1 /*-
2 * SPDX-License-Identifier: BSD-3-Clause
3 *
4 * Copyright (c) 1990 University of Utah.
5 * Copyright (c) 1991, 1993
6 * The Regents of the University of California. All rights reserved.
7 *
8 * This code is derived from software contributed to Berkeley by
9 * the Systems Programming Group of the University of Utah Computer
10 * Science Department.
11 *
12 * Redistribution and use in source and binary forms, with or without
13 * modification, are permitted provided that the following conditions
14 * are met:
15 * 1. Redistributions of source code must retain the above copyright
16 * notice, this list of conditions and the following disclaimer.
17 * 2. Redistributions in binary form must reproduce the above copyright
18 * notice, this list of conditions and the following disclaimer in the
19 * documentation and/or other materials provided with the distribution.
20 * 3. Neither the name of the University nor the names of its contributors
21 * may be used to endorse or promote products derived from this software
22 * without specific prior written permission.
23 *
24 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
25 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
26 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
27 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
28 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
29 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
30 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
31 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
32 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
33 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
34 * SUCH DAMAGE.
35 */
36
37 #include <sys/param.h>
38 #include <sys/systm.h>
39 #include <sys/conf.h>
40 #include <sys/lock.h>
41 #include <sys/proc.h>
42 #include <sys/mutex.h>
43 #include <sys/mman.h>
44 #include <sys/rwlock.h>
45 #include <sys/sx.h>
46 #include <sys/user.h>
47 #include <sys/vmmeter.h>
48
49 #include <vm/vm.h>
50 #include <vm/vm_param.h>
51 #include <vm/vm_object.h>
52 #include <vm/vm_page.h>
53 #include <vm/vm_pager.h>
54 #include <vm/vm_radix.h>
55 #include <vm/vm_phys.h>
56 #include <vm/vm_radix.h>
57 #include <vm/uma.h>
58
59 static void dev_pager_init(void);
60 static vm_object_t dev_pager_alloc(void *, vm_ooffset_t, vm_prot_t,
61 vm_ooffset_t, struct ucred *);
62 static void dev_pager_dealloc(vm_object_t);
63 static int dev_pager_getpages(vm_object_t, vm_page_t *, int, int *, int *);
64 static void dev_pager_putpages(vm_object_t, vm_page_t *, int, int, int *);
65 static boolean_t dev_pager_haspage(vm_object_t, vm_pindex_t, int *, int *);
66 static void dev_pager_free_page(vm_object_t object, vm_page_t m);
67 static int dev_pager_populate(vm_object_t object, vm_pindex_t pidx,
68 int fault_type, vm_prot_t, vm_pindex_t *first, vm_pindex_t *last);
69
70 /* list of device pager objects */
71 static struct pagerlst dev_pager_object_list;
72 /* protect list manipulation */
73 static struct mtx dev_pager_mtx;
74
75 const struct pagerops devicepagerops = {
76 .pgo_kvme_type = KVME_TYPE_DEVICE,
77 .pgo_init = dev_pager_init,
78 .pgo_alloc = dev_pager_alloc,
79 .pgo_dealloc = dev_pager_dealloc,
80 .pgo_getpages = dev_pager_getpages,
81 .pgo_putpages = dev_pager_putpages,
82 .pgo_haspage = dev_pager_haspage,
83 };
84
85 const struct pagerops mgtdevicepagerops = {
86 .pgo_kvme_type = KVME_TYPE_MGTDEVICE,
87 .pgo_alloc = dev_pager_alloc,
88 .pgo_dealloc = dev_pager_dealloc,
89 .pgo_getpages = dev_pager_getpages,
90 .pgo_putpages = dev_pager_putpages,
91 .pgo_haspage = dev_pager_haspage,
92 .pgo_populate = dev_pager_populate,
93 };
94
95 static int old_dev_pager_ctor(void *handle, vm_ooffset_t size, vm_prot_t prot,
96 vm_ooffset_t foff, struct ucred *cred, u_short *color);
97 static void old_dev_pager_dtor(void *handle);
98 static int old_dev_pager_fault(vm_object_t object, vm_ooffset_t offset,
99 int prot, vm_page_t *mres);
100
101 static const struct cdev_pager_ops old_dev_pager_ops = {
102 .cdev_pg_ctor = old_dev_pager_ctor,
103 .cdev_pg_dtor = old_dev_pager_dtor,
104 .cdev_pg_fault = old_dev_pager_fault
105 };
106
107 static void
dev_pager_init(void)108 dev_pager_init(void)
109 {
110
111 TAILQ_INIT(&dev_pager_object_list);
112 mtx_init(&dev_pager_mtx, "dev_pager list", NULL, MTX_DEF);
113 }
114
115 vm_object_t
cdev_pager_lookup(void * handle)116 cdev_pager_lookup(void *handle)
117 {
118 vm_object_t object;
119
120 again:
121 mtx_lock(&dev_pager_mtx);
122 object = vm_pager_object_lookup(&dev_pager_object_list, handle);
123 if (object != NULL && object->un_pager.devp.handle == NULL) {
124 msleep(&object->un_pager.devp.handle, &dev_pager_mtx,
125 PVM | PDROP, "cdplkp", 0);
126 vm_object_deallocate(object);
127 goto again;
128 }
129 mtx_unlock(&dev_pager_mtx);
130 return (object);
131 }
132
133 vm_object_t
cdev_pager_allocate(void * handle,enum obj_type tp,const struct cdev_pager_ops * ops,vm_ooffset_t size,vm_prot_t prot,vm_ooffset_t foff,struct ucred * cred)134 cdev_pager_allocate(void *handle, enum obj_type tp,
135 const struct cdev_pager_ops *ops, vm_ooffset_t size, vm_prot_t prot,
136 vm_ooffset_t foff, struct ucred *cred)
137 {
138 vm_object_t object;
139 vm_pindex_t pindex;
140
141 KASSERT(handle != NULL, ("device pager with NULL handle"));
142
143 if (tp != OBJT_DEVICE && tp != OBJT_MGTDEVICE)
144 return (NULL);
145 KASSERT(tp == OBJT_MGTDEVICE || ops->cdev_pg_populate == NULL,
146 ("populate on unmanaged device pager"));
147
148 /*
149 * Offset should be page aligned.
150 */
151 if (foff & PAGE_MASK)
152 return (NULL);
153
154 /*
155 * Treat the mmap(2) file offset as an unsigned value for a
156 * device mapping. This, in effect, allows a user to pass all
157 * possible off_t values as the mapping cookie to the driver. At
158 * this point, we know that both foff and size are a multiple
159 * of the page size. Do a check to avoid wrap.
160 */
161 size = round_page(size);
162 pindex = OFF_TO_IDX(foff) + OFF_TO_IDX(size);
163 if (pindex > OBJ_MAX_SIZE || pindex < OFF_TO_IDX(foff) ||
164 pindex < OFF_TO_IDX(size))
165 return (NULL);
166
167 again:
168 mtx_lock(&dev_pager_mtx);
169
170 /*
171 * Look up pager, creating as necessary.
172 */
173 object = vm_pager_object_lookup(&dev_pager_object_list, handle);
174 if (object == NULL) {
175 vm_object_t object1;
176
177 /*
178 * Allocate object and associate it with the pager. Initialize
179 * the object's pg_color based upon the physical address of the
180 * device's memory.
181 */
182 mtx_unlock(&dev_pager_mtx);
183 object1 = vm_object_allocate(tp, pindex);
184 mtx_lock(&dev_pager_mtx);
185 object = vm_pager_object_lookup(&dev_pager_object_list, handle);
186 if (object != NULL) {
187 object1->type = OBJT_DEAD;
188 vm_object_deallocate(object1);
189 object1 = NULL;
190 if (object->un_pager.devp.handle == NULL) {
191 msleep(&object->un_pager.devp.handle,
192 &dev_pager_mtx, PVM | PDROP, "cdplkp", 0);
193 vm_object_deallocate(object);
194 goto again;
195 }
196
197 /*
198 * We raced with other thread while allocating object.
199 */
200 if (pindex > object->size)
201 object->size = pindex;
202 KASSERT(object->type == tp,
203 ("Inconsistent device pager type %p %d",
204 object, tp));
205 KASSERT(object->un_pager.devp.ops == ops,
206 ("Inconsistent devops %p %p", object, ops));
207 } else {
208 u_short color;
209
210 object = object1;
211 object1 = NULL;
212 object->handle = handle;
213 object->un_pager.devp.ops = ops;
214 TAILQ_INIT(&object->un_pager.devp.devp_pglist);
215 TAILQ_INSERT_TAIL(&dev_pager_object_list, object,
216 pager_object_list);
217 mtx_unlock(&dev_pager_mtx);
218 if (ops->cdev_pg_populate != NULL)
219 vm_object_set_flag(object, OBJ_POPULATE);
220 if (ops->cdev_pg_ctor(handle, size, prot, foff,
221 cred, &color) != 0) {
222 mtx_lock(&dev_pager_mtx);
223 TAILQ_REMOVE(&dev_pager_object_list, object,
224 pager_object_list);
225 wakeup(&object->un_pager.devp.handle);
226 mtx_unlock(&dev_pager_mtx);
227 object->type = OBJT_DEAD;
228 vm_object_deallocate(object);
229 object = NULL;
230 mtx_lock(&dev_pager_mtx);
231 } else {
232 mtx_lock(&dev_pager_mtx);
233 object->flags |= OBJ_COLORED;
234 object->pg_color = color;
235 object->un_pager.devp.handle = handle;
236 wakeup(&object->un_pager.devp.handle);
237 }
238 }
239 MPASS(object1 == NULL);
240 } else {
241 if (object->un_pager.devp.handle == NULL) {
242 msleep(&object->un_pager.devp.handle,
243 &dev_pager_mtx, PVM | PDROP, "cdplkp", 0);
244 vm_object_deallocate(object);
245 goto again;
246 }
247 if (pindex > object->size)
248 object->size = pindex;
249 KASSERT(object->type == tp,
250 ("Inconsistent device pager type %p %d", object, tp));
251 }
252 mtx_unlock(&dev_pager_mtx);
253 return (object);
254 }
255
256 static vm_object_t
dev_pager_alloc(void * handle,vm_ooffset_t size,vm_prot_t prot,vm_ooffset_t foff,struct ucred * cred)257 dev_pager_alloc(void *handle, vm_ooffset_t size, vm_prot_t prot,
258 vm_ooffset_t foff, struct ucred *cred)
259 {
260
261 return (cdev_pager_allocate(handle, OBJT_DEVICE, &old_dev_pager_ops,
262 size, prot, foff, cred));
263 }
264
265 void
cdev_pager_free_page(vm_object_t object,vm_page_t m)266 cdev_pager_free_page(vm_object_t object, vm_page_t m)
267 {
268
269 if (object->type == OBJT_MGTDEVICE) {
270 struct pctrie_iter pages;
271
272 vm_page_iter_init(&pages, object);
273 vm_radix_iter_lookup(&pages, m->pindex);
274 cdev_mgtdev_pager_free_page(&pages, m);
275 } else if (object->type == OBJT_DEVICE)
276 dev_pager_free_page(object, m);
277 else
278 KASSERT(false,
279 ("Invalid device type obj %p m %p", object, m));
280 }
281
282 void
cdev_mgtdev_pager_free_page(struct pctrie_iter * pages,vm_page_t m)283 cdev_mgtdev_pager_free_page(struct pctrie_iter *pages, vm_page_t m)
284 {
285 pmap_remove_all(m);
286 vm_page_iter_remove(pages, m);
287 }
288
289 void
cdev_mgtdev_pager_free_pages(vm_object_t object)290 cdev_mgtdev_pager_free_pages(vm_object_t object)
291 {
292 struct pctrie_iter pages;
293 vm_page_t m;
294
295 vm_page_iter_init(&pages, object);
296 VM_OBJECT_WLOCK(object);
297 retry:
298 KASSERT(pctrie_iter_is_reset(&pages),
299 ("%s: pctrie_iter not reset for retry", __func__));
300 for (m = vm_radix_iter_lookup_ge(&pages, 0); m != NULL;
301 m = vm_radix_iter_step(&pages)) {
302 if (!vm_page_busy_acquire(m, VM_ALLOC_WAITFAIL)) {
303 pctrie_iter_reset(&pages);
304 goto retry;
305 }
306 cdev_mgtdev_pager_free_page(&pages, m);
307 }
308 VM_OBJECT_WUNLOCK(object);
309 }
310
311 static void
dev_pager_free_page(vm_object_t object,vm_page_t m)312 dev_pager_free_page(vm_object_t object, vm_page_t m)
313 {
314
315 VM_OBJECT_ASSERT_WLOCKED(object);
316 KASSERT((object->type == OBJT_DEVICE &&
317 (m->oflags & VPO_UNMANAGED) != 0),
318 ("Managed device or page obj %p m %p", object, m));
319 TAILQ_REMOVE(&object->un_pager.devp.devp_pglist, m, plinks.q);
320 vm_page_putfake(m);
321 }
322
323 static void
dev_pager_dealloc(vm_object_t object)324 dev_pager_dealloc(vm_object_t object)
325 {
326 vm_page_t m;
327
328 VM_OBJECT_WUNLOCK(object);
329 object->un_pager.devp.ops->cdev_pg_dtor(object->un_pager.devp.handle);
330
331 mtx_lock(&dev_pager_mtx);
332 TAILQ_REMOVE(&dev_pager_object_list, object, pager_object_list);
333 mtx_unlock(&dev_pager_mtx);
334 VM_OBJECT_WLOCK(object);
335
336 if (object->type == OBJT_DEVICE) {
337 /*
338 * Free up our fake pages.
339 */
340 while ((m = TAILQ_FIRST(&object->un_pager.devp.devp_pglist))
341 != NULL) {
342 if (vm_page_busy_acquire(m, VM_ALLOC_WAITFAIL) == 0)
343 continue;
344
345 dev_pager_free_page(object, m);
346 }
347 }
348 object->handle = NULL;
349 object->type = OBJT_DEAD;
350 }
351
352 static int
dev_pager_getpages(vm_object_t object,vm_page_t * ma,int count,int * rbehind,int * rahead)353 dev_pager_getpages(vm_object_t object, vm_page_t *ma, int count, int *rbehind,
354 int *rahead)
355 {
356 int error;
357
358 /* Since our haspage reports zero after/before, the count is 1. */
359 KASSERT(count == 1, ("%s: count %d", __func__, count));
360 if (object->un_pager.devp.ops->cdev_pg_fault == NULL)
361 return (VM_PAGER_FAIL);
362 VM_OBJECT_WLOCK(object);
363 error = object->un_pager.devp.ops->cdev_pg_fault(object,
364 IDX_TO_OFF(ma[0]->pindex), PROT_READ, &ma[0]);
365
366 VM_OBJECT_ASSERT_WLOCKED(object);
367
368 if (error == VM_PAGER_OK) {
369 KASSERT((object->type == OBJT_DEVICE &&
370 (ma[0]->oflags & VPO_UNMANAGED) != 0) ||
371 (object->type == OBJT_MGTDEVICE &&
372 (ma[0]->oflags & VPO_UNMANAGED) == 0),
373 ("Wrong page type %p %p", ma[0], object));
374 if (object->type == OBJT_DEVICE) {
375 TAILQ_INSERT_TAIL(&object->un_pager.devp.devp_pglist,
376 ma[0], plinks.q);
377 }
378 if (rbehind)
379 *rbehind = 0;
380 if (rahead)
381 *rahead = 0;
382 }
383 VM_OBJECT_WUNLOCK(object);
384
385 return (error);
386 }
387
388 static int
dev_pager_populate(vm_object_t object,vm_pindex_t pidx,int fault_type,vm_prot_t max_prot,vm_pindex_t * first,vm_pindex_t * last)389 dev_pager_populate(vm_object_t object, vm_pindex_t pidx, int fault_type,
390 vm_prot_t max_prot, vm_pindex_t *first, vm_pindex_t *last)
391 {
392
393 VM_OBJECT_ASSERT_WLOCKED(object);
394 if (object->un_pager.devp.ops->cdev_pg_populate == NULL)
395 return (VM_PAGER_FAIL);
396 return (object->un_pager.devp.ops->cdev_pg_populate(object, pidx,
397 fault_type, max_prot, first, last));
398 }
399
400 static int
old_dev_pager_fault(vm_object_t object,vm_ooffset_t offset,int prot,vm_page_t * mres)401 old_dev_pager_fault(vm_object_t object, vm_ooffset_t offset, int prot,
402 vm_page_t *mres)
403 {
404 vm_paddr_t paddr;
405 vm_page_t m_paddr, page;
406 struct cdev *dev;
407 struct cdevsw *csw;
408 struct file *fpop;
409 struct thread *td;
410 vm_memattr_t memattr, memattr1;
411 int ref, ret;
412
413 memattr = object->memattr;
414
415 VM_OBJECT_WUNLOCK(object);
416
417 dev = object->handle;
418 csw = dev_refthread(dev, &ref);
419 if (csw == NULL) {
420 VM_OBJECT_WLOCK(object);
421 return (VM_PAGER_FAIL);
422 }
423 td = curthread;
424 fpop = td->td_fpop;
425 td->td_fpop = NULL;
426 ret = csw->d_mmap(dev, offset, &paddr, prot, &memattr);
427 td->td_fpop = fpop;
428 dev_relthread(dev, ref);
429 if (ret != 0) {
430 printf(
431 "WARNING: dev_pager_getpage: map function returns error %d", ret);
432 VM_OBJECT_WLOCK(object);
433 return (VM_PAGER_FAIL);
434 }
435
436 /* If "paddr" is a real page, perform a sanity check on "memattr". */
437 if ((m_paddr = vm_phys_paddr_to_vm_page(paddr)) != NULL &&
438 (memattr1 = pmap_page_get_memattr(m_paddr)) != memattr) {
439 /*
440 * For the /dev/mem d_mmap routine to return the
441 * correct memattr, pmap_page_get_memattr() needs to
442 * be called, which we do there.
443 */
444 if ((csw->d_flags & D_MEM) == 0) {
445 printf("WARNING: Device driver %s has set "
446 "\"memattr\" inconsistently (drv %u pmap %u).\n",
447 csw->d_name, memattr, memattr1);
448 }
449 memattr = memattr1;
450 }
451 if (((*mres)->flags & PG_FICTITIOUS) != 0) {
452 /*
453 * If the passed in result page is a fake page, update it with
454 * the new physical address.
455 */
456 page = *mres;
457 VM_OBJECT_WLOCK(object);
458 vm_page_updatefake(page, paddr, memattr);
459 } else {
460 /*
461 * Replace the passed in reqpage page with our own fake page and
462 * free up the all of the original pages.
463 */
464 page = vm_page_getfake(paddr, memattr);
465 VM_OBJECT_WLOCK(object);
466 vm_page_replace(page, object, (*mres)->pindex, *mres);
467 *mres = page;
468 }
469 vm_page_valid(page);
470 return (VM_PAGER_OK);
471 }
472
473 static void
dev_pager_putpages(vm_object_t object,vm_page_t * m,int count,int flags,int * rtvals)474 dev_pager_putpages(vm_object_t object, vm_page_t *m, int count, int flags,
475 int *rtvals)
476 {
477
478 panic("dev_pager_putpage called");
479 }
480
481 static boolean_t
dev_pager_haspage(vm_object_t object,vm_pindex_t pindex,int * before,int * after)482 dev_pager_haspage(vm_object_t object, vm_pindex_t pindex, int *before,
483 int *after)
484 {
485
486 if (before != NULL)
487 *before = 0;
488 if (after != NULL)
489 *after = 0;
490 return (TRUE);
491 }
492
493 static int
old_dev_pager_ctor(void * handle,vm_ooffset_t size,vm_prot_t prot,vm_ooffset_t foff,struct ucred * cred,u_short * color)494 old_dev_pager_ctor(void *handle, vm_ooffset_t size, vm_prot_t prot,
495 vm_ooffset_t foff, struct ucred *cred, u_short *color)
496 {
497 struct cdev *dev;
498 struct cdevsw *csw;
499 vm_memattr_t dummy;
500 vm_ooffset_t off;
501 vm_paddr_t paddr;
502 unsigned int npages;
503 int ref;
504
505 /*
506 * Make sure this device can be mapped.
507 */
508 dev = handle;
509 csw = dev_refthread(dev, &ref);
510 if (csw == NULL)
511 return (ENXIO);
512
513 /*
514 * Check that the specified range of the device allows the desired
515 * protection.
516 *
517 * XXX assumes VM_PROT_* == PROT_*
518 */
519 npages = OFF_TO_IDX(size);
520 paddr = 0; /* Make paddr initialized for the case of size == 0. */
521 for (off = foff; npages--; off += PAGE_SIZE) {
522 if (csw->d_mmap(dev, off, &paddr, (int)prot, &dummy) != 0) {
523 dev_relthread(dev, ref);
524 return (EINVAL);
525 }
526 }
527
528 dev_ref(dev);
529 dev_relthread(dev, ref);
530 *color = atop(paddr) - OFF_TO_IDX(off - PAGE_SIZE);
531 return (0);
532 }
533
534 static void
old_dev_pager_dtor(void * handle)535 old_dev_pager_dtor(void *handle)
536 {
537
538 dev_rel(handle);
539 }
540