Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wirel...
[pandora-kernel.git] / drivers / infiniband / hw / nes / nes_cm.c
1 /*
2  * Copyright (c) 2006 - 2009 Intel Corporation.  All rights reserved.
3  *
4  * This software is available to you under a choice of one of two
5  * licenses.  You may choose to be licensed under the terms of the GNU
6  * General Public License (GPL) Version 2, available from the file
7  * COPYING in the main directory of this source tree, or the
8  * OpenIB.org BSD license below:
9  *
10  *     Redistribution and use in source and binary forms, with or
11  *     without modification, are permitted provided that the following
12  *     conditions are met:
13  *
14  *      - Redistributions of source code must retain the above
15  *        copyright notice, this list of conditions and the following
16  *        disclaimer.
17  *
18  *      - Redistributions in binary form must reproduce the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer in the documentation and/or other materials
21  *        provided with the distribution.
22  *
23  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
24  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
25  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
26  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
27  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
28  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
29  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
30  * SOFTWARE.
31  *
32  */
33
34
35 #define TCPOPT_TIMESTAMP 8
36
37 #include <asm/atomic.h>
38 #include <linux/skbuff.h>
39 #include <linux/ip.h>
40 #include <linux/tcp.h>
41 #include <linux/init.h>
42 #include <linux/if_arp.h>
43 #include <linux/if_vlan.h>
44 #include <linux/notifier.h>
45 #include <linux/net.h>
46 #include <linux/types.h>
47 #include <linux/timer.h>
48 #include <linux/time.h>
49 #include <linux/delay.h>
50 #include <linux/etherdevice.h>
51 #include <linux/netdevice.h>
52 #include <linux/random.h>
53 #include <linux/list.h>
54 #include <linux/threads.h>
55 #include <linux/highmem.h>
56 #include <linux/slab.h>
57 #include <net/arp.h>
58 #include <net/neighbour.h>
59 #include <net/route.h>
60 #include <net/ip_fib.h>
61 #include <net/tcp.h>
62
63 #include "nes.h"
64
65 u32 cm_packets_sent;
66 u32 cm_packets_bounced;
67 u32 cm_packets_dropped;
68 u32 cm_packets_retrans;
69 u32 cm_packets_created;
70 u32 cm_packets_received;
71 atomic_t cm_listens_created;
72 atomic_t cm_listens_destroyed;
73 u32 cm_backlog_drops;
74 atomic_t cm_loopbacks;
75 atomic_t cm_nodes_created;
76 atomic_t cm_nodes_destroyed;
77 atomic_t cm_accel_dropped_pkts;
78 atomic_t cm_resets_recvd;
79
80 static inline int mini_cm_accelerated(struct nes_cm_core *,
81         struct nes_cm_node *);
82 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *,
83         struct nes_vnic *, struct nes_cm_info *);
84 static int mini_cm_del_listen(struct nes_cm_core *, struct nes_cm_listener *);
85 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *,
86         struct nes_vnic *, u16, void *, struct nes_cm_info *);
87 static int mini_cm_close(struct nes_cm_core *, struct nes_cm_node *);
88 static int mini_cm_accept(struct nes_cm_core *, struct ietf_mpa_frame *,
89         struct nes_cm_node *);
90 static int mini_cm_reject(struct nes_cm_core *, struct ietf_mpa_frame *,
91         struct nes_cm_node *);
92 static int mini_cm_recv_pkt(struct nes_cm_core *, struct nes_vnic *,
93         struct sk_buff *);
94 static int mini_cm_dealloc_core(struct nes_cm_core *);
95 static int mini_cm_get(struct nes_cm_core *);
96 static int mini_cm_set(struct nes_cm_core *, u32, u32);
97
98 static void form_cm_frame(struct sk_buff *, struct nes_cm_node *,
99         void *, u32, void *, u32, u8);
100 static int add_ref_cm_node(struct nes_cm_node *);
101 static int rem_ref_cm_node(struct nes_cm_core *, struct nes_cm_node *);
102
103 static int nes_cm_disconn_true(struct nes_qp *);
104 static int nes_cm_post_event(struct nes_cm_event *event);
105 static int nes_disconnect(struct nes_qp *nesqp, int abrupt);
106 static void nes_disconnect_worker(struct work_struct *work);
107
108 static int send_mpa_request(struct nes_cm_node *, struct sk_buff *);
109 static int send_mpa_reject(struct nes_cm_node *);
110 static int send_syn(struct nes_cm_node *, u32, struct sk_buff *);
111 static int send_reset(struct nes_cm_node *, struct sk_buff *);
112 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb);
113 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb);
114 static void process_packet(struct nes_cm_node *, struct sk_buff *,
115         struct nes_cm_core *);
116
117 static void active_open_err(struct nes_cm_node *, struct sk_buff *, int);
118 static void passive_open_err(struct nes_cm_node *, struct sk_buff *, int);
119 static void cleanup_retrans_entry(struct nes_cm_node *);
120 static void handle_rcv_mpa(struct nes_cm_node *, struct sk_buff *);
121 static void free_retrans_entry(struct nes_cm_node *cm_node);
122 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph,
123         struct sk_buff *skb, int optionsize, int passive);
124
125 /* CM event handler functions */
126 static void cm_event_connected(struct nes_cm_event *);
127 static void cm_event_connect_error(struct nes_cm_event *);
128 static void cm_event_reset(struct nes_cm_event *);
129 static void cm_event_mpa_req(struct nes_cm_event *);
130 static void cm_event_mpa_reject(struct nes_cm_event *);
131 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node);
132
133 static void print_core(struct nes_cm_core *core);
134
135 /* External CM API Interface */
136 /* instance of function pointers for client API */
137 /* set address of this instance to cm_core->cm_ops at cm_core alloc */
138 static struct nes_cm_ops nes_cm_api = {
139         mini_cm_accelerated,
140         mini_cm_listen,
141         mini_cm_del_listen,
142         mini_cm_connect,
143         mini_cm_close,
144         mini_cm_accept,
145         mini_cm_reject,
146         mini_cm_recv_pkt,
147         mini_cm_dealloc_core,
148         mini_cm_get,
149         mini_cm_set
150 };
151
152 static struct nes_cm_core *g_cm_core;
153
154 atomic_t cm_connects;
155 atomic_t cm_accepts;
156 atomic_t cm_disconnects;
157 atomic_t cm_closes;
158 atomic_t cm_connecteds;
159 atomic_t cm_connect_reqs;
160 atomic_t cm_rejects;
161
162
163 /**
164  * create_event
165  */
166 static struct nes_cm_event *create_event(struct nes_cm_node *cm_node,
167                 enum nes_cm_event_type type)
168 {
169         struct nes_cm_event *event;
170
171         if (!cm_node->cm_id)
172                 return NULL;
173
174         /* allocate an empty event */
175         event = kzalloc(sizeof(*event), GFP_ATOMIC);
176
177         if (!event)
178                 return NULL;
179
180         event->type = type;
181         event->cm_node = cm_node;
182         event->cm_info.rem_addr = cm_node->rem_addr;
183         event->cm_info.loc_addr = cm_node->loc_addr;
184         event->cm_info.rem_port = cm_node->rem_port;
185         event->cm_info.loc_port = cm_node->loc_port;
186         event->cm_info.cm_id = cm_node->cm_id;
187
188         nes_debug(NES_DBG_CM, "cm_node=%p Created event=%p, type=%u, "
189                 "dst_addr=%08x[%x], src_addr=%08x[%x]\n",
190                 cm_node, event, type, event->cm_info.loc_addr,
191                 event->cm_info.loc_port, event->cm_info.rem_addr,
192                 event->cm_info.rem_port);
193
194         nes_cm_post_event(event);
195         return event;
196 }
197
198
199 /**
200  * send_mpa_request
201  */
202 static int send_mpa_request(struct nes_cm_node *cm_node, struct sk_buff *skb)
203 {
204         if (!skb) {
205                 nes_debug(NES_DBG_CM, "skb set to NULL\n");
206                 return -1;
207         }
208
209         /* send an MPA Request frame */
210         form_cm_frame(skb, cm_node, NULL, 0, &cm_node->mpa_frame,
211                         cm_node->mpa_frame_size, SET_ACK);
212
213         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
214 }
215
216
217
218 static int send_mpa_reject(struct nes_cm_node *cm_node)
219 {
220         struct sk_buff  *skb = NULL;
221
222         skb = dev_alloc_skb(MAX_CM_BUFFER);
223         if (!skb) {
224                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
225                 return -ENOMEM;
226         }
227
228         /* send an MPA reject frame */
229         form_cm_frame(skb, cm_node, NULL, 0, &cm_node->mpa_frame,
230                         cm_node->mpa_frame_size, SET_ACK | SET_FIN);
231
232         cm_node->state = NES_CM_STATE_FIN_WAIT1;
233         return schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
234 }
235
236
237 /**
238  * recv_mpa - process a received TCP pkt, we are expecting an
239  * IETF MPA frame
240  */
241 static int parse_mpa(struct nes_cm_node *cm_node, u8 *buffer, u32 *type,
242                 u32 len)
243 {
244         struct ietf_mpa_frame *mpa_frame;
245
246         *type = NES_MPA_REQUEST_ACCEPT;
247
248         /* assume req frame is in tcp data payload */
249         if (len < sizeof(struct ietf_mpa_frame)) {
250                 nes_debug(NES_DBG_CM, "The received ietf buffer was too small (%x)\n", len);
251                 return -EINVAL;
252         }
253
254         mpa_frame = (struct ietf_mpa_frame *)buffer;
255         cm_node->mpa_frame_size = ntohs(mpa_frame->priv_data_len);
256         /* make sure mpa private data len is less than 512 bytes */
257         if (cm_node->mpa_frame_size > IETF_MAX_PRIV_DATA_LEN) {
258                 nes_debug(NES_DBG_CM, "The received Length of Private"
259                         " Data field exceeds 512 octets\n");
260                 return -EINVAL;
261         }
262         /*
263          * make sure MPA receiver interoperate with the
264          * received MPA version and MPA key information
265          *
266          */
267         if (mpa_frame->rev != mpa_version) {
268                 nes_debug(NES_DBG_CM, "The received mpa version"
269                                 " can not be interoperated\n");
270                 return -EINVAL;
271         }
272         if (cm_node->state != NES_CM_STATE_MPAREQ_SENT) {
273                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE)) {
274                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
275                         return -EINVAL;
276                 }
277         } else {
278                 if (memcmp(mpa_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE)) {
279                         nes_debug(NES_DBG_CM, "Unexpected MPA Key received \n");
280                         return -EINVAL;
281                 }
282         }
283
284         if (cm_node->mpa_frame_size + sizeof(struct ietf_mpa_frame) != len) {
285                 nes_debug(NES_DBG_CM, "The received ietf buffer was not right"
286                                 " complete (%x + %x != %x)\n",
287                                 cm_node->mpa_frame_size,
288                                 (u32)sizeof(struct ietf_mpa_frame), len);
289                 return -EINVAL;
290         }
291         /* make sure it does not exceed the max size */
292         if (len > MAX_CM_BUFFER) {
293                 nes_debug(NES_DBG_CM, "The received ietf buffer was too large"
294                                 " (%x + %x != %x)\n",
295                                 cm_node->mpa_frame_size,
296                                 (u32)sizeof(struct ietf_mpa_frame), len);
297                 return -EINVAL;
298         }
299
300         /* copy entire MPA frame to our cm_node's frame */
301         memcpy(cm_node->mpa_frame_buf, buffer + sizeof(struct ietf_mpa_frame),
302                         cm_node->mpa_frame_size);
303
304         if (mpa_frame->flags & IETF_MPA_FLAGS_REJECT)
305                 *type = NES_MPA_REQUEST_REJECT;
306         return 0;
307 }
308
309
310 /**
311  * form_cm_frame - get a free packet and build empty frame Use
312  * node info to build.
313  */
314 static void form_cm_frame(struct sk_buff *skb,
315         struct nes_cm_node *cm_node, void *options, u32 optionsize,
316         void *data, u32 datasize, u8 flags)
317 {
318         struct tcphdr *tcph;
319         struct iphdr *iph;
320         struct ethhdr *ethh;
321         u8 *buf;
322         u16 packetsize = sizeof(*iph);
323
324         packetsize += sizeof(*tcph);
325         packetsize +=  optionsize + datasize;
326
327         memset(skb->data, 0x00, ETH_HLEN + sizeof(*iph) + sizeof(*tcph));
328
329         skb->len = 0;
330         buf = skb_put(skb, packetsize + ETH_HLEN);
331
332         ethh = (struct ethhdr *) buf;
333         buf += ETH_HLEN;
334
335         iph = (struct iphdr *)buf;
336         buf += sizeof(*iph);
337         tcph = (struct tcphdr *)buf;
338         skb_reset_mac_header(skb);
339         skb_set_network_header(skb, ETH_HLEN);
340         skb_set_transport_header(skb, ETH_HLEN+sizeof(*iph));
341         buf += sizeof(*tcph);
342
343         skb->ip_summed = CHECKSUM_PARTIAL;
344         skb->protocol = htons(0x800);
345         skb->data_len = 0;
346         skb->mac_len = ETH_HLEN;
347
348         memcpy(ethh->h_dest, cm_node->rem_mac, ETH_ALEN);
349         memcpy(ethh->h_source, cm_node->loc_mac, ETH_ALEN);
350         ethh->h_proto = htons(0x0800);
351
352         iph->version = IPVERSION;
353         iph->ihl = 5;           /* 5 * 4Byte words, IP headr len */
354         iph->tos = 0;
355         iph->tot_len = htons(packetsize);
356         iph->id = htons(++cm_node->tcp_cntxt.loc_id);
357
358         iph->frag_off = htons(0x4000);
359         iph->ttl = 0x40;
360         iph->protocol = 0x06;   /* IPPROTO_TCP */
361
362         iph->saddr = htonl(cm_node->loc_addr);
363         iph->daddr = htonl(cm_node->rem_addr);
364
365         tcph->source = htons(cm_node->loc_port);
366         tcph->dest = htons(cm_node->rem_port);
367         tcph->seq = htonl(cm_node->tcp_cntxt.loc_seq_num);
368
369         if (flags & SET_ACK) {
370                 cm_node->tcp_cntxt.loc_ack_num = cm_node->tcp_cntxt.rcv_nxt;
371                 tcph->ack_seq = htonl(cm_node->tcp_cntxt.loc_ack_num);
372                 tcph->ack = 1;
373         } else
374                 tcph->ack_seq = 0;
375
376         if (flags & SET_SYN) {
377                 cm_node->tcp_cntxt.loc_seq_num++;
378                 tcph->syn = 1;
379         } else
380                 cm_node->tcp_cntxt.loc_seq_num += datasize;
381
382         if (flags & SET_FIN) {
383                 cm_node->tcp_cntxt.loc_seq_num++;
384                 tcph->fin = 1;
385         }
386
387         if (flags & SET_RST)
388                 tcph->rst = 1;
389
390         tcph->doff = (u16)((sizeof(*tcph) + optionsize + 3) >> 2);
391         tcph->window = htons(cm_node->tcp_cntxt.rcv_wnd);
392         tcph->urg_ptr = 0;
393         if (optionsize)
394                 memcpy(buf, options, optionsize);
395         buf += optionsize;
396         if (datasize)
397                 memcpy(buf, data, datasize);
398
399         skb_shinfo(skb)->nr_frags = 0;
400         cm_packets_created++;
401
402 }
403
404
405 /**
406  * print_core - dump a cm core
407  */
408 static void print_core(struct nes_cm_core *core)
409 {
410         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
411         nes_debug(NES_DBG_CM, "CM Core  -- (core = %p )\n", core);
412         if (!core)
413                 return;
414         nes_debug(NES_DBG_CM, "---------------------------------------------\n");
415
416         nes_debug(NES_DBG_CM, "State         : %u \n",  core->state);
417
418         nes_debug(NES_DBG_CM, "Listen Nodes  : %u \n", atomic_read(&core->listen_node_cnt));
419         nes_debug(NES_DBG_CM, "Active Nodes  : %u \n", atomic_read(&core->node_cnt));
420
421         nes_debug(NES_DBG_CM, "core          : %p \n", core);
422
423         nes_debug(NES_DBG_CM, "-------------- end core ---------------\n");
424 }
425
426
427 /**
428  * schedule_nes_timer
429  * note - cm_node needs to be protected before calling this. Encase in:
430  *                      rem_ref_cm_node(cm_core, cm_node);add_ref_cm_node(cm_node);
431  */
432 int schedule_nes_timer(struct nes_cm_node *cm_node, struct sk_buff *skb,
433                 enum nes_timer_type type, int send_retrans,
434                 int close_when_complete)
435 {
436         unsigned long  flags;
437         struct nes_cm_core *cm_core = cm_node->cm_core;
438         struct nes_timer_entry *new_send;
439         int ret = 0;
440         u32 was_timer_set;
441
442         new_send = kzalloc(sizeof(*new_send), GFP_ATOMIC);
443         if (!new_send)
444                 return -ENOMEM;
445
446         /* new_send->timetosend = currenttime */
447         new_send->retrycount = NES_DEFAULT_RETRYS;
448         new_send->retranscount = NES_DEFAULT_RETRANS;
449         new_send->skb = skb;
450         new_send->timetosend = jiffies;
451         new_send->type = type;
452         new_send->netdev = cm_node->netdev;
453         new_send->send_retrans = send_retrans;
454         new_send->close_when_complete = close_when_complete;
455
456         if (type == NES_TIMER_TYPE_CLOSE) {
457                 new_send->timetosend += (HZ/10);
458                 if (cm_node->recv_entry) {
459                         kfree(new_send);
460                         WARN_ON(1);
461                         return -EINVAL;
462                 }
463                 cm_node->recv_entry = new_send;
464         }
465
466         if (type == NES_TIMER_TYPE_SEND) {
467                 new_send->seq_num = ntohl(tcp_hdr(skb)->seq);
468                 atomic_inc(&new_send->skb->users);
469                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
470                 cm_node->send_entry = new_send;
471                 add_ref_cm_node(cm_node);
472                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
473                 new_send->timetosend = jiffies + NES_RETRY_TIMEOUT;
474
475                 ret = nes_nic_cm_xmit(new_send->skb, cm_node->netdev);
476                 if (ret != NETDEV_TX_OK) {
477                         nes_debug(NES_DBG_CM, "Error sending packet %p "
478                                 "(jiffies = %lu)\n", new_send, jiffies);
479                         new_send->timetosend = jiffies;
480                         ret = NETDEV_TX_OK;
481                 } else {
482                         cm_packets_sent++;
483                         if (!send_retrans) {
484                                 cleanup_retrans_entry(cm_node);
485                                 if (close_when_complete)
486                                         rem_ref_cm_node(cm_core, cm_node);
487                                 return ret;
488                         }
489                 }
490         }
491
492         was_timer_set = timer_pending(&cm_core->tcp_timer);
493
494         if (!was_timer_set) {
495                 cm_core->tcp_timer.expires = new_send->timetosend;
496                 add_timer(&cm_core->tcp_timer);
497         }
498
499         return ret;
500 }
501
502 static void nes_retrans_expired(struct nes_cm_node *cm_node)
503 {
504         struct iw_cm_id *cm_id = cm_node->cm_id;
505         enum nes_cm_node_state state = cm_node->state;
506         cm_node->state = NES_CM_STATE_CLOSED;
507         switch (state) {
508         case NES_CM_STATE_SYN_RCVD:
509         case NES_CM_STATE_CLOSING:
510                 rem_ref_cm_node(cm_node->cm_core, cm_node);
511                 break;
512         case NES_CM_STATE_LAST_ACK:
513         case NES_CM_STATE_FIN_WAIT1:
514                 if (cm_node->cm_id)
515                         cm_id->rem_ref(cm_id);
516                 send_reset(cm_node, NULL);
517                 break;
518         default:
519                 add_ref_cm_node(cm_node);
520                 send_reset(cm_node, NULL);
521                 create_event(cm_node, NES_CM_EVENT_ABORTED);
522         }
523 }
524
525 static void handle_recv_entry(struct nes_cm_node *cm_node, u32 rem_node)
526 {
527         struct nes_timer_entry *recv_entry = cm_node->recv_entry;
528         struct iw_cm_id *cm_id = cm_node->cm_id;
529         struct nes_qp *nesqp;
530         unsigned long qplockflags;
531
532         if (!recv_entry)
533                 return;
534         nesqp = (struct nes_qp *)recv_entry->skb;
535         if (nesqp) {
536                 spin_lock_irqsave(&nesqp->lock, qplockflags);
537                 if (nesqp->cm_id) {
538                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
539                                 "refcount = %d: HIT A "
540                                 "NES_TIMER_TYPE_CLOSE with something "
541                                 "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
542                                 atomic_read(&nesqp->refcount));
543                         nesqp->hw_tcp_state = NES_AEQE_TCP_STATE_CLOSED;
544                         nesqp->last_aeq = NES_AEQE_AEID_RESET_SENT;
545                         nesqp->ibqp_state = IB_QPS_ERR;
546                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
547                         nes_cm_disconn(nesqp);
548                 } else {
549                         spin_unlock_irqrestore(&nesqp->lock, qplockflags);
550                         nes_debug(NES_DBG_CM, "QP%u: cm_id = %p, "
551                                 "refcount = %d: HIT A "
552                                 "NES_TIMER_TYPE_CLOSE with nothing "
553                                 "to do!!!\n", nesqp->hwqp.qp_id, cm_id,
554                                 atomic_read(&nesqp->refcount));
555                 }
556         } else if (rem_node) {
557                 /* TIME_WAIT state */
558                 rem_ref_cm_node(cm_node->cm_core, cm_node);
559         }
560         if (cm_node->cm_id)
561                 cm_id->rem_ref(cm_id);
562         kfree(recv_entry);
563         cm_node->recv_entry = NULL;
564 }
565
566 /**
567  * nes_cm_timer_tick
568  */
569 static void nes_cm_timer_tick(unsigned long pass)
570 {
571         unsigned long flags;
572         unsigned long nexttimeout = jiffies + NES_LONG_TIME;
573         struct nes_cm_node *cm_node;
574         struct nes_timer_entry *send_entry, *recv_entry;
575         struct list_head *list_core_temp;
576         struct list_head *list_node;
577         struct nes_cm_core *cm_core = g_cm_core;
578         u32 settimer = 0;
579         unsigned long timetosend;
580         int ret = NETDEV_TX_OK;
581
582         struct list_head timer_list;
583         INIT_LIST_HEAD(&timer_list);
584         spin_lock_irqsave(&cm_core->ht_lock, flags);
585
586         list_for_each_safe(list_node, list_core_temp,
587                                 &cm_core->connected_nodes) {
588                 cm_node = container_of(list_node, struct nes_cm_node, list);
589                 if ((cm_node->recv_entry) || (cm_node->send_entry)) {
590                         add_ref_cm_node(cm_node);
591                         list_add(&cm_node->timer_entry, &timer_list);
592                 }
593         }
594         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
595
596         list_for_each_safe(list_node, list_core_temp, &timer_list) {
597                 cm_node = container_of(list_node, struct nes_cm_node,
598                                         timer_entry);
599                 recv_entry = cm_node->recv_entry;
600
601                 if (recv_entry) {
602                         if (time_after(recv_entry->timetosend, jiffies)) {
603                                 if (nexttimeout > recv_entry->timetosend ||
604                                                 !settimer) {
605                                         nexttimeout = recv_entry->timetosend;
606                                         settimer = 1;
607                                 }
608                         } else
609                                 handle_recv_entry(cm_node, 1);
610                 }
611
612                 spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
613                 do {
614                         send_entry = cm_node->send_entry;
615                         if (!send_entry)
616                                 break;
617                         if (time_after(send_entry->timetosend, jiffies)) {
618                                 if (cm_node->state != NES_CM_STATE_TSA) {
619                                         if ((nexttimeout >
620                                                 send_entry->timetosend) ||
621                                                 !settimer) {
622                                                 nexttimeout =
623                                                         send_entry->timetosend;
624                                                 settimer = 1;
625                                         }
626                                 } else {
627                                         free_retrans_entry(cm_node);
628                                 }
629                                 break;
630                         }
631
632                         if ((cm_node->state == NES_CM_STATE_TSA) ||
633                                 (cm_node->state == NES_CM_STATE_CLOSED)) {
634                                 free_retrans_entry(cm_node);
635                                 break;
636                         }
637
638                         if (!send_entry->retranscount ||
639                                 !send_entry->retrycount) {
640                                 cm_packets_dropped++;
641                                 free_retrans_entry(cm_node);
642
643                                 spin_unlock_irqrestore(
644                                         &cm_node->retrans_list_lock, flags);
645                                 nes_retrans_expired(cm_node);
646                                 cm_node->state = NES_CM_STATE_CLOSED;
647                                 spin_lock_irqsave(&cm_node->retrans_list_lock,
648                                         flags);
649                                 break;
650                         }
651                         atomic_inc(&send_entry->skb->users);
652                         cm_packets_retrans++;
653                         nes_debug(NES_DBG_CM, "Retransmitting send_entry %p "
654                                 "for node %p, jiffies = %lu, time to send = "
655                                 "%lu, retranscount = %u, send_entry->seq_num = "
656                                 "0x%08X, cm_node->tcp_cntxt.rem_ack_num = "
657                                 "0x%08X\n", send_entry, cm_node, jiffies,
658                                 send_entry->timetosend,
659                                 send_entry->retranscount,
660                                 send_entry->seq_num,
661                                 cm_node->tcp_cntxt.rem_ack_num);
662
663                         spin_unlock_irqrestore(&cm_node->retrans_list_lock,
664                                 flags);
665                         ret = nes_nic_cm_xmit(send_entry->skb, cm_node->netdev);
666                         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
667                         if (ret != NETDEV_TX_OK) {
668                                 nes_debug(NES_DBG_CM, "rexmit failed for "
669                                         "node=%p\n", cm_node);
670                                 cm_packets_bounced++;
671                                 send_entry->retrycount--;
672                                 nexttimeout = jiffies + NES_SHORT_TIME;
673                                 settimer = 1;
674                                 break;
675                         } else {
676                                 cm_packets_sent++;
677                         }
678                         nes_debug(NES_DBG_CM, "Packet Sent: retrans count = "
679                                 "%u, retry count = %u.\n",
680                                 send_entry->retranscount,
681                                 send_entry->retrycount);
682                         if (send_entry->send_retrans) {
683                                 send_entry->retranscount--;
684                                 timetosend = (NES_RETRY_TIMEOUT <<
685                                         (NES_DEFAULT_RETRANS - send_entry->retranscount));
686
687                                 send_entry->timetosend = jiffies +
688                                         min(timetosend, NES_MAX_TIMEOUT);
689                                 if (nexttimeout > send_entry->timetosend ||
690                                         !settimer) {
691                                         nexttimeout = send_entry->timetosend;
692                                         settimer = 1;
693                                 }
694                         } else {
695                                 int close_when_complete;
696                                 close_when_complete =
697                                         send_entry->close_when_complete;
698                                 nes_debug(NES_DBG_CM, "cm_node=%p state=%d\n",
699                                         cm_node, cm_node->state);
700                                 free_retrans_entry(cm_node);
701                                 if (close_when_complete)
702                                         rem_ref_cm_node(cm_node->cm_core,
703                                                 cm_node);
704                         }
705                 } while (0);
706
707                 spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
708                 rem_ref_cm_node(cm_node->cm_core, cm_node);
709         }
710
711         if (settimer) {
712                 if (!timer_pending(&cm_core->tcp_timer)) {
713                         cm_core->tcp_timer.expires  = nexttimeout;
714                         add_timer(&cm_core->tcp_timer);
715                 }
716         }
717 }
718
719
720 /**
721  * send_syn
722  */
723 static int send_syn(struct nes_cm_node *cm_node, u32 sendack,
724         struct sk_buff *skb)
725 {
726         int ret;
727         int flags = SET_SYN;
728         char optionsbuffer[sizeof(struct option_mss) +
729                 sizeof(struct option_windowscale) + sizeof(struct option_base) +
730                 TCP_OPTIONS_PADDING];
731
732         int optionssize = 0;
733         /* Sending MSS option */
734         union all_known_options *options;
735
736         if (!cm_node)
737                 return -EINVAL;
738
739         options = (union all_known_options *)&optionsbuffer[optionssize];
740         options->as_mss.optionnum = OPTION_NUMBER_MSS;
741         options->as_mss.length = sizeof(struct option_mss);
742         options->as_mss.mss = htons(cm_node->tcp_cntxt.mss);
743         optionssize += sizeof(struct option_mss);
744
745         options = (union all_known_options *)&optionsbuffer[optionssize];
746         options->as_windowscale.optionnum = OPTION_NUMBER_WINDOW_SCALE;
747         options->as_windowscale.length = sizeof(struct option_windowscale);
748         options->as_windowscale.shiftcount = cm_node->tcp_cntxt.rcv_wscale;
749         optionssize += sizeof(struct option_windowscale);
750
751         if (sendack && !(NES_DRV_OPT_SUPRESS_OPTION_BC & nes_drv_opt)) {
752                 options = (union all_known_options *)&optionsbuffer[optionssize];
753                 options->as_base.optionnum = OPTION_NUMBER_WRITE0;
754                 options->as_base.length = sizeof(struct option_base);
755                 optionssize += sizeof(struct option_base);
756                 /* we need the size to be a multiple of 4 */
757                 options = (union all_known_options *)&optionsbuffer[optionssize];
758                 options->as_end = 1;
759                 optionssize += 1;
760                 options = (union all_known_options *)&optionsbuffer[optionssize];
761                 options->as_end = 1;
762                 optionssize += 1;
763         }
764
765         options = (union all_known_options *)&optionsbuffer[optionssize];
766         options->as_end = OPTION_NUMBER_END;
767         optionssize += 1;
768
769         if (!skb)
770                 skb = dev_alloc_skb(MAX_CM_BUFFER);
771         if (!skb) {
772                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
773                 return -1;
774         }
775
776         if (sendack)
777                 flags |= SET_ACK;
778
779         form_cm_frame(skb, cm_node, optionsbuffer, optionssize, NULL, 0, flags);
780         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
781
782         return ret;
783 }
784
785
786 /**
787  * send_reset
788  */
789 static int send_reset(struct nes_cm_node *cm_node, struct sk_buff *skb)
790 {
791         int ret;
792         int flags = SET_RST | SET_ACK;
793
794         if (!skb)
795                 skb = dev_alloc_skb(MAX_CM_BUFFER);
796         if (!skb) {
797                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
798                 return -ENOMEM;
799         }
800
801         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, flags);
802         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 1);
803
804         return ret;
805 }
806
807
808 /**
809  * send_ack
810  */
811 static int send_ack(struct nes_cm_node *cm_node, struct sk_buff *skb)
812 {
813         int ret;
814
815         if (!skb)
816                 skb = dev_alloc_skb(MAX_CM_BUFFER);
817
818         if (!skb) {
819                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
820                 return -1;
821         }
822
823         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK);
824         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 0, 0);
825
826         return ret;
827 }
828
829
830 /**
831  * send_fin
832  */
833 static int send_fin(struct nes_cm_node *cm_node, struct sk_buff *skb)
834 {
835         int ret;
836
837         /* if we didn't get a frame get one */
838         if (!skb)
839                 skb = dev_alloc_skb(MAX_CM_BUFFER);
840
841         if (!skb) {
842                 nes_debug(NES_DBG_CM, "Failed to get a Free pkt\n");
843                 return -1;
844         }
845
846         form_cm_frame(skb, cm_node, NULL, 0, NULL, 0, SET_ACK | SET_FIN);
847         ret = schedule_nes_timer(cm_node, skb, NES_TIMER_TYPE_SEND, 1, 0);
848
849         return ret;
850 }
851
852
853 /**
854  * find_node - find a cm node that matches the reference cm node
855  */
856 static struct nes_cm_node *find_node(struct nes_cm_core *cm_core,
857                 u16 rem_port, nes_addr_t rem_addr, u16 loc_port, nes_addr_t loc_addr)
858 {
859         unsigned long flags;
860         struct list_head *hte;
861         struct nes_cm_node *cm_node;
862
863         /* get a handle on the hte */
864         hte = &cm_core->connected_nodes;
865
866         /* walk list and find cm_node associated with this session ID */
867         spin_lock_irqsave(&cm_core->ht_lock, flags);
868         list_for_each_entry(cm_node, hte, list) {
869                 /* compare quad, return node handle if a match */
870                 nes_debug(NES_DBG_CM, "finding node %x:%x =? %x:%x ^ %x:%x =? %x:%x\n",
871                                 cm_node->loc_addr, cm_node->loc_port,
872                                 loc_addr, loc_port,
873                                 cm_node->rem_addr, cm_node->rem_port,
874                                 rem_addr, rem_port);
875                 if ((cm_node->loc_addr == loc_addr) && (cm_node->loc_port == loc_port) &&
876                                 (cm_node->rem_addr == rem_addr) && (cm_node->rem_port == rem_port)) {
877                         add_ref_cm_node(cm_node);
878                         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
879                         return cm_node;
880                 }
881         }
882         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
883
884         /* no owner node */
885         return NULL;
886 }
887
888
889 /**
890  * find_listener - find a cm node listening on this addr-port pair
891  */
892 static struct nes_cm_listener *find_listener(struct nes_cm_core *cm_core,
893                 nes_addr_t dst_addr, u16 dst_port, enum nes_cm_listener_state listener_state)
894 {
895         unsigned long flags;
896         struct nes_cm_listener *listen_node;
897
898         /* walk list and find cm_node associated with this session ID */
899         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
900         list_for_each_entry(listen_node, &cm_core->listen_list.list, list) {
901                 /* compare node pair, return node handle if a match */
902                 if (((listen_node->loc_addr == dst_addr) ||
903                                 listen_node->loc_addr == 0x00000000) &&
904                                 (listen_node->loc_port == dst_port) &&
905                                 (listener_state & listen_node->listener_state)) {
906                         atomic_inc(&listen_node->ref_count);
907                         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
908                         return listen_node;
909                 }
910         }
911         spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
912
913         /* no listener */
914         return NULL;
915 }
916
917
918 /**
919  * add_hte_node - add a cm node to the hash table
920  */
921 static int add_hte_node(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
922 {
923         unsigned long flags;
924         struct list_head *hte;
925
926         if (!cm_node || !cm_core)
927                 return -EINVAL;
928
929         nes_debug(NES_DBG_CM, "Adding Node %p to Active Connection HT\n",
930                 cm_node);
931
932         spin_lock_irqsave(&cm_core->ht_lock, flags);
933
934         /* get a handle on the hash table element (list head for this slot) */
935         hte = &cm_core->connected_nodes;
936         list_add_tail(&cm_node->list, hte);
937         atomic_inc(&cm_core->ht_node_cnt);
938
939         spin_unlock_irqrestore(&cm_core->ht_lock, flags);
940
941         return 0;
942 }
943
944
945 /**
946  * mini_cm_dec_refcnt_listen
947  */
948 static int mini_cm_dec_refcnt_listen(struct nes_cm_core *cm_core,
949         struct nes_cm_listener *listener, int free_hanging_nodes)
950 {
951         int ret = -EINVAL;
952         int err = 0;
953         unsigned long flags;
954         struct list_head *list_pos = NULL;
955         struct list_head *list_temp = NULL;
956         struct nes_cm_node *cm_node = NULL;
957         struct list_head reset_list;
958
959         nes_debug(NES_DBG_CM, "attempting listener= %p free_nodes= %d, "
960                 "refcnt=%d\n", listener, free_hanging_nodes,
961                 atomic_read(&listener->ref_count));
962         /* free non-accelerated child nodes for this listener */
963         INIT_LIST_HEAD(&reset_list);
964         if (free_hanging_nodes) {
965                 spin_lock_irqsave(&cm_core->ht_lock, flags);
966                 list_for_each_safe(list_pos, list_temp,
967                                    &g_cm_core->connected_nodes) {
968                         cm_node = container_of(list_pos, struct nes_cm_node,
969                                 list);
970                         if ((cm_node->listener == listener) &&
971                             (!cm_node->accelerated)) {
972                                 add_ref_cm_node(cm_node);
973                                 list_add(&cm_node->reset_entry, &reset_list);
974                         }
975                 }
976                 spin_unlock_irqrestore(&cm_core->ht_lock, flags);
977         }
978
979         list_for_each_safe(list_pos, list_temp, &reset_list) {
980                 cm_node = container_of(list_pos, struct nes_cm_node,
981                                 reset_entry);
982                 {
983                         struct nes_cm_node *loopback = cm_node->loopbackpartner;
984                         enum nes_cm_node_state old_state;
985                         if (NES_CM_STATE_FIN_WAIT1 <= cm_node->state) {
986                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
987                         } else {
988                                 if (!loopback) {
989                                         cleanup_retrans_entry(cm_node);
990                                         err = send_reset(cm_node, NULL);
991                                         if (err) {
992                                                 cm_node->state =
993                                                          NES_CM_STATE_CLOSED;
994                                                 WARN_ON(1);
995                                         } else {
996                                                 old_state = cm_node->state;
997                                                 cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
998                                                 if (old_state != NES_CM_STATE_MPAREQ_RCVD)
999                                                         rem_ref_cm_node(
1000                                                                 cm_node->cm_core,
1001                                                                 cm_node);
1002                                         }
1003                                 } else {
1004                                         struct nes_cm_event event;
1005
1006                                         event.cm_node = loopback;
1007                                         event.cm_info.rem_addr =
1008                                                         loopback->rem_addr;
1009                                         event.cm_info.loc_addr =
1010                                                         loopback->loc_addr;
1011                                         event.cm_info.rem_port =
1012                                                         loopback->rem_port;
1013                                         event.cm_info.loc_port =
1014                                                          loopback->loc_port;
1015                                         event.cm_info.cm_id = loopback->cm_id;
1016                                         add_ref_cm_node(loopback);
1017                                         loopback->state = NES_CM_STATE_CLOSED;
1018                                         cm_event_connect_error(&event);
1019                                         cm_node->state = NES_CM_STATE_LISTENER_DESTROYED;
1020
1021                                         rem_ref_cm_node(cm_node->cm_core,
1022                                                          cm_node);
1023
1024                                 }
1025                         }
1026                 }
1027         }
1028
1029         spin_lock_irqsave(&cm_core->listen_list_lock, flags);
1030         if (!atomic_dec_return(&listener->ref_count)) {
1031                 list_del(&listener->list);
1032
1033                 /* decrement our listen node count */
1034                 atomic_dec(&cm_core->listen_node_cnt);
1035
1036                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1037
1038                 if (listener->nesvnic) {
1039                         nes_manage_apbvt(listener->nesvnic, listener->loc_port,
1040                                         PCI_FUNC(listener->nesvnic->nesdev->pcidev->devfn), NES_MANAGE_APBVT_DEL);
1041                 }
1042
1043                 nes_debug(NES_DBG_CM, "destroying listener (%p)\n", listener);
1044
1045                 kfree(listener);
1046                 listener = NULL;
1047                 ret = 0;
1048                 atomic_inc(&cm_listens_destroyed);
1049         } else {
1050                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
1051         }
1052         if (listener) {
1053                 if (atomic_read(&listener->pend_accepts_cnt) > 0)
1054                         nes_debug(NES_DBG_CM, "destroying listener (%p)"
1055                                         " with non-zero pending accepts=%u\n",
1056                                         listener, atomic_read(&listener->pend_accepts_cnt));
1057         }
1058
1059         return ret;
1060 }
1061
1062
1063 /**
1064  * mini_cm_del_listen
1065  */
1066 static int mini_cm_del_listen(struct nes_cm_core *cm_core,
1067                 struct nes_cm_listener *listener)
1068 {
1069         listener->listener_state = NES_CM_LISTENER_PASSIVE_STATE;
1070         listener->cm_id = NULL; /* going to be destroyed pretty soon */
1071         return mini_cm_dec_refcnt_listen(cm_core, listener, 1);
1072 }
1073
1074
1075 /**
1076  * mini_cm_accelerated
1077  */
1078 static inline int mini_cm_accelerated(struct nes_cm_core *cm_core,
1079                 struct nes_cm_node *cm_node)
1080 {
1081         u32 was_timer_set;
1082         cm_node->accelerated = 1;
1083
1084         if (cm_node->accept_pend) {
1085                 BUG_ON(!cm_node->listener);
1086                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1087                 cm_node->accept_pend = 0;
1088                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1089         }
1090
1091         was_timer_set = timer_pending(&cm_core->tcp_timer);
1092         if (!was_timer_set) {
1093                 cm_core->tcp_timer.expires = jiffies + NES_SHORT_TIME;
1094                 add_timer(&cm_core->tcp_timer);
1095         }
1096
1097         return 0;
1098 }
1099
1100
1101 /**
1102  * nes_addr_resolve_neigh
1103  */
1104 static int nes_addr_resolve_neigh(struct nes_vnic *nesvnic, u32 dst_ip, int arpindex)
1105 {
1106         struct rtable *rt;
1107         struct flowi fl;
1108         struct neighbour *neigh;
1109         int rc = arpindex;
1110         struct net_device *netdev;
1111         struct nes_adapter *nesadapter = nesvnic->nesdev->nesadapter;
1112
1113         memset(&fl, 0, sizeof fl);
1114         fl.nl_u.ip4_u.daddr = htonl(dst_ip);
1115         rt = ip_route_output_key(&init_net, &fl);
1116         if (IS_ERR(rt)) {
1117                 printk(KERN_ERR "%s: ip_route_output_key failed for 0x%08X\n",
1118                                 __func__, dst_ip);
1119                 return rc;
1120         }
1121
1122         if (netif_is_bond_slave(netdev))
1123                 netdev = nesvnic->netdev->master;
1124         else
1125                 netdev = nesvnic->netdev;
1126
1127         neigh = neigh_lookup(&arp_tbl, &rt->rt_gateway, netdev);
1128         if (neigh) {
1129                 if (neigh->nud_state & NUD_VALID) {
1130                         nes_debug(NES_DBG_CM, "Neighbor MAC address for 0x%08X"
1131                                   " is %pM, Gateway is 0x%08X \n", dst_ip,
1132                                   neigh->ha, ntohl(rt->rt_gateway));
1133
1134                         if (arpindex >= 0) {
1135                                 if (!memcmp(nesadapter->arp_table[arpindex].mac_addr,
1136                                                         neigh->ha, ETH_ALEN)){
1137                                         /* Mac address same as in nes_arp_table */
1138                                         neigh_release(neigh);
1139                                         ip_rt_put(rt);
1140                                         return rc;
1141                                 }
1142
1143                                 nes_manage_arp_cache(nesvnic->netdev,
1144                                                 nesadapter->arp_table[arpindex].mac_addr,
1145                                                 dst_ip, NES_ARP_DELETE);
1146                         }
1147
1148                         nes_manage_arp_cache(nesvnic->netdev, neigh->ha,
1149                                              dst_ip, NES_ARP_ADD);
1150                         rc = nes_arp_table(nesvnic->nesdev, dst_ip, NULL,
1151                                            NES_ARP_RESOLVE);
1152                 }
1153                 neigh_release(neigh);
1154         }
1155
1156         if ((neigh == NULL) || (!(neigh->nud_state & NUD_VALID)))
1157                 neigh_event_send(rt->dst.neighbour, NULL);
1158
1159         ip_rt_put(rt);
1160         return rc;
1161 }
1162
1163 /**
1164  * make_cm_node - create a new instance of a cm node
1165  */
1166 static struct nes_cm_node *make_cm_node(struct nes_cm_core *cm_core,
1167                 struct nes_vnic *nesvnic, struct nes_cm_info *cm_info,
1168                 struct nes_cm_listener *listener)
1169 {
1170         struct nes_cm_node *cm_node;
1171         struct timespec ts;
1172         int oldarpindex = 0;
1173         int arpindex = 0;
1174         struct nes_device *nesdev;
1175         struct nes_adapter *nesadapter;
1176
1177         /* create an hte and cm_node for this instance */
1178         cm_node = kzalloc(sizeof(*cm_node), GFP_ATOMIC);
1179         if (!cm_node)
1180                 return NULL;
1181
1182         /* set our node specific transport info */
1183         cm_node->loc_addr = cm_info->loc_addr;
1184         cm_node->rem_addr = cm_info->rem_addr;
1185         cm_node->loc_port = cm_info->loc_port;
1186         cm_node->rem_port = cm_info->rem_port;
1187         cm_node->send_write0 = send_first;
1188         nes_debug(NES_DBG_CM, "Make node addresses : loc = %pI4:%x, rem = %pI4:%x\n",
1189                   &cm_node->loc_addr, cm_node->loc_port,
1190                   &cm_node->rem_addr, cm_node->rem_port);
1191         cm_node->listener = listener;
1192         cm_node->netdev = nesvnic->netdev;
1193         cm_node->cm_id = cm_info->cm_id;
1194         memcpy(cm_node->loc_mac, nesvnic->netdev->dev_addr, ETH_ALEN);
1195
1196         nes_debug(NES_DBG_CM, "listener=%p, cm_id=%p\n", cm_node->listener,
1197                         cm_node->cm_id);
1198
1199         spin_lock_init(&cm_node->retrans_list_lock);
1200
1201         cm_node->loopbackpartner = NULL;
1202         atomic_set(&cm_node->ref_count, 1);
1203         /* associate our parent CM core */
1204         cm_node->cm_core = cm_core;
1205         cm_node->tcp_cntxt.loc_id = NES_CM_DEF_LOCAL_ID;
1206         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
1207         cm_node->tcp_cntxt.rcv_wnd = NES_CM_DEFAULT_RCV_WND_SCALED >>
1208                         NES_CM_DEFAULT_RCV_WND_SCALE;
1209         ts = current_kernel_time();
1210         cm_node->tcp_cntxt.loc_seq_num = htonl(ts.tv_nsec);
1211         cm_node->tcp_cntxt.mss = nesvnic->max_frame_size - sizeof(struct iphdr) -
1212                         sizeof(struct tcphdr) - ETH_HLEN - VLAN_HLEN;
1213         cm_node->tcp_cntxt.rcv_nxt = 0;
1214         /* get a unique session ID , add thread_id to an upcounter to handle race */
1215         atomic_inc(&cm_core->node_cnt);
1216         cm_node->conn_type = cm_info->conn_type;
1217         cm_node->apbvt_set = 0;
1218         cm_node->accept_pend = 0;
1219
1220         cm_node->nesvnic = nesvnic;
1221         /* get some device handles, for arp lookup */
1222         nesdev = nesvnic->nesdev;
1223         nesadapter = nesdev->nesadapter;
1224
1225         cm_node->loopbackpartner = NULL;
1226
1227         /* get the mac addr for the remote node */
1228         if (ipv4_is_loopback(htonl(cm_node->rem_addr)))
1229                 arpindex = nes_arp_table(nesdev, ntohl(nesvnic->local_ipaddr), NULL, NES_ARP_RESOLVE);
1230         else {
1231                 oldarpindex = nes_arp_table(nesdev, cm_node->rem_addr, NULL, NES_ARP_RESOLVE);
1232                 arpindex = nes_addr_resolve_neigh(nesvnic, cm_info->rem_addr, oldarpindex);
1233
1234         }
1235         if (arpindex < 0) {
1236                 kfree(cm_node);
1237                 return NULL;
1238         }
1239
1240         /* copy the mac addr to node context */
1241         memcpy(cm_node->rem_mac, nesadapter->arp_table[arpindex].mac_addr, ETH_ALEN);
1242         nes_debug(NES_DBG_CM, "Remote mac addr from arp table: %pM\n",
1243                   cm_node->rem_mac);
1244
1245         add_hte_node(cm_core, cm_node);
1246         atomic_inc(&cm_nodes_created);
1247
1248         return cm_node;
1249 }
1250
1251
1252 /**
1253  * add_ref_cm_node - destroy an instance of a cm node
1254  */
1255 static int add_ref_cm_node(struct nes_cm_node *cm_node)
1256 {
1257         atomic_inc(&cm_node->ref_count);
1258         return 0;
1259 }
1260
1261
1262 /**
1263  * rem_ref_cm_node - destroy an instance of a cm node
1264  */
1265 static int rem_ref_cm_node(struct nes_cm_core *cm_core,
1266         struct nes_cm_node *cm_node)
1267 {
1268         unsigned long flags;
1269         struct nes_qp *nesqp;
1270
1271         if (!cm_node)
1272                 return -EINVAL;
1273
1274         spin_lock_irqsave(&cm_node->cm_core->ht_lock, flags);
1275         if (atomic_dec_return(&cm_node->ref_count)) {
1276                 spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1277                 return 0;
1278         }
1279         list_del(&cm_node->list);
1280         atomic_dec(&cm_core->ht_node_cnt);
1281         spin_unlock_irqrestore(&cm_node->cm_core->ht_lock, flags);
1282
1283         /* if the node is destroyed before connection was accelerated */
1284         if (!cm_node->accelerated && cm_node->accept_pend) {
1285                 BUG_ON(!cm_node->listener);
1286                 atomic_dec(&cm_node->listener->pend_accepts_cnt);
1287                 BUG_ON(atomic_read(&cm_node->listener->pend_accepts_cnt) < 0);
1288         }
1289         WARN_ON(cm_node->send_entry);
1290         if (cm_node->recv_entry)
1291                 handle_recv_entry(cm_node, 0);
1292         if (cm_node->listener) {
1293                 mini_cm_dec_refcnt_listen(cm_core, cm_node->listener, 0);
1294         } else {
1295                 if (cm_node->apbvt_set && cm_node->nesvnic) {
1296                         nes_manage_apbvt(cm_node->nesvnic, cm_node->loc_port,
1297                                 PCI_FUNC(
1298                                 cm_node->nesvnic->nesdev->pcidev->devfn),
1299                                 NES_MANAGE_APBVT_DEL);
1300                 }
1301         }
1302
1303         atomic_dec(&cm_core->node_cnt);
1304         atomic_inc(&cm_nodes_destroyed);
1305         nesqp = cm_node->nesqp;
1306         if (nesqp) {
1307                 nesqp->cm_node = NULL;
1308                 nes_rem_ref(&nesqp->ibqp);
1309                 cm_node->nesqp = NULL;
1310         }
1311
1312         kfree(cm_node);
1313         return 0;
1314 }
1315
1316 /**
1317  * process_options
1318  */
1319 static int process_options(struct nes_cm_node *cm_node, u8 *optionsloc,
1320         u32 optionsize, u32 syn_packet)
1321 {
1322         u32 tmp;
1323         u32 offset = 0;
1324         union all_known_options *all_options;
1325         char got_mss_option = 0;
1326
1327         while (offset < optionsize) {
1328                 all_options = (union all_known_options *)(optionsloc + offset);
1329                 switch (all_options->as_base.optionnum) {
1330                 case OPTION_NUMBER_END:
1331                         offset = optionsize;
1332                         break;
1333                 case OPTION_NUMBER_NONE:
1334                         offset += 1;
1335                         continue;
1336                 case OPTION_NUMBER_MSS:
1337                         nes_debug(NES_DBG_CM, "%s: MSS Length: %d Offset: %d "
1338                                 "Size: %d\n", __func__,
1339                                 all_options->as_mss.length, offset, optionsize);
1340                         got_mss_option = 1;
1341                         if (all_options->as_mss.length != 4) {
1342                                 return 1;
1343                         } else {
1344                                 tmp = ntohs(all_options->as_mss.mss);
1345                                 if (tmp > 0 && tmp <
1346                                         cm_node->tcp_cntxt.mss)
1347                                         cm_node->tcp_cntxt.mss = tmp;
1348                         }
1349                         break;
1350                 case OPTION_NUMBER_WINDOW_SCALE:
1351                         cm_node->tcp_cntxt.snd_wscale =
1352                                 all_options->as_windowscale.shiftcount;
1353                         break;
1354                 case OPTION_NUMBER_WRITE0:
1355                         cm_node->send_write0 = 1;
1356                         break;
1357                 default:
1358                         nes_debug(NES_DBG_CM, "TCP Option not understood: %x\n",
1359                                 all_options->as_base.optionnum);
1360                         break;
1361                 }
1362                 offset += all_options->as_base.length;
1363         }
1364         if ((!got_mss_option) && (syn_packet))
1365                 cm_node->tcp_cntxt.mss = NES_CM_DEFAULT_MSS;
1366         return 0;
1367 }
1368
1369 static void drop_packet(struct sk_buff *skb)
1370 {
1371         atomic_inc(&cm_accel_dropped_pkts);
1372         dev_kfree_skb_any(skb);
1373 }
1374
1375 static void handle_fin_pkt(struct nes_cm_node *cm_node)
1376 {
1377         nes_debug(NES_DBG_CM, "Received FIN, cm_node = %p, state = %u. "
1378                 "refcnt=%d\n", cm_node, cm_node->state,
1379                 atomic_read(&cm_node->ref_count));
1380         switch (cm_node->state) {
1381         case NES_CM_STATE_SYN_RCVD:
1382         case NES_CM_STATE_SYN_SENT:
1383         case NES_CM_STATE_ESTABLISHED:
1384         case NES_CM_STATE_MPAREJ_RCVD:
1385                 cm_node->tcp_cntxt.rcv_nxt++;
1386                 cleanup_retrans_entry(cm_node);
1387                 cm_node->state = NES_CM_STATE_LAST_ACK;
1388                 send_fin(cm_node, NULL);
1389                 break;
1390         case NES_CM_STATE_MPAREQ_SENT:
1391                 create_event(cm_node, NES_CM_EVENT_ABORTED);
1392                 cm_node->tcp_cntxt.rcv_nxt++;
1393                 cleanup_retrans_entry(cm_node);
1394                 cm_node->state = NES_CM_STATE_CLOSED;
1395                 add_ref_cm_node(cm_node);
1396                 send_reset(cm_node, NULL);
1397                 break;
1398         case NES_CM_STATE_FIN_WAIT1:
1399                 cm_node->tcp_cntxt.rcv_nxt++;
1400                 cleanup_retrans_entry(cm_node);
1401                 cm_node->state = NES_CM_STATE_CLOSING;
1402                 send_ack(cm_node, NULL);
1403                 /* Wait for ACK as this is simultanous close..
1404                 * After we receive ACK, do not send anything..
1405                 * Just rm the node.. Done.. */
1406                 break;
1407         case NES_CM_STATE_FIN_WAIT2:
1408                 cm_node->tcp_cntxt.rcv_nxt++;
1409                 cleanup_retrans_entry(cm_node);
1410                 cm_node->state = NES_CM_STATE_TIME_WAIT;
1411                 send_ack(cm_node, NULL);
1412                 schedule_nes_timer(cm_node, NULL,  NES_TIMER_TYPE_CLOSE, 1, 0);
1413                 break;
1414         case NES_CM_STATE_TIME_WAIT:
1415                 cm_node->tcp_cntxt.rcv_nxt++;
1416                 cleanup_retrans_entry(cm_node);
1417                 cm_node->state = NES_CM_STATE_CLOSED;
1418                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1419                 break;
1420         case NES_CM_STATE_TSA:
1421         default:
1422                 nes_debug(NES_DBG_CM, "Error Rcvd FIN for node-%p state = %d\n",
1423                         cm_node, cm_node->state);
1424                 break;
1425         }
1426 }
1427
1428
1429 static void handle_rst_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1430         struct tcphdr *tcph)
1431 {
1432
1433         int     reset = 0;      /* whether to send reset in case of err.. */
1434         atomic_inc(&cm_resets_recvd);
1435         nes_debug(NES_DBG_CM, "Received Reset, cm_node = %p, state = %u."
1436                         " refcnt=%d\n", cm_node, cm_node->state,
1437                         atomic_read(&cm_node->ref_count));
1438         cleanup_retrans_entry(cm_node);
1439         switch (cm_node->state) {
1440         case NES_CM_STATE_SYN_SENT:
1441         case NES_CM_STATE_MPAREQ_SENT:
1442                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1443                         "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1444                         cm_node->listener, cm_node->state);
1445                 active_open_err(cm_node, skb, reset);
1446                 break;
1447         case NES_CM_STATE_MPAREQ_RCVD:
1448                 atomic_inc(&cm_node->passive_state);
1449                 dev_kfree_skb_any(skb);
1450                 break;
1451         case NES_CM_STATE_ESTABLISHED:
1452         case NES_CM_STATE_SYN_RCVD:
1453         case NES_CM_STATE_LISTENING:
1454                 nes_debug(NES_DBG_CM, "Bad state %s[%u]\n", __func__, __LINE__);
1455                 passive_open_err(cm_node, skb, reset);
1456                 break;
1457         case NES_CM_STATE_TSA:
1458                 active_open_err(cm_node, skb, reset);
1459                 break;
1460         case NES_CM_STATE_CLOSED:
1461                 drop_packet(skb);
1462                 break;
1463         case NES_CM_STATE_FIN_WAIT2:
1464         case NES_CM_STATE_FIN_WAIT1:
1465         case NES_CM_STATE_LAST_ACK:
1466                 cm_node->cm_id->rem_ref(cm_node->cm_id);
1467         case NES_CM_STATE_TIME_WAIT:
1468                 cm_node->state = NES_CM_STATE_CLOSED;
1469                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1470                 drop_packet(skb);
1471                 break;
1472         default:
1473                 drop_packet(skb);
1474                 break;
1475         }
1476 }
1477
1478
1479 static void handle_rcv_mpa(struct nes_cm_node *cm_node, struct sk_buff *skb)
1480 {
1481
1482         int     ret = 0;
1483         int datasize = skb->len;
1484         u8 *dataloc = skb->data;
1485
1486         enum nes_cm_event_type type = NES_CM_EVENT_UNKNOWN;
1487         u32     res_type;
1488         ret = parse_mpa(cm_node, dataloc, &res_type, datasize);
1489         if (ret) {
1490                 nes_debug(NES_DBG_CM, "didn't like MPA Request\n");
1491                 if (cm_node->state == NES_CM_STATE_MPAREQ_SENT) {
1492                         nes_debug(NES_DBG_CM, "%s[%u] create abort for "
1493                                 "cm_node=%p listener=%p state=%d\n", __func__,
1494                                 __LINE__, cm_node, cm_node->listener,
1495                                 cm_node->state);
1496                         active_open_err(cm_node, skb, 1);
1497                 } else {
1498                         passive_open_err(cm_node, skb, 1);
1499                 }
1500                 return;
1501         }
1502
1503         switch (cm_node->state) {
1504         case NES_CM_STATE_ESTABLISHED:
1505                 if (res_type == NES_MPA_REQUEST_REJECT) {
1506                         /*BIG problem as we are receiving the MPA.. So should
1507                         * not be REJECT.. This is Passive Open.. We can
1508                         * only receive it Reject for Active Open...*/
1509                         WARN_ON(1);
1510                 }
1511                 cm_node->state = NES_CM_STATE_MPAREQ_RCVD;
1512                 type = NES_CM_EVENT_MPA_REQ;
1513                 atomic_set(&cm_node->passive_state,
1514                                 NES_PASSIVE_STATE_INDICATED);
1515                 break;
1516         case NES_CM_STATE_MPAREQ_SENT:
1517                 cleanup_retrans_entry(cm_node);
1518                 if (res_type == NES_MPA_REQUEST_REJECT) {
1519                         type = NES_CM_EVENT_MPA_REJECT;
1520                         cm_node->state = NES_CM_STATE_MPAREJ_RCVD;
1521                 } else {
1522                         type = NES_CM_EVENT_CONNECTED;
1523                         cm_node->state = NES_CM_STATE_TSA;
1524                 }
1525
1526                 break;
1527         default:
1528                 WARN_ON(1);
1529                 break;
1530         }
1531         dev_kfree_skb_any(skb);
1532         create_event(cm_node, type);
1533 }
1534
1535 static void indicate_pkt_err(struct nes_cm_node *cm_node, struct sk_buff *skb)
1536 {
1537         switch (cm_node->state) {
1538         case NES_CM_STATE_SYN_SENT:
1539         case NES_CM_STATE_MPAREQ_SENT:
1540                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1541                         "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1542                         cm_node->listener, cm_node->state);
1543                 active_open_err(cm_node, skb, 1);
1544                 break;
1545         case NES_CM_STATE_ESTABLISHED:
1546         case NES_CM_STATE_SYN_RCVD:
1547                 passive_open_err(cm_node, skb, 1);
1548                 break;
1549         case NES_CM_STATE_TSA:
1550         default:
1551                 drop_packet(skb);
1552         }
1553 }
1554
1555 static int check_syn(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1556         struct sk_buff *skb)
1557 {
1558         int err;
1559
1560         err = ((ntohl(tcph->ack_seq) == cm_node->tcp_cntxt.loc_seq_num))? 0 : 1;
1561         if (err)
1562                 active_open_err(cm_node, skb, 1);
1563
1564         return err;
1565 }
1566
1567 static int check_seq(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1568         struct sk_buff *skb)
1569 {
1570         int err = 0;
1571         u32 seq;
1572         u32 ack_seq;
1573         u32 loc_seq_num = cm_node->tcp_cntxt.loc_seq_num;
1574         u32 rcv_nxt = cm_node->tcp_cntxt.rcv_nxt;
1575         u32 rcv_wnd;
1576         seq = ntohl(tcph->seq);
1577         ack_seq = ntohl(tcph->ack_seq);
1578         rcv_wnd = cm_node->tcp_cntxt.rcv_wnd;
1579         if (ack_seq != loc_seq_num)
1580                 err = 1;
1581         else if (!between(seq, rcv_nxt, (rcv_nxt+rcv_wnd)))
1582                 err = 1;
1583         if (err) {
1584                 nes_debug(NES_DBG_CM, "%s[%u] create abort for cm_node=%p "
1585                         "listener=%p state=%d\n", __func__, __LINE__, cm_node,
1586                         cm_node->listener, cm_node->state);
1587                 indicate_pkt_err(cm_node, skb);
1588                 nes_debug(NES_DBG_CM, "seq ERROR cm_node =%p seq=0x%08X "
1589                         "rcv_nxt=0x%08X rcv_wnd=0x%x\n", cm_node, seq, rcv_nxt,
1590                         rcv_wnd);
1591         }
1592         return err;
1593 }
1594
1595 /*
1596  * handle_syn_pkt() is for Passive node. The syn packet is received when a node
1597  * is created with a listener or it may comein as rexmitted packet which in
1598  * that case will be just dropped.
1599  */
1600
1601 static void handle_syn_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1602         struct tcphdr *tcph)
1603 {
1604         int ret;
1605         u32 inc_sequence;
1606         int optionsize;
1607
1608         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1609         skb_trim(skb, 0);
1610         inc_sequence = ntohl(tcph->seq);
1611
1612         switch (cm_node->state) {
1613         case NES_CM_STATE_SYN_SENT:
1614         case NES_CM_STATE_MPAREQ_SENT:
1615                 /* Rcvd syn on active open connection*/
1616                 active_open_err(cm_node, skb, 1);
1617                 break;
1618         case NES_CM_STATE_LISTENING:
1619                 /* Passive OPEN */
1620                 if (atomic_read(&cm_node->listener->pend_accepts_cnt) >
1621                                 cm_node->listener->backlog) {
1622                         nes_debug(NES_DBG_CM, "drop syn due to backlog "
1623                                 "pressure \n");
1624                         cm_backlog_drops++;
1625                         passive_open_err(cm_node, skb, 0);
1626                         break;
1627                 }
1628                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize,
1629                         1);
1630                 if (ret) {
1631                         passive_open_err(cm_node, skb, 0);
1632                         /* drop pkt */
1633                         break;
1634                 }
1635                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1636                 BUG_ON(cm_node->send_entry);
1637                 cm_node->accept_pend = 1;
1638                 atomic_inc(&cm_node->listener->pend_accepts_cnt);
1639
1640                 cm_node->state = NES_CM_STATE_SYN_RCVD;
1641                 send_syn(cm_node, 1, skb);
1642                 break;
1643         case NES_CM_STATE_CLOSED:
1644                 cleanup_retrans_entry(cm_node);
1645                 add_ref_cm_node(cm_node);
1646                 send_reset(cm_node, skb);
1647                 break;
1648         case NES_CM_STATE_TSA:
1649         case NES_CM_STATE_ESTABLISHED:
1650         case NES_CM_STATE_FIN_WAIT1:
1651         case NES_CM_STATE_FIN_WAIT2:
1652         case NES_CM_STATE_MPAREQ_RCVD:
1653         case NES_CM_STATE_LAST_ACK:
1654         case NES_CM_STATE_CLOSING:
1655         case NES_CM_STATE_UNKNOWN:
1656         default:
1657                 drop_packet(skb);
1658                 break;
1659         }
1660 }
1661
1662 static void handle_synack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1663         struct tcphdr *tcph)
1664 {
1665
1666         int ret;
1667         u32 inc_sequence;
1668         int optionsize;
1669
1670         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1671         skb_trim(skb, 0);
1672         inc_sequence = ntohl(tcph->seq);
1673         switch (cm_node->state) {
1674         case NES_CM_STATE_SYN_SENT:
1675                 cleanup_retrans_entry(cm_node);
1676                 /* active open */
1677                 if (check_syn(cm_node, tcph, skb))
1678                         return;
1679                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
1680                 /* setup options */
1681                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 0);
1682                 if (ret) {
1683                         nes_debug(NES_DBG_CM, "cm_node=%p tcp_options failed\n",
1684                                 cm_node);
1685                         break;
1686                 }
1687                 cleanup_retrans_entry(cm_node);
1688                 cm_node->tcp_cntxt.rcv_nxt = inc_sequence + 1;
1689                 send_mpa_request(cm_node, skb);
1690                 cm_node->state = NES_CM_STATE_MPAREQ_SENT;
1691                 break;
1692         case NES_CM_STATE_MPAREQ_RCVD:
1693                 /* passive open, so should not be here */
1694                 passive_open_err(cm_node, skb, 1);
1695                 break;
1696         case NES_CM_STATE_LISTENING:
1697                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
1698                 cleanup_retrans_entry(cm_node);
1699                 cm_node->state = NES_CM_STATE_CLOSED;
1700                 send_reset(cm_node, skb);
1701                 break;
1702         case NES_CM_STATE_CLOSED:
1703                 cm_node->tcp_cntxt.loc_seq_num = ntohl(tcph->ack_seq);
1704                 cleanup_retrans_entry(cm_node);
1705                 add_ref_cm_node(cm_node);
1706                 send_reset(cm_node, skb);
1707                 break;
1708         case NES_CM_STATE_ESTABLISHED:
1709         case NES_CM_STATE_FIN_WAIT1:
1710         case NES_CM_STATE_FIN_WAIT2:
1711         case NES_CM_STATE_LAST_ACK:
1712         case NES_CM_STATE_TSA:
1713         case NES_CM_STATE_CLOSING:
1714         case NES_CM_STATE_UNKNOWN:
1715         case NES_CM_STATE_MPAREQ_SENT:
1716         default:
1717                 drop_packet(skb);
1718                 break;
1719         }
1720 }
1721
1722 static int handle_ack_pkt(struct nes_cm_node *cm_node, struct sk_buff *skb,
1723         struct tcphdr *tcph)
1724 {
1725         int datasize = 0;
1726         u32 inc_sequence;
1727         int ret = 0;
1728         int optionsize;
1729         optionsize = (tcph->doff << 2) - sizeof(struct tcphdr);
1730
1731         if (check_seq(cm_node, tcph, skb))
1732                 return -EINVAL;
1733
1734         skb_pull(skb, tcph->doff << 2);
1735         inc_sequence = ntohl(tcph->seq);
1736         datasize = skb->len;
1737         switch (cm_node->state) {
1738         case NES_CM_STATE_SYN_RCVD:
1739                 /* Passive OPEN */
1740                 cleanup_retrans_entry(cm_node);
1741                 ret = handle_tcp_options(cm_node, tcph, skb, optionsize, 1);
1742                 if (ret)
1743                         break;
1744                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
1745                 cm_node->state = NES_CM_STATE_ESTABLISHED;
1746                 if (datasize) {
1747                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
1748                         handle_rcv_mpa(cm_node, skb);
1749                 } else  /* rcvd ACK only */
1750                         dev_kfree_skb_any(skb);
1751                 break;
1752         case NES_CM_STATE_ESTABLISHED:
1753                 /* Passive OPEN */
1754                 cleanup_retrans_entry(cm_node);
1755                 if (datasize) {
1756                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
1757                         handle_rcv_mpa(cm_node, skb);
1758                 } else
1759                         drop_packet(skb);
1760                 break;
1761         case NES_CM_STATE_MPAREQ_SENT:
1762                 cm_node->tcp_cntxt.rem_ack_num = ntohl(tcph->ack_seq);
1763                 if (datasize) {
1764                         cm_node->tcp_cntxt.rcv_nxt = inc_sequence + datasize;
1765                         handle_rcv_mpa(cm_node, skb);
1766                 } else  /* Could be just an ack pkt.. */
1767                         dev_kfree_skb_any(skb);
1768                 break;
1769         case NES_CM_STATE_LISTENING:
1770                 cleanup_retrans_entry(cm_node);
1771                 cm_node->state = NES_CM_STATE_CLOSED;
1772                 send_reset(cm_node, skb);
1773                 break;
1774         case NES_CM_STATE_CLOSED:
1775                 cleanup_retrans_entry(cm_node);
1776                 add_ref_cm_node(cm_node);
1777                 send_reset(cm_node, skb);
1778                 break;
1779         case NES_CM_STATE_LAST_ACK:
1780         case NES_CM_STATE_CLOSING:
1781                 cleanup_retrans_entry(cm_node);
1782                 cm_node->state = NES_CM_STATE_CLOSED;
1783                 cm_node->cm_id->rem_ref(cm_node->cm_id);
1784                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1785                 drop_packet(skb);
1786                 break;
1787         case NES_CM_STATE_FIN_WAIT1:
1788                 cleanup_retrans_entry(cm_node);
1789                 drop_packet(skb);
1790                 cm_node->state = NES_CM_STATE_FIN_WAIT2;
1791                 break;
1792         case NES_CM_STATE_SYN_SENT:
1793         case NES_CM_STATE_FIN_WAIT2:
1794         case NES_CM_STATE_TSA:
1795         case NES_CM_STATE_MPAREQ_RCVD:
1796         case NES_CM_STATE_UNKNOWN:
1797         default:
1798                 cleanup_retrans_entry(cm_node);
1799                 drop_packet(skb);
1800                 break;
1801         }
1802         return ret;
1803 }
1804
1805
1806
1807 static int handle_tcp_options(struct nes_cm_node *cm_node, struct tcphdr *tcph,
1808         struct sk_buff *skb, int optionsize, int passive)
1809 {
1810         u8 *optionsloc = (u8 *)&tcph[1];
1811         if (optionsize) {
1812                 if (process_options(cm_node, optionsloc, optionsize,
1813                         (u32)tcph->syn)) {
1814                         nes_debug(NES_DBG_CM, "%s: Node %p, Sending RESET\n",
1815                                 __func__, cm_node);
1816                         if (passive)
1817                                 passive_open_err(cm_node, skb, 1);
1818                         else
1819                                 active_open_err(cm_node, skb, 1);
1820                         return 1;
1821                 }
1822         }
1823
1824         cm_node->tcp_cntxt.snd_wnd = ntohs(tcph->window) <<
1825                         cm_node->tcp_cntxt.snd_wscale;
1826
1827         if (cm_node->tcp_cntxt.snd_wnd > cm_node->tcp_cntxt.max_snd_wnd)
1828                 cm_node->tcp_cntxt.max_snd_wnd = cm_node->tcp_cntxt.snd_wnd;
1829         return 0;
1830 }
1831
1832 /*
1833  * active_open_err() will send reset() if flag set..
1834  * It will also send ABORT event.
1835  */
1836
1837 static void active_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
1838         int reset)
1839 {
1840         cleanup_retrans_entry(cm_node);
1841         if (reset) {
1842                 nes_debug(NES_DBG_CM, "ERROR active err called for cm_node=%p, "
1843                                 "state=%d\n", cm_node, cm_node->state);
1844                 add_ref_cm_node(cm_node);
1845                 send_reset(cm_node, skb);
1846         } else
1847                 dev_kfree_skb_any(skb);
1848
1849         cm_node->state = NES_CM_STATE_CLOSED;
1850         create_event(cm_node, NES_CM_EVENT_ABORTED);
1851 }
1852
1853 /*
1854  * passive_open_err() will either do a reset() or will free up the skb and
1855  * remove the cm_node.
1856  */
1857
1858 static void passive_open_err(struct nes_cm_node *cm_node, struct sk_buff *skb,
1859         int reset)
1860 {
1861         cleanup_retrans_entry(cm_node);
1862         cm_node->state = NES_CM_STATE_CLOSED;
1863         if (reset) {
1864                 nes_debug(NES_DBG_CM, "passive_open_err sending RST for "
1865                         "cm_node=%p state =%d\n", cm_node, cm_node->state);
1866                 send_reset(cm_node, skb);
1867         } else {
1868                 dev_kfree_skb_any(skb);
1869                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1870         }
1871 }
1872
1873 /*
1874  * free_retrans_entry() routines assumes that the retrans_list_lock has
1875  * been acquired before calling.
1876  */
1877 static void free_retrans_entry(struct nes_cm_node *cm_node)
1878 {
1879         struct nes_timer_entry *send_entry;
1880         send_entry = cm_node->send_entry;
1881         if (send_entry) {
1882                 cm_node->send_entry = NULL;
1883                 dev_kfree_skb_any(send_entry->skb);
1884                 kfree(send_entry);
1885                 rem_ref_cm_node(cm_node->cm_core, cm_node);
1886         }
1887 }
1888
1889 static void cleanup_retrans_entry(struct nes_cm_node *cm_node)
1890 {
1891         unsigned long flags;
1892
1893         spin_lock_irqsave(&cm_node->retrans_list_lock, flags);
1894         free_retrans_entry(cm_node);
1895         spin_unlock_irqrestore(&cm_node->retrans_list_lock, flags);
1896 }
1897
1898 /**
1899  * process_packet
1900  * Returns skb if to be freed, else it will return NULL if already used..
1901  */
1902 static void process_packet(struct nes_cm_node *cm_node, struct sk_buff *skb,
1903         struct nes_cm_core *cm_core)
1904 {
1905         enum nes_tcpip_pkt_type pkt_type = NES_PKT_TYPE_UNKNOWN;
1906         struct tcphdr *tcph = tcp_hdr(skb);
1907         u32     fin_set = 0;
1908         int ret = 0;
1909         skb_pull(skb, ip_hdr(skb)->ihl << 2);
1910
1911         nes_debug(NES_DBG_CM, "process_packet: cm_node=%p state =%d syn=%d "
1912                 "ack=%d rst=%d fin=%d\n", cm_node, cm_node->state, tcph->syn,
1913                 tcph->ack, tcph->rst, tcph->fin);
1914
1915         if (tcph->rst)
1916                 pkt_type = NES_PKT_TYPE_RST;
1917         else if (tcph->syn) {
1918                 pkt_type = NES_PKT_TYPE_SYN;
1919                 if (tcph->ack)
1920                         pkt_type = NES_PKT_TYPE_SYNACK;
1921         } else if (tcph->ack)
1922                 pkt_type = NES_PKT_TYPE_ACK;
1923         if (tcph->fin)
1924                 fin_set = 1;
1925
1926         switch (pkt_type) {
1927         case NES_PKT_TYPE_SYN:
1928                 handle_syn_pkt(cm_node, skb, tcph);
1929                 break;
1930         case NES_PKT_TYPE_SYNACK:
1931                 handle_synack_pkt(cm_node, skb, tcph);
1932                 break;
1933         case NES_PKT_TYPE_ACK:
1934                 ret = handle_ack_pkt(cm_node, skb, tcph);
1935                 if (fin_set && !ret)
1936                         handle_fin_pkt(cm_node);
1937                 break;
1938         case NES_PKT_TYPE_RST:
1939                 handle_rst_pkt(cm_node, skb, tcph);
1940                 break;
1941         default:
1942                 if ((fin_set) && (!check_seq(cm_node, tcph, skb)))
1943                         handle_fin_pkt(cm_node);
1944                 drop_packet(skb);
1945                 break;
1946         }
1947 }
1948
1949 /**
1950  * mini_cm_listen - create a listen node with params
1951  */
1952 static struct nes_cm_listener *mini_cm_listen(struct nes_cm_core *cm_core,
1953         struct nes_vnic *nesvnic, struct nes_cm_info *cm_info)
1954 {
1955         struct nes_cm_listener *listener;
1956         unsigned long flags;
1957
1958         nes_debug(NES_DBG_CM, "Search for 0x%08x : 0x%04x\n",
1959                 cm_info->loc_addr, cm_info->loc_port);
1960
1961         /* cannot have multiple matching listeners */
1962         listener = find_listener(cm_core, htonl(cm_info->loc_addr),
1963                         htons(cm_info->loc_port), NES_CM_LISTENER_EITHER_STATE);
1964         if (listener && listener->listener_state == NES_CM_LISTENER_ACTIVE_STATE) {
1965                 /* find automatically incs ref count ??? */
1966                 atomic_dec(&listener->ref_count);
1967                 nes_debug(NES_DBG_CM, "Not creating listener since it already exists\n");
1968                 return NULL;
1969         }
1970
1971         if (!listener) {
1972                 /* create a CM listen node (1/2 node to compare incoming traffic to) */
1973                 listener = kzalloc(sizeof(*listener), GFP_ATOMIC);
1974                 if (!listener) {
1975                         nes_debug(NES_DBG_CM, "Not creating listener memory allocation failed\n");
1976                         return NULL;
1977                 }
1978
1979                 listener->loc_addr = htonl(cm_info->loc_addr);
1980                 listener->loc_port = htons(cm_info->loc_port);
1981                 listener->reused_node = 0;
1982
1983                 atomic_set(&listener->ref_count, 1);
1984         }
1985         /* pasive case */
1986         /* find already inc'ed the ref count */
1987         else {
1988                 listener->reused_node = 1;
1989         }
1990
1991         listener->cm_id = cm_info->cm_id;
1992         atomic_set(&listener->pend_accepts_cnt, 0);
1993         listener->cm_core = cm_core;
1994         listener->nesvnic = nesvnic;
1995         atomic_inc(&cm_core->node_cnt);
1996
1997         listener->conn_type = cm_info->conn_type;
1998         listener->backlog = cm_info->backlog;
1999         listener->listener_state = NES_CM_LISTENER_ACTIVE_STATE;
2000
2001         if (!listener->reused_node) {
2002                 spin_lock_irqsave(&cm_core->listen_list_lock, flags);
2003                 list_add(&listener->list, &cm_core->listen_list.list);
2004                 spin_unlock_irqrestore(&cm_core->listen_list_lock, flags);
2005                 atomic_inc(&cm_core->listen_node_cnt);
2006         }
2007
2008         nes_debug(NES_DBG_CM, "Api - listen(): addr=0x%08X, port=0x%04x,"
2009                         " listener = %p, backlog = %d, cm_id = %p.\n",
2010                         cm_info->loc_addr, cm_info->loc_port,
2011                         listener, listener->backlog, listener->cm_id);
2012
2013         return listener;
2014 }
2015
2016
2017 /**
2018  * mini_cm_connect - make a connection node with params
2019  */
2020 static struct nes_cm_node *mini_cm_connect(struct nes_cm_core *cm_core,
2021         struct nes_vnic *nesvnic, u16 private_data_len,
2022         void *private_data, struct nes_cm_info *cm_info)
2023 {
2024         int ret = 0;
2025         struct nes_cm_node *cm_node;
2026         struct nes_cm_listener *loopbackremotelistener;
2027         struct nes_cm_node *loopbackremotenode;
2028         struct nes_cm_info loopback_cm_info;
2029         u16 mpa_frame_size = sizeof(struct ietf_mpa_frame) + private_data_len;
2030         struct ietf_mpa_frame *mpa_frame = NULL;
2031
2032         /* create a CM connection node */
2033         cm_node = make_cm_node(cm_core, nesvnic, cm_info, NULL);
2034         if (!cm_node)
2035                 return NULL;
2036         mpa_frame = &cm_node->mpa_frame;
2037         memcpy(mpa_frame->key, IEFT_MPA_KEY_REQ, IETF_MPA_KEY_SIZE);
2038         mpa_frame->flags = IETF_MPA_FLAGS_CRC;
2039         mpa_frame->rev =  IETF_MPA_VERSION;
2040         mpa_frame->priv_data_len = htons(private_data_len);
2041
2042         /* set our node side to client (active) side */
2043         cm_node->tcp_cntxt.client = 1;
2044         cm_node->tcp_cntxt.rcv_wscale = NES_CM_DEFAULT_RCV_WND_SCALE;
2045
2046         if (cm_info->loc_addr == cm_info->rem_addr) {
2047                 loopbackremotelistener = find_listener(cm_core,
2048                                 ntohl(nesvnic->local_ipaddr), cm_node->rem_port,
2049                                 NES_CM_LISTENER_ACTIVE_STATE);
2050                 if (loopbackremotelistener == NULL) {
2051                         create_event(cm_node, NES_CM_EVENT_ABORTED);
2052                 } else {
2053                         loopback_cm_info = *cm_info;
2054                         loopback_cm_info.loc_port = cm_info->rem_port;
2055                         loopback_cm_info.rem_port = cm_info->loc_port;
2056                         loopback_cm_info.cm_id = loopbackremotelistener->cm_id;
2057                         loopbackremotenode = make_cm_node(cm_core, nesvnic,
2058                                 &loopback_cm_info, loopbackremotelistener);
2059                         if (!loopbackremotenode) {
2060                                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2061                                 return NULL;
2062                         }
2063                         atomic_inc(&cm_loopbacks);
2064                         loopbackremotenode->loopbackpartner = cm_node;
2065                         loopbackremotenode->tcp_cntxt.rcv_wscale =
2066                                 NES_CM_DEFAULT_RCV_WND_SCALE;
2067                         cm_node->loopbackpartner = loopbackremotenode;
2068                         memcpy(loopbackremotenode->mpa_frame_buf, private_data,
2069                                 private_data_len);
2070                         loopbackremotenode->mpa_frame_size = private_data_len;
2071
2072                         /* we are done handling this state. */
2073                         /* set node to a TSA state */
2074                         cm_node->state = NES_CM_STATE_TSA;
2075                         cm_node->tcp_cntxt.rcv_nxt =
2076                                 loopbackremotenode->tcp_cntxt.loc_seq_num;
2077                         loopbackremotenode->tcp_cntxt.rcv_nxt =
2078                                 cm_node->tcp_cntxt.loc_seq_num;
2079                         cm_node->tcp_cntxt.max_snd_wnd =
2080                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2081                         loopbackremotenode->tcp_cntxt.max_snd_wnd =
2082                                 cm_node->tcp_cntxt.rcv_wnd;
2083                         cm_node->tcp_cntxt.snd_wnd =
2084                                 loopbackremotenode->tcp_cntxt.rcv_wnd;
2085                         loopbackremotenode->tcp_cntxt.snd_wnd =
2086                                 cm_node->tcp_cntxt.rcv_wnd;
2087                         cm_node->tcp_cntxt.snd_wscale =
2088                                 loopbackremotenode->tcp_cntxt.rcv_wscale;
2089                         loopbackremotenode->tcp_cntxt.snd_wscale =
2090                                 cm_node->tcp_cntxt.rcv_wscale;
2091                         loopbackremotenode->state = NES_CM_STATE_MPAREQ_RCVD;
2092                         create_event(loopbackremotenode, NES_CM_EVENT_MPA_REQ);
2093                 }
2094                 return cm_node;
2095         }
2096
2097         /* set our node side to client (active) side */
2098         cm_node->tcp_cntxt.client = 1;
2099         /* init our MPA frame ptr */
2100         memcpy(mpa_frame->priv_data, private_data, private_data_len);
2101
2102         cm_node->mpa_frame_size = mpa_frame_size;
2103
2104         /* send a syn and goto syn sent state */
2105         cm_node->state = NES_CM_STATE_SYN_SENT;
2106         ret = send_syn(cm_node, 0, NULL);
2107
2108         if (ret) {
2109                 /* error in sending the syn free up the cm_node struct */
2110                 nes_debug(NES_DBG_CM, "Api - connect() FAILED: dest "
2111                         "addr=0x%08X, port=0x%04x, cm_node=%p, cm_id = %p.\n",
2112                         cm_node->rem_addr, cm_node->rem_port, cm_node,
2113                         cm_node->cm_id);
2114                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2115                 cm_node = NULL;
2116         }
2117
2118         if (cm_node)
2119                 nes_debug(NES_DBG_CM, "Api - connect(): dest addr=0x%08X,"
2120                         "port=0x%04x, cm_node=%p, cm_id = %p.\n",
2121                         cm_node->rem_addr, cm_node->rem_port, cm_node,
2122                         cm_node->cm_id);
2123
2124         return cm_node;
2125 }
2126
2127
2128 /**
2129  * mini_cm_accept - accept a connection
2130  * This function is never called
2131  */
2132 static int mini_cm_accept(struct nes_cm_core *cm_core,
2133         struct ietf_mpa_frame *mpa_frame, struct nes_cm_node *cm_node)
2134 {
2135         return 0;
2136 }
2137
2138
2139 /**
2140  * mini_cm_reject - reject and teardown a connection
2141  */
2142 static int mini_cm_reject(struct nes_cm_core *cm_core,
2143         struct ietf_mpa_frame *mpa_frame, struct nes_cm_node *cm_node)
2144 {
2145         int ret = 0;
2146         int err = 0;
2147         int passive_state;
2148         struct nes_cm_event event;
2149         struct iw_cm_id *cm_id = cm_node->cm_id;
2150         struct nes_cm_node *loopback = cm_node->loopbackpartner;
2151
2152         nes_debug(NES_DBG_CM, "%s cm_node=%p type=%d state=%d\n",
2153                 __func__, cm_node, cm_node->tcp_cntxt.client, cm_node->state);
2154
2155         if (cm_node->tcp_cntxt.client)
2156                 return ret;
2157         cleanup_retrans_entry(cm_node);
2158
2159         if (!loopback) {
2160                 passive_state = atomic_add_return(1, &cm_node->passive_state);
2161                 if (passive_state == NES_SEND_RESET_EVENT) {
2162                         cm_node->state = NES_CM_STATE_CLOSED;
2163                         rem_ref_cm_node(cm_core, cm_node);
2164                 } else {
2165                         if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2166                                 rem_ref_cm_node(cm_core, cm_node);
2167                         } else {
2168                                 ret = send_mpa_reject(cm_node);
2169                                 if (ret) {
2170                                         cm_node->state = NES_CM_STATE_CLOSED;
2171                                         err = send_reset(cm_node, NULL);
2172                                         if (err)
2173                                                 WARN_ON(1);
2174                                 } else
2175                                         cm_id->add_ref(cm_id);
2176                         }
2177                 }
2178         } else {
2179                 cm_node->cm_id = NULL;
2180                 if (cm_node->state == NES_CM_STATE_LISTENER_DESTROYED) {
2181                         rem_ref_cm_node(cm_core, cm_node);
2182                         rem_ref_cm_node(cm_core, loopback);
2183                 } else {
2184                         event.cm_node = loopback;
2185                         event.cm_info.rem_addr = loopback->rem_addr;
2186                         event.cm_info.loc_addr = loopback->loc_addr;
2187                         event.cm_info.rem_port = loopback->rem_port;
2188                         event.cm_info.loc_port = loopback->loc_port;
2189                         event.cm_info.cm_id = loopback->cm_id;
2190                         cm_event_mpa_reject(&event);
2191                         rem_ref_cm_node(cm_core, cm_node);
2192                         loopback->state = NES_CM_STATE_CLOSING;
2193
2194                         cm_id = loopback->cm_id;
2195                         rem_ref_cm_node(cm_core, loopback);
2196                         cm_id->rem_ref(cm_id);
2197                 }
2198         }
2199
2200         return ret;
2201 }
2202
2203
2204 /**
2205  * mini_cm_close
2206  */
2207 static int mini_cm_close(struct nes_cm_core *cm_core, struct nes_cm_node *cm_node)
2208 {
2209         int ret = 0;
2210
2211         if (!cm_core || !cm_node)
2212                 return -EINVAL;
2213
2214         switch (cm_node->state) {
2215         case NES_CM_STATE_SYN_RCVD:
2216         case NES_CM_STATE_SYN_SENT:
2217         case NES_CM_STATE_ONE_SIDE_ESTABLISHED:
2218         case NES_CM_STATE_ESTABLISHED:
2219         case NES_CM_STATE_ACCEPTING:
2220         case NES_CM_STATE_MPAREQ_SENT:
2221         case NES_CM_STATE_MPAREQ_RCVD:
2222                 cleanup_retrans_entry(cm_node);
2223                 send_reset(cm_node, NULL);
2224                 break;
2225         case NES_CM_STATE_CLOSE_WAIT:
2226                 cm_node->state = NES_CM_STATE_LAST_ACK;
2227                 send_fin(cm_node, NULL);
2228                 break;
2229         case NES_CM_STATE_FIN_WAIT1:
2230         case NES_CM_STATE_FIN_WAIT2:
2231         case NES_CM_STATE_LAST_ACK:
2232         case NES_CM_STATE_TIME_WAIT:
2233         case NES_CM_STATE_CLOSING:
2234                 ret = -1;
2235                 break;
2236         case NES_CM_STATE_LISTENING:
2237                 cleanup_retrans_entry(cm_node);
2238                 send_reset(cm_node, NULL);
2239                 break;
2240         case NES_CM_STATE_MPAREJ_RCVD:
2241         case NES_CM_STATE_UNKNOWN:
2242         case NES_CM_STATE_INITED:
2243         case NES_CM_STATE_CLOSED:
2244         case NES_CM_STATE_LISTENER_DESTROYED:
2245                 ret = rem_ref_cm_node(cm_core, cm_node);
2246                 break;
2247         case NES_CM_STATE_TSA:
2248                 if (cm_node->send_entry)
2249                         printk(KERN_ERR "ERROR Close got called from STATE_TSA "
2250                                 "send_entry=%p\n", cm_node->send_entry);
2251                 ret = rem_ref_cm_node(cm_core, cm_node);
2252                 break;
2253         }
2254         return ret;
2255 }
2256
2257
2258 /**
2259  * recv_pkt - recv an ETHERNET packet, and process it through CM
2260  * node state machine
2261  */
2262 static int mini_cm_recv_pkt(struct nes_cm_core *cm_core,
2263         struct nes_vnic *nesvnic, struct sk_buff *skb)
2264 {
2265         struct nes_cm_node *cm_node = NULL;
2266         struct nes_cm_listener *listener = NULL;
2267         struct iphdr *iph;
2268         struct tcphdr *tcph;
2269         struct nes_cm_info nfo;
2270         int skb_handled = 1;
2271         __be32 tmp_daddr, tmp_saddr;
2272
2273         if (!skb)
2274                 return 0;
2275         if (skb->len < sizeof(struct iphdr) + sizeof(struct tcphdr)) {
2276                 return 0;
2277         }
2278
2279         iph = (struct iphdr *)skb->data;
2280         tcph = (struct tcphdr *)(skb->data + sizeof(struct iphdr));
2281
2282         nfo.loc_addr = ntohl(iph->daddr);
2283         nfo.loc_port = ntohs(tcph->dest);
2284         nfo.rem_addr = ntohl(iph->saddr);
2285         nfo.rem_port = ntohs(tcph->source);
2286
2287         tmp_daddr = cpu_to_be32(iph->daddr);
2288         tmp_saddr = cpu_to_be32(iph->saddr);
2289
2290         nes_debug(NES_DBG_CM, "Received packet: dest=%pI4:0x%04X src=%pI4:0x%04X\n",
2291                   &tmp_daddr, tcph->dest, &tmp_saddr, tcph->source);
2292
2293         do {
2294                 cm_node = find_node(cm_core,
2295                         nfo.rem_port, nfo.rem_addr,
2296                         nfo.loc_port, nfo.loc_addr);
2297
2298                 if (!cm_node) {
2299                         /* Only type of packet accepted are for */
2300                         /* the PASSIVE open (syn only) */
2301                         if ((!tcph->syn) || (tcph->ack)) {
2302                                 skb_handled = 0;
2303                                 break;
2304                         }
2305                         listener = find_listener(cm_core, nfo.loc_addr,
2306                                 nfo.loc_port,
2307                                 NES_CM_LISTENER_ACTIVE_STATE);
2308                         if (!listener) {
2309                                 nfo.cm_id = NULL;
2310                                 nfo.conn_type = 0;
2311                                 nes_debug(NES_DBG_CM, "Unable to find listener for the pkt\n");
2312                                 skb_handled = 0;
2313                                 break;
2314                         }
2315                         nfo.cm_id = listener->cm_id;
2316                         nfo.conn_type = listener->conn_type;
2317                         cm_node = make_cm_node(cm_core, nesvnic, &nfo,
2318                                 listener);
2319                         if (!cm_node) {
2320                                 nes_debug(NES_DBG_CM, "Unable to allocate "
2321                                         "node\n");
2322                                 cm_packets_dropped++;
2323                                 atomic_dec(&listener->ref_count);
2324                                 dev_kfree_skb_any(skb);
2325                                 break;
2326                         }
2327                         if (!tcph->rst && !tcph->fin) {
2328                                 cm_node->state = NES_CM_STATE_LISTENING;
2329                         } else {
2330                                 cm_packets_dropped++;
2331                                 rem_ref_cm_node(cm_core, cm_node);
2332                                 dev_kfree_skb_any(skb);
2333                                 break;
2334                         }
2335                         add_ref_cm_node(cm_node);
2336                 } else if (cm_node->state == NES_CM_STATE_TSA) {
2337                         rem_ref_cm_node(cm_core, cm_node);
2338                         atomic_inc(&cm_accel_dropped_pkts);
2339                         dev_kfree_skb_any(skb);
2340                         break;
2341                 }
2342                 skb_reset_network_header(skb);
2343                 skb_set_transport_header(skb, sizeof(*tcph));
2344                 skb->len = ntohs(iph->tot_len);
2345                 process_packet(cm_node, skb, cm_core);
2346                 rem_ref_cm_node(cm_core, cm_node);
2347         } while (0);
2348         return skb_handled;
2349 }
2350
2351
2352 /**
2353  * nes_cm_alloc_core - allocate a top level instance of a cm core
2354  */
2355 static struct nes_cm_core *nes_cm_alloc_core(void)
2356 {
2357         struct nes_cm_core *cm_core;
2358
2359         /* setup the CM core */
2360         /* alloc top level core control structure */
2361         cm_core = kzalloc(sizeof(*cm_core), GFP_KERNEL);
2362         if (!cm_core)
2363                 return NULL;
2364
2365         INIT_LIST_HEAD(&cm_core->connected_nodes);
2366         init_timer(&cm_core->tcp_timer);
2367         cm_core->tcp_timer.function = nes_cm_timer_tick;
2368
2369         cm_core->mtu   = NES_CM_DEFAULT_MTU;
2370         cm_core->state = NES_CM_STATE_INITED;
2371         cm_core->free_tx_pkt_max = NES_CM_DEFAULT_FREE_PKTS;
2372
2373         atomic_set(&cm_core->events_posted, 0);
2374
2375         cm_core->api = &nes_cm_api;
2376
2377         spin_lock_init(&cm_core->ht_lock);
2378         spin_lock_init(&cm_core->listen_list_lock);
2379
2380         INIT_LIST_HEAD(&cm_core->listen_list.list);
2381
2382         nes_debug(NES_DBG_CM, "Init CM Core completed -- cm_core=%p\n", cm_core);
2383
2384         nes_debug(NES_DBG_CM, "Enable QUEUE EVENTS\n");
2385         cm_core->event_wq = create_singlethread_workqueue("nesewq");
2386         cm_core->post_event = nes_cm_post_event;
2387         nes_debug(NES_DBG_CM, "Enable QUEUE DISCONNECTS\n");
2388         cm_core->disconn_wq = create_singlethread_workqueue("nesdwq");
2389
2390         print_core(cm_core);
2391         return cm_core;
2392 }
2393
2394
2395 /**
2396  * mini_cm_dealloc_core - deallocate a top level instance of a cm core
2397  */
2398 static int mini_cm_dealloc_core(struct nes_cm_core *cm_core)
2399 {
2400         nes_debug(NES_DBG_CM, "De-Alloc CM Core (%p)\n", cm_core);
2401
2402         if (!cm_core)
2403                 return -EINVAL;
2404
2405         barrier();
2406
2407         if (timer_pending(&cm_core->tcp_timer)) {
2408                 del_timer(&cm_core->tcp_timer);
2409         }
2410
2411         destroy_workqueue(cm_core->event_wq);
2412         destroy_workqueue(cm_core->disconn_wq);
2413         nes_debug(NES_DBG_CM, "\n");
2414         kfree(cm_core);
2415
2416         return 0;
2417 }
2418
2419
2420 /**
2421  * mini_cm_get
2422  */
2423 static int mini_cm_get(struct nes_cm_core *cm_core)
2424 {
2425         return cm_core->state;
2426 }
2427
2428
2429 /**
2430  * mini_cm_set
2431  */
2432 static int mini_cm_set(struct nes_cm_core *cm_core, u32 type, u32 value)
2433 {
2434         int ret = 0;
2435
2436         switch (type) {
2437         case NES_CM_SET_PKT_SIZE:
2438                 cm_core->mtu = value;
2439                 break;
2440         case NES_CM_SET_FREE_PKT_Q_SIZE:
2441                 cm_core->free_tx_pkt_max = value;
2442                 break;
2443         default:
2444                 /* unknown set option */
2445                 ret = -EINVAL;
2446         }
2447
2448         return ret;
2449 }
2450
2451
2452 /**
2453  * nes_cm_init_tsa_conn setup HW; MPA frames must be
2454  * successfully exchanged when this is called
2455  */
2456 static int nes_cm_init_tsa_conn(struct nes_qp *nesqp, struct nes_cm_node *cm_node)
2457 {
2458         int ret = 0;
2459
2460         if (!nesqp)
2461                 return -EINVAL;
2462
2463         nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_IPV4 |
2464                         NES_QPCONTEXT_MISC_NO_NAGLE | NES_QPCONTEXT_MISC_DO_NOT_FRAG |
2465                         NES_QPCONTEXT_MISC_DROS);
2466
2467         if (cm_node->tcp_cntxt.snd_wscale || cm_node->tcp_cntxt.rcv_wscale)
2468                 nesqp->nesqp_context->misc |= cpu_to_le32(NES_QPCONTEXT_MISC_WSCALE);
2469
2470         nesqp->nesqp_context->misc2 |= cpu_to_le32(64 << NES_QPCONTEXT_MISC2_TTL_SHIFT);
2471
2472         nesqp->nesqp_context->mss |= cpu_to_le32(((u32)cm_node->tcp_cntxt.mss) << 16);
2473
2474         nesqp->nesqp_context->tcp_state_flow_label |= cpu_to_le32(
2475                         (u32)NES_QPCONTEXT_TCPSTATE_EST << NES_QPCONTEXT_TCPFLOW_TCP_STATE_SHIFT);
2476
2477         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2478                         (cm_node->tcp_cntxt.snd_wscale << NES_QPCONTEXT_PDWSCALE_SND_WSCALE_SHIFT) &
2479                         NES_QPCONTEXT_PDWSCALE_SND_WSCALE_MASK);
2480
2481         nesqp->nesqp_context->pd_index_wscale |= cpu_to_le32(
2482                         (cm_node->tcp_cntxt.rcv_wscale << NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_SHIFT) &
2483                         NES_QPCONTEXT_PDWSCALE_RCV_WSCALE_MASK);
2484
2485         nesqp->nesqp_context->keepalive = cpu_to_le32(0x80);
2486         nesqp->nesqp_context->ts_recent = 0;
2487         nesqp->nesqp_context->ts_age = 0;
2488         nesqp->nesqp_context->snd_nxt = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2489         nesqp->nesqp_context->snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.snd_wnd);
2490         nesqp->nesqp_context->rcv_nxt = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2491         nesqp->nesqp_context->rcv_wnd = cpu_to_le32(cm_node->tcp_cntxt.rcv_wnd <<
2492                         cm_node->tcp_cntxt.rcv_wscale);
2493         nesqp->nesqp_context->snd_max = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2494         nesqp->nesqp_context->snd_una = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2495         nesqp->nesqp_context->srtt = 0;
2496         nesqp->nesqp_context->rttvar = cpu_to_le32(0x6);
2497         nesqp->nesqp_context->ssthresh = cpu_to_le32(0x3FFFC000);
2498         nesqp->nesqp_context->cwnd = cpu_to_le32(2*cm_node->tcp_cntxt.mss);
2499         nesqp->nesqp_context->snd_wl1 = cpu_to_le32(cm_node->tcp_cntxt.rcv_nxt);
2500         nesqp->nesqp_context->snd_wl2 = cpu_to_le32(cm_node->tcp_cntxt.loc_seq_num);
2501         nesqp->nesqp_context->max_snd_wnd = cpu_to_le32(cm_node->tcp_cntxt.max_snd_wnd);
2502
2503         nes_debug(NES_DBG_CM, "QP%u: rcv_nxt = 0x%08X, snd_nxt = 0x%08X,"
2504                         " Setting MSS to %u, PDWscale = 0x%08X, rcv_wnd = %u, context misc = 0x%08X.\n",
2505                         nesqp->hwqp.qp_id, le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
2506                         le32_to_cpu(nesqp->nesqp_context->snd_nxt),
2507                         cm_node->tcp_cntxt.mss, le32_to_cpu(nesqp->nesqp_context->pd_index_wscale),
2508                         le32_to_cpu(nesqp->nesqp_context->rcv_wnd),
2509                         le32_to_cpu(nesqp->nesqp_context->misc));
2510         nes_debug(NES_DBG_CM, "  snd_wnd  = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->snd_wnd));
2511         nes_debug(NES_DBG_CM, "  snd_cwnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->cwnd));
2512         nes_debug(NES_DBG_CM, "  max_swnd = 0x%08X.\n", le32_to_cpu(nesqp->nesqp_context->max_snd_wnd));
2513
2514         nes_debug(NES_DBG_CM, "Change cm_node state to TSA\n");
2515         cm_node->state = NES_CM_STATE_TSA;
2516
2517         return ret;
2518 }
2519
2520
2521 /**
2522  * nes_cm_disconn
2523  */
2524 int nes_cm_disconn(struct nes_qp *nesqp)
2525 {
2526         struct disconn_work *work;
2527
2528         work = kzalloc(sizeof *work, GFP_ATOMIC);
2529         if (!work)
2530                 return -ENOMEM; /* Timer will clean up */
2531
2532         nes_add_ref(&nesqp->ibqp);
2533         work->nesqp = nesqp;
2534         INIT_WORK(&work->work, nes_disconnect_worker);
2535         queue_work(g_cm_core->disconn_wq, &work->work);
2536         return 0;
2537 }
2538
2539
2540 /**
2541  * nes_disconnect_worker
2542  */
2543 static void nes_disconnect_worker(struct work_struct *work)
2544 {
2545         struct disconn_work *dwork = container_of(work, struct disconn_work, work);
2546         struct nes_qp *nesqp = dwork->nesqp;
2547
2548         kfree(dwork);
2549         nes_debug(NES_DBG_CM, "processing AEQE id 0x%04X for QP%u.\n",
2550                         nesqp->last_aeq, nesqp->hwqp.qp_id);
2551         nes_cm_disconn_true(nesqp);
2552         nes_rem_ref(&nesqp->ibqp);
2553 }
2554
2555
2556 /**
2557  * nes_cm_disconn_true
2558  */
2559 static int nes_cm_disconn_true(struct nes_qp *nesqp)
2560 {
2561         unsigned long flags;
2562         int ret = 0;
2563         struct iw_cm_id *cm_id;
2564         struct iw_cm_event cm_event;
2565         struct nes_vnic *nesvnic;
2566         u16 last_ae;
2567         u8 original_hw_tcp_state;
2568         u8 original_ibqp_state;
2569         enum iw_cm_event_status disconn_status = IW_CM_EVENT_STATUS_OK;
2570         int issue_disconn = 0;
2571         int issue_close = 0;
2572         int issue_flush = 0;
2573         u32 flush_q = NES_CQP_FLUSH_RQ;
2574         struct ib_event ibevent;
2575
2576         if (!nesqp) {
2577                 nes_debug(NES_DBG_CM, "disconnect_worker nesqp is NULL\n");
2578                 return -1;
2579         }
2580
2581         spin_lock_irqsave(&nesqp->lock, flags);
2582         cm_id = nesqp->cm_id;
2583         /* make sure we havent already closed this connection */
2584         if (!cm_id) {
2585                 nes_debug(NES_DBG_CM, "QP%u disconnect_worker cmid is NULL\n",
2586                                 nesqp->hwqp.qp_id);
2587                 spin_unlock_irqrestore(&nesqp->lock, flags);
2588                 return -1;
2589         }
2590
2591         nesvnic = to_nesvnic(nesqp->ibqp.device);
2592         nes_debug(NES_DBG_CM, "Disconnecting QP%u\n", nesqp->hwqp.qp_id);
2593
2594         original_hw_tcp_state = nesqp->hw_tcp_state;
2595         original_ibqp_state   = nesqp->ibqp_state;
2596         last_ae = nesqp->last_aeq;
2597
2598         if (nesqp->term_flags) {
2599                 issue_disconn = 1;
2600                 issue_close = 1;
2601                 nesqp->cm_id = NULL;
2602                 if (nesqp->flush_issued == 0) {
2603                         nesqp->flush_issued = 1;
2604                         issue_flush = 1;
2605                 }
2606         } else if ((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSE_WAIT) ||
2607                         ((original_ibqp_state == IB_QPS_RTS) &&
2608                         (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2609                 issue_disconn = 1;
2610                 if (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET)
2611                         disconn_status = IW_CM_EVENT_STATUS_RESET;
2612         }
2613
2614         if (((original_hw_tcp_state == NES_AEQE_TCP_STATE_CLOSED) ||
2615                  (original_hw_tcp_state == NES_AEQE_TCP_STATE_TIME_WAIT) ||
2616                  (last_ae == NES_AEQE_AEID_RDMAP_ROE_BAD_LLP_CLOSE) ||
2617                  (last_ae == NES_AEQE_AEID_LLP_CONNECTION_RESET))) {
2618                 issue_close = 1;
2619                 nesqp->cm_id = NULL;
2620                 if (nesqp->flush_issued == 0) {
2621                         nesqp->flush_issued = 1;
2622                         issue_flush = 1;
2623                 }
2624         }
2625
2626         spin_unlock_irqrestore(&nesqp->lock, flags);
2627
2628         if ((issue_flush) && (nesqp->destroyed == 0)) {
2629                 /* Flush the queue(s) */
2630                 if (nesqp->hw_iwarp_state >= NES_AEQE_IWARP_STATE_TERMINATE)
2631                         flush_q |= NES_CQP_FLUSH_SQ;
2632                 flush_wqes(nesvnic->nesdev, nesqp, flush_q, 1);
2633
2634                 if (nesqp->term_flags) {
2635                         ibevent.device = nesqp->ibqp.device;
2636                         ibevent.event = nesqp->terminate_eventtype;
2637                         ibevent.element.qp = &nesqp->ibqp;
2638                         nesqp->ibqp.event_handler(&ibevent, nesqp->ibqp.qp_context);
2639                 }
2640         }
2641
2642         if ((cm_id) && (cm_id->event_handler)) {
2643                 if (issue_disconn) {
2644                         atomic_inc(&cm_disconnects);
2645                         cm_event.event = IW_CM_EVENT_DISCONNECT;
2646                         cm_event.status = disconn_status;
2647                         cm_event.local_addr = cm_id->local_addr;
2648                         cm_event.remote_addr = cm_id->remote_addr;
2649                         cm_event.private_data = NULL;
2650                         cm_event.private_data_len = 0;
2651
2652                         nes_debug(NES_DBG_CM, "Generating a CM Disconnect Event"
2653                                 " for  QP%u, SQ Head = %u, SQ Tail = %u. "
2654                                 "cm_id = %p, refcount = %u.\n",
2655                                 nesqp->hwqp.qp_id, nesqp->hwqp.sq_head,
2656                                 nesqp->hwqp.sq_tail, cm_id,
2657                                 atomic_read(&nesqp->refcount));
2658
2659                         ret = cm_id->event_handler(cm_id, &cm_event);
2660                         if (ret)
2661                                 nes_debug(NES_DBG_CM, "OFA CM event_handler "
2662                                         "returned, ret=%d\n", ret);
2663                 }
2664
2665                 if (issue_close) {
2666                         atomic_inc(&cm_closes);
2667                         nes_disconnect(nesqp, 1);
2668
2669                         cm_id->provider_data = nesqp;
2670                         /* Send up the close complete event */
2671                         cm_event.event = IW_CM_EVENT_CLOSE;
2672                         cm_event.status = IW_CM_EVENT_STATUS_OK;
2673                         cm_event.provider_data = cm_id->provider_data;
2674                         cm_event.local_addr = cm_id->local_addr;
2675                         cm_event.remote_addr = cm_id->remote_addr;
2676                         cm_event.private_data = NULL;
2677                         cm_event.private_data_len = 0;
2678
2679                         ret = cm_id->event_handler(cm_id, &cm_event);
2680                         if (ret) {
2681                                 nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
2682                         }
2683
2684                         cm_id->rem_ref(cm_id);
2685                 }
2686         }
2687
2688         return 0;
2689 }
2690
2691
2692 /**
2693  * nes_disconnect
2694  */
2695 static int nes_disconnect(struct nes_qp *nesqp, int abrupt)
2696 {
2697         int ret = 0;
2698         struct nes_vnic *nesvnic;
2699         struct nes_device *nesdev;
2700         struct nes_ib_device *nesibdev;
2701
2702         nesvnic = to_nesvnic(nesqp->ibqp.device);
2703         if (!nesvnic)
2704                 return -EINVAL;
2705
2706         nesdev = nesvnic->nesdev;
2707         nesibdev = nesvnic->nesibdev;
2708
2709         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
2710                         netdev_refcnt_read(nesvnic->netdev));
2711
2712         if (nesqp->active_conn) {
2713
2714                 /* indicate this connection is NOT active */
2715                 nesqp->active_conn = 0;
2716         } else {
2717                 /* Need to free the Last Streaming Mode Message */
2718                 if (nesqp->ietf_frame) {
2719                         if (nesqp->lsmm_mr)
2720                                 nesibdev->ibdev.dereg_mr(nesqp->lsmm_mr);
2721                         pci_free_consistent(nesdev->pcidev,
2722                                         nesqp->private_data_len+sizeof(struct ietf_mpa_frame),
2723                                         nesqp->ietf_frame, nesqp->ietf_frame_pbase);
2724                 }
2725         }
2726
2727         /* close the CM node down if it is still active */
2728         if (nesqp->cm_node) {
2729                 nes_debug(NES_DBG_CM, "Call close API\n");
2730
2731                 g_cm_core->api->close(g_cm_core, nesqp->cm_node);
2732         }
2733
2734         return ret;
2735 }
2736
2737
2738 /**
2739  * nes_accept
2740  */
2741 int nes_accept(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
2742 {
2743         u64 u64temp;
2744         struct ib_qp *ibqp;
2745         struct nes_qp *nesqp;
2746         struct nes_vnic *nesvnic;
2747         struct nes_device *nesdev;
2748         struct nes_cm_node *cm_node;
2749         struct nes_adapter *adapter;
2750         struct ib_qp_attr attr;
2751         struct iw_cm_event cm_event;
2752         struct nes_hw_qp_wqe *wqe;
2753         struct nes_v4_quad nes_quad;
2754         u32 crc_value;
2755         int ret;
2756         int passive_state;
2757         struct nes_ib_device *nesibdev;
2758         struct ib_mr *ibmr = NULL;
2759         struct ib_phys_buf ibphysbuf;
2760         struct nes_pd *nespd;
2761         u64 tagged_offset;
2762
2763         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
2764         if (!ibqp)
2765                 return -EINVAL;
2766
2767         /* get all our handles */
2768         nesqp = to_nesqp(ibqp);
2769         nesvnic = to_nesvnic(nesqp->ibqp.device);
2770         nesdev = nesvnic->nesdev;
2771         adapter = nesdev->nesadapter;
2772
2773         cm_node = (struct nes_cm_node *)cm_id->provider_data;
2774         nes_debug(NES_DBG_CM, "nes_accept: cm_node= %p nesvnic=%p, netdev=%p,"
2775                 "%s\n", cm_node, nesvnic, nesvnic->netdev,
2776                 nesvnic->netdev->name);
2777
2778         if (NES_CM_STATE_LISTENER_DESTROYED == cm_node->state) {
2779                 if (cm_node->loopbackpartner)
2780                         rem_ref_cm_node(cm_node->cm_core, cm_node->loopbackpartner);
2781                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2782                 return -EINVAL;
2783         }
2784
2785         passive_state = atomic_add_return(1, &cm_node->passive_state);
2786         if (passive_state == NES_SEND_RESET_EVENT) {
2787                 rem_ref_cm_node(cm_node->cm_core, cm_node);
2788                 return -ECONNRESET;
2789         }
2790
2791         /* associate the node with the QP */
2792         nesqp->cm_node = (void *)cm_node;
2793         cm_node->nesqp = nesqp;
2794
2795         nes_debug(NES_DBG_CM, "QP%u, cm_node=%p, jiffies = %lu listener = %p\n",
2796                 nesqp->hwqp.qp_id, cm_node, jiffies, cm_node->listener);
2797         atomic_inc(&cm_accepts);
2798
2799         nes_debug(NES_DBG_CM, "netdev refcnt = %u.\n",
2800                         netdev_refcnt_read(nesvnic->netdev));
2801
2802         /* allocate the ietf frame and space for private data */
2803         nesqp->ietf_frame = pci_alloc_consistent(nesdev->pcidev,
2804                 sizeof(struct ietf_mpa_frame) + conn_param->private_data_len,
2805                 &nesqp->ietf_frame_pbase);
2806
2807         if (!nesqp->ietf_frame) {
2808                 nes_debug(NES_DBG_CM, "Unable to allocate memory for private "
2809                         "data\n");
2810                 return -ENOMEM;
2811         }
2812
2813
2814         /* setup the MPA frame */
2815         nesqp->private_data_len = conn_param->private_data_len;
2816         memcpy(nesqp->ietf_frame->key, IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE);
2817
2818         memcpy(nesqp->ietf_frame->priv_data, conn_param->private_data,
2819                         conn_param->private_data_len);
2820
2821         nesqp->ietf_frame->priv_data_len =
2822                 cpu_to_be16(conn_param->private_data_len);
2823         nesqp->ietf_frame->rev = mpa_version;
2824         nesqp->ietf_frame->flags = IETF_MPA_FLAGS_CRC;
2825
2826         /* setup our first outgoing iWarp send WQE (the IETF frame response) */
2827         wqe = &nesqp->hwqp.sq_vbase[0];
2828
2829         if (cm_id->remote_addr.sin_addr.s_addr !=
2830                         cm_id->local_addr.sin_addr.s_addr) {
2831                 u64temp = (unsigned long)nesqp;
2832                 nesibdev = nesvnic->nesibdev;
2833                 nespd = nesqp->nespd;
2834                 ibphysbuf.addr = nesqp->ietf_frame_pbase;
2835                 ibphysbuf.size = conn_param->private_data_len +
2836                                         sizeof(struct ietf_mpa_frame);
2837                 tagged_offset = (u64)(unsigned long)nesqp->ietf_frame;
2838                 ibmr = nesibdev->ibdev.reg_phys_mr((struct ib_pd *)nespd,
2839                                                 &ibphysbuf, 1,
2840                                                 IB_ACCESS_LOCAL_WRITE,
2841                                                 &tagged_offset);
2842                 if (!ibmr) {
2843                         nes_debug(NES_DBG_CM, "Unable to register memory region"
2844                                         "for lSMM for cm_node = %p \n",
2845                                         cm_node);
2846                         pci_free_consistent(nesdev->pcidev,
2847                                 nesqp->private_data_len+sizeof(struct ietf_mpa_frame),
2848                                 nesqp->ietf_frame, nesqp->ietf_frame_pbase);
2849                         return -ENOMEM;
2850                 }
2851
2852                 ibmr->pd = &nespd->ibpd;
2853                 ibmr->device = nespd->ibpd.device;
2854                 nesqp->lsmm_mr = ibmr;
2855
2856                 u64temp |= NES_SW_CONTEXT_ALIGN>>1;
2857                 set_wqe_64bit_value(wqe->wqe_words,
2858                         NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX,
2859                         u64temp);
2860                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
2861                         cpu_to_le32(NES_IWARP_SQ_WQE_STREAMING |
2862                         NES_IWARP_SQ_WQE_WRPDU);
2863                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] =
2864                         cpu_to_le32(conn_param->private_data_len +
2865                         sizeof(struct ietf_mpa_frame));
2866                 set_wqe_64bit_value(wqe->wqe_words,
2867                                         NES_IWARP_SQ_WQE_FRAG0_LOW_IDX,
2868                                         (u64)(unsigned long)nesqp->ietf_frame);
2869                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] =
2870                         cpu_to_le32(conn_param->private_data_len +
2871                         sizeof(struct ietf_mpa_frame));
2872                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = ibmr->lkey;
2873                 if (nesqp->sq_kmapped) {
2874                         nesqp->sq_kmapped = 0;
2875                         kunmap(nesqp->page);
2876                 }
2877
2878                 nesqp->nesqp_context->ird_ord_sizes |=
2879                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
2880                         NES_QPCONTEXT_ORDIRD_WRPDU);
2881         } else {
2882                 nesqp->nesqp_context->ird_ord_sizes |=
2883                         cpu_to_le32(NES_QPCONTEXT_ORDIRD_WRPDU);
2884         }
2885         nesqp->skip_lsmm = 1;
2886
2887
2888         /* Cache the cm_id in the qp */
2889         nesqp->cm_id = cm_id;
2890         cm_node->cm_id = cm_id;
2891
2892         /*  nesqp->cm_node = (void *)cm_id->provider_data; */
2893         cm_id->provider_data = nesqp;
2894         nesqp->active_conn   = 0;
2895
2896         if (cm_node->state == NES_CM_STATE_TSA)
2897                 nes_debug(NES_DBG_CM, "Already state = TSA for cm_node=%p\n",
2898                         cm_node);
2899
2900         nes_cm_init_tsa_conn(nesqp, cm_node);
2901
2902         nesqp->nesqp_context->tcpPorts[0] =
2903                 cpu_to_le16(ntohs(cm_id->local_addr.sin_port));
2904         nesqp->nesqp_context->tcpPorts[1] =
2905                 cpu_to_le16(ntohs(cm_id->remote_addr.sin_port));
2906
2907         if (ipv4_is_loopback(cm_id->remote_addr.sin_addr.s_addr))
2908                 nesqp->nesqp_context->ip0 =
2909                         cpu_to_le32(ntohl(nesvnic->local_ipaddr));
2910         else
2911                 nesqp->nesqp_context->ip0 =
2912                         cpu_to_le32(ntohl(cm_id->remote_addr.sin_addr.s_addr));
2913
2914         nesqp->nesqp_context->misc2 |= cpu_to_le32(
2915                         (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
2916                         NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
2917
2918         nesqp->nesqp_context->arp_index_vlan |=
2919                 cpu_to_le32(nes_arp_table(nesdev,
2920                         le32_to_cpu(nesqp->nesqp_context->ip0), NULL,
2921                         NES_ARP_RESOLVE) << 16);
2922
2923         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
2924                 jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
2925
2926         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
2927
2928         nesqp->nesqp_context->ird_ord_sizes |= cpu_to_le32(
2929                 ((u32)1 << NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT));
2930         nesqp->nesqp_context->ird_ord_sizes |=
2931                 cpu_to_le32((u32)conn_param->ord);
2932
2933         memset(&nes_quad, 0, sizeof(nes_quad));
2934         nes_quad.DstIpAdrIndex =
2935                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
2936         if (ipv4_is_loopback(cm_id->remote_addr.sin_addr.s_addr))
2937                 nes_quad.SrcIpadr = nesvnic->local_ipaddr;
2938         else
2939                 nes_quad.SrcIpadr = cm_id->remote_addr.sin_addr.s_addr;
2940         nes_quad.TcpPorts[0] = cm_id->remote_addr.sin_port;
2941         nes_quad.TcpPorts[1] = cm_id->local_addr.sin_port;
2942
2943         /* Produce hash key */
2944         crc_value = get_crc_value(&nes_quad);
2945         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
2946         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, CRC = 0x%08X\n",
2947                 nesqp->hte_index, nesqp->hte_index & adapter->hte_index_mask);
2948
2949         nesqp->hte_index &= adapter->hte_index_mask;
2950         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
2951
2952         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
2953
2954         nes_debug(NES_DBG_CM, "QP%u, Destination IP = 0x%08X:0x%04X, local = "
2955                         "0x%08X:0x%04X, rcv_nxt=0x%08X, snd_nxt=0x%08X, mpa + "
2956                         "private data length=%zu.\n", nesqp->hwqp.qp_id,
2957                         ntohl(cm_id->remote_addr.sin_addr.s_addr),
2958                         ntohs(cm_id->remote_addr.sin_port),
2959                         ntohl(cm_id->local_addr.sin_addr.s_addr),
2960                         ntohs(cm_id->local_addr.sin_port),
2961                         le32_to_cpu(nesqp->nesqp_context->rcv_nxt),
2962                         le32_to_cpu(nesqp->nesqp_context->snd_nxt),
2963                         conn_param->private_data_len +
2964                         sizeof(struct ietf_mpa_frame));
2965
2966
2967         /* notify OF layer that accept event was successful */
2968         cm_id->add_ref(cm_id);
2969         nes_add_ref(&nesqp->ibqp);
2970
2971         cm_event.event = IW_CM_EVENT_ESTABLISHED;
2972         cm_event.status = IW_CM_EVENT_STATUS_ACCEPTED;
2973         cm_event.provider_data = (void *)nesqp;
2974         cm_event.local_addr = cm_id->local_addr;
2975         cm_event.remote_addr = cm_id->remote_addr;
2976         cm_event.private_data = NULL;
2977         cm_event.private_data_len = 0;
2978         ret = cm_id->event_handler(cm_id, &cm_event);
2979         attr.qp_state = IB_QPS_RTS;
2980         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
2981         if (cm_node->loopbackpartner) {
2982                 cm_node->loopbackpartner->mpa_frame_size =
2983                         nesqp->private_data_len;
2984                 /* copy entire MPA frame to our cm_node's frame */
2985                 memcpy(cm_node->loopbackpartner->mpa_frame_buf,
2986                         nesqp->ietf_frame->priv_data, nesqp->private_data_len);
2987                 create_event(cm_node->loopbackpartner, NES_CM_EVENT_CONNECTED);
2988         }
2989         if (ret)
2990                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
2991                         "ret=%d\n", __func__, __LINE__, ret);
2992
2993         return 0;
2994 }
2995
2996
2997 /**
2998  * nes_reject
2999  */
3000 int nes_reject(struct iw_cm_id *cm_id, const void *pdata, u8 pdata_len)
3001 {
3002         struct nes_cm_node *cm_node;
3003         struct nes_cm_node *loopback;
3004
3005         struct nes_cm_core *cm_core;
3006
3007         atomic_inc(&cm_rejects);
3008         cm_node = (struct nes_cm_node *) cm_id->provider_data;
3009         loopback = cm_node->loopbackpartner;
3010         cm_core = cm_node->cm_core;
3011         cm_node->cm_id = cm_id;
3012         cm_node->mpa_frame_size = sizeof(struct ietf_mpa_frame) + pdata_len;
3013
3014         if (cm_node->mpa_frame_size > MAX_CM_BUFFER)
3015                 return -EINVAL;
3016
3017         memcpy(&cm_node->mpa_frame.key[0], IEFT_MPA_KEY_REP, IETF_MPA_KEY_SIZE);
3018         if (loopback) {
3019                 memcpy(&loopback->mpa_frame.priv_data, pdata, pdata_len);
3020                 loopback->mpa_frame.priv_data_len = pdata_len;
3021                 loopback->mpa_frame_size = sizeof(struct ietf_mpa_frame) +
3022                                 pdata_len;
3023         } else {
3024                 memcpy(&cm_node->mpa_frame.priv_data, pdata, pdata_len);
3025                 cm_node->mpa_frame.priv_data_len = cpu_to_be16(pdata_len);
3026         }
3027
3028         cm_node->mpa_frame.rev = mpa_version;
3029         cm_node->mpa_frame.flags = IETF_MPA_FLAGS_CRC | IETF_MPA_FLAGS_REJECT;
3030
3031         return cm_core->api->reject(cm_core, &cm_node->mpa_frame, cm_node);
3032 }
3033
3034
3035 /**
3036  * nes_connect
3037  * setup and launch cm connect node
3038  */
3039 int nes_connect(struct iw_cm_id *cm_id, struct iw_cm_conn_param *conn_param)
3040 {
3041         struct ib_qp *ibqp;
3042         struct nes_qp *nesqp;
3043         struct nes_vnic *nesvnic;
3044         struct nes_device *nesdev;
3045         struct nes_cm_node *cm_node;
3046         struct nes_cm_info cm_info;
3047         int apbvt_set = 0;
3048
3049         ibqp = nes_get_qp(cm_id->device, conn_param->qpn);
3050         if (!ibqp)
3051                 return -EINVAL;
3052         nesqp = to_nesqp(ibqp);
3053         if (!nesqp)
3054                 return -EINVAL;
3055         nesvnic = to_nesvnic(nesqp->ibqp.device);
3056         if (!nesvnic)
3057                 return -EINVAL;
3058         nesdev  = nesvnic->nesdev;
3059         if (!nesdev)
3060                 return -EINVAL;
3061
3062         if (!(cm_id->local_addr.sin_port) || !(cm_id->remote_addr.sin_port))
3063                 return -EINVAL;
3064
3065         nes_debug(NES_DBG_CM, "QP%u, current IP = 0x%08X, Destination IP = "
3066                 "0x%08X:0x%04X, local = 0x%08X:0x%04X.\n", nesqp->hwqp.qp_id,
3067                 ntohl(nesvnic->local_ipaddr),
3068                 ntohl(cm_id->remote_addr.sin_addr.s_addr),
3069                 ntohs(cm_id->remote_addr.sin_port),
3070                 ntohl(cm_id->local_addr.sin_addr.s_addr),
3071                 ntohs(cm_id->local_addr.sin_port));
3072
3073         atomic_inc(&cm_connects);
3074         nesqp->active_conn = 1;
3075
3076         /* cache the cm_id in the qp */
3077         nesqp->cm_id = cm_id;
3078
3079         cm_id->provider_data = nesqp;
3080
3081         nesqp->private_data_len = conn_param->private_data_len;
3082         nesqp->nesqp_context->ird_ord_sizes |= cpu_to_le32((u32)conn_param->ord);
3083         nes_debug(NES_DBG_CM, "requested ord = 0x%08X.\n", (u32)conn_param->ord);
3084         nes_debug(NES_DBG_CM, "mpa private data len =%u\n",
3085                 conn_param->private_data_len);
3086
3087         if (cm_id->local_addr.sin_addr.s_addr !=
3088                 cm_id->remote_addr.sin_addr.s_addr) {
3089                 nes_manage_apbvt(nesvnic, ntohs(cm_id->local_addr.sin_port),
3090                         PCI_FUNC(nesdev->pcidev->devfn), NES_MANAGE_APBVT_ADD);
3091                 apbvt_set = 1;
3092         }
3093
3094         /* set up the connection params for the node */
3095         cm_info.loc_addr = htonl(cm_id->local_addr.sin_addr.s_addr);
3096         cm_info.loc_port = htons(cm_id->local_addr.sin_port);
3097         cm_info.rem_addr = htonl(cm_id->remote_addr.sin_addr.s_addr);
3098         cm_info.rem_port = htons(cm_id->remote_addr.sin_port);
3099         cm_info.cm_id = cm_id;
3100         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3101
3102         cm_id->add_ref(cm_id);
3103
3104         /* create a connect CM node connection */
3105         cm_node = g_cm_core->api->connect(g_cm_core, nesvnic,
3106                 conn_param->private_data_len, (void *)conn_param->private_data,
3107                 &cm_info);
3108         if (!cm_node) {
3109                 if (apbvt_set)
3110                         nes_manage_apbvt(nesvnic, ntohs(cm_id->local_addr.sin_port),
3111                                 PCI_FUNC(nesdev->pcidev->devfn),
3112                                 NES_MANAGE_APBVT_DEL);
3113
3114                 cm_id->rem_ref(cm_id);
3115                 return -ENOMEM;
3116         }
3117
3118         cm_node->apbvt_set = apbvt_set;
3119         nesqp->cm_node = cm_node;
3120         cm_node->nesqp = nesqp;
3121         nes_add_ref(&nesqp->ibqp);
3122
3123         return 0;
3124 }
3125
3126
3127 /**
3128  * nes_create_listen
3129  */
3130 int nes_create_listen(struct iw_cm_id *cm_id, int backlog)
3131 {
3132         struct nes_vnic *nesvnic;
3133         struct nes_cm_listener *cm_node;
3134         struct nes_cm_info cm_info;
3135         int err;
3136
3137         nes_debug(NES_DBG_CM, "cm_id = %p, local port = 0x%04X.\n",
3138                         cm_id, ntohs(cm_id->local_addr.sin_port));
3139
3140         nesvnic = to_nesvnic(cm_id->device);
3141         if (!nesvnic)
3142                 return -EINVAL;
3143
3144         nes_debug(NES_DBG_CM, "nesvnic=%p, netdev=%p, %s\n",
3145                         nesvnic, nesvnic->netdev, nesvnic->netdev->name);
3146
3147         nes_debug(NES_DBG_CM, "nesvnic->local_ipaddr=0x%08x, sin_addr.s_addr=0x%08x\n",
3148                         nesvnic->local_ipaddr, cm_id->local_addr.sin_addr.s_addr);
3149
3150         /* setup listen params in our api call struct */
3151         cm_info.loc_addr = nesvnic->local_ipaddr;
3152         cm_info.loc_port = cm_id->local_addr.sin_port;
3153         cm_info.backlog = backlog;
3154         cm_info.cm_id = cm_id;
3155
3156         cm_info.conn_type = NES_CM_IWARP_CONN_TYPE;
3157
3158
3159         cm_node = g_cm_core->api->listen(g_cm_core, nesvnic, &cm_info);
3160         if (!cm_node) {
3161                 printk(KERN_ERR "%s[%u] Error returned from listen API call\n",
3162                                 __func__, __LINE__);
3163                 return -ENOMEM;
3164         }
3165
3166         cm_id->provider_data = cm_node;
3167
3168         if (!cm_node->reused_node) {
3169                 err = nes_manage_apbvt(nesvnic,
3170                         ntohs(cm_id->local_addr.sin_port),
3171                         PCI_FUNC(nesvnic->nesdev->pcidev->devfn),
3172                         NES_MANAGE_APBVT_ADD);
3173                 if (err) {
3174                         printk(KERN_ERR "nes_manage_apbvt call returned %d.\n",
3175                                 err);
3176                         g_cm_core->api->stop_listener(g_cm_core, (void *)cm_node);
3177                         return err;
3178                 }
3179                 atomic_inc(&cm_listens_created);
3180         }
3181
3182         cm_id->add_ref(cm_id);
3183         cm_id->provider_data = (void *)cm_node;
3184
3185
3186         return 0;
3187 }
3188
3189
3190 /**
3191  * nes_destroy_listen
3192  */
3193 int nes_destroy_listen(struct iw_cm_id *cm_id)
3194 {
3195         if (cm_id->provider_data)
3196                 g_cm_core->api->stop_listener(g_cm_core, cm_id->provider_data);
3197         else
3198                 nes_debug(NES_DBG_CM, "cm_id->provider_data was NULL\n");
3199
3200         cm_id->rem_ref(cm_id);
3201
3202         return 0;
3203 }
3204
3205
3206 /**
3207  * nes_cm_recv
3208  */
3209 int nes_cm_recv(struct sk_buff *skb, struct net_device *netdevice)
3210 {
3211         int rc = 0;
3212         cm_packets_received++;
3213         if ((g_cm_core) && (g_cm_core->api)) {
3214                 rc = g_cm_core->api->recv_pkt(g_cm_core, netdev_priv(netdevice), skb);
3215         } else {
3216                 nes_debug(NES_DBG_CM, "Unable to process packet for CM,"
3217                                 " cm is not setup properly.\n");
3218         }
3219
3220         return rc;
3221 }
3222
3223
3224 /**
3225  * nes_cm_start
3226  * Start and init a cm core module
3227  */
3228 int nes_cm_start(void)
3229 {
3230         nes_debug(NES_DBG_CM, "\n");
3231         /* create the primary CM core, pass this handle to subsequent core inits */
3232         g_cm_core = nes_cm_alloc_core();
3233         if (g_cm_core) {
3234                 return 0;
3235         } else {
3236                 return -ENOMEM;
3237         }
3238 }
3239
3240
3241 /**
3242  * nes_cm_stop
3243  * stop and dealloc all cm core instances
3244  */
3245 int nes_cm_stop(void)
3246 {
3247         g_cm_core->api->destroy_cm_core(g_cm_core);
3248         return 0;
3249 }
3250
3251
3252 /**
3253  * cm_event_connected
3254  * handle a connected event, setup QPs and HW
3255  */
3256 static void cm_event_connected(struct nes_cm_event *event)
3257 {
3258         u64 u64temp;
3259         struct nes_qp *nesqp;
3260         struct nes_vnic *nesvnic;
3261         struct nes_device *nesdev;
3262         struct nes_cm_node *cm_node;
3263         struct nes_adapter *nesadapter;
3264         struct ib_qp_attr attr;
3265         struct iw_cm_id *cm_id;
3266         struct iw_cm_event cm_event;
3267         struct nes_hw_qp_wqe *wqe;
3268         struct nes_v4_quad nes_quad;
3269         u32 crc_value;
3270         int ret;
3271
3272         /* get all our handles */
3273         cm_node = event->cm_node;
3274         cm_id = cm_node->cm_id;
3275         nes_debug(NES_DBG_CM, "cm_event_connected - %p - cm_id = %p\n", cm_node, cm_id);
3276         nesqp = (struct nes_qp *)cm_id->provider_data;
3277         nesvnic = to_nesvnic(nesqp->ibqp.device);
3278         nesdev = nesvnic->nesdev;
3279         nesadapter = nesdev->nesadapter;
3280
3281         if (nesqp->destroyed) {
3282                 return;
3283         }
3284         atomic_inc(&cm_connecteds);
3285         nes_debug(NES_DBG_CM, "QP%u attempting to connect to  0x%08X:0x%04X on"
3286                         " local port 0x%04X. jiffies = %lu.\n",
3287                         nesqp->hwqp.qp_id,
3288                         ntohl(cm_id->remote_addr.sin_addr.s_addr),
3289                         ntohs(cm_id->remote_addr.sin_port),
3290                         ntohs(cm_id->local_addr.sin_port),
3291                         jiffies);
3292
3293         nes_cm_init_tsa_conn(nesqp, cm_node);
3294
3295         /* set the QP tsa context */
3296         nesqp->nesqp_context->tcpPorts[0] =
3297                 cpu_to_le16(ntohs(cm_id->local_addr.sin_port));
3298         nesqp->nesqp_context->tcpPorts[1] =
3299                 cpu_to_le16(ntohs(cm_id->remote_addr.sin_port));
3300         if (ipv4_is_loopback(cm_id->remote_addr.sin_addr.s_addr))
3301                 nesqp->nesqp_context->ip0 =
3302                         cpu_to_le32(ntohl(nesvnic->local_ipaddr));
3303         else
3304                 nesqp->nesqp_context->ip0 =
3305                         cpu_to_le32(ntohl(cm_id->remote_addr.sin_addr.s_addr));
3306
3307         nesqp->nesqp_context->misc2 |= cpu_to_le32(
3308                         (u32)PCI_FUNC(nesdev->pcidev->devfn) <<
3309                         NES_QPCONTEXT_MISC2_SRC_IP_SHIFT);
3310         nesqp->nesqp_context->arp_index_vlan |= cpu_to_le32(
3311                         nes_arp_table(nesdev,
3312                         le32_to_cpu(nesqp->nesqp_context->ip0),
3313                         NULL, NES_ARP_RESOLVE) << 16);
3314         nesqp->nesqp_context->ts_val_delta = cpu_to_le32(
3315                         jiffies - nes_read_indexed(nesdev, NES_IDX_TCP_NOW));
3316         nesqp->nesqp_context->ird_index = cpu_to_le32(nesqp->hwqp.qp_id);
3317         nesqp->nesqp_context->ird_ord_sizes |=
3318                         cpu_to_le32((u32)1 <<
3319                         NES_QPCONTEXT_ORDIRD_IWARP_MODE_SHIFT);
3320
3321         /* Adjust tail for not having a LSMM */
3322         nesqp->hwqp.sq_tail = 1;
3323
3324 #if defined(NES_SEND_FIRST_WRITE)
3325         if (cm_node->send_write0) {
3326                 nes_debug(NES_DBG_CM, "Sending first write.\n");
3327                 wqe = &nesqp->hwqp.sq_vbase[0];
3328                 u64temp = (unsigned long)nesqp;
3329                 u64temp |= NES_SW_CONTEXT_ALIGN>>1;
3330                 set_wqe_64bit_value(wqe->wqe_words,
3331                                 NES_IWARP_SQ_WQE_COMP_CTX_LOW_IDX, u64temp);
3332                 wqe->wqe_words[NES_IWARP_SQ_WQE_MISC_IDX] =
3333                         cpu_to_le32(NES_IWARP_SQ_OP_RDMAW);
3334                 wqe->wqe_words[NES_IWARP_SQ_WQE_TOTAL_PAYLOAD_IDX] = 0;
3335                 wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_LOW_IDX] = 0;
3336                 wqe->wqe_words[NES_IWARP_SQ_WQE_FRAG0_HIGH_IDX] = 0;
3337                 wqe->wqe_words[NES_IWARP_SQ_WQE_LENGTH0_IDX] = 0;
3338                 wqe->wqe_words[NES_IWARP_SQ_WQE_STAG0_IDX] = 0;
3339
3340                 if (nesqp->sq_kmapped) {
3341                         nesqp->sq_kmapped = 0;
3342                         kunmap(nesqp->page);
3343                 }
3344
3345                 /* use the reserved spot on the WQ for the extra first WQE */
3346                 nesqp->nesqp_context->ird_ord_sizes &=
3347                         cpu_to_le32(~(NES_QPCONTEXT_ORDIRD_LSMM_PRESENT |
3348                                                 NES_QPCONTEXT_ORDIRD_WRPDU |
3349                                                 NES_QPCONTEXT_ORDIRD_ALSMM));
3350                 nesqp->skip_lsmm = 1;
3351                 nesqp->hwqp.sq_tail = 0;
3352                 nes_write32(nesdev->regs + NES_WQE_ALLOC,
3353                                 (1 << 24) | 0x00800000 | nesqp->hwqp.qp_id);
3354         }
3355 #endif
3356
3357         memset(&nes_quad, 0, sizeof(nes_quad));
3358
3359         nes_quad.DstIpAdrIndex =
3360                 cpu_to_le32((u32)PCI_FUNC(nesdev->pcidev->devfn) << 24);
3361         if (ipv4_is_loopback(cm_id->remote_addr.sin_addr.s_addr))
3362                 nes_quad.SrcIpadr = nesvnic->local_ipaddr;
3363         else
3364                 nes_quad.SrcIpadr = cm_id->remote_addr.sin_addr.s_addr;
3365         nes_quad.TcpPorts[0] = cm_id->remote_addr.sin_port;
3366         nes_quad.TcpPorts[1] = cm_id->local_addr.sin_port;
3367
3368         /* Produce hash key */
3369         crc_value = get_crc_value(&nes_quad);
3370         nesqp->hte_index = cpu_to_be32(crc_value ^ 0xffffffff);
3371         nes_debug(NES_DBG_CM, "HTE Index = 0x%08X, After CRC = 0x%08X\n",
3372                         nesqp->hte_index, nesqp->hte_index & nesadapter->hte_index_mask);
3373
3374         nesqp->hte_index &= nesadapter->hte_index_mask;
3375         nesqp->nesqp_context->hte_index = cpu_to_le32(nesqp->hte_index);
3376
3377         nesqp->ietf_frame = &cm_node->mpa_frame;
3378         nesqp->private_data_len = (u8) cm_node->mpa_frame_size;
3379         cm_node->cm_core->api->accelerated(cm_node->cm_core, cm_node);
3380
3381         /* notify OF layer we successfully created the requested connection */
3382         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3383         cm_event.status = IW_CM_EVENT_STATUS_ACCEPTED;
3384         cm_event.provider_data = cm_id->provider_data;
3385         cm_event.local_addr.sin_family = AF_INET;
3386         cm_event.local_addr.sin_port = cm_id->local_addr.sin_port;
3387         cm_event.remote_addr = cm_id->remote_addr;
3388
3389         cm_event.private_data = (void *)event->cm_node->mpa_frame_buf;
3390         cm_event.private_data_len = (u8) event->cm_node->mpa_frame_size;
3391
3392         cm_event.local_addr.sin_addr.s_addr = event->cm_info.rem_addr;
3393         ret = cm_id->event_handler(cm_id, &cm_event);
3394         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3395
3396         if (ret)
3397                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3398                         "ret=%d\n", __func__, __LINE__, ret);
3399         attr.qp_state = IB_QPS_RTS;
3400         nes_modify_qp(&nesqp->ibqp, &attr, IB_QP_STATE, NULL);
3401
3402         nes_debug(NES_DBG_CM, "Exiting connect thread for QP%u. jiffies = "
3403                 "%lu\n", nesqp->hwqp.qp_id, jiffies);
3404
3405         return;
3406 }
3407
3408
3409 /**
3410  * cm_event_connect_error
3411  */
3412 static void cm_event_connect_error(struct nes_cm_event *event)
3413 {
3414         struct nes_qp *nesqp;
3415         struct iw_cm_id *cm_id;
3416         struct iw_cm_event cm_event;
3417         /* struct nes_cm_info cm_info; */
3418         int ret;
3419
3420         if (!event->cm_node)
3421                 return;
3422
3423         cm_id = event->cm_node->cm_id;
3424         if (!cm_id) {
3425                 return;
3426         }
3427
3428         nes_debug(NES_DBG_CM, "cm_node=%p, cm_id=%p\n", event->cm_node, cm_id);
3429         nesqp = cm_id->provider_data;
3430
3431         if (!nesqp) {
3432                 return;
3433         }
3434
3435         /* notify OF layer about this connection error event */
3436         /* cm_id->rem_ref(cm_id); */
3437         nesqp->cm_id = NULL;
3438         cm_id->provider_data = NULL;
3439         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3440         cm_event.status = -ECONNRESET;
3441         cm_event.provider_data = cm_id->provider_data;
3442         cm_event.local_addr = cm_id->local_addr;
3443         cm_event.remote_addr = cm_id->remote_addr;
3444         cm_event.private_data = NULL;
3445         cm_event.private_data_len = 0;
3446
3447         nes_debug(NES_DBG_CM, "call CM_EVENT REJECTED, local_addr=%08x, "
3448                 "remove_addr=%08x\n", cm_event.local_addr.sin_addr.s_addr,
3449                 cm_event.remote_addr.sin_addr.s_addr);
3450
3451         ret = cm_id->event_handler(cm_id, &cm_event);
3452         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3453         if (ret)
3454                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, "
3455                         "ret=%d\n", __func__, __LINE__, ret);
3456         cm_id->rem_ref(cm_id);
3457
3458         rem_ref_cm_node(event->cm_node->cm_core, event->cm_node);
3459         return;
3460 }
3461
3462
3463 /**
3464  * cm_event_reset
3465  */
3466 static void cm_event_reset(struct nes_cm_event *event)
3467 {
3468         struct nes_qp *nesqp;
3469         struct iw_cm_id *cm_id;
3470         struct iw_cm_event cm_event;
3471         /* struct nes_cm_info cm_info; */
3472         int ret;
3473
3474         if (!event->cm_node)
3475                 return;
3476
3477         if (!event->cm_node->cm_id)
3478                 return;
3479
3480         cm_id = event->cm_node->cm_id;
3481
3482         nes_debug(NES_DBG_CM, "%p - cm_id = %p\n", event->cm_node, cm_id);
3483         nesqp = cm_id->provider_data;
3484         if (!nesqp)
3485                 return;
3486
3487         nesqp->cm_id = NULL;
3488         /* cm_id->provider_data = NULL; */
3489         cm_event.event = IW_CM_EVENT_DISCONNECT;
3490         cm_event.status = IW_CM_EVENT_STATUS_RESET;
3491         cm_event.provider_data = cm_id->provider_data;
3492         cm_event.local_addr = cm_id->local_addr;
3493         cm_event.remote_addr = cm_id->remote_addr;
3494         cm_event.private_data = NULL;
3495         cm_event.private_data_len = 0;
3496
3497         cm_id->add_ref(cm_id);
3498         ret = cm_id->event_handler(cm_id, &cm_event);
3499         atomic_inc(&cm_closes);
3500         cm_event.event = IW_CM_EVENT_CLOSE;
3501         cm_event.status = IW_CM_EVENT_STATUS_OK;
3502         cm_event.provider_data = cm_id->provider_data;
3503         cm_event.local_addr = cm_id->local_addr;
3504         cm_event.remote_addr = cm_id->remote_addr;
3505         cm_event.private_data = NULL;
3506         cm_event.private_data_len = 0;
3507         nes_debug(NES_DBG_CM, "NODE %p Generating CLOSE\n", event->cm_node);
3508         ret = cm_id->event_handler(cm_id, &cm_event);
3509
3510         nes_debug(NES_DBG_CM, "OFA CM event_handler returned, ret=%d\n", ret);
3511
3512
3513         /* notify OF layer about this connection error event */
3514         cm_id->rem_ref(cm_id);
3515
3516         return;
3517 }
3518
3519
3520 /**
3521  * cm_event_mpa_req
3522  */
3523 static void cm_event_mpa_req(struct nes_cm_event *event)
3524 {
3525         struct iw_cm_id   *cm_id;
3526         struct iw_cm_event cm_event;
3527         int ret;
3528         struct nes_cm_node *cm_node;
3529
3530         cm_node = event->cm_node;
3531         if (!cm_node)
3532                 return;
3533         cm_id = cm_node->cm_id;
3534
3535         atomic_inc(&cm_connect_reqs);
3536         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3537                         cm_node, cm_id, jiffies);
3538
3539         cm_event.event = IW_CM_EVENT_CONNECT_REQUEST;
3540         cm_event.status = IW_CM_EVENT_STATUS_OK;
3541         cm_event.provider_data = (void *)cm_node;
3542
3543         cm_event.local_addr.sin_family = AF_INET;
3544         cm_event.local_addr.sin_port = htons(event->cm_info.loc_port);
3545         cm_event.local_addr.sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3546
3547         cm_event.remote_addr.sin_family = AF_INET;
3548         cm_event.remote_addr.sin_port = htons(event->cm_info.rem_port);
3549         cm_event.remote_addr.sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3550         cm_event.private_data = cm_node->mpa_frame_buf;
3551         cm_event.private_data_len  = (u8) cm_node->mpa_frame_size;
3552
3553         ret = cm_id->event_handler(cm_id, &cm_event);
3554         if (ret)
3555                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3556                                 __func__, __LINE__, ret);
3557         return;
3558 }
3559
3560
3561 static void cm_event_mpa_reject(struct nes_cm_event *event)
3562 {
3563         struct iw_cm_id   *cm_id;
3564         struct iw_cm_event cm_event;
3565         struct nes_cm_node *cm_node;
3566         int ret;
3567
3568         cm_node = event->cm_node;
3569         if (!cm_node)
3570                 return;
3571         cm_id = cm_node->cm_id;
3572
3573         atomic_inc(&cm_connect_reqs);
3574         nes_debug(NES_DBG_CM, "cm_node = %p - cm_id = %p, jiffies = %lu\n",
3575                         cm_node, cm_id, jiffies);
3576
3577         cm_event.event = IW_CM_EVENT_CONNECT_REPLY;
3578         cm_event.status = -ECONNREFUSED;
3579         cm_event.provider_data = cm_id->provider_data;
3580
3581         cm_event.local_addr.sin_family = AF_INET;
3582         cm_event.local_addr.sin_port = htons(event->cm_info.loc_port);
3583         cm_event.local_addr.sin_addr.s_addr = htonl(event->cm_info.loc_addr);
3584
3585         cm_event.remote_addr.sin_family = AF_INET;
3586         cm_event.remote_addr.sin_port = htons(event->cm_info.rem_port);
3587         cm_event.remote_addr.sin_addr.s_addr = htonl(event->cm_info.rem_addr);
3588
3589         cm_event.private_data = cm_node->mpa_frame_buf;
3590         cm_event.private_data_len = (u8) cm_node->mpa_frame_size;
3591
3592         nes_debug(NES_DBG_CM, "call CM_EVENT_MPA_REJECTED, local_addr=%08x, "
3593                         "remove_addr=%08x\n",
3594                         cm_event.local_addr.sin_addr.s_addr,
3595                         cm_event.remote_addr.sin_addr.s_addr);
3596
3597         ret = cm_id->event_handler(cm_id, &cm_event);
3598         if (ret)
3599                 printk(KERN_ERR "%s[%u] OFA CM event_handler returned, ret=%d\n",
3600                                 __func__, __LINE__, ret);
3601
3602         return;
3603 }
3604
3605
3606 static void nes_cm_event_handler(struct work_struct *);
3607
3608 /**
3609  * nes_cm_post_event
3610  * post an event to the cm event handler
3611  */
3612 static int nes_cm_post_event(struct nes_cm_event *event)
3613 {
3614         atomic_inc(&event->cm_node->cm_core->events_posted);
3615         add_ref_cm_node(event->cm_node);
3616         event->cm_info.cm_id->add_ref(event->cm_info.cm_id);
3617         INIT_WORK(&event->event_work, nes_cm_event_handler);
3618         nes_debug(NES_DBG_CM, "cm_node=%p queue_work, event=%p\n",
3619                 event->cm_node, event);
3620
3621         queue_work(event->cm_node->cm_core->event_wq, &event->event_work);
3622
3623         nes_debug(NES_DBG_CM, "Exit\n");
3624         return 0;
3625 }
3626
3627
3628 /**
3629  * nes_cm_event_handler
3630  * worker function to handle cm events
3631  * will free instance of nes_cm_event
3632  */
3633 static void nes_cm_event_handler(struct work_struct *work)
3634 {
3635         struct nes_cm_event *event = container_of(work, struct nes_cm_event,
3636                         event_work);
3637         struct nes_cm_core *cm_core;
3638
3639         if ((!event) || (!event->cm_node) || (!event->cm_node->cm_core))
3640                 return;
3641
3642         cm_core = event->cm_node->cm_core;
3643         nes_debug(NES_DBG_CM, "event=%p, event->type=%u, events posted=%u\n",
3644                 event, event->type, atomic_read(&cm_core->events_posted));
3645
3646         switch (event->type) {
3647         case NES_CM_EVENT_MPA_REQ:
3648                 cm_event_mpa_req(event);
3649                 nes_debug(NES_DBG_CM, "cm_node=%p CM Event: MPA REQUEST\n",
3650                         event->cm_node);
3651                 break;
3652         case NES_CM_EVENT_RESET:
3653                 nes_debug(NES_DBG_CM, "cm_node = %p CM Event: RESET\n",
3654                         event->cm_node);
3655                 cm_event_reset(event);
3656                 break;
3657         case NES_CM_EVENT_CONNECTED:
3658                 if ((!event->cm_node->cm_id) ||
3659                         (event->cm_node->state != NES_CM_STATE_TSA))
3660                         break;
3661                 cm_event_connected(event);
3662                 nes_debug(NES_DBG_CM, "CM Event: CONNECTED\n");
3663                 break;
3664         case NES_CM_EVENT_MPA_REJECT:
3665                 if ((!event->cm_node->cm_id) ||
3666                                 (event->cm_node->state == NES_CM_STATE_TSA))
3667                         break;
3668                 cm_event_mpa_reject(event);
3669                 nes_debug(NES_DBG_CM, "CM Event: REJECT\n");
3670                 break;
3671
3672         case NES_CM_EVENT_ABORTED:
3673                 if ((!event->cm_node->cm_id) ||
3674                         (event->cm_node->state == NES_CM_STATE_TSA))
3675                         break;
3676                 cm_event_connect_error(event);
3677                 nes_debug(NES_DBG_CM, "CM Event: ABORTED\n");
3678                 break;
3679         case NES_CM_EVENT_DROPPED_PKT:
3680                 nes_debug(NES_DBG_CM, "CM Event: DROPPED PKT\n");
3681                 break;
3682         default:
3683                 nes_debug(NES_DBG_CM, "CM Event: UNKNOWN EVENT TYPE\n");
3684                 break;
3685         }
3686
3687         atomic_dec(&cm_core->events_posted);
3688         event->cm_info.cm_id->rem_ref(event->cm_info.cm_id);
3689         rem_ref_cm_node(cm_core, event->cm_node);
3690         kfree(event);
3691
3692         return;
3693 }