1/*******************************************************************************
2 * Filename:  target_core_tmr.c
3 *
4 * This file contains SPC-3 task management infrastructure
5 *
6 * (c) Copyright 2009-2013 Datera, Inc.
7 *
8 * Nicholas A. Bellinger <nab@kernel.org>
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License as published by
12 * the Free Software Foundation; either version 2 of the License, or
13 * (at your option) any later version.
14 *
15 * This program is distributed in the hope that it will be useful,
16 * but WITHOUT ANY WARRANTY; without even the implied warranty of
17 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
18 * GNU General Public License for more details.
19 *
20 * You should have received a copy of the GNU General Public License
21 * along with this program; if not, write to the Free Software
22 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
23 *
24 ******************************************************************************/
25
26#include <linux/slab.h>
27#include <linux/spinlock.h>
28#include <linux/list.h>
29#include <linux/export.h>
30#include <scsi/scsi.h>
31#include <scsi/scsi_cmnd.h>
32
33#include <target/target_core_base.h>
34#include <target/target_core_backend.h>
35#include <target/target_core_fabric.h>
36#include <target/target_core_configfs.h>
37
38#include "target_core_internal.h"
39#include "target_core_alua.h"
40#include "target_core_pr.h"
41
42int core_tmr_alloc_req(
43	struct se_cmd *se_cmd,
44	void *fabric_tmr_ptr,
45	u8 function,
46	gfp_t gfp_flags)
47{
48	struct se_tmr_req *tmr;
49
50	tmr = kzalloc(sizeof(struct se_tmr_req), gfp_flags);
51	if (!tmr) {
52		pr_err("Unable to allocate struct se_tmr_req\n");
53		return -ENOMEM;
54	}
55
56	se_cmd->se_cmd_flags |= SCF_SCSI_TMR_CDB;
57	se_cmd->se_tmr_req = tmr;
58	tmr->task_cmd = se_cmd;
59	tmr->fabric_tmr_ptr = fabric_tmr_ptr;
60	tmr->function = function;
61	INIT_LIST_HEAD(&tmr->tmr_list);
62
63	return 0;
64}
65EXPORT_SYMBOL(core_tmr_alloc_req);
66
67void core_tmr_release_req(struct se_tmr_req *tmr)
68{
69	struct se_device *dev = tmr->tmr_dev;
70	unsigned long flags;
71
72	if (dev) {
73		spin_lock_irqsave(&dev->se_tmr_lock, flags);
74		list_del_init(&tmr->tmr_list);
75		spin_unlock_irqrestore(&dev->se_tmr_lock, flags);
76	}
77
78	kfree(tmr);
79}
80
81static void core_tmr_handle_tas_abort(struct se_cmd *cmd, int tas)
82{
83	unsigned long flags;
84	bool remove = true, send_tas;
85	/*
86	 * TASK ABORTED status (TAS) bit support
87	 */
88	spin_lock_irqsave(&cmd->t_state_lock, flags);
89	send_tas = (cmd->transport_state & CMD_T_TAS);
90	spin_unlock_irqrestore(&cmd->t_state_lock, flags);
91
92	if (send_tas) {
93		remove = false;
94		transport_send_task_abort(cmd);
95	}
96
97	transport_cmd_finish_abort(cmd, remove);
98}
99
100static int target_check_cdb_and_preempt(struct list_head *list,
101		struct se_cmd *cmd)
102{
103	struct t10_pr_registration *reg;
104
105	if (!list)
106		return 0;
107	list_for_each_entry(reg, list, pr_reg_abort_list) {
108		if (reg->pr_res_key == cmd->pr_res_key)
109			return 0;
110	}
111
112	return 1;
113}
114
115static bool __target_check_io_state(struct se_cmd *se_cmd,
116				    struct se_session *tmr_sess, int tas)
117{
118	struct se_session *sess = se_cmd->se_sess;
119
120	assert_spin_locked(&sess->sess_cmd_lock);
121	WARN_ON_ONCE(!irqs_disabled());
122	/*
123	 * If command already reached CMD_T_COMPLETE state within
124	 * target_complete_cmd() or CMD_T_FABRIC_STOP due to shutdown,
125	 * this se_cmd has been passed to fabric driver and will
126	 * not be aborted.
127	 *
128	 * Otherwise, obtain a local se_cmd->cmd_kref now for TMR
129	 * ABORT_TASK + LUN_RESET for CMD_T_ABORTED processing as
130	 * long as se_cmd->cmd_kref is still active unless zero.
131	 */
132	spin_lock(&se_cmd->t_state_lock);
133	if (se_cmd->transport_state & (CMD_T_COMPLETE | CMD_T_FABRIC_STOP)) {
134		pr_debug("Attempted to abort io tag: %u already complete or"
135			" fabric stop, skipping\n",
136			se_cmd->se_tfo->get_task_tag(se_cmd));
137		spin_unlock(&se_cmd->t_state_lock);
138		return false;
139	}
140	if (sess->sess_tearing_down || se_cmd->cmd_wait_set) {
141		pr_debug("Attempted to abort io tag: %u already shutdown,"
142			" skipping\n", se_cmd->se_tfo->get_task_tag(se_cmd));
143		spin_unlock(&se_cmd->t_state_lock);
144		return false;
145	}
146	se_cmd->transport_state |= CMD_T_ABORTED;
147
148	if ((tmr_sess != se_cmd->se_sess) && tas)
149		se_cmd->transport_state |= CMD_T_TAS;
150
151	spin_unlock(&se_cmd->t_state_lock);
152
153	return kref_get_unless_zero(&se_cmd->cmd_kref);
154}
155
156void core_tmr_abort_task(
157	struct se_device *dev,
158	struct se_tmr_req *tmr,
159	struct se_session *se_sess)
160{
161	struct se_cmd *se_cmd;
162	unsigned long flags;
163	int ref_tag;
164
165	spin_lock_irqsave(&se_sess->sess_cmd_lock, flags);
166	list_for_each_entry(se_cmd, &se_sess->sess_cmd_list, se_cmd_list) {
167
168		if (dev != se_cmd->se_dev)
169			continue;
170
171		/* skip task management functions, including tmr->task_cmd */
172		if (se_cmd->se_cmd_flags & SCF_SCSI_TMR_CDB)
173			continue;
174
175		ref_tag = se_cmd->se_tfo->get_task_tag(se_cmd);
176		if (tmr->ref_task_tag != ref_tag)
177			continue;
178
179		printk("ABORT_TASK: Found referenced %s task_tag: %u\n",
180			se_cmd->se_tfo->get_fabric_name(), ref_tag);
181
182		if (!__target_check_io_state(se_cmd, se_sess, 0)) {
183			spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
184			goto out;
185		}
186
187		list_del_init(&se_cmd->se_cmd_list);
188		spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
189
190		cancel_work_sync(&se_cmd->work);
191		transport_wait_for_tasks(se_cmd);
192
193		transport_cmd_finish_abort(se_cmd, true);
194		target_put_sess_cmd(se_cmd);
195
196		printk("ABORT_TASK: Sending TMR_FUNCTION_COMPLETE for"
197				" ref_tag: %d\n", ref_tag);
198		tmr->response = TMR_FUNCTION_COMPLETE;
199		return;
200	}
201	spin_unlock_irqrestore(&se_sess->sess_cmd_lock, flags);
202
203out:
204	printk("ABORT_TASK: Sending TMR_TASK_DOES_NOT_EXIST for ref_tag: %d\n",
205			tmr->ref_task_tag);
206	tmr->response = TMR_TASK_DOES_NOT_EXIST;
207}
208
209static void core_tmr_drain_tmr_list(
210	struct se_device *dev,
211	struct se_tmr_req *tmr,
212	struct list_head *preempt_and_abort_list)
213{
214	LIST_HEAD(drain_tmr_list);
215	struct se_session *sess;
216	struct se_tmr_req *tmr_p, *tmr_pp;
217	struct se_cmd *cmd;
218	unsigned long flags;
219	bool rc;
220	/*
221	 * Release all pending and outgoing TMRs aside from the received
222	 * LUN_RESET tmr..
223	 */
224	spin_lock_irqsave(&dev->se_tmr_lock, flags);
225	list_for_each_entry_safe(tmr_p, tmr_pp, &dev->dev_tmr_list, tmr_list) {
226		/*
227		 * Allow the received TMR to return with FUNCTION_COMPLETE.
228		 */
229		if (tmr_p == tmr)
230			continue;
231
232		cmd = tmr_p->task_cmd;
233		if (!cmd) {
234			pr_err("Unable to locate struct se_cmd for TMR\n");
235			continue;
236		}
237		/*
238		 * If this function was called with a valid pr_res_key
239		 * parameter (eg: for PROUT PREEMPT_AND_ABORT service action
240		 * skip non regisration key matching TMRs.
241		 */
242		if (target_check_cdb_and_preempt(preempt_and_abort_list, cmd))
243			continue;
244
245		sess = cmd->se_sess;
246		if (WARN_ON_ONCE(!sess))
247			continue;
248
249		spin_lock(&sess->sess_cmd_lock);
250		spin_lock(&cmd->t_state_lock);
251		if (!(cmd->transport_state & CMD_T_ACTIVE) ||
252		     (cmd->transport_state & CMD_T_FABRIC_STOP)) {
253			spin_unlock(&cmd->t_state_lock);
254			spin_unlock(&sess->sess_cmd_lock);
255			continue;
256		}
257		if (cmd->t_state == TRANSPORT_ISTATE_PROCESSING) {
258			spin_unlock(&cmd->t_state_lock);
259			spin_unlock(&sess->sess_cmd_lock);
260			continue;
261		}
262		if (sess->sess_tearing_down || cmd->cmd_wait_set) {
263			spin_unlock(&cmd->t_state_lock);
264			spin_unlock(&sess->sess_cmd_lock);
265			continue;
266		}
267		cmd->transport_state |= CMD_T_ABORTED;
268		spin_unlock(&cmd->t_state_lock);
269
270		rc = kref_get_unless_zero(&cmd->cmd_kref);
271		if (!rc) {
272			printk("LUN_RESET TMR: non-zero kref_get_unless_zero\n");
273			spin_unlock(&sess->sess_cmd_lock);
274			continue;
275		}
276		spin_unlock(&sess->sess_cmd_lock);
277
278		list_move_tail(&tmr_p->tmr_list, &drain_tmr_list);
279	}
280	spin_unlock_irqrestore(&dev->se_tmr_lock, flags);
281
282	list_for_each_entry_safe(tmr_p, tmr_pp, &drain_tmr_list, tmr_list) {
283		list_del_init(&tmr_p->tmr_list);
284		cmd = tmr_p->task_cmd;
285
286		pr_debug("LUN_RESET: %s releasing TMR %p Function: 0x%02x,"
287			" Response: 0x%02x, t_state: %d\n",
288			(preempt_and_abort_list) ? "Preempt" : "", tmr_p,
289			tmr_p->function, tmr_p->response, cmd->t_state);
290
291		cancel_work_sync(&cmd->work);
292		transport_wait_for_tasks(cmd);
293
294		transport_cmd_finish_abort(cmd, 1);
295		target_put_sess_cmd(cmd);
296	}
297}
298
299static void core_tmr_drain_state_list(
300	struct se_device *dev,
301	struct se_cmd *prout_cmd,
302	struct se_session *tmr_sess,
303	int tas,
304	struct list_head *preempt_and_abort_list)
305{
306	LIST_HEAD(drain_task_list);
307	struct se_session *sess;
308	struct se_cmd *cmd, *next;
309	unsigned long flags;
310	int rc;
311
312	/*
313	 * Complete outstanding commands with TASK_ABORTED SAM status.
314	 *
315	 * This is following sam4r17, section 5.6 Aborting commands, Table 38
316	 * for TMR LUN_RESET:
317	 *
318	 * a) "Yes" indicates that each command that is aborted on an I_T nexus
319	 * other than the one that caused the SCSI device condition is
320	 * completed with TASK ABORTED status, if the TAS bit is set to one in
321	 * the Control mode page (see SPC-4). "No" indicates that no status is
322	 * returned for aborted commands.
323	 *
324	 * d) If the logical unit reset is caused by a particular I_T nexus
325	 * (e.g., by a LOGICAL UNIT RESET task management function), then "yes"
326	 * (TASK_ABORTED status) applies.
327	 *
328	 * Otherwise (e.g., if triggered by a hard reset), "no"
329	 * (no TASK_ABORTED SAM status) applies.
330	 *
331	 * Note that this seems to be independent of TAS (Task Aborted Status)
332	 * in the Control Mode Page.
333	 */
334	spin_lock_irqsave(&dev->execute_task_lock, flags);
335	list_for_each_entry_safe(cmd, next, &dev->state_list, state_list) {
336		/*
337		 * For PREEMPT_AND_ABORT usage, only process commands
338		 * with a matching reservation key.
339		 */
340		if (target_check_cdb_and_preempt(preempt_and_abort_list, cmd))
341			continue;
342
343		/*
344		 * Not aborting PROUT PREEMPT_AND_ABORT CDB..
345		 */
346		if (prout_cmd == cmd)
347			continue;
348
349		sess = cmd->se_sess;
350		if (WARN_ON_ONCE(!sess))
351			continue;
352
353		spin_lock(&sess->sess_cmd_lock);
354		rc = __target_check_io_state(cmd, tmr_sess, tas);
355		spin_unlock(&sess->sess_cmd_lock);
356		if (!rc)
357			continue;
358
359		list_move_tail(&cmd->state_list, &drain_task_list);
360		cmd->state_active = false;
361	}
362	spin_unlock_irqrestore(&dev->execute_task_lock, flags);
363
364	while (!list_empty(&drain_task_list)) {
365		cmd = list_entry(drain_task_list.next, struct se_cmd, state_list);
366		list_del_init(&cmd->state_list);
367
368		pr_debug("LUN_RESET: %s cmd: %p"
369			" ITT/CmdSN: 0x%08x/0x%08x, i_state: %d, t_state: %d"
370			"cdb: 0x%02x\n",
371			(preempt_and_abort_list) ? "Preempt" : "", cmd,
372			cmd->se_tfo->get_task_tag(cmd), 0,
373			cmd->se_tfo->get_cmd_state(cmd), cmd->t_state,
374			cmd->t_task_cdb[0]);
375		pr_debug("LUN_RESET: ITT[0x%08x] - pr_res_key: 0x%016Lx"
376			" -- CMD_T_ACTIVE: %d"
377			" CMD_T_STOP: %d CMD_T_SENT: %d\n",
378			cmd->se_tfo->get_task_tag(cmd), cmd->pr_res_key,
379			(cmd->transport_state & CMD_T_ACTIVE) != 0,
380			(cmd->transport_state & CMD_T_STOP) != 0,
381			(cmd->transport_state & CMD_T_SENT) != 0);
382
383		/*
384		 * If the command may be queued onto a workqueue cancel it now.
385		 *
386		 * This is equivalent to removal from the execute queue in the
387		 * loop above, but we do it down here given that
388		 * cancel_work_sync may block.
389		 */
390		cancel_work_sync(&cmd->work);
391		transport_wait_for_tasks(cmd);
392
393		core_tmr_handle_tas_abort(cmd, tas);
394		target_put_sess_cmd(cmd);
395	}
396}
397
398int core_tmr_lun_reset(
399        struct se_device *dev,
400        struct se_tmr_req *tmr,
401        struct list_head *preempt_and_abort_list,
402        struct se_cmd *prout_cmd)
403{
404	struct se_node_acl *tmr_nacl = NULL;
405	struct se_portal_group *tmr_tpg = NULL;
406	struct se_session *tmr_sess = NULL;
407	int tas;
408        /*
409	 * TASK_ABORTED status bit, this is configurable via ConfigFS
410	 * struct se_device attributes.  spc4r17 section 7.4.6 Control mode page
411	 *
412	 * A task aborted status (TAS) bit set to zero specifies that aborted
413	 * tasks shall be terminated by the device server without any response
414	 * to the application client. A TAS bit set to one specifies that tasks
415	 * aborted by the actions of an I_T nexus other than the I_T nexus on
416	 * which the command was received shall be completed with TASK ABORTED
417	 * status (see SAM-4).
418	 */
419	tas = dev->dev_attrib.emulate_tas;
420	/*
421	 * Determine if this se_tmr is coming from a $FABRIC_MOD
422	 * or struct se_device passthrough..
423	 */
424	if (tmr && tmr->task_cmd && tmr->task_cmd->se_sess) {
425		tmr_sess = tmr->task_cmd->se_sess;
426		tmr_nacl = tmr_sess->se_node_acl;
427		tmr_tpg = tmr_sess->se_tpg;
428		if (tmr_nacl && tmr_tpg) {
429			pr_debug("LUN_RESET: TMR caller fabric: %s"
430				" initiator port %s\n",
431				tmr_tpg->se_tpg_tfo->get_fabric_name(),
432				tmr_nacl->initiatorname);
433		}
434	}
435	pr_debug("LUN_RESET: %s starting for [%s], tas: %d\n",
436		(preempt_and_abort_list) ? "Preempt" : "TMR",
437		dev->transport->name, tas);
438
439	core_tmr_drain_tmr_list(dev, tmr, preempt_and_abort_list);
440	core_tmr_drain_state_list(dev, prout_cmd, tmr_sess, tas,
441				preempt_and_abort_list);
442
443	/*
444	 * Clear any legacy SPC-2 reservation when called during
445	 * LOGICAL UNIT RESET
446	 */
447	if (!preempt_and_abort_list &&
448	     (dev->dev_reservation_flags & DRF_SPC2_RESERVATIONS)) {
449		spin_lock(&dev->dev_reservation_lock);
450		dev->dev_reserved_node_acl = NULL;
451		dev->dev_reservation_flags &= ~DRF_SPC2_RESERVATIONS;
452		spin_unlock(&dev->dev_reservation_lock);
453		pr_debug("LUN_RESET: SCSI-2 Released reservation\n");
454	}
455
456	atomic_long_inc(&dev->num_resets);
457
458	pr_debug("LUN_RESET: %s for [%s] Complete\n",
459			(preempt_and_abort_list) ? "Preempt" : "TMR",
460			dev->transport->name);
461	return 0;
462}
463
464