Home | History | Annotate | Line # | Download | only in uvm
uvm_glue.c revision 1.102
      1 /*	$NetBSD: uvm_glue.c,v 1.102 2007/02/21 23:00:13 thorpej Exp $	*/
      2 
      3 /*
      4  * Copyright (c) 1997 Charles D. Cranor and Washington University.
      5  * Copyright (c) 1991, 1993, The Regents of the University of California.
      6  *
      7  * All rights reserved.
      8  *
      9  * This code is derived from software contributed to Berkeley by
     10  * The Mach Operating System project at Carnegie-Mellon University.
     11  *
     12  * Redistribution and use in source and binary forms, with or without
     13  * modification, are permitted provided that the following conditions
     14  * are met:
     15  * 1. Redistributions of source code must retain the above copyright
     16  *    notice, this list of conditions and the following disclaimer.
     17  * 2. Redistributions in binary form must reproduce the above copyright
     18  *    notice, this list of conditions and the following disclaimer in the
     19  *    documentation and/or other materials provided with the distribution.
     20  * 3. All advertising materials mentioning features or use of this software
     21  *    must display the following acknowledgement:
     22  *	This product includes software developed by Charles D. Cranor,
     23  *      Washington University, the University of California, Berkeley and
     24  *      its contributors.
     25  * 4. Neither the name of the University nor the names of its contributors
     26  *    may be used to endorse or promote products derived from this software
     27  *    without specific prior written permission.
     28  *
     29  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     30  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     31  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     32  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     33  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     34  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     35  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     36  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     37  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     38  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     39  * SUCH DAMAGE.
     40  *
     41  *	@(#)vm_glue.c	8.6 (Berkeley) 1/5/94
     42  * from: Id: uvm_glue.c,v 1.1.2.8 1998/02/07 01:16:54 chs Exp
     43  *
     44  *
     45  * Copyright (c) 1987, 1990 Carnegie-Mellon University.
     46  * All rights reserved.
     47  *
     48  * Permission to use, copy, modify and distribute this software and
     49  * its documentation is hereby granted, provided that both the copyright
     50  * notice and this permission notice appear in all copies of the
     51  * software, derivative works or modified versions, and any portions
     52  * thereof, and that both notices appear in supporting documentation.
     53  *
     54  * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
     55  * CONDITION.  CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND
     56  * FOR ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
     57  *
     58  * Carnegie Mellon requests users of this software to return to
     59  *
     60  *  Software Distribution Coordinator  or  Software.Distribution (at) CS.CMU.EDU
     61  *  School of Computer Science
     62  *  Carnegie Mellon University
     63  *  Pittsburgh PA 15213-3890
     64  *
     65  * any improvements or extensions that they make and grant Carnegie the
     66  * rights to redistribute these changes.
     67  */
     68 
     69 #include <sys/cdefs.h>
     70 __KERNEL_RCSID(0, "$NetBSD: uvm_glue.c,v 1.102 2007/02/21 23:00:13 thorpej Exp $");
     71 
     72 #include "opt_coredump.h"
     73 #include "opt_kgdb.h"
     74 #include "opt_kstack.h"
     75 #include "opt_uvmhist.h"
     76 
     77 /*
     78  * uvm_glue.c: glue functions
     79  */
     80 
     81 #include <sys/param.h>
     82 #include <sys/systm.h>
     83 #include <sys/proc.h>
     84 #include <sys/resourcevar.h>
     85 #include <sys/buf.h>
     86 #include <sys/user.h>
     87 
     88 #include <uvm/uvm.h>
     89 
     90 #include <machine/cpu.h>
     91 
     92 /*
     93  * local prototypes
     94  */
     95 
     96 static void uvm_swapout(struct lwp *);
     97 
     98 #define UVM_NUAREA_MAX 16
     99 static vaddr_t uvm_uareas;
    100 static int uvm_nuarea;
    101 static struct simplelock uvm_uareas_slock = SIMPLELOCK_INITIALIZER;
    102 #define	UAREA_NEXTFREE(uarea)	(*(vaddr_t *)(UAREA_TO_USER(uarea)))
    103 
    104 static void uvm_uarea_free(vaddr_t);
    105 
    106 /*
    107  * XXXCDC: do these really belong here?
    108  */
    109 
    110 /*
    111  * uvm_kernacc: can the kernel access a region of memory
    112  *
    113  * - used only by /dev/kmem driver (mem.c)
    114  */
    115 
    116 bool
    117 uvm_kernacc(caddr_t addr, size_t len, int rw)
    118 {
    119 	bool rv;
    120 	vaddr_t saddr, eaddr;
    121 	vm_prot_t prot = rw == B_READ ? VM_PROT_READ : VM_PROT_WRITE;
    122 
    123 	saddr = trunc_page((vaddr_t)addr);
    124 	eaddr = round_page((vaddr_t)addr + len);
    125 	vm_map_lock_read(kernel_map);
    126 	rv = uvm_map_checkprot(kernel_map, saddr, eaddr, prot);
    127 	vm_map_unlock_read(kernel_map);
    128 
    129 	return(rv);
    130 }
    131 
    132 #ifdef KGDB
    133 /*
    134  * Change protections on kernel pages from addr to addr+len
    135  * (presumably so debugger can plant a breakpoint).
    136  *
    137  * We force the protection change at the pmap level.  If we were
    138  * to use vm_map_protect a change to allow writing would be lazily-
    139  * applied meaning we would still take a protection fault, something
    140  * we really don't want to do.  It would also fragment the kernel
    141  * map unnecessarily.  We cannot use pmap_protect since it also won't
    142  * enforce a write-enable request.  Using pmap_enter is the only way
    143  * we can ensure the change takes place properly.
    144  */
    145 void
    146 uvm_chgkprot(caddr_t addr, size_t len, int rw)
    147 {
    148 	vm_prot_t prot;
    149 	paddr_t pa;
    150 	vaddr_t sva, eva;
    151 
    152 	prot = rw == B_READ ? VM_PROT_READ : VM_PROT_READ|VM_PROT_WRITE;
    153 	eva = round_page((vaddr_t)addr + len);
    154 	for (sva = trunc_page((vaddr_t)addr); sva < eva; sva += PAGE_SIZE) {
    155 		/*
    156 		 * Extract physical address for the page.
    157 		 */
    158 		if (pmap_extract(pmap_kernel(), sva, &pa) == FALSE)
    159 			panic("chgkprot: invalid page");
    160 		pmap_enter(pmap_kernel(), sva, pa, prot, PMAP_WIRED);
    161 	}
    162 	pmap_update(pmap_kernel());
    163 }
    164 #endif
    165 
    166 /*
    167  * uvm_vslock: wire user memory for I/O
    168  *
    169  * - called from physio and sys___sysctl
    170  * - XXXCDC: consider nuking this (or making it a macro?)
    171  */
    172 
    173 int
    174 uvm_vslock(struct vmspace *vs, void *addr, size_t len, vm_prot_t access_type)
    175 {
    176 	struct vm_map *map;
    177 	vaddr_t start, end;
    178 	int error;
    179 
    180 	map = &vs->vm_map;
    181 	start = trunc_page((vaddr_t)addr);
    182 	end = round_page((vaddr_t)addr + len);
    183 	error = uvm_fault_wire(map, start, end, access_type, 0);
    184 	return error;
    185 }
    186 
    187 /*
    188  * uvm_vsunlock: unwire user memory wired by uvm_vslock()
    189  *
    190  * - called from physio and sys___sysctl
    191  * - XXXCDC: consider nuking this (or making it a macro?)
    192  */
    193 
    194 void
    195 uvm_vsunlock(struct vmspace *vs, void *addr, size_t len)
    196 {
    197 	uvm_fault_unwire(&vs->vm_map, trunc_page((vaddr_t)addr),
    198 		round_page((vaddr_t)addr + len));
    199 }
    200 
    201 /*
    202  * uvm_proc_fork: fork a virtual address space
    203  *
    204  * - the address space is copied as per parent map's inherit values
    205  */
    206 void
    207 uvm_proc_fork(struct proc *p1, struct proc *p2, bool shared)
    208 {
    209 
    210 	if (shared == TRUE) {
    211 		p2->p_vmspace = NULL;
    212 		uvmspace_share(p1, p2);
    213 	} else {
    214 		p2->p_vmspace = uvmspace_fork(p1->p_vmspace);
    215 	}
    216 
    217 	cpu_proc_fork(p1, p2);
    218 }
    219 
    220 
    221 /*
    222  * uvm_lwp_fork: fork a thread
    223  *
    224  * - a new "user" structure is allocated for the child process
    225  *	[filled in by MD layer...]
    226  * - if specified, the child gets a new user stack described by
    227  *	stack and stacksize
    228  * - NOTE: the kernel stack may be at a different location in the child
    229  *	process, and thus addresses of automatic variables may be invalid
    230  *	after cpu_lwp_fork returns in the child process.  We do nothing here
    231  *	after cpu_lwp_fork returns.
    232  * - XXXCDC: we need a way for this to return a failure value rather
    233  *   than just hang
    234  */
    235 void
    236 uvm_lwp_fork(struct lwp *l1, struct lwp *l2, void *stack, size_t stacksize,
    237     void (*func)(void *), void *arg)
    238 {
    239 	int error;
    240 
    241 	/*
    242 	 * Wire down the U-area for the process, which contains the PCB
    243 	 * and the kernel stack.  Wired state is stored in l->l_flag's
    244 	 * L_INMEM bit rather than in the vm_map_entry's wired count
    245 	 * to prevent kernel_map fragmentation.  If we reused a cached U-area,
    246 	 * L_INMEM will already be set and we don't need to do anything.
    247 	 *
    248 	 * Note the kernel stack gets read/write accesses right off the bat.
    249 	 */
    250 
    251 	if ((l2->l_flag & LW_INMEM) == 0) {
    252 		vaddr_t uarea = USER_TO_UAREA(l2->l_addr);
    253 
    254 		error = uvm_fault_wire(kernel_map, uarea,
    255 		    uarea + USPACE, VM_PROT_READ | VM_PROT_WRITE, 0);
    256 		if (error)
    257 			panic("uvm_lwp_fork: uvm_fault_wire failed: %d", error);
    258 #ifdef PMAP_UAREA
    259 		/* Tell the pmap this is a u-area mapping */
    260 		PMAP_UAREA(uarea);
    261 #endif
    262 		l2->l_flag |= LW_INMEM;
    263 	}
    264 
    265 #ifdef KSTACK_CHECK_MAGIC
    266 	/*
    267 	 * fill stack with magic number
    268 	 */
    269 	kstack_setup_magic(l2);
    270 #endif
    271 
    272 	/*
    273 	 * cpu_lwp_fork() copy and update the pcb, and make the child ready
    274  	 * to run.  If this is a normal user fork, the child will exit
    275 	 * directly to user mode via child_return() on its first time
    276 	 * slice and will not return here.  If this is a kernel thread,
    277 	 * the specified entry point will be executed.
    278 	 */
    279 	cpu_lwp_fork(l1, l2, stack, stacksize, func, arg);
    280 }
    281 
    282 /*
    283  * uvm_uarea_alloc: allocate a u-area
    284  */
    285 
    286 bool
    287 uvm_uarea_alloc(vaddr_t *uaddrp)
    288 {
    289 	vaddr_t uaddr;
    290 
    291 #ifndef USPACE_ALIGN
    292 #define USPACE_ALIGN    0
    293 #endif
    294 
    295 	simple_lock(&uvm_uareas_slock);
    296 	if (uvm_nuarea > 0) {
    297 		uaddr = uvm_uareas;
    298 		uvm_uareas = UAREA_NEXTFREE(uaddr);
    299 		uvm_nuarea--;
    300 		simple_unlock(&uvm_uareas_slock);
    301 		*uaddrp = uaddr;
    302 		return TRUE;
    303 	} else {
    304 		simple_unlock(&uvm_uareas_slock);
    305 		*uaddrp = uvm_km_alloc(kernel_map, USPACE, USPACE_ALIGN,
    306 		    UVM_KMF_PAGEABLE);
    307 		return FALSE;
    308 	}
    309 }
    310 
    311 /*
    312  * uvm_uarea_free: free a u-area; never blocks
    313  */
    314 
    315 static inline void
    316 uvm_uarea_free(vaddr_t uaddr)
    317 {
    318 	simple_lock(&uvm_uareas_slock);
    319 	UAREA_NEXTFREE(uaddr) = uvm_uareas;
    320 	uvm_uareas = uaddr;
    321 	uvm_nuarea++;
    322 	simple_unlock(&uvm_uareas_slock);
    323 }
    324 
    325 /*
    326  * uvm_uarea_drain: return memory of u-areas over limit
    327  * back to system
    328  */
    329 
    330 void
    331 uvm_uarea_drain(bool empty)
    332 {
    333 	int leave = empty ? 0 : UVM_NUAREA_MAX;
    334 	vaddr_t uaddr;
    335 
    336 	if (uvm_nuarea <= leave)
    337 		return;
    338 
    339 	simple_lock(&uvm_uareas_slock);
    340 	while(uvm_nuarea > leave) {
    341 		uaddr = uvm_uareas;
    342 		uvm_uareas = UAREA_NEXTFREE(uaddr);
    343 		uvm_nuarea--;
    344 		simple_unlock(&uvm_uareas_slock);
    345 		uvm_km_free(kernel_map, uaddr, USPACE, UVM_KMF_PAGEABLE);
    346 		simple_lock(&uvm_uareas_slock);
    347 	}
    348 	simple_unlock(&uvm_uareas_slock);
    349 }
    350 
    351 /*
    352  * uvm_exit: exit a virtual address space
    353  *
    354  * - the process passed to us is a dead (pre-zombie) process; we
    355  *   are running on a different context now (the reaper).
    356  * - borrow proc0's address space because freeing the vmspace
    357  *   of the dead process may block.
    358  */
    359 
    360 void
    361 uvm_proc_exit(struct proc *p)
    362 {
    363 	struct lwp *l = curlwp; /* XXX */
    364 	struct vmspace *ovm;
    365 
    366 	KASSERT(p == l->l_proc);
    367 	ovm = p->p_vmspace;
    368 
    369 	/*
    370 	 * borrow proc0's address space.
    371 	 */
    372 	pmap_deactivate(l);
    373 	p->p_vmspace = proc0.p_vmspace;
    374 	pmap_activate(l);
    375 
    376 	uvmspace_free(ovm);
    377 }
    378 
    379 void
    380 uvm_lwp_exit(struct lwp *l)
    381 {
    382 	vaddr_t va = USER_TO_UAREA(l->l_addr);
    383 
    384 	l->l_flag &= ~LW_INMEM;
    385 	uvm_uarea_free(va);
    386 	l->l_addr = NULL;
    387 }
    388 
    389 /*
    390  * uvm_init_limit: init per-process VM limits
    391  *
    392  * - called for process 0 and then inherited by all others.
    393  */
    394 
    395 void
    396 uvm_init_limits(struct proc *p)
    397 {
    398 
    399 	/*
    400 	 * Set up the initial limits on process VM.  Set the maximum
    401 	 * resident set size to be all of (reasonably) available memory.
    402 	 * This causes any single, large process to start random page
    403 	 * replacement once it fills memory.
    404 	 */
    405 
    406 	p->p_rlimit[RLIMIT_STACK].rlim_cur = DFLSSIZ;
    407 	p->p_rlimit[RLIMIT_STACK].rlim_max = maxsmap;
    408 	p->p_rlimit[RLIMIT_DATA].rlim_cur = DFLDSIZ;
    409 	p->p_rlimit[RLIMIT_DATA].rlim_max = maxdmap;
    410 	p->p_rlimit[RLIMIT_RSS].rlim_cur = ptoa(uvmexp.free);
    411 }
    412 
    413 #ifdef DEBUG
    414 int	enableswap = 1;
    415 int	swapdebug = 0;
    416 #define	SDB_FOLLOW	1
    417 #define SDB_SWAPIN	2
    418 #define SDB_SWAPOUT	4
    419 #endif
    420 
    421 /*
    422  * uvm_swapin: swap in an lwp's u-area.
    423  */
    424 
    425 void
    426 uvm_swapin(struct lwp *l)
    427 {
    428 	vaddr_t addr;
    429 	int error;
    430 
    431 	addr = USER_TO_UAREA(l->l_addr);
    432 	/* make L_INMEM true */
    433 	error = uvm_fault_wire(kernel_map, addr, addr + USPACE,
    434 	    VM_PROT_READ | VM_PROT_WRITE, 0);
    435 	if (error) {
    436 		panic("uvm_swapin: rewiring stack failed: %d", error);
    437 	}
    438 
    439 	/*
    440 	 * Some architectures need to be notified when the user area has
    441 	 * moved to new physical page(s) (e.g.  see mips/mips/vm_machdep.c).
    442 	 */
    443 	cpu_swapin(l);
    444 	lwp_lock(l);
    445 	if (l->l_stat == LSRUN)
    446 		setrunqueue(l);
    447 	l->l_flag |= LW_INMEM;
    448 	l->l_swtime = 0;
    449 	lwp_unlock(l);
    450 	++uvmexp.swapins;
    451 }
    452 
    453 /*
    454  * uvm_kick_scheduler: kick the scheduler into action if not running.
    455  *
    456  * - called when swapped out processes have been awoken.
    457  */
    458 
    459 void
    460 uvm_kick_scheduler(void)
    461 {
    462 
    463 	if (uvm.swap_running == FALSE)
    464 		return;
    465 
    466 	mutex_enter(&uvm.scheduler_mutex);
    467 	uvm.scheduler_kicked = TRUE;
    468 	cv_signal(&uvm.scheduler_cv);
    469 	mutex_exit(&uvm.scheduler_mutex);
    470 }
    471 
    472 /*
    473  * uvm_scheduler: process zero main loop
    474  *
    475  * - attempt to swapin every swaped-out, runnable process in order of
    476  *	priority.
    477  * - if not enough memory, wake the pagedaemon and let it clear space.
    478  */
    479 
    480 void
    481 uvm_scheduler(void)
    482 {
    483 	struct lwp *l, *ll;
    484 	int pri;
    485 	int ppri;
    486 
    487 	l = curlwp;
    488 	lwp_lock(l);
    489 	lwp_changepri(l, PVM);
    490 	lwp_unlock(l);
    491 
    492 	for (;;) {
    493 #ifdef DEBUG
    494 		mutex_enter(&uvm.scheduler_mutex);
    495 		while (!enableswap)
    496 			cv_wait(&uvm.scheduler_cv, &uvm.scheduler_mutex);
    497 		mutex_exit(&uvm.scheduler_mutex);
    498 #endif
    499 		ll = NULL;		/* process to choose */
    500 		ppri = INT_MIN;		/* its priority */
    501 
    502 		mutex_enter(&proclist_mutex);
    503 		LIST_FOREACH(l, &alllwp, l_list) {
    504 			/* is it a runnable swapped out process? */
    505 			if (l->l_stat == LSRUN && !(l->l_flag & LW_INMEM)) {
    506 				pri = l->l_swtime + l->l_slptime -
    507 				    (l->l_proc->p_nice - NZERO) * 8;
    508 				if (pri > ppri) {   /* higher priority? */
    509 					ll = l;
    510 					ppri = pri;
    511 				}
    512 			}
    513 		}
    514 		mutex_exit(&proclist_mutex);
    515 #ifdef DEBUG
    516 		if (swapdebug & SDB_FOLLOW)
    517 			printf("scheduler: running, procp %p pri %d\n", ll,
    518 			    ppri);
    519 #endif
    520 		/*
    521 		 * Nothing to do, back to sleep
    522 		 */
    523 		if ((l = ll) == NULL) {
    524 			mutex_enter(&uvm.scheduler_mutex);
    525 			if (uvm.scheduler_kicked == FALSE)
    526 				cv_wait(&uvm.scheduler_cv,
    527 				    &uvm.scheduler_mutex);
    528 			uvm.scheduler_kicked = FALSE;
    529 			mutex_exit(&uvm.scheduler_mutex);
    530 			continue;
    531 		}
    532 
    533 		/*
    534 		 * we have found swapped out process which we would like
    535 		 * to bring back in.
    536 		 *
    537 		 * XXX: this part is really bogus cuz we could deadlock
    538 		 * on memory despite our feeble check
    539 		 */
    540 		if (uvmexp.free > atop(USPACE)) {
    541 #ifdef DEBUG
    542 			if (swapdebug & SDB_SWAPIN)
    543 				printf("swapin: pid %d(%s)@%p, pri %d "
    544 				    "free %d\n", l->l_proc->p_pid,
    545 				    l->l_proc->p_comm, l->l_addr, ppri,
    546 				    uvmexp.free);
    547 #endif
    548 			uvm_swapin(l);
    549 		} else {
    550 			/*
    551 			 * not enough memory, jab the pageout daemon and
    552 			 * wait til the coast is clear
    553 			 */
    554 #ifdef DEBUG
    555 			if (swapdebug & SDB_FOLLOW)
    556 				printf("scheduler: no room for pid %d(%s),"
    557 				    " free %d\n", l->l_proc->p_pid,
    558 				    l->l_proc->p_comm, uvmexp.free);
    559 #endif
    560 			uvm_wait("schedpwait");
    561 #ifdef DEBUG
    562 			if (swapdebug & SDB_FOLLOW)
    563 				printf("scheduler: room again, free %d\n",
    564 				    uvmexp.free);
    565 #endif
    566 		}
    567 	}
    568 }
    569 
    570 /*
    571  * swappable: is LWP "l" swappable?
    572  */
    573 
    574 #define	swappable(l)							\
    575 	(((l)->l_flag & (LW_INMEM)) &&					\
    576 	 ((((l)->l_flag) & (LW_SYSTEM | LW_WEXIT)) == 0) &&		\
    577 	 (l)->l_holdcnt == 0)
    578 
    579 /*
    580  * swapout_threads: find threads that can be swapped and unwire their
    581  *	u-areas.
    582  *
    583  * - called by the pagedaemon
    584  * - try and swap at least one processs
    585  * - processes that are sleeping or stopped for maxslp or more seconds
    586  *   are swapped... otherwise the longest-sleeping or stopped process
    587  *   is swapped, otherwise the longest resident process...
    588  */
    589 
    590 void
    591 uvm_swapout_threads(void)
    592 {
    593 	struct lwp *l;
    594 	struct lwp *outl, *outl2;
    595 	int outpri, outpri2;
    596 	int didswap = 0;
    597 	extern int maxslp;
    598 	/* XXXCDC: should move off to uvmexp. or uvm., also in uvm_meter */
    599 
    600 #ifdef DEBUG
    601 	if (!enableswap)
    602 		return;
    603 #endif
    604 
    605 	/*
    606 	 * outl/outpri  : stop/sleep thread with largest sleeptime < maxslp
    607 	 * outl2/outpri2: the longest resident thread (its swap time)
    608 	 */
    609 	outl = outl2 = NULL;
    610 	outpri = outpri2 = 0;
    611 	mutex_enter(&proclist_mutex);	/* XXXSMP */
    612 	LIST_FOREACH(l, &alllwp, l_list) {
    613 		KASSERT(l->l_proc != NULL);
    614 		lwp_lock(l);
    615 		if (!swappable(l)) {
    616 			lwp_unlock(l);
    617 			continue;
    618 		}
    619 		switch (l->l_stat) {
    620 		case LSONPROC:
    621 			break;
    622 
    623 		case LSRUN:
    624 			if (l->l_swtime > outpri2) {
    625 				outl2 = l;
    626 				outpri2 = l->l_swtime;
    627 			}
    628 			break;
    629 
    630 		case LSSLEEP:
    631 		case LSSTOP:
    632 			if (l->l_slptime >= maxslp) {
    633 				/* uvm_swapout() will release the lock. */
    634 				uvm_swapout(l);
    635 				didswap++;
    636 				continue;
    637 			} else if (l->l_slptime > outpri) {
    638 				outl = l;
    639 				outpri = l->l_slptime;
    640 			}
    641 			break;
    642 		}
    643 		lwp_unlock(l);
    644 	}
    645 	/*
    646 	 * If we didn't get rid of any real duds, toss out the next most
    647 	 * likely sleeping/stopped or running candidate.  We only do this
    648 	 * if we are real low on memory since we don't gain much by doing
    649 	 * it (USPACE bytes).
    650 	 */
    651 	if (didswap == 0 && uvmexp.free <= atop(round_page(USPACE))) {
    652 		if ((l = outl) == NULL)
    653 			l = outl2;
    654 #ifdef DEBUG
    655 		if (swapdebug & SDB_SWAPOUT)
    656 			printf("swapout_threads: no duds, try procp %p\n", l);
    657 #endif
    658 		if (l) {
    659 			/* uvm_swapout() will release the lock. */
    660 			lwp_lock(l);
    661 			uvm_swapout(l);
    662 		}
    663 	}
    664 
    665 	mutex_exit(&proclist_mutex);
    666 
    667 }
    668 
    669 /*
    670  * uvm_swapout: swap out lwp "l"
    671  *
    672  * - currently "swapout" means "unwire U-area" and "pmap_collect()"
    673  *   the pmap.
    674  * - must be called with the LWP locked, and will release the lock.
    675  * - XXXCDC: should deactivate all process' private anonymous memory
    676  */
    677 
    678 static void
    679 uvm_swapout(struct lwp *l)
    680 {
    681 	vaddr_t addr;
    682 	struct proc *p = l->l_proc;
    683 
    684 	LOCK_ASSERT(lwp_locked(l, NULL));
    685 
    686 #ifdef DEBUG
    687 	if (swapdebug & SDB_SWAPOUT)
    688 		printf("swapout: lid %d.%d(%s)@%p, stat %x pri %d free %d\n",
    689 	   p->p_pid, l->l_lid, p->p_comm, l->l_addr, l->l_stat,
    690 	   l->l_slptime, uvmexp.free);
    691 #endif
    692 
    693 	/*
    694 	 * Mark it as (potentially) swapped out.
    695 	 */
    696 	if (l->l_stat == LSONPROC) {
    697 		KDASSERT(l->l_cpu != curcpu());
    698 		lwp_unlock(l);
    699 		return;
    700 	}
    701 	l->l_flag &= ~LW_INMEM;
    702 	l->l_swtime = 0;
    703 	if (l->l_stat == LSRUN)
    704 		remrunqueue(l);
    705 	lwp_unlock(l);
    706 	p->p_stats->p_ru.ru_nswap++;	/* XXXSMP */
    707 	++uvmexp.swapouts;
    708 
    709 	mutex_exit(&proclist_mutex);	/* XXXSMP */
    710 
    711 	/*
    712 	 * Do any machine-specific actions necessary before swapout.
    713 	 * This can include saving floating point state, etc.
    714 	 */
    715 	cpu_swapout(l);
    716 
    717 	/*
    718 	 * Unwire the to-be-swapped process's user struct and kernel stack.
    719 	 */
    720 	addr = USER_TO_UAREA(l->l_addr);
    721 	uvm_fault_unwire(kernel_map, addr, addr + USPACE); /* !L_INMEM */
    722 	pmap_collect(vm_map_pmap(&p->p_vmspace->vm_map));
    723 
    724 	mutex_enter(&proclist_mutex);	/* XXXSMP */
    725 }
    726 
    727 #ifdef COREDUMP
    728 /*
    729  * uvm_coredump_walkmap: walk a process's map for the purpose of dumping
    730  * a core file.
    731  */
    732 
    733 int
    734 uvm_coredump_walkmap(struct proc *p, void *iocookie,
    735     int (*func)(struct proc *, void *, struct uvm_coredump_state *),
    736     void *cookie)
    737 {
    738 	struct uvm_coredump_state state;
    739 	struct vmspace *vm = p->p_vmspace;
    740 	struct vm_map *map = &vm->vm_map;
    741 	struct vm_map_entry *entry;
    742 	int error;
    743 
    744 	entry = NULL;
    745 	vm_map_lock_read(map);
    746 	state.end = 0;
    747 	for (;;) {
    748 		if (entry == NULL)
    749 			entry = map->header.next;
    750 		else if (!uvm_map_lookup_entry(map, state.end, &entry))
    751 			entry = entry->next;
    752 		if (entry == &map->header)
    753 			break;
    754 
    755 		state.cookie = cookie;
    756 		if (state.end > entry->start) {
    757 			state.start = state.end;
    758 		} else {
    759 			state.start = entry->start;
    760 		}
    761 		state.realend = entry->end;
    762 		state.end = entry->end;
    763 		state.prot = entry->protection;
    764 		state.flags = 0;
    765 
    766 		/*
    767 		 * Dump the region unless one of the following is true:
    768 		 *
    769 		 * (1) the region has neither object nor amap behind it
    770 		 *     (ie. it has never been accessed).
    771 		 *
    772 		 * (2) the region has no amap and is read-only
    773 		 *     (eg. an executable text section).
    774 		 *
    775 		 * (3) the region's object is a device.
    776 		 *
    777 		 * (4) the region is unreadable by the process.
    778 		 */
    779 
    780 		KASSERT(!UVM_ET_ISSUBMAP(entry));
    781 		KASSERT(state.start < VM_MAXUSER_ADDRESS);
    782 		KASSERT(state.end <= VM_MAXUSER_ADDRESS);
    783 		if (entry->object.uvm_obj == NULL &&
    784 		    entry->aref.ar_amap == NULL) {
    785 			state.realend = state.start;
    786 		} else if ((entry->protection & VM_PROT_WRITE) == 0 &&
    787 		    entry->aref.ar_amap == NULL) {
    788 			state.realend = state.start;
    789 		} else if (entry->object.uvm_obj != NULL &&
    790 		    UVM_OBJ_IS_DEVICE(entry->object.uvm_obj)) {
    791 			state.realend = state.start;
    792 		} else if ((entry->protection & VM_PROT_READ) == 0) {
    793 			state.realend = state.start;
    794 		} else {
    795 			if (state.start >= (vaddr_t)vm->vm_maxsaddr)
    796 				state.flags |= UVM_COREDUMP_STACK;
    797 
    798 			/*
    799 			 * If this an anonymous entry, only dump instantiated
    800 			 * pages.
    801 			 */
    802 			if (entry->object.uvm_obj == NULL) {
    803 				vaddr_t end;
    804 
    805 				amap_lock(entry->aref.ar_amap);
    806 				for (end = state.start;
    807 				     end < state.end; end += PAGE_SIZE) {
    808 					struct vm_anon *anon;
    809 					anon = amap_lookup(&entry->aref,
    810 					    end - entry->start);
    811 					/*
    812 					 * If we have already encountered an
    813 					 * uninstantiated page, stop at the
    814 					 * first instantied page.
    815 					 */
    816 					if (anon != NULL &&
    817 					    state.realend != state.end) {
    818 						state.end = end;
    819 						break;
    820 					}
    821 
    822 					/*
    823 					 * If this page is the first
    824 					 * uninstantiated page, mark this as
    825 					 * the real ending point.  Continue to
    826 					 * counting uninstantiated pages.
    827 					 */
    828 					if (anon == NULL &&
    829 					    state.realend == state.end) {
    830 						state.realend = end;
    831 					}
    832 				}
    833 				amap_unlock(entry->aref.ar_amap);
    834 			}
    835 		}
    836 
    837 
    838 		vm_map_unlock_read(map);
    839 		error = (*func)(p, iocookie, &state);
    840 		if (error)
    841 			return (error);
    842 		vm_map_lock_read(map);
    843 	}
    844 	vm_map_unlock_read(map);
    845 
    846 	return (0);
    847 }
    848 #endif /* COREDUMP */
    849