2 * SPDX-License-Identifier: BSD-3-Clause
4 * Copyright (c) 2002 Poul-Henning Kamp
5 * Copyright (c) 2002 Networks Associates Technology, Inc.
8 * This software was developed for the FreeBSD Project by Poul-Henning Kamp
9 * and NAI Labs, the Security Research Division of Network Associates, Inc.
10 * under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
11 * DARPA CHATS research program.
13 * Redistribution and use in source and binary forms, with or without
14 * modification, are permitted provided that the following conditions
16 * 1. Redistributions of source code must retain the above copyright
17 * notice, this list of conditions and the following disclaimer.
18 * 2. Redistributions in binary form must reproduce the above copyright
19 * notice, this list of conditions and the following disclaimer in the
20 * documentation and/or other materials provided with the distribution.
21 * 3. The names of the authors may not be used to endorse or promote
22 * products derived from this software without specific prior written
25 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
26 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
27 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
28 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
29 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
30 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
31 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
32 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
33 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
34 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
38 #include <sys/cdefs.h>
39 __FBSDID("$FreeBSD$");
41 #include <sys/param.h>
42 #include <sys/systm.h>
43 #include <sys/malloc.h>
44 #include <sys/kernel.h>
46 #include <sys/ctype.h>
50 #include <sys/mutex.h>
52 #include <sys/errno.h>
55 #include <sys/fcntl.h>
56 #include <sys/limits.h>
57 #include <sys/sysctl.h>
58 #include <geom/geom.h>
59 #include <geom/geom_int.h>
60 #include <machine/stdarg.h>
65 struct cdev *sc_alias;
68 #define SC_A_DESTROY (1 << 31)
69 #define SC_A_OPEN (1 << 30)
70 #define SC_A_ACTIVE (SC_A_OPEN - 1)
73 static d_open_t g_dev_open;
74 static d_close_t g_dev_close;
75 static d_strategy_t g_dev_strategy;
76 static d_ioctl_t g_dev_ioctl;
78 static struct cdevsw g_dev_cdevsw = {
79 .d_version = D_VERSION,
81 .d_close = g_dev_close,
84 .d_ioctl = g_dev_ioctl,
85 .d_strategy = g_dev_strategy,
87 .d_flags = D_DISK | D_TRACKCLOSE,
90 static g_init_t g_dev_init;
91 static g_fini_t g_dev_fini;
92 static g_taste_t g_dev_taste;
93 static g_orphan_t g_dev_orphan;
94 static g_attrchanged_t g_dev_attrchanged;
96 static struct g_class g_dev_class = {
101 .taste = g_dev_taste,
102 .orphan = g_dev_orphan,
103 .attrchanged = g_dev_attrchanged
107 * We target 262144 (8 x 32768) sectors by default as this significantly
108 * increases the throughput on commonly used SSD's with a marginal
109 * increase in non-interruptible request latency.
111 static uint64_t g_dev_del_max_sectors = 262144;
112 SYSCTL_DECL(_kern_geom);
113 SYSCTL_NODE(_kern_geom, OID_AUTO, dev, CTLFLAG_RW, 0, "GEOM_DEV stuff");
114 SYSCTL_QUAD(_kern_geom_dev, OID_AUTO, delete_max_sectors, CTLFLAG_RW,
115 &g_dev_del_max_sectors, 0, "Maximum number of sectors in a single "
116 "delete request sent to the provider. Larger requests are chunked "
117 "so they can be interrupted. (0 = disable chunking)");
119 static char *dumpdev = NULL;
121 g_dev_init(struct g_class *mp)
124 dumpdev = kern_getenv("dumpdev");
128 g_dev_fini(struct g_class *mp)
136 g_dev_setdumpdev(struct cdev *dev, struct diocskerneldump_arg *kda,
139 struct g_kerneldump kd;
140 struct g_consumer *cp;
143 if (dev == NULL || kda == NULL)
144 return (clear_dumper(td));
151 error = g_io_getattr("GEOM::kerneldump", cp, &len, &kd);
155 error = set_dumper(&kd.di, devtoname(dev), td, kda->kda_compression,
156 kda->kda_encryption, kda->kda_key, kda->kda_encryptedkeysize,
157 kda->kda_encryptedkey);
159 dev->si_flags |= SI_DUMPDEV;
165 init_dumpdev(struct cdev *dev)
167 struct diocskerneldump_arg kda;
168 struct g_consumer *cp;
169 const char *devprefix = "/dev/", *devname;
173 bzero(&kda, sizeof(kda));
179 len = strlen(devprefix);
180 devname = devtoname(dev);
181 if (strcmp(devname, dumpdev) != 0 &&
182 (strncmp(dumpdev, devprefix, len) != 0 ||
183 strcmp(devname, dumpdev + len) != 0))
186 cp = (struct g_consumer *)dev->si_drv2;
187 error = g_access(cp, 1, 0, 0);
191 error = g_dev_setdumpdev(dev, &kda, curthread);
197 (void)g_access(cp, -1, 0, 0);
203 g_dev_destroy(void *arg, int flags __unused)
205 struct g_consumer *cp;
207 struct g_dev_softc *sc;
208 char buf[SPECNAMELEN + 6];
214 g_trace(G_T_TOPOLOGY, "g_dev_destroy(%p(%s))", cp, gp->name);
215 snprintf(buf, sizeof(buf), "cdev=%s", gp->name);
216 devctl_notify_f("GEOM", "DEV", "DESTROY", buf, M_WAITOK);
217 if (cp->acr > 0 || cp->acw > 0 || cp->ace > 0)
218 g_access(cp, -cp->acr, -cp->acw, -cp->ace);
220 g_destroy_consumer(cp);
222 mtx_destroy(&sc->sc_mtx);
232 LIST_FOREACH(gp, &g_dev_class.geom, geom) {
233 printf("%s%s", p, gp->name);
240 g_dev_set_physpath(struct g_consumer *cp)
242 struct g_dev_softc *sc;
244 int error, physpath_len;
246 if (g_access(cp, 1, 0, 0) != 0)
250 physpath_len = MAXPATHLEN;
251 physpath = g_malloc(physpath_len, M_WAITOK|M_ZERO);
252 error = g_io_getattr("GEOM::physpath", cp, &physpath_len, physpath);
253 g_access(cp, -1, 0, 0);
254 if (error == 0 && strlen(physpath) != 0) {
255 struct cdev *dev, *old_alias_dev;
256 struct cdev **alias_devp;
259 old_alias_dev = sc->sc_alias;
260 alias_devp = (struct cdev **)&sc->sc_alias;
261 make_dev_physpath_alias(MAKEDEV_WAITOK, alias_devp, dev,
262 old_alias_dev, physpath);
263 } else if (sc->sc_alias) {
264 destroy_dev((struct cdev *)sc->sc_alias);
271 g_dev_set_media(struct g_consumer *cp)
273 struct g_dev_softc *sc;
275 char buf[SPECNAMELEN + 6];
279 snprintf(buf, sizeof(buf), "cdev=%s", dev->si_name);
280 devctl_notify_f("DEVFS", "CDEV", "MEDIACHANGE", buf, M_WAITOK);
281 devctl_notify_f("GEOM", "DEV", "MEDIACHANGE", buf, M_WAITOK);
284 snprintf(buf, sizeof(buf), "cdev=%s", dev->si_name);
285 devctl_notify_f("DEVFS", "CDEV", "MEDIACHANGE", buf, M_WAITOK);
286 devctl_notify_f("GEOM", "DEV", "MEDIACHANGE", buf, M_WAITOK);
291 g_dev_attrchanged(struct g_consumer *cp, const char *attr)
294 if (strcmp(attr, "GEOM::media") == 0) {
299 if (strcmp(attr, "GEOM::physpath") == 0) {
300 g_dev_set_physpath(cp);
306 g_dev_getprovider(struct cdev *dev)
308 struct g_consumer *cp;
313 if (dev->si_devsw != &g_dev_cdevsw)
316 return (cp->provider);
319 static struct g_geom *
320 g_dev_taste(struct g_class *mp, struct g_provider *pp, int insist __unused)
323 struct g_geom_alias *gap;
324 struct g_consumer *cp;
325 struct g_dev_softc *sc;
327 struct cdev *dev, *adev;
328 char buf[SPECNAMELEN + 6];
329 struct make_dev_args args;
331 g_trace(G_T_TOPOLOGY, "dev_taste(%s,%s)", mp->name, pp->name);
333 gp = g_new_geomf(mp, "%s", pp->name);
334 sc = g_malloc(sizeof(*sc), M_WAITOK | M_ZERO);
335 mtx_init(&sc->sc_mtx, "g_dev", NULL, MTX_DEF);
336 cp = g_new_consumer(gp);
338 cp->flags |= G_CF_DIRECT_SEND | G_CF_DIRECT_RECEIVE;
339 error = g_attach(cp, pp);
341 ("g_dev_taste(%s) failed to g_attach, err=%d", pp->name, error));
343 make_dev_args_init(&args);
344 args.mda_flags = MAKEDEV_CHECKNAME | MAKEDEV_WAITOK;
345 args.mda_devsw = &g_dev_cdevsw;
347 args.mda_uid = UID_ROOT;
348 args.mda_gid = GID_OPERATOR;
349 args.mda_mode = 0640;
350 args.mda_si_drv1 = sc;
351 args.mda_si_drv2 = cp;
352 error = make_dev_s(&args, &sc->sc_dev, "%s", gp->name);
354 printf("%s: make_dev_p() failed (gp->name=%s, error=%d)\n",
355 __func__, gp->name, error);
357 g_destroy_consumer(cp);
359 mtx_destroy(&sc->sc_mtx);
364 dev->si_flags |= SI_UNMAPPED;
365 dev->si_iosize_max = MAXPHYS;
366 error = init_dumpdev(dev);
368 printf("%s: init_dumpdev() failed (gp->name=%s, error=%d)\n",
369 __func__, gp->name, error);
371 g_dev_attrchanged(cp, "GEOM::physpath");
372 snprintf(buf, sizeof(buf), "cdev=%s", gp->name);
373 devctl_notify_f("GEOM", "DEV", "CREATE", buf, M_WAITOK);
375 * Now add all the aliases for this drive
377 LIST_FOREACH(gap, &pp->geom->aliases, ga_next) {
378 error = make_dev_alias_p(MAKEDEV_CHECKNAME | MAKEDEV_WAITOK, &adev, dev,
379 "%s", gap->ga_alias);
381 printf("%s: make_dev_alias_p() failed (name=%s, error=%d)\n",
382 __func__, gap->ga_alias, error);
385 snprintf(buf, sizeof(buf), "cdev=%s", gap->ga_alias);
386 devctl_notify_f("GEOM", "DEV", "CREATE", buf, M_WAITOK);
393 g_dev_open(struct cdev *dev, int flags, int fmt, struct thread *td)
395 struct g_consumer *cp;
396 struct g_dev_softc *sc;
400 g_trace(G_T_ACCESS, "g_dev_open(%s, %d, %d, %p)",
401 cp->geom->name, flags, fmt, td);
403 r = flags & FREAD ? 1 : 0;
404 w = flags & FWRITE ? 1 : 0;
406 e = flags & O_EXCL ? 1 : 0;
412 * This happens on attempt to open a device node with O_EXEC.
419 * When running in very secure mode, do not allow
420 * opens for writing of any disks.
422 error = securelevel_ge(td->td_ucred, 2);
427 error = g_access(cp, r, w, e);
431 mtx_lock(&sc->sc_mtx);
432 if (sc->sc_open == 0 && (sc->sc_active & SC_A_ACTIVE) != 0)
433 wakeup(&sc->sc_active);
434 sc->sc_open += r + w + e;
435 if (sc->sc_open == 0)
436 atomic_clear_int(&sc->sc_active, SC_A_OPEN);
438 atomic_set_int(&sc->sc_active, SC_A_OPEN);
439 mtx_unlock(&sc->sc_mtx);
445 g_dev_close(struct cdev *dev, int flags, int fmt, struct thread *td)
447 struct g_consumer *cp;
448 struct g_dev_softc *sc;
452 g_trace(G_T_ACCESS, "g_dev_close(%s, %d, %d, %p)",
453 cp->geom->name, flags, fmt, td);
455 r = flags & FREAD ? -1 : 0;
456 w = flags & FWRITE ? -1 : 0;
458 e = flags & O_EXCL ? -1 : 0;
464 * The vgonel(9) - caused by eg. forced unmount of devfs - calls
465 * VOP_CLOSE(9) on devfs vnode without any FREAD or FWRITE flags,
466 * which would result in zero deltas, which in turn would cause
467 * panic in g_access(9).
469 * Note that we cannot zero the counters (ie. do "r = cp->acr"
470 * etc) instead, because the consumer might be opened in another
477 mtx_lock(&sc->sc_mtx);
478 sc->sc_open += r + w + e;
479 if (sc->sc_open == 0)
480 atomic_clear_int(&sc->sc_active, SC_A_OPEN);
482 atomic_set_int(&sc->sc_active, SC_A_OPEN);
483 while (sc->sc_open == 0 && (sc->sc_active & SC_A_ACTIVE) != 0)
484 msleep(&sc->sc_active, &sc->sc_mtx, 0, "g_dev_close", hz / 10);
485 mtx_unlock(&sc->sc_mtx);
487 error = g_access(cp, r, w, e);
493 g_dev_ioctl(struct cdev *dev, u_long cmd, caddr_t data, int fflag, struct thread *td)
495 struct g_consumer *cp;
496 struct g_provider *pp;
497 off_t offset, length, chunk, odd;
503 /* If consumer or provider is dying, don't disturb. */
504 if (cp->flags & G_CF_ORPHAN)
510 KASSERT(cp->acr || cp->acw,
511 ("Consumer with zero access count in g_dev_ioctl"));
513 i = IOCPARM_LEN(cmd);
515 case DIOCGSECTORSIZE:
516 *(u_int *)data = pp->sectorsize;
517 if (*(u_int *)data == 0)
521 *(off_t *)data = pp->mediasize;
522 if (*(off_t *)data == 0)
526 error = g_io_getattr("GEOM::fwsectors", cp, &i, data);
527 if (error == 0 && *(u_int *)data == 0)
531 error = g_io_getattr("GEOM::fwheads", cp, &i, data);
532 if (error == 0 && *(u_int *)data == 0)
535 case DIOCGFRONTSTUFF:
536 error = g_io_getattr("GEOM::frontstuff", cp, &i, data);
538 #ifdef COMPAT_FREEBSD11
539 case DIOCSKERNELDUMP_FREEBSD11:
541 struct diocskerneldump_arg kda;
543 bzero(&kda, sizeof(kda));
544 kda.kda_encryption = KERNELDUMP_ENC_NONE;
545 kda.kda_enable = (uint8_t)*(u_int *)data;
546 if (kda.kda_enable == 0)
547 error = g_dev_setdumpdev(NULL, NULL, td);
549 error = g_dev_setdumpdev(dev, &kda, td);
553 case DIOCSKERNELDUMP:
555 struct diocskerneldump_arg *kda;
556 uint8_t *encryptedkey;
558 kda = (struct diocskerneldump_arg *)data;
559 if (kda->kda_enable == 0) {
560 error = g_dev_setdumpdev(NULL, NULL, td);
564 if (kda->kda_encryption != KERNELDUMP_ENC_NONE) {
565 if (kda->kda_encryptedkeysize <= 0 ||
566 kda->kda_encryptedkeysize >
567 KERNELDUMP_ENCKEY_MAX_SIZE) {
570 encryptedkey = malloc(kda->kda_encryptedkeysize, M_TEMP,
572 error = copyin(kda->kda_encryptedkey, encryptedkey,
573 kda->kda_encryptedkeysize);
578 kda->kda_encryptedkey = encryptedkey;
579 error = g_dev_setdumpdev(dev, kda, td);
581 if (encryptedkey != NULL) {
582 explicit_bzero(encryptedkey, kda->kda_encryptedkeysize);
583 free(encryptedkey, M_TEMP);
585 explicit_bzero(kda, sizeof(*kda));
589 error = g_io_flush(cp);
592 offset = ((off_t *)data)[0];
593 length = ((off_t *)data)[1];
594 if ((offset % pp->sectorsize) != 0 ||
595 (length % pp->sectorsize) != 0 || length <= 0) {
596 printf("%s: offset=%jd length=%jd\n", __func__, offset,
603 if (g_dev_del_max_sectors != 0 &&
604 chunk > g_dev_del_max_sectors * pp->sectorsize) {
605 chunk = g_dev_del_max_sectors * pp->sectorsize;
606 if (pp->stripesize > 0) {
607 odd = (offset + chunk +
608 pp->stripeoffset) % pp->stripesize;
613 error = g_delete_data(cp, offset, chunk);
619 * Since the request size can be large, the service
620 * time can be is likewise. We make this ioctl
621 * interruptible by checking for signals for each bio.
628 error = g_io_getattr("GEOM::ident", cp, &i, data);
630 case DIOCGPROVIDERNAME:
631 strlcpy(data, pp->name, i);
633 case DIOCGSTRIPESIZE:
634 *(off_t *)data = pp->stripesize;
636 case DIOCGSTRIPEOFFSET:
637 *(off_t *)data = pp->stripeoffset;
640 error = g_io_getattr("GEOM::physpath", cp, &i, data);
641 if (error == 0 && *(char *)data == '\0')
645 struct diocgattr_arg *arg = (struct diocgattr_arg *)data;
647 if (arg->len > sizeof(arg->value)) {
651 error = g_io_getattr(arg->name, cp, &arg->len, &arg->value);
655 struct disk_zone_args *zone_args =(struct disk_zone_args *)data;
656 struct disk_zone_rep_entry *new_entries, *old_entries;
657 struct disk_zone_report *rep;
665 if (zone_args->zone_cmd == DISK_ZONE_REPORT_ZONES) {
666 rep = &zone_args->zone_params.report;
667 #define MAXENTRIES (MAXPHYS / sizeof(struct disk_zone_rep_entry))
668 if (rep->entries_allocated > MAXENTRIES)
669 rep->entries_allocated = MAXENTRIES;
670 alloc_size = rep->entries_allocated *
671 sizeof(struct disk_zone_rep_entry);
673 new_entries = g_malloc(alloc_size,
675 old_entries = rep->entries;
676 rep->entries = new_entries;
678 error = g_io_zonecmd(zone_args, cp);
679 if (zone_args->zone_cmd == DISK_ZONE_REPORT_ZONES &&
680 alloc_size != 0 && error == 0)
681 error = copyout(new_entries, old_entries, alloc_size);
682 if (old_entries != NULL && rep != NULL)
683 rep->entries = old_entries;
684 if (new_entries != NULL)
689 if (pp->geom->ioctl != NULL) {
690 error = pp->geom->ioctl(pp, cmd, data, fflag, td);
700 g_dev_done(struct bio *bp2)
702 struct g_consumer *cp;
703 struct g_dev_softc *sc;
709 bp = bp2->bio_parent;
710 bp->bio_error = bp2->bio_error;
711 bp->bio_completed = bp2->bio_completed;
712 bp->bio_resid = bp->bio_length - bp2->bio_completed;
713 if (bp2->bio_cmd == BIO_ZONE)
714 bcopy(&bp2->bio_zone, &bp->bio_zone, sizeof(bp->bio_zone));
716 if (bp2->bio_error != 0) {
717 g_trace(G_T_BIO, "g_dev_done(%p) had error %d",
718 bp2, bp2->bio_error);
719 bp->bio_flags |= BIO_ERROR;
721 g_trace(G_T_BIO, "g_dev_done(%p/%p) resid %ld completed %jd",
722 bp2, bp, bp2->bio_resid, (intmax_t)bp2->bio_completed);
725 active = atomic_fetchadd_int(&sc->sc_active, -1) - 1;
726 if ((active & SC_A_ACTIVE) == 0) {
727 if ((active & SC_A_OPEN) == 0)
728 wakeup(&sc->sc_active);
729 if (active & SC_A_DESTROY)
730 g_post_event(g_dev_destroy, cp, M_NOWAIT, NULL);
736 g_dev_strategy(struct bio *bp)
738 struct g_consumer *cp;
741 struct g_dev_softc *sc;
743 KASSERT(bp->bio_cmd == BIO_READ ||
744 bp->bio_cmd == BIO_WRITE ||
745 bp->bio_cmd == BIO_DELETE ||
746 bp->bio_cmd == BIO_FLUSH ||
747 bp->bio_cmd == BIO_ZONE,
748 ("Wrong bio_cmd bio=%p cmd=%d", bp, bp->bio_cmd));
751 KASSERT(cp->acr || cp->acw,
752 ("Consumer with zero access count in g_dev_strategy"));
753 biotrack(bp, __func__);
755 if ((bp->bio_offset % cp->provider->sectorsize) != 0 ||
756 (bp->bio_bcount % cp->provider->sectorsize) != 0) {
757 bp->bio_resid = bp->bio_bcount;
758 biofinish(bp, NULL, EINVAL);
763 KASSERT(sc->sc_open > 0, ("Closed device in g_dev_strategy"));
764 atomic_add_int(&sc->sc_active, 1);
768 * XXX: This is not an ideal solution, but I believe it to
769 * XXX: deadlock safely, all things considered.
771 bp2 = g_clone_bio(bp);
774 pause("gdstrat", hz / 10);
776 KASSERT(bp2 != NULL, ("XXX: ENOMEM in a bad place"));
777 bp2->bio_done = g_dev_done;
779 "g_dev_strategy(%p/%p) offset %jd length %jd data %p cmd %d",
780 bp, bp2, (intmax_t)bp->bio_offset, (intmax_t)bp2->bio_length,
781 bp2->bio_data, bp2->bio_cmd);
782 g_io_request(bp2, cp);
783 KASSERT(cp->acr || cp->acw,
784 ("g_dev_strategy raced with g_dev_close and lost"));
791 * Called by devfs when asynchronous device destruction is completed.
792 * - Mark that we have no attached device any more.
793 * - If there are no outstanding requests, schedule geom destruction.
794 * Otherwise destruction will be scheduled later by g_dev_done().
798 g_dev_callback(void *arg)
800 struct g_consumer *cp;
801 struct g_dev_softc *sc;
806 g_trace(G_T_TOPOLOGY, "g_dev_callback(%p(%s))", cp, cp->geom->name);
810 active = atomic_fetchadd_int(&sc->sc_active, SC_A_DESTROY);
811 if ((active & SC_A_ACTIVE) == 0)
812 g_post_event(g_dev_destroy, cp, M_WAITOK, NULL);
818 * Called from below when the provider orphaned us.
819 * - Clear any dump settings.
820 * - Request asynchronous device destruction to prevent any more requests
821 * from coming in. The provider is already marked with an error, so
822 * anything which comes in the interim will be returned immediately.
826 g_dev_orphan(struct g_consumer *cp)
829 struct g_dev_softc *sc;
834 g_trace(G_T_TOPOLOGY, "g_dev_orphan(%p(%s))", cp, cp->geom->name);
836 /* Reset any dump-area set on this device */
837 if (dev->si_flags & SI_DUMPDEV)
838 (void)clear_dumper(curthread);
840 /* Destroy the struct cdev *so we get no more requests */
842 destroy_dev_sched_cb(dev, g_dev_callback, cp);
845 DECLARE_GEOM_CLASS(g_dev_class, g_dev);