xref: /onnv-gate/usr/src/uts/common/vm/vm_page.c (revision 5331:3047ad28a67b)
10Sstevel@tonic-gate /*
20Sstevel@tonic-gate  * CDDL HEADER START
30Sstevel@tonic-gate  *
40Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
52048Sstans  * Common Development and Distribution License (the "License").
62048Sstans  * You may not use this file except in compliance with the License.
70Sstevel@tonic-gate  *
80Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
90Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
100Sstevel@tonic-gate  * See the License for the specific language governing permissions
110Sstevel@tonic-gate  * and limitations under the License.
120Sstevel@tonic-gate  *
130Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
140Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
150Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
160Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
170Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
180Sstevel@tonic-gate  *
190Sstevel@tonic-gate  * CDDL HEADER END
200Sstevel@tonic-gate  */
210Sstevel@tonic-gate /*
223480Sjfrank  * Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
230Sstevel@tonic-gate  * Use is subject to license terms.
240Sstevel@tonic-gate  */
250Sstevel@tonic-gate 
260Sstevel@tonic-gate /*	Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989  AT&T	*/
270Sstevel@tonic-gate /*	  All Rights Reserved  	*/
280Sstevel@tonic-gate 
290Sstevel@tonic-gate /*
300Sstevel@tonic-gate  * University Copyright- Copyright (c) 1982, 1986, 1988
310Sstevel@tonic-gate  * The Regents of the University of California
320Sstevel@tonic-gate  * All Rights Reserved
330Sstevel@tonic-gate  *
340Sstevel@tonic-gate  * University Acknowledgment- Portions of this document are derived from
350Sstevel@tonic-gate  * software developed by the University of California, Berkeley, and its
360Sstevel@tonic-gate  * contributors.
370Sstevel@tonic-gate  */
380Sstevel@tonic-gate 
390Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
400Sstevel@tonic-gate 
410Sstevel@tonic-gate /*
420Sstevel@tonic-gate  * VM - physical page management.
430Sstevel@tonic-gate  */
440Sstevel@tonic-gate 
450Sstevel@tonic-gate #include <sys/types.h>
460Sstevel@tonic-gate #include <sys/t_lock.h>
470Sstevel@tonic-gate #include <sys/param.h>
480Sstevel@tonic-gate #include <sys/systm.h>
490Sstevel@tonic-gate #include <sys/errno.h>
500Sstevel@tonic-gate #include <sys/time.h>
510Sstevel@tonic-gate #include <sys/vnode.h>
520Sstevel@tonic-gate #include <sys/vm.h>
530Sstevel@tonic-gate #include <sys/vtrace.h>
540Sstevel@tonic-gate #include <sys/swap.h>
550Sstevel@tonic-gate #include <sys/cmn_err.h>
560Sstevel@tonic-gate #include <sys/tuneable.h>
570Sstevel@tonic-gate #include <sys/sysmacros.h>
580Sstevel@tonic-gate #include <sys/cpuvar.h>
590Sstevel@tonic-gate #include <sys/callb.h>
600Sstevel@tonic-gate #include <sys/debug.h>
610Sstevel@tonic-gate #include <sys/tnf_probe.h>
620Sstevel@tonic-gate #include <sys/condvar_impl.h>
630Sstevel@tonic-gate #include <sys/mem_config.h>
640Sstevel@tonic-gate #include <sys/mem_cage.h>
650Sstevel@tonic-gate #include <sys/kmem.h>
660Sstevel@tonic-gate #include <sys/atomic.h>
670Sstevel@tonic-gate #include <sys/strlog.h>
680Sstevel@tonic-gate #include <sys/mman.h>
690Sstevel@tonic-gate #include <sys/ontrap.h>
700Sstevel@tonic-gate #include <sys/lgrp.h>
710Sstevel@tonic-gate #include <sys/vfs.h>
720Sstevel@tonic-gate 
730Sstevel@tonic-gate #include <vm/hat.h>
740Sstevel@tonic-gate #include <vm/anon.h>
750Sstevel@tonic-gate #include <vm/page.h>
760Sstevel@tonic-gate #include <vm/seg.h>
770Sstevel@tonic-gate #include <vm/pvn.h>
780Sstevel@tonic-gate #include <vm/seg_kmem.h>
790Sstevel@tonic-gate #include <vm/vm_dep.h>
803247Sgjelinek #include <sys/vm_usage.h>
810Sstevel@tonic-gate #include <fs/fs_subr.h>
823480Sjfrank #include <sys/ddi.h>
833480Sjfrank #include <sys/modctl.h>
840Sstevel@tonic-gate 
850Sstevel@tonic-gate static int nopageage = 0;
860Sstevel@tonic-gate 
870Sstevel@tonic-gate static pgcnt_t max_page_get;	/* max page_get request size in pages */
880Sstevel@tonic-gate pgcnt_t total_pages = 0;	/* total number of pages (used by /proc) */
890Sstevel@tonic-gate 
900Sstevel@tonic-gate /*
910Sstevel@tonic-gate  * freemem_lock protects all freemem variables:
920Sstevel@tonic-gate  * availrmem. Also this lock protects the globals which track the
930Sstevel@tonic-gate  * availrmem changes for accurate kernel footprint calculation.
940Sstevel@tonic-gate  * See below for an explanation of these
950Sstevel@tonic-gate  * globals.
960Sstevel@tonic-gate  */
970Sstevel@tonic-gate kmutex_t freemem_lock;
980Sstevel@tonic-gate pgcnt_t availrmem;
990Sstevel@tonic-gate pgcnt_t availrmem_initial;
1000Sstevel@tonic-gate 
1010Sstevel@tonic-gate /*
1020Sstevel@tonic-gate  * These globals track availrmem changes to get a more accurate
1030Sstevel@tonic-gate  * estimate of tke kernel size. Historically pp_kernel is used for
1040Sstevel@tonic-gate  * kernel size and is based on availrmem. But availrmem is adjusted for
1050Sstevel@tonic-gate  * locked pages in the system not just for kernel locked pages.
1060Sstevel@tonic-gate  * These new counters will track the pages locked through segvn and
1070Sstevel@tonic-gate  * by explicit user locking.
1080Sstevel@tonic-gate  *
1090Sstevel@tonic-gate  * segvn_pages_locked : This keeps track on a global basis how many pages
1100Sstevel@tonic-gate  * are currently locked because of I/O.
1110Sstevel@tonic-gate  *
112*5331Samw  * pages_locked : How many pages are locked because of user specified
1130Sstevel@tonic-gate  * locking through mlock or plock.
1140Sstevel@tonic-gate  *
1150Sstevel@tonic-gate  * pages_useclaim,pages_claimed : These two variables track the
116*5331Samw  * claim adjustments because of the protection changes on a segvn segment.
1170Sstevel@tonic-gate  *
1180Sstevel@tonic-gate  * All these globals are protected by the same lock which protects availrmem.
1190Sstevel@tonic-gate  */
1200Sstevel@tonic-gate pgcnt_t segvn_pages_locked;
1210Sstevel@tonic-gate pgcnt_t pages_locked;
1220Sstevel@tonic-gate pgcnt_t pages_useclaim;
1230Sstevel@tonic-gate pgcnt_t pages_claimed;
1240Sstevel@tonic-gate 
1250Sstevel@tonic-gate 
1260Sstevel@tonic-gate /*
1270Sstevel@tonic-gate  * new_freemem_lock protects freemem, freemem_wait & freemem_cv.
1280Sstevel@tonic-gate  */
1290Sstevel@tonic-gate static kmutex_t	new_freemem_lock;
1300Sstevel@tonic-gate static uint_t	freemem_wait;	/* someone waiting for freemem */
1310Sstevel@tonic-gate static kcondvar_t freemem_cv;
1320Sstevel@tonic-gate 
1330Sstevel@tonic-gate /*
1340Sstevel@tonic-gate  * The logical page free list is maintained as two lists, the 'free'
1350Sstevel@tonic-gate  * and the 'cache' lists.
1360Sstevel@tonic-gate  * The free list contains those pages that should be reused first.
1370Sstevel@tonic-gate  *
1380Sstevel@tonic-gate  * The implementation of the lists is machine dependent.
1390Sstevel@tonic-gate  * page_get_freelist(), page_get_cachelist(),
1400Sstevel@tonic-gate  * page_list_sub(), and page_list_add()
1410Sstevel@tonic-gate  * form the interface to the machine dependent implementation.
1420Sstevel@tonic-gate  *
1430Sstevel@tonic-gate  * Pages with p_free set are on the cache list.
1440Sstevel@tonic-gate  * Pages with p_free and p_age set are on the free list,
1450Sstevel@tonic-gate  *
1460Sstevel@tonic-gate  * A page may be locked while on either list.
1470Sstevel@tonic-gate  */
1480Sstevel@tonic-gate 
1490Sstevel@tonic-gate /*
1500Sstevel@tonic-gate  * free list accounting stuff.
1510Sstevel@tonic-gate  *
1520Sstevel@tonic-gate  *
1530Sstevel@tonic-gate  * Spread out the value for the number of pages on the
1540Sstevel@tonic-gate  * page free and page cache lists.  If there is just one
1550Sstevel@tonic-gate  * value, then it must be under just one lock.
1560Sstevel@tonic-gate  * The lock contention and cache traffic are a real bother.
1570Sstevel@tonic-gate  *
1580Sstevel@tonic-gate  * When we acquire and then drop a single pcf lock
1590Sstevel@tonic-gate  * we can start in the middle of the array of pcf structures.
1600Sstevel@tonic-gate  * If we acquire more than one pcf lock at a time, we need to
1610Sstevel@tonic-gate  * start at the front to avoid deadlocking.
1620Sstevel@tonic-gate  *
1630Sstevel@tonic-gate  * pcf_count holds the number of pages in each pool.
1640Sstevel@tonic-gate  *
1650Sstevel@tonic-gate  * pcf_block is set when page_create_get_something() has asked the
1660Sstevel@tonic-gate  * PSM page freelist and page cachelist routines without specifying
1670Sstevel@tonic-gate  * a color and nothing came back.  This is used to block anything
1680Sstevel@tonic-gate  * else from moving pages from one list to the other while the
1690Sstevel@tonic-gate  * lists are searched again.  If a page is freeed while pcf_block is
1700Sstevel@tonic-gate  * set, then pcf_reserve is incremented.  pcgs_unblock() takes care
1710Sstevel@tonic-gate  * of clearning pcf_block, doing the wakeups, etc.
1720Sstevel@tonic-gate  */
1730Sstevel@tonic-gate 
1740Sstevel@tonic-gate #if NCPU <= 4
1752290Sfr157268 #define	PAD	2
1760Sstevel@tonic-gate #define	PCF_FANOUT	4
1770Sstevel@tonic-gate static	uint_t	pcf_mask = PCF_FANOUT - 1;
1780Sstevel@tonic-gate #else
1792290Sfr157268 #define	PAD	10
1800Sstevel@tonic-gate #ifdef sun4v
1810Sstevel@tonic-gate #define	PCF_FANOUT	32
1820Sstevel@tonic-gate #else
1830Sstevel@tonic-gate #define	PCF_FANOUT	128
1840Sstevel@tonic-gate #endif
1850Sstevel@tonic-gate static	uint_t	pcf_mask = PCF_FANOUT - 1;
1860Sstevel@tonic-gate #endif
1870Sstevel@tonic-gate 
1880Sstevel@tonic-gate struct pcf {
1892290Sfr157268 	kmutex_t	pcf_lock;	/* protects the structure */
1900Sstevel@tonic-gate 	uint_t		pcf_count;	/* page count */
1910Sstevel@tonic-gate 	uint_t		pcf_wait;	/* number of waiters */
1920Sstevel@tonic-gate 	uint_t		pcf_block; 	/* pcgs flag to page_free() */
1930Sstevel@tonic-gate 	uint_t		pcf_reserve; 	/* pages freed after pcf_block set */
1940Sstevel@tonic-gate 	uint_t		pcf_fill[PAD];	/* to line up on the caches */
1950Sstevel@tonic-gate };
1960Sstevel@tonic-gate 
1970Sstevel@tonic-gate static struct	pcf	pcf[PCF_FANOUT];
1980Sstevel@tonic-gate #define	PCF_INDEX()	((CPU->cpu_id) & (pcf_mask))
1990Sstevel@tonic-gate 
2000Sstevel@tonic-gate kmutex_t	pcgs_lock;		/* serializes page_create_get_ */
2010Sstevel@tonic-gate kmutex_t	pcgs_cagelock;		/* serializes NOSLEEP cage allocs */
2020Sstevel@tonic-gate kmutex_t	pcgs_wait_lock;		/* used for delay in pcgs */
2030Sstevel@tonic-gate static kcondvar_t	pcgs_cv;	/* cv for delay in pcgs */
2040Sstevel@tonic-gate 
2050Sstevel@tonic-gate #ifdef VM_STATS
2060Sstevel@tonic-gate 
2070Sstevel@tonic-gate /*
2080Sstevel@tonic-gate  * No locks, but so what, they are only statistics.
2090Sstevel@tonic-gate  */
2100Sstevel@tonic-gate 
2110Sstevel@tonic-gate static struct page_tcnt {
2120Sstevel@tonic-gate 	int	pc_free_cache;		/* free's into cache list */
2130Sstevel@tonic-gate 	int	pc_free_dontneed;	/* free's with dontneed */
2140Sstevel@tonic-gate 	int	pc_free_pageout;	/* free's from pageout */
2150Sstevel@tonic-gate 	int	pc_free_free;		/* free's into free list */
2160Sstevel@tonic-gate 	int	pc_free_pages;		/* free's into large page free list */
2170Sstevel@tonic-gate 	int	pc_destroy_pages;	/* large page destroy's */
2180Sstevel@tonic-gate 	int	pc_get_cache;		/* get's from cache list */
2190Sstevel@tonic-gate 	int	pc_get_free;		/* get's from free list */
2200Sstevel@tonic-gate 	int	pc_reclaim;		/* reclaim's */
2210Sstevel@tonic-gate 	int	pc_abortfree;		/* abort's of free pages */
2220Sstevel@tonic-gate 	int	pc_find_hit;		/* find's that find page */
2230Sstevel@tonic-gate 	int	pc_find_miss;		/* find's that don't find page */
2240Sstevel@tonic-gate 	int	pc_destroy_free;	/* # of free pages destroyed */
2250Sstevel@tonic-gate #define	PC_HASH_CNT	(4*PAGE_HASHAVELEN)
2260Sstevel@tonic-gate 	int	pc_find_hashlen[PC_HASH_CNT+1];
2270Sstevel@tonic-gate 	int	pc_addclaim_pages;
2280Sstevel@tonic-gate 	int	pc_subclaim_pages;
2290Sstevel@tonic-gate 	int	pc_free_replacement_page[2];
2300Sstevel@tonic-gate 	int	pc_try_demote_pages[6];
2310Sstevel@tonic-gate 	int	pc_demote_pages[2];
2320Sstevel@tonic-gate } pagecnt;
2330Sstevel@tonic-gate 
2340Sstevel@tonic-gate uint_t	hashin_count;
2350Sstevel@tonic-gate uint_t	hashin_not_held;
2360Sstevel@tonic-gate uint_t	hashin_already;
2370Sstevel@tonic-gate 
2380Sstevel@tonic-gate uint_t	hashout_count;
2390Sstevel@tonic-gate uint_t	hashout_not_held;
2400Sstevel@tonic-gate 
2410Sstevel@tonic-gate uint_t	page_create_count;
2420Sstevel@tonic-gate uint_t	page_create_not_enough;
2430Sstevel@tonic-gate uint_t	page_create_not_enough_again;
2440Sstevel@tonic-gate uint_t	page_create_zero;
2450Sstevel@tonic-gate uint_t	page_create_hashout;
2460Sstevel@tonic-gate uint_t	page_create_page_lock_failed;
2470Sstevel@tonic-gate uint_t	page_create_trylock_failed;
2480Sstevel@tonic-gate uint_t	page_create_found_one;
2490Sstevel@tonic-gate uint_t	page_create_hashin_failed;
2500Sstevel@tonic-gate uint_t	page_create_dropped_phm;
2510Sstevel@tonic-gate 
2520Sstevel@tonic-gate uint_t	page_create_new;
2530Sstevel@tonic-gate uint_t	page_create_exists;
2540Sstevel@tonic-gate uint_t	page_create_putbacks;
2550Sstevel@tonic-gate uint_t	page_create_overshoot;
2560Sstevel@tonic-gate 
2570Sstevel@tonic-gate uint_t	page_reclaim_zero;
2580Sstevel@tonic-gate uint_t	page_reclaim_zero_locked;
2590Sstevel@tonic-gate 
2600Sstevel@tonic-gate uint_t	page_rename_exists;
2610Sstevel@tonic-gate uint_t	page_rename_count;
2620Sstevel@tonic-gate 
2630Sstevel@tonic-gate uint_t	page_lookup_cnt[20];
2640Sstevel@tonic-gate uint_t	page_lookup_nowait_cnt[10];
2650Sstevel@tonic-gate uint_t	page_find_cnt;
2660Sstevel@tonic-gate uint_t	page_exists_cnt;
2670Sstevel@tonic-gate uint_t	page_exists_forreal_cnt;
2680Sstevel@tonic-gate uint_t	page_lookup_dev_cnt;
2690Sstevel@tonic-gate uint_t	get_cachelist_cnt;
2700Sstevel@tonic-gate uint_t	page_create_cnt[10];
2710Sstevel@tonic-gate uint_t	alloc_pages[8];
2720Sstevel@tonic-gate uint_t	page_exphcontg[19];
2730Sstevel@tonic-gate uint_t  page_create_large_cnt[10];
2740Sstevel@tonic-gate 
2750Sstevel@tonic-gate /*
2760Sstevel@tonic-gate  * Collects statistics.
2770Sstevel@tonic-gate  */
2780Sstevel@tonic-gate #define	PAGE_HASH_SEARCH(index, pp, vp, off) { \
2790Sstevel@tonic-gate 	uint_t	mylen = 0; \
2800Sstevel@tonic-gate 			\
2810Sstevel@tonic-gate 	for ((pp) = page_hash[(index)]; (pp); (pp) = (pp)->p_hash, mylen++) { \
2820Sstevel@tonic-gate 		if ((pp)->p_vnode == (vp) && (pp)->p_offset == (off)) \
2830Sstevel@tonic-gate 			break; \
2840Sstevel@tonic-gate 	} \
2850Sstevel@tonic-gate 	if ((pp) != NULL) \
2860Sstevel@tonic-gate 		pagecnt.pc_find_hit++; \
2870Sstevel@tonic-gate 	else \
2880Sstevel@tonic-gate 		pagecnt.pc_find_miss++; \
2890Sstevel@tonic-gate 	if (mylen > PC_HASH_CNT) \
2900Sstevel@tonic-gate 		mylen = PC_HASH_CNT; \
2910Sstevel@tonic-gate 	pagecnt.pc_find_hashlen[mylen]++; \
2920Sstevel@tonic-gate }
2930Sstevel@tonic-gate 
2940Sstevel@tonic-gate #else	/* VM_STATS */
2950Sstevel@tonic-gate 
2960Sstevel@tonic-gate /*
2970Sstevel@tonic-gate  * Don't collect statistics
2980Sstevel@tonic-gate  */
2990Sstevel@tonic-gate #define	PAGE_HASH_SEARCH(index, pp, vp, off) { \
3000Sstevel@tonic-gate 	for ((pp) = page_hash[(index)]; (pp); (pp) = (pp)->p_hash) { \
3010Sstevel@tonic-gate 		if ((pp)->p_vnode == (vp) && (pp)->p_offset == (off)) \
3020Sstevel@tonic-gate 			break; \
3030Sstevel@tonic-gate 	} \
3040Sstevel@tonic-gate }
3050Sstevel@tonic-gate 
3060Sstevel@tonic-gate #endif	/* VM_STATS */
3070Sstevel@tonic-gate 
3080Sstevel@tonic-gate 
3090Sstevel@tonic-gate 
3100Sstevel@tonic-gate #ifdef DEBUG
3110Sstevel@tonic-gate #define	MEMSEG_SEARCH_STATS
3120Sstevel@tonic-gate #endif
3130Sstevel@tonic-gate 
3140Sstevel@tonic-gate #ifdef MEMSEG_SEARCH_STATS
3150Sstevel@tonic-gate struct memseg_stats {
3160Sstevel@tonic-gate     uint_t nsearch;
3170Sstevel@tonic-gate     uint_t nlastwon;
3180Sstevel@tonic-gate     uint_t nhashwon;
3190Sstevel@tonic-gate     uint_t nnotfound;
3200Sstevel@tonic-gate } memseg_stats;
3210Sstevel@tonic-gate 
3220Sstevel@tonic-gate #define	MEMSEG_STAT_INCR(v) \
3230Sstevel@tonic-gate 	atomic_add_32(&memseg_stats.v, 1)
3240Sstevel@tonic-gate #else
3250Sstevel@tonic-gate #define	MEMSEG_STAT_INCR(x)
3260Sstevel@tonic-gate #endif
3270Sstevel@tonic-gate 
3280Sstevel@tonic-gate struct memseg *memsegs;		/* list of memory segments */
3290Sstevel@tonic-gate 
3300Sstevel@tonic-gate 
3310Sstevel@tonic-gate static void page_init_mem_config(void);
3320Sstevel@tonic-gate static int page_do_hashin(page_t *, vnode_t *, u_offset_t);
3330Sstevel@tonic-gate static void page_do_hashout(page_t *);
3343253Smec static void page_capture_init();
3353253Smec int page_capture_take_action(page_t *, uint_t, void *);
3360Sstevel@tonic-gate 
3370Sstevel@tonic-gate static void page_demote_vp_pages(page_t *);
3380Sstevel@tonic-gate 
3390Sstevel@tonic-gate /*
3400Sstevel@tonic-gate  * vm subsystem related initialization
3410Sstevel@tonic-gate  */
3420Sstevel@tonic-gate void
3430Sstevel@tonic-gate vm_init(void)
3440Sstevel@tonic-gate {
3450Sstevel@tonic-gate 	boolean_t callb_vm_cpr(void *, int);
3460Sstevel@tonic-gate 
3470Sstevel@tonic-gate 	(void) callb_add(callb_vm_cpr, 0, CB_CL_CPR_VM, "vm");
3480Sstevel@tonic-gate 	page_init_mem_config();
349917Selowe 	page_retire_init();
3503247Sgjelinek 	vm_usage_init();
3513253Smec 	page_capture_init();
3520Sstevel@tonic-gate }
3530Sstevel@tonic-gate 
3540Sstevel@tonic-gate /*
3550Sstevel@tonic-gate  * This function is called at startup and when memory is added or deleted.
3560Sstevel@tonic-gate  */
3570Sstevel@tonic-gate void
3580Sstevel@tonic-gate init_pages_pp_maximum()
3590Sstevel@tonic-gate {
3600Sstevel@tonic-gate 	static pgcnt_t p_min;
3610Sstevel@tonic-gate 	static pgcnt_t pages_pp_maximum_startup;
3620Sstevel@tonic-gate 	static pgcnt_t avrmem_delta;
3630Sstevel@tonic-gate 	static int init_done;
3640Sstevel@tonic-gate 	static int user_set;	/* true if set in /etc/system */
3650Sstevel@tonic-gate 
3660Sstevel@tonic-gate 	if (init_done == 0) {
3670Sstevel@tonic-gate 
3680Sstevel@tonic-gate 		/* If the user specified a value, save it */
3690Sstevel@tonic-gate 		if (pages_pp_maximum != 0) {
3700Sstevel@tonic-gate 			user_set = 1;
3710Sstevel@tonic-gate 			pages_pp_maximum_startup = pages_pp_maximum;
3720Sstevel@tonic-gate 		}
3730Sstevel@tonic-gate 
3740Sstevel@tonic-gate 		/*
3750Sstevel@tonic-gate 		 * Setting of pages_pp_maximum is based first time
3760Sstevel@tonic-gate 		 * on the value of availrmem just after the start-up
3770Sstevel@tonic-gate 		 * allocations. To preserve this relationship at run
3780Sstevel@tonic-gate 		 * time, use a delta from availrmem_initial.
3790Sstevel@tonic-gate 		 */
3800Sstevel@tonic-gate 		ASSERT(availrmem_initial >= availrmem);
3810Sstevel@tonic-gate 		avrmem_delta = availrmem_initial - availrmem;
3820Sstevel@tonic-gate 
3830Sstevel@tonic-gate 		/* The allowable floor of pages_pp_maximum */
3840Sstevel@tonic-gate 		p_min = tune.t_minarmem + 100;
3850Sstevel@tonic-gate 
3860Sstevel@tonic-gate 		/* Make sure we don't come through here again. */
3870Sstevel@tonic-gate 		init_done = 1;
3880Sstevel@tonic-gate 	}
3890Sstevel@tonic-gate 	/*
3900Sstevel@tonic-gate 	 * Determine pages_pp_maximum, the number of currently available
3910Sstevel@tonic-gate 	 * pages (availrmem) that can't be `locked'. If not set by
3920Sstevel@tonic-gate 	 * the user, we set it to 4% of the currently available memory
3930Sstevel@tonic-gate 	 * plus 4MB.
3940Sstevel@tonic-gate 	 * But we also insist that it be greater than tune.t_minarmem;
3950Sstevel@tonic-gate 	 * otherwise a process could lock down a lot of memory, get swapped
3960Sstevel@tonic-gate 	 * out, and never have enough to get swapped back in.
3970Sstevel@tonic-gate 	 */
3980Sstevel@tonic-gate 	if (user_set)
3990Sstevel@tonic-gate 		pages_pp_maximum = pages_pp_maximum_startup;
4000Sstevel@tonic-gate 	else
4010Sstevel@tonic-gate 		pages_pp_maximum = ((availrmem_initial - avrmem_delta) / 25)
4020Sstevel@tonic-gate 		    + btop(4 * 1024 * 1024);
4030Sstevel@tonic-gate 
4040Sstevel@tonic-gate 	if (pages_pp_maximum <= p_min) {
4050Sstevel@tonic-gate 		pages_pp_maximum = p_min;
4060Sstevel@tonic-gate 	}
4070Sstevel@tonic-gate }
4080Sstevel@tonic-gate 
4090Sstevel@tonic-gate void
4100Sstevel@tonic-gate set_max_page_get(pgcnt_t target_total_pages)
4110Sstevel@tonic-gate {
4120Sstevel@tonic-gate 	max_page_get = target_total_pages / 2;
4130Sstevel@tonic-gate }
4140Sstevel@tonic-gate 
4150Sstevel@tonic-gate static pgcnt_t pending_delete;
4160Sstevel@tonic-gate 
4170Sstevel@tonic-gate /*ARGSUSED*/
4180Sstevel@tonic-gate static void
4190Sstevel@tonic-gate page_mem_config_post_add(
4200Sstevel@tonic-gate 	void *arg,
4210Sstevel@tonic-gate 	pgcnt_t delta_pages)
4220Sstevel@tonic-gate {
4230Sstevel@tonic-gate 	set_max_page_get(total_pages - pending_delete);
4240Sstevel@tonic-gate 	init_pages_pp_maximum();
4250Sstevel@tonic-gate }
4260Sstevel@tonic-gate 
4270Sstevel@tonic-gate /*ARGSUSED*/
4280Sstevel@tonic-gate static int
4290Sstevel@tonic-gate page_mem_config_pre_del(
4300Sstevel@tonic-gate 	void *arg,
4310Sstevel@tonic-gate 	pgcnt_t delta_pages)
4320Sstevel@tonic-gate {
4330Sstevel@tonic-gate 	pgcnt_t nv;
4340Sstevel@tonic-gate 
4350Sstevel@tonic-gate 	nv = atomic_add_long_nv(&pending_delete, (spgcnt_t)delta_pages);
4360Sstevel@tonic-gate 	set_max_page_get(total_pages - nv);
4370Sstevel@tonic-gate 	return (0);
4380Sstevel@tonic-gate }
4390Sstevel@tonic-gate 
4400Sstevel@tonic-gate /*ARGSUSED*/
4410Sstevel@tonic-gate static void
4420Sstevel@tonic-gate page_mem_config_post_del(
4430Sstevel@tonic-gate 	void *arg,
4440Sstevel@tonic-gate 	pgcnt_t delta_pages,
4450Sstevel@tonic-gate 	int cancelled)
4460Sstevel@tonic-gate {
4470Sstevel@tonic-gate 	pgcnt_t nv;
4480Sstevel@tonic-gate 
4490Sstevel@tonic-gate 	nv = atomic_add_long_nv(&pending_delete, -(spgcnt_t)delta_pages);
4500Sstevel@tonic-gate 	set_max_page_get(total_pages - nv);
4510Sstevel@tonic-gate 	if (!cancelled)
4520Sstevel@tonic-gate 		init_pages_pp_maximum();
4530Sstevel@tonic-gate }
4540Sstevel@tonic-gate 
4550Sstevel@tonic-gate static kphysm_setup_vector_t page_mem_config_vec = {
4560Sstevel@tonic-gate 	KPHYSM_SETUP_VECTOR_VERSION,
4570Sstevel@tonic-gate 	page_mem_config_post_add,
4580Sstevel@tonic-gate 	page_mem_config_pre_del,
4590Sstevel@tonic-gate 	page_mem_config_post_del,
4600Sstevel@tonic-gate };
4610Sstevel@tonic-gate 
4620Sstevel@tonic-gate static void
4630Sstevel@tonic-gate page_init_mem_config(void)
4640Sstevel@tonic-gate {
4650Sstevel@tonic-gate 	int ret;
4660Sstevel@tonic-gate 
4670Sstevel@tonic-gate 	ret = kphysm_setup_func_register(&page_mem_config_vec, (void *)NULL);
4680Sstevel@tonic-gate 	ASSERT(ret == 0);
4690Sstevel@tonic-gate }
4700Sstevel@tonic-gate 
4710Sstevel@tonic-gate /*
4720Sstevel@tonic-gate  * Evenly spread out the PCF counters for large free pages
4730Sstevel@tonic-gate  */
4740Sstevel@tonic-gate static void
4750Sstevel@tonic-gate page_free_large_ctr(pgcnt_t npages)
4760Sstevel@tonic-gate {
4770Sstevel@tonic-gate 	static struct pcf	*p = pcf;
4780Sstevel@tonic-gate 	pgcnt_t			lump;
4790Sstevel@tonic-gate 
4800Sstevel@tonic-gate 	freemem += npages;
4810Sstevel@tonic-gate 
4820Sstevel@tonic-gate 	lump = roundup(npages, PCF_FANOUT) / PCF_FANOUT;
4830Sstevel@tonic-gate 
4840Sstevel@tonic-gate 	while (npages > 0) {
4850Sstevel@tonic-gate 
4860Sstevel@tonic-gate 		ASSERT(!p->pcf_block);
4870Sstevel@tonic-gate 
4880Sstevel@tonic-gate 		if (lump < npages) {
4890Sstevel@tonic-gate 			p->pcf_count += (uint_t)lump;
4900Sstevel@tonic-gate 			npages -= lump;
4910Sstevel@tonic-gate 		} else {
4920Sstevel@tonic-gate 			p->pcf_count += (uint_t)npages;
4930Sstevel@tonic-gate 			npages = 0;
4940Sstevel@tonic-gate 		}
4950Sstevel@tonic-gate 
4960Sstevel@tonic-gate 		ASSERT(!p->pcf_wait);
4970Sstevel@tonic-gate 
4980Sstevel@tonic-gate 		if (++p > &pcf[PCF_FANOUT - 1])
4990Sstevel@tonic-gate 			p = pcf;
5000Sstevel@tonic-gate 	}
5010Sstevel@tonic-gate 
5020Sstevel@tonic-gate 	ASSERT(npages == 0);
5030Sstevel@tonic-gate }
5040Sstevel@tonic-gate 
5050Sstevel@tonic-gate /*
506*5331Samw  * Add a physical chunk of memory to the system free lists during startup.
5070Sstevel@tonic-gate  * Platform specific startup() allocates the memory for the page structs.
5080Sstevel@tonic-gate  *
5090Sstevel@tonic-gate  * num	- number of page structures
5100Sstevel@tonic-gate  * base - page number (pfn) to be associated with the first page.
5110Sstevel@tonic-gate  *
5120Sstevel@tonic-gate  * Since we are doing this during startup (ie. single threaded), we will
5130Sstevel@tonic-gate  * use shortcut routines to avoid any locking overhead while putting all
5140Sstevel@tonic-gate  * these pages on the freelists.
5150Sstevel@tonic-gate  *
5160Sstevel@tonic-gate  * NOTE: Any changes performed to page_free(), must also be performed to
5170Sstevel@tonic-gate  *	 add_physmem() since this is how we initialize all page_t's at
5180Sstevel@tonic-gate  *	 boot time.
5190Sstevel@tonic-gate  */
5200Sstevel@tonic-gate void
5210Sstevel@tonic-gate add_physmem(
5220Sstevel@tonic-gate 	page_t	*pp,
5230Sstevel@tonic-gate 	pgcnt_t	num,
5240Sstevel@tonic-gate 	pfn_t	pnum)
5250Sstevel@tonic-gate {
5260Sstevel@tonic-gate 	page_t	*root = NULL;
5270Sstevel@tonic-gate 	uint_t	szc = page_num_pagesizes() - 1;
5280Sstevel@tonic-gate 	pgcnt_t	large = page_get_pagecnt(szc);
5290Sstevel@tonic-gate 	pgcnt_t	cnt = 0;
5300Sstevel@tonic-gate 
5310Sstevel@tonic-gate 	TRACE_2(TR_FAC_VM, TR_PAGE_INIT,
5323559Smec 	    "add_physmem:pp %p num %lu", pp, num);
5330Sstevel@tonic-gate 
5340Sstevel@tonic-gate 	/*
5350Sstevel@tonic-gate 	 * Arbitrarily limit the max page_get request
5360Sstevel@tonic-gate 	 * to 1/2 of the page structs we have.
5370Sstevel@tonic-gate 	 */
5380Sstevel@tonic-gate 	total_pages += num;
5390Sstevel@tonic-gate 	set_max_page_get(total_pages);
5400Sstevel@tonic-gate 
5411373Skchow 	PLCNT_MODIFY_MAX(pnum, (long)num);
5421373Skchow 
5430Sstevel@tonic-gate 	/*
5440Sstevel@tonic-gate 	 * The physical space for the pages array
5450Sstevel@tonic-gate 	 * representing ram pages has already been
5460Sstevel@tonic-gate 	 * allocated.  Here we initialize each lock
5470Sstevel@tonic-gate 	 * in the page structure, and put each on
5480Sstevel@tonic-gate 	 * the free list
5490Sstevel@tonic-gate 	 */
550414Skchow 	for (; num; pp++, pnum++, num--) {
5510Sstevel@tonic-gate 
5520Sstevel@tonic-gate 		/*
5530Sstevel@tonic-gate 		 * this needs to fill in the page number
5540Sstevel@tonic-gate 		 * and do any other arch specific initialization
5550Sstevel@tonic-gate 		 */
5560Sstevel@tonic-gate 		add_physmem_cb(pp, pnum);
5570Sstevel@tonic-gate 
5582414Saguzovsk 		pp->p_lckcnt = 0;
5592414Saguzovsk 		pp->p_cowcnt = 0;
5602414Saguzovsk 		pp->p_slckcnt = 0;
5612414Saguzovsk 
5620Sstevel@tonic-gate 		/*
5630Sstevel@tonic-gate 		 * Initialize the page lock as unlocked, since nobody
5640Sstevel@tonic-gate 		 * can see or access this page yet.
5650Sstevel@tonic-gate 		 */
5660Sstevel@tonic-gate 		pp->p_selock = 0;
5670Sstevel@tonic-gate 
5680Sstevel@tonic-gate 		/*
5690Sstevel@tonic-gate 		 * Initialize IO lock
5700Sstevel@tonic-gate 		 */
5710Sstevel@tonic-gate 		page_iolock_init(pp);
5720Sstevel@tonic-gate 
5730Sstevel@tonic-gate 		/*
5740Sstevel@tonic-gate 		 * initialize other fields in the page_t
5750Sstevel@tonic-gate 		 */
5760Sstevel@tonic-gate 		PP_SETFREE(pp);
5770Sstevel@tonic-gate 		page_clr_all_props(pp);
5780Sstevel@tonic-gate 		PP_SETAGED(pp);
5790Sstevel@tonic-gate 		pp->p_offset = (u_offset_t)-1;
5800Sstevel@tonic-gate 		pp->p_next = pp;
5810Sstevel@tonic-gate 		pp->p_prev = pp;
5820Sstevel@tonic-gate 
5830Sstevel@tonic-gate 		/*
5840Sstevel@tonic-gate 		 * Simple case: System doesn't support large pages.
5850Sstevel@tonic-gate 		 */
5860Sstevel@tonic-gate 		if (szc == 0) {
5870Sstevel@tonic-gate 			pp->p_szc = 0;
5880Sstevel@tonic-gate 			page_free_at_startup(pp);
5890Sstevel@tonic-gate 			continue;
5900Sstevel@tonic-gate 		}
5910Sstevel@tonic-gate 
5920Sstevel@tonic-gate 		/*
5930Sstevel@tonic-gate 		 * Handle unaligned pages, we collect them up onto
5940Sstevel@tonic-gate 		 * the root page until we have a full large page.
5950Sstevel@tonic-gate 		 */
5960Sstevel@tonic-gate 		if (!IS_P2ALIGNED(pnum, large)) {
5970Sstevel@tonic-gate 
5980Sstevel@tonic-gate 			/*
5990Sstevel@tonic-gate 			 * If not in a large page,
6000Sstevel@tonic-gate 			 * just free as small page.
6010Sstevel@tonic-gate 			 */
6020Sstevel@tonic-gate 			if (root == NULL) {
6030Sstevel@tonic-gate 				pp->p_szc = 0;
6040Sstevel@tonic-gate 				page_free_at_startup(pp);
6050Sstevel@tonic-gate 				continue;
6060Sstevel@tonic-gate 			}
6070Sstevel@tonic-gate 
6080Sstevel@tonic-gate 			/*
6090Sstevel@tonic-gate 			 * Link a constituent page into the large page.
6100Sstevel@tonic-gate 			 */
6110Sstevel@tonic-gate 			pp->p_szc = szc;
6120Sstevel@tonic-gate 			page_list_concat(&root, &pp);
6130Sstevel@tonic-gate 
6140Sstevel@tonic-gate 			/*
6150Sstevel@tonic-gate 			 * When large page is fully formed, free it.
6160Sstevel@tonic-gate 			 */
6170Sstevel@tonic-gate 			if (++cnt == large) {
6180Sstevel@tonic-gate 				page_free_large_ctr(cnt);
6190Sstevel@tonic-gate 				page_list_add_pages(root, PG_LIST_ISINIT);
6200Sstevel@tonic-gate 				root = NULL;
6210Sstevel@tonic-gate 				cnt = 0;
6220Sstevel@tonic-gate 			}
6230Sstevel@tonic-gate 			continue;
6240Sstevel@tonic-gate 		}
6250Sstevel@tonic-gate 
6260Sstevel@tonic-gate 		/*
6270Sstevel@tonic-gate 		 * At this point we have a page number which
6280Sstevel@tonic-gate 		 * is aligned. We assert that we aren't already
6290Sstevel@tonic-gate 		 * in a different large page.
6300Sstevel@tonic-gate 		 */
6310Sstevel@tonic-gate 		ASSERT(IS_P2ALIGNED(pnum, large));
6320Sstevel@tonic-gate 		ASSERT(root == NULL && cnt == 0);
6330Sstevel@tonic-gate 
6340Sstevel@tonic-gate 		/*
6350Sstevel@tonic-gate 		 * If insufficient number of pages left to form
6360Sstevel@tonic-gate 		 * a large page, just free the small page.
6370Sstevel@tonic-gate 		 */
6380Sstevel@tonic-gate 		if (num < large) {
6390Sstevel@tonic-gate 			pp->p_szc = 0;
6400Sstevel@tonic-gate 			page_free_at_startup(pp);
6410Sstevel@tonic-gate 			continue;
6420Sstevel@tonic-gate 		}
6430Sstevel@tonic-gate 
6440Sstevel@tonic-gate 		/*
6450Sstevel@tonic-gate 		 * Otherwise start a new large page.
6460Sstevel@tonic-gate 		 */
6470Sstevel@tonic-gate 		pp->p_szc = szc;
6480Sstevel@tonic-gate 		cnt++;
6490Sstevel@tonic-gate 		root = pp;
6500Sstevel@tonic-gate 	}
6510Sstevel@tonic-gate 	ASSERT(root == NULL && cnt == 0);
6520Sstevel@tonic-gate }
6530Sstevel@tonic-gate 
6540Sstevel@tonic-gate /*
6550Sstevel@tonic-gate  * Find a page representing the specified [vp, offset].
6560Sstevel@tonic-gate  * If we find the page but it is intransit coming in,
6570Sstevel@tonic-gate  * it will have an "exclusive" lock and we wait for
6580Sstevel@tonic-gate  * the i/o to complete.  A page found on the free list
6590Sstevel@tonic-gate  * is always reclaimed and then locked.  On success, the page
6600Sstevel@tonic-gate  * is locked, its data is valid and it isn't on the free
6610Sstevel@tonic-gate  * list, while a NULL is returned if the page doesn't exist.
6620Sstevel@tonic-gate  */
6630Sstevel@tonic-gate page_t *
6640Sstevel@tonic-gate page_lookup(vnode_t *vp, u_offset_t off, se_t se)
6650Sstevel@tonic-gate {
6660Sstevel@tonic-gate 	return (page_lookup_create(vp, off, se, NULL, NULL, 0));
6670Sstevel@tonic-gate }
6680Sstevel@tonic-gate 
6690Sstevel@tonic-gate /*
6700Sstevel@tonic-gate  * Find a page representing the specified [vp, offset].
6710Sstevel@tonic-gate  * We either return the one we found or, if passed in,
6720Sstevel@tonic-gate  * create one with identity of [vp, offset] of the
673*5331Samw  * pre-allocated page. If we find existing page but it is
6740Sstevel@tonic-gate  * intransit coming in, it will have an "exclusive" lock
6750Sstevel@tonic-gate  * and we wait for the i/o to complete.  A page found on
6760Sstevel@tonic-gate  * the free list is always reclaimed and then locked.
6770Sstevel@tonic-gate  * On success, the page is locked, its data is valid and
6780Sstevel@tonic-gate  * it isn't on the free list, while a NULL is returned
6790Sstevel@tonic-gate  * if the page doesn't exist and newpp is NULL;
6800Sstevel@tonic-gate  */
6810Sstevel@tonic-gate page_t *
6820Sstevel@tonic-gate page_lookup_create(
6830Sstevel@tonic-gate 	vnode_t *vp,
6840Sstevel@tonic-gate 	u_offset_t off,
6850Sstevel@tonic-gate 	se_t se,
6860Sstevel@tonic-gate 	page_t *newpp,
6870Sstevel@tonic-gate 	spgcnt_t *nrelocp,
6880Sstevel@tonic-gate 	int flags)
6890Sstevel@tonic-gate {
6900Sstevel@tonic-gate 	page_t		*pp;
6910Sstevel@tonic-gate 	kmutex_t	*phm;
6920Sstevel@tonic-gate 	ulong_t		index;
6930Sstevel@tonic-gate 	uint_t		hash_locked;
6940Sstevel@tonic-gate 	uint_t		es;
6950Sstevel@tonic-gate 
6960Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
6970Sstevel@tonic-gate 	VM_STAT_ADD(page_lookup_cnt[0]);
6980Sstevel@tonic-gate 	ASSERT(newpp ? PAGE_EXCL(newpp) : 1);
6990Sstevel@tonic-gate 
7000Sstevel@tonic-gate 	/*
7010Sstevel@tonic-gate 	 * Acquire the appropriate page hash lock since
7020Sstevel@tonic-gate 	 * we have to search the hash list.  Pages that
7030Sstevel@tonic-gate 	 * hash to this list can't change identity while
7040Sstevel@tonic-gate 	 * this lock is held.
7050Sstevel@tonic-gate 	 */
7060Sstevel@tonic-gate 	hash_locked = 0;
7070Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
7080Sstevel@tonic-gate 	phm = NULL;
7090Sstevel@tonic-gate top:
7100Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
7110Sstevel@tonic-gate 	if (pp != NULL) {
7120Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_cnt[1]);
7130Sstevel@tonic-gate 		es = (newpp != NULL) ? 1 : 0;
7140Sstevel@tonic-gate 		es |= flags;
7150Sstevel@tonic-gate 		if (!hash_locked) {
7160Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_cnt[2]);
7170Sstevel@tonic-gate 			if (!page_try_reclaim_lock(pp, se, es)) {
7180Sstevel@tonic-gate 				/*
7190Sstevel@tonic-gate 				 * On a miss, acquire the phm.  Then
7200Sstevel@tonic-gate 				 * next time, page_lock() will be called,
7210Sstevel@tonic-gate 				 * causing a wait if the page is busy.
7220Sstevel@tonic-gate 				 * just looping with page_trylock() would
7230Sstevel@tonic-gate 				 * get pretty boring.
7240Sstevel@tonic-gate 				 */
7250Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_cnt[3]);
7260Sstevel@tonic-gate 				phm = PAGE_HASH_MUTEX(index);
7270Sstevel@tonic-gate 				mutex_enter(phm);
7280Sstevel@tonic-gate 				hash_locked = 1;
7290Sstevel@tonic-gate 				goto top;
7300Sstevel@tonic-gate 			}
7310Sstevel@tonic-gate 		} else {
7320Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_cnt[4]);
7330Sstevel@tonic-gate 			if (!page_lock_es(pp, se, phm, P_RECLAIM, es)) {
7340Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_cnt[5]);
7350Sstevel@tonic-gate 				goto top;
7360Sstevel@tonic-gate 			}
7370Sstevel@tonic-gate 		}
7380Sstevel@tonic-gate 
7390Sstevel@tonic-gate 		/*
7400Sstevel@tonic-gate 		 * Since `pp' is locked it can not change identity now.
7410Sstevel@tonic-gate 		 * Reconfirm we locked the correct page.
7420Sstevel@tonic-gate 		 *
7430Sstevel@tonic-gate 		 * Both the p_vnode and p_offset *must* be cast volatile
7440Sstevel@tonic-gate 		 * to force a reload of their values: The PAGE_HASH_SEARCH
7450Sstevel@tonic-gate 		 * macro will have stuffed p_vnode and p_offset into
7460Sstevel@tonic-gate 		 * registers before calling page_trylock(); another thread,
7470Sstevel@tonic-gate 		 * actually holding the hash lock, could have changed the
7480Sstevel@tonic-gate 		 * page's identity in memory, but our registers would not
7490Sstevel@tonic-gate 		 * be changed, fooling the reconfirmation.  If the hash
7500Sstevel@tonic-gate 		 * lock was held during the search, the casting would
7510Sstevel@tonic-gate 		 * not be needed.
7520Sstevel@tonic-gate 		 */
7530Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_cnt[6]);
7540Sstevel@tonic-gate 		if (((volatile struct vnode *)(pp->p_vnode) != vp) ||
7550Sstevel@tonic-gate 		    ((volatile u_offset_t)(pp->p_offset) != off)) {
7560Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_cnt[7]);
7570Sstevel@tonic-gate 			if (hash_locked) {
7580Sstevel@tonic-gate 				panic("page_lookup_create: lost page %p",
7590Sstevel@tonic-gate 				    (void *)pp);
7600Sstevel@tonic-gate 				/*NOTREACHED*/
7610Sstevel@tonic-gate 			}
7620Sstevel@tonic-gate 			page_unlock(pp);
7630Sstevel@tonic-gate 			phm = PAGE_HASH_MUTEX(index);
7640Sstevel@tonic-gate 			mutex_enter(phm);
7650Sstevel@tonic-gate 			hash_locked = 1;
7660Sstevel@tonic-gate 			goto top;
7670Sstevel@tonic-gate 		}
7680Sstevel@tonic-gate 
7690Sstevel@tonic-gate 		/*
7700Sstevel@tonic-gate 		 * If page_trylock() was called, then pp may still be on
7710Sstevel@tonic-gate 		 * the cachelist (can't be on the free list, it would not
7720Sstevel@tonic-gate 		 * have been found in the search).  If it is on the
7730Sstevel@tonic-gate 		 * cachelist it must be pulled now. To pull the page from
7740Sstevel@tonic-gate 		 * the cachelist, it must be exclusively locked.
7750Sstevel@tonic-gate 		 *
7760Sstevel@tonic-gate 		 * The other big difference between page_trylock() and
7770Sstevel@tonic-gate 		 * page_lock(), is that page_lock() will pull the
7780Sstevel@tonic-gate 		 * page from whatever free list (the cache list in this
7790Sstevel@tonic-gate 		 * case) the page is on.  If page_trylock() was used
7800Sstevel@tonic-gate 		 * above, then we have to do the reclaim ourselves.
7810Sstevel@tonic-gate 		 */
7820Sstevel@tonic-gate 		if ((!hash_locked) && (PP_ISFREE(pp))) {
7830Sstevel@tonic-gate 			ASSERT(PP_ISAGED(pp) == 0);
7840Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_cnt[8]);
7850Sstevel@tonic-gate 
7860Sstevel@tonic-gate 			/*
7870Sstevel@tonic-gate 			 * page_relcaim will insure that we
7880Sstevel@tonic-gate 			 * have this page exclusively
7890Sstevel@tonic-gate 			 */
7900Sstevel@tonic-gate 
7910Sstevel@tonic-gate 			if (!page_reclaim(pp, NULL)) {
7920Sstevel@tonic-gate 				/*
7930Sstevel@tonic-gate 				 * Page_reclaim dropped whatever lock
7940Sstevel@tonic-gate 				 * we held.
7950Sstevel@tonic-gate 				 */
7960Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_cnt[9]);
7970Sstevel@tonic-gate 				phm = PAGE_HASH_MUTEX(index);
7980Sstevel@tonic-gate 				mutex_enter(phm);
7990Sstevel@tonic-gate 				hash_locked = 1;
8000Sstevel@tonic-gate 				goto top;
8010Sstevel@tonic-gate 			} else if (se == SE_SHARED && newpp == NULL) {
8020Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_cnt[10]);
8030Sstevel@tonic-gate 				page_downgrade(pp);
8040Sstevel@tonic-gate 			}
8050Sstevel@tonic-gate 		}
8060Sstevel@tonic-gate 
8070Sstevel@tonic-gate 		if (hash_locked) {
8080Sstevel@tonic-gate 			mutex_exit(phm);
8090Sstevel@tonic-gate 		}
8100Sstevel@tonic-gate 
8110Sstevel@tonic-gate 		if (newpp != NULL && pp->p_szc < newpp->p_szc &&
8120Sstevel@tonic-gate 		    PAGE_EXCL(pp) && nrelocp != NULL) {
8130Sstevel@tonic-gate 			ASSERT(nrelocp != NULL);
8140Sstevel@tonic-gate 			(void) page_relocate(&pp, &newpp, 1, 1, nrelocp,
8150Sstevel@tonic-gate 			    NULL);
8160Sstevel@tonic-gate 			if (*nrelocp > 0) {
8170Sstevel@tonic-gate 				VM_STAT_COND_ADD(*nrelocp == 1,
8180Sstevel@tonic-gate 				    page_lookup_cnt[11]);
8190Sstevel@tonic-gate 				VM_STAT_COND_ADD(*nrelocp > 1,
8200Sstevel@tonic-gate 				    page_lookup_cnt[12]);
8210Sstevel@tonic-gate 				pp = newpp;
8220Sstevel@tonic-gate 				se = SE_EXCL;
8230Sstevel@tonic-gate 			} else {
8240Sstevel@tonic-gate 				if (se == SE_SHARED) {
8250Sstevel@tonic-gate 					page_downgrade(pp);
8260Sstevel@tonic-gate 				}
8270Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_cnt[13]);
8280Sstevel@tonic-gate 			}
8290Sstevel@tonic-gate 		} else if (newpp != NULL && nrelocp != NULL) {
8300Sstevel@tonic-gate 			if (PAGE_EXCL(pp) && se == SE_SHARED) {
8310Sstevel@tonic-gate 				page_downgrade(pp);
8320Sstevel@tonic-gate 			}
8330Sstevel@tonic-gate 			VM_STAT_COND_ADD(pp->p_szc < newpp->p_szc,
8340Sstevel@tonic-gate 			    page_lookup_cnt[14]);
8350Sstevel@tonic-gate 			VM_STAT_COND_ADD(pp->p_szc == newpp->p_szc,
8360Sstevel@tonic-gate 			    page_lookup_cnt[15]);
8370Sstevel@tonic-gate 			VM_STAT_COND_ADD(pp->p_szc > newpp->p_szc,
8380Sstevel@tonic-gate 			    page_lookup_cnt[16]);
8390Sstevel@tonic-gate 		} else if (newpp != NULL && PAGE_EXCL(pp)) {
8400Sstevel@tonic-gate 			se = SE_EXCL;
8410Sstevel@tonic-gate 		}
8420Sstevel@tonic-gate 	} else if (!hash_locked) {
8430Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_cnt[17]);
8440Sstevel@tonic-gate 		phm = PAGE_HASH_MUTEX(index);
8450Sstevel@tonic-gate 		mutex_enter(phm);
8460Sstevel@tonic-gate 		hash_locked = 1;
8470Sstevel@tonic-gate 		goto top;
8480Sstevel@tonic-gate 	} else if (newpp != NULL) {
8490Sstevel@tonic-gate 		/*
8500Sstevel@tonic-gate 		 * If we have a preallocated page then
8510Sstevel@tonic-gate 		 * insert it now and basically behave like
8520Sstevel@tonic-gate 		 * page_create.
8530Sstevel@tonic-gate 		 */
8540Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_cnt[18]);
8550Sstevel@tonic-gate 		/*
8560Sstevel@tonic-gate 		 * Since we hold the page hash mutex and
8570Sstevel@tonic-gate 		 * just searched for this page, page_hashin
8580Sstevel@tonic-gate 		 * had better not fail.  If it does, that
8590Sstevel@tonic-gate 		 * means some thread did not follow the
8600Sstevel@tonic-gate 		 * page hash mutex rules.  Panic now and
8610Sstevel@tonic-gate 		 * get it over with.  As usual, go down
8620Sstevel@tonic-gate 		 * holding all the locks.
8630Sstevel@tonic-gate 		 */
8640Sstevel@tonic-gate 		ASSERT(MUTEX_HELD(phm));
8650Sstevel@tonic-gate 		if (!page_hashin(newpp, vp, off, phm)) {
8660Sstevel@tonic-gate 			ASSERT(MUTEX_HELD(phm));
8670Sstevel@tonic-gate 			panic("page_lookup_create: hashin failed %p %p %llx %p",
8680Sstevel@tonic-gate 			    (void *)newpp, (void *)vp, off, (void *)phm);
8690Sstevel@tonic-gate 			/*NOTREACHED*/
8700Sstevel@tonic-gate 		}
8710Sstevel@tonic-gate 		ASSERT(MUTEX_HELD(phm));
8720Sstevel@tonic-gate 		mutex_exit(phm);
8730Sstevel@tonic-gate 		phm = NULL;
8740Sstevel@tonic-gate 		page_set_props(newpp, P_REF);
8750Sstevel@tonic-gate 		page_io_lock(newpp);
8760Sstevel@tonic-gate 		pp = newpp;
8770Sstevel@tonic-gate 		se = SE_EXCL;
8780Sstevel@tonic-gate 	} else {
8790Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_cnt[19]);
8800Sstevel@tonic-gate 		mutex_exit(phm);
8810Sstevel@tonic-gate 	}
8820Sstevel@tonic-gate 
8830Sstevel@tonic-gate 	ASSERT(pp ? PAGE_LOCKED_SE(pp, se) : 1);
8840Sstevel@tonic-gate 
8850Sstevel@tonic-gate 	ASSERT(pp ? ((PP_ISFREE(pp) == 0) && (PP_ISAGED(pp) == 0)) : 1);
8860Sstevel@tonic-gate 
8870Sstevel@tonic-gate 	return (pp);
8880Sstevel@tonic-gate }
8890Sstevel@tonic-gate 
8900Sstevel@tonic-gate /*
8910Sstevel@tonic-gate  * Search the hash list for the page representing the
8920Sstevel@tonic-gate  * specified [vp, offset] and return it locked.  Skip
8930Sstevel@tonic-gate  * free pages and pages that cannot be locked as requested.
8940Sstevel@tonic-gate  * Used while attempting to kluster pages.
8950Sstevel@tonic-gate  */
8960Sstevel@tonic-gate page_t *
8970Sstevel@tonic-gate page_lookup_nowait(vnode_t *vp, u_offset_t off, se_t se)
8980Sstevel@tonic-gate {
8990Sstevel@tonic-gate 	page_t		*pp;
9000Sstevel@tonic-gate 	kmutex_t	*phm;
9010Sstevel@tonic-gate 	ulong_t		index;
9020Sstevel@tonic-gate 	uint_t		locked;
9030Sstevel@tonic-gate 
9040Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
9050Sstevel@tonic-gate 	VM_STAT_ADD(page_lookup_nowait_cnt[0]);
9060Sstevel@tonic-gate 
9070Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
9080Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
9090Sstevel@tonic-gate 	locked = 0;
9100Sstevel@tonic-gate 	if (pp == NULL) {
9110Sstevel@tonic-gate top:
9120Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_nowait_cnt[1]);
9130Sstevel@tonic-gate 		locked = 1;
9140Sstevel@tonic-gate 		phm = PAGE_HASH_MUTEX(index);
9150Sstevel@tonic-gate 		mutex_enter(phm);
9160Sstevel@tonic-gate 		PAGE_HASH_SEARCH(index, pp, vp, off);
9170Sstevel@tonic-gate 	}
9180Sstevel@tonic-gate 
9190Sstevel@tonic-gate 	if (pp == NULL || PP_ISFREE(pp)) {
9200Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_nowait_cnt[2]);
9210Sstevel@tonic-gate 		pp = NULL;
9220Sstevel@tonic-gate 	} else {
9230Sstevel@tonic-gate 		if (!page_trylock(pp, se)) {
9240Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_nowait_cnt[3]);
9250Sstevel@tonic-gate 			pp = NULL;
9260Sstevel@tonic-gate 		} else {
9270Sstevel@tonic-gate 			VM_STAT_ADD(page_lookup_nowait_cnt[4]);
9280Sstevel@tonic-gate 			/*
9290Sstevel@tonic-gate 			 * See the comment in page_lookup()
9300Sstevel@tonic-gate 			 */
9310Sstevel@tonic-gate 			if (((volatile struct vnode *)(pp->p_vnode) != vp) ||
9320Sstevel@tonic-gate 			    ((u_offset_t)(pp->p_offset) != off)) {
9330Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_nowait_cnt[5]);
9340Sstevel@tonic-gate 				if (locked) {
9350Sstevel@tonic-gate 					panic("page_lookup_nowait %p",
9360Sstevel@tonic-gate 					    (void *)pp);
9370Sstevel@tonic-gate 					/*NOTREACHED*/
9380Sstevel@tonic-gate 				}
9390Sstevel@tonic-gate 				page_unlock(pp);
9400Sstevel@tonic-gate 				goto top;
9410Sstevel@tonic-gate 			}
9420Sstevel@tonic-gate 			if (PP_ISFREE(pp)) {
9430Sstevel@tonic-gate 				VM_STAT_ADD(page_lookup_nowait_cnt[6]);
9440Sstevel@tonic-gate 				page_unlock(pp);
9450Sstevel@tonic-gate 				pp = NULL;
9460Sstevel@tonic-gate 			}
9470Sstevel@tonic-gate 		}
9480Sstevel@tonic-gate 	}
9490Sstevel@tonic-gate 	if (locked) {
9500Sstevel@tonic-gate 		VM_STAT_ADD(page_lookup_nowait_cnt[7]);
9510Sstevel@tonic-gate 		mutex_exit(phm);
9520Sstevel@tonic-gate 	}
9530Sstevel@tonic-gate 
9540Sstevel@tonic-gate 	ASSERT(pp ? PAGE_LOCKED_SE(pp, se) : 1);
9550Sstevel@tonic-gate 
9560Sstevel@tonic-gate 	return (pp);
9570Sstevel@tonic-gate }
9580Sstevel@tonic-gate 
9590Sstevel@tonic-gate /*
9600Sstevel@tonic-gate  * Search the hash list for a page with the specified [vp, off]
9610Sstevel@tonic-gate  * that is known to exist and is already locked.  This routine
9620Sstevel@tonic-gate  * is typically used by segment SOFTUNLOCK routines.
9630Sstevel@tonic-gate  */
9640Sstevel@tonic-gate page_t *
9650Sstevel@tonic-gate page_find(vnode_t *vp, u_offset_t off)
9660Sstevel@tonic-gate {
9670Sstevel@tonic-gate 	page_t		*pp;
9680Sstevel@tonic-gate 	kmutex_t	*phm;
9690Sstevel@tonic-gate 	ulong_t		index;
9700Sstevel@tonic-gate 
9710Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
9720Sstevel@tonic-gate 	VM_STAT_ADD(page_find_cnt);
9730Sstevel@tonic-gate 
9740Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
9750Sstevel@tonic-gate 	phm = PAGE_HASH_MUTEX(index);
9760Sstevel@tonic-gate 
9770Sstevel@tonic-gate 	mutex_enter(phm);
9780Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
9790Sstevel@tonic-gate 	mutex_exit(phm);
9800Sstevel@tonic-gate 
9811338Selowe 	ASSERT(pp == NULL || PAGE_LOCKED(pp) || panicstr);
9820Sstevel@tonic-gate 	return (pp);
9830Sstevel@tonic-gate }
9840Sstevel@tonic-gate 
9850Sstevel@tonic-gate /*
9860Sstevel@tonic-gate  * Determine whether a page with the specified [vp, off]
9870Sstevel@tonic-gate  * currently exists in the system.  Obviously this should
9880Sstevel@tonic-gate  * only be considered as a hint since nothing prevents the
9890Sstevel@tonic-gate  * page from disappearing or appearing immediately after
9900Sstevel@tonic-gate  * the return from this routine. Subsequently, we don't
9910Sstevel@tonic-gate  * even bother to lock the list.
9920Sstevel@tonic-gate  */
9930Sstevel@tonic-gate page_t *
9940Sstevel@tonic-gate page_exists(vnode_t *vp, u_offset_t off)
9950Sstevel@tonic-gate {
9960Sstevel@tonic-gate 	page_t	*pp;
9970Sstevel@tonic-gate 	ulong_t		index;
9980Sstevel@tonic-gate 
9990Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
10000Sstevel@tonic-gate 	VM_STAT_ADD(page_exists_cnt);
10010Sstevel@tonic-gate 
10020Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
10030Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
10040Sstevel@tonic-gate 
10050Sstevel@tonic-gate 	return (pp);
10060Sstevel@tonic-gate }
10070Sstevel@tonic-gate 
10080Sstevel@tonic-gate /*
10090Sstevel@tonic-gate  * Determine if physically contiguous pages exist for [vp, off] - [vp, off +
10100Sstevel@tonic-gate  * page_size(szc)) range.  if they exist and ppa is not NULL fill ppa array
10110Sstevel@tonic-gate  * with these pages locked SHARED. If necessary reclaim pages from
10120Sstevel@tonic-gate  * freelist. Return 1 if contiguous pages exist and 0 otherwise.
10130Sstevel@tonic-gate  *
10140Sstevel@tonic-gate  * If we fail to lock pages still return 1 if pages exist and contiguous.
10150Sstevel@tonic-gate  * But in this case return value is just a hint. ppa array won't be filled.
10160Sstevel@tonic-gate  * Caller should initialize ppa[0] as NULL to distinguish return value.
10170Sstevel@tonic-gate  *
10180Sstevel@tonic-gate  * Returns 0 if pages don't exist or not physically contiguous.
10190Sstevel@tonic-gate  *
10200Sstevel@tonic-gate  * This routine doesn't work for anonymous(swapfs) pages.
10210Sstevel@tonic-gate  */
10220Sstevel@tonic-gate int
10230Sstevel@tonic-gate page_exists_physcontig(vnode_t *vp, u_offset_t off, uint_t szc, page_t *ppa[])
10240Sstevel@tonic-gate {
10250Sstevel@tonic-gate 	pgcnt_t pages;
10260Sstevel@tonic-gate 	pfn_t pfn;
10270Sstevel@tonic-gate 	page_t *rootpp;
10280Sstevel@tonic-gate 	pgcnt_t i;
10290Sstevel@tonic-gate 	pgcnt_t j;
10300Sstevel@tonic-gate 	u_offset_t save_off = off;
10310Sstevel@tonic-gate 	ulong_t index;
10320Sstevel@tonic-gate 	kmutex_t *phm;
10330Sstevel@tonic-gate 	page_t *pp;
10340Sstevel@tonic-gate 	uint_t pszc;
10350Sstevel@tonic-gate 	int loopcnt = 0;
10360Sstevel@tonic-gate 
10370Sstevel@tonic-gate 	ASSERT(szc != 0);
10380Sstevel@tonic-gate 	ASSERT(vp != NULL);
10390Sstevel@tonic-gate 	ASSERT(!IS_SWAPFSVP(vp));
10403290Sjohansen 	ASSERT(!VN_ISKAS(vp));
10410Sstevel@tonic-gate 
10420Sstevel@tonic-gate again:
10430Sstevel@tonic-gate 	if (++loopcnt > 3) {
10440Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[0]);
10450Sstevel@tonic-gate 		return (0);
10460Sstevel@tonic-gate 	}
10470Sstevel@tonic-gate 
10480Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
10490Sstevel@tonic-gate 	phm = PAGE_HASH_MUTEX(index);
10500Sstevel@tonic-gate 
10510Sstevel@tonic-gate 	mutex_enter(phm);
10520Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
10530Sstevel@tonic-gate 	mutex_exit(phm);
10540Sstevel@tonic-gate 
10550Sstevel@tonic-gate 	VM_STAT_ADD(page_exphcontg[1]);
10560Sstevel@tonic-gate 
10570Sstevel@tonic-gate 	if (pp == NULL) {
10580Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[2]);
10590Sstevel@tonic-gate 		return (0);
10600Sstevel@tonic-gate 	}
10610Sstevel@tonic-gate 
10620Sstevel@tonic-gate 	pages = page_get_pagecnt(szc);
10630Sstevel@tonic-gate 	rootpp = pp;
10640Sstevel@tonic-gate 	pfn = rootpp->p_pagenum;
10650Sstevel@tonic-gate 
10660Sstevel@tonic-gate 	if ((pszc = pp->p_szc) >= szc && ppa != NULL) {
10670Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[3]);
10680Sstevel@tonic-gate 		if (!page_trylock(pp, SE_SHARED)) {
10690Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[4]);
10700Sstevel@tonic-gate 			return (1);
10710Sstevel@tonic-gate 		}
10720Sstevel@tonic-gate 		if (pp->p_szc != pszc || pp->p_vnode != vp ||
10730Sstevel@tonic-gate 		    pp->p_offset != off) {
10740Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[5]);
10750Sstevel@tonic-gate 			page_unlock(pp);
10760Sstevel@tonic-gate 			off = save_off;
10770Sstevel@tonic-gate 			goto again;
10780Sstevel@tonic-gate 		}
10790Sstevel@tonic-gate 		/*
10800Sstevel@tonic-gate 		 * szc was non zero and vnode and offset matched after we
10810Sstevel@tonic-gate 		 * locked the page it means it can't become free on us.
10820Sstevel@tonic-gate 		 */
10830Sstevel@tonic-gate 		ASSERT(!PP_ISFREE(pp));
10840Sstevel@tonic-gate 		if (!IS_P2ALIGNED(pfn, pages)) {
10850Sstevel@tonic-gate 			page_unlock(pp);
10860Sstevel@tonic-gate 			return (0);
10870Sstevel@tonic-gate 		}
10880Sstevel@tonic-gate 		ppa[0] = pp;
10890Sstevel@tonic-gate 		pp++;
10900Sstevel@tonic-gate 		off += PAGESIZE;
10910Sstevel@tonic-gate 		pfn++;
10920Sstevel@tonic-gate 		for (i = 1; i < pages; i++, pp++, off += PAGESIZE, pfn++) {
10930Sstevel@tonic-gate 			if (!page_trylock(pp, SE_SHARED)) {
10940Sstevel@tonic-gate 				VM_STAT_ADD(page_exphcontg[6]);
10950Sstevel@tonic-gate 				pp--;
10960Sstevel@tonic-gate 				while (i-- > 0) {
10970Sstevel@tonic-gate 					page_unlock(pp);
10980Sstevel@tonic-gate 					pp--;
10990Sstevel@tonic-gate 				}
11000Sstevel@tonic-gate 				ppa[0] = NULL;
11010Sstevel@tonic-gate 				return (1);
11020Sstevel@tonic-gate 			}
11030Sstevel@tonic-gate 			if (pp->p_szc != pszc) {
11040Sstevel@tonic-gate 				VM_STAT_ADD(page_exphcontg[7]);
11050Sstevel@tonic-gate 				page_unlock(pp);
11060Sstevel@tonic-gate 				pp--;
11070Sstevel@tonic-gate 				while (i-- > 0) {
11080Sstevel@tonic-gate 					page_unlock(pp);
11090Sstevel@tonic-gate 					pp--;
11100Sstevel@tonic-gate 				}
11110Sstevel@tonic-gate 				ppa[0] = NULL;
11120Sstevel@tonic-gate 				off = save_off;
11130Sstevel@tonic-gate 				goto again;
11140Sstevel@tonic-gate 			}
11150Sstevel@tonic-gate 			/*
11160Sstevel@tonic-gate 			 * szc the same as for previous already locked pages
11170Sstevel@tonic-gate 			 * with right identity. Since this page had correct
11180Sstevel@tonic-gate 			 * szc after we locked it can't get freed or destroyed
11190Sstevel@tonic-gate 			 * and therefore must have the expected identity.
11200Sstevel@tonic-gate 			 */
11210Sstevel@tonic-gate 			ASSERT(!PP_ISFREE(pp));
11220Sstevel@tonic-gate 			if (pp->p_vnode != vp ||
11230Sstevel@tonic-gate 			    pp->p_offset != off) {
11240Sstevel@tonic-gate 				panic("page_exists_physcontig: "
11250Sstevel@tonic-gate 				    "large page identity doesn't match");
11260Sstevel@tonic-gate 			}
11270Sstevel@tonic-gate 			ppa[i] = pp;
11280Sstevel@tonic-gate 			ASSERT(pp->p_pagenum == pfn);
11290Sstevel@tonic-gate 		}
11300Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[8]);
11310Sstevel@tonic-gate 		ppa[pages] = NULL;
11320Sstevel@tonic-gate 		return (1);
11330Sstevel@tonic-gate 	} else if (pszc >= szc) {
11340Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[9]);
11350Sstevel@tonic-gate 		if (!IS_P2ALIGNED(pfn, pages)) {
11360Sstevel@tonic-gate 			return (0);
11370Sstevel@tonic-gate 		}
11380Sstevel@tonic-gate 		return (1);
11390Sstevel@tonic-gate 	}
11400Sstevel@tonic-gate 
11410Sstevel@tonic-gate 	if (!IS_P2ALIGNED(pfn, pages)) {
11420Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[10]);
11430Sstevel@tonic-gate 		return (0);
11440Sstevel@tonic-gate 	}
11450Sstevel@tonic-gate 
11460Sstevel@tonic-gate 	if (page_numtomemseg_nolock(pfn) !=
11470Sstevel@tonic-gate 	    page_numtomemseg_nolock(pfn + pages - 1)) {
11480Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[11]);
11490Sstevel@tonic-gate 		return (0);
11500Sstevel@tonic-gate 	}
11510Sstevel@tonic-gate 
11520Sstevel@tonic-gate 	/*
11530Sstevel@tonic-gate 	 * We loop up 4 times across pages to promote page size.
11540Sstevel@tonic-gate 	 * We're extra cautious to promote page size atomically with respect
11550Sstevel@tonic-gate 	 * to everybody else.  But we can probably optimize into 1 loop if
11560Sstevel@tonic-gate 	 * this becomes an issue.
11570Sstevel@tonic-gate 	 */
11580Sstevel@tonic-gate 
11590Sstevel@tonic-gate 	for (i = 0; i < pages; i++, pp++, off += PAGESIZE, pfn++) {
11600Sstevel@tonic-gate 		ASSERT(pp->p_pagenum == pfn);
11610Sstevel@tonic-gate 		if (!page_trylock(pp, SE_EXCL)) {
11620Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[12]);
11630Sstevel@tonic-gate 			break;
11640Sstevel@tonic-gate 		}
11650Sstevel@tonic-gate 		if (pp->p_vnode != vp ||
11660Sstevel@tonic-gate 		    pp->p_offset != off) {
11670Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[13]);
11680Sstevel@tonic-gate 			page_unlock(pp);
11690Sstevel@tonic-gate 			break;
11700Sstevel@tonic-gate 		}
11710Sstevel@tonic-gate 		if (pp->p_szc >= szc) {
11720Sstevel@tonic-gate 			ASSERT(i == 0);
11730Sstevel@tonic-gate 			page_unlock(pp);
11740Sstevel@tonic-gate 			off = save_off;
11750Sstevel@tonic-gate 			goto again;
11760Sstevel@tonic-gate 		}
11770Sstevel@tonic-gate 	}
11780Sstevel@tonic-gate 
11790Sstevel@tonic-gate 	if (i != pages) {
11800Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[14]);
11810Sstevel@tonic-gate 		--pp;
11820Sstevel@tonic-gate 		while (i-- > 0) {
11830Sstevel@tonic-gate 			page_unlock(pp);
11840Sstevel@tonic-gate 			--pp;
11850Sstevel@tonic-gate 		}
11860Sstevel@tonic-gate 		return (0);
11870Sstevel@tonic-gate 	}
11880Sstevel@tonic-gate 
11890Sstevel@tonic-gate 	pp = rootpp;
11900Sstevel@tonic-gate 	for (i = 0; i < pages; i++, pp++) {
11910Sstevel@tonic-gate 		if (PP_ISFREE(pp)) {
11920Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[15]);
11930Sstevel@tonic-gate 			ASSERT(!PP_ISAGED(pp));
11940Sstevel@tonic-gate 			ASSERT(pp->p_szc == 0);
11950Sstevel@tonic-gate 			if (!page_reclaim(pp, NULL)) {
11960Sstevel@tonic-gate 				break;
11970Sstevel@tonic-gate 			}
11980Sstevel@tonic-gate 		} else {
11990Sstevel@tonic-gate 			ASSERT(pp->p_szc < szc);
12000Sstevel@tonic-gate 			VM_STAT_ADD(page_exphcontg[16]);
12010Sstevel@tonic-gate 			(void) hat_pageunload(pp, HAT_FORCE_PGUNLOAD);
12020Sstevel@tonic-gate 		}
12030Sstevel@tonic-gate 	}
12040Sstevel@tonic-gate 	if (i < pages) {
12050Sstevel@tonic-gate 		VM_STAT_ADD(page_exphcontg[17]);
12060Sstevel@tonic-gate 		/*
12070Sstevel@tonic-gate 		 * page_reclaim failed because we were out of memory.
12080Sstevel@tonic-gate 		 * drop the rest of the locks and return because this page
12090Sstevel@tonic-gate 		 * must be already reallocated anyway.
12100Sstevel@tonic-gate 		 */
12110Sstevel@tonic-gate 		pp = rootpp;
12120Sstevel@tonic-gate 		for (j = 0; j < pages; j++, pp++) {
12130Sstevel@tonic-gate 			if (j != i) {
12140Sstevel@tonic-gate 				page_unlock(pp);
12150Sstevel@tonic-gate 			}
12160Sstevel@tonic-gate 		}
12170Sstevel@tonic-gate 		return (0);
12180Sstevel@tonic-gate 	}
12190Sstevel@tonic-gate 
12200Sstevel@tonic-gate 	off = save_off;
12210Sstevel@tonic-gate 	pp = rootpp;
12220Sstevel@tonic-gate 	for (i = 0; i < pages; i++, pp++, off += PAGESIZE) {
12230Sstevel@tonic-gate 		ASSERT(PAGE_EXCL(pp));
12240Sstevel@tonic-gate 		ASSERT(!PP_ISFREE(pp));
12250Sstevel@tonic-gate 		ASSERT(!hat_page_is_mapped(pp));
12260Sstevel@tonic-gate 		ASSERT(pp->p_vnode == vp);
12270Sstevel@tonic-gate 		ASSERT(pp->p_offset == off);
12280Sstevel@tonic-gate 		pp->p_szc = szc;
12290Sstevel@tonic-gate 	}
12300Sstevel@tonic-gate 	pp = rootpp;
12310Sstevel@tonic-gate 	for (i = 0; i < pages; i++, pp++) {
12320Sstevel@tonic-gate 		if (ppa == NULL) {
12330Sstevel@tonic-gate 			page_unlock(pp);
12340Sstevel@tonic-gate 		} else {
12350Sstevel@tonic-gate 			ppa[i] = pp;
12360Sstevel@tonic-gate 			page_downgrade(ppa[i]);
12370Sstevel@tonic-gate 		}
12380Sstevel@tonic-gate 	}
12390Sstevel@tonic-gate 	if (ppa != NULL) {
12400Sstevel@tonic-gate 		ppa[pages] = NULL;
12410Sstevel@tonic-gate 	}
12420Sstevel@tonic-gate 	VM_STAT_ADD(page_exphcontg[18]);
12430Sstevel@tonic-gate 	ASSERT(vp->v_pages != NULL);
12440Sstevel@tonic-gate 	return (1);
12450Sstevel@tonic-gate }
12460Sstevel@tonic-gate 
12470Sstevel@tonic-gate /*
12480Sstevel@tonic-gate  * Determine whether a page with the specified [vp, off]
12490Sstevel@tonic-gate  * currently exists in the system and if so return its
12500Sstevel@tonic-gate  * size code. Obviously this should only be considered as
12510Sstevel@tonic-gate  * a hint since nothing prevents the page from disappearing
12520Sstevel@tonic-gate  * or appearing immediately after the return from this routine.
12530Sstevel@tonic-gate  */
12540Sstevel@tonic-gate int
12550Sstevel@tonic-gate page_exists_forreal(vnode_t *vp, u_offset_t off, uint_t *szc)
12560Sstevel@tonic-gate {
12570Sstevel@tonic-gate 	page_t		*pp;
12580Sstevel@tonic-gate 	kmutex_t	*phm;
12590Sstevel@tonic-gate 	ulong_t		index;
12600Sstevel@tonic-gate 	int		rc = 0;
12610Sstevel@tonic-gate 
12620Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
12630Sstevel@tonic-gate 	ASSERT(szc != NULL);
12640Sstevel@tonic-gate 	VM_STAT_ADD(page_exists_forreal_cnt);
12650Sstevel@tonic-gate 
12660Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
12670Sstevel@tonic-gate 	phm = PAGE_HASH_MUTEX(index);
12680Sstevel@tonic-gate 
12690Sstevel@tonic-gate 	mutex_enter(phm);
12700Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
12710Sstevel@tonic-gate 	if (pp != NULL) {
12720Sstevel@tonic-gate 		*szc = pp->p_szc;
12730Sstevel@tonic-gate 		rc = 1;
12740Sstevel@tonic-gate 	}
12750Sstevel@tonic-gate 	mutex_exit(phm);
12760Sstevel@tonic-gate 	return (rc);
12770Sstevel@tonic-gate }
12780Sstevel@tonic-gate 
12790Sstevel@tonic-gate /* wakeup threads waiting for pages in page_create_get_something() */
12800Sstevel@tonic-gate void
12810Sstevel@tonic-gate wakeup_pcgs(void)
12820Sstevel@tonic-gate {
12830Sstevel@tonic-gate 	if (!CV_HAS_WAITERS(&pcgs_cv))
12840Sstevel@tonic-gate 		return;
12850Sstevel@tonic-gate 	cv_broadcast(&pcgs_cv);
12860Sstevel@tonic-gate }
12870Sstevel@tonic-gate 
12880Sstevel@tonic-gate /*
12890Sstevel@tonic-gate  * 'freemem' is used all over the kernel as an indication of how many
12900Sstevel@tonic-gate  * pages are free (either on the cache list or on the free page list)
12910Sstevel@tonic-gate  * in the system.  In very few places is a really accurate 'freemem'
12920Sstevel@tonic-gate  * needed.  To avoid contention of the lock protecting a the
12930Sstevel@tonic-gate  * single freemem, it was spread out into NCPU buckets.  Set_freemem
12940Sstevel@tonic-gate  * sets freemem to the total of all NCPU buckets.  It is called from
12950Sstevel@tonic-gate  * clock() on each TICK.
12960Sstevel@tonic-gate  */
12970Sstevel@tonic-gate void
12980Sstevel@tonic-gate set_freemem()
12990Sstevel@tonic-gate {
13000Sstevel@tonic-gate 	struct pcf	*p;
13010Sstevel@tonic-gate 	ulong_t		t;
13020Sstevel@tonic-gate 	uint_t		i;
13030Sstevel@tonic-gate 
13040Sstevel@tonic-gate 	t = 0;
13050Sstevel@tonic-gate 	p = pcf;
13060Sstevel@tonic-gate 	for (i = 0;  i < PCF_FANOUT; i++) {
13070Sstevel@tonic-gate 		t += p->pcf_count;
13080Sstevel@tonic-gate 		p++;
13090Sstevel@tonic-gate 	}
13100Sstevel@tonic-gate 	freemem = t;
13110Sstevel@tonic-gate 
13120Sstevel@tonic-gate 	/*
13130Sstevel@tonic-gate 	 * Don't worry about grabbing mutex.  It's not that
13140Sstevel@tonic-gate 	 * critical if we miss a tick or two.  This is
13150Sstevel@tonic-gate 	 * where we wakeup possible delayers in
13160Sstevel@tonic-gate 	 * page_create_get_something().
13170Sstevel@tonic-gate 	 */
13180Sstevel@tonic-gate 	wakeup_pcgs();
13190Sstevel@tonic-gate }
13200Sstevel@tonic-gate 
13210Sstevel@tonic-gate ulong_t
13220Sstevel@tonic-gate get_freemem()
13230Sstevel@tonic-gate {
13240Sstevel@tonic-gate 	struct pcf	*p;
13250Sstevel@tonic-gate 	ulong_t		t;
13260Sstevel@tonic-gate 	uint_t		i;
13270Sstevel@tonic-gate 
13280Sstevel@tonic-gate 	t = 0;
13290Sstevel@tonic-gate 	p = pcf;
13300Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
13310Sstevel@tonic-gate 		t += p->pcf_count;
13320Sstevel@tonic-gate 		p++;
13330Sstevel@tonic-gate 	}
13340Sstevel@tonic-gate 	/*
13350Sstevel@tonic-gate 	 * We just calculated it, might as well set it.
13360Sstevel@tonic-gate 	 */
13370Sstevel@tonic-gate 	freemem = t;
13380Sstevel@tonic-gate 	return (t);
13390Sstevel@tonic-gate }
13400Sstevel@tonic-gate 
13410Sstevel@tonic-gate /*
13420Sstevel@tonic-gate  * Acquire all of the page cache & free (pcf) locks.
13430Sstevel@tonic-gate  */
13440Sstevel@tonic-gate void
13450Sstevel@tonic-gate pcf_acquire_all()
13460Sstevel@tonic-gate {
13470Sstevel@tonic-gate 	struct pcf	*p;
13480Sstevel@tonic-gate 	uint_t		i;
13490Sstevel@tonic-gate 
13500Sstevel@tonic-gate 	p = pcf;
13510Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
13520Sstevel@tonic-gate 		mutex_enter(&p->pcf_lock);
13530Sstevel@tonic-gate 		p++;
13540Sstevel@tonic-gate 	}
13550Sstevel@tonic-gate }
13560Sstevel@tonic-gate 
13570Sstevel@tonic-gate /*
13580Sstevel@tonic-gate  * Release all the pcf_locks.
13590Sstevel@tonic-gate  */
13600Sstevel@tonic-gate void
13610Sstevel@tonic-gate pcf_release_all()
13620Sstevel@tonic-gate {
13630Sstevel@tonic-gate 	struct pcf	*p;
13640Sstevel@tonic-gate 	uint_t		i;
13650Sstevel@tonic-gate 
13660Sstevel@tonic-gate 	p = pcf;
13670Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
13680Sstevel@tonic-gate 		mutex_exit(&p->pcf_lock);
13690Sstevel@tonic-gate 		p++;
13700Sstevel@tonic-gate 	}
13710Sstevel@tonic-gate }
13720Sstevel@tonic-gate 
13730Sstevel@tonic-gate /*
13740Sstevel@tonic-gate  * Inform the VM system that we need some pages freed up.
13750Sstevel@tonic-gate  * Calls must be symmetric, e.g.:
13760Sstevel@tonic-gate  *
13770Sstevel@tonic-gate  *	page_needfree(100);
13780Sstevel@tonic-gate  *	wait a bit;
13790Sstevel@tonic-gate  *	page_needfree(-100);
13800Sstevel@tonic-gate  */
13810Sstevel@tonic-gate void
13820Sstevel@tonic-gate page_needfree(spgcnt_t npages)
13830Sstevel@tonic-gate {
13840Sstevel@tonic-gate 	mutex_enter(&new_freemem_lock);
13850Sstevel@tonic-gate 	needfree += npages;
13860Sstevel@tonic-gate 	mutex_exit(&new_freemem_lock);
13870Sstevel@tonic-gate }
13880Sstevel@tonic-gate 
13890Sstevel@tonic-gate /*
13900Sstevel@tonic-gate  * Throttle for page_create(): try to prevent freemem from dropping
13910Sstevel@tonic-gate  * below throttlefree.  We can't provide a 100% guarantee because
13920Sstevel@tonic-gate  * KM_NOSLEEP allocations, page_reclaim(), and various other things
13930Sstevel@tonic-gate  * nibble away at the freelist.  However, we can block all PG_WAIT
13940Sstevel@tonic-gate  * allocations until memory becomes available.  The motivation is
13950Sstevel@tonic-gate  * that several things can fall apart when there's no free memory:
13960Sstevel@tonic-gate  *
13970Sstevel@tonic-gate  * (1) If pageout() needs memory to push a page, the system deadlocks.
13980Sstevel@tonic-gate  *
13990Sstevel@tonic-gate  * (2) By (broken) specification, timeout(9F) can neither fail nor
14000Sstevel@tonic-gate  *     block, so it has no choice but to panic the system if it
14010Sstevel@tonic-gate  *     cannot allocate a callout structure.
14020Sstevel@tonic-gate  *
14030Sstevel@tonic-gate  * (3) Like timeout(), ddi_set_callback() cannot fail and cannot block;
14040Sstevel@tonic-gate  *     it panics if it cannot allocate a callback structure.
14050Sstevel@tonic-gate  *
14060Sstevel@tonic-gate  * (4) Untold numbers of third-party drivers have not yet been hardened
14070Sstevel@tonic-gate  *     against KM_NOSLEEP and/or allocb() failures; they simply assume
14080Sstevel@tonic-gate  *     success and panic the system with a data fault on failure.
14090Sstevel@tonic-gate  *     (The long-term solution to this particular problem is to ship
14100Sstevel@tonic-gate  *     hostile fault-injecting DEBUG kernels with the DDK.)
14110Sstevel@tonic-gate  *
14120Sstevel@tonic-gate  * It is theoretically impossible to guarantee success of non-blocking
14130Sstevel@tonic-gate  * allocations, but in practice, this throttle is very hard to break.
14140Sstevel@tonic-gate  */
14150Sstevel@tonic-gate static int
14160Sstevel@tonic-gate page_create_throttle(pgcnt_t npages, int flags)
14170Sstevel@tonic-gate {
14180Sstevel@tonic-gate 	ulong_t	fm;
14190Sstevel@tonic-gate 	uint_t	i;
14200Sstevel@tonic-gate 	pgcnt_t tf;	/* effective value of throttlefree */
14210Sstevel@tonic-gate 
14220Sstevel@tonic-gate 	/*
14230Sstevel@tonic-gate 	 * Never deny pages when:
14240Sstevel@tonic-gate 	 * - it's a thread that cannot block [NOMEMWAIT()]
14250Sstevel@tonic-gate 	 * - the allocation cannot block and must not fail
14260Sstevel@tonic-gate 	 * - the allocation cannot block and is pageout dispensated
14270Sstevel@tonic-gate 	 */
14280Sstevel@tonic-gate 	if (NOMEMWAIT() ||
14290Sstevel@tonic-gate 	    ((flags & (PG_WAIT | PG_PANIC)) == PG_PANIC) ||
14300Sstevel@tonic-gate 	    ((flags & (PG_WAIT | PG_PUSHPAGE)) == PG_PUSHPAGE))
14310Sstevel@tonic-gate 		return (1);
14320Sstevel@tonic-gate 
14330Sstevel@tonic-gate 	/*
14340Sstevel@tonic-gate 	 * If the allocation can't block, we look favorably upon it
14350Sstevel@tonic-gate 	 * unless we're below pageout_reserve.  In that case we fail
14360Sstevel@tonic-gate 	 * the allocation because we want to make sure there are a few
14370Sstevel@tonic-gate 	 * pages available for pageout.
14380Sstevel@tonic-gate 	 */
14390Sstevel@tonic-gate 	if ((flags & PG_WAIT) == 0)
14400Sstevel@tonic-gate 		return (freemem >= npages + pageout_reserve);
14410Sstevel@tonic-gate 
14420Sstevel@tonic-gate 	/* Calculate the effective throttlefree value */
14430Sstevel@tonic-gate 	tf = throttlefree -
14440Sstevel@tonic-gate 	    ((flags & PG_PUSHPAGE) ? pageout_reserve : 0);
14450Sstevel@tonic-gate 
14460Sstevel@tonic-gate 	cv_signal(&proc_pageout->p_cv);
14470Sstevel@tonic-gate 
14480Sstevel@tonic-gate 	while (freemem < npages + tf) {
14490Sstevel@tonic-gate 		pcf_acquire_all();
14500Sstevel@tonic-gate 		mutex_enter(&new_freemem_lock);
14510Sstevel@tonic-gate 		fm = 0;
14520Sstevel@tonic-gate 		for (i = 0; i < PCF_FANOUT; i++) {
14530Sstevel@tonic-gate 			fm += pcf[i].pcf_count;
14540Sstevel@tonic-gate 			pcf[i].pcf_wait++;
14550Sstevel@tonic-gate 			mutex_exit(&pcf[i].pcf_lock);
14560Sstevel@tonic-gate 		}
14570Sstevel@tonic-gate 		freemem = fm;
14580Sstevel@tonic-gate 		needfree += npages;
14590Sstevel@tonic-gate 		freemem_wait++;
14600Sstevel@tonic-gate 		cv_wait(&freemem_cv, &new_freemem_lock);
14610Sstevel@tonic-gate 		freemem_wait--;
14620Sstevel@tonic-gate 		needfree -= npages;
14630Sstevel@tonic-gate 		mutex_exit(&new_freemem_lock);
14640Sstevel@tonic-gate 	}
14650Sstevel@tonic-gate 	return (1);
14660Sstevel@tonic-gate }
14670Sstevel@tonic-gate 
14680Sstevel@tonic-gate /*
1469*5331Samw  * page_create_wait() is called to either coalesce pages from the
14700Sstevel@tonic-gate  * different pcf buckets or to wait because there simply are not
14710Sstevel@tonic-gate  * enough pages to satisfy the caller's request.
14720Sstevel@tonic-gate  *
14730Sstevel@tonic-gate  * Sadly, this is called from platform/vm/vm_machdep.c
14740Sstevel@tonic-gate  */
14750Sstevel@tonic-gate int
14760Sstevel@tonic-gate page_create_wait(size_t npages, uint_t flags)
14770Sstevel@tonic-gate {
14780Sstevel@tonic-gate 	pgcnt_t		total;
14790Sstevel@tonic-gate 	uint_t		i;
14800Sstevel@tonic-gate 	struct pcf	*p;
14810Sstevel@tonic-gate 
14820Sstevel@tonic-gate 	/*
14830Sstevel@tonic-gate 	 * Wait until there are enough free pages to satisfy our
14840Sstevel@tonic-gate 	 * entire request.
14850Sstevel@tonic-gate 	 * We set needfree += npages before prodding pageout, to make sure
14860Sstevel@tonic-gate 	 * it does real work when npages > lotsfree > freemem.
14870Sstevel@tonic-gate 	 */
14880Sstevel@tonic-gate 	VM_STAT_ADD(page_create_not_enough);
14890Sstevel@tonic-gate 
14900Sstevel@tonic-gate 	ASSERT(!kcage_on ? !(flags & PG_NORELOC) : 1);
14910Sstevel@tonic-gate checkagain:
14920Sstevel@tonic-gate 	if ((flags & PG_NORELOC) &&
14930Sstevel@tonic-gate 	    kcage_freemem < kcage_throttlefree + npages)
14940Sstevel@tonic-gate 		(void) kcage_create_throttle(npages, flags);
14950Sstevel@tonic-gate 
14960Sstevel@tonic-gate 	if (freemem < npages + throttlefree)
14970Sstevel@tonic-gate 		if (!page_create_throttle(npages, flags))
14980Sstevel@tonic-gate 			return (0);
14990Sstevel@tonic-gate 
15000Sstevel@tonic-gate 	/*
15010Sstevel@tonic-gate 	 * Since page_create_va() looked at every
15020Sstevel@tonic-gate 	 * bucket, assume we are going to have to wait.
15030Sstevel@tonic-gate 	 * Get all of the pcf locks.
15040Sstevel@tonic-gate 	 */
15050Sstevel@tonic-gate 	total = 0;
15060Sstevel@tonic-gate 	p = pcf;
15070Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
15080Sstevel@tonic-gate 		mutex_enter(&p->pcf_lock);
15090Sstevel@tonic-gate 		total += p->pcf_count;
15100Sstevel@tonic-gate 		if (total >= npages) {
15110Sstevel@tonic-gate 			/*
15120Sstevel@tonic-gate 			 * Wow!  There are enough pages laying around
15130Sstevel@tonic-gate 			 * to satisfy the request.  Do the accounting,
15140Sstevel@tonic-gate 			 * drop the locks we acquired, and go back.
15150Sstevel@tonic-gate 			 *
15160Sstevel@tonic-gate 			 * freemem is not protected by any lock. So,
15170Sstevel@tonic-gate 			 * we cannot have any assertion containing
15180Sstevel@tonic-gate 			 * freemem.
15190Sstevel@tonic-gate 			 */
15200Sstevel@tonic-gate 			freemem -= npages;
15210Sstevel@tonic-gate 
15220Sstevel@tonic-gate 			while (p >= pcf) {
15230Sstevel@tonic-gate 				if (p->pcf_count <= npages) {
15240Sstevel@tonic-gate 					npages -= p->pcf_count;
15250Sstevel@tonic-gate 					p->pcf_count = 0;
15260Sstevel@tonic-gate 				} else {
15270Sstevel@tonic-gate 					p->pcf_count -= (uint_t)npages;
15280Sstevel@tonic-gate 					npages = 0;
15290Sstevel@tonic-gate 				}
15300Sstevel@tonic-gate 				mutex_exit(&p->pcf_lock);
15310Sstevel@tonic-gate 				p--;
15320Sstevel@tonic-gate 			}
15330Sstevel@tonic-gate 			ASSERT(npages == 0);
15340Sstevel@tonic-gate 			return (1);
15350Sstevel@tonic-gate 		}
15360Sstevel@tonic-gate 		p++;
15370Sstevel@tonic-gate 	}
15380Sstevel@tonic-gate 
15390Sstevel@tonic-gate 	/*
15400Sstevel@tonic-gate 	 * All of the pcf locks are held, there are not enough pages
15410Sstevel@tonic-gate 	 * to satisfy the request (npages < total).
15420Sstevel@tonic-gate 	 * Be sure to acquire the new_freemem_lock before dropping
15430Sstevel@tonic-gate 	 * the pcf locks.  This prevents dropping wakeups in page_free().
15440Sstevel@tonic-gate 	 * The order is always pcf_lock then new_freemem_lock.
15450Sstevel@tonic-gate 	 *
15460Sstevel@tonic-gate 	 * Since we hold all the pcf locks, it is a good time to set freemem.
15470Sstevel@tonic-gate 	 *
15480Sstevel@tonic-gate 	 * If the caller does not want to wait, return now.
15490Sstevel@tonic-gate 	 * Else turn the pageout daemon loose to find something
15500Sstevel@tonic-gate 	 * and wait till it does.
15510Sstevel@tonic-gate 	 *
15520Sstevel@tonic-gate 	 */
15530Sstevel@tonic-gate 	freemem = total;
15540Sstevel@tonic-gate 
15550Sstevel@tonic-gate 	if ((flags & PG_WAIT) == 0) {
15560Sstevel@tonic-gate 		pcf_release_all();
15570Sstevel@tonic-gate 
15580Sstevel@tonic-gate 		TRACE_2(TR_FAC_VM, TR_PAGE_CREATE_NOMEM,
15590Sstevel@tonic-gate 		"page_create_nomem:npages %ld freemem %ld", npages, freemem);
15600Sstevel@tonic-gate 		return (0);
15610Sstevel@tonic-gate 	}
15620Sstevel@tonic-gate 
15630Sstevel@tonic-gate 	ASSERT(proc_pageout != NULL);
15640Sstevel@tonic-gate 	cv_signal(&proc_pageout->p_cv);
15650Sstevel@tonic-gate 
15660Sstevel@tonic-gate 	TRACE_2(TR_FAC_VM, TR_PAGE_CREATE_SLEEP_START,
15670Sstevel@tonic-gate 	    "page_create_sleep_start: freemem %ld needfree %ld",
15680Sstevel@tonic-gate 	    freemem, needfree);
15690Sstevel@tonic-gate 
15700Sstevel@tonic-gate 	/*
15710Sstevel@tonic-gate 	 * We are going to wait.
15720Sstevel@tonic-gate 	 * We currently hold all of the pcf_locks,
15730Sstevel@tonic-gate 	 * get the new_freemem_lock (it protects freemem_wait),
15740Sstevel@tonic-gate 	 * before dropping the pcf_locks.
15750Sstevel@tonic-gate 	 */
15760Sstevel@tonic-gate 	mutex_enter(&new_freemem_lock);
15770Sstevel@tonic-gate 
15780Sstevel@tonic-gate 	p = pcf;
15790Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
15800Sstevel@tonic-gate 		p->pcf_wait++;
15810Sstevel@tonic-gate 		mutex_exit(&p->pcf_lock);
15820Sstevel@tonic-gate 		p++;
15830Sstevel@tonic-gate 	}
15840Sstevel@tonic-gate 
15850Sstevel@tonic-gate 	needfree += npages;
15860Sstevel@tonic-gate 	freemem_wait++;
15870Sstevel@tonic-gate 
15880Sstevel@tonic-gate 	cv_wait(&freemem_cv, &new_freemem_lock);
15890Sstevel@tonic-gate 
15900Sstevel@tonic-gate 	freemem_wait--;
15910Sstevel@tonic-gate 	needfree -= npages;
15920Sstevel@tonic-gate 
15930Sstevel@tonic-gate 	mutex_exit(&new_freemem_lock);
15940Sstevel@tonic-gate 
15950Sstevel@tonic-gate 	TRACE_2(TR_FAC_VM, TR_PAGE_CREATE_SLEEP_END,
15960Sstevel@tonic-gate 	    "page_create_sleep_end: freemem %ld needfree %ld",
15970Sstevel@tonic-gate 	    freemem, needfree);
15980Sstevel@tonic-gate 
15990Sstevel@tonic-gate 	VM_STAT_ADD(page_create_not_enough_again);
16000Sstevel@tonic-gate 	goto checkagain;
16010Sstevel@tonic-gate }
16020Sstevel@tonic-gate 
16030Sstevel@tonic-gate /*
16040Sstevel@tonic-gate  * A routine to do the opposite of page_create_wait().
16050Sstevel@tonic-gate  */
16060Sstevel@tonic-gate void
16070Sstevel@tonic-gate page_create_putback(spgcnt_t npages)
16080Sstevel@tonic-gate {
16090Sstevel@tonic-gate 	struct pcf	*p;
16100Sstevel@tonic-gate 	pgcnt_t		lump;
16110Sstevel@tonic-gate 	uint_t		*which;
16120Sstevel@tonic-gate 
16130Sstevel@tonic-gate 	/*
16140Sstevel@tonic-gate 	 * When a contiguous lump is broken up, we have to
16150Sstevel@tonic-gate 	 * deal with lots of pages (min 64) so lets spread
16160Sstevel@tonic-gate 	 * the wealth around.
16170Sstevel@tonic-gate 	 */
16180Sstevel@tonic-gate 	lump = roundup(npages, PCF_FANOUT) / PCF_FANOUT;
16190Sstevel@tonic-gate 	freemem += npages;
16200Sstevel@tonic-gate 
16210Sstevel@tonic-gate 	for (p = pcf; (npages > 0) && (p < &pcf[PCF_FANOUT]); p++) {
16220Sstevel@tonic-gate 		which = &p->pcf_count;
16230Sstevel@tonic-gate 
16240Sstevel@tonic-gate 		mutex_enter(&p->pcf_lock);
16250Sstevel@tonic-gate 
16260Sstevel@tonic-gate 		if (p->pcf_block) {
16270Sstevel@tonic-gate 			which = &p->pcf_reserve;
16280Sstevel@tonic-gate 		}
16290Sstevel@tonic-gate 
16300Sstevel@tonic-gate 		if (lump < npages) {
16310Sstevel@tonic-gate 			*which += (uint_t)lump;
16320Sstevel@tonic-gate 			npages -= lump;
16330Sstevel@tonic-gate 		} else {
16340Sstevel@tonic-gate 			*which += (uint_t)npages;
16350Sstevel@tonic-gate 			npages = 0;
16360Sstevel@tonic-gate 		}
16370Sstevel@tonic-gate 
16380Sstevel@tonic-gate 		if (p->pcf_wait) {
16390Sstevel@tonic-gate 			mutex_enter(&new_freemem_lock);
16400Sstevel@tonic-gate 			/*
16410Sstevel@tonic-gate 			 * Check to see if some other thread
16420Sstevel@tonic-gate 			 * is actually waiting.  Another bucket
16430Sstevel@tonic-gate 			 * may have woken it up by now.  If there
16440Sstevel@tonic-gate 			 * are no waiters, then set our pcf_wait
16450Sstevel@tonic-gate 			 * count to zero to avoid coming in here
16460Sstevel@tonic-gate 			 * next time.
16470Sstevel@tonic-gate 			 */
16480Sstevel@tonic-gate 			if (freemem_wait) {
16490Sstevel@tonic-gate 				if (npages > 1) {
16500Sstevel@tonic-gate 					cv_broadcast(&freemem_cv);
16510Sstevel@tonic-gate 				} else {
16520Sstevel@tonic-gate 					cv_signal(&freemem_cv);
16530Sstevel@tonic-gate 				}
16540Sstevel@tonic-gate 				p->pcf_wait--;
16550Sstevel@tonic-gate 			} else {
16560Sstevel@tonic-gate 				p->pcf_wait = 0;
16570Sstevel@tonic-gate 			}
16580Sstevel@tonic-gate 			mutex_exit(&new_freemem_lock);
16590Sstevel@tonic-gate 		}
16600Sstevel@tonic-gate 		mutex_exit(&p->pcf_lock);
16610Sstevel@tonic-gate 	}
16620Sstevel@tonic-gate 	ASSERT(npages == 0);
16630Sstevel@tonic-gate }
16640Sstevel@tonic-gate 
16650Sstevel@tonic-gate /*
16660Sstevel@tonic-gate  * A helper routine for page_create_get_something.
16670Sstevel@tonic-gate  * The indenting got to deep down there.
16680Sstevel@tonic-gate  * Unblock the pcf counters.  Any pages freed after
16690Sstevel@tonic-gate  * pcf_block got set are moved to pcf_count and
16700Sstevel@tonic-gate  * wakeups (cv_broadcast() or cv_signal()) are done as needed.
16710Sstevel@tonic-gate  */
16720Sstevel@tonic-gate static void
16730Sstevel@tonic-gate pcgs_unblock(void)
16740Sstevel@tonic-gate {
16750Sstevel@tonic-gate 	int		i;
16760Sstevel@tonic-gate 	struct pcf	*p;
16770Sstevel@tonic-gate 
16780Sstevel@tonic-gate 	/* Update freemem while we're here. */
16790Sstevel@tonic-gate 	freemem = 0;
16800Sstevel@tonic-gate 	p = pcf;
16810Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
16820Sstevel@tonic-gate 		mutex_enter(&p->pcf_lock);
16830Sstevel@tonic-gate 		ASSERT(p->pcf_count == 0);
16840Sstevel@tonic-gate 		p->pcf_count = p->pcf_reserve;
16850Sstevel@tonic-gate 		p->pcf_block = 0;
16860Sstevel@tonic-gate 		freemem += p->pcf_count;
16870Sstevel@tonic-gate 		if (p->pcf_wait) {
16880Sstevel@tonic-gate 			mutex_enter(&new_freemem_lock);
16890Sstevel@tonic-gate 			if (freemem_wait) {
16900Sstevel@tonic-gate 				if (p->pcf_reserve > 1) {
16910Sstevel@tonic-gate 					cv_broadcast(&freemem_cv);
16920Sstevel@tonic-gate 					p->pcf_wait = 0;
16930Sstevel@tonic-gate 				} else {
16940Sstevel@tonic-gate 					cv_signal(&freemem_cv);
16950Sstevel@tonic-gate 					p->pcf_wait--;
16960Sstevel@tonic-gate 				}
16970Sstevel@tonic-gate 			} else {
16980Sstevel@tonic-gate 				p->pcf_wait = 0;
16990Sstevel@tonic-gate 			}
17000Sstevel@tonic-gate 			mutex_exit(&new_freemem_lock);
17010Sstevel@tonic-gate 		}
17020Sstevel@tonic-gate 		p->pcf_reserve = 0;
17030Sstevel@tonic-gate 		mutex_exit(&p->pcf_lock);
17040Sstevel@tonic-gate 		p++;
17050Sstevel@tonic-gate 	}
17060Sstevel@tonic-gate }
17070Sstevel@tonic-gate 
17080Sstevel@tonic-gate /*
17090Sstevel@tonic-gate  * Called from page_create_va() when both the cache and free lists
17100Sstevel@tonic-gate  * have been checked once.
17110Sstevel@tonic-gate  *
17120Sstevel@tonic-gate  * Either returns a page or panics since the accounting was done
17130Sstevel@tonic-gate  * way before we got here.
17140Sstevel@tonic-gate  *
17150Sstevel@tonic-gate  * We don't come here often, so leave the accounting on permanently.
17160Sstevel@tonic-gate  */
17170Sstevel@tonic-gate 
17180Sstevel@tonic-gate #define	MAX_PCGS	100
17190Sstevel@tonic-gate 
17200Sstevel@tonic-gate #ifdef	DEBUG
17210Sstevel@tonic-gate #define	PCGS_TRIES	100
17220Sstevel@tonic-gate #else	/* DEBUG */
17230Sstevel@tonic-gate #define	PCGS_TRIES	10
17240Sstevel@tonic-gate #endif	/* DEBUG */
17250Sstevel@tonic-gate 
17260Sstevel@tonic-gate #ifdef	VM_STATS
17270Sstevel@tonic-gate uint_t	pcgs_counts[PCGS_TRIES];
17280Sstevel@tonic-gate uint_t	pcgs_too_many;
17290Sstevel@tonic-gate uint_t	pcgs_entered;
17300Sstevel@tonic-gate uint_t	pcgs_entered_noreloc;
17310Sstevel@tonic-gate uint_t	pcgs_locked;
17320Sstevel@tonic-gate uint_t	pcgs_cagelocked;
17330Sstevel@tonic-gate #endif	/* VM_STATS */
17340Sstevel@tonic-gate 
17350Sstevel@tonic-gate static page_t *
17360Sstevel@tonic-gate page_create_get_something(vnode_t *vp, u_offset_t off, struct seg *seg,
17370Sstevel@tonic-gate     caddr_t vaddr, uint_t flags)
17380Sstevel@tonic-gate {
17390Sstevel@tonic-gate 	uint_t		count;
17400Sstevel@tonic-gate 	page_t		*pp;
17410Sstevel@tonic-gate 	uint_t		locked, i;
17420Sstevel@tonic-gate 	struct	pcf	*p;
17430Sstevel@tonic-gate 	lgrp_t		*lgrp;
17440Sstevel@tonic-gate 	int		cagelocked = 0;
17450Sstevel@tonic-gate 
17460Sstevel@tonic-gate 	VM_STAT_ADD(pcgs_entered);
17470Sstevel@tonic-gate 
17480Sstevel@tonic-gate 	/*
17490Sstevel@tonic-gate 	 * Tap any reserve freelists: if we fail now, we'll die
17500Sstevel@tonic-gate 	 * since the page(s) we're looking for have already been
17510Sstevel@tonic-gate 	 * accounted for.
17520Sstevel@tonic-gate 	 */
17530Sstevel@tonic-gate 	flags |= PG_PANIC;
17540Sstevel@tonic-gate 
17550Sstevel@tonic-gate 	if ((flags & PG_NORELOC) != 0) {
17560Sstevel@tonic-gate 		VM_STAT_ADD(pcgs_entered_noreloc);
17570Sstevel@tonic-gate 		/*
17580Sstevel@tonic-gate 		 * Requests for free pages from critical threads
17590Sstevel@tonic-gate 		 * such as pageout still won't throttle here, but
17600Sstevel@tonic-gate 		 * we must try again, to give the cageout thread
17610Sstevel@tonic-gate 		 * another chance to catch up. Since we already
17620Sstevel@tonic-gate 		 * accounted for the pages, we had better get them
17630Sstevel@tonic-gate 		 * this time.
17640Sstevel@tonic-gate 		 *
17650Sstevel@tonic-gate 		 * N.B. All non-critical threads acquire the pcgs_cagelock
17660Sstevel@tonic-gate 		 * to serialize access to the freelists. This implements a
17670Sstevel@tonic-gate 		 * turnstile-type synchornization to avoid starvation of
17680Sstevel@tonic-gate 		 * critical requests for PG_NORELOC memory by non-critical
17690Sstevel@tonic-gate 		 * threads: all non-critical threads must acquire a 'ticket'
17700Sstevel@tonic-gate 		 * before passing through, which entails making sure
17710Sstevel@tonic-gate 		 * kcage_freemem won't fall below minfree prior to grabbing
17720Sstevel@tonic-gate 		 * pages from the freelists.
17730Sstevel@tonic-gate 		 */
17740Sstevel@tonic-gate 		if (kcage_create_throttle(1, flags) == KCT_NONCRIT) {
17750Sstevel@tonic-gate 			mutex_enter(&pcgs_cagelock);
17760Sstevel@tonic-gate 			cagelocked = 1;
17770Sstevel@tonic-gate 			VM_STAT_ADD(pcgs_cagelocked);
17780Sstevel@tonic-gate 		}
17790Sstevel@tonic-gate 	}
17800Sstevel@tonic-gate 
17810Sstevel@tonic-gate 	/*
17820Sstevel@tonic-gate 	 * Time to get serious.
17830Sstevel@tonic-gate 	 * We failed to get a `correctly colored' page from both the
17840Sstevel@tonic-gate 	 * free and cache lists.
17850Sstevel@tonic-gate 	 * We escalate in stage.
17860Sstevel@tonic-gate 	 *
17870Sstevel@tonic-gate 	 * First try both lists without worring about color.
17880Sstevel@tonic-gate 	 *
17890Sstevel@tonic-gate 	 * Then, grab all page accounting locks (ie. pcf[]) and
17900Sstevel@tonic-gate 	 * steal any pages that they have and set the pcf_block flag to
17910Sstevel@tonic-gate 	 * stop deletions from the lists.  This will help because
17920Sstevel@tonic-gate 	 * a page can get added to the free list while we are looking
17930Sstevel@tonic-gate 	 * at the cache list, then another page could be added to the cache
17940Sstevel@tonic-gate 	 * list allowing the page on the free list to be removed as we
17950Sstevel@tonic-gate 	 * move from looking at the cache list to the free list. This
17960Sstevel@tonic-gate 	 * could happen over and over. We would never find the page
17970Sstevel@tonic-gate 	 * we have accounted for.
17980Sstevel@tonic-gate 	 *
17990Sstevel@tonic-gate 	 * Noreloc pages are a subset of the global (relocatable) page pool.
18000Sstevel@tonic-gate 	 * They are not tracked separately in the pcf bins, so it is
18010Sstevel@tonic-gate 	 * impossible to know when doing pcf accounting if the available
18020Sstevel@tonic-gate 	 * page(s) are noreloc pages or not. When looking for a noreloc page
18030Sstevel@tonic-gate 	 * it is quite easy to end up here even if the global (relocatable)
18040Sstevel@tonic-gate 	 * page pool has plenty of free pages but the noreloc pool is empty.
18050Sstevel@tonic-gate 	 *
18060Sstevel@tonic-gate 	 * When the noreloc pool is empty (or low), additional noreloc pages
18070Sstevel@tonic-gate 	 * are created by converting pages from the global page pool. This
18080Sstevel@tonic-gate 	 * process will stall during pcf accounting if the pcf bins are
18090Sstevel@tonic-gate 	 * already locked. Such is the case when a noreloc allocation is
18100Sstevel@tonic-gate 	 * looping here in page_create_get_something waiting for more noreloc
18110Sstevel@tonic-gate 	 * pages to appear.
18120Sstevel@tonic-gate 	 *
18130Sstevel@tonic-gate 	 * Short of adding a new field to the pcf bins to accurately track
18140Sstevel@tonic-gate 	 * the number of free noreloc pages, we instead do not grab the
18150Sstevel@tonic-gate 	 * pcgs_lock, do not set the pcf blocks and do not timeout when
18160Sstevel@tonic-gate 	 * allocating a noreloc page. This allows noreloc allocations to
18170Sstevel@tonic-gate 	 * loop without blocking global page pool allocations.
18180Sstevel@tonic-gate 	 *
18190Sstevel@tonic-gate 	 * NOTE: the behaviour of page_create_get_something has not changed
18200Sstevel@tonic-gate 	 * for the case of global page pool allocations.
18210Sstevel@tonic-gate 	 */
18220Sstevel@tonic-gate 
18230Sstevel@tonic-gate 	flags &= ~PG_MATCH_COLOR;
18240Sstevel@tonic-gate 	locked = 0;
18251385Skchow #if defined(__i386) || defined(__amd64)
18265084Sjohnlev 	flags = page_create_update_flags_x86(flags);
18270Sstevel@tonic-gate #endif
18280Sstevel@tonic-gate 
18290Sstevel@tonic-gate 	lgrp = lgrp_mem_choose(seg, vaddr, PAGESIZE);
18300Sstevel@tonic-gate 
18310Sstevel@tonic-gate 	for (count = 0; kcage_on || count < MAX_PCGS; count++) {
18320Sstevel@tonic-gate 		pp = page_get_freelist(vp, off, seg, vaddr, PAGESIZE,
18330Sstevel@tonic-gate 		    flags, lgrp);
18340Sstevel@tonic-gate 		if (pp == NULL) {
18350Sstevel@tonic-gate 			pp = page_get_cachelist(vp, off, seg, vaddr,
18363559Smec 			    flags, lgrp);
18370Sstevel@tonic-gate 		}
18380Sstevel@tonic-gate 		if (pp == NULL) {
18390Sstevel@tonic-gate 			/*
18400Sstevel@tonic-gate 			 * Serialize.  Don't fight with other pcgs().
18410Sstevel@tonic-gate 			 */
18420Sstevel@tonic-gate 			if (!locked && (!kcage_on || !(flags & PG_NORELOC))) {
18430Sstevel@tonic-gate 				mutex_enter(&pcgs_lock);
18440Sstevel@tonic-gate 				VM_STAT_ADD(pcgs_locked);
18450Sstevel@tonic-gate 				locked = 1;
18460Sstevel@tonic-gate 				p = pcf;
18470Sstevel@tonic-gate 				for (i = 0; i < PCF_FANOUT; i++) {
18480Sstevel@tonic-gate 					mutex_enter(&p->pcf_lock);
18490Sstevel@tonic-gate 					ASSERT(p->pcf_block == 0);
18500Sstevel@tonic-gate 					p->pcf_block = 1;
18510Sstevel@tonic-gate 					p->pcf_reserve = p->pcf_count;
18520Sstevel@tonic-gate 					p->pcf_count = 0;
18530Sstevel@tonic-gate 					mutex_exit(&p->pcf_lock);
18540Sstevel@tonic-gate 					p++;
18550Sstevel@tonic-gate 				}
18560Sstevel@tonic-gate 				freemem = 0;
18570Sstevel@tonic-gate 			}
18580Sstevel@tonic-gate 
18590Sstevel@tonic-gate 			if (count) {
18600Sstevel@tonic-gate 				/*
18610Sstevel@tonic-gate 				 * Since page_free() puts pages on
18620Sstevel@tonic-gate 				 * a list then accounts for it, we
18630Sstevel@tonic-gate 				 * just have to wait for page_free()
18640Sstevel@tonic-gate 				 * to unlock any page it was working
18650Sstevel@tonic-gate 				 * with. The page_lock()-page_reclaim()
18660Sstevel@tonic-gate 				 * path falls in the same boat.
18670Sstevel@tonic-gate 				 *
18680Sstevel@tonic-gate 				 * We don't need to check on the
18690Sstevel@tonic-gate 				 * PG_WAIT flag, we have already
18700Sstevel@tonic-gate 				 * accounted for the page we are
18710Sstevel@tonic-gate 				 * looking for in page_create_va().
18720Sstevel@tonic-gate 				 *
18730Sstevel@tonic-gate 				 * We just wait a moment to let any
18740Sstevel@tonic-gate 				 * locked pages on the lists free up,
18750Sstevel@tonic-gate 				 * then continue around and try again.
18760Sstevel@tonic-gate 				 *
18770Sstevel@tonic-gate 				 * Will be awakened by set_freemem().
18780Sstevel@tonic-gate 				 */
18790Sstevel@tonic-gate 				mutex_enter(&pcgs_wait_lock);
18800Sstevel@tonic-gate 				cv_wait(&pcgs_cv, &pcgs_wait_lock);
18810Sstevel@tonic-gate 				mutex_exit(&pcgs_wait_lock);
18820Sstevel@tonic-gate 			}
18830Sstevel@tonic-gate 		} else {
18840Sstevel@tonic-gate #ifdef VM_STATS
18850Sstevel@tonic-gate 			if (count >= PCGS_TRIES) {
18860Sstevel@tonic-gate 				VM_STAT_ADD(pcgs_too_many);
18870Sstevel@tonic-gate 			} else {
18880Sstevel@tonic-gate 				VM_STAT_ADD(pcgs_counts[count]);
18890Sstevel@tonic-gate 			}
18900Sstevel@tonic-gate #endif
18910Sstevel@tonic-gate 			if (locked) {
18920Sstevel@tonic-gate 				pcgs_unblock();
18930Sstevel@tonic-gate 				mutex_exit(&pcgs_lock);
18940Sstevel@tonic-gate 			}
18950Sstevel@tonic-gate 			if (cagelocked)
18960Sstevel@tonic-gate 				mutex_exit(&pcgs_cagelock);
18970Sstevel@tonic-gate 			return (pp);
18980Sstevel@tonic-gate 		}
18990Sstevel@tonic-gate 	}
19000Sstevel@tonic-gate 	/*
19010Sstevel@tonic-gate 	 * we go down holding the pcf locks.
19020Sstevel@tonic-gate 	 */
19030Sstevel@tonic-gate 	panic("no %spage found %d",
19040Sstevel@tonic-gate 	    ((flags & PG_NORELOC) ? "non-reloc " : ""), count);
19050Sstevel@tonic-gate 	/*NOTREACHED*/
19060Sstevel@tonic-gate }
19070Sstevel@tonic-gate 
19080Sstevel@tonic-gate /*
19090Sstevel@tonic-gate  * Create enough pages for "bytes" worth of data starting at
19100Sstevel@tonic-gate  * "off" in "vp".
19110Sstevel@tonic-gate  *
19120Sstevel@tonic-gate  *	Where flag must be one of:
19130Sstevel@tonic-gate  *
19140Sstevel@tonic-gate  *		PG_EXCL:	Exclusive create (fail if any page already
19150Sstevel@tonic-gate  *				exists in the page cache) which does not
19160Sstevel@tonic-gate  *				wait for memory to become available.
19170Sstevel@tonic-gate  *
19180Sstevel@tonic-gate  *		PG_WAIT:	Non-exclusive create which can wait for
19190Sstevel@tonic-gate  *				memory to become available.
19200Sstevel@tonic-gate  *
19210Sstevel@tonic-gate  *		PG_PHYSCONTIG:	Allocate physically contiguous pages.
19220Sstevel@tonic-gate  *				(Not Supported)
19230Sstevel@tonic-gate  *
19240Sstevel@tonic-gate  * A doubly linked list of pages is returned to the caller.  Each page
19250Sstevel@tonic-gate  * on the list has the "exclusive" (p_selock) lock and "iolock" (p_iolock)
19260Sstevel@tonic-gate  * lock.
19270Sstevel@tonic-gate  *
19280Sstevel@tonic-gate  * Unable to change the parameters to page_create() in a minor release,
19290Sstevel@tonic-gate  * we renamed page_create() to page_create_va(), changed all known calls
19300Sstevel@tonic-gate  * from page_create() to page_create_va(), and created this wrapper.
19310Sstevel@tonic-gate  *
19320Sstevel@tonic-gate  * Upon a major release, we should break compatibility by deleting this
19330Sstevel@tonic-gate  * wrapper, and replacing all the strings "page_create_va", with "page_create".
19340Sstevel@tonic-gate  *
19350Sstevel@tonic-gate  * NOTE: There is a copy of this interface as page_create_io() in
19360Sstevel@tonic-gate  *	 i86/vm/vm_machdep.c. Any bugs fixed here should be applied
19370Sstevel@tonic-gate  *	 there.
19380Sstevel@tonic-gate  */
19390Sstevel@tonic-gate page_t *
19400Sstevel@tonic-gate page_create(vnode_t *vp, u_offset_t off, size_t bytes, uint_t flags)
19410Sstevel@tonic-gate {
19420Sstevel@tonic-gate 	caddr_t random_vaddr;
19430Sstevel@tonic-gate 	struct seg kseg;
19440Sstevel@tonic-gate 
19450Sstevel@tonic-gate #ifdef DEBUG
19460Sstevel@tonic-gate 	cmn_err(CE_WARN, "Using deprecated interface page_create: caller %p",
19470Sstevel@tonic-gate 	    (void *)caller());
19480Sstevel@tonic-gate #endif
19490Sstevel@tonic-gate 
19500Sstevel@tonic-gate 	random_vaddr = (caddr_t)(((uintptr_t)vp >> 7) ^
19510Sstevel@tonic-gate 	    (uintptr_t)(off >> PAGESHIFT));
19520Sstevel@tonic-gate 	kseg.s_as = &kas;
19530Sstevel@tonic-gate 
19540Sstevel@tonic-gate 	return (page_create_va(vp, off, bytes, flags, &kseg, random_vaddr));
19550Sstevel@tonic-gate }
19560Sstevel@tonic-gate 
19570Sstevel@tonic-gate #ifdef DEBUG
19580Sstevel@tonic-gate uint32_t pg_alloc_pgs_mtbf = 0;
19590Sstevel@tonic-gate #endif
19600Sstevel@tonic-gate 
19610Sstevel@tonic-gate /*
19620Sstevel@tonic-gate  * Used for large page support. It will attempt to allocate
19630Sstevel@tonic-gate  * a large page(s) off the freelist.
19640Sstevel@tonic-gate  *
19650Sstevel@tonic-gate  * Returns non zero on failure.
19660Sstevel@tonic-gate  */
19670Sstevel@tonic-gate int
1968749Ssusans page_alloc_pages(struct vnode *vp, struct seg *seg, caddr_t addr,
19694426Saguzovsk     page_t **basepp, page_t *ppa[], uint_t szc, int anypgsz, int pgflags)
19700Sstevel@tonic-gate {
19710Sstevel@tonic-gate 	pgcnt_t		npgs, curnpgs, totpgs;
19720Sstevel@tonic-gate 	size_t		pgsz;
19730Sstevel@tonic-gate 	page_t		*pplist = NULL, *pp;
19740Sstevel@tonic-gate 	int		err = 0;
19750Sstevel@tonic-gate 	lgrp_t		*lgrp;
19760Sstevel@tonic-gate 
19770Sstevel@tonic-gate 	ASSERT(szc != 0 && szc <= (page_num_pagesizes() - 1));
19784426Saguzovsk 	ASSERT(pgflags == 0 || pgflags == PG_LOCAL);
19790Sstevel@tonic-gate 
19800Sstevel@tonic-gate 	VM_STAT_ADD(alloc_pages[0]);
19810Sstevel@tonic-gate 
19820Sstevel@tonic-gate #ifdef DEBUG
19830Sstevel@tonic-gate 	if (pg_alloc_pgs_mtbf && !(gethrtime() % pg_alloc_pgs_mtbf)) {
19840Sstevel@tonic-gate 		return (ENOMEM);
19850Sstevel@tonic-gate 	}
19860Sstevel@tonic-gate #endif
19870Sstevel@tonic-gate 
19880Sstevel@tonic-gate 	pgsz = page_get_pagesize(szc);
19890Sstevel@tonic-gate 	totpgs = curnpgs = npgs = pgsz >> PAGESHIFT;
19900Sstevel@tonic-gate 
19910Sstevel@tonic-gate 	ASSERT(((uintptr_t)addr & (pgsz - 1)) == 0);
19920Sstevel@tonic-gate 	/*
19930Sstevel@tonic-gate 	 * One must be NULL but not both.
19940Sstevel@tonic-gate 	 * And one must be non NULL but not both.
19950Sstevel@tonic-gate 	 */
19960Sstevel@tonic-gate 	ASSERT(basepp != NULL || ppa != NULL);
19970Sstevel@tonic-gate 	ASSERT(basepp == NULL || ppa == NULL);
19980Sstevel@tonic-gate 
19990Sstevel@tonic-gate 	(void) page_create_wait(npgs, PG_WAIT);
20000Sstevel@tonic-gate 
20010Sstevel@tonic-gate 	while (npgs && szc) {
20020Sstevel@tonic-gate 		lgrp = lgrp_mem_choose(seg, addr, pgsz);
20034426Saguzovsk 		if (pgflags == PG_LOCAL) {
20044426Saguzovsk 			pp = page_get_freelist(vp, 0, seg, addr, pgsz,
20054426Saguzovsk 			    pgflags, lgrp);
20064426Saguzovsk 			if (pp == NULL) {
20074426Saguzovsk 				pp = page_get_freelist(vp, 0, seg, addr, pgsz,
20084426Saguzovsk 				    0, lgrp);
20094426Saguzovsk 			}
20104426Saguzovsk 		} else {
20114426Saguzovsk 			pp = page_get_freelist(vp, 0, seg, addr, pgsz,
20124426Saguzovsk 			    0, lgrp);
20134426Saguzovsk 		}
20140Sstevel@tonic-gate 		if (pp != NULL) {
20150Sstevel@tonic-gate 			VM_STAT_ADD(alloc_pages[1]);
20160Sstevel@tonic-gate 			page_list_concat(&pplist, &pp);
20170Sstevel@tonic-gate 			ASSERT(npgs >= curnpgs);
20180Sstevel@tonic-gate 			npgs -= curnpgs;
20190Sstevel@tonic-gate 		} else if (anypgsz) {
20200Sstevel@tonic-gate 			VM_STAT_ADD(alloc_pages[2]);
20210Sstevel@tonic-gate 			szc--;
20220Sstevel@tonic-gate 			pgsz = page_get_pagesize(szc);
20230Sstevel@tonic-gate 			curnpgs = pgsz >> PAGESHIFT;
20240Sstevel@tonic-gate 		} else {
20250Sstevel@tonic-gate 			VM_STAT_ADD(alloc_pages[3]);
20260Sstevel@tonic-gate 			ASSERT(npgs == totpgs);
20270Sstevel@tonic-gate 			page_create_putback(npgs);
20280Sstevel@tonic-gate 			return (ENOMEM);
20290Sstevel@tonic-gate 		}
20300Sstevel@tonic-gate 	}
20310Sstevel@tonic-gate 	if (szc == 0) {
20320Sstevel@tonic-gate 		VM_STAT_ADD(alloc_pages[4]);
20330Sstevel@tonic-gate 		ASSERT(npgs != 0);
20340Sstevel@tonic-gate 		page_create_putback(npgs);
20350Sstevel@tonic-gate 		err = ENOMEM;
20360Sstevel@tonic-gate 	} else if (basepp != NULL) {
20370Sstevel@tonic-gate 		ASSERT(npgs == 0);
20380Sstevel@tonic-gate 		ASSERT(ppa == NULL);
20390Sstevel@tonic-gate 		*basepp = pplist;
20400Sstevel@tonic-gate 	}
20410Sstevel@tonic-gate 
20420Sstevel@tonic-gate 	npgs = totpgs - npgs;
20430Sstevel@tonic-gate 	pp = pplist;
20440Sstevel@tonic-gate 
20450Sstevel@tonic-gate 	/*
20460Sstevel@tonic-gate 	 * Clear the free and age bits. Also if we were passed in a ppa then
20470Sstevel@tonic-gate 	 * fill it in with all the constituent pages from the large page. But
20480Sstevel@tonic-gate 	 * if we failed to allocate all the pages just free what we got.
20490Sstevel@tonic-gate 	 */
20500Sstevel@tonic-gate 	while (npgs != 0) {
20510Sstevel@tonic-gate 		ASSERT(PP_ISFREE(pp));
20520Sstevel@tonic-gate 		ASSERT(PP_ISAGED(pp));
20530Sstevel@tonic-gate 		if (ppa != NULL || err != 0) {
20540Sstevel@tonic-gate 			if (err == 0) {
20550Sstevel@tonic-gate 				VM_STAT_ADD(alloc_pages[5]);
20560Sstevel@tonic-gate 				PP_CLRFREE(pp);
20570Sstevel@tonic-gate 				PP_CLRAGED(pp);
20580Sstevel@tonic-gate 				page_sub(&pplist, pp);
20590Sstevel@tonic-gate 				*ppa++ = pp;
20600Sstevel@tonic-gate 				npgs--;
20610Sstevel@tonic-gate 			} else {
20620Sstevel@tonic-gate 				VM_STAT_ADD(alloc_pages[6]);
20630Sstevel@tonic-gate 				ASSERT(pp->p_szc != 0);
20640Sstevel@tonic-gate 				curnpgs = page_get_pagecnt(pp->p_szc);
20650Sstevel@tonic-gate 				page_list_break(&pp, &pplist, curnpgs);
20660Sstevel@tonic-gate 				page_list_add_pages(pp, 0);
20670Sstevel@tonic-gate 				page_create_putback(curnpgs);
20680Sstevel@tonic-gate 				ASSERT(npgs >= curnpgs);
20690Sstevel@tonic-gate 				npgs -= curnpgs;
20700Sstevel@tonic-gate 			}
20710Sstevel@tonic-gate 			pp = pplist;
20720Sstevel@tonic-gate 		} else {
20730Sstevel@tonic-gate 			VM_STAT_ADD(alloc_pages[7]);
20740Sstevel@tonic-gate 			PP_CLRFREE(pp);
20750Sstevel@tonic-gate 			PP_CLRAGED(pp);
20760Sstevel@tonic-gate 			pp = pp->p_next;
20770Sstevel@tonic-gate 			npgs--;
20780Sstevel@tonic-gate 		}
20790Sstevel@tonic-gate 	}
20800Sstevel@tonic-gate 	return (err);
20810Sstevel@tonic-gate }
20820Sstevel@tonic-gate 
20830Sstevel@tonic-gate /*
20840Sstevel@tonic-gate  * Get a single large page off of the freelists, and set it up for use.
20850Sstevel@tonic-gate  * Number of bytes requested must be a supported page size.
20860Sstevel@tonic-gate  *
20870Sstevel@tonic-gate  * Note that this call may fail even if there is sufficient
20880Sstevel@tonic-gate  * memory available or PG_WAIT is set, so the caller must
20890Sstevel@tonic-gate  * be willing to fallback on page_create_va(), block and retry,
20900Sstevel@tonic-gate  * or fail the requester.
20910Sstevel@tonic-gate  */
20920Sstevel@tonic-gate page_t *
20930Sstevel@tonic-gate page_create_va_large(vnode_t *vp, u_offset_t off, size_t bytes, uint_t flags,
20940Sstevel@tonic-gate     struct seg *seg, caddr_t vaddr, void *arg)
20950Sstevel@tonic-gate {
20960Sstevel@tonic-gate 	pgcnt_t		npages, pcftotal;
20970Sstevel@tonic-gate 	page_t		*pp;
20980Sstevel@tonic-gate 	page_t		*rootpp;
20990Sstevel@tonic-gate 	lgrp_t		*lgrp;
21000Sstevel@tonic-gate 	uint_t		enough;
21010Sstevel@tonic-gate 	uint_t		pcf_index;
21020Sstevel@tonic-gate 	uint_t		i;
21030Sstevel@tonic-gate 	struct pcf	*p;
21040Sstevel@tonic-gate 	struct pcf	*q;
21050Sstevel@tonic-gate 	lgrp_id_t	*lgrpid = (lgrp_id_t *)arg;
21060Sstevel@tonic-gate 
21070Sstevel@tonic-gate 	ASSERT(vp != NULL);
21080Sstevel@tonic-gate 
21090Sstevel@tonic-gate 	ASSERT((flags & ~(PG_EXCL | PG_WAIT |
21103559Smec 	    PG_NORELOC | PG_PANIC | PG_PUSHPAGE)) == 0);
21110Sstevel@tonic-gate 	/* but no others */
21120Sstevel@tonic-gate 
21130Sstevel@tonic-gate 	ASSERT((flags & PG_EXCL) == PG_EXCL);
21140Sstevel@tonic-gate 
21150Sstevel@tonic-gate 	npages = btop(bytes);
21160Sstevel@tonic-gate 
21170Sstevel@tonic-gate 	if (!kcage_on || panicstr) {
21180Sstevel@tonic-gate 		/*
21190Sstevel@tonic-gate 		 * Cage is OFF, or we are single threaded in
21200Sstevel@tonic-gate 		 * panic, so make everything a RELOC request.
21210Sstevel@tonic-gate 		 */
21220Sstevel@tonic-gate 		flags &= ~PG_NORELOC;
21230Sstevel@tonic-gate 	}
21240Sstevel@tonic-gate 
21250Sstevel@tonic-gate 	/*
21260Sstevel@tonic-gate 	 * Make sure there's adequate physical memory available.
21270Sstevel@tonic-gate 	 * Note: PG_WAIT is ignored here.
21280Sstevel@tonic-gate 	 */
21290Sstevel@tonic-gate 	if (freemem <= throttlefree + npages) {
21300Sstevel@tonic-gate 		VM_STAT_ADD(page_create_large_cnt[1]);
21310Sstevel@tonic-gate 		return (NULL);
21320Sstevel@tonic-gate 	}
21330Sstevel@tonic-gate 
21340Sstevel@tonic-gate 	/*
21350Sstevel@tonic-gate 	 * If cage is on, dampen draw from cage when available
21360Sstevel@tonic-gate 	 * cage space is low.
21370Sstevel@tonic-gate 	 */
21380Sstevel@tonic-gate 	if ((flags & (PG_NORELOC | PG_WAIT)) ==  (PG_NORELOC | PG_WAIT) &&
21390Sstevel@tonic-gate 	    kcage_freemem < kcage_throttlefree + npages) {
21400Sstevel@tonic-gate 
21410Sstevel@tonic-gate 		/*
21420Sstevel@tonic-gate 		 * The cage is on, the caller wants PG_NORELOC
21430Sstevel@tonic-gate 		 * pages and available cage memory is very low.
21440Sstevel@tonic-gate 		 * Call kcage_create_throttle() to attempt to
21450Sstevel@tonic-gate 		 * control demand on the cage.
21460Sstevel@tonic-gate 		 */
21470Sstevel@tonic-gate 		if (kcage_create_throttle(npages, flags) == KCT_FAILURE) {
21480Sstevel@tonic-gate 			VM_STAT_ADD(page_create_large_cnt[2]);
21490Sstevel@tonic-gate 			return (NULL);
21500Sstevel@tonic-gate 		}
21510Sstevel@tonic-gate 	}
21520Sstevel@tonic-gate 
21530Sstevel@tonic-gate 	enough = 0;
21540Sstevel@tonic-gate 	pcf_index = PCF_INDEX();
21550Sstevel@tonic-gate 	p = &pcf[pcf_index];
21560Sstevel@tonic-gate 	q = &pcf[PCF_FANOUT];
21570Sstevel@tonic-gate 	for (pcftotal = 0, i = 0; i < PCF_FANOUT; i++) {
21580Sstevel@tonic-gate 		if (p->pcf_count > npages) {
21590Sstevel@tonic-gate 			/*
21600Sstevel@tonic-gate 			 * a good one to try.
21610Sstevel@tonic-gate 			 */
21620Sstevel@tonic-gate 			mutex_enter(&p->pcf_lock);
21630Sstevel@tonic-gate 			if (p->pcf_count > npages) {
21640Sstevel@tonic-gate 				p->pcf_count -= (uint_t)npages;
21650Sstevel@tonic-gate 				/*
21660Sstevel@tonic-gate 				 * freemem is not protected by any lock.
21670Sstevel@tonic-gate 				 * Thus, we cannot have any assertion
21680Sstevel@tonic-gate 				 * containing freemem here.
21690Sstevel@tonic-gate 				 */
21700Sstevel@tonic-gate 				freemem -= npages;
21710Sstevel@tonic-gate 				enough = 1;
21720Sstevel@tonic-gate 				mutex_exit(&p->pcf_lock);
21730Sstevel@tonic-gate 				break;
21740Sstevel@tonic-gate 			}
21750Sstevel@tonic-gate 			mutex_exit(&p->pcf_lock);
21760Sstevel@tonic-gate 		}
21770Sstevel@tonic-gate 		pcftotal += p->pcf_count;
21780Sstevel@tonic-gate 		p++;
21790Sstevel@tonic-gate 		if (p >= q) {
21800Sstevel@tonic-gate 			p = pcf;
21810Sstevel@tonic-gate 		}
21820Sstevel@tonic-gate 	}
21830Sstevel@tonic-gate 
21840Sstevel@tonic-gate 	if (!enough) {
21850Sstevel@tonic-gate 		/* If there isn't enough memory available, give up. */
21860Sstevel@tonic-gate 		if (pcftotal < npages) {
21870Sstevel@tonic-gate 			VM_STAT_ADD(page_create_large_cnt[3]);
21880Sstevel@tonic-gate 			return (NULL);
21890Sstevel@tonic-gate 		}
21900Sstevel@tonic-gate 
21910Sstevel@tonic-gate 		/* try to collect pages from several pcf bins */
21920Sstevel@tonic-gate 		for (p = pcf, pcftotal = 0, i = 0; i < PCF_FANOUT; i++) {
21930Sstevel@tonic-gate 			mutex_enter(&p->pcf_lock);
21940Sstevel@tonic-gate 			pcftotal += p->pcf_count;
21950Sstevel@tonic-gate 			if (pcftotal >= npages) {
21960Sstevel@tonic-gate 				/*
21970Sstevel@tonic-gate 				 * Wow!  There are enough pages laying around
21980Sstevel@tonic-gate 				 * to satisfy the request.  Do the accounting,
21990Sstevel@tonic-gate 				 * drop the locks we acquired, and go back.
22000Sstevel@tonic-gate 				 *
22010Sstevel@tonic-gate 				 * freemem is not protected by any lock. So,
22020Sstevel@tonic-gate 				 * we cannot have any assertion containing
22030Sstevel@tonic-gate 				 * freemem.
22040Sstevel@tonic-gate 				 */
22050Sstevel@tonic-gate 				pgcnt_t	tpages = npages;
22060Sstevel@tonic-gate 				freemem -= npages;
22070Sstevel@tonic-gate 				while (p >= pcf) {
22080Sstevel@tonic-gate 					if (p->pcf_count <= tpages) {
22090Sstevel@tonic-gate 						tpages -= p->pcf_count;
22100Sstevel@tonic-gate 						p->pcf_count = 0;
22110Sstevel@tonic-gate 					} else {
22120Sstevel@tonic-gate 						p->pcf_count -= (uint_t)tpages;
22130Sstevel@tonic-gate 						tpages = 0;
22140Sstevel@tonic-gate 					}
22150Sstevel@tonic-gate 					mutex_exit(&p->pcf_lock);
22160Sstevel@tonic-gate 					p--;
22170Sstevel@tonic-gate 				}
22180Sstevel@tonic-gate 				ASSERT(tpages == 0);
22190Sstevel@tonic-gate 				break;
22200Sstevel@tonic-gate 			}
22210Sstevel@tonic-gate 			p++;
22220Sstevel@tonic-gate 		}
22230Sstevel@tonic-gate 		if (i == PCF_FANOUT) {
22240Sstevel@tonic-gate 			/* failed to collect pages - release the locks */
22250Sstevel@tonic-gate 			while (--p >= pcf) {
22260Sstevel@tonic-gate 				mutex_exit(&p->pcf_lock);
22270Sstevel@tonic-gate 			}
22280Sstevel@tonic-gate 			VM_STAT_ADD(page_create_large_cnt[4]);
22290Sstevel@tonic-gate 			return (NULL);
22300Sstevel@tonic-gate 		}
22310Sstevel@tonic-gate 	}
22320Sstevel@tonic-gate 
22330Sstevel@tonic-gate 	/*
22340Sstevel@tonic-gate 	 * This is where this function behaves fundamentally differently
22350Sstevel@tonic-gate 	 * than page_create_va(); since we're intending to map the page
22360Sstevel@tonic-gate 	 * with a single TTE, we have to get it as a physically contiguous
22370Sstevel@tonic-gate 	 * hardware pagesize chunk.  If we can't, we fail.
22380Sstevel@tonic-gate 	 */
22390Sstevel@tonic-gate 	if (lgrpid != NULL && *lgrpid >= 0 && *lgrpid <= lgrp_alloc_max &&
22403559Smec 	    LGRP_EXISTS(lgrp_table[*lgrpid]))
22410Sstevel@tonic-gate 		lgrp = lgrp_table[*lgrpid];
22420Sstevel@tonic-gate 	else
22430Sstevel@tonic-gate 		lgrp = lgrp_mem_choose(seg, vaddr, bytes);
22440Sstevel@tonic-gate 
22450Sstevel@tonic-gate 	if ((rootpp = page_get_freelist(&kvp, off, seg, vaddr,
22460Sstevel@tonic-gate 	    bytes, flags & ~PG_MATCH_COLOR, lgrp)) == NULL) {
22470Sstevel@tonic-gate 		page_create_putback(npages);
22480Sstevel@tonic-gate 		VM_STAT_ADD(page_create_large_cnt[5]);
22490Sstevel@tonic-gate 		return (NULL);
22500Sstevel@tonic-gate 	}
22510Sstevel@tonic-gate 
22520Sstevel@tonic-gate 	/*
22530Sstevel@tonic-gate 	 * if we got the page with the wrong mtype give it back this is a
22540Sstevel@tonic-gate 	 * workaround for CR 6249718. When CR 6249718 is fixed we never get
22550Sstevel@tonic-gate 	 * inside "if" and the workaround becomes just a nop
22560Sstevel@tonic-gate 	 */
22570Sstevel@tonic-gate 	if (kcage_on && (flags & PG_NORELOC) && !PP_ISNORELOC(rootpp)) {
22580Sstevel@tonic-gate 		page_list_add_pages(rootpp, 0);
22590Sstevel@tonic-gate 		page_create_putback(npages);
22600Sstevel@tonic-gate 		VM_STAT_ADD(page_create_large_cnt[6]);
22610Sstevel@tonic-gate 		return (NULL);
22620Sstevel@tonic-gate 	}
22630Sstevel@tonic-gate 
22640Sstevel@tonic-gate 	/*
22650Sstevel@tonic-gate 	 * If satisfying this request has left us with too little
22660Sstevel@tonic-gate 	 * memory, start the wheels turning to get some back.  The
22670Sstevel@tonic-gate 	 * first clause of the test prevents waking up the pageout
22680Sstevel@tonic-gate 	 * daemon in situations where it would decide that there's
22690Sstevel@tonic-gate 	 * nothing to do.
22700Sstevel@tonic-gate 	 */
22710Sstevel@tonic-gate 	if (nscan < desscan && freemem < minfree) {
22720Sstevel@tonic-gate 		TRACE_1(TR_FAC_VM, TR_PAGEOUT_CV_SIGNAL,
22730Sstevel@tonic-gate 		    "pageout_cv_signal:freemem %ld", freemem);
22740Sstevel@tonic-gate 		cv_signal(&proc_pageout->p_cv);
22750Sstevel@tonic-gate 	}
22760Sstevel@tonic-gate 
22770Sstevel@tonic-gate 	pp = rootpp;
22780Sstevel@tonic-gate 	while (npages--) {
22790Sstevel@tonic-gate 		ASSERT(PAGE_EXCL(pp));
22800Sstevel@tonic-gate 		ASSERT(pp->p_vnode == NULL);
22810Sstevel@tonic-gate 		ASSERT(!hat_page_is_mapped(pp));
22820Sstevel@tonic-gate 		PP_CLRFREE(pp);
22830Sstevel@tonic-gate 		PP_CLRAGED(pp);
22840Sstevel@tonic-gate 		if (!page_hashin(pp, vp, off, NULL))
22850Sstevel@tonic-gate 			panic("page_create_large: hashin failed: page %p",
22860Sstevel@tonic-gate 			    (void *)pp);
22870Sstevel@tonic-gate 		page_io_lock(pp);
22880Sstevel@tonic-gate 		off += PAGESIZE;
22890Sstevel@tonic-gate 		pp = pp->p_next;
22900Sstevel@tonic-gate 	}
22910Sstevel@tonic-gate 
22920Sstevel@tonic-gate 	VM_STAT_ADD(page_create_large_cnt[0]);
22930Sstevel@tonic-gate 	return (rootpp);
22940Sstevel@tonic-gate }
22950Sstevel@tonic-gate 
22960Sstevel@tonic-gate page_t *
22970Sstevel@tonic-gate page_create_va(vnode_t *vp, u_offset_t off, size_t bytes, uint_t flags,
22980Sstevel@tonic-gate     struct seg *seg, caddr_t vaddr)
22990Sstevel@tonic-gate {
23000Sstevel@tonic-gate 	page_t		*plist = NULL;
23010Sstevel@tonic-gate 	pgcnt_t		npages;
23020Sstevel@tonic-gate 	pgcnt_t		found_on_free = 0;
23030Sstevel@tonic-gate 	pgcnt_t		pages_req;
23040Sstevel@tonic-gate 	page_t		*npp = NULL;
23050Sstevel@tonic-gate 	uint_t		enough;
23060Sstevel@tonic-gate 	uint_t		i;
23070Sstevel@tonic-gate 	uint_t		pcf_index;
23080Sstevel@tonic-gate 	struct pcf	*p;
23090Sstevel@tonic-gate 	struct pcf	*q;
23100Sstevel@tonic-gate 	lgrp_t		*lgrp;
23110Sstevel@tonic-gate 
23120Sstevel@tonic-gate 	TRACE_4(TR_FAC_VM, TR_PAGE_CREATE_START,
23133559Smec 	    "page_create_start:vp %p off %llx bytes %lu flags %x",
23143559Smec 	    vp, off, bytes, flags);
23150Sstevel@tonic-gate 
23160Sstevel@tonic-gate 	ASSERT(bytes != 0 && vp != NULL);
23170Sstevel@tonic-gate 
23180Sstevel@tonic-gate 	if ((flags & PG_EXCL) == 0 && (flags & PG_WAIT) == 0) {
23190Sstevel@tonic-gate 		panic("page_create: invalid flags");
23200Sstevel@tonic-gate 		/*NOTREACHED*/
23210Sstevel@tonic-gate 	}
23220Sstevel@tonic-gate 	ASSERT((flags & ~(PG_EXCL | PG_WAIT |
23230Sstevel@tonic-gate 	    PG_NORELOC | PG_PANIC | PG_PUSHPAGE)) == 0);
23240Sstevel@tonic-gate 	    /* but no others */
23250Sstevel@tonic-gate 
23260Sstevel@tonic-gate 	pages_req = npages = btopr(bytes);
23270Sstevel@tonic-gate 	/*
23280Sstevel@tonic-gate 	 * Try to see whether request is too large to *ever* be
23290Sstevel@tonic-gate 	 * satisfied, in order to prevent deadlock.  We arbitrarily
23300Sstevel@tonic-gate 	 * decide to limit maximum size requests to max_page_get.
23310Sstevel@tonic-gate 	 */
23320Sstevel@tonic-gate 	if (npages >= max_page_get) {
23330Sstevel@tonic-gate 		if ((flags & PG_WAIT) == 0) {
23340Sstevel@tonic-gate 			TRACE_4(TR_FAC_VM, TR_PAGE_CREATE_TOOBIG,
23350Sstevel@tonic-gate 			    "page_create_toobig:vp %p off %llx npages "
23360Sstevel@tonic-gate 			    "%lu max_page_get %lu",
23370Sstevel@tonic-gate 			    vp, off, npages, max_page_get);
23380Sstevel@tonic-gate 			return (NULL);
23390Sstevel@tonic-gate 		} else {
23400Sstevel@tonic-gate 			cmn_err(CE_WARN,
23410Sstevel@tonic-gate 			    "Request for too much kernel memory "
23420Sstevel@tonic-gate 			    "(%lu bytes), will hang forever", bytes);
23430Sstevel@tonic-gate 			for (;;)
23440Sstevel@tonic-gate 				delay(1000000000);
23450Sstevel@tonic-gate 		}
23460Sstevel@tonic-gate 	}
23470Sstevel@tonic-gate 
23480Sstevel@tonic-gate 	if (!kcage_on || panicstr) {
23490Sstevel@tonic-gate 		/*
23500Sstevel@tonic-gate 		 * Cage is OFF, or we are single threaded in
23510Sstevel@tonic-gate 		 * panic, so make everything a RELOC request.
23520Sstevel@tonic-gate 		 */
23530Sstevel@tonic-gate 		flags &= ~PG_NORELOC;
23540Sstevel@tonic-gate 	}
23550Sstevel@tonic-gate 
23560Sstevel@tonic-gate 	if (freemem <= throttlefree + npages)
23570Sstevel@tonic-gate 		if (!page_create_throttle(npages, flags))
23580Sstevel@tonic-gate 			return (NULL);
23590Sstevel@tonic-gate 
23600Sstevel@tonic-gate 	/*
23610Sstevel@tonic-gate 	 * If cage is on, dampen draw from cage when available
23620Sstevel@tonic-gate 	 * cage space is low.
23630Sstevel@tonic-gate 	 */
23640Sstevel@tonic-gate 	if ((flags & PG_NORELOC) &&
23653559Smec 	    kcage_freemem < kcage_throttlefree + npages) {
23660Sstevel@tonic-gate 
23670Sstevel@tonic-gate 		/*
23680Sstevel@tonic-gate 		 * The cage is on, the caller wants PG_NORELOC
23690Sstevel@tonic-gate 		 * pages and available cage memory is very low.
23700Sstevel@tonic-gate 		 * Call kcage_create_throttle() to attempt to
23710Sstevel@tonic-gate 		 * control demand on the cage.
23720Sstevel@tonic-gate 		 */
23730Sstevel@tonic-gate 		if (kcage_create_throttle(npages, flags) == KCT_FAILURE)
23740Sstevel@tonic-gate 			return (NULL);
23750Sstevel@tonic-gate 	}
23760Sstevel@tonic-gate 
23770Sstevel@tonic-gate 	VM_STAT_ADD(page_create_cnt[0]);
23780Sstevel@tonic-gate 
23790Sstevel@tonic-gate 	enough = 0;
23800Sstevel@tonic-gate 	pcf_index = PCF_INDEX();
23810Sstevel@tonic-gate 
23820Sstevel@tonic-gate 	p = &pcf[pcf_index];
23830Sstevel@tonic-gate 	q = &pcf[PCF_FANOUT];
23840Sstevel@tonic-gate 	for (i = 0; i < PCF_FANOUT; i++) {
23850Sstevel@tonic-gate 		if (p->pcf_count > npages) {
23860Sstevel@tonic-gate 			/*
23870Sstevel@tonic-gate 			 * a good one to try.
23880Sstevel@tonic-gate 			 */
23890Sstevel@tonic-gate 			mutex_enter(&p->pcf_lock);
23900Sstevel@tonic-gate 			if (p->pcf_count > npages) {
23910Sstevel@tonic-gate 				p->pcf_count -= (uint_t)npages;
23920Sstevel@tonic-gate 				/*
23930Sstevel@tonic-gate 				 * freemem is not protected by any lock.
23940Sstevel@tonic-gate 				 * Thus, we cannot have any assertion
23950Sstevel@tonic-gate 				 * containing freemem here.
23960Sstevel@tonic-gate 				 */
23970Sstevel@tonic-gate 				freemem -= npages;
23980Sstevel@tonic-gate 				enough = 1;
23990Sstevel@tonic-gate 				mutex_exit(&p->pcf_lock);
24000Sstevel@tonic-gate 				break;
24010Sstevel@tonic-gate 			}
24020Sstevel@tonic-gate 			mutex_exit(&p->pcf_lock);
24030Sstevel@tonic-gate 		}
24040Sstevel@tonic-gate 		p++;
24050Sstevel@tonic-gate 		if (p >= q) {
24060Sstevel@tonic-gate 			p = pcf;
24070Sstevel@tonic-gate 		}
24080Sstevel@tonic-gate 	}
24090Sstevel@tonic-gate 
24100Sstevel@tonic-gate 	if (!enough) {
24110Sstevel@tonic-gate 		/*
24120Sstevel@tonic-gate 		 * Have to look harder.  If npages is greater than
2413*5331Samw 		 * one, then we might have to coalesce the counters.
24140Sstevel@tonic-gate 		 *
24150Sstevel@tonic-gate 		 * Go wait.  We come back having accounted
24160Sstevel@tonic-gate 		 * for the memory.
24170Sstevel@tonic-gate 		 */
24180Sstevel@tonic-gate 		VM_STAT_ADD(page_create_cnt[1]);
24190Sstevel@tonic-gate 		if (!page_create_wait(npages, flags)) {
24200Sstevel@tonic-gate 			VM_STAT_ADD(page_create_cnt[2]);
24210Sstevel@tonic-gate 			return (NULL);
24220Sstevel@tonic-gate 		}
24230Sstevel@tonic-gate 	}
24240Sstevel@tonic-gate 
24250Sstevel@tonic-gate 	TRACE_2(TR_FAC_VM, TR_PAGE_CREATE_SUCCESS,
24263559Smec 	    "page_create_success:vp %p off %llx", vp, off);
24270Sstevel@tonic-gate 
24280Sstevel@tonic-gate 	/*
24290Sstevel@tonic-gate 	 * If satisfying this request has left us with too little
24300Sstevel@tonic-gate 	 * memory, start the wheels turning to get some back.  The
24310Sstevel@tonic-gate 	 * first clause of the test prevents waking up the pageout
24320Sstevel@tonic-gate 	 * daemon in situations where it would decide that there's
24330Sstevel@tonic-gate 	 * nothing to do.
24340Sstevel@tonic-gate 	 */
24350Sstevel@tonic-gate 	if (nscan < desscan && freemem < minfree) {
24360Sstevel@tonic-gate 		TRACE_1(TR_FAC_VM, TR_PAGEOUT_CV_SIGNAL,
24373559Smec 		    "pageout_cv_signal:freemem %ld", freemem);
24380Sstevel@tonic-gate 		cv_signal(&proc_pageout->p_cv);
24390Sstevel@tonic-gate 	}
24400Sstevel@tonic-gate 
24410Sstevel@tonic-gate 	/*
24420Sstevel@tonic-gate 	 * Loop around collecting the requested number of pages.
24430Sstevel@tonic-gate 	 * Most of the time, we have to `create' a new page. With
24440Sstevel@tonic-gate 	 * this in mind, pull the page off the free list before
24450Sstevel@tonic-gate 	 * getting the hash lock.  This will minimize the hash
24460Sstevel@tonic-gate 	 * lock hold time, nesting, and the like.  If it turns
24470Sstevel@tonic-gate 	 * out we don't need the page, we put it back at the end.
24480Sstevel@tonic-gate 	 */
24490Sstevel@tonic-gate 	while (npages--) {
24500Sstevel@tonic-gate 		page_t		*pp;
24510Sstevel@tonic-gate 		kmutex_t	*phm = NULL;
24520Sstevel@tonic-gate 		ulong_t		index;
24530Sstevel@tonic-gate 
24540Sstevel@tonic-gate 		index = PAGE_HASH_FUNC(vp, off);
24550Sstevel@tonic-gate top:
24560Sstevel@tonic-gate 		ASSERT(phm == NULL);
24570Sstevel@tonic-gate 		ASSERT(index == PAGE_HASH_FUNC(vp, off));
24580Sstevel@tonic-gate 		ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
24590Sstevel@tonic-gate 
24600Sstevel@tonic-gate 		if (npp == NULL) {
24610Sstevel@tonic-gate 			/*
24620Sstevel@tonic-gate 			 * Try to get a page from the freelist (ie,
24630Sstevel@tonic-gate 			 * a page with no [vp, off] tag).  If that
24640Sstevel@tonic-gate 			 * fails, use the cachelist.
24650Sstevel@tonic-gate 			 *
24660Sstevel@tonic-gate 			 * During the first attempt at both the free
24670Sstevel@tonic-gate 			 * and cache lists we try for the correct color.
24680Sstevel@tonic-gate 			 */
24690Sstevel@tonic-gate 			/*
24700Sstevel@tonic-gate 			 * XXXX-how do we deal with virtual indexed
24710Sstevel@tonic-gate 			 * caches and and colors?
24720Sstevel@tonic-gate 			 */
24730Sstevel@tonic-gate 			VM_STAT_ADD(page_create_cnt[4]);
24740Sstevel@tonic-gate 			/*
24750Sstevel@tonic-gate 			 * Get lgroup to allocate next page of shared memory
24760Sstevel@tonic-gate 			 * from and use it to specify where to allocate
24770Sstevel@tonic-gate 			 * the physical memory
24780Sstevel@tonic-gate 			 */
24790Sstevel@tonic-gate 			lgrp = lgrp_mem_choose(seg, vaddr, PAGESIZE);
24800Sstevel@tonic-gate 			npp = page_get_freelist(vp, off, seg, vaddr, PAGESIZE,
24810Sstevel@tonic-gate 			    flags | PG_MATCH_COLOR, lgrp);
24820Sstevel@tonic-gate 			if (npp == NULL) {
24830Sstevel@tonic-gate 				npp = page_get_cachelist(vp, off, seg,
24840Sstevel@tonic-gate 				    vaddr, flags | PG_MATCH_COLOR, lgrp);
24850Sstevel@tonic-gate 				if (npp == NULL) {
24860Sstevel@tonic-gate 					npp = page_create_get_something(vp,
24870Sstevel@tonic-gate 					    off, seg, vaddr,
24880Sstevel@tonic-gate 					    flags & ~PG_MATCH_COLOR);
24890Sstevel@tonic-gate 				}
24900Sstevel@tonic-gate 
24910Sstevel@tonic-gate 				if (PP_ISAGED(npp) == 0) {
24920Sstevel@tonic-gate 					/*
24930Sstevel@tonic-gate 					 * Since this page came from the
24940Sstevel@tonic-gate 					 * cachelist, we must destroy the
24950Sstevel@tonic-gate 					 * old vnode association.
24960Sstevel@tonic-gate 					 */
24970Sstevel@tonic-gate 					page_hashout(npp, NULL);
24980Sstevel@tonic-gate 				}
24990Sstevel@tonic-gate 			}
25000Sstevel@tonic-gate 		}
25010Sstevel@tonic-gate 
25020Sstevel@tonic-gate 		/*
25030Sstevel@tonic-gate 		 * We own this page!
25040Sstevel@tonic-gate 		 */
25050Sstevel@tonic-gate 		ASSERT(PAGE_EXCL(npp));
25060Sstevel@tonic-gate 		ASSERT(npp->p_vnode == NULL);
25070Sstevel@tonic-gate 		ASSERT(!hat_page_is_mapped(npp));
25080Sstevel@tonic-gate 		PP_CLRFREE(npp);
25090Sstevel@tonic-gate 		PP_CLRAGED(npp);
25100Sstevel@tonic-gate 
25110Sstevel@tonic-gate 		/*
25120Sstevel@tonic-gate 		 * Here we have a page in our hot little mits and are
25130Sstevel@tonic-gate 		 * just waiting to stuff it on the appropriate lists.
25140Sstevel@tonic-gate 		 * Get the mutex and check to see if it really does
25150Sstevel@tonic-gate 		 * not exist.
25160Sstevel@tonic-gate 		 */
25170Sstevel@tonic-gate 		phm = PAGE_HASH_MUTEX(index);
25180Sstevel@tonic-gate 		mutex_enter(phm);
25190Sstevel@tonic-gate 		PAGE_HASH_SEARCH(index, pp, vp, off);
25200Sstevel@tonic-gate 		if (pp == NULL) {
25210Sstevel@tonic-gate 			VM_STAT_ADD(page_create_new);
25220Sstevel@tonic-gate 			pp = npp;
25230Sstevel@tonic-gate 			npp = NULL;
25240Sstevel@tonic-gate 			if (!page_hashin(pp, vp, off, phm)) {
25250Sstevel@tonic-gate 				/*
25260Sstevel@tonic-gate 				 * Since we hold the page hash mutex and
25270Sstevel@tonic-gate 				 * just searched for this page, page_hashin
25280Sstevel@tonic-gate 				 * had better not fail.  If it does, that
25290Sstevel@tonic-gate 				 * means somethread did not follow the
25300Sstevel@tonic-gate 				 * page hash mutex rules.  Panic now and
25310Sstevel@tonic-gate 				 * get it over with.  As usual, go down
25320Sstevel@tonic-gate 				 * holding all the locks.
25330Sstevel@tonic-gate 				 */
25340Sstevel@tonic-gate 				ASSERT(MUTEX_HELD(phm));
25350Sstevel@tonic-gate 				panic("page_create: "
25360Sstevel@tonic-gate 				    "hashin failed %p %p %llx %p",
25370Sstevel@tonic-gate 				    (void *)pp, (void *)vp, off, (void *)phm);
25380Sstevel@tonic-gate 				/*NOTREACHED*/
25390Sstevel@tonic-gate 			}
25400Sstevel@tonic-gate 			ASSERT(MUTEX_HELD(phm));
25410Sstevel@tonic-gate 			mutex_exit(phm);
25420Sstevel@tonic-gate 			phm = NULL;
25430Sstevel@tonic-gate 
25440Sstevel@tonic-gate 			/*
25450Sstevel@tonic-gate 			 * Hat layer locking need not be done to set
25460Sstevel@tonic-gate 			 * the following bits since the page is not hashed
25470Sstevel@tonic-gate 			 * and was on the free list (i.e., had no mappings).
25480Sstevel@tonic-gate 			 *
25490Sstevel@tonic-gate 			 * Set the reference bit to protect
25500Sstevel@tonic-gate 			 * against immediate pageout
25510Sstevel@tonic-gate 			 *
25520Sstevel@tonic-gate 			 * XXXmh modify freelist code to set reference
25530Sstevel@tonic-gate 			 * bit so we don't have to do it here.
25540Sstevel@tonic-gate 			 */
25550Sstevel@tonic-gate 			page_set_props(pp, P_REF);
25560Sstevel@tonic-gate 			found_on_free++;
25570Sstevel@tonic-gate 		} else {
25580Sstevel@tonic-gate 			VM_STAT_ADD(page_create_exists);
25590Sstevel@tonic-gate 			if (flags & PG_EXCL) {
25600Sstevel@tonic-gate 				/*
25610Sstevel@tonic-gate 				 * Found an existing page, and the caller
25620Sstevel@tonic-gate 				 * wanted all new pages.  Undo all of the work
25630Sstevel@tonic-gate 				 * we have done.
25640Sstevel@tonic-gate 				 */
25650Sstevel@tonic-gate 				mutex_exit(phm);
25660Sstevel@tonic-gate 				phm = NULL;
25670Sstevel@tonic-gate 				while (plist != NULL) {
25680Sstevel@tonic-gate 					pp = plist;
25690Sstevel@tonic-gate 					page_sub(&plist, pp);
25700Sstevel@tonic-gate 					page_io_unlock(pp);
25710Sstevel@tonic-gate 					/* large pages should not end up here */
25720Sstevel@tonic-gate 					ASSERT(pp->p_szc == 0);
25730Sstevel@tonic-gate 					/*LINTED: constant in conditional ctx*/
25740Sstevel@tonic-gate 					VN_DISPOSE(pp, B_INVAL, 0, kcred);
25750Sstevel@tonic-gate 				}
25760Sstevel@tonic-gate 				VM_STAT_ADD(page_create_found_one);
25770Sstevel@tonic-gate 				goto fail;
25780Sstevel@tonic-gate 			}
25790Sstevel@tonic-gate 			ASSERT(flags & PG_WAIT);
25800Sstevel@tonic-gate 			if (!page_lock(pp, SE_EXCL, phm, P_NO_RECLAIM)) {
25810Sstevel@tonic-gate 				/*
25820Sstevel@tonic-gate 				 * Start all over again if we blocked trying
25830Sstevel@tonic-gate 				 * to lock the page.
25840Sstevel@tonic-gate 				 */
25850Sstevel@tonic-gate 				mutex_exit(phm);
25860Sstevel@tonic-gate 				VM_STAT_ADD(page_create_page_lock_failed);
25870Sstevel@tonic-gate 				phm = NULL;
25880Sstevel@tonic-gate 				goto top;
25890Sstevel@tonic-gate 			}
25900Sstevel@tonic-gate 			mutex_exit(phm);
25910Sstevel@tonic-gate 			phm = NULL;
25920Sstevel@tonic-gate 
25930Sstevel@tonic-gate 			if (PP_ISFREE(pp)) {
25940Sstevel@tonic-gate 				ASSERT(PP_ISAGED(pp) == 0);
25950Sstevel@tonic-gate 				VM_STAT_ADD(pagecnt.pc_get_cache);
25960Sstevel@tonic-gate 				page_list_sub(pp, PG_CACHE_LIST);
25970Sstevel@tonic-gate 				PP_CLRFREE(pp);
25980Sstevel@tonic-gate 				found_on_free++;
25990Sstevel@tonic-gate 			}
26000Sstevel@tonic-gate 		}
26010Sstevel@tonic-gate 
26020Sstevel@tonic-gate 		/*
26030Sstevel@tonic-gate 		 * Got a page!  It is locked.  Acquire the i/o
26040Sstevel@tonic-gate 		 * lock since we are going to use the p_next and
26050Sstevel@tonic-gate 		 * p_prev fields to link the requested pages together.
26060Sstevel@tonic-gate 		 */
26070Sstevel@tonic-gate 		page_io_lock(pp);
26080Sstevel@tonic-gate 		page_add(&plist, pp);
26090Sstevel@tonic-gate 		plist = plist->p_next;
26100Sstevel@tonic-gate 		off += PAGESIZE;
26110Sstevel@tonic-gate 		vaddr += PAGESIZE;
26120Sstevel@tonic-gate 	}
26130Sstevel@tonic-gate 
26140Sstevel@tonic-gate 	ASSERT((flags & PG_EXCL) ? (found_on_free == pages_req) : 1);
26150Sstevel@tonic-gate fail:
26160Sstevel@tonic-gate 	if (npp != NULL) {
26170Sstevel@tonic-gate 		/*
26180Sstevel@tonic-gate 		 * Did not need this page after all.
26190Sstevel@tonic-gate 		 * Put it back on the free list.
26200Sstevel@tonic-gate 		 */
26210Sstevel@tonic-gate 		VM_STAT_ADD(page_create_putbacks);
26220Sstevel@tonic-gate 		PP_SETFREE(npp);
26230Sstevel@tonic-gate 		PP_SETAGED(npp);
26240Sstevel@tonic-gate 		npp->p_offset = (u_offset_t)-1;
26250Sstevel@tonic-gate 		page_list_add(npp, PG_FREE_LIST | PG_LIST_TAIL);
26260Sstevel@tonic-gate 		page_unlock(npp);
26270Sstevel@tonic-gate 
26280Sstevel@tonic-gate 	}
26290Sstevel@tonic-gate 
26300Sstevel@tonic-gate 	ASSERT(pages_req >= found_on_free);
26310Sstevel@tonic-gate 
26320Sstevel@tonic-gate 	{
26330Sstevel@tonic-gate 		uint_t overshoot = (uint_t)(pages_req - found_on_free);
26340Sstevel@tonic-gate 
26350Sstevel@tonic-gate 		if (overshoot) {
26360Sstevel@tonic-gate 			VM_STAT_ADD(page_create_overshoot);
26370Sstevel@tonic-gate 			p = &pcf[pcf_index];
26380Sstevel@tonic-gate 			mutex_enter(&p->pcf_lock);
26390Sstevel@tonic-gate 			if (p->pcf_block) {
26400Sstevel@tonic-gate 				p->pcf_reserve += overshoot;
26410Sstevel@tonic-gate 			} else {
26420Sstevel@tonic-gate 				p->pcf_count += overshoot;
26430Sstevel@tonic-gate 				if (p->pcf_wait) {
26440Sstevel@tonic-gate 					mutex_enter(&new_freemem_lock);
26450Sstevel@tonic-gate 					if (freemem_wait) {
26460Sstevel@tonic-gate 						cv_signal(&freemem_cv);
26470Sstevel@tonic-gate 						p->pcf_wait--;
26480Sstevel@tonic-gate 					} else {
26490Sstevel@tonic-gate 						p->pcf_wait = 0;
26500Sstevel@tonic-gate 					}
26510Sstevel@tonic-gate 					mutex_exit(&new_freemem_lock);
26520Sstevel@tonic-gate 				}
26530Sstevel@tonic-gate 			}
26540Sstevel@tonic-gate 			mutex_exit(&p->pcf_lock);
26550Sstevel@tonic-gate 			/* freemem is approximate, so this test OK */
26560Sstevel@tonic-gate 			if (!p->pcf_block)
26570Sstevel@tonic-gate 				freemem += overshoot;
26580Sstevel@tonic-gate 		}
26590Sstevel@tonic-gate 	}
26600Sstevel@tonic-gate 
26610Sstevel@tonic-gate 	return (plist);
26620Sstevel@tonic-gate }
26630Sstevel@tonic-gate 
26640Sstevel@tonic-gate /*
26650Sstevel@tonic-gate  * One or more constituent pages of this large page has been marked
26660Sstevel@tonic-gate  * toxic. Simply demote the large page to PAGESIZE pages and let
26670Sstevel@tonic-gate  * page_free() handle it. This routine should only be called by
26680Sstevel@tonic-gate  * large page free routines (page_free_pages() and page_destroy_pages().
26690Sstevel@tonic-gate  * All pages are locked SE_EXCL and have already been marked free.
26700Sstevel@tonic-gate  */
26710Sstevel@tonic-gate static void
26720Sstevel@tonic-gate page_free_toxic_pages(page_t *rootpp)
26730Sstevel@tonic-gate {
26740Sstevel@tonic-gate 	page_t	*tpp;
26750Sstevel@tonic-gate 	pgcnt_t	i, pgcnt = page_get_pagecnt(rootpp->p_szc);
26760Sstevel@tonic-gate 	uint_t	szc = rootpp->p_szc;
26770Sstevel@tonic-gate 
26780Sstevel@tonic-gate 	for (i = 0, tpp = rootpp; i < pgcnt; i++, tpp = tpp->p_next) {
26790Sstevel@tonic-gate 		ASSERT(tpp->p_szc == szc);
26800Sstevel@tonic-gate 		ASSERT((PAGE_EXCL(tpp) &&
26810Sstevel@tonic-gate 		    !page_iolock_assert(tpp)) || panicstr);
26820Sstevel@tonic-gate 		tpp->p_szc = 0;
26830Sstevel@tonic-gate 	}
26840Sstevel@tonic-gate 
26850Sstevel@tonic-gate 	while (rootpp != NULL) {
26860Sstevel@tonic-gate 		tpp = rootpp;
26870Sstevel@tonic-gate 		page_sub(&rootpp, tpp);
26880Sstevel@tonic-gate 		ASSERT(PP_ISFREE(tpp));
26890Sstevel@tonic-gate 		PP_CLRFREE(tpp);
26900Sstevel@tonic-gate 		page_free(tpp, 1);
26910Sstevel@tonic-gate 	}
26920Sstevel@tonic-gate }
26930Sstevel@tonic-gate 
26940Sstevel@tonic-gate /*
26950Sstevel@tonic-gate  * Put page on the "free" list.
26960Sstevel@tonic-gate  * The free list is really two lists maintained by
26970Sstevel@tonic-gate  * the PSM of whatever machine we happen to be on.
26980Sstevel@tonic-gate  */
26990Sstevel@tonic-gate void
27000Sstevel@tonic-gate page_free(page_t *pp, int dontneed)
27010Sstevel@tonic-gate {
27020Sstevel@tonic-gate 	struct pcf	*p;
27030Sstevel@tonic-gate 	uint_t		pcf_index;
27040Sstevel@tonic-gate 
27050Sstevel@tonic-gate 	ASSERT((PAGE_EXCL(pp) &&
27060Sstevel@tonic-gate 	    !page_iolock_assert(pp)) || panicstr);
27070Sstevel@tonic-gate 
27080Sstevel@tonic-gate 	if (PP_ISFREE(pp)) {
27090Sstevel@tonic-gate 		panic("page_free: page %p is free", (void *)pp);
27100Sstevel@tonic-gate 	}
27110Sstevel@tonic-gate 
27120Sstevel@tonic-gate 	if (pp->p_szc != 0) {
27130Sstevel@tonic-gate 		if (pp->p_vnode == NULL || IS_SWAPFSVP(pp->p_vnode) ||
27143290Sjohansen 		    PP_ISKAS(pp)) {
27150Sstevel@tonic-gate 			panic("page_free: anon or kernel "
27160Sstevel@tonic-gate 			    "or no vnode large page %p", (void *)pp);
27170Sstevel@tonic-gate 		}
27180Sstevel@tonic-gate 		page_demote_vp_pages(pp);
27190Sstevel@tonic-gate 		ASSERT(pp->p_szc == 0);
27200Sstevel@tonic-gate 	}
27210Sstevel@tonic-gate 
27220Sstevel@tonic-gate 	/*
27230Sstevel@tonic-gate 	 * The page_struct_lock need not be acquired to examine these
27240Sstevel@tonic-gate 	 * fields since the page has an "exclusive" lock.
27250Sstevel@tonic-gate 	 */
27262414Saguzovsk 	if (hat_page_is_mapped(pp) || pp->p_lckcnt != 0 || pp->p_cowcnt != 0 ||
27272414Saguzovsk 	    pp->p_slckcnt != 0) {
27282414Saguzovsk 		panic("page_free pp=%p, pfn=%lx, lckcnt=%d, cowcnt=%d "
27292414Saguzovsk 		    "slckcnt = %d", pp, page_pptonum(pp), pp->p_lckcnt,
27302414Saguzovsk 		    pp->p_cowcnt, pp->p_slckcnt);
27310Sstevel@tonic-gate 		/*NOTREACHED*/
27320Sstevel@tonic-gate 	}
27330Sstevel@tonic-gate 
27340Sstevel@tonic-gate 	ASSERT(!hat_page_getshare(pp));
27350Sstevel@tonic-gate 
27360Sstevel@tonic-gate 	PP_SETFREE(pp);
27370Sstevel@tonic-gate 	ASSERT(pp->p_vnode == NULL || !IS_VMODSORT(pp->p_vnode) ||
27380Sstevel@tonic-gate 	    !hat_ismod(pp));
27390Sstevel@tonic-gate 	page_clr_all_props(pp);
27400Sstevel@tonic-gate 	ASSERT(!hat_page_getshare(pp));
27410Sstevel@tonic-gate 
27420Sstevel@tonic-gate 	/*
27430Sstevel@tonic-gate 	 * Now we add the page to the head of the free list.
27440Sstevel@tonic-gate 	 * But if this page is associated with a paged vnode
27450Sstevel@tonic-gate 	 * then we adjust the head forward so that the page is
27460Sstevel@tonic-gate 	 * effectively at the end of the list.
27470Sstevel@tonic-gate 	 */
27480Sstevel@tonic-gate 	if (pp->p_vnode == NULL) {
27490Sstevel@tonic-gate 		/*
27500Sstevel@tonic-gate 		 * Page has no identity, put it on the free list.
27510Sstevel@tonic-gate 		 */
27520Sstevel@tonic-gate 		PP_SETAGED(pp);
27530Sstevel@tonic-gate 		pp->p_offset = (u_offset_t)-1;
27540Sstevel@tonic-gate 		page_list_add(pp, PG_FREE_LIST | PG_LIST_TAIL);
27550Sstevel@tonic-gate 		VM_STAT_ADD(pagecnt.pc_free_free);
27560Sstevel@tonic-gate 		TRACE_1(TR_FAC_VM, TR_PAGE_FREE_FREE,
27570Sstevel@tonic-gate 		    "page_free_free:pp %p", pp);
27580Sstevel@tonic-gate 	} else {
27590Sstevel@tonic-gate 		PP_CLRAGED(pp);
27600Sstevel@tonic-gate 
27610Sstevel@tonic-gate 		if (!dontneed || nopageage) {
27620Sstevel@tonic-gate 			/* move it to the tail of the list */
27630Sstevel@tonic-gate 			page_list_add(pp, PG_CACHE_LIST | PG_LIST_TAIL);
27640Sstevel@tonic-gate 
27650Sstevel@tonic-gate 			VM_STAT_ADD(pagecnt.pc_free_cache);
27660Sstevel@tonic-gate 			TRACE_1(TR_FAC_VM, TR_PAGE_FREE_CACHE_TAIL,
27670Sstevel@tonic-gate 			    "page_free_cache_tail:pp %p", pp);
27680Sstevel@tonic-gate 		} else {
27690Sstevel@tonic-gate 			page_list_add(pp, PG_CACHE_LIST | PG_LIST_HEAD);
27700Sstevel@tonic-gate 
27710Sstevel@tonic-gate 			VM_STAT_ADD(pagecnt.pc_free_dontneed);
27720Sstevel@tonic-gate 			TRACE_1(TR_FAC_VM, TR_PAGE_FREE_CACHE_HEAD,
27730Sstevel@tonic-gate 			    "page_free_cache_head:pp %p", pp);
27740Sstevel@tonic-gate 		}
27750Sstevel@tonic-gate 	}
27760Sstevel@tonic-gate 	page_unlock(pp);
27770Sstevel@tonic-gate 
27780Sstevel@tonic-gate 	/*
27790Sstevel@tonic-gate 	 * Now do the `freemem' accounting.
27800Sstevel@tonic-gate 	 */
27810Sstevel@tonic-gate 	pcf_index = PCF_INDEX();
27820Sstevel@tonic-gate 	p = &pcf[pcf_index];
27830Sstevel@tonic-gate 
27840Sstevel@tonic-gate 	mutex_enter(&p->pcf_lock);
27850Sstevel@tonic-gate 	if (p->pcf_block) {
27860Sstevel@tonic-gate 		p->pcf_reserve += 1;
27870Sstevel@tonic-gate 	} else {
27880Sstevel@tonic-gate 		p->pcf_count += 1;
27890Sstevel@tonic-gate 		if (p->pcf_wait) {
27900Sstevel@tonic-gate 			mutex_enter(&new_freemem_lock);
27910Sstevel@tonic-gate 			/*
27920Sstevel@tonic-gate 			 * Check to see if some other thread
27930Sstevel@tonic-gate 			 * is actually waiting.  Another bucket
27940Sstevel@tonic-gate 			 * may have woken it up by now.  If there
27950Sstevel@tonic-gate 			 * are no waiters, then set our pcf_wait
27960Sstevel@tonic-gate 			 * count to zero to avoid coming in here
27970Sstevel@tonic-gate 			 * next time.  Also, since only one page
27980Sstevel@tonic-gate 			 * was put on the free list, just wake
27990Sstevel@tonic-gate 			 * up one waiter.
28000Sstevel@tonic-gate 			 */
28010Sstevel@tonic-gate 			if (freemem_wait) {
28020Sstevel@tonic-gate 				cv_signal(&freemem_cv);
28030Sstevel@tonic-gate 				p->pcf_wait--;
28040Sstevel@tonic-gate 			} else {
28050Sstevel@tonic-gate 				p->pcf_wait = 0;
28060Sstevel@tonic-gate 			}
28070Sstevel@tonic-gate 			mutex_exit(&new_freemem_lock);
28080Sstevel@tonic-gate 		}
28090Sstevel@tonic-gate 	}
28100Sstevel@tonic-gate 	mutex_exit(&p->pcf_lock);
28110Sstevel@tonic-gate 
28120Sstevel@tonic-gate 	/* freemem is approximate, so this test OK */
28130Sstevel@tonic-gate 	if (!p->pcf_block)
28140Sstevel@tonic-gate 		freemem += 1;
28150Sstevel@tonic-gate }
28160Sstevel@tonic-gate 
28170Sstevel@tonic-gate /*
28180Sstevel@tonic-gate  * Put page on the "free" list during intial startup.
28190Sstevel@tonic-gate  * This happens during initial single threaded execution.
28200Sstevel@tonic-gate  */
28210Sstevel@tonic-gate void
28220Sstevel@tonic-gate page_free_at_startup(page_t *pp)
28230Sstevel@tonic-gate {
28240Sstevel@tonic-gate 	struct pcf	*p;
28250Sstevel@tonic-gate 	uint_t		pcf_index;
28260Sstevel@tonic-gate 
28270Sstevel@tonic-gate 	page_list_add(pp, PG_FREE_LIST | PG_LIST_HEAD | PG_LIST_ISINIT);
28280Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_free_free);
28290Sstevel@tonic-gate 
28300Sstevel@tonic-gate 	/*
28310Sstevel@tonic-gate 	 * Now do the `freemem' accounting.
28320Sstevel@tonic-gate 	 */
28330Sstevel@tonic-gate 	pcf_index = PCF_INDEX();
28340Sstevel@tonic-gate 	p = &pcf[pcf_index];
28350Sstevel@tonic-gate 
28360Sstevel@tonic-gate 	ASSERT(p->pcf_block == 0);
28370Sstevel@tonic-gate 	ASSERT(p->pcf_wait == 0);
28380Sstevel@tonic-gate 	p->pcf_count += 1;
28390Sstevel@tonic-gate 
28400Sstevel@tonic-gate 	/* freemem is approximate, so this is OK */
28410Sstevel@tonic-gate 	freemem += 1;
28420Sstevel@tonic-gate }
28430Sstevel@tonic-gate 
28440Sstevel@tonic-gate void
28450Sstevel@tonic-gate page_free_pages(page_t *pp)
28460Sstevel@tonic-gate {
28470Sstevel@tonic-gate 	page_t	*tpp, *rootpp = NULL;
28480Sstevel@tonic-gate 	pgcnt_t	pgcnt = page_get_pagecnt(pp->p_szc);
28490Sstevel@tonic-gate 	pgcnt_t	i;
28500Sstevel@tonic-gate 	uint_t	szc = pp->p_szc;
28510Sstevel@tonic-gate 
28520Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_free_pages);
28530Sstevel@tonic-gate 	TRACE_1(TR_FAC_VM, TR_PAGE_FREE_FREE,
28540Sstevel@tonic-gate 	    "page_free_free:pp %p", pp);
28550Sstevel@tonic-gate 
28560Sstevel@tonic-gate 	ASSERT(pp->p_szc != 0 && pp->p_szc < page_num_pagesizes());
28570Sstevel@tonic-gate 	if ((page_pptonum(pp) & (pgcnt - 1)) != 0) {
28580Sstevel@tonic-gate 		panic("page_free_pages: not root page %p", (void *)pp);
28590Sstevel@tonic-gate 		/*NOTREACHED*/
28600Sstevel@tonic-gate 	}
28610Sstevel@tonic-gate 
2862414Skchow 	for (i = 0, tpp = pp; i < pgcnt; i++, tpp++) {
28630Sstevel@tonic-gate 		ASSERT((PAGE_EXCL(tpp) &&
28640Sstevel@tonic-gate 		    !page_iolock_assert(tpp)) || panicstr);
28650Sstevel@tonic-gate 		if (PP_ISFREE(tpp)) {
28660Sstevel@tonic-gate 			panic("page_free_pages: page %p is free", (void *)tpp);
28670Sstevel@tonic-gate 			/*NOTREACHED*/
28680Sstevel@tonic-gate 		}
28690Sstevel@tonic-gate 		if (hat_page_is_mapped(tpp) || tpp->p_lckcnt != 0 ||
28702414Saguzovsk 		    tpp->p_cowcnt != 0 || tpp->p_slckcnt != 0) {
28710Sstevel@tonic-gate 			panic("page_free_pages %p", (void *)tpp);
28720Sstevel@tonic-gate 			/*NOTREACHED*/
28730Sstevel@tonic-gate 		}
28740Sstevel@tonic-gate 
28750Sstevel@tonic-gate 		ASSERT(!hat_page_getshare(tpp));
28760Sstevel@tonic-gate 		ASSERT(tpp->p_vnode == NULL);
28770Sstevel@tonic-gate 		ASSERT(tpp->p_szc == szc);
28780Sstevel@tonic-gate 
28790Sstevel@tonic-gate 		PP_SETFREE(tpp);
28800Sstevel@tonic-gate 		page_clr_all_props(tpp);
28810Sstevel@tonic-gate 		PP_SETAGED(tpp);
28820Sstevel@tonic-gate 		tpp->p_offset = (u_offset_t)-1;
28830Sstevel@tonic-gate 		ASSERT(tpp->p_next == tpp);
28840Sstevel@tonic-gate 		ASSERT(tpp->p_prev == tpp);
28850Sstevel@tonic-gate 		page_list_concat(&rootpp, &tpp);
28860Sstevel@tonic-gate 	}
28870Sstevel@tonic-gate 	ASSERT(rootpp == pp);
28880Sstevel@tonic-gate 
28890Sstevel@tonic-gate 	page_list_add_pages(rootpp, 0);
28900Sstevel@tonic-gate 	page_create_putback(pgcnt);
28910Sstevel@tonic-gate }
28920Sstevel@tonic-gate 
28930Sstevel@tonic-gate int free_pages = 1;
28940Sstevel@tonic-gate 
28950Sstevel@tonic-gate /*
28960Sstevel@tonic-gate  * This routine attempts to return pages to the cachelist via page_release().
28970Sstevel@tonic-gate  * It does not *have* to be successful in all cases, since the pageout scanner
28980Sstevel@tonic-gate  * will catch any pages it misses.  It does need to be fast and not introduce
28990Sstevel@tonic-gate  * too much overhead.
29000Sstevel@tonic-gate  *
29010Sstevel@tonic-gate  * If a page isn't found on the unlocked sweep of the page_hash bucket, we
29020Sstevel@tonic-gate  * don't lock and retry.  This is ok, since the page scanner will eventually
29030Sstevel@tonic-gate  * find any page we miss in free_vp_pages().
29040Sstevel@tonic-gate  */
29050Sstevel@tonic-gate void
29060Sstevel@tonic-gate free_vp_pages(vnode_t *vp, u_offset_t off, size_t len)
29070Sstevel@tonic-gate {
29080Sstevel@tonic-gate 	page_t *pp;
29090Sstevel@tonic-gate 	u_offset_t eoff;
29100Sstevel@tonic-gate 	extern int swap_in_range(vnode_t *, u_offset_t, size_t);
29110Sstevel@tonic-gate 
29120Sstevel@tonic-gate 	eoff = off + len;
29130Sstevel@tonic-gate 
29140Sstevel@tonic-gate 	if (free_pages == 0)
29150Sstevel@tonic-gate 		return;
29160Sstevel@tonic-gate 	if (swap_in_range(vp, off, len))
29170Sstevel@tonic-gate 		return;
29180Sstevel@tonic-gate 
29190Sstevel@tonic-gate 	for (; off < eoff; off += PAGESIZE) {
29200Sstevel@tonic-gate 
29210Sstevel@tonic-gate 		/*
29220Sstevel@tonic-gate 		 * find the page using a fast, but inexact search. It'll be OK
29230Sstevel@tonic-gate 		 * if a few pages slip through the cracks here.
29240Sstevel@tonic-gate 		 */
29250Sstevel@tonic-gate 		pp = page_exists(vp, off);
29260Sstevel@tonic-gate 
29270Sstevel@tonic-gate 		/*
29280Sstevel@tonic-gate 		 * If we didn't find the page (it may not exist), the page
29290Sstevel@tonic-gate 		 * is free, looks still in use (shared), or we can't lock it,
29300Sstevel@tonic-gate 		 * just give up.
29310Sstevel@tonic-gate 		 */
29320Sstevel@tonic-gate 		if (pp == NULL ||
29330Sstevel@tonic-gate 		    PP_ISFREE(pp) ||
29340Sstevel@tonic-gate 		    page_share_cnt(pp) > 0 ||
29350Sstevel@tonic-gate 		    !page_trylock(pp, SE_EXCL))
29360Sstevel@tonic-gate 			continue;
29370Sstevel@tonic-gate 
29380Sstevel@tonic-gate 		/*
29390Sstevel@tonic-gate 		 * Once we have locked pp, verify that it's still the
29400Sstevel@tonic-gate 		 * correct page and not already free
29410Sstevel@tonic-gate 		 */
29420Sstevel@tonic-gate 		ASSERT(PAGE_LOCKED_SE(pp, SE_EXCL));
29430Sstevel@tonic-gate 		if (pp->p_vnode != vp || pp->p_offset != off || PP_ISFREE(pp)) {
29440Sstevel@tonic-gate 			page_unlock(pp);
29450Sstevel@tonic-gate 			continue;
29460Sstevel@tonic-gate 		}
29470Sstevel@tonic-gate 
29480Sstevel@tonic-gate 		/*
29490Sstevel@tonic-gate 		 * try to release the page...
29500Sstevel@tonic-gate 		 */
29510Sstevel@tonic-gate 		(void) page_release(pp, 1);
29520Sstevel@tonic-gate 	}
29530Sstevel@tonic-gate }
29540Sstevel@tonic-gate 
29550Sstevel@tonic-gate /*
29560Sstevel@tonic-gate  * Reclaim the given page from the free list.
29573559Smec  * If pp is part of a large pages, only the given constituent page is reclaimed
29583559Smec  * and the large page it belonged to will be demoted.  This can only happen
29593559Smec  * if the page is not on the cachelist.
29603559Smec  *
29610Sstevel@tonic-gate  * Returns 1 on success or 0 on failure.
29620Sstevel@tonic-gate  *
29630Sstevel@tonic-gate  * The page is unlocked if it can't be reclaimed (when freemem == 0).
29640Sstevel@tonic-gate  * If `lock' is non-null, it will be dropped and re-acquired if
29650Sstevel@tonic-gate  * the routine must wait while freemem is 0.
29660Sstevel@tonic-gate  *
29670Sstevel@tonic-gate  * As it turns out, boot_getpages() does this.  It picks a page,
29680Sstevel@tonic-gate  * based on where OBP mapped in some address, gets its pfn, searches
29690Sstevel@tonic-gate  * the memsegs, locks the page, then pulls it off the free list!
29700Sstevel@tonic-gate  */
29710Sstevel@tonic-gate int
29720Sstevel@tonic-gate page_reclaim(page_t *pp, kmutex_t *lock)
29730Sstevel@tonic-gate {
29740Sstevel@tonic-gate 	struct pcf	*p;
29750Sstevel@tonic-gate 	uint_t		pcf_index;
29760Sstevel@tonic-gate 	struct cpu	*cpup;
29773559Smec 	int		enough;
29780Sstevel@tonic-gate 	uint_t		i;
29790Sstevel@tonic-gate 
29800Sstevel@tonic-gate 	ASSERT(lock != NULL ? MUTEX_HELD(lock) : 1);
29810Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp) && PP_ISFREE(pp));
2982917Selowe 
29830Sstevel@tonic-gate 	/*
29840Sstevel@tonic-gate 	 * If `freemem' is 0, we cannot reclaim this page from the
29850Sstevel@tonic-gate 	 * freelist, so release every lock we might hold: the page,
29860Sstevel@tonic-gate 	 * and the `lock' before blocking.
29870Sstevel@tonic-gate 	 *
29880Sstevel@tonic-gate 	 * The only way `freemem' can become 0 while there are pages
29890Sstevel@tonic-gate 	 * marked free (have their p->p_free bit set) is when the
29900Sstevel@tonic-gate 	 * system is low on memory and doing a page_create().  In
29910Sstevel@tonic-gate 	 * order to guarantee that once page_create() starts acquiring
29920Sstevel@tonic-gate 	 * pages it will be able to get all that it needs since `freemem'
29930Sstevel@tonic-gate 	 * was decreased by the requested amount.  So, we need to release
29940Sstevel@tonic-gate 	 * this page, and let page_create() have it.
29950Sstevel@tonic-gate 	 *
29960Sstevel@tonic-gate 	 * Since `freemem' being zero is not supposed to happen, just
29970Sstevel@tonic-gate 	 * use the usual hash stuff as a starting point.  If that bucket
29980Sstevel@tonic-gate 	 * is empty, then assume the worst, and start at the beginning
29990Sstevel@tonic-gate 	 * of the pcf array.  If we always start at the beginning
30000Sstevel@tonic-gate 	 * when acquiring more than one pcf lock, there won't be any
30010Sstevel@tonic-gate 	 * deadlock problems.
30020Sstevel@tonic-gate 	 */
30030Sstevel@tonic-gate 
30040Sstevel@tonic-gate 	/* TODO: Do we need to test kcage_freemem if PG_NORELOC(pp)? */
30050Sstevel@tonic-gate 
30063559Smec 	if (freemem <= throttlefree && !page_create_throttle(1l, 0)) {
30070Sstevel@tonic-gate 		pcf_acquire_all();
30080Sstevel@tonic-gate 		goto page_reclaim_nomem;
30090Sstevel@tonic-gate 	}
30100Sstevel@tonic-gate 
30113559Smec 	enough = 0;
30120Sstevel@tonic-gate 	pcf_index = PCF_INDEX();
30130Sstevel@tonic-gate 	p = &pcf[pcf_index];
30140Sstevel@tonic-gate 	mutex_enter(&p->pcf_lock);
30153559Smec 	if (p->pcf_count >= 1) {
30163559Smec 		enough = 1;
30173559Smec 		p->pcf_count--;
30180Sstevel@tonic-gate 	}
30190Sstevel@tonic-gate 	mutex_exit(&p->pcf_lock);
30203559Smec 
30213559Smec 	if (!enough) {
30220Sstevel@tonic-gate 		VM_STAT_ADD(page_reclaim_zero);
30230Sstevel@tonic-gate 		/*
30240Sstevel@tonic-gate 		 * Check again. Its possible that some other thread
30250Sstevel@tonic-gate 		 * could have been right behind us, and added one
30260Sstevel@tonic-gate 		 * to a list somewhere.  Acquire each of the pcf locks
30270Sstevel@tonic-gate 		 * until we find a page.
30280Sstevel@tonic-gate 		 */
30290Sstevel@tonic-gate 		p = pcf;
30300Sstevel@tonic-gate 		for (i = 0; i < PCF_FANOUT; i++) {
30310Sstevel@tonic-gate 			mutex_enter(&p->pcf_lock);
30323559Smec 			if (p->pcf_count >= 1) {
30333559Smec 				p->pcf_count -= 1;
30343559Smec 				enough = 1;
30353559Smec 				break;
30360Sstevel@tonic-gate 			}
30370Sstevel@tonic-gate 			p++;
30380Sstevel@tonic-gate 		}
30390Sstevel@tonic-gate 
30403559Smec 		if (!enough) {
30410Sstevel@tonic-gate page_reclaim_nomem:
30420Sstevel@tonic-gate 			/*
30430Sstevel@tonic-gate 			 * We really can't have page `pp'.
30440Sstevel@tonic-gate 			 * Time for the no-memory dance with
30450Sstevel@tonic-gate 			 * page_free().  This is just like
30460Sstevel@tonic-gate 			 * page_create_wait().  Plus the added
30470Sstevel@tonic-gate 			 * attraction of releasing whatever mutex
30480Sstevel@tonic-gate 			 * we held when we were called with in `lock'.
30490Sstevel@tonic-gate 			 * Page_unlock() will wakeup any thread
30500Sstevel@tonic-gate 			 * waiting around for this page.
30510Sstevel@tonic-gate 			 */
30520Sstevel@tonic-gate 			if (lock) {
30530Sstevel@tonic-gate 				VM_STAT_ADD(page_reclaim_zero_locked);
30540Sstevel@tonic-gate 				mutex_exit(lock);
30550Sstevel@tonic-gate 			}
30560Sstevel@tonic-gate 			page_unlock(pp);
30570Sstevel@tonic-gate 
30580Sstevel@tonic-gate 			/*
30590Sstevel@tonic-gate 			 * get this before we drop all the pcf locks.
30600Sstevel@tonic-gate 			 */
30610Sstevel@tonic-gate 			mutex_enter(&new_freemem_lock);
30620Sstevel@tonic-gate 
30630Sstevel@tonic-gate 			p = pcf;
30640Sstevel@tonic-gate 			for (i = 0; i < PCF_FANOUT; i++) {
30650Sstevel@tonic-gate 				p->pcf_wait++;
30660Sstevel@tonic-gate 				mutex_exit(&p->pcf_lock);
30670Sstevel@tonic-gate 				p++;
30680Sstevel@tonic-gate 			}
30690Sstevel@tonic-gate 
30700Sstevel@tonic-gate 			freemem_wait++;
30710Sstevel@tonic-gate 			cv_wait(&freemem_cv, &new_freemem_lock);
30720Sstevel@tonic-gate 			freemem_wait--;
30730Sstevel@tonic-gate 
30740Sstevel@tonic-gate 			mutex_exit(&new_freemem_lock);
30750Sstevel@tonic-gate 
30760Sstevel@tonic-gate 			if (lock) {
30770Sstevel@tonic-gate 				mutex_enter(lock);
30780Sstevel@tonic-gate 			}
30790Sstevel@tonic-gate 			return (0);
30800Sstevel@tonic-gate 		}
30810Sstevel@tonic-gate 
30820Sstevel@tonic-gate 		/*
30830Sstevel@tonic-gate 		 * The pcf accounting has been done,
30840Sstevel@tonic-gate 		 * though none of the pcf_wait flags have been set,
30850Sstevel@tonic-gate 		 * drop the locks and continue on.
30860Sstevel@tonic-gate 		 */
30870Sstevel@tonic-gate 		while (p >= pcf) {
30880Sstevel@tonic-gate 			mutex_exit(&p->pcf_lock);
30890Sstevel@tonic-gate 			p--;
30900Sstevel@tonic-gate 		}
30910Sstevel@tonic-gate 	}
30920Sstevel@tonic-gate 
30930Sstevel@tonic-gate 	/*
30940Sstevel@tonic-gate 	 * freemem is not protected by any lock. Thus, we cannot
30950Sstevel@tonic-gate 	 * have any assertion containing freemem here.
30960Sstevel@tonic-gate 	 */
30973559Smec 	freemem -= 1;
30980Sstevel@tonic-gate 
30990Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_reclaim);
31003559Smec 
31013559Smec 	/*
31023559Smec 	 * page_list_sub will handle the case where pp is a large page.
31033559Smec 	 * It's possible that the page was promoted while on the freelist
31043559Smec 	 */
31050Sstevel@tonic-gate 	if (PP_ISAGED(pp)) {
31063559Smec 		page_list_sub(pp, PG_FREE_LIST);
31070Sstevel@tonic-gate 		TRACE_1(TR_FAC_VM, TR_PAGE_UNFREE_FREE,
31080Sstevel@tonic-gate 		    "page_reclaim_free:pp %p", pp);
31090Sstevel@tonic-gate 	} else {
31100Sstevel@tonic-gate 		page_list_sub(pp, PG_CACHE_LIST);
31110Sstevel@tonic-gate 		TRACE_1(TR_FAC_VM, TR_PAGE_UNFREE_CACHE,
31120Sstevel@tonic-gate 		    "page_reclaim_cache:pp %p", pp);
31130Sstevel@tonic-gate 	}
31140Sstevel@tonic-gate 
31150Sstevel@tonic-gate 	/*
31160Sstevel@tonic-gate 	 * clear the p_free & p_age bits since this page is no longer
31170Sstevel@tonic-gate 	 * on the free list.  Notice that there was a brief time where
31180Sstevel@tonic-gate 	 * a page is marked as free, but is not on the list.
31190Sstevel@tonic-gate 	 *
31200Sstevel@tonic-gate 	 * Set the reference bit to protect against immediate pageout.
31210Sstevel@tonic-gate 	 */
31223559Smec 	PP_CLRFREE(pp);
31233559Smec 	PP_CLRAGED(pp);
31243559Smec 	page_set_props(pp, P_REF);
31250Sstevel@tonic-gate 
31260Sstevel@tonic-gate 	CPU_STATS_ENTER_K();
31270Sstevel@tonic-gate 	cpup = CPU;	/* get cpup now that CPU cannot change */
31280Sstevel@tonic-gate 	CPU_STATS_ADDQ(cpup, vm, pgrec, 1);
31290Sstevel@tonic-gate 	CPU_STATS_ADDQ(cpup, vm, pgfrec, 1);
31300Sstevel@tonic-gate 	CPU_STATS_EXIT_K();
31313559Smec 	ASSERT(pp->p_szc == 0);
31320Sstevel@tonic-gate 
31330Sstevel@tonic-gate 	return (1);
31340Sstevel@tonic-gate }
31350Sstevel@tonic-gate 
31360Sstevel@tonic-gate /*
31370Sstevel@tonic-gate  * Destroy identity of the page and put it back on
31380Sstevel@tonic-gate  * the page free list.  Assumes that the caller has
31390Sstevel@tonic-gate  * acquired the "exclusive" lock on the page.
31400Sstevel@tonic-gate  */
31410Sstevel@tonic-gate void
31420Sstevel@tonic-gate page_destroy(page_t *pp, int dontfree)
31430Sstevel@tonic-gate {
31440Sstevel@tonic-gate 	ASSERT((PAGE_EXCL(pp) &&
31450Sstevel@tonic-gate 	    !page_iolock_assert(pp)) || panicstr);
31462414Saguzovsk 	ASSERT(pp->p_slckcnt == 0 || panicstr);
31470Sstevel@tonic-gate 
31480Sstevel@tonic-gate 	if (pp->p_szc != 0) {
31490Sstevel@tonic-gate 		if (pp->p_vnode == NULL || IS_SWAPFSVP(pp->p_vnode) ||
31503290Sjohansen 		    PP_ISKAS(pp)) {
31510Sstevel@tonic-gate 			panic("page_destroy: anon or kernel or no vnode "
31520Sstevel@tonic-gate 			    "large page %p", (void *)pp);
31530Sstevel@tonic-gate 		}
31540Sstevel@tonic-gate 		page_demote_vp_pages(pp);
31550Sstevel@tonic-gate 		ASSERT(pp->p_szc == 0);
31560Sstevel@tonic-gate 	}
31570Sstevel@tonic-gate 
31580Sstevel@tonic-gate 	TRACE_1(TR_FAC_VM, TR_PAGE_DESTROY, "page_destroy:pp %p", pp);
31590Sstevel@tonic-gate 
31600Sstevel@tonic-gate 	/*
31610Sstevel@tonic-gate 	 * Unload translations, if any, then hash out the
31620Sstevel@tonic-gate 	 * page to erase its identity.
31630Sstevel@tonic-gate 	 */
31640Sstevel@tonic-gate 	(void) hat_pageunload(pp, HAT_FORCE_PGUNLOAD);
31650Sstevel@tonic-gate 	page_hashout(pp, NULL);
31660Sstevel@tonic-gate 
31670Sstevel@tonic-gate 	if (!dontfree) {
31680Sstevel@tonic-gate 		/*
31690Sstevel@tonic-gate 		 * Acquire the "freemem_lock" for availrmem.
31700Sstevel@tonic-gate 		 * The page_struct_lock need not be acquired for lckcnt
31710Sstevel@tonic-gate 		 * and cowcnt since the page has an "exclusive" lock.
31720Sstevel@tonic-gate 		 */
31730Sstevel@tonic-gate 		if ((pp->p_lckcnt != 0) || (pp->p_cowcnt != 0)) {
31740Sstevel@tonic-gate 			mutex_enter(&freemem_lock);
31750Sstevel@tonic-gate 			if (pp->p_lckcnt != 0) {
31760Sstevel@tonic-gate 				availrmem++;
31770Sstevel@tonic-gate 				pp->p_lckcnt = 0;
31780Sstevel@tonic-gate 			}
31790Sstevel@tonic-gate 			if (pp->p_cowcnt != 0) {
31800Sstevel@tonic-gate 				availrmem += pp->p_cowcnt;
31810Sstevel@tonic-gate 				pp->p_cowcnt = 0;
31820Sstevel@tonic-gate 			}
31830Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
31840Sstevel@tonic-gate 		}
31850Sstevel@tonic-gate 		/*
31860Sstevel@tonic-gate 		 * Put the page on the "free" list.
31870Sstevel@tonic-gate 		 */
31880Sstevel@tonic-gate 		page_free(pp, 0);
31890Sstevel@tonic-gate 	}
31900Sstevel@tonic-gate }
31910Sstevel@tonic-gate 
31920Sstevel@tonic-gate void
31930Sstevel@tonic-gate page_destroy_pages(page_t *pp)
31940Sstevel@tonic-gate {
31950Sstevel@tonic-gate 
31960Sstevel@tonic-gate 	page_t	*tpp, *rootpp = NULL;
31970Sstevel@tonic-gate 	pgcnt_t	pgcnt = page_get_pagecnt(pp->p_szc);
31980Sstevel@tonic-gate 	pgcnt_t	i, pglcks = 0;
31990Sstevel@tonic-gate 	uint_t	szc = pp->p_szc;
32000Sstevel@tonic-gate 
32010Sstevel@tonic-gate 	ASSERT(pp->p_szc != 0 && pp->p_szc < page_num_pagesizes());
32020Sstevel@tonic-gate 
32030Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_destroy_pages);
32040Sstevel@tonic-gate 
32050Sstevel@tonic-gate 	TRACE_1(TR_FAC_VM, TR_PAGE_DESTROY, "page_destroy_pages:pp %p", pp);
32060Sstevel@tonic-gate 
32070Sstevel@tonic-gate 	if ((page_pptonum(pp) & (pgcnt - 1)) != 0) {
32080Sstevel@tonic-gate 		panic("page_destroy_pages: not root page %p", (void *)pp);
32090Sstevel@tonic-gate 		/*NOTREACHED*/
32100Sstevel@tonic-gate 	}
32110Sstevel@tonic-gate 
3212414Skchow 	for (i = 0, tpp = pp; i < pgcnt; i++, tpp++) {
32130Sstevel@tonic-gate 		ASSERT((PAGE_EXCL(tpp) &&
32140Sstevel@tonic-gate 		    !page_iolock_assert(tpp)) || panicstr);
32152414Saguzovsk 		ASSERT(tpp->p_slckcnt == 0 || panicstr);
32160Sstevel@tonic-gate 		(void) hat_pageunload(tpp, HAT_FORCE_PGUNLOAD);
32170Sstevel@tonic-gate 		page_hashout(tpp, NULL);
32180Sstevel@tonic-gate 		ASSERT(tpp->p_offset == (u_offset_t)-1);
32190Sstevel@tonic-gate 		if (tpp->p_lckcnt != 0) {
32200Sstevel@tonic-gate 			pglcks++;
32210Sstevel@tonic-gate 			tpp->p_lckcnt = 0;
32220Sstevel@tonic-gate 		} else if (tpp->p_cowcnt != 0) {
32230Sstevel@tonic-gate 			pglcks += tpp->p_cowcnt;
32240Sstevel@tonic-gate 			tpp->p_cowcnt = 0;
32250Sstevel@tonic-gate 		}
32260Sstevel@tonic-gate 		ASSERT(!hat_page_getshare(tpp));
32270Sstevel@tonic-gate 		ASSERT(tpp->p_vnode == NULL);
32280Sstevel@tonic-gate 		ASSERT(tpp->p_szc == szc);
32290Sstevel@tonic-gate 
32300Sstevel@tonic-gate 		PP_SETFREE(tpp);
32310Sstevel@tonic-gate 		page_clr_all_props(tpp);
32320Sstevel@tonic-gate 		PP_SETAGED(tpp);
32330Sstevel@tonic-gate 		ASSERT(tpp->p_next == tpp);
32340Sstevel@tonic-gate 		ASSERT(tpp->p_prev == tpp);
32350Sstevel@tonic-gate 		page_list_concat(&rootpp, &tpp);
32360Sstevel@tonic-gate 	}
32370Sstevel@tonic-gate 
32380Sstevel@tonic-gate 	ASSERT(rootpp == pp);
32390Sstevel@tonic-gate 	if (pglcks != 0) {
32400Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
32410Sstevel@tonic-gate 		availrmem += pglcks;
32420Sstevel@tonic-gate 		mutex_exit(&freemem_lock);
32430Sstevel@tonic-gate 	}
32440Sstevel@tonic-gate 
32450Sstevel@tonic-gate 	page_list_add_pages(rootpp, 0);
32460Sstevel@tonic-gate 	page_create_putback(pgcnt);
32470Sstevel@tonic-gate }
32480Sstevel@tonic-gate 
32490Sstevel@tonic-gate /*
32500Sstevel@tonic-gate  * Similar to page_destroy(), but destroys pages which are
32510Sstevel@tonic-gate  * locked and known to be on the page free list.  Since
32520Sstevel@tonic-gate  * the page is known to be free and locked, no one can access
32530Sstevel@tonic-gate  * it.
32540Sstevel@tonic-gate  *
32550Sstevel@tonic-gate  * Also, the number of free pages does not change.
32560Sstevel@tonic-gate  */
32570Sstevel@tonic-gate void
32580Sstevel@tonic-gate page_destroy_free(page_t *pp)
32590Sstevel@tonic-gate {
32600Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp));
32610Sstevel@tonic-gate 	ASSERT(PP_ISFREE(pp));
32620Sstevel@tonic-gate 	ASSERT(pp->p_vnode);
32630Sstevel@tonic-gate 	ASSERT(hat_page_getattr(pp, P_MOD | P_REF | P_RO) == 0);
32640Sstevel@tonic-gate 	ASSERT(!hat_page_is_mapped(pp));
32650Sstevel@tonic-gate 	ASSERT(PP_ISAGED(pp) == 0);
32660Sstevel@tonic-gate 	ASSERT(pp->p_szc == 0);
32670Sstevel@tonic-gate 
32680Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_destroy_free);
32690Sstevel@tonic-gate 	page_list_sub(pp, PG_CACHE_LIST);
32700Sstevel@tonic-gate 
32710Sstevel@tonic-gate 	page_hashout(pp, NULL);
32720Sstevel@tonic-gate 	ASSERT(pp->p_vnode == NULL);
32730Sstevel@tonic-gate 	ASSERT(pp->p_offset == (u_offset_t)-1);
32740Sstevel@tonic-gate 	ASSERT(pp->p_hash == NULL);
32750Sstevel@tonic-gate 
32760Sstevel@tonic-gate 	PP_SETAGED(pp);
32770Sstevel@tonic-gate 	page_list_add(pp, PG_FREE_LIST | PG_LIST_TAIL);
32780Sstevel@tonic-gate 	page_unlock(pp);
32790Sstevel@tonic-gate 
32800Sstevel@tonic-gate 	mutex_enter(&new_freemem_lock);
32810Sstevel@tonic-gate 	if (freemem_wait) {
32820Sstevel@tonic-gate 		cv_signal(&freemem_cv);
32830Sstevel@tonic-gate 	}
32840Sstevel@tonic-gate 	mutex_exit(&new_freemem_lock);
32850Sstevel@tonic-gate }
32860Sstevel@tonic-gate 
32870Sstevel@tonic-gate /*
32880Sstevel@tonic-gate  * Rename the page "opp" to have an identity specified
32890Sstevel@tonic-gate  * by [vp, off].  If a page already exists with this name
32900Sstevel@tonic-gate  * it is locked and destroyed.  Note that the page's
32910Sstevel@tonic-gate  * translations are not unloaded during the rename.
32920Sstevel@tonic-gate  *
32930Sstevel@tonic-gate  * This routine is used by the anon layer to "steal" the
32940Sstevel@tonic-gate  * original page and is not unlike destroying a page and
32950Sstevel@tonic-gate  * creating a new page using the same page frame.
32960Sstevel@tonic-gate  *
32970Sstevel@tonic-gate  * XXX -- Could deadlock if caller 1 tries to rename A to B while
32980Sstevel@tonic-gate  * caller 2 tries to rename B to A.
32990Sstevel@tonic-gate  */
33000Sstevel@tonic-gate void
33010Sstevel@tonic-gate page_rename(page_t *opp, vnode_t *vp, u_offset_t off)
33020Sstevel@tonic-gate {
33030Sstevel@tonic-gate 	page_t		*pp;
33040Sstevel@tonic-gate 	int		olckcnt = 0;
33050Sstevel@tonic-gate 	int		ocowcnt = 0;
33060Sstevel@tonic-gate 	kmutex_t	*phm;
33070Sstevel@tonic-gate 	ulong_t		index;
33080Sstevel@tonic-gate 
33090Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(opp) && !page_iolock_assert(opp));
33100Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
33110Sstevel@tonic-gate 	ASSERT(PP_ISFREE(opp) == 0);
33120Sstevel@tonic-gate 
33130Sstevel@tonic-gate 	VM_STAT_ADD(page_rename_count);
33140Sstevel@tonic-gate 
33150Sstevel@tonic-gate 	TRACE_3(TR_FAC_VM, TR_PAGE_RENAME,
33163559Smec 	    "page rename:pp %p vp %p off %llx", opp, vp, off);
33170Sstevel@tonic-gate 
331863Saguzovsk 	/*
331963Saguzovsk 	 * CacheFS may call page_rename for a large NFS page
332063Saguzovsk 	 * when both CacheFS and NFS mount points are used
332163Saguzovsk 	 * by applications. Demote this large page before
332263Saguzovsk 	 * renaming it, to ensure that there are no "partial"
332363Saguzovsk 	 * large pages left lying around.
332463Saguzovsk 	 */
332563Saguzovsk 	if (opp->p_szc != 0) {
332663Saguzovsk 		vnode_t *ovp = opp->p_vnode;
332763Saguzovsk 		ASSERT(ovp != NULL);
332863Saguzovsk 		ASSERT(!IS_SWAPFSVP(ovp));
33293290Sjohansen 		ASSERT(!VN_ISKAS(ovp));
333063Saguzovsk 		page_demote_vp_pages(opp);
333163Saguzovsk 		ASSERT(opp->p_szc == 0);
333263Saguzovsk 	}
333363Saguzovsk 
33340Sstevel@tonic-gate 	page_hashout(opp, NULL);
33350Sstevel@tonic-gate 	PP_CLRAGED(opp);
33360Sstevel@tonic-gate 
33370Sstevel@tonic-gate 	/*
33380Sstevel@tonic-gate 	 * Acquire the appropriate page hash lock, since
33390Sstevel@tonic-gate 	 * we're going to rename the page.
33400Sstevel@tonic-gate 	 */
33410Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, off);
33420Sstevel@tonic-gate 	phm = PAGE_HASH_MUTEX(index);
33430Sstevel@tonic-gate 	mutex_enter(phm);
33440Sstevel@tonic-gate top:
33450Sstevel@tonic-gate 	/*
33460Sstevel@tonic-gate 	 * Look for an existing page with this name and destroy it if found.
33470Sstevel@tonic-gate 	 * By holding the page hash lock all the way to the page_hashin()
33480Sstevel@tonic-gate 	 * call, we are assured that no page can be created with this
33490Sstevel@tonic-gate 	 * identity.  In the case when the phm lock is dropped to undo any
33500Sstevel@tonic-gate 	 * hat layer mappings, the existing page is held with an "exclusive"
33510Sstevel@tonic-gate 	 * lock, again preventing another page from being created with
33520Sstevel@tonic-gate 	 * this identity.
33530Sstevel@tonic-gate 	 */
33540Sstevel@tonic-gate 	PAGE_HASH_SEARCH(index, pp, vp, off);
33550Sstevel@tonic-gate 	if (pp != NULL) {
33560Sstevel@tonic-gate 		VM_STAT_ADD(page_rename_exists);
33570Sstevel@tonic-gate 
33580Sstevel@tonic-gate 		/*
33590Sstevel@tonic-gate 		 * As it turns out, this is one of only two places where
33600Sstevel@tonic-gate 		 * page_lock() needs to hold the passed in lock in the
33610Sstevel@tonic-gate 		 * successful case.  In all of the others, the lock could
33620Sstevel@tonic-gate 		 * be dropped as soon as the attempt is made to lock
33630Sstevel@tonic-gate 		 * the page.  It is tempting to add yet another arguement,
33640Sstevel@tonic-gate 		 * PL_KEEP or PL_DROP, to let page_lock know what to do.
33650Sstevel@tonic-gate 		 */
33660Sstevel@tonic-gate 		if (!page_lock(pp, SE_EXCL, phm, P_RECLAIM)) {
33670Sstevel@tonic-gate 			/*
33680Sstevel@tonic-gate 			 * Went to sleep because the page could not
33690Sstevel@tonic-gate 			 * be locked.  We were woken up when the page
33700Sstevel@tonic-gate 			 * was unlocked, or when the page was destroyed.
33710Sstevel@tonic-gate 			 * In either case, `phm' was dropped while we
33720Sstevel@tonic-gate 			 * slept.  Hence we should not just roar through
33730Sstevel@tonic-gate 			 * this loop.
33740Sstevel@tonic-gate 			 */
33750Sstevel@tonic-gate 			goto top;
33760Sstevel@tonic-gate 		}
33770Sstevel@tonic-gate 
337863Saguzovsk 		/*
337963Saguzovsk 		 * If an existing page is a large page, then demote
338063Saguzovsk 		 * it to ensure that no "partial" large pages are
338163Saguzovsk 		 * "created" after page_rename. An existing page
338263Saguzovsk 		 * can be a CacheFS page, and can't belong to swapfs.
338363Saguzovsk 		 */
33840Sstevel@tonic-gate 		if (hat_page_is_mapped(pp)) {
33850Sstevel@tonic-gate 			/*
33860Sstevel@tonic-gate 			 * Unload translations.  Since we hold the
33870Sstevel@tonic-gate 			 * exclusive lock on this page, the page
33880Sstevel@tonic-gate 			 * can not be changed while we drop phm.
33890Sstevel@tonic-gate 			 * This is also not a lock protocol violation,
33900Sstevel@tonic-gate 			 * but rather the proper way to do things.
33910Sstevel@tonic-gate 			 */
33920Sstevel@tonic-gate 			mutex_exit(phm);
33930Sstevel@tonic-gate 			(void) hat_pageunload(pp, HAT_FORCE_PGUNLOAD);
339463Saguzovsk 			if (pp->p_szc != 0) {
339563Saguzovsk 				ASSERT(!IS_SWAPFSVP(vp));
33963290Sjohansen 				ASSERT(!VN_ISKAS(vp));
339763Saguzovsk 				page_demote_vp_pages(pp);
339863Saguzovsk 				ASSERT(pp->p_szc == 0);
339963Saguzovsk 			}
340063Saguzovsk 			mutex_enter(phm);
340163Saguzovsk 		} else if (pp->p_szc != 0) {
340263Saguzovsk 			ASSERT(!IS_SWAPFSVP(vp));
34033290Sjohansen 			ASSERT(!VN_ISKAS(vp));
340463Saguzovsk 			mutex_exit(phm);
340563Saguzovsk 			page_demote_vp_pages(pp);
340663Saguzovsk 			ASSERT(pp->p_szc == 0);
34070Sstevel@tonic-gate 			mutex_enter(phm);
34080Sstevel@tonic-gate 		}
34090Sstevel@tonic-gate 		page_hashout(pp, phm);
34100Sstevel@tonic-gate 	}
34110Sstevel@tonic-gate 	/*
34120Sstevel@tonic-gate 	 * Hash in the page with the new identity.
34130Sstevel@tonic-gate 	 */
34140Sstevel@tonic-gate 	if (!page_hashin(opp, vp, off, phm)) {
34150Sstevel@tonic-gate 		/*
34160Sstevel@tonic-gate 		 * We were holding phm while we searched for [vp, off]
34170Sstevel@tonic-gate 		 * and only dropped phm if we found and locked a page.
34180Sstevel@tonic-gate 		 * If we can't create this page now, then some thing
34190Sstevel@tonic-gate 		 * is really broken.
34200Sstevel@tonic-gate 		 */
34210Sstevel@tonic-gate 		panic("page_rename: Can't hash in page: %p", (void *)pp);
34220Sstevel@tonic-gate 		/*NOTREACHED*/
34230Sstevel@tonic-gate 	}
34240Sstevel@tonic-gate 
34250Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(phm));
34260Sstevel@tonic-gate 	mutex_exit(phm);
34270Sstevel@tonic-gate 
34280Sstevel@tonic-gate 	/*
34290Sstevel@tonic-gate 	 * Now that we have dropped phm, lets get around to finishing up
34300Sstevel@tonic-gate 	 * with pp.
34310Sstevel@tonic-gate 	 */
34320Sstevel@tonic-gate 	if (pp != NULL) {
34330Sstevel@tonic-gate 		ASSERT(!hat_page_is_mapped(pp));
34340Sstevel@tonic-gate 		/* for now large pages should not end up here */
34350Sstevel@tonic-gate 		ASSERT(pp->p_szc == 0);
34360Sstevel@tonic-gate 		/*
34370Sstevel@tonic-gate 		 * Save the locks for transfer to the new page and then
34380Sstevel@tonic-gate 		 * clear them so page_free doesn't think they're important.
34390Sstevel@tonic-gate 		 * The page_struct_lock need not be acquired for lckcnt and
34400Sstevel@tonic-gate 		 * cowcnt since the page has an "exclusive" lock.
34410Sstevel@tonic-gate 		 */
34420Sstevel@tonic-gate 		olckcnt = pp->p_lckcnt;
34430Sstevel@tonic-gate 		ocowcnt = pp->p_cowcnt;
34440Sstevel@tonic-gate 		pp->p_lckcnt = pp->p_cowcnt = 0;
34450Sstevel@tonic-gate 
34460Sstevel@tonic-gate 		/*
34470Sstevel@tonic-gate 		 * Put the page on the "free" list after we drop
34480Sstevel@tonic-gate 		 * the lock.  The less work under the lock the better.
34490Sstevel@tonic-gate 		 */
34500Sstevel@tonic-gate 		/*LINTED: constant in conditional context*/
34510Sstevel@tonic-gate 		VN_DISPOSE(pp, B_FREE, 0, kcred);
34520Sstevel@tonic-gate 	}
34530Sstevel@tonic-gate 
34540Sstevel@tonic-gate 	/*
34550Sstevel@tonic-gate 	 * Transfer the lock count from the old page (if any).
34560Sstevel@tonic-gate 	 * The page_struct_lock need not be acquired for lckcnt and
34570Sstevel@tonic-gate 	 * cowcnt since the page has an "exclusive" lock.
34580Sstevel@tonic-gate 	 */
34590Sstevel@tonic-gate 	opp->p_lckcnt += olckcnt;
34600Sstevel@tonic-gate 	opp->p_cowcnt += ocowcnt;
34610Sstevel@tonic-gate }
34620Sstevel@tonic-gate 
34630Sstevel@tonic-gate /*
34640Sstevel@tonic-gate  * low level routine to add page `pp' to the hash and vp chains for [vp, offset]
34650Sstevel@tonic-gate  *
34660Sstevel@tonic-gate  * Pages are normally inserted at the start of a vnode's v_pages list.
34670Sstevel@tonic-gate  * If the vnode is VMODSORT and the page is modified, it goes at the end.
34680Sstevel@tonic-gate  * This can happen when a modified page is relocated for DR.
34690Sstevel@tonic-gate  *
34700Sstevel@tonic-gate  * Returns 1 on success and 0 on failure.
34710Sstevel@tonic-gate  */
34720Sstevel@tonic-gate static int
34730Sstevel@tonic-gate page_do_hashin(page_t *pp, vnode_t *vp, u_offset_t offset)
34740Sstevel@tonic-gate {
34750Sstevel@tonic-gate 	page_t		**listp;
34760Sstevel@tonic-gate 	page_t		*tp;
34770Sstevel@tonic-gate 	ulong_t		index;
34780Sstevel@tonic-gate 
34790Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp));
34800Sstevel@tonic-gate 	ASSERT(vp != NULL);
34810Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(page_vnode_mutex(vp)));
34820Sstevel@tonic-gate 
34830Sstevel@tonic-gate 	/*
34840Sstevel@tonic-gate 	 * Be sure to set these up before the page is inserted on the hash
34850Sstevel@tonic-gate 	 * list.  As soon as the page is placed on the list some other
34860Sstevel@tonic-gate 	 * thread might get confused and wonder how this page could
34870Sstevel@tonic-gate 	 * possibly hash to this list.
34880Sstevel@tonic-gate 	 */
34890Sstevel@tonic-gate 	pp->p_vnode = vp;
34900Sstevel@tonic-gate 	pp->p_offset = offset;
34910Sstevel@tonic-gate 
34920Sstevel@tonic-gate 	/*
34930Sstevel@tonic-gate 	 * record if this page is on a swap vnode
34940Sstevel@tonic-gate 	 */
34950Sstevel@tonic-gate 	if ((vp->v_flag & VISSWAP) != 0)
34960Sstevel@tonic-gate 		PP_SETSWAP(pp);
34970Sstevel@tonic-gate 
34980Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, offset);
34990Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(PAGE_HASH_MUTEX(index)));
35000Sstevel@tonic-gate 	listp = &page_hash[index];
35010Sstevel@tonic-gate 
35020Sstevel@tonic-gate 	/*
35030Sstevel@tonic-gate 	 * If this page is already hashed in, fail this attempt to add it.
35040Sstevel@tonic-gate 	 */
35050Sstevel@tonic-gate 	for (tp = *listp; tp != NULL; tp = tp->p_hash) {
35060Sstevel@tonic-gate 		if (tp->p_vnode == vp && tp->p_offset == offset) {
35070Sstevel@tonic-gate 			pp->p_vnode = NULL;
35080Sstevel@tonic-gate 			pp->p_offset = (u_offset_t)(-1);
35090Sstevel@tonic-gate 			return (0);
35100Sstevel@tonic-gate 		}
35110Sstevel@tonic-gate 	}
35120Sstevel@tonic-gate 	pp->p_hash = *listp;
35130Sstevel@tonic-gate 	*listp = pp;
35140Sstevel@tonic-gate 
35150Sstevel@tonic-gate 	/*
35160Sstevel@tonic-gate 	 * Add the page to the vnode's list of pages
35170Sstevel@tonic-gate 	 */
35180Sstevel@tonic-gate 	if (vp->v_pages != NULL && IS_VMODSORT(vp) && hat_ismod(pp))
35190Sstevel@tonic-gate 		listp = &vp->v_pages->p_vpprev->p_vpnext;
35200Sstevel@tonic-gate 	else
35210Sstevel@tonic-gate 		listp = &vp->v_pages;
35220Sstevel@tonic-gate 
35230Sstevel@tonic-gate 	page_vpadd(listp, pp);
35240Sstevel@tonic-gate 
35250Sstevel@tonic-gate 	return (1);
35260Sstevel@tonic-gate }
35270Sstevel@tonic-gate 
35280Sstevel@tonic-gate /*
35290Sstevel@tonic-gate  * Add page `pp' to both the hash and vp chains for [vp, offset].
35300Sstevel@tonic-gate  *
35310Sstevel@tonic-gate  * Returns 1 on success and 0 on failure.
35320Sstevel@tonic-gate  * If hold is passed in, it is not dropped.
35330Sstevel@tonic-gate  */
35340Sstevel@tonic-gate int
35350Sstevel@tonic-gate page_hashin(page_t *pp, vnode_t *vp, u_offset_t offset, kmutex_t *hold)
35360Sstevel@tonic-gate {
35370Sstevel@tonic-gate 	kmutex_t	*phm = NULL;
35380Sstevel@tonic-gate 	kmutex_t	*vphm;
35390Sstevel@tonic-gate 	int		rc;
35400Sstevel@tonic-gate 
35410Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(vp)));
35420Sstevel@tonic-gate 
35430Sstevel@tonic-gate 	TRACE_3(TR_FAC_VM, TR_PAGE_HASHIN,
35443559Smec 	    "page_hashin:pp %p vp %p offset %llx",
35453559Smec 	    pp, vp, offset);
35460Sstevel@tonic-gate 
35470Sstevel@tonic-gate 	VM_STAT_ADD(hashin_count);
35480Sstevel@tonic-gate 
35490Sstevel@tonic-gate 	if (hold != NULL)
35500Sstevel@tonic-gate 		phm = hold;
35510Sstevel@tonic-gate 	else {
35520Sstevel@tonic-gate 		VM_STAT_ADD(hashin_not_held);
35530Sstevel@tonic-gate 		phm = PAGE_HASH_MUTEX(PAGE_HASH_FUNC(vp, offset));
35540Sstevel@tonic-gate 		mutex_enter(phm);
35550Sstevel@tonic-gate 	}
35560Sstevel@tonic-gate 
35570Sstevel@tonic-gate 	vphm = page_vnode_mutex(vp);
35580Sstevel@tonic-gate 	mutex_enter(vphm);
35590Sstevel@tonic-gate 	rc = page_do_hashin(pp, vp, offset);
35600Sstevel@tonic-gate 	mutex_exit(vphm);
35610Sstevel@tonic-gate 	if (hold == NULL)
35620Sstevel@tonic-gate 		mutex_exit(phm);
35630Sstevel@tonic-gate 	if (rc == 0)
35640Sstevel@tonic-gate 		VM_STAT_ADD(hashin_already);
35650Sstevel@tonic-gate 	return (rc);
35660Sstevel@tonic-gate }
35670Sstevel@tonic-gate 
35680Sstevel@tonic-gate /*
35690Sstevel@tonic-gate  * Remove page ``pp'' from the hash and vp chains and remove vp association.
35700Sstevel@tonic-gate  * All mutexes must be held
35710Sstevel@tonic-gate  */
35720Sstevel@tonic-gate static void
35730Sstevel@tonic-gate page_do_hashout(page_t *pp)
35740Sstevel@tonic-gate {
35750Sstevel@tonic-gate 	page_t	**hpp;
35760Sstevel@tonic-gate 	page_t	*hp;
35770Sstevel@tonic-gate 	vnode_t	*vp = pp->p_vnode;
35780Sstevel@tonic-gate 
35790Sstevel@tonic-gate 	ASSERT(vp != NULL);
35800Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(page_vnode_mutex(vp)));
35810Sstevel@tonic-gate 
35820Sstevel@tonic-gate 	/*
35830Sstevel@tonic-gate 	 * First, take pp off of its hash chain.
35840Sstevel@tonic-gate 	 */
35850Sstevel@tonic-gate 	hpp = &page_hash[PAGE_HASH_FUNC(vp, pp->p_offset)];
35860Sstevel@tonic-gate 
35870Sstevel@tonic-gate 	for (;;) {
35880Sstevel@tonic-gate 		hp = *hpp;
35890Sstevel@tonic-gate 		if (hp == pp)
35900Sstevel@tonic-gate 			break;
35910Sstevel@tonic-gate 		if (hp == NULL) {
35920Sstevel@tonic-gate 			panic("page_do_hashout");
35930Sstevel@tonic-gate 			/*NOTREACHED*/
35940Sstevel@tonic-gate 		}
35950Sstevel@tonic-gate 		hpp = &hp->p_hash;
35960Sstevel@tonic-gate 	}
35970Sstevel@tonic-gate 	*hpp = pp->p_hash;
35980Sstevel@tonic-gate 
35990Sstevel@tonic-gate 	/*
36000Sstevel@tonic-gate 	 * Now remove it from its associated vnode.
36010Sstevel@tonic-gate 	 */
36020Sstevel@tonic-gate 	if (vp->v_pages)
36030Sstevel@tonic-gate 		page_vpsub(&vp->v_pages, pp);
36040Sstevel@tonic-gate 
36050Sstevel@tonic-gate 	pp->p_hash = NULL;
36060Sstevel@tonic-gate 	page_clr_all_props(pp);
36070Sstevel@tonic-gate 	PP_CLRSWAP(pp);
36080Sstevel@tonic-gate 	pp->p_vnode = NULL;
36090Sstevel@tonic-gate 	pp->p_offset = (u_offset_t)-1;
36100Sstevel@tonic-gate }
36110Sstevel@tonic-gate 
36120Sstevel@tonic-gate /*
36130Sstevel@tonic-gate  * Remove page ``pp'' from the hash and vp chains and remove vp association.
36140Sstevel@tonic-gate  *
36150Sstevel@tonic-gate  * When `phm' is non-NULL it contains the address of the mutex protecting the
36160Sstevel@tonic-gate  * hash list pp is on.  It is not dropped.
36170Sstevel@tonic-gate  */
36180Sstevel@tonic-gate void
36190Sstevel@tonic-gate page_hashout(page_t *pp, kmutex_t *phm)
36200Sstevel@tonic-gate {
36210Sstevel@tonic-gate 	vnode_t		*vp;
36220Sstevel@tonic-gate 	ulong_t		index;
36230Sstevel@tonic-gate 	kmutex_t	*nphm;
36240Sstevel@tonic-gate 	kmutex_t	*vphm;
36250Sstevel@tonic-gate 	kmutex_t	*sep;
36260Sstevel@tonic-gate 
36270Sstevel@tonic-gate 	ASSERT(phm != NULL ? MUTEX_HELD(phm) : 1);
36280Sstevel@tonic-gate 	ASSERT(pp->p_vnode != NULL);
36290Sstevel@tonic-gate 	ASSERT((PAGE_EXCL(pp) && !page_iolock_assert(pp)) || panicstr);
36300Sstevel@tonic-gate 	ASSERT(MUTEX_NOT_HELD(page_vnode_mutex(pp->p_vnode)));
36310Sstevel@tonic-gate 
36320Sstevel@tonic-gate 	vp = pp->p_vnode;
36330Sstevel@tonic-gate 
36340Sstevel@tonic-gate 	TRACE_2(TR_FAC_VM, TR_PAGE_HASHOUT,
36353559Smec 	    "page_hashout:pp %p vp %p", pp, vp);
36360Sstevel@tonic-gate 
36370Sstevel@tonic-gate 	/* Kernel probe */
36380Sstevel@tonic-gate 	TNF_PROBE_2(page_unmap, "vm pagefault", /* CSTYLED */,
36390Sstevel@tonic-gate 	    tnf_opaque, vnode, vp,
36400Sstevel@tonic-gate 	    tnf_offset, offset, pp->p_offset);
36410Sstevel@tonic-gate 
36420Sstevel@tonic-gate 	/*
36430Sstevel@tonic-gate 	 *
36440Sstevel@tonic-gate 	 */
36450Sstevel@tonic-gate 	VM_STAT_ADD(hashout_count);
36460Sstevel@tonic-gate 	index = PAGE_HASH_FUNC(vp, pp->p_offset);
36470Sstevel@tonic-gate 	if (phm == NULL) {
36480Sstevel@tonic-gate 		VM_STAT_ADD(hashout_not_held);
36490Sstevel@tonic-gate 		nphm = PAGE_HASH_MUTEX(index);
36500Sstevel@tonic-gate 		mutex_enter(nphm);
36510Sstevel@tonic-gate 	}
36520Sstevel@tonic-gate 	ASSERT(phm ? phm == PAGE_HASH_MUTEX(index) : 1);
36530Sstevel@tonic-gate 
36540Sstevel@tonic-gate 
36550Sstevel@tonic-gate 	/*
36560Sstevel@tonic-gate 	 * grab page vnode mutex and remove it...
36570Sstevel@tonic-gate 	 */
36580Sstevel@tonic-gate 	vphm = page_vnode_mutex(vp);
36590Sstevel@tonic-gate 	mutex_enter(vphm);
36600Sstevel@tonic-gate 
36610Sstevel@tonic-gate 	page_do_hashout(pp);
36620Sstevel@tonic-gate 
36630Sstevel@tonic-gate 	mutex_exit(vphm);
36640Sstevel@tonic-gate 	if (phm == NULL)
36650Sstevel@tonic-gate 		mutex_exit(nphm);
36660Sstevel@tonic-gate 
36670Sstevel@tonic-gate 	/*
36680Sstevel@tonic-gate 	 * Wake up processes waiting for this page.  The page's
36690Sstevel@tonic-gate 	 * identity has been changed, and is probably not the
36700Sstevel@tonic-gate 	 * desired page any longer.
36710Sstevel@tonic-gate 	 */
36720Sstevel@tonic-gate 	sep = page_se_mutex(pp);
36730Sstevel@tonic-gate 	mutex_enter(sep);
3674800Sstans 	pp->p_selock &= ~SE_EWANTED;
36750Sstevel@tonic-gate 	if (CV_HAS_WAITERS(&pp->p_cv))
36760Sstevel@tonic-gate 		cv_broadcast(&pp->p_cv);
36770Sstevel@tonic-gate 	mutex_exit(sep);
36780Sstevel@tonic-gate }
36790Sstevel@tonic-gate 
36800Sstevel@tonic-gate /*
36810Sstevel@tonic-gate  * Add the page to the front of a linked list of pages
36820Sstevel@tonic-gate  * using the p_next & p_prev pointers for the list.
36830Sstevel@tonic-gate  * The caller is responsible for protecting the list pointers.
36840Sstevel@tonic-gate  */
36850Sstevel@tonic-gate void
36860Sstevel@tonic-gate page_add(page_t **ppp, page_t *pp)
36870Sstevel@tonic-gate {
36880Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp) || (PAGE_SHARED(pp) && page_iolock_assert(pp)));
36890Sstevel@tonic-gate 
36900Sstevel@tonic-gate 	page_add_common(ppp, pp);
36910Sstevel@tonic-gate }
36920Sstevel@tonic-gate 
36930Sstevel@tonic-gate 
36940Sstevel@tonic-gate 
36950Sstevel@tonic-gate /*
36960Sstevel@tonic-gate  *  Common code for page_add() and mach_page_add()
36970Sstevel@tonic-gate  */
36980Sstevel@tonic-gate void
36990Sstevel@tonic-gate page_add_common(page_t **ppp, page_t *pp)
37000Sstevel@tonic-gate {
37010Sstevel@tonic-gate 	if (*ppp == NULL) {
37020Sstevel@tonic-gate 		pp->p_next = pp->p_prev = pp;
37030Sstevel@tonic-gate 	} else {
37040Sstevel@tonic-gate 		pp->p_next = *ppp;
37050Sstevel@tonic-gate 		pp->p_prev = (*ppp)->p_prev;
37060Sstevel@tonic-gate 		(*ppp)->p_prev = pp;
37070Sstevel@tonic-gate 		pp->p_prev->p_next = pp;
37080Sstevel@tonic-gate 	}
37090Sstevel@tonic-gate 	*ppp = pp;
37100Sstevel@tonic-gate }
37110Sstevel@tonic-gate 
37120Sstevel@tonic-gate 
37130Sstevel@tonic-gate /*
37140Sstevel@tonic-gate  * Remove this page from a linked list of pages
37150Sstevel@tonic-gate  * using the p_next & p_prev pointers for the list.
37160Sstevel@tonic-gate  *
37170Sstevel@tonic-gate  * The caller is responsible for protecting the list pointers.
37180Sstevel@tonic-gate  */
37190Sstevel@tonic-gate void
37200Sstevel@tonic-gate page_sub(page_t **ppp, page_t *pp)
37210Sstevel@tonic-gate {
37220Sstevel@tonic-gate 	ASSERT((PP_ISFREE(pp)) ? 1 :
37230Sstevel@tonic-gate 	    (PAGE_EXCL(pp)) || (PAGE_SHARED(pp) && page_iolock_assert(pp)));
37240Sstevel@tonic-gate 
37250Sstevel@tonic-gate 	if (*ppp == NULL || pp == NULL) {
37260Sstevel@tonic-gate 		panic("page_sub: bad arg(s): pp %p, *ppp %p",
37270Sstevel@tonic-gate 		    (void *)pp, (void *)(*ppp));
37280Sstevel@tonic-gate 		/*NOTREACHED*/
37290Sstevel@tonic-gate 	}
37300Sstevel@tonic-gate 
37310Sstevel@tonic-gate 	page_sub_common(ppp, pp);
37320Sstevel@tonic-gate }
37330Sstevel@tonic-gate 
37340Sstevel@tonic-gate 
37350Sstevel@tonic-gate /*
37360Sstevel@tonic-gate  *  Common code for page_sub() and mach_page_sub()
37370Sstevel@tonic-gate  */
37380Sstevel@tonic-gate void
37390Sstevel@tonic-gate page_sub_common(page_t **ppp, page_t *pp)
37400Sstevel@tonic-gate {
37410Sstevel@tonic-gate 	if (*ppp == pp)
37420Sstevel@tonic-gate 		*ppp = pp->p_next;		/* go to next page */
37430Sstevel@tonic-gate 
37440Sstevel@tonic-gate 	if (*ppp == pp)
37450Sstevel@tonic-gate 		*ppp = NULL;			/* page list is gone */
37460Sstevel@tonic-gate 	else {
37470Sstevel@tonic-gate 		pp->p_prev->p_next = pp->p_next;
37480Sstevel@tonic-gate 		pp->p_next->p_prev = pp->p_prev;
37490Sstevel@tonic-gate 	}
37500Sstevel@tonic-gate 	pp->p_prev = pp->p_next = pp;		/* make pp a list of one */
37510Sstevel@tonic-gate }
37520Sstevel@tonic-gate 
37530Sstevel@tonic-gate 
37540Sstevel@tonic-gate /*
37550Sstevel@tonic-gate  * Break page list cppp into two lists with npages in the first list.
37560Sstevel@tonic-gate  * The tail is returned in nppp.
37570Sstevel@tonic-gate  */
37580Sstevel@tonic-gate void
37590Sstevel@tonic-gate page_list_break(page_t **oppp, page_t **nppp, pgcnt_t npages)
37600Sstevel@tonic-gate {
37610Sstevel@tonic-gate 	page_t *s1pp = *oppp;
37620Sstevel@tonic-gate 	page_t *s2pp;
37630Sstevel@tonic-gate 	page_t *e1pp, *e2pp;
37640Sstevel@tonic-gate 	long n = 0;
37650Sstevel@tonic-gate 
37660Sstevel@tonic-gate 	if (s1pp == NULL) {
37670Sstevel@tonic-gate 		*nppp = NULL;
37680Sstevel@tonic-gate 		return;
37690Sstevel@tonic-gate 	}
37700Sstevel@tonic-gate 	if (npages == 0) {
37710Sstevel@tonic-gate 		*nppp = s1pp;
37720Sstevel@tonic-gate 		*oppp = NULL;
37730Sstevel@tonic-gate 		return;
37740Sstevel@tonic-gate 	}
37750Sstevel@tonic-gate 	for (n = 0, s2pp = *oppp; n < npages; n++) {
37760Sstevel@tonic-gate 		s2pp = s2pp->p_next;
37770Sstevel@tonic-gate 	}
37780Sstevel@tonic-gate 	/* Fix head and tail of new lists */
37790Sstevel@tonic-gate 	e1pp = s2pp->p_prev;
37800Sstevel@tonic-gate 	e2pp = s1pp->p_prev;
37810Sstevel@tonic-gate 	s1pp->p_prev = e1pp;
37820Sstevel@tonic-gate 	e1pp->p_next = s1pp;
37830Sstevel@tonic-gate 	s2pp->p_prev = e2pp;
37840Sstevel@tonic-gate 	e2pp->p_next = s2pp;
37850Sstevel@tonic-gate 
37860Sstevel@tonic-gate 	/* second list empty */
37870Sstevel@tonic-gate 	if (s2pp == s1pp) {
37880Sstevel@tonic-gate 		*oppp = s1pp;
37890Sstevel@tonic-gate 		*nppp = NULL;
37900Sstevel@tonic-gate 	} else {
37910Sstevel@tonic-gate 		*oppp = s1pp;
37920Sstevel@tonic-gate 		*nppp = s2pp;
37930Sstevel@tonic-gate 	}
37940Sstevel@tonic-gate }
37950Sstevel@tonic-gate 
37960Sstevel@tonic-gate /*
37970Sstevel@tonic-gate  * Concatenate page list nppp onto the end of list ppp.
37980Sstevel@tonic-gate  */
37990Sstevel@tonic-gate void
38000Sstevel@tonic-gate page_list_concat(page_t **ppp, page_t **nppp)
38010Sstevel@tonic-gate {
38020Sstevel@tonic-gate 	page_t *s1pp, *s2pp, *e1pp, *e2pp;
38030Sstevel@tonic-gate 
38040Sstevel@tonic-gate 	if (*nppp == NULL) {
38050Sstevel@tonic-gate 		return;
38060Sstevel@tonic-gate 	}
38070Sstevel@tonic-gate 	if (*ppp == NULL) {
38080Sstevel@tonic-gate 		*ppp = *nppp;
38090Sstevel@tonic-gate 		return;
38100Sstevel@tonic-gate 	}
38110Sstevel@tonic-gate 	s1pp = *ppp;
38120Sstevel@tonic-gate 	e1pp =  s1pp->p_prev;
38130Sstevel@tonic-gate 	s2pp = *nppp;
38140Sstevel@tonic-gate 	e2pp = s2pp->p_prev;
38150Sstevel@tonic-gate 	s1pp->p_prev = e2pp;
38160Sstevel@tonic-gate 	e2pp->p_next = s1pp;
38170Sstevel@tonic-gate 	e1pp->p_next = s2pp;
38180Sstevel@tonic-gate 	s2pp->p_prev = e1pp;
38190Sstevel@tonic-gate }
38200Sstevel@tonic-gate 
38210Sstevel@tonic-gate /*
38220Sstevel@tonic-gate  * return the next page in the page list
38230Sstevel@tonic-gate  */
38240Sstevel@tonic-gate page_t *
38250Sstevel@tonic-gate page_list_next(page_t *pp)
38260Sstevel@tonic-gate {
38270Sstevel@tonic-gate 	return (pp->p_next);
38280Sstevel@tonic-gate }
38290Sstevel@tonic-gate 
38300Sstevel@tonic-gate 
38310Sstevel@tonic-gate /*
38320Sstevel@tonic-gate  * Add the page to the front of the linked list of pages
38330Sstevel@tonic-gate  * using p_vpnext/p_vpprev pointers for the list.
38340Sstevel@tonic-gate  *
38350Sstevel@tonic-gate  * The caller is responsible for protecting the lists.
38360Sstevel@tonic-gate  */
38370Sstevel@tonic-gate void
38380Sstevel@tonic-gate page_vpadd(page_t **ppp, page_t *pp)
38390Sstevel@tonic-gate {
38400Sstevel@tonic-gate 	if (*ppp == NULL) {
38410Sstevel@tonic-gate 		pp->p_vpnext = pp->p_vpprev = pp;
38420Sstevel@tonic-gate 	} else {
38430Sstevel@tonic-gate 		pp->p_vpnext = *ppp;
38440Sstevel@tonic-gate 		pp->p_vpprev = (*ppp)->p_vpprev;
38450Sstevel@tonic-gate 		(*ppp)->p_vpprev = pp;
38460Sstevel@tonic-gate 		pp->p_vpprev->p_vpnext = pp;
38470Sstevel@tonic-gate 	}
38480Sstevel@tonic-gate 	*ppp = pp;
38490Sstevel@tonic-gate }
38500Sstevel@tonic-gate 
38510Sstevel@tonic-gate /*
38520Sstevel@tonic-gate  * Remove this page from the linked list of pages
38530Sstevel@tonic-gate  * using p_vpnext/p_vpprev pointers for the list.
38540Sstevel@tonic-gate  *
38550Sstevel@tonic-gate  * The caller is responsible for protecting the lists.
38560Sstevel@tonic-gate  */
38570Sstevel@tonic-gate void
38580Sstevel@tonic-gate page_vpsub(page_t **ppp, page_t *pp)
38590Sstevel@tonic-gate {
38600Sstevel@tonic-gate 	if (*ppp == NULL || pp == NULL) {
38610Sstevel@tonic-gate 		panic("page_vpsub: bad arg(s): pp %p, *ppp %p",
38620Sstevel@tonic-gate 		    (void *)pp, (void *)(*ppp));
38630Sstevel@tonic-gate 		/*NOTREACHED*/
38640Sstevel@tonic-gate 	}
38650Sstevel@tonic-gate 
38660Sstevel@tonic-gate 	if (*ppp == pp)
38670Sstevel@tonic-gate 		*ppp = pp->p_vpnext;		/* go to next page */
38680Sstevel@tonic-gate 
38690Sstevel@tonic-gate 	if (*ppp == pp)
38700Sstevel@tonic-gate 		*ppp = NULL;			/* page list is gone */
38710Sstevel@tonic-gate 	else {
38720Sstevel@tonic-gate 		pp->p_vpprev->p_vpnext = pp->p_vpnext;
38730Sstevel@tonic-gate 		pp->p_vpnext->p_vpprev = pp->p_vpprev;
38740Sstevel@tonic-gate 	}
38750Sstevel@tonic-gate 	pp->p_vpprev = pp->p_vpnext = pp;	/* make pp a list of one */
38760Sstevel@tonic-gate }
38770Sstevel@tonic-gate 
38780Sstevel@tonic-gate /*
38790Sstevel@tonic-gate  * Lock a physical page into memory "long term".  Used to support "lock
38800Sstevel@tonic-gate  * in memory" functions.  Accepts the page to be locked, and a cow variable
38810Sstevel@tonic-gate  * to indicate whether a the lock will travel to the new page during
38820Sstevel@tonic-gate  * a potential copy-on-write.
38830Sstevel@tonic-gate  */
38840Sstevel@tonic-gate int
38850Sstevel@tonic-gate page_pp_lock(
38860Sstevel@tonic-gate 	page_t *pp,			/* page to be locked */
38870Sstevel@tonic-gate 	int cow,			/* cow lock */
38880Sstevel@tonic-gate 	int kernel)			/* must succeed -- ignore checking */
38890Sstevel@tonic-gate {
38900Sstevel@tonic-gate 	int r = 0;			/* result -- assume failure */
38910Sstevel@tonic-gate 
38920Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp));
38930Sstevel@tonic-gate 
38940Sstevel@tonic-gate 	page_struct_lock(pp);
38950Sstevel@tonic-gate 	/*
38960Sstevel@tonic-gate 	 * Acquire the "freemem_lock" for availrmem.
38970Sstevel@tonic-gate 	 */
38980Sstevel@tonic-gate 	if (cow) {
38990Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
39000Sstevel@tonic-gate 		if ((availrmem > pages_pp_maximum) &&
39010Sstevel@tonic-gate 		    (pp->p_cowcnt < (ushort_t)PAGE_LOCK_MAXIMUM)) {
39020Sstevel@tonic-gate 			availrmem--;
39030Sstevel@tonic-gate 			pages_locked++;
39040Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
39050Sstevel@tonic-gate 			r = 1;
39060Sstevel@tonic-gate 			if (++pp->p_cowcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
39070Sstevel@tonic-gate 				cmn_err(CE_WARN,
39080Sstevel@tonic-gate 				    "COW lock limit reached on pfn 0x%lx",
39090Sstevel@tonic-gate 				    page_pptonum(pp));
39100Sstevel@tonic-gate 			}
39110Sstevel@tonic-gate 		} else
39120Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
39130Sstevel@tonic-gate 	} else {
39140Sstevel@tonic-gate 		if (pp->p_lckcnt) {
39150Sstevel@tonic-gate 			if (pp->p_lckcnt < (ushort_t)PAGE_LOCK_MAXIMUM) {
39160Sstevel@tonic-gate 				r = 1;
39170Sstevel@tonic-gate 				if (++pp->p_lckcnt ==
39180Sstevel@tonic-gate 				    (ushort_t)PAGE_LOCK_MAXIMUM) {
39190Sstevel@tonic-gate 					cmn_err(CE_WARN, "Page lock limit "
39200Sstevel@tonic-gate 					    "reached on pfn 0x%lx",
39210Sstevel@tonic-gate 					    page_pptonum(pp));
39220Sstevel@tonic-gate 				}
39230Sstevel@tonic-gate 			}
39240Sstevel@tonic-gate 		} else {
39250Sstevel@tonic-gate 			if (kernel) {
39260Sstevel@tonic-gate 				/* availrmem accounting done by caller */
39270Sstevel@tonic-gate 				++pp->p_lckcnt;
39280Sstevel@tonic-gate 				r = 1;
39290Sstevel@tonic-gate 			} else {
39300Sstevel@tonic-gate 				mutex_enter(&freemem_lock);
39310Sstevel@tonic-gate 				if (availrmem > pages_pp_maximum) {
39320Sstevel@tonic-gate 					availrmem--;
39330Sstevel@tonic-gate 					pages_locked++;
39340Sstevel@tonic-gate 					++pp->p_lckcnt;
39350Sstevel@tonic-gate 					r = 1;
39360Sstevel@tonic-gate 				}
39370Sstevel@tonic-gate 				mutex_exit(&freemem_lock);
39380Sstevel@tonic-gate 			}
39390Sstevel@tonic-gate 		}
39400Sstevel@tonic-gate 	}
39410Sstevel@tonic-gate 	page_struct_unlock(pp);
39420Sstevel@tonic-gate 	return (r);
39430Sstevel@tonic-gate }
39440Sstevel@tonic-gate 
39450Sstevel@tonic-gate /*
39460Sstevel@tonic-gate  * Decommit a lock on a physical page frame.  Account for cow locks if
39470Sstevel@tonic-gate  * appropriate.
39480Sstevel@tonic-gate  */
39490Sstevel@tonic-gate void
39500Sstevel@tonic-gate page_pp_unlock(
39510Sstevel@tonic-gate 	page_t *pp,			/* page to be unlocked */
39520Sstevel@tonic-gate 	int cow,			/* expect cow lock */
39530Sstevel@tonic-gate 	int kernel)			/* this was a kernel lock */
39540Sstevel@tonic-gate {
39550Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp));
39560Sstevel@tonic-gate 
39570Sstevel@tonic-gate 	page_struct_lock(pp);
39580Sstevel@tonic-gate 	/*
39590Sstevel@tonic-gate 	 * Acquire the "freemem_lock" for availrmem.
39600Sstevel@tonic-gate 	 * If cowcnt or lcknt is already 0 do nothing; i.e., we
39610Sstevel@tonic-gate 	 * could be called to unlock even if nothing is locked. This could
39620Sstevel@tonic-gate 	 * happen if locked file pages were truncated (removing the lock)
39630Sstevel@tonic-gate 	 * and the file was grown again and new pages faulted in; the new
39640Sstevel@tonic-gate 	 * pages are unlocked but the segment still thinks they're locked.
39650Sstevel@tonic-gate 	 */
39660Sstevel@tonic-gate 	if (cow) {
39670Sstevel@tonic-gate 		if (pp->p_cowcnt) {
39680Sstevel@tonic-gate 			mutex_enter(&freemem_lock);
39690Sstevel@tonic-gate 			pp->p_cowcnt--;
39700Sstevel@tonic-gate 			availrmem++;
39710Sstevel@tonic-gate 			pages_locked--;
39720Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
39730Sstevel@tonic-gate 		}
39740Sstevel@tonic-gate 	} else {
39750Sstevel@tonic-gate 		if (pp->p_lckcnt && --pp->p_lckcnt == 0) {
39760Sstevel@tonic-gate 			if (!kernel) {
39770Sstevel@tonic-gate 				mutex_enter(&freemem_lock);
39780Sstevel@tonic-gate 				availrmem++;
39790Sstevel@tonic-gate 				pages_locked--;
39800Sstevel@tonic-gate 				mutex_exit(&freemem_lock);
39810Sstevel@tonic-gate 			}
39820Sstevel@tonic-gate 		}
39830Sstevel@tonic-gate 	}
39840Sstevel@tonic-gate 	page_struct_unlock(pp);
39850Sstevel@tonic-gate }
39860Sstevel@tonic-gate 
39870Sstevel@tonic-gate /*
39880Sstevel@tonic-gate  * This routine reserves availrmem for npages;
39890Sstevel@tonic-gate  * 	flags: KM_NOSLEEP or KM_SLEEP
39900Sstevel@tonic-gate  * 	returns 1 on success or 0 on failure
39910Sstevel@tonic-gate  */
39920Sstevel@tonic-gate int
39930Sstevel@tonic-gate page_resv(pgcnt_t npages, uint_t flags)
39940Sstevel@tonic-gate {
39950Sstevel@tonic-gate 	mutex_enter(&freemem_lock);
39960Sstevel@tonic-gate 	while (availrmem < tune.t_minarmem + npages) {
39970Sstevel@tonic-gate 		if (flags & KM_NOSLEEP) {
39980Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
39990Sstevel@tonic-gate 			return (0);
40000Sstevel@tonic-gate 		}
40010Sstevel@tonic-gate 		mutex_exit(&freemem_lock);
40020Sstevel@tonic-gate 		page_needfree(npages);
40030Sstevel@tonic-gate 		kmem_reap();
40040Sstevel@tonic-gate 		delay(hz >> 2);
40050Sstevel@tonic-gate 		page_needfree(-(spgcnt_t)npages);
40060Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
40070Sstevel@tonic-gate 	}
40080Sstevel@tonic-gate 	availrmem -= npages;
40090Sstevel@tonic-gate 	mutex_exit(&freemem_lock);
40100Sstevel@tonic-gate 	return (1);
40110Sstevel@tonic-gate }
40120Sstevel@tonic-gate 
40130Sstevel@tonic-gate /*
40140Sstevel@tonic-gate  * This routine unreserves availrmem for npages;
40150Sstevel@tonic-gate  */
40160Sstevel@tonic-gate void
40170Sstevel@tonic-gate page_unresv(pgcnt_t npages)
40180Sstevel@tonic-gate {
40190Sstevel@tonic-gate 	mutex_enter(&freemem_lock);
40200Sstevel@tonic-gate 	availrmem += npages;
40210Sstevel@tonic-gate 	mutex_exit(&freemem_lock);
40220Sstevel@tonic-gate }
40230Sstevel@tonic-gate 
40240Sstevel@tonic-gate /*
40250Sstevel@tonic-gate  * See Statement at the beginning of segvn_lockop() regarding
40260Sstevel@tonic-gate  * the way we handle cowcnts and lckcnts.
40270Sstevel@tonic-gate  *
40280Sstevel@tonic-gate  * Transfer cowcnt on 'opp' to cowcnt on 'npp' if the vpage
40290Sstevel@tonic-gate  * that breaks COW has PROT_WRITE.
40300Sstevel@tonic-gate  *
40310Sstevel@tonic-gate  * Note that, we may also break COW in case we are softlocking
40320Sstevel@tonic-gate  * on read access during physio;
40330Sstevel@tonic-gate  * in this softlock case, the vpage may not have PROT_WRITE.
40340Sstevel@tonic-gate  * So, we need to transfer lckcnt on 'opp' to lckcnt on 'npp'
40350Sstevel@tonic-gate  * if the vpage doesn't have PROT_WRITE.
40360Sstevel@tonic-gate  *
40370Sstevel@tonic-gate  * This routine is never called if we are stealing a page
40380Sstevel@tonic-gate  * in anon_private.
40390Sstevel@tonic-gate  *
40400Sstevel@tonic-gate  * The caller subtracted from availrmem for read only mapping.
40410Sstevel@tonic-gate  * if lckcnt is 1 increment availrmem.
40420Sstevel@tonic-gate  */
40430Sstevel@tonic-gate void
40440Sstevel@tonic-gate page_pp_useclaim(
40450Sstevel@tonic-gate 	page_t *opp,		/* original page frame losing lock */
40460Sstevel@tonic-gate 	page_t *npp,		/* new page frame gaining lock */
40470Sstevel@tonic-gate 	uint_t	write_perm) 	/* set if vpage has PROT_WRITE */
40480Sstevel@tonic-gate {
40490Sstevel@tonic-gate 	int payback = 0;
40500Sstevel@tonic-gate 
40510Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(opp));
40520Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(npp));
40530Sstevel@tonic-gate 
40540Sstevel@tonic-gate 	page_struct_lock(opp);
40550Sstevel@tonic-gate 
40560Sstevel@tonic-gate 	ASSERT(npp->p_cowcnt == 0);
40570Sstevel@tonic-gate 	ASSERT(npp->p_lckcnt == 0);
40580Sstevel@tonic-gate 
40590Sstevel@tonic-gate 	/* Don't use claim if nothing is locked (see page_pp_unlock above) */
40600Sstevel@tonic-gate 	if ((write_perm && opp->p_cowcnt != 0) ||
40610Sstevel@tonic-gate 	    (!write_perm && opp->p_lckcnt != 0)) {
40620Sstevel@tonic-gate 
40630Sstevel@tonic-gate 		if (write_perm) {
40640Sstevel@tonic-gate 			npp->p_cowcnt++;
40650Sstevel@tonic-gate 			ASSERT(opp->p_cowcnt != 0);
40660Sstevel@tonic-gate 			opp->p_cowcnt--;
40670Sstevel@tonic-gate 		} else {
40680Sstevel@tonic-gate 
40690Sstevel@tonic-gate 			ASSERT(opp->p_lckcnt != 0);
40700Sstevel@tonic-gate 
40710Sstevel@tonic-gate 			/*
40720Sstevel@tonic-gate 			 * We didn't need availrmem decremented if p_lckcnt on
40730Sstevel@tonic-gate 			 * original page is 1. Here, we are unlocking
40740Sstevel@tonic-gate 			 * read-only copy belonging to original page and
40750Sstevel@tonic-gate 			 * are locking a copy belonging to new page.
40760Sstevel@tonic-gate 			 */
40770Sstevel@tonic-gate 			if (opp->p_lckcnt == 1)
40780Sstevel@tonic-gate 				payback = 1;
40790Sstevel@tonic-gate 
40800Sstevel@tonic-gate 			npp->p_lckcnt++;
40810Sstevel@tonic-gate 			opp->p_lckcnt--;
40820Sstevel@tonic-gate 		}
40830Sstevel@tonic-gate 	}
40840Sstevel@tonic-gate 	if (payback) {
40850Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
40860Sstevel@tonic-gate 		availrmem++;
40870Sstevel@tonic-gate 		pages_useclaim--;
40880Sstevel@tonic-gate 		mutex_exit(&freemem_lock);
40890Sstevel@tonic-gate 	}
40900Sstevel@tonic-gate 	page_struct_unlock(opp);
40910Sstevel@tonic-gate }
40920Sstevel@tonic-gate 
40930Sstevel@tonic-gate /*
40940Sstevel@tonic-gate  * Simple claim adjust functions -- used to support changes in
40950Sstevel@tonic-gate  * claims due to changes in access permissions.  Used by segvn_setprot().
40960Sstevel@tonic-gate  */
40970Sstevel@tonic-gate int
40980Sstevel@tonic-gate page_addclaim(page_t *pp)
40990Sstevel@tonic-gate {
41000Sstevel@tonic-gate 	int r = 0;			/* result */
41010Sstevel@tonic-gate 
41020Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp));
41030Sstevel@tonic-gate 
41040Sstevel@tonic-gate 	page_struct_lock(pp);
41050Sstevel@tonic-gate 	ASSERT(pp->p_lckcnt != 0);
41060Sstevel@tonic-gate 
41070Sstevel@tonic-gate 	if (pp->p_lckcnt == 1) {
41080Sstevel@tonic-gate 		if (pp->p_cowcnt < (ushort_t)PAGE_LOCK_MAXIMUM) {
41090Sstevel@tonic-gate 			--pp->p_lckcnt;
41100Sstevel@tonic-gate 			r = 1;
41110Sstevel@tonic-gate 			if (++pp->p_cowcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
41120Sstevel@tonic-gate 				cmn_err(CE_WARN,
41130Sstevel@tonic-gate 				    "COW lock limit reached on pfn 0x%lx",
41140Sstevel@tonic-gate 				    page_pptonum(pp));
41150Sstevel@tonic-gate 			}
41160Sstevel@tonic-gate 		}
41170Sstevel@tonic-gate 	} else {
41180Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
41190Sstevel@tonic-gate 		if ((availrmem > pages_pp_maximum) &&
41200Sstevel@tonic-gate 		    (pp->p_cowcnt < (ushort_t)PAGE_LOCK_MAXIMUM)) {
41210Sstevel@tonic-gate 			--availrmem;
41220Sstevel@tonic-gate 			++pages_claimed;
41230Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
41240Sstevel@tonic-gate 			--pp->p_lckcnt;
41250Sstevel@tonic-gate 			r = 1;
41260Sstevel@tonic-gate 			if (++pp->p_cowcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
41270Sstevel@tonic-gate 				cmn_err(CE_WARN,
41280Sstevel@tonic-gate 				    "COW lock limit reached on pfn 0x%lx",
41290Sstevel@tonic-gate 				    page_pptonum(pp));
41300Sstevel@tonic-gate 			}
41310Sstevel@tonic-gate 		} else
41320Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
41330Sstevel@tonic-gate 	}
41340Sstevel@tonic-gate 	page_struct_unlock(pp);
41350Sstevel@tonic-gate 	return (r);
41360Sstevel@tonic-gate }
41370Sstevel@tonic-gate 
41380Sstevel@tonic-gate int
41390Sstevel@tonic-gate page_subclaim(page_t *pp)
41400Sstevel@tonic-gate {
41410Sstevel@tonic-gate 	int r = 0;
41420Sstevel@tonic-gate 
41430Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp));
41440Sstevel@tonic-gate 
41450Sstevel@tonic-gate 	page_struct_lock(pp);
41460Sstevel@tonic-gate 	ASSERT(pp->p_cowcnt != 0);
41470Sstevel@tonic-gate 
41480Sstevel@tonic-gate 	if (pp->p_lckcnt) {
41490Sstevel@tonic-gate 		if (pp->p_lckcnt < (ushort_t)PAGE_LOCK_MAXIMUM) {
41500Sstevel@tonic-gate 			r = 1;
41510Sstevel@tonic-gate 			/*
41520Sstevel@tonic-gate 			 * for availrmem
41530Sstevel@tonic-gate 			 */
41540Sstevel@tonic-gate 			mutex_enter(&freemem_lock);
41550Sstevel@tonic-gate 			availrmem++;
41560Sstevel@tonic-gate 			pages_claimed--;
41570Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
41580Sstevel@tonic-gate 
41590Sstevel@tonic-gate 			pp->p_cowcnt--;
41600Sstevel@tonic-gate 
41610Sstevel@tonic-gate 			if (++pp->p_lckcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
41620Sstevel@tonic-gate 				cmn_err(CE_WARN,
41630Sstevel@tonic-gate 				    "Page lock limit reached on pfn 0x%lx",
41640Sstevel@tonic-gate 				    page_pptonum(pp));
41650Sstevel@tonic-gate 			}
41660Sstevel@tonic-gate 		}
41670Sstevel@tonic-gate 	} else {
41680Sstevel@tonic-gate 		r = 1;
41690Sstevel@tonic-gate 		pp->p_cowcnt--;
41700Sstevel@tonic-gate 		pp->p_lckcnt++;
41710Sstevel@tonic-gate 	}
41720Sstevel@tonic-gate 	page_struct_unlock(pp);
41730Sstevel@tonic-gate 	return (r);
41740Sstevel@tonic-gate }
41750Sstevel@tonic-gate 
41760Sstevel@tonic-gate int
41770Sstevel@tonic-gate page_addclaim_pages(page_t  **ppa)
41780Sstevel@tonic-gate {
41790Sstevel@tonic-gate 
41800Sstevel@tonic-gate 	pgcnt_t	lckpgs = 0, pg_idx;
41810Sstevel@tonic-gate 
41820Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_addclaim_pages);
41830Sstevel@tonic-gate 
41840Sstevel@tonic-gate 	mutex_enter(&page_llock);
41850Sstevel@tonic-gate 	for (pg_idx = 0; ppa[pg_idx] != NULL; pg_idx++) {
41860Sstevel@tonic-gate 
41870Sstevel@tonic-gate 		ASSERT(PAGE_LOCKED(ppa[pg_idx]));
41880Sstevel@tonic-gate 		ASSERT(ppa[pg_idx]->p_lckcnt != 0);
41890Sstevel@tonic-gate 		if (ppa[pg_idx]->p_cowcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
41900Sstevel@tonic-gate 			mutex_exit(&page_llock);
41910Sstevel@tonic-gate 			return (0);
41920Sstevel@tonic-gate 		}
41930Sstevel@tonic-gate 		if (ppa[pg_idx]->p_lckcnt > 1)
41940Sstevel@tonic-gate 			lckpgs++;
41950Sstevel@tonic-gate 	}
41960Sstevel@tonic-gate 
41970Sstevel@tonic-gate 	if (lckpgs != 0) {
41980Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
41990Sstevel@tonic-gate 		if (availrmem >= pages_pp_maximum + lckpgs) {
42000Sstevel@tonic-gate 			availrmem -= lckpgs;
42010Sstevel@tonic-gate 			pages_claimed += lckpgs;
42020Sstevel@tonic-gate 		} else {
42030Sstevel@tonic-gate 			mutex_exit(&freemem_lock);
42040Sstevel@tonic-gate 			mutex_exit(&page_llock);
42050Sstevel@tonic-gate 			return (0);
42060Sstevel@tonic-gate 		}
42070Sstevel@tonic-gate 		mutex_exit(&freemem_lock);
42080Sstevel@tonic-gate 	}
42090Sstevel@tonic-gate 
42100Sstevel@tonic-gate 	for (pg_idx = 0; ppa[pg_idx] != NULL; pg_idx++) {
42110Sstevel@tonic-gate 		ppa[pg_idx]->p_lckcnt--;
42120Sstevel@tonic-gate 		ppa[pg_idx]->p_cowcnt++;
42130Sstevel@tonic-gate 	}
42140Sstevel@tonic-gate 	mutex_exit(&page_llock);
42150Sstevel@tonic-gate 	return (1);
42160Sstevel@tonic-gate }
42170Sstevel@tonic-gate 
42180Sstevel@tonic-gate int
42190Sstevel@tonic-gate page_subclaim_pages(page_t  **ppa)
42200Sstevel@tonic-gate {
42210Sstevel@tonic-gate 	pgcnt_t	ulckpgs = 0, pg_idx;
42220Sstevel@tonic-gate 
42230Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_subclaim_pages);
42240Sstevel@tonic-gate 
42250Sstevel@tonic-gate 	mutex_enter(&page_llock);
42260Sstevel@tonic-gate 	for (pg_idx = 0; ppa[pg_idx] != NULL; pg_idx++) {
42270Sstevel@tonic-gate 
42280Sstevel@tonic-gate 		ASSERT(PAGE_LOCKED(ppa[pg_idx]));
42290Sstevel@tonic-gate 		ASSERT(ppa[pg_idx]->p_cowcnt != 0);
42300Sstevel@tonic-gate 		if (ppa[pg_idx]->p_lckcnt == (ushort_t)PAGE_LOCK_MAXIMUM) {
42310Sstevel@tonic-gate 			mutex_exit(&page_llock);
42320Sstevel@tonic-gate 			return (0);
42330Sstevel@tonic-gate 		}
42340Sstevel@tonic-gate 		if (ppa[pg_idx]->p_lckcnt != 0)
42350Sstevel@tonic-gate 			ulckpgs++;
42360Sstevel@tonic-gate 	}
42370Sstevel@tonic-gate 
42380Sstevel@tonic-gate 	if (ulckpgs != 0) {
42390Sstevel@tonic-gate 		mutex_enter(&freemem_lock);
42400Sstevel@tonic-gate 		availrmem += ulckpgs;
42410Sstevel@tonic-gate 		pages_claimed -= ulckpgs;
42420Sstevel@tonic-gate 		mutex_exit(&freemem_lock);
42430Sstevel@tonic-gate 	}
42440Sstevel@tonic-gate 
42450Sstevel@tonic-gate 	for (pg_idx = 0; ppa[pg_idx] != NULL; pg_idx++) {
42460Sstevel@tonic-gate 		ppa[pg_idx]->p_cowcnt--;
42470Sstevel@tonic-gate 		ppa[pg_idx]->p_lckcnt++;
42480Sstevel@tonic-gate 
42490Sstevel@tonic-gate 	}
42500Sstevel@tonic-gate 	mutex_exit(&page_llock);
42510Sstevel@tonic-gate 	return (1);
42520Sstevel@tonic-gate }
42530Sstevel@tonic-gate 
42540Sstevel@tonic-gate page_t *
42550Sstevel@tonic-gate page_numtopp(pfn_t pfnum, se_t se)
42560Sstevel@tonic-gate {
42570Sstevel@tonic-gate 	page_t *pp;
42580Sstevel@tonic-gate 
42590Sstevel@tonic-gate retry:
42600Sstevel@tonic-gate 	pp = page_numtopp_nolock(pfnum);
42610Sstevel@tonic-gate 	if (pp == NULL) {
42620Sstevel@tonic-gate 		return ((page_t *)NULL);
42630Sstevel@tonic-gate 	}
42640Sstevel@tonic-gate 
42650Sstevel@tonic-gate 	/*
42660Sstevel@tonic-gate 	 * Acquire the appropriate lock on the page.
42670Sstevel@tonic-gate 	 */
42680Sstevel@tonic-gate 	while (!page_lock(pp, se, (kmutex_t *)NULL, P_RECLAIM)) {
42690Sstevel@tonic-gate 		if (page_pptonum(pp) != pfnum)
42700Sstevel@tonic-gate 			goto retry;
42710Sstevel@tonic-gate 		continue;
42720Sstevel@tonic-gate 	}
42730Sstevel@tonic-gate 
42740Sstevel@tonic-gate 	if (page_pptonum(pp) != pfnum) {
42750Sstevel@tonic-gate 		page_unlock(pp);
42760Sstevel@tonic-gate 		goto retry;
42770Sstevel@tonic-gate 	}
42780Sstevel@tonic-gate 
42790Sstevel@tonic-gate 	return (pp);
42800Sstevel@tonic-gate }
42810Sstevel@tonic-gate 
42820Sstevel@tonic-gate page_t *
42830Sstevel@tonic-gate page_numtopp_noreclaim(pfn_t pfnum, se_t se)
42840Sstevel@tonic-gate {
42850Sstevel@tonic-gate 	page_t *pp;
42860Sstevel@tonic-gate 
42870Sstevel@tonic-gate retry:
42880Sstevel@tonic-gate 	pp = page_numtopp_nolock(pfnum);
42890Sstevel@tonic-gate 	if (pp == NULL) {
42900Sstevel@tonic-gate 		return ((page_t *)NULL);
42910Sstevel@tonic-gate 	}
42920Sstevel@tonic-gate 
42930Sstevel@tonic-gate 	/*
42940Sstevel@tonic-gate 	 * Acquire the appropriate lock on the page.
42950Sstevel@tonic-gate 	 */
42960Sstevel@tonic-gate 	while (!page_lock(pp, se, (kmutex_t *)NULL, P_NO_RECLAIM)) {
42970Sstevel@tonic-gate 		if (page_pptonum(pp) != pfnum)
42980Sstevel@tonic-gate 			goto retry;
42990Sstevel@tonic-gate 		continue;
43000Sstevel@tonic-gate 	}
43010Sstevel@tonic-gate 
43020Sstevel@tonic-gate 	if (page_pptonum(pp) != pfnum) {
43030Sstevel@tonic-gate 		page_unlock(pp);
43040Sstevel@tonic-gate 		goto retry;
43050Sstevel@tonic-gate 	}
43060Sstevel@tonic-gate 
43070Sstevel@tonic-gate 	return (pp);
43080Sstevel@tonic-gate }
43090Sstevel@tonic-gate 
43100Sstevel@tonic-gate /*
43110Sstevel@tonic-gate  * This routine is like page_numtopp, but will only return page structs
43120Sstevel@tonic-gate  * for pages which are ok for loading into hardware using the page struct.
43130Sstevel@tonic-gate  */
43140Sstevel@tonic-gate page_t *
43150Sstevel@tonic-gate page_numtopp_nowait(pfn_t pfnum, se_t se)
43160Sstevel@tonic-gate {
43170Sstevel@tonic-gate 	page_t *pp;
43180Sstevel@tonic-gate 
43190Sstevel@tonic-gate retry:
43200Sstevel@tonic-gate 	pp = page_numtopp_nolock(pfnum);
43210Sstevel@tonic-gate 	if (pp == NULL) {
43220Sstevel@tonic-gate 		return ((page_t *)NULL);
43230Sstevel@tonic-gate 	}
43240Sstevel@tonic-gate 
43250Sstevel@tonic-gate 	/*
43260Sstevel@tonic-gate 	 * Try to acquire the appropriate lock on the page.
43270Sstevel@tonic-gate 	 */
43280Sstevel@tonic-gate 	if (PP_ISFREE(pp))
43290Sstevel@tonic-gate 		pp = NULL;
43300Sstevel@tonic-gate 	else {
43310Sstevel@tonic-gate 		if (!page_trylock(pp, se))
43320Sstevel@tonic-gate 			pp = NULL;
43330Sstevel@tonic-gate 		else {
43340Sstevel@tonic-gate 			if (page_pptonum(pp) != pfnum) {
43350Sstevel@tonic-gate 				page_unlock(pp);
43360Sstevel@tonic-gate 				goto retry;
43370Sstevel@tonic-gate 			}
43380Sstevel@tonic-gate 			if (PP_ISFREE(pp)) {
43390Sstevel@tonic-gate 				page_unlock(pp);
43400Sstevel@tonic-gate 				pp = NULL;
43410Sstevel@tonic-gate 			}
43420Sstevel@tonic-gate 		}
43430Sstevel@tonic-gate 	}
43440Sstevel@tonic-gate 	return (pp);
43450Sstevel@tonic-gate }
43460Sstevel@tonic-gate 
43470Sstevel@tonic-gate /*
43480Sstevel@tonic-gate  * Returns a count of dirty pages that are in the process
43490Sstevel@tonic-gate  * of being written out.  If 'cleanit' is set, try to push the page.
43500Sstevel@tonic-gate  */
43510Sstevel@tonic-gate pgcnt_t
43520Sstevel@tonic-gate page_busy(int cleanit)
43530Sstevel@tonic-gate {
43540Sstevel@tonic-gate 	page_t *page0 = page_first();
43550Sstevel@tonic-gate 	page_t *pp = page0;
43560Sstevel@tonic-gate 	pgcnt_t nppbusy = 0;
43570Sstevel@tonic-gate 	u_offset_t off;
43580Sstevel@tonic-gate 
43590Sstevel@tonic-gate 	do {
43600Sstevel@tonic-gate 		vnode_t *vp = pp->p_vnode;
43610Sstevel@tonic-gate 
43620Sstevel@tonic-gate 		/*
43630Sstevel@tonic-gate 		 * A page is a candidate for syncing if it is:
43640Sstevel@tonic-gate 		 *
43650Sstevel@tonic-gate 		 * (a)	On neither the freelist nor the cachelist
43660Sstevel@tonic-gate 		 * (b)	Hashed onto a vnode
43670Sstevel@tonic-gate 		 * (c)	Not a kernel page
43680Sstevel@tonic-gate 		 * (d)	Dirty
43690Sstevel@tonic-gate 		 * (e)	Not part of a swapfile
43700Sstevel@tonic-gate 		 * (f)	a page which belongs to a real vnode; eg has a non-null
43710Sstevel@tonic-gate 		 *	v_vfsp pointer.
43720Sstevel@tonic-gate 		 * (g)	Backed by a filesystem which doesn't have a
43730Sstevel@tonic-gate 		 *	stubbed-out sync operation
43740Sstevel@tonic-gate 		 */
43753290Sjohansen 		if (!PP_ISFREE(pp) && vp != NULL && !VN_ISKAS(vp) &&
43760Sstevel@tonic-gate 		    hat_ismod(pp) && !IS_SWAPVP(vp) && vp->v_vfsp != NULL &&
43770Sstevel@tonic-gate 		    vfs_can_sync(vp->v_vfsp)) {
43780Sstevel@tonic-gate 			nppbusy++;
43790Sstevel@tonic-gate 			vfs_syncprogress();
43800Sstevel@tonic-gate 
43810Sstevel@tonic-gate 			if (!cleanit)
43820Sstevel@tonic-gate 				continue;
43830Sstevel@tonic-gate 			if (!page_trylock(pp, SE_EXCL))
43840Sstevel@tonic-gate 				continue;
43850Sstevel@tonic-gate 
43860Sstevel@tonic-gate 			if (PP_ISFREE(pp) || vp == NULL || IS_SWAPVP(vp) ||
43870Sstevel@tonic-gate 			    pp->p_lckcnt != 0 || pp->p_cowcnt != 0 ||
43880Sstevel@tonic-gate 			    !(hat_pagesync(pp,
43890Sstevel@tonic-gate 			    HAT_SYNC_DONTZERO | HAT_SYNC_STOPON_MOD) & P_MOD)) {
43900Sstevel@tonic-gate 				page_unlock(pp);
43910Sstevel@tonic-gate 				continue;
43920Sstevel@tonic-gate 			}
43930Sstevel@tonic-gate 			off = pp->p_offset;
43940Sstevel@tonic-gate 			VN_HOLD(vp);
43950Sstevel@tonic-gate 			page_unlock(pp);
43960Sstevel@tonic-gate 			(void) VOP_PUTPAGE(vp, off, PAGESIZE,
4397*5331Samw 			    B_ASYNC | B_FREE, kcred, NULL);
43980Sstevel@tonic-gate 			VN_RELE(vp);
43990Sstevel@tonic-gate 		}
44000Sstevel@tonic-gate 	} while ((pp = page_next(pp)) != page0);
44010Sstevel@tonic-gate 
44020Sstevel@tonic-gate 	return (nppbusy);
44030Sstevel@tonic-gate }
44040Sstevel@tonic-gate 
44050Sstevel@tonic-gate void page_invalidate_pages(void);
44060Sstevel@tonic-gate 
44070Sstevel@tonic-gate /*
44080Sstevel@tonic-gate  * callback handler to vm sub-system
44090Sstevel@tonic-gate  *
44100Sstevel@tonic-gate  * callers make sure no recursive entries to this func.
44110Sstevel@tonic-gate  */
44120Sstevel@tonic-gate /*ARGSUSED*/
44130Sstevel@tonic-gate boolean_t
44140Sstevel@tonic-gate callb_vm_cpr(void *arg, int code)
44150Sstevel@tonic-gate {
44160Sstevel@tonic-gate 	if (code == CB_CODE_CPR_CHKPT)
44170Sstevel@tonic-gate 		page_invalidate_pages();
44180Sstevel@tonic-gate 	return (B_TRUE);
44190Sstevel@tonic-gate }
44200Sstevel@tonic-gate 
44210Sstevel@tonic-gate /*
44220Sstevel@tonic-gate  * Invalidate all pages of the system.
44230Sstevel@tonic-gate  * It shouldn't be called until all user page activities are all stopped.
44240Sstevel@tonic-gate  */
44250Sstevel@tonic-gate void
44260Sstevel@tonic-gate page_invalidate_pages()
44270Sstevel@tonic-gate {
44280Sstevel@tonic-gate 	page_t *pp;
44290Sstevel@tonic-gate 	page_t *page0;
44300Sstevel@tonic-gate 	pgcnt_t nbusypages;
44310Sstevel@tonic-gate 	int retry = 0;
44320Sstevel@tonic-gate 	const int MAXRETRIES = 4;
44330Sstevel@tonic-gate #if defined(__sparc)
44340Sstevel@tonic-gate 	extern struct vnode prom_ppages;
44350Sstevel@tonic-gate #endif /* __sparc */
44360Sstevel@tonic-gate 
44370Sstevel@tonic-gate top:
44380Sstevel@tonic-gate 	/*
44393253Smec 	 * Flush dirty pages and destroy the clean ones.
44400Sstevel@tonic-gate 	 */
44410Sstevel@tonic-gate 	nbusypages = 0;
44420Sstevel@tonic-gate 
44430Sstevel@tonic-gate 	pp = page0 = page_first();
44440Sstevel@tonic-gate 	do {
44450Sstevel@tonic-gate 		struct vnode	*vp;
44460Sstevel@tonic-gate 		u_offset_t	offset;
44470Sstevel@tonic-gate 		int		mod;
44480Sstevel@tonic-gate 
44490Sstevel@tonic-gate 		/*
44500Sstevel@tonic-gate 		 * skip the page if it has no vnode or the page associated
44510Sstevel@tonic-gate 		 * with the kernel vnode or prom allocated kernel mem.
44520Sstevel@tonic-gate 		 */
44530Sstevel@tonic-gate #if defined(__sparc)
44543290Sjohansen 		if ((vp = pp->p_vnode) == NULL || VN_ISKAS(vp) ||
44550Sstevel@tonic-gate 		    vp == &prom_ppages)
44560Sstevel@tonic-gate #else /* x86 doesn't have prom or prom_ppage */
44573290Sjohansen 		if ((vp = pp->p_vnode) == NULL || VN_ISKAS(vp))
44580Sstevel@tonic-gate #endif /* __sparc */
44590Sstevel@tonic-gate 			continue;
44600Sstevel@tonic-gate 
44610Sstevel@tonic-gate 		/*
44620Sstevel@tonic-gate 		 * skip the page which is already free invalidated.
44630Sstevel@tonic-gate 		 */
44640Sstevel@tonic-gate 		if (PP_ISFREE(pp) && PP_ISAGED(pp))
44650Sstevel@tonic-gate 			continue;
44660Sstevel@tonic-gate 
44670Sstevel@tonic-gate 		/*
44680Sstevel@tonic-gate 		 * skip pages that are already locked or can't be "exclusively"
44690Sstevel@tonic-gate 		 * locked or are already free.  After we lock the page, check
44700Sstevel@tonic-gate 		 * the free and age bits again to be sure it's not destroied
44710Sstevel@tonic-gate 		 * yet.
44720Sstevel@tonic-gate 		 * To achieve max. parallelization, we use page_trylock instead
44730Sstevel@tonic-gate 		 * of page_lock so that we don't get block on individual pages
44740Sstevel@tonic-gate 		 * while we have thousands of other pages to process.
44750Sstevel@tonic-gate 		 */
44760Sstevel@tonic-gate 		if (!page_trylock(pp, SE_EXCL)) {
44770Sstevel@tonic-gate 			nbusypages++;
44780Sstevel@tonic-gate 			continue;
44790Sstevel@tonic-gate 		} else if (PP_ISFREE(pp)) {
44800Sstevel@tonic-gate 			if (!PP_ISAGED(pp)) {
44810Sstevel@tonic-gate 				page_destroy_free(pp);
44820Sstevel@tonic-gate 			} else {
44830Sstevel@tonic-gate 				page_unlock(pp);
44840Sstevel@tonic-gate 			}
44850Sstevel@tonic-gate 			continue;
44860Sstevel@tonic-gate 		}
44870Sstevel@tonic-gate 		/*
44880Sstevel@tonic-gate 		 * Is this page involved in some I/O? shared?
44890Sstevel@tonic-gate 		 *
44900Sstevel@tonic-gate 		 * The page_struct_lock need not be acquired to
44910Sstevel@tonic-gate 		 * examine these fields since the page has an
44920Sstevel@tonic-gate 		 * "exclusive" lock.
44930Sstevel@tonic-gate 		 */
44940Sstevel@tonic-gate 		if (pp->p_lckcnt != 0 || pp->p_cowcnt != 0) {
44950Sstevel@tonic-gate 			page_unlock(pp);
44960Sstevel@tonic-gate 			continue;
44970Sstevel@tonic-gate 		}
44980Sstevel@tonic-gate 
44990Sstevel@tonic-gate 		if (vp->v_type == VCHR) {
45000Sstevel@tonic-gate 			panic("vp->v_type == VCHR");
45010Sstevel@tonic-gate 			/*NOTREACHED*/
45020Sstevel@tonic-gate 		}
45030Sstevel@tonic-gate 
45040Sstevel@tonic-gate 		if (!page_try_demote_pages(pp)) {
45050Sstevel@tonic-gate 			page_unlock(pp);
45060Sstevel@tonic-gate 			continue;
45070Sstevel@tonic-gate 		}
45080Sstevel@tonic-gate 
45090Sstevel@tonic-gate 		/*
45100Sstevel@tonic-gate 		 * Check the modified bit. Leave the bits alone in hardware
45110Sstevel@tonic-gate 		 * (they will be modified if we do the putpage).
45120Sstevel@tonic-gate 		 */
45130Sstevel@tonic-gate 		mod = (hat_pagesync(pp, HAT_SYNC_DONTZERO | HAT_SYNC_STOPON_MOD)
45143559Smec 		    & P_MOD);
45150Sstevel@tonic-gate 		if (mod) {
45160Sstevel@tonic-gate 			offset = pp->p_offset;
45170Sstevel@tonic-gate 			/*
45180Sstevel@tonic-gate 			 * Hold the vnode before releasing the page lock
45190Sstevel@tonic-gate 			 * to prevent it from being freed and re-used by
45200Sstevel@tonic-gate 			 * some other thread.
45210Sstevel@tonic-gate 			 */
45220Sstevel@tonic-gate 			VN_HOLD(vp);
45230Sstevel@tonic-gate 			page_unlock(pp);
45240Sstevel@tonic-gate 			/*
45250Sstevel@tonic-gate 			 * No error return is checked here. Callers such as
45260Sstevel@tonic-gate 			 * cpr deals with the dirty pages at the dump time
45270Sstevel@tonic-gate 			 * if this putpage fails.
45280Sstevel@tonic-gate 			 */
45290Sstevel@tonic-gate 			(void) VOP_PUTPAGE(vp, offset, PAGESIZE, B_INVAL,
4530*5331Samw 			    kcred, NULL);
45310Sstevel@tonic-gate 			VN_RELE(vp);
45320Sstevel@tonic-gate 		} else {
45330Sstevel@tonic-gate 			page_destroy(pp, 0);
45340Sstevel@tonic-gate 		}
45350Sstevel@tonic-gate 	} while ((pp = page_next(pp)) != page0);
45360Sstevel@tonic-gate 	if (nbusypages && retry++ < MAXRETRIES) {
45370Sstevel@tonic-gate 		delay(1);
45380Sstevel@tonic-gate 		goto top;
45390Sstevel@tonic-gate 	}
45400Sstevel@tonic-gate }
45410Sstevel@tonic-gate 
45420Sstevel@tonic-gate /*
45430Sstevel@tonic-gate  * Replace the page "old" with the page "new" on the page hash and vnode lists
45440Sstevel@tonic-gate  *
4545*5331Samw  * the replacement must be done in place, ie the equivalent sequence:
45460Sstevel@tonic-gate  *
45470Sstevel@tonic-gate  *	vp = old->p_vnode;
45480Sstevel@tonic-gate  *	off = old->p_offset;
45490Sstevel@tonic-gate  *	page_do_hashout(old)
45500Sstevel@tonic-gate  *	page_do_hashin(new, vp, off)
45510Sstevel@tonic-gate  *
45520Sstevel@tonic-gate  * doesn't work, since
45530Sstevel@tonic-gate  *  1) if old is the only page on the vnode, the v_pages list has a window
45540Sstevel@tonic-gate  *     where it looks empty. This will break file system assumptions.
45550Sstevel@tonic-gate  * and
45560Sstevel@tonic-gate  *  2) pvn_vplist_dirty() can't deal with pages moving on the v_pages list.
45570Sstevel@tonic-gate  */
45580Sstevel@tonic-gate static void
45590Sstevel@tonic-gate page_do_relocate_hash(page_t *new, page_t *old)
45600Sstevel@tonic-gate {
45610Sstevel@tonic-gate 	page_t	**hash_list;
45620Sstevel@tonic-gate 	vnode_t	*vp = old->p_vnode;
45630Sstevel@tonic-gate 	kmutex_t *sep;
45640Sstevel@tonic-gate 
45650Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(old));
45660Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(new));
45670Sstevel@tonic-gate 	ASSERT(vp != NULL);
45680Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(page_vnode_mutex(vp)));
45690Sstevel@tonic-gate 	ASSERT(MUTEX_HELD(PAGE_HASH_MUTEX(PAGE_HASH_FUNC(vp, old->p_offset))));
45700Sstevel@tonic-gate 
45710Sstevel@tonic-gate 	/*
45720Sstevel@tonic-gate 	 * First find old page on the page hash list
45730Sstevel@tonic-gate 	 */
45740Sstevel@tonic-gate 	hash_list = &page_hash[PAGE_HASH_FUNC(vp, old->p_offset)];
45750Sstevel@tonic-gate 
45760Sstevel@tonic-gate 	for (;;) {
45770Sstevel@tonic-gate 		if (*hash_list == old)
45780Sstevel@tonic-gate 			break;
45790Sstevel@tonic-gate 		if (*hash_list == NULL) {
45800Sstevel@tonic-gate 			panic("page_do_hashout");
45810Sstevel@tonic-gate 			/*NOTREACHED*/
45820Sstevel@tonic-gate 		}
45830Sstevel@tonic-gate 		hash_list = &(*hash_list)->p_hash;
45840Sstevel@tonic-gate 	}
45850Sstevel@tonic-gate 
45860Sstevel@tonic-gate 	/*
45870Sstevel@tonic-gate 	 * update new and replace old with new on the page hash list
45880Sstevel@tonic-gate 	 */
45890Sstevel@tonic-gate 	new->p_vnode = old->p_vnode;
45900Sstevel@tonic-gate 	new->p_offset = old->p_offset;
45910Sstevel@tonic-gate 	new->p_hash = old->p_hash;
45920Sstevel@tonic-gate 	*hash_list = new;
45930Sstevel@tonic-gate 
45940Sstevel@tonic-gate 	if ((new->p_vnode->v_flag & VISSWAP) != 0)
45950Sstevel@tonic-gate 		PP_SETSWAP(new);
45960Sstevel@tonic-gate 
45970Sstevel@tonic-gate 	/*
45980Sstevel@tonic-gate 	 * replace old with new on the vnode's page list
45990Sstevel@tonic-gate 	 */
46000Sstevel@tonic-gate 	if (old->p_vpnext == old) {
46010Sstevel@tonic-gate 		new->p_vpnext = new;
46020Sstevel@tonic-gate 		new->p_vpprev = new;
46030Sstevel@tonic-gate 	} else {
46040Sstevel@tonic-gate 		new->p_vpnext = old->p_vpnext;
46050Sstevel@tonic-gate 		new->p_vpprev = old->p_vpprev;
46060Sstevel@tonic-gate 		new->p_vpnext->p_vpprev = new;
46070Sstevel@tonic-gate 		new->p_vpprev->p_vpnext = new;
46080Sstevel@tonic-gate 	}
46090Sstevel@tonic-gate 	if (vp->v_pages == old)
46100Sstevel@tonic-gate 		vp->v_pages = new;
46110Sstevel@tonic-gate 
46120Sstevel@tonic-gate 	/*
46130Sstevel@tonic-gate 	 * clear out the old page
46140Sstevel@tonic-gate 	 */
46150Sstevel@tonic-gate 	old->p_hash = NULL;
46160Sstevel@tonic-gate 	old->p_vpnext = NULL;
46170Sstevel@tonic-gate 	old->p_vpprev = NULL;
46180Sstevel@tonic-gate 	old->p_vnode = NULL;
46190Sstevel@tonic-gate 	PP_CLRSWAP(old);
46200Sstevel@tonic-gate 	old->p_offset = (u_offset_t)-1;
46210Sstevel@tonic-gate 	page_clr_all_props(old);
46220Sstevel@tonic-gate 
46230Sstevel@tonic-gate 	/*
46240Sstevel@tonic-gate 	 * Wake up processes waiting for this page.  The page's
46250Sstevel@tonic-gate 	 * identity has been changed, and is probably not the
46260Sstevel@tonic-gate 	 * desired page any longer.
46270Sstevel@tonic-gate 	 */
46280Sstevel@tonic-gate 	sep = page_se_mutex(old);
46290Sstevel@tonic-gate 	mutex_enter(sep);
4630800Sstans 	old->p_selock &= ~SE_EWANTED;
46310Sstevel@tonic-gate 	if (CV_HAS_WAITERS(&old->p_cv))
46320Sstevel@tonic-gate 		cv_broadcast(&old->p_cv);
46330Sstevel@tonic-gate 	mutex_exit(sep);
46340Sstevel@tonic-gate }
46350Sstevel@tonic-gate 
46360Sstevel@tonic-gate /*
46370Sstevel@tonic-gate  * This function moves the identity of page "pp_old" to page "pp_new".
46380Sstevel@tonic-gate  * Both pages must be locked on entry.  "pp_new" is free, has no identity,
46390Sstevel@tonic-gate  * and need not be hashed out from anywhere.
46400Sstevel@tonic-gate  */
46410Sstevel@tonic-gate void
46420Sstevel@tonic-gate page_relocate_hash(page_t *pp_new, page_t *pp_old)
46430Sstevel@tonic-gate {
46440Sstevel@tonic-gate 	vnode_t *vp = pp_old->p_vnode;
46450Sstevel@tonic-gate 	u_offset_t off = pp_old->p_offset;
46460Sstevel@tonic-gate 	kmutex_t *phm, *vphm;
46470Sstevel@tonic-gate 
46480Sstevel@tonic-gate 	/*
46490Sstevel@tonic-gate 	 * Rehash two pages
46500Sstevel@tonic-gate 	 */
46510Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp_old));
46520Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp_new));
46530Sstevel@tonic-gate 	ASSERT(vp != NULL);
46540Sstevel@tonic-gate 	ASSERT(pp_new->p_vnode == NULL);
46550Sstevel@tonic-gate 
46560Sstevel@tonic-gate 	/*
46570Sstevel@tonic-gate 	 * hashout then hashin while holding the mutexes
46580Sstevel@tonic-gate 	 */
46590Sstevel@tonic-gate 	phm = PAGE_HASH_MUTEX(PAGE_HASH_FUNC(vp, off));
46600Sstevel@tonic-gate 	mutex_enter(phm);
46610Sstevel@tonic-gate 	vphm = page_vnode_mutex(vp);
46620Sstevel@tonic-gate 	mutex_enter(vphm);
46630Sstevel@tonic-gate 
46640Sstevel@tonic-gate 	page_do_relocate_hash(pp_new, pp_old);
46650Sstevel@tonic-gate 
46660Sstevel@tonic-gate 	mutex_exit(vphm);
46670Sstevel@tonic-gate 	mutex_exit(phm);
46680Sstevel@tonic-gate 
46690Sstevel@tonic-gate 	/*
46700Sstevel@tonic-gate 	 * The page_struct_lock need not be acquired for lckcnt and
46710Sstevel@tonic-gate 	 * cowcnt since the page has an "exclusive" lock.
46720Sstevel@tonic-gate 	 */
46730Sstevel@tonic-gate 	ASSERT(pp_new->p_lckcnt == 0);
46740Sstevel@tonic-gate 	ASSERT(pp_new->p_cowcnt == 0);
46750Sstevel@tonic-gate 	pp_new->p_lckcnt = pp_old->p_lckcnt;
46760Sstevel@tonic-gate 	pp_new->p_cowcnt = pp_old->p_cowcnt;
46770Sstevel@tonic-gate 	pp_old->p_lckcnt = pp_old->p_cowcnt = 0;
46780Sstevel@tonic-gate 
46790Sstevel@tonic-gate 	/* The following comment preserved from page_flip(). */
46800Sstevel@tonic-gate 	/* XXX - Do we need to protect fsdata? */
46810Sstevel@tonic-gate 	pp_new->p_fsdata = pp_old->p_fsdata;
46820Sstevel@tonic-gate }
46830Sstevel@tonic-gate 
46840Sstevel@tonic-gate /*
46850Sstevel@tonic-gate  * Helper routine used to lock all remaining members of a
46860Sstevel@tonic-gate  * large page. The caller is responsible for passing in a locked
46870Sstevel@tonic-gate  * pp. If pp is a large page, then it succeeds in locking all the
46880Sstevel@tonic-gate  * remaining constituent pages or it returns with only the
46890Sstevel@tonic-gate  * original page locked.
46900Sstevel@tonic-gate  *
46910Sstevel@tonic-gate  * Returns 1 on success, 0 on failure.
46920Sstevel@tonic-gate  *
4693*5331Samw  * If success is returned this routine guarantees p_szc for all constituent
46940Sstevel@tonic-gate  * pages of a large page pp belongs to can't change. To achieve this we
46950Sstevel@tonic-gate  * recheck szc of pp after locking all constituent pages and retry if szc
46960Sstevel@tonic-gate  * changed (it could only decrease). Since hat_page_demote() needs an EXCL
46970Sstevel@tonic-gate  * lock on one of constituent pages it can't be running after all constituent
46980Sstevel@tonic-gate  * pages are locked.  hat_page_demote() with a lock on a constituent page
46990Sstevel@tonic-gate  * outside of this large page (i.e. pp belonged to a larger large page) is
47000Sstevel@tonic-gate  * already done with all constituent pages of pp since the root's p_szc is
4701*5331Samw  * changed last. Therefore no need to synchronize with hat_page_demote() that
47020Sstevel@tonic-gate  * locked a constituent page outside of pp's current large page.
47030Sstevel@tonic-gate  */
47040Sstevel@tonic-gate #ifdef DEBUG
47050Sstevel@tonic-gate uint32_t gpg_trylock_mtbf = 0;
47060Sstevel@tonic-gate #endif
47070Sstevel@tonic-gate 
47080Sstevel@tonic-gate int
47090Sstevel@tonic-gate group_page_trylock(page_t *pp, se_t se)
47100Sstevel@tonic-gate {
47110Sstevel@tonic-gate 	page_t  *tpp;
47120Sstevel@tonic-gate 	pgcnt_t	npgs, i, j;
47130Sstevel@tonic-gate 	uint_t pszc = pp->p_szc;
47140Sstevel@tonic-gate 
47150Sstevel@tonic-gate #ifdef DEBUG
47160Sstevel@tonic-gate 	if (gpg_trylock_mtbf && !(gethrtime() % gpg_trylock_mtbf)) {
47170Sstevel@tonic-gate 		return (0);
47180Sstevel@tonic-gate 	}
47190Sstevel@tonic-gate #endif
47200Sstevel@tonic-gate 
47210Sstevel@tonic-gate 	if (pp != PP_GROUPLEADER(pp, pszc)) {
47220Sstevel@tonic-gate 		return (0);
47230Sstevel@tonic-gate 	}
47240Sstevel@tonic-gate 
47250Sstevel@tonic-gate retry:
47260Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED_SE(pp, se));
47270Sstevel@tonic-gate 	ASSERT(!PP_ISFREE(pp));
47280Sstevel@tonic-gate 	if (pszc == 0) {
47290Sstevel@tonic-gate 		return (1);
47300Sstevel@tonic-gate 	}
47310Sstevel@tonic-gate 	npgs = page_get_pagecnt(pszc);
47320Sstevel@tonic-gate 	tpp = pp + 1;
47330Sstevel@tonic-gate 	for (i = 1; i < npgs; i++, tpp++) {
47340Sstevel@tonic-gate 		if (!page_trylock(tpp, se)) {
47350Sstevel@tonic-gate 			tpp = pp + 1;
47360Sstevel@tonic-gate 			for (j = 1; j < i; j++, tpp++) {
47370Sstevel@tonic-gate 				page_unlock(tpp);
47380Sstevel@tonic-gate 			}
47390Sstevel@tonic-gate 			return (0);
47400Sstevel@tonic-gate 		}
47410Sstevel@tonic-gate 	}
47420Sstevel@tonic-gate 	if (pp->p_szc != pszc) {
47430Sstevel@tonic-gate 		ASSERT(pp->p_szc < pszc);
47443290Sjohansen 		ASSERT(pp->p_vnode != NULL && !PP_ISKAS(pp) &&
47450Sstevel@tonic-gate 		    !IS_SWAPFSVP(pp->p_vnode));
47460Sstevel@tonic-gate 		tpp = pp + 1;
47470Sstevel@tonic-gate 		for (i = 1; i < npgs; i++, tpp++) {
47480Sstevel@tonic-gate 			page_unlock(tpp);
47490Sstevel@tonic-gate 		}
47500Sstevel@tonic-gate 		pszc = pp->p_szc;
47510Sstevel@tonic-gate 		goto retry;
47520Sstevel@tonic-gate 	}
47530Sstevel@tonic-gate 	return (1);
47540Sstevel@tonic-gate }
47550Sstevel@tonic-gate 
47560Sstevel@tonic-gate void
47570Sstevel@tonic-gate group_page_unlock(page_t *pp)
47580Sstevel@tonic-gate {
47590Sstevel@tonic-gate 	page_t *tpp;
47600Sstevel@tonic-gate 	pgcnt_t	npgs, i;
47610Sstevel@tonic-gate 
47620Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp));
47630Sstevel@tonic-gate 	ASSERT(!PP_ISFREE(pp));
47640Sstevel@tonic-gate 	ASSERT(pp == PP_PAGEROOT(pp));
47650Sstevel@tonic-gate 	npgs = page_get_pagecnt(pp->p_szc);
47660Sstevel@tonic-gate 	for (i = 1, tpp = pp + 1; i < npgs; i++, tpp++) {
47670Sstevel@tonic-gate 		page_unlock(tpp);
47680Sstevel@tonic-gate 	}
47690Sstevel@tonic-gate }
47700Sstevel@tonic-gate 
47710Sstevel@tonic-gate /*
47720Sstevel@tonic-gate  * returns
47730Sstevel@tonic-gate  * 0 		: on success and *nrelocp is number of relocated PAGESIZE pages
47740Sstevel@tonic-gate  * ERANGE	: this is not a base page
47750Sstevel@tonic-gate  * EBUSY	: failure to get locks on the page/pages
47760Sstevel@tonic-gate  * ENOMEM	: failure to obtain replacement pages
47770Sstevel@tonic-gate  * EAGAIN	: OBP has not yet completed its boot-time handoff to the kernel
47783253Smec  * EIO		: An error occurred while trying to copy the page data
47790Sstevel@tonic-gate  *
47800Sstevel@tonic-gate  * Return with all constituent members of target and replacement
47810Sstevel@tonic-gate  * SE_EXCL locked. It is the callers responsibility to drop the
47820Sstevel@tonic-gate  * locks.
47830Sstevel@tonic-gate  */
47840Sstevel@tonic-gate int
47850Sstevel@tonic-gate do_page_relocate(
47860Sstevel@tonic-gate 	page_t **target,
47870Sstevel@tonic-gate 	page_t **replacement,
47880Sstevel@tonic-gate 	int grouplock,
47890Sstevel@tonic-gate 	spgcnt_t *nrelocp,
47900Sstevel@tonic-gate 	lgrp_t *lgrp)
47910Sstevel@tonic-gate {
47920Sstevel@tonic-gate 	page_t *first_repl;
47930Sstevel@tonic-gate 	page_t *repl;
47940Sstevel@tonic-gate 	page_t *targ;
47950Sstevel@tonic-gate 	page_t *pl = NULL;
47960Sstevel@tonic-gate 	uint_t ppattr;
47970Sstevel@tonic-gate 	pfn_t   pfn, repl_pfn;
47980Sstevel@tonic-gate 	uint_t	szc;
47990Sstevel@tonic-gate 	spgcnt_t npgs, i;
48000Sstevel@tonic-gate 	int repl_contig = 0;
48010Sstevel@tonic-gate 	uint_t flags = 0;
48020Sstevel@tonic-gate 	spgcnt_t dofree = 0;
48030Sstevel@tonic-gate 
48040Sstevel@tonic-gate 	*nrelocp = 0;
48050Sstevel@tonic-gate 
48060Sstevel@tonic-gate #if defined(__sparc)
48070Sstevel@tonic-gate 	/*
48080Sstevel@tonic-gate 	 * We need to wait till OBP has completed
48090Sstevel@tonic-gate 	 * its boot-time handoff of its resources to the kernel
48100Sstevel@tonic-gate 	 * before we allow page relocation
48110Sstevel@tonic-gate 	 */
48120Sstevel@tonic-gate 	if (page_relocate_ready == 0) {
48130Sstevel@tonic-gate 		return (EAGAIN);
48140Sstevel@tonic-gate 	}
48150Sstevel@tonic-gate #endif
48160Sstevel@tonic-gate 
48170Sstevel@tonic-gate 	/*
48180Sstevel@tonic-gate 	 * If this is not a base page,
48190Sstevel@tonic-gate 	 * just return with 0x0 pages relocated.
48200Sstevel@tonic-gate 	 */
48210Sstevel@tonic-gate 	targ = *target;
48220Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(targ));
48230Sstevel@tonic-gate 	ASSERT(!PP_ISFREE(targ));
48240Sstevel@tonic-gate 	szc = targ->p_szc;
48250Sstevel@tonic-gate 	ASSERT(szc < mmu_page_sizes);
48260Sstevel@tonic-gate 	VM_STAT_ADD(vmm_vmstats.ppr_reloc[szc]);
48270Sstevel@tonic-gate 	pfn = targ->p_pagenum;
48280Sstevel@tonic-gate 	if (pfn != PFN_BASE(pfn, szc)) {
48290Sstevel@tonic-gate 		VM_STAT_ADD(vmm_vmstats.ppr_relocnoroot[szc]);
48300Sstevel@tonic-gate 		return (ERANGE);
48310Sstevel@tonic-gate 	}
48320Sstevel@tonic-gate 
48330Sstevel@tonic-gate 	if ((repl = *replacement) != NULL && repl->p_szc >= szc) {
48340Sstevel@tonic-gate 		repl_pfn = repl->p_pagenum;
48350Sstevel@tonic-gate 		if (repl_pfn != PFN_BASE(repl_pfn, szc)) {
48360Sstevel@tonic-gate 			VM_STAT_ADD(vmm_vmstats.ppr_reloc_replnoroot[szc]);
48370Sstevel@tonic-gate 			return (ERANGE);
48380Sstevel@tonic-gate 		}
48390Sstevel@tonic-gate 		repl_contig = 1;
48400Sstevel@tonic-gate 	}
48410Sstevel@tonic-gate 
48420Sstevel@tonic-gate 	/*
48430Sstevel@tonic-gate 	 * We must lock all members of this large page or we cannot
48440Sstevel@tonic-gate 	 * relocate any part of it.
48450Sstevel@tonic-gate 	 */
48460Sstevel@tonic-gate 	if (grouplock != 0 && !group_page_trylock(targ, SE_EXCL)) {
48470Sstevel@tonic-gate 		VM_STAT_ADD(vmm_vmstats.ppr_relocnolock[targ->p_szc]);
48480Sstevel@tonic-gate 		return (EBUSY);
48490Sstevel@tonic-gate 	}
48500Sstevel@tonic-gate 
48510Sstevel@tonic-gate 	/*
48520Sstevel@tonic-gate 	 * reread szc it could have been decreased before
48530Sstevel@tonic-gate 	 * group_page_trylock() was done.
48540Sstevel@tonic-gate 	 */
48550Sstevel@tonic-gate 	szc = targ->p_szc;
48560Sstevel@tonic-gate 	ASSERT(szc < mmu_page_sizes);
48570Sstevel@tonic-gate 	VM_STAT_ADD(vmm_vmstats.ppr_reloc[szc]);
48580Sstevel@tonic-gate 	ASSERT(pfn == PFN_BASE(pfn, szc));
48590Sstevel@tonic-gate 
48600Sstevel@tonic-gate 	npgs = page_get_pagecnt(targ->p_szc);
48610Sstevel@tonic-gate 
48620Sstevel@tonic-gate 	if (repl == NULL) {
48630Sstevel@tonic-gate 		dofree = npgs;		/* Size of target page in MMU pages */
48640Sstevel@tonic-gate 		if (!page_create_wait(dofree, 0)) {
48650Sstevel@tonic-gate 			if (grouplock != 0) {
48660Sstevel@tonic-gate 				group_page_unlock(targ);
48670Sstevel@tonic-gate 			}
48680Sstevel@tonic-gate 			VM_STAT_ADD(vmm_vmstats.ppr_relocnomem[szc]);
48690Sstevel@tonic-gate 			return (ENOMEM);
48700Sstevel@tonic-gate 		}
48710Sstevel@tonic-gate 
48720Sstevel@tonic-gate 		/*
48730Sstevel@tonic-gate 		 * seg kmem pages require that the target and replacement
48740Sstevel@tonic-gate 		 * page be the same pagesize.
48750Sstevel@tonic-gate 		 */
48763290Sjohansen 		flags = (VN_ISKAS(targ->p_vnode)) ? PGR_SAMESZC : 0;
48770Sstevel@tonic-gate 		repl = page_get_replacement_page(targ, lgrp, flags);
48780Sstevel@tonic-gate 		if (repl == NULL) {
48790Sstevel@tonic-gate 			if (grouplock != 0) {
48800Sstevel@tonic-gate 				group_page_unlock(targ);
48810Sstevel@tonic-gate 			}
48820Sstevel@tonic-gate 			page_create_putback(dofree);
48830Sstevel@tonic-gate 			VM_STAT_ADD(vmm_vmstats.ppr_relocnomem[szc]);
48840Sstevel@tonic-gate 			return (ENOMEM);
48850Sstevel@tonic-gate 		}
48860Sstevel@tonic-gate 	}
48870Sstevel@tonic-gate #ifdef DEBUG
48880Sstevel@tonic-gate 	else {
48890Sstevel@tonic-gate 		ASSERT(PAGE_LOCKED(repl));
48900Sstevel@tonic-gate 	}
48910Sstevel@tonic-gate #endif /* DEBUG */
48920Sstevel@tonic-gate 
48930Sstevel@tonic-gate #if defined(__sparc)
48940Sstevel@tonic-gate 	/*
48950Sstevel@tonic-gate 	 * Let hat_page_relocate() complete the relocation if it's kernel page
48960Sstevel@tonic-gate 	 */
48973290Sjohansen 	if (VN_ISKAS(targ->p_vnode)) {
48980Sstevel@tonic-gate 		*replacement = repl;
48990Sstevel@tonic-gate 		if (hat_page_relocate(target, replacement, nrelocp) != 0) {
49000Sstevel@tonic-gate 			if (grouplock != 0) {
49010Sstevel@tonic-gate 				group_page_unlock(targ);
49020Sstevel@tonic-gate 			}
49030Sstevel@tonic-gate 			if (dofree) {
49040Sstevel@tonic-gate 				*replacement = NULL;
49050Sstevel@tonic-gate 				page_free_replacement_page(repl);
49060Sstevel@tonic-gate 				page_create_putback(dofree);
49070Sstevel@tonic-gate 			}
49080Sstevel@tonic-gate 			VM_STAT_ADD(vmm_vmstats.ppr_krelocfail[szc]);
49090Sstevel@tonic-gate 			return (EAGAIN);
49100Sstevel@tonic-gate 		}
49110Sstevel@tonic-gate 		VM_STAT_ADD(vmm_vmstats.ppr_relocok[szc]);
49120Sstevel@tonic-gate 		return (0);
49130Sstevel@tonic-gate 	}
49140Sstevel@tonic-gate #else
49150Sstevel@tonic-gate #if defined(lint)
49160Sstevel@tonic-gate 	dofree = dofree;
49170Sstevel@tonic-gate #endif
49180Sstevel@tonic-gate #endif
49190Sstevel@tonic-gate 
49200Sstevel@tonic-gate 	first_repl = repl;
49210Sstevel@tonic-gate 
49220Sstevel@tonic-gate 	for (i = 0; i < npgs; i++) {
49230Sstevel@tonic-gate 		ASSERT(PAGE_EXCL(targ));
49242414Saguzovsk 		ASSERT(targ->p_slckcnt == 0);
49252414Saguzovsk 		ASSERT(repl->p_slckcnt == 0);
49260Sstevel@tonic-gate 
49270Sstevel@tonic-gate 		(void) hat_pageunload(targ, HAT_FORCE_PGUNLOAD);
49280Sstevel@tonic-gate 
49290Sstevel@tonic-gate 		ASSERT(hat_page_getshare(targ) == 0);
49300Sstevel@tonic-gate 		ASSERT(!PP_ISFREE(targ));
49310Sstevel@tonic-gate 		ASSERT(targ->p_pagenum == (pfn + i));
49320Sstevel@tonic-gate 		ASSERT(repl_contig == 0 ||
49330Sstevel@tonic-gate 		    repl->p_pagenum == (repl_pfn + i));
49340Sstevel@tonic-gate 
49350Sstevel@tonic-gate 		/*
49360Sstevel@tonic-gate 		 * Copy the page contents and attributes then
49370Sstevel@tonic-gate 		 * relocate the page in the page hash.
49380Sstevel@tonic-gate 		 */
49393253Smec 		if (ppcopy(targ, repl) == 0) {
49403253Smec 			targ = *target;
49413253Smec 			repl = first_repl;
49423253Smec 			VM_STAT_ADD(vmm_vmstats.ppr_copyfail);
49433253Smec 			if (grouplock != 0) {
49443253Smec 				group_page_unlock(targ);
49453253Smec 			}
49463253Smec 			if (dofree) {
49473253Smec 				*replacement = NULL;
49483253Smec 				page_free_replacement_page(repl);
49493253Smec 				page_create_putback(dofree);
49503253Smec 			}
49513253Smec 			return (EIO);
49523253Smec 		}
49533253Smec 
49543253Smec 		targ++;
49553253Smec 		if (repl_contig != 0) {
49563253Smec 			repl++;
49573253Smec 		} else {
49583253Smec 			repl = repl->p_next;
49593253Smec 		}
49603253Smec 	}
49613253Smec 
49623253Smec 	repl = first_repl;
49633253Smec 	targ = *target;
49643253Smec 
49653253Smec 	for (i = 0; i < npgs; i++) {
49660Sstevel@tonic-gate 		ppattr = hat_page_getattr(targ, (P_MOD | P_REF | P_RO));
49670Sstevel@tonic-gate 		page_clr_all_props(repl);
49680Sstevel@tonic-gate 		page_set_props(repl, ppattr);
49690Sstevel@tonic-gate 		page_relocate_hash(repl, targ);
49700Sstevel@tonic-gate 
49710Sstevel@tonic-gate 		ASSERT(hat_page_getshare(targ) == 0);
49720Sstevel@tonic-gate 		ASSERT(hat_page_getshare(repl) == 0);
49730Sstevel@tonic-gate 		/*
49740Sstevel@tonic-gate 		 * Now clear the props on targ, after the
49750Sstevel@tonic-gate 		 * page_relocate_hash(), they no longer
49760Sstevel@tonic-gate 		 * have any meaning.
49770Sstevel@tonic-gate 		 */
49780Sstevel@tonic-gate 		page_clr_all_props(targ);
49790Sstevel@tonic-gate 		ASSERT(targ->p_next == targ);
49800Sstevel@tonic-gate 		ASSERT(targ->p_prev == targ);
49810Sstevel@tonic-gate 		page_list_concat(&pl, &targ);
49820Sstevel@tonic-gate 
49830Sstevel@tonic-gate 		targ++;
49840Sstevel@tonic-gate 		if (repl_contig != 0) {
49850Sstevel@tonic-gate 			repl++;
49860Sstevel@tonic-gate 		} else {
49870Sstevel@tonic-gate 			repl = repl->p_next;
49880Sstevel@tonic-gate 		}
49890Sstevel@tonic-gate 	}
49900Sstevel@tonic-gate 	/* assert that we have come full circle with repl */
49910Sstevel@tonic-gate 	ASSERT(repl_contig == 1 || first_repl == repl);
49920Sstevel@tonic-gate 
49930Sstevel@tonic-gate 	*target = pl;
49940Sstevel@tonic-gate 	if (*replacement == NULL) {
49950Sstevel@tonic-gate 		ASSERT(first_repl == repl);
49960Sstevel@tonic-gate 		*replacement = repl;
49970Sstevel@tonic-gate 	}
49980Sstevel@tonic-gate 	VM_STAT_ADD(vmm_vmstats.ppr_relocok[szc]);
49990Sstevel@tonic-gate 	*nrelocp = npgs;
50000Sstevel@tonic-gate 	return (0);
50010Sstevel@tonic-gate }
50020Sstevel@tonic-gate /*
50030Sstevel@tonic-gate  * On success returns 0 and *nrelocp the number of PAGESIZE pages relocated.
50040Sstevel@tonic-gate  */
50050Sstevel@tonic-gate int
50060Sstevel@tonic-gate page_relocate(
50070Sstevel@tonic-gate 	page_t **target,
50080Sstevel@tonic-gate 	page_t **replacement,
50090Sstevel@tonic-gate 	int grouplock,
50100Sstevel@tonic-gate 	int freetarget,
50110Sstevel@tonic-gate 	spgcnt_t *nrelocp,
50120Sstevel@tonic-gate 	lgrp_t *lgrp)
50130Sstevel@tonic-gate {
50140Sstevel@tonic-gate 	spgcnt_t ret;
50150Sstevel@tonic-gate 
50160Sstevel@tonic-gate 	/* do_page_relocate returns 0 on success or errno value */
50170Sstevel@tonic-gate 	ret = do_page_relocate(target, replacement, grouplock, nrelocp, lgrp);
50180Sstevel@tonic-gate 
50190Sstevel@tonic-gate 	if (ret != 0 || freetarget == 0) {
50200Sstevel@tonic-gate 		return (ret);
50210Sstevel@tonic-gate 	}
50220Sstevel@tonic-gate 	if (*nrelocp == 1) {
50230Sstevel@tonic-gate 		ASSERT(*target != NULL);
50240Sstevel@tonic-gate 		page_free(*target, 1);
50250Sstevel@tonic-gate 	} else {
50260Sstevel@tonic-gate 		page_t *tpp = *target;
50270Sstevel@tonic-gate 		uint_t szc = tpp->p_szc;
50280Sstevel@tonic-gate 		pgcnt_t npgs = page_get_pagecnt(szc);
50290Sstevel@tonic-gate 		ASSERT(npgs > 1);
50300Sstevel@tonic-gate 		ASSERT(szc != 0);
50310Sstevel@tonic-gate 		do {
50320Sstevel@tonic-gate 			ASSERT(PAGE_EXCL(tpp));
50330Sstevel@tonic-gate 			ASSERT(!hat_page_is_mapped(tpp));
50340Sstevel@tonic-gate 			ASSERT(tpp->p_szc == szc);
50350Sstevel@tonic-gate 			PP_SETFREE(tpp);
50360Sstevel@tonic-gate 			PP_SETAGED(tpp);
50370Sstevel@tonic-gate 			npgs--;
50380Sstevel@tonic-gate 		} while ((tpp = tpp->p_next) != *target);
50390Sstevel@tonic-gate 		ASSERT(npgs == 0);
50400Sstevel@tonic-gate 		page_list_add_pages(*target, 0);
50410Sstevel@tonic-gate 		npgs = page_get_pagecnt(szc);
50420Sstevel@tonic-gate 		page_create_putback(npgs);
50430Sstevel@tonic-gate 	}
50440Sstevel@tonic-gate 	return (ret);
50450Sstevel@tonic-gate }
50460Sstevel@tonic-gate 
50470Sstevel@tonic-gate /*
50480Sstevel@tonic-gate  * it is up to the caller to deal with pcf accounting.
50490Sstevel@tonic-gate  */
50500Sstevel@tonic-gate void
50510Sstevel@tonic-gate page_free_replacement_page(page_t *pplist)
50520Sstevel@tonic-gate {
50530Sstevel@tonic-gate 	page_t *pp;
50540Sstevel@tonic-gate 
50550Sstevel@tonic-gate 	while (pplist != NULL) {
50560Sstevel@tonic-gate 		/*
50570Sstevel@tonic-gate 		 * pp_targ is a linked list.
50580Sstevel@tonic-gate 		 */
50590Sstevel@tonic-gate 		pp = pplist;
50600Sstevel@tonic-gate 		if (pp->p_szc == 0) {
50610Sstevel@tonic-gate 			page_sub(&pplist, pp);
50620Sstevel@tonic-gate 			page_clr_all_props(pp);
50630Sstevel@tonic-gate 			PP_SETFREE(pp);
50640Sstevel@tonic-gate 			PP_SETAGED(pp);
50650Sstevel@tonic-gate 			page_list_add(pp, PG_FREE_LIST | PG_LIST_TAIL);
50660Sstevel@tonic-gate 			page_unlock(pp);
50670Sstevel@tonic-gate 			VM_STAT_ADD(pagecnt.pc_free_replacement_page[0]);
50680Sstevel@tonic-gate 		} else {
50690Sstevel@tonic-gate 			spgcnt_t curnpgs = page_get_pagecnt(pp->p_szc);
50700Sstevel@tonic-gate 			page_t *tpp;
50710Sstevel@tonic-gate 			page_list_break(&pp, &pplist, curnpgs);
50720Sstevel@tonic-gate 			tpp = pp;
50730Sstevel@tonic-gate 			do {
50740Sstevel@tonic-gate 				ASSERT(PAGE_EXCL(tpp));
50750Sstevel@tonic-gate 				ASSERT(!hat_page_is_mapped(tpp));
50760Sstevel@tonic-gate 				page_clr_all_props(pp);
50770Sstevel@tonic-gate 				PP_SETFREE(tpp);
50780Sstevel@tonic-gate 				PP_SETAGED(tpp);
50790Sstevel@tonic-gate 			} while ((tpp = tpp->p_next) != pp);
50800Sstevel@tonic-gate 			page_list_add_pages(pp, 0);
50810Sstevel@tonic-gate 			VM_STAT_ADD(pagecnt.pc_free_replacement_page[1]);
50820Sstevel@tonic-gate 		}
50830Sstevel@tonic-gate 	}
50840Sstevel@tonic-gate }
50850Sstevel@tonic-gate 
50860Sstevel@tonic-gate /*
50870Sstevel@tonic-gate  * Relocate target to non-relocatable replacement page.
50880Sstevel@tonic-gate  */
50890Sstevel@tonic-gate int
50900Sstevel@tonic-gate page_relocate_cage(page_t **target, page_t **replacement)
50910Sstevel@tonic-gate {
50920Sstevel@tonic-gate 	page_t *tpp, *rpp;
50930Sstevel@tonic-gate 	spgcnt_t pgcnt, npgs;
50940Sstevel@tonic-gate 	int result;
50950Sstevel@tonic-gate 
50960Sstevel@tonic-gate 	tpp = *target;
50970Sstevel@tonic-gate 
50980Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(tpp));
50990Sstevel@tonic-gate 	ASSERT(tpp->p_szc == 0);
51000Sstevel@tonic-gate 
51010Sstevel@tonic-gate 	pgcnt = btop(page_get_pagesize(tpp->p_szc));
51020Sstevel@tonic-gate 
51030Sstevel@tonic-gate 	do {
51040Sstevel@tonic-gate 		(void) page_create_wait(pgcnt, PG_WAIT | PG_NORELOC);
51050Sstevel@tonic-gate 		rpp = page_get_replacement_page(tpp, NULL, PGR_NORELOC);
51060Sstevel@tonic-gate 		if (rpp == NULL) {
51070Sstevel@tonic-gate 			page_create_putback(pgcnt);
51080Sstevel@tonic-gate 			kcage_cageout_wakeup();
51090Sstevel@tonic-gate 		}
51100Sstevel@tonic-gate 	} while (rpp == NULL);
51110Sstevel@tonic-gate 
51120Sstevel@tonic-gate 	ASSERT(PP_ISNORELOC(rpp));
51130Sstevel@tonic-gate 
51140Sstevel@tonic-gate 	result = page_relocate(&tpp, &rpp, 0, 1, &npgs, NULL);
51150Sstevel@tonic-gate 
51160Sstevel@tonic-gate 	if (result == 0) {
51170Sstevel@tonic-gate 		*replacement = rpp;
51180Sstevel@tonic-gate 		if (pgcnt != npgs)
51190Sstevel@tonic-gate 			panic("page_relocate_cage: partial relocation");
51200Sstevel@tonic-gate 	}
51210Sstevel@tonic-gate 
51220Sstevel@tonic-gate 	return (result);
51230Sstevel@tonic-gate }
51240Sstevel@tonic-gate 
51250Sstevel@tonic-gate /*
51260Sstevel@tonic-gate  * Release the page lock on a page, place on cachelist
51270Sstevel@tonic-gate  * tail if no longer mapped. Caller can let us know if
51280Sstevel@tonic-gate  * the page is known to be clean.
51290Sstevel@tonic-gate  */
51300Sstevel@tonic-gate int
51310Sstevel@tonic-gate page_release(page_t *pp, int checkmod)
51320Sstevel@tonic-gate {
51330Sstevel@tonic-gate 	int status;
51340Sstevel@tonic-gate 
51350Sstevel@tonic-gate 	ASSERT(PAGE_LOCKED(pp) && !PP_ISFREE(pp) &&
51363559Smec 	    (pp->p_vnode != NULL));
51370Sstevel@tonic-gate 
51380Sstevel@tonic-gate 	if (!hat_page_is_mapped(pp) && !IS_SWAPVP(pp->p_vnode) &&
51390Sstevel@tonic-gate 	    ((PAGE_SHARED(pp) && page_tryupgrade(pp)) || PAGE_EXCL(pp)) &&
51400Sstevel@tonic-gate 	    pp->p_lckcnt == 0 && pp->p_cowcnt == 0 &&
51410Sstevel@tonic-gate 	    !hat_page_is_mapped(pp)) {
51420Sstevel@tonic-gate 
51430Sstevel@tonic-gate 		/*
51440Sstevel@tonic-gate 		 * If page is modified, unlock it
51450Sstevel@tonic-gate 		 *
51460Sstevel@tonic-gate 		 * (p_nrm & P_MOD) bit has the latest stuff because:
51470Sstevel@tonic-gate 		 * (1) We found that this page doesn't have any mappings
51480Sstevel@tonic-gate 		 *	_after_ holding SE_EXCL and
51490Sstevel@tonic-gate 		 * (2) We didn't drop SE_EXCL lock after the check in (1)
51500Sstevel@tonic-gate 		 */
51510Sstevel@tonic-gate 		if (checkmod && hat_ismod(pp)) {
51520Sstevel@tonic-gate 			page_unlock(pp);
51530Sstevel@tonic-gate 			status = PGREL_MOD;
51540Sstevel@tonic-gate 		} else {
51550Sstevel@tonic-gate 			/*LINTED: constant in conditional context*/
51560Sstevel@tonic-gate 			VN_DISPOSE(pp, B_FREE, 0, kcred);
51570Sstevel@tonic-gate 			status = PGREL_CLEAN;
51580Sstevel@tonic-gate 		}
51590Sstevel@tonic-gate 	} else {
51600Sstevel@tonic-gate 		page_unlock(pp);
51610Sstevel@tonic-gate 		status = PGREL_NOTREL;
51620Sstevel@tonic-gate 	}
51630Sstevel@tonic-gate 	return (status);
51640Sstevel@tonic-gate }
51650Sstevel@tonic-gate 
5166917Selowe /*
5167917Selowe  * Given a constituent page, try to demote the large page on the freelist.
5168917Selowe  *
5169917Selowe  * Returns nonzero if the page could be demoted successfully. Returns with
5170917Selowe  * the constituent page still locked.
5171917Selowe  */
5172917Selowe int
5173917Selowe page_try_demote_free_pages(page_t *pp)
5174917Selowe {
5175917Selowe 	page_t *rootpp = pp;
5176917Selowe 	pfn_t	pfn = page_pptonum(pp);
5177917Selowe 	spgcnt_t npgs;
5178917Selowe 	uint_t	szc = pp->p_szc;
5179917Selowe 
5180917Selowe 	ASSERT(PP_ISFREE(pp));
5181917Selowe 	ASSERT(PAGE_EXCL(pp));
5182917Selowe 
5183917Selowe 	/*
5184917Selowe 	 * Adjust rootpp and lock it, if `pp' is not the base
5185917Selowe 	 * constituent page.
5186917Selowe 	 */
5187917Selowe 	npgs = page_get_pagecnt(pp->p_szc);
5188917Selowe 	if (npgs == 1) {
5189917Selowe 		return (0);
5190917Selowe 	}
5191917Selowe 
5192917Selowe 	if (!IS_P2ALIGNED(pfn, npgs)) {
5193917Selowe 		pfn = P2ALIGN(pfn, npgs);
5194917Selowe 		rootpp = page_numtopp_nolock(pfn);
5195917Selowe 	}
5196917Selowe 
5197917Selowe 	if (pp != rootpp && !page_trylock(rootpp, SE_EXCL)) {
5198917Selowe 		return (0);
5199917Selowe 	}
5200917Selowe 
5201917Selowe 	if (rootpp->p_szc != szc) {
5202917Selowe 		if (pp != rootpp)
5203917Selowe 			page_unlock(rootpp);
5204917Selowe 		return (0);
5205917Selowe 	}
5206917Selowe 
5207917Selowe 	page_demote_free_pages(rootpp);
5208917Selowe 
5209917Selowe 	if (pp != rootpp)
5210917Selowe 		page_unlock(rootpp);
5211917Selowe 
5212917Selowe 	ASSERT(PP_ISFREE(pp));
5213917Selowe 	ASSERT(PAGE_EXCL(pp));
5214917Selowe 	return (1);
5215917Selowe }
5216917Selowe 
5217917Selowe /*
5218917Selowe  * Given a constituent page, try to demote the large page.
5219917Selowe  *
5220917Selowe  * Returns nonzero if the page could be demoted successfully. Returns with
5221917Selowe  * the constituent page still locked.
5222917Selowe  */
52230Sstevel@tonic-gate int
52240Sstevel@tonic-gate page_try_demote_pages(page_t *pp)
52250Sstevel@tonic-gate {
52260Sstevel@tonic-gate 	page_t *tpp, *rootpp = pp;
52270Sstevel@tonic-gate 	pfn_t	pfn = page_pptonum(pp);
52280Sstevel@tonic-gate 	spgcnt_t i, npgs;
52290Sstevel@tonic-gate 	uint_t	szc = pp->p_szc;
52300Sstevel@tonic-gate 	vnode_t *vp = pp->p_vnode;
52310Sstevel@tonic-gate 
5232917Selowe 	ASSERT(PAGE_EXCL(pp));
52330Sstevel@tonic-gate 
52340Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_try_demote_pages[0]);
52350Sstevel@tonic-gate 
5236917Selowe 	if (pp->p_szc == 0) {
52370Sstevel@tonic-gate 		VM_STAT_ADD(pagecnt.pc_try_demote_pages[1]);
52380Sstevel@tonic-gate 		return (1);
52390Sstevel@tonic-gate 	}
52400Sstevel@tonic-gate 
52413290Sjohansen 	if (vp != NULL && !IS_SWAPFSVP(vp) && !VN_ISKAS(vp)) {
52420Sstevel@tonic-gate 		VM_STAT_ADD(pagecnt.pc_try_demote_pages[2]);
5243917Selowe 		page_demote_vp_pages(pp);
52440Sstevel@tonic-gate 		ASSERT(pp->p_szc == 0);
52450Sstevel@tonic-gate 		return (1);
52460Sstevel@tonic-gate 	}
52470Sstevel@tonic-gate 
52480Sstevel@tonic-gate 	/*
5249917Selowe 	 * Adjust rootpp if passed in is not the base
52500Sstevel@tonic-gate 	 * constituent page.
52510Sstevel@tonic-gate 	 */
5252917Selowe 	npgs = page_get_pagecnt(pp->p_szc);
52530Sstevel@tonic-gate 	ASSERT(npgs > 1);
52540Sstevel@tonic-gate 	if (!IS_P2ALIGNED(pfn, npgs)) {
52550Sstevel@tonic-gate 		pfn = P2ALIGN(pfn, npgs);
52560Sstevel@tonic-gate 		rootpp = page_numtopp_nolock(pfn);
52570Sstevel@tonic-gate 		VM_STAT_ADD(pagecnt.pc_try_demote_pages[3]);
52580Sstevel@tonic-gate 		ASSERT(rootpp->p_vnode != NULL);
52590Sstevel@tonic-gate 		ASSERT(rootpp->p_szc == szc);
52600Sstevel@tonic-gate 	}
52610Sstevel@tonic-gate 
52620Sstevel@tonic-gate 	/*
52630Sstevel@tonic-gate 	 * We can't demote kernel pages since we can't hat_unload()
52640Sstevel@tonic-gate 	 * the mappings.
52650Sstevel@tonic-gate 	 */
52663290Sjohansen 	if (VN_ISKAS(rootpp->p_vnode))
52670Sstevel@tonic-gate 		return (0);
52680Sstevel@tonic-gate 
52690Sstevel@tonic-gate 	/*
52700Sstevel@tonic-gate 	 * Attempt to lock all constituent pages except the page passed
52710Sstevel@tonic-gate 	 * in since it's already locked.
52720Sstevel@tonic-gate 	 */
5273414Skchow 	for (tpp = rootpp, i = 0; i < npgs; i++, tpp++) {
52740Sstevel@tonic-gate 		ASSERT(!PP_ISFREE(tpp));
52750Sstevel@tonic-gate 		ASSERT(tpp->p_vnode != NULL);
52760Sstevel@tonic-gate 
52770Sstevel@tonic-gate 		if (tpp != pp && !page_trylock(tpp, SE_EXCL))
52780Sstevel@tonic-gate 			break;
52790Sstevel@tonic-gate 		ASSERT(tpp->p_szc == rootpp->p_szc);
52800Sstevel@tonic-gate 		ASSERT(page_pptonum(tpp) == page_pptonum(rootpp) + i);
52810Sstevel@tonic-gate 	}
52820Sstevel@tonic-gate 
52830Sstevel@tonic-gate 	/*
5284917Selowe 	 * If we failed to lock them all then unlock what we have
5285917Selowe 	 * locked so far and bail.
52860Sstevel@tonic-gate 	 */
52870Sstevel@tonic-gate 	if (i < npgs) {
52880Sstevel@tonic-gate 		tpp = rootpp;
52890Sstevel@tonic-gate 		while (i-- > 0) {
52900Sstevel@tonic-gate 			if (tpp != pp)
52910Sstevel@tonic-gate 				page_unlock(tpp);
5292414Skchow 			tpp++;
52930Sstevel@tonic-gate 		}
52940Sstevel@tonic-gate 		VM_STAT_ADD(pagecnt.pc_try_demote_pages[4]);
52950Sstevel@tonic-gate 		return (0);
52960Sstevel@tonic-gate 	}
52970Sstevel@tonic-gate 
5298414Skchow 	for (tpp = rootpp, i = 0; i < npgs; i++, tpp++) {
52990Sstevel@tonic-gate 		ASSERT(PAGE_EXCL(tpp));
53002414Saguzovsk 		ASSERT(tpp->p_slckcnt == 0);
5301917Selowe 		(void) hat_pageunload(tpp, HAT_FORCE_PGUNLOAD);
53020Sstevel@tonic-gate 		tpp->p_szc = 0;
53030Sstevel@tonic-gate 	}
53040Sstevel@tonic-gate 
53050Sstevel@tonic-gate 	/*
53060Sstevel@tonic-gate 	 * Unlock all pages except the page passed in.
53070Sstevel@tonic-gate 	 */
5308414Skchow 	for (tpp = rootpp, i = 0; i < npgs; i++, tpp++) {
53090Sstevel@tonic-gate 		ASSERT(!hat_page_is_mapped(tpp));
53100Sstevel@tonic-gate 		if (tpp != pp)
53110Sstevel@tonic-gate 			page_unlock(tpp);
53120Sstevel@tonic-gate 	}
5313917Selowe 
53140Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_try_demote_pages[5]);
53150Sstevel@tonic-gate 	return (1);
53160Sstevel@tonic-gate }
53170Sstevel@tonic-gate 
53180Sstevel@tonic-gate /*
53190Sstevel@tonic-gate  * Called by page_free() and page_destroy() to demote the page size code
53200Sstevel@tonic-gate  * (p_szc) to 0 (since we can't just put a single PAGESIZE page with non zero
53210Sstevel@tonic-gate  * p_szc on free list, neither can we just clear p_szc of a single page_t
53220Sstevel@tonic-gate  * within a large page since it will break other code that relies on p_szc
53230Sstevel@tonic-gate  * being the same for all page_t's of a large page). Anonymous pages should
53240Sstevel@tonic-gate  * never end up here because anon_map_getpages() cannot deal with p_szc
53250Sstevel@tonic-gate  * changes after a single constituent page is locked.  While anonymous or
53260Sstevel@tonic-gate  * kernel large pages are demoted or freed the entire large page at a time
53270Sstevel@tonic-gate  * with all constituent pages locked EXCL for the file system pages we
53280Sstevel@tonic-gate  * have to be able to demote a large page (i.e. decrease all constituent pages
53290Sstevel@tonic-gate  * p_szc) with only just an EXCL lock on one of constituent pages. The reason
53300Sstevel@tonic-gate  * we can easily deal with anonymous page demotion the entire large page at a
53310Sstevel@tonic-gate  * time is that those operation originate at address space level and concern
53320Sstevel@tonic-gate  * the entire large page region with actual demotion only done when pages are
53330Sstevel@tonic-gate  * not shared with any other processes (therefore we can always get EXCL lock
53340Sstevel@tonic-gate  * on all anonymous constituent pages after clearing segment page
53350Sstevel@tonic-gate  * cache). However file system pages can be truncated or invalidated at a
53360Sstevel@tonic-gate  * PAGESIZE level from the file system side and end up in page_free() or
53370Sstevel@tonic-gate  * page_destroy() (we also allow only part of the large page to be SOFTLOCKed
5338*5331Samw  * and therefore pageout should be able to demote a large page by EXCL locking
53390Sstevel@tonic-gate  * any constituent page that is not under SOFTLOCK). In those cases we cannot
53400Sstevel@tonic-gate  * rely on being able to lock EXCL all constituent pages.
53410Sstevel@tonic-gate  *
53420Sstevel@tonic-gate  * To prevent szc changes on file system pages one has to lock all constituent
53430Sstevel@tonic-gate  * pages at least SHARED (or call page_szc_lock()). The only subsystem that
53440Sstevel@tonic-gate  * doesn't rely on locking all constituent pages (or using page_szc_lock()) to
53450Sstevel@tonic-gate  * prevent szc changes is hat layer that uses its own page level mlist
53460Sstevel@tonic-gate  * locks. hat assumes that szc doesn't change after mlist lock for a page is
53470Sstevel@tonic-gate  * taken. Therefore we need to change szc under hat level locks if we only
53480Sstevel@tonic-gate  * have an EXCL lock on a single constituent page and hat still references any
53490Sstevel@tonic-gate  * of constituent pages.  (Note we can't "ignore" hat layer by simply
53500Sstevel@tonic-gate  * hat_pageunload() all constituent pages without having EXCL locks on all of
53510Sstevel@tonic-gate  * constituent pages). We use hat_page_demote() call to safely demote szc of
53520Sstevel@tonic-gate  * all constituent pages under hat locks when we only have an EXCL lock on one
53530Sstevel@tonic-gate  * of constituent pages.
53540Sstevel@tonic-gate  *
53550Sstevel@tonic-gate  * This routine calls page_szc_lock() before calling hat_page_demote() to
53560Sstevel@tonic-gate  * allow segvn in one special case not to lock all constituent pages SHARED
5357*5331Samw  * before calling hat_memload_array() that relies on p_szc not changing even
53580Sstevel@tonic-gate  * before hat level mlist lock is taken.  In that case segvn uses
5359*5331Samw  * page_szc_lock() to prevent hat_page_demote() changing p_szc values.
53600Sstevel@tonic-gate  *
53610Sstevel@tonic-gate  * Anonymous or kernel page demotion still has to lock all pages exclusively
53620Sstevel@tonic-gate  * and do hat_pageunload() on all constituent pages before demoting the page
53630Sstevel@tonic-gate  * therefore there's no need for anonymous or kernel page demotion to use
53640Sstevel@tonic-gate  * hat_page_demote() mechanism.
53650Sstevel@tonic-gate  *
53660Sstevel@tonic-gate  * hat_page_demote() removes all large mappings that map pp and then decreases
53670Sstevel@tonic-gate  * p_szc starting from the last constituent page of the large page. By working
53680Sstevel@tonic-gate  * from the tail of a large page in pfn decreasing order allows one looking at
53690Sstevel@tonic-gate  * the root page to know that hat_page_demote() is done for root's szc area.
53700Sstevel@tonic-gate  * e.g. if a root page has szc 1 one knows it only has to lock all constituent
53710Sstevel@tonic-gate  * pages within szc 1 area to prevent szc changes because hat_page_demote()
53720Sstevel@tonic-gate  * that started on this page when it had szc > 1 is done for this szc 1 area.
53730Sstevel@tonic-gate  *
5374*5331Samw  * We are guaranteed that all constituent pages of pp's large page belong to
53750Sstevel@tonic-gate  * the same vnode with the consecutive offsets increasing in the direction of
53760Sstevel@tonic-gate  * the pfn i.e. the identity of constituent pages can't change until their
53770Sstevel@tonic-gate  * p_szc is decreased. Therefore it's safe for hat_page_demote() to remove
53780Sstevel@tonic-gate  * large mappings to pp even though we don't lock any constituent page except
53790Sstevel@tonic-gate  * pp (i.e. we won't unload e.g. kernel locked page).
53800Sstevel@tonic-gate  */
53810Sstevel@tonic-gate static void
53820Sstevel@tonic-gate page_demote_vp_pages(page_t *pp)
53830Sstevel@tonic-gate {
53840Sstevel@tonic-gate 	kmutex_t *mtx;
53850Sstevel@tonic-gate 
53860Sstevel@tonic-gate 	ASSERT(PAGE_EXCL(pp));
53870Sstevel@tonic-gate 	ASSERT(!PP_ISFREE(pp));
53880Sstevel@tonic-gate 	ASSERT(pp->p_vnode != NULL);
53890Sstevel@tonic-gate 	ASSERT(!IS_SWAPFSVP(pp->p_vnode));
53903290Sjohansen 	ASSERT(!PP_ISKAS(pp));
53910Sstevel@tonic-gate 
53920Sstevel@tonic-gate 	VM_STAT_ADD(pagecnt.pc_demote_pages[0]);
53930Sstevel@tonic-gate 
53940Sstevel@tonic-gate 	mtx = page_szc_lock(pp);
53950Sstevel@tonic-gate 	if (mtx != NULL) {
53960Sstevel@tonic-gate 		hat_page_demote(pp);
53970Sstevel@tonic-gate 		mutex_exit(mtx);
53980Sstevel@tonic-gate 	}
53990Sstevel@tonic-gate 	ASSERT(pp->p_szc == 0);
54000Sstevel@tonic-gate }
54010Sstevel@tonic-gate 
54020Sstevel@tonic-gate /*
54030Sstevel@tonic-gate  * Mark any existing pages for migration in the given range
54040Sstevel@tonic-gate  */
54050Sstevel@tonic-gate void
54060Sstevel@tonic-gate page_mark_migrate(struct seg *seg, caddr_t addr, size_t len,
54070Sstevel@tonic-gate     struct anon_map *amp, ulong_t anon_index, vnode_t *vp,
54080Sstevel@tonic-gate     u_offset_t vnoff, int rflag)
54090Sstevel@tonic-gate {
54100Sstevel@tonic-gate 	struct anon	*ap;
54110Sstevel@tonic-gate 	vnode_t		*curvp;
54120Sstevel@tonic-gate 	lgrp_t		*from;
54130Sstevel@tonic-gate 	pgcnt_t		i;
54140Sstevel@tonic-gate 	pgcnt_t		nlocked;
54150Sstevel@tonic-gate 	u_offset_t	off;
54160Sstevel@tonic-gate 	pfn_t		pfn;
54170Sstevel@tonic-gate 	size_t		pgsz;
54180Sstevel@tonic-gate 	size_t		segpgsz;
54190Sstevel@tonic-gate 	pgcnt_t		pages;
54200Sstevel@tonic-gate 	uint_t		pszc;
54210Sstevel@tonic-gate 	page_t		**ppa;
54220Sstevel@tonic-gate 	pgcnt_t		ppa_nentries;
54230Sstevel@tonic-gate 	page_t		*pp;
54240Sstevel@tonic-gate 	caddr_t		va;
54250Sstevel@tonic-gate 	ulong_t		an_idx;
54260Sstevel@tonic-gate 	anon_sync_obj_t	cookie;
54270Sstevel@tonic-gate 
54280Sstevel@tonic-gate 	ASSERT(seg->s_as && AS_LOCK_HELD(seg->s_as, &seg->s_as->a_lock));
54290Sstevel@tonic-gate 
54300Sstevel@tonic-gate 	/*
54310Sstevel@tonic-gate 	 * Don't do anything if don't need to do lgroup optimizations
54320Sstevel@tonic-gate 	 * on this system
54330Sstevel@tonic-gate 	 */
54340Sstevel@tonic-gate 	if (!lgrp_optimizations())
54350Sstevel@tonic-gate 		return;
54360Sstevel@tonic-gate 
54370Sstevel@tonic-gate 	/*
54380Sstevel@tonic-gate 	 * Align address and length to (potentially large) page boundary
54390Sstevel@tonic-gate 	 */
54400Sstevel@tonic-gate 	segpgsz = page_get_pagesize(seg->s_szc);
54410Sstevel@tonic-gate 	addr = (caddr_t)P2ALIGN((uintptr_t)addr, segpgsz);
54420Sstevel@tonic-gate 	if (rflag)
54430Sstevel@tonic-gate 		len = P2ROUNDUP(len, segpgsz);
54440Sstevel@tonic-gate 
54450Sstevel@tonic-gate 	/*
5446*5331Samw 	 * Allocate page array to accommodate largest page size
54470Sstevel@tonic-gate 	 */
54480Sstevel@tonic-gate 	pgsz = page_get_pagesize(page_num_pagesizes() - 1);
54490Sstevel@tonic-gate 	ppa_nentries = btop(pgsz);
54500Sstevel@tonic-gate 	ppa = kmem_zalloc(ppa_nentries * sizeof (page_t *), KM_SLEEP);
54510Sstevel@tonic-gate 
54520Sstevel@tonic-gate 	/*
54530Sstevel@tonic-gate 	 * Do one (large) page at a time
54540Sstevel@tonic-gate 	 */
54550Sstevel@tonic-gate 	va = addr;
54560Sstevel@tonic-gate 	while (va < addr + len) {
54570Sstevel@tonic-gate 		/*
54580Sstevel@tonic-gate 		 * Lookup (root) page for vnode and offset corresponding to
54590Sstevel@tonic-gate 		 * this virtual address
54600Sstevel@tonic-gate 		 * Try anonmap first since there may be copy-on-write
54610Sstevel@tonic-gate 		 * pages, but initialize vnode pointer and offset using
54620Sstevel@tonic-gate 		 * vnode arguments just in case there isn't an amp.
54630Sstevel@tonic-gate 		 */
54640Sstevel@tonic-gate 		curvp = vp;
54650Sstevel@tonic-gate 		off = vnoff + va - seg->s_base;
54660Sstevel@tonic-gate 		if (amp) {
54670Sstevel@tonic-gate 			ANON_LOCK_ENTER(&amp->a_rwlock, RW_READER);
54680Sstevel@tonic-gate 			an_idx = anon_index + seg_page(seg, va);
54690Sstevel@tonic-gate 			anon_array_enter(amp, an_idx, &cookie);
54700Sstevel@tonic-gate 			ap = anon_get_ptr(amp->ahp, an_idx);
54710Sstevel@tonic-gate 			if (ap)
54720Sstevel@tonic-gate 				swap_xlate(ap, &curvp, &off);
54730Sstevel@tonic-gate 			anon_array_exit(&cookie);
54740Sstevel@tonic-gate 			ANON_LOCK_EXIT(&amp->a_rwlock);
54750Sstevel@tonic-gate 		}
54760Sstevel@tonic-gate 
54770Sstevel@tonic-gate 		pp = NULL;
54780Sstevel@tonic-gate 		if (curvp)
54790Sstevel@tonic-gate 			pp = page_lookup(curvp, off, SE_SHARED);
54800Sstevel@tonic-gate 
54810Sstevel@tonic-gate 		/*
54820Sstevel@tonic-gate 		 * If there isn't a page at this virtual address,
54830Sstevel@tonic-gate 		 * skip to next page
54840Sstevel@tonic-gate 		 */
54850Sstevel@tonic-gate 		if (pp == NULL) {
54860Sstevel@tonic-gate 			va += PAGESIZE;
54870Sstevel@tonic-gate 			continue;
54880Sstevel@tonic-gate 		}
54890Sstevel@tonic-gate 
54900Sstevel@tonic-gate 		/*
54910Sstevel@tonic-gate 		 * Figure out which lgroup this page is in for kstats
54920Sstevel@tonic-gate 		 */
54930Sstevel@tonic-gate 		pfn = page_pptonum(pp);
54940Sstevel@tonic-gate 		from = lgrp_pfn_to_lgrp(pfn);
54950Sstevel@tonic-gate 
54960Sstevel@tonic-gate 		/*
54970Sstevel@tonic-gate 		 * Get page size, and round up and skip to next page boundary
54980Sstevel@tonic-gate 		 * if unaligned address
54990Sstevel@tonic-gate 		 */
55000Sstevel@tonic-gate 		pszc = pp->p_szc;
55010Sstevel@tonic-gate 		pgsz = page_get_pagesize(pszc);
55020Sstevel@tonic-gate 		pages = btop(pgsz);
55030Sstevel@tonic-gate 		if (!IS_P2ALIGNED(va, pgsz) ||
55040Sstevel@tonic-gate 		    !IS_P2ALIGNED(pfn, pages) ||
55050Sstevel@tonic-gate 		    pgsz > segpgsz) {
55060Sstevel@tonic-gate 			pgsz = MIN(pgsz, segpgsz);
55070Sstevel@tonic-gate 			page_unlock(pp);
55080Sstevel@tonic-gate 			i = btop(P2END((uintptr_t)va, pgsz) -
55090Sstevel@tonic-gate 			    (uintptr_t)va);
55100Sstevel@tonic-gate 			va = (caddr_t)P2END((uintptr_t)va, pgsz);
55110Sstevel@tonic-gate 			lgrp_stat_add(from->lgrp_id, LGRP_PMM_FAIL_PGS, i);
55120Sstevel@tonic-gate 			continue;
55130Sstevel@tonic-gate 		}
55140Sstevel@tonic-gate 
55150Sstevel@tonic-gate 		/*
55160Sstevel@tonic-gate 		 * Upgrade to exclusive lock on page
55170Sstevel@tonic-gate 		 */
55180Sstevel@tonic-gate 		if (!page_tryupgrade(pp)) {
55190Sstevel@tonic-gate 			page_unlock(pp);
55200Sstevel@tonic-gate 			va += pgsz;
55210Sstevel@tonic-gate 			lgrp_stat_add(from->lgrp_id, LGRP_PMM_FAIL_PGS,
55220Sstevel@tonic-gate 			    btop(pgsz));
55230Sstevel@tonic-gate 			continue;
55240Sstevel@tonic-gate 		}
55250Sstevel@tonic-gate 
55260Sstevel@tonic-gate 		/*
55270Sstevel@tonic-gate 		 * Remember pages locked exclusively and how many
55280Sstevel@tonic-gate 		 */
55290Sstevel@tonic-gate 		ppa[0] = pp;
55300Sstevel@tonic-gate 		nlocked = 1;
55310Sstevel@tonic-gate 
55320Sstevel@tonic-gate 		/*
55330Sstevel@tonic-gate 		 * Lock constituent pages if this is large page
55340Sstevel@tonic-gate 		 */
55350Sstevel@tonic-gate 		if (pages > 1) {
55360Sstevel@tonic-gate 			/*
55370Sstevel@tonic-gate 			 * Lock all constituents except root page, since it
55380Sstevel@tonic-gate 			 * should be locked already.
55390Sstevel@tonic-gate 			 */
55400Sstevel@tonic-gate 			for (i = 1; i < pages; i++) {
5541414Skchow 				pp++;
55420Sstevel@tonic-gate 				if (!page_trylock(pp, SE_EXCL)) {
55430Sstevel@tonic-gate 					break;
55440Sstevel@tonic-gate 				}
55450Sstevel@tonic-gate 				if (PP_ISFREE(pp) ||
55460Sstevel@tonic-gate 				    pp->p_szc != pszc) {
55470Sstevel@tonic-gate 					/*
55480Sstevel@tonic-gate 					 * hat_page_demote() raced in with us.
55490Sstevel@tonic-gate 					 */
55500Sstevel@tonic-gate 					ASSERT(!IS_SWAPFSVP(curvp));
55510Sstevel@tonic-gate 					page_unlock(pp);
55520Sstevel@tonic-gate 					break;
55530Sstevel@tonic-gate 				}
55540Sstevel@tonic-gate 				ppa[nlocked] = pp;
55550Sstevel@tonic-gate 				nlocked++;
55560Sstevel@tonic-gate 			}
55570Sstevel@tonic-gate 		}
55580Sstevel@tonic-gate 
55590Sstevel@tonic-gate 		/*
55600Sstevel@tonic-gate 		 * If all constituent pages couldn't be locked,
55610Sstevel@tonic-gate 		 * unlock pages locked so far and skip to next page.
55620Sstevel@tonic-gate 		 */
55630Sstevel@tonic-gate 		if (nlocked != pages) {
55640Sstevel@tonic-gate 			for (i = 0; i < nlocked; i++)
55650Sstevel@tonic-gate 				page_unlock(ppa[i]);
55660Sstevel@tonic-gate 			va += pgsz;
55670Sstevel@tonic-gate 			lgrp_stat_add(from->lgrp_id, LGRP_PMM_FAIL_PGS,
55680Sstevel@tonic-gate 			    btop(pgsz));
55690Sstevel@tonic-gate 			continue;
55700Sstevel@tonic-gate 		}
55710Sstevel@tonic-gate 
55720Sstevel@tonic-gate 		/*
55730Sstevel@tonic-gate 		 * hat_page_demote() can no longer happen
55740Sstevel@tonic-gate 		 * since last cons page had the right p_szc after
55750Sstevel@tonic-gate 		 * all cons pages were locked. all cons pages
55760Sstevel@tonic-gate 		 * should now have the same p_szc.
55770Sstevel@tonic-gate 		 */
55780Sstevel@tonic-gate 
55790Sstevel@tonic-gate 		/*
55800Sstevel@tonic-gate 		 * All constituent pages locked successfully, so mark
55810Sstevel@tonic-gate 		 * large page for migration and unload the mappings of
55820Sstevel@tonic-gate 		 * constituent pages, so a fault will occur on any part of the
55830Sstevel@tonic-gate 		 * large page
55840Sstevel@tonic-gate 		 */
55850Sstevel@tonic-gate 		PP_SETMIGRATE(ppa[0]);
55860Sstevel@tonic-gate 		for (i = 0; i < nlocked; i++) {
55870Sstevel@tonic-gate 			pp = ppa[i];
55880Sstevel@tonic-gate 			(void) hat_pageunload(pp, HAT_FORCE_PGUNLOAD);
55890Sstevel@tonic-gate 			ASSERT(hat_page_getshare(pp) == 0);
55900Sstevel@tonic-gate 			page_unlock(pp);
55910Sstevel@tonic-gate 		}
55920Sstevel@tonic-gate 		lgrp_stat_add(from->lgrp_id, LGRP_PMM_PGS, nlocked);
55930Sstevel@tonic-gate 
55940Sstevel@tonic-gate 		va += pgsz;
55950Sstevel@tonic-gate 	}
55960Sstevel@tonic-gate 	kmem_free(ppa, ppa_nentries * sizeof (page_t *));
55970Sstevel@tonic-gate }
55980Sstevel@tonic-gate 
55990Sstevel@tonic-gate /*
56000Sstevel@tonic-gate  * Migrate any pages that have been marked for migration in the given range
56010Sstevel@tonic-gate  */
56020Sstevel@tonic-gate void
56030Sstevel@tonic-gate page_migrate(
56040Sstevel@tonic-gate 	struct seg	*seg,
56050Sstevel@tonic-gate 	caddr_t		addr,
56060Sstevel@tonic-gate 	page_t		**ppa,
56070Sstevel@tonic-gate 	pgcnt_t		npages)
56080Sstevel@tonic-gate {
56090Sstevel@tonic-gate 	lgrp_t		*from;
56100Sstevel@tonic-gate 	lgrp_t		*to;
56110Sstevel@tonic-gate 	page_t		*newpp;
56120Sstevel@tonic-gate 	page_t		*pp;
56130Sstevel@tonic-gate 	pfn_t		pfn;
56140Sstevel@tonic-gate 	size_t		pgsz;
56150Sstevel@tonic-gate 	spgcnt_t	page_cnt;
56160Sstevel@tonic-gate 	spgcnt_t	i;
56170Sstevel@tonic-gate 	uint_t		pszc;
56180Sstevel@tonic-gate 
56190Sstevel@tonic-gate 	ASSERT(seg->s_as && AS_LOCK_HELD(seg->s_as, &seg->s_as->a_lock));
56200Sstevel@tonic-gate 
56210Sstevel@tonic-gate 	while (npages > 0) {
56220Sstevel@tonic-gate 		pp = *ppa;
56230Sstevel@tonic-gate 		pszc = pp->p_szc;
56240Sstevel@tonic-gate 		pgsz = page_get_pagesize(pszc);
56250Sstevel@tonic-gate 		page_cnt = btop(pgsz);
56260Sstevel@tonic-gate 
56270Sstevel@tonic-gate 		/*
56280Sstevel@tonic-gate 		 * Check to see whether this page is marked for migration
56290Sstevel@tonic-gate 		 *
56300Sstevel@tonic-gate 		 * Assume that root page of large page is marked for
56310Sstevel@tonic-gate 		 * migration and none of the other constituent pages
56320Sstevel@tonic-gate 		 * are marked.  This really simplifies clearing the
56330Sstevel@tonic-gate 		 * migrate bit by not having to clear it from each
56340Sstevel@tonic-gate 		 * constituent page.
56350Sstevel@tonic-gate 		 *
56360Sstevel@tonic-gate 		 * note we don't want to relocate an entire large page if
56370Sstevel@tonic-gate 		 * someone is only using one subpage.
56380Sstevel@tonic-gate 		 */
56390Sstevel@tonic-gate 		if (npages < page_cnt)
56400Sstevel@tonic-gate 			break;
56410Sstevel@tonic-gate 
56420Sstevel@tonic-gate 		/*
56430Sstevel@tonic-gate 		 * Is it marked for migration?
56440Sstevel@tonic-gate 		 */
56450Sstevel@tonic-gate 		if (!PP_ISMIGRATE(pp))
56460Sstevel@tonic-gate 			goto next;
56470Sstevel@tonic-gate 
56480Sstevel@tonic-gate 		/*
56490Sstevel@tonic-gate 		 * Determine lgroups that page is being migrated between
56500Sstevel@tonic-gate 		 */
56510Sstevel@tonic-gate 		pfn = page_pptonum(pp);
56520Sstevel@tonic-gate 		if (!IS_P2ALIGNED(pfn, page_cnt)) {
56530Sstevel@tonic-gate 			break;
56540Sstevel@tonic-gate 		}
56550Sstevel@tonic-gate 		from = lgrp_pfn_to_lgrp(pfn);
56560Sstevel@tonic-gate 		to = lgrp_mem_choose(seg, addr, pgsz);
56570Sstevel@tonic-gate 
56580Sstevel@tonic-gate 		/*
56590Sstevel@tonic-gate 		 * Check to see whether we are trying to migrate page to lgroup
56600Sstevel@tonic-gate 		 * where it is allocated already
56610Sstevel@tonic-gate 		 */
56620Sstevel@tonic-gate 		if (to == from) {
56630Sstevel@tonic-gate 			PP_CLRMIGRATE(pp);
56640Sstevel@tonic-gate 			goto next;
56650Sstevel@tonic-gate 		}
56660Sstevel@tonic-gate 
56670Sstevel@tonic-gate 		/*
56680Sstevel@tonic-gate 		 * Need to get exclusive lock's to migrate
56690Sstevel@tonic-gate 		 */
56700Sstevel@tonic-gate 		for (i = 0; i < page_cnt; i++) {
56710Sstevel@tonic-gate 			ASSERT(PAGE_LOCKED(ppa[i]));
56720Sstevel@tonic-gate 			if (page_pptonum(ppa[i]) != pfn + i ||
56730Sstevel@tonic-gate 			    ppa[i]->p_szc != pszc) {
56740Sstevel@tonic-gate 				break;
56750Sstevel@tonic-gate 			}
56760Sstevel@tonic-gate 			if (!page_tryupgrade(ppa[i])) {
56770Sstevel@tonic-gate 				lgrp_stat_add(from->lgrp_id,
56780Sstevel@tonic-gate 				    LGRP_PM_FAIL_LOCK_PGS,
56790Sstevel@tonic-gate 				    page_cnt);
56800Sstevel@tonic-gate 				break;
56810Sstevel@tonic-gate 			}
56820Sstevel@tonic-gate 		}
56830Sstevel@tonic-gate 		if (i != page_cnt) {
56840Sstevel@tonic-gate 			while (--i != -1) {
56850Sstevel@tonic-gate 				page_downgrade(ppa[i]);
56860Sstevel@tonic-gate 			}
56870Sstevel@tonic-gate 			goto next;
56880Sstevel@tonic-gate 		}
56890Sstevel@tonic-gate 
56900Sstevel@tonic-gate 		(void) page_create_wait(page_cnt, PG_WAIT);
56910Sstevel@tonic-gate 		newpp = page_get_replacement_page(pp, to, PGR_SAMESZC);
56920Sstevel@tonic-gate 		if (newpp == NULL) {
56930Sstevel@tonic-gate 			page_create_putback(page_cnt);
56940Sstevel@tonic-gate 			for (i = 0; i < page_cnt; i++) {
56950Sstevel@tonic-gate 				page_downgrade(ppa[i]);
56960Sstevel@tonic-gate 			}
56970Sstevel@tonic-gate 			lgrp_stat_add(to->lgrp_id, LGRP_PM_FAIL_ALLOC_PGS,
56980Sstevel@tonic-gate 			    page_cnt);
56990Sstevel@tonic-gate 			goto next;
57000Sstevel@tonic-gate 		}
57010Sstevel@tonic-gate 		ASSERT(newpp->p_szc == pszc);
57020Sstevel@tonic-gate 		/*
57030Sstevel@tonic-gate 		 * Clear migrate bit and relocate page
57040Sstevel@tonic-gate 		 */
57050Sstevel@tonic-gate 		PP_CLRMIGRATE(pp);
57060Sstevel@tonic-gate 		if (page_relocate(&pp, &newpp, 0, 1, &page_cnt, to)) {
57070Sstevel@tonic-gate 			panic("page_migrate: page_relocate failed");
57080Sstevel@tonic-gate 		}
57090Sstevel@tonic-gate 		ASSERT(page_cnt * PAGESIZE == pgsz);
57100Sstevel@tonic-gate 
57110Sstevel@tonic-gate 		/*
57120Sstevel@tonic-gate 		 * Keep stats for number of pages migrated from and to
57130Sstevel@tonic-gate 		 * each lgroup
57140Sstevel@tonic-gate 		 */
57150Sstevel@tonic-gate 		lgrp_stat_add(from->lgrp_id, LGRP_PM_SRC_PGS, page_cnt);
57160Sstevel@tonic-gate 		lgrp_stat_add(to->lgrp_id, LGRP_PM_DEST_PGS, page_cnt);
57170Sstevel@tonic-gate 		/*
57180Sstevel@tonic-gate 		 * update the page_t array we were passed in and
57190Sstevel@tonic-gate 		 * unlink constituent pages of a large page.
57200Sstevel@tonic-gate 		 */
57210Sstevel@tonic-gate 		for (i = 0; i < page_cnt; ++i, ++pp) {
57220Sstevel@tonic-gate 			ASSERT(PAGE_EXCL(newpp));
57230Sstevel@tonic-gate 			ASSERT(newpp->p_szc == pszc);
57240Sstevel@tonic-gate 			ppa[i] = newpp;
57250Sstevel@tonic-gate 			pp = newpp;
57260Sstevel@tonic-gate 			page_sub(&newpp, pp);
57270Sstevel@tonic-gate 			page_downgrade(pp);
57280Sstevel@tonic-gate 		}
57290Sstevel@tonic-gate 		ASSERT(newpp == NULL);
57300Sstevel@tonic-gate next:
57310Sstevel@tonic-gate 		addr += pgsz;
57320Sstevel@tonic-gate 		ppa += page_cnt;
57330Sstevel@tonic-gate 		npages -= page_cnt;
57340Sstevel@tonic-gate 	}
57350Sstevel@tonic-gate }
57360Sstevel@tonic-gate 
57370Sstevel@tonic-gate ulong_t mem_waiters 	= 0;
57380Sstevel@tonic-gate ulong_t	max_count 	= 20;
57390Sstevel@tonic-gate #define	MAX_DELAY	0x1ff
57400Sstevel@tonic-gate 
57410Sstevel@tonic-gate /*
57420Sstevel@tonic-gate  * Check if enough memory is available to proceed.
57430Sstevel@tonic-gate  * Depending on system configuration and how much memory is
57440Sstevel@tonic-gate  * reserved for swap we need to check against two variables.
57450Sstevel@tonic-gate  * e.g. on systems with little physical swap availrmem can be
57460Sstevel@tonic-gate  * more reliable indicator of how much memory is available.
57470Sstevel@tonic-gate  * On systems with large phys swap freemem can be better indicator.
57480Sstevel@tonic-gate  * If freemem drops below threshold level don't return an error
57490Sstevel@tonic-gate  * immediately but wake up pageout to free memory and block.
57500Sstevel@tonic-gate  * This is done number of times. If pageout is not able to free
57510Sstevel@tonic-gate  * memory within certain time return an error.
57520Sstevel@tonic-gate  * The same applies for availrmem but kmem_reap is used to
57530Sstevel@tonic-gate  * free memory.
57540Sstevel@tonic-gate  */
57550Sstevel@tonic-gate int
57560Sstevel@tonic-gate page_mem_avail(pgcnt_t npages)
57570Sstevel@tonic-gate {
57580Sstevel@tonic-gate 	ulong_t count;
57590Sstevel@tonic-gate 
57600Sstevel@tonic-gate #if defined(__i386)
57610Sstevel@tonic-gate 	if (freemem > desfree + npages &&
57620Sstevel@tonic-gate 	    availrmem > swapfs_reserve + npages &&
57630Sstevel@tonic-gate 	    btop(vmem_size(heap_arena, VMEM_FREE)) > tune.t_minarmem +
57640Sstevel@tonic-gate 	    npages)
57650Sstevel@tonic-gate 		return (1);
57660Sstevel@tonic-gate #else
57670Sstevel@tonic-gate 	if (freemem > desfree + npages &&
57680Sstevel@tonic-gate 	    availrmem > swapfs_reserve + npages)
57690Sstevel@tonic-gate 		return (1);
57700Sstevel@tonic-gate #endif
57710Sstevel@tonic-gate 
57720Sstevel@tonic-gate 	count = max_count;
57730Sstevel@tonic-gate 	atomic_add_long(&mem_waiters, 1);
57740Sstevel@tonic-gate 
57750Sstevel@tonic-gate 	while (freemem < desfree + npages && --count) {
57760Sstevel@tonic-gate 		cv_signal(&proc_pageout->p_cv);
57770Sstevel@tonic-gate 		if (delay_sig(hz + (mem_waiters & MAX_DELAY))) {
57780Sstevel@tonic-gate 			atomic_add_long(&mem_waiters, -1);
57790Sstevel@tonic-gate 			return (0);
57800Sstevel@tonic-gate 		}
57810Sstevel@tonic-gate 	}
57820Sstevel@tonic-gate 	if (count == 0) {
57830Sstevel@tonic-gate 		atomic_add_long(&mem_waiters, -1);
57840Sstevel@tonic-gate 		return (0);
57850Sstevel@tonic-gate 	}
57860Sstevel@tonic-gate 
57870Sstevel@tonic-gate 	count = max_count;
57880Sstevel@tonic-gate 	while (availrmem < swapfs_reserve + npages && --count) {
57890Sstevel@tonic-gate 		kmem_reap();
57900Sstevel@tonic-gate 		if (delay_sig(hz + (mem_waiters & MAX_DELAY))) {
57910Sstevel@tonic-gate 			atomic_add_long(&mem_waiters, -1);
57920Sstevel@tonic-gate 			return (0);
57930Sstevel@tonic-gate 		}
57940Sstevel@tonic-gate 	}
57950Sstevel@tonic-gate 	atomic_add_long(&mem_waiters, -1);
57960Sstevel@tonic-gate 	if (count == 0)
57970Sstevel@tonic-gate 		return (0);
57980Sstevel@tonic-gate 
57990Sstevel@tonic-gate #if defined(__i386)
58000Sstevel@tonic-gate 	if (btop(vmem_size(heap_arena, VMEM_FREE)) <
58010Sstevel@tonic-gate 	    tune.t_minarmem + npages)
58020Sstevel@tonic-gate 		return (0);
58030Sstevel@tonic-gate #endif
58040Sstevel@tonic-gate 	return (1);
58050Sstevel@tonic-gate }
58060Sstevel@tonic-gate 
58072048Sstans #define	MAX_CNT	60	/* max num of iterations */
58082048Sstans /*
58092048Sstans  * Reclaim/reserve availrmem for npages.
58102048Sstans  * If there is not enough memory start reaping seg, kmem caches.
58112048Sstans  * Start pageout scanner (via page_needfree()).
58122048Sstans  * Exit after ~ MAX_CNT s regardless of how much memory has been released.
58132048Sstans  * Note: There is no guarantee that any availrmem will be freed as
58142048Sstans  * this memory typically is locked (kernel heap) or reserved for swap.
58152048Sstans  * Also due to memory fragmentation kmem allocator may not be able
58162048Sstans  * to free any memory (single user allocated buffer will prevent
58172048Sstans  * freeing slab or a page).
58182048Sstans  */
58192048Sstans int
58202048Sstans page_reclaim_mem(pgcnt_t npages, pgcnt_t epages, int adjust)
58212048Sstans {
58222048Sstans 	int	i = 0;
58232048Sstans 	int	ret = 0;
58242048Sstans 	pgcnt_t	deficit;
58252048Sstans 	pgcnt_t old_availrmem;
58262048Sstans 
58272048Sstans 	mutex_enter(&freemem_lock);
58282048Sstans 	old_availrmem = availrmem - 1;
58292048Sstans 	while ((availrmem < tune.t_minarmem + npages + epages) &&
58302048Sstans 	    (old_availrmem < availrmem) && (i++ < MAX_CNT)) {
58312048Sstans 		old_availrmem = availrmem;
58322048Sstans 		deficit = tune.t_minarmem + npages + epages - availrmem;
58332048Sstans 		mutex_exit(&freemem_lock);
58342048Sstans 		page_needfree(deficit);
58352048Sstans 		seg_preap();
58362048Sstans 		kmem_reap();
58372048Sstans 		delay(hz);
58382048Sstans 		page_needfree(-(spgcnt_t)deficit);
58392048Sstans 		mutex_enter(&freemem_lock);
58402048Sstans 	}
58412048Sstans 
58422048Sstans 	if (adjust && (availrmem >= tune.t_minarmem + npages + epages)) {
58432048Sstans 		availrmem -= npages;
58442048Sstans 		ret = 1;
58452048Sstans 	}
58462048Sstans 
58472048Sstans 	mutex_exit(&freemem_lock);
58482048Sstans 
58492048Sstans 	return (ret);
58502048Sstans }
58510Sstevel@tonic-gate 
58520Sstevel@tonic-gate /*
58530Sstevel@tonic-gate  * Search the memory segments to locate the desired page.  Within a
58540Sstevel@tonic-gate  * segment, pages increase linearly with one page structure per
58550Sstevel@tonic-gate  * physical page frame (size PAGESIZE).  The search begins
58560Sstevel@tonic-gate  * with the segment that was accessed last, to take advantage of locality.
58570Sstevel@tonic-gate  * If the hint misses, we start from the beginning of the sorted memseg list
58580Sstevel@tonic-gate  */
58590Sstevel@tonic-gate 
58600Sstevel@tonic-gate 
58610Sstevel@tonic-gate /*
58620Sstevel@tonic-gate  * Some data structures for pfn to pp lookup.
58630Sstevel@tonic-gate  */
58640Sstevel@tonic-gate ulong_t mhash_per_slot;
58650Sstevel@tonic-gate struct memseg *memseg_hash[N_MEM_SLOTS];
58660Sstevel@tonic-gate 
58670Sstevel@tonic-gate page_t *
58680Sstevel@tonic-gate page_numtopp_nolock(pfn_t pfnum)
58690Sstevel@tonic-gate {
58700Sstevel@tonic-gate 	struct memseg *seg;
58710Sstevel@tonic-gate 	page_t *pp;
5872414Skchow 	vm_cpu_data_t *vc = CPU->cpu_vm_data;
5873414Skchow 
5874414Skchow 	ASSERT(vc != NULL);
58750Sstevel@tonic-gate 
58760Sstevel@tonic-gate 	MEMSEG_STAT_INCR(nsearch);
58770Sstevel@tonic-gate 
58780Sstevel@tonic-gate 	/* Try last winner first */
5879414Skchow 	if (((seg = vc->vc_pnum_memseg) != NULL) &&
58803559Smec 	    (pfnum >= seg->pages_base) && (pfnum < seg->pages_end)) {
58810Sstevel@tonic-gate 		MEMSEG_STAT_INCR(nlastwon);
58820Sstevel@tonic-gate 		pp = seg->pages + (pfnum - seg->pages_base);
58830Sstevel@tonic-gate 		if (pp->p_pagenum == pfnum)
58840Sstevel@tonic-gate 			return ((page_t *)pp);
58850Sstevel@tonic-gate 	}
58860Sstevel@tonic-gate 
58870Sstevel@tonic-gate 	/* Else Try hash */
58880Sstevel@tonic-gate 	if (((seg = memseg_hash[MEMSEG_PFN_HASH(pfnum)]) != NULL) &&
58893559Smec 	    (pfnum >= seg->pages_base) && (pfnum < seg->pages_end)) {
58900Sstevel@tonic-gate 		MEMSEG_STAT_INCR(nhashwon);
5891414Skchow 		vc->vc_pnum_memseg = seg;
58920Sstevel@tonic-gate 		pp = seg->pages + (pfnum - seg->pages_base);
58930Sstevel@tonic-gate 		if (pp->p_pagenum == pfnum)
58940Sstevel@tonic-gate 			return ((page_t *)pp);
58950Sstevel@tonic-gate 	}
58960Sstevel@tonic-gate 
58970Sstevel@tonic-gate 	/* Else Brute force */
58980Sstevel@tonic-gate 	for (seg = memsegs; seg != NULL; seg = seg->next) {
58990Sstevel@tonic-gate 		if (pfnum >= seg->pages_base && pfnum < seg->pages_end) {
5900414Skchow 			vc->vc_pnum_memseg = seg;
59010Sstevel@tonic-gate 			pp = seg->pages + (pfnum - seg->pages_base);
59020Sstevel@tonic-gate 			return ((page_t *)pp);
59030Sstevel@tonic-gate 		}
59040Sstevel@tonic-gate 	}
5905414Skchow 	vc->vc_pnum_memseg = NULL;
59060Sstevel@tonic-gate 	MEMSEG_STAT_INCR(nnotfound);
59070Sstevel@tonic-gate 	return ((page_t *)NULL);
59080Sstevel@tonic-gate 
59090Sstevel@tonic-gate }
59100Sstevel@tonic-gate 
59110Sstevel@tonic-gate struct memseg *
59120Sstevel@tonic-gate page_numtomemseg_nolock(pfn_t pfnum)
59130Sstevel@tonic-gate {
59140Sstevel@tonic-gate 	struct memseg *seg;
59150Sstevel@tonic-gate 	page_t *pp;
59160Sstevel@tonic-gate 
59170Sstevel@tonic-gate 	/* Try hash */
59180Sstevel@tonic-gate 	if (((seg = memseg_hash[MEMSEG_PFN_HASH(pfnum)]) != NULL) &&
59193559Smec 	    (pfnum >= seg->pages_base) && (pfnum < seg->pages_end)) {
59200Sstevel@tonic-gate 		pp = seg->pages + (pfnum - seg->pages_base);
59210Sstevel@tonic-gate 		if (pp->p_pagenum == pfnum)
59220Sstevel@tonic-gate 			return (seg);
59230Sstevel@tonic-gate 	}
59240Sstevel@tonic-gate 
59250Sstevel@tonic-gate 	/* Else Brute force */
59260Sstevel@tonic-gate 	for (seg = memsegs; seg != NULL; seg = seg->next) {
59270Sstevel@tonic-gate 		if (pfnum >= seg->pages_base && pfnum < seg->pages_end) {
59280Sstevel@tonic-gate 			return (seg);
59290Sstevel@tonic-gate 		}
59300Sstevel@tonic-gate 	}
59310Sstevel@tonic-gate 	return ((struct memseg *)NULL);
59320Sstevel@tonic-gate }
59330Sstevel@tonic-gate 
59340Sstevel@tonic-gate /*
59350Sstevel@tonic-gate  * Given a page and a count return the page struct that is
59360Sstevel@tonic-gate  * n structs away from the current one in the global page
59370Sstevel@tonic-gate  * list.
59380Sstevel@tonic-gate  *
59390Sstevel@tonic-gate  * This function wraps to the first page upon
59400Sstevel@tonic-gate  * reaching the end of the memseg list.
59410Sstevel@tonic-gate  */
59420Sstevel@tonic-gate page_t *
59430Sstevel@tonic-gate page_nextn(page_t *pp, ulong_t n)
59440Sstevel@tonic-gate {
59450Sstevel@tonic-gate 	struct memseg *seg;
59460Sstevel@tonic-gate 	page_t *ppn;
5947414Skchow 	vm_cpu_data_t *vc = (vm_cpu_data_t *)CPU->cpu_vm_data;
5948414Skchow 
5949414Skchow 	ASSERT(vc != NULL);
5950414Skchow 
5951414Skchow 	if (((seg = vc->vc_pnext_memseg) == NULL) ||
59520Sstevel@tonic-gate 	    (seg->pages_base == seg->pages_end) ||
59530Sstevel@tonic-gate 	    !(pp >= seg->pages && pp < seg->epages)) {
59540Sstevel@tonic-gate 
59550Sstevel@tonic-gate 		for (seg = memsegs; seg; seg = seg->next) {
59560Sstevel@tonic-gate 			if (pp >= seg->pages && pp < seg->epages)
59570Sstevel@tonic-gate 				break;
59580Sstevel@tonic-gate 		}
59590Sstevel@tonic-gate 
59600Sstevel@tonic-gate 		if (seg == NULL) {
59610Sstevel@tonic-gate 			/* Memory delete got in, return something valid. */
59620Sstevel@tonic-gate 			/* TODO: fix me. */
59630Sstevel@tonic-gate 			seg = memsegs;
59640Sstevel@tonic-gate 			pp = seg->pages;
59650Sstevel@tonic-gate 		}
59660Sstevel@tonic-gate 	}
59670Sstevel@tonic-gate 
59680Sstevel@tonic-gate 	/* check for wraparound - possible if n is large */
59690Sstevel@tonic-gate 	while ((ppn = (pp + n)) >= seg->epages || ppn < pp) {
59700Sstevel@tonic-gate 		n -= seg->epages - pp;
59710Sstevel@tonic-gate 		seg = seg->next;
59720Sstevel@tonic-gate 		if (seg == NULL)
59730Sstevel@tonic-gate 			seg = memsegs;
59740Sstevel@tonic-gate 		pp = seg->pages;
59750Sstevel@tonic-gate 	}
5976414Skchow 	vc->vc_pnext_memseg = seg;
59770Sstevel@tonic-gate 	return (ppn);
59780Sstevel@tonic-gate }
59790Sstevel@tonic-gate 
59800Sstevel@tonic-gate /*
59810Sstevel@tonic-gate  * Initialize for a loop using page_next_scan_large().
59820Sstevel@tonic-gate  */
59830Sstevel@tonic-gate page_t *
59840Sstevel@tonic-gate page_next_scan_init(void **cookie)
59850Sstevel@tonic-gate {
59860Sstevel@tonic-gate 	ASSERT(cookie != NULL);
59870Sstevel@tonic-gate 	*cookie = (void *)memsegs;
59880Sstevel@tonic-gate 	return ((page_t *)memsegs->pages);
59890Sstevel@tonic-gate }
59900Sstevel@tonic-gate 
59910Sstevel@tonic-gate /*
59920Sstevel@tonic-gate  * Return the next page in a scan of page_t's, assuming we want
59930Sstevel@tonic-gate  * to skip over sub-pages within larger page sizes.
59940Sstevel@tonic-gate  *
59950Sstevel@tonic-gate  * The cookie is used to keep track of the current memseg.
59960Sstevel@tonic-gate  */
59970Sstevel@tonic-gate page_t *
59980Sstevel@tonic-gate page_next_scan_large(
59990Sstevel@tonic-gate 	page_t		*pp,
60000Sstevel@tonic-gate 	ulong_t		*n,
60010Sstevel@tonic-gate 	void		**cookie)
60020Sstevel@tonic-gate {
60030Sstevel@tonic-gate 	struct memseg	*seg = (struct memseg *)*cookie;
60040Sstevel@tonic-gate 	page_t		*new_pp;
60050Sstevel@tonic-gate 	ulong_t		cnt;
60060Sstevel@tonic-gate 	pfn_t		pfn;
60070Sstevel@tonic-gate 
60080Sstevel@tonic-gate 
60090Sstevel@tonic-gate 	/*
60100Sstevel@tonic-gate 	 * get the count of page_t's to skip based on the page size
60110Sstevel@tonic-gate 	 */
60120Sstevel@tonic-gate 	ASSERT(pp != NULL);
60130Sstevel@tonic-gate 	if (pp->p_szc == 0) {
60140Sstevel@tonic-gate 		cnt = 1;
60150Sstevel@tonic-gate 	} else {
60160Sstevel@tonic-gate 		pfn = page_pptonum(pp);
60170Sstevel@tonic-gate 		cnt = page_get_pagecnt(pp->p_szc);
60180Sstevel@tonic-gate 		cnt -= pfn & (cnt - 1);
60190Sstevel@tonic-gate 	}
60200Sstevel@tonic-gate 	*n += cnt;
60210Sstevel@tonic-gate 	new_pp = pp + cnt;
60220Sstevel@tonic-gate 
60230Sstevel@tonic-gate 	/*
60240Sstevel@tonic-gate 	 * Catch if we went past the end of the current memory segment. If so,
60250Sstevel@tonic-gate 	 * just move to the next segment with pages.
60260Sstevel@tonic-gate 	 */
60270Sstevel@tonic-gate 	if (new_pp >= seg->epages) {
60280Sstevel@tonic-gate 		do {
60290Sstevel@tonic-gate 			seg = seg->next;
60300Sstevel@tonic-gate 			if (seg == NULL)
60310Sstevel@tonic-gate 				seg = memsegs;
60320Sstevel@tonic-gate 		} while (seg->pages == seg->epages);
60330Sstevel@tonic-gate 		new_pp = seg->pages;
60340Sstevel@tonic-gate 		*cookie = (void *)seg;
60350Sstevel@tonic-gate 	}
60360Sstevel@tonic-gate 
60370Sstevel@tonic-gate 	return (new_pp);
60380Sstevel@tonic-gate }
60390Sstevel@tonic-gate 
60400Sstevel@tonic-gate 
60410Sstevel@tonic-gate /*
60420Sstevel@tonic-gate  * Returns next page in list. Note: this function wraps
60430Sstevel@tonic-gate  * to the first page in the list upon reaching the end
60440Sstevel@tonic-gate  * of the list. Callers should be aware of this fact.
60450Sstevel@tonic-gate  */
60460Sstevel@tonic-gate 
60470Sstevel@tonic-gate /* We should change this be a #define */
60480Sstevel@tonic-gate 
60490Sstevel@tonic-gate page_t *
60500Sstevel@tonic-gate page_next(page_t *pp)
60510Sstevel@tonic-gate {
60520Sstevel@tonic-gate 	return (page_nextn(pp, 1));
60530Sstevel@tonic-gate }
60540Sstevel@tonic-gate 
60550Sstevel@tonic-gate page_t *
60560Sstevel@tonic-gate page_first()
60570Sstevel@tonic-gate {
60580Sstevel@tonic-gate 	return ((page_t *)memsegs->pages);
60590Sstevel@tonic-gate }
60600Sstevel@tonic-gate 
60610Sstevel@tonic-gate 
60620Sstevel@tonic-gate /*
60630Sstevel@tonic-gate  * This routine is called at boot with the initial memory configuration
60640Sstevel@tonic-gate  * and when memory is added or removed.
60650Sstevel@tonic-gate  */
60660Sstevel@tonic-gate void
60670Sstevel@tonic-gate build_pfn_hash()
60680Sstevel@tonic-gate {
60690Sstevel@tonic-gate 	pfn_t cur;
60700Sstevel@tonic-gate 	pgcnt_t index;
60710Sstevel@tonic-gate 	struct memseg *pseg;
60720Sstevel@tonic-gate 	int	i;
60730Sstevel@tonic-gate 
60740Sstevel@tonic-gate 	/*
60750Sstevel@tonic-gate 	 * Clear memseg_hash array.
60760Sstevel@tonic-gate 	 * Since memory add/delete is designed to operate concurrently
60770Sstevel@tonic-gate 	 * with normal operation, the hash rebuild must be able to run
60780Sstevel@tonic-gate 	 * concurrently with page_numtopp_nolock(). To support this
60790Sstevel@tonic-gate 	 * functionality, assignments to memseg_hash array members must
60800Sstevel@tonic-gate 	 * be done atomically.
60810Sstevel@tonic-gate 	 *
60820Sstevel@tonic-gate 	 * NOTE: bzero() does not currently guarantee this for kernel
60830Sstevel@tonic-gate 	 * threads, and cannot be used here.
60840Sstevel@tonic-gate 	 */
60850Sstevel@tonic-gate 	for (i = 0; i < N_MEM_SLOTS; i++)
60860Sstevel@tonic-gate 		memseg_hash[i] = NULL;
60870Sstevel@tonic-gate 
60880Sstevel@tonic-gate 	hat_kpm_mseghash_clear(N_MEM_SLOTS);
60890Sstevel@tonic-gate 
60900Sstevel@tonic-gate 	/*
60910Sstevel@tonic-gate 	 * Physmax is the last valid pfn.
60920Sstevel@tonic-gate 	 */
60930Sstevel@tonic-gate 	mhash_per_slot = (physmax + 1) >> MEM_HASH_SHIFT;
60940Sstevel@tonic-gate 	for (pseg = memsegs; pseg != NULL; pseg = pseg->next) {
60950Sstevel@tonic-gate 		index = MEMSEG_PFN_HASH(pseg->pages_base);
60960Sstevel@tonic-gate 		cur = pseg->pages_base;
60970Sstevel@tonic-gate 		do {
60980Sstevel@tonic-gate 			if (index >= N_MEM_SLOTS)
60990Sstevel@tonic-gate 				index = MEMSEG_PFN_HASH(cur);
61000Sstevel@tonic-gate 
61010Sstevel@tonic-gate 			if (memseg_hash[index] == NULL ||
61020Sstevel@tonic-gate 			    memseg_hash[index]->pages_base > pseg->pages_base) {
61030Sstevel@tonic-gate 				memseg_hash[index] = pseg;
61040Sstevel@tonic-gate 				hat_kpm_mseghash_update(index, pseg);
61050Sstevel@tonic-gate 			}
61060Sstevel@tonic-gate 			cur += mhash_per_slot;
61070Sstevel@tonic-gate 			index++;
61080Sstevel@tonic-gate 		} while (cur < pseg->pages_end);
61090Sstevel@tonic-gate 	}
61100Sstevel@tonic-gate }
61110Sstevel@tonic-gate 
61120Sstevel@tonic-gate /*
61130Sstevel@tonic-gate  * Return the pagenum for the pp
61140Sstevel@tonic-gate  */
61150Sstevel@tonic-gate pfn_t
61160Sstevel@tonic-gate page_pptonum(page_t *pp)
61170Sstevel@tonic-gate {
61180Sstevel@tonic-gate 	return (pp->p_pagenum);
61190Sstevel@tonic-gate }
61200Sstevel@tonic-gate 
61210Sstevel@tonic-gate /*
61220Sstevel@tonic-gate  * interface to the referenced and modified etc bits
61230Sstevel@tonic-gate  * in the PSM part of the page struct
61240Sstevel@tonic-gate  * when no locking is desired.
61250Sstevel@tonic-gate  */
61260Sstevel@tonic-gate void
61270Sstevel@tonic-gate page_set_props(page_t *pp, uint_t flags)
61280Sstevel@tonic-gate {
61290Sstevel@tonic-gate 	ASSERT((flags & ~(P_MOD | P_REF | P_RO)) == 0);
61300Sstevel@tonic-gate 	pp->p_nrm |= (uchar_t)flags;
61310Sstevel@tonic-gate }
61320Sstevel@tonic-gate 
61330Sstevel@tonic-gate void
61340Sstevel@tonic-gate page_clr_all_props(page_t *pp)
61350Sstevel@tonic-gate {
61360Sstevel@tonic-gate 	pp->p_nrm = 0;
61370Sstevel@tonic-gate }
61380Sstevel@tonic-gate 
61390Sstevel@tonic-gate /*
6140917Selowe  * Clear p_lckcnt and p_cowcnt, adjusting freemem if required.
6141917Selowe  */
6142917Selowe int
6143917Selowe page_clear_lck_cow(page_t *pp, int adjust)
6144917Selowe {
6145917Selowe 	int	f_amount;
6146917Selowe 
6147917Selowe 	ASSERT(PAGE_EXCL(pp));
6148917Selowe 
6149917Selowe 	/*
6150917Selowe 	 * The page_struct_lock need not be acquired here since
6151917Selowe 	 * we require the caller hold the page exclusively locked.
6152917Selowe 	 */
6153917Selowe 	f_amount = 0;
6154917Selowe 	if (pp->p_lckcnt) {
6155917Selowe 		f_amount = 1;
6156917Selowe 		pp->p_lckcnt = 0;
6157917Selowe 	}
6158917Selowe 	if (pp->p_cowcnt) {
6159917Selowe 		f_amount += pp->p_cowcnt;
6160917Selowe 		pp->p_cowcnt = 0;
6161917Selowe 	}
6162917Selowe 
6163917Selowe 	if (adjust && f_amount) {
6164917Selowe 		mutex_enter(&freemem_lock);
6165917Selowe 		availrmem += f_amount;
6166917Selowe 		mutex_exit(&freemem_lock);
6167917Selowe 	}
6168917Selowe 
6169917Selowe 	return (f_amount);
6170917Selowe }
6171917Selowe 
6172917Selowe /*
61730Sstevel@tonic-gate  * The following functions is called from free_vp_pages()
61740Sstevel@tonic-gate  * for an inexact estimate of a newly free'd page...
61750Sstevel@tonic-gate  */
61760Sstevel@tonic-gate ulong_t
61770Sstevel@tonic-gate page_share_cnt(page_t *pp)
61780Sstevel@tonic-gate {
61790Sstevel@tonic-gate 	return (hat_page_getshare(pp));
61800Sstevel@tonic-gate }
61810Sstevel@tonic-gate 
61820Sstevel@tonic-gate int
61830Sstevel@tonic-gate page_isshared(page_t *pp)
61840Sstevel@tonic-gate {
61854528Spaulsan 	return (hat_page_checkshare(pp, 1));
61860Sstevel@tonic-gate }
61870Sstevel@tonic-gate 
61880Sstevel@tonic-gate int
61890Sstevel@tonic-gate page_isfree(page_t *pp)
61900Sstevel@tonic-gate {
61910Sstevel@tonic-gate 	return (PP_ISFREE(pp));
61920Sstevel@tonic-gate }
61930Sstevel@tonic-gate 
61940Sstevel@tonic-gate int
61950Sstevel@tonic-gate page_isref(page_t *pp)
61960Sstevel@tonic-gate {
61970Sstevel@tonic-gate 	return (hat_page_getattr(pp, P_REF));
61980Sstevel@tonic-gate }
61990Sstevel@tonic-gate 
62000Sstevel@tonic-gate int
62010Sstevel@tonic-gate page_ismod(page_t *pp)
62020Sstevel@tonic-gate {
62030Sstevel@tonic-gate 	return (hat_page_getattr(pp, P_MOD));
62040Sstevel@tonic-gate }
62053253Smec 
62063253Smec /*
62073253Smec  * The following code all currently relates to the page capture logic:
62083253Smec  *
62093253Smec  * This logic is used for cases where there is a desire to claim a certain
62103253Smec  * physical page in the system for the caller.  As it may not be possible
62113253Smec  * to capture the page immediately, the p_toxic bits are used in the page
62123253Smec  * structure to indicate that someone wants to capture this page.  When the
62133253Smec  * page gets unlocked, the toxic flag will be noted and an attempt to capture
62143253Smec  * the page will be made.  If it is successful, the original callers callback
62153253Smec  * will be called with the page to do with it what they please.
62163253Smec  *
62173253Smec  * There is also an async thread which wakes up to attempt to capture
62183253Smec  * pages occasionally which have the capture bit set.  All of the pages which
62193253Smec  * need to be captured asynchronously have been inserted into the
62203253Smec  * page_capture_hash and thus this thread walks that hash list.  Items in the
62213253Smec  * hash have an expiration time so this thread handles that as well by removing
62223253Smec  * the item from the hash if it has expired.
62233253Smec  *
62243253Smec  * Some important things to note are:
62253253Smec  * - if the PR_CAPTURE bit is set on a page, then the page is in the
62263253Smec  *   page_capture_hash.  The page_capture_hash_head.pchh_mutex is needed
62273253Smec  *   to set and clear this bit, and while the lock is held is the only time
62283253Smec  *   you can add or remove an entry from the hash.
62293253Smec  * - the PR_CAPTURE bit can only be set and cleared while holding the
62303253Smec  *   page_capture_hash_head.pchh_mutex
62313253Smec  * - the t_flag field of the thread struct is used with the T_CAPTURING
62323253Smec  *   flag to prevent recursion while dealing with large pages.
62333253Smec  * - pages which need to be retired never expire on the page_capture_hash.
62343253Smec  */
62353253Smec 
62363253Smec static void page_capture_thread(void);
62373253Smec static kthread_t *pc_thread_id;
62383253Smec kcondvar_t pc_cv;
62393253Smec static kmutex_t pc_thread_mutex;
62403253Smec static clock_t pc_thread_shortwait;
62413253Smec static clock_t pc_thread_longwait;
62423480Sjfrank static int pc_thread_ism_retry;
62433253Smec 
62443253Smec struct page_capture_callback pc_cb[PC_NUM_CALLBACKS];
62453253Smec 
62463253Smec /* Note that this is a circular linked list */
62473253Smec typedef struct page_capture_hash_bucket {
62483253Smec 	page_t *pp;
62493253Smec 	uint_t szc;
62503253Smec 	uint_t flags;
62513253Smec 	clock_t expires;	/* lbolt at which this request expires. */
62523253Smec 	void *datap;		/* Cached data passed in for callback */
62533253Smec 	struct page_capture_hash_bucket *next;
62543253Smec 	struct page_capture_hash_bucket *prev;
62553253Smec } page_capture_hash_bucket_t;
62563253Smec 
62573253Smec /*
62583253Smec  * Each hash bucket will have it's own mutex and two lists which are:
62593253Smec  * active (0):	represents requests which have not been processed by
62603253Smec  *		the page_capture async thread yet.
62613253Smec  * walked (1):	represents requests which have been processed by the
62623253Smec  *		page_capture async thread within it's given walk of this bucket.
62633253Smec  *
62643253Smec  * These are all needed so that we can synchronize all async page_capture
62653253Smec  * events.  When the async thread moves to a new bucket, it will append the
62663253Smec  * walked list to the active list and walk each item one at a time, moving it
62673253Smec  * from the active list to the walked list.  Thus if there is an async request
62683253Smec  * outstanding for a given page, it will always be in one of the two lists.
62693253Smec  * New requests will always be added to the active list.
62703253Smec  * If we were not able to capture a page before the request expired, we'd free
62713253Smec  * up the request structure which would indicate to page_capture that there is
62723253Smec  * no longer a need for the given page, and clear the PR_CAPTURE flag if
62733253Smec  * possible.
62743253Smec  */
62753253Smec typedef struct page_capture_hash_head {
62763253Smec 	kmutex_t pchh_mutex;
62773253Smec 	uint_t num_pages;
62783253Smec 	page_capture_hash_bucket_t lists[2]; /* sentinel nodes */
62793253Smec } page_capture_hash_head_t;
62803253Smec 
62813253Smec #ifdef DEBUG
62823253Smec #define	NUM_PAGE_CAPTURE_BUCKETS 4
62833253Smec #else
62843253Smec #define	NUM_PAGE_CAPTURE_BUCKETS 64
62853253Smec #endif
62863253Smec 
62873253Smec page_capture_hash_head_t page_capture_hash[NUM_PAGE_CAPTURE_BUCKETS];
62883253Smec 
62893253Smec /* for now use a very simple hash based upon the size of a page struct */
62903253Smec #define	PAGE_CAPTURE_HASH(pp)	\
62913253Smec 	((int)(((uintptr_t)pp >> 7) & (NUM_PAGE_CAPTURE_BUCKETS - 1)))
62923253Smec 
62933253Smec extern pgcnt_t swapfs_minfree;
62943253Smec 
62953253Smec int page_trycapture(page_t *pp, uint_t szc, uint_t flags, void *datap);
62963253Smec 
62973253Smec /*
62983253Smec  * a callback function is required for page capture requests.
62993253Smec  */
63003253Smec void
63013253Smec page_capture_register_callback(uint_t index, clock_t duration,
63023253Smec     int (*cb_func)(page_t *, void *, uint_t))
63033253Smec {
63043253Smec 	ASSERT(pc_cb[index].cb_active == 0);
63053253Smec 	ASSERT(cb_func != NULL);
63063253Smec 	rw_enter(&pc_cb[index].cb_rwlock, RW_WRITER);
63073253Smec 	pc_cb[index].duration = duration;
63083253Smec 	pc_cb[index].cb_func = cb_func;
63093253Smec 	pc_cb[index].cb_active = 1;
63103253Smec 	rw_exit(&pc_cb[index].cb_rwlock);
63113253Smec }
63123253Smec 
63133253Smec void
63143253Smec page_capture_unregister_callback(uint_t index)
63153253Smec {
63163253Smec 	int i, j;
63173253Smec 	struct page_capture_hash_bucket *bp1;
63183253Smec 	struct page_capture_hash_bucket *bp2;
63193253Smec 	struct page_capture_hash_bucket *head = NULL;
63203253Smec 	uint_t flags = (1 << index);
63213253Smec 
63223253Smec 	rw_enter(&pc_cb[index].cb_rwlock, RW_WRITER);
63233253Smec 	ASSERT(pc_cb[index].cb_active == 1);
63243253Smec 	pc_cb[index].duration = 0;	/* Paranoia */
63253253Smec 	pc_cb[index].cb_func = NULL;	/* Paranoia */
63263253Smec 	pc_cb[index].cb_active = 0;
63273253Smec 	rw_exit(&pc_cb[index].cb_rwlock);
63283253Smec 
63293253Smec 	/*
63303253Smec 	 * Just move all the entries to a private list which we can walk
63313253Smec 	 * through without the need to hold any locks.
63323253Smec 	 * No more requests can get added to the hash lists for this consumer
63333253Smec 	 * as the cb_active field for the callback has been cleared.
63343253Smec 	 */
63353253Smec 	for (i = 0; i < NUM_PAGE_CAPTURE_BUCKETS; i++) {
63363253Smec 		mutex_enter(&page_capture_hash[i].pchh_mutex);
63373253Smec 		for (j = 0; j < 2; j++) {
63383253Smec 			bp1 = page_capture_hash[i].lists[j].next;
63393253Smec 			/* walk through all but first (sentinel) element */
63403253Smec 			while (bp1 != &page_capture_hash[i].lists[j]) {
63413253Smec 				bp2 = bp1;
63423253Smec 				if (bp2->flags & flags) {
63433253Smec 					bp1 = bp2->next;
63443253Smec 					bp1->prev = bp2->prev;
63453253Smec 					bp2->prev->next = bp1;
63463253Smec 					bp2->next = head;
63473253Smec 					head = bp2;
63483253Smec 					/*
63493253Smec 					 * Clear the PR_CAPTURE bit as we
63503253Smec 					 * hold appropriate locks here.
63513253Smec 					 */
63523253Smec 					page_clrtoxic(head->pp, PR_CAPTURE);
63533253Smec 					page_capture_hash[i].num_pages--;
63543253Smec 					continue;
63553253Smec 				}
63563253Smec 				bp1 = bp1->next;
63573253Smec 			}
63583253Smec 		}
63593253Smec 		mutex_exit(&page_capture_hash[i].pchh_mutex);
63603253Smec 	}
63613253Smec 
63623253Smec 	while (head != NULL) {
63633253Smec 		bp1 = head;
63643253Smec 		head = head->next;
63653253Smec 		kmem_free(bp1, sizeof (*bp1));
63663253Smec 	}
63673253Smec }
63683253Smec 
63693253Smec 
63703253Smec /*
63713253Smec  * Find pp in the active list and move it to the walked list if it
63723253Smec  * exists.
63733253Smec  * Note that most often pp should be at the front of the active list
63743253Smec  * as it is currently used and thus there is no other sort of optimization
63753253Smec  * being done here as this is a linked list data structure.
63763253Smec  * Returns 1 on successful move or 0 if page could not be found.
63773253Smec  */
63783253Smec static int
63793253Smec page_capture_move_to_walked(page_t *pp)
63803253Smec {
63813253Smec 	page_capture_hash_bucket_t *bp;
63823253Smec 	int index;
63833253Smec 
63843253Smec 	index = PAGE_CAPTURE_HASH(pp);
63853253Smec 
63863253Smec 	mutex_enter(&page_capture_hash[index].pchh_mutex);
63873253Smec 	bp = page_capture_hash[index].lists[0].next;
63883253Smec 	while (bp != &page_capture_hash[index].lists[0]) {
63893253Smec 		if (bp->pp == pp) {
63903253Smec 			/* Remove from old list */
63913253Smec 			bp->next->prev = bp->prev;
63923253Smec 			bp->prev->next = bp->next;
63933253Smec 
63943253Smec 			/* Add to new list */
63953253Smec 			bp->next = page_capture_hash[index].lists[1].next;
63963253Smec 			bp->prev = &page_capture_hash[index].lists[1];
63973253Smec 			page_capture_hash[index].lists[1].next = bp;
63983253Smec 			bp->next->prev = bp;
63993253Smec 			mutex_exit(&page_capture_hash[index].pchh_mutex);
64003253Smec 
64013253Smec 			return (1);
64023253Smec 		}
64033253Smec 		bp = bp->next;
64043253Smec 	}
64053253Smec 	mutex_exit(&page_capture_hash[index].pchh_mutex);
64063253Smec 	return (0);
64073253Smec }
64083253Smec 
64093253Smec /*
64103253Smec  * Add a new entry to the page capture hash.  The only case where a new
64113253Smec  * entry is not added is when the page capture consumer is no longer registered.
64123253Smec  * In this case, we'll silently not add the page to the hash.  We know that
64133253Smec  * page retire will always be registered for the case where we are currently
64143253Smec  * unretiring a page and thus there are no conflicts.
64153253Smec  */
64163253Smec static void
64173253Smec page_capture_add_hash(page_t *pp, uint_t szc, uint_t flags, void *datap)
64183253Smec {
64193253Smec 	page_capture_hash_bucket_t *bp1;
64203253Smec 	page_capture_hash_bucket_t *bp2;
64213253Smec 	int index;
64223253Smec 	int cb_index;
64233253Smec 	int i;
64243253Smec #ifdef DEBUG
64253253Smec 	page_capture_hash_bucket_t *tp1;
64263253Smec 	int l;
64273253Smec #endif
64283253Smec 
64293253Smec 	ASSERT(!(flags & CAPTURE_ASYNC));
64303253Smec 
64313253Smec 	bp1 = kmem_alloc(sizeof (struct page_capture_hash_bucket), KM_SLEEP);
64323253Smec 
64333253Smec 	bp1->pp = pp;
64343253Smec 	bp1->szc = szc;
64353253Smec 	bp1->flags = flags;
64363253Smec 	bp1->datap = datap;
64373253Smec 
64383253Smec 	for (cb_index = 0; cb_index < PC_NUM_CALLBACKS; cb_index++) {
64393253Smec 		if ((flags >> cb_index) & 1) {
64403253Smec 			break;
64413253Smec 		}
64423253Smec 	}
64433253Smec 
64443253Smec 	ASSERT(cb_index != PC_NUM_CALLBACKS);
64453253Smec 
64463253Smec 	rw_enter(&pc_cb[cb_index].cb_rwlock, RW_READER);
64473253Smec 	if (pc_cb[cb_index].cb_active) {
64483253Smec 		if (pc_cb[cb_index].duration == -1) {
64493253Smec 			bp1->expires = (clock_t)-1;
64503253Smec 		} else {
64513253Smec 			bp1->expires = lbolt + pc_cb[cb_index].duration;
64523253Smec 		}
64533253Smec 	} else {
64543253Smec 		/* There's no callback registered so don't add to the hash */
64553253Smec 		rw_exit(&pc_cb[cb_index].cb_rwlock);
64563253Smec 		kmem_free(bp1, sizeof (*bp1));
64573253Smec 		return;
64583253Smec 	}
64593253Smec 
64603253Smec 	index = PAGE_CAPTURE_HASH(pp);
64613253Smec 
64623253Smec 	/*
64633253Smec 	 * Only allow capture flag to be modified under this mutex.
64643253Smec 	 * Prevents multiple entries for same page getting added.
64653253Smec 	 */
64663253Smec 	mutex_enter(&page_capture_hash[index].pchh_mutex);
64673253Smec 
64683253Smec 	/*
64693253Smec 	 * if not already on the hash, set capture bit and add to the hash
64703253Smec 	 */
64713253Smec 	if (!(pp->p_toxic & PR_CAPTURE)) {
64723253Smec #ifdef DEBUG
64733253Smec 		/* Check for duplicate entries */
64743253Smec 		for (l = 0; l < 2; l++) {
64753253Smec 			tp1 = page_capture_hash[index].lists[l].next;
64763253Smec 			while (tp1 != &page_capture_hash[index].lists[l]) {
64773253Smec 				if (tp1->pp == pp) {
64783253Smec 					panic("page pp 0x%p already on hash "
64793253Smec 					    "at 0x%p\n", pp, tp1);
64803253Smec 				}
64813253Smec 				tp1 = tp1->next;
64823253Smec 			}
64833253Smec 		}
64843253Smec 
64853253Smec #endif
64863253Smec 		page_settoxic(pp, PR_CAPTURE);
64873253Smec 		bp1->next = page_capture_hash[index].lists[0].next;
64883253Smec 		bp1->prev = &page_capture_hash[index].lists[0];
64893253Smec 		bp1->next->prev = bp1;
64903253Smec 		page_capture_hash[index].lists[0].next = bp1;
64913253Smec 		page_capture_hash[index].num_pages++;
64923480Sjfrank 		if (flags & CAPTURE_RETIRE) {
64933480Sjfrank 			page_retire_incr_pend_count();
64943480Sjfrank 		}
64953253Smec 		mutex_exit(&page_capture_hash[index].pchh_mutex);
64963253Smec 		rw_exit(&pc_cb[cb_index].cb_rwlock);
64973253Smec 		cv_signal(&pc_cv);
64983253Smec 		return;
64993253Smec 	}
65003253Smec 
65013253Smec 	/*
65023253Smec 	 * A page retire request will replace any other request.
65033253Smec 	 * A second physmem request which is for a different process than
65043253Smec 	 * the currently registered one will be dropped as there is
65053253Smec 	 * no way to hold the private data for both calls.
65063253Smec 	 * In the future, once there are more callers, this will have to
65073253Smec 	 * be worked out better as there needs to be private storage for
65083253Smec 	 * at least each type of caller (maybe have datap be an array of
65093253Smec 	 * *void's so that we can index based upon callers index).
65103253Smec 	 */
65113253Smec 
65123253Smec 	/* walk hash list to update expire time */
65133253Smec 	for (i = 0; i < 2; i++) {
65143253Smec 		bp2 = page_capture_hash[index].lists[i].next;
65153253Smec 		while (bp2 != &page_capture_hash[index].lists[i]) {
65163253Smec 			if (bp2->pp == pp) {
65173253Smec 				if (flags & CAPTURE_RETIRE) {
65183253Smec 					if (!(bp2->flags & CAPTURE_RETIRE)) {
65193480Sjfrank 						page_retire_incr_pend_count();
65203253Smec 						bp2->flags = flags;
65213253Smec 						bp2->expires = bp1->expires;
65223253Smec 						bp2->datap = datap;
65233253Smec 					}
65243253Smec 				} else {
65253253Smec 					ASSERT(flags & CAPTURE_PHYSMEM);
65263253Smec 					if (!(bp2->flags & CAPTURE_RETIRE) &&
65273253Smec 					    (datap == bp2->datap)) {
65283253Smec 						bp2->expires = bp1->expires;
65293253Smec 					}
65303253Smec 				}
65313253Smec 				mutex_exit(&page_capture_hash[index].
65323253Smec 				    pchh_mutex);
65333253Smec 				rw_exit(&pc_cb[cb_index].cb_rwlock);
65343253Smec 				kmem_free(bp1, sizeof (*bp1));
65353253Smec 				return;
65363253Smec 			}
65373253Smec 			bp2 = bp2->next;
65383253Smec 		}
65393253Smec 	}
65403253Smec 
65413253Smec 	/*
65423253Smec 	 * the PR_CAPTURE flag is protected by the page_capture_hash mutexes
65433253Smec 	 * and thus it either has to be set or not set and can't change
65443253Smec 	 * while holding the mutex above.
65453253Smec 	 */
65463253Smec 	panic("page_capture_add_hash, PR_CAPTURE flag set on pp %p\n", pp);
65473253Smec }
65483253Smec 
65493253Smec /*
65503253Smec  * We have a page in our hands, lets try and make it ours by turning
65513253Smec  * it into a clean page like it had just come off the freelists.
65523253Smec  *
65533253Smec  * Returns 0 on success, with the page still EXCL locked.
65543253Smec  * On failure, the page will be unlocked, and returns EAGAIN
65553253Smec  */
65563253Smec static int
65573253Smec page_capture_clean_page(page_t *pp)
65583253Smec {
65593253Smec 	page_t *newpp;
65603253Smec 	int skip_unlock = 0;
65613253Smec 	spgcnt_t count;
65623253Smec 	page_t *tpp;
65633253Smec 	int ret = 0;
65643253Smec 	int extra;
65653253Smec 
65663253Smec 	ASSERT(PAGE_EXCL(pp));
65673253Smec 	ASSERT(!PP_RETIRED(pp));
65683253Smec 	ASSERT(curthread->t_flag & T_CAPTURING);
65693253Smec 
65703253Smec 	if (PP_ISFREE(pp)) {
65713559Smec 		if (!page_reclaim(pp, NULL)) {
65723253Smec 			skip_unlock = 1;
65733253Smec 			ret = EAGAIN;
65743253Smec 			goto cleanup;
65753253Smec 		}
65763559Smec 		ASSERT(pp->p_szc == 0);
65773253Smec 		if (pp->p_vnode != NULL) {
65783253Smec 			/*
65793253Smec 			 * Since this page came from the
65803253Smec 			 * cachelist, we must destroy the
65813253Smec 			 * old vnode association.
65823253Smec 			 */
65833253Smec 			page_hashout(pp, NULL);
65843253Smec 		}
65853253Smec 		goto cleanup;
65863253Smec 	}
65873253Smec 
65883253Smec 	/*
65893253Smec 	 * If we know page_relocate will fail, skip it
65903253Smec 	 * It could still fail due to a UE on another page but we
65913253Smec 	 * can't do anything about that.
65923253Smec 	 */
65933253Smec 	if (pp->p_toxic & PR_UE) {
65943253Smec 		goto skip_relocate;
65953253Smec 	}
65963253Smec 
65973253Smec 	/*
65983253Smec 	 * It's possible that pages can not have a vnode as fsflush comes
65993253Smec 	 * through and cleans up these pages.  It's ugly but that's how it is.
66003253Smec 	 */
66013253Smec 	if (pp->p_vnode == NULL) {
66023253Smec 		goto skip_relocate;
66033253Smec 	}
66043253Smec 
66053253Smec 	/*
66063253Smec 	 * Page was not free, so lets try to relocate it.
66073253Smec 	 * page_relocate only works with root pages, so if this is not a root
66083253Smec 	 * page, we need to demote it to try and relocate it.
66093253Smec 	 * Unfortunately this is the best we can do right now.
66103253Smec 	 */
66113253Smec 	newpp = NULL;
66123253Smec 	if ((pp->p_szc > 0) && (pp != PP_PAGEROOT(pp))) {
66133253Smec 		if (page_try_demote_pages(pp) == 0) {
66143253Smec 			ret = EAGAIN;
66153253Smec 			goto cleanup;
66163253Smec 		}
66173253Smec 	}
66183253Smec 	ret = page_relocate(&pp, &newpp, 1, 0, &count, NULL);
66193253Smec 	if (ret == 0) {
66203253Smec 		page_t *npp;
66213253Smec 		/* unlock the new page(s) */
66223253Smec 		while (count-- > 0) {
66233253Smec 			ASSERT(newpp != NULL);
66243253Smec 			npp = newpp;
66253253Smec 			page_sub(&newpp, npp);
66263253Smec 			page_unlock(npp);
66273253Smec 		}
66283253Smec 		ASSERT(newpp == NULL);
66293253Smec 		/*
66303253Smec 		 * Check to see if the page we have is too large.
66313253Smec 		 * If so, demote it freeing up the extra pages.
66323253Smec 		 */
66333253Smec 		if (pp->p_szc > 0) {
66343253Smec 			/* For now demote extra pages to szc == 0 */
66353253Smec 			extra = page_get_pagecnt(pp->p_szc) - 1;
66363253Smec 			while (extra > 0) {
66373253Smec 				tpp = pp->p_next;
66383253Smec 				page_sub(&pp, tpp);
66393253Smec 				tpp->p_szc = 0;
66403253Smec 				page_free(tpp, 1);
66413253Smec 				extra--;
66423253Smec 			}
66433253Smec 			/* Make sure to set our page to szc 0 as well */
66443253Smec 			ASSERT(pp->p_next == pp && pp->p_prev == pp);
66453253Smec 			pp->p_szc = 0;
66463253Smec 		}
66473253Smec 		goto cleanup;
66483253Smec 	} else if (ret == EIO) {
66493253Smec 		ret = EAGAIN;
66503253Smec 		goto cleanup;
66513253Smec 	} else {
66523253Smec 		/*
66533253Smec 		 * Need to reset return type as we failed to relocate the page
66543253Smec 		 * but that does not mean that some of the next steps will not
66553253Smec 		 * work.
66563253Smec 		 */
66573253Smec 		ret = 0;
66583253Smec 	}
66593253Smec 
66603253Smec skip_relocate:
66613253Smec 
66623253Smec 	if (pp->p_szc > 0) {
66633253Smec 		if (page_try_demote_pages(pp) == 0) {
66643253Smec 			ret = EAGAIN;
66653253Smec 			goto cleanup;
66663253Smec 		}
66673253Smec 	}
66683253Smec 
66693253Smec 	ASSERT(pp->p_szc == 0);
66703253Smec 
66713253Smec 	if (hat_ismod(pp)) {
66723253Smec 		ret = EAGAIN;
66733253Smec 		goto cleanup;
66743253Smec 	}
66753290Sjohansen 	if (PP_ISKAS(pp)) {
66763253Smec 		ret = EAGAIN;
66773253Smec 		goto cleanup;
66783253Smec 	}
66793253Smec 	if (pp->p_lckcnt || pp->p_cowcnt) {
66803253Smec 		ret = EAGAIN;
66813253Smec 		goto cleanup;
66823253Smec 	}
66833253Smec 
66843253Smec 	(void) hat_pageunload(pp, HAT_FORCE_PGUNLOAD);
66853253Smec 	ASSERT(!hat_page_is_mapped(pp));
66863253Smec 
66873253Smec 	if (hat_ismod(pp)) {
66883253Smec 		/*
66893253Smec 		 * This is a semi-odd case as the page is now modified but not
66903253Smec 		 * mapped as we just unloaded the mappings above.
66913253Smec 		 */
66923253Smec 		ret = EAGAIN;
66933253Smec 		goto cleanup;
66943253Smec 	}
66953253Smec 	if (pp->p_vnode != NULL) {
66963253Smec 		page_hashout(pp, NULL);
66973253Smec 	}
66983253Smec 
66993253Smec 	/*
67003253Smec 	 * At this point, the page should be in a clean state and
67013253Smec 	 * we can do whatever we want with it.
67023253Smec 	 */
67033253Smec 
67043253Smec cleanup:
67053253Smec 	if (ret != 0) {
67063253Smec 		if (!skip_unlock) {
67073253Smec 			page_unlock(pp);
67083253Smec 		}
67093253Smec 	} else {
67103253Smec 		ASSERT(pp->p_szc == 0);
67113253Smec 		ASSERT(PAGE_EXCL(pp));
67123253Smec 
67133253Smec 		pp->p_next = pp;
67143253Smec 		pp->p_prev = pp;
67153253Smec 	}
67163253Smec 	return (ret);
67173253Smec }
67183253Smec 
67193253Smec /*
67203253Smec  * Various callers of page_trycapture() can have different restrictions upon
67213253Smec  * what memory they have access to.
67223253Smec  * Returns 0 on success, with the following error codes on failure:
67233253Smec  *      EPERM - The requested page is long term locked, and thus repeated
67243253Smec  *              requests to capture this page will likely fail.
67253253Smec  *      ENOMEM - There was not enough free memory in the system to safely
67263253Smec  *              map the requested page.
67273253Smec  *      ENOENT - The requested page was inside the kernel cage, and the
67283253Smec  *              PHYSMEM_CAGE flag was not set.
67293253Smec  */
67303253Smec int
67313253Smec page_capture_pre_checks(page_t *pp, uint_t flags)
67323253Smec {
67333253Smec #if defined(__sparc)
67343253Smec 	extern struct vnode prom_ppages;
67353253Smec #endif /* __sparc */
67363253Smec 
67373253Smec 	ASSERT(pp != NULL);
67383253Smec 
67393253Smec 	/* only physmem currently has restrictions */
67403253Smec 	if (!(flags & CAPTURE_PHYSMEM)) {
67413253Smec 		return (0);
67423253Smec 	}
67433253Smec 
67443253Smec #if defined(__sparc)
67453253Smec 	if (pp->p_vnode == &prom_ppages) {
67463253Smec 		return (EPERM);
67473253Smec 	}
67483253Smec 
67493253Smec 	if (PP_ISNORELOC(pp) && !(flags & CAPTURE_GET_CAGE)) {
67503253Smec 		return (ENOENT);
67513253Smec 	}
67523253Smec 
67533253Smec 	if (PP_ISNORELOCKERNEL(pp)) {
67543253Smec 		return (EPERM);
67553253Smec 	}
67563253Smec #else
67573290Sjohansen 	if (PP_ISKAS(pp)) {
67583253Smec 		return (EPERM);
67593253Smec 	}
67603253Smec #endif /* __sparc */
67613253Smec 
67623253Smec 	if (availrmem < swapfs_minfree) {
67633253Smec 		/*
67643253Smec 		 * We won't try to capture this page as we are
67653253Smec 		 * running low on memory.
67663253Smec 		 */
67673253Smec 		return (ENOMEM);
67683253Smec 	}
67693253Smec 	return (0);
67703253Smec }
67713253Smec 
67723253Smec /*
67733253Smec  * Once we have a page in our mits, go ahead and complete the capture
67743253Smec  * operation.
67753253Smec  * Returns 1 on failure where page is no longer needed
67763253Smec  * Returns 0 on success
67773253Smec  * Returns -1 if there was a transient failure.
67783253Smec  * Failure cases must release the SE_EXCL lock on pp (usually via page_free).
67793253Smec  */
67803253Smec int
67813253Smec page_capture_take_action(page_t *pp, uint_t flags, void *datap)
67823253Smec {
67833253Smec 	int cb_index;
67843253Smec 	int ret = 0;
67853253Smec 	page_capture_hash_bucket_t *bp1;
67863253Smec 	page_capture_hash_bucket_t *bp2;
67873253Smec 	int index;
67883253Smec 	int found = 0;
67893253Smec 	int i;
67903253Smec 
67913253Smec 	ASSERT(PAGE_EXCL(pp));
67923253Smec 	ASSERT(curthread->t_flag & T_CAPTURING);
67933253Smec 
67943253Smec 	for (cb_index = 0; cb_index < PC_NUM_CALLBACKS; cb_index++) {
67953253Smec 		if ((flags >> cb_index) & 1) {
67963253Smec 			break;
67973253Smec 		}
67983253Smec 	}
67993253Smec 	ASSERT(cb_index < PC_NUM_CALLBACKS);
68003253Smec 
68013253Smec 	/*
68023253Smec 	 * Remove the entry from the page_capture hash, but don't free it yet
68033253Smec 	 * as we may need to put it back.
68043253Smec 	 * Since we own the page at this point in time, we should find it
68053253Smec 	 * in the hash if this is an ASYNC call.  If we don't it's likely
68063253Smec 	 * that the page_capture_async() thread decided that this request
68073253Smec 	 * had expired, in which case we just continue on.
68083253Smec 	 */
68093253Smec 	if (flags & CAPTURE_ASYNC) {
68103253Smec 
68113253Smec 		index = PAGE_CAPTURE_HASH(pp);
68123253Smec 
68133253Smec 		mutex_enter(&page_capture_hash[index].pchh_mutex);
68143253Smec 		for (i = 0; i < 2 && !found; i++) {
68153253Smec 			bp1 = page_capture_hash[index].lists[i].next;
68163253Smec 			while (bp1 != &page_capture_hash[index].lists[i]) {
68173253Smec 				if (bp1->pp == pp) {
68183253Smec 					bp1->next->prev = bp1->prev;
68193253Smec 					bp1->prev->next = bp1->next;
68203253Smec 					page_capture_hash[index].num_pages--;
68213253Smec 					page_clrtoxic(pp, PR_CAPTURE);
68223253Smec 					found = 1;
68233253Smec 					break;
68243253Smec 				}
68253253Smec 				bp1 = bp1->next;
68263253Smec 			}
68273253Smec 		}
68283253Smec 		mutex_exit(&page_capture_hash[index].pchh_mutex);
68293253Smec 	}
68303253Smec 
68313253Smec 	/* Synchronize with the unregister func. */
68323253Smec 	rw_enter(&pc_cb[cb_index].cb_rwlock, RW_READER);
68333253Smec 	if (!pc_cb[cb_index].cb_active) {
68343253Smec 		page_free(pp, 1);
68353253Smec 		rw_exit(&pc_cb[cb_index].cb_rwlock);
68363253Smec 		if (found) {
68373253Smec 			kmem_free(bp1, sizeof (*bp1));
68383253Smec 		}
68393253Smec 		return (1);
68403253Smec 	}
68413253Smec 
68423253Smec 	/*
68433253Smec 	 * We need to remove the entry from the page capture hash and turn off
68443253Smec 	 * the PR_CAPTURE bit before calling the callback.  We'll need to cache
68453253Smec 	 * the entry here, and then based upon the return value, cleanup
68463253Smec 	 * appropriately or re-add it to the hash, making sure that someone else
68473253Smec 	 * hasn't already done so.
68483253Smec 	 * It should be rare for the callback to fail and thus it's ok for
68493253Smec 	 * the failure path to be a bit complicated as the success path is
68503253Smec 	 * cleaner and the locking rules are easier to follow.
68513253Smec 	 */
68523253Smec 
68533253Smec 	ret = pc_cb[cb_index].cb_func(pp, datap, flags);
68543253Smec 
68553253Smec 	rw_exit(&pc_cb[cb_index].cb_rwlock);
68563253Smec 
68573253Smec 	/*
68583253Smec 	 * If this was an ASYNC request, we need to cleanup the hash if the
68593253Smec 	 * callback was successful or if the request was no longer valid.
68603253Smec 	 * For non-ASYNC requests, we return failure to map and the caller
68613253Smec 	 * will take care of adding the request to the hash.
68623253Smec 	 * Note also that the callback itself is responsible for the page
68633253Smec 	 * at this point in time in terms of locking ...  The most common
68643253Smec 	 * case for the failure path should just be a page_free.
68653253Smec 	 */
68663253Smec 	if (ret >= 0) {
68673253Smec 		if (found) {
68683480Sjfrank 			if (bp1->flags & CAPTURE_RETIRE) {
68693480Sjfrank 				page_retire_decr_pend_count();
68703480Sjfrank 			}
68713253Smec 			kmem_free(bp1, sizeof (*bp1));
68723253Smec 		}
68733253Smec 		return (ret);
68743253Smec 	}
68753253Smec 	if (!found) {
68763253Smec 		return (ret);
68773253Smec 	}
68783253Smec 
68793253Smec 	ASSERT(flags & CAPTURE_ASYNC);
68803253Smec 
68813253Smec 	/*
68823253Smec 	 * Check for expiration time first as we can just free it up if it's
68833253Smec 	 * expired.
68843253Smec 	 */
68853253Smec 	if (lbolt > bp1->expires && bp1->expires != -1) {
68863253Smec 		kmem_free(bp1, sizeof (*bp1));
68873253Smec 		return (ret);
68883253Smec 	}
68893253Smec 
68903253Smec 	/*
68913253Smec 	 * The callback failed and there used to be an entry in the hash for
68923253Smec 	 * this page, so we need to add it back to the hash.
68933253Smec 	 */
68943253Smec 	mutex_enter(&page_capture_hash[index].pchh_mutex);
68953253Smec 	if (!(pp->p_toxic & PR_CAPTURE)) {
68963253Smec 		/* just add bp1 back to head of walked list */
68973253Smec 		page_settoxic(pp, PR_CAPTURE);
68983253Smec 		bp1->next = page_capture_hash[index].lists[1].next;
68993253Smec 		bp1->prev = &page_capture_hash[index].lists[1];
69003253Smec 		bp1->next->prev = bp1;
69013253Smec 		page_capture_hash[index].lists[1].next = bp1;
69023253Smec 		page_capture_hash[index].num_pages++;
69033253Smec 		mutex_exit(&page_capture_hash[index].pchh_mutex);
69043253Smec 		return (ret);
69053253Smec 	}
69063253Smec 
69073253Smec 	/*
69083253Smec 	 * Otherwise there was a new capture request added to list
69093253Smec 	 * Need to make sure that our original data is represented if
69103253Smec 	 * appropriate.
69113253Smec 	 */
69123253Smec 	for (i = 0; i < 2; i++) {
69133253Smec 		bp2 = page_capture_hash[index].lists[i].next;
69143253Smec 		while (bp2 != &page_capture_hash[index].lists[i]) {
69153253Smec 			if (bp2->pp == pp) {
69163253Smec 				if (bp1->flags & CAPTURE_RETIRE) {
69173253Smec 					if (!(bp2->flags & CAPTURE_RETIRE)) {
69183253Smec 						bp2->szc = bp1->szc;
69193253Smec 						bp2->flags = bp1->flags;
69203253Smec 						bp2->expires = bp1->expires;
69213253Smec 						bp2->datap = bp1->datap;
69223253Smec 					}
69233253Smec 				} else {
69243253Smec 					ASSERT(bp1->flags & CAPTURE_PHYSMEM);
69253253Smec 					if (!(bp2->flags & CAPTURE_RETIRE)) {
69263253Smec 						bp2->szc = bp1->szc;
69273253Smec 						bp2->flags = bp1->flags;
69283253Smec 						bp2->expires = bp1->expires;
69293253Smec 						bp2->datap = bp1->datap;
69303253Smec 					}
69313253Smec 				}
69323253Smec 				mutex_exit(&page_capture_hash[index].
69333253Smec 				    pchh_mutex);
69343253Smec 				kmem_free(bp1, sizeof (*bp1));
69353253Smec 				return (ret);
69363253Smec 			}
69373253Smec 			bp2 = bp2->next;
69383253Smec 		}
69393253Smec 	}
69403253Smec 	panic("PR_CAPTURE set but not on hash for pp 0x%p\n", pp);
69413253Smec 	/*NOTREACHED*/
69423253Smec }
69433253Smec 
69443253Smec /*
69453253Smec  * Try to capture the given page for the caller specified in the flags
69463253Smec  * parameter.  The page will either be captured and handed over to the
69473253Smec  * appropriate callback, or will be queued up in the page capture hash
69483253Smec  * to be captured asynchronously.
69493253Smec  * If the current request is due to an async capture, the page must be
69503253Smec  * exclusively locked before calling this function.
69513253Smec  * Currently szc must be 0 but in the future this should be expandable to
69523253Smec  * other page sizes.
69533253Smec  * Returns 0 on success, with the following error codes on failure:
69543253Smec  *      EPERM - The requested page is long term locked, and thus repeated
69553253Smec  *              requests to capture this page will likely fail.
69563253Smec  *      ENOMEM - There was not enough free memory in the system to safely
69573253Smec  *              map the requested page.
69583253Smec  *      ENOENT - The requested page was inside the kernel cage, and the
69593253Smec  *              CAPTURE_GET_CAGE flag was not set.
69603253Smec  *	EAGAIN - The requested page could not be capturead at this point in
69613253Smec  *		time but future requests will likely work.
69623253Smec  *	EBUSY - The requested page is retired and the CAPTURE_GET_RETIRED flag
69633253Smec  *		was not set.
69643253Smec  */
69653253Smec int
69663253Smec page_itrycapture(page_t *pp, uint_t szc, uint_t flags, void *datap)
69673253Smec {
69683253Smec 	int ret;
69693253Smec 	int cb_index;
69703253Smec 
69713253Smec 	if (flags & CAPTURE_ASYNC) {
69723253Smec 		ASSERT(PAGE_EXCL(pp));
69733253Smec 		goto async;
69743253Smec 	}
69753253Smec 
69763253Smec 	/* Make sure there's enough availrmem ... */
69773253Smec 	ret = page_capture_pre_checks(pp, flags);
69783253Smec 	if (ret != 0) {
69793253Smec 		return (ret);
69803253Smec 	}
69813253Smec 
69823253Smec 	if (!page_trylock(pp, SE_EXCL)) {
69833253Smec 		for (cb_index = 0; cb_index < PC_NUM_CALLBACKS; cb_index++) {
69843253Smec 			if ((flags >> cb_index) & 1) {
69853253Smec 				break;
69863253Smec 			}
69873253Smec 		}
69883253Smec 		ASSERT(cb_index < PC_NUM_CALLBACKS);
69893253Smec 		ret = EAGAIN;
69903253Smec 		/* Special case for retired pages */
69913253Smec 		if (PP_RETIRED(pp)) {
69923253Smec 			if (flags & CAPTURE_GET_RETIRED) {
69933253Smec 				if (!page_unretire_pp(pp, PR_UNR_TEMP)) {
69943253Smec 					/*
69953253Smec 					 * Need to set capture bit and add to
69963253Smec 					 * hash so that the page will be
69973253Smec 					 * retired when freed.
69983253Smec 					 */
69993253Smec 					page_capture_add_hash(pp, szc,
70003253Smec 					    CAPTURE_RETIRE, NULL);
70013253Smec 					ret = 0;
70023253Smec 					goto own_page;
70033253Smec 				}
70043253Smec 			} else {
70053253Smec 				return (EBUSY);
70063253Smec 			}
70073253Smec 		}
70083253Smec 		page_capture_add_hash(pp, szc, flags, datap);
70093253Smec 		return (ret);
70103253Smec 	}
70113253Smec 
70123253Smec async:
70133253Smec 	ASSERT(PAGE_EXCL(pp));
70143253Smec 
70153253Smec 	/* Need to check for physmem async requests that availrmem is sane */
70163253Smec 	if ((flags & (CAPTURE_ASYNC | CAPTURE_PHYSMEM)) ==
70173253Smec 	    (CAPTURE_ASYNC | CAPTURE_PHYSMEM) &&
70183253Smec 	    (availrmem < swapfs_minfree)) {
70193253Smec 		page_unlock(pp);
70203253Smec 		return (ENOMEM);
70213253Smec 	}
70223253Smec 
70233253Smec 	ret = page_capture_clean_page(pp);
70243253Smec 
70253253Smec 	if (ret != 0) {
70263253Smec 		/* We failed to get the page, so lets add it to the hash */
70273253Smec 		if (!(flags & CAPTURE_ASYNC)) {
70283253Smec 			page_capture_add_hash(pp, szc, flags, datap);
70293253Smec 		}
70303253Smec 		return (ret);
70313253Smec 	}
70323253Smec 
70333253Smec own_page:
70343253Smec 	ASSERT(PAGE_EXCL(pp));
70353253Smec 	ASSERT(pp->p_szc == 0);
70363253Smec 
70373253Smec 	/* Call the callback */
70383253Smec 	ret = page_capture_take_action(pp, flags, datap);
70393253Smec 
70403253Smec 	if (ret == 0) {
70413253Smec 		return (0);
70423253Smec 	}
70433253Smec 
70443253Smec 	/*
70453253Smec 	 * Note that in the failure cases from page_capture_take_action, the
70463253Smec 	 * EXCL lock will have already been dropped.
70473253Smec 	 */
70483253Smec 	if ((ret == -1) && (!(flags & CAPTURE_ASYNC))) {
70493253Smec 		page_capture_add_hash(pp, szc, flags, datap);
70503253Smec 	}
70513253Smec 	return (EAGAIN);
70523253Smec }
70533253Smec 
70543253Smec int
70553253Smec page_trycapture(page_t *pp, uint_t szc, uint_t flags, void *datap)
70563253Smec {
70573253Smec 	int ret;
70583253Smec 
70593253Smec 	curthread->t_flag |= T_CAPTURING;
70603253Smec 	ret = page_itrycapture(pp, szc, flags, datap);
70613253Smec 	curthread->t_flag &= ~T_CAPTURING; /* xor works as we know its set */
70623253Smec 	return (ret);
70633253Smec }
70643253Smec 
70653253Smec /*
70663253Smec  * When unlocking a page which has the PR_CAPTURE bit set, this routine
70673253Smec  * gets called to try and capture the page.
70683253Smec  */
70693253Smec void
70703253Smec page_unlock_capture(page_t *pp)
70713253Smec {
70723253Smec 	page_capture_hash_bucket_t *bp;
70733253Smec 	int index;
70743253Smec 	int i;
70753253Smec 	uint_t szc;
70763253Smec 	uint_t flags = 0;
70773253Smec 	void *datap;
70783253Smec 	kmutex_t *mp;
70793253Smec 	extern vnode_t retired_pages;
70803253Smec 
70813253Smec 	/*
70823253Smec 	 * We need to protect against a possible deadlock here where we own
70833253Smec 	 * the vnode page hash mutex and want to acquire it again as there
70843253Smec 	 * are locations in the code, where we unlock a page while holding
70853253Smec 	 * the mutex which can lead to the page being captured and eventually
70863253Smec 	 * end up here.  As we may be hashing out the old page and hashing into
70873253Smec 	 * the retire vnode, we need to make sure we don't own them.
70883253Smec 	 * Other callbacks who do hash operations also need to make sure that
70893253Smec 	 * before they hashin to a vnode that they do not currently own the
70903253Smec 	 * vphm mutex otherwise there will be a panic.
70913253Smec 	 */
70923253Smec 	if (mutex_owned(page_vnode_mutex(&retired_pages))) {
70933311Smec 		page_unlock_nocapture(pp);
70943253Smec 		return;
70953253Smec 	}
70963253Smec 	if (pp->p_vnode != NULL && mutex_owned(page_vnode_mutex(pp->p_vnode))) {
70973311Smec 		page_unlock_nocapture(pp);
70983253Smec 		return;
70993253Smec 	}
71003253Smec 
71013253Smec 	index = PAGE_CAPTURE_HASH(pp);
71023253Smec 
71033253Smec 	mp = &page_capture_hash[index].pchh_mutex;
71043253Smec 	mutex_enter(mp);
71053253Smec 	for (i = 0; i < 2; i++) {
71063253Smec 		bp = page_capture_hash[index].lists[i].next;
71073253Smec 		while (bp != &page_capture_hash[index].lists[i]) {
71083253Smec 			if (bp->pp == pp) {
71093253Smec 				szc = bp->szc;
71103253Smec 				flags = bp->flags | CAPTURE_ASYNC;
71113253Smec 				datap = bp->datap;
71123253Smec 				mutex_exit(mp);
71133253Smec 				(void) page_trycapture(pp, szc, flags, datap);
71143253Smec 				return;
71153253Smec 			}
71163253Smec 			bp = bp->next;
71173253Smec 		}
71183253Smec 	}
71193253Smec 
71203253Smec 	/* Failed to find page in hash so clear flags and unlock it. */
71213253Smec 	page_clrtoxic(pp, PR_CAPTURE);
71223253Smec 	page_unlock(pp);
71233253Smec 
71243253Smec 	mutex_exit(mp);
71253253Smec }
71263253Smec 
71273253Smec void
71283253Smec page_capture_init()
71293253Smec {
71303253Smec 	int i;
71313253Smec 	for (i = 0; i < NUM_PAGE_CAPTURE_BUCKETS; i++) {
71323253Smec 		page_capture_hash[i].lists[0].next =
71333253Smec 		    &page_capture_hash[i].lists[0];
71343253Smec 		page_capture_hash[i].lists[0].prev =
71353253Smec 		    &page_capture_hash[i].lists[0];
71363253Smec 		page_capture_hash[i].lists[1].next =
71373253Smec 		    &page_capture_hash[i].lists[1];
71383253Smec 		page_capture_hash[i].lists[1].prev =
71393253Smec 		    &page_capture_hash[i].lists[1];
71403253Smec 	}
71413253Smec 
71423253Smec 	pc_thread_shortwait = 23 * hz;
71433253Smec 	pc_thread_longwait = 1201 * hz;
71443480Sjfrank 	pc_thread_ism_retry = 3;
71453253Smec 	mutex_init(&pc_thread_mutex, NULL, MUTEX_DEFAULT, NULL);
71463253Smec 	cv_init(&pc_cv, NULL, CV_DEFAULT, NULL);
71473253Smec 	pc_thread_id = thread_create(NULL, 0, page_capture_thread, NULL, 0, &p0,
71483253Smec 	    TS_RUN, minclsyspri);
71493253Smec }
71503253Smec 
71513253Smec /*
71523253Smec  * It is necessary to scrub any failing pages prior to reboot in order to
71533253Smec  * prevent a latent error trap from occurring on the next boot.
71543253Smec  */
71553253Smec void
71563253Smec page_retire_mdboot()
71573253Smec {
71583253Smec 	page_t *pp;
71593253Smec 	int i, j;
71603253Smec 	page_capture_hash_bucket_t *bp;
71613253Smec 
71623253Smec 	/* walk lists looking for pages to scrub */
71633253Smec 	for (i = 0; i < NUM_PAGE_CAPTURE_BUCKETS; i++) {
71643253Smec 		if (page_capture_hash[i].num_pages == 0)
71653253Smec 			continue;
71663253Smec 
71673253Smec 		mutex_enter(&page_capture_hash[i].pchh_mutex);
71683253Smec 
71693253Smec 		for (j = 0; j < 2; j++) {
71703253Smec 			bp = page_capture_hash[i].lists[j].next;
71713253Smec 			while (bp != &page_capture_hash[i].lists[j]) {
71723253Smec 				pp = bp->pp;
71733290Sjohansen 				if (!PP_ISKAS(pp) && PP_TOXIC(pp)) {
71743253Smec 					pp->p_selock = -1;  /* pacify ASSERTs */
71753253Smec 					PP_CLRFREE(pp);
71763253Smec 					pagescrub(pp, 0, PAGESIZE);
71773253Smec 					pp->p_selock = 0;
71783253Smec 				}
71793253Smec 				bp = bp->next;
71803253Smec 			}
71813253Smec 		}
71823253Smec 		mutex_exit(&page_capture_hash[i].pchh_mutex);
71833253Smec 	}
71843253Smec }
71853253Smec 
71863253Smec /*
71873253Smec  * Walk the page_capture_hash trying to capture pages and also cleanup old
71883253Smec  * entries which have expired.
71893253Smec  */
71903253Smec void
71913253Smec page_capture_async()
71923253Smec {
71933253Smec 	page_t *pp;
71943253Smec 	int i;
71953253Smec 	int ret;
71963253Smec 	page_capture_hash_bucket_t *bp1, *bp2;
71973253Smec 	uint_t szc;
71983253Smec 	uint_t flags;
71993253Smec 	void *datap;
72003253Smec 
72013253Smec 	/* If there are outstanding pages to be captured, get to work */
72023253Smec 	for (i = 0; i < NUM_PAGE_CAPTURE_BUCKETS; i++) {
72033253Smec 		if (page_capture_hash[i].num_pages == 0)
72043253Smec 			continue;
72053253Smec 		/* Append list 1 to list 0 and then walk through list 0 */
72063253Smec 		mutex_enter(&page_capture_hash[i].pchh_mutex);
72073253Smec 		bp1 = &page_capture_hash[i].lists[1];
72083253Smec 		bp2 = bp1->next;
72093253Smec 		if (bp1 != bp2) {
72103253Smec 			bp1->prev->next = page_capture_hash[i].lists[0].next;
72113253Smec 			bp2->prev = &page_capture_hash[i].lists[0];
72123253Smec 			page_capture_hash[i].lists[0].next->prev = bp1->prev;
72133253Smec 			page_capture_hash[i].lists[0].next = bp2;
72143253Smec 			bp1->next = bp1;
72153253Smec 			bp1->prev = bp1;
72163253Smec 		}
72173253Smec 
72183253Smec 		/* list[1] will be empty now */
72193253Smec 
72203253Smec 		bp1 = page_capture_hash[i].lists[0].next;
72213253Smec 		while (bp1 != &page_capture_hash[i].lists[0]) {
72223253Smec 			/* Check expiration time */
72233253Smec 			if ((lbolt > bp1->expires && bp1->expires != -1) ||
72243253Smec 			    page_deleted(bp1->pp)) {
72253253Smec 				page_capture_hash[i].lists[0].next = bp1->next;
72263253Smec 				bp1->next->prev =
72273253Smec 				    &page_capture_hash[i].lists[0];
72283253Smec 				page_capture_hash[i].num_pages--;
72293253Smec 
72303253Smec 				/*
72313253Smec 				 * We can safely remove the PR_CAPTURE bit
72323253Smec 				 * without holding the EXCL lock on the page
72333253Smec 				 * as the PR_CAPTURE bit requres that the
72343253Smec 				 * page_capture_hash[].pchh_mutex be held
72353253Smec 				 * to modify it.
72363253Smec 				 */
72373253Smec 				page_clrtoxic(bp1->pp, PR_CAPTURE);
72383253Smec 				mutex_exit(&page_capture_hash[i].pchh_mutex);
72393253Smec 				kmem_free(bp1, sizeof (*bp1));
72403253Smec 				mutex_enter(&page_capture_hash[i].pchh_mutex);
72413253Smec 				bp1 = page_capture_hash[i].lists[0].next;
72423253Smec 				continue;
72433253Smec 			}
72443253Smec 			pp = bp1->pp;
72453253Smec 			szc = bp1->szc;
72463253Smec 			flags = bp1->flags;
72473253Smec 			datap = bp1->datap;
72483253Smec 			mutex_exit(&page_capture_hash[i].pchh_mutex);
72493253Smec 			if (page_trylock(pp, SE_EXCL)) {
72503253Smec 				ret = page_trycapture(pp, szc,
72513253Smec 				    flags | CAPTURE_ASYNC, datap);
72523253Smec 			} else {
72533253Smec 				ret = 1;	/* move to walked hash */
72543253Smec 			}
72553253Smec 
72563253Smec 			if (ret != 0) {
72573253Smec 				/* Move to walked hash */
72583253Smec 				(void) page_capture_move_to_walked(pp);
72593253Smec 			}
72603253Smec 			mutex_enter(&page_capture_hash[i].pchh_mutex);
72613253Smec 			bp1 = page_capture_hash[i].lists[0].next;
72623253Smec 		}
72633253Smec 
72643253Smec 		mutex_exit(&page_capture_hash[i].pchh_mutex);
72653253Smec 	}
72663253Smec }
72673253Smec 
72683253Smec /*
72693480Sjfrank  * This function is called by the page_capture_thread, and is needed in
72703480Sjfrank  * in order to initiate aio cleanup, so that pages used in aio
72713480Sjfrank  * will be unlocked and subsequently retired by page_capture_thread.
72723480Sjfrank  */
72733480Sjfrank static int
72743480Sjfrank do_aio_cleanup(void)
72753480Sjfrank {
72763480Sjfrank 	proc_t *procp;
72773480Sjfrank 	int (*aio_cleanup_dr_delete_memory)(proc_t *);
72783480Sjfrank 	int cleaned = 0;
72793480Sjfrank 
72803480Sjfrank 	if (modload("sys", "kaio") == -1) {
72813480Sjfrank 		cmn_err(CE_WARN, "do_aio_cleanup: cannot load kaio");
72823480Sjfrank 		return (0);
72833480Sjfrank 	}
72843480Sjfrank 	/*
72853480Sjfrank 	 * We use the aio_cleanup_dr_delete_memory function to
72863480Sjfrank 	 * initiate the actual clean up; this function will wake
72873480Sjfrank 	 * up the per-process aio_cleanup_thread.
72883480Sjfrank 	 */
72893480Sjfrank 	aio_cleanup_dr_delete_memory = (int (*)(proc_t *))
72903480Sjfrank 	    modgetsymvalue("aio_cleanup_dr_delete_memory", 0);
72913480Sjfrank 	if (aio_cleanup_dr_delete_memory == NULL) {
72923480Sjfrank 		cmn_err(CE_WARN,
72933480Sjfrank 	    "aio_cleanup_dr_delete_memory not found in kaio");
72943480Sjfrank 		return (0);
72953480Sjfrank 	}
72963480Sjfrank 	mutex_enter(&pidlock);
72973480Sjfrank 	for (procp = practive; (procp != NULL); procp = procp->p_next) {
72983480Sjfrank 		mutex_enter(&procp->p_lock);
72993480Sjfrank 		if (procp->p_aio != NULL) {
73003480Sjfrank 			/* cleanup proc's outstanding kaio */
73013480Sjfrank 			cleaned += (*aio_cleanup_dr_delete_memory)(procp);
73023480Sjfrank 		}
73033480Sjfrank 		mutex_exit(&procp->p_lock);
73043480Sjfrank 	}
73053480Sjfrank 	mutex_exit(&pidlock);
73063480Sjfrank 	return (cleaned);
73073480Sjfrank }
73083480Sjfrank 
73093480Sjfrank /*
73103480Sjfrank  * helper function for page_capture_thread
73113480Sjfrank  */
73123480Sjfrank static void
73133480Sjfrank page_capture_handle_outstanding(void)
73143480Sjfrank {
73153480Sjfrank 	extern size_t spt_used;
73163480Sjfrank 	int ntry;
73173480Sjfrank 
73183480Sjfrank 	if (!page_retire_pend_count()) {
73193480Sjfrank 		/*
73203480Sjfrank 		 * Do we really want to be this aggressive
73213480Sjfrank 		 * for things other than page_retire?
73223480Sjfrank 		 * Maybe have a counter for each callback
73233480Sjfrank 		 * type to guide how aggressive we should
73243480Sjfrank 		 * be here.  Thus if there's at least one
73253480Sjfrank 		 * page for page_retire we go ahead and reap
73263480Sjfrank 		 * like this.
73273480Sjfrank 		 */
73283480Sjfrank 		kmem_reap();
73293480Sjfrank 		seg_preap();
73303480Sjfrank 		page_capture_async();
73313480Sjfrank 	} else {
73323480Sjfrank 		/*
73333480Sjfrank 		 * There are pages pending retirement, so
73343480Sjfrank 		 * we reap prior to attempting to capture.
73353480Sjfrank 		 */
73363480Sjfrank 		kmem_reap();
73373480Sjfrank 		/*
73383480Sjfrank 		 * When ISM is in use, we need to disable and
73393480Sjfrank 		 * purge the seg_pcache, and initiate aio
73403480Sjfrank 		 * cleanup in order to release page locks and
73413480Sjfrank 		 * subsquently retire pages in need of
73423480Sjfrank 		 * retirement.
73433480Sjfrank 		 */
73443480Sjfrank 		if (spt_used) {
73453480Sjfrank 			/* disable and purge seg_pcache */
73463480Sjfrank 			(void) seg_p_disable();
73473480Sjfrank 			for (ntry = 0; ntry < pc_thread_ism_retry; ntry++) {
73483480Sjfrank 				if (!page_retire_pend_count())
73493480Sjfrank 					break;
73503480Sjfrank 				if (do_aio_cleanup()) {
73513480Sjfrank 					/*
73523480Sjfrank 					 * allow the apps cleanup threads
73533480Sjfrank 					 * to run
73543480Sjfrank 					 */
73553480Sjfrank 					delay(pc_thread_shortwait);
73563480Sjfrank 				}
73573480Sjfrank 				page_capture_async();
73583480Sjfrank 			}
73593480Sjfrank 			/* reenable seg_pcache */
73603480Sjfrank 			seg_p_enable();
73613480Sjfrank 		} else {
73623480Sjfrank 			seg_preap();
73633480Sjfrank 			page_capture_async();
73643480Sjfrank 		}
73653480Sjfrank 	}
73663480Sjfrank }
73673480Sjfrank 
73683480Sjfrank /*
73693253Smec  * The page_capture_thread loops forever, looking to see if there are
73703253Smec  * pages still waiting to be captured.
73713253Smec  */
73723253Smec static void
73733253Smec page_capture_thread(void)
73743253Smec {
73753253Smec 	callb_cpr_t c;
73763253Smec 	int outstanding;
73773253Smec 	int i;
73783253Smec 
73793253Smec 	CALLB_CPR_INIT(&c, &pc_thread_mutex, callb_generic_cpr, "page_capture");
73803253Smec 
73813253Smec 	mutex_enter(&pc_thread_mutex);
73823253Smec 	for (;;) {
73833253Smec 		outstanding = 0;
73843253Smec 		for (i = 0; i < NUM_PAGE_CAPTURE_BUCKETS; i++)
73853253Smec 			outstanding += page_capture_hash[i].num_pages;
73863253Smec 		if (outstanding) {
73873480Sjfrank 			page_capture_handle_outstanding();
73883253Smec 			CALLB_CPR_SAFE_BEGIN(&c);
73893253Smec 			(void) cv_timedwait(&pc_cv, &pc_thread_mutex,
73903253Smec 			    lbolt + pc_thread_shortwait);
73913253Smec 			CALLB_CPR_SAFE_END(&c, &pc_thread_mutex);
73923253Smec 		} else {
73933253Smec 			CALLB_CPR_SAFE_BEGIN(&c);
73943253Smec 			(void) cv_timedwait(&pc_cv, &pc_thread_mutex,
73953253Smec 			    lbolt + pc_thread_longwait);
73963253Smec 			CALLB_CPR_SAFE_END(&c, &pc_thread_mutex);
73973253Smec 		}
73983253Smec 	}
73993253Smec 	/*NOTREACHED*/
74003253Smec }
7401