1 /*******************************************************************************
2  * This file contains the iSCSI Target specific utility functions.
3  *
4  * (c) Copyright 2007-2013 Datera, Inc.
5  *
6  * Author: Nicholas A. Bellinger <nab@linux-iscsi.org>
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License as published by
10  * the Free Software Foundation; either version 2 of the License, or
11  * (at your option) any later version.
12  *
13  * This program is distributed in the hope that it will be useful,
14  * but WITHOUT ANY WARRANTY; without even the implied warranty of
15  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16  * GNU General Public License for more details.
17  ******************************************************************************/
18 
19 #include <linux/list.h>
20 #include <linux/percpu_ida.h>
21 #include <net/ipv6.h>         /* ipv6_addr_equal() */
22 #include <scsi/scsi_tcq.h>
23 #include <scsi/iscsi_proto.h>
24 #include <target/target_core_base.h>
25 #include <target/target_core_fabric.h>
26 #include <target/iscsi/iscsi_transport.h>
27 
28 #include <target/iscsi/iscsi_target_core.h>
29 #include "iscsi_target_parameters.h"
30 #include "iscsi_target_seq_pdu_list.h"
31 #include "iscsi_target_datain_values.h"
32 #include "iscsi_target_erl0.h"
33 #include "iscsi_target_erl1.h"
34 #include "iscsi_target_erl2.h"
35 #include "iscsi_target_tpg.h"
36 #include "iscsi_target_util.h"
37 #include "iscsi_target.h"
38 
39 #define PRINT_BUFF(buff, len)					\
40 {								\
41 	int zzz;						\
42 								\
43 	pr_debug("%d:\n", __LINE__);				\
44 	for (zzz = 0; zzz < len; zzz++) {			\
45 		if (zzz % 16 == 0) {				\
46 			if (zzz)				\
47 				pr_debug("\n");			\
48 			pr_debug("%4i: ", zzz);			\
49 		}						\
50 		pr_debug("%02x ", (unsigned char) (buff)[zzz]);	\
51 	}							\
52 	if ((len + 1) % 16)					\
53 		pr_debug("\n");					\
54 }
55 
56 extern struct list_head g_tiqn_list;
57 extern spinlock_t tiqn_lock;
58 
59 /*
60  *	Called with cmd->r2t_lock held.
61  */
62 int iscsit_add_r2t_to_list(
63 	struct iscsi_cmd *cmd,
64 	u32 offset,
65 	u32 xfer_len,
66 	int recovery,
67 	u32 r2t_sn)
68 {
69 	struct iscsi_r2t *r2t;
70 
71 	r2t = kmem_cache_zalloc(lio_r2t_cache, GFP_ATOMIC);
72 	if (!r2t) {
73 		pr_err("Unable to allocate memory for struct iscsi_r2t.\n");
74 		return -1;
75 	}
76 	INIT_LIST_HEAD(&r2t->r2t_list);
77 
78 	r2t->recovery_r2t = recovery;
79 	r2t->r2t_sn = (!r2t_sn) ? cmd->r2t_sn++ : r2t_sn;
80 	r2t->offset = offset;
81 	r2t->xfer_len = xfer_len;
82 	list_add_tail(&r2t->r2t_list, &cmd->cmd_r2t_list);
83 	spin_unlock_bh(&cmd->r2t_lock);
84 
85 	iscsit_add_cmd_to_immediate_queue(cmd, cmd->conn, ISTATE_SEND_R2T);
86 
87 	spin_lock_bh(&cmd->r2t_lock);
88 	return 0;
89 }
90 
91 struct iscsi_r2t *iscsit_get_r2t_for_eos(
92 	struct iscsi_cmd *cmd,
93 	u32 offset,
94 	u32 length)
95 {
96 	struct iscsi_r2t *r2t;
97 
98 	spin_lock_bh(&cmd->r2t_lock);
99 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
100 		if ((r2t->offset <= offset) &&
101 		    (r2t->offset + r2t->xfer_len) >= (offset + length)) {
102 			spin_unlock_bh(&cmd->r2t_lock);
103 			return r2t;
104 		}
105 	}
106 	spin_unlock_bh(&cmd->r2t_lock);
107 
108 	pr_err("Unable to locate R2T for Offset: %u, Length:"
109 			" %u\n", offset, length);
110 	return NULL;
111 }
112 
113 struct iscsi_r2t *iscsit_get_r2t_from_list(struct iscsi_cmd *cmd)
114 {
115 	struct iscsi_r2t *r2t;
116 
117 	spin_lock_bh(&cmd->r2t_lock);
118 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
119 		if (!r2t->sent_r2t) {
120 			spin_unlock_bh(&cmd->r2t_lock);
121 			return r2t;
122 		}
123 	}
124 	spin_unlock_bh(&cmd->r2t_lock);
125 
126 	pr_err("Unable to locate next R2T to send for ITT:"
127 			" 0x%08x.\n", cmd->init_task_tag);
128 	return NULL;
129 }
130 
131 /*
132  *	Called with cmd->r2t_lock held.
133  */
134 void iscsit_free_r2t(struct iscsi_r2t *r2t, struct iscsi_cmd *cmd)
135 {
136 	list_del(&r2t->r2t_list);
137 	kmem_cache_free(lio_r2t_cache, r2t);
138 }
139 
140 void iscsit_free_r2ts_from_list(struct iscsi_cmd *cmd)
141 {
142 	struct iscsi_r2t *r2t, *r2t_tmp;
143 
144 	spin_lock_bh(&cmd->r2t_lock);
145 	list_for_each_entry_safe(r2t, r2t_tmp, &cmd->cmd_r2t_list, r2t_list)
146 		iscsit_free_r2t(r2t, cmd);
147 	spin_unlock_bh(&cmd->r2t_lock);
148 }
149 
150 /*
151  * May be called from software interrupt (timer) context for allocating
152  * iSCSI NopINs.
153  */
154 struct iscsi_cmd *iscsit_allocate_cmd(struct iscsi_conn *conn, int state)
155 {
156 	struct iscsi_cmd *cmd;
157 	struct se_session *se_sess = conn->sess->se_sess;
158 	int size, tag;
159 
160 	tag = percpu_ida_alloc(&se_sess->sess_tag_pool, state);
161 	if (tag < 0)
162 		return NULL;
163 
164 	size = sizeof(struct iscsi_cmd) + conn->conn_transport->priv_size;
165 	cmd = (struct iscsi_cmd *)(se_sess->sess_cmd_map + (tag * size));
166 	memset(cmd, 0, size);
167 
168 	cmd->se_cmd.map_tag = tag;
169 	cmd->conn = conn;
170 	INIT_LIST_HEAD(&cmd->i_conn_node);
171 	INIT_LIST_HEAD(&cmd->datain_list);
172 	INIT_LIST_HEAD(&cmd->cmd_r2t_list);
173 	spin_lock_init(&cmd->datain_lock);
174 	spin_lock_init(&cmd->dataout_timeout_lock);
175 	spin_lock_init(&cmd->istate_lock);
176 	spin_lock_init(&cmd->error_lock);
177 	spin_lock_init(&cmd->r2t_lock);
178 
179 	return cmd;
180 }
181 EXPORT_SYMBOL(iscsit_allocate_cmd);
182 
183 struct iscsi_seq *iscsit_get_seq_holder_for_datain(
184 	struct iscsi_cmd *cmd,
185 	u32 seq_send_order)
186 {
187 	u32 i;
188 
189 	for (i = 0; i < cmd->seq_count; i++)
190 		if (cmd->seq_list[i].seq_send_order == seq_send_order)
191 			return &cmd->seq_list[i];
192 
193 	return NULL;
194 }
195 
196 struct iscsi_seq *iscsit_get_seq_holder_for_r2t(struct iscsi_cmd *cmd)
197 {
198 	u32 i;
199 
200 	if (!cmd->seq_list) {
201 		pr_err("struct iscsi_cmd->seq_list is NULL!\n");
202 		return NULL;
203 	}
204 
205 	for (i = 0; i < cmd->seq_count; i++) {
206 		if (cmd->seq_list[i].type != SEQTYPE_NORMAL)
207 			continue;
208 		if (cmd->seq_list[i].seq_send_order == cmd->seq_send_order) {
209 			cmd->seq_send_order++;
210 			return &cmd->seq_list[i];
211 		}
212 	}
213 
214 	return NULL;
215 }
216 
217 struct iscsi_r2t *iscsit_get_holder_for_r2tsn(
218 	struct iscsi_cmd *cmd,
219 	u32 r2t_sn)
220 {
221 	struct iscsi_r2t *r2t;
222 
223 	spin_lock_bh(&cmd->r2t_lock);
224 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
225 		if (r2t->r2t_sn == r2t_sn) {
226 			spin_unlock_bh(&cmd->r2t_lock);
227 			return r2t;
228 		}
229 	}
230 	spin_unlock_bh(&cmd->r2t_lock);
231 
232 	return NULL;
233 }
234 
235 static inline int iscsit_check_received_cmdsn(struct iscsi_session *sess, u32 cmdsn)
236 {
237 	u32 max_cmdsn;
238 	int ret;
239 
240 	/*
241 	 * This is the proper method of checking received CmdSN against
242 	 * ExpCmdSN and MaxCmdSN values, as well as accounting for out
243 	 * or order CmdSNs due to multiple connection sessions and/or
244 	 * CRC failures.
245 	 */
246 	max_cmdsn = atomic_read(&sess->max_cmd_sn);
247 	if (iscsi_sna_gt(cmdsn, max_cmdsn)) {
248 		pr_err("Received CmdSN: 0x%08x is greater than"
249 		       " MaxCmdSN: 0x%08x, ignoring.\n", cmdsn, max_cmdsn);
250 		ret = CMDSN_MAXCMDSN_OVERRUN;
251 
252 	} else if (cmdsn == sess->exp_cmd_sn) {
253 		sess->exp_cmd_sn++;
254 		pr_debug("Received CmdSN matches ExpCmdSN,"
255 		      " incremented ExpCmdSN to: 0x%08x\n",
256 		      sess->exp_cmd_sn);
257 		ret = CMDSN_NORMAL_OPERATION;
258 
259 	} else if (iscsi_sna_gt(cmdsn, sess->exp_cmd_sn)) {
260 		pr_debug("Received CmdSN: 0x%08x is greater"
261 		      " than ExpCmdSN: 0x%08x, not acknowledging.\n",
262 		      cmdsn, sess->exp_cmd_sn);
263 		ret = CMDSN_HIGHER_THAN_EXP;
264 
265 	} else {
266 		pr_err("Received CmdSN: 0x%08x is less than"
267 		       " ExpCmdSN: 0x%08x, ignoring.\n", cmdsn,
268 		       sess->exp_cmd_sn);
269 		ret = CMDSN_LOWER_THAN_EXP;
270 	}
271 
272 	return ret;
273 }
274 
275 /*
276  * Commands may be received out of order if MC/S is in use.
277  * Ensure they are executed in CmdSN order.
278  */
279 int iscsit_sequence_cmd(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
280 			unsigned char *buf, __be32 cmdsn)
281 {
282 	int ret, cmdsn_ret;
283 	bool reject = false;
284 	u8 reason = ISCSI_REASON_BOOKMARK_NO_RESOURCES;
285 
286 	mutex_lock(&conn->sess->cmdsn_mutex);
287 
288 	cmdsn_ret = iscsit_check_received_cmdsn(conn->sess, be32_to_cpu(cmdsn));
289 	switch (cmdsn_ret) {
290 	case CMDSN_NORMAL_OPERATION:
291 		ret = iscsit_execute_cmd(cmd, 0);
292 		if ((ret >= 0) && !list_empty(&conn->sess->sess_ooo_cmdsn_list))
293 			iscsit_execute_ooo_cmdsns(conn->sess);
294 		else if (ret < 0) {
295 			reject = true;
296 			ret = CMDSN_ERROR_CANNOT_RECOVER;
297 		}
298 		break;
299 	case CMDSN_HIGHER_THAN_EXP:
300 		ret = iscsit_handle_ooo_cmdsn(conn->sess, cmd, be32_to_cpu(cmdsn));
301 		if (ret < 0) {
302 			reject = true;
303 			ret = CMDSN_ERROR_CANNOT_RECOVER;
304 			break;
305 		}
306 		ret = CMDSN_HIGHER_THAN_EXP;
307 		break;
308 	case CMDSN_LOWER_THAN_EXP:
309 	case CMDSN_MAXCMDSN_OVERRUN:
310 	default:
311 		cmd->i_state = ISTATE_REMOVE;
312 		iscsit_add_cmd_to_immediate_queue(cmd, conn, cmd->i_state);
313 		/*
314 		 * Existing callers for iscsit_sequence_cmd() will silently
315 		 * ignore commands with CMDSN_LOWER_THAN_EXP, so force this
316 		 * return for CMDSN_MAXCMDSN_OVERRUN as well..
317 		 */
318 		ret = CMDSN_LOWER_THAN_EXP;
319 		break;
320 	}
321 	mutex_unlock(&conn->sess->cmdsn_mutex);
322 
323 	if (reject)
324 		iscsit_reject_cmd(cmd, reason, buf);
325 
326 	return ret;
327 }
328 EXPORT_SYMBOL(iscsit_sequence_cmd);
329 
330 int iscsit_check_unsolicited_dataout(struct iscsi_cmd *cmd, unsigned char *buf)
331 {
332 	struct iscsi_conn *conn = cmd->conn;
333 	struct se_cmd *se_cmd = &cmd->se_cmd;
334 	struct iscsi_data *hdr = (struct iscsi_data *) buf;
335 	u32 payload_length = ntoh24(hdr->dlength);
336 
337 	if (conn->sess->sess_ops->InitialR2T) {
338 		pr_err("Received unexpected unsolicited data"
339 			" while InitialR2T=Yes, protocol error.\n");
340 		transport_send_check_condition_and_sense(se_cmd,
341 				TCM_UNEXPECTED_UNSOLICITED_DATA, 0);
342 		return -1;
343 	}
344 
345 	if ((cmd->first_burst_len + payload_length) >
346 	     conn->sess->sess_ops->FirstBurstLength) {
347 		pr_err("Total %u bytes exceeds FirstBurstLength: %u"
348 			" for this Unsolicited DataOut Burst.\n",
349 			(cmd->first_burst_len + payload_length),
350 				conn->sess->sess_ops->FirstBurstLength);
351 		transport_send_check_condition_and_sense(se_cmd,
352 				TCM_INCORRECT_AMOUNT_OF_DATA, 0);
353 		return -1;
354 	}
355 
356 	if (!(hdr->flags & ISCSI_FLAG_CMD_FINAL))
357 		return 0;
358 
359 	if (((cmd->first_burst_len + payload_length) != cmd->se_cmd.data_length) &&
360 	    ((cmd->first_burst_len + payload_length) !=
361 	      conn->sess->sess_ops->FirstBurstLength)) {
362 		pr_err("Unsolicited non-immediate data received %u"
363 			" does not equal FirstBurstLength: %u, and does"
364 			" not equal ExpXferLen %u.\n",
365 			(cmd->first_burst_len + payload_length),
366 			conn->sess->sess_ops->FirstBurstLength, cmd->se_cmd.data_length);
367 		transport_send_check_condition_and_sense(se_cmd,
368 				TCM_INCORRECT_AMOUNT_OF_DATA, 0);
369 		return -1;
370 	}
371 	return 0;
372 }
373 
374 struct iscsi_cmd *iscsit_find_cmd_from_itt(
375 	struct iscsi_conn *conn,
376 	itt_t init_task_tag)
377 {
378 	struct iscsi_cmd *cmd;
379 
380 	spin_lock_bh(&conn->cmd_lock);
381 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
382 		if (cmd->init_task_tag == init_task_tag) {
383 			spin_unlock_bh(&conn->cmd_lock);
384 			return cmd;
385 		}
386 	}
387 	spin_unlock_bh(&conn->cmd_lock);
388 
389 	pr_err("Unable to locate ITT: 0x%08x on CID: %hu",
390 			init_task_tag, conn->cid);
391 	return NULL;
392 }
393 EXPORT_SYMBOL(iscsit_find_cmd_from_itt);
394 
395 struct iscsi_cmd *iscsit_find_cmd_from_itt_or_dump(
396 	struct iscsi_conn *conn,
397 	itt_t init_task_tag,
398 	u32 length)
399 {
400 	struct iscsi_cmd *cmd;
401 
402 	spin_lock_bh(&conn->cmd_lock);
403 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
404 		if (cmd->cmd_flags & ICF_GOT_LAST_DATAOUT)
405 			continue;
406 		if (cmd->init_task_tag == init_task_tag) {
407 			spin_unlock_bh(&conn->cmd_lock);
408 			return cmd;
409 		}
410 	}
411 	spin_unlock_bh(&conn->cmd_lock);
412 
413 	pr_err("Unable to locate ITT: 0x%08x on CID: %hu,"
414 			" dumping payload\n", init_task_tag, conn->cid);
415 	if (length)
416 		iscsit_dump_data_payload(conn, length, 1);
417 
418 	return NULL;
419 }
420 
421 struct iscsi_cmd *iscsit_find_cmd_from_ttt(
422 	struct iscsi_conn *conn,
423 	u32 targ_xfer_tag)
424 {
425 	struct iscsi_cmd *cmd = NULL;
426 
427 	spin_lock_bh(&conn->cmd_lock);
428 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
429 		if (cmd->targ_xfer_tag == targ_xfer_tag) {
430 			spin_unlock_bh(&conn->cmd_lock);
431 			return cmd;
432 		}
433 	}
434 	spin_unlock_bh(&conn->cmd_lock);
435 
436 	pr_err("Unable to locate TTT: 0x%08x on CID: %hu\n",
437 			targ_xfer_tag, conn->cid);
438 	return NULL;
439 }
440 
441 int iscsit_find_cmd_for_recovery(
442 	struct iscsi_session *sess,
443 	struct iscsi_cmd **cmd_ptr,
444 	struct iscsi_conn_recovery **cr_ptr,
445 	itt_t init_task_tag)
446 {
447 	struct iscsi_cmd *cmd = NULL;
448 	struct iscsi_conn_recovery *cr;
449 	/*
450 	 * Scan through the inactive connection recovery list's command list.
451 	 * If init_task_tag matches the command is still alligent.
452 	 */
453 	spin_lock(&sess->cr_i_lock);
454 	list_for_each_entry(cr, &sess->cr_inactive_list, cr_list) {
455 		spin_lock(&cr->conn_recovery_cmd_lock);
456 		list_for_each_entry(cmd, &cr->conn_recovery_cmd_list, i_conn_node) {
457 			if (cmd->init_task_tag == init_task_tag) {
458 				spin_unlock(&cr->conn_recovery_cmd_lock);
459 				spin_unlock(&sess->cr_i_lock);
460 
461 				*cr_ptr = cr;
462 				*cmd_ptr = cmd;
463 				return -2;
464 			}
465 		}
466 		spin_unlock(&cr->conn_recovery_cmd_lock);
467 	}
468 	spin_unlock(&sess->cr_i_lock);
469 	/*
470 	 * Scan through the active connection recovery list's command list.
471 	 * If init_task_tag matches the command is ready to be reassigned.
472 	 */
473 	spin_lock(&sess->cr_a_lock);
474 	list_for_each_entry(cr, &sess->cr_active_list, cr_list) {
475 		spin_lock(&cr->conn_recovery_cmd_lock);
476 		list_for_each_entry(cmd, &cr->conn_recovery_cmd_list, i_conn_node) {
477 			if (cmd->init_task_tag == init_task_tag) {
478 				spin_unlock(&cr->conn_recovery_cmd_lock);
479 				spin_unlock(&sess->cr_a_lock);
480 
481 				*cr_ptr = cr;
482 				*cmd_ptr = cmd;
483 				return 0;
484 			}
485 		}
486 		spin_unlock(&cr->conn_recovery_cmd_lock);
487 	}
488 	spin_unlock(&sess->cr_a_lock);
489 
490 	return -1;
491 }
492 
493 void iscsit_add_cmd_to_immediate_queue(
494 	struct iscsi_cmd *cmd,
495 	struct iscsi_conn *conn,
496 	u8 state)
497 {
498 	struct iscsi_queue_req *qr;
499 
500 	qr = kmem_cache_zalloc(lio_qr_cache, GFP_ATOMIC);
501 	if (!qr) {
502 		pr_err("Unable to allocate memory for"
503 				" struct iscsi_queue_req\n");
504 		return;
505 	}
506 	INIT_LIST_HEAD(&qr->qr_list);
507 	qr->cmd = cmd;
508 	qr->state = state;
509 
510 	spin_lock_bh(&conn->immed_queue_lock);
511 	list_add_tail(&qr->qr_list, &conn->immed_queue_list);
512 	atomic_inc(&cmd->immed_queue_count);
513 	atomic_set(&conn->check_immediate_queue, 1);
514 	spin_unlock_bh(&conn->immed_queue_lock);
515 
516 	wake_up(&conn->queues_wq);
517 }
518 EXPORT_SYMBOL(iscsit_add_cmd_to_immediate_queue);
519 
520 struct iscsi_queue_req *iscsit_get_cmd_from_immediate_queue(struct iscsi_conn *conn)
521 {
522 	struct iscsi_queue_req *qr;
523 
524 	spin_lock_bh(&conn->immed_queue_lock);
525 	if (list_empty(&conn->immed_queue_list)) {
526 		spin_unlock_bh(&conn->immed_queue_lock);
527 		return NULL;
528 	}
529 	qr = list_first_entry(&conn->immed_queue_list,
530 			      struct iscsi_queue_req, qr_list);
531 
532 	list_del(&qr->qr_list);
533 	if (qr->cmd)
534 		atomic_dec(&qr->cmd->immed_queue_count);
535 	spin_unlock_bh(&conn->immed_queue_lock);
536 
537 	return qr;
538 }
539 
540 static void iscsit_remove_cmd_from_immediate_queue(
541 	struct iscsi_cmd *cmd,
542 	struct iscsi_conn *conn)
543 {
544 	struct iscsi_queue_req *qr, *qr_tmp;
545 
546 	spin_lock_bh(&conn->immed_queue_lock);
547 	if (!atomic_read(&cmd->immed_queue_count)) {
548 		spin_unlock_bh(&conn->immed_queue_lock);
549 		return;
550 	}
551 
552 	list_for_each_entry_safe(qr, qr_tmp, &conn->immed_queue_list, qr_list) {
553 		if (qr->cmd != cmd)
554 			continue;
555 
556 		atomic_dec(&qr->cmd->immed_queue_count);
557 		list_del(&qr->qr_list);
558 		kmem_cache_free(lio_qr_cache, qr);
559 	}
560 	spin_unlock_bh(&conn->immed_queue_lock);
561 
562 	if (atomic_read(&cmd->immed_queue_count)) {
563 		pr_err("ITT: 0x%08x immed_queue_count: %d\n",
564 			cmd->init_task_tag,
565 			atomic_read(&cmd->immed_queue_count));
566 	}
567 }
568 
569 void iscsit_add_cmd_to_response_queue(
570 	struct iscsi_cmd *cmd,
571 	struct iscsi_conn *conn,
572 	u8 state)
573 {
574 	struct iscsi_queue_req *qr;
575 
576 	qr = kmem_cache_zalloc(lio_qr_cache, GFP_ATOMIC);
577 	if (!qr) {
578 		pr_err("Unable to allocate memory for"
579 			" struct iscsi_queue_req\n");
580 		return;
581 	}
582 	INIT_LIST_HEAD(&qr->qr_list);
583 	qr->cmd = cmd;
584 	qr->state = state;
585 
586 	spin_lock_bh(&conn->response_queue_lock);
587 	list_add_tail(&qr->qr_list, &conn->response_queue_list);
588 	atomic_inc(&cmd->response_queue_count);
589 	spin_unlock_bh(&conn->response_queue_lock);
590 
591 	wake_up(&conn->queues_wq);
592 }
593 
594 struct iscsi_queue_req *iscsit_get_cmd_from_response_queue(struct iscsi_conn *conn)
595 {
596 	struct iscsi_queue_req *qr;
597 
598 	spin_lock_bh(&conn->response_queue_lock);
599 	if (list_empty(&conn->response_queue_list)) {
600 		spin_unlock_bh(&conn->response_queue_lock);
601 		return NULL;
602 	}
603 
604 	qr = list_first_entry(&conn->response_queue_list,
605 			      struct iscsi_queue_req, qr_list);
606 
607 	list_del(&qr->qr_list);
608 	if (qr->cmd)
609 		atomic_dec(&qr->cmd->response_queue_count);
610 	spin_unlock_bh(&conn->response_queue_lock);
611 
612 	return qr;
613 }
614 
615 static void iscsit_remove_cmd_from_response_queue(
616 	struct iscsi_cmd *cmd,
617 	struct iscsi_conn *conn)
618 {
619 	struct iscsi_queue_req *qr, *qr_tmp;
620 
621 	spin_lock_bh(&conn->response_queue_lock);
622 	if (!atomic_read(&cmd->response_queue_count)) {
623 		spin_unlock_bh(&conn->response_queue_lock);
624 		return;
625 	}
626 
627 	list_for_each_entry_safe(qr, qr_tmp, &conn->response_queue_list,
628 				qr_list) {
629 		if (qr->cmd != cmd)
630 			continue;
631 
632 		atomic_dec(&qr->cmd->response_queue_count);
633 		list_del(&qr->qr_list);
634 		kmem_cache_free(lio_qr_cache, qr);
635 	}
636 	spin_unlock_bh(&conn->response_queue_lock);
637 
638 	if (atomic_read(&cmd->response_queue_count)) {
639 		pr_err("ITT: 0x%08x response_queue_count: %d\n",
640 			cmd->init_task_tag,
641 			atomic_read(&cmd->response_queue_count));
642 	}
643 }
644 
645 bool iscsit_conn_all_queues_empty(struct iscsi_conn *conn)
646 {
647 	bool empty;
648 
649 	spin_lock_bh(&conn->immed_queue_lock);
650 	empty = list_empty(&conn->immed_queue_list);
651 	spin_unlock_bh(&conn->immed_queue_lock);
652 
653 	if (!empty)
654 		return empty;
655 
656 	spin_lock_bh(&conn->response_queue_lock);
657 	empty = list_empty(&conn->response_queue_list);
658 	spin_unlock_bh(&conn->response_queue_lock);
659 
660 	return empty;
661 }
662 
663 void iscsit_free_queue_reqs_for_conn(struct iscsi_conn *conn)
664 {
665 	struct iscsi_queue_req *qr, *qr_tmp;
666 
667 	spin_lock_bh(&conn->immed_queue_lock);
668 	list_for_each_entry_safe(qr, qr_tmp, &conn->immed_queue_list, qr_list) {
669 		list_del(&qr->qr_list);
670 		if (qr->cmd)
671 			atomic_dec(&qr->cmd->immed_queue_count);
672 
673 		kmem_cache_free(lio_qr_cache, qr);
674 	}
675 	spin_unlock_bh(&conn->immed_queue_lock);
676 
677 	spin_lock_bh(&conn->response_queue_lock);
678 	list_for_each_entry_safe(qr, qr_tmp, &conn->response_queue_list,
679 			qr_list) {
680 		list_del(&qr->qr_list);
681 		if (qr->cmd)
682 			atomic_dec(&qr->cmd->response_queue_count);
683 
684 		kmem_cache_free(lio_qr_cache, qr);
685 	}
686 	spin_unlock_bh(&conn->response_queue_lock);
687 }
688 
689 void iscsit_release_cmd(struct iscsi_cmd *cmd)
690 {
691 	struct iscsi_session *sess;
692 	struct se_cmd *se_cmd = &cmd->se_cmd;
693 
694 	if (cmd->conn)
695 		sess = cmd->conn->sess;
696 	else
697 		sess = cmd->sess;
698 
699 	BUG_ON(!sess || !sess->se_sess);
700 
701 	kfree(cmd->buf_ptr);
702 	kfree(cmd->pdu_list);
703 	kfree(cmd->seq_list);
704 	kfree(cmd->tmr_req);
705 	kfree(cmd->iov_data);
706 	kfree(cmd->text_in_ptr);
707 
708 	percpu_ida_free(&sess->se_sess->sess_tag_pool, se_cmd->map_tag);
709 }
710 EXPORT_SYMBOL(iscsit_release_cmd);
711 
712 void __iscsit_free_cmd(struct iscsi_cmd *cmd, bool scsi_cmd,
713 		       bool check_queues)
714 {
715 	struct iscsi_conn *conn = cmd->conn;
716 
717 	if (scsi_cmd) {
718 		if (cmd->data_direction == DMA_TO_DEVICE) {
719 			iscsit_stop_dataout_timer(cmd);
720 			iscsit_free_r2ts_from_list(cmd);
721 		}
722 		if (cmd->data_direction == DMA_FROM_DEVICE)
723 			iscsit_free_all_datain_reqs(cmd);
724 	}
725 
726 	if (conn && check_queues) {
727 		iscsit_remove_cmd_from_immediate_queue(cmd, conn);
728 		iscsit_remove_cmd_from_response_queue(cmd, conn);
729 	}
730 
731 	if (conn && conn->conn_transport->iscsit_release_cmd)
732 		conn->conn_transport->iscsit_release_cmd(conn, cmd);
733 }
734 
735 void iscsit_free_cmd(struct iscsi_cmd *cmd, bool shutdown)
736 {
737 	struct se_cmd *se_cmd = NULL;
738 	int rc;
739 	/*
740 	 * Determine if a struct se_cmd is associated with
741 	 * this struct iscsi_cmd.
742 	 */
743 	switch (cmd->iscsi_opcode) {
744 	case ISCSI_OP_SCSI_CMD:
745 		se_cmd = &cmd->se_cmd;
746 		__iscsit_free_cmd(cmd, true, shutdown);
747 		/*
748 		 * Fallthrough
749 		 */
750 	case ISCSI_OP_SCSI_TMFUNC:
751 		rc = transport_generic_free_cmd(&cmd->se_cmd, shutdown);
752 		if (!rc && shutdown && se_cmd && se_cmd->se_sess) {
753 			__iscsit_free_cmd(cmd, true, shutdown);
754 			target_put_sess_cmd(se_cmd);
755 		}
756 		break;
757 	case ISCSI_OP_REJECT:
758 		/*
759 		 * Handle special case for REJECT when iscsi_add_reject*() has
760 		 * overwritten the original iscsi_opcode assignment, and the
761 		 * associated cmd->se_cmd needs to be released.
762 		 */
763 		if (cmd->se_cmd.se_tfo != NULL) {
764 			se_cmd = &cmd->se_cmd;
765 			__iscsit_free_cmd(cmd, true, shutdown);
766 
767 			rc = transport_generic_free_cmd(&cmd->se_cmd, shutdown);
768 			if (!rc && shutdown && se_cmd->se_sess) {
769 				__iscsit_free_cmd(cmd, true, shutdown);
770 				target_put_sess_cmd(se_cmd);
771 			}
772 			break;
773 		}
774 		/* Fall-through */
775 	default:
776 		__iscsit_free_cmd(cmd, false, shutdown);
777 		iscsit_release_cmd(cmd);
778 		break;
779 	}
780 }
781 EXPORT_SYMBOL(iscsit_free_cmd);
782 
783 int iscsit_check_session_usage_count(struct iscsi_session *sess)
784 {
785 	spin_lock_bh(&sess->session_usage_lock);
786 	if (sess->session_usage_count != 0) {
787 		sess->session_waiting_on_uc = 1;
788 		spin_unlock_bh(&sess->session_usage_lock);
789 		if (in_interrupt())
790 			return 2;
791 
792 		wait_for_completion(&sess->session_waiting_on_uc_comp);
793 		return 1;
794 	}
795 	spin_unlock_bh(&sess->session_usage_lock);
796 
797 	return 0;
798 }
799 
800 void iscsit_dec_session_usage_count(struct iscsi_session *sess)
801 {
802 	spin_lock_bh(&sess->session_usage_lock);
803 	sess->session_usage_count--;
804 
805 	if (!sess->session_usage_count && sess->session_waiting_on_uc)
806 		complete(&sess->session_waiting_on_uc_comp);
807 
808 	spin_unlock_bh(&sess->session_usage_lock);
809 }
810 
811 void iscsit_inc_session_usage_count(struct iscsi_session *sess)
812 {
813 	spin_lock_bh(&sess->session_usage_lock);
814 	sess->session_usage_count++;
815 	spin_unlock_bh(&sess->session_usage_lock);
816 }
817 
818 struct iscsi_conn *iscsit_get_conn_from_cid(struct iscsi_session *sess, u16 cid)
819 {
820 	struct iscsi_conn *conn;
821 
822 	spin_lock_bh(&sess->conn_lock);
823 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list) {
824 		if ((conn->cid == cid) &&
825 		    (conn->conn_state == TARG_CONN_STATE_LOGGED_IN)) {
826 			iscsit_inc_conn_usage_count(conn);
827 			spin_unlock_bh(&sess->conn_lock);
828 			return conn;
829 		}
830 	}
831 	spin_unlock_bh(&sess->conn_lock);
832 
833 	return NULL;
834 }
835 
836 struct iscsi_conn *iscsit_get_conn_from_cid_rcfr(struct iscsi_session *sess, u16 cid)
837 {
838 	struct iscsi_conn *conn;
839 
840 	spin_lock_bh(&sess->conn_lock);
841 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list) {
842 		if (conn->cid == cid) {
843 			iscsit_inc_conn_usage_count(conn);
844 			spin_lock(&conn->state_lock);
845 			atomic_set(&conn->connection_wait_rcfr, 1);
846 			spin_unlock(&conn->state_lock);
847 			spin_unlock_bh(&sess->conn_lock);
848 			return conn;
849 		}
850 	}
851 	spin_unlock_bh(&sess->conn_lock);
852 
853 	return NULL;
854 }
855 
856 void iscsit_check_conn_usage_count(struct iscsi_conn *conn)
857 {
858 	spin_lock_bh(&conn->conn_usage_lock);
859 	if (conn->conn_usage_count != 0) {
860 		conn->conn_waiting_on_uc = 1;
861 		spin_unlock_bh(&conn->conn_usage_lock);
862 
863 		wait_for_completion(&conn->conn_waiting_on_uc_comp);
864 		return;
865 	}
866 	spin_unlock_bh(&conn->conn_usage_lock);
867 }
868 
869 void iscsit_dec_conn_usage_count(struct iscsi_conn *conn)
870 {
871 	spin_lock_bh(&conn->conn_usage_lock);
872 	conn->conn_usage_count--;
873 
874 	if (!conn->conn_usage_count && conn->conn_waiting_on_uc)
875 		complete(&conn->conn_waiting_on_uc_comp);
876 
877 	spin_unlock_bh(&conn->conn_usage_lock);
878 }
879 
880 void iscsit_inc_conn_usage_count(struct iscsi_conn *conn)
881 {
882 	spin_lock_bh(&conn->conn_usage_lock);
883 	conn->conn_usage_count++;
884 	spin_unlock_bh(&conn->conn_usage_lock);
885 }
886 
887 static int iscsit_add_nopin(struct iscsi_conn *conn, int want_response)
888 {
889 	u8 state;
890 	struct iscsi_cmd *cmd;
891 
892 	cmd = iscsit_allocate_cmd(conn, TASK_RUNNING);
893 	if (!cmd)
894 		return -1;
895 
896 	cmd->iscsi_opcode = ISCSI_OP_NOOP_IN;
897 	state = (want_response) ? ISTATE_SEND_NOPIN_WANT_RESPONSE :
898 				ISTATE_SEND_NOPIN_NO_RESPONSE;
899 	cmd->init_task_tag = RESERVED_ITT;
900 	cmd->targ_xfer_tag = (want_response) ?
901 			     session_get_next_ttt(conn->sess) : 0xFFFFFFFF;
902 	spin_lock_bh(&conn->cmd_lock);
903 	list_add_tail(&cmd->i_conn_node, &conn->conn_cmd_list);
904 	spin_unlock_bh(&conn->cmd_lock);
905 
906 	if (want_response)
907 		iscsit_start_nopin_response_timer(conn);
908 	iscsit_add_cmd_to_immediate_queue(cmd, conn, state);
909 
910 	return 0;
911 }
912 
913 static void iscsit_handle_nopin_response_timeout(unsigned long data)
914 {
915 	struct iscsi_conn *conn = (struct iscsi_conn *) data;
916 
917 	iscsit_inc_conn_usage_count(conn);
918 
919 	spin_lock_bh(&conn->nopin_timer_lock);
920 	if (conn->nopin_response_timer_flags & ISCSI_TF_STOP) {
921 		spin_unlock_bh(&conn->nopin_timer_lock);
922 		iscsit_dec_conn_usage_count(conn);
923 		return;
924 	}
925 
926 	pr_debug("Did not receive response to NOPIN on CID: %hu on"
927 		" SID: %u, failing connection.\n", conn->cid,
928 			conn->sess->sid);
929 	conn->nopin_response_timer_flags &= ~ISCSI_TF_RUNNING;
930 	spin_unlock_bh(&conn->nopin_timer_lock);
931 
932 	{
933 	struct iscsi_portal_group *tpg = conn->sess->tpg;
934 	struct iscsi_tiqn *tiqn = tpg->tpg_tiqn;
935 
936 	if (tiqn) {
937 		spin_lock_bh(&tiqn->sess_err_stats.lock);
938 		strcpy(tiqn->sess_err_stats.last_sess_fail_rem_name,
939 				conn->sess->sess_ops->InitiatorName);
940 		tiqn->sess_err_stats.last_sess_failure_type =
941 				ISCSI_SESS_ERR_CXN_TIMEOUT;
942 		tiqn->sess_err_stats.cxn_timeout_errors++;
943 		atomic_long_inc(&conn->sess->conn_timeout_errors);
944 		spin_unlock_bh(&tiqn->sess_err_stats.lock);
945 	}
946 	}
947 
948 	iscsit_cause_connection_reinstatement(conn, 0);
949 	iscsit_dec_conn_usage_count(conn);
950 }
951 
952 void iscsit_mod_nopin_response_timer(struct iscsi_conn *conn)
953 {
954 	struct iscsi_session *sess = conn->sess;
955 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
956 
957 	spin_lock_bh(&conn->nopin_timer_lock);
958 	if (!(conn->nopin_response_timer_flags & ISCSI_TF_RUNNING)) {
959 		spin_unlock_bh(&conn->nopin_timer_lock);
960 		return;
961 	}
962 
963 	mod_timer(&conn->nopin_response_timer,
964 		(get_jiffies_64() + na->nopin_response_timeout * HZ));
965 	spin_unlock_bh(&conn->nopin_timer_lock);
966 }
967 
968 /*
969  *	Called with conn->nopin_timer_lock held.
970  */
971 void iscsit_start_nopin_response_timer(struct iscsi_conn *conn)
972 {
973 	struct iscsi_session *sess = conn->sess;
974 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
975 
976 	spin_lock_bh(&conn->nopin_timer_lock);
977 	if (conn->nopin_response_timer_flags & ISCSI_TF_RUNNING) {
978 		spin_unlock_bh(&conn->nopin_timer_lock);
979 		return;
980 	}
981 
982 	init_timer(&conn->nopin_response_timer);
983 	conn->nopin_response_timer.expires =
984 		(get_jiffies_64() + na->nopin_response_timeout * HZ);
985 	conn->nopin_response_timer.data = (unsigned long)conn;
986 	conn->nopin_response_timer.function = iscsit_handle_nopin_response_timeout;
987 	conn->nopin_response_timer_flags &= ~ISCSI_TF_STOP;
988 	conn->nopin_response_timer_flags |= ISCSI_TF_RUNNING;
989 	add_timer(&conn->nopin_response_timer);
990 
991 	pr_debug("Started NOPIN Response Timer on CID: %d to %u"
992 		" seconds\n", conn->cid, na->nopin_response_timeout);
993 	spin_unlock_bh(&conn->nopin_timer_lock);
994 }
995 
996 void iscsit_stop_nopin_response_timer(struct iscsi_conn *conn)
997 {
998 	spin_lock_bh(&conn->nopin_timer_lock);
999 	if (!(conn->nopin_response_timer_flags & ISCSI_TF_RUNNING)) {
1000 		spin_unlock_bh(&conn->nopin_timer_lock);
1001 		return;
1002 	}
1003 	conn->nopin_response_timer_flags |= ISCSI_TF_STOP;
1004 	spin_unlock_bh(&conn->nopin_timer_lock);
1005 
1006 	del_timer_sync(&conn->nopin_response_timer);
1007 
1008 	spin_lock_bh(&conn->nopin_timer_lock);
1009 	conn->nopin_response_timer_flags &= ~ISCSI_TF_RUNNING;
1010 	spin_unlock_bh(&conn->nopin_timer_lock);
1011 }
1012 
1013 static void iscsit_handle_nopin_timeout(unsigned long data)
1014 {
1015 	struct iscsi_conn *conn = (struct iscsi_conn *) data;
1016 
1017 	iscsit_inc_conn_usage_count(conn);
1018 
1019 	spin_lock_bh(&conn->nopin_timer_lock);
1020 	if (conn->nopin_timer_flags & ISCSI_TF_STOP) {
1021 		spin_unlock_bh(&conn->nopin_timer_lock);
1022 		iscsit_dec_conn_usage_count(conn);
1023 		return;
1024 	}
1025 	conn->nopin_timer_flags &= ~ISCSI_TF_RUNNING;
1026 	spin_unlock_bh(&conn->nopin_timer_lock);
1027 
1028 	iscsit_add_nopin(conn, 1);
1029 	iscsit_dec_conn_usage_count(conn);
1030 }
1031 
1032 /*
1033  * Called with conn->nopin_timer_lock held.
1034  */
1035 void __iscsit_start_nopin_timer(struct iscsi_conn *conn)
1036 {
1037 	struct iscsi_session *sess = conn->sess;
1038 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1039 	/*
1040 	* NOPIN timeout is disabled.
1041 	 */
1042 	if (!na->nopin_timeout)
1043 		return;
1044 
1045 	if (conn->nopin_timer_flags & ISCSI_TF_RUNNING)
1046 		return;
1047 
1048 	init_timer(&conn->nopin_timer);
1049 	conn->nopin_timer.expires = (get_jiffies_64() + na->nopin_timeout * HZ);
1050 	conn->nopin_timer.data = (unsigned long)conn;
1051 	conn->nopin_timer.function = iscsit_handle_nopin_timeout;
1052 	conn->nopin_timer_flags &= ~ISCSI_TF_STOP;
1053 	conn->nopin_timer_flags |= ISCSI_TF_RUNNING;
1054 	add_timer(&conn->nopin_timer);
1055 
1056 	pr_debug("Started NOPIN Timer on CID: %d at %u second"
1057 		" interval\n", conn->cid, na->nopin_timeout);
1058 }
1059 
1060 void iscsit_start_nopin_timer(struct iscsi_conn *conn)
1061 {
1062 	struct iscsi_session *sess = conn->sess;
1063 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1064 	/*
1065 	 * NOPIN timeout is disabled..
1066 	 */
1067 	if (!na->nopin_timeout)
1068 		return;
1069 
1070 	spin_lock_bh(&conn->nopin_timer_lock);
1071 	if (conn->nopin_timer_flags & ISCSI_TF_RUNNING) {
1072 		spin_unlock_bh(&conn->nopin_timer_lock);
1073 		return;
1074 	}
1075 
1076 	init_timer(&conn->nopin_timer);
1077 	conn->nopin_timer.expires = (get_jiffies_64() + na->nopin_timeout * HZ);
1078 	conn->nopin_timer.data = (unsigned long)conn;
1079 	conn->nopin_timer.function = iscsit_handle_nopin_timeout;
1080 	conn->nopin_timer_flags &= ~ISCSI_TF_STOP;
1081 	conn->nopin_timer_flags |= ISCSI_TF_RUNNING;
1082 	add_timer(&conn->nopin_timer);
1083 
1084 	pr_debug("Started NOPIN Timer on CID: %d at %u second"
1085 			" interval\n", conn->cid, na->nopin_timeout);
1086 	spin_unlock_bh(&conn->nopin_timer_lock);
1087 }
1088 
1089 void iscsit_stop_nopin_timer(struct iscsi_conn *conn)
1090 {
1091 	spin_lock_bh(&conn->nopin_timer_lock);
1092 	if (!(conn->nopin_timer_flags & ISCSI_TF_RUNNING)) {
1093 		spin_unlock_bh(&conn->nopin_timer_lock);
1094 		return;
1095 	}
1096 	conn->nopin_timer_flags |= ISCSI_TF_STOP;
1097 	spin_unlock_bh(&conn->nopin_timer_lock);
1098 
1099 	del_timer_sync(&conn->nopin_timer);
1100 
1101 	spin_lock_bh(&conn->nopin_timer_lock);
1102 	conn->nopin_timer_flags &= ~ISCSI_TF_RUNNING;
1103 	spin_unlock_bh(&conn->nopin_timer_lock);
1104 }
1105 
1106 int iscsit_send_tx_data(
1107 	struct iscsi_cmd *cmd,
1108 	struct iscsi_conn *conn,
1109 	int use_misc)
1110 {
1111 	int tx_sent, tx_size;
1112 	u32 iov_count;
1113 	struct kvec *iov;
1114 
1115 send_data:
1116 	tx_size = cmd->tx_size;
1117 
1118 	if (!use_misc) {
1119 		iov = &cmd->iov_data[0];
1120 		iov_count = cmd->iov_data_count;
1121 	} else {
1122 		iov = &cmd->iov_misc[0];
1123 		iov_count = cmd->iov_misc_count;
1124 	}
1125 
1126 	tx_sent = tx_data(conn, &iov[0], iov_count, tx_size);
1127 	if (tx_size != tx_sent) {
1128 		if (tx_sent == -EAGAIN) {
1129 			pr_err("tx_data() returned -EAGAIN\n");
1130 			goto send_data;
1131 		} else
1132 			return -1;
1133 	}
1134 	cmd->tx_size = 0;
1135 
1136 	return 0;
1137 }
1138 
1139 int iscsit_fe_sendpage_sg(
1140 	struct iscsi_cmd *cmd,
1141 	struct iscsi_conn *conn)
1142 {
1143 	struct scatterlist *sg = cmd->first_data_sg;
1144 	struct kvec iov;
1145 	u32 tx_hdr_size, data_len;
1146 	u32 offset = cmd->first_data_sg_off;
1147 	int tx_sent, iov_off;
1148 
1149 send_hdr:
1150 	tx_hdr_size = ISCSI_HDR_LEN;
1151 	if (conn->conn_ops->HeaderDigest)
1152 		tx_hdr_size += ISCSI_CRC_LEN;
1153 
1154 	iov.iov_base = cmd->pdu;
1155 	iov.iov_len = tx_hdr_size;
1156 
1157 	tx_sent = tx_data(conn, &iov, 1, tx_hdr_size);
1158 	if (tx_hdr_size != tx_sent) {
1159 		if (tx_sent == -EAGAIN) {
1160 			pr_err("tx_data() returned -EAGAIN\n");
1161 			goto send_hdr;
1162 		}
1163 		return -1;
1164 	}
1165 
1166 	data_len = cmd->tx_size - tx_hdr_size - cmd->padding;
1167 	/*
1168 	 * Set iov_off used by padding and data digest tx_data() calls below
1169 	 * in order to determine proper offset into cmd->iov_data[]
1170 	 */
1171 	if (conn->conn_ops->DataDigest) {
1172 		data_len -= ISCSI_CRC_LEN;
1173 		if (cmd->padding)
1174 			iov_off = (cmd->iov_data_count - 2);
1175 		else
1176 			iov_off = (cmd->iov_data_count - 1);
1177 	} else {
1178 		iov_off = (cmd->iov_data_count - 1);
1179 	}
1180 	/*
1181 	 * Perform sendpage() for each page in the scatterlist
1182 	 */
1183 	while (data_len) {
1184 		u32 space = (sg->length - offset);
1185 		u32 sub_len = min_t(u32, data_len, space);
1186 send_pg:
1187 		tx_sent = conn->sock->ops->sendpage(conn->sock,
1188 					sg_page(sg), sg->offset + offset, sub_len, 0);
1189 		if (tx_sent != sub_len) {
1190 			if (tx_sent == -EAGAIN) {
1191 				pr_err("tcp_sendpage() returned"
1192 						" -EAGAIN\n");
1193 				goto send_pg;
1194 			}
1195 
1196 			pr_err("tcp_sendpage() failure: %d\n",
1197 					tx_sent);
1198 			return -1;
1199 		}
1200 
1201 		data_len -= sub_len;
1202 		offset = 0;
1203 		sg = sg_next(sg);
1204 	}
1205 
1206 send_padding:
1207 	if (cmd->padding) {
1208 		struct kvec *iov_p = &cmd->iov_data[iov_off++];
1209 
1210 		tx_sent = tx_data(conn, iov_p, 1, cmd->padding);
1211 		if (cmd->padding != tx_sent) {
1212 			if (tx_sent == -EAGAIN) {
1213 				pr_err("tx_data() returned -EAGAIN\n");
1214 				goto send_padding;
1215 			}
1216 			return -1;
1217 		}
1218 	}
1219 
1220 send_datacrc:
1221 	if (conn->conn_ops->DataDigest) {
1222 		struct kvec *iov_d = &cmd->iov_data[iov_off];
1223 
1224 		tx_sent = tx_data(conn, iov_d, 1, ISCSI_CRC_LEN);
1225 		if (ISCSI_CRC_LEN != tx_sent) {
1226 			if (tx_sent == -EAGAIN) {
1227 				pr_err("tx_data() returned -EAGAIN\n");
1228 				goto send_datacrc;
1229 			}
1230 			return -1;
1231 		}
1232 	}
1233 
1234 	return 0;
1235 }
1236 
1237 /*
1238  *      This function is used for mainly sending a ISCSI_TARG_LOGIN_RSP PDU
1239  *      back to the Initiator when an expection condition occurs with the
1240  *      errors set in status_class and status_detail.
1241  *
1242  *      Parameters:     iSCSI Connection, Status Class, Status Detail.
1243  *      Returns:        0 on success, -1 on error.
1244  */
1245 int iscsit_tx_login_rsp(struct iscsi_conn *conn, u8 status_class, u8 status_detail)
1246 {
1247 	struct iscsi_login_rsp *hdr;
1248 	struct iscsi_login *login = conn->conn_login;
1249 
1250 	login->login_failed = 1;
1251 	iscsit_collect_login_stats(conn, status_class, status_detail);
1252 
1253 	memset(&login->rsp[0], 0, ISCSI_HDR_LEN);
1254 
1255 	hdr	= (struct iscsi_login_rsp *)&login->rsp[0];
1256 	hdr->opcode		= ISCSI_OP_LOGIN_RSP;
1257 	hdr->status_class	= status_class;
1258 	hdr->status_detail	= status_detail;
1259 	hdr->itt		= conn->login_itt;
1260 
1261 	return conn->conn_transport->iscsit_put_login_tx(conn, login, 0);
1262 }
1263 
1264 void iscsit_print_session_params(struct iscsi_session *sess)
1265 {
1266 	struct iscsi_conn *conn;
1267 
1268 	pr_debug("-----------------------------[Session Params for"
1269 		" SID: %u]-----------------------------\n", sess->sid);
1270 	spin_lock_bh(&sess->conn_lock);
1271 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list)
1272 		iscsi_dump_conn_ops(conn->conn_ops);
1273 	spin_unlock_bh(&sess->conn_lock);
1274 
1275 	iscsi_dump_sess_ops(sess->sess_ops);
1276 }
1277 
1278 static int iscsit_do_rx_data(
1279 	struct iscsi_conn *conn,
1280 	struct iscsi_data_count *count)
1281 {
1282 	int data = count->data_length, rx_loop = 0, total_rx = 0;
1283 	struct msghdr msg;
1284 
1285 	if (!conn || !conn->sock || !conn->conn_ops)
1286 		return -1;
1287 
1288 	memset(&msg, 0, sizeof(struct msghdr));
1289 	iov_iter_kvec(&msg.msg_iter, READ | ITER_KVEC,
1290 		      count->iov, count->iov_count, data);
1291 
1292 	while (msg_data_left(&msg)) {
1293 		rx_loop = sock_recvmsg(conn->sock, &msg, MSG_WAITALL);
1294 		if (rx_loop <= 0) {
1295 			pr_debug("rx_loop: %d total_rx: %d\n",
1296 				rx_loop, total_rx);
1297 			return rx_loop;
1298 		}
1299 		total_rx += rx_loop;
1300 		pr_debug("rx_loop: %d, total_rx: %d, data: %d\n",
1301 				rx_loop, total_rx, data);
1302 	}
1303 
1304 	return total_rx;
1305 }
1306 
1307 static int iscsit_do_tx_data(
1308 	struct iscsi_conn *conn,
1309 	struct iscsi_data_count *count)
1310 {
1311 	int ret, iov_len;
1312 	struct kvec *iov_p;
1313 	struct msghdr msg;
1314 
1315 	if (!conn || !conn->sock || !conn->conn_ops)
1316 		return -1;
1317 
1318 	if (count->data_length <= 0) {
1319 		pr_err("Data length is: %d\n", count->data_length);
1320 		return -1;
1321 	}
1322 
1323 	memset(&msg, 0, sizeof(struct msghdr));
1324 
1325 	iov_p = count->iov;
1326 	iov_len = count->iov_count;
1327 
1328 	ret = kernel_sendmsg(conn->sock, &msg, iov_p, iov_len,
1329 			     count->data_length);
1330 	if (ret != count->data_length) {
1331 		pr_err("Unexpected ret: %d send data %d\n",
1332 		       ret, count->data_length);
1333 		return -EPIPE;
1334 	}
1335 	pr_debug("ret: %d, sent data: %d\n", ret, count->data_length);
1336 
1337 	return ret;
1338 }
1339 
1340 int rx_data(
1341 	struct iscsi_conn *conn,
1342 	struct kvec *iov,
1343 	int iov_count,
1344 	int data)
1345 {
1346 	struct iscsi_data_count c;
1347 
1348 	if (!conn || !conn->sock || !conn->conn_ops)
1349 		return -1;
1350 
1351 	memset(&c, 0, sizeof(struct iscsi_data_count));
1352 	c.iov = iov;
1353 	c.iov_count = iov_count;
1354 	c.data_length = data;
1355 	c.type = ISCSI_RX_DATA;
1356 
1357 	return iscsit_do_rx_data(conn, &c);
1358 }
1359 
1360 int tx_data(
1361 	struct iscsi_conn *conn,
1362 	struct kvec *iov,
1363 	int iov_count,
1364 	int data)
1365 {
1366 	struct iscsi_data_count c;
1367 
1368 	if (!conn || !conn->sock || !conn->conn_ops)
1369 		return -1;
1370 
1371 	memset(&c, 0, sizeof(struct iscsi_data_count));
1372 	c.iov = iov;
1373 	c.iov_count = iov_count;
1374 	c.data_length = data;
1375 	c.type = ISCSI_TX_DATA;
1376 
1377 	return iscsit_do_tx_data(conn, &c);
1378 }
1379 
1380 static bool sockaddr_equal(struct sockaddr_storage *x, struct sockaddr_storage *y)
1381 {
1382 	switch (x->ss_family) {
1383 	case AF_INET: {
1384 		struct sockaddr_in *sinx = (struct sockaddr_in *)x;
1385 		struct sockaddr_in *siny = (struct sockaddr_in *)y;
1386 		if (sinx->sin_addr.s_addr != siny->sin_addr.s_addr)
1387 			return false;
1388 		if (sinx->sin_port != siny->sin_port)
1389 			return false;
1390 		break;
1391 	}
1392 	case AF_INET6: {
1393 		struct sockaddr_in6 *sinx = (struct sockaddr_in6 *)x;
1394 		struct sockaddr_in6 *siny = (struct sockaddr_in6 *)y;
1395 		if (!ipv6_addr_equal(&sinx->sin6_addr, &siny->sin6_addr))
1396 			return false;
1397 		if (sinx->sin6_port != siny->sin6_port)
1398 			return false;
1399 		break;
1400 	}
1401 	default:
1402 		return false;
1403 	}
1404 	return true;
1405 }
1406 
1407 void iscsit_collect_login_stats(
1408 	struct iscsi_conn *conn,
1409 	u8 status_class,
1410 	u8 status_detail)
1411 {
1412 	struct iscsi_param *intrname = NULL;
1413 	struct iscsi_tiqn *tiqn;
1414 	struct iscsi_login_stats *ls;
1415 
1416 	tiqn = iscsit_snmp_get_tiqn(conn);
1417 	if (!tiqn)
1418 		return;
1419 
1420 	ls = &tiqn->login_stats;
1421 
1422 	spin_lock(&ls->lock);
1423 	if (sockaddr_equal(&conn->login_sockaddr, &ls->last_intr_fail_sockaddr) &&
1424 	    ((get_jiffies_64() - ls->last_fail_time) < 10)) {
1425 		/* We already have the failure info for this login */
1426 		spin_unlock(&ls->lock);
1427 		return;
1428 	}
1429 
1430 	if (status_class == ISCSI_STATUS_CLS_SUCCESS)
1431 		ls->accepts++;
1432 	else if (status_class == ISCSI_STATUS_CLS_REDIRECT) {
1433 		ls->redirects++;
1434 		ls->last_fail_type = ISCSI_LOGIN_FAIL_REDIRECT;
1435 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR)  &&
1436 		 (status_detail == ISCSI_LOGIN_STATUS_AUTH_FAILED)) {
1437 		ls->authenticate_fails++;
1438 		ls->last_fail_type =  ISCSI_LOGIN_FAIL_AUTHENTICATE;
1439 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR)  &&
1440 		 (status_detail == ISCSI_LOGIN_STATUS_TGT_FORBIDDEN)) {
1441 		ls->authorize_fails++;
1442 		ls->last_fail_type = ISCSI_LOGIN_FAIL_AUTHORIZE;
1443 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR) &&
1444 		 (status_detail == ISCSI_LOGIN_STATUS_INIT_ERR)) {
1445 		ls->negotiate_fails++;
1446 		ls->last_fail_type = ISCSI_LOGIN_FAIL_NEGOTIATE;
1447 	} else {
1448 		ls->other_fails++;
1449 		ls->last_fail_type = ISCSI_LOGIN_FAIL_OTHER;
1450 	}
1451 
1452 	/* Save initiator name, ip address and time, if it is a failed login */
1453 	if (status_class != ISCSI_STATUS_CLS_SUCCESS) {
1454 		if (conn->param_list)
1455 			intrname = iscsi_find_param_from_key(INITIATORNAME,
1456 							     conn->param_list);
1457 		strlcpy(ls->last_intr_fail_name,
1458 		       (intrname ? intrname->value : "Unknown"),
1459 		       sizeof(ls->last_intr_fail_name));
1460 
1461 		ls->last_intr_fail_ip_family = conn->login_family;
1462 
1463 		ls->last_intr_fail_sockaddr = conn->login_sockaddr;
1464 		ls->last_fail_time = get_jiffies_64();
1465 	}
1466 
1467 	spin_unlock(&ls->lock);
1468 }
1469 
1470 struct iscsi_tiqn *iscsit_snmp_get_tiqn(struct iscsi_conn *conn)
1471 {
1472 	struct iscsi_portal_group *tpg;
1473 
1474 	if (!conn || !conn->sess)
1475 		return NULL;
1476 
1477 	tpg = conn->sess->tpg;
1478 	if (!tpg)
1479 		return NULL;
1480 
1481 	if (!tpg->tpg_tiqn)
1482 		return NULL;
1483 
1484 	return tpg->tpg_tiqn;
1485 }
1486