xref: /freebsd/sys/dev/md/md.c (revision 4c1a82cea504df7a79f5bd8f7d0a41cacccff16e)
1 /*-
2  * SPDX-License-Identifier: (Beerware AND BSD-3-Clause)
3  *
4  * ----------------------------------------------------------------------------
5  * "THE BEER-WARE LICENSE" (Revision 42):
6  * <phk@FreeBSD.ORG> wrote this file.  As long as you retain this notice you
7  * can do whatever you want with this stuff. If we meet some day, and you think
8  * this stuff is worth it, you can buy me a beer in return.   Poul-Henning Kamp
9  * ----------------------------------------------------------------------------
10  *
11  * $FreeBSD$
12  *
13  */
14 
15 /*-
16  * The following functions are based in the vn(4) driver: mdstart_swap(),
17  * mdstart_vnode(), mdcreate_swap(), mdcreate_vnode() and mddestroy(),
18  * and as such under the following copyright:
19  *
20  * Copyright (c) 1988 University of Utah.
21  * Copyright (c) 1990, 1993
22  *	The Regents of the University of California.  All rights reserved.
23  * Copyright (c) 2013 The FreeBSD Foundation
24  * All rights reserved.
25  *
26  * This code is derived from software contributed to Berkeley by
27  * the Systems Programming Group of the University of Utah Computer
28  * Science Department.
29  *
30  * Portions of this software were developed by Konstantin Belousov
31  * under sponsorship from the FreeBSD Foundation.
32  *
33  * Redistribution and use in source and binary forms, with or without
34  * modification, are permitted provided that the following conditions
35  * are met:
36  * 1. Redistributions of source code must retain the above copyright
37  *    notice, this list of conditions and the following disclaimer.
38  * 2. Redistributions in binary form must reproduce the above copyright
39  *    notice, this list of conditions and the following disclaimer in the
40  *    documentation and/or other materials provided with the distribution.
41  * 3. Neither the name of the University nor the names of its contributors
42  *    may be used to endorse or promote products derived from this software
43  *    without specific prior written permission.
44  *
45  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
46  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
47  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
48  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
49  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
50  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
51  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
52  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
53  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
54  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
55  * SUCH DAMAGE.
56  *
57  * from: Utah Hdr: vn.c 1.13 94/04/02
58  *
59  *	from: @(#)vn.c	8.6 (Berkeley) 4/1/94
60  * From: src/sys/dev/vn/vn.c,v 1.122 2000/12/16 16:06:03
61  */
62 
63 #include "opt_rootdevname.h"
64 #include "opt_geom.h"
65 #include "opt_md.h"
66 
67 #include <sys/param.h>
68 #include <sys/systm.h>
69 #include <sys/bio.h>
70 #include <sys/buf.h>
71 #include <sys/conf.h>
72 #include <sys/devicestat.h>
73 #include <sys/fcntl.h>
74 #include <sys/kernel.h>
75 #include <sys/kthread.h>
76 #include <sys/limits.h>
77 #include <sys/linker.h>
78 #include <sys/lock.h>
79 #include <sys/malloc.h>
80 #include <sys/mdioctl.h>
81 #include <sys/mount.h>
82 #include <sys/mutex.h>
83 #include <sys/sx.h>
84 #include <sys/namei.h>
85 #include <sys/proc.h>
86 #include <sys/queue.h>
87 #include <sys/rwlock.h>
88 #include <sys/sbuf.h>
89 #include <sys/sched.h>
90 #include <sys/sf_buf.h>
91 #include <sys/sysctl.h>
92 #include <sys/uio.h>
93 #include <sys/vnode.h>
94 #include <sys/disk.h>
95 
96 #include <geom/geom.h>
97 #include <geom/geom_int.h>
98 
99 #include <vm/vm.h>
100 #include <vm/vm_param.h>
101 #include <vm/vm_object.h>
102 #include <vm/vm_page.h>
103 #include <vm/vm_pager.h>
104 #include <vm/swap_pager.h>
105 #include <vm/uma.h>
106 
107 #include <machine/bus.h>
108 
109 #define MD_MODVER 1
110 
111 #define MD_SHUTDOWN	0x10000		/* Tell worker thread to terminate. */
112 #define	MD_EXITING	0x20000		/* Worker thread is exiting. */
113 #define MD_PROVIDERGONE	0x40000		/* Safe to free the softc */
114 
115 #ifndef MD_NSECT
116 #define MD_NSECT (10000 * 2)
117 #endif
118 
119 struct md_req {
120 	unsigned	md_unit;	/* unit number */
121 	enum md_types	md_type;	/* type of disk */
122 	off_t		md_mediasize;	/* size of disk in bytes */
123 	unsigned	md_sectorsize;	/* sectorsize */
124 	unsigned	md_options;	/* options */
125 	int		md_fwheads;	/* firmware heads */
126 	int		md_fwsectors;	/* firmware sectors */
127 	char		*md_file;	/* pathname of file to mount */
128 	enum uio_seg	md_file_seg;	/* location of md_file */
129 	char		*md_label;	/* label of the device (userspace) */
130 	int		*md_units;	/* pointer to units array (kernel) */
131 	size_t		md_units_nitems; /* items in md_units array */
132 };
133 
134 #ifdef COMPAT_FREEBSD32
135 struct md_ioctl32 {
136 	unsigned	md_version;
137 	unsigned	md_unit;
138 	enum md_types	md_type;
139 	uint32_t	md_file;
140 	off_t		md_mediasize;
141 	unsigned	md_sectorsize;
142 	unsigned	md_options;
143 	uint64_t	md_base;
144 	int		md_fwheads;
145 	int		md_fwsectors;
146 	uint32_t	md_label;
147 	int		md_pad[MDNPAD];
148 } __attribute__((__packed__));
149 CTASSERT((sizeof(struct md_ioctl32)) == 436);
150 
151 #define	MDIOCATTACH_32	_IOC_NEWTYPE(MDIOCATTACH, struct md_ioctl32)
152 #define	MDIOCDETACH_32	_IOC_NEWTYPE(MDIOCDETACH, struct md_ioctl32)
153 #define	MDIOCQUERY_32	_IOC_NEWTYPE(MDIOCQUERY, struct md_ioctl32)
154 #define	MDIOCRESIZE_32	_IOC_NEWTYPE(MDIOCRESIZE, struct md_ioctl32)
155 #endif /* COMPAT_FREEBSD32 */
156 
157 static MALLOC_DEFINE(M_MD, "md_disk", "Memory Disk");
158 static MALLOC_DEFINE(M_MDSECT, "md_sectors", "Memory Disk Sectors");
159 
160 static int md_debug;
161 SYSCTL_INT(_debug, OID_AUTO, mddebug, CTLFLAG_RW, &md_debug, 0,
162     "Enable md(4) debug messages");
163 static int md_malloc_wait;
164 SYSCTL_INT(_vm, OID_AUTO, md_malloc_wait, CTLFLAG_RW, &md_malloc_wait, 0,
165     "Allow malloc to wait for memory allocations");
166 
167 #if defined(MD_ROOT) && !defined(MD_ROOT_FSTYPE)
168 #define	MD_ROOT_FSTYPE	"ufs"
169 #endif
170 
171 #if defined(MD_ROOT)
172 /*
173  * Preloaded image gets put here.
174  */
175 #if defined(MD_ROOT_SIZE)
176 /*
177  * We put the mfs_root symbol into the oldmfs section of the kernel object file.
178  * Applications that patch the object with the image can determine
179  * the size looking at the oldmfs section size within the kernel.
180  */
181 u_char mfs_root[MD_ROOT_SIZE*1024] __attribute__ ((section ("oldmfs")));
182 const int mfs_root_size = sizeof(mfs_root);
183 #elif defined(MD_ROOT_MEM)
184 /* MD region already mapped in the memory */
185 u_char *mfs_root;
186 int mfs_root_size;
187 #else
188 extern volatile u_char __weak_symbol mfs_root;
189 extern volatile u_char __weak_symbol mfs_root_end;
190 __GLOBL(mfs_root);
191 __GLOBL(mfs_root_end);
192 #define mfs_root_size ((uintptr_t)(&mfs_root_end - &mfs_root))
193 #endif
194 #endif
195 
196 static g_init_t g_md_init;
197 static g_fini_t g_md_fini;
198 static g_start_t g_md_start;
199 static g_access_t g_md_access;
200 static void g_md_dumpconf(struct sbuf *sb, const char *indent,
201     struct g_geom *gp, struct g_consumer *cp __unused, struct g_provider *pp);
202 static g_provgone_t g_md_providergone;
203 
204 static struct cdev *status_dev = NULL;
205 static struct sx md_sx;
206 static struct unrhdr *md_uh;
207 
208 static d_ioctl_t mdctlioctl;
209 
210 static struct cdevsw mdctl_cdevsw = {
211 	.d_version =	D_VERSION,
212 	.d_ioctl =	mdctlioctl,
213 	.d_name =	MD_NAME,
214 };
215 
216 struct g_class g_md_class = {
217 	.name = "MD",
218 	.version = G_VERSION,
219 	.init = g_md_init,
220 	.fini = g_md_fini,
221 	.start = g_md_start,
222 	.access = g_md_access,
223 	.dumpconf = g_md_dumpconf,
224 	.providergone = g_md_providergone,
225 };
226 
227 DECLARE_GEOM_CLASS(g_md_class, g_md);
228 
229 
230 static LIST_HEAD(, md_s) md_softc_list = LIST_HEAD_INITIALIZER(md_softc_list);
231 
232 #define NINDIR	(PAGE_SIZE / sizeof(uintptr_t))
233 #define NMASK	(NINDIR-1)
234 static int nshift;
235 
236 static uma_zone_t md_pbuf_zone;
237 
238 struct indir {
239 	uintptr_t	*array;
240 	u_int		total;
241 	u_int		used;
242 	u_int		shift;
243 };
244 
245 struct md_s {
246 	int unit;
247 	LIST_ENTRY(md_s) list;
248 	struct bio_queue_head bio_queue;
249 	struct mtx queue_mtx;
250 	struct mtx stat_mtx;
251 	struct cdev *dev;
252 	enum md_types type;
253 	off_t mediasize;
254 	unsigned sectorsize;
255 	unsigned opencount;
256 	unsigned fwheads;
257 	unsigned fwsectors;
258 	char ident[32];
259 	unsigned flags;
260 	char name[20];
261 	struct proc *procp;
262 	struct g_geom *gp;
263 	struct g_provider *pp;
264 	int (*start)(struct md_s *sc, struct bio *bp);
265 	struct devstat *devstat;
266 
267 	/* MD_MALLOC related fields */
268 	struct indir *indir;
269 	uma_zone_t uma;
270 
271 	/* MD_PRELOAD related fields */
272 	u_char *pl_ptr;
273 	size_t pl_len;
274 
275 	/* MD_VNODE related fields */
276 	struct vnode *vnode;
277 	char file[PATH_MAX];
278 	char label[PATH_MAX];
279 	struct ucred *cred;
280 
281 	/* MD_SWAP related fields */
282 	vm_object_t object;
283 };
284 
285 static struct indir *
286 new_indir(u_int shift)
287 {
288 	struct indir *ip;
289 
290 	ip = malloc(sizeof *ip, M_MD, (md_malloc_wait ? M_WAITOK : M_NOWAIT)
291 	    | M_ZERO);
292 	if (ip == NULL)
293 		return (NULL);
294 	ip->array = malloc(sizeof(uintptr_t) * NINDIR,
295 	    M_MDSECT, (md_malloc_wait ? M_WAITOK : M_NOWAIT) | M_ZERO);
296 	if (ip->array == NULL) {
297 		free(ip, M_MD);
298 		return (NULL);
299 	}
300 	ip->total = NINDIR;
301 	ip->shift = shift;
302 	return (ip);
303 }
304 
305 static void
306 del_indir(struct indir *ip)
307 {
308 
309 	free(ip->array, M_MDSECT);
310 	free(ip, M_MD);
311 }
312 
313 static void
314 destroy_indir(struct md_s *sc, struct indir *ip)
315 {
316 	int i;
317 
318 	for (i = 0; i < NINDIR; i++) {
319 		if (!ip->array[i])
320 			continue;
321 		if (ip->shift)
322 			destroy_indir(sc, (struct indir*)(ip->array[i]));
323 		else if (ip->array[i] > 255)
324 			uma_zfree(sc->uma, (void *)(ip->array[i]));
325 	}
326 	del_indir(ip);
327 }
328 
329 /*
330  * This function does the math and allocates the top level "indir" structure
331  * for a device of "size" sectors.
332  */
333 
334 static struct indir *
335 dimension(off_t size)
336 {
337 	off_t rcnt;
338 	struct indir *ip;
339 	int layer;
340 
341 	rcnt = size;
342 	layer = 0;
343 	while (rcnt > NINDIR) {
344 		rcnt /= NINDIR;
345 		layer++;
346 	}
347 
348 	/*
349 	 * XXX: the top layer is probably not fully populated, so we allocate
350 	 * too much space for ip->array in here.
351 	 */
352 	ip = malloc(sizeof *ip, M_MD, M_WAITOK | M_ZERO);
353 	ip->array = malloc(sizeof(uintptr_t) * NINDIR,
354 	    M_MDSECT, M_WAITOK | M_ZERO);
355 	ip->total = NINDIR;
356 	ip->shift = layer * nshift;
357 	return (ip);
358 }
359 
360 /*
361  * Read a given sector
362  */
363 
364 static uintptr_t
365 s_read(struct indir *ip, off_t offset)
366 {
367 	struct indir *cip;
368 	int idx;
369 	uintptr_t up;
370 
371 	if (md_debug > 1)
372 		printf("s_read(%jd)\n", (intmax_t)offset);
373 	up = 0;
374 	for (cip = ip; cip != NULL;) {
375 		if (cip->shift) {
376 			idx = (offset >> cip->shift) & NMASK;
377 			up = cip->array[idx];
378 			cip = (struct indir *)up;
379 			continue;
380 		}
381 		idx = offset & NMASK;
382 		return (cip->array[idx]);
383 	}
384 	return (0);
385 }
386 
387 /*
388  * Write a given sector, prune the tree if the value is 0
389  */
390 
391 static int
392 s_write(struct indir *ip, off_t offset, uintptr_t ptr)
393 {
394 	struct indir *cip, *lip[10];
395 	int idx, li;
396 	uintptr_t up;
397 
398 	if (md_debug > 1)
399 		printf("s_write(%jd, %p)\n", (intmax_t)offset, (void *)ptr);
400 	up = 0;
401 	li = 0;
402 	cip = ip;
403 	for (;;) {
404 		lip[li++] = cip;
405 		if (cip->shift) {
406 			idx = (offset >> cip->shift) & NMASK;
407 			up = cip->array[idx];
408 			if (up != 0) {
409 				cip = (struct indir *)up;
410 				continue;
411 			}
412 			/* Allocate branch */
413 			cip->array[idx] =
414 			    (uintptr_t)new_indir(cip->shift - nshift);
415 			if (cip->array[idx] == 0)
416 				return (ENOSPC);
417 			cip->used++;
418 			up = cip->array[idx];
419 			cip = (struct indir *)up;
420 			continue;
421 		}
422 		/* leafnode */
423 		idx = offset & NMASK;
424 		up = cip->array[idx];
425 		if (up != 0)
426 			cip->used--;
427 		cip->array[idx] = ptr;
428 		if (ptr != 0)
429 			cip->used++;
430 		break;
431 	}
432 	if (cip->used != 0 || li == 1)
433 		return (0);
434 	li--;
435 	while (cip->used == 0 && cip != ip) {
436 		li--;
437 		idx = (offset >> lip[li]->shift) & NMASK;
438 		up = lip[li]->array[idx];
439 		KASSERT(up == (uintptr_t)cip, ("md screwed up"));
440 		del_indir(cip);
441 		lip[li]->array[idx] = 0;
442 		lip[li]->used--;
443 		cip = lip[li];
444 	}
445 	return (0);
446 }
447 
448 
449 static int
450 g_md_access(struct g_provider *pp, int r, int w, int e)
451 {
452 	struct md_s *sc;
453 
454 	sc = pp->geom->softc;
455 	if (sc == NULL) {
456 		if (r <= 0 && w <= 0 && e <= 0)
457 			return (0);
458 		return (ENXIO);
459 	}
460 	r += pp->acr;
461 	w += pp->acw;
462 	e += pp->ace;
463 	if ((sc->flags & MD_READONLY) != 0 && w > 0)
464 		return (EROFS);
465 	if ((pp->acr + pp->acw + pp->ace) == 0 && (r + w + e) > 0) {
466 		sc->opencount = 1;
467 	} else if ((pp->acr + pp->acw + pp->ace) > 0 && (r + w + e) == 0) {
468 		sc->opencount = 0;
469 	}
470 	return (0);
471 }
472 
473 static void
474 g_md_start(struct bio *bp)
475 {
476 	struct md_s *sc;
477 
478 	sc = bp->bio_to->geom->softc;
479 	if ((bp->bio_cmd == BIO_READ) || (bp->bio_cmd == BIO_WRITE)) {
480 		mtx_lock(&sc->stat_mtx);
481 		devstat_start_transaction_bio(sc->devstat, bp);
482 		mtx_unlock(&sc->stat_mtx);
483 	}
484 	mtx_lock(&sc->queue_mtx);
485 	bioq_disksort(&sc->bio_queue, bp);
486 	wakeup(sc);
487 	mtx_unlock(&sc->queue_mtx);
488 }
489 
490 #define	MD_MALLOC_MOVE_ZERO	1
491 #define	MD_MALLOC_MOVE_FILL	2
492 #define	MD_MALLOC_MOVE_READ	3
493 #define	MD_MALLOC_MOVE_WRITE	4
494 #define	MD_MALLOC_MOVE_CMP	5
495 
496 static int
497 md_malloc_move_ma(vm_page_t **mp, int *ma_offs, unsigned sectorsize,
498     void *ptr, u_char fill, int op)
499 {
500 	struct sf_buf *sf;
501 	vm_page_t m, *mp1;
502 	char *p, first;
503 	off_t *uc;
504 	unsigned n;
505 	int error, i, ma_offs1, sz, first_read;
506 
507 	m = NULL;
508 	error = 0;
509 	sf = NULL;
510 	/* if (op == MD_MALLOC_MOVE_CMP) { gcc */
511 		first = 0;
512 		first_read = 0;
513 		uc = ptr;
514 		mp1 = *mp;
515 		ma_offs1 = *ma_offs;
516 	/* } */
517 	sched_pin();
518 	for (n = sectorsize; n != 0; n -= sz) {
519 		sz = imin(PAGE_SIZE - *ma_offs, n);
520 		if (m != **mp) {
521 			if (sf != NULL)
522 				sf_buf_free(sf);
523 			m = **mp;
524 			sf = sf_buf_alloc(m, SFB_CPUPRIVATE |
525 			    (md_malloc_wait ? 0 : SFB_NOWAIT));
526 			if (sf == NULL) {
527 				error = ENOMEM;
528 				break;
529 			}
530 		}
531 		p = (char *)sf_buf_kva(sf) + *ma_offs;
532 		switch (op) {
533 		case MD_MALLOC_MOVE_ZERO:
534 			bzero(p, sz);
535 			break;
536 		case MD_MALLOC_MOVE_FILL:
537 			memset(p, fill, sz);
538 			break;
539 		case MD_MALLOC_MOVE_READ:
540 			bcopy(ptr, p, sz);
541 			cpu_flush_dcache(p, sz);
542 			break;
543 		case MD_MALLOC_MOVE_WRITE:
544 			bcopy(p, ptr, sz);
545 			break;
546 		case MD_MALLOC_MOVE_CMP:
547 			for (i = 0; i < sz; i++, p++) {
548 				if (!first_read) {
549 					*uc = (u_char)*p;
550 					first = *p;
551 					first_read = 1;
552 				} else if (*p != first) {
553 					error = EDOOFUS;
554 					break;
555 				}
556 			}
557 			break;
558 		default:
559 			KASSERT(0, ("md_malloc_move_ma unknown op %d\n", op));
560 			break;
561 		}
562 		if (error != 0)
563 			break;
564 		*ma_offs += sz;
565 		*ma_offs %= PAGE_SIZE;
566 		if (*ma_offs == 0)
567 			(*mp)++;
568 		ptr = (char *)ptr + sz;
569 	}
570 
571 	if (sf != NULL)
572 		sf_buf_free(sf);
573 	sched_unpin();
574 	if (op == MD_MALLOC_MOVE_CMP && error != 0) {
575 		*mp = mp1;
576 		*ma_offs = ma_offs1;
577 	}
578 	return (error);
579 }
580 
581 static int
582 md_malloc_move_vlist(bus_dma_segment_t **pvlist, int *pma_offs,
583     unsigned len, void *ptr, u_char fill, int op)
584 {
585 	bus_dma_segment_t *vlist;
586 	uint8_t *p, *end, first;
587 	off_t *uc;
588 	int ma_offs, seg_len;
589 
590 	vlist = *pvlist;
591 	ma_offs = *pma_offs;
592 	uc = ptr;
593 
594 	for (; len != 0; len -= seg_len) {
595 		seg_len = imin(vlist->ds_len - ma_offs, len);
596 		p = (uint8_t *)(uintptr_t)vlist->ds_addr + ma_offs;
597 		switch (op) {
598 		case MD_MALLOC_MOVE_ZERO:
599 			bzero(p, seg_len);
600 			break;
601 		case MD_MALLOC_MOVE_FILL:
602 			memset(p, fill, seg_len);
603 			break;
604 		case MD_MALLOC_MOVE_READ:
605 			bcopy(ptr, p, seg_len);
606 			cpu_flush_dcache(p, seg_len);
607 			break;
608 		case MD_MALLOC_MOVE_WRITE:
609 			bcopy(p, ptr, seg_len);
610 			break;
611 		case MD_MALLOC_MOVE_CMP:
612 			end = p + seg_len;
613 			first = *uc = *p;
614 			/* Confirm all following bytes match the first */
615 			while (++p < end) {
616 				if (*p != first)
617 					return (EDOOFUS);
618 			}
619 			break;
620 		default:
621 			KASSERT(0, ("md_malloc_move_vlist unknown op %d\n", op));
622 			break;
623 		}
624 
625 		ma_offs += seg_len;
626 		if (ma_offs == vlist->ds_len) {
627 			ma_offs = 0;
628 			vlist++;
629 		}
630 		ptr = (uint8_t *)ptr + seg_len;
631 	}
632 	*pvlist = vlist;
633 	*pma_offs = ma_offs;
634 
635 	return (0);
636 }
637 
638 static int
639 mdstart_malloc(struct md_s *sc, struct bio *bp)
640 {
641 	u_char *dst;
642 	vm_page_t *m;
643 	bus_dma_segment_t *vlist;
644 	int i, error, error1, ma_offs, notmapped;
645 	off_t secno, nsec, uc;
646 	uintptr_t sp, osp;
647 
648 	switch (bp->bio_cmd) {
649 	case BIO_READ:
650 	case BIO_WRITE:
651 	case BIO_DELETE:
652 		break;
653 	default:
654 		return (EOPNOTSUPP);
655 	}
656 
657 	notmapped = (bp->bio_flags & BIO_UNMAPPED) != 0;
658 	vlist = (bp->bio_flags & BIO_VLIST) != 0 ?
659 	    (bus_dma_segment_t *)bp->bio_data : NULL;
660 	if (notmapped) {
661 		m = bp->bio_ma;
662 		ma_offs = bp->bio_ma_offset;
663 		dst = NULL;
664 		KASSERT(vlist == NULL, ("vlists cannot be unmapped"));
665 	} else if (vlist != NULL) {
666 		ma_offs = bp->bio_ma_offset;
667 		dst = NULL;
668 	} else {
669 		dst = bp->bio_data;
670 	}
671 
672 	nsec = bp->bio_length / sc->sectorsize;
673 	secno = bp->bio_offset / sc->sectorsize;
674 	error = 0;
675 	while (nsec--) {
676 		osp = s_read(sc->indir, secno);
677 		if (bp->bio_cmd == BIO_DELETE) {
678 			if (osp != 0)
679 				error = s_write(sc->indir, secno, 0);
680 		} else if (bp->bio_cmd == BIO_READ) {
681 			if (osp == 0) {
682 				if (notmapped) {
683 					error = md_malloc_move_ma(&m, &ma_offs,
684 					    sc->sectorsize, NULL, 0,
685 					    MD_MALLOC_MOVE_ZERO);
686 				} else if (vlist != NULL) {
687 					error = md_malloc_move_vlist(&vlist,
688 					    &ma_offs, sc->sectorsize, NULL, 0,
689 					    MD_MALLOC_MOVE_ZERO);
690 				} else
691 					bzero(dst, sc->sectorsize);
692 			} else if (osp <= 255) {
693 				if (notmapped) {
694 					error = md_malloc_move_ma(&m, &ma_offs,
695 					    sc->sectorsize, NULL, osp,
696 					    MD_MALLOC_MOVE_FILL);
697 				} else if (vlist != NULL) {
698 					error = md_malloc_move_vlist(&vlist,
699 					    &ma_offs, sc->sectorsize, NULL, osp,
700 					    MD_MALLOC_MOVE_FILL);
701 				} else
702 					memset(dst, osp, sc->sectorsize);
703 			} else {
704 				if (notmapped) {
705 					error = md_malloc_move_ma(&m, &ma_offs,
706 					    sc->sectorsize, (void *)osp, 0,
707 					    MD_MALLOC_MOVE_READ);
708 				} else if (vlist != NULL) {
709 					error = md_malloc_move_vlist(&vlist,
710 					    &ma_offs, sc->sectorsize,
711 					    (void *)osp, 0,
712 					    MD_MALLOC_MOVE_READ);
713 				} else {
714 					bcopy((void *)osp, dst, sc->sectorsize);
715 					cpu_flush_dcache(dst, sc->sectorsize);
716 				}
717 			}
718 			osp = 0;
719 		} else if (bp->bio_cmd == BIO_WRITE) {
720 			if (sc->flags & MD_COMPRESS) {
721 				if (notmapped) {
722 					error1 = md_malloc_move_ma(&m, &ma_offs,
723 					    sc->sectorsize, &uc, 0,
724 					    MD_MALLOC_MOVE_CMP);
725 					i = error1 == 0 ? sc->sectorsize : 0;
726 				} else if (vlist != NULL) {
727 					error1 = md_malloc_move_vlist(&vlist,
728 					    &ma_offs, sc->sectorsize, &uc, 0,
729 					    MD_MALLOC_MOVE_CMP);
730 					i = error1 == 0 ? sc->sectorsize : 0;
731 				} else {
732 					uc = dst[0];
733 					for (i = 1; i < sc->sectorsize; i++) {
734 						if (dst[i] != uc)
735 							break;
736 					}
737 				}
738 			} else {
739 				i = 0;
740 				uc = 0;
741 			}
742 			if (i == sc->sectorsize) {
743 				if (osp != uc)
744 					error = s_write(sc->indir, secno, uc);
745 			} else {
746 				if (osp <= 255) {
747 					sp = (uintptr_t)uma_zalloc(sc->uma,
748 					    md_malloc_wait ? M_WAITOK :
749 					    M_NOWAIT);
750 					if (sp == 0) {
751 						error = ENOSPC;
752 						break;
753 					}
754 					if (notmapped) {
755 						error = md_malloc_move_ma(&m,
756 						    &ma_offs, sc->sectorsize,
757 						    (void *)sp, 0,
758 						    MD_MALLOC_MOVE_WRITE);
759 					} else if (vlist != NULL) {
760 						error = md_malloc_move_vlist(
761 						    &vlist, &ma_offs,
762 						    sc->sectorsize, (void *)sp,
763 						    0, MD_MALLOC_MOVE_WRITE);
764 					} else {
765 						bcopy(dst, (void *)sp,
766 						    sc->sectorsize);
767 					}
768 					error = s_write(sc->indir, secno, sp);
769 				} else {
770 					if (notmapped) {
771 						error = md_malloc_move_ma(&m,
772 						    &ma_offs, sc->sectorsize,
773 						    (void *)osp, 0,
774 						    MD_MALLOC_MOVE_WRITE);
775 					} else if (vlist != NULL) {
776 						error = md_malloc_move_vlist(
777 						    &vlist, &ma_offs,
778 						    sc->sectorsize, (void *)osp,
779 						    0, MD_MALLOC_MOVE_WRITE);
780 					} else {
781 						bcopy(dst, (void *)osp,
782 						    sc->sectorsize);
783 					}
784 					osp = 0;
785 				}
786 			}
787 		} else {
788 			error = EOPNOTSUPP;
789 		}
790 		if (osp > 255)
791 			uma_zfree(sc->uma, (void*)osp);
792 		if (error != 0)
793 			break;
794 		secno++;
795 		if (!notmapped && vlist == NULL)
796 			dst += sc->sectorsize;
797 	}
798 	bp->bio_resid = 0;
799 	return (error);
800 }
801 
802 static void
803 mdcopyto_vlist(void *src, bus_dma_segment_t *vlist, off_t offset, off_t len)
804 {
805 	off_t seg_len;
806 
807 	while (offset >= vlist->ds_len) {
808 		offset -= vlist->ds_len;
809 		vlist++;
810 	}
811 
812 	while (len != 0) {
813 		seg_len = omin(len, vlist->ds_len - offset);
814 		bcopy(src, (void *)(uintptr_t)(vlist->ds_addr + offset),
815 		    seg_len);
816 		offset = 0;
817 		src = (uint8_t *)src + seg_len;
818 		len -= seg_len;
819 		vlist++;
820 	}
821 }
822 
823 static void
824 mdcopyfrom_vlist(bus_dma_segment_t *vlist, off_t offset, void *dst, off_t len)
825 {
826 	off_t seg_len;
827 
828 	while (offset >= vlist->ds_len) {
829 		offset -= vlist->ds_len;
830 		vlist++;
831 	}
832 
833 	while (len != 0) {
834 		seg_len = omin(len, vlist->ds_len - offset);
835 		bcopy((void *)(uintptr_t)(vlist->ds_addr + offset), dst,
836 		    seg_len);
837 		offset = 0;
838 		dst = (uint8_t *)dst + seg_len;
839 		len -= seg_len;
840 		vlist++;
841 	}
842 }
843 
844 static int
845 mdstart_preload(struct md_s *sc, struct bio *bp)
846 {
847 	uint8_t *p;
848 
849 	p = sc->pl_ptr + bp->bio_offset;
850 	switch (bp->bio_cmd) {
851 	case BIO_READ:
852 		if ((bp->bio_flags & BIO_VLIST) != 0) {
853 			mdcopyto_vlist(p, (bus_dma_segment_t *)bp->bio_data,
854 			    bp->bio_ma_offset, bp->bio_length);
855 		} else {
856 			bcopy(p, bp->bio_data, bp->bio_length);
857 		}
858 		cpu_flush_dcache(bp->bio_data, bp->bio_length);
859 		break;
860 	case BIO_WRITE:
861 		if ((bp->bio_flags & BIO_VLIST) != 0) {
862 			mdcopyfrom_vlist((bus_dma_segment_t *)bp->bio_data,
863 			    bp->bio_ma_offset, p, bp->bio_length);
864 		} else {
865 			bcopy(bp->bio_data, p, bp->bio_length);
866 		}
867 		break;
868 	}
869 	bp->bio_resid = 0;
870 	return (0);
871 }
872 
873 static int
874 mdstart_vnode(struct md_s *sc, struct bio *bp)
875 {
876 	int error;
877 	struct uio auio;
878 	struct iovec aiov;
879 	struct iovec *piov;
880 	struct mount *mp;
881 	struct vnode *vp;
882 	struct buf *pb;
883 	bus_dma_segment_t *vlist;
884 	struct thread *td;
885 	off_t iolen, iostart, len, zerosize;
886 	int ma_offs, npages;
887 
888 	switch (bp->bio_cmd) {
889 	case BIO_READ:
890 		auio.uio_rw = UIO_READ;
891 		break;
892 	case BIO_WRITE:
893 	case BIO_DELETE:
894 		auio.uio_rw = UIO_WRITE;
895 		break;
896 	case BIO_FLUSH:
897 		break;
898 	default:
899 		return (EOPNOTSUPP);
900 	}
901 
902 	td = curthread;
903 	vp = sc->vnode;
904 	pb = NULL;
905 	piov = NULL;
906 	ma_offs = bp->bio_ma_offset;
907 	len = bp->bio_length;
908 
909 	/*
910 	 * VNODE I/O
911 	 *
912 	 * If an error occurs, we set BIO_ERROR but we do not set
913 	 * B_INVAL because (for a write anyway), the buffer is
914 	 * still valid.
915 	 */
916 
917 	if (bp->bio_cmd == BIO_FLUSH) {
918 		(void) vn_start_write(vp, &mp, V_WAIT);
919 		vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
920 		error = VOP_FSYNC(vp, MNT_WAIT, td);
921 		VOP_UNLOCK(vp, 0);
922 		vn_finished_write(mp);
923 		return (error);
924 	}
925 
926 	auio.uio_offset = (vm_ooffset_t)bp->bio_offset;
927 	auio.uio_resid = bp->bio_length;
928 	auio.uio_segflg = UIO_SYSSPACE;
929 	auio.uio_td = td;
930 
931 	if (bp->bio_cmd == BIO_DELETE) {
932 		/*
933 		 * Emulate BIO_DELETE by writing zeros.
934 		 */
935 		zerosize = ZERO_REGION_SIZE -
936 		    (ZERO_REGION_SIZE % sc->sectorsize);
937 		auio.uio_iovcnt = howmany(bp->bio_length, zerosize);
938 		piov = malloc(sizeof(*piov) * auio.uio_iovcnt, M_MD, M_WAITOK);
939 		auio.uio_iov = piov;
940 		while (len > 0) {
941 			piov->iov_base = __DECONST(void *, zero_region);
942 			piov->iov_len = len;
943 			if (len > zerosize)
944 				piov->iov_len = zerosize;
945 			len -= piov->iov_len;
946 			piov++;
947 		}
948 		piov = auio.uio_iov;
949 	} else if ((bp->bio_flags & BIO_VLIST) != 0) {
950 		piov = malloc(sizeof(*piov) * bp->bio_ma_n, M_MD, M_WAITOK);
951 		auio.uio_iov = piov;
952 		vlist = (bus_dma_segment_t *)bp->bio_data;
953 		while (len > 0) {
954 			piov->iov_base = (void *)(uintptr_t)(vlist->ds_addr +
955 			    ma_offs);
956 			piov->iov_len = vlist->ds_len - ma_offs;
957 			if (piov->iov_len > len)
958 				piov->iov_len = len;
959 			len -= piov->iov_len;
960 			ma_offs = 0;
961 			vlist++;
962 			piov++;
963 		}
964 		auio.uio_iovcnt = piov - auio.uio_iov;
965 		piov = auio.uio_iov;
966 	} else if ((bp->bio_flags & BIO_UNMAPPED) != 0) {
967 		pb = uma_zalloc(md_pbuf_zone, M_WAITOK);
968 		bp->bio_resid = len;
969 unmapped_step:
970 		npages = atop(min(MAXPHYS, round_page(len + (ma_offs &
971 		    PAGE_MASK))));
972 		iolen = min(ptoa(npages) - (ma_offs & PAGE_MASK), len);
973 		KASSERT(iolen > 0, ("zero iolen"));
974 		pmap_qenter((vm_offset_t)pb->b_data,
975 		    &bp->bio_ma[atop(ma_offs)], npages);
976 		aiov.iov_base = (void *)((vm_offset_t)pb->b_data +
977 		    (ma_offs & PAGE_MASK));
978 		aiov.iov_len = iolen;
979 		auio.uio_iov = &aiov;
980 		auio.uio_iovcnt = 1;
981 		auio.uio_resid = iolen;
982 	} else {
983 		aiov.iov_base = bp->bio_data;
984 		aiov.iov_len = bp->bio_length;
985 		auio.uio_iov = &aiov;
986 		auio.uio_iovcnt = 1;
987 	}
988 	iostart = auio.uio_offset;
989 	if (auio.uio_rw == UIO_READ) {
990 		vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
991 		error = VOP_READ(vp, &auio, 0, sc->cred);
992 		VOP_UNLOCK(vp, 0);
993 	} else {
994 		(void) vn_start_write(vp, &mp, V_WAIT);
995 		vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
996 		error = VOP_WRITE(vp, &auio, sc->flags & MD_ASYNC ? 0 : IO_SYNC,
997 		    sc->cred);
998 		VOP_UNLOCK(vp, 0);
999 		vn_finished_write(mp);
1000 		if (error == 0)
1001 			sc->flags &= ~MD_VERIFY;
1002 	}
1003 
1004 	/* When MD_CACHE is set, try to avoid double-caching the data. */
1005 	if (error == 0 && (sc->flags & MD_CACHE) == 0)
1006 		VOP_ADVISE(vp, iostart, auio.uio_offset - 1,
1007 		    POSIX_FADV_DONTNEED);
1008 
1009 	if (pb != NULL) {
1010 		pmap_qremove((vm_offset_t)pb->b_data, npages);
1011 		if (error == 0) {
1012 			len -= iolen;
1013 			bp->bio_resid -= iolen;
1014 			ma_offs += iolen;
1015 			if (len > 0)
1016 				goto unmapped_step;
1017 		}
1018 		uma_zfree(md_pbuf_zone, pb);
1019 	}
1020 
1021 	free(piov, M_MD);
1022 	if (pb == NULL)
1023 		bp->bio_resid = auio.uio_resid;
1024 	return (error);
1025 }
1026 
1027 static void
1028 md_swap_page_free(vm_page_t m)
1029 {
1030 
1031 	vm_page_xunbusy(m);
1032 	vm_page_lock(m);
1033 	vm_page_free(m);
1034 	vm_page_unlock(m);
1035 }
1036 
1037 static int
1038 mdstart_swap(struct md_s *sc, struct bio *bp)
1039 {
1040 	vm_page_t m;
1041 	u_char *p;
1042 	vm_pindex_t i, lastp;
1043 	bus_dma_segment_t *vlist;
1044 	int rv, ma_offs, offs, len, lastend;
1045 
1046 	switch (bp->bio_cmd) {
1047 	case BIO_READ:
1048 	case BIO_WRITE:
1049 	case BIO_DELETE:
1050 		break;
1051 	default:
1052 		return (EOPNOTSUPP);
1053 	}
1054 
1055 	p = bp->bio_data;
1056 	ma_offs = (bp->bio_flags & (BIO_UNMAPPED|BIO_VLIST)) != 0 ?
1057 	    bp->bio_ma_offset : 0;
1058 	vlist = (bp->bio_flags & BIO_VLIST) != 0 ?
1059 	    (bus_dma_segment_t *)bp->bio_data : NULL;
1060 
1061 	/*
1062 	 * offs is the offset at which to start operating on the
1063 	 * next (ie, first) page.  lastp is the last page on
1064 	 * which we're going to operate.  lastend is the ending
1065 	 * position within that last page (ie, PAGE_SIZE if
1066 	 * we're operating on complete aligned pages).
1067 	 */
1068 	offs = bp->bio_offset % PAGE_SIZE;
1069 	lastp = (bp->bio_offset + bp->bio_length - 1) / PAGE_SIZE;
1070 	lastend = (bp->bio_offset + bp->bio_length - 1) % PAGE_SIZE + 1;
1071 
1072 	rv = VM_PAGER_OK;
1073 	VM_OBJECT_WLOCK(sc->object);
1074 	vm_object_pip_add(sc->object, 1);
1075 	for (i = bp->bio_offset / PAGE_SIZE; i <= lastp; i++) {
1076 		len = ((i == lastp) ? lastend : PAGE_SIZE) - offs;
1077 		m = vm_page_grab(sc->object, i, VM_ALLOC_SYSTEM);
1078 		if (bp->bio_cmd == BIO_READ) {
1079 			if (m->valid == VM_PAGE_BITS_ALL)
1080 				rv = VM_PAGER_OK;
1081 			else
1082 				rv = vm_pager_get_pages(sc->object, &m, 1,
1083 				    NULL, NULL);
1084 			if (rv == VM_PAGER_ERROR) {
1085 				md_swap_page_free(m);
1086 				break;
1087 			} else if (rv == VM_PAGER_FAIL) {
1088 				/*
1089 				 * Pager does not have the page.  Zero
1090 				 * the allocated page, and mark it as
1091 				 * valid. Do not set dirty, the page
1092 				 * can be recreated if thrown out.
1093 				 */
1094 				pmap_zero_page(m);
1095 				m->valid = VM_PAGE_BITS_ALL;
1096 			}
1097 			if ((bp->bio_flags & BIO_UNMAPPED) != 0) {
1098 				pmap_copy_pages(&m, offs, bp->bio_ma,
1099 				    ma_offs, len);
1100 			} else if ((bp->bio_flags & BIO_VLIST) != 0) {
1101 				physcopyout_vlist(VM_PAGE_TO_PHYS(m) + offs,
1102 				    vlist, ma_offs, len);
1103 				cpu_flush_dcache(p, len);
1104 			} else {
1105 				physcopyout(VM_PAGE_TO_PHYS(m) + offs, p, len);
1106 				cpu_flush_dcache(p, len);
1107 			}
1108 		} else if (bp->bio_cmd == BIO_WRITE) {
1109 			if (len == PAGE_SIZE || m->valid == VM_PAGE_BITS_ALL)
1110 				rv = VM_PAGER_OK;
1111 			else
1112 				rv = vm_pager_get_pages(sc->object, &m, 1,
1113 				    NULL, NULL);
1114 			if (rv == VM_PAGER_ERROR) {
1115 				md_swap_page_free(m);
1116 				break;
1117 			} else if (rv == VM_PAGER_FAIL)
1118 				pmap_zero_page(m);
1119 
1120 			if ((bp->bio_flags & BIO_UNMAPPED) != 0) {
1121 				pmap_copy_pages(bp->bio_ma, ma_offs, &m,
1122 				    offs, len);
1123 			} else if ((bp->bio_flags & BIO_VLIST) != 0) {
1124 				physcopyin_vlist(vlist, ma_offs,
1125 				    VM_PAGE_TO_PHYS(m) + offs, len);
1126 			} else {
1127 				physcopyin(p, VM_PAGE_TO_PHYS(m) + offs, len);
1128 			}
1129 
1130 			m->valid = VM_PAGE_BITS_ALL;
1131 			if (m->dirty != VM_PAGE_BITS_ALL) {
1132 				vm_page_dirty(m);
1133 				vm_pager_page_unswapped(m);
1134 			}
1135 		} else if (bp->bio_cmd == BIO_DELETE) {
1136 			if (len == PAGE_SIZE || m->valid == VM_PAGE_BITS_ALL)
1137 				rv = VM_PAGER_OK;
1138 			else
1139 				rv = vm_pager_get_pages(sc->object, &m, 1,
1140 				    NULL, NULL);
1141 			if (rv == VM_PAGER_ERROR) {
1142 				md_swap_page_free(m);
1143 				break;
1144 			} else if (rv == VM_PAGER_FAIL) {
1145 				md_swap_page_free(m);
1146 				m = NULL;
1147 			} else {
1148 				/* Page is valid. */
1149 				if (len != PAGE_SIZE) {
1150 					pmap_zero_page_area(m, offs, len);
1151 					if (m->dirty != VM_PAGE_BITS_ALL) {
1152 						vm_page_dirty(m);
1153 						vm_pager_page_unswapped(m);
1154 					}
1155 				} else {
1156 					vm_pager_page_unswapped(m);
1157 					md_swap_page_free(m);
1158 					m = NULL;
1159 				}
1160 			}
1161 		}
1162 		if (m != NULL) {
1163 			vm_page_xunbusy(m);
1164 			vm_page_lock(m);
1165 			if (vm_page_active(m))
1166 				vm_page_reference(m);
1167 			else
1168 				vm_page_activate(m);
1169 			vm_page_unlock(m);
1170 		}
1171 
1172 		/* Actions on further pages start at offset 0 */
1173 		p += PAGE_SIZE - offs;
1174 		offs = 0;
1175 		ma_offs += len;
1176 	}
1177 	vm_object_pip_wakeup(sc->object);
1178 	VM_OBJECT_WUNLOCK(sc->object);
1179 	return (rv != VM_PAGER_ERROR ? 0 : ENOSPC);
1180 }
1181 
1182 static int
1183 mdstart_null(struct md_s *sc, struct bio *bp)
1184 {
1185 
1186 	switch (bp->bio_cmd) {
1187 	case BIO_READ:
1188 		bzero(bp->bio_data, bp->bio_length);
1189 		cpu_flush_dcache(bp->bio_data, bp->bio_length);
1190 		break;
1191 	case BIO_WRITE:
1192 		break;
1193 	}
1194 	bp->bio_resid = 0;
1195 	return (0);
1196 }
1197 
1198 static void
1199 md_kthread(void *arg)
1200 {
1201 	struct md_s *sc;
1202 	struct bio *bp;
1203 	int error;
1204 
1205 	sc = arg;
1206 	thread_lock(curthread);
1207 	sched_prio(curthread, PRIBIO);
1208 	thread_unlock(curthread);
1209 	if (sc->type == MD_VNODE)
1210 		curthread->td_pflags |= TDP_NORUNNINGBUF;
1211 
1212 	for (;;) {
1213 		mtx_lock(&sc->queue_mtx);
1214 		if (sc->flags & MD_SHUTDOWN) {
1215 			sc->flags |= MD_EXITING;
1216 			mtx_unlock(&sc->queue_mtx);
1217 			kproc_exit(0);
1218 		}
1219 		bp = bioq_takefirst(&sc->bio_queue);
1220 		if (!bp) {
1221 			msleep(sc, &sc->queue_mtx, PRIBIO | PDROP, "mdwait", 0);
1222 			continue;
1223 		}
1224 		mtx_unlock(&sc->queue_mtx);
1225 		if (bp->bio_cmd == BIO_GETATTR) {
1226 			int isv = ((sc->flags & MD_VERIFY) != 0);
1227 
1228 			if ((sc->fwsectors && sc->fwheads &&
1229 			    (g_handleattr_int(bp, "GEOM::fwsectors",
1230 			    sc->fwsectors) ||
1231 			    g_handleattr_int(bp, "GEOM::fwheads",
1232 			    sc->fwheads))) ||
1233 			    g_handleattr_int(bp, "GEOM::candelete", 1))
1234 				error = -1;
1235 			else if (sc->ident[0] != '\0' &&
1236 			    g_handleattr_str(bp, "GEOM::ident", sc->ident))
1237 				error = -1;
1238 			else if (g_handleattr_int(bp, "MNT::verified", isv))
1239 				error = -1;
1240 			else
1241 				error = EOPNOTSUPP;
1242 		} else {
1243 			error = sc->start(sc, bp);
1244 		}
1245 
1246 		if (bp->bio_cmd == BIO_READ || bp->bio_cmd == BIO_WRITE) {
1247 			/*
1248 			 * Devstat uses (bio_bcount, bio_resid) for
1249 			 * determining the length of the completed part of
1250 			 * the i/o.  g_io_deliver() will translate from
1251 			 * bio_completed to that, but it also destroys the
1252 			 * bio so we must do our own translation.
1253 			 */
1254 			bp->bio_bcount = bp->bio_length;
1255 			bp->bio_resid = (error == -1 ? bp->bio_bcount : 0);
1256 			devstat_end_transaction_bio(sc->devstat, bp);
1257 		}
1258 		if (error != -1) {
1259 			bp->bio_completed = bp->bio_length;
1260 			g_io_deliver(bp, error);
1261 		}
1262 	}
1263 }
1264 
1265 static struct md_s *
1266 mdfind(int unit)
1267 {
1268 	struct md_s *sc;
1269 
1270 	LIST_FOREACH(sc, &md_softc_list, list) {
1271 		if (sc->unit == unit)
1272 			break;
1273 	}
1274 	return (sc);
1275 }
1276 
1277 static struct md_s *
1278 mdnew(int unit, int *errp, enum md_types type)
1279 {
1280 	struct md_s *sc;
1281 	int error;
1282 
1283 	*errp = 0;
1284 	if (unit == -1)
1285 		unit = alloc_unr(md_uh);
1286 	else
1287 		unit = alloc_unr_specific(md_uh, unit);
1288 
1289 	if (unit == -1) {
1290 		*errp = EBUSY;
1291 		return (NULL);
1292 	}
1293 
1294 	sc = (struct md_s *)malloc(sizeof *sc, M_MD, M_WAITOK | M_ZERO);
1295 	sc->type = type;
1296 	bioq_init(&sc->bio_queue);
1297 	mtx_init(&sc->queue_mtx, "md bio queue", NULL, MTX_DEF);
1298 	mtx_init(&sc->stat_mtx, "md stat", NULL, MTX_DEF);
1299 	sc->unit = unit;
1300 	sprintf(sc->name, "md%d", unit);
1301 	LIST_INSERT_HEAD(&md_softc_list, sc, list);
1302 	error = kproc_create(md_kthread, sc, &sc->procp, 0, 0,"%s", sc->name);
1303 	if (error == 0)
1304 		return (sc);
1305 	LIST_REMOVE(sc, list);
1306 	mtx_destroy(&sc->stat_mtx);
1307 	mtx_destroy(&sc->queue_mtx);
1308 	free_unr(md_uh, sc->unit);
1309 	free(sc, M_MD);
1310 	*errp = error;
1311 	return (NULL);
1312 }
1313 
1314 static void
1315 mdinit(struct md_s *sc)
1316 {
1317 	struct g_geom *gp;
1318 	struct g_provider *pp;
1319 
1320 	g_topology_lock();
1321 	gp = g_new_geomf(&g_md_class, "md%d", sc->unit);
1322 	gp->softc = sc;
1323 	pp = g_new_providerf(gp, "md%d", sc->unit);
1324 	pp->flags |= G_PF_DIRECT_SEND | G_PF_DIRECT_RECEIVE;
1325 	pp->mediasize = sc->mediasize;
1326 	pp->sectorsize = sc->sectorsize;
1327 	switch (sc->type) {
1328 	case MD_MALLOC:
1329 	case MD_VNODE:
1330 	case MD_SWAP:
1331 		pp->flags |= G_PF_ACCEPT_UNMAPPED;
1332 		break;
1333 	case MD_PRELOAD:
1334 	case MD_NULL:
1335 		break;
1336 	}
1337 	sc->gp = gp;
1338 	sc->pp = pp;
1339 	g_error_provider(pp, 0);
1340 	g_topology_unlock();
1341 	sc->devstat = devstat_new_entry("md", sc->unit, sc->sectorsize,
1342 	    DEVSTAT_ALL_SUPPORTED, DEVSTAT_TYPE_DIRECT, DEVSTAT_PRIORITY_MAX);
1343 }
1344 
1345 static int
1346 mdcreate_malloc(struct md_s *sc, struct md_req *mdr)
1347 {
1348 	uintptr_t sp;
1349 	int error;
1350 	off_t u;
1351 
1352 	error = 0;
1353 	if (mdr->md_options & ~(MD_AUTOUNIT | MD_COMPRESS | MD_RESERVE))
1354 		return (EINVAL);
1355 	if (mdr->md_sectorsize != 0 && !powerof2(mdr->md_sectorsize))
1356 		return (EINVAL);
1357 	/* Compression doesn't make sense if we have reserved space */
1358 	if (mdr->md_options & MD_RESERVE)
1359 		mdr->md_options &= ~MD_COMPRESS;
1360 	if (mdr->md_fwsectors != 0)
1361 		sc->fwsectors = mdr->md_fwsectors;
1362 	if (mdr->md_fwheads != 0)
1363 		sc->fwheads = mdr->md_fwheads;
1364 	sc->flags = mdr->md_options & (MD_COMPRESS | MD_FORCE);
1365 	sc->indir = dimension(sc->mediasize / sc->sectorsize);
1366 	sc->uma = uma_zcreate(sc->name, sc->sectorsize, NULL, NULL, NULL, NULL,
1367 	    0x1ff, 0);
1368 	if (mdr->md_options & MD_RESERVE) {
1369 		off_t nsectors;
1370 
1371 		nsectors = sc->mediasize / sc->sectorsize;
1372 		for (u = 0; u < nsectors; u++) {
1373 			sp = (uintptr_t)uma_zalloc(sc->uma, (md_malloc_wait ?
1374 			    M_WAITOK : M_NOWAIT) | M_ZERO);
1375 			if (sp != 0)
1376 				error = s_write(sc->indir, u, sp);
1377 			else
1378 				error = ENOMEM;
1379 			if (error != 0)
1380 				break;
1381 		}
1382 	}
1383 	return (error);
1384 }
1385 
1386 
1387 static int
1388 mdsetcred(struct md_s *sc, struct ucred *cred)
1389 {
1390 	char *tmpbuf;
1391 	int error = 0;
1392 
1393 	/*
1394 	 * Set credits in our softc
1395 	 */
1396 
1397 	if (sc->cred)
1398 		crfree(sc->cred);
1399 	sc->cred = crhold(cred);
1400 
1401 	/*
1402 	 * Horrible kludge to establish credentials for NFS  XXX.
1403 	 */
1404 
1405 	if (sc->vnode) {
1406 		struct uio auio;
1407 		struct iovec aiov;
1408 
1409 		tmpbuf = malloc(sc->sectorsize, M_TEMP, M_WAITOK);
1410 		bzero(&auio, sizeof(auio));
1411 
1412 		aiov.iov_base = tmpbuf;
1413 		aiov.iov_len = sc->sectorsize;
1414 		auio.uio_iov = &aiov;
1415 		auio.uio_iovcnt = 1;
1416 		auio.uio_offset = 0;
1417 		auio.uio_rw = UIO_READ;
1418 		auio.uio_segflg = UIO_SYSSPACE;
1419 		auio.uio_resid = aiov.iov_len;
1420 		vn_lock(sc->vnode, LK_EXCLUSIVE | LK_RETRY);
1421 		error = VOP_READ(sc->vnode, &auio, 0, sc->cred);
1422 		VOP_UNLOCK(sc->vnode, 0);
1423 		free(tmpbuf, M_TEMP);
1424 	}
1425 	return (error);
1426 }
1427 
1428 static int
1429 mdcreate_vnode(struct md_s *sc, struct md_req *mdr, struct thread *td)
1430 {
1431 	struct vattr vattr;
1432 	struct nameidata nd;
1433 	char *fname;
1434 	int error, flags;
1435 
1436 	fname = mdr->md_file;
1437 	if (mdr->md_file_seg == UIO_USERSPACE) {
1438 		error = copyinstr(fname, sc->file, sizeof(sc->file), NULL);
1439 		if (error != 0)
1440 			return (error);
1441 	} else if (mdr->md_file_seg == UIO_SYSSPACE)
1442 		strlcpy(sc->file, fname, sizeof(sc->file));
1443 	else
1444 		return (EDOOFUS);
1445 
1446 	/*
1447 	 * If the user specified that this is a read only device, don't
1448 	 * set the FWRITE mask before trying to open the backing store.
1449 	 */
1450 	flags = FREAD | ((mdr->md_options & MD_READONLY) ? 0 : FWRITE) \
1451 	    | ((mdr->md_options & MD_VERIFY) ? O_VERIFY : 0);
1452 	NDINIT(&nd, LOOKUP, FOLLOW, UIO_SYSSPACE, sc->file, td);
1453 	error = vn_open(&nd, &flags, 0, NULL);
1454 	if (error != 0)
1455 		return (error);
1456 	NDFREE(&nd, NDF_ONLY_PNBUF);
1457 	if (nd.ni_vp->v_type != VREG) {
1458 		error = EINVAL;
1459 		goto bad;
1460 	}
1461 	error = VOP_GETATTR(nd.ni_vp, &vattr, td->td_ucred);
1462 	if (error != 0)
1463 		goto bad;
1464 	if (VOP_ISLOCKED(nd.ni_vp) != LK_EXCLUSIVE) {
1465 		vn_lock(nd.ni_vp, LK_UPGRADE | LK_RETRY);
1466 		if (nd.ni_vp->v_iflag & VI_DOOMED) {
1467 			/* Forced unmount. */
1468 			error = EBADF;
1469 			goto bad;
1470 		}
1471 	}
1472 	nd.ni_vp->v_vflag |= VV_MD;
1473 	VOP_UNLOCK(nd.ni_vp, 0);
1474 
1475 	if (mdr->md_fwsectors != 0)
1476 		sc->fwsectors = mdr->md_fwsectors;
1477 	if (mdr->md_fwheads != 0)
1478 		sc->fwheads = mdr->md_fwheads;
1479 	snprintf(sc->ident, sizeof(sc->ident), "MD-DEV%ju-INO%ju",
1480 	    (uintmax_t)vattr.va_fsid, (uintmax_t)vattr.va_fileid);
1481 	sc->flags = mdr->md_options & (MD_ASYNC | MD_CACHE | MD_FORCE |
1482 	    MD_VERIFY);
1483 	if (!(flags & FWRITE))
1484 		sc->flags |= MD_READONLY;
1485 	sc->vnode = nd.ni_vp;
1486 
1487 	error = mdsetcred(sc, td->td_ucred);
1488 	if (error != 0) {
1489 		sc->vnode = NULL;
1490 		vn_lock(nd.ni_vp, LK_EXCLUSIVE | LK_RETRY);
1491 		nd.ni_vp->v_vflag &= ~VV_MD;
1492 		goto bad;
1493 	}
1494 	return (0);
1495 bad:
1496 	VOP_UNLOCK(nd.ni_vp, 0);
1497 	(void)vn_close(nd.ni_vp, flags, td->td_ucred, td);
1498 	return (error);
1499 }
1500 
1501 static void
1502 g_md_providergone(struct g_provider *pp)
1503 {
1504 	struct md_s *sc = pp->geom->softc;
1505 
1506 	mtx_lock(&sc->queue_mtx);
1507 	sc->flags |= MD_PROVIDERGONE;
1508 	wakeup(&sc->flags);
1509 	mtx_unlock(&sc->queue_mtx);
1510 }
1511 
1512 static int
1513 mddestroy(struct md_s *sc, struct thread *td)
1514 {
1515 
1516 	if (sc->gp) {
1517 		g_topology_lock();
1518 		g_wither_geom(sc->gp, ENXIO);
1519 		g_topology_unlock();
1520 
1521 		mtx_lock(&sc->queue_mtx);
1522 		while (!(sc->flags & MD_PROVIDERGONE))
1523 			msleep(&sc->flags, &sc->queue_mtx, PRIBIO, "mddestroy", 0);
1524 		mtx_unlock(&sc->queue_mtx);
1525 	}
1526 	if (sc->devstat) {
1527 		devstat_remove_entry(sc->devstat);
1528 		sc->devstat = NULL;
1529 	}
1530 	mtx_lock(&sc->queue_mtx);
1531 	sc->flags |= MD_SHUTDOWN;
1532 	wakeup(sc);
1533 	while (!(sc->flags & MD_EXITING))
1534 		msleep(sc->procp, &sc->queue_mtx, PRIBIO, "mddestroy", hz / 10);
1535 	mtx_unlock(&sc->queue_mtx);
1536 	mtx_destroy(&sc->stat_mtx);
1537 	mtx_destroy(&sc->queue_mtx);
1538 	if (sc->vnode != NULL) {
1539 		vn_lock(sc->vnode, LK_EXCLUSIVE | LK_RETRY);
1540 		sc->vnode->v_vflag &= ~VV_MD;
1541 		VOP_UNLOCK(sc->vnode, 0);
1542 		(void)vn_close(sc->vnode, sc->flags & MD_READONLY ?
1543 		    FREAD : (FREAD|FWRITE), sc->cred, td);
1544 	}
1545 	if (sc->cred != NULL)
1546 		crfree(sc->cred);
1547 	if (sc->object != NULL)
1548 		vm_object_deallocate(sc->object);
1549 	if (sc->indir)
1550 		destroy_indir(sc, sc->indir);
1551 	if (sc->uma)
1552 		uma_zdestroy(sc->uma);
1553 
1554 	LIST_REMOVE(sc, list);
1555 	free_unr(md_uh, sc->unit);
1556 	free(sc, M_MD);
1557 	return (0);
1558 }
1559 
1560 static int
1561 mdresize(struct md_s *sc, struct md_req *mdr)
1562 {
1563 	int error, res;
1564 	vm_pindex_t oldpages, newpages;
1565 
1566 	switch (sc->type) {
1567 	case MD_VNODE:
1568 	case MD_NULL:
1569 		break;
1570 	case MD_SWAP:
1571 		if (mdr->md_mediasize <= 0 ||
1572 		    (mdr->md_mediasize % PAGE_SIZE) != 0)
1573 			return (EDOM);
1574 		oldpages = OFF_TO_IDX(round_page(sc->mediasize));
1575 		newpages = OFF_TO_IDX(round_page(mdr->md_mediasize));
1576 		if (newpages < oldpages) {
1577 			VM_OBJECT_WLOCK(sc->object);
1578 			vm_object_page_remove(sc->object, newpages, 0, 0);
1579 			swap_pager_freespace(sc->object, newpages,
1580 			    oldpages - newpages);
1581 			swap_release_by_cred(IDX_TO_OFF(oldpages -
1582 			    newpages), sc->cred);
1583 			sc->object->charge = IDX_TO_OFF(newpages);
1584 			sc->object->size = newpages;
1585 			VM_OBJECT_WUNLOCK(sc->object);
1586 		} else if (newpages > oldpages) {
1587 			res = swap_reserve_by_cred(IDX_TO_OFF(newpages -
1588 			    oldpages), sc->cred);
1589 			if (!res)
1590 				return (ENOMEM);
1591 			if ((mdr->md_options & MD_RESERVE) ||
1592 			    (sc->flags & MD_RESERVE)) {
1593 				error = swap_pager_reserve(sc->object,
1594 				    oldpages, newpages - oldpages);
1595 				if (error < 0) {
1596 					swap_release_by_cred(
1597 					    IDX_TO_OFF(newpages - oldpages),
1598 					    sc->cred);
1599 					return (EDOM);
1600 				}
1601 			}
1602 			VM_OBJECT_WLOCK(sc->object);
1603 			sc->object->charge = IDX_TO_OFF(newpages);
1604 			sc->object->size = newpages;
1605 			VM_OBJECT_WUNLOCK(sc->object);
1606 		}
1607 		break;
1608 	default:
1609 		return (EOPNOTSUPP);
1610 	}
1611 
1612 	sc->mediasize = mdr->md_mediasize;
1613 	g_topology_lock();
1614 	g_resize_provider(sc->pp, sc->mediasize);
1615 	g_topology_unlock();
1616 	return (0);
1617 }
1618 
1619 static int
1620 mdcreate_swap(struct md_s *sc, struct md_req *mdr, struct thread *td)
1621 {
1622 	vm_ooffset_t npage;
1623 	int error;
1624 
1625 	/*
1626 	 * Range check.  Disallow negative sizes and sizes not being
1627 	 * multiple of page size.
1628 	 */
1629 	if (sc->mediasize <= 0 || (sc->mediasize % PAGE_SIZE) != 0)
1630 		return (EDOM);
1631 
1632 	/*
1633 	 * Allocate an OBJT_SWAP object.
1634 	 *
1635 	 * Note the truncation.
1636 	 */
1637 
1638 	if ((mdr->md_options & MD_VERIFY) != 0)
1639 		return (EINVAL);
1640 	npage = mdr->md_mediasize / PAGE_SIZE;
1641 	if (mdr->md_fwsectors != 0)
1642 		sc->fwsectors = mdr->md_fwsectors;
1643 	if (mdr->md_fwheads != 0)
1644 		sc->fwheads = mdr->md_fwheads;
1645 	sc->object = vm_pager_allocate(OBJT_SWAP, NULL, PAGE_SIZE * npage,
1646 	    VM_PROT_DEFAULT, 0, td->td_ucred);
1647 	if (sc->object == NULL)
1648 		return (ENOMEM);
1649 	sc->flags = mdr->md_options & (MD_FORCE | MD_RESERVE);
1650 	if (mdr->md_options & MD_RESERVE) {
1651 		if (swap_pager_reserve(sc->object, 0, npage) < 0) {
1652 			error = EDOM;
1653 			goto finish;
1654 		}
1655 	}
1656 	error = mdsetcred(sc, td->td_ucred);
1657  finish:
1658 	if (error != 0) {
1659 		vm_object_deallocate(sc->object);
1660 		sc->object = NULL;
1661 	}
1662 	return (error);
1663 }
1664 
1665 static int
1666 mdcreate_null(struct md_s *sc, struct md_req *mdr, struct thread *td)
1667 {
1668 
1669 	/*
1670 	 * Range check.  Disallow negative sizes and sizes not being
1671 	 * multiple of page size.
1672 	 */
1673 	if (sc->mediasize <= 0 || (sc->mediasize % PAGE_SIZE) != 0)
1674 		return (EDOM);
1675 
1676 	return (0);
1677 }
1678 
1679 static int
1680 kern_mdattach_locked(struct thread *td, struct md_req *mdr)
1681 {
1682 	struct md_s *sc;
1683 	unsigned sectsize;
1684 	int error, i;
1685 
1686 	sx_assert(&md_sx, SA_XLOCKED);
1687 
1688 	switch (mdr->md_type) {
1689 	case MD_MALLOC:
1690 	case MD_PRELOAD:
1691 	case MD_VNODE:
1692 	case MD_SWAP:
1693 	case MD_NULL:
1694 		break;
1695 	default:
1696 		return (EINVAL);
1697 	}
1698 	if (mdr->md_sectorsize == 0)
1699 		sectsize = DEV_BSIZE;
1700 	else
1701 		sectsize = mdr->md_sectorsize;
1702 	if (sectsize > MAXPHYS || mdr->md_mediasize < sectsize)
1703 		return (EINVAL);
1704 	if (mdr->md_options & MD_AUTOUNIT)
1705 		sc = mdnew(-1, &error, mdr->md_type);
1706 	else {
1707 		if (mdr->md_unit > INT_MAX)
1708 			return (EINVAL);
1709 		sc = mdnew(mdr->md_unit, &error, mdr->md_type);
1710 	}
1711 	if (sc == NULL)
1712 		return (error);
1713 	if (mdr->md_label != NULL)
1714 		error = copyinstr(mdr->md_label, sc->label,
1715 		    sizeof(sc->label), NULL);
1716 	if (error != 0)
1717 		goto err_after_new;
1718 	if (mdr->md_options & MD_AUTOUNIT)
1719 		mdr->md_unit = sc->unit;
1720 	sc->mediasize = mdr->md_mediasize;
1721 	sc->sectorsize = sectsize;
1722 	error = EDOOFUS;
1723 	switch (sc->type) {
1724 	case MD_MALLOC:
1725 		sc->start = mdstart_malloc;
1726 		error = mdcreate_malloc(sc, mdr);
1727 		break;
1728 	case MD_PRELOAD:
1729 		/*
1730 		 * We disallow attaching preloaded memory disks via
1731 		 * ioctl. Preloaded memory disks are automatically
1732 		 * attached in g_md_init().
1733 		 */
1734 		error = EOPNOTSUPP;
1735 		break;
1736 	case MD_VNODE:
1737 		sc->start = mdstart_vnode;
1738 		error = mdcreate_vnode(sc, mdr, td);
1739 		break;
1740 	case MD_SWAP:
1741 		sc->start = mdstart_swap;
1742 		error = mdcreate_swap(sc, mdr, td);
1743 		break;
1744 	case MD_NULL:
1745 		sc->start = mdstart_null;
1746 		error = mdcreate_null(sc, mdr, td);
1747 		break;
1748 	}
1749 err_after_new:
1750 	if (error != 0) {
1751 		mddestroy(sc, td);
1752 		return (error);
1753 	}
1754 
1755 	/* Prune off any residual fractional sector */
1756 	i = sc->mediasize % sc->sectorsize;
1757 	sc->mediasize -= i;
1758 
1759 	mdinit(sc);
1760 	return (0);
1761 }
1762 
1763 static int
1764 kern_mdattach(struct thread *td, struct md_req *mdr)
1765 {
1766 	int error;
1767 
1768 	sx_xlock(&md_sx);
1769 	error = kern_mdattach_locked(td, mdr);
1770 	sx_xunlock(&md_sx);
1771 	return (error);
1772 }
1773 
1774 static int
1775 kern_mddetach_locked(struct thread *td, struct md_req *mdr)
1776 {
1777 	struct md_s *sc;
1778 
1779 	sx_assert(&md_sx, SA_XLOCKED);
1780 
1781 	if (mdr->md_mediasize != 0 ||
1782 	    (mdr->md_options & ~MD_FORCE) != 0)
1783 		return (EINVAL);
1784 
1785 	sc = mdfind(mdr->md_unit);
1786 	if (sc == NULL)
1787 		return (ENOENT);
1788 	if (sc->opencount != 0 && !(sc->flags & MD_FORCE) &&
1789 	    !(mdr->md_options & MD_FORCE))
1790 		return (EBUSY);
1791 	return (mddestroy(sc, td));
1792 }
1793 
1794 static int
1795 kern_mddetach(struct thread *td, struct md_req *mdr)
1796 {
1797 	int error;
1798 
1799 	sx_xlock(&md_sx);
1800 	error = kern_mddetach_locked(td, mdr);
1801 	sx_xunlock(&md_sx);
1802 	return (error);
1803 }
1804 
1805 static int
1806 kern_mdresize_locked(struct md_req *mdr)
1807 {
1808 	struct md_s *sc;
1809 
1810 	sx_assert(&md_sx, SA_XLOCKED);
1811 
1812 	if ((mdr->md_options & ~(MD_FORCE | MD_RESERVE)) != 0)
1813 		return (EINVAL);
1814 
1815 	sc = mdfind(mdr->md_unit);
1816 	if (sc == NULL)
1817 		return (ENOENT);
1818 	if (mdr->md_mediasize < sc->sectorsize)
1819 		return (EINVAL);
1820 	if (mdr->md_mediasize < sc->mediasize &&
1821 	    !(sc->flags & MD_FORCE) &&
1822 	    !(mdr->md_options & MD_FORCE))
1823 		return (EBUSY);
1824 	return (mdresize(sc, mdr));
1825 }
1826 
1827 static int
1828 kern_mdresize(struct md_req *mdr)
1829 {
1830 	int error;
1831 
1832 	sx_xlock(&md_sx);
1833 	error = kern_mdresize_locked(mdr);
1834 	sx_xunlock(&md_sx);
1835 	return (error);
1836 }
1837 
1838 static int
1839 kern_mdquery_locked(struct md_req *mdr)
1840 {
1841 	struct md_s *sc;
1842 	int error;
1843 
1844 	sx_assert(&md_sx, SA_XLOCKED);
1845 
1846 	sc = mdfind(mdr->md_unit);
1847 	if (sc == NULL)
1848 		return (ENOENT);
1849 	mdr->md_type = sc->type;
1850 	mdr->md_options = sc->flags;
1851 	mdr->md_mediasize = sc->mediasize;
1852 	mdr->md_sectorsize = sc->sectorsize;
1853 	error = 0;
1854 	if (mdr->md_label != NULL) {
1855 		error = copyout(sc->label, mdr->md_label,
1856 		    strlen(sc->label) + 1);
1857 		if (error != 0)
1858 			return (error);
1859 	}
1860 	if (sc->type == MD_VNODE ||
1861 	    (sc->type == MD_PRELOAD && mdr->md_file != NULL))
1862 		error = copyout(sc->file, mdr->md_file,
1863 		    strlen(sc->file) + 1);
1864 	return (error);
1865 }
1866 
1867 static int
1868 kern_mdquery(struct md_req *mdr)
1869 {
1870 	int error;
1871 
1872 	sx_xlock(&md_sx);
1873 	error = kern_mdquery_locked(mdr);
1874 	sx_xunlock(&md_sx);
1875 	return (error);
1876 }
1877 
1878 /* Copy members that are not userspace pointers. */
1879 #define	MD_IOCTL2REQ(mdio, mdr) do {					\
1880 	(mdr)->md_unit = (mdio)->md_unit;				\
1881 	(mdr)->md_type = (mdio)->md_type;				\
1882 	(mdr)->md_mediasize = (mdio)->md_mediasize;			\
1883 	(mdr)->md_sectorsize = (mdio)->md_sectorsize;			\
1884 	(mdr)->md_options = (mdio)->md_options;				\
1885 	(mdr)->md_fwheads = (mdio)->md_fwheads;				\
1886 	(mdr)->md_fwsectors = (mdio)->md_fwsectors;			\
1887 	(mdr)->md_units = &(mdio)->md_pad[0];				\
1888 	(mdr)->md_units_nitems = nitems((mdio)->md_pad);		\
1889 } while(0)
1890 
1891 /* Copy members that might have been updated */
1892 #define MD_REQ2IOCTL(mdr, mdio) do {					\
1893 	(mdio)->md_unit = (mdr)->md_unit;				\
1894 	(mdio)->md_type = (mdr)->md_type;				\
1895 	(mdio)->md_mediasize = (mdr)->md_mediasize;			\
1896 	(mdio)->md_sectorsize = (mdr)->md_sectorsize;			\
1897 	(mdio)->md_options = (mdr)->md_options;				\
1898 	(mdio)->md_fwheads = (mdr)->md_fwheads;				\
1899 	(mdio)->md_fwsectors = (mdr)->md_fwsectors;			\
1900 } while(0)
1901 
1902 static int
1903 mdctlioctl(struct cdev *dev, u_long cmd, caddr_t addr, int flags,
1904     struct thread *td)
1905 {
1906 	struct md_req mdr;
1907 	int error;
1908 
1909 	if (md_debug)
1910 		printf("mdctlioctl(%s %lx %p %x %p)\n",
1911 			devtoname(dev), cmd, addr, flags, td);
1912 
1913 	bzero(&mdr, sizeof(mdr));
1914 	switch (cmd) {
1915 	case MDIOCATTACH:
1916 	case MDIOCDETACH:
1917 	case MDIOCRESIZE:
1918 	case MDIOCQUERY: {
1919 		struct md_ioctl *mdio = (struct md_ioctl *)addr;
1920 		if (mdio->md_version != MDIOVERSION)
1921 			return (EINVAL);
1922 		MD_IOCTL2REQ(mdio, &mdr);
1923 		mdr.md_file = mdio->md_file;
1924 		mdr.md_file_seg = UIO_USERSPACE;
1925 		/* If the file is adjacent to the md_ioctl it's in kernel. */
1926 		if ((void *)mdio->md_file == (void *)(mdio + 1))
1927 			mdr.md_file_seg = UIO_SYSSPACE;
1928 		mdr.md_label = mdio->md_label;
1929 		break;
1930 	}
1931 #ifdef COMPAT_FREEBSD32
1932 	case MDIOCATTACH_32:
1933 	case MDIOCDETACH_32:
1934 	case MDIOCRESIZE_32:
1935 	case MDIOCQUERY_32: {
1936 		struct md_ioctl32 *mdio = (struct md_ioctl32 *)addr;
1937 		if (mdio->md_version != MDIOVERSION)
1938 			return (EINVAL);
1939 		MD_IOCTL2REQ(mdio, &mdr);
1940 		mdr.md_file = (void *)(uintptr_t)mdio->md_file;
1941 		mdr.md_file_seg = UIO_USERSPACE;
1942 		mdr.md_label = (void *)(uintptr_t)mdio->md_label;
1943 		break;
1944 	}
1945 #endif
1946 	default:
1947 		/* Fall through to handler switch. */
1948 		break;
1949 	}
1950 
1951 	error = 0;
1952 	switch (cmd) {
1953 	case MDIOCATTACH:
1954 #ifdef COMPAT_FREEBSD32
1955 	case MDIOCATTACH_32:
1956 #endif
1957 		error = kern_mdattach(td, &mdr);
1958 		break;
1959 	case MDIOCDETACH:
1960 #ifdef COMPAT_FREEBSD32
1961 	case MDIOCDETACH_32:
1962 #endif
1963 		error = kern_mddetach(td, &mdr);
1964 		break;
1965 	case MDIOCRESIZE:
1966 #ifdef COMPAT_FREEBSD32
1967 	case MDIOCRESIZE_32:
1968 #endif
1969 		error = kern_mdresize(&mdr);
1970 		break;
1971 	case MDIOCQUERY:
1972 #ifdef COMPAT_FREEBSD32
1973 	case MDIOCQUERY_32:
1974 #endif
1975 		error = kern_mdquery(&mdr);
1976 		break;
1977 	default:
1978 		error = ENOIOCTL;
1979 	}
1980 
1981 	switch (cmd) {
1982 	case MDIOCATTACH:
1983 	case MDIOCQUERY: {
1984 		struct md_ioctl *mdio = (struct md_ioctl *)addr;
1985 		MD_REQ2IOCTL(&mdr, mdio);
1986 		break;
1987 	}
1988 #ifdef COMPAT_FREEBSD32
1989 	case MDIOCATTACH_32:
1990 	case MDIOCQUERY_32: {
1991 		struct md_ioctl32 *mdio = (struct md_ioctl32 *)addr;
1992 		MD_REQ2IOCTL(&mdr, mdio);
1993 		break;
1994 	}
1995 #endif
1996 	default:
1997 		/* Other commands to not alter mdr. */
1998 		break;
1999 	}
2000 
2001 	return (error);
2002 }
2003 
2004 static void
2005 md_preloaded(u_char *image, size_t length, const char *name)
2006 {
2007 	struct md_s *sc;
2008 	int error;
2009 
2010 	sc = mdnew(-1, &error, MD_PRELOAD);
2011 	if (sc == NULL)
2012 		return;
2013 	sc->mediasize = length;
2014 	sc->sectorsize = DEV_BSIZE;
2015 	sc->pl_ptr = image;
2016 	sc->pl_len = length;
2017 	sc->start = mdstart_preload;
2018 	if (name != NULL)
2019 		strlcpy(sc->file, name, sizeof(sc->file));
2020 #ifdef MD_ROOT
2021 	if (sc->unit == 0) {
2022 #ifndef ROOTDEVNAME
2023 		rootdevnames[0] = MD_ROOT_FSTYPE ":/dev/md0";
2024 #endif
2025 #ifdef MD_ROOT_READONLY
2026 		sc->flags |= MD_READONLY;
2027 #endif
2028 	}
2029 #endif
2030 	mdinit(sc);
2031 	if (name != NULL) {
2032 		printf("%s%d: Preloaded image <%s> %zd bytes at %p\n",
2033 		    MD_NAME, sc->unit, name, length, image);
2034 	} else {
2035 		printf("%s%d: Embedded image %zd bytes at %p\n",
2036 		    MD_NAME, sc->unit, length, image);
2037 	}
2038 }
2039 
2040 static void
2041 g_md_init(struct g_class *mp __unused)
2042 {
2043 	caddr_t mod;
2044 	u_char *ptr, *name, *type;
2045 	unsigned len;
2046 	int i;
2047 
2048 	/* figure out log2(NINDIR) */
2049 	for (i = NINDIR, nshift = -1; i; nshift++)
2050 		i >>= 1;
2051 
2052 	mod = NULL;
2053 	sx_init(&md_sx, "MD config lock");
2054 	g_topology_unlock();
2055 	md_uh = new_unrhdr(0, INT_MAX, NULL);
2056 #ifdef MD_ROOT
2057 	if (mfs_root_size != 0) {
2058 		sx_xlock(&md_sx);
2059 #ifdef MD_ROOT_MEM
2060 		md_preloaded(mfs_root, mfs_root_size, NULL);
2061 #else
2062 		md_preloaded(__DEVOLATILE(u_char *, &mfs_root), mfs_root_size,
2063 		    NULL);
2064 #endif
2065 		sx_xunlock(&md_sx);
2066 	}
2067 #endif
2068 	/* XXX: are preload_* static or do they need Giant ? */
2069 	while ((mod = preload_search_next_name(mod)) != NULL) {
2070 		name = (char *)preload_search_info(mod, MODINFO_NAME);
2071 		if (name == NULL)
2072 			continue;
2073 		type = (char *)preload_search_info(mod, MODINFO_TYPE);
2074 		if (type == NULL)
2075 			continue;
2076 		if (strcmp(type, "md_image") && strcmp(type, "mfs_root"))
2077 			continue;
2078 		ptr = preload_fetch_addr(mod);
2079 		len = preload_fetch_size(mod);
2080 		if (ptr != NULL && len != 0) {
2081 			sx_xlock(&md_sx);
2082 			md_preloaded(ptr, len, name);
2083 			sx_xunlock(&md_sx);
2084 		}
2085 	}
2086 	md_pbuf_zone = pbuf_zsecond_create("mdpbuf", nswbuf / 10);
2087 	status_dev = make_dev(&mdctl_cdevsw, INT_MAX, UID_ROOT, GID_WHEEL,
2088 	    0600, MDCTL_NAME);
2089 	g_topology_lock();
2090 }
2091 
2092 static void
2093 g_md_dumpconf(struct sbuf *sb, const char *indent, struct g_geom *gp,
2094     struct g_consumer *cp __unused, struct g_provider *pp)
2095 {
2096 	struct md_s *mp;
2097 	char *type;
2098 
2099 	mp = gp->softc;
2100 	if (mp == NULL)
2101 		return;
2102 
2103 	switch (mp->type) {
2104 	case MD_MALLOC:
2105 		type = "malloc";
2106 		break;
2107 	case MD_PRELOAD:
2108 		type = "preload";
2109 		break;
2110 	case MD_VNODE:
2111 		type = "vnode";
2112 		break;
2113 	case MD_SWAP:
2114 		type = "swap";
2115 		break;
2116 	case MD_NULL:
2117 		type = "null";
2118 		break;
2119 	default:
2120 		type = "unknown";
2121 		break;
2122 	}
2123 
2124 	if (pp != NULL) {
2125 		if (indent == NULL) {
2126 			sbuf_printf(sb, " u %d", mp->unit);
2127 			sbuf_printf(sb, " s %ju", (uintmax_t) mp->sectorsize);
2128 			sbuf_printf(sb, " f %ju", (uintmax_t) mp->fwheads);
2129 			sbuf_printf(sb, " fs %ju", (uintmax_t) mp->fwsectors);
2130 			sbuf_printf(sb, " l %ju", (uintmax_t) mp->mediasize);
2131 			sbuf_printf(sb, " t %s", type);
2132 			if ((mp->type == MD_VNODE && mp->vnode != NULL) ||
2133 			    (mp->type == MD_PRELOAD && mp->file[0] != '\0'))
2134 				sbuf_printf(sb, " file %s", mp->file);
2135 			sbuf_printf(sb, " label %s", mp->label);
2136 		} else {
2137 			sbuf_printf(sb, "%s<unit>%d</unit>\n", indent,
2138 			    mp->unit);
2139 			sbuf_printf(sb, "%s<sectorsize>%ju</sectorsize>\n",
2140 			    indent, (uintmax_t) mp->sectorsize);
2141 			sbuf_printf(sb, "%s<fwheads>%ju</fwheads>\n",
2142 			    indent, (uintmax_t) mp->fwheads);
2143 			sbuf_printf(sb, "%s<fwsectors>%ju</fwsectors>\n",
2144 			    indent, (uintmax_t) mp->fwsectors);
2145 			if (mp->ident[0] != '\0') {
2146 				sbuf_printf(sb, "%s<ident>", indent);
2147 				g_conf_printf_escaped(sb, "%s", mp->ident);
2148 				sbuf_printf(sb, "</ident>\n");
2149 			}
2150 			sbuf_printf(sb, "%s<length>%ju</length>\n",
2151 			    indent, (uintmax_t) mp->mediasize);
2152 			sbuf_printf(sb, "%s<compression>%s</compression>\n", indent,
2153 			    (mp->flags & MD_COMPRESS) == 0 ? "off": "on");
2154 			sbuf_printf(sb, "%s<access>%s</access>\n", indent,
2155 			    (mp->flags & MD_READONLY) == 0 ? "read-write":
2156 			    "read-only");
2157 			sbuf_printf(sb, "%s<type>%s</type>\n", indent,
2158 			    type);
2159 			if ((mp->type == MD_VNODE && mp->vnode != NULL) ||
2160 			    (mp->type == MD_PRELOAD && mp->file[0] != '\0')) {
2161 				sbuf_printf(sb, "%s<file>", indent);
2162 				g_conf_printf_escaped(sb, "%s", mp->file);
2163 				sbuf_printf(sb, "</file>\n");
2164 			}
2165 			if (mp->type == MD_VNODE)
2166 				sbuf_printf(sb, "%s<cache>%s</cache>\n", indent,
2167 				    (mp->flags & MD_CACHE) == 0 ? "off": "on");
2168 			sbuf_printf(sb, "%s<label>", indent);
2169 			g_conf_printf_escaped(sb, "%s", mp->label);
2170 			sbuf_printf(sb, "</label>\n");
2171 		}
2172 	}
2173 }
2174 
2175 static void
2176 g_md_fini(struct g_class *mp __unused)
2177 {
2178 
2179 	sx_destroy(&md_sx);
2180 	if (status_dev != NULL)
2181 		destroy_dev(status_dev);
2182 	uma_zdestroy(md_pbuf_zone);
2183 	delete_unrhdr(md_uh);
2184 }
2185