xref: /illumos-gate/usr/src/uts/common/io/devpoll.c (revision ac2250cb76bb32944fd2c8a3ba2cd3f79747748d)
1 /*
2  * CDDL HEADER START
3  *
4  * The contents of this file are subject to the terms of the
5  * Common Development and Distribution License (the "License").
6  * You may not use this file except in compliance with the License.
7  *
8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9  * or http://www.opensolaris.org/os/licensing.
10  * See the License for the specific language governing permissions
11  * and limitations under the License.
12  *
13  * When distributing Covered Code, include this CDDL HEADER in each
14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15  * If applicable, add the following below this CDDL HEADER, with the
16  * fields enclosed by brackets "[]" replaced with your own identifying
17  * information: Portions Copyright [yyyy] [name of copyright owner]
18  *
19  * CDDL HEADER END
20  */
21 /*
22  * Copyright 2008 Sun Microsystems, Inc.  All rights reserved.
23  * Use is subject to license terms.
24  */
25 
26 /*
27  * Copyright (c) 2012 by Delphix. All rights reserved.
28  * Copyright 2019 Joyent, Inc.
29  * Copyright 2022 Oxide Computer Company
30  * Copyright 2026 OmniOS Community Edition (OmniOSce) Association.
31  */
32 
33 #include <sys/types.h>
34 #include <sys/devops.h>
35 #include <sys/conf.h>
36 #include <sys/modctl.h>
37 #include <sys/sunddi.h>
38 #include <sys/stat.h>
39 #include <sys/poll_impl.h>
40 #include <sys/errno.h>
41 #include <sys/kmem.h>
42 #include <sys/mkdev.h>
43 #include <sys/debug.h>
44 #include <sys/file.h>
45 #include <sys/sysmacros.h>
46 #include <sys/systm.h>
47 #include <sys/bitmap.h>
48 #include <sys/devpoll.h>
49 #include <sys/rctl.h>
50 #include <sys/resource.h>
51 #include <sys/schedctl.h>
52 #include <sys/epoll.h>
53 
54 #define	RESERVED	1
55 
56 /* local data struct */
57 static	dp_entry_t	**devpolltbl;	/* dev poll entries */
58 static	size_t		dptblsize;
59 
60 static	kmutex_t	devpoll_lock;	/* lock protecting dev tbl */
61 int			devpoll_init;	/* is /dev/poll initialized already */
62 
63 /* device local functions */
64 
65 static int dpopen(dev_t *devp, int flag, int otyp, cred_t *credp);
66 static int dpwrite(dev_t dev, struct uio *uiop, cred_t *credp);
67 static int dpioctl(dev_t dev, int cmd, intptr_t arg, int mode, cred_t *credp,
68     int *rvalp);
69 static int dppoll(dev_t dev, short events, int anyyet, short *reventsp,
70     struct pollhead **phpp);
71 static int dpclose(dev_t dev, int flag, int otyp, cred_t *credp);
72 static dev_info_t *dpdevi;
73 
74 
75 static struct cb_ops    dp_cb_ops = {
76 	dpopen,			/* open */
77 	dpclose,		/* close */
78 	nodev,			/* strategy */
79 	nodev,			/* print */
80 	nodev,			/* dump */
81 	nodev,			/* read */
82 	dpwrite,		/* write */
83 	dpioctl,		/* ioctl */
84 	nodev,			/* devmap */
85 	nodev,			/* mmap */
86 	nodev,			/* segmap */
87 	dppoll,			/* poll */
88 	ddi_prop_op,		/* prop_op */
89 	(struct streamtab *)0,	/* streamtab */
90 	D_MP,			/* flags */
91 	CB_REV,			/* cb_ops revision */
92 	nodev,			/* aread */
93 	nodev			/* awrite */
94 };
95 
96 static int dpattach(dev_info_t *, ddi_attach_cmd_t);
97 static int dpdetach(dev_info_t *, ddi_detach_cmd_t);
98 static int dpinfo(dev_info_t *, ddi_info_cmd_t, void *, void **);
99 
100 static struct dev_ops dp_ops = {
101 	DEVO_REV,		/* devo_rev */
102 	0,			/* refcnt */
103 	dpinfo,			/* info */
104 	nulldev,		/* identify */
105 	nulldev,		/* probe */
106 	dpattach,		/* attach */
107 	dpdetach,		/* detach */
108 	nodev,			/* reset */
109 	&dp_cb_ops,		/* driver operations */
110 	(struct bus_ops *)NULL, /* bus operations */
111 	nulldev,		/* power */
112 	ddi_quiesce_not_needed,		/* quiesce */
113 };
114 
115 
116 static struct modldrv modldrv = {
117 	&mod_driverops,		/* type of module - a driver */
118 	"/dev/poll driver",
119 	&dp_ops,
120 };
121 
122 static struct modlinkage modlinkage = {
123 	MODREV_1,
124 	(void *)&modldrv,
125 	NULL
126 };
127 
128 static void pcachelink_assoc(pollcache_t *, pollcache_t *);
129 static void pcachelink_mark_stale(pollcache_t *);
130 static void pcachelink_purge_stale(pollcache_t *);
131 static void pcachelink_purge_all(pollcache_t *);
132 
133 
134 /*
135  * Locking Design
136  *
137  * The /dev/poll driver shares most of its code with poll sys call whose
138  * code is in common/syscall/poll.c. In poll(2) design, the pollcache
139  * structure is per lwp. An implicit assumption is made there that some
140  * portion of pollcache will never be touched by other lwps. E.g., in
141  * poll(2) design, no lwp will ever need to grow bitmap of other lwp.
142  * This assumption is not true for /dev/poll; hence the need for extra
143  * locking.
144  *
145  * To allow more parallelism, each /dev/poll file descriptor (indexed by
146  * minor number) has its own lock. Since read (dpioctl) is a much more
147  * frequent operation than write, we want to allow multiple reads on same
148  * /dev/poll fd. However, we prevent writes from being starved by giving
149  * priority to write operation. Theoretically writes can starve reads as
150  * well. But in practical sense this is not important because (1) writes
151  * happens less often than reads, and (2) write operation defines the
152  * content of poll fd a cache set. If writes happens so often that they
153  * can starve reads, that means the cached set is very unstable. It may
154  * not make sense to read an unstable cache set anyway. Therefore, the
155  * writers starving readers case is not handled in this design.
156  */
157 
158 int
159 _init()
160 {
161 	int	error;
162 
163 	dptblsize = DEVPOLLSIZE;
164 	devpolltbl = kmem_zalloc(sizeof (caddr_t) * dptblsize, KM_SLEEP);
165 	mutex_init(&devpoll_lock, NULL, MUTEX_DEFAULT, NULL);
166 	devpoll_init = 1;
167 	if ((error = mod_install(&modlinkage)) != 0) {
168 		kmem_free(devpolltbl, sizeof (caddr_t) * dptblsize);
169 		devpoll_init = 0;
170 	}
171 	return (error);
172 }
173 
174 int
175 _fini()
176 {
177 	int error;
178 
179 	if ((error = mod_remove(&modlinkage)) != 0) {
180 		return (error);
181 	}
182 	mutex_destroy(&devpoll_lock);
183 	kmem_free(devpolltbl, sizeof (caddr_t) * dptblsize);
184 	return (0);
185 }
186 
187 int
188 _info(struct modinfo *modinfop)
189 {
190 	return (mod_info(&modlinkage, modinfop));
191 }
192 
193 /*ARGSUSED*/
194 static int
195 dpattach(dev_info_t *devi, ddi_attach_cmd_t cmd)
196 {
197 	if (ddi_create_minor_node(devi, "poll", S_IFCHR, 0, DDI_PSEUDO, 0)
198 	    == DDI_FAILURE) {
199 		ddi_remove_minor_node(devi, NULL);
200 		return (DDI_FAILURE);
201 	}
202 	dpdevi = devi;
203 	return (DDI_SUCCESS);
204 }
205 
206 static int
207 dpdetach(dev_info_t *devi, ddi_detach_cmd_t cmd)
208 {
209 	if (cmd != DDI_DETACH)
210 		return (DDI_FAILURE);
211 
212 	ddi_remove_minor_node(devi, NULL);
213 	return (DDI_SUCCESS);
214 }
215 
216 /* ARGSUSED */
217 static int
218 dpinfo(dev_info_t *dip, ddi_info_cmd_t infocmd, void *arg, void **result)
219 {
220 	int error;
221 
222 	switch (infocmd) {
223 	case DDI_INFO_DEVT2DEVINFO:
224 		*result = (void *)dpdevi;
225 		error = DDI_SUCCESS;
226 		break;
227 	case DDI_INFO_DEVT2INSTANCE:
228 		*result = (void *)0;
229 		error = DDI_SUCCESS;
230 		break;
231 	default:
232 		error = DDI_FAILURE;
233 	}
234 	return (error);
235 }
236 
237 /*
238  * dp_pcache_poll has similar logic to pcache_poll() in poll.c. The major
239  * differences are: (1) /dev/poll requires scanning the bitmap starting at
240  * where it was stopped last time, instead of always starting from 0,
241  * (2) since user may not have cleaned up the cached fds when they are
242  * closed, some polldats in cache may refer to closed or reused fds. We
243  * need to check for those cases.
244  *
245  * NOTE: Upon closing an fd, automatic poll cache cleanup is done for
246  *	 poll(2) caches but NOT for /dev/poll caches. So expect some
247  *	 stale entries!
248  */
249 static int
250 dp_pcache_poll(dp_entry_t *dpep, void *dpbuf, pollcache_t *pcp, nfds_t nfds,
251     int *fdcntp)
252 {
253 	int		start, ostart, end, fdcnt, error = 0;
254 	boolean_t	done, no_wrap;
255 	pollfd_t	*pfdp;
256 	epoll_event_t	*epoll;
257 	const short	mask = POLLRDHUP | POLLWRBAND;
258 	const boolean_t	is_epoll = (dpep->dpe_flag & DP_ISEPOLLCOMPAT) != 0;
259 
260 	ASSERT(MUTEX_HELD(&pcp->pc_lock));
261 	if (pcp->pc_bitmap == NULL) {
262 		/* No Need to search because no poll fd has been cached. */
263 		return (0);
264 	}
265 
266 	if (is_epoll) {
267 		pfdp = NULL;
268 		epoll = (epoll_event_t *)dpbuf;
269 	} else {
270 		pfdp = (pollfd_t *)dpbuf;
271 		epoll = NULL;
272 	}
273 retry:
274 	start = ostart = pcp->pc_mapstart;
275 	end = pcp->pc_mapend;
276 
277 	if (start == 0) {
278 		/*
279 		 * started from every begining, no need to wrap around.
280 		 */
281 		no_wrap = B_TRUE;
282 	} else {
283 		no_wrap = B_FALSE;
284 	}
285 	done = B_FALSE;
286 	fdcnt = 0;
287 	while ((fdcnt < nfds) && !done) {
288 		pollhead_t *php = NULL;
289 		short revent = 0;
290 		uf_entry_gen_t gen;
291 		int fd;
292 
293 		/*
294 		 * Examine the bit map in a circular fashion
295 		 * to avoid starvation. Always resume from
296 		 * last stop. Scan till end of the map. Then
297 		 * wrap around.
298 		 */
299 		fd = bt_getlowbit(pcp->pc_bitmap, start, end);
300 		ASSERT(fd <= end);
301 		if (fd >= 0) {
302 			file_t *fp;
303 			polldat_t *pdp;
304 
305 			if (fd == end) {
306 				if (no_wrap) {
307 					done = B_TRUE;
308 				} else {
309 					start = 0;
310 					end = ostart - 1;
311 					no_wrap = B_TRUE;
312 				}
313 			} else {
314 				start = fd + 1;
315 			}
316 			pdp = pcache_lookup_fd(pcp, fd);
317 repoll:
318 			ASSERT(pdp != NULL);
319 			ASSERT(pdp->pd_fd == fd);
320 			if (pdp->pd_fp == NULL) {
321 				/*
322 				 * The fd is POLLREMOVed. This fd is
323 				 * logically no longer cached. So move
324 				 * on to the next one.
325 				 */
326 				continue;
327 			}
328 			if ((fp = getf_gen(fd, &gen)) == NULL) {
329 				if (is_epoll) {
330 					/*
331 					 * In the epoll compatibility case, we
332 					 * actually perform the implicit
333 					 * removal to remain closer to the
334 					 * epoll semantics.
335 					 */
336 					pdp->pd_fp = NULL;
337 					pdp->pd_events = 0;
338 
339 					polldat_disassociate(pdp);
340 
341 					BT_CLEAR(pcp->pc_bitmap, fd);
342 				} else if (pfdp != NULL) {
343 					/*
344 					 * The fd has been closed, but user has
345 					 * not done a POLLREMOVE on this fd
346 					 * yet. Instead of cleaning it here
347 					 * implicitly, we return POLLNVAL. This
348 					 * is consistent with poll(2) polling a
349 					 * closed fd. Hope this will remind
350 					 * user to do a POLLREMOVE.
351 					 */
352 					pfdp[fdcnt].fd = fd;
353 					pfdp[fdcnt].revents = POLLNVAL;
354 					fdcnt++;
355 				}
356 				continue;
357 			}
358 
359 			/*
360 			 * Detect a change to the resource underlying a cached
361 			 * file descriptor.  While the fd generation comparison
362 			 * will catch nearly all cases, the file_t comparison
363 			 * is maintained as a failsafe as well.
364 			 */
365 			if (gen != pdp->pd_gen || fp != pdp->pd_fp) {
366 				/*
367 				 * The user is polling on a cached fd which was
368 				 * closed and then reused.  Unfortunately there
369 				 * is no good way to communicate this fact to
370 				 * the consumer.
371 				 *
372 				 * When this situation has been detected, it's
373 				 * likely that any existing pollhead is
374 				 * ill-suited to perform proper wake-ups.
375 				 *
376 				 * Clean up the old entry under the expectation
377 				 * that a valid one will be provided as part of
378 				 * the later VOP_POLL.
379 				 */
380 				polldat_disassociate(pdp);
381 
382 				/*
383 				 * Since epoll is expected to act on the
384 				 * underlying 'struct file' (in Linux terms,
385 				 * our vnode_t would be a closer analog) rather
386 				 * than the fd itself, an implicit remove
387 				 * is necessary under these circumstances to
388 				 * suppress any results (or errors) from the
389 				 * new resource occupying the fd.
390 				 */
391 				if (is_epoll) {
392 					pdp->pd_fp = NULL;
393 					pdp->pd_events = 0;
394 					BT_CLEAR(pcp->pc_bitmap, fd);
395 					releasef(fd);
396 					continue;
397 				} else {
398 					/*
399 					 * Regular /dev/poll is unbothered
400 					 * about the fd reassignment.
401 					 */
402 					pdp->pd_fp = fp;
403 					pdp->pd_gen = gen;
404 				}
405 			}
406 
407 			/*
408 			 * Skip entries marked with the sentinal value for
409 			 * having already fired under oneshot conditions.
410 			 */
411 			if (pdp->pd_events == POLLONESHOT) {
412 				releasef(fd);
413 				BT_CLEAR(pcp->pc_bitmap, fd);
414 				continue;
415 			}
416 
417 			/*
418 			 * XXX - pollrelock() logic needs to know which
419 			 * which pollcache lock to grab. It'd be a
420 			 * cleaner solution if we could pass pcp as
421 			 * an arguement in VOP_POLL interface instead
422 			 * of implicitly passing it using thread_t
423 			 * struct. On the other hand, changing VOP_POLL
424 			 * interface will require all driver/file system
425 			 * poll routine to change. May want to revisit
426 			 * the tradeoff later.
427 			 */
428 			curthread->t_pollcache = pcp;
429 			error = VOP_POLL(fp->f_vnode, pdp->pd_events, 0,
430 			    &revent, &php, NULL);
431 
432 			/*
433 			 * Recheck edge-triggered descriptors which lack a
434 			 * pollhead.  While this check is performed when an fd
435 			 * is added to the pollcache in dpwrite(), subsequent
436 			 * descriptor manipulation could cause a different
437 			 * resource to be present now.
438 			 */
439 			if ((pdp->pd_events & POLLET) && error == 0 &&
440 			    pdp->pd_php == NULL && php == NULL && revent != 0) {
441 				short levent = 0;
442 
443 				/*
444 				 * The same POLLET-only VOP_POLL is used in an
445 				 * attempt to coax a pollhead from older
446 				 * driver logic.
447 				 */
448 				error = VOP_POLL(fp->f_vnode, POLLET,
449 				    0, &levent, &php, NULL);
450 			}
451 
452 			curthread->t_pollcache = NULL;
453 			releasef(fd);
454 			if (error != 0) {
455 				break;
456 			}
457 
458 			/*
459 			 * layered devices (e.g. console driver)
460 			 * may change the vnode and thus the pollhead
461 			 * pointer out from underneath us.
462 			 */
463 			if (php != NULL && pdp->pd_php != NULL &&
464 			    php != pdp->pd_php) {
465 				polldat_disassociate(pdp);
466 				polldat_associate(pdp, php);
467 				/*
468 				 * The bit should still be set.
469 				 */
470 				ASSERT(BT_TEST(pcp->pc_bitmap, fd));
471 				goto retry;
472 			}
473 
474 			if (revent != 0) {
475 				if (pfdp != NULL) {
476 					pfdp[fdcnt].fd = fd;
477 					pfdp[fdcnt].events = pdp->pd_events;
478 					pfdp[fdcnt].revents = revent;
479 				} else if (epoll != NULL) {
480 					epoll_event_t *ep = &epoll[fdcnt];
481 
482 					ASSERT(epoll != NULL);
483 					ep->data.u64 = pdp->pd_epolldata;
484 
485 					/*
486 					 * Since POLLNVAL is a legal event for
487 					 * VOP_POLL handlers to emit, it must
488 					 * be translated epoll-legal.
489 					 */
490 					if (revent & POLLNVAL) {
491 						revent &= ~POLLNVAL;
492 						revent |= POLLERR;
493 					}
494 
495 					/*
496 					 * If any of the event bits are set for
497 					 * which poll and epoll representations
498 					 * differ, swizzle in the native epoll
499 					 * values.
500 					 */
501 					if (revent & mask) {
502 						ep->events = (revent & ~mask) |
503 						    ((revent & POLLRDHUP) ?
504 						    EPOLLRDHUP : 0) |
505 						    ((revent & POLLWRBAND) ?
506 						    EPOLLWRBAND : 0);
507 					} else {
508 						ep->events = revent;
509 					}
510 
511 					/*
512 					 * We define POLLWRNORM to be POLLOUT,
513 					 * but epoll has separate definitions
514 					 * for them; if POLLOUT is set and the
515 					 * user has asked for EPOLLWRNORM, set
516 					 * that as well.
517 					 */
518 					if ((revent & POLLOUT) &&
519 					    (pdp->pd_events & EPOLLWRNORM)) {
520 						ep->events |= EPOLLWRNORM;
521 					}
522 				} else {
523 					pollstate_t *ps =
524 					    curthread->t_pollstate;
525 					/*
526 					 * The devpoll handle itself is being
527 					 * polled.  Notify the caller of any
528 					 * readable event(s), leaving as much
529 					 * state as possible untouched.
530 					 */
531 					VERIFY(fdcnt == 0);
532 					VERIFY(ps != NULL);
533 
534 					/*
535 					 * If a call to pollunlock() fails
536 					 * during VOP_POLL, skip over the fd
537 					 * and continue polling.
538 					 *
539 					 * Otherwise, report that there is an
540 					 * event pending.
541 					 */
542 					if ((ps->ps_flags & POLLSTATE_ULFAIL)
543 					    != 0) {
544 						ps->ps_flags &=
545 						    ~POLLSTATE_ULFAIL;
546 						continue;
547 					} else {
548 						fdcnt++;
549 						break;
550 					}
551 				}
552 
553 				/* Handle special polling modes. */
554 				if (pdp->pd_events & POLLONESHOT) {
555 					/*
556 					 * Entries operating under POLLONESHOT
557 					 * will be marked with a sentinel value
558 					 * to indicate that they have "fired"
559 					 * when emitting an event.  This will
560 					 * disable them from polling until a
561 					 * later add/modify event rearms them.
562 					 */
563 					pdp->pd_events = POLLONESHOT;
564 					polldat_disassociate(pdp);
565 					BT_CLEAR(pcp->pc_bitmap, fd);
566 				} else if (pdp->pd_events & POLLET) {
567 					/*
568 					 * Wire up the pollhead which should
569 					 * have been provided.  Edge-triggered
570 					 * polling cannot function properly
571 					 * with drivers which do not emit one.
572 					 */
573 					if (php != NULL &&
574 					    pdp->pd_php == NULL) {
575 						polldat_associate(pdp, php);
576 					}
577 
578 					/*
579 					 * If the driver has emitted a pollhead,
580 					 * clear the bit in the bitmap which
581 					 * effectively latches the edge on a
582 					 * pollwakeup() from the driver.
583 					 */
584 					if (pdp->pd_php != NULL) {
585 						BT_CLEAR(pcp->pc_bitmap, fd);
586 					}
587 				}
588 
589 				fdcnt++;
590 			} else if (php != NULL) {
591 				/*
592 				 * We clear a bit or cache a poll fd if
593 				 * the driver returns a poll head ptr,
594 				 * which is expected in the case of 0
595 				 * revents. Some buggy driver may return
596 				 * NULL php pointer with 0 revents. In
597 				 * this case, we just treat the driver as
598 				 * "noncachable" and not clearing the bit
599 				 * in bitmap.
600 				 */
601 				if ((pdp->pd_php != NULL) &&
602 				    ((pcp->pc_flag & PC_POLLWAKE) == 0)) {
603 					BT_CLEAR(pcp->pc_bitmap, fd);
604 				}
605 				if (pdp->pd_php == NULL) {
606 					polldat_associate(pdp, php);
607 					/*
608 					 * An event of interest may have
609 					 * arrived between the VOP_POLL() and
610 					 * the polldat_associate(), so we
611 					 * must check again.
612 					 */
613 					goto repoll;
614 				}
615 			}
616 		} else {
617 			/*
618 			 * No bit set in the range. Check for wrap around.
619 			 */
620 			if (!no_wrap) {
621 				start = 0;
622 				end = ostart - 1;
623 				no_wrap = B_TRUE;
624 			} else {
625 				done = B_TRUE;
626 			}
627 		}
628 	}
629 
630 	if (!done) {
631 		pcp->pc_mapstart = start;
632 	}
633 	ASSERT(*fdcntp == 0);
634 	*fdcntp = fdcnt;
635 	return (error);
636 }
637 
638 /*ARGSUSED*/
639 static int
640 dpopen(dev_t *devp, int flag, int otyp, cred_t *credp)
641 {
642 	minor_t		minordev;
643 	dp_entry_t	*dpep;
644 	pollcache_t	*pcp;
645 
646 	ASSERT(devpoll_init);
647 	ASSERT(dptblsize <= MAXMIN);
648 	mutex_enter(&devpoll_lock);
649 	for (minordev = 0; minordev < dptblsize; minordev++) {
650 		if (devpolltbl[minordev] == NULL) {
651 			devpolltbl[minordev] = (dp_entry_t *)RESERVED;
652 			break;
653 		}
654 	}
655 	if (minordev == dptblsize) {
656 		dp_entry_t	**newtbl;
657 		size_t		oldsize;
658 
659 		/*
660 		 * Used up every entry in the existing devpoll table.
661 		 * Grow the table by DEVPOLLSIZE.
662 		 */
663 		if ((oldsize = dptblsize) >= MAXMIN) {
664 			mutex_exit(&devpoll_lock);
665 			return (ENXIO);
666 		}
667 		dptblsize += DEVPOLLSIZE;
668 		if (dptblsize > MAXMIN) {
669 			dptblsize = MAXMIN;
670 		}
671 		newtbl = kmem_zalloc(sizeof (caddr_t) * dptblsize, KM_SLEEP);
672 		bcopy(devpolltbl, newtbl, sizeof (caddr_t) * oldsize);
673 		kmem_free(devpolltbl, sizeof (caddr_t) * oldsize);
674 		devpolltbl = newtbl;
675 		devpolltbl[minordev] = (dp_entry_t *)RESERVED;
676 	}
677 	mutex_exit(&devpoll_lock);
678 
679 	dpep = kmem_zalloc(sizeof (dp_entry_t), KM_SLEEP);
680 	/*
681 	 * allocate a pollcache skeleton here. Delay allocating bitmap
682 	 * structures until dpwrite() time, since we don't know the
683 	 * optimal size yet.  We also delay setting the pid until either
684 	 * dpwrite() or attempt to poll on the instance, allowing parents
685 	 * to create instances of /dev/poll for their children.  (In the
686 	 * epoll compatibility case, this check isn't performed to maintain
687 	 * semantic compatibility.)
688 	 */
689 	pcp = pcache_alloc();
690 	dpep->dpe_pcache = pcp;
691 	pcp->pc_pid = -1;
692 	*devp = makedevice(getmajor(*devp), minordev);  /* clone the driver */
693 	mutex_enter(&devpoll_lock);
694 	ASSERT(minordev < dptblsize);
695 	ASSERT(devpolltbl[minordev] == (dp_entry_t *)RESERVED);
696 	devpolltbl[minordev] = dpep;
697 	mutex_exit(&devpoll_lock);
698 	return (0);
699 }
700 
701 /*
702  * Write to dev/poll add/remove fd's to/from a cached poll fd set,
703  * or change poll events for a watched fd.
704  */
705 /*ARGSUSED*/
706 static int
707 dpwrite(dev_t dev, struct uio *uiop, cred_t *credp)
708 {
709 	minor_t		minor;
710 	dp_entry_t	*dpep;
711 	pollcache_t	*pcp;
712 	pollfd_t	*pollfdp, *pfdp;
713 	dvpoll_epollfd_t *epfdp;
714 	uintptr_t	limit;
715 	int		error;
716 	uint_t		size;
717 	size_t		copysize, uiosize;
718 	nfds_t		pollfdnum;
719 	boolean_t	is_epoll, fds_added = B_FALSE;
720 
721 	minor = getminor(dev);
722 
723 	mutex_enter(&devpoll_lock);
724 	ASSERT(minor < dptblsize);
725 	dpep = devpolltbl[minor];
726 	ASSERT(dpep != NULL);
727 	mutex_exit(&devpoll_lock);
728 
729 	mutex_enter(&dpep->dpe_lock);
730 	pcp = dpep->dpe_pcache;
731 	is_epoll = (dpep->dpe_flag & DP_ISEPOLLCOMPAT) != 0;
732 	size = (is_epoll) ? sizeof (dvpoll_epollfd_t) : sizeof (pollfd_t);
733 	mutex_exit(&dpep->dpe_lock);
734 
735 	if (!is_epoll && curproc->p_pid != pcp->pc_pid) {
736 		if (pcp->pc_pid != -1) {
737 			return (EACCES);
738 		}
739 
740 		pcp->pc_pid = curproc->p_pid;
741 	}
742 
743 	if (uiop->uio_resid < 0) {
744 		/* No one else is this careful, but maybe they should be. */
745 		return (EINVAL);
746 	}
747 
748 	uiosize = (size_t)uiop->uio_resid;
749 	pollfdnum = uiosize / size;
750 
751 	/*
752 	 * For epoll-enabled handles, restrict the allowed write size to 2.
753 	 * This corresponds to an epoll_ctl(3C) performing an EPOLL_CTL_MOD
754 	 * operation which is expanded into two operations (DEL and ADD).
755 	 *
756 	 * All other operations performed through epoll_ctl(3C) will consist of
757 	 * a single entry.
758 	 */
759 	if (is_epoll && pollfdnum > 2) {
760 		return (EINVAL);
761 	}
762 
763 	/*
764 	 * We want to make sure that pollfdnum isn't large enough to DoS us,
765 	 * but we also don't want to grab p_lock unnecessarily -- so we
766 	 * perform the full check against our resource limits if and only if
767 	 * pollfdnum is larger than the known-to-be-sane value of UINT8_MAX.
768 	 */
769 	if (pollfdnum > UINT8_MAX) {
770 		mutex_enter(&curproc->p_lock);
771 		if (pollfdnum >
772 		    (uint_t)rctl_enforced_value(rctlproc_legacy[RLIMIT_NOFILE],
773 		    curproc->p_rctls, curproc)) {
774 			(void) rctl_action(rctlproc_legacy[RLIMIT_NOFILE],
775 			    curproc->p_rctls, curproc, RCA_SAFE);
776 			mutex_exit(&curproc->p_lock);
777 			return (EINVAL);
778 		}
779 		mutex_exit(&curproc->p_lock);
780 	}
781 
782 	/*
783 	 * Copy in the pollfd array.  Walk through the array and add
784 	 * each polled fd to the cached set.
785 	 */
786 	pollfdp = kmem_alloc(uiosize, KM_SLEEP);
787 	limit = (uintptr_t)pollfdp + (pollfdnum * size);
788 
789 	/*
790 	 * Although /dev/poll uses the write(2) interface to cache fds, it's
791 	 * not supposed to function as a seekable device. To prevent offset
792 	 * from growing and eventually exceed the maximum, reset the offset
793 	 * here for every call.
794 	 */
795 	uiop->uio_loffset = 0;
796 
797 	/*
798 	 * Use uiocopy instead of uiomove when populating pollfdp, keeping
799 	 * uio_resid untouched for now.  Write syscalls will translate EINTR
800 	 * into a success if they detect "successfully transfered" data via an
801 	 * updated uio_resid.  Falsely suppressing such errors is disastrous.
802 	 */
803 	if ((error = uiocopy((caddr_t)pollfdp, uiosize, UIO_WRITE, uiop,
804 	    &copysize)) != 0) {
805 		kmem_free(pollfdp, uiosize);
806 		return (error);
807 	}
808 
809 	/*
810 	 * We are about to enter the core portion of dpwrite(). Make sure this
811 	 * write has exclusive access in this portion of the code, i.e., no
812 	 * other writers in this code.
813 	 *
814 	 * Waiting for all readers to drop their references to the dpe is
815 	 * unecessary since the pollcache itself is protected by pc_lock.
816 	 */
817 	mutex_enter(&dpep->dpe_lock);
818 	dpep->dpe_writerwait++;
819 	while ((dpep->dpe_flag & DP_WRITER_PRESENT) != 0) {
820 		ASSERT(dpep->dpe_refcnt != 0);
821 
822 		/*
823 		 * The epoll API does not allow EINTR as a result when making
824 		 * modifications to the set of polled fds.  Given that write
825 		 * activity is relatively quick and the size of accepted writes
826 		 * is limited above to two entries, a signal-ignorant wait is
827 		 * used here to avoid the EINTR.
828 		 */
829 		if (is_epoll) {
830 			cv_wait(&dpep->dpe_cv, &dpep->dpe_lock);
831 			continue;
832 		}
833 
834 		/*
835 		 * Non-epoll writers to /dev/poll handles can tolerate EINTR.
836 		 */
837 		if (!cv_wait_sig_swap(&dpep->dpe_cv, &dpep->dpe_lock)) {
838 			dpep->dpe_writerwait--;
839 			mutex_exit(&dpep->dpe_lock);
840 			kmem_free(pollfdp, uiosize);
841 			return (EINTR);
842 		}
843 	}
844 	dpep->dpe_writerwait--;
845 	dpep->dpe_flag |= DP_WRITER_PRESENT;
846 	dpep->dpe_refcnt++;
847 
848 	if (!is_epoll && (dpep->dpe_flag & DP_ISEPOLLCOMPAT) != 0) {
849 		/*
850 		 * The epoll compat mode was enabled while we were waiting to
851 		 * establish write access. It is not safe to continue since
852 		 * state was prepared for non-epoll operation.
853 		 */
854 		error = EBUSY;
855 		goto bypass;
856 	}
857 	mutex_exit(&dpep->dpe_lock);
858 
859 	/*
860 	 * Since the dpwrite() may recursively walk an added /dev/poll handle,
861 	 * pollstate_enter() deadlock and loop detection must be used.
862 	 */
863 	(void) pollstate_create();
864 	VERIFY(pollstate_enter(pcp) == PSE_SUCCESS);
865 
866 	if (pcp->pc_bitmap == NULL) {
867 		pcache_create(pcp, pollfdnum);
868 	}
869 	for (pfdp = pollfdp; (uintptr_t)pfdp < limit;
870 	    pfdp = (pollfd_t *)((uintptr_t)pfdp + size)) {
871 		int fd = pfdp->fd;
872 		polldat_t *pdp;
873 
874 		if ((uint_t)fd >= P_FINFO(curproc)->fi_nfiles) {
875 			/*
876 			 * epoll semantics demand that we return EBADF if our
877 			 * specified fd is invalid.
878 			 */
879 			if (is_epoll) {
880 				error = EBADF;
881 				break;
882 			}
883 
884 			continue;
885 		}
886 
887 		pdp = pcache_lookup_fd(pcp, fd);
888 		if (pfdp->events != POLLREMOVE) {
889 			uf_entry_gen_t gen;
890 			file_t *fp = NULL;
891 			struct pollhead *php = NULL;
892 
893 			/*
894 			 * If we're in epoll compatibility mode, check that the
895 			 * fd is valid before allocating anything for it; epoll
896 			 * semantics demand that we return EBADF if our
897 			 * specified fd is invalid.
898 			 */
899 			if (is_epoll) {
900 				if ((fp = getf_gen(fd, &gen)) == NULL) {
901 					error = EBADF;
902 					break;
903 				}
904 			}
905 			if (pdp == NULL) {
906 				pdp = pcache_alloc_fd(0);
907 				pdp->pd_fd = fd;
908 				pdp->pd_pcache = pcp;
909 				pcache_insert_fd(pcp, pdp, pollfdnum);
910 			}
911 
912 			if (is_epoll) {
913 				/*
914 				 * If the fd is already a member of the epoll
915 				 * set, error emission is needed only when the
916 				 * fd assignment generation matches the one
917 				 * recorded in the polldat_t.  Absence of such
918 				 * a generation match indicates that a new
919 				 * resource has been assigned at that fd.
920 				 *
921 				 * Caveat: It is possible to force a generation
922 				 * update while keeping the same backing
923 				 * resource.  This is possible via dup2, but
924 				 * does not represent real-world use cases,
925 				 * making the lack of error acceptable.
926 				 */
927 				if (pdp->pd_fp != NULL && pdp->pd_gen == gen) {
928 					error = EEXIST;
929 					releasef(fd);
930 					break;
931 				}
932 
933 				/*
934 				 * We have decided that the cached information
935 				 * was stale.  Reset pd_events to assure that
936 				 * we don't mistakenly operate on cached event
937 				 * disposition.  This configures the implicit
938 				 * subscription to HUP and ERR events which
939 				 * epoll features.
940 				 */
941 				pdp->pd_events = POLLERR|POLLHUP;
942 
943 				epfdp = (dvpoll_epollfd_t *)pfdp;
944 				pdp->pd_epolldata = epfdp->dpep_data;
945 			}
946 
947 			ASSERT(pdp->pd_fd == fd);
948 			ASSERT(pdp->pd_pcache == pcp);
949 			if (fd >= pcp->pc_mapsize) {
950 				mutex_exit(&pcp->pc_lock);
951 				pcache_grow_map(pcp, fd);
952 				mutex_enter(&pcp->pc_lock);
953 			}
954 			if (fd > pcp->pc_mapend) {
955 				pcp->pc_mapend = fd;
956 			}
957 
958 			if (!is_epoll) {
959 				ASSERT(fp == NULL);
960 
961 				if ((fp = getf_gen(fd, &gen)) == NULL) {
962 					/*
963 					 * The fd is not valid. Since we can't
964 					 * pass this error back in the write()
965 					 * call, set the bit in bitmap to force
966 					 * DP_POLL ioctl to examine it.
967 					 */
968 					BT_SET(pcp->pc_bitmap, fd);
969 					pdp->pd_events |= pfdp->events;
970 					continue;
971 				}
972 				/*
973 				 * Don't do VOP_POLL for an already cached fd
974 				 * with same poll events.
975 				 */
976 				if ((pdp->pd_events == pfdp->events) &&
977 				    (pdp->pd_fp == fp)) {
978 					/*
979 					 * the events are already cached
980 					 */
981 					releasef(fd);
982 					continue;
983 				}
984 			}
985 
986 
987 			/*
988 			 * do VOP_POLL and cache this poll fd.
989 			 */
990 			/*
991 			 * XXX - pollrelock() logic needs to know which
992 			 * which pollcache lock to grab. It'd be a
993 			 * cleaner solution if we could pass pcp as
994 			 * an arguement in VOP_POLL interface instead
995 			 * of implicitly passing it using thread_t
996 			 * struct. On the other hand, changing VOP_POLL
997 			 * interface will require all driver/file system
998 			 * poll routine to change. May want to revisit
999 			 * the tradeoff later.
1000 			 */
1001 			curthread->t_pollcache = pcp;
1002 			error = VOP_POLL(fp->f_vnode, pfdp->events, 0,
1003 			    &pfdp->revents, &php, NULL);
1004 
1005 			/*
1006 			 * Edge-triggered polling requires a pollhead in order
1007 			 * to initiate wake-ups properly.  Drivers which are
1008 			 * savvy to POLLET presence, which should include
1009 			 * everything in-gate, will always emit one, regardless
1010 			 * of revent status.  Older drivers which only emit a
1011 			 * pollhead if 'revents == 0' are given a second chance
1012 			 * here via a second VOP_POLL, with only POLLET set in
1013 			 * the events of interest.  These circumstances should
1014 			 * induce any cacheable drivers to emit a pollhead for
1015 			 * wake-ups.
1016 			 *
1017 			 * Drivers which never emit a pollhead will simply
1018 			 * disobey the expectation of edge-triggered behavior.
1019 			 * This includes recursive epoll which, even on Linux,
1020 			 * yields its events in a level-triggered fashion only.
1021 			 */
1022 			if ((pfdp->events & POLLET) != 0 && error == 0 &&
1023 			    php == NULL) {
1024 				short levent = 0;
1025 
1026 				error = VOP_POLL(fp->f_vnode, POLLET, 0,
1027 				    &levent, &php, NULL);
1028 			}
1029 
1030 			curthread->t_pollcache = NULL;
1031 			/*
1032 			 * We always set the bit when this fd is cached;
1033 			 * this forces the first DP_POLL to poll this fd.
1034 			 * Real performance gain comes from subsequent
1035 			 * DP_POLL.  We also attempt a polldat_associate();
1036 			 * if it's not possible, we'll do it in dpioctl().
1037 			 */
1038 			BT_SET(pcp->pc_bitmap, fd);
1039 			if (error != 0) {
1040 				releasef(fd);
1041 				break;
1042 			}
1043 			pdp->pd_fp = fp;
1044 			pdp->pd_gen = gen;
1045 			pdp->pd_events |= pfdp->events;
1046 			if (php != NULL) {
1047 				if (pdp->pd_php == NULL) {
1048 					polldat_associate(pdp, php);
1049 				} else {
1050 					if (pdp->pd_php != php) {
1051 						polldat_disassociate(pdp);
1052 						polldat_associate(pdp, php);
1053 					}
1054 				}
1055 			}
1056 			fds_added = B_TRUE;
1057 			releasef(fd);
1058 		} else {
1059 			if (pdp == NULL || pdp->pd_fp == NULL) {
1060 				if (is_epoll) {
1061 					/*
1062 					 * As with the add case (above), epoll
1063 					 * semantics demand that we error out
1064 					 * in this case.
1065 					 */
1066 					error = ENOENT;
1067 					break;
1068 				}
1069 
1070 				continue;
1071 			}
1072 			ASSERT(pdp->pd_fd == fd);
1073 			pdp->pd_fp = NULL;
1074 			pdp->pd_events = 0;
1075 			ASSERT(pdp->pd_thread == NULL);
1076 			polldat_disassociate(pdp);
1077 			BT_CLEAR(pcp->pc_bitmap, fd);
1078 		}
1079 	}
1080 	/*
1081 	 * Wake any pollcache waiters so they can check the new descriptors.
1082 	 *
1083 	 * Any fds added to an recursive-capable pollcache could themselves be
1084 	 * /dev/poll handles. To ensure that proper event propagation occurs,
1085 	 * parent pollcaches are woken too, so that they can create any needed
1086 	 * pollcache links.
1087 	 */
1088 	if (fds_added) {
1089 		cv_broadcast(&pcp->pc_cv);
1090 		pcache_wake_parents(pcp);
1091 	}
1092 	pollstate_exit(pcp);
1093 	mutex_enter(&dpep->dpe_lock);
1094 bypass:
1095 	dpep->dpe_flag &= ~DP_WRITER_PRESENT;
1096 	dpep->dpe_refcnt--;
1097 	cv_broadcast(&dpep->dpe_cv);
1098 	mutex_exit(&dpep->dpe_lock);
1099 	kmem_free(pollfdp, uiosize);
1100 	if (error == 0) {
1101 		/*
1102 		 * The state of uio_resid is updated only after the pollcache
1103 		 * is successfully modified.
1104 		 */
1105 		uioskip(uiop, copysize);
1106 	}
1107 	return (error);
1108 }
1109 
1110 #define	DP_SIGMASK_RESTORE(ksetp) {					\
1111 	if (ksetp != NULL) {						\
1112 		mutex_enter(&p->p_lock);				\
1113 		if (lwp->lwp_cursig == 0) {				\
1114 			t->t_hold = lwp->lwp_sigoldmask;		\
1115 			t->t_flag &= ~T_TOMASK;				\
1116 		}							\
1117 		mutex_exit(&p->p_lock);					\
1118 	}								\
1119 }
1120 
1121 /*ARGSUSED*/
1122 static int
1123 dpioctl(dev_t dev, int cmd, intptr_t arg, int mode, cred_t *credp, int *rvalp)
1124 {
1125 	minor_t		minor;
1126 	dp_entry_t	*dpep;
1127 	pollcache_t	*pcp;
1128 	hrtime_t	now;
1129 	int		error = 0;
1130 	boolean_t	is_epoll;
1131 	STRUCT_DECL(dvpoll, dvpoll);
1132 
1133 	if (cmd == DP_POLL || cmd == DP_PPOLL) {
1134 		/* do this now, before we sleep on DP_WRITER_PRESENT */
1135 		now = gethrtime();
1136 	}
1137 
1138 	minor = getminor(dev);
1139 	mutex_enter(&devpoll_lock);
1140 	ASSERT(minor < dptblsize);
1141 	dpep = devpolltbl[minor];
1142 	mutex_exit(&devpoll_lock);
1143 	ASSERT(dpep != NULL);
1144 	pcp = dpep->dpe_pcache;
1145 
1146 	mutex_enter(&dpep->dpe_lock);
1147 	is_epoll = (dpep->dpe_flag & DP_ISEPOLLCOMPAT) != 0;
1148 
1149 	if (cmd == DP_EPOLLCOMPAT) {
1150 		if (dpep->dpe_refcnt != 0) {
1151 			/*
1152 			 * We can't turn on epoll compatibility while there
1153 			 * are outstanding operations.
1154 			 */
1155 			mutex_exit(&dpep->dpe_lock);
1156 			return (EBUSY);
1157 		}
1158 
1159 		/*
1160 		 * epoll compatibility is a one-way street: there's no way
1161 		 * to turn it off for a particular open.
1162 		 */
1163 		dpep->dpe_flag |= DP_ISEPOLLCOMPAT;
1164 
1165 		/* Record the epoll-enabled nature in the pollcache too */
1166 		mutex_enter(&pcp->pc_lock);
1167 		pcp->pc_flag |= PC_EPOLL;
1168 		mutex_exit(&pcp->pc_lock);
1169 
1170 		mutex_exit(&dpep->dpe_lock);
1171 		return (0);
1172 	}
1173 
1174 	if (!is_epoll && curproc->p_pid != pcp->pc_pid) {
1175 		if (pcp->pc_pid != -1) {
1176 			mutex_exit(&dpep->dpe_lock);
1177 			return (EACCES);
1178 		}
1179 
1180 		pcp->pc_pid = curproc->p_pid;
1181 	}
1182 
1183 	/* Wait until all writers have cleared the handle before continuing */
1184 	while ((dpep->dpe_flag & DP_WRITER_PRESENT) != 0 ||
1185 	    (dpep->dpe_writerwait != 0)) {
1186 		if (!cv_wait_sig_swap(&dpep->dpe_cv, &dpep->dpe_lock)) {
1187 			mutex_exit(&dpep->dpe_lock);
1188 			return (EINTR);
1189 		}
1190 	}
1191 	dpep->dpe_refcnt++;
1192 	mutex_exit(&dpep->dpe_lock);
1193 
1194 	switch (cmd) {
1195 	case	DP_POLL:
1196 	case	DP_PPOLL:
1197 	{
1198 		pollstate_t	*ps;
1199 		nfds_t		nfds;
1200 		int		fdcnt = 0;
1201 		size_t		size, fdsize, dpsize;
1202 		hrtime_t	deadline = 0;
1203 		k_sigset_t	*ksetp = NULL;
1204 		k_sigset_t	kset;
1205 		sigset_t	set;
1206 		kthread_t	*t = curthread;
1207 		klwp_t		*lwp = ttolwp(t);
1208 		struct proc	*p = ttoproc(curthread);
1209 
1210 		STRUCT_INIT(dvpoll, mode);
1211 
1212 		/*
1213 		 * The dp_setp member is only required/consumed for DP_PPOLL,
1214 		 * which otherwise uses the same structure as DP_POLL.
1215 		 */
1216 		if (cmd == DP_POLL) {
1217 			dpsize = (uintptr_t)STRUCT_FADDR(dvpoll, dp_setp) -
1218 			    (uintptr_t)STRUCT_FADDR(dvpoll, dp_fds);
1219 		} else {
1220 			ASSERT(cmd == DP_PPOLL);
1221 			dpsize = STRUCT_SIZE(dvpoll);
1222 		}
1223 
1224 		if ((mode & FKIOCTL) != 0) {
1225 			/* Kernel-internal ioctl call */
1226 			bcopy((caddr_t)arg, STRUCT_BUF(dvpoll), dpsize);
1227 			error = 0;
1228 		} else {
1229 			error = copyin((caddr_t)arg, STRUCT_BUF(dvpoll),
1230 			    dpsize);
1231 		}
1232 
1233 		if (error) {
1234 			DP_REFRELE(dpep);
1235 			return (EFAULT);
1236 		}
1237 
1238 		deadline = STRUCT_FGET(dvpoll, dp_timeout);
1239 		if (deadline > 0) {
1240 			/*
1241 			 * Convert the deadline from relative milliseconds
1242 			 * to absolute nanoseconds.  They must wait for at
1243 			 * least a tick.
1244 			 */
1245 			deadline = MSEC2NSEC(deadline);
1246 			deadline = MAX(deadline, nsec_per_tick);
1247 			deadline += now;
1248 		}
1249 
1250 		if (cmd == DP_PPOLL) {
1251 			void *setp = STRUCT_FGETP(dvpoll, dp_setp);
1252 
1253 			if (setp != NULL) {
1254 				if ((mode & FKIOCTL) != 0) {
1255 					/* Use the signal set directly */
1256 					ksetp = (k_sigset_t *)setp;
1257 				} else {
1258 					if (copyin(setp, &set, sizeof (set))) {
1259 						DP_REFRELE(dpep);
1260 						return (EFAULT);
1261 					}
1262 					sigutok(&set, &kset);
1263 					ksetp = &kset;
1264 				}
1265 
1266 				mutex_enter(&p->p_lock);
1267 				schedctl_finish_sigblock(t);
1268 				lwp->lwp_sigoldmask = t->t_hold;
1269 				t->t_hold = *ksetp;
1270 				t->t_flag |= T_TOMASK;
1271 
1272 				/*
1273 				 * Like ppoll() with a non-NULL sigset, we'll
1274 				 * call cv_reltimedwait_sig() just to check for
1275 				 * signals.  This call will return immediately
1276 				 * with either 0 (signalled) or -1 (no signal).
1277 				 * There are some conditions whereby we can
1278 				 * get 0 from cv_reltimedwait_sig() without
1279 				 * a true signal (e.g., a directed stop), so
1280 				 * we restore our signal mask in the unlikely
1281 				 * event that lwp_cursig is 0.
1282 				 */
1283 				if (!cv_reltimedwait_sig(&t->t_delay_cv,
1284 				    &p->p_lock, 0, TR_CLOCK_TICK)) {
1285 					if (lwp->lwp_cursig == 0) {
1286 						t->t_hold = lwp->lwp_sigoldmask;
1287 						t->t_flag &= ~T_TOMASK;
1288 					}
1289 
1290 					mutex_exit(&p->p_lock);
1291 
1292 					DP_REFRELE(dpep);
1293 					return (EINTR);
1294 				}
1295 
1296 				mutex_exit(&p->p_lock);
1297 			}
1298 		}
1299 
1300 		if ((nfds = STRUCT_FGET(dvpoll, dp_nfds)) == 0) {
1301 			/*
1302 			 * We are just using DP_POLL to sleep, so
1303 			 * we don't any of the devpoll apparatus.
1304 			 * Do not check for signals if we have a zero timeout.
1305 			 */
1306 			DP_REFRELE(dpep);
1307 			if (deadline == 0) {
1308 				DP_SIGMASK_RESTORE(ksetp);
1309 				return (0);
1310 			}
1311 
1312 			mutex_enter(&curthread->t_delay_lock);
1313 			while ((error =
1314 			    cv_timedwait_sig_hrtime(&curthread->t_delay_cv,
1315 			    &curthread->t_delay_lock, deadline)) > 0)
1316 				continue;
1317 			mutex_exit(&curthread->t_delay_lock);
1318 
1319 			DP_SIGMASK_RESTORE(ksetp);
1320 
1321 			return (error == 0 ? EINTR : 0);
1322 		}
1323 
1324 		fdsize = is_epoll ?
1325 		    sizeof (epoll_event_t) : sizeof (pollfd_t);
1326 
1327 		/*
1328 		 * Guard against integer overflow in the nfds * fdsize
1329 		 * calculation below. Without this check, a sufficiently
1330 		 * large nfds could overflow to a small size, bypassing the
1331 		 * buffer reallocation and allowing a heap overflow.
1332 		 */
1333 		if (nfds > SIZE_MAX / fdsize) {
1334 			DP_REFRELE(dpep);
1335 			DP_SIGMASK_RESTORE(ksetp);
1336 			return (EINVAL);
1337 		}
1338 
1339 		size = nfds * fdsize;
1340 
1341 		/*
1342 		 * XXX It would be nice not to have to alloc each time, but it
1343 		 * requires another per thread structure hook. This can be
1344 		 * implemented later if data suggests that it's necessary.
1345 		 */
1346 		ps = pollstate_create();
1347 
1348 		if (ps->ps_dpbufsize < size) {
1349 			/*
1350 			 * If nfds is larger than twice the current maximum
1351 			 * open file count, we'll silently clamp it.  This
1352 			 * only limits our exposure to allocating an
1353 			 * inordinate amount of kernel memory; it doesn't
1354 			 * otherwise affect the semantics.  (We have this
1355 			 * check at twice the maximum instead of merely the
1356 			 * maximum because some applications pass an nfds that
1357 			 * is only slightly larger than their limit.)
1358 			 */
1359 			mutex_enter(&p->p_lock);
1360 			if ((nfds >> 1) > p->p_fno_ctl) {
1361 				nfds = p->p_fno_ctl;
1362 				size = nfds * fdsize;
1363 			}
1364 			mutex_exit(&p->p_lock);
1365 
1366 			if (ps->ps_dpbufsize < size) {
1367 				kmem_free(ps->ps_dpbuf, ps->ps_dpbufsize);
1368 				ps->ps_dpbuf = kmem_zalloc(size, KM_SLEEP);
1369 				ps->ps_dpbufsize = size;
1370 			}
1371 		}
1372 
1373 		VERIFY(pollstate_enter(pcp) == PSE_SUCCESS);
1374 		for (;;) {
1375 			pcp->pc_flag &= ~PC_POLLWAKE;
1376 
1377 			/*
1378 			 * Mark all child pcachelinks as stale.
1379 			 * Those which are still part of the tree will be
1380 			 * marked as valid during the poll.
1381 			 */
1382 			pcachelink_mark_stale(pcp);
1383 
1384 			error = dp_pcache_poll(dpep, ps->ps_dpbuf,
1385 			    pcp, nfds, &fdcnt);
1386 			if (fdcnt > 0 || error != 0)
1387 				break;
1388 
1389 			/* Purge still-stale child pcachelinks */
1390 			pcachelink_purge_stale(pcp);
1391 
1392 			/*
1393 			 * A pollwake has happened since we polled cache.
1394 			 */
1395 			if (pcp->pc_flag & PC_POLLWAKE)
1396 				continue;
1397 
1398 			/*
1399 			 * Sleep until we are notified, signaled, or timed out.
1400 			 */
1401 			if (deadline == 0) {
1402 				/* immediate timeout; do not check signals */
1403 				break;
1404 			}
1405 
1406 			error = cv_timedwait_sig_hrtime(&pcp->pc_cv,
1407 			    &pcp->pc_lock, deadline);
1408 
1409 			/*
1410 			 * If we were awakened by a signal or timeout then
1411 			 * break the loop, else poll again.
1412 			 */
1413 			if (error <= 0) {
1414 				error = (error == 0) ? EINTR : 0;
1415 				break;
1416 			} else {
1417 				error = 0;
1418 			}
1419 		}
1420 		pollstate_exit(pcp);
1421 
1422 		DP_SIGMASK_RESTORE(ksetp);
1423 
1424 		if (error == 0 && fdcnt > 0) {
1425 			/*
1426 			 * It should be noted that FKIOCTL does not influence
1427 			 * the copyout (vs bcopy) of dp_fds at this time.
1428 			 */
1429 			if (copyout(ps->ps_dpbuf,
1430 			    STRUCT_FGETP(dvpoll, dp_fds), fdcnt * fdsize)) {
1431 				DP_REFRELE(dpep);
1432 				return (EFAULT);
1433 			}
1434 			*rvalp = fdcnt;
1435 		}
1436 		break;
1437 	}
1438 
1439 	case	DP_ISPOLLED:
1440 	{
1441 		pollfd_t	pollfd;
1442 		polldat_t	*pdp;
1443 
1444 		STRUCT_INIT(dvpoll, mode);
1445 		error = copyin((caddr_t)arg, &pollfd, sizeof (pollfd_t));
1446 		if (error) {
1447 			DP_REFRELE(dpep);
1448 			return (EFAULT);
1449 		}
1450 		mutex_enter(&pcp->pc_lock);
1451 		if (pcp->pc_hash == NULL) {
1452 			/*
1453 			 * No Need to search because no poll fd
1454 			 * has been cached.
1455 			 */
1456 			mutex_exit(&pcp->pc_lock);
1457 			DP_REFRELE(dpep);
1458 			return (0);
1459 		}
1460 		if (pollfd.fd < 0) {
1461 			mutex_exit(&pcp->pc_lock);
1462 			break;
1463 		}
1464 		pdp = pcache_lookup_fd(pcp, pollfd.fd);
1465 		if ((pdp != NULL) && (pdp->pd_fd == pollfd.fd) &&
1466 		    (pdp->pd_fp != NULL)) {
1467 			pollfd.revents = pdp->pd_events;
1468 			if (copyout(&pollfd, (caddr_t)arg, sizeof (pollfd_t))) {
1469 				mutex_exit(&pcp->pc_lock);
1470 				DP_REFRELE(dpep);
1471 				return (EFAULT);
1472 			}
1473 			*rvalp = 1;
1474 		}
1475 		mutex_exit(&pcp->pc_lock);
1476 		break;
1477 	}
1478 
1479 	default:
1480 		DP_REFRELE(dpep);
1481 		return (EINVAL);
1482 	}
1483 	DP_REFRELE(dpep);
1484 	return (error);
1485 }
1486 
1487 /*
1488  * Overview of Recursive Polling
1489  *
1490  * It is possible for /dev/poll to poll for events on file descriptors which
1491  * themselves are /dev/poll handles.  Pending events in the child handle are
1492  * represented as readable data via the POLLIN flag.  To limit surface area,
1493  * this recursion is presently allowed on only /dev/poll handles which have
1494  * been placed in epoll mode via the DP_EPOLLCOMPAT ioctl.  Recursion depth is
1495  * limited to 5 in order to be consistent with Linux epoll.
1496  *
1497  * Extending dppoll() for VOP_POLL:
1498  *
1499  * The recursive /dev/poll implementation begins by extending dppoll() to
1500  * report when resources contained in the pollcache have relevant event state.
1501  * At the highest level, it means calling dp_pcache_poll() so it indicates if
1502  * fd events are present without consuming them or altering the pollcache
1503  * bitmap.  This ensures that a subsequent DP_POLL operation on the bitmap will
1504  * yield the initiating event.  Additionally, the VOP_POLL should return in
1505  * such a way that dp_pcache_poll() does not clear the parent bitmap entry
1506  * which corresponds to the child /dev/poll fd.  This means that child
1507  * pollcaches will be checked during every poll which facilitates wake-up
1508  * behavior detailed below.
1509  *
1510  * Pollcache Links and Wake Events:
1511  *
1512  * Recursive /dev/poll avoids complicated pollcache locking constraints during
1513  * pollwakeup events by eschewing the traditional pollhead mechanism in favor
1514  * of a different approach.  For each pollcache at the root of a recursive
1515  * /dev/poll "tree", pcachelink_t structures are established to all child
1516  * /dev/poll pollcaches.  During pollnotify() in a child pollcache, the
1517  * linked list of pcachelink_t entries is walked, where those marked as valid
1518  * incur a cv_broadcast to their parent pollcache.  Most notably, these
1519  * pcachelink_t cv wakeups are performed without acquiring pc_lock on the
1520  * parent pollcache (which would require careful deadlock avoidance).  This
1521  * still allows the woken poll on the parent to discover the pertinent events
1522  * due to the fact that bitmap entires for the child pollcache are always
1523  * maintained by the dppoll() logic above.
1524  *
1525  * Depth Limiting and Loop Prevention:
1526  *
1527  * As each pollcache is encountered (either via DP_POLL or dppoll()), depth and
1528  * loop constraints are enforced via pollstate_enter().  The pollcache_t
1529  * pointer is compared against any existing entries in ps_pc_stack and is added
1530  * to the end if no match (and therefore loop) is found.  Once poll operations
1531  * for a given pollcache_t are complete, pollstate_exit() clears the pointer
1532  * from the list.  The pollstate_enter() and pollstate_exit() functions are
1533  * responsible for acquiring and releasing pc_lock, respectively.
1534  *
1535  * Deadlock Safety:
1536  *
1537  * Descending through a tree of recursive /dev/poll handles involves the tricky
1538  * business of sequentially entering multiple pollcache locks.  This tree
1539  * topology cannot define a lock acquisition order in such a way that it is
1540  * immune to deadlocks between threads.  The pollstate_enter() and
1541  * pollstate_exit() functions provide an interface for recursive /dev/poll
1542  * operations to safely lock pollcaches while failing gracefully in the face of
1543  * deadlocking topologies. (See pollstate_contend() for more detail about how
1544  * deadlocks are detected and resolved.)
1545  */
1546 
1547 /*ARGSUSED*/
1548 static int
1549 dppoll(dev_t dev, short events, int anyyet, short *reventsp,
1550     struct pollhead **phpp)
1551 {
1552 	minor_t		minor;
1553 	dp_entry_t	*dpep;
1554 	pollcache_t	*pcp;
1555 	int		res, rc = 0;
1556 
1557 	minor = getminor(dev);
1558 	mutex_enter(&devpoll_lock);
1559 	ASSERT(minor < dptblsize);
1560 	dpep = devpolltbl[minor];
1561 	ASSERT(dpep != NULL);
1562 	mutex_exit(&devpoll_lock);
1563 
1564 	mutex_enter(&dpep->dpe_lock);
1565 	if ((dpep->dpe_flag & DP_ISEPOLLCOMPAT) == 0) {
1566 		/* Poll recursion is not yet supported for non-epoll handles */
1567 		*reventsp = POLLERR;
1568 		mutex_exit(&dpep->dpe_lock);
1569 		return (0);
1570 	} else {
1571 		dpep->dpe_refcnt++;
1572 		pcp = dpep->dpe_pcache;
1573 		mutex_exit(&dpep->dpe_lock);
1574 	}
1575 
1576 	res = pollstate_enter(pcp);
1577 	if (res == PSE_SUCCESS) {
1578 		nfds_t		nfds = 1;
1579 		int		fdcnt = 0;
1580 		pollstate_t	*ps = curthread->t_pollstate;
1581 
1582 		/*
1583 		 * Recursive polling will only emit certain events.  Skip a
1584 		 * scan of the pollcache if those events are not of interest.
1585 		 */
1586 		if (events & (POLLIN|POLLRDNORM)) {
1587 			rc = dp_pcache_poll(dpep, NULL, pcp, nfds, &fdcnt);
1588 		} else {
1589 			rc = 0;
1590 			fdcnt = 0;
1591 		}
1592 
1593 		if (rc == 0 && fdcnt > 0) {
1594 			*reventsp = POLLIN|POLLRDNORM;
1595 		} else {
1596 			*reventsp = 0;
1597 		}
1598 		pcachelink_assoc(pcp, ps->ps_pc_stack[0]);
1599 		pollstate_exit(pcp);
1600 	} else {
1601 		switch (res) {
1602 		case PSE_FAIL_DEPTH:
1603 			rc = EINVAL;
1604 			break;
1605 		case PSE_FAIL_LOOP:
1606 		case PSE_FAIL_DEADLOCK:
1607 			rc = ELOOP;
1608 			break;
1609 		default:
1610 			/*
1611 			 * If anything else has gone awry, such as being polled
1612 			 * from an unexpected context, fall back to the
1613 			 * recursion-intolerant response.
1614 			 */
1615 			*reventsp = POLLERR;
1616 			rc = 0;
1617 			break;
1618 		}
1619 	}
1620 
1621 	DP_REFRELE(dpep);
1622 	return (rc);
1623 }
1624 
1625 /*
1626  * devpoll close should do enough clean up before the pollcache is deleted,
1627  * i.e., it should ensure no one still references the pollcache later.
1628  * There is no "permission" check in here. Any process having the last
1629  * reference of this /dev/poll fd can close.
1630  */
1631 /*ARGSUSED*/
1632 static int
1633 dpclose(dev_t dev, int flag, int otyp, cred_t *credp)
1634 {
1635 	minor_t		minor;
1636 	dp_entry_t	*dpep;
1637 	pollcache_t	*pcp;
1638 	int		i;
1639 	polldat_t	**hashtbl;
1640 	polldat_t	*pdp;
1641 
1642 	minor = getminor(dev);
1643 
1644 	mutex_enter(&devpoll_lock);
1645 	dpep = devpolltbl[minor];
1646 	ASSERT(dpep != NULL);
1647 	devpolltbl[minor] = NULL;
1648 	mutex_exit(&devpoll_lock);
1649 	pcp = dpep->dpe_pcache;
1650 	ASSERT(pcp != NULL);
1651 	/*
1652 	 * At this point, no other lwp can access this pollcache via the
1653 	 * /dev/poll fd. This pollcache is going away, so do the clean
1654 	 * up without the pc_lock.
1655 	 */
1656 	hashtbl = pcp->pc_hash;
1657 	for (i = 0; i < pcp->pc_hashsize; i++) {
1658 		for (pdp = hashtbl[i]; pdp; pdp = pdp->pd_hashnext) {
1659 			polldat_disassociate(pdp);
1660 			pdp->pd_fp = NULL;
1661 		}
1662 	}
1663 	/*
1664 	 * pollwakeup() may still interact with this pollcache. Wait until
1665 	 * it is done.
1666 	 */
1667 	mutex_enter(&pcp->pc_no_exit);
1668 	ASSERT(pcp->pc_busy >= 0);
1669 	while (pcp->pc_busy > 0)
1670 		cv_wait(&pcp->pc_busy_cv, &pcp->pc_no_exit);
1671 	mutex_exit(&pcp->pc_no_exit);
1672 
1673 	/* Clean up any pollcache links created via recursive /dev/poll */
1674 	if (pcp->pc_parents != NULL || pcp->pc_children != NULL) {
1675 		/*
1676 		 * Because of the locking rules for pcachelink manipulation,
1677 		 * acquring pc_lock is required for this step.
1678 		 */
1679 		mutex_enter(&pcp->pc_lock);
1680 		pcachelink_purge_all(pcp);
1681 		mutex_exit(&pcp->pc_lock);
1682 	}
1683 
1684 	pcache_destroy(pcp);
1685 	ASSERT(dpep->dpe_refcnt == 0);
1686 	kmem_free(dpep, sizeof (dp_entry_t));
1687 	return (0);
1688 }
1689 
1690 static void
1691 pcachelink_locked_rele(pcachelink_t *pl)
1692 {
1693 	ASSERT(MUTEX_HELD(&pl->pcl_lock));
1694 	VERIFY(pl->pcl_refcnt >= 1);
1695 
1696 	pl->pcl_refcnt--;
1697 	if (pl->pcl_refcnt == 0) {
1698 		VERIFY(pl->pcl_state == PCL_INVALID);
1699 		ASSERT(pl->pcl_parent_pc == NULL);
1700 		ASSERT(pl->pcl_child_pc == NULL);
1701 		ASSERT(pl->pcl_parent_next == NULL);
1702 		ASSERT(pl->pcl_child_next == NULL);
1703 
1704 		pl->pcl_state = PCL_FREE;
1705 		mutex_destroy(&pl->pcl_lock);
1706 		kmem_free(pl, sizeof (pcachelink_t));
1707 	} else {
1708 		mutex_exit(&pl->pcl_lock);
1709 	}
1710 }
1711 
1712 /*
1713  * Associate parent and child pollcaches via a pcachelink_t.  If an existing
1714  * link (stale or valid) between the two is found, it will be reused.  If a
1715  * suitable link is not found for reuse, a new one will be allocated.
1716  */
1717 static void
1718 pcachelink_assoc(pollcache_t *child, pollcache_t *parent)
1719 {
1720 	pcachelink_t	*pl, **plpn;
1721 
1722 	ASSERT(MUTEX_HELD(&child->pc_lock));
1723 	ASSERT(MUTEX_HELD(&parent->pc_lock));
1724 
1725 	/* Search for an existing link we can reuse. */
1726 	plpn = &child->pc_parents;
1727 	for (pl = child->pc_parents; pl != NULL; pl = *plpn) {
1728 		mutex_enter(&pl->pcl_lock);
1729 		if (pl->pcl_state == PCL_INVALID) {
1730 			/* Clean any invalid links while walking the list */
1731 			*plpn = pl->pcl_parent_next;
1732 			pl->pcl_child_pc = NULL;
1733 			pl->pcl_parent_next = NULL;
1734 			pcachelink_locked_rele(pl);
1735 		} else if (pl->pcl_parent_pc == parent) {
1736 			/* Successfully found parent link */
1737 			ASSERT(pl->pcl_state == PCL_VALID ||
1738 			    pl->pcl_state == PCL_STALE);
1739 			pl->pcl_state = PCL_VALID;
1740 			mutex_exit(&pl->pcl_lock);
1741 			return;
1742 		} else {
1743 			plpn = &pl->pcl_parent_next;
1744 			mutex_exit(&pl->pcl_lock);
1745 		}
1746 	}
1747 
1748 	/* No existing link to the parent was found.  Create a fresh one. */
1749 	pl = kmem_zalloc(sizeof (pcachelink_t), KM_SLEEP);
1750 	mutex_init(&pl->pcl_lock,  NULL, MUTEX_DEFAULT, NULL);
1751 
1752 	pl->pcl_parent_pc = parent;
1753 	pl->pcl_child_next = parent->pc_children;
1754 	parent->pc_children = pl;
1755 	pl->pcl_refcnt++;
1756 
1757 	pl->pcl_child_pc = child;
1758 	pl->pcl_parent_next = child->pc_parents;
1759 	child->pc_parents = pl;
1760 	pl->pcl_refcnt++;
1761 
1762 	pl->pcl_state = PCL_VALID;
1763 }
1764 
1765 /*
1766  * Mark all child links in a pollcache as stale.  Any invalid child links found
1767  * during iteration are purged.
1768  */
1769 static void
1770 pcachelink_mark_stale(pollcache_t *pcp)
1771 {
1772 	pcachelink_t	*pl, **plpn;
1773 
1774 	ASSERT(MUTEX_HELD(&pcp->pc_lock));
1775 
1776 	plpn = &pcp->pc_children;
1777 	for (pl = pcp->pc_children; pl != NULL; pl = *plpn) {
1778 		mutex_enter(&pl->pcl_lock);
1779 		if (pl->pcl_state == PCL_INVALID) {
1780 			/*
1781 			 * Remove any invalid links while we are going to the
1782 			 * trouble of walking the list.
1783 			 */
1784 			*plpn = pl->pcl_child_next;
1785 			pl->pcl_parent_pc = NULL;
1786 			pl->pcl_child_next = NULL;
1787 			pcachelink_locked_rele(pl);
1788 		} else {
1789 			pl->pcl_state = PCL_STALE;
1790 			plpn = &pl->pcl_child_next;
1791 			mutex_exit(&pl->pcl_lock);
1792 		}
1793 	}
1794 }
1795 
1796 /*
1797  * Purge all stale (or invalid) child links from a pollcache.
1798  */
1799 static void
1800 pcachelink_purge_stale(pollcache_t *pcp)
1801 {
1802 	pcachelink_t	*pl, **plpn;
1803 
1804 	ASSERT(MUTEX_HELD(&pcp->pc_lock));
1805 
1806 	plpn = &pcp->pc_children;
1807 	for (pl = pcp->pc_children; pl != NULL; pl = *plpn) {
1808 		mutex_enter(&pl->pcl_lock);
1809 		switch (pl->pcl_state) {
1810 		case PCL_STALE:
1811 			pl->pcl_state = PCL_INVALID;
1812 			/* FALLTHROUGH */
1813 		case PCL_INVALID:
1814 			*plpn = pl->pcl_child_next;
1815 			pl->pcl_parent_pc = NULL;
1816 			pl->pcl_child_next = NULL;
1817 			pcachelink_locked_rele(pl);
1818 			break;
1819 		default:
1820 			plpn = &pl->pcl_child_next;
1821 			mutex_exit(&pl->pcl_lock);
1822 		}
1823 	}
1824 }
1825 
1826 /*
1827  * Purge all child and parent links from a pollcache, regardless of status.
1828  */
1829 static void
1830 pcachelink_purge_all(pollcache_t *pcp)
1831 {
1832 	pcachelink_t	*pl, **plpn;
1833 
1834 	ASSERT(MUTEX_HELD(&pcp->pc_lock));
1835 
1836 	plpn = &pcp->pc_parents;
1837 	for (pl = pcp->pc_parents; pl != NULL; pl = *plpn) {
1838 		mutex_enter(&pl->pcl_lock);
1839 		pl->pcl_state = PCL_INVALID;
1840 		*plpn = pl->pcl_parent_next;
1841 		pl->pcl_child_pc = NULL;
1842 		pl->pcl_parent_next = NULL;
1843 		pcachelink_locked_rele(pl);
1844 	}
1845 
1846 	plpn = &pcp->pc_children;
1847 	for (pl = pcp->pc_children; pl != NULL; pl = *plpn) {
1848 		mutex_enter(&pl->pcl_lock);
1849 		pl->pcl_state = PCL_INVALID;
1850 		*plpn = pl->pcl_child_next;
1851 		pl->pcl_parent_pc = NULL;
1852 		pl->pcl_child_next = NULL;
1853 		pcachelink_locked_rele(pl);
1854 	}
1855 
1856 	ASSERT(pcp->pc_parents == NULL);
1857 	ASSERT(pcp->pc_children == NULL);
1858 }
1859