]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/blob - sys/riscv/riscv/busdma_bounce.c
riscv: very large dma mappings can cause integer overflow
[FreeBSD/FreeBSD.git] / sys / riscv / riscv / busdma_bounce.c
1 /*-
2  * Copyright (c) 1997, 1998 Justin T. Gibbs.
3  * Copyright (c) 2015-2016 The FreeBSD Foundation
4  * All rights reserved.
5  *
6  * Portions of this software were developed by Andrew Turner
7  * under sponsorship of the FreeBSD Foundation.
8  *
9  * Portions of this software were developed by Semihalf
10  * under sponsorship of the FreeBSD Foundation.
11  *
12  * Redistribution and use in source and binary forms, with or without
13  * modification, are permitted provided that the following conditions
14  * are met:
15  * 1. Redistributions of source code must retain the above copyright
16  *    notice, this list of conditions, and the following disclaimer,
17  *    without modification, immediately at the beginning of the file.
18  * 2. The name of the author may not be used to endorse or promote products
19  *    derived from this software without specific prior written permission.
20  *
21  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24  * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE FOR
25  * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  */
33
34 #include <sys/cdefs.h>
35 __FBSDID("$FreeBSD$");
36
37 #include <sys/param.h>
38 #include <sys/systm.h>
39 #include <sys/malloc.h>
40 #include <sys/bus.h>
41 #include <sys/interrupt.h>
42 #include <sys/kernel.h>
43 #include <sys/ktr.h>
44 #include <sys/lock.h>
45 #include <sys/proc.h>
46 #include <sys/memdesc.h>
47 #include <sys/mutex.h>
48 #include <sys/sysctl.h>
49 #include <sys/uio.h>
50
51 #include <vm/vm.h>
52 #include <vm/vm_extern.h>
53 #include <vm/vm_kern.h>
54 #include <vm/vm_page.h>
55 #include <vm/vm_map.h>
56
57 #include <machine/atomic.h>
58 #include <machine/bus.h>
59 #include <machine/md_var.h>
60 #include <machine/bus_dma_impl.h>
61
62 #define MAX_BPAGES 4096
63
64 enum {
65         BF_COULD_BOUNCE         = 0x01,
66         BF_MIN_ALLOC_COMP       = 0x02,
67         BF_KMEM_ALLOC           = 0x04,
68         BF_COHERENT             = 0x10,
69 };
70
71 struct bounce_zone;
72
73 struct bus_dma_tag {
74         struct bus_dma_tag_common common;
75         int                     map_count;
76         int                     bounce_flags;
77         bus_dma_segment_t       *segments;
78         struct bounce_zone      *bounce_zone;
79 };
80
81 struct bounce_page {
82         vm_offset_t     vaddr;          /* kva of bounce buffer */
83         bus_addr_t      busaddr;        /* Physical address */
84         vm_offset_t     datavaddr;      /* kva of client data */
85         vm_page_t       datapage;       /* physical page of client data */
86         vm_offset_t     dataoffs;       /* page offset of client data */
87         bus_size_t      datacount;      /* client data count */
88         STAILQ_ENTRY(bounce_page) links;
89 };
90
91 int busdma_swi_pending;
92
93 struct bounce_zone {
94         STAILQ_ENTRY(bounce_zone) links;
95         STAILQ_HEAD(bp_list, bounce_page) bounce_page_list;
96         int             total_bpages;
97         int             free_bpages;
98         int             reserved_bpages;
99         int             active_bpages;
100         int             total_bounced;
101         int             total_deferred;
102         int             map_count;
103         bus_size_t      alignment;
104         bus_addr_t      lowaddr;
105         char            zoneid[8];
106         char            lowaddrid[20];
107         struct sysctl_ctx_list sysctl_tree;
108         struct sysctl_oid *sysctl_tree_top;
109 };
110
111 static struct mtx bounce_lock;
112 static int total_bpages;
113 static int busdma_zonecount;
114 static STAILQ_HEAD(, bounce_zone) bounce_zone_list;
115
116 static SYSCTL_NODE(_hw, OID_AUTO, busdma, CTLFLAG_RD | CTLFLAG_MPSAFE, 0,
117     "Busdma parameters");
118 SYSCTL_INT(_hw_busdma, OID_AUTO, total_bpages, CTLFLAG_RD, &total_bpages, 0,
119            "Total bounce pages");
120
121 struct sync_list {
122         vm_offset_t     vaddr;          /* kva of client data */
123         bus_addr_t      paddr;          /* physical address */
124         vm_page_t       pages;          /* starting page of client data */
125         bus_size_t      datacount;      /* client data count */
126 };
127
128 struct bus_dmamap {
129         struct bp_list         bpages;
130         int                    pagesneeded;
131         int                    pagesreserved;
132         bus_dma_tag_t          dmat;
133         struct memdesc         mem;
134         bus_dmamap_callback_t *callback;
135         void                  *callback_arg;
136         STAILQ_ENTRY(bus_dmamap) links;
137         u_int                   flags;
138 #define DMAMAP_COULD_BOUNCE     (1 << 0)
139 #define DMAMAP_FROM_DMAMEM      (1 << 1)
140         int                     sync_count;
141         struct sync_list        slist[];
142 };
143
144 static STAILQ_HEAD(, bus_dmamap) bounce_map_waitinglist;
145 static STAILQ_HEAD(, bus_dmamap) bounce_map_callbacklist;
146
147 static void init_bounce_pages(void *dummy);
148 static int alloc_bounce_zone(bus_dma_tag_t dmat);
149 static int alloc_bounce_pages(bus_dma_tag_t dmat, u_int numpages);
150 static int reserve_bounce_pages(bus_dma_tag_t dmat, bus_dmamap_t map,
151     int commit);
152 static bus_addr_t add_bounce_page(bus_dma_tag_t dmat, bus_dmamap_t map,
153     vm_offset_t vaddr, bus_addr_t addr, bus_size_t size);
154 static void free_bounce_page(bus_dma_tag_t dmat, struct bounce_page *bpage);
155 int run_filter(bus_dma_tag_t dmat, bus_addr_t paddr);
156 static void _bus_dmamap_count_pages(bus_dma_tag_t dmat, bus_dmamap_t map,
157     pmap_t pmap, void *buf, bus_size_t buflen, int flags);
158 static void _bus_dmamap_count_phys(bus_dma_tag_t dmat, bus_dmamap_t map,
159     vm_paddr_t buf, bus_size_t buflen, int flags);
160 static int _bus_dmamap_reserve_pages(bus_dma_tag_t dmat, bus_dmamap_t map,
161     int flags);
162
163 /*
164  * Allocate a device specific dma_tag.
165  */
166 static int
167 bounce_bus_dma_tag_create(bus_dma_tag_t parent, bus_size_t alignment,
168     bus_addr_t boundary, bus_addr_t lowaddr, bus_addr_t highaddr,
169     bus_dma_filter_t *filter, void *filterarg, bus_size_t maxsize,
170     int nsegments, bus_size_t maxsegsz, int flags, bus_dma_lock_t *lockfunc,
171     void *lockfuncarg, bus_dma_tag_t *dmat)
172 {
173         bus_dma_tag_t newtag;
174         int error;
175
176         *dmat = NULL;
177         error = common_bus_dma_tag_create(parent != NULL ? &parent->common :
178             NULL, alignment, boundary, lowaddr, highaddr, filter, filterarg,
179             maxsize, nsegments, maxsegsz, flags, lockfunc, lockfuncarg,
180             sizeof (struct bus_dma_tag), (void **)&newtag);
181         if (error != 0)
182                 return (error);
183
184         newtag->common.impl = &bus_dma_bounce_impl;
185         newtag->map_count = 0;
186         newtag->segments = NULL;
187
188         if ((flags & BUS_DMA_COHERENT) != 0)
189                 newtag->bounce_flags |= BF_COHERENT;
190
191         if (parent != NULL) {
192                 if ((newtag->common.filter != NULL ||
193                     (parent->bounce_flags & BF_COULD_BOUNCE) != 0))
194                         newtag->bounce_flags |= BF_COULD_BOUNCE;
195
196                 /* Copy some flags from the parent */
197                 newtag->bounce_flags |= parent->bounce_flags & BF_COHERENT;
198         }
199
200         if (newtag->common.lowaddr < ptoa((vm_paddr_t)Maxmem) ||
201             newtag->common.alignment > 1)
202                 newtag->bounce_flags |= BF_COULD_BOUNCE;
203
204         if (((newtag->bounce_flags & BF_COULD_BOUNCE) != 0) &&
205             (flags & BUS_DMA_ALLOCNOW) != 0) {
206                 struct bounce_zone *bz;
207
208                 /* Must bounce */
209                 if ((error = alloc_bounce_zone(newtag)) != 0) {
210                         free(newtag, M_DEVBUF);
211                         return (error);
212                 }
213                 bz = newtag->bounce_zone;
214
215                 if (ptoa(bz->total_bpages) < maxsize) {
216                         int pages;
217
218                         pages = atop(round_page(maxsize)) - bz->total_bpages;
219
220                         /* Add pages to our bounce pool */
221                         if (alloc_bounce_pages(newtag, pages) < pages)
222                                 error = ENOMEM;
223                 }
224                 /* Performed initial allocation */
225                 newtag->bounce_flags |= BF_MIN_ALLOC_COMP;
226         } else
227                 error = 0;
228
229         if (error != 0)
230                 free(newtag, M_DEVBUF);
231         else
232                 *dmat = newtag;
233         CTR4(KTR_BUSDMA, "%s returned tag %p tag flags 0x%x error %d",
234             __func__, newtag, (newtag != NULL ? newtag->common.flags : 0),
235             error);
236         return (error);
237 }
238
239 static int
240 bounce_bus_dma_tag_destroy(bus_dma_tag_t dmat)
241 {
242         bus_dma_tag_t dmat_copy, parent;
243         int error;
244
245         error = 0;
246         dmat_copy = dmat;
247
248         if (dmat != NULL) {
249                 if (dmat->map_count != 0) {
250                         error = EBUSY;
251                         goto out;
252                 }
253                 while (dmat != NULL) {
254                         parent = (bus_dma_tag_t)dmat->common.parent;
255                         atomic_subtract_int(&dmat->common.ref_count, 1);
256                         if (dmat->common.ref_count == 0) {
257                                 if (dmat->segments != NULL)
258                                         free(dmat->segments, M_DEVBUF);
259                                 free(dmat, M_DEVBUF);
260                                 /*
261                                  * Last reference count, so
262                                  * release our reference
263                                  * count on our parent.
264                                  */
265                                 dmat = parent;
266                         } else
267                                 dmat = NULL;
268                 }
269         }
270 out:
271         CTR3(KTR_BUSDMA, "%s tag %p error %d", __func__, dmat_copy, error);
272         return (error);
273 }
274
275 static bus_dmamap_t
276 alloc_dmamap(bus_dma_tag_t dmat, int flags)
277 {
278         u_long mapsize;
279         bus_dmamap_t map;
280
281         mapsize = sizeof(*map);
282         mapsize += sizeof(struct sync_list) * dmat->common.nsegments;
283         map = malloc(mapsize, M_DEVBUF, flags | M_ZERO);
284         if (map == NULL)
285                 return (NULL);
286
287         /* Initialize the new map */
288         STAILQ_INIT(&map->bpages);
289
290         return (map);
291 }
292
293 /*
294  * Allocate a handle for mapping from kva/uva/physical
295  * address space into bus device space.
296  */
297 static int
298 bounce_bus_dmamap_create(bus_dma_tag_t dmat, int flags, bus_dmamap_t *mapp)
299 {
300         struct bounce_zone *bz;
301         int error, maxpages, pages;
302
303         error = 0;
304
305         if (dmat->segments == NULL) {
306                 dmat->segments = (bus_dma_segment_t *)malloc(
307                     sizeof(bus_dma_segment_t) * dmat->common.nsegments,
308                     M_DEVBUF, M_NOWAIT);
309                 if (dmat->segments == NULL) {
310                         CTR3(KTR_BUSDMA, "%s: tag %p error %d",
311                             __func__, dmat, ENOMEM);
312                         return (ENOMEM);
313                 }
314         }
315
316         *mapp = alloc_dmamap(dmat, M_NOWAIT);
317         if (*mapp == NULL) {
318                 CTR3(KTR_BUSDMA, "%s: tag %p error %d",
319                     __func__, dmat, ENOMEM);
320                 return (ENOMEM);
321         }
322
323         /*
324          * Bouncing might be required if the driver asks for an active
325          * exclusion region, a data alignment that is stricter than 1, and/or
326          * an active address boundary.
327          */
328         if (dmat->bounce_flags & BF_COULD_BOUNCE) {
329                 /* Must bounce */
330                 if (dmat->bounce_zone == NULL) {
331                         if ((error = alloc_bounce_zone(dmat)) != 0) {
332                                 free(*mapp, M_DEVBUF);
333                                 return (error);
334                         }
335                 }
336                 bz = dmat->bounce_zone;
337
338                 (*mapp)->flags = DMAMAP_COULD_BOUNCE;
339
340                 /*
341                  * Attempt to add pages to our pool on a per-instance
342                  * basis up to a sane limit.
343                  */
344                 if (dmat->common.alignment > 1)
345                         maxpages = MAX_BPAGES;
346                 else
347                         maxpages = MIN(MAX_BPAGES, Maxmem -
348                             atop(dmat->common.lowaddr));
349                 if ((dmat->bounce_flags & BF_MIN_ALLOC_COMP) == 0 ||
350                     (bz->map_count > 0 && bz->total_bpages < maxpages)) {
351                         pages = MAX(atop(dmat->common.maxsize), 1);
352                         pages = MIN(maxpages - bz->total_bpages, pages);
353                         pages = MAX(pages, 1);
354                         if (alloc_bounce_pages(dmat, pages) < pages)
355                                 error = ENOMEM;
356                         if ((dmat->bounce_flags & BF_MIN_ALLOC_COMP)
357                             == 0) {
358                                 if (error == 0) {
359                                         dmat->bounce_flags |=
360                                             BF_MIN_ALLOC_COMP;
361                                 }
362                         } else
363                                 error = 0;
364                 }
365                 bz->map_count++;
366         }
367         if (error == 0)
368                 dmat->map_count++;
369         else
370                 free(*mapp, M_DEVBUF);
371         CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x error %d",
372             __func__, dmat, dmat->common.flags, error);
373         return (error);
374 }
375
376 /*
377  * Destroy a handle for mapping from kva/uva/physical
378  * address space into bus device space.
379  */
380 static int
381 bounce_bus_dmamap_destroy(bus_dma_tag_t dmat, bus_dmamap_t map)
382 {
383
384         /* Check we are destroying the correct map type */
385         if ((map->flags & DMAMAP_FROM_DMAMEM) != 0)
386                 panic("bounce_bus_dmamap_destroy: Invalid map freed\n");
387
388         if (STAILQ_FIRST(&map->bpages) != NULL || map->sync_count != 0) {
389                 CTR3(KTR_BUSDMA, "%s: tag %p error %d", __func__, dmat, EBUSY);
390                 return (EBUSY);
391         }
392         if (dmat->bounce_zone) {
393                 KASSERT((map->flags & DMAMAP_COULD_BOUNCE) != 0,
394                     ("%s: Bounce zone when cannot bounce", __func__));
395                 dmat->bounce_zone->map_count--;
396         }
397         free(map, M_DEVBUF);
398         dmat->map_count--;
399         CTR2(KTR_BUSDMA, "%s: tag %p error 0", __func__, dmat);
400         return (0);
401 }
402
403 /*
404  * Allocate a piece of memory that can be efficiently mapped into
405  * bus device space based on the constraints lited in the dma tag.
406  * A dmamap to for use with dmamap_load is also allocated.
407  */
408 static int
409 bounce_bus_dmamem_alloc(bus_dma_tag_t dmat, void** vaddr, int flags,
410     bus_dmamap_t *mapp)
411 {
412         /*
413          * XXX ARM64TODO:
414          * This bus_dma implementation requires IO-Coherent architecutre.
415          * If IO-Coherency is not guaranteed, the BUS_DMA_COHERENT flag has
416          * to be implented using non-cacheable memory.
417          */
418
419         vm_memattr_t attr;
420         int mflags;
421
422         if (flags & BUS_DMA_NOWAIT)
423                 mflags = M_NOWAIT;
424         else
425                 mflags = M_WAITOK;
426
427         if (dmat->segments == NULL) {
428                 dmat->segments = (bus_dma_segment_t *)malloc(
429                     sizeof(bus_dma_segment_t) * dmat->common.nsegments,
430                     M_DEVBUF, mflags);
431                 if (dmat->segments == NULL) {
432                         CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x error %d",
433                             __func__, dmat, dmat->common.flags, ENOMEM);
434                         return (ENOMEM);
435                 }
436         }
437         if (flags & BUS_DMA_ZERO)
438                 mflags |= M_ZERO;
439         if (flags & BUS_DMA_NOCACHE)
440                 attr = VM_MEMATTR_UNCACHEABLE;
441         else if ((flags & BUS_DMA_COHERENT) != 0 &&
442             (dmat->bounce_flags & BF_COHERENT) == 0)
443                 /*
444                  * If we have a non-coherent tag, and are trying to allocate
445                  * a coherent block of memory it needs to be uncached.
446                  */
447                 attr = VM_MEMATTR_UNCACHEABLE;
448         else
449                 attr = VM_MEMATTR_DEFAULT;
450
451         /*
452          * Create the map, but don't set the could bounce flag as
453          * this allocation should never bounce;
454          */
455         *mapp = alloc_dmamap(dmat, mflags);
456         if (*mapp == NULL) {
457                 CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x error %d",
458                     __func__, dmat, dmat->common.flags, ENOMEM);
459                 return (ENOMEM);
460         }
461         (*mapp)->flags = DMAMAP_FROM_DMAMEM;
462
463         /*
464          * Allocate the buffer from the malloc(9) allocator if...
465          *  - It's small enough to fit into a single power of two sized bucket.
466          *  - The alignment is less than or equal to the maximum size
467          *  - The low address requirement is fulfilled.
468          * else allocate non-contiguous pages if...
469          *  - The page count that could get allocated doesn't exceed
470          *    nsegments also when the maximum segment size is less
471          *    than PAGE_SIZE.
472          *  - The alignment constraint isn't larger than a page boundary.
473          *  - There are no boundary-crossing constraints.
474          * else allocate a block of contiguous pages because one or more of the
475          * constraints is something that only the contig allocator can fulfill.
476          *
477          * NOTE: The (dmat->common.alignment <= dmat->maxsize) check
478          * below is just a quick hack. The exact alignment guarantees
479          * of malloc(9) need to be nailed down, and the code below
480          * should be rewritten to take that into account.
481          *
482          * In the meantime warn the user if malloc gets it wrong.
483          */
484         if ((dmat->common.maxsize <= PAGE_SIZE) &&
485            (dmat->common.alignment <= dmat->common.maxsize) &&
486             dmat->common.lowaddr >= ptoa((vm_paddr_t)Maxmem) &&
487             attr == VM_MEMATTR_DEFAULT) {
488                 *vaddr = malloc(dmat->common.maxsize, M_DEVBUF, mflags);
489         } else if (dmat->common.nsegments >=
490             howmany(dmat->common.maxsize, MIN(dmat->common.maxsegsz, PAGE_SIZE)) &&
491             dmat->common.alignment <= PAGE_SIZE &&
492             (dmat->common.boundary % PAGE_SIZE) == 0) {
493                 /* Page-based multi-segment allocations allowed */
494                 *vaddr = (void *)kmem_alloc_attr(dmat->common.maxsize, mflags,
495                     0ul, dmat->common.lowaddr, attr);
496                 dmat->bounce_flags |= BF_KMEM_ALLOC;
497         } else {
498                 *vaddr = (void *)kmem_alloc_contig(dmat->common.maxsize, mflags,
499                     0ul, dmat->common.lowaddr, dmat->common.alignment != 0 ?
500                     dmat->common.alignment : 1ul, dmat->common.boundary, attr);
501                 dmat->bounce_flags |= BF_KMEM_ALLOC;
502         }
503         if (*vaddr == NULL) {
504                 CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x error %d",
505                     __func__, dmat, dmat->common.flags, ENOMEM);
506                 free(*mapp, M_DEVBUF);
507                 return (ENOMEM);
508         } else if (vtophys(*vaddr) & (dmat->common.alignment - 1)) {
509                 printf("bus_dmamem_alloc failed to align memory properly.\n");
510         }
511         dmat->map_count++;
512         CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x error %d",
513             __func__, dmat, dmat->common.flags, 0);
514         return (0);
515 }
516
517 /*
518  * Free a piece of memory and it's allociated dmamap, that was allocated
519  * via bus_dmamem_alloc.  Make the same choice for free/contigfree.
520  */
521 static void
522 bounce_bus_dmamem_free(bus_dma_tag_t dmat, void *vaddr, bus_dmamap_t map)
523 {
524
525         /*
526          * Check the map came from bounce_bus_dmamem_alloc, so the map
527          * should be NULL and the BF_KMEM_ALLOC flag cleared if malloc()
528          * was used and set if kmem_alloc_contig() was used.
529          */
530         if ((map->flags & DMAMAP_FROM_DMAMEM) == 0)
531                 panic("bus_dmamem_free: Invalid map freed\n");
532         if ((dmat->bounce_flags & BF_KMEM_ALLOC) == 0)
533                 free(vaddr, M_DEVBUF);
534         else
535                 kmem_free((vm_offset_t)vaddr, dmat->common.maxsize);
536         free(map, M_DEVBUF);
537         dmat->map_count--;
538         CTR3(KTR_BUSDMA, "%s: tag %p flags 0x%x", __func__, dmat,
539             dmat->bounce_flags);
540 }
541
542 static void
543 _bus_dmamap_count_phys(bus_dma_tag_t dmat, bus_dmamap_t map, vm_paddr_t buf,
544     bus_size_t buflen, int flags)
545 {
546         bus_addr_t curaddr;
547         bus_size_t sgsize;
548
549         if ((map->flags & DMAMAP_COULD_BOUNCE) != 0 && map->pagesneeded == 0) {
550                 /*
551                  * Count the number of bounce pages
552                  * needed in order to complete this transfer
553                  */
554                 curaddr = buf;
555                 while (buflen != 0) {
556                         sgsize = MIN(buflen, dmat->common.maxsegsz);
557                         if (bus_dma_run_filter(&dmat->common, curaddr)) {
558                                 sgsize = MIN(sgsize,
559                                     PAGE_SIZE - (curaddr & PAGE_MASK));
560                                 map->pagesneeded++;
561                         }
562                         curaddr += sgsize;
563                         buflen -= sgsize;
564                 }
565                 CTR1(KTR_BUSDMA, "pagesneeded= %d\n", map->pagesneeded);
566         }
567 }
568
569 static void
570 _bus_dmamap_count_pages(bus_dma_tag_t dmat, bus_dmamap_t map, pmap_t pmap,
571     void *buf, bus_size_t buflen, int flags)
572 {
573         vm_offset_t vaddr;
574         vm_offset_t vendaddr;
575         bus_addr_t paddr;
576         bus_size_t sg_len;
577
578         if ((map->flags & DMAMAP_COULD_BOUNCE) != 0 && map->pagesneeded == 0) {
579                 CTR4(KTR_BUSDMA, "lowaddr= %d Maxmem= %d, boundary= %d, "
580                     "alignment= %d", dmat->common.lowaddr,
581                     ptoa((vm_paddr_t)Maxmem),
582                     dmat->common.boundary, dmat->common.alignment);
583                 CTR2(KTR_BUSDMA, "map= %p, pagesneeded= %d", map,
584                     map->pagesneeded);
585                 /*
586                  * Count the number of bounce pages
587                  * needed in order to complete this transfer
588                  */
589                 vaddr = (vm_offset_t)buf;
590                 vendaddr = (vm_offset_t)buf + buflen;
591
592                 while (vaddr < vendaddr) {
593                         sg_len = PAGE_SIZE - ((vm_offset_t)vaddr & PAGE_MASK);
594                         if (pmap == kernel_pmap)
595                                 paddr = pmap_kextract(vaddr);
596                         else
597                                 paddr = pmap_extract(pmap, vaddr);
598                         if (bus_dma_run_filter(&dmat->common, paddr) != 0) {
599                                 sg_len = roundup2(sg_len,
600                                     dmat->common.alignment);
601                                 map->pagesneeded++;
602                         }
603                         vaddr += sg_len;
604                 }
605                 CTR1(KTR_BUSDMA, "pagesneeded= %d\n", map->pagesneeded);
606         }
607 }
608
609 static int
610 _bus_dmamap_reserve_pages(bus_dma_tag_t dmat, bus_dmamap_t map, int flags)
611 {
612
613         /* Reserve Necessary Bounce Pages */
614         mtx_lock(&bounce_lock);
615         if (flags & BUS_DMA_NOWAIT) {
616                 if (reserve_bounce_pages(dmat, map, 0) != 0) {
617                         mtx_unlock(&bounce_lock);
618                         return (ENOMEM);
619                 }
620         } else {
621                 if (reserve_bounce_pages(dmat, map, 1) != 0) {
622                         /* Queue us for resources */
623                         STAILQ_INSERT_TAIL(&bounce_map_waitinglist, map, links);
624                         mtx_unlock(&bounce_lock);
625                         return (EINPROGRESS);
626                 }
627         }
628         mtx_unlock(&bounce_lock);
629
630         return (0);
631 }
632
633 /*
634  * Add a single contiguous physical range to the segment list.
635  */
636 static bus_size_t
637 _bus_dmamap_addseg(bus_dma_tag_t dmat, bus_dmamap_t map, bus_addr_t curaddr,
638     bus_size_t sgsize, bus_dma_segment_t *segs, int *segp)
639 {
640         bus_addr_t baddr, bmask;
641         int seg;
642
643         /*
644          * Make sure we don't cross any boundaries.
645          */
646         bmask = ~(dmat->common.boundary - 1);
647         if (dmat->common.boundary > 0) {
648                 baddr = (curaddr + dmat->common.boundary) & bmask;
649                 if (sgsize > (baddr - curaddr))
650                         sgsize = (baddr - curaddr);
651         }
652
653         /*
654          * Insert chunk into a segment, coalescing with
655          * previous segment if possible.
656          */
657         seg = *segp;
658         if (seg == -1) {
659                 seg = 0;
660                 segs[seg].ds_addr = curaddr;
661                 segs[seg].ds_len = sgsize;
662         } else {
663                 if (curaddr == segs[seg].ds_addr + segs[seg].ds_len &&
664                     (segs[seg].ds_len + sgsize) <= dmat->common.maxsegsz &&
665                     (dmat->common.boundary == 0 ||
666                      (segs[seg].ds_addr & bmask) == (curaddr & bmask)))
667                         segs[seg].ds_len += sgsize;
668                 else {
669                         if (++seg >= dmat->common.nsegments)
670                                 return (0);
671                         segs[seg].ds_addr = curaddr;
672                         segs[seg].ds_len = sgsize;
673                 }
674         }
675         *segp = seg;
676         return (sgsize);
677 }
678
679 /*
680  * Utility function to load a physical buffer.  segp contains
681  * the starting segment on entrace, and the ending segment on exit.
682  */
683 static int
684 bounce_bus_dmamap_load_phys(bus_dma_tag_t dmat, bus_dmamap_t map,
685     vm_paddr_t buf, bus_size_t buflen, int flags, bus_dma_segment_t *segs,
686     int *segp)
687 {
688         struct sync_list *sl;
689         bus_size_t sgsize;
690         bus_addr_t curaddr, sl_end;
691         int error;
692
693         if (segs == NULL)
694                 segs = dmat->segments;
695
696         if ((dmat->bounce_flags & BF_COULD_BOUNCE) != 0) {
697                 _bus_dmamap_count_phys(dmat, map, buf, buflen, flags);
698                 if (map->pagesneeded != 0) {
699                         error = _bus_dmamap_reserve_pages(dmat, map, flags);
700                         if (error)
701                                 return (error);
702                 }
703         }
704
705         sl = map->slist + map->sync_count - 1;
706         sl_end = 0;
707
708         while (buflen > 0) {
709                 curaddr = buf;
710                 sgsize = MIN(buflen, dmat->common.maxsegsz);
711                 if (((dmat->bounce_flags & BF_COULD_BOUNCE) != 0) &&
712                     map->pagesneeded != 0 &&
713                     bus_dma_run_filter(&dmat->common, curaddr)) {
714                         sgsize = MIN(sgsize, PAGE_SIZE - (curaddr & PAGE_MASK));
715                         curaddr = add_bounce_page(dmat, map, 0, curaddr,
716                             sgsize);
717                 } else if ((dmat->bounce_flags & BF_COHERENT) == 0) {
718                         if (map->sync_count > 0)
719                                 sl_end = sl->paddr + sl->datacount;
720
721                         if (map->sync_count == 0 || curaddr != sl_end) {
722                                 if (++map->sync_count > dmat->common.nsegments)
723                                         break;
724                                 sl++;
725                                 sl->vaddr = 0;
726                                 sl->paddr = curaddr;
727                                 sl->datacount = sgsize;
728                                 sl->pages = PHYS_TO_VM_PAGE(curaddr);
729                                 KASSERT(sl->pages != NULL,
730                                     ("%s: page at PA:0x%08lx is not in "
731                                     "vm_page_array", __func__, curaddr));
732                         } else
733                                 sl->datacount += sgsize;
734                 }
735                 sgsize = _bus_dmamap_addseg(dmat, map, curaddr, sgsize, segs,
736                     segp);
737                 if (sgsize == 0)
738                         break;
739                 buf += sgsize;
740                 buflen -= sgsize;
741         }
742
743         /*
744          * Did we fit?
745          */
746         return (buflen != 0 ? EFBIG : 0); /* XXX better return value here? */
747 }
748
749 /*
750  * Utility function to load a linear buffer.  segp contains
751  * the starting segment on entrace, and the ending segment on exit.
752  */
753 static int
754 bounce_bus_dmamap_load_buffer(bus_dma_tag_t dmat, bus_dmamap_t map, void *buf,
755     bus_size_t buflen, pmap_t pmap, int flags, bus_dma_segment_t *segs,
756     int *segp)
757 {
758         struct sync_list *sl;
759         bus_size_t sgsize, max_sgsize;
760         bus_addr_t curaddr, sl_pend;
761         vm_offset_t kvaddr, vaddr, sl_vend;
762         int error;
763
764         if (segs == NULL)
765                 segs = dmat->segments;
766
767         if ((dmat->bounce_flags & BF_COULD_BOUNCE) != 0) {
768                 _bus_dmamap_count_pages(dmat, map, pmap, buf, buflen, flags);
769                 if (map->pagesneeded != 0) {
770                         error = _bus_dmamap_reserve_pages(dmat, map, flags);
771                         if (error)
772                                 return (error);
773                 }
774         }
775
776         sl = map->slist + map->sync_count - 1;
777         vaddr = (vm_offset_t)buf;
778         sl_pend = 0;
779         sl_vend = 0;
780
781         while (buflen > 0) {
782                 /*
783                  * Get the physical address for this segment.
784                  */
785                 if (pmap == kernel_pmap) {
786                         curaddr = pmap_kextract(vaddr);
787                         kvaddr = vaddr;
788                 } else {
789                         curaddr = pmap_extract(pmap, vaddr);
790                         kvaddr = 0;
791                 }
792
793                 /*
794                  * Compute the segment size, and adjust counts.
795                  */
796                 max_sgsize = MIN(buflen, dmat->common.maxsegsz);
797                 sgsize = PAGE_SIZE - (curaddr & PAGE_MASK);
798                 if (((dmat->bounce_flags & BF_COULD_BOUNCE) != 0) &&
799                     map->pagesneeded != 0 &&
800                     bus_dma_run_filter(&dmat->common, curaddr)) {
801                         sgsize = roundup2(sgsize, dmat->common.alignment);
802                         sgsize = MIN(sgsize, max_sgsize);
803                         curaddr = add_bounce_page(dmat, map, kvaddr, curaddr,
804                             sgsize);
805                 } else if ((dmat->bounce_flags & BF_COHERENT) == 0) {
806                         sgsize = MIN(sgsize, max_sgsize);
807                         if (map->sync_count > 0) {
808                                 sl_pend = sl->paddr + sl->datacount;
809                                 sl_vend = sl->vaddr + sl->datacount;
810                         }
811
812                         if (map->sync_count == 0 ||
813                             (kvaddr != 0 && kvaddr != sl_vend) ||
814                             (curaddr != sl_pend)) {
815                                 if (++map->sync_count > dmat->common.nsegments)
816                                         goto cleanup;
817                                 sl++;
818                                 sl->vaddr = kvaddr;
819                                 sl->paddr = curaddr;
820                                 if (kvaddr != 0) {
821                                         sl->pages = NULL;
822                                 } else {
823                                         sl->pages = PHYS_TO_VM_PAGE(curaddr);
824                                         KASSERT(sl->pages != NULL,
825                                             ("%s: page at PA:0x%08lx is not "
826                                             "in vm_page_array", __func__,
827                                             curaddr));
828                                 }
829                                 sl->datacount = sgsize;
830                         } else
831                                 sl->datacount += sgsize;
832                 } else {
833                         sgsize = MIN(sgsize, max_sgsize);
834                 }
835                 sgsize = _bus_dmamap_addseg(dmat, map, curaddr, sgsize, segs,
836                     segp);
837                 if (sgsize == 0)
838                         break;
839                 vaddr += sgsize;
840                 buflen -= sgsize;
841         }
842
843 cleanup:
844         /*
845          * Did we fit?
846          */
847         return (buflen != 0 ? EFBIG : 0); /* XXX better return value here? */
848 }
849
850 static void
851 bounce_bus_dmamap_waitok(bus_dma_tag_t dmat, bus_dmamap_t map,
852     struct memdesc *mem, bus_dmamap_callback_t *callback, void *callback_arg)
853 {
854
855         if ((map->flags & DMAMAP_COULD_BOUNCE) == 0)
856                 return;
857         map->mem = *mem;
858         map->dmat = dmat;
859         map->callback = callback;
860         map->callback_arg = callback_arg;
861 }
862
863 static bus_dma_segment_t *
864 bounce_bus_dmamap_complete(bus_dma_tag_t dmat, bus_dmamap_t map,
865     bus_dma_segment_t *segs, int nsegs, int error)
866 {
867
868         if (segs == NULL)
869                 segs = dmat->segments;
870         return (segs);
871 }
872
873 /*
874  * Release the mapping held by map.
875  */
876 static void
877 bounce_bus_dmamap_unload(bus_dma_tag_t dmat, bus_dmamap_t map)
878 {
879         struct bounce_page *bpage;
880
881         while ((bpage = STAILQ_FIRST(&map->bpages)) != NULL) {
882                 STAILQ_REMOVE_HEAD(&map->bpages, links);
883                 free_bounce_page(dmat, bpage);
884         }
885
886         map->sync_count = 0;
887 }
888
889 static void
890 dma_preread_safe(vm_offset_t va, vm_size_t size)
891 {
892         /*
893          * Write back any partial cachelines immediately before and
894          * after the DMA region.
895          */
896         if (va & (dcache_line_size - 1))
897                 cpu_dcache_wb_range(va, 1);
898         if ((va + size) & (dcache_line_size - 1))
899                 cpu_dcache_wb_range(va + size, 1);
900
901         cpu_dcache_inv_range(va, size);
902 }
903
904 static void
905 dma_dcache_sync(struct sync_list *sl, bus_dmasync_op_t op)
906 {
907         uint32_t len, offset;
908         vm_page_t m;
909         vm_paddr_t pa;
910         vm_offset_t va, tempva;
911         bus_size_t size;
912
913         offset = sl->paddr & PAGE_MASK;
914         m = sl->pages;
915         size = sl->datacount;
916         pa = sl->paddr;
917
918         for ( ; size != 0; size -= len, pa += len, offset = 0, ++m) {
919                 tempva = 0;
920                 if (sl->vaddr == 0) {
921                         len = min(PAGE_SIZE - offset, size);
922                         tempva = pmap_quick_enter_page(m);
923                         va = tempva | offset;
924                         KASSERT(pa == (VM_PAGE_TO_PHYS(m) | offset),
925                             ("unexpected vm_page_t phys: 0x%16lx != 0x%16lx",
926                             VM_PAGE_TO_PHYS(m) | offset, pa));
927                 } else {
928                         len = sl->datacount;
929                         va = sl->vaddr;
930                 }
931
932                 switch (op) {
933                 case BUS_DMASYNC_PREWRITE:
934                 case BUS_DMASYNC_PREWRITE | BUS_DMASYNC_PREREAD:
935                         cpu_dcache_wb_range(va, len);
936                         break;
937                 case BUS_DMASYNC_PREREAD:
938                         /*
939                          * An mbuf may start in the middle of a cacheline. There
940                          * will be no cpu writes to the beginning of that line
941                          * (which contains the mbuf header) while dma is in
942                          * progress.  Handle that case by doing a writeback of
943                          * just the first cacheline before invalidating the
944                          * overall buffer.  Any mbuf in a chain may have this
945                          * misalignment.  Buffers which are not mbufs bounce if
946                          * they are not aligned to a cacheline.
947                          */
948                         dma_preread_safe(va, len);
949                         break;
950                 case BUS_DMASYNC_POSTREAD:
951                 case BUS_DMASYNC_POSTREAD | BUS_DMASYNC_POSTWRITE:
952                         cpu_dcache_inv_range(va, len);
953                         break;
954                 default:
955                         panic("unsupported combination of sync operations: "
956                               "0x%08x\n", op);
957                 }
958
959                 if (tempva != 0)
960                         pmap_quick_remove_page(tempva);
961         }
962 }
963
964 static void
965 bounce_bus_dmamap_sync(bus_dma_tag_t dmat, bus_dmamap_t map,
966     bus_dmasync_op_t op)
967 {
968         struct bounce_page *bpage;
969         struct sync_list *sl, *end;
970         vm_offset_t datavaddr, tempvaddr;
971
972         if (op == BUS_DMASYNC_POSTWRITE)
973                 return;
974
975         if ((op & BUS_DMASYNC_POSTREAD) != 0) {
976                 /*
977                  * Wait for any DMA operations to complete before the bcopy.
978                  */
979                 fence();
980         }
981
982         if ((bpage = STAILQ_FIRST(&map->bpages)) != NULL) {
983                 CTR4(KTR_BUSDMA, "%s: tag %p tag flags 0x%x op 0x%x "
984                     "performing bounce", __func__, dmat, dmat->common.flags,
985                     op);
986
987                 if ((op & BUS_DMASYNC_PREWRITE) != 0) {
988                         while (bpage != NULL) {
989                                 tempvaddr = 0;
990                                 datavaddr = bpage->datavaddr;
991                                 if (datavaddr == 0) {
992                                         tempvaddr = pmap_quick_enter_page(
993                                             bpage->datapage);
994                                         datavaddr = tempvaddr | bpage->dataoffs;
995                                 }
996
997                                 bcopy((void *)datavaddr,
998                                     (void *)bpage->vaddr, bpage->datacount);
999                                 if (tempvaddr != 0)
1000                                         pmap_quick_remove_page(tempvaddr);
1001                                 if ((dmat->bounce_flags & BF_COHERENT) == 0)
1002                                         cpu_dcache_wb_range(bpage->vaddr,
1003                                             bpage->datacount);
1004                                 bpage = STAILQ_NEXT(bpage, links);
1005                         }
1006                         dmat->bounce_zone->total_bounced++;
1007                 } else if ((op & BUS_DMASYNC_PREREAD) != 0) {
1008                         while (bpage != NULL) {
1009                                 if ((dmat->bounce_flags & BF_COHERENT) == 0)
1010                                         cpu_dcache_wbinv_range(bpage->vaddr,
1011                                             bpage->datacount);
1012                                 bpage = STAILQ_NEXT(bpage, links);
1013                         }
1014                 }
1015
1016                 if ((op & BUS_DMASYNC_POSTREAD) != 0) {
1017                         while (bpage != NULL) {
1018                                 if ((dmat->bounce_flags & BF_COHERENT) == 0)
1019                                         cpu_dcache_inv_range(bpage->vaddr,
1020                                             bpage->datacount);
1021                                 tempvaddr = 0;
1022                                 datavaddr = bpage->datavaddr;
1023                                 if (datavaddr == 0) {
1024                                         tempvaddr = pmap_quick_enter_page(
1025                                             bpage->datapage);
1026                                         datavaddr = tempvaddr | bpage->dataoffs;
1027                                 }
1028
1029                                 bcopy((void *)bpage->vaddr,
1030                                     (void *)datavaddr, bpage->datacount);
1031
1032                                 if (tempvaddr != 0)
1033                                         pmap_quick_remove_page(tempvaddr);
1034                                 bpage = STAILQ_NEXT(bpage, links);
1035                         }
1036                         dmat->bounce_zone->total_bounced++;
1037                 }
1038         }
1039
1040         /*
1041          * Cache maintenance for normal (non-COHERENT non-bounce) buffers.
1042          */
1043         if (map->sync_count != 0) {
1044                 sl = &map->slist[0];
1045                 end = &map->slist[map->sync_count];
1046                 CTR3(KTR_BUSDMA, "%s: tag %p op 0x%x "
1047                     "performing sync", __func__, dmat, op);
1048
1049                 for ( ; sl != end; ++sl)
1050                         dma_dcache_sync(sl, op);
1051         }
1052
1053         if ((op & (BUS_DMASYNC_PREREAD | BUS_DMASYNC_PREWRITE)) != 0) {
1054                 /*
1055                  * Wait for the bcopy to complete before any DMA operations.
1056                  */
1057                 fence();
1058         }
1059 }
1060
1061 static void
1062 init_bounce_pages(void *dummy __unused)
1063 {
1064
1065         total_bpages = 0;
1066         STAILQ_INIT(&bounce_zone_list);
1067         STAILQ_INIT(&bounce_map_waitinglist);
1068         STAILQ_INIT(&bounce_map_callbacklist);
1069         mtx_init(&bounce_lock, "bounce pages lock", NULL, MTX_DEF);
1070 }
1071 SYSINIT(bpages, SI_SUB_LOCK, SI_ORDER_ANY, init_bounce_pages, NULL);
1072
1073 static struct sysctl_ctx_list *
1074 busdma_sysctl_tree(struct bounce_zone *bz)
1075 {
1076
1077         return (&bz->sysctl_tree);
1078 }
1079
1080 static struct sysctl_oid *
1081 busdma_sysctl_tree_top(struct bounce_zone *bz)
1082 {
1083
1084         return (bz->sysctl_tree_top);
1085 }
1086
1087 static int
1088 alloc_bounce_zone(bus_dma_tag_t dmat)
1089 {
1090         struct bounce_zone *bz;
1091
1092         /* Check to see if we already have a suitable zone */
1093         STAILQ_FOREACH(bz, &bounce_zone_list, links) {
1094                 if ((dmat->common.alignment <= bz->alignment) &&
1095                     (dmat->common.lowaddr >= bz->lowaddr)) {
1096                         dmat->bounce_zone = bz;
1097                         return (0);
1098                 }
1099         }
1100
1101         if ((bz = (struct bounce_zone *)malloc(sizeof(*bz), M_DEVBUF,
1102             M_NOWAIT | M_ZERO)) == NULL)
1103                 return (ENOMEM);
1104
1105         STAILQ_INIT(&bz->bounce_page_list);
1106         bz->free_bpages = 0;
1107         bz->reserved_bpages = 0;
1108         bz->active_bpages = 0;
1109         bz->lowaddr = dmat->common.lowaddr;
1110         bz->alignment = MAX(dmat->common.alignment, PAGE_SIZE);
1111         bz->map_count = 0;
1112         snprintf(bz->zoneid, 8, "zone%d", busdma_zonecount);
1113         busdma_zonecount++;
1114         snprintf(bz->lowaddrid, 18, "%#jx", (uintmax_t)bz->lowaddr);
1115         STAILQ_INSERT_TAIL(&bounce_zone_list, bz, links);
1116         dmat->bounce_zone = bz;
1117
1118         sysctl_ctx_init(&bz->sysctl_tree);
1119         bz->sysctl_tree_top = SYSCTL_ADD_NODE(&bz->sysctl_tree,
1120             SYSCTL_STATIC_CHILDREN(_hw_busdma), OID_AUTO, bz->zoneid,
1121             CTLFLAG_RD | CTLFLAG_MPSAFE, 0, "");
1122         if (bz->sysctl_tree_top == NULL) {
1123                 sysctl_ctx_free(&bz->sysctl_tree);
1124                 return (0);     /* XXX error code? */
1125         }
1126
1127         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1128             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1129             "total_bpages", CTLFLAG_RD, &bz->total_bpages, 0,
1130             "Total bounce pages");
1131         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1132             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1133             "free_bpages", CTLFLAG_RD, &bz->free_bpages, 0,
1134             "Free bounce pages");
1135         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1136             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1137             "reserved_bpages", CTLFLAG_RD, &bz->reserved_bpages, 0,
1138             "Reserved bounce pages");
1139         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1140             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1141             "active_bpages", CTLFLAG_RD, &bz->active_bpages, 0,
1142             "Active bounce pages");
1143         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1144             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1145             "total_bounced", CTLFLAG_RD, &bz->total_bounced, 0,
1146             "Total bounce requests");
1147         SYSCTL_ADD_INT(busdma_sysctl_tree(bz),
1148             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1149             "total_deferred", CTLFLAG_RD, &bz->total_deferred, 0,
1150             "Total bounce requests that were deferred");
1151         SYSCTL_ADD_STRING(busdma_sysctl_tree(bz),
1152             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1153             "lowaddr", CTLFLAG_RD, bz->lowaddrid, 0, "");
1154         SYSCTL_ADD_UAUTO(busdma_sysctl_tree(bz),
1155             SYSCTL_CHILDREN(busdma_sysctl_tree_top(bz)), OID_AUTO,
1156             "alignment", CTLFLAG_RD, &bz->alignment, "");
1157
1158         return (0);
1159 }
1160
1161 static int
1162 alloc_bounce_pages(bus_dma_tag_t dmat, u_int numpages)
1163 {
1164         struct bounce_zone *bz;
1165         int count;
1166
1167         bz = dmat->bounce_zone;
1168         count = 0;
1169         while (numpages > 0) {
1170                 struct bounce_page *bpage;
1171
1172                 bpage = (struct bounce_page *)malloc(sizeof(*bpage), M_DEVBUF,
1173                                                      M_NOWAIT | M_ZERO);
1174
1175                 if (bpage == NULL)
1176                         break;
1177                 bpage->vaddr = (vm_offset_t)contigmalloc(PAGE_SIZE, M_DEVBUF,
1178                     M_NOWAIT, 0ul, bz->lowaddr, PAGE_SIZE, 0);
1179                 if (bpage->vaddr == 0) {
1180                         free(bpage, M_DEVBUF);
1181                         break;
1182                 }
1183                 bpage->busaddr = pmap_kextract(bpage->vaddr);
1184                 mtx_lock(&bounce_lock);
1185                 STAILQ_INSERT_TAIL(&bz->bounce_page_list, bpage, links);
1186                 total_bpages++;
1187                 bz->total_bpages++;
1188                 bz->free_bpages++;
1189                 mtx_unlock(&bounce_lock);
1190                 count++;
1191                 numpages--;
1192         }
1193         return (count);
1194 }
1195
1196 static int
1197 reserve_bounce_pages(bus_dma_tag_t dmat, bus_dmamap_t map, int commit)
1198 {
1199         struct bounce_zone *bz;
1200         int pages;
1201
1202         mtx_assert(&bounce_lock, MA_OWNED);
1203         bz = dmat->bounce_zone;
1204         pages = MIN(bz->free_bpages, map->pagesneeded - map->pagesreserved);
1205         if (commit == 0 && map->pagesneeded > (map->pagesreserved + pages))
1206                 return (map->pagesneeded - (map->pagesreserved + pages));
1207         bz->free_bpages -= pages;
1208         bz->reserved_bpages += pages;
1209         map->pagesreserved += pages;
1210         pages = map->pagesneeded - map->pagesreserved;
1211
1212         return (pages);
1213 }
1214
1215 static bus_addr_t
1216 add_bounce_page(bus_dma_tag_t dmat, bus_dmamap_t map, vm_offset_t vaddr,
1217                 bus_addr_t addr, bus_size_t size)
1218 {
1219         struct bounce_zone *bz;
1220         struct bounce_page *bpage;
1221
1222         KASSERT(dmat->bounce_zone != NULL, ("no bounce zone in dma tag"));
1223         KASSERT((map->flags & DMAMAP_COULD_BOUNCE) != 0,
1224             ("add_bounce_page: bad map %p", map));
1225
1226         bz = dmat->bounce_zone;
1227         if (map->pagesneeded == 0)
1228                 panic("add_bounce_page: map doesn't need any pages");
1229         map->pagesneeded--;
1230
1231         if (map->pagesreserved == 0)
1232                 panic("add_bounce_page: map doesn't need any pages");
1233         map->pagesreserved--;
1234
1235         mtx_lock(&bounce_lock);
1236         bpage = STAILQ_FIRST(&bz->bounce_page_list);
1237         if (bpage == NULL)
1238                 panic("add_bounce_page: free page list is empty");
1239
1240         STAILQ_REMOVE_HEAD(&bz->bounce_page_list, links);
1241         bz->reserved_bpages--;
1242         bz->active_bpages++;
1243         mtx_unlock(&bounce_lock);
1244
1245         if (dmat->common.flags & BUS_DMA_KEEP_PG_OFFSET) {
1246                 /* Page offset needs to be preserved. */
1247                 bpage->vaddr |= addr & PAGE_MASK;
1248                 bpage->busaddr |= addr & PAGE_MASK;
1249         }
1250         bpage->datavaddr = vaddr;
1251         bpage->datapage = PHYS_TO_VM_PAGE(addr);
1252         bpage->dataoffs = addr & PAGE_MASK;
1253         bpage->datacount = size;
1254         STAILQ_INSERT_TAIL(&(map->bpages), bpage, links);
1255         return (bpage->busaddr);
1256 }
1257
1258 static void
1259 free_bounce_page(bus_dma_tag_t dmat, struct bounce_page *bpage)
1260 {
1261         struct bus_dmamap *map;
1262         struct bounce_zone *bz;
1263
1264         bz = dmat->bounce_zone;
1265         bpage->datavaddr = 0;
1266         bpage->datacount = 0;
1267         if (dmat->common.flags & BUS_DMA_KEEP_PG_OFFSET) {
1268                 /*
1269                  * Reset the bounce page to start at offset 0.  Other uses
1270                  * of this bounce page may need to store a full page of
1271                  * data and/or assume it starts on a page boundary.
1272                  */
1273                 bpage->vaddr &= ~PAGE_MASK;
1274                 bpage->busaddr &= ~PAGE_MASK;
1275         }
1276
1277         mtx_lock(&bounce_lock);
1278         STAILQ_INSERT_HEAD(&bz->bounce_page_list, bpage, links);
1279         bz->free_bpages++;
1280         bz->active_bpages--;
1281         if ((map = STAILQ_FIRST(&bounce_map_waitinglist)) != NULL) {
1282                 if (reserve_bounce_pages(map->dmat, map, 1) == 0) {
1283                         STAILQ_REMOVE_HEAD(&bounce_map_waitinglist, links);
1284                         STAILQ_INSERT_TAIL(&bounce_map_callbacklist,
1285                             map, links);
1286                         busdma_swi_pending = 1;
1287                         bz->total_deferred++;
1288                         swi_sched(vm_ih, 0);
1289                 }
1290         }
1291         mtx_unlock(&bounce_lock);
1292 }
1293
1294 void
1295 busdma_swi(void)
1296 {
1297         bus_dma_tag_t dmat;
1298         struct bus_dmamap *map;
1299
1300         mtx_lock(&bounce_lock);
1301         while ((map = STAILQ_FIRST(&bounce_map_callbacklist)) != NULL) {
1302                 STAILQ_REMOVE_HEAD(&bounce_map_callbacklist, links);
1303                 mtx_unlock(&bounce_lock);
1304                 dmat = map->dmat;
1305                 (dmat->common.lockfunc)(dmat->common.lockfuncarg, BUS_DMA_LOCK);
1306                 bus_dmamap_load_mem(map->dmat, map, &map->mem,
1307                     map->callback, map->callback_arg, BUS_DMA_WAITOK);
1308                 (dmat->common.lockfunc)(dmat->common.lockfuncarg,
1309                     BUS_DMA_UNLOCK);
1310                 mtx_lock(&bounce_lock);
1311         }
1312         mtx_unlock(&bounce_lock);
1313 }
1314
1315 struct bus_dma_impl bus_dma_bounce_impl = {
1316         .tag_create = bounce_bus_dma_tag_create,
1317         .tag_destroy = bounce_bus_dma_tag_destroy,
1318         .map_create = bounce_bus_dmamap_create,
1319         .map_destroy = bounce_bus_dmamap_destroy,
1320         .mem_alloc = bounce_bus_dmamem_alloc,
1321         .mem_free = bounce_bus_dmamem_free,
1322         .load_phys = bounce_bus_dmamap_load_phys,
1323         .load_buffer = bounce_bus_dmamap_load_buffer,
1324         .load_ma = bus_dmamap_load_ma_triv,
1325         .map_waitok = bounce_bus_dmamap_waitok,
1326         .map_complete = bounce_bus_dmamap_complete,
1327         .map_unload = bounce_bus_dmamap_unload,
1328         .map_sync = bounce_bus_dmamap_sync
1329 };