_RESIDUAL_UNDER;
2141 
2142 	qla2x00_start_iocbs(vha, vha->req);
2143 	return ret;
2144 }
2145 
2146 static void qlt_send_term_exchange(struct scsi_qla_host *vha,
2147 	struct qla_tgt_cmd *cmd, struct atio_from_isp *atio, int ha_locked)
2148 {
2149 	unsigned long flags;
2150 	int rc;
2151 
2152 	if (qlt_issue_marker(vha, ha_locked) < 0)
2153 		return;
2154 
2155 	if (ha_locked) {
2156 		rc = __qlt_send_term_exchange(vha, cmd, atio);
2157 		goto done;
2158 	}
2159 	spin_lock_irqsave(&vha->hw->hardware_lock, flags);
2160 	rc = __qlt_send_term_exchange(vha, cmd, atio);
2161 	spin_unlock_irqrestore(&vha->hw->hardware_lock, flags);
2162 done:
2163 	if (rc == 1) {
2164 		if (!ha_locked && !in_interrupt())
2165 			msleep(250); /* just in case */
2166 
2167 		vha->hw->tgt.tgt_ops->free_cmd(cmd);
2168 	}
2169 }
2170 
2171 void qlt_free_cmd(struct qla_tgt_cmd *cmd)
2172 {
2173 	BUG_ON(cmd->sg_mapped);
2174 
2175 	if (unlikely(cmd->free_sg))
2176 		kfree(cmd->sg);
2177 	kmem_cache_free(qla_tgt_cmd_cachep, cmd);
2178 }
2179 EXPORT_SYMBOL(qlt_free_cmd);
2180 
2181 /* ha->hardware_lock supposed to be held on entry */
2182 static int qlt_prepare_srr_ctio(struct scsi_qla_host *vha,
2183 	struct qla_tgt_cmd *cmd, void *ctio)
2184 {
2185 	struct qla_tgt_srr_ctio *sc;
2186 	struct qla_hw_data *ha = vha->hw;
2187 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
2188 	struct qla_tgt_srr_imm *imm;
2189 
2190 	tgt->ctio_srr_id++;
2191 
2192 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf019,
2193 	    "qla_target(%d): CTIO with SRR status received\n", vha->vp_idx);
2194 
2195 	if (!ctio) {
2196 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf055,
2197 		    "qla_target(%d): SRR CTIO, but ctio is NULL\n",
2198 		    vha->vp_idx);
2199 		return -EINVAL;
2200 	}
2201 
2202 	sc = kzalloc(sizeof(*sc), GFP_ATOMIC);
2203 	if (sc != NULL) {
2204 		sc->cmd = cmd;
2205 		/* IRQ is already OFF */
2206 		spin_lock(&tgt->srr_lock);
2207 		sc->srr_id = tgt->ctio_srr_id;
2208 		list_add_tail(&sc->srr_list_entry,
2209 		    &tgt->srr_ctio_list);
2210 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01a,
2211 		    "CTIO SRR %p added (id %d)\n", sc, sc->srr_id);
2212 		if (tgt->imm_srr_id == tgt->ctio_srr_id) {
2213 			int found = 0;
2214 			list_for_each_entry(imm, &tgt->srr_imm_list,
2215 			    srr_list_entry) {
2216 				if (imm->srr_id == sc->srr_id) {
2217 					found = 1;
2218 					break;
2219 				}
2220 			}
2221 			if (found) {
2222 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01b,
2223 				    "Scheduling srr work\n");
2224 				schedule_work(&tgt->srr_work);
2225 			} else {
2226 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf056,
2227 				    "qla_target(%d): imm_srr_id "
2228 				    "== ctio_srr_id (%d), but there is no "
2229 				    "corresponding SRR IMM, deleting CTIO "
2230 				    "SRR %p\n", vha->vp_idx,
2231 				    tgt->ctio_srr_id, sc);
2232 				list_del(&sc->srr_list_entry);
2233 				spin_unlock(&tgt->srr_lock);
2234 
2235 				kfree(sc);
2236 				return -EINVAL;
2237 			}
2238 		}
2239 		spin_unlock(&tgt->srr_lock);
2240 	} else {
2241 		struct qla_tgt_srr_imm *ti;
2242 
2243 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf057,
2244 		    "qla_target(%d): Unable to allocate SRR CTIO entry\n",
2245 		    vha->vp_idx);
2246 		spin_lock(&tgt->srr_lock);
2247 		list_for_each_entry_safe(imm, ti, &tgt->srr_imm_list,
2248 		    srr_list_entry) {
2249 			if (imm->srr_id == tgt->ctio_srr_id) {
2250 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01c,
2251 				    "IMM SRR %p deleted (id %d)\n",
2252 				    imm, imm->srr_id);
2253 				list_del(&imm->srr_list_entry);
2254 				qlt_reject_free_srr_imm(vha, imm, 1);
2255 			}
2256 		}
2257 		spin_unlock(&tgt->srr_lock);
2258 
2259 		return -ENOMEM;
2260 	}
2261 
2262 	return 0;
2263 }
2264 
2265 /*
2266  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
2267  */
2268 static int qlt_term_ctio_exchange(struct scsi_qla_host *vha, void *ctio,
2269 	struct qla_tgt_cmd *cmd, uint32_t status)
2270 {
2271 	int term = 0;
2272 
2273 	if (ctio != NULL) {
2274 		struct ctio7_from_24xx *c = (struct ctio7_from_24xx *)ctio;
2275 		term = !(c->flags &
2276 		    __constant_cpu_to_le16(OF_TERM_EXCH));
2277 	} else
2278 		term = 1;
2279 
2280 	if (term)
2281 		qlt_send_term_exchange(vha, cmd, &cmd->atio, 1);
2282 
2283 	return term;
2284 }
2285 
2286 /* ha->hardware_lock supposed to be held on entry */
2287 static inline struct qla_tgt_cmd *qlt_get_cmd(struct scsi_qla_host *vha,
2288 	uint32_t handle)
2289 {
2290 	struct qla_hw_data *ha = vha->hw;
2291 
2292 	handle--;
2293 	if (ha->tgt.cmds[handle] != NULL) {
2294 		struct qla_tgt_cmd *cmd = ha->tgt.cmds[handle];
2295 		ha->tgt.cmds[handle] = NULL;
2296 		return cmd;
2297 	} else
2298 		return NULL;
2299 }
2300 
2301 /* ha->hardware_lock supposed to be held on entry */
2302 static struct qla_tgt_cmd *qlt_ctio_to_cmd(struct scsi_qla_host *vha,
2303 	uint32_t handle, void *ctio)
2304 {
2305 	struct qla_tgt_cmd *cmd = NULL;
2306 
2307 	/* Clear out internal marks */
2308 	handle &= ~(CTIO_COMPLETION_HANDLE_MARK |
2309 	    CTIO_INTERMEDIATE_HANDLE_MARK);
2310 
2311 	if (handle != QLA_TGT_NULL_HANDLE) {
2312 		if (unlikely(handle == QLA_TGT_SKIP_HANDLE)) {
2313 			ql_dbg(ql_dbg_tgt, vha, 0xe01d, "%s",
2314 			    "SKIP_HANDLE CTIO\n");
2315 			return NULL;
2316 		}
2317 		/* handle-1 is actually used */
2318 		if (unlikely(handle > DEFAULT_OUTSTANDING_COMMANDS)) {
2319 			ql_dbg(ql_dbg_tgt, vha, 0xe052,
2320 			    "qla_target(%d): Wrong handle %x received\n",
2321 			    vha->vp_idx, handle);
2322 			return NULL;
2323 		}
2324 		cmd = qlt_get_cmd(vha, handle);
2325 		if (unlikely(cmd == NULL)) {
2326 			ql_dbg(ql_dbg_tgt, vha, 0xe053,
2327 			    "qla_target(%d): Suspicious: unable to "
2328 			    "find the command with handle %x\n", vha->vp_idx,
2329 			    handle);
2330 			return NULL;
2331 		}
2332 	} else if (ctio != NULL) {
2333 		/* We can't get loop ID from CTIO7 */
2334 		ql_dbg(ql_dbg_tgt, vha, 0xe054,
2335 		    "qla_target(%d): Wrong CTIO received: QLA24xx doesn't "
2336 		    "support NULL handles\n", vha->vp_idx);
2337 		return NULL;
2338 	}
2339 
2340 	return cmd;
2341 }
2342 
2343 /*
2344  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
2345  */
2346 static void qlt_do_ctio_completion(struct scsi_qla_host *vha, uint32_t handle,
2347 	uint32_t status, void *ctio)
2348 {
2349 	struct qla_hw_data *ha = vha->hw;
2350 	struct se_cmd *se_cmd;
2351 	struct target_core_fabric_ops *tfo;
2352 	struct qla_tgt_cmd *cmd;
2353 
2354 	ql_dbg(ql_dbg_tgt, vha, 0xe01e,
2355 	    "qla_target(%d): handle(ctio %p status %#x) <- %08x\n",
2356 	    vha->vp_idx, ctio, status, handle);
2357 
2358 	if (handle & CTIO_INTERMEDIATE_HANDLE_MARK) {
2359 		/* That could happen only in case of an error/reset/abort */
2360 		if (status != CTIO_SUCCESS) {
2361 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01d,
2362 			    "Intermediate CTIO received"
2363 			    " (status %x)\n", status);
2364 		}
2365 		return;
2366 	}
2367 
2368 	cmd = qlt_ctio_to_cmd(vha, handle, ctio);
2369 	if (cmd == NULL)
2370 		return;
2371 
2372 	se_cmd = &cmd->se_cmd;
2373 	tfo = se_cmd->se_tfo;
2374 
2375 	if (cmd->sg_mapped)
2376 		qlt_unmap_sg(vha, cmd);
2377 
2378 	if (unlikely(status != CTIO_SUCCESS)) {
2379 		switch (status & 0xFFFF) {
2380 		case CTIO_LIP_RESET:
2381 		case CTIO_TARGET_RESET:
2382 		case CTIO_ABORTED:
2383 		case CTIO_TIMEOUT:
2384 		case CTIO_INVALID_RX_ID:
2385 			/* They are OK */
2386 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf058,
2387 			    "qla_target(%d): CTIO with "
2388 			    "status %#x received, state %x, se_cmd %p, "
2389 			    "(LIP_RESET=e, ABORTED=2, TARGET_RESET=17, "
2390 			    "TIMEOUT=b, INVALID_RX_ID=8)\n", vha->vp_idx,
2391 			    status, cmd->state, se_cmd);
2392 			break;
2393 
2394 		case CTIO_PORT_LOGGED_OUT:
2395 		case CTIO_PORT_UNAVAILABLE:
2396 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf059,
2397 			    "qla_target(%d): CTIO with PORT LOGGED "
2398 			    "OUT (29) or PORT UNAVAILABLE (28) status %x "
2399 			    "received (state %x, se_cmd %p)\n", vha->vp_idx,
2400 			    status, cmd->state, se_cmd);
2401 			break;
2402 
2403 		case CTIO_SRR_RECEIVED:
2404 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05a,
2405 			    "qla_target(%d): CTIO with SRR_RECEIVED"
2406 			    " status %x received (state %x, se_cmd %p)\n",
2407 			    vha->vp_idx, status, cmd->state, se_cmd);
2408 			if (qlt_prepare_srr_ctio(vha, cmd, ctio) != 0)
2409 				break;
2410 			else
2411 				return;
2412 
2413 		default:
2414 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05b,
2415 			    "qla_target(%d): CTIO with error status "
2416 			    "0x%x received (state %x, se_cmd %p\n",
2417 			    vha->vp_idx, status, cmd->state, se_cmd);
2418 			break;
2419 		}
2420 
2421 		if (cmd->state != QLA_TGT_STATE_NEED_DATA)
2422 			if (qlt_term_ctio_exchange(vha, ctio, cmd, status))
2423 				return;
2424 	}
2425 
2426 	if (cmd->state == QLA_TGT_STATE_PROCESSED) {
2427 		ql_dbg(ql_dbg_tgt, vha, 0xe01f, "Command %p finished\n", cmd);
2428 	} else if (cmd->state == QLA_TGT_STATE_NEED_DATA) {
2429 		int rx_status = 0;
2430 
2431 		cmd->state = QLA_TGT_STATE_DATA_IN;
2432 
2433 		if (unlikely(status != CTIO_SUCCESS))
2434 			rx_status = -EIO;
2435 		else
2436 			cmd->write_data_transferred = 1;
2437 
2438 		ql_dbg(ql_dbg_tgt, vha, 0xe020,
2439 		    "Data received, context %x, rx_status %d\n",
2440 		    0x0, rx_status);
2441 
2442 		ha->tgt.tgt_ops->handle_data(cmd);
2443 		return;
2444 	} else if (cmd->state == QLA_TGT_STATE_ABORTED) {
2445 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01e,
2446 		    "Aborted command %p (tag %d) finished\n", cmd, cmd->tag);
2447 	} else {
2448 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05c,
2449 		    "qla_target(%d): A command in state (%d) should "
2450 		    "not return a CTIO complete\n", vha->vp_idx, cmd->state);
2451 	}
2452 
2453 	if (unlikely(status != CTIO_SUCCESS)) {
2454 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf01f, "Finishing failed CTIO\n");
2455 		dump_stack();
2456 	}
2457 
2458 	ha->tgt.tgt_ops->free_cmd(cmd);
2459 }
2460 
2461 static inline int qlt_get_fcp_task_attr(struct scsi_qla_host *vha,
2462 	uint8_t task_codes)
2463 {
2464 	int fcp_task_attr;
2465 
2466 	switch (task_codes) {
2467 	case ATIO_SIMPLE_QUEUE:
2468 		fcp_task_attr = MSG_SIMPLE_TAG;
2469 		break;
2470 	case ATIO_HEAD_OF_QUEUE:
2471 		fcp_task_attr = MSG_HEAD_TAG;
2472 		break;
2473 	case ATIO_ORDERED_QUEUE:
2474 		fcp_task_attr = MSG_ORDERED_TAG;
2475 		break;
2476 	case ATIO_ACA_QUEUE:
2477 		fcp_task_attr = MSG_ACA_TAG;
2478 		break;
2479 	case ATIO_UNTAGGED:
2480 		fcp_task_attr = MSG_SIMPLE_TAG;
2481 		break;
2482 	default:
2483 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05d,
2484 		    "qla_target: unknown task code %x, use ORDERED instead\n",
2485 		    task_codes);
2486 		fcp_task_attr = MSG_ORDERED_TAG;
2487 		break;
2488 	}
2489 
2490 	return fcp_task_attr;
2491 }
2492 
2493 static struct qla_tgt_sess *qlt_make_local_sess(struct scsi_qla_host *,
2494 					uint8_t *);
2495 /*
2496  * Process context for I/O path into tcm_qla2xxx code
2497  */
2498 static void qlt_do_work(struct work_struct *work)
2499 {
2500 	struct qla_tgt_cmd *cmd = container_of(work, struct qla_tgt_cmd, work);
2501 	scsi_qla_host_t *vha = cmd->vha;
2502 	struct qla_hw_data *ha = vha->hw;
2503 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
2504 	struct qla_tgt_sess *sess = NULL;
2505 	struct atio_from_isp *atio = &cmd->atio;
2506 	unsigned char *cdb;
2507 	unsigned long flags;
2508 	uint32_t data_length;
2509 	int ret, fcp_task_attr, data_dir, bidi = 0;
2510 
2511 	if (tgt->tgt_stop)
2512 		goto out_term;
2513 
2514 	spin_lock_irqsave(&ha->hardware_lock, flags);
2515 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha,
2516 	    atio->u.isp24.fcp_hdr.s_id);
2517 	/* Do kref_get() before dropping qla_hw_data->hardware_lock. */
2518 	if (sess)
2519 		kref_get(&sess->se_sess->sess_kref);
2520 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2521 
2522 	if (unlikely(!sess)) {
2523 		uint8_t *s_id =	atio->u.isp24.fcp_hdr.s_id;
2524 
2525 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf022,
2526 			"qla_target(%d): Unable to find wwn login"
2527 			" (s_id %x:%x:%x), trying to create it manually\n",
2528 			vha->vp_idx, s_id[0], s_id[1], s_id[2]);
2529 
2530 		if (atio->u.raw.entry_count > 1) {
2531 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf023,
2532 				"Dropping multy entry cmd %p\n", cmd);
2533 			goto out_term;
2534 		}
2535 
2536 		mutex_lock(&ha->tgt.tgt_mutex);
2537 		sess = qlt_make_local_sess(vha, s_id);
2538 		/* sess has an extra creation ref. */
2539 		mutex_unlock(&ha->tgt.tgt_mutex);
2540 
2541 		if (!sess)
2542 			goto out_term;
2543 	}
2544 
2545 	cmd->sess = sess;
2546 	cmd->loop_id = sess->loop_id;
2547 	cmd->conf_compl_supported = sess->conf_compl_supported;
2548 
2549 	cdb = &atio->u.isp24.fcp_cmnd.cdb[0];
2550 	cmd->tag = atio->u.isp24.exchange_addr;
2551 	cmd->unpacked_lun = scsilun_to_int(
2552 	    (struct scsi_lun *)&atio->u.isp24.fcp_cmnd.lun);
2553 
2554 	if (atio->u.isp24.fcp_cmnd.rddata &&
2555 	    atio->u.isp24.fcp_cmnd.wrdata) {
2556 		bidi = 1;
2557 		data_dir = DMA_TO_DEVICE;
2558 	} else if (atio->u.isp24.fcp_cmnd.rddata)
2559 		data_dir = DMA_FROM_DEVICE;
2560 	else if (atio->u.isp24.fcp_cmnd.wrdata)
2561 		data_dir = DMA_TO_DEVICE;
2562 	else
2563 		data_dir = DMA_NONE;
2564 
2565 	fcp_task_attr = qlt_get_fcp_task_attr(vha,
2566 	    atio->u.isp24.fcp_cmnd.task_attr);
2567 	data_length = be32_to_cpu(get_unaligned((uint32_t *)
2568 	    &atio->u.isp24.fcp_cmnd.add_cdb[
2569 	    atio->u.isp24.fcp_cmnd.add_cdb_len]));
2570 
2571 	ql_dbg(ql_dbg_tgt, vha, 0xe022,
2572 	    "qla_target: START qla command: %p lun: 0x%04x (tag %d)\n",
2573 	    cmd, cmd->unpacked_lun, cmd->tag);
2574 
2575 	ret = vha->hw->tgt.tgt_ops->handle_cmd(vha, cmd, cdb, data_length,
2576 	    fcp_task_attr, data_dir, bidi);
2577 	if (ret != 0)
2578 		goto out_term;
2579 	/*
2580 	 * Drop extra session reference from qla_tgt_handle_cmd_for_atio*(
2581 	 */
2582 	spin_lock_irqsave(&ha->hardware_lock, flags);
2583 	ha->tgt.tgt_ops->put_sess(sess);
2584 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2585 	return;
2586 
2587 out_term:
2588 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf020, "Terminating work cmd %p", cmd);
2589 	/*
2590 	 * cmd has not sent to target yet, so pass NULL as the second
2591 	 * argument to qlt_send_term_exchange() and free the memory here.
2592 	 */
2593 	spin_lock_irqsave(&ha->hardware_lock, flags);
2594 	qlt_send_term_exchange(vha, NULL, &cmd->atio, 1);
2595 	kmem_cache_free(qla_tgt_cmd_cachep, cmd);
2596 	if (sess)
2597 		ha->tgt.tgt_ops->put_sess(sess);
2598 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
2599 }
2600 
2601 /* ha->hardware_lock supposed to be held on entry */
2602 static int qlt_handle_cmd_for_atio(struct scsi_qla_host *vha,
2603 	struct atio_from_isp *atio)
2604 {
2605 	struct qla_hw_data *ha = vha->hw;
2606 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
2607 	struct qla_tgt_cmd *cmd;
2608 
2609 	if (unlikely(tgt->tgt_stop)) {
2610 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf021,
2611 		    "New command while device %p is shutting down\n", tgt);
2612 		return -EFAULT;
2613 	}
2614 
2615 	cmd = kmem_cache_zalloc(qla_tgt_cmd_cachep, GFP_ATOMIC);
2616 	if (!cmd) {
2617 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05e,
2618 		    "qla_target(%d): Allocation of cmd failed\n", vha->vp_idx);
2619 		return -ENOMEM;
2620 	}
2621 
2622 	INIT_LIST_HEAD(&cmd->cmd_list);
2623 
2624 	memcpy(&cmd->atio, atio, sizeof(*atio));
2625 	cmd->state = QLA_TGT_STATE_NEW;
2626 	cmd->tgt = ha->tgt.qla_tgt;
2627 	cmd->vha = vha;
2628 
2629 	INIT_WORK(&cmd->work, qlt_do_work);
2630 	queue_work(qla_tgt_wq, &cmd->work);
2631 	return 0;
2632 
2633 }
2634 
2635 /* ha->hardware_lock supposed to be held on entry */
2636 static int qlt_issue_task_mgmt(struct qla_tgt_sess *sess, uint32_t lun,
2637 	int fn, void *iocb, int flags)
2638 {
2639 	struct scsi_qla_host *vha = sess->vha;
2640 	struct qla_hw_data *ha = vha->hw;
2641 	struct qla_tgt_mgmt_cmd *mcmd;
2642 	int res;
2643 	uint8_t tmr_func;
2644 
2645 	mcmd = mempool_alloc(qla_tgt_mgmt_cmd_mempool, GFP_ATOMIC);
2646 	if (!mcmd) {
2647 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10009,
2648 		    "qla_target(%d): Allocation of management "
2649 		    "command failed, some commands and their data could "
2650 		    "leak\n", vha->vp_idx);
2651 		return -ENOMEM;
2652 	}
2653 	memset(mcmd, 0, sizeof(*mcmd));
2654 	mcmd->sess = sess;
2655 
2656 	if (iocb) {
2657 		memcpy(&mcmd->orig_iocb.imm_ntfy, iocb,
2658 		    sizeof(mcmd->orig_iocb.imm_ntfy));
2659 	}
2660 	mcmd->tmr_func = fn;
2661 	mcmd->flags = flags;
2662 
2663 	switch (fn) {
2664 	case QLA_TGT_CLEAR_ACA:
2665 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10000,
2666 		    "qla_target(%d): CLEAR_ACA received\n", sess->vha->vp_idx);
2667 		tmr_func = TMR_CLEAR_ACA;
2668 		break;
2669 
2670 	case QLA_TGT_TARGET_RESET:
2671 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10001,
2672 		    "qla_target(%d): TARGET_RESET received\n",
2673 		    sess->vha->vp_idx);
2674 		tmr_func = TMR_TARGET_WARM_RESET;
2675 		break;
2676 
2677 	case QLA_TGT_LUN_RESET:
2678 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10002,
2679 		    "qla_target(%d): LUN_RESET received\n", sess->vha->vp_idx);
2680 		tmr_func = TMR_LUN_RESET;
2681 		break;
2682 
2683 	case QLA_TGT_CLEAR_TS:
2684 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10003,
2685 		    "qla_target(%d): CLEAR_TS received\n", sess->vha->vp_idx);
2686 		tmr_func = TMR_CLEAR_TASK_SET;
2687 		break;
2688 
2689 	case QLA_TGT_ABORT_TS:
2690 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10004,
2691 		    "qla_target(%d): ABORT_TS received\n", sess->vha->vp_idx);
2692 		tmr_func = TMR_ABORT_TASK_SET;
2693 		break;
2694 #if 0
2695 	case QLA_TGT_ABORT_ALL:
2696 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10005,
2697 		    "qla_target(%d): Doing ABORT_ALL_TASKS\n",
2698 		    sess->vha->vp_idx);
2699 		tmr_func = 0;
2700 		break;
2701 
2702 	case QLA_TGT_ABORT_ALL_SESS:
2703 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10006,
2704 		    "qla_target(%d): Doing ABORT_ALL_TASKS_SESS\n",
2705 		    sess->vha->vp_idx);
2706 		tmr_func = 0;
2707 		break;
2708 
2709 	case QLA_TGT_NEXUS_LOSS_SESS:
2710 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10007,
2711 		    "qla_target(%d): Doing NEXUS_LOSS_SESS\n",
2712 		    sess->vha->vp_idx);
2713 		tmr_func = 0;
2714 		break;
2715 
2716 	case QLA_TGT_NEXUS_LOSS:
2717 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x10008,
2718 		    "qla_target(%d): Doing NEXUS_LOSS\n", sess->vha->vp_idx);
2719 		tmr_func = 0;
2720 		break;
2721 #endif
2722 	default:
2723 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x1000a,
2724 		    "qla_target(%d): Unknown task mgmt fn 0x%x\n",
2725 		    sess->vha->vp_idx, fn);
2726 		mempool_free(mcmd, qla_tgt_mgmt_cmd_mempool);
2727 		return -ENOSYS;
2728 	}
2729 
2730 	res = ha->tgt.tgt_ops->handle_tmr(mcmd, lun, tmr_func, 0);
2731 	if (res != 0) {
2732 		ql_dbg(ql_dbg_tgt_tmr, vha, 0x1000b,
2733 		    "qla_target(%d): tgt.tgt_ops->handle_tmr() failed: %d\n",
2734 		    sess->vha->vp_idx, res);
2735 		mempool_free(mcmd, qla_tgt_mgmt_cmd_mempool);
2736 		return -EFAULT;
2737 	}
2738 
2739 	return 0;
2740 }
2741 
2742 /* ha->hardware_lock supposed to be held on entry */
2743 static int qlt_handle_task_mgmt(struct scsi_qla_host *vha, void *iocb)
2744 {
2745 	struct atio_from_isp *a = (struct atio_from_isp *)iocb;
2746 	struct qla_hw_data *ha = vha->hw;
2747 	struct qla_tgt *tgt;
2748 	struct qla_tgt_sess *sess;
2749 	uint32_t lun, unpacked_lun;
2750 	int lun_size, fn;
2751 
2752 	tgt = ha->tgt.qla_tgt;
2753 
2754 	lun = a->u.isp24.fcp_cmnd.lun;
2755 	lun_size = sizeof(a->u.isp24.fcp_cmnd.lun);
2756 	fn = a->u.isp24.fcp_cmnd.task_mgmt_flags;
2757 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha,
2758 	    a->u.isp24.fcp_hdr.s_id);
2759 	unpacked_lun = scsilun_to_int((struct scsi_lun *)&lun);
2760 
2761 	if (!sess) {
2762 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf024,
2763 		    "qla_target(%d): task mgmt fn 0x%x for "
2764 		    "non-existant session\n", vha->vp_idx, fn);
2765 		return qlt_sched_sess_work(tgt, QLA_TGT_SESS_WORK_TM, iocb,
2766 		    sizeof(struct atio_from_isp));
2767 	}
2768 
2769 	return qlt_issue_task_mgmt(sess, unpacked_lun, fn, iocb, 0);
2770 }
2771 
2772 /* ha->hardware_lock supposed to be held on entry */
2773 static int __qlt_abort_task(struct scsi_qla_host *vha,
2774 	struct imm_ntfy_from_isp *iocb, struct qla_tgt_sess *sess)
2775 {
2776 	struct atio_from_isp *a = (struct atio_from_isp *)iocb;
2777 	struct qla_hw_data *ha = vha->hw;
2778 	struct qla_tgt_mgmt_cmd *mcmd;
2779 	uint32_t lun, unpacked_lun;
2780 	int rc;
2781 
2782 	mcmd = mempool_alloc(qla_tgt_mgmt_cmd_mempool, GFP_ATOMIC);
2783 	if (mcmd == NULL) {
2784 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf05f,
2785 		    "qla_target(%d): %s: Allocation of ABORT cmd failed\n",
2786 		    vha->vp_idx, __func__);
2787 		return -ENOMEM;
2788 	}
2789 	memset(mcmd, 0, sizeof(*mcmd));
2790 
2791 	mcmd->sess = sess;
2792 	memcpy(&mcmd->orig_iocb.imm_ntfy, iocb,
2793 	    sizeof(mcmd->orig_iocb.imm_ntfy));
2794 
2795 	lun = a->u.isp24.fcp_cmnd.lun;
2796 	unpacked_lun = scsilun_to_int((struct scsi_lun *)&lun);
2797 
2798 	rc = ha->tgt.tgt_ops->handle_tmr(mcmd, unpacked_lun, TMR_ABORT_TASK,
2799 	    le16_to_cpu(iocb->u.isp2x.seq_id));
2800 	if (rc != 0) {
2801 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf060,
2802 		    "qla_target(%d): tgt_ops->handle_tmr() failed: %d\n",
2803 		    vha->vp_idx, rc);
2804 		mempool_free(mcmd, qla_tgt_mgmt_cmd_mempool);
2805 		return -EFAULT;
2806 	}
2807 
2808 	return 0;
2809 }
2810 
2811 /* ha->hardware_lock supposed to be held on entry */
2812 static int qlt_abort_task(struct scsi_qla_host *vha,
2813 	struct imm_ntfy_from_isp *iocb)
2814 {
2815 	struct qla_hw_data *ha = vha->hw;
2816 	struct qla_tgt_sess *sess;
2817 	int loop_id;
2818 
2819 	loop_id = GET_TARGET_ID(ha, (struct atio_from_isp *)iocb);
2820 
2821 	sess = ha->tgt.tgt_ops->find_sess_by_loop_id(vha, loop_id);
2822 	if (sess == NULL) {
2823 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf025,
2824 		    "qla_target(%d): task abort for unexisting "
2825 		    "session\n", vha->vp_idx);
2826 		return qlt_sched_sess_work(ha->tgt.qla_tgt,
2827 		    QLA_TGT_SESS_WORK_ABORT, iocb, sizeof(*iocb));
2828 	}
2829 
2830 	return __qlt_abort_task(vha, iocb, sess);
2831 }
2832 
2833 /*
2834  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
2835  */
2836 static int qlt_24xx_handle_els(struct scsi_qla_host *vha,
2837 	struct imm_ntfy_from_isp *iocb)
2838 {
2839 	struct qla_hw_data *ha = vha->hw;
2840 	int res = 0;
2841 
2842 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf026,
2843 	    "qla_target(%d): Port ID: 0x%02x:%02x:%02x"
2844 	    " ELS opcode: 0x%02x\n", vha->vp_idx, iocb->u.isp24.port_id[0],
2845 	    iocb->u.isp24.port_id[1], iocb->u.isp24.port_id[2],
2846 	    iocb->u.isp24.status_subcode);
2847 
2848 	switch (iocb->u.isp24.status_subcode) {
2849 	case ELS_PLOGI:
2850 	case ELS_FLOGI:
2851 	case ELS_PRLI:
2852 	case ELS_LOGO:
2853 	case ELS_PRLO:
2854 		res = qlt_reset(vha, iocb, QLA_TGT_NEXUS_LOSS_SESS);
2855 		break;
2856 	case ELS_PDISC:
2857 	case ELS_ADISC:
2858 	{
2859 		struct qla_tgt *tgt = ha->tgt.qla_tgt;
2860 		if (tgt->link_reinit_iocb_pending) {
2861 			qlt_send_notify_ack(vha, &tgt->link_reinit_iocb,
2862 			    0, 0, 0, 0, 0, 0);
2863 			tgt->link_reinit_iocb_pending = 0;
2864 		}
2865 		res = 1; /* send notify ack */
2866 		break;
2867 	}
2868 
2869 	default:
2870 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf061,
2871 		    "qla_target(%d): Unsupported ELS command %x "
2872 		    "received\n", vha->vp_idx, iocb->u.isp24.status_subcode);
2873 		res = qlt_reset(vha, iocb, QLA_TGT_NEXUS_LOSS_SESS);
2874 		break;
2875 	}
2876 
2877 	return res;
2878 }
2879 
2880 static int qlt_set_data_offset(struct qla_tgt_cmd *cmd, uint32_t offset)
2881 {
2882 	struct scatterlist *sg, *sgp, *sg_srr, *sg_srr_start = NULL;
2883 	size_t first_offset = 0, rem_offset = offset, tmp = 0;
2884 	int i, sg_srr_cnt, bufflen = 0;
2885 
2886 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe023,
2887 	    "Entering qla_tgt_set_data_offset: cmd: %p, cmd->sg: %p, "
2888 	    "cmd->sg_cnt: %u, direction: %d\n",
2889 	    cmd, cmd->sg, cmd->sg_cnt, cmd->dma_data_direction);
2890 
2891 	/*
2892 	 * FIXME: Reject non zero SRR relative offset until we can test
2893 	 * this code properly.
2894 	 */
2895 	pr_debug("Rejecting non zero SRR rel_offs: %u\n", offset);
2896 	return -1;
2897 
2898 	if (!cmd->sg || !cmd->sg_cnt) {
2899 		ql_dbg(ql_dbg_tgt, cmd->vha, 0xe055,
2900 		    "Missing cmd->sg or zero cmd->sg_cnt in"
2901 		    " qla_tgt_set_data_offset\n");
2902 		return -EINVAL;
2903 	}
2904 	/*
2905 	 * Walk the current cmd->sg list until we locate the new sg_srr_start
2906 	 */
2907 	for_each_sg(cmd->sg, sg, cmd->sg_cnt, i) {
2908 		ql_dbg(ql_dbg_tgt, cmd->vha, 0xe024,
2909 		    "sg[%d]: %p page: %p, length: %d, offset: %d\n",
2910 		    i, sg, sg_page(sg), sg->length, sg->offset);
2911 
2912 		if ((sg->length + tmp) > offset) {
2913 			first_offset = rem_offset;
2914 			sg_srr_start = sg;
2915 			ql_dbg(ql_dbg_tgt, cmd->vha, 0xe025,
2916 			    "Found matching sg[%d], using %p as sg_srr_start, "
2917 			    "and using first_offset: %zu\n", i, sg,
2918 			    first_offset);
2919 			break;
2920 		}
2921 		tmp += sg->length;
2922 		rem_offset -= sg->length;
2923 	}
2924 
2925 	if (!sg_srr_start) {
2926 		ql_dbg(ql_dbg_tgt, cmd->vha, 0xe056,
2927 		    "Unable to locate sg_srr_start for offset: %u\n", offset);
2928 		return -EINVAL;
2929 	}
2930 	sg_srr_cnt = (cmd->sg_cnt - i);
2931 
2932 	sg_srr = kzalloc(sizeof(struct scatterlist) * sg_srr_cnt, GFP_KERNEL);
2933 	if (!sg_srr) {
2934 		ql_dbg(ql_dbg_tgt, cmd->vha, 0xe057,
2935 		    "Unable to allocate sgp\n");
2936 		return -ENOMEM;
2937 	}
2938 	sg_init_table(sg_srr, sg_srr_cnt);
2939 	sgp = &sg_srr[0];
2940 	/*
2941 	 * Walk the remaining list for sg_srr_start, mapping to the newly
2942 	 * allocated sg_srr taking first_offset into account.
2943 	 */
2944 	for_each_sg(sg_srr_start, sg, sg_srr_cnt, i) {
2945 		if (first_offset) {
2946 			sg_set_page(sgp, sg_page(sg),
2947 			    (sg->length - first_offset), first_offset);
2948 			first_offset = 0;
2949 		} else {
2950 			sg_set_page(sgp, sg_page(sg), sg->length, 0);
2951 		}
2952 		bufflen += sgp->length;
2953 
2954 		sgp = sg_next(sgp);
2955 		if (!sgp)
2956 			break;
2957 	}
2958 
2959 	cmd->sg = sg_srr;
2960 	cmd->sg_cnt = sg_srr_cnt;
2961 	cmd->bufflen = bufflen;
2962 	cmd->offset += offset;
2963 	cmd->free_sg = 1;
2964 
2965 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe026, "New cmd->sg: %p\n", cmd->sg);
2966 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe027, "New cmd->sg_cnt: %u\n",
2967 	    cmd->sg_cnt);
2968 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe028, "New cmd->bufflen: %u\n",
2969 	    cmd->bufflen);
2970 	ql_dbg(ql_dbg_tgt, cmd->vha, 0xe029, "New cmd->offset: %u\n",
2971 	    cmd->offset);
2972 
2973 	if (cmd->sg_cnt < 0)
2974 		BUG();
2975 
2976 	if (cmd->bufflen < 0)
2977 		BUG();
2978 
2979 	return 0;
2980 }
2981 
2982 static inline int qlt_srr_adjust_data(struct qla_tgt_cmd *cmd,
2983 	uint32_t srr_rel_offs, int *xmit_type)
2984 {
2985 	int res = 0, rel_offs;
2986 
2987 	rel_offs = srr_rel_offs - cmd->offset;
2988 	ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf027, "srr_rel_offs=%d, rel_offs=%d",
2989 	    srr_rel_offs, rel_offs);
2990 
2991 	*xmit_type = QLA_TGT_XMIT_ALL;
2992 
2993 	if (rel_offs < 0) {
2994 		ql_dbg(ql_dbg_tgt_mgt, cmd->vha, 0xf062,
2995 		    "qla_target(%d): SRR rel_offs (%d) < 0",
2996 		    cmd->vha->vp_idx, rel_offs);
2997 		res = -1;
2998 	} else if (rel_offs == cmd->bufflen)
2999 		*xmit_type = QLA_TGT_XMIT_STATUS;
3000 	else if (rel_offs > 0)
3001 		res = qlt_set_data_offset(cmd, rel_offs);
3002 
3003 	return res;
3004 }
3005 
3006 /* No locks, thread context */
3007 static void qlt_handle_srr(struct scsi_qla_host *vha,
3008 	struct qla_tgt_srr_ctio *sctio, struct qla_tgt_srr_imm *imm)
3009 {
3010 	struct imm_ntfy_from_isp *ntfy =
3011 	    (struct imm_ntfy_from_isp *)&imm->imm_ntfy;
3012 	struct qla_hw_data *ha = vha->hw;
3013 	struct qla_tgt_cmd *cmd = sctio->cmd;
3014 	struct se_cmd *se_cmd = &cmd->se_cmd;
3015 	unsigned long flags;
3016 	int xmit_type = 0, resp = 0;
3017 	uint32_t offset;
3018 	uint16_t srr_ui;
3019 
3020 	offset = le32_to_cpu(ntfy->u.isp24.srr_rel_offs);
3021 	srr_ui = ntfy->u.isp24.srr_ui;
3022 
3023 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf028, "SRR cmd %p, srr_ui %x\n",
3024 	    cmd, srr_ui);
3025 
3026 	switch (srr_ui) {
3027 	case SRR_IU_STATUS:
3028 		spin_lock_irqsave(&ha->hardware_lock, flags);
3029 		qlt_send_notify_ack(vha, ntfy,
3030 		    0, 0, 0, NOTIFY_ACK_SRR_FLAGS_ACCEPT, 0, 0);
3031 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
3032 		xmit_type = QLA_TGT_XMIT_STATUS;
3033 		resp = 1;
3034 		break;
3035 	case SRR_IU_DATA_IN:
3036 		if (!cmd->sg || !cmd->sg_cnt) {
3037 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf063,
3038 			    "Unable to process SRR_IU_DATA_IN due to"
3039 			    " missing cmd->sg, state: %d\n", cmd->state);
3040 			dump_stack();
3041 			goto out_reject;
3042 		}
3043 		if (se_cmd->scsi_status != 0) {
3044 			ql_dbg(ql_dbg_tgt, vha, 0xe02a,
3045 			    "Rejecting SRR_IU_DATA_IN with non GOOD "
3046 			    "scsi_status\n");
3047 			goto out_reject;
3048 		}
3049 		cmd->bufflen = se_cmd->data_length;
3050 
3051 		if (qlt_has_data(cmd)) {
3052 			if (qlt_srr_adjust_data(cmd, offset, &xmit_type) != 0)
3053 				goto out_reject;
3054 			spin_lock_irqsave(&ha->hardware_lock, flags);
3055 			qlt_send_notify_ack(vha, ntfy,
3056 			    0, 0, 0, NOTIFY_ACK_SRR_FLAGS_ACCEPT, 0, 0);
3057 			spin_unlock_irqrestore(&ha->hardware_lock, flags);
3058 			resp = 1;
3059 		} else {
3060 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf064,
3061 			    "qla_target(%d): SRR for in data for cmd "
3062 			    "without them (tag %d, SCSI status %d), "
3063 			    "reject", vha->vp_idx, cmd->tag,
3064 			    cmd->se_cmd.scsi_status);
3065 			goto out_reject;
3066 		}
3067 		break;
3068 	case SRR_IU_DATA_OUT:
3069 		if (!cmd->sg || !cmd->sg_cnt) {
3070 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf065,
3071 			    "Unable to process SRR_IU_DATA_OUT due to"
3072 			    " missing cmd->sg\n");
3073 			dump_stack();
3074 			goto out_reject;
3075 		}
3076 		if (se_cmd->scsi_status != 0) {
3077 			ql_dbg(ql_dbg_tgt, vha, 0xe02b,
3078 			    "Rejecting SRR_IU_DATA_OUT"
3079 			    " with non GOOD scsi_status\n");
3080 			goto out_reject;
3081 		}
3082 		cmd->bufflen = se_cmd->data_length;
3083 
3084 		if (qlt_has_data(cmd)) {
3085 			if (qlt_srr_adjust_data(cmd, offset, &xmit_type) != 0)
3086 				goto out_reject;
3087 			spin_lock_irqsave(&ha->hardware_lock, flags);
3088 			qlt_send_notify_ack(vha, ntfy,
3089 			    0, 0, 0, NOTIFY_ACK_SRR_FLAGS_ACCEPT, 0, 0);
3090 			spin_unlock_irqrestore(&ha->hardware_lock, flags);
3091 			if (xmit_type & QLA_TGT_XMIT_DATA)
3092 				qlt_rdy_to_xfer(cmd);
3093 		} else {
3094 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf066,
3095 			    "qla_target(%d): SRR for out data for cmd "
3096 			    "without them (tag %d, SCSI status %d), "
3097 			    "reject", vha->vp_idx, cmd->tag,
3098 			    cmd->se_cmd.scsi_status);
3099 			goto out_reject;
3100 		}
3101 		break;
3102 	default:
3103 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf067,
3104 		    "qla_target(%d): Unknown srr_ui value %x",
3105 		    vha->vp_idx, srr_ui);
3106 		goto out_reject;
3107 	}
3108 
3109 	/* Transmit response in case of status and data-in cases */
3110 	if (resp)
3111 		qlt_xmit_response(cmd, xmit_type, se_cmd->scsi_status);
3112 
3113 	return;
3114 
3115 out_reject:
3116 	spin_lock_irqsave(&ha->hardware_lock, flags);
3117 	qlt_send_notify_ack(vha, ntfy, 0, 0, 0,
3118 	    NOTIFY_ACK_SRR_FLAGS_REJECT,
3119 	    NOTIFY_ACK_SRR_REJECT_REASON_UNABLE_TO_PERFORM,
3120 	    NOTIFY_ACK_SRR_FLAGS_REJECT_EXPL_NO_EXPL);
3121 	if (cmd->state == QLA_TGT_STATE_NEED_DATA) {
3122 		cmd->state = QLA_TGT_STATE_DATA_IN;
3123 		dump_stack();
3124 	} else
3125 		qlt_send_term_exchange(vha, cmd, &cmd->atio, 1);
3126 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
3127 }
3128 
3129 static void qlt_reject_free_srr_imm(struct scsi_qla_host *vha,
3130 	struct qla_tgt_srr_imm *imm, int ha_locked)
3131 {
3132 	struct qla_hw_data *ha = vha->hw;
3133 	unsigned long flags = 0;
3134 
3135 	if (!ha_locked)
3136 		spin_lock_irqsave(&ha->hardware_lock, flags);
3137 
3138 	qlt_send_notify_ack(vha, (void *)&imm->imm_ntfy, 0, 0, 0,
3139 	    NOTIFY_ACK_SRR_FLAGS_REJECT,
3140 	    NOTIFY_ACK_SRR_REJECT_REASON_UNABLE_TO_PERFORM,
3141 	    NOTIFY_ACK_SRR_FLAGS_REJECT_EXPL_NO_EXPL);
3142 
3143 	if (!ha_locked)
3144 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
3145 
3146 	kfree(imm);
3147 }
3148 
3149 static void qlt_handle_srr_work(struct work_struct *work)
3150 {
3151 	struct qla_tgt *tgt = container_of(work, struct qla_tgt, srr_work);
3152 	struct scsi_qla_host *vha = tgt->vha;
3153 	struct qla_tgt_srr_ctio *sctio;
3154 	unsigned long flags;
3155 
3156 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf029, "Entering SRR work (tgt %p)\n",
3157 	    tgt);
3158 
3159 restart:
3160 	spin_lock_irqsave(&tgt->srr_lock, flags);
3161 	list_for_each_entry(sctio, &tgt->srr_ctio_list, srr_list_entry) {
3162 		struct qla_tgt_srr_imm *imm, *i, *ti;
3163 		struct qla_tgt_cmd *cmd;
3164 		struct se_cmd *se_cmd;
3165 
3166 		imm = NULL;
3167 		list_for_each_entry_safe(i, ti, &tgt->srr_imm_list,
3168 						srr_list_entry) {
3169 			if (i->srr_id == sctio->srr_id) {
3170 				list_del(&i->srr_list_entry);
3171 				if (imm) {
3172 					ql_dbg(ql_dbg_tgt_mgt, vha, 0xf068,
3173 					  "qla_target(%d): There must be "
3174 					  "only one IMM SRR per CTIO SRR "
3175 					  "(IMM SRR %p, id %d, CTIO %p\n",
3176 					  vha->vp_idx, i, i->srr_id, sctio);
3177 					qlt_reject_free_srr_imm(tgt->vha, i, 0);
3178 				} else
3179 					imm = i;
3180 			}
3181 		}
3182 
3183 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02a,
3184 		    "IMM SRR %p, CTIO SRR %p (id %d)\n", imm, sctio,
3185 		    sctio->srr_id);
3186 
3187 		if (imm == NULL) {
3188 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02b,
3189 			    "Not found matching IMM for SRR CTIO (id %d)\n",
3190 			    sctio->srr_id);
3191 			continue;
3192 		} else
3193 			list_del(&sctio->srr_list_entry);
3194 
3195 		spin_unlock_irqrestore(&tgt->srr_lock, flags);
3196 
3197 		cmd = sctio->cmd;
3198 		/*
3199 		 * Reset qla_tgt_cmd SRR values and SGL pointer+count to follow
3200 		 * tcm_qla2xxx_write_pending() and tcm_qla2xxx_queue_data_in()
3201 		 * logic..
3202 		 */
3203 		cmd->offset = 0;
3204 		if (cmd->free_sg) {
3205 			kfree(cmd->sg);
3206 			cmd->sg = NULL;
3207 			cmd->free_sg = 0;
3208 		}
3209 		se_cmd = &cmd->se_cmd;
3210 
3211 		cmd->sg_cnt = se_cmd->t_data_nents;
3212 		cmd->sg = se_cmd->t_data_sg;
3213 
3214 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02c,
3215 		    "SRR cmd %p (se_cmd %p, tag %d, op %x), "
3216 		    "sg_cnt=%d, offset=%d", cmd, &cmd->se_cmd, cmd->tag,
3217 		    se_cmd->t_task_cdb[0], cmd->sg_cnt, cmd->offset);
3218 
3219 		qlt_handle_srr(vha, sctio, imm);
3220 
3221 		kfree(imm);
3222 		kfree(sctio);
3223 		goto restart;
3224 	}
3225 	spin_unlock_irqrestore(&tgt->srr_lock, flags);
3226 }
3227 
3228 /* ha->hardware_lock supposed to be held on entry */
3229 static void qlt_prepare_srr_imm(struct scsi_qla_host *vha,
3230 	struct imm_ntfy_from_isp *iocb)
3231 {
3232 	struct qla_tgt_srr_imm *imm;
3233 	struct qla_hw_data *ha = vha->hw;
3234 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
3235 	struct qla_tgt_srr_ctio *sctio;
3236 
3237 	tgt->imm_srr_id++;
3238 
3239 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02d, "qla_target(%d): SRR received\n",
3240 	    vha->vp_idx);
3241 
3242 	imm = kzalloc(sizeof(*imm), GFP_ATOMIC);
3243 	if (imm != NULL) {
3244 		memcpy(&imm->imm_ntfy, iocb, sizeof(imm->imm_ntfy));
3245 
3246 		/* IRQ is already OFF */
3247 		spin_lock(&tgt->srr_lock);
3248 		imm->srr_id = tgt->imm_srr_id;
3249 		list_add_tail(&imm->srr_list_entry,
3250 		    &tgt->srr_imm_list);
3251 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02e,
3252 		    "IMM NTFY SRR %p added (id %d, ui %x)\n",
3253 		    imm, imm->srr_id, iocb->u.isp24.srr_ui);
3254 		if (tgt->imm_srr_id == tgt->ctio_srr_id) {
3255 			int found = 0;
3256 			list_for_each_entry(sctio, &tgt->srr_ctio_list,
3257 			    srr_list_entry) {
3258 				if (sctio->srr_id == imm->srr_id) {
3259 					found = 1;
3260 					break;
3261 				}
3262 			}
3263 			if (found) {
3264 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf02f, "%s",
3265 				    "Scheduling srr work\n");
3266 				schedule_work(&tgt->srr_work);
3267 			} else {
3268 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf030,
3269 				    "qla_target(%d): imm_srr_id "
3270 				    "== ctio_srr_id (%d), but there is no "
3271 				    "corresponding SRR CTIO, deleting IMM "
3272 				    "SRR %p\n", vha->vp_idx, tgt->ctio_srr_id,
3273 				    imm);
3274 				list_del(&imm->srr_list_entry);
3275 
3276 				kfree(imm);
3277 
3278 				spin_unlock(&tgt->srr_lock);
3279 				goto out_reject;
3280 			}
3281 		}
3282 		spin_unlock(&tgt->srr_lock);
3283 	} else {
3284 		struct qla_tgt_srr_ctio *ts;
3285 
3286 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf069,
3287 		    "qla_target(%d): Unable to allocate SRR IMM "
3288 		    "entry, SRR request will be rejected\n", vha->vp_idx);
3289 
3290 		/* IRQ is already OFF */
3291 		spin_lock(&tgt->srr_lock);
3292 		list_for_each_entry_safe(sctio, ts, &tgt->srr_ctio_list,
3293 		    srr_list_entry) {
3294 			if (sctio->srr_id == tgt->imm_srr_id) {
3295 				ql_dbg(ql_dbg_tgt_mgt, vha, 0xf031,
3296 				    "CTIO SRR %p deleted (id %d)\n",
3297 				    sctio, sctio->srr_id);
3298 				list_del(&sctio->srr_list_entry);
3299 				qlt_send_term_exchange(vha, sctio->cmd,
3300 				    &sctio->cmd->atio, 1);
3301 				kfree(sctio);
3302 			}
3303 		}
3304 		spin_unlock(&tgt->srr_lock);
3305 		goto out_reject;
3306 	}
3307 
3308 	return;
3309 
3310 out_reject:
3311 	qlt_send_notify_ack(vha, iocb, 0, 0, 0,
3312 	    NOTIFY_ACK_SRR_FLAGS_REJECT,
3313 	    NOTIFY_ACK_SRR_REJECT_REASON_UNABLE_TO_PERFORM,
3314 	    NOTIFY_ACK_SRR_FLAGS_REJECT_EXPL_NO_EXPL);
3315 }
3316 
3317 /*
3318  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
3319  */
3320 static void qlt_handle_imm_notify(struct scsi_qla_host *vha,
3321 	struct imm_ntfy_from_isp *iocb)
3322 {
3323 	struct qla_hw_data *ha = vha->hw;
3324 	uint32_t add_flags = 0;
3325 	int send_notify_ack = 1;
3326 	uint16_t status;
3327 
3328 	status = le16_to_cpu(iocb->u.isp2x.status);
3329 	switch (status) {
3330 	case IMM_NTFY_LIP_RESET:
3331 	{
3332 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf032,
3333 		    "qla_target(%d): LIP reset (loop %#x), subcode %x\n",
3334 		    vha->vp_idx, le16_to_cpu(iocb->u.isp24.nport_handle),
3335 		    iocb->u.isp24.status_subcode);
3336 
3337 		if (qlt_reset(vha, iocb, QLA_TGT_ABORT_ALL) == 0)
3338 			send_notify_ack = 0;
3339 		break;
3340 	}
3341 
3342 	case IMM_NTFY_LIP_LINK_REINIT:
3343 	{
3344 		struct qla_tgt *tgt = ha->tgt.qla_tgt;
3345 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf033,
3346 		    "qla_target(%d): LINK REINIT (loop %#x, "
3347 		    "subcode %x)\n", vha->vp_idx,
3348 		    le16_to_cpu(iocb->u.isp24.nport_handle),
3349 		    iocb->u.isp24.status_subcode);
3350 		if (tgt->link_reinit_iocb_pending) {
3351 			qlt_send_notify_ack(vha, &tgt->link_reinit_iocb,
3352 			    0, 0, 0, 0, 0, 0);
3353 		}
3354 		memcpy(&tgt->link_reinit_iocb, iocb, sizeof(*iocb));
3355 		tgt->link_reinit_iocb_pending = 1;
3356 		/*
3357 		 * QLogic requires to wait after LINK REINIT for possible
3358 		 * PDISC or ADISC ELS commands
3359 		 */
3360 		send_notify_ack = 0;
3361 		break;
3362 	}
3363 
3364 	case IMM_NTFY_PORT_LOGOUT:
3365 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf034,
3366 		    "qla_target(%d): Port logout (loop "
3367 		    "%#x, subcode %x)\n", vha->vp_idx,
3368 		    le16_to_cpu(iocb->u.isp24.nport_handle),
3369 		    iocb->u.isp24.status_subcode);
3370 
3371 		if (qlt_reset(vha, iocb, QLA_TGT_NEXUS_LOSS_SESS) == 0)
3372 			send_notify_ack = 0;
3373 		/* The sessions will be cleared in the callback, if needed */
3374 		break;
3375 
3376 	case IMM_NTFY_GLBL_TPRLO:
3377 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf035,
3378 		    "qla_target(%d): Global TPRLO (%x)\n", vha->vp_idx, status);
3379 		if (qlt_reset(vha, iocb, QLA_TGT_NEXUS_LOSS) == 0)
3380 			send_notify_ack = 0;
3381 		/* The sessions will be cleared in the callback, if needed */
3382 		break;
3383 
3384 	case IMM_NTFY_PORT_CONFIG:
3385 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf036,
3386 		    "qla_target(%d): Port config changed (%x)\n", vha->vp_idx,
3387 		    status);
3388 		if (qlt_reset(vha, iocb, QLA_TGT_ABORT_ALL) == 0)
3389 			send_notify_ack = 0;
3390 		/* The sessions will be cleared in the callback, if needed */
3391 		break;
3392 
3393 	case IMM_NTFY_GLBL_LOGO:
3394 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06a,
3395 		    "qla_target(%d): Link failure detected\n",
3396 		    vha->vp_idx);
3397 		/* I_T nexus loss */
3398 		if (qlt_reset(vha, iocb, QLA_TGT_NEXUS_LOSS) == 0)
3399 			send_notify_ack = 0;
3400 		break;
3401 
3402 	case IMM_NTFY_IOCB_OVERFLOW:
3403 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06b,
3404 		    "qla_target(%d): Cannot provide requested "
3405 		    "capability (IOCB overflowed the immediate notify "
3406 		    "resource count)\n", vha->vp_idx);
3407 		break;
3408 
3409 	case IMM_NTFY_ABORT_TASK:
3410 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf037,
3411 		    "qla_target(%d): Abort Task (S %08x I %#x -> "
3412 		    "L %#x)\n", vha->vp_idx,
3413 		    le16_to_cpu(iocb->u.isp2x.seq_id),
3414 		    GET_TARGET_ID(ha, (struct atio_from_isp *)iocb),
3415 		    le16_to_cpu(iocb->u.isp2x.lun));
3416 		if (qlt_abort_task(vha, iocb) == 0)
3417 			send_notify_ack = 0;
3418 		break;
3419 
3420 	case IMM_NTFY_RESOURCE:
3421 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06c,
3422 		    "qla_target(%d): Out of resources, host %ld\n",
3423 		    vha->vp_idx, vha->host_no);
3424 		break;
3425 
3426 	case IMM_NTFY_MSG_RX:
3427 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf038,
3428 		    "qla_target(%d): Immediate notify task %x\n",
3429 		    vha->vp_idx, iocb->u.isp2x.task_flags);
3430 		if (qlt_handle_task_mgmt(vha, iocb) == 0)
3431 			send_notify_ack = 0;
3432 		break;
3433 
3434 	case IMM_NTFY_ELS:
3435 		if (qlt_24xx_handle_els(vha, iocb) == 0)
3436 			send_notify_ack = 0;
3437 		break;
3438 
3439 	case IMM_NTFY_SRR:
3440 		qlt_prepare_srr_imm(vha, iocb);
3441 		send_notify_ack = 0;
3442 		break;
3443 
3444 	default:
3445 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06d,
3446 		    "qla_target(%d): Received unknown immediate "
3447 		    "notify status %x\n", vha->vp_idx, status);
3448 		break;
3449 	}
3450 
3451 	if (send_notify_ack)
3452 		qlt_send_notify_ack(vha, iocb, add_flags, 0, 0, 0, 0, 0);
3453 }
3454 
3455 /*
3456  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
3457  * This function sends busy to ISP 2xxx or 24xx.
3458  */
3459 static void qlt_send_busy(struct scsi_qla_host *vha,
3460 	struct atio_from_isp *atio, uint16_t status)
3461 {
3462 	struct ctio7_to_24xx *ctio24;
3463 	struct qla_hw_data *ha = vha->hw;
3464 	request_t *pkt;
3465 	struct qla_tgt_sess *sess = NULL;
3466 
3467 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha,
3468 	    atio->u.isp24.fcp_hdr.s_id);
3469 	if (!sess) {
3470 		qlt_send_term_exchange(vha, NULL, atio, 1);
3471 		return;
3472 	}
3473 	/* Sending marker isn't necessary, since we called from ISR */
3474 
3475 	pkt = (request_t *)qla2x00_alloc_iocbs(vha, NULL);
3476 	if (!pkt) {
3477 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06e,
3478 		    "qla_target(%d): %s failed: unable to allocate "
3479 		    "request packet", vha->vp_idx, __func__);
3480 		return;
3481 	}
3482 
3483 	pkt->entry_count = 1;
3484 	pkt->handle = QLA_TGT_SKIP_HANDLE | CTIO_COMPLETION_HANDLE_MARK;
3485 
3486 	ctio24 = (struct ctio7_to_24xx *)pkt;
3487 	ctio24->entry_type = CTIO_TYPE7;
3488 	ctio24->nport_handle = sess->loop_id;
3489 	ctio24->timeout = __constant_cpu_to_le16(QLA_TGT_TIMEOUT);
3490 	ctio24->vp_index = vha->vp_idx;
3491 	ctio24->initiator_id[0] = atio->u.isp24.fcp_hdr.s_id[2];
3492 	ctio24->initiator_id[1] = atio->u.isp24.fcp_hdr.s_id[1];
3493 	ctio24->initiator_id[2] = atio->u.isp24.fcp_hdr.s_id[0];
3494 	ctio24->exchange_addr = atio->u.isp24.exchange_addr;
3495 	ctio24->u.status1.flags = (atio->u.isp24.attr << 9) |
3496 	    __constant_cpu_to_le16(
3497 		CTIO7_FLAGS_STATUS_MODE_1 | CTIO7_FLAGS_SEND_STATUS |
3498 		CTIO7_FLAGS_DONT_RET_CTIO);
3499 	/*
3500 	 * CTIO from fw w/o se_cmd doesn't provide enough info to retry it,
3501 	 * if the explicit conformation is used.
3502 	 */
3503 	ctio24->u.status1.ox_id = swab16(atio->u.isp24.fcp_hdr.ox_id);
3504 	ctio24->u.status1.scsi_status = cpu_to_le16(status);
3505 	ctio24->u.status1.residual = get_unaligned((uint32_t *)
3506 	    &atio->u.isp24.fcp_cmnd.add_cdb[
3507 	    atio->u.isp24.fcp_cmnd.add_cdb_len]);
3508 	if (ctio24->u.status1.residual != 0)
3509 		ctio24->u.status1.scsi_status |= SS_RESIDUAL_UNDER;
3510 
3511 	qla2x00_start_iocbs(vha, vha->req);
3512 }
3513 
3514 /* ha->hardware_lock supposed to be held on entry */
3515 /* called via callback from qla2xxx */
3516 static void qlt_24xx_atio_pkt(struct scsi_qla_host *vha,
3517 	struct atio_from_isp *atio)
3518 {
3519 	struct qla_hw_data *ha = vha->hw;
3520 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
3521 	int rc;
3522 
3523 	if (unlikely(tgt == NULL)) {
3524 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf039,
3525 		    "ATIO pkt, but no tgt (ha %p)", ha);
3526 		return;
3527 	}
3528 	ql_dbg(ql_dbg_tgt, vha, 0xe02c,
3529 	    "qla_target(%d): ATIO pkt %p: type %02x count %02x",
3530 	    vha->vp_idx, atio, atio->u.raw.entry_type,
3531 	    atio->u.raw.entry_count);
3532 	/*
3533 	 * In tgt_stop mode we also should allow all requests to pass.
3534 	 * Otherwise, some commands can stuck.
3535 	 */
3536 
3537 	tgt->irq_cmd_count++;
3538 
3539 	switch (atio->u.raw.entry_type) {
3540 	case ATIO_TYPE7:
3541 		ql_dbg(ql_dbg_tgt, vha, 0xe02d,
3542 		    "ATIO_TYPE7 instance %d, lun %Lx, read/write %d/%d, "
3543 		    "add_cdb_len %d, data_length %04x, s_id %x:%x:%x\n",
3544 		    vha->vp_idx, atio->u.isp24.fcp_cmnd.lun,
3545 		    atio->u.isp24.fcp_cmnd.rddata,
3546 		    atio->u.isp24.fcp_cmnd.wrdata,
3547 		    atio->u.isp24.fcp_cmnd.add_cdb_len,
3548 		    be32_to_cpu(get_unaligned((uint32_t *)
3549 			&atio->u.isp24.fcp_cmnd.add_cdb[
3550 			atio->u.isp24.fcp_cmnd.add_cdb_len])),
3551 		    atio->u.isp24.fcp_hdr.s_id[0],
3552 		    atio->u.isp24.fcp_hdr.s_id[1],
3553 		    atio->u.isp24.fcp_hdr.s_id[2]);
3554 
3555 		if (unlikely(atio->u.isp24.exchange_addr ==
3556 		    ATIO_EXCHANGE_ADDRESS_UNKNOWN)) {
3557 			ql_dbg(ql_dbg_tgt, vha, 0xe058,
3558 			    "qla_target(%d): ATIO_TYPE7 "
3559 			    "received with UNKNOWN exchange address, "
3560 			    "sending QUEUE_FULL\n", vha->vp_idx);
3561 			qlt_send_busy(vha, atio, SAM_STAT_TASK_SET_FULL);
3562 			break;
3563 		}
3564 		if (likely(atio->u.isp24.fcp_cmnd.task_mgmt_flags == 0))
3565 			rc = qlt_handle_cmd_for_atio(vha, atio);
3566 		else
3567 			rc = qlt_handle_task_mgmt(vha, atio);
3568 		if (unlikely(rc != 0)) {
3569 			if (rc == -ESRCH) {
3570 #if 1 /* With TERM EXCHANGE some FC cards refuse to boot */
3571 				qlt_send_busy(vha, atio, SAM_STAT_BUSY);
3572 #else
3573 				qlt_send_term_exchange(vha, NULL, atio, 1);
3574 #endif
3575 			} else {
3576 				if (tgt->tgt_stop) {
3577 					ql_dbg(ql_dbg_tgt, vha, 0xe059,
3578 					    "qla_target: Unable to send "
3579 					    "command to target for req, "
3580 					    "ignoring.\n");
3581 				} else {
3582 					ql_dbg(ql_dbg_tgt, vha, 0xe05a,
3583 					    "qla_target(%d): Unable to send "
3584 					    "command to target, sending BUSY "
3585 					    "status.\n", vha->vp_idx);
3586 					qlt_send_busy(vha, atio, SAM_STAT_BUSY);
3587 				}
3588 			}
3589 		}
3590 		break;
3591 
3592 	case IMMED_NOTIFY_TYPE:
3593 	{
3594 		if (unlikely(atio->u.isp2x.entry_status != 0)) {
3595 			ql_dbg(ql_dbg_tgt, vha, 0xe05b,
3596 			    "qla_target(%d): Received ATIO packet %x "
3597 			    "with error status %x\n", vha->vp_idx,
3598 			    atio->u.raw.entry_type,
3599 			    atio->u.isp2x.entry_status);
3600 			break;
3601 		}
3602 		ql_dbg(ql_dbg_tgt, vha, 0xe02e, "%s", "IMMED_NOTIFY ATIO");
3603 		qlt_handle_imm_notify(vha, (struct imm_ntfy_from_isp *)atio);
3604 		break;
3605 	}
3606 
3607 	default:
3608 		ql_dbg(ql_dbg_tgt, vha, 0xe05c,
3609 		    "qla_target(%d): Received unknown ATIO atio "
3610 		    "type %x\n", vha->vp_idx, atio->u.raw.entry_type);
3611 		break;
3612 	}
3613 
3614 	tgt->irq_cmd_count--;
3615 }
3616 
3617 /* ha->hardware_lock supposed to be held on entry */
3618 /* called via callback from qla2xxx */
3619 static void qlt_response_pkt(struct scsi_qla_host *vha, response_t *pkt)
3620 {
3621 	struct qla_hw_data *ha = vha->hw;
3622 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
3623 
3624 	if (unlikely(tgt == NULL)) {
3625 		ql_dbg(ql_dbg_tgt, vha, 0xe05d,
3626 		    "qla_target(%d): Response pkt %x received, but no "
3627 		    "tgt (ha %p)\n", vha->vp_idx, pkt->entry_type, ha);
3628 		return;
3629 	}
3630 
3631 	ql_dbg(ql_dbg_tgt, vha, 0xe02f,
3632 	    "qla_target(%d): response pkt %p: T %02x C %02x S %02x "
3633 	    "handle %#x\n", vha->vp_idx, pkt, pkt->entry_type,
3634 	    pkt->entry_count, pkt->entry_status, pkt->handle);
3635 
3636 	/*
3637 	 * In tgt_stop mode we also should allow all requests to pass.
3638 	 * Otherwise, some commands can stuck.
3639 	 */
3640 
3641 	tgt->irq_cmd_count++;
3642 
3643 	switch (pkt->entry_type) {
3644 	case CTIO_TYPE7:
3645 	{
3646 		struct ctio7_from_24xx *entry = (struct ctio7_from_24xx *)pkt;
3647 		ql_dbg(ql_dbg_tgt, vha, 0xe030, "CTIO_TYPE7: instance %d\n",
3648 		    vha->vp_idx);
3649 		qlt_do_ctio_completion(vha, entry->handle,
3650 		    le16_to_cpu(entry->status)|(pkt->entry_status << 16),
3651 		    entry);
3652 		break;
3653 	}
3654 
3655 	case ACCEPT_TGT_IO_TYPE:
3656 	{
3657 		struct atio_from_isp *atio = (struct atio_from_isp *)pkt;
3658 		int rc;
3659 		ql_dbg(ql_dbg_tgt, vha, 0xe031,
3660 		    "ACCEPT_TGT_IO instance %d status %04x "
3661 		    "lun %04x read/write %d data_length %04x "
3662 		    "target_id %02x rx_id %04x\n ", vha->vp_idx,
3663 		    le16_to_cpu(atio->u.isp2x.status),
3664 		    le16_to_cpu(atio->u.isp2x.lun),
3665 		    atio->u.isp2x.execution_codes,
3666 		    le32_to_cpu(atio->u.isp2x.data_length), GET_TARGET_ID(ha,
3667 		    atio), atio->u.isp2x.rx_id);
3668 		if (atio->u.isp2x.status !=
3669 		    __constant_cpu_to_le16(ATIO_CDB_VALID)) {
3670 			ql_dbg(ql_dbg_tgt, vha, 0xe05e,
3671 			    "qla_target(%d): ATIO with error "
3672 			    "status %x received\n", vha->vp_idx,
3673 			    le16_to_cpu(atio->u.isp2x.status));
3674 			break;
3675 		}
3676 		ql_dbg(ql_dbg_tgt, vha, 0xe032,
3677 		    "FCP CDB: 0x%02x, sizeof(cdb): %lu",
3678 		    atio->u.isp2x.cdb[0], (unsigned long
3679 		    int)sizeof(atio->u.isp2x.cdb));
3680 
3681 		rc = qlt_handle_cmd_for_atio(vha, atio);
3682 		if (unlikely(rc != 0)) {
3683 			if (rc == -ESRCH) {
3684 #if 1 /* With TERM EXCHANGE some FC cards refuse to boot */
3685 				qlt_send_busy(vha, atio, 0);
3686 #else
3687 				qlt_send_term_exchange(vha, NULL, atio, 1);
3688 #endif
3689 			} else {
3690 				if (tgt->tgt_stop) {
3691 					ql_dbg(ql_dbg_tgt, vha, 0xe05f,
3692 					    "qla_target: Unable to send "
3693 					    "command to target, sending TERM "
3694 					    "EXCHANGE for rsp\n");
3695 					qlt_send_term_exchange(vha, NULL,
3696 					    atio, 1);
3697 				} else {
3698 					ql_dbg(ql_dbg_tgt, vha, 0xe060,
3699 					    "qla_target(%d): Unable to send "
3700 					    "command to target, sending BUSY "
3701 					    "status\n", vha->vp_idx);
3702 					qlt_send_busy(vha, atio, 0);
3703 				}
3704 			}
3705 		}
3706 	}
3707 	break;
3708 
3709 	case CONTINUE_TGT_IO_TYPE:
3710 	{
3711 		struct ctio_to_2xxx *entry = (struct ctio_to_2xxx *)pkt;
3712 		ql_dbg(ql_dbg_tgt, vha, 0xe033,
3713 		    "CONTINUE_TGT_IO: instance %d\n", vha->vp_idx);
3714 		qlt_do_ctio_completion(vha, entry->handle,
3715 		    le16_to_cpu(entry->status)|(pkt->entry_status << 16),
3716 		    entry);
3717 		break;
3718 	}
3719 
3720 	case CTIO_A64_TYPE:
3721 	{
3722 		struct ctio_to_2xxx *entry = (struct ctio_to_2xxx *)pkt;
3723 		ql_dbg(ql_dbg_tgt, vha, 0xe034, "CTIO_A64: instance %d\n",
3724 		    vha->vp_idx);
3725 		qlt_do_ctio_completion(vha, entry->handle,
3726 		    le16_to_cpu(entry->status)|(pkt->entry_status << 16),
3727 		    entry);
3728 		break;
3729 	}
3730 
3731 	case IMMED_NOTIFY_TYPE:
3732 		ql_dbg(ql_dbg_tgt, vha, 0xe035, "%s", "IMMED_NOTIFY\n");
3733 		qlt_handle_imm_notify(vha, (struct imm_ntfy_from_isp *)pkt);
3734 		break;
3735 
3736 	case NOTIFY_ACK_TYPE:
3737 		if (tgt->notify_ack_expected > 0) {
3738 			struct nack_to_isp *entry = (struct nack_to_isp *)pkt;
3739 			ql_dbg(ql_dbg_tgt, vha, 0xe036,
3740 			    "NOTIFY_ACK seq %08x status %x\n",
3741 			    le16_to_cpu(entry->u.isp2x.seq_id),
3742 			    le16_to_cpu(entry->u.isp2x.status));
3743 			tgt->notify_ack_expected--;
3744 			if (entry->u.isp2x.status !=
3745 			    __constant_cpu_to_le16(NOTIFY_ACK_SUCCESS)) {
3746 				ql_dbg(ql_dbg_tgt, vha, 0xe061,
3747 				    "qla_target(%d): NOTIFY_ACK "
3748 				    "failed %x\n", vha->vp_idx,
3749 				    le16_to_cpu(entry->u.isp2x.status));
3750 			}
3751 		} else {
3752 			ql_dbg(ql_dbg_tgt, vha, 0xe062,
3753 			    "qla_target(%d): Unexpected NOTIFY_ACK received\n",
3754 			    vha->vp_idx);
3755 		}
3756 		break;
3757 
3758 	case ABTS_RECV_24XX:
3759 		ql_dbg(ql_dbg_tgt, vha, 0xe037,
3760 		    "ABTS_RECV_24XX: instance %d\n", vha->vp_idx);
3761 		qlt_24xx_handle_abts(vha, (struct abts_recv_from_24xx *)pkt);
3762 		break;
3763 
3764 	case ABTS_RESP_24XX:
3765 		if (tgt->abts_resp_expected > 0) {
3766 			struct abts_resp_from_24xx_fw *entry =
3767 				(struct abts_resp_from_24xx_fw *)pkt;
3768 			ql_dbg(ql_dbg_tgt, vha, 0xe038,
3769 			    "ABTS_RESP_24XX: compl_status %x\n",
3770 			    entry->compl_status);
3771 			tgt->abts_resp_expected--;
3772 			if (le16_to_cpu(entry->compl_status) !=
3773 			    ABTS_RESP_COMPL_SUCCESS) {
3774 				if ((entry->error_subcode1 == 0x1E) &&
3775 				    (entry->error_subcode2 == 0)) {
3776 					/*
3777 					 * We've got a race here: aborted
3778 					 * exchange not terminated, i.e.
3779 					 * response for the aborted command was
3780 					 * sent between the abort request was
3781 					 * received and processed.
3782 					 * Unfortunately, the firmware has a
3783 					 * silly requirement that all aborted
3784 					 * exchanges must be explicitely
3785 					 * terminated, otherwise it refuses to
3786 					 * send responses for the abort
3787 					 * requests. So, we have to
3788 					 * (re)terminate the exchange and retry
3789 					 * the abort response.
3790 					 */
3791 					qlt_24xx_retry_term_exchange(vha,
3792 					    entry);
3793 				} else
3794 					ql_dbg(ql_dbg_tgt, vha, 0xe063,
3795 					    "qla_target(%d): ABTS_RESP_24XX "
3796 					    "failed %x (subcode %x:%x)",
3797 					    vha->vp_idx, entry->compl_status,
3798 					    entry->error_subcode1,
3799 					    entry->error_subcode2);
3800 			}
3801 		} else {
3802 			ql_dbg(ql_dbg_tgt, vha, 0xe064,
3803 			    "qla_target(%d): Unexpected ABTS_RESP_24XX "
3804 			    "received\n", vha->vp_idx);
3805 		}
3806 		break;
3807 
3808 	default:
3809 		ql_dbg(ql_dbg_tgt, vha, 0xe065,
3810 		    "qla_target(%d): Received unknown response pkt "
3811 		    "type %x\n", vha->vp_idx, pkt->entry_type);
3812 		break;
3813 	}
3814 
3815 	tgt->irq_cmd_count--;
3816 }
3817 
3818 /*
3819  * ha->hardware_lock supposed to be held on entry. Might drop it, then reaquire
3820  */
3821 void qlt_async_event(uint16_t code, struct scsi_qla_host *vha,
3822 	uint16_t *mailbox)
3823 {
3824 	struct qla_hw_data *ha = vha->hw;
3825 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
3826 	int login_code;
3827 
3828 	ql_dbg(ql_dbg_tgt, vha, 0xe039,
3829 	    "scsi(%ld): ha state %d init_done %d oper_mode %d topo %d\n",
3830 	    vha->host_no, atomic_read(&vha->loop_state), vha->flags.init_done,
3831 	    ha->operating_mode, ha->current_topology);
3832 
3833 	if (!ha->tgt.tgt_ops)
3834 		return;
3835 
3836 	if (unlikely(tgt == NULL)) {
3837 		ql_dbg(ql_dbg_tgt, vha, 0xe03a,
3838 		    "ASYNC EVENT %#x, but no tgt (ha %p)\n", code, ha);
3839 		return;
3840 	}
3841 
3842 	if (((code == MBA_POINT_TO_POINT) || (code == MBA_CHG_IN_CONNECTION)) &&
3843 	    IS_QLA2100(ha))
3844 		return;
3845 	/*
3846 	 * In tgt_stop mode we also should allow all requests to pass.
3847 	 * Otherwise, some commands can stuck.
3848 	 */
3849 
3850 	tgt->irq_cmd_count++;
3851 
3852 	switch (code) {
3853 	case MBA_RESET:			/* Reset */
3854 	case MBA_SYSTEM_ERR:		/* System Error */
3855 	case MBA_REQ_TRANSFER_ERR:	/* Request Transfer Error */
3856 	case MBA_RSP_TRANSFER_ERR:	/* Response Transfer Error */
3857 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03a,
3858 		    "qla_target(%d): System error async event %#x "
3859 		    "occurred", vha->vp_idx, code);
3860 		break;
3861 	case MBA_WAKEUP_THRES:		/* Request Queue Wake-up. */
3862 		set_bit(ISP_ABORT_NEEDED, &vha->dpc_flags);
3863 		break;
3864 
3865 	case MBA_LOOP_UP:
3866 	{
3867 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03b,
3868 		    "qla_target(%d): Async LOOP_UP occurred "
3869 		    "(m[0]=%x, m[1]=%x, m[2]=%x, m[3]=%x)", vha->vp_idx,
3870 		    le16_to_cpu(mailbox[0]), le16_to_cpu(mailbox[1]),
3871 		    le16_to_cpu(mailbox[2]), le16_to_cpu(mailbox[3]));
3872 		if (tgt->link_reinit_iocb_pending) {
3873 			qlt_send_notify_ack(vha, (void *)&tgt->link_reinit_iocb,
3874 			    0, 0, 0, 0, 0, 0);
3875 			tgt->link_reinit_iocb_pending = 0;
3876 		}
3877 		break;
3878 	}
3879 
3880 	case MBA_LIP_OCCURRED:
3881 	case MBA_LOOP_DOWN:
3882 	case MBA_LIP_RESET:
3883 	case MBA_RSCN_UPDATE:
3884 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03c,
3885 		    "qla_target(%d): Async event %#x occurred "
3886 		    "(m[0]=%x, m[1]=%x, m[2]=%x, m[3]=%x)", vha->vp_idx, code,
3887 		    le16_to_cpu(mailbox[0]), le16_to_cpu(mailbox[1]),
3888 		    le16_to_cpu(mailbox[2]), le16_to_cpu(mailbox[3]));
3889 		break;
3890 
3891 	case MBA_PORT_UPDATE:
3892 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03d,
3893 		    "qla_target(%d): Port update async event %#x "
3894 		    "occurred: updating the ports database (m[0]=%x, m[1]=%x, "
3895 		    "m[2]=%x, m[3]=%x)", vha->vp_idx, code,
3896 		    le16_to_cpu(mailbox[0]), le16_to_cpu(mailbox[1]),
3897 		    le16_to_cpu(mailbox[2]), le16_to_cpu(mailbox[3]));
3898 
3899 		login_code = le16_to_cpu(mailbox[2]);
3900 		if (login_code == 0x4)
3901 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03e,
3902 			    "Async MB 2: Got PLOGI Complete\n");
3903 		else if (login_code == 0x7)
3904 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf03f,
3905 			    "Async MB 2: Port Logged Out\n");
3906 		break;
3907 
3908 	default:
3909 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf040,
3910 		    "qla_target(%d): Async event %#x occurred: "
3911 		    "ignore (m[0]=%x, m[1]=%x, m[2]=%x, m[3]=%x)", vha->vp_idx,
3912 		    code, le16_to_cpu(mailbox[0]), le16_to_cpu(mailbox[1]),
3913 		    le16_to_cpu(mailbox[2]), le16_to_cpu(mailbox[3]));
3914 		break;
3915 	}
3916 
3917 	tgt->irq_cmd_count--;
3918 }
3919 
3920 static fc_port_t *qlt_get_port_database(struct scsi_qla_host *vha,
3921 	uint16_t loop_id)
3922 {
3923 	fc_port_t *fcport;
3924 	int rc;
3925 
3926 	fcport = kzalloc(sizeof(*fcport), GFP_KERNEL);
3927 	if (!fcport) {
3928 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf06f,
3929 		    "qla_target(%d): Allocation of tmp FC port failed",
3930 		    vha->vp_idx);
3931 		return NULL;
3932 	}
3933 
3934 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf041, "loop_id %d", loop_id);
3935 
3936 	fcport->loop_id = loop_id;
3937 
3938 	rc = qla2x00_get_port_database(vha, fcport, 0);
3939 	if (rc != QLA_SUCCESS) {
3940 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf070,
3941 		    "qla_target(%d): Failed to retrieve fcport "
3942 		    "information -- get_port_database() returned %x "
3943 		    "(loop_id=0x%04x)", vha->vp_idx, rc, loop_id);
3944 		kfree(fcport);
3945 		return NULL;
3946 	}
3947 
3948 	return fcport;
3949 }
3950 
3951 /* Must be called under tgt_mutex */
3952 static struct qla_tgt_sess *qlt_make_local_sess(struct scsi_qla_host *vha,
3953 	uint8_t *s_id)
3954 {
3955 	struct qla_hw_data *ha = vha->hw;
3956 	struct qla_tgt_sess *sess = NULL;
3957 	fc_port_t *fcport = NULL;
3958 	int rc, global_resets;
3959 	uint16_t loop_id = 0;
3960 
3961 retry:
3962 	global_resets = atomic_read(&ha->tgt.qla_tgt->tgt_global_resets_count);
3963 
3964 	rc = qla24xx_get_loop_id(vha, s_id, &loop_id);
3965 	if (rc != 0) {
3966 		if ((s_id[0] == 0xFF) &&
3967 		    (s_id[1] == 0xFC)) {
3968 			/*
3969 			 * This is Domain Controller, so it should be
3970 			 * OK to drop SCSI commands from it.
3971 			 */
3972 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf042,
3973 			    "Unable to find initiator with S_ID %x:%x:%x",
3974 			    s_id[0], s_id[1], s_id[2]);
3975 		} else
3976 			ql_dbg(ql_dbg_tgt_mgt, vha, 0xf071,
3977 			    "qla_target(%d): Unable to find "
3978 			    "initiator with S_ID %x:%x:%x",
3979 			    vha->vp_idx, s_id[0], s_id[1],
3980 			    s_id[2]);
3981 		return NULL;
3982 	}
3983 
3984 	fcport = qlt_get_port_database(vha, loop_id);
3985 	if (!fcport)
3986 		return NULL;
3987 
3988 	if (global_resets !=
3989 	    atomic_read(&ha->tgt.qla_tgt->tgt_global_resets_count)) {
3990 		ql_dbg(ql_dbg_tgt_mgt, vha, 0xf043,
3991 		    "qla_target(%d): global reset during session discovery "
3992 		    "(counter was %d, new %d), retrying", vha->vp_idx,
3993 		    global_resets,
3994 		    atomic_read(&ha->tgt.qla_tgt->tgt_global_resets_count));
3995 		goto retry;
3996 	}
3997 
3998 	sess = qlt_create_sess(vha, fcport, true);
3999 
4000 	kfree(fcport);
4001 	return sess;
4002 }
4003 
4004 static void qlt_abort_work(struct qla_tgt *tgt,
4005 	struct qla_tgt_sess_work_param *prm)
4006 {
4007 	struct scsi_qla_host *vha = tgt->vha;
4008 	struct qla_hw_data *ha = vha->hw;
4009 	struct qla_tgt_sess *sess = NULL;
4010 	unsigned long flags;
4011 	uint32_t be_s_id;
4012 	uint8_t s_id[3];
4013 	int rc;
4014 
4015 	spin_lock_irqsave(&ha->hardware_lock, flags);
4016 
4017 	if (tgt->tgt_stop)
4018 		goto out_term;
4019 
4020 	s_id[0] = prm->abts.fcp_hdr_le.s_id[2];
4021 	s_id[1] = prm->abts.fcp_hdr_le.s_id[1];
4022 	s_id[2] = prm->abts.fcp_hdr_le.s_id[0];
4023 
4024 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha,
4025 	    (unsigned char *)&be_s_id);
4026 	if (!sess) {
4027 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
4028 
4029 		mutex_lock(&ha->tgt.tgt_mutex);
4030 		sess = qlt_make_local_sess(vha, s_id);
4031 		/* sess has got an extra creation ref */
4032 		mutex_unlock(&ha->tgt.tgt_mutex);
4033 
4034 		spin_lock_irqsave(&ha->hardware_lock, flags);
4035 		if (!sess)
4036 			goto out_term;
4037 	} else {
4038 		kref_get(&sess->se_sess->sess_kref);
4039 	}
4040 
4041 	if (tgt->tgt_stop)
4042 		goto out_term;
4043 
4044 	rc = __qlt_24xx_handle_abts(vha, &prm->abts, sess);
4045 	if (rc != 0)
4046 		goto out_term;
4047 
4048 	ha->tgt.tgt_ops->put_sess(sess);
4049 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4050 	return;
4051 
4052 out_term:
4053 	qlt_24xx_send_abts_resp(vha, &prm->abts, FCP_TMF_REJECTED, false);
4054 	if (sess)
4055 		ha->tgt.tgt_ops->put_sess(sess);
4056 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4057 }
4058 
4059 static void qlt_tmr_work(struct qla_tgt *tgt,
4060 	struct qla_tgt_sess_work_param *prm)
4061 {
4062 	struct atio_from_isp *a = &prm->tm_iocb2;
4063 	struct scsi_qla_host *vha = tgt->vha;
4064 	struct qla_hw_data *ha = vha->hw;
4065 	struct qla_tgt_sess *sess = NULL;
4066 	unsigned long flags;
4067 	uint8_t *s_id = NULL; /* to hide compiler warnings */
4068 	int rc;
4069 	uint32_t lun, unpacked_lun;
4070 	int lun_size, fn;
4071 	void *iocb;
4072 
4073 	spin_lock_irqsave(&ha->hardware_lock, flags);
4074 
4075 	if (tgt->tgt_stop)
4076 		goto out_term;
4077 
4078 	s_id = prm->tm_iocb2.u.isp24.fcp_hdr.s_id;
4079 	sess = ha->tgt.tgt_ops->find_sess_by_s_id(vha, s_id);
4080 	if (!sess) {
4081 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
4082 
4083 		mutex_lock(&ha->tgt.tgt_mutex);
4084 		sess = qlt_make_local_sess(vha, s_id);
4085 		/* sess has got an extra creation ref */
4086 		mutex_unlock(&ha->tgt.tgt_mutex);
4087 
4088 		spin_lock_irqsave(&ha->hardware_lock, flags);
4089 		if (!sess)
4090 			goto out_term;
4091 	} else {
4092 		kref_get(&sess->se_sess->sess_kref);
4093 	}
4094 
4095 	iocb = a;
4096 	lun = a->u.isp24.fcp_cmnd.lun;
4097 	lun_size = sizeof(lun);
4098 	fn = a->u.isp24.fcp_cmnd.task_mgmt_flags;
4099 	unpacked_lun = scsilun_to_int((struct scsi_lun *)&lun);
4100 
4101 	rc = qlt_issue_task_mgmt(sess, unpacked_lun, fn, iocb, 0);
4102 	if (rc != 0)
4103 		goto out_term;
4104 
4105 	ha->tgt.tgt_ops->put_sess(sess);
4106 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4107 	return;
4108 
4109 out_term:
4110 	qlt_send_term_exchange(vha, NULL, &prm->tm_iocb2, 1);
4111 	if (sess)
4112 		ha->tgt.tgt_ops->put_sess(sess);
4113 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4114 }
4115 
4116 static void qlt_sess_work_fn(struct work_struct *work)
4117 {
4118 	struct qla_tgt *tgt = container_of(work, struct qla_tgt, sess_work);
4119 	struct scsi_qla_host *vha = tgt->vha;
4120 	unsigned long flags;
4121 
4122 	ql_dbg(ql_dbg_tgt_mgt, vha, 0xf000, "Sess work (tgt %p)", tgt);
4123 
4124 	spin_lock_irqsave(&tgt->sess_work_lock, flags);
4125 	while (!list_empty(&tgt->sess_works_list)) {
4126 		struct qla_tgt_sess_work_param *prm = list_entry(
4127 		    tgt->sess_works_list.next, typeof(*prm),
4128 		    sess_works_list_entry);
4129 
4130 		/*
4131 		 * This work can be scheduled on several CPUs at time, so we
4132 		 * must delete the entry to eliminate double processing
4133 		 */
4134 		list_del(&prm->sess_works_list_entry);
4135 
4136 		spin_unlock_irqrestore(&tgt->sess_work_lock, flags);
4137 
4138 		switch (prm->type) {
4139 		case QLA_TGT_SESS_WORK_ABORT:
4140 			qlt_abort_work(tgt, prm);
4141 			break;
4142 		case QLA_TGT_SESS_WORK_TM:
4143 			qlt_tmr_work(tgt, prm);
4144 			break;
4145 		default:
4146 			BUG_ON(1);
4147 			break;
4148 		}
4149 
4150 		spin_lock_irqsave(&tgt->sess_work_lock, flags);
4151 
4152 		kfree(prm);
4153 	}
4154 	spin_unlock_irqrestore(&tgt->sess_work_lock, flags);
4155 }
4156 
4157 /* Must be called under tgt_host_action_mutex */
4158 int qlt_add_target(struct qla_hw_data *ha, struct scsi_qla_host *base_vha)
4159 {
4160 	struct qla_tgt *tgt;
4161 
4162 	if (!QLA_TGT_MODE_ENABLED())
4163 		return 0;
4164 
4165 	if (!IS_TGT_MODE_CAPABLE(ha)) {
4166 		ql_log(ql_log_warn, base_vha, 0xe070,
4167 		    "This adapter does not support target mode.\n");
4168 		return 0;
4169 	}
4170 
4171 	ql_dbg(ql_dbg_tgt, base_vha, 0xe03b,
4172 	    "Registering target for host %ld(%p)", base_vha->host_no, ha);
4173 
4174 	BUG_ON((ha->tgt.qla_tgt != NULL) || (ha->tgt.tgt_ops != NULL));
4175 
4176 	tgt = kzalloc(sizeof(struct qla_tgt), GFP_KERNEL);
4177 	if (!tgt) {
4178 		ql_dbg(ql_dbg_tgt, base_vha, 0xe066,
4179 		    "Unable to allocate struct qla_tgt\n");
4180 		return -ENOMEM;
4181 	}
4182 
4183 	if (!(base_vha->host->hostt->supported_mode & MODE_TARGET))
4184 		base_vha->host->hostt->supported_mode |= MODE_TARGET;
4185 
4186 	tgt->ha = ha;
4187 	tgt->vha = base_vha;
4188 	init_waitqueue_head(&tgt->waitQ);
4189 	INIT_LIST_HEAD(&tgt->sess_list);
4190 	INIT_LIST_HEAD(&tgt->del_sess_list);
4191 	INIT_DELAYED_WORK(&tgt->sess_del_work,
4192 		(void (*)(struct work_struct *))qlt_del_sess_work_fn);
4193 	spin_lock_init(&tgt->sess_work_lock);
4194 	INIT_WORK(&tgt->sess_work, qlt_sess_work_fn);
4195 	INIT_LIST_HEAD(&tgt->sess_works_list);
4196 	spin_lock_init(&tgt->srr_lock);
4197 	INIT_LIST_HEAD(&tgt->srr_ctio_list);
4198 	INIT_LIST_HEAD(&tgt->srr_imm_list);
4199 	INIT_WORK(&tgt->srr_work, qlt_handle_srr_work);
4200 	atomic_set(&tgt->tgt_global_resets_count, 0);
4201 
4202 	ha->tgt.qla_tgt = tgt;
4203 
4204 	ql_dbg(ql_dbg_tgt, base_vha, 0xe067,
4205 		"qla_target(%d): using 64 Bit PCI addressing",
4206 		base_vha->vp_idx);
4207 	tgt->tgt_enable_64bit_addr = 1;
4208 	/* 3 is reserved */
4209 	tgt->sg_tablesize = QLA_TGT_MAX_SG_24XX(base_vha->req->length - 3);
4210 	tgt->datasegs_per_cmd = QLA_TGT_DATASEGS_PER_CMD_24XX;
4211 	tgt->datasegs_per_cont = QLA_TGT_DATASEGS_PER_CONT_24XX;
4212 
4213 	mutex_lock(&qla_tgt_mutex);
4214 	list_add_tail(&tgt->tgt_list_entry, &qla_tgt_glist);
4215 	mutex_unlock(&qla_tgt_mutex);
4216 
4217 	return 0;
4218 }
4219 
4220 /* Must be called under tgt_host_action_mutex */
4221 int qlt_remove_target(struct qla_hw_data *ha, struct scsi_qla_host *vha)
4222 {
4223 	if (!ha->tgt.qla_tgt)
4224 		return 0;
4225 
4226 	mutex_lock(&qla_tgt_mutex);
4227 	list_del(&ha->tgt.qla_tgt->tgt_list_entry);
4228 	mutex_unlock(&qla_tgt_mutex);
4229 
4230 	ql_dbg(ql_dbg_tgt, vha, 0xe03c, "Unregistering target for host %ld(%p)",
4231 	    vha->host_no, ha);
4232 	qlt_release(ha->tgt.qla_tgt);
4233 
4234 	return 0;
4235 }
4236 
4237 static void qlt_lport_dump(struct scsi_qla_host *vha, u64 wwpn,
4238 	unsigned char *b)
4239 {
4240 	int i;
4241 
4242 	pr_debug("qla2xxx HW vha->node_name: ");
4243 	for (i = 0; i < WWN_SIZE; i++)
4244 		pr_debug("%02x ", vha->node_name[i]);
4245 	pr_debug("\n");
4246 	pr_debug("qla2xxx HW vha->port_name: ");
4247 	for (i = 0; i < WWN_SIZE; i++)
4248 		pr_debug("%02x ", vha->port_name[i]);
4249 	pr_debug("\n");
4250 
4251 	pr_debug("qla2xxx passed configfs WWPN: ");
4252 	put_unaligned_be64(wwpn, b);
4253 	for (i = 0; i < WWN_SIZE; i++)
4254 		pr_debug("%02x ", b[i]);
4255 	pr_debug("\n");
4256 }
4257 
4258 /**
4259  * qla_tgt_lport_register - register lport with external module
4260  *
4261  * @qla_tgt_ops: Pointer for tcm_qla2xxx qla_tgt_ops
4262  * @wwpn: Passwd FC target WWPN
4263  * @callback:  lport initialization callback for tcm_qla2xxx code
4264  * @target_lport_ptr: pointer for tcm_qla2xxx specific lport data
4265  */
4266 int qlt_lport_register(struct qla_tgt_func_tmpl *qla_tgt_ops, u64 wwpn,
4267 	int (*callback)(struct scsi_qla_host *), void *target_lport_ptr)
4268 {
4269 	struct qla_tgt *tgt;
4270 	struct scsi_qla_host *vha;
4271 	struct qla_hw_data *ha;
4272 	struct Scsi_Host *host;
4273 	unsigned long flags;
4274 	int rc;
4275 	u8 b[WWN_SIZE];
4276 
4277 	mutex_lock(&qla_tgt_mutex);
4278 	list_for_each_entry(tgt, &qla_tgt_glist, tgt_list_entry) {
4279 		vha = tgt->vha;
4280 		ha = vha->hw;
4281 
4282 		host = vha->host;
4283 		if (!host)
4284 			continue;
4285 
4286 		if (ha->tgt.tgt_ops != NULL)
4287 			continue;
4288 
4289 		if (!(host->hostt->supported_mode & MODE_TARGET))
4290 			continue;
4291 
4292 		spin_lock_irqsave(&ha->hardware_lock, flags);
4293 		if (host->active_mode & MODE_TARGET) {
4294 			pr_debug("MODE_TARGET already active on qla2xxx(%d)\n",
4295 			    host->host_no);
4296 			spin_unlock_irqrestore(&ha->hardware_lock, flags);
4297 			continue;
4298 		}
4299 		spin_unlock_irqrestore(&ha->hardware_lock, flags);
4300 
4301 		if (!scsi_host_get(host)) {
4302 			ql_dbg(ql_dbg_tgt, vha, 0xe068,
4303 			    "Unable to scsi_host_get() for"
4304 			    " qla2xxx scsi_host\n");
4305 			continue;
4306 		}
4307 		qlt_lport_dump(vha, wwpn, b);
4308 
4309 		if (memcmp(vha->port_name, b, WWN_SIZE)) {
4310 			scsi_host_put(host);
4311 			continue;
4312 		}
4313 		/*
4314 		 * Setup passed parameters ahead of invoking callback
4315 		 */
4316 		ha->tgt.tgt_ops = qla_tgt_ops;
4317 		ha->tgt.target_lport_ptr = target_lport_ptr;
4318 		rc = (*callback)(vha);
4319 		if (rc != 0) {
4320 			ha->tgt.tgt_ops = NULL;
4321 			ha->tgt.target_lport_ptr = NULL;
4322 		}
4323 		mutex_unlock(&qla_tgt_mutex);
4324 		return rc;
4325 	}
4326 	mutex_unlock(&qla_tgt_mutex);
4327 
4328 	return -ENODEV;
4329 }
4330 EXPORT_SYMBOL(qlt_lport_register);
4331 
4332 /**
4333  * qla_tgt_lport_deregister - Degister lport
4334  *
4335  * @vha:  Registered scsi_qla_host pointer
4336  */
4337 void qlt_lport_deregister(struct scsi_qla_host *vha)
4338 {
4339 	struct qla_hw_data *ha = vha->hw;
4340 	struct Scsi_Host *sh = vha->host;
4341 	/*
4342 	 * Clear the target_lport_ptr qla_target_template pointer in qla_hw_data
4343 	 */
4344 	ha->tgt.target_lport_ptr = NULL;
4345 	ha->tgt.tgt_ops = NULL;
4346 	/*
4347 	 * Release the Scsi_Host reference for the underlying qla2xxx host
4348 	 */
4349 	scsi_host_put(sh);
4350 }
4351 EXPORT_SYMBOL(qlt_lport_deregister);
4352 
4353 /* Must be called under HW lock */
4354 void qlt_set_mode(struct scsi_qla_host *vha)
4355 {
4356 	struct qla_hw_data *ha = vha->hw;
4357 
4358 	switch (ql2x_ini_mode) {
4359 	case QLA2XXX_INI_MODE_DISABLED:
4360 	case QLA2XXX_INI_MODE_EXCLUSIVE:
4361 		vha->host->active_mode = MODE_TARGET;
4362 		break;
4363 	case QLA2XXX_INI_MODE_ENABLED:
4364 		vha->host->active_mode |= MODE_TARGET;
4365 		break;
4366 	default:
4367 		break;
4368 	}
4369 
4370 	if (ha->tgt.ini_mode_force_reverse)
4371 		qla_reverse_ini_mode(vha);
4372 }
4373 
4374 /* Must be called under HW lock */
4375 void qlt_clear_mode(struct scsi_qla_host *vha)
4376 {
4377 	struct qla_hw_data *ha = vha->hw;
4378 
4379 	switch (ql2x_ini_mode) {
4380 	case QLA2XXX_INI_MODE_DISABLED:
4381 		vha->host->active_mode = MODE_UNKNOWN;
4382 		break;
4383 	case QLA2XXX_INI_MODE_EXCLUSIVE:
4384 		vha->host->active_mode = MODE_INITIATOR;
4385 		break;
4386 	case QLA2XXX_INI_MODE_ENABLED:
4387 		vha->host->active_mode &= ~MODE_TARGET;
4388 		break;
4389 	default:
4390 		break;
4391 	}
4392 
4393 	if (ha->tgt.ini_mode_force_reverse)
4394 		qla_reverse_ini_mode(vha);
4395 }
4396 
4397 /*
4398  * qla_tgt_enable_vha - NO LOCK HELD
4399  *
4400  * host_reset, bring up w/ Target Mode Enabled
4401  */
4402 void
4403 qlt_enable_vha(struct scsi_qla_host *vha)
4404 {
4405 	struct qla_hw_data *ha = vha->hw;
4406 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
4407 	unsigned long flags;
4408 
4409 	if (!tgt) {
4410 		ql_dbg(ql_dbg_tgt, vha, 0xe069,
4411 		    "Unable to locate qla_tgt pointer from"
4412 		    " struct qla_hw_data\n");
4413 		dump_stack();
4414 		return;
4415 	}
4416 
4417 	spin_lock_irqsave(&ha->hardware_lock, flags);
4418 	tgt->tgt_stopped = 0;
4419 	qlt_set_mode(vha);
4420 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4421 
4422 	set_bit(ISP_ABORT_NEEDED, &vha->dpc_flags);
4423 	qla2xxx_wake_dpc(vha);
4424 	qla2x00_wait_for_hba_online(vha);
4425 }
4426 EXPORT_SYMBOL(qlt_enable_vha);
4427 
4428 /*
4429  * qla_tgt_disable_vha - NO LOCK HELD
4430  *
4431  * Disable Target Mode and reset the adapter
4432  */
4433 void
4434 qlt_disable_vha(struct scsi_qla_host *vha)
4435 {
4436 	struct qla_hw_data *ha = vha->hw;
4437 	struct qla_tgt *tgt = ha->tgt.qla_tgt;
4438 	unsigned long flags;
4439 
4440 	if (!tgt) {
4441 		ql_dbg(ql_dbg_tgt, vha, 0xe06a,
4442 		    "Unable to locate qla_tgt pointer from"
4443 		    " struct qla_hw_data\n");
4444 		dump_stack();
4445 		return;
4446 	}
4447 
4448 	spin_lock_irqsave(&ha->hardware_lock, flags);
4449 	qlt_clear_mode(vha);
4450 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4451 
4452 	set_bit(ISP_ABORT_NEEDED, &vha->dpc_flags);
4453 	qla2xxx_wake_dpc(vha);
4454 	qla2x00_wait_for_hba_online(vha);
4455 }
4456 
4457 /*
4458  * Called from qla_init.c:qla24xx_vport_create() contex to setup
4459  * the target mode specific struct scsi_qla_host and struct qla_hw_data
4460  * members.
4461  */
4462 void
4463 qlt_vport_create(struct scsi_qla_host *vha, struct qla_hw_data *ha)
4464 {
4465 	if (!qla_tgt_mode_enabled(vha))
4466 		return;
4467 
4468 	mutex_init(&ha->tgt.tgt_mutex);
4469 	mutex_init(&ha->tgt.tgt_host_action_mutex);
4470 
4471 	qlt_clear_mode(vha);
4472 
4473 	/*
4474 	 * NOTE: Currently the value is kept the same for <24xx and
4475 	 * >=24xx ISPs. If it is necessary to change it,
4476 	 * the check should be added for specific ISPs,
4477 	 * assigning the value appropriately.
4478 	 */
4479 	ha->tgt.atio_q_length = ATIO_ENTRY_CNT_24XX;
4480 }
4481 
4482 void
4483 qlt_rff_id(struct scsi_qla_host *vha, struct ct_sns_req *ct_req)
4484 {
4485 	/*
4486 	 * FC-4 Feature bit 0 indicates target functionality to the name server.
4487 	 */
4488 	if (qla_tgt_mode_enabled(vha)) {
4489 		if (qla_ini_mode_enabled(vha))
4490 			ct_req->req.rff_id.fc4_feature = BIT_0 | BIT_1;
4491 		else
4492 			ct_req->req.rff_id.fc4_feature = BIT_0;
4493 	} else if (qla_ini_mode_enabled(vha)) {
4494 		ct_req->req.rff_id.fc4_feature = BIT_1;
4495 	}
4496 }
4497 
4498 /*
4499  * qlt_init_atio_q_entries() - Initializes ATIO queue entries.
4500  * @ha: HA context
4501  *
4502  * Beginning of ATIO ring has initialization control block already built
4503  * by nvram config routine.
4504  *
4505  * Returns 0 on success.
4506  */
4507 void
4508 qlt_init_atio_q_entries(struct scsi_qla_host *vha)
4509 {
4510 	struct qla_hw_data *ha = vha->hw;
4511 	uint16_t cnt;
4512 	struct atio_from_isp *pkt = (struct atio_from_isp *)ha->tgt.atio_ring;
4513 
4514 	if (!qla_tgt_mode_enabled(vha))
4515 		return;
4516 
4517 	for (cnt = 0; cnt < ha->tgt.atio_q_length; cnt++) {
4518 		pkt->u.raw.signature = ATIO_PROCESSED;
4519 		pkt++;
4520 	}
4521 
4522 }
4523 
4524 /*
4525  * qlt_24xx_process_atio_queue() - Process ATIO queue entries.
4526  * @ha: SCSI driver HA context
4527  */
4528 void
4529 qlt_24xx_process_atio_queue(struct scsi_qla_host *vha)
4530 {
4531 	struct qla_hw_data *ha = vha->hw;
4532 	struct atio_from_isp *pkt;
4533 	int cnt, i;
4534 
4535 	if (!vha->flags.online)
4536 		return;
4537 
4538 	while (ha->tgt.atio_ring_ptr->signature != ATIO_PROCESSED) {
4539 		pkt = (struct atio_from_isp *)ha->tgt.atio_ring_ptr;
4540 		cnt = pkt->u.raw.entry_count;
4541 
4542 		qlt_24xx_atio_pkt_all_vps(vha, (struct atio_from_isp *)pkt);
4543 
4544 		for (i = 0; i < cnt; i++) {
4545 			ha->tgt.atio_ring_index++;
4546 			if (ha->tgt.atio_ring_index == ha->tgt.atio_q_length) {
4547 				ha->tgt.atio_ring_index = 0;
4548 				ha->tgt.atio_ring_ptr = ha->tgt.atio_ring;
4549 			} else
4550 				ha->tgt.atio_ring_ptr++;
4551 
4552 			pkt->u.raw.signature = ATIO_PROCESSED;
4553 			pkt = (struct atio_from_isp *)ha->tgt.atio_ring_ptr;
4554 		}
4555 		wmb();
4556 	}
4557 
4558 	/* Adjust ring index */
4559 	WRT_REG_DWORD(ISP_ATIO_Q_OUT(vha), ha->tgt.atio_ring_index);
4560 }
4561 
4562 void
4563 qlt_24xx_config_rings(struct scsi_qla_host *vha)
4564 {
4565 	struct qla_hw_data *ha = vha->hw;
4566 	if (!QLA_TGT_MODE_ENABLED())
4567 		return;
4568 
4569 	WRT_REG_DWORD(ISP_ATIO_Q_IN(vha), 0);
4570 	WRT_REG_DWORD(ISP_ATIO_Q_OUT(vha), 0);
4571 	RD_REG_DWORD(ISP_ATIO_Q_OUT(vha));
4572 
4573 	if (IS_ATIO_MSIX_CAPABLE(ha)) {
4574 		struct qla_msix_entry *msix = &ha->msix_entries[2];
4575 		struct init_cb_24xx *icb = (struct init_cb_24xx *)ha->init_cb;
4576 
4577 		icb->msix_atio = cpu_to_le16(msix->entry);
4578 		ql_dbg(ql_dbg_init, vha, 0xf072,
4579 		    "Registering ICB vector 0x%x for atio que.\n",
4580 		    msix->entry);
4581 	}
4582 }
4583 
4584 void
4585 qlt_24xx_config_nvram_stage1(struct scsi_qla_host *vha, struct nvram_24xx *nv)
4586 {
4587 	struct qla_hw_data *ha = vha->hw;
4588 
4589 	if (qla_tgt_mode_enabled(vha)) {
4590 		if (!ha->tgt.saved_set) {
4591 			/* We save only once */
4592 			ha->tgt.saved_exchange_count = nv->exchange_count;
4593 			ha->tgt.saved_firmware_options_1 =
4594 			    nv->firmware_options_1;
4595 			ha->tgt.saved_firmware_options_2 =
4596 			    nv->firmware_options_2;
4597 			ha->tgt.saved_firmware_options_3 =
4598 			    nv->firmware_options_3;
4599 			ha->tgt.saved_set = 1;
4600 		}
4601 
4602 		nv->exchange_count = __constant_cpu_to_le16(0xFFFF);
4603 
4604 		/* Enable target mode */
4605 		nv->firmware_options_1 |= __constant_cpu_to_le32(BIT_4);
4606 
4607 		/* Disable ini mode, if requested */
4608 		if (!qla_ini_mode_enabled(vha))
4609 			nv->firmware_options_1 |= __constant_cpu_to_le32(BIT_5);
4610 
4611 		/* Disable Full Login after LIP */
4612 		nv->firmware_options_1 &= __constant_cpu_to_le32(~BIT_13);
4613 		/* Enable initial LIP */
4614 		nv->firmware_options_1 &= __constant_cpu_to_le32(~BIT_9);
4615 		/* Enable FC tapes support */
4616 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_12);
4617 		/* Disable Full Login after LIP */
4618 		nv->host_p &= __constant_cpu_to_le32(~BIT_10);
4619 		/* Enable target PRLI control */
4620 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_14);
4621 	} else {
4622 		if (ha->tgt.saved_set) {
4623 			nv->exchange_count = ha->tgt.saved_exchange_count;
4624 			nv->firmware_options_1 =
4625 			    ha->tgt.saved_firmware_options_1;
4626 			nv->firmware_options_2 =
4627 			    ha->tgt.saved_firmware_options_2;
4628 			nv->firmware_options_3 =
4629 			    ha->tgt.saved_firmware_options_3;
4630 		}
4631 		return;
4632 	}
4633 
4634 	/* out-of-order frames reassembly */
4635 	nv->firmware_options_3 |= BIT_6|BIT_9;
4636 
4637 	if (ha->tgt.enable_class_2) {
4638 		if (vha->flags.init_done)
4639 			fc_host_supported_classes(vha->host) =
4640 				FC_COS_CLASS2 | FC_COS_CLASS3;
4641 
4642 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_8);
4643 	} else {
4644 		if (vha->flags.init_done)
4645 			fc_host_supported_classes(vha->host) = FC_COS_CLASS3;
4646 
4647 		nv->firmware_options_2 &= ~__constant_cpu_to_le32(BIT_8);
4648 	}
4649 }
4650 
4651 void
4652 qlt_24xx_config_nvram_stage2(struct scsi_qla_host *vha,
4653 	struct init_cb_24xx *icb)
4654 {
4655 	struct qla_hw_data *ha = vha->hw;
4656 
4657 	if (ha->tgt.node_name_set) {
4658 		memcpy(icb->node_name, ha->tgt.tgt_node_name, WWN_SIZE);
4659 		icb->firmware_options_1 |= __constant_cpu_to_le32(BIT_14);
4660 	}
4661 }
4662 
4663 void
4664 qlt_81xx_config_nvram_stage1(struct scsi_qla_host *vha, struct nvram_81xx *nv)
4665 {
4666 	struct qla_hw_data *ha = vha->hw;
4667 
4668 	if (!QLA_TGT_MODE_ENABLED())
4669 		return;
4670 
4671 	if (qla_tgt_mode_enabled(vha)) {
4672 		if (!ha->tgt.saved_set) {
4673 			/* We save only once */
4674 			ha->tgt.saved_exchange_count = nv->exchange_count;
4675 			ha->tgt.saved_firmware_options_1 =
4676 			    nv->firmware_options_1;
4677 			ha->tgt.saved_firmware_options_2 =
4678 			    nv->firmware_options_2;
4679 			ha->tgt.saved_firmware_options_3 =
4680 			    nv->firmware_options_3;
4681 			ha->tgt.saved_set = 1;
4682 		}
4683 
4684 		nv->exchange_count = __constant_cpu_to_le16(0xFFFF);
4685 
4686 		/* Enable target mode */
4687 		nv->firmware_options_1 |= __constant_cpu_to_le32(BIT_4);
4688 
4689 		/* Disable ini mode, if requested */
4690 		if (!qla_ini_mode_enabled(vha))
4691 			nv->firmware_options_1 |=
4692 			    __constant_cpu_to_le32(BIT_5);
4693 
4694 		/* Disable Full Login after LIP */
4695 		nv->firmware_options_1 &= __constant_cpu_to_le32(~BIT_13);
4696 		/* Enable initial LIP */
4697 		nv->firmware_options_1 &= __constant_cpu_to_le32(~BIT_9);
4698 		/* Enable FC tapes support */
4699 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_12);
4700 		/* Disable Full Login after LIP */
4701 		nv->host_p &= __constant_cpu_to_le32(~BIT_10);
4702 		/* Enable target PRLI control */
4703 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_14);
4704 	} else {
4705 		if (ha->tgt.saved_set) {
4706 			nv->exchange_count = ha->tgt.saved_exchange_count;
4707 			nv->firmware_options_1 =
4708 			    ha->tgt.saved_firmware_options_1;
4709 			nv->firmware_options_2 =
4710 			    ha->tgt.saved_firmware_options_2;
4711 			nv->firmware_options_3 =
4712 			    ha->tgt.saved_firmware_options_3;
4713 		}
4714 		return;
4715 	}
4716 
4717 	/* out-of-order frames reassembly */
4718 	nv->firmware_options_3 |= BIT_6|BIT_9;
4719 
4720 	if (ha->tgt.enable_class_2) {
4721 		if (vha->flags.init_done)
4722 			fc_host_supported_classes(vha->host) =
4723 				FC_COS_CLASS2 | FC_COS_CLASS3;
4724 
4725 		nv->firmware_options_2 |= __constant_cpu_to_le32(BIT_8);
4726 	} else {
4727 		if (vha->flags.init_done)
4728 			fc_host_supported_classes(vha->host) = FC_COS_CLASS3;
4729 
4730 		nv->firmware_options_2 &= ~__constant_cpu_to_le32(BIT_8);
4731 	}
4732 }
4733 
4734 void
4735 qlt_81xx_config_nvram_stage2(struct scsi_qla_host *vha,
4736 	struct init_cb_81xx *icb)
4737 {
4738 	struct qla_hw_data *ha = vha->hw;
4739 
4740 	if (!QLA_TGT_MODE_ENABLED())
4741 		return;
4742 
4743 	if (ha->tgt.node_name_set) {
4744 		memcpy(icb->node_name, ha->tgt.tgt_node_name, WWN_SIZE);
4745 		icb->firmware_options_1 |= __constant_cpu_to_le32(BIT_14);
4746 	}
4747 }
4748 
4749 void
4750 qlt_83xx_iospace_config(struct qla_hw_data *ha)
4751 {
4752 	if (!QLA_TGT_MODE_ENABLED())
4753 		return;
4754 
4755 	ha->msix_count += 1; /* For ATIO Q */
4756 }
4757 
4758 int
4759 qlt_24xx_process_response_error(struct scsi_qla_host *vha,
4760 	struct sts_entry_24xx *pkt)
4761 {
4762 	switch (pkt->entry_type) {
4763 	case ABTS_RECV_24XX:
4764 	case ABTS_RESP_24XX:
4765 	case CTIO_TYPE7:
4766 	case NOTIFY_ACK_TYPE:
4767 		return 1;
4768 	default:
4769 		return 0;
4770 	}
4771 }
4772 
4773 void
4774 qlt_modify_vp_config(struct scsi_qla_host *vha,
4775 	struct vp_config_entry_24xx *vpmod)
4776 {
4777 	if (qla_tgt_mode_enabled(vha))
4778 		vpmod->options_idx1 &= ~BIT_5;
4779 	/* Disable ini mode, if requested */
4780 	if (!qla_ini_mode_enabled(vha))
4781 		vpmod->options_idx1 &= ~BIT_4;
4782 }
4783 
4784 void
4785 qlt_probe_one_stage1(struct scsi_qla_host *base_vha, struct qla_hw_data *ha)
4786 {
4787 	if (!QLA_TGT_MODE_ENABLED())
4788 		return;
4789 
4790 	if  (ha->mqenable || IS_QLA83XX(ha)) {
4791 		ISP_ATIO_Q_IN(base_vha) = &ha->mqiobase->isp25mq.atio_q_in;
4792 		ISP_ATIO_Q_OUT(base_vha) = &ha->mqiobase->isp25mq.atio_q_out;
4793 	} else {
4794 		ISP_ATIO_Q_IN(base_vha) = &ha->iobase->isp24.atio_q_in;
4795 		ISP_ATIO_Q_OUT(base_vha) = &ha->iobase->isp24.atio_q_out;
4796 	}
4797 
4798 	mutex_init(&ha->tgt.tgt_mutex);
4799 	mutex_init(&ha->tgt.tgt_host_action_mutex);
4800 	qlt_clear_mode(base_vha);
4801 }
4802 
4803 irqreturn_t
4804 qla83xx_msix_atio_q(int irq, void *dev_id)
4805 {
4806 	struct rsp_que *rsp;
4807 	scsi_qla_host_t	*vha;
4808 	struct qla_hw_data *ha;
4809 	unsigned long flags;
4810 
4811 	rsp = (struct rsp_que *) dev_id;
4812 	ha = rsp->hw;
4813 	vha = pci_get_drvdata(ha->pdev);
4814 
4815 	spin_lock_irqsave(&ha->hardware_lock, flags);
4816 
4817 	qlt_24xx_process_atio_queue(vha);
4818 	qla24xx_process_response_queue(vha, rsp);
4819 
4820 	spin_unlock_irqrestore(&ha->hardware_lock, flags);
4821 
4822 	return IRQ_HANDLED;
4823 }
4824 
4825 int
4826 qlt_mem_alloc(struct qla_hw_data *ha)
4827 {
4828 	if (!QLA_TGT_MODE_ENABLED())
4829 		return 0;
4830 
4831 	ha->tgt.tgt_vp_map = kzalloc(sizeof(struct qla_tgt_vp_map) *
4832 	    MAX_MULTI_ID_FABRIC, GFP_KERNEL);
4833 	if (!ha->tgt.tgt_vp_map)
4834 		return -ENOMEM;
4835 
4836 	ha->tgt.atio_ring = dma_alloc_coherent(&ha->pdev->dev,
4837 	    (ha->tgt.atio_q_length + 1) * sizeof(struct atio_from_isp),
4838 	    &ha->tgt.atio_dma, GFP_KERNEL);
4839 	if (!ha->tgt.atio_ring) {
4840 		kfree(ha->tgt.tgt_vp_map);
4841 		return -ENOMEM;
4842 	}
4843 	return 0;
4844 }
4845 
4846 void
4847 qlt_mem_free(struct qla_hw_data *ha)
4848 {
4849 	if (!QLA_TGT_MODE_ENABLED())
4850 		return;
4851 
4852 	if (ha->tgt.atio_ring) {
4853 		dma_free_coherent(&ha->pdev->dev, (ha->tgt.atio_q_length + 1) *
4854 		    sizeof(struct atio_from_isp), ha->tgt.atio_ring,
4855 		    ha->tgt.atio_dma);
4856 	}
4857 	kfree(ha->tgt.tgt_vp_map);
4858 }
4859 
4860 /* vport_slock to be held by the caller */
4861 void
4862 qlt_update_vp_map(struct scsi_qla_host *vha, int cmd)
4863 {
4864 	if (!QLA_TGT_MODE_ENABLED())
4865 		return;
4866 
4867 	switch (cmd) {
4868 	case SET_VP_IDX:
4869 		vha->hw->tgt.tgt_vp_map[vha->vp_idx].vha = vha;
4870 		break;
4871 	case SET_AL_PA:
4872 		vha->hw->tgt.tgt_vp_map[vha->d_id.b.al_pa].idx = vha->vp_idx;
4873 		break;
4874 	case RESET_VP_IDX:
4875 		vha->hw->tgt.tgt_vp_map[vha->vp_idx].vha = NULL;
4876 		break;
4877 	case RESET_AL_PA:
4878 		vha->hw->tgt.tgt_vp_map[vha->d_id.b.al_pa].idx = 0;
4879 		break;
4880 	}
4881 }
4882 
4883 static int __init qlt_parse_ini_mode(void)
4884 {
4885 	if (strcasecmp(qlini_mode, QLA2XXX_INI_MODE_STR_EXCLUSIVE) == 0)
4886 		ql2x_ini_mode = QLA2XXX_INI_MODE_EXCLUSIVE;
4887 	else if (strcasecmp(qlini_mode, QLA2XXX_INI_MODE_STR_DISABLED) == 0)
4888 		ql2x_ini_mode = QLA2XXX_INI_MODE_DISABLED;
4889 	else if (strcasecmp(qlini_mode, QLA2XXX_INI_MODE_STR_ENABLED) == 0)
4890 		ql2x_ini_mode = QLA2XXX_INI_MODE_ENABLED;
4891 	else
4892 		return false;
4893 
4894 	return true;
4895 }
4896 
4897 int __init qlt_init(void)
4898 {
4899 	int ret;
4900 
4901 	if (!qlt_parse_ini_mode()) {
4902 		ql_log(ql_log_fatal, NULL, 0xe06b,
4903 		    "qlt_parse_ini_mode() failed\n");
4904 		return -EINVAL;
4905 	}
4906 
4907 	if (!QLA_TGT_MODE_ENABLED())
4908 		return 0;
4909 
4910 	qla_tgt_cmd_cachep = kmem_cache_create("qla_tgt_cmd_cachep",
4911 	    sizeof(struct qla_tgt_cmd), __alignof__(struct qla_tgt_cmd), 0,
4912 	    NULL);
4913 	if (!qla_tgt_cmd_cachep) {
4914 		ql_log(ql_log_fatal, NULL, 0xe06c,
4915 		    "kmem_cache_create for qla_tgt_cmd_cachep failed\n");
4916 		return -ENOMEM;
4917 	}
4918 
4919 	qla_tgt_mgmt_cmd_cachep = kmem_cache_create("qla_tgt_mgmt_cmd_cachep",
4920 	    sizeof(struct qla_tgt_mgmt_cmd), __alignof__(struct
4921 	    qla_tgt_mgmt_cmd), 0, NULL);
4922 	if (!qla_tgt_mgmt_cmd_cachep) {
4923 		ql_log(ql_log_fatal, NULL, 0xe06d,
4924 		    "kmem_cache_create for qla_tgt_mgmt_cmd_cachep failed\n");
4925 		ret = -ENOMEM;
4926 		goto out;
4927 	}
4928 
4929 	qla_tgt_mgmt_cmd_mempool = mempool_create(25, mempool_alloc_slab,
4930 	    mempool_free_slab, qla_tgt_mgmt_cmd_cachep);
4931 	if (!qla_tgt_mgmt_cmd_mempool) {
4932 		ql_log(ql_log_fatal, NULL, 0xe06e,
4933 		    "mempool_create for qla_tgt_mgmt_cmd_mempool failed\n");
4934 		ret = -ENOMEM;
4935 		goto out_mgmt_cmd_cachep;
4936 	}
4937 
4938 	qla_tgt_wq = alloc_workqueue("qla_tgt_wq", 0, 0);
4939 	if (!qla_tgt_wq) {
4940 		ql_log(ql_log_fatal, NULL, 0xe06f,
4941 		    "alloc_workqueue for qla_tgt_wq failed\n");
4942 		ret = -ENOMEM;
4943 		goto out_cmd_mempool;
4944 	}
4945 	/*
4946 	 * Return 1 to signal that initiator-mode is being disabled
4947 	 */
4948 	return (ql2x_ini_mode == QLA2XXX_INI_MODE_DISABLED) ? 1 : 0;
4949 
4950 out_cmd_mempool:
4951 	mempool_destroy(qla_tgt_mgmt_cmd_mempool);
4952 out_mgmt_cmd_cachep:
4953 	kmem_cache_destroy(qla_tgt_mgmt_cmd_cachep);
4954 out:
4955 	kmem_cache_destroy(qla_tgt_cmd_cachep);
4956 	return ret;
4957 }
4958 
4959 void qlt_exit(void)
4960 {
4961 	if (!QLA_TGT_MODE_ENABLED())
4962 		return;
4963 
4964 	destroy_workqueue(qla_tgt_wq);
4965 	mempool_destroy(qla_tgt_mgmt_cmd_mempool);
4966 	kmem_cache_destroy(qla_tgt_mgmt_cmd_cachep);
4967 	kmem_cache_destroy(qla_tgt_cmd_cachep);
4968 }
4969