GNU Linux-libre 4.19.245-gnu1
[releases.git] / drivers / infiniband / hw / nes / nes_cm.c
1 /*
2  * Copyright (c) 2006 - 2014 Intel Corporation.  All rights reserved.
3  *
4  * This software is available to you under a choice of one of two
5  * licenses.  You may choose to be licensed under the terms of the GNU
6  * General Public License (GPL) Version 2, available from the file
7  * COPYING in the main directory of this source tree, or the
8  * OpenIB.org BSD license below:
9  *
10  *     Redistribution and use in source and binary forms, with or
11  *     without modification, are permitted provided that the following
12  *     conditions are met:
13  *
14  *      - Redistributions of source code must retain the above
15  *        copyright notice, this list of conditions and the following
16  *        disclaimer.
17  *
18  *      - Redistributions in binary form must reproduce the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer in the documentation and/or other materials
21  *        provided with the distribution.
22  *
23  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
24  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
25  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
26  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
27  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
28  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
29  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30  * SOFTWARE.
31  *
32  */
33
34
35 #define TCPOPT_TIMESTAMP 8
36
37 #include <linux/atomic.h>
38 #include <linux/skbuff.h>
39 #include <linux/ip.h>
40 #include <linux/tcp.h>
41 #include <linux/init.h>
42 #include <linux/if_arp.h>
43 #include <linux/if_vlan.h>
44 #include <linux/notifier.h>
45 #include <linux/net.h>
46 #include <linux/types.h>
47 #include <linux/timer.h>
48 #include <linux/time.h>
49 #include <linux/delay.h>
50 #include <linux/etherdevice.h>
51 #include <linux/netdevice.h>
52 #include <linux/random.h>
53 #include <linux/list.h>
54 #include <linux/threads.h>
55 #include <linux/highmem.h>
56 #include <linux/slab.h>
57 #include <net/arp.h>
58 #include <net/neighbour.h>
59 #include <net/route.h>
60 #include <net/ip_fib.h>
61 #include <net/secure_seq.h>
62 #include <net/tcp.h>
63 #include <linux/fcntl.h>
64
65 #include "nes.h"
66
67 u32 cm_packets_sent;
68 u32 cm_packets_bounced;
69 u32 cm_packets_dropped;
70 u32 cm_packets_retrans;
71 u32 cm_packets_created;
72 u32 cm_packets_received;
73 atomic_t cm_listens_created;
74 atomic_t cm_listens_destroyed;
75 u32 cm_backlog_drops;
76 atomic_t cm_loopbacks;
77 atomic_t cm_nodes_created;
78 atomic_t cm_nodes_destroyed;
79 atomic_t cm_accel_dropped_pkts;
80 atomic_t cm_resets_recvd;
81
82 static inline int mini_cm_accelerated(struct nes_cm_core *, struct nes_cm_node *);
83 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *, struct nes_vnic *, struct nes_cm_info *);
84 static int mini_cm_del_listen(struct nes_cm_core *, struct nes_cm_listener *);
85 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *, struct nes_vnic *, u16, void *, struct nes_cm_info *);
86 static int mini_cm_close(struct nes_cm_core *, struct nes_cm_node *);
87 static int mini_cm_accept(struct nes_cm_core *, struct nes_cm_node *);
88 static int mini_cm_reject(struct nes_cm_core *, struct nes_cm_node *);
89 static int mini_cm_recv_pkt(struct nes_cm_core *, struct nes_vnic *, struct sk_buff *);
90 static int mini_cm_dealloc_core(struct nes_cm_core *);
91 static int mini_cm_get(struct nes_cm_core *);
92 static int mini_cm_set(struct nes_cm_core *, u32, u32);
93
94 static void form_cm_frame(struct sk_buff *, struct nes_cm_node *, void *, u32, void *, u32, u8);
95 static int add_ref_cm_node(struct nes_cm_node *);
96 static int rem_ref_cm_node(struct nes_cm_core *, struct nes_cm_node *);
97
98 static int nes_cm_disconn_true(struct nes_qp *);
99 static int nes_cm_post_event(struct nes_cm_event *event);
100 static int nes_disconnect(struct nes_qp *nesqp, int abrupt);
101 static void nes_disconnect_worker(struct work_struct *work);
102
103 static int send_mpa_request(struct nes_cm_node *, struct sk_buff *);
104 static int send_mpa_reject(struct nes_cm_node *);
105 static int send_syn(struct nes_cm_node *, u32, struct sk_buff *);
106 static int send_reset(struct nes_cm_node *, struct sk_buff *);
107 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb);
108 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb);
109 static void process_packet(struct nes_cm_node *, struct sk_buff *, struct nes_cm_core *);
110
111 static void active_open_err(struct nes_cm_node *, struct sk_buff *, int);
112 static void passive_open_err(struct nes_cm_node *, struct sk_buff *, int);
113 static void cleanup_retrans_entry(struct nes_cm_node *);
114 static void handle_rcv_mpa(struct nes_cm_node *, struct sk_buff *);
115 static void free_retrans_entry(struct nes_cm_node *cm_node);
116 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph, struct sk_buff *skb, int optionsize, int passive);
117
118 /* CM event handler functions */
119 static void cm_event_connected(struct nes_cm_event *);
120 static void cm_event_connect_error(struct nes_cm_event *);
121 static void cm_event_reset(struct nes_cm_event *);
122 static void cm_event_mpa_req(struct nes_cm_event *);
123 static void cm_event_mpa_reject(struct nes_cm_event *);
124 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node);
125
126 /* MPA build functions */
127 static int cm_build_mpa_frame(struct nes_cm_node *, u8 **, u16 *, u8 *, u8);
128 static void build_mpa_v2(struct nes_cm_node *, void *, u8);
129 static void build_mpa_v1(struct nes_cm_node *, void *, u8);
130 static void build_rdma0_msg(struct nes_cm_node *, struct nes_qp **);
131
132 static void print_core(struct nes_cm_core *core);
133 static void record_ird_ord(struct nes_cm_node *, u16, u16);
134
135 /* External CM API Interface */
136 /* instance of function pointers for client API */
137 /* set address of this instance to cm_core->cm_ops at cm_core alloc */
138 static const struct nes_cm_ops nes_cm_api = {
139         .accelerated = mini_cm_accelerated,
140         .listen = mini_cm_listen,
141         .stop_listener = mini_cm_del_listen,
142         .connect = mini_cm_connect,
143         .close = mini_cm_close,
144         .accept = mini_cm_accept,
145         .reject = mini_cm_reject,
146         .recv_pkt = mini_cm_recv_pkt,
147         .destroy_cm_core = mini_cm_dealloc_core,
148         .get = mini_cm_get,
149         .set = mini_cm_set
150 };
151
152 static struct nes_cm_core *g_cm_core;
153
154 atomic_t cm_connects;
155 atomic_t cm_accepts;
156 atomic_t cm_disconnects;
157 atomic_t cm_closes;
158 atomic_t cm_connecteds;
159 atomic_t cm_connect_reqs;
160 atomic_t cm_rejects;
161
162 int nes_add_ref_cm_node(struct nes_cm_node *cm_node)
163 {
164         return add_ref_cm_node(cm_node);
165 }
166
167 int nes_rem_ref_cm_node(struct nes_cm_node *cm_node)
168 {
169         return rem_ref_cm_node(cm_node->cm_core, cm_node);
170 }
171 /**
172  * create_event
173  */
174 static struct nes_cm_event *create_event(struct nes_cm_node *   cm_node,
175                                          enum nes_cm_event_type type)
176 {
177         struct nes_cm_event *event;
178
179         if (!cm_node->cm_id)
180                 return NULL;
181
182         /* allocate an empty event */
183         event = kzalloc(sizeof(*event), GFP_ATOMIC);
184
185         if (!event)
186                 return NULL;
187
188         event->type = type;
189         event->cm_node = cm_node;
190         event->cm_info.rem_addr = cm_node->rem_addr;
191         event->cm_info.loc_addr = cm_node->loc_addr;
192         event->cm_info.rem_port = cm_node->rem_port;
193         event->cm_info.loc_port = cm_node->loc_port;
194         event->cm_info.cm_id = cm_node->cm_id;
195
196         nes_debug(NES_DBG_CM, "cm_node=%p Created event=%p, type=%u, "
197                   "dst_addr=%08x[%x], src_addr=%08x[%x]\n",
198                   cm_node, event, type, event->cm_info.loc_addr,
199                   event->cm_info.loc_port, event->cm_info.rem_addr,
200                   event->cm_info.rem_port);
201
202         nes_cm_post_event(event);
203         return event;
204 }
205
206
207 /**
208  * send_mpa_request
209  */
210 static int send_mpa_request(struct nes_cm_node *cm_node, struct sk_buff *skb)
211 {
212         u8 start_addr = 0;
213         u8 *start_ptr = &start_addr;
214         u8 **start_buff = &start_ptr;
215         u16 buff_len = 0;
216
217         if (!skb) {
218                 nes_debug(NES_DBG_CM, "skb set to NULL\n");
219                 return -1;
220         }
221
222         /* send an MPA Request frame */
223         cm_build_mpa_frame(cm_node, start_buff, &buff_len, NULL, MPA_KEY_REQUEST);
224         form_cm_frame(skb, cm_node, NULL, 0, *start_buff, buff_len, SET_ACK);
225
226         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
227 }
228
229
230
231 static int send_mpa_reject(struct nes_cm_node *cm_node)
232 {
233         struct sk_buff *skb = NULL;
234         u8 start_addr = 0;
235         u8 *start_ptr = &start_addr;
236         u8 **start_buff = &start_ptr;
237         u16 buff_len = 0;
238         struct ietf_mpa_v1 *mpa_frame;
239
240         skb = dev_alloc_skb(MAX_CM_BUFFER);
241         if (!skb) {
242                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
243                 return -ENOMEM;
244         }
245
246         /* send an MPA reject frame */
247         cm_build_mpa_frame(cm_node, start_buff, &buff_len, NULL, MPA_KEY_REPLY);
248         mpa_frame = (struct ietf_mpa_v1 *)*start_buff;
249         mpa_frame->flags |= IETF_MPA_FLAGS_REJECT;
250         form_cm_frame(skb, cm_node, NULL, 0, *start_buff, buff_len, SET_ACK | SET_FIN);
251
252         cm_node->state = NES_CM_STATE_FIN_WAIT1;
253         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
254 }
255
256
257 /**
258  * recv_mpa - process a received TCP pkt, we are expecting an
259  * IETF MPA frame
260  */
261 static int parse_mpa(struct nes_cm_node *cm_node, u8 *buffer, u32 *type,
262                      u32 len)
263 {
264         struct ietf_mpa_v1 *mpa_frame;
265         struct ietf_mpa_v2 *mpa_v2_frame;
266         struct ietf_rtr_msg *rtr_msg;
267         int mpa_hdr_len;
268         int priv_data_len;
269
270         *type = NES_MPA_REQUEST_ACCEPT;
271
272         /* assume req frame is in tcp data payload */
273         if (len < sizeof(struct ietf_mpa_v1)) {
274                 nes_debug(NES_DBG_CM, "The received ietf buffer was too small (%x)\n", len);
275                 return -EINVAL;
276         }
277
278         /* points to the beginning of the frame, which could be MPA V1 or V2 */
279         mpa_frame = (struct ietf_mpa_v1 *)buffer;
280         mpa_hdr_len = sizeof(struct ietf_mpa_v1);
281         priv_data_len = ntohs(mpa_frame->priv_data_len);
282
283         /* make sure mpa private data len is less than 512 bytes */
284         if (priv_data_len > IETF_MAX_PRIV_DATA_LEN) {
285                 nes_debug(NES_DBG_CM, "The received Length of Private"
286                           " Data field exceeds 512 octets\n");
287                 return -EINVAL;
288         }
289         /*
290          * make sure MPA receiver interoperate with the
291          * received MPA version and MPA key information
292          *
293          */
294         if (mpa_frame->rev != IETF_MPA_V1 && mpa_frame->rev != IETF_MPA_V2) {
295                 nes_debug(NES_DBG_CM, "The received mpa version"
296                           " is not supported\n");
297                 return -EINVAL;
298         }
299         /*
300         * backwards compatibility only
301         */
302         if (mpa_frame->rev > cm_node->mpa_frame_rev) {
303                 nes_debug(NES_DBG_CM, "The received mpa version"
304                         " can not be interoperated\n");
305                 return -EINVAL;
306         } else {
307                 cm_node->mpa_frame_rev = mpa_frame->rev;
308         }
309
310         if (cm_node->state != NES_CM_STATE_MPAREQ_SENT) {
311                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE)) {
312                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
313                         return -EINVAL;
314                 }
315         } else {
316                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE)) {
317                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
318                         return -EINVAL;
319                 }
320         }
321
322         if (priv_data_len + mpa_hdr_len != len) {
323                 nes_debug(NES_DBG_CM, "The received ietf buffer was not right"
324                         " complete (%x + %x != %x)\n",
325                         priv_data_len, mpa_hdr_len, len);
326                 return -EINVAL;
327         }
328         /* make sure it does not exceed the max size */
329         if (len > MAX_CM_BUFFER) {
330                 nes_debug(NES_DBG_CM, "The received ietf buffer was too large"
331                         " (%x + %x != %x)\n",
332                         priv_data_len, mpa_hdr_len, len);
333                 return -EINVAL;
334         }
335
336         cm_node->mpa_frame_size = priv_data_len;
337
338         switch (mpa_frame->rev) {
339         case IETF_MPA_V2: {
340                 u16 ird_size;
341                 u16 ord_size;
342                 u16 rtr_ctrl_ird;
343                 u16 rtr_ctrl_ord;
344
345                 mpa_v2_frame = (struct ietf_mpa_v2 *)buffer;
346                 mpa_hdr_len += IETF_RTR_MSG_SIZE;
347                 cm_node->mpa_frame_size -= IETF_RTR_MSG_SIZE;
348                 rtr_msg = &mpa_v2_frame->rtr_msg;
349
350                 /* parse rtr message */
351                 rtr_ctrl_ird = ntohs(rtr_msg->ctrl_ird);
352                 rtr_ctrl_ord = ntohs(rtr_msg->ctrl_ord);
353                 ird_size = rtr_ctrl_ird & IETF_NO_IRD_ORD;
354                 ord_size = rtr_ctrl_ord & IETF_NO_IRD_ORD;
355
356                 if (!(rtr_ctrl_ird & IETF_PEER_TO_PEER)) {
357                         /* send reset */
358                         return -EINVAL;
359                 }
360                 if (ird_size == IETF_NO_IRD_ORD || ord_size == IETF_NO_IRD_ORD)
361                         cm_node->mpav2_ird_ord = IETF_NO_IRD_ORD;
362
363                 if (cm_node->mpav2_ird_ord != IETF_NO_IRD_ORD) {
364                         /* responder */
365                         if (cm_node->state != NES_CM_STATE_MPAREQ_SENT) {
366                                 /* we are still negotiating */
367                                 if (ord_size > NES_MAX_IRD) {
368                                         cm_node->ird_size = NES_MAX_IRD;
369                                 } else {
370                                         cm_node->ird_size = ord_size;
371                                         if (ord_size == 0 &&
372                                         (rtr_ctrl_ord & IETF_RDMA0_READ)) {
373                                                 cm_node->ird_size = 1;
374                                                 nes_debug(NES_DBG_CM,
375                                                 "%s: Remote peer doesn't support RDMA0_READ (ord=%u)\n",
376                                                         __func__, ord_size);
377                                         }
378                                 }
379                                 if (ird_size > NES_MAX_ORD)
380                                         cm_node->ord_size = NES_MAX_ORD;
381                                 else
382                                         cm_node->ord_size = ird_size;
383                         } else { /* initiator */
384                                 if (ord_size > NES_MAX_IRD) {
385                                         nes_debug(NES_DBG_CM,
386                                         "%s: Unable to support the requested (ord =%u)\n",
387                                                         __func__, ord_size);
388                                         return -EINVAL;
389                                 }
390                                 cm_node->ird_size = ord_size;
391
392                                 if (ird_size > NES_MAX_ORD) {
393                                         cm_node->ord_size = NES_MAX_ORD;
394                                 } else {
395                                         if (ird_size == 0 &&
396                                         (rtr_ctrl_ord & IETF_RDMA0_READ)) {
397                                                 nes_debug(NES_DBG_CM,
398                                                 "%s: Remote peer doesn't support RDMA0_READ (ird=%u)\n",
399                                                         __func__, ird_size);
400                                                 return -EINVAL;
401                                         } else {
402                                                 cm_node->ord_size = ird_size;
403                                         }
404                                 }
405                         }
406                 }
407
408                 if (rtr_ctrl_ord & IETF_RDMA0_READ) {
409                         cm_node->send_rdma0_op = SEND_RDMA_READ_ZERO;
410
411                 } else if (rtr_ctrl_ord & IETF_RDMA0_WRITE) {
412                         cm_node->send_rdma0_op = SEND_RDMA_WRITE_ZERO;
413                 } else {        /* Not supported RDMA0 operation */
414                         return -EINVAL;
415                 }
416                 break;
417         }
418         case IETF_MPA_V1:
419         default:
420                 break;
421         }
422
423         /* copy entire MPA frame to our cm_node's frame */
424         memcpy(cm_node->mpa_frame_buf, buffer + mpa_hdr_len, cm_node->mpa_frame_size);
425
426         if (mpa_frame->flags & IETF_MPA_FLAGS_REJECT)
427                 *type = NES_MPA_REQUEST_REJECT;
428         return 0;
429 }
430
431
432 /**
433  * form_cm_frame - get a free packet and build empty frame Use
434  * node info to build.
435  */
436 static void form_cm_frame(struct sk_buff *skb,
437                           struct nes_cm_node *cm_node, void *options, u32 optionsize,
438                           void *data, u32 datasize, u8 flags)
439 {
440         struct tcphdr *tcph;
441         struct iphdr *iph;
442         struct ethhdr *ethh;
443         u8 *buf;
444         u16 packetsize = sizeof(*iph);
445
446         packetsize += sizeof(*tcph);
447         packetsize += optionsize + datasize;
448
449         skb_trim(skb, 0);
450         memset(skb->data, 0x00, ETH_HLEN + sizeof(*iph) + sizeof(*tcph));
451
452         buf = skb_put(skb, packetsize + ETH_HLEN);
453
454         ethh = (struct ethhdr *)buf;
455         buf += ETH_HLEN;
456
457         iph = (struct iphdr *)buf;
458         buf += sizeof(*iph);
459         tcph = (struct tcphdr *)buf;
460         skb_reset_mac_header(skb);
461         skb_set_network_header(skb, ETH_HLEN);
462         skb_set_transport_header(skb, ETH_HLEN + sizeof(*iph));
463         buf += sizeof(*tcph);
464
465         skb->ip_summed = CHECKSUM_PARTIAL;
466         if (!(cm_node->netdev->features & NETIF_F_IP_CSUM))
467                 skb->ip_summed = CHECKSUM_NONE;
468         skb->protocol = htons(0x800);
469         skb->data_len = 0;
470         skb->mac_len = ETH_HLEN;
471
472         memcpy(ethh->h_dest, cm_node->rem_mac, ETH_ALEN);
473         memcpy(ethh->h_source, cm_node->loc_mac, ETH_ALEN);
474         ethh->h_proto = htons(0x0800);
475
476         iph->version = IPVERSION;
477         iph->ihl = 5;           /* 5 * 4Byte words, IP headr len */
478         iph->tos = 0;
479         iph->tot_len = htons(packetsize);
480         iph->id = htons(++cm_node->tcp_cntxt.loc_id);
481
482         iph->frag_off = htons(0x4000);
483         iph->ttl = 0x40;
484         iph->protocol = 0x06;   /* IPPROTO_TCP */
485
486         iph->saddr = htonl(cm_node->loc_addr);
487         iph->daddr = htonl(cm_node->rem_addr);
488
489         tcph->source = htons(cm_node->loc_port);
490         tcph->dest = htons(cm_node->rem_port);
491         tcph->seq = htonl(cm_node->tcp_cntxt.loc_seq_num);
492
493         if (flags & SET_ACK) {
494                 cm_node->tcp_cntxt.loc_ack_num = cm_node->tcp_cntxt.rcv_nxt;
495                 tcph->ack_seq = htonl(cm_node->tcp_cntxt.loc_ack_num);
496                 tcph->ack = 1;
497         } else {
498                 tcph->ack_seq = 0;
499         }
500
501         if (flags & SET_SYN) {
502                 cm_node->tcp_cntxt.loc_seq_num++;
503                 tcph->syn = 1;
504         } else {
505                 cm_node->tcp_cntxt.loc_seq_num += datasize;
506         }
507
508         if (flags & SET_FIN) {
509                 cm_node->tcp_cntxt.loc_seq_num++;
510                 tcph->fin = 1;
511         }
512
513         if (flags & SET_RST)
514                 tcph->rst = 1;
515
516         tcph->doff = (u16)((sizeof(*tcph) + optionsize + 3) >> 2);
517         tcph->window = htons(cm_node->tcp_cntxt.rcv_wnd);
518         tcph->urg_ptr = 0;
519         if (optionsize)
520                 memcpy(buf, options, optionsize);
521         buf += optionsize;
522         if (datasize)
523                 memcpy(buf, data, datasize);
524
525         skb_shinfo(skb)->nr_frags = 0;
526         cm_packets_created++;
527 }
528
529 /**
530  * print_core - dump a cm core
531  */
532 static void print_core(struct nes_cm_core *core)
533 {
534         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
535         nes_debug(NES_DBG_CM, "CM Core  -- (core = %p )\n", core);
536         if (!core)
537                 return;
538         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
539
540         nes_debug(NES_DBG_CM, "State         : %u \n", core->state);
541
542         nes_debug(NES_DBG_CM, "Listen Nodes  : %u \n", atomic_read(&core->listen_node_cnt));
543         nes_debug(NES_DBG_CM, "Active Nodes  : %u \n", atomic_read(&core->node_cnt));
544
545         nes_debug(NES_DBG_CM, "core          : %p \n", core);
546
547         nes_debug(NES_DBG_CM, "-------------- end core ---------------\n");
548 }
549
550 static void record_ird_ord(struct nes_cm_node *cm_node,
551                                         u16 conn_ird, u16 conn_ord)
552 {
553         if (conn_ird > NES_MAX_IRD)
554                 conn_ird = NES_MAX_IRD;
555
556         if (conn_ord > NES_MAX_ORD)
557                 conn_ord = NES_MAX_ORD;
558
559         cm_node->ird_size = conn_ird;
560         cm_node->ord_size = conn_ord;
561 }
562
563 /**
564  * cm_build_mpa_frame - build a MPA V1 frame or MPA V2 frame
565  */
566 static int cm_build_mpa_frame(struct nes_cm_node *cm_node, u8 **start_buff,
567                               u16 *buff_len, u8 *pci_mem, u8 mpa_key)
568 {
569         int ret = 0;
570
571         *start_buff = (pci_mem) ? pci_mem : &cm_node->mpa_frame_buf[0];
572
573         switch (cm_node->mpa_frame_rev) {
574         case IETF_MPA_V1:
575                 *start_buff = (u8 *)*start_buff + sizeof(struct ietf_rtr_msg);
576                 *buff_len = sizeof(struct ietf_mpa_v1) + cm_node->mpa_frame_size;
577                 build_mpa_v1(cm_node, *start_buff, mpa_key);
578                 break;
579         case IETF_MPA_V2:
580                 *buff_len = sizeof(struct ietf_mpa_v2) + cm_node->mpa_frame_size;
581                 build_mpa_v2(cm_node, *start_buff, mpa_key);
582                 break;
583         default:
584                 ret = -EINVAL;
585         }
586         return ret;
587 }
588
589 /**
590  * build_mpa_v2 - build a MPA V2 frame
591  */
592 static void build_mpa_v2(struct nes_cm_node *cm_node,
593                          void *start_addr, u8 mpa_key)
594 {
595         struct ietf_mpa_v2 *mpa_frame = (struct ietf_mpa_v2 *)start_addr;
596         struct ietf_rtr_msg *rtr_msg = &mpa_frame->rtr_msg;
597         u16 ctrl_ird;
598         u16 ctrl_ord;
599
600         /* initialize the upper 5 bytes of the frame */
601         build_mpa_v1(cm_node, start_addr, mpa_key);
602         mpa_frame->flags |= IETF_MPA_V2_FLAG; /* set a bit to indicate MPA V2 */
603         mpa_frame->priv_data_len += htons(IETF_RTR_MSG_SIZE);
604
605         /* initialize RTR msg */
606         if (cm_node->mpav2_ird_ord == IETF_NO_IRD_ORD) {
607                 ctrl_ird = IETF_NO_IRD_ORD;
608                 ctrl_ord = IETF_NO_IRD_ORD;
609         } else {
610                 ctrl_ird = cm_node->ird_size & IETF_NO_IRD_ORD;
611                 ctrl_ord = cm_node->ord_size & IETF_NO_IRD_ORD;
612         }
613         ctrl_ird |= IETF_PEER_TO_PEER;
614
615         switch (mpa_key) {
616         case MPA_KEY_REQUEST:
617                 ctrl_ord |= IETF_RDMA0_WRITE;
618                 ctrl_ord |= IETF_RDMA0_READ;
619                 break;
620         case MPA_KEY_REPLY:
621                 switch (cm_node->send_rdma0_op) {
622                 case SEND_RDMA_WRITE_ZERO:
623                         ctrl_ord |= IETF_RDMA0_WRITE;
624                         break;
625                 case SEND_RDMA_READ_ZERO:
626                         ctrl_ord |= IETF_RDMA0_READ;
627                         break;
628                 }
629         }
630         rtr_msg->ctrl_ird = htons(ctrl_ird);
631         rtr_msg->ctrl_ord = htons(ctrl_ord);
632 }
633
634 /**
635  * build_mpa_v1 - build a MPA V1 frame
636  */
637 static void build_mpa_v1(struct nes_cm_node *cm_node, void *start_addr, u8 mpa_key)
638 {
639         struct ietf_mpa_v1 *mpa_frame = (struct ietf_mpa_v1 *)start_addr;
640
641         switch (mpa_key) {
642         case MPA_KEY_REQUEST:
643                 memcpy(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE);
644                 break;
645         case MPA_KEY_REPLY:
646                 memcpy(mpa_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE);
647                 break;
648         }
649         mpa_frame->flags = IETF_MPA_FLAGS_CRC;
650         mpa_frame->rev = cm_node->mpa_frame_rev;
651         mpa_frame->priv_data_len = htons(cm_node->mpa_frame_size);
652 }
653
654 static void build_rdma0_msg(struct nes_cm_node *cm_node, struct nes_qp **nesqp_addr)
655 {
656         u64 u64temp;
657         struct nes_qp *nesqp = *nesqp_addr;
658         struct nes_hw_qp_wqe *wqe = &nesqp->hwqp.sq_vbase[0];
659
660         u64temp = (unsigned long)nesqp->nesuqp_addr;
661         u64temp |= NES_SW_CONTEXT_ALIGN >> 1;
662         set_wqe_64bit_value(wqe->wqe_words, NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX, u64temp);
663
664         wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_LOW_IDX] = 0;
665         wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_HIGH_IDX] = 0;
666
667         switch (cm_node->send_rdma0_op) {
668         case SEND_RDMA_WRITE_ZERO:
669                 nes_debug(NES_DBG_CM, "Sending first write.\n");
670                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
671                         cpu_to_le32(NES_IWARP_SQ_OP_RDMAW);
672                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] = 0;
673                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] = 0;
674                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = 0;
675                 break;
676
677         case SEND_RDMA_READ_ZERO:
678         default:
679                 if (cm_node->send_rdma0_op != SEND_RDMA_READ_ZERO)
680                         WARN(1, "Unsupported RDMA0 len operation=%u\n",
681                              cm_node->send_rdma0_op);
682                 nes_debug(NES_DBG_CM, "Sending first rdma operation.\n");
683                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
684                         cpu_to_le32(NES_IWARP_SQ_OP_RDMAR);
685                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_TO_LOW_IDX] = 1;
686                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_TO_HIGH_IDX] = 0;
687                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_LENGTH_IDX] = 0;
688                 wqe->wqe_words[NES_IWARP_SQ_WQE_RDMA_STAG_IDX] = 1;
689                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = 1;
690                 break;
691         }
692
693         if (nesqp->sq_kmapped) {
694                 nesqp->sq_kmapped = 0;
695                 kunmap(nesqp->page);
696         }
697
698         /*use the reserved spot on the WQ for the extra first WQE*/
699         nesqp->nesqp_context->ird_ord_sizes &= cpu_to_le32(~(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
700                                                              NES_QPCONTEXT_ORDIRD_WRPDU |
701                                                              NES_QPCONTEXT_ORDIRD_ALSMM));
702         nesqp->skip_lsmm = 1;
703         nesqp->hwqp.sq_tail = 0;
704 }
705
706 /**
707  * schedule_nes_timer
708  * note - cm_node needs to be protected before calling this. Encase in:
709  *                      rem_ref_cm_node(cm_core, cm_node);add_ref_cm_node(cm_node);
710  */
711 int schedule_nes_timer(struct nes_cm_node *cm_node, struct sk_buff *skb,
712                        enum nes_timer_type type, int send_retrans,
713                        int close_when_complete)
714 {
715         unsigned long flags;
716         struct nes_cm_core *cm_core = cm_node->cm_core;
717         struct nes_timer_entry *new_send;
718         int ret = 0;
719
720         new_send = kzalloc(sizeof(*new_send), GFP_ATOMIC);
721         if (!new_send)
722                 return -ENOMEM;
723
724         /* new_send->timetosend = currenttime */
725         new_send->retrycount = NES_DEFAULT_RETRYS;
726         new_send->retranscount = NES_DEFAULT_RETRANS;
727         new_send->skb = skb;
728         new_send->timetosend = jiffies;
729         new_send->type = type;
730         new_send->netdev = cm_node->netdev;
731         new_send->send_retrans = send_retrans;
732         new_send->close_when_complete = close_when_complete;
733
734         if (type == NES_TIMER_TYPE_CLOSE) {
735                 new_send->timetosend += (HZ / 10);
736                 if (cm_node->recv_entry) {
737                         kfree(new_send);
738                         WARN_ON(1);
739                         return -EINVAL;
740                 }
741                 cm_node->recv_entry = new_send;
742         }
743
744         if (type == NES_TIMER_TYPE_SEND) {
745                 new_send->seq_num = ntohl(tcp_hdr(skb)->seq);
746                 refcount_inc(&new_send->skb->users);
747                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
748                 cm_node->send_entry = new_send;
749                 add_ref_cm_node(cm_node);
750                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
751                 new_send->timetosend = jiffies + NES_RETRY_TIMEOUT;
752
753                 ret = nes_nic_cm_xmit(new_send->skb, cm_node->netdev);
754                 if (ret != NETDEV_TX_OK) {
755                         nes_debug(NES_DBG_CM, "Error sending packet %p "
756                                   "(jiffies = %lu)\n", new_send, jiffies);
757                         new_send->timetosend = jiffies;
758                         ret = NETDEV_TX_OK;
759                 } else {
760                         cm_packets_sent++;
761                         if (!send_retrans) {
762                                 cleanup_retrans_entry(cm_node);
763                                 if (close_when_complete)
764                                         rem_ref_cm_node(cm_core, cm_node);
765                                 return ret;
766                         }
767                 }
768         }
769
770         if (!timer_pending(&cm_core->tcp_timer))
771                 mod_timer(&cm_core->tcp_timer, new_send->timetosend);
772
773         return ret;
774 }
775
776 static void nes_retrans_expired(struct nes_cm_node *cm_node)
777 {
778         struct iw_cm_id *cm_id = cm_node->cm_id;
779         enum nes_cm_node_state state = cm_node->state;
780         cm_node->state = NES_CM_STATE_CLOSED;
781
782         switch (state) {
783         case NES_CM_STATE_SYN_RCVD:
784         case NES_CM_STATE_CLOSING:
785                 rem_ref_cm_node(cm_node->cm_core, cm_node);
786                 break;
787         case NES_CM_STATE_LAST_ACK:
788         case NES_CM_STATE_FIN_WAIT1:
789                 if (cm_node->cm_id)
790                         cm_id->rem_ref(cm_id);
791                 send_reset(cm_node, NULL);
792                 break;
793         default:
794                 add_ref_cm_node(cm_node);
795                 send_reset(cm_node, NULL);
796                 create_event(cm_node, NES_CM_EVENT_ABORTED);
797         }
798 }
799
800 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node)
801 {
802         struct nes_timer_entry *recv_entry = cm_node->recv_entry;
803         struct iw_cm_id *cm_id = cm_node->cm_id;
804         struct nes_qp *nesqp;
805         unsigned long qplockflags;
806
807         if (!recv_entry)
808                 return;
809         nesqp = (struct nes_qp *)recv_entry->skb;
810         if (nesqp) {
811                 spin_lock_irqsave(&nesqp->lock, qplockflags);
812                 if (nesqp->cm_id) {
813                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
814                                   "refcount = %d: HIT A "
815                                   "NES_TIMER_TYPE_CLOSE with something "
816                                   "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
817                                   atomic_read(&nesqp->refcount));
818                         nesqp->hw_tcp_state = NES_AEQE_TCP_STATE_CLOSED;
819                         nesqp->last_aeq = NES_AEQE_AEID_RESET_SENT;
820                         nesqp->ibqp_state = IB_QPS_ERR;
821                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
822                         nes_cm_disconn(nesqp);
823                 } else {
824                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
825                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
826                                   "refcount = %d: HIT A "
827                                   "NES_TIMER_TYPE_CLOSE with nothing "
828                                   "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
829                                   atomic_read(&nesqp->refcount));
830                 }
831         } else if (rem_node) {
832                 /* TIME_WAIT state */
833                 rem_ref_cm_node(cm_node->cm_core, cm_node);
834         }
835         if (cm_node->cm_id)
836                 cm_id->rem_ref(cm_id);
837         kfree(recv_entry);
838         cm_node->recv_entry = NULL;
839 }
840
841 /**
842  * nes_cm_timer_tick
843  */
844 static void nes_cm_timer_tick(struct timer_list *unused)
845 {
846         unsigned long flags;
847         unsigned long nexttimeout = jiffies + NES_LONG_TIME;
848         struct nes_cm_node *cm_node;
849         struct nes_timer_entry *send_entry, *recv_entry;
850         struct list_head *list_core_temp;
851         struct list_head *list_node;
852         struct nes_cm_core *cm_core = g_cm_core;
853         u32 settimer = 0;
854         unsigned long timetosend;
855         int ret = NETDEV_TX_OK;
856
857         struct list_head timer_list;
858
859         INIT_LIST_HEAD(&timer_list);
860         spin_lock_irqsave(&cm_core->ht_lock, flags);
861
862         list_for_each_safe(list_node, list_core_temp,
863                            &cm_core->connected_nodes) {
864                 cm_node = container_of(list_node, struct nes_cm_node, list);
865                 if ((cm_node->recv_entry) || (cm_node->send_entry)) {
866                         add_ref_cm_node(cm_node);
867                         list_add(&cm_node->timer_entry, &timer_list);
868                 }
869         }
870         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
871
872         list_for_each_safe(list_node, list_core_temp, &timer_list) {
873                 cm_node = container_of(list_node, struct nes_cm_node,
874                                        timer_entry);
875                 recv_entry = cm_node->recv_entry;
876
877                 if (recv_entry) {
878                         if (time_after(recv_entry->timetosend, jiffies)) {
879                                 if (nexttimeout > recv_entry->timetosend ||
880                                     !settimer) {
881                                         nexttimeout = recv_entry->timetosend;
882                                         settimer = 1;
883                                 }
884                         } else {
885                                 handle_recv_entry(cm_node, 1);
886                         }
887                 }
888
889                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
890                 do {
891                         send_entry = cm_node->send_entry;
892                         if (!send_entry)
893                                 break;
894                         if (time_after(send_entry->timetosend, jiffies)) {
895                                 if (cm_node->state != NES_CM_STATE_TSA) {
896                                         if ((nexttimeout >
897                                              send_entry->timetosend) ||
898                                             !settimer) {
899                                                 nexttimeout =
900                                                         send_entry->timetosend;
901                                                 settimer = 1;
902                                         }
903                                 } else {
904                                         free_retrans_entry(cm_node);
905                                 }
906                                 break;
907                         }
908
909                         if ((cm_node->state == NES_CM_STATE_TSA) ||
910                             (cm_node->state == NES_CM_STATE_CLOSED)) {
911                                 free_retrans_entry(cm_node);
912                                 break;
913                         }
914
915                         if (!send_entry->retranscount ||
916                             !send_entry->retrycount) {
917                                 cm_packets_dropped++;
918                                 free_retrans_entry(cm_node);
919
920                                 spin_unlock_irqrestore(
921                                         &cm_node->retrans_list_lock, flags);
922                                 nes_retrans_expired(cm_node);
923                                 cm_node->state = NES_CM_STATE_CLOSED;
924                                 spin_lock_irqsave(&cm_node->retrans_list_lock,
925                                                   flags);
926                                 break;
927                         }
928                         refcount_inc(&send_entry->skb->users);
929                         cm_packets_retrans++;
930                         nes_debug(NES_DBG_CM, "Retransmitting send_entry %p "
931                                   "for node %p, jiffies = %lu, time to send = "
932                                   "%lu, retranscount = %u, send_entry->seq_num = "
933                                   "0x%08X, cm_node->tcp_cntxt.rem_ack_num = "
934                                   "0x%08X\n", send_entry, cm_node, jiffies,
935                                   send_entry->timetosend,
936                                   send_entry->retranscount,
937                                   send_entry->seq_num,
938                                   cm_node->tcp_cntxt.rem_ack_num);
939
940                         spin_unlock_irqrestore(&cm_node->retrans_list_lock,
941                                                flags);
942                         ret = nes_nic_cm_xmit(send_entry->skb, cm_node->netdev);
943                         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
944                         if (ret != NETDEV_TX_OK) {
945                                 nes_debug(NES_DBG_CM, "rexmit failed for "
946                                           "node=%p\n", cm_node);
947                                 cm_packets_bounced++;
948                                 send_entry->retrycount--;
949                                 nexttimeout = jiffies + NES_SHORT_TIME;
950                                 settimer = 1;
951                                 break;
952                         } else {
953                                 cm_packets_sent++;
954                         }
955                         nes_debug(NES_DBG_CM, "Packet Sent: retrans count = "
956                                   "%u, retry count = %u.\n",
957                                   send_entry->retranscount,
958                                   send_entry->retrycount);
959                         if (send_entry->send_retrans) {
960                                 send_entry->retranscount--;
961                                 timetosend = (NES_RETRY_TIMEOUT <<
962                                               (NES_DEFAULT_RETRANS - send_entry->retranscount));
963
964                                 send_entry->timetosend = jiffies +
965                                                          min(timetosend, NES_MAX_TIMEOUT);
966                                 if (nexttimeout > send_entry->timetosend ||
967                                     !settimer) {
968                                         nexttimeout = send_entry->timetosend;
969                                         settimer = 1;
970                                 }
971                         } else {
972                                 int close_when_complete;
973                                 close_when_complete =
974                                         send_entry->close_when_complete;
975                                 nes_debug(NES_DBG_CM, "cm_node=%p state=%d\n",
976                                           cm_node, cm_node->state);
977                                 free_retrans_entry(cm_node);
978                                 if (close_when_complete)
979                                         rem_ref_cm_node(cm_node->cm_core,
980                                                         cm_node);
981                         }
982                 } while (0);
983
984                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
985                 rem_ref_cm_node(cm_node->cm_core, cm_node);
986         }
987
988         if (settimer) {
989                 if (!timer_pending(&cm_core->tcp_timer))
990                         mod_timer(&cm_core->tcp_timer, nexttimeout);
991         }
992 }
993
994
995 /**
996  * send_syn
997  */
998 static int send_syn(struct nes_cm_node *cm_node, u32 sendack,
999                     struct sk_buff *skb)
1000 {
1001         int ret;
1002         int flags = SET_SYN;
1003         char optionsbuffer[sizeof(struct option_mss) +
1004                            sizeof(struct option_windowscale) + sizeof(struct option_base) +
1005                            TCP_OPTIONS_PADDING];
1006
1007         int optionssize = 0;
1008         /* Sending MSS option */
1009         union all_known_options *options;
1010
1011         if (!cm_node)
1012                 return -EINVAL;
1013
1014         options = (union all_known_options *)&optionsbuffer[optionssize];
1015         options->as_mss.optionnum = OPTION_NUMBER_MSS;
1016         options->as_mss.length = sizeof(struct option_mss);
1017         options->as_mss.mss = htons(cm_node->tcp_cntxt.mss);
1018         optionssize += sizeof(struct option_mss);
1019
1020         options = (union all_known_options *)&optionsbuffer[optionssize];
1021         options->as_windowscale.optionnum = OPTION_NUMBER_WINDOW_SCALE;
1022         options->as_windowscale.length = sizeof(struct option_windowscale);
1023         options->as_windowscale.shiftcount = cm_node->tcp_cntxt.rcv_wscale;
1024         optionssize += sizeof(struct option_windowscale);
1025
1026         if (sendack && !(NES_DRV_OPT_SUPRESS_OPTION_BC & nes_drv_opt)) {
1027                 options = (union all_known_options *)&optionsbuffer[optionssize];
1028                 options->as_base.optionnum = OPTION_NUMBER_WRITE0;
1029                 options->as_base.length = sizeof(struct option_base);
1030                 optionssize += sizeof(struct option_base);
1031                 /* we need the size to be a multiple of 4 */
1032                 options = (union all_known_options *)&optionsbuffer[optionssize];
1033                 options->as_end = 1;
1034                 optionssize += 1;
1035                 options = (union all_known_options *)&optionsbuffer[optionssize];
1036                 options->as_end = 1;
1037                 optionssize += 1;
1038         }
1039
1040         options = (union all_known_options *)&optionsbuffer[optionssize];
1041         options->as_end = OPTION_NUMBER_END;
1042         optionssize += 1;
1043
1044         if (!skb)
1045                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1046         if (!skb) {
1047                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1048                 return -1;
1049         }
1050
1051         if (sendack)
1052                 flags |= SET_ACK;
1053
1054         form_cm_frame(skb, cm_node, optionsbuffer, optionssize, NULL, 0, flags);
1055         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
1056
1057         return ret;
1058 }
1059
1060
1061 /**
1062  * send_reset
1063  */
1064 static int send_reset(struct nes_cm_node *cm_node, struct sk_buff *skb)
1065 {
1066         int ret;
1067         int flags = SET_RST | SET_ACK;
1068
1069         if (!skb)
1070                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1071         if (!skb) {
1072                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1073                 return -ENOMEM;
1074         }
1075
1076         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, flags);
1077         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 1);
1078
1079         return ret;
1080 }
1081
1082
1083 /**
1084  * send_ack
1085  */
1086 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb)
1087 {
1088         int ret;
1089
1090         if (!skb)
1091                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1092
1093         if (!skb) {
1094                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1095                 return -1;
1096         }
1097
1098         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK);
1099         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 0);
1100
1101         return ret;
1102 }
1103
1104
1105 /**
1106  * send_fin
1107  */
1108 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb)
1109 {
1110         int ret;
1111
1112         /* if we didn't get a frame get one */
1113         if (!skb)
1114                 skb = dev_alloc_skb(MAX_CM_BUFFER);
1115
1116         if (!skb) {
1117                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
1118                 return -1;
1119         }
1120
1121         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK | SET_FIN);
1122         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
1123
1124         return ret;
1125 }
1126
1127
1128 /**
1129  * find_node - find a cm node that matches the reference cm node
1130  */
1131 static struct nes_cm_node *find_node(struct nes_cm_core *cm_core,
1132                                      u16 rem_port, nes_addr_t rem_addr, u16 loc_port, nes_addr_t loc_addr)
1133 {
1134         unsigned long flags;
1135         struct list_head *hte;
1136         struct nes_cm_node *cm_node;
1137
1138         /* get a handle on the hte */
1139         hte = &cm_core->connected_nodes;
1140
1141         /* walk list and find cm_node associated with this session ID */
1142         spin_lock_irqsave(&cm_core->ht_lock, flags);
1143         list_for_each_entry(cm_node, hte, list) {
1144                 /* compare quad, return node handle if a match */
1145                 nes_debug(NES_DBG_CM, "finding node %x:%x =? %x:%x ^ %x:%x =? %x:%x\n",
1146                           cm_node->loc_addr, cm_node->loc_port,
1147                           loc_addr, loc_port,
1148                           cm_node->rem_addr, cm_node->rem_port,
1149                           rem_addr, rem_port);
1150                 if ((cm_node->loc_addr == loc_addr) &&
1151                     (cm_node->loc_port == loc_port) &&
1152                     (cm_node->rem_addr == rem_addr) &&
1153                     (cm_node->rem_port == rem_port)) {
1154                         add_ref_cm_node(cm_node);
1155                         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1156                         return cm_node;
1157                 }
1158         }
1159         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1160
1161         /* no owner node */
1162         return NULL;
1163 }
1164
1165
1166 /**
1167  * find_listener - find a cm node listening on this addr-port pair
1168  */
1169 static struct nes_cm_listener *find_listener(struct nes_cm_core *cm_core,
1170                                              nes_addr_t dst_addr, u16 dst_port,
1171                                              enum nes_cm_listener_state listener_state)
1172 {
1173         unsigned long flags;
1174         struct nes_cm_listener *listen_node;
1175         nes_addr_t listen_addr;
1176         u16 listen_port;
1177
1178         /* walk list and find cm_node associated with this session ID */
1179         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
1180         list_for_each_entry(listen_node, &cm_core->listen_list.list, list) {
1181                 listen_addr = listen_node->loc_addr;
1182                 listen_port = listen_node->loc_port;
1183
1184                 /* compare node pair, return node handle if a match */
1185                 if (((listen_addr == dst_addr) ||
1186                      listen_addr == 0x00000000) &&
1187                     (listen_port == dst_port) &&
1188                     (listener_state & listen_node->listener_state)) {
1189                         atomic_inc(&listen_node->ref_count);
1190                         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1191                         return listen_node;
1192                 }
1193         }
1194         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1195
1196         /* no listener */
1197         return NULL;
1198 }
1199
1200 /**
1201  * add_hte_node - add a cm node to the hash table
1202  */
1203 static int add_hte_node(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
1204 {
1205         unsigned long flags;
1206         struct list_head *hte;
1207
1208         if (!cm_node || !cm_core)
1209                 return -EINVAL;
1210
1211         nes_debug(NES_DBG_CM, "Adding Node %p to Active Connection HT\n",
1212                   cm_node);
1213
1214         spin_lock_irqsave(&cm_core->ht_lock, flags);
1215
1216         /* get a handle on the hash table element (list head for this slot) */
1217         hte = &cm_core->connected_nodes;
1218         list_add_tail(&cm_node->list, hte);
1219         atomic_inc(&cm_core->ht_node_cnt);
1220
1221         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1222
1223         return 0;
1224 }
1225
1226
1227 /**
1228  * mini_cm_dec_refcnt_listen
1229  */
1230 static int mini_cm_dec_refcnt_listen(struct nes_cm_core *cm_core,
1231                                      struct nes_cm_listener *listener, int free_hanging_nodes)
1232 {
1233         int ret = -EINVAL;
1234         int err = 0;
1235         unsigned long flags;
1236         struct list_head *list_pos = NULL;
1237         struct list_head *list_temp = NULL;
1238         struct nes_cm_node *cm_node = NULL;
1239         struct list_head reset_list;
1240
1241         nes_debug(NES_DBG_CM, "attempting listener= %p free_nodes= %d, "
1242                   "refcnt=%d\n", listener, free_hanging_nodes,
1243                   atomic_read(&listener->ref_count));
1244         /* free non-accelerated child nodes for this listener */
1245         INIT_LIST_HEAD(&reset_list);
1246         if (free_hanging_nodes) {
1247                 spin_lock_irqsave(&cm_core->ht_lock, flags);
1248                 list_for_each_safe(list_pos, list_temp,
1249                                    &g_cm_core->connected_nodes) {
1250                         cm_node = container_of(list_pos, struct nes_cm_node,
1251                                                list);
1252                         if ((cm_node->listener == listener) &&
1253                             (!cm_node->accelerated)) {
1254                                 add_ref_cm_node(cm_node);
1255                                 list_add(&cm_node->reset_entry, &reset_list);
1256                         }
1257                 }
1258                 spin_unlock_irqrestore(&cm_core->ht_lock, flags);
1259         }
1260
1261         list_for_each_safe(list_pos, list_temp, &reset_list) {
1262                 cm_node = container_of(list_pos, struct nes_cm_node,
1263                                        reset_entry);
1264                 {
1265                         struct nes_cm_node *loopback = cm_node->loopbackpartner;
1266                         enum nes_cm_node_state old_state;
1267                         if (NES_CM_STATE_FIN_WAIT1 <= cm_node->state) {
1268                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1269                         } else {
1270                                 if (!loopback) {
1271                                         cleanup_retrans_entry(cm_node);
1272                                         err = send_reset(cm_node, NULL);
1273                                         if (err) {
1274                                                 cm_node->state =
1275                                                         NES_CM_STATE_CLOSED;
1276                                                 WARN_ON(1);
1277                                         } else {
1278                                                 old_state = cm_node->state;
1279                                                 cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
1280                                                 if (old_state != NES_CM_STATE_MPAREQ_RCVD)
1281                                                         rem_ref_cm_node(
1282                                                                 cm_node->cm_core,
1283                                                                 cm_node);
1284                                         }
1285                                 } else {
1286                                         struct nes_cm_event event;
1287
1288                                         event.cm_node = loopback;
1289                                         event.cm_info.rem_addr =
1290                                                         loopback->rem_addr;
1291                                         event.cm_info.loc_addr =
1292                                                         loopback->loc_addr;
1293                                         event.cm_info.rem_port =
1294                                                         loopback->rem_port;
1295                                         event.cm_info.loc_port =
1296                                                          loopback->loc_port;
1297                                         event.cm_info.cm_id = loopback->cm_id;
1298                                         add_ref_cm_node(loopback);
1299                                         loopback->state = NES_CM_STATE_CLOSED;
1300                                         cm_event_connect_error(&event);
1301                                         cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
1302
1303                                         rem_ref_cm_node(cm_node->cm_core,
1304                                                          cm_node);
1305
1306                                 }
1307                         }
1308                 }
1309         }
1310
1311         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
1312         if (!atomic_dec_return(&listener->ref_count)) {
1313                 list_del(&listener->list);
1314
1315                 /* decrement our listen node count */
1316                 atomic_dec(&cm_core->listen_node_cnt);
1317
1318                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1319
1320                 if (listener->nesvnic) {
1321                         nes_manage_apbvt(listener->nesvnic,
1322                                 listener->loc_port,
1323                                 PCI_FUNC(listener->nesvnic->nesdev->pcidev->devfn),
1324                                 NES_MANAGE_APBVT_DEL);
1325
1326                         nes_debug(NES_DBG_NLMSG,
1327                                         "Delete APBVT loc_port = %04X\n",
1328                                         listener->loc_port);
1329                 }
1330
1331                 nes_debug(NES_DBG_CM, "destroying listener (%p)\n", listener);
1332
1333                 kfree(listener);
1334                 listener = NULL;
1335                 ret = 0;
1336                 atomic_inc(&cm_listens_destroyed);
1337         } else {
1338                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1339         }
1340         if (listener) {
1341                 if (atomic_read(&listener->pend_accepts_cnt) > 0)
1342                         nes_debug(NES_DBG_CM, "destroying listener (%p)"
1343                                   " with non-zero pending accepts=%u\n",
1344                                   listener, atomic_read(&listener->pend_accepts_cnt));
1345         }
1346
1347         return ret;
1348 }
1349
1350
1351 /**
1352  * mini_cm_del_listen
1353  */
1354 static int mini_cm_del_listen(struct nes_cm_core *cm_core,
1355                               struct nes_cm_listener *listener)
1356 {
1357         listener->listener_state = NES_CM_LISTENER_PASSIVE_STATE;
1358         listener->cm_id = NULL; /* going to be destroyed pretty soon */
1359         return mini_cm_dec_refcnt_listen(cm_core, listener, 1);
1360 }
1361
1362
1363 /**
1364  * mini_cm_accelerated
1365  */
1366 static inline int mini_cm_accelerated(struct nes_cm_core *cm_core,
1367                                       struct nes_cm_node *cm_node)
1368 {
1369         cm_node->accelerated = true;
1370
1371         if (cm_node->accept_pend) {
1372                 BUG_ON(!cm_node->listener);
1373                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1374                 cm_node->accept_pend = 0;
1375                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1376         }
1377
1378         if (!timer_pending(&cm_core->tcp_timer))
1379                 mod_timer(&cm_core->tcp_timer, (jiffies + NES_SHORT_TIME));
1380
1381         return 0;
1382 }
1383
1384
1385 /**
1386  * nes_addr_resolve_neigh
1387  */
1388 static int nes_addr_resolve_neigh(struct nes_vnic *nesvnic, u32 dst_ip, int arpindex)
1389 {
1390         struct rtable *rt;
1391         struct neighbour *neigh;
1392         int rc = arpindex;
1393         struct nes_adapter *nesadapter = nesvnic->nesdev->nesadapter;
1394         __be32 dst_ipaddr = htonl(dst_ip);
1395
1396         rt = ip_route_output(&init_net, dst_ipaddr, nesvnic->local_ipaddr, 0, 0);
1397         if (IS_ERR(rt)) {
1398                 printk(KERN_ERR "%s: ip_route_output_key failed for 0x%08X\n",
1399                        __func__, dst_ip);
1400                 return rc;
1401         }
1402
1403         neigh = dst_neigh_lookup(&rt->dst, &dst_ipaddr);
1404
1405         rcu_read_lock();
1406         if (neigh) {
1407                 if (neigh->nud_state & NUD_VALID) {
1408                         nes_debug(NES_DBG_CM, "Neighbor MAC address for 0x%08X"
1409                                   " is %pM, Gateway is 0x%08X \n", dst_ip,
1410                                   neigh->ha, ntohl(rt->rt_gateway));
1411
1412                         if (arpindex >= 0) {
1413                                 if (ether_addr_equal(nesadapter->arp_table[arpindex].mac_addr, neigh->ha)) {
1414                                         /* Mac address same as in nes_arp_table */
1415                                         goto out;
1416                                 }
1417
1418                                 nes_manage_arp_cache(nesvnic->netdev,
1419                                                      nesadapter->arp_table[arpindex].mac_addr,
1420                                                      dst_ip, NES_ARP_DELETE);
1421                         }
1422
1423                         nes_manage_arp_cache(nesvnic->netdev, neigh->ha,
1424                                              dst_ip, NES_ARP_ADD);
1425                         rc = nes_arp_table(nesvnic->nesdev, dst_ip, NULL,
1426                                            NES_ARP_RESOLVE);
1427                 } else {
1428                         neigh_event_send(neigh, NULL);
1429                 }
1430         }
1431 out:
1432         rcu_read_unlock();
1433
1434         if (neigh)
1435                 neigh_release(neigh);
1436
1437         ip_rt_put(rt);
1438         return rc;
1439 }
1440
1441 /**
1442  * make_cm_node - create a new instance of a cm node
1443  */
1444 static struct nes_cm_node *make_cm_node(struct nes_cm_core *cm_core,
1445                                         struct nes_vnic *nesvnic, struct nes_cm_info *cm_info,
1446                                         struct nes_cm_listener *listener)
1447 {
1448         struct nes_cm_node *cm_node;
1449         int oldarpindex = 0;
1450         int arpindex = 0;
1451         struct nes_device *nesdev;
1452         struct nes_adapter *nesadapter;
1453
1454         /* create an hte and cm_node for this instance */
1455         cm_node = kzalloc(sizeof(*cm_node), GFP_ATOMIC);
1456         if (!cm_node)
1457                 return NULL;
1458
1459         /* set our node specific transport info */
1460         if (listener) {
1461                 cm_node->loc_addr = listener->loc_addr;
1462                 cm_node->loc_port = listener->loc_port;
1463         } else {
1464                 cm_node->loc_addr = cm_info->loc_addr;
1465                 cm_node->loc_port = cm_info->loc_port;
1466         }
1467         cm_node->rem_addr = cm_info->rem_addr;
1468         cm_node->rem_port = cm_info->rem_port;
1469
1470         cm_node->mpa_frame_rev = mpa_version;
1471         cm_node->send_rdma0_op = SEND_RDMA_READ_ZERO;
1472         cm_node->mpav2_ird_ord = 0;
1473         cm_node->ird_size = 0;
1474         cm_node->ord_size = 0;
1475
1476         nes_debug(NES_DBG_CM, "Make node addresses : loc = %pI4:%x, rem = %pI4:%x\n",
1477                   &cm_node->loc_addr, cm_node->loc_port,
1478                   &cm_node->rem_addr, cm_node->rem_port);
1479         cm_node->listener = listener;
1480         if (listener)
1481                 cm_node->tos = listener->tos;
1482         cm_node->netdev = nesvnic->netdev;
1483         cm_node->cm_id = cm_info->cm_id;
1484         memcpy(cm_node->loc_mac, nesvnic->netdev->dev_addr, ETH_ALEN);
1485
1486         nes_debug(NES_DBG_CM, "listener=%p, cm_id=%p\n", cm_node->listener,
1487                   cm_node->cm_id);
1488
1489         spin_lock_init(&cm_node->retrans_list_lock);
1490
1491         cm_node->loopbackpartner = NULL;
1492         atomic_set(&cm_node->ref_count, 1);
1493         /* associate our parent CM core */
1494         cm_node->cm_core = cm_core;
1495         cm_node->tcp_cntxt.loc_id = NES_CM_DEF_LOCAL_ID;
1496         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
1497         cm_node->tcp_cntxt.rcv_wnd = NES_CM_DEFAULT_RCV_WND_SCALED >>
1498                                      NES_CM_DEFAULT_RCV_WND_SCALE;
1499         cm_node->tcp_cntxt.loc_seq_num = secure_tcp_seq(htonl(cm_node->loc_addr),
1500                                                         htonl(cm_node->rem_addr),
1501                                                         htons(cm_node->loc_port),
1502                                                         htons(cm_node->rem_port));
1503         cm_node->tcp_cntxt.mss = nesvnic->max_frame_size - sizeof(struct iphdr) -
1504                                  sizeof(struct tcphdr) - ETH_HLEN - VLAN_HLEN;
1505         cm_node->tcp_cntxt.rcv_nxt = 0;
1506         /* get a unique session ID , add thread_id to an upcounter to handle race */
1507         atomic_inc(&cm_core->node_cnt);
1508         cm_node->conn_type = cm_info->conn_type;
1509         cm_node->apbvt_set = 0;
1510         cm_node->accept_pend = 0;
1511
1512         cm_node->nesvnic = nesvnic;
1513         /* get some device handles, for arp lookup */
1514         nesdev = nesvnic->nesdev;
1515         nesadapter = nesdev->nesadapter;
1516
1517         cm_node->loopbackpartner = NULL;
1518
1519         /* get the mac addr for the remote node */
1520         oldarpindex = nes_arp_table(nesdev, cm_node->rem_addr,
1521                                     NULL, NES_ARP_RESOLVE);
1522         arpindex = nes_addr_resolve_neigh(nesvnic, cm_node->rem_addr,
1523                                           oldarpindex);
1524         if (arpindex < 0) {
1525                 kfree(cm_node);
1526                 return NULL;
1527         }
1528
1529         /* copy the mac addr to node context */
1530         memcpy(cm_node->rem_mac, nesadapter->arp_table[arpindex].mac_addr, ETH_ALEN);
1531         nes_debug(NES_DBG_CM, "Remote mac addr from arp table: %pM\n",
1532                   cm_node->rem_mac);
1533
1534         add_hte_node(cm_core, cm_node);
1535         atomic_inc(&cm_nodes_created);
1536
1537         return cm_node;
1538 }
1539
1540
1541 /**
1542  * add_ref_cm_node - destroy an instance of a cm node
1543  */
1544 static int add_ref_cm_node(struct nes_cm_node *cm_node)
1545 {
1546         atomic_inc(&cm_node->ref_count);
1547         return 0;
1548 }
1549
1550
1551 /**
1552  * rem_ref_cm_node - destroy an instance of a cm node
1553  */
1554 static int rem_ref_cm_node(struct nes_cm_core *cm_core,
1555                            struct nes_cm_node *cm_node)
1556 {
1557         unsigned long flags;
1558         struct nes_qp *nesqp;
1559
1560         if (!cm_node)
1561                 return -EINVAL;
1562
1563         spin_lock_irqsave(&cm_node->cm_core->ht_lock, flags);
1564         if (atomic_dec_return(&cm_node->ref_count)) {
1565                 spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1566                 return 0;
1567         }
1568         list_del(&cm_node->list);
1569         atomic_dec(&cm_core->ht_node_cnt);
1570         spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1571
1572         /* if the node is destroyed before connection was accelerated */
1573         if (!cm_node->accelerated && cm_node->accept_pend) {
1574                 BUG_ON(!cm_node->listener);
1575                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1576                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1577         }
1578         WARN_ON(cm_node->send_entry);
1579         if (cm_node->recv_entry)
1580                 handle_recv_entry(cm_node, 0);
1581         if (cm_node->listener) {
1582                 mini_cm_dec_refcnt_listen(cm_core, cm_node->listener, 0);
1583         } else {
1584                 if (cm_node->apbvt_set && cm_node->nesvnic) {
1585                         nes_manage_apbvt(cm_node->nesvnic, cm_node->loc_port,
1586                                          PCI_FUNC(cm_node->nesvnic->nesdev->pcidev->devfn),
1587                                          NES_MANAGE_APBVT_DEL);
1588                 }
1589                 nes_debug(NES_DBG_NLMSG, "Delete APBVT loc_port = %04X\n",
1590                           cm_node->loc_port);
1591         }
1592
1593         atomic_dec(&cm_core->node_cnt);
1594         atomic_inc(&cm_nodes_destroyed);
1595         nesqp = cm_node->nesqp;
1596         if (nesqp) {
1597                 nesqp->cm_node = NULL;
1598                 nes_rem_ref(&nesqp->ibqp);
1599                 cm_node->nesqp = NULL;
1600         }
1601
1602         kfree(cm_node);
1603         return 0;
1604 }
1605
1606 /**
1607  * process_options
1608  */
1609 static int process_options(struct nes_cm_node *cm_node, u8 *optionsloc,
1610                            u32 optionsize, u32 syn_packet)
1611 {
1612         u32 tmp;
1613         u32 offset = 0;
1614         union all_known_options *all_options;
1615         char got_mss_option = 0;
1616
1617         while (offset < optionsize) {
1618                 all_options = (union all_known_options *)(optionsloc + offset);
1619                 switch (all_options->as_base.optionnum) {
1620                 case OPTION_NUMBER_END:
1621                         offset = optionsize;
1622                         break;
1623                 case OPTION_NUMBER_NONE:
1624                         offset += 1;
1625                         continue;
1626                 case OPTION_NUMBER_MSS:
1627                         nes_debug(NES_DBG_CM, "%s: MSS Length: %d Offset: %d "
1628                                   "Size: %d\n", __func__,
1629                                   all_options->as_mss.length, offset, optionsize);
1630                         got_mss_option = 1;
1631                         if (all_options->as_mss.length != 4) {
1632                                 return 1;
1633                         } else {
1634                                 tmp = ntohs(all_options->as_mss.mss);
1635                                 if (tmp > 0 && tmp <
1636                                     cm_node->tcp_cntxt.mss)
1637                                         cm_node->tcp_cntxt.mss = tmp;
1638                         }
1639                         break;
1640                 case OPTION_NUMBER_WINDOW_SCALE:
1641                         cm_node->tcp_cntxt.snd_wscale =
1642                                 all_options->as_windowscale.shiftcount;
1643                         break;
1644                 default:
1645                         nes_debug(NES_DBG_CM, "TCP Option not understood: %x\n",
1646                                   all_options->as_base.optionnum);
1647                         break;
1648                 }
1649                 offset += all_options->as_base.length;
1650         }
1651         if ((!got_mss_option) && (syn_packet))
1652                 cm_node->tcp_cntxt.mss = NES_CM_DEFAULT_MSS;
1653         return 0;
1654 }
1655
1656 static void drop_packet(struct sk_buff *skb)
1657 {
1658         atomic_inc(&cm_accel_dropped_pkts);
1659         dev_kfree_skb_any(skb);
1660 }
1661
1662 static void handle_fin_pkt(struct nes_cm_node *cm_node)
1663 {
1664         nes_debug(NES_DBG_CM, "Received FIN, cm_node = %p, state = %u. "
1665                   "refcnt=%d\n", cm_node, cm_node->state,
1666                   atomic_read(&cm_node->ref_count));
1667         switch (cm_node->state) {
1668         case NES_CM_STATE_SYN_RCVD:
1669         case NES_CM_STATE_SYN_SENT:
1670         case NES_CM_STATE_ESTABLISHED:
1671         case NES_CM_STATE_MPAREJ_RCVD:
1672                 cm_node->tcp_cntxt.rcv_nxt++;
1673                 cleanup_retrans_entry(cm_node);
1674                 cm_node->state = NES_CM_STATE_LAST_ACK;
1675                 send_fin(cm_node, NULL);
1676                 break;
1677         case NES_CM_STATE_MPAREQ_SENT:
1678                 create_event(cm_node, NES_CM_EVENT_ABORTED);
1679                 cm_node->tcp_cntxt.rcv_nxt++;
1680                 cleanup_retrans_entry(cm_node);
1681                 cm_node->state = NES_CM_STATE_CLOSED;
1682                 add_ref_cm_node(cm_node);
1683                 send_reset(cm_node, NULL);
1684                 break;
1685         case NES_CM_STATE_FIN_WAIT1:
1686                 cm_node->tcp_cntxt.rcv_nxt++;
1687                 cleanup_retrans_entry(cm_node);
1688                 cm_node->state = NES_CM_STATE_CLOSING;
1689                 send_ack(cm_node, NULL);
1690                 /* Wait for ACK as this is simultaneous close..
1691                 * After we receive ACK, do not send anything..
1692                 * Just rm the node.. Done.. */
1693                 break;
1694         case NES_CM_STATE_FIN_WAIT2:
1695                 cm_node->tcp_cntxt.rcv_nxt++;
1696                 cleanup_retrans_entry(cm_node);
1697                 cm_node->state = NES_CM_STATE_TIME_WAIT;
1698                 send_ack(cm_node, NULL);
1699                 schedule_nes_timer(cm_node, NULL,  NES_TIMER_TYPE_CLOSE, 1, 0);
1700                 break;
1701         case NES_CM_STATE_TIME_WAIT:
1702                 cm_node->tcp_cntxt.rcv_nxt++;
1703                 cleanup_retrans_entry(cm_node);
1704                 cm_node->state = NES_CM_STATE_CLOSED;
1705                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1706                 break;
1707         case NES_CM_STATE_TSA:
1708         default:
1709                 nes_debug(NES_DBG_CM, "Error Rcvd FIN for node-%p state = %d\n",
1710                         cm_node, cm_node->state);
1711                 break;
1712         }
1713 }
1714
1715
1716 static void handle_rst_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1717         struct tcphdr *tcph)
1718 {
1719
1720         int     reset = 0;      /* whether to send reset in case of err.. */
1721         atomic_inc(&cm_resets_recvd);
1722         nes_debug(NES_DBG_CM, "Received Reset, cm_node = %p, state = %u."
1723                         " refcnt=%d\n", cm_node, cm_node->state,
1724                         atomic_read(&cm_node->ref_count));
1725         cleanup_retrans_entry(cm_node);
1726         switch (cm_node->state) {
1727         case NES_CM_STATE_SYN_SENT:
1728         case NES_CM_STATE_MPAREQ_SENT:
1729                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1730                         "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1731                         cm_node->listener, cm_node->state);
1732                 switch (cm_node->mpa_frame_rev) {
1733                 case IETF_MPA_V2:
1734                         cm_node->mpa_frame_rev = IETF_MPA_V1;
1735                         /* send a syn and goto syn sent state */
1736                         cm_node->state = NES_CM_STATE_SYN_SENT;
1737                         if (send_syn(cm_node, 0, NULL)) {
1738                                 active_open_err(cm_node, skb, reset);
1739                         }
1740                         break;
1741                 case IETF_MPA_V1:
1742                 default:
1743                         active_open_err(cm_node, skb, reset);
1744                         break;
1745                 }
1746                 break;
1747         case NES_CM_STATE_MPAREQ_RCVD:
1748                 atomic_inc(&cm_node->passive_state);
1749                 dev_kfree_skb_any(skb);
1750                 break;
1751         case NES_CM_STATE_ESTABLISHED:
1752         case NES_CM_STATE_SYN_RCVD:
1753         case NES_CM_STATE_LISTENING:
1754                 nes_debug(NES_DBG_CM, "Bad state %s[%u]\n", __func__, __LINE__);
1755                 passive_open_err(cm_node, skb, reset);
1756                 break;
1757         case NES_CM_STATE_TSA:
1758                 active_open_err(cm_node, skb, reset);
1759                 break;
1760         case NES_CM_STATE_CLOSED:
1761                 drop_packet(skb);
1762                 break;
1763         case NES_CM_STATE_FIN_WAIT2:
1764         case NES_CM_STATE_FIN_WAIT1:
1765         case NES_CM_STATE_LAST_ACK:
1766                 cm_node->cm_id->rem_ref(cm_node->cm_id);
1767                 /* fall through */
1768         case NES_CM_STATE_TIME_WAIT:
1769                 cm_node->state = NES_CM_STATE_CLOSED;
1770                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1771                 drop_packet(skb);
1772                 break;
1773         default:
1774                 drop_packet(skb);
1775                 break;
1776         }
1777 }
1778
1779
1780 static void handle_rcv_mpa(struct nes_cm_node *cm_node, struct sk_buff *skb)
1781 {
1782         int ret = 0;
1783         int datasize = skb->len;
1784         u8 *dataloc = skb->data;
1785
1786         enum nes_cm_event_type type = NES_CM_EVENT_UNKNOWN;
1787         u32 res_type;
1788
1789         ret = parse_mpa(cm_node, dataloc, &res_type, datasize);
1790         if (ret) {
1791                 nes_debug(NES_DBG_CM, "didn't like MPA Request\n");
1792                 if (cm_node->state == NES_CM_STATE_MPAREQ_SENT) {
1793                         nes_debug(NES_DBG_CM, "%s[%u] create abort for "
1794                                   "cm_node=%p listener=%p state=%d\n", __func__,
1795                                   __LINE__, cm_node, cm_node->listener,
1796                                   cm_node->state);
1797                         active_open_err(cm_node, skb, 1);
1798                 } else {
1799                         passive_open_err(cm_node, skb, 1);
1800                 }
1801                 return;
1802         }
1803
1804         switch (cm_node->state) {
1805         case NES_CM_STATE_ESTABLISHED:
1806                 if (res_type == NES_MPA_REQUEST_REJECT)
1807                         /*BIG problem as we are receiving the MPA.. So should
1808                          * not be REJECT.. This is Passive Open.. We can
1809                          * only receive it Reject for Active Open...*/
1810                         WARN_ON(1);
1811                 cm_node->state = NES_CM_STATE_MPAREQ_RCVD;
1812                 type = NES_CM_EVENT_MPA_REQ;
1813                 atomic_set(&cm_node->passive_state,
1814                            NES_PASSIVE_STATE_INDICATED);
1815                 break;
1816         case NES_CM_STATE_MPAREQ_SENT:
1817                 cleanup_retrans_entry(cm_node);
1818                 if (res_type == NES_MPA_REQUEST_REJECT) {
1819                         type = NES_CM_EVENT_MPA_REJECT;
1820                         cm_node->state = NES_CM_STATE_MPAREJ_RCVD;
1821                 } else {
1822                         type = NES_CM_EVENT_CONNECTED;
1823                         cm_node->state = NES_CM_STATE_TSA;
1824                 }
1825                 send_ack(cm_node, NULL);
1826                 break;
1827         default:
1828                 WARN_ON(1);
1829                 break;
1830         }
1831         dev_kfree_skb_any(skb);
1832         create_event(cm_node, type);
1833 }
1834
1835 static void indicate_pkt_err(struct nes_cm_node *cm_node, struct sk_buff *skb)
1836 {
1837         switch (cm_node->state) {
1838         case NES_CM_STATE_SYN_SENT:
1839         case NES_CM_STATE_MPAREQ_SENT:
1840                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1841                           "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1842                           cm_node->listener, cm_node->state);
1843                 active_open_err(cm_node, skb, 1);
1844                 break;
1845         case NES_CM_STATE_ESTABLISHED:
1846         case NES_CM_STATE_SYN_RCVD:
1847                 passive_open_err(cm_node, skb, 1);
1848                 break;
1849         case NES_CM_STATE_TSA:
1850         default:
1851                 drop_packet(skb);
1852         }
1853 }
1854
1855 static int check_syn(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1856                      struct sk_buff *skb)
1857 {
1858         int err;
1859
1860         err = ((ntohl(tcph->ack_seq) == cm_node->tcp_cntxt.loc_seq_num)) ? 0 : 1;
1861         if (err)
1862                 active_open_err(cm_node, skb, 1);
1863
1864         return err;
1865 }
1866
1867 static int check_seq(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1868                      struct sk_buff *skb)
1869 {
1870         int err = 0;
1871         u32 seq;
1872         u32 ack_seq;
1873         u32 loc_seq_num = cm_node->tcp_cntxt.loc_seq_num;
1874         u32 rcv_nxt = cm_node->tcp_cntxt.rcv_nxt;
1875         u32 rcv_wnd;
1876
1877         seq = ntohl(tcph->seq);
1878         ack_seq = ntohl(tcph->ack_seq);
1879         rcv_wnd = cm_node->tcp_cntxt.rcv_wnd;
1880         if (ack_seq != loc_seq_num)
1881                 err = 1;
1882         else if (!between(seq, rcv_nxt, (rcv_nxt + rcv_wnd)))
1883                 err = 1;
1884         if (err) {
1885                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1886                           "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1887                           cm_node->listener, cm_node->state);
1888                 indicate_pkt_err(cm_node, skb);
1889                 nes_debug(NES_DBG_CM, "seq ERROR cm_node =%p seq=0x%08X "
1890                           "rcv_nxt=0x%08X rcv_wnd=0x%x\n", cm_node, seq, rcv_nxt,
1891                           rcv_wnd);
1892         }
1893         return err;
1894 }
1895
1896 /*
1897  * handle_syn_pkt() is for Passive node. The syn packet is received when a node
1898  * is created with a listener or it may comein as rexmitted packet which in
1899  * that case will be just dropped.
1900  */
1901 static void handle_syn_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1902                            struct tcphdr *tcph)
1903 {
1904         int ret;
1905         u32 inc_sequence;
1906         int optionsize;
1907
1908         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1909         skb_trim(skb, 0);
1910         inc_sequence = ntohl(tcph->seq);
1911
1912         switch (cm_node->state) {
1913         case NES_CM_STATE_SYN_SENT:
1914         case NES_CM_STATE_MPAREQ_SENT:
1915                 /* Rcvd syn on active open connection*/
1916                 active_open_err(cm_node, skb, 1);
1917                 break;
1918         case NES_CM_STATE_LISTENING:
1919                 /* Passive OPEN */
1920                 if (atomic_read(&cm_node->listener->pend_accepts_cnt) >
1921                     cm_node->listener->backlog) {
1922                         nes_debug(NES_DBG_CM, "drop syn due to backlog "
1923                                   "pressure \n");
1924                         cm_backlog_drops++;
1925                         passive_open_err(cm_node, skb, 0);
1926                         break;
1927                 }
1928                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize,
1929                                          1);
1930                 if (ret) {
1931                         passive_open_err(cm_node, skb, 0);
1932                         /* drop pkt */
1933                         break;
1934                 }
1935                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1936                 BUG_ON(cm_node->send_entry);
1937                 cm_node->accept_pend = 1;
1938                 atomic_inc(&cm_node->listener->pend_accepts_cnt);
1939
1940                 cm_node->state = NES_CM_STATE_SYN_RCVD;
1941                 send_syn(cm_node, 1, skb);
1942                 break;
1943         case NES_CM_STATE_CLOSED:
1944                 cleanup_retrans_entry(cm_node);
1945                 add_ref_cm_node(cm_node);
1946                 send_reset(cm_node, skb);
1947                 break;
1948         case NES_CM_STATE_TSA:
1949         case NES_CM_STATE_ESTABLISHED:
1950         case NES_CM_STATE_FIN_WAIT1:
1951         case NES_CM_STATE_FIN_WAIT2:
1952         case NES_CM_STATE_MPAREQ_RCVD:
1953         case NES_CM_STATE_LAST_ACK:
1954         case NES_CM_STATE_CLOSING:
1955         case NES_CM_STATE_UNKNOWN:
1956         default:
1957                 drop_packet(skb);
1958                 break;
1959         }
1960 }
1961
1962 static void handle_synack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1963                               struct tcphdr *tcph)
1964 {
1965         int ret;
1966         u32 inc_sequence;
1967         int optionsize;
1968
1969         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1970         skb_trim(skb, 0);
1971         inc_sequence = ntohl(tcph->seq);
1972         switch (cm_node->state) {
1973         case NES_CM_STATE_SYN_SENT:
1974                 cleanup_retrans_entry(cm_node);
1975                 /* active open */
1976                 if (check_syn(cm_node, tcph, skb))
1977                         return;
1978                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
1979                 /* setup options */
1980                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 0);
1981                 if (ret) {
1982                         nes_debug(NES_DBG_CM, "cm_node=%p tcp_options failed\n",
1983                                   cm_node);
1984                         break;
1985                 }
1986                 cleanup_retrans_entry(cm_node);
1987                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1988                 send_mpa_request(cm_node, skb);
1989                 cm_node->state = NES_CM_STATE_MPAREQ_SENT;
1990                 break;
1991         case NES_CM_STATE_MPAREQ_RCVD:
1992                 /* passive open, so should not be here */
1993                 passive_open_err(cm_node, skb, 1);
1994                 break;
1995         case NES_CM_STATE_LISTENING:
1996                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
1997                 cleanup_retrans_entry(cm_node);
1998                 cm_node->state = NES_CM_STATE_CLOSED;
1999                 send_reset(cm_node, skb);
2000                 break;
2001         case NES_CM_STATE_CLOSED:
2002                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
2003                 cleanup_retrans_entry(cm_node);
2004                 add_ref_cm_node(cm_node);
2005                 send_reset(cm_node, skb);
2006                 break;
2007         case NES_CM_STATE_ESTABLISHED:
2008         case NES_CM_STATE_FIN_WAIT1:
2009         case NES_CM_STATE_FIN_WAIT2:
2010         case NES_CM_STATE_LAST_ACK:
2011         case NES_CM_STATE_TSA:
2012         case NES_CM_STATE_CLOSING:
2013         case NES_CM_STATE_UNKNOWN:
2014         case NES_CM_STATE_MPAREQ_SENT:
2015         default:
2016                 drop_packet(skb);
2017                 break;
2018         }
2019 }
2020
2021 static int handle_ack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
2022                           struct tcphdr *tcph)
2023 {
2024         int datasize = 0;
2025         u32 inc_sequence;
2026         int ret = 0;
2027         int optionsize;
2028
2029         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
2030
2031         if (check_seq(cm_node, tcph, skb))
2032                 return -EINVAL;
2033
2034         skb_pull(skb, tcph->doff << 2);
2035         inc_sequence = ntohl(tcph->seq);
2036         datasize = skb->len;
2037         switch (cm_node->state) {
2038         case NES_CM_STATE_SYN_RCVD:
2039                 /* Passive OPEN */
2040                 cleanup_retrans_entry(cm_node);
2041                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 1);
2042                 if (ret)
2043                         break;
2044                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
2045                 cm_node->state = NES_CM_STATE_ESTABLISHED;
2046                 if (datasize) {
2047                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2048                         handle_rcv_mpa(cm_node, skb);
2049                 } else { /* rcvd ACK only */
2050                         dev_kfree_skb_any(skb);
2051                 }
2052                 break;
2053         case NES_CM_STATE_ESTABLISHED:
2054                 /* Passive OPEN */
2055                 cleanup_retrans_entry(cm_node);
2056                 if (datasize) {
2057                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2058                         handle_rcv_mpa(cm_node, skb);
2059                 } else {
2060                         drop_packet(skb);
2061                 }
2062                 break;
2063         case NES_CM_STATE_MPAREQ_SENT:
2064                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
2065                 if (datasize) {
2066                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
2067                         handle_rcv_mpa(cm_node, skb);
2068                 } else { /* Could be just an ack pkt.. */
2069                         dev_kfree_skb_any(skb);
2070                 }
2071                 break;
2072         case NES_CM_STATE_LISTENING:
2073                 cleanup_retrans_entry(cm_node);
2074                 cm_node->state = NES_CM_STATE_CLOSED;
2075                 send_reset(cm_node, skb);
2076                 break;
2077         case NES_CM_STATE_CLOSED:
2078                 cleanup_retrans_entry(cm_node);
2079                 add_ref_cm_node(cm_node);
2080                 send_reset(cm_node, skb);
2081                 break;
2082         case NES_CM_STATE_LAST_ACK:
2083         case NES_CM_STATE_CLOSING:
2084                 cleanup_retrans_entry(cm_node);
2085                 cm_node->state = NES_CM_STATE_CLOSED;
2086                 cm_node->cm_id->rem_ref(cm_node->cm_id);
2087                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2088                 drop_packet(skb);
2089                 break;
2090         case NES_CM_STATE_FIN_WAIT1:
2091                 cleanup_retrans_entry(cm_node);
2092                 drop_packet(skb);
2093                 cm_node->state = NES_CM_STATE_FIN_WAIT2;
2094                 break;
2095         case NES_CM_STATE_SYN_SENT:
2096         case NES_CM_STATE_FIN_WAIT2:
2097         case NES_CM_STATE_TSA:
2098         case NES_CM_STATE_MPAREQ_RCVD:
2099         case NES_CM_STATE_UNKNOWN:
2100         default:
2101                 cleanup_retrans_entry(cm_node);
2102                 drop_packet(skb);
2103                 break;
2104         }
2105         return ret;
2106 }
2107
2108
2109
2110 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph,
2111                               struct sk_buff *skb, int optionsize, int passive)
2112 {
2113         u8 *optionsloc = (u8 *)&tcph[1];
2114
2115         if (optionsize) {
2116                 if (process_options(cm_node, optionsloc, optionsize,
2117                                     (u32)tcph->syn)) {
2118                         nes_debug(NES_DBG_CM, "%s: Node %p, Sending RESET\n",
2119                                   __func__, cm_node);
2120                         if (passive)
2121                                 passive_open_err(cm_node, skb, 1);
2122                         else
2123                                 active_open_err(cm_node, skb, 1);
2124                         return 1;
2125                 }
2126         }
2127
2128         cm_node->tcp_cntxt.snd_wnd = ntohs(tcph->window) <<
2129                                      cm_node->tcp_cntxt.snd_wscale;
2130
2131         if (cm_node->tcp_cntxt.snd_wnd > cm_node->tcp_cntxt.max_snd_wnd)
2132                 cm_node->tcp_cntxt.max_snd_wnd = cm_node->tcp_cntxt.snd_wnd;
2133         return 0;
2134 }
2135
2136 /*
2137  * active_open_err() will send reset() if flag set..
2138  * It will also send ABORT event.
2139  */
2140 static void active_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
2141                             int reset)
2142 {
2143         cleanup_retrans_entry(cm_node);
2144         if (reset) {
2145                 nes_debug(NES_DBG_CM, "ERROR active err called for cm_node=%p, "
2146                           "state=%d\n", cm_node, cm_node->state);
2147                 add_ref_cm_node(cm_node);
2148                 send_reset(cm_node, skb);
2149         } else {
2150                 dev_kfree_skb_any(skb);
2151         }
2152
2153         cm_node->state = NES_CM_STATE_CLOSED;
2154         create_event(cm_node, NES_CM_EVENT_ABORTED);
2155 }
2156
2157 /*
2158  * passive_open_err() will either do a reset() or will free up the skb and
2159  * remove the cm_node.
2160  */
2161 static void passive_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
2162                              int reset)
2163 {
2164         cleanup_retrans_entry(cm_node);
2165         cm_node->state = NES_CM_STATE_CLOSED;
2166         if (reset) {
2167                 nes_debug(NES_DBG_CM, "passive_open_err sending RST for "
2168                           "cm_node=%p state =%d\n", cm_node, cm_node->state);
2169                 send_reset(cm_node, skb);
2170         } else {
2171                 dev_kfree_skb_any(skb);
2172                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2173         }
2174 }
2175
2176 /*
2177  * free_retrans_entry() routines assumes that the retrans_list_lock has
2178  * been acquired before calling.
2179  */
2180 static void free_retrans_entry(struct nes_cm_node *cm_node)
2181 {
2182         struct nes_timer_entry *send_entry;
2183
2184         send_entry = cm_node->send_entry;
2185         if (send_entry) {
2186                 cm_node->send_entry = NULL;
2187                 dev_kfree_skb_any(send_entry->skb);
2188                 kfree(send_entry);
2189                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2190         }
2191 }
2192
2193 static void cleanup_retrans_entry(struct nes_cm_node *cm_node)
2194 {
2195         unsigned long flags;
2196
2197         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
2198         free_retrans_entry(cm_node);
2199         spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
2200 }
2201
2202 /**
2203  * process_packet
2204  * Returns skb if to be freed, else it will return NULL if already used..
2205  */
2206 static void process_packet(struct nes_cm_node *cm_node, struct sk_buff *skb,
2207                            struct nes_cm_core *cm_core)
2208 {
2209         enum nes_tcpip_pkt_type pkt_type = NES_PKT_TYPE_UNKNOWN;
2210         struct tcphdr *tcph = tcp_hdr(skb);
2211         u32 fin_set = 0;
2212         int ret = 0;
2213
2214         skb_pull(skb, ip_hdr(skb)->ihl << 2);
2215
2216         nes_debug(NES_DBG_CM, "process_packet: cm_node=%p state =%d syn=%d "
2217                   "ack=%d rst=%d fin=%d\n", cm_node, cm_node->state, tcph->syn,
2218                   tcph->ack, tcph->rst, tcph->fin);
2219
2220         if (tcph->rst) {
2221                 pkt_type = NES_PKT_TYPE_RST;
2222         } else if (tcph->syn) {
2223                 pkt_type = NES_PKT_TYPE_SYN;
2224                 if (tcph->ack)
2225                         pkt_type = NES_PKT_TYPE_SYNACK;
2226         } else if (tcph->ack) {
2227                 pkt_type = NES_PKT_TYPE_ACK;
2228         }
2229         if (tcph->fin)
2230                 fin_set = 1;
2231
2232         switch (pkt_type) {
2233         case NES_PKT_TYPE_SYN:
2234                 handle_syn_pkt(cm_node, skb, tcph);
2235                 break;
2236         case NES_PKT_TYPE_SYNACK:
2237                 handle_synack_pkt(cm_node, skb, tcph);
2238                 break;
2239         case NES_PKT_TYPE_ACK:
2240                 ret = handle_ack_pkt(cm_node, skb, tcph);
2241                 if (fin_set && !ret)
2242                         handle_fin_pkt(cm_node);
2243                 break;
2244         case NES_PKT_TYPE_RST:
2245                 handle_rst_pkt(cm_node, skb, tcph);
2246                 break;
2247         default:
2248                 if ((fin_set) && (!check_seq(cm_node, tcph, skb)))
2249                         handle_fin_pkt(cm_node);
2250                 drop_packet(skb);
2251                 break;
2252         }
2253 }
2254
2255 /**
2256  * mini_cm_listen - create a listen node with params
2257  */
2258 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *cm_core,
2259                         struct nes_vnic *nesvnic, struct nes_cm_info *cm_info)
2260 {
2261         struct nes_cm_listener *listener;
2262         unsigned long flags;
2263
2264         nes_debug(NES_DBG_CM, "Search for 0x%08x : 0x%04x\n",
2265                   cm_info->loc_addr, cm_info->loc_port);
2266
2267         /* cannot have multiple matching listeners */
2268         listener = find_listener(cm_core, cm_info->loc_addr, cm_info->loc_port,
2269                                 NES_CM_LISTENER_EITHER_STATE);
2270
2271         if (listener && listener->listener_state == NES_CM_LISTENER_ACTIVE_STATE) {
2272                 /* find automatically incs ref count ??? */
2273                 atomic_dec(&listener->ref_count);
2274                 nes_debug(NES_DBG_CM, "Not creating listener since it already exists\n");
2275                 return NULL;
2276         }
2277
2278         if (!listener) {
2279                 /* create a CM listen node (1/2 node to compare incoming traffic to) */
2280                 listener = kzalloc(sizeof(*listener), GFP_ATOMIC);
2281                 if (!listener)
2282                         return NULL;
2283
2284                 listener->loc_addr = cm_info->loc_addr;
2285                 listener->loc_port = cm_info->loc_port;
2286                 listener->reused_node = 0;
2287
2288                 atomic_set(&listener->ref_count, 1);
2289         }
2290         /* pasive case */
2291         /* find already inc'ed the ref count */
2292         else {
2293                 listener->reused_node = 1;
2294         }
2295
2296         listener->cm_id = cm_info->cm_id;
2297         atomic_set(&listener->pend_accepts_cnt, 0);
2298         listener->cm_core = cm_core;
2299         listener->nesvnic = nesvnic;
2300         atomic_inc(&cm_core->node_cnt);
2301
2302         listener->conn_type = cm_info->conn_type;
2303         listener->backlog = cm_info->backlog;
2304         listener->listener_state = NES_CM_LISTENER_ACTIVE_STATE;
2305
2306         if (!listener->reused_node) {
2307                 spin_lock_irqsave(&cm_core->listen_list_lock, flags);
2308                 list_add(&listener->list, &cm_core->listen_list.list);
2309                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
2310                 atomic_inc(&cm_core->listen_node_cnt);
2311         }
2312
2313         nes_debug(NES_DBG_CM, "Api - listen(): addr=0x%08X, port=0x%04x,"
2314                   " listener = %p, backlog = %d, cm_id = %p.\n",
2315                   cm_info->loc_addr, cm_info->loc_port,
2316                   listener, listener->backlog, listener->cm_id);
2317
2318         return listener;
2319 }
2320
2321
2322 /**
2323  * mini_cm_connect - make a connection node with params
2324  */
2325 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *cm_core,
2326                                            struct nes_vnic *nesvnic, u16 private_data_len,
2327                                            void *private_data, struct nes_cm_info *cm_info)
2328 {
2329         int ret = 0;
2330         struct nes_cm_node *cm_node;
2331         struct nes_cm_listener *loopbackremotelistener;
2332         struct nes_cm_node *loopbackremotenode;
2333         struct nes_cm_info loopback_cm_info;
2334         u8 *start_buff;
2335
2336         /* create a CM connection node */
2337         cm_node = make_cm_node(cm_core, nesvnic, cm_info, NULL);
2338         if (!cm_node)
2339                 return NULL;
2340
2341         /* set our node side to client (active) side */
2342         cm_node->tcp_cntxt.client = 1;
2343         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
2344
2345         if (cm_info->loc_addr == cm_info->rem_addr) {
2346                 loopbackremotelistener = find_listener(cm_core,
2347                         cm_node->loc_addr, cm_node->rem_port,
2348                         NES_CM_LISTENER_ACTIVE_STATE);
2349                 if (loopbackremotelistener == NULL) {
2350                         create_event(cm_node, NES_CM_EVENT_ABORTED);
2351                 } else {
2352                         loopback_cm_info = *cm_info;
2353                         loopback_cm_info.loc_port = cm_info->rem_port;
2354                         loopback_cm_info.rem_port = cm_info->loc_port;
2355                         loopback_cm_info.loc_port =
2356                                 cm_info->rem_port;
2357                         loopback_cm_info.rem_port =
2358                                 cm_info->loc_port;
2359                         loopback_cm_info.cm_id = loopbackremotelistener->cm_id;
2360                         loopbackremotenode = make_cm_node(cm_core, nesvnic,
2361                                                           &loopback_cm_info, loopbackremotelistener);
2362                         if (!loopbackremotenode) {
2363                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2364                                 return NULL;
2365                         }
2366                         atomic_inc(&cm_loopbacks);
2367                         loopbackremotenode->loopbackpartner = cm_node;
2368                         loopbackremotenode->tcp_cntxt.rcv_wscale =
2369                                 NES_CM_DEFAULT_RCV_WND_SCALE;
2370                         cm_node->loopbackpartner = loopbackremotenode;
2371                         memcpy(loopbackremotenode->mpa_frame_buf, private_data,
2372                                private_data_len);
2373                         loopbackremotenode->mpa_frame_size = private_data_len;
2374
2375                         /* we are done handling this state. */
2376                         /* set node to a TSA state */
2377                         cm_node->state = NES_CM_STATE_TSA;
2378                         cm_node->tcp_cntxt.rcv_nxt =
2379                                 loopbackremotenode->tcp_cntxt.loc_seq_num;
2380                         loopbackremotenode->tcp_cntxt.rcv_nxt =
2381                                 cm_node->tcp_cntxt.loc_seq_num;
2382                         cm_node->tcp_cntxt.max_snd_wnd =
2383                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2384                         loopbackremotenode->tcp_cntxt.max_snd_wnd =
2385                                 cm_node->tcp_cntxt.rcv_wnd;
2386                         cm_node->tcp_cntxt.snd_wnd =
2387                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2388                         loopbackremotenode->tcp_cntxt.snd_wnd =
2389                                 cm_node->tcp_cntxt.rcv_wnd;
2390                         cm_node->tcp_cntxt.snd_wscale =
2391                                 loopbackremotenode->tcp_cntxt.rcv_wscale;
2392                         loopbackremotenode->tcp_cntxt.snd_wscale =
2393                                 cm_node->tcp_cntxt.rcv_wscale;
2394                         loopbackremotenode->state = NES_CM_STATE_MPAREQ_RCVD;
2395                         create_event(loopbackremotenode, NES_CM_EVENT_MPA_REQ);
2396                 }
2397                 return cm_node;
2398         }
2399
2400         start_buff = &cm_node->mpa_frame_buf[0] + sizeof(struct ietf_mpa_v2);
2401         cm_node->mpa_frame_size = private_data_len;
2402
2403         memcpy(start_buff, private_data, private_data_len);
2404
2405         /* send a syn and goto syn sent state */
2406         cm_node->state = NES_CM_STATE_SYN_SENT;
2407         ret = send_syn(cm_node, 0, NULL);
2408
2409         if (ret) {
2410                 /* error in sending the syn free up the cm_node struct */
2411                 nes_debug(NES_DBG_CM, "Api - connect() FAILED: dest "
2412                           "addr=0x%08X, port=0x%04x, cm_node=%p, cm_id = %p.\n",
2413                           cm_node->rem_addr, cm_node->rem_port, cm_node,
2414                           cm_node->cm_id);
2415                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2416                 cm_node = NULL;
2417         }
2418
2419         if (cm_node) {
2420                 nes_debug(NES_DBG_CM, "Api - connect(): dest addr=0x%08X,"
2421                           "port=0x%04x, cm_node=%p, cm_id = %p.\n",
2422                           cm_node->rem_addr, cm_node->rem_port, cm_node,
2423                           cm_node->cm_id);
2424         }
2425
2426         return cm_node;
2427 }
2428
2429
2430 /**
2431  * mini_cm_accept - accept a connection
2432  * This function is never called
2433  */
2434 static int mini_cm_accept(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2435 {
2436         return 0;
2437 }
2438
2439
2440 /**
2441  * mini_cm_reject - reject and teardown a connection
2442  */
2443 static int mini_cm_reject(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2444 {
2445         int ret = 0;
2446         int err = 0;
2447         int passive_state;
2448         struct nes_cm_event event;
2449         struct iw_cm_id *cm_id = cm_node->cm_id;
2450         struct nes_cm_node *loopback = cm_node->loopbackpartner;
2451
2452         nes_debug(NES_DBG_CM, "%s cm_node=%p type=%d state=%d\n",
2453                   __func__, cm_node, cm_node->tcp_cntxt.client, cm_node->state);
2454
2455         if (cm_node->tcp_cntxt.client)
2456                 return ret;
2457         cleanup_retrans_entry(cm_node);
2458
2459         if (!loopback) {
2460                 passive_state = atomic_add_return(1, &cm_node->passive_state);
2461                 if (passive_state == NES_SEND_RESET_EVENT) {
2462                         cm_node->state = NES_CM_STATE_CLOSED;
2463                         rem_ref_cm_node(cm_core, cm_node);
2464                 } else {
2465                         if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2466                                 rem_ref_cm_node(cm_core, cm_node);
2467                         } else {
2468                                 ret = send_mpa_reject(cm_node);
2469                                 if (ret) {
2470                                         cm_node->state = NES_CM_STATE_CLOSED;
2471                                         err = send_reset(cm_node, NULL);
2472                                         if (err)
2473                                                 WARN_ON(1);
2474                                 } else {
2475                                         cm_id->add_ref(cm_id);
2476                                 }
2477                         }
2478                 }
2479         } else {
2480                 cm_node->cm_id = NULL;
2481                 if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2482                         rem_ref_cm_node(cm_core, cm_node);
2483                         rem_ref_cm_node(cm_core, loopback);
2484                 } else {
2485                         event.cm_node = loopback;
2486                         event.cm_info.rem_addr = loopback->rem_addr;
2487                         event.cm_info.loc_addr = loopback->loc_addr;
2488                         event.cm_info.rem_port = loopback->rem_port;
2489                         event.cm_info.loc_port = loopback->loc_port;
2490                         event.cm_info.cm_id = loopback->cm_id;
2491                         cm_event_mpa_reject(&event);
2492                         rem_ref_cm_node(cm_core, cm_node);
2493                         loopback->state = NES_CM_STATE_CLOSING;
2494
2495                         cm_id = loopback->cm_id;
2496                         rem_ref_cm_node(cm_core, loopback);
2497                         cm_id->rem_ref(cm_id);
2498                 }
2499         }
2500
2501         return ret;
2502 }
2503
2504
2505 /**
2506  * mini_cm_close
2507  */
2508 static int mini_cm_close(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2509 {
2510         int ret = 0;
2511
2512         if (!cm_core || !cm_node)
2513                 return -EINVAL;
2514
2515         switch (cm_node->state) {
2516         case NES_CM_STATE_SYN_RCVD:
2517         case NES_CM_STATE_SYN_SENT:
2518         case NES_CM_STATE_ONE_SIDE_ESTABLISHED:
2519         case NES_CM_STATE_ESTABLISHED:
2520         case NES_CM_STATE_ACCEPTING:
2521         case NES_CM_STATE_MPAREQ_SENT:
2522         case NES_CM_STATE_MPAREQ_RCVD:
2523                 cleanup_retrans_entry(cm_node);
2524                 send_reset(cm_node, NULL);
2525                 break;
2526         case NES_CM_STATE_CLOSE_WAIT:
2527                 cm_node->state = NES_CM_STATE_LAST_ACK;
2528                 send_fin(cm_node, NULL);
2529                 break;
2530         case NES_CM_STATE_FIN_WAIT1:
2531         case NES_CM_STATE_FIN_WAIT2:
2532         case NES_CM_STATE_LAST_ACK:
2533         case NES_CM_STATE_TIME_WAIT:
2534         case NES_CM_STATE_CLOSING:
2535                 ret = -1;
2536                 break;
2537         case NES_CM_STATE_LISTENING:
2538                 cleanup_retrans_entry(cm_node);
2539                 send_reset(cm_node, NULL);
2540                 break;
2541         case NES_CM_STATE_MPAREJ_RCVD:
2542         case NES_CM_STATE_UNKNOWN:
2543         case NES_CM_STATE_INITED:
2544         case NES_CM_STATE_CLOSED:
2545         case NES_CM_STATE_LISTENER_DESTROYED:
2546                 ret = rem_ref_cm_node(cm_core, cm_node);
2547                 break;
2548         case NES_CM_STATE_TSA:
2549                 if (cm_node->send_entry)
2550                         printk(KERN_ERR "ERROR Close got called from STATE_TSA "
2551                                "send_entry=%p\n", cm_node->send_entry);
2552                 ret = rem_ref_cm_node(cm_core, cm_node);
2553                 break;
2554         }
2555         return ret;
2556 }
2557
2558
2559 /**
2560  * recv_pkt - recv an ETHERNET packet, and process it through CM
2561  * node state machine
2562  */
2563 static int mini_cm_recv_pkt(struct nes_cm_core *cm_core,
2564                             struct nes_vnic *nesvnic, struct sk_buff *skb)
2565 {
2566         struct nes_cm_node *cm_node = NULL;
2567         struct nes_cm_listener *listener = NULL;
2568         struct iphdr *iph;
2569         struct tcphdr *tcph;
2570         struct nes_cm_info nfo;
2571         int skb_handled = 1;
2572         __be32 tmp_daddr, tmp_saddr;
2573
2574         if (!skb)
2575                 return 0;
2576         if (skb->len < sizeof(struct iphdr) + sizeof(struct tcphdr))
2577                 return 0;
2578
2579         iph = (struct iphdr *)skb->data;
2580         tcph = (struct tcphdr *)(skb->data + sizeof(struct iphdr));
2581
2582         nfo.loc_addr = ntohl(iph->daddr);
2583         nfo.loc_port = ntohs(tcph->dest);
2584         nfo.rem_addr = ntohl(iph->saddr);
2585         nfo.rem_port = ntohs(tcph->source);
2586
2587         tmp_daddr = cpu_to_be32(iph->daddr);
2588         tmp_saddr = cpu_to_be32(iph->saddr);
2589
2590         nes_debug(NES_DBG_CM, "Received packet: dest=%pI4:0x%04X src=%pI4:0x%04X\n",
2591                   &tmp_daddr, tcph->dest, &tmp_saddr, tcph->source);
2592
2593         do {
2594                 cm_node = find_node(cm_core,
2595                                     nfo.rem_port, nfo.rem_addr,
2596                                     nfo.loc_port, nfo.loc_addr);
2597
2598                 if (!cm_node) {
2599                         /* Only type of packet accepted are for */
2600                         /* the PASSIVE open (syn only) */
2601                         if ((!tcph->syn) || (tcph->ack)) {
2602                                 skb_handled = 0;
2603                                 break;
2604                         }
2605                         listener = find_listener(cm_core, nfo.loc_addr,
2606                                                  nfo.loc_port,
2607                                                  NES_CM_LISTENER_ACTIVE_STATE);
2608                         if (!listener) {
2609                                 nfo.cm_id = NULL;
2610                                 nfo.conn_type = 0;
2611                                 nes_debug(NES_DBG_CM, "Unable to find listener for the pkt\n");
2612                                 skb_handled = 0;
2613                                 break;
2614                         }
2615                         nfo.cm_id = listener->cm_id;
2616                         nfo.conn_type = listener->conn_type;
2617                         cm_node = make_cm_node(cm_core, nesvnic, &nfo,
2618                                                listener);
2619                         if (!cm_node) {
2620                                 nes_debug(NES_DBG_CM, "Unable to allocate "
2621                                           "node\n");
2622                                 cm_packets_dropped++;
2623                                 atomic_dec(&listener->ref_count);
2624                                 dev_kfree_skb_any(skb);
2625                                 break;
2626                         }
2627                         if (!tcph->rst && !tcph->fin) {
2628                                 cm_node->state = NES_CM_STATE_LISTENING;
2629                         } else {
2630                                 cm_packets_dropped++;
2631                                 rem_ref_cm_node(cm_core, cm_node);
2632                                 dev_kfree_skb_any(skb);
2633                                 break;
2634                         }
2635                         add_ref_cm_node(cm_node);
2636                 } else if (cm_node->state == NES_CM_STATE_TSA) {
2637                         if (cm_node->nesqp->pau_mode)
2638                                 nes_queue_mgt_skbs(skb, nesvnic, cm_node->nesqp);
2639                         else {
2640                                 rem_ref_cm_node(cm_core, cm_node);
2641                                 atomic_inc(&cm_accel_dropped_pkts);
2642                                 dev_kfree_skb_any(skb);
2643                         }
2644                         break;
2645                 }
2646                 skb_reset_network_header(skb);
2647                 skb_set_transport_header(skb, sizeof(*tcph));
2648                 skb->len = ntohs(iph->tot_len);
2649                 process_packet(cm_node, skb, cm_core);
2650                 rem_ref_cm_node(cm_core, cm_node);
2651         } while (0);
2652         return skb_handled;
2653 }
2654
2655
2656 /**
2657  * nes_cm_alloc_core - allocate a top level instance of a cm core
2658  */
2659 static struct nes_cm_core *nes_cm_alloc_core(void)
2660 {
2661         struct nes_cm_core *cm_core;
2662
2663         /* setup the CM core */
2664         /* alloc top level core control structure */
2665         cm_core = kzalloc(sizeof(*cm_core), GFP_KERNEL);
2666         if (!cm_core)
2667                 return NULL;
2668
2669         INIT_LIST_HEAD(&cm_core->connected_nodes);
2670         timer_setup(&cm_core->tcp_timer, nes_cm_timer_tick, 0);
2671
2672         cm_core->mtu = NES_CM_DEFAULT_MTU;
2673         cm_core->state = NES_CM_STATE_INITED;
2674         cm_core->free_tx_pkt_max = NES_CM_DEFAULT_FREE_PKTS;
2675
2676         atomic_set(&cm_core->events_posted, 0);
2677
2678         cm_core->api = &nes_cm_api;
2679
2680         spin_lock_init(&cm_core->ht_lock);
2681         spin_lock_init(&cm_core->listen_list_lock);
2682
2683         INIT_LIST_HEAD(&cm_core->listen_list.list);
2684
2685         nes_debug(NES_DBG_CM, "Init CM Core completed -- cm_core=%p\n", cm_core);
2686
2687         nes_debug(NES_DBG_CM, "Enable QUEUE EVENTS\n");
2688         cm_core->event_wq = alloc_ordered_workqueue("nesewq", 0);
2689         if (!cm_core->event_wq)
2690                 goto out_free_cmcore;
2691         cm_core->post_event = nes_cm_post_event;
2692         nes_debug(NES_DBG_CM, "Enable QUEUE DISCONNECTS\n");
2693         cm_core->disconn_wq = alloc_ordered_workqueue("nesdwq", 0);
2694         if (!cm_core->disconn_wq)
2695                 goto out_free_wq;
2696
2697         print_core(cm_core);
2698         return cm_core;
2699
2700 out_free_wq:
2701         destroy_workqueue(cm_core->event_wq);
2702 out_free_cmcore:
2703         kfree(cm_core);
2704         return NULL;
2705 }
2706
2707
2708 /**
2709  * mini_cm_dealloc_core - deallocate a top level instance of a cm core
2710  */
2711 static int mini_cm_dealloc_core(struct nes_cm_core *cm_core)
2712 {
2713         nes_debug(NES_DBG_CM, "De-Alloc CM Core (%p)\n", cm_core);
2714
2715         if (!cm_core)
2716                 return -EINVAL;
2717
2718         barrier();
2719
2720         if (timer_pending(&cm_core->tcp_timer))
2721                 del_timer(&cm_core->tcp_timer);
2722
2723         destroy_workqueue(cm_core->event_wq);
2724         destroy_workqueue(cm_core->disconn_wq);
2725         nes_debug(NES_DBG_CM, "\n");
2726         kfree(cm_core);
2727
2728         return 0;
2729 }
2730
2731
2732 /**
2733  * mini_cm_get
2734  */
2735 static int mini_cm_get(struct nes_cm_core *cm_core)
2736 {
2737         return cm_core->state;
2738 }
2739
2740
2741 /**
2742  * mini_cm_set
2743  */
2744 static int mini_cm_set(struct nes_cm_core *cm_core, u32 type, u32 value)
2745 {
2746         int ret = 0;
2747
2748         switch (type) {
2749         case NES_CM_SET_PKT_SIZE:
2750                 cm_core->mtu = value;
2751                 break;
2752         case NES_CM_SET_FREE_PKT_Q_SIZE:
2753                 cm_core->free_tx_pkt_max = value;
2754                 break;
2755         default:
2756                 /* unknown set option */
2757                 ret = -EINVAL;
2758         }
2759
2760         return ret;
2761 }
2762
2763
2764 /**
2765  * nes_cm_init_tsa_conn setup HW; MPA frames must be
2766  * successfully exchanged when this is called
2767  */
2768 static int nes_cm_init_tsa_conn(struct nes_qp *nesqp, struct nes_cm_node *cm_node)
2769 {
2770         int ret = 0;
2771
2772         if (!nesqp)
2773                 return -EINVAL;
2774
2775         nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_IPV4 |
2776                                                   NES_QPCONTEXT_MISC_NO_NAGLE | NES_QPCONTEXT_MISC_DO_NOT_FRAG |
2777                                                   NES_QPCONTEXT_MISC_DROS);
2778
2779         if (cm_node->tcp_cntxt.snd_wscale || cm_node->tcp_cntxt.rcv_wscale)
2780                 nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_WSCALE);
2781
2782         nesqp->nesqp_context->misc2 |= cpu_to_le32(64 << NES_QPCONTEXT_MISC2_TTL_SHIFT);
2783
2784         nesqp->nesqp_context->misc2 |= cpu_to_le32(
2785                 cm_node->tos << NES_QPCONTEXT_MISC2_TOS_SHIFT);
2786
2787         nesqp->nesqp_context->mss |= cpu_to_le32(((u32)cm_node->tcp_cntxt.mss) << 16);
2788
2789         nesqp->nesqp_context->tcp_state_flow_label |= cpu_to_le32(
2790                 (u32)NES_QPCONTEXT_TCPSTATE_EST << NES_QPCONTEXT_TCPFLOW_TCP_STATE_SHIFT);
2791
2792         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2793                 (cm_node->tcp_cntxt.snd_wscale << NES_QPCONTEXT_PDWSCALE_SND_WSCALE_SHIFT) &
2794                 NES_QPCONTEXT_PDWSCALE_SND_WSCALE_MASK);
2795
2796         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2797                 (cm_node->tcp_cntxt.rcv_wscale << NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_SHIFT) &
2798                 NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_MASK);
2799
2800         nesqp->nesqp_context->keepalive = cpu_to_le32(0x80);
2801         nesqp->nesqp_context->ts_recent = 0;
2802         nesqp->nesqp_context->ts_age = 0;
2803         nesqp->nesqp_context->snd_nxt = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2804         nesqp->nesqp_context->snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.snd_wnd);
2805         nesqp->nesqp_context->rcv_nxt = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2806         nesqp->nesqp_context->rcv_wnd = cpu_to_le32(cm_node->tcp_cntxt.rcv_wnd <<
2807                                                     cm_node->tcp_cntxt.rcv_wscale);
2808         nesqp->nesqp_context->snd_max = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2809         nesqp->nesqp_context->snd_una = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2810         nesqp->nesqp_context->srtt = 0;
2811         nesqp->nesqp_context->rttvar = cpu_to_le32(0x6);
2812         nesqp->nesqp_context->ssthresh = cpu_to_le32(0x3FFFC000);
2813         nesqp->nesqp_context->cwnd = cpu_to_le32(2 * cm_node->tcp_cntxt.mss);
2814         nesqp->nesqp_context->snd_wl1 = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2815         nesqp->nesqp_context->snd_wl2 = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2816         nesqp->nesqp_context->max_snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.max_snd_wnd);
2817
2818         nes_debug(NES_DBG_CM, "QP%u: rcv_nxt = 0x%08X, snd_nxt = 0x%08X,"
2819                   " Setting MSS to %u, PDWscale = 0x%08X, rcv_wnd = %u, context misc = 0x%08X.\n",
2820                   nesqp->hwqp.qp_id, le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
2821                   le32_to_cpu(nesqp->nesqp_context->snd_nxt),
2822                   cm_node->tcp_cntxt.mss, le32_to_cpu(nesqp->nesqp_context->pd_index_wscale),
2823                   le32_to_cpu(nesqp->nesqp_context->rcv_wnd),
2824                   le32_to_cpu(nesqp->nesqp_context->misc));
2825         nes_debug(NES_DBG_CM, "  snd_wnd  = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->snd_wnd));
2826         nes_debug(NES_DBG_CM, "  snd_cwnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->cwnd));
2827         nes_debug(NES_DBG_CM, "  max_swnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->max_snd_wnd));
2828
2829         nes_debug(NES_DBG_CM, "Change cm_node state to TSA\n");
2830         cm_node->state = NES_CM_STATE_TSA;
2831
2832         return ret;
2833 }
2834
2835
2836 /**
2837  * nes_cm_disconn
2838  */
2839 int nes_cm_disconn(struct nes_qp *nesqp)
2840 {
2841         struct disconn_work *work;
2842
2843         work = kzalloc(sizeof *work, GFP_ATOMIC);
2844         if (!work)
2845                 return -ENOMEM;  /* Timer will clean up */
2846
2847         nes_add_ref(&nesqp->ibqp);
2848         work->nesqp = nesqp;
2849         INIT_WORK(&work->work, nes_disconnect_worker);
2850         queue_work(g_cm_core->disconn_wq, &work->work);
2851         return 0;
2852 }
2853
2854
2855 /**
2856  * nes_disconnect_worker
2857  */
2858 static void nes_disconnect_worker(struct work_struct *work)
2859 {
2860         struct disconn_work *dwork = container_of(work, struct disconn_work, work);
2861         struct nes_qp *nesqp = dwork->nesqp;
2862
2863         kfree(dwork);
2864         nes_debug(NES_DBG_CM, "processing AEQE id 0x%04X for QP%u.\n",
2865                   nesqp->last_aeq, nesqp->hwqp.qp_id);
2866         nes_cm_disconn_true(nesqp);
2867         nes_rem_ref(&nesqp->ibqp);
2868 }
2869
2870
2871 /**
2872  * nes_cm_disconn_true
2873  */
2874 static int nes_cm_disconn_true(struct nes_qp *nesqp)
2875 {
2876         unsigned long flags;
2877         int ret = 0;
2878         struct iw_cm_id *cm_id;
2879         struct iw_cm_event cm_event;
2880         struct nes_vnic *nesvnic;
2881         u16 last_ae;
2882         u8 original_hw_tcp_state;
2883         u8 original_ibqp_state;
2884         int disconn_status = 0;
2885         int issue_disconn = 0;
2886         int issue_close = 0;
2887         int issue_flush = 0;
2888         u32 flush_q = NES_CQP_FLUSH_RQ;
2889         struct ib_event ibevent;
2890
2891         if (!nesqp) {
2892                 nes_debug(NES_DBG_CM, "disconnect_worker nesqp is NULL\n");
2893                 return -1;
2894         }
2895
2896         spin_lock_irqsave(&nesqp->lock, flags);
2897         cm_id = nesqp->cm_id;
2898         /* make sure we havent already closed this connection */
2899         if (!cm_id) {
2900                 nes_debug(NES_DBG_CM, "QP%u disconnect_worker cmid is NULL\n",
2901                           nesqp->hwqp.qp_id);
2902                 spin_unlock_irqrestore(&nesqp->lock, flags);
2903                 return -1;
2904         }
2905
2906         nesvnic = to_nesvnic(nesqp->ibqp.device);
2907         nes_debug(NES_DBG_CM, "Disconnecting QP%u\n", nesqp->hwqp.qp_id);
2908
2909         original_hw_tcp_state = nesqp->hw_tcp_state;
2910         original_ibqp_state = nesqp->ibqp_state;
2911         last_ae = nesqp->last_aeq;
2912
2913         if (nesqp->term_flags) {
2914                 issue_disconn = 1;
2915                 issue_close = 1;
2916                 nesqp->cm_id = NULL;
2917                 del_timer(&nesqp->terminate_timer);
2918                 if (nesqp->flush_issued == 0) {
2919                         nesqp->flush_issued = 1;
2920                         issue_flush = 1;
2921                 }
2922         } else if ((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSE_WAIT) ||
2923                         ((original_ibqp_state == IB_QPS_RTS) &&
2924                         (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2925                 issue_disconn = 1;
2926                 if (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET)
2927                         disconn_status = -ECONNRESET;
2928         }
2929
2930         if (((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSED) ||
2931                  (original_hw_tcp_state == NES_AEQE_TCP_STATE_TIME_WAIT) ||
2932                  (last_ae == NES_AEQE_AEID_RDMAP_ROE_BAD_LLP_CLOSE) ||
2933                  (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2934                 issue_close = 1;
2935                 nesqp->cm_id = NULL;
2936                 if (nesqp->flush_issued == 0) {
2937                         nesqp->flush_issued = 1;
2938                         issue_flush = 1;
2939                 }
2940         }
2941
2942         spin_unlock_irqrestore(&nesqp->lock, flags);
2943
2944         if ((issue_flush) && (nesqp->destroyed == 0)) {
2945                 /* Flush the queue(s) */
2946                 if (nesqp->hw_iwarp_state >= NES_AEQE_IWARP_STATE_TERMINATE)
2947                         flush_q |= NES_CQP_FLUSH_SQ;
2948                 flush_wqes(nesvnic->nesdev, nesqp, flush_q, 1);
2949
2950                 if (nesqp->term_flags) {
2951                         ibevent.device = nesqp->ibqp.device;
2952                         ibevent.event = nesqp->terminate_eventtype;
2953                         ibevent.element.qp = &nesqp->ibqp;
2954                         if (nesqp->ibqp.event_handler)
2955                                 nesqp->ibqp.event_handler(&ibevent, nesqp->ibqp.qp_context);
2956                 }
2957         }
2958
2959         if ((cm_id) && (cm_id->event_handler)) {
2960                 if (issue_disconn) {
2961                         atomic_inc(&cm_disconnects);
2962                         cm_event.event = IW_CM_EVENT_DISCONNECT;
2963                         cm_event.status = disconn_status;
2964                         cm_event.local_addr = cm_id->m_local_addr;
2965                         cm_event.remote_addr = cm_id->m_remote_addr;
2966                         cm_event.private_data = NULL;
2967                         cm_event.private_data_len = 0;
2968
2969                         nes_debug(NES_DBG_CM, "Generating a CM Disconnect Event"
2970                                   " for  QP%u, SQ Head = %u, SQ Tail = %u. "
2971                                   "cm_id = %p, refcount = %u.\n",
2972                                   nesqp->hwqp.qp_id, nesqp->hwqp.sq_head,
2973                                   nesqp->hwqp.sq_tail, cm_id,
2974                                   atomic_read(&nesqp->refcount));
2975
2976                         ret = cm_id->event_handler(cm_id, &cm_event);
2977                         if (ret)
2978                                 nes_debug(NES_DBG_CM, "OFA CM event_handler "
2979                                           "returned, ret=%d\n", ret);
2980                 }
2981
2982                 if (issue_close) {
2983                         atomic_inc(&cm_closes);
2984                         nes_disconnect(nesqp, 1);
2985
2986                         cm_id->provider_data = nesqp;
2987                         /* Send up the close complete event */
2988                         cm_event.event = IW_CM_EVENT_CLOSE;
2989                         cm_event.status = 0;
2990                         cm_event.provider_data = cm_id->provider_data;
2991                         cm_event.local_addr = cm_id->m_local_addr;
2992                         cm_event.remote_addr = cm_id->m_remote_addr;
2993                         cm_event.private_data = NULL;
2994                         cm_event.private_data_len = 0;
2995
2996                         ret = cm_id->event_handler(cm_id, &cm_event);
2997                         if (ret)
2998                                 nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
2999
3000                         cm_id->rem_ref(cm_id);
3001                 }
3002         }
3003
3004         return 0;
3005 }
3006
3007
3008 /**
3009  * nes_disconnect
3010  */
3011 static int nes_disconnect(struct nes_qp *nesqp, int abrupt)
3012 {
3013         int ret = 0;
3014         struct nes_vnic *nesvnic;
3015         struct nes_device *nesdev;
3016         struct nes_ib_device *nesibdev;
3017
3018         nesvnic = to_nesvnic(nesqp->ibqp.device);
3019         if (!nesvnic)
3020                 return -EINVAL;
3021
3022         nesdev = nesvnic->nesdev;
3023         nesibdev = nesvnic->nesibdev;
3024
3025         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
3026                         netdev_refcnt_read(nesvnic->netdev));
3027
3028         if (nesqp->active_conn) {
3029
3030                 /* indicate this connection is NOT active */
3031                 nesqp->active_conn = 0;
3032         } else {
3033                 /* Need to free the Last Streaming Mode Message */
3034                 if (nesqp->ietf_frame) {
3035                         if (nesqp->lsmm_mr)
3036                                 nesibdev->ibdev.dereg_mr(nesqp->lsmm_mr);
3037                         pci_free_consistent(nesdev->pcidev,
3038                                             nesqp->private_data_len + nesqp->ietf_frame_size,
3039                                             nesqp->ietf_frame, nesqp->ietf_frame_pbase);
3040                 }
3041         }
3042
3043         /* close the CM node down if it is still active */
3044         if (nesqp->cm_node) {
3045                 nes_debug(NES_DBG_CM, "Call close API\n");
3046
3047                 g_cm_core->api->close(g_cm_core, nesqp->cm_node);
3048         }
3049
3050         return ret;
3051 }
3052
3053
3054 /**
3055  * nes_accept
3056  */
3057 int nes_accept(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
3058 {
3059         u64 u64temp;
3060         struct ib_qp *ibqp;
3061         struct nes_qp *nesqp;
3062         struct nes_vnic *nesvnic;
3063         struct nes_device *nesdev;
3064         struct nes_cm_node *cm_node;
3065         struct nes_adapter *adapter;
3066         struct ib_qp_attr attr;
3067         struct iw_cm_event cm_event;
3068         struct nes_hw_qp_wqe *wqe;
3069         struct nes_v4_quad nes_quad;
3070         u32 crc_value;
3071         int ret;
3072         int passive_state;
3073         struct ib_mr *ibmr = NULL;
3074         struct nes_pd *nespd;
3075         u64 tagged_offset;
3076         u8 mpa_frame_offset = 0;
3077         struct ietf_mpa_v2 *mpa_v2_frame;
3078         u8 start_addr = 0;
3079         u8 *start_ptr = &start_addr;
3080         u8 **start_buff = &start_ptr;
3081         u16 buff_len = 0;
3082         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3083         struct sockaddr_in *raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3084
3085         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
3086         if (!ibqp)
3087                 return -EINVAL;
3088
3089         /* get all our handles */
3090         nesqp = to_nesqp(ibqp);
3091         nesvnic = to_nesvnic(nesqp->ibqp.device);
3092         nesdev = nesvnic->nesdev;
3093         adapter = nesdev->nesadapter;
3094
3095         cm_node = (struct nes_cm_node *)cm_id->provider_data;
3096         nes_debug(NES_DBG_CM, "nes_accept: cm_node= %p nesvnic=%p, netdev=%p,"
3097                 "%s\n", cm_node, nesvnic, nesvnic->netdev,
3098                 nesvnic->netdev->name);
3099
3100         if (NES_CM_STATE_LISTENER_DESTROYED == cm_node->state) {
3101                 if (cm_node->loopbackpartner)
3102                         rem_ref_cm_node(cm_node->cm_core, cm_node->loopbackpartner);
3103                 rem_ref_cm_node(cm_node->cm_core, cm_node);
3104                 return -EINVAL;
3105         }
3106
3107         passive_state = atomic_add_return(1, &cm_node->passive_state);
3108         if (passive_state == NES_SEND_RESET_EVENT) {
3109                 rem_ref_cm_node(cm_node->cm_core, cm_node);
3110                 return -ECONNRESET;
3111         }
3112         /* associate the node with the QP */
3113         nesqp->cm_node = (void *)cm_node;
3114         cm_node->nesqp = nesqp;
3115
3116
3117         nes_debug(NES_DBG_CM, "QP%u, cm_node=%p, jiffies = %lu listener = %p\n",
3118                 nesqp->hwqp.qp_id, cm_node, jiffies, cm_node->listener);
3119         atomic_inc(&cm_accepts);
3120
3121         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
3122                         netdev_refcnt_read(nesvnic->netdev));
3123
3124         nesqp->ietf_frame_size = sizeof(struct ietf_mpa_v2);
3125         /* allocate the ietf frame and space for private data */
3126         nesqp->ietf_frame = pci_alloc_consistent(nesdev->pcidev,
3127                                                  nesqp->ietf_frame_size + conn_param->private_data_len,
3128                                                  &nesqp->ietf_frame_pbase);
3129
3130         if (!nesqp->ietf_frame) {
3131                 nes_debug(NES_DBG_CM, "Unable to allocate memory for private data\n");
3132                 return -ENOMEM;
3133         }
3134         mpa_v2_frame = (struct ietf_mpa_v2 *)nesqp->ietf_frame;
3135
3136         if (cm_node->mpa_frame_rev == IETF_MPA_V1)
3137                 mpa_frame_offset = 4;
3138
3139         if (cm_node->mpa_frame_rev == IETF_MPA_V1 ||
3140                         cm_node->mpav2_ird_ord == IETF_NO_IRD_ORD) {
3141                 record_ird_ord(cm_node, (u16)conn_param->ird, (u16)conn_param->ord);
3142         }
3143
3144         memcpy(mpa_v2_frame->priv_data, conn_param->private_data,
3145                conn_param->private_data_len);
3146
3147         cm_build_mpa_frame(cm_node, start_buff, &buff_len, nesqp->ietf_frame, MPA_KEY_REPLY);
3148         nesqp->private_data_len = conn_param->private_data_len;
3149
3150         /* setup our first outgoing iWarp send WQE (the IETF frame response) */
3151         wqe = &nesqp->hwqp.sq_vbase[0];
3152
3153         if (raddr->sin_addr.s_addr != laddr->sin_addr.s_addr) {
3154                 u64temp = (unsigned long)nesqp;
3155                 nespd = nesqp->nespd;
3156                 tagged_offset = (u64)(unsigned long)*start_buff;
3157                 ibmr = nes_reg_phys_mr(&nespd->ibpd,
3158                                 nesqp->ietf_frame_pbase + mpa_frame_offset,
3159                                 buff_len, IB_ACCESS_LOCAL_WRITE,
3160                                 &tagged_offset);
3161                 if (IS_ERR(ibmr)) {
3162                         nes_debug(NES_DBG_CM, "Unable to register memory region"
3163                                   "for lSMM for cm_node = %p \n",
3164                                   cm_node);
3165                         pci_free_consistent(nesdev->pcidev,
3166                                             nesqp->private_data_len + nesqp->ietf_frame_size,
3167                                             nesqp->ietf_frame, nesqp->ietf_frame_pbase);
3168                         return PTR_ERR(ibmr);
3169                 }
3170
3171                 ibmr->pd = &nespd->ibpd;
3172                 ibmr->device = nespd->ibpd.device;
3173                 nesqp->lsmm_mr = ibmr;
3174
3175                 u64temp |= NES_SW_CONTEXT_ALIGN >> 1;
3176                 set_wqe_64bit_value(wqe->wqe_words,
3177                                     NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX,
3178                                     u64temp);
3179                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
3180                         cpu_to_le32(NES_IWARP_SQ_WQE_STREAMING |
3181                                     NES_IWARP_SQ_WQE_WRPDU);
3182                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] =
3183                         cpu_to_le32(buff_len);
3184                 set_wqe_64bit_value(wqe->wqe_words,
3185                                     NES_IWARP_SQ_WQE_FRAG0_LOW_IDX,
3186                                     (u64)(unsigned long)(*start_buff));
3187                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] =
3188                         cpu_to_le32(buff_len);
3189                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = ibmr->lkey;
3190                 if (nesqp->sq_kmapped) {
3191                         nesqp->sq_kmapped = 0;
3192                         kunmap(nesqp->page);
3193                 }
3194
3195                 nesqp->nesqp_context->ird_ord_sizes |=
3196                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
3197                                     NES_QPCONTEXT_ORDIRD_WRPDU);
3198         } else {
3199                 nesqp->nesqp_context->ird_ord_sizes |=
3200                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_WRPDU);
3201         }
3202         nesqp->skip_lsmm = 1;
3203
3204         /* Cache the cm_id in the qp */
3205         nesqp->cm_id = cm_id;
3206         cm_node->cm_id = cm_id;
3207
3208         /*  nesqp->cm_node = (void *)cm_id->provider_data; */
3209         cm_id->provider_data = nesqp;
3210         nesqp->active_conn = 0;
3211
3212         if (cm_node->state == NES_CM_STATE_TSA)
3213                 nes_debug(NES_DBG_CM, "Already state = TSA for cm_node=%p\n",
3214                           cm_node);
3215
3216         nes_cm_init_tsa_conn(nesqp, cm_node);
3217
3218         nesqp->nesqp_context->tcpPorts[0] =
3219                                 cpu_to_le16(cm_node->loc_port);
3220         nesqp->nesqp_context->tcpPorts[1] =
3221                                 cpu_to_le16(cm_node->rem_port);
3222
3223         nesqp->nesqp_context->ip0 = cpu_to_le32(cm_node->rem_addr);
3224
3225         nesqp->nesqp_context->misc2 |= cpu_to_le32(
3226                 (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
3227                 NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
3228
3229         nesqp->nesqp_context->arp_index_vlan |=
3230                 cpu_to_le32(nes_arp_table(nesdev,
3231                                           le32_to_cpu(nesqp->nesqp_context->ip0), NULL,
3232                                           NES_ARP_RESOLVE) << 16);
3233
3234         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
3235                 jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
3236
3237         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
3238
3239         nesqp->nesqp_context->ird_ord_sizes |= cpu_to_le32(
3240                 ((u32)1 << NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT));
3241         nesqp->nesqp_context->ird_ord_sizes |=
3242                 cpu_to_le32((u32)cm_node->ord_size);
3243
3244         memset(&nes_quad, 0, sizeof(nes_quad));
3245         nes_quad.DstIpAdrIndex =
3246                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
3247         nes_quad.SrcIpadr = htonl(cm_node->rem_addr);
3248         nes_quad.TcpPorts[0] = htons(cm_node->rem_port);
3249         nes_quad.TcpPorts[1] = htons(cm_node->loc_port);
3250
3251         /* Produce hash key */
3252         crc_value = get_crc_value(&nes_quad);
3253         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
3254         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, CRC = 0x%08X\n",
3255                   nesqp->hte_index, nesqp->hte_index & adapter->hte_index_mask);
3256
3257         nesqp->hte_index &= adapter->hte_index_mask;
3258         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
3259
3260         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
3261
3262         nes_debug(NES_DBG_CM, "QP%u, Destination IP = 0x%08X:0x%04X, local = "
3263                   "0x%08X:0x%04X, rcv_nxt=0x%08X, snd_nxt=0x%08X, mpa + "
3264                   "private data length=%u.\n", nesqp->hwqp.qp_id,
3265                   ntohl(raddr->sin_addr.s_addr), ntohs(raddr->sin_port),
3266                   ntohl(laddr->sin_addr.s_addr), ntohs(laddr->sin_port),
3267                   le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
3268                   le32_to_cpu(nesqp->nesqp_context->snd_nxt),
3269                   buff_len);
3270
3271         /* notify OF layer that accept event was successful */
3272         cm_id->add_ref(cm_id);
3273         nes_add_ref(&nesqp->ibqp);
3274
3275         cm_event.event = IW_CM_EVENT_ESTABLISHED;
3276         cm_event.status = 0;
3277         cm_event.provider_data = (void *)nesqp;
3278         cm_event.local_addr = cm_id->m_local_addr;
3279         cm_event.remote_addr = cm_id->m_remote_addr;
3280         cm_event.private_data = NULL;
3281         cm_event.private_data_len = 0;
3282         cm_event.ird = cm_node->ird_size;
3283         cm_event.ord = cm_node->ord_size;
3284
3285         ret = cm_id->event_handler(cm_id, &cm_event);
3286         attr.qp_state = IB_QPS_RTS;
3287         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
3288         if (cm_node->loopbackpartner) {
3289                 cm_node->loopbackpartner->mpa_frame_size =
3290                         nesqp->private_data_len;
3291                 /* copy entire MPA frame to our cm_node's frame */
3292                 memcpy(cm_node->loopbackpartner->mpa_frame_buf,
3293                        conn_param->private_data, conn_param->private_data_len);
3294                 create_event(cm_node->loopbackpartner, NES_CM_EVENT_CONNECTED);
3295         }
3296         if (ret)
3297                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3298                        "ret=%d\n", __func__, __LINE__, ret);
3299
3300         return 0;
3301 }
3302
3303
3304 /**
3305  * nes_reject
3306  */
3307 int nes_reject(struct iw_cm_id *cm_id, const void *pdata, u8 pdata_len)
3308 {
3309         struct nes_cm_node *cm_node;
3310         struct nes_cm_node *loopback;
3311         struct nes_cm_core *cm_core;
3312         u8 *start_buff;
3313
3314         atomic_inc(&cm_rejects);
3315         cm_node = (struct nes_cm_node *)cm_id->provider_data;
3316         loopback = cm_node->loopbackpartner;
3317         cm_core = cm_node->cm_core;
3318         cm_node->cm_id = cm_id;
3319
3320         if (pdata_len + sizeof(struct ietf_mpa_v2) > MAX_CM_BUFFER)
3321                 return -EINVAL;
3322
3323         if (loopback) {
3324                 memcpy(&loopback->mpa_frame.priv_data, pdata, pdata_len);
3325                 loopback->mpa_frame.priv_data_len = pdata_len;
3326                 loopback->mpa_frame_size = pdata_len;
3327         } else {
3328                 start_buff = &cm_node->mpa_frame_buf[0] + sizeof(struct ietf_mpa_v2);
3329                 cm_node->mpa_frame_size = pdata_len;
3330                 memcpy(start_buff, pdata, pdata_len);
3331         }
3332         return cm_core->api->reject(cm_core, cm_node);
3333 }
3334
3335
3336 /**
3337  * nes_connect
3338  * setup and launch cm connect node
3339  */
3340 int nes_connect(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
3341 {
3342         struct ib_qp *ibqp;
3343         struct nes_qp *nesqp;
3344         struct nes_vnic *nesvnic;
3345         struct nes_device *nesdev;
3346         struct nes_cm_node *cm_node;
3347         struct nes_cm_info cm_info;
3348         int apbvt_set = 0;
3349         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3350         struct sockaddr_in *raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3351
3352         if (cm_id->remote_addr.ss_family != AF_INET)
3353                 return -ENOSYS;
3354         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
3355         if (!ibqp)
3356                 return -EINVAL;
3357         nesqp = to_nesqp(ibqp);
3358         if (!nesqp)
3359                 return -EINVAL;
3360         nesvnic = to_nesvnic(nesqp->ibqp.device);
3361         if (!nesvnic)
3362                 return -EINVAL;
3363         nesdev = nesvnic->nesdev;
3364         if (!nesdev)
3365                 return -EINVAL;
3366
3367         if (!laddr->sin_port || !raddr->sin_port)
3368                 return -EINVAL;
3369
3370         nes_debug(NES_DBG_CM, "QP%u, current IP = 0x%08X, Destination IP = "
3371                   "0x%08X:0x%04X, local = 0x%08X:0x%04X.\n", nesqp->hwqp.qp_id,
3372                   ntohl(nesvnic->local_ipaddr), ntohl(raddr->sin_addr.s_addr),
3373                   ntohs(raddr->sin_port), ntohl(laddr->sin_addr.s_addr),
3374                   ntohs(laddr->sin_port));
3375
3376         atomic_inc(&cm_connects);
3377         nesqp->active_conn = 1;
3378
3379         /* cache the cm_id in the qp */
3380         nesqp->cm_id = cm_id;
3381         cm_id->provider_data = nesqp;
3382         nesqp->private_data_len = conn_param->private_data_len;
3383
3384         nes_debug(NES_DBG_CM, "requested ord = 0x%08X.\n", (u32)conn_param->ord);
3385         nes_debug(NES_DBG_CM, "mpa private data len =%u\n",
3386                   conn_param->private_data_len);
3387
3388         /* set up the connection params for the node */
3389         cm_info.loc_addr = ntohl(laddr->sin_addr.s_addr);
3390         cm_info.loc_port = ntohs(laddr->sin_port);
3391         cm_info.rem_addr = ntohl(raddr->sin_addr.s_addr);
3392         cm_info.rem_port = ntohs(raddr->sin_port);
3393         cm_info.cm_id = cm_id;
3394         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3395
3396         if (laddr->sin_addr.s_addr != raddr->sin_addr.s_addr) {
3397                 nes_manage_apbvt(nesvnic, cm_info.loc_port,
3398                                  PCI_FUNC(nesdev->pcidev->devfn),
3399                                  NES_MANAGE_APBVT_ADD);
3400                 apbvt_set = 1;
3401         }
3402
3403         cm_id->add_ref(cm_id);
3404
3405         /* create a connect CM node connection */
3406         cm_node = g_cm_core->api->connect(g_cm_core, nesvnic,
3407                                           conn_param->private_data_len, (void *)conn_param->private_data,
3408                                           &cm_info);
3409         if (!cm_node) {
3410                 if (apbvt_set)
3411                         nes_manage_apbvt(nesvnic, cm_info.loc_port,
3412                                          PCI_FUNC(nesdev->pcidev->devfn),
3413                                          NES_MANAGE_APBVT_DEL);
3414
3415                 nes_debug(NES_DBG_NLMSG, "Delete loc_port = %04X\n",
3416                           cm_info.loc_port);
3417                 cm_id->rem_ref(cm_id);
3418                 return -ENOMEM;
3419         }
3420
3421         record_ird_ord(cm_node, (u16)conn_param->ird, (u16)conn_param->ord);
3422         if (cm_node->send_rdma0_op == SEND_RDMA_READ_ZERO &&
3423                                 cm_node->ord_size == 0)
3424                 cm_node->ord_size = 1;
3425
3426         cm_node->apbvt_set = apbvt_set;
3427         cm_node->tos = cm_id->tos;
3428         nesqp->cm_node = cm_node;
3429         cm_node->nesqp = nesqp;
3430         nes_add_ref(&nesqp->ibqp);
3431
3432         return 0;
3433 }
3434
3435
3436 /**
3437  * nes_create_listen
3438  */
3439 int nes_create_listen(struct iw_cm_id *cm_id, int backlog)
3440 {
3441         struct nes_vnic *nesvnic;
3442         struct nes_cm_listener *cm_node;
3443         struct nes_cm_info cm_info;
3444         int err;
3445         struct sockaddr_in *laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3446
3447         nes_debug(NES_DBG_CM, "cm_id = %p, local port = 0x%04X.\n",
3448                   cm_id, ntohs(laddr->sin_port));
3449
3450         if (cm_id->m_local_addr.ss_family != AF_INET)
3451                 return -ENOSYS;
3452         nesvnic = to_nesvnic(cm_id->device);
3453         if (!nesvnic)
3454                 return -EINVAL;
3455
3456         nes_debug(NES_DBG_CM, "nesvnic=%p, netdev=%p, %s\n",
3457                         nesvnic, nesvnic->netdev, nesvnic->netdev->name);
3458
3459         nes_debug(NES_DBG_CM, "nesvnic->local_ipaddr=0x%08x, sin_addr.s_addr=0x%08x\n",
3460                         nesvnic->local_ipaddr, laddr->sin_addr.s_addr);
3461
3462         /* setup listen params in our api call struct */
3463         cm_info.loc_addr = ntohl(nesvnic->local_ipaddr);
3464         cm_info.loc_port = ntohs(laddr->sin_port);
3465         cm_info.backlog = backlog;
3466         cm_info.cm_id = cm_id;
3467
3468         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3469
3470         cm_node = g_cm_core->api->listen(g_cm_core, nesvnic, &cm_info);
3471         if (!cm_node) {
3472                 printk(KERN_ERR "%s[%u] Error returned from listen API call\n",
3473                        __func__, __LINE__);
3474                 return -ENOMEM;
3475         }
3476
3477         cm_id->provider_data = cm_node;
3478         cm_node->tos = cm_id->tos;
3479
3480         if (!cm_node->reused_node) {
3481                 err = nes_manage_apbvt(nesvnic, cm_node->loc_port,
3482                                        PCI_FUNC(nesvnic->nesdev->pcidev->devfn),
3483                                        NES_MANAGE_APBVT_ADD);
3484                 if (err) {
3485                         printk(KERN_ERR "nes_manage_apbvt call returned %d.\n",
3486                                err);
3487                         g_cm_core->api->stop_listener(g_cm_core, (void *)cm_node);
3488                         return err;
3489                 }
3490                 atomic_inc(&cm_listens_created);
3491         }
3492
3493         cm_id->add_ref(cm_id);
3494         cm_id->provider_data = (void *)cm_node;
3495
3496
3497         return 0;
3498 }
3499
3500
3501 /**
3502  * nes_destroy_listen
3503  */
3504 int nes_destroy_listen(struct iw_cm_id *cm_id)
3505 {
3506         if (cm_id->provider_data)
3507                 g_cm_core->api->stop_listener(g_cm_core, cm_id->provider_data);
3508         else
3509                 nes_debug(NES_DBG_CM, "cm_id->provider_data was NULL\n");
3510
3511         cm_id->rem_ref(cm_id);
3512
3513         return 0;
3514 }
3515
3516
3517 /**
3518  * nes_cm_recv
3519  */
3520 int nes_cm_recv(struct sk_buff *skb, struct net_device *netdevice)
3521 {
3522         int rc = 0;
3523
3524         cm_packets_received++;
3525         if ((g_cm_core) && (g_cm_core->api))
3526                 rc = g_cm_core->api->recv_pkt(g_cm_core, netdev_priv(netdevice), skb);
3527         else
3528                 nes_debug(NES_DBG_CM, "Unable to process packet for CM,"
3529                           " cm is not setup properly.\n");
3530
3531         return rc;
3532 }
3533
3534
3535 /**
3536  * nes_cm_start
3537  * Start and init a cm core module
3538  */
3539 int nes_cm_start(void)
3540 {
3541         nes_debug(NES_DBG_CM, "\n");
3542         /* create the primary CM core, pass this handle to subsequent core inits */
3543         g_cm_core = nes_cm_alloc_core();
3544         if (g_cm_core)
3545                 return 0;
3546         else
3547                 return -ENOMEM;
3548 }
3549
3550
3551 /**
3552  * nes_cm_stop
3553  * stop and dealloc all cm core instances
3554  */
3555 int nes_cm_stop(void)
3556 {
3557         g_cm_core->api->destroy_cm_core(g_cm_core);
3558         return 0;
3559 }
3560
3561
3562 /**
3563  * cm_event_connected
3564  * handle a connected event, setup QPs and HW
3565  */
3566 static void cm_event_connected(struct nes_cm_event *event)
3567 {
3568         struct nes_qp *nesqp;
3569         struct nes_vnic *nesvnic;
3570         struct nes_device *nesdev;
3571         struct nes_cm_node *cm_node;
3572         struct nes_adapter *nesadapter;
3573         struct ib_qp_attr attr;
3574         struct iw_cm_id *cm_id;
3575         struct iw_cm_event cm_event;
3576         struct nes_v4_quad nes_quad;
3577         u32 crc_value;
3578         int ret;
3579         struct sockaddr_in *laddr;
3580         struct sockaddr_in *raddr;
3581         struct sockaddr_in *cm_event_laddr;
3582
3583         /* get all our handles */
3584         cm_node = event->cm_node;
3585         cm_id = cm_node->cm_id;
3586         nes_debug(NES_DBG_CM, "cm_event_connected - %p - cm_id = %p\n", cm_node, cm_id);
3587         nesqp = (struct nes_qp *)cm_id->provider_data;
3588         nesvnic = to_nesvnic(nesqp->ibqp.device);
3589         nesdev = nesvnic->nesdev;
3590         nesadapter = nesdev->nesadapter;
3591         laddr = (struct sockaddr_in *)&cm_id->m_local_addr;
3592         raddr = (struct sockaddr_in *)&cm_id->m_remote_addr;
3593         cm_event_laddr = (struct sockaddr_in *)&cm_event.local_addr;
3594
3595         if (nesqp->destroyed)
3596                 return;
3597         atomic_inc(&cm_connecteds);
3598         nes_debug(NES_DBG_CM, "QP%u attempting to connect to  0x%08X:0x%04X on"
3599                   " local port 0x%04X. jiffies = %lu.\n",
3600                   nesqp->hwqp.qp_id, ntohl(raddr->sin_addr.s_addr),
3601                   ntohs(raddr->sin_port), ntohs(laddr->sin_port), jiffies);
3602
3603         nes_cm_init_tsa_conn(nesqp, cm_node);
3604
3605         /* set the QP tsa context */
3606         nesqp->nesqp_context->tcpPorts[0] =
3607                         cpu_to_le16(cm_node->loc_port);
3608         nesqp->nesqp_context->tcpPorts[1] =
3609                         cpu_to_le16(cm_node->rem_port);
3610         nesqp->nesqp_context->ip0 = cpu_to_le32(cm_node->rem_addr);
3611
3612         nesqp->nesqp_context->misc2 |= cpu_to_le32(
3613                         (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
3614                         NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
3615         nesqp->nesqp_context->arp_index_vlan |= cpu_to_le32(
3616                         nes_arp_table(nesdev,
3617                         le32_to_cpu(nesqp->nesqp_context->ip0),
3618                         NULL, NES_ARP_RESOLVE) << 16);
3619         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
3620                         jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
3621         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
3622         nesqp->nesqp_context->ird_ord_sizes |=
3623                         cpu_to_le32((u32)1 <<
3624                         NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT);
3625         nesqp->nesqp_context->ird_ord_sizes |=
3626                         cpu_to_le32((u32)cm_node->ord_size);
3627
3628         /* Adjust tail for not having a LSMM */
3629         /*nesqp->hwqp.sq_tail = 1;*/
3630
3631         build_rdma0_msg(cm_node, &nesqp);
3632
3633         nes_write32(nesdev->regs + NES_WQE_ALLOC,
3634                     (1 << 24) | 0x00800000 | nesqp->hwqp.qp_id);
3635
3636         memset(&nes_quad, 0, sizeof(nes_quad));
3637
3638         nes_quad.DstIpAdrIndex =
3639                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
3640         nes_quad.SrcIpadr = htonl(cm_node->rem_addr);
3641         nes_quad.TcpPorts[0] = htons(cm_node->rem_port);
3642         nes_quad.TcpPorts[1] = htons(cm_node->loc_port);
3643
3644         /* Produce hash key */
3645         crc_value = get_crc_value(&nes_quad);
3646         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
3647         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, After CRC = 0x%08X\n",
3648                   nesqp->hte_index, nesqp->hte_index & nesadapter->hte_index_mask);
3649
3650         nesqp->hte_index &= nesadapter->hte_index_mask;
3651         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
3652
3653         nesqp->ietf_frame = &cm_node->mpa_frame;
3654         nesqp->private_data_len = (u8)cm_node->mpa_frame_size;
3655         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
3656
3657         /* notify OF layer we successfully created the requested connection */
3658         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3659         cm_event.status = 0;
3660         cm_event.provider_data = cm_id->provider_data;
3661         cm_event_laddr->sin_family = AF_INET;
3662         cm_event_laddr->sin_port = laddr->sin_port;
3663         cm_event.remote_addr = cm_id->m_remote_addr;
3664
3665         cm_event.private_data = (void *)event->cm_node->mpa_frame_buf;
3666         cm_event.private_data_len = (u8)event->cm_node->mpa_frame_size;
3667         cm_event.ird = cm_node->ird_size;
3668         cm_event.ord = cm_node->ord_size;
3669
3670         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3671         ret = cm_id->event_handler(cm_id, &cm_event);
3672         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3673
3674         if (ret)
3675                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3676                        "ret=%d\n", __func__, __LINE__, ret);
3677         attr.qp_state = IB_QPS_RTS;
3678         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
3679
3680         nes_debug(NES_DBG_CM, "Exiting connect thread for QP%u. jiffies = "
3681                   "%lu\n", nesqp->hwqp.qp_id, jiffies);
3682
3683         return;
3684 }
3685
3686
3687 /**
3688  * cm_event_connect_error
3689  */
3690 static void cm_event_connect_error(struct nes_cm_event *event)
3691 {
3692         struct nes_qp *nesqp;
3693         struct iw_cm_id *cm_id;
3694         struct iw_cm_event cm_event;
3695         /* struct nes_cm_info cm_info; */
3696         int ret;
3697
3698         if (!event->cm_node)
3699                 return;
3700
3701         cm_id = event->cm_node->cm_id;
3702         if (!cm_id)
3703                 return;
3704
3705         nes_debug(NES_DBG_CM, "cm_node=%p, cm_id=%p\n", event->cm_node, cm_id);
3706         nesqp = cm_id->provider_data;
3707
3708         if (!nesqp)
3709                 return;
3710
3711         /* notify OF layer about this connection error event */
3712         /* cm_id->rem_ref(cm_id); */
3713         nesqp->cm_id = NULL;
3714         cm_id->provider_data = NULL;
3715         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3716         cm_event.status = -ECONNRESET;
3717         cm_event.provider_data = cm_id->provider_data;
3718         cm_event.local_addr = cm_id->m_local_addr;
3719         cm_event.remote_addr = cm_id->m_remote_addr;
3720         cm_event.private_data = NULL;
3721         cm_event.private_data_len = 0;
3722
3723 #ifdef CONFIG_INFINIBAND_NES_DEBUG
3724         {
3725                 struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3726                                                      &cm_event.local_addr;
3727                 struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3728                                                      &cm_event.remote_addr;
3729                 nes_debug(NES_DBG_CM, "call CM_EVENT REJECTED, local_addr=%08x, remote_addr=%08x\n",
3730                           cm_event_laddr->sin_addr.s_addr, cm_event_raddr->sin_addr.s_addr);
3731         }
3732 #endif
3733
3734         ret = cm_id->event_handler(cm_id, &cm_event);
3735         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3736         if (ret)
3737                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3738                        "ret=%d\n", __func__, __LINE__, ret);
3739         cm_id->rem_ref(cm_id);
3740
3741         rem_ref_cm_node(event->cm_node->cm_core, event->cm_node);
3742         return;
3743 }
3744
3745
3746 /**
3747  * cm_event_reset
3748  */
3749 static void cm_event_reset(struct nes_cm_event *event)
3750 {
3751         struct nes_qp *nesqp;
3752         struct iw_cm_id *cm_id;
3753         struct iw_cm_event cm_event;
3754         /* struct nes_cm_info cm_info; */
3755         int ret;
3756
3757         if (!event->cm_node)
3758                 return;
3759
3760         if (!event->cm_node->cm_id)
3761                 return;
3762
3763         cm_id = event->cm_node->cm_id;
3764
3765         nes_debug(NES_DBG_CM, "%p - cm_id = %p\n", event->cm_node, cm_id);
3766         nesqp = cm_id->provider_data;
3767         if (!nesqp)
3768                 return;
3769
3770         nesqp->cm_id = NULL;
3771         /* cm_id->provider_data = NULL; */
3772         cm_event.event = IW_CM_EVENT_DISCONNECT;
3773         cm_event.status = -ECONNRESET;
3774         cm_event.provider_data = cm_id->provider_data;
3775         cm_event.local_addr = cm_id->m_local_addr;
3776         cm_event.remote_addr = cm_id->m_remote_addr;
3777         cm_event.private_data = NULL;
3778         cm_event.private_data_len = 0;
3779
3780         cm_id->add_ref(cm_id);
3781         ret = cm_id->event_handler(cm_id, &cm_event);
3782         atomic_inc(&cm_closes);
3783         cm_event.event = IW_CM_EVENT_CLOSE;
3784         cm_event.status = 0;
3785         cm_event.provider_data = cm_id->provider_data;
3786         cm_event.local_addr = cm_id->m_local_addr;
3787         cm_event.remote_addr = cm_id->m_remote_addr;
3788         cm_event.private_data = NULL;
3789         cm_event.private_data_len = 0;
3790         nes_debug(NES_DBG_CM, "NODE %p Generating CLOSE\n", event->cm_node);
3791         ret = cm_id->event_handler(cm_id, &cm_event);
3792
3793         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3794
3795
3796         /* notify OF layer about this connection error event */
3797         cm_id->rem_ref(cm_id);
3798
3799         return;
3800 }
3801
3802
3803 /**
3804  * cm_event_mpa_req
3805  */
3806 static void cm_event_mpa_req(struct nes_cm_event *event)
3807 {
3808         struct iw_cm_id *cm_id;
3809         struct iw_cm_event cm_event;
3810         int ret;
3811         struct nes_cm_node *cm_node;
3812         struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3813                                              &cm_event.local_addr;
3814         struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3815                                              &cm_event.remote_addr;
3816
3817         cm_node = event->cm_node;
3818         if (!cm_node)
3819                 return;
3820         cm_id = cm_node->cm_id;
3821
3822         atomic_inc(&cm_connect_reqs);
3823         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3824                   cm_node, cm_id, jiffies);
3825
3826         cm_event.event = IW_CM_EVENT_CONNECT_REQUEST;
3827         cm_event.status = 0;
3828         cm_event.provider_data = (void *)cm_node;
3829
3830         cm_event_laddr->sin_family = AF_INET;
3831         cm_event_laddr->sin_port = htons(event->cm_info.loc_port);
3832         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3833
3834         cm_event_raddr->sin_family = AF_INET;
3835         cm_event_raddr->sin_port = htons(event->cm_info.rem_port);
3836         cm_event_raddr->sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3837         cm_event.private_data = cm_node->mpa_frame_buf;
3838         cm_event.private_data_len = (u8)cm_node->mpa_frame_size;
3839         if (cm_node->mpa_frame_rev == IETF_MPA_V1) {
3840                 cm_event.ird = NES_MAX_IRD;
3841                 cm_event.ord = NES_MAX_ORD;
3842         } else {
3843         cm_event.ird = cm_node->ird_size;
3844         cm_event.ord = cm_node->ord_size;
3845         }
3846
3847         ret = cm_id->event_handler(cm_id, &cm_event);
3848         if (ret)
3849                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3850                        __func__, __LINE__, ret);
3851         return;
3852 }
3853
3854
3855 static void cm_event_mpa_reject(struct nes_cm_event *event)
3856 {
3857         struct iw_cm_id *cm_id;
3858         struct iw_cm_event cm_event;
3859         struct nes_cm_node *cm_node;
3860         int ret;
3861         struct sockaddr_in *cm_event_laddr = (struct sockaddr_in *)
3862                                              &cm_event.local_addr;
3863         struct sockaddr_in *cm_event_raddr = (struct sockaddr_in *)
3864                                              &cm_event.remote_addr;
3865
3866         cm_node = event->cm_node;
3867         if (!cm_node)
3868                 return;
3869         cm_id = cm_node->cm_id;
3870
3871         atomic_inc(&cm_connect_reqs);
3872         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3873                   cm_node, cm_id, jiffies);
3874
3875         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3876         cm_event.status = -ECONNREFUSED;
3877         cm_event.provider_data = cm_id->provider_data;
3878
3879         cm_event_laddr->sin_family = AF_INET;
3880         cm_event_laddr->sin_port = htons(event->cm_info.loc_port);
3881         cm_event_laddr->sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3882
3883         cm_event_raddr->sin_family = AF_INET;
3884         cm_event_raddr->sin_port = htons(event->cm_info.rem_port);
3885         cm_event_raddr->sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3886
3887         cm_event.private_data = cm_node->mpa_frame_buf;
3888         cm_event.private_data_len = (u8)cm_node->mpa_frame_size;
3889
3890         nes_debug(NES_DBG_CM, "call CM_EVENT_MPA_REJECTED, local_addr=%08x, "
3891                   "remove_addr=%08x\n",
3892                   cm_event_laddr->sin_addr.s_addr,
3893                   cm_event_raddr->sin_addr.s_addr);
3894
3895         ret = cm_id->event_handler(cm_id, &cm_event);
3896         if (ret)
3897                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3898                        __func__, __LINE__, ret);
3899
3900         return;
3901 }
3902
3903
3904 static void nes_cm_event_handler(struct work_struct *);
3905
3906 /**
3907  * nes_cm_post_event
3908  * post an event to the cm event handler
3909  */
3910 static int nes_cm_post_event(struct nes_cm_event *event)
3911 {
3912         atomic_inc(&event->cm_node->cm_core->events_posted);
3913         add_ref_cm_node(event->cm_node);
3914         event->cm_info.cm_id->add_ref(event->cm_info.cm_id);
3915         INIT_WORK(&event->event_work, nes_cm_event_handler);
3916         nes_debug(NES_DBG_CM, "cm_node=%p queue_work, event=%p\n",
3917                   event->cm_node, event);
3918
3919         queue_work(event->cm_node->cm_core->event_wq, &event->event_work);
3920
3921         nes_debug(NES_DBG_CM, "Exit\n");
3922         return 0;
3923 }
3924
3925
3926 /**
3927  * nes_cm_event_handler
3928  * worker function to handle cm events
3929  * will free instance of nes_cm_event
3930  */
3931 static void nes_cm_event_handler(struct work_struct *work)
3932 {
3933         struct nes_cm_event *event = container_of(work, struct nes_cm_event,
3934                                                   event_work);
3935         struct nes_cm_core *cm_core;
3936
3937         if ((!event) || (!event->cm_node) || (!event->cm_node->cm_core))
3938                 return;
3939
3940         cm_core = event->cm_node->cm_core;
3941         nes_debug(NES_DBG_CM, "event=%p, event->type=%u, events posted=%u\n",
3942                   event, event->type, atomic_read(&cm_core->events_posted));
3943
3944         switch (event->type) {
3945         case NES_CM_EVENT_MPA_REQ:
3946                 cm_event_mpa_req(event);
3947                 nes_debug(NES_DBG_CM, "cm_node=%p CM Event: MPA REQUEST\n",
3948                           event->cm_node);
3949                 break;
3950         case NES_CM_EVENT_RESET:
3951                 nes_debug(NES_DBG_CM, "cm_node = %p CM Event: RESET\n",
3952                           event->cm_node);
3953                 cm_event_reset(event);
3954                 break;
3955         case NES_CM_EVENT_CONNECTED:
3956                 if ((!event->cm_node->cm_id) ||
3957                     (event->cm_node->state != NES_CM_STATE_TSA))
3958                         break;
3959                 cm_event_connected(event);
3960                 nes_debug(NES_DBG_CM, "CM Event: CONNECTED\n");
3961                 break;
3962         case NES_CM_EVENT_MPA_REJECT:
3963                 if ((!event->cm_node->cm_id) ||
3964                     (event->cm_node->state == NES_CM_STATE_TSA))
3965                         break;
3966                 cm_event_mpa_reject(event);
3967                 nes_debug(NES_DBG_CM, "CM Event: REJECT\n");
3968                 break;
3969
3970         case NES_CM_EVENT_ABORTED:
3971                 if ((!event->cm_node->cm_id) ||
3972                     (event->cm_node->state == NES_CM_STATE_TSA))
3973                         break;
3974                 cm_event_connect_error(event);
3975                 nes_debug(NES_DBG_CM, "CM Event: ABORTED\n");
3976                 break;
3977         case NES_CM_EVENT_DROPPED_PKT:
3978                 nes_debug(NES_DBG_CM, "CM Event: DROPPED PKT\n");
3979                 break;
3980         default:
3981                 nes_debug(NES_DBG_CM, "CM Event: UNKNOWN EVENT TYPE\n");
3982                 break;
3983         }
3984
3985         atomic_dec(&cm_core->events_posted);
3986         event->cm_info.cm_id->rem_ref(event->cm_info.cm_id);
3987         rem_ref_cm_node(cm_core, event->cm_node);
3988         kfree(event);
3989
3990         return;
3991 }