xref: /freebsd/sys/kern/uipc_sem.c (revision 993182e57ce25dc17114025bdaa1944b93817be6)
19454b2d8SWarner Losh /*-
2efaa6588SAlfred Perlstein  * Copyright (c) 2002 Alfred Perlstein <alfred@FreeBSD.org>
352648411SRobert Watson  * Copyright (c) 2003-2005 SPARTA, Inc.
4590f242cSRobert Watson  * Copyright (c) 2005 Robert N. M. Watson
5efaa6588SAlfred Perlstein  * All rights reserved.
6efaa6588SAlfred Perlstein  *
752648411SRobert Watson  * This software was developed for the FreeBSD Project in part by Network
852648411SRobert Watson  * Associates Laboratories, the Security Research Division of Network
952648411SRobert Watson  * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
1052648411SRobert Watson  * as part of the DARPA CHATS research program.
1152648411SRobert Watson  *
12efaa6588SAlfred Perlstein  * Redistribution and use in source and binary forms, with or without
13efaa6588SAlfred Perlstein  * modification, are permitted provided that the following conditions
14efaa6588SAlfred Perlstein  * are met:
15efaa6588SAlfred Perlstein  * 1. Redistributions of source code must retain the above copyright
16efaa6588SAlfred Perlstein  *    notice, this list of conditions and the following disclaimer.
17efaa6588SAlfred Perlstein  * 2. Redistributions in binary form must reproduce the above copyright
18efaa6588SAlfred Perlstein  *    notice, this list of conditions and the following disclaimer in the
19efaa6588SAlfred Perlstein  *    documentation and/or other materials provided with the distribution.
20efaa6588SAlfred Perlstein  *
21efaa6588SAlfred Perlstein  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
22efaa6588SAlfred Perlstein  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23efaa6588SAlfred Perlstein  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24efaa6588SAlfred Perlstein  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
25efaa6588SAlfred Perlstein  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26efaa6588SAlfred Perlstein  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27efaa6588SAlfred Perlstein  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28efaa6588SAlfred Perlstein  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29efaa6588SAlfred Perlstein  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30efaa6588SAlfred Perlstein  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31efaa6588SAlfred Perlstein  * SUCH DAMAGE.
32efaa6588SAlfred Perlstein  */
33efaa6588SAlfred Perlstein 
34677b542eSDavid E. O'Brien #include <sys/cdefs.h>
35677b542eSDavid E. O'Brien __FBSDID("$FreeBSD$");
36677b542eSDavid E. O'Brien 
3752648411SRobert Watson #include "opt_mac.h"
38efaa6588SAlfred Perlstein #include "opt_posix.h"
39efaa6588SAlfred Perlstein 
40efaa6588SAlfred Perlstein #include <sys/param.h>
41efaa6588SAlfred Perlstein #include <sys/systm.h>
42efaa6588SAlfred Perlstein #include <sys/sysproto.h>
4375b8b3b2SJohn Baldwin #include <sys/eventhandler.h>
44efaa6588SAlfred Perlstein #include <sys/kernel.h>
45efaa6588SAlfred Perlstein #include <sys/proc.h>
46efaa6588SAlfred Perlstein #include <sys/lock.h>
47efaa6588SAlfred Perlstein #include <sys/mutex.h>
4877409fe1SPoul-Henning Kamp #include <sys/module.h>
49efaa6588SAlfred Perlstein #include <sys/condvar.h>
50efaa6588SAlfred Perlstein #include <sys/sem.h>
51efaa6588SAlfred Perlstein #include <sys/uio.h>
52efaa6588SAlfred Perlstein #include <sys/syscall.h>
53efaa6588SAlfred Perlstein #include <sys/stat.h>
54efaa6588SAlfred Perlstein #include <sys/sysent.h>
55efaa6588SAlfred Perlstein #include <sys/sysctl.h>
56aae94fbbSDaniel Eischen #include <sys/time.h>
5752648411SRobert Watson #include <sys/mac.h>
58efaa6588SAlfred Perlstein #include <sys/malloc.h>
59efaa6588SAlfred Perlstein #include <sys/fcntl.h>
60efaa6588SAlfred Perlstein 
6197cce326SRobert Watson #include <posix4/ksem.h>
62efaa6588SAlfred Perlstein #include <posix4/posix4.h>
63efaa6588SAlfred Perlstein #include <posix4/semaphore.h>
64efaa6588SAlfred Perlstein #include <posix4/_semaphore.h>
65efaa6588SAlfred Perlstein 
66590f242cSRobert Watson static int sem_count_proc(struct proc *p);
67efaa6588SAlfred Perlstein static struct ksem *sem_lookup_byname(const char *name);
68efaa6588SAlfred Perlstein static int sem_create(struct thread *td, const char *name,
69efaa6588SAlfred Perlstein     struct ksem **ksret, mode_t mode, unsigned int value);
70efaa6588SAlfred Perlstein static void sem_free(struct ksem *ksnew);
71b2546660SJohn Baldwin static int sem_perm(struct thread *td, struct ksem *ks);
72efaa6588SAlfred Perlstein static void sem_enter(struct proc *p, struct ksem *ks);
73efaa6588SAlfred Perlstein static int sem_leave(struct proc *p, struct ksem *ks);
74993182e5SAlexander Leidinger static void sem_exechook(void *arg, struct proc *p, struct image_params *imgp);
7575b8b3b2SJohn Baldwin static void sem_exithook(void *arg, struct proc *p);
76590f242cSRobert Watson static void sem_forkhook(void *arg, struct proc *p1, struct proc *p2,
77590f242cSRobert Watson     int flags);
78b2546660SJohn Baldwin static int sem_hasopen(struct thread *td, struct ksem *ks);
79efaa6588SAlfred Perlstein 
80efaa6588SAlfred Perlstein static int kern_sem_close(struct thread *td, semid_t id);
81efaa6588SAlfred Perlstein static int kern_sem_post(struct thread *td, semid_t id);
82aae94fbbSDaniel Eischen static int kern_sem_wait(struct thread *td, semid_t id, int tryflag,
83aae94fbbSDaniel Eischen     struct timespec *abstime);
84efaa6588SAlfred Perlstein static int kern_sem_init(struct thread *td, int dir, unsigned int value,
85efaa6588SAlfred Perlstein     semid_t *idp);
86efaa6588SAlfred Perlstein static int kern_sem_open(struct thread *td, int dir, const char *name,
87efaa6588SAlfred Perlstein     int oflag, mode_t mode, unsigned int value, semid_t *idp);
88efaa6588SAlfred Perlstein static int kern_sem_unlink(struct thread *td, const char *name);
89efaa6588SAlfred Perlstein 
90efaa6588SAlfred Perlstein #ifndef SEM_MAX
91efaa6588SAlfred Perlstein #define SEM_MAX	30
92efaa6588SAlfred Perlstein #endif
93efaa6588SAlfred Perlstein 
94efaa6588SAlfred Perlstein #define SEM_MAX_NAMELEN	14
95efaa6588SAlfred Perlstein 
96efaa6588SAlfred Perlstein #define SEM_TO_ID(x)	((intptr_t)(x))
97efaa6588SAlfred Perlstein #define ID_TO_SEM(x)	id_to_sem(x)
98efaa6588SAlfred Perlstein 
99efaa6588SAlfred Perlstein /*
100efaa6588SAlfred Perlstein  * available semaphores go here, this includes sem_init and any semaphores
101efaa6588SAlfred Perlstein  * created via sem_open that have not yet been unlinked.
102efaa6588SAlfred Perlstein  */
103efaa6588SAlfred Perlstein LIST_HEAD(, ksem) ksem_head = LIST_HEAD_INITIALIZER(&ksem_head);
104efaa6588SAlfred Perlstein /*
105efaa6588SAlfred Perlstein  * semaphores still in use but have been sem_unlink()'d go here.
106efaa6588SAlfred Perlstein  */
107efaa6588SAlfred Perlstein LIST_HEAD(, ksem) ksem_deadhead = LIST_HEAD_INITIALIZER(&ksem_deadhead);
108efaa6588SAlfred Perlstein 
109efaa6588SAlfred Perlstein static struct mtx sem_lock;
110efaa6588SAlfred Perlstein static MALLOC_DEFINE(M_SEM, "sems", "semaphore data");
111efaa6588SAlfred Perlstein 
112efaa6588SAlfred Perlstein static int nsems = 0;
113efaa6588SAlfred Perlstein SYSCTL_DECL(_p1003_1b);
114efaa6588SAlfred Perlstein SYSCTL_INT(_p1003_1b, OID_AUTO, nsems, CTLFLAG_RD, &nsems, 0, "");
115efaa6588SAlfred Perlstein 
116590f242cSRobert Watson static eventhandler_tag sem_exit_tag, sem_exec_tag, sem_fork_tag;
11775b8b3b2SJohn Baldwin 
118c814aa3fSAlfred Perlstein #ifdef SEM_DEBUG
119c814aa3fSAlfred Perlstein #define DP(x)	printf x
120c814aa3fSAlfred Perlstein #else
121c814aa3fSAlfred Perlstein #define DP(x)
122c814aa3fSAlfred Perlstein #endif
123c814aa3fSAlfred Perlstein 
124efaa6588SAlfred Perlstein static __inline
125efaa6588SAlfred Perlstein void
126efaa6588SAlfred Perlstein sem_ref(struct ksem *ks)
127efaa6588SAlfred Perlstein {
128efaa6588SAlfred Perlstein 
1290fddf92dSRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
130efaa6588SAlfred Perlstein 	ks->ks_ref++;
131c814aa3fSAlfred Perlstein 	DP(("sem_ref: ks = %p, ref = %d\n", ks, ks->ks_ref));
132efaa6588SAlfred Perlstein }
133efaa6588SAlfred Perlstein 
134efaa6588SAlfred Perlstein static __inline
135efaa6588SAlfred Perlstein void
136efaa6588SAlfred Perlstein sem_rel(struct ksem *ks)
137efaa6588SAlfred Perlstein {
138efaa6588SAlfred Perlstein 
1390fddf92dSRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
140c814aa3fSAlfred Perlstein 	DP(("sem_rel: ks = %p, ref = %d\n", ks, ks->ks_ref - 1));
141efaa6588SAlfred Perlstein 	if (--ks->ks_ref == 0)
142efaa6588SAlfred Perlstein 		sem_free(ks);
143efaa6588SAlfred Perlstein }
144efaa6588SAlfred Perlstein 
145efaa6588SAlfred Perlstein static __inline struct ksem *id_to_sem(semid_t id);
146efaa6588SAlfred Perlstein 
147efaa6588SAlfred Perlstein static __inline
148efaa6588SAlfred Perlstein struct ksem *
149c1250af6SRobert Watson id_to_sem(semid_t id)
150efaa6588SAlfred Perlstein {
151efaa6588SAlfred Perlstein 	struct ksem *ks;
152efaa6588SAlfred Perlstein 
153955ec415SRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
154c814aa3fSAlfred Perlstein 	DP(("id_to_sem: id = %0x,%p\n", id, (struct ksem *)id));
155efaa6588SAlfred Perlstein 	LIST_FOREACH(ks, &ksem_head, ks_entry) {
156c814aa3fSAlfred Perlstein 		DP(("id_to_sem: ks = %p\n", ks));
157efaa6588SAlfred Perlstein 		if (ks == (struct ksem *)id)
158efaa6588SAlfred Perlstein 			return (ks);
159efaa6588SAlfred Perlstein 	}
160efaa6588SAlfred Perlstein 	return (NULL);
161efaa6588SAlfred Perlstein }
162efaa6588SAlfred Perlstein 
163c3053131SPoul-Henning Kamp static struct ksem *
164c1250af6SRobert Watson sem_lookup_byname(const char *name)
165efaa6588SAlfred Perlstein {
166efaa6588SAlfred Perlstein 	struct ksem *ks;
167efaa6588SAlfred Perlstein 
168955ec415SRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
169efaa6588SAlfred Perlstein 	LIST_FOREACH(ks, &ksem_head, ks_entry)
170efaa6588SAlfred Perlstein 		if (ks->ks_name != NULL && strcmp(ks->ks_name, name) == 0)
171efaa6588SAlfred Perlstein 			return (ks);
172efaa6588SAlfred Perlstein 	return (NULL);
173efaa6588SAlfred Perlstein }
174efaa6588SAlfred Perlstein 
175c3053131SPoul-Henning Kamp static int
176c1250af6SRobert Watson sem_create(struct thread *td, const char *name, struct ksem **ksret,
177c1250af6SRobert Watson     mode_t mode, unsigned int value)
178efaa6588SAlfred Perlstein {
179efaa6588SAlfred Perlstein 	struct ksem *ret;
180efaa6588SAlfred Perlstein 	struct proc *p;
181efaa6588SAlfred Perlstein 	struct ucred *uc;
182efaa6588SAlfred Perlstein 	size_t len;
183efaa6588SAlfred Perlstein 	int error;
184efaa6588SAlfred Perlstein 
185c814aa3fSAlfred Perlstein 	DP(("sem_create\n"));
186efaa6588SAlfred Perlstein 	p = td->td_proc;
187b2546660SJohn Baldwin 	uc = td->td_ucred;
188efaa6588SAlfred Perlstein 	if (value > SEM_VALUE_MAX)
189efaa6588SAlfred Perlstein 		return (EINVAL);
190a163d034SWarner Losh 	ret = malloc(sizeof(*ret), M_SEM, M_WAITOK | M_ZERO);
191efaa6588SAlfred Perlstein 	if (name != NULL) {
192efaa6588SAlfred Perlstein 		len = strlen(name);
193efaa6588SAlfred Perlstein 		if (len > SEM_MAX_NAMELEN) {
194efaa6588SAlfred Perlstein 			free(ret, M_SEM);
195efaa6588SAlfred Perlstein 			return (ENAMETOOLONG);
196efaa6588SAlfred Perlstein 		}
197efaa6588SAlfred Perlstein 		/* name must start with a '/' but not contain one. */
198efaa6588SAlfred Perlstein 		if (*name != '/' || len < 2 || index(name + 1, '/') != NULL) {
199efaa6588SAlfred Perlstein 			free(ret, M_SEM);
200efaa6588SAlfred Perlstein 			return (EINVAL);
201efaa6588SAlfred Perlstein 		}
202a163d034SWarner Losh 		ret->ks_name = malloc(len + 1, M_SEM, M_WAITOK);
203efaa6588SAlfred Perlstein 		strcpy(ret->ks_name, name);
204efaa6588SAlfred Perlstein 	} else {
205efaa6588SAlfred Perlstein 		ret->ks_name = NULL;
206efaa6588SAlfred Perlstein 	}
207efaa6588SAlfred Perlstein 	ret->ks_mode = mode;
208efaa6588SAlfred Perlstein 	ret->ks_value = value;
209efaa6588SAlfred Perlstein 	ret->ks_ref = 1;
210efaa6588SAlfred Perlstein 	ret->ks_waiters = 0;
211efaa6588SAlfred Perlstein 	ret->ks_uid = uc->cr_uid;
212efaa6588SAlfred Perlstein 	ret->ks_gid = uc->cr_gid;
213efaa6588SAlfred Perlstein 	ret->ks_onlist = 0;
214efaa6588SAlfred Perlstein 	cv_init(&ret->ks_cv, "sem");
215efaa6588SAlfred Perlstein 	LIST_INIT(&ret->ks_users);
21652648411SRobert Watson #ifdef MAC
21752648411SRobert Watson 	mac_init_posix_sem(ret);
21852648411SRobert Watson 	mac_create_posix_sem(uc, ret);
21952648411SRobert Watson #endif
220efaa6588SAlfred Perlstein 	if (name != NULL)
221efaa6588SAlfred Perlstein 		sem_enter(td->td_proc, ret);
222efaa6588SAlfred Perlstein 	*ksret = ret;
223efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
224efaa6588SAlfred Perlstein 	if (nsems >= p31b_getcfg(CTL_P1003_1B_SEM_NSEMS_MAX)) {
225efaa6588SAlfred Perlstein 		sem_leave(td->td_proc, ret);
226efaa6588SAlfred Perlstein 		sem_free(ret);
227efaa6588SAlfred Perlstein 		error = ENFILE;
228efaa6588SAlfred Perlstein 	} else {
229efaa6588SAlfred Perlstein 		nsems++;
230efaa6588SAlfred Perlstein 		error = 0;
231efaa6588SAlfred Perlstein 	}
232efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
233efaa6588SAlfred Perlstein 	return (error);
234efaa6588SAlfred Perlstein }
235efaa6588SAlfred Perlstein 
236efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
237efaa6588SAlfred Perlstein struct ksem_init_args {
238efaa6588SAlfred Perlstein 	unsigned int value;
239efaa6588SAlfred Perlstein 	semid_t *idp;
240efaa6588SAlfred Perlstein };
241efaa6588SAlfred Perlstein int ksem_init(struct thread *td, struct ksem_init_args *uap);
242efaa6588SAlfred Perlstein #endif
243efaa6588SAlfred Perlstein int
244c1250af6SRobert Watson ksem_init(struct thread *td, struct ksem_init_args *uap)
245efaa6588SAlfred Perlstein {
246efaa6588SAlfred Perlstein 	int error;
247efaa6588SAlfred Perlstein 
248efaa6588SAlfred Perlstein 	error = kern_sem_init(td, UIO_USERSPACE, uap->value, uap->idp);
249efaa6588SAlfred Perlstein 	return (error);
250efaa6588SAlfred Perlstein }
251efaa6588SAlfred Perlstein 
252efaa6588SAlfred Perlstein static int
253c1250af6SRobert Watson kern_sem_init(struct thread *td, int dir, unsigned int value, semid_t *idp)
254efaa6588SAlfred Perlstein {
255efaa6588SAlfred Perlstein 	struct ksem *ks;
256efaa6588SAlfred Perlstein 	semid_t id;
257efaa6588SAlfred Perlstein 	int error;
258efaa6588SAlfred Perlstein 
259efaa6588SAlfred Perlstein 	error = sem_create(td, NULL, &ks, S_IRWXU | S_IRWXG, value);
260efaa6588SAlfred Perlstein 	if (error)
261efaa6588SAlfred Perlstein 		return (error);
262efaa6588SAlfred Perlstein 	id = SEM_TO_ID(ks);
263efaa6588SAlfred Perlstein 	if (dir == UIO_USERSPACE) {
264efaa6588SAlfred Perlstein 		error = copyout(&id, idp, sizeof(id));
265efaa6588SAlfred Perlstein 		if (error) {
266efaa6588SAlfred Perlstein 			mtx_lock(&sem_lock);
267efaa6588SAlfred Perlstein 			sem_rel(ks);
268efaa6588SAlfred Perlstein 			mtx_unlock(&sem_lock);
269efaa6588SAlfred Perlstein 			return (error);
270efaa6588SAlfred Perlstein 		}
271efaa6588SAlfred Perlstein 	} else {
272efaa6588SAlfred Perlstein 		*idp = id;
273efaa6588SAlfred Perlstein 	}
274efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
275efaa6588SAlfred Perlstein 	LIST_INSERT_HEAD(&ksem_head, ks, ks_entry);
276efaa6588SAlfred Perlstein 	ks->ks_onlist = 1;
277efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
278efaa6588SAlfred Perlstein 	return (error);
279efaa6588SAlfred Perlstein }
280efaa6588SAlfred Perlstein 
281efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
282efaa6588SAlfred Perlstein struct ksem_open_args {
283efaa6588SAlfred Perlstein 	char *name;
284efaa6588SAlfred Perlstein 	int oflag;
285efaa6588SAlfred Perlstein 	mode_t mode;
286efaa6588SAlfred Perlstein 	unsigned int value;
287efaa6588SAlfred Perlstein 	semid_t *idp;
288efaa6588SAlfred Perlstein };
289efaa6588SAlfred Perlstein int ksem_open(struct thread *td, struct ksem_open_args *uap);
290efaa6588SAlfred Perlstein #endif
291efaa6588SAlfred Perlstein int
292c1250af6SRobert Watson ksem_open(struct thread *td, struct ksem_open_args *uap)
293efaa6588SAlfred Perlstein {
294efaa6588SAlfred Perlstein 	char name[SEM_MAX_NAMELEN + 1];
295efaa6588SAlfred Perlstein 	size_t done;
296efaa6588SAlfred Perlstein 	int error;
297efaa6588SAlfred Perlstein 
298efaa6588SAlfred Perlstein 	error = copyinstr(uap->name, name, SEM_MAX_NAMELEN + 1, &done);
299efaa6588SAlfred Perlstein 	if (error)
300efaa6588SAlfred Perlstein 		return (error);
301c814aa3fSAlfred Perlstein 	DP((">>> sem_open start\n"));
302efaa6588SAlfred Perlstein 	error = kern_sem_open(td, UIO_USERSPACE,
303efaa6588SAlfred Perlstein 	    name, uap->oflag, uap->mode, uap->value, uap->idp);
304c814aa3fSAlfred Perlstein 	DP(("<<< sem_open end\n"));
305efaa6588SAlfred Perlstein 	return (error);
306efaa6588SAlfred Perlstein }
307efaa6588SAlfred Perlstein 
308efaa6588SAlfred Perlstein static int
309c1250af6SRobert Watson kern_sem_open(struct thread *td, int dir, const char *name, int oflag,
310c1250af6SRobert Watson     mode_t mode, unsigned int value, semid_t *idp)
311efaa6588SAlfred Perlstein {
312efaa6588SAlfred Perlstein 	struct ksem *ksnew, *ks;
313efaa6588SAlfred Perlstein 	int error;
314efaa6588SAlfred Perlstein 	semid_t id;
315efaa6588SAlfred Perlstein 
316efaa6588SAlfred Perlstein 	ksnew = NULL;
317efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
318efaa6588SAlfred Perlstein 	ks = sem_lookup_byname(name);
319efaa6588SAlfred Perlstein 	/*
320efaa6588SAlfred Perlstein 	 * If we found it but O_EXCL is set, error.
321efaa6588SAlfred Perlstein 	 */
322efaa6588SAlfred Perlstein 	if (ks != NULL && (oflag & O_EXCL) != 0) {
323efaa6588SAlfred Perlstein 		mtx_unlock(&sem_lock);
324efaa6588SAlfred Perlstein 		return (EEXIST);
325efaa6588SAlfred Perlstein 	}
326efaa6588SAlfred Perlstein 	/*
327efaa6588SAlfred Perlstein 	 * If we didn't find it...
328efaa6588SAlfred Perlstein 	 */
329efaa6588SAlfred Perlstein 	if (ks == NULL) {
330efaa6588SAlfred Perlstein 		/*
331efaa6588SAlfred Perlstein 		 * didn't ask for creation? error.
332efaa6588SAlfred Perlstein 		 */
333efaa6588SAlfred Perlstein 		if ((oflag & O_CREAT) == 0) {
334efaa6588SAlfred Perlstein 			mtx_unlock(&sem_lock);
335efaa6588SAlfred Perlstein 			return (ENOENT);
336efaa6588SAlfred Perlstein 		}
337efaa6588SAlfred Perlstein 		/*
338efaa6588SAlfred Perlstein 		 * We may block during creation, so drop the lock.
339efaa6588SAlfred Perlstein 		 */
340efaa6588SAlfred Perlstein 		mtx_unlock(&sem_lock);
341efaa6588SAlfred Perlstein 		error = sem_create(td, name, &ksnew, mode, value);
342efaa6588SAlfred Perlstein 		if (error != 0)
343efaa6588SAlfred Perlstein 			return (error);
344efaa6588SAlfred Perlstein 		id = SEM_TO_ID(ksnew);
345efaa6588SAlfred Perlstein 		if (dir == UIO_USERSPACE) {
346c814aa3fSAlfred Perlstein 			DP(("about to copyout! %d to %p\n", id, idp));
347efaa6588SAlfred Perlstein 			error = copyout(&id, idp, sizeof(id));
348efaa6588SAlfred Perlstein 			if (error) {
349efaa6588SAlfred Perlstein 				mtx_lock(&sem_lock);
350efaa6588SAlfred Perlstein 				sem_leave(td->td_proc, ksnew);
351efaa6588SAlfred Perlstein 				sem_rel(ksnew);
352efaa6588SAlfred Perlstein 				mtx_unlock(&sem_lock);
353efaa6588SAlfred Perlstein 				return (error);
354efaa6588SAlfred Perlstein 			}
355efaa6588SAlfred Perlstein 		} else {
356c814aa3fSAlfred Perlstein 			DP(("about to set! %d to %p\n", id, idp));
357efaa6588SAlfred Perlstein 			*idp = id;
358efaa6588SAlfred Perlstein 		}
359efaa6588SAlfred Perlstein 		/*
360efaa6588SAlfred Perlstein 		 * We need to make sure we haven't lost a race while
361efaa6588SAlfred Perlstein 		 * allocating during creation.
362efaa6588SAlfred Perlstein 		 */
363efaa6588SAlfred Perlstein 		mtx_lock(&sem_lock);
364efaa6588SAlfred Perlstein 		ks = sem_lookup_byname(name);
365efaa6588SAlfred Perlstein 		if (ks != NULL) {
366efaa6588SAlfred Perlstein 			/* we lost... */
367efaa6588SAlfred Perlstein 			sem_leave(td->td_proc, ksnew);
368efaa6588SAlfred Perlstein 			sem_rel(ksnew);
369efaa6588SAlfred Perlstein 			/* we lost and we can't loose... */
370efaa6588SAlfred Perlstein 			if ((oflag & O_EXCL) != 0) {
371efaa6588SAlfred Perlstein 				mtx_unlock(&sem_lock);
372efaa6588SAlfred Perlstein 				return (EEXIST);
373efaa6588SAlfred Perlstein 			}
374efaa6588SAlfred Perlstein 		} else {
375c814aa3fSAlfred Perlstein 			DP(("sem_create: about to add to list...\n"));
376efaa6588SAlfred Perlstein 			LIST_INSERT_HEAD(&ksem_head, ksnew, ks_entry);
377c814aa3fSAlfred Perlstein 			DP(("sem_create: setting list bit...\n"));
378efaa6588SAlfred Perlstein 			ksnew->ks_onlist = 1;
379c814aa3fSAlfred Perlstein 			DP(("sem_create: done, about to unlock...\n"));
380efaa6588SAlfred Perlstein 		}
381efaa6588SAlfred Perlstein 	} else {
38252648411SRobert Watson #ifdef MAC
38352648411SRobert Watson 		error = mac_check_posix_sem_open(td->td_ucred, ks);
38452648411SRobert Watson 		if (error)
38552648411SRobert Watson 			goto err_open;
38652648411SRobert Watson #endif
387efaa6588SAlfred Perlstein 		/*
388efaa6588SAlfred Perlstein 		 * if we aren't the creator, then enforce permissions.
389efaa6588SAlfred Perlstein 		 */
390b2546660SJohn Baldwin 		error = sem_perm(td, ks);
39152648411SRobert Watson 		if (error)
39252648411SRobert Watson 			goto err_open;
393efaa6588SAlfred Perlstein 		sem_ref(ks);
394efaa6588SAlfred Perlstein 		mtx_unlock(&sem_lock);
395efaa6588SAlfred Perlstein 		id = SEM_TO_ID(ks);
396efaa6588SAlfred Perlstein 		if (dir == UIO_USERSPACE) {
397efaa6588SAlfred Perlstein 			error = copyout(&id, idp, sizeof(id));
398efaa6588SAlfred Perlstein 			if (error) {
399efaa6588SAlfred Perlstein 				mtx_lock(&sem_lock);
400efaa6588SAlfred Perlstein 				sem_rel(ks);
401efaa6588SAlfred Perlstein 				mtx_unlock(&sem_lock);
402efaa6588SAlfred Perlstein 				return (error);
403efaa6588SAlfred Perlstein 			}
404efaa6588SAlfred Perlstein 		} else {
405efaa6588SAlfred Perlstein 			*idp = id;
406efaa6588SAlfred Perlstein 		}
407efaa6588SAlfred Perlstein 		sem_enter(td->td_proc, ks);
408efaa6588SAlfred Perlstein 		mtx_lock(&sem_lock);
409efaa6588SAlfred Perlstein 		sem_rel(ks);
410efaa6588SAlfred Perlstein 	}
41152648411SRobert Watson err_open:
41252648411SRobert Watson 	mtx_unlock(&sem_lock);
413efaa6588SAlfred Perlstein 	return (error);
414efaa6588SAlfred Perlstein }
415efaa6588SAlfred Perlstein 
416c3053131SPoul-Henning Kamp static int
417c1250af6SRobert Watson sem_perm(struct thread *td, struct ksem *ks)
418efaa6588SAlfred Perlstein {
419efaa6588SAlfred Perlstein 	struct ucred *uc;
420efaa6588SAlfred Perlstein 
421b2546660SJohn Baldwin 	uc = td->td_ucred;
422c814aa3fSAlfred Perlstein 	DP(("sem_perm: uc(%d,%d) ks(%d,%d,%o)\n",
423efaa6588SAlfred Perlstein 	    uc->cr_uid, uc->cr_gid,
424c814aa3fSAlfred Perlstein 	     ks->ks_uid, ks->ks_gid, ks->ks_mode));
425efaa6588SAlfred Perlstein 	if ((uc->cr_uid == ks->ks_uid && (ks->ks_mode & S_IWUSR) != 0) ||
426efaa6588SAlfred Perlstein 	    (uc->cr_gid == ks->ks_gid && (ks->ks_mode & S_IWGRP) != 0) ||
427b2546660SJohn Baldwin 	    (ks->ks_mode & S_IWOTH) != 0 || suser(td) == 0)
428efaa6588SAlfred Perlstein 		return (0);
429efaa6588SAlfred Perlstein 	return (EPERM);
430efaa6588SAlfred Perlstein }
431efaa6588SAlfred Perlstein 
432c3053131SPoul-Henning Kamp static void
433efaa6588SAlfred Perlstein sem_free(struct ksem *ks)
434efaa6588SAlfred Perlstein {
435efaa6588SAlfred Perlstein 
436efaa6588SAlfred Perlstein 	nsems--;
437efaa6588SAlfred Perlstein 	if (ks->ks_onlist)
438efaa6588SAlfred Perlstein 		LIST_REMOVE(ks, ks_entry);
439efaa6588SAlfred Perlstein 	if (ks->ks_name != NULL)
440efaa6588SAlfred Perlstein 		free(ks->ks_name, M_SEM);
441efaa6588SAlfred Perlstein 	cv_destroy(&ks->ks_cv);
442efaa6588SAlfred Perlstein 	free(ks, M_SEM);
443efaa6588SAlfred Perlstein }
444efaa6588SAlfred Perlstein 
445efaa6588SAlfred Perlstein static __inline struct kuser *sem_getuser(struct proc *p, struct ksem *ks);
446efaa6588SAlfred Perlstein 
447efaa6588SAlfred Perlstein static __inline struct kuser *
448c1250af6SRobert Watson sem_getuser(struct proc *p, struct ksem *ks)
449efaa6588SAlfred Perlstein {
450efaa6588SAlfred Perlstein 	struct kuser *k;
451efaa6588SAlfred Perlstein 
452efaa6588SAlfred Perlstein 	LIST_FOREACH(k, &ks->ks_users, ku_next)
453efaa6588SAlfred Perlstein 		if (k->ku_pid == p->p_pid)
454efaa6588SAlfred Perlstein 			return (k);
455efaa6588SAlfred Perlstein 	return (NULL);
456efaa6588SAlfred Perlstein }
457efaa6588SAlfred Perlstein 
458c3053131SPoul-Henning Kamp static int
459c1250af6SRobert Watson sem_hasopen(struct thread *td, struct ksem *ks)
460efaa6588SAlfred Perlstein {
461efaa6588SAlfred Perlstein 
462aae94fbbSDaniel Eischen 	return ((ks->ks_name == NULL && sem_perm(td, ks) == 0)
463b2546660SJohn Baldwin 	    || sem_getuser(td->td_proc, ks) != NULL);
464efaa6588SAlfred Perlstein }
465efaa6588SAlfred Perlstein 
466c3053131SPoul-Henning Kamp static int
467c1250af6SRobert Watson sem_leave(struct proc *p, struct ksem *ks)
468efaa6588SAlfred Perlstein {
469efaa6588SAlfred Perlstein 	struct kuser *k;
470efaa6588SAlfred Perlstein 
471c814aa3fSAlfred Perlstein 	DP(("sem_leave: ks = %p\n", ks));
472efaa6588SAlfred Perlstein 	k = sem_getuser(p, ks);
473c814aa3fSAlfred Perlstein 	DP(("sem_leave: ks = %p, k = %p\n", ks, k));
474efaa6588SAlfred Perlstein 	if (k != NULL) {
475efaa6588SAlfred Perlstein 		LIST_REMOVE(k, ku_next);
476efaa6588SAlfred Perlstein 		sem_rel(ks);
477c814aa3fSAlfred Perlstein 		DP(("sem_leave: about to free k\n"));
478efaa6588SAlfred Perlstein 		free(k, M_SEM);
479c814aa3fSAlfred Perlstein 		DP(("sem_leave: returning\n"));
480efaa6588SAlfred Perlstein 		return (0);
481efaa6588SAlfred Perlstein 	}
482b3890a1cSAlfred Perlstein 	return (EINVAL);
483efaa6588SAlfred Perlstein }
484efaa6588SAlfred Perlstein 
485c3053131SPoul-Henning Kamp static void
486efaa6588SAlfred Perlstein sem_enter(p, ks)
487efaa6588SAlfred Perlstein 	struct proc *p;
488efaa6588SAlfred Perlstein 	struct ksem *ks;
489efaa6588SAlfred Perlstein {
490efaa6588SAlfred Perlstein 	struct kuser *ku, *k;
491efaa6588SAlfred Perlstein 
492a163d034SWarner Losh 	ku = malloc(sizeof(*ku), M_SEM, M_WAITOK);
493efaa6588SAlfred Perlstein 	ku->ku_pid = p->p_pid;
494efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
495efaa6588SAlfred Perlstein 	k = sem_getuser(p, ks);
496efaa6588SAlfred Perlstein 	if (k != NULL) {
497efaa6588SAlfred Perlstein 		mtx_unlock(&sem_lock);
498efaa6588SAlfred Perlstein 		free(ku, M_TEMP);
499efaa6588SAlfred Perlstein 		return;
500efaa6588SAlfred Perlstein 	}
501efaa6588SAlfred Perlstein 	LIST_INSERT_HEAD(&ks->ks_users, ku, ku_next);
502efaa6588SAlfred Perlstein 	sem_ref(ks);
503efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
504efaa6588SAlfred Perlstein }
505efaa6588SAlfred Perlstein 
506efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
507efaa6588SAlfred Perlstein struct ksem_unlink_args {
508efaa6588SAlfred Perlstein 	char *name;
509efaa6588SAlfred Perlstein };
510efaa6588SAlfred Perlstein int ksem_unlink(struct thread *td, struct ksem_unlink_args *uap);
511efaa6588SAlfred Perlstein #endif
512efaa6588SAlfred Perlstein 
513efaa6588SAlfred Perlstein int
514c1250af6SRobert Watson ksem_unlink(struct thread *td, struct ksem_unlink_args *uap)
515efaa6588SAlfred Perlstein {
516efaa6588SAlfred Perlstein 	char name[SEM_MAX_NAMELEN + 1];
517efaa6588SAlfred Perlstein 	size_t done;
518efaa6588SAlfred Perlstein 	int error;
519efaa6588SAlfred Perlstein 
520efaa6588SAlfred Perlstein 	error = copyinstr(uap->name, name, SEM_MAX_NAMELEN + 1, &done);
521efaa6588SAlfred Perlstein 	return (error ? error :
522efaa6588SAlfred Perlstein 	    kern_sem_unlink(td, name));
523efaa6588SAlfred Perlstein }
524efaa6588SAlfred Perlstein 
525efaa6588SAlfred Perlstein static int
526c1250af6SRobert Watson kern_sem_unlink(struct thread *td, const char *name)
527efaa6588SAlfred Perlstein {
528efaa6588SAlfred Perlstein 	struct ksem *ks;
529efaa6588SAlfred Perlstein 	int error;
530efaa6588SAlfred Perlstein 
531efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
532efaa6588SAlfred Perlstein 	ks = sem_lookup_byname(name);
53352648411SRobert Watson 	if (ks != NULL) {
53452648411SRobert Watson #ifdef MAC
53552648411SRobert Watson 		error = mac_check_posix_sem_unlink(td->td_ucred, ks);
53652648411SRobert Watson 		if (error) {
53752648411SRobert Watson 			mtx_unlock(&sem_lock);
53852648411SRobert Watson 			return (error);
53952648411SRobert Watson 		}
54052648411SRobert Watson #endif
541b2546660SJohn Baldwin 		error = sem_perm(td, ks);
54252648411SRobert Watson 	} else
54352648411SRobert Watson 		error = ENOENT;
544c814aa3fSAlfred Perlstein 	DP(("sem_unlink: '%s' ks = %p, error = %d\n", name, ks, error));
545efaa6588SAlfred Perlstein 	if (error == 0) {
546efaa6588SAlfred Perlstein 		LIST_REMOVE(ks, ks_entry);
547efaa6588SAlfred Perlstein 		LIST_INSERT_HEAD(&ksem_deadhead, ks, ks_entry);
548efaa6588SAlfred Perlstein 		sem_rel(ks);
549efaa6588SAlfred Perlstein 	}
550efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
551efaa6588SAlfred Perlstein 	return (error);
552efaa6588SAlfred Perlstein }
553efaa6588SAlfred Perlstein 
554efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
555efaa6588SAlfred Perlstein struct ksem_close_args {
556efaa6588SAlfred Perlstein 	semid_t id;
557efaa6588SAlfred Perlstein };
558efaa6588SAlfred Perlstein int ksem_close(struct thread *td, struct ksem_close_args *uap);
559efaa6588SAlfred Perlstein #endif
560efaa6588SAlfred Perlstein 
561efaa6588SAlfred Perlstein int
562efaa6588SAlfred Perlstein ksem_close(struct thread *td, struct ksem_close_args *uap)
563efaa6588SAlfred Perlstein {
564efaa6588SAlfred Perlstein 
565efaa6588SAlfred Perlstein 	return (kern_sem_close(td, uap->id));
566efaa6588SAlfred Perlstein }
567efaa6588SAlfred Perlstein 
568c3053131SPoul-Henning Kamp static int
569c1250af6SRobert Watson kern_sem_close(struct thread *td, semid_t id)
570efaa6588SAlfred Perlstein {
571efaa6588SAlfred Perlstein 	struct ksem *ks;
572efaa6588SAlfred Perlstein 	int error;
573efaa6588SAlfred Perlstein 
574efaa6588SAlfred Perlstein 	error = EINVAL;
575efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
576efaa6588SAlfred Perlstein 	ks = ID_TO_SEM(id);
577efaa6588SAlfred Perlstein 	/* this is not a valid operation for unnamed sems */
578efaa6588SAlfred Perlstein 	if (ks != NULL && ks->ks_name != NULL)
579b3890a1cSAlfred Perlstein 		error = sem_leave(td->td_proc, ks);
580efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
581b3890a1cSAlfred Perlstein 	return (error);
582efaa6588SAlfred Perlstein }
583efaa6588SAlfred Perlstein 
584efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
585efaa6588SAlfred Perlstein struct ksem_post_args {
586efaa6588SAlfred Perlstein 	semid_t id;
587efaa6588SAlfred Perlstein };
588efaa6588SAlfred Perlstein int ksem_post(struct thread *td, struct ksem_post_args *uap);
589efaa6588SAlfred Perlstein #endif
590efaa6588SAlfred Perlstein int
591c1250af6SRobert Watson ksem_post(struct thread *td, struct ksem_post_args *uap)
592efaa6588SAlfred Perlstein {
593efaa6588SAlfred Perlstein 
594efaa6588SAlfred Perlstein 	return (kern_sem_post(td, uap->id));
595efaa6588SAlfred Perlstein }
596efaa6588SAlfred Perlstein 
597c3053131SPoul-Henning Kamp static int
598c1250af6SRobert Watson kern_sem_post(struct thread *td, semid_t id)
599efaa6588SAlfred Perlstein {
600efaa6588SAlfred Perlstein 	struct ksem *ks;
601efaa6588SAlfred Perlstein 	int error;
602efaa6588SAlfred Perlstein 
603efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
604efaa6588SAlfred Perlstein 	ks = ID_TO_SEM(id);
605b2546660SJohn Baldwin 	if (ks == NULL || !sem_hasopen(td, ks)) {
606efaa6588SAlfred Perlstein 		error = EINVAL;
607efaa6588SAlfred Perlstein 		goto err;
608efaa6588SAlfred Perlstein 	}
60952648411SRobert Watson #ifdef MAC
61052648411SRobert Watson 	error = mac_check_posix_sem_post(td->td_ucred, ks);
61152648411SRobert Watson 	if (error)
61252648411SRobert Watson 		goto err;
61352648411SRobert Watson #endif
614efaa6588SAlfred Perlstein 	if (ks->ks_value == SEM_VALUE_MAX) {
615efaa6588SAlfred Perlstein 		error = EOVERFLOW;
616efaa6588SAlfred Perlstein 		goto err;
617efaa6588SAlfred Perlstein 	}
618efaa6588SAlfred Perlstein 	++ks->ks_value;
619efaa6588SAlfred Perlstein 	if (ks->ks_waiters > 0)
620efaa6588SAlfred Perlstein 		cv_signal(&ks->ks_cv);
621efaa6588SAlfred Perlstein 	error = 0;
622efaa6588SAlfred Perlstein err:
623efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
624efaa6588SAlfred Perlstein 	return (error);
625efaa6588SAlfred Perlstein }
626efaa6588SAlfred Perlstein 
627efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
628efaa6588SAlfred Perlstein struct ksem_wait_args {
629efaa6588SAlfred Perlstein 	semid_t id;
630efaa6588SAlfred Perlstein };
631efaa6588SAlfred Perlstein int ksem_wait(struct thread *td, struct ksem_wait_args *uap);
632efaa6588SAlfred Perlstein #endif
633efaa6588SAlfred Perlstein 
634efaa6588SAlfred Perlstein int
635c1250af6SRobert Watson ksem_wait(struct thread *td, struct ksem_wait_args *uap)
636efaa6588SAlfred Perlstein {
637efaa6588SAlfred Perlstein 
638aae94fbbSDaniel Eischen 	return (kern_sem_wait(td, uap->id, 0, NULL));
639aae94fbbSDaniel Eischen }
640aae94fbbSDaniel Eischen 
641aae94fbbSDaniel Eischen #ifndef _SYS_SYSPROTO_H_
642aae94fbbSDaniel Eischen struct ksem_timedwait_args {
643aae94fbbSDaniel Eischen 	semid_t id;
644d60e86c8SStefan Farfeleder 	const struct timespec *abstime;
645aae94fbbSDaniel Eischen };
646aae94fbbSDaniel Eischen int ksem_timedwait(struct thread *td, struct ksem_timedwait_args *uap);
647aae94fbbSDaniel Eischen #endif
648aae94fbbSDaniel Eischen int
649c1250af6SRobert Watson ksem_timedwait(struct thread *td, struct ksem_timedwait_args *uap)
650aae94fbbSDaniel Eischen {
651aae94fbbSDaniel Eischen 	struct timespec abstime;
652aae94fbbSDaniel Eischen 	struct timespec *ts;
653aae94fbbSDaniel Eischen 	int error;
654aae94fbbSDaniel Eischen 
655aae94fbbSDaniel Eischen 	/* We allow a null timespec (wait forever). */
656aae94fbbSDaniel Eischen 	if (uap->abstime == NULL)
657aae94fbbSDaniel Eischen 		ts = NULL;
658aae94fbbSDaniel Eischen 	else {
659aae94fbbSDaniel Eischen 		error = copyin(uap->abstime, &abstime, sizeof(abstime));
660aae94fbbSDaniel Eischen 		if (error != 0)
661aae94fbbSDaniel Eischen 			return (error);
662aae94fbbSDaniel Eischen 		if (abstime.tv_nsec >= 1000000000 || abstime.tv_nsec < 0)
663aae94fbbSDaniel Eischen 			return (EINVAL);
664aae94fbbSDaniel Eischen 		ts = &abstime;
665aae94fbbSDaniel Eischen 	}
666aae94fbbSDaniel Eischen 	return (kern_sem_wait(td, uap->id, 0, ts));
667efaa6588SAlfred Perlstein }
668efaa6588SAlfred Perlstein 
669efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
670efaa6588SAlfred Perlstein struct ksem_trywait_args {
671efaa6588SAlfred Perlstein 	semid_t id;
672efaa6588SAlfred Perlstein };
673efaa6588SAlfred Perlstein int ksem_trywait(struct thread *td, struct ksem_trywait_args *uap);
674efaa6588SAlfred Perlstein #endif
675efaa6588SAlfred Perlstein int
676c1250af6SRobert Watson ksem_trywait(struct thread *td, struct ksem_trywait_args *uap)
677efaa6588SAlfred Perlstein {
678efaa6588SAlfred Perlstein 
679aae94fbbSDaniel Eischen 	return (kern_sem_wait(td, uap->id, 1, NULL));
680efaa6588SAlfred Perlstein }
681efaa6588SAlfred Perlstein 
682c3053131SPoul-Henning Kamp static int
683c1250af6SRobert Watson kern_sem_wait(struct thread *td, semid_t id, int tryflag,
684c1250af6SRobert Watson     struct timespec *abstime)
685efaa6588SAlfred Perlstein {
686aae94fbbSDaniel Eischen 	struct timespec ts1, ts2;
687aae94fbbSDaniel Eischen 	struct timeval tv;
688efaa6588SAlfred Perlstein 	struct ksem *ks;
689efaa6588SAlfred Perlstein 	int error;
690efaa6588SAlfred Perlstein 
691c814aa3fSAlfred Perlstein 	DP((">>> kern_sem_wait entered!\n"));
692efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
693efaa6588SAlfred Perlstein 	ks = ID_TO_SEM(id);
694efaa6588SAlfred Perlstein 	if (ks == NULL) {
695c814aa3fSAlfred Perlstein 		DP(("kern_sem_wait ks == NULL\n"));
696efaa6588SAlfred Perlstein 		error = EINVAL;
697efaa6588SAlfred Perlstein 		goto err;
698efaa6588SAlfred Perlstein 	}
699efaa6588SAlfred Perlstein 	sem_ref(ks);
700b2546660SJohn Baldwin 	if (!sem_hasopen(td, ks)) {
701c814aa3fSAlfred Perlstein 		DP(("kern_sem_wait hasopen failed\n"));
702efaa6588SAlfred Perlstein 		error = EINVAL;
703efaa6588SAlfred Perlstein 		goto err;
704efaa6588SAlfred Perlstein 	}
70552648411SRobert Watson #ifdef MAC
70652648411SRobert Watson 	error = mac_check_posix_sem_wait(td->td_ucred, ks);
70752648411SRobert Watson 	if (error) {
70852648411SRobert Watson 		DP(("kern_sem_wait mac failed\n"));
70952648411SRobert Watson 		goto err;
71052648411SRobert Watson 	}
71152648411SRobert Watson #endif
712c814aa3fSAlfred Perlstein 	DP(("kern_sem_wait value = %d, tryflag %d\n", ks->ks_value, tryflag));
713efaa6588SAlfred Perlstein 	if (ks->ks_value == 0) {
714efaa6588SAlfred Perlstein 		ks->ks_waiters++;
715aae94fbbSDaniel Eischen 		if (tryflag != 0)
716aae94fbbSDaniel Eischen 			error = EAGAIN;
717aae94fbbSDaniel Eischen 		else if (abstime == NULL)
718aae94fbbSDaniel Eischen 			error = cv_wait_sig(&ks->ks_cv, &sem_lock);
719aae94fbbSDaniel Eischen 		else {
720aae94fbbSDaniel Eischen 			for (;;) {
721aae94fbbSDaniel Eischen 				ts1 = *abstime;
722aae94fbbSDaniel Eischen 				getnanotime(&ts2);
723aae94fbbSDaniel Eischen 				timespecsub(&ts1, &ts2);
724aae94fbbSDaniel Eischen 				TIMESPEC_TO_TIMEVAL(&tv, &ts1);
725aae94fbbSDaniel Eischen 				if (tv.tv_sec < 0) {
726aae94fbbSDaniel Eischen 					error = ETIMEDOUT;
727aae94fbbSDaniel Eischen 					break;
728aae94fbbSDaniel Eischen 				}
729aae94fbbSDaniel Eischen 				error = cv_timedwait_sig(&ks->ks_cv,
730aae94fbbSDaniel Eischen 				    &sem_lock, tvtohz(&tv));
731aae94fbbSDaniel Eischen 				if (error != EWOULDBLOCK)
732aae94fbbSDaniel Eischen 					break;
733aae94fbbSDaniel Eischen 			}
734aae94fbbSDaniel Eischen 		}
735efaa6588SAlfred Perlstein 		ks->ks_waiters--;
736efaa6588SAlfred Perlstein 		if (error)
737efaa6588SAlfred Perlstein 			goto err;
738efaa6588SAlfred Perlstein 	}
739efaa6588SAlfred Perlstein 	ks->ks_value--;
740efaa6588SAlfred Perlstein 	error = 0;
741efaa6588SAlfred Perlstein err:
742efaa6588SAlfred Perlstein 	if (ks != NULL)
743efaa6588SAlfred Perlstein 		sem_rel(ks);
744efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
745c814aa3fSAlfred Perlstein 	DP(("<<< kern_sem_wait leaving, error = %d\n", error));
746efaa6588SAlfred Perlstein 	return (error);
747efaa6588SAlfred Perlstein }
748efaa6588SAlfred Perlstein 
749efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
750efaa6588SAlfred Perlstein struct ksem_getvalue_args {
751efaa6588SAlfred Perlstein 	semid_t id;
752efaa6588SAlfred Perlstein 	int *val;
753efaa6588SAlfred Perlstein };
754efaa6588SAlfred Perlstein int ksem_getvalue(struct thread *td, struct ksem_getvalue_args *uap);
755efaa6588SAlfred Perlstein #endif
756efaa6588SAlfred Perlstein int
757c1250af6SRobert Watson ksem_getvalue(struct thread *td, struct ksem_getvalue_args *uap)
758efaa6588SAlfred Perlstein {
759efaa6588SAlfred Perlstein 	struct ksem *ks;
760efaa6588SAlfred Perlstein 	int error, val;
761efaa6588SAlfred Perlstein 
762efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
763efaa6588SAlfred Perlstein 	ks = ID_TO_SEM(uap->id);
764b2546660SJohn Baldwin 	if (ks == NULL || !sem_hasopen(td, ks)) {
765efaa6588SAlfred Perlstein 		mtx_unlock(&sem_lock);
766efaa6588SAlfred Perlstein 		return (EINVAL);
767efaa6588SAlfred Perlstein 	}
76852648411SRobert Watson #ifdef MAC
76952648411SRobert Watson 	error = mac_check_posix_sem_getvalue(td->td_ucred, ks);
77052648411SRobert Watson 	if (error) {
77152648411SRobert Watson 		mtx_unlock(&sem_lock);
77252648411SRobert Watson 		return (error);
77352648411SRobert Watson 	}
77452648411SRobert Watson #endif
775efaa6588SAlfred Perlstein 	val = ks->ks_value;
776efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
777efaa6588SAlfred Perlstein 	error = copyout(&val, uap->val, sizeof(val));
778efaa6588SAlfred Perlstein 	return (error);
779efaa6588SAlfred Perlstein }
780efaa6588SAlfred Perlstein 
781efaa6588SAlfred Perlstein #ifndef _SYS_SYSPROTO_H_
782efaa6588SAlfred Perlstein struct ksem_destroy_args {
783efaa6588SAlfred Perlstein 	semid_t id;
784efaa6588SAlfred Perlstein };
785efaa6588SAlfred Perlstein int ksem_destroy(struct thread *td, struct ksem_destroy_args *uap);
786efaa6588SAlfred Perlstein #endif
787efaa6588SAlfred Perlstein int
788c1250af6SRobert Watson ksem_destroy(struct thread *td, struct ksem_destroy_args *uap)
789efaa6588SAlfred Perlstein {
790efaa6588SAlfred Perlstein 	struct ksem *ks;
791efaa6588SAlfred Perlstein 	int error;
792efaa6588SAlfred Perlstein 
793efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
794efaa6588SAlfred Perlstein 	ks = ID_TO_SEM(uap->id);
795b2546660SJohn Baldwin 	if (ks == NULL || !sem_hasopen(td, ks) ||
796efaa6588SAlfred Perlstein 	    ks->ks_name != NULL) {
797efaa6588SAlfred Perlstein 		error = EINVAL;
798efaa6588SAlfred Perlstein 		goto err;
799efaa6588SAlfred Perlstein 	}
80052648411SRobert Watson #ifdef MAC
80152648411SRobert Watson 	error = mac_check_posix_sem_destroy(td->td_ucred, ks);
80252648411SRobert Watson 	if (error)
80352648411SRobert Watson 		goto err;
80452648411SRobert Watson #endif
805efaa6588SAlfred Perlstein 	if (ks->ks_waiters != 0) {
806efaa6588SAlfred Perlstein 		error = EBUSY;
807efaa6588SAlfred Perlstein 		goto err;
808efaa6588SAlfred Perlstein 	}
809efaa6588SAlfred Perlstein 	sem_rel(ks);
810efaa6588SAlfred Perlstein 	error = 0;
811efaa6588SAlfred Perlstein err:
812efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
813efaa6588SAlfred Perlstein 	return (error);
814efaa6588SAlfred Perlstein }
815efaa6588SAlfred Perlstein 
816590f242cSRobert Watson /*
817590f242cSRobert Watson  * Count the number of kusers associated with a proc, so as to guess at how
818590f242cSRobert Watson  * many to allocate when forking.
819590f242cSRobert Watson  */
820590f242cSRobert Watson static int
821c1250af6SRobert Watson sem_count_proc(struct proc *p)
822590f242cSRobert Watson {
823590f242cSRobert Watson 	struct ksem *ks;
824590f242cSRobert Watson 	struct kuser *ku;
825590f242cSRobert Watson 	int count;
826590f242cSRobert Watson 
827590f242cSRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
828590f242cSRobert Watson 
829590f242cSRobert Watson 	count = 0;
830590f242cSRobert Watson 	LIST_FOREACH(ks, &ksem_head, ks_entry) {
831590f242cSRobert Watson 		LIST_FOREACH(ku, &ks->ks_users, ku_next) {
832590f242cSRobert Watson 			if (ku->ku_pid == p->p_pid)
833590f242cSRobert Watson 				count++;
834590f242cSRobert Watson 		}
835590f242cSRobert Watson 	}
836590f242cSRobert Watson 	LIST_FOREACH(ks, &ksem_deadhead, ks_entry) {
837590f242cSRobert Watson 		LIST_FOREACH(ku, &ks->ks_users, ku_next) {
838590f242cSRobert Watson 			if (ku->ku_pid == p->p_pid)
839590f242cSRobert Watson 				count++;
840590f242cSRobert Watson 		}
841590f242cSRobert Watson 	}
842590f242cSRobert Watson 	return (count);
843590f242cSRobert Watson }
844590f242cSRobert Watson 
845590f242cSRobert Watson /*
846590f242cSRobert Watson  * When a process forks, the child process must gain a reference to each open
847590f242cSRobert Watson  * semaphore in the parent process, whether it is unlinked or not.  This
848590f242cSRobert Watson  * requires allocating a kuser structure for each semaphore reference in the
849590f242cSRobert Watson  * new process.  Because the set of semaphores in the parent can change while
850590f242cSRobert Watson  * the fork is in progress, we have to handle races -- first we attempt to
851590f242cSRobert Watson  * allocate enough storage to acquire references to each of the semaphores,
852590f242cSRobert Watson  * then we enter the semaphores and release the temporary references.
853590f242cSRobert Watson  */
854590f242cSRobert Watson static void
855c1250af6SRobert Watson sem_forkhook(void *arg, struct proc *p1, struct proc *p2, int flags)
856590f242cSRobert Watson {
857590f242cSRobert Watson 	struct ksem *ks, **sem_array;
858590f242cSRobert Watson 	int count, i, new_count;
859590f242cSRobert Watson 	struct kuser *ku;
860590f242cSRobert Watson 
861590f242cSRobert Watson 	mtx_lock(&sem_lock);
862590f242cSRobert Watson 	count = sem_count_proc(p1);
863e2f7a83dSRobert Watson 	if (count == 0) {
864e2f7a83dSRobert Watson 		mtx_unlock(&sem_lock);
865e2f7a83dSRobert Watson 		return;
866e2f7a83dSRobert Watson 	}
867590f242cSRobert Watson race_lost:
868590f242cSRobert Watson 	mtx_assert(&sem_lock, MA_OWNED);
869590f242cSRobert Watson 	mtx_unlock(&sem_lock);
870590f242cSRobert Watson 	sem_array = malloc(sizeof(struct ksem *) * count, M_TEMP, M_WAITOK);
871590f242cSRobert Watson 	mtx_lock(&sem_lock);
872590f242cSRobert Watson 	new_count = sem_count_proc(p1);
873590f242cSRobert Watson 	if (count < new_count) {
874590f242cSRobert Watson 		/* Lost race, repeat and allocate more storage. */
875590f242cSRobert Watson 		free(sem_array, M_TEMP);
876590f242cSRobert Watson 		count = new_count;
877590f242cSRobert Watson 		goto race_lost;
878590f242cSRobert Watson 	}
879590f242cSRobert Watson 	/*
880590f242cSRobert Watson 	 * Given an array capable of storing an adequate number of semaphore
881590f242cSRobert Watson 	 * references, now walk the list of semaphores and acquire a new
882590f242cSRobert Watson 	 * reference for any semaphore opened by p1.
883590f242cSRobert Watson 	 */
884590f242cSRobert Watson 	count = new_count;
885590f242cSRobert Watson 	i = 0;
886590f242cSRobert Watson 	LIST_FOREACH(ks, &ksem_head, ks_entry) {
887590f242cSRobert Watson 		LIST_FOREACH(ku, &ks->ks_users, ku_next) {
888590f242cSRobert Watson 			if (ku->ku_pid == p1->p_pid) {
889590f242cSRobert Watson 				sem_ref(ks);
890590f242cSRobert Watson 				sem_array[i] = ks;
891fa6fc5b8SRobert Watson 				i++;
892590f242cSRobert Watson 				break;
893590f242cSRobert Watson 			}
894590f242cSRobert Watson 		}
895590f242cSRobert Watson 	}
896590f242cSRobert Watson 	LIST_FOREACH(ks, &ksem_deadhead, ks_entry) {
897590f242cSRobert Watson 		LIST_FOREACH(ku, &ks->ks_users, ku_next) {
898590f242cSRobert Watson 			if (ku->ku_pid == p1->p_pid) {
899590f242cSRobert Watson 				sem_ref(ks);
900590f242cSRobert Watson 				sem_array[i] = ks;
901fa6fc5b8SRobert Watson 				i++;
902590f242cSRobert Watson 				break;
903590f242cSRobert Watson 			}
904590f242cSRobert Watson 		}
905590f242cSRobert Watson 	}
906590f242cSRobert Watson 	mtx_unlock(&sem_lock);
907fa6fc5b8SRobert Watson 	KASSERT(i == count, ("sem_forkhook: i != count (%d, %d)", i, count));
908590f242cSRobert Watson 	/*
909590f242cSRobert Watson 	 * Now cause p2 to enter each of the referenced semaphores, then
910590f242cSRobert Watson 	 * release our temporary reference.  This is pretty inefficient.
911590f242cSRobert Watson 	 * Finally, free our temporary array.
912590f242cSRobert Watson 	 */
913590f242cSRobert Watson 	for (i = 0; i < count; i++) {
914590f242cSRobert Watson 		sem_enter(p2, sem_array[i]);
915590f242cSRobert Watson 		mtx_lock(&sem_lock);
916590f242cSRobert Watson 		sem_rel(sem_array[i]);
917590f242cSRobert Watson 		mtx_unlock(&sem_lock);
918590f242cSRobert Watson 	}
919590f242cSRobert Watson 	free(sem_array, M_TEMP);
920590f242cSRobert Watson }
921590f242cSRobert Watson 
922c3053131SPoul-Henning Kamp static void
923993182e5SAlexander Leidinger sem_exithook(void *arg, struct proc *p, struct image_params *imgp __unused)
924993182e5SAlexander Leidinger {
925993182e5SAlexander Leidinger    	sem_exechook(arg, p);
926993182e5SAlexander Leidinger }
927993182e5SAlexander Leidinger 
928993182e5SAlexander Leidinger static void
929993182e5SAlexander Leidinger sem_exechook(void *arg, struct proc *p)
930efaa6588SAlfred Perlstein {
931efaa6588SAlfred Perlstein 	struct ksem *ks, *ksnext;
932efaa6588SAlfred Perlstein 
933efaa6588SAlfred Perlstein 	mtx_lock(&sem_lock);
934efaa6588SAlfred Perlstein 	ks = LIST_FIRST(&ksem_head);
935efaa6588SAlfred Perlstein 	while (ks != NULL) {
936efaa6588SAlfred Perlstein 		ksnext = LIST_NEXT(ks, ks_entry);
937efaa6588SAlfred Perlstein 		sem_leave(p, ks);
938efaa6588SAlfred Perlstein 		ks = ksnext;
939efaa6588SAlfred Perlstein 	}
940efaa6588SAlfred Perlstein 	ks = LIST_FIRST(&ksem_deadhead);
941efaa6588SAlfred Perlstein 	while (ks != NULL) {
942efaa6588SAlfred Perlstein 		ksnext = LIST_NEXT(ks, ks_entry);
943efaa6588SAlfred Perlstein 		sem_leave(p, ks);
944efaa6588SAlfred Perlstein 		ks = ksnext;
945efaa6588SAlfred Perlstein 	}
946efaa6588SAlfred Perlstein 	mtx_unlock(&sem_lock);
947efaa6588SAlfred Perlstein }
948efaa6588SAlfred Perlstein 
949efaa6588SAlfred Perlstein static int
950efaa6588SAlfred Perlstein sem_modload(struct module *module, int cmd, void *arg)
951efaa6588SAlfred Perlstein {
952efaa6588SAlfred Perlstein         int error = 0;
953efaa6588SAlfred Perlstein 
954efaa6588SAlfred Perlstein         switch (cmd) {
955efaa6588SAlfred Perlstein         case MOD_LOAD:
956efaa6588SAlfred Perlstein 		mtx_init(&sem_lock, "sem", "semaphore", MTX_DEF);
957efaa6588SAlfred Perlstein 		p31b_setcfg(CTL_P1003_1B_SEM_NSEMS_MAX, SEM_MAX);
958efaa6588SAlfred Perlstein 		p31b_setcfg(CTL_P1003_1B_SEM_VALUE_MAX, SEM_VALUE_MAX);
95975b8b3b2SJohn Baldwin 		sem_exit_tag = EVENTHANDLER_REGISTER(process_exit, sem_exithook,
96075b8b3b2SJohn Baldwin 		    NULL, EVENTHANDLER_PRI_ANY);
96175b8b3b2SJohn Baldwin 		sem_exec_tag = EVENTHANDLER_REGISTER(process_exec, sem_exithook,
96275b8b3b2SJohn Baldwin 		    NULL, EVENTHANDLER_PRI_ANY);
963590f242cSRobert Watson 		sem_fork_tag = EVENTHANDLER_REGISTER(process_fork, sem_forkhook, NULL, EVENTHANDLER_PRI_ANY);
964efaa6588SAlfred Perlstein                 break;
965efaa6588SAlfred Perlstein         case MOD_UNLOAD:
966efaa6588SAlfred Perlstein 		if (nsems != 0) {
967efaa6588SAlfred Perlstein 			error = EOPNOTSUPP;
968efaa6588SAlfred Perlstein 			break;
969efaa6588SAlfred Perlstein 		}
97075b8b3b2SJohn Baldwin 		EVENTHANDLER_DEREGISTER(process_exit, sem_exit_tag);
97175b8b3b2SJohn Baldwin 		EVENTHANDLER_DEREGISTER(process_exec, sem_exec_tag);
972590f242cSRobert Watson 		EVENTHANDLER_DEREGISTER(process_fork, sem_fork_tag);
973efaa6588SAlfred Perlstein 		mtx_destroy(&sem_lock);
974efaa6588SAlfred Perlstein                 break;
975efaa6588SAlfred Perlstein         case MOD_SHUTDOWN:
976efaa6588SAlfred Perlstein                 break;
977efaa6588SAlfred Perlstein         default:
978efaa6588SAlfred Perlstein                 error = EINVAL;
979efaa6588SAlfred Perlstein                 break;
980efaa6588SAlfred Perlstein         }
981efaa6588SAlfred Perlstein         return (error);
982efaa6588SAlfred Perlstein }
983efaa6588SAlfred Perlstein 
984efaa6588SAlfred Perlstein static moduledata_t sem_mod = {
985efaa6588SAlfred Perlstein         "sem",
986efaa6588SAlfred Perlstein         &sem_modload,
987efaa6588SAlfred Perlstein         NULL
988efaa6588SAlfred Perlstein };
989efaa6588SAlfred Perlstein 
990efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_init);
991efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_open);
992efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_unlink);
993efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_close);
994efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_post);
995efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_wait);
996aae94fbbSDaniel Eischen SYSCALL_MODULE_HELPER(ksem_timedwait);
997efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_trywait);
998efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_getvalue);
999efaa6588SAlfred Perlstein SYSCALL_MODULE_HELPER(ksem_destroy);
1000efaa6588SAlfred Perlstein 
1001efaa6588SAlfred Perlstein DECLARE_MODULE(sem, sem_mod, SI_SUB_SYSV_SEM, SI_ORDER_FIRST);
1002efaa6588SAlfred Perlstein MODULE_VERSION(sem, 1);
1003