puffs_subr.c revision 1.23.2.1       1 /*	$NetBSD: puffs_subr.c,v 1.23.2.1 2007/07/11 20:09:29 mjf Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 2005, 2006  Antti Kantee.  All Rights Reserved.
      5  *
      6  * Development of this software was supported by the
      7  * Google Summer of Code program and the Ulla Tuominen Foundation.
      8  * The Google SoC project was mentored by Bill Studenmund.
      9  *
     10  * Redistribution and use in source and binary forms, with or without
     11  * modification, are permitted provided that the following conditions
     12  * are met:
     13  * 1. Redistributions of source code must retain the above copyright
     14  *    notice, this list of conditions and the following disclaimer.
     15  * 2. Redistributions in binary form must reproduce the above copyright
     16  *    notice, this list of conditions and the following disclaimer in the
     17  *    documentation and/or other materials provided with the distribution.
     18  *
     19  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS
     20  * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
     21  * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
     22  * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     23  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     24  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
     25  * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     26  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     27  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     28  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     29  * SUCH DAMAGE.
     30  */
     31 
     32 #include <sys/cdefs.h>
     33 __KERNEL_RCSID(0, "$NetBSD: puffs_subr.c,v 1.23.2.1 2007/07/11 20:09:29 mjf Exp $");
     34 
     35 #include <sys/param.h>
     36 #include <sys/conf.h>
     37 #include <sys/hash.h>
     38 #include <sys/kauth.h>
     39 #include <sys/malloc.h>
     40 #include <sys/mount.h>
     41 #include <sys/namei.h>
     42 #include <sys/poll.h>
     43 #include <sys/socketvar.h>
     44 #include <sys/vnode.h>
     45 #include <sys/proc.h>
     46 
     47 #include <fs/puffs/puffs_msgif.h>
     48 #include <fs/puffs/puffs_sys.h>
     49 
     50 #include <miscfs/genfs/genfs_node.h>
     51 #include <miscfs/specfs/specdev.h>
     52 
     53 struct pool puffs_pnpool;
     54 
     55 #ifdef PUFFSDEBUG
     56 int puffsdebug;
     57 #endif
     58 
     59 static __inline struct puffs_node_hashlist
     60 	*puffs_cookie2hashlist(struct puffs_mount *, void *);
     61 static struct puffs_node *puffs_cookie2pnode(struct puffs_mount *, void *);
     62 
     63 static void puffs_gop_size(struct vnode *, off_t, off_t *, int);
     64 static void puffs_gop_markupdate(struct vnode *, int);
     65 
     66 static const struct genfs_ops puffs_genfsops = {
     67 	.gop_size = puffs_gop_size,
     68 	.gop_write = genfs_gop_write,
     69 	.gop_markupdate = puffs_gop_markupdate,
     70 #if 0
     71 	.gop_alloc, should ask userspace
     72 #endif
     73 };
     74 
     75 /*
     76  * Grab a vnode, intialize all the puffs-dependant stuff.
     77  */
     78 int
     79 puffs_getvnode(struct mount *mp, void *cookie, enum vtype type,
     80 	voff_t vsize, dev_t rdev, struct vnode **vpp)
     81 {
     82 	struct puffs_mount *pmp;
     83 	struct vnode *vp, *nvp;
     84 	struct puffs_node *pnode;
     85 	struct puffs_node_hashlist *plist;
     86 	int error;
     87 
     88 	if (type <= VNON || type >= VBAD)
     89 		return EINVAL;
     90 
     91 	pmp = MPTOPUFFSMP(mp);
     92 
     93 	/*
     94 	 * XXX: there is a deadlock condition between vfs_busy() and
     95 	 * vnode locks.  For an unmounting file system the mountpoint
     96 	 * is frozen, but in unmount(FORCE) vflush() wants to access all
     97 	 * of the vnodes.  If we are here waiting for the mountpoint
     98 	 * lock while holding on to a vnode lock, well, we ain't
     99 	 * just pining for the fjords anymore.  If we release the
    100 	 * vnode lock, we will be in the situation "mount point
    101 	 * is dying" and panic() will ensue in insmntque.  So as a
    102 	 * temporary workaround, get a vnode without putting it on
    103 	 * the mount point list, check if mount point is still alive
    104 	 * and kicking and only then add the vnode to the list.
    105 	 */
    106 	error = getnewvnode(VT_PUFFS, NULL, puffs_vnodeop_p, &vp);
    107 	if (error)
    108 		return error;
    109 	vp->v_vnlock = NULL;
    110 	vp->v_type = type;
    111 
    112 	/*
    113 	 * Check what mount point isn't going away.  This will work
    114 	 * until we decide to remove biglock or make the kernel
    115 	 * preemptive.  But hopefully the real problem will be fixed
    116 	 * by then.
    117 	 *
    118 	 * XXX: yes, should call vfs_busy(), but thar be rabbits with
    119 	 * vicious streaks a mile wide ...
    120 	 */
    121 	if (mp->mnt_iflag & IMNT_UNMOUNT) {
    122 		DPRINTF(("puffs_getvnode: mp %p unmount, unable to create "
    123 		    "vnode for cookie %p\n", mp, cookie));
    124 		ungetnewvnode(vp);
    125 		return ENXIO;
    126 	}
    127 
    128 	/* So it's not dead yet.. good.. inform new vnode of its master */
    129 	simple_lock(&mntvnode_slock);
    130 	TAILQ_INSERT_TAIL(&mp->mnt_vnodelist, vp, v_mntvnodes);
    131 	simple_unlock(&mntvnode_slock);
    132 	vp->v_mount = mp;
    133 
    134 	/*
    135 	 * clerical tasks & footwork
    136 	 */
    137 
    138 	/* default size */
    139 	uvm_vnp_setsize(vp, 0);
    140 
    141 	/* dances based on vnode type. almost ufs_vinit(), but not quite */
    142 	switch (type) {
    143 	case VCHR:
    144 	case VBLK:
    145 		/*
    146 		 * replace vnode operation vector with the specops vector.
    147 		 * our user server has very little control over the node
    148 		 * if it decides its a character or block special file
    149 		 */
    150 		vp->v_op = puffs_specop_p;
    151 
    152 		/* do the standard checkalias-dance */
    153 		if ((nvp = checkalias(vp, rdev, mp)) != NULL) {
    154 			/*
    155 			 * found: release & unallocate aliased
    156 			 * old (well, actually, new) node
    157 			 */
    158 			vp->v_op = spec_vnodeop_p;
    159 			vp->v_flag &= ~VLOCKSWORK;
    160 			vrele(vp);
    161 			vgone(vp); /* cya */
    162 
    163 			/* init "new" vnode */
    164 			vp = nvp;
    165 			vp->v_vnlock = NULL;
    166 			vp->v_mount = mp;
    167 		}
    168 		break;
    169 
    170 	case VFIFO:
    171 		vp->v_op = puffs_fifoop_p;
    172 		break;
    173 
    174 	case VREG:
    175 		uvm_vnp_setsize(vp, vsize);
    176 		break;
    177 
    178 	case VDIR:
    179 	case VLNK:
    180 	case VSOCK:
    181 		break;
    182 	default:
    183 #ifdef DIAGNOSTIC
    184 		panic("puffs_getvnode: invalid vtype %d", type);
    185 #endif
    186 		break;
    187 	}
    188 
    189 	pnode = pool_get(&puffs_pnpool, PR_WAITOK);
    190 	pnode->pn_cookie = cookie;
    191 	pnode->pn_stat = 0;
    192 	pnode->pn_refcount = 1;
    193 
    194 	mutex_init(&pnode->pn_mtx, MUTEX_DEFAULT, IPL_NONE);
    195 	SLIST_INIT(&pnode->pn_sel.sel_klist);
    196 	pnode->pn_revents = 0;
    197 
    198 	plist = puffs_cookie2hashlist(pmp, cookie);
    199 	LIST_INSERT_HEAD(plist, pnode, pn_hashent);
    200 	vp->v_data = pnode;
    201 	vp->v_type = type;
    202 	pnode->pn_vp = vp;
    203 
    204 	genfs_node_init(vp, &puffs_genfsops);
    205 	*vpp = vp;
    206 
    207 	DPRINTF(("new vnode at %p, pnode %p, cookie %p\n", vp,
    208 	    pnode, pnode->pn_cookie));
    209 
    210 	return 0;
    211 }
    212 
    213 /* new node creating for creative vop ops (create, symlink, mkdir, mknod) */
    214 int
    215 puffs_newnode(struct mount *mp, struct vnode *dvp, struct vnode **vpp,
    216 	void *cookie, struct componentname *cnp, enum vtype type, dev_t rdev)
    217 {
    218 	struct puffs_mount *pmp = MPTOPUFFSMP(mp);
    219 	struct vnode *vp;
    220 	int error;
    221 
    222 	/* userspace probably has this as a NULL op */
    223 	if (cookie == NULL) {
    224 		error = EOPNOTSUPP;
    225 		return error;
    226 	}
    227 
    228 	/*
    229 	 * Check for previous node with the same designation.
    230 	 * Explicitly check the root node cookie, since it might be
    231 	 * reclaimed from the kernel when this check is made.
    232 	 *
    233 	 * XXX: technically this error check should punish the fs,
    234 	 * not the caller.
    235 	 */
    236 	mutex_enter(&pmp->pmp_lock);
    237 	if (cookie == pmp->pmp_root_cookie
    238 	    || puffs_cookie2pnode(pmp, cookie) != NULL) {
    239 		mutex_exit(&pmp->pmp_lock);
    240 		error = EEXIST;
    241 		return error;
    242 	}
    243 	mutex_exit(&pmp->pmp_lock);
    244 
    245 	error = puffs_getvnode(dvp->v_mount, cookie, type, 0, rdev, &vp);
    246 	if (error)
    247 		return error;
    248 
    249 	vp->v_type = type;
    250 	vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
    251 	*vpp = vp;
    252 
    253 	if ((cnp->cn_flags & MAKEENTRY) && PUFFS_USE_NAMECACHE(pmp))
    254 		cache_enter(dvp, vp, cnp);
    255 
    256 	return 0;
    257 }
    258 
    259 /*
    260  * Release pnode structure which dealing with references to the
    261  * puffs_node instead of the vnode.  Can't use vref()/vrele() on
    262  * the vnode there, since that causes the lovely VOP_INACTIVE(),
    263  * which in turn causes the lovely deadlock when called by the one
    264  * who is supposed to handle it.
    265  */
    266 void
    267 puffs_releasenode(struct puffs_node *pn)
    268 {
    269 
    270 	mutex_enter(&pn->pn_mtx);
    271 	if (--pn->pn_refcount == 0) {
    272 		mutex_exit(&pn->pn_mtx);
    273 		mutex_destroy(&pn->pn_mtx);
    274 		pool_put(&puffs_pnpool, pn);
    275 	} else {
    276 		mutex_exit(&pn->pn_mtx);
    277 	}
    278 }
    279 
    280 /*
    281  * Add reference to node.
    282  *  mutex held on entry and return
    283  */
    284 void
    285 puffs_referencenode(struct puffs_node *pn)
    286 {
    287 
    288 	KASSERT(mutex_owned(&pn->pn_mtx));
    289 	pn->pn_refcount++;
    290 }
    291 
    292 void
    293 puffs_putvnode(struct vnode *vp)
    294 {
    295 	struct puffs_mount *pmp;
    296 	struct puffs_node *pnode;
    297 
    298 	pmp = VPTOPUFFSMP(vp);
    299 	pnode = VPTOPP(vp);
    300 
    301 #ifdef DIAGNOSTIC
    302 	if (vp->v_tag != VT_PUFFS)
    303 		panic("puffs_putvnode: %p not a puffs vnode", vp);
    304 #endif
    305 
    306 	LIST_REMOVE(pnode, pn_hashent);
    307 	genfs_node_destroy(vp);
    308 	puffs_releasenode(pnode);
    309 	vp->v_data = NULL;
    310 
    311 	return;
    312 }
    313 
    314 static __inline struct puffs_node_hashlist *
    315 puffs_cookie2hashlist(struct puffs_mount *pmp, void *cookie)
    316 {
    317 	uint32_t hash;
    318 
    319 	hash = hash32_buf(&cookie, sizeof(void *), HASH32_BUF_INIT);
    320 	return &pmp->pmp_pnodehash[hash % pmp->pmp_npnodehash];
    321 }
    322 
    323 /*
    324  * Translate cookie to puffs_node.  Caller must hold mountpoint
    325  * lock and it will be held upon return.
    326  */
    327 static struct puffs_node *
    328 puffs_cookie2pnode(struct puffs_mount *pmp, void *cookie)
    329 {
    330 	struct puffs_node_hashlist *plist;
    331 	struct puffs_node *pnode;
    332 
    333 	plist = puffs_cookie2hashlist(pmp, cookie);
    334 	LIST_FOREACH(pnode, plist, pn_hashent) {
    335 		if (pnode->pn_cookie == cookie)
    336 			break;
    337 	}
    338 
    339 	return pnode;
    340 }
    341 
    342 /*
    343  * Make sure root vnode exists and reference it.  Does NOT lock.
    344  */
    345 static int
    346 puffs_makeroot(struct puffs_mount *pmp)
    347 {
    348 	struct vnode *vp;
    349 	int rv;
    350 
    351 	/*
    352 	 * pmp_lock must be held if vref()'ing or vrele()'ing the
    353 	 * root vnode.  the latter is controlled by puffs_inactive().
    354 	 *
    355 	 * pmp_root is set here and cleared in puffs_reclaim().
    356 	 */
    357  retry:
    358 	mutex_enter(&pmp->pmp_lock);
    359 	vp = pmp->pmp_root;
    360 	if (vp) {
    361 		simple_lock(&vp->v_interlock);
    362 		mutex_exit(&pmp->pmp_lock);
    363 		if (vget(vp, LK_INTERLOCK) == 0)
    364 			return 0;
    365 	} else
    366 		mutex_exit(&pmp->pmp_lock);
    367 
    368 	/*
    369 	 * So, didn't have the magic root vnode available.
    370 	 * No matter, grab another an stuff it with the cookie.
    371 	 */
    372 	if ((rv = puffs_getvnode(pmp->pmp_mp, pmp->pmp_root_cookie,
    373 	    pmp->pmp_root_vtype, pmp->pmp_root_vsize, pmp->pmp_root_rdev, &vp)))
    374 		return rv;
    375 
    376 	/*
    377 	 * Someone magically managed to race us into puffs_getvnode?
    378 	 * Put our previous new vnode back and retry.
    379 	 */
    380 	mutex_enter(&pmp->pmp_lock);
    381 	if (pmp->pmp_root) {
    382 		mutex_exit(&pmp->pmp_lock);
    383 		puffs_putvnode(vp);
    384 		goto retry;
    385 	}
    386 
    387 	/* store cache */
    388 	vp->v_flag = VROOT;
    389 	pmp->pmp_root = vp;
    390 	mutex_exit(&pmp->pmp_lock);
    391 
    392 	return 0;
    393 }
    394 
    395 /*
    396  * Locate the in-kernel vnode based on the cookie received given
    397  * from userspace.  Returns a vnode, if found, NULL otherwise.
    398  * The parameter "lock" control whether to lock the possible or
    399  * not.  Locking always might cause us to lock against ourselves
    400  * in situations where we want the vnode but don't care for the
    401  * vnode lock, e.g. file server issued putpages.
    402  */
    403 int
    404 puffs_pnode2vnode(struct puffs_mount *pmp, void *cookie, int lock,
    405 	struct vnode **vpp)
    406 {
    407 	struct puffs_node *pnode;
    408 	struct vnode *vp;
    409 	int vgetflags, rv;
    410 
    411 	/*
    412 	 * Handle root in a special manner, since we want to make sure
    413 	 * pmp_root is properly set.
    414 	 */
    415 	if (cookie == pmp->pmp_root_cookie) {
    416 		if ((rv = puffs_makeroot(pmp)))
    417 			return rv;
    418 		if (lock)
    419 			vn_lock(pmp->pmp_root, LK_EXCLUSIVE | LK_RETRY);
    420 
    421 		*vpp = pmp->pmp_root;
    422 		return 0;
    423 	}
    424 
    425 	mutex_enter(&pmp->pmp_lock);
    426 	pnode = puffs_cookie2pnode(pmp, cookie);
    427 
    428 	if (pnode == NULL) {
    429 		mutex_exit(&pmp->pmp_lock);
    430 		return ENOENT;
    431 	}
    432 
    433 	vp = pnode->pn_vp;
    434 	simple_lock(&vp->v_interlock);
    435 	mutex_exit(&pmp->pmp_lock);
    436 
    437 	vgetflags = LK_INTERLOCK;
    438 	if (lock)
    439 		vgetflags |= LK_EXCLUSIVE | LK_RETRY;
    440 	if ((rv = vget(vp, vgetflags)))
    441 		return rv;
    442 
    443 	*vpp = vp;
    444 	return 0;
    445 }
    446 
    447 void
    448 puffs_makecn(struct puffs_kcn *pkcn, struct puffs_kcred *pkcr,
    449 	struct puffs_kcid *pkcid, const struct componentname *cn, int full)
    450 {
    451 
    452 	pkcn->pkcn_nameiop = cn->cn_nameiop;
    453 	pkcn->pkcn_flags = cn->cn_flags;
    454 	puffs_cidcvt(pkcid, cn->cn_lwp);
    455 
    456 	if (full) {
    457 		(void)strcpy(pkcn->pkcn_name, cn->cn_nameptr);
    458 	} else {
    459 		(void)memcpy(pkcn->pkcn_name, cn->cn_nameptr, cn->cn_namelen);
    460 		pkcn->pkcn_name[cn->cn_namelen] = '\0';
    461 	}
    462 	pkcn->pkcn_namelen = cn->cn_namelen;
    463 	pkcn->pkcn_consume = 0;
    464 
    465 	puffs_credcvt(pkcr, cn->cn_cred);
    466 }
    467 
    468 /*
    469  * Convert given credentials to struct puffs_kcred for userspace.
    470  */
    471 void
    472 puffs_credcvt(struct puffs_kcred *pkcr, const kauth_cred_t cred)
    473 {
    474 
    475 	memset(pkcr, 0, sizeof(struct puffs_kcred));
    476 
    477 	if (cred == NOCRED || cred == FSCRED) {
    478 		pkcr->pkcr_type = PUFFCRED_TYPE_INTERNAL;
    479 		if (cred == NOCRED)
    480 			pkcr->pkcr_internal = PUFFCRED_CRED_NOCRED;
    481 		if (cred == FSCRED)
    482 			pkcr->pkcr_internal = PUFFCRED_CRED_FSCRED;
    483  	} else {
    484 		pkcr->pkcr_type = PUFFCRED_TYPE_UUC;
    485 		kauth_cred_to_uucred(&pkcr->pkcr_uuc, cred);
    486 	}
    487 }
    488 
    489 void
    490 puffs_cidcvt(struct puffs_kcid *pkcid, const struct lwp *l)
    491 {
    492 
    493 	if (l) {
    494 		pkcid->pkcid_type = PUFFCID_TYPE_REAL;
    495 		pkcid->pkcid_pid = l->l_proc->p_pid;
    496 		pkcid->pkcid_lwpid = l->l_lid;
    497 	} else {
    498 		pkcid->pkcid_type = PUFFCID_TYPE_FAKE;
    499 		pkcid->pkcid_pid = 0;
    500 		pkcid->pkcid_lwpid = 0;
    501 	}
    502 }
    503 
    504 static void
    505 puffs_gop_size(struct vnode *vp, off_t size, off_t *eobp,
    506 	int flags)
    507 {
    508 
    509 	*eobp = size;
    510 }
    511 
    512 static void
    513 puffs_gop_markupdate(struct vnode *vp, int flags)
    514 {
    515 	int uflags = 0;
    516 
    517 	if (flags & GOP_UPDATE_ACCESSED)
    518 		uflags |= PUFFS_UPDATEATIME;
    519 	if (flags & GOP_UPDATE_MODIFIED)
    520 		uflags |= PUFFS_UPDATEMTIME;
    521 
    522 	puffs_updatenode(vp, uflags);
    523 }
    524 
    525 void
    526 puffs_updatenode(struct vnode *vp, int flags)
    527 {
    528 	struct puffs_node *pn;
    529 	struct timespec ts;
    530 
    531 	if (flags == 0)
    532 		return;
    533 
    534 	pn = VPTOPP(vp);
    535 	nanotime(&ts);
    536 
    537 	if (flags & PUFFS_UPDATEATIME) {
    538 		pn->pn_mc_atime = ts;
    539 		pn->pn_stat |= PNODE_METACACHE_ATIME;
    540 	}
    541 	if (flags & PUFFS_UPDATECTIME) {
    542 		pn->pn_mc_ctime = ts;
    543 		pn->pn_stat |= PNODE_METACACHE_CTIME;
    544 	}
    545 	if (flags & PUFFS_UPDATEMTIME) {
    546 		pn->pn_mc_mtime = ts;
    547 		pn->pn_stat |= PNODE_METACACHE_MTIME;
    548 	}
    549 	if (flags & PUFFS_UPDATESIZE) {
    550 		pn->pn_mc_size = vp->v_size;
    551 		pn->pn_stat |= PNODE_METACACHE_SIZE;
    552 	}
    553 }
    554 
    555 void
    556 puffs_updatevpsize(struct vnode *vp)
    557 {
    558 	struct vattr va;
    559 
    560 	if (VOP_GETATTR(vp, &va, FSCRED, NULL))
    561 		return;
    562 
    563 	if (va.va_size != VNOVAL)
    564 		vp->v_size = va.va_size;
    565 }
    566 
    567 void
    568 puffs_parkdone_asyncbioread(struct puffs_req *preq, void *arg)
    569 {
    570 	struct puffs_vnreq_read *read_argp = (void *)preq;
    571 	struct buf *bp = arg;
    572 	size_t moved;
    573 
    574 	bp->b_error = preq->preq_rv;
    575 	if (bp->b_error == 0) {
    576 		moved = bp->b_bcount - read_argp->pvnr_resid;
    577 		bp->b_resid = read_argp->pvnr_resid;
    578 
    579 		memcpy(bp->b_data, read_argp->pvnr_data, moved);
    580 	} else {
    581 		bp->b_flags |= B_ERROR;
    582 	}
    583 
    584 	biodone(bp);
    585 	free(preq, M_PUFFS);
    586 }
    587 
    588 void
    589 puffs_parkdone_poll(struct puffs_req *preq, void *arg)
    590 {
    591 	struct puffs_vnreq_poll *poll_argp = (void *)preq;
    592 	struct puffs_node *pn = arg;
    593 	int revents;
    594 
    595 	if (preq->preq_rv == 0)
    596 		revents = poll_argp->pvnr_events;
    597 	else
    598 		revents = POLLERR;
    599 
    600 	mutex_enter(&pn->pn_mtx);
    601 	pn->pn_revents |= revents;
    602 	mutex_exit(&pn->pn_mtx);
    603 
    604 	selnotify(&pn->pn_sel, 0);
    605 	free(preq, M_PUFFS);
    606 
    607 	puffs_releasenode(pn);
    608 }
    609 
    610 void
    611 puffs_mp_reference(struct puffs_mount *pmp)
    612 {
    613 
    614 	KASSERT(mutex_owned(&pmp->pmp_lock));
    615 	pmp->pmp_refcount++;
    616 }
    617 
    618 void
    619 puffs_mp_release(struct puffs_mount *pmp)
    620 {
    621 
    622 	KASSERT(mutex_owned(&pmp->pmp_lock));
    623 	if (--pmp->pmp_refcount == 0)
    624 		cv_broadcast(&pmp->pmp_refcount_cv);
    625 }
    626