#include <sys/atomic.h>
#include <sys/cmn_err.h>
#include <sys/id_space.h>
#include <sys/kmem.h>
#include <sys/kstat.h>
#include <sys/log.h>
#include <sys/modctl.h>
#include <sys/modhash.h>
#include <sys/mutex.h>
#include <sys/proc.h>
#include <sys/procset.h>
#include <sys/project.h>
#include <sys/resource.h>
#include <sys/rctl.h>
#include <sys/siginfo.h>
#include <sys/strlog.h>
#include <sys/systm.h>
#include <sys/task.h>
#include <sys/types.h>
#include <sys/policy.h>
#include <sys/zone.h>
id_t max_rctl_hndl = 32768;
int rctl_dict_size = 64;
int rctl_set_size = 8;
kmutex_t rctl_dict_lock;
mod_hash_t *rctl_dict;
mod_hash_t *rctl_dict_by_name;
id_space_t *rctl_ids;
kmem_cache_t *rctl_cache;
kmem_cache_t *rctl_val_cache;
kmutex_t rctl_lists_lock;
rctl_dict_entry_t *rctl_lists[RC_MAX_ENTITY + 1];
void
rcop_no_action(struct rctl *r, struct proc *p, rctl_entity_p_t *e)
{
}
rctl_qty_t
rcop_no_usage(struct rctl *r, struct proc *p)
{
return (0);
}
int
rcop_no_set(struct rctl *r, struct proc *p, rctl_entity_p_t *e, rctl_qty_t l)
{
return (0);
}
int
rcop_no_test(struct rctl *r, struct proc *p, rctl_entity_p_t *e,
struct rctl_val *rv, rctl_qty_t i, uint_t f)
{
return (0);
}
rctl_ops_t rctl_default_ops = {
rcop_no_action,
rcop_no_usage,
rcop_no_set,
rcop_no_test
};
int
rcop_absolute_test(struct rctl *r, struct proc *p, rctl_entity_p_t *e,
struct rctl_val *rv, rctl_qty_t i, uint_t f)
{
return (i > rv->rcv_value);
}
rctl_ops_t rctl_absolute_ops = {
rcop_no_action,
rcop_no_usage,
rcop_no_set,
rcop_absolute_test
};
static uint_t
rctl_dict_hash_by_id(void *hash_data, mod_hash_key_t key)
{
return ((uint_t)(uintptr_t)key % rctl_dict_size);
}
static int
rctl_dict_id_cmp(mod_hash_key_t key1, mod_hash_key_t key2)
{
uint_t u1 = (uint_t)(uintptr_t)key1;
uint_t u2 = (uint_t)(uintptr_t)key2;
if (u1 > u2)
return (1);
if (u1 == u2)
return (0);
return (-1);
}
static void
rctl_dict_val_dtor(mod_hash_val_t val)
{
rctl_dict_entry_t *kr = (rctl_dict_entry_t *)val;
kmem_free(kr, sizeof (rctl_dict_entry_t));
}
size_t
rctl_build_name_buf(char **rbufp)
{
size_t req_size, cpy_size;
char *rbufloc;
int i;
rctl_rebuild_name_buf:
req_size = cpy_size = 0;
mutex_enter(&rctl_lists_lock);
for (i = 0; i < RC_MAX_ENTITY + 1; i++) {
rctl_dict_entry_t *rde;
for (rde = rctl_lists[i];
rde != NULL;
rde = rde->rcd_next)
req_size += strlen(rde->rcd_name) + 1;
}
mutex_exit(&rctl_lists_lock);
rbufloc = *rbufp = kmem_alloc(req_size, KM_SLEEP);
mutex_enter(&rctl_lists_lock);
for (i = 0; i < RC_MAX_ENTITY + 1; i++) {
rctl_dict_entry_t *rde;
for (rde = rctl_lists[i];
rde != NULL;
rde = rde->rcd_next) {
size_t length = strlen(rde->rcd_name) + 1;
cpy_size += length;
if (cpy_size > req_size) {
kmem_free(*rbufp, req_size);
mutex_exit(&rctl_lists_lock);
goto rctl_rebuild_name_buf;
}
bcopy(rde->rcd_name, rbufloc, length);
rbufloc += length;
}
}
mutex_exit(&rctl_lists_lock);
return (req_size);
}
rctl_dict_entry_t *
rctl_dict_lookup(const char *name)
{
rctl_dict_entry_t *rde;
mutex_enter(&rctl_dict_lock);
if (mod_hash_find(rctl_dict_by_name, (mod_hash_key_t)name,
(mod_hash_val_t *)&rde) == MH_ERR_NOTFOUND) {
mutex_exit(&rctl_dict_lock);
return (NULL);
}
mutex_exit(&rctl_dict_lock);
return (rde);
}
rctl_hndl_t
rctl_hndl_lookup(const char *name)
{
rctl_dict_entry_t *rde;
if ((rde = rctl_dict_lookup(name)) == NULL)
return (-1);
return (rde->rcd_id);
}
rctl_dict_entry_t *
rctl_dict_lookup_hndl(rctl_hndl_t hndl)
{
uint_t i;
mutex_enter(&rctl_lists_lock);
for (i = 0; i < RC_MAX_ENTITY + 1; i++) {
rctl_dict_entry_t *rde;
for (rde = rctl_lists[i];
rde != NULL;
rde = rde->rcd_next)
if (rde->rcd_id == hndl) {
mutex_exit(&rctl_lists_lock);
return (rde);
}
}
mutex_exit(&rctl_lists_lock);
return (NULL);
}
void
rctl_add_default_limit(const char *name, rctl_qty_t value,
rctl_priv_t privilege, uint_t action)
{
rctl_val_t *dval;
rctl_dict_entry_t *rde;
dval = kmem_cache_alloc(rctl_val_cache, KM_SLEEP);
bzero(dval, sizeof (rctl_val_t));
dval->rcv_value = value;
dval->rcv_privilege = privilege;
dval->rcv_flagaction = action;
dval->rcv_action_recip_pid = -1;
rde = rctl_dict_lookup(name);
(void) rctl_val_list_insert(&rde->rcd_default_value, dval);
}
void
rctl_add_legacy_limit(const char *name, const char *mname, const char *lname,
rctl_qty_t dflt, rctl_qty_t max)
{
rctl_qty_t qty;
if (!mod_sysvar(mname, lname, &qty) || (qty < dflt))
qty = dflt;
if (qty > max)
qty = max;
rctl_add_default_limit(name, qty, RCPRIV_PRIVILEGED, RCTL_LOCAL_DENY);
}
rctl_set_t *
rctl_entity_obtain_rset(rctl_dict_entry_t *rcd, struct proc *p)
{
rctl_set_t *rset = NULL;
if (rcd == NULL)
return (NULL);
switch (rcd->rcd_entity) {
case RCENTITY_PROCESS:
rset = p->p_rctls;
break;
case RCENTITY_TASK:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_task != NULL)
rset = p->p_task->tk_rctls;
break;
case RCENTITY_PROJECT:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_task != NULL &&
p->p_task->tk_proj != NULL)
rset = p->p_task->tk_proj->kpj_rctls;
break;
case RCENTITY_ZONE:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_zone != NULL)
rset = p->p_zone->zone_rctls;
break;
default:
panic("unknown rctl entity type %d seen", rcd->rcd_entity);
break;
}
return (rset);
}
static void
rctl_entity_obtain_entity_p(rctl_entity_t entity, struct proc *p,
rctl_entity_p_t *e)
{
e->rcep_p.proc = NULL;
e->rcep_t = entity;
switch (entity) {
case RCENTITY_PROCESS:
e->rcep_p.proc = p;
break;
case RCENTITY_TASK:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_task != NULL)
e->rcep_p.task = p->p_task;
break;
case RCENTITY_PROJECT:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_task != NULL &&
p->p_task->tk_proj != NULL)
e->rcep_p.proj = p->p_task->tk_proj;
break;
case RCENTITY_ZONE:
ASSERT(MUTEX_HELD(&p->p_lock));
if (p->p_zone != NULL)
e->rcep_p.zone = p->p_zone;
break;
default:
panic("unknown rctl entity type %d seen", entity);
break;
}
}
static void
rctl_gp_alloc(rctl_alloc_gp_t *rcgp)
{
uint_t i;
if (rcgp->rcag_nctls > 0) {
rctl_t *prev = kmem_cache_alloc(rctl_cache, KM_SLEEP);
rctl_t *rctl = prev;
rcgp->rcag_ctls = prev;
for (i = 1; i < rcgp->rcag_nctls; i++) {
rctl = kmem_cache_alloc(rctl_cache, KM_SLEEP);
prev->rc_next = rctl;
prev = rctl;
}
rctl->rc_next = NULL;
}
if (rcgp->rcag_nvals > 0) {
rctl_val_t *prev = kmem_cache_alloc(rctl_val_cache, KM_SLEEP);
rctl_val_t *rval = prev;
rcgp->rcag_vals = prev;
for (i = 1; i < rcgp->rcag_nvals; i++) {
rval = kmem_cache_alloc(rctl_val_cache, KM_SLEEP);
prev->rcv_next = rval;
prev = rval;
}
rval->rcv_next = NULL;
}
}
static rctl_val_t *
rctl_gp_detach_val(rctl_alloc_gp_t *rcgp)
{
rctl_val_t *rval = rcgp->rcag_vals;
ASSERT(rcgp->rcag_nvals > 0);
rcgp->rcag_nvals--;
rcgp->rcag_vals = rval->rcv_next;
rval->rcv_next = NULL;
return (rval);
}
static rctl_t *
rctl_gp_detach_ctl(rctl_alloc_gp_t *rcgp)
{
rctl_t *rctl = rcgp->rcag_ctls;
ASSERT(rcgp->rcag_nctls > 0);
rcgp->rcag_nctls--;
rcgp->rcag_ctls = rctl->rc_next;
rctl->rc_next = NULL;
return (rctl);
}
static void
rctl_gp_free(rctl_alloc_gp_t *rcgp)
{
rctl_val_t *rval = rcgp->rcag_vals;
rctl_t *rctl = rcgp->rcag_ctls;
while (rval != NULL) {
rctl_val_t *next = rval->rcv_next;
kmem_cache_free(rctl_val_cache, rval);
rval = next;
}
while (rctl != NULL) {
rctl_t *next = rctl->rc_next;
kmem_cache_free(rctl_cache, rctl);
rctl = next;
}
}
void
rctl_prealloc_destroy(rctl_alloc_gp_t *gp)
{
rctl_gp_free(gp);
kmem_free(gp, sizeof (rctl_alloc_gp_t));
}
int
rctl_val_cmp(rctl_val_t *a, rctl_val_t *b, int imprecise)
{
if ((a->rcv_flagaction & RCTL_LOCAL_MAXIMAL) <
(b->rcv_flagaction & RCTL_LOCAL_MAXIMAL))
return (-1);
if ((a->rcv_flagaction & RCTL_LOCAL_MAXIMAL) >
(b->rcv_flagaction & RCTL_LOCAL_MAXIMAL))
return (1);
if (a->rcv_value < b->rcv_value)
return (-1);
if (a->rcv_value > b->rcv_value)
return (1);
if ((a->rcv_flagaction & RCTL_LOCAL_DENY) <
(b->rcv_flagaction & RCTL_LOCAL_DENY))
return (-1);
if ((a->rcv_flagaction & RCTL_LOCAL_DENY) >
(b->rcv_flagaction & RCTL_LOCAL_DENY))
return (1);
if (a->rcv_privilege < b->rcv_privilege)
return (-1);
if (a->rcv_privilege > b->rcv_privilege)
return (1);
if (imprecise)
return (0);
if (a->rcv_action_recip_pid < b->rcv_action_recip_pid)
return (-1);
if (a->rcv_action_recip_pid > b->rcv_action_recip_pid)
return (1);
return (0);
}
static rctl_val_t *
rctl_val_list_find(rctl_val_t **head, rctl_val_t *cval)
{
rctl_val_t *rval = *head;
while (rval != NULL) {
if (rctl_val_cmp(cval, rval, 0) == 0)
return (rval);
rval = rval->rcv_next;
}
return (NULL);
}
int
rctl_val_list_insert(rctl_val_t **root, rctl_val_t *rval)
{
rctl_val_t *prev;
int equiv;
rval->rcv_next = NULL;
rval->rcv_prev = NULL;
if (*root == NULL) {
*root = rval;
return (0);
}
equiv = rctl_val_cmp(rval, *root, 0);
if (equiv == 0)
return (1);
if (equiv < 0) {
rval->rcv_next = *root;
rval->rcv_next->rcv_prev = rval;
*root = rval;
return (0);
}
prev = *root;
while (prev->rcv_next != NULL &&
(equiv = rctl_val_cmp(rval, prev->rcv_next, 0)) > 0) {
prev = prev->rcv_next;
}
if (equiv == 0)
return (1);
rval->rcv_next = prev->rcv_next;
if (rval->rcv_next != NULL)
rval->rcv_next->rcv_prev = rval;
prev->rcv_next = rval;
rval->rcv_prev = prev;
return (0);
}
static int
rctl_val_list_delete(rctl_val_t **root, rctl_val_t *rval)
{
rctl_val_t *prev;
if (*root == NULL)
return (-1);
prev = *root;
if (rctl_val_cmp(rval, prev, 0) == 0) {
*root = prev->rcv_next;
if (*root != NULL)
(*root)->rcv_prev = NULL;
kmem_cache_free(rctl_val_cache, prev);
return (0);
}
while (prev->rcv_next != NULL &&
rctl_val_cmp(rval, prev->rcv_next, 0) != 0) {
prev = prev->rcv_next;
}
if (prev->rcv_next == NULL) {
return (-1);
}
prev = prev->rcv_next;
prev->rcv_prev->rcv_next = prev->rcv_next;
if (prev->rcv_next != NULL)
prev->rcv_next->rcv_prev = prev->rcv_prev;
kmem_cache_free(rctl_val_cache, prev);
return (0);
}
static rctl_val_t *
rctl_val_list_dup(rctl_val_t *rval, rctl_alloc_gp_t *ragp, struct proc *oldp,
struct proc *newp)
{
rctl_val_t *head = NULL;
for (; rval != NULL; rval = rval->rcv_next) {
rctl_val_t *dval = rctl_gp_detach_val(ragp);
bcopy(rval, dval, sizeof (rctl_val_t));
dval->rcv_prev = dval->rcv_next = NULL;
if (oldp == NULL ||
rval->rcv_action_recipient == NULL ||
rval->rcv_action_recipient == oldp) {
if (rval->rcv_privilege == RCPRIV_BASIC) {
dval->rcv_action_recipient = newp;
dval->rcv_action_recip_pid = newp->p_pid;
} else {
dval->rcv_action_recipient = NULL;
dval->rcv_action_recip_pid = -1;
}
(void) rctl_val_list_insert(&head, dval);
} else {
kmem_cache_free(rctl_val_cache, dval);
}
}
return (head);
}
static void
rctl_val_list_reset(rctl_val_t *rval)
{
for (; rval != NULL; rval = rval->rcv_next)
rval->rcv_firing_time = 0;
}
static uint_t
rctl_val_list_count(rctl_val_t *rval)
{
uint_t n = 0;
for (; rval != NULL; rval = rval->rcv_next)
n++;
return (n);
}
static void
rctl_val_list_free(rctl_val_t *rval)
{
while (rval != NULL) {
rctl_val_t *next = rval->rcv_next;
kmem_cache_free(rctl_val_cache, rval);
rval = next;
}
}
rctl_qty_t
rctl_model_maximum(rctl_dict_entry_t *rde, struct proc *p)
{
if (p->p_model == DATAMODEL_NATIVE)
return (rde->rcd_max_native);
return (rde->rcd_max_ilp32);
}
rctl_qty_t
rctl_model_value(rctl_dict_entry_t *rde, struct proc *p, rctl_qty_t value)
{
rctl_qty_t max = rctl_model_maximum(rde, p);
return (value < max ? value : max);
}
static void
rctl_set_insert(rctl_set_t *set, rctl_hndl_t hndl, rctl_t *rctl)
{
uint_t index = hndl % rctl_set_size;
rctl_t *next_ctl, *prev_ctl;
ASSERT(MUTEX_HELD(&set->rcs_lock));
rctl->rc_next = NULL;
if (set->rcs_ctls[index] == NULL) {
set->rcs_ctls[index] = rctl;
return;
}
if (hndl < set->rcs_ctls[index]->rc_id) {
rctl->rc_next = set->rcs_ctls[index];
set->rcs_ctls[index] = rctl;
return;
}
for (next_ctl = set->rcs_ctls[index]->rc_next,
prev_ctl = set->rcs_ctls[index];
next_ctl != NULL;
prev_ctl = next_ctl,
next_ctl = next_ctl->rc_next) {
if (next_ctl->rc_id > hndl) {
rctl->rc_next = next_ctl;
prev_ctl->rc_next = rctl;
return;
}
}
rctl->rc_next = next_ctl;
prev_ctl->rc_next = rctl;
}
rctl_set_t *
rctl_set_create()
{
rctl_set_t *rset = kmem_zalloc(sizeof (rctl_set_t), KM_SLEEP);
mutex_init(&rset->rcs_lock, NULL, MUTEX_DEFAULT, NULL);
rset->rcs_ctls = kmem_zalloc(rctl_set_size * sizeof (rctl_t *),
KM_SLEEP);
rset->rcs_entity = -1;
return (rset);
}
rctl_alloc_gp_t *
rctl_set_init_prealloc(rctl_entity_t entity)
{
rctl_dict_entry_t *rde;
rctl_alloc_gp_t *ragp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP);
ASSERT(MUTEX_NOT_HELD(&curproc->p_lock));
if (rctl_lists[entity] == NULL)
return (ragp);
mutex_enter(&rctl_lists_lock);
for (rde = rctl_lists[entity]; rde != NULL; rde = rde->rcd_next) {
ragp->rcag_nctls++;
ragp->rcag_nvals += rctl_val_list_count(rde->rcd_default_value);
}
mutex_exit(&rctl_lists_lock);
rctl_gp_alloc(ragp);
return (ragp);
}
rctl_set_t *
rctl_set_init(rctl_entity_t entity, struct proc *p, rctl_entity_p_t *e,
rctl_set_t *rset, rctl_alloc_gp_t *ragp)
{
rctl_dict_entry_t *rde;
ASSERT(MUTEX_HELD(&p->p_lock));
ASSERT(e);
rset->rcs_entity = entity;
if (rctl_lists[entity] == NULL)
return (rset);
mutex_enter(&rctl_lists_lock);
mutex_enter(&rset->rcs_lock);
for (rde = rctl_lists[entity]; rde != NULL; rde = rde->rcd_next) {
rctl_t *rctl = rctl_gp_detach_ctl(ragp);
rctl->rc_dict_entry = rde;
rctl->rc_id = rde->rcd_id;
rctl->rc_projdb = NULL;
rctl->rc_values = rctl_val_list_dup(rde->rcd_default_value,
ragp, NULL, p);
rctl->rc_cursor = rctl->rc_values;
ASSERT(rctl->rc_cursor != NULL);
rctl_set_insert(rset, rde->rcd_id, rctl);
RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
}
mutex_exit(&rset->rcs_lock);
mutex_exit(&rctl_lists_lock);
return (rset);
}
static rctl_t *
rctl_dup(rctl_t *rctl, rctl_alloc_gp_t *ragp, struct proc *oldp,
struct proc *newp)
{
rctl_t *dup = rctl_gp_detach_ctl(ragp);
rctl_val_t *dval;
dup->rc_id = rctl->rc_id;
dup->rc_dict_entry = rctl->rc_dict_entry;
dup->rc_next = NULL;
dup->rc_cursor = NULL;
dup->rc_values = rctl_val_list_dup(rctl->rc_values, ragp, oldp, newp);
for (dval = dup->rc_values;
dval != NULL; dval = dval->rcv_next) {
if (rctl_val_cmp(rctl->rc_cursor, dval, 0) >= 0) {
dup->rc_cursor = dval;
break;
}
}
if (dup->rc_cursor == NULL)
dup->rc_cursor = dup->rc_values;
return (dup);
}
static void
rctl_set_fill_alloc_gp(rctl_set_t *set, rctl_alloc_gp_t *ragp)
{
uint_t i;
bzero(ragp, sizeof (rctl_alloc_gp_t));
for (i = 0; i < rctl_set_size; i++) {
rctl_t *r = set->rcs_ctls[i];
while (r != NULL) {
ragp->rcag_nctls++;
ragp->rcag_nvals += rctl_val_list_count(r->rc_values);
r = r->rc_next;
}
}
}
rctl_alloc_gp_t *
rctl_set_dup_prealloc(rctl_set_t *set)
{
rctl_alloc_gp_t *ragp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP);
ASSERT(MUTEX_NOT_HELD(&curproc->p_lock));
mutex_enter(&set->rcs_lock);
rctl_set_fill_alloc_gp(set, ragp);
mutex_exit(&set->rcs_lock);
rctl_gp_alloc(ragp);
return (ragp);
}
int
rctl_set_dup_ready(rctl_set_t *set, rctl_alloc_gp_t *ragp)
{
rctl_alloc_gp_t curr_gp;
ASSERT(MUTEX_HELD(&set->rcs_lock));
rctl_set_fill_alloc_gp(set, &curr_gp);
if (curr_gp.rcag_nctls <= ragp->rcag_nctls &&
curr_gp.rcag_nvals <= ragp->rcag_nvals)
return (1);
return (0);
}
rctl_set_t *
rctl_set_dup(rctl_set_t *set, struct proc *oldp, struct proc *newp,
rctl_entity_p_t *e, rctl_set_t *dup, rctl_alloc_gp_t *ragp, int flag)
{
uint_t i;
rctl_set_t *iter;
ASSERT((flag & RCD_DUP) || (flag & RCD_CALLBACK));
ASSERT(e);
if (flag & RCD_DUP) {
ASSERT(MUTEX_HELD(&set->rcs_lock));
iter = set;
dup->rcs_entity = set->rcs_entity;
} else {
iter = dup;
}
mutex_enter(&dup->rcs_lock);
for (i = 0; i < rctl_set_size; i++) {
rctl_t *r = iter->rcs_ctls[i];
rctl_t *d;
while (r != NULL) {
if (flag & RCD_DUP) {
d = rctl_dup(r, ragp, oldp, newp);
rctl_set_insert(dup, r->rc_id, d);
} else {
d = r;
}
if (flag & RCD_CALLBACK)
RCTLOP_SET(d, newp, e,
rctl_model_value(d->rc_dict_entry, newp,
d->rc_cursor->rcv_value));
r = r->rc_next;
}
}
mutex_exit(&dup->rcs_lock);
return (dup);
}
void
rctl_set_free(rctl_set_t *set)
{
uint_t i;
mutex_enter(&set->rcs_lock);
for (i = 0; i < rctl_set_size; i++) {
rctl_t *r = set->rcs_ctls[i];
while (r != NULL) {
rctl_val_t *v = r->rc_values;
rctl_t *n = r->rc_next;
kmem_cache_free(rctl_cache, r);
rctl_val_list_free(v);
r = n;
}
}
mutex_exit(&set->rcs_lock);
kmem_free(set->rcs_ctls, sizeof (rctl_t *) * rctl_set_size);
kmem_free(set, sizeof (rctl_set_t));
}
void
rctl_set_reset(rctl_set_t *set, struct proc *p, rctl_entity_p_t *e)
{
uint_t i;
ASSERT(e);
mutex_enter(&set->rcs_lock);
for (i = 0; i < rctl_set_size; i++) {
rctl_t *r = set->rcs_ctls[i];
while (r != NULL) {
r->rc_cursor = r->rc_values;
rctl_val_list_reset(r->rc_cursor);
RCTLOP_SET(r, p, e, rctl_model_value(r->rc_dict_entry,
p, r->rc_cursor->rcv_value));
ASSERT(r->rc_cursor != NULL);
r = r->rc_next;
}
}
mutex_exit(&set->rcs_lock);
}
void
rctl_set_tearoff(rctl_set_t *set, struct proc *p)
{
uint_t i;
mutex_enter(&set->rcs_lock);
for (i = 0; i < rctl_set_size; i++) {
rctl_t *r = set->rcs_ctls[i];
while (r != NULL) {
rctl_val_t *rval;
tearoff_rewalk_list:
rval = r->rc_values;
while (rval != NULL) {
if (rval->rcv_privilege == RCPRIV_BASIC &&
rval->rcv_action_recipient == p) {
if (r->rc_cursor == rval)
r->rc_cursor = rval->rcv_next;
(void) rctl_val_list_delete(
&r->rc_values, rval);
goto tearoff_rewalk_list;
}
rval = rval->rcv_next;
}
ASSERT(r->rc_cursor != NULL);
r = r->rc_next;
}
}
mutex_exit(&set->rcs_lock);
}
int
rctl_set_find(rctl_set_t *set, rctl_hndl_t hndl, rctl_t **rctl)
{
uint_t index = hndl % rctl_set_size;
rctl_t *curr_ctl;
ASSERT(MUTEX_HELD(&set->rcs_lock));
for (curr_ctl = set->rcs_ctls[index]; curr_ctl != NULL;
curr_ctl = curr_ctl->rc_next) {
if (curr_ctl->rc_id == hndl) {
*rctl = curr_ctl;
return (0);
}
}
return (-1);
}
rctl_qty_t
rctl_enforced_value(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p)
{
rctl_t *rctl;
rlim64_t ret;
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, hndl, &rctl) == -1)
panic("unknown resource control handle %d requested", hndl);
else
ret = rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value);
mutex_exit(&rset->rcs_lock);
return (ret);
}
int
rctl_global_get(const char *name, rctl_dict_entry_t *drde)
{
rctl_dict_entry_t *rde = rctl_dict_lookup(name);
if (rde == NULL)
return (-1);
bcopy(rde, drde, sizeof (rctl_dict_entry_t));
drde->rcd_next = NULL;
drde->rcd_ops = NULL;
return (0);
}
int
rctl_global_set(const char *name, rctl_dict_entry_t *drde)
{
rctl_dict_entry_t *rde = rctl_dict_lookup(name);
if (rde == NULL)
return (-1);
rde->rcd_flagaction = drde->rcd_flagaction;
rde->rcd_syslog_level = drde->rcd_syslog_level;
rde->rcd_strlog_flags = drde->rcd_strlog_flags;
return (0);
}
static int
rctl_local_op(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval,
int (*cbop)(rctl_hndl_t, struct proc *p, rctl_entity_p_t *e, rctl_t *,
rctl_val_t *, rctl_val_t *), struct proc *p)
{
rctl_t *rctl;
rctl_set_t *rset;
rctl_entity_p_t e;
int ret = 0;
rctl_dict_entry_t *rde = rctl_dict_lookup_hndl(hndl);
ASSERT(MUTEX_HELD(&p->p_lock));
rset = rctl_entity_obtain_rset(rde, p);
if (rset == NULL) {
return (-1);
}
rctl_entity_obtain_entity_p(rset->rcs_entity, p, &e);
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, hndl, &rctl) == -1) {
mutex_exit(&rset->rcs_lock);
return (-1);
}
ret = cbop(hndl, p, &e, rctl, oval, nval);
mutex_exit(&rset->rcs_lock);
return (ret);
}
static int
rctl_local_get_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval)
{
if (oval == NULL) {
bcopy(rctl->rc_values, nval, sizeof (rctl_val_t));
} else {
rctl_val_t *tval = rctl_val_list_find(&rctl->rc_values, oval);
if (tval == NULL)
return (ESRCH);
else if (tval->rcv_next == NULL)
return (ENOENT);
else
bcopy(tval->rcv_next, nval, sizeof (rctl_val_t));
}
return (0);
}
int
rctl_local_get(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval,
struct proc *p)
{
return (rctl_local_op(hndl, oval, nval, rctl_local_get_cb, p));
}
static int
rctl_local_delete_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval)
{
if ((oval = rctl_val_list_find(&rctl->rc_values, nval)) == NULL)
return (ESRCH);
if (rctl->rc_cursor == oval) {
rctl->rc_cursor = oval->rcv_next;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
ASSERT(rctl->rc_cursor != NULL);
}
(void) rctl_val_list_delete(&rctl->rc_values, oval);
return (0);
}
int
rctl_local_delete(rctl_hndl_t hndl, rctl_val_t *val, struct proc *p)
{
return (rctl_local_op(hndl, NULL, val, rctl_local_delete_cb, p));
}
static int
rctl_local_insert_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval)
{
if (rctl_val_list_insert(&rctl->rc_values, nval) != 0)
return (EINVAL);
if (rctl_val_cmp(nval, rctl->rc_cursor, 0) < 0) {
rctl->rc_cursor = nval;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
ASSERT(rctl->rc_cursor != NULL);
}
return (0);
}
int
rctl_local_insert(rctl_hndl_t hndl, rctl_val_t *val, struct proc *p)
{
return (rctl_local_op(hndl, NULL, val, rctl_local_insert_cb, p));
}
static int
rctl_local_insert_all_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *new_values, rctl_val_t *alloc_values)
{
rctl_val_t *val;
rctl_val_t *tmp_val;
rctl_val_t *next;
int modified = 0;
if (rctl->rc_projdb == NULL) {
val = rctl->rc_values;
while (val != NULL) {
if (val->rcv_privilege == RCPRIV_PRIVILEGED) {
if (val->rcv_prev != NULL)
val->rcv_prev->rcv_next = val->rcv_next;
else
rctl->rc_values = val->rcv_next;
if (val->rcv_next != NULL)
val->rcv_next->rcv_prev = val->rcv_prev;
tmp_val = val;
val = val->rcv_next;
kmem_cache_free(rctl_val_cache, tmp_val);
} else {
val = val->rcv_next;
}
}
modified = 1;
}
val = rctl->rc_projdb;
while (val != NULL) {
if (rctl_val_list_find(&new_values, val) == NULL) {
if (((tmp_val = rctl_val_list_find(&rctl->rc_values,
val)) != NULL) &&
(tmp_val->rcv_flagaction & RCTL_LOCAL_PROJDB)) {
(void) rctl_val_list_delete(&rctl->rc_values,
tmp_val);
}
tmp_val = val->rcv_next;
(void) rctl_val_list_delete(&rctl->rc_projdb, val);
val = tmp_val;
modified = 1;
} else
val = val->rcv_next;
}
while (new_values != NULL) {
next = new_values->rcv_next;
if (rctl_val_list_insert(&rctl->rc_projdb, new_values) == 0) {
tmp_val = alloc_values->rcv_next;
bcopy(new_values, alloc_values, sizeof (rctl_val_t));
alloc_values->rcv_next = tmp_val;
if (rctl_val_list_insert(&rctl->rc_values,
alloc_values) == 0) {
alloc_values = tmp_val;
modified = 1;
}
} else {
kmem_cache_free(rctl_val_cache, new_values);
}
new_values = next;
}
while (alloc_values != NULL) {
tmp_val = alloc_values;
alloc_values = alloc_values->rcv_next;
kmem_cache_free(rctl_val_cache, tmp_val);
}
if (modified) {
rctl->rc_cursor = rctl->rc_values;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
}
return (0);
}
int
rctl_local_insert_all(rctl_hndl_t hndl, rctl_val_t *new_values,
rctl_val_t *alloc_values, struct proc *p)
{
return (rctl_local_op(hndl, new_values, alloc_values,
rctl_local_insert_all_cb, p));
}
static int
rctl_local_replace_all_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *new_values, rctl_val_t *alloc_values)
{
rctl_val_t *val;
rctl_val_t *next;
rctl_val_t *tmp_val;
val = rctl->rc_values;
while (val != NULL) {
if (val->rcv_privilege == RCPRIV_PRIVILEGED) {
if (val->rcv_prev != NULL)
val->rcv_prev->rcv_next = val->rcv_next;
else
rctl->rc_values = val->rcv_next;
if (val->rcv_next != NULL)
val->rcv_next->rcv_prev = val->rcv_prev;
tmp_val = val;
val = val->rcv_next;
kmem_cache_free(rctl_val_cache, tmp_val);
} else {
val = val->rcv_next;
}
}
val = rctl->rc_projdb;
while (val != NULL) {
tmp_val = val;
val = val->rcv_next;
kmem_cache_free(rctl_val_cache, tmp_val);
}
rctl->rc_projdb = NULL;
while (new_values != NULL) {
next = new_values->rcv_next;
if (rctl_val_list_insert(&rctl->rc_projdb, new_values) == 0) {
tmp_val = alloc_values->rcv_next;
bcopy(new_values, alloc_values, sizeof (rctl_val_t));
alloc_values->rcv_next = tmp_val;
if (rctl_val_list_insert(&rctl->rc_values,
alloc_values) == 0) {
alloc_values = tmp_val;
}
} else {
kmem_cache_free(rctl_val_cache, new_values);
}
new_values = next;
}
while (alloc_values != NULL) {
tmp_val = alloc_values;
alloc_values = alloc_values->rcv_next;
kmem_cache_free(rctl_val_cache, tmp_val);
}
rctl->rc_cursor = rctl->rc_values;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
return (0);
}
int
rctl_local_replace_all(rctl_hndl_t hndl, rctl_val_t *new_values,
rctl_val_t *alloc_values, struct proc *p)
{
return (rctl_local_op(hndl, new_values, alloc_values,
rctl_local_replace_all_cb, p));
}
static int
rctl_local_replace_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e,
rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval)
{
int ret;
rctl_val_t *tmp;
tmp = rctl_val_list_find(&rctl->rc_values, oval);
if (tmp == NULL)
return (ESRCH);
ASSERT(tmp->rcv_privilege != RCPRIV_SYSTEM);
if (ret = rctl_local_insert_cb(hndl, p, e, rctl, NULL, nval))
return (ret);
ret = rctl_local_delete_cb(hndl, p, e, rctl, NULL, oval);
ASSERT(ret == 0);
return (0);
}
int
rctl_local_replace(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval,
struct proc *p)
{
return (rctl_local_op(hndl, oval, nval, rctl_local_replace_cb, p));
}
int
rctl_rlimit_get(rctl_hndl_t rc, struct proc *p, struct rlimit64 *rlp64)
{
rctl_t *rctl;
rctl_val_t *rval;
rctl_set_t *rset = p->p_rctls;
int soft_limit_seen = 0;
int test_for_deny = 1;
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, rc, &rctl) == -1) {
mutex_exit(&rset->rcs_lock);
return (-1);
}
rval = rctl->rc_values;
if (rctl->rc_dict_entry->rcd_flagaction & (RCTL_GLOBAL_DENY_NEVER |
RCTL_GLOBAL_DENY_ALWAYS))
test_for_deny = 0;
while (rval != NULL && rval->rcv_privilege != RCPRIV_SYSTEM) {
if (test_for_deny &&
(rval->rcv_flagaction & RCTL_LOCAL_DENY) == 0) {
rval = rval->rcv_next;
continue;
}
if (rval->rcv_privilege == RCPRIV_BASIC) {
if (soft_limit_seen) {
rval = rval->rcv_next;
continue;
}
if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 &&
rval->rcv_value < rctl_model_maximum(
rctl->rc_dict_entry, p))
rlp64->rlim_cur = rval->rcv_value;
else
rlp64->rlim_cur = RLIM64_INFINITY;
soft_limit_seen = 1;
rval = rval->rcv_next;
continue;
}
if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 &&
rval->rcv_value < rctl_model_maximum(rctl->rc_dict_entry,
p))
rlp64->rlim_max = rval->rcv_value;
else
rlp64->rlim_max = RLIM64_INFINITY;
if (!soft_limit_seen)
rlp64->rlim_cur = rlp64->rlim_max;
mutex_exit(&rset->rcs_lock);
return (0);
}
if (rval == NULL) {
mutex_exit(&rset->rcs_lock);
return (-1);
}
if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 &&
rval->rcv_value < rctl_model_maximum(rctl->rc_dict_entry, p))
rlp64->rlim_max = rval->rcv_value;
else
rlp64->rlim_max = RLIM64_INFINITY;
if (!soft_limit_seen)
rlp64->rlim_cur = rlp64->rlim_max;
mutex_exit(&rset->rcs_lock);
return (0);
}
rctl_alloc_gp_t *
rctl_rlimit_set_prealloc(uint_t n)
{
rctl_alloc_gp_t *gp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP);
ASSERT(MUTEX_NOT_HELD(&curproc->p_lock));
gp->rcag_nvals = 2 * n;
rctl_gp_alloc(gp);
return (gp);
}
int
rctl_rlimit_set(rctl_hndl_t rc, struct proc *p, struct rlimit64 *rlp64,
rctl_alloc_gp_t *ragp, int flagaction, int signal, const cred_t *cr)
{
rctl_t *rctl;
rctl_val_t *rval, *rval_priv, *rval_basic;
rctl_set_t *rset = p->p_rctls;
rctl_qty_t max;
rctl_entity_p_t e;
struct rlimit64 cur_rl;
e.rcep_t = RCENTITY_PROCESS;
e.rcep_p.proc = p;
if (rlp64->rlim_cur > rlp64->rlim_max)
return (EINVAL);
if (rctl_rlimit_get(rc, p, &cur_rl) == -1)
return (EINVAL);
if ((rlp64->rlim_max > cur_rl.rlim_max) &&
cur_rl.rlim_max != RLIM64_INFINITY &&
secpolicy_resource(cr) != 0)
return (EPERM);
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, rc, &rctl) == -1) {
mutex_exit(&rset->rcs_lock);
return (EINVAL);
}
rval_priv = rctl_gp_detach_val(ragp);
rval = rctl->rc_values;
while (rval != NULL) {
rctl_val_t *next = rval->rcv_next;
if (rval->rcv_privilege == RCPRIV_SYSTEM)
break;
if ((rval->rcv_privilege == RCPRIV_BASIC) ||
(rval->rcv_flagaction & ~RCTL_LOCAL_ACTION_MASK) ==
(flagaction & ~RCTL_LOCAL_ACTION_MASK)) {
if (rctl->rc_cursor == rval) {
rctl->rc_cursor = rval->rcv_next;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, &e, rctl_model_value(
rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
}
(void) rctl_val_list_delete(&rctl->rc_values, rval);
}
rval = next;
}
rval_priv->rcv_privilege = RCPRIV_PRIVILEGED;
rval_priv->rcv_flagaction = flagaction;
if (rlp64->rlim_max == RLIM64_INFINITY) {
rval_priv->rcv_flagaction |= RCTL_LOCAL_MAXIMAL;
max = rctl->rc_dict_entry->rcd_max_native;
} else {
max = rlp64->rlim_max;
}
rval_priv->rcv_value = max;
rval_priv->rcv_action_signal = signal;
rval_priv->rcv_action_recipient = NULL;
rval_priv->rcv_action_recip_pid = -1;
rval_priv->rcv_firing_time = 0;
rval_priv->rcv_prev = rval_priv->rcv_next = NULL;
(void) rctl_val_list_insert(&rctl->rc_values, rval_priv);
rctl->rc_cursor = rval_priv;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, &e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
if (rlp64->rlim_cur != RLIM64_INFINITY && rlp64->rlim_cur < max) {
rval_basic = rctl_gp_detach_val(ragp);
rval_basic->rcv_privilege = RCPRIV_BASIC;
rval_basic->rcv_value = rlp64->rlim_cur;
rval_basic->rcv_flagaction = flagaction;
rval_basic->rcv_action_signal = signal;
rval_basic->rcv_action_recipient = p;
rval_basic->rcv_action_recip_pid = p->p_pid;
rval_basic->rcv_firing_time = 0;
rval_basic->rcv_prev = rval_basic->rcv_next = NULL;
(void) rctl_val_list_insert(&rctl->rc_values, rval_basic);
rctl->rc_cursor = rval_basic;
rctl_val_list_reset(rctl->rc_cursor);
RCTLOP_SET(rctl, p, &e, rctl_model_value(rctl->rc_dict_entry, p,
rctl->rc_cursor->rcv_value));
}
ASSERT(rctl->rc_cursor != NULL);
mutex_exit(&rset->rcs_lock);
return (0);
}
rctl_hndl_t
rctl_register(
const char *name,
rctl_entity_t entity,
int global_flags,
rlim64_t max_native,
rlim64_t max_ilp32,
rctl_ops_t *ops)
{
rctl_t *rctl = kmem_cache_alloc(rctl_cache, KM_SLEEP);
rctl_val_t *rctl_val = kmem_cache_alloc(rctl_val_cache, KM_SLEEP);
rctl_dict_entry_t *rctl_de = kmem_zalloc(sizeof (rctl_dict_entry_t),
KM_SLEEP);
rctl_t *old_rctl;
rctl_hndl_t rhndl;
int localflags;
ASSERT(ops != NULL);
bzero(rctl, sizeof (rctl_t));
bzero(rctl_val, sizeof (rctl_val_t));
if (global_flags & RCTL_GLOBAL_DENY_NEVER)
localflags = RCTL_LOCAL_MAXIMAL;
else
localflags = RCTL_LOCAL_MAXIMAL | RCTL_LOCAL_DENY;
rctl_val->rcv_privilege = RCPRIV_SYSTEM;
rctl_val->rcv_value = max_native;
rctl_val->rcv_flagaction = localflags;
rctl_val->rcv_action_signal = 0;
rctl_val->rcv_action_recipient = NULL;
rctl_val->rcv_action_recip_pid = -1;
rctl_val->rcv_firing_time = 0;
rctl_val->rcv_next = NULL;
rctl_val->rcv_prev = NULL;
rctl_de->rcd_name = (char *)name;
rctl_de->rcd_default_value = rctl_val;
rctl_de->rcd_max_native = max_native;
rctl_de->rcd_max_ilp32 = max_ilp32;
rctl_de->rcd_entity = entity;
rctl_de->rcd_ops = ops;
rctl_de->rcd_flagaction = global_flags;
rctl->rc_dict_entry = rctl_de;
rctl->rc_values = rctl_val;
mutex_enter(&rctl_dict_lock);
if (mod_hash_find(rctl_dict_by_name, (mod_hash_key_t)name,
(mod_hash_val_t *)&rhndl) != MH_ERR_NOTFOUND)
panic("duplicate registration of rctl %s", name);
rhndl = rctl_de->rcd_id = rctl->rc_id =
(rctl_hndl_t)id_alloc(rctl_ids);
if (mod_hash_insert(rctl_dict_by_name, (mod_hash_key_t)name,
(mod_hash_val_t)rctl_de))
panic("unable to insert rctl dict entry for %s (%u)", name,
(uint_t)rctl->rc_id);
if (mod_hash_find(rctl_dict, (mod_hash_key_t)(uintptr_t)rctl->rc_id,
(mod_hash_val_t *)&old_rctl) != MH_ERR_NOTFOUND)
panic("duplicate rctl ID %u registered", rctl->rc_id);
if (mod_hash_insert(rctl_dict, (mod_hash_key_t)(uintptr_t)rctl->rc_id,
(mod_hash_val_t)rctl))
panic("unable to insert rctl %s/%u (%p)", name,
(uint_t)rctl->rc_id, (void *)rctl);
mutex_enter(&rctl_lists_lock);
switch (entity) {
case RCENTITY_ZONE:
case RCENTITY_PROJECT:
case RCENTITY_TASK:
case RCENTITY_PROCESS:
rctl_de->rcd_next = rctl_lists[entity];
rctl_lists[entity] = rctl_de;
break;
default:
panic("registering unknown rctl entity %d (%s)", entity,
name);
break;
}
mutex_exit(&rctl_lists_lock);
mutex_exit(&rctl_dict_lock);
return (rhndl);
}
static int
rctl_global_action(rctl_t *r, rctl_set_t *rset, struct proc *p, rctl_val_t *v)
{
rctl_dict_entry_t *rde = r->rc_dict_entry;
const char *pr, *en, *idstr;
id_t id;
enum {
SUFFIX_NONE,
SUFFIX_NUMERIC,
SUFFIX_STRING
} suffix = SUFFIX_NONE;
int ret = 0;
v->rcv_firing_time = gethrtime();
switch (v->rcv_privilege) {
case RCPRIV_BASIC:
pr = "basic";
break;
case RCPRIV_PRIVILEGED:
pr = "privileged";
break;
case RCPRIV_SYSTEM:
pr = "system";
break;
default:
pr = "unknown";
break;
}
switch (rde->rcd_entity) {
case RCENTITY_PROCESS:
en = "process";
id = p->p_pid;
suffix = SUFFIX_NONE;
break;
case RCENTITY_TASK:
en = "task";
id = p->p_task->tk_tkid;
suffix = SUFFIX_NUMERIC;
break;
case RCENTITY_PROJECT:
en = "project";
id = p->p_task->tk_proj->kpj_id;
suffix = SUFFIX_NUMERIC;
break;
case RCENTITY_ZONE:
en = "zone";
idstr = p->p_zone->zone_name;
suffix = SUFFIX_STRING;
break;
default:
en = "unknown entity associated with process";
id = p->p_pid;
suffix = SUFFIX_NONE;
break;
}
if (rde->rcd_flagaction & RCTL_GLOBAL_SYSLOG) {
switch (suffix) {
default:
case SUFFIX_NONE:
(void) strlog(0, 0, 0,
rde->rcd_strlog_flags | log_global.lz_active,
"%s rctl %s (value %llu) exceeded by %s %d.",
pr, rde->rcd_name, v->rcv_value, en, id);
break;
case SUFFIX_NUMERIC:
(void) strlog(0, 0, 0,
rde->rcd_strlog_flags | log_global.lz_active,
"%s rctl %s (value %llu) exceeded by process %d"
" in %s %d.",
pr, rde->rcd_name, v->rcv_value, p->p_pid,
en, id);
break;
case SUFFIX_STRING:
(void) strlog(0, 0, 0,
rde->rcd_strlog_flags | log_global.lz_active,
"%s rctl %s (value %llu) exceeded by process %d"
" in %s %s.",
pr, rde->rcd_name, v->rcv_value, p->p_pid,
en, idstr);
break;
}
}
if (rde->rcd_flagaction & RCTL_GLOBAL_DENY_ALWAYS)
ret |= RCT_DENY;
return (ret);
}
static int
rctl_local_action(rctl_t *r, rctl_set_t *rset, struct proc *p, rctl_val_t *v,
uint_t safety)
{
int ret = 0;
sigqueue_t *sqp = NULL;
rctl_dict_entry_t *rde = r->rc_dict_entry;
int unobservable = (rde->rcd_flagaction & RCTL_GLOBAL_UNOBSERVABLE);
proc_t *recipient = v->rcv_action_recipient;
id_t recip_pid = v->rcv_action_recip_pid;
int recip_signal = v->rcv_action_signal;
uint_t flagaction = v->rcv_flagaction;
if (safety == RCA_UNSAFE_ALL) {
if (flagaction & RCTL_LOCAL_DENY) {
ret |= RCT_DENY;
}
return (ret);
}
if (flagaction & RCTL_LOCAL_SIGNAL) {
if (safety == RCA_SAFE) {
mutex_exit(&rset->rcs_lock);
mutex_exit(&p->p_lock);
sqp = kmem_zalloc(sizeof (sigqueue_t), KM_SLEEP);
mutex_enter(&p->p_lock);
mutex_enter(&rset->rcs_lock);
sqp->sq_info.si_signo = recip_signal;
sqp->sq_info.si_code = SI_RCTL;
sqp->sq_info.si_errno = 0;
sqp->sq_info.si_entity = (int)rde->rcd_entity;
}
if (recipient == NULL || recipient == p) {
ret |= RCT_SIGNAL;
if (sqp == NULL) {
sigtoproc(p, NULL, recip_signal);
} else if (p == curproc) {
sigaddqa(curproc, curthread, sqp);
} else {
sigaddqa(p, NULL, sqp);
}
} else if (!unobservable) {
proc_t *rp;
mutex_exit(&rset->rcs_lock);
mutex_exit(&p->p_lock);
mutex_enter(&pidlock);
if ((rp = prfind(recip_pid)) == recipient) {
mutex_enter(&rp->p_lock);
mutex_exit(&pidlock);
if (rctl_entity_obtain_rset(rde, rp) == rset) {
ret |= RCT_SIGNAL;
if (sqp == NULL)
sigtoproc(rp, NULL,
recip_signal);
else
sigaddqa(rp, NULL, sqp);
} else if (sqp) {
kmem_free(sqp, sizeof (sigqueue_t));
}
mutex_exit(&rp->p_lock);
} else {
mutex_exit(&pidlock);
if (sqp)
kmem_free(sqp, sizeof (sigqueue_t));
}
mutex_enter(&p->p_lock);
ret |= RCT_LK_ABANDONED;
} else if (sqp) {
kmem_free(sqp, sizeof (sigqueue_t));
}
}
if ((flagaction & RCTL_LOCAL_DENY) &&
(recipient == NULL || recipient == p)) {
ret |= RCT_DENY;
}
return (ret);
}
int
rctl_action(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p, uint_t safety)
{
return (rctl_action_entity(hndl, rset, p, NULL, safety));
}
int
rctl_action_entity(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p,
rctl_entity_p_t *e, uint_t safety)
{
int ret = RCT_NONE;
rctl_t *lrctl;
rctl_entity_p_t e_tmp;
rctl_action_acquire:
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, hndl, &lrctl) == -1) {
mutex_exit(&rset->rcs_lock);
return (ret);
}
if (e == NULL) {
rctl_entity_obtain_entity_p(lrctl->rc_dict_entry->rcd_entity,
p, &e_tmp);
e = &e_tmp;
}
if ((ret & RCT_LK_ABANDONED) == 0) {
ret |= rctl_global_action(lrctl, rset, p, lrctl->rc_cursor);
RCTLOP_ACTION(lrctl, p, e);
ret |= rctl_local_action(lrctl, rset, p,
lrctl->rc_cursor, safety);
if (ret & RCT_LK_ABANDONED)
goto rctl_action_acquire;
}
ret &= ~RCT_LK_ABANDONED;
if (!(ret & RCT_DENY) &&
lrctl->rc_cursor->rcv_next != NULL) {
lrctl->rc_cursor = lrctl->rc_cursor->rcv_next;
RCTLOP_SET(lrctl, p, e, rctl_model_value(lrctl->rc_dict_entry,
p, lrctl->rc_cursor->rcv_value));
}
mutex_exit(&rset->rcs_lock);
return (ret);
}
int
rctl_test(rctl_hndl_t rhndl, rctl_set_t *rset, struct proc *p,
rctl_qty_t incr, uint_t flags)
{
return (rctl_test_entity(rhndl, rset, p, NULL, incr, flags));
}
int
rctl_test_entity(rctl_hndl_t rhndl, rctl_set_t *rset, struct proc *p,
rctl_entity_p_t *e, rctl_qty_t incr, uint_t flags)
{
rctl_t *lrctl;
int ret = RCT_NONE;
rctl_entity_p_t e_tmp;
if (p == &p0) {
return (ret);
}
rctl_test_acquire:
ASSERT(MUTEX_HELD(&p->p_lock));
mutex_enter(&rset->rcs_lock);
if (rctl_set_find(rset, rhndl, &lrctl) == -1) {
mutex_exit(&rset->rcs_lock);
return (ret);
}
if ((lrctl->rc_dict_entry->rcd_flagaction & RCTL_GLOBAL_INFINITE) &&
(lrctl->rc_cursor->rcv_flagaction & RCTL_LOCAL_MAXIMAL)) {
mutex_exit(&rset->rcs_lock);
return (ret);
}
if (e == NULL) {
rctl_entity_obtain_entity_p(lrctl->rc_dict_entry->rcd_entity,
p, &e_tmp);
e = &e_tmp;
}
while (RCTLOP_TEST(lrctl, p, e, lrctl->rc_cursor, incr, flags)) {
if ((ret & RCT_LK_ABANDONED) == 0) {
ret |= rctl_global_action(lrctl, rset, p,
lrctl->rc_cursor);
RCTLOP_ACTION(lrctl, p, e);
ret |= rctl_local_action(lrctl, rset, p,
lrctl->rc_cursor, flags);
if (ret & RCT_LK_ABANDONED)
goto rctl_test_acquire;
}
ret &= ~RCT_LK_ABANDONED;
if ((ret & RCT_DENY) == RCT_DENY ||
lrctl->rc_cursor->rcv_next == NULL) {
ret |= RCT_DENY;
break;
}
lrctl->rc_cursor = lrctl->rc_cursor->rcv_next;
RCTLOP_SET(lrctl, p, e, rctl_model_value(lrctl->rc_dict_entry,
p, lrctl->rc_cursor->rcv_value));
}
mutex_exit(&rset->rcs_lock);
return (ret);
}
void
rctl_init(void)
{
rctl_cache = kmem_cache_create("rctl_cache", sizeof (rctl_t),
0, NULL, NULL, NULL, NULL, NULL, 0);
rctl_val_cache = kmem_cache_create("rctl_val_cache",
sizeof (rctl_val_t), 0, NULL, NULL, NULL, NULL, NULL, 0);
rctl_dict = mod_hash_create_extended("rctl_dict",
rctl_dict_size, mod_hash_null_keydtor, rctl_dict_val_dtor,
rctl_dict_hash_by_id, NULL, rctl_dict_id_cmp, KM_SLEEP);
rctl_dict_by_name = mod_hash_create_strhash(
"rctl_handles_by_name", rctl_dict_size,
mod_hash_null_valdtor);
rctl_ids = id_space_create("rctl_ids", 1, max_rctl_hndl);
bzero(rctl_lists, (RC_MAX_ENTITY + 1) * sizeof (rctl_dict_entry_t *));
rctlproc_init();
}
int
rctl_incr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc,
int chargeproc)
{
kproject_t *projp;
zone_t *zonep;
rctl_entity_p_t e;
int ret = 0;
ASSERT(p != NULL);
ASSERT(MUTEX_HELD(&p->p_lock));
if (proj != NULL) {
projp = proj;
zonep = proj->kpj_zone;
} else {
projp = p->p_task->tk_proj;
zonep = p->p_zone;
}
mutex_enter(&zonep->zone_mem_lock);
e.rcep_p.proj = projp;
e.rcep_t = RCENTITY_PROJECT;
if ((projp->kpj_data.kpd_locked_mem + inc) <
projp->kpj_data.kpd_locked_mem) {
ret = EAGAIN;
goto out;
}
if (projp->kpj_data.kpd_locked_mem + inc >
projp->kpj_data.kpd_locked_mem_ctl) {
if (rctl_test_entity(rc_project_locked_mem, projp->kpj_rctls,
p, &e, inc, 0) & RCT_DENY) {
ret = EAGAIN;
goto out;
}
}
e.rcep_p.zone = zonep;
e.rcep_t = RCENTITY_ZONE;
if ((zonep->zone_locked_mem + inc) < zonep->zone_locked_mem) {
ret = EAGAIN;
goto out;
}
if (zonep->zone_locked_mem + inc > zonep->zone_locked_mem_ctl) {
if (rctl_test_entity(rc_zone_locked_mem, zonep->zone_rctls,
p, &e, inc, 0) & RCT_DENY) {
ret = EAGAIN;
goto out;
}
}
zonep->zone_locked_mem += inc;
projp->kpj_data.kpd_locked_mem += inc;
if (chargeproc != 0) {
p->p_locked_mem += inc;
}
out:
mutex_exit(&zonep->zone_mem_lock);
return (ret);
}
void
rctl_decr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc,
int creditproc)
{
kproject_t *projp;
zone_t *zonep;
if (proj != NULL) {
projp = proj;
zonep = proj->kpj_zone;
} else {
ASSERT(p != NULL);
ASSERT(MUTEX_HELD(&p->p_lock));
projp = p->p_task->tk_proj;
zonep = p->p_zone;
}
mutex_enter(&zonep->zone_mem_lock);
zonep->zone_locked_mem -= inc;
projp->kpj_data.kpd_locked_mem -= inc;
if (creditproc != 0) {
ASSERT(p != NULL);
ASSERT(MUTEX_HELD(&p->p_lock));
p->p_locked_mem -= inc;
}
mutex_exit(&zonep->zone_mem_lock);
}
int
rctl_incr_swap(proc_t *proc, zone_t *zone, size_t swap)
{
rctl_entity_p_t e;
ASSERT(MUTEX_HELD(&proc->p_lock));
ASSERT((swap & PAGEOFFSET) == 0);
e.rcep_p.zone = zone;
e.rcep_t = RCENTITY_ZONE;
mutex_enter(&zone->zone_mem_lock);
if ((zone->zone_max_swap + swap) < zone->zone_max_swap) {
mutex_exit(&zone->zone_mem_lock);
return (EAGAIN);
}
if ((zone->zone_max_swap + swap) >
zone->zone_max_swap_ctl) {
if (rctl_test_entity(rc_zone_max_swap, zone->zone_rctls,
proc, &e, swap, 0) & RCT_DENY) {
mutex_exit(&zone->zone_mem_lock);
return (EAGAIN);
}
}
zone->zone_max_swap += swap;
mutex_exit(&zone->zone_mem_lock);
return (0);
}
void
rctl_decr_swap(zone_t *zone, size_t swap)
{
ASSERT((swap & PAGEOFFSET) == 0);
mutex_enter(&zone->zone_mem_lock);
ASSERT(zone->zone_max_swap >= swap);
zone->zone_max_swap -= swap;
mutex_exit(&zone->zone_mem_lock);
}
int
rctl_incr_lofi(proc_t *proc, zone_t *zone, size_t incr)
{
rctl_entity_p_t e;
ASSERT(MUTEX_HELD(&proc->p_lock));
ASSERT(incr > 0);
e.rcep_p.zone = zone;
e.rcep_t = RCENTITY_ZONE;
mutex_enter(&zone->zone_rctl_lock);
if ((zone->zone_max_lofi + incr) < zone->zone_max_lofi) {
mutex_exit(&zone->zone_rctl_lock);
return (EAGAIN);
}
if ((zone->zone_max_lofi + incr) > zone->zone_max_lofi_ctl) {
if (rctl_test_entity(rc_zone_max_lofi, zone->zone_rctls,
proc, &e, incr, 0) & RCT_DENY) {
mutex_exit(&zone->zone_rctl_lock);
return (EAGAIN);
}
}
zone->zone_max_lofi += incr;
mutex_exit(&zone->zone_rctl_lock);
return (0);
}
void
rctl_decr_lofi(zone_t *zone, size_t decr)
{
mutex_enter(&zone->zone_rctl_lock);
ASSERT(zone->zone_max_lofi >= decr);
zone->zone_max_lofi -= decr;
mutex_exit(&zone->zone_rctl_lock);
}
static kstat_t *
rctl_kstat_create_common(char *ks_name, int ks_instance, char *ks_class,
uchar_t ks_type, uint_t ks_ndata, uchar_t ks_flags, int ks_zoneid)
{
kstat_t *ksp = NULL;
char name[KSTAT_STRLEN];
(void) snprintf(name, KSTAT_STRLEN, "%s_%d", ks_name, ks_instance);
if ((ksp = kstat_create_zone("caps", ks_zoneid,
name, ks_class, ks_type,
ks_ndata, ks_flags, ks_zoneid)) != NULL) {
if (ks_zoneid != GLOBAL_ZONEID)
kstat_zone_add(ksp, GLOBAL_ZONEID);
}
return (ksp);
}
kstat_t *
rctl_kstat_create_zone(zone_t *zone, char *ks_name, uchar_t ks_type,
uint_t ks_ndata, uchar_t ks_flags)
{
char name[KSTAT_STRLEN];
(void) snprintf(name, KSTAT_STRLEN, "%s_zone", ks_name);
return (rctl_kstat_create_common(name, zone->zone_id, "zone_caps",
ks_type, ks_ndata, ks_flags, zone->zone_id));
}
kstat_t *
rctl_kstat_create_project(kproject_t *kpj, char *ks_name, uchar_t ks_type,
uint_t ks_ndata, uchar_t ks_flags)
{
char name[KSTAT_STRLEN];
(void) snprintf(name, KSTAT_STRLEN, "%s_project", ks_name);
return (rctl_kstat_create_common(name, kpj->kpj_id, "project_caps",
ks_type, ks_ndata, ks_flags, kpj->kpj_zoneid));
}
kstat_t *
rctl_kstat_create_task(task_t *tk, char *ks_name, uchar_t ks_type,
uint_t ks_ndata, uchar_t ks_flags)
{
char name[KSTAT_STRLEN];
(void) snprintf(name, KSTAT_STRLEN, "%s_task", ks_name);
return (rctl_kstat_create_common(name, tk->tk_tkid, "task_caps",
ks_type, ks_ndata, ks_flags, tk->tk_proj->kpj_zoneid));
}