xref: /spdk/lib/nvmf/tcp.c (revision 7c06be855a536a76a47e88f1632af3f64afc3af2)
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright (c) Intel Corporation. All rights reserved.
5  *   Copyright (c) 2019, 2020 Mellanox Technologies LTD. All rights reserved.
6  *
7  *   Redistribution and use in source and binary forms, with or without
8  *   modification, are permitted provided that the following conditions
9  *   are met:
10  *
11  *     * Redistributions of source code must retain the above copyright
12  *       notice, this list of conditions and the following disclaimer.
13  *     * Redistributions in binary form must reproduce the above copyright
14  *       notice, this list of conditions and the following disclaimer in
15  *       the documentation and/or other materials provided with the
16  *       distribution.
17  *     * Neither the name of Intel Corporation nor the names of its
18  *       contributors may be used to endorse or promote products derived
19  *       from this software without specific prior written permission.
20  *
21  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
22  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
23  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
24  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
25  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
26  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
27  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
28  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
29  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32  */
33 
34 #include "spdk/accel_engine.h"
35 #include "spdk/stdinc.h"
36 #include "spdk/crc32.h"
37 #include "spdk/endian.h"
38 #include "spdk/assert.h"
39 #include "spdk/thread.h"
40 #include "spdk/nvmf_transport.h"
41 #include "spdk/string.h"
42 #include "spdk/trace.h"
43 #include "spdk/util.h"
44 #include "spdk/log.h"
45 
46 #include "spdk_internal/assert.h"
47 #include "spdk_internal/nvme_tcp.h"
48 #include "spdk_internal/sock.h"
49 
50 #include "nvmf_internal.h"
51 
52 #define NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME 16
53 #define SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY 16
54 #define SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY 0
55 #define SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM 32
56 #define SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION true
57 
58 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp;
59 
60 /* spdk nvmf related structure */
61 enum spdk_nvmf_tcp_req_state {
62 
63 	/* The request is not currently in use */
64 	TCP_REQUEST_STATE_FREE = 0,
65 
66 	/* Initial state when request first received */
67 	TCP_REQUEST_STATE_NEW,
68 
69 	/* The request is queued until a data buffer is available. */
70 	TCP_REQUEST_STATE_NEED_BUFFER,
71 
72 	/* The request is currently transferring data from the host to the controller. */
73 	TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
74 
75 	/* The request is waiting for the R2T send acknowledgement. */
76 	TCP_REQUEST_STATE_AWAITING_R2T_ACK,
77 
78 	/* The request is ready to execute at the block device */
79 	TCP_REQUEST_STATE_READY_TO_EXECUTE,
80 
81 	/* The request is currently executing at the block device */
82 	TCP_REQUEST_STATE_EXECUTING,
83 
84 	/* The request finished executing at the block device */
85 	TCP_REQUEST_STATE_EXECUTED,
86 
87 	/* The request is ready to send a completion */
88 	TCP_REQUEST_STATE_READY_TO_COMPLETE,
89 
90 	/* The request is currently transferring final pdus from the controller to the host. */
91 	TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
92 
93 	/* The request completed and can be marked free. */
94 	TCP_REQUEST_STATE_COMPLETED,
95 
96 	/* Terminator */
97 	TCP_REQUEST_NUM_STATES,
98 };
99 
100 static const char *spdk_nvmf_tcp_term_req_fes_str[] = {
101 	"Invalid PDU Header Field",
102 	"PDU Sequence Error",
103 	"Header Digiest Error",
104 	"Data Transfer Out of Range",
105 	"R2T Limit Exceeded",
106 	"Unsupported parameter",
107 };
108 
109 #define OBJECT_NVMF_TCP_IO				0x80
110 
111 #define TRACE_GROUP_NVMF_TCP				0x5
112 #define TRACE_TCP_REQUEST_STATE_NEW					SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x0)
113 #define TRACE_TCP_REQUEST_STATE_NEED_BUFFER				SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x1)
114 #define TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER		SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x2)
115 #define TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE			SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x3)
116 #define TRACE_TCP_REQUEST_STATE_EXECUTING				SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x4)
117 #define TRACE_TCP_REQUEST_STATE_EXECUTED				SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x5)
118 #define TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE			SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x6)
119 #define TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST		SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x7)
120 #define TRACE_TCP_REQUEST_STATE_COMPLETED				SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x8)
121 #define TRACE_TCP_FLUSH_WRITEBUF_START					SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0x9)
122 #define TRACE_TCP_FLUSH_WRITEBUF_DONE					SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0xA)
123 #define TRACE_TCP_READ_FROM_SOCKET_DONE					SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0xB)
124 #define TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK				SPDK_TPOINT_ID(TRACE_GROUP_NVMF_TCP, 0xC)
125 
126 SPDK_TRACE_REGISTER_FN(nvmf_tcp_trace, "nvmf_tcp", TRACE_GROUP_NVMF_TCP)
127 {
128 	spdk_trace_register_object(OBJECT_NVMF_TCP_IO, 'r');
129 	spdk_trace_register_description("TCP_REQ_NEW",
130 					TRACE_TCP_REQUEST_STATE_NEW,
131 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 1,
132 					SPDK_TRACE_ARG_TYPE_INT, "");
133 	spdk_trace_register_description("TCP_REQ_NEED_BUFFER",
134 					TRACE_TCP_REQUEST_STATE_NEED_BUFFER,
135 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
136 					SPDK_TRACE_ARG_TYPE_INT, "");
137 	spdk_trace_register_description("TCP_REQ_TX_H_TO_C",
138 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
139 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
140 					SPDK_TRACE_ARG_TYPE_INT, "");
141 	spdk_trace_register_description("TCP_REQ_RDY_TO_EXECUTE",
142 					TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE,
143 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
144 					SPDK_TRACE_ARG_TYPE_INT, "");
145 	spdk_trace_register_description("TCP_REQ_EXECUTING",
146 					TRACE_TCP_REQUEST_STATE_EXECUTING,
147 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
148 					SPDK_TRACE_ARG_TYPE_INT, "");
149 	spdk_trace_register_description("TCP_REQ_EXECUTED",
150 					TRACE_TCP_REQUEST_STATE_EXECUTED,
151 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
152 					SPDK_TRACE_ARG_TYPE_INT, "");
153 	spdk_trace_register_description("TCP_REQ_RDY_TO_COMPLETE",
154 					TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE,
155 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
156 					SPDK_TRACE_ARG_TYPE_INT, "");
157 	spdk_trace_register_description("TCP_REQ_TRANSFER_C2H",
158 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
159 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
160 					SPDK_TRACE_ARG_TYPE_INT, "");
161 	spdk_trace_register_description("TCP_REQ_COMPLETED",
162 					TRACE_TCP_REQUEST_STATE_COMPLETED,
163 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
164 					SPDK_TRACE_ARG_TYPE_INT, "");
165 	spdk_trace_register_description("TCP_WRITE_START",
166 					TRACE_TCP_FLUSH_WRITEBUF_START,
167 					OWNER_NONE, OBJECT_NONE, 0,
168 					SPDK_TRACE_ARG_TYPE_INT, "");
169 	spdk_trace_register_description("TCP_WRITE_DONE",
170 					TRACE_TCP_FLUSH_WRITEBUF_DONE,
171 					OWNER_NONE, OBJECT_NONE, 0,
172 					SPDK_TRACE_ARG_TYPE_INT, "");
173 	spdk_trace_register_description("TCP_READ_DONE",
174 					TRACE_TCP_READ_FROM_SOCKET_DONE,
175 					OWNER_NONE, OBJECT_NONE, 0,
176 					SPDK_TRACE_ARG_TYPE_INT, "");
177 	spdk_trace_register_description("TCP_REQ_AWAIT_R2T_ACK",
178 					TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK,
179 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
180 					SPDK_TRACE_ARG_TYPE_INT, "");
181 }
182 
183 struct spdk_nvmf_tcp_req  {
184 	struct spdk_nvmf_request		req;
185 	struct spdk_nvme_cpl			rsp;
186 	struct spdk_nvme_cmd			cmd;
187 
188 	/* A PDU that can be used for sending responses. This is
189 	 * not the incoming PDU! */
190 	struct nvme_tcp_pdu			*pdu;
191 
192 	/* In-capsule data buffer */
193 	uint8_t					*buf;
194 	/*
195 	 * The PDU for a request may be used multiple times in serial over
196 	 * the request's lifetime. For example, first to send an R2T, then
197 	 * to send a completion. To catch mistakes where the PDU is used
198 	 * twice at the same time, add a debug flag here for init/fini.
199 	 */
200 	bool					pdu_in_use;
201 	bool					has_incapsule_data;
202 
203 	/* transfer_tag */
204 	uint16_t				ttag;
205 
206 	enum spdk_nvmf_tcp_req_state		state;
207 
208 	/*
209 	 * h2c_offset is used when we receive the h2c_data PDU.
210 	 */
211 	uint32_t				h2c_offset;
212 
213 	STAILQ_ENTRY(spdk_nvmf_tcp_req)		link;
214 	TAILQ_ENTRY(spdk_nvmf_tcp_req)		state_link;
215 };
216 
217 struct spdk_nvmf_tcp_qpair {
218 	struct spdk_nvmf_qpair			qpair;
219 	struct spdk_nvmf_tcp_poll_group		*group;
220 	struct spdk_sock			*sock;
221 
222 	enum nvme_tcp_pdu_recv_state		recv_state;
223 	enum nvme_tcp_qpair_state		state;
224 
225 	/* PDU being actively received */
226 	struct nvme_tcp_pdu			*pdu_in_progress;
227 
228 	/* Queues to track the requests in all states */
229 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_working_queue;
230 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_free_queue;
231 
232 	/* Number of requests in each state */
233 	uint32_t				state_cntr[TCP_REQUEST_NUM_STATES];
234 
235 	uint8_t					cpda;
236 
237 	bool					host_hdgst_enable;
238 	bool					host_ddgst_enable;
239 
240 	/* This is a spare PDU used for sending special management
241 	 * operations. Primarily, this is used for the initial
242 	 * connection response and c2h termination request. */
243 	struct nvme_tcp_pdu			*mgmt_pdu;
244 
245 	/* Arrays of in-capsule buffers, requests, and pdus.
246 	 * Each array is 'resource_count' number of elements */
247 	void					*bufs;
248 	struct spdk_nvmf_tcp_req		*reqs;
249 	struct nvme_tcp_pdu			*pdus;
250 	uint32_t				resource_count;
251 	uint32_t				recv_buf_size;
252 
253 	struct spdk_nvmf_tcp_port		*port;
254 
255 	/* IP address */
256 	char					initiator_addr[SPDK_NVMF_TRADDR_MAX_LEN];
257 	char					target_addr[SPDK_NVMF_TRADDR_MAX_LEN];
258 
259 	/* IP port */
260 	uint16_t				initiator_port;
261 	uint16_t				target_port;
262 
263 	/* Timer used to destroy qpair after detecting transport error issue if initiator does
264 	 *  not close the connection.
265 	 */
266 	struct spdk_poller			*timeout_poller;
267 
268 
269 	TAILQ_ENTRY(spdk_nvmf_tcp_qpair)	link;
270 };
271 
272 struct spdk_nvmf_tcp_control_msg {
273 	STAILQ_ENTRY(spdk_nvmf_tcp_control_msg) link;
274 };
275 
276 struct spdk_nvmf_tcp_control_msg_list {
277 	void *msg_buf;
278 	STAILQ_HEAD(, spdk_nvmf_tcp_control_msg) free_msgs;
279 };
280 
281 struct spdk_nvmf_tcp_poll_group {
282 	struct spdk_nvmf_transport_poll_group	group;
283 	struct spdk_sock_group			*sock_group;
284 
285 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	qpairs;
286 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	await_req;
287 
288 	struct spdk_io_channel			*accel_channel;
289 	struct spdk_nvmf_tcp_control_msg_list	*control_msg_list;
290 };
291 
292 struct spdk_nvmf_tcp_port {
293 	const struct spdk_nvme_transport_id	*trid;
294 	struct spdk_sock			*listen_sock;
295 	TAILQ_ENTRY(spdk_nvmf_tcp_port)		link;
296 };
297 
298 struct tcp_transport_opts {
299 	bool		c2h_success;
300 	uint16_t	control_msg_num;
301 	uint32_t	sock_priority;
302 };
303 
304 struct spdk_nvmf_tcp_transport {
305 	struct spdk_nvmf_transport		transport;
306 	struct tcp_transport_opts               tcp_opts;
307 
308 	pthread_mutex_t				lock;
309 
310 	TAILQ_HEAD(, spdk_nvmf_tcp_port)	ports;
311 };
312 
313 static const struct spdk_json_object_decoder tcp_transport_opts_decoder[] = {
314 	{
315 		"c2h_success", offsetof(struct tcp_transport_opts, c2h_success),
316 		spdk_json_decode_bool, true
317 	},
318 	{
319 		"control_msg_num", offsetof(struct tcp_transport_opts, control_msg_num),
320 		spdk_json_decode_uint16, true
321 	},
322 	{
323 		"sock_priority", offsetof(struct tcp_transport_opts, sock_priority),
324 		spdk_json_decode_uint32, true
325 	},
326 };
327 
328 static bool nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
329 				 struct spdk_nvmf_tcp_req *tcp_req);
330 static void nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group);
331 
332 static void _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
333 				    struct spdk_nvmf_tcp_req *tcp_req);
334 
335 static void
336 nvmf_tcp_req_set_state(struct spdk_nvmf_tcp_req *tcp_req,
337 		       enum spdk_nvmf_tcp_req_state state)
338 {
339 	struct spdk_nvmf_qpair *qpair;
340 	struct spdk_nvmf_tcp_qpair *tqpair;
341 
342 	qpair = tcp_req->req.qpair;
343 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
344 
345 	assert(tqpair->state_cntr[tcp_req->state] > 0);
346 	tqpair->state_cntr[tcp_req->state]--;
347 	tqpair->state_cntr[state]++;
348 
349 	tcp_req->state = state;
350 }
351 
352 static inline struct nvme_tcp_pdu *
353 nvmf_tcp_req_pdu_init(struct spdk_nvmf_tcp_req *tcp_req)
354 {
355 	assert(tcp_req->pdu_in_use == false);
356 	tcp_req->pdu_in_use = true;
357 
358 	memset(tcp_req->pdu, 0, sizeof(*tcp_req->pdu));
359 	tcp_req->pdu->qpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
360 
361 	return tcp_req->pdu;
362 }
363 
364 static inline void
365 nvmf_tcp_req_pdu_fini(struct spdk_nvmf_tcp_req *tcp_req)
366 {
367 	tcp_req->pdu_in_use = false;
368 }
369 
370 static struct spdk_nvmf_tcp_req *
371 nvmf_tcp_req_get(struct spdk_nvmf_tcp_qpair *tqpair)
372 {
373 	struct spdk_nvmf_tcp_req *tcp_req;
374 
375 	tcp_req = TAILQ_FIRST(&tqpair->tcp_req_free_queue);
376 	if (!tcp_req) {
377 		return NULL;
378 	}
379 
380 	memset(&tcp_req->rsp, 0, sizeof(tcp_req->rsp));
381 	tcp_req->h2c_offset = 0;
382 	tcp_req->has_incapsule_data = false;
383 	tcp_req->req.dif_enabled = false;
384 
385 	TAILQ_REMOVE(&tqpair->tcp_req_free_queue, tcp_req, state_link);
386 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_working_queue, tcp_req, state_link);
387 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEW);
388 	return tcp_req;
389 }
390 
391 static inline void
392 nvmf_tcp_req_put(struct spdk_nvmf_tcp_qpair *tqpair, struct spdk_nvmf_tcp_req *tcp_req)
393 {
394 	TAILQ_REMOVE(&tqpair->tcp_req_working_queue, tcp_req, state_link);
395 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
396 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_FREE);
397 }
398 
399 static void
400 nvmf_tcp_request_free(void *cb_arg)
401 {
402 	struct spdk_nvmf_tcp_transport *ttransport;
403 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
404 
405 	assert(tcp_req != NULL);
406 
407 	SPDK_DEBUGLOG(nvmf_tcp, "tcp_req=%p will be freed\n", tcp_req);
408 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
409 				      struct spdk_nvmf_tcp_transport, transport);
410 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
411 	nvmf_tcp_req_process(ttransport, tcp_req);
412 }
413 
414 static int
415 nvmf_tcp_req_free(struct spdk_nvmf_request *req)
416 {
417 	struct spdk_nvmf_tcp_req *tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
418 
419 	nvmf_tcp_request_free(tcp_req);
420 
421 	return 0;
422 }
423 
424 static void
425 nvmf_tcp_drain_state_queue(struct spdk_nvmf_tcp_qpair *tqpair,
426 			   enum spdk_nvmf_tcp_req_state state)
427 {
428 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
429 
430 	assert(state != TCP_REQUEST_STATE_FREE);
431 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
432 		if (state == tcp_req->state) {
433 			nvmf_tcp_request_free(tcp_req);
434 		}
435 	}
436 }
437 
438 static void
439 nvmf_tcp_cleanup_all_states(struct spdk_nvmf_tcp_qpair *tqpair)
440 {
441 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
442 
443 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
444 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEW);
445 
446 	/* Wipe the requests waiting for buffer from the global list */
447 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
448 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
449 			STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue, &tcp_req->req,
450 				      spdk_nvmf_request, buf_link);
451 		}
452 	}
453 
454 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEED_BUFFER);
455 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_EXECUTING);
456 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
457 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
458 }
459 
460 static void
461 nvmf_tcp_dump_qpair_req_contents(struct spdk_nvmf_tcp_qpair *tqpair)
462 {
463 	int i;
464 	struct spdk_nvmf_tcp_req *tcp_req;
465 
466 	SPDK_ERRLOG("Dumping contents of queue pair (QID %d)\n", tqpair->qpair.qid);
467 	for (i = 1; i < TCP_REQUEST_NUM_STATES; i++) {
468 		SPDK_ERRLOG("\tNum of requests in state[%d] = %u\n", i, tqpair->state_cntr[i]);
469 		TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
470 			if ((int)tcp_req->state == i) {
471 				SPDK_ERRLOG("\t\tRequest Data From Pool: %d\n", tcp_req->req.data_from_pool);
472 				SPDK_ERRLOG("\t\tRequest opcode: %d\n", tcp_req->req.cmd->nvmf_cmd.opcode);
473 			}
474 		}
475 	}
476 }
477 
478 static void
479 nvmf_tcp_qpair_destroy(struct spdk_nvmf_tcp_qpair *tqpair)
480 {
481 	int err = 0;
482 
483 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
484 
485 	err = spdk_sock_close(&tqpair->sock);
486 	assert(err == 0);
487 	nvmf_tcp_cleanup_all_states(tqpair);
488 
489 	if (tqpair->state_cntr[TCP_REQUEST_STATE_FREE] != tqpair->resource_count) {
490 		SPDK_ERRLOG("tqpair(%p) free tcp request num is %u but should be %u\n", tqpair,
491 			    tqpair->state_cntr[TCP_REQUEST_STATE_FREE],
492 			    tqpair->resource_count);
493 		err++;
494 	}
495 
496 	if (err > 0) {
497 		nvmf_tcp_dump_qpair_req_contents(tqpair);
498 	}
499 
500 	spdk_dma_free(tqpair->pdus);
501 	free(tqpair->reqs);
502 	spdk_free(tqpair->bufs);
503 	free(tqpair);
504 	SPDK_DEBUGLOG(nvmf_tcp, "Leave\n");
505 }
506 
507 static void
508 nvmf_tcp_dump_opts(struct spdk_nvmf_transport *transport, struct spdk_json_write_ctx *w)
509 {
510 	struct spdk_nvmf_tcp_transport	*ttransport;
511 	assert(w != NULL);
512 
513 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
514 	spdk_json_write_named_bool(w, "c2h_success", ttransport->tcp_opts.c2h_success);
515 	spdk_json_write_named_uint32(w, "sock_priority", ttransport->tcp_opts.sock_priority);
516 }
517 
518 static int
519 nvmf_tcp_destroy(struct spdk_nvmf_transport *transport,
520 		 spdk_nvmf_transport_destroy_done_cb cb_fn, void *cb_arg)
521 {
522 	struct spdk_nvmf_tcp_transport	*ttransport;
523 
524 	assert(transport != NULL);
525 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
526 
527 	pthread_mutex_destroy(&ttransport->lock);
528 	free(ttransport);
529 
530 	if (cb_fn) {
531 		cb_fn(cb_arg);
532 	}
533 	return 0;
534 }
535 
536 static struct spdk_nvmf_transport *
537 nvmf_tcp_create(struct spdk_nvmf_transport_opts *opts)
538 {
539 	struct spdk_nvmf_tcp_transport *ttransport;
540 	uint32_t sge_count;
541 	uint32_t min_shared_buffers;
542 
543 	ttransport = calloc(1, sizeof(*ttransport));
544 	if (!ttransport) {
545 		return NULL;
546 	}
547 
548 	TAILQ_INIT(&ttransport->ports);
549 
550 	ttransport->transport.ops = &spdk_nvmf_transport_tcp;
551 
552 	ttransport->tcp_opts.c2h_success = SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION;
553 	ttransport->tcp_opts.sock_priority = SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY;
554 	ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
555 	if (opts->transport_specific != NULL &&
556 	    spdk_json_decode_object_relaxed(opts->transport_specific, tcp_transport_opts_decoder,
557 					    SPDK_COUNTOF(tcp_transport_opts_decoder),
558 					    &ttransport->tcp_opts)) {
559 		SPDK_ERRLOG("spdk_json_decode_object_relaxed failed\n");
560 		free(ttransport);
561 		return NULL;
562 	}
563 
564 	SPDK_NOTICELOG("*** TCP Transport Init ***\n");
565 
566 	SPDK_INFOLOG(nvmf_tcp, "*** TCP Transport Init ***\n"
567 		     "  Transport opts:  max_ioq_depth=%d, max_io_size=%d,\n"
568 		     "  max_io_qpairs_per_ctrlr=%d, io_unit_size=%d,\n"
569 		     "  in_capsule_data_size=%d, max_aq_depth=%d\n"
570 		     "  num_shared_buffers=%d, c2h_success=%d,\n"
571 		     "  dif_insert_or_strip=%d, sock_priority=%d\n"
572 		     "  abort_timeout_sec=%d, control_msg_num=%hu\n",
573 		     opts->max_queue_depth,
574 		     opts->max_io_size,
575 		     opts->max_qpairs_per_ctrlr - 1,
576 		     opts->io_unit_size,
577 		     opts->in_capsule_data_size,
578 		     opts->max_aq_depth,
579 		     opts->num_shared_buffers,
580 		     ttransport->tcp_opts.c2h_success,
581 		     opts->dif_insert_or_strip,
582 		     ttransport->tcp_opts.sock_priority,
583 		     opts->abort_timeout_sec,
584 		     ttransport->tcp_opts.control_msg_num);
585 
586 	if (ttransport->tcp_opts.sock_priority > SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY) {
587 		SPDK_ERRLOG("Unsupported socket_priority=%d, the current range is: 0 to %d\n"
588 			    "you can use man 7 socket to view the range of priority under SO_PRIORITY item\n",
589 			    ttransport->tcp_opts.sock_priority, SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY);
590 		free(ttransport);
591 		return NULL;
592 	}
593 
594 	if (ttransport->tcp_opts.control_msg_num == 0 &&
595 	    opts->in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
596 		SPDK_WARNLOG("TCP param control_msg_num can't be 0 if ICD is less than %u bytes. Using default value %u\n",
597 			     SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE, SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM);
598 		ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
599 	}
600 
601 	/* I/O unit size cannot be larger than max I/O size */
602 	if (opts->io_unit_size > opts->max_io_size) {
603 		opts->io_unit_size = opts->max_io_size;
604 	}
605 
606 	sge_count = opts->max_io_size / opts->io_unit_size;
607 	if (sge_count > SPDK_NVMF_MAX_SGL_ENTRIES) {
608 		SPDK_ERRLOG("Unsupported IO Unit size specified, %d bytes\n", opts->io_unit_size);
609 		free(ttransport);
610 		return NULL;
611 	}
612 
613 	min_shared_buffers = spdk_env_get_core_count() * opts->buf_cache_size;
614 	if (min_shared_buffers > opts->num_shared_buffers) {
615 		SPDK_ERRLOG("There are not enough buffers to satisfy"
616 			    "per-poll group caches for each thread. (%" PRIu32 ")"
617 			    "supplied. (%" PRIu32 ") required\n", opts->num_shared_buffers, min_shared_buffers);
618 		SPDK_ERRLOG("Please specify a larger number of shared buffers\n");
619 		free(ttransport);
620 		return NULL;
621 	}
622 
623 	pthread_mutex_init(&ttransport->lock, NULL);
624 
625 	return &ttransport->transport;
626 }
627 
628 static int
629 nvmf_tcp_trsvcid_to_int(const char *trsvcid)
630 {
631 	unsigned long long ull;
632 	char *end = NULL;
633 
634 	ull = strtoull(trsvcid, &end, 10);
635 	if (end == NULL || end == trsvcid || *end != '\0') {
636 		return -1;
637 	}
638 
639 	/* Valid TCP/IP port numbers are in [0, 65535] */
640 	if (ull > 65535) {
641 		return -1;
642 	}
643 
644 	return (int)ull;
645 }
646 
647 /**
648  * Canonicalize a listen address trid.
649  */
650 static int
651 nvmf_tcp_canon_listen_trid(struct spdk_nvme_transport_id *canon_trid,
652 			   const struct spdk_nvme_transport_id *trid)
653 {
654 	int trsvcid_int;
655 
656 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
657 	if (trsvcid_int < 0) {
658 		return -EINVAL;
659 	}
660 
661 	memset(canon_trid, 0, sizeof(*canon_trid));
662 	spdk_nvme_trid_populate_transport(canon_trid, SPDK_NVME_TRANSPORT_TCP);
663 	canon_trid->adrfam = trid->adrfam;
664 	snprintf(canon_trid->traddr, sizeof(canon_trid->traddr), "%s", trid->traddr);
665 	snprintf(canon_trid->trsvcid, sizeof(canon_trid->trsvcid), "%d", trsvcid_int);
666 
667 	return 0;
668 }
669 
670 /**
671  * Find an existing listening port.
672  *
673  * Caller must hold ttransport->lock.
674  */
675 static struct spdk_nvmf_tcp_port *
676 nvmf_tcp_find_port(struct spdk_nvmf_tcp_transport *ttransport,
677 		   const struct spdk_nvme_transport_id *trid)
678 {
679 	struct spdk_nvme_transport_id canon_trid;
680 	struct spdk_nvmf_tcp_port *port;
681 
682 	if (nvmf_tcp_canon_listen_trid(&canon_trid, trid) != 0) {
683 		return NULL;
684 	}
685 
686 	TAILQ_FOREACH(port, &ttransport->ports, link) {
687 		if (spdk_nvme_transport_id_compare(&canon_trid, port->trid) == 0) {
688 			return port;
689 		}
690 	}
691 
692 	return NULL;
693 }
694 
695 static int
696 nvmf_tcp_listen(struct spdk_nvmf_transport *transport, const struct spdk_nvme_transport_id *trid,
697 		struct spdk_nvmf_listen_opts *listen_opts)
698 {
699 	struct spdk_nvmf_tcp_transport *ttransport;
700 	struct spdk_nvmf_tcp_port *port;
701 	int trsvcid_int;
702 	uint8_t adrfam;
703 	struct spdk_sock_opts opts;
704 
705 	if (!strlen(trid->trsvcid)) {
706 		SPDK_ERRLOG("Service id is required\n");
707 		return -EINVAL;
708 	}
709 
710 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
711 
712 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
713 	if (trsvcid_int < 0) {
714 		SPDK_ERRLOG("Invalid trsvcid '%s'\n", trid->trsvcid);
715 		return -EINVAL;
716 	}
717 
718 	pthread_mutex_lock(&ttransport->lock);
719 	port = calloc(1, sizeof(*port));
720 	if (!port) {
721 		SPDK_ERRLOG("Port allocation failed\n");
722 		pthread_mutex_unlock(&ttransport->lock);
723 		return -ENOMEM;
724 	}
725 
726 	port->trid = trid;
727 	opts.opts_size = sizeof(opts);
728 	spdk_sock_get_default_opts(&opts);
729 	opts.priority = ttransport->tcp_opts.sock_priority;
730 	port->listen_sock = spdk_sock_listen_ext(trid->traddr, trsvcid_int,
731 			    NULL, &opts);
732 	if (port->listen_sock == NULL) {
733 		SPDK_ERRLOG("spdk_sock_listen(%s, %d) failed: %s (%d)\n",
734 			    trid->traddr, trsvcid_int,
735 			    spdk_strerror(errno), errno);
736 		free(port);
737 		pthread_mutex_unlock(&ttransport->lock);
738 		return -errno;
739 	}
740 
741 	if (spdk_sock_is_ipv4(port->listen_sock)) {
742 		adrfam = SPDK_NVMF_ADRFAM_IPV4;
743 	} else if (spdk_sock_is_ipv6(port->listen_sock)) {
744 		adrfam = SPDK_NVMF_ADRFAM_IPV6;
745 	} else {
746 		SPDK_ERRLOG("Unhandled socket type\n");
747 		adrfam = 0;
748 	}
749 
750 	if (adrfam != trid->adrfam) {
751 		SPDK_ERRLOG("Socket address family mismatch\n");
752 		spdk_sock_close(&port->listen_sock);
753 		free(port);
754 		pthread_mutex_unlock(&ttransport->lock);
755 		return -EINVAL;
756 	}
757 
758 	SPDK_NOTICELOG("*** NVMe/TCP Target Listening on %s port %s ***\n",
759 		       trid->traddr, trid->trsvcid);
760 
761 	TAILQ_INSERT_TAIL(&ttransport->ports, port, link);
762 	pthread_mutex_unlock(&ttransport->lock);
763 	return 0;
764 }
765 
766 static void
767 nvmf_tcp_stop_listen(struct spdk_nvmf_transport *transport,
768 		     const struct spdk_nvme_transport_id *trid)
769 {
770 	struct spdk_nvmf_tcp_transport *ttransport;
771 	struct spdk_nvmf_tcp_port *port;
772 
773 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
774 
775 	SPDK_DEBUGLOG(nvmf_tcp, "Removing listen address %s port %s\n",
776 		      trid->traddr, trid->trsvcid);
777 
778 	pthread_mutex_lock(&ttransport->lock);
779 	port = nvmf_tcp_find_port(ttransport, trid);
780 	if (port) {
781 		TAILQ_REMOVE(&ttransport->ports, port, link);
782 		spdk_sock_close(&port->listen_sock);
783 		free(port);
784 	}
785 
786 	pthread_mutex_unlock(&ttransport->lock);
787 }
788 
789 static void nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
790 		enum nvme_tcp_pdu_recv_state state);
791 
792 static void
793 nvmf_tcp_qpair_disconnect(struct spdk_nvmf_tcp_qpair *tqpair)
794 {
795 	SPDK_DEBUGLOG(nvmf_tcp, "Disconnecting qpair %p\n", tqpair);
796 
797 	if (tqpair->state <= NVME_TCP_QPAIR_STATE_RUNNING) {
798 		tqpair->state = NVME_TCP_QPAIR_STATE_EXITING;
799 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
800 		spdk_poller_unregister(&tqpair->timeout_poller);
801 
802 		/* This will end up calling nvmf_tcp_close_qpair */
803 		spdk_nvmf_qpair_disconnect(&tqpair->qpair, NULL, NULL);
804 	}
805 }
806 
807 static void
808 _pdu_write_done(void *_pdu, int err)
809 {
810 	struct nvme_tcp_pdu			*pdu = _pdu;
811 	struct spdk_nvmf_tcp_qpair		*tqpair = pdu->qpair;
812 
813 	if (err != 0) {
814 		nvmf_tcp_qpair_disconnect(tqpair);
815 		return;
816 	}
817 
818 	assert(pdu->cb_fn != NULL);
819 	pdu->cb_fn(pdu->cb_arg);
820 }
821 
822 static void
823 _tcp_write_pdu(struct nvme_tcp_pdu *pdu)
824 {
825 	uint32_t mapped_length = 0;
826 	ssize_t rc;
827 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
828 
829 	pdu->sock_req.iovcnt = nvme_tcp_build_iovs(pdu->iov, SPDK_COUNTOF(pdu->iov), pdu,
830 			       tqpair->host_hdgst_enable, tqpair->host_ddgst_enable,
831 			       &mapped_length);
832 	pdu->sock_req.cb_fn = _pdu_write_done;
833 	pdu->sock_req.cb_arg = pdu;
834 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_RESP ||
835 	    pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ) {
836 		rc = spdk_sock_writev(tqpair->sock, pdu->iov, pdu->sock_req.iovcnt);
837 		if (rc == mapped_length) {
838 			_pdu_write_done(pdu, 0);
839 		} else {
840 			SPDK_ERRLOG("IC_RESP or TERM_REQ could not write to socket.\n");
841 			_pdu_write_done(pdu, -1);
842 		}
843 	} else {
844 		spdk_sock_writev_async(tqpair->sock, &pdu->sock_req);
845 	}
846 }
847 
848 static void
849 data_crc32_accel_done(void *cb_arg, int status)
850 {
851 	struct nvme_tcp_pdu *pdu = cb_arg;
852 
853 	if (spdk_unlikely(status)) {
854 		SPDK_ERRLOG("Failed to compute the data digest for pdu =%p\n", pdu);
855 		_pdu_write_done(pdu, status);
856 		return;
857 	}
858 
859 	pdu->data_digest_crc32 ^= SPDK_CRC32C_XOR;
860 	MAKE_DIGEST_WORD(pdu->data_digest, pdu->data_digest_crc32);
861 
862 	_tcp_write_pdu(pdu);
863 }
864 
865 static void
866 pdu_data_crc32_compute(struct nvme_tcp_pdu *pdu)
867 {
868 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
869 	uint32_t crc32c;
870 
871 	/* Data Digest */
872 	if (pdu->data_len > 0 && g_nvme_tcp_ddgst[pdu->hdr.common.pdu_type] && tqpair->host_ddgst_enable) {
873 		/* Only suport this limitated case for the first step */
874 		if (spdk_likely(!pdu->dif_ctx && (pdu->data_len % SPDK_NVME_TCP_DIGEST_ALIGNMENT == 0)
875 				&& tqpair->group)) {
876 			spdk_accel_submit_crc32cv(tqpair->group->accel_channel, &pdu->data_digest_crc32,
877 						  pdu->data_iov, pdu->data_iovcnt, 0, data_crc32_accel_done, pdu);
878 			return;
879 		}
880 
881 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
882 		MAKE_DIGEST_WORD(pdu->data_digest, crc32c);
883 	}
884 
885 	_tcp_write_pdu(pdu);
886 }
887 
888 static void
889 nvmf_tcp_qpair_write_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
890 			 struct nvme_tcp_pdu *pdu,
891 			 nvme_tcp_qpair_xfer_complete_cb cb_fn,
892 			 void *cb_arg)
893 {
894 	int hlen;
895 	uint32_t crc32c;
896 
897 	assert(tqpair->pdu_in_progress != pdu);
898 
899 	hlen = pdu->hdr.common.hlen;
900 	pdu->cb_fn = cb_fn;
901 	pdu->cb_arg = cb_arg;
902 
903 	pdu->iov[0].iov_base = &pdu->hdr.raw;
904 	pdu->iov[0].iov_len = hlen;
905 
906 	/* Header Digest */
907 	if (g_nvme_tcp_hdgst[pdu->hdr.common.pdu_type] && tqpair->host_hdgst_enable) {
908 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
909 		MAKE_DIGEST_WORD((uint8_t *)pdu->hdr.raw + hlen, crc32c);
910 	}
911 
912 	/* Data Digest */
913 	pdu_data_crc32_compute(pdu);
914 }
915 
916 static int
917 nvmf_tcp_qpair_init_mem_resource(struct spdk_nvmf_tcp_qpair *tqpair)
918 {
919 	uint32_t i;
920 	struct spdk_nvmf_transport_opts *opts;
921 	uint32_t in_capsule_data_size;
922 
923 	opts = &tqpair->qpair.transport->opts;
924 
925 	in_capsule_data_size = opts->in_capsule_data_size;
926 	if (opts->dif_insert_or_strip) {
927 		in_capsule_data_size = SPDK_BDEV_BUF_SIZE_WITH_MD(in_capsule_data_size);
928 	}
929 
930 	tqpair->resource_count = opts->max_queue_depth;
931 
932 	tqpair->reqs = calloc(tqpair->resource_count, sizeof(*tqpair->reqs));
933 	if (!tqpair->reqs) {
934 		SPDK_ERRLOG("Unable to allocate reqs on tqpair=%p\n", tqpair);
935 		return -1;
936 	}
937 
938 	if (in_capsule_data_size) {
939 		tqpair->bufs = spdk_zmalloc(tqpair->resource_count * in_capsule_data_size, 0x1000,
940 					    NULL, SPDK_ENV_LCORE_ID_ANY,
941 					    SPDK_MALLOC_DMA);
942 		if (!tqpair->bufs) {
943 			SPDK_ERRLOG("Unable to allocate bufs on tqpair=%p.\n", tqpair);
944 			return -1;
945 		}
946 	}
947 
948 	/* Add addtional 2 members, which will be used for mgmt_pdu and pdu_in_progress owned by the tqpair */
949 	tqpair->pdus = spdk_dma_zmalloc((tqpair->resource_count + 2) * sizeof(*tqpair->pdus), 0x1000, NULL);
950 	if (!tqpair->pdus) {
951 		SPDK_ERRLOG("Unable to allocate pdu pool on tqpair =%p.\n", tqpair);
952 		return -1;
953 	}
954 
955 	for (i = 0; i < tqpair->resource_count; i++) {
956 		struct spdk_nvmf_tcp_req *tcp_req = &tqpair->reqs[i];
957 
958 		tcp_req->ttag = i + 1;
959 		tcp_req->req.qpair = &tqpair->qpair;
960 
961 		tcp_req->pdu = &tqpair->pdus[i];
962 		tcp_req->pdu->qpair = tqpair;
963 
964 		/* Set up memory to receive commands */
965 		if (tqpair->bufs) {
966 			tcp_req->buf = (void *)((uintptr_t)tqpair->bufs + (i * in_capsule_data_size));
967 		}
968 
969 		/* Set the cmdn and rsp */
970 		tcp_req->req.rsp = (union nvmf_c2h_msg *)&tcp_req->rsp;
971 		tcp_req->req.cmd = (union nvmf_h2c_msg *)&tcp_req->cmd;
972 
973 		/* Initialize request state to FREE */
974 		tcp_req->state = TCP_REQUEST_STATE_FREE;
975 		TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
976 		tqpair->state_cntr[TCP_REQUEST_STATE_FREE]++;
977 	}
978 
979 	tqpair->mgmt_pdu = &tqpair->pdus[i];
980 	tqpair->mgmt_pdu->qpair = tqpair;
981 	tqpair->pdu_in_progress = &tqpair->pdus[i + 1];
982 
983 	tqpair->recv_buf_size = (in_capsule_data_size + sizeof(struct spdk_nvme_tcp_cmd) + 2 *
984 				 SPDK_NVME_TCP_DIGEST_LEN) * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
985 
986 	return 0;
987 }
988 
989 static int
990 nvmf_tcp_qpair_init(struct spdk_nvmf_qpair *qpair)
991 {
992 	struct spdk_nvmf_tcp_qpair *tqpair;
993 
994 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
995 
996 	SPDK_DEBUGLOG(nvmf_tcp, "New TCP Connection: %p\n", qpair);
997 
998 	/* Initialise request state queues of the qpair */
999 	TAILQ_INIT(&tqpair->tcp_req_free_queue);
1000 	TAILQ_INIT(&tqpair->tcp_req_working_queue);
1001 
1002 	tqpair->host_hdgst_enable = true;
1003 	tqpair->host_ddgst_enable = true;
1004 
1005 	return 0;
1006 }
1007 
1008 static int
1009 nvmf_tcp_qpair_sock_init(struct spdk_nvmf_tcp_qpair *tqpair)
1010 {
1011 	int rc;
1012 
1013 	/* set low water mark */
1014 	rc = spdk_sock_set_recvlowat(tqpair->sock, sizeof(struct spdk_nvme_tcp_common_pdu_hdr));
1015 	if (rc != 0) {
1016 		SPDK_ERRLOG("spdk_sock_set_recvlowat() failed\n");
1017 		return rc;
1018 	}
1019 
1020 	return 0;
1021 }
1022 
1023 static void
1024 nvmf_tcp_handle_connect(struct spdk_nvmf_transport *transport,
1025 			struct spdk_nvmf_tcp_port *port,
1026 			struct spdk_sock *sock)
1027 {
1028 	struct spdk_nvmf_tcp_qpair *tqpair;
1029 	int rc;
1030 
1031 	SPDK_DEBUGLOG(nvmf_tcp, "New connection accepted on %s port %s\n",
1032 		      port->trid->traddr, port->trid->trsvcid);
1033 
1034 	tqpair = calloc(1, sizeof(struct spdk_nvmf_tcp_qpair));
1035 	if (tqpair == NULL) {
1036 		SPDK_ERRLOG("Could not allocate new connection.\n");
1037 		spdk_sock_close(&sock);
1038 		return;
1039 	}
1040 
1041 	tqpair->sock = sock;
1042 	tqpair->state_cntr[TCP_REQUEST_STATE_FREE] = 0;
1043 	tqpair->port = port;
1044 	tqpair->qpair.transport = transport;
1045 
1046 	rc = spdk_sock_getaddr(tqpair->sock, tqpair->target_addr,
1047 			       sizeof(tqpair->target_addr), &tqpair->target_port,
1048 			       tqpair->initiator_addr, sizeof(tqpair->initiator_addr),
1049 			       &tqpair->initiator_port);
1050 	if (rc < 0) {
1051 		SPDK_ERRLOG("spdk_sock_getaddr() failed of tqpair=%p\n", tqpair);
1052 		nvmf_tcp_qpair_destroy(tqpair);
1053 		return;
1054 	}
1055 
1056 	spdk_nvmf_tgt_new_qpair(transport->tgt, &tqpair->qpair);
1057 }
1058 
1059 static uint32_t
1060 nvmf_tcp_port_accept(struct spdk_nvmf_transport *transport, struct spdk_nvmf_tcp_port *port)
1061 {
1062 	struct spdk_sock *sock;
1063 	uint32_t count = 0;
1064 	int i;
1065 
1066 	for (i = 0; i < NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME; i++) {
1067 		sock = spdk_sock_accept(port->listen_sock);
1068 		if (sock == NULL) {
1069 			break;
1070 		}
1071 		count++;
1072 		nvmf_tcp_handle_connect(transport, port, sock);
1073 	}
1074 
1075 	return count;
1076 }
1077 
1078 static uint32_t
1079 nvmf_tcp_accept(struct spdk_nvmf_transport *transport)
1080 {
1081 	struct spdk_nvmf_tcp_transport *ttransport;
1082 	struct spdk_nvmf_tcp_port *port;
1083 	uint32_t count = 0;
1084 
1085 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1086 
1087 	TAILQ_FOREACH(port, &ttransport->ports, link) {
1088 		count += nvmf_tcp_port_accept(transport, port);
1089 	}
1090 
1091 	return count;
1092 }
1093 
1094 static void
1095 nvmf_tcp_discover(struct spdk_nvmf_transport *transport,
1096 		  struct spdk_nvme_transport_id *trid,
1097 		  struct spdk_nvmf_discovery_log_page_entry *entry)
1098 {
1099 	entry->trtype = SPDK_NVMF_TRTYPE_TCP;
1100 	entry->adrfam = trid->adrfam;
1101 	entry->treq.secure_channel = SPDK_NVMF_TREQ_SECURE_CHANNEL_NOT_REQUIRED;
1102 
1103 	spdk_strcpy_pad(entry->trsvcid, trid->trsvcid, sizeof(entry->trsvcid), ' ');
1104 	spdk_strcpy_pad(entry->traddr, trid->traddr, sizeof(entry->traddr), ' ');
1105 
1106 	entry->tsas.tcp.sectype = SPDK_NVME_TCP_SECURITY_NONE;
1107 }
1108 
1109 static struct spdk_nvmf_tcp_control_msg_list *
1110 nvmf_tcp_control_msg_list_create(uint16_t num_messages)
1111 {
1112 	struct spdk_nvmf_tcp_control_msg_list *list;
1113 	struct spdk_nvmf_tcp_control_msg *msg;
1114 	uint16_t i;
1115 
1116 	list = calloc(1, sizeof(*list));
1117 	if (!list) {
1118 		SPDK_ERRLOG("Failed to allocate memory for list structure\n");
1119 		return NULL;
1120 	}
1121 
1122 	list->msg_buf = spdk_zmalloc(num_messages * SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE,
1123 				     NVMF_DATA_BUFFER_ALIGNMENT, NULL, SPDK_ENV_SOCKET_ID_ANY, SPDK_MALLOC_DMA);
1124 	if (!list->msg_buf) {
1125 		SPDK_ERRLOG("Failed to allocate memory for control message buffers\n");
1126 		free(list);
1127 		return NULL;
1128 	}
1129 
1130 	STAILQ_INIT(&list->free_msgs);
1131 
1132 	for (i = 0; i < num_messages; i++) {
1133 		msg = (struct spdk_nvmf_tcp_control_msg *)((char *)list->msg_buf + i *
1134 				SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1135 		STAILQ_INSERT_TAIL(&list->free_msgs, msg, link);
1136 	}
1137 
1138 	return list;
1139 }
1140 
1141 static void
1142 nvmf_tcp_control_msg_list_free(struct spdk_nvmf_tcp_control_msg_list *list)
1143 {
1144 	if (!list) {
1145 		return;
1146 	}
1147 
1148 	spdk_free(list->msg_buf);
1149 	free(list);
1150 }
1151 
1152 static struct spdk_nvmf_transport_poll_group *
1153 nvmf_tcp_poll_group_create(struct spdk_nvmf_transport *transport)
1154 {
1155 	struct spdk_nvmf_tcp_transport	*ttransport;
1156 	struct spdk_nvmf_tcp_poll_group *tgroup;
1157 
1158 	tgroup = calloc(1, sizeof(*tgroup));
1159 	if (!tgroup) {
1160 		return NULL;
1161 	}
1162 
1163 	tgroup->sock_group = spdk_sock_group_create(&tgroup->group);
1164 	if (!tgroup->sock_group) {
1165 		goto cleanup;
1166 	}
1167 
1168 	TAILQ_INIT(&tgroup->qpairs);
1169 	TAILQ_INIT(&tgroup->await_req);
1170 
1171 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1172 
1173 	if (transport->opts.in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
1174 		SPDK_DEBUGLOG(nvmf_tcp, "ICD %u is less than min required for admin/fabric commands (%u). "
1175 			      "Creating control messages list\n", transport->opts.in_capsule_data_size,
1176 			      SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1177 		tgroup->control_msg_list = nvmf_tcp_control_msg_list_create(ttransport->tcp_opts.control_msg_num);
1178 		if (!tgroup->control_msg_list) {
1179 			goto cleanup;
1180 		}
1181 	}
1182 
1183 	tgroup->accel_channel = spdk_accel_engine_get_io_channel();
1184 	if (spdk_unlikely(!tgroup->accel_channel)) {
1185 		SPDK_ERRLOG("Cannot create accel_channel for tgroup=%p\n", tgroup);
1186 		goto cleanup;
1187 	}
1188 
1189 	return &tgroup->group;
1190 
1191 cleanup:
1192 	nvmf_tcp_poll_group_destroy(&tgroup->group);
1193 	return NULL;
1194 }
1195 
1196 static struct spdk_nvmf_transport_poll_group *
1197 nvmf_tcp_get_optimal_poll_group(struct spdk_nvmf_qpair *qpair)
1198 {
1199 	struct spdk_nvmf_tcp_qpair *tqpair;
1200 	struct spdk_sock_group *group = NULL;
1201 	int rc;
1202 
1203 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1204 	rc = spdk_sock_get_optimal_sock_group(tqpair->sock, &group);
1205 	if (!rc && group != NULL) {
1206 		return spdk_sock_group_get_ctx(group);
1207 	}
1208 
1209 	return NULL;
1210 }
1211 
1212 static void
1213 nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group)
1214 {
1215 	struct spdk_nvmf_tcp_poll_group *tgroup;
1216 
1217 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
1218 	spdk_sock_group_close(&tgroup->sock_group);
1219 	if (tgroup->control_msg_list) {
1220 		nvmf_tcp_control_msg_list_free(tgroup->control_msg_list);
1221 	}
1222 
1223 	if (tgroup->accel_channel) {
1224 		spdk_put_io_channel(tgroup->accel_channel);
1225 	}
1226 
1227 	free(tgroup);
1228 }
1229 
1230 static void
1231 nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
1232 			      enum nvme_tcp_pdu_recv_state state)
1233 {
1234 	if (tqpair->recv_state == state) {
1235 		SPDK_ERRLOG("The recv state of tqpair=%p is same with the state(%d) to be set\n",
1236 			    tqpair, state);
1237 		return;
1238 	}
1239 
1240 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
1241 		/* When leaving the await req state, move the qpair to the main list */
1242 		TAILQ_REMOVE(&tqpair->group->await_req, tqpair, link);
1243 		TAILQ_INSERT_TAIL(&tqpair->group->qpairs, tqpair, link);
1244 	}
1245 
1246 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv state=%d\n", tqpair, state);
1247 	tqpair->recv_state = state;
1248 
1249 	switch (state) {
1250 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
1251 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
1252 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
1253 		break;
1254 	case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
1255 		TAILQ_REMOVE(&tqpair->group->qpairs, tqpair, link);
1256 		TAILQ_INSERT_TAIL(&tqpair->group->await_req, tqpair, link);
1257 		break;
1258 	case NVME_TCP_PDU_RECV_STATE_ERROR:
1259 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1260 		memset(tqpair->pdu_in_progress, 0, sizeof(*(tqpair->pdu_in_progress)));
1261 		break;
1262 	default:
1263 		SPDK_ERRLOG("The state(%d) is invalid\n", state);
1264 		abort();
1265 		break;
1266 	}
1267 }
1268 
1269 static int
1270 nvmf_tcp_qpair_handle_timeout(void *ctx)
1271 {
1272 	struct spdk_nvmf_tcp_qpair *tqpair = ctx;
1273 
1274 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_ERROR);
1275 
1276 	SPDK_ERRLOG("No pdu coming for tqpair=%p within %d seconds\n", tqpair,
1277 		    SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT);
1278 
1279 	nvmf_tcp_qpair_disconnect(tqpair);
1280 	return SPDK_POLLER_BUSY;
1281 }
1282 
1283 static void
1284 nvmf_tcp_send_c2h_term_req_complete(void *cb_arg)
1285 {
1286 	struct spdk_nvmf_tcp_qpair *tqpair = (struct spdk_nvmf_tcp_qpair *)cb_arg;
1287 
1288 	if (!tqpair->timeout_poller) {
1289 		tqpair->timeout_poller = SPDK_POLLER_REGISTER(nvmf_tcp_qpair_handle_timeout, tqpair,
1290 					 SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT * 1000000);
1291 	}
1292 }
1293 
1294 static void
1295 nvmf_tcp_send_c2h_term_req(struct spdk_nvmf_tcp_qpair *tqpair, struct nvme_tcp_pdu *pdu,
1296 			   enum spdk_nvme_tcp_term_req_fes fes, uint32_t error_offset)
1297 {
1298 	struct nvme_tcp_pdu *rsp_pdu;
1299 	struct spdk_nvme_tcp_term_req_hdr *c2h_term_req;
1300 	uint32_t c2h_term_req_hdr_len = sizeof(*c2h_term_req);
1301 	uint32_t copy_len;
1302 
1303 	rsp_pdu = tqpair->mgmt_pdu;
1304 
1305 	c2h_term_req = &rsp_pdu->hdr.term_req;
1306 	c2h_term_req->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ;
1307 	c2h_term_req->common.hlen = c2h_term_req_hdr_len;
1308 
1309 	if ((fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1310 	    (fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1311 		DSET32(&c2h_term_req->fei, error_offset);
1312 	}
1313 
1314 	copy_len = spdk_min(pdu->hdr.common.hlen, SPDK_NVME_TCP_TERM_REQ_ERROR_DATA_MAX_SIZE);
1315 
1316 	/* Copy the error info into the buffer */
1317 	memcpy((uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, pdu->hdr.raw, copy_len);
1318 	nvme_tcp_pdu_set_data(rsp_pdu, (uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, copy_len);
1319 
1320 	/* Contain the header of the wrong received pdu */
1321 	c2h_term_req->common.plen = c2h_term_req->common.hlen + copy_len;
1322 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1323 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_c2h_term_req_complete, tqpair);
1324 }
1325 
1326 static void
1327 nvmf_tcp_capsule_cmd_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1328 				struct spdk_nvmf_tcp_qpair *tqpair,
1329 				struct nvme_tcp_pdu *pdu)
1330 {
1331 	struct spdk_nvmf_tcp_req *tcp_req;
1332 
1333 	assert(pdu->psh_valid_bytes == pdu->psh_len);
1334 	assert(pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD);
1335 
1336 	tcp_req = nvmf_tcp_req_get(tqpair);
1337 	if (!tcp_req) {
1338 		/* Directly return and make the allocation retry again */
1339 		if (tqpair->state_cntr[TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST] > 0) {
1340 			return;
1341 		}
1342 
1343 		/* The host sent more commands than the maximum queue depth. */
1344 		SPDK_ERRLOG("Cannot allocate tcp_req on tqpair=%p\n", tqpair);
1345 		nvmf_tcp_qpair_disconnect(tqpair);
1346 		return;
1347 	}
1348 
1349 	pdu->req = tcp_req;
1350 	assert(tcp_req->state == TCP_REQUEST_STATE_NEW);
1351 	nvmf_tcp_req_process(ttransport, tcp_req);
1352 }
1353 
1354 static void
1355 nvmf_tcp_capsule_cmd_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1356 				    struct spdk_nvmf_tcp_qpair *tqpair,
1357 				    struct nvme_tcp_pdu *pdu)
1358 {
1359 	struct spdk_nvmf_tcp_req *tcp_req;
1360 	struct spdk_nvme_tcp_cmd *capsule_cmd;
1361 	uint32_t error_offset = 0;
1362 	enum spdk_nvme_tcp_term_req_fes fes;
1363 	struct spdk_nvme_cpl *rsp;
1364 
1365 	capsule_cmd = &pdu->hdr.capsule_cmd;
1366 	tcp_req = pdu->req;
1367 	assert(tcp_req != NULL);
1368 
1369 	if (capsule_cmd->common.pdo > SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET) {
1370 		SPDK_ERRLOG("Expected ICReq capsule_cmd pdu offset <= %d, got %c\n",
1371 			    SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET, capsule_cmd->common.pdo);
1372 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1373 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1374 		goto err;
1375 	}
1376 
1377 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1378 
1379 	rsp = &tcp_req->req.rsp->nvme_cpl;
1380 	if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1381 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1382 	} else {
1383 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1384 	}
1385 
1386 	nvmf_tcp_req_process(ttransport, tcp_req);
1387 
1388 	return;
1389 err:
1390 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1391 }
1392 
1393 static int
1394 nvmf_tcp_find_req_in_state(struct spdk_nvmf_tcp_qpair *tqpair,
1395 			   enum spdk_nvmf_tcp_req_state state,
1396 			   uint16_t cid, uint16_t tag,
1397 			   struct spdk_nvmf_tcp_req **req)
1398 {
1399 	struct spdk_nvmf_tcp_req *tcp_req = NULL;
1400 
1401 	TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
1402 		if (tcp_req->state != state) {
1403 			continue;
1404 		}
1405 
1406 		if (tcp_req->req.cmd->nvme_cmd.cid != cid) {
1407 			continue;
1408 		}
1409 
1410 		if (tcp_req->ttag == tag) {
1411 			*req = tcp_req;
1412 			return 0;
1413 		}
1414 
1415 		*req = NULL;
1416 		return -1;
1417 	}
1418 
1419 	/* Didn't find it, but not an error */
1420 	*req = NULL;
1421 	return 0;
1422 }
1423 
1424 static void
1425 nvmf_tcp_h2c_data_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1426 			     struct spdk_nvmf_tcp_qpair *tqpair,
1427 			     struct nvme_tcp_pdu *pdu)
1428 {
1429 	struct spdk_nvmf_tcp_req *tcp_req;
1430 	uint32_t error_offset = 0;
1431 	enum spdk_nvme_tcp_term_req_fes fes = 0;
1432 	struct spdk_nvme_tcp_h2c_data_hdr *h2c_data;
1433 	int rc;
1434 
1435 	h2c_data = &pdu->hdr.h2c_data;
1436 
1437 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair=%p, r2t_info: datao=%u, datal=%u, cccid=%u, ttag=%u\n",
1438 		      tqpair, h2c_data->datao, h2c_data->datal, h2c_data->cccid, h2c_data->ttag);
1439 
1440 	rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
1441 					h2c_data->cccid, h2c_data->ttag, &tcp_req);
1442 	if (rc == 0 && tcp_req == NULL) {
1443 		rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK, h2c_data->cccid,
1444 						h2c_data->ttag, &tcp_req);
1445 	}
1446 
1447 	if (!tcp_req) {
1448 		SPDK_DEBUGLOG(nvmf_tcp, "tcp_req is not found for tqpair=%p\n", tqpair);
1449 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER;
1450 		if (rc == 0) {
1451 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, cccid);
1452 		} else {
1453 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, ttag);
1454 		}
1455 		goto err;
1456 	}
1457 
1458 	if (tcp_req->h2c_offset != h2c_data->datao) {
1459 		SPDK_DEBUGLOG(nvmf_tcp,
1460 			      "tcp_req(%p), tqpair=%p, expected data offset %u, but data offset is %u\n",
1461 			      tcp_req, tqpair, tcp_req->h2c_offset, h2c_data->datao);
1462 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1463 		goto err;
1464 	}
1465 
1466 	if ((h2c_data->datao + h2c_data->datal) > tcp_req->req.length) {
1467 		SPDK_DEBUGLOG(nvmf_tcp,
1468 			      "tcp_req(%p), tqpair=%p,  (datao=%u + datal=%u) execeeds requested length=%u\n",
1469 			      tcp_req, tqpair, h2c_data->datao, h2c_data->datal, tcp_req->req.length);
1470 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1471 		goto err;
1472 	}
1473 
1474 	pdu->req = tcp_req;
1475 
1476 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
1477 		pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
1478 	}
1479 
1480 	nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
1481 				  h2c_data->datao, h2c_data->datal);
1482 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1483 	return;
1484 
1485 err:
1486 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1487 }
1488 
1489 static void
1490 nvmf_tcp_send_capsule_resp_pdu(struct spdk_nvmf_tcp_req *tcp_req,
1491 			       struct spdk_nvmf_tcp_qpair *tqpair)
1492 {
1493 	struct nvme_tcp_pdu *rsp_pdu;
1494 	struct spdk_nvme_tcp_rsp *capsule_resp;
1495 
1496 	SPDK_DEBUGLOG(nvmf_tcp, "enter, tqpair=%p\n", tqpair);
1497 
1498 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1499 	assert(rsp_pdu != NULL);
1500 
1501 	capsule_resp = &rsp_pdu->hdr.capsule_resp;
1502 	capsule_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_CAPSULE_RESP;
1503 	capsule_resp->common.plen = capsule_resp->common.hlen = sizeof(*capsule_resp);
1504 	capsule_resp->rccqe = tcp_req->req.rsp->nvme_cpl;
1505 	if (tqpair->host_hdgst_enable) {
1506 		capsule_resp->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1507 		capsule_resp->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1508 	}
1509 
1510 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_request_free, tcp_req);
1511 }
1512 
1513 static void
1514 nvmf_tcp_pdu_c2h_data_complete(void *cb_arg)
1515 {
1516 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1517 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair,
1518 					     struct spdk_nvmf_tcp_qpair, qpair);
1519 
1520 	assert(tqpair != NULL);
1521 
1522 	if (spdk_unlikely(tcp_req->pdu->rw_offset < tcp_req->req.length)) {
1523 		SPDK_DEBUGLOG(nvmf_tcp, "sending another C2H part, offset %u length %u\n", tcp_req->pdu->rw_offset,
1524 			      tcp_req->req.length);
1525 		_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
1526 		return;
1527 	}
1528 
1529 	if (tcp_req->pdu->hdr.c2h_data.common.flags & SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS) {
1530 		nvmf_tcp_request_free(tcp_req);
1531 	} else {
1532 		nvmf_tcp_req_pdu_fini(tcp_req);
1533 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
1534 	}
1535 }
1536 
1537 static void
1538 nvmf_tcp_r2t_complete(void *cb_arg)
1539 {
1540 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1541 	struct spdk_nvmf_tcp_transport *ttransport;
1542 
1543 	nvmf_tcp_req_pdu_fini(tcp_req);
1544 
1545 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
1546 				      struct spdk_nvmf_tcp_transport, transport);
1547 
1548 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
1549 
1550 	if (tcp_req->h2c_offset == tcp_req->req.length) {
1551 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1552 		nvmf_tcp_req_process(ttransport, tcp_req);
1553 	}
1554 }
1555 
1556 static void
1557 nvmf_tcp_send_r2t_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
1558 		      struct spdk_nvmf_tcp_req *tcp_req)
1559 {
1560 	struct nvme_tcp_pdu *rsp_pdu;
1561 	struct spdk_nvme_tcp_r2t_hdr *r2t;
1562 
1563 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1564 	assert(rsp_pdu != NULL);
1565 
1566 	r2t = &rsp_pdu->hdr.r2t;
1567 	r2t->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_R2T;
1568 	r2t->common.plen = r2t->common.hlen = sizeof(*r2t);
1569 
1570 	if (tqpair->host_hdgst_enable) {
1571 		r2t->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1572 		r2t->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1573 	}
1574 
1575 	r2t->cccid = tcp_req->req.cmd->nvme_cmd.cid;
1576 	r2t->ttag = tcp_req->ttag;
1577 	r2t->r2to = tcp_req->h2c_offset;
1578 	r2t->r2tl = tcp_req->req.length;
1579 
1580 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
1581 
1582 	SPDK_DEBUGLOG(nvmf_tcp,
1583 		      "tcp_req(%p) on tqpair(%p), r2t_info: cccid=%u, ttag=%u, r2to=%u, r2tl=%u\n",
1584 		      tcp_req, tqpair, r2t->cccid, r2t->ttag, r2t->r2to, r2t->r2tl);
1585 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_r2t_complete, tcp_req);
1586 }
1587 
1588 static void
1589 nvmf_tcp_h2c_data_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1590 				 struct spdk_nvmf_tcp_qpair *tqpair,
1591 				 struct nvme_tcp_pdu *pdu)
1592 {
1593 	struct spdk_nvmf_tcp_req *tcp_req;
1594 	struct spdk_nvme_cpl *rsp;
1595 
1596 	tcp_req = pdu->req;
1597 	assert(tcp_req != NULL);
1598 
1599 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1600 
1601 	tcp_req->h2c_offset += pdu->data_len;
1602 
1603 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1604 
1605 	/* Wait for all of the data to arrive AND for the initial R2T PDU send to be
1606 	 * acknowledged before moving on. */
1607 	if (tcp_req->h2c_offset == tcp_req->req.length &&
1608 	    tcp_req->state == TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER) {
1609 		/* After receving all the h2c data, we need to check whether there is
1610 		 * transient transport error */
1611 		rsp = &tcp_req->req.rsp->nvme_cpl;
1612 		if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1613 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1614 		} else {
1615 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1616 		}
1617 		nvmf_tcp_req_process(ttransport, tcp_req);
1618 	}
1619 }
1620 
1621 static void
1622 nvmf_tcp_h2c_term_req_dump(struct spdk_nvme_tcp_term_req_hdr *h2c_term_req)
1623 {
1624 	SPDK_ERRLOG("Error info of pdu(%p): %s\n", h2c_term_req,
1625 		    spdk_nvmf_tcp_term_req_fes_str[h2c_term_req->fes]);
1626 	if ((h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1627 	    (h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1628 		SPDK_DEBUGLOG(nvmf_tcp, "The offset from the start of the PDU header is %u\n",
1629 			      DGET32(h2c_term_req->fei));
1630 	}
1631 }
1632 
1633 static void
1634 nvmf_tcp_h2c_term_req_hdr_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1635 				 struct nvme_tcp_pdu *pdu)
1636 {
1637 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1638 	uint32_t error_offset = 0;
1639 	enum spdk_nvme_tcp_term_req_fes fes;
1640 
1641 	if (h2c_term_req->fes > SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER) {
1642 		SPDK_ERRLOG("Fatal Error Status(FES) is unknown for h2c_term_req pdu=%p\n", pdu);
1643 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1644 		error_offset = offsetof(struct spdk_nvme_tcp_term_req_hdr, fes);
1645 		goto end;
1646 	}
1647 
1648 	/* set the data buffer */
1649 	nvme_tcp_pdu_set_data(pdu, (uint8_t *)pdu->hdr.raw + h2c_term_req->common.hlen,
1650 			      h2c_term_req->common.plen - h2c_term_req->common.hlen);
1651 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1652 	return;
1653 end:
1654 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1655 }
1656 
1657 static void
1658 nvmf_tcp_h2c_term_req_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1659 				     struct nvme_tcp_pdu *pdu)
1660 {
1661 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1662 
1663 	nvmf_tcp_h2c_term_req_dump(h2c_term_req);
1664 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1665 }
1666 
1667 static void
1668 _nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1669 			     struct spdk_nvmf_tcp_transport *ttransport)
1670 {
1671 	struct nvme_tcp_pdu *pdu = tqpair->pdu_in_progress;
1672 
1673 	switch (pdu->hdr.common.pdu_type) {
1674 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1675 		nvmf_tcp_capsule_cmd_payload_handle(ttransport, tqpair, pdu);
1676 		break;
1677 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1678 		nvmf_tcp_h2c_data_payload_handle(ttransport, tqpair, pdu);
1679 		break;
1680 
1681 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1682 		nvmf_tcp_h2c_term_req_payload_handle(tqpair, pdu);
1683 		break;
1684 
1685 	default:
1686 		/* The code should not go to here */
1687 		SPDK_ERRLOG("The code should not go to here\n");
1688 		break;
1689 	}
1690 }
1691 
1692 static void
1693 nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1694 			    struct spdk_nvmf_tcp_transport *ttransport)
1695 {
1696 	int rc = 0;
1697 	struct nvme_tcp_pdu *pdu;
1698 	uint32_t crc32c;
1699 	struct spdk_nvmf_tcp_req *tcp_req;
1700 	struct spdk_nvme_cpl *rsp;
1701 
1702 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1703 	pdu = tqpair->pdu_in_progress;
1704 
1705 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1706 	/* check data digest if need */
1707 	if (pdu->ddgst_enable) {
1708 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
1709 		rc = MATCH_DIGEST_WORD(pdu->data_digest, crc32c);
1710 		if (rc == 0) {
1711 			SPDK_ERRLOG("Data digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1712 			tcp_req = pdu->req;
1713 			assert(tcp_req != NULL);
1714 			rsp = &tcp_req->req.rsp->nvme_cpl;
1715 			rsp->status.sc = SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR;
1716 		}
1717 	}
1718 
1719 	_nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
1720 }
1721 
1722 static void
1723 nvmf_tcp_send_icresp_complete(void *cb_arg)
1724 {
1725 	struct spdk_nvmf_tcp_qpair *tqpair = cb_arg;
1726 
1727 	tqpair->state = NVME_TCP_QPAIR_STATE_RUNNING;
1728 }
1729 
1730 static void
1731 nvmf_tcp_icreq_handle(struct spdk_nvmf_tcp_transport *ttransport,
1732 		      struct spdk_nvmf_tcp_qpair *tqpair,
1733 		      struct nvme_tcp_pdu *pdu)
1734 {
1735 	struct spdk_nvme_tcp_ic_req *ic_req = &pdu->hdr.ic_req;
1736 	struct nvme_tcp_pdu *rsp_pdu;
1737 	struct spdk_nvme_tcp_ic_resp *ic_resp;
1738 	uint32_t error_offset = 0;
1739 	enum spdk_nvme_tcp_term_req_fes fes;
1740 
1741 	/* Only PFV 0 is defined currently */
1742 	if (ic_req->pfv != 0) {
1743 		SPDK_ERRLOG("Expected ICReq PFV %u, got %u\n", 0u, ic_req->pfv);
1744 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1745 		error_offset = offsetof(struct spdk_nvme_tcp_ic_req, pfv);
1746 		goto end;
1747 	}
1748 
1749 	/* MAXR2T is 0's based */
1750 	SPDK_DEBUGLOG(nvmf_tcp, "maxr2t =%u\n", (ic_req->maxr2t + 1u));
1751 
1752 	tqpair->host_hdgst_enable = ic_req->dgst.bits.hdgst_enable ? true : false;
1753 	if (!tqpair->host_hdgst_enable) {
1754 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1755 	}
1756 
1757 	tqpair->host_ddgst_enable = ic_req->dgst.bits.ddgst_enable ? true : false;
1758 	if (!tqpair->host_ddgst_enable) {
1759 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1760 	}
1761 
1762 	tqpair->recv_buf_size = spdk_max(tqpair->recv_buf_size, MIN_SOCK_PIPE_SIZE);
1763 	/* Now that we know whether digests are enabled, properly size the receive buffer */
1764 	if (spdk_sock_set_recvbuf(tqpair->sock, tqpair->recv_buf_size) < 0) {
1765 		SPDK_WARNLOG("Unable to allocate enough memory for receive buffer on tqpair=%p with size=%d\n",
1766 			     tqpair,
1767 			     tqpair->recv_buf_size);
1768 		/* Not fatal. */
1769 	}
1770 
1771 	tqpair->cpda = spdk_min(ic_req->hpda, SPDK_NVME_TCP_CPDA_MAX);
1772 	SPDK_DEBUGLOG(nvmf_tcp, "cpda of tqpair=(%p) is : %u\n", tqpair, tqpair->cpda);
1773 
1774 	rsp_pdu = tqpair->mgmt_pdu;
1775 
1776 	ic_resp = &rsp_pdu->hdr.ic_resp;
1777 	ic_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_IC_RESP;
1778 	ic_resp->common.hlen = ic_resp->common.plen =  sizeof(*ic_resp);
1779 	ic_resp->pfv = 0;
1780 	ic_resp->cpda = tqpair->cpda;
1781 	ic_resp->maxh2cdata = ttransport->transport.opts.max_io_size;
1782 	ic_resp->dgst.bits.hdgst_enable = tqpair->host_hdgst_enable ? 1 : 0;
1783 	ic_resp->dgst.bits.ddgst_enable = tqpair->host_ddgst_enable ? 1 : 0;
1784 
1785 	SPDK_DEBUGLOG(nvmf_tcp, "host_hdgst_enable: %u\n", tqpair->host_hdgst_enable);
1786 	SPDK_DEBUGLOG(nvmf_tcp, "host_ddgst_enable: %u\n", tqpair->host_ddgst_enable);
1787 
1788 	tqpair->state = NVME_TCP_QPAIR_STATE_INITIALIZING;
1789 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_icresp_complete, tqpair);
1790 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1791 	return;
1792 end:
1793 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1794 }
1795 
1796 static void
1797 nvmf_tcp_pdu_psh_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1798 			struct spdk_nvmf_tcp_transport *ttransport)
1799 {
1800 	struct nvme_tcp_pdu *pdu;
1801 	int rc;
1802 	uint32_t crc32c, error_offset = 0;
1803 	enum spdk_nvme_tcp_term_req_fes fes;
1804 
1805 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1806 	pdu = tqpair->pdu_in_progress;
1807 
1808 	SPDK_DEBUGLOG(nvmf_tcp, "pdu type of tqpair(%p) is %d\n", tqpair,
1809 		      pdu->hdr.common.pdu_type);
1810 	/* check header digest if needed */
1811 	if (pdu->has_hdgst) {
1812 		SPDK_DEBUGLOG(nvmf_tcp, "Compare the header of pdu=%p on tqpair=%p\n", pdu, tqpair);
1813 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
1814 		rc = MATCH_DIGEST_WORD((uint8_t *)pdu->hdr.raw + pdu->hdr.common.hlen, crc32c);
1815 		if (rc == 0) {
1816 			SPDK_ERRLOG("Header digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1817 			fes = SPDK_NVME_TCP_TERM_REQ_FES_HDGST_ERROR;
1818 			nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1819 			return;
1820 
1821 		}
1822 	}
1823 
1824 	switch (pdu->hdr.common.pdu_type) {
1825 	case SPDK_NVME_TCP_PDU_TYPE_IC_REQ:
1826 		nvmf_tcp_icreq_handle(ttransport, tqpair, pdu);
1827 		break;
1828 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1829 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_REQ);
1830 		break;
1831 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1832 		nvmf_tcp_h2c_data_hdr_handle(ttransport, tqpair, pdu);
1833 		break;
1834 
1835 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1836 		nvmf_tcp_h2c_term_req_hdr_handle(tqpair, pdu);
1837 		break;
1838 
1839 	default:
1840 		SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", tqpair->pdu_in_progress->hdr.common.pdu_type);
1841 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1842 		error_offset = 1;
1843 		nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1844 		break;
1845 	}
1846 }
1847 
1848 static void
1849 nvmf_tcp_pdu_ch_handle(struct spdk_nvmf_tcp_qpair *tqpair)
1850 {
1851 	struct nvme_tcp_pdu *pdu;
1852 	uint32_t error_offset = 0;
1853 	enum spdk_nvme_tcp_term_req_fes fes;
1854 	uint8_t expected_hlen, pdo;
1855 	bool plen_error = false, pdo_error = false;
1856 
1857 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
1858 	pdu = tqpair->pdu_in_progress;
1859 
1860 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_REQ) {
1861 		if (tqpair->state != NVME_TCP_QPAIR_STATE_INVALID) {
1862 			SPDK_ERRLOG("Already received ICreq PDU, and reject this pdu=%p\n", pdu);
1863 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1864 			goto err;
1865 		}
1866 		expected_hlen = sizeof(struct spdk_nvme_tcp_ic_req);
1867 		if (pdu->hdr.common.plen != expected_hlen) {
1868 			plen_error = true;
1869 		}
1870 	} else {
1871 		if (tqpair->state != NVME_TCP_QPAIR_STATE_RUNNING) {
1872 			SPDK_ERRLOG("The TCP/IP connection is not negotitated\n");
1873 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1874 			goto err;
1875 		}
1876 
1877 		switch (pdu->hdr.common.pdu_type) {
1878 		case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1879 			expected_hlen = sizeof(struct spdk_nvme_tcp_cmd);
1880 			pdo = pdu->hdr.common.pdo;
1881 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1882 				pdo_error = true;
1883 				break;
1884 			}
1885 
1886 			if (pdu->hdr.common.plen < expected_hlen) {
1887 				plen_error = true;
1888 			}
1889 			break;
1890 		case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1891 			expected_hlen = sizeof(struct spdk_nvme_tcp_h2c_data_hdr);
1892 			pdo = pdu->hdr.common.pdo;
1893 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
1894 				pdo_error = true;
1895 				break;
1896 			}
1897 			if (pdu->hdr.common.plen < expected_hlen) {
1898 				plen_error = true;
1899 			}
1900 			break;
1901 
1902 		case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1903 			expected_hlen = sizeof(struct spdk_nvme_tcp_term_req_hdr);
1904 			if ((pdu->hdr.common.plen <= expected_hlen) ||
1905 			    (pdu->hdr.common.plen > SPDK_NVME_TCP_TERM_REQ_PDU_MAX_SIZE)) {
1906 				plen_error = true;
1907 			}
1908 			break;
1909 
1910 		default:
1911 			SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", pdu->hdr.common.pdu_type);
1912 			fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1913 			error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdu_type);
1914 			goto err;
1915 		}
1916 	}
1917 
1918 	if (pdu->hdr.common.hlen != expected_hlen) {
1919 		SPDK_ERRLOG("PDU type=0x%02x, Expected ICReq header length %u, got %u on tqpair=%p\n",
1920 			    pdu->hdr.common.pdu_type,
1921 			    expected_hlen, pdu->hdr.common.hlen, tqpair);
1922 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1923 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, hlen);
1924 		goto err;
1925 	} else if (pdo_error) {
1926 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1927 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1928 	} else if (plen_error) {
1929 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1930 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, plen);
1931 		goto err;
1932 	} else {
1933 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1934 		nvme_tcp_pdu_calc_psh_len(tqpair->pdu_in_progress, tqpair->host_hdgst_enable);
1935 		return;
1936 	}
1937 err:
1938 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1939 }
1940 
1941 static int
1942 nvmf_tcp_pdu_payload_insert_dif(struct nvme_tcp_pdu *pdu, uint32_t read_offset,
1943 				int read_len)
1944 {
1945 	int rc;
1946 
1947 	rc = spdk_dif_generate_stream(pdu->data_iov, pdu->data_iovcnt,
1948 				      read_offset, read_len, pdu->dif_ctx);
1949 	if (rc != 0) {
1950 		SPDK_ERRLOG("DIF generate failed\n");
1951 	}
1952 
1953 	return rc;
1954 }
1955 
1956 static int
1957 nvmf_tcp_sock_process(struct spdk_nvmf_tcp_qpair *tqpair)
1958 {
1959 	int rc = 0;
1960 	struct nvme_tcp_pdu *pdu;
1961 	enum nvme_tcp_pdu_recv_state prev_state;
1962 	uint32_t data_len;
1963 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(tqpair->qpair.transport,
1964 			struct spdk_nvmf_tcp_transport, transport);
1965 
1966 	/* The loop here is to allow for several back-to-back state changes. */
1967 	do {
1968 		prev_state = tqpair->recv_state;
1969 		SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv pdu entering state %d\n", tqpair, prev_state);
1970 
1971 		pdu = tqpair->pdu_in_progress;
1972 		switch (tqpair->recv_state) {
1973 		/* Wait for the common header  */
1974 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1975 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
1976 			if (spdk_unlikely(tqpair->state == NVME_TCP_QPAIR_STATE_INITIALIZING)) {
1977 				return rc;
1978 			}
1979 
1980 			rc = nvme_tcp_read_data(tqpair->sock,
1981 						sizeof(struct spdk_nvme_tcp_common_pdu_hdr) - pdu->ch_valid_bytes,
1982 						(void *)&pdu->hdr.common + pdu->ch_valid_bytes);
1983 			if (rc < 0) {
1984 				SPDK_DEBUGLOG(nvmf_tcp, "will disconnect tqpair=%p\n", tqpair);
1985 				return NVME_TCP_PDU_FATAL;
1986 			} else if (rc > 0) {
1987 				pdu->ch_valid_bytes += rc;
1988 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0);
1989 				if (spdk_likely(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY)) {
1990 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
1991 				}
1992 			}
1993 
1994 			if (pdu->ch_valid_bytes < sizeof(struct spdk_nvme_tcp_common_pdu_hdr)) {
1995 				return NVME_TCP_PDU_IN_PROGRESS;
1996 			}
1997 
1998 			/* The command header of this PDU has now been read from the socket. */
1999 			nvmf_tcp_pdu_ch_handle(tqpair);
2000 			break;
2001 		/* Wait for the pdu specific header  */
2002 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
2003 			rc = nvme_tcp_read_data(tqpair->sock,
2004 						pdu->psh_len - pdu->psh_valid_bytes,
2005 						(void *)&pdu->hdr.raw + sizeof(struct spdk_nvme_tcp_common_pdu_hdr) + pdu->psh_valid_bytes);
2006 			if (rc < 0) {
2007 				return NVME_TCP_PDU_FATAL;
2008 			} else if (rc > 0) {
2009 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0);
2010 				pdu->psh_valid_bytes += rc;
2011 			}
2012 
2013 			if (pdu->psh_valid_bytes < pdu->psh_len) {
2014 				return NVME_TCP_PDU_IN_PROGRESS;
2015 			}
2016 
2017 			/* All header(ch, psh, head digist) of this PDU has now been read from the socket. */
2018 			nvmf_tcp_pdu_psh_handle(tqpair, ttransport);
2019 			break;
2020 		/* Wait for the req slot */
2021 		case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
2022 			nvmf_tcp_capsule_cmd_hdr_handle(ttransport, tqpair, pdu);
2023 			break;
2024 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
2025 			/* check whether the data is valid, if not we just return */
2026 			if (!pdu->data_len) {
2027 				return NVME_TCP_PDU_IN_PROGRESS;
2028 			}
2029 
2030 			data_len = pdu->data_len;
2031 			/* data digest */
2032 			if (spdk_unlikely((pdu->hdr.common.pdu_type != SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ) &&
2033 					  tqpair->host_ddgst_enable)) {
2034 				data_len += SPDK_NVME_TCP_DIGEST_LEN;
2035 				pdu->ddgst_enable = true;
2036 			}
2037 
2038 			rc = nvme_tcp_read_payload_data(tqpair->sock, pdu);
2039 			if (rc < 0) {
2040 				return NVME_TCP_PDU_FATAL;
2041 			}
2042 			pdu->rw_offset += rc;
2043 
2044 			if (spdk_unlikely(pdu->dif_ctx != NULL)) {
2045 				rc = nvmf_tcp_pdu_payload_insert_dif(pdu, pdu->rw_offset - rc, rc);
2046 				if (rc != 0) {
2047 					return NVME_TCP_PDU_FATAL;
2048 				}
2049 			}
2050 
2051 			if (pdu->rw_offset < data_len) {
2052 				return NVME_TCP_PDU_IN_PROGRESS;
2053 			}
2054 
2055 			/* All of this PDU has now been read from the socket. */
2056 			nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
2057 			break;
2058 		case NVME_TCP_PDU_RECV_STATE_ERROR:
2059 			if (!spdk_sock_is_connected(tqpair->sock)) {
2060 				return NVME_TCP_PDU_FATAL;
2061 			}
2062 			break;
2063 		default:
2064 			assert(0);
2065 			SPDK_ERRLOG("code should not come to here");
2066 			break;
2067 		}
2068 	} while (tqpair->recv_state != prev_state);
2069 
2070 	return rc;
2071 }
2072 
2073 static inline void *
2074 nvmf_tcp_control_msg_get(struct spdk_nvmf_tcp_control_msg_list *list)
2075 {
2076 	struct spdk_nvmf_tcp_control_msg *msg;
2077 
2078 	assert(list);
2079 
2080 	msg = STAILQ_FIRST(&list->free_msgs);
2081 	if (!msg) {
2082 		SPDK_DEBUGLOG(nvmf_tcp, "Out of control messages\n");
2083 		return NULL;
2084 	}
2085 	STAILQ_REMOVE_HEAD(&list->free_msgs, link);
2086 	return msg;
2087 }
2088 
2089 static inline void
2090 nvmf_tcp_control_msg_put(struct spdk_nvmf_tcp_control_msg_list *list, void *_msg)
2091 {
2092 	struct spdk_nvmf_tcp_control_msg *msg = _msg;
2093 
2094 	assert(list);
2095 	STAILQ_INSERT_HEAD(&list->free_msgs, msg, link);
2096 }
2097 
2098 static int
2099 nvmf_tcp_req_parse_sgl(struct spdk_nvmf_tcp_req *tcp_req,
2100 		       struct spdk_nvmf_transport *transport,
2101 		       struct spdk_nvmf_transport_poll_group *group)
2102 {
2103 	struct spdk_nvmf_request		*req = &tcp_req->req;
2104 	struct spdk_nvme_cmd			*cmd;
2105 	struct spdk_nvme_cpl			*rsp;
2106 	struct spdk_nvme_sgl_descriptor		*sgl;
2107 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2108 	uint32_t				length;
2109 
2110 	cmd = &req->cmd->nvme_cmd;
2111 	rsp = &req->rsp->nvme_cpl;
2112 	sgl = &cmd->dptr.sgl1;
2113 
2114 	length = sgl->unkeyed.length;
2115 
2116 	if (sgl->generic.type == SPDK_NVME_SGL_TYPE_TRANSPORT_DATA_BLOCK &&
2117 	    sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_TRANSPORT) {
2118 		if (length > transport->opts.max_io_size) {
2119 			SPDK_ERRLOG("SGL length 0x%x exceeds max io size 0x%x\n",
2120 				    length, transport->opts.max_io_size);
2121 			rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2122 			return -1;
2123 		}
2124 
2125 		/* fill request length and populate iovs */
2126 		req->length = length;
2127 
2128 		SPDK_DEBUGLOG(nvmf_tcp, "Data requested length= 0x%x\n", length);
2129 
2130 		if (spdk_unlikely(req->dif_enabled)) {
2131 			req->dif.orig_length = length;
2132 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2133 			req->dif.elba_length = length;
2134 		}
2135 
2136 		if (spdk_nvmf_request_get_buffers(req, group, transport, length)) {
2137 			/* No available buffers. Queue this request up. */
2138 			SPDK_DEBUGLOG(nvmf_tcp, "No available large data buffers. Queueing request %p\n",
2139 				      tcp_req);
2140 			return 0;
2141 		}
2142 
2143 		/* backward compatible */
2144 		req->data = req->iov[0].iov_base;
2145 
2146 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p took %d buffer/s from central pool, and data=%p\n",
2147 			      tcp_req, req->iovcnt, req->data);
2148 
2149 		return 0;
2150 	} else if (sgl->generic.type == SPDK_NVME_SGL_TYPE_DATA_BLOCK &&
2151 		   sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_OFFSET) {
2152 		uint64_t offset = sgl->address;
2153 		uint32_t max_len = transport->opts.in_capsule_data_size;
2154 		assert(tcp_req->has_incapsule_data);
2155 
2156 		SPDK_DEBUGLOG(nvmf_tcp, "In-capsule data: offset 0x%" PRIx64 ", length 0x%x\n",
2157 			      offset, length);
2158 
2159 		if (offset > max_len) {
2160 			SPDK_ERRLOG("In-capsule offset 0x%" PRIx64 " exceeds capsule length 0x%x\n",
2161 				    offset, max_len);
2162 			rsp->status.sc = SPDK_NVME_SC_INVALID_SGL_OFFSET;
2163 			return -1;
2164 		}
2165 		max_len -= (uint32_t)offset;
2166 
2167 		if (spdk_unlikely(length > max_len)) {
2168 			/* According to the SPEC we should support ICD up to 8192 bytes for admin and fabric commands */
2169 			if (length <= SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE &&
2170 			    (cmd->opc == SPDK_NVME_OPC_FABRIC || req->qpair->qid == 0)) {
2171 
2172 				/* Get a buffer from dedicated list */
2173 				SPDK_DEBUGLOG(nvmf_tcp, "Getting a buffer from control msg list\n");
2174 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2175 				assert(tgroup->control_msg_list);
2176 				req->data = nvmf_tcp_control_msg_get(tgroup->control_msg_list);
2177 				if (!req->data) {
2178 					/* No available buffers. Queue this request up. */
2179 					SPDK_DEBUGLOG(nvmf_tcp, "No available ICD buffers. Queueing request %p\n", tcp_req);
2180 					return 0;
2181 				}
2182 			} else {
2183 				SPDK_ERRLOG("In-capsule data length 0x%x exceeds capsule length 0x%x\n",
2184 					    length, max_len);
2185 				rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2186 				return -1;
2187 			}
2188 		} else {
2189 			req->data = tcp_req->buf;
2190 		}
2191 
2192 		req->length = length;
2193 		req->data_from_pool = false;
2194 
2195 		if (spdk_unlikely(req->dif_enabled)) {
2196 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2197 			req->dif.elba_length = length;
2198 		}
2199 
2200 		req->iov[0].iov_base = req->data;
2201 		req->iov[0].iov_len = length;
2202 		req->iovcnt = 1;
2203 
2204 		return 0;
2205 	}
2206 
2207 	SPDK_ERRLOG("Invalid NVMf I/O Command SGL:  Type 0x%x, Subtype 0x%x\n",
2208 		    sgl->generic.type, sgl->generic.subtype);
2209 	rsp->status.sc = SPDK_NVME_SC_SGL_DESCRIPTOR_TYPE_INVALID;
2210 	return -1;
2211 }
2212 
2213 static inline enum spdk_nvme_media_error_status_code
2214 nvmf_tcp_dif_error_to_compl_status(uint8_t err_type) {
2215 	enum spdk_nvme_media_error_status_code result;
2216 
2217 	switch (err_type)
2218 	{
2219 	case SPDK_DIF_REFTAG_ERROR:
2220 		result = SPDK_NVME_SC_REFERENCE_TAG_CHECK_ERROR;
2221 		break;
2222 	case SPDK_DIF_APPTAG_ERROR:
2223 		result = SPDK_NVME_SC_APPLICATION_TAG_CHECK_ERROR;
2224 		break;
2225 	case SPDK_DIF_GUARD_ERROR:
2226 		result = SPDK_NVME_SC_GUARD_CHECK_ERROR;
2227 		break;
2228 	default:
2229 		SPDK_UNREACHABLE();
2230 		break;
2231 	}
2232 
2233 	return result;
2234 }
2235 
2236 static void
2237 _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2238 			struct spdk_nvmf_tcp_req *tcp_req)
2239 {
2240 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(
2241 				tqpair->qpair.transport, struct spdk_nvmf_tcp_transport, transport);
2242 	struct nvme_tcp_pdu *rsp_pdu;
2243 	struct spdk_nvme_tcp_c2h_data_hdr *c2h_data;
2244 	uint32_t plen, pdo, alignment;
2245 	int rc;
2246 
2247 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2248 
2249 	rsp_pdu = tcp_req->pdu;
2250 	assert(rsp_pdu != NULL);
2251 	assert(tcp_req->pdu_in_use);
2252 
2253 	c2h_data = &rsp_pdu->hdr.c2h_data;
2254 	c2h_data->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_DATA;
2255 	plen = c2h_data->common.hlen = sizeof(*c2h_data);
2256 
2257 	if (tqpair->host_hdgst_enable) {
2258 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2259 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
2260 	}
2261 
2262 	/* set the psh */
2263 	c2h_data->cccid = tcp_req->req.cmd->nvme_cmd.cid;
2264 	c2h_data->datal = tcp_req->req.length - tcp_req->pdu->rw_offset;
2265 	c2h_data->datao = tcp_req->pdu->rw_offset;
2266 
2267 	/* set the padding */
2268 	rsp_pdu->padding_len = 0;
2269 	pdo = plen;
2270 	if (tqpair->cpda) {
2271 		alignment = (tqpair->cpda + 1) << 2;
2272 		if (plen % alignment != 0) {
2273 			pdo = (plen + alignment) / alignment * alignment;
2274 			rsp_pdu->padding_len = pdo - plen;
2275 			plen = pdo;
2276 		}
2277 	}
2278 
2279 	c2h_data->common.pdo = pdo;
2280 	plen += c2h_data->datal;
2281 	if (tqpair->host_ddgst_enable) {
2282 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_DDGSTF;
2283 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2284 	}
2285 
2286 	c2h_data->common.plen = plen;
2287 
2288 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2289 		rsp_pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
2290 	}
2291 
2292 	nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2293 				  c2h_data->datao, c2h_data->datal);
2294 
2295 
2296 	c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU;
2297 	/* Need to send the capsule response if response is not all 0 */
2298 	if (ttransport->tcp_opts.c2h_success &&
2299 	    tcp_req->rsp.cdw0 == 0 && tcp_req->rsp.cdw1 == 0) {
2300 		c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS;
2301 	}
2302 
2303 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2304 		struct spdk_nvme_cpl *rsp = &tcp_req->req.rsp->nvme_cpl;
2305 		struct spdk_dif_error err_blk = {};
2306 		uint32_t mapped_length = 0;
2307 		uint32_t available_iovs = SPDK_COUNTOF(rsp_pdu->iov);
2308 		uint32_t ddgst_len = 0;
2309 
2310 		if (tqpair->host_ddgst_enable) {
2311 			/* Data digest consumes additional iov entry */
2312 			available_iovs--;
2313 			/* plen needs to be updated since nvme_tcp_build_iovs compares expected and actual plen */
2314 			ddgst_len = SPDK_NVME_TCP_DIGEST_LEN;
2315 			c2h_data->common.plen -= ddgst_len;
2316 		}
2317 		/* Temp call to estimate if data can be described by limited number of iovs.
2318 		 * iov vector will be rebuilt in nvmf_tcp_qpair_write_pdu */
2319 		nvme_tcp_build_iovs(rsp_pdu->iov, available_iovs, rsp_pdu, tqpair->host_hdgst_enable,
2320 				    false, &mapped_length);
2321 
2322 		if (mapped_length != c2h_data->common.plen) {
2323 			c2h_data->datal = mapped_length - (c2h_data->common.plen - c2h_data->datal);
2324 			SPDK_DEBUGLOG(nvmf_tcp,
2325 				      "Part C2H, data_len %u (of %u), PDU len %u, updated PDU len %u, offset %u\n",
2326 				      c2h_data->datal, tcp_req->req.length, c2h_data->common.plen, mapped_length, rsp_pdu->rw_offset);
2327 			c2h_data->common.plen = mapped_length;
2328 
2329 			/* Rebuild pdu->data_iov since data length is changed */
2330 			nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt, c2h_data->datao,
2331 						  c2h_data->datal);
2332 
2333 			c2h_data->common.flags &= ~(SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU |
2334 						    SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS);
2335 		}
2336 
2337 		c2h_data->common.plen += ddgst_len;
2338 
2339 		assert(rsp_pdu->rw_offset <= tcp_req->req.length);
2340 
2341 		rc = spdk_dif_verify_stream(rsp_pdu->data_iov, rsp_pdu->data_iovcnt,
2342 					    0, rsp_pdu->data_len, rsp_pdu->dif_ctx, &err_blk);
2343 		if (rc != 0) {
2344 			SPDK_ERRLOG("DIF error detected. type=%d, offset=%" PRIu32 "\n",
2345 				    err_blk.err_type, err_blk.err_offset);
2346 			rsp->status.sct = SPDK_NVME_SCT_MEDIA_ERROR;
2347 			rsp->status.sc = nvmf_tcp_dif_error_to_compl_status(err_blk.err_type);
2348 			nvmf_tcp_req_pdu_fini(tcp_req);
2349 			nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2350 			return;
2351 		}
2352 	}
2353 
2354 	rsp_pdu->rw_offset += c2h_data->datal;
2355 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_pdu_c2h_data_complete, tcp_req);
2356 }
2357 
2358 static void
2359 nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2360 		       struct spdk_nvmf_tcp_req *tcp_req)
2361 {
2362 	nvmf_tcp_req_pdu_init(tcp_req);
2363 	_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2364 }
2365 
2366 static int
2367 request_transfer_out(struct spdk_nvmf_request *req)
2368 {
2369 	struct spdk_nvmf_tcp_req	*tcp_req;
2370 	struct spdk_nvmf_qpair		*qpair;
2371 	struct spdk_nvmf_tcp_qpair	*tqpair;
2372 	struct spdk_nvme_cpl		*rsp;
2373 
2374 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2375 
2376 	qpair = req->qpair;
2377 	rsp = &req->rsp->nvme_cpl;
2378 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2379 
2380 	/* Advance our sq_head pointer */
2381 	if (qpair->sq_head == qpair->sq_head_max) {
2382 		qpair->sq_head = 0;
2383 	} else {
2384 		qpair->sq_head++;
2385 	}
2386 	rsp->sqhd = qpair->sq_head;
2387 
2388 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2389 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
2390 	if (rsp->status.sc == SPDK_NVME_SC_SUCCESS && req->xfer == SPDK_NVME_DATA_CONTROLLER_TO_HOST) {
2391 		nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2392 	} else {
2393 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2394 	}
2395 
2396 	return 0;
2397 }
2398 
2399 static void
2400 nvmf_tcp_set_incapsule_data(struct spdk_nvmf_tcp_qpair *tqpair,
2401 			    struct spdk_nvmf_tcp_req *tcp_req)
2402 {
2403 	struct nvme_tcp_pdu *pdu;
2404 	uint32_t plen = 0;
2405 
2406 	pdu = tqpair->pdu_in_progress;
2407 	plen = pdu->hdr.common.hlen;
2408 
2409 	if (tqpair->host_hdgst_enable) {
2410 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2411 	}
2412 
2413 	if (pdu->hdr.common.plen != plen) {
2414 		tcp_req->has_incapsule_data = true;
2415 	}
2416 }
2417 
2418 static bool
2419 nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
2420 		     struct spdk_nvmf_tcp_req *tcp_req)
2421 {
2422 	struct spdk_nvmf_tcp_qpair		*tqpair;
2423 	int					rc;
2424 	enum spdk_nvmf_tcp_req_state		prev_state;
2425 	bool					progress = false;
2426 	struct spdk_nvmf_transport		*transport = &ttransport->transport;
2427 	struct spdk_nvmf_transport_poll_group	*group;
2428 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2429 
2430 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2431 	group = &tqpair->group->group;
2432 	assert(tcp_req->state != TCP_REQUEST_STATE_FREE);
2433 
2434 	/* If the qpair is not active, we need to abort the outstanding requests. */
2435 	if (tqpair->qpair.state != SPDK_NVMF_QPAIR_ACTIVE) {
2436 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
2437 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2438 		}
2439 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
2440 	}
2441 
2442 	/* The loop here is to allow for several back-to-back state changes. */
2443 	do {
2444 		prev_state = tcp_req->state;
2445 
2446 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p entering state %d on tqpair=%p\n", tcp_req, prev_state,
2447 			      tqpair);
2448 
2449 		switch (tcp_req->state) {
2450 		case TCP_REQUEST_STATE_FREE:
2451 			/* Some external code must kick a request into TCP_REQUEST_STATE_NEW
2452 			 * to escape this state. */
2453 			break;
2454 		case TCP_REQUEST_STATE_NEW:
2455 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEW, 0, 0, (uintptr_t)tcp_req);
2456 
2457 			/* copy the cmd from the receive pdu */
2458 			tcp_req->cmd = tqpair->pdu_in_progress->hdr.capsule_cmd.ccsqe;
2459 
2460 			if (spdk_unlikely(spdk_nvmf_request_get_dif_ctx(&tcp_req->req, &tcp_req->req.dif.dif_ctx))) {
2461 				tcp_req->req.dif_enabled = true;
2462 				tqpair->pdu_in_progress->dif_ctx = &tcp_req->req.dif.dif_ctx;
2463 			}
2464 
2465 			/* The next state transition depends on the data transfer needs of this request. */
2466 			tcp_req->req.xfer = spdk_nvmf_req_get_xfer(&tcp_req->req);
2467 
2468 			if (spdk_unlikely(tcp_req->req.xfer == SPDK_NVME_DATA_BIDIRECTIONAL)) {
2469 				tcp_req->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2470 				tcp_req->req.rsp->nvme_cpl.status.sc  = SPDK_NVME_SC_INVALID_OPCODE;
2471 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2472 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2473 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2474 				SPDK_DEBUGLOG(nvmf_tcp, "Request %p: invalid xfer type (BIDIRECTIONAL)\n", tcp_req);
2475 				break;
2476 			}
2477 
2478 			/* If no data to transfer, ready to execute. */
2479 			if (tcp_req->req.xfer == SPDK_NVME_DATA_NONE) {
2480 				/* Reset the tqpair receving pdu state */
2481 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2482 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2483 				break;
2484 			}
2485 
2486 			nvmf_tcp_set_incapsule_data(tqpair, tcp_req);
2487 
2488 			if (!tcp_req->has_incapsule_data) {
2489 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2490 			}
2491 
2492 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEED_BUFFER);
2493 			STAILQ_INSERT_TAIL(&group->pending_buf_queue, &tcp_req->req, buf_link);
2494 			break;
2495 		case TCP_REQUEST_STATE_NEED_BUFFER:
2496 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEED_BUFFER, 0, 0, (uintptr_t)tcp_req);
2497 
2498 			assert(tcp_req->req.xfer != SPDK_NVME_DATA_NONE);
2499 
2500 			if (!tcp_req->has_incapsule_data && (&tcp_req->req != STAILQ_FIRST(&group->pending_buf_queue))) {
2501 				SPDK_DEBUGLOG(nvmf_tcp,
2502 					      "Not the first element to wait for the buf for tcp_req(%p) on tqpair=%p\n",
2503 					      tcp_req, tqpair);
2504 				/* This request needs to wait in line to obtain a buffer */
2505 				break;
2506 			}
2507 
2508 			/* Try to get a data buffer */
2509 			rc = nvmf_tcp_req_parse_sgl(tcp_req, transport, group);
2510 			if (rc < 0) {
2511 				STAILQ_REMOVE_HEAD(&group->pending_buf_queue, buf_link);
2512 				/* Reset the tqpair receving pdu state */
2513 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
2514 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2515 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2516 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2517 				break;
2518 			}
2519 
2520 			if (!tcp_req->req.data) {
2521 				SPDK_DEBUGLOG(nvmf_tcp, "No buffer allocated for tcp_req(%p) on tqpair(%p\n)",
2522 					      tcp_req, tqpair);
2523 				/* No buffers available. */
2524 				break;
2525 			}
2526 
2527 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2528 
2529 			/* If data is transferring from host to controller, we need to do a transfer from the host. */
2530 			if (tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER) {
2531 				if (tcp_req->req.data_from_pool) {
2532 					SPDK_DEBUGLOG(nvmf_tcp, "Sending R2T for tcp_req(%p) on tqpair=%p\n", tcp_req, tqpair);
2533 					nvmf_tcp_send_r2t_pdu(tqpair, tcp_req);
2534 				} else {
2535 					struct nvme_tcp_pdu *pdu;
2536 
2537 					nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
2538 
2539 					pdu = tqpair->pdu_in_progress;
2540 					SPDK_DEBUGLOG(nvmf_tcp, "Not need to send r2t for tcp_req(%p) on tqpair=%p\n", tcp_req,
2541 						      tqpair);
2542 					/* No need to send r2t, contained in the capsuled data */
2543 					nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2544 								  0, tcp_req->req.length);
2545 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
2546 				}
2547 				break;
2548 			}
2549 
2550 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2551 			break;
2552 		case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2553 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK, 0, 0, (uintptr_t)tcp_req);
2554 			/* The R2T completion or the h2c data incoming will kick it out of this state. */
2555 			break;
2556 		case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2557 
2558 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER, 0, 0,
2559 					  (uintptr_t)tcp_req);
2560 			/* Some external code must kick a request into TCP_REQUEST_STATE_READY_TO_EXECUTE
2561 			 * to escape this state. */
2562 			break;
2563 		case TCP_REQUEST_STATE_READY_TO_EXECUTE:
2564 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE, 0, 0, (uintptr_t)tcp_req);
2565 
2566 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2567 				assert(tcp_req->req.dif.elba_length >= tcp_req->req.length);
2568 				tcp_req->req.length = tcp_req->req.dif.elba_length;
2569 			}
2570 
2571 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTING);
2572 			spdk_nvmf_request_exec(&tcp_req->req);
2573 			break;
2574 		case TCP_REQUEST_STATE_EXECUTING:
2575 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTING, 0, 0, (uintptr_t)tcp_req);
2576 			/* Some external code must kick a request into TCP_REQUEST_STATE_EXECUTED
2577 			 * to escape this state. */
2578 			break;
2579 		case TCP_REQUEST_STATE_EXECUTED:
2580 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTED, 0, 0, (uintptr_t)tcp_req);
2581 
2582 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2583 				tcp_req->req.length = tcp_req->req.dif.orig_length;
2584 			}
2585 
2586 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2587 			break;
2588 		case TCP_REQUEST_STATE_READY_TO_COMPLETE:
2589 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE, 0, 0, (uintptr_t)tcp_req);
2590 			rc = request_transfer_out(&tcp_req->req);
2591 			assert(rc == 0); /* No good way to handle this currently */
2592 			break;
2593 		case TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST:
2594 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST, 0, 0,
2595 					  (uintptr_t)tcp_req);
2596 			/* Some external code must kick a request into TCP_REQUEST_STATE_COMPLETED
2597 			 * to escape this state. */
2598 			break;
2599 		case TCP_REQUEST_STATE_COMPLETED:
2600 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_COMPLETED, 0, 0, (uintptr_t)tcp_req);
2601 			if (tcp_req->req.data_from_pool) {
2602 				spdk_nvmf_request_free_buffers(&tcp_req->req, group, transport);
2603 			} else if (spdk_unlikely(tcp_req->has_incapsule_data && (tcp_req->cmd.opc == SPDK_NVME_OPC_FABRIC ||
2604 						 tqpair->qpair.qid == 0) && tcp_req->req.length > transport->opts.in_capsule_data_size)) {
2605 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2606 				assert(tgroup->control_msg_list);
2607 				SPDK_DEBUGLOG(nvmf_tcp, "Put buf to control msg list\n");
2608 				nvmf_tcp_control_msg_put(tgroup->control_msg_list, tcp_req->req.data);
2609 			}
2610 			tcp_req->req.length = 0;
2611 			tcp_req->req.iovcnt = 0;
2612 			tcp_req->req.data = NULL;
2613 
2614 			nvmf_tcp_req_pdu_fini(tcp_req);
2615 
2616 			nvmf_tcp_req_put(tqpair, tcp_req);
2617 			break;
2618 		case TCP_REQUEST_NUM_STATES:
2619 		default:
2620 			assert(0);
2621 			break;
2622 		}
2623 
2624 		if (tcp_req->state != prev_state) {
2625 			progress = true;
2626 		}
2627 	} while (tcp_req->state != prev_state);
2628 
2629 	return progress;
2630 }
2631 
2632 static void
2633 nvmf_tcp_sock_cb(void *arg, struct spdk_sock_group *group, struct spdk_sock *sock)
2634 {
2635 	struct spdk_nvmf_tcp_qpair *tqpair = arg;
2636 	int rc;
2637 
2638 	assert(tqpair != NULL);
2639 	rc = nvmf_tcp_sock_process(tqpair);
2640 
2641 	/* If there was a new socket error, disconnect */
2642 	if (rc < 0) {
2643 		nvmf_tcp_qpair_disconnect(tqpair);
2644 	}
2645 }
2646 
2647 static int
2648 nvmf_tcp_poll_group_add(struct spdk_nvmf_transport_poll_group *group,
2649 			struct spdk_nvmf_qpair *qpair)
2650 {
2651 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2652 	struct spdk_nvmf_tcp_qpair	*tqpair;
2653 	int				rc;
2654 
2655 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2656 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2657 
2658 	rc = spdk_sock_group_add_sock(tgroup->sock_group, tqpair->sock,
2659 				      nvmf_tcp_sock_cb, tqpair);
2660 	if (rc != 0) {
2661 		SPDK_ERRLOG("Could not add sock to sock_group: %s (%d)\n",
2662 			    spdk_strerror(errno), errno);
2663 		return -1;
2664 	}
2665 
2666 	rc =  nvmf_tcp_qpair_sock_init(tqpair);
2667 	if (rc != 0) {
2668 		SPDK_ERRLOG("Cannot set sock opt for tqpair=%p\n", tqpair);
2669 		return -1;
2670 	}
2671 
2672 	rc = nvmf_tcp_qpair_init(&tqpair->qpair);
2673 	if (rc < 0) {
2674 		SPDK_ERRLOG("Cannot init tqpair=%p\n", tqpair);
2675 		return -1;
2676 	}
2677 
2678 	rc = nvmf_tcp_qpair_init_mem_resource(tqpair);
2679 	if (rc < 0) {
2680 		SPDK_ERRLOG("Cannot init memory resource info for tqpair=%p\n", tqpair);
2681 		return -1;
2682 	}
2683 
2684 	tqpair->group = tgroup;
2685 	tqpair->state = NVME_TCP_QPAIR_STATE_INVALID;
2686 	TAILQ_INSERT_TAIL(&tgroup->qpairs, tqpair, link);
2687 
2688 	return 0;
2689 }
2690 
2691 static int
2692 nvmf_tcp_poll_group_remove(struct spdk_nvmf_transport_poll_group *group,
2693 			   struct spdk_nvmf_qpair *qpair)
2694 {
2695 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2696 	struct spdk_nvmf_tcp_qpair		*tqpair;
2697 	int				rc;
2698 
2699 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2700 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2701 
2702 	assert(tqpair->group == tgroup);
2703 
2704 	SPDK_DEBUGLOG(nvmf_tcp, "remove tqpair=%p from the tgroup=%p\n", tqpair, tgroup);
2705 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
2706 		TAILQ_REMOVE(&tgroup->await_req, tqpair, link);
2707 	} else {
2708 		TAILQ_REMOVE(&tgroup->qpairs, tqpair, link);
2709 	}
2710 
2711 	rc = spdk_sock_group_remove_sock(tgroup->sock_group, tqpair->sock);
2712 	if (rc != 0) {
2713 		SPDK_ERRLOG("Could not remove sock from sock_group: %s (%d)\n",
2714 			    spdk_strerror(errno), errno);
2715 	}
2716 
2717 	return rc;
2718 }
2719 
2720 static int
2721 nvmf_tcp_req_complete(struct spdk_nvmf_request *req)
2722 {
2723 	struct spdk_nvmf_tcp_transport *ttransport;
2724 	struct spdk_nvmf_tcp_req *tcp_req;
2725 
2726 	ttransport = SPDK_CONTAINEROF(req->qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2727 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2728 
2729 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTED);
2730 	nvmf_tcp_req_process(ttransport, tcp_req);
2731 
2732 	return 0;
2733 }
2734 
2735 static void
2736 nvmf_tcp_close_qpair(struct spdk_nvmf_qpair *qpair,
2737 		     spdk_nvmf_transport_qpair_fini_cb cb_fn, void *cb_arg)
2738 {
2739 	struct spdk_nvmf_tcp_qpair *tqpair;
2740 
2741 	SPDK_DEBUGLOG(nvmf_tcp, "Qpair: %p\n", qpair);
2742 
2743 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2744 	tqpair->state = NVME_TCP_QPAIR_STATE_EXITED;
2745 	nvmf_tcp_qpair_destroy(tqpair);
2746 
2747 	if (cb_fn) {
2748 		cb_fn(cb_arg);
2749 	}
2750 }
2751 
2752 static int
2753 nvmf_tcp_poll_group_poll(struct spdk_nvmf_transport_poll_group *group)
2754 {
2755 	struct spdk_nvmf_tcp_poll_group *tgroup;
2756 	int rc;
2757 	struct spdk_nvmf_request *req, *req_tmp;
2758 	struct spdk_nvmf_tcp_req *tcp_req;
2759 	struct spdk_nvmf_tcp_qpair *tqpair, *tqpair_tmp;
2760 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(group->transport,
2761 			struct spdk_nvmf_tcp_transport, transport);
2762 
2763 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2764 
2765 	if (spdk_unlikely(TAILQ_EMPTY(&tgroup->qpairs) && TAILQ_EMPTY(&tgroup->await_req))) {
2766 		return 0;
2767 	}
2768 
2769 	STAILQ_FOREACH_SAFE(req, &group->pending_buf_queue, buf_link, req_tmp) {
2770 		tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2771 		if (nvmf_tcp_req_process(ttransport, tcp_req) == false) {
2772 			break;
2773 		}
2774 	}
2775 
2776 	rc = spdk_sock_group_poll(tgroup->sock_group);
2777 	if (rc < 0) {
2778 		SPDK_ERRLOG("Failed to poll sock_group=%p\n", tgroup->sock_group);
2779 	}
2780 
2781 	TAILQ_FOREACH_SAFE(tqpair, &tgroup->await_req, link, tqpair_tmp) {
2782 		nvmf_tcp_sock_process(tqpair);
2783 	}
2784 
2785 	return rc;
2786 }
2787 
2788 static int
2789 nvmf_tcp_qpair_get_trid(struct spdk_nvmf_qpair *qpair,
2790 			struct spdk_nvme_transport_id *trid, bool peer)
2791 {
2792 	struct spdk_nvmf_tcp_qpair     *tqpair;
2793 	uint16_t			port;
2794 
2795 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2796 	spdk_nvme_trid_populate_transport(trid, SPDK_NVME_TRANSPORT_TCP);
2797 
2798 	if (peer) {
2799 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->initiator_addr);
2800 		port = tqpair->initiator_port;
2801 	} else {
2802 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->target_addr);
2803 		port = tqpair->target_port;
2804 	}
2805 
2806 	if (spdk_sock_is_ipv4(tqpair->sock)) {
2807 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV4;
2808 	} else if (spdk_sock_is_ipv6(tqpair->sock)) {
2809 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV6;
2810 	} else {
2811 		return -1;
2812 	}
2813 
2814 	snprintf(trid->trsvcid, sizeof(trid->trsvcid), "%d", port);
2815 	return 0;
2816 }
2817 
2818 static int
2819 nvmf_tcp_qpair_get_local_trid(struct spdk_nvmf_qpair *qpair,
2820 			      struct spdk_nvme_transport_id *trid)
2821 {
2822 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2823 }
2824 
2825 static int
2826 nvmf_tcp_qpair_get_peer_trid(struct spdk_nvmf_qpair *qpair,
2827 			     struct spdk_nvme_transport_id *trid)
2828 {
2829 	return nvmf_tcp_qpair_get_trid(qpair, trid, 1);
2830 }
2831 
2832 static int
2833 nvmf_tcp_qpair_get_listen_trid(struct spdk_nvmf_qpair *qpair,
2834 			       struct spdk_nvme_transport_id *trid)
2835 {
2836 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
2837 }
2838 
2839 static void
2840 nvmf_tcp_req_set_abort_status(struct spdk_nvmf_request *req,
2841 			      struct spdk_nvmf_tcp_req *tcp_req_to_abort)
2842 {
2843 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2844 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sc = SPDK_NVME_SC_ABORTED_BY_REQUEST;
2845 
2846 	nvmf_tcp_req_set_state(tcp_req_to_abort, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2847 
2848 	req->rsp->nvme_cpl.cdw0 &= ~1U; /* Command was successfully aborted. */
2849 }
2850 
2851 static int
2852 _nvmf_tcp_qpair_abort_request(void *ctx)
2853 {
2854 	struct spdk_nvmf_request *req = ctx;
2855 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = SPDK_CONTAINEROF(req->req_to_abort,
2856 			struct spdk_nvmf_tcp_req, req);
2857 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(req->req_to_abort->qpair,
2858 					     struct spdk_nvmf_tcp_qpair, qpair);
2859 	int rc;
2860 
2861 	spdk_poller_unregister(&req->poller);
2862 
2863 	switch (tcp_req_to_abort->state) {
2864 	case TCP_REQUEST_STATE_EXECUTING:
2865 		rc = nvmf_ctrlr_abort_request(req);
2866 		if (rc == SPDK_NVMF_REQUEST_EXEC_STATUS_ASYNCHRONOUS) {
2867 			return SPDK_POLLER_BUSY;
2868 		}
2869 		break;
2870 
2871 	case TCP_REQUEST_STATE_NEED_BUFFER:
2872 		STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue,
2873 			      &tcp_req_to_abort->req, spdk_nvmf_request, buf_link);
2874 
2875 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2876 		break;
2877 
2878 	case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2879 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
2880 		break;
2881 
2882 	case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2883 		if (spdk_get_ticks() < req->timeout_tsc) {
2884 			req->poller = SPDK_POLLER_REGISTER(_nvmf_tcp_qpair_abort_request, req, 0);
2885 			return SPDK_POLLER_BUSY;
2886 		}
2887 		break;
2888 
2889 	default:
2890 		break;
2891 	}
2892 
2893 	spdk_nvmf_request_complete(req);
2894 	return SPDK_POLLER_BUSY;
2895 }
2896 
2897 static void
2898 nvmf_tcp_qpair_abort_request(struct spdk_nvmf_qpair *qpair,
2899 			     struct spdk_nvmf_request *req)
2900 {
2901 	struct spdk_nvmf_tcp_qpair *tqpair;
2902 	struct spdk_nvmf_tcp_transport *ttransport;
2903 	struct spdk_nvmf_transport *transport;
2904 	uint16_t cid;
2905 	uint32_t i;
2906 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = NULL;
2907 
2908 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2909 	ttransport = SPDK_CONTAINEROF(qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2910 	transport = &ttransport->transport;
2911 
2912 	cid = req->cmd->nvme_cmd.cdw10_bits.abort.cid;
2913 
2914 	for (i = 0; i < tqpair->resource_count; i++) {
2915 		if (tqpair->reqs[i].state != TCP_REQUEST_STATE_FREE &&
2916 		    tqpair->reqs[i].req.cmd->nvme_cmd.cid == cid) {
2917 			tcp_req_to_abort = &tqpair->reqs[i];
2918 			break;
2919 		}
2920 	}
2921 
2922 	if (tcp_req_to_abort == NULL) {
2923 		spdk_nvmf_request_complete(req);
2924 		return;
2925 	}
2926 
2927 	req->req_to_abort = &tcp_req_to_abort->req;
2928 	req->timeout_tsc = spdk_get_ticks() +
2929 			   transport->opts.abort_timeout_sec * spdk_get_ticks_hz();
2930 	req->poller = NULL;
2931 
2932 	_nvmf_tcp_qpair_abort_request(req);
2933 }
2934 
2935 #define SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH 128
2936 #define SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH 128
2937 #define SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR 128
2938 #define SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE 4096
2939 #define SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE 131072
2940 #define SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE 131072
2941 #define SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS 511
2942 #define SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE 32
2943 #define SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP false
2944 #define SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC 1
2945 
2946 static void
2947 nvmf_tcp_opts_init(struct spdk_nvmf_transport_opts *opts)
2948 {
2949 	opts->max_queue_depth =		SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH;
2950 	opts->max_qpairs_per_ctrlr =	SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR;
2951 	opts->in_capsule_data_size =	SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE;
2952 	opts->max_io_size =		SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE;
2953 	opts->io_unit_size =		SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE;
2954 	opts->max_aq_depth =		SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH;
2955 	opts->num_shared_buffers =	SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS;
2956 	opts->buf_cache_size =		SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE;
2957 	opts->dif_insert_or_strip =	SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP;
2958 	opts->abort_timeout_sec =	SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC;
2959 	opts->transport_specific =      NULL;
2960 }
2961 
2962 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp = {
2963 	.name = "TCP",
2964 	.type = SPDK_NVME_TRANSPORT_TCP,
2965 	.opts_init = nvmf_tcp_opts_init,
2966 	.create = nvmf_tcp_create,
2967 	.dump_opts = nvmf_tcp_dump_opts,
2968 	.destroy = nvmf_tcp_destroy,
2969 
2970 	.listen = nvmf_tcp_listen,
2971 	.stop_listen = nvmf_tcp_stop_listen,
2972 	.accept = nvmf_tcp_accept,
2973 
2974 	.listener_discover = nvmf_tcp_discover,
2975 
2976 	.poll_group_create = nvmf_tcp_poll_group_create,
2977 	.get_optimal_poll_group = nvmf_tcp_get_optimal_poll_group,
2978 	.poll_group_destroy = nvmf_tcp_poll_group_destroy,
2979 	.poll_group_add = nvmf_tcp_poll_group_add,
2980 	.poll_group_remove = nvmf_tcp_poll_group_remove,
2981 	.poll_group_poll = nvmf_tcp_poll_group_poll,
2982 
2983 	.req_free = nvmf_tcp_req_free,
2984 	.req_complete = nvmf_tcp_req_complete,
2985 
2986 	.qpair_fini = nvmf_tcp_close_qpair,
2987 	.qpair_get_local_trid = nvmf_tcp_qpair_get_local_trid,
2988 	.qpair_get_peer_trid = nvmf_tcp_qpair_get_peer_trid,
2989 	.qpair_get_listen_trid = nvmf_tcp_qpair_get_listen_trid,
2990 	.qpair_abort_request = nvmf_tcp_qpair_abort_request,
2991 };
2992 
2993 SPDK_NVMF_TRANSPORT_REGISTER(tcp, &spdk_nvmf_transport_tcp);
2994 SPDK_LOG_REGISTER_COMPONENT(nvmf_tcp)
2995