xref: /spdk/lib/nvmf/tcp.c (revision 43adb646b8462caf10aabf76acb1b73b4261ebb9)
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright (c) Intel Corporation. All rights reserved.
5  *   Copyright (c) 2019, 2020 Mellanox Technologies LTD. All rights reserved.
6  *
7  *   Redistribution and use in source and binary forms, with or without
8  *   modification, are permitted provided that the following conditions
9  *   are met:
10  *
11  *     * Redistributions of source code must retain the above copyright
12  *       notice, this list of conditions and the following disclaimer.
13  *     * Redistributions in binary form must reproduce the above copyright
14  *       notice, this list of conditions and the following disclaimer in
15  *       the documentation and/or other materials provided with the
16  *       distribution.
17  *     * Neither the name of Intel Corporation nor the names of its
18  *       contributors may be used to endorse or promote products derived
19  *       from this software without specific prior written permission.
20  *
21  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
22  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
23  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
24  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
25  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
26  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
27  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33 
34 #include "spdk/accel_engine.h"
35 #include "spdk/stdinc.h"
36 #include "spdk/crc32.h"
37 #include "spdk/endian.h"
38 #include "spdk/assert.h"
39 #include "spdk/thread.h"
40 #include "spdk/nvmf_transport.h"
41 #include "spdk/string.h"
42 #include "spdk/trace.h"
43 #include "spdk/util.h"
44 #include "spdk/log.h"
45 
46 #include "spdk_internal/assert.h"
47 #include "spdk_internal/nvme_tcp.h"
48 #include "spdk_internal/sock.h"
49 
50 #include "nvmf_internal.h"
51 
52 #include "spdk_internal/trace_defs.h"
53 
54 #define NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME 16
55 #define SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY 16
56 #define SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY 0
57 #define SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM 32
58 #define SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION true
59 
60 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp;
61 
62 /* spdk nvmf related structure */
63 enum spdk_nvmf_tcp_req_state {
64 
65 	/* The request is not currently in use */
66 	TCP_REQUEST_STATE_FREE = 0,
67 
68 	/* Initial state when request first received */
69 	TCP_REQUEST_STATE_NEW,
70 
71 	/* The request is queued until a data buffer is available. */
72 	TCP_REQUEST_STATE_NEED_BUFFER,
73 
74 	/* The request is currently transferring data from the host to the controller. */
75 	TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
76 
77 	/* The request is waiting for the R2T send acknowledgement. */
78 	TCP_REQUEST_STATE_AWAITING_R2T_ACK,
79 
80 	/* The request is ready to execute at the block device */
81 	TCP_REQUEST_STATE_READY_TO_EXECUTE,
82 
83 	/* The request is currently executing at the block device */
84 	TCP_REQUEST_STATE_EXECUTING,
85 
86 	/* The request finished executing at the block device */
87 	TCP_REQUEST_STATE_EXECUTED,
88 
89 	/* The request is ready to send a completion */
90 	TCP_REQUEST_STATE_READY_TO_COMPLETE,
91 
92 	/* The request is currently transferring final pdus from the controller to the host. */
93 	TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
94 
95 	/* The request completed and can be marked free. */
96 	TCP_REQUEST_STATE_COMPLETED,
97 
98 	/* Terminator */
99 	TCP_REQUEST_NUM_STATES,
100 };
101 
102 static const char *spdk_nvmf_tcp_term_req_fes_str[] = {
103 	"Invalid PDU Header Field",
104 	"PDU Sequence Error",
105 	"Header Digiest Error",
106 	"Data Transfer Out of Range",
107 	"R2T Limit Exceeded",
108 	"Unsupported parameter",
109 };
110 
111 SPDK_TRACE_REGISTER_FN(nvmf_tcp_trace, "nvmf_tcp", TRACE_GROUP_NVMF_TCP)
112 {
113 	spdk_trace_register_object(OBJECT_NVMF_TCP_IO, 'r');
114 	spdk_trace_register_description("TCP_REQ_NEW",
115 					TRACE_TCP_REQUEST_STATE_NEW,
116 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 1,
117 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
118 	spdk_trace_register_description("TCP_REQ_NEED_BUFFER",
119 					TRACE_TCP_REQUEST_STATE_NEED_BUFFER,
120 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
121 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
122 	spdk_trace_register_description("TCP_REQ_TX_H_TO_C",
123 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
124 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
125 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
126 	spdk_trace_register_description("TCP_REQ_RDY_TO_EXECUTE",
127 					TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE,
128 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
129 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
130 	spdk_trace_register_description("TCP_REQ_EXECUTING",
131 					TRACE_TCP_REQUEST_STATE_EXECUTING,
132 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
133 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
134 	spdk_trace_register_description("TCP_REQ_EXECUTED",
135 					TRACE_TCP_REQUEST_STATE_EXECUTED,
136 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
137 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
138 	spdk_trace_register_description("TCP_REQ_RDY_TO_COMPLETE",
139 					TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE,
140 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
141 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
142 	spdk_trace_register_description("TCP_REQ_TRANSFER_C2H",
143 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
144 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
145 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
146 	spdk_trace_register_description("TCP_REQ_COMPLETED",
147 					TRACE_TCP_REQUEST_STATE_COMPLETED,
148 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
149 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
150 	spdk_trace_register_description("TCP_WRITE_START",
151 					TRACE_TCP_FLUSH_WRITEBUF_START,
152 					OWNER_NONE, OBJECT_NONE, 0,
153 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
154 	spdk_trace_register_description("TCP_WRITE_DONE",
155 					TRACE_TCP_FLUSH_WRITEBUF_DONE,
156 					OWNER_NONE, OBJECT_NONE, 0,
157 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
158 	spdk_trace_register_description("TCP_READ_DONE",
159 					TRACE_TCP_READ_FROM_SOCKET_DONE,
160 					OWNER_NONE, OBJECT_NONE, 0,
161 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
162 	spdk_trace_register_description("TCP_REQ_AWAIT_R2T_ACK",
163 					TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK,
164 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
165 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
166 
167 	spdk_trace_register_description("TCP_QP_CREATE", TRACE_TCP_QP_CREATE,
168 					OWNER_NONE, OBJECT_NONE, 0,
169 					SPDK_TRACE_ARG_TYPE_INT, "");
170 	spdk_trace_register_description("TCP_QP_SOCK_INIT", TRACE_TCP_QP_SOCK_INIT,
171 					OWNER_NONE, OBJECT_NONE, 0,
172 					SPDK_TRACE_ARG_TYPE_INT, "");
173 	spdk_trace_register_description("TCP_QP_STATE_CHANGE", TRACE_TCP_QP_STATE_CHANGE,
174 					OWNER_NONE, OBJECT_NONE, 0,
175 					SPDK_TRACE_ARG_TYPE_INT, "state");
176 	spdk_trace_register_description("TCP_QP_DISCONNECT", TRACE_TCP_QP_DISCONNECT,
177 					OWNER_NONE, OBJECT_NONE, 0,
178 					SPDK_TRACE_ARG_TYPE_INT, "");
179 	spdk_trace_register_description("TCP_QP_DESTROY", TRACE_TCP_QP_DESTROY,
180 					OWNER_NONE, OBJECT_NONE, 0,
181 					SPDK_TRACE_ARG_TYPE_INT, "");
182 	spdk_trace_register_description("TCP_QP_ABORT_REQ", TRACE_TCP_QP_ABORT_REQ,
183 					OWNER_NONE, OBJECT_NONE, 0,
184 					SPDK_TRACE_ARG_TYPE_INT, "");
185 	spdk_trace_register_description("TCP_QP_RCV_STATE_CHANGE", TRACE_TCP_QP_RCV_STATE_CHANGE,
186 					OWNER_NONE, OBJECT_NONE, 0,
187 					SPDK_TRACE_ARG_TYPE_INT, "state");
188 
189 	spdk_trace_tpoint_register_relation(TRACE_BDEV_IO_START, OBJECT_NVMF_TCP_IO, 1);
190 	spdk_trace_tpoint_register_relation(TRACE_BDEV_IO_DONE, OBJECT_NVMF_TCP_IO, 0);
191 }
192 
193 struct spdk_nvmf_tcp_req  {
194 	struct spdk_nvmf_request		req;
195 	struct spdk_nvme_cpl			rsp;
196 	struct spdk_nvme_cmd			cmd;
197 
198 	/* A PDU that can be used for sending responses. This is
199 	 * not the incoming PDU! */
200 	struct nvme_tcp_pdu			*pdu;
201 
202 	/* In-capsule data buffer */
203 	uint8_t					*buf;
204 	/*
205 	 * The PDU for a request may be used multiple times in serial over
206 	 * the request's lifetime. For example, first to send an R2T, then
207 	 * to send a completion. To catch mistakes where the PDU is used
208 	 * twice at the same time, add a debug flag here for init/fini.
209 	 */
210 	bool					pdu_in_use;
211 	bool					has_incapsule_data;
212 
213 	/* transfer_tag */
214 	uint16_t				ttag;
215 
216 	enum spdk_nvmf_tcp_req_state		state;
217 
218 	/*
219 	 * h2c_offset is used when we receive the h2c_data PDU.
220 	 */
221 	uint32_t				h2c_offset;
222 
223 	STAILQ_ENTRY(spdk_nvmf_tcp_req)		link;
224 	TAILQ_ENTRY(spdk_nvmf_tcp_req)		state_link;
225 };
226 
227 struct spdk_nvmf_tcp_qpair {
228 	struct spdk_nvmf_qpair			qpair;
229 	struct spdk_nvmf_tcp_poll_group		*group;
230 	struct spdk_sock			*sock;
231 
232 	enum nvme_tcp_pdu_recv_state		recv_state;
233 	enum nvme_tcp_qpair_state		state;
234 
235 	/* PDU being actively received */
236 	struct nvme_tcp_pdu			*pdu_in_progress;
237 
238 	/* Queues to track the requests in all states */
239 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_working_queue;
240 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_free_queue;
241 
242 	/* Number of requests in each state */
243 	uint32_t				state_cntr[TCP_REQUEST_NUM_STATES];
244 
245 	uint8_t					cpda;
246 
247 	bool					host_hdgst_enable;
248 	bool					host_ddgst_enable;
249 
250 	/* This is a spare PDU used for sending special management
251 	 * operations. Primarily, this is used for the initial
252 	 * connection response and c2h termination request. */
253 	struct nvme_tcp_pdu			*mgmt_pdu;
254 
255 	/* Arrays of in-capsule buffers, requests, and pdus.
256 	 * Each array is 'resource_count' number of elements */
257 	void					*bufs;
258 	struct spdk_nvmf_tcp_req		*reqs;
259 	struct nvme_tcp_pdu			*pdus;
260 	uint32_t				resource_count;
261 	uint32_t				recv_buf_size;
262 
263 	struct spdk_nvmf_tcp_port		*port;
264 
265 	/* IP address */
266 	char					initiator_addr[SPDK_NVMF_TRADDR_MAX_LEN];
267 	char					target_addr[SPDK_NVMF_TRADDR_MAX_LEN];
268 
269 	/* IP port */
270 	uint16_t				initiator_port;
271 	uint16_t				target_port;
272 
273 	/* Timer used to destroy qpair after detecting transport error issue if initiator does
274 	 *  not close the connection.
275 	 */
276 	struct spdk_poller			*timeout_poller;
277 
278 
279 	TAILQ_ENTRY(spdk_nvmf_tcp_qpair)	link;
280 };
281 
282 struct spdk_nvmf_tcp_control_msg {
283 	STAILQ_ENTRY(spdk_nvmf_tcp_control_msg) link;
284 };
285 
286 struct spdk_nvmf_tcp_control_msg_list {
287 	void *msg_buf;
288 	STAILQ_HEAD(, spdk_nvmf_tcp_control_msg) free_msgs;
289 };
290 
291 struct spdk_nvmf_tcp_poll_group {
292 	struct spdk_nvmf_transport_poll_group	group;
293 	struct spdk_sock_group			*sock_group;
294 
295 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	qpairs;
296 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	await_req;
297 
298 	struct spdk_io_channel			*accel_channel;
299 	struct spdk_nvmf_tcp_control_msg_list	*control_msg_list;
300 };
301 
302 struct spdk_nvmf_tcp_port {
303 	const struct spdk_nvme_transport_id	*trid;
304 	struct spdk_sock			*listen_sock;
305 	TAILQ_ENTRY(spdk_nvmf_tcp_port)		link;
306 };
307 
308 struct tcp_transport_opts {
309 	bool		c2h_success;
310 	uint16_t	control_msg_num;
311 	uint32_t	sock_priority;
312 };
313 
314 struct spdk_nvmf_tcp_transport {
315 	struct spdk_nvmf_transport		transport;
316 	struct tcp_transport_opts               tcp_opts;
317 
318 	pthread_mutex_t				lock;
319 
320 	TAILQ_HEAD(, spdk_nvmf_tcp_port)	ports;
321 };
322 
323 static const struct spdk_json_object_decoder tcp_transport_opts_decoder[] = {
324 	{
325 		"c2h_success", offsetof(struct tcp_transport_opts, c2h_success),
326 		spdk_json_decode_bool, true
327 	},
328 	{
329 		"control_msg_num", offsetof(struct tcp_transport_opts, control_msg_num),
330 		spdk_json_decode_uint16, true
331 	},
332 	{
333 		"sock_priority", offsetof(struct tcp_transport_opts, sock_priority),
334 		spdk_json_decode_uint32, true
335 	},
336 };
337 
338 static bool nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
339 				 struct spdk_nvmf_tcp_req *tcp_req);
340 static void nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group);
341 
342 static void _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
343 				    struct spdk_nvmf_tcp_req *tcp_req);
344 
345 static void
346 nvmf_tcp_req_set_state(struct spdk_nvmf_tcp_req *tcp_req,
347 		       enum spdk_nvmf_tcp_req_state state)
348 {
349 	struct spdk_nvmf_qpair *qpair;
350 	struct spdk_nvmf_tcp_qpair *tqpair;
351 
352 	qpair = tcp_req->req.qpair;
353 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
354 
355 	assert(tqpair->state_cntr[tcp_req->state] > 0);
356 	tqpair->state_cntr[tcp_req->state]--;
357 	tqpair->state_cntr[state]++;
358 
359 	tcp_req->state = state;
360 }
361 
362 static inline struct nvme_tcp_pdu *
363 nvmf_tcp_req_pdu_init(struct spdk_nvmf_tcp_req *tcp_req)
364 {
365 	assert(tcp_req->pdu_in_use == false);
366 	tcp_req->pdu_in_use = true;
367 
368 	memset(tcp_req->pdu, 0, sizeof(*tcp_req->pdu));
369 	tcp_req->pdu->qpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
370 
371 	return tcp_req->pdu;
372 }
373 
374 static inline void
375 nvmf_tcp_req_pdu_fini(struct spdk_nvmf_tcp_req *tcp_req)
376 {
377 	tcp_req->pdu_in_use = false;
378 }
379 
380 static struct spdk_nvmf_tcp_req *
381 nvmf_tcp_req_get(struct spdk_nvmf_tcp_qpair *tqpair)
382 {
383 	struct spdk_nvmf_tcp_req *tcp_req;
384 
385 	tcp_req = TAILQ_FIRST(&tqpair->tcp_req_free_queue);
386 	if (!tcp_req) {
387 		return NULL;
388 	}
389 
390 	memset(&tcp_req->rsp, 0, sizeof(tcp_req->rsp));
391 	tcp_req->h2c_offset = 0;
392 	tcp_req->has_incapsule_data = false;
393 	tcp_req->req.dif_enabled = false;
394 
395 	TAILQ_REMOVE(&tqpair->tcp_req_free_queue, tcp_req, state_link);
396 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_working_queue, tcp_req, state_link);
397 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEW);
398 	return tcp_req;
399 }
400 
401 static inline void
402 nvmf_tcp_req_put(struct spdk_nvmf_tcp_qpair *tqpair, struct spdk_nvmf_tcp_req *tcp_req)
403 {
404 	TAILQ_REMOVE(&tqpair->tcp_req_working_queue, tcp_req, state_link);
405 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
406 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_FREE);
407 }
408 
409 static void
410 nvmf_tcp_request_free(void *cb_arg)
411 {
412 	struct spdk_nvmf_tcp_transport *ttransport;
413 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
414 
415 	assert(tcp_req != NULL);
416 
417 	SPDK_DEBUGLOG(nvmf_tcp, "tcp_req=%p will be freed\n", tcp_req);
418 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
419 				      struct spdk_nvmf_tcp_transport, transport);
420 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
421 	nvmf_tcp_req_process(ttransport, tcp_req);
422 }
423 
424 static int
425 nvmf_tcp_req_free(struct spdk_nvmf_request *req)
426 {
427 	struct spdk_nvmf_tcp_req *tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
428 
429 	nvmf_tcp_request_free(tcp_req);
430 
431 	return 0;
432 }
433 
434 static void
435 nvmf_tcp_drain_state_queue(struct spdk_nvmf_tcp_qpair *tqpair,
436 			   enum spdk_nvmf_tcp_req_state state)
437 {
438 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
439 
440 	assert(state != TCP_REQUEST_STATE_FREE);
441 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
442 		if (state == tcp_req->state) {
443 			nvmf_tcp_request_free(tcp_req);
444 		}
445 	}
446 }
447 
448 static void
449 nvmf_tcp_cleanup_all_states(struct spdk_nvmf_tcp_qpair *tqpair)
450 {
451 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
452 
453 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
454 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEW);
455 
456 	/* Wipe the requests waiting for buffer from the global list */
457 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
458 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
459 			STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue, &tcp_req->req,
460 				      spdk_nvmf_request, buf_link);
461 		}
462 	}
463 
464 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEED_BUFFER);
465 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_EXECUTING);
466 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
467 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
468 }
469 
470 static void
471 nvmf_tcp_dump_qpair_req_contents(struct spdk_nvmf_tcp_qpair *tqpair)
472 {
473 	int i;
474 	struct spdk_nvmf_tcp_req *tcp_req;
475 
476 	SPDK_ERRLOG("Dumping contents of queue pair (QID %d)\n", tqpair->qpair.qid);
477 	for (i = 1; i < TCP_REQUEST_NUM_STATES; i++) {
478 		SPDK_ERRLOG("\tNum of requests in state[%d] = %u\n", i, tqpair->state_cntr[i]);
479 		TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
480 			if ((int)tcp_req->state == i) {
481 				SPDK_ERRLOG("\t\tRequest Data From Pool: %d\n", tcp_req->req.data_from_pool);
482 				SPDK_ERRLOG("\t\tRequest opcode: %d\n", tcp_req->req.cmd->nvmf_cmd.opcode);
483 			}
484 		}
485 	}
486 }
487 
488 static void
489 nvmf_tcp_qpair_destroy(struct spdk_nvmf_tcp_qpair *tqpair)
490 {
491 	int err = 0;
492 
493 	spdk_trace_record(TRACE_TCP_QP_DESTROY, 0, 0, (uintptr_t)tqpair);
494 
495 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
496 
497 	err = spdk_sock_close(&tqpair->sock);
498 	assert(err == 0);
499 	nvmf_tcp_cleanup_all_states(tqpair);
500 
501 	if (tqpair->state_cntr[TCP_REQUEST_STATE_FREE] != tqpair->resource_count) {
502 		SPDK_ERRLOG("tqpair(%p) free tcp request num is %u but should be %u\n", tqpair,
503 			    tqpair->state_cntr[TCP_REQUEST_STATE_FREE],
504 			    tqpair->resource_count);
505 		err++;
506 	}
507 
508 	if (err > 0) {
509 		nvmf_tcp_dump_qpair_req_contents(tqpair);
510 	}
511 
512 	spdk_dma_free(tqpair->pdus);
513 	free(tqpair->reqs);
514 	spdk_free(tqpair->bufs);
515 	free(tqpair);
516 	SPDK_DEBUGLOG(nvmf_tcp, "Leave\n");
517 }
518 
519 static void
520 nvmf_tcp_dump_opts(struct spdk_nvmf_transport *transport, struct spdk_json_write_ctx *w)
521 {
522 	struct spdk_nvmf_tcp_transport	*ttransport;
523 	assert(w != NULL);
524 
525 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
526 	spdk_json_write_named_bool(w, "c2h_success", ttransport->tcp_opts.c2h_success);
527 	spdk_json_write_named_uint32(w, "sock_priority", ttransport->tcp_opts.sock_priority);
528 }
529 
530 static int
531 nvmf_tcp_destroy(struct spdk_nvmf_transport *transport,
532 		 spdk_nvmf_transport_destroy_done_cb cb_fn, void *cb_arg)
533 {
534 	struct spdk_nvmf_tcp_transport	*ttransport;
535 
536 	assert(transport != NULL);
537 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
538 
539 	pthread_mutex_destroy(&ttransport->lock);
540 	free(ttransport);
541 
542 	if (cb_fn) {
543 		cb_fn(cb_arg);
544 	}
545 	return 0;
546 }
547 
548 static struct spdk_nvmf_transport *
549 nvmf_tcp_create(struct spdk_nvmf_transport_opts *opts)
550 {
551 	struct spdk_nvmf_tcp_transport *ttransport;
552 	uint32_t sge_count;
553 	uint32_t min_shared_buffers;
554 
555 	ttransport = calloc(1, sizeof(*ttransport));
556 	if (!ttransport) {
557 		return NULL;
558 	}
559 
560 	TAILQ_INIT(&ttransport->ports);
561 
562 	ttransport->transport.ops = &spdk_nvmf_transport_tcp;
563 
564 	ttransport->tcp_opts.c2h_success = SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION;
565 	ttransport->tcp_opts.sock_priority = SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY;
566 	ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
567 	if (opts->transport_specific != NULL &&
568 	    spdk_json_decode_object_relaxed(opts->transport_specific, tcp_transport_opts_decoder,
569 					    SPDK_COUNTOF(tcp_transport_opts_decoder),
570 					    &ttransport->tcp_opts)) {
571 		SPDK_ERRLOG("spdk_json_decode_object_relaxed failed\n");
572 		free(ttransport);
573 		return NULL;
574 	}
575 
576 	SPDK_NOTICELOG("*** TCP Transport Init ***\n");
577 
578 	SPDK_INFOLOG(nvmf_tcp, "*** TCP Transport Init ***\n"
579 		     "  Transport opts:  max_ioq_depth=%d, max_io_size=%d,\n"
580 		     "  max_io_qpairs_per_ctrlr=%d, io_unit_size=%d,\n"
581 		     "  in_capsule_data_size=%d, max_aq_depth=%d\n"
582 		     "  num_shared_buffers=%d, c2h_success=%d,\n"
583 		     "  dif_insert_or_strip=%d, sock_priority=%d\n"
584 		     "  abort_timeout_sec=%d, control_msg_num=%hu\n",
585 		     opts->max_queue_depth,
586 		     opts->max_io_size,
587 		     opts->max_qpairs_per_ctrlr - 1,
588 		     opts->io_unit_size,
589 		     opts->in_capsule_data_size,
590 		     opts->max_aq_depth,
591 		     opts->num_shared_buffers,
592 		     ttransport->tcp_opts.c2h_success,
593 		     opts->dif_insert_or_strip,
594 		     ttransport->tcp_opts.sock_priority,
595 		     opts->abort_timeout_sec,
596 		     ttransport->tcp_opts.control_msg_num);
597 
598 	if (ttransport->tcp_opts.sock_priority > SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY) {
599 		SPDK_ERRLOG("Unsupported socket_priority=%d, the current range is: 0 to %d\n"
600 			    "you can use man 7 socket to view the range of priority under SO_PRIORITY item\n",
601 			    ttransport->tcp_opts.sock_priority, SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY);
602 		free(ttransport);
603 		return NULL;
604 	}
605 
606 	if (ttransport->tcp_opts.control_msg_num == 0 &&
607 	    opts->in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
608 		SPDK_WARNLOG("TCP param control_msg_num can't be 0 if ICD is less than %u bytes. Using default value %u\n",
609 			     SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE, SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM);
610 		ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
611 	}
612 
613 	/* I/O unit size cannot be larger than max I/O size */
614 	if (opts->io_unit_size > opts->max_io_size) {
615 		opts->io_unit_size = opts->max_io_size;
616 	}
617 
618 	sge_count = opts->max_io_size / opts->io_unit_size;
619 	if (sge_count > SPDK_NVMF_MAX_SGL_ENTRIES) {
620 		SPDK_ERRLOG("Unsupported IO Unit size specified, %d bytes\n", opts->io_unit_size);
621 		free(ttransport);
622 		return NULL;
623 	}
624 
625 	min_shared_buffers = spdk_env_get_core_count() * opts->buf_cache_size;
626 	if (min_shared_buffers > opts->num_shared_buffers) {
627 		SPDK_ERRLOG("There are not enough buffers to satisfy "
628 			    "per-poll group caches for each thread. (%" PRIu32 ") "
629 			    "supplied. (%" PRIu32 ") required\n", opts->num_shared_buffers, min_shared_buffers);
630 		SPDK_ERRLOG("Please specify a larger number of shared buffers\n");
631 		free(ttransport);
632 		return NULL;
633 	}
634 
635 	pthread_mutex_init(&ttransport->lock, NULL);
636 
637 	return &ttransport->transport;
638 }
639 
640 static int
641 nvmf_tcp_trsvcid_to_int(const char *trsvcid)
642 {
643 	unsigned long long ull;
644 	char *end = NULL;
645 
646 	ull = strtoull(trsvcid, &end, 10);
647 	if (end == NULL || end == trsvcid || *end != '\0') {
648 		return -1;
649 	}
650 
651 	/* Valid TCP/IP port numbers are in [0, 65535] */
652 	if (ull > 65535) {
653 		return -1;
654 	}
655 
656 	return (int)ull;
657 }
658 
659 /**
660  * Canonicalize a listen address trid.
661  */
662 static int
663 nvmf_tcp_canon_listen_trid(struct spdk_nvme_transport_id *canon_trid,
664 			   const struct spdk_nvme_transport_id *trid)
665 {
666 	int trsvcid_int;
667 
668 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
669 	if (trsvcid_int < 0) {
670 		return -EINVAL;
671 	}
672 
673 	memset(canon_trid, 0, sizeof(*canon_trid));
674 	spdk_nvme_trid_populate_transport(canon_trid, SPDK_NVME_TRANSPORT_TCP);
675 	canon_trid->adrfam = trid->adrfam;
676 	snprintf(canon_trid->traddr, sizeof(canon_trid->traddr), "%s", trid->traddr);
677 	snprintf(canon_trid->trsvcid, sizeof(canon_trid->trsvcid), "%d", trsvcid_int);
678 
679 	return 0;
680 }
681 
682 /**
683  * Find an existing listening port.
684  *
685  * Caller must hold ttransport->lock.
686  */
687 static struct spdk_nvmf_tcp_port *
688 nvmf_tcp_find_port(struct spdk_nvmf_tcp_transport *ttransport,
689 		   const struct spdk_nvme_transport_id *trid)
690 {
691 	struct spdk_nvme_transport_id canon_trid;
692 	struct spdk_nvmf_tcp_port *port;
693 
694 	if (nvmf_tcp_canon_listen_trid(&canon_trid, trid) != 0) {
695 		return NULL;
696 	}
697 
698 	TAILQ_FOREACH(port, &ttransport->ports, link) {
699 		if (spdk_nvme_transport_id_compare(&canon_trid, port->trid) == 0) {
700 			return port;
701 		}
702 	}
703 
704 	return NULL;
705 }
706 
707 static int
708 nvmf_tcp_listen(struct spdk_nvmf_transport *transport, const struct spdk_nvme_transport_id *trid,
709 		struct spdk_nvmf_listen_opts *listen_opts)
710 {
711 	struct spdk_nvmf_tcp_transport *ttransport;
712 	struct spdk_nvmf_tcp_port *port;
713 	int trsvcid_int;
714 	uint8_t adrfam;
715 	struct spdk_sock_opts opts;
716 
717 	if (!strlen(trid->trsvcid)) {
718 		SPDK_ERRLOG("Service id is required\n");
719 		return -EINVAL;
720 	}
721 
722 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
723 
724 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
725 	if (trsvcid_int < 0) {
726 		SPDK_ERRLOG("Invalid trsvcid '%s'\n", trid->trsvcid);
727 		return -EINVAL;
728 	}
729 
730 	pthread_mutex_lock(&ttransport->lock);
731 	port = calloc(1, sizeof(*port));
732 	if (!port) {
733 		SPDK_ERRLOG("Port allocation failed\n");
734 		pthread_mutex_unlock(&ttransport->lock);
735 		return -ENOMEM;
736 	}
737 
738 	port->trid = trid;
739 	opts.opts_size = sizeof(opts);
740 	spdk_sock_get_default_opts(&opts);
741 	opts.priority = ttransport->tcp_opts.sock_priority;
742 	port->listen_sock = spdk_sock_listen_ext(trid->traddr, trsvcid_int,
743 			    NULL, &opts);
744 	if (port->listen_sock == NULL) {
745 		SPDK_ERRLOG("spdk_sock_listen(%s, %d) failed: %s (%d)\n",
746 			    trid->traddr, trsvcid_int,
747 			    spdk_strerror(errno), errno);
748 		free(port);
749 		pthread_mutex_unlock(&ttransport->lock);
750 		return -errno;
751 	}
752 
753 	if (spdk_sock_is_ipv4(port->listen_sock)) {
754 		adrfam = SPDK_NVMF_ADRFAM_IPV4;
755 	} else if (spdk_sock_is_ipv6(port->listen_sock)) {
756 		adrfam = SPDK_NVMF_ADRFAM_IPV6;
757 	} else {
758 		SPDK_ERRLOG("Unhandled socket type\n");
759 		adrfam = 0;
760 	}
761 
762 	if (adrfam != trid->adrfam) {
763 		SPDK_ERRLOG("Socket address family mismatch\n");
764 		spdk_sock_close(&port->listen_sock);
765 		free(port);
766 		pthread_mutex_unlock(&ttransport->lock);
767 		return -EINVAL;
768 	}
769 
770 	SPDK_NOTICELOG("*** NVMe/TCP Target Listening on %s port %s ***\n",
771 		       trid->traddr, trid->trsvcid);
772 
773 	TAILQ_INSERT_TAIL(&ttransport->ports, port, link);
774 	pthread_mutex_unlock(&ttransport->lock);
775 	return 0;
776 }
777 
778 static void
779 nvmf_tcp_stop_listen(struct spdk_nvmf_transport *transport,
780 		     const struct spdk_nvme_transport_id *trid)
781 {
782 	struct spdk_nvmf_tcp_transport *ttransport;
783 	struct spdk_nvmf_tcp_port *port;
784 
785 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
786 
787 	SPDK_DEBUGLOG(nvmf_tcp, "Removing listen address %s port %s\n",
788 		      trid->traddr, trid->trsvcid);
789 
790 	pthread_mutex_lock(&ttransport->lock);
791 	port = nvmf_tcp_find_port(ttransport, trid);
792 	if (port) {
793 		TAILQ_REMOVE(&ttransport->ports, port, link);
794 		spdk_sock_close(&port->listen_sock);
795 		free(port);
796 	}
797 
798 	pthread_mutex_unlock(&ttransport->lock);
799 }
800 
801 static void nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
802 		enum nvme_tcp_pdu_recv_state state);
803 
804 static void
805 nvmf_tcp_qpair_set_state(struct spdk_nvmf_tcp_qpair *tqpair, enum nvme_tcp_qpair_state state)
806 {
807 	tqpair->state = state;
808 	spdk_trace_record(TRACE_TCP_QP_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->state);
809 }
810 
811 static void
812 nvmf_tcp_qpair_disconnect(struct spdk_nvmf_tcp_qpair *tqpair)
813 {
814 	SPDK_DEBUGLOG(nvmf_tcp, "Disconnecting qpair %p\n", tqpair);
815 
816 	spdk_trace_record(TRACE_TCP_QP_DISCONNECT, 0, 0, (uintptr_t)tqpair);
817 
818 	if (tqpair->state <= NVME_TCP_QPAIR_STATE_RUNNING) {
819 		nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITING);
820 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
821 		spdk_poller_unregister(&tqpair->timeout_poller);
822 
823 		/* This will end up calling nvmf_tcp_close_qpair */
824 		spdk_nvmf_qpair_disconnect(&tqpair->qpair, NULL, NULL);
825 	}
826 }
827 
828 static void
829 _pdu_write_done(void *_pdu, int err)
830 {
831 	struct nvme_tcp_pdu			*pdu = _pdu;
832 	struct spdk_nvmf_tcp_qpair		*tqpair = pdu->qpair;
833 
834 	if (err != 0) {
835 		nvmf_tcp_qpair_disconnect(tqpair);
836 		return;
837 	}
838 
839 	assert(pdu->cb_fn != NULL);
840 	pdu->cb_fn(pdu->cb_arg);
841 }
842 
843 static void
844 _tcp_write_pdu(struct nvme_tcp_pdu *pdu)
845 {
846 	uint32_t mapped_length = 0;
847 	ssize_t rc;
848 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
849 
850 	pdu->sock_req.iovcnt = nvme_tcp_build_iovs(pdu->iov, SPDK_COUNTOF(pdu->iov), pdu,
851 			       tqpair->host_hdgst_enable, tqpair->host_ddgst_enable,
852 			       &mapped_length);
853 	pdu->sock_req.cb_fn = _pdu_write_done;
854 	pdu->sock_req.cb_arg = pdu;
855 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_RESP ||
856 	    pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ) {
857 		rc = spdk_sock_writev(tqpair->sock, pdu->iov, pdu->sock_req.iovcnt);
858 		if (rc == mapped_length) {
859 			_pdu_write_done(pdu, 0);
860 		} else {
861 			SPDK_ERRLOG("IC_RESP or TERM_REQ could not write to socket.\n");
862 			_pdu_write_done(pdu, -1);
863 		}
864 	} else {
865 		spdk_sock_writev_async(tqpair->sock, &pdu->sock_req);
866 	}
867 }
868 
869 static void
870 data_crc32_accel_done(void *cb_arg, int status)
871 {
872 	struct nvme_tcp_pdu *pdu = cb_arg;
873 
874 	if (spdk_unlikely(status)) {
875 		SPDK_ERRLOG("Failed to compute the data digest for pdu =%p\n", pdu);
876 		_pdu_write_done(pdu, status);
877 		return;
878 	}
879 
880 	pdu->data_digest_crc32 ^= SPDK_CRC32C_XOR;
881 	MAKE_DIGEST_WORD(pdu->data_digest, pdu->data_digest_crc32);
882 
883 	_tcp_write_pdu(pdu);
884 }
885 
886 static void
887 pdu_data_crc32_compute(struct nvme_tcp_pdu *pdu)
888 {
889 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
890 	uint32_t crc32c;
891 
892 	/* Data Digest */
893 	if (pdu->data_len > 0 && g_nvme_tcp_ddgst[pdu->hdr.common.pdu_type] && tqpair->host_ddgst_enable) {
894 		/* Only suport this limitated case for the first step */
895 		if (spdk_likely(!pdu->dif_ctx && (pdu->data_len % SPDK_NVME_TCP_DIGEST_ALIGNMENT == 0)
896 				&& tqpair->group)) {
897 			spdk_accel_submit_crc32cv(tqpair->group->accel_channel, &pdu->data_digest_crc32,
898 						  pdu->data_iov, pdu->data_iovcnt, 0, data_crc32_accel_done, pdu);
899 			return;
900 		}
901 
902 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
903 		MAKE_DIGEST_WORD(pdu->data_digest, crc32c);
904 	}
905 
906 	_tcp_write_pdu(pdu);
907 }
908 
909 static void
910 nvmf_tcp_qpair_write_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
911 			 struct nvme_tcp_pdu *pdu,
912 			 nvme_tcp_qpair_xfer_complete_cb cb_fn,
913 			 void *cb_arg)
914 {
915 	int hlen;
916 	uint32_t crc32c;
917 
918 	assert(tqpair->pdu_in_progress != pdu);
919 
920 	hlen = pdu->hdr.common.hlen;
921 	pdu->cb_fn = cb_fn;
922 	pdu->cb_arg = cb_arg;
923 
924 	pdu->iov[0].iov_base = &pdu->hdr.raw;
925 	pdu->iov[0].iov_len = hlen;
926 
927 	/* Header Digest */
928 	if (g_nvme_tcp_hdgst[pdu->hdr.common.pdu_type] && tqpair->host_hdgst_enable) {
929 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
930 		MAKE_DIGEST_WORD((uint8_t *)pdu->hdr.raw + hlen, crc32c);
931 	}
932 
933 	/* Data Digest */
934 	pdu_data_crc32_compute(pdu);
935 }
936 
937 static int
938 nvmf_tcp_qpair_init_mem_resource(struct spdk_nvmf_tcp_qpair *tqpair)
939 {
940 	uint32_t i;
941 	struct spdk_nvmf_transport_opts *opts;
942 	uint32_t in_capsule_data_size;
943 
944 	opts = &tqpair->qpair.transport->opts;
945 
946 	in_capsule_data_size = opts->in_capsule_data_size;
947 	if (opts->dif_insert_or_strip) {
948 		in_capsule_data_size = SPDK_BDEV_BUF_SIZE_WITH_MD(in_capsule_data_size);
949 	}
950 
951 	tqpair->resource_count = opts->max_queue_depth;
952 
953 	tqpair->reqs = calloc(tqpair->resource_count, sizeof(*tqpair->reqs));
954 	if (!tqpair->reqs) {
955 		SPDK_ERRLOG("Unable to allocate reqs on tqpair=%p\n", tqpair);
956 		return -1;
957 	}
958 
959 	if (in_capsule_data_size) {
960 		tqpair->bufs = spdk_zmalloc(tqpair->resource_count * in_capsule_data_size, 0x1000,
961 					    NULL, SPDK_ENV_LCORE_ID_ANY,
962 					    SPDK_MALLOC_DMA);
963 		if (!tqpair->bufs) {
964 			SPDK_ERRLOG("Unable to allocate bufs on tqpair=%p.\n", tqpair);
965 			return -1;
966 		}
967 	}
968 
969 	/* Add addtional 2 members, which will be used for mgmt_pdu and pdu_in_progress owned by the tqpair */
970 	tqpair->pdus = spdk_dma_zmalloc((tqpair->resource_count + 2) * sizeof(*tqpair->pdus), 0x1000, NULL);
971 	if (!tqpair->pdus) {
972 		SPDK_ERRLOG("Unable to allocate pdu pool on tqpair =%p.\n", tqpair);
973 		return -1;
974 	}
975 
976 	for (i = 0; i < tqpair->resource_count; i++) {
977 		struct spdk_nvmf_tcp_req *tcp_req = &tqpair->reqs[i];
978 
979 		tcp_req->ttag = i + 1;
980 		tcp_req->req.qpair = &tqpair->qpair;
981 
982 		tcp_req->pdu = &tqpair->pdus[i];
983 		tcp_req->pdu->qpair = tqpair;
984 
985 		/* Set up memory to receive commands */
986 		if (tqpair->bufs) {
987 			tcp_req->buf = (void *)((uintptr_t)tqpair->bufs + (i * in_capsule_data_size));
988 		}
989 
990 		/* Set the cmdn and rsp */
991 		tcp_req->req.rsp = (union nvmf_c2h_msg *)&tcp_req->rsp;
992 		tcp_req->req.cmd = (union nvmf_h2c_msg *)&tcp_req->cmd;
993 
994 		/* Initialize request state to FREE */
995 		tcp_req->state = TCP_REQUEST_STATE_FREE;
996 		TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
997 		tqpair->state_cntr[TCP_REQUEST_STATE_FREE]++;
998 	}
999 
1000 	tqpair->mgmt_pdu = &tqpair->pdus[i];
1001 	tqpair->mgmt_pdu->qpair = tqpair;
1002 	tqpair->pdu_in_progress = &tqpair->pdus[i + 1];
1003 
1004 	tqpair->recv_buf_size = (in_capsule_data_size + sizeof(struct spdk_nvme_tcp_cmd) + 2 *
1005 				 SPDK_NVME_TCP_DIGEST_LEN) * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1006 
1007 	return 0;
1008 }
1009 
1010 static int
1011 nvmf_tcp_qpair_init(struct spdk_nvmf_qpair *qpair)
1012 {
1013 	struct spdk_nvmf_tcp_qpair *tqpair;
1014 
1015 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1016 
1017 	SPDK_DEBUGLOG(nvmf_tcp, "New TCP Connection: %p\n", qpair);
1018 
1019 	spdk_trace_record(TRACE_TCP_QP_CREATE, 0, 0, (uintptr_t)tqpair);
1020 
1021 	/* Initialise request state queues of the qpair */
1022 	TAILQ_INIT(&tqpair->tcp_req_free_queue);
1023 	TAILQ_INIT(&tqpair->tcp_req_working_queue);
1024 
1025 	tqpair->host_hdgst_enable = true;
1026 	tqpair->host_ddgst_enable = true;
1027 
1028 	return 0;
1029 }
1030 
1031 static int
1032 nvmf_tcp_qpair_sock_init(struct spdk_nvmf_tcp_qpair *tqpair)
1033 {
1034 	int rc;
1035 
1036 	spdk_trace_record(TRACE_TCP_QP_SOCK_INIT, 0, 0, (uintptr_t)tqpair);
1037 
1038 	/* set low water mark */
1039 	rc = spdk_sock_set_recvlowat(tqpair->sock, sizeof(struct spdk_nvme_tcp_common_pdu_hdr));
1040 	if (rc != 0) {
1041 		SPDK_ERRLOG("spdk_sock_set_recvlowat() failed\n");
1042 		return rc;
1043 	}
1044 
1045 	return 0;
1046 }
1047 
1048 static void
1049 nvmf_tcp_handle_connect(struct spdk_nvmf_transport *transport,
1050 			struct spdk_nvmf_tcp_port *port,
1051 			struct spdk_sock *sock)
1052 {
1053 	struct spdk_nvmf_tcp_qpair *tqpair;
1054 	int rc;
1055 
1056 	SPDK_DEBUGLOG(nvmf_tcp, "New connection accepted on %s port %s\n",
1057 		      port->trid->traddr, port->trid->trsvcid);
1058 
1059 	tqpair = calloc(1, sizeof(struct spdk_nvmf_tcp_qpair));
1060 	if (tqpair == NULL) {
1061 		SPDK_ERRLOG("Could not allocate new connection.\n");
1062 		spdk_sock_close(&sock);
1063 		return;
1064 	}
1065 
1066 	tqpair->sock = sock;
1067 	tqpair->state_cntr[TCP_REQUEST_STATE_FREE] = 0;
1068 	tqpair->port = port;
1069 	tqpair->qpair.transport = transport;
1070 
1071 	rc = spdk_sock_getaddr(tqpair->sock, tqpair->target_addr,
1072 			       sizeof(tqpair->target_addr), &tqpair->target_port,
1073 			       tqpair->initiator_addr, sizeof(tqpair->initiator_addr),
1074 			       &tqpair->initiator_port);
1075 	if (rc < 0) {
1076 		SPDK_ERRLOG("spdk_sock_getaddr() failed of tqpair=%p\n", tqpair);
1077 		nvmf_tcp_qpair_destroy(tqpair);
1078 		return;
1079 	}
1080 
1081 	spdk_nvmf_tgt_new_qpair(transport->tgt, &tqpair->qpair);
1082 }
1083 
1084 static uint32_t
1085 nvmf_tcp_port_accept(struct spdk_nvmf_transport *transport, struct spdk_nvmf_tcp_port *port)
1086 {
1087 	struct spdk_sock *sock;
1088 	uint32_t count = 0;
1089 	int i;
1090 
1091 	for (i = 0; i < NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME; i++) {
1092 		sock = spdk_sock_accept(port->listen_sock);
1093 		if (sock == NULL) {
1094 			break;
1095 		}
1096 		count++;
1097 		nvmf_tcp_handle_connect(transport, port, sock);
1098 	}
1099 
1100 	return count;
1101 }
1102 
1103 static uint32_t
1104 nvmf_tcp_accept(struct spdk_nvmf_transport *transport)
1105 {
1106 	struct spdk_nvmf_tcp_transport *ttransport;
1107 	struct spdk_nvmf_tcp_port *port;
1108 	uint32_t count = 0;
1109 
1110 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1111 
1112 	TAILQ_FOREACH(port, &ttransport->ports, link) {
1113 		count += nvmf_tcp_port_accept(transport, port);
1114 	}
1115 
1116 	return count;
1117 }
1118 
1119 static void
1120 nvmf_tcp_discover(struct spdk_nvmf_transport *transport,
1121 		  struct spdk_nvme_transport_id *trid,
1122 		  struct spdk_nvmf_discovery_log_page_entry *entry)
1123 {
1124 	entry->trtype = SPDK_NVMF_TRTYPE_TCP;
1125 	entry->adrfam = trid->adrfam;
1126 	entry->treq.secure_channel = SPDK_NVMF_TREQ_SECURE_CHANNEL_NOT_REQUIRED;
1127 
1128 	spdk_strcpy_pad(entry->trsvcid, trid->trsvcid, sizeof(entry->trsvcid), ' ');
1129 	spdk_strcpy_pad(entry->traddr, trid->traddr, sizeof(entry->traddr), ' ');
1130 
1131 	entry->tsas.tcp.sectype = SPDK_NVME_TCP_SECURITY_NONE;
1132 }
1133 
1134 static struct spdk_nvmf_tcp_control_msg_list *
1135 nvmf_tcp_control_msg_list_create(uint16_t num_messages)
1136 {
1137 	struct spdk_nvmf_tcp_control_msg_list *list;
1138 	struct spdk_nvmf_tcp_control_msg *msg;
1139 	uint16_t i;
1140 
1141 	list = calloc(1, sizeof(*list));
1142 	if (!list) {
1143 		SPDK_ERRLOG("Failed to allocate memory for list structure\n");
1144 		return NULL;
1145 	}
1146 
1147 	list->msg_buf = spdk_zmalloc(num_messages * SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE,
1148 				     NVMF_DATA_BUFFER_ALIGNMENT, NULL, SPDK_ENV_SOCKET_ID_ANY, SPDK_MALLOC_DMA);
1149 	if (!list->msg_buf) {
1150 		SPDK_ERRLOG("Failed to allocate memory for control message buffers\n");
1151 		free(list);
1152 		return NULL;
1153 	}
1154 
1155 	STAILQ_INIT(&list->free_msgs);
1156 
1157 	for (i = 0; i < num_messages; i++) {
1158 		msg = (struct spdk_nvmf_tcp_control_msg *)((char *)list->msg_buf + i *
1159 				SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1160 		STAILQ_INSERT_TAIL(&list->free_msgs, msg, link);
1161 	}
1162 
1163 	return list;
1164 }
1165 
1166 static void
1167 nvmf_tcp_control_msg_list_free(struct spdk_nvmf_tcp_control_msg_list *list)
1168 {
1169 	if (!list) {
1170 		return;
1171 	}
1172 
1173 	spdk_free(list->msg_buf);
1174 	free(list);
1175 }
1176 
1177 static struct spdk_nvmf_transport_poll_group *
1178 nvmf_tcp_poll_group_create(struct spdk_nvmf_transport *transport)
1179 {
1180 	struct spdk_nvmf_tcp_transport	*ttransport;
1181 	struct spdk_nvmf_tcp_poll_group *tgroup;
1182 
1183 	tgroup = calloc(1, sizeof(*tgroup));
1184 	if (!tgroup) {
1185 		return NULL;
1186 	}
1187 
1188 	tgroup->sock_group = spdk_sock_group_create(&tgroup->group);
1189 	if (!tgroup->sock_group) {
1190 		goto cleanup;
1191 	}
1192 
1193 	TAILQ_INIT(&tgroup->qpairs);
1194 	TAILQ_INIT(&tgroup->await_req);
1195 
1196 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1197 
1198 	if (transport->opts.in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
1199 		SPDK_DEBUGLOG(nvmf_tcp, "ICD %u is less than min required for admin/fabric commands (%u). "
1200 			      "Creating control messages list\n", transport->opts.in_capsule_data_size,
1201 			      SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1202 		tgroup->control_msg_list = nvmf_tcp_control_msg_list_create(ttransport->tcp_opts.control_msg_num);
1203 		if (!tgroup->control_msg_list) {
1204 			goto cleanup;
1205 		}
1206 	}
1207 
1208 	tgroup->accel_channel = spdk_accel_engine_get_io_channel();
1209 	if (spdk_unlikely(!tgroup->accel_channel)) {
1210 		SPDK_ERRLOG("Cannot create accel_channel for tgroup=%p\n", tgroup);
1211 		goto cleanup;
1212 	}
1213 
1214 	return &tgroup->group;
1215 
1216 cleanup:
1217 	nvmf_tcp_poll_group_destroy(&tgroup->group);
1218 	return NULL;
1219 }
1220 
1221 static struct spdk_nvmf_transport_poll_group *
1222 nvmf_tcp_get_optimal_poll_group(struct spdk_nvmf_qpair *qpair)
1223 {
1224 	struct spdk_nvmf_tcp_qpair *tqpair;
1225 	struct spdk_sock_group *group = NULL;
1226 	int rc;
1227 
1228 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1229 	rc = spdk_sock_get_optimal_sock_group(tqpair->sock, &group);
1230 	if (!rc && group != NULL) {
1231 		return spdk_sock_group_get_ctx(group);
1232 	}
1233 
1234 	return NULL;
1235 }
1236 
1237 static void
1238 nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group)
1239 {
1240 	struct spdk_nvmf_tcp_poll_group *tgroup;
1241 
1242 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
1243 	spdk_sock_group_close(&tgroup->sock_group);
1244 	if (tgroup->control_msg_list) {
1245 		nvmf_tcp_control_msg_list_free(tgroup->control_msg_list);
1246 	}
1247 
1248 	if (tgroup->accel_channel) {
1249 		spdk_put_io_channel(tgroup->accel_channel);
1250 	}
1251 
1252 	free(tgroup);
1253 }
1254 
1255 static void
1256 nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
1257 			      enum nvme_tcp_pdu_recv_state state)
1258 {
1259 	if (tqpair->recv_state == state) {
1260 		SPDK_ERRLOG("The recv state of tqpair=%p is same with the state(%d) to be set\n",
1261 			    tqpair, state);
1262 		return;
1263 	}
1264 
1265 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
1266 		/* When leaving the await req state, move the qpair to the main list */
1267 		TAILQ_REMOVE(&tqpair->group->await_req, tqpair, link);
1268 		TAILQ_INSERT_TAIL(&tqpair->group->qpairs, tqpair, link);
1269 	}
1270 
1271 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv state=%d\n", tqpair, state);
1272 	tqpair->recv_state = state;
1273 
1274 	spdk_trace_record(TRACE_TCP_QP_RCV_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->recv_state);
1275 
1276 	switch (state) {
1277 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
1278 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
1279 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
1280 		break;
1281 	case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
1282 		TAILQ_REMOVE(&tqpair->group->qpairs, tqpair, link);
1283 		TAILQ_INSERT_TAIL(&tqpair->group->await_req, tqpair, link);
1284 		break;
1285 	case NVME_TCP_PDU_RECV_STATE_ERROR:
1286 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1287 		memset(tqpair->pdu_in_progress, 0, sizeof(*(tqpair->pdu_in_progress)));
1288 		break;
1289 	default:
1290 		SPDK_ERRLOG("The state(%d) is invalid\n", state);
1291 		abort();
1292 		break;
1293 	}
1294 }
1295 
1296 static int
1297 nvmf_tcp_qpair_handle_timeout(void *ctx)
1298 {
1299 	struct spdk_nvmf_tcp_qpair *tqpair = ctx;
1300 
1301 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_ERROR);
1302 
1303 	SPDK_ERRLOG("No pdu coming for tqpair=%p within %d seconds\n", tqpair,
1304 		    SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT);
1305 
1306 	nvmf_tcp_qpair_disconnect(tqpair);
1307 	return SPDK_POLLER_BUSY;
1308 }
1309 
1310 static void
1311 nvmf_tcp_send_c2h_term_req_complete(void *cb_arg)
1312 {
1313 	struct spdk_nvmf_tcp_qpair *tqpair = (struct spdk_nvmf_tcp_qpair *)cb_arg;
1314 
1315 	if (!tqpair->timeout_poller) {
1316 		tqpair->timeout_poller = SPDK_POLLER_REGISTER(nvmf_tcp_qpair_handle_timeout, tqpair,
1317 					 SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT * 1000000);
1318 	}
1319 }
1320 
1321 static void
1322 nvmf_tcp_send_c2h_term_req(struct spdk_nvmf_tcp_qpair *tqpair, struct nvme_tcp_pdu *pdu,
1323 			   enum spdk_nvme_tcp_term_req_fes fes, uint32_t error_offset)
1324 {
1325 	struct nvme_tcp_pdu *rsp_pdu;
1326 	struct spdk_nvme_tcp_term_req_hdr *c2h_term_req;
1327 	uint32_t c2h_term_req_hdr_len = sizeof(*c2h_term_req);
1328 	uint32_t copy_len;
1329 
1330 	rsp_pdu = tqpair->mgmt_pdu;
1331 
1332 	c2h_term_req = &rsp_pdu->hdr.term_req;
1333 	c2h_term_req->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ;
1334 	c2h_term_req->common.hlen = c2h_term_req_hdr_len;
1335 
1336 	if ((fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1337 	    (fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1338 		DSET32(&c2h_term_req->fei, error_offset);
1339 	}
1340 
1341 	copy_len = spdk_min(pdu->hdr.common.hlen, SPDK_NVME_TCP_TERM_REQ_ERROR_DATA_MAX_SIZE);
1342 
1343 	/* Copy the error info into the buffer */
1344 	memcpy((uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, pdu->hdr.raw, copy_len);
1345 	nvme_tcp_pdu_set_data(rsp_pdu, (uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, copy_len);
1346 
1347 	/* Contain the header of the wrong received pdu */
1348 	c2h_term_req->common.plen = c2h_term_req->common.hlen + copy_len;
1349 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1350 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_c2h_term_req_complete, tqpair);
1351 }
1352 
1353 static void
1354 nvmf_tcp_capsule_cmd_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1355 				struct spdk_nvmf_tcp_qpair *tqpair,
1356 				struct nvme_tcp_pdu *pdu)
1357 {
1358 	struct spdk_nvmf_tcp_req *tcp_req;
1359 
1360 	assert(pdu->psh_valid_bytes == pdu->psh_len);
1361 	assert(pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD);
1362 
1363 	tcp_req = nvmf_tcp_req_get(tqpair);
1364 	if (!tcp_req) {
1365 		/* Directly return and make the allocation retry again */
1366 		if (tqpair->state_cntr[TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST] > 0) {
1367 			return;
1368 		}
1369 
1370 		/* The host sent more commands than the maximum queue depth. */
1371 		SPDK_ERRLOG("Cannot allocate tcp_req on tqpair=%p\n", tqpair);
1372 		nvmf_tcp_qpair_disconnect(tqpair);
1373 		return;
1374 	}
1375 
1376 	pdu->req = tcp_req;
1377 	assert(tcp_req->state == TCP_REQUEST_STATE_NEW);
1378 	nvmf_tcp_req_process(ttransport, tcp_req);
1379 }
1380 
1381 static void
1382 nvmf_tcp_capsule_cmd_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1383 				    struct spdk_nvmf_tcp_qpair *tqpair,
1384 				    struct nvme_tcp_pdu *pdu)
1385 {
1386 	struct spdk_nvmf_tcp_req *tcp_req;
1387 	struct spdk_nvme_tcp_cmd *capsule_cmd;
1388 	uint32_t error_offset = 0;
1389 	enum spdk_nvme_tcp_term_req_fes fes;
1390 	struct spdk_nvme_cpl *rsp;
1391 
1392 	capsule_cmd = &pdu->hdr.capsule_cmd;
1393 	tcp_req = pdu->req;
1394 	assert(tcp_req != NULL);
1395 
1396 	if (capsule_cmd->common.pdo > SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET) {
1397 		SPDK_ERRLOG("Expected ICReq capsule_cmd pdu offset <= %d, got %c\n",
1398 			    SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET, capsule_cmd->common.pdo);
1399 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1400 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1401 		goto err;
1402 	}
1403 
1404 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1405 
1406 	rsp = &tcp_req->req.rsp->nvme_cpl;
1407 	if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1408 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1409 	} else {
1410 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1411 	}
1412 
1413 	nvmf_tcp_req_process(ttransport, tcp_req);
1414 
1415 	return;
1416 err:
1417 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1418 }
1419 
1420 static int
1421 nvmf_tcp_find_req_in_state(struct spdk_nvmf_tcp_qpair *tqpair,
1422 			   enum spdk_nvmf_tcp_req_state state,
1423 			   uint16_t cid, uint16_t tag,
1424 			   struct spdk_nvmf_tcp_req **req)
1425 {
1426 	struct spdk_nvmf_tcp_req *tcp_req = NULL;
1427 
1428 	TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
1429 		if (tcp_req->state != state) {
1430 			continue;
1431 		}
1432 
1433 		if (tcp_req->req.cmd->nvme_cmd.cid != cid) {
1434 			continue;
1435 		}
1436 
1437 		if (tcp_req->ttag == tag) {
1438 			*req = tcp_req;
1439 			return 0;
1440 		}
1441 
1442 		*req = NULL;
1443 		return -1;
1444 	}
1445 
1446 	/* Didn't find it, but not an error */
1447 	*req = NULL;
1448 	return 0;
1449 }
1450 
1451 static void
1452 nvmf_tcp_h2c_data_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1453 			     struct spdk_nvmf_tcp_qpair *tqpair,
1454 			     struct nvme_tcp_pdu *pdu)
1455 {
1456 	struct spdk_nvmf_tcp_req *tcp_req;
1457 	uint32_t error_offset = 0;
1458 	enum spdk_nvme_tcp_term_req_fes fes = 0;
1459 	struct spdk_nvme_tcp_h2c_data_hdr *h2c_data;
1460 	int rc;
1461 
1462 	h2c_data = &pdu->hdr.h2c_data;
1463 
1464 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair=%p, r2t_info: datao=%u, datal=%u, cccid=%u, ttag=%u\n",
1465 		      tqpair, h2c_data->datao, h2c_data->datal, h2c_data->cccid, h2c_data->ttag);
1466 
1467 	rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
1468 					h2c_data->cccid, h2c_data->ttag, &tcp_req);
1469 	if (rc == 0 && tcp_req == NULL) {
1470 		rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK, h2c_data->cccid,
1471 						h2c_data->ttag, &tcp_req);
1472 	}
1473 
1474 	if (!tcp_req) {
1475 		SPDK_DEBUGLOG(nvmf_tcp, "tcp_req is not found for tqpair=%p\n", tqpair);
1476 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER;
1477 		if (rc == 0) {
1478 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, cccid);
1479 		} else {
1480 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, ttag);
1481 		}
1482 		goto err;
1483 	}
1484 
1485 	if (tcp_req->h2c_offset != h2c_data->datao) {
1486 		SPDK_DEBUGLOG(nvmf_tcp,
1487 			      "tcp_req(%p), tqpair=%p, expected data offset %u, but data offset is %u\n",
1488 			      tcp_req, tqpair, tcp_req->h2c_offset, h2c_data->datao);
1489 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1490 		goto err;
1491 	}
1492 
1493 	if ((h2c_data->datao + h2c_data->datal) > tcp_req->req.length) {
1494 		SPDK_DEBUGLOG(nvmf_tcp,
1495 			      "tcp_req(%p), tqpair=%p,  (datao=%u + datal=%u) execeeds requested length=%u\n",
1496 			      tcp_req, tqpair, h2c_data->datao, h2c_data->datal, tcp_req->req.length);
1497 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1498 		goto err;
1499 	}
1500 
1501 	pdu->req = tcp_req;
1502 
1503 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
1504 		pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
1505 	}
1506 
1507 	nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
1508 				  h2c_data->datao, h2c_data->datal);
1509 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1510 	return;
1511 
1512 err:
1513 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1514 }
1515 
1516 static void
1517 nvmf_tcp_send_capsule_resp_pdu(struct spdk_nvmf_tcp_req *tcp_req,
1518 			       struct spdk_nvmf_tcp_qpair *tqpair)
1519 {
1520 	struct nvme_tcp_pdu *rsp_pdu;
1521 	struct spdk_nvme_tcp_rsp *capsule_resp;
1522 
1523 	SPDK_DEBUGLOG(nvmf_tcp, "enter, tqpair=%p\n", tqpair);
1524 
1525 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1526 	assert(rsp_pdu != NULL);
1527 
1528 	capsule_resp = &rsp_pdu->hdr.capsule_resp;
1529 	capsule_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_CAPSULE_RESP;
1530 	capsule_resp->common.plen = capsule_resp->common.hlen = sizeof(*capsule_resp);
1531 	capsule_resp->rccqe = tcp_req->req.rsp->nvme_cpl;
1532 	if (tqpair->host_hdgst_enable) {
1533 		capsule_resp->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1534 		capsule_resp->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1535 	}
1536 
1537 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_request_free, tcp_req);
1538 }
1539 
1540 static void
1541 nvmf_tcp_pdu_c2h_data_complete(void *cb_arg)
1542 {
1543 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1544 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair,
1545 					     struct spdk_nvmf_tcp_qpair, qpair);
1546 
1547 	assert(tqpair != NULL);
1548 
1549 	if (spdk_unlikely(tcp_req->pdu->rw_offset < tcp_req->req.length)) {
1550 		SPDK_DEBUGLOG(nvmf_tcp, "sending another C2H part, offset %u length %u\n", tcp_req->pdu->rw_offset,
1551 			      tcp_req->req.length);
1552 		_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
1553 		return;
1554 	}
1555 
1556 	if (tcp_req->pdu->hdr.c2h_data.common.flags & SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS) {
1557 		nvmf_tcp_request_free(tcp_req);
1558 	} else {
1559 		nvmf_tcp_req_pdu_fini(tcp_req);
1560 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
1561 	}
1562 }
1563 
1564 static void
1565 nvmf_tcp_r2t_complete(void *cb_arg)
1566 {
1567 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1568 	struct spdk_nvmf_tcp_transport *ttransport;
1569 
1570 	nvmf_tcp_req_pdu_fini(tcp_req);
1571 
1572 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
1573 				      struct spdk_nvmf_tcp_transport, transport);
1574 
1575 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
1576 
1577 	if (tcp_req->h2c_offset == tcp_req->req.length) {
1578 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1579 		nvmf_tcp_req_process(ttransport, tcp_req);
1580 	}
1581 }
1582 
1583 static void
1584 nvmf_tcp_send_r2t_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
1585 		      struct spdk_nvmf_tcp_req *tcp_req)
1586 {
1587 	struct nvme_tcp_pdu *rsp_pdu;
1588 	struct spdk_nvme_tcp_r2t_hdr *r2t;
1589 
1590 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1591 	assert(rsp_pdu != NULL);
1592 
1593 	r2t = &rsp_pdu->hdr.r2t;
1594 	r2t->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_R2T;
1595 	r2t->common.plen = r2t->common.hlen = sizeof(*r2t);
1596 
1597 	if (tqpair->host_hdgst_enable) {
1598 		r2t->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1599 		r2t->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1600 	}
1601 
1602 	r2t->cccid = tcp_req->req.cmd->nvme_cmd.cid;
1603 	r2t->ttag = tcp_req->ttag;
1604 	r2t->r2to = tcp_req->h2c_offset;
1605 	r2t->r2tl = tcp_req->req.length;
1606 
1607 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
1608 
1609 	SPDK_DEBUGLOG(nvmf_tcp,
1610 		      "tcp_req(%p) on tqpair(%p), r2t_info: cccid=%u, ttag=%u, r2to=%u, r2tl=%u\n",
1611 		      tcp_req, tqpair, r2t->cccid, r2t->ttag, r2t->r2to, r2t->r2tl);
1612 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_r2t_complete, tcp_req);
1613 }
1614 
1615 static void
1616 nvmf_tcp_h2c_data_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1617 				 struct spdk_nvmf_tcp_qpair *tqpair,
1618 				 struct nvme_tcp_pdu *pdu)
1619 {
1620 	struct spdk_nvmf_tcp_req *tcp_req;
1621 	struct spdk_nvme_cpl *rsp;
1622 
1623 	tcp_req = pdu->req;
1624 	assert(tcp_req != NULL);
1625 
1626 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1627 
1628 	tcp_req->h2c_offset += pdu->data_len;
1629 
1630 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1631 
1632 	/* Wait for all of the data to arrive AND for the initial R2T PDU send to be
1633 	 * acknowledged before moving on. */
1634 	if (tcp_req->h2c_offset == tcp_req->req.length &&
1635 	    tcp_req->state == TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER) {
1636 		/* After receving all the h2c data, we need to check whether there is
1637 		 * transient transport error */
1638 		rsp = &tcp_req->req.rsp->nvme_cpl;
1639 		if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1640 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1641 		} else {
1642 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1643 		}
1644 		nvmf_tcp_req_process(ttransport, tcp_req);
1645 	}
1646 }
1647 
1648 static void
1649 nvmf_tcp_h2c_term_req_dump(struct spdk_nvme_tcp_term_req_hdr *h2c_term_req)
1650 {
1651 	SPDK_ERRLOG("Error info of pdu(%p): %s\n", h2c_term_req,
1652 		    spdk_nvmf_tcp_term_req_fes_str[h2c_term_req->fes]);
1653 	if ((h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1654 	    (h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1655 		SPDK_DEBUGLOG(nvmf_tcp, "The offset from the start of the PDU header is %u\n",
1656 			      DGET32(h2c_term_req->fei));
1657 	}
1658 }
1659 
1660 static void
1661 nvmf_tcp_h2c_term_req_hdr_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1662 				 struct nvme_tcp_pdu *pdu)
1663 {
1664 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1665 	uint32_t error_offset = 0;
1666 	enum spdk_nvme_tcp_term_req_fes fes;
1667 
1668 	if (h2c_term_req->fes > SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER) {
1669 		SPDK_ERRLOG("Fatal Error Status(FES) is unknown for h2c_term_req pdu=%p\n", pdu);
1670 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1671 		error_offset = offsetof(struct spdk_nvme_tcp_term_req_hdr, fes);
1672 		goto end;
1673 	}
1674 
1675 	/* set the data buffer */
1676 	nvme_tcp_pdu_set_data(pdu, (uint8_t *)pdu->hdr.raw + h2c_term_req->common.hlen,
1677 			      h2c_term_req->common.plen - h2c_term_req->common.hlen);
1678 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1679 	return;
1680 end:
1681 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1682 }
1683 
1684 static void
1685 nvmf_tcp_h2c_term_req_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1686 				     struct nvme_tcp_pdu *pdu)
1687 {
1688 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1689 
1690 	nvmf_tcp_h2c_term_req_dump(h2c_term_req);
1691 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1692 }
1693 
1694 static void
1695 _nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1696 			     struct spdk_nvmf_tcp_transport *ttransport)
1697 {
1698 	struct nvme_tcp_pdu *pdu = tqpair->pdu_in_progress;
1699 
1700 	switch (pdu->hdr.common.pdu_type) {
1701 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1702 		nvmf_tcp_capsule_cmd_payload_handle(ttransport, tqpair, pdu);
1703 		break;
1704 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1705 		nvmf_tcp_h2c_data_payload_handle(ttransport, tqpair, pdu);
1706 		break;
1707 
1708 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1709 		nvmf_tcp_h2c_term_req_payload_handle(tqpair, pdu);
1710 		break;
1711 
1712 	default:
1713 		/* The code should not go to here */
1714 		SPDK_ERRLOG("The code should not go to here\n");
1715 		break;
1716 	}
1717 }
1718 
1719 static void
1720 nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1721 			    struct spdk_nvmf_tcp_transport *ttransport)
1722 {
1723 	int rc = 0;
1724 	struct nvme_tcp_pdu *pdu;
1725 	uint32_t crc32c;
1726 	struct spdk_nvmf_tcp_req *tcp_req;
1727 	struct spdk_nvme_cpl *rsp;
1728 
1729 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1730 	pdu = tqpair->pdu_in_progress;
1731 
1732 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1733 	/* check data digest if need */
1734 	if (pdu->ddgst_enable) {
1735 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
1736 		rc = MATCH_DIGEST_WORD(pdu->data_digest, crc32c);
1737 		if (rc == 0) {
1738 			SPDK_ERRLOG("Data digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1739 			tcp_req = pdu->req;
1740 			assert(tcp_req != NULL);
1741 			rsp = &tcp_req->req.rsp->nvme_cpl;
1742 			rsp->status.sc = SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR;
1743 		}
1744 	}
1745 
1746 	_nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
1747 }
1748 
1749 static void
1750 nvmf_tcp_send_icresp_complete(void *cb_arg)
1751 {
1752 	struct spdk_nvmf_tcp_qpair *tqpair = cb_arg;
1753 
1754 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_RUNNING);
1755 }
1756 
1757 static void
1758 nvmf_tcp_icreq_handle(struct spdk_nvmf_tcp_transport *ttransport,
1759 		      struct spdk_nvmf_tcp_qpair *tqpair,
1760 		      struct nvme_tcp_pdu *pdu)
1761 {
1762 	struct spdk_nvme_tcp_ic_req *ic_req = &pdu->hdr.ic_req;
1763 	struct nvme_tcp_pdu *rsp_pdu;
1764 	struct spdk_nvme_tcp_ic_resp *ic_resp;
1765 	uint32_t error_offset = 0;
1766 	enum spdk_nvme_tcp_term_req_fes fes;
1767 
1768 	/* Only PFV 0 is defined currently */
1769 	if (ic_req->pfv != 0) {
1770 		SPDK_ERRLOG("Expected ICReq PFV %u, got %u\n", 0u, ic_req->pfv);
1771 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1772 		error_offset = offsetof(struct spdk_nvme_tcp_ic_req, pfv);
1773 		goto end;
1774 	}
1775 
1776 	/* MAXR2T is 0's based */
1777 	SPDK_DEBUGLOG(nvmf_tcp, "maxr2t =%u\n", (ic_req->maxr2t + 1u));
1778 
1779 	tqpair->host_hdgst_enable = ic_req->dgst.bits.hdgst_enable ? true : false;
1780 	if (!tqpair->host_hdgst_enable) {
1781 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1782 	}
1783 
1784 	tqpair->host_ddgst_enable = ic_req->dgst.bits.ddgst_enable ? true : false;
1785 	if (!tqpair->host_ddgst_enable) {
1786 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1787 	}
1788 
1789 	tqpair->recv_buf_size = spdk_max(tqpair->recv_buf_size, MIN_SOCK_PIPE_SIZE);
1790 	/* Now that we know whether digests are enabled, properly size the receive buffer */
1791 	if (spdk_sock_set_recvbuf(tqpair->sock, tqpair->recv_buf_size) < 0) {
1792 		SPDK_WARNLOG("Unable to allocate enough memory for receive buffer on tqpair=%p with size=%d\n",
1793 			     tqpair,
1794 			     tqpair->recv_buf_size);
1795 		/* Not fatal. */
1796 	}
1797 
1798 	tqpair->cpda = spdk_min(ic_req->hpda, SPDK_NVME_TCP_CPDA_MAX);
1799 	SPDK_DEBUGLOG(nvmf_tcp, "cpda of tqpair=(%p) is : %u\n", tqpair, tqpair->cpda);
1800 
1801 	rsp_pdu = tqpair->mgmt_pdu;
1802 
1803 	ic_resp = &rsp_pdu->hdr.ic_resp;
1804 	ic_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_IC_RESP;
1805 	ic_resp->common.hlen = ic_resp->common.plen =  sizeof(*ic_resp);
1806 	ic_resp->pfv = 0;
1807 	ic_resp->cpda = tqpair->cpda;
1808 	ic_resp->maxh2cdata = ttransport->transport.opts.max_io_size;
1809 	ic_resp->dgst.bits.hdgst_enable = tqpair->host_hdgst_enable ? 1 : 0;
1810 	ic_resp->dgst.bits.ddgst_enable = tqpair->host_ddgst_enable ? 1 : 0;
1811 
1812 	SPDK_DEBUGLOG(nvmf_tcp, "host_hdgst_enable: %u\n", tqpair->host_hdgst_enable);
1813 	SPDK_DEBUGLOG(nvmf_tcp, "host_ddgst_enable: %u\n", tqpair->host_ddgst_enable);
1814 
1815 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INITIALIZING);
1816 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_icresp_complete, tqpair);
1817 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1818 	return;
1819 end:
1820 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1821 }
1822 
1823 static void
1824 nvmf_tcp_pdu_psh_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1825 			struct spdk_nvmf_tcp_transport *ttransport)
1826 {
1827 	struct nvme_tcp_pdu *pdu;
1828 	int rc;
1829 	uint32_t crc32c, error_offset = 0;
1830 	enum spdk_nvme_tcp_term_req_fes fes;
1831 
1832 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1833 	pdu = tqpair->pdu_in_progress;
1834 
1835 	SPDK_DEBUGLOG(nvmf_tcp, "pdu type of tqpair(%p) is %d\n", tqpair,
1836 		      pdu->hdr.common.pdu_type);
1837 	/* check header digest if needed */
1838 	if (pdu->has_hdgst) {
1839 		SPDK_DEBUGLOG(nvmf_tcp, "Compare the header of pdu=%p on tqpair=%p\n", pdu, tqpair);
1840 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
1841 		rc = MATCH_DIGEST_WORD((uint8_t *)pdu->hdr.raw + pdu->hdr.common.hlen, crc32c);
1842 		if (rc == 0) {
1843 			SPDK_ERRLOG("Header digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1844 			fes = SPDK_NVME_TCP_TERM_REQ_FES_HDGST_ERROR;
1845 			nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1846 			return;
1847 
1848 		}
1849 	}
1850 
1851 	switch (pdu->hdr.common.pdu_type) {
1852 	case SPDK_NVME_TCP_PDU_TYPE_IC_REQ:
1853 		nvmf_tcp_icreq_handle(ttransport, tqpair, pdu);
1854 		break;
1855 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1856 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_REQ);
1857 		break;
1858 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1859 		nvmf_tcp_h2c_data_hdr_handle(ttransport, tqpair, pdu);
1860 		break;
1861 
1862 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1863 		nvmf_tcp_h2c_term_req_hdr_handle(tqpair, pdu);
1864 		break;
1865 
1866 	default:
1867 		SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", tqpair->pdu_in_progress->hdr.common.pdu_type);
1868 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1869 		error_offset = 1;
1870 		nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1871 		break;
1872 	}
1873 }
1874 
1875 static void
1876 nvmf_tcp_pdu_ch_handle(struct spdk_nvmf_tcp_qpair *tqpair)
1877 {
1878 	struct nvme_tcp_pdu *pdu;
1879 	uint32_t error_offset = 0;
1880 	enum spdk_nvme_tcp_term_req_fes fes;
1881 	uint8_t expected_hlen, pdo;
1882 	bool plen_error = false, pdo_error = false;
1883 
1884 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
1885 	pdu = tqpair->pdu_in_progress;
1886 
1887 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_REQ) {
1888 		if (tqpair->state != NVME_TCP_QPAIR_STATE_INVALID) {
1889 			SPDK_ERRLOG("Already received ICreq PDU, and reject this pdu=%p\n", pdu);
1890 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1891 			goto err;
1892 		}
1893 		expected_hlen = sizeof(struct spdk_nvme_tcp_ic_req);
1894 		if (pdu->hdr.common.plen != expected_hlen) {
1895 			plen_error = true;
1896 		}
1897 	} else {
1898 		if (tqpair->state != NVME_TCP_QPAIR_STATE_RUNNING) {
1899 			SPDK_ERRLOG("The TCP/IP connection is not negotitated\n");
1900 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1901 			goto err;
1902 		}
1903 
1904 		switch (pdu->hdr.common.pdu_type) {
1905 		case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1906 			expected_hlen = sizeof(struct spdk_nvme_tcp_cmd);
1907 			pdo = pdu->hdr.common.pdo;
1908 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1909 				pdo_error = true;
1910 				break;
1911 			}
1912 
1913 			if (pdu->hdr.common.plen < expected_hlen) {
1914 				plen_error = true;
1915 			}
1916 			break;
1917 		case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1918 			expected_hlen = sizeof(struct spdk_nvme_tcp_h2c_data_hdr);
1919 			pdo = pdu->hdr.common.pdo;
1920 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1921 				pdo_error = true;
1922 				break;
1923 			}
1924 			if (pdu->hdr.common.plen < expected_hlen) {
1925 				plen_error = true;
1926 			}
1927 			break;
1928 
1929 		case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1930 			expected_hlen = sizeof(struct spdk_nvme_tcp_term_req_hdr);
1931 			if ((pdu->hdr.common.plen <= expected_hlen) ||
1932 			    (pdu->hdr.common.plen > SPDK_NVME_TCP_TERM_REQ_PDU_MAX_SIZE)) {
1933 				plen_error = true;
1934 			}
1935 			break;
1936 
1937 		default:
1938 			SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", pdu->hdr.common.pdu_type);
1939 			fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1940 			error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdu_type);
1941 			goto err;
1942 		}
1943 	}
1944 
1945 	if (pdu->hdr.common.hlen != expected_hlen) {
1946 		SPDK_ERRLOG("PDU type=0x%02x, Expected ICReq header length %u, got %u on tqpair=%p\n",
1947 			    pdu->hdr.common.pdu_type,
1948 			    expected_hlen, pdu->hdr.common.hlen, tqpair);
1949 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1950 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, hlen);
1951 		goto err;
1952 	} else if (pdo_error) {
1953 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1954 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1955 	} else if (plen_error) {
1956 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1957 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, plen);
1958 		goto err;
1959 	} else {
1960 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1961 		nvme_tcp_pdu_calc_psh_len(tqpair->pdu_in_progress, tqpair->host_hdgst_enable);
1962 		return;
1963 	}
1964 err:
1965 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1966 }
1967 
1968 static int
1969 nvmf_tcp_pdu_payload_insert_dif(struct nvme_tcp_pdu *pdu, uint32_t read_offset,
1970 				int read_len)
1971 {
1972 	int rc;
1973 
1974 	rc = spdk_dif_generate_stream(pdu->data_iov, pdu->data_iovcnt,
1975 				      read_offset, read_len, pdu->dif_ctx);
1976 	if (rc != 0) {
1977 		SPDK_ERRLOG("DIF generate failed\n");
1978 	}
1979 
1980 	return rc;
1981 }
1982 
1983 static int
1984 nvmf_tcp_sock_process(struct spdk_nvmf_tcp_qpair *tqpair)
1985 {
1986 	int rc = 0;
1987 	struct nvme_tcp_pdu *pdu;
1988 	enum nvme_tcp_pdu_recv_state prev_state;
1989 	uint32_t data_len;
1990 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(tqpair->qpair.transport,
1991 			struct spdk_nvmf_tcp_transport, transport);
1992 
1993 	/* The loop here is to allow for several back-to-back state changes. */
1994 	do {
1995 		prev_state = tqpair->recv_state;
1996 		SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv pdu entering state %d\n", tqpair, prev_state);
1997 
1998 		pdu = tqpair->pdu_in_progress;
1999 		switch (tqpair->recv_state) {
2000 		/* Wait for the common header  */
2001 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
2002 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
2003 			if (spdk_unlikely(tqpair->state == NVME_TCP_QPAIR_STATE_INITIALIZING)) {
2004 				return rc;
2005 			}
2006 
2007 			rc = nvme_tcp_read_data(tqpair->sock,
2008 						sizeof(struct spdk_nvme_tcp_common_pdu_hdr) - pdu->ch_valid_bytes,
2009 						(void *)&pdu->hdr.common + pdu->ch_valid_bytes);
2010 			if (rc < 0) {
2011 				SPDK_DEBUGLOG(nvmf_tcp, "will disconnect tqpair=%p\n", tqpair);
2012 				return NVME_TCP_PDU_FATAL;
2013 			} else if (rc > 0) {
2014 				pdu->ch_valid_bytes += rc;
2015 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2016 				if (spdk_likely(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY)) {
2017 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
2018 				}
2019 			}
2020 
2021 			if (pdu->ch_valid_bytes < sizeof(struct spdk_nvme_tcp_common_pdu_hdr)) {
2022 				return NVME_TCP_PDU_IN_PROGRESS;
2023 			}
2024 
2025 			/* The command header of this PDU has now been read from the socket. */
2026 			nvmf_tcp_pdu_ch_handle(tqpair);
2027 			break;
2028 		/* Wait for the pdu specific header  */
2029 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
2030 			rc = nvme_tcp_read_data(tqpair->sock,
2031 						pdu->psh_len - pdu->psh_valid_bytes,
2032 						(void *)&pdu->hdr.raw + sizeof(struct spdk_nvme_tcp_common_pdu_hdr) + pdu->psh_valid_bytes);
2033 			if (rc < 0) {
2034 				return NVME_TCP_PDU_FATAL;
2035 			} else if (rc > 0) {
2036 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2037 				pdu->psh_valid_bytes += rc;
2038 			}
2039 
2040 			if (pdu->psh_valid_bytes < pdu->psh_len) {
2041 				return NVME_TCP_PDU_IN_PROGRESS;
2042 			}
2043 
2044 			/* All header(ch, psh, head digist) of this PDU has now been read from the socket. */
2045 			nvmf_tcp_pdu_psh_handle(tqpair, ttransport);
2046 			break;
2047 		/* Wait for the req slot */
2048 		case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
2049 			nvmf_tcp_capsule_cmd_hdr_handle(ttransport, tqpair, pdu);
2050 			break;
2051 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
2052 			/* check whether the data is valid, if not we just return */
2053 			if (!pdu->data_len) {
2054 				return NVME_TCP_PDU_IN_PROGRESS;
2055 			}
2056 
2057 			data_len = pdu->data_len;
2058 			/* data digest */
2059 			if (spdk_unlikely((pdu->hdr.common.pdu_type != SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ) &&
2060 					  tqpair->host_ddgst_enable)) {
2061 				data_len += SPDK_NVME_TCP_DIGEST_LEN;
2062 				pdu->ddgst_enable = true;
2063 			}
2064 
2065 			rc = nvme_tcp_read_payload_data(tqpair->sock, pdu);
2066 			if (rc < 0) {
2067 				return NVME_TCP_PDU_FATAL;
2068 			}
2069 			pdu->rw_offset += rc;
2070 
2071 			if (spdk_unlikely(pdu->dif_ctx != NULL)) {
2072 				rc = nvmf_tcp_pdu_payload_insert_dif(pdu, pdu->rw_offset - rc, rc);
2073 				if (rc != 0) {
2074 					return NVME_TCP_PDU_FATAL;
2075 				}
2076 			}
2077 
2078 			if (pdu->rw_offset < data_len) {
2079 				return NVME_TCP_PDU_IN_PROGRESS;
2080 			}
2081 
2082 			/* All of this PDU has now been read from the socket. */
2083 			nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
2084 			break;
2085 		case NVME_TCP_PDU_RECV_STATE_ERROR:
2086 			if (!spdk_sock_is_connected(tqpair->sock)) {
2087 				return NVME_TCP_PDU_FATAL;
2088 			}
2089 			break;
2090 		default:
2091 			assert(0);
2092 			SPDK_ERRLOG("code should not come to here");
2093 			break;
2094 		}
2095 	} while (tqpair->recv_state != prev_state);
2096 
2097 	return rc;
2098 }
2099 
2100 static inline void *
2101 nvmf_tcp_control_msg_get(struct spdk_nvmf_tcp_control_msg_list *list)
2102 {
2103 	struct spdk_nvmf_tcp_control_msg *msg;
2104 
2105 	assert(list);
2106 
2107 	msg = STAILQ_FIRST(&list->free_msgs);
2108 	if (!msg) {
2109 		SPDK_DEBUGLOG(nvmf_tcp, "Out of control messages\n");
2110 		return NULL;
2111 	}
2112 	STAILQ_REMOVE_HEAD(&list->free_msgs, link);
2113 	return msg;
2114 }
2115 
2116 static inline void
2117 nvmf_tcp_control_msg_put(struct spdk_nvmf_tcp_control_msg_list *list, void *_msg)
2118 {
2119 	struct spdk_nvmf_tcp_control_msg *msg = _msg;
2120 
2121 	assert(list);
2122 	STAILQ_INSERT_HEAD(&list->free_msgs, msg, link);
2123 }
2124 
2125 static int
2126 nvmf_tcp_req_parse_sgl(struct spdk_nvmf_tcp_req *tcp_req,
2127 		       struct spdk_nvmf_transport *transport,
2128 		       struct spdk_nvmf_transport_poll_group *group)
2129 {
2130 	struct spdk_nvmf_request		*req = &tcp_req->req;
2131 	struct spdk_nvme_cmd			*cmd;
2132 	struct spdk_nvme_cpl			*rsp;
2133 	struct spdk_nvme_sgl_descriptor		*sgl;
2134 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2135 	uint32_t				length;
2136 
2137 	cmd = &req->cmd->nvme_cmd;
2138 	rsp = &req->rsp->nvme_cpl;
2139 	sgl = &cmd->dptr.sgl1;
2140 
2141 	length = sgl->unkeyed.length;
2142 
2143 	if (sgl->generic.type == SPDK_NVME_SGL_TYPE_TRANSPORT_DATA_BLOCK &&
2144 	    sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_TRANSPORT) {
2145 		if (length > transport->opts.max_io_size) {
2146 			SPDK_ERRLOG("SGL length 0x%x exceeds max io size 0x%x\n",
2147 				    length, transport->opts.max_io_size);
2148 			rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2149 			return -1;
2150 		}
2151 
2152 		/* fill request length and populate iovs */
2153 		req->length = length;
2154 
2155 		SPDK_DEBUGLOG(nvmf_tcp, "Data requested length= 0x%x\n", length);
2156 
2157 		if (spdk_unlikely(req->dif_enabled)) {
2158 			req->dif.orig_length = length;
2159 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2160 			req->dif.elba_length = length;
2161 		}
2162 
2163 		if (spdk_nvmf_request_get_buffers(req, group, transport, length)) {
2164 			/* No available buffers. Queue this request up. */
2165 			SPDK_DEBUGLOG(nvmf_tcp, "No available large data buffers. Queueing request %p\n",
2166 				      tcp_req);
2167 			return 0;
2168 		}
2169 
2170 		/* backward compatible */
2171 		req->data = req->iov[0].iov_base;
2172 
2173 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p took %d buffer/s from central pool, and data=%p\n",
2174 			      tcp_req, req->iovcnt, req->data);
2175 
2176 		return 0;
2177 	} else if (sgl->generic.type == SPDK_NVME_SGL_TYPE_DATA_BLOCK &&
2178 		   sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_OFFSET) {
2179 		uint64_t offset = sgl->address;
2180 		uint32_t max_len = transport->opts.in_capsule_data_size;
2181 		assert(tcp_req->has_incapsule_data);
2182 
2183 		SPDK_DEBUGLOG(nvmf_tcp, "In-capsule data: offset 0x%" PRIx64 ", length 0x%x\n",
2184 			      offset, length);
2185 
2186 		if (offset > max_len) {
2187 			SPDK_ERRLOG("In-capsule offset 0x%" PRIx64 " exceeds capsule length 0x%x\n",
2188 				    offset, max_len);
2189 			rsp->status.sc = SPDK_NVME_SC_INVALID_SGL_OFFSET;
2190 			return -1;
2191 		}
2192 		max_len -= (uint32_t)offset;
2193 
2194 		if (spdk_unlikely(length > max_len)) {
2195 			/* According to the SPEC we should support ICD up to 8192 bytes for admin and fabric commands */
2196 			if (length <= SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE &&
2197 			    (cmd->opc == SPDK_NVME_OPC_FABRIC || req->qpair->qid == 0)) {
2198 
2199 				/* Get a buffer from dedicated list */
2200 				SPDK_DEBUGLOG(nvmf_tcp, "Getting a buffer from control msg list\n");
2201 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2202 				assert(tgroup->control_msg_list);
2203 				req->data = nvmf_tcp_control_msg_get(tgroup->control_msg_list);
2204 				if (!req->data) {
2205 					/* No available buffers. Queue this request up. */
2206 					SPDK_DEBUGLOG(nvmf_tcp, "No available ICD buffers. Queueing request %p\n", tcp_req);
2207 					return 0;
2208 				}
2209 			} else {
2210 				SPDK_ERRLOG("In-capsule data length 0x%x exceeds capsule length 0x%x\n",
2211 					    length, max_len);
2212 				rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2213 				return -1;
2214 			}
2215 		} else {
2216 			req->data = tcp_req->buf;
2217 		}
2218 
2219 		req->length = length;
2220 		req->data_from_pool = false;
2221 
2222 		if (spdk_unlikely(req->dif_enabled)) {
2223 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2224 			req->dif.elba_length = length;
2225 		}
2226 
2227 		req->iov[0].iov_base = req->data;
2228 		req->iov[0].iov_len = length;
2229 		req->iovcnt = 1;
2230 
2231 		return 0;
2232 	}
2233 
2234 	SPDK_ERRLOG("Invalid NVMf I/O Command SGL:  Type 0x%x, Subtype 0x%x\n",
2235 		    sgl->generic.type, sgl->generic.subtype);
2236 	rsp->status.sc = SPDK_NVME_SC_SGL_DESCRIPTOR_TYPE_INVALID;
2237 	return -1;
2238 }
2239 
2240 static inline enum spdk_nvme_media_error_status_code
2241 nvmf_tcp_dif_error_to_compl_status(uint8_t err_type) {
2242 	enum spdk_nvme_media_error_status_code result;
2243 
2244 	switch (err_type)
2245 	{
2246 	case SPDK_DIF_REFTAG_ERROR:
2247 		result = SPDK_NVME_SC_REFERENCE_TAG_CHECK_ERROR;
2248 		break;
2249 	case SPDK_DIF_APPTAG_ERROR:
2250 		result = SPDK_NVME_SC_APPLICATION_TAG_CHECK_ERROR;
2251 		break;
2252 	case SPDK_DIF_GUARD_ERROR:
2253 		result = SPDK_NVME_SC_GUARD_CHECK_ERROR;
2254 		break;
2255 	default:
2256 		SPDK_UNREACHABLE();
2257 		break;
2258 	}
2259 
2260 	return result;
2261 }
2262 
2263 static void
2264 _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2265 			struct spdk_nvmf_tcp_req *tcp_req)
2266 {
2267 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(
2268 				tqpair->qpair.transport, struct spdk_nvmf_tcp_transport, transport);
2269 	struct nvme_tcp_pdu *rsp_pdu;
2270 	struct spdk_nvme_tcp_c2h_data_hdr *c2h_data;
2271 	uint32_t plen, pdo, alignment;
2272 	int rc;
2273 
2274 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2275 
2276 	rsp_pdu = tcp_req->pdu;
2277 	assert(rsp_pdu != NULL);
2278 	assert(tcp_req->pdu_in_use);
2279 
2280 	c2h_data = &rsp_pdu->hdr.c2h_data;
2281 	c2h_data->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_DATA;
2282 	plen = c2h_data->common.hlen = sizeof(*c2h_data);
2283 
2284 	if (tqpair->host_hdgst_enable) {
2285 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2286 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
2287 	}
2288 
2289 	/* set the psh */
2290 	c2h_data->cccid = tcp_req->req.cmd->nvme_cmd.cid;
2291 	c2h_data->datal = tcp_req->req.length - tcp_req->pdu->rw_offset;
2292 	c2h_data->datao = tcp_req->pdu->rw_offset;
2293 
2294 	/* set the padding */
2295 	rsp_pdu->padding_len = 0;
2296 	pdo = plen;
2297 	if (tqpair->cpda) {
2298 		alignment = (tqpair->cpda + 1) << 2;
2299 		if (plen % alignment != 0) {
2300 			pdo = (plen + alignment) / alignment * alignment;
2301 			rsp_pdu->padding_len = pdo - plen;
2302 			plen = pdo;
2303 		}
2304 	}
2305 
2306 	c2h_data->common.pdo = pdo;
2307 	plen += c2h_data->datal;
2308 	if (tqpair->host_ddgst_enable) {
2309 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_DDGSTF;
2310 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2311 	}
2312 
2313 	c2h_data->common.plen = plen;
2314 
2315 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2316 		rsp_pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
2317 	}
2318 
2319 	nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2320 				  c2h_data->datao, c2h_data->datal);
2321 
2322 
2323 	c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU;
2324 	/* Need to send the capsule response if response is not all 0 */
2325 	if (ttransport->tcp_opts.c2h_success &&
2326 	    tcp_req->rsp.cdw0 == 0 && tcp_req->rsp.cdw1 == 0) {
2327 		c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS;
2328 	}
2329 
2330 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2331 		struct spdk_nvme_cpl *rsp = &tcp_req->req.rsp->nvme_cpl;
2332 		struct spdk_dif_error err_blk = {};
2333 		uint32_t mapped_length = 0;
2334 		uint32_t available_iovs = SPDK_COUNTOF(rsp_pdu->iov);
2335 		uint32_t ddgst_len = 0;
2336 
2337 		if (tqpair->host_ddgst_enable) {
2338 			/* Data digest consumes additional iov entry */
2339 			available_iovs--;
2340 			/* plen needs to be updated since nvme_tcp_build_iovs compares expected and actual plen */
2341 			ddgst_len = SPDK_NVME_TCP_DIGEST_LEN;
2342 			c2h_data->common.plen -= ddgst_len;
2343 		}
2344 		/* Temp call to estimate if data can be described by limited number of iovs.
2345 		 * iov vector will be rebuilt in nvmf_tcp_qpair_write_pdu */
2346 		nvme_tcp_build_iovs(rsp_pdu->iov, available_iovs, rsp_pdu, tqpair->host_hdgst_enable,
2347 				    false, &mapped_length);
2348 
2349 		if (mapped_length != c2h_data->common.plen) {
2350 			c2h_data->datal = mapped_length - (c2h_data->common.plen - c2h_data->datal);
2351 			SPDK_DEBUGLOG(nvmf_tcp,
2352 				      "Part C2H, data_len %u (of %u), PDU len %u, updated PDU len %u, offset %u\n",
2353 				      c2h_data->datal, tcp_req->req.length, c2h_data->common.plen, mapped_length, rsp_pdu->rw_offset);
2354 			c2h_data->common.plen = mapped_length;
2355 
2356 			/* Rebuild pdu->data_iov since data length is changed */
2357 			nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt, c2h_data->datao,
2358 						  c2h_data->datal);
2359 
2360 			c2h_data->common.flags &= ~(SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU |
2361 						    SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS);
2362 		}
2363 
2364 		c2h_data->common.plen += ddgst_len;
2365 
2366 		assert(rsp_pdu->rw_offset <= tcp_req->req.length);
2367 
2368 		rc = spdk_dif_verify_stream(rsp_pdu->data_iov, rsp_pdu->data_iovcnt,
2369 					    0, rsp_pdu->data_len, rsp_pdu->dif_ctx, &err_blk);
2370 		if (rc != 0) {
2371 			SPDK_ERRLOG("DIF error detected. type=%d, offset=%" PRIu32 "\n",
2372 				    err_blk.err_type, err_blk.err_offset);
2373 			rsp->status.sct = SPDK_NVME_SCT_MEDIA_ERROR;
2374 			rsp->status.sc = nvmf_tcp_dif_error_to_compl_status(err_blk.err_type);
2375 			nvmf_tcp_req_pdu_fini(tcp_req);
2376 			nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2377 			return;
2378 		}
2379 	}
2380 
2381 	rsp_pdu->rw_offset += c2h_data->datal;
2382 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_pdu_c2h_data_complete, tcp_req);
2383 }
2384 
2385 static void
2386 nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2387 		       struct spdk_nvmf_tcp_req *tcp_req)
2388 {
2389 	nvmf_tcp_req_pdu_init(tcp_req);
2390 	_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2391 }
2392 
2393 static int
2394 request_transfer_out(struct spdk_nvmf_request *req)
2395 {
2396 	struct spdk_nvmf_tcp_req	*tcp_req;
2397 	struct spdk_nvmf_qpair		*qpair;
2398 	struct spdk_nvmf_tcp_qpair	*tqpair;
2399 	struct spdk_nvme_cpl		*rsp;
2400 
2401 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2402 
2403 	qpair = req->qpair;
2404 	rsp = &req->rsp->nvme_cpl;
2405 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2406 
2407 	/* Advance our sq_head pointer */
2408 	if (qpair->sq_head == qpair->sq_head_max) {
2409 		qpair->sq_head = 0;
2410 	} else {
2411 		qpair->sq_head++;
2412 	}
2413 	rsp->sqhd = qpair->sq_head;
2414 
2415 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2416 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
2417 	if (rsp->status.sc == SPDK_NVME_SC_SUCCESS && req->xfer == SPDK_NVME_DATA_CONTROLLER_TO_HOST) {
2418 		nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2419 	} else {
2420 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2421 	}
2422 
2423 	return 0;
2424 }
2425 
2426 static void
2427 nvmf_tcp_set_incapsule_data(struct spdk_nvmf_tcp_qpair *tqpair,
2428 			    struct spdk_nvmf_tcp_req *tcp_req)
2429 {
2430 	struct nvme_tcp_pdu *pdu;
2431 	uint32_t plen = 0;
2432 
2433 	pdu = tqpair->pdu_in_progress;
2434 	plen = pdu->hdr.common.hlen;
2435 
2436 	if (tqpair->host_hdgst_enable) {
2437 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2438 	}
2439 
2440 	if (pdu->hdr.common.plen != plen) {
2441 		tcp_req->has_incapsule_data = true;
2442 	}
2443 }
2444 
2445 static bool
2446 nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
2447 		     struct spdk_nvmf_tcp_req *tcp_req)
2448 {
2449 	struct spdk_nvmf_tcp_qpair		*tqpair;
2450 	int					rc;
2451 	enum spdk_nvmf_tcp_req_state		prev_state;
2452 	bool					progress = false;
2453 	struct spdk_nvmf_transport		*transport = &ttransport->transport;
2454 	struct spdk_nvmf_transport_poll_group	*group;
2455 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2456 
2457 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2458 	group = &tqpair->group->group;
2459 	assert(tcp_req->state != TCP_REQUEST_STATE_FREE);
2460 
2461 	/* If the qpair is not active, we need to abort the outstanding requests. */
2462 	if (tqpair->qpair.state != SPDK_NVMF_QPAIR_ACTIVE) {
2463 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
2464 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2465 		}
2466 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
2467 	}
2468 
2469 	/* The loop here is to allow for several back-to-back state changes. */
2470 	do {
2471 		prev_state = tcp_req->state;
2472 
2473 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p entering state %d on tqpair=%p\n", tcp_req, prev_state,
2474 			      tqpair);
2475 
2476 		switch (tcp_req->state) {
2477 		case TCP_REQUEST_STATE_FREE:
2478 			/* Some external code must kick a request into TCP_REQUEST_STATE_NEW
2479 			 * to escape this state. */
2480 			break;
2481 		case TCP_REQUEST_STATE_NEW:
2482 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEW, 0, 0, (uintptr_t)tcp_req, tqpair);
2483 
2484 			/* copy the cmd from the receive pdu */
2485 			tcp_req->cmd = tqpair->pdu_in_progress->hdr.capsule_cmd.ccsqe;
2486 
2487 			if (spdk_unlikely(spdk_nvmf_request_get_dif_ctx(&tcp_req->req, &tcp_req->req.dif.dif_ctx))) {
2488 				tcp_req->req.dif_enabled = true;
2489 				tqpair->pdu_in_progress->dif_ctx = &tcp_req->req.dif.dif_ctx;
2490 			}
2491 
2492 			/* The next state transition depends on the data transfer needs of this request. */
2493 			tcp_req->req.xfer = spdk_nvmf_req_get_xfer(&tcp_req->req);
2494 
2495 			if (spdk_unlikely(tcp_req->req.xfer == SPDK_NVME_DATA_BIDIRECTIONAL)) {
2496 				tcp_req->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2497 				tcp_req->req.rsp->nvme_cpl.status.sc  = SPDK_NVME_SC_INVALID_OPCODE;
2498 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2499 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2500 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2501 				SPDK_DEBUGLOG(nvmf_tcp, "Request %p: invalid xfer type (BIDIRECTIONAL)\n", tcp_req);
2502 				break;
2503 			}
2504 
2505 			/* If no data to transfer, ready to execute. */
2506 			if (tcp_req->req.xfer == SPDK_NVME_DATA_NONE) {
2507 				/* Reset the tqpair receving pdu state */
2508 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2509 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2510 				break;
2511 			}
2512 
2513 			nvmf_tcp_set_incapsule_data(tqpair, tcp_req);
2514 
2515 			if (!tcp_req->has_incapsule_data) {
2516 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2517 			}
2518 
2519 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEED_BUFFER);
2520 			STAILQ_INSERT_TAIL(&group->pending_buf_queue, &tcp_req->req, buf_link);
2521 			break;
2522 		case TCP_REQUEST_STATE_NEED_BUFFER:
2523 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEED_BUFFER, 0, 0, (uintptr_t)tcp_req, tqpair);
2524 
2525 			assert(tcp_req->req.xfer != SPDK_NVME_DATA_NONE);
2526 
2527 			if (!tcp_req->has_incapsule_data && (&tcp_req->req != STAILQ_FIRST(&group->pending_buf_queue))) {
2528 				SPDK_DEBUGLOG(nvmf_tcp,
2529 					      "Not the first element to wait for the buf for tcp_req(%p) on tqpair=%p\n",
2530 					      tcp_req, tqpair);
2531 				/* This request needs to wait in line to obtain a buffer */
2532 				break;
2533 			}
2534 
2535 			/* Try to get a data buffer */
2536 			rc = nvmf_tcp_req_parse_sgl(tcp_req, transport, group);
2537 			if (rc < 0) {
2538 				STAILQ_REMOVE_HEAD(&group->pending_buf_queue, buf_link);
2539 				/* Reset the tqpair receving pdu state */
2540 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
2541 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2542 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2543 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2544 				break;
2545 			}
2546 
2547 			if (!tcp_req->req.data) {
2548 				SPDK_DEBUGLOG(nvmf_tcp, "No buffer allocated for tcp_req(%p) on tqpair(%p\n)",
2549 					      tcp_req, tqpair);
2550 				/* No buffers available. */
2551 				break;
2552 			}
2553 
2554 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2555 
2556 			/* If data is transferring from host to controller, we need to do a transfer from the host. */
2557 			if (tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER) {
2558 				if (tcp_req->req.data_from_pool) {
2559 					SPDK_DEBUGLOG(nvmf_tcp, "Sending R2T for tcp_req(%p) on tqpair=%p\n", tcp_req, tqpair);
2560 					nvmf_tcp_send_r2t_pdu(tqpair, tcp_req);
2561 				} else {
2562 					struct nvme_tcp_pdu *pdu;
2563 
2564 					nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
2565 
2566 					pdu = tqpair->pdu_in_progress;
2567 					SPDK_DEBUGLOG(nvmf_tcp, "Not need to send r2t for tcp_req(%p) on tqpair=%p\n", tcp_req,
2568 						      tqpair);
2569 					/* No need to send r2t, contained in the capsuled data */
2570 					nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2571 								  0, tcp_req->req.length);
2572 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
2573 				}
2574 				break;
2575 			}
2576 
2577 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2578 			break;
2579 		case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2580 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK, 0, 0, (uintptr_t)tcp_req,
2581 					  tqpair);
2582 			/* The R2T completion or the h2c data incoming will kick it out of this state. */
2583 			break;
2584 		case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2585 
2586 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER, 0, 0,
2587 					  (uintptr_t)tcp_req, tqpair);
2588 			/* Some external code must kick a request into TCP_REQUEST_STATE_READY_TO_EXECUTE
2589 			 * to escape this state. */
2590 			break;
2591 		case TCP_REQUEST_STATE_READY_TO_EXECUTE:
2592 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE, 0, 0, (uintptr_t)tcp_req,
2593 					  tqpair);
2594 
2595 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2596 				assert(tcp_req->req.dif.elba_length >= tcp_req->req.length);
2597 				tcp_req->req.length = tcp_req->req.dif.elba_length;
2598 			}
2599 
2600 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTING);
2601 			spdk_nvmf_request_exec(&tcp_req->req);
2602 			break;
2603 		case TCP_REQUEST_STATE_EXECUTING:
2604 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTING, 0, 0, (uintptr_t)tcp_req, tqpair);
2605 			/* Some external code must kick a request into TCP_REQUEST_STATE_EXECUTED
2606 			 * to escape this state. */
2607 			break;
2608 		case TCP_REQUEST_STATE_EXECUTED:
2609 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTED, 0, 0, (uintptr_t)tcp_req, tqpair);
2610 
2611 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2612 				tcp_req->req.length = tcp_req->req.dif.orig_length;
2613 			}
2614 
2615 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2616 			break;
2617 		case TCP_REQUEST_STATE_READY_TO_COMPLETE:
2618 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE, 0, 0, (uintptr_t)tcp_req,
2619 					  tqpair);
2620 			rc = request_transfer_out(&tcp_req->req);
2621 			assert(rc == 0); /* No good way to handle this currently */
2622 			break;
2623 		case TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST:
2624 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST, 0, 0,
2625 					  (uintptr_t)tcp_req, tqpair);
2626 			/* Some external code must kick a request into TCP_REQUEST_STATE_COMPLETED
2627 			 * to escape this state. */
2628 			break;
2629 		case TCP_REQUEST_STATE_COMPLETED:
2630 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_COMPLETED, 0, 0, (uintptr_t)tcp_req, tqpair);
2631 			if (tcp_req->req.data_from_pool) {
2632 				spdk_nvmf_request_free_buffers(&tcp_req->req, group, transport);
2633 			} else if (spdk_unlikely(tcp_req->has_incapsule_data && (tcp_req->cmd.opc == SPDK_NVME_OPC_FABRIC ||
2634 						 tqpair->qpair.qid == 0) && tcp_req->req.length > transport->opts.in_capsule_data_size)) {
2635 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2636 				assert(tgroup->control_msg_list);
2637 				SPDK_DEBUGLOG(nvmf_tcp, "Put buf to control msg list\n");
2638 				nvmf_tcp_control_msg_put(tgroup->control_msg_list, tcp_req->req.data);
2639 			}
2640 			tcp_req->req.length = 0;
2641 			tcp_req->req.iovcnt = 0;
2642 			tcp_req->req.data = NULL;
2643 
2644 			nvmf_tcp_req_pdu_fini(tcp_req);
2645 
2646 			nvmf_tcp_req_put(tqpair, tcp_req);
2647 			break;
2648 		case TCP_REQUEST_NUM_STATES:
2649 		default:
2650 			assert(0);
2651 			break;
2652 		}
2653 
2654 		if (tcp_req->state != prev_state) {
2655 			progress = true;
2656 		}
2657 	} while (tcp_req->state != prev_state);
2658 
2659 	return progress;
2660 }
2661 
2662 static void
2663 nvmf_tcp_sock_cb(void *arg, struct spdk_sock_group *group, struct spdk_sock *sock)
2664 {
2665 	struct spdk_nvmf_tcp_qpair *tqpair = arg;
2666 	int rc;
2667 
2668 	assert(tqpair != NULL);
2669 	rc = nvmf_tcp_sock_process(tqpair);
2670 
2671 	/* If there was a new socket error, disconnect */
2672 	if (rc < 0) {
2673 		nvmf_tcp_qpair_disconnect(tqpair);
2674 	}
2675 }
2676 
2677 static int
2678 nvmf_tcp_poll_group_add(struct spdk_nvmf_transport_poll_group *group,
2679 			struct spdk_nvmf_qpair *qpair)
2680 {
2681 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2682 	struct spdk_nvmf_tcp_qpair	*tqpair;
2683 	int				rc;
2684 
2685 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2686 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2687 
2688 	rc = spdk_sock_group_add_sock(tgroup->sock_group, tqpair->sock,
2689 				      nvmf_tcp_sock_cb, tqpair);
2690 	if (rc != 0) {
2691 		SPDK_ERRLOG("Could not add sock to sock_group: %s (%d)\n",
2692 			    spdk_strerror(errno), errno);
2693 		return -1;
2694 	}
2695 
2696 	rc =  nvmf_tcp_qpair_sock_init(tqpair);
2697 	if (rc != 0) {
2698 		SPDK_ERRLOG("Cannot set sock opt for tqpair=%p\n", tqpair);
2699 		return -1;
2700 	}
2701 
2702 	rc = nvmf_tcp_qpair_init(&tqpair->qpair);
2703 	if (rc < 0) {
2704 		SPDK_ERRLOG("Cannot init tqpair=%p\n", tqpair);
2705 		return -1;
2706 	}
2707 
2708 	rc = nvmf_tcp_qpair_init_mem_resource(tqpair);
2709 	if (rc < 0) {
2710 		SPDK_ERRLOG("Cannot init memory resource info for tqpair=%p\n", tqpair);
2711 		return -1;
2712 	}
2713 
2714 	tqpair->group = tgroup;
2715 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INVALID);
2716 	TAILQ_INSERT_TAIL(&tgroup->qpairs, tqpair, link);
2717 
2718 	return 0;
2719 }
2720 
2721 static int
2722 nvmf_tcp_poll_group_remove(struct spdk_nvmf_transport_poll_group *group,
2723 			   struct spdk_nvmf_qpair *qpair)
2724 {
2725 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2726 	struct spdk_nvmf_tcp_qpair		*tqpair;
2727 	int				rc;
2728 
2729 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2730 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2731 
2732 	assert(tqpair->group == tgroup);
2733 
2734 	SPDK_DEBUGLOG(nvmf_tcp, "remove tqpair=%p from the tgroup=%p\n", tqpair, tgroup);
2735 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
2736 		TAILQ_REMOVE(&tgroup->await_req, tqpair, link);
2737 	} else {
2738 		TAILQ_REMOVE(&tgroup->qpairs, tqpair, link);
2739 	}
2740 
2741 	rc = spdk_sock_group_remove_sock(tgroup->sock_group, tqpair->sock);
2742 	if (rc != 0) {
2743 		SPDK_ERRLOG("Could not remove sock from sock_group: %s (%d)\n",
2744 			    spdk_strerror(errno), errno);
2745 	}
2746 
2747 	return rc;
2748 }
2749 
2750 static int
2751 nvmf_tcp_req_complete(struct spdk_nvmf_request *req)
2752 {
2753 	struct spdk_nvmf_tcp_transport *ttransport;
2754 	struct spdk_nvmf_tcp_req *tcp_req;
2755 
2756 	ttransport = SPDK_CONTAINEROF(req->qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2757 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2758 
2759 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTED);
2760 	nvmf_tcp_req_process(ttransport, tcp_req);
2761 
2762 	return 0;
2763 }
2764 
2765 static void
2766 nvmf_tcp_close_qpair(struct spdk_nvmf_qpair *qpair,
2767 		     spdk_nvmf_transport_qpair_fini_cb cb_fn, void *cb_arg)
2768 {
2769 	struct spdk_nvmf_tcp_qpair *tqpair;
2770 
2771 	SPDK_DEBUGLOG(nvmf_tcp, "Qpair: %p\n", qpair);
2772 
2773 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2774 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITED);
2775 	nvmf_tcp_qpair_destroy(tqpair);
2776 
2777 	if (cb_fn) {
2778 		cb_fn(cb_arg);
2779 	}
2780 }
2781 
2782 static int
2783 nvmf_tcp_poll_group_poll(struct spdk_nvmf_transport_poll_group *group)
2784 {
2785 	struct spdk_nvmf_tcp_poll_group *tgroup;
2786 	int rc;
2787 	struct spdk_nvmf_request *req, *req_tmp;
2788 	struct spdk_nvmf_tcp_req *tcp_req;
2789 	struct spdk_nvmf_tcp_qpair *tqpair, *tqpair_tmp;
2790 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(group->transport,
2791 			struct spdk_nvmf_tcp_transport, transport);
2792 
2793 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2794 
2795 	if (spdk_unlikely(TAILQ_EMPTY(&tgroup->qpairs) && TAILQ_EMPTY(&tgroup->await_req))) {
2796 		return 0;
2797 	}
2798 
2799 	STAILQ_FOREACH_SAFE(req, &group->pending_buf_queue, buf_link, req_tmp) {
2800 		tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2801 		if (nvmf_tcp_req_process(ttransport, tcp_req) == false) {
2802 			break;
2803 		}
2804 	}
2805 
2806 	rc = spdk_sock_group_poll(tgroup->sock_group);
2807 	if (rc < 0) {
2808 		SPDK_ERRLOG("Failed to poll sock_group=%p\n", tgroup->sock_group);
2809 	}
2810 
2811 	TAILQ_FOREACH_SAFE(tqpair, &tgroup->await_req, link, tqpair_tmp) {
2812 		nvmf_tcp_sock_process(tqpair);
2813 	}
2814 
2815 	return rc;
2816 }
2817 
2818 static int
2819 nvmf_tcp_qpair_get_trid(struct spdk_nvmf_qpair *qpair,
2820 			struct spdk_nvme_transport_id *trid, bool peer)
2821 {
2822 	struct spdk_nvmf_tcp_qpair     *tqpair;
2823 	uint16_t			port;
2824 
2825 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2826 	spdk_nvme_trid_populate_transport(trid, SPDK_NVME_TRANSPORT_TCP);
2827 
2828 	if (peer) {
2829 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->initiator_addr);
2830 		port = tqpair->initiator_port;
2831 	} else {
2832 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->target_addr);
2833 		port = tqpair->target_port;
2834 	}
2835 
2836 	if (spdk_sock_is_ipv4(tqpair->sock)) {
2837 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV4;
2838 	} else if (spdk_sock_is_ipv6(tqpair->sock)) {
2839 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV6;
2840 	} else {
2841 		return -1;
2842 	}
2843 
2844 	snprintf(trid->trsvcid, sizeof(trid->trsvcid), "%d", port);
2845 	return 0;
2846 }
2847 
2848 static int
2849 nvmf_tcp_qpair_get_local_trid(struct spdk_nvmf_qpair *qpair,
2850 			      struct spdk_nvme_transport_id *trid)
2851 {
2852 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2853 }
2854 
2855 static int
2856 nvmf_tcp_qpair_get_peer_trid(struct spdk_nvmf_qpair *qpair,
2857 			     struct spdk_nvme_transport_id *trid)
2858 {
2859 	return nvmf_tcp_qpair_get_trid(qpair, trid, 1);
2860 }
2861 
2862 static int
2863 nvmf_tcp_qpair_get_listen_trid(struct spdk_nvmf_qpair *qpair,
2864 			       struct spdk_nvme_transport_id *trid)
2865 {
2866 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2867 }
2868 
2869 static void
2870 nvmf_tcp_req_set_abort_status(struct spdk_nvmf_request *req,
2871 			      struct spdk_nvmf_tcp_req *tcp_req_to_abort)
2872 {
2873 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2874 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sc = SPDK_NVME_SC_ABORTED_BY_REQUEST;
2875 
2876 	nvmf_tcp_req_set_state(tcp_req_to_abort, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2877 
2878 	req->rsp->nvme_cpl.cdw0 &= ~1U; /* Command was successfully aborted. */
2879 }
2880 
2881 static int
2882 _nvmf_tcp_qpair_abort_request(void *ctx)
2883 {
2884 	struct spdk_nvmf_request *req = ctx;
2885 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = SPDK_CONTAINEROF(req->req_to_abort,
2886 			struct spdk_nvmf_tcp_req, req);
2887 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(req->req_to_abort->qpair,
2888 					     struct spdk_nvmf_tcp_qpair, qpair);
2889 	int rc;
2890 
2891 	spdk_poller_unregister(&req->poller);
2892 
2893 	switch (tcp_req_to_abort->state) {
2894 	case TCP_REQUEST_STATE_EXECUTING:
2895 		rc = nvmf_ctrlr_abort_request(req);
2896 		if (rc == SPDK_NVMF_REQUEST_EXEC_STATUS_ASYNCHRONOUS) {
2897 			return SPDK_POLLER_BUSY;
2898 		}
2899 		break;
2900 
2901 	case TCP_REQUEST_STATE_NEED_BUFFER:
2902 		STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue,
2903 			      &tcp_req_to_abort->req, spdk_nvmf_request, buf_link);
2904 
2905 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2906 		break;
2907 
2908 	case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2909 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2910 		break;
2911 
2912 	case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2913 		if (spdk_get_ticks() < req->timeout_tsc) {
2914 			req->poller = SPDK_POLLER_REGISTER(_nvmf_tcp_qpair_abort_request, req, 0);
2915 			return SPDK_POLLER_BUSY;
2916 		}
2917 		break;
2918 
2919 	default:
2920 		break;
2921 	}
2922 
2923 	spdk_nvmf_request_complete(req);
2924 	return SPDK_POLLER_BUSY;
2925 }
2926 
2927 static void
2928 nvmf_tcp_qpair_abort_request(struct spdk_nvmf_qpair *qpair,
2929 			     struct spdk_nvmf_request *req)
2930 {
2931 	struct spdk_nvmf_tcp_qpair *tqpair;
2932 	struct spdk_nvmf_tcp_transport *ttransport;
2933 	struct spdk_nvmf_transport *transport;
2934 	uint16_t cid;
2935 	uint32_t i;
2936 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = NULL;
2937 
2938 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2939 	ttransport = SPDK_CONTAINEROF(qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2940 	transport = &ttransport->transport;
2941 
2942 	cid = req->cmd->nvme_cmd.cdw10_bits.abort.cid;
2943 
2944 	for (i = 0; i < tqpair->resource_count; i++) {
2945 		if (tqpair->reqs[i].state != TCP_REQUEST_STATE_FREE &&
2946 		    tqpair->reqs[i].req.cmd->nvme_cmd.cid == cid) {
2947 			tcp_req_to_abort = &tqpair->reqs[i];
2948 			break;
2949 		}
2950 	}
2951 
2952 	spdk_trace_record(TRACE_TCP_QP_ABORT_REQ, 0, 0, (uintptr_t)req, tqpair);
2953 
2954 	if (tcp_req_to_abort == NULL) {
2955 		spdk_nvmf_request_complete(req);
2956 		return;
2957 	}
2958 
2959 	req->req_to_abort = &tcp_req_to_abort->req;
2960 	req->timeout_tsc = spdk_get_ticks() +
2961 			   transport->opts.abort_timeout_sec * spdk_get_ticks_hz();
2962 	req->poller = NULL;
2963 
2964 	_nvmf_tcp_qpair_abort_request(req);
2965 }
2966 
2967 #define SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH 128
2968 #define SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH 128
2969 #define SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR 128
2970 #define SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE 4096
2971 #define SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE 131072
2972 #define SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE 131072
2973 #define SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS 511
2974 #define SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE 32
2975 #define SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP false
2976 #define SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC 1
2977 
2978 static void
2979 nvmf_tcp_opts_init(struct spdk_nvmf_transport_opts *opts)
2980 {
2981 	opts->max_queue_depth =		SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH;
2982 	opts->max_qpairs_per_ctrlr =	SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR;
2983 	opts->in_capsule_data_size =	SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE;
2984 	opts->max_io_size =		SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE;
2985 	opts->io_unit_size =		SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE;
2986 	opts->max_aq_depth =		SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH;
2987 	opts->num_shared_buffers =	SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS;
2988 	opts->buf_cache_size =		SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE;
2989 	opts->dif_insert_or_strip =	SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP;
2990 	opts->abort_timeout_sec =	SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC;
2991 	opts->transport_specific =      NULL;
2992 }
2993 
2994 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp = {
2995 	.name = "TCP",
2996 	.type = SPDK_NVME_TRANSPORT_TCP,
2997 	.opts_init = nvmf_tcp_opts_init,
2998 	.create = nvmf_tcp_create,
2999 	.dump_opts = nvmf_tcp_dump_opts,
3000 	.destroy = nvmf_tcp_destroy,
3001 
3002 	.listen = nvmf_tcp_listen,
3003 	.stop_listen = nvmf_tcp_stop_listen,
3004 	.accept = nvmf_tcp_accept,
3005 
3006 	.listener_discover = nvmf_tcp_discover,
3007 
3008 	.poll_group_create = nvmf_tcp_poll_group_create,
3009 	.get_optimal_poll_group = nvmf_tcp_get_optimal_poll_group,
3010 	.poll_group_destroy = nvmf_tcp_poll_group_destroy,
3011 	.poll_group_add = nvmf_tcp_poll_group_add,
3012 	.poll_group_remove = nvmf_tcp_poll_group_remove,
3013 	.poll_group_poll = nvmf_tcp_poll_group_poll,
3014 
3015 	.req_free = nvmf_tcp_req_free,
3016 	.req_complete = nvmf_tcp_req_complete,
3017 
3018 	.qpair_fini = nvmf_tcp_close_qpair,
3019 	.qpair_get_local_trid = nvmf_tcp_qpair_get_local_trid,
3020 	.qpair_get_peer_trid = nvmf_tcp_qpair_get_peer_trid,
3021 	.qpair_get_listen_trid = nvmf_tcp_qpair_get_listen_trid,
3022 	.qpair_abort_request = nvmf_tcp_qpair_abort_request,
3023 };
3024 
3025 SPDK_NVMF_TRANSPORT_REGISTER(tcp, &spdk_nvmf_transport_tcp);
3026 SPDK_LOG_REGISTER_COMPONENT(nvmf_tcp)
3027