Home | History | Annotate | Line # | Download | only in kern
kern_malloc.c revision 1.31
      1  1.31       mrg /*	$NetBSD: kern_malloc.c,v 1.31 1998/02/10 14:09:34 mrg Exp $	*/
      2   1.9       cgd 
      3   1.1       cgd /*
      4  1.20       cgd  * Copyright 1996 Christopher G. Demetriou.  All rights reserved.
      5   1.8       cgd  * Copyright (c) 1987, 1991, 1993
      6   1.8       cgd  *	The Regents of the University of California.  All rights reserved.
      7   1.1       cgd  *
      8   1.1       cgd  * Redistribution and use in source and binary forms, with or without
      9   1.1       cgd  * modification, are permitted provided that the following conditions
     10   1.1       cgd  * are met:
     11   1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     12   1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     13   1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     14   1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     15   1.1       cgd  *    documentation and/or other materials provided with the distribution.
     16   1.1       cgd  * 3. All advertising materials mentioning features or use of this software
     17   1.1       cgd  *    must display the following acknowledgement:
     18   1.1       cgd  *	This product includes software developed by the University of
     19   1.1       cgd  *	California, Berkeley and its contributors.
     20   1.1       cgd  * 4. Neither the name of the University nor the names of its contributors
     21   1.1       cgd  *    may be used to endorse or promote products derived from this software
     22   1.1       cgd  *    without specific prior written permission.
     23   1.1       cgd  *
     24   1.1       cgd  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     25   1.1       cgd  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     26   1.1       cgd  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     27   1.1       cgd  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     28   1.1       cgd  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     29   1.1       cgd  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     30   1.1       cgd  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     31   1.1       cgd  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     32   1.1       cgd  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     33   1.1       cgd  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     34   1.1       cgd  * SUCH DAMAGE.
     35   1.1       cgd  *
     36   1.9       cgd  *	@(#)kern_malloc.c	8.3 (Berkeley) 1/4/94
     37   1.1       cgd  */
     38  1.31       mrg 
     39  1.31       mrg #include "opt_uvm.h"
     40   1.1       cgd 
     41   1.7   mycroft #include <sys/param.h>
     42   1.7   mycroft #include <sys/proc.h>
     43   1.8       cgd #include <sys/map.h>
     44   1.7   mycroft #include <sys/kernel.h>
     45   1.7   mycroft #include <sys/malloc.h>
     46  1.12  christos #include <sys/systm.h>
     47   1.7   mycroft 
     48   1.7   mycroft #include <vm/vm.h>
     49   1.7   mycroft #include <vm/vm_kern.h>
     50  1.24   thorpej 
     51  1.28       mrg #if defined(UVM)
     52  1.28       mrg #include <uvm/uvm_extern.h>
     53  1.28       mrg 
     54  1.28       mrg static struct vm_map kmem_map_store;
     55  1.28       mrg vm_map_t kmem_map = NULL;
     56  1.28       mrg #endif
     57  1.28       mrg 
     58  1.24   thorpej #include "opt_kmemstats.h"
     59  1.27   thorpej #include "opt_malloclog.h"
     60  1.12  christos 
     61   1.1       cgd struct kmembuckets bucket[MINBUCKET + 16];
     62   1.8       cgd struct kmemstats kmemstats[M_LAST];
     63   1.1       cgd struct kmemusage *kmemusage;
     64   1.1       cgd char *kmembase, *kmemlimit;
     65  1.25   mycroft const char *memname[] = INITKMEMNAMES;
     66   1.1       cgd 
     67  1.27   thorpej #ifdef MALLOCLOG
     68  1.27   thorpej #ifndef MALLOCLOGSIZE
     69  1.27   thorpej #define	MALLOCLOGSIZE	100000
     70  1.27   thorpej #endif
     71  1.27   thorpej 
     72  1.27   thorpej struct malloclog {
     73  1.27   thorpej 	void *addr;
     74  1.27   thorpej 	long size;
     75  1.27   thorpej 	int type;
     76  1.27   thorpej 	int action;
     77  1.27   thorpej 	const char *file;
     78  1.27   thorpej 	long line;
     79  1.27   thorpej } malloclog[MALLOCLOGSIZE];
     80  1.27   thorpej 
     81  1.27   thorpej long	malloclogptr;
     82  1.27   thorpej 
     83  1.27   thorpej static void domlog __P((void *a, long size, int type, int action,
     84  1.27   thorpej 	const char *file, long line));
     85  1.27   thorpej static void hitmlog __P((void *a));
     86  1.27   thorpej 
     87  1.27   thorpej static void
     88  1.27   thorpej domlog(a, size, type, action, file, line)
     89  1.27   thorpej 	void *a;
     90  1.27   thorpej 	long size;
     91  1.27   thorpej 	int type;
     92  1.27   thorpej 	int action;
     93  1.27   thorpej 	const char *file;
     94  1.27   thorpej 	long line;
     95  1.27   thorpej {
     96  1.27   thorpej 
     97  1.27   thorpej 	malloclog[malloclogptr].addr = a;
     98  1.27   thorpej 	malloclog[malloclogptr].size = size;
     99  1.27   thorpej 	malloclog[malloclogptr].type = type;
    100  1.27   thorpej 	malloclog[malloclogptr].action = action;
    101  1.27   thorpej 	malloclog[malloclogptr].file = file;
    102  1.27   thorpej 	malloclog[malloclogptr].line = line;
    103  1.27   thorpej 	malloclogptr++;
    104  1.27   thorpej 	if (malloclogptr >= MALLOCLOGSIZE)
    105  1.27   thorpej 		malloclogptr = 0;
    106  1.27   thorpej }
    107  1.27   thorpej 
    108  1.27   thorpej static void
    109  1.27   thorpej hitmlog(a)
    110  1.27   thorpej 	void *a;
    111  1.27   thorpej {
    112  1.27   thorpej 	struct malloclog *lp;
    113  1.27   thorpej 	long l;
    114  1.27   thorpej 
    115  1.27   thorpej #define	PRT \
    116  1.27   thorpej 	if (malloclog[l].addr == a && malloclog[l].action) { \
    117  1.27   thorpej 		lp = &malloclog[l]; \
    118  1.27   thorpej 		printf("malloc log entry %ld:\n", l); \
    119  1.27   thorpej 		printf("\taddr = %p\n", lp->addr); \
    120  1.27   thorpej 		printf("\tsize = %ld\n", lp->size); \
    121  1.27   thorpej 		printf("\ttype = %s\n", memname[lp->type]); \
    122  1.27   thorpej 		printf("\taction = %s\n", lp->action == 1 ? "alloc" : "free"); \
    123  1.27   thorpej 		printf("\tfile = %s\n", lp->file); \
    124  1.27   thorpej 		printf("\tline = %ld\n", lp->line); \
    125  1.27   thorpej 	}
    126  1.27   thorpej 
    127  1.27   thorpej 	for (l = malloclogptr; l < MALLOCLOGSIZE; l++)
    128  1.27   thorpej 		PRT
    129  1.27   thorpej 
    130  1.27   thorpej 	for (l = 0; l < malloclogptr; l++)
    131  1.27   thorpej 		PRT
    132  1.27   thorpej }
    133  1.27   thorpej #endif /* MALLOCLOG */
    134  1.27   thorpej 
    135   1.8       cgd #ifdef DIAGNOSTIC
    136   1.8       cgd /*
    137   1.8       cgd  * This structure provides a set of masks to catch unaligned frees.
    138   1.8       cgd  */
    139   1.8       cgd long addrmask[] = { 0,
    140   1.8       cgd 	0x00000001, 0x00000003, 0x00000007, 0x0000000f,
    141   1.8       cgd 	0x0000001f, 0x0000003f, 0x0000007f, 0x000000ff,
    142   1.8       cgd 	0x000001ff, 0x000003ff, 0x000007ff, 0x00000fff,
    143   1.8       cgd 	0x00001fff, 0x00003fff, 0x00007fff, 0x0000ffff,
    144   1.8       cgd };
    145   1.8       cgd 
    146   1.8       cgd /*
    147   1.8       cgd  * The WEIRD_ADDR is used as known text to copy into free objects so
    148   1.8       cgd  * that modifications after frees can be detected.
    149   1.8       cgd  */
    150  1.12  christos #define WEIRD_ADDR	((unsigned) 0xdeadbeef)
    151   1.8       cgd #define MAX_COPY	32
    152   1.8       cgd 
    153   1.8       cgd /*
    154  1.11       cgd  * Normally the freelist structure is used only to hold the list pointer
    155  1.11       cgd  * for free objects.  However, when running with diagnostics, the first
    156  1.11       cgd  * 8 bytes of the structure is unused except for diagnostic information,
    157  1.11       cgd  * and the free list pointer is at offst 8 in the structure.  Since the
    158  1.11       cgd  * first 8 bytes is the portion of the structure most often modified, this
    159  1.11       cgd  * helps to detect memory reuse problems and avoid free list corruption.
    160   1.8       cgd  */
    161   1.8       cgd struct freelist {
    162  1.11       cgd 	int32_t	spare0;
    163  1.11       cgd 	int16_t	type;
    164  1.11       cgd 	int16_t	spare1;
    165   1.8       cgd 	caddr_t	next;
    166   1.8       cgd };
    167   1.8       cgd #else /* !DIAGNOSTIC */
    168   1.8       cgd struct freelist {
    169   1.8       cgd 	caddr_t	next;
    170   1.8       cgd };
    171   1.8       cgd #endif /* DIAGNOSTIC */
    172   1.8       cgd 
    173   1.1       cgd /*
    174   1.1       cgd  * Allocate a block of memory
    175   1.1       cgd  */
    176  1.27   thorpej #ifdef MALLOCLOG
    177  1.27   thorpej void *
    178  1.27   thorpej _malloc(size, type, flags, file, line)
    179  1.27   thorpej 	unsigned long size;
    180  1.27   thorpej 	int type, flags;
    181  1.27   thorpej 	const char *file;
    182  1.27   thorpej 	long line;
    183  1.27   thorpej #else
    184   1.1       cgd void *
    185   1.1       cgd malloc(size, type, flags)
    186   1.1       cgd 	unsigned long size;
    187   1.1       cgd 	int type, flags;
    188  1.27   thorpej #endif /* MALLOCLOG */
    189   1.1       cgd {
    190   1.1       cgd 	register struct kmembuckets *kbp;
    191   1.1       cgd 	register struct kmemusage *kup;
    192   1.8       cgd 	register struct freelist *freep;
    193   1.5    andrew 	long indx, npg, allocsize;
    194   1.1       cgd 	int s;
    195   1.1       cgd 	caddr_t va, cp, savedlist;
    196   1.8       cgd #ifdef DIAGNOSTIC
    197  1.11       cgd 	int32_t *end, *lp;
    198   1.8       cgd 	int copysize;
    199  1.26   mycroft 	const char *savedtype;
    200   1.8       cgd #endif
    201   1.1       cgd #ifdef KMEMSTATS
    202   1.1       cgd 	register struct kmemstats *ksp = &kmemstats[type];
    203   1.1       cgd 
    204   1.1       cgd 	if (((unsigned long)type) > M_LAST)
    205   1.1       cgd 		panic("malloc - bogus type");
    206   1.1       cgd #endif
    207   1.1       cgd 	indx = BUCKETINDX(size);
    208   1.1       cgd 	kbp = &bucket[indx];
    209   1.1       cgd 	s = splimp();
    210   1.1       cgd #ifdef KMEMSTATS
    211   1.1       cgd 	while (ksp->ks_memuse >= ksp->ks_limit) {
    212   1.1       cgd 		if (flags & M_NOWAIT) {
    213   1.1       cgd 			splx(s);
    214   1.1       cgd 			return ((void *) NULL);
    215   1.1       cgd 		}
    216   1.1       cgd 		if (ksp->ks_limblocks < 65535)
    217   1.1       cgd 			ksp->ks_limblocks++;
    218   1.1       cgd 		tsleep((caddr_t)ksp, PSWP+2, memname[type], 0);
    219   1.1       cgd 	}
    220   1.8       cgd 	ksp->ks_size |= 1 << indx;
    221   1.8       cgd #endif
    222   1.8       cgd #ifdef DIAGNOSTIC
    223   1.8       cgd 	copysize = 1 << indx < MAX_COPY ? 1 << indx : MAX_COPY;
    224   1.1       cgd #endif
    225   1.1       cgd 	if (kbp->kb_next == NULL) {
    226   1.8       cgd 		kbp->kb_last = NULL;
    227   1.1       cgd 		if (size > MAXALLOCSAVE)
    228   1.1       cgd 			allocsize = roundup(size, CLBYTES);
    229   1.1       cgd 		else
    230   1.1       cgd 			allocsize = 1 << indx;
    231   1.1       cgd 		npg = clrnd(btoc(allocsize));
    232  1.28       mrg #if defined(UVM)
    233  1.28       mrg 		va = (caddr_t) uvm_km_kmemalloc(kmem_map, uvmexp.kmem_object,
    234  1.28       mrg 				(vm_size_t)ctob(npg),
    235  1.28       mrg 				(flags & M_NOWAIT) ? UVM_KMF_NOWAIT : 0);
    236  1.28       mrg #else
    237   1.1       cgd 		va = (caddr_t) kmem_malloc(kmem_map, (vm_size_t)ctob(npg),
    238   1.1       cgd 					   !(flags & M_NOWAIT));
    239  1.28       mrg #endif
    240   1.1       cgd 		if (va == NULL) {
    241  1.17       cgd 			/*
    242  1.17       cgd 			 * Kmem_malloc() can return NULL, even if it can
    243  1.17       cgd 			 * wait, if there is no map space avaiable, because
    244  1.17       cgd 			 * it can't fix that problem.  Neither can we,
    245  1.17       cgd 			 * right now.  (We should release pages which
    246  1.17       cgd 			 * are completely free and which are in buckets
    247  1.17       cgd 			 * with too many free elements.)
    248  1.17       cgd 			 */
    249  1.17       cgd 			if ((flags & M_NOWAIT) == 0)
    250  1.17       cgd 				panic("malloc: out of space in kmem_map");
    251   1.6       cgd 			splx(s);
    252   1.6       cgd 			return ((void *) NULL);
    253   1.1       cgd 		}
    254   1.1       cgd #ifdef KMEMSTATS
    255   1.1       cgd 		kbp->kb_total += kbp->kb_elmpercl;
    256   1.1       cgd #endif
    257   1.1       cgd 		kup = btokup(va);
    258   1.1       cgd 		kup->ku_indx = indx;
    259   1.1       cgd 		if (allocsize > MAXALLOCSAVE) {
    260   1.1       cgd 			if (npg > 65535)
    261   1.1       cgd 				panic("malloc: allocation too large");
    262   1.1       cgd 			kup->ku_pagecnt = npg;
    263   1.1       cgd #ifdef KMEMSTATS
    264   1.1       cgd 			ksp->ks_memuse += allocsize;
    265   1.1       cgd #endif
    266   1.1       cgd 			goto out;
    267   1.1       cgd 		}
    268   1.1       cgd #ifdef KMEMSTATS
    269   1.1       cgd 		kup->ku_freecnt = kbp->kb_elmpercl;
    270   1.1       cgd 		kbp->kb_totalfree += kbp->kb_elmpercl;
    271   1.1       cgd #endif
    272   1.1       cgd 		/*
    273   1.1       cgd 		 * Just in case we blocked while allocating memory,
    274   1.1       cgd 		 * and someone else also allocated memory for this
    275   1.1       cgd 		 * bucket, don't assume the list is still empty.
    276   1.1       cgd 		 */
    277   1.1       cgd 		savedlist = kbp->kb_next;
    278   1.8       cgd 		kbp->kb_next = cp = va + (npg * NBPG) - allocsize;
    279   1.8       cgd 		for (;;) {
    280   1.8       cgd 			freep = (struct freelist *)cp;
    281   1.8       cgd #ifdef DIAGNOSTIC
    282   1.8       cgd 			/*
    283   1.8       cgd 			 * Copy in known text to detect modification
    284   1.8       cgd 			 * after freeing.
    285   1.8       cgd 			 */
    286  1.11       cgd 			end = (int32_t *)&cp[copysize];
    287  1.11       cgd 			for (lp = (int32_t *)cp; lp < end; lp++)
    288   1.8       cgd 				*lp = WEIRD_ADDR;
    289   1.8       cgd 			freep->type = M_FREE;
    290   1.8       cgd #endif /* DIAGNOSTIC */
    291   1.8       cgd 			if (cp <= va)
    292   1.8       cgd 				break;
    293   1.8       cgd 			cp -= allocsize;
    294   1.8       cgd 			freep->next = cp;
    295   1.8       cgd 		}
    296   1.8       cgd 		freep->next = savedlist;
    297   1.8       cgd 		if (kbp->kb_last == NULL)
    298   1.8       cgd 			kbp->kb_last = (caddr_t)freep;
    299   1.1       cgd 	}
    300   1.1       cgd 	va = kbp->kb_next;
    301   1.8       cgd 	kbp->kb_next = ((struct freelist *)va)->next;
    302   1.8       cgd #ifdef DIAGNOSTIC
    303   1.8       cgd 	freep = (struct freelist *)va;
    304   1.8       cgd 	savedtype = (unsigned)freep->type < M_LAST ?
    305   1.8       cgd 		memname[freep->type] : "???";
    306  1.28       mrg #if defined(UVM)
    307  1.29       chs 	if (kbp->kb_next) {
    308  1.29       chs 		int rv;
    309  1.29       chs 		vm_offset_t addr = (vm_offset_t)kbp->kb_next;
    310  1.29       chs 
    311  1.29       chs 		vm_map_lock_read(kmem_map);
    312  1.29       chs 		rv = uvm_map_checkprot(kmem_map, addr,
    313  1.29       chs 				       addr + sizeof(struct freelist),
    314  1.29       chs 				       VM_PROT_WRITE);
    315  1.29       chs 		vm_map_unlock_read(kmem_map);
    316  1.29       chs 
    317  1.29       chs 		if (!rv)
    318  1.28       mrg #else
    319  1.29       chs 	if (kbp->kb_next &&
    320  1.28       mrg 	    !kernacc(kbp->kb_next, sizeof(struct freelist), 0))
    321  1.28       mrg #endif
    322  1.28       mrg 								{
    323  1.22  christos 		printf(
    324  1.21  christos 		    "%s %ld of object %p size %ld %s %s (invalid addr %p)\n",
    325  1.21  christos 		    "Data modified on freelist: word",
    326  1.21  christos 		    (long)((int32_t *)&kbp->kb_next - (int32_t *)kbp),
    327  1.21  christos 		    va, size, "previous type", savedtype, kbp->kb_next);
    328  1.27   thorpej #ifdef MALLOCLOG
    329  1.27   thorpej 		hitmlog(va);
    330  1.27   thorpej #endif
    331   1.8       cgd 		kbp->kb_next = NULL;
    332  1.29       chs #if defined(UVM)
    333  1.29       chs 		}
    334  1.29       chs #endif
    335   1.8       cgd 	}
    336  1.11       cgd 
    337  1.11       cgd 	/* Fill the fields that we've used with WEIRD_ADDR */
    338   1.8       cgd #if BYTE_ORDER == BIG_ENDIAN
    339   1.8       cgd 	freep->type = WEIRD_ADDR >> 16;
    340   1.8       cgd #endif
    341   1.8       cgd #if BYTE_ORDER == LITTLE_ENDIAN
    342   1.8       cgd 	freep->type = (short)WEIRD_ADDR;
    343   1.8       cgd #endif
    344  1.11       cgd 	end = (int32_t *)&freep->next +
    345  1.11       cgd 	    (sizeof(freep->next) / sizeof(int32_t));
    346  1.11       cgd 	for (lp = (int32_t *)&freep->next; lp < end; lp++)
    347  1.11       cgd 		*lp = WEIRD_ADDR;
    348  1.11       cgd 
    349  1.11       cgd 	/* and check that the data hasn't been modified. */
    350  1.11       cgd 	end = (int32_t *)&va[copysize];
    351  1.11       cgd 	for (lp = (int32_t *)va; lp < end; lp++) {
    352   1.8       cgd 		if (*lp == WEIRD_ADDR)
    353   1.8       cgd 			continue;
    354  1.22  christos 		printf("%s %ld of object %p size %ld %s %s (0x%x != 0x%x)\n",
    355  1.21  christos 		    "Data modified on freelist: word",
    356  1.21  christos 		    (long)(lp - (int32_t *)va), va, size, "previous type",
    357  1.21  christos 		    savedtype, *lp, WEIRD_ADDR);
    358  1.27   thorpej #ifdef MALLOCLOG
    359  1.27   thorpej 		hitmlog(va);
    360  1.27   thorpej #endif
    361   1.8       cgd 		break;
    362   1.8       cgd 	}
    363  1.11       cgd 
    364   1.8       cgd 	freep->spare0 = 0;
    365   1.8       cgd #endif /* DIAGNOSTIC */
    366   1.1       cgd #ifdef KMEMSTATS
    367   1.1       cgd 	kup = btokup(va);
    368   1.1       cgd 	if (kup->ku_indx != indx)
    369   1.1       cgd 		panic("malloc: wrong bucket");
    370   1.1       cgd 	if (kup->ku_freecnt == 0)
    371   1.1       cgd 		panic("malloc: lost data");
    372   1.1       cgd 	kup->ku_freecnt--;
    373   1.1       cgd 	kbp->kb_totalfree--;
    374   1.1       cgd 	ksp->ks_memuse += 1 << indx;
    375   1.1       cgd out:
    376   1.1       cgd 	kbp->kb_calls++;
    377   1.1       cgd 	ksp->ks_inuse++;
    378   1.1       cgd 	ksp->ks_calls++;
    379   1.1       cgd 	if (ksp->ks_memuse > ksp->ks_maxused)
    380   1.1       cgd 		ksp->ks_maxused = ksp->ks_memuse;
    381   1.1       cgd #else
    382   1.1       cgd out:
    383   1.1       cgd #endif
    384  1.27   thorpej #ifdef MALLOCLOG
    385  1.27   thorpej 	domlog(va, size, type, 1, file, line);
    386  1.27   thorpej #endif
    387   1.1       cgd 	splx(s);
    388   1.1       cgd 	return ((void *) va);
    389   1.1       cgd }
    390   1.1       cgd 
    391   1.1       cgd /*
    392   1.1       cgd  * Free a block of memory allocated by malloc.
    393   1.1       cgd  */
    394  1.27   thorpej #ifdef MALLOCLOG
    395  1.27   thorpej void
    396  1.27   thorpej _free(addr, type, file, line)
    397  1.27   thorpej 	void *addr;
    398  1.27   thorpej 	int type;
    399  1.27   thorpej 	const char *file;
    400  1.27   thorpej 	long line;
    401  1.27   thorpej #else
    402   1.1       cgd void
    403   1.1       cgd free(addr, type)
    404   1.1       cgd 	void *addr;
    405   1.1       cgd 	int type;
    406  1.27   thorpej #endif /* MALLOCLOG */
    407   1.1       cgd {
    408   1.1       cgd 	register struct kmembuckets *kbp;
    409   1.1       cgd 	register struct kmemusage *kup;
    410   1.8       cgd 	register struct freelist *freep;
    411   1.8       cgd 	long size;
    412   1.8       cgd 	int s;
    413   1.5    andrew #ifdef DIAGNOSTIC
    414   1.8       cgd 	caddr_t cp;
    415  1.11       cgd 	int32_t *end, *lp;
    416  1.11       cgd 	long alloc, copysize;
    417   1.5    andrew #endif
    418   1.1       cgd #ifdef KMEMSTATS
    419   1.1       cgd 	register struct kmemstats *ksp = &kmemstats[type];
    420   1.1       cgd #endif
    421   1.1       cgd 
    422   1.1       cgd 	kup = btokup(addr);
    423   1.1       cgd 	size = 1 << kup->ku_indx;
    424   1.8       cgd 	kbp = &bucket[kup->ku_indx];
    425   1.8       cgd 	s = splimp();
    426  1.27   thorpej #ifdef MALLOCLOG
    427  1.27   thorpej 	domlog(addr, 0, type, 2, file, line);
    428  1.27   thorpej #endif
    429   1.1       cgd #ifdef DIAGNOSTIC
    430   1.8       cgd 	/*
    431   1.8       cgd 	 * Check for returns of data that do not point to the
    432   1.8       cgd 	 * beginning of the allocation.
    433   1.8       cgd 	 */
    434   1.1       cgd 	if (size > NBPG * CLSIZE)
    435   1.1       cgd 		alloc = addrmask[BUCKETINDX(NBPG * CLSIZE)];
    436   1.1       cgd 	else
    437   1.1       cgd 		alloc = addrmask[kup->ku_indx];
    438   1.8       cgd 	if (((u_long)addr & alloc) != 0)
    439  1.15  christos 		panic("free: unaligned addr %p, size %ld, type %s, mask %ld\n",
    440   1.8       cgd 			addr, size, memname[type], alloc);
    441   1.1       cgd #endif /* DIAGNOSTIC */
    442   1.1       cgd 	if (size > MAXALLOCSAVE) {
    443  1.28       mrg #if defined(UVM)
    444  1.28       mrg 		uvm_km_free(kmem_map, (vm_offset_t)addr, ctob(kup->ku_pagecnt));
    445  1.28       mrg #else
    446   1.1       cgd 		kmem_free(kmem_map, (vm_offset_t)addr, ctob(kup->ku_pagecnt));
    447  1.28       mrg #endif
    448   1.1       cgd #ifdef KMEMSTATS
    449   1.1       cgd 		size = kup->ku_pagecnt << PGSHIFT;
    450   1.1       cgd 		ksp->ks_memuse -= size;
    451   1.1       cgd 		kup->ku_indx = 0;
    452   1.1       cgd 		kup->ku_pagecnt = 0;
    453   1.1       cgd 		if (ksp->ks_memuse + size >= ksp->ks_limit &&
    454   1.1       cgd 		    ksp->ks_memuse < ksp->ks_limit)
    455   1.1       cgd 			wakeup((caddr_t)ksp);
    456   1.1       cgd 		ksp->ks_inuse--;
    457   1.1       cgd 		kbp->kb_total -= 1;
    458   1.1       cgd #endif
    459   1.1       cgd 		splx(s);
    460   1.1       cgd 		return;
    461   1.1       cgd 	}
    462   1.8       cgd 	freep = (struct freelist *)addr;
    463   1.8       cgd #ifdef DIAGNOSTIC
    464   1.8       cgd 	/*
    465   1.8       cgd 	 * Check for multiple frees. Use a quick check to see if
    466   1.8       cgd 	 * it looks free before laboriously searching the freelist.
    467   1.8       cgd 	 */
    468   1.8       cgd 	if (freep->spare0 == WEIRD_ADDR) {
    469  1.16       cgd 		for (cp = kbp->kb_next; cp;
    470  1.16       cgd 		    cp = ((struct freelist *)cp)->next) {
    471   1.8       cgd 			if (addr != cp)
    472   1.8       cgd 				continue;
    473  1.22  christos 			printf("multiply freed item %p\n", addr);
    474  1.27   thorpej #ifdef MALLOCLOG
    475  1.27   thorpej 			hitmlog(addr);
    476  1.27   thorpej #endif
    477   1.8       cgd 			panic("free: duplicated free");
    478   1.8       cgd 		}
    479   1.8       cgd 	}
    480   1.8       cgd 	/*
    481   1.8       cgd 	 * Copy in known text to detect modification after freeing
    482   1.8       cgd 	 * and to make it look free. Also, save the type being freed
    483   1.8       cgd 	 * so we can list likely culprit if modification is detected
    484   1.8       cgd 	 * when the object is reallocated.
    485   1.8       cgd 	 */
    486   1.8       cgd 	copysize = size < MAX_COPY ? size : MAX_COPY;
    487  1.11       cgd 	end = (int32_t *)&((caddr_t)addr)[copysize];
    488  1.11       cgd 	for (lp = (int32_t *)addr; lp < end; lp++)
    489   1.8       cgd 		*lp = WEIRD_ADDR;
    490   1.8       cgd 	freep->type = type;
    491   1.8       cgd #endif /* DIAGNOSTIC */
    492   1.1       cgd #ifdef KMEMSTATS
    493   1.1       cgd 	kup->ku_freecnt++;
    494   1.1       cgd 	if (kup->ku_freecnt >= kbp->kb_elmpercl)
    495   1.1       cgd 		if (kup->ku_freecnt > kbp->kb_elmpercl)
    496   1.1       cgd 			panic("free: multiple frees");
    497   1.1       cgd 		else if (kbp->kb_totalfree > kbp->kb_highwat)
    498   1.1       cgd 			kbp->kb_couldfree++;
    499   1.1       cgd 	kbp->kb_totalfree++;
    500   1.1       cgd 	ksp->ks_memuse -= size;
    501   1.1       cgd 	if (ksp->ks_memuse + size >= ksp->ks_limit &&
    502   1.1       cgd 	    ksp->ks_memuse < ksp->ks_limit)
    503   1.1       cgd 		wakeup((caddr_t)ksp);
    504   1.1       cgd 	ksp->ks_inuse--;
    505   1.1       cgd #endif
    506   1.8       cgd 	if (kbp->kb_next == NULL)
    507   1.8       cgd 		kbp->kb_next = addr;
    508   1.8       cgd 	else
    509   1.8       cgd 		((struct freelist *)kbp->kb_last)->next = addr;
    510   1.8       cgd 	freep->next = NULL;
    511   1.8       cgd 	kbp->kb_last = addr;
    512   1.1       cgd 	splx(s);
    513  1.20       cgd }
    514  1.20       cgd 
    515  1.20       cgd /*
    516  1.20       cgd  * Change the size of a block of memory.
    517  1.20       cgd  */
    518  1.20       cgd void *
    519  1.20       cgd realloc(curaddr, newsize, type, flags)
    520  1.20       cgd 	void *curaddr;
    521  1.20       cgd 	unsigned long newsize;
    522  1.20       cgd 	int type, flags;
    523  1.20       cgd {
    524  1.20       cgd 	register struct kmemusage *kup;
    525  1.20       cgd 	long cursize;
    526  1.20       cgd 	void *newaddr;
    527  1.20       cgd #ifdef DIAGNOSTIC
    528  1.20       cgd 	long alloc;
    529  1.20       cgd #endif
    530  1.20       cgd 
    531  1.20       cgd 	/*
    532  1.20       cgd 	 * Realloc() with a NULL pointer is the same as malloc().
    533  1.20       cgd 	 */
    534  1.20       cgd 	if (curaddr == NULL)
    535  1.20       cgd 		return (malloc(newsize, type, flags));
    536  1.20       cgd 
    537  1.20       cgd 	/*
    538  1.20       cgd 	 * Realloc() with zero size is the same as free().
    539  1.20       cgd 	 */
    540  1.20       cgd 	if (newsize == 0) {
    541  1.20       cgd 		free(curaddr, type);
    542  1.20       cgd 		return (NULL);
    543  1.20       cgd 	}
    544  1.20       cgd 
    545  1.20       cgd 	/*
    546  1.20       cgd 	 * Find out how large the old allocation was (and do some
    547  1.20       cgd 	 * sanity checking).
    548  1.20       cgd 	 */
    549  1.20       cgd 	kup = btokup(curaddr);
    550  1.20       cgd 	cursize = 1 << kup->ku_indx;
    551  1.20       cgd 
    552  1.20       cgd #ifdef DIAGNOSTIC
    553  1.20       cgd 	/*
    554  1.20       cgd 	 * Check for returns of data that do not point to the
    555  1.20       cgd 	 * beginning of the allocation.
    556  1.20       cgd 	 */
    557  1.20       cgd 	if (cursize > NBPG * CLSIZE)
    558  1.20       cgd 		alloc = addrmask[BUCKETINDX(NBPG * CLSIZE)];
    559  1.20       cgd 	else
    560  1.20       cgd 		alloc = addrmask[kup->ku_indx];
    561  1.20       cgd 	if (((u_long)curaddr & alloc) != 0)
    562  1.20       cgd 		panic("realloc: unaligned addr %p, size %ld, type %s, mask %ld\n",
    563  1.20       cgd 			curaddr, cursize, memname[type], alloc);
    564  1.20       cgd #endif /* DIAGNOSTIC */
    565  1.20       cgd 
    566  1.20       cgd 	if (cursize > MAXALLOCSAVE)
    567  1.20       cgd 		cursize = ctob(kup->ku_pagecnt);
    568  1.20       cgd 
    569  1.20       cgd 	/*
    570  1.20       cgd 	 * If we already actually have as much as they want, we're done.
    571  1.20       cgd 	 */
    572  1.20       cgd 	if (newsize <= cursize)
    573  1.20       cgd 		return (curaddr);
    574  1.20       cgd 
    575  1.20       cgd 	/*
    576  1.20       cgd 	 * Can't satisfy the allocation with the existing block.
    577  1.20       cgd 	 * Allocate a new one and copy the data.
    578  1.20       cgd 	 */
    579  1.20       cgd 	newaddr = malloc(newsize, type, flags);
    580  1.20       cgd 	if (newaddr == NULL) {
    581  1.20       cgd 		/*
    582  1.20       cgd 		 * Malloc() failed, because flags included M_NOWAIT.
    583  1.20       cgd 		 * Return NULL to indicate that failure.  The old
    584  1.20       cgd 		 * pointer is still valid.
    585  1.20       cgd 		 */
    586  1.20       cgd 		return NULL;
    587  1.20       cgd 	}
    588  1.20       cgd 	bcopy(curaddr, newaddr, cursize);
    589  1.20       cgd 
    590  1.20       cgd 	/*
    591  1.20       cgd 	 * We were successful: free the old allocation and return
    592  1.20       cgd 	 * the new one.
    593  1.20       cgd 	 */
    594  1.20       cgd 	free(curaddr, type);
    595  1.20       cgd 	return (newaddr);
    596   1.1       cgd }
    597   1.1       cgd 
    598   1.1       cgd /*
    599   1.1       cgd  * Initialize the kernel memory allocator
    600   1.1       cgd  */
    601  1.12  christos void
    602   1.1       cgd kmeminit()
    603   1.1       cgd {
    604  1.23       tls #ifdef KMEMSTATS
    605   1.1       cgd 	register long indx;
    606  1.23       tls #endif
    607   1.1       cgd 	int npg;
    608   1.1       cgd 
    609   1.1       cgd #if	((MAXALLOCSAVE & (MAXALLOCSAVE - 1)) != 0)
    610   1.1       cgd 		ERROR!_kmeminit:_MAXALLOCSAVE_not_power_of_2
    611   1.1       cgd #endif
    612   1.1       cgd #if	(MAXALLOCSAVE > MINALLOCSIZE * 32768)
    613   1.1       cgd 		ERROR!_kmeminit:_MAXALLOCSAVE_too_big
    614   1.1       cgd #endif
    615   1.1       cgd #if	(MAXALLOCSAVE < CLBYTES)
    616   1.1       cgd 		ERROR!_kmeminit:_MAXALLOCSAVE_too_small
    617   1.1       cgd #endif
    618  1.11       cgd 
    619  1.11       cgd 	if (sizeof(struct freelist) > (1 << MINBUCKET))
    620  1.11       cgd 		panic("minbucket too small/struct freelist too big");
    621  1.11       cgd 
    622   1.1       cgd 	npg = VM_KMEM_SIZE/ NBPG;
    623  1.28       mrg #if defined(UVM)
    624  1.28       mrg 	kmemusage = (struct kmemusage *) uvm_km_zalloc(kernel_map,
    625  1.28       mrg 		(vm_size_t)(npg * sizeof(struct kmemusage)));
    626  1.28       mrg 	kmem_map = uvm_km_suballoc(kernel_map, (vm_offset_t *)&kmembase,
    627  1.28       mrg 		(vm_offset_t *)&kmemlimit, (vm_size_t)(npg * NBPG),
    628  1.30   thorpej 			FALSE, FALSE, &kmem_map_store);
    629  1.28       mrg #else
    630   1.1       cgd 	kmemusage = (struct kmemusage *) kmem_alloc(kernel_map,
    631   1.1       cgd 		(vm_size_t)(npg * sizeof(struct kmemusage)));
    632   1.1       cgd 	kmem_map = kmem_suballoc(kernel_map, (vm_offset_t *)&kmembase,
    633   1.1       cgd 		(vm_offset_t *)&kmemlimit, (vm_size_t)(npg * NBPG), FALSE);
    634  1.28       mrg #endif
    635   1.1       cgd #ifdef KMEMSTATS
    636   1.1       cgd 	for (indx = 0; indx < MINBUCKET + 16; indx++) {
    637   1.1       cgd 		if (1 << indx >= CLBYTES)
    638   1.1       cgd 			bucket[indx].kb_elmpercl = 1;
    639   1.1       cgd 		else
    640   1.1       cgd 			bucket[indx].kb_elmpercl = CLBYTES / (1 << indx);
    641   1.1       cgd 		bucket[indx].kb_highwat = 5 * bucket[indx].kb_elmpercl;
    642   1.1       cgd 	}
    643   1.8       cgd 	for (indx = 0; indx < M_LAST; indx++)
    644   1.1       cgd 		kmemstats[indx].ks_limit = npg * NBPG * 6 / 10;
    645   1.1       cgd #endif
    646   1.1       cgd }
    647