1.\" Copyright (c) 2001 John H. Baldwin <jhb@FreeBSD.org> 2.\" All rights reserved. 3.\" 4.\" Redistribution and use in source and binary forms, with or without 5.\" modification, are permitted provided that the following conditions 6.\" are met: 7.\" 1. Redistributions of source code must retain the above copyright 8.\" notice, this list of conditions and the following disclaimer. 9.\" 2. Redistributions in binary form must reproduce the above copyright 10.\" notice, this list of conditions and the following disclaimer in the 11.\" documentation and/or other materials provided with the distribution. 12.\" 13.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 14.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 15.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 16.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 17.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 18.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 19.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 20.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 21.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 22.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 23.\" SUCH DAMAGE. 24.\" 25.\" $FreeBSD$ 26.\" 27.Dd March 24, 2015 28.Dt WITNESS 4 29.Os 30.Sh NAME 31.Nm witness 32.Nd lock validation facility 33.Sh SYNOPSIS 34.Cd options WITNESS 35.Cd options WITNESS_COUNT 36.Cd options WITNESS_KDB 37.Cd options WITNESS_NO_VNODE 38.Cd options WITNESS_SKIPSPIN 39.Sh DESCRIPTION 40The 41.Nm 42module keeps track of the locks acquired and released by each thread. 43It also keeps track of the order in which locks are acquired with respect 44to each other. 45Each time a lock is acquired, 46.Nm 47uses these two lists to verify that a lock is not being acquired in the 48wrong order. 49If a lock order violation is detected, then a message is output to the 50kernel console detailing the locks involved and the locations in question. 51Witness can also be configured to drop into the kernel debugger when an order 52violation occurs. 53.Pp 54The 55.Nm 56code also checks various other conditions such as verifying that one 57does not recurse on a non-recursive lock, 58or attempt an upgrade on a shared lock held by another thread. 59If any of these checks fail, then the kernel will panic. 60.Pp 61The 62.Dv WITNESS_COUNT 63kernel option controls the maximum number of 64.Xr witness 4 65entries that are tracked in the kernel. 66The maximum number of entries can be queried via the 67.Va debug.witness.count 68sysctl. 69It can also be set from the 70.Xr loader 8 71via the 72.Va debug.witness.count 73environment variable. 74.Pp 75The 76.Dv WITNESS_NO_VNODE 77kernel option tells 78.Xr witness 4 79to ignore locking issues between 80.Xr vnode 9 81objects. 82.Pp 83The flag that controls whether or not the kernel debugger is entered when a 84lock order violation is detected can be set in a variety of ways. 85By default, the flag is off, but if the 86.Dv WITNESS_KDB 87kernel option is 88specified, then the flag will default to on. 89It can also be set from the 90.Xr loader 8 91via the 92.Va debug.witness.kdb 93environment variable or after the kernel has booted via the 94.Va debug.witness.kdb 95sysctl. 96If the flag is set to zero, then the debugger will not be entered. 97If the flag is non-zero, then the debugger will be entered. 98.Pp 99The 100.Nm 101code can also be configured to skip all checks on spin mutexes. 102By default, this flag defaults to off, but it can be turned on by 103specifying the 104.Dv WITNESS_SKIPSPIN 105kernel option. 106The flag can also be set via the 107.Xr loader 8 108environment variable 109.Va debug.witness.skipspin . 110If the variable is set to a non-zero value, then spin mutexes are skipped. 111Once the kernel has booted, the status of this flag can be examined but not 112set via the read-only sysctl 113.Va debug.witness.skipspin . 114.Pp 115The sysctl 116.Va debug.witness.watch 117specifies the level of witness involvement in the system. 118A value of 1 specifies that witness is enabled. 119A value of 0 specifies that witness is disabled, but that can be enabled 120again. This will maintain a small amount of overhead in the system. 121A value of -1 specifies that witness is disabled permanently and 122cannot be enabled again. 123The sysctl 124.Va debug.witness.watch 125can be set via 126.Xr loader 8 . 127.Pp 128The 129.Nm 130code also provides three extra 131.Xr ddb 4 132commands if both 133.Nm 134and 135.Xr ddb 4 136are compiled into the kernel: 137.Bl -ohang 138.It Ic show locks Op thread 139Outputs the list of locks held by a thread to the kernel console 140along with the filename and line number at which each lock was last acquired 141by the thread. 142The optional 143.Ar thread 144argument may be either a TID, 145PID, 146or pointer to a thread structure. 147If 148.Ar thread 149is not specified, 150then the locks held by the current thread are displayed. 151.It Ic show all locks 152Outputs the list of locks held by all threads in the system to the 153kernel console. 154.It Ic show witness 155Dump the current order list to the kernel console. 156The code first displays the lock order tree for all of the sleep locks. 157Then it displays the lock order tree for all of the spin locks. 158Finally, it displays a list of locks that have not yet been acquired. 159.El 160.Sh SEE ALSO 161.Xr ddb 4 , 162.Xr loader 8 , 163.Xr sysctl 8 , 164.Xr mutex 9 165.Sh HISTORY 166The 167.Nm 168code first appeared in 169.Bsx 5.0 170and was imported from there into 171.Fx 5.0 . 172