1 /*
2  * Copyright (c) 2005 Topspin Communications.  All rights reserved.
3  * Copyright (c) 2005 Intel Corporation.  All rights reserved.
4  *
5  * This software is available to you under a choice of one of two
6  * licenses.  You may choose to be licensed under the terms of the GNU
7  * General Public License (GPL) Version 2, available from the file
8  * COPYING in the main directory of this source tree, or the
9  * OpenIB.org BSD license below:
10  *
11  *     Redistribution and use in source and binary forms, with or
12  *     without modification, are permitted provided that the following
13  *     conditions are met:
14  *
15  *      - Redistributions of source code must retain the above
16  *	copyright notice, this list of conditions and the following
17  *	disclaimer.
18  *
19  *      - Redistributions in binary form must reproduce the above
20  *	copyright notice, this list of conditions and the following
21  *	disclaimer in the documentation and/or other materials
22  *	provided with the distribution.
23  *
24  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
25  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
26  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
27  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
28  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
29  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
30  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
31  * SOFTWARE.
32  */
33 
34 #include <linux/completion.h>
35 #include <linux/init.h>
36 #include <linux/fs.h>
37 #include <linux/module.h>
38 #include <linux/device.h>
39 #include <linux/err.h>
40 #include <linux/poll.h>
41 #include <linux/sched.h>
42 #include <linux/file.h>
43 #include <linux/mount.h>
44 #include <linux/cdev.h>
45 #include <linux/idr.h>
46 #include <linux/mutex.h>
47 #include <linux/slab.h>
48 
49 #include <asm/uaccess.h>
50 
51 #include <rdma/ib.h>
52 #include <rdma/ib_cm.h>
53 #include <rdma/ib_user_cm.h>
54 #include <rdma/ib_marshall.h>
55 
56 MODULE_AUTHOR("Libor Michalek");
57 MODULE_DESCRIPTION("InfiniBand userspace Connection Manager access");
58 MODULE_LICENSE("Dual BSD/GPL");
59 
60 struct ib_ucm_device {
61 	int			devnum;
62 	struct cdev		cdev;
63 	struct device		dev;
64 	struct ib_device	*ib_dev;
65 };
66 
67 struct ib_ucm_file {
68 	struct mutex file_mutex;
69 	struct file *filp;
70 	struct ib_ucm_device *device;
71 
72 	struct list_head  ctxs;
73 	struct list_head  events;
74 	wait_queue_head_t poll_wait;
75 };
76 
77 struct ib_ucm_context {
78 	int                 id;
79 	struct completion   comp;
80 	atomic_t            ref;
81 	int		    events_reported;
82 
83 	struct ib_ucm_file *file;
84 	struct ib_cm_id    *cm_id;
85 	__u64		   uid;
86 
87 	struct list_head    events;    /* list of pending events. */
88 	struct list_head    file_list; /* member in file ctx list */
89 };
90 
91 struct ib_ucm_event {
92 	struct ib_ucm_context *ctx;
93 	struct list_head file_list; /* member in file event list */
94 	struct list_head ctx_list;  /* member in ctx event list */
95 
96 	struct ib_cm_id *cm_id;
97 	struct ib_ucm_event_resp resp;
98 	void *data;
99 	void *info;
100 	int data_len;
101 	int info_len;
102 };
103 
104 enum {
105 	IB_UCM_MAJOR = 231,
106 	IB_UCM_BASE_MINOR = 224,
107 	IB_UCM_MAX_DEVICES = 32
108 };
109 
110 #define IB_UCM_BASE_DEV MKDEV(IB_UCM_MAJOR, IB_UCM_BASE_MINOR)
111 
112 static void ib_ucm_add_one(struct ib_device *device);
113 static void ib_ucm_remove_one(struct ib_device *device, void *client_data);
114 
115 static struct ib_client ucm_client = {
116 	.name   = "ucm",
117 	.add    = ib_ucm_add_one,
118 	.remove = ib_ucm_remove_one
119 };
120 
121 static DEFINE_MUTEX(ctx_id_mutex);
122 static DEFINE_IDR(ctx_id_table);
123 static DECLARE_BITMAP(dev_map, IB_UCM_MAX_DEVICES);
124 
ib_ucm_ctx_get(struct ib_ucm_file * file,int id)125 static struct ib_ucm_context *ib_ucm_ctx_get(struct ib_ucm_file *file, int id)
126 {
127 	struct ib_ucm_context *ctx;
128 
129 	mutex_lock(&ctx_id_mutex);
130 	ctx = idr_find(&ctx_id_table, id);
131 	if (!ctx)
132 		ctx = ERR_PTR(-ENOENT);
133 	else if (ctx->file != file)
134 		ctx = ERR_PTR(-EINVAL);
135 	else
136 		atomic_inc(&ctx->ref);
137 	mutex_unlock(&ctx_id_mutex);
138 
139 	return ctx;
140 }
141 
ib_ucm_ctx_put(struct ib_ucm_context * ctx)142 static void ib_ucm_ctx_put(struct ib_ucm_context *ctx)
143 {
144 	if (atomic_dec_and_test(&ctx->ref))
145 		complete(&ctx->comp);
146 }
147 
ib_ucm_new_cm_id(int event)148 static inline int ib_ucm_new_cm_id(int event)
149 {
150 	return event == IB_CM_REQ_RECEIVED || event == IB_CM_SIDR_REQ_RECEIVED;
151 }
152 
ib_ucm_cleanup_events(struct ib_ucm_context * ctx)153 static void ib_ucm_cleanup_events(struct ib_ucm_context *ctx)
154 {
155 	struct ib_ucm_event *uevent;
156 
157 	mutex_lock(&ctx->file->file_mutex);
158 	list_del(&ctx->file_list);
159 	while (!list_empty(&ctx->events)) {
160 
161 		uevent = list_entry(ctx->events.next,
162 				    struct ib_ucm_event, ctx_list);
163 		list_del(&uevent->file_list);
164 		list_del(&uevent->ctx_list);
165 		mutex_unlock(&ctx->file->file_mutex);
166 
167 		/* clear incoming connections. */
168 		if (ib_ucm_new_cm_id(uevent->resp.event))
169 			ib_destroy_cm_id(uevent->cm_id);
170 
171 		kfree(uevent);
172 		mutex_lock(&ctx->file->file_mutex);
173 	}
174 	mutex_unlock(&ctx->file->file_mutex);
175 }
176 
ib_ucm_ctx_alloc(struct ib_ucm_file * file)177 static struct ib_ucm_context *ib_ucm_ctx_alloc(struct ib_ucm_file *file)
178 {
179 	struct ib_ucm_context *ctx;
180 
181 	ctx = kzalloc(sizeof *ctx, GFP_KERNEL);
182 	if (!ctx)
183 		return NULL;
184 
185 	atomic_set(&ctx->ref, 1);
186 	init_completion(&ctx->comp);
187 	ctx->file = file;
188 	INIT_LIST_HEAD(&ctx->events);
189 
190 	mutex_lock(&ctx_id_mutex);
191 	ctx->id = idr_alloc(&ctx_id_table, ctx, 0, 0, GFP_KERNEL);
192 	mutex_unlock(&ctx_id_mutex);
193 	if (ctx->id < 0)
194 		goto error;
195 
196 	list_add_tail(&ctx->file_list, &file->ctxs);
197 	return ctx;
198 
199 error:
200 	kfree(ctx);
201 	return NULL;
202 }
203 
ib_ucm_event_req_get(struct ib_ucm_req_event_resp * ureq,struct ib_cm_req_event_param * kreq)204 static void ib_ucm_event_req_get(struct ib_ucm_req_event_resp *ureq,
205 				 struct ib_cm_req_event_param *kreq)
206 {
207 	ureq->remote_ca_guid             = kreq->remote_ca_guid;
208 	ureq->remote_qkey                = kreq->remote_qkey;
209 	ureq->remote_qpn                 = kreq->remote_qpn;
210 	ureq->qp_type                    = kreq->qp_type;
211 	ureq->starting_psn               = kreq->starting_psn;
212 	ureq->responder_resources        = kreq->responder_resources;
213 	ureq->initiator_depth            = kreq->initiator_depth;
214 	ureq->local_cm_response_timeout  = kreq->local_cm_response_timeout;
215 	ureq->flow_control               = kreq->flow_control;
216 	ureq->remote_cm_response_timeout = kreq->remote_cm_response_timeout;
217 	ureq->retry_count                = kreq->retry_count;
218 	ureq->rnr_retry_count            = kreq->rnr_retry_count;
219 	ureq->srq                        = kreq->srq;
220 	ureq->port			 = kreq->port;
221 
222 	ib_copy_path_rec_to_user(&ureq->primary_path, kreq->primary_path);
223 	if (kreq->alternate_path)
224 		ib_copy_path_rec_to_user(&ureq->alternate_path,
225 					 kreq->alternate_path);
226 }
227 
ib_ucm_event_rep_get(struct ib_ucm_rep_event_resp * urep,struct ib_cm_rep_event_param * krep)228 static void ib_ucm_event_rep_get(struct ib_ucm_rep_event_resp *urep,
229 				 struct ib_cm_rep_event_param *krep)
230 {
231 	urep->remote_ca_guid      = krep->remote_ca_guid;
232 	urep->remote_qkey         = krep->remote_qkey;
233 	urep->remote_qpn          = krep->remote_qpn;
234 	urep->starting_psn        = krep->starting_psn;
235 	urep->responder_resources = krep->responder_resources;
236 	urep->initiator_depth     = krep->initiator_depth;
237 	urep->target_ack_delay    = krep->target_ack_delay;
238 	urep->failover_accepted   = krep->failover_accepted;
239 	urep->flow_control        = krep->flow_control;
240 	urep->rnr_retry_count     = krep->rnr_retry_count;
241 	urep->srq                 = krep->srq;
242 }
243 
ib_ucm_event_sidr_rep_get(struct ib_ucm_sidr_rep_event_resp * urep,struct ib_cm_sidr_rep_event_param * krep)244 static void ib_ucm_event_sidr_rep_get(struct ib_ucm_sidr_rep_event_resp *urep,
245 				      struct ib_cm_sidr_rep_event_param *krep)
246 {
247 	urep->status = krep->status;
248 	urep->qkey   = krep->qkey;
249 	urep->qpn    = krep->qpn;
250 };
251 
ib_ucm_event_process(struct ib_cm_event * evt,struct ib_ucm_event * uvt)252 static int ib_ucm_event_process(struct ib_cm_event *evt,
253 				struct ib_ucm_event *uvt)
254 {
255 	void *info = NULL;
256 
257 	switch (evt->event) {
258 	case IB_CM_REQ_RECEIVED:
259 		ib_ucm_event_req_get(&uvt->resp.u.req_resp,
260 				     &evt->param.req_rcvd);
261 		uvt->data_len      = IB_CM_REQ_PRIVATE_DATA_SIZE;
262 		uvt->resp.present  = IB_UCM_PRES_PRIMARY;
263 		uvt->resp.present |= (evt->param.req_rcvd.alternate_path ?
264 				      IB_UCM_PRES_ALTERNATE : 0);
265 		break;
266 	case IB_CM_REP_RECEIVED:
267 		ib_ucm_event_rep_get(&uvt->resp.u.rep_resp,
268 				     &evt->param.rep_rcvd);
269 		uvt->data_len = IB_CM_REP_PRIVATE_DATA_SIZE;
270 		break;
271 	case IB_CM_RTU_RECEIVED:
272 		uvt->data_len = IB_CM_RTU_PRIVATE_DATA_SIZE;
273 		uvt->resp.u.send_status = evt->param.send_status;
274 		break;
275 	case IB_CM_DREQ_RECEIVED:
276 		uvt->data_len = IB_CM_DREQ_PRIVATE_DATA_SIZE;
277 		uvt->resp.u.send_status = evt->param.send_status;
278 		break;
279 	case IB_CM_DREP_RECEIVED:
280 		uvt->data_len = IB_CM_DREP_PRIVATE_DATA_SIZE;
281 		uvt->resp.u.send_status = evt->param.send_status;
282 		break;
283 	case IB_CM_MRA_RECEIVED:
284 		uvt->resp.u.mra_resp.timeout =
285 					evt->param.mra_rcvd.service_timeout;
286 		uvt->data_len = IB_CM_MRA_PRIVATE_DATA_SIZE;
287 		break;
288 	case IB_CM_REJ_RECEIVED:
289 		uvt->resp.u.rej_resp.reason = evt->param.rej_rcvd.reason;
290 		uvt->data_len = IB_CM_REJ_PRIVATE_DATA_SIZE;
291 		uvt->info_len = evt->param.rej_rcvd.ari_length;
292 		info	      = evt->param.rej_rcvd.ari;
293 		break;
294 	case IB_CM_LAP_RECEIVED:
295 		ib_copy_path_rec_to_user(&uvt->resp.u.lap_resp.path,
296 					 evt->param.lap_rcvd.alternate_path);
297 		uvt->data_len = IB_CM_LAP_PRIVATE_DATA_SIZE;
298 		uvt->resp.present = IB_UCM_PRES_ALTERNATE;
299 		break;
300 	case IB_CM_APR_RECEIVED:
301 		uvt->resp.u.apr_resp.status = evt->param.apr_rcvd.ap_status;
302 		uvt->data_len = IB_CM_APR_PRIVATE_DATA_SIZE;
303 		uvt->info_len = evt->param.apr_rcvd.info_len;
304 		info	      = evt->param.apr_rcvd.apr_info;
305 		break;
306 	case IB_CM_SIDR_REQ_RECEIVED:
307 		uvt->resp.u.sidr_req_resp.pkey =
308 					evt->param.sidr_req_rcvd.pkey;
309 		uvt->resp.u.sidr_req_resp.port =
310 					evt->param.sidr_req_rcvd.port;
311 		uvt->data_len = IB_CM_SIDR_REQ_PRIVATE_DATA_SIZE;
312 		break;
313 	case IB_CM_SIDR_REP_RECEIVED:
314 		ib_ucm_event_sidr_rep_get(&uvt->resp.u.sidr_rep_resp,
315 					  &evt->param.sidr_rep_rcvd);
316 		uvt->data_len = IB_CM_SIDR_REP_PRIVATE_DATA_SIZE;
317 		uvt->info_len = evt->param.sidr_rep_rcvd.info_len;
318 		info	      = evt->param.sidr_rep_rcvd.info;
319 		break;
320 	default:
321 		uvt->resp.u.send_status = evt->param.send_status;
322 		break;
323 	}
324 
325 	if (uvt->data_len) {
326 		uvt->data = kmemdup(evt->private_data, uvt->data_len, GFP_KERNEL);
327 		if (!uvt->data)
328 			goto err1;
329 
330 		uvt->resp.present |= IB_UCM_PRES_DATA;
331 	}
332 
333 	if (uvt->info_len) {
334 		uvt->info = kmemdup(info, uvt->info_len, GFP_KERNEL);
335 		if (!uvt->info)
336 			goto err2;
337 
338 		uvt->resp.present |= IB_UCM_PRES_INFO;
339 	}
340 	return 0;
341 
342 err2:
343 	kfree(uvt->data);
344 err1:
345 	return -ENOMEM;
346 }
347 
ib_ucm_event_handler(struct ib_cm_id * cm_id,struct ib_cm_event * event)348 static int ib_ucm_event_handler(struct ib_cm_id *cm_id,
349 				struct ib_cm_event *event)
350 {
351 	struct ib_ucm_event *uevent;
352 	struct ib_ucm_context *ctx;
353 	int result = 0;
354 
355 	ctx = cm_id->context;
356 
357 	uevent = kzalloc(sizeof *uevent, GFP_KERNEL);
358 	if (!uevent)
359 		goto err1;
360 
361 	uevent->ctx = ctx;
362 	uevent->cm_id = cm_id;
363 	uevent->resp.uid = ctx->uid;
364 	uevent->resp.id = ctx->id;
365 	uevent->resp.event = event->event;
366 
367 	result = ib_ucm_event_process(event, uevent);
368 	if (result)
369 		goto err2;
370 
371 	mutex_lock(&ctx->file->file_mutex);
372 	list_add_tail(&uevent->file_list, &ctx->file->events);
373 	list_add_tail(&uevent->ctx_list, &ctx->events);
374 	wake_up_interruptible(&ctx->file->poll_wait);
375 	mutex_unlock(&ctx->file->file_mutex);
376 	return 0;
377 
378 err2:
379 	kfree(uevent);
380 err1:
381 	/* Destroy new cm_id's */
382 	return ib_ucm_new_cm_id(event->event);
383 }
384 
ib_ucm_event(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)385 static ssize_t ib_ucm_event(struct ib_ucm_file *file,
386 			    const char __user *inbuf,
387 			    int in_len, int out_len)
388 {
389 	struct ib_ucm_context *ctx;
390 	struct ib_ucm_event_get cmd;
391 	struct ib_ucm_event *uevent;
392 	int result = 0;
393 
394 	if (out_len < sizeof(struct ib_ucm_event_resp))
395 		return -ENOSPC;
396 
397 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
398 		return -EFAULT;
399 
400 	mutex_lock(&file->file_mutex);
401 	while (list_empty(&file->events)) {
402 		mutex_unlock(&file->file_mutex);
403 
404 		if (file->filp->f_flags & O_NONBLOCK)
405 			return -EAGAIN;
406 
407 		if (wait_event_interruptible(file->poll_wait,
408 					     !list_empty(&file->events)))
409 			return -ERESTARTSYS;
410 
411 		mutex_lock(&file->file_mutex);
412 	}
413 
414 	uevent = list_entry(file->events.next, struct ib_ucm_event, file_list);
415 
416 	if (ib_ucm_new_cm_id(uevent->resp.event)) {
417 		ctx = ib_ucm_ctx_alloc(file);
418 		if (!ctx) {
419 			result = -ENOMEM;
420 			goto done;
421 		}
422 
423 		ctx->cm_id = uevent->cm_id;
424 		ctx->cm_id->context = ctx;
425 		uevent->resp.id = ctx->id;
426 	}
427 
428 	if (copy_to_user((void __user *)(unsigned long)cmd.response,
429 			 &uevent->resp, sizeof(uevent->resp))) {
430 		result = -EFAULT;
431 		goto done;
432 	}
433 
434 	if (uevent->data) {
435 		if (cmd.data_len < uevent->data_len) {
436 			result = -ENOMEM;
437 			goto done;
438 		}
439 		if (copy_to_user((void __user *)(unsigned long)cmd.data,
440 				 uevent->data, uevent->data_len)) {
441 			result = -EFAULT;
442 			goto done;
443 		}
444 	}
445 
446 	if (uevent->info) {
447 		if (cmd.info_len < uevent->info_len) {
448 			result = -ENOMEM;
449 			goto done;
450 		}
451 		if (copy_to_user((void __user *)(unsigned long)cmd.info,
452 				 uevent->info, uevent->info_len)) {
453 			result = -EFAULT;
454 			goto done;
455 		}
456 	}
457 
458 	list_del(&uevent->file_list);
459 	list_del(&uevent->ctx_list);
460 	uevent->ctx->events_reported++;
461 
462 	kfree(uevent->data);
463 	kfree(uevent->info);
464 	kfree(uevent);
465 done:
466 	mutex_unlock(&file->file_mutex);
467 	return result;
468 }
469 
ib_ucm_create_id(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)470 static ssize_t ib_ucm_create_id(struct ib_ucm_file *file,
471 				const char __user *inbuf,
472 				int in_len, int out_len)
473 {
474 	struct ib_ucm_create_id cmd;
475 	struct ib_ucm_create_id_resp resp;
476 	struct ib_ucm_context *ctx;
477 	int result;
478 
479 	if (out_len < sizeof(resp))
480 		return -ENOSPC;
481 
482 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
483 		return -EFAULT;
484 
485 	mutex_lock(&file->file_mutex);
486 	ctx = ib_ucm_ctx_alloc(file);
487 	mutex_unlock(&file->file_mutex);
488 	if (!ctx)
489 		return -ENOMEM;
490 
491 	ctx->uid = cmd.uid;
492 	ctx->cm_id = ib_create_cm_id(file->device->ib_dev,
493 				     ib_ucm_event_handler, ctx);
494 	if (IS_ERR(ctx->cm_id)) {
495 		result = PTR_ERR(ctx->cm_id);
496 		goto err1;
497 	}
498 
499 	resp.id = ctx->id;
500 	if (copy_to_user((void __user *)(unsigned long)cmd.response,
501 			 &resp, sizeof(resp))) {
502 		result = -EFAULT;
503 		goto err2;
504 	}
505 	return 0;
506 
507 err2:
508 	ib_destroy_cm_id(ctx->cm_id);
509 err1:
510 	mutex_lock(&ctx_id_mutex);
511 	idr_remove(&ctx_id_table, ctx->id);
512 	mutex_unlock(&ctx_id_mutex);
513 	kfree(ctx);
514 	return result;
515 }
516 
ib_ucm_destroy_id(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)517 static ssize_t ib_ucm_destroy_id(struct ib_ucm_file *file,
518 				 const char __user *inbuf,
519 				 int in_len, int out_len)
520 {
521 	struct ib_ucm_destroy_id cmd;
522 	struct ib_ucm_destroy_id_resp resp;
523 	struct ib_ucm_context *ctx;
524 	int result = 0;
525 
526 	if (out_len < sizeof(resp))
527 		return -ENOSPC;
528 
529 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
530 		return -EFAULT;
531 
532 	mutex_lock(&ctx_id_mutex);
533 	ctx = idr_find(&ctx_id_table, cmd.id);
534 	if (!ctx)
535 		ctx = ERR_PTR(-ENOENT);
536 	else if (ctx->file != file)
537 		ctx = ERR_PTR(-EINVAL);
538 	else
539 		idr_remove(&ctx_id_table, ctx->id);
540 	mutex_unlock(&ctx_id_mutex);
541 
542 	if (IS_ERR(ctx))
543 		return PTR_ERR(ctx);
544 
545 	ib_ucm_ctx_put(ctx);
546 	wait_for_completion(&ctx->comp);
547 
548 	/* No new events will be generated after destroying the cm_id. */
549 	ib_destroy_cm_id(ctx->cm_id);
550 	/* Cleanup events not yet reported to the user. */
551 	ib_ucm_cleanup_events(ctx);
552 
553 	resp.events_reported = ctx->events_reported;
554 	if (copy_to_user((void __user *)(unsigned long)cmd.response,
555 			 &resp, sizeof(resp)))
556 		result = -EFAULT;
557 
558 	kfree(ctx);
559 	return result;
560 }
561 
ib_ucm_attr_id(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)562 static ssize_t ib_ucm_attr_id(struct ib_ucm_file *file,
563 			      const char __user *inbuf,
564 			      int in_len, int out_len)
565 {
566 	struct ib_ucm_attr_id_resp resp;
567 	struct ib_ucm_attr_id cmd;
568 	struct ib_ucm_context *ctx;
569 	int result = 0;
570 
571 	if (out_len < sizeof(resp))
572 		return -ENOSPC;
573 
574 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
575 		return -EFAULT;
576 
577 	ctx = ib_ucm_ctx_get(file, cmd.id);
578 	if (IS_ERR(ctx))
579 		return PTR_ERR(ctx);
580 
581 	resp.service_id   = ctx->cm_id->service_id;
582 	resp.service_mask = ctx->cm_id->service_mask;
583 	resp.local_id     = ctx->cm_id->local_id;
584 	resp.remote_id    = ctx->cm_id->remote_id;
585 
586 	if (copy_to_user((void __user *)(unsigned long)cmd.response,
587 			 &resp, sizeof(resp)))
588 		result = -EFAULT;
589 
590 	ib_ucm_ctx_put(ctx);
591 	return result;
592 }
593 
ib_ucm_init_qp_attr(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)594 static ssize_t ib_ucm_init_qp_attr(struct ib_ucm_file *file,
595 				   const char __user *inbuf,
596 				   int in_len, int out_len)
597 {
598 	struct ib_uverbs_qp_attr resp;
599 	struct ib_ucm_init_qp_attr cmd;
600 	struct ib_ucm_context *ctx;
601 	struct ib_qp_attr qp_attr;
602 	int result = 0;
603 
604 	if (out_len < sizeof(resp))
605 		return -ENOSPC;
606 
607 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
608 		return -EFAULT;
609 
610 	ctx = ib_ucm_ctx_get(file, cmd.id);
611 	if (IS_ERR(ctx))
612 		return PTR_ERR(ctx);
613 
614 	resp.qp_attr_mask = 0;
615 	memset(&qp_attr, 0, sizeof qp_attr);
616 	qp_attr.qp_state = cmd.qp_state;
617 	result = ib_cm_init_qp_attr(ctx->cm_id, &qp_attr, &resp.qp_attr_mask);
618 	if (result)
619 		goto out;
620 
621 	ib_copy_qp_attr_to_user(&resp, &qp_attr);
622 
623 	if (copy_to_user((void __user *)(unsigned long)cmd.response,
624 			 &resp, sizeof(resp)))
625 		result = -EFAULT;
626 
627 out:
628 	ib_ucm_ctx_put(ctx);
629 	return result;
630 }
631 
ucm_validate_listen(__be64 service_id,__be64 service_mask)632 static int ucm_validate_listen(__be64 service_id, __be64 service_mask)
633 {
634 	service_id &= service_mask;
635 
636 	if (((service_id & IB_CMA_SERVICE_ID_MASK) == IB_CMA_SERVICE_ID) ||
637 	    ((service_id & IB_SDP_SERVICE_ID_MASK) == IB_SDP_SERVICE_ID))
638 		return -EINVAL;
639 
640 	return 0;
641 }
642 
ib_ucm_listen(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)643 static ssize_t ib_ucm_listen(struct ib_ucm_file *file,
644 			     const char __user *inbuf,
645 			     int in_len, int out_len)
646 {
647 	struct ib_ucm_listen cmd;
648 	struct ib_ucm_context *ctx;
649 	int result;
650 
651 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
652 		return -EFAULT;
653 
654 	ctx = ib_ucm_ctx_get(file, cmd.id);
655 	if (IS_ERR(ctx))
656 		return PTR_ERR(ctx);
657 
658 	result = ucm_validate_listen(cmd.service_id, cmd.service_mask);
659 	if (result)
660 		goto out;
661 
662 	result = ib_cm_listen(ctx->cm_id, cmd.service_id, cmd.service_mask);
663 out:
664 	ib_ucm_ctx_put(ctx);
665 	return result;
666 }
667 
ib_ucm_notify(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)668 static ssize_t ib_ucm_notify(struct ib_ucm_file *file,
669 			     const char __user *inbuf,
670 			     int in_len, int out_len)
671 {
672 	struct ib_ucm_notify cmd;
673 	struct ib_ucm_context *ctx;
674 	int result;
675 
676 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
677 		return -EFAULT;
678 
679 	ctx = ib_ucm_ctx_get(file, cmd.id);
680 	if (IS_ERR(ctx))
681 		return PTR_ERR(ctx);
682 
683 	result = ib_cm_notify(ctx->cm_id, (enum ib_event_type) cmd.event);
684 	ib_ucm_ctx_put(ctx);
685 	return result;
686 }
687 
ib_ucm_alloc_data(const void ** dest,u64 src,u32 len)688 static int ib_ucm_alloc_data(const void **dest, u64 src, u32 len)
689 {
690 	void *data;
691 
692 	*dest = NULL;
693 
694 	if (!len)
695 		return 0;
696 
697 	data = memdup_user((void __user *)(unsigned long)src, len);
698 	if (IS_ERR(data))
699 		return PTR_ERR(data);
700 
701 	*dest = data;
702 	return 0;
703 }
704 
ib_ucm_path_get(struct ib_sa_path_rec ** path,u64 src)705 static int ib_ucm_path_get(struct ib_sa_path_rec **path, u64 src)
706 {
707 	struct ib_user_path_rec upath;
708 	struct ib_sa_path_rec  *sa_path;
709 
710 	*path = NULL;
711 
712 	if (!src)
713 		return 0;
714 
715 	sa_path = kmalloc(sizeof(*sa_path), GFP_KERNEL);
716 	if (!sa_path)
717 		return -ENOMEM;
718 
719 	if (copy_from_user(&upath, (void __user *)(unsigned long)src,
720 			   sizeof(upath))) {
721 
722 		kfree(sa_path);
723 		return -EFAULT;
724 	}
725 
726 	ib_copy_path_rec_from_user(sa_path, &upath);
727 	*path = sa_path;
728 	return 0;
729 }
730 
ib_ucm_send_req(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)731 static ssize_t ib_ucm_send_req(struct ib_ucm_file *file,
732 			       const char __user *inbuf,
733 			       int in_len, int out_len)
734 {
735 	struct ib_cm_req_param param;
736 	struct ib_ucm_context *ctx;
737 	struct ib_ucm_req cmd;
738 	int result;
739 
740 	param.private_data   = NULL;
741 	param.primary_path   = NULL;
742 	param.alternate_path = NULL;
743 
744 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
745 		return -EFAULT;
746 
747 	result = ib_ucm_alloc_data(&param.private_data, cmd.data, cmd.len);
748 	if (result)
749 		goto done;
750 
751 	result = ib_ucm_path_get(&param.primary_path, cmd.primary_path);
752 	if (result)
753 		goto done;
754 
755 	result = ib_ucm_path_get(&param.alternate_path, cmd.alternate_path);
756 	if (result)
757 		goto done;
758 
759 	param.private_data_len           = cmd.len;
760 	param.service_id                 = cmd.sid;
761 	param.qp_num                     = cmd.qpn;
762 	param.qp_type                    = cmd.qp_type;
763 	param.starting_psn               = cmd.psn;
764 	param.peer_to_peer               = cmd.peer_to_peer;
765 	param.responder_resources        = cmd.responder_resources;
766 	param.initiator_depth            = cmd.initiator_depth;
767 	param.remote_cm_response_timeout = cmd.remote_cm_response_timeout;
768 	param.flow_control               = cmd.flow_control;
769 	param.local_cm_response_timeout  = cmd.local_cm_response_timeout;
770 	param.retry_count                = cmd.retry_count;
771 	param.rnr_retry_count            = cmd.rnr_retry_count;
772 	param.max_cm_retries             = cmd.max_cm_retries;
773 	param.srq                        = cmd.srq;
774 
775 	ctx = ib_ucm_ctx_get(file, cmd.id);
776 	if (!IS_ERR(ctx)) {
777 		result = ib_send_cm_req(ctx->cm_id, &param);
778 		ib_ucm_ctx_put(ctx);
779 	} else
780 		result = PTR_ERR(ctx);
781 
782 done:
783 	kfree(param.private_data);
784 	kfree(param.primary_path);
785 	kfree(param.alternate_path);
786 	return result;
787 }
788 
ib_ucm_send_rep(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)789 static ssize_t ib_ucm_send_rep(struct ib_ucm_file *file,
790 			       const char __user *inbuf,
791 			       int in_len, int out_len)
792 {
793 	struct ib_cm_rep_param param;
794 	struct ib_ucm_context *ctx;
795 	struct ib_ucm_rep cmd;
796 	int result;
797 
798 	param.private_data = NULL;
799 
800 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
801 		return -EFAULT;
802 
803 	result = ib_ucm_alloc_data(&param.private_data, cmd.data, cmd.len);
804 	if (result)
805 		return result;
806 
807 	param.qp_num              = cmd.qpn;
808 	param.starting_psn        = cmd.psn;
809 	param.private_data_len    = cmd.len;
810 	param.responder_resources = cmd.responder_resources;
811 	param.initiator_depth     = cmd.initiator_depth;
812 	param.failover_accepted   = cmd.failover_accepted;
813 	param.flow_control        = cmd.flow_control;
814 	param.rnr_retry_count     = cmd.rnr_retry_count;
815 	param.srq                 = cmd.srq;
816 
817 	ctx = ib_ucm_ctx_get(file, cmd.id);
818 	if (!IS_ERR(ctx)) {
819 		ctx->uid = cmd.uid;
820 		result = ib_send_cm_rep(ctx->cm_id, &param);
821 		ib_ucm_ctx_put(ctx);
822 	} else
823 		result = PTR_ERR(ctx);
824 
825 	kfree(param.private_data);
826 	return result;
827 }
828 
ib_ucm_send_private_data(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int (* func)(struct ib_cm_id * cm_id,const void * private_data,u8 private_data_len))829 static ssize_t ib_ucm_send_private_data(struct ib_ucm_file *file,
830 					const char __user *inbuf, int in_len,
831 					int (*func)(struct ib_cm_id *cm_id,
832 						    const void *private_data,
833 						    u8 private_data_len))
834 {
835 	struct ib_ucm_private_data cmd;
836 	struct ib_ucm_context *ctx;
837 	const void *private_data = NULL;
838 	int result;
839 
840 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
841 		return -EFAULT;
842 
843 	result = ib_ucm_alloc_data(&private_data, cmd.data, cmd.len);
844 	if (result)
845 		return result;
846 
847 	ctx = ib_ucm_ctx_get(file, cmd.id);
848 	if (!IS_ERR(ctx)) {
849 		result = func(ctx->cm_id, private_data, cmd.len);
850 		ib_ucm_ctx_put(ctx);
851 	} else
852 		result = PTR_ERR(ctx);
853 
854 	kfree(private_data);
855 	return result;
856 }
857 
ib_ucm_send_rtu(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)858 static ssize_t ib_ucm_send_rtu(struct ib_ucm_file *file,
859 			       const char __user *inbuf,
860 			       int in_len, int out_len)
861 {
862 	return ib_ucm_send_private_data(file, inbuf, in_len, ib_send_cm_rtu);
863 }
864 
ib_ucm_send_dreq(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)865 static ssize_t ib_ucm_send_dreq(struct ib_ucm_file *file,
866 				const char __user *inbuf,
867 				int in_len, int out_len)
868 {
869 	return ib_ucm_send_private_data(file, inbuf, in_len, ib_send_cm_dreq);
870 }
871 
ib_ucm_send_drep(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)872 static ssize_t ib_ucm_send_drep(struct ib_ucm_file *file,
873 				const char __user *inbuf,
874 				int in_len, int out_len)
875 {
876 	return ib_ucm_send_private_data(file, inbuf, in_len, ib_send_cm_drep);
877 }
878 
ib_ucm_send_info(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int (* func)(struct ib_cm_id * cm_id,int status,const void * info,u8 info_len,const void * data,u8 data_len))879 static ssize_t ib_ucm_send_info(struct ib_ucm_file *file,
880 				const char __user *inbuf, int in_len,
881 				int (*func)(struct ib_cm_id *cm_id,
882 					    int status,
883 					    const void *info,
884 					    u8 info_len,
885 					    const void *data,
886 					    u8 data_len))
887 {
888 	struct ib_ucm_context *ctx;
889 	struct ib_ucm_info cmd;
890 	const void *data = NULL;
891 	const void *info = NULL;
892 	int result;
893 
894 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
895 		return -EFAULT;
896 
897 	result = ib_ucm_alloc_data(&data, cmd.data, cmd.data_len);
898 	if (result)
899 		goto done;
900 
901 	result = ib_ucm_alloc_data(&info, cmd.info, cmd.info_len);
902 	if (result)
903 		goto done;
904 
905 	ctx = ib_ucm_ctx_get(file, cmd.id);
906 	if (!IS_ERR(ctx)) {
907 		result = func(ctx->cm_id, cmd.status, info, cmd.info_len,
908 			      data, cmd.data_len);
909 		ib_ucm_ctx_put(ctx);
910 	} else
911 		result = PTR_ERR(ctx);
912 
913 done:
914 	kfree(data);
915 	kfree(info);
916 	return result;
917 }
918 
ib_ucm_send_rej(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)919 static ssize_t ib_ucm_send_rej(struct ib_ucm_file *file,
920 			       const char __user *inbuf,
921 			       int in_len, int out_len)
922 {
923 	return ib_ucm_send_info(file, inbuf, in_len, (void *)ib_send_cm_rej);
924 }
925 
ib_ucm_send_apr(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)926 static ssize_t ib_ucm_send_apr(struct ib_ucm_file *file,
927 			       const char __user *inbuf,
928 			       int in_len, int out_len)
929 {
930 	return ib_ucm_send_info(file, inbuf, in_len, (void *)ib_send_cm_apr);
931 }
932 
ib_ucm_send_mra(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)933 static ssize_t ib_ucm_send_mra(struct ib_ucm_file *file,
934 			       const char __user *inbuf,
935 			       int in_len, int out_len)
936 {
937 	struct ib_ucm_context *ctx;
938 	struct ib_ucm_mra cmd;
939 	const void *data = NULL;
940 	int result;
941 
942 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
943 		return -EFAULT;
944 
945 	result = ib_ucm_alloc_data(&data, cmd.data, cmd.len);
946 	if (result)
947 		return result;
948 
949 	ctx = ib_ucm_ctx_get(file, cmd.id);
950 	if (!IS_ERR(ctx)) {
951 		result = ib_send_cm_mra(ctx->cm_id, cmd.timeout, data, cmd.len);
952 		ib_ucm_ctx_put(ctx);
953 	} else
954 		result = PTR_ERR(ctx);
955 
956 	kfree(data);
957 	return result;
958 }
959 
ib_ucm_send_lap(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)960 static ssize_t ib_ucm_send_lap(struct ib_ucm_file *file,
961 			       const char __user *inbuf,
962 			       int in_len, int out_len)
963 {
964 	struct ib_ucm_context *ctx;
965 	struct ib_sa_path_rec *path = NULL;
966 	struct ib_ucm_lap cmd;
967 	const void *data = NULL;
968 	int result;
969 
970 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
971 		return -EFAULT;
972 
973 	result = ib_ucm_alloc_data(&data, cmd.data, cmd.len);
974 	if (result)
975 		goto done;
976 
977 	result = ib_ucm_path_get(&path, cmd.path);
978 	if (result)
979 		goto done;
980 
981 	ctx = ib_ucm_ctx_get(file, cmd.id);
982 	if (!IS_ERR(ctx)) {
983 		result = ib_send_cm_lap(ctx->cm_id, path, data, cmd.len);
984 		ib_ucm_ctx_put(ctx);
985 	} else
986 		result = PTR_ERR(ctx);
987 
988 done:
989 	kfree(data);
990 	kfree(path);
991 	return result;
992 }
993 
ib_ucm_send_sidr_req(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)994 static ssize_t ib_ucm_send_sidr_req(struct ib_ucm_file *file,
995 				    const char __user *inbuf,
996 				    int in_len, int out_len)
997 {
998 	struct ib_cm_sidr_req_param param;
999 	struct ib_ucm_context *ctx;
1000 	struct ib_ucm_sidr_req cmd;
1001 	int result;
1002 
1003 	param.private_data = NULL;
1004 	param.path = NULL;
1005 
1006 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
1007 		return -EFAULT;
1008 
1009 	result = ib_ucm_alloc_data(&param.private_data, cmd.data, cmd.len);
1010 	if (result)
1011 		goto done;
1012 
1013 	result = ib_ucm_path_get(&param.path, cmd.path);
1014 	if (result)
1015 		goto done;
1016 
1017 	param.private_data_len = cmd.len;
1018 	param.service_id       = cmd.sid;
1019 	param.timeout_ms       = cmd.timeout;
1020 	param.max_cm_retries   = cmd.max_cm_retries;
1021 
1022 	ctx = ib_ucm_ctx_get(file, cmd.id);
1023 	if (!IS_ERR(ctx)) {
1024 		result = ib_send_cm_sidr_req(ctx->cm_id, &param);
1025 		ib_ucm_ctx_put(ctx);
1026 	} else
1027 		result = PTR_ERR(ctx);
1028 
1029 done:
1030 	kfree(param.private_data);
1031 	kfree(param.path);
1032 	return result;
1033 }
1034 
ib_ucm_send_sidr_rep(struct ib_ucm_file * file,const char __user * inbuf,int in_len,int out_len)1035 static ssize_t ib_ucm_send_sidr_rep(struct ib_ucm_file *file,
1036 				    const char __user *inbuf,
1037 				    int in_len, int out_len)
1038 {
1039 	struct ib_cm_sidr_rep_param param;
1040 	struct ib_ucm_sidr_rep cmd;
1041 	struct ib_ucm_context *ctx;
1042 	int result;
1043 
1044 	param.info = NULL;
1045 
1046 	if (copy_from_user(&cmd, inbuf, sizeof(cmd)))
1047 		return -EFAULT;
1048 
1049 	result = ib_ucm_alloc_data(&param.private_data,
1050 				   cmd.data, cmd.data_len);
1051 	if (result)
1052 		goto done;
1053 
1054 	result = ib_ucm_alloc_data(&param.info, cmd.info, cmd.info_len);
1055 	if (result)
1056 		goto done;
1057 
1058 	param.qp_num		= cmd.qpn;
1059 	param.qkey		= cmd.qkey;
1060 	param.status		= cmd.status;
1061 	param.info_length	= cmd.info_len;
1062 	param.private_data_len	= cmd.data_len;
1063 
1064 	ctx = ib_ucm_ctx_get(file, cmd.id);
1065 	if (!IS_ERR(ctx)) {
1066 		result = ib_send_cm_sidr_rep(ctx->cm_id, &param);
1067 		ib_ucm_ctx_put(ctx);
1068 	} else
1069 		result = PTR_ERR(ctx);
1070 
1071 done:
1072 	kfree(param.private_data);
1073 	kfree(param.info);
1074 	return result;
1075 }
1076 
1077 static ssize_t (*ucm_cmd_table[])(struct ib_ucm_file *file,
1078 				  const char __user *inbuf,
1079 				  int in_len, int out_len) = {
1080 	[IB_USER_CM_CMD_CREATE_ID]     = ib_ucm_create_id,
1081 	[IB_USER_CM_CMD_DESTROY_ID]    = ib_ucm_destroy_id,
1082 	[IB_USER_CM_CMD_ATTR_ID]       = ib_ucm_attr_id,
1083 	[IB_USER_CM_CMD_LISTEN]        = ib_ucm_listen,
1084 	[IB_USER_CM_CMD_NOTIFY]        = ib_ucm_notify,
1085 	[IB_USER_CM_CMD_SEND_REQ]      = ib_ucm_send_req,
1086 	[IB_USER_CM_CMD_SEND_REP]      = ib_ucm_send_rep,
1087 	[IB_USER_CM_CMD_SEND_RTU]      = ib_ucm_send_rtu,
1088 	[IB_USER_CM_CMD_SEND_DREQ]     = ib_ucm_send_dreq,
1089 	[IB_USER_CM_CMD_SEND_DREP]     = ib_ucm_send_drep,
1090 	[IB_USER_CM_CMD_SEND_REJ]      = ib_ucm_send_rej,
1091 	[IB_USER_CM_CMD_SEND_MRA]      = ib_ucm_send_mra,
1092 	[IB_USER_CM_CMD_SEND_LAP]      = ib_ucm_send_lap,
1093 	[IB_USER_CM_CMD_SEND_APR]      = ib_ucm_send_apr,
1094 	[IB_USER_CM_CMD_SEND_SIDR_REQ] = ib_ucm_send_sidr_req,
1095 	[IB_USER_CM_CMD_SEND_SIDR_REP] = ib_ucm_send_sidr_rep,
1096 	[IB_USER_CM_CMD_EVENT]	       = ib_ucm_event,
1097 	[IB_USER_CM_CMD_INIT_QP_ATTR]  = ib_ucm_init_qp_attr,
1098 };
1099 
ib_ucm_write(struct file * filp,const char __user * buf,size_t len,loff_t * pos)1100 static ssize_t ib_ucm_write(struct file *filp, const char __user *buf,
1101 			    size_t len, loff_t *pos)
1102 {
1103 	struct ib_ucm_file *file = filp->private_data;
1104 	struct ib_ucm_cmd_hdr hdr;
1105 	ssize_t result;
1106 
1107 	if (WARN_ON_ONCE(!ib_safe_file_access(filp)))
1108 		return -EACCES;
1109 
1110 	if (len < sizeof(hdr))
1111 		return -EINVAL;
1112 
1113 	if (copy_from_user(&hdr, buf, sizeof(hdr)))
1114 		return -EFAULT;
1115 
1116 	if (hdr.cmd >= ARRAY_SIZE(ucm_cmd_table))
1117 		return -EINVAL;
1118 
1119 	if (hdr.in + sizeof(hdr) > len)
1120 		return -EINVAL;
1121 
1122 	result = ucm_cmd_table[hdr.cmd](file, buf + sizeof(hdr),
1123 					hdr.in, hdr.out);
1124 	if (!result)
1125 		result = len;
1126 
1127 	return result;
1128 }
1129 
ib_ucm_poll(struct file * filp,struct poll_table_struct * wait)1130 static unsigned int ib_ucm_poll(struct file *filp,
1131 				struct poll_table_struct *wait)
1132 {
1133 	struct ib_ucm_file *file = filp->private_data;
1134 	unsigned int mask = 0;
1135 
1136 	poll_wait(filp, &file->poll_wait, wait);
1137 
1138 	if (!list_empty(&file->events))
1139 		mask = POLLIN | POLLRDNORM;
1140 
1141 	return mask;
1142 }
1143 
1144 /*
1145  * ib_ucm_open() does not need the BKL:
1146  *
1147  *  - no global state is referred to;
1148  *  - there is no ioctl method to race against;
1149  *  - no further module initialization is required for open to work
1150  *    after the device is registered.
1151  */
ib_ucm_open(struct inode * inode,struct file * filp)1152 static int ib_ucm_open(struct inode *inode, struct file *filp)
1153 {
1154 	struct ib_ucm_file *file;
1155 
1156 	file = kmalloc(sizeof(*file), GFP_KERNEL);
1157 	if (!file)
1158 		return -ENOMEM;
1159 
1160 	INIT_LIST_HEAD(&file->events);
1161 	INIT_LIST_HEAD(&file->ctxs);
1162 	init_waitqueue_head(&file->poll_wait);
1163 
1164 	mutex_init(&file->file_mutex);
1165 
1166 	filp->private_data = file;
1167 	file->filp = filp;
1168 	file->device = container_of(inode->i_cdev, struct ib_ucm_device, cdev);
1169 
1170 	return nonseekable_open(inode, filp);
1171 }
1172 
ib_ucm_close(struct inode * inode,struct file * filp)1173 static int ib_ucm_close(struct inode *inode, struct file *filp)
1174 {
1175 	struct ib_ucm_file *file = filp->private_data;
1176 	struct ib_ucm_context *ctx;
1177 
1178 	mutex_lock(&file->file_mutex);
1179 	while (!list_empty(&file->ctxs)) {
1180 		ctx = list_entry(file->ctxs.next,
1181 				 struct ib_ucm_context, file_list);
1182 		mutex_unlock(&file->file_mutex);
1183 
1184 		mutex_lock(&ctx_id_mutex);
1185 		idr_remove(&ctx_id_table, ctx->id);
1186 		mutex_unlock(&ctx_id_mutex);
1187 
1188 		ib_destroy_cm_id(ctx->cm_id);
1189 		ib_ucm_cleanup_events(ctx);
1190 		kfree(ctx);
1191 
1192 		mutex_lock(&file->file_mutex);
1193 	}
1194 	mutex_unlock(&file->file_mutex);
1195 	kfree(file);
1196 	return 0;
1197 }
1198 
1199 static DECLARE_BITMAP(overflow_map, IB_UCM_MAX_DEVICES);
ib_ucm_release_dev(struct device * dev)1200 static void ib_ucm_release_dev(struct device *dev)
1201 {
1202 	struct ib_ucm_device *ucm_dev;
1203 
1204 	ucm_dev = container_of(dev, struct ib_ucm_device, dev);
1205 	cdev_del(&ucm_dev->cdev);
1206 	if (ucm_dev->devnum < IB_UCM_MAX_DEVICES)
1207 		clear_bit(ucm_dev->devnum, dev_map);
1208 	else
1209 		clear_bit(ucm_dev->devnum - IB_UCM_MAX_DEVICES, overflow_map);
1210 	kfree(ucm_dev);
1211 }
1212 
1213 static const struct file_operations ucm_fops = {
1214 	.owner	 = THIS_MODULE,
1215 	.open	 = ib_ucm_open,
1216 	.release = ib_ucm_close,
1217 	.write	 = ib_ucm_write,
1218 	.poll    = ib_ucm_poll,
1219 	.llseek	 = no_llseek,
1220 };
1221 
show_ibdev(struct device * dev,struct device_attribute * attr,char * buf)1222 static ssize_t show_ibdev(struct device *dev, struct device_attribute *attr,
1223 			  char *buf)
1224 {
1225 	struct ib_ucm_device *ucm_dev;
1226 
1227 	ucm_dev = container_of(dev, struct ib_ucm_device, dev);
1228 	return sprintf(buf, "%s\n", ucm_dev->ib_dev->name);
1229 }
1230 static DEVICE_ATTR(ibdev, S_IRUGO, show_ibdev, NULL);
1231 
1232 static dev_t overflow_maj;
find_overflow_devnum(void)1233 static int find_overflow_devnum(void)
1234 {
1235 	int ret;
1236 
1237 	if (!overflow_maj) {
1238 		ret = alloc_chrdev_region(&overflow_maj, 0, IB_UCM_MAX_DEVICES,
1239 					  "infiniband_cm");
1240 		if (ret) {
1241 			printk(KERN_ERR "ucm: couldn't register dynamic device number\n");
1242 			return ret;
1243 		}
1244 	}
1245 
1246 	ret = find_first_zero_bit(overflow_map, IB_UCM_MAX_DEVICES);
1247 	if (ret >= IB_UCM_MAX_DEVICES)
1248 		return -1;
1249 
1250 	return ret;
1251 }
1252 
ib_ucm_add_one(struct ib_device * device)1253 static void ib_ucm_add_one(struct ib_device *device)
1254 {
1255 	int devnum;
1256 	dev_t base;
1257 	struct ib_ucm_device *ucm_dev;
1258 
1259 	if (!device->alloc_ucontext || !rdma_cap_ib_cm(device, 1))
1260 		return;
1261 
1262 	ucm_dev = kzalloc(sizeof *ucm_dev, GFP_KERNEL);
1263 	if (!ucm_dev)
1264 		return;
1265 
1266 	ucm_dev->ib_dev = device;
1267 
1268 	devnum = find_first_zero_bit(dev_map, IB_UCM_MAX_DEVICES);
1269 	if (devnum >= IB_UCM_MAX_DEVICES) {
1270 		devnum = find_overflow_devnum();
1271 		if (devnum < 0)
1272 			goto err;
1273 
1274 		ucm_dev->devnum = devnum + IB_UCM_MAX_DEVICES;
1275 		base = devnum + overflow_maj;
1276 		set_bit(devnum, overflow_map);
1277 	} else {
1278 		ucm_dev->devnum = devnum;
1279 		base = devnum + IB_UCM_BASE_DEV;
1280 		set_bit(devnum, dev_map);
1281 	}
1282 
1283 	cdev_init(&ucm_dev->cdev, &ucm_fops);
1284 	ucm_dev->cdev.owner = THIS_MODULE;
1285 	kobject_set_name(&ucm_dev->cdev.kobj, "ucm%d", ucm_dev->devnum);
1286 	if (cdev_add(&ucm_dev->cdev, base, 1))
1287 		goto err;
1288 
1289 	ucm_dev->dev.class = &cm_class;
1290 	ucm_dev->dev.parent = device->dma_device;
1291 	ucm_dev->dev.devt = ucm_dev->cdev.dev;
1292 	ucm_dev->dev.release = ib_ucm_release_dev;
1293 	dev_set_name(&ucm_dev->dev, "ucm%d", ucm_dev->devnum);
1294 	if (device_register(&ucm_dev->dev))
1295 		goto err_cdev;
1296 
1297 	if (device_create_file(&ucm_dev->dev, &dev_attr_ibdev))
1298 		goto err_dev;
1299 
1300 	ib_set_client_data(device, &ucm_client, ucm_dev);
1301 	return;
1302 
1303 err_dev:
1304 	device_unregister(&ucm_dev->dev);
1305 err_cdev:
1306 	cdev_del(&ucm_dev->cdev);
1307 	if (ucm_dev->devnum < IB_UCM_MAX_DEVICES)
1308 		clear_bit(devnum, dev_map);
1309 	else
1310 		clear_bit(devnum, overflow_map);
1311 err:
1312 	kfree(ucm_dev);
1313 	return;
1314 }
1315 
ib_ucm_remove_one(struct ib_device * device,void * client_data)1316 static void ib_ucm_remove_one(struct ib_device *device, void *client_data)
1317 {
1318 	struct ib_ucm_device *ucm_dev = client_data;
1319 
1320 	if (!ucm_dev)
1321 		return;
1322 
1323 	device_unregister(&ucm_dev->dev);
1324 }
1325 
1326 static CLASS_ATTR_STRING(abi_version, S_IRUGO,
1327 			 __stringify(IB_USER_CM_ABI_VERSION));
1328 
ib_ucm_init(void)1329 static int __init ib_ucm_init(void)
1330 {
1331 	int ret;
1332 
1333 	ret = register_chrdev_region(IB_UCM_BASE_DEV, IB_UCM_MAX_DEVICES,
1334 				     "infiniband_cm");
1335 	if (ret) {
1336 		printk(KERN_ERR "ucm: couldn't register device number\n");
1337 		goto error1;
1338 	}
1339 
1340 	ret = class_create_file(&cm_class, &class_attr_abi_version.attr);
1341 	if (ret) {
1342 		printk(KERN_ERR "ucm: couldn't create abi_version attribute\n");
1343 		goto error2;
1344 	}
1345 
1346 	ret = ib_register_client(&ucm_client);
1347 	if (ret) {
1348 		printk(KERN_ERR "ucm: couldn't register client\n");
1349 		goto error3;
1350 	}
1351 	return 0;
1352 
1353 error3:
1354 	class_remove_file(&cm_class, &class_attr_abi_version.attr);
1355 error2:
1356 	unregister_chrdev_region(IB_UCM_BASE_DEV, IB_UCM_MAX_DEVICES);
1357 error1:
1358 	return ret;
1359 }
1360 
ib_ucm_cleanup(void)1361 static void __exit ib_ucm_cleanup(void)
1362 {
1363 	ib_unregister_client(&ucm_client);
1364 	class_remove_file(&cm_class, &class_attr_abi_version.attr);
1365 	unregister_chrdev_region(IB_UCM_BASE_DEV, IB_UCM_MAX_DEVICES);
1366 	if (overflow_maj)
1367 		unregister_chrdev_region(overflow_maj, IB_UCM_MAX_DEVICES);
1368 	idr_destroy(&ctx_id_table);
1369 }
1370 
1371 module_init(ib_ucm_init);
1372 module_exit(ib_ucm_cleanup);
1373