IB/uverbs: Fix race between uverbs_close and remove_one
[cascardo/linux.git] / drivers / infiniband / core / uverbs_main.c
1 /*
2  * Copyright (c) 2005 Topspin Communications.  All rights reserved.
3  * Copyright (c) 2005, 2006 Cisco Systems.  All rights reserved.
4  * Copyright (c) 2005 Mellanox Technologies. All rights reserved.
5  * Copyright (c) 2005 Voltaire, Inc. All rights reserved.
6  * Copyright (c) 2005 PathScale, Inc. All rights reserved.
7  *
8  * This software is available to you under a choice of one of two
9  * licenses.  You may choose to be licensed under the terms of the GNU
10  * General Public License (GPL) Version 2, available from the file
11  * COPYING in the main directory of this source tree, or the
12  * OpenIB.org BSD license below:
13  *
14  *     Redistribution and use in source and binary forms, with or
15  *     without modification, are permitted provided that the following
16  *     conditions are met:
17  *
18  *      - Redistributions of source code must retain the above
19  *        copyright notice, this list of conditions and the following
20  *        disclaimer.
21  *
22  *      - Redistributions in binary form must reproduce the above
23  *        copyright notice, this list of conditions and the following
24  *        disclaimer in the documentation and/or other materials
25  *        provided with the distribution.
26  *
27  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
28  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
29  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
30  * NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
31  * BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
32  * ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
33  * CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
34  * SOFTWARE.
35  */
36
37 #include <linux/module.h>
38 #include <linux/init.h>
39 #include <linux/device.h>
40 #include <linux/err.h>
41 #include <linux/fs.h>
42 #include <linux/poll.h>
43 #include <linux/sched.h>
44 #include <linux/file.h>
45 #include <linux/cdev.h>
46 #include <linux/anon_inodes.h>
47 #include <linux/slab.h>
48
49 #include <asm/uaccess.h>
50
51 #include <rdma/ib.h>
52
53 #include "uverbs.h"
54
55 MODULE_AUTHOR("Roland Dreier");
56 MODULE_DESCRIPTION("InfiniBand userspace verbs access");
57 MODULE_LICENSE("Dual BSD/GPL");
58
59 enum {
60         IB_UVERBS_MAJOR       = 231,
61         IB_UVERBS_BASE_MINOR  = 192,
62         IB_UVERBS_MAX_DEVICES = 32
63 };
64
65 #define IB_UVERBS_BASE_DEV      MKDEV(IB_UVERBS_MAJOR, IB_UVERBS_BASE_MINOR)
66
67 static struct class *uverbs_class;
68
69 DEFINE_SPINLOCK(ib_uverbs_idr_lock);
70 DEFINE_IDR(ib_uverbs_pd_idr);
71 DEFINE_IDR(ib_uverbs_mr_idr);
72 DEFINE_IDR(ib_uverbs_mw_idr);
73 DEFINE_IDR(ib_uverbs_ah_idr);
74 DEFINE_IDR(ib_uverbs_cq_idr);
75 DEFINE_IDR(ib_uverbs_qp_idr);
76 DEFINE_IDR(ib_uverbs_srq_idr);
77 DEFINE_IDR(ib_uverbs_xrcd_idr);
78 DEFINE_IDR(ib_uverbs_rule_idr);
79
80 static DEFINE_SPINLOCK(map_lock);
81 static DECLARE_BITMAP(dev_map, IB_UVERBS_MAX_DEVICES);
82
83 static ssize_t (*uverbs_cmd_table[])(struct ib_uverbs_file *file,
84                                      struct ib_device *ib_dev,
85                                      const char __user *buf, int in_len,
86                                      int out_len) = {
87         [IB_USER_VERBS_CMD_GET_CONTEXT]         = ib_uverbs_get_context,
88         [IB_USER_VERBS_CMD_QUERY_DEVICE]        = ib_uverbs_query_device,
89         [IB_USER_VERBS_CMD_QUERY_PORT]          = ib_uverbs_query_port,
90         [IB_USER_VERBS_CMD_ALLOC_PD]            = ib_uverbs_alloc_pd,
91         [IB_USER_VERBS_CMD_DEALLOC_PD]          = ib_uverbs_dealloc_pd,
92         [IB_USER_VERBS_CMD_REG_MR]              = ib_uverbs_reg_mr,
93         [IB_USER_VERBS_CMD_REREG_MR]            = ib_uverbs_rereg_mr,
94         [IB_USER_VERBS_CMD_DEREG_MR]            = ib_uverbs_dereg_mr,
95         [IB_USER_VERBS_CMD_ALLOC_MW]            = ib_uverbs_alloc_mw,
96         [IB_USER_VERBS_CMD_DEALLOC_MW]          = ib_uverbs_dealloc_mw,
97         [IB_USER_VERBS_CMD_CREATE_COMP_CHANNEL] = ib_uverbs_create_comp_channel,
98         [IB_USER_VERBS_CMD_CREATE_CQ]           = ib_uverbs_create_cq,
99         [IB_USER_VERBS_CMD_RESIZE_CQ]           = ib_uverbs_resize_cq,
100         [IB_USER_VERBS_CMD_POLL_CQ]             = ib_uverbs_poll_cq,
101         [IB_USER_VERBS_CMD_REQ_NOTIFY_CQ]       = ib_uverbs_req_notify_cq,
102         [IB_USER_VERBS_CMD_DESTROY_CQ]          = ib_uverbs_destroy_cq,
103         [IB_USER_VERBS_CMD_CREATE_QP]           = ib_uverbs_create_qp,
104         [IB_USER_VERBS_CMD_QUERY_QP]            = ib_uverbs_query_qp,
105         [IB_USER_VERBS_CMD_MODIFY_QP]           = ib_uverbs_modify_qp,
106         [IB_USER_VERBS_CMD_DESTROY_QP]          = ib_uverbs_destroy_qp,
107         [IB_USER_VERBS_CMD_POST_SEND]           = ib_uverbs_post_send,
108         [IB_USER_VERBS_CMD_POST_RECV]           = ib_uverbs_post_recv,
109         [IB_USER_VERBS_CMD_POST_SRQ_RECV]       = ib_uverbs_post_srq_recv,
110         [IB_USER_VERBS_CMD_CREATE_AH]           = ib_uverbs_create_ah,
111         [IB_USER_VERBS_CMD_DESTROY_AH]          = ib_uverbs_destroy_ah,
112         [IB_USER_VERBS_CMD_ATTACH_MCAST]        = ib_uverbs_attach_mcast,
113         [IB_USER_VERBS_CMD_DETACH_MCAST]        = ib_uverbs_detach_mcast,
114         [IB_USER_VERBS_CMD_CREATE_SRQ]          = ib_uverbs_create_srq,
115         [IB_USER_VERBS_CMD_MODIFY_SRQ]          = ib_uverbs_modify_srq,
116         [IB_USER_VERBS_CMD_QUERY_SRQ]           = ib_uverbs_query_srq,
117         [IB_USER_VERBS_CMD_DESTROY_SRQ]         = ib_uverbs_destroy_srq,
118         [IB_USER_VERBS_CMD_OPEN_XRCD]           = ib_uverbs_open_xrcd,
119         [IB_USER_VERBS_CMD_CLOSE_XRCD]          = ib_uverbs_close_xrcd,
120         [IB_USER_VERBS_CMD_CREATE_XSRQ]         = ib_uverbs_create_xsrq,
121         [IB_USER_VERBS_CMD_OPEN_QP]             = ib_uverbs_open_qp,
122 };
123
124 static int (*uverbs_ex_cmd_table[])(struct ib_uverbs_file *file,
125                                     struct ib_device *ib_dev,
126                                     struct ib_udata *ucore,
127                                     struct ib_udata *uhw) = {
128         [IB_USER_VERBS_EX_CMD_CREATE_FLOW]      = ib_uverbs_ex_create_flow,
129         [IB_USER_VERBS_EX_CMD_DESTROY_FLOW]     = ib_uverbs_ex_destroy_flow,
130         [IB_USER_VERBS_EX_CMD_QUERY_DEVICE]     = ib_uverbs_ex_query_device,
131         [IB_USER_VERBS_EX_CMD_CREATE_CQ]        = ib_uverbs_ex_create_cq,
132         [IB_USER_VERBS_EX_CMD_CREATE_QP]        = ib_uverbs_ex_create_qp,
133 };
134
135 static void ib_uverbs_add_one(struct ib_device *device);
136 static void ib_uverbs_remove_one(struct ib_device *device, void *client_data);
137
138 int uverbs_dealloc_mw(struct ib_mw *mw)
139 {
140         struct ib_pd *pd = mw->pd;
141         int ret;
142
143         ret = mw->device->dealloc_mw(mw);
144         if (!ret)
145                 atomic_dec(&pd->usecnt);
146         return ret;
147 }
148
149 static void ib_uverbs_release_dev(struct kobject *kobj)
150 {
151         struct ib_uverbs_device *dev =
152                 container_of(kobj, struct ib_uverbs_device, kobj);
153
154         cleanup_srcu_struct(&dev->disassociate_srcu);
155         kfree(dev);
156 }
157
158 static struct kobj_type ib_uverbs_dev_ktype = {
159         .release = ib_uverbs_release_dev,
160 };
161
162 static void ib_uverbs_release_event_file(struct kref *ref)
163 {
164         struct ib_uverbs_event_file *file =
165                 container_of(ref, struct ib_uverbs_event_file, ref);
166
167         kfree(file);
168 }
169
170 void ib_uverbs_release_ucq(struct ib_uverbs_file *file,
171                           struct ib_uverbs_event_file *ev_file,
172                           struct ib_ucq_object *uobj)
173 {
174         struct ib_uverbs_event *evt, *tmp;
175
176         if (ev_file) {
177                 spin_lock_irq(&ev_file->lock);
178                 list_for_each_entry_safe(evt, tmp, &uobj->comp_list, obj_list) {
179                         list_del(&evt->list);
180                         kfree(evt);
181                 }
182                 spin_unlock_irq(&ev_file->lock);
183
184                 kref_put(&ev_file->ref, ib_uverbs_release_event_file);
185         }
186
187         spin_lock_irq(&file->async_file->lock);
188         list_for_each_entry_safe(evt, tmp, &uobj->async_list, obj_list) {
189                 list_del(&evt->list);
190                 kfree(evt);
191         }
192         spin_unlock_irq(&file->async_file->lock);
193 }
194
195 void ib_uverbs_release_uevent(struct ib_uverbs_file *file,
196                               struct ib_uevent_object *uobj)
197 {
198         struct ib_uverbs_event *evt, *tmp;
199
200         spin_lock_irq(&file->async_file->lock);
201         list_for_each_entry_safe(evt, tmp, &uobj->event_list, obj_list) {
202                 list_del(&evt->list);
203                 kfree(evt);
204         }
205         spin_unlock_irq(&file->async_file->lock);
206 }
207
208 static void ib_uverbs_detach_umcast(struct ib_qp *qp,
209                                     struct ib_uqp_object *uobj)
210 {
211         struct ib_uverbs_mcast_entry *mcast, *tmp;
212
213         list_for_each_entry_safe(mcast, tmp, &uobj->mcast_list, list) {
214                 ib_detach_mcast(qp, &mcast->gid, mcast->lid);
215                 list_del(&mcast->list);
216                 kfree(mcast);
217         }
218 }
219
220 static int ib_uverbs_cleanup_ucontext(struct ib_uverbs_file *file,
221                                       struct ib_ucontext *context)
222 {
223         struct ib_uobject *uobj, *tmp;
224
225         context->closing = 1;
226
227         list_for_each_entry_safe(uobj, tmp, &context->ah_list, list) {
228                 struct ib_ah *ah = uobj->object;
229
230                 idr_remove_uobj(&ib_uverbs_ah_idr, uobj);
231                 ib_destroy_ah(ah);
232                 kfree(uobj);
233         }
234
235         /* Remove MWs before QPs, in order to support type 2A MWs. */
236         list_for_each_entry_safe(uobj, tmp, &context->mw_list, list) {
237                 struct ib_mw *mw = uobj->object;
238
239                 idr_remove_uobj(&ib_uverbs_mw_idr, uobj);
240                 uverbs_dealloc_mw(mw);
241                 kfree(uobj);
242         }
243
244         list_for_each_entry_safe(uobj, tmp, &context->rule_list, list) {
245                 struct ib_flow *flow_id = uobj->object;
246
247                 idr_remove_uobj(&ib_uverbs_rule_idr, uobj);
248                 ib_destroy_flow(flow_id);
249                 kfree(uobj);
250         }
251
252         list_for_each_entry_safe(uobj, tmp, &context->qp_list, list) {
253                 struct ib_qp *qp = uobj->object;
254                 struct ib_uqp_object *uqp =
255                         container_of(uobj, struct ib_uqp_object, uevent.uobject);
256
257                 idr_remove_uobj(&ib_uverbs_qp_idr, uobj);
258                 if (qp != qp->real_qp) {
259                         ib_close_qp(qp);
260                 } else {
261                         ib_uverbs_detach_umcast(qp, uqp);
262                         ib_destroy_qp(qp);
263                 }
264                 ib_uverbs_release_uevent(file, &uqp->uevent);
265                 kfree(uqp);
266         }
267
268         list_for_each_entry_safe(uobj, tmp, &context->srq_list, list) {
269                 struct ib_srq *srq = uobj->object;
270                 struct ib_uevent_object *uevent =
271                         container_of(uobj, struct ib_uevent_object, uobject);
272
273                 idr_remove_uobj(&ib_uverbs_srq_idr, uobj);
274                 ib_destroy_srq(srq);
275                 ib_uverbs_release_uevent(file, uevent);
276                 kfree(uevent);
277         }
278
279         list_for_each_entry_safe(uobj, tmp, &context->cq_list, list) {
280                 struct ib_cq *cq = uobj->object;
281                 struct ib_uverbs_event_file *ev_file = cq->cq_context;
282                 struct ib_ucq_object *ucq =
283                         container_of(uobj, struct ib_ucq_object, uobject);
284
285                 idr_remove_uobj(&ib_uverbs_cq_idr, uobj);
286                 ib_destroy_cq(cq);
287                 ib_uverbs_release_ucq(file, ev_file, ucq);
288                 kfree(ucq);
289         }
290
291         list_for_each_entry_safe(uobj, tmp, &context->mr_list, list) {
292                 struct ib_mr *mr = uobj->object;
293
294                 idr_remove_uobj(&ib_uverbs_mr_idr, uobj);
295                 ib_dereg_mr(mr);
296                 kfree(uobj);
297         }
298
299         mutex_lock(&file->device->xrcd_tree_mutex);
300         list_for_each_entry_safe(uobj, tmp, &context->xrcd_list, list) {
301                 struct ib_xrcd *xrcd = uobj->object;
302                 struct ib_uxrcd_object *uxrcd =
303                         container_of(uobj, struct ib_uxrcd_object, uobject);
304
305                 idr_remove_uobj(&ib_uverbs_xrcd_idr, uobj);
306                 ib_uverbs_dealloc_xrcd(file->device, xrcd);
307                 kfree(uxrcd);
308         }
309         mutex_unlock(&file->device->xrcd_tree_mutex);
310
311         list_for_each_entry_safe(uobj, tmp, &context->pd_list, list) {
312                 struct ib_pd *pd = uobj->object;
313
314                 idr_remove_uobj(&ib_uverbs_pd_idr, uobj);
315                 ib_dealloc_pd(pd);
316                 kfree(uobj);
317         }
318
319         put_pid(context->tgid);
320
321         return context->device->dealloc_ucontext(context);
322 }
323
324 static void ib_uverbs_comp_dev(struct ib_uverbs_device *dev)
325 {
326         complete(&dev->comp);
327 }
328
329 static void ib_uverbs_release_file(struct kref *ref)
330 {
331         struct ib_uverbs_file *file =
332                 container_of(ref, struct ib_uverbs_file, ref);
333         struct ib_device *ib_dev;
334         int srcu_key;
335
336         srcu_key = srcu_read_lock(&file->device->disassociate_srcu);
337         ib_dev = srcu_dereference(file->device->ib_dev,
338                                   &file->device->disassociate_srcu);
339         if (ib_dev && !ib_dev->disassociate_ucontext)
340                 module_put(ib_dev->owner);
341         srcu_read_unlock(&file->device->disassociate_srcu, srcu_key);
342
343         if (atomic_dec_and_test(&file->device->refcount))
344                 ib_uverbs_comp_dev(file->device);
345
346         kfree(file);
347 }
348
349 static ssize_t ib_uverbs_event_read(struct file *filp, char __user *buf,
350                                     size_t count, loff_t *pos)
351 {
352         struct ib_uverbs_event_file *file = filp->private_data;
353         struct ib_uverbs_event *event;
354         int eventsz;
355         int ret = 0;
356
357         spin_lock_irq(&file->lock);
358
359         while (list_empty(&file->event_list)) {
360                 spin_unlock_irq(&file->lock);
361
362                 if (filp->f_flags & O_NONBLOCK)
363                         return -EAGAIN;
364
365                 if (wait_event_interruptible(file->poll_wait,
366                                              (!list_empty(&file->event_list) ||
367                         /* The barriers built into wait_event_interruptible()
368                          * and wake_up() guarentee this will see the null set
369                          * without using RCU
370                          */
371                                              !file->uverbs_file->device->ib_dev)))
372                         return -ERESTARTSYS;
373
374                 /* If device was disassociated and no event exists set an error */
375                 if (list_empty(&file->event_list) &&
376                     !file->uverbs_file->device->ib_dev)
377                         return -EIO;
378
379                 spin_lock_irq(&file->lock);
380         }
381
382         event = list_entry(file->event_list.next, struct ib_uverbs_event, list);
383
384         if (file->is_async)
385                 eventsz = sizeof (struct ib_uverbs_async_event_desc);
386         else
387                 eventsz = sizeof (struct ib_uverbs_comp_event_desc);
388
389         if (eventsz > count) {
390                 ret   = -EINVAL;
391                 event = NULL;
392         } else {
393                 list_del(file->event_list.next);
394                 if (event->counter) {
395                         ++(*event->counter);
396                         list_del(&event->obj_list);
397                 }
398         }
399
400         spin_unlock_irq(&file->lock);
401
402         if (event) {
403                 if (copy_to_user(buf, event, eventsz))
404                         ret = -EFAULT;
405                 else
406                         ret = eventsz;
407         }
408
409         kfree(event);
410
411         return ret;
412 }
413
414 static unsigned int ib_uverbs_event_poll(struct file *filp,
415                                          struct poll_table_struct *wait)
416 {
417         unsigned int pollflags = 0;
418         struct ib_uverbs_event_file *file = filp->private_data;
419
420         poll_wait(filp, &file->poll_wait, wait);
421
422         spin_lock_irq(&file->lock);
423         if (!list_empty(&file->event_list))
424                 pollflags = POLLIN | POLLRDNORM;
425         spin_unlock_irq(&file->lock);
426
427         return pollflags;
428 }
429
430 static int ib_uverbs_event_fasync(int fd, struct file *filp, int on)
431 {
432         struct ib_uverbs_event_file *file = filp->private_data;
433
434         return fasync_helper(fd, filp, on, &file->async_queue);
435 }
436
437 static int ib_uverbs_event_close(struct inode *inode, struct file *filp)
438 {
439         struct ib_uverbs_event_file *file = filp->private_data;
440         struct ib_uverbs_event *entry, *tmp;
441         int closed_already = 0;
442
443         mutex_lock(&file->uverbs_file->device->lists_mutex);
444         spin_lock_irq(&file->lock);
445         closed_already = file->is_closed;
446         file->is_closed = 1;
447         list_for_each_entry_safe(entry, tmp, &file->event_list, list) {
448                 if (entry->counter)
449                         list_del(&entry->obj_list);
450                 kfree(entry);
451         }
452         spin_unlock_irq(&file->lock);
453         if (!closed_already) {
454                 list_del(&file->list);
455                 if (file->is_async)
456                         ib_unregister_event_handler(&file->uverbs_file->
457                                 event_handler);
458         }
459         mutex_unlock(&file->uverbs_file->device->lists_mutex);
460
461         kref_put(&file->uverbs_file->ref, ib_uverbs_release_file);
462         kref_put(&file->ref, ib_uverbs_release_event_file);
463
464         return 0;
465 }
466
467 static const struct file_operations uverbs_event_fops = {
468         .owner   = THIS_MODULE,
469         .read    = ib_uverbs_event_read,
470         .poll    = ib_uverbs_event_poll,
471         .release = ib_uverbs_event_close,
472         .fasync  = ib_uverbs_event_fasync,
473         .llseek  = no_llseek,
474 };
475
476 void ib_uverbs_comp_handler(struct ib_cq *cq, void *cq_context)
477 {
478         struct ib_uverbs_event_file    *file = cq_context;
479         struct ib_ucq_object           *uobj;
480         struct ib_uverbs_event         *entry;
481         unsigned long                   flags;
482
483         if (!file)
484                 return;
485
486         spin_lock_irqsave(&file->lock, flags);
487         if (file->is_closed) {
488                 spin_unlock_irqrestore(&file->lock, flags);
489                 return;
490         }
491
492         entry = kmalloc(sizeof *entry, GFP_ATOMIC);
493         if (!entry) {
494                 spin_unlock_irqrestore(&file->lock, flags);
495                 return;
496         }
497
498         uobj = container_of(cq->uobject, struct ib_ucq_object, uobject);
499
500         entry->desc.comp.cq_handle = cq->uobject->user_handle;
501         entry->counter             = &uobj->comp_events_reported;
502
503         list_add_tail(&entry->list, &file->event_list);
504         list_add_tail(&entry->obj_list, &uobj->comp_list);
505         spin_unlock_irqrestore(&file->lock, flags);
506
507         wake_up_interruptible(&file->poll_wait);
508         kill_fasync(&file->async_queue, SIGIO, POLL_IN);
509 }
510
511 static void ib_uverbs_async_handler(struct ib_uverbs_file *file,
512                                     __u64 element, __u64 event,
513                                     struct list_head *obj_list,
514                                     u32 *counter)
515 {
516         struct ib_uverbs_event *entry;
517         unsigned long flags;
518
519         spin_lock_irqsave(&file->async_file->lock, flags);
520         if (file->async_file->is_closed) {
521                 spin_unlock_irqrestore(&file->async_file->lock, flags);
522                 return;
523         }
524
525         entry = kmalloc(sizeof *entry, GFP_ATOMIC);
526         if (!entry) {
527                 spin_unlock_irqrestore(&file->async_file->lock, flags);
528                 return;
529         }
530
531         entry->desc.async.element    = element;
532         entry->desc.async.event_type = event;
533         entry->desc.async.reserved   = 0;
534         entry->counter               = counter;
535
536         list_add_tail(&entry->list, &file->async_file->event_list);
537         if (obj_list)
538                 list_add_tail(&entry->obj_list, obj_list);
539         spin_unlock_irqrestore(&file->async_file->lock, flags);
540
541         wake_up_interruptible(&file->async_file->poll_wait);
542         kill_fasync(&file->async_file->async_queue, SIGIO, POLL_IN);
543 }
544
545 void ib_uverbs_cq_event_handler(struct ib_event *event, void *context_ptr)
546 {
547         struct ib_ucq_object *uobj = container_of(event->element.cq->uobject,
548                                                   struct ib_ucq_object, uobject);
549
550         ib_uverbs_async_handler(uobj->uverbs_file, uobj->uobject.user_handle,
551                                 event->event, &uobj->async_list,
552                                 &uobj->async_events_reported);
553 }
554
555 void ib_uverbs_qp_event_handler(struct ib_event *event, void *context_ptr)
556 {
557         struct ib_uevent_object *uobj;
558
559         /* for XRC target qp's, check that qp is live */
560         if (!event->element.qp->uobject || !event->element.qp->uobject->live)
561                 return;
562
563         uobj = container_of(event->element.qp->uobject,
564                             struct ib_uevent_object, uobject);
565
566         ib_uverbs_async_handler(context_ptr, uobj->uobject.user_handle,
567                                 event->event, &uobj->event_list,
568                                 &uobj->events_reported);
569 }
570
571 void ib_uverbs_srq_event_handler(struct ib_event *event, void *context_ptr)
572 {
573         struct ib_uevent_object *uobj;
574
575         uobj = container_of(event->element.srq->uobject,
576                             struct ib_uevent_object, uobject);
577
578         ib_uverbs_async_handler(context_ptr, uobj->uobject.user_handle,
579                                 event->event, &uobj->event_list,
580                                 &uobj->events_reported);
581 }
582
583 void ib_uverbs_event_handler(struct ib_event_handler *handler,
584                              struct ib_event *event)
585 {
586         struct ib_uverbs_file *file =
587                 container_of(handler, struct ib_uverbs_file, event_handler);
588
589         ib_uverbs_async_handler(file, event->element.port_num, event->event,
590                                 NULL, NULL);
591 }
592
593 void ib_uverbs_free_async_event_file(struct ib_uverbs_file *file)
594 {
595         kref_put(&file->async_file->ref, ib_uverbs_release_event_file);
596         file->async_file = NULL;
597 }
598
599 struct file *ib_uverbs_alloc_event_file(struct ib_uverbs_file *uverbs_file,
600                                         struct ib_device        *ib_dev,
601                                         int is_async)
602 {
603         struct ib_uverbs_event_file *ev_file;
604         struct file *filp;
605         int ret;
606
607         ev_file = kzalloc(sizeof(*ev_file), GFP_KERNEL);
608         if (!ev_file)
609                 return ERR_PTR(-ENOMEM);
610
611         kref_init(&ev_file->ref);
612         spin_lock_init(&ev_file->lock);
613         INIT_LIST_HEAD(&ev_file->event_list);
614         init_waitqueue_head(&ev_file->poll_wait);
615         ev_file->uverbs_file = uverbs_file;
616         kref_get(&ev_file->uverbs_file->ref);
617         ev_file->async_queue = NULL;
618         ev_file->is_closed   = 0;
619
620         filp = anon_inode_getfile("[infinibandevent]", &uverbs_event_fops,
621                                   ev_file, O_RDONLY);
622         if (IS_ERR(filp))
623                 goto err_put_refs;
624
625         mutex_lock(&uverbs_file->device->lists_mutex);
626         list_add_tail(&ev_file->list,
627                       &uverbs_file->device->uverbs_events_file_list);
628         mutex_unlock(&uverbs_file->device->lists_mutex);
629
630         if (is_async) {
631                 WARN_ON(uverbs_file->async_file);
632                 uverbs_file->async_file = ev_file;
633                 kref_get(&uverbs_file->async_file->ref);
634                 INIT_IB_EVENT_HANDLER(&uverbs_file->event_handler,
635                                       ib_dev,
636                                       ib_uverbs_event_handler);
637                 ret = ib_register_event_handler(&uverbs_file->event_handler);
638                 if (ret)
639                         goto err_put_file;
640
641                 /* At that point async file stuff was fully set */
642                 ev_file->is_async = 1;
643         }
644
645         return filp;
646
647 err_put_file:
648         fput(filp);
649         kref_put(&uverbs_file->async_file->ref, ib_uverbs_release_event_file);
650         uverbs_file->async_file = NULL;
651         return ERR_PTR(ret);
652
653 err_put_refs:
654         kref_put(&ev_file->uverbs_file->ref, ib_uverbs_release_file);
655         kref_put(&ev_file->ref, ib_uverbs_release_event_file);
656         return filp;
657 }
658
659 /*
660  * Look up a completion event file by FD.  If lookup is successful,
661  * takes a ref to the event file struct that it returns; if
662  * unsuccessful, returns NULL.
663  */
664 struct ib_uverbs_event_file *ib_uverbs_lookup_comp_file(int fd)
665 {
666         struct ib_uverbs_event_file *ev_file = NULL;
667         struct fd f = fdget(fd);
668
669         if (!f.file)
670                 return NULL;
671
672         if (f.file->f_op != &uverbs_event_fops)
673                 goto out;
674
675         ev_file = f.file->private_data;
676         if (ev_file->is_async) {
677                 ev_file = NULL;
678                 goto out;
679         }
680
681         kref_get(&ev_file->ref);
682
683 out:
684         fdput(f);
685         return ev_file;
686 }
687
688 static int verify_command_mask(struct ib_device *ib_dev, __u32 command)
689 {
690         u64 mask;
691
692         if (command <= IB_USER_VERBS_CMD_OPEN_QP)
693                 mask = ib_dev->uverbs_cmd_mask;
694         else
695                 mask = ib_dev->uverbs_ex_cmd_mask;
696
697         if (mask & ((u64)1 << command))
698                 return 0;
699
700         return -1;
701 }
702
703 static ssize_t ib_uverbs_write(struct file *filp, const char __user *buf,
704                              size_t count, loff_t *pos)
705 {
706         struct ib_uverbs_file *file = filp->private_data;
707         struct ib_device *ib_dev;
708         struct ib_uverbs_cmd_hdr hdr;
709         __u32 command;
710         __u32 flags;
711         int srcu_key;
712         ssize_t ret;
713
714         if (WARN_ON_ONCE(!ib_safe_file_access(filp)))
715                 return -EACCES;
716
717         if (count < sizeof hdr)
718                 return -EINVAL;
719
720         if (copy_from_user(&hdr, buf, sizeof hdr))
721                 return -EFAULT;
722
723         srcu_key = srcu_read_lock(&file->device->disassociate_srcu);
724         ib_dev = srcu_dereference(file->device->ib_dev,
725                                   &file->device->disassociate_srcu);
726         if (!ib_dev) {
727                 ret = -EIO;
728                 goto out;
729         }
730
731         if (hdr.command & ~(__u32)(IB_USER_VERBS_CMD_FLAGS_MASK |
732                                    IB_USER_VERBS_CMD_COMMAND_MASK)) {
733                 ret = -EINVAL;
734                 goto out;
735         }
736
737         command = hdr.command & IB_USER_VERBS_CMD_COMMAND_MASK;
738         if (verify_command_mask(ib_dev, command)) {
739                 ret = -EOPNOTSUPP;
740                 goto out;
741         }
742
743         if (!file->ucontext &&
744             command != IB_USER_VERBS_CMD_GET_CONTEXT) {
745                 ret = -EINVAL;
746                 goto out;
747         }
748
749         flags = (hdr.command &
750                  IB_USER_VERBS_CMD_FLAGS_MASK) >> IB_USER_VERBS_CMD_FLAGS_SHIFT;
751
752         if (!flags) {
753                 if (command >= ARRAY_SIZE(uverbs_cmd_table) ||
754                     !uverbs_cmd_table[command]) {
755                         ret = -EINVAL;
756                         goto out;
757                 }
758
759                 if (hdr.in_words * 4 != count) {
760                         ret = -EINVAL;
761                         goto out;
762                 }
763
764                 ret = uverbs_cmd_table[command](file, ib_dev,
765                                                  buf + sizeof(hdr),
766                                                  hdr.in_words * 4,
767                                                  hdr.out_words * 4);
768
769         } else if (flags == IB_USER_VERBS_CMD_FLAG_EXTENDED) {
770                 struct ib_uverbs_ex_cmd_hdr ex_hdr;
771                 struct ib_udata ucore;
772                 struct ib_udata uhw;
773                 size_t written_count = count;
774
775                 if (command >= ARRAY_SIZE(uverbs_ex_cmd_table) ||
776                     !uverbs_ex_cmd_table[command]) {
777                         ret = -ENOSYS;
778                         goto out;
779                 }
780
781                 if (!file->ucontext) {
782                         ret = -EINVAL;
783                         goto out;
784                 }
785
786                 if (count < (sizeof(hdr) + sizeof(ex_hdr))) {
787                         ret = -EINVAL;
788                         goto out;
789                 }
790
791                 if (copy_from_user(&ex_hdr, buf + sizeof(hdr), sizeof(ex_hdr))) {
792                         ret = -EFAULT;
793                         goto out;
794                 }
795
796                 count -= sizeof(hdr) + sizeof(ex_hdr);
797                 buf += sizeof(hdr) + sizeof(ex_hdr);
798
799                 if ((hdr.in_words + ex_hdr.provider_in_words) * 8 != count) {
800                         ret = -EINVAL;
801                         goto out;
802                 }
803
804                 if (ex_hdr.cmd_hdr_reserved) {
805                         ret = -EINVAL;
806                         goto out;
807                 }
808
809                 if (ex_hdr.response) {
810                         if (!hdr.out_words && !ex_hdr.provider_out_words) {
811                                 ret = -EINVAL;
812                                 goto out;
813                         }
814
815                         if (!access_ok(VERIFY_WRITE,
816                                        (void __user *) (unsigned long) ex_hdr.response,
817                                        (hdr.out_words + ex_hdr.provider_out_words) * 8)) {
818                                 ret = -EFAULT;
819                                 goto out;
820                         }
821                 } else {
822                         if (hdr.out_words || ex_hdr.provider_out_words) {
823                                 ret = -EINVAL;
824                                 goto out;
825                         }
826                 }
827
828                 INIT_UDATA_BUF_OR_NULL(&ucore, buf, (unsigned long) ex_hdr.response,
829                                        hdr.in_words * 8, hdr.out_words * 8);
830
831                 INIT_UDATA_BUF_OR_NULL(&uhw,
832                                        buf + ucore.inlen,
833                                        (unsigned long) ex_hdr.response + ucore.outlen,
834                                        ex_hdr.provider_in_words * 8,
835                                        ex_hdr.provider_out_words * 8);
836
837                 ret = uverbs_ex_cmd_table[command](file,
838                                                    ib_dev,
839                                                    &ucore,
840                                                    &uhw);
841                 if (!ret)
842                         ret = written_count;
843         } else {
844                 ret = -ENOSYS;
845         }
846
847 out:
848         srcu_read_unlock(&file->device->disassociate_srcu, srcu_key);
849         return ret;
850 }
851
852 static int ib_uverbs_mmap(struct file *filp, struct vm_area_struct *vma)
853 {
854         struct ib_uverbs_file *file = filp->private_data;
855         struct ib_device *ib_dev;
856         int ret = 0;
857         int srcu_key;
858
859         srcu_key = srcu_read_lock(&file->device->disassociate_srcu);
860         ib_dev = srcu_dereference(file->device->ib_dev,
861                                   &file->device->disassociate_srcu);
862         if (!ib_dev) {
863                 ret = -EIO;
864                 goto out;
865         }
866
867         if (!file->ucontext)
868                 ret = -ENODEV;
869         else
870                 ret = ib_dev->mmap(file->ucontext, vma);
871 out:
872         srcu_read_unlock(&file->device->disassociate_srcu, srcu_key);
873         return ret;
874 }
875
876 /*
877  * ib_uverbs_open() does not need the BKL:
878  *
879  *  - the ib_uverbs_device structures are properly reference counted and
880  *    everything else is purely local to the file being created, so
881  *    races against other open calls are not a problem;
882  *  - there is no ioctl method to race against;
883  *  - the open method will either immediately run -ENXIO, or all
884  *    required initialization will be done.
885  */
886 static int ib_uverbs_open(struct inode *inode, struct file *filp)
887 {
888         struct ib_uverbs_device *dev;
889         struct ib_uverbs_file *file;
890         struct ib_device *ib_dev;
891         int ret;
892         int module_dependent;
893         int srcu_key;
894
895         dev = container_of(inode->i_cdev, struct ib_uverbs_device, cdev);
896         if (!atomic_inc_not_zero(&dev->refcount))
897                 return -ENXIO;
898
899         srcu_key = srcu_read_lock(&dev->disassociate_srcu);
900         mutex_lock(&dev->lists_mutex);
901         ib_dev = srcu_dereference(dev->ib_dev,
902                                   &dev->disassociate_srcu);
903         if (!ib_dev) {
904                 ret = -EIO;
905                 goto err;
906         }
907
908         /* In case IB device supports disassociate ucontext, there is no hard
909          * dependency between uverbs device and its low level device.
910          */
911         module_dependent = !(ib_dev->disassociate_ucontext);
912
913         if (module_dependent) {
914                 if (!try_module_get(ib_dev->owner)) {
915                         ret = -ENODEV;
916                         goto err;
917                 }
918         }
919
920         file = kzalloc(sizeof(*file), GFP_KERNEL);
921         if (!file) {
922                 ret = -ENOMEM;
923                 if (module_dependent)
924                         goto err_module;
925
926                 goto err;
927         }
928
929         file->device     = dev;
930         file->ucontext   = NULL;
931         file->async_file = NULL;
932         kref_init(&file->ref);
933         mutex_init(&file->mutex);
934         mutex_init(&file->cleanup_mutex);
935
936         filp->private_data = file;
937         kobject_get(&dev->kobj);
938         list_add_tail(&file->list, &dev->uverbs_file_list);
939         mutex_unlock(&dev->lists_mutex);
940         srcu_read_unlock(&dev->disassociate_srcu, srcu_key);
941
942         return nonseekable_open(inode, filp);
943
944 err_module:
945         module_put(ib_dev->owner);
946
947 err:
948         mutex_unlock(&dev->lists_mutex);
949         srcu_read_unlock(&dev->disassociate_srcu, srcu_key);
950         if (atomic_dec_and_test(&dev->refcount))
951                 ib_uverbs_comp_dev(dev);
952
953         return ret;
954 }
955
956 static int ib_uverbs_close(struct inode *inode, struct file *filp)
957 {
958         struct ib_uverbs_file *file = filp->private_data;
959         struct ib_uverbs_device *dev = file->device;
960
961         mutex_lock(&file->cleanup_mutex);
962         if (file->ucontext) {
963                 ib_uverbs_cleanup_ucontext(file, file->ucontext);
964                 file->ucontext = NULL;
965         }
966         mutex_unlock(&file->cleanup_mutex);
967
968         mutex_lock(&file->device->lists_mutex);
969         if (!file->is_closed) {
970                 list_del(&file->list);
971                 file->is_closed = 1;
972         }
973         mutex_unlock(&file->device->lists_mutex);
974
975         if (file->async_file)
976                 kref_put(&file->async_file->ref, ib_uverbs_release_event_file);
977
978         kref_put(&file->ref, ib_uverbs_release_file);
979         kobject_put(&dev->kobj);
980
981         return 0;
982 }
983
984 static const struct file_operations uverbs_fops = {
985         .owner   = THIS_MODULE,
986         .write   = ib_uverbs_write,
987         .open    = ib_uverbs_open,
988         .release = ib_uverbs_close,
989         .llseek  = no_llseek,
990 };
991
992 static const struct file_operations uverbs_mmap_fops = {
993         .owner   = THIS_MODULE,
994         .write   = ib_uverbs_write,
995         .mmap    = ib_uverbs_mmap,
996         .open    = ib_uverbs_open,
997         .release = ib_uverbs_close,
998         .llseek  = no_llseek,
999 };
1000
1001 static struct ib_client uverbs_client = {
1002         .name   = "uverbs",
1003         .add    = ib_uverbs_add_one,
1004         .remove = ib_uverbs_remove_one
1005 };
1006
1007 static ssize_t show_ibdev(struct device *device, struct device_attribute *attr,
1008                           char *buf)
1009 {
1010         int ret = -ENODEV;
1011         int srcu_key;
1012         struct ib_uverbs_device *dev = dev_get_drvdata(device);
1013         struct ib_device *ib_dev;
1014
1015         if (!dev)
1016                 return -ENODEV;
1017
1018         srcu_key = srcu_read_lock(&dev->disassociate_srcu);
1019         ib_dev = srcu_dereference(dev->ib_dev, &dev->disassociate_srcu);
1020         if (ib_dev)
1021                 ret = sprintf(buf, "%s\n", ib_dev->name);
1022         srcu_read_unlock(&dev->disassociate_srcu, srcu_key);
1023
1024         return ret;
1025 }
1026 static DEVICE_ATTR(ibdev, S_IRUGO, show_ibdev, NULL);
1027
1028 static ssize_t show_dev_abi_version(struct device *device,
1029                                     struct device_attribute *attr, char *buf)
1030 {
1031         struct ib_uverbs_device *dev = dev_get_drvdata(device);
1032         int ret = -ENODEV;
1033         int srcu_key;
1034         struct ib_device *ib_dev;
1035
1036         if (!dev)
1037                 return -ENODEV;
1038         srcu_key = srcu_read_lock(&dev->disassociate_srcu);
1039         ib_dev = srcu_dereference(dev->ib_dev, &dev->disassociate_srcu);
1040         if (ib_dev)
1041                 ret = sprintf(buf, "%d\n", ib_dev->uverbs_abi_ver);
1042         srcu_read_unlock(&dev->disassociate_srcu, srcu_key);
1043
1044         return ret;
1045 }
1046 static DEVICE_ATTR(abi_version, S_IRUGO, show_dev_abi_version, NULL);
1047
1048 static CLASS_ATTR_STRING(abi_version, S_IRUGO,
1049                          __stringify(IB_USER_VERBS_ABI_VERSION));
1050
1051 static dev_t overflow_maj;
1052 static DECLARE_BITMAP(overflow_map, IB_UVERBS_MAX_DEVICES);
1053
1054 /*
1055  * If we have more than IB_UVERBS_MAX_DEVICES, dynamically overflow by
1056  * requesting a new major number and doubling the number of max devices we
1057  * support. It's stupid, but simple.
1058  */
1059 static int find_overflow_devnum(void)
1060 {
1061         int ret;
1062
1063         if (!overflow_maj) {
1064                 ret = alloc_chrdev_region(&overflow_maj, 0, IB_UVERBS_MAX_DEVICES,
1065                                           "infiniband_verbs");
1066                 if (ret) {
1067                         pr_err("user_verbs: couldn't register dynamic device number\n");
1068                         return ret;
1069                 }
1070         }
1071
1072         ret = find_first_zero_bit(overflow_map, IB_UVERBS_MAX_DEVICES);
1073         if (ret >= IB_UVERBS_MAX_DEVICES)
1074                 return -1;
1075
1076         return ret;
1077 }
1078
1079 static void ib_uverbs_add_one(struct ib_device *device)
1080 {
1081         int devnum;
1082         dev_t base;
1083         struct ib_uverbs_device *uverbs_dev;
1084         int ret;
1085
1086         if (!device->alloc_ucontext)
1087                 return;
1088
1089         uverbs_dev = kzalloc(sizeof *uverbs_dev, GFP_KERNEL);
1090         if (!uverbs_dev)
1091                 return;
1092
1093         ret = init_srcu_struct(&uverbs_dev->disassociate_srcu);
1094         if (ret) {
1095                 kfree(uverbs_dev);
1096                 return;
1097         }
1098
1099         atomic_set(&uverbs_dev->refcount, 1);
1100         init_completion(&uverbs_dev->comp);
1101         uverbs_dev->xrcd_tree = RB_ROOT;
1102         mutex_init(&uverbs_dev->xrcd_tree_mutex);
1103         kobject_init(&uverbs_dev->kobj, &ib_uverbs_dev_ktype);
1104         mutex_init(&uverbs_dev->lists_mutex);
1105         INIT_LIST_HEAD(&uverbs_dev->uverbs_file_list);
1106         INIT_LIST_HEAD(&uverbs_dev->uverbs_events_file_list);
1107
1108         spin_lock(&map_lock);
1109         devnum = find_first_zero_bit(dev_map, IB_UVERBS_MAX_DEVICES);
1110         if (devnum >= IB_UVERBS_MAX_DEVICES) {
1111                 spin_unlock(&map_lock);
1112                 devnum = find_overflow_devnum();
1113                 if (devnum < 0)
1114                         goto err;
1115
1116                 spin_lock(&map_lock);
1117                 uverbs_dev->devnum = devnum + IB_UVERBS_MAX_DEVICES;
1118                 base = devnum + overflow_maj;
1119                 set_bit(devnum, overflow_map);
1120         } else {
1121                 uverbs_dev->devnum = devnum;
1122                 base = devnum + IB_UVERBS_BASE_DEV;
1123                 set_bit(devnum, dev_map);
1124         }
1125         spin_unlock(&map_lock);
1126
1127         rcu_assign_pointer(uverbs_dev->ib_dev, device);
1128         uverbs_dev->num_comp_vectors = device->num_comp_vectors;
1129
1130         cdev_init(&uverbs_dev->cdev, NULL);
1131         uverbs_dev->cdev.owner = THIS_MODULE;
1132         uverbs_dev->cdev.ops = device->mmap ? &uverbs_mmap_fops : &uverbs_fops;
1133         uverbs_dev->cdev.kobj.parent = &uverbs_dev->kobj;
1134         kobject_set_name(&uverbs_dev->cdev.kobj, "uverbs%d", uverbs_dev->devnum);
1135         if (cdev_add(&uverbs_dev->cdev, base, 1))
1136                 goto err_cdev;
1137
1138         uverbs_dev->dev = device_create(uverbs_class, device->dma_device,
1139                                         uverbs_dev->cdev.dev, uverbs_dev,
1140                                         "uverbs%d", uverbs_dev->devnum);
1141         if (IS_ERR(uverbs_dev->dev))
1142                 goto err_cdev;
1143
1144         if (device_create_file(uverbs_dev->dev, &dev_attr_ibdev))
1145                 goto err_class;
1146         if (device_create_file(uverbs_dev->dev, &dev_attr_abi_version))
1147                 goto err_class;
1148
1149         ib_set_client_data(device, &uverbs_client, uverbs_dev);
1150
1151         return;
1152
1153 err_class:
1154         device_destroy(uverbs_class, uverbs_dev->cdev.dev);
1155
1156 err_cdev:
1157         cdev_del(&uverbs_dev->cdev);
1158         if (uverbs_dev->devnum < IB_UVERBS_MAX_DEVICES)
1159                 clear_bit(devnum, dev_map);
1160         else
1161                 clear_bit(devnum, overflow_map);
1162
1163 err:
1164         if (atomic_dec_and_test(&uverbs_dev->refcount))
1165                 ib_uverbs_comp_dev(uverbs_dev);
1166         wait_for_completion(&uverbs_dev->comp);
1167         kobject_put(&uverbs_dev->kobj);
1168         return;
1169 }
1170
1171 static void ib_uverbs_free_hw_resources(struct ib_uverbs_device *uverbs_dev,
1172                                         struct ib_device *ib_dev)
1173 {
1174         struct ib_uverbs_file *file;
1175         struct ib_uverbs_event_file *event_file;
1176         struct ib_event event;
1177
1178         /* Pending running commands to terminate */
1179         synchronize_srcu(&uverbs_dev->disassociate_srcu);
1180         event.event = IB_EVENT_DEVICE_FATAL;
1181         event.element.port_num = 0;
1182         event.device = ib_dev;
1183
1184         mutex_lock(&uverbs_dev->lists_mutex);
1185         while (!list_empty(&uverbs_dev->uverbs_file_list)) {
1186                 struct ib_ucontext *ucontext;
1187                 file = list_first_entry(&uverbs_dev->uverbs_file_list,
1188                                         struct ib_uverbs_file, list);
1189                 file->is_closed = 1;
1190                 list_del(&file->list);
1191                 kref_get(&file->ref);
1192                 mutex_unlock(&uverbs_dev->lists_mutex);
1193
1194                 ib_uverbs_event_handler(&file->event_handler, &event);
1195
1196                 mutex_lock(&file->cleanup_mutex);
1197                 ucontext = file->ucontext;
1198                 file->ucontext = NULL;
1199                 mutex_unlock(&file->cleanup_mutex);
1200
1201                 /* At this point ib_uverbs_close cannot be running
1202                  * ib_uverbs_cleanup_ucontext
1203                  */
1204                 if (ucontext) {
1205                         /* We must release the mutex before going ahead and
1206                          * calling disassociate_ucontext. disassociate_ucontext
1207                          * might end up indirectly calling uverbs_close,
1208                          * for example due to freeing the resources
1209                          * (e.g mmput).
1210                          */
1211                         ib_dev->disassociate_ucontext(ucontext);
1212                         ib_uverbs_cleanup_ucontext(file, ucontext);
1213                 }
1214
1215                 mutex_lock(&uverbs_dev->lists_mutex);
1216                 kref_put(&file->ref, ib_uverbs_release_file);
1217         }
1218
1219         while (!list_empty(&uverbs_dev->uverbs_events_file_list)) {
1220                 event_file = list_first_entry(&uverbs_dev->
1221                                               uverbs_events_file_list,
1222                                               struct ib_uverbs_event_file,
1223                                               list);
1224                 spin_lock_irq(&event_file->lock);
1225                 event_file->is_closed = 1;
1226                 spin_unlock_irq(&event_file->lock);
1227
1228                 list_del(&event_file->list);
1229                 if (event_file->is_async) {
1230                         ib_unregister_event_handler(&event_file->uverbs_file->
1231                                                     event_handler);
1232                         event_file->uverbs_file->event_handler.device = NULL;
1233                 }
1234
1235                 wake_up_interruptible(&event_file->poll_wait);
1236                 kill_fasync(&event_file->async_queue, SIGIO, POLL_IN);
1237         }
1238         mutex_unlock(&uverbs_dev->lists_mutex);
1239 }
1240
1241 static void ib_uverbs_remove_one(struct ib_device *device, void *client_data)
1242 {
1243         struct ib_uverbs_device *uverbs_dev = client_data;
1244         int wait_clients = 1;
1245
1246         if (!uverbs_dev)
1247                 return;
1248
1249         dev_set_drvdata(uverbs_dev->dev, NULL);
1250         device_destroy(uverbs_class, uverbs_dev->cdev.dev);
1251         cdev_del(&uverbs_dev->cdev);
1252
1253         if (uverbs_dev->devnum < IB_UVERBS_MAX_DEVICES)
1254                 clear_bit(uverbs_dev->devnum, dev_map);
1255         else
1256                 clear_bit(uverbs_dev->devnum - IB_UVERBS_MAX_DEVICES, overflow_map);
1257
1258         if (device->disassociate_ucontext) {
1259                 /* We disassociate HW resources and immediately return.
1260                  * Userspace will see a EIO errno for all future access.
1261                  * Upon returning, ib_device may be freed internally and is not
1262                  * valid any more.
1263                  * uverbs_device is still available until all clients close
1264                  * their files, then the uverbs device ref count will be zero
1265                  * and its resources will be freed.
1266                  * Note: At this point no more files can be opened since the
1267                  * cdev was deleted, however active clients can still issue
1268                  * commands and close their open files.
1269                  */
1270                 rcu_assign_pointer(uverbs_dev->ib_dev, NULL);
1271                 ib_uverbs_free_hw_resources(uverbs_dev, device);
1272                 wait_clients = 0;
1273         }
1274
1275         if (atomic_dec_and_test(&uverbs_dev->refcount))
1276                 ib_uverbs_comp_dev(uverbs_dev);
1277         if (wait_clients)
1278                 wait_for_completion(&uverbs_dev->comp);
1279         kobject_put(&uverbs_dev->kobj);
1280 }
1281
1282 static char *uverbs_devnode(struct device *dev, umode_t *mode)
1283 {
1284         if (mode)
1285                 *mode = 0666;
1286         return kasprintf(GFP_KERNEL, "infiniband/%s", dev_name(dev));
1287 }
1288
1289 static int __init ib_uverbs_init(void)
1290 {
1291         int ret;
1292
1293         ret = register_chrdev_region(IB_UVERBS_BASE_DEV, IB_UVERBS_MAX_DEVICES,
1294                                      "infiniband_verbs");
1295         if (ret) {
1296                 pr_err("user_verbs: couldn't register device number\n");
1297                 goto out;
1298         }
1299
1300         uverbs_class = class_create(THIS_MODULE, "infiniband_verbs");
1301         if (IS_ERR(uverbs_class)) {
1302                 ret = PTR_ERR(uverbs_class);
1303                 pr_err("user_verbs: couldn't create class infiniband_verbs\n");
1304                 goto out_chrdev;
1305         }
1306
1307         uverbs_class->devnode = uverbs_devnode;
1308
1309         ret = class_create_file(uverbs_class, &class_attr_abi_version.attr);
1310         if (ret) {
1311                 pr_err("user_verbs: couldn't create abi_version attribute\n");
1312                 goto out_class;
1313         }
1314
1315         ret = ib_register_client(&uverbs_client);
1316         if (ret) {
1317                 pr_err("user_verbs: couldn't register client\n");
1318                 goto out_class;
1319         }
1320
1321         return 0;
1322
1323 out_class:
1324         class_destroy(uverbs_class);
1325
1326 out_chrdev:
1327         unregister_chrdev_region(IB_UVERBS_BASE_DEV, IB_UVERBS_MAX_DEVICES);
1328
1329 out:
1330         return ret;
1331 }
1332
1333 static void __exit ib_uverbs_cleanup(void)
1334 {
1335         ib_unregister_client(&uverbs_client);
1336         class_destroy(uverbs_class);
1337         unregister_chrdev_region(IB_UVERBS_BASE_DEV, IB_UVERBS_MAX_DEVICES);
1338         if (overflow_maj)
1339                 unregister_chrdev_region(overflow_maj, IB_UVERBS_MAX_DEVICES);
1340         idr_destroy(&ib_uverbs_pd_idr);
1341         idr_destroy(&ib_uverbs_mr_idr);
1342         idr_destroy(&ib_uverbs_mw_idr);
1343         idr_destroy(&ib_uverbs_ah_idr);
1344         idr_destroy(&ib_uverbs_cq_idr);
1345         idr_destroy(&ib_uverbs_qp_idr);
1346         idr_destroy(&ib_uverbs_srq_idr);
1347 }
1348
1349 module_init(ib_uverbs_init);
1350 module_exit(ib_uverbs_cleanup);