]> asedeno.scripts.mit.edu Git - linux.git/blob - drivers/infiniband/hw/mlx5/devx.c
270452c9e673304781a88d983752e8f79d007681
[linux.git] / drivers / infiniband / hw / mlx5 / devx.c
1 // SPDX-License-Identifier: GPL-2.0 OR Linux-OpenIB
2 /*
3  * Copyright (c) 2018, Mellanox Technologies inc.  All rights reserved.
4  */
5
6 #include <rdma/ib_user_verbs.h>
7 #include <rdma/ib_verbs.h>
8 #include <rdma/uverbs_types.h>
9 #include <rdma/uverbs_ioctl.h>
10 #include <rdma/mlx5_user_ioctl_cmds.h>
11 #include <rdma/ib_umem.h>
12 #include <linux/mlx5/driver.h>
13 #include <linux/mlx5/fs.h>
14 #include "mlx5_ib.h"
15
16 #define UVERBS_MODULE_NAME mlx5_ib
17 #include <rdma/uverbs_named_ioctl.h>
18
19 #define MLX5_MAX_DESTROY_INBOX_SIZE_DW MLX5_ST_SZ_DW(delete_fte_in)
20 struct devx_obj {
21         struct mlx5_core_dev    *mdev;
22         u32                     obj_id;
23         u32                     dinlen; /* destroy inbox length */
24         u32                     dinbox[MLX5_MAX_DESTROY_INBOX_SIZE_DW];
25 };
26
27 struct devx_umem {
28         struct mlx5_core_dev            *mdev;
29         struct ib_umem                  *umem;
30         u32                             page_offset;
31         int                             page_shift;
32         int                             ncont;
33         u32                             dinlen;
34         u32                             dinbox[MLX5_ST_SZ_DW(general_obj_in_cmd_hdr)];
35 };
36
37 struct devx_umem_reg_cmd {
38         void                            *in;
39         u32                             inlen;
40         u32                             out[MLX5_ST_SZ_DW(general_obj_out_cmd_hdr)];
41 };
42
43 static struct mlx5_ib_ucontext *devx_ufile2uctx(struct ib_uverbs_file *file)
44 {
45         return to_mucontext(ib_uverbs_get_ucontext(file));
46 }
47
48 int mlx5_ib_devx_create(struct mlx5_ib_dev *dev, struct mlx5_ib_ucontext *context)
49 {
50         u32 in[MLX5_ST_SZ_DW(create_uctx_in)] = {0};
51         u32 out[MLX5_ST_SZ_DW(general_obj_out_cmd_hdr)] = {0};
52         u64 general_obj_types;
53         void *hdr;
54         int err;
55
56         hdr = MLX5_ADDR_OF(create_uctx_in, in, hdr);
57
58         general_obj_types = MLX5_CAP_GEN_64(dev->mdev, general_obj_types);
59         if (!(general_obj_types & MLX5_GENERAL_OBJ_TYPES_CAP_UCTX) ||
60             !(general_obj_types & MLX5_GENERAL_OBJ_TYPES_CAP_UMEM))
61                 return -EINVAL;
62
63         if (!capable(CAP_NET_RAW))
64                 return -EPERM;
65
66         MLX5_SET(general_obj_in_cmd_hdr, hdr, opcode, MLX5_CMD_OP_CREATE_GENERAL_OBJECT);
67         MLX5_SET(general_obj_in_cmd_hdr, hdr, obj_type, MLX5_OBJ_TYPE_UCTX);
68
69         err = mlx5_cmd_exec(dev->mdev, in, sizeof(in), out, sizeof(out));
70         if (err)
71                 return err;
72
73         context->devx_uid = MLX5_GET(general_obj_out_cmd_hdr, out, obj_id);
74         return 0;
75 }
76
77 void mlx5_ib_devx_destroy(struct mlx5_ib_dev *dev,
78                           struct mlx5_ib_ucontext *context)
79 {
80         u32 in[MLX5_ST_SZ_DW(general_obj_in_cmd_hdr)] = {0};
81         u32 out[MLX5_ST_SZ_DW(general_obj_out_cmd_hdr)] = {0};
82
83         MLX5_SET(general_obj_in_cmd_hdr, in, opcode, MLX5_CMD_OP_DESTROY_GENERAL_OBJECT);
84         MLX5_SET(general_obj_in_cmd_hdr, in, obj_type, MLX5_OBJ_TYPE_UCTX);
85         MLX5_SET(general_obj_in_cmd_hdr, in, obj_id, context->devx_uid);
86
87         mlx5_cmd_exec(dev->mdev, in, sizeof(in), out, sizeof(out));
88 }
89
90 bool mlx5_ib_devx_is_flow_dest(void *obj, int *dest_id, int *dest_type)
91 {
92         struct devx_obj *devx_obj = obj;
93         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, devx_obj->dinbox, opcode);
94
95         switch (opcode) {
96         case MLX5_CMD_OP_DESTROY_TIR:
97                 *dest_type = MLX5_FLOW_DESTINATION_TYPE_TIR;
98                 *dest_id = MLX5_GET(general_obj_in_cmd_hdr, devx_obj->dinbox,
99                                     obj_id);
100                 return true;
101
102         case MLX5_CMD_OP_DESTROY_FLOW_TABLE:
103                 *dest_type = MLX5_FLOW_DESTINATION_TYPE_FLOW_TABLE;
104                 *dest_id = MLX5_GET(destroy_flow_table_in, devx_obj->dinbox,
105                                     table_id);
106                 return true;
107         default:
108                 return false;
109         }
110 }
111
112 static int devx_is_valid_obj_id(struct devx_obj *obj, const void *in)
113 {
114         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, in, opcode);
115         u32 obj_id;
116
117         switch (opcode) {
118         case MLX5_CMD_OP_MODIFY_GENERAL_OBJECT:
119         case MLX5_CMD_OP_QUERY_GENERAL_OBJECT:
120                 obj_id = MLX5_GET(general_obj_in_cmd_hdr, in, obj_id);
121                 break;
122         case MLX5_CMD_OP_QUERY_MKEY:
123                 obj_id = MLX5_GET(query_mkey_in, in, mkey_index);
124                 break;
125         case MLX5_CMD_OP_QUERY_CQ:
126                 obj_id = MLX5_GET(query_cq_in, in, cqn);
127                 break;
128         case MLX5_CMD_OP_MODIFY_CQ:
129                 obj_id = MLX5_GET(modify_cq_in, in, cqn);
130                 break;
131         case MLX5_CMD_OP_QUERY_SQ:
132                 obj_id = MLX5_GET(query_sq_in, in, sqn);
133                 break;
134         case MLX5_CMD_OP_MODIFY_SQ:
135                 obj_id = MLX5_GET(modify_sq_in, in, sqn);
136                 break;
137         case MLX5_CMD_OP_QUERY_RQ:
138                 obj_id = MLX5_GET(query_rq_in, in, rqn);
139                 break;
140         case MLX5_CMD_OP_MODIFY_RQ:
141                 obj_id = MLX5_GET(modify_rq_in, in, rqn);
142                 break;
143         case MLX5_CMD_OP_QUERY_RMP:
144                 obj_id = MLX5_GET(query_rmp_in, in, rmpn);
145                 break;
146         case MLX5_CMD_OP_MODIFY_RMP:
147                 obj_id = MLX5_GET(modify_rmp_in, in, rmpn);
148                 break;
149         case MLX5_CMD_OP_QUERY_RQT:
150                 obj_id = MLX5_GET(query_rqt_in, in, rqtn);
151                 break;
152         case MLX5_CMD_OP_MODIFY_RQT:
153                 obj_id = MLX5_GET(modify_rqt_in, in, rqtn);
154                 break;
155         case MLX5_CMD_OP_QUERY_TIR:
156                 obj_id = MLX5_GET(query_tir_in, in, tirn);
157                 break;
158         case MLX5_CMD_OP_MODIFY_TIR:
159                 obj_id = MLX5_GET(modify_tir_in, in, tirn);
160                 break;
161         case MLX5_CMD_OP_QUERY_TIS:
162                 obj_id = MLX5_GET(query_tis_in, in, tisn);
163                 break;
164         case MLX5_CMD_OP_MODIFY_TIS:
165                 obj_id = MLX5_GET(modify_tis_in, in, tisn);
166                 break;
167         case MLX5_CMD_OP_QUERY_FLOW_TABLE:
168                 obj_id = MLX5_GET(query_flow_table_in, in, table_id);
169                 break;
170         case MLX5_CMD_OP_MODIFY_FLOW_TABLE:
171                 obj_id = MLX5_GET(modify_flow_table_in, in, table_id);
172                 break;
173         case MLX5_CMD_OP_QUERY_FLOW_GROUP:
174                 obj_id = MLX5_GET(query_flow_group_in, in, group_id);
175                 break;
176         case MLX5_CMD_OP_QUERY_FLOW_TABLE_ENTRY:
177                 obj_id = MLX5_GET(query_fte_in, in, flow_index);
178                 break;
179         case MLX5_CMD_OP_SET_FLOW_TABLE_ENTRY:
180                 obj_id = MLX5_GET(set_fte_in, in, flow_index);
181                 break;
182         case MLX5_CMD_OP_QUERY_Q_COUNTER:
183                 obj_id = MLX5_GET(query_q_counter_in, in, counter_set_id);
184                 break;
185         case MLX5_CMD_OP_QUERY_FLOW_COUNTER:
186                 obj_id = MLX5_GET(query_flow_counter_in, in, flow_counter_id);
187                 break;
188         case MLX5_CMD_OP_QUERY_MODIFY_HEADER_CONTEXT:
189                 obj_id = MLX5_GET(general_obj_in_cmd_hdr, in, obj_id);
190                 break;
191         case MLX5_CMD_OP_QUERY_SCHEDULING_ELEMENT:
192                 obj_id = MLX5_GET(query_scheduling_element_in, in,
193                                   scheduling_element_id);
194                 break;
195         case MLX5_CMD_OP_MODIFY_SCHEDULING_ELEMENT:
196                 obj_id = MLX5_GET(modify_scheduling_element_in, in,
197                                   scheduling_element_id);
198                 break;
199         case MLX5_CMD_OP_ADD_VXLAN_UDP_DPORT:
200                 obj_id = MLX5_GET(add_vxlan_udp_dport_in, in, vxlan_udp_port);
201                 break;
202         case MLX5_CMD_OP_QUERY_L2_TABLE_ENTRY:
203                 obj_id = MLX5_GET(query_l2_table_entry_in, in, table_index);
204                 break;
205         case MLX5_CMD_OP_SET_L2_TABLE_ENTRY:
206                 obj_id = MLX5_GET(set_l2_table_entry_in, in, table_index);
207                 break;
208         case MLX5_CMD_OP_QUERY_QP:
209                 obj_id = MLX5_GET(query_qp_in, in, qpn);
210                 break;
211         case MLX5_CMD_OP_RST2INIT_QP:
212                 obj_id = MLX5_GET(rst2init_qp_in, in, qpn);
213                 break;
214         case MLX5_CMD_OP_INIT2RTR_QP:
215                 obj_id = MLX5_GET(init2rtr_qp_in, in, qpn);
216                 break;
217         case MLX5_CMD_OP_RTR2RTS_QP:
218                 obj_id = MLX5_GET(rtr2rts_qp_in, in, qpn);
219                 break;
220         case MLX5_CMD_OP_RTS2RTS_QP:
221                 obj_id = MLX5_GET(rts2rts_qp_in, in, qpn);
222                 break;
223         case MLX5_CMD_OP_SQERR2RTS_QP:
224                 obj_id = MLX5_GET(sqerr2rts_qp_in, in, qpn);
225                 break;
226         case MLX5_CMD_OP_2ERR_QP:
227                 obj_id = MLX5_GET(qp_2err_in, in, qpn);
228                 break;
229         case MLX5_CMD_OP_2RST_QP:
230                 obj_id = MLX5_GET(qp_2rst_in, in, qpn);
231                 break;
232         case MLX5_CMD_OP_QUERY_DCT:
233                 obj_id = MLX5_GET(query_dct_in, in, dctn);
234                 break;
235         case MLX5_CMD_OP_QUERY_XRQ:
236                 obj_id = MLX5_GET(query_xrq_in, in, xrqn);
237                 break;
238         case MLX5_CMD_OP_QUERY_XRC_SRQ:
239                 obj_id = MLX5_GET(query_xrc_srq_in, in, xrc_srqn);
240                 break;
241         case MLX5_CMD_OP_ARM_XRC_SRQ:
242                 obj_id = MLX5_GET(arm_xrc_srq_in, in, xrc_srqn);
243                 break;
244         case MLX5_CMD_OP_QUERY_SRQ:
245                 obj_id = MLX5_GET(query_srq_in, in, srqn);
246                 break;
247         case MLX5_CMD_OP_ARM_RQ:
248                 obj_id = MLX5_GET(arm_rq_in, in, srq_number);
249                 break;
250         case MLX5_CMD_OP_DRAIN_DCT:
251         case MLX5_CMD_OP_ARM_DCT_FOR_KEY_VIOLATION:
252                 obj_id = MLX5_GET(drain_dct_in, in, dctn);
253                 break;
254         case MLX5_CMD_OP_ARM_XRQ:
255                 obj_id = MLX5_GET(arm_xrq_in, in, xrqn);
256                 break;
257         default:
258                 return false;
259         }
260
261         if (obj_id == obj->obj_id)
262                 return true;
263
264         return false;
265 }
266
267 static bool devx_is_obj_create_cmd(const void *in)
268 {
269         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, in, opcode);
270
271         switch (opcode) {
272         case MLX5_CMD_OP_CREATE_GENERAL_OBJECT:
273         case MLX5_CMD_OP_CREATE_MKEY:
274         case MLX5_CMD_OP_CREATE_CQ:
275         case MLX5_CMD_OP_ALLOC_PD:
276         case MLX5_CMD_OP_ALLOC_TRANSPORT_DOMAIN:
277         case MLX5_CMD_OP_CREATE_RMP:
278         case MLX5_CMD_OP_CREATE_SQ:
279         case MLX5_CMD_OP_CREATE_RQ:
280         case MLX5_CMD_OP_CREATE_RQT:
281         case MLX5_CMD_OP_CREATE_TIR:
282         case MLX5_CMD_OP_CREATE_TIS:
283         case MLX5_CMD_OP_ALLOC_Q_COUNTER:
284         case MLX5_CMD_OP_CREATE_FLOW_TABLE:
285         case MLX5_CMD_OP_CREATE_FLOW_GROUP:
286         case MLX5_CMD_OP_ALLOC_FLOW_COUNTER:
287         case MLX5_CMD_OP_ALLOC_ENCAP_HEADER:
288         case MLX5_CMD_OP_ALLOC_MODIFY_HEADER_CONTEXT:
289         case MLX5_CMD_OP_CREATE_SCHEDULING_ELEMENT:
290         case MLX5_CMD_OP_ADD_VXLAN_UDP_DPORT:
291         case MLX5_CMD_OP_SET_L2_TABLE_ENTRY:
292         case MLX5_CMD_OP_CREATE_QP:
293         case MLX5_CMD_OP_CREATE_SRQ:
294         case MLX5_CMD_OP_CREATE_XRC_SRQ:
295         case MLX5_CMD_OP_CREATE_DCT:
296         case MLX5_CMD_OP_CREATE_XRQ:
297         case MLX5_CMD_OP_ATTACH_TO_MCG:
298         case MLX5_CMD_OP_ALLOC_XRCD:
299                 return true;
300         case MLX5_CMD_OP_SET_FLOW_TABLE_ENTRY:
301         {
302                 u16 op_mod = MLX5_GET(set_fte_in, in, op_mod);
303                 if (op_mod == 0)
304                         return true;
305                 return false;
306         }
307         default:
308                 return false;
309         }
310 }
311
312 static bool devx_is_obj_modify_cmd(const void *in)
313 {
314         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, in, opcode);
315
316         switch (opcode) {
317         case MLX5_CMD_OP_MODIFY_GENERAL_OBJECT:
318         case MLX5_CMD_OP_MODIFY_CQ:
319         case MLX5_CMD_OP_MODIFY_RMP:
320         case MLX5_CMD_OP_MODIFY_SQ:
321         case MLX5_CMD_OP_MODIFY_RQ:
322         case MLX5_CMD_OP_MODIFY_RQT:
323         case MLX5_CMD_OP_MODIFY_TIR:
324         case MLX5_CMD_OP_MODIFY_TIS:
325         case MLX5_CMD_OP_MODIFY_FLOW_TABLE:
326         case MLX5_CMD_OP_MODIFY_SCHEDULING_ELEMENT:
327         case MLX5_CMD_OP_ADD_VXLAN_UDP_DPORT:
328         case MLX5_CMD_OP_SET_L2_TABLE_ENTRY:
329         case MLX5_CMD_OP_RST2INIT_QP:
330         case MLX5_CMD_OP_INIT2RTR_QP:
331         case MLX5_CMD_OP_RTR2RTS_QP:
332         case MLX5_CMD_OP_RTS2RTS_QP:
333         case MLX5_CMD_OP_SQERR2RTS_QP:
334         case MLX5_CMD_OP_2ERR_QP:
335         case MLX5_CMD_OP_2RST_QP:
336         case MLX5_CMD_OP_ARM_XRC_SRQ:
337         case MLX5_CMD_OP_ARM_RQ:
338         case MLX5_CMD_OP_DRAIN_DCT:
339         case MLX5_CMD_OP_ARM_DCT_FOR_KEY_VIOLATION:
340         case MLX5_CMD_OP_ARM_XRQ:
341                 return true;
342         case MLX5_CMD_OP_SET_FLOW_TABLE_ENTRY:
343         {
344                 u16 op_mod = MLX5_GET(set_fte_in, in, op_mod);
345
346                 if (op_mod == 1)
347                         return true;
348                 return false;
349         }
350         default:
351                 return false;
352         }
353 }
354
355 static bool devx_is_obj_query_cmd(const void *in)
356 {
357         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, in, opcode);
358
359         switch (opcode) {
360         case MLX5_CMD_OP_QUERY_GENERAL_OBJECT:
361         case MLX5_CMD_OP_QUERY_MKEY:
362         case MLX5_CMD_OP_QUERY_CQ:
363         case MLX5_CMD_OP_QUERY_RMP:
364         case MLX5_CMD_OP_QUERY_SQ:
365         case MLX5_CMD_OP_QUERY_RQ:
366         case MLX5_CMD_OP_QUERY_RQT:
367         case MLX5_CMD_OP_QUERY_TIR:
368         case MLX5_CMD_OP_QUERY_TIS:
369         case MLX5_CMD_OP_QUERY_Q_COUNTER:
370         case MLX5_CMD_OP_QUERY_FLOW_TABLE:
371         case MLX5_CMD_OP_QUERY_FLOW_GROUP:
372         case MLX5_CMD_OP_QUERY_FLOW_TABLE_ENTRY:
373         case MLX5_CMD_OP_QUERY_FLOW_COUNTER:
374         case MLX5_CMD_OP_QUERY_MODIFY_HEADER_CONTEXT:
375         case MLX5_CMD_OP_QUERY_SCHEDULING_ELEMENT:
376         case MLX5_CMD_OP_QUERY_L2_TABLE_ENTRY:
377         case MLX5_CMD_OP_QUERY_QP:
378         case MLX5_CMD_OP_QUERY_SRQ:
379         case MLX5_CMD_OP_QUERY_XRC_SRQ:
380         case MLX5_CMD_OP_QUERY_DCT:
381         case MLX5_CMD_OP_QUERY_XRQ:
382                 return true;
383         default:
384                 return false;
385         }
386 }
387
388 static bool devx_is_general_cmd(void *in)
389 {
390         u16 opcode = MLX5_GET(general_obj_in_cmd_hdr, in, opcode);
391
392         switch (opcode) {
393         case MLX5_CMD_OP_QUERY_HCA_CAP:
394         case MLX5_CMD_OP_QUERY_VPORT_STATE:
395         case MLX5_CMD_OP_QUERY_ADAPTER:
396         case MLX5_CMD_OP_QUERY_ISSI:
397         case MLX5_CMD_OP_QUERY_NIC_VPORT_CONTEXT:
398         case MLX5_CMD_OP_QUERY_ROCE_ADDRESS:
399         case MLX5_CMD_OP_QUERY_VNIC_ENV:
400         case MLX5_CMD_OP_QUERY_VPORT_COUNTER:
401         case MLX5_CMD_OP_GET_DROPPED_PACKET_LOG:
402         case MLX5_CMD_OP_NOP:
403         case MLX5_CMD_OP_QUERY_CONG_STATUS:
404         case MLX5_CMD_OP_QUERY_CONG_PARAMS:
405         case MLX5_CMD_OP_QUERY_CONG_STATISTICS:
406                 return true;
407         default:
408                 return false;
409         }
410 }
411
412 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_QUERY_EQN)(struct ib_device *ib_dev,
413                                   struct ib_uverbs_file *file,
414                                   struct uverbs_attr_bundle *attrs)
415 {
416         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
417         int user_vector;
418         int dev_eqn;
419         unsigned int irqn;
420         int err;
421
422         if (uverbs_copy_from(&user_vector, attrs,
423                              MLX5_IB_ATTR_DEVX_QUERY_EQN_USER_VEC))
424                 return -EFAULT;
425
426         err = mlx5_vector2eqn(dev->mdev, user_vector, &dev_eqn, &irqn);
427         if (err < 0)
428                 return err;
429
430         if (uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_QUERY_EQN_DEV_EQN,
431                            &dev_eqn, sizeof(dev_eqn)))
432                 return -EFAULT;
433
434         return 0;
435 }
436
437 /*
438  *Security note:
439  * The hardware protection mechanism works like this: Each device object that
440  * is subject to UAR doorbells (QP/SQ/CQ) gets a UAR ID (called uar_page in
441  * the device specification manual) upon its creation. Then upon doorbell,
442  * hardware fetches the object context for which the doorbell was rang, and
443  * validates that the UAR through which the DB was rang matches the UAR ID
444  * of the object.
445  * If no match the doorbell is silently ignored by the hardware. Of course,
446  * the user cannot ring a doorbell on a UAR that was not mapped to it.
447  * Now in devx, as the devx kernel does not manipulate the QP/SQ/CQ command
448  * mailboxes (except tagging them with UID), we expose to the user its UAR
449  * ID, so it can embed it in these objects in the expected specification
450  * format. So the only thing the user can do is hurt itself by creating a
451  * QP/SQ/CQ with a UAR ID other than his, and then in this case other users
452  * may ring a doorbell on its objects.
453  * The consequence of that will be that another user can schedule a QP/SQ
454  * of the buggy user for execution (just insert it to the hardware schedule
455  * queue or arm its CQ for event generation), no further harm is expected.
456  */
457 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_QUERY_UAR)(struct ib_device *ib_dev,
458                                   struct ib_uverbs_file *file,
459                                   struct uverbs_attr_bundle *attrs)
460 {
461         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
462         u32 user_idx;
463         s32 dev_idx;
464
465         if (uverbs_copy_from(&user_idx, attrs,
466                              MLX5_IB_ATTR_DEVX_QUERY_UAR_USER_IDX))
467                 return -EFAULT;
468
469         dev_idx = bfregn_to_uar_index(to_mdev(ib_dev),
470                                       &c->bfregi, user_idx, true);
471         if (dev_idx < 0)
472                 return dev_idx;
473
474         if (uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_QUERY_UAR_DEV_IDX,
475                            &dev_idx, sizeof(dev_idx)))
476                 return -EFAULT;
477
478         return 0;
479 }
480
481 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_OTHER)(struct ib_device *ib_dev,
482                                   struct ib_uverbs_file *file,
483                                   struct uverbs_attr_bundle *attrs)
484 {
485         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
486         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
487         void *cmd_in = uverbs_attr_get_alloced_ptr(
488                 attrs, MLX5_IB_ATTR_DEVX_OTHER_CMD_IN);
489         int cmd_out_len = uverbs_attr_get_len(attrs,
490                                         MLX5_IB_ATTR_DEVX_OTHER_CMD_OUT);
491         void *cmd_out;
492         int err;
493
494         if (!c->devx_uid)
495                 return -EPERM;
496
497         /* Only white list of some general HCA commands are allowed for this method. */
498         if (!devx_is_general_cmd(cmd_in))
499                 return -EINVAL;
500
501         cmd_out = kvzalloc(cmd_out_len, GFP_KERNEL);
502         if (!cmd_out)
503                 return -ENOMEM;
504
505         MLX5_SET(general_obj_in_cmd_hdr, cmd_in, uid, c->devx_uid);
506         err = mlx5_cmd_exec(dev->mdev, cmd_in,
507                             uverbs_attr_get_len(attrs, MLX5_IB_ATTR_DEVX_OTHER_CMD_IN),
508                             cmd_out, cmd_out_len);
509         if (err)
510                 goto other_cmd_free;
511
512         err = uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_OTHER_CMD_OUT, cmd_out, cmd_out_len);
513
514 other_cmd_free:
515         kvfree(cmd_out);
516         return err;
517 }
518
519 static void devx_obj_build_destroy_cmd(void *in, void *out, void *din,
520                                        u32 *dinlen,
521                                        u32 *obj_id)
522 {
523         u16 obj_type = MLX5_GET(general_obj_in_cmd_hdr, in, obj_type);
524         u16 uid = MLX5_GET(general_obj_in_cmd_hdr, in, uid);
525
526         *obj_id = MLX5_GET(general_obj_out_cmd_hdr, out, obj_id);
527         *dinlen = MLX5_ST_SZ_BYTES(general_obj_in_cmd_hdr);
528
529         MLX5_SET(general_obj_in_cmd_hdr, din, obj_id, *obj_id);
530         MLX5_SET(general_obj_in_cmd_hdr, din, uid, uid);
531
532         switch (MLX5_GET(general_obj_in_cmd_hdr, in, opcode)) {
533         case MLX5_CMD_OP_CREATE_GENERAL_OBJECT:
534                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_GENERAL_OBJECT);
535                 MLX5_SET(general_obj_in_cmd_hdr, din, obj_type, obj_type);
536                 break;
537
538         case MLX5_CMD_OP_CREATE_MKEY:
539                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_MKEY);
540                 break;
541         case MLX5_CMD_OP_CREATE_CQ:
542                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_CQ);
543                 break;
544         case MLX5_CMD_OP_ALLOC_PD:
545                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DEALLOC_PD);
546                 break;
547         case MLX5_CMD_OP_ALLOC_TRANSPORT_DOMAIN:
548                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
549                          MLX5_CMD_OP_DEALLOC_TRANSPORT_DOMAIN);
550                 break;
551         case MLX5_CMD_OP_CREATE_RMP:
552                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_RMP);
553                 break;
554         case MLX5_CMD_OP_CREATE_SQ:
555                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_SQ);
556                 break;
557         case MLX5_CMD_OP_CREATE_RQ:
558                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_RQ);
559                 break;
560         case MLX5_CMD_OP_CREATE_RQT:
561                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_RQT);
562                 break;
563         case MLX5_CMD_OP_CREATE_TIR:
564                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_TIR);
565                 break;
566         case MLX5_CMD_OP_CREATE_TIS:
567                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_TIS);
568                 break;
569         case MLX5_CMD_OP_ALLOC_Q_COUNTER:
570                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
571                          MLX5_CMD_OP_DEALLOC_Q_COUNTER);
572                 break;
573         case MLX5_CMD_OP_CREATE_FLOW_TABLE:
574                 *dinlen = MLX5_ST_SZ_BYTES(destroy_flow_table_in);
575                 *obj_id = MLX5_GET(create_flow_table_out, out, table_id);
576                 MLX5_SET(destroy_flow_table_in, din, other_vport,
577                          MLX5_GET(create_flow_table_in,  in, other_vport));
578                 MLX5_SET(destroy_flow_table_in, din, vport_number,
579                          MLX5_GET(create_flow_table_in,  in, vport_number));
580                 MLX5_SET(destroy_flow_table_in, din, table_type,
581                          MLX5_GET(create_flow_table_in,  in, table_type));
582                 MLX5_SET(destroy_flow_table_in, din, table_id, *obj_id);
583                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
584                          MLX5_CMD_OP_DESTROY_FLOW_TABLE);
585                 break;
586         case MLX5_CMD_OP_CREATE_FLOW_GROUP:
587                 *dinlen = MLX5_ST_SZ_BYTES(destroy_flow_group_in);
588                 *obj_id = MLX5_GET(create_flow_group_out, out, group_id);
589                 MLX5_SET(destroy_flow_group_in, din, other_vport,
590                          MLX5_GET(create_flow_group_in, in, other_vport));
591                 MLX5_SET(destroy_flow_group_in, din, vport_number,
592                          MLX5_GET(create_flow_group_in, in, vport_number));
593                 MLX5_SET(destroy_flow_group_in, din, table_type,
594                          MLX5_GET(create_flow_group_in, in, table_type));
595                 MLX5_SET(destroy_flow_group_in, din, table_id,
596                          MLX5_GET(create_flow_group_in, in, table_id));
597                 MLX5_SET(destroy_flow_group_in, din, group_id, *obj_id);
598                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
599                          MLX5_CMD_OP_DESTROY_FLOW_GROUP);
600                 break;
601         case MLX5_CMD_OP_SET_FLOW_TABLE_ENTRY:
602                 *dinlen = MLX5_ST_SZ_BYTES(delete_fte_in);
603                 *obj_id = MLX5_GET(set_fte_in, in, flow_index);
604                 MLX5_SET(delete_fte_in, din, other_vport,
605                          MLX5_GET(set_fte_in,  in, other_vport));
606                 MLX5_SET(delete_fte_in, din, vport_number,
607                          MLX5_GET(set_fte_in, in, vport_number));
608                 MLX5_SET(delete_fte_in, din, table_type,
609                          MLX5_GET(set_fte_in, in, table_type));
610                 MLX5_SET(delete_fte_in, din, table_id,
611                          MLX5_GET(set_fte_in, in, table_id));
612                 MLX5_SET(delete_fte_in, din, flow_index, *obj_id);
613                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
614                          MLX5_CMD_OP_DELETE_FLOW_TABLE_ENTRY);
615                 break;
616         case MLX5_CMD_OP_ALLOC_FLOW_COUNTER:
617                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
618                          MLX5_CMD_OP_DEALLOC_FLOW_COUNTER);
619                 break;
620         case MLX5_CMD_OP_ALLOC_ENCAP_HEADER:
621                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
622                          MLX5_CMD_OP_DEALLOC_ENCAP_HEADER);
623                 break;
624         case MLX5_CMD_OP_ALLOC_MODIFY_HEADER_CONTEXT:
625                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
626                          MLX5_CMD_OP_DEALLOC_MODIFY_HEADER_CONTEXT);
627                 break;
628         case MLX5_CMD_OP_CREATE_SCHEDULING_ELEMENT:
629                 *dinlen = MLX5_ST_SZ_BYTES(destroy_scheduling_element_in);
630                 *obj_id = MLX5_GET(create_scheduling_element_out, out,
631                                    scheduling_element_id);
632                 MLX5_SET(destroy_scheduling_element_in, din,
633                          scheduling_hierarchy,
634                          MLX5_GET(create_scheduling_element_in, in,
635                                   scheduling_hierarchy));
636                 MLX5_SET(destroy_scheduling_element_in, din,
637                          scheduling_element_id, *obj_id);
638                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
639                          MLX5_CMD_OP_DESTROY_SCHEDULING_ELEMENT);
640                 break;
641         case MLX5_CMD_OP_ADD_VXLAN_UDP_DPORT:
642                 *dinlen = MLX5_ST_SZ_BYTES(delete_vxlan_udp_dport_in);
643                 *obj_id = MLX5_GET(add_vxlan_udp_dport_in, in, vxlan_udp_port);
644                 MLX5_SET(delete_vxlan_udp_dport_in, din, vxlan_udp_port, *obj_id);
645                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
646                          MLX5_CMD_OP_DELETE_VXLAN_UDP_DPORT);
647                 break;
648         case MLX5_CMD_OP_SET_L2_TABLE_ENTRY:
649                 *dinlen = MLX5_ST_SZ_BYTES(delete_l2_table_entry_in);
650                 *obj_id = MLX5_GET(set_l2_table_entry_in, in, table_index);
651                 MLX5_SET(delete_l2_table_entry_in, din, table_index, *obj_id);
652                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
653                          MLX5_CMD_OP_DELETE_L2_TABLE_ENTRY);
654                 break;
655         case MLX5_CMD_OP_CREATE_QP:
656                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_QP);
657                 break;
658         case MLX5_CMD_OP_CREATE_SRQ:
659                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_SRQ);
660                 break;
661         case MLX5_CMD_OP_CREATE_XRC_SRQ:
662                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode,
663                          MLX5_CMD_OP_DESTROY_XRC_SRQ);
664                 break;
665         case MLX5_CMD_OP_CREATE_DCT:
666                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_DCT);
667                 break;
668         case MLX5_CMD_OP_CREATE_XRQ:
669                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DESTROY_XRQ);
670                 break;
671         case MLX5_CMD_OP_ATTACH_TO_MCG:
672                 *dinlen = MLX5_ST_SZ_BYTES(detach_from_mcg_in);
673                 MLX5_SET(detach_from_mcg_in, din, qpn,
674                          MLX5_GET(attach_to_mcg_in, in, qpn));
675                 memcpy(MLX5_ADDR_OF(detach_from_mcg_in, din, multicast_gid),
676                        MLX5_ADDR_OF(attach_to_mcg_in, in, multicast_gid),
677                        MLX5_FLD_SZ_BYTES(attach_to_mcg_in, multicast_gid));
678                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DETACH_FROM_MCG);
679                 break;
680         case MLX5_CMD_OP_ALLOC_XRCD:
681                 MLX5_SET(general_obj_in_cmd_hdr, din, opcode, MLX5_CMD_OP_DEALLOC_XRCD);
682                 break;
683         default:
684                 /* The entry must match to one of the devx_is_obj_create_cmd */
685                 WARN_ON(true);
686                 break;
687         }
688 }
689
690 static int devx_obj_cleanup(struct ib_uobject *uobject,
691                             enum rdma_remove_reason why)
692 {
693         u32 out[MLX5_ST_SZ_DW(general_obj_out_cmd_hdr)];
694         struct devx_obj *obj = uobject->object;
695         int ret;
696
697         ret = mlx5_cmd_exec(obj->mdev, obj->dinbox, obj->dinlen, out, sizeof(out));
698         if (ib_is_destroy_retryable(ret, why, uobject))
699                 return ret;
700
701         kfree(obj);
702         return ret;
703 }
704
705 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_OBJ_CREATE)(struct ib_device *ib_dev,
706                                    struct ib_uverbs_file *file,
707                                    struct uverbs_attr_bundle *attrs)
708 {
709         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
710         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
711         void *cmd_in = uverbs_attr_get_alloced_ptr(attrs, MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_IN);
712         int cmd_out_len =  uverbs_attr_get_len(attrs,
713                                         MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_OUT);
714         void *cmd_out;
715         struct ib_uobject *uobj;
716         struct devx_obj *obj;
717         int err;
718
719         if (!c->devx_uid)
720                 return -EPERM;
721
722         if (!devx_is_obj_create_cmd(cmd_in))
723                 return -EINVAL;
724
725         obj = kzalloc(sizeof(struct devx_obj), GFP_KERNEL);
726         if (!obj)
727                 return -ENOMEM;
728
729         cmd_out = kvzalloc(cmd_out_len, GFP_KERNEL);
730         if (!cmd_out) {
731                 err = -ENOMEM;
732                 goto obj_free;
733         }
734
735         MLX5_SET(general_obj_in_cmd_hdr, cmd_in, uid, c->devx_uid);
736         err = mlx5_cmd_exec(dev->mdev, cmd_in,
737                             uverbs_attr_get_len(attrs, MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_IN),
738                             cmd_out, cmd_out_len);
739         if (err)
740                 goto cmd_free;
741
742         uobj = uverbs_attr_get_uobject(attrs, MLX5_IB_ATTR_DEVX_OBJ_CREATE_HANDLE);
743         uobj->object = obj;
744         obj->mdev = dev->mdev;
745         devx_obj_build_destroy_cmd(cmd_in, cmd_out, obj->dinbox, &obj->dinlen, &obj->obj_id);
746         WARN_ON(obj->dinlen > MLX5_MAX_DESTROY_INBOX_SIZE_DW * sizeof(u32));
747
748         err = uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_OUT, cmd_out, cmd_out_len);
749         if (err)
750                 goto cmd_free;
751
752         kvfree(cmd_out);
753         return 0;
754
755 cmd_free:
756         kvfree(cmd_out);
757 obj_free:
758         kfree(obj);
759         return err;
760 }
761
762 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_OBJ_MODIFY)(struct ib_device *ib_dev,
763                                    struct ib_uverbs_file *file,
764                                    struct uverbs_attr_bundle *attrs)
765 {
766         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
767         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
768         void *cmd_in = uverbs_attr_get_alloced_ptr(attrs, MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_IN);
769         int cmd_out_len = uverbs_attr_get_len(attrs,
770                                         MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_OUT);
771         struct ib_uobject *uobj = uverbs_attr_get_uobject(attrs,
772                                                           MLX5_IB_ATTR_DEVX_OBJ_MODIFY_HANDLE);
773         void *cmd_out;
774         int err;
775
776         if (!c->devx_uid)
777                 return -EPERM;
778
779         if (!devx_is_obj_modify_cmd(cmd_in))
780                 return -EINVAL;
781
782         if (!devx_is_valid_obj_id(uobj->object, cmd_in))
783                 return -EINVAL;
784
785         cmd_out = kvzalloc(cmd_out_len, GFP_KERNEL);
786         if (!cmd_out)
787                 return -ENOMEM;
788
789         MLX5_SET(general_obj_in_cmd_hdr, cmd_in, uid, c->devx_uid);
790         err = mlx5_cmd_exec(dev->mdev, cmd_in,
791                             uverbs_attr_get_len(attrs, MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_IN),
792                             cmd_out, cmd_out_len);
793         if (err)
794                 goto other_cmd_free;
795
796         err = uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_OUT,
797                              cmd_out, cmd_out_len);
798
799 other_cmd_free:
800         kvfree(cmd_out);
801         return err;
802 }
803
804 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_OBJ_QUERY)(struct ib_device *ib_dev,
805                                    struct ib_uverbs_file *file,
806                                    struct uverbs_attr_bundle *attrs)
807 {
808         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
809         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
810         void *cmd_in = uverbs_attr_get_alloced_ptr(attrs, MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_IN);
811         int cmd_out_len = uverbs_attr_get_len(attrs,
812                                               MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_OUT);
813         struct ib_uobject *uobj = uverbs_attr_get_uobject(attrs,
814                                                           MLX5_IB_ATTR_DEVX_OBJ_QUERY_HANDLE);
815         void *cmd_out;
816         int err;
817
818         if (!c->devx_uid)
819                 return -EPERM;
820
821         if (!devx_is_obj_query_cmd(cmd_in))
822                 return -EINVAL;
823
824         if (!devx_is_valid_obj_id(uobj->object, cmd_in))
825                 return -EINVAL;
826
827         cmd_out = kvzalloc(cmd_out_len, GFP_KERNEL);
828         if (!cmd_out)
829                 return -ENOMEM;
830
831         MLX5_SET(general_obj_in_cmd_hdr, cmd_in, uid, c->devx_uid);
832         err = mlx5_cmd_exec(dev->mdev, cmd_in,
833                             uverbs_attr_get_len(attrs, MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_IN),
834                             cmd_out, cmd_out_len);
835         if (err)
836                 goto other_cmd_free;
837
838         err = uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_OUT, cmd_out, cmd_out_len);
839
840 other_cmd_free:
841         kvfree(cmd_out);
842         return err;
843 }
844
845 static int devx_umem_get(struct mlx5_ib_dev *dev, struct ib_ucontext *ucontext,
846                          struct uverbs_attr_bundle *attrs,
847                          struct devx_umem *obj)
848 {
849         u64 addr;
850         size_t size;
851         int access;
852         int npages;
853         int err;
854         u32 page_mask;
855
856         if (uverbs_copy_from(&addr, attrs, MLX5_IB_ATTR_DEVX_UMEM_REG_ADDR) ||
857             uverbs_copy_from(&size, attrs, MLX5_IB_ATTR_DEVX_UMEM_REG_LEN) ||
858             uverbs_copy_from(&access, attrs, MLX5_IB_ATTR_DEVX_UMEM_REG_ACCESS))
859                 return -EFAULT;
860
861         err = ib_check_mr_access(access);
862         if (err)
863                 return err;
864
865         obj->umem = ib_umem_get(ucontext, addr, size, access, 0);
866         if (IS_ERR(obj->umem))
867                 return PTR_ERR(obj->umem);
868
869         mlx5_ib_cont_pages(obj->umem, obj->umem->address,
870                            MLX5_MKEY_PAGE_SHIFT_MASK, &npages,
871                            &obj->page_shift, &obj->ncont, NULL);
872
873         if (!npages) {
874                 ib_umem_release(obj->umem);
875                 return -EINVAL;
876         }
877
878         page_mask = (1 << obj->page_shift) - 1;
879         obj->page_offset = obj->umem->address & page_mask;
880
881         return 0;
882 }
883
884 static int devx_umem_reg_cmd_alloc(struct devx_umem *obj,
885                                    struct devx_umem_reg_cmd *cmd)
886 {
887         cmd->inlen = MLX5_ST_SZ_BYTES(create_umem_in) +
888                     (MLX5_ST_SZ_BYTES(mtt) * obj->ncont);
889         cmd->in = kvzalloc(cmd->inlen, GFP_KERNEL);
890         return cmd->in ? 0 : -ENOMEM;
891 }
892
893 static void devx_umem_reg_cmd_free(struct devx_umem_reg_cmd *cmd)
894 {
895         kvfree(cmd->in);
896 }
897
898 static void devx_umem_reg_cmd_build(struct mlx5_ib_dev *dev,
899                                     struct devx_umem *obj,
900                                     struct devx_umem_reg_cmd *cmd)
901 {
902         void *umem;
903         __be64 *mtt;
904
905         umem = MLX5_ADDR_OF(create_umem_in, cmd->in, umem);
906         mtt = (__be64 *)MLX5_ADDR_OF(umem, umem, mtt);
907
908         MLX5_SET(general_obj_in_cmd_hdr, cmd->in, opcode, MLX5_CMD_OP_CREATE_GENERAL_OBJECT);
909         MLX5_SET(general_obj_in_cmd_hdr, cmd->in, obj_type, MLX5_OBJ_TYPE_UMEM);
910         MLX5_SET64(umem, umem, num_of_mtt, obj->ncont);
911         MLX5_SET(umem, umem, log_page_size, obj->page_shift -
912                                             MLX5_ADAPTER_PAGE_SHIFT);
913         MLX5_SET(umem, umem, page_offset, obj->page_offset);
914         mlx5_ib_populate_pas(dev, obj->umem, obj->page_shift, mtt,
915                              (obj->umem->writable ? MLX5_IB_MTT_WRITE : 0) |
916                              MLX5_IB_MTT_READ);
917 }
918
919 static int UVERBS_HANDLER(MLX5_IB_METHOD_DEVX_UMEM_REG)(struct ib_device *ib_dev,
920                                  struct ib_uverbs_file *file,
921                                  struct uverbs_attr_bundle *attrs)
922 {
923         struct mlx5_ib_ucontext *c = devx_ufile2uctx(file);
924         struct mlx5_ib_dev *dev = to_mdev(ib_dev);
925         struct devx_umem_reg_cmd cmd;
926         struct devx_umem *obj;
927         struct ib_uobject *uobj;
928         u32 obj_id;
929         int err;
930
931         if (!c->devx_uid)
932                 return -EPERM;
933
934         uobj = uverbs_attr_get_uobject(attrs, MLX5_IB_ATTR_DEVX_UMEM_REG_HANDLE);
935         obj = kzalloc(sizeof(struct devx_umem), GFP_KERNEL);
936         if (!obj)
937                 return -ENOMEM;
938
939         err = devx_umem_get(dev, &c->ibucontext, attrs, obj);
940         if (err)
941                 goto err_obj_free;
942
943         err = devx_umem_reg_cmd_alloc(obj, &cmd);
944         if (err)
945                 goto err_umem_release;
946
947         devx_umem_reg_cmd_build(dev, obj, &cmd);
948
949         MLX5_SET(general_obj_in_cmd_hdr, cmd.in, uid, c->devx_uid);
950         err = mlx5_cmd_exec(dev->mdev, cmd.in, cmd.inlen, cmd.out,
951                             sizeof(cmd.out));
952         if (err)
953                 goto err_umem_reg_cmd_free;
954
955         obj->mdev = dev->mdev;
956         uobj->object = obj;
957         devx_obj_build_destroy_cmd(cmd.in, cmd.out, obj->dinbox, &obj->dinlen, &obj_id);
958         err = uverbs_copy_to(attrs, MLX5_IB_ATTR_DEVX_UMEM_REG_OUT_ID, &obj_id, sizeof(obj_id));
959         if (err)
960                 goto err_umem_destroy;
961
962         devx_umem_reg_cmd_free(&cmd);
963
964         return 0;
965
966 err_umem_destroy:
967         mlx5_cmd_exec(obj->mdev, obj->dinbox, obj->dinlen, cmd.out, sizeof(cmd.out));
968 err_umem_reg_cmd_free:
969         devx_umem_reg_cmd_free(&cmd);
970 err_umem_release:
971         ib_umem_release(obj->umem);
972 err_obj_free:
973         kfree(obj);
974         return err;
975 }
976
977 static int devx_umem_cleanup(struct ib_uobject *uobject,
978                              enum rdma_remove_reason why)
979 {
980         struct devx_umem *obj = uobject->object;
981         u32 out[MLX5_ST_SZ_DW(general_obj_out_cmd_hdr)];
982         int err;
983
984         err = mlx5_cmd_exec(obj->mdev, obj->dinbox, obj->dinlen, out, sizeof(out));
985         if (ib_is_destroy_retryable(err, why, uobject))
986                 return err;
987
988         ib_umem_release(obj->umem);
989         kfree(obj);
990         return 0;
991 }
992
993 DECLARE_UVERBS_NAMED_METHOD(
994         MLX5_IB_METHOD_DEVX_UMEM_REG,
995         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_UMEM_REG_HANDLE,
996                         MLX5_IB_OBJECT_DEVX_UMEM,
997                         UVERBS_ACCESS_NEW,
998                         UA_MANDATORY),
999         UVERBS_ATTR_PTR_IN(MLX5_IB_ATTR_DEVX_UMEM_REG_ADDR,
1000                            UVERBS_ATTR_TYPE(u64),
1001                            UA_MANDATORY),
1002         UVERBS_ATTR_PTR_IN(MLX5_IB_ATTR_DEVX_UMEM_REG_LEN,
1003                            UVERBS_ATTR_TYPE(u64),
1004                            UA_MANDATORY),
1005         UVERBS_ATTR_PTR_IN(MLX5_IB_ATTR_DEVX_UMEM_REG_ACCESS,
1006                            UVERBS_ATTR_TYPE(u32),
1007                            UA_MANDATORY),
1008         UVERBS_ATTR_PTR_OUT(MLX5_IB_ATTR_DEVX_UMEM_REG_OUT_ID,
1009                             UVERBS_ATTR_TYPE(u32),
1010                             UA_MANDATORY));
1011
1012 DECLARE_UVERBS_NAMED_METHOD_DESTROY(
1013         MLX5_IB_METHOD_DEVX_UMEM_DEREG,
1014         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_UMEM_DEREG_HANDLE,
1015                         MLX5_IB_OBJECT_DEVX_UMEM,
1016                         UVERBS_ACCESS_DESTROY,
1017                         UA_MANDATORY));
1018
1019 DECLARE_UVERBS_NAMED_METHOD(
1020         MLX5_IB_METHOD_DEVX_QUERY_EQN,
1021         UVERBS_ATTR_PTR_IN(MLX5_IB_ATTR_DEVX_QUERY_EQN_USER_VEC,
1022                            UVERBS_ATTR_TYPE(u32),
1023                            UA_MANDATORY),
1024         UVERBS_ATTR_PTR_OUT(MLX5_IB_ATTR_DEVX_QUERY_EQN_DEV_EQN,
1025                             UVERBS_ATTR_TYPE(u32),
1026                             UA_MANDATORY));
1027
1028 DECLARE_UVERBS_NAMED_METHOD(
1029         MLX5_IB_METHOD_DEVX_QUERY_UAR,
1030         UVERBS_ATTR_PTR_IN(MLX5_IB_ATTR_DEVX_QUERY_UAR_USER_IDX,
1031                            UVERBS_ATTR_TYPE(u32),
1032                            UA_MANDATORY),
1033         UVERBS_ATTR_PTR_OUT(MLX5_IB_ATTR_DEVX_QUERY_UAR_DEV_IDX,
1034                             UVERBS_ATTR_TYPE(u32),
1035                             UA_MANDATORY));
1036
1037 DECLARE_UVERBS_NAMED_METHOD(
1038         MLX5_IB_METHOD_DEVX_OTHER,
1039         UVERBS_ATTR_PTR_IN(
1040                 MLX5_IB_ATTR_DEVX_OTHER_CMD_IN,
1041                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_in_cmd_hdr)),
1042                 UA_MANDATORY,
1043                 UA_ALLOC_AND_COPY),
1044         UVERBS_ATTR_PTR_OUT(
1045                 MLX5_IB_ATTR_DEVX_OTHER_CMD_OUT,
1046                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_out_cmd_hdr)),
1047                 UA_MANDATORY));
1048
1049 DECLARE_UVERBS_NAMED_METHOD(
1050         MLX5_IB_METHOD_DEVX_OBJ_CREATE,
1051         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_OBJ_CREATE_HANDLE,
1052                         MLX5_IB_OBJECT_DEVX_OBJ,
1053                         UVERBS_ACCESS_NEW,
1054                         UA_MANDATORY),
1055         UVERBS_ATTR_PTR_IN(
1056                 MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_IN,
1057                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_in_cmd_hdr)),
1058                 UA_MANDATORY,
1059                 UA_ALLOC_AND_COPY),
1060         UVERBS_ATTR_PTR_OUT(
1061                 MLX5_IB_ATTR_DEVX_OBJ_CREATE_CMD_OUT,
1062                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_out_cmd_hdr)),
1063                 UA_MANDATORY));
1064
1065 DECLARE_UVERBS_NAMED_METHOD_DESTROY(
1066         MLX5_IB_METHOD_DEVX_OBJ_DESTROY,
1067         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_OBJ_DESTROY_HANDLE,
1068                         MLX5_IB_OBJECT_DEVX_OBJ,
1069                         UVERBS_ACCESS_DESTROY,
1070                         UA_MANDATORY));
1071
1072 DECLARE_UVERBS_NAMED_METHOD(
1073         MLX5_IB_METHOD_DEVX_OBJ_MODIFY,
1074         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_OBJ_MODIFY_HANDLE,
1075                         MLX5_IB_OBJECT_DEVX_OBJ,
1076                         UVERBS_ACCESS_WRITE,
1077                         UA_MANDATORY),
1078         UVERBS_ATTR_PTR_IN(
1079                 MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_IN,
1080                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_in_cmd_hdr)),
1081                 UA_MANDATORY,
1082                 UA_ALLOC_AND_COPY),
1083         UVERBS_ATTR_PTR_OUT(
1084                 MLX5_IB_ATTR_DEVX_OBJ_MODIFY_CMD_OUT,
1085                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_out_cmd_hdr)),
1086                 UA_MANDATORY));
1087
1088 DECLARE_UVERBS_NAMED_METHOD(
1089         MLX5_IB_METHOD_DEVX_OBJ_QUERY,
1090         UVERBS_ATTR_IDR(MLX5_IB_ATTR_DEVX_OBJ_QUERY_HANDLE,
1091                         MLX5_IB_OBJECT_DEVX_OBJ,
1092                         UVERBS_ACCESS_READ,
1093                         UA_MANDATORY),
1094         UVERBS_ATTR_PTR_IN(
1095                 MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_IN,
1096                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_in_cmd_hdr)),
1097                 UA_MANDATORY,
1098                 UA_ALLOC_AND_COPY),
1099         UVERBS_ATTR_PTR_OUT(
1100                 MLX5_IB_ATTR_DEVX_OBJ_QUERY_CMD_OUT,
1101                 UVERBS_ATTR_MIN_SIZE(MLX5_ST_SZ_BYTES(general_obj_out_cmd_hdr)),
1102                 UA_MANDATORY));
1103
1104 DECLARE_UVERBS_GLOBAL_METHODS(MLX5_IB_OBJECT_DEVX,
1105                               &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_OTHER),
1106                               &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_QUERY_UAR),
1107                               &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_QUERY_EQN));
1108
1109 DECLARE_UVERBS_NAMED_OBJECT(MLX5_IB_OBJECT_DEVX_OBJ,
1110                             UVERBS_TYPE_ALLOC_IDR(devx_obj_cleanup),
1111                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_OBJ_CREATE),
1112                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_OBJ_DESTROY),
1113                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_OBJ_MODIFY),
1114                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_OBJ_QUERY));
1115
1116 DECLARE_UVERBS_NAMED_OBJECT(MLX5_IB_OBJECT_DEVX_UMEM,
1117                             UVERBS_TYPE_ALLOC_IDR(devx_umem_cleanup),
1118                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_UMEM_REG),
1119                             &UVERBS_METHOD(MLX5_IB_METHOD_DEVX_UMEM_DEREG));
1120
1121 DECLARE_UVERBS_OBJECT_TREE(devx_objects,
1122                            &UVERBS_OBJECT(MLX5_IB_OBJECT_DEVX),
1123                            &UVERBS_OBJECT(MLX5_IB_OBJECT_DEVX_OBJ),
1124                            &UVERBS_OBJECT(MLX5_IB_OBJECT_DEVX_UMEM));
1125
1126 const struct uverbs_object_tree_def *mlx5_ib_get_devx_tree(void)
1127 {
1128         return &devx_objects;
1129 }