xref: /spdk/lib/nvmf/tcp.c (revision 0ecbe09bc18245c46ebf6a3aae64ce64ea26c067)
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright (c) Intel Corporation. All rights reserved.
5  *   Copyright (c) 2019, 2020 Mellanox Technologies LTD. All rights reserved.
6  *
7  *   Redistribution and use in source and binary forms, with or without
8  *   modification, are permitted provided that the following conditions
9  *   are met:
10  *
11  *     * Redistributions of source code must retain the above copyright
12  *       notice, this list of conditions and the following disclaimer.
13  *     * Redistributions in binary form must reproduce the above copyright
14  *       notice, this list of conditions and the following disclaimer in
15  *       the documentation and/or other materials provided with the
16  *       distribution.
17  *     * Neither the name of Intel Corporation nor the names of its
18  *       contributors may be used to endorse or promote products derived
19  *       from this software without specific prior written permission.
20  *
21  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
22  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
23  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
24  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
25  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
26  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
27  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33 
34 #include "spdk/accel_engine.h"
35 #include "spdk/stdinc.h"
36 #include "spdk/crc32.h"
37 #include "spdk/endian.h"
38 #include "spdk/assert.h"
39 #include "spdk/thread.h"
40 #include "spdk/nvmf_transport.h"
41 #include "spdk/string.h"
42 #include "spdk/trace.h"
43 #include "spdk/util.h"
44 #include "spdk/log.h"
45 
46 #include "spdk_internal/assert.h"
47 #include "spdk_internal/nvme_tcp.h"
48 #include "spdk_internal/sock.h"
49 
50 #include "nvmf_internal.h"
51 
52 #include "spdk_internal/trace_defs.h"
53 
54 #define NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME 16
55 #define SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY 16
56 #define SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY 0
57 #define SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM 32
58 #define SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION true
59 
60 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp;
61 
62 /* spdk nvmf related structure */
63 enum spdk_nvmf_tcp_req_state {
64 
65 	/* The request is not currently in use */
66 	TCP_REQUEST_STATE_FREE = 0,
67 
68 	/* Initial state when request first received */
69 	TCP_REQUEST_STATE_NEW,
70 
71 	/* The request is queued until a data buffer is available. */
72 	TCP_REQUEST_STATE_NEED_BUFFER,
73 
74 	/* The request is currently transferring data from the host to the controller. */
75 	TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
76 
77 	/* The request is waiting for the R2T send acknowledgement. */
78 	TCP_REQUEST_STATE_AWAITING_R2T_ACK,
79 
80 	/* The request is ready to execute at the block device */
81 	TCP_REQUEST_STATE_READY_TO_EXECUTE,
82 
83 	/* The request is currently executing at the block device */
84 	TCP_REQUEST_STATE_EXECUTING,
85 
86 	/* The request finished executing at the block device */
87 	TCP_REQUEST_STATE_EXECUTED,
88 
89 	/* The request is ready to send a completion */
90 	TCP_REQUEST_STATE_READY_TO_COMPLETE,
91 
92 	/* The request is currently transferring final pdus from the controller to the host. */
93 	TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
94 
95 	/* The request completed and can be marked free. */
96 	TCP_REQUEST_STATE_COMPLETED,
97 
98 	/* Terminator */
99 	TCP_REQUEST_NUM_STATES,
100 };
101 
102 static const char *spdk_nvmf_tcp_term_req_fes_str[] = {
103 	"Invalid PDU Header Field",
104 	"PDU Sequence Error",
105 	"Header Digiest Error",
106 	"Data Transfer Out of Range",
107 	"R2T Limit Exceeded",
108 	"Unsupported parameter",
109 };
110 
111 SPDK_TRACE_REGISTER_FN(nvmf_tcp_trace, "nvmf_tcp", TRACE_GROUP_NVMF_TCP)
112 {
113 	spdk_trace_register_object(OBJECT_NVMF_TCP_IO, 'r');
114 	spdk_trace_register_description("TCP_REQ_NEW",
115 					TRACE_TCP_REQUEST_STATE_NEW,
116 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 1,
117 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
118 	spdk_trace_register_description("TCP_REQ_NEED_BUFFER",
119 					TRACE_TCP_REQUEST_STATE_NEED_BUFFER,
120 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
121 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
122 	spdk_trace_register_description("TCP_REQ_TX_H_TO_C",
123 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
124 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
125 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
126 	spdk_trace_register_description("TCP_REQ_RDY_TO_EXECUTE",
127 					TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE,
128 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
129 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
130 	spdk_trace_register_description("TCP_REQ_EXECUTING",
131 					TRACE_TCP_REQUEST_STATE_EXECUTING,
132 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
133 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
134 	spdk_trace_register_description("TCP_REQ_EXECUTED",
135 					TRACE_TCP_REQUEST_STATE_EXECUTED,
136 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
137 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
138 	spdk_trace_register_description("TCP_REQ_RDY_TO_COMPLETE",
139 					TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE,
140 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
141 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
142 	spdk_trace_register_description("TCP_REQ_TRANSFER_C2H",
143 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
144 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
145 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
146 	spdk_trace_register_description("TCP_REQ_COMPLETED",
147 					TRACE_TCP_REQUEST_STATE_COMPLETED,
148 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
149 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
150 	spdk_trace_register_description("TCP_WRITE_START",
151 					TRACE_TCP_FLUSH_WRITEBUF_START,
152 					OWNER_NONE, OBJECT_NONE, 0,
153 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
154 	spdk_trace_register_description("TCP_WRITE_DONE",
155 					TRACE_TCP_FLUSH_WRITEBUF_DONE,
156 					OWNER_NONE, OBJECT_NONE, 0,
157 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
158 	spdk_trace_register_description("TCP_READ_DONE",
159 					TRACE_TCP_READ_FROM_SOCKET_DONE,
160 					OWNER_NONE, OBJECT_NONE, 0,
161 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
162 	spdk_trace_register_description("TCP_REQ_AWAIT_R2T_ACK",
163 					TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK,
164 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
165 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
166 
167 	spdk_trace_register_description("TCP_QP_CREATE", TRACE_TCP_QP_CREATE,
168 					OWNER_NONE, OBJECT_NONE, 0,
169 					SPDK_TRACE_ARG_TYPE_INT, "");
170 	spdk_trace_register_description("TCP_QP_SOCK_INIT", TRACE_TCP_QP_SOCK_INIT,
171 					OWNER_NONE, OBJECT_NONE, 0,
172 					SPDK_TRACE_ARG_TYPE_INT, "");
173 	spdk_trace_register_description("TCP_QP_STATE_CHANGE", TRACE_TCP_QP_STATE_CHANGE,
174 					OWNER_NONE, OBJECT_NONE, 0,
175 					SPDK_TRACE_ARG_TYPE_INT, "state");
176 	spdk_trace_register_description("TCP_QP_DISCONNECT", TRACE_TCP_QP_DISCONNECT,
177 					OWNER_NONE, OBJECT_NONE, 0,
178 					SPDK_TRACE_ARG_TYPE_INT, "");
179 	spdk_trace_register_description("TCP_QP_DESTROY", TRACE_TCP_QP_DESTROY,
180 					OWNER_NONE, OBJECT_NONE, 0,
181 					SPDK_TRACE_ARG_TYPE_INT, "");
182 	spdk_trace_register_description("TCP_QP_ABORT_REQ", TRACE_TCP_QP_ABORT_REQ,
183 					OWNER_NONE, OBJECT_NONE, 0,
184 					SPDK_TRACE_ARG_TYPE_INT, "");
185 	spdk_trace_register_description("TCP_QP_RECV_STATE_CHANGE", TRACE_TCP_QP_RECV_STATE_CHANGE,
186 					OWNER_NONE, OBJECT_NONE, 0,
187 					SPDK_TRACE_ARG_TYPE_INT, "state");
188 }
189 
190 struct spdk_nvmf_tcp_req  {
191 	struct spdk_nvmf_request		req;
192 	struct spdk_nvme_cpl			rsp;
193 	struct spdk_nvme_cmd			cmd;
194 
195 	/* A PDU that can be used for sending responses. This is
196 	 * not the incoming PDU! */
197 	struct nvme_tcp_pdu			*pdu;
198 
199 	/* In-capsule data buffer */
200 	uint8_t					*buf;
201 	/*
202 	 * The PDU for a request may be used multiple times in serial over
203 	 * the request's lifetime. For example, first to send an R2T, then
204 	 * to send a completion. To catch mistakes where the PDU is used
205 	 * twice at the same time, add a debug flag here for init/fini.
206 	 */
207 	bool					pdu_in_use;
208 	bool					has_incapsule_data;
209 
210 	/* transfer_tag */
211 	uint16_t				ttag;
212 
213 	enum spdk_nvmf_tcp_req_state		state;
214 
215 	/*
216 	 * h2c_offset is used when we receive the h2c_data PDU.
217 	 */
218 	uint32_t				h2c_offset;
219 
220 	STAILQ_ENTRY(spdk_nvmf_tcp_req)		link;
221 	TAILQ_ENTRY(spdk_nvmf_tcp_req)		state_link;
222 };
223 
224 struct spdk_nvmf_tcp_qpair {
225 	struct spdk_nvmf_qpair			qpair;
226 	struct spdk_nvmf_tcp_poll_group		*group;
227 	struct spdk_sock			*sock;
228 
229 	enum nvme_tcp_pdu_recv_state		recv_state;
230 	enum nvme_tcp_qpair_state		state;
231 
232 	/* PDU being actively received */
233 	struct nvme_tcp_pdu			*pdu_in_progress;
234 
235 	/* Queues to track the requests in all states */
236 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_working_queue;
237 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_free_queue;
238 
239 	/* Number of requests in each state */
240 	uint32_t				state_cntr[TCP_REQUEST_NUM_STATES];
241 
242 	uint8_t					cpda;
243 
244 	bool					host_hdgst_enable;
245 	bool					host_ddgst_enable;
246 
247 	/* This is a spare PDU used for sending special management
248 	 * operations. Primarily, this is used for the initial
249 	 * connection response and c2h termination request. */
250 	struct nvme_tcp_pdu			*mgmt_pdu;
251 
252 	/* Arrays of in-capsule buffers, requests, and pdus.
253 	 * Each array is 'resource_count' number of elements */
254 	void					*bufs;
255 	struct spdk_nvmf_tcp_req		*reqs;
256 	struct nvme_tcp_pdu			*pdus;
257 	uint32_t				resource_count;
258 	uint32_t				recv_buf_size;
259 
260 	struct spdk_nvmf_tcp_port		*port;
261 
262 	/* IP address */
263 	char					initiator_addr[SPDK_NVMF_TRADDR_MAX_LEN];
264 	char					target_addr[SPDK_NVMF_TRADDR_MAX_LEN];
265 
266 	/* IP port */
267 	uint16_t				initiator_port;
268 	uint16_t				target_port;
269 
270 	/* Timer used to destroy qpair after detecting transport error issue if initiator does
271 	 *  not close the connection.
272 	 */
273 	struct spdk_poller			*timeout_poller;
274 
275 
276 	TAILQ_ENTRY(spdk_nvmf_tcp_qpair)	link;
277 };
278 
279 struct spdk_nvmf_tcp_control_msg {
280 	STAILQ_ENTRY(spdk_nvmf_tcp_control_msg) link;
281 };
282 
283 struct spdk_nvmf_tcp_control_msg_list {
284 	void *msg_buf;
285 	STAILQ_HEAD(, spdk_nvmf_tcp_control_msg) free_msgs;
286 };
287 
288 struct spdk_nvmf_tcp_poll_group {
289 	struct spdk_nvmf_transport_poll_group	group;
290 	struct spdk_sock_group			*sock_group;
291 
292 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	qpairs;
293 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	await_req;
294 
295 	struct spdk_io_channel			*accel_channel;
296 	struct spdk_nvmf_tcp_control_msg_list	*control_msg_list;
297 };
298 
299 struct spdk_nvmf_tcp_port {
300 	const struct spdk_nvme_transport_id	*trid;
301 	struct spdk_sock			*listen_sock;
302 	TAILQ_ENTRY(spdk_nvmf_tcp_port)		link;
303 };
304 
305 struct tcp_transport_opts {
306 	bool		c2h_success;
307 	uint16_t	control_msg_num;
308 	uint32_t	sock_priority;
309 };
310 
311 struct spdk_nvmf_tcp_transport {
312 	struct spdk_nvmf_transport		transport;
313 	struct tcp_transport_opts               tcp_opts;
314 
315 	pthread_mutex_t				lock;
316 
317 	TAILQ_HEAD(, spdk_nvmf_tcp_port)	ports;
318 };
319 
320 static const struct spdk_json_object_decoder tcp_transport_opts_decoder[] = {
321 	{
322 		"c2h_success", offsetof(struct tcp_transport_opts, c2h_success),
323 		spdk_json_decode_bool, true
324 	},
325 	{
326 		"control_msg_num", offsetof(struct tcp_transport_opts, control_msg_num),
327 		spdk_json_decode_uint16, true
328 	},
329 	{
330 		"sock_priority", offsetof(struct tcp_transport_opts, sock_priority),
331 		spdk_json_decode_uint32, true
332 	},
333 };
334 
335 static bool nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
336 				 struct spdk_nvmf_tcp_req *tcp_req);
337 static void nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group);
338 
339 static void _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
340 				    struct spdk_nvmf_tcp_req *tcp_req);
341 
342 static void
343 nvmf_tcp_req_set_state(struct spdk_nvmf_tcp_req *tcp_req,
344 		       enum spdk_nvmf_tcp_req_state state)
345 {
346 	struct spdk_nvmf_qpair *qpair;
347 	struct spdk_nvmf_tcp_qpair *tqpair;
348 
349 	qpair = tcp_req->req.qpair;
350 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
351 
352 	assert(tqpair->state_cntr[tcp_req->state] > 0);
353 	tqpair->state_cntr[tcp_req->state]--;
354 	tqpair->state_cntr[state]++;
355 
356 	tcp_req->state = state;
357 }
358 
359 static inline struct nvme_tcp_pdu *
360 nvmf_tcp_req_pdu_init(struct spdk_nvmf_tcp_req *tcp_req)
361 {
362 	assert(tcp_req->pdu_in_use == false);
363 	tcp_req->pdu_in_use = true;
364 
365 	memset(tcp_req->pdu, 0, sizeof(*tcp_req->pdu));
366 	tcp_req->pdu->qpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
367 
368 	return tcp_req->pdu;
369 }
370 
371 static inline void
372 nvmf_tcp_req_pdu_fini(struct spdk_nvmf_tcp_req *tcp_req)
373 {
374 	tcp_req->pdu_in_use = false;
375 }
376 
377 static struct spdk_nvmf_tcp_req *
378 nvmf_tcp_req_get(struct spdk_nvmf_tcp_qpair *tqpair)
379 {
380 	struct spdk_nvmf_tcp_req *tcp_req;
381 
382 	tcp_req = TAILQ_FIRST(&tqpair->tcp_req_free_queue);
383 	if (!tcp_req) {
384 		return NULL;
385 	}
386 
387 	memset(&tcp_req->rsp, 0, sizeof(tcp_req->rsp));
388 	tcp_req->h2c_offset = 0;
389 	tcp_req->has_incapsule_data = false;
390 	tcp_req->req.dif_enabled = false;
391 
392 	TAILQ_REMOVE(&tqpair->tcp_req_free_queue, tcp_req, state_link);
393 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_working_queue, tcp_req, state_link);
394 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEW);
395 	return tcp_req;
396 }
397 
398 static inline void
399 nvmf_tcp_req_put(struct spdk_nvmf_tcp_qpair *tqpair, struct spdk_nvmf_tcp_req *tcp_req)
400 {
401 	TAILQ_REMOVE(&tqpair->tcp_req_working_queue, tcp_req, state_link);
402 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
403 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_FREE);
404 }
405 
406 static void
407 nvmf_tcp_request_free(void *cb_arg)
408 {
409 	struct spdk_nvmf_tcp_transport *ttransport;
410 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
411 
412 	assert(tcp_req != NULL);
413 
414 	SPDK_DEBUGLOG(nvmf_tcp, "tcp_req=%p will be freed\n", tcp_req);
415 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
416 				      struct spdk_nvmf_tcp_transport, transport);
417 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
418 	nvmf_tcp_req_process(ttransport, tcp_req);
419 }
420 
421 static int
422 nvmf_tcp_req_free(struct spdk_nvmf_request *req)
423 {
424 	struct spdk_nvmf_tcp_req *tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
425 
426 	nvmf_tcp_request_free(tcp_req);
427 
428 	return 0;
429 }
430 
431 static void
432 nvmf_tcp_drain_state_queue(struct spdk_nvmf_tcp_qpair *tqpair,
433 			   enum spdk_nvmf_tcp_req_state state)
434 {
435 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
436 
437 	assert(state != TCP_REQUEST_STATE_FREE);
438 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
439 		if (state == tcp_req->state) {
440 			nvmf_tcp_request_free(tcp_req);
441 		}
442 	}
443 }
444 
445 static void
446 nvmf_tcp_cleanup_all_states(struct spdk_nvmf_tcp_qpair *tqpair)
447 {
448 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
449 
450 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
451 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEW);
452 
453 	/* Wipe the requests waiting for buffer from the global list */
454 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
455 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
456 			STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue, &tcp_req->req,
457 				      spdk_nvmf_request, buf_link);
458 		}
459 	}
460 
461 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEED_BUFFER);
462 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_EXECUTING);
463 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
464 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
465 }
466 
467 static void
468 nvmf_tcp_dump_qpair_req_contents(struct spdk_nvmf_tcp_qpair *tqpair)
469 {
470 	int i;
471 	struct spdk_nvmf_tcp_req *tcp_req;
472 
473 	SPDK_ERRLOG("Dumping contents of queue pair (QID %d)\n", tqpair->qpair.qid);
474 	for (i = 1; i < TCP_REQUEST_NUM_STATES; i++) {
475 		SPDK_ERRLOG("\tNum of requests in state[%d] = %u\n", i, tqpair->state_cntr[i]);
476 		TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
477 			if ((int)tcp_req->state == i) {
478 				SPDK_ERRLOG("\t\tRequest Data From Pool: %d\n", tcp_req->req.data_from_pool);
479 				SPDK_ERRLOG("\t\tRequest opcode: %d\n", tcp_req->req.cmd->nvmf_cmd.opcode);
480 			}
481 		}
482 	}
483 }
484 
485 static void
486 nvmf_tcp_qpair_destroy(struct spdk_nvmf_tcp_qpair *tqpair)
487 {
488 	int err = 0;
489 
490 	spdk_trace_record(TRACE_TCP_QP_DESTROY, 0, 0, (uintptr_t)tqpair);
491 
492 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
493 
494 	err = spdk_sock_close(&tqpair->sock);
495 	assert(err == 0);
496 	nvmf_tcp_cleanup_all_states(tqpair);
497 
498 	if (tqpair->state_cntr[TCP_REQUEST_STATE_FREE] != tqpair->resource_count) {
499 		SPDK_ERRLOG("tqpair(%p) free tcp request num is %u but should be %u\n", tqpair,
500 			    tqpair->state_cntr[TCP_REQUEST_STATE_FREE],
501 			    tqpair->resource_count);
502 		err++;
503 	}
504 
505 	if (err > 0) {
506 		nvmf_tcp_dump_qpair_req_contents(tqpair);
507 	}
508 
509 	spdk_dma_free(tqpair->pdus);
510 	free(tqpair->reqs);
511 	spdk_free(tqpair->bufs);
512 	free(tqpair);
513 	SPDK_DEBUGLOG(nvmf_tcp, "Leave\n");
514 }
515 
516 static void
517 nvmf_tcp_dump_opts(struct spdk_nvmf_transport *transport, struct spdk_json_write_ctx *w)
518 {
519 	struct spdk_nvmf_tcp_transport	*ttransport;
520 	assert(w != NULL);
521 
522 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
523 	spdk_json_write_named_bool(w, "c2h_success", ttransport->tcp_opts.c2h_success);
524 	spdk_json_write_named_uint32(w, "sock_priority", ttransport->tcp_opts.sock_priority);
525 }
526 
527 static int
528 nvmf_tcp_destroy(struct spdk_nvmf_transport *transport,
529 		 spdk_nvmf_transport_destroy_done_cb cb_fn, void *cb_arg)
530 {
531 	struct spdk_nvmf_tcp_transport	*ttransport;
532 
533 	assert(transport != NULL);
534 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
535 
536 	pthread_mutex_destroy(&ttransport->lock);
537 	free(ttransport);
538 
539 	if (cb_fn) {
540 		cb_fn(cb_arg);
541 	}
542 	return 0;
543 }
544 
545 static struct spdk_nvmf_transport *
546 nvmf_tcp_create(struct spdk_nvmf_transport_opts *opts)
547 {
548 	struct spdk_nvmf_tcp_transport *ttransport;
549 	uint32_t sge_count;
550 	uint32_t min_shared_buffers;
551 
552 	ttransport = calloc(1, sizeof(*ttransport));
553 	if (!ttransport) {
554 		return NULL;
555 	}
556 
557 	TAILQ_INIT(&ttransport->ports);
558 
559 	ttransport->transport.ops = &spdk_nvmf_transport_tcp;
560 
561 	ttransport->tcp_opts.c2h_success = SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION;
562 	ttransport->tcp_opts.sock_priority = SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY;
563 	ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
564 	if (opts->transport_specific != NULL &&
565 	    spdk_json_decode_object_relaxed(opts->transport_specific, tcp_transport_opts_decoder,
566 					    SPDK_COUNTOF(tcp_transport_opts_decoder),
567 					    &ttransport->tcp_opts)) {
568 		SPDK_ERRLOG("spdk_json_decode_object_relaxed failed\n");
569 		free(ttransport);
570 		return NULL;
571 	}
572 
573 	SPDK_NOTICELOG("*** TCP Transport Init ***\n");
574 
575 	SPDK_INFOLOG(nvmf_tcp, "*** TCP Transport Init ***\n"
576 		     "  Transport opts:  max_ioq_depth=%d, max_io_size=%d,\n"
577 		     "  max_io_qpairs_per_ctrlr=%d, io_unit_size=%d,\n"
578 		     "  in_capsule_data_size=%d, max_aq_depth=%d\n"
579 		     "  num_shared_buffers=%d, c2h_success=%d,\n"
580 		     "  dif_insert_or_strip=%d, sock_priority=%d\n"
581 		     "  abort_timeout_sec=%d, control_msg_num=%hu\n",
582 		     opts->max_queue_depth,
583 		     opts->max_io_size,
584 		     opts->max_qpairs_per_ctrlr - 1,
585 		     opts->io_unit_size,
586 		     opts->in_capsule_data_size,
587 		     opts->max_aq_depth,
588 		     opts->num_shared_buffers,
589 		     ttransport->tcp_opts.c2h_success,
590 		     opts->dif_insert_or_strip,
591 		     ttransport->tcp_opts.sock_priority,
592 		     opts->abort_timeout_sec,
593 		     ttransport->tcp_opts.control_msg_num);
594 
595 	if (ttransport->tcp_opts.sock_priority > SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY) {
596 		SPDK_ERRLOG("Unsupported socket_priority=%d, the current range is: 0 to %d\n"
597 			    "you can use man 7 socket to view the range of priority under SO_PRIORITY item\n",
598 			    ttransport->tcp_opts.sock_priority, SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY);
599 		free(ttransport);
600 		return NULL;
601 	}
602 
603 	if (ttransport->tcp_opts.control_msg_num == 0 &&
604 	    opts->in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
605 		SPDK_WARNLOG("TCP param control_msg_num can't be 0 if ICD is less than %u bytes. Using default value %u\n",
606 			     SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE, SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM);
607 		ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
608 	}
609 
610 	/* I/O unit size cannot be larger than max I/O size */
611 	if (opts->io_unit_size > opts->max_io_size) {
612 		opts->io_unit_size = opts->max_io_size;
613 	}
614 
615 	sge_count = opts->max_io_size / opts->io_unit_size;
616 	if (sge_count > SPDK_NVMF_MAX_SGL_ENTRIES) {
617 		SPDK_ERRLOG("Unsupported IO Unit size specified, %d bytes\n", opts->io_unit_size);
618 		free(ttransport);
619 		return NULL;
620 	}
621 
622 	min_shared_buffers = spdk_env_get_core_count() * opts->buf_cache_size;
623 	if (min_shared_buffers > opts->num_shared_buffers) {
624 		SPDK_ERRLOG("There are not enough buffers to satisfy "
625 			    "per-poll group caches for each thread. (%" PRIu32 ") "
626 			    "supplied. (%" PRIu32 ") required\n", opts->num_shared_buffers, min_shared_buffers);
627 		SPDK_ERRLOG("Please specify a larger number of shared buffers\n");
628 		free(ttransport);
629 		return NULL;
630 	}
631 
632 	pthread_mutex_init(&ttransport->lock, NULL);
633 
634 	return &ttransport->transport;
635 }
636 
637 static int
638 nvmf_tcp_trsvcid_to_int(const char *trsvcid)
639 {
640 	unsigned long long ull;
641 	char *end = NULL;
642 
643 	ull = strtoull(trsvcid, &end, 10);
644 	if (end == NULL || end == trsvcid || *end != '\0') {
645 		return -1;
646 	}
647 
648 	/* Valid TCP/IP port numbers are in [0, 65535] */
649 	if (ull > 65535) {
650 		return -1;
651 	}
652 
653 	return (int)ull;
654 }
655 
656 /**
657  * Canonicalize a listen address trid.
658  */
659 static int
660 nvmf_tcp_canon_listen_trid(struct spdk_nvme_transport_id *canon_trid,
661 			   const struct spdk_nvme_transport_id *trid)
662 {
663 	int trsvcid_int;
664 
665 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
666 	if (trsvcid_int < 0) {
667 		return -EINVAL;
668 	}
669 
670 	memset(canon_trid, 0, sizeof(*canon_trid));
671 	spdk_nvme_trid_populate_transport(canon_trid, SPDK_NVME_TRANSPORT_TCP);
672 	canon_trid->adrfam = trid->adrfam;
673 	snprintf(canon_trid->traddr, sizeof(canon_trid->traddr), "%s", trid->traddr);
674 	snprintf(canon_trid->trsvcid, sizeof(canon_trid->trsvcid), "%d", trsvcid_int);
675 
676 	return 0;
677 }
678 
679 /**
680  * Find an existing listening port.
681  *
682  * Caller must hold ttransport->lock.
683  */
684 static struct spdk_nvmf_tcp_port *
685 nvmf_tcp_find_port(struct spdk_nvmf_tcp_transport *ttransport,
686 		   const struct spdk_nvme_transport_id *trid)
687 {
688 	struct spdk_nvme_transport_id canon_trid;
689 	struct spdk_nvmf_tcp_port *port;
690 
691 	if (nvmf_tcp_canon_listen_trid(&canon_trid, trid) != 0) {
692 		return NULL;
693 	}
694 
695 	TAILQ_FOREACH(port, &ttransport->ports, link) {
696 		if (spdk_nvme_transport_id_compare(&canon_trid, port->trid) == 0) {
697 			return port;
698 		}
699 	}
700 
701 	return NULL;
702 }
703 
704 static int
705 nvmf_tcp_listen(struct spdk_nvmf_transport *transport, const struct spdk_nvme_transport_id *trid,
706 		struct spdk_nvmf_listen_opts *listen_opts)
707 {
708 	struct spdk_nvmf_tcp_transport *ttransport;
709 	struct spdk_nvmf_tcp_port *port;
710 	int trsvcid_int;
711 	uint8_t adrfam;
712 	struct spdk_sock_opts opts;
713 
714 	if (!strlen(trid->trsvcid)) {
715 		SPDK_ERRLOG("Service id is required\n");
716 		return -EINVAL;
717 	}
718 
719 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
720 
721 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
722 	if (trsvcid_int < 0) {
723 		SPDK_ERRLOG("Invalid trsvcid '%s'\n", trid->trsvcid);
724 		return -EINVAL;
725 	}
726 
727 	pthread_mutex_lock(&ttransport->lock);
728 	port = calloc(1, sizeof(*port));
729 	if (!port) {
730 		SPDK_ERRLOG("Port allocation failed\n");
731 		pthread_mutex_unlock(&ttransport->lock);
732 		return -ENOMEM;
733 	}
734 
735 	port->trid = trid;
736 	opts.opts_size = sizeof(opts);
737 	spdk_sock_get_default_opts(&opts);
738 	opts.priority = ttransport->tcp_opts.sock_priority;
739 	port->listen_sock = spdk_sock_listen_ext(trid->traddr, trsvcid_int,
740 			    NULL, &opts);
741 	if (port->listen_sock == NULL) {
742 		SPDK_ERRLOG("spdk_sock_listen(%s, %d) failed: %s (%d)\n",
743 			    trid->traddr, trsvcid_int,
744 			    spdk_strerror(errno), errno);
745 		free(port);
746 		pthread_mutex_unlock(&ttransport->lock);
747 		return -errno;
748 	}
749 
750 	if (spdk_sock_is_ipv4(port->listen_sock)) {
751 		adrfam = SPDK_NVMF_ADRFAM_IPV4;
752 	} else if (spdk_sock_is_ipv6(port->listen_sock)) {
753 		adrfam = SPDK_NVMF_ADRFAM_IPV6;
754 	} else {
755 		SPDK_ERRLOG("Unhandled socket type\n");
756 		adrfam = 0;
757 	}
758 
759 	if (adrfam != trid->adrfam) {
760 		SPDK_ERRLOG("Socket address family mismatch\n");
761 		spdk_sock_close(&port->listen_sock);
762 		free(port);
763 		pthread_mutex_unlock(&ttransport->lock);
764 		return -EINVAL;
765 	}
766 
767 	SPDK_NOTICELOG("*** NVMe/TCP Target Listening on %s port %s ***\n",
768 		       trid->traddr, trid->trsvcid);
769 
770 	TAILQ_INSERT_TAIL(&ttransport->ports, port, link);
771 	pthread_mutex_unlock(&ttransport->lock);
772 	return 0;
773 }
774 
775 static void
776 nvmf_tcp_stop_listen(struct spdk_nvmf_transport *transport,
777 		     const struct spdk_nvme_transport_id *trid)
778 {
779 	struct spdk_nvmf_tcp_transport *ttransport;
780 	struct spdk_nvmf_tcp_port *port;
781 
782 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
783 
784 	SPDK_DEBUGLOG(nvmf_tcp, "Removing listen address %s port %s\n",
785 		      trid->traddr, trid->trsvcid);
786 
787 	pthread_mutex_lock(&ttransport->lock);
788 	port = nvmf_tcp_find_port(ttransport, trid);
789 	if (port) {
790 		TAILQ_REMOVE(&ttransport->ports, port, link);
791 		spdk_sock_close(&port->listen_sock);
792 		free(port);
793 	}
794 
795 	pthread_mutex_unlock(&ttransport->lock);
796 }
797 
798 static void nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
799 		enum nvme_tcp_pdu_recv_state state);
800 
801 static void
802 nvmf_tcp_qpair_set_state(struct spdk_nvmf_tcp_qpair *tqpair, enum nvme_tcp_qpair_state state)
803 {
804 	tqpair->state = state;
805 	spdk_trace_record(TRACE_TCP_QP_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->state);
806 }
807 
808 static void
809 nvmf_tcp_qpair_disconnect(struct spdk_nvmf_tcp_qpair *tqpair)
810 {
811 	SPDK_DEBUGLOG(nvmf_tcp, "Disconnecting qpair %p\n", tqpair);
812 
813 	spdk_trace_record(TRACE_TCP_QP_DISCONNECT, 0, 0, (uintptr_t)tqpair);
814 
815 	if (tqpair->state <= NVME_TCP_QPAIR_STATE_RUNNING) {
816 		nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITING);
817 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
818 		spdk_poller_unregister(&tqpair->timeout_poller);
819 
820 		/* This will end up calling nvmf_tcp_close_qpair */
821 		spdk_nvmf_qpair_disconnect(&tqpair->qpair, NULL, NULL);
822 	}
823 }
824 
825 static void
826 _pdu_write_done(void *_pdu, int err)
827 {
828 	struct nvme_tcp_pdu			*pdu = _pdu;
829 	struct spdk_nvmf_tcp_qpair		*tqpair = pdu->qpair;
830 
831 	if (err != 0) {
832 		nvmf_tcp_qpair_disconnect(tqpair);
833 		return;
834 	}
835 
836 	assert(pdu->cb_fn != NULL);
837 	pdu->cb_fn(pdu->cb_arg);
838 }
839 
840 static void
841 _tcp_write_pdu(struct nvme_tcp_pdu *pdu)
842 {
843 	uint32_t mapped_length = 0;
844 	ssize_t rc;
845 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
846 
847 	pdu->sock_req.iovcnt = nvme_tcp_build_iovs(pdu->iov, SPDK_COUNTOF(pdu->iov), pdu,
848 			       tqpair->host_hdgst_enable, tqpair->host_ddgst_enable,
849 			       &mapped_length);
850 	pdu->sock_req.cb_fn = _pdu_write_done;
851 	pdu->sock_req.cb_arg = pdu;
852 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_RESP ||
853 	    pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ) {
854 		rc = spdk_sock_writev(tqpair->sock, pdu->iov, pdu->sock_req.iovcnt);
855 		if (rc == mapped_length) {
856 			_pdu_write_done(pdu, 0);
857 		} else {
858 			SPDK_ERRLOG("IC_RESP or TERM_REQ could not write to socket.\n");
859 			_pdu_write_done(pdu, -1);
860 		}
861 	} else {
862 		spdk_sock_writev_async(tqpair->sock, &pdu->sock_req);
863 	}
864 }
865 
866 static void
867 data_crc32_accel_done(void *cb_arg, int status)
868 {
869 	struct nvme_tcp_pdu *pdu = cb_arg;
870 
871 	if (spdk_unlikely(status)) {
872 		SPDK_ERRLOG("Failed to compute the data digest for pdu =%p\n", pdu);
873 		_pdu_write_done(pdu, status);
874 		return;
875 	}
876 
877 	pdu->data_digest_crc32 ^= SPDK_CRC32C_XOR;
878 	MAKE_DIGEST_WORD(pdu->data_digest, pdu->data_digest_crc32);
879 
880 	_tcp_write_pdu(pdu);
881 }
882 
883 static void
884 pdu_data_crc32_compute(struct nvme_tcp_pdu *pdu)
885 {
886 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
887 	uint32_t crc32c;
888 
889 	/* Data Digest */
890 	if (pdu->data_len > 0 && g_nvme_tcp_ddgst[pdu->hdr.common.pdu_type] && tqpair->host_ddgst_enable) {
891 		/* Only suport this limitated case for the first step */
892 		if (spdk_likely(!pdu->dif_ctx && (pdu->data_len % SPDK_NVME_TCP_DIGEST_ALIGNMENT == 0)
893 				&& tqpair->group)) {
894 			spdk_accel_submit_crc32cv(tqpair->group->accel_channel, &pdu->data_digest_crc32,
895 						  pdu->data_iov, pdu->data_iovcnt, 0, data_crc32_accel_done, pdu);
896 			return;
897 		}
898 
899 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
900 		MAKE_DIGEST_WORD(pdu->data_digest, crc32c);
901 	}
902 
903 	_tcp_write_pdu(pdu);
904 }
905 
906 static void
907 nvmf_tcp_qpair_write_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
908 			 struct nvme_tcp_pdu *pdu,
909 			 nvme_tcp_qpair_xfer_complete_cb cb_fn,
910 			 void *cb_arg)
911 {
912 	int hlen;
913 	uint32_t crc32c;
914 
915 	assert(tqpair->pdu_in_progress != pdu);
916 
917 	hlen = pdu->hdr.common.hlen;
918 	pdu->cb_fn = cb_fn;
919 	pdu->cb_arg = cb_arg;
920 
921 	pdu->iov[0].iov_base = &pdu->hdr.raw;
922 	pdu->iov[0].iov_len = hlen;
923 
924 	/* Header Digest */
925 	if (g_nvme_tcp_hdgst[pdu->hdr.common.pdu_type] && tqpair->host_hdgst_enable) {
926 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
927 		MAKE_DIGEST_WORD((uint8_t *)pdu->hdr.raw + hlen, crc32c);
928 	}
929 
930 	/* Data Digest */
931 	pdu_data_crc32_compute(pdu);
932 }
933 
934 static int
935 nvmf_tcp_qpair_init_mem_resource(struct spdk_nvmf_tcp_qpair *tqpair)
936 {
937 	uint32_t i;
938 	struct spdk_nvmf_transport_opts *opts;
939 	uint32_t in_capsule_data_size;
940 
941 	opts = &tqpair->qpair.transport->opts;
942 
943 	in_capsule_data_size = opts->in_capsule_data_size;
944 	if (opts->dif_insert_or_strip) {
945 		in_capsule_data_size = SPDK_BDEV_BUF_SIZE_WITH_MD(in_capsule_data_size);
946 	}
947 
948 	tqpair->resource_count = opts->max_queue_depth;
949 
950 	tqpair->reqs = calloc(tqpair->resource_count, sizeof(*tqpair->reqs));
951 	if (!tqpair->reqs) {
952 		SPDK_ERRLOG("Unable to allocate reqs on tqpair=%p\n", tqpair);
953 		return -1;
954 	}
955 
956 	if (in_capsule_data_size) {
957 		tqpair->bufs = spdk_zmalloc(tqpair->resource_count * in_capsule_data_size, 0x1000,
958 					    NULL, SPDK_ENV_LCORE_ID_ANY,
959 					    SPDK_MALLOC_DMA);
960 		if (!tqpair->bufs) {
961 			SPDK_ERRLOG("Unable to allocate bufs on tqpair=%p.\n", tqpair);
962 			return -1;
963 		}
964 	}
965 
966 	/* Add addtional 2 members, which will be used for mgmt_pdu and pdu_in_progress owned by the tqpair */
967 	tqpair->pdus = spdk_dma_zmalloc((tqpair->resource_count + 2) * sizeof(*tqpair->pdus), 0x1000, NULL);
968 	if (!tqpair->pdus) {
969 		SPDK_ERRLOG("Unable to allocate pdu pool on tqpair =%p.\n", tqpair);
970 		return -1;
971 	}
972 
973 	for (i = 0; i < tqpair->resource_count; i++) {
974 		struct spdk_nvmf_tcp_req *tcp_req = &tqpair->reqs[i];
975 
976 		tcp_req->ttag = i + 1;
977 		tcp_req->req.qpair = &tqpair->qpair;
978 
979 		tcp_req->pdu = &tqpair->pdus[i];
980 		tcp_req->pdu->qpair = tqpair;
981 
982 		/* Set up memory to receive commands */
983 		if (tqpair->bufs) {
984 			tcp_req->buf = (void *)((uintptr_t)tqpair->bufs + (i * in_capsule_data_size));
985 		}
986 
987 		/* Set the cmdn and rsp */
988 		tcp_req->req.rsp = (union nvmf_c2h_msg *)&tcp_req->rsp;
989 		tcp_req->req.cmd = (union nvmf_h2c_msg *)&tcp_req->cmd;
990 
991 		/* Initialize request state to FREE */
992 		tcp_req->state = TCP_REQUEST_STATE_FREE;
993 		TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
994 		tqpair->state_cntr[TCP_REQUEST_STATE_FREE]++;
995 	}
996 
997 	tqpair->mgmt_pdu = &tqpair->pdus[i];
998 	tqpair->mgmt_pdu->qpair = tqpair;
999 	tqpair->pdu_in_progress = &tqpair->pdus[i + 1];
1000 
1001 	tqpair->recv_buf_size = (in_capsule_data_size + sizeof(struct spdk_nvme_tcp_cmd) + 2 *
1002 				 SPDK_NVME_TCP_DIGEST_LEN) * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1003 
1004 	return 0;
1005 }
1006 
1007 static int
1008 nvmf_tcp_qpair_init(struct spdk_nvmf_qpair *qpair)
1009 {
1010 	struct spdk_nvmf_tcp_qpair *tqpair;
1011 
1012 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1013 
1014 	SPDK_DEBUGLOG(nvmf_tcp, "New TCP Connection: %p\n", qpair);
1015 
1016 	spdk_trace_record(TRACE_TCP_QP_CREATE, 0, 0, (uintptr_t)tqpair);
1017 
1018 	/* Initialise request state queues of the qpair */
1019 	TAILQ_INIT(&tqpair->tcp_req_free_queue);
1020 	TAILQ_INIT(&tqpair->tcp_req_working_queue);
1021 
1022 	tqpair->host_hdgst_enable = true;
1023 	tqpair->host_ddgst_enable = true;
1024 
1025 	return 0;
1026 }
1027 
1028 static int
1029 nvmf_tcp_qpair_sock_init(struct spdk_nvmf_tcp_qpair *tqpair)
1030 {
1031 	int rc;
1032 
1033 	spdk_trace_record(TRACE_TCP_QP_SOCK_INIT, 0, 0, (uintptr_t)tqpair);
1034 
1035 	/* set low water mark */
1036 	rc = spdk_sock_set_recvlowat(tqpair->sock, sizeof(struct spdk_nvme_tcp_common_pdu_hdr));
1037 	if (rc != 0) {
1038 		SPDK_ERRLOG("spdk_sock_set_recvlowat() failed\n");
1039 		return rc;
1040 	}
1041 
1042 	return 0;
1043 }
1044 
1045 static void
1046 nvmf_tcp_handle_connect(struct spdk_nvmf_transport *transport,
1047 			struct spdk_nvmf_tcp_port *port,
1048 			struct spdk_sock *sock)
1049 {
1050 	struct spdk_nvmf_tcp_qpair *tqpair;
1051 	int rc;
1052 
1053 	SPDK_DEBUGLOG(nvmf_tcp, "New connection accepted on %s port %s\n",
1054 		      port->trid->traddr, port->trid->trsvcid);
1055 
1056 	tqpair = calloc(1, sizeof(struct spdk_nvmf_tcp_qpair));
1057 	if (tqpair == NULL) {
1058 		SPDK_ERRLOG("Could not allocate new connection.\n");
1059 		spdk_sock_close(&sock);
1060 		return;
1061 	}
1062 
1063 	tqpair->sock = sock;
1064 	tqpair->state_cntr[TCP_REQUEST_STATE_FREE] = 0;
1065 	tqpair->port = port;
1066 	tqpair->qpair.transport = transport;
1067 
1068 	rc = spdk_sock_getaddr(tqpair->sock, tqpair->target_addr,
1069 			       sizeof(tqpair->target_addr), &tqpair->target_port,
1070 			       tqpair->initiator_addr, sizeof(tqpair->initiator_addr),
1071 			       &tqpair->initiator_port);
1072 	if (rc < 0) {
1073 		SPDK_ERRLOG("spdk_sock_getaddr() failed of tqpair=%p\n", tqpair);
1074 		nvmf_tcp_qpair_destroy(tqpair);
1075 		return;
1076 	}
1077 
1078 	spdk_nvmf_tgt_new_qpair(transport->tgt, &tqpair->qpair);
1079 }
1080 
1081 static uint32_t
1082 nvmf_tcp_port_accept(struct spdk_nvmf_transport *transport, struct spdk_nvmf_tcp_port *port)
1083 {
1084 	struct spdk_sock *sock;
1085 	uint32_t count = 0;
1086 	int i;
1087 
1088 	for (i = 0; i < NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME; i++) {
1089 		sock = spdk_sock_accept(port->listen_sock);
1090 		if (sock == NULL) {
1091 			break;
1092 		}
1093 		count++;
1094 		nvmf_tcp_handle_connect(transport, port, sock);
1095 	}
1096 
1097 	return count;
1098 }
1099 
1100 static uint32_t
1101 nvmf_tcp_accept(struct spdk_nvmf_transport *transport)
1102 {
1103 	struct spdk_nvmf_tcp_transport *ttransport;
1104 	struct spdk_nvmf_tcp_port *port;
1105 	uint32_t count = 0;
1106 
1107 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1108 
1109 	TAILQ_FOREACH(port, &ttransport->ports, link) {
1110 		count += nvmf_tcp_port_accept(transport, port);
1111 	}
1112 
1113 	return count;
1114 }
1115 
1116 static void
1117 nvmf_tcp_discover(struct spdk_nvmf_transport *transport,
1118 		  struct spdk_nvme_transport_id *trid,
1119 		  struct spdk_nvmf_discovery_log_page_entry *entry)
1120 {
1121 	entry->trtype = SPDK_NVMF_TRTYPE_TCP;
1122 	entry->adrfam = trid->adrfam;
1123 	entry->treq.secure_channel = SPDK_NVMF_TREQ_SECURE_CHANNEL_NOT_REQUIRED;
1124 
1125 	spdk_strcpy_pad(entry->trsvcid, trid->trsvcid, sizeof(entry->trsvcid), ' ');
1126 	spdk_strcpy_pad(entry->traddr, trid->traddr, sizeof(entry->traddr), ' ');
1127 
1128 	entry->tsas.tcp.sectype = SPDK_NVME_TCP_SECURITY_NONE;
1129 }
1130 
1131 static struct spdk_nvmf_tcp_control_msg_list *
1132 nvmf_tcp_control_msg_list_create(uint16_t num_messages)
1133 {
1134 	struct spdk_nvmf_tcp_control_msg_list *list;
1135 	struct spdk_nvmf_tcp_control_msg *msg;
1136 	uint16_t i;
1137 
1138 	list = calloc(1, sizeof(*list));
1139 	if (!list) {
1140 		SPDK_ERRLOG("Failed to allocate memory for list structure\n");
1141 		return NULL;
1142 	}
1143 
1144 	list->msg_buf = spdk_zmalloc(num_messages * SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE,
1145 				     NVMF_DATA_BUFFER_ALIGNMENT, NULL, SPDK_ENV_SOCKET_ID_ANY, SPDK_MALLOC_DMA);
1146 	if (!list->msg_buf) {
1147 		SPDK_ERRLOG("Failed to allocate memory for control message buffers\n");
1148 		free(list);
1149 		return NULL;
1150 	}
1151 
1152 	STAILQ_INIT(&list->free_msgs);
1153 
1154 	for (i = 0; i < num_messages; i++) {
1155 		msg = (struct spdk_nvmf_tcp_control_msg *)((char *)list->msg_buf + i *
1156 				SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1157 		STAILQ_INSERT_TAIL(&list->free_msgs, msg, link);
1158 	}
1159 
1160 	return list;
1161 }
1162 
1163 static void
1164 nvmf_tcp_control_msg_list_free(struct spdk_nvmf_tcp_control_msg_list *list)
1165 {
1166 	if (!list) {
1167 		return;
1168 	}
1169 
1170 	spdk_free(list->msg_buf);
1171 	free(list);
1172 }
1173 
1174 static struct spdk_nvmf_transport_poll_group *
1175 nvmf_tcp_poll_group_create(struct spdk_nvmf_transport *transport)
1176 {
1177 	struct spdk_nvmf_tcp_transport	*ttransport;
1178 	struct spdk_nvmf_tcp_poll_group *tgroup;
1179 
1180 	tgroup = calloc(1, sizeof(*tgroup));
1181 	if (!tgroup) {
1182 		return NULL;
1183 	}
1184 
1185 	tgroup->sock_group = spdk_sock_group_create(&tgroup->group);
1186 	if (!tgroup->sock_group) {
1187 		goto cleanup;
1188 	}
1189 
1190 	TAILQ_INIT(&tgroup->qpairs);
1191 	TAILQ_INIT(&tgroup->await_req);
1192 
1193 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1194 
1195 	if (transport->opts.in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
1196 		SPDK_DEBUGLOG(nvmf_tcp, "ICD %u is less than min required for admin/fabric commands (%u). "
1197 			      "Creating control messages list\n", transport->opts.in_capsule_data_size,
1198 			      SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1199 		tgroup->control_msg_list = nvmf_tcp_control_msg_list_create(ttransport->tcp_opts.control_msg_num);
1200 		if (!tgroup->control_msg_list) {
1201 			goto cleanup;
1202 		}
1203 	}
1204 
1205 	tgroup->accel_channel = spdk_accel_engine_get_io_channel();
1206 	if (spdk_unlikely(!tgroup->accel_channel)) {
1207 		SPDK_ERRLOG("Cannot create accel_channel for tgroup=%p\n", tgroup);
1208 		goto cleanup;
1209 	}
1210 
1211 	return &tgroup->group;
1212 
1213 cleanup:
1214 	nvmf_tcp_poll_group_destroy(&tgroup->group);
1215 	return NULL;
1216 }
1217 
1218 static struct spdk_nvmf_transport_poll_group *
1219 nvmf_tcp_get_optimal_poll_group(struct spdk_nvmf_qpair *qpair)
1220 {
1221 	struct spdk_nvmf_tcp_qpair *tqpair;
1222 	struct spdk_sock_group *group = NULL;
1223 	int rc;
1224 
1225 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1226 	rc = spdk_sock_get_optimal_sock_group(tqpair->sock, &group);
1227 	if (!rc && group != NULL) {
1228 		return spdk_sock_group_get_ctx(group);
1229 	}
1230 
1231 	return NULL;
1232 }
1233 
1234 static void
1235 nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group)
1236 {
1237 	struct spdk_nvmf_tcp_poll_group *tgroup;
1238 
1239 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
1240 	spdk_sock_group_close(&tgroup->sock_group);
1241 	if (tgroup->control_msg_list) {
1242 		nvmf_tcp_control_msg_list_free(tgroup->control_msg_list);
1243 	}
1244 
1245 	if (tgroup->accel_channel) {
1246 		spdk_put_io_channel(tgroup->accel_channel);
1247 	}
1248 
1249 	free(tgroup);
1250 }
1251 
1252 static void
1253 nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
1254 			      enum nvme_tcp_pdu_recv_state state)
1255 {
1256 	if (tqpair->recv_state == state) {
1257 		SPDK_ERRLOG("The recv state of tqpair=%p is same with the state(%d) to be set\n",
1258 			    tqpair, state);
1259 		return;
1260 	}
1261 
1262 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
1263 		/* When leaving the await req state, move the qpair to the main list */
1264 		TAILQ_REMOVE(&tqpair->group->await_req, tqpair, link);
1265 		TAILQ_INSERT_TAIL(&tqpair->group->qpairs, tqpair, link);
1266 	}
1267 
1268 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv state=%d\n", tqpair, state);
1269 	tqpair->recv_state = state;
1270 
1271 	spdk_trace_record(TRACE_TCP_QP_RECV_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->recv_state);
1272 
1273 	switch (state) {
1274 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
1275 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
1276 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
1277 		break;
1278 	case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
1279 		TAILQ_REMOVE(&tqpair->group->qpairs, tqpair, link);
1280 		TAILQ_INSERT_TAIL(&tqpair->group->await_req, tqpair, link);
1281 		break;
1282 	case NVME_TCP_PDU_RECV_STATE_ERROR:
1283 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1284 		memset(tqpair->pdu_in_progress, 0, sizeof(*(tqpair->pdu_in_progress)));
1285 		break;
1286 	default:
1287 		SPDK_ERRLOG("The state(%d) is invalid\n", state);
1288 		abort();
1289 		break;
1290 	}
1291 }
1292 
1293 static int
1294 nvmf_tcp_qpair_handle_timeout(void *ctx)
1295 {
1296 	struct spdk_nvmf_tcp_qpair *tqpair = ctx;
1297 
1298 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_ERROR);
1299 
1300 	SPDK_ERRLOG("No pdu coming for tqpair=%p within %d seconds\n", tqpair,
1301 		    SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT);
1302 
1303 	nvmf_tcp_qpair_disconnect(tqpair);
1304 	return SPDK_POLLER_BUSY;
1305 }
1306 
1307 static void
1308 nvmf_tcp_send_c2h_term_req_complete(void *cb_arg)
1309 {
1310 	struct spdk_nvmf_tcp_qpair *tqpair = (struct spdk_nvmf_tcp_qpair *)cb_arg;
1311 
1312 	if (!tqpair->timeout_poller) {
1313 		tqpair->timeout_poller = SPDK_POLLER_REGISTER(nvmf_tcp_qpair_handle_timeout, tqpair,
1314 					 SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT * 1000000);
1315 	}
1316 }
1317 
1318 static void
1319 nvmf_tcp_send_c2h_term_req(struct spdk_nvmf_tcp_qpair *tqpair, struct nvme_tcp_pdu *pdu,
1320 			   enum spdk_nvme_tcp_term_req_fes fes, uint32_t error_offset)
1321 {
1322 	struct nvme_tcp_pdu *rsp_pdu;
1323 	struct spdk_nvme_tcp_term_req_hdr *c2h_term_req;
1324 	uint32_t c2h_term_req_hdr_len = sizeof(*c2h_term_req);
1325 	uint32_t copy_len;
1326 
1327 	rsp_pdu = tqpair->mgmt_pdu;
1328 
1329 	c2h_term_req = &rsp_pdu->hdr.term_req;
1330 	c2h_term_req->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ;
1331 	c2h_term_req->common.hlen = c2h_term_req_hdr_len;
1332 
1333 	if ((fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1334 	    (fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1335 		DSET32(&c2h_term_req->fei, error_offset);
1336 	}
1337 
1338 	copy_len = spdk_min(pdu->hdr.common.hlen, SPDK_NVME_TCP_TERM_REQ_ERROR_DATA_MAX_SIZE);
1339 
1340 	/* Copy the error info into the buffer */
1341 	memcpy((uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, pdu->hdr.raw, copy_len);
1342 	nvme_tcp_pdu_set_data(rsp_pdu, (uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, copy_len);
1343 
1344 	/* Contain the header of the wrong received pdu */
1345 	c2h_term_req->common.plen = c2h_term_req->common.hlen + copy_len;
1346 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1347 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_c2h_term_req_complete, tqpair);
1348 }
1349 
1350 static void
1351 nvmf_tcp_capsule_cmd_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1352 				struct spdk_nvmf_tcp_qpair *tqpair,
1353 				struct nvme_tcp_pdu *pdu)
1354 {
1355 	struct spdk_nvmf_tcp_req *tcp_req;
1356 
1357 	assert(pdu->psh_valid_bytes == pdu->psh_len);
1358 	assert(pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD);
1359 
1360 	tcp_req = nvmf_tcp_req_get(tqpair);
1361 	if (!tcp_req) {
1362 		/* Directly return and make the allocation retry again */
1363 		if (tqpair->state_cntr[TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST] > 0) {
1364 			return;
1365 		}
1366 
1367 		/* The host sent more commands than the maximum queue depth. */
1368 		SPDK_ERRLOG("Cannot allocate tcp_req on tqpair=%p\n", tqpair);
1369 		nvmf_tcp_qpair_disconnect(tqpair);
1370 		return;
1371 	}
1372 
1373 	pdu->req = tcp_req;
1374 	assert(tcp_req->state == TCP_REQUEST_STATE_NEW);
1375 	nvmf_tcp_req_process(ttransport, tcp_req);
1376 }
1377 
1378 static void
1379 nvmf_tcp_capsule_cmd_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1380 				    struct spdk_nvmf_tcp_qpair *tqpair,
1381 				    struct nvme_tcp_pdu *pdu)
1382 {
1383 	struct spdk_nvmf_tcp_req *tcp_req;
1384 	struct spdk_nvme_tcp_cmd *capsule_cmd;
1385 	uint32_t error_offset = 0;
1386 	enum spdk_nvme_tcp_term_req_fes fes;
1387 	struct spdk_nvme_cpl *rsp;
1388 
1389 	capsule_cmd = &pdu->hdr.capsule_cmd;
1390 	tcp_req = pdu->req;
1391 	assert(tcp_req != NULL);
1392 
1393 	if (capsule_cmd->common.pdo > SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET) {
1394 		SPDK_ERRLOG("Expected ICReq capsule_cmd pdu offset <= %d, got %c\n",
1395 			    SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET, capsule_cmd->common.pdo);
1396 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1397 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1398 		goto err;
1399 	}
1400 
1401 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1402 
1403 	rsp = &tcp_req->req.rsp->nvme_cpl;
1404 	if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1405 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1406 	} else {
1407 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1408 	}
1409 
1410 	nvmf_tcp_req_process(ttransport, tcp_req);
1411 
1412 	return;
1413 err:
1414 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1415 }
1416 
1417 static int
1418 nvmf_tcp_find_req_in_state(struct spdk_nvmf_tcp_qpair *tqpair,
1419 			   enum spdk_nvmf_tcp_req_state state,
1420 			   uint16_t cid, uint16_t tag,
1421 			   struct spdk_nvmf_tcp_req **req)
1422 {
1423 	struct spdk_nvmf_tcp_req *tcp_req = NULL;
1424 
1425 	TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
1426 		if (tcp_req->state != state) {
1427 			continue;
1428 		}
1429 
1430 		if (tcp_req->req.cmd->nvme_cmd.cid != cid) {
1431 			continue;
1432 		}
1433 
1434 		if (tcp_req->ttag == tag) {
1435 			*req = tcp_req;
1436 			return 0;
1437 		}
1438 
1439 		*req = NULL;
1440 		return -1;
1441 	}
1442 
1443 	/* Didn't find it, but not an error */
1444 	*req = NULL;
1445 	return 0;
1446 }
1447 
1448 static void
1449 nvmf_tcp_h2c_data_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1450 			     struct spdk_nvmf_tcp_qpair *tqpair,
1451 			     struct nvme_tcp_pdu *pdu)
1452 {
1453 	struct spdk_nvmf_tcp_req *tcp_req;
1454 	uint32_t error_offset = 0;
1455 	enum spdk_nvme_tcp_term_req_fes fes = 0;
1456 	struct spdk_nvme_tcp_h2c_data_hdr *h2c_data;
1457 	int rc;
1458 
1459 	h2c_data = &pdu->hdr.h2c_data;
1460 
1461 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair=%p, r2t_info: datao=%u, datal=%u, cccid=%u, ttag=%u\n",
1462 		      tqpair, h2c_data->datao, h2c_data->datal, h2c_data->cccid, h2c_data->ttag);
1463 
1464 	rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
1465 					h2c_data->cccid, h2c_data->ttag, &tcp_req);
1466 	if (rc == 0 && tcp_req == NULL) {
1467 		rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK, h2c_data->cccid,
1468 						h2c_data->ttag, &tcp_req);
1469 	}
1470 
1471 	if (!tcp_req) {
1472 		SPDK_DEBUGLOG(nvmf_tcp, "tcp_req is not found for tqpair=%p\n", tqpair);
1473 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER;
1474 		if (rc == 0) {
1475 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, cccid);
1476 		} else {
1477 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, ttag);
1478 		}
1479 		goto err;
1480 	}
1481 
1482 	if (tcp_req->h2c_offset != h2c_data->datao) {
1483 		SPDK_DEBUGLOG(nvmf_tcp,
1484 			      "tcp_req(%p), tqpair=%p, expected data offset %u, but data offset is %u\n",
1485 			      tcp_req, tqpair, tcp_req->h2c_offset, h2c_data->datao);
1486 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1487 		goto err;
1488 	}
1489 
1490 	if ((h2c_data->datao + h2c_data->datal) > tcp_req->req.length) {
1491 		SPDK_DEBUGLOG(nvmf_tcp,
1492 			      "tcp_req(%p), tqpair=%p,  (datao=%u + datal=%u) execeeds requested length=%u\n",
1493 			      tcp_req, tqpair, h2c_data->datao, h2c_data->datal, tcp_req->req.length);
1494 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1495 		goto err;
1496 	}
1497 
1498 	pdu->req = tcp_req;
1499 
1500 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
1501 		pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
1502 	}
1503 
1504 	nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
1505 				  h2c_data->datao, h2c_data->datal);
1506 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1507 	return;
1508 
1509 err:
1510 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1511 }
1512 
1513 static void
1514 nvmf_tcp_send_capsule_resp_pdu(struct spdk_nvmf_tcp_req *tcp_req,
1515 			       struct spdk_nvmf_tcp_qpair *tqpair)
1516 {
1517 	struct nvme_tcp_pdu *rsp_pdu;
1518 	struct spdk_nvme_tcp_rsp *capsule_resp;
1519 
1520 	SPDK_DEBUGLOG(nvmf_tcp, "enter, tqpair=%p\n", tqpair);
1521 
1522 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1523 	assert(rsp_pdu != NULL);
1524 
1525 	capsule_resp = &rsp_pdu->hdr.capsule_resp;
1526 	capsule_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_CAPSULE_RESP;
1527 	capsule_resp->common.plen = capsule_resp->common.hlen = sizeof(*capsule_resp);
1528 	capsule_resp->rccqe = tcp_req->req.rsp->nvme_cpl;
1529 	if (tqpair->host_hdgst_enable) {
1530 		capsule_resp->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1531 		capsule_resp->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1532 	}
1533 
1534 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_request_free, tcp_req);
1535 }
1536 
1537 static void
1538 nvmf_tcp_pdu_c2h_data_complete(void *cb_arg)
1539 {
1540 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1541 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair,
1542 					     struct spdk_nvmf_tcp_qpair, qpair);
1543 
1544 	assert(tqpair != NULL);
1545 
1546 	if (spdk_unlikely(tcp_req->pdu->rw_offset < tcp_req->req.length)) {
1547 		SPDK_DEBUGLOG(nvmf_tcp, "sending another C2H part, offset %u length %u\n", tcp_req->pdu->rw_offset,
1548 			      tcp_req->req.length);
1549 		_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
1550 		return;
1551 	}
1552 
1553 	if (tcp_req->pdu->hdr.c2h_data.common.flags & SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS) {
1554 		nvmf_tcp_request_free(tcp_req);
1555 	} else {
1556 		nvmf_tcp_req_pdu_fini(tcp_req);
1557 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
1558 	}
1559 }
1560 
1561 static void
1562 nvmf_tcp_r2t_complete(void *cb_arg)
1563 {
1564 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1565 	struct spdk_nvmf_tcp_transport *ttransport;
1566 
1567 	nvmf_tcp_req_pdu_fini(tcp_req);
1568 
1569 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
1570 				      struct spdk_nvmf_tcp_transport, transport);
1571 
1572 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
1573 
1574 	if (tcp_req->h2c_offset == tcp_req->req.length) {
1575 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1576 		nvmf_tcp_req_process(ttransport, tcp_req);
1577 	}
1578 }
1579 
1580 static void
1581 nvmf_tcp_send_r2t_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
1582 		      struct spdk_nvmf_tcp_req *tcp_req)
1583 {
1584 	struct nvme_tcp_pdu *rsp_pdu;
1585 	struct spdk_nvme_tcp_r2t_hdr *r2t;
1586 
1587 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1588 	assert(rsp_pdu != NULL);
1589 
1590 	r2t = &rsp_pdu->hdr.r2t;
1591 	r2t->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_R2T;
1592 	r2t->common.plen = r2t->common.hlen = sizeof(*r2t);
1593 
1594 	if (tqpair->host_hdgst_enable) {
1595 		r2t->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1596 		r2t->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1597 	}
1598 
1599 	r2t->cccid = tcp_req->req.cmd->nvme_cmd.cid;
1600 	r2t->ttag = tcp_req->ttag;
1601 	r2t->r2to = tcp_req->h2c_offset;
1602 	r2t->r2tl = tcp_req->req.length;
1603 
1604 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
1605 
1606 	SPDK_DEBUGLOG(nvmf_tcp,
1607 		      "tcp_req(%p) on tqpair(%p), r2t_info: cccid=%u, ttag=%u, r2to=%u, r2tl=%u\n",
1608 		      tcp_req, tqpair, r2t->cccid, r2t->ttag, r2t->r2to, r2t->r2tl);
1609 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_r2t_complete, tcp_req);
1610 }
1611 
1612 static void
1613 nvmf_tcp_h2c_data_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1614 				 struct spdk_nvmf_tcp_qpair *tqpair,
1615 				 struct nvme_tcp_pdu *pdu)
1616 {
1617 	struct spdk_nvmf_tcp_req *tcp_req;
1618 	struct spdk_nvme_cpl *rsp;
1619 
1620 	tcp_req = pdu->req;
1621 	assert(tcp_req != NULL);
1622 
1623 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1624 
1625 	tcp_req->h2c_offset += pdu->data_len;
1626 
1627 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1628 
1629 	/* Wait for all of the data to arrive AND for the initial R2T PDU send to be
1630 	 * acknowledged before moving on. */
1631 	if (tcp_req->h2c_offset == tcp_req->req.length &&
1632 	    tcp_req->state == TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER) {
1633 		/* After receving all the h2c data, we need to check whether there is
1634 		 * transient transport error */
1635 		rsp = &tcp_req->req.rsp->nvme_cpl;
1636 		if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1637 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1638 		} else {
1639 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1640 		}
1641 		nvmf_tcp_req_process(ttransport, tcp_req);
1642 	}
1643 }
1644 
1645 static void
1646 nvmf_tcp_h2c_term_req_dump(struct spdk_nvme_tcp_term_req_hdr *h2c_term_req)
1647 {
1648 	SPDK_ERRLOG("Error info of pdu(%p): %s\n", h2c_term_req,
1649 		    spdk_nvmf_tcp_term_req_fes_str[h2c_term_req->fes]);
1650 	if ((h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1651 	    (h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1652 		SPDK_DEBUGLOG(nvmf_tcp, "The offset from the start of the PDU header is %u\n",
1653 			      DGET32(h2c_term_req->fei));
1654 	}
1655 }
1656 
1657 static void
1658 nvmf_tcp_h2c_term_req_hdr_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1659 				 struct nvme_tcp_pdu *pdu)
1660 {
1661 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1662 	uint32_t error_offset = 0;
1663 	enum spdk_nvme_tcp_term_req_fes fes;
1664 
1665 	if (h2c_term_req->fes > SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER) {
1666 		SPDK_ERRLOG("Fatal Error Status(FES) is unknown for h2c_term_req pdu=%p\n", pdu);
1667 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1668 		error_offset = offsetof(struct spdk_nvme_tcp_term_req_hdr, fes);
1669 		goto end;
1670 	}
1671 
1672 	/* set the data buffer */
1673 	nvme_tcp_pdu_set_data(pdu, (uint8_t *)pdu->hdr.raw + h2c_term_req->common.hlen,
1674 			      h2c_term_req->common.plen - h2c_term_req->common.hlen);
1675 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1676 	return;
1677 end:
1678 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1679 }
1680 
1681 static void
1682 nvmf_tcp_h2c_term_req_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1683 				     struct nvme_tcp_pdu *pdu)
1684 {
1685 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1686 
1687 	nvmf_tcp_h2c_term_req_dump(h2c_term_req);
1688 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1689 }
1690 
1691 static void
1692 _nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1693 			     struct spdk_nvmf_tcp_transport *ttransport)
1694 {
1695 	struct nvme_tcp_pdu *pdu = tqpair->pdu_in_progress;
1696 
1697 	switch (pdu->hdr.common.pdu_type) {
1698 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1699 		nvmf_tcp_capsule_cmd_payload_handle(ttransport, tqpair, pdu);
1700 		break;
1701 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1702 		nvmf_tcp_h2c_data_payload_handle(ttransport, tqpair, pdu);
1703 		break;
1704 
1705 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1706 		nvmf_tcp_h2c_term_req_payload_handle(tqpair, pdu);
1707 		break;
1708 
1709 	default:
1710 		/* The code should not go to here */
1711 		SPDK_ERRLOG("The code should not go to here\n");
1712 		break;
1713 	}
1714 }
1715 
1716 static void
1717 nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1718 			    struct spdk_nvmf_tcp_transport *ttransport)
1719 {
1720 	int rc = 0;
1721 	struct nvme_tcp_pdu *pdu;
1722 	uint32_t crc32c;
1723 	struct spdk_nvmf_tcp_req *tcp_req;
1724 	struct spdk_nvme_cpl *rsp;
1725 
1726 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1727 	pdu = tqpair->pdu_in_progress;
1728 
1729 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1730 	/* check data digest if need */
1731 	if (pdu->ddgst_enable) {
1732 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
1733 		rc = MATCH_DIGEST_WORD(pdu->data_digest, crc32c);
1734 		if (rc == 0) {
1735 			SPDK_ERRLOG("Data digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1736 			tcp_req = pdu->req;
1737 			assert(tcp_req != NULL);
1738 			rsp = &tcp_req->req.rsp->nvme_cpl;
1739 			rsp->status.sc = SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR;
1740 		}
1741 	}
1742 
1743 	_nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
1744 }
1745 
1746 static void
1747 nvmf_tcp_send_icresp_complete(void *cb_arg)
1748 {
1749 	struct spdk_nvmf_tcp_qpair *tqpair = cb_arg;
1750 
1751 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_RUNNING);
1752 }
1753 
1754 static void
1755 nvmf_tcp_icreq_handle(struct spdk_nvmf_tcp_transport *ttransport,
1756 		      struct spdk_nvmf_tcp_qpair *tqpair,
1757 		      struct nvme_tcp_pdu *pdu)
1758 {
1759 	struct spdk_nvme_tcp_ic_req *ic_req = &pdu->hdr.ic_req;
1760 	struct nvme_tcp_pdu *rsp_pdu;
1761 	struct spdk_nvme_tcp_ic_resp *ic_resp;
1762 	uint32_t error_offset = 0;
1763 	enum spdk_nvme_tcp_term_req_fes fes;
1764 
1765 	/* Only PFV 0 is defined currently */
1766 	if (ic_req->pfv != 0) {
1767 		SPDK_ERRLOG("Expected ICReq PFV %u, got %u\n", 0u, ic_req->pfv);
1768 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1769 		error_offset = offsetof(struct spdk_nvme_tcp_ic_req, pfv);
1770 		goto end;
1771 	}
1772 
1773 	/* MAXR2T is 0's based */
1774 	SPDK_DEBUGLOG(nvmf_tcp, "maxr2t =%u\n", (ic_req->maxr2t + 1u));
1775 
1776 	tqpair->host_hdgst_enable = ic_req->dgst.bits.hdgst_enable ? true : false;
1777 	if (!tqpair->host_hdgst_enable) {
1778 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1779 	}
1780 
1781 	tqpair->host_ddgst_enable = ic_req->dgst.bits.ddgst_enable ? true : false;
1782 	if (!tqpair->host_ddgst_enable) {
1783 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1784 	}
1785 
1786 	tqpair->recv_buf_size = spdk_max(tqpair->recv_buf_size, MIN_SOCK_PIPE_SIZE);
1787 	/* Now that we know whether digests are enabled, properly size the receive buffer */
1788 	if (spdk_sock_set_recvbuf(tqpair->sock, tqpair->recv_buf_size) < 0) {
1789 		SPDK_WARNLOG("Unable to allocate enough memory for receive buffer on tqpair=%p with size=%d\n",
1790 			     tqpair,
1791 			     tqpair->recv_buf_size);
1792 		/* Not fatal. */
1793 	}
1794 
1795 	tqpair->cpda = spdk_min(ic_req->hpda, SPDK_NVME_TCP_CPDA_MAX);
1796 	SPDK_DEBUGLOG(nvmf_tcp, "cpda of tqpair=(%p) is : %u\n", tqpair, tqpair->cpda);
1797 
1798 	rsp_pdu = tqpair->mgmt_pdu;
1799 
1800 	ic_resp = &rsp_pdu->hdr.ic_resp;
1801 	ic_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_IC_RESP;
1802 	ic_resp->common.hlen = ic_resp->common.plen =  sizeof(*ic_resp);
1803 	ic_resp->pfv = 0;
1804 	ic_resp->cpda = tqpair->cpda;
1805 	ic_resp->maxh2cdata = ttransport->transport.opts.max_io_size;
1806 	ic_resp->dgst.bits.hdgst_enable = tqpair->host_hdgst_enable ? 1 : 0;
1807 	ic_resp->dgst.bits.ddgst_enable = tqpair->host_ddgst_enable ? 1 : 0;
1808 
1809 	SPDK_DEBUGLOG(nvmf_tcp, "host_hdgst_enable: %u\n", tqpair->host_hdgst_enable);
1810 	SPDK_DEBUGLOG(nvmf_tcp, "host_ddgst_enable: %u\n", tqpair->host_ddgst_enable);
1811 
1812 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INITIALIZING);
1813 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_icresp_complete, tqpair);
1814 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1815 	return;
1816 end:
1817 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1818 }
1819 
1820 static void
1821 nvmf_tcp_pdu_psh_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1822 			struct spdk_nvmf_tcp_transport *ttransport)
1823 {
1824 	struct nvme_tcp_pdu *pdu;
1825 	int rc;
1826 	uint32_t crc32c, error_offset = 0;
1827 	enum spdk_nvme_tcp_term_req_fes fes;
1828 
1829 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1830 	pdu = tqpair->pdu_in_progress;
1831 
1832 	SPDK_DEBUGLOG(nvmf_tcp, "pdu type of tqpair(%p) is %d\n", tqpair,
1833 		      pdu->hdr.common.pdu_type);
1834 	/* check header digest if needed */
1835 	if (pdu->has_hdgst) {
1836 		SPDK_DEBUGLOG(nvmf_tcp, "Compare the header of pdu=%p on tqpair=%p\n", pdu, tqpair);
1837 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
1838 		rc = MATCH_DIGEST_WORD((uint8_t *)pdu->hdr.raw + pdu->hdr.common.hlen, crc32c);
1839 		if (rc == 0) {
1840 			SPDK_ERRLOG("Header digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1841 			fes = SPDK_NVME_TCP_TERM_REQ_FES_HDGST_ERROR;
1842 			nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1843 			return;
1844 
1845 		}
1846 	}
1847 
1848 	switch (pdu->hdr.common.pdu_type) {
1849 	case SPDK_NVME_TCP_PDU_TYPE_IC_REQ:
1850 		nvmf_tcp_icreq_handle(ttransport, tqpair, pdu);
1851 		break;
1852 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1853 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_REQ);
1854 		break;
1855 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1856 		nvmf_tcp_h2c_data_hdr_handle(ttransport, tqpair, pdu);
1857 		break;
1858 
1859 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1860 		nvmf_tcp_h2c_term_req_hdr_handle(tqpair, pdu);
1861 		break;
1862 
1863 	default:
1864 		SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", tqpair->pdu_in_progress->hdr.common.pdu_type);
1865 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1866 		error_offset = 1;
1867 		nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1868 		break;
1869 	}
1870 }
1871 
1872 static void
1873 nvmf_tcp_pdu_ch_handle(struct spdk_nvmf_tcp_qpair *tqpair)
1874 {
1875 	struct nvme_tcp_pdu *pdu;
1876 	uint32_t error_offset = 0;
1877 	enum spdk_nvme_tcp_term_req_fes fes;
1878 	uint8_t expected_hlen, pdo;
1879 	bool plen_error = false, pdo_error = false;
1880 
1881 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
1882 	pdu = tqpair->pdu_in_progress;
1883 
1884 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_REQ) {
1885 		if (tqpair->state != NVME_TCP_QPAIR_STATE_INVALID) {
1886 			SPDK_ERRLOG("Already received ICreq PDU, and reject this pdu=%p\n", pdu);
1887 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1888 			goto err;
1889 		}
1890 		expected_hlen = sizeof(struct spdk_nvme_tcp_ic_req);
1891 		if (pdu->hdr.common.plen != expected_hlen) {
1892 			plen_error = true;
1893 		}
1894 	} else {
1895 		if (tqpair->state != NVME_TCP_QPAIR_STATE_RUNNING) {
1896 			SPDK_ERRLOG("The TCP/IP connection is not negotitated\n");
1897 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1898 			goto err;
1899 		}
1900 
1901 		switch (pdu->hdr.common.pdu_type) {
1902 		case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1903 			expected_hlen = sizeof(struct spdk_nvme_tcp_cmd);
1904 			pdo = pdu->hdr.common.pdo;
1905 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1906 				pdo_error = true;
1907 				break;
1908 			}
1909 
1910 			if (pdu->hdr.common.plen < expected_hlen) {
1911 				plen_error = true;
1912 			}
1913 			break;
1914 		case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1915 			expected_hlen = sizeof(struct spdk_nvme_tcp_h2c_data_hdr);
1916 			pdo = pdu->hdr.common.pdo;
1917 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1918 				pdo_error = true;
1919 				break;
1920 			}
1921 			if (pdu->hdr.common.plen < expected_hlen) {
1922 				plen_error = true;
1923 			}
1924 			break;
1925 
1926 		case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1927 			expected_hlen = sizeof(struct spdk_nvme_tcp_term_req_hdr);
1928 			if ((pdu->hdr.common.plen <= expected_hlen) ||
1929 			    (pdu->hdr.common.plen > SPDK_NVME_TCP_TERM_REQ_PDU_MAX_SIZE)) {
1930 				plen_error = true;
1931 			}
1932 			break;
1933 
1934 		default:
1935 			SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", pdu->hdr.common.pdu_type);
1936 			fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1937 			error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdu_type);
1938 			goto err;
1939 		}
1940 	}
1941 
1942 	if (pdu->hdr.common.hlen != expected_hlen) {
1943 		SPDK_ERRLOG("PDU type=0x%02x, Expected ICReq header length %u, got %u on tqpair=%p\n",
1944 			    pdu->hdr.common.pdu_type,
1945 			    expected_hlen, pdu->hdr.common.hlen, tqpair);
1946 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1947 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, hlen);
1948 		goto err;
1949 	} else if (pdo_error) {
1950 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1951 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1952 	} else if (plen_error) {
1953 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1954 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, plen);
1955 		goto err;
1956 	} else {
1957 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1958 		nvme_tcp_pdu_calc_psh_len(tqpair->pdu_in_progress, tqpair->host_hdgst_enable);
1959 		return;
1960 	}
1961 err:
1962 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1963 }
1964 
1965 static int
1966 nvmf_tcp_pdu_payload_insert_dif(struct nvme_tcp_pdu *pdu, uint32_t read_offset,
1967 				int read_len)
1968 {
1969 	int rc;
1970 
1971 	rc = spdk_dif_generate_stream(pdu->data_iov, pdu->data_iovcnt,
1972 				      read_offset, read_len, pdu->dif_ctx);
1973 	if (rc != 0) {
1974 		SPDK_ERRLOG("DIF generate failed\n");
1975 	}
1976 
1977 	return rc;
1978 }
1979 
1980 static int
1981 nvmf_tcp_sock_process(struct spdk_nvmf_tcp_qpair *tqpair)
1982 {
1983 	int rc = 0;
1984 	struct nvme_tcp_pdu *pdu;
1985 	enum nvme_tcp_pdu_recv_state prev_state;
1986 	uint32_t data_len;
1987 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(tqpair->qpair.transport,
1988 			struct spdk_nvmf_tcp_transport, transport);
1989 
1990 	/* The loop here is to allow for several back-to-back state changes. */
1991 	do {
1992 		prev_state = tqpair->recv_state;
1993 		SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv pdu entering state %d\n", tqpair, prev_state);
1994 
1995 		pdu = tqpair->pdu_in_progress;
1996 		switch (tqpair->recv_state) {
1997 		/* Wait for the common header  */
1998 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1999 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
2000 			if (spdk_unlikely(tqpair->state == NVME_TCP_QPAIR_STATE_INITIALIZING)) {
2001 				return rc;
2002 			}
2003 
2004 			rc = nvme_tcp_read_data(tqpair->sock,
2005 						sizeof(struct spdk_nvme_tcp_common_pdu_hdr) - pdu->ch_valid_bytes,
2006 						(void *)&pdu->hdr.common + pdu->ch_valid_bytes);
2007 			if (rc < 0) {
2008 				SPDK_DEBUGLOG(nvmf_tcp, "will disconnect tqpair=%p\n", tqpair);
2009 				return NVME_TCP_PDU_FATAL;
2010 			} else if (rc > 0) {
2011 				pdu->ch_valid_bytes += rc;
2012 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2013 				if (spdk_likely(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY)) {
2014 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
2015 				}
2016 			}
2017 
2018 			if (pdu->ch_valid_bytes < sizeof(struct spdk_nvme_tcp_common_pdu_hdr)) {
2019 				return NVME_TCP_PDU_IN_PROGRESS;
2020 			}
2021 
2022 			/* The command header of this PDU has now been read from the socket. */
2023 			nvmf_tcp_pdu_ch_handle(tqpair);
2024 			break;
2025 		/* Wait for the pdu specific header  */
2026 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
2027 			rc = nvme_tcp_read_data(tqpair->sock,
2028 						pdu->psh_len - pdu->psh_valid_bytes,
2029 						(void *)&pdu->hdr.raw + sizeof(struct spdk_nvme_tcp_common_pdu_hdr) + pdu->psh_valid_bytes);
2030 			if (rc < 0) {
2031 				return NVME_TCP_PDU_FATAL;
2032 			} else if (rc > 0) {
2033 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2034 				pdu->psh_valid_bytes += rc;
2035 			}
2036 
2037 			if (pdu->psh_valid_bytes < pdu->psh_len) {
2038 				return NVME_TCP_PDU_IN_PROGRESS;
2039 			}
2040 
2041 			/* All header(ch, psh, head digist) of this PDU has now been read from the socket. */
2042 			nvmf_tcp_pdu_psh_handle(tqpair, ttransport);
2043 			break;
2044 		/* Wait for the req slot */
2045 		case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
2046 			nvmf_tcp_capsule_cmd_hdr_handle(ttransport, tqpair, pdu);
2047 			break;
2048 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
2049 			/* check whether the data is valid, if not we just return */
2050 			if (!pdu->data_len) {
2051 				return NVME_TCP_PDU_IN_PROGRESS;
2052 			}
2053 
2054 			data_len = pdu->data_len;
2055 			/* data digest */
2056 			if (spdk_unlikely((pdu->hdr.common.pdu_type != SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ) &&
2057 					  tqpair->host_ddgst_enable)) {
2058 				data_len += SPDK_NVME_TCP_DIGEST_LEN;
2059 				pdu->ddgst_enable = true;
2060 			}
2061 
2062 			rc = nvme_tcp_read_payload_data(tqpair->sock, pdu);
2063 			if (rc < 0) {
2064 				return NVME_TCP_PDU_FATAL;
2065 			}
2066 			pdu->rw_offset += rc;
2067 
2068 			if (spdk_unlikely(pdu->dif_ctx != NULL)) {
2069 				rc = nvmf_tcp_pdu_payload_insert_dif(pdu, pdu->rw_offset - rc, rc);
2070 				if (rc != 0) {
2071 					return NVME_TCP_PDU_FATAL;
2072 				}
2073 			}
2074 
2075 			if (pdu->rw_offset < data_len) {
2076 				return NVME_TCP_PDU_IN_PROGRESS;
2077 			}
2078 
2079 			/* All of this PDU has now been read from the socket. */
2080 			nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
2081 			break;
2082 		case NVME_TCP_PDU_RECV_STATE_ERROR:
2083 			if (!spdk_sock_is_connected(tqpair->sock)) {
2084 				return NVME_TCP_PDU_FATAL;
2085 			}
2086 			break;
2087 		default:
2088 			assert(0);
2089 			SPDK_ERRLOG("code should not come to here");
2090 			break;
2091 		}
2092 	} while (tqpair->recv_state != prev_state);
2093 
2094 	return rc;
2095 }
2096 
2097 static inline void *
2098 nvmf_tcp_control_msg_get(struct spdk_nvmf_tcp_control_msg_list *list)
2099 {
2100 	struct spdk_nvmf_tcp_control_msg *msg;
2101 
2102 	assert(list);
2103 
2104 	msg = STAILQ_FIRST(&list->free_msgs);
2105 	if (!msg) {
2106 		SPDK_DEBUGLOG(nvmf_tcp, "Out of control messages\n");
2107 		return NULL;
2108 	}
2109 	STAILQ_REMOVE_HEAD(&list->free_msgs, link);
2110 	return msg;
2111 }
2112 
2113 static inline void
2114 nvmf_tcp_control_msg_put(struct spdk_nvmf_tcp_control_msg_list *list, void *_msg)
2115 {
2116 	struct spdk_nvmf_tcp_control_msg *msg = _msg;
2117 
2118 	assert(list);
2119 	STAILQ_INSERT_HEAD(&list->free_msgs, msg, link);
2120 }
2121 
2122 static int
2123 nvmf_tcp_req_parse_sgl(struct spdk_nvmf_tcp_req *tcp_req,
2124 		       struct spdk_nvmf_transport *transport,
2125 		       struct spdk_nvmf_transport_poll_group *group)
2126 {
2127 	struct spdk_nvmf_request		*req = &tcp_req->req;
2128 	struct spdk_nvme_cmd			*cmd;
2129 	struct spdk_nvme_cpl			*rsp;
2130 	struct spdk_nvme_sgl_descriptor		*sgl;
2131 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2132 	uint32_t				length;
2133 
2134 	cmd = &req->cmd->nvme_cmd;
2135 	rsp = &req->rsp->nvme_cpl;
2136 	sgl = &cmd->dptr.sgl1;
2137 
2138 	length = sgl->unkeyed.length;
2139 
2140 	if (sgl->generic.type == SPDK_NVME_SGL_TYPE_TRANSPORT_DATA_BLOCK &&
2141 	    sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_TRANSPORT) {
2142 		if (length > transport->opts.max_io_size) {
2143 			SPDK_ERRLOG("SGL length 0x%x exceeds max io size 0x%x\n",
2144 				    length, transport->opts.max_io_size);
2145 			rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2146 			return -1;
2147 		}
2148 
2149 		/* fill request length and populate iovs */
2150 		req->length = length;
2151 
2152 		SPDK_DEBUGLOG(nvmf_tcp, "Data requested length= 0x%x\n", length);
2153 
2154 		if (spdk_unlikely(req->dif_enabled)) {
2155 			req->dif.orig_length = length;
2156 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2157 			req->dif.elba_length = length;
2158 		}
2159 
2160 		if (spdk_nvmf_request_get_buffers(req, group, transport, length)) {
2161 			/* No available buffers. Queue this request up. */
2162 			SPDK_DEBUGLOG(nvmf_tcp, "No available large data buffers. Queueing request %p\n",
2163 				      tcp_req);
2164 			return 0;
2165 		}
2166 
2167 		/* backward compatible */
2168 		req->data = req->iov[0].iov_base;
2169 
2170 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p took %d buffer/s from central pool, and data=%p\n",
2171 			      tcp_req, req->iovcnt, req->data);
2172 
2173 		return 0;
2174 	} else if (sgl->generic.type == SPDK_NVME_SGL_TYPE_DATA_BLOCK &&
2175 		   sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_OFFSET) {
2176 		uint64_t offset = sgl->address;
2177 		uint32_t max_len = transport->opts.in_capsule_data_size;
2178 		assert(tcp_req->has_incapsule_data);
2179 
2180 		SPDK_DEBUGLOG(nvmf_tcp, "In-capsule data: offset 0x%" PRIx64 ", length 0x%x\n",
2181 			      offset, length);
2182 
2183 		if (offset > max_len) {
2184 			SPDK_ERRLOG("In-capsule offset 0x%" PRIx64 " exceeds capsule length 0x%x\n",
2185 				    offset, max_len);
2186 			rsp->status.sc = SPDK_NVME_SC_INVALID_SGL_OFFSET;
2187 			return -1;
2188 		}
2189 		max_len -= (uint32_t)offset;
2190 
2191 		if (spdk_unlikely(length > max_len)) {
2192 			/* According to the SPEC we should support ICD up to 8192 bytes for admin and fabric commands */
2193 			if (length <= SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE &&
2194 			    (cmd->opc == SPDK_NVME_OPC_FABRIC || req->qpair->qid == 0)) {
2195 
2196 				/* Get a buffer from dedicated list */
2197 				SPDK_DEBUGLOG(nvmf_tcp, "Getting a buffer from control msg list\n");
2198 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2199 				assert(tgroup->control_msg_list);
2200 				req->data = nvmf_tcp_control_msg_get(tgroup->control_msg_list);
2201 				if (!req->data) {
2202 					/* No available buffers. Queue this request up. */
2203 					SPDK_DEBUGLOG(nvmf_tcp, "No available ICD buffers. Queueing request %p\n", tcp_req);
2204 					return 0;
2205 				}
2206 			} else {
2207 				SPDK_ERRLOG("In-capsule data length 0x%x exceeds capsule length 0x%x\n",
2208 					    length, max_len);
2209 				rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2210 				return -1;
2211 			}
2212 		} else {
2213 			req->data = tcp_req->buf;
2214 		}
2215 
2216 		req->length = length;
2217 		req->data_from_pool = false;
2218 
2219 		if (spdk_unlikely(req->dif_enabled)) {
2220 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2221 			req->dif.elba_length = length;
2222 		}
2223 
2224 		req->iov[0].iov_base = req->data;
2225 		req->iov[0].iov_len = length;
2226 		req->iovcnt = 1;
2227 
2228 		return 0;
2229 	}
2230 
2231 	SPDK_ERRLOG("Invalid NVMf I/O Command SGL:  Type 0x%x, Subtype 0x%x\n",
2232 		    sgl->generic.type, sgl->generic.subtype);
2233 	rsp->status.sc = SPDK_NVME_SC_SGL_DESCRIPTOR_TYPE_INVALID;
2234 	return -1;
2235 }
2236 
2237 static inline enum spdk_nvme_media_error_status_code
2238 nvmf_tcp_dif_error_to_compl_status(uint8_t err_type) {
2239 	enum spdk_nvme_media_error_status_code result;
2240 
2241 	switch (err_type)
2242 	{
2243 	case SPDK_DIF_REFTAG_ERROR:
2244 		result = SPDK_NVME_SC_REFERENCE_TAG_CHECK_ERROR;
2245 		break;
2246 	case SPDK_DIF_APPTAG_ERROR:
2247 		result = SPDK_NVME_SC_APPLICATION_TAG_CHECK_ERROR;
2248 		break;
2249 	case SPDK_DIF_GUARD_ERROR:
2250 		result = SPDK_NVME_SC_GUARD_CHECK_ERROR;
2251 		break;
2252 	default:
2253 		SPDK_UNREACHABLE();
2254 		break;
2255 	}
2256 
2257 	return result;
2258 }
2259 
2260 static void
2261 _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2262 			struct spdk_nvmf_tcp_req *tcp_req)
2263 {
2264 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(
2265 				tqpair->qpair.transport, struct spdk_nvmf_tcp_transport, transport);
2266 	struct nvme_tcp_pdu *rsp_pdu;
2267 	struct spdk_nvme_tcp_c2h_data_hdr *c2h_data;
2268 	uint32_t plen, pdo, alignment;
2269 	int rc;
2270 
2271 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2272 
2273 	rsp_pdu = tcp_req->pdu;
2274 	assert(rsp_pdu != NULL);
2275 	assert(tcp_req->pdu_in_use);
2276 
2277 	c2h_data = &rsp_pdu->hdr.c2h_data;
2278 	c2h_data->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_DATA;
2279 	plen = c2h_data->common.hlen = sizeof(*c2h_data);
2280 
2281 	if (tqpair->host_hdgst_enable) {
2282 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2283 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
2284 	}
2285 
2286 	/* set the psh */
2287 	c2h_data->cccid = tcp_req->req.cmd->nvme_cmd.cid;
2288 	c2h_data->datal = tcp_req->req.length - tcp_req->pdu->rw_offset;
2289 	c2h_data->datao = tcp_req->pdu->rw_offset;
2290 
2291 	/* set the padding */
2292 	rsp_pdu->padding_len = 0;
2293 	pdo = plen;
2294 	if (tqpair->cpda) {
2295 		alignment = (tqpair->cpda + 1) << 2;
2296 		if (plen % alignment != 0) {
2297 			pdo = (plen + alignment) / alignment * alignment;
2298 			rsp_pdu->padding_len = pdo - plen;
2299 			plen = pdo;
2300 		}
2301 	}
2302 
2303 	c2h_data->common.pdo = pdo;
2304 	plen += c2h_data->datal;
2305 	if (tqpair->host_ddgst_enable) {
2306 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_DDGSTF;
2307 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2308 	}
2309 
2310 	c2h_data->common.plen = plen;
2311 
2312 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2313 		rsp_pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
2314 	}
2315 
2316 	nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2317 				  c2h_data->datao, c2h_data->datal);
2318 
2319 
2320 	c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU;
2321 	/* Need to send the capsule response if response is not all 0 */
2322 	if (ttransport->tcp_opts.c2h_success &&
2323 	    tcp_req->rsp.cdw0 == 0 && tcp_req->rsp.cdw1 == 0) {
2324 		c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS;
2325 	}
2326 
2327 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2328 		struct spdk_nvme_cpl *rsp = &tcp_req->req.rsp->nvme_cpl;
2329 		struct spdk_dif_error err_blk = {};
2330 		uint32_t mapped_length = 0;
2331 		uint32_t available_iovs = SPDK_COUNTOF(rsp_pdu->iov);
2332 		uint32_t ddgst_len = 0;
2333 
2334 		if (tqpair->host_ddgst_enable) {
2335 			/* Data digest consumes additional iov entry */
2336 			available_iovs--;
2337 			/* plen needs to be updated since nvme_tcp_build_iovs compares expected and actual plen */
2338 			ddgst_len = SPDK_NVME_TCP_DIGEST_LEN;
2339 			c2h_data->common.plen -= ddgst_len;
2340 		}
2341 		/* Temp call to estimate if data can be described by limited number of iovs.
2342 		 * iov vector will be rebuilt in nvmf_tcp_qpair_write_pdu */
2343 		nvme_tcp_build_iovs(rsp_pdu->iov, available_iovs, rsp_pdu, tqpair->host_hdgst_enable,
2344 				    false, &mapped_length);
2345 
2346 		if (mapped_length != c2h_data->common.plen) {
2347 			c2h_data->datal = mapped_length - (c2h_data->common.plen - c2h_data->datal);
2348 			SPDK_DEBUGLOG(nvmf_tcp,
2349 				      "Part C2H, data_len %u (of %u), PDU len %u, updated PDU len %u, offset %u\n",
2350 				      c2h_data->datal, tcp_req->req.length, c2h_data->common.plen, mapped_length, rsp_pdu->rw_offset);
2351 			c2h_data->common.plen = mapped_length;
2352 
2353 			/* Rebuild pdu->data_iov since data length is changed */
2354 			nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt, c2h_data->datao,
2355 						  c2h_data->datal);
2356 
2357 			c2h_data->common.flags &= ~(SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU |
2358 						    SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS);
2359 		}
2360 
2361 		c2h_data->common.plen += ddgst_len;
2362 
2363 		assert(rsp_pdu->rw_offset <= tcp_req->req.length);
2364 
2365 		rc = spdk_dif_verify_stream(rsp_pdu->data_iov, rsp_pdu->data_iovcnt,
2366 					    0, rsp_pdu->data_len, rsp_pdu->dif_ctx, &err_blk);
2367 		if (rc != 0) {
2368 			SPDK_ERRLOG("DIF error detected. type=%d, offset=%" PRIu32 "\n",
2369 				    err_blk.err_type, err_blk.err_offset);
2370 			rsp->status.sct = SPDK_NVME_SCT_MEDIA_ERROR;
2371 			rsp->status.sc = nvmf_tcp_dif_error_to_compl_status(err_blk.err_type);
2372 			nvmf_tcp_req_pdu_fini(tcp_req);
2373 			nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2374 			return;
2375 		}
2376 	}
2377 
2378 	rsp_pdu->rw_offset += c2h_data->datal;
2379 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_pdu_c2h_data_complete, tcp_req);
2380 }
2381 
2382 static void
2383 nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2384 		       struct spdk_nvmf_tcp_req *tcp_req)
2385 {
2386 	nvmf_tcp_req_pdu_init(tcp_req);
2387 	_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2388 }
2389 
2390 static int
2391 request_transfer_out(struct spdk_nvmf_request *req)
2392 {
2393 	struct spdk_nvmf_tcp_req	*tcp_req;
2394 	struct spdk_nvmf_qpair		*qpair;
2395 	struct spdk_nvmf_tcp_qpair	*tqpair;
2396 	struct spdk_nvme_cpl		*rsp;
2397 
2398 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2399 
2400 	qpair = req->qpair;
2401 	rsp = &req->rsp->nvme_cpl;
2402 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2403 
2404 	/* Advance our sq_head pointer */
2405 	if (qpair->sq_head == qpair->sq_head_max) {
2406 		qpair->sq_head = 0;
2407 	} else {
2408 		qpair->sq_head++;
2409 	}
2410 	rsp->sqhd = qpair->sq_head;
2411 
2412 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2413 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
2414 	if (rsp->status.sc == SPDK_NVME_SC_SUCCESS && req->xfer == SPDK_NVME_DATA_CONTROLLER_TO_HOST) {
2415 		nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2416 	} else {
2417 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2418 	}
2419 
2420 	return 0;
2421 }
2422 
2423 static void
2424 nvmf_tcp_set_incapsule_data(struct spdk_nvmf_tcp_qpair *tqpair,
2425 			    struct spdk_nvmf_tcp_req *tcp_req)
2426 {
2427 	struct nvme_tcp_pdu *pdu;
2428 	uint32_t plen = 0;
2429 
2430 	pdu = tqpair->pdu_in_progress;
2431 	plen = pdu->hdr.common.hlen;
2432 
2433 	if (tqpair->host_hdgst_enable) {
2434 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2435 	}
2436 
2437 	if (pdu->hdr.common.plen != plen) {
2438 		tcp_req->has_incapsule_data = true;
2439 	}
2440 }
2441 
2442 static bool
2443 nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
2444 		     struct spdk_nvmf_tcp_req *tcp_req)
2445 {
2446 	struct spdk_nvmf_tcp_qpair		*tqpair;
2447 	int					rc;
2448 	enum spdk_nvmf_tcp_req_state		prev_state;
2449 	bool					progress = false;
2450 	struct spdk_nvmf_transport		*transport = &ttransport->transport;
2451 	struct spdk_nvmf_transport_poll_group	*group;
2452 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2453 
2454 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2455 	group = &tqpair->group->group;
2456 	assert(tcp_req->state != TCP_REQUEST_STATE_FREE);
2457 
2458 	/* If the qpair is not active, we need to abort the outstanding requests. */
2459 	if (tqpair->qpair.state != SPDK_NVMF_QPAIR_ACTIVE) {
2460 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
2461 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2462 		}
2463 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
2464 	}
2465 
2466 	/* The loop here is to allow for several back-to-back state changes. */
2467 	do {
2468 		prev_state = tcp_req->state;
2469 
2470 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p entering state %d on tqpair=%p\n", tcp_req, prev_state,
2471 			      tqpair);
2472 
2473 		switch (tcp_req->state) {
2474 		case TCP_REQUEST_STATE_FREE:
2475 			/* Some external code must kick a request into TCP_REQUEST_STATE_NEW
2476 			 * to escape this state. */
2477 			break;
2478 		case TCP_REQUEST_STATE_NEW:
2479 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEW, 0, 0, (uintptr_t)tcp_req, tqpair);
2480 
2481 			/* copy the cmd from the receive pdu */
2482 			tcp_req->cmd = tqpair->pdu_in_progress->hdr.capsule_cmd.ccsqe;
2483 
2484 			if (spdk_unlikely(spdk_nvmf_request_get_dif_ctx(&tcp_req->req, &tcp_req->req.dif.dif_ctx))) {
2485 				tcp_req->req.dif_enabled = true;
2486 				tqpair->pdu_in_progress->dif_ctx = &tcp_req->req.dif.dif_ctx;
2487 			}
2488 
2489 			/* The next state transition depends on the data transfer needs of this request. */
2490 			tcp_req->req.xfer = spdk_nvmf_req_get_xfer(&tcp_req->req);
2491 
2492 			if (spdk_unlikely(tcp_req->req.xfer == SPDK_NVME_DATA_BIDIRECTIONAL)) {
2493 				tcp_req->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2494 				tcp_req->req.rsp->nvme_cpl.status.sc  = SPDK_NVME_SC_INVALID_OPCODE;
2495 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2496 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2497 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2498 				SPDK_DEBUGLOG(nvmf_tcp, "Request %p: invalid xfer type (BIDIRECTIONAL)\n", tcp_req);
2499 				break;
2500 			}
2501 
2502 			/* If no data to transfer, ready to execute. */
2503 			if (tcp_req->req.xfer == SPDK_NVME_DATA_NONE) {
2504 				/* Reset the tqpair receving pdu state */
2505 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2506 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2507 				break;
2508 			}
2509 
2510 			nvmf_tcp_set_incapsule_data(tqpair, tcp_req);
2511 
2512 			if (!tcp_req->has_incapsule_data) {
2513 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2514 			}
2515 
2516 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEED_BUFFER);
2517 			STAILQ_INSERT_TAIL(&group->pending_buf_queue, &tcp_req->req, buf_link);
2518 			break;
2519 		case TCP_REQUEST_STATE_NEED_BUFFER:
2520 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEED_BUFFER, 0, 0, (uintptr_t)tcp_req, tqpair);
2521 
2522 			assert(tcp_req->req.xfer != SPDK_NVME_DATA_NONE);
2523 
2524 			if (!tcp_req->has_incapsule_data && (&tcp_req->req != STAILQ_FIRST(&group->pending_buf_queue))) {
2525 				SPDK_DEBUGLOG(nvmf_tcp,
2526 					      "Not the first element to wait for the buf for tcp_req(%p) on tqpair=%p\n",
2527 					      tcp_req, tqpair);
2528 				/* This request needs to wait in line to obtain a buffer */
2529 				break;
2530 			}
2531 
2532 			/* Try to get a data buffer */
2533 			rc = nvmf_tcp_req_parse_sgl(tcp_req, transport, group);
2534 			if (rc < 0) {
2535 				STAILQ_REMOVE_HEAD(&group->pending_buf_queue, buf_link);
2536 				/* Reset the tqpair receving pdu state */
2537 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
2538 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2539 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2540 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2541 				break;
2542 			}
2543 
2544 			if (!tcp_req->req.data) {
2545 				SPDK_DEBUGLOG(nvmf_tcp, "No buffer allocated for tcp_req(%p) on tqpair(%p\n)",
2546 					      tcp_req, tqpair);
2547 				/* No buffers available. */
2548 				break;
2549 			}
2550 
2551 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2552 
2553 			/* If data is transferring from host to controller, we need to do a transfer from the host. */
2554 			if (tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER) {
2555 				if (tcp_req->req.data_from_pool) {
2556 					SPDK_DEBUGLOG(nvmf_tcp, "Sending R2T for tcp_req(%p) on tqpair=%p\n", tcp_req, tqpair);
2557 					nvmf_tcp_send_r2t_pdu(tqpair, tcp_req);
2558 				} else {
2559 					struct nvme_tcp_pdu *pdu;
2560 
2561 					nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
2562 
2563 					pdu = tqpair->pdu_in_progress;
2564 					SPDK_DEBUGLOG(nvmf_tcp, "Not need to send r2t for tcp_req(%p) on tqpair=%p\n", tcp_req,
2565 						      tqpair);
2566 					/* No need to send r2t, contained in the capsuled data */
2567 					nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2568 								  0, tcp_req->req.length);
2569 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
2570 				}
2571 				break;
2572 			}
2573 
2574 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2575 			break;
2576 		case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2577 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK, 0, 0, (uintptr_t)tcp_req,
2578 					  tqpair);
2579 			/* The R2T completion or the h2c data incoming will kick it out of this state. */
2580 			break;
2581 		case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2582 
2583 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER, 0, 0,
2584 					  (uintptr_t)tcp_req, tqpair);
2585 			/* Some external code must kick a request into TCP_REQUEST_STATE_READY_TO_EXECUTE
2586 			 * to escape this state. */
2587 			break;
2588 		case TCP_REQUEST_STATE_READY_TO_EXECUTE:
2589 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE, 0, 0, (uintptr_t)tcp_req,
2590 					  tqpair);
2591 
2592 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2593 				assert(tcp_req->req.dif.elba_length >= tcp_req->req.length);
2594 				tcp_req->req.length = tcp_req->req.dif.elba_length;
2595 			}
2596 
2597 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTING);
2598 			spdk_nvmf_request_exec(&tcp_req->req);
2599 			break;
2600 		case TCP_REQUEST_STATE_EXECUTING:
2601 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTING, 0, 0, (uintptr_t)tcp_req, tqpair);
2602 			/* Some external code must kick a request into TCP_REQUEST_STATE_EXECUTED
2603 			 * to escape this state. */
2604 			break;
2605 		case TCP_REQUEST_STATE_EXECUTED:
2606 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTED, 0, 0, (uintptr_t)tcp_req, tqpair);
2607 
2608 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2609 				tcp_req->req.length = tcp_req->req.dif.orig_length;
2610 			}
2611 
2612 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2613 			break;
2614 		case TCP_REQUEST_STATE_READY_TO_COMPLETE:
2615 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE, 0, 0, (uintptr_t)tcp_req,
2616 					  tqpair);
2617 			rc = request_transfer_out(&tcp_req->req);
2618 			assert(rc == 0); /* No good way to handle this currently */
2619 			break;
2620 		case TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST:
2621 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST, 0, 0,
2622 					  (uintptr_t)tcp_req, tqpair);
2623 			/* Some external code must kick a request into TCP_REQUEST_STATE_COMPLETED
2624 			 * to escape this state. */
2625 			break;
2626 		case TCP_REQUEST_STATE_COMPLETED:
2627 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_COMPLETED, 0, 0, (uintptr_t)tcp_req, tqpair);
2628 			if (tcp_req->req.data_from_pool) {
2629 				spdk_nvmf_request_free_buffers(&tcp_req->req, group, transport);
2630 			} else if (spdk_unlikely(tcp_req->has_incapsule_data && (tcp_req->cmd.opc == SPDK_NVME_OPC_FABRIC ||
2631 						 tqpair->qpair.qid == 0) && tcp_req->req.length > transport->opts.in_capsule_data_size)) {
2632 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2633 				assert(tgroup->control_msg_list);
2634 				SPDK_DEBUGLOG(nvmf_tcp, "Put buf to control msg list\n");
2635 				nvmf_tcp_control_msg_put(tgroup->control_msg_list, tcp_req->req.data);
2636 			}
2637 			tcp_req->req.length = 0;
2638 			tcp_req->req.iovcnt = 0;
2639 			tcp_req->req.data = NULL;
2640 
2641 			nvmf_tcp_req_pdu_fini(tcp_req);
2642 
2643 			nvmf_tcp_req_put(tqpair, tcp_req);
2644 			break;
2645 		case TCP_REQUEST_NUM_STATES:
2646 		default:
2647 			assert(0);
2648 			break;
2649 		}
2650 
2651 		if (tcp_req->state != prev_state) {
2652 			progress = true;
2653 		}
2654 	} while (tcp_req->state != prev_state);
2655 
2656 	return progress;
2657 }
2658 
2659 static void
2660 nvmf_tcp_sock_cb(void *arg, struct spdk_sock_group *group, struct spdk_sock *sock)
2661 {
2662 	struct spdk_nvmf_tcp_qpair *tqpair = arg;
2663 	int rc;
2664 
2665 	assert(tqpair != NULL);
2666 	rc = nvmf_tcp_sock_process(tqpair);
2667 
2668 	/* If there was a new socket error, disconnect */
2669 	if (rc < 0) {
2670 		nvmf_tcp_qpair_disconnect(tqpair);
2671 	}
2672 }
2673 
2674 static int
2675 nvmf_tcp_poll_group_add(struct spdk_nvmf_transport_poll_group *group,
2676 			struct spdk_nvmf_qpair *qpair)
2677 {
2678 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2679 	struct spdk_nvmf_tcp_qpair	*tqpair;
2680 	int				rc;
2681 
2682 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2683 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2684 
2685 	rc = spdk_sock_group_add_sock(tgroup->sock_group, tqpair->sock,
2686 				      nvmf_tcp_sock_cb, tqpair);
2687 	if (rc != 0) {
2688 		SPDK_ERRLOG("Could not add sock to sock_group: %s (%d)\n",
2689 			    spdk_strerror(errno), errno);
2690 		return -1;
2691 	}
2692 
2693 	rc =  nvmf_tcp_qpair_sock_init(tqpair);
2694 	if (rc != 0) {
2695 		SPDK_ERRLOG("Cannot set sock opt for tqpair=%p\n", tqpair);
2696 		return -1;
2697 	}
2698 
2699 	rc = nvmf_tcp_qpair_init(&tqpair->qpair);
2700 	if (rc < 0) {
2701 		SPDK_ERRLOG("Cannot init tqpair=%p\n", tqpair);
2702 		return -1;
2703 	}
2704 
2705 	rc = nvmf_tcp_qpair_init_mem_resource(tqpair);
2706 	if (rc < 0) {
2707 		SPDK_ERRLOG("Cannot init memory resource info for tqpair=%p\n", tqpair);
2708 		return -1;
2709 	}
2710 
2711 	tqpair->group = tgroup;
2712 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INVALID);
2713 	TAILQ_INSERT_TAIL(&tgroup->qpairs, tqpair, link);
2714 
2715 	return 0;
2716 }
2717 
2718 static int
2719 nvmf_tcp_poll_group_remove(struct spdk_nvmf_transport_poll_group *group,
2720 			   struct spdk_nvmf_qpair *qpair)
2721 {
2722 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2723 	struct spdk_nvmf_tcp_qpair		*tqpair;
2724 	int				rc;
2725 
2726 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2727 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2728 
2729 	assert(tqpair->group == tgroup);
2730 
2731 	SPDK_DEBUGLOG(nvmf_tcp, "remove tqpair=%p from the tgroup=%p\n", tqpair, tgroup);
2732 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
2733 		TAILQ_REMOVE(&tgroup->await_req, tqpair, link);
2734 	} else {
2735 		TAILQ_REMOVE(&tgroup->qpairs, tqpair, link);
2736 	}
2737 
2738 	rc = spdk_sock_group_remove_sock(tgroup->sock_group, tqpair->sock);
2739 	if (rc != 0) {
2740 		SPDK_ERRLOG("Could not remove sock from sock_group: %s (%d)\n",
2741 			    spdk_strerror(errno), errno);
2742 	}
2743 
2744 	return rc;
2745 }
2746 
2747 static int
2748 nvmf_tcp_req_complete(struct spdk_nvmf_request *req)
2749 {
2750 	struct spdk_nvmf_tcp_transport *ttransport;
2751 	struct spdk_nvmf_tcp_req *tcp_req;
2752 
2753 	ttransport = SPDK_CONTAINEROF(req->qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2754 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2755 
2756 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTED);
2757 	nvmf_tcp_req_process(ttransport, tcp_req);
2758 
2759 	return 0;
2760 }
2761 
2762 static void
2763 nvmf_tcp_close_qpair(struct spdk_nvmf_qpair *qpair,
2764 		     spdk_nvmf_transport_qpair_fini_cb cb_fn, void *cb_arg)
2765 {
2766 	struct spdk_nvmf_tcp_qpair *tqpair;
2767 
2768 	SPDK_DEBUGLOG(nvmf_tcp, "Qpair: %p\n", qpair);
2769 
2770 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2771 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITED);
2772 	nvmf_tcp_qpair_destroy(tqpair);
2773 
2774 	if (cb_fn) {
2775 		cb_fn(cb_arg);
2776 	}
2777 }
2778 
2779 static int
2780 nvmf_tcp_poll_group_poll(struct spdk_nvmf_transport_poll_group *group)
2781 {
2782 	struct spdk_nvmf_tcp_poll_group *tgroup;
2783 	int rc;
2784 	struct spdk_nvmf_request *req, *req_tmp;
2785 	struct spdk_nvmf_tcp_req *tcp_req;
2786 	struct spdk_nvmf_tcp_qpair *tqpair, *tqpair_tmp;
2787 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(group->transport,
2788 			struct spdk_nvmf_tcp_transport, transport);
2789 
2790 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2791 
2792 	if (spdk_unlikely(TAILQ_EMPTY(&tgroup->qpairs) && TAILQ_EMPTY(&tgroup->await_req))) {
2793 		return 0;
2794 	}
2795 
2796 	STAILQ_FOREACH_SAFE(req, &group->pending_buf_queue, buf_link, req_tmp) {
2797 		tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2798 		if (nvmf_tcp_req_process(ttransport, tcp_req) == false) {
2799 			break;
2800 		}
2801 	}
2802 
2803 	rc = spdk_sock_group_poll(tgroup->sock_group);
2804 	if (rc < 0) {
2805 		SPDK_ERRLOG("Failed to poll sock_group=%p\n", tgroup->sock_group);
2806 	}
2807 
2808 	TAILQ_FOREACH_SAFE(tqpair, &tgroup->await_req, link, tqpair_tmp) {
2809 		nvmf_tcp_sock_process(tqpair);
2810 	}
2811 
2812 	return rc;
2813 }
2814 
2815 static int
2816 nvmf_tcp_qpair_get_trid(struct spdk_nvmf_qpair *qpair,
2817 			struct spdk_nvme_transport_id *trid, bool peer)
2818 {
2819 	struct spdk_nvmf_tcp_qpair     *tqpair;
2820 	uint16_t			port;
2821 
2822 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2823 	spdk_nvme_trid_populate_transport(trid, SPDK_NVME_TRANSPORT_TCP);
2824 
2825 	if (peer) {
2826 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->initiator_addr);
2827 		port = tqpair->initiator_port;
2828 	} else {
2829 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->target_addr);
2830 		port = tqpair->target_port;
2831 	}
2832 
2833 	if (spdk_sock_is_ipv4(tqpair->sock)) {
2834 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV4;
2835 	} else if (spdk_sock_is_ipv6(tqpair->sock)) {
2836 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV6;
2837 	} else {
2838 		return -1;
2839 	}
2840 
2841 	snprintf(trid->trsvcid, sizeof(trid->trsvcid), "%d", port);
2842 	return 0;
2843 }
2844 
2845 static int
2846 nvmf_tcp_qpair_get_local_trid(struct spdk_nvmf_qpair *qpair,
2847 			      struct spdk_nvme_transport_id *trid)
2848 {
2849 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2850 }
2851 
2852 static int
2853 nvmf_tcp_qpair_get_peer_trid(struct spdk_nvmf_qpair *qpair,
2854 			     struct spdk_nvme_transport_id *trid)
2855 {
2856 	return nvmf_tcp_qpair_get_trid(qpair, trid, 1);
2857 }
2858 
2859 static int
2860 nvmf_tcp_qpair_get_listen_trid(struct spdk_nvmf_qpair *qpair,
2861 			       struct spdk_nvme_transport_id *trid)
2862 {
2863 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2864 }
2865 
2866 static void
2867 nvmf_tcp_req_set_abort_status(struct spdk_nvmf_request *req,
2868 			      struct spdk_nvmf_tcp_req *tcp_req_to_abort)
2869 {
2870 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2871 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sc = SPDK_NVME_SC_ABORTED_BY_REQUEST;
2872 
2873 	nvmf_tcp_req_set_state(tcp_req_to_abort, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2874 
2875 	req->rsp->nvme_cpl.cdw0 &= ~1U; /* Command was successfully aborted. */
2876 }
2877 
2878 static int
2879 _nvmf_tcp_qpair_abort_request(void *ctx)
2880 {
2881 	struct spdk_nvmf_request *req = ctx;
2882 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = SPDK_CONTAINEROF(req->req_to_abort,
2883 			struct spdk_nvmf_tcp_req, req);
2884 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(req->req_to_abort->qpair,
2885 					     struct spdk_nvmf_tcp_qpair, qpair);
2886 	int rc;
2887 
2888 	spdk_poller_unregister(&req->poller);
2889 
2890 	switch (tcp_req_to_abort->state) {
2891 	case TCP_REQUEST_STATE_EXECUTING:
2892 		rc = nvmf_ctrlr_abort_request(req);
2893 		if (rc == SPDK_NVMF_REQUEST_EXEC_STATUS_ASYNCHRONOUS) {
2894 			return SPDK_POLLER_BUSY;
2895 		}
2896 		break;
2897 
2898 	case TCP_REQUEST_STATE_NEED_BUFFER:
2899 		STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue,
2900 			      &tcp_req_to_abort->req, spdk_nvmf_request, buf_link);
2901 
2902 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2903 		break;
2904 
2905 	case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2906 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2907 		break;
2908 
2909 	case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2910 		if (spdk_get_ticks() < req->timeout_tsc) {
2911 			req->poller = SPDK_POLLER_REGISTER(_nvmf_tcp_qpair_abort_request, req, 0);
2912 			return SPDK_POLLER_BUSY;
2913 		}
2914 		break;
2915 
2916 	default:
2917 		break;
2918 	}
2919 
2920 	spdk_nvmf_request_complete(req);
2921 	return SPDK_POLLER_BUSY;
2922 }
2923 
2924 static void
2925 nvmf_tcp_qpair_abort_request(struct spdk_nvmf_qpair *qpair,
2926 			     struct spdk_nvmf_request *req)
2927 {
2928 	struct spdk_nvmf_tcp_qpair *tqpair;
2929 	struct spdk_nvmf_tcp_transport *ttransport;
2930 	struct spdk_nvmf_transport *transport;
2931 	uint16_t cid;
2932 	uint32_t i;
2933 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = NULL;
2934 
2935 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2936 	ttransport = SPDK_CONTAINEROF(qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2937 	transport = &ttransport->transport;
2938 
2939 	cid = req->cmd->nvme_cmd.cdw10_bits.abort.cid;
2940 
2941 	for (i = 0; i < tqpair->resource_count; i++) {
2942 		if (tqpair->reqs[i].state != TCP_REQUEST_STATE_FREE &&
2943 		    tqpair->reqs[i].req.cmd->nvme_cmd.cid == cid) {
2944 			tcp_req_to_abort = &tqpair->reqs[i];
2945 			break;
2946 		}
2947 	}
2948 
2949 	spdk_trace_record(TRACE_TCP_QP_ABORT_REQ, 0, 0, (uintptr_t)req, tqpair);
2950 
2951 	if (tcp_req_to_abort == NULL) {
2952 		spdk_nvmf_request_complete(req);
2953 		return;
2954 	}
2955 
2956 	req->req_to_abort = &tcp_req_to_abort->req;
2957 	req->timeout_tsc = spdk_get_ticks() +
2958 			   transport->opts.abort_timeout_sec * spdk_get_ticks_hz();
2959 	req->poller = NULL;
2960 
2961 	_nvmf_tcp_qpair_abort_request(req);
2962 }
2963 
2964 #define SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH 128
2965 #define SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH 128
2966 #define SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR 128
2967 #define SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE 4096
2968 #define SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE 131072
2969 #define SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE 131072
2970 #define SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS 511
2971 #define SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE 32
2972 #define SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP false
2973 #define SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC 1
2974 
2975 static void
2976 nvmf_tcp_opts_init(struct spdk_nvmf_transport_opts *opts)
2977 {
2978 	opts->max_queue_depth =		SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH;
2979 	opts->max_qpairs_per_ctrlr =	SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR;
2980 	opts->in_capsule_data_size =	SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE;
2981 	opts->max_io_size =		SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE;
2982 	opts->io_unit_size =		SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE;
2983 	opts->max_aq_depth =		SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH;
2984 	opts->num_shared_buffers =	SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS;
2985 	opts->buf_cache_size =		SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE;
2986 	opts->dif_insert_or_strip =	SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP;
2987 	opts->abort_timeout_sec =	SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC;
2988 	opts->transport_specific =      NULL;
2989 }
2990 
2991 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp = {
2992 	.name = "TCP",
2993 	.type = SPDK_NVME_TRANSPORT_TCP,
2994 	.opts_init = nvmf_tcp_opts_init,
2995 	.create = nvmf_tcp_create,
2996 	.dump_opts = nvmf_tcp_dump_opts,
2997 	.destroy = nvmf_tcp_destroy,
2998 
2999 	.listen = nvmf_tcp_listen,
3000 	.stop_listen = nvmf_tcp_stop_listen,
3001 	.accept = nvmf_tcp_accept,
3002 
3003 	.listener_discover = nvmf_tcp_discover,
3004 
3005 	.poll_group_create = nvmf_tcp_poll_group_create,
3006 	.get_optimal_poll_group = nvmf_tcp_get_optimal_poll_group,
3007 	.poll_group_destroy = nvmf_tcp_poll_group_destroy,
3008 	.poll_group_add = nvmf_tcp_poll_group_add,
3009 	.poll_group_remove = nvmf_tcp_poll_group_remove,
3010 	.poll_group_poll = nvmf_tcp_poll_group_poll,
3011 
3012 	.req_free = nvmf_tcp_req_free,
3013 	.req_complete = nvmf_tcp_req_complete,
3014 
3015 	.qpair_fini = nvmf_tcp_close_qpair,
3016 	.qpair_get_local_trid = nvmf_tcp_qpair_get_local_trid,
3017 	.qpair_get_peer_trid = nvmf_tcp_qpair_get_peer_trid,
3018 	.qpair_get_listen_trid = nvmf_tcp_qpair_get_listen_trid,
3019 	.qpair_abort_request = nvmf_tcp_qpair_abort_request,
3020 };
3021 
3022 SPDK_NVMF_TRANSPORT_REGISTER(tcp, &spdk_nvmf_transport_tcp);
3023 SPDK_LOG_REGISTER_COMPONENT(nvmf_tcp)
3024