svcsock.c 50.1 KB
Newer Older
Linus Torvalds's avatar
Linus Torvalds committed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
/*
 * linux/net/sunrpc/svcsock.c
 *
 * These are the RPC server socket internals.
 *
 * The server scheduling algorithm does not always distribute the load
 * evenly when servicing a single client. May need to modify the
 * svc_sock_enqueue procedure...
 *
 * TCP support is largely untested and may be a little slow. The problem
 * is that we currently do two separate recvfrom's, one for the 4-byte
 * record length, and the second for the actual record. This could possibly
 * be improved by always reading a minimum size of around 100 bytes and
 * tucking any superfluous bytes away in a temporary store. Still, that
 * leaves write requests out in the rain. An alternative may be to peek at
 * the first skb in the queue, and if it matches the next TCP sequence
 * number, to extract the record marker. Yuck.
 *
 * Copyright (C) 1995, 1996 Olaf Kirch <okir@monad.swb.de>
 */

#include <linux/sched.h>
#include <linux/errno.h>
#include <linux/fcntl.h>
#include <linux/net.h>
#include <linux/in.h>
#include <linux/inet.h>
#include <linux/udp.h>
29
#include <linux/tcp.h>
Linus Torvalds's avatar
Linus Torvalds committed
30
31
32
33
#include <linux/unistd.h>
#include <linux/slab.h>
#include <linux/netdevice.h>
#include <linux/skbuff.h>
34
#include <linux/file.h>
35
#include <linux/freezer.h>
Linus Torvalds's avatar
Linus Torvalds committed
36
37
38
#include <net/sock.h>
#include <net/checksum.h>
#include <net/ip.h>
39
#include <net/ipv6.h>
40
#include <net/tcp_states.h>
Linus Torvalds's avatar
Linus Torvalds committed
41
42
43
44
#include <asm/uaccess.h>
#include <asm/ioctls.h>

#include <linux/sunrpc/types.h>
45
#include <linux/sunrpc/clnt.h>
Linus Torvalds's avatar
Linus Torvalds committed
46
47
48
49
50
51
#include <linux/sunrpc/xdr.h>
#include <linux/sunrpc/svcsock.h>
#include <linux/sunrpc/stats.h>

/* SMP locking strategy:
 *
52
53
54
55
 *	svc_pool->sp_lock protects most of the fields of that pool.
 * 	svc_serv->sv_lock protects sv_tempsocks, sv_permsocks, sv_tmpcnt.
 *	when both need to be taken (rare), svc_serv->sv_lock is first.
 *	BKL protects svc_serv->sv_nrthread.
56
57
 *	svc_sock->sk_lock protects the svc_sock->sk_deferred list
 *             and the ->sk_info_authunix cache.
58
 *	svc_sock->sk_flags.SK_BUSY prevents a svc_sock being enqueued multiply.
Linus Torvalds's avatar
Linus Torvalds committed
59
60
61
62
63
 *
 *	Some flags can be set to certain values at any time
 *	providing that certain rules are followed:
 *
 *	SK_CONN, SK_DATA, can be set or cleared at any time.
64
 *		after a set, svc_sock_enqueue must be called.
Linus Torvalds's avatar
Linus Torvalds committed
65
66
67
 *		after a clear, the socket must be read/accepted
 *		 if this succeeds, it must be set again.
 *	SK_CLOSE can set at any time. It is never cleared.
68
69
70
71
72
73
 *      sk_inuse contains a bias of '1' until SK_DEAD is set.
 *             so when sk_inuse hits zero, we know the socket is dead
 *             and no-one is using it.
 *      SK_DEAD can only be set while SK_BUSY is held which ensures
 *             no other thread will be using the socket or will try to
 *	       set SK_DEAD.
Linus Torvalds's avatar
Linus Torvalds committed
74
75
76
77
78
79
80
 *
 */

#define RPCDBG_FACILITY	RPCDBG_SVCSOCK


static struct svc_sock *svc_setup_socket(struct svc_serv *, struct socket *,
81
					 int *errp, int flags);
82
static void		svc_delete_socket(struct svc_sock *svsk);
Linus Torvalds's avatar
Linus Torvalds committed
83
84
85
static void		svc_udp_data_ready(struct sock *, int);
static int		svc_udp_recvfrom(struct svc_rqst *);
static int		svc_udp_sendto(struct svc_rqst *);
86
static void		svc_close_socket(struct svc_sock *svsk);
Linus Torvalds's avatar
Linus Torvalds committed
87
88
89
90
91

static struct svc_deferred_req *svc_deferred_dequeue(struct svc_sock *svsk);
static int svc_deferred_recv(struct svc_rqst *rqstp);
static struct cache_deferred_req *svc_defer(struct cache_req *req);

92
93
94
95
96
97
98
/* apparently the "standard" is that clients close
 * idle connections after 5 minutes, servers after
 * 6 minutes
 *   http://www.connectathon.org/talks96/nfstcp.pdf
 */
static int svc_conn_age_period = 6*60;

99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
#ifdef CONFIG_DEBUG_LOCK_ALLOC
static struct lock_class_key svc_key[2];
static struct lock_class_key svc_slock_key[2];

static inline void svc_reclassify_socket(struct socket *sock)
{
	struct sock *sk = sock->sk;
	BUG_ON(sk->sk_lock.owner != NULL);
	switch (sk->sk_family) {
	case AF_INET:
		sock_lock_init_class_and_name(sk, "slock-AF_INET-NFSD",
		    &svc_slock_key[0], "sk_lock-AF_INET-NFSD", &svc_key[0]);
		break;

	case AF_INET6:
		sock_lock_init_class_and_name(sk, "slock-AF_INET6-NFSD",
		    &svc_slock_key[1], "sk_lock-AF_INET6-NFSD", &svc_key[1]);
		break;

	default:
		BUG();
	}
}
#else
static inline void svc_reclassify_socket(struct socket *sock)
{
}
#endif

128
129
130
131
132
133
static char *__svc_print_addr(struct sockaddr *addr, char *buf, size_t len)
{
	switch (addr->sa_family) {
	case AF_INET:
		snprintf(buf, len, "%u.%u.%u.%u, port=%u",
			NIPQUAD(((struct sockaddr_in *) addr)->sin_addr),
Al Viro's avatar
Al Viro committed
134
			ntohs(((struct sockaddr_in *) addr)->sin_port));
135
		break;
136

137
138
139
	case AF_INET6:
		snprintf(buf, len, "%x:%x:%x:%x:%x:%x:%x:%x, port=%u",
			NIP6(((struct sockaddr_in6 *) addr)->sin6_addr),
Al Viro's avatar
Al Viro committed
140
			ntohs(((struct sockaddr_in6 *) addr)->sin6_port));
141
		break;
142

143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
	default:
		snprintf(buf, len, "unknown address type: %d", addr->sa_family);
		break;
	}
	return buf;
}

/**
 * svc_print_addr - Format rq_addr field for printing
 * @rqstp: svc_rqst struct containing address to print
 * @buf: target buffer for formatted address
 * @len: length of target buffer
 *
 */
char *svc_print_addr(struct svc_rqst *rqstp, char *buf, size_t len)
{
159
	return __svc_print_addr(svc_addr(rqstp), buf, len);
160
161
162
}
EXPORT_SYMBOL_GPL(svc_print_addr);

Linus Torvalds's avatar
Linus Torvalds committed
163
/*
164
 * Queue up an idle server thread.  Must have pool->sp_lock held.
Linus Torvalds's avatar
Linus Torvalds committed
165
 * Note: this is really a stack rather than a queue, so that we only
166
 * use as many different threads as we need, and the rest don't pollute
Linus Torvalds's avatar
Linus Torvalds committed
167
168
169
 * the cache.
 */
static inline void
170
svc_thread_enqueue(struct svc_pool *pool, struct svc_rqst *rqstp)
Linus Torvalds's avatar
Linus Torvalds committed
171
{
172
	list_add(&rqstp->rq_list, &pool->sp_threads);
Linus Torvalds's avatar
Linus Torvalds committed
173
174
175
}

/*
176
 * Dequeue an nfsd thread.  Must have pool->sp_lock held.
Linus Torvalds's avatar
Linus Torvalds committed
177
178
 */
static inline void
179
svc_thread_dequeue(struct svc_pool *pool, struct svc_rqst *rqstp)
Linus Torvalds's avatar
Linus Torvalds committed
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
{
	list_del(&rqstp->rq_list);
}

/*
 * Release an skbuff after use
 */
static inline void
svc_release_skb(struct svc_rqst *rqstp)
{
	struct sk_buff *skb = rqstp->rq_skbuff;
	struct svc_deferred_req *dr = rqstp->rq_deferred;

	if (skb) {
		rqstp->rq_skbuff = NULL;

		dprintk("svc: service %p, releasing skb %p\n", rqstp, skb);
		skb_free_datagram(rqstp->rq_sock->sk_sk, skb);
	}
	if (dr) {
		rqstp->rq_deferred = NULL;
		kfree(dr);
	}
}

/*
 * Any space to write?
 */
static inline unsigned long
svc_sock_wspace(struct svc_sock *svsk)
{
	int wspace;

	if (svsk->sk_sock->type == SOCK_STREAM)
		wspace = sk_stream_wspace(svsk->sk_sk);
	else
		wspace = sock_wspace(svsk->sk_sk);

	return wspace;
}

/*
 * Queue up a socket with data pending. If there are idle nfsd
 * processes, wake 'em up.
 *
 */
static void
svc_sock_enqueue(struct svc_sock *svsk)
{
	struct svc_serv	*serv = svsk->sk_server;
230
	struct svc_pool *pool;
Linus Torvalds's avatar
Linus Torvalds committed
231
	struct svc_rqst	*rqstp;
232
	int cpu;
Linus Torvalds's avatar
Linus Torvalds committed
233
234
235
236
237
238
239

	if (!(svsk->sk_flags &
	      ( (1<<SK_CONN)|(1<<SK_DATA)|(1<<SK_CLOSE)|(1<<SK_DEFERRED)) ))
		return;
	if (test_bit(SK_DEAD, &svsk->sk_flags))
		return;

240
241
242
243
	cpu = get_cpu();
	pool = svc_pool_for_cpu(svsk->sk_server, cpu);
	put_cpu();

244
	spin_lock_bh(&pool->sp_lock);
Linus Torvalds's avatar
Linus Torvalds committed
245

246
247
	if (!list_empty(&pool->sp_threads) &&
	    !list_empty(&pool->sp_sockets))
Linus Torvalds's avatar
Linus Torvalds committed
248
249
250
251
252
253
254
255
256
		printk(KERN_ERR
			"svc_sock_enqueue: threads and sockets both waiting??\n");

	if (test_bit(SK_DEAD, &svsk->sk_flags)) {
		/* Don't enqueue dead sockets */
		dprintk("svc: socket %p is dead, not enqueued\n", svsk->sk_sk);
		goto out_unlock;
	}

257
258
259
260
261
262
263
	/* Mark socket as busy. It will remain in this state until the
	 * server has processed all pending data and put the socket back
	 * on the idle list.  We update SK_BUSY atomically because
	 * it also guards against trying to enqueue the svc_sock twice.
	 */
	if (test_and_set_bit(SK_BUSY, &svsk->sk_flags)) {
		/* Don't enqueue socket while already enqueued */
Linus Torvalds's avatar
Linus Torvalds committed
264
265
266
		dprintk("svc: socket %p busy, not enqueued\n", svsk->sk_sk);
		goto out_unlock;
	}
267
268
	BUG_ON(svsk->sk_pool != NULL);
	svsk->sk_pool = pool;
Linus Torvalds's avatar
Linus Torvalds committed
269
270

	set_bit(SOCK_NOSPACE, &svsk->sk_sock->flags);
271
	if (((atomic_read(&svsk->sk_reserved) + serv->sv_max_mesg)*2
Linus Torvalds's avatar
Linus Torvalds committed
272
273
274
275
276
	     > svc_sock_wspace(svsk))
	    && !test_bit(SK_CLOSE, &svsk->sk_flags)
	    && !test_bit(SK_CONN, &svsk->sk_flags)) {
		/* Don't enqueue while not enough space for reply */
		dprintk("svc: socket %p  no space, %d*2 > %ld, not enqueued\n",
277
			svsk->sk_sk, atomic_read(&svsk->sk_reserved)+serv->sv_max_mesg,
Linus Torvalds's avatar
Linus Torvalds committed
278
			svc_sock_wspace(svsk));
279
		svsk->sk_pool = NULL;
280
		clear_bit(SK_BUSY, &svsk->sk_flags);
Linus Torvalds's avatar
Linus Torvalds committed
281
282
283
284
285
		goto out_unlock;
	}
	clear_bit(SOCK_NOSPACE, &svsk->sk_sock->flags);


286
287
	if (!list_empty(&pool->sp_threads)) {
		rqstp = list_entry(pool->sp_threads.next,
Linus Torvalds's avatar
Linus Torvalds committed
288
289
290
291
				   struct svc_rqst,
				   rq_list);
		dprintk("svc: socket %p served by daemon %p\n",
			svsk->sk_sk, rqstp);
292
		svc_thread_dequeue(pool, rqstp);
Linus Torvalds's avatar
Linus Torvalds committed
293
		if (rqstp->rq_sock)
294
			printk(KERN_ERR
Linus Torvalds's avatar
Linus Torvalds committed
295
296
297
				"svc_sock_enqueue: server %p, rq_sock=%p!\n",
				rqstp, rqstp->rq_sock);
		rqstp->rq_sock = svsk;
298
		atomic_inc(&svsk->sk_inuse);
299
		rqstp->rq_reserved = serv->sv_max_mesg;
300
		atomic_add(rqstp->rq_reserved, &svsk->sk_reserved);
301
		BUG_ON(svsk->sk_pool != pool);
Linus Torvalds's avatar
Linus Torvalds committed
302
303
304
		wake_up(&rqstp->rq_wait);
	} else {
		dprintk("svc: socket %p put into queue\n", svsk->sk_sk);
305
306
		list_add_tail(&svsk->sk_ready, &pool->sp_sockets);
		BUG_ON(svsk->sk_pool != pool);
Linus Torvalds's avatar
Linus Torvalds committed
307
308
309
	}

out_unlock:
310
	spin_unlock_bh(&pool->sp_lock);
Linus Torvalds's avatar
Linus Torvalds committed
311
312
313
}

/*
314
 * Dequeue the first socket.  Must be called with the pool->sp_lock held.
Linus Torvalds's avatar
Linus Torvalds committed
315
316
 */
static inline struct svc_sock *
317
svc_sock_dequeue(struct svc_pool *pool)
Linus Torvalds's avatar
Linus Torvalds committed
318
319
320
{
	struct svc_sock	*svsk;

321
	if (list_empty(&pool->sp_sockets))
Linus Torvalds's avatar
Linus Torvalds committed
322
323
		return NULL;

324
	svsk = list_entry(pool->sp_sockets.next,
Linus Torvalds's avatar
Linus Torvalds committed
325
326
327
328
			  struct svc_sock, sk_ready);
	list_del_init(&svsk->sk_ready);

	dprintk("svc: socket %p dequeued, inuse=%d\n",
329
		svsk->sk_sk, atomic_read(&svsk->sk_inuse));
Linus Torvalds's avatar
Linus Torvalds committed
330
331
332
333
334
335
336
337
338
339
340
341
342

	return svsk;
}

/*
 * Having read something from a socket, check whether it
 * needs to be re-enqueued.
 * Note: SK_DATA only gets cleared when a read-attempt finds
 * no (or insufficient) data.
 */
static inline void
svc_sock_received(struct svc_sock *svsk)
{
343
	svsk->sk_pool = NULL;
Linus Torvalds's avatar
Linus Torvalds committed
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
	clear_bit(SK_BUSY, &svsk->sk_flags);
	svc_sock_enqueue(svsk);
}


/**
 * svc_reserve - change the space reserved for the reply to a request.
 * @rqstp:  The request in question
 * @space: new max space to reserve
 *
 * Each request reserves some space on the output queue of the socket
 * to make sure the reply fits.  This function reduces that reserved
 * space to be the amount of space used already, plus @space.
 *
 */
void svc_reserve(struct svc_rqst *rqstp, int space)
{
	space += rqstp->rq_res.head[0].iov_len;

	if (space < rqstp->rq_reserved) {
		struct svc_sock *svsk = rqstp->rq_sock;
365
		atomic_sub((rqstp->rq_reserved - space), &svsk->sk_reserved);
Linus Torvalds's avatar
Linus Torvalds committed
366
367
368
369
370
371
372
373
374
375
376
377
		rqstp->rq_reserved = space;

		svc_sock_enqueue(svsk);
	}
}

/*
 * Release a socket after use.
 */
static inline void
svc_sock_put(struct svc_sock *svsk)
{
378
379
380
	if (atomic_dec_and_test(&svsk->sk_inuse)) {
		BUG_ON(! test_bit(SK_DEAD, &svsk->sk_flags));

381
		dprintk("svc: releasing dead socket\n");
382
383
384
385
386
387
		if (svsk->sk_sock->file)
			sockfd_put(svsk->sk_sock);
		else
			sock_release(svsk->sk_sock);
		if (svsk->sk_info_authunix != NULL)
			svcauth_unix_info_release(svsk->sk_info_authunix);
Linus Torvalds's avatar
Linus Torvalds committed
388
389
390
391
392
393
394
395
396
397
398
		kfree(svsk);
	}
}

static void
svc_sock_release(struct svc_rqst *rqstp)
{
	struct svc_sock	*svsk = rqstp->rq_sock;

	svc_release_skb(rqstp);

399
	svc_free_res_pages(rqstp);
Linus Torvalds's avatar
Linus Torvalds committed
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
	rqstp->rq_res.page_len = 0;
	rqstp->rq_res.page_base = 0;


	/* Reset response buffer and release
	 * the reservation.
	 * But first, check that enough space was reserved
	 * for the reply, otherwise we have a bug!
	 */
	if ((rqstp->rq_res.len) >  rqstp->rq_reserved)
		printk(KERN_ERR "RPC request reserved %d but used %d\n",
		       rqstp->rq_reserved,
		       rqstp->rq_res.len);

	rqstp->rq_res.head[0].iov_len = 0;
	svc_reserve(rqstp, 0);
	rqstp->rq_sock = NULL;

	svc_sock_put(svsk);
}

/*
 * External function to wake up a server waiting for data
423
424
 * This really only makes sense for services like lockd
 * which have exactly one thread anyway.
Linus Torvalds's avatar
Linus Torvalds committed
425
426
427
428
429
 */
void
svc_wake_up(struct svc_serv *serv)
{
	struct svc_rqst	*rqstp;
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
	unsigned int i;
	struct svc_pool *pool;

	for (i = 0; i < serv->sv_nrpools; i++) {
		pool = &serv->sv_pools[i];

		spin_lock_bh(&pool->sp_lock);
		if (!list_empty(&pool->sp_threads)) {
			rqstp = list_entry(pool->sp_threads.next,
					   struct svc_rqst,
					   rq_list);
			dprintk("svc: daemon %p woken up.\n", rqstp);
			/*
			svc_thread_dequeue(pool, rqstp);
			rqstp->rq_sock = NULL;
			 */
			wake_up(&rqstp->rq_wait);
		}
		spin_unlock_bh(&pool->sp_lock);
Linus Torvalds's avatar
Linus Torvalds committed
449
450
451
	}
}

452
453
454
455
union svc_pktinfo_u {
	struct in_pktinfo pkti;
	struct in6_pktinfo pkti6;
};
456
457
#define SVC_PKTINFO_SPACE \
	CMSG_SPACE(sizeof(union svc_pktinfo_u))
458
459
460
461
462
463
464
465
466
467
468
469
470
471

static void svc_set_cmsg_data(struct svc_rqst *rqstp, struct cmsghdr *cmh)
{
	switch (rqstp->rq_sock->sk_sk->sk_family) {
	case AF_INET: {
			struct in_pktinfo *pki = CMSG_DATA(cmh);

			cmh->cmsg_level = SOL_IP;
			cmh->cmsg_type = IP_PKTINFO;
			pki->ipi_ifindex = 0;
			pki->ipi_spec_dst.s_addr = rqstp->rq_daddr.addr.s_addr;
			cmh->cmsg_len = CMSG_LEN(sizeof(*pki));
		}
		break;
472

473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
	case AF_INET6: {
			struct in6_pktinfo *pki = CMSG_DATA(cmh);

			cmh->cmsg_level = SOL_IPV6;
			cmh->cmsg_type = IPV6_PKTINFO;
			pki->ipi6_ifindex = 0;
			ipv6_addr_copy(&pki->ipi6_addr,
					&rqstp->rq_daddr.addr6);
			cmh->cmsg_len = CMSG_LEN(sizeof(*pki));
		}
		break;
	}
	return;
}

Linus Torvalds's avatar
Linus Torvalds committed
488
489
490
491
492
493
494
495
496
/*
 * Generic sendto routine
 */
static int
svc_sendto(struct svc_rqst *rqstp, struct xdr_buf *xdr)
{
	struct svc_sock	*svsk = rqstp->rq_sock;
	struct socket	*sock = svsk->sk_sock;
	int		slen;
497
498
499
500
501
	union {
		struct cmsghdr	hdr;
		long		all[SVC_PKTINFO_SPACE / sizeof(long)];
	} buffer;
	struct cmsghdr *cmh = &buffer.hdr;
Linus Torvalds's avatar
Linus Torvalds committed
502
503
504
505
506
507
508
	int		len = 0;
	int		result;
	int		size;
	struct page	**ppage = xdr->pages;
	size_t		base = xdr->page_base;
	unsigned int	pglen = xdr->page_len;
	unsigned int	flags = MSG_MORE;
509
	char		buf[RPC_MAX_ADDRBUFLEN];
Linus Torvalds's avatar
Linus Torvalds committed
510
511
512
513

	slen = xdr->len;

	if (rqstp->rq_prot == IPPROTO_UDP) {
514
515
516
517
518
519
520
521
522
		struct msghdr msg = {
			.msg_name	= &rqstp->rq_addr,
			.msg_namelen	= rqstp->rq_addrlen,
			.msg_control	= cmh,
			.msg_controllen	= sizeof(buffer),
			.msg_flags	= MSG_MORE,
		};

		svc_set_cmsg_data(rqstp, cmh);
Linus Torvalds's avatar
Linus Torvalds committed
523
524
525
526
527
528
529
530

		if (sock_sendmsg(sock, &msg, 0) < 0)
			goto out;
	}

	/* send head */
	if (slen == xdr->head[0].iov_len)
		flags = 0;
531
532
	len = kernel_sendpage(sock, rqstp->rq_respages[0], 0,
				  xdr->head[0].iov_len, flags);
Linus Torvalds's avatar
Linus Torvalds committed
533
534
535
536
537
538
539
540
541
542
543
	if (len != xdr->head[0].iov_len)
		goto out;
	slen -= xdr->head[0].iov_len;
	if (slen == 0)
		goto out;

	/* send page data */
	size = PAGE_SIZE - base < pglen ? PAGE_SIZE - base : pglen;
	while (pglen > 0) {
		if (slen == size)
			flags = 0;
544
		result = kernel_sendpage(sock, *ppage, base, size, flags);
Linus Torvalds's avatar
Linus Torvalds committed
545
546
547
548
549
550
551
552
553
554
555
556
		if (result > 0)
			len += result;
		if (result != size)
			goto out;
		slen -= size;
		pglen -= size;
		size = PAGE_SIZE < pglen ? PAGE_SIZE : pglen;
		base = 0;
		ppage++;
	}
	/* send tail */
	if (xdr->tail[0].iov_len) {
557
558
		result = kernel_sendpage(sock, rqstp->rq_respages[0],
					     ((unsigned long)xdr->tail[0].iov_base)
559
						& (PAGE_SIZE-1),
Linus Torvalds's avatar
Linus Torvalds committed
560
561
562
563
564
565
					     xdr->tail[0].iov_len, 0);

		if (result > 0)
			len += result;
	}
out:
566
567
568
	dprintk("svc: socket %p sendto([%p %Zu... ], %d) = %d (addr %s)\n",
		rqstp->rq_sock, xdr->head[0].iov_base, xdr->head[0].iov_len,
		xdr->len, len, svc_print_addr(rqstp, buf, sizeof(buf)));
Linus Torvalds's avatar
Linus Torvalds committed
569
570
571
572

	return len;
}

573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
/*
 * Report socket names for nfsdfs
 */
static int one_sock_name(char *buf, struct svc_sock *svsk)
{
	int len;

	switch(svsk->sk_sk->sk_family) {
	case AF_INET:
		len = sprintf(buf, "ipv4 %s %u.%u.%u.%u %d\n",
			      svsk->sk_sk->sk_protocol==IPPROTO_UDP?
			      "udp" : "tcp",
			      NIPQUAD(inet_sk(svsk->sk_sk)->rcv_saddr),
			      inet_sk(svsk->sk_sk)->num);
		break;
	default:
		len = sprintf(buf, "*unknown-%d*\n",
			       svsk->sk_sk->sk_family);
	}
	return len;
}

int
596
svc_sock_names(char *buf, struct svc_serv *serv, char *toclose)
597
{
598
	struct svc_sock *svsk, *closesk = NULL;
599
600
601
602
	int len = 0;

	if (!serv)
		return 0;
603
	spin_lock_bh(&serv->sv_lock);
604
605
	list_for_each_entry(svsk, &serv->sv_permsocks, sk_list) {
		int onelen = one_sock_name(buf+len, svsk);
606
607
608
609
		if (toclose && strcmp(toclose, buf+len) == 0)
			closesk = svsk;
		else
			len += onelen;
610
	}
611
	spin_unlock_bh(&serv->sv_lock);
612
	if (closesk)
613
614
615
		/* Should unregister with portmap, but you cannot
		 * unregister just one protocol...
		 */
616
		svc_close_socket(closesk);
617
618
	else if (toclose)
		return -ENOENT;
619
620
621
622
	return len;
}
EXPORT_SYMBOL(svc_sock_names);

Linus Torvalds's avatar
Linus Torvalds committed
623
624
625
626
627
628
629
630
631
/*
 * Check input queue length
 */
static int
svc_recv_available(struct svc_sock *svsk)
{
	struct socket	*sock = svsk->sk_sock;
	int		avail, err;

632
	err = kernel_sock_ioctl(sock, TIOCINQ, (unsigned long) &avail);
Linus Torvalds's avatar
Linus Torvalds committed
633
634
635
636
637
638
639
640
641
642

	return (err >= 0)? avail : err;
}

/*
 * Generic recvfrom routine.
 */
static int
svc_recvfrom(struct svc_rqst *rqstp, struct kvec *iov, int nr, int buflen)
{
643
	struct svc_sock *svsk = rqstp->rq_sock;
644
645
646
	struct msghdr msg = {
		.msg_flags	= MSG_DONTWAIT,
	};
647
	struct sockaddr *sin;
648
	int len;
Linus Torvalds's avatar
Linus Torvalds committed
649

650
651
	len = kernel_recvmsg(svsk->sk_sock, &msg, iov, nr, buflen,
				msg.msg_flags);
Linus Torvalds's avatar
Linus Torvalds committed
652
653
654

	/* sock_recvmsg doesn't fill in the name/namelen, so we must..
	 */
655
656
	memcpy(&rqstp->rq_addr, &svsk->sk_remote, svsk->sk_remotelen);
	rqstp->rq_addrlen = svsk->sk_remotelen;
Linus Torvalds's avatar
Linus Torvalds committed
657

658
659
660
661
662
663
664
665
666
667
668
669
670
	/* Destination address in request is needed for binding the
	 * source address in RPC callbacks later.
	 */
	sin = (struct sockaddr *)&svsk->sk_local;
	switch (sin->sa_family) {
	case AF_INET:
		rqstp->rq_daddr.addr = ((struct sockaddr_in *)sin)->sin_addr;
		break;
	case AF_INET6:
		rqstp->rq_daddr.addr6 = ((struct sockaddr_in6 *)sin)->sin6_addr;
		break;
	}

Linus Torvalds's avatar
Linus Torvalds committed
671
	dprintk("svc: socket %p recvfrom(%p, %Zu) = %d\n",
672
		svsk, iov[0].iov_base, iov[0].iov_len, len);
Linus Torvalds's avatar
Linus Torvalds committed
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708

	return len;
}

/*
 * Set socket snd and rcv buffer lengths
 */
static inline void
svc_sock_setbufsize(struct socket *sock, unsigned int snd, unsigned int rcv)
{
#if 0
	mm_segment_t	oldfs;
	oldfs = get_fs(); set_fs(KERNEL_DS);
	sock_setsockopt(sock, SOL_SOCKET, SO_SNDBUF,
			(char*)&snd, sizeof(snd));
	sock_setsockopt(sock, SOL_SOCKET, SO_RCVBUF,
			(char*)&rcv, sizeof(rcv));
#else
	/* sock_setsockopt limits use to sysctl_?mem_max,
	 * which isn't acceptable.  Until that is made conditional
	 * on not having CAP_SYS_RESOURCE or similar, we go direct...
	 * DaveM said I could!
	 */
	lock_sock(sock->sk);
	sock->sk->sk_sndbuf = snd * 2;
	sock->sk->sk_rcvbuf = rcv * 2;
	sock->sk->sk_userlocks |= SOCK_SNDBUF_LOCK|SOCK_RCVBUF_LOCK;
	release_sock(sock->sk);
#endif
}
/*
 * INET callback when data has been received on the socket.
 */
static void
svc_udp_data_ready(struct sock *sk, int count)
{
709
	struct svc_sock	*svsk = (struct svc_sock *)sk->sk_user_data;
Linus Torvalds's avatar
Linus Torvalds committed
710

711
712
713
714
715
716
	if (svsk) {
		dprintk("svc: socket %p(inet %p), count=%d, busy=%d\n",
			svsk, sk, count, test_bit(SK_BUSY, &svsk->sk_flags));
		set_bit(SK_DATA, &svsk->sk_flags);
		svc_sock_enqueue(svsk);
	}
Linus Torvalds's avatar
Linus Torvalds committed
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
	if (sk->sk_sleep && waitqueue_active(sk->sk_sleep))
		wake_up_interruptible(sk->sk_sleep);
}

/*
 * INET callback when space is newly available on the socket.
 */
static void
svc_write_space(struct sock *sk)
{
	struct svc_sock	*svsk = (struct svc_sock *)(sk->sk_user_data);

	if (svsk) {
		dprintk("svc: socket %p(inet %p), write_space busy=%d\n",
			svsk, sk, test_bit(SK_BUSY, &svsk->sk_flags));
		svc_sock_enqueue(svsk);
	}

	if (sk->sk_sleep && waitqueue_active(sk->sk_sleep)) {
736
		dprintk("RPC svc_write_space: someone sleeping on %p\n",
Linus Torvalds's avatar
Linus Torvalds committed
737
738
739
740
741
		       svsk);
		wake_up_interruptible(sk->sk_sleep);
	}
}

742
743
static inline void svc_udp_get_dest_address(struct svc_rqst *rqstp,
					    struct cmsghdr *cmh)
744
745
746
{
	switch (rqstp->rq_sock->sk_sk->sk_family) {
	case AF_INET: {
747
748
		struct in_pktinfo *pki = CMSG_DATA(cmh);
		rqstp->rq_daddr.addr.s_addr = pki->ipi_spec_dst.s_addr;
749
		break;
750
		}
751
	case AF_INET6: {
752
753
		struct in6_pktinfo *pki = CMSG_DATA(cmh);
		ipv6_addr_copy(&rqstp->rq_daddr.addr6, &pki->ipi6_addr);
754
		break;
755
		}
756
757
758
	}
}

Linus Torvalds's avatar
Linus Torvalds committed
759
760
761
762
763
764
765
766
767
/*
 * Receive a datagram from a UDP socket.
 */
static int
svc_udp_recvfrom(struct svc_rqst *rqstp)
{
	struct svc_sock	*svsk = rqstp->rq_sock;
	struct svc_serv	*serv = svsk->sk_server;
	struct sk_buff	*skb;
768
769
770
771
772
	union {
		struct cmsghdr	hdr;
		long		all[SVC_PKTINFO_SPACE / sizeof(long)];
	} buffer;
	struct cmsghdr *cmh = &buffer.hdr;
Linus Torvalds's avatar
Linus Torvalds committed
773
	int		err, len;
774
775
776
777
778
779
	struct msghdr msg = {
		.msg_name = svc_addr(rqstp),
		.msg_control = cmh,
		.msg_controllen = sizeof(buffer),
		.msg_flags = MSG_DONTWAIT,
	};
Linus Torvalds's avatar
Linus Torvalds committed
780
781
782
783
784

	if (test_and_clear_bit(SK_CHNGBUF, &svsk->sk_flags))
	    /* udp sockets need large rcvbuf as all pending
	     * requests are still in that buffer.  sndbuf must
	     * also be large enough that there is enough space
785
786
787
788
	     * for one reply per thread.  We count all threads
	     * rather than threads in a particular pool, which
	     * provides an upper bound on the number of threads
	     * which will access the socket.
Linus Torvalds's avatar
Linus Torvalds committed
789
790
	     */
	    svc_sock_setbufsize(svsk->sk_sock,
791
792
				(serv->sv_nrthreads+3) * serv->sv_max_mesg,
				(serv->sv_nrthreads+3) * serv->sv_max_mesg);
Linus Torvalds's avatar
Linus Torvalds committed
793
794
795
796
797
798

	if ((rqstp->rq_deferred = svc_deferred_dequeue(svsk))) {
		svc_sock_received(svsk);
		return svc_deferred_recv(rqstp);
	}

799
800
801
802
803
	if (test_bit(SK_CLOSE, &svsk->sk_flags)) {
		svc_delete_socket(svsk);
		return 0;
	}

Linus Torvalds's avatar
Linus Torvalds committed
804
	clear_bit(SK_DATA, &svsk->sk_flags);
805
806
807
808
809
810
811
812
813
814
815
	skb = NULL;
	err = kernel_recvmsg(svsk->sk_sock, &msg, NULL,
			     0, 0, MSG_PEEK | MSG_DONTWAIT);
	if (err >= 0)
		skb = skb_recv_datagram(svsk->sk_sk, 0, 1, &err);

	if (skb == NULL) {
		if (err != -EAGAIN) {
			/* possibly an icmp error */
			dprintk("svc: recvfrom returned error %d\n", -err);
			set_bit(SK_DATA, &svsk->sk_flags);
Linus Torvalds's avatar
Linus Torvalds committed
816
		}
817
818
		svc_sock_received(svsk);
		return -EAGAIN;
Linus Torvalds's avatar
Linus Torvalds committed
819
	}
820
	rqstp->rq_addrlen = sizeof(rqstp->rq_addr);
821
822
	if (skb->tstamp.tv64 == 0) {
		skb->tstamp = ktime_get_real();
823
		/* Don't enable netstamp, sunrpc doesn't
Linus Torvalds's avatar
Linus Torvalds committed
824
825
		   need that much accuracy */
	}
826
	svsk->sk_sk->sk_stamp = skb->tstamp;
Linus Torvalds's avatar
Linus Torvalds committed
827
828
829
830
831
832
833
834
835
836
	set_bit(SK_DATA, &svsk->sk_flags); /* there may be more data... */

	/*
	 * Maybe more packets - kick another thread ASAP.
	 */
	svc_sock_received(svsk);

	len  = skb->len - sizeof(struct udphdr);
	rqstp->rq_arg.len = len;

837
	rqstp->rq_prot = IPPROTO_UDP;
838

839
840
841
842
843
844
845
846
847
848
	if (cmh->cmsg_level != IPPROTO_IP ||
	    cmh->cmsg_type != IP_PKTINFO) {
		if (net_ratelimit())
			printk("rpcsvc: received unknown control message:"
			       "%d/%d\n",
			       cmh->cmsg_level, cmh->cmsg_type);
		skb_free_datagram(svsk->sk_sk, skb);
		return 0;
	}
	svc_udp_get_dest_address(rqstp, cmh);
Linus Torvalds's avatar
Linus Torvalds committed
849
850
851
852
853
854
855
856
857
858
859

	if (skb_is_nonlinear(skb)) {
		/* we have to copy */
		local_bh_disable();
		if (csum_partial_copy_to_xdr(&rqstp->rq_arg, skb)) {
			local_bh_enable();
			/* checksum error */
			skb_free_datagram(svsk->sk_sk, skb);
			return 0;
		}
		local_bh_enable();
860
		skb_free_datagram(svsk->sk_sk, skb);
Linus Torvalds's avatar
Linus Torvalds committed
861
862
863
864
	} else {
		/* we can use it in-place */
		rqstp->rq_arg.head[0].iov_base = skb->data + sizeof(struct udphdr);
		rqstp->rq_arg.head[0].iov_len = len;
865
866
867
		if (skb_checksum_complete(skb)) {
			skb_free_datagram(svsk->sk_sk, skb);
			return 0;
Linus Torvalds's avatar
Linus Torvalds committed
868
869
870
871
872
873
874
875
		}
		rqstp->rq_skbuff = skb;
	}

	rqstp->rq_arg.page_base = 0;
	if (len <= rqstp->rq_arg.head[0].iov_len) {
		rqstp->rq_arg.head[0].iov_len = len;
		rqstp->rq_arg.page_len = 0;
876
		rqstp->rq_respages = rqstp->rq_pages+1;
Linus Torvalds's avatar
Linus Torvalds committed
877
878
	} else {
		rqstp->rq_arg.page_len = len - rqstp->rq_arg.head[0].iov_len;
879
880
		rqstp->rq_respages = rqstp->rq_pages + 1 +
			(rqstp->rq_arg.page_len + PAGE_SIZE - 1)/ PAGE_SIZE;
Linus Torvalds's avatar
Linus Torvalds committed
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
	}

	if (serv->sv_stats)
		serv->sv_stats->netudpcnt++;

	return len;
}

static int
svc_udp_sendto(struct svc_rqst *rqstp)
{
	int		error;

	error = svc_sendto(rqstp, &rqstp->rq_res);
	if (error == -ECONNREFUSED)
		/* ICMP error on earlier request. */
		error = svc_sendto(rqstp, &rqstp->rq_res);

	return error;
}

static void
svc_udp_init(struct svc_sock *svsk)
{
905
906
907
	int one = 1;
	mm_segment_t oldfs;

Linus Torvalds's avatar
Linus Torvalds committed
908
909
910
911
912
913
	svsk->sk_sk->sk_data_ready = svc_udp_data_ready;
	svsk->sk_sk->sk_write_space = svc_write_space;
	svsk->sk_recvfrom = svc_udp_recvfrom;
	svsk->sk_sendto = svc_udp_sendto;

	/* initialise setting must have enough space to
914
	 * receive and respond to one request.
Linus Torvalds's avatar
Linus Torvalds committed
915
916
917
	 * svc_udp_recvfrom will re-adjust if necessary
	 */
	svc_sock_setbufsize(svsk->sk_sock,
918
919
			    3 * svsk->sk_server->sv_max_mesg,
			    3 * svsk->sk_server->sv_max_mesg);
Linus Torvalds's avatar
Linus Torvalds committed
920
921
922

	set_bit(SK_DATA, &svsk->sk_flags); /* might have come in before data_ready set up */
	set_bit(SK_CHNGBUF, &svsk->sk_flags);
923
924
925
926
927
928
929

	oldfs = get_fs();
	set_fs(KERNEL_DS);
	/* make sure we get destination address info */
	svsk->sk_sock->ops->setsockopt(svsk->sk_sock, IPPROTO_IP, IP_PKTINFO,
				       (char __user *)&one, sizeof(one));
	set_fs(oldfs);
Linus Torvalds's avatar
Linus Torvalds committed
930
931
932
933
934
935
936
937
938
}

/*
 * A data_ready event on a listening socket means there's a connection
 * pending. Do not use state_change as a substitute for it.
 */
static void
svc_tcp_listen_data_ready(struct sock *sk, int count_unused)
{
939
	struct svc_sock	*svsk = (struct svc_sock *)sk->sk_user_data;
Linus Torvalds's avatar
Linus Torvalds committed
940
941

	dprintk("svc: socket %p TCP (listen) state change %d\n",
942
		sk, sk->sk_state);
Linus Torvalds's avatar
Linus Torvalds committed
943

944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
	/*
	 * This callback may called twice when a new connection
	 * is established as a child socket inherits everything
	 * from a parent LISTEN socket.
	 * 1) data_ready method of the parent socket will be called
	 *    when one of child sockets become ESTABLISHED.
	 * 2) data_ready method of the child socket may be called
	 *    when it receives data before the socket is accepted.
	 * In case of 2, we should ignore it silently.
	 */
	if (sk->sk_state == TCP_LISTEN) {
		if (svsk) {
			set_bit(SK_CONN, &svsk->sk_flags);
			svc_sock_enqueue(svsk);
		} else
			printk("svc: socket %p: no user data\n", sk);
Linus Torvalds's avatar
Linus Torvalds committed
960
	}
961

Linus Torvalds's avatar
Linus Torvalds committed
962
963
964
965
966
967
968
969
970
971
	if (sk->sk_sleep && waitqueue_active(sk->sk_sleep))
		wake_up_interruptible_all(sk->sk_sleep);
}

/*
 * A state change on a connected socket means it's dying or dead.
 */
static void
svc_tcp_state_change(struct sock *sk)
{
972
	struct svc_sock	*svsk = (struct svc_sock *)sk->sk_user_data;
Linus Torvalds's avatar
Linus Torvalds committed
973
974

	dprintk("svc: socket %p TCP (connected) state change %d (svsk %p)\n",
975
		sk, sk->sk_state, sk->sk_user_data);
Linus Torvalds's avatar
Linus Torvalds committed
976

977
	if (!svsk)
Linus Torvalds's avatar
Linus Torvalds committed
978
		printk("svc: socket %p: no user data\n", sk);
979
980
981
	else {
		set_bit(SK_CLOSE, &svsk->sk_flags);
		svc_sock_enqueue(svsk);
Linus Torvalds's avatar
Linus Torvalds committed
982
983
984
985
986
987
988
989
	}
	if (sk->sk_sleep && waitqueue_active(sk->sk_sleep))
		wake_up_interruptible_all(sk->sk_sleep);
}

static void
svc_tcp_data_ready(struct sock *sk, int count)
{
990
	struct svc_sock *svsk = (struct svc_sock *)sk->sk_user_data;
Linus Torvalds's avatar
Linus Torvalds committed
991
992

	dprintk("svc: socket %p TCP data ready (svsk %p)\n",
993
994
995
996
997
		sk, sk->sk_user_data);
	if (svsk) {
		set_bit(SK_DATA, &svsk->sk_flags);
		svc_sock_enqueue(svsk);
	}
Linus Torvalds's avatar
Linus Torvalds committed
998
999
1000
1001
	if (sk->sk_sleep && waitqueue_active(sk->sk_sleep))
		wake_up_interruptible(sk->sk_sleep);
}

1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
static inline int svc_port_is_privileged(struct sockaddr *sin)
{
	switch (sin->sa_family) {
	case AF_INET:
		return ntohs(((struct sockaddr_in *)sin)->sin_port)
			< PROT_SOCK;
	case AF_INET6:
		return ntohs(((struct sockaddr_in6 *)sin)->sin6_port)
			< PROT_SOCK;
	default:
		return 0;
	}
}

Linus Torvalds's avatar
Linus Torvalds committed
1016
1017
1018
1019
1020
1021
/*
 * Accept a TCP connection
 */
static void
svc_tcp_accept(struct svc_sock *svsk)
{
1022
1023
	struct sockaddr_storage addr;
	struct sockaddr	*sin = (struct sockaddr *) &addr;
Linus Torvalds's avatar
Linus Torvalds committed
1024
1025
1026
1027
1028
	struct svc_serv	*serv = svsk->sk_server;
	struct socket	*sock = svsk->sk_sock;
	struct socket	*newsock;
	struct svc_sock	*newsvsk;
	int		err, slen;
1029
	char		buf[RPC_MAX_ADDRBUFLEN];
Linus Torvalds's avatar
Linus Torvalds committed
1030
1031
1032
1033
1034

	dprintk("svc: tcp_accept %p sock %p\n", svsk, sock);
	if (!sock)
		return;

1035
1036
1037
	clear_bit(SK_CONN, &svsk->sk_flags);
	err = kernel_accept(sock, &newsock, O_NONBLOCK);
	if (err < 0) {
Linus Torvalds's avatar
Linus Torvalds committed
1038
1039
1040
		if (err == -ENOMEM)
			printk(KERN_WARNING "%s: no more sockets!\n",
			       serv->sv_name);
1041
		else if (err != -EAGAIN && net_ratelimit())
Linus Torvalds's avatar
Linus Torvalds committed
1042
1043
			printk(KERN_WARNING "%s: accept failed (err %d)!\n",
				   serv->sv_name, -err);
1044
		return;
Linus Torvalds's avatar
Linus Torvalds committed
1045
	}
1046

Linus Torvalds's avatar
Linus Torvalds committed
1047
1048
1049
	set_bit(SK_CONN, &svsk->sk_flags);
	svc_sock_enqueue(svsk);

1050
	err = kernel_getpeername(newsock, sin, &slen);
Linus Torvalds's avatar
Linus Torvalds committed
1051
1052
1053
1054
1055
1056
1057
1058
	if (err < 0) {
		if (net_ratelimit())
			printk(KERN_WARNING "%s: peername failed (err %d)!\n",
				   serv->sv_name, -err);
		goto failed;		/* aborted connection or whatever */
	}

	/* Ideally, we would want to reject connections from unauthorized
1059
1060
	 * hosts here, but when we get encryption, the IP of the host won't
	 * tell us anything.  For now just warn about unpriv connections.
Linus Torvalds's avatar
Linus Torvalds committed
1061
	 */
1062
	if (!svc_port_is_privileged(sin)) {
Linus Torvalds's avatar
Linus Torvalds committed
1063
		dprintk(KERN_WARNING
1064
			"%s: connect from unprivileged port: %s\n",
1065
			serv->sv_name,
1066
			__svc_print_addr(sin, buf, sizeof(buf)));
Linus Torvalds's avatar
Linus Torvalds committed
1067
	}
1068
	dprintk("%s: connect from %s\n", serv->sv_name,
1069
		__svc_print_addr(sin, buf, sizeof(buf)));
Linus Torvalds's avatar
Linus Torvalds committed
1070
1071
1072
1073
1074
1075

	/* make sure that a write doesn't block forever when
	 * low on memory
	 */
	newsock->sk->sk_sndtimeo = HZ*30;

1076
1077
	if (!(newsvsk = svc_setup_socket(serv, newsock, &err,
				 (SVC_SOCK_ANONYMOUS | SVC_SOCK_TEMPORARY))))
Linus Torvalds's avatar
Linus Torvalds committed
1078
		goto failed;
1079
	memcpy(&newsvsk->sk_remote, sin, slen);
1080
	newsvsk->sk_remotelen = slen;
1081
1082
1083
1084
1085
1086
	err = kernel_getsockname(newsock, sin, &slen);
	if (unlikely(err < 0)) {
		dprintk("svc_tcp_accept: kernel_getsockname error %d\n", -err);
		slen = offsetof(struct sockaddr, sa_data);
	}
	memcpy(&newsvsk->sk_local, sin, slen);
1087

1088
	svc_sock_received(newsvsk);
Linus Torvalds's avatar
Linus Torvalds committed
1089
1090
1091
1092
1093
1094
1095
1096
1097
1098
1099
1100
1101
1102
1103
1104
1105
1106
1107
1108
1109
1110

	/* make sure that we don't have too many active connections.
	 * If we have, something must be dropped.
	 *
	 * There's no point in trying to do random drop here for
	 * DoS prevention. The NFS clients does 1 reconnect in 15
	 * seconds. An attacker can easily beat that.
	 *
	 * The only somewhat efficient mechanism would be if drop
	 * old connections from the same IP first. But right now
	 * we don't even record the client IP in svc_sock.
	 */
	if (serv->sv_tmpcnt > (serv->sv_nrthreads+3)*20) {
		struct svc_sock *svsk = NULL;
		spin_lock_bh(&serv->sv_lock);
		if (!list_empty(&serv->sv_tempsocks)) {
			if (net_ratelimit()) {
				/* Try to help the admin */
				printk(KERN_NOTICE "%s: too many open TCP "
					"sockets, consider increasing the "
					"number of nfsd threads\n",
						   serv->sv_name);
1111
1112
1113
				printk(KERN_NOTICE
				       "%s: last TCP connect from %s\n",
				       serv->sv_name, buf);
Linus Torvalds's avatar
Linus Torvalds committed
1114
1115
1116
1117
1118
1119
1120
1121
1122
			}
			/*
			 * Always select the oldest socket. It's not fair,
			 * but so is life
			 */
			svsk = list_entry(serv->sv_tempsocks.prev,
					  struct svc_sock,
					  sk_list);
			set_bit(SK_CLOSE, &svsk->sk_flags);
1123
			atomic_inc(&svsk->sk_inuse);
Linus Torvalds's avatar
Linus Torvalds committed
1124
1125
1126
1127
1128
1129
1130
1131
1132
1133
1134
1135
1136
1137
1138
1139
1140
1141
1142
1143
1144
1145
1146
1147
1148
1149
1150
1151
1152
		}
		spin_unlock_bh(&serv->sv_lock);

		if (svsk) {
			svc_sock_enqueue(svsk);
			svc_sock_put(svsk);
		}

	}

	if (serv->sv_stats)
		serv->sv_stats->nettcpconn++;

	return;

failed:
	sock_release(newsock);
	return;
}

/*
 * Receive data from a TCP socket.
 */
static int
svc_tcp_recvfrom(struct svc_rqst *rqstp)
{
	struct svc_sock	*svsk = rqstp->rq_sock;
	struct svc_serv	*serv = svsk->sk_server;
	int		len;
1153
	struct kvec *vec;
Linus Torvalds's avatar
Linus Torvalds committed
1154
1155
1156
1157
1158
1159
1160
1161
1162
1163
1164
1165
1166
1167
1168
1169
1170
	int pnum, vlen;

	dprintk("svc: tcp_recv %p data %d conn %d close %d\n",
		svsk, test_bit(SK_DATA, &svsk->sk_flags),
		test_bit(SK_CONN, &svsk->sk_flags),
		test_bit(SK_CLOSE, &svsk->sk_flags));

	if ((rqstp->rq_deferred = svc_deferred_dequeue(svsk))) {
		svc_sock_received(svsk);
		return svc_deferred_recv(rqstp);
	}

	if (test_bit(SK_CLOSE, &svsk->sk_flags)) {
		svc_delete_socket(svsk);
		return 0;
	}

1171
	if (svsk->sk_sk->sk_state == TCP_LISTEN) {
Linus Torvalds's avatar
Linus Torvalds committed
1172
1173
1174
1175
1176
1177
1178
1179
1180
		svc_tcp_accept(svsk);
		svc_sock_received(svsk);
		return 0;
	}

	if (test_and_clear_bit(SK_CHNGBUF, &svsk->sk_flags))
		/* sndbuf needs to have room for one request
		 * per thread, otherwise we can stall even when the
		 * network isn't a bottleneck.
1181
1182
1183
1184
1185
		 *
		 * We count all threads rather than threads in a
		 * particular pool, which provides an upper bound
		 * on the number of threads which will access the socket.
		 *
Linus Torvalds's avatar
Linus Torvalds committed
1186
		 * rcvbuf just needs to be able to hold a few requests.
1187
		 * Normally they will be removed from the queue
Linus Torvalds's avatar
Linus Torvalds committed
1188
1189
1190
		 * as soon a a complete request arrives.
		 */
		svc_sock_setbufsize(svsk->sk_sock,
1191
1192
				    (serv->sv_nrthreads+3) * serv->sv_max_mesg,
				    3 * serv->sv_max_mesg);
Linus Torvalds's avatar
Linus Torvalds committed
1193
1194
1195
1196
1197
1198
1199
1200
1201
1202
1203
1204
1205
1206
1207
1208
1209
1210
1211

	clear_bit(SK_DATA, &svsk->sk_flags);

	/* Receive data. If we haven't got the record length yet, get
	 * the next four bytes. Otherwise try to gobble up as much as
	 * possible up to the complete record length.
	 */
	if (svsk->sk_tcplen < 4) {
		unsigned long	want = 4 - svsk->sk_tcplen;
		struct kvec	iov;

		iov.iov_base = ((char *) &svsk->sk_reclen) + svsk->sk_tcplen;
		iov.iov_len  = want;
		if ((len = svc_recvfrom(rqstp, &iov, 1, want)) < 0)
			goto error;
		svsk->sk_tcplen += len;

		if (len < want) {
			dprintk("svc: short recvfrom while reading record length (%d of %lu)\n",
1212
				len, want);
Linus Torvalds's avatar
Linus Torvalds committed
1213
1214
1215
1216
1217
1218
1219
1220
1221
1222
1223
			svc_sock_received(svsk);
			return -EAGAIN; /* record header not complete */
		}

		svsk->sk_reclen = ntohl(svsk->sk_reclen);
		if (!(svsk->sk_reclen & 0x80000000)) {
			/* FIXME: technically, a record can be fragmented,
			 *  and non-terminal fragments will not have the top
			 *  bit set in the fragment length header.
			 *  But apparently no known nfs clients send fragmented
			 *  records. */
1224
1225
1226
1227
			if (net_ratelimit())
				printk(KERN_NOTICE "RPC: bad TCP reclen 0x%08lx"
				       " (non-terminal)\n",
				       (unsigned long) svsk->sk_reclen);
Linus Torvalds's avatar
Linus Torvalds committed
1228
1229
1230
1231
			goto err_delete;
		}
		svsk->sk_reclen &= 0x7fffffff;
		dprintk("svc: TCP record, %d bytes\n", svsk->sk_reclen);
1232
		if (svsk->sk_reclen > serv->sv_max_mesg) {
1233
1234
1235
1236
			if (net_ratelimit())
				printk(KERN_NOTICE "RPC: bad TCP reclen 0x%08lx"
				       " (large)\n",
				       (unsigned long) svsk->sk_reclen);
Linus Torvalds's avatar
Linus Torvalds committed
1237
1238
1239
1240
1241
1242
1243
1244
1245
1246
1247
1248
1249
1250
1251
1252
1253
1254
			goto err_delete;
		}
	}

	/* Check whether enough data is available */
	len = svc_recv_available(svsk);
	if (len < 0)
		goto error;

	if (len < svsk->sk_reclen) {
		dprintk("svc: incomplete TCP record (%d of %d)\n",
			len, svsk->sk_reclen);
		svc_sock_received(svsk);
		return -EAGAIN;	/* record not complete */
	}
	len = svsk->sk_reclen;
	set_bit(SK_DATA, &svsk->sk_flags);

1255
	vec = rqstp->rq_vec;
Linus Torvalds's avatar
Linus Torvalds committed
1256
1257
1258
1259
	vec[0] = rqstp->rq_arg.head[0];
	vlen = PAGE_SIZE;
	pnum = 1;
	while (vlen < len) {
1260
		vec[pnum].iov_base = page_address(rqstp->rq_pages[pnum]);
Linus Torvalds's avatar
Linus Torvalds committed
1261
1262
1263
1264
		vec[pnum].iov_len = PAGE_SIZE;
		pnum++;
		vlen += PAGE_SIZE;
	}
1265
	rqstp->rq_respages = &rqstp->rq_pages[pnum];
Linus Torvalds's avatar
Linus Torvalds committed
1266
1267
1268
1269
1270
1271
1272
1273
1274
1275
1276
1277
1278
1279
1280
1281
1282
1283
1284
1285
1286
1287
1288
1289
1290
1291
1292
1293
1294
1295
1296
1297
1298
1299
1300
1301
1302
1303
1304
1305

	/* Now receive data */
	len = svc_recvfrom(rqstp, vec, pnum, len);
	if (len < 0)
		goto error;

	dprintk("svc: TCP complete record (%d bytes)\n", len);
	rqstp->rq_arg.len = len;
	rqstp->rq_arg.page_base = 0;
	if (len <= rqstp->rq_arg.head[0].iov_len) {
		rqstp->rq_arg.head[0].iov_len = len;
		rqstp->rq_arg.page_len = 0;
	} else {
		rqstp->rq_arg.page_len = len - rqstp->rq_arg.head[0].iov_len;
	}

	rqstp->rq_skbuff      = NULL;
	rqstp->rq_prot	      = IPPROTO_TCP;

	/* Reset TCP read info */
	svsk->sk_reclen = 0;
	svsk->sk_tcplen = 0;

	svc_sock_received(svsk);
	if (serv->sv_stats)
		serv->sv_stats->nettcpcnt++;

	return len;

 err_delete:
	svc_delete_socket(svsk);
	return -EAGAIN;

 error:
	if (len == -EAGAIN) {
		dprintk("RPC: TCP recvfrom got EAGAIN\n");
		svc_sock_received(svsk);
	} else {
		printk(KERN_NOTICE "%s: recvfrom returned errno %d\n",
					svsk->sk_server->sv_name, -len);
1306
		goto err_delete;
Linus Torvalds's avatar
Linus Torvalds committed
1307
1308
1309
1310
1311
1312
1313
1314
1315
1316
1317
1318
1319
	}

	return len;
}

/*
 * Send out data on TCP socket.
 */
static int
svc_tcp_sendto(struct svc_rqst *rqstp)
{
	struct xdr_buf	*xbufp = &rqstp->rq_res;
	int sent;
1320
	__be32 reclen;
Linus Torvalds's avatar
Linus Torvalds committed
1321
1322
1323
1324
1325
1326
1327
1328
1329
1330
1331
1332
1333
1334
1335
1336
1337

	/* Set up the first element of the reply kvec.
	 * Any other kvecs that may be in use have been taken
	 * care of by the server implementation itself.
	 */
	reclen = htonl(0x80000000|((xbufp->len ) - 4));
	memcpy(xbufp->head[0].iov_base, &reclen, 4);

	if (test_bit(SK_DEAD, &rqstp->rq_sock->sk_flags))
		return -ENOTCONN;

	sent = svc_sendto(rqstp, &rqstp->rq_res);
	if (sent != xbufp->len) {
		printk(KERN_NOTICE "rpc-srv/tcp: %s: %s %d when sending %d bytes - shutting down socket\n",
		       rqstp->rq_sock->sk_server->sv_name,
		       (sent<0)?"got error":"sent only",
		       sent, xbufp->len);
1338
1339
		set_bit(SK_CLOSE, &rqstp->rq_sock->sk_flags);
		svc_sock_enqueue(rqstp->rq_sock);
Linus Torvalds's avatar
Linus Torvalds committed
1340
1341
1342
1343
1344
1345
1346
1347
1348
1349
1350
1351
1352
1353
1354
1355
1356
1357
1358
1359
1360
1361
1362
1363
1364
1365
1366
1367
1368
1369
		sent = -EAGAIN;
	}
	return sent;
}

static void
svc_tcp_init(struct svc_sock *svsk)
{
	struct sock	*sk = svsk->sk_sk;
	struct tcp_sock *tp = tcp_sk(sk);

	svsk->sk_recvfrom = svc_tcp_recvfrom;
	svsk->sk_sendto = svc_tcp_sendto;

	if (sk->sk_state == TCP_LISTEN) {
		dprintk("setting up TCP socket for listening\n");
		sk->sk_data_ready = svc_tcp_listen_data_ready;
		set_bit(SK_CONN, &svsk->sk_flags);
	} else {
		dprintk("setting up TCP socket for reading\n");
		sk->sk_state_change = svc_tcp_state_change;
		sk->sk_data_ready = svc_tcp_data_ready;
		sk->sk_write_space = svc_write_space;

		svsk->sk_reclen = 0;
		svsk->sk_tcplen = 0;

		tp->nonagle = 1;        /* disable Nagle's algorithm */

		/* initialise setting must have enough space to
1370
		 * receive and respond to one request.
Linus Torvalds's avatar
Linus Torvalds committed
1371
1372
1373
		 * svc_tcp_recvfrom will re-adjust if necessary
		 */
		svc_sock_setbufsize(svsk->sk_sock,
1374
1375
				    3 * svsk->sk_server->sv_max_mesg,
				    3 * svsk->sk_server->sv_max_mesg);
Linus Torvalds's avatar
Linus Torvalds committed
1376
1377
1378

		set_bit(SK_CHNGBUF, &svsk->sk_flags);
		set_bit(SK_DATA, &svsk->sk_flags);
1379
		if (sk->sk_state != TCP_ESTABLISHED)
Linus Torvalds's avatar
Linus Torvalds committed
1380
1381
1382
1383
1384
1385
1386
1387
1388
1389
1390
1391
1392
1393
1394
			set_bit(SK_CLOSE, &svsk->sk_flags);
	}
}

void
svc_sock_update_bufs(struct svc_serv *serv)
{
	/*
	 * The number of server threads has changed. Update
	 * rcvbuf and sndbuf accordingly on all sockets
	 */
	struct list_head *le;

	spin_lock_bh(&serv->sv_lock);
	list_for_each(le, &serv->sv_permsocks) {
1395
		struct svc_sock *svsk =
Linus Torvalds's avatar
Linus Torvalds committed
1396
1397
1398
1399
1400
1401
1402
1403
1404
1405
1406
1407
			list_entry(le, struct svc_sock, sk_list);
		set_bit(SK_CHNGBUF, &svsk->sk_flags);
	}
	list_for_each(le, &serv->sv_tempsocks) {
		struct svc_sock *svsk =
			list_entry(le, struct svc_sock, sk_list);
		set_bit(SK_CHNGBUF, &svsk->sk_flags);
	}
	spin_unlock_bh(&serv->sv_lock);
}

/*
1408
1409
1410
 * Receive the next request on any socket.  This code is carefully
 * organised not to touch any cachelines in the shared svc_serv
 * structure, only cachelines in the local svc_pool.
Linus Torvalds's avatar
Linus Torvalds committed
1411
1412
 */
int
1413
svc_recv(struct svc_rqst *rqstp, long timeout)
Linus Torvalds's avatar
Linus Torvalds committed
1414
{
1415
	struct svc_sock		*svsk = NULL;
1416
	struct svc_serv		*serv = rqstp->rq_server;
1417
	struct svc_pool		*pool = rqstp->rq_pool;
1418
	int			len, i;
Linus Torvalds's avatar
Linus Torvalds committed
1419
1420
1421
1422
1423
1424
1425
1426
	int 			pages;
	struct xdr_buf		*arg;
	DECLARE_WAITQUEUE(wait, current);

	dprintk("svc: server %p waiting for data (to = %ld)\n",
		rqstp, timeout);

	if (rqstp->rq_sock)
1427
		printk(KERN_ERR
Linus Torvalds's avatar
Linus Torvalds committed
1428
1429
1430
			"svc_recv: service %p, socket not NULL!\n",
			 rqstp);
	if (waitqueue_active(&rqstp->rq_wait))
1431
		printk(KERN_ERR
Linus Torvalds's avatar
Linus Torvalds committed
1432
1433
1434
1435
1436
			"svc_recv: service %p, wait queue active!\n",
			 rqstp);


	/* now allocate needed pages.  If we get a failure, sleep briefly */
1437
	pages = (serv->sv_max_mesg + PAGE_SIZE) / PAGE_SIZE;
1438
1439
1440
1441
1442
1443
	for (i=0; i < pages ; i++)
		while (rqstp->rq_pages[i] == NULL) {
			struct page *p = alloc_page(GFP_KERNEL);
			if (!p)
				schedule_timeout_uninterruptible(msecs_to_jiffies(500));
			rqstp->rq_pages[i] = p;
Linus Torvalds's avatar
Linus Torvalds committed
1444
		}
1445
1446
	rqstp->rq_pages[i++] = NULL; /* this might be seen in nfs_read_actor */
	BUG_ON(pages >= RPCSVC_MAXPAGES);
Linus Torvalds's avatar
Linus Torvalds committed
1447
1448
1449

	/* Make arg->head point to first page and arg->pages point to rest */
	arg = &rqstp->rq_arg;
1450
	arg->head[0].iov_base = page_address(rqstp->rq_pages[0]);
Linus Torvalds's avatar
Linus Torvalds committed
1451
	arg->head[0].iov_len = PAGE_SIZE;
1452
	arg->pages = rqstp->rq_pages + 1;
Linus Torvalds's avatar
Linus Torvalds committed
1453
1454
1455
1456
1457
	arg->page_base = 0;
	/* save at least one page for response */
	arg->page_len = (pages-2)*PAGE_SIZE;
	arg->len = (pages-1)*PAGE_SIZE;
	arg->tail[0].iov_len = 0;
1458
1459

	try_to_freeze();
1460
	cond_resched();
Linus Torvalds's avatar
Linus Torvalds committed
1461
1462
1463
	if (signalled())
		return -EINTR;

1464
1465
	spin_lock_bh(&pool->sp_lock);
	if ((svsk = svc_sock_dequeue(pool)) != NULL) {
Linus Torvalds's avatar
Linus Torvalds committed
1466
		rqstp->rq_sock = svsk;
1467
		atomic_inc(&svsk->sk_inuse);
1468
		rqstp->rq_reserved = serv->sv_max_mesg;
1469
		atomic_add(rqstp->rq_reserved, &svsk->sk_reserved);
Linus Torvalds's avatar
Linus Torvalds committed
1470
1471
	} else {
		/* No data pending. Go to sleep */
1472
		svc_thread_enqueue(pool, rqstp);
Linus Torvalds's avatar
Linus Torvalds committed
1473
1474
1475
1476
1477
1478
1479

		/*
		 * We have to be able to interrupt this wait
		 * to bring down the daemons ...
		 */
		set_current_state(TASK_INTERRUPTIBLE);
		add_wait_queue(&rqstp->rq_wait, &wait);
1480
		spin_unlock_bh(&pool->sp_lock);