xref: /netbsd-src/sys/uvm/uvm_glue.c (revision cac8e449158efc7261bebc8657cbb0125a2cfdde)
1 /*	$NetBSD: uvm_glue.c,v 1.133 2008/06/25 19:20:56 ad Exp $	*/
2 
3 /*
4  * Copyright (c) 1997 Charles D. Cranor and Washington University.
5  * Copyright (c) 1991, 1993, The Regents of the University of California.
6  *
7  * All rights reserved.
8  *
9  * This code is derived from software contributed to Berkeley by
10  * The Mach Operating System project at Carnegie-Mellon University.
11  *
12  * Redistribution and use in source and binary forms, with or without
13  * modification, are permitted provided that the following conditions
14  * are met:
15  * 1. Redistributions of source code must retain the above copyright
16  *    notice, this list of conditions and the following disclaimer.
17  * 2. Redistributions in binary form must reproduce the above copyright
18  *    notice, this list of conditions and the following disclaimer in the
19  *    documentation and/or other materials provided with the distribution.
20  * 3. All advertising materials mentioning features or use of this software
21  *    must display the following acknowledgement:
22  *	This product includes software developed by Charles D. Cranor,
23  *      Washington University, the University of California, Berkeley and
24  *      its contributors.
25  * 4. Neither the name of the University nor the names of its contributors
26  *    may be used to endorse or promote products derived from this software
27  *    without specific prior written permission.
28  *
29  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
30  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
31  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
32  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
33  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
34  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
35  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
36  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
37  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
38  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
39  * SUCH DAMAGE.
40  *
41  *	@(#)vm_glue.c	8.6 (Berkeley) 1/5/94
42  * from: Id: uvm_glue.c,v 1.1.2.8 1998/02/07 01:16:54 chs Exp
43  *
44  *
45  * Copyright (c) 1987, 1990 Carnegie-Mellon University.
46  * All rights reserved.
47  *
48  * Permission to use, copy, modify and distribute this software and
49  * its documentation is hereby granted, provided that both the copyright
50  * notice and this permission notice appear in all copies of the
51  * software, derivative works or modified versions, and any portions
52  * thereof, and that both notices appear in supporting documentation.
53  *
54  * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
55  * CONDITION.  CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND
56  * FOR ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
57  *
58  * Carnegie Mellon requests users of this software to return to
59  *
60  *  Software Distribution Coordinator  or  Software.Distribution@CS.CMU.EDU
61  *  School of Computer Science
62  *  Carnegie Mellon University
63  *  Pittsburgh PA 15213-3890
64  *
65  * any improvements or extensions that they make and grant Carnegie the
66  * rights to redistribute these changes.
67  */
68 
69 #include <sys/cdefs.h>
70 __KERNEL_RCSID(0, "$NetBSD: uvm_glue.c,v 1.133 2008/06/25 19:20:56 ad Exp $");
71 
72 #include "opt_coredump.h"
73 #include "opt_kgdb.h"
74 #include "opt_kstack.h"
75 #include "opt_uvmhist.h"
76 
77 /*
78  * uvm_glue.c: glue functions
79  */
80 
81 #include <sys/param.h>
82 #include <sys/systm.h>
83 #include <sys/proc.h>
84 #include <sys/resourcevar.h>
85 #include <sys/buf.h>
86 #include <sys/user.h>
87 #include <sys/syncobj.h>
88 #include <sys/cpu.h>
89 #include <sys/atomic.h>
90 
91 #include <uvm/uvm.h>
92 
93 /*
94  * local prototypes
95  */
96 
97 static void uvm_swapout(struct lwp *);
98 static int uarea_swapin(vaddr_t);
99 
100 /*
101  * XXXCDC: do these really belong here?
102  */
103 
104 /*
105  * uvm_kernacc: can the kernel access a region of memory
106  *
107  * - used only by /dev/kmem driver (mem.c)
108  */
109 
110 bool
111 uvm_kernacc(void *addr, size_t len, int rw)
112 {
113 	bool rv;
114 	vaddr_t saddr, eaddr;
115 	vm_prot_t prot = rw == B_READ ? VM_PROT_READ : VM_PROT_WRITE;
116 
117 	saddr = trunc_page((vaddr_t)addr);
118 	eaddr = round_page((vaddr_t)addr + len);
119 	vm_map_lock_read(kernel_map);
120 	rv = uvm_map_checkprot(kernel_map, saddr, eaddr, prot);
121 	vm_map_unlock_read(kernel_map);
122 
123 	return(rv);
124 }
125 
126 #ifdef KGDB
127 /*
128  * Change protections on kernel pages from addr to addr+len
129  * (presumably so debugger can plant a breakpoint).
130  *
131  * We force the protection change at the pmap level.  If we were
132  * to use vm_map_protect a change to allow writing would be lazily-
133  * applied meaning we would still take a protection fault, something
134  * we really don't want to do.  It would also fragment the kernel
135  * map unnecessarily.  We cannot use pmap_protect since it also won't
136  * enforce a write-enable request.  Using pmap_enter is the only way
137  * we can ensure the change takes place properly.
138  */
139 void
140 uvm_chgkprot(void *addr, size_t len, int rw)
141 {
142 	vm_prot_t prot;
143 	paddr_t pa;
144 	vaddr_t sva, eva;
145 
146 	prot = rw == B_READ ? VM_PROT_READ : VM_PROT_READ|VM_PROT_WRITE;
147 	eva = round_page((vaddr_t)addr + len);
148 	for (sva = trunc_page((vaddr_t)addr); sva < eva; sva += PAGE_SIZE) {
149 		/*
150 		 * Extract physical address for the page.
151 		 */
152 		if (pmap_extract(pmap_kernel(), sva, &pa) == false)
153 			panic("%s: invalid page", __func__);
154 		pmap_enter(pmap_kernel(), sva, pa, prot, PMAP_WIRED);
155 	}
156 	pmap_update(pmap_kernel());
157 }
158 #endif
159 
160 /*
161  * uvm_vslock: wire user memory for I/O
162  *
163  * - called from physio and sys___sysctl
164  * - XXXCDC: consider nuking this (or making it a macro?)
165  */
166 
167 int
168 uvm_vslock(struct vmspace *vs, void *addr, size_t len, vm_prot_t access_type)
169 {
170 	struct vm_map *map;
171 	vaddr_t start, end;
172 	int error;
173 
174 	map = &vs->vm_map;
175 	start = trunc_page((vaddr_t)addr);
176 	end = round_page((vaddr_t)addr + len);
177 	error = uvm_fault_wire(map, start, end, access_type, 0);
178 	return error;
179 }
180 
181 /*
182  * uvm_vsunlock: unwire user memory wired by uvm_vslock()
183  *
184  * - called from physio and sys___sysctl
185  * - XXXCDC: consider nuking this (or making it a macro?)
186  */
187 
188 void
189 uvm_vsunlock(struct vmspace *vs, void *addr, size_t len)
190 {
191 	uvm_fault_unwire(&vs->vm_map, trunc_page((vaddr_t)addr),
192 		round_page((vaddr_t)addr + len));
193 }
194 
195 /*
196  * uvm_proc_fork: fork a virtual address space
197  *
198  * - the address space is copied as per parent map's inherit values
199  */
200 void
201 uvm_proc_fork(struct proc *p1, struct proc *p2, bool shared)
202 {
203 
204 	if (shared == true) {
205 		p2->p_vmspace = NULL;
206 		uvmspace_share(p1, p2);
207 	} else {
208 		p2->p_vmspace = uvmspace_fork(p1->p_vmspace);
209 	}
210 
211 	cpu_proc_fork(p1, p2);
212 }
213 
214 
215 /*
216  * uvm_lwp_fork: fork a thread
217  *
218  * - a new "user" structure is allocated for the child process
219  *	[filled in by MD layer...]
220  * - if specified, the child gets a new user stack described by
221  *	stack and stacksize
222  * - NOTE: the kernel stack may be at a different location in the child
223  *	process, and thus addresses of automatic variables may be invalid
224  *	after cpu_lwp_fork returns in the child process.  We do nothing here
225  *	after cpu_lwp_fork returns.
226  * - XXXCDC: we need a way for this to return a failure value rather
227  *   than just hang
228  */
229 void
230 uvm_lwp_fork(struct lwp *l1, struct lwp *l2, void *stack, size_t stacksize,
231     void (*func)(void *), void *arg)
232 {
233 	int error;
234 
235 	/*
236 	 * Wire down the U-area for the process, which contains the PCB
237 	 * and the kernel stack.  Wired state is stored in l->l_flag's
238 	 * L_INMEM bit rather than in the vm_map_entry's wired count
239 	 * to prevent kernel_map fragmentation.  If we reused a cached U-area,
240 	 * L_INMEM will already be set and we don't need to do anything.
241 	 *
242 	 * Note the kernel stack gets read/write accesses right off the bat.
243 	 */
244 
245 	if ((l2->l_flag & LW_INMEM) == 0) {
246 		vaddr_t uarea = USER_TO_UAREA(l2->l_addr);
247 
248 		if ((error = uarea_swapin(uarea)) != 0)
249 			panic("%s: uvm_fault_wire failed: %d", __func__, error);
250 #ifdef PMAP_UAREA
251 		/* Tell the pmap this is a u-area mapping */
252 		PMAP_UAREA(uarea);
253 #endif
254 		l2->l_flag |= LW_INMEM;
255 	}
256 
257 #ifdef KSTACK_CHECK_MAGIC
258 	/*
259 	 * fill stack with magic number
260 	 */
261 	kstack_setup_magic(l2);
262 #endif
263 
264 	/*
265 	 * cpu_lwp_fork() copy and update the pcb, and make the child ready
266  	 * to run.  If this is a normal user fork, the child will exit
267 	 * directly to user mode via child_return() on its first time
268 	 * slice and will not return here.  If this is a kernel thread,
269 	 * the specified entry point will be executed.
270 	 */
271 	cpu_lwp_fork(l1, l2, stack, stacksize, func, arg);
272 }
273 
274 static int
275 uarea_swapin(vaddr_t addr)
276 {
277 
278 	return uvm_fault_wire(kernel_map, addr, addr + USPACE,
279 	    VM_PROT_READ | VM_PROT_WRITE, 0);
280 }
281 
282 static void
283 uarea_swapout(vaddr_t addr)
284 {
285 
286 	uvm_fault_unwire(kernel_map, addr, addr + USPACE);
287 }
288 
289 #ifndef USPACE_ALIGN
290 #define	USPACE_ALIGN	0
291 #endif
292 
293 static pool_cache_t uvm_uarea_cache;
294 
295 static int
296 uarea_ctor(void *arg, void *obj, int flags)
297 {
298 
299 	KASSERT((flags & PR_WAITOK) != 0);
300 	return uarea_swapin((vaddr_t)obj);
301 }
302 
303 static void *
304 uarea_poolpage_alloc(struct pool *pp, int flags)
305 {
306 
307 	return (void *)uvm_km_alloc(kernel_map, pp->pr_alloc->pa_pagesz,
308 	    USPACE_ALIGN, UVM_KMF_PAGEABLE |
309 	    ((flags & PR_WAITOK) != 0 ? UVM_KMF_WAITVA :
310 	    (UVM_KMF_NOWAIT | UVM_KMF_TRYLOCK)));
311 }
312 
313 static void
314 uarea_poolpage_free(struct pool *pp, void *addr)
315 {
316 
317 	uvm_km_free(kernel_map, (vaddr_t)addr, pp->pr_alloc->pa_pagesz,
318 	    UVM_KMF_PAGEABLE);
319 }
320 
321 static struct pool_allocator uvm_uarea_allocator = {
322 	.pa_alloc = uarea_poolpage_alloc,
323 	.pa_free = uarea_poolpage_free,
324 	.pa_pagesz = USPACE,
325 };
326 
327 void
328 uvm_uarea_init(void)
329 {
330 	int flags = PR_NOTOUCH;
331 
332 	/*
333 	 * specify PR_NOALIGN unless the alignment provided by
334 	 * the backend (USPACE_ALIGN) is sufficient to provide
335 	 * pool page size (UPSACE) alignment.
336 	 */
337 
338 	if ((USPACE_ALIGN == 0 && USPACE != PAGE_SIZE) ||
339 	    (USPACE_ALIGN % USPACE) != 0) {
340 		flags |= PR_NOALIGN;
341 	}
342 
343 	uvm_uarea_cache = pool_cache_init(USPACE, USPACE_ALIGN, 0, flags,
344 	    "uarea", &uvm_uarea_allocator, IPL_NONE, uarea_ctor, NULL, NULL);
345 }
346 
347 /*
348  * uvm_uarea_alloc: allocate a u-area
349  */
350 
351 bool
352 uvm_uarea_alloc(vaddr_t *uaddrp)
353 {
354 
355 	*uaddrp = (vaddr_t)pool_cache_get(uvm_uarea_cache, PR_WAITOK);
356 	return true;
357 }
358 
359 /*
360  * uvm_uarea_free: free a u-area
361  */
362 
363 void
364 uvm_uarea_free(vaddr_t uaddr, struct cpu_info *ci)
365 {
366 
367 	pool_cache_put(uvm_uarea_cache, (void *)uaddr);
368 }
369 
370 /*
371  * uvm_proc_exit: exit a virtual address space
372  *
373  * - borrow proc0's address space because freeing the vmspace
374  *   of the dead process may block.
375  */
376 
377 void
378 uvm_proc_exit(struct proc *p)
379 {
380 	struct lwp *l = curlwp; /* XXX */
381 	struct vmspace *ovm;
382 
383 	KASSERT(p == l->l_proc);
384 	ovm = p->p_vmspace;
385 
386 	/*
387 	 * borrow proc0's address space.
388 	 */
389 	KPREEMPT_DISABLE(l);
390 	pmap_deactivate(l);
391 	p->p_vmspace = proc0.p_vmspace;
392 	pmap_activate(l);
393 	KPREEMPT_ENABLE(l);
394 
395 	uvmspace_free(ovm);
396 }
397 
398 void
399 uvm_lwp_exit(struct lwp *l)
400 {
401 	vaddr_t va = USER_TO_UAREA(l->l_addr);
402 
403 	l->l_flag &= ~LW_INMEM;
404 	uvm_uarea_free(va, l->l_cpu);
405 	l->l_addr = NULL;
406 }
407 
408 /*
409  * uvm_init_limit: init per-process VM limits
410  *
411  * - called for process 0 and then inherited by all others.
412  */
413 
414 void
415 uvm_init_limits(struct proc *p)
416 {
417 
418 	/*
419 	 * Set up the initial limits on process VM.  Set the maximum
420 	 * resident set size to be all of (reasonably) available memory.
421 	 * This causes any single, large process to start random page
422 	 * replacement once it fills memory.
423 	 */
424 
425 	p->p_rlimit[RLIMIT_STACK].rlim_cur = DFLSSIZ;
426 	p->p_rlimit[RLIMIT_STACK].rlim_max = maxsmap;
427 	p->p_rlimit[RLIMIT_DATA].rlim_cur = DFLDSIZ;
428 	p->p_rlimit[RLIMIT_DATA].rlim_max = maxdmap;
429 	p->p_rlimit[RLIMIT_RSS].rlim_cur = ptoa(uvmexp.free);
430 }
431 
432 #ifdef DEBUG
433 int	enableswap = 1;
434 int	swapdebug = 0;
435 #define	SDB_FOLLOW	1
436 #define SDB_SWAPIN	2
437 #define SDB_SWAPOUT	4
438 #endif
439 
440 /*
441  * uvm_swapin: swap in an lwp's u-area.
442  *
443  * - must be called with the LWP's swap lock held.
444  * - naturally, must not be called with l == curlwp
445  */
446 
447 void
448 uvm_swapin(struct lwp *l)
449 {
450 	int error;
451 
452 	/* XXXSMP notyet KASSERT(mutex_owned(&l->l_swaplock)); */
453 	KASSERT(l != curlwp);
454 
455 	error = uarea_swapin(USER_TO_UAREA(l->l_addr));
456 	if (error) {
457 		panic("%s: rewiring stack failed: %d", __func__, error);
458 	}
459 
460 	/*
461 	 * Some architectures need to be notified when the user area has
462 	 * moved to new physical page(s) (e.g.  see mips/mips/vm_machdep.c).
463 	 */
464 	cpu_swapin(l);
465 	lwp_lock(l);
466 	if (l->l_stat == LSRUN)
467 		sched_enqueue(l, false);
468 	l->l_flag |= LW_INMEM;
469 	l->l_swtime = 0;
470 	lwp_unlock(l);
471 	++uvmexp.swapins;
472 }
473 
474 /*
475  * uvm_kick_scheduler: kick the scheduler into action if not running.
476  *
477  * - called when swapped out processes have been awoken.
478  */
479 
480 void
481 uvm_kick_scheduler(void)
482 {
483 
484 	if (uvm.swap_running == false)
485 		return;
486 
487 	mutex_enter(&uvm_scheduler_mutex);
488 	uvm.scheduler_kicked = true;
489 	cv_signal(&uvm.scheduler_cv);
490 	mutex_exit(&uvm_scheduler_mutex);
491 }
492 
493 /*
494  * uvm_scheduler: process zero main loop
495  *
496  * - attempt to swapin every swaped-out, runnable process in order of
497  *	priority.
498  * - if not enough memory, wake the pagedaemon and let it clear space.
499  */
500 
501 void
502 uvm_scheduler(void)
503 {
504 	struct lwp *l, *ll;
505 	int pri;
506 	int ppri;
507 
508 	l = curlwp;
509 	lwp_lock(l);
510 	l->l_priority = PRI_VM;
511 	l->l_class = SCHED_FIFO;
512 	lwp_unlock(l);
513 
514 	for (;;) {
515 #ifdef DEBUG
516 		mutex_enter(&uvm_scheduler_mutex);
517 		while (!enableswap)
518 			cv_wait(&uvm.scheduler_cv, &uvm_scheduler_mutex);
519 		mutex_exit(&uvm_scheduler_mutex);
520 #endif
521 		ll = NULL;		/* process to choose */
522 		ppri = INT_MIN;		/* its priority */
523 
524 		mutex_enter(proc_lock);
525 		LIST_FOREACH(l, &alllwp, l_list) {
526 			/* is it a runnable swapped out process? */
527 			if (l->l_stat == LSRUN && !(l->l_flag & LW_INMEM)) {
528 				pri = l->l_swtime + l->l_slptime -
529 				    (l->l_proc->p_nice - NZERO) * 8;
530 				if (pri > ppri) {   /* higher priority? */
531 					ll = l;
532 					ppri = pri;
533 				}
534 			}
535 		}
536 #ifdef DEBUG
537 		if (swapdebug & SDB_FOLLOW)
538 			printf("%s: running, procp %p pri %d\n", __func__, ll,
539 			    ppri);
540 #endif
541 		/*
542 		 * Nothing to do, back to sleep
543 		 */
544 		if ((l = ll) == NULL) {
545 			mutex_exit(proc_lock);
546 			mutex_enter(&uvm_scheduler_mutex);
547 			if (uvm.scheduler_kicked == false)
548 				cv_wait(&uvm.scheduler_cv,
549 				    &uvm_scheduler_mutex);
550 			uvm.scheduler_kicked = false;
551 			mutex_exit(&uvm_scheduler_mutex);
552 			continue;
553 		}
554 
555 		/*
556 		 * we have found swapped out process which we would like
557 		 * to bring back in.
558 		 *
559 		 * XXX: this part is really bogus cuz we could deadlock
560 		 * on memory despite our feeble check
561 		 */
562 		if (uvmexp.free > atop(USPACE)) {
563 #ifdef DEBUG
564 			if (swapdebug & SDB_SWAPIN)
565 				printf("swapin: pid %d(%s)@%p, pri %d "
566 				    "free %d\n", l->l_proc->p_pid,
567 				    l->l_proc->p_comm, l->l_addr, ppri,
568 				    uvmexp.free);
569 #endif
570 			mutex_enter(&l->l_swaplock);
571 			mutex_exit(proc_lock);
572 			uvm_swapin(l);
573 			mutex_exit(&l->l_swaplock);
574 			continue;
575 		} else {
576 			/*
577 			 * not enough memory, jab the pageout daemon and
578 			 * wait til the coast is clear
579 			 */
580 			mutex_exit(proc_lock);
581 #ifdef DEBUG
582 			if (swapdebug & SDB_FOLLOW)
583 				printf("%s: no room for pid %d(%s),"
584 				    " free %d\n", __func__, l->l_proc->p_pid,
585 				    l->l_proc->p_comm, uvmexp.free);
586 #endif
587 			uvm_wait("schedpwait");
588 #ifdef DEBUG
589 			if (swapdebug & SDB_FOLLOW)
590 				printf("%s: room again, free %d\n", __func__,
591 				    uvmexp.free);
592 #endif
593 		}
594 	}
595 }
596 
597 /*
598  * swappable: is LWP "l" swappable?
599  */
600 
601 static bool
602 swappable(struct lwp *l)
603 {
604 
605 	if ((l->l_flag & (LW_INMEM|LW_SYSTEM|LW_WEXIT)) != LW_INMEM)
606 		return false;
607 	if ((l->l_pflag & LP_RUNNING) != 0)
608 		return false;
609 	if (l->l_holdcnt != 0)
610 		return false;
611 	if (l->l_class != SCHED_OTHER)
612 		return false;
613 	if (l->l_syncobj == &rw_syncobj || l->l_syncobj == &mutex_syncobj)
614 		return false;
615 	if (l->l_proc->p_stat != SACTIVE && l->l_proc->p_stat != SSTOP)
616 		return false;
617 	return true;
618 }
619 
620 /*
621  * swapout_threads: find threads that can be swapped and unwire their
622  *	u-areas.
623  *
624  * - called by the pagedaemon
625  * - try and swap at least one processs
626  * - processes that are sleeping or stopped for maxslp or more seconds
627  *   are swapped... otherwise the longest-sleeping or stopped process
628  *   is swapped, otherwise the longest resident process...
629  */
630 
631 void
632 uvm_swapout_threads(void)
633 {
634 	struct lwp *l;
635 	struct lwp *outl, *outl2;
636 	int outpri, outpri2;
637 	int didswap = 0;
638 	extern int maxslp;
639 	bool gotit;
640 
641 	/* XXXCDC: should move off to uvmexp. or uvm., also in uvm_meter */
642 
643 #ifdef DEBUG
644 	if (!enableswap)
645 		return;
646 #endif
647 
648 	/*
649 	 * outl/outpri  : stop/sleep thread with largest sleeptime < maxslp
650 	 * outl2/outpri2: the longest resident thread (its swap time)
651 	 */
652 	outl = outl2 = NULL;
653 	outpri = outpri2 = 0;
654 
655  restart:
656 	mutex_enter(proc_lock);
657 	LIST_FOREACH(l, &alllwp, l_list) {
658 		KASSERT(l->l_proc != NULL);
659 		if (!mutex_tryenter(&l->l_swaplock))
660 			continue;
661 		if (!swappable(l)) {
662 			mutex_exit(&l->l_swaplock);
663 			continue;
664 		}
665 		switch (l->l_stat) {
666 		case LSONPROC:
667 			break;
668 
669 		case LSRUN:
670 			if (l->l_swtime > outpri2) {
671 				outl2 = l;
672 				outpri2 = l->l_swtime;
673 			}
674 			break;
675 
676 		case LSSLEEP:
677 		case LSSTOP:
678 			if (l->l_slptime >= maxslp) {
679 				mutex_exit(proc_lock);
680 				uvm_swapout(l);
681 				/*
682 				 * Locking in the wrong direction -
683 				 * try to prevent the LWP from exiting.
684 				 */
685 				gotit = mutex_tryenter(proc_lock);
686 				mutex_exit(&l->l_swaplock);
687 				didswap++;
688 				if (!gotit)
689 					goto restart;
690 				continue;
691 			} else if (l->l_slptime > outpri) {
692 				outl = l;
693 				outpri = l->l_slptime;
694 			}
695 			break;
696 		}
697 		mutex_exit(&l->l_swaplock);
698 	}
699 
700 	/*
701 	 * If we didn't get rid of any real duds, toss out the next most
702 	 * likely sleeping/stopped or running candidate.  We only do this
703 	 * if we are real low on memory since we don't gain much by doing
704 	 * it (USPACE bytes).
705 	 */
706 	if (didswap == 0 && uvmexp.free <= atop(round_page(USPACE))) {
707 		if ((l = outl) == NULL)
708 			l = outl2;
709 #ifdef DEBUG
710 		if (swapdebug & SDB_SWAPOUT)
711 			printf("%s: no duds, try procp %p\n", __func__, l);
712 #endif
713 		if (l) {
714 			mutex_enter(&l->l_swaplock);
715 			mutex_exit(proc_lock);
716 			if (swappable(l))
717 				uvm_swapout(l);
718 			mutex_exit(&l->l_swaplock);
719 			return;
720 		}
721 	}
722 
723 	mutex_exit(proc_lock);
724 }
725 
726 /*
727  * uvm_swapout: swap out lwp "l"
728  *
729  * - currently "swapout" means "unwire U-area" and "pmap_collect()"
730  *   the pmap.
731  * - must be called with l->l_swaplock held.
732  * - XXXCDC: should deactivate all process' private anonymous memory
733  */
734 
735 static void
736 uvm_swapout(struct lwp *l)
737 {
738 	struct vm_map *map;
739 
740 	KASSERT(mutex_owned(&l->l_swaplock));
741 
742 #ifdef DEBUG
743 	if (swapdebug & SDB_SWAPOUT)
744 		printf("%s: lid %d.%d(%s)@%p, stat %x pri %d free %d\n",
745 		   __func__, l->l_proc->p_pid, l->l_lid, l->l_proc->p_comm,
746 		   l->l_addr, l->l_stat, l->l_slptime, uvmexp.free);
747 #endif
748 
749 	/*
750 	 * Mark it as (potentially) swapped out.
751 	 */
752 	lwp_lock(l);
753 	if (!swappable(l)) {
754 		KDASSERT(l->l_cpu != curcpu());
755 		lwp_unlock(l);
756 		return;
757 	}
758 	l->l_flag &= ~LW_INMEM;
759 	l->l_swtime = 0;
760 	if (l->l_stat == LSRUN)
761 		sched_dequeue(l);
762 	lwp_unlock(l);
763 	l->l_ru.ru_nswap++;
764 	++uvmexp.swapouts;
765 
766 	/*
767 	 * Do any machine-specific actions necessary before swapout.
768 	 * This can include saving floating point state, etc.
769 	 */
770 	cpu_swapout(l);
771 
772 	/*
773 	 * Unwire the to-be-swapped process's user struct and kernel stack.
774 	 */
775 	uarea_swapout(USER_TO_UAREA(l->l_addr));
776 	map = &l->l_proc->p_vmspace->vm_map;
777 	if (vm_map_lock_try(map)) {
778 		pmap_collect(vm_map_pmap(map));
779 		vm_map_unlock(map);
780 	}
781 }
782 
783 /*
784  * uvm_lwp_hold: prevent lwp "l" from being swapped out, and bring
785  * back into memory if it is currently swapped.
786  */
787 
788 void
789 uvm_lwp_hold(struct lwp *l)
790 {
791 
792 	if (l == curlwp) {
793 		atomic_inc_uint(&l->l_holdcnt);
794 	} else {
795 		mutex_enter(&l->l_swaplock);
796 		if (atomic_inc_uint_nv(&l->l_holdcnt) == 1 &&
797 		    (l->l_flag & LW_INMEM) == 0)
798 			uvm_swapin(l);
799 		mutex_exit(&l->l_swaplock);
800 	}
801 }
802 
803 /*
804  * uvm_lwp_rele: release a hold on lwp "l".  when the holdcount
805  * drops to zero, it's eligable to be swapped.
806  */
807 
808 void
809 uvm_lwp_rele(struct lwp *l)
810 {
811 
812 	KASSERT(l->l_holdcnt != 0);
813 
814 	atomic_dec_uint(&l->l_holdcnt);
815 }
816 
817 #ifdef COREDUMP
818 /*
819  * uvm_coredump_walkmap: walk a process's map for the purpose of dumping
820  * a core file.
821  */
822 
823 int
824 uvm_coredump_walkmap(struct proc *p, void *iocookie,
825     int (*func)(struct proc *, void *, struct uvm_coredump_state *),
826     void *cookie)
827 {
828 	struct uvm_coredump_state state;
829 	struct vmspace *vm = p->p_vmspace;
830 	struct vm_map *map = &vm->vm_map;
831 	struct vm_map_entry *entry;
832 	int error;
833 
834 	entry = NULL;
835 	vm_map_lock_read(map);
836 	state.end = 0;
837 	for (;;) {
838 		if (entry == NULL)
839 			entry = map->header.next;
840 		else if (!uvm_map_lookup_entry(map, state.end, &entry))
841 			entry = entry->next;
842 		if (entry == &map->header)
843 			break;
844 
845 		state.cookie = cookie;
846 		if (state.end > entry->start) {
847 			state.start = state.end;
848 		} else {
849 			state.start = entry->start;
850 		}
851 		state.realend = entry->end;
852 		state.end = entry->end;
853 		state.prot = entry->protection;
854 		state.flags = 0;
855 
856 		/*
857 		 * Dump the region unless one of the following is true:
858 		 *
859 		 * (1) the region has neither object nor amap behind it
860 		 *     (ie. it has never been accessed).
861 		 *
862 		 * (2) the region has no amap and is read-only
863 		 *     (eg. an executable text section).
864 		 *
865 		 * (3) the region's object is a device.
866 		 *
867 		 * (4) the region is unreadable by the process.
868 		 */
869 
870 		KASSERT(!UVM_ET_ISSUBMAP(entry));
871 		KASSERT(state.start < VM_MAXUSER_ADDRESS);
872 		KASSERT(state.end <= VM_MAXUSER_ADDRESS);
873 		if (entry->object.uvm_obj == NULL &&
874 		    entry->aref.ar_amap == NULL) {
875 			state.realend = state.start;
876 		} else if ((entry->protection & VM_PROT_WRITE) == 0 &&
877 		    entry->aref.ar_amap == NULL) {
878 			state.realend = state.start;
879 		} else if (entry->object.uvm_obj != NULL &&
880 		    UVM_OBJ_IS_DEVICE(entry->object.uvm_obj)) {
881 			state.realend = state.start;
882 		} else if ((entry->protection & VM_PROT_READ) == 0) {
883 			state.realend = state.start;
884 		} else {
885 			if (state.start >= (vaddr_t)vm->vm_maxsaddr)
886 				state.flags |= UVM_COREDUMP_STACK;
887 
888 			/*
889 			 * If this an anonymous entry, only dump instantiated
890 			 * pages.
891 			 */
892 			if (entry->object.uvm_obj == NULL) {
893 				vaddr_t end;
894 
895 				amap_lock(entry->aref.ar_amap);
896 				for (end = state.start;
897 				     end < state.end; end += PAGE_SIZE) {
898 					struct vm_anon *anon;
899 					anon = amap_lookup(&entry->aref,
900 					    end - entry->start);
901 					/*
902 					 * If we have already encountered an
903 					 * uninstantiated page, stop at the
904 					 * first instantied page.
905 					 */
906 					if (anon != NULL &&
907 					    state.realend != state.end) {
908 						state.end = end;
909 						break;
910 					}
911 
912 					/*
913 					 * If this page is the first
914 					 * uninstantiated page, mark this as
915 					 * the real ending point.  Continue to
916 					 * counting uninstantiated pages.
917 					 */
918 					if (anon == NULL &&
919 					    state.realend == state.end) {
920 						state.realend = end;
921 					}
922 				}
923 				amap_unlock(entry->aref.ar_amap);
924 			}
925 		}
926 
927 
928 		vm_map_unlock_read(map);
929 		error = (*func)(p, iocookie, &state);
930 		if (error)
931 			return (error);
932 		vm_map_lock_read(map);
933 	}
934 	vm_map_unlock_read(map);
935 
936 	return (0);
937 }
938 #endif /* COREDUMP */
939