xref: /spdk/lib/nvmf/tcp.c (revision c39647df83e4be9bcc49025132c48bf2414ef8b1)
1 /*-
2  *   BSD LICENSE
3  *
4  *   Copyright (c) Intel Corporation. All rights reserved.
5  *   Copyright (c) 2019, 2020 Mellanox Technologies LTD. All rights reserved.
6  *   Copyright (c) 2022 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
7  *
8  *   Redistribution and use in source and binary forms, with or without
9  *   modification, are permitted provided that the following conditions
10  *   are met:
11  *
12  *     * Redistributions of source code must retain the above copyright
13  *       notice, this list of conditions and the following disclaimer.
14  *     * Redistributions in binary form must reproduce the above copyright
15  *       notice, this list of conditions and the following disclaimer in
16  *       the documentation and/or other materials provided with the
17  *       distribution.
18  *     * Neither the name of Intel Corporation nor the names of its
19  *       contributors may be used to endorse or promote products derived
20  *       from this software without specific prior written permission.
21  *
22  *   THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
23  *   "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
24  *   LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
25  *   A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
26  *   OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
27  *   SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
28  *   LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
29  *   DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
30  *   THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
31  *   (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
32  *   OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
33  */
34 
35 #include "spdk/accel_engine.h"
36 #include "spdk/stdinc.h"
37 #include "spdk/crc32.h"
38 #include "spdk/endian.h"
39 #include "spdk/assert.h"
40 #include "spdk/thread.h"
41 #include "spdk/nvmf_transport.h"
42 #include "spdk/string.h"
43 #include "spdk/trace.h"
44 #include "spdk/util.h"
45 #include "spdk/log.h"
46 
47 #include "spdk_internal/assert.h"
48 #include "spdk_internal/nvme_tcp.h"
49 #include "spdk_internal/sock.h"
50 
51 #include "nvmf_internal.h"
52 
53 #include "spdk_internal/trace_defs.h"
54 
55 #define NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME 16
56 #define SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY 16
57 #define SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY 0
58 #define SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM 32
59 #define SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION true
60 
61 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp;
62 
63 /* spdk nvmf related structure */
64 enum spdk_nvmf_tcp_req_state {
65 
66 	/* The request is not currently in use */
67 	TCP_REQUEST_STATE_FREE = 0,
68 
69 	/* Initial state when request first received */
70 	TCP_REQUEST_STATE_NEW = 1,
71 
72 	/* The request is queued until a data buffer is available. */
73 	TCP_REQUEST_STATE_NEED_BUFFER = 2,
74 
75 	/* The request is waiting for zcopy_start to finish */
76 	TCP_REQUEST_STATE_AWAITING_ZCOPY_START = 3,
77 
78 	/* The request has received a zero-copy buffer */
79 	TCP_REQUEST_STATE_ZCOPY_START_COMPLETED = 4,
80 
81 	/* The request is currently transferring data from the host to the controller. */
82 	TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER = 5,
83 
84 	/* The request is waiting for the R2T send acknowledgement. */
85 	TCP_REQUEST_STATE_AWAITING_R2T_ACK = 6,
86 
87 	/* The request is ready to execute at the block device */
88 	TCP_REQUEST_STATE_READY_TO_EXECUTE = 7,
89 
90 	/* The request is currently executing at the block device */
91 	TCP_REQUEST_STATE_EXECUTING = 8,
92 
93 	/* The request is waiting for zcopy buffers to be commited */
94 	TCP_REQUEST_STATE_AWAITING_ZCOPY_COMMIT = 9,
95 
96 	/* The request finished executing at the block device */
97 	TCP_REQUEST_STATE_EXECUTED = 10,
98 
99 	/* The request is ready to send a completion */
100 	TCP_REQUEST_STATE_READY_TO_COMPLETE = 11,
101 
102 	/* The request is currently transferring final pdus from the controller to the host. */
103 	TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST = 12,
104 
105 	/* The request is waiting for zcopy buffers to be released (without committing) */
106 	TCP_REQUEST_STATE_AWAITING_ZCOPY_RELEASE = 13,
107 
108 	/* The request completed and can be marked free. */
109 	TCP_REQUEST_STATE_COMPLETED = 14,
110 
111 	/* Terminator */
112 	TCP_REQUEST_NUM_STATES,
113 };
114 
115 static const char *spdk_nvmf_tcp_term_req_fes_str[] = {
116 	"Invalid PDU Header Field",
117 	"PDU Sequence Error",
118 	"Header Digiest Error",
119 	"Data Transfer Out of Range",
120 	"R2T Limit Exceeded",
121 	"Unsupported parameter",
122 };
123 
124 SPDK_TRACE_REGISTER_FN(nvmf_tcp_trace, "nvmf_tcp", TRACE_GROUP_NVMF_TCP)
125 {
126 	spdk_trace_register_object(OBJECT_NVMF_TCP_IO, 'r');
127 	spdk_trace_register_description("TCP_REQ_NEW",
128 					TRACE_TCP_REQUEST_STATE_NEW,
129 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 1,
130 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
131 	spdk_trace_register_description("TCP_REQ_NEED_BUFFER",
132 					TRACE_TCP_REQUEST_STATE_NEED_BUFFER,
133 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
134 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
135 	spdk_trace_register_description("TCP_REQ_WAIT_ZCPY_START",
136 					TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_START,
137 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
138 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
139 	spdk_trace_register_description("TCP_REQ_ZCPY_START_CPL",
140 					TRACE_TCP_REQUEST_STATE_ZCOPY_START_COMPLETED,
141 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
142 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
143 	spdk_trace_register_description("TCP_REQ_TX_H_TO_C",
144 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
145 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
146 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
147 	spdk_trace_register_description("TCP_REQ_RDY_TO_EXECUTE",
148 					TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE,
149 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
150 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
151 	spdk_trace_register_description("TCP_REQ_EXECUTING",
152 					TRACE_TCP_REQUEST_STATE_EXECUTING,
153 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
154 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
155 	spdk_trace_register_description("TCP_REQ_WAIT_ZCPY_CMT",
156 					TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_COMMIT,
157 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
158 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
159 	spdk_trace_register_description("TCP_REQ_EXECUTED",
160 					TRACE_TCP_REQUEST_STATE_EXECUTED,
161 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
162 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
163 	spdk_trace_register_description("TCP_REQ_RDY_TO_COMPLETE",
164 					TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE,
165 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
166 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
167 	spdk_trace_register_description("TCP_REQ_TRANSFER_C2H",
168 					TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST,
169 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
170 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
171 	spdk_trace_register_description("TCP_REQ_AWAIT_ZCPY_RLS",
172 					TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_RELEASE,
173 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
174 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
175 	spdk_trace_register_description("TCP_REQ_COMPLETED",
176 					TRACE_TCP_REQUEST_STATE_COMPLETED,
177 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
178 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
179 	spdk_trace_register_description("TCP_WRITE_START",
180 					TRACE_TCP_FLUSH_WRITEBUF_START,
181 					OWNER_NONE, OBJECT_NONE, 0,
182 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
183 	spdk_trace_register_description("TCP_WRITE_DONE",
184 					TRACE_TCP_FLUSH_WRITEBUF_DONE,
185 					OWNER_NONE, OBJECT_NONE, 0,
186 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
187 	spdk_trace_register_description("TCP_READ_DONE",
188 					TRACE_TCP_READ_FROM_SOCKET_DONE,
189 					OWNER_NONE, OBJECT_NONE, 0,
190 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
191 	spdk_trace_register_description("TCP_REQ_AWAIT_R2T_ACK",
192 					TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK,
193 					OWNER_NONE, OBJECT_NVMF_TCP_IO, 0,
194 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
195 
196 	spdk_trace_register_description("TCP_QP_CREATE", TRACE_TCP_QP_CREATE,
197 					OWNER_NONE, OBJECT_NONE, 0,
198 					SPDK_TRACE_ARG_TYPE_INT, "");
199 	spdk_trace_register_description("TCP_QP_SOCK_INIT", TRACE_TCP_QP_SOCK_INIT,
200 					OWNER_NONE, OBJECT_NONE, 0,
201 					SPDK_TRACE_ARG_TYPE_INT, "");
202 	spdk_trace_register_description("TCP_QP_STATE_CHANGE", TRACE_TCP_QP_STATE_CHANGE,
203 					OWNER_NONE, OBJECT_NONE, 0,
204 					SPDK_TRACE_ARG_TYPE_INT, "state");
205 	spdk_trace_register_description("TCP_QP_DISCONNECT", TRACE_TCP_QP_DISCONNECT,
206 					OWNER_NONE, OBJECT_NONE, 0,
207 					SPDK_TRACE_ARG_TYPE_INT, "");
208 	spdk_trace_register_description("TCP_QP_DESTROY", TRACE_TCP_QP_DESTROY,
209 					OWNER_NONE, OBJECT_NONE, 0,
210 					SPDK_TRACE_ARG_TYPE_INT, "");
211 	spdk_trace_register_description("TCP_QP_ABORT_REQ", TRACE_TCP_QP_ABORT_REQ,
212 					OWNER_NONE, OBJECT_NONE, 0,
213 					SPDK_TRACE_ARG_TYPE_PTR, "qpair");
214 	spdk_trace_register_description("TCP_QP_RCV_STATE_CHANGE", TRACE_TCP_QP_RCV_STATE_CHANGE,
215 					OWNER_NONE, OBJECT_NONE, 0,
216 					SPDK_TRACE_ARG_TYPE_INT, "state");
217 
218 	spdk_trace_tpoint_register_relation(TRACE_BDEV_IO_START, OBJECT_NVMF_TCP_IO, 1);
219 	spdk_trace_tpoint_register_relation(TRACE_BDEV_IO_DONE, OBJECT_NVMF_TCP_IO, 0);
220 }
221 
222 struct spdk_nvmf_tcp_req  {
223 	struct spdk_nvmf_request		req;
224 	struct spdk_nvme_cpl			rsp;
225 	struct spdk_nvme_cmd			cmd;
226 
227 	/* A PDU that can be used for sending responses. This is
228 	 * not the incoming PDU! */
229 	struct nvme_tcp_pdu			*pdu;
230 
231 	/* In-capsule data buffer */
232 	uint8_t					*buf;
233 	/*
234 	 * The PDU for a request may be used multiple times in serial over
235 	 * the request's lifetime. For example, first to send an R2T, then
236 	 * to send a completion. To catch mistakes where the PDU is used
237 	 * twice at the same time, add a debug flag here for init/fini.
238 	 */
239 	bool					pdu_in_use;
240 	bool					has_in_capsule_data;
241 
242 	/* transfer_tag */
243 	uint16_t				ttag;
244 
245 	enum spdk_nvmf_tcp_req_state		state;
246 
247 	/*
248 	 * h2c_offset is used when we receive the h2c_data PDU.
249 	 */
250 	uint32_t				h2c_offset;
251 
252 	STAILQ_ENTRY(spdk_nvmf_tcp_req)		link;
253 	TAILQ_ENTRY(spdk_nvmf_tcp_req)		state_link;
254 };
255 
256 struct spdk_nvmf_tcp_qpair {
257 	struct spdk_nvmf_qpair			qpair;
258 	struct spdk_nvmf_tcp_poll_group		*group;
259 	struct spdk_sock			*sock;
260 
261 	enum nvme_tcp_pdu_recv_state		recv_state;
262 	enum nvme_tcp_qpair_state		state;
263 
264 	/* PDU being actively received */
265 	struct nvme_tcp_pdu			*pdu_in_progress;
266 
267 	/* Queues to track the requests in all states */
268 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_working_queue;
269 	TAILQ_HEAD(, spdk_nvmf_tcp_req)		tcp_req_free_queue;
270 
271 	/* Number of requests in each state */
272 	uint32_t				state_cntr[TCP_REQUEST_NUM_STATES];
273 
274 	uint8_t					cpda;
275 
276 	bool					host_hdgst_enable;
277 	bool					host_ddgst_enable;
278 
279 	/* This is a spare PDU used for sending special management
280 	 * operations. Primarily, this is used for the initial
281 	 * connection response and c2h termination request. */
282 	struct nvme_tcp_pdu			*mgmt_pdu;
283 
284 	/* Arrays of in-capsule buffers, requests, and pdus.
285 	 * Each array is 'resource_count' number of elements */
286 	void					*bufs;
287 	struct spdk_nvmf_tcp_req		*reqs;
288 	struct nvme_tcp_pdu			*pdus;
289 	uint32_t				resource_count;
290 	uint32_t				recv_buf_size;
291 
292 	struct spdk_nvmf_tcp_port		*port;
293 
294 	/* IP address */
295 	char					initiator_addr[SPDK_NVMF_TRADDR_MAX_LEN];
296 	char					target_addr[SPDK_NVMF_TRADDR_MAX_LEN];
297 
298 	/* IP port */
299 	uint16_t				initiator_port;
300 	uint16_t				target_port;
301 
302 	/* Timer used to destroy qpair after detecting transport error issue if initiator does
303 	 *  not close the connection.
304 	 */
305 	struct spdk_poller			*timeout_poller;
306 
307 
308 	TAILQ_ENTRY(spdk_nvmf_tcp_qpair)	link;
309 };
310 
311 struct spdk_nvmf_tcp_control_msg {
312 	STAILQ_ENTRY(spdk_nvmf_tcp_control_msg) link;
313 };
314 
315 struct spdk_nvmf_tcp_control_msg_list {
316 	void *msg_buf;
317 	STAILQ_HEAD(, spdk_nvmf_tcp_control_msg) free_msgs;
318 };
319 
320 struct spdk_nvmf_tcp_poll_group {
321 	struct spdk_nvmf_transport_poll_group	group;
322 	struct spdk_sock_group			*sock_group;
323 
324 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	qpairs;
325 	TAILQ_HEAD(, spdk_nvmf_tcp_qpair)	await_req;
326 
327 	struct spdk_io_channel			*accel_channel;
328 	struct spdk_nvmf_tcp_control_msg_list	*control_msg_list;
329 
330 	TAILQ_ENTRY(spdk_nvmf_tcp_poll_group)	link;
331 };
332 
333 struct spdk_nvmf_tcp_port {
334 	const struct spdk_nvme_transport_id	*trid;
335 	struct spdk_sock			*listen_sock;
336 	TAILQ_ENTRY(spdk_nvmf_tcp_port)		link;
337 };
338 
339 struct tcp_transport_opts {
340 	bool		c2h_success;
341 	uint16_t	control_msg_num;
342 	uint32_t	sock_priority;
343 };
344 
345 struct spdk_nvmf_tcp_transport {
346 	struct spdk_nvmf_transport		transport;
347 	struct tcp_transport_opts               tcp_opts;
348 
349 	struct spdk_nvmf_tcp_poll_group		*next_pg;
350 
351 	struct spdk_poller			*accept_poller;
352 	pthread_mutex_t				lock;
353 
354 	TAILQ_HEAD(, spdk_nvmf_tcp_port)	ports;
355 	TAILQ_HEAD(, spdk_nvmf_tcp_poll_group)	poll_groups;
356 };
357 
358 static const struct spdk_json_object_decoder tcp_transport_opts_decoder[] = {
359 	{
360 		"c2h_success", offsetof(struct tcp_transport_opts, c2h_success),
361 		spdk_json_decode_bool, true
362 	},
363 	{
364 		"control_msg_num", offsetof(struct tcp_transport_opts, control_msg_num),
365 		spdk_json_decode_uint16, true
366 	},
367 	{
368 		"sock_priority", offsetof(struct tcp_transport_opts, sock_priority),
369 		spdk_json_decode_uint32, true
370 	},
371 };
372 
373 static bool nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
374 				 struct spdk_nvmf_tcp_req *tcp_req);
375 static void nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group);
376 
377 static void _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
378 				    struct spdk_nvmf_tcp_req *tcp_req);
379 
380 static void
381 nvmf_tcp_req_set_state(struct spdk_nvmf_tcp_req *tcp_req,
382 		       enum spdk_nvmf_tcp_req_state state)
383 {
384 	struct spdk_nvmf_qpair *qpair;
385 	struct spdk_nvmf_tcp_qpair *tqpair;
386 
387 	qpair = tcp_req->req.qpair;
388 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
389 
390 	assert(tqpair->state_cntr[tcp_req->state] > 0);
391 	tqpair->state_cntr[tcp_req->state]--;
392 	tqpair->state_cntr[state]++;
393 
394 	tcp_req->state = state;
395 }
396 
397 static inline struct nvme_tcp_pdu *
398 nvmf_tcp_req_pdu_init(struct spdk_nvmf_tcp_req *tcp_req)
399 {
400 	assert(tcp_req->pdu_in_use == false);
401 	tcp_req->pdu_in_use = true;
402 
403 	memset(tcp_req->pdu, 0, sizeof(*tcp_req->pdu));
404 	tcp_req->pdu->qpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
405 
406 	return tcp_req->pdu;
407 }
408 
409 static inline void
410 nvmf_tcp_req_pdu_fini(struct spdk_nvmf_tcp_req *tcp_req)
411 {
412 	tcp_req->pdu_in_use = false;
413 }
414 
415 static struct spdk_nvmf_tcp_req *
416 nvmf_tcp_req_get(struct spdk_nvmf_tcp_qpair *tqpair)
417 {
418 	struct spdk_nvmf_tcp_req *tcp_req;
419 
420 	tcp_req = TAILQ_FIRST(&tqpair->tcp_req_free_queue);
421 	if (!tcp_req) {
422 		return NULL;
423 	}
424 
425 	memset(&tcp_req->rsp, 0, sizeof(tcp_req->rsp));
426 	tcp_req->h2c_offset = 0;
427 	tcp_req->has_in_capsule_data = false;
428 	tcp_req->req.dif_enabled = false;
429 	tcp_req->req.zcopy_phase = NVMF_ZCOPY_PHASE_NONE;
430 
431 	TAILQ_REMOVE(&tqpair->tcp_req_free_queue, tcp_req, state_link);
432 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_working_queue, tcp_req, state_link);
433 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEW);
434 	return tcp_req;
435 }
436 
437 static inline void
438 nvmf_tcp_req_put(struct spdk_nvmf_tcp_qpair *tqpair, struct spdk_nvmf_tcp_req *tcp_req)
439 {
440 	TAILQ_REMOVE(&tqpair->tcp_req_working_queue, tcp_req, state_link);
441 	TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
442 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_FREE);
443 }
444 
445 static void
446 nvmf_tcp_request_free(void *cb_arg)
447 {
448 	struct spdk_nvmf_tcp_transport *ttransport;
449 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
450 
451 	assert(tcp_req != NULL);
452 
453 	SPDK_DEBUGLOG(nvmf_tcp, "tcp_req=%p will be freed\n", tcp_req);
454 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
455 				      struct spdk_nvmf_tcp_transport, transport);
456 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
457 	nvmf_tcp_req_process(ttransport, tcp_req);
458 }
459 
460 static int
461 nvmf_tcp_req_free(struct spdk_nvmf_request *req)
462 {
463 	struct spdk_nvmf_tcp_req *tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
464 
465 	nvmf_tcp_request_free(tcp_req);
466 
467 	return 0;
468 }
469 
470 static void
471 nvmf_tcp_drain_state_queue(struct spdk_nvmf_tcp_qpair *tqpair,
472 			   enum spdk_nvmf_tcp_req_state state)
473 {
474 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
475 
476 	assert(state != TCP_REQUEST_STATE_FREE);
477 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
478 		if (state == tcp_req->state) {
479 			nvmf_tcp_request_free(tcp_req);
480 		}
481 	}
482 }
483 
484 static void
485 nvmf_tcp_cleanup_all_states(struct spdk_nvmf_tcp_qpair *tqpair)
486 {
487 	struct spdk_nvmf_tcp_req *tcp_req, *req_tmp;
488 
489 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
490 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEW);
491 
492 	/* Wipe the requests waiting for buffer from the global list */
493 	TAILQ_FOREACH_SAFE(tcp_req, &tqpair->tcp_req_working_queue, state_link, req_tmp) {
494 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
495 			STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue, &tcp_req->req,
496 				      spdk_nvmf_request, buf_link);
497 		}
498 	}
499 
500 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_NEED_BUFFER);
501 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_EXECUTING);
502 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
503 	nvmf_tcp_drain_state_queue(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
504 }
505 
506 static void
507 nvmf_tcp_dump_qpair_req_contents(struct spdk_nvmf_tcp_qpair *tqpair)
508 {
509 	int i;
510 	struct spdk_nvmf_tcp_req *tcp_req;
511 
512 	SPDK_ERRLOG("Dumping contents of queue pair (QID %d)\n", tqpair->qpair.qid);
513 	for (i = 1; i < TCP_REQUEST_NUM_STATES; i++) {
514 		SPDK_ERRLOG("\tNum of requests in state[%d] = %u\n", i, tqpair->state_cntr[i]);
515 		TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
516 			if ((int)tcp_req->state == i) {
517 				SPDK_ERRLOG("\t\tRequest Data From Pool: %d\n", tcp_req->req.data_from_pool);
518 				SPDK_ERRLOG("\t\tRequest opcode: %d\n", tcp_req->req.cmd->nvmf_cmd.opcode);
519 			}
520 		}
521 	}
522 }
523 
524 static void
525 nvmf_tcp_qpair_destroy(struct spdk_nvmf_tcp_qpair *tqpair)
526 {
527 	int err = 0;
528 
529 	spdk_trace_record(TRACE_TCP_QP_DESTROY, 0, 0, (uintptr_t)tqpair);
530 
531 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
532 
533 	err = spdk_sock_close(&tqpair->sock);
534 	assert(err == 0);
535 	nvmf_tcp_cleanup_all_states(tqpair);
536 
537 	if (tqpair->state_cntr[TCP_REQUEST_STATE_FREE] != tqpair->resource_count) {
538 		SPDK_ERRLOG("tqpair(%p) free tcp request num is %u but should be %u\n", tqpair,
539 			    tqpair->state_cntr[TCP_REQUEST_STATE_FREE],
540 			    tqpair->resource_count);
541 		err++;
542 	}
543 
544 	if (err > 0) {
545 		nvmf_tcp_dump_qpair_req_contents(tqpair);
546 	}
547 
548 	spdk_dma_free(tqpair->pdus);
549 	free(tqpair->reqs);
550 	spdk_free(tqpair->bufs);
551 	free(tqpair);
552 	SPDK_DEBUGLOG(nvmf_tcp, "Leave\n");
553 }
554 
555 static void
556 nvmf_tcp_dump_opts(struct spdk_nvmf_transport *transport, struct spdk_json_write_ctx *w)
557 {
558 	struct spdk_nvmf_tcp_transport	*ttransport;
559 	assert(w != NULL);
560 
561 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
562 	spdk_json_write_named_bool(w, "c2h_success", ttransport->tcp_opts.c2h_success);
563 	spdk_json_write_named_uint32(w, "sock_priority", ttransport->tcp_opts.sock_priority);
564 }
565 
566 static int
567 nvmf_tcp_destroy(struct spdk_nvmf_transport *transport,
568 		 spdk_nvmf_transport_destroy_done_cb cb_fn, void *cb_arg)
569 {
570 	struct spdk_nvmf_tcp_transport	*ttransport;
571 
572 	assert(transport != NULL);
573 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
574 
575 	spdk_poller_unregister(&ttransport->accept_poller);
576 	pthread_mutex_destroy(&ttransport->lock);
577 	free(ttransport);
578 
579 	if (cb_fn) {
580 		cb_fn(cb_arg);
581 	}
582 	return 0;
583 }
584 
585 static int
586 nvmf_tcp_accept(void *ctx);
587 
588 static struct spdk_nvmf_transport *
589 nvmf_tcp_create(struct spdk_nvmf_transport_opts *opts)
590 {
591 	struct spdk_nvmf_tcp_transport *ttransport;
592 	uint32_t sge_count;
593 	uint32_t min_shared_buffers;
594 
595 	ttransport = calloc(1, sizeof(*ttransport));
596 	if (!ttransport) {
597 		return NULL;
598 	}
599 
600 	TAILQ_INIT(&ttransport->ports);
601 	TAILQ_INIT(&ttransport->poll_groups);
602 
603 	ttransport->transport.ops = &spdk_nvmf_transport_tcp;
604 
605 	ttransport->tcp_opts.c2h_success = SPDK_NVMF_TCP_DEFAULT_SUCCESS_OPTIMIZATION;
606 	ttransport->tcp_opts.sock_priority = SPDK_NVMF_TCP_DEFAULT_SOCK_PRIORITY;
607 	ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
608 	if (opts->transport_specific != NULL &&
609 	    spdk_json_decode_object_relaxed(opts->transport_specific, tcp_transport_opts_decoder,
610 					    SPDK_COUNTOF(tcp_transport_opts_decoder),
611 					    &ttransport->tcp_opts)) {
612 		SPDK_ERRLOG("spdk_json_decode_object_relaxed failed\n");
613 		free(ttransport);
614 		return NULL;
615 	}
616 
617 	SPDK_NOTICELOG("*** TCP Transport Init ***\n");
618 
619 	SPDK_INFOLOG(nvmf_tcp, "*** TCP Transport Init ***\n"
620 		     "  Transport opts:  max_ioq_depth=%d, max_io_size=%d,\n"
621 		     "  max_io_qpairs_per_ctrlr=%d, io_unit_size=%d,\n"
622 		     "  in_capsule_data_size=%d, max_aq_depth=%d\n"
623 		     "  num_shared_buffers=%d, c2h_success=%d,\n"
624 		     "  dif_insert_or_strip=%d, sock_priority=%d\n"
625 		     "  abort_timeout_sec=%d, control_msg_num=%hu\n",
626 		     opts->max_queue_depth,
627 		     opts->max_io_size,
628 		     opts->max_qpairs_per_ctrlr - 1,
629 		     opts->io_unit_size,
630 		     opts->in_capsule_data_size,
631 		     opts->max_aq_depth,
632 		     opts->num_shared_buffers,
633 		     ttransport->tcp_opts.c2h_success,
634 		     opts->dif_insert_or_strip,
635 		     ttransport->tcp_opts.sock_priority,
636 		     opts->abort_timeout_sec,
637 		     ttransport->tcp_opts.control_msg_num);
638 
639 	if (ttransport->tcp_opts.sock_priority > SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY) {
640 		SPDK_ERRLOG("Unsupported socket_priority=%d, the current range is: 0 to %d\n"
641 			    "you can use man 7 socket to view the range of priority under SO_PRIORITY item\n",
642 			    ttransport->tcp_opts.sock_priority, SPDK_NVMF_TCP_DEFAULT_MAX_SOCK_PRIORITY);
643 		free(ttransport);
644 		return NULL;
645 	}
646 
647 	if (ttransport->tcp_opts.control_msg_num == 0 &&
648 	    opts->in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
649 		SPDK_WARNLOG("TCP param control_msg_num can't be 0 if ICD is less than %u bytes. Using default value %u\n",
650 			     SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE, SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM);
651 		ttransport->tcp_opts.control_msg_num = SPDK_NVMF_TCP_DEFAULT_CONTROL_MSG_NUM;
652 	}
653 
654 	/* I/O unit size cannot be larger than max I/O size */
655 	if (opts->io_unit_size > opts->max_io_size) {
656 		opts->io_unit_size = opts->max_io_size;
657 	}
658 
659 	sge_count = opts->max_io_size / opts->io_unit_size;
660 	if (sge_count > SPDK_NVMF_MAX_SGL_ENTRIES) {
661 		SPDK_ERRLOG("Unsupported IO Unit size specified, %d bytes\n", opts->io_unit_size);
662 		free(ttransport);
663 		return NULL;
664 	}
665 
666 	min_shared_buffers = spdk_env_get_core_count() * opts->buf_cache_size;
667 	if (min_shared_buffers > opts->num_shared_buffers) {
668 		SPDK_ERRLOG("There are not enough buffers to satisfy "
669 			    "per-poll group caches for each thread. (%" PRIu32 ") "
670 			    "supplied. (%" PRIu32 ") required\n", opts->num_shared_buffers, min_shared_buffers);
671 		SPDK_ERRLOG("Please specify a larger number of shared buffers\n");
672 		free(ttransport);
673 		return NULL;
674 	}
675 
676 	pthread_mutex_init(&ttransport->lock, NULL);
677 
678 	ttransport->accept_poller = SPDK_POLLER_REGISTER(nvmf_tcp_accept, &ttransport->transport,
679 				    opts->acceptor_poll_rate);
680 	if (!ttransport->accept_poller) {
681 		pthread_mutex_destroy(&ttransport->lock);
682 		free(ttransport);
683 		return NULL;
684 	}
685 
686 	return &ttransport->transport;
687 }
688 
689 static int
690 nvmf_tcp_trsvcid_to_int(const char *trsvcid)
691 {
692 	unsigned long long ull;
693 	char *end = NULL;
694 
695 	ull = strtoull(trsvcid, &end, 10);
696 	if (end == NULL || end == trsvcid || *end != '\0') {
697 		return -1;
698 	}
699 
700 	/* Valid TCP/IP port numbers are in [0, 65535] */
701 	if (ull > 65535) {
702 		return -1;
703 	}
704 
705 	return (int)ull;
706 }
707 
708 /**
709  * Canonicalize a listen address trid.
710  */
711 static int
712 nvmf_tcp_canon_listen_trid(struct spdk_nvme_transport_id *canon_trid,
713 			   const struct spdk_nvme_transport_id *trid)
714 {
715 	int trsvcid_int;
716 
717 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
718 	if (trsvcid_int < 0) {
719 		return -EINVAL;
720 	}
721 
722 	memset(canon_trid, 0, sizeof(*canon_trid));
723 	spdk_nvme_trid_populate_transport(canon_trid, SPDK_NVME_TRANSPORT_TCP);
724 	canon_trid->adrfam = trid->adrfam;
725 	snprintf(canon_trid->traddr, sizeof(canon_trid->traddr), "%s", trid->traddr);
726 	snprintf(canon_trid->trsvcid, sizeof(canon_trid->trsvcid), "%d", trsvcid_int);
727 
728 	return 0;
729 }
730 
731 /**
732  * Find an existing listening port.
733  *
734  * Caller must hold ttransport->lock.
735  */
736 static struct spdk_nvmf_tcp_port *
737 nvmf_tcp_find_port(struct spdk_nvmf_tcp_transport *ttransport,
738 		   const struct spdk_nvme_transport_id *trid)
739 {
740 	struct spdk_nvme_transport_id canon_trid;
741 	struct spdk_nvmf_tcp_port *port;
742 
743 	if (nvmf_tcp_canon_listen_trid(&canon_trid, trid) != 0) {
744 		return NULL;
745 	}
746 
747 	TAILQ_FOREACH(port, &ttransport->ports, link) {
748 		if (spdk_nvme_transport_id_compare(&canon_trid, port->trid) == 0) {
749 			return port;
750 		}
751 	}
752 
753 	return NULL;
754 }
755 
756 static int
757 nvmf_tcp_listen(struct spdk_nvmf_transport *transport, const struct spdk_nvme_transport_id *trid,
758 		struct spdk_nvmf_listen_opts *listen_opts)
759 {
760 	struct spdk_nvmf_tcp_transport *ttransport;
761 	struct spdk_nvmf_tcp_port *port;
762 	int trsvcid_int;
763 	uint8_t adrfam;
764 	struct spdk_sock_opts opts;
765 
766 	if (!strlen(trid->trsvcid)) {
767 		SPDK_ERRLOG("Service id is required\n");
768 		return -EINVAL;
769 	}
770 
771 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
772 
773 	trsvcid_int = nvmf_tcp_trsvcid_to_int(trid->trsvcid);
774 	if (trsvcid_int < 0) {
775 		SPDK_ERRLOG("Invalid trsvcid '%s'\n", trid->trsvcid);
776 		return -EINVAL;
777 	}
778 
779 	pthread_mutex_lock(&ttransport->lock);
780 	port = calloc(1, sizeof(*port));
781 	if (!port) {
782 		SPDK_ERRLOG("Port allocation failed\n");
783 		pthread_mutex_unlock(&ttransport->lock);
784 		return -ENOMEM;
785 	}
786 
787 	port->trid = trid;
788 	opts.opts_size = sizeof(opts);
789 	spdk_sock_get_default_opts(&opts);
790 	opts.priority = ttransport->tcp_opts.sock_priority;
791 	port->listen_sock = spdk_sock_listen_ext(trid->traddr, trsvcid_int,
792 			    NULL, &opts);
793 	if (port->listen_sock == NULL) {
794 		SPDK_ERRLOG("spdk_sock_listen(%s, %d) failed: %s (%d)\n",
795 			    trid->traddr, trsvcid_int,
796 			    spdk_strerror(errno), errno);
797 		free(port);
798 		pthread_mutex_unlock(&ttransport->lock);
799 		return -errno;
800 	}
801 
802 	if (spdk_sock_is_ipv4(port->listen_sock)) {
803 		adrfam = SPDK_NVMF_ADRFAM_IPV4;
804 	} else if (spdk_sock_is_ipv6(port->listen_sock)) {
805 		adrfam = SPDK_NVMF_ADRFAM_IPV6;
806 	} else {
807 		SPDK_ERRLOG("Unhandled socket type\n");
808 		adrfam = 0;
809 	}
810 
811 	if (adrfam != trid->adrfam) {
812 		SPDK_ERRLOG("Socket address family mismatch\n");
813 		spdk_sock_close(&port->listen_sock);
814 		free(port);
815 		pthread_mutex_unlock(&ttransport->lock);
816 		return -EINVAL;
817 	}
818 
819 	SPDK_NOTICELOG("*** NVMe/TCP Target Listening on %s port %s ***\n",
820 		       trid->traddr, trid->trsvcid);
821 
822 	TAILQ_INSERT_TAIL(&ttransport->ports, port, link);
823 	pthread_mutex_unlock(&ttransport->lock);
824 	return 0;
825 }
826 
827 static void
828 nvmf_tcp_stop_listen(struct spdk_nvmf_transport *transport,
829 		     const struct spdk_nvme_transport_id *trid)
830 {
831 	struct spdk_nvmf_tcp_transport *ttransport;
832 	struct spdk_nvmf_tcp_port *port;
833 
834 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
835 
836 	SPDK_DEBUGLOG(nvmf_tcp, "Removing listen address %s port %s\n",
837 		      trid->traddr, trid->trsvcid);
838 
839 	pthread_mutex_lock(&ttransport->lock);
840 	port = nvmf_tcp_find_port(ttransport, trid);
841 	if (port) {
842 		TAILQ_REMOVE(&ttransport->ports, port, link);
843 		spdk_sock_close(&port->listen_sock);
844 		free(port);
845 	}
846 
847 	pthread_mutex_unlock(&ttransport->lock);
848 }
849 
850 static void nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
851 		enum nvme_tcp_pdu_recv_state state);
852 
853 static void
854 nvmf_tcp_qpair_set_state(struct spdk_nvmf_tcp_qpair *tqpair, enum nvme_tcp_qpair_state state)
855 {
856 	tqpair->state = state;
857 	spdk_trace_record(TRACE_TCP_QP_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->state);
858 }
859 
860 static void
861 nvmf_tcp_qpair_disconnect(struct spdk_nvmf_tcp_qpair *tqpair)
862 {
863 	SPDK_DEBUGLOG(nvmf_tcp, "Disconnecting qpair %p\n", tqpair);
864 
865 	spdk_trace_record(TRACE_TCP_QP_DISCONNECT, 0, 0, (uintptr_t)tqpair);
866 
867 	if (tqpair->state <= NVME_TCP_QPAIR_STATE_RUNNING) {
868 		nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITING);
869 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
870 		spdk_poller_unregister(&tqpair->timeout_poller);
871 
872 		/* This will end up calling nvmf_tcp_close_qpair */
873 		spdk_nvmf_qpair_disconnect(&tqpair->qpair, NULL, NULL);
874 	}
875 }
876 
877 static void
878 _pdu_write_done(void *_pdu, int err)
879 {
880 	struct nvme_tcp_pdu			*pdu = _pdu;
881 	struct spdk_nvmf_tcp_qpair		*tqpair = pdu->qpair;
882 
883 	if (err != 0) {
884 		nvmf_tcp_qpair_disconnect(tqpair);
885 		return;
886 	}
887 
888 	assert(pdu->cb_fn != NULL);
889 	pdu->cb_fn(pdu->cb_arg);
890 }
891 
892 static void
893 _tcp_write_pdu(struct nvme_tcp_pdu *pdu)
894 {
895 	uint32_t mapped_length = 0;
896 	ssize_t rc;
897 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
898 
899 	pdu->sock_req.iovcnt = nvme_tcp_build_iovs(pdu->iov, SPDK_COUNTOF(pdu->iov), pdu,
900 			       tqpair->host_hdgst_enable, tqpair->host_ddgst_enable,
901 			       &mapped_length);
902 	pdu->sock_req.cb_fn = _pdu_write_done;
903 	pdu->sock_req.cb_arg = pdu;
904 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_RESP ||
905 	    pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ) {
906 		rc = spdk_sock_writev(tqpair->sock, pdu->iov, pdu->sock_req.iovcnt);
907 		if (rc == mapped_length) {
908 			_pdu_write_done(pdu, 0);
909 		} else {
910 			SPDK_ERRLOG("IC_RESP or TERM_REQ could not write to socket.\n");
911 			_pdu_write_done(pdu, -1);
912 		}
913 	} else {
914 		spdk_sock_writev_async(tqpair->sock, &pdu->sock_req);
915 	}
916 }
917 
918 static void
919 data_crc32_accel_done(void *cb_arg, int status)
920 {
921 	struct nvme_tcp_pdu *pdu = cb_arg;
922 
923 	if (spdk_unlikely(status)) {
924 		SPDK_ERRLOG("Failed to compute the data digest for pdu =%p\n", pdu);
925 		_pdu_write_done(pdu, status);
926 		return;
927 	}
928 
929 	pdu->data_digest_crc32 ^= SPDK_CRC32C_XOR;
930 	MAKE_DIGEST_WORD(pdu->data_digest, pdu->data_digest_crc32);
931 
932 	_tcp_write_pdu(pdu);
933 }
934 
935 static void
936 pdu_data_crc32_compute(struct nvme_tcp_pdu *pdu)
937 {
938 	struct spdk_nvmf_tcp_qpair *tqpair = pdu->qpair;
939 	uint32_t crc32c;
940 
941 	/* Data Digest */
942 	if (pdu->data_len > 0 && g_nvme_tcp_ddgst[pdu->hdr.common.pdu_type] && tqpair->host_ddgst_enable) {
943 		/* Only suport this limitated case for the first step */
944 		if (spdk_likely(!pdu->dif_ctx && (pdu->data_len % SPDK_NVME_TCP_DIGEST_ALIGNMENT == 0)
945 				&& tqpair->group)) {
946 			spdk_accel_submit_crc32cv(tqpair->group->accel_channel, &pdu->data_digest_crc32,
947 						  pdu->data_iov, pdu->data_iovcnt, 0, data_crc32_accel_done, pdu);
948 			return;
949 		}
950 
951 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
952 		MAKE_DIGEST_WORD(pdu->data_digest, crc32c);
953 	}
954 
955 	_tcp_write_pdu(pdu);
956 }
957 
958 static void
959 nvmf_tcp_qpair_write_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
960 			 struct nvme_tcp_pdu *pdu,
961 			 nvme_tcp_qpair_xfer_complete_cb cb_fn,
962 			 void *cb_arg)
963 {
964 	int hlen;
965 	uint32_t crc32c;
966 
967 	assert(tqpair->pdu_in_progress != pdu);
968 
969 	hlen = pdu->hdr.common.hlen;
970 	pdu->cb_fn = cb_fn;
971 	pdu->cb_arg = cb_arg;
972 
973 	pdu->iov[0].iov_base = &pdu->hdr.raw;
974 	pdu->iov[0].iov_len = hlen;
975 
976 	/* Header Digest */
977 	if (g_nvme_tcp_hdgst[pdu->hdr.common.pdu_type] && tqpair->host_hdgst_enable) {
978 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
979 		MAKE_DIGEST_WORD((uint8_t *)pdu->hdr.raw + hlen, crc32c);
980 	}
981 
982 	/* Data Digest */
983 	pdu_data_crc32_compute(pdu);
984 }
985 
986 static int
987 nvmf_tcp_qpair_init_mem_resource(struct spdk_nvmf_tcp_qpair *tqpair)
988 {
989 	uint32_t i;
990 	struct spdk_nvmf_transport_opts *opts;
991 	uint32_t in_capsule_data_size;
992 
993 	opts = &tqpair->qpair.transport->opts;
994 
995 	in_capsule_data_size = opts->in_capsule_data_size;
996 	if (opts->dif_insert_or_strip) {
997 		in_capsule_data_size = SPDK_BDEV_BUF_SIZE_WITH_MD(in_capsule_data_size);
998 	}
999 
1000 	tqpair->resource_count = opts->max_queue_depth;
1001 
1002 	tqpair->reqs = calloc(tqpair->resource_count, sizeof(*tqpair->reqs));
1003 	if (!tqpair->reqs) {
1004 		SPDK_ERRLOG("Unable to allocate reqs on tqpair=%p\n", tqpair);
1005 		return -1;
1006 	}
1007 
1008 	if (in_capsule_data_size) {
1009 		tqpair->bufs = spdk_zmalloc(tqpair->resource_count * in_capsule_data_size, 0x1000,
1010 					    NULL, SPDK_ENV_LCORE_ID_ANY,
1011 					    SPDK_MALLOC_DMA);
1012 		if (!tqpair->bufs) {
1013 			SPDK_ERRLOG("Unable to allocate bufs on tqpair=%p.\n", tqpair);
1014 			return -1;
1015 		}
1016 	}
1017 
1018 	/* Add additional 2 members, which will be used for mgmt_pdu and pdu_in_progress owned by the tqpair */
1019 	tqpair->pdus = spdk_dma_zmalloc((tqpair->resource_count + 2) * sizeof(*tqpair->pdus), 0x1000, NULL);
1020 	if (!tqpair->pdus) {
1021 		SPDK_ERRLOG("Unable to allocate pdu pool on tqpair =%p.\n", tqpair);
1022 		return -1;
1023 	}
1024 
1025 	for (i = 0; i < tqpair->resource_count; i++) {
1026 		struct spdk_nvmf_tcp_req *tcp_req = &tqpair->reqs[i];
1027 
1028 		tcp_req->ttag = i + 1;
1029 		tcp_req->req.qpair = &tqpair->qpair;
1030 
1031 		tcp_req->pdu = &tqpair->pdus[i];
1032 		tcp_req->pdu->qpair = tqpair;
1033 
1034 		/* Set up memory to receive commands */
1035 		if (tqpair->bufs) {
1036 			tcp_req->buf = (void *)((uintptr_t)tqpair->bufs + (i * in_capsule_data_size));
1037 		}
1038 
1039 		/* Set the cmdn and rsp */
1040 		tcp_req->req.rsp = (union nvmf_c2h_msg *)&tcp_req->rsp;
1041 		tcp_req->req.cmd = (union nvmf_h2c_msg *)&tcp_req->cmd;
1042 
1043 		/* Initialize request state to FREE */
1044 		tcp_req->state = TCP_REQUEST_STATE_FREE;
1045 		TAILQ_INSERT_TAIL(&tqpair->tcp_req_free_queue, tcp_req, state_link);
1046 		tqpair->state_cntr[TCP_REQUEST_STATE_FREE]++;
1047 	}
1048 
1049 	tqpair->mgmt_pdu = &tqpair->pdus[i];
1050 	tqpair->mgmt_pdu->qpair = tqpair;
1051 	tqpair->pdu_in_progress = &tqpair->pdus[i + 1];
1052 
1053 	tqpair->recv_buf_size = (in_capsule_data_size + sizeof(struct spdk_nvme_tcp_cmd) + 2 *
1054 				 SPDK_NVME_TCP_DIGEST_LEN) * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1055 
1056 	return 0;
1057 }
1058 
1059 static int
1060 nvmf_tcp_qpair_init(struct spdk_nvmf_qpair *qpair)
1061 {
1062 	struct spdk_nvmf_tcp_qpair *tqpair;
1063 
1064 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1065 
1066 	SPDK_DEBUGLOG(nvmf_tcp, "New TCP Connection: %p\n", qpair);
1067 
1068 	spdk_trace_record(TRACE_TCP_QP_CREATE, 0, 0, (uintptr_t)tqpair);
1069 
1070 	/* Initialise request state queues of the qpair */
1071 	TAILQ_INIT(&tqpair->tcp_req_free_queue);
1072 	TAILQ_INIT(&tqpair->tcp_req_working_queue);
1073 
1074 	tqpair->host_hdgst_enable = true;
1075 	tqpair->host_ddgst_enable = true;
1076 
1077 	return 0;
1078 }
1079 
1080 static int
1081 nvmf_tcp_qpair_sock_init(struct spdk_nvmf_tcp_qpair *tqpair)
1082 {
1083 	int rc;
1084 
1085 	spdk_trace_record(TRACE_TCP_QP_SOCK_INIT, 0, 0, (uintptr_t)tqpair);
1086 
1087 	/* set low water mark */
1088 	rc = spdk_sock_set_recvlowat(tqpair->sock, sizeof(struct spdk_nvme_tcp_common_pdu_hdr));
1089 	if (rc != 0) {
1090 		SPDK_ERRLOG("spdk_sock_set_recvlowat() failed\n");
1091 		return rc;
1092 	}
1093 
1094 	return 0;
1095 }
1096 
1097 static void
1098 nvmf_tcp_handle_connect(struct spdk_nvmf_transport *transport,
1099 			struct spdk_nvmf_tcp_port *port,
1100 			struct spdk_sock *sock)
1101 {
1102 	struct spdk_nvmf_tcp_qpair *tqpair;
1103 	int rc;
1104 
1105 	SPDK_DEBUGLOG(nvmf_tcp, "New connection accepted on %s port %s\n",
1106 		      port->trid->traddr, port->trid->trsvcid);
1107 
1108 	tqpair = calloc(1, sizeof(struct spdk_nvmf_tcp_qpair));
1109 	if (tqpair == NULL) {
1110 		SPDK_ERRLOG("Could not allocate new connection.\n");
1111 		spdk_sock_close(&sock);
1112 		return;
1113 	}
1114 
1115 	tqpair->sock = sock;
1116 	tqpair->state_cntr[TCP_REQUEST_STATE_FREE] = 0;
1117 	tqpair->port = port;
1118 	tqpair->qpair.transport = transport;
1119 
1120 	rc = spdk_sock_getaddr(tqpair->sock, tqpair->target_addr,
1121 			       sizeof(tqpair->target_addr), &tqpair->target_port,
1122 			       tqpair->initiator_addr, sizeof(tqpair->initiator_addr),
1123 			       &tqpair->initiator_port);
1124 	if (rc < 0) {
1125 		SPDK_ERRLOG("spdk_sock_getaddr() failed of tqpair=%p\n", tqpair);
1126 		nvmf_tcp_qpair_destroy(tqpair);
1127 		return;
1128 	}
1129 
1130 	spdk_nvmf_tgt_new_qpair(transport->tgt, &tqpair->qpair);
1131 }
1132 
1133 static uint32_t
1134 nvmf_tcp_port_accept(struct spdk_nvmf_transport *transport, struct spdk_nvmf_tcp_port *port)
1135 {
1136 	struct spdk_sock *sock;
1137 	uint32_t count = 0;
1138 	int i;
1139 
1140 	for (i = 0; i < NVMF_TCP_MAX_ACCEPT_SOCK_ONE_TIME; i++) {
1141 		sock = spdk_sock_accept(port->listen_sock);
1142 		if (sock == NULL) {
1143 			break;
1144 		}
1145 		count++;
1146 		nvmf_tcp_handle_connect(transport, port, sock);
1147 	}
1148 
1149 	return count;
1150 }
1151 
1152 static int
1153 nvmf_tcp_accept(void *ctx)
1154 {
1155 	struct spdk_nvmf_transport *transport = ctx;
1156 	struct spdk_nvmf_tcp_transport *ttransport;
1157 	struct spdk_nvmf_tcp_port *port;
1158 	uint32_t count = 0;
1159 
1160 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1161 
1162 	TAILQ_FOREACH(port, &ttransport->ports, link) {
1163 		count += nvmf_tcp_port_accept(transport, port);
1164 	}
1165 
1166 	return count > 0 ? SPDK_POLLER_BUSY : SPDK_POLLER_IDLE;
1167 }
1168 
1169 static void
1170 nvmf_tcp_discover(struct spdk_nvmf_transport *transport,
1171 		  struct spdk_nvme_transport_id *trid,
1172 		  struct spdk_nvmf_discovery_log_page_entry *entry)
1173 {
1174 	entry->trtype = SPDK_NVMF_TRTYPE_TCP;
1175 	entry->adrfam = trid->adrfam;
1176 	entry->treq.secure_channel = SPDK_NVMF_TREQ_SECURE_CHANNEL_NOT_REQUIRED;
1177 
1178 	spdk_strcpy_pad(entry->trsvcid, trid->trsvcid, sizeof(entry->trsvcid), ' ');
1179 	spdk_strcpy_pad(entry->traddr, trid->traddr, sizeof(entry->traddr), ' ');
1180 
1181 	entry->tsas.tcp.sectype = SPDK_NVME_TCP_SECURITY_NONE;
1182 }
1183 
1184 static struct spdk_nvmf_tcp_control_msg_list *
1185 nvmf_tcp_control_msg_list_create(uint16_t num_messages)
1186 {
1187 	struct spdk_nvmf_tcp_control_msg_list *list;
1188 	struct spdk_nvmf_tcp_control_msg *msg;
1189 	uint16_t i;
1190 
1191 	list = calloc(1, sizeof(*list));
1192 	if (!list) {
1193 		SPDK_ERRLOG("Failed to allocate memory for list structure\n");
1194 		return NULL;
1195 	}
1196 
1197 	list->msg_buf = spdk_zmalloc(num_messages * SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE,
1198 				     NVMF_DATA_BUFFER_ALIGNMENT, NULL, SPDK_ENV_SOCKET_ID_ANY, SPDK_MALLOC_DMA);
1199 	if (!list->msg_buf) {
1200 		SPDK_ERRLOG("Failed to allocate memory for control message buffers\n");
1201 		free(list);
1202 		return NULL;
1203 	}
1204 
1205 	STAILQ_INIT(&list->free_msgs);
1206 
1207 	for (i = 0; i < num_messages; i++) {
1208 		msg = (struct spdk_nvmf_tcp_control_msg *)((char *)list->msg_buf + i *
1209 				SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1210 		STAILQ_INSERT_TAIL(&list->free_msgs, msg, link);
1211 	}
1212 
1213 	return list;
1214 }
1215 
1216 static void
1217 nvmf_tcp_control_msg_list_free(struct spdk_nvmf_tcp_control_msg_list *list)
1218 {
1219 	if (!list) {
1220 		return;
1221 	}
1222 
1223 	spdk_free(list->msg_buf);
1224 	free(list);
1225 }
1226 
1227 static struct spdk_nvmf_transport_poll_group *
1228 nvmf_tcp_poll_group_create(struct spdk_nvmf_transport *transport,
1229 			   struct spdk_nvmf_poll_group *group)
1230 {
1231 	struct spdk_nvmf_tcp_transport	*ttransport;
1232 	struct spdk_nvmf_tcp_poll_group *tgroup;
1233 
1234 	tgroup = calloc(1, sizeof(*tgroup));
1235 	if (!tgroup) {
1236 		return NULL;
1237 	}
1238 
1239 	tgroup->sock_group = spdk_sock_group_create(&tgroup->group);
1240 	if (!tgroup->sock_group) {
1241 		goto cleanup;
1242 	}
1243 
1244 	TAILQ_INIT(&tgroup->qpairs);
1245 	TAILQ_INIT(&tgroup->await_req);
1246 
1247 	ttransport = SPDK_CONTAINEROF(transport, struct spdk_nvmf_tcp_transport, transport);
1248 
1249 	if (transport->opts.in_capsule_data_size < SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE) {
1250 		SPDK_DEBUGLOG(nvmf_tcp, "ICD %u is less than min required for admin/fabric commands (%u). "
1251 			      "Creating control messages list\n", transport->opts.in_capsule_data_size,
1252 			      SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE);
1253 		tgroup->control_msg_list = nvmf_tcp_control_msg_list_create(ttransport->tcp_opts.control_msg_num);
1254 		if (!tgroup->control_msg_list) {
1255 			goto cleanup;
1256 		}
1257 	}
1258 
1259 	tgroup->accel_channel = spdk_accel_engine_get_io_channel();
1260 	if (spdk_unlikely(!tgroup->accel_channel)) {
1261 		SPDK_ERRLOG("Cannot create accel_channel for tgroup=%p\n", tgroup);
1262 		goto cleanup;
1263 	}
1264 
1265 	pthread_mutex_lock(&ttransport->lock);
1266 	TAILQ_INSERT_TAIL(&ttransport->poll_groups, tgroup, link);
1267 	if (ttransport->next_pg == NULL) {
1268 		ttransport->next_pg = tgroup;
1269 	}
1270 	pthread_mutex_unlock(&ttransport->lock);
1271 
1272 	return &tgroup->group;
1273 
1274 cleanup:
1275 	nvmf_tcp_poll_group_destroy(&tgroup->group);
1276 	return NULL;
1277 }
1278 
1279 static struct spdk_nvmf_transport_poll_group *
1280 nvmf_tcp_get_optimal_poll_group(struct spdk_nvmf_qpair *qpair)
1281 {
1282 	struct spdk_nvmf_tcp_transport *ttransport;
1283 	struct spdk_nvmf_transport_poll_group *result;
1284 	struct spdk_nvmf_tcp_poll_group **pg;
1285 	struct spdk_nvmf_tcp_qpair *tqpair;
1286 	struct spdk_sock_group *group = NULL;
1287 	int rc;
1288 
1289 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
1290 	rc = spdk_sock_get_optimal_sock_group(tqpair->sock, &group);
1291 	if (!rc && group != NULL) {
1292 		return spdk_sock_group_get_ctx(group);
1293 	}
1294 
1295 	ttransport = SPDK_CONTAINEROF(qpair->transport, struct spdk_nvmf_tcp_transport, transport);
1296 
1297 	pthread_mutex_lock(&ttransport->lock);
1298 
1299 	if (TAILQ_EMPTY(&ttransport->poll_groups)) {
1300 		pthread_mutex_unlock(&ttransport->lock);
1301 		return NULL;
1302 	}
1303 
1304 	pg = &ttransport->next_pg;
1305 	assert(*pg != NULL);
1306 
1307 	result = &(*pg)->group;
1308 
1309 	*pg = TAILQ_NEXT(*pg, link);
1310 	if (*pg == NULL) {
1311 		*pg = TAILQ_FIRST(&ttransport->poll_groups);
1312 	}
1313 
1314 	pthread_mutex_unlock(&ttransport->lock);
1315 	return result;
1316 }
1317 
1318 static void
1319 nvmf_tcp_poll_group_destroy(struct spdk_nvmf_transport_poll_group *group)
1320 {
1321 	struct spdk_nvmf_tcp_poll_group *tgroup, *next_tgroup;
1322 	struct spdk_nvmf_tcp_transport *ttransport;
1323 
1324 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
1325 	spdk_sock_group_close(&tgroup->sock_group);
1326 	if (tgroup->control_msg_list) {
1327 		nvmf_tcp_control_msg_list_free(tgroup->control_msg_list);
1328 	}
1329 
1330 	if (tgroup->accel_channel) {
1331 		spdk_put_io_channel(tgroup->accel_channel);
1332 	}
1333 
1334 	ttransport = SPDK_CONTAINEROF(tgroup->group.transport, struct spdk_nvmf_tcp_transport, transport);
1335 
1336 	pthread_mutex_lock(&ttransport->lock);
1337 	next_tgroup = TAILQ_NEXT(tgroup, link);
1338 	TAILQ_REMOVE(&ttransport->poll_groups, tgroup, link);
1339 	if (next_tgroup == NULL) {
1340 		next_tgroup = TAILQ_FIRST(&ttransport->poll_groups);
1341 	}
1342 	if (ttransport->next_pg == tgroup) {
1343 		ttransport->next_pg = next_tgroup;
1344 	}
1345 	pthread_mutex_unlock(&ttransport->lock);
1346 
1347 	free(tgroup);
1348 }
1349 
1350 static void
1351 nvmf_tcp_qpair_set_recv_state(struct spdk_nvmf_tcp_qpair *tqpair,
1352 			      enum nvme_tcp_pdu_recv_state state)
1353 {
1354 	if (tqpair->recv_state == state) {
1355 		SPDK_ERRLOG("The recv state of tqpair=%p is same with the state(%d) to be set\n",
1356 			    tqpair, state);
1357 		return;
1358 	}
1359 
1360 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
1361 		/* When leaving the await req state, move the qpair to the main list */
1362 		TAILQ_REMOVE(&tqpair->group->await_req, tqpair, link);
1363 		TAILQ_INSERT_TAIL(&tqpair->group->qpairs, tqpair, link);
1364 	}
1365 
1366 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv state=%d\n", tqpair, state);
1367 	tqpair->recv_state = state;
1368 
1369 	spdk_trace_record(TRACE_TCP_QP_RCV_STATE_CHANGE, 0, 0, (uintptr_t)tqpair, tqpair->recv_state);
1370 
1371 	switch (state) {
1372 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
1373 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
1374 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
1375 		break;
1376 	case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
1377 		TAILQ_REMOVE(&tqpair->group->qpairs, tqpair, link);
1378 		TAILQ_INSERT_TAIL(&tqpair->group->await_req, tqpair, link);
1379 		break;
1380 	case NVME_TCP_PDU_RECV_STATE_ERROR:
1381 	case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
1382 		memset(tqpair->pdu_in_progress, 0, sizeof(*(tqpair->pdu_in_progress)));
1383 		break;
1384 	default:
1385 		SPDK_ERRLOG("The state(%d) is invalid\n", state);
1386 		abort();
1387 		break;
1388 	}
1389 }
1390 
1391 static int
1392 nvmf_tcp_qpair_handle_timeout(void *ctx)
1393 {
1394 	struct spdk_nvmf_tcp_qpair *tqpair = ctx;
1395 
1396 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_ERROR);
1397 
1398 	SPDK_ERRLOG("No pdu coming for tqpair=%p within %d seconds\n", tqpair,
1399 		    SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT);
1400 
1401 	nvmf_tcp_qpair_disconnect(tqpair);
1402 	return SPDK_POLLER_BUSY;
1403 }
1404 
1405 static void
1406 nvmf_tcp_send_c2h_term_req_complete(void *cb_arg)
1407 {
1408 	struct spdk_nvmf_tcp_qpair *tqpair = (struct spdk_nvmf_tcp_qpair *)cb_arg;
1409 
1410 	if (!tqpair->timeout_poller) {
1411 		tqpair->timeout_poller = SPDK_POLLER_REGISTER(nvmf_tcp_qpair_handle_timeout, tqpair,
1412 					 SPDK_NVME_TCP_QPAIR_EXIT_TIMEOUT * 1000000);
1413 	}
1414 }
1415 
1416 static void
1417 nvmf_tcp_send_c2h_term_req(struct spdk_nvmf_tcp_qpair *tqpair, struct nvme_tcp_pdu *pdu,
1418 			   enum spdk_nvme_tcp_term_req_fes fes, uint32_t error_offset)
1419 {
1420 	struct nvme_tcp_pdu *rsp_pdu;
1421 	struct spdk_nvme_tcp_term_req_hdr *c2h_term_req;
1422 	uint32_t c2h_term_req_hdr_len = sizeof(*c2h_term_req);
1423 	uint32_t copy_len;
1424 
1425 	rsp_pdu = tqpair->mgmt_pdu;
1426 
1427 	c2h_term_req = &rsp_pdu->hdr.term_req;
1428 	c2h_term_req->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_TERM_REQ;
1429 	c2h_term_req->common.hlen = c2h_term_req_hdr_len;
1430 
1431 	if ((fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1432 	    (fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1433 		DSET32(&c2h_term_req->fei, error_offset);
1434 	}
1435 
1436 	copy_len = spdk_min(pdu->hdr.common.hlen, SPDK_NVME_TCP_TERM_REQ_ERROR_DATA_MAX_SIZE);
1437 
1438 	/* Copy the error info into the buffer */
1439 	memcpy((uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, pdu->hdr.raw, copy_len);
1440 	nvme_tcp_pdu_set_data(rsp_pdu, (uint8_t *)rsp_pdu->hdr.raw + c2h_term_req_hdr_len, copy_len);
1441 
1442 	/* Contain the header of the wrong received pdu */
1443 	c2h_term_req->common.plen = c2h_term_req->common.hlen + copy_len;
1444 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1445 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_c2h_term_req_complete, tqpair);
1446 }
1447 
1448 static void
1449 nvmf_tcp_capsule_cmd_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1450 				struct spdk_nvmf_tcp_qpair *tqpair,
1451 				struct nvme_tcp_pdu *pdu)
1452 {
1453 	struct spdk_nvmf_tcp_req *tcp_req;
1454 
1455 	assert(pdu->psh_valid_bytes == pdu->psh_len);
1456 	assert(pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD);
1457 
1458 	tcp_req = nvmf_tcp_req_get(tqpair);
1459 	if (!tcp_req) {
1460 		/* Directly return and make the allocation retry again.  This can happen if we're
1461 		 * using asynchronous writes to send the response to the host or when releasing
1462 		 * zero-copy buffers after a response has been sent.  In both cases, the host might
1463 		 * receive the response before we've finished processing the request and is free to
1464 		 * send another one.
1465 		 */
1466 		if (tqpair->state_cntr[TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST] > 0 ||
1467 		    tqpair->state_cntr[TCP_REQUEST_STATE_AWAITING_ZCOPY_RELEASE] > 0) {
1468 			return;
1469 		}
1470 
1471 		/* The host sent more commands than the maximum queue depth. */
1472 		SPDK_ERRLOG("Cannot allocate tcp_req on tqpair=%p\n", tqpair);
1473 		nvmf_tcp_qpair_disconnect(tqpair);
1474 		return;
1475 	}
1476 
1477 	pdu->req = tcp_req;
1478 	assert(tcp_req->state == TCP_REQUEST_STATE_NEW);
1479 	nvmf_tcp_req_process(ttransport, tcp_req);
1480 }
1481 
1482 static void
1483 nvmf_tcp_capsule_cmd_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1484 				    struct spdk_nvmf_tcp_qpair *tqpair,
1485 				    struct nvme_tcp_pdu *pdu)
1486 {
1487 	struct spdk_nvmf_tcp_req *tcp_req;
1488 	struct spdk_nvme_tcp_cmd *capsule_cmd;
1489 	uint32_t error_offset = 0;
1490 	enum spdk_nvme_tcp_term_req_fes fes;
1491 	struct spdk_nvme_cpl *rsp;
1492 
1493 	capsule_cmd = &pdu->hdr.capsule_cmd;
1494 	tcp_req = pdu->req;
1495 	assert(tcp_req != NULL);
1496 
1497 	/* Zero-copy requests don't support ICD */
1498 	assert(!spdk_nvmf_request_using_zcopy(&tcp_req->req));
1499 
1500 	if (capsule_cmd->common.pdo > SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET) {
1501 		SPDK_ERRLOG("Expected ICReq capsule_cmd pdu offset <= %d, got %c\n",
1502 			    SPDK_NVME_TCP_PDU_PDO_MAX_OFFSET, capsule_cmd->common.pdo);
1503 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1504 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
1505 		goto err;
1506 	}
1507 
1508 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1509 
1510 	rsp = &tcp_req->req.rsp->nvme_cpl;
1511 	if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1512 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1513 	} else {
1514 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1515 	}
1516 
1517 	nvmf_tcp_req_process(ttransport, tcp_req);
1518 
1519 	return;
1520 err:
1521 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1522 }
1523 
1524 static int
1525 nvmf_tcp_find_req_in_state(struct spdk_nvmf_tcp_qpair *tqpair,
1526 			   enum spdk_nvmf_tcp_req_state state,
1527 			   uint16_t cid, uint16_t tag,
1528 			   struct spdk_nvmf_tcp_req **req)
1529 {
1530 	struct spdk_nvmf_tcp_req *tcp_req = NULL;
1531 
1532 	TAILQ_FOREACH(tcp_req, &tqpair->tcp_req_working_queue, state_link) {
1533 		if (tcp_req->state != state) {
1534 			continue;
1535 		}
1536 
1537 		if (tcp_req->req.cmd->nvme_cmd.cid != cid) {
1538 			continue;
1539 		}
1540 
1541 		if (tcp_req->ttag == tag) {
1542 			*req = tcp_req;
1543 			return 0;
1544 		}
1545 
1546 		*req = NULL;
1547 		return -1;
1548 	}
1549 
1550 	/* Didn't find it, but not an error */
1551 	*req = NULL;
1552 	return 0;
1553 }
1554 
1555 static void
1556 nvmf_tcp_h2c_data_hdr_handle(struct spdk_nvmf_tcp_transport *ttransport,
1557 			     struct spdk_nvmf_tcp_qpair *tqpair,
1558 			     struct nvme_tcp_pdu *pdu)
1559 {
1560 	struct spdk_nvmf_tcp_req *tcp_req;
1561 	uint32_t error_offset = 0;
1562 	enum spdk_nvme_tcp_term_req_fes fes = 0;
1563 	struct spdk_nvme_tcp_h2c_data_hdr *h2c_data;
1564 	int rc;
1565 
1566 	h2c_data = &pdu->hdr.h2c_data;
1567 
1568 	SPDK_DEBUGLOG(nvmf_tcp, "tqpair=%p, r2t_info: datao=%u, datal=%u, cccid=%u, ttag=%u\n",
1569 		      tqpair, h2c_data->datao, h2c_data->datal, h2c_data->cccid, h2c_data->ttag);
1570 
1571 	rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER,
1572 					h2c_data->cccid, h2c_data->ttag, &tcp_req);
1573 	if (rc == 0 && tcp_req == NULL) {
1574 		rc = nvmf_tcp_find_req_in_state(tqpair, TCP_REQUEST_STATE_AWAITING_R2T_ACK, h2c_data->cccid,
1575 						h2c_data->ttag, &tcp_req);
1576 	}
1577 
1578 	if (!tcp_req) {
1579 		SPDK_DEBUGLOG(nvmf_tcp, "tcp_req is not found for tqpair=%p\n", tqpair);
1580 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER;
1581 		if (rc == 0) {
1582 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, cccid);
1583 		} else {
1584 			error_offset = offsetof(struct spdk_nvme_tcp_h2c_data_hdr, ttag);
1585 		}
1586 		goto err;
1587 	}
1588 
1589 	if (tcp_req->h2c_offset != h2c_data->datao) {
1590 		SPDK_DEBUGLOG(nvmf_tcp,
1591 			      "tcp_req(%p), tqpair=%p, expected data offset %u, but data offset is %u\n",
1592 			      tcp_req, tqpair, tcp_req->h2c_offset, h2c_data->datao);
1593 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1594 		goto err;
1595 	}
1596 
1597 	if ((h2c_data->datao + h2c_data->datal) > tcp_req->req.length) {
1598 		SPDK_DEBUGLOG(nvmf_tcp,
1599 			      "tcp_req(%p), tqpair=%p,  (datao=%u + datal=%u) exceeds requested length=%u\n",
1600 			      tcp_req, tqpair, h2c_data->datao, h2c_data->datal, tcp_req->req.length);
1601 		fes = SPDK_NVME_TCP_TERM_REQ_FES_DATA_TRANSFER_OUT_OF_RANGE;
1602 		goto err;
1603 	}
1604 
1605 	pdu->req = tcp_req;
1606 
1607 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
1608 		pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
1609 	}
1610 
1611 	nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
1612 				  h2c_data->datao, h2c_data->datal);
1613 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1614 	return;
1615 
1616 err:
1617 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1618 }
1619 
1620 static void
1621 nvmf_tcp_send_capsule_resp_pdu(struct spdk_nvmf_tcp_req *tcp_req,
1622 			       struct spdk_nvmf_tcp_qpair *tqpair)
1623 {
1624 	struct nvme_tcp_pdu *rsp_pdu;
1625 	struct spdk_nvme_tcp_rsp *capsule_resp;
1626 
1627 	SPDK_DEBUGLOG(nvmf_tcp, "enter, tqpair=%p\n", tqpair);
1628 
1629 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1630 	assert(rsp_pdu != NULL);
1631 
1632 	capsule_resp = &rsp_pdu->hdr.capsule_resp;
1633 	capsule_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_CAPSULE_RESP;
1634 	capsule_resp->common.plen = capsule_resp->common.hlen = sizeof(*capsule_resp);
1635 	capsule_resp->rccqe = tcp_req->req.rsp->nvme_cpl;
1636 	if (tqpair->host_hdgst_enable) {
1637 		capsule_resp->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1638 		capsule_resp->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1639 	}
1640 
1641 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_request_free, tcp_req);
1642 }
1643 
1644 static void
1645 nvmf_tcp_pdu_c2h_data_complete(void *cb_arg)
1646 {
1647 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1648 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair,
1649 					     struct spdk_nvmf_tcp_qpair, qpair);
1650 
1651 	assert(tqpair != NULL);
1652 
1653 	if (spdk_unlikely(tcp_req->pdu->rw_offset < tcp_req->req.length)) {
1654 		SPDK_DEBUGLOG(nvmf_tcp, "sending another C2H part, offset %u length %u\n", tcp_req->pdu->rw_offset,
1655 			      tcp_req->req.length);
1656 		_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
1657 		return;
1658 	}
1659 
1660 	if (tcp_req->pdu->hdr.c2h_data.common.flags & SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS) {
1661 		nvmf_tcp_request_free(tcp_req);
1662 	} else {
1663 		nvmf_tcp_req_pdu_fini(tcp_req);
1664 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
1665 	}
1666 }
1667 
1668 static void
1669 nvmf_tcp_r2t_complete(void *cb_arg)
1670 {
1671 	struct spdk_nvmf_tcp_req *tcp_req = cb_arg;
1672 	struct spdk_nvmf_tcp_transport *ttransport;
1673 
1674 	nvmf_tcp_req_pdu_fini(tcp_req);
1675 
1676 	ttransport = SPDK_CONTAINEROF(tcp_req->req.qpair->transport,
1677 				      struct spdk_nvmf_tcp_transport, transport);
1678 
1679 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
1680 
1681 	if (tcp_req->h2c_offset == tcp_req->req.length) {
1682 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1683 		nvmf_tcp_req_process(ttransport, tcp_req);
1684 	}
1685 }
1686 
1687 static void
1688 nvmf_tcp_send_r2t_pdu(struct spdk_nvmf_tcp_qpair *tqpair,
1689 		      struct spdk_nvmf_tcp_req *tcp_req)
1690 {
1691 	struct nvme_tcp_pdu *rsp_pdu;
1692 	struct spdk_nvme_tcp_r2t_hdr *r2t;
1693 
1694 	rsp_pdu = nvmf_tcp_req_pdu_init(tcp_req);
1695 	assert(rsp_pdu != NULL);
1696 
1697 	r2t = &rsp_pdu->hdr.r2t;
1698 	r2t->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_R2T;
1699 	r2t->common.plen = r2t->common.hlen = sizeof(*r2t);
1700 
1701 	if (tqpair->host_hdgst_enable) {
1702 		r2t->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
1703 		r2t->common.plen += SPDK_NVME_TCP_DIGEST_LEN;
1704 	}
1705 
1706 	r2t->cccid = tcp_req->req.cmd->nvme_cmd.cid;
1707 	r2t->ttag = tcp_req->ttag;
1708 	r2t->r2to = tcp_req->h2c_offset;
1709 	r2t->r2tl = tcp_req->req.length;
1710 
1711 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_R2T_ACK);
1712 
1713 	SPDK_DEBUGLOG(nvmf_tcp,
1714 		      "tcp_req(%p) on tqpair(%p), r2t_info: cccid=%u, ttag=%u, r2to=%u, r2tl=%u\n",
1715 		      tcp_req, tqpair, r2t->cccid, r2t->ttag, r2t->r2to, r2t->r2tl);
1716 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_r2t_complete, tcp_req);
1717 }
1718 
1719 static void
1720 nvmf_tcp_h2c_data_payload_handle(struct spdk_nvmf_tcp_transport *ttransport,
1721 				 struct spdk_nvmf_tcp_qpair *tqpair,
1722 				 struct nvme_tcp_pdu *pdu)
1723 {
1724 	struct spdk_nvmf_tcp_req *tcp_req;
1725 	struct spdk_nvme_cpl *rsp;
1726 
1727 	tcp_req = pdu->req;
1728 	assert(tcp_req != NULL);
1729 
1730 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1731 
1732 	tcp_req->h2c_offset += pdu->data_len;
1733 
1734 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1735 
1736 	/* Wait for all of the data to arrive AND for the initial R2T PDU send to be
1737 	 * acknowledged before moving on. */
1738 	if (tcp_req->h2c_offset == tcp_req->req.length &&
1739 	    tcp_req->state == TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER) {
1740 		/* After receiving all the h2c data, we need to check whether there is
1741 		 * transient transport error */
1742 		rsp = &tcp_req->req.rsp->nvme_cpl;
1743 		if (spdk_unlikely(rsp->status.sc == SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR)) {
1744 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
1745 		} else {
1746 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
1747 		}
1748 		nvmf_tcp_req_process(ttransport, tcp_req);
1749 	}
1750 }
1751 
1752 static void
1753 nvmf_tcp_h2c_term_req_dump(struct spdk_nvme_tcp_term_req_hdr *h2c_term_req)
1754 {
1755 	SPDK_ERRLOG("Error info of pdu(%p): %s\n", h2c_term_req,
1756 		    spdk_nvmf_tcp_term_req_fes_str[h2c_term_req->fes]);
1757 	if ((h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD) ||
1758 	    (h2c_term_req->fes == SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER)) {
1759 		SPDK_DEBUGLOG(nvmf_tcp, "The offset from the start of the PDU header is %u\n",
1760 			      DGET32(h2c_term_req->fei));
1761 	}
1762 }
1763 
1764 static void
1765 nvmf_tcp_h2c_term_req_hdr_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1766 				 struct nvme_tcp_pdu *pdu)
1767 {
1768 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1769 	uint32_t error_offset = 0;
1770 	enum spdk_nvme_tcp_term_req_fes fes;
1771 
1772 	if (h2c_term_req->fes > SPDK_NVME_TCP_TERM_REQ_FES_INVALID_DATA_UNSUPPORTED_PARAMETER) {
1773 		SPDK_ERRLOG("Fatal Error Status(FES) is unknown for h2c_term_req pdu=%p\n", pdu);
1774 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1775 		error_offset = offsetof(struct spdk_nvme_tcp_term_req_hdr, fes);
1776 		goto end;
1777 	}
1778 
1779 	/* set the data buffer */
1780 	nvme_tcp_pdu_set_data(pdu, (uint8_t *)pdu->hdr.raw + h2c_term_req->common.hlen,
1781 			      h2c_term_req->common.plen - h2c_term_req->common.hlen);
1782 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1783 	return;
1784 end:
1785 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1786 }
1787 
1788 static void
1789 nvmf_tcp_h2c_term_req_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1790 				     struct nvme_tcp_pdu *pdu)
1791 {
1792 	struct spdk_nvme_tcp_term_req_hdr *h2c_term_req = &pdu->hdr.term_req;
1793 
1794 	nvmf_tcp_h2c_term_req_dump(h2c_term_req);
1795 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
1796 }
1797 
1798 static void
1799 _nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1800 			     struct spdk_nvmf_tcp_transport *ttransport)
1801 {
1802 	struct nvme_tcp_pdu *pdu = tqpair->pdu_in_progress;
1803 
1804 	switch (pdu->hdr.common.pdu_type) {
1805 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1806 		nvmf_tcp_capsule_cmd_payload_handle(ttransport, tqpair, pdu);
1807 		break;
1808 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1809 		nvmf_tcp_h2c_data_payload_handle(ttransport, tqpair, pdu);
1810 		break;
1811 
1812 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1813 		nvmf_tcp_h2c_term_req_payload_handle(tqpair, pdu);
1814 		break;
1815 
1816 	default:
1817 		/* The code should not go to here */
1818 		SPDK_ERRLOG("The code should not go to here\n");
1819 		break;
1820 	}
1821 }
1822 
1823 static void
1824 nvmf_tcp_pdu_payload_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1825 			    struct spdk_nvmf_tcp_transport *ttransport)
1826 {
1827 	int rc = 0;
1828 	struct nvme_tcp_pdu *pdu;
1829 	uint32_t crc32c;
1830 	struct spdk_nvmf_tcp_req *tcp_req;
1831 	struct spdk_nvme_cpl *rsp;
1832 
1833 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
1834 	pdu = tqpair->pdu_in_progress;
1835 
1836 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
1837 	/* check data digest if need */
1838 	if (pdu->ddgst_enable) {
1839 		crc32c = nvme_tcp_pdu_calc_data_digest(pdu);
1840 		rc = MATCH_DIGEST_WORD(pdu->data_digest, crc32c);
1841 		if (rc == 0) {
1842 			SPDK_ERRLOG("Data digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1843 			tcp_req = pdu->req;
1844 			assert(tcp_req != NULL);
1845 			rsp = &tcp_req->req.rsp->nvme_cpl;
1846 			rsp->status.sc = SPDK_NVME_SC_COMMAND_TRANSIENT_TRANSPORT_ERROR;
1847 		}
1848 	}
1849 
1850 	_nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
1851 }
1852 
1853 static void
1854 nvmf_tcp_send_icresp_complete(void *cb_arg)
1855 {
1856 	struct spdk_nvmf_tcp_qpair *tqpair = cb_arg;
1857 
1858 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_RUNNING);
1859 }
1860 
1861 static void
1862 nvmf_tcp_icreq_handle(struct spdk_nvmf_tcp_transport *ttransport,
1863 		      struct spdk_nvmf_tcp_qpair *tqpair,
1864 		      struct nvme_tcp_pdu *pdu)
1865 {
1866 	struct spdk_nvme_tcp_ic_req *ic_req = &pdu->hdr.ic_req;
1867 	struct nvme_tcp_pdu *rsp_pdu;
1868 	struct spdk_nvme_tcp_ic_resp *ic_resp;
1869 	uint32_t error_offset = 0;
1870 	enum spdk_nvme_tcp_term_req_fes fes;
1871 
1872 	/* Only PFV 0 is defined currently */
1873 	if (ic_req->pfv != 0) {
1874 		SPDK_ERRLOG("Expected ICReq PFV %u, got %u\n", 0u, ic_req->pfv);
1875 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1876 		error_offset = offsetof(struct spdk_nvme_tcp_ic_req, pfv);
1877 		goto end;
1878 	}
1879 
1880 	/* MAXR2T is 0's based */
1881 	SPDK_DEBUGLOG(nvmf_tcp, "maxr2t =%u\n", (ic_req->maxr2t + 1u));
1882 
1883 	tqpair->host_hdgst_enable = ic_req->dgst.bits.hdgst_enable ? true : false;
1884 	if (!tqpair->host_hdgst_enable) {
1885 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1886 	}
1887 
1888 	tqpair->host_ddgst_enable = ic_req->dgst.bits.ddgst_enable ? true : false;
1889 	if (!tqpair->host_ddgst_enable) {
1890 		tqpair->recv_buf_size -= SPDK_NVME_TCP_DIGEST_LEN * SPDK_NVMF_TCP_RECV_BUF_SIZE_FACTOR;
1891 	}
1892 
1893 	tqpair->recv_buf_size = spdk_max(tqpair->recv_buf_size, MIN_SOCK_PIPE_SIZE);
1894 	/* Now that we know whether digests are enabled, properly size the receive buffer */
1895 	if (spdk_sock_set_recvbuf(tqpair->sock, tqpair->recv_buf_size) < 0) {
1896 		SPDK_WARNLOG("Unable to allocate enough memory for receive buffer on tqpair=%p with size=%d\n",
1897 			     tqpair,
1898 			     tqpair->recv_buf_size);
1899 		/* Not fatal. */
1900 	}
1901 
1902 	tqpair->cpda = spdk_min(ic_req->hpda, SPDK_NVME_TCP_CPDA_MAX);
1903 	SPDK_DEBUGLOG(nvmf_tcp, "cpda of tqpair=(%p) is : %u\n", tqpair, tqpair->cpda);
1904 
1905 	rsp_pdu = tqpair->mgmt_pdu;
1906 
1907 	ic_resp = &rsp_pdu->hdr.ic_resp;
1908 	ic_resp->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_IC_RESP;
1909 	ic_resp->common.hlen = ic_resp->common.plen =  sizeof(*ic_resp);
1910 	ic_resp->pfv = 0;
1911 	ic_resp->cpda = tqpair->cpda;
1912 	ic_resp->maxh2cdata = ttransport->transport.opts.max_io_size;
1913 	ic_resp->dgst.bits.hdgst_enable = tqpair->host_hdgst_enable ? 1 : 0;
1914 	ic_resp->dgst.bits.ddgst_enable = tqpair->host_ddgst_enable ? 1 : 0;
1915 
1916 	SPDK_DEBUGLOG(nvmf_tcp, "host_hdgst_enable: %u\n", tqpair->host_hdgst_enable);
1917 	SPDK_DEBUGLOG(nvmf_tcp, "host_ddgst_enable: %u\n", tqpair->host_ddgst_enable);
1918 
1919 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INITIALIZING);
1920 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_send_icresp_complete, tqpair);
1921 	nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
1922 	return;
1923 end:
1924 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1925 }
1926 
1927 static void
1928 nvmf_tcp_pdu_psh_handle(struct spdk_nvmf_tcp_qpair *tqpair,
1929 			struct spdk_nvmf_tcp_transport *ttransport)
1930 {
1931 	struct nvme_tcp_pdu *pdu;
1932 	int rc;
1933 	uint32_t crc32c, error_offset = 0;
1934 	enum spdk_nvme_tcp_term_req_fes fes;
1935 
1936 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
1937 	pdu = tqpair->pdu_in_progress;
1938 
1939 	SPDK_DEBUGLOG(nvmf_tcp, "pdu type of tqpair(%p) is %d\n", tqpair,
1940 		      pdu->hdr.common.pdu_type);
1941 	/* check header digest if needed */
1942 	if (pdu->has_hdgst) {
1943 		SPDK_DEBUGLOG(nvmf_tcp, "Compare the header of pdu=%p on tqpair=%p\n", pdu, tqpair);
1944 		crc32c = nvme_tcp_pdu_calc_header_digest(pdu);
1945 		rc = MATCH_DIGEST_WORD((uint8_t *)pdu->hdr.raw + pdu->hdr.common.hlen, crc32c);
1946 		if (rc == 0) {
1947 			SPDK_ERRLOG("Header digest error on tqpair=(%p) with pdu=%p\n", tqpair, pdu);
1948 			fes = SPDK_NVME_TCP_TERM_REQ_FES_HDGST_ERROR;
1949 			nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1950 			return;
1951 
1952 		}
1953 	}
1954 
1955 	switch (pdu->hdr.common.pdu_type) {
1956 	case SPDK_NVME_TCP_PDU_TYPE_IC_REQ:
1957 		nvmf_tcp_icreq_handle(ttransport, tqpair, pdu);
1958 		break;
1959 	case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
1960 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_REQ);
1961 		break;
1962 	case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
1963 		nvmf_tcp_h2c_data_hdr_handle(ttransport, tqpair, pdu);
1964 		break;
1965 
1966 	case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
1967 		nvmf_tcp_h2c_term_req_hdr_handle(tqpair, pdu);
1968 		break;
1969 
1970 	default:
1971 		SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", tqpair->pdu_in_progress->hdr.common.pdu_type);
1972 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
1973 		error_offset = 1;
1974 		nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
1975 		break;
1976 	}
1977 }
1978 
1979 static void
1980 nvmf_tcp_pdu_ch_handle(struct spdk_nvmf_tcp_qpair *tqpair)
1981 {
1982 	struct nvme_tcp_pdu *pdu;
1983 	uint32_t error_offset = 0;
1984 	enum spdk_nvme_tcp_term_req_fes fes;
1985 	uint8_t expected_hlen, pdo;
1986 	bool plen_error = false, pdo_error = false;
1987 
1988 	assert(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
1989 	pdu = tqpair->pdu_in_progress;
1990 
1991 	if (pdu->hdr.common.pdu_type == SPDK_NVME_TCP_PDU_TYPE_IC_REQ) {
1992 		if (tqpair->state != NVME_TCP_QPAIR_STATE_INVALID) {
1993 			SPDK_ERRLOG("Already received ICreq PDU, and reject this pdu=%p\n", pdu);
1994 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
1995 			goto err;
1996 		}
1997 		expected_hlen = sizeof(struct spdk_nvme_tcp_ic_req);
1998 		if (pdu->hdr.common.plen != expected_hlen) {
1999 			plen_error = true;
2000 		}
2001 	} else {
2002 		if (tqpair->state != NVME_TCP_QPAIR_STATE_RUNNING) {
2003 			SPDK_ERRLOG("The TCP/IP connection is not negotiated\n");
2004 			fes = SPDK_NVME_TCP_TERM_REQ_FES_PDU_SEQUENCE_ERROR;
2005 			goto err;
2006 		}
2007 
2008 		switch (pdu->hdr.common.pdu_type) {
2009 		case SPDK_NVME_TCP_PDU_TYPE_CAPSULE_CMD:
2010 			expected_hlen = sizeof(struct spdk_nvme_tcp_cmd);
2011 			pdo = pdu->hdr.common.pdo;
2012 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
2013 				pdo_error = true;
2014 				break;
2015 			}
2016 
2017 			if (pdu->hdr.common.plen < expected_hlen) {
2018 				plen_error = true;
2019 			}
2020 			break;
2021 		case SPDK_NVME_TCP_PDU_TYPE_H2C_DATA:
2022 			expected_hlen = sizeof(struct spdk_nvme_tcp_h2c_data_hdr);
2023 			pdo = pdu->hdr.common.pdo;
2024 			if ((tqpair->cpda != 0) && (pdo % ((tqpair->cpda + 1) << 2) != 0)) {
2025 				pdo_error = true;
2026 				break;
2027 			}
2028 			if (pdu->hdr.common.plen < expected_hlen) {
2029 				plen_error = true;
2030 			}
2031 			break;
2032 
2033 		case SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ:
2034 			expected_hlen = sizeof(struct spdk_nvme_tcp_term_req_hdr);
2035 			if ((pdu->hdr.common.plen <= expected_hlen) ||
2036 			    (pdu->hdr.common.plen > SPDK_NVME_TCP_TERM_REQ_PDU_MAX_SIZE)) {
2037 				plen_error = true;
2038 			}
2039 			break;
2040 
2041 		default:
2042 			SPDK_ERRLOG("Unexpected PDU type 0x%02x\n", pdu->hdr.common.pdu_type);
2043 			fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
2044 			error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdu_type);
2045 			goto err;
2046 		}
2047 	}
2048 
2049 	if (pdu->hdr.common.hlen != expected_hlen) {
2050 		SPDK_ERRLOG("PDU type=0x%02x, Expected ICReq header length %u, got %u on tqpair=%p\n",
2051 			    pdu->hdr.common.pdu_type,
2052 			    expected_hlen, pdu->hdr.common.hlen, tqpair);
2053 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
2054 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, hlen);
2055 		goto err;
2056 	} else if (pdo_error) {
2057 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
2058 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, pdo);
2059 	} else if (plen_error) {
2060 		fes = SPDK_NVME_TCP_TERM_REQ_FES_INVALID_HEADER_FIELD;
2061 		error_offset = offsetof(struct spdk_nvme_tcp_common_pdu_hdr, plen);
2062 		goto err;
2063 	} else {
2064 		nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH);
2065 		nvme_tcp_pdu_calc_psh_len(tqpair->pdu_in_progress, tqpair->host_hdgst_enable);
2066 		return;
2067 	}
2068 err:
2069 	nvmf_tcp_send_c2h_term_req(tqpair, pdu, fes, error_offset);
2070 }
2071 
2072 static int
2073 nvmf_tcp_pdu_payload_insert_dif(struct nvme_tcp_pdu *pdu, uint32_t read_offset,
2074 				int read_len)
2075 {
2076 	int rc;
2077 
2078 	rc = spdk_dif_generate_stream(pdu->data_iov, pdu->data_iovcnt,
2079 				      read_offset, read_len, pdu->dif_ctx);
2080 	if (rc != 0) {
2081 		SPDK_ERRLOG("DIF generate failed\n");
2082 	}
2083 
2084 	return rc;
2085 }
2086 
2087 static int
2088 nvmf_tcp_sock_process(struct spdk_nvmf_tcp_qpair *tqpair)
2089 {
2090 	int rc = 0;
2091 	struct nvme_tcp_pdu *pdu;
2092 	enum nvme_tcp_pdu_recv_state prev_state;
2093 	uint32_t data_len;
2094 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(tqpair->qpair.transport,
2095 			struct spdk_nvmf_tcp_transport, transport);
2096 
2097 	/* The loop here is to allow for several back-to-back state changes. */
2098 	do {
2099 		prev_state = tqpair->recv_state;
2100 		SPDK_DEBUGLOG(nvmf_tcp, "tqpair(%p) recv pdu entering state %d\n", tqpair, prev_state);
2101 
2102 		pdu = tqpair->pdu_in_progress;
2103 		switch (tqpair->recv_state) {
2104 		/* Wait for the common header  */
2105 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY:
2106 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH:
2107 			if (spdk_unlikely(tqpair->state == NVME_TCP_QPAIR_STATE_INITIALIZING)) {
2108 				return rc;
2109 			}
2110 
2111 			rc = nvme_tcp_read_data(tqpair->sock,
2112 						sizeof(struct spdk_nvme_tcp_common_pdu_hdr) - pdu->ch_valid_bytes,
2113 						(void *)&pdu->hdr.common + pdu->ch_valid_bytes);
2114 			if (rc < 0) {
2115 				SPDK_DEBUGLOG(nvmf_tcp, "will disconnect tqpair=%p\n", tqpair);
2116 				return NVME_TCP_PDU_FATAL;
2117 			} else if (rc > 0) {
2118 				pdu->ch_valid_bytes += rc;
2119 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2120 				if (spdk_likely(tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY)) {
2121 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_CH);
2122 				}
2123 			}
2124 
2125 			if (pdu->ch_valid_bytes < sizeof(struct spdk_nvme_tcp_common_pdu_hdr)) {
2126 				return NVME_TCP_PDU_IN_PROGRESS;
2127 			}
2128 
2129 			/* The command header of this PDU has now been read from the socket. */
2130 			nvmf_tcp_pdu_ch_handle(tqpair);
2131 			break;
2132 		/* Wait for the pdu specific header  */
2133 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PSH:
2134 			rc = nvme_tcp_read_data(tqpair->sock,
2135 						pdu->psh_len - pdu->psh_valid_bytes,
2136 						(void *)&pdu->hdr.raw + sizeof(struct spdk_nvme_tcp_common_pdu_hdr) + pdu->psh_valid_bytes);
2137 			if (rc < 0) {
2138 				return NVME_TCP_PDU_FATAL;
2139 			} else if (rc > 0) {
2140 				spdk_trace_record(TRACE_TCP_READ_FROM_SOCKET_DONE, 0, rc, 0, tqpair);
2141 				pdu->psh_valid_bytes += rc;
2142 			}
2143 
2144 			if (pdu->psh_valid_bytes < pdu->psh_len) {
2145 				return NVME_TCP_PDU_IN_PROGRESS;
2146 			}
2147 
2148 			/* All header(ch, psh, head digist) of this PDU has now been read from the socket. */
2149 			nvmf_tcp_pdu_psh_handle(tqpair, ttransport);
2150 			break;
2151 		/* Wait for the req slot */
2152 		case NVME_TCP_PDU_RECV_STATE_AWAIT_REQ:
2153 			nvmf_tcp_capsule_cmd_hdr_handle(ttransport, tqpair, pdu);
2154 			break;
2155 		case NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD:
2156 			/* check whether the data is valid, if not we just return */
2157 			if (!pdu->data_len) {
2158 				return NVME_TCP_PDU_IN_PROGRESS;
2159 			}
2160 
2161 			data_len = pdu->data_len;
2162 			/* data digest */
2163 			if (spdk_unlikely((pdu->hdr.common.pdu_type != SPDK_NVME_TCP_PDU_TYPE_H2C_TERM_REQ) &&
2164 					  tqpair->host_ddgst_enable)) {
2165 				data_len += SPDK_NVME_TCP_DIGEST_LEN;
2166 				pdu->ddgst_enable = true;
2167 			}
2168 
2169 			rc = nvme_tcp_read_payload_data(tqpair->sock, pdu);
2170 			if (rc < 0) {
2171 				return NVME_TCP_PDU_FATAL;
2172 			}
2173 			pdu->rw_offset += rc;
2174 
2175 			if (spdk_unlikely(pdu->dif_ctx != NULL)) {
2176 				rc = nvmf_tcp_pdu_payload_insert_dif(pdu, pdu->rw_offset - rc, rc);
2177 				if (rc != 0) {
2178 					return NVME_TCP_PDU_FATAL;
2179 				}
2180 			}
2181 
2182 			if (pdu->rw_offset < data_len) {
2183 				return NVME_TCP_PDU_IN_PROGRESS;
2184 			}
2185 
2186 			/* All of this PDU has now been read from the socket. */
2187 			nvmf_tcp_pdu_payload_handle(tqpair, ttransport);
2188 			break;
2189 		case NVME_TCP_PDU_RECV_STATE_ERROR:
2190 			if (!spdk_sock_is_connected(tqpair->sock)) {
2191 				return NVME_TCP_PDU_FATAL;
2192 			}
2193 			break;
2194 		default:
2195 			assert(0);
2196 			SPDK_ERRLOG("code should not come to here");
2197 			break;
2198 		}
2199 	} while (tqpair->recv_state != prev_state);
2200 
2201 	return rc;
2202 }
2203 
2204 static inline void *
2205 nvmf_tcp_control_msg_get(struct spdk_nvmf_tcp_control_msg_list *list)
2206 {
2207 	struct spdk_nvmf_tcp_control_msg *msg;
2208 
2209 	assert(list);
2210 
2211 	msg = STAILQ_FIRST(&list->free_msgs);
2212 	if (!msg) {
2213 		SPDK_DEBUGLOG(nvmf_tcp, "Out of control messages\n");
2214 		return NULL;
2215 	}
2216 	STAILQ_REMOVE_HEAD(&list->free_msgs, link);
2217 	return msg;
2218 }
2219 
2220 static inline void
2221 nvmf_tcp_control_msg_put(struct spdk_nvmf_tcp_control_msg_list *list, void *_msg)
2222 {
2223 	struct spdk_nvmf_tcp_control_msg *msg = _msg;
2224 
2225 	assert(list);
2226 	STAILQ_INSERT_HEAD(&list->free_msgs, msg, link);
2227 }
2228 
2229 static int
2230 nvmf_tcp_req_parse_sgl(struct spdk_nvmf_tcp_req *tcp_req,
2231 		       struct spdk_nvmf_transport *transport,
2232 		       struct spdk_nvmf_transport_poll_group *group)
2233 {
2234 	struct spdk_nvmf_request		*req = &tcp_req->req;
2235 	struct spdk_nvme_cmd			*cmd;
2236 	struct spdk_nvme_cpl			*rsp;
2237 	struct spdk_nvme_sgl_descriptor		*sgl;
2238 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2239 	uint32_t				length;
2240 
2241 	cmd = &req->cmd->nvme_cmd;
2242 	rsp = &req->rsp->nvme_cpl;
2243 	sgl = &cmd->dptr.sgl1;
2244 
2245 	length = sgl->unkeyed.length;
2246 
2247 	if (sgl->generic.type == SPDK_NVME_SGL_TYPE_TRANSPORT_DATA_BLOCK &&
2248 	    sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_TRANSPORT) {
2249 		if (length > transport->opts.max_io_size) {
2250 			SPDK_ERRLOG("SGL length 0x%x exceeds max io size 0x%x\n",
2251 				    length, transport->opts.max_io_size);
2252 			rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2253 			return -1;
2254 		}
2255 
2256 		/* fill request length and populate iovs */
2257 		req->length = length;
2258 
2259 		SPDK_DEBUGLOG(nvmf_tcp, "Data requested length= 0x%x\n", length);
2260 
2261 		if (spdk_unlikely(req->dif_enabled)) {
2262 			req->dif.orig_length = length;
2263 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2264 			req->dif.elba_length = length;
2265 		}
2266 
2267 		if (nvmf_ctrlr_use_zcopy(req)) {
2268 			SPDK_DEBUGLOG(nvmf_tcp, "Using zero-copy to execute request %p\n", tcp_req);
2269 			req->data_from_pool = false;
2270 			return 0;
2271 		}
2272 
2273 		if (spdk_nvmf_request_get_buffers(req, group, transport, length)) {
2274 			/* No available buffers. Queue this request up. */
2275 			SPDK_DEBUGLOG(nvmf_tcp, "No available large data buffers. Queueing request %p\n",
2276 				      tcp_req);
2277 			return 0;
2278 		}
2279 
2280 		/* backward compatible */
2281 		req->data = req->iov[0].iov_base;
2282 
2283 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p took %d buffer/s from central pool, and data=%p\n",
2284 			      tcp_req, req->iovcnt, req->data);
2285 
2286 		return 0;
2287 	} else if (sgl->generic.type == SPDK_NVME_SGL_TYPE_DATA_BLOCK &&
2288 		   sgl->unkeyed.subtype == SPDK_NVME_SGL_SUBTYPE_OFFSET) {
2289 		uint64_t offset = sgl->address;
2290 		uint32_t max_len = transport->opts.in_capsule_data_size;
2291 		assert(tcp_req->has_in_capsule_data);
2292 
2293 		SPDK_DEBUGLOG(nvmf_tcp, "In-capsule data: offset 0x%" PRIx64 ", length 0x%x\n",
2294 			      offset, length);
2295 
2296 		if (offset > max_len) {
2297 			SPDK_ERRLOG("In-capsule offset 0x%" PRIx64 " exceeds capsule length 0x%x\n",
2298 				    offset, max_len);
2299 			rsp->status.sc = SPDK_NVME_SC_INVALID_SGL_OFFSET;
2300 			return -1;
2301 		}
2302 		max_len -= (uint32_t)offset;
2303 
2304 		if (spdk_unlikely(length > max_len)) {
2305 			/* According to the SPEC we should support ICD up to 8192 bytes for admin and fabric commands */
2306 			if (length <= SPDK_NVME_TCP_IN_CAPSULE_DATA_MAX_SIZE &&
2307 			    (cmd->opc == SPDK_NVME_OPC_FABRIC || req->qpair->qid == 0)) {
2308 
2309 				/* Get a buffer from dedicated list */
2310 				SPDK_DEBUGLOG(nvmf_tcp, "Getting a buffer from control msg list\n");
2311 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2312 				assert(tgroup->control_msg_list);
2313 				req->data = nvmf_tcp_control_msg_get(tgroup->control_msg_list);
2314 				if (!req->data) {
2315 					/* No available buffers. Queue this request up. */
2316 					SPDK_DEBUGLOG(nvmf_tcp, "No available ICD buffers. Queueing request %p\n", tcp_req);
2317 					return 0;
2318 				}
2319 			} else {
2320 				SPDK_ERRLOG("In-capsule data length 0x%x exceeds capsule length 0x%x\n",
2321 					    length, max_len);
2322 				rsp->status.sc = SPDK_NVME_SC_DATA_SGL_LENGTH_INVALID;
2323 				return -1;
2324 			}
2325 		} else {
2326 			req->data = tcp_req->buf;
2327 		}
2328 
2329 		req->length = length;
2330 		req->data_from_pool = false;
2331 
2332 		if (spdk_unlikely(req->dif_enabled)) {
2333 			length = spdk_dif_get_length_with_md(length, &req->dif.dif_ctx);
2334 			req->dif.elba_length = length;
2335 		}
2336 
2337 		req->iov[0].iov_base = req->data;
2338 		req->iov[0].iov_len = length;
2339 		req->iovcnt = 1;
2340 
2341 		return 0;
2342 	}
2343 
2344 	SPDK_ERRLOG("Invalid NVMf I/O Command SGL:  Type 0x%x, Subtype 0x%x\n",
2345 		    sgl->generic.type, sgl->generic.subtype);
2346 	rsp->status.sc = SPDK_NVME_SC_SGL_DESCRIPTOR_TYPE_INVALID;
2347 	return -1;
2348 }
2349 
2350 static inline enum spdk_nvme_media_error_status_code
2351 nvmf_tcp_dif_error_to_compl_status(uint8_t err_type) {
2352 	enum spdk_nvme_media_error_status_code result;
2353 
2354 	switch (err_type)
2355 	{
2356 	case SPDK_DIF_REFTAG_ERROR:
2357 		result = SPDK_NVME_SC_REFERENCE_TAG_CHECK_ERROR;
2358 		break;
2359 	case SPDK_DIF_APPTAG_ERROR:
2360 		result = SPDK_NVME_SC_APPLICATION_TAG_CHECK_ERROR;
2361 		break;
2362 	case SPDK_DIF_GUARD_ERROR:
2363 		result = SPDK_NVME_SC_GUARD_CHECK_ERROR;
2364 		break;
2365 	default:
2366 		SPDK_UNREACHABLE();
2367 		break;
2368 	}
2369 
2370 	return result;
2371 }
2372 
2373 static void
2374 _nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2375 			struct spdk_nvmf_tcp_req *tcp_req)
2376 {
2377 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(
2378 				tqpair->qpair.transport, struct spdk_nvmf_tcp_transport, transport);
2379 	struct nvme_tcp_pdu *rsp_pdu;
2380 	struct spdk_nvme_tcp_c2h_data_hdr *c2h_data;
2381 	uint32_t plen, pdo, alignment;
2382 	int rc;
2383 
2384 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2385 
2386 	rsp_pdu = tcp_req->pdu;
2387 	assert(rsp_pdu != NULL);
2388 	assert(tcp_req->pdu_in_use);
2389 
2390 	c2h_data = &rsp_pdu->hdr.c2h_data;
2391 	c2h_data->common.pdu_type = SPDK_NVME_TCP_PDU_TYPE_C2H_DATA;
2392 	plen = c2h_data->common.hlen = sizeof(*c2h_data);
2393 
2394 	if (tqpair->host_hdgst_enable) {
2395 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2396 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_HDGSTF;
2397 	}
2398 
2399 	/* set the psh */
2400 	c2h_data->cccid = tcp_req->req.cmd->nvme_cmd.cid;
2401 	c2h_data->datal = tcp_req->req.length - tcp_req->pdu->rw_offset;
2402 	c2h_data->datao = tcp_req->pdu->rw_offset;
2403 
2404 	/* set the padding */
2405 	rsp_pdu->padding_len = 0;
2406 	pdo = plen;
2407 	if (tqpair->cpda) {
2408 		alignment = (tqpair->cpda + 1) << 2;
2409 		if (plen % alignment != 0) {
2410 			pdo = (plen + alignment) / alignment * alignment;
2411 			rsp_pdu->padding_len = pdo - plen;
2412 			plen = pdo;
2413 		}
2414 	}
2415 
2416 	c2h_data->common.pdo = pdo;
2417 	plen += c2h_data->datal;
2418 	if (tqpair->host_ddgst_enable) {
2419 		c2h_data->common.flags |= SPDK_NVME_TCP_CH_FLAGS_DDGSTF;
2420 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2421 	}
2422 
2423 	c2h_data->common.plen = plen;
2424 
2425 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2426 		rsp_pdu->dif_ctx = &tcp_req->req.dif.dif_ctx;
2427 	}
2428 
2429 	nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2430 				  c2h_data->datao, c2h_data->datal);
2431 
2432 
2433 	c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU;
2434 	/* Need to send the capsule response if response is not all 0 */
2435 	if (ttransport->tcp_opts.c2h_success &&
2436 	    tcp_req->rsp.cdw0 == 0 && tcp_req->rsp.cdw1 == 0) {
2437 		c2h_data->common.flags |= SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS;
2438 	}
2439 
2440 	if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2441 		struct spdk_nvme_cpl *rsp = &tcp_req->req.rsp->nvme_cpl;
2442 		struct spdk_dif_error err_blk = {};
2443 		uint32_t mapped_length = 0;
2444 		uint32_t available_iovs = SPDK_COUNTOF(rsp_pdu->iov);
2445 		uint32_t ddgst_len = 0;
2446 
2447 		if (tqpair->host_ddgst_enable) {
2448 			/* Data digest consumes additional iov entry */
2449 			available_iovs--;
2450 			/* plen needs to be updated since nvme_tcp_build_iovs compares expected and actual plen */
2451 			ddgst_len = SPDK_NVME_TCP_DIGEST_LEN;
2452 			c2h_data->common.plen -= ddgst_len;
2453 		}
2454 		/* Temp call to estimate if data can be described by limited number of iovs.
2455 		 * iov vector will be rebuilt in nvmf_tcp_qpair_write_pdu */
2456 		nvme_tcp_build_iovs(rsp_pdu->iov, available_iovs, rsp_pdu, tqpair->host_hdgst_enable,
2457 				    false, &mapped_length);
2458 
2459 		if (mapped_length != c2h_data->common.plen) {
2460 			c2h_data->datal = mapped_length - (c2h_data->common.plen - c2h_data->datal);
2461 			SPDK_DEBUGLOG(nvmf_tcp,
2462 				      "Part C2H, data_len %u (of %u), PDU len %u, updated PDU len %u, offset %u\n",
2463 				      c2h_data->datal, tcp_req->req.length, c2h_data->common.plen, mapped_length, rsp_pdu->rw_offset);
2464 			c2h_data->common.plen = mapped_length;
2465 
2466 			/* Rebuild pdu->data_iov since data length is changed */
2467 			nvme_tcp_pdu_set_data_buf(rsp_pdu, tcp_req->req.iov, tcp_req->req.iovcnt, c2h_data->datao,
2468 						  c2h_data->datal);
2469 
2470 			c2h_data->common.flags &= ~(SPDK_NVME_TCP_C2H_DATA_FLAGS_LAST_PDU |
2471 						    SPDK_NVME_TCP_C2H_DATA_FLAGS_SUCCESS);
2472 		}
2473 
2474 		c2h_data->common.plen += ddgst_len;
2475 
2476 		assert(rsp_pdu->rw_offset <= tcp_req->req.length);
2477 
2478 		rc = spdk_dif_verify_stream(rsp_pdu->data_iov, rsp_pdu->data_iovcnt,
2479 					    0, rsp_pdu->data_len, rsp_pdu->dif_ctx, &err_blk);
2480 		if (rc != 0) {
2481 			SPDK_ERRLOG("DIF error detected. type=%d, offset=%" PRIu32 "\n",
2482 				    err_blk.err_type, err_blk.err_offset);
2483 			rsp->status.sct = SPDK_NVME_SCT_MEDIA_ERROR;
2484 			rsp->status.sc = nvmf_tcp_dif_error_to_compl_status(err_blk.err_type);
2485 			nvmf_tcp_req_pdu_fini(tcp_req);
2486 			nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2487 			return;
2488 		}
2489 	}
2490 
2491 	rsp_pdu->rw_offset += c2h_data->datal;
2492 	nvmf_tcp_qpair_write_pdu(tqpair, rsp_pdu, nvmf_tcp_pdu_c2h_data_complete, tcp_req);
2493 }
2494 
2495 static void
2496 nvmf_tcp_send_c2h_data(struct spdk_nvmf_tcp_qpair *tqpair,
2497 		       struct spdk_nvmf_tcp_req *tcp_req)
2498 {
2499 	nvmf_tcp_req_pdu_init(tcp_req);
2500 	_nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2501 }
2502 
2503 static int
2504 request_transfer_out(struct spdk_nvmf_request *req)
2505 {
2506 	struct spdk_nvmf_tcp_req	*tcp_req;
2507 	struct spdk_nvmf_qpair		*qpair;
2508 	struct spdk_nvmf_tcp_qpair	*tqpair;
2509 	struct spdk_nvme_cpl		*rsp;
2510 
2511 	SPDK_DEBUGLOG(nvmf_tcp, "enter\n");
2512 
2513 	qpair = req->qpair;
2514 	rsp = &req->rsp->nvme_cpl;
2515 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2516 
2517 	/* Advance our sq_head pointer */
2518 	if (qpair->sq_head == qpair->sq_head_max) {
2519 		qpair->sq_head = 0;
2520 	} else {
2521 		qpair->sq_head++;
2522 	}
2523 	rsp->sqhd = qpair->sq_head;
2524 
2525 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2526 	nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST);
2527 	if (rsp->status.sc == SPDK_NVME_SC_SUCCESS && req->xfer == SPDK_NVME_DATA_CONTROLLER_TO_HOST) {
2528 		nvmf_tcp_send_c2h_data(tqpair, tcp_req);
2529 	} else {
2530 		nvmf_tcp_send_capsule_resp_pdu(tcp_req, tqpair);
2531 	}
2532 
2533 	return 0;
2534 }
2535 
2536 static void
2537 nvmf_tcp_set_in_capsule_data(struct spdk_nvmf_tcp_qpair *tqpair,
2538 			     struct spdk_nvmf_tcp_req *tcp_req)
2539 {
2540 	struct nvme_tcp_pdu *pdu;
2541 	uint32_t plen = 0;
2542 
2543 	pdu = tqpair->pdu_in_progress;
2544 	plen = pdu->hdr.common.hlen;
2545 
2546 	if (tqpair->host_hdgst_enable) {
2547 		plen += SPDK_NVME_TCP_DIGEST_LEN;
2548 	}
2549 
2550 	if (pdu->hdr.common.plen != plen) {
2551 		tcp_req->has_in_capsule_data = true;
2552 	}
2553 }
2554 
2555 static bool
2556 nvmf_tcp_req_process(struct spdk_nvmf_tcp_transport *ttransport,
2557 		     struct spdk_nvmf_tcp_req *tcp_req)
2558 {
2559 	struct spdk_nvmf_tcp_qpair		*tqpair;
2560 	int					rc;
2561 	enum spdk_nvmf_tcp_req_state		prev_state;
2562 	bool					progress = false;
2563 	struct spdk_nvmf_transport		*transport = &ttransport->transport;
2564 	struct spdk_nvmf_transport_poll_group	*group;
2565 	struct spdk_nvmf_tcp_poll_group		*tgroup;
2566 
2567 	tqpair = SPDK_CONTAINEROF(tcp_req->req.qpair, struct spdk_nvmf_tcp_qpair, qpair);
2568 	group = &tqpair->group->group;
2569 	assert(tcp_req->state != TCP_REQUEST_STATE_FREE);
2570 
2571 	/* If the qpair is not active, we need to abort the outstanding requests. */
2572 	if (tqpair->qpair.state != SPDK_NVMF_QPAIR_ACTIVE) {
2573 		if (tcp_req->state == TCP_REQUEST_STATE_NEED_BUFFER) {
2574 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2575 		}
2576 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
2577 	}
2578 
2579 	/* The loop here is to allow for several back-to-back state changes. */
2580 	do {
2581 		prev_state = tcp_req->state;
2582 
2583 		SPDK_DEBUGLOG(nvmf_tcp, "Request %p entering state %d on tqpair=%p\n", tcp_req, prev_state,
2584 			      tqpair);
2585 
2586 		switch (tcp_req->state) {
2587 		case TCP_REQUEST_STATE_FREE:
2588 			/* Some external code must kick a request into TCP_REQUEST_STATE_NEW
2589 			 * to escape this state. */
2590 			break;
2591 		case TCP_REQUEST_STATE_NEW:
2592 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEW, 0, 0, (uintptr_t)tcp_req, tqpair);
2593 
2594 			/* copy the cmd from the receive pdu */
2595 			tcp_req->cmd = tqpair->pdu_in_progress->hdr.capsule_cmd.ccsqe;
2596 
2597 			if (spdk_unlikely(spdk_nvmf_request_get_dif_ctx(&tcp_req->req, &tcp_req->req.dif.dif_ctx))) {
2598 				tcp_req->req.dif_enabled = true;
2599 				tqpair->pdu_in_progress->dif_ctx = &tcp_req->req.dif.dif_ctx;
2600 			}
2601 
2602 			/* The next state transition depends on the data transfer needs of this request. */
2603 			tcp_req->req.xfer = spdk_nvmf_req_get_xfer(&tcp_req->req);
2604 
2605 			if (spdk_unlikely(tcp_req->req.xfer == SPDK_NVME_DATA_BIDIRECTIONAL)) {
2606 				tcp_req->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
2607 				tcp_req->req.rsp->nvme_cpl.status.sc  = SPDK_NVME_SC_INVALID_OPCODE;
2608 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2609 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2610 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2611 				SPDK_DEBUGLOG(nvmf_tcp, "Request %p: invalid xfer type (BIDIRECTIONAL)\n", tcp_req);
2612 				break;
2613 			}
2614 
2615 			/* If no data to transfer, ready to execute. */
2616 			if (tcp_req->req.xfer == SPDK_NVME_DATA_NONE) {
2617 				/* Reset the tqpair receiving pdu state */
2618 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2619 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2620 				break;
2621 			}
2622 
2623 			nvmf_tcp_set_in_capsule_data(tqpair, tcp_req);
2624 
2625 			if (!tcp_req->has_in_capsule_data) {
2626 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2627 			}
2628 
2629 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_NEED_BUFFER);
2630 			STAILQ_INSERT_TAIL(&group->pending_buf_queue, &tcp_req->req, buf_link);
2631 			break;
2632 		case TCP_REQUEST_STATE_NEED_BUFFER:
2633 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_NEED_BUFFER, 0, 0, (uintptr_t)tcp_req, tqpair);
2634 
2635 			assert(tcp_req->req.xfer != SPDK_NVME_DATA_NONE);
2636 
2637 			if (!tcp_req->has_in_capsule_data && (&tcp_req->req != STAILQ_FIRST(&group->pending_buf_queue))) {
2638 				SPDK_DEBUGLOG(nvmf_tcp,
2639 					      "Not the first element to wait for the buf for tcp_req(%p) on tqpair=%p\n",
2640 					      tcp_req, tqpair);
2641 				/* This request needs to wait in line to obtain a buffer */
2642 				break;
2643 			}
2644 
2645 			/* Try to get a data buffer */
2646 			rc = nvmf_tcp_req_parse_sgl(tcp_req, transport, group);
2647 			if (rc < 0) {
2648 				STAILQ_REMOVE_HEAD(&group->pending_buf_queue, buf_link);
2649 				/* Reset the tqpair receiving pdu state */
2650 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_ERROR);
2651 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2652 				tcp_req->req.rsp->nvme_cpl.cid = tcp_req->req.cmd->nvme_cmd.cid;
2653 				nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_READY);
2654 				break;
2655 			}
2656 
2657 			/* Get a zcopy buffer if the request can be serviced through zcopy */
2658 			if (spdk_nvmf_request_using_zcopy(&tcp_req->req)) {
2659 				if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2660 					assert(tcp_req->req.dif.elba_length >= tcp_req->req.length);
2661 					tcp_req->req.length = tcp_req->req.dif.elba_length;
2662 				}
2663 
2664 				STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2665 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_ZCOPY_START);
2666 				spdk_nvmf_request_zcopy_start(&tcp_req->req);
2667 				break;
2668 			}
2669 
2670 			if (!tcp_req->req.data) {
2671 				SPDK_DEBUGLOG(nvmf_tcp, "No buffer allocated for tcp_req(%p) on tqpair(%p\n)",
2672 					      tcp_req, tqpair);
2673 				/* No buffers available. */
2674 				break;
2675 			}
2676 
2677 			STAILQ_REMOVE(&group->pending_buf_queue, &tcp_req->req, spdk_nvmf_request, buf_link);
2678 
2679 			/* If data is transferring from host to controller, we need to do a transfer from the host. */
2680 			if (tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER) {
2681 				if (tcp_req->req.data_from_pool) {
2682 					SPDK_DEBUGLOG(nvmf_tcp, "Sending R2T for tcp_req(%p) on tqpair=%p\n", tcp_req, tqpair);
2683 					nvmf_tcp_send_r2t_pdu(tqpair, tcp_req);
2684 				} else {
2685 					struct nvme_tcp_pdu *pdu;
2686 
2687 					nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER);
2688 
2689 					pdu = tqpair->pdu_in_progress;
2690 					SPDK_DEBUGLOG(nvmf_tcp, "Not need to send r2t for tcp_req(%p) on tqpair=%p\n", tcp_req,
2691 						      tqpair);
2692 					/* No need to send r2t, contained in the capsuled data */
2693 					nvme_tcp_pdu_set_data_buf(pdu, tcp_req->req.iov, tcp_req->req.iovcnt,
2694 								  0, tcp_req->req.length);
2695 					nvmf_tcp_qpair_set_recv_state(tqpair, NVME_TCP_PDU_RECV_STATE_AWAIT_PDU_PAYLOAD);
2696 				}
2697 				break;
2698 			}
2699 
2700 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_EXECUTE);
2701 			break;
2702 		case TCP_REQUEST_STATE_AWAITING_ZCOPY_START:
2703 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_START, 0, 0,
2704 					  (uintptr_t)tcp_req, tqpair);
2705 			/* Some external code must kick a request into  TCP_REQUEST_STATE_ZCOPY_START_COMPLETED
2706 			 * to escape this state. */
2707 			break;
2708 		case TCP_REQUEST_STATE_ZCOPY_START_COMPLETED:
2709 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_ZCOPY_START_COMPLETED, 0, 0,
2710 					  (uintptr_t)tcp_req, tqpair);
2711 			if (spdk_unlikely(spdk_nvme_cpl_is_error(&tcp_req->req.rsp->nvme_cpl))) {
2712 				SPDK_DEBUGLOG(nvmf_tcp, "Zero-copy start failed for tcp_req(%p) on tqpair=%p\n",
2713 					      tcp_req, tqpair);
2714 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2715 				break;
2716 			}
2717 			if (tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER) {
2718 				SPDK_DEBUGLOG(nvmf_tcp, "Sending R2T for tcp_req(%p) on tqpair=%p\n", tcp_req, tqpair);
2719 				nvmf_tcp_send_r2t_pdu(tqpair, tcp_req);
2720 			} else {
2721 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTED);
2722 			}
2723 			break;
2724 		case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
2725 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_R2T_ACK, 0, 0, (uintptr_t)tcp_req,
2726 					  tqpair);
2727 			/* The R2T completion or the h2c data incoming will kick it out of this state. */
2728 			break;
2729 		case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
2730 
2731 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER, 0, 0,
2732 					  (uintptr_t)tcp_req, tqpair);
2733 			/* Some external code must kick a request into TCP_REQUEST_STATE_READY_TO_EXECUTE
2734 			 * to escape this state. */
2735 			break;
2736 		case TCP_REQUEST_STATE_READY_TO_EXECUTE:
2737 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_EXECUTE, 0, 0, (uintptr_t)tcp_req,
2738 					  tqpair);
2739 
2740 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2741 				assert(tcp_req->req.dif.elba_length >= tcp_req->req.length);
2742 				tcp_req->req.length = tcp_req->req.dif.elba_length;
2743 			}
2744 
2745 			if (!spdk_nvmf_request_using_zcopy(&tcp_req->req)) {
2746 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTING);
2747 				spdk_nvmf_request_exec(&tcp_req->req);
2748 			} else {
2749 				/* For zero-copy, only requests with data coming from host to the
2750 				 * controller can end up here. */
2751 				assert(tcp_req->req.xfer == SPDK_NVME_DATA_HOST_TO_CONTROLLER);
2752 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_ZCOPY_COMMIT);
2753 				spdk_nvmf_request_zcopy_end(&tcp_req->req, true);
2754 			}
2755 			break;
2756 		case TCP_REQUEST_STATE_EXECUTING:
2757 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTING, 0, 0, (uintptr_t)tcp_req, tqpair);
2758 			/* Some external code must kick a request into TCP_REQUEST_STATE_EXECUTED
2759 			 * to escape this state. */
2760 			break;
2761 		case TCP_REQUEST_STATE_AWAITING_ZCOPY_COMMIT:
2762 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_COMMIT, 0, 0,
2763 					  (uintptr_t)tcp_req, tqpair);
2764 			/* Some external code must kick a request into TCP_REQUEST_STATE_EXECUTED
2765 			 * to escape this state. */
2766 			break;
2767 		case TCP_REQUEST_STATE_EXECUTED:
2768 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_EXECUTED, 0, 0, (uintptr_t)tcp_req, tqpair);
2769 
2770 			if (spdk_unlikely(tcp_req->req.dif_enabled)) {
2771 				tcp_req->req.length = tcp_req->req.dif.orig_length;
2772 			}
2773 
2774 			nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_READY_TO_COMPLETE);
2775 			break;
2776 		case TCP_REQUEST_STATE_READY_TO_COMPLETE:
2777 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_READY_TO_COMPLETE, 0, 0, (uintptr_t)tcp_req,
2778 					  tqpair);
2779 			rc = request_transfer_out(&tcp_req->req);
2780 			assert(rc == 0); /* No good way to handle this currently */
2781 			break;
2782 		case TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST:
2783 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_TRANSFERRING_CONTROLLER_TO_HOST, 0, 0,
2784 					  (uintptr_t)tcp_req, tqpair);
2785 			/* Some external code must kick a request into TCP_REQUEST_STATE_COMPLETED
2786 			 * to escape this state. */
2787 			break;
2788 		case TCP_REQUEST_STATE_AWAITING_ZCOPY_RELEASE:
2789 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_AWAIT_ZCOPY_RELEASE, 0, 0,
2790 					  (uintptr_t)tcp_req, tqpair);
2791 			/* Some external code must kick a request into TCP_REQUEST_STATE_COMPLETED
2792 			 * to escape this state. */
2793 			break;
2794 		case TCP_REQUEST_STATE_COMPLETED:
2795 			spdk_trace_record(TRACE_TCP_REQUEST_STATE_COMPLETED, 0, 0, (uintptr_t)tcp_req, tqpair);
2796 			if (tcp_req->req.data_from_pool) {
2797 				spdk_nvmf_request_free_buffers(&tcp_req->req, group, transport);
2798 			} else if (spdk_unlikely(tcp_req->has_in_capsule_data &&
2799 						 (tcp_req->cmd.opc == SPDK_NVME_OPC_FABRIC ||
2800 						  tqpair->qpair.qid == 0) && tcp_req->req.length > transport->opts.in_capsule_data_size)) {
2801 				tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2802 				assert(tgroup->control_msg_list);
2803 				SPDK_DEBUGLOG(nvmf_tcp, "Put buf to control msg list\n");
2804 				nvmf_tcp_control_msg_put(tgroup->control_msg_list, tcp_req->req.data);
2805 			} else if (tcp_req->req.zcopy_bdev_io != NULL) {
2806 				/* If the request has an unreleased zcopy bdev_io, it's either a
2807 				 * read or a failed write */
2808 				assert(spdk_nvmf_request_using_zcopy(&tcp_req->req));
2809 				assert(tcp_req->req.xfer == SPDK_NVME_DATA_CONTROLLER_TO_HOST ||
2810 				       spdk_nvme_cpl_is_error(&tcp_req->req.rsp->nvme_cpl));
2811 				nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_AWAITING_ZCOPY_RELEASE);
2812 				spdk_nvmf_request_zcopy_end(&tcp_req->req, false);
2813 				break;
2814 			}
2815 			tcp_req->req.length = 0;
2816 			tcp_req->req.iovcnt = 0;
2817 			tcp_req->req.data = NULL;
2818 
2819 			nvmf_tcp_req_pdu_fini(tcp_req);
2820 
2821 			nvmf_tcp_req_put(tqpair, tcp_req);
2822 			break;
2823 		case TCP_REQUEST_NUM_STATES:
2824 		default:
2825 			assert(0);
2826 			break;
2827 		}
2828 
2829 		if (tcp_req->state != prev_state) {
2830 			progress = true;
2831 		}
2832 	} while (tcp_req->state != prev_state);
2833 
2834 	return progress;
2835 }
2836 
2837 static void
2838 nvmf_tcp_sock_cb(void *arg, struct spdk_sock_group *group, struct spdk_sock *sock)
2839 {
2840 	struct spdk_nvmf_tcp_qpair *tqpair = arg;
2841 	int rc;
2842 
2843 	assert(tqpair != NULL);
2844 	rc = nvmf_tcp_sock_process(tqpair);
2845 
2846 	/* If there was a new socket error, disconnect */
2847 	if (rc < 0) {
2848 		nvmf_tcp_qpair_disconnect(tqpair);
2849 	}
2850 }
2851 
2852 static int
2853 nvmf_tcp_poll_group_add(struct spdk_nvmf_transport_poll_group *group,
2854 			struct spdk_nvmf_qpair *qpair)
2855 {
2856 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2857 	struct spdk_nvmf_tcp_qpair	*tqpair;
2858 	int				rc;
2859 
2860 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2861 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2862 
2863 	rc =  nvmf_tcp_qpair_sock_init(tqpair);
2864 	if (rc != 0) {
2865 		SPDK_ERRLOG("Cannot set sock opt for tqpair=%p\n", tqpair);
2866 		return -1;
2867 	}
2868 
2869 	rc = nvmf_tcp_qpair_init(&tqpair->qpair);
2870 	if (rc < 0) {
2871 		SPDK_ERRLOG("Cannot init tqpair=%p\n", tqpair);
2872 		return -1;
2873 	}
2874 
2875 	rc = nvmf_tcp_qpair_init_mem_resource(tqpair);
2876 	if (rc < 0) {
2877 		SPDK_ERRLOG("Cannot init memory resource info for tqpair=%p\n", tqpair);
2878 		return -1;
2879 	}
2880 
2881 	rc = spdk_sock_group_add_sock(tgroup->sock_group, tqpair->sock,
2882 				      nvmf_tcp_sock_cb, tqpair);
2883 	if (rc != 0) {
2884 		SPDK_ERRLOG("Could not add sock to sock_group: %s (%d)\n",
2885 			    spdk_strerror(errno), errno);
2886 		return -1;
2887 	}
2888 
2889 	tqpair->group = tgroup;
2890 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_INVALID);
2891 	TAILQ_INSERT_TAIL(&tgroup->qpairs, tqpair, link);
2892 
2893 	return 0;
2894 }
2895 
2896 static int
2897 nvmf_tcp_poll_group_remove(struct spdk_nvmf_transport_poll_group *group,
2898 			   struct spdk_nvmf_qpair *qpair)
2899 {
2900 	struct spdk_nvmf_tcp_poll_group	*tgroup;
2901 	struct spdk_nvmf_tcp_qpair		*tqpair;
2902 	int				rc;
2903 
2904 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2905 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2906 
2907 	assert(tqpair->group == tgroup);
2908 
2909 	SPDK_DEBUGLOG(nvmf_tcp, "remove tqpair=%p from the tgroup=%p\n", tqpair, tgroup);
2910 	if (tqpair->recv_state == NVME_TCP_PDU_RECV_STATE_AWAIT_REQ) {
2911 		TAILQ_REMOVE(&tgroup->await_req, tqpair, link);
2912 	} else {
2913 		TAILQ_REMOVE(&tgroup->qpairs, tqpair, link);
2914 	}
2915 
2916 	rc = spdk_sock_group_remove_sock(tgroup->sock_group, tqpair->sock);
2917 	if (rc != 0) {
2918 		SPDK_ERRLOG("Could not remove sock from sock_group: %s (%d)\n",
2919 			    spdk_strerror(errno), errno);
2920 	}
2921 
2922 	return rc;
2923 }
2924 
2925 static int
2926 nvmf_tcp_req_complete(struct spdk_nvmf_request *req)
2927 {
2928 	struct spdk_nvmf_tcp_transport *ttransport;
2929 	struct spdk_nvmf_tcp_req *tcp_req;
2930 
2931 	ttransport = SPDK_CONTAINEROF(req->qpair->transport, struct spdk_nvmf_tcp_transport, transport);
2932 	tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2933 
2934 	switch (tcp_req->state) {
2935 	case TCP_REQUEST_STATE_EXECUTING:
2936 	case TCP_REQUEST_STATE_AWAITING_ZCOPY_COMMIT:
2937 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_EXECUTED);
2938 		break;
2939 	case TCP_REQUEST_STATE_AWAITING_ZCOPY_START:
2940 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_ZCOPY_START_COMPLETED);
2941 		break;
2942 	case TCP_REQUEST_STATE_AWAITING_ZCOPY_RELEASE:
2943 		nvmf_tcp_req_set_state(tcp_req, TCP_REQUEST_STATE_COMPLETED);
2944 		break;
2945 	default:
2946 		assert(0 && "Unexpected request state");
2947 		break;
2948 	}
2949 
2950 	nvmf_tcp_req_process(ttransport, tcp_req);
2951 
2952 	return 0;
2953 }
2954 
2955 static void
2956 nvmf_tcp_close_qpair(struct spdk_nvmf_qpair *qpair,
2957 		     spdk_nvmf_transport_qpair_fini_cb cb_fn, void *cb_arg)
2958 {
2959 	struct spdk_nvmf_tcp_qpair *tqpair;
2960 
2961 	SPDK_DEBUGLOG(nvmf_tcp, "Qpair: %p\n", qpair);
2962 
2963 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
2964 	nvmf_tcp_qpair_set_state(tqpair, NVME_TCP_QPAIR_STATE_EXITED);
2965 	nvmf_tcp_qpair_destroy(tqpair);
2966 
2967 	if (cb_fn) {
2968 		cb_fn(cb_arg);
2969 	}
2970 }
2971 
2972 static int
2973 nvmf_tcp_poll_group_poll(struct spdk_nvmf_transport_poll_group *group)
2974 {
2975 	struct spdk_nvmf_tcp_poll_group *tgroup;
2976 	int rc;
2977 	struct spdk_nvmf_request *req, *req_tmp;
2978 	struct spdk_nvmf_tcp_req *tcp_req;
2979 	struct spdk_nvmf_tcp_qpair *tqpair, *tqpair_tmp;
2980 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(group->transport,
2981 			struct spdk_nvmf_tcp_transport, transport);
2982 
2983 	tgroup = SPDK_CONTAINEROF(group, struct spdk_nvmf_tcp_poll_group, group);
2984 
2985 	if (spdk_unlikely(TAILQ_EMPTY(&tgroup->qpairs) && TAILQ_EMPTY(&tgroup->await_req))) {
2986 		return 0;
2987 	}
2988 
2989 	STAILQ_FOREACH_SAFE(req, &group->pending_buf_queue, buf_link, req_tmp) {
2990 		tcp_req = SPDK_CONTAINEROF(req, struct spdk_nvmf_tcp_req, req);
2991 		if (nvmf_tcp_req_process(ttransport, tcp_req) == false) {
2992 			break;
2993 		}
2994 	}
2995 
2996 	rc = spdk_sock_group_poll(tgroup->sock_group);
2997 	if (rc < 0) {
2998 		SPDK_ERRLOG("Failed to poll sock_group=%p\n", tgroup->sock_group);
2999 	}
3000 
3001 	TAILQ_FOREACH_SAFE(tqpair, &tgroup->await_req, link, tqpair_tmp) {
3002 		nvmf_tcp_sock_process(tqpair);
3003 	}
3004 
3005 	return rc;
3006 }
3007 
3008 static int
3009 nvmf_tcp_qpair_get_trid(struct spdk_nvmf_qpair *qpair,
3010 			struct spdk_nvme_transport_id *trid, bool peer)
3011 {
3012 	struct spdk_nvmf_tcp_qpair     *tqpair;
3013 	uint16_t			port;
3014 
3015 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
3016 	spdk_nvme_trid_populate_transport(trid, SPDK_NVME_TRANSPORT_TCP);
3017 
3018 	if (peer) {
3019 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->initiator_addr);
3020 		port = tqpair->initiator_port;
3021 	} else {
3022 		snprintf(trid->traddr, sizeof(trid->traddr), "%s", tqpair->target_addr);
3023 		port = tqpair->target_port;
3024 	}
3025 
3026 	if (spdk_sock_is_ipv4(tqpair->sock)) {
3027 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV4;
3028 	} else if (spdk_sock_is_ipv6(tqpair->sock)) {
3029 		trid->adrfam = SPDK_NVMF_ADRFAM_IPV6;
3030 	} else {
3031 		return -1;
3032 	}
3033 
3034 	snprintf(trid->trsvcid, sizeof(trid->trsvcid), "%d", port);
3035 	return 0;
3036 }
3037 
3038 static int
3039 nvmf_tcp_qpair_get_local_trid(struct spdk_nvmf_qpair *qpair,
3040 			      struct spdk_nvme_transport_id *trid)
3041 {
3042 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
3043 }
3044 
3045 static int
3046 nvmf_tcp_qpair_get_peer_trid(struct spdk_nvmf_qpair *qpair,
3047 			     struct spdk_nvme_transport_id *trid)
3048 {
3049 	return nvmf_tcp_qpair_get_trid(qpair, trid, 1);
3050 }
3051 
3052 static int
3053 nvmf_tcp_qpair_get_listen_trid(struct spdk_nvmf_qpair *qpair,
3054 			       struct spdk_nvme_transport_id *trid)
3055 {
3056 	return nvmf_tcp_qpair_get_trid(qpair, trid, 0);
3057 }
3058 
3059 static void
3060 nvmf_tcp_req_set_abort_status(struct spdk_nvmf_request *req,
3061 			      struct spdk_nvmf_tcp_req *tcp_req_to_abort)
3062 {
3063 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sct = SPDK_NVME_SCT_GENERIC;
3064 	tcp_req_to_abort->req.rsp->nvme_cpl.status.sc = SPDK_NVME_SC_ABORTED_BY_REQUEST;
3065 	tcp_req_to_abort->req.rsp->nvme_cpl.cid = tcp_req_to_abort->req.cmd->nvme_cmd.cid;
3066 
3067 	nvmf_tcp_req_set_state(tcp_req_to_abort, TCP_REQUEST_STATE_READY_TO_COMPLETE);
3068 
3069 	req->rsp->nvme_cpl.cdw0 &= ~1U; /* Command was successfully aborted. */
3070 }
3071 
3072 static int
3073 _nvmf_tcp_qpair_abort_request(void *ctx)
3074 {
3075 	struct spdk_nvmf_request *req = ctx;
3076 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = SPDK_CONTAINEROF(req->req_to_abort,
3077 			struct spdk_nvmf_tcp_req, req);
3078 	struct spdk_nvmf_tcp_qpair *tqpair = SPDK_CONTAINEROF(req->req_to_abort->qpair,
3079 					     struct spdk_nvmf_tcp_qpair, qpair);
3080 	struct spdk_nvmf_tcp_transport *ttransport = SPDK_CONTAINEROF(tqpair->qpair.transport,
3081 			struct spdk_nvmf_tcp_transport, transport);
3082 	int rc;
3083 
3084 	spdk_poller_unregister(&req->poller);
3085 
3086 	switch (tcp_req_to_abort->state) {
3087 	case TCP_REQUEST_STATE_EXECUTING:
3088 	case TCP_REQUEST_STATE_AWAITING_ZCOPY_START:
3089 	case TCP_REQUEST_STATE_AWAITING_ZCOPY_COMMIT:
3090 		rc = nvmf_ctrlr_abort_request(req);
3091 		if (rc == SPDK_NVMF_REQUEST_EXEC_STATUS_ASYNCHRONOUS) {
3092 			return SPDK_POLLER_BUSY;
3093 		}
3094 		break;
3095 
3096 	case TCP_REQUEST_STATE_NEED_BUFFER:
3097 		STAILQ_REMOVE(&tqpair->group->group.pending_buf_queue,
3098 			      &tcp_req_to_abort->req, spdk_nvmf_request, buf_link);
3099 
3100 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
3101 		nvmf_tcp_req_process(ttransport, tcp_req_to_abort);
3102 		break;
3103 
3104 	case TCP_REQUEST_STATE_AWAITING_R2T_ACK:
3105 	case TCP_REQUEST_STATE_ZCOPY_START_COMPLETED:
3106 		nvmf_tcp_req_set_abort_status(req, tcp_req_to_abort);
3107 		break;
3108 
3109 	case TCP_REQUEST_STATE_TRANSFERRING_HOST_TO_CONTROLLER:
3110 		if (spdk_get_ticks() < req->timeout_tsc) {
3111 			req->poller = SPDK_POLLER_REGISTER(_nvmf_tcp_qpair_abort_request, req, 0);
3112 			return SPDK_POLLER_BUSY;
3113 		}
3114 		break;
3115 
3116 	default:
3117 		break;
3118 	}
3119 
3120 	spdk_nvmf_request_complete(req);
3121 	return SPDK_POLLER_BUSY;
3122 }
3123 
3124 static void
3125 nvmf_tcp_qpair_abort_request(struct spdk_nvmf_qpair *qpair,
3126 			     struct spdk_nvmf_request *req)
3127 {
3128 	struct spdk_nvmf_tcp_qpair *tqpair;
3129 	struct spdk_nvmf_tcp_transport *ttransport;
3130 	struct spdk_nvmf_transport *transport;
3131 	uint16_t cid;
3132 	uint32_t i;
3133 	struct spdk_nvmf_tcp_req *tcp_req_to_abort = NULL;
3134 
3135 	tqpair = SPDK_CONTAINEROF(qpair, struct spdk_nvmf_tcp_qpair, qpair);
3136 	ttransport = SPDK_CONTAINEROF(qpair->transport, struct spdk_nvmf_tcp_transport, transport);
3137 	transport = &ttransport->transport;
3138 
3139 	cid = req->cmd->nvme_cmd.cdw10_bits.abort.cid;
3140 
3141 	for (i = 0; i < tqpair->resource_count; i++) {
3142 		if (tqpair->reqs[i].state != TCP_REQUEST_STATE_FREE &&
3143 		    tqpair->reqs[i].req.cmd->nvme_cmd.cid == cid) {
3144 			tcp_req_to_abort = &tqpair->reqs[i];
3145 			break;
3146 		}
3147 	}
3148 
3149 	spdk_trace_record(TRACE_TCP_QP_ABORT_REQ, 0, 0, (uintptr_t)req, tqpair);
3150 
3151 	if (tcp_req_to_abort == NULL) {
3152 		spdk_nvmf_request_complete(req);
3153 		return;
3154 	}
3155 
3156 	req->req_to_abort = &tcp_req_to_abort->req;
3157 	req->timeout_tsc = spdk_get_ticks() +
3158 			   transport->opts.abort_timeout_sec * spdk_get_ticks_hz();
3159 	req->poller = NULL;
3160 
3161 	_nvmf_tcp_qpair_abort_request(req);
3162 }
3163 
3164 #define SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH 128
3165 #define SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH 128
3166 #define SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR 128
3167 #define SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE 4096
3168 #define SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE 131072
3169 #define SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE 131072
3170 #define SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS 511
3171 #define SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE 32
3172 #define SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP false
3173 #define SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC 1
3174 
3175 static void
3176 nvmf_tcp_opts_init(struct spdk_nvmf_transport_opts *opts)
3177 {
3178 	opts->max_queue_depth =		SPDK_NVMF_TCP_DEFAULT_MAX_QUEUE_DEPTH;
3179 	opts->max_qpairs_per_ctrlr =	SPDK_NVMF_TCP_DEFAULT_MAX_QPAIRS_PER_CTRLR;
3180 	opts->in_capsule_data_size =	SPDK_NVMF_TCP_DEFAULT_IN_CAPSULE_DATA_SIZE;
3181 	opts->max_io_size =		SPDK_NVMF_TCP_DEFAULT_MAX_IO_SIZE;
3182 	opts->io_unit_size =		SPDK_NVMF_TCP_DEFAULT_IO_UNIT_SIZE;
3183 	opts->max_aq_depth =		SPDK_NVMF_TCP_DEFAULT_AQ_DEPTH;
3184 	opts->num_shared_buffers =	SPDK_NVMF_TCP_DEFAULT_NUM_SHARED_BUFFERS;
3185 	opts->buf_cache_size =		SPDK_NVMF_TCP_DEFAULT_BUFFER_CACHE_SIZE;
3186 	opts->dif_insert_or_strip =	SPDK_NVMF_TCP_DEFAULT_DIF_INSERT_OR_STRIP;
3187 	opts->abort_timeout_sec =	SPDK_NVMF_TCP_DEFAULT_ABORT_TIMEOUT_SEC;
3188 	opts->transport_specific =      NULL;
3189 }
3190 
3191 const struct spdk_nvmf_transport_ops spdk_nvmf_transport_tcp = {
3192 	.name = "TCP",
3193 	.type = SPDK_NVME_TRANSPORT_TCP,
3194 	.opts_init = nvmf_tcp_opts_init,
3195 	.create = nvmf_tcp_create,
3196 	.dump_opts = nvmf_tcp_dump_opts,
3197 	.destroy = nvmf_tcp_destroy,
3198 
3199 	.listen = nvmf_tcp_listen,
3200 	.stop_listen = nvmf_tcp_stop_listen,
3201 
3202 	.listener_discover = nvmf_tcp_discover,
3203 
3204 	.poll_group_create = nvmf_tcp_poll_group_create,
3205 	.get_optimal_poll_group = nvmf_tcp_get_optimal_poll_group,
3206 	.poll_group_destroy = nvmf_tcp_poll_group_destroy,
3207 	.poll_group_add = nvmf_tcp_poll_group_add,
3208 	.poll_group_remove = nvmf_tcp_poll_group_remove,
3209 	.poll_group_poll = nvmf_tcp_poll_group_poll,
3210 
3211 	.req_free = nvmf_tcp_req_free,
3212 	.req_complete = nvmf_tcp_req_complete,
3213 
3214 	.qpair_fini = nvmf_tcp_close_qpair,
3215 	.qpair_get_local_trid = nvmf_tcp_qpair_get_local_trid,
3216 	.qpair_get_peer_trid = nvmf_tcp_qpair_get_peer_trid,
3217 	.qpair_get_listen_trid = nvmf_tcp_qpair_get_listen_trid,
3218 	.qpair_abort_request = nvmf_tcp_qpair_abort_request,
3219 };
3220 
3221 SPDK_NVMF_TRANSPORT_REGISTER(tcp, &spdk_nvmf_transport_tcp);
3222 SPDK_LOG_REGISTER_COMPONENT(nvmf_tcp)
3223