2 * Copyright (c) 2002 Poul-Henning Kamp
3 * Copyright (c) 2002 Networks Associates Technology, Inc.
6 * This software was developed for the FreeBSD Project by Poul-Henning Kamp
7 * and NAI Labs, the Security Research Division of Network Associates, Inc.
8 * under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
9 * DARPA CHATS research program.
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
14 * 1. Redistributions of source code must retain the above copyright
15 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
19 * 3. The names of the authors may not be used to endorse or promote
20 * products derived from this software without specific prior written
23 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
36 #include <sys/cdefs.h>
37 __FBSDID("$FreeBSD$");
39 #include <sys/param.h>
40 #include <sys/systm.h>
41 #include <sys/malloc.h>
42 #include <sys/kernel.h>
46 #include <sys/mutex.h>
48 #include <sys/errno.h>
51 #include <sys/fcntl.h>
52 #include <sys/limits.h>
53 #include <geom/geom.h>
54 #include <geom/geom_int.h>
56 static d_open_t g_dev_open;
57 static d_close_t g_dev_close;
58 static d_strategy_t g_dev_strategy;
59 static d_ioctl_t g_dev_ioctl;
61 static struct cdevsw g_dev_cdevsw = {
62 .d_version = D_VERSION,
64 .d_close = g_dev_close,
67 .d_ioctl = g_dev_ioctl,
68 .d_strategy = g_dev_strategy,
70 .d_flags = D_DISK | D_TRACKCLOSE,
73 static g_taste_t g_dev_taste;
74 static g_orphan_t g_dev_orphan;
76 static struct g_class g_dev_class = {
80 .orphan = g_dev_orphan,
89 LIST_FOREACH(gp, &g_dev_class.geom, geom) {
90 printf("%s%s", p, gp->name);
97 g_dev_getprovider(struct cdev *dev)
99 struct g_consumer *cp;
104 if (dev->si_devsw != &g_dev_cdevsw)
107 return (cp->provider);
111 static struct g_geom *
112 g_dev_taste(struct g_class *mp, struct g_provider *pp, int insist __unused)
115 struct g_consumer *cp;
119 g_trace(G_T_TOPOLOGY, "dev_taste(%s,%s)", mp->name, pp->name);
121 LIST_FOREACH(cp, &pp->consumers, consumers)
122 if (cp->geom->class == mp)
124 gp = g_new_geomf(mp, pp->name);
125 cp = g_new_consumer(gp);
126 error = g_attach(cp, pp);
128 ("g_dev_taste(%s) failed to g_attach, err=%d", pp->name, error));
129 dev = make_dev(&g_dev_cdevsw, 0,
130 UID_ROOT, GID_OPERATOR, 0640, "%s", gp->name);
131 if (pp->flags & G_PF_CANDELETE)
132 dev->si_flags |= SI_CANDELETE;
133 dev->si_iosize_max = MAXPHYS;
141 g_dev_open(struct cdev *dev, int flags, int fmt, struct thread *td)
144 struct g_consumer *cp;
149 if (gp == NULL || cp == NULL || gp->softc != dev)
150 return(ENXIO); /* g_dev_taste() not done yet */
152 g_trace(G_T_ACCESS, "g_dev_open(%s, %d, %d, %p)",
153 gp->name, flags, fmt, td);
155 r = flags & FREAD ? 1 : 0;
156 w = flags & FWRITE ? 1 : 0;
158 e = flags & O_EXCL ? 1 : 0;
164 * When running in very secure mode, do not allow
165 * opens for writing of any disks.
167 error = securelevel_ge(td->td_ucred, 2);
172 if (dev->si_devsw == NULL)
173 error = ENXIO; /* We were orphaned */
175 error = g_access(cp, r, w, e);
181 g_dev_close(struct cdev *dev, int flags, int fmt, struct thread *td)
184 struct g_consumer *cp;
185 int error, r, w, e, i;
189 if (gp == NULL || cp == NULL)
191 g_trace(G_T_ACCESS, "g_dev_close(%s, %d, %d, %p)",
192 gp->name, flags, fmt, td);
193 r = flags & FREAD ? -1 : 0;
194 w = flags & FWRITE ? -1 : 0;
196 e = flags & O_EXCL ? -1 : 0;
201 if (dev->si_devsw == NULL)
202 error = ENXIO; /* We were orphaned */
204 error = g_access(cp, r, w, e);
205 for (i = 0; i < 10 * hz;) {
206 if (cp->acr != 0 || cp->acw != 0)
208 if (cp->nstart == cp->nend)
210 pause("gdevwclose", hz / 10);
213 if (cp->acr == 0 && cp->acw == 0 && cp->nstart != cp->nend) {
214 printf("WARNING: Final close of geom_dev(%s) %s %s\n",
216 "still has outstanding I/O after 10 seconds.",
217 "Completing close anyway, panic may happen later.");
224 * XXX: Until we have unmessed the ioctl situation, there is a race against
225 * XXX: a concurrent orphanization. We cannot close it by holding topology
226 * XXX: since that would prevent us from doing our job, and stalling events
227 * XXX: will break (actually: stall) the BSD disklabel hacks.
230 g_dev_ioctl(struct cdev *dev, u_long cmd, caddr_t data, int fflag, struct thread *td)
233 struct g_consumer *cp;
234 struct g_provider *pp;
235 struct g_kerneldump kd;
236 off_t offset, length, chunk;
245 KASSERT(cp->acr || cp->acw,
246 ("Consumer with zero access count in g_dev_ioctl"));
248 i = IOCPARM_LEN(cmd);
250 case DIOCGSECTORSIZE:
251 *(u_int *)data = cp->provider->sectorsize;
252 if (*(u_int *)data == 0)
256 *(off_t *)data = cp->provider->mediasize;
257 if (*(off_t *)data == 0)
261 error = g_io_getattr("GEOM::fwsectors", cp, &i, data);
262 if (error == 0 && *(u_int *)data == 0)
266 error = g_io_getattr("GEOM::fwheads", cp, &i, data);
267 if (error == 0 && *(u_int *)data == 0)
270 case DIOCGFRONTSTUFF:
271 error = g_io_getattr("GEOM::frontstuff", cp, &i, data);
273 case DIOCSKERNELDUMP:
274 u = *((u_int *)data);
283 error = g_io_getattr("GEOM::kerneldump", cp, &i, &kd);
285 error = set_dumper(&kd.di);
287 dev->si_flags |= SI_DUMPDEV;
291 error = g_io_flush(cp);
294 offset = ((off_t *)data)[0];
295 length = ((off_t *)data)[1];
296 if ((offset % cp->provider->sectorsize) != 0 ||
297 (length % cp->provider->sectorsize) != 0 || length <= 0) {
298 printf("%s: offset=%jd length=%jd\n", __func__, offset,
305 if (chunk > 65536 * cp->provider->sectorsize)
306 chunk = 65536 * cp->provider->sectorsize;
307 error = g_delete_data(cp, offset, chunk);
313 * Since the request size is unbounded, the service
314 * time is likewise. We make this ioctl interruptible
315 * by checking for signals for each bio.
322 error = g_io_getattr("GEOM::ident", cp, &i, data);
324 case DIOCGPROVIDERNAME:
327 strlcpy(data, pp->name, i);
329 case DIOCGSTRIPESIZE:
330 *(off_t *)data = cp->provider->stripesize;
332 case DIOCGSTRIPEOFFSET:
333 *(off_t *)data = cp->provider->stripeoffset;
336 if (cp->provider->geom->ioctl != NULL) {
337 error = cp->provider->geom->ioctl(cp->provider, cmd, data, fflag, td);
347 g_dev_done(struct bio *bp2)
351 bp = bp2->bio_parent;
352 bp->bio_error = bp2->bio_error;
353 if (bp->bio_error != 0) {
354 g_trace(G_T_BIO, "g_dev_done(%p) had error %d",
356 bp->bio_flags |= BIO_ERROR;
358 g_trace(G_T_BIO, "g_dev_done(%p/%p) resid %ld completed %jd",
359 bp2, bp, bp->bio_resid, (intmax_t)bp2->bio_completed);
361 bp->bio_resid = bp->bio_length - bp2->bio_completed;
362 bp->bio_completed = bp2->bio_completed;
368 g_dev_strategy(struct bio *bp)
370 struct g_consumer *cp;
374 KASSERT(bp->bio_cmd == BIO_READ ||
375 bp->bio_cmd == BIO_WRITE ||
376 bp->bio_cmd == BIO_DELETE,
377 ("Wrong bio_cmd bio=%p cmd=%d", bp, bp->bio_cmd));
380 KASSERT(cp->acr || cp->acw,
381 ("Consumer with zero access count in g_dev_strategy"));
383 if ((bp->bio_offset % cp->provider->sectorsize) != 0 ||
384 (bp->bio_bcount % cp->provider->sectorsize) != 0) {
385 bp->bio_resid = bp->bio_bcount;
386 biofinish(bp, NULL, EINVAL);
392 * XXX: This is not an ideal solution, but I belive it to
393 * XXX: deadlock safe, all things considered.
395 bp2 = g_clone_bio(bp);
398 pause("gdstrat", hz / 10);
400 KASSERT(bp2 != NULL, ("XXX: ENOMEM in a bad place"));
401 bp2->bio_done = g_dev_done;
403 "g_dev_strategy(%p/%p) offset %jd length %jd data %p cmd %d",
404 bp, bp2, (intmax_t)bp->bio_offset, (intmax_t)bp2->bio_length,
405 bp2->bio_data, bp2->bio_cmd);
406 g_io_request(bp2, cp);
407 KASSERT(cp->acr || cp->acw,
408 ("g_dev_strategy raced with g_dev_close and lost"));
415 * Called from below when the provider orphaned us.
416 * - Clear any dump settings.
417 * - Destroy the struct cdev *to prevent any more request from coming in. The
418 * provider is already marked with an error, so anything which comes in
419 * in the interrim will be returned immediately.
420 * - Wait for any outstanding I/O to finish.
421 * - Set our access counts to zero, whatever they were.
422 * - Detach and self-destruct.
426 g_dev_orphan(struct g_consumer *cp)
434 g_trace(G_T_TOPOLOGY, "g_dev_orphan(%p(%s))", cp, gp->name);
436 /* Reset any dump-area set on this device */
437 if (dev->si_flags & SI_DUMPDEV)
440 /* Destroy the struct cdev *so we get no more requests */
443 /* Wait for the cows to come home */
444 while (cp->nstart != cp->nend)
445 pause("gdevorphan", hz / 10);
447 if (cp->acr > 0 || cp->acw > 0 || cp->ace > 0)
448 g_access(cp, -cp->acr, -cp->acw, -cp->ace);
451 g_destroy_consumer(cp);
455 DECLARE_GEOM_CLASS(g_dev_class, g_dev);