1 /*******************************************************************************
2  * This file contains the iSCSI Target specific utility functions.
3  *
4  * (c) Copyright 2007-2013 Datera, Inc.
5  *
6  * Author: Nicholas A. Bellinger <nab@linux-iscsi.org>
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License as published by
10  * the Free Software Foundation; either version 2 of the License, or
11  * (at your option) any later version.
12  *
13  * This program is distributed in the hope that it will be useful,
14  * but WITHOUT ANY WARRANTY; without even the implied warranty of
15  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
16  * GNU General Public License for more details.
17  ******************************************************************************/
18 
19 #include <linux/list.h>
20 #include <linux/percpu_ida.h>
21 #include <net/ipv6.h>         /* ipv6_addr_equal() */
22 #include <scsi/scsi_tcq.h>
23 #include <scsi/iscsi_proto.h>
24 #include <target/target_core_base.h>
25 #include <target/target_core_fabric.h>
26 #include <target/iscsi/iscsi_transport.h>
27 
28 #include <target/iscsi/iscsi_target_core.h>
29 #include "iscsi_target_parameters.h"
30 #include "iscsi_target_seq_pdu_list.h"
31 #include "iscsi_target_datain_values.h"
32 #include "iscsi_target_erl0.h"
33 #include "iscsi_target_erl1.h"
34 #include "iscsi_target_erl2.h"
35 #include "iscsi_target_tpg.h"
36 #include "iscsi_target_util.h"
37 #include "iscsi_target.h"
38 
39 #define PRINT_BUFF(buff, len)					\
40 {								\
41 	int zzz;						\
42 								\
43 	pr_debug("%d:\n", __LINE__);				\
44 	for (zzz = 0; zzz < len; zzz++) {			\
45 		if (zzz % 16 == 0) {				\
46 			if (zzz)				\
47 				pr_debug("\n");			\
48 			pr_debug("%4i: ", zzz);			\
49 		}						\
50 		pr_debug("%02x ", (unsigned char) (buff)[zzz]);	\
51 	}							\
52 	if ((len + 1) % 16)					\
53 		pr_debug("\n");					\
54 }
55 
56 extern struct list_head g_tiqn_list;
57 extern spinlock_t tiqn_lock;
58 
59 /*
60  *	Called with cmd->r2t_lock held.
61  */
62 int iscsit_add_r2t_to_list(
63 	struct iscsi_cmd *cmd,
64 	u32 offset,
65 	u32 xfer_len,
66 	int recovery,
67 	u32 r2t_sn)
68 {
69 	struct iscsi_r2t *r2t;
70 
71 	r2t = kmem_cache_zalloc(lio_r2t_cache, GFP_ATOMIC);
72 	if (!r2t) {
73 		pr_err("Unable to allocate memory for struct iscsi_r2t.\n");
74 		return -1;
75 	}
76 	INIT_LIST_HEAD(&r2t->r2t_list);
77 
78 	r2t->recovery_r2t = recovery;
79 	r2t->r2t_sn = (!r2t_sn) ? cmd->r2t_sn++ : r2t_sn;
80 	r2t->offset = offset;
81 	r2t->xfer_len = xfer_len;
82 	list_add_tail(&r2t->r2t_list, &cmd->cmd_r2t_list);
83 	spin_unlock_bh(&cmd->r2t_lock);
84 
85 	iscsit_add_cmd_to_immediate_queue(cmd, cmd->conn, ISTATE_SEND_R2T);
86 
87 	spin_lock_bh(&cmd->r2t_lock);
88 	return 0;
89 }
90 
91 struct iscsi_r2t *iscsit_get_r2t_for_eos(
92 	struct iscsi_cmd *cmd,
93 	u32 offset,
94 	u32 length)
95 {
96 	struct iscsi_r2t *r2t;
97 
98 	spin_lock_bh(&cmd->r2t_lock);
99 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
100 		if ((r2t->offset <= offset) &&
101 		    (r2t->offset + r2t->xfer_len) >= (offset + length)) {
102 			spin_unlock_bh(&cmd->r2t_lock);
103 			return r2t;
104 		}
105 	}
106 	spin_unlock_bh(&cmd->r2t_lock);
107 
108 	pr_err("Unable to locate R2T for Offset: %u, Length:"
109 			" %u\n", offset, length);
110 	return NULL;
111 }
112 
113 struct iscsi_r2t *iscsit_get_r2t_from_list(struct iscsi_cmd *cmd)
114 {
115 	struct iscsi_r2t *r2t;
116 
117 	spin_lock_bh(&cmd->r2t_lock);
118 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
119 		if (!r2t->sent_r2t) {
120 			spin_unlock_bh(&cmd->r2t_lock);
121 			return r2t;
122 		}
123 	}
124 	spin_unlock_bh(&cmd->r2t_lock);
125 
126 	pr_err("Unable to locate next R2T to send for ITT:"
127 			" 0x%08x.\n", cmd->init_task_tag);
128 	return NULL;
129 }
130 
131 /*
132  *	Called with cmd->r2t_lock held.
133  */
134 void iscsit_free_r2t(struct iscsi_r2t *r2t, struct iscsi_cmd *cmd)
135 {
136 	list_del(&r2t->r2t_list);
137 	kmem_cache_free(lio_r2t_cache, r2t);
138 }
139 
140 void iscsit_free_r2ts_from_list(struct iscsi_cmd *cmd)
141 {
142 	struct iscsi_r2t *r2t, *r2t_tmp;
143 
144 	spin_lock_bh(&cmd->r2t_lock);
145 	list_for_each_entry_safe(r2t, r2t_tmp, &cmd->cmd_r2t_list, r2t_list)
146 		iscsit_free_r2t(r2t, cmd);
147 	spin_unlock_bh(&cmd->r2t_lock);
148 }
149 
150 /*
151  * May be called from software interrupt (timer) context for allocating
152  * iSCSI NopINs.
153  */
154 struct iscsi_cmd *iscsit_allocate_cmd(struct iscsi_conn *conn, int state)
155 {
156 	struct iscsi_cmd *cmd;
157 	struct se_session *se_sess = conn->sess->se_sess;
158 	int size, tag;
159 
160 	tag = percpu_ida_alloc(&se_sess->sess_tag_pool, state);
161 	if (tag < 0)
162 		return NULL;
163 
164 	size = sizeof(struct iscsi_cmd) + conn->conn_transport->priv_size;
165 	cmd = (struct iscsi_cmd *)(se_sess->sess_cmd_map + (tag * size));
166 	memset(cmd, 0, size);
167 
168 	cmd->se_cmd.map_tag = tag;
169 	cmd->conn = conn;
170 	INIT_LIST_HEAD(&cmd->i_conn_node);
171 	INIT_LIST_HEAD(&cmd->datain_list);
172 	INIT_LIST_HEAD(&cmd->cmd_r2t_list);
173 	spin_lock_init(&cmd->datain_lock);
174 	spin_lock_init(&cmd->dataout_timeout_lock);
175 	spin_lock_init(&cmd->istate_lock);
176 	spin_lock_init(&cmd->error_lock);
177 	spin_lock_init(&cmd->r2t_lock);
178 
179 	return cmd;
180 }
181 EXPORT_SYMBOL(iscsit_allocate_cmd);
182 
183 struct iscsi_seq *iscsit_get_seq_holder_for_datain(
184 	struct iscsi_cmd *cmd,
185 	u32 seq_send_order)
186 {
187 	u32 i;
188 
189 	for (i = 0; i < cmd->seq_count; i++)
190 		if (cmd->seq_list[i].seq_send_order == seq_send_order)
191 			return &cmd->seq_list[i];
192 
193 	return NULL;
194 }
195 
196 struct iscsi_seq *iscsit_get_seq_holder_for_r2t(struct iscsi_cmd *cmd)
197 {
198 	u32 i;
199 
200 	if (!cmd->seq_list) {
201 		pr_err("struct iscsi_cmd->seq_list is NULL!\n");
202 		return NULL;
203 	}
204 
205 	for (i = 0; i < cmd->seq_count; i++) {
206 		if (cmd->seq_list[i].type != SEQTYPE_NORMAL)
207 			continue;
208 		if (cmd->seq_list[i].seq_send_order == cmd->seq_send_order) {
209 			cmd->seq_send_order++;
210 			return &cmd->seq_list[i];
211 		}
212 	}
213 
214 	return NULL;
215 }
216 
217 struct iscsi_r2t *iscsit_get_holder_for_r2tsn(
218 	struct iscsi_cmd *cmd,
219 	u32 r2t_sn)
220 {
221 	struct iscsi_r2t *r2t;
222 
223 	spin_lock_bh(&cmd->r2t_lock);
224 	list_for_each_entry(r2t, &cmd->cmd_r2t_list, r2t_list) {
225 		if (r2t->r2t_sn == r2t_sn) {
226 			spin_unlock_bh(&cmd->r2t_lock);
227 			return r2t;
228 		}
229 	}
230 	spin_unlock_bh(&cmd->r2t_lock);
231 
232 	return NULL;
233 }
234 
235 static inline int iscsit_check_received_cmdsn(struct iscsi_session *sess, u32 cmdsn)
236 {
237 	u32 max_cmdsn;
238 	int ret;
239 
240 	/*
241 	 * This is the proper method of checking received CmdSN against
242 	 * ExpCmdSN and MaxCmdSN values, as well as accounting for out
243 	 * or order CmdSNs due to multiple connection sessions and/or
244 	 * CRC failures.
245 	 */
246 	max_cmdsn = atomic_read(&sess->max_cmd_sn);
247 	if (iscsi_sna_gt(cmdsn, max_cmdsn)) {
248 		pr_err("Received CmdSN: 0x%08x is greater than"
249 		       " MaxCmdSN: 0x%08x, ignoring.\n", cmdsn, max_cmdsn);
250 		ret = CMDSN_MAXCMDSN_OVERRUN;
251 
252 	} else if (cmdsn == sess->exp_cmd_sn) {
253 		sess->exp_cmd_sn++;
254 		pr_debug("Received CmdSN matches ExpCmdSN,"
255 		      " incremented ExpCmdSN to: 0x%08x\n",
256 		      sess->exp_cmd_sn);
257 		ret = CMDSN_NORMAL_OPERATION;
258 
259 	} else if (iscsi_sna_gt(cmdsn, sess->exp_cmd_sn)) {
260 		pr_debug("Received CmdSN: 0x%08x is greater"
261 		      " than ExpCmdSN: 0x%08x, not acknowledging.\n",
262 		      cmdsn, sess->exp_cmd_sn);
263 		ret = CMDSN_HIGHER_THAN_EXP;
264 
265 	} else {
266 		pr_err("Received CmdSN: 0x%08x is less than"
267 		       " ExpCmdSN: 0x%08x, ignoring.\n", cmdsn,
268 		       sess->exp_cmd_sn);
269 		ret = CMDSN_LOWER_THAN_EXP;
270 	}
271 
272 	return ret;
273 }
274 
275 /*
276  * Commands may be received out of order if MC/S is in use.
277  * Ensure they are executed in CmdSN order.
278  */
279 int iscsit_sequence_cmd(struct iscsi_conn *conn, struct iscsi_cmd *cmd,
280 			unsigned char *buf, __be32 cmdsn)
281 {
282 	int ret, cmdsn_ret;
283 	bool reject = false;
284 	u8 reason = ISCSI_REASON_BOOKMARK_NO_RESOURCES;
285 
286 	mutex_lock(&conn->sess->cmdsn_mutex);
287 
288 	cmdsn_ret = iscsit_check_received_cmdsn(conn->sess, be32_to_cpu(cmdsn));
289 	switch (cmdsn_ret) {
290 	case CMDSN_NORMAL_OPERATION:
291 		ret = iscsit_execute_cmd(cmd, 0);
292 		if ((ret >= 0) && !list_empty(&conn->sess->sess_ooo_cmdsn_list))
293 			iscsit_execute_ooo_cmdsns(conn->sess);
294 		else if (ret < 0) {
295 			reject = true;
296 			ret = CMDSN_ERROR_CANNOT_RECOVER;
297 		}
298 		break;
299 	case CMDSN_HIGHER_THAN_EXP:
300 		ret = iscsit_handle_ooo_cmdsn(conn->sess, cmd, be32_to_cpu(cmdsn));
301 		if (ret < 0) {
302 			reject = true;
303 			ret = CMDSN_ERROR_CANNOT_RECOVER;
304 			break;
305 		}
306 		ret = CMDSN_HIGHER_THAN_EXP;
307 		break;
308 	case CMDSN_LOWER_THAN_EXP:
309 	case CMDSN_MAXCMDSN_OVERRUN:
310 	default:
311 		cmd->i_state = ISTATE_REMOVE;
312 		iscsit_add_cmd_to_immediate_queue(cmd, conn, cmd->i_state);
313 		/*
314 		 * Existing callers for iscsit_sequence_cmd() will silently
315 		 * ignore commands with CMDSN_LOWER_THAN_EXP, so force this
316 		 * return for CMDSN_MAXCMDSN_OVERRUN as well..
317 		 */
318 		ret = CMDSN_LOWER_THAN_EXP;
319 		break;
320 	}
321 	mutex_unlock(&conn->sess->cmdsn_mutex);
322 
323 	if (reject)
324 		iscsit_reject_cmd(cmd, reason, buf);
325 
326 	return ret;
327 }
328 EXPORT_SYMBOL(iscsit_sequence_cmd);
329 
330 int iscsit_check_unsolicited_dataout(struct iscsi_cmd *cmd, unsigned char *buf)
331 {
332 	struct iscsi_conn *conn = cmd->conn;
333 	struct se_cmd *se_cmd = &cmd->se_cmd;
334 	struct iscsi_data *hdr = (struct iscsi_data *) buf;
335 	u32 payload_length = ntoh24(hdr->dlength);
336 
337 	if (conn->sess->sess_ops->InitialR2T) {
338 		pr_err("Received unexpected unsolicited data"
339 			" while InitialR2T=Yes, protocol error.\n");
340 		transport_send_check_condition_and_sense(se_cmd,
341 				TCM_UNEXPECTED_UNSOLICITED_DATA, 0);
342 		return -1;
343 	}
344 
345 	if ((cmd->first_burst_len + payload_length) >
346 	     conn->sess->sess_ops->FirstBurstLength) {
347 		pr_err("Total %u bytes exceeds FirstBurstLength: %u"
348 			" for this Unsolicited DataOut Burst.\n",
349 			(cmd->first_burst_len + payload_length),
350 				conn->sess->sess_ops->FirstBurstLength);
351 		transport_send_check_condition_and_sense(se_cmd,
352 				TCM_INCORRECT_AMOUNT_OF_DATA, 0);
353 		return -1;
354 	}
355 
356 	if (!(hdr->flags & ISCSI_FLAG_CMD_FINAL))
357 		return 0;
358 
359 	if (((cmd->first_burst_len + payload_length) != cmd->se_cmd.data_length) &&
360 	    ((cmd->first_burst_len + payload_length) !=
361 	      conn->sess->sess_ops->FirstBurstLength)) {
362 		pr_err("Unsolicited non-immediate data received %u"
363 			" does not equal FirstBurstLength: %u, and does"
364 			" not equal ExpXferLen %u.\n",
365 			(cmd->first_burst_len + payload_length),
366 			conn->sess->sess_ops->FirstBurstLength, cmd->se_cmd.data_length);
367 		transport_send_check_condition_and_sense(se_cmd,
368 				TCM_INCORRECT_AMOUNT_OF_DATA, 0);
369 		return -1;
370 	}
371 	return 0;
372 }
373 
374 struct iscsi_cmd *iscsit_find_cmd_from_itt(
375 	struct iscsi_conn *conn,
376 	itt_t init_task_tag)
377 {
378 	struct iscsi_cmd *cmd;
379 
380 	spin_lock_bh(&conn->cmd_lock);
381 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
382 		if (cmd->init_task_tag == init_task_tag) {
383 			spin_unlock_bh(&conn->cmd_lock);
384 			return cmd;
385 		}
386 	}
387 	spin_unlock_bh(&conn->cmd_lock);
388 
389 	pr_err("Unable to locate ITT: 0x%08x on CID: %hu",
390 			init_task_tag, conn->cid);
391 	return NULL;
392 }
393 EXPORT_SYMBOL(iscsit_find_cmd_from_itt);
394 
395 struct iscsi_cmd *iscsit_find_cmd_from_itt_or_dump(
396 	struct iscsi_conn *conn,
397 	itt_t init_task_tag,
398 	u32 length)
399 {
400 	struct iscsi_cmd *cmd;
401 
402 	spin_lock_bh(&conn->cmd_lock);
403 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
404 		if (cmd->cmd_flags & ICF_GOT_LAST_DATAOUT)
405 			continue;
406 		if (cmd->init_task_tag == init_task_tag) {
407 			spin_unlock_bh(&conn->cmd_lock);
408 			return cmd;
409 		}
410 	}
411 	spin_unlock_bh(&conn->cmd_lock);
412 
413 	pr_err("Unable to locate ITT: 0x%08x on CID: %hu,"
414 			" dumping payload\n", init_task_tag, conn->cid);
415 	if (length)
416 		iscsit_dump_data_payload(conn, length, 1);
417 
418 	return NULL;
419 }
420 EXPORT_SYMBOL(iscsit_find_cmd_from_itt_or_dump);
421 
422 struct iscsi_cmd *iscsit_find_cmd_from_ttt(
423 	struct iscsi_conn *conn,
424 	u32 targ_xfer_tag)
425 {
426 	struct iscsi_cmd *cmd = NULL;
427 
428 	spin_lock_bh(&conn->cmd_lock);
429 	list_for_each_entry(cmd, &conn->conn_cmd_list, i_conn_node) {
430 		if (cmd->targ_xfer_tag == targ_xfer_tag) {
431 			spin_unlock_bh(&conn->cmd_lock);
432 			return cmd;
433 		}
434 	}
435 	spin_unlock_bh(&conn->cmd_lock);
436 
437 	pr_err("Unable to locate TTT: 0x%08x on CID: %hu\n",
438 			targ_xfer_tag, conn->cid);
439 	return NULL;
440 }
441 
442 int iscsit_find_cmd_for_recovery(
443 	struct iscsi_session *sess,
444 	struct iscsi_cmd **cmd_ptr,
445 	struct iscsi_conn_recovery **cr_ptr,
446 	itt_t init_task_tag)
447 {
448 	struct iscsi_cmd *cmd = NULL;
449 	struct iscsi_conn_recovery *cr;
450 	/*
451 	 * Scan through the inactive connection recovery list's command list.
452 	 * If init_task_tag matches the command is still alligent.
453 	 */
454 	spin_lock(&sess->cr_i_lock);
455 	list_for_each_entry(cr, &sess->cr_inactive_list, cr_list) {
456 		spin_lock(&cr->conn_recovery_cmd_lock);
457 		list_for_each_entry(cmd, &cr->conn_recovery_cmd_list, i_conn_node) {
458 			if (cmd->init_task_tag == init_task_tag) {
459 				spin_unlock(&cr->conn_recovery_cmd_lock);
460 				spin_unlock(&sess->cr_i_lock);
461 
462 				*cr_ptr = cr;
463 				*cmd_ptr = cmd;
464 				return -2;
465 			}
466 		}
467 		spin_unlock(&cr->conn_recovery_cmd_lock);
468 	}
469 	spin_unlock(&sess->cr_i_lock);
470 	/*
471 	 * Scan through the active connection recovery list's command list.
472 	 * If init_task_tag matches the command is ready to be reassigned.
473 	 */
474 	spin_lock(&sess->cr_a_lock);
475 	list_for_each_entry(cr, &sess->cr_active_list, cr_list) {
476 		spin_lock(&cr->conn_recovery_cmd_lock);
477 		list_for_each_entry(cmd, &cr->conn_recovery_cmd_list, i_conn_node) {
478 			if (cmd->init_task_tag == init_task_tag) {
479 				spin_unlock(&cr->conn_recovery_cmd_lock);
480 				spin_unlock(&sess->cr_a_lock);
481 
482 				*cr_ptr = cr;
483 				*cmd_ptr = cmd;
484 				return 0;
485 			}
486 		}
487 		spin_unlock(&cr->conn_recovery_cmd_lock);
488 	}
489 	spin_unlock(&sess->cr_a_lock);
490 
491 	return -1;
492 }
493 
494 void iscsit_add_cmd_to_immediate_queue(
495 	struct iscsi_cmd *cmd,
496 	struct iscsi_conn *conn,
497 	u8 state)
498 {
499 	struct iscsi_queue_req *qr;
500 
501 	qr = kmem_cache_zalloc(lio_qr_cache, GFP_ATOMIC);
502 	if (!qr) {
503 		pr_err("Unable to allocate memory for"
504 				" struct iscsi_queue_req\n");
505 		return;
506 	}
507 	INIT_LIST_HEAD(&qr->qr_list);
508 	qr->cmd = cmd;
509 	qr->state = state;
510 
511 	spin_lock_bh(&conn->immed_queue_lock);
512 	list_add_tail(&qr->qr_list, &conn->immed_queue_list);
513 	atomic_inc(&cmd->immed_queue_count);
514 	atomic_set(&conn->check_immediate_queue, 1);
515 	spin_unlock_bh(&conn->immed_queue_lock);
516 
517 	wake_up(&conn->queues_wq);
518 }
519 EXPORT_SYMBOL(iscsit_add_cmd_to_immediate_queue);
520 
521 struct iscsi_queue_req *iscsit_get_cmd_from_immediate_queue(struct iscsi_conn *conn)
522 {
523 	struct iscsi_queue_req *qr;
524 
525 	spin_lock_bh(&conn->immed_queue_lock);
526 	if (list_empty(&conn->immed_queue_list)) {
527 		spin_unlock_bh(&conn->immed_queue_lock);
528 		return NULL;
529 	}
530 	qr = list_first_entry(&conn->immed_queue_list,
531 			      struct iscsi_queue_req, qr_list);
532 
533 	list_del(&qr->qr_list);
534 	if (qr->cmd)
535 		atomic_dec(&qr->cmd->immed_queue_count);
536 	spin_unlock_bh(&conn->immed_queue_lock);
537 
538 	return qr;
539 }
540 
541 static void iscsit_remove_cmd_from_immediate_queue(
542 	struct iscsi_cmd *cmd,
543 	struct iscsi_conn *conn)
544 {
545 	struct iscsi_queue_req *qr, *qr_tmp;
546 
547 	spin_lock_bh(&conn->immed_queue_lock);
548 	if (!atomic_read(&cmd->immed_queue_count)) {
549 		spin_unlock_bh(&conn->immed_queue_lock);
550 		return;
551 	}
552 
553 	list_for_each_entry_safe(qr, qr_tmp, &conn->immed_queue_list, qr_list) {
554 		if (qr->cmd != cmd)
555 			continue;
556 
557 		atomic_dec(&qr->cmd->immed_queue_count);
558 		list_del(&qr->qr_list);
559 		kmem_cache_free(lio_qr_cache, qr);
560 	}
561 	spin_unlock_bh(&conn->immed_queue_lock);
562 
563 	if (atomic_read(&cmd->immed_queue_count)) {
564 		pr_err("ITT: 0x%08x immed_queue_count: %d\n",
565 			cmd->init_task_tag,
566 			atomic_read(&cmd->immed_queue_count));
567 	}
568 }
569 
570 void iscsit_add_cmd_to_response_queue(
571 	struct iscsi_cmd *cmd,
572 	struct iscsi_conn *conn,
573 	u8 state)
574 {
575 	struct iscsi_queue_req *qr;
576 
577 	qr = kmem_cache_zalloc(lio_qr_cache, GFP_ATOMIC);
578 	if (!qr) {
579 		pr_err("Unable to allocate memory for"
580 			" struct iscsi_queue_req\n");
581 		return;
582 	}
583 	INIT_LIST_HEAD(&qr->qr_list);
584 	qr->cmd = cmd;
585 	qr->state = state;
586 
587 	spin_lock_bh(&conn->response_queue_lock);
588 	list_add_tail(&qr->qr_list, &conn->response_queue_list);
589 	atomic_inc(&cmd->response_queue_count);
590 	spin_unlock_bh(&conn->response_queue_lock);
591 
592 	wake_up(&conn->queues_wq);
593 }
594 
595 struct iscsi_queue_req *iscsit_get_cmd_from_response_queue(struct iscsi_conn *conn)
596 {
597 	struct iscsi_queue_req *qr;
598 
599 	spin_lock_bh(&conn->response_queue_lock);
600 	if (list_empty(&conn->response_queue_list)) {
601 		spin_unlock_bh(&conn->response_queue_lock);
602 		return NULL;
603 	}
604 
605 	qr = list_first_entry(&conn->response_queue_list,
606 			      struct iscsi_queue_req, qr_list);
607 
608 	list_del(&qr->qr_list);
609 	if (qr->cmd)
610 		atomic_dec(&qr->cmd->response_queue_count);
611 	spin_unlock_bh(&conn->response_queue_lock);
612 
613 	return qr;
614 }
615 
616 static void iscsit_remove_cmd_from_response_queue(
617 	struct iscsi_cmd *cmd,
618 	struct iscsi_conn *conn)
619 {
620 	struct iscsi_queue_req *qr, *qr_tmp;
621 
622 	spin_lock_bh(&conn->response_queue_lock);
623 	if (!atomic_read(&cmd->response_queue_count)) {
624 		spin_unlock_bh(&conn->response_queue_lock);
625 		return;
626 	}
627 
628 	list_for_each_entry_safe(qr, qr_tmp, &conn->response_queue_list,
629 				qr_list) {
630 		if (qr->cmd != cmd)
631 			continue;
632 
633 		atomic_dec(&qr->cmd->response_queue_count);
634 		list_del(&qr->qr_list);
635 		kmem_cache_free(lio_qr_cache, qr);
636 	}
637 	spin_unlock_bh(&conn->response_queue_lock);
638 
639 	if (atomic_read(&cmd->response_queue_count)) {
640 		pr_err("ITT: 0x%08x response_queue_count: %d\n",
641 			cmd->init_task_tag,
642 			atomic_read(&cmd->response_queue_count));
643 	}
644 }
645 
646 bool iscsit_conn_all_queues_empty(struct iscsi_conn *conn)
647 {
648 	bool empty;
649 
650 	spin_lock_bh(&conn->immed_queue_lock);
651 	empty = list_empty(&conn->immed_queue_list);
652 	spin_unlock_bh(&conn->immed_queue_lock);
653 
654 	if (!empty)
655 		return empty;
656 
657 	spin_lock_bh(&conn->response_queue_lock);
658 	empty = list_empty(&conn->response_queue_list);
659 	spin_unlock_bh(&conn->response_queue_lock);
660 
661 	return empty;
662 }
663 
664 void iscsit_free_queue_reqs_for_conn(struct iscsi_conn *conn)
665 {
666 	struct iscsi_queue_req *qr, *qr_tmp;
667 
668 	spin_lock_bh(&conn->immed_queue_lock);
669 	list_for_each_entry_safe(qr, qr_tmp, &conn->immed_queue_list, qr_list) {
670 		list_del(&qr->qr_list);
671 		if (qr->cmd)
672 			atomic_dec(&qr->cmd->immed_queue_count);
673 
674 		kmem_cache_free(lio_qr_cache, qr);
675 	}
676 	spin_unlock_bh(&conn->immed_queue_lock);
677 
678 	spin_lock_bh(&conn->response_queue_lock);
679 	list_for_each_entry_safe(qr, qr_tmp, &conn->response_queue_list,
680 			qr_list) {
681 		list_del(&qr->qr_list);
682 		if (qr->cmd)
683 			atomic_dec(&qr->cmd->response_queue_count);
684 
685 		kmem_cache_free(lio_qr_cache, qr);
686 	}
687 	spin_unlock_bh(&conn->response_queue_lock);
688 }
689 
690 void iscsit_release_cmd(struct iscsi_cmd *cmd)
691 {
692 	struct iscsi_session *sess;
693 	struct se_cmd *se_cmd = &cmd->se_cmd;
694 
695 	if (cmd->conn)
696 		sess = cmd->conn->sess;
697 	else
698 		sess = cmd->sess;
699 
700 	BUG_ON(!sess || !sess->se_sess);
701 
702 	kfree(cmd->buf_ptr);
703 	kfree(cmd->pdu_list);
704 	kfree(cmd->seq_list);
705 	kfree(cmd->tmr_req);
706 	kfree(cmd->iov_data);
707 	kfree(cmd->text_in_ptr);
708 
709 	percpu_ida_free(&sess->se_sess->sess_tag_pool, se_cmd->map_tag);
710 }
711 EXPORT_SYMBOL(iscsit_release_cmd);
712 
713 void __iscsit_free_cmd(struct iscsi_cmd *cmd, bool scsi_cmd,
714 		       bool check_queues)
715 {
716 	struct iscsi_conn *conn = cmd->conn;
717 
718 	if (scsi_cmd) {
719 		if (cmd->data_direction == DMA_TO_DEVICE) {
720 			iscsit_stop_dataout_timer(cmd);
721 			iscsit_free_r2ts_from_list(cmd);
722 		}
723 		if (cmd->data_direction == DMA_FROM_DEVICE)
724 			iscsit_free_all_datain_reqs(cmd);
725 	}
726 
727 	if (conn && check_queues) {
728 		iscsit_remove_cmd_from_immediate_queue(cmd, conn);
729 		iscsit_remove_cmd_from_response_queue(cmd, conn);
730 	}
731 
732 	if (conn && conn->conn_transport->iscsit_release_cmd)
733 		conn->conn_transport->iscsit_release_cmd(conn, cmd);
734 }
735 
736 void iscsit_free_cmd(struct iscsi_cmd *cmd, bool shutdown)
737 {
738 	struct se_cmd *se_cmd = NULL;
739 	int rc;
740 	/*
741 	 * Determine if a struct se_cmd is associated with
742 	 * this struct iscsi_cmd.
743 	 */
744 	switch (cmd->iscsi_opcode) {
745 	case ISCSI_OP_SCSI_CMD:
746 		se_cmd = &cmd->se_cmd;
747 		__iscsit_free_cmd(cmd, true, shutdown);
748 		/*
749 		 * Fallthrough
750 		 */
751 	case ISCSI_OP_SCSI_TMFUNC:
752 		rc = transport_generic_free_cmd(&cmd->se_cmd, shutdown);
753 		if (!rc && shutdown && se_cmd && se_cmd->se_sess) {
754 			__iscsit_free_cmd(cmd, true, shutdown);
755 			target_put_sess_cmd(se_cmd);
756 		}
757 		break;
758 	case ISCSI_OP_REJECT:
759 		/*
760 		 * Handle special case for REJECT when iscsi_add_reject*() has
761 		 * overwritten the original iscsi_opcode assignment, and the
762 		 * associated cmd->se_cmd needs to be released.
763 		 */
764 		if (cmd->se_cmd.se_tfo != NULL) {
765 			se_cmd = &cmd->se_cmd;
766 			__iscsit_free_cmd(cmd, true, shutdown);
767 
768 			rc = transport_generic_free_cmd(&cmd->se_cmd, shutdown);
769 			if (!rc && shutdown && se_cmd->se_sess) {
770 				__iscsit_free_cmd(cmd, true, shutdown);
771 				target_put_sess_cmd(se_cmd);
772 			}
773 			break;
774 		}
775 		/* Fall-through */
776 	default:
777 		__iscsit_free_cmd(cmd, false, shutdown);
778 		iscsit_release_cmd(cmd);
779 		break;
780 	}
781 }
782 EXPORT_SYMBOL(iscsit_free_cmd);
783 
784 int iscsit_check_session_usage_count(struct iscsi_session *sess)
785 {
786 	spin_lock_bh(&sess->session_usage_lock);
787 	if (sess->session_usage_count != 0) {
788 		sess->session_waiting_on_uc = 1;
789 		spin_unlock_bh(&sess->session_usage_lock);
790 		if (in_interrupt())
791 			return 2;
792 
793 		wait_for_completion(&sess->session_waiting_on_uc_comp);
794 		return 1;
795 	}
796 	spin_unlock_bh(&sess->session_usage_lock);
797 
798 	return 0;
799 }
800 
801 void iscsit_dec_session_usage_count(struct iscsi_session *sess)
802 {
803 	spin_lock_bh(&sess->session_usage_lock);
804 	sess->session_usage_count--;
805 
806 	if (!sess->session_usage_count && sess->session_waiting_on_uc)
807 		complete(&sess->session_waiting_on_uc_comp);
808 
809 	spin_unlock_bh(&sess->session_usage_lock);
810 }
811 
812 void iscsit_inc_session_usage_count(struct iscsi_session *sess)
813 {
814 	spin_lock_bh(&sess->session_usage_lock);
815 	sess->session_usage_count++;
816 	spin_unlock_bh(&sess->session_usage_lock);
817 }
818 
819 struct iscsi_conn *iscsit_get_conn_from_cid(struct iscsi_session *sess, u16 cid)
820 {
821 	struct iscsi_conn *conn;
822 
823 	spin_lock_bh(&sess->conn_lock);
824 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list) {
825 		if ((conn->cid == cid) &&
826 		    (conn->conn_state == TARG_CONN_STATE_LOGGED_IN)) {
827 			iscsit_inc_conn_usage_count(conn);
828 			spin_unlock_bh(&sess->conn_lock);
829 			return conn;
830 		}
831 	}
832 	spin_unlock_bh(&sess->conn_lock);
833 
834 	return NULL;
835 }
836 
837 struct iscsi_conn *iscsit_get_conn_from_cid_rcfr(struct iscsi_session *sess, u16 cid)
838 {
839 	struct iscsi_conn *conn;
840 
841 	spin_lock_bh(&sess->conn_lock);
842 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list) {
843 		if (conn->cid == cid) {
844 			iscsit_inc_conn_usage_count(conn);
845 			spin_lock(&conn->state_lock);
846 			atomic_set(&conn->connection_wait_rcfr, 1);
847 			spin_unlock(&conn->state_lock);
848 			spin_unlock_bh(&sess->conn_lock);
849 			return conn;
850 		}
851 	}
852 	spin_unlock_bh(&sess->conn_lock);
853 
854 	return NULL;
855 }
856 
857 void iscsit_check_conn_usage_count(struct iscsi_conn *conn)
858 {
859 	spin_lock_bh(&conn->conn_usage_lock);
860 	if (conn->conn_usage_count != 0) {
861 		conn->conn_waiting_on_uc = 1;
862 		spin_unlock_bh(&conn->conn_usage_lock);
863 
864 		wait_for_completion(&conn->conn_waiting_on_uc_comp);
865 		return;
866 	}
867 	spin_unlock_bh(&conn->conn_usage_lock);
868 }
869 
870 void iscsit_dec_conn_usage_count(struct iscsi_conn *conn)
871 {
872 	spin_lock_bh(&conn->conn_usage_lock);
873 	conn->conn_usage_count--;
874 
875 	if (!conn->conn_usage_count && conn->conn_waiting_on_uc)
876 		complete(&conn->conn_waiting_on_uc_comp);
877 
878 	spin_unlock_bh(&conn->conn_usage_lock);
879 }
880 
881 void iscsit_inc_conn_usage_count(struct iscsi_conn *conn)
882 {
883 	spin_lock_bh(&conn->conn_usage_lock);
884 	conn->conn_usage_count++;
885 	spin_unlock_bh(&conn->conn_usage_lock);
886 }
887 
888 static int iscsit_add_nopin(struct iscsi_conn *conn, int want_response)
889 {
890 	u8 state;
891 	struct iscsi_cmd *cmd;
892 
893 	cmd = iscsit_allocate_cmd(conn, TASK_RUNNING);
894 	if (!cmd)
895 		return -1;
896 
897 	cmd->iscsi_opcode = ISCSI_OP_NOOP_IN;
898 	state = (want_response) ? ISTATE_SEND_NOPIN_WANT_RESPONSE :
899 				ISTATE_SEND_NOPIN_NO_RESPONSE;
900 	cmd->init_task_tag = RESERVED_ITT;
901 	cmd->targ_xfer_tag = (want_response) ?
902 			     session_get_next_ttt(conn->sess) : 0xFFFFFFFF;
903 	spin_lock_bh(&conn->cmd_lock);
904 	list_add_tail(&cmd->i_conn_node, &conn->conn_cmd_list);
905 	spin_unlock_bh(&conn->cmd_lock);
906 
907 	if (want_response)
908 		iscsit_start_nopin_response_timer(conn);
909 	iscsit_add_cmd_to_immediate_queue(cmd, conn, state);
910 
911 	return 0;
912 }
913 
914 static void iscsit_handle_nopin_response_timeout(unsigned long data)
915 {
916 	struct iscsi_conn *conn = (struct iscsi_conn *) data;
917 
918 	iscsit_inc_conn_usage_count(conn);
919 
920 	spin_lock_bh(&conn->nopin_timer_lock);
921 	if (conn->nopin_response_timer_flags & ISCSI_TF_STOP) {
922 		spin_unlock_bh(&conn->nopin_timer_lock);
923 		iscsit_dec_conn_usage_count(conn);
924 		return;
925 	}
926 
927 	pr_debug("Did not receive response to NOPIN on CID: %hu on"
928 		" SID: %u, failing connection.\n", conn->cid,
929 			conn->sess->sid);
930 	conn->nopin_response_timer_flags &= ~ISCSI_TF_RUNNING;
931 	spin_unlock_bh(&conn->nopin_timer_lock);
932 
933 	{
934 	struct iscsi_portal_group *tpg = conn->sess->tpg;
935 	struct iscsi_tiqn *tiqn = tpg->tpg_tiqn;
936 
937 	if (tiqn) {
938 		spin_lock_bh(&tiqn->sess_err_stats.lock);
939 		strcpy(tiqn->sess_err_stats.last_sess_fail_rem_name,
940 				conn->sess->sess_ops->InitiatorName);
941 		tiqn->sess_err_stats.last_sess_failure_type =
942 				ISCSI_SESS_ERR_CXN_TIMEOUT;
943 		tiqn->sess_err_stats.cxn_timeout_errors++;
944 		atomic_long_inc(&conn->sess->conn_timeout_errors);
945 		spin_unlock_bh(&tiqn->sess_err_stats.lock);
946 	}
947 	}
948 
949 	iscsit_cause_connection_reinstatement(conn, 0);
950 	iscsit_dec_conn_usage_count(conn);
951 }
952 
953 void iscsit_mod_nopin_response_timer(struct iscsi_conn *conn)
954 {
955 	struct iscsi_session *sess = conn->sess;
956 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
957 
958 	spin_lock_bh(&conn->nopin_timer_lock);
959 	if (!(conn->nopin_response_timer_flags & ISCSI_TF_RUNNING)) {
960 		spin_unlock_bh(&conn->nopin_timer_lock);
961 		return;
962 	}
963 
964 	mod_timer(&conn->nopin_response_timer,
965 		(get_jiffies_64() + na->nopin_response_timeout * HZ));
966 	spin_unlock_bh(&conn->nopin_timer_lock);
967 }
968 
969 /*
970  *	Called with conn->nopin_timer_lock held.
971  */
972 void iscsit_start_nopin_response_timer(struct iscsi_conn *conn)
973 {
974 	struct iscsi_session *sess = conn->sess;
975 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
976 
977 	spin_lock_bh(&conn->nopin_timer_lock);
978 	if (conn->nopin_response_timer_flags & ISCSI_TF_RUNNING) {
979 		spin_unlock_bh(&conn->nopin_timer_lock);
980 		return;
981 	}
982 
983 	init_timer(&conn->nopin_response_timer);
984 	conn->nopin_response_timer.expires =
985 		(get_jiffies_64() + na->nopin_response_timeout * HZ);
986 	conn->nopin_response_timer.data = (unsigned long)conn;
987 	conn->nopin_response_timer.function = iscsit_handle_nopin_response_timeout;
988 	conn->nopin_response_timer_flags &= ~ISCSI_TF_STOP;
989 	conn->nopin_response_timer_flags |= ISCSI_TF_RUNNING;
990 	add_timer(&conn->nopin_response_timer);
991 
992 	pr_debug("Started NOPIN Response Timer on CID: %d to %u"
993 		" seconds\n", conn->cid, na->nopin_response_timeout);
994 	spin_unlock_bh(&conn->nopin_timer_lock);
995 }
996 
997 void iscsit_stop_nopin_response_timer(struct iscsi_conn *conn)
998 {
999 	spin_lock_bh(&conn->nopin_timer_lock);
1000 	if (!(conn->nopin_response_timer_flags & ISCSI_TF_RUNNING)) {
1001 		spin_unlock_bh(&conn->nopin_timer_lock);
1002 		return;
1003 	}
1004 	conn->nopin_response_timer_flags |= ISCSI_TF_STOP;
1005 	spin_unlock_bh(&conn->nopin_timer_lock);
1006 
1007 	del_timer_sync(&conn->nopin_response_timer);
1008 
1009 	spin_lock_bh(&conn->nopin_timer_lock);
1010 	conn->nopin_response_timer_flags &= ~ISCSI_TF_RUNNING;
1011 	spin_unlock_bh(&conn->nopin_timer_lock);
1012 }
1013 
1014 static void iscsit_handle_nopin_timeout(unsigned long data)
1015 {
1016 	struct iscsi_conn *conn = (struct iscsi_conn *) data;
1017 
1018 	iscsit_inc_conn_usage_count(conn);
1019 
1020 	spin_lock_bh(&conn->nopin_timer_lock);
1021 	if (conn->nopin_timer_flags & ISCSI_TF_STOP) {
1022 		spin_unlock_bh(&conn->nopin_timer_lock);
1023 		iscsit_dec_conn_usage_count(conn);
1024 		return;
1025 	}
1026 	conn->nopin_timer_flags &= ~ISCSI_TF_RUNNING;
1027 	spin_unlock_bh(&conn->nopin_timer_lock);
1028 
1029 	iscsit_add_nopin(conn, 1);
1030 	iscsit_dec_conn_usage_count(conn);
1031 }
1032 
1033 /*
1034  * Called with conn->nopin_timer_lock held.
1035  */
1036 void __iscsit_start_nopin_timer(struct iscsi_conn *conn)
1037 {
1038 	struct iscsi_session *sess = conn->sess;
1039 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1040 	/*
1041 	* NOPIN timeout is disabled.
1042 	 */
1043 	if (!na->nopin_timeout)
1044 		return;
1045 
1046 	if (conn->nopin_timer_flags & ISCSI_TF_RUNNING)
1047 		return;
1048 
1049 	init_timer(&conn->nopin_timer);
1050 	conn->nopin_timer.expires = (get_jiffies_64() + na->nopin_timeout * HZ);
1051 	conn->nopin_timer.data = (unsigned long)conn;
1052 	conn->nopin_timer.function = iscsit_handle_nopin_timeout;
1053 	conn->nopin_timer_flags &= ~ISCSI_TF_STOP;
1054 	conn->nopin_timer_flags |= ISCSI_TF_RUNNING;
1055 	add_timer(&conn->nopin_timer);
1056 
1057 	pr_debug("Started NOPIN Timer on CID: %d at %u second"
1058 		" interval\n", conn->cid, na->nopin_timeout);
1059 }
1060 
1061 void iscsit_start_nopin_timer(struct iscsi_conn *conn)
1062 {
1063 	struct iscsi_session *sess = conn->sess;
1064 	struct iscsi_node_attrib *na = iscsit_tpg_get_node_attrib(sess);
1065 	/*
1066 	 * NOPIN timeout is disabled..
1067 	 */
1068 	if (!na->nopin_timeout)
1069 		return;
1070 
1071 	spin_lock_bh(&conn->nopin_timer_lock);
1072 	if (conn->nopin_timer_flags & ISCSI_TF_RUNNING) {
1073 		spin_unlock_bh(&conn->nopin_timer_lock);
1074 		return;
1075 	}
1076 
1077 	init_timer(&conn->nopin_timer);
1078 	conn->nopin_timer.expires = (get_jiffies_64() + na->nopin_timeout * HZ);
1079 	conn->nopin_timer.data = (unsigned long)conn;
1080 	conn->nopin_timer.function = iscsit_handle_nopin_timeout;
1081 	conn->nopin_timer_flags &= ~ISCSI_TF_STOP;
1082 	conn->nopin_timer_flags |= ISCSI_TF_RUNNING;
1083 	add_timer(&conn->nopin_timer);
1084 
1085 	pr_debug("Started NOPIN Timer on CID: %d at %u second"
1086 			" interval\n", conn->cid, na->nopin_timeout);
1087 	spin_unlock_bh(&conn->nopin_timer_lock);
1088 }
1089 
1090 void iscsit_stop_nopin_timer(struct iscsi_conn *conn)
1091 {
1092 	spin_lock_bh(&conn->nopin_timer_lock);
1093 	if (!(conn->nopin_timer_flags & ISCSI_TF_RUNNING)) {
1094 		spin_unlock_bh(&conn->nopin_timer_lock);
1095 		return;
1096 	}
1097 	conn->nopin_timer_flags |= ISCSI_TF_STOP;
1098 	spin_unlock_bh(&conn->nopin_timer_lock);
1099 
1100 	del_timer_sync(&conn->nopin_timer);
1101 
1102 	spin_lock_bh(&conn->nopin_timer_lock);
1103 	conn->nopin_timer_flags &= ~ISCSI_TF_RUNNING;
1104 	spin_unlock_bh(&conn->nopin_timer_lock);
1105 }
1106 
1107 int iscsit_send_tx_data(
1108 	struct iscsi_cmd *cmd,
1109 	struct iscsi_conn *conn,
1110 	int use_misc)
1111 {
1112 	int tx_sent, tx_size;
1113 	u32 iov_count;
1114 	struct kvec *iov;
1115 
1116 send_data:
1117 	tx_size = cmd->tx_size;
1118 
1119 	if (!use_misc) {
1120 		iov = &cmd->iov_data[0];
1121 		iov_count = cmd->iov_data_count;
1122 	} else {
1123 		iov = &cmd->iov_misc[0];
1124 		iov_count = cmd->iov_misc_count;
1125 	}
1126 
1127 	tx_sent = tx_data(conn, &iov[0], iov_count, tx_size);
1128 	if (tx_size != tx_sent) {
1129 		if (tx_sent == -EAGAIN) {
1130 			pr_err("tx_data() returned -EAGAIN\n");
1131 			goto send_data;
1132 		} else
1133 			return -1;
1134 	}
1135 	cmd->tx_size = 0;
1136 
1137 	return 0;
1138 }
1139 
1140 int iscsit_fe_sendpage_sg(
1141 	struct iscsi_cmd *cmd,
1142 	struct iscsi_conn *conn)
1143 {
1144 	struct scatterlist *sg = cmd->first_data_sg;
1145 	struct kvec iov;
1146 	u32 tx_hdr_size, data_len;
1147 	u32 offset = cmd->first_data_sg_off;
1148 	int tx_sent, iov_off;
1149 
1150 send_hdr:
1151 	tx_hdr_size = ISCSI_HDR_LEN;
1152 	if (conn->conn_ops->HeaderDigest)
1153 		tx_hdr_size += ISCSI_CRC_LEN;
1154 
1155 	iov.iov_base = cmd->pdu;
1156 	iov.iov_len = tx_hdr_size;
1157 
1158 	tx_sent = tx_data(conn, &iov, 1, tx_hdr_size);
1159 	if (tx_hdr_size != tx_sent) {
1160 		if (tx_sent == -EAGAIN) {
1161 			pr_err("tx_data() returned -EAGAIN\n");
1162 			goto send_hdr;
1163 		}
1164 		return -1;
1165 	}
1166 
1167 	data_len = cmd->tx_size - tx_hdr_size - cmd->padding;
1168 	/*
1169 	 * Set iov_off used by padding and data digest tx_data() calls below
1170 	 * in order to determine proper offset into cmd->iov_data[]
1171 	 */
1172 	if (conn->conn_ops->DataDigest) {
1173 		data_len -= ISCSI_CRC_LEN;
1174 		if (cmd->padding)
1175 			iov_off = (cmd->iov_data_count - 2);
1176 		else
1177 			iov_off = (cmd->iov_data_count - 1);
1178 	} else {
1179 		iov_off = (cmd->iov_data_count - 1);
1180 	}
1181 	/*
1182 	 * Perform sendpage() for each page in the scatterlist
1183 	 */
1184 	while (data_len) {
1185 		u32 space = (sg->length - offset);
1186 		u32 sub_len = min_t(u32, data_len, space);
1187 send_pg:
1188 		tx_sent = conn->sock->ops->sendpage(conn->sock,
1189 					sg_page(sg), sg->offset + offset, sub_len, 0);
1190 		if (tx_sent != sub_len) {
1191 			if (tx_sent == -EAGAIN) {
1192 				pr_err("tcp_sendpage() returned"
1193 						" -EAGAIN\n");
1194 				goto send_pg;
1195 			}
1196 
1197 			pr_err("tcp_sendpage() failure: %d\n",
1198 					tx_sent);
1199 			return -1;
1200 		}
1201 
1202 		data_len -= sub_len;
1203 		offset = 0;
1204 		sg = sg_next(sg);
1205 	}
1206 
1207 send_padding:
1208 	if (cmd->padding) {
1209 		struct kvec *iov_p = &cmd->iov_data[iov_off++];
1210 
1211 		tx_sent = tx_data(conn, iov_p, 1, cmd->padding);
1212 		if (cmd->padding != tx_sent) {
1213 			if (tx_sent == -EAGAIN) {
1214 				pr_err("tx_data() returned -EAGAIN\n");
1215 				goto send_padding;
1216 			}
1217 			return -1;
1218 		}
1219 	}
1220 
1221 send_datacrc:
1222 	if (conn->conn_ops->DataDigest) {
1223 		struct kvec *iov_d = &cmd->iov_data[iov_off];
1224 
1225 		tx_sent = tx_data(conn, iov_d, 1, ISCSI_CRC_LEN);
1226 		if (ISCSI_CRC_LEN != tx_sent) {
1227 			if (tx_sent == -EAGAIN) {
1228 				pr_err("tx_data() returned -EAGAIN\n");
1229 				goto send_datacrc;
1230 			}
1231 			return -1;
1232 		}
1233 	}
1234 
1235 	return 0;
1236 }
1237 
1238 /*
1239  *      This function is used for mainly sending a ISCSI_TARG_LOGIN_RSP PDU
1240  *      back to the Initiator when an expection condition occurs with the
1241  *      errors set in status_class and status_detail.
1242  *
1243  *      Parameters:     iSCSI Connection, Status Class, Status Detail.
1244  *      Returns:        0 on success, -1 on error.
1245  */
1246 int iscsit_tx_login_rsp(struct iscsi_conn *conn, u8 status_class, u8 status_detail)
1247 {
1248 	struct iscsi_login_rsp *hdr;
1249 	struct iscsi_login *login = conn->conn_login;
1250 
1251 	login->login_failed = 1;
1252 	iscsit_collect_login_stats(conn, status_class, status_detail);
1253 
1254 	memset(&login->rsp[0], 0, ISCSI_HDR_LEN);
1255 
1256 	hdr	= (struct iscsi_login_rsp *)&login->rsp[0];
1257 	hdr->opcode		= ISCSI_OP_LOGIN_RSP;
1258 	hdr->status_class	= status_class;
1259 	hdr->status_detail	= status_detail;
1260 	hdr->itt		= conn->login_itt;
1261 
1262 	return conn->conn_transport->iscsit_put_login_tx(conn, login, 0);
1263 }
1264 
1265 void iscsit_print_session_params(struct iscsi_session *sess)
1266 {
1267 	struct iscsi_conn *conn;
1268 
1269 	pr_debug("-----------------------------[Session Params for"
1270 		" SID: %u]-----------------------------\n", sess->sid);
1271 	spin_lock_bh(&sess->conn_lock);
1272 	list_for_each_entry(conn, &sess->sess_conn_list, conn_list)
1273 		iscsi_dump_conn_ops(conn->conn_ops);
1274 	spin_unlock_bh(&sess->conn_lock);
1275 
1276 	iscsi_dump_sess_ops(sess->sess_ops);
1277 }
1278 
1279 static int iscsit_do_rx_data(
1280 	struct iscsi_conn *conn,
1281 	struct iscsi_data_count *count)
1282 {
1283 	int data = count->data_length, rx_loop = 0, total_rx = 0;
1284 	struct msghdr msg;
1285 
1286 	if (!conn || !conn->sock || !conn->conn_ops)
1287 		return -1;
1288 
1289 	memset(&msg, 0, sizeof(struct msghdr));
1290 	iov_iter_kvec(&msg.msg_iter, READ | ITER_KVEC,
1291 		      count->iov, count->iov_count, data);
1292 
1293 	while (msg_data_left(&msg)) {
1294 		rx_loop = sock_recvmsg(conn->sock, &msg, MSG_WAITALL);
1295 		if (rx_loop <= 0) {
1296 			pr_debug("rx_loop: %d total_rx: %d\n",
1297 				rx_loop, total_rx);
1298 			return rx_loop;
1299 		}
1300 		total_rx += rx_loop;
1301 		pr_debug("rx_loop: %d, total_rx: %d, data: %d\n",
1302 				rx_loop, total_rx, data);
1303 	}
1304 
1305 	return total_rx;
1306 }
1307 
1308 int rx_data(
1309 	struct iscsi_conn *conn,
1310 	struct kvec *iov,
1311 	int iov_count,
1312 	int data)
1313 {
1314 	struct iscsi_data_count c;
1315 
1316 	if (!conn || !conn->sock || !conn->conn_ops)
1317 		return -1;
1318 
1319 	memset(&c, 0, sizeof(struct iscsi_data_count));
1320 	c.iov = iov;
1321 	c.iov_count = iov_count;
1322 	c.data_length = data;
1323 	c.type = ISCSI_RX_DATA;
1324 
1325 	return iscsit_do_rx_data(conn, &c);
1326 }
1327 
1328 int tx_data(
1329 	struct iscsi_conn *conn,
1330 	struct kvec *iov,
1331 	int iov_count,
1332 	int data)
1333 {
1334 	struct msghdr msg;
1335 	int total_tx = 0;
1336 
1337 	if (!conn || !conn->sock || !conn->conn_ops)
1338 		return -1;
1339 
1340 	if (data <= 0) {
1341 		pr_err("Data length is: %d\n", data);
1342 		return -1;
1343 	}
1344 
1345 	memset(&msg, 0, sizeof(struct msghdr));
1346 
1347 	iov_iter_kvec(&msg.msg_iter, WRITE | ITER_KVEC,
1348 		      iov, iov_count, data);
1349 
1350 	while (msg_data_left(&msg)) {
1351 		int tx_loop = sock_sendmsg(conn->sock, &msg);
1352 		if (tx_loop <= 0) {
1353 			pr_debug("tx_loop: %d total_tx %d\n",
1354 				tx_loop, total_tx);
1355 			return tx_loop;
1356 		}
1357 		total_tx += tx_loop;
1358 		pr_debug("tx_loop: %d, total_tx: %d, data: %d\n",
1359 					tx_loop, total_tx, data);
1360 	}
1361 
1362 	return total_tx;
1363 }
1364 
1365 void iscsit_collect_login_stats(
1366 	struct iscsi_conn *conn,
1367 	u8 status_class,
1368 	u8 status_detail)
1369 {
1370 	struct iscsi_param *intrname = NULL;
1371 	struct iscsi_tiqn *tiqn;
1372 	struct iscsi_login_stats *ls;
1373 
1374 	tiqn = iscsit_snmp_get_tiqn(conn);
1375 	if (!tiqn)
1376 		return;
1377 
1378 	ls = &tiqn->login_stats;
1379 
1380 	spin_lock(&ls->lock);
1381 	if (status_class == ISCSI_STATUS_CLS_SUCCESS)
1382 		ls->accepts++;
1383 	else if (status_class == ISCSI_STATUS_CLS_REDIRECT) {
1384 		ls->redirects++;
1385 		ls->last_fail_type = ISCSI_LOGIN_FAIL_REDIRECT;
1386 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR)  &&
1387 		 (status_detail == ISCSI_LOGIN_STATUS_AUTH_FAILED)) {
1388 		ls->authenticate_fails++;
1389 		ls->last_fail_type =  ISCSI_LOGIN_FAIL_AUTHENTICATE;
1390 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR)  &&
1391 		 (status_detail == ISCSI_LOGIN_STATUS_TGT_FORBIDDEN)) {
1392 		ls->authorize_fails++;
1393 		ls->last_fail_type = ISCSI_LOGIN_FAIL_AUTHORIZE;
1394 	} else if ((status_class == ISCSI_STATUS_CLS_INITIATOR_ERR) &&
1395 		 (status_detail == ISCSI_LOGIN_STATUS_INIT_ERR)) {
1396 		ls->negotiate_fails++;
1397 		ls->last_fail_type = ISCSI_LOGIN_FAIL_NEGOTIATE;
1398 	} else {
1399 		ls->other_fails++;
1400 		ls->last_fail_type = ISCSI_LOGIN_FAIL_OTHER;
1401 	}
1402 
1403 	/* Save initiator name, ip address and time, if it is a failed login */
1404 	if (status_class != ISCSI_STATUS_CLS_SUCCESS) {
1405 		if (conn->param_list)
1406 			intrname = iscsi_find_param_from_key(INITIATORNAME,
1407 							     conn->param_list);
1408 		strlcpy(ls->last_intr_fail_name,
1409 		       (intrname ? intrname->value : "Unknown"),
1410 		       sizeof(ls->last_intr_fail_name));
1411 
1412 		ls->last_intr_fail_ip_family = conn->login_family;
1413 
1414 		ls->last_intr_fail_sockaddr = conn->login_sockaddr;
1415 		ls->last_fail_time = get_jiffies_64();
1416 	}
1417 
1418 	spin_unlock(&ls->lock);
1419 }
1420 
1421 struct iscsi_tiqn *iscsit_snmp_get_tiqn(struct iscsi_conn *conn)
1422 {
1423 	struct iscsi_portal_group *tpg;
1424 
1425 	if (!conn)
1426 		return NULL;
1427 
1428 	tpg = conn->tpg;
1429 	if (!tpg)
1430 		return NULL;
1431 
1432 	if (!tpg->tpg_tiqn)
1433 		return NULL;
1434 
1435 	return tpg->tpg_tiqn;
1436 }
1437