Merge remote-tracking branches 'regmap/topic/1wire', 'regmap/topic/irq' and 'regmap...
[sfrench/cifs-2.6.git] / drivers / infiniband / hw / nes / nes_cm.c
1 /*
2  * Copyright (c) 2006 - 2014 Intel Corporation.  All rights reserved.
3  *
4  * This software is available to you under a choice of one of two
5  * licenses.  You may choose to be licensed under the terms of the GNU
6  * General Public License (GPL) Version 2, available from the file
7  * COPYING in the main directory of this source tree, or the
8  * OpenIB.org BSD license below:
9  *
10  *     Redistribution and use in source and binary forms, with or
11  *     without modification, are permitted provided that the following
12  *     conditions are met:
13  *
14  *      - Redistributions of source code must retain the above
15  *        copyright notice, this list of conditions and the following
16  *        disclaimer.
17  *
18  *      - Redistributions in binary form must reproduce the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer in the documentation and/or other materials
21  *        provided with the distribution.
22  *
23  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
24  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
25  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
26  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
27  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
28  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
29  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30  * SOFTWARE.
31  *
32  */
33
34
35 #define TCPOPT_TIMESTAMP 8
36
37 #include <linux/atomic.h>
38 #include <linux/skbuff.h>
39 #include <linux/ip.h>
40 #include <linux/tcp.h>
41 #include <linux/init.h>
42 #include <linux/if_arp.h>
43 #include <linux/if_vlan.h>
44 #include <linux/notifier.h>
45 #include <linux/net.h>
46 #include <linux/types.h>
47 #include <linux/timer.h>
48 #include <linux/time.h>
49 #include <linux/delay.h>
50 #include <linux/etherdevice.h>
51 #include <linux/netdevice.h>
52 #include <linux/random.h>
53 #include <linux/list.h>
54 #include <linux/threads.h>
55 #include <linux/highmem.h>
56 #include <linux/slab.h>
57 #include <net/arp.h>
58 #include <net/neighbour.h>
59 #include <net/route.h>
60 #include <net/ip_fib.h>
61 #include <net/tcp.h>
62 #include <linux/fcntl.h>
63
64 #include "nes.h"
65
66 u32 cm_packets_sent;
67 u32 cm_packets_bounced;
68 u32 cm_packets_dropped;
69 u32 cm_packets_retrans;
70 u32 cm_packets_created;
71 u32 cm_packets_received;
72 atomic_t cm_listens_created;
73 atomic_t cm_listens_destroyed;
74 u32 cm_backlog_drops;
75 atomic_t cm_loopbacks;
76 atomic_t cm_nodes_created;
77 atomic_t cm_nodes_destroyed;
78 atomic_t cm_accel_dropped_pkts;
79 atomic_t cm_resets_recvd;
80
81 static inline int mini_cm_accelerated(struct nes_cm_core *, struct nes_cm_node *);
82 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *, struct nes_vnic *, struct nes_cm_info *);
83 static int mini_cm_del_listen(struct nes_cm_core *, struct nes_cm_listener *);
84 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *, struct nes_vnic *, u16, void *, struct nes_cm_info *);
85 static int mini_cm_close(struct nes_cm_core *, struct nes_cm_node *);
86 static int mini_cm_accept(struct nes_cm_core *, struct nes_cm_node *);
87 static int mini_cm_reject(struct nes_cm_core *, struct nes_cm_node *);
88 static int mini_cm_recv_pkt(struct nes_cm_core *, struct nes_vnic *, struct sk_buff *);
89 static int mini_cm_dealloc_core(struct nes_cm_core *);
90 static int mini_cm_get(struct nes_cm_core *);
91 static int mini_cm_set(struct nes_cm_core *, u32, u32);
92
93 static void form_cm_frame(struct sk_buff *, struct nes_cm_node *, void *, u32, void *, u32, u8);
94 static int add_ref_cm_node(struct nes_cm_node *);
95 static int rem_ref_cm_node(struct nes_cm_core *, struct nes_cm_node *);
96
97 static int nes_cm_disconn_true(struct nes_qp *);
98 static int nes_cm_post_event(struct nes_cm_event *event);
99 static int nes_disconnect(struct nes_qp *nesqp, int abrupt);
100 static void nes_disconnect_worker(struct work_struct *work);
101
102 static int send_mpa_request(struct nes_cm_node *, struct sk_buff *);
103 static int send_mpa_reject(struct nes_cm_node *);
104 static int send_syn(struct nes_cm_node *, u32, struct sk_buff *);
105 static int send_reset(struct nes_cm_node *, struct sk_buff *);
106 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb);
107 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb);
108 static void process_packet(struct nes_cm_node *, struct sk_buff *, struct nes_cm_core *);
109
110 static void active_open_err(struct nes_cm_node *, struct sk_buff *, int);
111 static void passive_open_err(struct nes_cm_node *, struct sk_buff *, int);
112 static void cleanup_retrans_entry(struct nes_cm_node *);
113 static void handle_rcv_mpa(struct nes_cm_node *, struct sk_buff *);
114 static void free_retrans_entry(struct nes_cm_node *cm_node);
115 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph, struct sk_buff *skb, int optionsize, int passive);
116
117 /* CM event handler functions */
118 static void cm_event_connected(struct nes_cm_event *);
119 static void cm_event_connect_error(struct nes_cm_event *);
120 static void cm_event_reset(struct nes_cm_event *);
121 static void cm_event_mpa_req(struct nes_cm_event *);
122 static void cm_event_mpa_reject(struct nes_cm_event *);
123 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node);
124
125 /* MPA build functions */
126 static int cm_build_mpa_frame(struct nes_cm_node *, u8 **, u16 *, u8 *, u8);
127 static void build_mpa_v2(struct nes_cm_node *, void *, u8);
128 static void build_mpa_v1(struct nes_cm_node *, void *, u8);
129 static void build_rdma0_msg(struct nes_cm_node *, struct nes_qp **);
130
131 static void print_core(struct nes_cm_core *core);
132 static void record_ird_ord(struct nes_cm_node *, u16, u16);
133
134 /* External CM API Interface */
135 /* instance of function pointers for client API */
136 /* set address of this instance to cm_core->cm_ops at cm_core alloc */
137 static const struct nes_cm_ops nes_cm_api = {
138         .accelerated = mini_cm_accelerated,
139         .listen = mini_cm_listen,
140         .stop_listener = mini_cm_del_listen,
141         .connect = mini_cm_connect,
142         .close = mini_cm_close,
143         .accept = mini_cm_accept,
144         .reject = mini_cm_reject,
145         .recv_pkt = mini_cm_recv_pkt,
146         .destroy_cm_core = mini_cm_dealloc_core,
147         .get = mini_cm_get,
148         .set = mini_cm_set
149 };
150
151 static struct nes_cm_core *g_cm_core;
152
153 atomic_t cm_connects;
154 atomic_t cm_accepts;
155 atomic_t cm_disconnects;
156 atomic_t cm_closes;
157 atomic_t cm_connecteds;
158 atomic_t cm_connect_reqs;
159 atomic_t cm_rejects;
160
161 int nes_add_ref_cm_node(struct nes_cm_node *cm_node)
162 {
163         return add_ref_cm_node(cm_node);
164 }
165
166 int nes_rem_ref_cm_node(struct nes_cm_node *cm_node)
167 {
168         return rem_ref_cm_node(cm_node->cm_core, cm_node);
169 }
170 /**
171  * create_event
172  */
173 static struct nes_cm_event *create_event(struct nes_cm_node *   cm_node,
174                                          enum nes_cm_event_type type)
175 {
176         struct nes_cm_event *event;
177
178         if (!cm_node->cm_id)
179                 return NULL;
180
181         /* allocate an empty event */
182         event = kzalloc(sizeof(*event), GFP_ATOMIC);
183
184         if (!event)
185                 return NULL;
186
187         event->type = type;
188         event->cm_node = cm_node;
189         event->cm_info.rem_addr = cm_node->rem_addr;
190         event->cm_info.loc_addr = cm_node->loc_addr;
191         event->cm_info.rem_port = cm_node->rem_port;
192         event->cm_info.loc_port = cm_node->loc_port;
193         event->cm_info.cm_id = cm_node->cm_id;
194
195         nes_debug(NES_DBG_CM, "cm_node=%p Created event=%p, type=%u, "
196                   "dst_addr=%08x[%x], src_addr=%08x[%x]\n",
197                   cm_node, event, type, event->cm_info.loc_addr,
198                   event->cm_info.loc_port, event->cm_info.rem_addr,
199                   event->cm_info.rem_port);
200
201         nes_cm_post_event(event);
202         return event;
203 }
204
205
206 /**
207  * send_mpa_request
208  */
209 static int send_mpa_request(struct nes_cm_node *cm_node, struct sk_buff *skb)
210 {
211         u8 start_addr = 0;
212         u8 *start_ptr = &start_addr;
213         u8 **start_buff = &start_ptr;
214         u16 buff_len = 0;
215
216         if (!skb) {
217                 nes_debug(NES_DBG_CM, "skb set to NULL\n");
218                 return -1;
219         }
220
221         /* send an MPA Request frame */
222         cm_build_mpa_frame(cm_node, start_buff, &buff_len, NULL, MPA_KEY_REQUEST);
223         form_cm_frame(skb, cm_node, NULL, 0, *start_buff, buff_len, SET_ACK);
224
225         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
226 }
227
228
229
230 static int send_mpa_reject(struct nes_cm_node *cm_node)
231 {
232         struct sk_buff *skb = NULL;
233         u8 start_addr = 0;
234         u8 *start_ptr = &start_addr;
235         u8 **start_buff = &start_ptr;
236         u16 buff_len = 0;
237         struct ietf_mpa_v1 *mpa_frame;
238
239         skb = dev_alloc_skb(MAX_CM_BUFFER);
240         if (!skb) {
241                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
242                 return -ENOMEM;
243         }
244
245         /* send an MPA reject frame */
246         cm_build_mpa_frame(cm_node, start_buff, &buff_len, NULL, MPA_KEY_REPLY);
247         mpa_frame = (struct ietf_mpa_v1 *)*start_buff;
248         mpa_frame->flags |= IETF_MPA_FLAGS_REJECT;
249         form_cm_frame(skb, cm_node, NULL, 0, *start_buff, buff_len, SET_ACK | SET_FIN);
250
251         cm_node->state = NES_CM_STATE_FIN_WAIT1;
252         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
253 }
254
255
256 /**
257  * recv_mpa - process a received TCP pkt, we are expecting an
258  * IETF MPA frame
259  */
260 static int parse_mpa(struct nes_cm_node *cm_node, u8 *buffer, u32 *type,
261                      u32 len)
262 {
263         struct ietf_mpa_v1 *mpa_frame;
264         struct ietf_mpa_v2 *mpa_v2_frame;
265         struct ietf_rtr_msg *rtr_msg;
266         int mpa_hdr_len;
267         int priv_data_len;
268
269         *type = NES_MPA_REQUEST_ACCEPT;
270
271         /* assume req frame is in tcp data payload */
272         if (len < sizeof(struct ietf_mpa_v1)) {
273                 nes_debug(NES_DBG_CM, "The received ietf buffer was too small (%x)\n", len);
274                 return -EINVAL;
275         }
276
277         /* points to the beginning of the frame, which could be MPA V1 or V2 */
278         mpa_frame = (struct ietf_mpa_v1 *)buffer;
279         mpa_hdr_len = sizeof(struct ietf_mpa_v1);
280         priv_data_len = ntohs(mpa_frame->priv_data_len);
281
282         /* make sure mpa private data len is less than 512 bytes */
283         if (priv_data_len > IETF_MAX_PRIV_DATA_LEN) {
284                 nes_debug(NES_DBG_CM, "The received Length of Private"
285                           " Data field exceeds 512 octets\n");
286                 return -EINVAL;
287         }
288         /*
289          * make sure MPA receiver interoperate with the
290          * received MPA version and MPA key information
291          *
292          */
293         if (mpa_frame->rev != IETF_MPA_V1 && mpa_frame->rev != IETF_MPA_V2) {
294                 nes_debug(NES_DBG_CM, "The received mpa version"
295                           " is not supported\n");
296                 return -EINVAL;
297         }
298         /*
299         * backwards compatibility only
300         */
301         if (mpa_frame->rev > cm_node->mpa_frame_rev) {
302                 nes_debug(NES_DBG_CM, "The received mpa version"
303                         " can not be interoperated\n");
304                 return -EINVAL;
305         } else {
306                 cm_node->mpa_frame_rev = mpa_frame->rev;
307         }
308
309         if (cm_node->state != NES_CM_STATE_MPAREQ_SENT) {
310                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE)) {
311                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
312                         return -EINVAL;
313                 }
314         } else {
315                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE)) {
316                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
317                         return -EINVAL;
318                 }
319         }
320
321         if (priv_data_len + mpa_hdr_len != len) {
322                 nes_debug(NES_DBG_CM, "The received ietf buffer was not right"
323                         " complete (%x + %x != %x)\n",
324                         priv_data_len, mpa_hdr_len, len);
325                 return -EINVAL;
326         }
327         /* make sure it does not exceed the max size */
328         if (len > MAX_CM_BUFFER) {
329                 nes_debug(NES_DBG_CM, "The received ietf buffer was too large"
330                         " (%x + %x != %x)\n",
331                         priv_data_len, mpa_hdr_len, len);
332                 return -EINVAL;
333         }
334
335         cm_node->mpa_frame_size = priv_data_len;
336
337         switch (mpa_frame->rev) {
338         case IETF_MPA_V2: {
339                 u16 ird_size;
340                 u16 ord_size;
341                 u16 rtr_ctrl_ird;
342                 u16 rtr_ctrl_ord;
343
344                 mpa_v2_frame = (struct ietf_mpa_v2 *)buffer;
345                 mpa_hdr_len += IETF_RTR_MSG_SIZE;
346                 cm_node->mpa_frame_size -= IETF_RTR_MSG_SIZE;
347                 rtr_msg = &mpa_v2_frame->rtr_msg;
348
349                 /* parse rtr message */
350                 rtr_ctrl_ird = ntohs(rtr_msg->ctrl_ird);
351                 rtr_ctrl_ord = ntohs(rtr_msg->ctrl_ord);
352                 ird_size = rtr_ctrl_ird & IETF_NO_IRD_ORD;
353                 ord_size = rtr_ctrl_ord & IETF_NO_IRD_ORD;
354
355                 if (!(rtr_ctrl_ird & IETF_PEER_TO_PEER)) {
356                         /* send reset */
357                         return -EINVAL;
358                 }
359                 if (ird_size == IETF_NO_IRD_ORD || ord_size == IETF_NO_IRD_ORD)
360                         cm_node->mpav2_ird_ord = IETF_NO_IRD_ORD;
361
362                 if (cm_node->mpav2_ird_ord != IETF_NO_IRD_ORD) {
363                         /* responder */
364                         if (cm_node->state != NES_CM_STATE_MPAREQ_SENT) {
365                                 /* we are still negotiating */
366                                 if (ord_size > NES_MAX_IRD) {
367                                         cm_node->ird_size = NES_MAX_IRD;
368                                 } else {
369                                         cm_node->ird_size = ord_size;
370                                         if (ord_size == 0 &&
371                                         (rtr_ctrl_ord & IETF_RDMA0_READ)) {
372                                                 cm_node->ird_size = 1;
373                                                 nes_debug(NES_DBG_CM,
374                                                 "%s: Remote peer doesn't support RDMA0_READ (ord=%u)\n",
375                                                         __func__, ord_size);
376                                         }
377                                 }
378                                 if (ird_size > NES_MAX_ORD)
379                                         cm_node->ord_size = NES_MAX_ORD;
380                                 else
381                                         cm_node->ord_size = ird_size;
382                         } else { /* initiator */
383                                 if (ord_size > NES_MAX_IRD) {
384                                         nes_debug(NES_DBG_CM,
385                                         "%s: Unable to support the requested (ord =%u)\n",
386                                                         __func__, ord_size);
387                                         return -EINVAL;
388                                 }
389                                 cm_node->ird_size = ord_size;
390
391                                 if (ird_size > NES_MAX_ORD) {
392                                         cm_node->ord_size = NES_MAX_ORD;
393                                 } else {
394                                         if (ird_size == 0 &&
395                                         (rtr_ctrl_ord & IETF_RDMA0_READ)) {
396                                                 nes_debug(NES_DBG_CM,
397                                                 "%s: Remote peer doesn't support RDMA0_READ (ird=%u)\n",
398                                                         __func__, ird_size);
399                                                 return -EINVAL;
400                                         } else {
401                                                 cm_node->ord_size = ird_size;
402                                         }
403                                 }
404                         }
405                 }
406
407                 if (rtr_ctrl_ord & IETF_RDMA0_READ) {
408                         cm_node->send_rdma0_op = SEND_RDMA_READ_ZERO;
409
410                 } else if (rtr_ctrl_ord & IETF_RDMA0_WRITE) {
411                         cm_node->send_rdma0_op = SEND_RDMA_WRITE_ZERO;
412                 } else {        /* Not supported RDMA0 operation */
413                         return -EINVAL;
414                 }
415                 break;
416         }
417         case IETF_MPA_V1:
418         default:
419                 break;
420         }
421
422         /* copy entire MPA frame to our cm_node's frame */
423         memcpy(cm_node->mpa_frame_buf, buffer + mpa_hdr_len, cm_node->mpa_frame_size);
424
425         if (mpa_frame->flags & IETF_MPA_FLAGS_REJECT)
426                 *type = NES_MPA_REQUEST_REJECT;
427         return 0;
428 }
429
430
431 /**
432  * form_cm_frame - get a free packet and build empty frame Use
433  * node info to build.
434  */
435 static void form_cm_frame(struct sk_buff *skb,
436                           struct nes_cm_node *cm_node, void *options, u32 optionsize,
437                           void *data, u32 datasize, u8 flags)
438 {
439         struct tcphdr *tcph;
440         struct iphdr *iph;
441         struct ethhdr *ethh;
442         u8 *buf;
443         u16 packetsize = sizeof(*iph);
444
445         packetsize += sizeof(*tcph);
446         packetsize += optionsize + datasize;
447
448         skb_trim(skb, 0);
449         memset(skb->data, 0x00, ETH_HLEN + sizeof(*iph) + sizeof(*tcph));
450
451         buf = skb_put(skb, packetsize + ETH_HLEN);
452
453         ethh = (struct ethhdr *)buf;
454         buf += ETH_HLEN;
455
456         iph = (struct iphdr *)buf;
457         buf += sizeof(*iph);
458         tcph = (struct tcphdr *)buf;
459         skb_reset_mac_header(skb);
460         skb_set_network_header(skb, ETH_HLEN);
461         skb_set_transport_header(skb, ETH_HLEN + sizeof(*iph));
462         buf += sizeof(*tcph);
463
464         skb->ip_summed = CHECKSUM_PARTIAL;
465         if (!(cm_node->netdev->features & NETIF_F_IP_CSUM))
466                 skb->ip_summed = CHECKSUM_NONE;
467         skb->protocol = htons(0x800);
468         skb->data_len = 0;
469         skb->mac_len = ETH_HLEN;
470
471         memcpy(ethh->h_dest, cm_node->rem_mac, ETH_ALEN);
472         memcpy(ethh->h_source, cm_node->loc_mac, ETH_ALEN);
473         ethh->h_proto = htons(0x0800);
474
475         iph->version = IPVERSION;
476         iph->ihl = 5;           /* 5 * 4Byte words, IP headr len */
477         iph->tos = 0;
478         iph->tot_len = htons(packetsize);
479         iph->id = htons(++cm_node->tcp_cntxt.loc_id);
480
481         iph->frag_off = htons(0x4000);
482         iph->ttl = 0x40;
483         iph->protocol = 0x06;   /* IPPROTO_TCP */
484
485         iph->saddr = htonl(cm_node->loc_addr);
486         iph->daddr = htonl(cm_node->rem_addr);
487
488         tcph->source = htons(cm_node->loc_port);
489         tcph->dest = htons(cm_node->rem_port);
490         tcph->seq = htonl(cm_node->tcp_cntxt.loc_seq_num);
491
492         if (flags & SET_ACK) {
493                 cm_node->tcp_cntxt.loc_ack_num = cm_node->tcp_cntxt.rcv_nxt;
494                 tcph->ack_seq = htonl(cm_node->tcp_cntxt.loc_ack_num);
495                 tcph->ack = 1;
496         } else {
497                 tcph->ack_seq = 0;
498         }
499
500         if (flags & SET_SYN) {
501                 cm_node->tcp_cntxt.loc_seq_num++;
502                 tcph->syn = 1;
503         } else {
504                 cm_node->tcp_cntxt.loc_seq_num += datasize;
505         }
506
507         if (flags & SET_FIN) {
508                 cm_node->tcp_cntxt.loc_seq_num++;
509                 tcph->fin = 1;
510         }
511
512         if (flags & SET_RST)
513                 tcph->rst = 1;
514
515         tcph->doff = (u16)((sizeof(*tcph) + optionsize + 3) >> 2);
516         tcph->window = htons(cm_node->tcp_cntxt.rcv_wnd);
517         tcph->urg_ptr = 0;
518         if (optionsize)
519                 memcpy(buf, options, optionsize);
520         buf += optionsize;
521         if (datasize)
522                 memcpy(buf, data, datasize);
523
524         skb_shinfo(skb)->nr_frags = 0;
525         cm_packets_created++;
526 }
527
528 /**
529  * print_core - dump a cm core
530  */
531 static void print_core(struct nes_cm_core *core)
532 {
533         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
534         nes_debug(NES_DBG_CM, "CM Core  -- (core = %p )\n", core);
535         if (!core)
536                 return;
537         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
538
539         nes_debug(NES_DBG_CM, "State         : %u \n", core->state);
540
541         nes_debug(NES_DBG_CM, "Listen Nodes  : %u \n", atomic_read(&core->listen_node_cnt));
542         nes_debug(NES_DBG_CM, "Active Nodes  : %u \n", atomic_read(&core->node_cnt));
543
544         nes_debug(NES_DBG_CM, "core          : %p \n", core);
545
546         nes_debug(NES_DBG_CM, "-------------- end core ---------------\n");
547 }
548
549 static void record_ird_ord(struct nes_cm_node *cm_node,
550                                         u16 conn_ird, u16 conn_ord)
551 {
552         if (conn_ird > NES_MAX_IRD)
553                 conn_ird = NES_MAX_IRD;
554
555         if (conn_ord > NES_MAX_ORD)
556                 conn_ord = NES_MAX_ORD;
557
558         cm_node->ird_size = conn_ird;
559         cm_node->ord_size = conn_ord;
560 }
561
562 /**
563  * cm_build_mpa_frame - build a MPA V1 frame or MPA V2 frame
564  */
565 static int cm_build_mpa_frame(struct nes_cm_node *cm_node, u8 **start_buff,
566                               u16 *buff_len, u8 *pci_mem, u8 mpa_key)
567 {
568         int ret = 0;
569
570         *start_buff = (pci_mem) ? pci_mem : &cm_node->mpa_frame_buf[0];
571
572         switch (cm_node->mpa_frame_rev) {
573         case IETF_MPA_V1:
574                 *start_buff = (u8 *)*start_buff + sizeof(struct ietf_rtr_msg);
575                 *buff_len = sizeof(struct ietf_mpa_v1) + cm_node->mpa_frame_size;
576                 build_mpa_v1(cm_node, *start_buff, mpa_key);
577                 break;
578         case IETF_MPA_V2:
579                 *buff_len = sizeof(struct ietf_mpa_v2) + cm_node->mpa_frame_size;
580                 build_mpa_v2(cm_node, *start_buff, mpa_key);
581                 break;
582         default:
583                 ret = -EINVAL;
584         }
585         return ret;
586 }
587
588 /**
589  * build_mpa_v2 - build a MPA V2 frame
590  */
591 static void build_mpa_v2(struct nes_cm_node *cm_node,
592                          void *start_addr, u8 mpa_key)
593 {
594         struct ietf_mpa_v2 *mpa_frame = (struct ietf_mpa_v2 *)start_addr;
595         struct ietf_rtr_msg *rtr_msg = &mpa_frame->rtr_msg;
596         u16 ctrl_ird;
597         u16 ctrl_ord;
598
599         /* initialize the upper 5 bytes of the frame */
600         build_mpa_v1(cm_node, start_addr, mpa_key);
601         mpa_frame->flags |= IETF_MPA_V2_FLAG; /* set a bit to indicate MPA V2 */
602         mpa_frame->priv_data_len += htons(IETF_RTR_MSG_SIZE);
603
604         /* initialize RTR msg */
605         if (cm_node->mpav2_ird_ord == IETF_NO_IRD_ORD) {
606                 ctrl_ird = IETF_NO_IRD_ORD;
607                 ctrl_ord = IETF_NO_IRD_ORD;
608         } else {
609                 ctrl_ird = cm_node->ird_size & IETF_NO_IRD_ORD;
610                 ctrl_ord = cm_node->ord_size & IETF_NO_IRD_ORD;
611         }
612         ctrl_ird |= IETF_PEER_TO_PEER;
613
614         switch (mpa_key) {
615         case MPA_KEY_REQUEST:
616                 ctrl_ord |= IETF_RDMA0_WRITE;
617                 ctrl_ord |= IETF_RDMA0_READ;
618                 break;
619         case MPA_KEY_REPLY:
620                 switch (cm_node->send_rdma0_op) {
621                 case SEND_RDMA_WRITE_ZERO:
622                         ctrl_ord |= IETF_RDMA0_WRITE;
623                         break;
624                 case SEND_RDMA_READ_ZERO:
625                         ctrl_ord |= IETF_RDMA0_READ;
626                         break;
627                 }
628         }
629         rtr_msg->ctrl_ird = htons(ctrl_ird);
630         rtr_msg->ctrl_ord = htons(ctrl_ord);
631 }
632
633 /**
634  * build_mpa_v1 - build a MPA V1 frame
635  */
636 static void build_mpa_v1(struct nes_cm_node *cm_node, void *start_addr, u8 mpa_key)
637 {
638         struct ietf_mpa_v1 *mpa_frame = (struct ietf_mpa_v1 *)start_addr;
639
640         switch (mpa_key) {
641         case MPA_KEY_REQUEST:
642                 memcpy(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE);
643                 break;
644         case MPA_KEY_REPLY:
645                 memcpy(mpa_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE);
646                 break;
647         }
648         mpa_frame->flags = IETF_MPA_FLAGS_CRC;
649         mpa_frame->rev = cm_node->mpa_frame_rev;
650         mpa_frame->priv_data_len = htons(cm_node->mpa_frame_size);
651 }
652
653 static void build_rdma0_msg(struct nes_cm_node *cm_node, struct nes_qp **nesqp_addr)
654 {
655         u64 u64temp;
656         struct nes_qp *nesqp = *nesqp_addr;
657         struct nes_hw_qp_wqe *wqe = &nesqp->hwqp.sq_vbase[0];
658
659         u64temp = (unsigned long)nesqp->nesuqp_addr;
660         u64temp |= NES_SW_CONTEXT_ALIGN >> 1;
661         set_wqe_64bit_value(wqe->wqe_words, NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX, u64temp);
662
663         wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_LOW_IDX] = 0;
664         wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_HIGH_IDX] = 0;
665
666         switch (cm_node->send_rdma0_op) {
667         case SEND_RDMA_WRITE_ZERO:
668                 nes_debug(NES_DBG_CM, "Sending first write.\n");
669                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
670                         cpu_to_le32(NES_IWARP_SQ_OP_RDMAW);
671                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] = 0;
672                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] = 0;
673                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = 0;
674                 break;
675
676         case SEND_RDMA_READ_ZERO:
677         default:
678                 if (cm_node->send_rdma0_op != SEND_RDMA_READ_ZERO)
679                         WARN(1, "Unsupported RDMA0 len operation=%u\n",
680                              cm_node->send_rdma0_op);
681                 nes_debug(NES_DBG_CM, "Sending first rdma operation.\n");
682                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
683                         cpu_to_le32(NES_IWARP_SQ_OP_RDMAR);
684                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_TO_LOW_IDX] = 1;
685                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_TO_HIGH_IDX] = 0;
686                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_LENGTH_IDX] = 0;
687                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_STAG_IDX] = 1;
688                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = 1;
689                 break;
690         }
691
692         if (nesqp->sq_kmapped) {
693                 nesqp->sq_kmapped = 0;
694                 kunmap(nesqp->page);
695         }
696
697         /*use the reserved spot on the WQ for the extra first WQE*/
698         nesqp->nesqp_context->ird_ord_sizes &= cpu_to_le32(~(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
699                                                              NES_QPCONTEXT_ORDIRD_WRPDU |
700                                                              NES_QPCONTEXT_ORDIRD_ALSMM));
701         nesqp->skip_lsmm = 1;
702         nesqp->hwqp.sq_tail = 0;
703 }
704
705 /**
706  * schedule_nes_timer
707  * note - cm_node needs to be protected before calling this. Encase in:
708  *                      rem_ref_cm_node(cm_core, cm_node);add_ref_cm_node(cm_node);
709  */
710 int schedule_nes_timer(struct nes_cm_node *cm_node, struct sk_buff *skb,
711                        enum nes_timer_type type, int send_retrans,
712                        int close_when_complete)
713 {
714         unsigned long flags;
715         struct nes_cm_core *cm_core = cm_node->cm_core;
716         struct nes_timer_entry *new_send;
717         int ret = 0;
718
719         new_send = kzalloc(sizeof(*new_send), GFP_ATOMIC);
720         if (!new_send)
721                 return -ENOMEM;
722
723         /* new_send->timetosend = currenttime */
724         new_send->retrycount = NES_DEFAULT_RETRYS;
725         new_send->retranscount = NES_DEFAULT_RETRANS;
726         new_send->skb = skb;
727         new_send->timetosend = jiffies;
728         new_send->type = type;
729         new_send->netdev = cm_node->netdev;
730         new_send->send_retrans = send_retrans;
731         new_send->close_when_complete = close_when_complete;
732
733         if (type == NES_TIMER_TYPE_CLOSE) {
734                 new_send->timetosend += (HZ / 10);
735                 if (cm_node->recv_entry) {
736                         kfree(new_send);
737                         WARN_ON(1);
738                         return -EINVAL;
739                 }
740                 cm_node->recv_entry = new_send;
741         }
742
743         if (type == NES_TIMER_TYPE_SEND) {
744                 new_send->seq_num = ntohl(tcp_hdr(skb)->seq);
745                 atomic_inc(&new_send->skb->users);
746                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
747                 cm_node->send_entry = new_send;
748                 add_ref_cm_node(cm_node);
749                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
750                 new_send->timetosend = jiffies + NES_RETRY_TIMEOUT;
751
752                 ret = nes_nic_cm_xmit(new_send->skb, cm_node->netdev);
753                 if (ret != NETDEV_TX_OK) {
754                         nes_debug(NES_DBG_CM, "Error sending packet %p "
755                                   "(jiffies = %lu)\n", new_send, jiffies);
756                         new_send->timetosend = jiffies;
757                         ret = NETDEV_TX_OK;
758                 } else {
759                         cm_packets_sent++;
760                         if (!send_retrans) {
761                                 cleanup_retrans_entry(cm_node);
762                                 if (close_when_complete)
763                                         rem_ref_cm_node(cm_core, cm_node);
764                                 return ret;
765                         }
766                 }
767         }
768
769         if (!timer_pending(&cm_core->tcp_timer))
770                 mod_timer(&cm_core->tcp_timer, new_send->timetosend);
771
772         return ret;
773 }
774
775 static void nes_retrans_expired(struct nes_cm_node *cm_node)
776 {
777         struct iw_cm_id *cm_id = cm_node->cm_id;
778         enum nes_cm_node_state state = cm_node->state;
779         cm_node->state = NES_CM_STATE_CLOSED;
780
781         switch (state) {
782         case NES_CM_STATE_SYN_RCVD:
783         case NES_CM_STATE_CLOSING:
784                 rem_ref_cm_node(cm_node->cm_core, cm_node);
785                 break;
786         case NES_CM_STATE_LAST_ACK:
787         case NES_CM_STATE_FIN_WAIT1:
788                 if (cm_node->cm_id)
789                         cm_id->rem_ref(cm_id);
790                 send_reset(cm_node, NULL);
791                 break;
792         default:
793                 add_ref_cm_node(cm_node);
794                 send_reset(cm_node, NULL);
795                 create_event(cm_node, NES_CM_EVENT_ABORTED);
796         }
797 }
798
799 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node)
800 {
801         struct nes_timer_entry *recv_entry = cm_node->recv_entry;
802         struct iw_cm_id *cm_id = cm_node->cm_id;
803         struct nes_qp *nesqp;
804         unsigned long qplockflags;
805
806         if (!recv_entry)
807                 return;
808         nesqp = (struct nes_qp *)recv_entry->skb;
809         if (nesqp) {
810                 spin_lock_irqsave(&nesqp->lock, qplockflags);
811                 if (nesqp->cm_id) {
812                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
813                                   "refcount = %d: HIT A "
814                                   "NES_TIMER_TYPE_CLOSE with something "
815                                   "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
816                                   atomic_read(&nesqp->refcount));
817                         nesqp->hw_tcp_state = NES_AEQE_TCP_STATE_CLOSED;
818                         nesqp->last_aeq = NES_AEQE_AEID_RESET_SENT;
819                         nesqp->ibqp_state = IB_QPS_ERR;
820                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
821                         nes_cm_disconn(nesqp);
822                 } else {
823                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
824                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
825                                   "refcount = %d: HIT A "
826                                   "NES_TIMER_TYPE_CLOSE with nothing "
827                                   "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
828                                   atomic_read(&nesqp->refcount));
829                 }
830         } else if (rem_node) {
831                 /* TIME_WAIT state */
832                 rem_ref_cm_node(cm_node->cm_core, cm_node);
833         }
834         if (cm_node->cm_id)
835                 cm_id->rem_ref(cm_id);
836         kfree(recv_entry);
837         cm_node->recv_entry = NULL;
838 }
839
840 /**
841  * nes_cm_timer_tick
842  */
843 static void nes_cm_timer_tick(unsigned long pass)
844 {
845         unsigned long flags;
846         unsigned long nexttimeout = jiffies + NES_LONG_TIME;
847         struct nes_cm_node *cm_node;
848         struct nes_timer_entry *send_entry, *recv_entry;
849         struct list_head *list_core_temp;
850         struct list_head *list_node;
851         struct nes_cm_core *cm_core = g_cm_core;
852         u32 settimer = 0;
853         unsigned long timetosend;
854         int ret = NETDEV_TX_OK;
855
856         struct list_head timer_list;
857
858         INIT_LIST_HEAD(&timer_list);
859         spin_lock_irqsave(&cm_core->ht_lock, flags);
860
861         list_for_each_safe(list_node, list_core_temp,
862                            &cm_core->connected_nodes) {
863                 cm_node = container_of(list_node, struct nes_cm_node, list);
864                 if ((cm_node->recv_entry) || (cm_node->send_entry)) {
865                         add_ref_cm_node(cm_node);
866                         list_add(&cm_node->timer_entry, &timer_list);
867                 }
868         }
869         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
870
871         list_for_each_safe(list_node, list_core_temp, &timer_list) {
872                 cm_node = container_of(list_node, struct nes_cm_node,
873                                        timer_entry);
874                 recv_entry = cm_node->recv_entry;
875
876                 if (recv_entry) {
877                         if (time_after(recv_entry->timetosend, jiffies)) {
878                                 if (nexttimeout > recv_entry->timetosend ||
879                                     !settimer) {
880                                         nexttimeout = recv_entry->timetosend;
881                                         settimer = 1;
882                                 }
883                         } else {
884                                 handle_recv_entry(cm_node, 1);
885                         }
886                 }
887
888                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
889                 do {
890                         send_entry = cm_node->send_entry;
891                         if (!send_entry)
892                                 break;
893                         if (time_after(send_entry->timetosend, jiffies)) {
894                                 if (cm_node->state != NES_CM_STATE_TSA) {
895                                         if ((nexttimeout >
896                                              send_entry->timetosend) ||
897                                             !settimer) {
898                                                 nexttimeout =
899                                                         send_entry->timetosend;
900                                                 settimer = 1;
901                                         }
902                                 } else {
903                                         free_retrans_entry(cm_node);
904                                 }
905                                 break;
906                         }
907
908                         if ((cm_node->state == NES_CM_STATE_TSA) ||
909                             (cm_node->state == NES_CM_STATE_CLOSED)) {
910                                 free_retrans_entry(cm_node);
911                                 break;
912                         }
913
914                         if (!send_entry->retranscount ||
915                             !send_entry->retrycount) {
916                                 cm_packets_dropped++;
917                                 free_retrans_entry(cm_node);
918
919                                 spin_unlock_irqrestore(
920                                         &cm_node->retrans_list_lock, flags);
921                                 nes_retrans_expired(cm_node);
922                                 cm_node->state = NES_CM_STATE_CLOSED;
923                                 spin_lock_irqsave(&cm_node->retrans_list_lock,
924                                                   flags);
925                                 break;
926                         }
927                         atomic_inc(&send_entry->skb->users);
928                         cm_packets_retrans++;
929                         nes_debug(NES_DBG_CM, "Retransmitting send_entry %p "
930                                   "for node %p, jiffies = %lu, time to send = "
931                                   "%lu, retranscount = %u, send_entry->seq_num = "
932                                   "0x%08X, cm_node->tcp_cntxt.rem_ack_num = "
933                                   "0x%08X\n", send_entry, cm_node, jiffies,
934                                   send_entry->timetosend,
935                                   send_entry->retranscount,
936                                   send_entry->seq_num,
937                                   cm_node->tcp_cntxt.rem_ack_num);
938
939                         spin_unlock_irqrestore(&cm_node->retrans_list_lock,
940                                                flags);
941                         ret = nes_nic_cm_xmit(send_entry->skb, cm_node->netdev);
942                         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
943                         if (ret != NETDEV_TX_OK) {
944                                 nes_debug(NES_DBG_CM, "rexmit failed for "
945                                           "node=%p\n", cm_node);
946                                 cm_packets_bounced++;
947                                 send_entry->retrycount--;
948                                 nexttimeout = jiffies + NES_SHORT_TIME;
949                                 settimer = 1;
950                                 break;
951                         } else {
952                                 cm_packets_sent++;
953                         }
954                         nes_debug(NES_DBG_CM, "Packet Sent: retrans count = "
955                                   "%u, retry count = %u.\n",
956                                   send_entry->retranscount,
957                                   send_entry->retrycount);
958                         if (send_entry->send_retrans) {
959                                 send_entry->retranscount--;
960                                 timetosend = (NES_RETRY_TIMEOUT <<
961                                               (NES_DEFAULT_RETRANS - send_entry->retranscount));
962
963                                 send_entry->timetosend = jiffies +
964                                                          min(timetosend, NES_MAX_TIMEOUT);
965                                 if (nexttimeout > send_entry->timetosend ||
966                                     !settimer) {
967                                         nexttimeout = send_entry->timetosend;
968                                         settimer = 1;
969                                 }
970                         } else {
971                                 int close_when_complete;
972                                 close_when_complete =
973                                         send_entry->close_when_complete;
974                                 nes_debug(NES_DBG_CM, "cm_node=%p state=%d\n",
975                                           cm_node, cm_node->state);
976                                 free_retrans_entry(cm_node);
977                                 if (close_when_complete)
978                                         rem_ref_cm_node(cm_node->cm_core,
979                                                         cm_node);
980                         }
981                 } while (0);
982
983                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
984                 rem_ref_cm_node(cm_node->cm_core, cm_node);
985         }
986
987         if (settimer) {
988                 if (!timer_pending(&cm_core->tcp_timer))
989                         mod_timer(&cm_core->tcp_timer, nexttimeout);
990         }
991 }
992
993
994 /**
995  * send_syn
996  */
997 static int send_syn(struct nes_cm_node *cm_node, u32 sendack,
998                     struct sk_buff *skb)
999 {
1000         int ret;
1001         int flags = SET_SYN;
1002         char optionsbuffer[sizeof(struct option_mss) +
1003                            sizeof(struct option_windowscale) + sizeof(struct option_base) +
1004                            TCP_OPTIONS_PADDING];
1005
1006         int optionssize = 0;
1007         /* Sending MSS option */
1008         union all_known_options *options;
1009
1010         if (!cm_node)
1011                 return -EINVAL;
1012
1013         options = (union all_known_options *)&optionsbuffer[optionssize];
1014         options->as_mss.optionnum = OPTION_NUMBER_MSS;
1015         options->as_mss.length = sizeof(struct option_mss);
1016         options->as_mss.mss = htons(cm_node->tcp_cntxt.mss);
1017         optionssize += sizeof(struct option_mss);
1018
1019         options = (union all_known_options *)&optionsbuffer[optionssize];
1020         options->as_windowscale.optionnum = OPTION_NUMBER_WINDOW_SCALE;
1021         options->as_windowscale.length = sizeof(struct option_windowscale);
1022         options->as_windowscale.shiftcount = cm_node->tcp_cntxt.rcv_wscale;
1023         optionssize += sizeof(struct option_windowscale);
1024
1025         if (sendack && !(NES_DRV_OPT_SUPRESS_OPTION_BC & nes_drv_opt)) {
1026                 options = (union all_known_options *)&optionsbuffer[optionssize];
1027                 options->as_base.optionnum = OPTION_NUMBER_WRITE0;
1028                 options->as_base.length = sizeof(struct option_base);
1029                 optionssize += sizeof(struct option_base);
1030                 /* we need the size to be a multiple of 4 */
1031                 options = (union all_known_options *)&optionsbuffer[optionssize];
1032                 options->as_end = 1;
1033                 optionssize += 1;
1034                 options = (union all_known_options *)&optionsbuffer[optionssize];
1035                 options->as_end = 1;
1036                 optionssize += 1;
1037         }
1038
1039         options = (union all_known_options *)&optionsbuffer[optionssize];
1040         options->as_end = OPTION_NUMBER_END;
1041         optionssize += 1;
1042
1043         if (!skb)
1044                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1045         if (!skb) {
1046                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1047                 return -1;
1048         }
1049
1050         if (sendack)
1051                 flags |= SET_ACK;
1052
1053         form_cm_frame(skb, cm_node, optionsbuffer, optionssize, NULL, 0, flags);
1054         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
1055
1056         return ret;
1057 }
1058
1059
1060 /**
1061  * send_reset
1062  */
1063 static int send_reset(struct nes_cm_node *cm_node, struct sk_buff *skb)
1064 {
1065         int ret;
1066         int flags = SET_RST | SET_ACK;
1067
1068         if (!skb)
1069                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1070         if (!skb) {
1071                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1072                 return -ENOMEM;
1073         }
1074
1075         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, flags);
1076         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 1);
1077
1078         return ret;
1079 }
1080
1081
1082 /**
1083  * send_ack
1084  */
1085 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb)
1086 {
1087         int ret;
1088
1089         if (!skb)
1090                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1091
1092         if (!skb) {
1093                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1094                 return -1;
1095         }
1096
1097         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK);
1098         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 0);
1099
1100         return ret;
1101 }
1102
1103
1104 /**
1105  * send_fin
1106  */
1107 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb)
1108 {
1109         int ret;
1110
1111         /* if we didn't get a frame get one */
1112         if (!skb)
1113                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1114
1115         if (!skb) {
1116                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1117                 return -1;
1118         }
1119
1120         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK | SET_FIN);
1121         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
1122
1123         return ret;
1124 }
1125
1126
1127 /**
1128  * find_node - find a cm node that matches the reference cm node
1129  */
1130 static struct nes_cm_node *find_node(struct nes_cm_core *cm_core,
1131                                      u16 rem_port, nes_addr_t rem_addr, u16 loc_port, nes_addr_t loc_addr)
1132 {
1133         unsigned long flags;
1134         struct list_head *hte;
1135         struct nes_cm_node *cm_node;
1136
1137         /* get a handle on the hte */
1138         hte = &cm_core->connected_nodes;
1139
1140         /* walk list and find cm_node associated with this session ID */
1141         spin_lock_irqsave(&cm_core->ht_lock, flags);
1142         list_for_each_entry(cm_node, hte, list) {
1143                 /* compare quad, return node handle if a match */
1144                 nes_debug(NES_DBG_CM, "finding node %x:%x =? %x:%x ^ %x:%x =? %x:%x\n",
1145                           cm_node->loc_addr, cm_node->loc_port,
1146                           loc_addr, loc_port,
1147                           cm_node->rem_addr, cm_node->rem_port,
1148                           rem_addr, rem_port);
1149                 if ((cm_node->loc_addr == loc_addr) &&
1150                     (cm_node->loc_port == loc_port) &&
1151                     (cm_node->rem_addr == rem_addr) &&
1152                     (cm_node->rem_port == rem_port)) {
1153                         add_ref_cm_node(cm_node);
1154                         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1155                         return cm_node;
1156                 }
1157         }
1158         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1159
1160         /* no owner node */
1161         return NULL;
1162 }
1163
1164
1165 /**
1166  * find_listener - find a cm node listening on this addr-port pair
1167  */
1168 static struct nes_cm_listener *find_listener(struct nes_cm_core *cm_core,
1169                                              nes_addr_t dst_addr, u16 dst_port,
1170                                              enum nes_cm_listener_state listener_state)
1171 {
1172         unsigned long flags;
1173         struct nes_cm_listener *listen_node;
1174         nes_addr_t listen_addr;
1175         u16 listen_port;
1176
1177         /* walk list and find cm_node associated with this session ID */
1178         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
1179         list_for_each_entry(listen_node, &cm_core->listen_list.list, list) {
1180                 listen_addr = listen_node->loc_addr;
1181                 listen_port = listen_node->loc_port;
1182
1183                 /* compare node pair, return node handle if a match */
1184                 if (((listen_addr == dst_addr) ||
1185                      listen_addr == 0x00000000) &&
1186                     (listen_port == dst_port) &&
1187                     (listener_state & listen_node->listener_state)) {
1188                         atomic_inc(&listen_node->ref_count);
1189                         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1190                         return listen_node;
1191                 }
1192         }
1193         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1194
1195         /* no listener */
1196         return NULL;
1197 }
1198
1199 /**
1200  * add_hte_node - add a cm node to the hash table
1201  */
1202 static int add_hte_node(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
1203 {
1204         unsigned long flags;
1205         struct list_head *hte;
1206
1207         if (!cm_node || !cm_core)
1208                 return -EINVAL;
1209
1210         nes_debug(NES_DBG_CM, "Adding Node %p to Active Connection HT\n",
1211                   cm_node);
1212
1213         spin_lock_irqsave(&cm_core->ht_lock, flags);
1214
1215         /* get a handle on the hash table element (list head for this slot) */
1216         hte = &cm_core->connected_nodes;
1217         list_add_tail(&cm_node->list, hte);
1218         atomic_inc(&cm_core->ht_node_cnt);
1219
1220         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1221
1222         return 0;
1223 }
1224
1225
1226 /**
1227  * mini_cm_dec_refcnt_listen
1228  */
1229 static int mini_cm_dec_refcnt_listen(struct nes_cm_core *cm_core,
1230                                      struct nes_cm_listener *listener, int free_hanging_nodes)
1231 {
1232         int ret = -EINVAL;
1233         int err = 0;
1234         unsigned long flags;
1235         struct list_head *list_pos = NULL;
1236         struct list_head *list_temp = NULL;
1237         struct nes_cm_node *cm_node = NULL;
1238         struct list_head reset_list;
1239
1240         nes_debug(NES_DBG_CM, "attempting listener= %p free_nodes= %d, "
1241                   "refcnt=%d\n", listener, free_hanging_nodes,
1242                   atomic_read(&listener->ref_count));
1243         /* free non-accelerated child nodes for this listener */
1244         INIT_LIST_HEAD(&reset_list);
1245         if (free_hanging_nodes) {
1246                 spin_lock_irqsave(&cm_core->ht_lock, flags);
1247                 list_for_each_safe(list_pos, list_temp,
1248                                    &g_cm_core->connected_nodes) {
1249                         cm_node = container_of(list_pos, struct nes_cm_node,
1250                                                list);
1251                         if ((cm_node->listener == listener) &&
1252                             (!cm_node->accelerated)) {
1253                                 add_ref_cm_node(cm_node);
1254                                 list_add(&cm_node->reset_entry, &reset_list);
1255                         }
1256                 }
1257                 spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1258         }
1259
1260         list_for_each_safe(list_pos, list_temp, &reset_list) {
1261                 cm_node = container_of(list_pos, struct nes_cm_node,
1262                                        reset_entry);
1263                 {
1264                         struct nes_cm_node *loopback = cm_node->loopbackpartner;
1265                         enum nes_cm_node_state old_state;
1266                         if (NES_CM_STATE_FIN_WAIT1 <= cm_node->state) {
1267                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1268                         } else {
1269                                 if (!loopback) {
1270                                         cleanup_retrans_entry(cm_node);
1271                                         err = send_reset(cm_node, NULL);
1272                                         if (err) {
1273                                                 cm_node->state =
1274                                                         NES_CM_STATE_CLOSED;
1275                                                 WARN_ON(1);
1276                                         } else {
1277                                                 old_state = cm_node->state;
1278                                                 cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
1279                                                 if (old_state != NES_CM_STATE_MPAREQ_RCVD)
1280                                                         rem_ref_cm_node(
1281                                                                 cm_node->cm_core,
1282                                                                 cm_node);
1283                                         }
1284                                 } else {
1285                                         struct nes_cm_event event;
1286
1287                                         event.cm_node = loopback;
1288                                         event.cm_info.rem_addr =
1289                                                         loopback->rem_addr;
1290                                         event.cm_info.loc_addr =
1291                                                         loopback->loc_addr;
1292                                         event.cm_info.rem_port =
1293                                                         loopback->rem_port;
1294                                         event.cm_info.loc_port =
1295                                                          loopback->loc_port;
1296                                         event.cm_info.cm_id = loopback->cm_id;
1297                                         add_ref_cm_node(loopback);
1298                                         loopback->state = NES_CM_STATE_CLOSED;
1299                                         cm_event_connect_error(&event);
1300                                         cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
1301
1302                                         rem_ref_cm_node(cm_node->cm_core,
1303                                                          cm_node);
1304
1305                                 }
1306                         }
1307                 }
1308         }
1309
1310         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
1311         if (!atomic_dec_return(&listener->ref_count)) {
1312                 list_del(&listener->list);
1313
1314                 /* decrement our listen node count */
1315                 atomic_dec(&cm_core->listen_node_cnt);
1316
1317                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1318
1319                 if (listener->nesvnic) {
1320                         nes_manage_apbvt(listener->nesvnic,
1321                                 listener->loc_port,
1322                                 PCI_FUNC(listener->nesvnic->nesdev->pcidev->devfn),
1323                                 NES_MANAGE_APBVT_DEL);
1324
1325                         nes_debug(NES_DBG_NLMSG,
1326                                         "Delete APBVT loc_port = %04X\n",
1327                                         listener->loc_port);
1328                 }
1329
1330                 nes_debug(NES_DBG_CM, "destroying listener (%p)\n", listener);
1331
1332                 kfree(listener);
1333                 listener = NULL;
1334                 ret = 0;
1335                 atomic_inc(&cm_listens_destroyed);
1336         } else {
1337                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1338         }
1339         if (listener) {
1340                 if (atomic_read(&listener->pend_accepts_cnt) > 0)
1341                         nes_debug(NES_DBG_CM, "destroying listener (%p)"
1342                                   " with non-zero pending accepts=%u\n",
1343                                   listener, atomic_read(&listener->pend_accepts_cnt));
1344         }
1345
1346         return ret;
1347 }
1348
1349
1350 /**
1351  * mini_cm_del_listen
1352  */
1353 static int mini_cm_del_listen(struct nes_cm_core *cm_core,
1354                               struct nes_cm_listener *listener)
1355 {
1356         listener->listener_state = NES_CM_LISTENER_PASSIVE_STATE;
1357         listener->cm_id = NULL; /* going to be destroyed pretty soon */
1358         return mini_cm_dec_refcnt_listen(cm_core, listener, 1);
1359 }
1360
1361
1362 /**
1363  * mini_cm_accelerated
1364  */
1365 static inline int mini_cm_accelerated(struct nes_cm_core *cm_core,
1366                                       struct nes_cm_node *cm_node)
1367 {
1368         cm_node->accelerated = 1;
1369
1370         if (cm_node->accept_pend) {
1371                 BUG_ON(!cm_node->listener);
1372                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1373                 cm_node->accept_pend = 0;
1374                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1375         }
1376
1377         if (!timer_pending(&cm_core->tcp_timer))
1378                 mod_timer(&cm_core->tcp_timer, (jiffies + NES_SHORT_TIME));
1379
1380         return 0;
1381 }
1382
1383
1384 /**
1385  * nes_addr_resolve_neigh
1386  */
1387 static int nes_addr_resolve_neigh(struct nes_vnic *nesvnic, u32 dst_ip, int arpindex)
1388 {
1389         struct rtable *rt;
1390         struct neighbour *neigh;
1391         int rc = arpindex;
1392         struct net_device *netdev;
1393         struct nes_adapter *nesadapter = nesvnic->nesdev->nesadapter;
1394         __be32 dst_ipaddr = htonl(dst_ip);
1395
1396         rt = ip_route_output(&init_net, dst_ipaddr, nesvnic->local_ipaddr, 0, 0);
1397         if (IS_ERR(rt)) {
1398                 printk(KERN_ERR "%s: ip_route_output_key failed for 0x%08X\n",
1399                        __func__, dst_ip);
1400                 return rc;
1401         }
1402
1403         if (netif_is_bond_slave(nesvnic->netdev))
1404                 netdev = netdev_master_upper_dev_get(nesvnic->netdev);
1405         else
1406                 netdev = nesvnic->netdev;
1407
1408         neigh = dst_neigh_lookup(&rt->dst, &dst_ipaddr);
1409
1410         rcu_read_lock();
1411         if (neigh) {
1412                 if (neigh->nud_state & NUD_VALID) {
1413                         nes_debug(NES_DBG_CM, "Neighbor MAC address for 0x%08X"
1414                                   " is %pM, Gateway is 0x%08X \n", dst_ip,
1415                                   neigh->ha, ntohl(rt->rt_gateway));
1416
1417                         if (arpindex >= 0) {
1418                                 if (ether_addr_equal(nesadapter->arp_table[arpindex].mac_addr, neigh->ha)) {
1419                                         /* Mac address same as in nes_arp_table */
1420                                         goto out;
1421                                 }
1422
1423                                 nes_manage_arp_cache(nesvnic->netdev,
1424                                                      nesadapter->arp_table[arpindex].mac_addr,
1425                                                      dst_ip, NES_ARP_DELETE);
1426                         }
1427
1428                         nes_manage_arp_cache(nesvnic->netdev, neigh->ha,
1429                                              dst_ip, NES_ARP_ADD);
1430                         rc = nes_arp_table(nesvnic->nesdev, dst_ip, NULL,
1431                                            NES_ARP_RESOLVE);
1432                 } else {
1433                         neigh_event_send(neigh, NULL);
1434                 }
1435         }
1436 out:
1437         rcu_read_unlock();
1438
1439         if (neigh)
1440                 neigh_release(neigh);
1441
1442         ip_rt_put(rt);
1443         return rc;
1444 }
1445
1446 /**
1447  * make_cm_node - create a new instance of a cm node
1448  */
1449 static struct nes_cm_node *make_cm_node(struct nes_cm_core *cm_core,
1450                                         struct nes_vnic *nesvnic, struct nes_cm_info *cm_info,
1451                                         struct nes_cm_listener *listener)
1452 {
1453         struct nes_cm_node *cm_node;
1454         struct timespec ts;
1455         int oldarpindex = 0;
1456         int arpindex = 0;
1457         struct nes_device *nesdev;
1458         struct nes_adapter *nesadapter;
1459
1460         /* create an hte and cm_node for this instance */
1461         cm_node = kzalloc(sizeof(*cm_node), GFP_ATOMIC);
1462         if (!cm_node)
1463                 return NULL;
1464
1465         /* set our node specific transport info */
1466         if (listener) {
1467                 cm_node->loc_addr = listener->loc_addr;
1468                 cm_node->loc_port = listener->loc_port;
1469         } else {
1470                 cm_node->loc_addr = cm_info->loc_addr;
1471                 cm_node->loc_port = cm_info->loc_port;
1472         }
1473         cm_node->rem_addr = cm_info->rem_addr;
1474         cm_node->rem_port = cm_info->rem_port;
1475
1476         cm_node->mpa_frame_rev = mpa_version;
1477         cm_node->send_rdma0_op = SEND_RDMA_READ_ZERO;
1478         cm_node->mpav2_ird_ord = 0;
1479         cm_node->ird_size = 0;
1480         cm_node->ord_size = 0;
1481
1482         nes_debug(NES_DBG_CM, "Make node addresses : loc = %pI4:%x, rem = %pI4:%x\n",
1483                   &cm_node->loc_addr, cm_node->loc_port,
1484                   &cm_node->rem_addr, cm_node->rem_port);
1485         cm_node->listener = listener;
1486         if (listener)
1487                 cm_node->tos = listener->tos;
1488         cm_node->netdev = nesvnic->netdev;
1489         cm_node->cm_id = cm_info->cm_id;
1490         memcpy(cm_node->loc_mac, nesvnic->netdev->dev_addr, ETH_ALEN);
1491
1492         nes_debug(NES_DBG_CM, "listener=%p, cm_id=%p\n", cm_node->listener,
1493                   cm_node->cm_id);
1494
1495         spin_lock_init(&cm_node->retrans_list_lock);
1496
1497         cm_node->loopbackpartner = NULL;
1498         atomic_set(&cm_node->ref_count, 1);
1499         /* associate our parent CM core */
1500         cm_node->cm_core = cm_core;
1501         cm_node->tcp_cntxt.loc_id = NES_CM_DEF_LOCAL_ID;
1502         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
1503         cm_node->tcp_cntxt.rcv_wnd = NES_CM_DEFAULT_RCV_WND_SCALED >>
1504                                      NES_CM_DEFAULT_RCV_WND_SCALE;
1505         ts = current_kernel_time();
1506         cm_node->tcp_cntxt.loc_seq_num = htonl(ts.tv_nsec);
1507         cm_node->tcp_cntxt.mss = nesvnic->max_frame_size - sizeof(struct iphdr) -
1508                                  sizeof(struct tcphdr) - ETH_HLEN - VLAN_HLEN;
1509         cm_node->tcp_cntxt.rcv_nxt = 0;
1510         /* get a unique session ID , add thread_id to an upcounter to handle race */
1511         atomic_inc(&cm_core->node_cnt);
1512         cm_node->conn_type = cm_info->conn_type;
1513         cm_node->apbvt_set = 0;
1514         cm_node->accept_pend = 0;
1515
1516         cm_node->nesvnic = nesvnic;
1517         /* get some device handles, for arp lookup */
1518         nesdev = nesvnic->nesdev;
1519         nesadapter = nesdev->nesadapter;
1520
1521         cm_node->loopbackpartner = NULL;
1522
1523         /* get the mac addr for the remote node */
1524         oldarpindex = nes_arp_table(nesdev, cm_node->rem_addr,
1525                                     NULL, NES_ARP_RESOLVE);
1526         arpindex = nes_addr_resolve_neigh(nesvnic, cm_node->rem_addr,
1527                                           oldarpindex);
1528         if (arpindex < 0) {
1529                 kfree(cm_node);
1530                 return NULL;
1531         }
1532
1533         /* copy the mac addr to node context */
1534         memcpy(cm_node->rem_mac, nesadapter->arp_table[arpindex].mac_addr, ETH_ALEN);
1535         nes_debug(NES_DBG_CM, "Remote mac addr from arp table: %pM\n",
1536                   cm_node->rem_mac);
1537
1538         add_hte_node(cm_core, cm_node);
1539         atomic_inc(&cm_nodes_created);
1540
1541         return cm_node;
1542 }
1543
1544
1545 /**
1546  * add_ref_cm_node - destroy an instance of a cm node
1547  */
1548 static int add_ref_cm_node(struct nes_cm_node *cm_node)
1549 {
1550         atomic_inc(&cm_node->ref_count);
1551         return 0;
1552 }
1553
1554
1555 /**
1556  * rem_ref_cm_node - destroy an instance of a cm node
1557  */
1558 static int rem_ref_cm_node(struct nes_cm_core *cm_core,
1559                            struct nes_cm_node *cm_node)
1560 {
1561         unsigned long flags;
1562         struct nes_qp *nesqp;
1563
1564         if (!cm_node)
1565                 return -EINVAL;
1566
1567         spin_lock_irqsave(&cm_node->cm_core->ht_lock, flags);
1568         if (atomic_dec_return(&cm_node->ref_count)) {
1569                 spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1570                 return 0;
1571         }
1572         list_del(&cm_node->list);
1573         atomic_dec(&cm_core->ht_node_cnt);
1574         spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1575
1576         /* if the node is destroyed before connection was accelerated */
1577         if (!cm_node->accelerated && cm_node->accept_pend) {
1578                 BUG_ON(!cm_node->listener);
1579                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1580                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1581         }
1582         WARN_ON(cm_node->send_entry);
1583         if (cm_node->recv_entry)
1584                 handle_recv_entry(cm_node, 0);
1585         if (cm_node->listener) {
1586                 mini_cm_dec_refcnt_listen(cm_core, cm_node->listener, 0);
1587         } else {
1588                 if (cm_node->apbvt_set && cm_node->nesvnic) {
1589                         nes_manage_apbvt(cm_node->nesvnic, cm_node->loc_port,
1590                                          PCI_FUNC(cm_node->nesvnic->nesdev->pcidev->devfn),
1591                                          NES_MANAGE_APBVT_DEL);
1592                 }
1593                 nes_debug(NES_DBG_NLMSG, "Delete APBVT loc_port = %04X\n",
1594                           cm_node->loc_port);
1595         }
1596
1597         atomic_dec(&cm_core->node_cnt);
1598         atomic_inc(&cm_nodes_destroyed);
1599         nesqp = cm_node->nesqp;
1600         if (nesqp) {
1601                 nesqp->cm_node = NULL;
1602                 nes_rem_ref(&nesqp->ibqp);
1603                 cm_node->nesqp = NULL;
1604         }
1605
1606         kfree(cm_node);
1607         return 0;
1608 }
1609
1610 /**
1611  * process_options
1612  */
1613 static int process_options(struct nes_cm_node *cm_node, u8 *optionsloc,
1614                            u32 optionsize, u32 syn_packet)
1615 {
1616         u32 tmp;
1617         u32 offset = 0;
1618         union all_known_options *all_options;
1619         char got_mss_option = 0;
1620
1621         while (offset < optionsize) {
1622                 all_options = (union all_known_options *)(optionsloc + offset);
1623                 switch (all_options->as_base.optionnum) {
1624                 case OPTION_NUMBER_END:
1625                         offset = optionsize;
1626                         break;
1627                 case OPTION_NUMBER_NONE:
1628                         offset += 1;
1629                         continue;
1630                 case OPTION_NUMBER_MSS:
1631                         nes_debug(NES_DBG_CM, "%s: MSS Length: %d Offset: %d "
1632                                   "Size: %d\n", __func__,
1633                                   all_options->as_mss.length, offset, optionsize);
1634                         got_mss_option = 1;
1635                         if (all_options->as_mss.length != 4) {
1636                                 return 1;
1637                         } else {
1638                                 tmp = ntohs(all_options->as_mss.mss);
1639                                 if (tmp > 0 && tmp <
1640                                     cm_node->tcp_cntxt.mss)
1641                                         cm_node->tcp_cntxt.mss = tmp;
1642                         }
1643                         break;
1644                 case OPTION_NUMBER_WINDOW_SCALE:
1645                         cm_node->tcp_cntxt.snd_wscale =
1646                                 all_options->as_windowscale.shiftcount;
1647                         break;
1648                 default:
1649                         nes_debug(NES_DBG_CM, "TCP Option not understood: %x\n",
1650                                   all_options->as_base.optionnum);
1651                         break;
1652                 }
1653                 offset += all_options->as_base.length;
1654         }
1655         if ((!got_mss_option) && (syn_packet))
1656                 cm_node->tcp_cntxt.mss = NES_CM_DEFAULT_MSS;
1657         return 0;
1658 }
1659
1660 static void drop_packet(struct sk_buff *skb)
1661 {
1662         atomic_inc(&cm_accel_dropped_pkts);
1663         dev_kfree_skb_any(skb);
1664 }
1665
1666 static void handle_fin_pkt(struct nes_cm_node *cm_node)
1667 {
1668         nes_debug(NES_DBG_CM, "Received FIN, cm_node = %p, state = %u. "
1669                   "refcnt=%d\n", cm_node, cm_node->state,
1670                   atomic_read(&cm_node->ref_count));
1671         switch (cm_node->state) {
1672         case NES_CM_STATE_SYN_RCVD:
1673         case NES_CM_STATE_SYN_SENT:
1674         case NES_CM_STATE_ESTABLISHED:
1675         case NES_CM_STATE_MPAREJ_RCVD:
1676                 cm_node->tcp_cntxt.rcv_nxt++;
1677                 cleanup_retrans_entry(cm_node);
1678                 cm_node->state = NES_CM_STATE_LAST_ACK;
1679                 send_fin(cm_node, NULL);
1680                 break;
1681         case NES_CM_STATE_MPAREQ_SENT:
1682                 create_event(cm_node, NES_CM_EVENT_ABORTED);
1683                 cm_node->tcp_cntxt.rcv_nxt++;
1684                 cleanup_retrans_entry(cm_node);
1685                 cm_node->state = NES_CM_STATE_CLOSED;
1686                 add_ref_cm_node(cm_node);
1687                 send_reset(cm_node, NULL);
1688                 break;
1689         case NES_CM_STATE_FIN_WAIT1:
1690                 cm_node->tcp_cntxt.rcv_nxt++;
1691                 cleanup_retrans_entry(cm_node);
1692                 cm_node->state = NES_CM_STATE_CLOSING;
1693                 send_ack(cm_node, NULL);
1694                 /* Wait for ACK as this is simultaneous close..
1695                 * After we receive ACK, do not send anything..
1696                 * Just rm the node.. Done.. */
1697                 break;
1698         case NES_CM_STATE_FIN_WAIT2:
1699                 cm_node->tcp_cntxt.rcv_nxt++;
1700                 cleanup_retrans_entry(cm_node);
1701                 cm_node->state = NES_CM_STATE_TIME_WAIT;
1702                 send_ack(cm_node, NULL);
1703                 schedule_nes_timer(cm_node, NULL,  NES_TIMER_TYPE_CLOSE, 1, 0);
1704                 break;
1705         case NES_CM_STATE_TIME_WAIT:
1706                 cm_node->tcp_cntxt.rcv_nxt++;
1707                 cleanup_retrans_entry(cm_node);
1708                 cm_node->state = NES_CM_STATE_CLOSED;
1709                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1710                 break;
1711         case NES_CM_STATE_TSA:
1712         default:
1713                 nes_debug(NES_DBG_CM, "Error Rcvd FIN for node-%p state = %d\n",
1714                         cm_node, cm_node->state);
1715                 break;
1716         }
1717 }
1718
1719
1720 static void handle_rst_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1721         struct tcphdr *tcph)
1722 {
1723
1724         int     reset = 0;      /* whether to send reset in case of err.. */
1725         atomic_inc(&cm_resets_recvd);
1726         nes_debug(NES_DBG_CM, "Received Reset, cm_node = %p, state = %u."
1727                         " refcnt=%d\n", cm_node, cm_node->state,
1728                         atomic_read(&cm_node->ref_count));
1729         cleanup_retrans_entry(cm_node);
1730         switch (cm_node->state) {
1731         case NES_CM_STATE_SYN_SENT:
1732         case NES_CM_STATE_MPAREQ_SENT:
1733                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1734                         "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1735                         cm_node->listener, cm_node->state);
1736                 switch (cm_node->mpa_frame_rev) {
1737                 case IETF_MPA_V2:
1738                         cm_node->mpa_frame_rev = IETF_MPA_V1;
1739                         /* send a syn and goto syn sent state */
1740                         cm_node->state = NES_CM_STATE_SYN_SENT;
1741                         if (send_syn(cm_node, 0, NULL)) {
1742                                 active_open_err(cm_node, skb, reset);
1743                         }
1744                         break;
1745                 case IETF_MPA_V1:
1746                 default:
1747                         active_open_err(cm_node, skb, reset);
1748                         break;
1749                 }
1750                 break;
1751         case NES_CM_STATE_MPAREQ_RCVD:
1752                 atomic_inc(&cm_node->passive_state);
1753                 dev_kfree_skb_any(skb);
1754                 break;
1755         case NES_CM_STATE_ESTABLISHED:
1756         case NES_CM_STATE_SYN_RCVD:
1757         case NES_CM_STATE_LISTENING:
1758                 nes_debug(NES_DBG_CM, "Bad state %s[%u]\n", __func__, __LINE__);
1759                 passive_open_err(cm_node, skb, reset);
1760                 break;
1761         case NES_CM_STATE_TSA:
1762                 active_open_err(cm_node, skb, reset);
1763                 break;
1764         case NES_CM_STATE_CLOSED:
1765                 drop_packet(skb);
1766                 break;
1767         case NES_CM_STATE_FIN_WAIT2:
1768         case NES_CM_STATE_FIN_WAIT1:
1769         case NES_CM_STATE_LAST_ACK:
1770                 cm_node->cm_id->rem_ref(cm_node->cm_id);
1771         case NES_CM_STATE_TIME_WAIT:
1772                 cm_node->state = NES_CM_STATE_CLOSED;
1773                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1774                 drop_packet(skb);
1775                 break;
1776         default:
1777                 drop_packet(skb);
1778                 break;
1779         }
1780 }
1781
1782
1783 static void handle_rcv_mpa(struct nes_cm_node *cm_node, struct sk_buff *skb)
1784 {
1785         int ret = 0;
1786         int datasize = skb->len;
1787         u8 *dataloc = skb->data;
1788
1789         enum nes_cm_event_type type = NES_CM_EVENT_UNKNOWN;
1790         u32 res_type;
1791
1792         ret = parse_mpa(cm_node, dataloc, &res_type, datasize);
1793         if (ret) {
1794                 nes_debug(NES_DBG_CM, "didn't like MPA Request\n");
1795                 if (cm_node->state == NES_CM_STATE_MPAREQ_SENT) {
1796                         nes_debug(NES_DBG_CM, "%s[%u] create abort for "
1797                                   "cm_node=%p listener=%p state=%d\n", __func__,
1798                                   __LINE__, cm_node, cm_node->listener,
1799                                   cm_node->state);
1800                         active_open_err(cm_node, skb, 1);
1801                 } else {
1802                         passive_open_err(cm_node, skb, 1);
1803                 }
1804                 return;
1805         }
1806
1807         switch (cm_node->state) {
1808         case NES_CM_STATE_ESTABLISHED:
1809                 if (res_type == NES_MPA_REQUEST_REJECT)
1810                         /*BIG problem as we are receiving the MPA.. So should
1811                          * not be REJECT.. This is Passive Open.. We can
1812                          * only receive it Reject for Active Open...*/
1813                         WARN_ON(1);
1814                 cm_node->state = NES_CM_STATE_MPAREQ_RCVD;
1815                 type = NES_CM_EVENT_MPA_REQ;
1816                 atomic_set(&cm_node->passive_state,
1817                            NES_PASSIVE_STATE_INDICATED);
1818                 break;
1819         case NES_CM_STATE_MPAREQ_SENT:
1820                 cleanup_retrans_entry(cm_node);
1821                 if (res_type == NES_MPA_REQUEST_REJECT) {
1822                         type = NES_CM_EVENT_MPA_REJECT;
1823                         cm_node->state = NES_CM_STATE_MPAREJ_RCVD;
1824                 } else {
1825                         type = NES_CM_EVENT_CONNECTED;
1826                         cm_node->state = NES_CM_STATE_TSA;
1827                 }
1828                 send_ack(cm_node, NULL);
1829                 break;
1830         default:
1831                 WARN_ON(1);
1832                 break;
1833         }
1834         dev_kfree_skb_any(skb);
1835         create_event(cm_node, type);
1836 }
1837
1838 static void indicate_pkt_err(struct nes_cm_node *cm_node, struct sk_buff *skb)
1839 {
1840         switch (cm_node->state) {
1841         case NES_CM_STATE_SYN_SENT:
1842         case NES_CM_STATE_MPAREQ_SENT:
1843                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1844                           "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1845                           cm_node->listener, cm_node->state);
1846                 active_open_err(cm_node, skb, 1);
1847                 break;
1848         case NES_CM_STATE_ESTABLISHED:
1849         case NES_CM_STATE_SYN_RCVD:
1850                 passive_open_err(cm_node, skb, 1);
1851                 break;
1852         case NES_CM_STATE_TSA:
1853         default:
1854                 drop_packet(skb);
1855         }
1856 }
1857
1858 static int check_syn(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1859                      struct sk_buff *skb)
1860 {
1861         int err;
1862
1863         err = ((ntohl(tcph->ack_seq) == cm_node->tcp_cntxt.loc_seq_num)) ? 0 : 1;
1864         if (err)
1865                 active_open_err(cm_node, skb, 1);
1866
1867         return err;
1868 }
1869
1870 static int check_seq(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1871                      struct sk_buff *skb)
1872 {
1873         int err = 0;
1874         u32 seq;
1875         u32 ack_seq;
1876         u32 loc_seq_num = cm_node->tcp_cntxt.loc_seq_num;
1877         u32 rcv_nxt = cm_node->tcp_cntxt.rcv_nxt;
1878         u32 rcv_wnd;
1879
1880         seq = ntohl(tcph->seq);
1881         ack_seq = ntohl(tcph->ack_seq);
1882         rcv_wnd = cm_node->tcp_cntxt.rcv_wnd;
1883         if (ack_seq != loc_seq_num)
1884                 err = 1;
1885         else if (!between(seq, rcv_nxt, (rcv_nxt + rcv_wnd)))
1886                 err = 1;
1887         if (err) {
1888                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1889                           "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1890                           cm_node->listener, cm_node->state);
1891                 indicate_pkt_err(cm_node, skb);
1892                 nes_debug(NES_DBG_CM, "seq ERROR cm_node =%p seq=0x%08X "
1893                           "rcv_nxt=0x%08X rcv_wnd=0x%x\n", cm_node, seq, rcv_nxt,
1894                           rcv_wnd);
1895         }
1896         return err;
1897 }
1898
1899 /*
1900  * handle_syn_pkt() is for Passive node. The syn packet is received when a node
1901  * is created with a listener or it may comein as rexmitted packet which in
1902  * that case will be just dropped.
1903  */
1904 static void handle_syn_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1905                            struct tcphdr *tcph)
1906 {
1907         int ret;
1908         u32 inc_sequence;
1909         int optionsize;
1910
1911         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1912         skb_trim(skb, 0);
1913         inc_sequence = ntohl(tcph->seq);
1914
1915         switch (cm_node->state) {
1916         case NES_CM_STATE_SYN_SENT:
1917         case NES_CM_STATE_MPAREQ_SENT:
1918                 /* Rcvd syn on active open connection*/
1919                 active_open_err(cm_node, skb, 1);
1920                 break;
1921         case NES_CM_STATE_LISTENING:
1922                 /* Passive OPEN */
1923                 if (atomic_read(&cm_node->listener->pend_accepts_cnt) >
1924                     cm_node->listener->backlog) {
1925                         nes_debug(NES_DBG_CM, "drop syn due to backlog "
1926                                   "pressure \n");
1927                         cm_backlog_drops++;
1928                         passive_open_err(cm_node, skb, 0);
1929                         break;
1930                 }
1931                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize,
1932                                          1);
1933                 if (ret) {
1934                         passive_open_err(cm_node, skb, 0);
1935                         /* drop pkt */
1936                         break;
1937                 }
1938                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1939                 BUG_ON(cm_node->send_entry);
1940                 cm_node->accept_pend = 1;
1941                 atomic_inc(&cm_node->listener->pend_accepts_cnt);
1942
1943                 cm_node->state = NES_CM_STATE_SYN_RCVD;
1944                 send_syn(cm_node, 1, skb);
1945                 break;
1946         case NES_CM_STATE_CLOSED:
1947                 cleanup_retrans_entry(cm_node);
1948                 add_ref_cm_node(cm_node);
1949                 send_reset(cm_node, skb);
1950                 break;
1951         case NES_CM_STATE_TSA:
1952         case NES_CM_STATE_ESTABLISHED:
1953         case NES_CM_STATE_FIN_WAIT1:
1954         case NES_CM_STATE_FIN_WAIT2:
1955         case NES_CM_STATE_MPAREQ_RCVD:
1956         case NES_CM_STATE_LAST_ACK:
1957         case NES_CM_STATE_CLOSING:
1958         case NES_CM_STATE_UNKNOWN:
1959         default:
1960                 drop_packet(skb);
1961                 break;
1962         }
1963 }
1964
1965 static void handle_synack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1966                               struct tcphdr *tcph)
1967 {
1968         int ret;
1969         u32 inc_sequence;
1970         int optionsize;
1971
1972         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1973         skb_trim(skb, 0);
1974         inc_sequence = ntohl(tcph->seq);
1975         switch (cm_node->state) {
1976         case NES_CM_STATE_SYN_SENT:
1977                 cleanup_retrans_entry(cm_node);
1978                 /* active open */
1979                 if (check_syn(cm_node, tcph, skb))
1980                         return;
1981                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
1982                 /* setup options */
1983                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 0);
1984                 if (ret) {
1985                         nes_debug(NES_DBG_CM, "cm_node=%p tcp_options failed\n",
1986                                   cm_node);
1987                         break;
1988                 }
1989                 cleanup_retrans_entry(cm_node);
1990                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1991                 send_mpa_request(cm_node, skb);
1992                 cm_node->state = NES_CM_STATE_MPAREQ_SENT;
1993                 break;
1994         case NES_CM_STATE_MPAREQ_RCVD:
1995                 /* passive open, so should not be here */
1996                 passive_open_err(cm_node, skb, 1);
1997                 break;
1998         case NES_CM_STATE_LISTENING:
1999                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
2000                 cleanup_retrans_entry(cm_node);
2001                 cm_node->state = NES_CM_STATE_CLOSED;
2002                 send_reset(cm_node, skb);
2003                 break;
2004         case NES_CM_STATE_CLOSED:
2005                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
2006                 cleanup_retrans_entry(cm_node);
2007                 add_ref_cm_node(cm_node);
2008                 send_reset(cm_node, skb);
2009                 break;
2010         case NES_CM_STATE_ESTABLISHED:
2011         case NES_CM_STATE_FIN_WAIT1:
2012         case NES_CM_STATE_FIN_WAIT2:
2013         case NES_CM_STATE_LAST_ACK:
2014         case NES_CM_STATE_TSA:
2015         case NES_CM_STATE_CLOSING:
2016         case NES_CM_STATE_UNKNOWN:
2017         case NES_CM_STATE_MPAREQ_SENT:
2018         default:
2019                 drop_packet(skb);
2020                 break;
2021         }
2022 }
2023
2024 static int handle_ack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
2025                           struct tcphdr *tcph)
2026 {
2027         int datasize = 0;
2028         u32 inc_sequence;
2029         int ret = 0;
2030         int optionsize;
2031
2032         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
2033
2034         if (check_seq(cm_node, tcph, skb))
2035                 return -EINVAL;
2036
2037         skb_pull(skb, tcph->doff << 2);
2038         inc_sequence = ntohl(tcph->seq);
2039         datasize = skb->len;
2040         switch (cm_node->state) {
2041         case NES_CM_STATE_SYN_RCVD:
2042                 /* Passive OPEN */
2043                 cleanup_retrans_entry(cm_node);
2044                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 1);
2045                 if (ret)
2046                         break;
2047                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
2048                 cm_node->state = NES_CM_STATE_ESTABLISHED;
2049                 if (datasize) {
2050                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2051                         handle_rcv_mpa(cm_node, skb);
2052                 } else { /* rcvd ACK only */
2053                         dev_kfree_skb_any(skb);
2054                 }
2055                 break;
2056         case NES_CM_STATE_ESTABLISHED:
2057                 /* Passive OPEN */
2058                 cleanup_retrans_entry(cm_node);
2059                 if (datasize) {
2060                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2061                         handle_rcv_mpa(cm_node, skb);
2062                 } else {
2063                         drop_packet(skb);
2064                 }
2065                 break;
2066         case NES_CM_STATE_MPAREQ_SENT:
2067                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
2068                 if (datasize) {
2069                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2070                         handle_rcv_mpa(cm_node, skb);
2071                 } else { /* Could be just an ack pkt.. */
2072                         dev_kfree_skb_any(skb);
2073                 }
2074                 break;
2075         case NES_CM_STATE_LISTENING:
2076                 cleanup_retrans_entry(cm_node);
2077                 cm_node->state = NES_CM_STATE_CLOSED;
2078                 send_reset(cm_node, skb);
2079                 break;
2080         case NES_CM_STATE_CLOSED:
2081                 cleanup_retrans_entry(cm_node);
2082                 add_ref_cm_node(cm_node);
2083                 send_reset(cm_node, skb);
2084                 break;
2085         case NES_CM_STATE_LAST_ACK:
2086         case NES_CM_STATE_CLOSING:
2087                 cleanup_retrans_entry(cm_node);
2088                 cm_node->state = NES_CM_STATE_CLOSED;
2089                 cm_node->cm_id->rem_ref(cm_node->cm_id);
2090                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2091                 drop_packet(skb);
2092                 break;
2093         case NES_CM_STATE_FIN_WAIT1:
2094                 cleanup_retrans_entry(cm_node);
2095                 drop_packet(skb);
2096                 cm_node->state = NES_CM_STATE_FIN_WAIT2;
2097                 break;
2098         case NES_CM_STATE_SYN_SENT:
2099         case NES_CM_STATE_FIN_WAIT2:
2100         case NES_CM_STATE_TSA:
2101         case NES_CM_STATE_MPAREQ_RCVD:
2102         case NES_CM_STATE_UNKNOWN:
2103         default:
2104                 cleanup_retrans_entry(cm_node);
2105                 drop_packet(skb);
2106                 break;
2107         }
2108         return ret;
2109 }
2110
2111
2112
2113 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph,
2114                               struct sk_buff *skb, int optionsize, int passive)
2115 {
2116         u8 *optionsloc = (u8 *)&tcph[1];
2117
2118         if (optionsize) {
2119                 if (process_options(cm_node, optionsloc, optionsize,
2120                                     (u32)tcph->syn)) {
2121                         nes_debug(NES_DBG_CM, "%s: Node %p, Sending RESET\n",
2122                                   __func__, cm_node);
2123                         if (passive)
2124                                 passive_open_err(cm_node, skb, 1);
2125                         else
2126                                 active_open_err(cm_node, skb, 1);
2127                         return 1;
2128                 }
2129         }
2130
2131         cm_node->tcp_cntxt.snd_wnd = ntohs(tcph->window) <<
2132                                      cm_node->tcp_cntxt.snd_wscale;
2133
2134         if (cm_node->tcp_cntxt.snd_wnd > cm_node->tcp_cntxt.max_snd_wnd)
2135                 cm_node->tcp_cntxt.max_snd_wnd = cm_node->tcp_cntxt.snd_wnd;
2136         return 0;
2137 }
2138
2139 /*
2140  * active_open_err() will send reset() if flag set..
2141  * It will also send ABORT event.
2142  */
2143 static void active_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
2144                             int reset)
2145 {
2146         cleanup_retrans_entry(cm_node);
2147         if (reset) {
2148                 nes_debug(NES_DBG_CM, "ERROR active err called for cm_node=%p, "
2149                           "state=%d\n", cm_node, cm_node->state);
2150                 add_ref_cm_node(cm_node);
2151                 send_reset(cm_node, skb);
2152         } else {
2153                 dev_kfree_skb_any(skb);
2154         }
2155
2156         cm_node->state = NES_CM_STATE_CLOSED;
2157         create_event(cm_node, NES_CM_EVENT_ABORTED);
2158 }
2159
2160 /*
2161  * passive_open_err() will either do a reset() or will free up the skb and
2162  * remove the cm_node.
2163  */
2164 static void passive_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
2165                              int reset)
2166 {
2167         cleanup_retrans_entry(cm_node);
2168         cm_node->state = NES_CM_STATE_CLOSED;
2169         if (reset) {
2170                 nes_debug(NES_DBG_CM, "passive_open_err sending RST for "
2171                           "cm_node=%p state =%d\n", cm_node, cm_node->state);
2172                 send_reset(cm_node, skb);
2173         } else {
2174                 dev_kfree_skb_any(skb);
2175                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2176         }
2177 }
2178
2179 /*
2180  * free_retrans_entry() routines assumes that the retrans_list_lock has
2181  * been acquired before calling.
2182  */
2183 static void free_retrans_entry(struct nes_cm_node *cm_node)
2184 {
2185         struct nes_timer_entry *send_entry;
2186
2187         send_entry = cm_node->send_entry;
2188         if (send_entry) {
2189                 cm_node->send_entry = NULL;
2190                 dev_kfree_skb_any(send_entry->skb);
2191                 kfree(send_entry);
2192                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2193         }
2194 }
2195
2196 static void cleanup_retrans_entry(struct nes_cm_node *cm_node)
2197 {
2198         unsigned long flags;
2199
2200         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
2201         free_retrans_entry(cm_node);
2202         spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
2203 }
2204
2205 /**
2206  * process_packet
2207  * Returns skb if to be freed, else it will return NULL if already used..
2208  */
2209 static void process_packet(struct nes_cm_node *cm_node, struct sk_buff *skb,
2210                            struct nes_cm_core *cm_core)
2211 {
2212         enum nes_tcpip_pkt_type pkt_type = NES_PKT_TYPE_UNKNOWN;
2213         struct tcphdr *tcph = tcp_hdr(skb);
2214         u32 fin_set = 0;
2215         int ret = 0;
2216
2217         skb_pull(skb, ip_hdr(skb)->ihl << 2);
2218
2219         nes_debug(NES_DBG_CM, "process_packet: cm_node=%p state =%d syn=%d "
2220                   "ack=%d rst=%d fin=%d\n", cm_node, cm_node->state, tcph->syn,
2221                   tcph->ack, tcph->rst, tcph->fin);
2222
2223         if (tcph->rst) {
2224                 pkt_type = NES_PKT_TYPE_RST;
2225         } else if (tcph->syn) {
2226                 pkt_type = NES_PKT_TYPE_SYN;
2227                 if (tcph->ack)
2228                         pkt_type = NES_PKT_TYPE_SYNACK;
2229         } else if (tcph->ack) {
2230                 pkt_type = NES_PKT_TYPE_ACK;
2231         }
2232         if (tcph->fin)
2233                 fin_set = 1;
2234
2235         switch (pkt_type) {
2236         case NES_PKT_TYPE_SYN:
2237                 handle_syn_pkt(cm_node, skb, tcph);
2238                 break;
2239         case NES_PKT_TYPE_SYNACK:
2240                 handle_synack_pkt(cm_node, skb, tcph);
2241                 break;
2242         case NES_PKT_TYPE_ACK:
2243                 ret = handle_ack_pkt(cm_node, skb, tcph);
2244                 if (fin_set && !ret)
2245                         handle_fin_pkt(cm_node);
2246                 break;
2247         case NES_PKT_TYPE_RST:
2248                 handle_rst_pkt(cm_node, skb, tcph);
2249                 break;
2250         default:
2251                 if ((fin_set) && (!check_seq(cm_node, tcph, skb)))
2252                         handle_fin_pkt(cm_node);
2253                 drop_packet(skb);
2254                 break;
2255         }
2256 }
2257
2258 /**
2259  * mini_cm_listen - create a listen node with params
2260  */
2261 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *cm_core,
2262                         struct nes_vnic *nesvnic, struct nes_cm_info *cm_info)
2263 {
2264         struct nes_cm_listener *listener;
2265         unsigned long flags;
2266
2267         nes_debug(NES_DBG_CM, "Search for 0x%08x : 0x%04x\n",
2268                   cm_info->loc_addr, cm_info->loc_port);
2269
2270         /* cannot have multiple matching listeners */
2271         listener = find_listener(cm_core, cm_info->loc_addr, cm_info->loc_port,
2272                                 NES_CM_LISTENER_EITHER_STATE);
2273
2274         if (listener && listener->listener_state == NES_CM_LISTENER_ACTIVE_STATE) {
2275                 /* find automatically incs ref count ??? */
2276                 atomic_dec(&listener->ref_count);
2277                 nes_debug(NES_DBG_CM, "Not creating listener since it already exists\n");
2278                 return NULL;
2279         }
2280
2281         if (!listener) {
2282                 /* create a CM listen node (1/2 node to compare incoming traffic to) */
2283                 listener = kzalloc(sizeof(*listener), GFP_ATOMIC);
2284                 if (!listener)
2285                         return NULL;
2286
2287                 listener->loc_addr = cm_info->loc_addr;
2288                 listener->loc_port = cm_info->loc_port;
2289                 listener->reused_node = 0;
2290
2291                 atomic_set(&listener->ref_count, 1);
2292         }
2293         /* pasive case */
2294         /* find already inc'ed the ref count */
2295         else {
2296                 listener->reused_node = 1;
2297         }
2298
2299         listener->cm_id = cm_info->cm_id;
2300         atomic_set(&listener->pend_accepts_cnt, 0);
2301         listener->cm_core = cm_core;
2302         listener->nesvnic = nesvnic;
2303         atomic_inc(&cm_core->node_cnt);
2304
2305         listener->conn_type = cm_info->conn_type;
2306         listener->backlog = cm_info->backlog;
2307         listener->listener_state = NES_CM_LISTENER_ACTIVE_STATE;
2308
2309         if (!listener->reused_node) {
2310                 spin_lock_irqsave(&cm_core->listen_list_lock, flags);
2311                 list_add(&listener->list, &cm_core->listen_list.list);
2312                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
2313                 atomic_inc(&cm_core->listen_node_cnt);
2314         }
2315
2316         nes_debug(NES_DBG_CM, "Api - listen(): addr=0x%08X, port=0x%04x,"
2317                   " listener = %p, backlog = %d, cm_id = %p.\n",
2318                   cm_info->loc_addr, cm_info->loc_port,
2319                   listener, listener->backlog, listener->cm_id);
2320
2321         return listener;
2322 }
2323
2324
2325 /**
2326  * mini_cm_connect - make a connection node with params
2327  */
2328 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *cm_core,
2329                                            struct nes_vnic *nesvnic, u16 private_data_len,
2330                                            void *private_data, struct nes_cm_info *cm_info)
2331 {
2332         int ret = 0;
2333         struct nes_cm_node *cm_node;
2334         struct nes_cm_listener *loopbackremotelistener;
2335         struct nes_cm_node *loopbackremotenode;
2336         struct nes_cm_info loopback_cm_info;
2337         u8 *start_buff;
2338
2339         /* create a CM connection node */
2340         cm_node = make_cm_node(cm_core, nesvnic, cm_info, NULL);
2341         if (!cm_node)
2342                 return NULL;
2343
2344         /* set our node side to client (active) side */
2345         cm_node->tcp_cntxt.client = 1;
2346         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
2347
2348         if (cm_info->loc_addr == cm_info->rem_addr) {
2349                 loopbackremotelistener = find_listener(cm_core,
2350                         cm_node->loc_addr, cm_node->rem_port,
2351                         NES_CM_LISTENER_ACTIVE_STATE);
2352                 if (loopbackremotelistener == NULL) {
2353                         create_event(cm_node, NES_CM_EVENT_ABORTED);
2354                 } else {
2355                         loopback_cm_info = *cm_info;
2356                         loopback_cm_info.loc_port = cm_info->rem_port;
2357                         loopback_cm_info.rem_port = cm_info->loc_port;
2358                         loopback_cm_info.loc_port =
2359                                 cm_info->rem_port;
2360                         loopback_cm_info.rem_port =
2361                                 cm_info->loc_port;
2362                         loopback_cm_info.cm_id = loopbackremotelistener->cm_id;
2363                         loopbackremotenode = make_cm_node(cm_core, nesvnic,
2364                                                           &loopback_cm_info, loopbackremotelistener);
2365                         if (!loopbackremotenode) {
2366                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2367                                 return NULL;
2368                         }
2369                         atomic_inc(&cm_loopbacks);
2370                         loopbackremotenode->loopbackpartner = cm_node;
2371                         loopbackremotenode->tcp_cntxt.rcv_wscale =
2372                                 NES_CM_DEFAULT_RCV_WND_SCALE;
2373                         cm_node->loopbackpartner = loopbackremotenode;
2374                         memcpy(loopbackremotenode->mpa_frame_buf, private_data,
2375                                private_data_len);
2376                         loopbackremotenode->mpa_frame_size = private_data_len;
2377
2378                         /* we are done handling this state. */
2379                         /* set node to a TSA state */
2380                         cm_node->state = NES_CM_STATE_TSA;
2381                         cm_node->tcp_cntxt.rcv_nxt =
2382                                 loopbackremotenode->tcp_cntxt.loc_seq_num;
2383                         loopbackremotenode->tcp_cntxt.rcv_nxt =
2384                                 cm_node->tcp_cntxt.loc_seq_num;
2385                         cm_node->tcp_cntxt.max_snd_wnd =
2386                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2387                         loopbackremotenode->tcp_cntxt.max_snd_wnd =
2388                                 cm_node->tcp_cntxt.rcv_wnd;
2389                         cm_node->tcp_cntxt.snd_wnd =
2390                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2391                         loopbackremotenode->tcp_cntxt.snd_wnd =
2392                                 cm_node->tcp_cntxt.rcv_wnd;
2393                         cm_node->tcp_cntxt.snd_wscale =
2394                                 loopbackremotenode->tcp_cntxt.rcv_wscale;
2395                         loopbackremotenode->tcp_cntxt.snd_wscale =
2396                                 cm_node->tcp_cntxt.rcv_wscale;
2397                         loopbackremotenode->state = NES_CM_STATE_MPAREQ_RCVD;
2398                         create_event(loopbackremotenode, NES_CM_EVENT_MPA_REQ);
2399                 }
2400                 return cm_node;
2401         }
2402
2403         start_buff = &cm_node->mpa_frame_buf[0] + sizeof(struct ietf_mpa_v2);
2404         cm_node->mpa_frame_size = private_data_len;
2405
2406         memcpy(start_buff, private_data, private_data_len);
2407
2408         /* send a syn and goto syn sent state */
2409         cm_node->state = NES_CM_STATE_SYN_SENT;
2410         ret = send_syn(cm_node, 0, NULL);
2411
2412         if (ret) {
2413                 /* error in sending the syn free up the cm_node struct */
2414                 nes_debug(NES_DBG_CM, "Api - connect() FAILED: dest "
2415                           "addr=0x%08X, port=0x%04x, cm_node=%p, cm_id = %p.\n",
2416                           cm_node->rem_addr, cm_node->rem_port, cm_node,
2417                           cm_node->cm_id);
2418                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2419                 cm_node = NULL;
2420         }
2421
2422         if (cm_node) {
2423                 nes_debug(NES_DBG_CM, "Api - connect(): dest addr=0x%08X,"
2424                           "port=0x%04x, cm_node=%p, cm_id = %p.\n",
2425                           cm_node->rem_addr, cm_node->rem_port, cm_node,
2426                           cm_node->cm_id);
2427         }
2428
2429         return cm_node;
2430 }
2431
2432
2433 /**
2434  * mini_cm_accept - accept a connection
2435  * This function is never called
2436  */
2437 static int mini_cm_accept(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2438 {
2439         return 0;
2440 }
2441
2442
2443 /**
2444  * mini_cm_reject - reject and teardown a connection
2445  */
2446 static int mini_cm_reject(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2447 {
2448         int ret = 0;
2449         int err = 0;
2450         int passive_state;
2451         struct nes_cm_event event;
2452         struct iw_cm_id *cm_id = cm_node->cm_id;
2453         struct nes_cm_node *loopback = cm_node->loopbackpartner;
2454
2455         nes_debug(NES_DBG_CM, "%s cm_node=%p type=%d state=%d\n",
2456                   __func__, cm_node, cm_node->tcp_cntxt.client, cm_node->state);
2457
2458         if (cm_node->tcp_cntxt.client)
2459                 return ret;
2460         cleanup_retrans_entry(cm_node);
2461
2462         if (!loopback) {
2463                 passive_state = atomic_add_return(1, &cm_node->passive_state);
2464                 if (passive_state == NES_SEND_RESET_EVENT) {
2465                         cm_node->state = NES_CM_STATE_CLOSED;
2466                         rem_ref_cm_node(cm_core, cm_node);
2467                 } else {
2468                         if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2469                                 rem_ref_cm_node(cm_core, cm_node);
2470                         } else {
2471                                 ret = send_mpa_reject(cm_node);
2472                                 if (ret) {
2473                                         cm_node->state = NES_CM_STATE_CLOSED;
2474                                         err = send_reset(cm_node, NULL);
2475                                         if (err)
2476                                                 WARN_ON(1);
2477                                 } else {
2478                                         cm_id->add_ref(cm_id);
2479                                 }
2480                         }
2481                 }
2482         } else {
2483                 cm_node->cm_id = NULL;
2484                 if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2485                         rem_ref_cm_node(cm_core, cm_node);
2486                         rem_ref_cm_node(cm_core, loopback);
2487                 } else {
2488                         event.cm_node = loopback;
2489                         event.cm_info.rem_addr = loopback->rem_addr;
2490                         event.cm_info.loc_addr = loopback->loc_addr;
2491                         event.cm_info.rem_port = loopback->rem_port;
2492                         event.cm_info.loc_port = loopback->loc_port;
2493                         event.cm_info.cm_id = loopback->cm_id;
2494                         cm_event_mpa_reject(&event);
2495                         rem_ref_cm_node(cm_core, cm_node);
2496                         loopback->state = NES_CM_STATE_CLOSING;
2497
2498                         cm_id = loopback->cm_id;
2499                         rem_ref_cm_node(cm_core, loopback);
2500                         cm_id->rem_ref(cm_id);
2501                 }
2502         }
2503
2504         return ret;
2505 }
2506
2507
2508 /**
2509  * mini_cm_close
2510  */
2511 static int mini_cm_close(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2512 {
2513         int ret = 0;
2514
2515         if (!cm_core || !cm_node)
2516                 return -EINVAL;
2517
2518         switch (cm_node->state) {
2519         case NES_CM_STATE_SYN_RCVD:
2520         case NES_CM_STATE_SYN_SENT:
2521         case NES_CM_STATE_ONE_SIDE_ESTABLISHED:
2522         case NES_CM_STATE_ESTABLISHED:
2523         case NES_CM_STATE_ACCEPTING:
2524         case NES_CM_STATE_MPAREQ_SENT:
2525         case NES_CM_STATE_MPAREQ_RCVD:
2526                 cleanup_retrans_entry(cm_node);
2527                 send_reset(cm_node, NULL);
2528                 break;
2529         case NES_CM_STATE_CLOSE_WAIT:
2530                 cm_node->state = NES_CM_STATE_LAST_ACK;
2531                 send_fin(cm_node, NULL);
2532                 break;
2533         case NES_CM_STATE_FIN_WAIT1:
2534         case NES_CM_STATE_FIN_WAIT2:
2535         case NES_CM_STATE_LAST_ACK:
2536         case NES_CM_STATE_TIME_WAIT:
2537         case NES_CM_STATE_CLOSING:
2538                 ret = -1;
2539                 break;
2540         case NES_CM_STATE_LISTENING:
2541                 cleanup_retrans_entry(cm_node);
2542                 send_reset(cm_node, NULL);
2543                 break;
2544         case NES_CM_STATE_MPAREJ_RCVD:
2545         case NES_CM_STATE_UNKNOWN:
2546         case NES_CM_STATE_INITED:
2547         case NES_CM_STATE_CLOSED:
2548         case NES_CM_STATE_LISTENER_DESTROYED:
2549                 ret = rem_ref_cm_node(cm_core, cm_node);
2550                 break;
2551         case NES_CM_STATE_TSA:
2552                 if (cm_node->send_entry)
2553                         printk(KERN_ERR "ERROR Close got called from STATE_TSA "
2554                                "send_entry=%p\n", cm_node->send_entry);
2555                 ret = rem_ref_cm_node(cm_core, cm_node);
2556                 break;
2557         }
2558         return ret;
2559 }
2560
2561
2562 /**
2563  * recv_pkt - recv an ETHERNET packet, and process it through CM
2564  * node state machine
2565  */
2566 static int mini_cm_recv_pkt(struct nes_cm_core *cm_core,
2567                             struct nes_vnic *nesvnic, struct sk_buff *skb)
2568 {
2569         struct nes_cm_node *cm_node = NULL;
2570         struct nes_cm_listener *listener = NULL;
2571         struct iphdr *iph;
2572         struct tcphdr *tcph;
2573         struct nes_cm_info nfo;
2574         int skb_handled = 1;
2575         __be32 tmp_daddr, tmp_saddr;
2576
2577         if (!skb)
2578                 return 0;
2579         if (skb->len < sizeof(struct iphdr) + sizeof(struct tcphdr))
2580                 return 0;
2581
2582         iph = (struct iphdr *)skb->data;
2583         tcph = (struct tcphdr *)(skb->data + sizeof(struct iphdr));
2584
2585         nfo.loc_addr = ntohl(iph->daddr);
2586         nfo.loc_port = ntohs(tcph->dest);
2587         nfo.rem_addr = ntohl(iph->saddr);
2588         nfo.rem_port = ntohs(tcph->source);
2589
2590         tmp_daddr = cpu_to_be32(iph->daddr);
2591         tmp_saddr = cpu_to_be32(iph->saddr);
2592
2593         nes_debug(NES_DBG_CM, "Received packet: dest=%pI4:0x%04X src=%pI4:0x%04X\n",
2594                   &tmp_daddr, tcph->dest, &tmp_saddr, tcph->source);
2595
2596         do {
2597                 cm_node = find_node(cm_core,
2598                                     nfo.rem_port, nfo.rem_addr,
2599                                     nfo.loc_port, nfo.loc_addr);
2600
2601                 if (!cm_node) {
2602                         /* Only type of packet accepted are for */
2603                         /* the PASSIVE open (syn only) */
2604                         if ((!tcph->syn) || (tcph->ack)) {
2605                                 skb_handled = 0;
2606                                 break;
2607                         }
2608                         listener = find_listener(cm_core, nfo.loc_addr,
2609                                                  nfo.loc_port,
2610                                                  NES_CM_LISTENER_ACTIVE_STATE);
2611                         if (!listener) {
2612                                 nfo.cm_id = NULL;
2613                                 nfo.conn_type = 0;
2614                                 nes_debug(NES_DBG_CM, "Unable to find listener for the pkt\n");
2615                                 skb_handled = 0;
2616                                 break;
2617                         }
2618                         nfo.cm_id = listener->cm_id;
2619                         nfo.conn_type = listener->conn_type;
2620                         cm_node = make_cm_node(cm_core, nesvnic, &nfo,
2621                                                listener);
2622                         if (!cm_node) {
2623                                 nes_debug(NES_DBG_CM, "Unable to allocate "
2624                                           "node\n");
2625                                 cm_packets_dropped++;
2626                                 atomic_dec(&listener->ref_count);
2627                                 dev_kfree_skb_any(skb);
2628                                 break;
2629                         }
2630                         if (!tcph->rst && !tcph->fin) {
2631                                 cm_node->state = NES_CM_STATE_LISTENING;
2632                         } else {
2633                                 cm_packets_dropped++;
2634                                 rem_ref_cm_node(cm_core, cm_node);
2635                                 dev_kfree_skb_any(skb);
2636                                 break;
2637                         }
2638                         add_ref_cm_node(cm_node);
2639                 } else if (cm_node->state == NES_CM_STATE_TSA) {
2640                         if (cm_node->nesqp->pau_mode)
2641                                 nes_queue_mgt_skbs(skb, nesvnic, cm_node->nesqp);
2642                         else {
2643                                 rem_ref_cm_node(cm_core, cm_node);
2644                                 atomic_inc(&cm_accel_dropped_pkts);
2645                                 dev_kfree_skb_any(skb);
2646                         }
2647                         break;
2648                 }
2649                 skb_reset_network_header(skb);
2650                 skb_set_transport_header(skb, sizeof(*tcph));
2651                 skb->len = ntohs(iph->tot_len);
2652                 process_packet(cm_node, skb, cm_core);
2653                 rem_ref_cm_node(cm_core, cm_node);
2654         } while (0);
2655         return skb_handled;
2656 }
2657
2658
2659 /**
2660  * nes_cm_alloc_core - allocate a top level instance of a cm core
2661  */
2662 static struct nes_cm_core *nes_cm_alloc_core(void)
2663 {
2664         struct nes_cm_core *cm_core;
2665
2666         /* setup the CM core */
2667         /* alloc top level core control structure */
2668         cm_core = kzalloc(sizeof(*cm_core), GFP_KERNEL);
2669         if (!cm_core)
2670                 return NULL;
2671
2672         INIT_LIST_HEAD(&cm_core->connected_nodes);
2673         init_timer(&cm_core->tcp_timer);
2674         cm_core->tcp_timer.function = nes_cm_timer_tick;
2675
2676         cm_core->mtu = NES_CM_DEFAULT_MTU;
2677         cm_core->state = NES_CM_STATE_INITED;
2678         cm_core->free_tx_pkt_max = NES_CM_DEFAULT_FREE_PKTS;
2679
2680         atomic_set(&cm_core->events_posted, 0);
2681
2682         cm_core->api = &nes_cm_api;
2683
2684         spin_lock_init(&cm_core->ht_lock);
2685         spin_lock_init(&cm_core->listen_list_lock);
2686
2687         INIT_LIST_HEAD(&cm_core->listen_list.list);
2688
2689         nes_debug(NES_DBG_CM, "Init CM Core completed -- cm_core=%p\n", cm_core);
2690
2691         nes_debug(NES_DBG_CM, "Enable QUEUE EVENTS\n");
2692         cm_core->event_wq = alloc_ordered_workqueue("nesewq", 0);
2693         if (!cm_core->event_wq)
2694                 goto out_free_cmcore;
2695         cm_core->post_event = nes_cm_post_event;
2696         nes_debug(NES_DBG_CM, "Enable QUEUE DISCONNECTS\n");
2697         cm_core->disconn_wq = alloc_ordered_workqueue("nesdwq", 0);
2698         if (!cm_core->disconn_wq)
2699                 goto out_free_wq;
2700
2701         print_core(cm_core);
2702         return cm_core;
2703
2704 out_free_wq:
2705         destroy_workqueue(cm_core->event_wq);
2706 out_free_cmcore:
2707         kfree(cm_core);
2708         return NULL;
2709 }
2710
2711
2712 /**
2713  * mini_cm_dealloc_core - deallocate a top level instance of a cm core
2714  */
2715 static int mini_cm_dealloc_core(struct nes_cm_core *cm_core)
2716 {
2717         nes_debug(NES_DBG_CM, "De-Alloc CM Core (%p)\n", cm_core);
2718
2719         if (!cm_core)
2720                 return -EINVAL;
2721
2722         barrier();
2723
2724         if (timer_pending(&cm_core->tcp_timer))
2725                 del_timer(&cm_core->tcp_timer);
2726
2727         destroy_workqueue(cm_core->event_wq);
2728         destroy_workqueue(cm_core->disconn_wq);
2729         nes_debug(NES_DBG_CM, "\n");
2730         kfree(cm_core);
2731
2732         return 0;
2733 }
2734
2735
2736 /**
2737  * mini_cm_get
2738  */
2739 static int mini_cm_get(struct nes_cm_core *cm_core)
2740 {
2741         return cm_core->state;
2742 }
2743
2744
2745 /**
2746  * mini_cm_set
2747  */
2748 static int mini_cm_set(struct nes_cm_core *cm_core, u32 type, u32 value)
2749 {
2750         int ret = 0;
2751
2752         switch (type) {
2753         case NES_CM_SET_PKT_SIZE:
2754                 cm_core->mtu = value;
2755                 break;
2756         case NES_CM_SET_FREE_PKT_Q_SIZE:
2757                 cm_core->free_tx_pkt_max = value;
2758                 break;
2759         default:
2760                 /* unknown set option */
2761                 ret = -EINVAL;
2762         }
2763
2764         return ret;
2765 }
2766
2767
2768 /**
2769  * nes_cm_init_tsa_conn setup HW; MPA frames must be
2770  * successfully exchanged when this is called
2771  */
2772 static int nes_cm_init_tsa_conn(struct nes_qp *nesqp, struct nes_cm_node *cm_node)
2773 {
2774         int ret = 0;
2775
2776         if (!nesqp)
2777                 return -EINVAL;
2778
2779         nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_IPV4 |
2780                                                   NES_QPCONTEXT_MISC_NO_NAGLE | NES_QPCONTEXT_MISC_DO_NOT_FRAG |
2781                                                   NES_QPCONTEXT_MISC_DROS);
2782
2783         if (cm_node->tcp_cntxt.snd_wscale || cm_node->tcp_cntxt.rcv_wscale)
2784                 nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_WSCALE);
2785
2786         nesqp->nesqp_context->misc2 |= cpu_to_le32(64 << NES_QPCONTEXT_MISC2_TTL_SHIFT);
2787
2788         nesqp->nesqp_context->misc2 |= cpu_to_le32(
2789                 cm_node->tos << NES_QPCONTEXT_MISC2_TOS_SHIFT);
2790
2791         nesqp->nesqp_context->mss |= cpu_to_le32(((u32)cm_node->tcp_cntxt.mss) << 16);
2792
2793         nesqp->nesqp_context->tcp_state_flow_label |= cpu_to_le32(
2794                 (u32)NES_QPCONTEXT_TCPSTATE_EST << NES_QPCONTEXT_TCPFLOW_TCP_STATE_SHIFT);
2795
2796         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2797                 (cm_node->tcp_cntxt.snd_wscale << NES_QPCONTEXT_PDWSCALE_SND_WSCALE_SHIFT) &
2798                 NES_QPCONTEXT_PDWSCALE_SND_WSCALE_MASK);
2799
2800         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2801                 (cm_node->tcp_cntxt.rcv_wscale << NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_SHIFT) &
2802                 NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_MASK);
2803
2804         nesqp->nesqp_context->keepalive = cpu_to_le32(0x80);
2805         nesqp->nesqp_context->ts_recent = 0;
2806         nesqp->nesqp_context->ts_age = 0;
2807         nesqp->nesqp_context->snd_nxt = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2808         nesqp->nesqp_context->snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.snd_wnd);
2809         nesqp->nesqp_context->rcv_nxt = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2810         nesqp->nesqp_context->rcv_wnd = cpu_to_le32(cm_node->tcp_cntxt.rcv_wnd <<
2811                                                     cm_node->tcp_cntxt.rcv_wscale);
2812         nesqp->nesqp_context->snd_max = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2813         nesqp->nesqp_context->snd_una = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2814         nesqp->nesqp_context->srtt = 0;
2815         nesqp->nesqp_context->rttvar = cpu_to_le32(0x6);
2816         nesqp->nesqp_context->ssthresh = cpu_to_le32(0x3FFFC000);
2817         nesqp->nesqp_context->cwnd = cpu_to_le32(2 * cm_node->tcp_cntxt.mss);
2818         nesqp->nesqp_context->snd_wl1 = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2819         nesqp->nesqp_context->snd_wl2 = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2820         nesqp->nesqp_context->max_snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.max_snd_wnd);
2821
2822         nes_debug(NES_DBG_CM, "QP%u: rcv_nxt = 0x%08X, snd_nxt = 0x%08X,"
2823                   " Setting MSS to %u, PDWscale = 0x%08X, rcv_wnd = %u, context misc = 0x%08X.\n",
2824                   nesqp->hwqp.qp_id, le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
2825                   le32_to_cpu(nesqp->nesqp_context->snd_nxt),
2826                   cm_node->tcp_cntxt.mss, le32_to_cpu(nesqp->nesqp_context->pd_index_wscale),
2827                   le32_to_cpu(nesqp->nesqp_context->rcv_wnd),
2828                   le32_to_cpu(nesqp->nesqp_context->misc));
2829         nes_debug(NES_DBG_CM, "  snd_wnd  = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->snd_wnd));
2830         nes_debug(NES_DBG_CM, "  snd_cwnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->cwnd));
2831         nes_debug(NES_DBG_CM, "  max_swnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->max_snd_wnd));
2832
2833         nes_debug(NES_DBG_CM, "Change cm_node state to TSA\n");
2834         cm_node->state = NES_CM_STATE_TSA;
2835
2836         return ret;
2837 }
2838
2839
2840 /**
2841  * nes_cm_disconn
2842  */
2843 int nes_cm_disconn(struct nes_qp *nesqp)
2844 {
2845         struct disconn_work *work;
2846
2847         work = kzalloc(sizeof *work, GFP_ATOMIC);
2848         if (!work)
2849                 return -ENOMEM;  /* Timer will clean up */
2850
2851         nes_add_ref(&nesqp->ibqp);
2852         work->nesqp = nesqp;
2853         INIT_WORK(&work->work, nes_disconnect_worker);
2854         queue_work(g_cm_core->disconn_wq, &work->work);
2855         return 0;
2856 }
2857
2858
2859 /**
2860  * nes_disconnect_worker
2861  */
2862 static void nes_disconnect_worker(struct work_struct *work)
2863 {
2864         struct disconn_work *dwork = container_of(work, struct disconn_work, work);
2865         struct nes_qp *nesqp = dwork->nesqp;
2866
2867         kfree(dwork);
2868         nes_debug(NES_DBG_CM, "processing AEQE id 0x%04X for QP%u.\n",
2869                   nesqp->last_aeq, nesqp->hwqp.qp_id);
2870         nes_cm_disconn_true(nesqp);
2871         nes_rem_ref(&nesqp->ibqp);
2872 }
2873
2874
2875 /**
2876  * nes_cm_disconn_true
2877  */
2878 static int nes_cm_disconn_true(struct nes_qp *nesqp)
2879 {
2880         unsigned long flags;
2881         int ret = 0;
2882         struct iw_cm_id *cm_id;
2883         struct iw_cm_event cm_event;
2884         struct nes_vnic *nesvnic;
2885         u16 last_ae;
2886         u8 original_hw_tcp_state;
2887         u8 original_ibqp_state;
2888         int disconn_status = 0;
2889         int issue_disconn = 0;
2890         int issue_close = 0;
2891         int issue_flush = 0;
2892         u32 flush_q = NES_CQP_FLUSH_RQ;
2893         struct ib_event ibevent;
2894
2895         if (!nesqp) {
2896                 nes_debug(NES_DBG_CM, "disconnect_worker nesqp is NULL\n");
2897                 return -1;
2898         }
2899
2900         spin_lock_irqsave(&nesqp->lock, flags);
2901         cm_id = nesqp->cm_id;
2902         /* make sure we havent already closed this connection */
2903         if (!cm_id) {
2904                 nes_debug(NES_DBG_CM, "QP%u disconnect_worker cmid is NULL\n",
2905                           nesqp->hwqp.qp_id);
2906                 spin_unlock_irqrestore(&nesqp->lock, flags);
2907                 return -1;
2908         }
2909
2910         nesvnic = to_nesvnic(nesqp->ibqp.device);
2911         nes_debug(NES_DBG_CM, "Disconnecting QP%u\n", nesqp->hwqp.qp_id);
2912
2913         original_hw_tcp_state = nesqp->hw_tcp_state;
2914         original_ibqp_state = nesqp->ibqp_state;
2915         last_ae = nesqp->last_aeq;
2916
2917         if (nesqp->term_flags) {
2918                 issue_disconn = 1;
2919                 issue_close = 1;
2920                 nesqp->cm_id = NULL;
2921                 del_timer(&nesqp->terminate_timer);
2922                 if (nesqp->flush_issued == 0) {
2923                         nesqp->flush_issued = 1;
2924                         issue_flush = 1;
2925                 }
2926         } else if ((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSE_WAIT) ||
2927                         ((original_ibqp_state == IB_QPS_RTS) &&
2928                         (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2929                 issue_disconn = 1;
2930                 if (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET)
2931                         disconn_status = -ECONNRESET;
2932         }
2933
2934         if (((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSED) ||
2935                  (original_hw_tcp_state == NES_AEQE_TCP_STATE_TIME_WAIT) ||
2936                  (last_ae == NES_AEQE_AEID_RDMAP_ROE_BAD_LLP_CLOSE) ||
2937                  (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2938                 issue_close = 1;
2939                 nesqp->cm_id = NULL;
2940                 if (nesqp->flush_issued == 0) {
2941                         nesqp->flush_issued = 1;
2942                         issue_flush = 1;
2943                 }
2944         }
2945
2946         spin_unlock_irqrestore(&nesqp->lock, flags);
2947
2948         if ((issue_flush) && (nesqp->destroyed == 0)) {
2949                 /* Flush the queue(s) */
2950                 if (nesqp->hw_iwarp_state >= NES_AEQE_IWARP_STATE_TERMINATE)
2951                         flush_q |= NES_CQP_FLUSH_SQ;
2952                 flush_wqes(nesvnic->nesdev, nesqp, flush_q, 1);
2953
2954                 if (nesqp->term_flags) {
2955                         ibevent.device = nesqp->ibqp.device;
2956                         ibevent.event = nesqp->terminate_eventtype;
2957                         ibevent.element.qp = &nesqp->ibqp;
2958                         if (nesqp->ibqp.event_handler)
2959                                 nesqp->ibqp.event_handler(&ibevent, nesqp->ibqp.qp_context);
2960                 }
2961         }
2962
2963         if ((cm_id) && (cm_id->event_handler)) {
2964                 if (issue_disconn) {
2965                         atomic_inc(&cm_disconnects);
2966                         cm_event.event = IW_CM_EVENT_DISCONNECT;
2967                         cm_event.status = disconn_status;
2968                         cm_event.local_addr = cm_id->m_local_addr;
2969                         cm_event.remote_addr = cm_id->m_remote_addr;
2970                         cm_event.private_data = NULL;
2971                         cm_event.private_data_len = 0;
2972
2973                         nes_debug(NES_DBG_CM, "Generating a CM Disconnect Event"
2974                                   " for  QP%u, SQ Head = %u, SQ Tail = %u. "
2975                                   "cm_id = %p, refcount = %u.\n",
2976                                   nesqp->hwqp.qp_id, nesqp->hwqp.sq_head,
2977                                   nesqp->hwqp.sq_tail, cm_id,
2978                                   atomic_read(&nesqp->refcount));
2979
2980                         ret = cm_id->event_handler(cm_id, &cm_event);
2981                         if (ret)
2982                                 nes_debug(NES_DBG_CM, "OFA CM event_handler "
2983                                           "returned, ret=%d\n", ret);
2984                 }
2985
2986                 if (issue_close) {
2987                         atomic_inc(&cm_closes);
2988                         nes_disconnect(nesqp, 1);
2989
2990                         cm_id->provider_data = nesqp;
2991                         /* Send up the close complete event */
2992                         cm_event.event = IW_CM_EVENT_CLOSE;
2993                         cm_event.status = 0;
2994                         cm_event.provider_data = cm_id->provider_data;
2995                         cm_event.local_addr = cm_id->m_local_addr;
2996                         cm_event.remote_addr = cm_id->m_remote_addr;
2997                         cm_event.private_data = NULL;
2998                         cm_event.private_data_len = 0;
2999
3000                         ret = cm_id->event_handler(cm_id, &cm_event);
3001                         if (ret)
3002                                 nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3003
3004                         cm_id->rem_ref(cm_id);
3005                 }
3006         }
3007
3008         return 0;
3009 }
3010
3011
3012 /**
3013  * nes_disconnect
3014  */
3015 static int nes_disconnect(struct nes_qp *nesqp, int abrupt)
3016 {
3017         int ret = 0;
3018         struct nes_vnic *nesvnic;
3019         struct nes_device *nesdev;
3020         struct nes_ib_device *nesibdev;
3021
3022         nesvnic = to_nesvnic(nesqp->ibqp.device);
3023         if (!nesvnic)
3024                 return -EINVAL;
3025
3026         nesdev = nesvnic->nesdev;
3027         nesibdev = nesvnic->nesibdev;
3028
3029         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
3030                         netdev_refcnt_read(nesvnic->netdev));
3031
3032         if (nesqp->active_conn) {
3033
3034                 /* indicate this connection is NOT active */
3035                 nesqp->active_conn = 0;
3036         } else {
3037                 /* Need to free the Last Streaming Mode Message */
3038                 if (nesqp->ietf_frame) {
3039                         if (nesqp->lsmm_mr)
3040                                 nesibdev->ibdev.dereg_mr(nesqp->lsmm_mr);
3041                         pci_free_consistent(nesdev->pcidev,
3042                                             nesqp->private_data_len + nesqp->ietf_frame_size,
3043                                             nesqp->ietf_frame, nesqp->ietf_frame_pbase);
3044                 }
3045         }
3046
3047         /* close the CM node down if it is still active */
3048         if (nesqp->cm_node) {
3049                 nes_debug(NES_DBG_CM, "Call close API\n");
3050
3051                 g_cm_core->api->close(g_cm_core, nesqp->cm_node);
3052         }
3053
3054         return ret;
3055 }
3056
3057
3058 /**
3059  * nes_accept
3060  */
3061 int nes_accept(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
3062 {
3063         u64 u64temp;
3064         struct ib_qp *ibqp;
3065         struct nes_qp *nesqp;
3066         struct nes_vnic *nesvnic;
3067         struct nes_device *nesdev;
3068         struct nes_cm_node *cm_node;
3069         struct nes_adapter *adapter;
3070         struct ib_qp_attr attr;
3071         struct iw_cm_event cm_event;
3072         struct nes_hw_qp_wqe *wqe;
3073         struct nes_v4_quad nes_quad;
3074         u32 crc_value;
3075         int ret;
3076         int passive_state;
3077         struct nes_ib_device *nesibdev;
3078         struct ib_mr *ibmr = NULL;
3079         struct nes_pd *nespd;
3080         u64 tagged_offset;
3081         u8 mpa_frame_offset = 0;
3082         struct ietf_mpa_v2 *mpa_v2_frame;
3083         u8 start_addr = 0;
3084         u8 *start_ptr = &start_addr;
3085         u8 **start_buff = &start_ptr;
3086         u16 buff_len = 0;
3087         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3088         struct sockaddr_in *raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3089
3090         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
3091         if (!ibqp)
3092                 return -EINVAL;
3093
3094         /* get all our handles */
3095         nesqp = to_nesqp(ibqp);
3096         nesvnic = to_nesvnic(nesqp->ibqp.device);
3097         nesdev = nesvnic->nesdev;
3098         adapter = nesdev->nesadapter;
3099
3100         cm_node = (struct nes_cm_node *)cm_id->provider_data;
3101         nes_debug(NES_DBG_CM, "nes_accept: cm_node= %p nesvnic=%p, netdev=%p,"
3102                 "%s\n", cm_node, nesvnic, nesvnic->netdev,
3103                 nesvnic->netdev->name);
3104
3105         if (NES_CM_STATE_LISTENER_DESTROYED == cm_node->state) {
3106                 if (cm_node->loopbackpartner)
3107                         rem_ref_cm_node(cm_node->cm_core, cm_node->loopbackpartner);
3108                 rem_ref_cm_node(cm_node->cm_core, cm_node);
3109                 return -EINVAL;
3110         }
3111
3112         passive_state = atomic_add_return(1, &cm_node->passive_state);
3113         if (passive_state == NES_SEND_RESET_EVENT) {
3114                 rem_ref_cm_node(cm_node->cm_core, cm_node);
3115                 return -ECONNRESET;
3116         }
3117         /* associate the node with the QP */
3118         nesqp->cm_node = (void *)cm_node;
3119         cm_node->nesqp = nesqp;
3120
3121
3122         nes_debug(NES_DBG_CM, "QP%u, cm_node=%p, jiffies = %lu listener = %p\n",
3123                 nesqp->hwqp.qp_id, cm_node, jiffies, cm_node->listener);
3124         atomic_inc(&cm_accepts);
3125
3126         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
3127                         netdev_refcnt_read(nesvnic->netdev));
3128
3129         nesqp->ietf_frame_size = sizeof(struct ietf_mpa_v2);
3130         /* allocate the ietf frame and space for private data */
3131         nesqp->ietf_frame = pci_alloc_consistent(nesdev->pcidev,
3132                                                  nesqp->ietf_frame_size + conn_param->private_data_len,
3133                                                  &nesqp->ietf_frame_pbase);
3134
3135         if (!nesqp->ietf_frame) {
3136                 nes_debug(NES_DBG_CM, "Unable to allocate memory for private data\n");
3137                 return -ENOMEM;
3138         }
3139         mpa_v2_frame = (struct ietf_mpa_v2 *)nesqp->ietf_frame;
3140
3141         if (cm_node->mpa_frame_rev == IETF_MPA_V1)
3142                 mpa_frame_offset = 4;
3143
3144         if (cm_node->mpa_frame_rev == IETF_MPA_V1 ||
3145                         cm_node->mpav2_ird_ord == IETF_NO_IRD_ORD) {
3146                 record_ird_ord(cm_node, (u16)conn_param->ird, (u16)conn_param->ord);
3147         }
3148
3149         memcpy(mpa_v2_frame->priv_data, conn_param->private_data,
3150                conn_param->private_data_len);
3151
3152         cm_build_mpa_frame(cm_node, start_buff, &buff_len, nesqp->ietf_frame, MPA_KEY_REPLY);
3153         nesqp->private_data_len = conn_param->private_data_len;
3154
3155         /* setup our first outgoing iWarp send WQE (the IETF frame response) */
3156         wqe = &nesqp->hwqp.sq_vbase[0];
3157
3158         if (raddr->sin_addr.s_addr != laddr->sin_addr.s_addr) {
3159                 u64temp = (unsigned long)nesqp;
3160                 nesibdev = nesvnic->nesibdev;
3161                 nespd = nesqp->nespd;
3162                 tagged_offset = (u64)(unsigned long)*start_buff;
3163                 ibmr = nes_reg_phys_mr(&nespd->ibpd,
3164                                 nesqp->ietf_frame_pbase + mpa_frame_offset,
3165                                 buff_len, IB_ACCESS_LOCAL_WRITE,
3166                                 &tagged_offset);
3167                 if (IS_ERR(ibmr)) {
3168                         nes_debug(NES_DBG_CM, "Unable to register memory region"
3169                                   "for lSMM for cm_node = %p \n",
3170                                   cm_node);
3171                         pci_free_consistent(nesdev->pcidev,
3172                                             nesqp->private_data_len + nesqp->ietf_frame_size,
3173                                             nesqp->ietf_frame, nesqp->ietf_frame_pbase);
3174                         return PTR_ERR(ibmr);
3175                 }
3176
3177                 ibmr->pd = &nespd->ibpd;
3178                 ibmr->device = nespd->ibpd.device;
3179                 nesqp->lsmm_mr = ibmr;
3180
3181                 u64temp |= NES_SW_CONTEXT_ALIGN >> 1;
3182                 set_wqe_64bit_value(wqe->wqe_words,
3183                                     NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX,
3184                                     u64temp);
3185                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
3186                         cpu_to_le32(NES_IWARP_SQ_WQE_STREAMING |
3187                                     NES_IWARP_SQ_WQE_WRPDU);
3188                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] =
3189                         cpu_to_le32(buff_len);
3190                 set_wqe_64bit_value(wqe->wqe_words,
3191                                     NES_IWARP_SQ_WQE_FRAG0_LOW_IDX,
3192                                     (u64)(unsigned long)(*start_buff));
3193                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] =
3194                         cpu_to_le32(buff_len);
3195                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = ibmr->lkey;
3196                 if (nesqp->sq_kmapped) {
3197                         nesqp->sq_kmapped = 0;
3198                         kunmap(nesqp->page);
3199                 }
3200
3201                 nesqp->nesqp_context->ird_ord_sizes |=
3202                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
3203                                     NES_QPCONTEXT_ORDIRD_WRPDU);
3204         } else {
3205                 nesqp->nesqp_context->ird_ord_sizes |=
3206                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_WRPDU);
3207         }
3208         nesqp->skip_lsmm = 1;
3209
3210         /* Cache the cm_id in the qp */
3211         nesqp->cm_id = cm_id;
3212         cm_node->cm_id = cm_id;
3213
3214         /*  nesqp->cm_node = (void *)cm_id->provider_data; */
3215         cm_id->provider_data = nesqp;
3216         nesqp->active_conn = 0;
3217
3218         if (cm_node->state == NES_CM_STATE_TSA)
3219                 nes_debug(NES_DBG_CM, "Already state = TSA for cm_node=%p\n",
3220                           cm_node);
3221
3222         nes_cm_init_tsa_conn(nesqp, cm_node);
3223
3224         nesqp->nesqp_context->tcpPorts[0] =
3225                                 cpu_to_le16(cm_node->loc_port);
3226         nesqp->nesqp_context->tcpPorts[1] =
3227                                 cpu_to_le16(cm_node->rem_port);
3228
3229         nesqp->nesqp_context->ip0 = cpu_to_le32(cm_node->rem_addr);
3230
3231         nesqp->nesqp_context->misc2 |= cpu_to_le32(
3232                 (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
3233                 NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
3234
3235         nesqp->nesqp_context->arp_index_vlan |=
3236                 cpu_to_le32(nes_arp_table(nesdev,
3237                                           le32_to_cpu(nesqp->nesqp_context->ip0), NULL,
3238                                           NES_ARP_RESOLVE) << 16);
3239
3240         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
3241                 jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
3242
3243         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
3244
3245         nesqp->nesqp_context->ird_ord_sizes |= cpu_to_le32(
3246                 ((u32)1 << NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT));
3247         nesqp->nesqp_context->ird_ord_sizes |=
3248                 cpu_to_le32((u32)cm_node->ord_size);
3249
3250         memset(&nes_quad, 0, sizeof(nes_quad));
3251         nes_quad.DstIpAdrIndex =
3252                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
3253         nes_quad.SrcIpadr = htonl(cm_node->rem_addr);
3254         nes_quad.TcpPorts[0] = htons(cm_node->rem_port);
3255         nes_quad.TcpPorts[1] = htons(cm_node->loc_port);
3256
3257         /* Produce hash key */
3258         crc_value = get_crc_value(&nes_quad);
3259         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
3260         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, CRC = 0x%08X\n",
3261                   nesqp->hte_index, nesqp->hte_index & adapter->hte_index_mask);
3262
3263         nesqp->hte_index &= adapter->hte_index_mask;
3264         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
3265
3266         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
3267
3268         nes_debug(NES_DBG_CM, "QP%u, Destination IP = 0x%08X:0x%04X, local = "
3269                   "0x%08X:0x%04X, rcv_nxt=0x%08X, snd_nxt=0x%08X, mpa + "
3270                   "private data length=%u.\n", nesqp->hwqp.qp_id,
3271                   ntohl(raddr->sin_addr.s_addr), ntohs(raddr->sin_port),
3272                   ntohl(laddr->sin_addr.s_addr), ntohs(laddr->sin_port),
3273                   le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
3274                   le32_to_cpu(nesqp->nesqp_context->snd_nxt),
3275                   buff_len);
3276
3277         /* notify OF layer that accept event was successful */
3278         cm_id->add_ref(cm_id);
3279         nes_add_ref(&nesqp->ibqp);
3280
3281         cm_event.event = IW_CM_EVENT_ESTABLISHED;
3282         cm_event.status = 0;
3283         cm_event.provider_data = (void *)nesqp;
3284         cm_event.local_addr = cm_id->m_local_addr;
3285         cm_event.remote_addr = cm_id->m_remote_addr;
3286         cm_event.private_data = NULL;
3287         cm_event.private_data_len = 0;
3288         cm_event.ird = cm_node->ird_size;
3289         cm_event.ord = cm_node->ord_size;
3290
3291         ret = cm_id->event_handler(cm_id, &cm_event);
3292         attr.qp_state = IB_QPS_RTS;
3293         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
3294         if (cm_node->loopbackpartner) {
3295                 cm_node->loopbackpartner->mpa_frame_size =
3296                         nesqp->private_data_len;
3297                 /* copy entire MPA frame to our cm_node's frame */
3298                 memcpy(cm_node->loopbackpartner->mpa_frame_buf,
3299                        conn_param->private_data, conn_param->private_data_len);
3300                 create_event(cm_node->loopbackpartner, NES_CM_EVENT_CONNECTED);
3301         }
3302         if (ret)
3303                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3304                        "ret=%d\n", __func__, __LINE__, ret);
3305
3306         return 0;
3307 }
3308
3309
3310 /**
3311  * nes_reject
3312  */
3313 int nes_reject(struct iw_cm_id *cm_id, const void *pdata, u8 pdata_len)
3314 {
3315         struct nes_cm_node *cm_node;
3316         struct nes_cm_node *loopback;
3317         struct nes_cm_core *cm_core;
3318         u8 *start_buff;
3319
3320         atomic_inc(&cm_rejects);
3321         cm_node = (struct nes_cm_node *)cm_id->provider_data;
3322         loopback = cm_node->loopbackpartner;
3323         cm_core = cm_node->cm_core;
3324         cm_node->cm_id = cm_id;
3325
3326         if (pdata_len + sizeof(struct ietf_mpa_v2) > MAX_CM_BUFFER)
3327                 return -EINVAL;
3328
3329         if (loopback) {
3330                 memcpy(&loopback->mpa_frame.priv_data, pdata, pdata_len);
3331                 loopback->mpa_frame.priv_data_len = pdata_len;
3332                 loopback->mpa_frame_size = pdata_len;
3333         } else {
3334                 start_buff = &cm_node->mpa_frame_buf[0] + sizeof(struct ietf_mpa_v2);
3335                 cm_node->mpa_frame_size = pdata_len;
3336                 memcpy(start_buff, pdata, pdata_len);
3337         }
3338         return cm_core->api->reject(cm_core, cm_node);
3339 }
3340
3341
3342 /**
3343  * nes_connect
3344  * setup and launch cm connect node
3345  */
3346 int nes_connect(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
3347 {
3348         struct ib_qp *ibqp;
3349         struct nes_qp *nesqp;
3350         struct nes_vnic *nesvnic;
3351         struct nes_device *nesdev;
3352         struct nes_cm_node *cm_node;
3353         struct nes_cm_info cm_info;
3354         int apbvt_set = 0;
3355         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3356         struct sockaddr_in *raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3357
3358         if (cm_id->remote_addr.ss_family != AF_INET)
3359                 return -ENOSYS;
3360         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
3361         if (!ibqp)
3362                 return -EINVAL;
3363         nesqp = to_nesqp(ibqp);
3364         if (!nesqp)
3365                 return -EINVAL;
3366         nesvnic = to_nesvnic(nesqp->ibqp.device);
3367         if (!nesvnic)
3368                 return -EINVAL;
3369         nesdev = nesvnic->nesdev;
3370         if (!nesdev)
3371                 return -EINVAL;
3372
3373         if (!laddr->sin_port || !raddr->sin_port)
3374                 return -EINVAL;
3375
3376         nes_debug(NES_DBG_CM, "QP%u, current IP = 0x%08X, Destination IP = "
3377                   "0x%08X:0x%04X, local = 0x%08X:0x%04X.\n", nesqp->hwqp.qp_id,
3378                   ntohl(nesvnic->local_ipaddr), ntohl(raddr->sin_addr.s_addr),
3379                   ntohs(raddr->sin_port), ntohl(laddr->sin_addr.s_addr),
3380                   ntohs(laddr->sin_port));
3381
3382         atomic_inc(&cm_connects);
3383         nesqp->active_conn = 1;
3384
3385         /* cache the cm_id in the qp */
3386         nesqp->cm_id = cm_id;
3387         cm_id->provider_data = nesqp;
3388         nesqp->private_data_len = conn_param->private_data_len;
3389
3390         nes_debug(NES_DBG_CM, "requested ord = 0x%08X.\n", (u32)conn_param->ord);
3391         nes_debug(NES_DBG_CM, "mpa private data len =%u\n",
3392                   conn_param->private_data_len);
3393
3394         /* set up the connection params for the node */
3395         cm_info.loc_addr = ntohl(laddr->sin_addr.s_addr);
3396         cm_info.loc_port = ntohs(laddr->sin_port);
3397         cm_info.rem_addr = ntohl(raddr->sin_addr.s_addr);
3398         cm_info.rem_port = ntohs(raddr->sin_port);
3399         cm_info.cm_id = cm_id;
3400         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3401
3402         if (laddr->sin_addr.s_addr != raddr->sin_addr.s_addr) {
3403                 nes_manage_apbvt(nesvnic, cm_info.loc_port,
3404                                  PCI_FUNC(nesdev->pcidev->devfn),
3405                                  NES_MANAGE_APBVT_ADD);
3406                 apbvt_set = 1;
3407         }
3408
3409         cm_id->add_ref(cm_id);
3410
3411         /* create a connect CM node connection */
3412         cm_node = g_cm_core->api->connect(g_cm_core, nesvnic,
3413                                           conn_param->private_data_len, (void *)conn_param->private_data,
3414                                           &cm_info);
3415         if (!cm_node) {
3416                 if (apbvt_set)
3417                         nes_manage_apbvt(nesvnic, cm_info.loc_port,
3418                                          PCI_FUNC(nesdev->pcidev->devfn),
3419                                          NES_MANAGE_APBVT_DEL);
3420
3421                 nes_debug(NES_DBG_NLMSG, "Delete loc_port = %04X\n",
3422                           cm_info.loc_port);
3423                 cm_id->rem_ref(cm_id);
3424                 return -ENOMEM;
3425         }
3426
3427         record_ird_ord(cm_node, (u16)conn_param->ird, (u16)conn_param->ord);
3428         if (cm_node->send_rdma0_op == SEND_RDMA_READ_ZERO &&
3429                                 cm_node->ord_size == 0)
3430                 cm_node->ord_size = 1;
3431
3432         cm_node->apbvt_set = apbvt_set;
3433         cm_node->tos = cm_id->tos;
3434         nesqp->cm_node = cm_node;
3435         cm_node->nesqp = nesqp;
3436         nes_add_ref(&nesqp->ibqp);
3437
3438         return 0;
3439 }
3440
3441
3442 /**
3443  * nes_create_listen
3444  */
3445 int nes_create_listen(struct iw_cm_id *cm_id, int backlog)
3446 {
3447         struct nes_vnic *nesvnic;
3448         struct nes_cm_listener *cm_node;
3449         struct nes_cm_info cm_info;
3450         int err;
3451         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3452
3453         nes_debug(NES_DBG_CM, "cm_id = %p, local port = 0x%04X.\n",
3454                   cm_id, ntohs(laddr->sin_port));
3455
3456         if (cm_id->m_local_addr.ss_family != AF_INET)
3457                 return -ENOSYS;
3458         nesvnic = to_nesvnic(cm_id->device);
3459         if (!nesvnic)
3460                 return -EINVAL;
3461
3462         nes_debug(NES_DBG_CM, "nesvnic=%p, netdev=%p, %s\n",
3463                         nesvnic, nesvnic->netdev, nesvnic->netdev->name);
3464
3465         nes_debug(NES_DBG_CM, "nesvnic->local_ipaddr=0x%08x, sin_addr.s_addr=0x%08x\n",
3466                         nesvnic->local_ipaddr, laddr->sin_addr.s_addr);
3467
3468         /* setup listen params in our api call struct */
3469         cm_info.loc_addr = ntohl(nesvnic->local_ipaddr);
3470         cm_info.loc_port = ntohs(laddr->sin_port);
3471         cm_info.backlog = backlog;
3472         cm_info.cm_id = cm_id;
3473
3474         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3475
3476         cm_node = g_cm_core->api->listen(g_cm_core, nesvnic, &cm_info);
3477         if (!cm_node) {
3478                 printk(KERN_ERR "%s[%u] Error returned from listen API call\n",
3479                        __func__, __LINE__);
3480                 return -ENOMEM;
3481         }
3482
3483         cm_id->provider_data = cm_node;
3484         cm_node->tos = cm_id->tos;
3485
3486         if (!cm_node->reused_node) {
3487                 err = nes_manage_apbvt(nesvnic, cm_node->loc_port,
3488                                        PCI_FUNC(nesvnic->nesdev->pcidev->devfn),
3489                                        NES_MANAGE_APBVT_ADD);
3490                 if (err) {
3491                         printk(KERN_ERR "nes_manage_apbvt call returned %d.\n",
3492                                err);
3493                         g_cm_core->api->stop_listener(g_cm_core, (void *)cm_node);
3494                         return err;
3495                 }
3496                 atomic_inc(&cm_listens_created);
3497         }
3498
3499         cm_id->add_ref(cm_id);
3500         cm_id->provider_data = (void *)cm_node;
3501
3502
3503         return 0;
3504 }
3505
3506
3507 /**
3508  * nes_destroy_listen
3509  */
3510 int nes_destroy_listen(struct iw_cm_id *cm_id)
3511 {
3512         if (cm_id->provider_data)
3513                 g_cm_core->api->stop_listener(g_cm_core, cm_id->provider_data);
3514         else
3515                 nes_debug(NES_DBG_CM, "cm_id->provider_data was NULL\n");
3516
3517         cm_id->rem_ref(cm_id);
3518
3519         return 0;
3520 }
3521
3522
3523 /**
3524  * nes_cm_recv
3525  */
3526 int nes_cm_recv(struct sk_buff *skb, struct net_device *netdevice)
3527 {
3528         int rc = 0;
3529
3530         cm_packets_received++;
3531         if ((g_cm_core) && (g_cm_core->api))
3532                 rc = g_cm_core->api->recv_pkt(g_cm_core, netdev_priv(netdevice), skb);
3533         else
3534                 nes_debug(NES_DBG_CM, "Unable to process packet for CM,"
3535                           " cm is not setup properly.\n");
3536
3537         return rc;
3538 }
3539
3540
3541 /**
3542  * nes_cm_start
3543  * Start and init a cm core module
3544  */
3545 int nes_cm_start(void)
3546 {
3547         nes_debug(NES_DBG_CM, "\n");
3548         /* create the primary CM core, pass this handle to subsequent core inits */
3549         g_cm_core = nes_cm_alloc_core();
3550         if (g_cm_core)
3551                 return 0;
3552         else
3553                 return -ENOMEM;
3554 }
3555
3556
3557 /**
3558  * nes_cm_stop
3559  * stop and dealloc all cm core instances
3560  */
3561 int nes_cm_stop(void)
3562 {
3563         g_cm_core->api->destroy_cm_core(g_cm_core);
3564         return 0;
3565 }
3566
3567
3568 /**
3569  * cm_event_connected
3570  * handle a connected event, setup QPs and HW
3571  */
3572 static void cm_event_connected(struct nes_cm_event *event)
3573 {
3574         struct nes_qp *nesqp;
3575         struct nes_vnic *nesvnic;
3576         struct nes_device *nesdev;
3577         struct nes_cm_node *cm_node;
3578         struct nes_adapter *nesadapter;
3579         struct ib_qp_attr attr;
3580         struct iw_cm_id *cm_id;
3581         struct iw_cm_event cm_event;
3582         struct nes_v4_quad nes_quad;
3583         u32 crc_value;
3584         int ret;
3585         struct sockaddr_in *laddr;
3586         struct sockaddr_in *raddr;
3587         struct sockaddr_in *cm_event_laddr;
3588
3589         /* get all our handles */
3590         cm_node = event->cm_node;
3591         cm_id = cm_node->cm_id;
3592         nes_debug(NES_DBG_CM, "cm_event_connected - %p - cm_id = %p\n", cm_node, cm_id);
3593         nesqp = (struct nes_qp *)cm_id->provider_data;
3594         nesvnic = to_nesvnic(nesqp->ibqp.device);
3595         nesdev = nesvnic->nesdev;
3596         nesadapter = nesdev->nesadapter;
3597         laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3598         raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3599         cm_event_laddr = (struct sockaddr_in *)&cm_event.local_addr;
3600
3601         if (nesqp->destroyed)
3602                 return;
3603         atomic_inc(&cm_connecteds);
3604         nes_debug(NES_DBG_CM, "QP%u attempting to connect to  0x%08X:0x%04X on"
3605                   " local port 0x%04X. jiffies = %lu.\n",
3606                   nesqp->hwqp.qp_id, ntohl(raddr->sin_addr.s_addr),
3607                   ntohs(raddr->sin_port), ntohs(laddr->sin_port), jiffies);
3608
3609         nes_cm_init_tsa_conn(nesqp, cm_node);
3610
3611         /* set the QP tsa context */
3612         nesqp->nesqp_context->tcpPorts[0] =
3613                         cpu_to_le16(cm_node->loc_port);
3614         nesqp->nesqp_context->tcpPorts[1] =
3615                         cpu_to_le16(cm_node->rem_port);
3616         nesqp->nesqp_context->ip0 = cpu_to_le32(cm_node->rem_addr);
3617
3618         nesqp->nesqp_context->misc2 |= cpu_to_le32(
3619                         (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
3620                         NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
3621         nesqp->nesqp_context->arp_index_vlan |= cpu_to_le32(
3622                         nes_arp_table(nesdev,
3623                         le32_to_cpu(nesqp->nesqp_context->ip0),
3624                         NULL, NES_ARP_RESOLVE) << 16);
3625         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
3626                         jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
3627         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
3628         nesqp->nesqp_context->ird_ord_sizes |=
3629                         cpu_to_le32((u32)1 <<
3630                         NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT);
3631         nesqp->nesqp_context->ird_ord_sizes |=
3632                         cpu_to_le32((u32)cm_node->ord_size);
3633
3634         /* Adjust tail for not having a LSMM */
3635         /*nesqp->hwqp.sq_tail = 1;*/
3636
3637         build_rdma0_msg(cm_node, &nesqp);
3638
3639         nes_write32(nesdev->regs + NES_WQE_ALLOC,
3640                     (1 << 24) | 0x00800000 | nesqp->hwqp.qp_id);
3641
3642         memset(&nes_quad, 0, sizeof(nes_quad));
3643
3644         nes_quad.DstIpAdrIndex =
3645                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
3646         nes_quad.SrcIpadr = htonl(cm_node->rem_addr);
3647         nes_quad.TcpPorts[0] = htons(cm_node->rem_port);
3648         nes_quad.TcpPorts[1] = htons(cm_node->loc_port);
3649
3650         /* Produce hash key */
3651         crc_value = get_crc_value(&nes_quad);
3652         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
3653         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, After CRC = 0x%08X\n",
3654                   nesqp->hte_index, nesqp->hte_index & nesadapter->hte_index_mask);
3655
3656         nesqp->hte_index &= nesadapter->hte_index_mask;
3657         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
3658
3659         nesqp->ietf_frame = &cm_node->mpa_frame;
3660         nesqp->private_data_len = (u8)cm_node->mpa_frame_size;
3661         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
3662
3663         /* notify OF layer we successfully created the requested connection */
3664         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3665         cm_event.status = 0;
3666         cm_event.provider_data = cm_id->provider_data;
3667         cm_event_laddr->sin_family = AF_INET;
3668         cm_event_laddr->sin_port = laddr->sin_port;
3669         cm_event.remote_addr = cm_id->m_remote_addr;
3670
3671         cm_event.private_data = (void *)event->cm_node->mpa_frame_buf;
3672         cm_event.private_data_len = (u8)event->cm_node->mpa_frame_size;
3673         cm_event.ird = cm_node->ird_size;
3674         cm_event.ord = cm_node->ord_size;
3675
3676         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3677         ret = cm_id->event_handler(cm_id, &cm_event);
3678         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3679
3680         if (ret)
3681                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3682                        "ret=%d\n", __func__, __LINE__, ret);
3683         attr.qp_state = IB_QPS_RTS;
3684         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
3685
3686         nes_debug(NES_DBG_CM, "Exiting connect thread for QP%u. jiffies = "
3687                   "%lu\n", nesqp->hwqp.qp_id, jiffies);
3688
3689         return;
3690 }
3691
3692
3693 /**
3694  * cm_event_connect_error
3695  */
3696 static void cm_event_connect_error(struct nes_cm_event *event)
3697 {
3698         struct nes_qp *nesqp;
3699         struct iw_cm_id *cm_id;
3700         struct iw_cm_event cm_event;
3701         /* struct nes_cm_info cm_info; */
3702         int ret;
3703
3704         if (!event->cm_node)
3705                 return;
3706
3707         cm_id = event->cm_node->cm_id;
3708         if (!cm_id)
3709                 return;
3710
3711         nes_debug(NES_DBG_CM, "cm_node=%p, cm_id=%p\n", event->cm_node, cm_id);
3712         nesqp = cm_id->provider_data;
3713
3714         if (!nesqp)
3715                 return;
3716
3717         /* notify OF layer about this connection error event */
3718         /* cm_id->rem_ref(cm_id); */
3719         nesqp->cm_id = NULL;
3720         cm_id->provider_data = NULL;
3721         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3722         cm_event.status = -ECONNRESET;
3723         cm_event.provider_data = cm_id->provider_data;
3724         cm_event.local_addr = cm_id->m_local_addr;
3725         cm_event.remote_addr = cm_id->m_remote_addr;
3726         cm_event.private_data = NULL;
3727         cm_event.private_data_len = 0;
3728
3729 #ifdef CONFIG_INFINIBAND_NES_DEBUG
3730         {
3731                 struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3732                                                      &cm_event.local_addr;
3733                 struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3734                                                      &cm_event.remote_addr;
3735                 nes_debug(NES_DBG_CM, "call CM_EVENT REJECTED, local_addr=%08x, remote_addr=%08x\n",
3736                           cm_event_laddr->sin_addr.s_addr, cm_event_raddr->sin_addr.s_addr);
3737         }
3738 #endif
3739
3740         ret = cm_id->event_handler(cm_id, &cm_event);
3741         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3742         if (ret)
3743                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3744                        "ret=%d\n", __func__, __LINE__, ret);
3745         cm_id->rem_ref(cm_id);
3746
3747         rem_ref_cm_node(event->cm_node->cm_core, event->cm_node);
3748         return;
3749 }
3750
3751
3752 /**
3753  * cm_event_reset
3754  */
3755 static void cm_event_reset(struct nes_cm_event *event)
3756 {
3757         struct nes_qp *nesqp;
3758         struct iw_cm_id *cm_id;
3759         struct iw_cm_event cm_event;
3760         /* struct nes_cm_info cm_info; */
3761         int ret;
3762
3763         if (!event->cm_node)
3764                 return;
3765
3766         if (!event->cm_node->cm_id)
3767                 return;
3768
3769         cm_id = event->cm_node->cm_id;
3770
3771         nes_debug(NES_DBG_CM, "%p - cm_id = %p\n", event->cm_node, cm_id);
3772         nesqp = cm_id->provider_data;
3773         if (!nesqp)
3774                 return;
3775
3776         nesqp->cm_id = NULL;
3777         /* cm_id->provider_data = NULL; */
3778         cm_event.event = IW_CM_EVENT_DISCONNECT;
3779         cm_event.status = -ECONNRESET;
3780         cm_event.provider_data = cm_id->provider_data;
3781         cm_event.local_addr = cm_id->m_local_addr;
3782         cm_event.remote_addr = cm_id->m_remote_addr;
3783         cm_event.private_data = NULL;
3784         cm_event.private_data_len = 0;
3785
3786         cm_id->add_ref(cm_id);
3787         ret = cm_id->event_handler(cm_id, &cm_event);
3788         atomic_inc(&cm_closes);
3789         cm_event.event = IW_CM_EVENT_CLOSE;
3790         cm_event.status = 0;
3791         cm_event.provider_data = cm_id->provider_data;
3792         cm_event.local_addr = cm_id->m_local_addr;
3793         cm_event.remote_addr = cm_id->m_remote_addr;
3794         cm_event.private_data = NULL;
3795         cm_event.private_data_len = 0;
3796         nes_debug(NES_DBG_CM, "NODE %p Generating CLOSE\n", event->cm_node);
3797         ret = cm_id->event_handler(cm_id, &cm_event);
3798
3799         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3800
3801
3802         /* notify OF layer about this connection error event */
3803         cm_id->rem_ref(cm_id);
3804
3805         return;
3806 }
3807
3808
3809 /**
3810  * cm_event_mpa_req
3811  */
3812 static void cm_event_mpa_req(struct nes_cm_event *event)
3813 {
3814         struct iw_cm_id *cm_id;
3815         struct iw_cm_event cm_event;
3816         int ret;
3817         struct nes_cm_node *cm_node;
3818         struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3819                                              &cm_event.local_addr;
3820         struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3821                                              &cm_event.remote_addr;
3822
3823         cm_node = event->cm_node;
3824         if (!cm_node)
3825                 return;
3826         cm_id = cm_node->cm_id;
3827
3828         atomic_inc(&cm_connect_reqs);
3829         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3830                   cm_node, cm_id, jiffies);
3831
3832         cm_event.event = IW_CM_EVENT_CONNECT_REQUEST;
3833         cm_event.status = 0;
3834         cm_event.provider_data = (void *)cm_node;
3835
3836         cm_event_laddr->sin_family = AF_INET;
3837         cm_event_laddr->sin_port = htons(event->cm_info.loc_port);
3838         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3839
3840         cm_event_raddr->sin_family = AF_INET;
3841         cm_event_raddr->sin_port = htons(event->cm_info.rem_port);
3842         cm_event_raddr->sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3843         cm_event.private_data = cm_node->mpa_frame_buf;
3844         cm_event.private_data_len = (u8)cm_node->mpa_frame_size;
3845         if (cm_node->mpa_frame_rev == IETF_MPA_V1) {
3846                 cm_event.ird = NES_MAX_IRD;
3847                 cm_event.ord = NES_MAX_ORD;
3848         } else {
3849         cm_event.ird = cm_node->ird_size;
3850         cm_event.ord = cm_node->ord_size;
3851         }
3852
3853         ret = cm_id->event_handler(cm_id, &cm_event);
3854         if (ret)
3855                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3856                        __func__, __LINE__, ret);
3857         return;
3858 }
3859
3860
3861 static void cm_event_mpa_reject(struct nes_cm_event *event)
3862 {
3863         struct iw_cm_id *cm_id;
3864         struct iw_cm_event cm_event;
3865         struct nes_cm_node *cm_node;
3866         int ret;
3867         struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3868                                              &cm_event.local_addr;
3869         struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3870                                              &cm_event.remote_addr;
3871
3872         cm_node = event->cm_node;
3873         if (!cm_node)
3874                 return;
3875         cm_id = cm_node->cm_id;
3876
3877         atomic_inc(&cm_connect_reqs);
3878         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3879                   cm_node, cm_id, jiffies);
3880
3881         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3882         cm_event.status = -ECONNREFUSED;
3883         cm_event.provider_data = cm_id->provider_data;
3884
3885         cm_event_laddr->sin_family = AF_INET;
3886         cm_event_laddr->sin_port = htons(event->cm_info.loc_port);
3887         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3888
3889         cm_event_raddr->sin_family = AF_INET;
3890         cm_event_raddr->sin_port = htons(event->cm_info.rem_port);
3891         cm_event_raddr->sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3892
3893         cm_event.private_data = cm_node->mpa_frame_buf;
3894         cm_event.private_data_len = (u8)cm_node->mpa_frame_size;
3895
3896         nes_debug(NES_DBG_CM, "call CM_EVENT_MPA_REJECTED, local_addr=%08x, "
3897                   "remove_addr=%08x\n",
3898                   cm_event_laddr->sin_addr.s_addr,
3899                   cm_event_raddr->sin_addr.s_addr);
3900
3901         ret = cm_id->event_handler(cm_id, &cm_event);
3902         if (ret)
3903                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3904                        __func__, __LINE__, ret);
3905
3906         return;
3907 }
3908
3909
3910 static void nes_cm_event_handler(struct work_struct *);
3911
3912 /**
3913  * nes_cm_post_event
3914  * post an event to the cm event handler
3915  */
3916 static int nes_cm_post_event(struct nes_cm_event *event)
3917 {
3918         atomic_inc(&event->cm_node->cm_core->events_posted);
3919         add_ref_cm_node(event->cm_node);
3920         event->cm_info.cm_id->add_ref(event->cm_info.cm_id);
3921         INIT_WORK(&event->event_work, nes_cm_event_handler);
3922         nes_debug(NES_DBG_CM, "cm_node=%p queue_work, event=%p\n",
3923                   event->cm_node, event);
3924
3925         queue_work(event->cm_node->cm_core->event_wq, &event->event_work);
3926
3927         nes_debug(NES_DBG_CM, "Exit\n");
3928         return 0;
3929 }
3930
3931
3932 /**
3933  * nes_cm_event_handler
3934  * worker function to handle cm events
3935  * will free instance of nes_cm_event
3936  */
3937 static void nes_cm_event_handler(struct work_struct *work)
3938 {
3939         struct nes_cm_event *event = container_of(work, struct nes_cm_event,
3940                                                   event_work);
3941         struct nes_cm_core *cm_core;
3942
3943         if ((!event) || (!event->cm_node) || (!event->cm_node->cm_core))
3944                 return;
3945
3946         cm_core = event->cm_node->cm_core;
3947         nes_debug(NES_DBG_CM, "event=%p, event->type=%u, events posted=%u\n",
3948                   event, event->type, atomic_read(&cm_core->events_posted));
3949
3950         switch (event->type) {
3951         case NES_CM_EVENT_MPA_REQ:
3952                 cm_event_mpa_req(event);
3953                 nes_debug(NES_DBG_CM, "cm_node=%p CM Event: MPA REQUEST\n",
3954                           event->cm_node);
3955                 break;
3956         case NES_CM_EVENT_RESET:
3957                 nes_debug(NES_DBG_CM, "cm_node = %p CM Event: RESET\n",
3958                           event->cm_node);
3959                 cm_event_reset(event);
3960                 break;
3961         case NES_CM_EVENT_CONNECTED:
3962                 if ((!event->cm_node->cm_id) ||
3963                     (event->cm_node->state != NES_CM_STATE_TSA))
3964                         break;
3965                 cm_event_connected(event);
3966                 nes_debug(NES_DBG_CM, "CM Event: CONNECTED\n");
3967                 break;
3968         case NES_CM_EVENT_MPA_REJECT:
3969                 if ((!event->cm_node->cm_id) ||
3970                     (event->cm_node->state == NES_CM_STATE_TSA))
3971                         break;
3972                 cm_event_mpa_reject(event);
3973                 nes_debug(NES_DBG_CM, "CM Event: REJECT\n");
3974                 break;
3975
3976         case NES_CM_EVENT_ABORTED:
3977                 if ((!event->cm_node->cm_id) ||
3978                     (event->cm_node->state == NES_CM_STATE_TSA))
3979                         break;
3980                 cm_event_connect_error(event);
3981                 nes_debug(NES_DBG_CM, "CM Event: ABORTED\n");
3982                 break;
3983         case NES_CM_EVENT_DROPPED_PKT:
3984                 nes_debug(NES_DBG_CM, "CM Event: DROPPED PKT\n");
3985                 break;
3986         default:
3987                 nes_debug(NES_DBG_CM, "CM Event: UNKNOWN EVENT TYPE\n");
3988                 break;
3989         }
3990
3991         atomic_dec(&cm_core->events_posted);
3992         event->cm_info.cm_id->rem_ref(event->cm_info.cm_id);
3993         rem_ref_cm_node(cm_core, event->cm_node);
3994         kfree(event);
3995
3996         return;
3997 }