Home | History | Annotate | Line # | Download | only in kern
uipc_sem.c revision 1.60
      1  1.60       chs /*	$NetBSD: uipc_sem.c,v 1.60 2020/12/14 23:12:12 chs Exp $	*/
      2   1.3   thorpej 
      3   1.3   thorpej /*-
      4  1.52   thorpej  * Copyright (c) 2011, 2019 The NetBSD Foundation, Inc.
      5   1.3   thorpej  * All rights reserved.
      6   1.3   thorpej  *
      7   1.3   thorpej  * This code is derived from software contributed to The NetBSD Foundation
      8  1.52   thorpej  * by Mindaugas Rasiukevicius and Jason R. Thorpe.
      9   1.3   thorpej  *
     10   1.3   thorpej  * Redistribution and use in source and binary forms, with or without
     11   1.3   thorpej  * modification, are permitted provided that the following conditions
     12   1.3   thorpej  * are met:
     13   1.3   thorpej  * 1. Redistributions of source code must retain the above copyright
     14   1.3   thorpej  *    notice, this list of conditions and the following disclaimer.
     15   1.3   thorpej  * 2. Redistributions in binary form must reproduce the above copyright
     16   1.3   thorpej  *    notice, this list of conditions and the following disclaimer in the
     17   1.3   thorpej  *    documentation and/or other materials provided with the distribution.
     18   1.3   thorpej  *
     19   1.3   thorpej  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
     20   1.3   thorpej  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
     21   1.3   thorpej  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     22   1.3   thorpej  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
     23   1.3   thorpej  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     24   1.3   thorpej  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     25   1.3   thorpej  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     26   1.3   thorpej  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     27   1.3   thorpej  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     28   1.3   thorpej  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
     29   1.3   thorpej  * POSSIBILITY OF SUCH DAMAGE.
     30   1.3   thorpej  */
     31   1.1  christos 
     32   1.1  christos /*
     33   1.1  christos  * Copyright (c) 2002 Alfred Perlstein <alfred (at) FreeBSD.org>
     34   1.1  christos  * All rights reserved.
     35   1.1  christos  *
     36   1.1  christos  * Redistribution and use in source and binary forms, with or without
     37   1.1  christos  * modification, are permitted provided that the following conditions
     38   1.1  christos  * are met:
     39   1.1  christos  * 1. Redistributions of source code must retain the above copyright
     40   1.1  christos  *    notice, this list of conditions and the following disclaimer.
     41   1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     42   1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     43   1.1  christos  *    documentation and/or other materials provided with the distribution.
     44   1.1  christos  *
     45   1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
     46   1.1  christos  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     47   1.1  christos  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     48   1.1  christos  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     49   1.1  christos  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     50   1.1  christos  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     51   1.1  christos  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     52   1.1  christos  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     53   1.1  christos  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     54   1.1  christos  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     55   1.1  christos  * SUCH DAMAGE.
     56   1.1  christos  */
     57   1.9     lukem 
     58  1.30     rmind /*
     59  1.30     rmind  * Implementation of POSIX semaphore.
     60  1.30     rmind  */
     61  1.30     rmind 
     62   1.9     lukem #include <sys/cdefs.h>
     63  1.60       chs __KERNEL_RCSID(0, "$NetBSD: uipc_sem.c,v 1.60 2020/12/14 23:12:12 chs Exp $");
     64   1.1  christos 
     65   1.1  christos #include <sys/param.h>
     66   1.1  christos #include <sys/kernel.h>
     67  1.34     rmind 
     68  1.34     rmind #include <sys/atomic.h>
     69   1.1  christos #include <sys/proc.h>
     70  1.52   thorpej #include <sys/lwp.h>
     71   1.1  christos #include <sys/ksem.h>
     72   1.1  christos #include <sys/syscall.h>
     73   1.1  christos #include <sys/stat.h>
     74  1.21        ad #include <sys/kmem.h>
     75   1.1  christos #include <sys/fcntl.h>
     76  1.30     rmind #include <sys/file.h>
     77  1.30     rmind #include <sys/filedesc.h>
     78  1.14      elad #include <sys/kauth.h>
     79  1.27        ad #include <sys/module.h>
     80   1.1  christos #include <sys/mount.h>
     81  1.52   thorpej #include <sys/mutex.h>
     82  1.52   thorpej #include <sys/rwlock.h>
     83  1.45  dholland #include <sys/semaphore.h>
     84  1.27        ad #include <sys/syscall.h>
     85   1.1  christos #include <sys/syscallargs.h>
     86  1.27        ad #include <sys/syscallvar.h>
     87  1.43  pgoyette #include <sys/sysctl.h>
     88  1.55  christos #include <sys/uidinfo.h>
     89  1.52   thorpej #include <sys/cprng.h>
     90   1.1  christos 
     91  1.30     rmind MODULE(MODULE_CLASS_MISC, ksem, NULL);
     92  1.30     rmind 
     93  1.49  christos #define	SEM_MAX_NAMELEN		NAME_MAX
     94   1.1  christos 
     95  1.30     rmind #define	KS_UNLINKED		0x01
     96   1.4   thorpej 
     97  1.30     rmind static kmutex_t		ksem_lock	__cacheline_aligned;
     98  1.30     rmind static LIST_HEAD(,ksem)	ksem_head	__cacheline_aligned;
     99  1.34     rmind static u_int		nsems_total	__cacheline_aligned;
    100  1.30     rmind static u_int		nsems		__cacheline_aligned;
    101  1.30     rmind 
    102  1.52   thorpej static krwlock_t	ksem_pshared_lock __cacheline_aligned;
    103  1.52   thorpej static LIST_HEAD(, ksem) *ksem_pshared_hashtab __cacheline_aligned;
    104  1.52   thorpej static u_long		ksem_pshared_hashmask __read_mostly;
    105  1.52   thorpej 
    106  1.52   thorpej #define	KSEM_PSHARED_HASHSIZE	32
    107  1.52   thorpej 
    108  1.38      elad static kauth_listener_t	ksem_listener;
    109  1.38      elad 
    110  1.30     rmind static int		ksem_sysinit(void);
    111  1.30     rmind static int		ksem_sysfini(bool);
    112  1.30     rmind static int		ksem_modcmd(modcmd_t, void *);
    113  1.59  riastrad static void		ksem_release(ksem_t *, int);
    114  1.30     rmind static int		ksem_close_fop(file_t *);
    115  1.39  christos static int		ksem_stat_fop(file_t *, struct stat *);
    116  1.39  christos static int		ksem_read_fop(file_t *, off_t *, struct uio *,
    117  1.39  christos     kauth_cred_t, int);
    118  1.30     rmind 
    119  1.30     rmind static const struct fileops semops = {
    120  1.48  christos 	.fo_name = "sem",
    121  1.39  christos 	.fo_read = ksem_read_fop,
    122  1.30     rmind 	.fo_write = fbadop_write,
    123  1.30     rmind 	.fo_ioctl = fbadop_ioctl,
    124  1.30     rmind 	.fo_fcntl = fnullop_fcntl,
    125  1.30     rmind 	.fo_poll = fnullop_poll,
    126  1.39  christos 	.fo_stat = ksem_stat_fop,
    127  1.30     rmind 	.fo_close = ksem_close_fop,
    128  1.30     rmind 	.fo_kqfilter = fnullop_kqfilter,
    129  1.30     rmind 	.fo_restart = fnullop_restart,
    130  1.30     rmind };
    131  1.27        ad 
    132  1.27        ad static const struct syscall_package ksem_syscalls[] = {
    133  1.27        ad 	{ SYS__ksem_init, 0, (sy_call_t *)sys__ksem_init },
    134  1.27        ad 	{ SYS__ksem_open, 0, (sy_call_t *)sys__ksem_open },
    135  1.27        ad 	{ SYS__ksem_unlink, 0, (sy_call_t *)sys__ksem_unlink },
    136  1.27        ad 	{ SYS__ksem_close, 0, (sy_call_t *)sys__ksem_close },
    137  1.27        ad 	{ SYS__ksem_post, 0, (sy_call_t *)sys__ksem_post },
    138  1.27        ad 	{ SYS__ksem_wait, 0, (sy_call_t *)sys__ksem_wait },
    139  1.27        ad 	{ SYS__ksem_trywait, 0, (sy_call_t *)sys__ksem_trywait },
    140  1.27        ad 	{ SYS__ksem_getvalue, 0, (sy_call_t *)sys__ksem_getvalue },
    141  1.27        ad 	{ SYS__ksem_destroy, 0, (sy_call_t *)sys__ksem_destroy },
    142  1.36     joerg 	{ SYS__ksem_timedwait, 0, (sy_call_t *)sys__ksem_timedwait },
    143  1.27        ad 	{ 0, 0, NULL },
    144  1.27        ad };
    145   1.1  christos 
    146  1.43  pgoyette struct sysctllog *ksem_clog;
    147  1.57        ad int ksem_max = KSEM_MAX;
    148  1.43  pgoyette 
    149  1.30     rmind static int
    150  1.51  christos name_copyin(const char *uname, char **name)
    151  1.51  christos {
    152  1.51  christos 	*name = kmem_alloc(SEM_MAX_NAMELEN, KM_SLEEP);
    153  1.51  christos 
    154  1.51  christos 	int error = copyinstr(uname, *name, SEM_MAX_NAMELEN, NULL);
    155  1.51  christos 	if (error)
    156  1.51  christos 		kmem_free(*name, SEM_MAX_NAMELEN);
    157  1.51  christos 
    158  1.51  christos 	return error;
    159  1.51  christos }
    160  1.51  christos 
    161  1.51  christos static void
    162  1.51  christos name_destroy(char **name)
    163  1.51  christos {
    164  1.51  christos 	if (!*name)
    165  1.51  christos 		return;
    166  1.51  christos 
    167  1.51  christos 	kmem_free(*name, SEM_MAX_NAMELEN);
    168  1.51  christos 	*name = NULL;
    169  1.51  christos }
    170  1.51  christos 
    171  1.51  christos static int
    172  1.38      elad ksem_listener_cb(kauth_cred_t cred, kauth_action_t action, void *cookie,
    173  1.38      elad     void *arg0, void *arg1, void *arg2, void *arg3)
    174  1.38      elad {
    175  1.38      elad 	ksem_t *ks;
    176  1.38      elad 	mode_t mode;
    177  1.38      elad 
    178  1.38      elad 	if (action != KAUTH_SYSTEM_SEMAPHORE)
    179  1.38      elad 		return KAUTH_RESULT_DEFER;
    180  1.38      elad 
    181  1.38      elad 	ks = arg1;
    182  1.38      elad 	mode = ks->ks_mode;
    183  1.38      elad 
    184  1.38      elad 	if ((kauth_cred_geteuid(cred) == ks->ks_uid && (mode & S_IWUSR) != 0) ||
    185  1.38      elad 	    (kauth_cred_getegid(cred) == ks->ks_gid && (mode & S_IWGRP) != 0) ||
    186  1.38      elad 	    (mode & S_IWOTH) != 0)
    187  1.38      elad 		return KAUTH_RESULT_ALLOW;
    188  1.38      elad 
    189  1.38      elad 	return KAUTH_RESULT_DEFER;
    190  1.38      elad }
    191  1.38      elad 
    192  1.38      elad static int
    193  1.30     rmind ksem_sysinit(void)
    194   1.3   thorpej {
    195  1.30     rmind 	int error;
    196  1.43  pgoyette 	const struct sysctlnode *rnode;
    197   1.1  christos 
    198  1.30     rmind 	mutex_init(&ksem_lock, MUTEX_DEFAULT, IPL_NONE);
    199  1.30     rmind 	LIST_INIT(&ksem_head);
    200  1.34     rmind 	nsems_total = 0;
    201  1.34     rmind 	nsems = 0;
    202  1.20        ad 
    203  1.52   thorpej 	rw_init(&ksem_pshared_lock);
    204  1.52   thorpej 	ksem_pshared_hashtab = hashinit(KSEM_PSHARED_HASHSIZE, HASH_LIST,
    205  1.52   thorpej 	    true, &ksem_pshared_hashmask);
    206  1.52   thorpej 	KASSERT(ksem_pshared_hashtab != NULL);
    207  1.52   thorpej 
    208  1.38      elad 	ksem_listener = kauth_listen_scope(KAUTH_SCOPE_SYSTEM,
    209  1.38      elad 	    ksem_listener_cb, NULL);
    210  1.38      elad 
    211  1.43  pgoyette 	/* Define module-specific sysctl tree */
    212  1.43  pgoyette 
    213  1.43  pgoyette 	ksem_clog = NULL;
    214  1.43  pgoyette 
    215  1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, NULL, &rnode,
    216  1.43  pgoyette 			CTLFLAG_PERMANENT,
    217  1.43  pgoyette 			CTLTYPE_NODE, "posix",
    218  1.43  pgoyette 			SYSCTL_DESCR("POSIX options"),
    219  1.43  pgoyette 			NULL, 0, NULL, 0,
    220  1.43  pgoyette 			CTL_KERN, CTL_CREATE, CTL_EOL);
    221  1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, &rnode, NULL,
    222  1.43  pgoyette 			CTLFLAG_PERMANENT | CTLFLAG_READWRITE,
    223  1.43  pgoyette 			CTLTYPE_INT, "semmax",
    224  1.43  pgoyette 			SYSCTL_DESCR("Maximal number of semaphores"),
    225  1.43  pgoyette 			NULL, 0, &ksem_max, 0,
    226  1.43  pgoyette 			CTL_CREATE, CTL_EOL);
    227  1.43  pgoyette 	sysctl_createv(&ksem_clog, 0, &rnode, NULL,
    228  1.44  pgoyette 			CTLFLAG_PERMANENT | CTLFLAG_READONLY,
    229  1.43  pgoyette 			CTLTYPE_INT, "semcnt",
    230  1.43  pgoyette 			SYSCTL_DESCR("Current number of semaphores"),
    231  1.43  pgoyette 			NULL, 0, &nsems, 0,
    232  1.43  pgoyette 			CTL_CREATE, CTL_EOL);
    233  1.43  pgoyette 
    234  1.58        ad 	error = syscall_establish(NULL, ksem_syscalls);
    235  1.58        ad 	if (error) {
    236  1.58        ad 		(void)ksem_sysfini(false);
    237  1.58        ad 	}
    238  1.58        ad 
    239  1.30     rmind 	return error;
    240   1.3   thorpej }
    241   1.1  christos 
    242  1.30     rmind static int
    243  1.30     rmind ksem_sysfini(bool interface)
    244   1.1  christos {
    245  1.30     rmind 	int error;
    246   1.1  christos 
    247  1.30     rmind 	if (interface) {
    248  1.30     rmind 		error = syscall_disestablish(NULL, ksem_syscalls);
    249  1.30     rmind 		if (error != 0) {
    250  1.30     rmind 			return error;
    251  1.30     rmind 		}
    252  1.34     rmind 		/*
    253  1.34     rmind 		 * Make sure that no semaphores are in use.  Note: semops
    254  1.34     rmind 		 * must be unused at this point.
    255  1.34     rmind 		 */
    256  1.34     rmind 		if (nsems_total) {
    257  1.30     rmind 			error = syscall_establish(NULL, ksem_syscalls);
    258  1.30     rmind 			KASSERT(error == 0);
    259  1.30     rmind 			return EBUSY;
    260  1.30     rmind 		}
    261   1.3   thorpej 	}
    262  1.38      elad 	kauth_unlisten_scope(ksem_listener);
    263  1.52   thorpej 	hashdone(ksem_pshared_hashtab, HASH_LIST, ksem_pshared_hashmask);
    264  1.52   thorpej 	rw_destroy(&ksem_pshared_lock);
    265  1.30     rmind 	mutex_destroy(&ksem_lock);
    266  1.43  pgoyette 	sysctl_teardown(&ksem_clog);
    267  1.30     rmind 	return 0;
    268   1.3   thorpej }
    269   1.3   thorpej 
    270  1.30     rmind static int
    271  1.30     rmind ksem_modcmd(modcmd_t cmd, void *arg)
    272   1.3   thorpej {
    273   1.3   thorpej 
    274  1.30     rmind 	switch (cmd) {
    275  1.30     rmind 	case MODULE_CMD_INIT:
    276  1.30     rmind 		return ksem_sysinit();
    277   1.3   thorpej 
    278  1.30     rmind 	case MODULE_CMD_FINI:
    279  1.30     rmind 		return ksem_sysfini(true);
    280   1.1  christos 
    281  1.30     rmind 	default:
    282  1.30     rmind 		return ENOTTY;
    283  1.16   thorpej 	}
    284  1.16   thorpej }
    285  1.16   thorpej 
    286  1.30     rmind static ksem_t *
    287  1.30     rmind ksem_lookup(const char *name)
    288   1.3   thorpej {
    289  1.30     rmind 	ksem_t *ks;
    290   1.3   thorpej 
    291  1.30     rmind 	KASSERT(mutex_owned(&ksem_lock));
    292   1.3   thorpej 
    293  1.30     rmind 	LIST_FOREACH(ks, &ksem_head, ks_entry) {
    294  1.30     rmind 		if (strcmp(ks->ks_name, name) == 0) {
    295  1.30     rmind 			mutex_enter(&ks->ks_lock);
    296  1.30     rmind 			return ks;
    297   1.3   thorpej 		}
    298   1.1  christos 	}
    299  1.30     rmind 	return NULL;
    300   1.1  christos }
    301   1.1  christos 
    302   1.3   thorpej static int
    303  1.30     rmind ksem_perm(lwp_t *l, ksem_t *ks)
    304   1.3   thorpej {
    305  1.30     rmind 	kauth_cred_t uc = l->l_cred;
    306   1.3   thorpej 
    307  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    308  1.30     rmind 
    309  1.38      elad 	if (kauth_authorize_system(uc, KAUTH_SYSTEM_SEMAPHORE, 0, ks, NULL, NULL) != 0)
    310  1.38      elad 		return EACCES;
    311  1.38      elad 
    312  1.38      elad 	return 0;
    313   1.3   thorpej }
    314   1.3   thorpej 
    315  1.30     rmind /*
    316  1.52   thorpej  * Bits 1..23 are random, just pluck a few of those and assume the
    317  1.52   thorpej  * distribution is going to be pretty good.
    318  1.52   thorpej  */
    319  1.52   thorpej #define	KSEM_PSHARED_HASH(id)	(((id) >> 1) & ksem_pshared_hashmask)
    320  1.52   thorpej 
    321  1.52   thorpej static void
    322  1.52   thorpej ksem_remove_pshared(ksem_t *ksem)
    323  1.52   thorpej {
    324  1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_WRITER);
    325  1.52   thorpej 	LIST_REMOVE(ksem, ks_entry);
    326  1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    327  1.52   thorpej }
    328  1.52   thorpej 
    329  1.52   thorpej static ksem_t *
    330  1.52   thorpej ksem_lookup_pshared_locked(intptr_t id)
    331  1.52   thorpej {
    332  1.52   thorpej 	u_long bucket = KSEM_PSHARED_HASH(id);
    333  1.52   thorpej 	ksem_t *ksem = NULL;
    334  1.52   thorpej 
    335  1.52   thorpej 	/* ksem_t is locked and referenced upon return. */
    336  1.52   thorpej 
    337  1.52   thorpej 	LIST_FOREACH(ksem, &ksem_pshared_hashtab[bucket], ks_entry) {
    338  1.52   thorpej 		if (ksem->ks_pshared_id == id) {
    339  1.52   thorpej 			mutex_enter(&ksem->ks_lock);
    340  1.52   thorpej 			if (ksem->ks_pshared_proc == NULL) {
    341  1.52   thorpej 				/*
    342  1.52   thorpej 				 * This entry is dead, and in the process
    343  1.52   thorpej 				 * of being torn down; skip it.
    344  1.52   thorpej 				 */
    345  1.52   thorpej 				mutex_exit(&ksem->ks_lock);
    346  1.52   thorpej 				continue;
    347  1.52   thorpej 			}
    348  1.52   thorpej 			ksem->ks_ref++;
    349  1.52   thorpej 			KASSERT(ksem->ks_ref != 0);
    350  1.52   thorpej 			return ksem;
    351  1.52   thorpej 		}
    352  1.52   thorpej 	}
    353  1.52   thorpej 
    354  1.52   thorpej 	return NULL;
    355  1.52   thorpej }
    356  1.52   thorpej 
    357  1.52   thorpej static ksem_t *
    358  1.52   thorpej ksem_lookup_pshared(intptr_t id)
    359  1.52   thorpej {
    360  1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_READER);
    361  1.52   thorpej 	ksem_t *ksem = ksem_lookup_pshared_locked(id);
    362  1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    363  1.52   thorpej 	return ksem;
    364  1.52   thorpej }
    365  1.52   thorpej 
    366  1.52   thorpej static void
    367  1.52   thorpej ksem_alloc_pshared_id(ksem_t *ksem)
    368  1.52   thorpej {
    369  1.59  riastrad 	ksem_t *ksem0;
    370  1.52   thorpej 	uint32_t try;
    371  1.52   thorpej 
    372  1.52   thorpej 	KASSERT(ksem->ks_pshared_proc != NULL);
    373  1.52   thorpej 
    374  1.52   thorpej 	rw_enter(&ksem_pshared_lock, RW_WRITER);
    375  1.52   thorpej 	for (;;) {
    376  1.52   thorpej 		try = (cprng_fast32() & ~KSEM_MARKER_MASK) |
    377  1.52   thorpej 		    KSEM_PSHARED_MARKER;
    378  1.52   thorpej 
    379  1.59  riastrad 		if ((ksem0 = ksem_lookup_pshared_locked(try)) == NULL) {
    380  1.52   thorpej 			/* Got it! */
    381  1.52   thorpej 			break;
    382  1.52   thorpej 		}
    383  1.59  riastrad 		ksem_release(ksem0, -1);
    384  1.52   thorpej 	}
    385  1.52   thorpej 	ksem->ks_pshared_id = try;
    386  1.52   thorpej 	u_long bucket = KSEM_PSHARED_HASH(ksem->ks_pshared_id);
    387  1.52   thorpej 	LIST_INSERT_HEAD(&ksem_pshared_hashtab[bucket], ksem, ks_entry);
    388  1.52   thorpej 	rw_exit(&ksem_pshared_lock);
    389  1.52   thorpej }
    390  1.52   thorpej 
    391  1.52   thorpej /*
    392  1.30     rmind  * ksem_get: get the semaphore from the descriptor.
    393  1.30     rmind  *
    394  1.52   thorpej  * => locks the semaphore, if found, and holds an extra reference.
    395  1.30     rmind  * => holds a reference on the file descriptor.
    396  1.30     rmind  */
    397  1.30     rmind static int
    398  1.52   thorpej ksem_get(intptr_t id, ksem_t **ksret, int *fdp)
    399  1.13      cube {
    400  1.30     rmind 	ksem_t *ks;
    401  1.52   thorpej 	int fd;
    402  1.52   thorpej 
    403  1.52   thorpej 	if ((id & KSEM_MARKER_MASK) == KSEM_PSHARED_MARKER) {
    404  1.52   thorpej 		/*
    405  1.52   thorpej 		 * ksem_lookup_pshared() returns the ksem_t *
    406  1.52   thorpej 		 * locked and referenced.
    407  1.52   thorpej 		 */
    408  1.52   thorpej 		ks = ksem_lookup_pshared(id);
    409  1.52   thorpej 		if (ks == NULL)
    410  1.52   thorpej 			return EINVAL;
    411  1.52   thorpej 		KASSERT(ks->ks_pshared_id == id);
    412  1.52   thorpej 		KASSERT(ks->ks_pshared_proc != NULL);
    413  1.52   thorpej 		fd = -1;
    414  1.52   thorpej 	} else if (id <= INT_MAX) {
    415  1.52   thorpej 		fd = (int)id;
    416  1.52   thorpej 		file_t *fp = fd_getfile(fd);
    417  1.13      cube 
    418  1.52   thorpej 		if (__predict_false(fp == NULL))
    419  1.52   thorpej 			return EINVAL;
    420  1.52   thorpej 		if (__predict_false(fp->f_type != DTYPE_SEM)) {
    421  1.52   thorpej 			fd_putfile(fd);
    422  1.52   thorpej 			return EINVAL;
    423  1.52   thorpej 		}
    424  1.52   thorpej 		ks = fp->f_ksem;
    425  1.52   thorpej 		mutex_enter(&ks->ks_lock);
    426  1.52   thorpej 		ks->ks_ref++;
    427  1.52   thorpej 	} else {
    428  1.37     joerg 		return EINVAL;
    429  1.13      cube 	}
    430  1.13      cube 
    431  1.30     rmind 	*ksret = ks;
    432  1.52   thorpej 	*fdp = fd;
    433  1.30     rmind 	return 0;
    434   1.1  christos }
    435   1.1  christos 
    436  1.30     rmind /*
    437  1.30     rmind  * ksem_create: allocate and setup a new semaphore structure.
    438  1.30     rmind  */
    439   1.1  christos static int
    440  1.30     rmind ksem_create(lwp_t *l, const char *name, ksem_t **ksret, mode_t mode, u_int val)
    441   1.1  christos {
    442  1.30     rmind 	ksem_t *ks;
    443  1.14      elad 	kauth_cred_t uc;
    444  1.30     rmind 	char *kname;
    445   1.1  christos 	size_t len;
    446   1.1  christos 
    447  1.30     rmind 	/* Pre-check for the limit. */
    448  1.30     rmind 	if (nsems >= ksem_max) {
    449  1.30     rmind 		return ENFILE;
    450  1.30     rmind 	}
    451  1.30     rmind 
    452  1.30     rmind 	if (val > SEM_VALUE_MAX) {
    453  1.30     rmind 		return EINVAL;
    454  1.30     rmind 	}
    455  1.30     rmind 
    456   1.1  christos 	if (name != NULL) {
    457   1.1  christos 		len = strlen(name);
    458   1.1  christos 		if (len > SEM_MAX_NAMELEN) {
    459  1.30     rmind 			return ENAMETOOLONG;
    460   1.1  christos 		}
    461  1.30     rmind 		/* Name must start with a '/' but not contain one. */
    462   1.1  christos 		if (*name != '/' || len < 2 || strchr(name + 1, '/') != NULL) {
    463  1.30     rmind 			return EINVAL;
    464   1.1  christos 		}
    465  1.30     rmind 		kname = kmem_alloc(++len, KM_SLEEP);
    466  1.30     rmind 		strlcpy(kname, name, len);
    467  1.30     rmind 	} else {
    468  1.30     rmind 		kname = NULL;
    469  1.30     rmind 		len = 0;
    470  1.30     rmind 	}
    471  1.30     rmind 
    472  1.30     rmind 	ks = kmem_zalloc(sizeof(ksem_t), KM_SLEEP);
    473  1.30     rmind 	mutex_init(&ks->ks_lock, MUTEX_DEFAULT, IPL_NONE);
    474  1.30     rmind 	cv_init(&ks->ks_cv, "psem");
    475  1.30     rmind 	ks->ks_name = kname;
    476  1.30     rmind 	ks->ks_namelen = len;
    477  1.30     rmind 	ks->ks_mode = mode;
    478  1.30     rmind 	ks->ks_value = val;
    479  1.30     rmind 	ks->ks_ref = 1;
    480  1.30     rmind 
    481  1.30     rmind 	uc = l->l_cred;
    482  1.30     rmind 	ks->ks_uid = kauth_cred_geteuid(uc);
    483  1.30     rmind 	ks->ks_gid = kauth_cred_getegid(uc);
    484  1.60       chs 	chgsemcnt(ks->ks_uid, 1);
    485  1.60       chs 	atomic_inc_uint(&nsems_total);
    486  1.30     rmind 
    487  1.30     rmind 	*ksret = ks;
    488  1.30     rmind 	return 0;
    489  1.30     rmind }
    490  1.30     rmind 
    491  1.30     rmind static void
    492  1.30     rmind ksem_free(ksem_t *ks)
    493  1.30     rmind {
    494   1.3   thorpej 
    495  1.34     rmind 	KASSERT(!cv_has_waiters(&ks->ks_cv));
    496  1.34     rmind 
    497  1.60       chs 	chgsemcnt(ks->ks_uid, -1);
    498  1.60       chs 	atomic_dec_uint(&nsems_total);
    499  1.60       chs 
    500  1.52   thorpej 	if (ks->ks_pshared_id) {
    501  1.52   thorpej 		KASSERT(ks->ks_pshared_proc == NULL);
    502  1.52   thorpej 		ksem_remove_pshared(ks);
    503  1.52   thorpej 	}
    504  1.30     rmind 	if (ks->ks_name) {
    505  1.30     rmind 		KASSERT(ks->ks_namelen > 0);
    506  1.30     rmind 		kmem_free(ks->ks_name, ks->ks_namelen);
    507  1.13      cube 	}
    508  1.30     rmind 	mutex_destroy(&ks->ks_lock);
    509  1.30     rmind 	cv_destroy(&ks->ks_cv);
    510  1.30     rmind 	kmem_free(ks, sizeof(ksem_t));
    511   1.1  christos }
    512   1.1  christos 
    513  1.52   thorpej #define	KSEM_ID_IS_PSHARED(id)		\
    514  1.52   thorpej 	(((id) & KSEM_MARKER_MASK) == KSEM_PSHARED_MARKER)
    515  1.52   thorpej 
    516  1.52   thorpej static void
    517  1.52   thorpej ksem_release(ksem_t *ksem, int fd)
    518  1.52   thorpej {
    519  1.52   thorpej 	bool destroy = false;
    520  1.52   thorpej 
    521  1.52   thorpej 	KASSERT(mutex_owned(&ksem->ks_lock));
    522  1.52   thorpej 
    523  1.52   thorpej 	KASSERT(ksem->ks_ref > 0);
    524  1.52   thorpej 	if (--ksem->ks_ref == 0) {
    525  1.52   thorpej 		/*
    526  1.52   thorpej 		 * Destroy if the last reference and semaphore is unnamed,
    527  1.52   thorpej 		 * or unlinked (for named semaphore).
    528  1.52   thorpej 		 */
    529  1.52   thorpej 		destroy = (ksem->ks_flags & KS_UNLINKED) ||
    530  1.52   thorpej 		    (ksem->ks_name == NULL);
    531  1.52   thorpej 	}
    532  1.52   thorpej 	mutex_exit(&ksem->ks_lock);
    533  1.52   thorpej 
    534  1.52   thorpej 	if (destroy) {
    535  1.52   thorpej 		ksem_free(ksem);
    536  1.52   thorpej 	}
    537  1.52   thorpej 	if (fd != -1) {
    538  1.52   thorpej 		fd_putfile(fd);
    539  1.52   thorpej 	}
    540  1.52   thorpej }
    541  1.52   thorpej 
    542   1.1  christos int
    543  1.30     rmind sys__ksem_init(struct lwp *l, const struct sys__ksem_init_args *uap,
    544  1.30     rmind     register_t *retval)
    545   1.1  christos {
    546  1.23       dsl 	/* {
    547   1.1  christos 		unsigned int value;
    548  1.29        ad 		intptr_t *idp;
    549  1.23       dsl 	} */
    550  1.13      cube 
    551  1.52   thorpej 	return do_ksem_init(l, SCARG(uap, value), SCARG(uap, idp),
    552  1.52   thorpej 	    copyin, copyout);
    553  1.13      cube }
    554  1.13      cube 
    555  1.13      cube int
    556  1.52   thorpej do_ksem_init(lwp_t *l, u_int val, intptr_t *idp, copyin_t docopyin,
    557  1.52   thorpej     copyout_t docopyout)
    558  1.13      cube {
    559  1.30     rmind 	proc_t *p = l->l_proc;
    560  1.30     rmind 	ksem_t *ks;
    561  1.30     rmind 	file_t *fp;
    562  1.52   thorpej 	intptr_t id, arg;
    563  1.30     rmind 	int fd, error;
    564   1.1  christos 
    565  1.52   thorpej 	/*
    566  1.52   thorpej 	 * Newer versions of librt / libpthread pass us 'PSRD' in *idp to
    567  1.52   thorpej 	 * indicate that a pshared semaphore is wanted.  In that case we
    568  1.52   thorpej 	 * allocate globally unique ID and return that, rather than the
    569  1.52   thorpej 	 * process-scoped file descriptor ID.
    570  1.52   thorpej 	 */
    571  1.52   thorpej 	error = (*docopyin)(idp, &arg, sizeof(*idp));
    572  1.52   thorpej 	if (error) {
    573  1.52   thorpej 		return error;
    574  1.52   thorpej 	}
    575  1.52   thorpej 
    576  1.30     rmind 	error = fd_allocfile(&fp, &fd);
    577   1.1  christos 	if (error) {
    578  1.30     rmind 		return error;
    579   1.1  christos 	}
    580  1.30     rmind 	fp->f_type = DTYPE_SEM;
    581  1.30     rmind 	fp->f_flag = FREAD | FWRITE;
    582  1.30     rmind 	fp->f_ops = &semops;
    583   1.3   thorpej 
    584  1.52   thorpej 	if (fd >= KSEM_MARKER_MIN) {
    585  1.52   thorpej 		/*
    586  1.52   thorpej 		 * This is super-unlikely, but we check for it anyway
    587  1.52   thorpej 		 * because potential collisions with the pshared marker
    588  1.52   thorpej 		 * would be bad.
    589  1.52   thorpej 		 */
    590  1.52   thorpej 		fd_abort(p, fp, fd);
    591  1.52   thorpej 		return EMFILE;
    592  1.52   thorpej 	}
    593  1.52   thorpej 
    594  1.52   thorpej 	/* Note the mode does not matter for anonymous semaphores. */
    595  1.52   thorpej 	error = ksem_create(l, NULL, &ks, 0, val);
    596  1.30     rmind 	if (error) {
    597  1.30     rmind 		fd_abort(p, fp, fd);
    598  1.30     rmind 		return error;
    599  1.30     rmind 	}
    600   1.3   thorpej 
    601  1.52   thorpej 	if (arg == KSEM_PSHARED) {
    602  1.52   thorpej 		ks->ks_pshared_proc = curproc;
    603  1.52   thorpej 		ks->ks_pshared_fd = fd;
    604  1.52   thorpej 		ksem_alloc_pshared_id(ks);
    605  1.52   thorpej 		id = ks->ks_pshared_id;
    606  1.52   thorpej 	} else {
    607  1.52   thorpej 		id = (intptr_t)fd;
    608  1.52   thorpej 	}
    609  1.52   thorpej 
    610  1.52   thorpej 	error = (*docopyout)(&id, idp, sizeof(*idp));
    611  1.30     rmind 	if (error) {
    612  1.52   thorpej 		ksem_free(ks);
    613  1.30     rmind 		fd_abort(p, fp, fd);
    614  1.30     rmind 		return error;
    615  1.30     rmind 	}
    616  1.52   thorpej 
    617  1.42      matt 	fp->f_ksem = ks;
    618  1.30     rmind 	fd_affix(p, fp, fd);
    619  1.30     rmind 	return error;
    620   1.1  christos }
    621   1.1  christos 
    622   1.1  christos int
    623  1.30     rmind sys__ksem_open(struct lwp *l, const struct sys__ksem_open_args *uap,
    624  1.30     rmind     register_t *retval)
    625   1.1  christos {
    626  1.23       dsl 	/* {
    627   1.1  christos 		const char *name;
    628   1.1  christos 		int oflag;
    629   1.1  christos 		mode_t mode;
    630   1.1  christos 		unsigned int value;
    631  1.29        ad 		intptr_t *idp;
    632  1.23       dsl 	} */
    633  1.13      cube 
    634  1.13      cube 	return do_ksem_open(l, SCARG(uap, name), SCARG(uap, oflag),
    635  1.13      cube 	    SCARG(uap, mode), SCARG(uap, value), SCARG(uap, idp), copyout);
    636  1.13      cube }
    637  1.13      cube 
    638  1.13      cube int
    639  1.13      cube do_ksem_open(struct lwp *l, const char *semname, int oflag, mode_t mode,
    640  1.29        ad      unsigned int value, intptr_t *idp, copyout_t docopyout)
    641  1.13      cube {
    642  1.51  christos 	char *name;
    643  1.30     rmind 	proc_t *p = l->l_proc;
    644  1.30     rmind 	ksem_t *ksnew = NULL, *ks;
    645  1.30     rmind 	file_t *fp;
    646  1.29        ad 	intptr_t id;
    647  1.30     rmind 	int fd, error;
    648   1.1  christos 
    649  1.51  christos 	error = name_copyin(semname, &name);
    650  1.30     rmind 	if (error) {
    651  1.30     rmind 		return error;
    652  1.30     rmind 	}
    653  1.30     rmind 	error = fd_allocfile(&fp, &fd);
    654  1.30     rmind 	if (error) {
    655  1.51  christos 		name_destroy(&name);
    656  1.30     rmind 		return error;
    657  1.30     rmind 	}
    658  1.30     rmind 	fp->f_type = DTYPE_SEM;
    659  1.30     rmind 	fp->f_flag = FREAD | FWRITE;
    660  1.30     rmind 	fp->f_ops = &semops;
    661  1.30     rmind 
    662  1.52   thorpej 	if (fd >= KSEM_MARKER_MIN) {
    663  1.52   thorpej 		/*
    664  1.52   thorpej 		 * This is super-unlikely, but we check for it anyway
    665  1.52   thorpej 		 * because potential collisions with the pshared marker
    666  1.52   thorpej 		 * would be bad.
    667  1.52   thorpej 		 */
    668  1.52   thorpej 		fd_abort(p, fp, fd);
    669  1.52   thorpej 		return EMFILE;
    670  1.52   thorpej 	}
    671  1.52   thorpej 
    672  1.30     rmind 	/*
    673  1.30     rmind 	 * The ID (file descriptor number) can be stored early.
    674  1.30     rmind 	 * Note that zero is a special value for libpthread.
    675  1.30     rmind 	 */
    676  1.30     rmind 	id = (intptr_t)fd;
    677  1.30     rmind 	error = (*docopyout)(&id, idp, sizeof(*idp));
    678  1.30     rmind 	if (error) {
    679  1.30     rmind 		goto err;
    680  1.30     rmind 	}
    681  1.30     rmind 
    682  1.30     rmind 	if (oflag & O_CREAT) {
    683  1.30     rmind 		/* Create a new semaphore. */
    684  1.30     rmind 		error = ksem_create(l, name, &ksnew, mode, value);
    685  1.30     rmind 		if (error) {
    686  1.30     rmind 			goto err;
    687  1.30     rmind 		}
    688  1.30     rmind 		KASSERT(ksnew != NULL);
    689  1.30     rmind 	}
    690   1.1  christos 
    691  1.30     rmind 	/* Lookup for a semaphore with such name. */
    692  1.30     rmind 	mutex_enter(&ksem_lock);
    693  1.30     rmind 	ks = ksem_lookup(name);
    694  1.51  christos 	name_destroy(&name);
    695  1.30     rmind 	if (ks) {
    696  1.30     rmind 		KASSERT(mutex_owned(&ks->ks_lock));
    697  1.30     rmind 		mutex_exit(&ksem_lock);
    698   1.3   thorpej 
    699   1.3   thorpej 		/* Check for exclusive create. */
    700  1.13      cube 		if (oflag & O_EXCL) {
    701  1.30     rmind 			mutex_exit(&ks->ks_lock);
    702  1.30     rmind 			error = EEXIST;
    703  1.30     rmind 			goto err;
    704   1.1  christos 		}
    705   1.1  christos 		/*
    706  1.30     rmind 		 * Verify permissions.  If we can access it,
    707  1.30     rmind 		 * add the reference of this thread.
    708   1.1  christos 		 */
    709  1.15        ad 		error = ksem_perm(l, ks);
    710  1.30     rmind 		if (error == 0) {
    711  1.30     rmind 			ks->ks_ref++;
    712  1.30     rmind 		}
    713  1.30     rmind 		mutex_exit(&ks->ks_lock);
    714   1.1  christos 		if (error) {
    715  1.30     rmind 			goto err;
    716  1.30     rmind 		}
    717  1.30     rmind 	} else {
    718  1.30     rmind 		/* Fail if not found and not creating. */
    719  1.30     rmind 		if ((oflag & O_CREAT) == 0) {
    720  1.30     rmind 			mutex_exit(&ksem_lock);
    721  1.30     rmind 			KASSERT(ksnew == NULL);
    722  1.31     rmind 			error = ENOENT;
    723  1.31     rmind 			goto err;
    724   1.1  christos 		}
    725   1.3   thorpej 
    726  1.30     rmind 		/* Check for the limit locked. */
    727  1.30     rmind 		if (nsems >= ksem_max) {
    728  1.30     rmind 			mutex_exit(&ksem_lock);
    729  1.30     rmind 			error = ENFILE;
    730  1.30     rmind 			goto err;
    731  1.30     rmind 		}
    732   1.3   thorpej 
    733  1.30     rmind 		/*
    734  1.32     rmind 		 * Finally, insert semaphore into the list.
    735  1.30     rmind 		 * Note: it already has the initial reference.
    736  1.30     rmind 		 */
    737  1.30     rmind 		ks = ksnew;
    738  1.30     rmind 		LIST_INSERT_HEAD(&ksem_head, ks, ks_entry);
    739  1.30     rmind 		nsems++;
    740  1.30     rmind 		mutex_exit(&ksem_lock);
    741  1.30     rmind 
    742  1.30     rmind 		ksnew = NULL;
    743  1.30     rmind 	}
    744  1.30     rmind 	KASSERT(ks != NULL);
    745  1.42      matt 	fp->f_ksem = ks;
    746  1.30     rmind 	fd_affix(p, fp, fd);
    747  1.30     rmind err:
    748  1.51  christos 	name_destroy(&name);
    749  1.30     rmind 	if (error) {
    750  1.30     rmind 		fd_abort(p, fp, fd);
    751   1.3   thorpej 	}
    752  1.30     rmind 	if (ksnew) {
    753  1.30     rmind 		ksem_free(ksnew);
    754   1.1  christos 	}
    755  1.30     rmind 	return error;
    756  1.30     rmind }
    757   1.1  christos 
    758  1.30     rmind int
    759  1.30     rmind sys__ksem_close(struct lwp *l, const struct sys__ksem_close_args *uap,
    760  1.30     rmind     register_t *retval)
    761  1.30     rmind {
    762  1.30     rmind 	/* {
    763  1.30     rmind 		intptr_t id;
    764  1.30     rmind 	} */
    765  1.52   thorpej 	intptr_t id = SCARG(uap, id);
    766  1.52   thorpej 	int fd, error;
    767  1.52   thorpej 	ksem_t *ks;
    768  1.52   thorpej 
    769  1.52   thorpej 	error = ksem_get(id, &ks, &fd);
    770  1.52   thorpej 	if (error) {
    771  1.52   thorpej 		return error;
    772  1.52   thorpej 	}
    773  1.33     rmind 
    774  1.52   thorpej 	/* This is only for named semaphores. */
    775  1.52   thorpej 	if (ks->ks_name == NULL) {
    776  1.52   thorpej 		error = EINVAL;
    777  1.52   thorpej 	}
    778  1.52   thorpej 	ksem_release(ks, -1);
    779  1.52   thorpej 	if (error) {
    780  1.52   thorpej 		if (fd != -1)
    781  1.52   thorpej 			fd_putfile(fd);
    782  1.52   thorpej 		return error;
    783  1.33     rmind 	}
    784  1.33     rmind 	return fd_close(fd);
    785   1.1  christos }
    786   1.1  christos 
    787  1.30     rmind static int
    788  1.39  christos ksem_read_fop(file_t *fp, off_t *offset, struct uio *uio, kauth_cred_t cred,
    789  1.39  christos     int flags)
    790  1.39  christos {
    791  1.39  christos 	size_t len;
    792  1.39  christos 	char *name;
    793  1.42      matt 	ksem_t *ks = fp->f_ksem;
    794  1.39  christos 
    795  1.39  christos 	mutex_enter(&ks->ks_lock);
    796  1.39  christos 	len = ks->ks_namelen;
    797  1.39  christos 	name = ks->ks_name;
    798  1.39  christos 	mutex_exit(&ks->ks_lock);
    799  1.39  christos 	if (name == NULL || len == 0)
    800  1.39  christos 		return 0;
    801  1.39  christos 	return uiomove(name, len, uio);
    802  1.39  christos }
    803  1.39  christos 
    804  1.39  christos static int
    805  1.39  christos ksem_stat_fop(file_t *fp, struct stat *ub)
    806  1.39  christos {
    807  1.42      matt 	ksem_t *ks = fp->f_ksem;
    808  1.39  christos 
    809  1.39  christos 	mutex_enter(&ks->ks_lock);
    810  1.39  christos 
    811  1.39  christos 	memset(ub, 0, sizeof(*ub));
    812  1.39  christos 
    813  1.39  christos 	ub->st_mode = ks->ks_mode | ((ks->ks_name && ks->ks_namelen)
    814  1.39  christos 	    ? _S_IFLNK : _S_IFREG);
    815  1.39  christos 	ub->st_uid = ks->ks_uid;
    816  1.39  christos 	ub->st_gid = ks->ks_gid;
    817  1.39  christos 	ub->st_size = ks->ks_value;
    818  1.39  christos 	ub->st_blocks = (ub->st_size) ? 1 : 0;
    819  1.39  christos 	ub->st_nlink = ks->ks_ref;
    820  1.39  christos 	ub->st_blksize = 4096;
    821  1.39  christos 
    822  1.39  christos 	nanotime(&ub->st_atimespec);
    823  1.39  christos 	ub->st_mtimespec = ub->st_ctimespec = ub->st_birthtimespec =
    824  1.39  christos 	    ub->st_atimespec;
    825  1.39  christos 
    826  1.39  christos 	/*
    827  1.39  christos 	 * Left as 0: st_dev, st_ino, st_rdev, st_flags, st_gen.
    828  1.39  christos 	 * XXX (st_dev, st_ino) should be unique.
    829  1.39  christos 	 */
    830  1.39  christos 	mutex_exit(&ks->ks_lock);
    831  1.39  christos 	return 0;
    832  1.39  christos }
    833  1.39  christos 
    834  1.39  christos static int
    835  1.30     rmind ksem_close_fop(file_t *fp)
    836   1.1  christos {
    837  1.42      matt 	ksem_t *ks = fp->f_ksem;
    838   1.1  christos 
    839  1.53   thorpej 	mutex_enter(&ks->ks_lock);
    840  1.53   thorpej 
    841  1.53   thorpej 	if (ks->ks_pshared_id) {
    842  1.53   thorpej 		if (ks->ks_pshared_proc != curproc) {
    843  1.53   thorpej 			/* Do nothing if this is not the creator. */
    844  1.53   thorpej 			mutex_exit(&ks->ks_lock);
    845  1.53   thorpej 			return 0;
    846  1.53   thorpej 		}
    847  1.53   thorpej 		/* Mark this semaphore as dead. */
    848  1.53   thorpej 		ks->ks_pshared_proc = NULL;
    849   1.1  christos 	}
    850   1.3   thorpej 
    851  1.52   thorpej 	ksem_release(ks, -1);
    852  1.30     rmind 	return 0;
    853   1.1  christos }
    854   1.1  christos 
    855   1.1  christos int
    856  1.30     rmind sys__ksem_unlink(struct lwp *l, const struct sys__ksem_unlink_args *uap,
    857  1.30     rmind     register_t *retval)
    858   1.1  christos {
    859  1.23       dsl 	/* {
    860   1.1  christos 		const char *name;
    861  1.23       dsl 	} */
    862  1.51  christos 	char *name;
    863  1.30     rmind 	ksem_t *ks;
    864  1.30     rmind 	u_int refcnt;
    865   1.1  christos 	int error;
    866   1.1  christos 
    867  1.51  christos 	error = name_copyin(SCARG(uap, name), &name);
    868   1.1  christos 	if (error)
    869   1.1  christos 		return error;
    870   1.1  christos 
    871  1.30     rmind 	mutex_enter(&ksem_lock);
    872  1.30     rmind 	ks = ksem_lookup(name);
    873  1.51  christos 	name_destroy(&name);
    874   1.3   thorpej 	if (ks == NULL) {
    875  1.30     rmind 		mutex_exit(&ksem_lock);
    876  1.30     rmind 		return ENOENT;
    877   1.1  christos 	}
    878  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    879   1.3   thorpej 
    880  1.30     rmind 	/* Verify permissions. */
    881  1.30     rmind 	error = ksem_perm(l, ks);
    882  1.30     rmind 	if (error) {
    883  1.30     rmind 		mutex_exit(&ks->ks_lock);
    884  1.30     rmind 		mutex_exit(&ksem_lock);
    885  1.30     rmind 		return error;
    886  1.30     rmind 	}
    887   1.3   thorpej 
    888  1.31     rmind 	/* Remove from the global list. */
    889   1.3   thorpej 	LIST_REMOVE(ks, ks_entry);
    890  1.30     rmind 	nsems--;
    891  1.31     rmind 	mutex_exit(&ksem_lock);
    892   1.3   thorpej 
    893  1.30     rmind 	refcnt = ks->ks_ref;
    894  1.30     rmind 	if (refcnt) {
    895  1.30     rmind 		/* Mark as unlinked, if there are references. */
    896  1.30     rmind 		ks->ks_flags |= KS_UNLINKED;
    897  1.30     rmind 	}
    898  1.30     rmind 	mutex_exit(&ks->ks_lock);
    899   1.3   thorpej 
    900  1.30     rmind 	if (refcnt == 0) {
    901   1.3   thorpej 		ksem_free(ks);
    902  1.30     rmind 	}
    903  1.30     rmind 	return 0;
    904   1.1  christos }
    905   1.1  christos 
    906   1.1  christos int
    907  1.30     rmind sys__ksem_post(struct lwp *l, const struct sys__ksem_post_args *uap,
    908  1.30     rmind     register_t *retval)
    909   1.1  christos {
    910  1.23       dsl 	/* {
    911  1.29        ad 		intptr_t id;
    912  1.23       dsl 	} */
    913  1.52   thorpej 	int fd, error;
    914  1.30     rmind 	ksem_t *ks;
    915   1.1  christos 
    916  1.52   thorpej 	error = ksem_get(SCARG(uap, id), &ks, &fd);
    917  1.30     rmind 	if (error) {
    918  1.30     rmind 		return error;
    919   1.3   thorpej 	}
    920  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    921   1.1  christos 	if (ks->ks_value == SEM_VALUE_MAX) {
    922   1.1  christos 		error = EOVERFLOW;
    923   1.3   thorpej 		goto out;
    924   1.1  christos 	}
    925  1.30     rmind 	ks->ks_value++;
    926  1.30     rmind 	if (ks->ks_waiters) {
    927  1.20        ad 		cv_broadcast(&ks->ks_cv);
    928  1.30     rmind 	}
    929  1.30     rmind out:
    930  1.52   thorpej 	ksem_release(ks, fd);
    931  1.30     rmind 	return error;
    932   1.3   thorpej }
    933   1.3   thorpej 
    934  1.36     joerg int
    935  1.41      matt do_ksem_wait(lwp_t *l, intptr_t id, bool try_p, struct timespec *abstime)
    936   1.3   thorpej {
    937  1.52   thorpej 	int fd, error, timeo;
    938  1.30     rmind 	ksem_t *ks;
    939   1.3   thorpej 
    940  1.52   thorpej 	error = ksem_get(id, &ks, &fd);
    941  1.30     rmind 	if (error) {
    942  1.30     rmind 		return error;
    943  1.30     rmind 	}
    944  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
    945   1.3   thorpej 	while (ks->ks_value == 0) {
    946   1.3   thorpej 		ks->ks_waiters++;
    947  1.41      matt 		if (!try_p && abstime != NULL) {
    948  1.40  christos 			error = ts2timo(CLOCK_REALTIME, TIMER_ABSTIME, abstime,
    949  1.40  christos 			    &timeo, NULL);
    950  1.36     joerg 			if (error != 0)
    951  1.36     joerg 				goto out;
    952  1.36     joerg 		} else {
    953  1.36     joerg 			timeo = 0;
    954  1.36     joerg 		}
    955  1.41      matt 		error = try_p ? EAGAIN : cv_timedwait_sig(&ks->ks_cv,
    956  1.36     joerg 		    &ks->ks_lock, timeo);
    957   1.3   thorpej 		ks->ks_waiters--;
    958   1.3   thorpej 		if (error)
    959   1.3   thorpej 			goto out;
    960   1.3   thorpej 	}
    961   1.3   thorpej 	ks->ks_value--;
    962  1.30     rmind out:
    963  1.52   thorpej 	ksem_release(ks, fd);
    964  1.30     rmind 	return error;
    965   1.1  christos }
    966   1.1  christos 
    967   1.1  christos int
    968  1.30     rmind sys__ksem_wait(struct lwp *l, const struct sys__ksem_wait_args *uap,
    969  1.30     rmind     register_t *retval)
    970   1.1  christos {
    971  1.23       dsl 	/* {
    972  1.29        ad 		intptr_t id;
    973  1.23       dsl 	} */
    974   1.1  christos 
    975  1.36     joerg 	return do_ksem_wait(l, SCARG(uap, id), false, NULL);
    976  1.36     joerg }
    977  1.36     joerg 
    978  1.36     joerg int
    979  1.36     joerg sys__ksem_timedwait(struct lwp *l, const struct sys__ksem_timedwait_args *uap,
    980  1.36     joerg     register_t *retval)
    981  1.36     joerg {
    982  1.36     joerg 	/* {
    983  1.36     joerg 		intptr_t id;
    984  1.36     joerg 		const struct timespec *abstime;
    985  1.36     joerg 	} */
    986  1.36     joerg 	struct timespec ts;
    987  1.36     joerg 	int error;
    988  1.36     joerg 
    989  1.36     joerg 	error = copyin(SCARG(uap, abstime), &ts, sizeof(ts));
    990  1.36     joerg 	if (error != 0)
    991  1.36     joerg 		return error;
    992  1.36     joerg 
    993  1.36     joerg 	if (ts.tv_sec < 0 || ts.tv_nsec < 0 || ts.tv_nsec >= 1000000000)
    994  1.36     joerg 		return EINVAL;
    995  1.36     joerg 
    996  1.36     joerg 	error = do_ksem_wait(l, SCARG(uap, id), false, &ts);
    997  1.36     joerg 	if (error == EWOULDBLOCK)
    998  1.36     joerg 		error = ETIMEDOUT;
    999  1.36     joerg 	return error;
   1000   1.1  christos }
   1001   1.1  christos 
   1002   1.1  christos int
   1003  1.30     rmind sys__ksem_trywait(struct lwp *l, const struct sys__ksem_trywait_args *uap,
   1004  1.30     rmind     register_t *retval)
   1005   1.1  christos {
   1006  1.23       dsl 	/* {
   1007  1.29        ad 		intptr_t id;
   1008  1.23       dsl 	} */
   1009   1.1  christos 
   1010  1.36     joerg 	return do_ksem_wait(l, SCARG(uap, id), true, NULL);
   1011   1.1  christos }
   1012   1.1  christos 
   1013   1.1  christos int
   1014  1.30     rmind sys__ksem_getvalue(struct lwp *l, const struct sys__ksem_getvalue_args *uap,
   1015  1.30     rmind     register_t *retval)
   1016   1.1  christos {
   1017  1.23       dsl 	/* {
   1018  1.29        ad 		intptr_t id;
   1019   1.1  christos 		unsigned int *value;
   1020  1.23       dsl 	} */
   1021  1.52   thorpej 	int fd, error;
   1022  1.30     rmind 	ksem_t *ks;
   1023   1.1  christos 	unsigned int val;
   1024   1.1  christos 
   1025  1.52   thorpej 	error = ksem_get(SCARG(uap, id), &ks, &fd);
   1026  1.30     rmind 	if (error) {
   1027  1.30     rmind 		return error;
   1028  1.30     rmind 	}
   1029  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
   1030   1.1  christos 	val = ks->ks_value;
   1031  1.52   thorpej 	ksem_release(ks, fd);
   1032   1.3   thorpej 
   1033  1.30     rmind 	return copyout(&val, SCARG(uap, value), sizeof(val));
   1034   1.1  christos }
   1035   1.1  christos 
   1036   1.1  christos int
   1037  1.30     rmind sys__ksem_destroy(struct lwp *l, const struct sys__ksem_destroy_args *uap,
   1038  1.30     rmind     register_t *retval)
   1039   1.1  christos {
   1040  1.23       dsl 	/* {
   1041  1.29        ad 		intptr_t id;
   1042  1.23       dsl 	} */
   1043  1.52   thorpej 	int fd, error;
   1044  1.30     rmind 	ksem_t *ks;
   1045   1.1  christos 
   1046  1.52   thorpej 	intptr_t id = SCARG(uap, id);
   1047  1.52   thorpej 
   1048  1.52   thorpej 	error = ksem_get(id, &ks, &fd);
   1049  1.30     rmind 	if (error) {
   1050  1.30     rmind 		return error;
   1051   1.3   thorpej 	}
   1052  1.30     rmind 	KASSERT(mutex_owned(&ks->ks_lock));
   1053   1.3   thorpej 
   1054  1.30     rmind 	/* Operation is only for unnamed semaphores. */
   1055   1.3   thorpej 	if (ks->ks_name != NULL) {
   1056  1.30     rmind 		error = EINVAL;
   1057  1.30     rmind 		goto out;
   1058   1.3   thorpej 	}
   1059  1.30     rmind 	/* Cannot destroy if there are waiters. */
   1060   1.3   thorpej 	if (ks->ks_waiters) {
   1061  1.30     rmind 		error = EBUSY;
   1062  1.30     rmind 		goto out;
   1063   1.3   thorpej 	}
   1064  1.52   thorpej 	if (KSEM_ID_IS_PSHARED(id)) {
   1065  1.52   thorpej 		/* Cannot destroy if we did't create it. */
   1066  1.52   thorpej 		KASSERT(fd == -1);
   1067  1.52   thorpej 		KASSERT(ks->ks_pshared_proc != NULL);
   1068  1.52   thorpej 		if (ks->ks_pshared_proc != curproc) {
   1069  1.52   thorpej 			error = EINVAL;
   1070  1.52   thorpej 			goto out;
   1071  1.52   thorpej 		}
   1072  1.52   thorpej 		fd = ks->ks_pshared_fd;
   1073  1.52   thorpej 
   1074  1.52   thorpej 		/* Mark it dead so subsequent lookups fail. */
   1075  1.52   thorpej 		ks->ks_pshared_proc = NULL;
   1076  1.52   thorpej 
   1077  1.52   thorpej 		/* Do an fd_getfile() to for the benefit of fd_close(). */
   1078  1.52   thorpej 		file_t *fp __diagused = fd_getfile(fd);
   1079  1.52   thorpej 		KASSERT(fp != NULL);
   1080  1.52   thorpej 		KASSERT(fp->f_ksem == ks);
   1081  1.52   thorpej 	}
   1082  1.30     rmind out:
   1083  1.52   thorpej 	ksem_release(ks, -1);
   1084  1.30     rmind 	if (error) {
   1085  1.52   thorpej 		if (!KSEM_ID_IS_PSHARED(id))
   1086  1.52   thorpej 			fd_putfile(fd);
   1087  1.27        ad 		return error;
   1088  1.27        ad 	}
   1089  1.32     rmind 	return fd_close(fd);
   1090  1.22     rmind }
   1091