10Sstevel@tonic-gate /* 20Sstevel@tonic-gate * CDDL HEADER START 30Sstevel@tonic-gate * 40Sstevel@tonic-gate * The contents of this file are subject to the terms of the 52447Snf202958 * Common Development and Distribution License (the "License"). 62447Snf202958 * You may not use this file except in compliance with the License. 70Sstevel@tonic-gate * 80Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 90Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 100Sstevel@tonic-gate * See the License for the specific language governing permissions 110Sstevel@tonic-gate * and limitations under the License. 120Sstevel@tonic-gate * 130Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 140Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 150Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 160Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 170Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 180Sstevel@tonic-gate * 190Sstevel@tonic-gate * CDDL HEADER END 200Sstevel@tonic-gate */ 210Sstevel@tonic-gate /* 22*3684Srd117015 * Copyright 2007 Sun Microsystems, Inc. All rights reserved. 230Sstevel@tonic-gate * Use is subject to license terms. 240Sstevel@tonic-gate */ 250Sstevel@tonic-gate 260Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 270Sstevel@tonic-gate 280Sstevel@tonic-gate #include <sys/atomic.h> 290Sstevel@tonic-gate #include <sys/cmn_err.h> 300Sstevel@tonic-gate #include <sys/id_space.h> 310Sstevel@tonic-gate #include <sys/kmem.h> 323247Sgjelinek #include <sys/kstat.h> 330Sstevel@tonic-gate #include <sys/log.h> 340Sstevel@tonic-gate #include <sys/modctl.h> 350Sstevel@tonic-gate #include <sys/modhash.h> 360Sstevel@tonic-gate #include <sys/mutex.h> 370Sstevel@tonic-gate #include <sys/proc.h> 380Sstevel@tonic-gate #include <sys/procset.h> 390Sstevel@tonic-gate #include <sys/project.h> 400Sstevel@tonic-gate #include <sys/resource.h> 410Sstevel@tonic-gate #include <sys/rctl.h> 420Sstevel@tonic-gate #include <sys/siginfo.h> 430Sstevel@tonic-gate #include <sys/strlog.h> 440Sstevel@tonic-gate #include <sys/systm.h> 450Sstevel@tonic-gate #include <sys/task.h> 460Sstevel@tonic-gate #include <sys/types.h> 470Sstevel@tonic-gate #include <sys/policy.h> 480Sstevel@tonic-gate #include <sys/zone.h> 490Sstevel@tonic-gate 500Sstevel@tonic-gate /* 510Sstevel@tonic-gate * Resource controls (rctls) 520Sstevel@tonic-gate * 530Sstevel@tonic-gate * The rctl subsystem provides a mechanism for kernel components to 540Sstevel@tonic-gate * register their individual resource controls with the system as a whole, 550Sstevel@tonic-gate * such that those controls can subscribe to specific actions while being 560Sstevel@tonic-gate * associated with the various process-model entities provided by the kernel: 570Sstevel@tonic-gate * the process, the task, the project, and the zone. (In principle, only 580Sstevel@tonic-gate * minor modifications would be required to connect the resource control 590Sstevel@tonic-gate * functionality to non-process-model entities associated with the system.) 600Sstevel@tonic-gate * 610Sstevel@tonic-gate * Subsystems register their rctls via rctl_register(). Subsystems 620Sstevel@tonic-gate * also wishing to provide additional limits on a given rctl can modify 630Sstevel@tonic-gate * them once they have the rctl handle. Each subsystem should store the 640Sstevel@tonic-gate * handle to their rctl for direct access. 650Sstevel@tonic-gate * 660Sstevel@tonic-gate * A primary dictionary, rctl_dict, contains a hash of id to the default 670Sstevel@tonic-gate * control definition for each controlled resource-entity pair on the system. 680Sstevel@tonic-gate * A secondary dictionary, rctl_dict_by_name, contains a hash of name to 690Sstevel@tonic-gate * resource control handles. The resource control handles are distributed by 700Sstevel@tonic-gate * the rctl_ids ID space. The handles are private and not to be 710Sstevel@tonic-gate * advertised to userland; all userland interactions are via the rctl 720Sstevel@tonic-gate * names. 730Sstevel@tonic-gate * 740Sstevel@tonic-gate * Entities inherit their rctls from their predecessor. Since projects have 750Sstevel@tonic-gate * no ancestor, they inherit their rctls from the rctl dict for project 760Sstevel@tonic-gate * rctls. It is expected that project controls will be set to their 770Sstevel@tonic-gate * appropriate values shortly after project creation, presumably from a 780Sstevel@tonic-gate * policy source such as the project database. 790Sstevel@tonic-gate * 800Sstevel@tonic-gate * Data structures 810Sstevel@tonic-gate * The rctl_set_t attached to each of the process model entities is a simple 820Sstevel@tonic-gate * hash table keyed on the rctl handle assigned at registration. The entries 830Sstevel@tonic-gate * in the hash table are rctl_t's, whose relationship with the active control 840Sstevel@tonic-gate * values on that resource and with the global state of the resource we 850Sstevel@tonic-gate * illustrate below: 860Sstevel@tonic-gate * 870Sstevel@tonic-gate * rctl_dict[key] --> rctl_dict_entry 880Sstevel@tonic-gate * ^ 890Sstevel@tonic-gate * | 900Sstevel@tonic-gate * +--+---+ 910Sstevel@tonic-gate * rctl_set[key] ---> | rctl | --> value <-> value <-> system value --> NULL 920Sstevel@tonic-gate * +--+---+ ^ 930Sstevel@tonic-gate * | | 940Sstevel@tonic-gate * +------- cursor ------+ 950Sstevel@tonic-gate * 960Sstevel@tonic-gate * That is, the rctl contains a back pointer to the global resource control 970Sstevel@tonic-gate * state for this resource, which is also available in the rctl_dict hash 980Sstevel@tonic-gate * table mentioned earlier. The rctl contains two pointers to resource 990Sstevel@tonic-gate * control values: one, values, indicates the entire sequence of control 1000Sstevel@tonic-gate * values; the other, cursor, indicates the currently active control 1010Sstevel@tonic-gate * value--the next value to be enforced. The value list itself is an open, 1020Sstevel@tonic-gate * doubly-linked list, the last non-NULL member of which is the system value 1030Sstevel@tonic-gate * for that resource (being the theoretical/conventional maximum allowable 1040Sstevel@tonic-gate * value for the resource on this OS instance). 1050Sstevel@tonic-gate * 1060Sstevel@tonic-gate * Ops Vector 1070Sstevel@tonic-gate * Subsystems publishing rctls need not provide instances of all of the 1080Sstevel@tonic-gate * functions specified by the ops vector. In particular, if general 1090Sstevel@tonic-gate * rctl_*() entry points are not being called, certain functions can be 1100Sstevel@tonic-gate * omitted. These align as follows: 1110Sstevel@tonic-gate * 1120Sstevel@tonic-gate * rctl_set() 1130Sstevel@tonic-gate * You may wish to provide a set callback if locking circumstances prevent 1140Sstevel@tonic-gate * it or if the performance cost of requesting the enforced value from the 1150Sstevel@tonic-gate * resource control is prohibitively expensive. For instance, the currently 1160Sstevel@tonic-gate * enforced file size limit is stored on the process in the p_fsz_ctl to 1170Sstevel@tonic-gate * maintain read()/write() performance. 1180Sstevel@tonic-gate * 1190Sstevel@tonic-gate * rctl_test() 1200Sstevel@tonic-gate * You must provide a test callback if you are using the rctl_test() 1210Sstevel@tonic-gate * interface. An action callback is optional. 1220Sstevel@tonic-gate * 1230Sstevel@tonic-gate * rctl_action() 1240Sstevel@tonic-gate * You may wish to provide an action callback. 1250Sstevel@tonic-gate * 1260Sstevel@tonic-gate * Registration 1270Sstevel@tonic-gate * New resource controls can be added to a running instance by loaded modules 1280Sstevel@tonic-gate * via registration. (The current implementation does not support unloadable 1290Sstevel@tonic-gate * modules; this functionality can be added if needed, via an 1300Sstevel@tonic-gate * activation/deactivation interface involving the manipulation of the 1310Sstevel@tonic-gate * ops vector for the resource control(s) needing to support unloading.) 1320Sstevel@tonic-gate * 1330Sstevel@tonic-gate * Control value ordering 1340Sstevel@tonic-gate * Because the rctl_val chain on each rctl must be navigable in a 1350Sstevel@tonic-gate * deterministic way, we have to define an ordering on the rctl_val_t's. The 1360Sstevel@tonic-gate * defined order is (flags & [maximal], value, flags & [deny-action], 1370Sstevel@tonic-gate * privilege). 1380Sstevel@tonic-gate * 1390Sstevel@tonic-gate * Locking 1400Sstevel@tonic-gate * rctl_dict_lock must be acquired prior to rctl_lists_lock. Since 1410Sstevel@tonic-gate * rctl_dict_lock or rctl_lists_lock can be called at the enforcement point 1420Sstevel@tonic-gate * of any subsystem, holding subsystem locks, it is at all times inappropriate 1430Sstevel@tonic-gate * to call kmem_alloc(., KM_SLEEP) while holding either of these locks. 1440Sstevel@tonic-gate * Traversing any of the various resource control entity lists requires 1450Sstevel@tonic-gate * holding rctl_lists_lock. 1460Sstevel@tonic-gate * 1470Sstevel@tonic-gate * Each individual resource control set associated with an entity must have 1480Sstevel@tonic-gate * its rcs_lock held for the duration of any operations that would add 1490Sstevel@tonic-gate * resource controls or control values to the set. 1500Sstevel@tonic-gate * 1510Sstevel@tonic-gate * The locking subsequence of interest is: p_lock, rctl_dict_lock, 1520Sstevel@tonic-gate * rctl_lists_lock, entity->rcs_lock. 153*3684Srd117015 * 154*3684Srd117015 * The projects(4) database and project entity resource controls 155*3684Srd117015 * A special case is made for RCENTITY_PROJECT values set through the 156*3684Srd117015 * setproject(3PROJECT) interface. setproject() makes use of a private 157*3684Srd117015 * interface, setprojrctl(), which passes through an array of resource control 158*3684Srd117015 * blocks that need to be set while holding the entity->rcs_lock. This 159*3684Srd117015 * ensures that the act of modifying a project's resource controls is 160*3684Srd117015 * "atomic" within the kernel. 161*3684Srd117015 * 162*3684Srd117015 * Within the rctl sub-system, we provide two interfaces that are only used by 163*3684Srd117015 * the setprojrctl() code path - rctl_local_insert_all() and 164*3684Srd117015 * rctl_local_replace_all(). rctl_local_insert_all() will ensure that the 165*3684Srd117015 * resource values specified in *new_values are applied. 166*3684Srd117015 * rctl_local_replace_all() will purge the current rctl->rc_projdb and 167*3684Srd117015 * rctl->rc_values entries, and apply the *new_values. 168*3684Srd117015 * 169*3684Srd117015 * These functions modify not only the linked list of active resource controls 170*3684Srd117015 * (rctl->rc_values), but also a "cached" linked list (rctl->rc_projdb) of 171*3684Srd117015 * values set through these interfaces. To clarify: 172*3684Srd117015 * 173*3684Srd117015 * rctl->rc_values - a linked list of rctl_val_t. These are the active 174*3684Srd117015 * resource values associated with this rctl, and may have been set by 175*3684Srd117015 * setrctl() - via prctl(1M), or by setprojrctl() - via 176*3684Srd117015 * setproject(3PROJECT). 177*3684Srd117015 * 178*3684Srd117015 * rctl->rc_projdb - a linked list of rctl_val_t. These reflect the 179*3684Srd117015 * resource values set by the setprojrctl() code path. rc_projdb is not 180*3684Srd117015 * referenced by any other component of the rctl sub-system. 181*3684Srd117015 * 182*3684Srd117015 * As various locks are held when calling these functions, we ensure that all 183*3684Srd117015 * the possible memory allocations are performed prior to calling the 184*3684Srd117015 * function. *alloc_values is a linked list of uninitialized rctl_val_t, 185*3684Srd117015 * which may be used to duplicate a new resource control value (passed in as 186*3684Srd117015 * one of the members of the *new_values linked list), in order to populate 187*3684Srd117015 * rctl->rc_values. 1880Sstevel@tonic-gate */ 1890Sstevel@tonic-gate 1900Sstevel@tonic-gate id_t max_rctl_hndl = 32768; 1910Sstevel@tonic-gate int rctl_dict_size = 64; 1920Sstevel@tonic-gate int rctl_set_size = 8; 1930Sstevel@tonic-gate kmutex_t rctl_dict_lock; 1940Sstevel@tonic-gate mod_hash_t *rctl_dict; 1950Sstevel@tonic-gate mod_hash_t *rctl_dict_by_name; 1960Sstevel@tonic-gate id_space_t *rctl_ids; 1970Sstevel@tonic-gate kmem_cache_t *rctl_cache; /* kmem cache for rctl structures */ 1980Sstevel@tonic-gate kmem_cache_t *rctl_val_cache; /* kmem cache for rctl values */ 1990Sstevel@tonic-gate 2000Sstevel@tonic-gate kmutex_t rctl_lists_lock; 2010Sstevel@tonic-gate rctl_dict_entry_t *rctl_lists[RC_MAX_ENTITY + 1]; 2020Sstevel@tonic-gate 2030Sstevel@tonic-gate /* 2040Sstevel@tonic-gate * Default resource control operations and ops vector 2050Sstevel@tonic-gate * To be used if the particular rcontrol has no specific actions defined, or 2060Sstevel@tonic-gate * if the subsystem providing the control is quiescing (in preparation for 2070Sstevel@tonic-gate * unloading, presumably.) 2080Sstevel@tonic-gate * 2090Sstevel@tonic-gate * Resource controls with callbacks should fill the unused operations with the 2100Sstevel@tonic-gate * appropriate default impotent callback. 2110Sstevel@tonic-gate */ 2120Sstevel@tonic-gate /*ARGSUSED*/ 2130Sstevel@tonic-gate void 2140Sstevel@tonic-gate rcop_no_action(struct rctl *r, struct proc *p, rctl_entity_p_t *e) 2150Sstevel@tonic-gate { 2160Sstevel@tonic-gate } 2170Sstevel@tonic-gate 2180Sstevel@tonic-gate /*ARGSUSED*/ 2190Sstevel@tonic-gate rctl_qty_t 2200Sstevel@tonic-gate rcop_no_usage(struct rctl *r, struct proc *p) 2210Sstevel@tonic-gate { 2220Sstevel@tonic-gate return (0); 2230Sstevel@tonic-gate } 2240Sstevel@tonic-gate 2250Sstevel@tonic-gate /*ARGSUSED*/ 2260Sstevel@tonic-gate int 2270Sstevel@tonic-gate rcop_no_set(struct rctl *r, struct proc *p, rctl_entity_p_t *e, rctl_qty_t l) 2280Sstevel@tonic-gate { 2290Sstevel@tonic-gate return (0); 2300Sstevel@tonic-gate } 2310Sstevel@tonic-gate 2320Sstevel@tonic-gate /*ARGSUSED*/ 2330Sstevel@tonic-gate int 2340Sstevel@tonic-gate rcop_no_test(struct rctl *r, struct proc *p, rctl_entity_p_t *e, 2350Sstevel@tonic-gate struct rctl_val *rv, rctl_qty_t i, uint_t f) 2360Sstevel@tonic-gate { 2370Sstevel@tonic-gate return (0); 2380Sstevel@tonic-gate } 2390Sstevel@tonic-gate 2400Sstevel@tonic-gate rctl_ops_t rctl_default_ops = { 2410Sstevel@tonic-gate rcop_no_action, 2420Sstevel@tonic-gate rcop_no_usage, 2430Sstevel@tonic-gate rcop_no_set, 2440Sstevel@tonic-gate rcop_no_test 2450Sstevel@tonic-gate }; 2460Sstevel@tonic-gate 2470Sstevel@tonic-gate /* 2480Sstevel@tonic-gate * Default "absolute" resource control operation and ops vector 2490Sstevel@tonic-gate * Useful if there is no usage associated with the 2500Sstevel@tonic-gate * resource control. 2510Sstevel@tonic-gate */ 2520Sstevel@tonic-gate /*ARGSUSED*/ 2530Sstevel@tonic-gate int 2540Sstevel@tonic-gate rcop_absolute_test(struct rctl *r, struct proc *p, rctl_entity_p_t *e, 2550Sstevel@tonic-gate struct rctl_val *rv, rctl_qty_t i, uint_t f) 2560Sstevel@tonic-gate { 2570Sstevel@tonic-gate return (i > rv->rcv_value); 2580Sstevel@tonic-gate } 2590Sstevel@tonic-gate 2600Sstevel@tonic-gate rctl_ops_t rctl_absolute_ops = { 2610Sstevel@tonic-gate rcop_no_action, 2620Sstevel@tonic-gate rcop_no_usage, 2630Sstevel@tonic-gate rcop_no_set, 2640Sstevel@tonic-gate rcop_absolute_test 2650Sstevel@tonic-gate }; 2660Sstevel@tonic-gate 2670Sstevel@tonic-gate /*ARGSUSED*/ 2680Sstevel@tonic-gate static uint_t 2690Sstevel@tonic-gate rctl_dict_hash_by_id(void *hash_data, mod_hash_key_t key) 2700Sstevel@tonic-gate { 2710Sstevel@tonic-gate return ((uint_t)(uintptr_t)key % rctl_dict_size); 2720Sstevel@tonic-gate } 2730Sstevel@tonic-gate 2740Sstevel@tonic-gate static int 2750Sstevel@tonic-gate rctl_dict_id_cmp(mod_hash_key_t key1, mod_hash_key_t key2) 2760Sstevel@tonic-gate { 2770Sstevel@tonic-gate uint_t u1 = (uint_t)(uintptr_t)key1; 2780Sstevel@tonic-gate uint_t u2 = (uint_t)(uintptr_t)key2; 2790Sstevel@tonic-gate 2800Sstevel@tonic-gate if (u1 > u2) 2810Sstevel@tonic-gate return (1); 2820Sstevel@tonic-gate 2830Sstevel@tonic-gate if (u1 == u2) 2840Sstevel@tonic-gate return (0); 2850Sstevel@tonic-gate 2860Sstevel@tonic-gate return (-1); 2870Sstevel@tonic-gate } 2880Sstevel@tonic-gate 2890Sstevel@tonic-gate static void 2900Sstevel@tonic-gate rctl_dict_val_dtor(mod_hash_val_t val) 2910Sstevel@tonic-gate { 2920Sstevel@tonic-gate rctl_dict_entry_t *kr = (rctl_dict_entry_t *)val; 2930Sstevel@tonic-gate 2940Sstevel@tonic-gate kmem_free(kr, sizeof (rctl_dict_entry_t)); 2950Sstevel@tonic-gate } 2960Sstevel@tonic-gate 2970Sstevel@tonic-gate /* 2980Sstevel@tonic-gate * size_t rctl_build_name_buf() 2990Sstevel@tonic-gate * 3000Sstevel@tonic-gate * Overview 3010Sstevel@tonic-gate * rctl_build_name_buf() walks all active resource controls in the dictionary, 3020Sstevel@tonic-gate * building a buffer of continguous NUL-terminated strings. 3030Sstevel@tonic-gate * 3040Sstevel@tonic-gate * Return values 3050Sstevel@tonic-gate * The size of the buffer is returned, the passed pointer's contents are 3060Sstevel@tonic-gate * modified to that of the location of the buffer. 3070Sstevel@tonic-gate * 3080Sstevel@tonic-gate * Caller's context 3090Sstevel@tonic-gate * Caller must be in a context suitable for KM_SLEEP allocations. 3100Sstevel@tonic-gate */ 3110Sstevel@tonic-gate size_t 3120Sstevel@tonic-gate rctl_build_name_buf(char **rbufp) 3130Sstevel@tonic-gate { 3140Sstevel@tonic-gate size_t req_size, cpy_size; 3150Sstevel@tonic-gate char *rbufloc; 3160Sstevel@tonic-gate int i; 3170Sstevel@tonic-gate 3180Sstevel@tonic-gate rctl_rebuild_name_buf: 3190Sstevel@tonic-gate req_size = cpy_size = 0; 3200Sstevel@tonic-gate 3210Sstevel@tonic-gate /* 3220Sstevel@tonic-gate * Calculate needed buffer length. 3230Sstevel@tonic-gate */ 3240Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 3250Sstevel@tonic-gate for (i = 0; i < RC_MAX_ENTITY + 1; i++) { 3260Sstevel@tonic-gate rctl_dict_entry_t *rde; 3270Sstevel@tonic-gate 3280Sstevel@tonic-gate for (rde = rctl_lists[i]; 3290Sstevel@tonic-gate rde != NULL; 3300Sstevel@tonic-gate rde = rde->rcd_next) 3310Sstevel@tonic-gate req_size += strlen(rde->rcd_name) + 1; 3320Sstevel@tonic-gate } 3330Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 3340Sstevel@tonic-gate 3350Sstevel@tonic-gate rbufloc = *rbufp = kmem_alloc(req_size, KM_SLEEP); 3360Sstevel@tonic-gate 3370Sstevel@tonic-gate /* 3380Sstevel@tonic-gate * Copy rctl names into our buffer. If the copy length exceeds the 3390Sstevel@tonic-gate * allocate length (due to registration changes), stop copying, free the 3400Sstevel@tonic-gate * buffer, and start again. 3410Sstevel@tonic-gate */ 3420Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 3430Sstevel@tonic-gate for (i = 0; i < RC_MAX_ENTITY + 1; i++) { 3440Sstevel@tonic-gate rctl_dict_entry_t *rde; 3450Sstevel@tonic-gate 3460Sstevel@tonic-gate for (rde = rctl_lists[i]; 3470Sstevel@tonic-gate rde != NULL; 3480Sstevel@tonic-gate rde = rde->rcd_next) { 3490Sstevel@tonic-gate size_t length = strlen(rde->rcd_name) + 1; 3500Sstevel@tonic-gate 3510Sstevel@tonic-gate cpy_size += length; 3520Sstevel@tonic-gate 3530Sstevel@tonic-gate if (cpy_size > req_size) { 3540Sstevel@tonic-gate kmem_free(*rbufp, req_size); 3550Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 3560Sstevel@tonic-gate goto rctl_rebuild_name_buf; 3570Sstevel@tonic-gate } 3580Sstevel@tonic-gate 3590Sstevel@tonic-gate bcopy(rde->rcd_name, rbufloc, length); 3600Sstevel@tonic-gate rbufloc += length; 3610Sstevel@tonic-gate } 3620Sstevel@tonic-gate } 3630Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 3640Sstevel@tonic-gate 3650Sstevel@tonic-gate return (req_size); 3660Sstevel@tonic-gate } 3670Sstevel@tonic-gate 3680Sstevel@tonic-gate /* 3690Sstevel@tonic-gate * rctl_dict_entry_t *rctl_dict_lookup(const char *) 3700Sstevel@tonic-gate * 3710Sstevel@tonic-gate * Overview 3720Sstevel@tonic-gate * rctl_dict_lookup() returns the resource control dictionary entry for the 3730Sstevel@tonic-gate * named resource control. 3740Sstevel@tonic-gate * 3750Sstevel@tonic-gate * Return values 3760Sstevel@tonic-gate * A pointer to the appropriate resource control dictionary entry, or NULL if 3770Sstevel@tonic-gate * no such named entry exists. 3780Sstevel@tonic-gate * 3790Sstevel@tonic-gate * Caller's context 3800Sstevel@tonic-gate * Caller must not be holding rctl_dict_lock. 3810Sstevel@tonic-gate */ 3820Sstevel@tonic-gate rctl_dict_entry_t * 3830Sstevel@tonic-gate rctl_dict_lookup(const char *name) 3840Sstevel@tonic-gate { 3850Sstevel@tonic-gate rctl_dict_entry_t *rde; 3860Sstevel@tonic-gate 3870Sstevel@tonic-gate mutex_enter(&rctl_dict_lock); 3880Sstevel@tonic-gate 3890Sstevel@tonic-gate if (mod_hash_find(rctl_dict_by_name, (mod_hash_key_t)name, 3900Sstevel@tonic-gate (mod_hash_val_t *)&rde) == MH_ERR_NOTFOUND) { 3910Sstevel@tonic-gate mutex_exit(&rctl_dict_lock); 3920Sstevel@tonic-gate return (NULL); 3930Sstevel@tonic-gate } 3940Sstevel@tonic-gate 3950Sstevel@tonic-gate mutex_exit(&rctl_dict_lock); 3960Sstevel@tonic-gate 3970Sstevel@tonic-gate return (rde); 3980Sstevel@tonic-gate } 3990Sstevel@tonic-gate 4000Sstevel@tonic-gate /* 4010Sstevel@tonic-gate * rctl_hndl_t rctl_hndl_lookup(const char *) 4020Sstevel@tonic-gate * 4030Sstevel@tonic-gate * Overview 4040Sstevel@tonic-gate * rctl_hndl_lookup() returns the resource control id (the "handle") for the 4050Sstevel@tonic-gate * named resource control. 4060Sstevel@tonic-gate * 4070Sstevel@tonic-gate * Return values 4080Sstevel@tonic-gate * The appropriate id, or -1 if no such named entry exists. 4090Sstevel@tonic-gate * 4100Sstevel@tonic-gate * Caller's context 4110Sstevel@tonic-gate * Caller must not be holding rctl_dict_lock. 4120Sstevel@tonic-gate */ 4130Sstevel@tonic-gate rctl_hndl_t 4140Sstevel@tonic-gate rctl_hndl_lookup(const char *name) 4150Sstevel@tonic-gate { 4160Sstevel@tonic-gate rctl_dict_entry_t *rde; 4170Sstevel@tonic-gate 4180Sstevel@tonic-gate if ((rde = rctl_dict_lookup(name)) == NULL) 4190Sstevel@tonic-gate return (-1); 4200Sstevel@tonic-gate 4210Sstevel@tonic-gate return (rde->rcd_id); 4220Sstevel@tonic-gate } 4230Sstevel@tonic-gate 4240Sstevel@tonic-gate /* 4250Sstevel@tonic-gate * rctl_dict_entry_t * rctl_dict_lookup_hndl(rctl_hndl_t) 4260Sstevel@tonic-gate * 4270Sstevel@tonic-gate * Overview 4280Sstevel@tonic-gate * rctl_dict_lookup_hndl() completes the public lookup functions, by returning 4290Sstevel@tonic-gate * the resource control dictionary entry matching a given resource control id. 4300Sstevel@tonic-gate * 4310Sstevel@tonic-gate * Return values 4320Sstevel@tonic-gate * A pointer to the matching resource control dictionary entry, or NULL if the 4330Sstevel@tonic-gate * id does not match any existing entries. 4340Sstevel@tonic-gate * 4350Sstevel@tonic-gate * Caller's context 4360Sstevel@tonic-gate * Caller must not be holding rctl_lists_lock. 4370Sstevel@tonic-gate */ 4380Sstevel@tonic-gate rctl_dict_entry_t * 4390Sstevel@tonic-gate rctl_dict_lookup_hndl(rctl_hndl_t hndl) 4400Sstevel@tonic-gate { 4410Sstevel@tonic-gate uint_t i; 4420Sstevel@tonic-gate 4430Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 4440Sstevel@tonic-gate for (i = 0; i < RC_MAX_ENTITY + 1; i++) { 4450Sstevel@tonic-gate rctl_dict_entry_t *rde; 4460Sstevel@tonic-gate 4470Sstevel@tonic-gate for (rde = rctl_lists[i]; 4480Sstevel@tonic-gate rde != NULL; 4490Sstevel@tonic-gate rde = rde->rcd_next) 4500Sstevel@tonic-gate if (rde->rcd_id == hndl) { 4510Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 4520Sstevel@tonic-gate return (rde); 4530Sstevel@tonic-gate } 4540Sstevel@tonic-gate } 4550Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 4560Sstevel@tonic-gate 4570Sstevel@tonic-gate return (NULL); 4580Sstevel@tonic-gate } 4590Sstevel@tonic-gate 4600Sstevel@tonic-gate /* 4610Sstevel@tonic-gate * void rctl_add_default_limit(const char *name, rctl_qty_t value, 4620Sstevel@tonic-gate * rctl_priv_t privilege, uint_t action) 4630Sstevel@tonic-gate * 4640Sstevel@tonic-gate * Overview 4650Sstevel@tonic-gate * Create a default limit with specified value, privilege, and action. 4660Sstevel@tonic-gate * 4670Sstevel@tonic-gate * Return value 4680Sstevel@tonic-gate * No value returned. 4690Sstevel@tonic-gate */ 4700Sstevel@tonic-gate void 4710Sstevel@tonic-gate rctl_add_default_limit(const char *name, rctl_qty_t value, 4720Sstevel@tonic-gate rctl_priv_t privilege, uint_t action) 4730Sstevel@tonic-gate { 4740Sstevel@tonic-gate rctl_val_t *dval; 4750Sstevel@tonic-gate rctl_dict_entry_t *rde; 4760Sstevel@tonic-gate 4770Sstevel@tonic-gate dval = kmem_cache_alloc(rctl_val_cache, KM_SLEEP); 4780Sstevel@tonic-gate bzero(dval, sizeof (rctl_val_t)); 4790Sstevel@tonic-gate dval->rcv_value = value; 4800Sstevel@tonic-gate dval->rcv_privilege = privilege; 4810Sstevel@tonic-gate dval->rcv_flagaction = action; 4820Sstevel@tonic-gate dval->rcv_action_recip_pid = -1; 4830Sstevel@tonic-gate 4840Sstevel@tonic-gate rde = rctl_dict_lookup(name); 4850Sstevel@tonic-gate (void) rctl_val_list_insert(&rde->rcd_default_value, dval); 4860Sstevel@tonic-gate } 4870Sstevel@tonic-gate 4880Sstevel@tonic-gate /* 4890Sstevel@tonic-gate * void rctl_add_legacy_limit(const char *name, const char *mname, 4900Sstevel@tonic-gate * const char *lname, rctl_qty_t dflt) 4910Sstevel@tonic-gate * 4920Sstevel@tonic-gate * Overview 4930Sstevel@tonic-gate * Create a default privileged limit, using the value obtained from 4940Sstevel@tonic-gate * /etc/system if it exists and is greater than the specified default 4950Sstevel@tonic-gate * value. Exists primarily for System V IPC. 4960Sstevel@tonic-gate * 4970Sstevel@tonic-gate * Return value 4980Sstevel@tonic-gate * No value returned. 4990Sstevel@tonic-gate */ 5000Sstevel@tonic-gate void 5010Sstevel@tonic-gate rctl_add_legacy_limit(const char *name, const char *mname, const char *lname, 5020Sstevel@tonic-gate rctl_qty_t dflt, rctl_qty_t max) 5030Sstevel@tonic-gate { 5040Sstevel@tonic-gate rctl_qty_t qty; 5050Sstevel@tonic-gate 5060Sstevel@tonic-gate if (!mod_sysvar(mname, lname, &qty) || (qty < dflt)) 5070Sstevel@tonic-gate qty = dflt; 5080Sstevel@tonic-gate 5090Sstevel@tonic-gate if (qty > max) 5100Sstevel@tonic-gate qty = max; 5110Sstevel@tonic-gate 5120Sstevel@tonic-gate rctl_add_default_limit(name, qty, RCPRIV_PRIVILEGED, RCTL_LOCAL_DENY); 5130Sstevel@tonic-gate } 5140Sstevel@tonic-gate 5150Sstevel@tonic-gate static rctl_set_t * 5160Sstevel@tonic-gate rctl_entity_obtain_rset(rctl_dict_entry_t *rcd, struct proc *p) 5170Sstevel@tonic-gate { 5180Sstevel@tonic-gate rctl_set_t *rset = NULL; 5190Sstevel@tonic-gate 5200Sstevel@tonic-gate if (rcd == NULL) 5210Sstevel@tonic-gate return (NULL); 5220Sstevel@tonic-gate 5230Sstevel@tonic-gate switch (rcd->rcd_entity) { 5240Sstevel@tonic-gate case RCENTITY_PROCESS: 5250Sstevel@tonic-gate rset = p->p_rctls; 5260Sstevel@tonic-gate break; 5270Sstevel@tonic-gate case RCENTITY_TASK: 5280Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5290Sstevel@tonic-gate if (p->p_task != NULL) 5300Sstevel@tonic-gate rset = p->p_task->tk_rctls; 5310Sstevel@tonic-gate break; 5320Sstevel@tonic-gate case RCENTITY_PROJECT: 5330Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5340Sstevel@tonic-gate if (p->p_task != NULL && 5350Sstevel@tonic-gate p->p_task->tk_proj != NULL) 5360Sstevel@tonic-gate rset = p->p_task->tk_proj->kpj_rctls; 5370Sstevel@tonic-gate break; 5380Sstevel@tonic-gate case RCENTITY_ZONE: 5390Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5400Sstevel@tonic-gate if (p->p_zone != NULL) 5410Sstevel@tonic-gate rset = p->p_zone->zone_rctls; 5420Sstevel@tonic-gate break; 5430Sstevel@tonic-gate default: 5440Sstevel@tonic-gate panic("unknown rctl entity type %d seen", rcd->rcd_entity); 5450Sstevel@tonic-gate break; 5460Sstevel@tonic-gate } 5470Sstevel@tonic-gate 5480Sstevel@tonic-gate return (rset); 5490Sstevel@tonic-gate } 5500Sstevel@tonic-gate 5510Sstevel@tonic-gate static void 5520Sstevel@tonic-gate rctl_entity_obtain_entity_p(rctl_entity_t entity, struct proc *p, 5530Sstevel@tonic-gate rctl_entity_p_t *e) 5540Sstevel@tonic-gate { 5550Sstevel@tonic-gate e->rcep_p.proc = NULL; 5560Sstevel@tonic-gate e->rcep_t = entity; 5570Sstevel@tonic-gate 5580Sstevel@tonic-gate switch (entity) { 5590Sstevel@tonic-gate case RCENTITY_PROCESS: 5600Sstevel@tonic-gate e->rcep_p.proc = p; 5610Sstevel@tonic-gate break; 5620Sstevel@tonic-gate case RCENTITY_TASK: 5630Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5640Sstevel@tonic-gate if (p->p_task != NULL) 5650Sstevel@tonic-gate e->rcep_p.task = p->p_task; 5660Sstevel@tonic-gate break; 5670Sstevel@tonic-gate case RCENTITY_PROJECT: 5680Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5690Sstevel@tonic-gate if (p->p_task != NULL && 5700Sstevel@tonic-gate p->p_task->tk_proj != NULL) 5710Sstevel@tonic-gate e->rcep_p.proj = p->p_task->tk_proj; 5720Sstevel@tonic-gate break; 5730Sstevel@tonic-gate case RCENTITY_ZONE: 5740Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 5750Sstevel@tonic-gate if (p->p_zone != NULL) 5760Sstevel@tonic-gate e->rcep_p.zone = p->p_zone; 5770Sstevel@tonic-gate break; 5780Sstevel@tonic-gate default: 5790Sstevel@tonic-gate panic("unknown rctl entity type %d seen", entity); 5800Sstevel@tonic-gate break; 5810Sstevel@tonic-gate } 5820Sstevel@tonic-gate } 5830Sstevel@tonic-gate 5840Sstevel@tonic-gate static void 5850Sstevel@tonic-gate rctl_gp_alloc(rctl_alloc_gp_t *rcgp) 5860Sstevel@tonic-gate { 5870Sstevel@tonic-gate uint_t i; 5880Sstevel@tonic-gate 5890Sstevel@tonic-gate if (rcgp->rcag_nctls > 0) { 5900Sstevel@tonic-gate rctl_t *prev = kmem_cache_alloc(rctl_cache, KM_SLEEP); 5910Sstevel@tonic-gate rctl_t *rctl = prev; 5920Sstevel@tonic-gate 5930Sstevel@tonic-gate rcgp->rcag_ctls = prev; 5940Sstevel@tonic-gate 5950Sstevel@tonic-gate for (i = 1; i < rcgp->rcag_nctls; i++) { 5960Sstevel@tonic-gate rctl = kmem_cache_alloc(rctl_cache, KM_SLEEP); 5970Sstevel@tonic-gate prev->rc_next = rctl; 5980Sstevel@tonic-gate prev = rctl; 5990Sstevel@tonic-gate } 6000Sstevel@tonic-gate 6010Sstevel@tonic-gate rctl->rc_next = NULL; 6020Sstevel@tonic-gate } 6030Sstevel@tonic-gate 6040Sstevel@tonic-gate if (rcgp->rcag_nvals > 0) { 6050Sstevel@tonic-gate rctl_val_t *prev = kmem_cache_alloc(rctl_val_cache, KM_SLEEP); 6060Sstevel@tonic-gate rctl_val_t *rval = prev; 6070Sstevel@tonic-gate 6080Sstevel@tonic-gate rcgp->rcag_vals = prev; 6090Sstevel@tonic-gate 6100Sstevel@tonic-gate for (i = 1; i < rcgp->rcag_nvals; i++) { 6110Sstevel@tonic-gate rval = kmem_cache_alloc(rctl_val_cache, KM_SLEEP); 6120Sstevel@tonic-gate prev->rcv_next = rval; 6130Sstevel@tonic-gate prev = rval; 6140Sstevel@tonic-gate } 6150Sstevel@tonic-gate 6160Sstevel@tonic-gate rval->rcv_next = NULL; 6170Sstevel@tonic-gate } 6180Sstevel@tonic-gate 6190Sstevel@tonic-gate } 6200Sstevel@tonic-gate 6210Sstevel@tonic-gate static rctl_val_t * 6220Sstevel@tonic-gate rctl_gp_detach_val(rctl_alloc_gp_t *rcgp) 6230Sstevel@tonic-gate { 6240Sstevel@tonic-gate rctl_val_t *rval = rcgp->rcag_vals; 6250Sstevel@tonic-gate 6260Sstevel@tonic-gate ASSERT(rcgp->rcag_nvals > 0); 6270Sstevel@tonic-gate rcgp->rcag_nvals--; 6280Sstevel@tonic-gate rcgp->rcag_vals = rval->rcv_next; 6290Sstevel@tonic-gate 6300Sstevel@tonic-gate rval->rcv_next = NULL; 6310Sstevel@tonic-gate 6320Sstevel@tonic-gate return (rval); 6330Sstevel@tonic-gate } 6340Sstevel@tonic-gate 6350Sstevel@tonic-gate static rctl_t * 6360Sstevel@tonic-gate rctl_gp_detach_ctl(rctl_alloc_gp_t *rcgp) 6370Sstevel@tonic-gate { 6380Sstevel@tonic-gate rctl_t *rctl = rcgp->rcag_ctls; 6390Sstevel@tonic-gate 6400Sstevel@tonic-gate ASSERT(rcgp->rcag_nctls > 0); 6410Sstevel@tonic-gate rcgp->rcag_nctls--; 6420Sstevel@tonic-gate rcgp->rcag_ctls = rctl->rc_next; 6430Sstevel@tonic-gate 6440Sstevel@tonic-gate rctl->rc_next = NULL; 6450Sstevel@tonic-gate 6460Sstevel@tonic-gate return (rctl); 6470Sstevel@tonic-gate 6480Sstevel@tonic-gate } 6490Sstevel@tonic-gate 6500Sstevel@tonic-gate static void 6510Sstevel@tonic-gate rctl_gp_free(rctl_alloc_gp_t *rcgp) 6520Sstevel@tonic-gate { 6530Sstevel@tonic-gate rctl_val_t *rval = rcgp->rcag_vals; 6540Sstevel@tonic-gate rctl_t *rctl = rcgp->rcag_ctls; 6550Sstevel@tonic-gate 6560Sstevel@tonic-gate while (rval != NULL) { 6570Sstevel@tonic-gate rctl_val_t *next = rval->rcv_next; 6580Sstevel@tonic-gate 6590Sstevel@tonic-gate kmem_cache_free(rctl_val_cache, rval); 6600Sstevel@tonic-gate rval = next; 6610Sstevel@tonic-gate } 6620Sstevel@tonic-gate 6630Sstevel@tonic-gate while (rctl != NULL) { 6640Sstevel@tonic-gate rctl_t *next = rctl->rc_next; 6650Sstevel@tonic-gate 6660Sstevel@tonic-gate kmem_cache_free(rctl_cache, rctl); 6670Sstevel@tonic-gate rctl = next; 6680Sstevel@tonic-gate } 6690Sstevel@tonic-gate } 6700Sstevel@tonic-gate 6710Sstevel@tonic-gate /* 6720Sstevel@tonic-gate * void rctl_prealloc_destroy(rctl_alloc_gp_t *) 6730Sstevel@tonic-gate * 6740Sstevel@tonic-gate * Overview 6750Sstevel@tonic-gate * Release all unused memory allocated via one of the "prealloc" functions: 6760Sstevel@tonic-gate * rctl_set_init_prealloc, rctl_set_dup_prealloc, or rctl_rlimit_set_prealloc. 6770Sstevel@tonic-gate * 6780Sstevel@tonic-gate * Return values 6790Sstevel@tonic-gate * None. 6800Sstevel@tonic-gate * 6810Sstevel@tonic-gate * Caller's context 6820Sstevel@tonic-gate * No restrictions on context. 6830Sstevel@tonic-gate */ 6840Sstevel@tonic-gate void 6850Sstevel@tonic-gate rctl_prealloc_destroy(rctl_alloc_gp_t *gp) 6860Sstevel@tonic-gate { 6870Sstevel@tonic-gate rctl_gp_free(gp); 6880Sstevel@tonic-gate kmem_free(gp, sizeof (rctl_alloc_gp_t)); 6890Sstevel@tonic-gate } 6900Sstevel@tonic-gate 6910Sstevel@tonic-gate /* 6920Sstevel@tonic-gate * int rctl_val_cmp(rctl_val_t *, rctl_val_t *, int) 6930Sstevel@tonic-gate * 6940Sstevel@tonic-gate * Overview 6950Sstevel@tonic-gate * This function defines an ordering to rctl_val_t's in order to allow 6960Sstevel@tonic-gate * for correct placement in value lists. When the imprecise flag is set, 6970Sstevel@tonic-gate * the action recipient is ignored. This is to facilitate insert, 6980Sstevel@tonic-gate * delete, and replace operations by rctlsys. 6990Sstevel@tonic-gate * 7000Sstevel@tonic-gate * Return values 7010Sstevel@tonic-gate * 0 if the val_t's are are considered identical 7020Sstevel@tonic-gate * -1 if a is ordered lower than b 7030Sstevel@tonic-gate * 1 if a is lowered higher than b 7040Sstevel@tonic-gate * 7050Sstevel@tonic-gate * Caller's context 7060Sstevel@tonic-gate * No restrictions on context. 7070Sstevel@tonic-gate */ 7080Sstevel@tonic-gate int 7090Sstevel@tonic-gate rctl_val_cmp(rctl_val_t *a, rctl_val_t *b, int imprecise) 7100Sstevel@tonic-gate { 7110Sstevel@tonic-gate if ((a->rcv_flagaction & RCTL_LOCAL_MAXIMAL) < 7120Sstevel@tonic-gate (b->rcv_flagaction & RCTL_LOCAL_MAXIMAL)) 7130Sstevel@tonic-gate return (-1); 7140Sstevel@tonic-gate 7150Sstevel@tonic-gate if ((a->rcv_flagaction & RCTL_LOCAL_MAXIMAL) > 7160Sstevel@tonic-gate (b->rcv_flagaction & RCTL_LOCAL_MAXIMAL)) 7170Sstevel@tonic-gate return (1); 7180Sstevel@tonic-gate 7190Sstevel@tonic-gate if (a->rcv_value < b->rcv_value) 7200Sstevel@tonic-gate return (-1); 7210Sstevel@tonic-gate 7220Sstevel@tonic-gate if (a->rcv_value > b->rcv_value) 7230Sstevel@tonic-gate return (1); 7240Sstevel@tonic-gate 7250Sstevel@tonic-gate if ((a->rcv_flagaction & RCTL_LOCAL_DENY) < 7260Sstevel@tonic-gate (b->rcv_flagaction & RCTL_LOCAL_DENY)) 7270Sstevel@tonic-gate return (-1); 7280Sstevel@tonic-gate 7290Sstevel@tonic-gate if ((a->rcv_flagaction & RCTL_LOCAL_DENY) > 7300Sstevel@tonic-gate (b->rcv_flagaction & RCTL_LOCAL_DENY)) 7310Sstevel@tonic-gate return (1); 7320Sstevel@tonic-gate 7330Sstevel@tonic-gate if (a->rcv_privilege < b->rcv_privilege) 7340Sstevel@tonic-gate return (-1); 7350Sstevel@tonic-gate 7360Sstevel@tonic-gate if (a->rcv_privilege > b->rcv_privilege) 7370Sstevel@tonic-gate return (1); 7380Sstevel@tonic-gate 7390Sstevel@tonic-gate if (imprecise) 7400Sstevel@tonic-gate return (0); 7410Sstevel@tonic-gate 7420Sstevel@tonic-gate if (a->rcv_action_recip_pid < b->rcv_action_recip_pid) 7430Sstevel@tonic-gate return (-1); 7440Sstevel@tonic-gate 7450Sstevel@tonic-gate if (a->rcv_action_recip_pid > b->rcv_action_recip_pid) 7460Sstevel@tonic-gate return (1); 7470Sstevel@tonic-gate 7480Sstevel@tonic-gate return (0); 7490Sstevel@tonic-gate } 7500Sstevel@tonic-gate 7510Sstevel@tonic-gate static rctl_val_t * 7520Sstevel@tonic-gate rctl_val_list_find(rctl_val_t **head, rctl_val_t *cval) 7530Sstevel@tonic-gate { 7540Sstevel@tonic-gate rctl_val_t *rval = *head; 7550Sstevel@tonic-gate 7560Sstevel@tonic-gate while (rval != NULL) { 7570Sstevel@tonic-gate if (rctl_val_cmp(cval, rval, 0) == 0) 7580Sstevel@tonic-gate return (rval); 7590Sstevel@tonic-gate 7600Sstevel@tonic-gate rval = rval->rcv_next; 7610Sstevel@tonic-gate } 7620Sstevel@tonic-gate 7630Sstevel@tonic-gate return (NULL); 7640Sstevel@tonic-gate 7650Sstevel@tonic-gate } 7660Sstevel@tonic-gate 7670Sstevel@tonic-gate /* 7680Sstevel@tonic-gate * int rctl_val_list_insert(rctl_val_t **, rctl_val_t *) 7690Sstevel@tonic-gate * 7700Sstevel@tonic-gate * Overview 7710Sstevel@tonic-gate * This function inserts the rctl_val_t into the value list provided. 7720Sstevel@tonic-gate * The insert is always successful unless if the value is a duplicate 7730Sstevel@tonic-gate * of one already in the list. 7740Sstevel@tonic-gate * 7750Sstevel@tonic-gate * Return values 7760Sstevel@tonic-gate * 1 if the value was a duplicate of an existing value in the list. 7770Sstevel@tonic-gate * 0 if the insert was successful. 7780Sstevel@tonic-gate */ 7790Sstevel@tonic-gate int 7800Sstevel@tonic-gate rctl_val_list_insert(rctl_val_t **root, rctl_val_t *rval) 7810Sstevel@tonic-gate { 7820Sstevel@tonic-gate rctl_val_t *prev; 7830Sstevel@tonic-gate int equiv; 7840Sstevel@tonic-gate 7850Sstevel@tonic-gate rval->rcv_next = NULL; 7860Sstevel@tonic-gate rval->rcv_prev = NULL; 7870Sstevel@tonic-gate 7880Sstevel@tonic-gate if (*root == NULL) { 7890Sstevel@tonic-gate *root = rval; 7900Sstevel@tonic-gate return (0); 7910Sstevel@tonic-gate } 7920Sstevel@tonic-gate 7930Sstevel@tonic-gate equiv = rctl_val_cmp(rval, *root, 0); 7940Sstevel@tonic-gate 7950Sstevel@tonic-gate if (equiv == 0) 7960Sstevel@tonic-gate return (1); 7970Sstevel@tonic-gate 7980Sstevel@tonic-gate if (equiv < 0) { 7990Sstevel@tonic-gate rval->rcv_next = *root; 8000Sstevel@tonic-gate rval->rcv_next->rcv_prev = rval; 8010Sstevel@tonic-gate *root = rval; 8020Sstevel@tonic-gate 8030Sstevel@tonic-gate return (0); 8040Sstevel@tonic-gate } 8050Sstevel@tonic-gate 8060Sstevel@tonic-gate prev = *root; 8070Sstevel@tonic-gate while (prev->rcv_next != NULL && 8080Sstevel@tonic-gate (equiv = rctl_val_cmp(rval, prev->rcv_next, 0)) > 0) { 8090Sstevel@tonic-gate prev = prev->rcv_next; 8100Sstevel@tonic-gate } 8110Sstevel@tonic-gate 8120Sstevel@tonic-gate if (equiv == 0) 8130Sstevel@tonic-gate return (1); 8140Sstevel@tonic-gate 8150Sstevel@tonic-gate rval->rcv_next = prev->rcv_next; 8160Sstevel@tonic-gate if (rval->rcv_next != NULL) 8170Sstevel@tonic-gate rval->rcv_next->rcv_prev = rval; 8180Sstevel@tonic-gate prev->rcv_next = rval; 8190Sstevel@tonic-gate rval->rcv_prev = prev; 8200Sstevel@tonic-gate 8210Sstevel@tonic-gate return (0); 8220Sstevel@tonic-gate } 8230Sstevel@tonic-gate 8240Sstevel@tonic-gate static int 8250Sstevel@tonic-gate rctl_val_list_delete(rctl_val_t **root, rctl_val_t *rval) 8260Sstevel@tonic-gate { 8270Sstevel@tonic-gate rctl_val_t *prev; 8280Sstevel@tonic-gate 8290Sstevel@tonic-gate if (*root == NULL) 8300Sstevel@tonic-gate return (-1); 8310Sstevel@tonic-gate 8320Sstevel@tonic-gate prev = *root; 8330Sstevel@tonic-gate if (rctl_val_cmp(rval, prev, 0) == 0) { 8340Sstevel@tonic-gate *root = prev->rcv_next; 8350Sstevel@tonic-gate (*root)->rcv_prev = NULL; 8360Sstevel@tonic-gate 8370Sstevel@tonic-gate kmem_cache_free(rctl_val_cache, prev); 8380Sstevel@tonic-gate 8390Sstevel@tonic-gate return (0); 8400Sstevel@tonic-gate } 8410Sstevel@tonic-gate 8420Sstevel@tonic-gate while (prev->rcv_next != NULL && 8430Sstevel@tonic-gate rctl_val_cmp(rval, prev->rcv_next, 0) != 0) { 8440Sstevel@tonic-gate prev = prev->rcv_next; 8450Sstevel@tonic-gate } 8460Sstevel@tonic-gate 8470Sstevel@tonic-gate if (prev->rcv_next == NULL) { 8480Sstevel@tonic-gate /* 8490Sstevel@tonic-gate * If we navigate the entire list and cannot find a match, then 8500Sstevel@tonic-gate * return failure. 8510Sstevel@tonic-gate */ 8520Sstevel@tonic-gate return (-1); 8530Sstevel@tonic-gate } 8540Sstevel@tonic-gate 8550Sstevel@tonic-gate prev = prev->rcv_next; 8560Sstevel@tonic-gate prev->rcv_prev->rcv_next = prev->rcv_next; 8570Sstevel@tonic-gate if (prev->rcv_next != NULL) 8580Sstevel@tonic-gate prev->rcv_next->rcv_prev = prev->rcv_prev; 8590Sstevel@tonic-gate 8600Sstevel@tonic-gate kmem_cache_free(rctl_val_cache, prev); 8610Sstevel@tonic-gate 8620Sstevel@tonic-gate return (0); 8630Sstevel@tonic-gate } 8640Sstevel@tonic-gate 8650Sstevel@tonic-gate static rctl_val_t * 8660Sstevel@tonic-gate rctl_val_list_dup(rctl_val_t *rval, rctl_alloc_gp_t *ragp, struct proc *oldp, 8670Sstevel@tonic-gate struct proc *newp) 8680Sstevel@tonic-gate { 8690Sstevel@tonic-gate rctl_val_t *head = NULL; 8700Sstevel@tonic-gate 8710Sstevel@tonic-gate for (; rval != NULL; rval = rval->rcv_next) { 8720Sstevel@tonic-gate rctl_val_t *dval = rctl_gp_detach_val(ragp); 8730Sstevel@tonic-gate 8740Sstevel@tonic-gate bcopy(rval, dval, sizeof (rctl_val_t)); 8750Sstevel@tonic-gate dval->rcv_prev = dval->rcv_next = NULL; 8760Sstevel@tonic-gate 8770Sstevel@tonic-gate if (oldp == NULL || 8780Sstevel@tonic-gate rval->rcv_action_recipient == NULL || 8790Sstevel@tonic-gate rval->rcv_action_recipient == oldp) { 8800Sstevel@tonic-gate if (rval->rcv_privilege == RCPRIV_BASIC) { 8810Sstevel@tonic-gate dval->rcv_action_recipient = newp; 8820Sstevel@tonic-gate dval->rcv_action_recip_pid = newp->p_pid; 8830Sstevel@tonic-gate } else { 8840Sstevel@tonic-gate dval->rcv_action_recipient = NULL; 8850Sstevel@tonic-gate dval->rcv_action_recip_pid = -1; 8860Sstevel@tonic-gate } 8870Sstevel@tonic-gate 8880Sstevel@tonic-gate (void) rctl_val_list_insert(&head, dval); 8890Sstevel@tonic-gate } else { 8900Sstevel@tonic-gate kmem_cache_free(rctl_val_cache, dval); 8910Sstevel@tonic-gate } 8920Sstevel@tonic-gate } 8930Sstevel@tonic-gate 8940Sstevel@tonic-gate return (head); 8950Sstevel@tonic-gate } 8960Sstevel@tonic-gate 8970Sstevel@tonic-gate static void 8980Sstevel@tonic-gate rctl_val_list_reset(rctl_val_t *rval) 8990Sstevel@tonic-gate { 9000Sstevel@tonic-gate for (; rval != NULL; rval = rval->rcv_next) 9010Sstevel@tonic-gate rval->rcv_firing_time = 0; 9020Sstevel@tonic-gate } 9030Sstevel@tonic-gate 9040Sstevel@tonic-gate static uint_t 9050Sstevel@tonic-gate rctl_val_list_count(rctl_val_t *rval) 9060Sstevel@tonic-gate { 9070Sstevel@tonic-gate uint_t n = 0; 9080Sstevel@tonic-gate 9090Sstevel@tonic-gate for (; rval != NULL; rval = rval->rcv_next) 9100Sstevel@tonic-gate n++; 9110Sstevel@tonic-gate 9120Sstevel@tonic-gate return (n); 9130Sstevel@tonic-gate } 9140Sstevel@tonic-gate 9150Sstevel@tonic-gate 9160Sstevel@tonic-gate static void 9170Sstevel@tonic-gate rctl_val_list_free(rctl_val_t *rval) 9180Sstevel@tonic-gate { 9190Sstevel@tonic-gate while (rval != NULL) { 9200Sstevel@tonic-gate rctl_val_t *next = rval->rcv_next; 9210Sstevel@tonic-gate 9220Sstevel@tonic-gate kmem_cache_free(rctl_val_cache, rval); 9230Sstevel@tonic-gate 9240Sstevel@tonic-gate rval = next; 9250Sstevel@tonic-gate } 9260Sstevel@tonic-gate } 9270Sstevel@tonic-gate 9280Sstevel@tonic-gate /* 9290Sstevel@tonic-gate * rctl_qty_t rctl_model_maximum(rctl_dict_entry_t *, struct proc *) 9300Sstevel@tonic-gate * 9310Sstevel@tonic-gate * Overview 9320Sstevel@tonic-gate * In cases where the operating system supports more than one process 9330Sstevel@tonic-gate * addressing model, the operating system capabilities will exceed those of 9340Sstevel@tonic-gate * one or more of these models. Processes in a less capable model must have 9350Sstevel@tonic-gate * their resources accurately controlled, without diluting those of their 9360Sstevel@tonic-gate * descendants reached via exec(). rctl_model_maximum() returns the governing 9370Sstevel@tonic-gate * value for the specified process with respect to a resource control, such 9380Sstevel@tonic-gate * that the value can used for the RCTLOP_SET callback or compatability 9390Sstevel@tonic-gate * support. 9400Sstevel@tonic-gate * 9410Sstevel@tonic-gate * Return values 9420Sstevel@tonic-gate * The maximum value for the given process for the specified resource control. 9430Sstevel@tonic-gate * 9440Sstevel@tonic-gate * Caller's context 9450Sstevel@tonic-gate * No restrictions on context. 9460Sstevel@tonic-gate */ 9470Sstevel@tonic-gate rctl_qty_t 9480Sstevel@tonic-gate rctl_model_maximum(rctl_dict_entry_t *rde, struct proc *p) 9490Sstevel@tonic-gate { 9500Sstevel@tonic-gate if (p->p_model == DATAMODEL_NATIVE) 9510Sstevel@tonic-gate return (rde->rcd_max_native); 9520Sstevel@tonic-gate 9530Sstevel@tonic-gate return (rde->rcd_max_ilp32); 9540Sstevel@tonic-gate } 9550Sstevel@tonic-gate 9560Sstevel@tonic-gate /* 9570Sstevel@tonic-gate * rctl_qty_t rctl_model_value(rctl_dict_entry_t *, struct proc *, rctl_qty_t) 9580Sstevel@tonic-gate * 9590Sstevel@tonic-gate * Overview 9600Sstevel@tonic-gate * Convenience function wrapping the rctl_model_maximum() functionality. 9610Sstevel@tonic-gate * 9620Sstevel@tonic-gate * Return values 9630Sstevel@tonic-gate * The lesser of the process's maximum value and the given value for the 9640Sstevel@tonic-gate * specified resource control. 9650Sstevel@tonic-gate * 9660Sstevel@tonic-gate * Caller's context 9670Sstevel@tonic-gate * No restrictions on context. 9680Sstevel@tonic-gate */ 9690Sstevel@tonic-gate rctl_qty_t 9700Sstevel@tonic-gate rctl_model_value(rctl_dict_entry_t *rde, struct proc *p, rctl_qty_t value) 9710Sstevel@tonic-gate { 9720Sstevel@tonic-gate rctl_qty_t max = rctl_model_maximum(rde, p); 9730Sstevel@tonic-gate 9740Sstevel@tonic-gate return (value < max ? value : max); 9750Sstevel@tonic-gate } 9760Sstevel@tonic-gate 9770Sstevel@tonic-gate static void 9780Sstevel@tonic-gate rctl_set_insert(rctl_set_t *set, rctl_hndl_t hndl, rctl_t *rctl) 9790Sstevel@tonic-gate { 9800Sstevel@tonic-gate uint_t index = hndl % rctl_set_size; 9810Sstevel@tonic-gate rctl_t *next_ctl, *prev_ctl; 9820Sstevel@tonic-gate 9830Sstevel@tonic-gate ASSERT(MUTEX_HELD(&set->rcs_lock)); 9840Sstevel@tonic-gate 9850Sstevel@tonic-gate rctl->rc_next = NULL; 9860Sstevel@tonic-gate 9870Sstevel@tonic-gate if (set->rcs_ctls[index] == NULL) { 9880Sstevel@tonic-gate set->rcs_ctls[index] = rctl; 9890Sstevel@tonic-gate return; 9900Sstevel@tonic-gate } 9910Sstevel@tonic-gate 9920Sstevel@tonic-gate if (hndl < set->rcs_ctls[index]->rc_id) { 9930Sstevel@tonic-gate rctl->rc_next = set->rcs_ctls[index]; 9940Sstevel@tonic-gate set->rcs_ctls[index] = rctl; 9950Sstevel@tonic-gate 9960Sstevel@tonic-gate return; 9970Sstevel@tonic-gate } 9980Sstevel@tonic-gate 9990Sstevel@tonic-gate for (next_ctl = set->rcs_ctls[index]->rc_next, 10000Sstevel@tonic-gate prev_ctl = set->rcs_ctls[index]; 10010Sstevel@tonic-gate next_ctl != NULL; 10020Sstevel@tonic-gate prev_ctl = next_ctl, 10030Sstevel@tonic-gate next_ctl = next_ctl->rc_next) { 10040Sstevel@tonic-gate if (next_ctl->rc_id > hndl) { 10050Sstevel@tonic-gate rctl->rc_next = next_ctl; 10060Sstevel@tonic-gate prev_ctl->rc_next = rctl; 10070Sstevel@tonic-gate 10080Sstevel@tonic-gate return; 10090Sstevel@tonic-gate } 10100Sstevel@tonic-gate } 10110Sstevel@tonic-gate 10120Sstevel@tonic-gate rctl->rc_next = next_ctl; 10130Sstevel@tonic-gate prev_ctl->rc_next = rctl; 10140Sstevel@tonic-gate } 10150Sstevel@tonic-gate 10160Sstevel@tonic-gate /* 10170Sstevel@tonic-gate * rctl_set_t *rctl_set_create() 10180Sstevel@tonic-gate * 10190Sstevel@tonic-gate * Overview 10200Sstevel@tonic-gate * Create an empty resource control set, suitable for attaching to a 10210Sstevel@tonic-gate * controlled entity. 10220Sstevel@tonic-gate * 10230Sstevel@tonic-gate * Return values 10240Sstevel@tonic-gate * A pointer to the newly created set. 10250Sstevel@tonic-gate * 10260Sstevel@tonic-gate * Caller's context 10270Sstevel@tonic-gate * Safe for KM_SLEEP allocations. 10280Sstevel@tonic-gate */ 10290Sstevel@tonic-gate rctl_set_t * 10300Sstevel@tonic-gate rctl_set_create() 10310Sstevel@tonic-gate { 10320Sstevel@tonic-gate rctl_set_t *rset = kmem_zalloc(sizeof (rctl_set_t), KM_SLEEP); 10330Sstevel@tonic-gate 10340Sstevel@tonic-gate mutex_init(&rset->rcs_lock, NULL, MUTEX_DEFAULT, NULL); 10350Sstevel@tonic-gate rset->rcs_ctls = kmem_zalloc(rctl_set_size * sizeof (rctl_t *), 10360Sstevel@tonic-gate KM_SLEEP); 10370Sstevel@tonic-gate rset->rcs_entity = -1; 10380Sstevel@tonic-gate 10390Sstevel@tonic-gate return (rset); 10400Sstevel@tonic-gate } 10410Sstevel@tonic-gate 10420Sstevel@tonic-gate /* 10430Sstevel@tonic-gate * rctl_gp_alloc_t *rctl_set_init_prealloc(rctl_entity_t) 10440Sstevel@tonic-gate * 10450Sstevel@tonic-gate * Overview 10460Sstevel@tonic-gate * rctl_set_init_prealloc() examines the globally defined resource controls 10470Sstevel@tonic-gate * and their default values and returns a resource control allocation group 10480Sstevel@tonic-gate * populated with sufficient controls and values to form a representative 10490Sstevel@tonic-gate * resource control set for the specified entity. 10500Sstevel@tonic-gate * 10510Sstevel@tonic-gate * Return values 10520Sstevel@tonic-gate * A pointer to the newly created allocation group. 10530Sstevel@tonic-gate * 10540Sstevel@tonic-gate * Caller's context 10550Sstevel@tonic-gate * Caller must be in a context suitable for KM_SLEEP allocations. 10560Sstevel@tonic-gate */ 10570Sstevel@tonic-gate rctl_alloc_gp_t * 10580Sstevel@tonic-gate rctl_set_init_prealloc(rctl_entity_t entity) 10590Sstevel@tonic-gate { 10600Sstevel@tonic-gate rctl_dict_entry_t *rde; 10610Sstevel@tonic-gate rctl_alloc_gp_t *ragp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP); 10620Sstevel@tonic-gate 10630Sstevel@tonic-gate ASSERT(MUTEX_NOT_HELD(&curproc->p_lock)); 10640Sstevel@tonic-gate 10650Sstevel@tonic-gate if (rctl_lists[entity] == NULL) 10660Sstevel@tonic-gate return (ragp); 10670Sstevel@tonic-gate 10680Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 10690Sstevel@tonic-gate 10700Sstevel@tonic-gate for (rde = rctl_lists[entity]; rde != NULL; rde = rde->rcd_next) { 10710Sstevel@tonic-gate ragp->rcag_nctls++; 10720Sstevel@tonic-gate ragp->rcag_nvals += rctl_val_list_count(rde->rcd_default_value); 10730Sstevel@tonic-gate } 10740Sstevel@tonic-gate 10750Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 10760Sstevel@tonic-gate 10770Sstevel@tonic-gate rctl_gp_alloc(ragp); 10780Sstevel@tonic-gate 10790Sstevel@tonic-gate return (ragp); 10800Sstevel@tonic-gate } 10810Sstevel@tonic-gate 10820Sstevel@tonic-gate /* 10830Sstevel@tonic-gate * rctl_set_t *rctl_set_init(rctl_entity_t) 10840Sstevel@tonic-gate * 10850Sstevel@tonic-gate * Overview 10860Sstevel@tonic-gate * rctl_set_create() creates a resource control set, initialized with the 10870Sstevel@tonic-gate * system infinite values on all registered controls, for attachment to a 10880Sstevel@tonic-gate * system entity requiring resource controls, such as a process or a task. 10890Sstevel@tonic-gate * 10900Sstevel@tonic-gate * Return values 10910Sstevel@tonic-gate * A pointer to the newly filled set. 10920Sstevel@tonic-gate * 10930Sstevel@tonic-gate * Caller's context 10940Sstevel@tonic-gate * Caller must be holding p_lock on entry so that RCTLOP_SET() functions 10950Sstevel@tonic-gate * may modify task and project members based on the proc structure 10960Sstevel@tonic-gate * they are passed. 10970Sstevel@tonic-gate */ 10980Sstevel@tonic-gate rctl_set_t * 10990Sstevel@tonic-gate rctl_set_init(rctl_entity_t entity, struct proc *p, rctl_entity_p_t *e, 11000Sstevel@tonic-gate rctl_set_t *rset, rctl_alloc_gp_t *ragp) 11010Sstevel@tonic-gate { 11020Sstevel@tonic-gate rctl_dict_entry_t *rde; 11030Sstevel@tonic-gate 11040Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 11050Sstevel@tonic-gate ASSERT(e); 11060Sstevel@tonic-gate rset->rcs_entity = entity; 11070Sstevel@tonic-gate 11080Sstevel@tonic-gate if (rctl_lists[entity] == NULL) 11090Sstevel@tonic-gate return (rset); 11100Sstevel@tonic-gate 11110Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 11120Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 11130Sstevel@tonic-gate 11140Sstevel@tonic-gate for (rde = rctl_lists[entity]; rde != NULL; rde = rde->rcd_next) { 11150Sstevel@tonic-gate rctl_t *rctl = rctl_gp_detach_ctl(ragp); 11160Sstevel@tonic-gate 11170Sstevel@tonic-gate rctl->rc_dict_entry = rde; 11180Sstevel@tonic-gate rctl->rc_id = rde->rcd_id; 1119*3684Srd117015 rctl->rc_projdb = NULL; 11200Sstevel@tonic-gate 11210Sstevel@tonic-gate rctl->rc_values = rctl_val_list_dup(rde->rcd_default_value, 11220Sstevel@tonic-gate ragp, NULL, p); 11230Sstevel@tonic-gate rctl->rc_cursor = rctl->rc_values; 11240Sstevel@tonic-gate 11250Sstevel@tonic-gate ASSERT(rctl->rc_cursor != NULL); 11260Sstevel@tonic-gate 11270Sstevel@tonic-gate rctl_set_insert(rset, rde->rcd_id, rctl); 11280Sstevel@tonic-gate 11290Sstevel@tonic-gate RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p, 11300Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 11310Sstevel@tonic-gate } 11320Sstevel@tonic-gate 11330Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 11340Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 11350Sstevel@tonic-gate 11360Sstevel@tonic-gate return (rset); 11370Sstevel@tonic-gate } 11380Sstevel@tonic-gate 11390Sstevel@tonic-gate static rctl_t * 11400Sstevel@tonic-gate rctl_dup(rctl_t *rctl, rctl_alloc_gp_t *ragp, struct proc *oldp, 11410Sstevel@tonic-gate struct proc *newp) 11420Sstevel@tonic-gate { 11430Sstevel@tonic-gate rctl_t *dup = rctl_gp_detach_ctl(ragp); 11440Sstevel@tonic-gate rctl_val_t *dval; 11450Sstevel@tonic-gate 11460Sstevel@tonic-gate dup->rc_id = rctl->rc_id; 11470Sstevel@tonic-gate dup->rc_dict_entry = rctl->rc_dict_entry; 11480Sstevel@tonic-gate dup->rc_next = NULL; 11490Sstevel@tonic-gate dup->rc_cursor = NULL; 11500Sstevel@tonic-gate dup->rc_values = rctl_val_list_dup(rctl->rc_values, ragp, oldp, newp); 11510Sstevel@tonic-gate 11520Sstevel@tonic-gate for (dval = dup->rc_values; 11530Sstevel@tonic-gate dval != NULL; dval = dval->rcv_next) { 11540Sstevel@tonic-gate if (rctl_val_cmp(rctl->rc_cursor, dval, 0) >= 0) { 11550Sstevel@tonic-gate dup->rc_cursor = dval; 11560Sstevel@tonic-gate break; 11570Sstevel@tonic-gate } 11580Sstevel@tonic-gate } 11590Sstevel@tonic-gate 11600Sstevel@tonic-gate if (dup->rc_cursor == NULL) 11610Sstevel@tonic-gate dup->rc_cursor = dup->rc_values; 11620Sstevel@tonic-gate 11630Sstevel@tonic-gate return (dup); 11640Sstevel@tonic-gate } 11650Sstevel@tonic-gate 11660Sstevel@tonic-gate static void 11670Sstevel@tonic-gate rctl_set_fill_alloc_gp(rctl_set_t *set, rctl_alloc_gp_t *ragp) 11680Sstevel@tonic-gate { 11690Sstevel@tonic-gate uint_t i; 11700Sstevel@tonic-gate 11710Sstevel@tonic-gate bzero(ragp, sizeof (rctl_alloc_gp_t)); 11720Sstevel@tonic-gate 11730Sstevel@tonic-gate for (i = 0; i < rctl_set_size; i++) { 11740Sstevel@tonic-gate rctl_t *r = set->rcs_ctls[i]; 11750Sstevel@tonic-gate 11760Sstevel@tonic-gate while (r != NULL) { 11770Sstevel@tonic-gate ragp->rcag_nctls++; 11780Sstevel@tonic-gate 11790Sstevel@tonic-gate ragp->rcag_nvals += rctl_val_list_count(r->rc_values); 11800Sstevel@tonic-gate 11810Sstevel@tonic-gate r = r->rc_next; 11820Sstevel@tonic-gate } 11830Sstevel@tonic-gate } 11840Sstevel@tonic-gate } 11850Sstevel@tonic-gate 11860Sstevel@tonic-gate /* 11870Sstevel@tonic-gate * rctl_alloc_gp_t *rctl_set_dup_prealloc(rctl_set_t *) 11880Sstevel@tonic-gate * 11890Sstevel@tonic-gate * Overview 11900Sstevel@tonic-gate * Given a resource control set, allocate a sufficiently large allocation 11910Sstevel@tonic-gate * group to contain a duplicate of the set. 11920Sstevel@tonic-gate * 11930Sstevel@tonic-gate * Return value 11940Sstevel@tonic-gate * A pointer to the newly created allocation group. 11950Sstevel@tonic-gate * 11960Sstevel@tonic-gate * Caller's context 11970Sstevel@tonic-gate * Safe for KM_SLEEP allocations. 11980Sstevel@tonic-gate */ 11990Sstevel@tonic-gate rctl_alloc_gp_t * 12000Sstevel@tonic-gate rctl_set_dup_prealloc(rctl_set_t *set) 12010Sstevel@tonic-gate { 12020Sstevel@tonic-gate rctl_alloc_gp_t *ragp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP); 12030Sstevel@tonic-gate 12040Sstevel@tonic-gate ASSERT(MUTEX_NOT_HELD(&curproc->p_lock)); 12050Sstevel@tonic-gate 12060Sstevel@tonic-gate mutex_enter(&set->rcs_lock); 12070Sstevel@tonic-gate rctl_set_fill_alloc_gp(set, ragp); 12080Sstevel@tonic-gate mutex_exit(&set->rcs_lock); 12090Sstevel@tonic-gate 12100Sstevel@tonic-gate rctl_gp_alloc(ragp); 12110Sstevel@tonic-gate 12120Sstevel@tonic-gate return (ragp); 12130Sstevel@tonic-gate } 12140Sstevel@tonic-gate 12150Sstevel@tonic-gate /* 12160Sstevel@tonic-gate * int rctl_set_dup_ready(rctl_set_t *, rctl_alloc_gp_t *) 12170Sstevel@tonic-gate * 12180Sstevel@tonic-gate * Overview 12190Sstevel@tonic-gate * Verify that the allocation group provided is large enough to allow a 12200Sstevel@tonic-gate * duplicate of the given resource control set to be constructed from its 12210Sstevel@tonic-gate * contents. 12220Sstevel@tonic-gate * 12230Sstevel@tonic-gate * Return values 12240Sstevel@tonic-gate * 1 if the allocation group is sufficiently large, 0 otherwise. 12250Sstevel@tonic-gate * 12260Sstevel@tonic-gate * Caller's context 12270Sstevel@tonic-gate * rcs_lock must be held prior to entry. 12280Sstevel@tonic-gate */ 12290Sstevel@tonic-gate int 12300Sstevel@tonic-gate rctl_set_dup_ready(rctl_set_t *set, rctl_alloc_gp_t *ragp) 12310Sstevel@tonic-gate { 12320Sstevel@tonic-gate rctl_alloc_gp_t curr_gp; 12330Sstevel@tonic-gate 12340Sstevel@tonic-gate ASSERT(MUTEX_HELD(&set->rcs_lock)); 12350Sstevel@tonic-gate 12360Sstevel@tonic-gate rctl_set_fill_alloc_gp(set, &curr_gp); 12370Sstevel@tonic-gate 12380Sstevel@tonic-gate if (curr_gp.rcag_nctls <= ragp->rcag_nctls && 12390Sstevel@tonic-gate curr_gp.rcag_nvals <= ragp->rcag_nvals) 12400Sstevel@tonic-gate return (1); 12410Sstevel@tonic-gate 12420Sstevel@tonic-gate return (0); 12430Sstevel@tonic-gate } 12440Sstevel@tonic-gate 12450Sstevel@tonic-gate /* 12460Sstevel@tonic-gate * rctl_set_t *rctl_set_dup(rctl_set_t *, struct proc *, struct proc *, 12470Sstevel@tonic-gate * rctl_set_t *, rctl_alloc_gp_t *, int) 12480Sstevel@tonic-gate * 12490Sstevel@tonic-gate * Overview 12500Sstevel@tonic-gate * Make a duplicate of the resource control set. The proc pointers are those 12510Sstevel@tonic-gate * of the owning process and of the process associated with the entity 12520Sstevel@tonic-gate * receiving the duplicate. 12530Sstevel@tonic-gate * 12540Sstevel@tonic-gate * Duplication is a 3 stage process. Stage 1 is memory allocation for 12550Sstevel@tonic-gate * the duplicate set, which is taken care of by rctl_set_dup_prealloc(). 12560Sstevel@tonic-gate * Stage 2 consists of copying all rctls and values from the old set into 12570Sstevel@tonic-gate * the new. Stage 3 completes the duplication by performing the appropriate 12580Sstevel@tonic-gate * callbacks for each rctl in the new set. 12590Sstevel@tonic-gate * 12600Sstevel@tonic-gate * Stages 2 and 3 are handled by calling rctl_set_dup with the RCD_DUP and 12610Sstevel@tonic-gate * RCD_CALLBACK functions, respectively. The RCD_CALLBACK flag may only 12620Sstevel@tonic-gate * be supplied if the newp proc structure reflects the new task and 12630Sstevel@tonic-gate * project linkage. 12640Sstevel@tonic-gate * 12650Sstevel@tonic-gate * Return value 12660Sstevel@tonic-gate * A pointer to the duplicate set. 12670Sstevel@tonic-gate * 12680Sstevel@tonic-gate * Caller's context 12690Sstevel@tonic-gate * The rcs_lock of the set to be duplicated must be held prior to entry. 12700Sstevel@tonic-gate */ 12710Sstevel@tonic-gate rctl_set_t * 12720Sstevel@tonic-gate rctl_set_dup(rctl_set_t *set, struct proc *oldp, struct proc *newp, 12730Sstevel@tonic-gate rctl_entity_p_t *e, rctl_set_t *dup, rctl_alloc_gp_t *ragp, int flag) 12740Sstevel@tonic-gate { 12750Sstevel@tonic-gate uint_t i; 12760Sstevel@tonic-gate rctl_set_t *iter; 12770Sstevel@tonic-gate 12780Sstevel@tonic-gate ASSERT((flag & RCD_DUP) || (flag & RCD_CALLBACK)); 12790Sstevel@tonic-gate ASSERT(e); 12800Sstevel@tonic-gate /* 12810Sstevel@tonic-gate * When copying the old set, iterate over that. Otherwise, when 12820Sstevel@tonic-gate * only callbacks have been requested, iterate over the dup set. 12830Sstevel@tonic-gate */ 12840Sstevel@tonic-gate if (flag & RCD_DUP) { 12850Sstevel@tonic-gate ASSERT(MUTEX_HELD(&set->rcs_lock)); 12860Sstevel@tonic-gate iter = set; 12870Sstevel@tonic-gate dup->rcs_entity = set->rcs_entity; 12880Sstevel@tonic-gate } else { 12890Sstevel@tonic-gate iter = dup; 12900Sstevel@tonic-gate } 12910Sstevel@tonic-gate 12920Sstevel@tonic-gate mutex_enter(&dup->rcs_lock); 12930Sstevel@tonic-gate 12940Sstevel@tonic-gate for (i = 0; i < rctl_set_size; i++) { 12950Sstevel@tonic-gate rctl_t *r = iter->rcs_ctls[i]; 12960Sstevel@tonic-gate rctl_t *d; 12970Sstevel@tonic-gate 12980Sstevel@tonic-gate while (r != NULL) { 12990Sstevel@tonic-gate if (flag & RCD_DUP) { 13000Sstevel@tonic-gate d = rctl_dup(r, ragp, oldp, newp); 13010Sstevel@tonic-gate rctl_set_insert(dup, r->rc_id, d); 13020Sstevel@tonic-gate } else { 13030Sstevel@tonic-gate d = r; 13040Sstevel@tonic-gate } 13050Sstevel@tonic-gate 13060Sstevel@tonic-gate if (flag & RCD_CALLBACK) 13070Sstevel@tonic-gate RCTLOP_SET(d, newp, e, 13080Sstevel@tonic-gate rctl_model_value(d->rc_dict_entry, newp, 13090Sstevel@tonic-gate d->rc_cursor->rcv_value)); 13100Sstevel@tonic-gate 13110Sstevel@tonic-gate r = r->rc_next; 13120Sstevel@tonic-gate } 13130Sstevel@tonic-gate } 13140Sstevel@tonic-gate 13150Sstevel@tonic-gate mutex_exit(&dup->rcs_lock); 13160Sstevel@tonic-gate 13170Sstevel@tonic-gate return (dup); 13180Sstevel@tonic-gate } 13190Sstevel@tonic-gate 13200Sstevel@tonic-gate /* 13210Sstevel@tonic-gate * void rctl_set_free(rctl_set_t *) 13220Sstevel@tonic-gate * 13230Sstevel@tonic-gate * Overview 13240Sstevel@tonic-gate * Delete resource control set and all attached values. 13250Sstevel@tonic-gate * 13260Sstevel@tonic-gate * Return values 13270Sstevel@tonic-gate * No value returned. 13280Sstevel@tonic-gate * 13290Sstevel@tonic-gate * Caller's context 13300Sstevel@tonic-gate * No restrictions on context. 13310Sstevel@tonic-gate */ 13320Sstevel@tonic-gate void 13330Sstevel@tonic-gate rctl_set_free(rctl_set_t *set) 13340Sstevel@tonic-gate { 13350Sstevel@tonic-gate uint_t i; 13360Sstevel@tonic-gate 13370Sstevel@tonic-gate mutex_enter(&set->rcs_lock); 13380Sstevel@tonic-gate for (i = 0; i < rctl_set_size; i++) { 13390Sstevel@tonic-gate rctl_t *r = set->rcs_ctls[i]; 13400Sstevel@tonic-gate 13410Sstevel@tonic-gate while (r != NULL) { 13420Sstevel@tonic-gate rctl_val_t *v = r->rc_values; 13430Sstevel@tonic-gate rctl_t *n = r->rc_next; 13440Sstevel@tonic-gate 13450Sstevel@tonic-gate kmem_cache_free(rctl_cache, r); 13460Sstevel@tonic-gate 13470Sstevel@tonic-gate rctl_val_list_free(v); 13480Sstevel@tonic-gate 13490Sstevel@tonic-gate r = n; 13500Sstevel@tonic-gate } 13510Sstevel@tonic-gate } 13520Sstevel@tonic-gate mutex_exit(&set->rcs_lock); 13530Sstevel@tonic-gate 13540Sstevel@tonic-gate kmem_free(set->rcs_ctls, sizeof (rctl_t *) * rctl_set_size); 13550Sstevel@tonic-gate kmem_free(set, sizeof (rctl_set_t)); 13560Sstevel@tonic-gate } 13570Sstevel@tonic-gate 13580Sstevel@tonic-gate /* 13590Sstevel@tonic-gate * void rctl_set_reset(rctl_set_t *) 13600Sstevel@tonic-gate * 13610Sstevel@tonic-gate * Overview 13620Sstevel@tonic-gate * Resets all rctls within the set such that the lowest value becomes active. 13630Sstevel@tonic-gate * 13640Sstevel@tonic-gate * Return values 13650Sstevel@tonic-gate * No value returned. 13660Sstevel@tonic-gate * 13670Sstevel@tonic-gate * Caller's context 13680Sstevel@tonic-gate * No restrictions on context. 13690Sstevel@tonic-gate */ 13700Sstevel@tonic-gate void 13710Sstevel@tonic-gate rctl_set_reset(rctl_set_t *set, struct proc *p, rctl_entity_p_t *e) 13720Sstevel@tonic-gate { 13730Sstevel@tonic-gate uint_t i; 13740Sstevel@tonic-gate 13750Sstevel@tonic-gate ASSERT(e); 13760Sstevel@tonic-gate 13770Sstevel@tonic-gate mutex_enter(&set->rcs_lock); 13780Sstevel@tonic-gate for (i = 0; i < rctl_set_size; i++) { 13790Sstevel@tonic-gate rctl_t *r = set->rcs_ctls[i]; 13800Sstevel@tonic-gate 13810Sstevel@tonic-gate while (r != NULL) { 13820Sstevel@tonic-gate r->rc_cursor = r->rc_values; 13830Sstevel@tonic-gate rctl_val_list_reset(r->rc_cursor); 13840Sstevel@tonic-gate RCTLOP_SET(r, p, e, rctl_model_value(r->rc_dict_entry, 13850Sstevel@tonic-gate p, r->rc_cursor->rcv_value)); 13860Sstevel@tonic-gate 13870Sstevel@tonic-gate ASSERT(r->rc_cursor != NULL); 13880Sstevel@tonic-gate 13890Sstevel@tonic-gate r = r->rc_next; 13900Sstevel@tonic-gate } 13910Sstevel@tonic-gate } 13920Sstevel@tonic-gate 13930Sstevel@tonic-gate mutex_exit(&set->rcs_lock); 13940Sstevel@tonic-gate } 13950Sstevel@tonic-gate 13960Sstevel@tonic-gate /* 13970Sstevel@tonic-gate * void rctl_set_tearoff(rctl_set *, struct proc *) 13980Sstevel@tonic-gate * 13990Sstevel@tonic-gate * Overview 14000Sstevel@tonic-gate * Tear off any resource control values on this set with an action recipient 14010Sstevel@tonic-gate * equal to the specified process (as they are becoming invalid with the 14020Sstevel@tonic-gate * process's departure from this set as an observer). 14030Sstevel@tonic-gate * 14040Sstevel@tonic-gate * Return values 14050Sstevel@tonic-gate * No value returned. 14060Sstevel@tonic-gate * 14070Sstevel@tonic-gate * Caller's context 14080Sstevel@tonic-gate * No restrictions on context 14090Sstevel@tonic-gate */ 14100Sstevel@tonic-gate void 14110Sstevel@tonic-gate rctl_set_tearoff(rctl_set_t *set, struct proc *p) 14120Sstevel@tonic-gate { 14130Sstevel@tonic-gate uint_t i; 14140Sstevel@tonic-gate 14150Sstevel@tonic-gate mutex_enter(&set->rcs_lock); 14160Sstevel@tonic-gate for (i = 0; i < rctl_set_size; i++) { 14170Sstevel@tonic-gate rctl_t *r = set->rcs_ctls[i]; 14180Sstevel@tonic-gate 14190Sstevel@tonic-gate while (r != NULL) { 14200Sstevel@tonic-gate rctl_val_t *rval; 14210Sstevel@tonic-gate 14220Sstevel@tonic-gate tearoff_rewalk_list: 14230Sstevel@tonic-gate rval = r->rc_values; 14240Sstevel@tonic-gate 14250Sstevel@tonic-gate while (rval != NULL) { 14260Sstevel@tonic-gate if (rval->rcv_privilege == RCPRIV_BASIC && 14270Sstevel@tonic-gate rval->rcv_action_recipient == p) { 14280Sstevel@tonic-gate if (r->rc_cursor == rval) 14290Sstevel@tonic-gate r->rc_cursor = rval->rcv_next; 14300Sstevel@tonic-gate 14310Sstevel@tonic-gate (void) rctl_val_list_delete( 14320Sstevel@tonic-gate &r->rc_values, rval); 14330Sstevel@tonic-gate 14340Sstevel@tonic-gate goto tearoff_rewalk_list; 14350Sstevel@tonic-gate } 14360Sstevel@tonic-gate 14370Sstevel@tonic-gate rval = rval->rcv_next; 14380Sstevel@tonic-gate } 14390Sstevel@tonic-gate 14400Sstevel@tonic-gate ASSERT(r->rc_cursor != NULL); 14410Sstevel@tonic-gate 14420Sstevel@tonic-gate r = r->rc_next; 14430Sstevel@tonic-gate } 14440Sstevel@tonic-gate } 14450Sstevel@tonic-gate 14460Sstevel@tonic-gate mutex_exit(&set->rcs_lock); 14470Sstevel@tonic-gate } 14480Sstevel@tonic-gate 14490Sstevel@tonic-gate static int 14500Sstevel@tonic-gate rctl_set_find(rctl_set_t *set, rctl_hndl_t hndl, rctl_t **rctl) 14510Sstevel@tonic-gate { 14520Sstevel@tonic-gate uint_t index = hndl % rctl_set_size; 14530Sstevel@tonic-gate rctl_t *curr_ctl; 14540Sstevel@tonic-gate 14550Sstevel@tonic-gate ASSERT(MUTEX_HELD(&set->rcs_lock)); 14560Sstevel@tonic-gate 14570Sstevel@tonic-gate for (curr_ctl = set->rcs_ctls[index]; curr_ctl != NULL; 14580Sstevel@tonic-gate curr_ctl = curr_ctl->rc_next) { 14590Sstevel@tonic-gate if (curr_ctl->rc_id == hndl) { 14600Sstevel@tonic-gate *rctl = curr_ctl; 14610Sstevel@tonic-gate 14620Sstevel@tonic-gate return (0); 14630Sstevel@tonic-gate } 14640Sstevel@tonic-gate } 14650Sstevel@tonic-gate 14660Sstevel@tonic-gate return (-1); 14670Sstevel@tonic-gate } 14680Sstevel@tonic-gate 14690Sstevel@tonic-gate /* 14700Sstevel@tonic-gate * rlim64_t rctl_enforced_value(rctl_hndl_t, rctl_set_t *, struct proc *) 14710Sstevel@tonic-gate * 14720Sstevel@tonic-gate * Overview 14730Sstevel@tonic-gate * Given a process, get the next enforced value on the rctl of the specified 14740Sstevel@tonic-gate * handle. 14750Sstevel@tonic-gate * 14760Sstevel@tonic-gate * Return value 14770Sstevel@tonic-gate * The enforced value. 14780Sstevel@tonic-gate * 14790Sstevel@tonic-gate * Caller's context 14800Sstevel@tonic-gate * For controls on process collectives, p->p_lock must be held across the 14810Sstevel@tonic-gate * operation. 14820Sstevel@tonic-gate */ 14830Sstevel@tonic-gate /*ARGSUSED*/ 14840Sstevel@tonic-gate rctl_qty_t 14850Sstevel@tonic-gate rctl_enforced_value(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p) 14860Sstevel@tonic-gate { 14870Sstevel@tonic-gate rctl_t *rctl; 14880Sstevel@tonic-gate rlim64_t ret; 14890Sstevel@tonic-gate 14900Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 14910Sstevel@tonic-gate 14920Sstevel@tonic-gate if (rctl_set_find(rset, hndl, &rctl) == -1) 14930Sstevel@tonic-gate panic("unknown resource control handle %d requested", hndl); 14940Sstevel@tonic-gate else 14950Sstevel@tonic-gate ret = rctl_model_value(rctl->rc_dict_entry, p, 14960Sstevel@tonic-gate rctl->rc_cursor->rcv_value); 14970Sstevel@tonic-gate 14980Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 14990Sstevel@tonic-gate 15000Sstevel@tonic-gate return (ret); 15010Sstevel@tonic-gate } 15020Sstevel@tonic-gate 15030Sstevel@tonic-gate /* 15040Sstevel@tonic-gate * int rctl_global_get(const char *, rctl_dict_entry_t *) 15050Sstevel@tonic-gate * 15060Sstevel@tonic-gate * Overview 15070Sstevel@tonic-gate * Copy a sanitized version of the global rctl for a given resource control 15080Sstevel@tonic-gate * name. (By sanitization, we mean that the unsafe data pointers have been 15090Sstevel@tonic-gate * zeroed.) 15100Sstevel@tonic-gate * 15110Sstevel@tonic-gate * Return value 15120Sstevel@tonic-gate * -1 if name not defined, 0 otherwise. 15130Sstevel@tonic-gate * 15140Sstevel@tonic-gate * Caller's context 15150Sstevel@tonic-gate * No restrictions on context. rctl_dict_lock must not be held. 15160Sstevel@tonic-gate */ 15170Sstevel@tonic-gate int 15180Sstevel@tonic-gate rctl_global_get(const char *name, rctl_dict_entry_t *drde) 15190Sstevel@tonic-gate { 15200Sstevel@tonic-gate rctl_dict_entry_t *rde = rctl_dict_lookup(name); 15210Sstevel@tonic-gate 15220Sstevel@tonic-gate if (rde == NULL) 15230Sstevel@tonic-gate return (-1); 15240Sstevel@tonic-gate 15250Sstevel@tonic-gate bcopy(rde, drde, sizeof (rctl_dict_entry_t)); 15260Sstevel@tonic-gate 15270Sstevel@tonic-gate drde->rcd_next = NULL; 15280Sstevel@tonic-gate drde->rcd_ops = NULL; 15290Sstevel@tonic-gate 15300Sstevel@tonic-gate return (0); 15310Sstevel@tonic-gate } 15320Sstevel@tonic-gate 15330Sstevel@tonic-gate /* 15340Sstevel@tonic-gate * int rctl_global_set(const char *, rctl_dict_entry_t *) 15350Sstevel@tonic-gate * 15360Sstevel@tonic-gate * Overview 15370Sstevel@tonic-gate * Transfer the settable fields of the named rctl to the global rctl matching 15380Sstevel@tonic-gate * the given resource control name. 15390Sstevel@tonic-gate * 15400Sstevel@tonic-gate * Return value 15410Sstevel@tonic-gate * -1 if name not defined, 0 otherwise. 15420Sstevel@tonic-gate * 15430Sstevel@tonic-gate * Caller's context 15440Sstevel@tonic-gate * No restrictions on context. rctl_dict_lock must not be held. 15450Sstevel@tonic-gate */ 15460Sstevel@tonic-gate int 15470Sstevel@tonic-gate rctl_global_set(const char *name, rctl_dict_entry_t *drde) 15480Sstevel@tonic-gate { 15490Sstevel@tonic-gate rctl_dict_entry_t *rde = rctl_dict_lookup(name); 15500Sstevel@tonic-gate 15510Sstevel@tonic-gate if (rde == NULL) 15520Sstevel@tonic-gate return (-1); 15530Sstevel@tonic-gate 15540Sstevel@tonic-gate rde->rcd_flagaction = drde->rcd_flagaction; 15550Sstevel@tonic-gate rde->rcd_syslog_level = drde->rcd_syslog_level; 15560Sstevel@tonic-gate rde->rcd_strlog_flags = drde->rcd_strlog_flags; 15570Sstevel@tonic-gate 15580Sstevel@tonic-gate return (0); 15590Sstevel@tonic-gate } 15600Sstevel@tonic-gate 15610Sstevel@tonic-gate static int 15620Sstevel@tonic-gate rctl_local_op(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval, 15630Sstevel@tonic-gate int (*cbop)(rctl_hndl_t, struct proc *p, rctl_entity_p_t *e, rctl_t *, 15640Sstevel@tonic-gate rctl_val_t *, rctl_val_t *), struct proc *p) 15650Sstevel@tonic-gate { 15660Sstevel@tonic-gate rctl_t *rctl; 15670Sstevel@tonic-gate rctl_set_t *rset; 15680Sstevel@tonic-gate rctl_entity_p_t e; 15690Sstevel@tonic-gate int ret = 0; 15700Sstevel@tonic-gate rctl_dict_entry_t *rde = rctl_dict_lookup_hndl(hndl); 15710Sstevel@tonic-gate 15720Sstevel@tonic-gate local_op_retry: 15730Sstevel@tonic-gate 15740Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 15750Sstevel@tonic-gate 15760Sstevel@tonic-gate rset = rctl_entity_obtain_rset(rde, p); 15770Sstevel@tonic-gate 15780Sstevel@tonic-gate if (rset == NULL) { 15790Sstevel@tonic-gate return (-1); 15800Sstevel@tonic-gate } 15810Sstevel@tonic-gate rctl_entity_obtain_entity_p(rset->rcs_entity, p, &e); 15820Sstevel@tonic-gate 15830Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 15840Sstevel@tonic-gate 15850Sstevel@tonic-gate /* using rctl's hndl, get rctl from local set */ 15860Sstevel@tonic-gate if (rctl_set_find(rset, hndl, &rctl) == -1) { 15870Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 15880Sstevel@tonic-gate return (-1); 15890Sstevel@tonic-gate } 15900Sstevel@tonic-gate 15910Sstevel@tonic-gate ret = cbop(hndl, p, &e, rctl, oval, nval); 15920Sstevel@tonic-gate 15930Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 15940Sstevel@tonic-gate return (ret); 15950Sstevel@tonic-gate } 15960Sstevel@tonic-gate 15970Sstevel@tonic-gate /*ARGSUSED*/ 15980Sstevel@tonic-gate static int 15990Sstevel@tonic-gate rctl_local_get_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 16000Sstevel@tonic-gate rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval) 16010Sstevel@tonic-gate { 16020Sstevel@tonic-gate if (oval == NULL) { 16030Sstevel@tonic-gate /* 16040Sstevel@tonic-gate * RCTL_FIRST 16050Sstevel@tonic-gate */ 16060Sstevel@tonic-gate bcopy(rctl->rc_values, nval, sizeof (rctl_val_t)); 16070Sstevel@tonic-gate } else { 16080Sstevel@tonic-gate /* 16090Sstevel@tonic-gate * RCTL_NEXT 16100Sstevel@tonic-gate */ 16110Sstevel@tonic-gate rctl_val_t *tval = rctl_val_list_find(&rctl->rc_values, oval); 16120Sstevel@tonic-gate 16130Sstevel@tonic-gate if (tval == NULL) 16140Sstevel@tonic-gate return (ESRCH); 16150Sstevel@tonic-gate else if (tval->rcv_next == NULL) 16160Sstevel@tonic-gate return (ENOENT); 16170Sstevel@tonic-gate else 16180Sstevel@tonic-gate bcopy(tval->rcv_next, nval, sizeof (rctl_val_t)); 16190Sstevel@tonic-gate } 16200Sstevel@tonic-gate 16210Sstevel@tonic-gate return (0); 16220Sstevel@tonic-gate } 16230Sstevel@tonic-gate 16240Sstevel@tonic-gate /* 16250Sstevel@tonic-gate * int rctl_local_get(rctl_hndl_t, rctl_val_t *) 16260Sstevel@tonic-gate * 16270Sstevel@tonic-gate * Overview 16280Sstevel@tonic-gate * Get the rctl value for the given flags. 16290Sstevel@tonic-gate * 16300Sstevel@tonic-gate * Return values 16310Sstevel@tonic-gate * 0 for successful get, errno otherwise. 16320Sstevel@tonic-gate */ 16330Sstevel@tonic-gate int 16340Sstevel@tonic-gate rctl_local_get(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval, 16350Sstevel@tonic-gate struct proc *p) 16360Sstevel@tonic-gate { 16370Sstevel@tonic-gate return (rctl_local_op(hndl, oval, nval, rctl_local_get_cb, p)); 16380Sstevel@tonic-gate } 16390Sstevel@tonic-gate 16400Sstevel@tonic-gate /*ARGSUSED*/ 16410Sstevel@tonic-gate static int 16420Sstevel@tonic-gate rctl_local_delete_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 16430Sstevel@tonic-gate rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval) 16440Sstevel@tonic-gate { 16450Sstevel@tonic-gate if ((oval = rctl_val_list_find(&rctl->rc_values, nval)) == NULL) 16460Sstevel@tonic-gate return (ESRCH); 16470Sstevel@tonic-gate 16480Sstevel@tonic-gate if (rctl->rc_cursor == oval) { 16490Sstevel@tonic-gate rctl->rc_cursor = oval->rcv_next; 16500Sstevel@tonic-gate rctl_val_list_reset(rctl->rc_cursor); 16510Sstevel@tonic-gate RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p, 16520Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 16530Sstevel@tonic-gate 16540Sstevel@tonic-gate ASSERT(rctl->rc_cursor != NULL); 16550Sstevel@tonic-gate } 16560Sstevel@tonic-gate 16570Sstevel@tonic-gate (void) rctl_val_list_delete(&rctl->rc_values, oval); 16580Sstevel@tonic-gate 16590Sstevel@tonic-gate return (0); 16600Sstevel@tonic-gate } 16610Sstevel@tonic-gate 16620Sstevel@tonic-gate /* 16630Sstevel@tonic-gate * int rctl_local_delete(rctl_hndl_t, rctl_val_t *) 16640Sstevel@tonic-gate * 16650Sstevel@tonic-gate * Overview 16660Sstevel@tonic-gate * Delete the rctl value for the given flags. 16670Sstevel@tonic-gate * 16680Sstevel@tonic-gate * Return values 16690Sstevel@tonic-gate * 0 for successful delete, errno otherwise. 16700Sstevel@tonic-gate */ 16710Sstevel@tonic-gate int 16720Sstevel@tonic-gate rctl_local_delete(rctl_hndl_t hndl, rctl_val_t *val, struct proc *p) 16730Sstevel@tonic-gate { 16740Sstevel@tonic-gate return (rctl_local_op(hndl, NULL, val, rctl_local_delete_cb, p)); 16750Sstevel@tonic-gate } 16760Sstevel@tonic-gate 16770Sstevel@tonic-gate /* 16780Sstevel@tonic-gate * rctl_local_insert_cb() 16790Sstevel@tonic-gate * 16800Sstevel@tonic-gate * Overview 16810Sstevel@tonic-gate * Insert a new value into the rctl's val list. If an error occurs, 16820Sstevel@tonic-gate * the val list must be left in the same state as when the function 16830Sstevel@tonic-gate * was entered. 16840Sstevel@tonic-gate * 16850Sstevel@tonic-gate * Return Values 16860Sstevel@tonic-gate * 0 for successful insert, EINVAL if the value is duplicated in the 16870Sstevel@tonic-gate * existing list. 16880Sstevel@tonic-gate */ 16890Sstevel@tonic-gate /*ARGSUSED*/ 16900Sstevel@tonic-gate static int 16910Sstevel@tonic-gate rctl_local_insert_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 16920Sstevel@tonic-gate rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval) 16930Sstevel@tonic-gate { 16940Sstevel@tonic-gate /* 16950Sstevel@tonic-gate * Before inserting, confirm there are no duplicates of this value 16960Sstevel@tonic-gate * and flag level. If there is a duplicate, flag an error and do 16970Sstevel@tonic-gate * nothing. 16980Sstevel@tonic-gate */ 16990Sstevel@tonic-gate if (rctl_val_list_insert(&rctl->rc_values, nval) != 0) 17000Sstevel@tonic-gate return (EINVAL); 17010Sstevel@tonic-gate 17020Sstevel@tonic-gate if (rctl_val_cmp(nval, rctl->rc_cursor, 0) < 0) { 17030Sstevel@tonic-gate rctl->rc_cursor = nval; 17040Sstevel@tonic-gate rctl_val_list_reset(rctl->rc_cursor); 17050Sstevel@tonic-gate RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p, 17060Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 17070Sstevel@tonic-gate 17080Sstevel@tonic-gate ASSERT(rctl->rc_cursor != NULL); 17090Sstevel@tonic-gate } 17100Sstevel@tonic-gate 17110Sstevel@tonic-gate return (0); 17120Sstevel@tonic-gate } 17130Sstevel@tonic-gate 17140Sstevel@tonic-gate /* 17150Sstevel@tonic-gate * int rctl_local_insert(rctl_hndl_t, rctl_val_t *) 17160Sstevel@tonic-gate * 17170Sstevel@tonic-gate * Overview 17180Sstevel@tonic-gate * Insert the rctl value into the appropriate rctl set for the calling 17190Sstevel@tonic-gate * process, given the handle. 17200Sstevel@tonic-gate */ 17210Sstevel@tonic-gate int 17220Sstevel@tonic-gate rctl_local_insert(rctl_hndl_t hndl, rctl_val_t *val, struct proc *p) 17230Sstevel@tonic-gate { 17240Sstevel@tonic-gate return (rctl_local_op(hndl, NULL, val, rctl_local_insert_cb, p)); 17250Sstevel@tonic-gate } 17260Sstevel@tonic-gate 1727*3684Srd117015 /* 1728*3684Srd117015 * rctl_local_insert_all_cb() 1729*3684Srd117015 * 1730*3684Srd117015 * Overview 1731*3684Srd117015 * Called for RCENTITY_PROJECT rctls only, via rctlsys_projset(). 1732*3684Srd117015 * 1733*3684Srd117015 * Inserts new values from the project database (new_values). alloc_values 1734*3684Srd117015 * should be a linked list of pre-allocated rctl_val_t, which are used to 1735*3684Srd117015 * populate (rc_projdb). 1736*3684Srd117015 * 1737*3684Srd117015 * Should the *new_values linked list match the contents of the rctl's 1738*3684Srd117015 * rp_projdb then we do nothing. 1739*3684Srd117015 * 1740*3684Srd117015 * Return Values 1741*3684Srd117015 * 0 is always returned. 1742*3684Srd117015 */ 1743*3684Srd117015 /*ARGSUSED*/ 1744*3684Srd117015 static int 1745*3684Srd117015 rctl_local_insert_all_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 1746*3684Srd117015 rctl_t *rctl, rctl_val_t *new_values, rctl_val_t *alloc_values) 1747*3684Srd117015 { 1748*3684Srd117015 rctl_val_t *val; 1749*3684Srd117015 rctl_val_t *tmp_val; 1750*3684Srd117015 rctl_val_t *next; 1751*3684Srd117015 int modified = 0; 1752*3684Srd117015 1753*3684Srd117015 /* 1754*3684Srd117015 * If this the first time we've set this project rctl, then we delete 1755*3684Srd117015 * all the privilege values. These privilege values have been set by 1756*3684Srd117015 * rctl_add_default_limit(). 1757*3684Srd117015 * 1758*3684Srd117015 * We save some cycles here by not calling rctl_val_list_delete(). 1759*3684Srd117015 */ 1760*3684Srd117015 if (rctl->rc_projdb == NULL) { 1761*3684Srd117015 val = rctl->rc_values; 1762*3684Srd117015 1763*3684Srd117015 while (val != NULL) { 1764*3684Srd117015 if (val->rcv_privilege == RCPRIV_PRIVILEGED) { 1765*3684Srd117015 if (val->rcv_prev != NULL) 1766*3684Srd117015 val->rcv_prev->rcv_next = val->rcv_next; 1767*3684Srd117015 else 1768*3684Srd117015 rctl->rc_values = val->rcv_next; 1769*3684Srd117015 1770*3684Srd117015 if (val->rcv_next != NULL) 1771*3684Srd117015 val->rcv_next->rcv_prev = val->rcv_prev; 1772*3684Srd117015 1773*3684Srd117015 tmp_val = val; 1774*3684Srd117015 val = val->rcv_next; 1775*3684Srd117015 kmem_cache_free(rctl_val_cache, tmp_val); 1776*3684Srd117015 } else { 1777*3684Srd117015 val = val->rcv_next; 1778*3684Srd117015 } 1779*3684Srd117015 } 1780*3684Srd117015 modified = 1; 1781*3684Srd117015 } 1782*3684Srd117015 1783*3684Srd117015 /* 1784*3684Srd117015 * Delete active values previously set through the project database. 1785*3684Srd117015 */ 1786*3684Srd117015 val = rctl->rc_projdb; 1787*3684Srd117015 1788*3684Srd117015 while (val != NULL) { 1789*3684Srd117015 1790*3684Srd117015 /* Is the old value found in the new values? */ 1791*3684Srd117015 if (rctl_val_list_find(&new_values, val) == NULL) { 1792*3684Srd117015 1793*3684Srd117015 /* 1794*3684Srd117015 * Delete from the active values if it originated from 1795*3684Srd117015 * the project database. 1796*3684Srd117015 */ 1797*3684Srd117015 if (((tmp_val = rctl_val_list_find(&rctl->rc_values, 1798*3684Srd117015 val)) != NULL) && 1799*3684Srd117015 (tmp_val->rcv_flagaction & RCTL_LOCAL_PROJDB)) { 1800*3684Srd117015 (void) rctl_val_list_delete(&rctl->rc_values, 1801*3684Srd117015 tmp_val); 1802*3684Srd117015 } 1803*3684Srd117015 1804*3684Srd117015 tmp_val = val->rcv_next; 1805*3684Srd117015 (void) rctl_val_list_delete(&rctl->rc_projdb, val); 1806*3684Srd117015 val = tmp_val; 1807*3684Srd117015 modified = 1; 1808*3684Srd117015 1809*3684Srd117015 } else 1810*3684Srd117015 val = val->rcv_next; 1811*3684Srd117015 } 1812*3684Srd117015 1813*3684Srd117015 /* 1814*3684Srd117015 * Insert new values from the project database. 1815*3684Srd117015 */ 1816*3684Srd117015 while (new_values != NULL) { 1817*3684Srd117015 next = new_values->rcv_next; 1818*3684Srd117015 1819*3684Srd117015 /* 1820*3684Srd117015 * Insert this new value into the rc_projdb, and duplicate this 1821*3684Srd117015 * entry to the active list. 1822*3684Srd117015 */ 1823*3684Srd117015 if (rctl_val_list_insert(&rctl->rc_projdb, new_values) == 0) { 1824*3684Srd117015 1825*3684Srd117015 tmp_val = alloc_values->rcv_next; 1826*3684Srd117015 bcopy(new_values, alloc_values, sizeof (rctl_val_t)); 1827*3684Srd117015 alloc_values->rcv_next = tmp_val; 1828*3684Srd117015 1829*3684Srd117015 if (rctl_val_list_insert(&rctl->rc_values, 1830*3684Srd117015 alloc_values) == 0) { 1831*3684Srd117015 /* inserted move alloc_values on */ 1832*3684Srd117015 alloc_values = tmp_val; 1833*3684Srd117015 modified = 1; 1834*3684Srd117015 } 1835*3684Srd117015 } else { 1836*3684Srd117015 /* 1837*3684Srd117015 * Unlike setrctl() we don't want to return an error on 1838*3684Srd117015 * a duplicate entry; we are concerned solely with 1839*3684Srd117015 * ensuring that all the values specified are set. 1840*3684Srd117015 */ 1841*3684Srd117015 kmem_cache_free(rctl_val_cache, new_values); 1842*3684Srd117015 } 1843*3684Srd117015 new_values = next; 1844*3684Srd117015 } 1845*3684Srd117015 1846*3684Srd117015 /* Teardown any unused rctl_val_t */ 1847*3684Srd117015 while (alloc_values != NULL) { 1848*3684Srd117015 tmp_val = alloc_values; 1849*3684Srd117015 alloc_values = alloc_values->rcv_next; 1850*3684Srd117015 kmem_cache_free(rctl_val_cache, tmp_val); 1851*3684Srd117015 } 1852*3684Srd117015 1853*3684Srd117015 /* Reset the cursor if rctl values have been modified */ 1854*3684Srd117015 if (modified) { 1855*3684Srd117015 rctl->rc_cursor = rctl->rc_values; 1856*3684Srd117015 rctl_val_list_reset(rctl->rc_cursor); 1857*3684Srd117015 RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p, 1858*3684Srd117015 rctl->rc_cursor->rcv_value)); 1859*3684Srd117015 } 1860*3684Srd117015 1861*3684Srd117015 return (0); 1862*3684Srd117015 } 1863*3684Srd117015 1864*3684Srd117015 int 1865*3684Srd117015 rctl_local_insert_all(rctl_hndl_t hndl, rctl_val_t *new_values, 1866*3684Srd117015 rctl_val_t *alloc_values, struct proc *p) 1867*3684Srd117015 { 1868*3684Srd117015 return (rctl_local_op(hndl, new_values, alloc_values, 1869*3684Srd117015 rctl_local_insert_all_cb, p)); 1870*3684Srd117015 } 1871*3684Srd117015 1872*3684Srd117015 /* 1873*3684Srd117015 * rctl_local_replace_all_cb() 1874*3684Srd117015 * 1875*3684Srd117015 * Overview 1876*3684Srd117015 * Called for RCENTITY_PROJECT rctls only, via rctlsys_projset(). 1877*3684Srd117015 * 1878*3684Srd117015 * Clears the active rctl values (rc_values), and stored values from the 1879*3684Srd117015 * previous insertions from the project database (rc_projdb). 1880*3684Srd117015 * 1881*3684Srd117015 * Inserts new values from the project database (new_values). alloc_values 1882*3684Srd117015 * should be a linked list of pre-allocated rctl_val_t, which are used to 1883*3684Srd117015 * populate (rc_projdb). 1884*3684Srd117015 * 1885*3684Srd117015 * Return Values 1886*3684Srd117015 * 0 is always returned. 1887*3684Srd117015 */ 1888*3684Srd117015 /*ARGSUSED*/ 1889*3684Srd117015 static int 1890*3684Srd117015 rctl_local_replace_all_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 1891*3684Srd117015 rctl_t *rctl, rctl_val_t *new_values, rctl_val_t *alloc_values) 1892*3684Srd117015 { 1893*3684Srd117015 rctl_val_t *val; 1894*3684Srd117015 rctl_val_t *next; 1895*3684Srd117015 rctl_val_t *tmp_val; 1896*3684Srd117015 1897*3684Srd117015 /* Delete all the privilege vaules */ 1898*3684Srd117015 val = rctl->rc_values; 1899*3684Srd117015 1900*3684Srd117015 while (val != NULL) { 1901*3684Srd117015 if (val->rcv_privilege == RCPRIV_PRIVILEGED) { 1902*3684Srd117015 if (val->rcv_prev != NULL) 1903*3684Srd117015 val->rcv_prev->rcv_next = val->rcv_next; 1904*3684Srd117015 else 1905*3684Srd117015 rctl->rc_values = val->rcv_next; 1906*3684Srd117015 1907*3684Srd117015 if (val->rcv_next != NULL) 1908*3684Srd117015 val->rcv_next->rcv_prev = val->rcv_prev; 1909*3684Srd117015 1910*3684Srd117015 tmp_val = val; 1911*3684Srd117015 val = val->rcv_next; 1912*3684Srd117015 kmem_cache_free(rctl_val_cache, tmp_val); 1913*3684Srd117015 } else { 1914*3684Srd117015 val = val->rcv_next; 1915*3684Srd117015 } 1916*3684Srd117015 } 1917*3684Srd117015 1918*3684Srd117015 /* Delete the contents of rc_projdb */ 1919*3684Srd117015 val = rctl->rc_projdb; 1920*3684Srd117015 while (val != NULL) { 1921*3684Srd117015 1922*3684Srd117015 tmp_val = val; 1923*3684Srd117015 val = val->rcv_next; 1924*3684Srd117015 kmem_cache_free(rctl_val_cache, tmp_val); 1925*3684Srd117015 } 1926*3684Srd117015 rctl->rc_projdb = NULL; 1927*3684Srd117015 1928*3684Srd117015 /* 1929*3684Srd117015 * Insert new values from the project database. 1930*3684Srd117015 */ 1931*3684Srd117015 while (new_values != NULL) { 1932*3684Srd117015 next = new_values->rcv_next; 1933*3684Srd117015 1934*3684Srd117015 if (rctl_val_list_insert(&rctl->rc_projdb, new_values) == 0) { 1935*3684Srd117015 tmp_val = alloc_values->rcv_next; 1936*3684Srd117015 bcopy(new_values, alloc_values, sizeof (rctl_val_t)); 1937*3684Srd117015 alloc_values->rcv_next = tmp_val; 1938*3684Srd117015 1939*3684Srd117015 if (rctl_val_list_insert(&rctl->rc_values, 1940*3684Srd117015 alloc_values) == 0) { 1941*3684Srd117015 /* inserted, so move alloc_values on */ 1942*3684Srd117015 alloc_values = tmp_val; 1943*3684Srd117015 } 1944*3684Srd117015 } else { 1945*3684Srd117015 /* 1946*3684Srd117015 * Unlike setrctl() we don't want to return an error on 1947*3684Srd117015 * a duplicate entry; we are concerned solely with 1948*3684Srd117015 * ensuring that all the values specified are set. 1949*3684Srd117015 */ 1950*3684Srd117015 kmem_cache_free(rctl_val_cache, new_values); 1951*3684Srd117015 } 1952*3684Srd117015 1953*3684Srd117015 new_values = next; 1954*3684Srd117015 } 1955*3684Srd117015 1956*3684Srd117015 /* Teardown any unused rctl_val_t */ 1957*3684Srd117015 while (alloc_values != NULL) { 1958*3684Srd117015 tmp_val = alloc_values; 1959*3684Srd117015 alloc_values = alloc_values->rcv_next; 1960*3684Srd117015 kmem_cache_free(rctl_val_cache, tmp_val); 1961*3684Srd117015 } 1962*3684Srd117015 1963*3684Srd117015 /* Always reset the cursor */ 1964*3684Srd117015 rctl->rc_cursor = rctl->rc_values; 1965*3684Srd117015 rctl_val_list_reset(rctl->rc_cursor); 1966*3684Srd117015 RCTLOP_SET(rctl, p, e, rctl_model_value(rctl->rc_dict_entry, p, 1967*3684Srd117015 rctl->rc_cursor->rcv_value)); 1968*3684Srd117015 1969*3684Srd117015 return (0); 1970*3684Srd117015 } 1971*3684Srd117015 1972*3684Srd117015 int 1973*3684Srd117015 rctl_local_replace_all(rctl_hndl_t hndl, rctl_val_t *new_values, 1974*3684Srd117015 rctl_val_t *alloc_values, struct proc *p) 1975*3684Srd117015 { 1976*3684Srd117015 return (rctl_local_op(hndl, new_values, alloc_values, 1977*3684Srd117015 rctl_local_replace_all_cb, p)); 1978*3684Srd117015 } 1979*3684Srd117015 19800Sstevel@tonic-gate static int 19810Sstevel@tonic-gate rctl_local_replace_cb(rctl_hndl_t hndl, struct proc *p, rctl_entity_p_t *e, 19820Sstevel@tonic-gate rctl_t *rctl, rctl_val_t *oval, rctl_val_t *nval) 19830Sstevel@tonic-gate { 19840Sstevel@tonic-gate int ret; 19853251Ssl108498 rctl_val_t *tmp; 19863251Ssl108498 19873251Ssl108498 /* Verify that old will be delete-able */ 19883251Ssl108498 tmp = rctl_val_list_find(&rctl->rc_values, oval); 19893251Ssl108498 if (tmp == NULL) 19903251Ssl108498 return (ESRCH); 19913251Ssl108498 /* 19923251Ssl108498 * Caller should verify that value being deleted is not the 19933251Ssl108498 * system value. 19943251Ssl108498 */ 19953251Ssl108498 ASSERT(tmp->rcv_privilege != RCPRIV_SYSTEM); 19960Sstevel@tonic-gate 19970Sstevel@tonic-gate /* 19980Sstevel@tonic-gate * rctl_local_insert_cb() does the job of flagging an error 19990Sstevel@tonic-gate * for any duplicate values. So, call rctl_local_insert_cb() 20000Sstevel@tonic-gate * for the new value first, then do deletion of the old value. 20010Sstevel@tonic-gate * Since this is a callback function to rctl_local_op, we can 20020Sstevel@tonic-gate * count on rcs_lock being held at this point. This guarantees 20030Sstevel@tonic-gate * that there is at no point a visible list which contains both 20040Sstevel@tonic-gate * new and old values. 20050Sstevel@tonic-gate */ 20060Sstevel@tonic-gate if (ret = rctl_local_insert_cb(hndl, p, e, rctl, NULL, nval)) 20070Sstevel@tonic-gate return (ret); 20080Sstevel@tonic-gate 20093251Ssl108498 ret = rctl_local_delete_cb(hndl, p, e, rctl, NULL, oval); 20103251Ssl108498 ASSERT(ret == 0); 20113251Ssl108498 return (0); 20120Sstevel@tonic-gate } 20130Sstevel@tonic-gate 20140Sstevel@tonic-gate /* 20150Sstevel@tonic-gate * int rctl_local_replace(rctl_hndl_t, void *, int, uint64_t *) 20160Sstevel@tonic-gate * 20170Sstevel@tonic-gate * Overview 20180Sstevel@tonic-gate * Replace the rctl value with a new one. 20190Sstevel@tonic-gate * 20200Sstevel@tonic-gate * Return values 20210Sstevel@tonic-gate * 0 for successful replace, errno otherwise. 20220Sstevel@tonic-gate */ 20230Sstevel@tonic-gate int 20240Sstevel@tonic-gate rctl_local_replace(rctl_hndl_t hndl, rctl_val_t *oval, rctl_val_t *nval, 20250Sstevel@tonic-gate struct proc *p) 20260Sstevel@tonic-gate { 20270Sstevel@tonic-gate return (rctl_local_op(hndl, oval, nval, rctl_local_replace_cb, p)); 20280Sstevel@tonic-gate } 20290Sstevel@tonic-gate 20300Sstevel@tonic-gate /* 20310Sstevel@tonic-gate * int rctl_rlimit_get(rctl_hndl_t, struct proc *, struct rlimit64 *) 20320Sstevel@tonic-gate * 20330Sstevel@tonic-gate * Overview 20340Sstevel@tonic-gate * To support rlimit compatibility, we need a function which takes a 64-bit 20350Sstevel@tonic-gate * rlimit and encodes it as appropriate rcontrol values on the given rcontrol. 20360Sstevel@tonic-gate * This operation is only intended for legacy rlimits. 20370Sstevel@tonic-gate */ 20380Sstevel@tonic-gate int 20390Sstevel@tonic-gate rctl_rlimit_get(rctl_hndl_t rc, struct proc *p, struct rlimit64 *rlp64) 20400Sstevel@tonic-gate { 20410Sstevel@tonic-gate rctl_t *rctl; 20420Sstevel@tonic-gate rctl_val_t *rval; 20430Sstevel@tonic-gate rctl_set_t *rset = p->p_rctls; 20440Sstevel@tonic-gate int soft_limit_seen = 0; 20450Sstevel@tonic-gate int test_for_deny = 1; 20460Sstevel@tonic-gate 20470Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 20480Sstevel@tonic-gate if (rctl_set_find(rset, rc, &rctl) == -1) { 20490Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 20500Sstevel@tonic-gate return (-1); 20510Sstevel@tonic-gate } 20520Sstevel@tonic-gate 20530Sstevel@tonic-gate rval = rctl->rc_values; 20540Sstevel@tonic-gate 20550Sstevel@tonic-gate if (rctl->rc_dict_entry->rcd_flagaction & (RCTL_GLOBAL_DENY_NEVER | 20560Sstevel@tonic-gate RCTL_GLOBAL_DENY_ALWAYS)) 20570Sstevel@tonic-gate test_for_deny = 0; 20580Sstevel@tonic-gate 20590Sstevel@tonic-gate /* 20600Sstevel@tonic-gate * 1. Find the first control value with the RCTL_LOCAL_DENY bit set. 20610Sstevel@tonic-gate */ 20620Sstevel@tonic-gate while (rval != NULL && rval->rcv_privilege != RCPRIV_SYSTEM) { 20630Sstevel@tonic-gate if (test_for_deny && 20640Sstevel@tonic-gate (rval->rcv_flagaction & RCTL_LOCAL_DENY) == 0) { 20650Sstevel@tonic-gate rval = rval->rcv_next; 20660Sstevel@tonic-gate continue; 20670Sstevel@tonic-gate } 20680Sstevel@tonic-gate 20690Sstevel@tonic-gate /* 20700Sstevel@tonic-gate * 2. If this is an RCPRIV_BASIC value, then we've found the 20710Sstevel@tonic-gate * effective soft limit and should set rlim_cur. We should then 20720Sstevel@tonic-gate * continue looking for another control value with the DENY bit 20730Sstevel@tonic-gate * set. 20740Sstevel@tonic-gate */ 20750Sstevel@tonic-gate if (rval->rcv_privilege == RCPRIV_BASIC) { 20760Sstevel@tonic-gate if (soft_limit_seen) { 20770Sstevel@tonic-gate rval = rval->rcv_next; 20780Sstevel@tonic-gate continue; 20790Sstevel@tonic-gate } 20800Sstevel@tonic-gate 20810Sstevel@tonic-gate if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 && 20820Sstevel@tonic-gate rval->rcv_value < rctl_model_maximum( 20830Sstevel@tonic-gate rctl->rc_dict_entry, p)) 20840Sstevel@tonic-gate rlp64->rlim_cur = rval->rcv_value; 20850Sstevel@tonic-gate else 20860Sstevel@tonic-gate rlp64->rlim_cur = RLIM64_INFINITY; 20870Sstevel@tonic-gate soft_limit_seen = 1; 20880Sstevel@tonic-gate 20890Sstevel@tonic-gate rval = rval->rcv_next; 20900Sstevel@tonic-gate continue; 20910Sstevel@tonic-gate } 20920Sstevel@tonic-gate 20930Sstevel@tonic-gate /* 20940Sstevel@tonic-gate * 3. This is an RCPRIV_PRIVILEGED value. If we haven't found 20950Sstevel@tonic-gate * a soft limit candidate, then we've found the effective hard 20960Sstevel@tonic-gate * and soft limits and should set both If we had found a soft 20970Sstevel@tonic-gate * limit, then this is only the hard limit and we need only set 20980Sstevel@tonic-gate * rlim_max. 20990Sstevel@tonic-gate */ 21000Sstevel@tonic-gate if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 && 21010Sstevel@tonic-gate rval->rcv_value < rctl_model_maximum(rctl->rc_dict_entry, 21020Sstevel@tonic-gate p)) 21030Sstevel@tonic-gate rlp64->rlim_max = rval->rcv_value; 21040Sstevel@tonic-gate else 21050Sstevel@tonic-gate rlp64->rlim_max = RLIM64_INFINITY; 21060Sstevel@tonic-gate if (!soft_limit_seen) 21070Sstevel@tonic-gate rlp64->rlim_cur = rlp64->rlim_max; 21080Sstevel@tonic-gate 21090Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 21100Sstevel@tonic-gate return (0); 21110Sstevel@tonic-gate } 21120Sstevel@tonic-gate 21130Sstevel@tonic-gate if (rval == NULL) { 21140Sstevel@tonic-gate /* 21150Sstevel@tonic-gate * This control sequence is corrupt, as it is not terminated by 21160Sstevel@tonic-gate * a system privileged control value. 21170Sstevel@tonic-gate */ 21180Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 21190Sstevel@tonic-gate return (-1); 21200Sstevel@tonic-gate } 21210Sstevel@tonic-gate 21220Sstevel@tonic-gate /* 21230Sstevel@tonic-gate * 4. If we run into a RCPRIV_SYSTEM value, then the hard limit (and 21240Sstevel@tonic-gate * the soft, if we haven't a soft candidate) should be the value of the 21250Sstevel@tonic-gate * system control value. 21260Sstevel@tonic-gate */ 21270Sstevel@tonic-gate if ((rval->rcv_flagaction & RCTL_LOCAL_MAXIMAL) == 0 && 21280Sstevel@tonic-gate rval->rcv_value < rctl_model_maximum(rctl->rc_dict_entry, p)) 21290Sstevel@tonic-gate rlp64->rlim_max = rval->rcv_value; 21300Sstevel@tonic-gate else 21310Sstevel@tonic-gate rlp64->rlim_max = RLIM64_INFINITY; 21320Sstevel@tonic-gate 21330Sstevel@tonic-gate if (!soft_limit_seen) 21340Sstevel@tonic-gate rlp64->rlim_cur = rlp64->rlim_max; 21350Sstevel@tonic-gate 21360Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 21370Sstevel@tonic-gate return (0); 21380Sstevel@tonic-gate } 21390Sstevel@tonic-gate 21400Sstevel@tonic-gate /* 21410Sstevel@tonic-gate * rctl_alloc_gp_t *rctl_rlimit_set_prealloc(uint_t) 21420Sstevel@tonic-gate * 21430Sstevel@tonic-gate * Overview 21440Sstevel@tonic-gate * Before making a series of calls to rctl_rlimit_set(), we must have a 21450Sstevel@tonic-gate * preallocated batch of resource control values, as rctl_rlimit_set() can 21460Sstevel@tonic-gate * potentially consume two resource control values per call. 21470Sstevel@tonic-gate * 21480Sstevel@tonic-gate * Return values 21490Sstevel@tonic-gate * A populated resource control allocation group with 2n resource control 21500Sstevel@tonic-gate * values. 21510Sstevel@tonic-gate * 21520Sstevel@tonic-gate * Caller's context 21530Sstevel@tonic-gate * Must be safe for KM_SLEEP allocations. 21540Sstevel@tonic-gate */ 21550Sstevel@tonic-gate rctl_alloc_gp_t * 21560Sstevel@tonic-gate rctl_rlimit_set_prealloc(uint_t n) 21570Sstevel@tonic-gate { 21580Sstevel@tonic-gate rctl_alloc_gp_t *gp = kmem_zalloc(sizeof (rctl_alloc_gp_t), KM_SLEEP); 21590Sstevel@tonic-gate 21600Sstevel@tonic-gate ASSERT(MUTEX_NOT_HELD(&curproc->p_lock)); 21610Sstevel@tonic-gate 21620Sstevel@tonic-gate gp->rcag_nvals = 2 * n; 21630Sstevel@tonic-gate 21640Sstevel@tonic-gate rctl_gp_alloc(gp); 21650Sstevel@tonic-gate 21660Sstevel@tonic-gate return (gp); 21670Sstevel@tonic-gate } 21680Sstevel@tonic-gate 21690Sstevel@tonic-gate /* 21700Sstevel@tonic-gate * int rctl_rlimit_set(rctl_hndl_t, struct proc *, struct rlimit64 *, int, 21710Sstevel@tonic-gate * int) 21720Sstevel@tonic-gate * 21730Sstevel@tonic-gate * Overview 21740Sstevel@tonic-gate * To support rlimit compatibility, we need a function which takes a 64-bit 21750Sstevel@tonic-gate * rlimit and encodes it as appropriate rcontrol values on the given rcontrol. 21760Sstevel@tonic-gate * This operation is only intended for legacy rlimits. 21770Sstevel@tonic-gate * 21780Sstevel@tonic-gate * The implementation of rctl_rlimit_set() is a bit clever, as it tries to 21790Sstevel@tonic-gate * minimize the number of values placed on the value sequence in various 21800Sstevel@tonic-gate * cases. Furthermore, we don't allow multiple identical privilege-action 21810Sstevel@tonic-gate * values on the same sequence. (That is, we don't want a sequence like 21820Sstevel@tonic-gate * "while (1) { rlim.rlim_cur++; setrlimit(..., rlim); }" to exhaust kernel 21830Sstevel@tonic-gate * memory.) So we want to delete any values with the same privilege value and 21840Sstevel@tonic-gate * action. 21850Sstevel@tonic-gate * 21860Sstevel@tonic-gate * Return values 21870Sstevel@tonic-gate * 0 for successful set, errno otherwise. Errno will be either EINVAL 21880Sstevel@tonic-gate * or EPERM, in keeping with defined errnos for ulimit() and setrlimit() 21890Sstevel@tonic-gate * system calls. 21900Sstevel@tonic-gate */ 21910Sstevel@tonic-gate /*ARGSUSED*/ 21920Sstevel@tonic-gate int 21930Sstevel@tonic-gate rctl_rlimit_set(rctl_hndl_t rc, struct proc *p, struct rlimit64 *rlp64, 21940Sstevel@tonic-gate rctl_alloc_gp_t *ragp, int flagaction, int signal, const cred_t *cr) 21950Sstevel@tonic-gate { 21960Sstevel@tonic-gate rctl_t *rctl; 21970Sstevel@tonic-gate rctl_val_t *rval, *rval_priv, *rval_basic; 21980Sstevel@tonic-gate rctl_set_t *rset = p->p_rctls; 21990Sstevel@tonic-gate rctl_qty_t max; 22000Sstevel@tonic-gate rctl_entity_p_t e; 22010Sstevel@tonic-gate struct rlimit64 cur_rl; 22020Sstevel@tonic-gate 22030Sstevel@tonic-gate e.rcep_t = RCENTITY_PROCESS; 22040Sstevel@tonic-gate e.rcep_p.proc = p; 22050Sstevel@tonic-gate 22060Sstevel@tonic-gate if (rlp64->rlim_cur > rlp64->rlim_max) 22070Sstevel@tonic-gate return (EINVAL); 22080Sstevel@tonic-gate 22090Sstevel@tonic-gate if (rctl_rlimit_get(rc, p, &cur_rl) == -1) 22100Sstevel@tonic-gate return (EINVAL); 22110Sstevel@tonic-gate 22120Sstevel@tonic-gate /* 22130Sstevel@tonic-gate * If we are not privileged, we can only lower the hard limit. 22140Sstevel@tonic-gate */ 22150Sstevel@tonic-gate if ((rlp64->rlim_max > cur_rl.rlim_max) && 22160Sstevel@tonic-gate cur_rl.rlim_max != RLIM64_INFINITY && 22170Sstevel@tonic-gate secpolicy_resource(cr) != 0) 22180Sstevel@tonic-gate return (EPERM); 22190Sstevel@tonic-gate 22200Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 22210Sstevel@tonic-gate 22220Sstevel@tonic-gate if (rctl_set_find(rset, rc, &rctl) == -1) { 22230Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 22240Sstevel@tonic-gate return (EINVAL); 22250Sstevel@tonic-gate } 22260Sstevel@tonic-gate 22270Sstevel@tonic-gate rval_priv = rctl_gp_detach_val(ragp); 22280Sstevel@tonic-gate 22290Sstevel@tonic-gate rval = rctl->rc_values; 22300Sstevel@tonic-gate 22310Sstevel@tonic-gate while (rval != NULL) { 22320Sstevel@tonic-gate rctl_val_t *next = rval->rcv_next; 22330Sstevel@tonic-gate 22340Sstevel@tonic-gate if (rval->rcv_privilege == RCPRIV_SYSTEM) 22350Sstevel@tonic-gate break; 22360Sstevel@tonic-gate 22370Sstevel@tonic-gate if ((rval->rcv_privilege == RCPRIV_BASIC) || 22380Sstevel@tonic-gate (rval->rcv_flagaction & ~RCTL_LOCAL_ACTION_MASK) == 22390Sstevel@tonic-gate (flagaction & ~RCTL_LOCAL_ACTION_MASK)) { 22400Sstevel@tonic-gate if (rctl->rc_cursor == rval) { 22410Sstevel@tonic-gate rctl->rc_cursor = rval->rcv_next; 22420Sstevel@tonic-gate rctl_val_list_reset(rctl->rc_cursor); 22430Sstevel@tonic-gate RCTLOP_SET(rctl, p, &e, rctl_model_value( 22440Sstevel@tonic-gate rctl->rc_dict_entry, p, 22450Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 22460Sstevel@tonic-gate } 22470Sstevel@tonic-gate (void) rctl_val_list_delete(&rctl->rc_values, rval); 22480Sstevel@tonic-gate } 22490Sstevel@tonic-gate 22500Sstevel@tonic-gate rval = next; 22510Sstevel@tonic-gate } 22520Sstevel@tonic-gate 22530Sstevel@tonic-gate rval_priv->rcv_privilege = RCPRIV_PRIVILEGED; 22540Sstevel@tonic-gate rval_priv->rcv_flagaction = flagaction; 22550Sstevel@tonic-gate if (rlp64->rlim_max == RLIM64_INFINITY) { 22560Sstevel@tonic-gate rval_priv->rcv_flagaction |= RCTL_LOCAL_MAXIMAL; 22570Sstevel@tonic-gate max = rctl->rc_dict_entry->rcd_max_native; 22580Sstevel@tonic-gate } else { 22590Sstevel@tonic-gate max = rlp64->rlim_max; 22600Sstevel@tonic-gate } 22610Sstevel@tonic-gate rval_priv->rcv_value = max; 22620Sstevel@tonic-gate rval_priv->rcv_action_signal = signal; 22630Sstevel@tonic-gate rval_priv->rcv_action_recipient = NULL; 22640Sstevel@tonic-gate rval_priv->rcv_action_recip_pid = -1; 22650Sstevel@tonic-gate rval_priv->rcv_firing_time = 0; 22660Sstevel@tonic-gate rval_priv->rcv_prev = rval_priv->rcv_next = NULL; 22670Sstevel@tonic-gate 22680Sstevel@tonic-gate (void) rctl_val_list_insert(&rctl->rc_values, rval_priv); 22690Sstevel@tonic-gate rctl->rc_cursor = rval_priv; 22700Sstevel@tonic-gate rctl_val_list_reset(rctl->rc_cursor); 22710Sstevel@tonic-gate RCTLOP_SET(rctl, p, &e, rctl_model_value(rctl->rc_dict_entry, p, 22720Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 22730Sstevel@tonic-gate 22740Sstevel@tonic-gate if (rlp64->rlim_cur != RLIM64_INFINITY && rlp64->rlim_cur < max) { 22750Sstevel@tonic-gate rval_basic = rctl_gp_detach_val(ragp); 22760Sstevel@tonic-gate 22770Sstevel@tonic-gate rval_basic->rcv_privilege = RCPRIV_BASIC; 22780Sstevel@tonic-gate rval_basic->rcv_value = rlp64->rlim_cur; 22790Sstevel@tonic-gate rval_basic->rcv_flagaction = flagaction; 22800Sstevel@tonic-gate rval_basic->rcv_action_signal = signal; 22810Sstevel@tonic-gate rval_basic->rcv_action_recipient = p; 22820Sstevel@tonic-gate rval_basic->rcv_action_recip_pid = p->p_pid; 22830Sstevel@tonic-gate rval_basic->rcv_firing_time = 0; 22840Sstevel@tonic-gate rval_basic->rcv_prev = rval_basic->rcv_next = NULL; 22850Sstevel@tonic-gate 22860Sstevel@tonic-gate (void) rctl_val_list_insert(&rctl->rc_values, rval_basic); 22870Sstevel@tonic-gate rctl->rc_cursor = rval_basic; 22880Sstevel@tonic-gate rctl_val_list_reset(rctl->rc_cursor); 22890Sstevel@tonic-gate RCTLOP_SET(rctl, p, &e, rctl_model_value(rctl->rc_dict_entry, p, 22900Sstevel@tonic-gate rctl->rc_cursor->rcv_value)); 22910Sstevel@tonic-gate } 22920Sstevel@tonic-gate 22930Sstevel@tonic-gate ASSERT(rctl->rc_cursor != NULL); 22940Sstevel@tonic-gate 22950Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 22960Sstevel@tonic-gate return (0); 22970Sstevel@tonic-gate } 22980Sstevel@tonic-gate 22990Sstevel@tonic-gate 23000Sstevel@tonic-gate /* 23010Sstevel@tonic-gate * rctl_hndl_t rctl_register(const char *, rctl_entity_t, int, rlim64_t, 23020Sstevel@tonic-gate * rlim64_t, rctl_ops_t *) 23030Sstevel@tonic-gate * 23040Sstevel@tonic-gate * Overview 23050Sstevel@tonic-gate * rctl_register() performs a look-up in the dictionary of rctls 23060Sstevel@tonic-gate * active on the system; if a rctl of that name is absent, an entry is 23070Sstevel@tonic-gate * made into the dictionary. The rctl is returned with its reference 23080Sstevel@tonic-gate * count incremented by one. If the rctl name already exists, we panic. 23090Sstevel@tonic-gate * (Were the resource control system to support dynamic loading and unloading, 23100Sstevel@tonic-gate * which it is structured for, duplicate registration should lead to load 23110Sstevel@tonic-gate * failure instead of panicking.) 23120Sstevel@tonic-gate * 23130Sstevel@tonic-gate * Each registered rctl has a requirement that a RCPRIV_SYSTEM limit be 23140Sstevel@tonic-gate * defined. This limit contains the highest possible value for this quantity 23150Sstevel@tonic-gate * on the system. Furthermore, the registered control must provide infinite 23160Sstevel@tonic-gate * values for all applicable address space models supported by the operating 23170Sstevel@tonic-gate * system. Attempts to set resource control values beyond the system limit 23180Sstevel@tonic-gate * will fail. 23190Sstevel@tonic-gate * 23200Sstevel@tonic-gate * Return values 23210Sstevel@tonic-gate * The rctl's ID. 23220Sstevel@tonic-gate * 23230Sstevel@tonic-gate * Caller's context 23240Sstevel@tonic-gate * Caller must be in a context suitable for KM_SLEEP allocations. 23250Sstevel@tonic-gate */ 23260Sstevel@tonic-gate rctl_hndl_t 23270Sstevel@tonic-gate rctl_register( 23280Sstevel@tonic-gate const char *name, 23290Sstevel@tonic-gate rctl_entity_t entity, 23300Sstevel@tonic-gate int global_flags, 23310Sstevel@tonic-gate rlim64_t max_native, 23320Sstevel@tonic-gate rlim64_t max_ilp32, 23330Sstevel@tonic-gate rctl_ops_t *ops) 23340Sstevel@tonic-gate { 23350Sstevel@tonic-gate rctl_t *rctl = kmem_cache_alloc(rctl_cache, KM_SLEEP); 23360Sstevel@tonic-gate rctl_val_t *rctl_val = kmem_cache_alloc(rctl_val_cache, KM_SLEEP); 23370Sstevel@tonic-gate rctl_dict_entry_t *rctl_de = kmem_zalloc(sizeof (rctl_dict_entry_t), 23380Sstevel@tonic-gate KM_SLEEP); 23390Sstevel@tonic-gate rctl_t *old_rctl; 23400Sstevel@tonic-gate rctl_hndl_t rhndl; 23410Sstevel@tonic-gate int localflags; 23420Sstevel@tonic-gate 23430Sstevel@tonic-gate ASSERT(ops != NULL); 23440Sstevel@tonic-gate 23450Sstevel@tonic-gate bzero(rctl, sizeof (rctl_t)); 23460Sstevel@tonic-gate bzero(rctl_val, sizeof (rctl_val_t)); 23470Sstevel@tonic-gate 23480Sstevel@tonic-gate if (global_flags & RCTL_GLOBAL_DENY_NEVER) 23490Sstevel@tonic-gate localflags = RCTL_LOCAL_MAXIMAL; 23500Sstevel@tonic-gate else 23510Sstevel@tonic-gate localflags = RCTL_LOCAL_MAXIMAL | RCTL_LOCAL_DENY; 23520Sstevel@tonic-gate 23530Sstevel@tonic-gate rctl_val->rcv_privilege = RCPRIV_SYSTEM; 23540Sstevel@tonic-gate rctl_val->rcv_value = max_native; 23550Sstevel@tonic-gate rctl_val->rcv_flagaction = localflags; 23560Sstevel@tonic-gate rctl_val->rcv_action_signal = 0; 23570Sstevel@tonic-gate rctl_val->rcv_action_recipient = NULL; 23580Sstevel@tonic-gate rctl_val->rcv_action_recip_pid = -1; 23590Sstevel@tonic-gate rctl_val->rcv_firing_time = 0; 23600Sstevel@tonic-gate rctl_val->rcv_next = NULL; 23610Sstevel@tonic-gate rctl_val->rcv_prev = NULL; 23620Sstevel@tonic-gate 23630Sstevel@tonic-gate rctl_de->rcd_name = (char *)name; 23640Sstevel@tonic-gate rctl_de->rcd_default_value = rctl_val; 23650Sstevel@tonic-gate rctl_de->rcd_max_native = max_native; 23660Sstevel@tonic-gate rctl_de->rcd_max_ilp32 = max_ilp32; 23670Sstevel@tonic-gate rctl_de->rcd_entity = entity; 23680Sstevel@tonic-gate rctl_de->rcd_ops = ops; 23690Sstevel@tonic-gate rctl_de->rcd_flagaction = global_flags; 23700Sstevel@tonic-gate 23710Sstevel@tonic-gate rctl->rc_dict_entry = rctl_de; 23720Sstevel@tonic-gate rctl->rc_values = rctl_val; 23730Sstevel@tonic-gate 23740Sstevel@tonic-gate /* 23750Sstevel@tonic-gate * 1. Take global lock, validate nonexistence of name, get ID. 23760Sstevel@tonic-gate */ 23770Sstevel@tonic-gate mutex_enter(&rctl_dict_lock); 23780Sstevel@tonic-gate 23790Sstevel@tonic-gate if (mod_hash_find(rctl_dict_by_name, (mod_hash_key_t)name, 23800Sstevel@tonic-gate (mod_hash_val_t *)&rhndl) != MH_ERR_NOTFOUND) 23810Sstevel@tonic-gate panic("duplicate registration of rctl %s", name); 23820Sstevel@tonic-gate 23830Sstevel@tonic-gate rhndl = rctl_de->rcd_id = rctl->rc_id = 23840Sstevel@tonic-gate (rctl_hndl_t)id_alloc(rctl_ids); 23850Sstevel@tonic-gate 23860Sstevel@tonic-gate /* 23870Sstevel@tonic-gate * 2. Insert name-entry pair in rctl_dict_by_name. 23880Sstevel@tonic-gate */ 23890Sstevel@tonic-gate if (mod_hash_insert(rctl_dict_by_name, (mod_hash_key_t)name, 23900Sstevel@tonic-gate (mod_hash_val_t)rctl_de)) 23910Sstevel@tonic-gate panic("unable to insert rctl dict entry for %s (%u)", name, 23920Sstevel@tonic-gate (uint_t)rctl->rc_id); 23930Sstevel@tonic-gate 23940Sstevel@tonic-gate /* 23950Sstevel@tonic-gate * 3. Insert ID-rctl_t * pair in rctl_dict. 23960Sstevel@tonic-gate */ 23970Sstevel@tonic-gate if (mod_hash_find(rctl_dict, (mod_hash_key_t)(uintptr_t)rctl->rc_id, 23980Sstevel@tonic-gate (mod_hash_val_t *)&old_rctl) != MH_ERR_NOTFOUND) 23990Sstevel@tonic-gate panic("duplicate rctl ID %u registered", rctl->rc_id); 24000Sstevel@tonic-gate 24010Sstevel@tonic-gate if (mod_hash_insert(rctl_dict, (mod_hash_key_t)(uintptr_t)rctl->rc_id, 24020Sstevel@tonic-gate (mod_hash_val_t)rctl)) 24030Sstevel@tonic-gate panic("unable to insert rctl %s/%u (%p)", name, 24040Sstevel@tonic-gate (uint_t)rctl->rc_id, rctl); 24050Sstevel@tonic-gate 24060Sstevel@tonic-gate /* 24070Sstevel@tonic-gate * 3a. Insert rctl_dict_entry_t * in appropriate entity list. 24080Sstevel@tonic-gate */ 24090Sstevel@tonic-gate 24100Sstevel@tonic-gate mutex_enter(&rctl_lists_lock); 24110Sstevel@tonic-gate 24120Sstevel@tonic-gate switch (entity) { 24130Sstevel@tonic-gate case RCENTITY_ZONE: 24140Sstevel@tonic-gate case RCENTITY_PROJECT: 24150Sstevel@tonic-gate case RCENTITY_TASK: 24160Sstevel@tonic-gate case RCENTITY_PROCESS: 24170Sstevel@tonic-gate rctl_de->rcd_next = rctl_lists[entity]; 24180Sstevel@tonic-gate rctl_lists[entity] = rctl_de; 24190Sstevel@tonic-gate break; 24200Sstevel@tonic-gate default: 24210Sstevel@tonic-gate panic("registering unknown rctl entity %d (%s)", entity, 24220Sstevel@tonic-gate name); 24230Sstevel@tonic-gate break; 24240Sstevel@tonic-gate } 24250Sstevel@tonic-gate 24260Sstevel@tonic-gate mutex_exit(&rctl_lists_lock); 24270Sstevel@tonic-gate 24280Sstevel@tonic-gate /* 24290Sstevel@tonic-gate * 4. Drop lock. 24300Sstevel@tonic-gate */ 24310Sstevel@tonic-gate mutex_exit(&rctl_dict_lock); 24320Sstevel@tonic-gate 24330Sstevel@tonic-gate return (rhndl); 24340Sstevel@tonic-gate } 24350Sstevel@tonic-gate 24360Sstevel@tonic-gate /* 24370Sstevel@tonic-gate * static int rctl_global_action(rctl_t *r, rctl_set_t *rset, struct proc *p, 24380Sstevel@tonic-gate * rctl_val_t *v) 24390Sstevel@tonic-gate * 24400Sstevel@tonic-gate * Overview 24410Sstevel@tonic-gate * rctl_global_action() takes, in according with the flags on the rctl_dict 24420Sstevel@tonic-gate * entry for the given control, the appropriate actions on the exceeded 24430Sstevel@tonic-gate * control value. Additionally, rctl_global_action() updates the firing time 24440Sstevel@tonic-gate * on the exceeded value. 24450Sstevel@tonic-gate * 24460Sstevel@tonic-gate * Return values 24470Sstevel@tonic-gate * A bitmask reflecting the actions actually taken. 24480Sstevel@tonic-gate * 24490Sstevel@tonic-gate * Caller's context 24500Sstevel@tonic-gate * No restrictions on context. 24510Sstevel@tonic-gate */ 24520Sstevel@tonic-gate /*ARGSUSED*/ 24530Sstevel@tonic-gate static int 24540Sstevel@tonic-gate rctl_global_action(rctl_t *r, rctl_set_t *rset, struct proc *p, rctl_val_t *v) 24550Sstevel@tonic-gate { 24560Sstevel@tonic-gate rctl_dict_entry_t *rde = r->rc_dict_entry; 24572447Snf202958 const char *pr, *en, *idstr; 24580Sstevel@tonic-gate id_t id; 24592447Snf202958 enum { 24602447Snf202958 SUFFIX_NONE, /* id consumed directly */ 24612447Snf202958 SUFFIX_NUMERIC, /* id consumed in suffix */ 24622447Snf202958 SUFFIX_STRING /* idstr consumed in suffix */ 24632447Snf202958 } suffix = SUFFIX_NONE; 24640Sstevel@tonic-gate int ret = 0; 24650Sstevel@tonic-gate 24660Sstevel@tonic-gate v->rcv_firing_time = gethrtime(); 24670Sstevel@tonic-gate 24680Sstevel@tonic-gate switch (v->rcv_privilege) { 24690Sstevel@tonic-gate case RCPRIV_BASIC: 24700Sstevel@tonic-gate pr = "basic"; 24710Sstevel@tonic-gate break; 24720Sstevel@tonic-gate case RCPRIV_PRIVILEGED: 24730Sstevel@tonic-gate pr = "privileged"; 24740Sstevel@tonic-gate break; 24750Sstevel@tonic-gate case RCPRIV_SYSTEM: 24760Sstevel@tonic-gate pr = "system"; 24770Sstevel@tonic-gate break; 24780Sstevel@tonic-gate default: 24790Sstevel@tonic-gate pr = "unknown"; 24800Sstevel@tonic-gate break; 24810Sstevel@tonic-gate } 24820Sstevel@tonic-gate 24830Sstevel@tonic-gate switch (rde->rcd_entity) { 24840Sstevel@tonic-gate case RCENTITY_PROCESS: 24850Sstevel@tonic-gate en = "process"; 24860Sstevel@tonic-gate id = p->p_pid; 24872447Snf202958 suffix = SUFFIX_NONE; 24880Sstevel@tonic-gate break; 24890Sstevel@tonic-gate case RCENTITY_TASK: 24900Sstevel@tonic-gate en = "task"; 24910Sstevel@tonic-gate id = p->p_task->tk_tkid; 24922447Snf202958 suffix = SUFFIX_NUMERIC; 24930Sstevel@tonic-gate break; 24940Sstevel@tonic-gate case RCENTITY_PROJECT: 24950Sstevel@tonic-gate en = "project"; 24960Sstevel@tonic-gate id = p->p_task->tk_proj->kpj_id; 24972447Snf202958 suffix = SUFFIX_NUMERIC; 24980Sstevel@tonic-gate break; 24990Sstevel@tonic-gate case RCENTITY_ZONE: 25000Sstevel@tonic-gate en = "zone"; 25012447Snf202958 idstr = p->p_zone->zone_name; 25022447Snf202958 suffix = SUFFIX_STRING; 25030Sstevel@tonic-gate break; 25040Sstevel@tonic-gate default: 25052447Snf202958 en = "unknown entity associated with process"; 25060Sstevel@tonic-gate id = p->p_pid; 25072447Snf202958 suffix = SUFFIX_NONE; 25080Sstevel@tonic-gate break; 25090Sstevel@tonic-gate } 25100Sstevel@tonic-gate 25110Sstevel@tonic-gate if (rde->rcd_flagaction & RCTL_GLOBAL_SYSLOG) { 25122447Snf202958 switch (suffix) { 25132447Snf202958 default: 25142447Snf202958 case SUFFIX_NONE: 25152447Snf202958 (void) strlog(0, 0, 0, 25162447Snf202958 rde->rcd_strlog_flags | log_global.lz_active, 25172447Snf202958 "%s rctl %s (value %llu) exceeded by %s %d.", 25182447Snf202958 pr, rde->rcd_name, v->rcv_value, en, id); 25192447Snf202958 break; 25202447Snf202958 case SUFFIX_NUMERIC: 25212447Snf202958 (void) strlog(0, 0, 0, 25222447Snf202958 rde->rcd_strlog_flags | log_global.lz_active, 25232447Snf202958 "%s rctl %s (value %llu) exceeded by process %d" 25242447Snf202958 " in %s %d.", 25252447Snf202958 pr, rde->rcd_name, v->rcv_value, p->p_pid, 25262447Snf202958 en, id); 25272447Snf202958 break; 25282447Snf202958 case SUFFIX_STRING: 25292447Snf202958 (void) strlog(0, 0, 0, 25302447Snf202958 rde->rcd_strlog_flags | log_global.lz_active, 25312447Snf202958 "%s rctl %s (value %llu) exceeded by process %d" 25322447Snf202958 " in %s %s.", 25332447Snf202958 pr, rde->rcd_name, v->rcv_value, p->p_pid, 25342447Snf202958 en, idstr); 25352447Snf202958 break; 25362447Snf202958 } 25370Sstevel@tonic-gate } 25380Sstevel@tonic-gate 25390Sstevel@tonic-gate if (rde->rcd_flagaction & RCTL_GLOBAL_DENY_ALWAYS) 25400Sstevel@tonic-gate ret |= RCT_DENY; 25410Sstevel@tonic-gate 25420Sstevel@tonic-gate return (ret); 25430Sstevel@tonic-gate } 25440Sstevel@tonic-gate 25450Sstevel@tonic-gate static int 25460Sstevel@tonic-gate rctl_local_action(rctl_t *r, rctl_set_t *rset, struct proc *p, rctl_val_t *v, 25470Sstevel@tonic-gate uint_t safety) 25480Sstevel@tonic-gate { 25490Sstevel@tonic-gate int ret = 0; 25500Sstevel@tonic-gate sigqueue_t *sqp = NULL; 25510Sstevel@tonic-gate rctl_dict_entry_t *rde = r->rc_dict_entry; 25520Sstevel@tonic-gate int unobservable = (rde->rcd_flagaction & RCTL_GLOBAL_UNOBSERVABLE); 25530Sstevel@tonic-gate 25540Sstevel@tonic-gate proc_t *recipient = v->rcv_action_recipient; 25550Sstevel@tonic-gate id_t recip_pid = v->rcv_action_recip_pid; 25560Sstevel@tonic-gate int recip_signal = v->rcv_action_signal; 25570Sstevel@tonic-gate uint_t flagaction = v->rcv_flagaction; 25580Sstevel@tonic-gate 25590Sstevel@tonic-gate if (safety == RCA_UNSAFE_ALL) { 25600Sstevel@tonic-gate if (flagaction & RCTL_LOCAL_DENY) { 25610Sstevel@tonic-gate ret |= RCT_DENY; 25620Sstevel@tonic-gate } 25630Sstevel@tonic-gate return (ret); 25640Sstevel@tonic-gate } 25650Sstevel@tonic-gate 25660Sstevel@tonic-gate if (flagaction & RCTL_LOCAL_SIGNAL) { 25670Sstevel@tonic-gate /* 25680Sstevel@tonic-gate * We can build a siginfo only in the case that it is 25690Sstevel@tonic-gate * safe for us to drop p_lock. (For asynchronous 25700Sstevel@tonic-gate * checks this is currently not true.) 25710Sstevel@tonic-gate */ 25720Sstevel@tonic-gate if (safety == RCA_SAFE) { 25730Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 25740Sstevel@tonic-gate mutex_exit(&p->p_lock); 25750Sstevel@tonic-gate sqp = kmem_zalloc(sizeof (sigqueue_t), KM_SLEEP); 25760Sstevel@tonic-gate mutex_enter(&p->p_lock); 25770Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 25780Sstevel@tonic-gate 25790Sstevel@tonic-gate sqp->sq_info.si_signo = recip_signal; 25800Sstevel@tonic-gate sqp->sq_info.si_code = SI_RCTL; 25810Sstevel@tonic-gate sqp->sq_info.si_errno = 0; 25820Sstevel@tonic-gate sqp->sq_info.si_entity = (int)rde->rcd_entity; 25830Sstevel@tonic-gate } 25840Sstevel@tonic-gate 25850Sstevel@tonic-gate if (recipient == NULL || recipient == p) { 25860Sstevel@tonic-gate ret |= RCT_SIGNAL; 25870Sstevel@tonic-gate 25880Sstevel@tonic-gate if (sqp == NULL) { 25890Sstevel@tonic-gate sigtoproc(p, NULL, recip_signal); 25900Sstevel@tonic-gate } else if (p == curproc) { 25910Sstevel@tonic-gate /* 25920Sstevel@tonic-gate * Then this is a synchronous test and we can 25930Sstevel@tonic-gate * direct the signal at the violating thread. 25940Sstevel@tonic-gate */ 25950Sstevel@tonic-gate sigaddqa(curproc, curthread, sqp); 25960Sstevel@tonic-gate } else { 25970Sstevel@tonic-gate sigaddqa(p, NULL, sqp); 25980Sstevel@tonic-gate } 25990Sstevel@tonic-gate } else if (!unobservable) { 26000Sstevel@tonic-gate proc_t *rp; 26010Sstevel@tonic-gate 26020Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 26030Sstevel@tonic-gate mutex_exit(&p->p_lock); 26040Sstevel@tonic-gate 26050Sstevel@tonic-gate mutex_enter(&pidlock); 26060Sstevel@tonic-gate if ((rp = prfind(recip_pid)) == recipient) { 26070Sstevel@tonic-gate /* 26080Sstevel@tonic-gate * Recipient process is still alive, but may not 26090Sstevel@tonic-gate * be in this task or project any longer. In 26100Sstevel@tonic-gate * this case, the recipient's resource control 26110Sstevel@tonic-gate * set pertinent to this control will have 26120Sstevel@tonic-gate * changed--and we will not deliver the signal, 26130Sstevel@tonic-gate * as the recipient process is trying to tear 26140Sstevel@tonic-gate * itself off of its former set. 26150Sstevel@tonic-gate */ 26160Sstevel@tonic-gate mutex_enter(&rp->p_lock); 26170Sstevel@tonic-gate mutex_exit(&pidlock); 26180Sstevel@tonic-gate 26190Sstevel@tonic-gate if (rctl_entity_obtain_rset(rde, rp) == rset) { 26200Sstevel@tonic-gate ret |= RCT_SIGNAL; 26210Sstevel@tonic-gate 26220Sstevel@tonic-gate if (sqp == NULL) 26230Sstevel@tonic-gate sigtoproc(rp, NULL, 26240Sstevel@tonic-gate recip_signal); 26250Sstevel@tonic-gate else 26260Sstevel@tonic-gate sigaddqa(rp, NULL, sqp); 26270Sstevel@tonic-gate } else if (sqp) { 26280Sstevel@tonic-gate kmem_free(sqp, sizeof (sigqueue_t)); 26290Sstevel@tonic-gate } 26300Sstevel@tonic-gate mutex_exit(&rp->p_lock); 26310Sstevel@tonic-gate } else { 26320Sstevel@tonic-gate mutex_exit(&pidlock); 26330Sstevel@tonic-gate if (sqp) 26340Sstevel@tonic-gate kmem_free(sqp, sizeof (sigqueue_t)); 26350Sstevel@tonic-gate } 26360Sstevel@tonic-gate 26370Sstevel@tonic-gate mutex_enter(&p->p_lock); 26380Sstevel@tonic-gate /* 26390Sstevel@tonic-gate * Since we dropped p_lock, we may no longer be in the 26400Sstevel@tonic-gate * same task or project as we were at entry. It is thus 26410Sstevel@tonic-gate * unsafe for us to reacquire the set lock at this 26420Sstevel@tonic-gate * point; callers of rctl_local_action() must handle 26430Sstevel@tonic-gate * this possibility. 26440Sstevel@tonic-gate */ 26450Sstevel@tonic-gate ret |= RCT_LK_ABANDONED; 26460Sstevel@tonic-gate } else if (sqp) { 26470Sstevel@tonic-gate kmem_free(sqp, sizeof (sigqueue_t)); 26480Sstevel@tonic-gate } 26490Sstevel@tonic-gate } 26500Sstevel@tonic-gate 26510Sstevel@tonic-gate if ((flagaction & RCTL_LOCAL_DENY) && 26520Sstevel@tonic-gate (recipient == NULL || recipient == p)) { 26530Sstevel@tonic-gate ret |= RCT_DENY; 26540Sstevel@tonic-gate } 26550Sstevel@tonic-gate 26560Sstevel@tonic-gate return (ret); 26570Sstevel@tonic-gate } 26580Sstevel@tonic-gate 26590Sstevel@tonic-gate /* 26600Sstevel@tonic-gate * int rctl_action(rctl_hndl_t, rctl_set_t *, struct proc *, uint_t) 26610Sstevel@tonic-gate * 26620Sstevel@tonic-gate * Overview 26630Sstevel@tonic-gate * Take the action associated with the enforced value (as defined by 26640Sstevel@tonic-gate * rctl_get_enforced_value()) being exceeded or encountered. Possibly perform 26650Sstevel@tonic-gate * a restricted subset of the available actions, if circumstances dictate that 26660Sstevel@tonic-gate * we cannot safely allocate memory (for a sigqueue_t) or guarantee process 26670Sstevel@tonic-gate * persistence across the duration of the function (an asynchronous action). 26680Sstevel@tonic-gate * 26690Sstevel@tonic-gate * Return values 26700Sstevel@tonic-gate * Actions taken, according to the rctl_test bitmask. 26710Sstevel@tonic-gate * 26720Sstevel@tonic-gate * Caller's context 26730Sstevel@tonic-gate * Safe to acquire rcs_lock. 26740Sstevel@tonic-gate */ 26750Sstevel@tonic-gate int 26760Sstevel@tonic-gate rctl_action(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p, uint_t safety) 26770Sstevel@tonic-gate { 26780Sstevel@tonic-gate return (rctl_action_entity(hndl, rset, p, NULL, safety)); 26790Sstevel@tonic-gate } 26800Sstevel@tonic-gate 26810Sstevel@tonic-gate int 26820Sstevel@tonic-gate rctl_action_entity(rctl_hndl_t hndl, rctl_set_t *rset, struct proc *p, 26830Sstevel@tonic-gate rctl_entity_p_t *e, uint_t safety) 26840Sstevel@tonic-gate { 26850Sstevel@tonic-gate int ret = RCT_NONE; 26860Sstevel@tonic-gate rctl_t *lrctl; 26870Sstevel@tonic-gate rctl_entity_p_t e_tmp; 26880Sstevel@tonic-gate 26890Sstevel@tonic-gate rctl_action_acquire: 26900Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 26910Sstevel@tonic-gate if (rctl_set_find(rset, hndl, &lrctl) == -1) { 26920Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 26930Sstevel@tonic-gate return (ret); 26940Sstevel@tonic-gate } 26950Sstevel@tonic-gate 26960Sstevel@tonic-gate if (e == NULL) { 26970Sstevel@tonic-gate rctl_entity_obtain_entity_p(lrctl->rc_dict_entry->rcd_entity, 26980Sstevel@tonic-gate p, &e_tmp); 26990Sstevel@tonic-gate e = &e_tmp; 27000Sstevel@tonic-gate } 27010Sstevel@tonic-gate 27020Sstevel@tonic-gate if ((ret & RCT_LK_ABANDONED) == 0) { 27030Sstevel@tonic-gate ret |= rctl_global_action(lrctl, rset, p, lrctl->rc_cursor); 27040Sstevel@tonic-gate 27050Sstevel@tonic-gate RCTLOP_ACTION(lrctl, p, e); 27060Sstevel@tonic-gate 27070Sstevel@tonic-gate ret |= rctl_local_action(lrctl, rset, p, 27080Sstevel@tonic-gate lrctl->rc_cursor, safety); 27090Sstevel@tonic-gate 27100Sstevel@tonic-gate if (ret & RCT_LK_ABANDONED) 27110Sstevel@tonic-gate goto rctl_action_acquire; 27120Sstevel@tonic-gate } 27130Sstevel@tonic-gate 27140Sstevel@tonic-gate ret &= ~RCT_LK_ABANDONED; 27150Sstevel@tonic-gate 27160Sstevel@tonic-gate if (!(ret & RCT_DENY) && 27170Sstevel@tonic-gate lrctl->rc_cursor->rcv_next != NULL) { 27180Sstevel@tonic-gate lrctl->rc_cursor = lrctl->rc_cursor->rcv_next; 27190Sstevel@tonic-gate 27200Sstevel@tonic-gate RCTLOP_SET(lrctl, p, e, rctl_model_value(lrctl->rc_dict_entry, 27210Sstevel@tonic-gate p, lrctl->rc_cursor->rcv_value)); 27220Sstevel@tonic-gate 27230Sstevel@tonic-gate } 27240Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 27250Sstevel@tonic-gate 27260Sstevel@tonic-gate return (ret); 27270Sstevel@tonic-gate } 27280Sstevel@tonic-gate 27290Sstevel@tonic-gate /* 27300Sstevel@tonic-gate * int rctl_test(rctl_hndl_t, rctl_set_t *, struct proc *, rctl_qty_t, uint_t) 27310Sstevel@tonic-gate * 27320Sstevel@tonic-gate * Overview 27330Sstevel@tonic-gate * Increment the resource associated with the given handle, returning zero if 27340Sstevel@tonic-gate * the incremented value does not exceed the threshold for the current limit 27350Sstevel@tonic-gate * on the resource. 27360Sstevel@tonic-gate * 27370Sstevel@tonic-gate * Return values 27380Sstevel@tonic-gate * Actions taken, according to the rctl_test bitmask. 27390Sstevel@tonic-gate * 27400Sstevel@tonic-gate * Caller's context 27410Sstevel@tonic-gate * p_lock held by caller. 27420Sstevel@tonic-gate */ 27430Sstevel@tonic-gate /*ARGSUSED*/ 27440Sstevel@tonic-gate int 27450Sstevel@tonic-gate rctl_test(rctl_hndl_t rhndl, rctl_set_t *rset, struct proc *p, 27460Sstevel@tonic-gate rctl_qty_t incr, uint_t flags) 27470Sstevel@tonic-gate { 27480Sstevel@tonic-gate return (rctl_test_entity(rhndl, rset, p, NULL, incr, flags)); 27490Sstevel@tonic-gate } 27500Sstevel@tonic-gate 27510Sstevel@tonic-gate int 27520Sstevel@tonic-gate rctl_test_entity(rctl_hndl_t rhndl, rctl_set_t *rset, struct proc *p, 27530Sstevel@tonic-gate rctl_entity_p_t *e, rctl_qty_t incr, uint_t flags) 27540Sstevel@tonic-gate { 27550Sstevel@tonic-gate rctl_t *lrctl; 27560Sstevel@tonic-gate int ret = RCT_NONE; 27570Sstevel@tonic-gate rctl_entity_p_t e_tmp; 27580Sstevel@tonic-gate if (p == &p0) { 27590Sstevel@tonic-gate /* 27600Sstevel@tonic-gate * We don't enforce rctls on the kernel itself. 27610Sstevel@tonic-gate */ 27620Sstevel@tonic-gate return (ret); 27630Sstevel@tonic-gate } 27640Sstevel@tonic-gate 27650Sstevel@tonic-gate rctl_test_acquire: 27660Sstevel@tonic-gate ASSERT(MUTEX_HELD(&p->p_lock)); 27670Sstevel@tonic-gate 27680Sstevel@tonic-gate mutex_enter(&rset->rcs_lock); 27690Sstevel@tonic-gate 27700Sstevel@tonic-gate /* 27710Sstevel@tonic-gate * Dereference from rctl_set. We don't enforce newly loaded controls 27720Sstevel@tonic-gate * that haven't been set on this entity (since the only valid value is 27730Sstevel@tonic-gate * the infinite system value). 27740Sstevel@tonic-gate */ 27750Sstevel@tonic-gate if (rctl_set_find(rset, rhndl, &lrctl) == -1) { 27760Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 27770Sstevel@tonic-gate return (ret); 27780Sstevel@tonic-gate } 27790Sstevel@tonic-gate 27800Sstevel@tonic-gate /* 27810Sstevel@tonic-gate * This control is currently unenforced: maximal value on control 27820Sstevel@tonic-gate * supporting infinitely available resource. 27830Sstevel@tonic-gate */ 27840Sstevel@tonic-gate if ((lrctl->rc_dict_entry->rcd_flagaction & RCTL_GLOBAL_INFINITE) && 27850Sstevel@tonic-gate (lrctl->rc_cursor->rcv_flagaction & RCTL_LOCAL_MAXIMAL)) { 27860Sstevel@tonic-gate 27870Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 27880Sstevel@tonic-gate return (ret); 27890Sstevel@tonic-gate } 27900Sstevel@tonic-gate 27910Sstevel@tonic-gate /* 27920Sstevel@tonic-gate * If we have been called by rctl_test, look up the entity pointer 27930Sstevel@tonic-gate * from the proc pointer. 27940Sstevel@tonic-gate */ 27950Sstevel@tonic-gate if (e == NULL) { 27960Sstevel@tonic-gate rctl_entity_obtain_entity_p(lrctl->rc_dict_entry->rcd_entity, 27970Sstevel@tonic-gate p, &e_tmp); 27980Sstevel@tonic-gate e = &e_tmp; 27990Sstevel@tonic-gate } 28000Sstevel@tonic-gate 28010Sstevel@tonic-gate /* 28020Sstevel@tonic-gate * Get enforced rctl value and current usage. Test the increment 28030Sstevel@tonic-gate * with the current usage against the enforced value--take action as 28040Sstevel@tonic-gate * necessary. 28050Sstevel@tonic-gate */ 28060Sstevel@tonic-gate while (RCTLOP_TEST(lrctl, p, e, lrctl->rc_cursor, incr, flags)) { 28070Sstevel@tonic-gate if ((ret & RCT_LK_ABANDONED) == 0) { 28080Sstevel@tonic-gate ret |= rctl_global_action(lrctl, rset, p, 28090Sstevel@tonic-gate lrctl->rc_cursor); 28100Sstevel@tonic-gate 28110Sstevel@tonic-gate RCTLOP_ACTION(lrctl, p, e); 28120Sstevel@tonic-gate 28130Sstevel@tonic-gate ret |= rctl_local_action(lrctl, rset, p, 28140Sstevel@tonic-gate lrctl->rc_cursor, flags); 28150Sstevel@tonic-gate 28160Sstevel@tonic-gate if (ret & RCT_LK_ABANDONED) 28170Sstevel@tonic-gate goto rctl_test_acquire; 28180Sstevel@tonic-gate } 28190Sstevel@tonic-gate 28200Sstevel@tonic-gate ret &= ~RCT_LK_ABANDONED; 28210Sstevel@tonic-gate 28220Sstevel@tonic-gate if ((ret & RCT_DENY) == RCT_DENY || 28230Sstevel@tonic-gate lrctl->rc_cursor->rcv_next == NULL) { 28240Sstevel@tonic-gate ret |= RCT_DENY; 28250Sstevel@tonic-gate break; 28260Sstevel@tonic-gate } 28270Sstevel@tonic-gate 28280Sstevel@tonic-gate lrctl->rc_cursor = lrctl->rc_cursor->rcv_next; 28290Sstevel@tonic-gate RCTLOP_SET(lrctl, p, e, rctl_model_value(lrctl->rc_dict_entry, 28300Sstevel@tonic-gate p, lrctl->rc_cursor->rcv_value)); 28310Sstevel@tonic-gate } 28320Sstevel@tonic-gate 28330Sstevel@tonic-gate mutex_exit(&rset->rcs_lock); 28340Sstevel@tonic-gate 28350Sstevel@tonic-gate return (ret); 28360Sstevel@tonic-gate } 28370Sstevel@tonic-gate 28380Sstevel@tonic-gate /* 28390Sstevel@tonic-gate * void rctl_init(void) 28400Sstevel@tonic-gate * 28410Sstevel@tonic-gate * Overview 28420Sstevel@tonic-gate * Initialize the rctl subsystem, including the primoridal rctls 28430Sstevel@tonic-gate * provided by the system. New subsystem-specific rctls should _not_ be 28440Sstevel@tonic-gate * initialized here. (Do it in your own file.) 28450Sstevel@tonic-gate * 28460Sstevel@tonic-gate * Return values 28470Sstevel@tonic-gate * None. 28480Sstevel@tonic-gate * 28490Sstevel@tonic-gate * Caller's context 28500Sstevel@tonic-gate * Safe for KM_SLEEP allocations. Must be called prior to any process model 28510Sstevel@tonic-gate * initialization. 28520Sstevel@tonic-gate */ 28530Sstevel@tonic-gate void 28540Sstevel@tonic-gate rctl_init(void) 28550Sstevel@tonic-gate { 28560Sstevel@tonic-gate rctl_cache = kmem_cache_create("rctl_cache", sizeof (rctl_t), 28570Sstevel@tonic-gate 0, NULL, NULL, NULL, NULL, NULL, 0); 28580Sstevel@tonic-gate rctl_val_cache = kmem_cache_create("rctl_val_cache", 28590Sstevel@tonic-gate sizeof (rctl_val_t), 0, NULL, NULL, NULL, NULL, NULL, 0); 28600Sstevel@tonic-gate 28610Sstevel@tonic-gate rctl_dict = mod_hash_create_extended("rctl_dict", 28620Sstevel@tonic-gate rctl_dict_size, mod_hash_null_keydtor, rctl_dict_val_dtor, 28630Sstevel@tonic-gate rctl_dict_hash_by_id, NULL, rctl_dict_id_cmp, KM_SLEEP); 28640Sstevel@tonic-gate rctl_dict_by_name = mod_hash_create_strhash( 28650Sstevel@tonic-gate "rctl_handles_by_name", rctl_dict_size, 28660Sstevel@tonic-gate mod_hash_null_valdtor); 28670Sstevel@tonic-gate rctl_ids = id_space_create("rctl_ids", 1, max_rctl_hndl); 28680Sstevel@tonic-gate bzero(rctl_lists, (RC_MAX_ENTITY + 1) * sizeof (rctl_dict_entry_t *)); 28690Sstevel@tonic-gate 28700Sstevel@tonic-gate rctlproc_init(); 28710Sstevel@tonic-gate } 28722768Ssl108498 28732768Ssl108498 /* 28742768Ssl108498 * rctl_incr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc) 28752768Ssl108498 * 28762768Ssl108498 * Increments the amount of locked memory on a project, and 28772768Ssl108498 * zone. If proj is NULL, the proj and zone of proc_t p is used. If 28782768Ssl108498 * chargeproc is non-zero, then the charged amount is cached on p->p_locked_mem 28792768Ssl108498 * so that the charge can be migrated when a process changes projects. 28802768Ssl108498 * 28812768Ssl108498 * Return values 28822768Ssl108498 * 0 - success 28832768Ssl108498 * EAGAIN - attempting to increment locked memory is denied by one 28842768Ssl108498 * or more resource entities. 28852768Ssl108498 */ 28862768Ssl108498 int 28872768Ssl108498 rctl_incr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc, 28882768Ssl108498 int chargeproc) 28892768Ssl108498 { 28902768Ssl108498 kproject_t *projp; 28912768Ssl108498 zone_t *zonep; 28922768Ssl108498 rctl_entity_p_t e; 28932768Ssl108498 int ret = 0; 28942768Ssl108498 28952768Ssl108498 ASSERT(p != NULL); 28962768Ssl108498 ASSERT(MUTEX_HELD(&p->p_lock)); 28972768Ssl108498 if (proj != NULL) { 28982768Ssl108498 projp = proj; 28992768Ssl108498 zonep = zone_find_by_id(projp->kpj_zoneid); 29002768Ssl108498 } else { 29012768Ssl108498 projp = p->p_task->tk_proj; 29022768Ssl108498 zonep = p->p_zone; 29032768Ssl108498 } 29042768Ssl108498 29053247Sgjelinek mutex_enter(&zonep->zone_mem_lock); 29062768Ssl108498 29072768Ssl108498 e.rcep_p.proj = projp; 29082768Ssl108498 e.rcep_t = RCENTITY_PROJECT; 29092768Ssl108498 if (projp->kpj_data.kpd_locked_mem + inc > 29102768Ssl108498 projp->kpj_data.kpd_locked_mem_ctl) { 29112768Ssl108498 if (rctl_test_entity(rc_project_locked_mem, projp->kpj_rctls, 29122768Ssl108498 p, &e, inc, 0) & RCT_DENY) { 29132768Ssl108498 ret = EAGAIN; 29142768Ssl108498 goto out; 29152768Ssl108498 } 29162768Ssl108498 } 29172768Ssl108498 e.rcep_p.zone = zonep; 29182768Ssl108498 e.rcep_t = RCENTITY_ZONE; 29192768Ssl108498 if (zonep->zone_locked_mem + inc > zonep->zone_locked_mem_ctl) { 29202768Ssl108498 if (rctl_test_entity(rc_zone_locked_mem, zonep->zone_rctls, 29212768Ssl108498 p, &e, inc, 0) & RCT_DENY) { 29222768Ssl108498 ret = EAGAIN; 29232768Ssl108498 goto out; 29242768Ssl108498 } 29252768Ssl108498 } 29262768Ssl108498 29272768Ssl108498 zonep->zone_locked_mem += inc; 29282768Ssl108498 projp->kpj_data.kpd_locked_mem += inc; 29292768Ssl108498 if (chargeproc != 0) { 29302768Ssl108498 p->p_locked_mem += inc; 29312768Ssl108498 } 29322768Ssl108498 out: 29333247Sgjelinek mutex_exit(&zonep->zone_mem_lock); 29342768Ssl108498 if (proj != NULL) 29352768Ssl108498 zone_rele(zonep); 29362768Ssl108498 return (ret); 29372768Ssl108498 } 29382768Ssl108498 29392768Ssl108498 /* 29402768Ssl108498 * rctl_decr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc) 29412768Ssl108498 * 29422768Ssl108498 * Decrements the amount of locked memory on a project and 29432768Ssl108498 * zone. If proj is NULL, the proj and zone of proc_t p is used. If 29442768Ssl108498 * creditproc is non-zero, then the quantity of locked memory is subtracted 29452768Ssl108498 * from p->p_locked_mem. 29462768Ssl108498 * 29472768Ssl108498 * Return values 29482768Ssl108498 * none 29492768Ssl108498 */ 29502768Ssl108498 void 29512768Ssl108498 rctl_decr_locked_mem(proc_t *p, kproject_t *proj, rctl_qty_t inc, 29522768Ssl108498 int creditproc) 29532768Ssl108498 { 29542768Ssl108498 kproject_t *projp; 29552768Ssl108498 zone_t *zonep; 29562768Ssl108498 29572768Ssl108498 if (proj != NULL) { 29582768Ssl108498 projp = proj; 29592768Ssl108498 zonep = zone_find_by_id(projp->kpj_zoneid); 29602768Ssl108498 } else { 29612768Ssl108498 ASSERT(p != NULL); 29622768Ssl108498 ASSERT(MUTEX_HELD(&p->p_lock)); 29632768Ssl108498 projp = p->p_task->tk_proj; 29642768Ssl108498 zonep = p->p_zone; 29652768Ssl108498 } 29662768Ssl108498 29673247Sgjelinek mutex_enter(&zonep->zone_mem_lock); 29682768Ssl108498 zonep->zone_locked_mem -= inc; 29692768Ssl108498 projp->kpj_data.kpd_locked_mem -= inc; 29702768Ssl108498 if (creditproc != 0) { 29712768Ssl108498 ASSERT(p != NULL); 29722768Ssl108498 ASSERT(MUTEX_HELD(&p->p_lock)); 29732768Ssl108498 p->p_locked_mem -= inc; 29742768Ssl108498 } 29753247Sgjelinek mutex_exit(&zonep->zone_mem_lock); 29762768Ssl108498 if (proj != NULL) 29772768Ssl108498 zone_rele(zonep); 29782768Ssl108498 } 29793247Sgjelinek 29803247Sgjelinek /* 29813247Sgjelinek * rctl_incr_swap(proc_t *, zone_t *, size_t) 29823247Sgjelinek * 29833247Sgjelinek * Overview 29843247Sgjelinek * Increments the swap charge on the specified zone. 29853247Sgjelinek * 29863247Sgjelinek * Return values 29873247Sgjelinek * 0 on success. EAGAIN if swap increment fails due an rctl value 29883247Sgjelinek * on the zone. 29893247Sgjelinek * 29903247Sgjelinek * Callers context 29913247Sgjelinek * p_lock held on specified proc. 29923247Sgjelinek * swap must be even multiple of PAGESIZE 29933247Sgjelinek */ 29943247Sgjelinek int 29953247Sgjelinek rctl_incr_swap(proc_t *proc, zone_t *zone, size_t swap) 29963247Sgjelinek { 29973247Sgjelinek rctl_entity_p_t e; 29983247Sgjelinek 29993247Sgjelinek ASSERT(MUTEX_HELD(&proc->p_lock)); 30003247Sgjelinek ASSERT((swap & PAGEOFFSET) == 0); 30013247Sgjelinek e.rcep_p.zone = zone; 30023247Sgjelinek e.rcep_t = RCENTITY_ZONE; 30033247Sgjelinek 30043247Sgjelinek mutex_enter(&zone->zone_mem_lock); 30053247Sgjelinek 30063247Sgjelinek if ((zone->zone_max_swap + swap) > 30073247Sgjelinek zone->zone_max_swap_ctl) { 30083247Sgjelinek 30093247Sgjelinek if (rctl_test_entity(rc_zone_max_swap, zone->zone_rctls, 30103247Sgjelinek proc, &e, swap, 0) & RCT_DENY) { 30113247Sgjelinek mutex_exit(&zone->zone_mem_lock); 30123247Sgjelinek return (EAGAIN); 30133247Sgjelinek } 30143247Sgjelinek } 30153247Sgjelinek zone->zone_max_swap += swap; 30163247Sgjelinek mutex_exit(&zone->zone_mem_lock); 30173247Sgjelinek return (0); 30183247Sgjelinek } 30193247Sgjelinek 30203247Sgjelinek /* 30213247Sgjelinek * rctl_decr_swap(zone_t *, size_t) 30223247Sgjelinek * 30233247Sgjelinek * Overview 30243247Sgjelinek * Decrements the swap charge on the specified zone. 30253247Sgjelinek * 30263247Sgjelinek * Return values 30273247Sgjelinek * None 30283247Sgjelinek * 30293247Sgjelinek * Callers context 30303247Sgjelinek * swap must be even multiple of PAGESIZE 30313247Sgjelinek */ 30323247Sgjelinek void 30333247Sgjelinek rctl_decr_swap(zone_t *zone, size_t swap) 30343247Sgjelinek { 30353247Sgjelinek ASSERT((swap & PAGEOFFSET) == 0); 30363247Sgjelinek mutex_enter(&zone->zone_mem_lock); 30373247Sgjelinek ASSERT(zone->zone_max_swap >= swap); 30383247Sgjelinek zone->zone_max_swap -= swap; 30393247Sgjelinek mutex_exit(&zone->zone_mem_lock); 30403247Sgjelinek } 30413247Sgjelinek 30423247Sgjelinek /* 30433247Sgjelinek * Create resource kstat 30443247Sgjelinek */ 30453247Sgjelinek static kstat_t * 30463247Sgjelinek rctl_kstat_create_common(char *ks_name, int ks_instance, char *ks_class, 30473247Sgjelinek uchar_t ks_type, uint_t ks_ndata, uchar_t ks_flags, int ks_zoneid) 30483247Sgjelinek { 30493247Sgjelinek kstat_t *ksp = NULL; 30503247Sgjelinek char name[KSTAT_STRLEN]; 30513247Sgjelinek 30523247Sgjelinek (void) snprintf(name, KSTAT_STRLEN, "%s_%d", ks_name, ks_instance); 30533247Sgjelinek 30543247Sgjelinek if ((ksp = kstat_create_zone("caps", ks_zoneid, 30553247Sgjelinek name, ks_class, ks_type, 30563247Sgjelinek ks_ndata, ks_flags, ks_zoneid)) != NULL) { 30573247Sgjelinek if (ks_zoneid != GLOBAL_ZONEID) 30583247Sgjelinek kstat_zone_add(ksp, GLOBAL_ZONEID); 30593247Sgjelinek } 30603247Sgjelinek return (ksp); 30613247Sgjelinek } 30623247Sgjelinek 30633247Sgjelinek /* 30643247Sgjelinek * Create zone-specific resource kstat 30653247Sgjelinek */ 30663247Sgjelinek kstat_t * 30673247Sgjelinek rctl_kstat_create_zone(zone_t *zone, char *ks_name, uchar_t ks_type, 30683247Sgjelinek uint_t ks_ndata, uchar_t ks_flags) 30693247Sgjelinek { 30703247Sgjelinek char name[KSTAT_STRLEN]; 30713247Sgjelinek 30723247Sgjelinek (void) snprintf(name, KSTAT_STRLEN, "%s_zone", ks_name); 30733247Sgjelinek 30743247Sgjelinek return (rctl_kstat_create_common(name, zone->zone_id, "zone_caps", 30753247Sgjelinek ks_type, ks_ndata, ks_flags, zone->zone_id)); 30763247Sgjelinek } 30773247Sgjelinek 30783247Sgjelinek /* 30793247Sgjelinek * Create project-specific resource kstat 30803247Sgjelinek */ 30813247Sgjelinek kstat_t * 30823247Sgjelinek rctl_kstat_create_project(kproject_t *kpj, char *ks_name, uchar_t ks_type, 30833247Sgjelinek uint_t ks_ndata, uchar_t ks_flags) 30843247Sgjelinek { 30853247Sgjelinek char name[KSTAT_STRLEN]; 30863247Sgjelinek 30873247Sgjelinek (void) snprintf(name, KSTAT_STRLEN, "%s_project", ks_name); 30883247Sgjelinek 30893247Sgjelinek return (rctl_kstat_create_common(name, kpj->kpj_id, "project_caps", 30903247Sgjelinek ks_type, ks_ndata, ks_flags, kpj->kpj_zoneid)); 30913247Sgjelinek } 3092