Home | History | Annotate | Line # | Download | only in kern
uipc_sem.c revision 1.55.4.1
      1  1.55.4.1    martin /*	$NetBSD: uipc_sem.c,v 1.55.4.1 2019/12/18 20:20:17 martin Exp $	*/
      2       1.3   thorpej 
      3       1.3   thorpej /*-
      4      1.52   thorpej  * Copyright (c) 2011, 2019 The NetBSD Foundation, Inc.
      5       1.3   thorpej  * All rights reserved.
      6       1.3   thorpej  *
      7       1.3   thorpej  * This code is derived from software contributed to The NetBSD Foundation
      8      1.52   thorpej  * by Mindaugas Rasiukevicius and Jason R. Thorpe.
      9       1.3   thorpej  *
     10       1.3   thorpej  * Redistribution and use in source and binary forms, with or without
     11       1.3   thorpej  * modification, are permitted provided that the following conditions
     12       1.3   thorpej  * are met:
     13       1.3   thorpej  * 1. Redistributions of source code must retain the above copyright
     14       1.3   thorpej  *    notice, this list of conditions and the following disclaimer.
     15       1.3   thorpej  * 2. Redistributions in binary form must reproduce the above copyright
     16       1.3   thorpej  *    notice, this list of conditions and the following disclaimer in the
     17       1.3   thorpej  *    documentation and/or other materials provided with the distribution.
     18       1.3   thorpej  *
     19       1.3   thorpej  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20       1.3   thorpej  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21       1.3   thorpej  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22       1.3   thorpej  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23       1.3   thorpej  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24       1.3   thorpej  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25       1.3   thorpej  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26       1.3   thorpej  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27       1.3   thorpej  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28       1.3   thorpej  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29       1.3   thorpej  * POSSIBILITY OF SUCH DAMAGE.
     30       1.3   thorpej  */
     31       1.1  christos 
     32       1.1  christos /*
     33       1.1  christos  * Copyright (c) 2002 Alfred Perlstein <alfred (at) FreeBSD.org>
     34       1.1  christos  * All rights reserved.
     35       1.1  christos  *
     36       1.1  christos  * Redistribution and use in source and binary forms, with or without
     37       1.1  christos  * modification, are permitted provided that the following conditions
     38       1.1  christos  * are met:
     39       1.1  christos  * 1. Redistributions of source code must retain the above copyright
     40       1.1  christos  *    notice, this list of conditions and the following disclaimer.
     41       1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     42       1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     43       1.1  christos  *    documentation and/or other materials provided with the distribution.
     44       1.1  christos  *
     45       1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
     46       1.1  christos  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     47       1.1  christos  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     48       1.1  christos  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     49       1.1  christos  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     50       1.1  christos  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     51       1.1  christos  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     52       1.1  christos  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     53       1.1  christos  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     54       1.1  christos  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     55       1.1  christos  * SUCH DAMAGE.
     56       1.1  christos  */
     57       1.9     lukem 
     58      1.30     rmind /*
     59      1.30     rmind  * Implementation of POSIX semaphore.
     60      1.30     rmind  */
     61      1.30     rmind 
     62       1.9     lukem #include <sys/cdefs.h>
     63  1.55.4.1    martin __KERNEL_RCSID(0, "$NetBSD: uipc_sem.c,v 1.55.4.1 2019/12/18 20:20:17 martin Exp $");
     64       1.1  christos 
     65       1.1  christos #include <sys/param.h>
     66       1.1  christos #include <sys/kernel.h>
     67      1.34     rmind 
     68      1.34     rmind #include <sys/atomic.h>
     69       1.1  christos #include <sys/proc.h>
     70      1.52   thorpej #include <sys/lwp.h>
     71       1.1  christos #include <sys/ksem.h>
     72       1.1  christos #include <sys/syscall.h>
     73       1.1  christos #include <sys/stat.h>
     74      1.21        ad #include <sys/kmem.h>
     75       1.1  christos #include <sys/fcntl.h>
     76      1.30     rmind #include <sys/file.h>
     77      1.30     rmind #include <sys/filedesc.h>
     78      1.14      elad #include <sys/kauth.h>
     79      1.27        ad #include <sys/module.h>
     80       1.1  christos #include <sys/mount.h>
     81      1.52   thorpej #include <sys/mutex.h>
     82      1.52   thorpej #include <sys/rwlock.h>
     83      1.45  dholland #include <sys/semaphore.h>
     84      1.27        ad #include <sys/syscall.h>
     85       1.1  christos #include <sys/syscallargs.h>
     86      1.27        ad #include <sys/syscallvar.h>
     87      1.43  pgoyette #include <sys/sysctl.h>
     88      1.55  christos #include <sys/uidinfo.h>
     89      1.52   thorpej #include <sys/cprng.h>
     90       1.1  christos 
     91      1.30     rmind MODULE(MODULE_CLASS_MISC, ksem, NULL);
     92      1.30     rmind 
     93      1.49  christos #define	SEM_MAX_NAMELEN		NAME_MAX
     94       1.1  christos 
     95      1.30     rmind #define	KS_UNLINKED		0x01
     96       1.4   thorpej 
     97      1.30     rmind static kmutex_t		ksem_lock	__cacheline_aligned;
     98      1.30     rmind static LIST_HEAD(,ksem)	ksem_head	__cacheline_aligned;
     99      1.34     rmind static u_int		nsems_total	__cacheline_aligned;
    100      1.30     rmind static u_int		nsems		__cacheline_aligned;
    101      1.30     rmind 
    102      1.52   thorpej static krwlock_t	ksem_pshared_lock __cacheline_aligned;
    103      1.52   thorpej static LIST_HEAD(, ksem) *ksem_pshared_hashtab __cacheline_aligned;
    104      1.52   thorpej static u_long		ksem_pshared_hashmask __read_mostly;
    105      1.52   thorpej 
    106      1.52   thorpej #define	KSEM_PSHARED_HASHSIZE	32
    107      1.52   thorpej 
    108      1.38      elad static kauth_listener_t	ksem_listener;
    109      1.38      elad 
    110      1.30     rmind static int		ksem_sysinit(void);
    111      1.30     rmind static int		ksem_sysfini(bool);
    112      1.30     rmind static int		ksem_modcmd(modcmd_t, void *);
    113      1.30     rmind static int		ksem_close_fop(file_t *);
    114      1.39  christos static int		ksem_stat_fop(file_t *, struct stat *);
    115      1.39  christos static int		ksem_read_fop(file_t *, off_t *, struct uio *,
    116      1.39  christos     kauth_cred_t, int);
    117      1.30     rmind 
    118      1.30     rmind static const struct fileops semops = {
    119      1.48  christos 	.fo_name = "sem",
    120      1.39  christos 	.fo_read = ksem_read_fop,
    121      1.30     rmind 	.fo_write = fbadop_write,
    122      1.30     rmind 	.fo_ioctl = fbadop_ioctl,
    123      1.30     rmind 	.fo_fcntl = fnullop_fcntl,
    124      1.30     rmind 	.fo_poll = fnullop_poll,
    125      1.39  christos 	.fo_stat = ksem_stat_fop,
    126      1.30     rmind 	.fo_close = ksem_close_fop,
    127      1.30     rmind 	.fo_kqfilter = fnullop_kqfilter,
    128      1.30     rmind 	.fo_restart = fnullop_restart,
    129      1.30     rmind };
    130      1.27        ad 
    131      1.27        ad static const struct syscall_package ksem_syscalls[] = {
    132      1.27        ad 	{ SYS__ksem_init, 0, (sy_call_t *)sys__ksem_init },
    133      1.27        ad 	{ SYS__ksem_open, 0, (sy_call_t *)sys__ksem_open },
    134      1.27        ad 	{ SYS__ksem_unlink, 0, (sy_call_t *)sys__ksem_unlink },
    135      1.27        ad 	{ SYS__ksem_close, 0, (sy_call_t *)sys__ksem_close },
    136      1.27        ad 	{ SYS__ksem_post, 0, (sy_call_t *)sys__ksem_post },
    137      1.27        ad 	{ SYS__ksem_wait, 0, (sy_call_t *)sys__ksem_wait },
    138      1.27        ad 	{ SYS__ksem_trywait, 0, (sy_call_t *)sys__ksem_trywait },
    139      1.27        ad 	{ SYS__ksem_getvalue, 0, (sy_call_t *)sys__ksem_getvalue },
    140      1.27        ad 	{ SYS__ksem_destroy, 0, (sy_call_t *)sys__ksem_destroy },
    141      1.36     joerg 	{ SYS__ksem_timedwait, 0, (sy_call_t *)sys__ksem_timedwait },
    142      1.27        ad 	{ 0, 0, NULL },
    143      1.27        ad };
    144       1.1  christos 
    145      1.43  pgoyette struct sysctllog *ksem_clog;
    146      1.43  pgoyette int ksem_max;
    147      1.43  pgoyette 
    148      1.30     rmind static int
    149      1.51  christos name_copyin(const char *uname, char **name)
    150      1.51  christos {
    151      1.51  christos 	*name = kmem_alloc(SEM_MAX_NAMELEN, KM_SLEEP);
    152      1.51  christos 
    153      1.51  christos 	int error = copyinstr(uname, *name, SEM_MAX_NAMELEN, NULL);
    154      1.51  christos 	if (error)
    155      1.51  christos 		kmem_free(*name, SEM_MAX_NAMELEN);
    156      1.51  christos 
    157      1.51  christos 	return error;
    158      1.51  christos }
    159      1.51  christos 
    160      1.51  christos static void
    161      1.51  christos name_destroy(char **name)
    162      1.51  christos {
    163      1.51  christos 	if (!*name)
    164      1.51  christos 		return;
    165      1.51  christos 
    166      1.51  christos 	kmem_free(*name, SEM_MAX_NAMELEN);
    167      1.51  christos 	*name = NULL;
    168      1.51  christos }
    169      1.51  christos 
    170      1.51  christos static int
    171      1.38      elad ksem_listener_cb(kauth_cred_t cred, kauth_action_t action, void *cookie,
    172      1.38      elad     void *arg0, void *arg1, void *arg2, void *arg3)
    173      1.38      elad {
    174      1.38      elad 	ksem_t *ks;
    175      1.38      elad 	mode_t mode;
    176      1.38      elad 
    177      1.38      elad 	if (action != KAUTH_SYSTEM_SEMAPHORE)
    178      1.38      elad 		return KAUTH_RESULT_DEFER;
    179      1.38      elad 
    180      1.38      elad 	ks = arg1;
    181      1.38      elad 	mode = ks->ks_mode;
    182      1.38      elad 
    183      1.38      elad 	if ((kauth_cred_geteuid(cred) == ks->ks_uid && (mode & S_IWUSR) != 0) ||
    184      1.38      elad 	    (kauth_cred_getegid(cred) == ks->ks_gid && (mode & S_IWGRP) != 0) ||
    185      1.38      elad 	    (mode & S_IWOTH) != 0)
    186      1.38      elad 		return KAUTH_RESULT_ALLOW;
    187      1.38      elad 
    188      1.38      elad 	return KAUTH_RESULT_DEFER;
    189      1.38      elad }
    190      1.38      elad 
    191      1.38      elad static int
    192      1.30     rmind ksem_sysinit(void)
    193       1.3   thorpej {
    194      1.30     rmind 	int error;
    195      1.43  pgoyette 	const struct sysctlnode *rnode;
    196       1.1  christos 
    197      1.30     rmind 	mutex_init(&ksem_lock, MUTEX_DEFAULT, IPL_NONE);
    198      1.30     rmind 	LIST_INIT(&ksem_head);
    199      1.34     rmind 	nsems_total = 0;
    200      1.34     rmind 	nsems = 0;
    201      1.20        ad 
    202      1.52   thorpej 	rw_init(&ksem_pshared_lock);
    203      1.52   thorpej 	ksem_pshared_hashtab = hashinit(KSEM_PSHARED_HASHSIZE, HASH_LIST,
    204      1.52   thorpej 	    true, &ksem_pshared_hashmask);
    205      1.52   thorpej 	KASSERT(ksem_pshared_hashtab != NULL);
    206      1.52   thorpej 
    207      1.30     rmind 	error = syscall_establish(NULL, ksem_syscalls);
    208      1.30     rmind 	if (error) {
    209      1.30     rmind 		(void)ksem_sysfini(false);
    210       1.3   thorpej 	}
    211      1.38      elad 
    212      1.38      elad 	ksem_listener = kauth_listen_scope(KAUTH_SCOPE_SYSTEM,
    213      1.38      elad 	    ksem_listener_cb, NULL);
    214      1.38      elad 
    215      1.43  pgoyette 	/* Define module-specific sysctl tree */
    216      1.43  pgoyette 
    217      1.43  pgoyette 	ksem_max = KSEM_MAX;
    218      1.43  pgoyette 	ksem_clog = NULL;
    219      1.43  pgoyette 
    220      1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, NULL, &rnode,
    221      1.43  pgoyette 			CTLFLAG_PERMANENT,
    222      1.43  pgoyette 			CTLTYPE_NODE, "posix",
    223      1.43  pgoyette 			SYSCTL_DESCR("POSIX options"),
    224      1.43  pgoyette 			NULL, 0, NULL, 0,
    225      1.43  pgoyette 			CTL_KERN, CTL_CREATE, CTL_EOL);
    226      1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, &rnode, NULL,
    227      1.43  pgoyette 			CTLFLAG_PERMANENT | CTLFLAG_READWRITE,
    228      1.43  pgoyette 			CTLTYPE_INT, "semmax",
    229      1.43  pgoyette 			SYSCTL_DESCR("Maximal number of semaphores"),
    230      1.43  pgoyette 			NULL, 0, &ksem_max, 0,
    231      1.43  pgoyette 			CTL_CREATE, CTL_EOL);
    232      1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, &rnode, NULL,
    233      1.44  pgoyette 			CTLFLAG_PERMANENT | CTLFLAG_READONLY,
    234      1.43  pgoyette 			CTLTYPE_INT, "semcnt",
    235      1.43  pgoyette 			SYSCTL_DESCR("Current number of semaphores"),
    236      1.43  pgoyette 			NULL, 0, &nsems, 0,
    237      1.43  pgoyette 			CTL_CREATE, CTL_EOL);
    238      1.43  pgoyette 
    239      1.30     rmind 	return error;
    240       1.3   thorpej }
    241       1.1  christos 
    242      1.30     rmind static int
    243      1.30     rmind ksem_sysfini(bool interface)
    244       1.1  christos {
    245      1.30     rmind 	int error;
    246       1.1  christos 
    247      1.30     rmind 	if (interface) {
    248      1.30     rmind 		error = syscall_disestablish(NULL, ksem_syscalls);
    249      1.30     rmind 		if (error != 0) {
    250      1.30     rmind 			return error;
    251      1.30     rmind 		}
    252      1.34     rmind 		/*
    253      1.34     rmind 		 * Make sure that no semaphores are in use.  Note: semops
    254      1.34     rmind 		 * must be unused at this point.
    255      1.34     rmind 		 */
    256      1.34     rmind 		if (nsems_total) {
    257      1.30     rmind 			error = syscall_establish(NULL, ksem_syscalls);
    258      1.30     rmind 			KASSERT(error == 0);
    259      1.30     rmind 			return EBUSY;
    260      1.30     rmind 		}
    261       1.3   thorpej 	}
    262      1.38      elad 	kauth_unlisten_scope(ksem_listener);
    263      1.52   thorpej 	hashdone(ksem_pshared_hashtab, HASH_LIST, ksem_pshared_hashmask);
    264      1.52   thorpej 	rw_destroy(&ksem_pshared_lock);
    265      1.30     rmind 	mutex_destroy(&ksem_lock);
    266      1.43  pgoyette 	sysctl_teardown(&ksem_clog);
    267      1.30     rmind 	return 0;
    268       1.3   thorpej }
    269       1.3   thorpej 
    270      1.30     rmind static int
    271      1.30     rmind ksem_modcmd(modcmd_t cmd, void *arg)
    272       1.3   thorpej {
    273       1.3   thorpej 
    274      1.30     rmind 	switch (cmd) {
    275      1.30     rmind 	case MODULE_CMD_INIT:
    276      1.30     rmind 		return ksem_sysinit();
    277       1.3   thorpej 
    278      1.30     rmind 	case MODULE_CMD_FINI:
    279      1.30     rmind 		return ksem_sysfini(true);
    280       1.1  christos 
    281      1.30     rmind 	default:
    282      1.30     rmind 		return ENOTTY;
    283      1.16   thorpej 	}
    284      1.16   thorpej }
    285      1.16   thorpej 
    286      1.30     rmind static ksem_t *
    287      1.30     rmind ksem_lookup(const char *name)
    288       1.3   thorpej {
    289      1.30     rmind 	ksem_t *ks;
    290       1.3   thorpej 
    291      1.30     rmind 	KASSERT(mutex_owned(&ksem_lock));
    292       1.3   thorpej 
    293      1.30     rmind 	LIST_FOREACH(ks, &ksem_head, ks_entry) {
    294      1.30     rmind 		if (strcmp(ks->ks_name, name) == 0) {
    295      1.30     rmind 			mutex_enter(&ks->ks_lock);
    296      1.30     rmind 			return ks;
    297       1.3   thorpej 		}
    298       1.1  christos 	}
    299      1.30     rmind 	return NULL;
    300       1.1  christos }
    301       1.1  christos 
    302       1.3   thorpej static int
    303      1.30     rmind ksem_perm(lwp_t *l, ksem_t *ks)
    304       1.3   thorpej {
    305      1.30     rmind 	kauth_cred_t uc = l->l_cred;
    306       1.3   thorpej 
    307      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    308      1.30     rmind 
    309      1.38      elad 	if (kauth_authorize_system(uc, KAUTH_SYSTEM_SEMAPHORE, 0, ks, NULL, NULL) != 0)
    310      1.38      elad 		return EACCES;
    311      1.38      elad 
    312      1.38      elad 	return 0;
    313       1.3   thorpej }
    314       1.3   thorpej 
    315      1.30     rmind /*
    316      1.52   thorpej  * Bits 1..23 are random, just pluck a few of those and assume the
    317      1.52   thorpej  * distribution is going to be pretty good.
    318      1.52   thorpej  */
    319      1.52   thorpej #define	KSEM_PSHARED_HASH(id)	(((id) >> 1) & ksem_pshared_hashmask)
    320      1.52   thorpej 
    321      1.52   thorpej static void
    322      1.52   thorpej ksem_remove_pshared(ksem_t *ksem)
    323      1.52   thorpej {
    324      1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_WRITER);
    325      1.52   thorpej 	LIST_REMOVE(ksem, ks_entry);
    326      1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    327      1.52   thorpej }
    328      1.52   thorpej 
    329      1.52   thorpej static ksem_t *
    330      1.52   thorpej ksem_lookup_pshared_locked(intptr_t id)
    331      1.52   thorpej {
    332      1.52   thorpej 	u_long bucket = KSEM_PSHARED_HASH(id);
    333      1.52   thorpej 	ksem_t *ksem = NULL;
    334      1.52   thorpej 
    335      1.52   thorpej 	/* ksem_t is locked and referenced upon return. */
    336      1.52   thorpej 
    337      1.52   thorpej 	LIST_FOREACH(ksem, &ksem_pshared_hashtab[bucket], ks_entry) {
    338      1.52   thorpej 		if (ksem->ks_pshared_id == id) {
    339      1.52   thorpej 			mutex_enter(&ksem->ks_lock);
    340      1.52   thorpej 			if (ksem->ks_pshared_proc == NULL) {
    341      1.52   thorpej 				/*
    342      1.52   thorpej 				 * This entry is dead, and in the process
    343      1.52   thorpej 				 * of being torn down; skip it.
    344      1.52   thorpej 				 */
    345      1.52   thorpej 				mutex_exit(&ksem->ks_lock);
    346      1.52   thorpej 				continue;
    347      1.52   thorpej 			}
    348      1.52   thorpej 			ksem->ks_ref++;
    349      1.52   thorpej 			KASSERT(ksem->ks_ref != 0);
    350      1.52   thorpej 			return ksem;
    351      1.52   thorpej 		}
    352      1.52   thorpej 	}
    353      1.52   thorpej 
    354      1.52   thorpej 	return NULL;
    355      1.52   thorpej }
    356      1.52   thorpej 
    357      1.52   thorpej static ksem_t *
    358      1.52   thorpej ksem_lookup_pshared(intptr_t id)
    359      1.52   thorpej {
    360      1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_READER);
    361      1.52   thorpej 	ksem_t *ksem = ksem_lookup_pshared_locked(id);
    362      1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    363      1.52   thorpej 	return ksem;
    364      1.52   thorpej }
    365      1.52   thorpej 
    366      1.52   thorpej static void
    367      1.52   thorpej ksem_alloc_pshared_id(ksem_t *ksem)
    368      1.52   thorpej {
    369      1.52   thorpej 	uint32_t try;
    370      1.52   thorpej 
    371      1.52   thorpej 	KASSERT(ksem->ks_pshared_proc != NULL);
    372      1.52   thorpej 
    373      1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_WRITER);
    374      1.52   thorpej 	for (;;) {
    375      1.52   thorpej 		try = (cprng_fast32() & ~KSEM_MARKER_MASK) |
    376      1.52   thorpej 		    KSEM_PSHARED_MARKER;
    377      1.52   thorpej 
    378      1.52   thorpej 		if (ksem_lookup_pshared_locked(try) == NULL) {
    379      1.52   thorpej 			/* Got it! */
    380      1.52   thorpej 			break;
    381      1.52   thorpej 		}
    382      1.52   thorpej 	}
    383      1.52   thorpej 	ksem->ks_pshared_id = try;
    384      1.52   thorpej 	u_long bucket = KSEM_PSHARED_HASH(ksem->ks_pshared_id);
    385      1.52   thorpej 	LIST_INSERT_HEAD(&ksem_pshared_hashtab[bucket], ksem, ks_entry);
    386      1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    387      1.52   thorpej }
    388      1.52   thorpej 
    389      1.52   thorpej /*
    390      1.30     rmind  * ksem_get: get the semaphore from the descriptor.
    391      1.30     rmind  *
    392      1.52   thorpej  * => locks the semaphore, if found, and holds an extra reference.
    393      1.30     rmind  * => holds a reference on the file descriptor.
    394      1.30     rmind  */
    395      1.30     rmind static int
    396      1.52   thorpej ksem_get(intptr_t id, ksem_t **ksret, int *fdp)
    397      1.13      cube {
    398      1.30     rmind 	ksem_t *ks;
    399      1.52   thorpej 	int fd;
    400      1.52   thorpej 
    401      1.52   thorpej 	if ((id & KSEM_MARKER_MASK) == KSEM_PSHARED_MARKER) {
    402      1.52   thorpej 		/*
    403      1.52   thorpej 		 * ksem_lookup_pshared() returns the ksem_t *
    404      1.52   thorpej 		 * locked and referenced.
    405      1.52   thorpej 		 */
    406      1.52   thorpej 		ks = ksem_lookup_pshared(id);
    407      1.52   thorpej 		if (ks == NULL)
    408      1.52   thorpej 			return EINVAL;
    409      1.52   thorpej 		KASSERT(ks->ks_pshared_id == id);
    410      1.52   thorpej 		KASSERT(ks->ks_pshared_proc != NULL);
    411      1.52   thorpej 		fd = -1;
    412      1.52   thorpej 	} else if (id <= INT_MAX) {
    413      1.52   thorpej 		fd = (int)id;
    414      1.52   thorpej 		file_t *fp = fd_getfile(fd);
    415      1.13      cube 
    416      1.52   thorpej 		if (__predict_false(fp == NULL))
    417      1.52   thorpej 			return EINVAL;
    418      1.52   thorpej 		if (__predict_false(fp->f_type != DTYPE_SEM)) {
    419      1.52   thorpej 			fd_putfile(fd);
    420      1.52   thorpej 			return EINVAL;
    421      1.52   thorpej 		}
    422      1.52   thorpej 		ks = fp->f_ksem;
    423      1.52   thorpej 		mutex_enter(&ks->ks_lock);
    424      1.52   thorpej 		ks->ks_ref++;
    425      1.52   thorpej 	} else {
    426      1.37     joerg 		return EINVAL;
    427      1.13      cube 	}
    428      1.13      cube 
    429      1.30     rmind 	*ksret = ks;
    430      1.52   thorpej 	*fdp = fd;
    431      1.30     rmind 	return 0;
    432       1.1  christos }
    433       1.1  christos 
    434      1.30     rmind /*
    435      1.30     rmind  * ksem_create: allocate and setup a new semaphore structure.
    436      1.30     rmind  */
    437       1.1  christos static int
    438      1.30     rmind ksem_create(lwp_t *l, const char *name, ksem_t **ksret, mode_t mode, u_int val)
    439       1.1  christos {
    440      1.30     rmind 	ksem_t *ks;
    441      1.14      elad 	kauth_cred_t uc;
    442      1.30     rmind 	char *kname;
    443       1.1  christos 	size_t len;
    444       1.1  christos 
    445      1.30     rmind 	/* Pre-check for the limit. */
    446      1.30     rmind 	if (nsems >= ksem_max) {
    447      1.30     rmind 		return ENFILE;
    448      1.30     rmind 	}
    449      1.30     rmind 
    450      1.30     rmind 	if (val > SEM_VALUE_MAX) {
    451      1.30     rmind 		return EINVAL;
    452      1.30     rmind 	}
    453      1.30     rmind 
    454       1.1  christos 	if (name != NULL) {
    455       1.1  christos 		len = strlen(name);
    456       1.1  christos 		if (len > SEM_MAX_NAMELEN) {
    457      1.30     rmind 			return ENAMETOOLONG;
    458       1.1  christos 		}
    459      1.30     rmind 		/* Name must start with a '/' but not contain one. */
    460       1.1  christos 		if (*name != '/' || len < 2 || strchr(name + 1, '/') != NULL) {
    461      1.30     rmind 			return EINVAL;
    462       1.1  christos 		}
    463      1.30     rmind 		kname = kmem_alloc(++len, KM_SLEEP);
    464      1.30     rmind 		strlcpy(kname, name, len);
    465      1.30     rmind 	} else {
    466      1.30     rmind 		kname = NULL;
    467      1.30     rmind 		len = 0;
    468      1.30     rmind 	}
    469      1.30     rmind 
    470  1.55.4.1    martin 	chgsemcnt(kauth_cred_getuid(l->l_cred), 1);
    471      1.46  christos 
    472      1.30     rmind 	ks = kmem_zalloc(sizeof(ksem_t), KM_SLEEP);
    473      1.30     rmind 	mutex_init(&ks->ks_lock, MUTEX_DEFAULT, IPL_NONE);
    474      1.30     rmind 	cv_init(&ks->ks_cv, "psem");
    475      1.30     rmind 	ks->ks_name = kname;
    476      1.30     rmind 	ks->ks_namelen = len;
    477      1.30     rmind 	ks->ks_mode = mode;
    478      1.30     rmind 	ks->ks_value = val;
    479      1.30     rmind 	ks->ks_ref = 1;
    480      1.30     rmind 
    481      1.30     rmind 	uc = l->l_cred;
    482      1.30     rmind 	ks->ks_uid = kauth_cred_geteuid(uc);
    483      1.30     rmind 	ks->ks_gid = kauth_cred_getegid(uc);
    484      1.30     rmind 
    485      1.34     rmind 	atomic_inc_uint(&nsems_total);
    486      1.30     rmind 	*ksret = ks;
    487      1.30     rmind 	return 0;
    488      1.30     rmind }
    489      1.30     rmind 
    490      1.30     rmind static void
    491      1.30     rmind ksem_free(ksem_t *ks)
    492      1.30     rmind {
    493       1.3   thorpej 
    494      1.34     rmind 	KASSERT(!cv_has_waiters(&ks->ks_cv));
    495      1.34     rmind 
    496      1.52   thorpej 	if (ks->ks_pshared_id) {
    497      1.52   thorpej 		KASSERT(ks->ks_pshared_proc == NULL);
    498      1.52   thorpej 		ksem_remove_pshared(ks);
    499      1.52   thorpej 	}
    500      1.30     rmind 	if (ks->ks_name) {
    501      1.30     rmind 		KASSERT(ks->ks_namelen > 0);
    502      1.30     rmind 		kmem_free(ks->ks_name, ks->ks_namelen);
    503      1.13      cube 	}
    504      1.30     rmind 	mutex_destroy(&ks->ks_lock);
    505      1.30     rmind 	cv_destroy(&ks->ks_cv);
    506      1.30     rmind 	kmem_free(ks, sizeof(ksem_t));
    507      1.34     rmind 
    508      1.34     rmind 	atomic_dec_uint(&nsems_total);
    509      1.55  christos 	chgsemcnt(kauth_cred_getuid(curproc->p_cred), -1);
    510       1.1  christos }
    511       1.1  christos 
    512      1.52   thorpej #define	KSEM_ID_IS_PSHARED(id)		\
    513      1.52   thorpej 	(((id) & KSEM_MARKER_MASK) == KSEM_PSHARED_MARKER)
    514      1.52   thorpej 
    515      1.52   thorpej static void
    516      1.52   thorpej ksem_release(ksem_t *ksem, int fd)
    517      1.52   thorpej {
    518      1.52   thorpej 	bool destroy = false;
    519      1.52   thorpej 
    520      1.52   thorpej 	KASSERT(mutex_owned(&ksem->ks_lock));
    521      1.52   thorpej 
    522      1.52   thorpej 	KASSERT(ksem->ks_ref > 0);
    523      1.52   thorpej 	if (--ksem->ks_ref == 0) {
    524      1.52   thorpej 		/*
    525      1.52   thorpej 		 * Destroy if the last reference and semaphore is unnamed,
    526      1.52   thorpej 		 * or unlinked (for named semaphore).
    527      1.52   thorpej 		 */
    528      1.52   thorpej 		destroy = (ksem->ks_flags & KS_UNLINKED) ||
    529      1.52   thorpej 		    (ksem->ks_name == NULL);
    530      1.52   thorpej 	}
    531      1.52   thorpej 	mutex_exit(&ksem->ks_lock);
    532      1.52   thorpej 
    533      1.52   thorpej 	if (destroy) {
    534      1.52   thorpej 		ksem_free(ksem);
    535      1.52   thorpej 	}
    536      1.52   thorpej 	if (fd != -1) {
    537      1.52   thorpej 		fd_putfile(fd);
    538      1.52   thorpej 	}
    539      1.52   thorpej }
    540      1.52   thorpej 
    541       1.1  christos int
    542      1.30     rmind sys__ksem_init(struct lwp *l, const struct sys__ksem_init_args *uap,
    543      1.30     rmind     register_t *retval)
    544       1.1  christos {
    545      1.23       dsl 	/* {
    546       1.1  christos 		unsigned int value;
    547      1.29        ad 		intptr_t *idp;
    548      1.23       dsl 	} */
    549      1.13      cube 
    550      1.52   thorpej 	return do_ksem_init(l, SCARG(uap, value), SCARG(uap, idp),
    551      1.52   thorpej 	    copyin, copyout);
    552      1.13      cube }
    553      1.13      cube 
    554      1.13      cube int
    555      1.52   thorpej do_ksem_init(lwp_t *l, u_int val, intptr_t *idp, copyin_t docopyin,
    556      1.52   thorpej     copyout_t docopyout)
    557      1.13      cube {
    558      1.30     rmind 	proc_t *p = l->l_proc;
    559      1.30     rmind 	ksem_t *ks;
    560      1.30     rmind 	file_t *fp;
    561      1.52   thorpej 	intptr_t id, arg;
    562      1.30     rmind 	int fd, error;
    563       1.1  christos 
    564      1.52   thorpej 	/*
    565      1.52   thorpej 	 * Newer versions of librt / libpthread pass us 'PSRD' in *idp to
    566      1.52   thorpej 	 * indicate that a pshared semaphore is wanted.  In that case we
    567      1.52   thorpej 	 * allocate globally unique ID and return that, rather than the
    568      1.52   thorpej 	 * process-scoped file descriptor ID.
    569      1.52   thorpej 	 */
    570      1.52   thorpej 	error = (*docopyin)(idp, &arg, sizeof(*idp));
    571      1.52   thorpej 	if (error) {
    572      1.52   thorpej 		return error;
    573      1.52   thorpej 	}
    574      1.52   thorpej 
    575      1.30     rmind 	error = fd_allocfile(&fp, &fd);
    576       1.1  christos 	if (error) {
    577      1.30     rmind 		return error;
    578       1.1  christos 	}
    579      1.30     rmind 	fp->f_type = DTYPE_SEM;
    580      1.30     rmind 	fp->f_flag = FREAD | FWRITE;
    581      1.30     rmind 	fp->f_ops = &semops;
    582       1.3   thorpej 
    583      1.52   thorpej 	if (fd >= KSEM_MARKER_MIN) {
    584      1.52   thorpej 		/*
    585      1.52   thorpej 		 * This is super-unlikely, but we check for it anyway
    586      1.52   thorpej 		 * because potential collisions with the pshared marker
    587      1.52   thorpej 		 * would be bad.
    588      1.52   thorpej 		 */
    589      1.52   thorpej 		fd_abort(p, fp, fd);
    590      1.52   thorpej 		return EMFILE;
    591      1.52   thorpej 	}
    592      1.52   thorpej 
    593      1.52   thorpej 	/* Note the mode does not matter for anonymous semaphores. */
    594      1.52   thorpej 	error = ksem_create(l, NULL, &ks, 0, val);
    595      1.30     rmind 	if (error) {
    596      1.30     rmind 		fd_abort(p, fp, fd);
    597      1.30     rmind 		return error;
    598      1.30     rmind 	}
    599       1.3   thorpej 
    600      1.52   thorpej 	if (arg == KSEM_PSHARED) {
    601      1.52   thorpej 		ks->ks_pshared_proc = curproc;
    602      1.52   thorpej 		ks->ks_pshared_fd = fd;
    603      1.52   thorpej 		ksem_alloc_pshared_id(ks);
    604      1.52   thorpej 		id = ks->ks_pshared_id;
    605      1.52   thorpej 	} else {
    606      1.52   thorpej 		id = (intptr_t)fd;
    607      1.52   thorpej 	}
    608      1.52   thorpej 
    609      1.52   thorpej 	error = (*docopyout)(&id, idp, sizeof(*idp));
    610      1.30     rmind 	if (error) {
    611      1.52   thorpej 		ksem_free(ks);
    612      1.30     rmind 		fd_abort(p, fp, fd);
    613      1.30     rmind 		return error;
    614      1.30     rmind 	}
    615      1.52   thorpej 
    616      1.42      matt 	fp->f_ksem = ks;
    617      1.30     rmind 	fd_affix(p, fp, fd);
    618      1.30     rmind 	return error;
    619       1.1  christos }
    620       1.1  christos 
    621       1.1  christos int
    622      1.30     rmind sys__ksem_open(struct lwp *l, const struct sys__ksem_open_args *uap,
    623      1.30     rmind     register_t *retval)
    624       1.1  christos {
    625      1.23       dsl 	/* {
    626       1.1  christos 		const char *name;
    627       1.1  christos 		int oflag;
    628       1.1  christos 		mode_t mode;
    629       1.1  christos 		unsigned int value;
    630      1.29        ad 		intptr_t *idp;
    631      1.23       dsl 	} */
    632      1.13      cube 
    633      1.13      cube 	return do_ksem_open(l, SCARG(uap, name), SCARG(uap, oflag),
    634      1.13      cube 	    SCARG(uap, mode), SCARG(uap, value), SCARG(uap, idp), copyout);
    635      1.13      cube }
    636      1.13      cube 
    637      1.13      cube int
    638      1.13      cube do_ksem_open(struct lwp *l, const char *semname, int oflag, mode_t mode,
    639      1.29        ad      unsigned int value, intptr_t *idp, copyout_t docopyout)
    640      1.13      cube {
    641      1.51  christos 	char *name;
    642      1.30     rmind 	proc_t *p = l->l_proc;
    643      1.30     rmind 	ksem_t *ksnew = NULL, *ks;
    644      1.30     rmind 	file_t *fp;
    645      1.29        ad 	intptr_t id;
    646      1.30     rmind 	int fd, error;
    647       1.1  christos 
    648      1.51  christos 	error = name_copyin(semname, &name);
    649      1.30     rmind 	if (error) {
    650      1.30     rmind 		return error;
    651      1.30     rmind 	}
    652      1.30     rmind 	error = fd_allocfile(&fp, &fd);
    653      1.30     rmind 	if (error) {
    654      1.51  christos 		name_destroy(&name);
    655      1.30     rmind 		return error;
    656      1.30     rmind 	}
    657      1.30     rmind 	fp->f_type = DTYPE_SEM;
    658      1.30     rmind 	fp->f_flag = FREAD | FWRITE;
    659      1.30     rmind 	fp->f_ops = &semops;
    660      1.30     rmind 
    661      1.52   thorpej 	if (fd >= KSEM_MARKER_MIN) {
    662      1.52   thorpej 		/*
    663      1.52   thorpej 		 * This is super-unlikely, but we check for it anyway
    664      1.52   thorpej 		 * because potential collisions with the pshared marker
    665      1.52   thorpej 		 * would be bad.
    666      1.52   thorpej 		 */
    667      1.52   thorpej 		fd_abort(p, fp, fd);
    668      1.52   thorpej 		return EMFILE;
    669      1.52   thorpej 	}
    670      1.52   thorpej 
    671      1.30     rmind 	/*
    672      1.30     rmind 	 * The ID (file descriptor number) can be stored early.
    673      1.30     rmind 	 * Note that zero is a special value for libpthread.
    674      1.30     rmind 	 */
    675      1.30     rmind 	id = (intptr_t)fd;
    676      1.30     rmind 	error = (*docopyout)(&id, idp, sizeof(*idp));
    677      1.30     rmind 	if (error) {
    678      1.30     rmind 		goto err;
    679      1.30     rmind 	}
    680      1.30     rmind 
    681      1.30     rmind 	if (oflag & O_CREAT) {
    682      1.30     rmind 		/* Create a new semaphore. */
    683      1.30     rmind 		error = ksem_create(l, name, &ksnew, mode, value);
    684      1.30     rmind 		if (error) {
    685      1.30     rmind 			goto err;
    686      1.30     rmind 		}
    687      1.30     rmind 		KASSERT(ksnew != NULL);
    688      1.30     rmind 	}
    689       1.1  christos 
    690      1.30     rmind 	/* Lookup for a semaphore with such name. */
    691      1.30     rmind 	mutex_enter(&ksem_lock);
    692      1.30     rmind 	ks = ksem_lookup(name);
    693      1.51  christos 	name_destroy(&name);
    694      1.30     rmind 	if (ks) {
    695      1.30     rmind 		KASSERT(mutex_owned(&ks->ks_lock));
    696      1.30     rmind 		mutex_exit(&ksem_lock);
    697       1.3   thorpej 
    698       1.3   thorpej 		/* Check for exclusive create. */
    699      1.13      cube 		if (oflag & O_EXCL) {
    700      1.30     rmind 			mutex_exit(&ks->ks_lock);
    701      1.30     rmind 			error = EEXIST;
    702      1.30     rmind 			goto err;
    703       1.1  christos 		}
    704       1.1  christos 		/*
    705      1.30     rmind 		 * Verify permissions.  If we can access it,
    706      1.30     rmind 		 * add the reference of this thread.
    707       1.1  christos 		 */
    708      1.15        ad 		error = ksem_perm(l, ks);
    709      1.30     rmind 		if (error == 0) {
    710      1.30     rmind 			ks->ks_ref++;
    711      1.30     rmind 		}
    712      1.30     rmind 		mutex_exit(&ks->ks_lock);
    713       1.1  christos 		if (error) {
    714      1.30     rmind 			goto err;
    715      1.30     rmind 		}
    716      1.30     rmind 	} else {
    717      1.30     rmind 		/* Fail if not found and not creating. */
    718      1.30     rmind 		if ((oflag & O_CREAT) == 0) {
    719      1.30     rmind 			mutex_exit(&ksem_lock);
    720      1.30     rmind 			KASSERT(ksnew == NULL);
    721      1.31     rmind 			error = ENOENT;
    722      1.31     rmind 			goto err;
    723       1.1  christos 		}
    724       1.3   thorpej 
    725      1.30     rmind 		/* Check for the limit locked. */
    726      1.30     rmind 		if (nsems >= ksem_max) {
    727      1.30     rmind 			mutex_exit(&ksem_lock);
    728      1.30     rmind 			error = ENFILE;
    729      1.30     rmind 			goto err;
    730      1.30     rmind 		}
    731       1.3   thorpej 
    732      1.30     rmind 		/*
    733      1.32     rmind 		 * Finally, insert semaphore into the list.
    734      1.30     rmind 		 * Note: it already has the initial reference.
    735      1.30     rmind 		 */
    736      1.30     rmind 		ks = ksnew;
    737      1.30     rmind 		LIST_INSERT_HEAD(&ksem_head, ks, ks_entry);
    738      1.30     rmind 		nsems++;
    739      1.30     rmind 		mutex_exit(&ksem_lock);
    740      1.30     rmind 
    741      1.30     rmind 		ksnew = NULL;
    742      1.30     rmind 	}
    743      1.30     rmind 	KASSERT(ks != NULL);
    744      1.42      matt 	fp->f_ksem = ks;
    745      1.30     rmind 	fd_affix(p, fp, fd);
    746      1.30     rmind err:
    747      1.51  christos 	name_destroy(&name);
    748      1.30     rmind 	if (error) {
    749      1.30     rmind 		fd_abort(p, fp, fd);
    750       1.3   thorpej 	}
    751      1.30     rmind 	if (ksnew) {
    752      1.30     rmind 		ksem_free(ksnew);
    753       1.1  christos 	}
    754      1.30     rmind 	return error;
    755      1.30     rmind }
    756       1.1  christos 
    757      1.30     rmind int
    758      1.30     rmind sys__ksem_close(struct lwp *l, const struct sys__ksem_close_args *uap,
    759      1.30     rmind     register_t *retval)
    760      1.30     rmind {
    761      1.30     rmind 	/* {
    762      1.30     rmind 		intptr_t id;
    763      1.30     rmind 	} */
    764      1.52   thorpej 	intptr_t id = SCARG(uap, id);
    765      1.52   thorpej 	int fd, error;
    766      1.52   thorpej 	ksem_t *ks;
    767      1.52   thorpej 
    768      1.52   thorpej 	error = ksem_get(id, &ks, &fd);
    769      1.52   thorpej 	if (error) {
    770      1.52   thorpej 		return error;
    771      1.52   thorpej 	}
    772      1.33     rmind 
    773      1.52   thorpej 	/* This is only for named semaphores. */
    774      1.52   thorpej 	if (ks->ks_name == NULL) {
    775      1.52   thorpej 		error = EINVAL;
    776      1.52   thorpej 	}
    777      1.52   thorpej 	ksem_release(ks, -1);
    778      1.52   thorpej 	if (error) {
    779      1.52   thorpej 		if (fd != -1)
    780      1.52   thorpej 			fd_putfile(fd);
    781      1.52   thorpej 		return error;
    782      1.33     rmind 	}
    783      1.33     rmind 	return fd_close(fd);
    784       1.1  christos }
    785       1.1  christos 
    786      1.30     rmind static int
    787      1.39  christos ksem_read_fop(file_t *fp, off_t *offset, struct uio *uio, kauth_cred_t cred,
    788      1.39  christos     int flags)
    789      1.39  christos {
    790      1.39  christos 	size_t len;
    791      1.39  christos 	char *name;
    792      1.42      matt 	ksem_t *ks = fp->f_ksem;
    793      1.39  christos 
    794      1.39  christos 	mutex_enter(&ks->ks_lock);
    795      1.39  christos 	len = ks->ks_namelen;
    796      1.39  christos 	name = ks->ks_name;
    797      1.39  christos 	mutex_exit(&ks->ks_lock);
    798      1.39  christos 	if (name == NULL || len == 0)
    799      1.39  christos 		return 0;
    800      1.39  christos 	return uiomove(name, len, uio);
    801      1.39  christos }
    802      1.39  christos 
    803      1.39  christos static int
    804      1.39  christos ksem_stat_fop(file_t *fp, struct stat *ub)
    805      1.39  christos {
    806      1.42      matt 	ksem_t *ks = fp->f_ksem;
    807      1.39  christos 
    808      1.39  christos 	mutex_enter(&ks->ks_lock);
    809      1.39  christos 
    810      1.39  christos 	memset(ub, 0, sizeof(*ub));
    811      1.39  christos 
    812      1.39  christos 	ub->st_mode = ks->ks_mode | ((ks->ks_name && ks->ks_namelen)
    813      1.39  christos 	    ? _S_IFLNK : _S_IFREG);
    814      1.39  christos 	ub->st_uid = ks->ks_uid;
    815      1.39  christos 	ub->st_gid = ks->ks_gid;
    816      1.39  christos 	ub->st_size = ks->ks_value;
    817      1.39  christos 	ub->st_blocks = (ub->st_size) ? 1 : 0;
    818      1.39  christos 	ub->st_nlink = ks->ks_ref;
    819      1.39  christos 	ub->st_blksize = 4096;
    820      1.39  christos 
    821      1.39  christos 	nanotime(&ub->st_atimespec);
    822      1.39  christos 	ub->st_mtimespec = ub->st_ctimespec = ub->st_birthtimespec =
    823      1.39  christos 	    ub->st_atimespec;
    824      1.39  christos 
    825      1.39  christos 	/*
    826      1.39  christos 	 * Left as 0: st_dev, st_ino, st_rdev, st_flags, st_gen.
    827      1.39  christos 	 * XXX (st_dev, st_ino) should be unique.
    828      1.39  christos 	 */
    829      1.39  christos 	mutex_exit(&ks->ks_lock);
    830      1.39  christos 	return 0;
    831      1.39  christos }
    832      1.39  christos 
    833      1.39  christos static int
    834      1.30     rmind ksem_close_fop(file_t *fp)
    835       1.1  christos {
    836      1.42      matt 	ksem_t *ks = fp->f_ksem;
    837       1.1  christos 
    838      1.53   thorpej 	mutex_enter(&ks->ks_lock);
    839      1.53   thorpej 
    840      1.53   thorpej 	if (ks->ks_pshared_id) {
    841      1.53   thorpej 		if (ks->ks_pshared_proc != curproc) {
    842      1.53   thorpej 			/* Do nothing if this is not the creator. */
    843      1.53   thorpej 			mutex_exit(&ks->ks_lock);
    844      1.53   thorpej 			return 0;
    845      1.53   thorpej 		}
    846      1.53   thorpej 		/* Mark this semaphore as dead. */
    847      1.53   thorpej 		ks->ks_pshared_proc = NULL;
    848       1.1  christos 	}
    849       1.3   thorpej 
    850      1.52   thorpej 	ksem_release(ks, -1);
    851      1.30     rmind 	return 0;
    852       1.1  christos }
    853       1.1  christos 
    854       1.1  christos int
    855      1.30     rmind sys__ksem_unlink(struct lwp *l, const struct sys__ksem_unlink_args *uap,
    856      1.30     rmind     register_t *retval)
    857       1.1  christos {
    858      1.23       dsl 	/* {
    859       1.1  christos 		const char *name;
    860      1.23       dsl 	} */
    861      1.51  christos 	char *name;
    862      1.30     rmind 	ksem_t *ks;
    863      1.30     rmind 	u_int refcnt;
    864       1.1  christos 	int error;
    865       1.1  christos 
    866      1.51  christos 	error = name_copyin(SCARG(uap, name), &name);
    867       1.1  christos 	if (error)
    868       1.1  christos 		return error;
    869       1.1  christos 
    870      1.30     rmind 	mutex_enter(&ksem_lock);
    871      1.30     rmind 	ks = ksem_lookup(name);
    872      1.51  christos 	name_destroy(&name);
    873       1.3   thorpej 	if (ks == NULL) {
    874      1.30     rmind 		mutex_exit(&ksem_lock);
    875      1.30     rmind 		return ENOENT;
    876       1.1  christos 	}
    877      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    878       1.3   thorpej 
    879      1.30     rmind 	/* Verify permissions. */
    880      1.30     rmind 	error = ksem_perm(l, ks);
    881      1.30     rmind 	if (error) {
    882      1.30     rmind 		mutex_exit(&ks->ks_lock);
    883      1.30     rmind 		mutex_exit(&ksem_lock);
    884      1.30     rmind 		return error;
    885      1.30     rmind 	}
    886       1.3   thorpej 
    887      1.31     rmind 	/* Remove from the global list. */
    888       1.3   thorpej 	LIST_REMOVE(ks, ks_entry);
    889      1.30     rmind 	nsems--;
    890      1.31     rmind 	mutex_exit(&ksem_lock);
    891       1.3   thorpej 
    892      1.30     rmind 	refcnt = ks->ks_ref;
    893      1.30     rmind 	if (refcnt) {
    894      1.30     rmind 		/* Mark as unlinked, if there are references. */
    895      1.30     rmind 		ks->ks_flags |= KS_UNLINKED;
    896      1.30     rmind 	}
    897      1.30     rmind 	mutex_exit(&ks->ks_lock);
    898       1.3   thorpej 
    899      1.30     rmind 	if (refcnt == 0) {
    900       1.3   thorpej 		ksem_free(ks);
    901      1.30     rmind 	}
    902      1.30     rmind 	return 0;
    903       1.1  christos }
    904       1.1  christos 
    905       1.1  christos int
    906      1.30     rmind sys__ksem_post(struct lwp *l, const struct sys__ksem_post_args *uap,
    907      1.30     rmind     register_t *retval)
    908       1.1  christos {
    909      1.23       dsl 	/* {
    910      1.29        ad 		intptr_t id;
    911      1.23       dsl 	} */
    912      1.52   thorpej 	int fd, error;
    913      1.30     rmind 	ksem_t *ks;
    914       1.1  christos 
    915      1.52   thorpej 	error = ksem_get(SCARG(uap, id), &ks, &fd);
    916      1.30     rmind 	if (error) {
    917      1.30     rmind 		return error;
    918       1.3   thorpej 	}
    919      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    920       1.1  christos 	if (ks->ks_value == SEM_VALUE_MAX) {
    921       1.1  christos 		error = EOVERFLOW;
    922       1.3   thorpej 		goto out;
    923       1.1  christos 	}
    924      1.30     rmind 	ks->ks_value++;
    925      1.30     rmind 	if (ks->ks_waiters) {
    926      1.20        ad 		cv_broadcast(&ks->ks_cv);
    927      1.30     rmind 	}
    928      1.30     rmind out:
    929      1.52   thorpej 	ksem_release(ks, fd);
    930      1.30     rmind 	return error;
    931       1.3   thorpej }
    932       1.3   thorpej 
    933      1.36     joerg int
    934      1.41      matt do_ksem_wait(lwp_t *l, intptr_t id, bool try_p, struct timespec *abstime)
    935       1.3   thorpej {
    936      1.52   thorpej 	int fd, error, timeo;
    937      1.30     rmind 	ksem_t *ks;
    938       1.3   thorpej 
    939      1.52   thorpej 	error = ksem_get(id, &ks, &fd);
    940      1.30     rmind 	if (error) {
    941      1.30     rmind 		return error;
    942      1.30     rmind 	}
    943      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    944       1.3   thorpej 	while (ks->ks_value == 0) {
    945       1.3   thorpej 		ks->ks_waiters++;
    946      1.41      matt 		if (!try_p && abstime != NULL) {
    947      1.40  christos 			error = ts2timo(CLOCK_REALTIME, TIMER_ABSTIME, abstime,
    948      1.40  christos 			    &timeo, NULL);
    949      1.36     joerg 			if (error != 0)
    950      1.36     joerg 				goto out;
    951      1.36     joerg 		} else {
    952      1.36     joerg 			timeo = 0;
    953      1.36     joerg 		}
    954      1.41      matt 		error = try_p ? EAGAIN : cv_timedwait_sig(&ks->ks_cv,
    955      1.36     joerg 		    &ks->ks_lock, timeo);
    956       1.3   thorpej 		ks->ks_waiters--;
    957       1.3   thorpej 		if (error)
    958       1.3   thorpej 			goto out;
    959       1.3   thorpej 	}
    960       1.3   thorpej 	ks->ks_value--;
    961      1.30     rmind out:
    962      1.52   thorpej 	ksem_release(ks, fd);
    963      1.30     rmind 	return error;
    964       1.1  christos }
    965       1.1  christos 
    966       1.1  christos int
    967      1.30     rmind sys__ksem_wait(struct lwp *l, const struct sys__ksem_wait_args *uap,
    968      1.30     rmind     register_t *retval)
    969       1.1  christos {
    970      1.23       dsl 	/* {
    971      1.29        ad 		intptr_t id;
    972      1.23       dsl 	} */
    973       1.1  christos 
    974      1.36     joerg 	return do_ksem_wait(l, SCARG(uap, id), false, NULL);
    975      1.36     joerg }
    976      1.36     joerg 
    977      1.36     joerg int
    978      1.36     joerg sys__ksem_timedwait(struct lwp *l, const struct sys__ksem_timedwait_args *uap,
    979      1.36     joerg     register_t *retval)
    980      1.36     joerg {
    981      1.36     joerg 	/* {
    982      1.36     joerg 		intptr_t id;
    983      1.36     joerg 		const struct timespec *abstime;
    984      1.36     joerg 	} */
    985      1.36     joerg 	struct timespec ts;
    986      1.36     joerg 	int error;
    987      1.36     joerg 
    988      1.36     joerg 	error = copyin(SCARG(uap, abstime), &ts, sizeof(ts));
    989      1.36     joerg 	if (error != 0)
    990      1.36     joerg 		return error;
    991      1.36     joerg 
    992      1.36     joerg 	if (ts.tv_sec < 0 || ts.tv_nsec < 0 || ts.tv_nsec >= 1000000000)
    993      1.36     joerg 		return EINVAL;
    994      1.36     joerg 
    995      1.36     joerg 	error = do_ksem_wait(l, SCARG(uap, id), false, &ts);
    996      1.36     joerg 	if (error == EWOULDBLOCK)
    997      1.36     joerg 		error = ETIMEDOUT;
    998      1.36     joerg 	return error;
    999       1.1  christos }
   1000       1.1  christos 
   1001       1.1  christos int
   1002      1.30     rmind sys__ksem_trywait(struct lwp *l, const struct sys__ksem_trywait_args *uap,
   1003      1.30     rmind     register_t *retval)
   1004       1.1  christos {
   1005      1.23       dsl 	/* {
   1006      1.29        ad 		intptr_t id;
   1007      1.23       dsl 	} */
   1008       1.1  christos 
   1009      1.36     joerg 	return do_ksem_wait(l, SCARG(uap, id), true, NULL);
   1010       1.1  christos }
   1011       1.1  christos 
   1012       1.1  christos int
   1013      1.30     rmind sys__ksem_getvalue(struct lwp *l, const struct sys__ksem_getvalue_args *uap,
   1014      1.30     rmind     register_t *retval)
   1015       1.1  christos {
   1016      1.23       dsl 	/* {
   1017      1.29        ad 		intptr_t id;
   1018       1.1  christos 		unsigned int *value;
   1019      1.23       dsl 	} */
   1020      1.52   thorpej 	int fd, error;
   1021      1.30     rmind 	ksem_t *ks;
   1022       1.1  christos 	unsigned int val;
   1023       1.1  christos 
   1024      1.52   thorpej 	error = ksem_get(SCARG(uap, id), &ks, &fd);
   1025      1.30     rmind 	if (error) {
   1026      1.30     rmind 		return error;
   1027      1.30     rmind 	}
   1028      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
   1029       1.1  christos 	val = ks->ks_value;
   1030      1.52   thorpej 	ksem_release(ks, fd);
   1031       1.3   thorpej 
   1032      1.30     rmind 	return copyout(&val, SCARG(uap, value), sizeof(val));
   1033       1.1  christos }
   1034       1.1  christos 
   1035       1.1  christos int
   1036      1.30     rmind sys__ksem_destroy(struct lwp *l, const struct sys__ksem_destroy_args *uap,
   1037      1.30     rmind     register_t *retval)
   1038       1.1  christos {
   1039      1.23       dsl 	/* {
   1040      1.29        ad 		intptr_t id;
   1041      1.23       dsl 	} */
   1042      1.52   thorpej 	int fd, error;
   1043      1.30     rmind 	ksem_t *ks;
   1044       1.1  christos 
   1045      1.52   thorpej 	intptr_t id = SCARG(uap, id);
   1046      1.52   thorpej 
   1047      1.52   thorpej 	error = ksem_get(id, &ks, &fd);
   1048      1.30     rmind 	if (error) {
   1049      1.30     rmind 		return error;
   1050       1.3   thorpej 	}
   1051      1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
   1052       1.3   thorpej 
   1053      1.30     rmind 	/* Operation is only for unnamed semaphores. */
   1054       1.3   thorpej 	if (ks->ks_name != NULL) {
   1055      1.30     rmind 		error = EINVAL;
   1056      1.30     rmind 		goto out;
   1057       1.3   thorpej 	}
   1058      1.30     rmind 	/* Cannot destroy if there are waiters. */
   1059       1.3   thorpej 	if (ks->ks_waiters) {
   1060      1.30     rmind 		error = EBUSY;
   1061      1.30     rmind 		goto out;
   1062       1.3   thorpej 	}
   1063      1.52   thorpej 	if (KSEM_ID_IS_PSHARED(id)) {
   1064      1.52   thorpej 		/* Cannot destroy if we did't create it. */
   1065      1.52   thorpej 		KASSERT(fd == -1);
   1066      1.52   thorpej 		KASSERT(ks->ks_pshared_proc != NULL);
   1067      1.52   thorpej 		if (ks->ks_pshared_proc != curproc) {
   1068      1.52   thorpej 			error = EINVAL;
   1069      1.52   thorpej 			goto out;
   1070      1.52   thorpej 		}
   1071      1.52   thorpej 		fd = ks->ks_pshared_fd;
   1072      1.52   thorpej 
   1073      1.52   thorpej 		/* Mark it dead so subsequent lookups fail. */
   1074      1.52   thorpej 		ks->ks_pshared_proc = NULL;
   1075      1.52   thorpej 
   1076      1.52   thorpej 		/* Do an fd_getfile() to for the benefit of fd_close(). */
   1077      1.52   thorpej 		file_t *fp __diagused = fd_getfile(fd);
   1078      1.52   thorpej 		KASSERT(fp != NULL);
   1079      1.52   thorpej 		KASSERT(fp->f_ksem == ks);
   1080      1.52   thorpej 	}
   1081      1.30     rmind out:
   1082      1.52   thorpej 	ksem_release(ks, -1);
   1083      1.30     rmind 	if (error) {
   1084      1.52   thorpej 		if (!KSEM_ID_IS_PSHARED(id))
   1085      1.52   thorpej 			fd_putfile(fd);
   1086      1.27        ad 		return error;
   1087      1.27        ad 	}
   1088      1.32     rmind 	return fd_close(fd);
   1089      1.22     rmind }
   1090