xref: /freebsd/sys/kern/uipc_sem.c (revision 9fd69f37d28cfd7438cac3eeb45fe9dd46b4d7dd)
1 /*-
2  * Copyright (c) 2002 Alfred Perlstein <alfred@FreeBSD.org>
3  * Copyright (c) 2003-2005 SPARTA, Inc.
4  * Copyright (c) 2005 Robert N. M. Watson
5  * All rights reserved.
6  *
7  * This software was developed for the FreeBSD Project in part by Network
8  * Associates Laboratories, the Security Research Division of Network
9  * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
10  * as part of the DARPA CHATS research program.
11  *
12  * Redistribution and use in source and binary forms, with or without
13  * modification, are permitted provided that the following conditions
14  * are met:
15  * 1. Redistributions of source code must retain the above copyright
16  *    notice, this list of conditions and the following disclaimer.
17  * 2. Redistributions in binary form must reproduce the above copyright
18  *    notice, this list of conditions and the following disclaimer in the
19  *    documentation and/or other materials provided with the distribution.
20  *
21  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
25  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  */
33 
34 #include <sys/cdefs.h>
35 __FBSDID("$FreeBSD$");
36 
37 #include "opt_posix.h"
38 
39 #include <sys/param.h>
40 #include <sys/condvar.h>
41 #include <sys/fcntl.h>
42 #include <sys/file.h>
43 #include <sys/filedesc.h>
44 #include <sys/fnv_hash.h>
45 #include <sys/kernel.h>
46 #include <sys/ksem.h>
47 #include <sys/lock.h>
48 #include <sys/malloc.h>
49 #include <sys/module.h>
50 #include <sys/mutex.h>
51 #include <sys/priv.h>
52 #include <sys/proc.h>
53 #include <sys/posix4.h>
54 #include <sys/_semaphore.h>
55 #include <sys/stat.h>
56 #include <sys/syscall.h>
57 #include <sys/syscallsubr.h>
58 #include <sys/sysctl.h>
59 #include <sys/sysent.h>
60 #include <sys/sysproto.h>
61 #include <sys/systm.h>
62 #include <sys/sx.h>
63 #include <sys/vnode.h>
64 
65 #include <security/mac/mac_framework.h>
66 
67 /*
68  * TODO
69  *
70  * - Resource limits?
71  * - Update fstat(1)
72  * - Replace global sem_lock with mtx_pool locks?
73  * - Add a MAC check_create() hook for creating new named semaphores.
74  */
75 
76 #ifndef SEM_MAX
77 #define	SEM_MAX	30
78 #endif
79 
80 #ifdef SEM_DEBUG
81 #define	DP(x)	printf x
82 #else
83 #define	DP(x)
84 #endif
85 
86 struct ksem_mapping {
87 	char		*km_path;
88 	Fnv32_t		km_fnv;
89 	struct ksem	*km_ksem;
90 	LIST_ENTRY(ksem_mapping) km_link;
91 };
92 
93 static MALLOC_DEFINE(M_KSEM, "ksem", "semaphore file descriptor");
94 static LIST_HEAD(, ksem_mapping) *ksem_dictionary;
95 static struct sx ksem_dict_lock;
96 static struct mtx ksem_count_lock;
97 static struct mtx sem_lock;
98 static u_long ksem_hash;
99 static int ksem_dead;
100 
101 #define	KSEM_HASH(fnv)	(&ksem_dictionary[(fnv) & ksem_hash])
102 
103 static int nsems = 0;
104 SYSCTL_DECL(_p1003_1b);
105 SYSCTL_INT(_p1003_1b, OID_AUTO, nsems, CTLFLAG_RD, &nsems, 0,
106     "Number of active kernel POSIX semaphores");
107 
108 static int	kern_sem_wait(struct thread *td, semid_t id, int tryflag,
109 		    struct timespec *abstime);
110 static int	ksem_access(struct ksem *ks, struct ucred *ucred);
111 static struct ksem *ksem_alloc(struct ucred *ucred, mode_t mode,
112 		    unsigned int value);
113 static int	ksem_create(struct thread *td, const char *path,
114 		    semid_t *semidp, mode_t mode, unsigned int value,
115 		    int flags);
116 static void	ksem_drop(struct ksem *ks);
117 static int	ksem_get(struct thread *td, semid_t id, struct file **fpp);
118 static struct ksem *ksem_hold(struct ksem *ks);
119 static void	ksem_insert(char *path, Fnv32_t fnv, struct ksem *ks);
120 static struct ksem *ksem_lookup(char *path, Fnv32_t fnv);
121 static void	ksem_module_destroy(void);
122 static int	ksem_module_init(void);
123 static int	ksem_remove(char *path, Fnv32_t fnv, struct ucred *ucred);
124 static int	sem_modload(struct module *module, int cmd, void *arg);
125 
126 static fo_rdwr_t	ksem_read;
127 static fo_rdwr_t	ksem_write;
128 static fo_truncate_t	ksem_truncate;
129 static fo_ioctl_t	ksem_ioctl;
130 static fo_poll_t	ksem_poll;
131 static fo_kqfilter_t	ksem_kqfilter;
132 static fo_stat_t	ksem_stat;
133 static fo_close_t	ksem_closef;
134 
135 /* File descriptor operations. */
136 static struct fileops ksem_ops = {
137 	.fo_read = ksem_read,
138 	.fo_write = ksem_write,
139 	.fo_truncate = ksem_truncate,
140 	.fo_ioctl = ksem_ioctl,
141 	.fo_poll = ksem_poll,
142 	.fo_kqfilter = ksem_kqfilter,
143 	.fo_stat = ksem_stat,
144 	.fo_close = ksem_closef,
145 	.fo_flags = DFLAG_PASSABLE
146 };
147 
148 FEATURE(posix_sem, "POSIX semaphores");
149 
150 static int
151 ksem_read(struct file *fp, struct uio *uio, struct ucred *active_cred,
152     int flags, struct thread *td)
153 {
154 
155 	return (EOPNOTSUPP);
156 }
157 
158 static int
159 ksem_write(struct file *fp, struct uio *uio, struct ucred *active_cred,
160     int flags, struct thread *td)
161 {
162 
163 	return (EOPNOTSUPP);
164 }
165 
166 static int
167 ksem_truncate(struct file *fp, off_t length, struct ucred *active_cred,
168     struct thread *td)
169 {
170 
171 	return (EINVAL);
172 }
173 
174 static int
175 ksem_ioctl(struct file *fp, u_long com, void *data,
176     struct ucred *active_cred, struct thread *td)
177 {
178 
179 	return (EOPNOTSUPP);
180 }
181 
182 static int
183 ksem_poll(struct file *fp, int events, struct ucred *active_cred,
184     struct thread *td)
185 {
186 
187 	return (EOPNOTSUPP);
188 }
189 
190 static int
191 ksem_kqfilter(struct file *fp, struct knote *kn)
192 {
193 
194 	return (EOPNOTSUPP);
195 }
196 
197 static int
198 ksem_stat(struct file *fp, struct stat *sb, struct ucred *active_cred,
199     struct thread *td)
200 {
201 	struct ksem *ks;
202 #ifdef MAC
203 	int error;
204 #endif
205 
206 	ks = fp->f_data;
207 
208 #ifdef MAC
209 	error = mac_posixsem_check_stat(active_cred, fp->f_cred, ks);
210 	if (error)
211 		return (error);
212 #endif
213 
214 	/*
215 	 * Attempt to return sanish values for fstat() on a semaphore
216 	 * file descriptor.
217 	 */
218 	bzero(sb, sizeof(*sb));
219 	sb->st_mode = S_IFREG | ks->ks_mode;		/* XXX */
220 
221 	sb->st_atimespec = ks->ks_atime;
222 	sb->st_ctimespec = ks->ks_ctime;
223 	sb->st_mtimespec = ks->ks_mtime;
224 	sb->st_birthtimespec = ks->ks_birthtime;
225 	sb->st_uid = ks->ks_uid;
226 	sb->st_gid = ks->ks_gid;
227 
228 	return (0);
229 }
230 
231 static int
232 ksem_closef(struct file *fp, struct thread *td)
233 {
234 	struct ksem *ks;
235 
236 	ks = fp->f_data;
237 	fp->f_data = NULL;
238 	ksem_drop(ks);
239 
240 	return (0);
241 }
242 
243 /*
244  * ksem object management including creation and reference counting
245  * routines.
246  */
247 static struct ksem *
248 ksem_alloc(struct ucred *ucred, mode_t mode, unsigned int value)
249 {
250 	struct ksem *ks;
251 
252 	mtx_lock(&ksem_count_lock);
253 	if (nsems == p31b_getcfg(CTL_P1003_1B_SEM_NSEMS_MAX) || ksem_dead) {
254 		mtx_unlock(&ksem_count_lock);
255 		return (NULL);
256 	}
257 	nsems++;
258 	mtx_unlock(&ksem_count_lock);
259 	ks = malloc(sizeof(*ks), M_KSEM, M_WAITOK | M_ZERO);
260 	ks->ks_uid = ucred->cr_uid;
261 	ks->ks_gid = ucred->cr_gid;
262 	ks->ks_mode = mode;
263 	ks->ks_value = value;
264 	cv_init(&ks->ks_cv, "ksem");
265 	vfs_timestamp(&ks->ks_birthtime);
266 	ks->ks_atime = ks->ks_mtime = ks->ks_ctime = ks->ks_birthtime;
267 	refcount_init(&ks->ks_ref, 1);
268 #ifdef MAC
269 	mac_posixsem_init(ks);
270 	mac_posixsem_create(ucred, ks);
271 #endif
272 
273 	return (ks);
274 }
275 
276 static struct ksem *
277 ksem_hold(struct ksem *ks)
278 {
279 
280 	refcount_acquire(&ks->ks_ref);
281 	return (ks);
282 }
283 
284 static void
285 ksem_drop(struct ksem *ks)
286 {
287 
288 	if (refcount_release(&ks->ks_ref)) {
289 #ifdef MAC
290 		mac_posixsem_destroy(ks);
291 #endif
292 		cv_destroy(&ks->ks_cv);
293 		free(ks, M_KSEM);
294 		mtx_lock(&ksem_count_lock);
295 		nsems--;
296 		mtx_unlock(&ksem_count_lock);
297 	}
298 }
299 
300 /*
301  * Determine if the credentials have sufficient permissions for read
302  * and write access.
303  */
304 static int
305 ksem_access(struct ksem *ks, struct ucred *ucred)
306 {
307 	int error;
308 
309 	error = vaccess(VREG, ks->ks_mode, ks->ks_uid, ks->ks_gid,
310 	    VREAD | VWRITE, ucred, NULL);
311 	if (error)
312 		error = priv_check_cred(ucred, PRIV_SEM_WRITE, 0);
313 	return (error);
314 }
315 
316 /*
317  * Dictionary management.  We maintain an in-kernel dictionary to map
318  * paths to semaphore objects.  We use the FNV hash on the path to
319  * store the mappings in a hash table.
320  */
321 static struct ksem *
322 ksem_lookup(char *path, Fnv32_t fnv)
323 {
324 	struct ksem_mapping *map;
325 
326 	LIST_FOREACH(map, KSEM_HASH(fnv), km_link) {
327 		if (map->km_fnv != fnv)
328 			continue;
329 		if (strcmp(map->km_path, path) == 0)
330 			return (map->km_ksem);
331 	}
332 
333 	return (NULL);
334 }
335 
336 static void
337 ksem_insert(char *path, Fnv32_t fnv, struct ksem *ks)
338 {
339 	struct ksem_mapping *map;
340 
341 	map = malloc(sizeof(struct ksem_mapping), M_KSEM, M_WAITOK);
342 	map->km_path = path;
343 	map->km_fnv = fnv;
344 	map->km_ksem = ksem_hold(ks);
345 	LIST_INSERT_HEAD(KSEM_HASH(fnv), map, km_link);
346 }
347 
348 static int
349 ksem_remove(char *path, Fnv32_t fnv, struct ucred *ucred)
350 {
351 	struct ksem_mapping *map;
352 	int error;
353 
354 	LIST_FOREACH(map, KSEM_HASH(fnv), km_link) {
355 		if (map->km_fnv != fnv)
356 			continue;
357 		if (strcmp(map->km_path, path) == 0) {
358 #ifdef MAC
359 			error = mac_posixsem_check_unlink(ucred, map->km_ksem);
360 			if (error)
361 				return (error);
362 #endif
363 			error = ksem_access(map->km_ksem, ucred);
364 			if (error)
365 				return (error);
366 			LIST_REMOVE(map, km_link);
367 			ksem_drop(map->km_ksem);
368 			free(map->km_path, M_KSEM);
369 			free(map, M_KSEM);
370 			return (0);
371 		}
372 	}
373 
374 	return (ENOENT);
375 }
376 
377 /* Other helper routines. */
378 static int
379 ksem_create(struct thread *td, const char *name, semid_t *semidp, mode_t mode,
380     unsigned int value, int flags)
381 {
382 	struct filedesc *fdp;
383 	struct ksem *ks;
384 	struct file *fp;
385 	char *path;
386 	semid_t semid;
387 	Fnv32_t fnv;
388 	int error, fd;
389 
390 	if (value > SEM_VALUE_MAX)
391 		return (EINVAL);
392 
393 	fdp = td->td_proc->p_fd;
394 	mode = (mode & ~fdp->fd_cmask) & ACCESSPERMS;
395 	error = falloc(td, &fp, &fd);
396 	if (error) {
397 		if (name == NULL)
398 			error = ENOSPC;
399 		return (error);
400 	}
401 
402 	/*
403 	 * Go ahead and copyout the file descriptor now.  This is a bit
404 	 * premature, but it is a lot easier to handle errors as opposed
405 	 * to later when we've possibly created a new semaphore, etc.
406 	 */
407 	semid = fd;
408 	error = copyout(&semid, semidp, sizeof(semid));
409 	if (error) {
410 		fdclose(fdp, fp, fd, td);
411 		fdrop(fp, td);
412 		return (error);
413 	}
414 
415 	if (name == NULL) {
416 		/* Create an anonymous semaphore. */
417 		ks = ksem_alloc(td->td_ucred, mode, value);
418 		if (ks == NULL)
419 			error = ENOSPC;
420 		else
421 			ks->ks_flags |= KS_ANONYMOUS;
422 	} else {
423 		path = malloc(MAXPATHLEN, M_KSEM, M_WAITOK);
424 		error = copyinstr(name, path, MAXPATHLEN, NULL);
425 
426 		/* Require paths to start with a '/' character. */
427 		if (error == 0 && path[0] != '/')
428 			error = EINVAL;
429 		if (error) {
430 			fdclose(fdp, fp, fd, td);
431 			fdrop(fp, td);
432 			free(path, M_KSEM);
433 			return (error);
434 		}
435 
436 		fnv = fnv_32_str(path, FNV1_32_INIT);
437 		sx_xlock(&ksem_dict_lock);
438 		ks = ksem_lookup(path, fnv);
439 		if (ks == NULL) {
440 			/* Object does not exist, create it if requested. */
441 			if (flags & O_CREAT) {
442 				ks = ksem_alloc(td->td_ucred, mode, value);
443 				if (ks == NULL)
444 					error = ENFILE;
445 				else {
446 					ksem_insert(path, fnv, ks);
447 					path = NULL;
448 				}
449 			} else
450 				error = ENOENT;
451 		} else {
452 			/*
453 			 * Object already exists, obtain a new
454 			 * reference if requested and permitted.
455 			 */
456 			if ((flags & (O_CREAT | O_EXCL)) ==
457 			    (O_CREAT | O_EXCL))
458 				error = EEXIST;
459 			else {
460 #ifdef MAC
461 				error = mac_posixsem_check_open(td->td_ucred,
462 				    ks);
463 				if (error == 0)
464 #endif
465 				error = ksem_access(ks, td->td_ucred);
466 			}
467 			if (error == 0)
468 				ksem_hold(ks);
469 #ifdef INVARIANTS
470 			else
471 				ks = NULL;
472 #endif
473 		}
474 		sx_xunlock(&ksem_dict_lock);
475 		if (path)
476 			free(path, M_KSEM);
477 	}
478 
479 	if (error) {
480 		KASSERT(ks == NULL, ("ksem_create error with a ksem"));
481 		fdclose(fdp, fp, fd, td);
482 		fdrop(fp, td);
483 		return (error);
484 	}
485 	KASSERT(ks != NULL, ("ksem_create w/o a ksem"));
486 
487 	finit(fp, FREAD | FWRITE, DTYPE_SEM, ks, &ksem_ops);
488 
489 	FILEDESC_XLOCK(fdp);
490 	if (fdp->fd_ofiles[fd] == fp)
491 		fdp->fd_ofileflags[fd] |= UF_EXCLOSE;
492 	FILEDESC_XUNLOCK(fdp);
493 	fdrop(fp, td);
494 
495 	return (0);
496 }
497 
498 static int
499 ksem_get(struct thread *td, semid_t id, struct file **fpp)
500 {
501 	struct ksem *ks;
502 	struct file *fp;
503 	int error;
504 
505 	error = fget(td, id, &fp);
506 	if (error)
507 		return (EINVAL);
508 	if (fp->f_type != DTYPE_SEM) {
509 		fdrop(fp, td);
510 		return (EINVAL);
511 	}
512 	ks = fp->f_data;
513 	if (ks->ks_flags & KS_DEAD) {
514 		fdrop(fp, td);
515 		return (EINVAL);
516 	}
517 	*fpp = fp;
518 	return (0);
519 }
520 
521 /* System calls. */
522 #ifndef _SYS_SYSPROTO_H_
523 struct ksem_init_args {
524 	unsigned int	value;
525 	semid_t		*idp;
526 };
527 #endif
528 int
529 ksem_init(struct thread *td, struct ksem_init_args *uap)
530 {
531 
532 	return (ksem_create(td, NULL, uap->idp, S_IRWXU | S_IRWXG, uap->value,
533 	    0));
534 }
535 
536 #ifndef _SYS_SYSPROTO_H_
537 struct ksem_open_args {
538 	char		*name;
539 	int		oflag;
540 	mode_t		mode;
541 	unsigned int	value;
542 	semid_t		*idp;
543 };
544 #endif
545 int
546 ksem_open(struct thread *td, struct ksem_open_args *uap)
547 {
548 
549 	DP((">>> ksem_open start, pid=%d\n", (int)td->td_proc->p_pid));
550 
551 	if ((uap->oflag & ~(O_CREAT | O_EXCL)) != 0)
552 		return (EINVAL);
553 	return (ksem_create(td, uap->name, uap->idp, uap->mode, uap->value,
554 	    uap->oflag));
555 }
556 
557 #ifndef _SYS_SYSPROTO_H_
558 struct ksem_unlink_args {
559 	char		*name;
560 };
561 #endif
562 int
563 ksem_unlink(struct thread *td, struct ksem_unlink_args *uap)
564 {
565 	char *path;
566 	Fnv32_t fnv;
567 	int error;
568 
569 	path = malloc(MAXPATHLEN, M_TEMP, M_WAITOK);
570 	error = copyinstr(uap->name, path, MAXPATHLEN, NULL);
571 	if (error) {
572 		free(path, M_TEMP);
573 		return (error);
574 	}
575 
576 	fnv = fnv_32_str(path, FNV1_32_INIT);
577 	sx_xlock(&ksem_dict_lock);
578 	error = ksem_remove(path, fnv, td->td_ucred);
579 	sx_xunlock(&ksem_dict_lock);
580 	free(path, M_TEMP);
581 
582 	return (error);
583 }
584 
585 #ifndef _SYS_SYSPROTO_H_
586 struct ksem_close_args {
587 	semid_t		id;
588 };
589 #endif
590 int
591 ksem_close(struct thread *td, struct ksem_close_args *uap)
592 {
593 	struct ksem *ks;
594 	struct file *fp;
595 	int error;
596 
597 	error = ksem_get(td, uap->id, &fp);
598 	if (error)
599 		return (error);
600 	ks = fp->f_data;
601 	if (ks->ks_flags & KS_ANONYMOUS) {
602 		fdrop(fp, td);
603 		return (EINVAL);
604 	}
605 	error = kern_close(td, uap->id);
606 	fdrop(fp, td);
607 	return (error);
608 }
609 
610 #ifndef _SYS_SYSPROTO_H_
611 struct ksem_post_args {
612 	semid_t	id;
613 };
614 #endif
615 int
616 ksem_post(struct thread *td, struct ksem_post_args *uap)
617 {
618 	struct file *fp;
619 	struct ksem *ks;
620 	int error;
621 
622 	error = ksem_get(td, uap->id, &fp);
623 	if (error)
624 		return (error);
625 	ks = fp->f_data;
626 
627 	mtx_lock(&sem_lock);
628 #ifdef MAC
629 	error = mac_posixsem_check_post(td->td_ucred, fp->f_cred, ks);
630 	if (error)
631 		goto err;
632 #endif
633 	if (ks->ks_value == SEM_VALUE_MAX) {
634 		error = EOVERFLOW;
635 		goto err;
636 	}
637 	++ks->ks_value;
638 	if (ks->ks_waiters > 0)
639 		cv_signal(&ks->ks_cv);
640 	error = 0;
641 	vfs_timestamp(&ks->ks_ctime);
642 err:
643 	mtx_unlock(&sem_lock);
644 	fdrop(fp, td);
645 	return (error);
646 }
647 
648 #ifndef _SYS_SYSPROTO_H_
649 struct ksem_wait_args {
650 	semid_t		id;
651 };
652 #endif
653 int
654 ksem_wait(struct thread *td, struct ksem_wait_args *uap)
655 {
656 
657 	return (kern_sem_wait(td, uap->id, 0, NULL));
658 }
659 
660 #ifndef _SYS_SYSPROTO_H_
661 struct ksem_timedwait_args {
662 	semid_t		id;
663 	const struct timespec *abstime;
664 };
665 #endif
666 int
667 ksem_timedwait(struct thread *td, struct ksem_timedwait_args *uap)
668 {
669 	struct timespec abstime;
670 	struct timespec *ts;
671 	int error;
672 
673 	/*
674 	 * We allow a null timespec (wait forever).
675 	 */
676 	if (uap->abstime == NULL)
677 		ts = NULL;
678 	else {
679 		error = copyin(uap->abstime, &abstime, sizeof(abstime));
680 		if (error != 0)
681 			return (error);
682 		if (abstime.tv_nsec >= 1000000000 || abstime.tv_nsec < 0)
683 			return (EINVAL);
684 		ts = &abstime;
685 	}
686 	return (kern_sem_wait(td, uap->id, 0, ts));
687 }
688 
689 #ifndef _SYS_SYSPROTO_H_
690 struct ksem_trywait_args {
691 	semid_t		id;
692 };
693 #endif
694 int
695 ksem_trywait(struct thread *td, struct ksem_trywait_args *uap)
696 {
697 
698 	return (kern_sem_wait(td, uap->id, 1, NULL));
699 }
700 
701 static int
702 kern_sem_wait(struct thread *td, semid_t id, int tryflag,
703     struct timespec *abstime)
704 {
705 	struct timespec ts1, ts2;
706 	struct timeval tv;
707 	struct file *fp;
708 	struct ksem *ks;
709 	int error;
710 
711 	DP((">>> kern_sem_wait entered! pid=%d\n", (int)td->td_proc->p_pid));
712 	error = ksem_get(td, id, &fp);
713 	if (error)
714 		return (error);
715 	ks = fp->f_data;
716 	mtx_lock(&sem_lock);
717 	DP((">>> kern_sem_wait critical section entered! pid=%d\n",
718 	    (int)td->td_proc->p_pid));
719 #ifdef MAC
720 	error = mac_posixsem_check_wait(td->td_ucred, fp->f_cred, ks);
721 	if (error) {
722 		DP(("kern_sem_wait mac failed\n"));
723 		goto err;
724 	}
725 #endif
726 	DP(("kern_sem_wait value = %d, tryflag %d\n", ks->ks_value, tryflag));
727 	vfs_timestamp(&ks->ks_atime);
728 	while (ks->ks_value == 0) {
729 		ks->ks_waiters++;
730 		if (tryflag != 0)
731 			error = EAGAIN;
732 		else if (abstime == NULL)
733 			error = cv_wait_sig(&ks->ks_cv, &sem_lock);
734 		else {
735 			for (;;) {
736 				ts1 = *abstime;
737 				getnanotime(&ts2);
738 				timespecsub(&ts1, &ts2);
739 				TIMESPEC_TO_TIMEVAL(&tv, &ts1);
740 				if (tv.tv_sec < 0) {
741 					error = ETIMEDOUT;
742 					break;
743 				}
744 				error = cv_timedwait_sig(&ks->ks_cv,
745 				    &sem_lock, tvtohz(&tv));
746 				if (error != EWOULDBLOCK)
747 					break;
748 			}
749 		}
750 		ks->ks_waiters--;
751 		if (error)
752 			goto err;
753 	}
754 	ks->ks_value--;
755 	DP(("kern_sem_wait value post-decrement = %d\n", ks->ks_value));
756 	error = 0;
757 err:
758 	mtx_unlock(&sem_lock);
759 	fdrop(fp, td);
760 	DP(("<<< kern_sem_wait leaving, pid=%d, error = %d\n",
761 	    (int)td->td_proc->p_pid, error));
762 	return (error);
763 }
764 
765 #ifndef _SYS_SYSPROTO_H_
766 struct ksem_getvalue_args {
767 	semid_t		id;
768 	int		*val;
769 };
770 #endif
771 int
772 ksem_getvalue(struct thread *td, struct ksem_getvalue_args *uap)
773 {
774 	struct file *fp;
775 	struct ksem *ks;
776 	int error, val;
777 
778 	error = ksem_get(td, uap->id, &fp);
779 	if (error)
780 		return (error);
781 	ks = fp->f_data;
782 
783 	mtx_lock(&sem_lock);
784 #ifdef MAC
785 	error = mac_posixsem_check_getvalue(td->td_ucred, fp->f_cred, ks);
786 	if (error) {
787 		mtx_unlock(&sem_lock);
788 		fdrop(fp, td);
789 		return (error);
790 	}
791 #endif
792 	val = ks->ks_value;
793 	vfs_timestamp(&ks->ks_atime);
794 	mtx_unlock(&sem_lock);
795 	fdrop(fp, td);
796 	error = copyout(&val, uap->val, sizeof(val));
797 	return (error);
798 }
799 
800 #ifndef _SYS_SYSPROTO_H_
801 struct ksem_destroy_args {
802 	semid_t		id;
803 };
804 #endif
805 int
806 ksem_destroy(struct thread *td, struct ksem_destroy_args *uap)
807 {
808 	struct file *fp;
809 	struct ksem *ks;
810 	int error;
811 
812 	error = ksem_get(td, uap->id, &fp);
813 	if (error)
814 		return (error);
815 	ks = fp->f_data;
816 	if (!(ks->ks_flags & KS_ANONYMOUS)) {
817 		fdrop(fp, td);
818 		return (EINVAL);
819 	}
820 	mtx_lock(&sem_lock);
821 	if (ks->ks_waiters != 0) {
822 		mtx_unlock(&sem_lock);
823 		error = EBUSY;
824 		goto err;
825 	}
826 	ks->ks_flags |= KS_DEAD;
827 	mtx_unlock(&sem_lock);
828 
829 	error = kern_close(td, uap->id);
830 err:
831 	fdrop(fp, td);
832 	return (error);
833 }
834 
835 #define	SYSCALL_DATA(syscallname)				\
836 static int syscallname##_syscall = SYS_##syscallname;		\
837 static int syscallname##_registered;				\
838 static struct sysent syscallname##_old_sysent;			\
839 MAKE_SYSENT(syscallname);
840 
841 #define	SYSCALL_REGISTER(syscallname) do {				\
842 	error = syscall_register(& syscallname##_syscall,		\
843 	    & syscallname##_sysent, & syscallname##_old_sysent);	\
844 	if (error)							\
845 		return (error);						\
846 	syscallname##_registered = 1;					\
847 } while(0)
848 
849 #define	SYSCALL_DEREGISTER(syscallname) do {				\
850 	if (syscallname##_registered) {					\
851 		syscallname##_registered = 0;				\
852 		syscall_deregister(& syscallname##_syscall,		\
853 		    & syscallname##_old_sysent);			\
854 	}								\
855 } while(0)
856 
857 SYSCALL_DATA(ksem_init);
858 SYSCALL_DATA(ksem_open);
859 SYSCALL_DATA(ksem_unlink);
860 SYSCALL_DATA(ksem_close);
861 SYSCALL_DATA(ksem_post);
862 SYSCALL_DATA(ksem_wait);
863 SYSCALL_DATA(ksem_timedwait);
864 SYSCALL_DATA(ksem_trywait);
865 SYSCALL_DATA(ksem_getvalue);
866 SYSCALL_DATA(ksem_destroy);
867 
868 static int
869 ksem_module_init(void)
870 {
871 	int error;
872 
873 	mtx_init(&sem_lock, "sem", NULL, MTX_DEF);
874 	mtx_init(&ksem_count_lock, "ksem count", NULL, MTX_DEF);
875 	sx_init(&ksem_dict_lock, "ksem dictionary");
876 	ksem_dictionary = hashinit(1024, M_KSEM, &ksem_hash);
877 	p31b_setcfg(CTL_P1003_1B_SEM_NSEMS_MAX, SEM_MAX);
878 	p31b_setcfg(CTL_P1003_1B_SEM_VALUE_MAX, SEM_VALUE_MAX);
879 
880 	SYSCALL_REGISTER(ksem_init);
881 	SYSCALL_REGISTER(ksem_open);
882 	SYSCALL_REGISTER(ksem_unlink);
883 	SYSCALL_REGISTER(ksem_close);
884 	SYSCALL_REGISTER(ksem_post);
885 	SYSCALL_REGISTER(ksem_wait);
886 	SYSCALL_REGISTER(ksem_timedwait);
887 	SYSCALL_REGISTER(ksem_trywait);
888 	SYSCALL_REGISTER(ksem_getvalue);
889 	SYSCALL_REGISTER(ksem_destroy);
890 	return (0);
891 }
892 
893 static void
894 ksem_module_destroy(void)
895 {
896 
897 	SYSCALL_DEREGISTER(ksem_init);
898 	SYSCALL_DEREGISTER(ksem_open);
899 	SYSCALL_DEREGISTER(ksem_unlink);
900 	SYSCALL_DEREGISTER(ksem_close);
901 	SYSCALL_DEREGISTER(ksem_post);
902 	SYSCALL_DEREGISTER(ksem_wait);
903 	SYSCALL_DEREGISTER(ksem_timedwait);
904 	SYSCALL_DEREGISTER(ksem_trywait);
905 	SYSCALL_DEREGISTER(ksem_getvalue);
906 	SYSCALL_DEREGISTER(ksem_destroy);
907 
908 	hashdestroy(ksem_dictionary, M_KSEM, ksem_hash);
909 	sx_destroy(&ksem_dict_lock);
910 	mtx_destroy(&ksem_count_lock);
911 	mtx_destroy(&sem_lock);
912 }
913 
914 static int
915 sem_modload(struct module *module, int cmd, void *arg)
916 {
917         int error = 0;
918 
919         switch (cmd) {
920         case MOD_LOAD:
921 		error = ksem_module_init();
922 		if (error)
923 			ksem_module_destroy();
924                 break;
925 
926         case MOD_UNLOAD:
927 		mtx_lock(&ksem_count_lock);
928 		if (nsems != 0) {
929 			error = EOPNOTSUPP;
930 			mtx_unlock(&ksem_count_lock);
931 			break;
932 		}
933 		ksem_dead = 1;
934 		mtx_unlock(&ksem_count_lock);
935 		ksem_module_destroy();
936                 break;
937 
938         case MOD_SHUTDOWN:
939                 break;
940         default:
941                 error = EINVAL;
942                 break;
943         }
944         return (error);
945 }
946 
947 static moduledata_t sem_mod = {
948         "sem",
949         &sem_modload,
950         NULL
951 };
952 
953 DECLARE_MODULE(sem, sem_mod, SI_SUB_SYSV_SEM, SI_ORDER_FIRST);
954 MODULE_VERSION(sem, 1);
955