2 * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
4 * Copyright (c) 2007-2009 Kip Macy <kmacy@freebsd.org>
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 #ifndef _SYS_BUF_RING_H_
33 #define _SYS_BUF_RING_H_
35 #include <machine/cpu.h>
39 #include <sys/mutex.h>
43 volatile uint32_t br_prod_head;
44 volatile uint32_t br_prod_tail;
48 volatile uint32_t br_cons_head __aligned(CACHE_LINE_SIZE);
49 volatile uint32_t br_cons_tail;
55 void *br_ring[0] __aligned(CACHE_LINE_SIZE);
59 * multi-producer safe lock-free ring buffer enqueue
63 buf_ring_enqueue(struct buf_ring *br, void *buf)
65 uint32_t prod_head, prod_next, cons_tail;
70 * Note: It is possible to encounter an mbuf that was removed
71 * via drbr_peek(), and then re-added via drbr_putback() and
72 * trigger a spurious panic.
74 for (i = br->br_cons_head; i != br->br_prod_head;
75 i = ((i + 1) & br->br_cons_mask))
76 if(br->br_ring[i] == buf)
77 panic("buf=%p already enqueue at %d prod=%d cons=%d",
78 buf, i, br->br_prod_tail, br->br_cons_tail);
82 prod_head = br->br_prod_head;
83 prod_next = (prod_head + 1) & br->br_prod_mask;
84 cons_tail = br->br_cons_tail;
86 if (prod_next == cons_tail) {
88 if (prod_head == br->br_prod_head &&
89 cons_tail == br->br_cons_tail) {
96 } while (!atomic_cmpset_acq_int(&br->br_prod_head, prod_head, prod_next));
98 if (br->br_ring[prod_head] != NULL)
99 panic("dangling value in enqueue");
101 br->br_ring[prod_head] = buf;
104 * If there are other enqueues in progress
105 * that preceded us, we need to wait for them
108 while (br->br_prod_tail != prod_head)
110 atomic_store_rel_int(&br->br_prod_tail, prod_next);
116 * multi-consumer safe dequeue
119 static __inline void *
120 buf_ring_dequeue_mc(struct buf_ring *br)
122 uint32_t cons_head, cons_next;
127 cons_head = br->br_cons_head;
128 cons_next = (cons_head + 1) & br->br_cons_mask;
130 if (cons_head == br->br_prod_tail) {
134 } while (!atomic_cmpset_acq_int(&br->br_cons_head, cons_head, cons_next));
136 buf = br->br_ring[cons_head];
138 br->br_ring[cons_head] = NULL;
141 * If there are other dequeues in progress
142 * that preceded us, we need to wait for them
145 while (br->br_cons_tail != cons_head)
148 atomic_store_rel_int(&br->br_cons_tail, cons_next);
155 * single-consumer dequeue
156 * use where dequeue is protected by a lock
157 * e.g. a network driver's tx queue lock
159 static __inline void *
160 buf_ring_dequeue_sc(struct buf_ring *br)
162 uint32_t cons_head, cons_next;
163 #ifdef PREFETCH_DEFINED
164 uint32_t cons_next_next;
170 * This is a workaround to allow using buf_ring on ARM and ARM64.
171 * ARM64TODO: Fix buf_ring in a generic way.
172 * REMARKS: It is suspected that br_cons_head does not require
173 * load_acq operation, but this change was extensively tested
174 * and confirmed it's working. To be reviewed once again in
177 * Preventing following situation:
179 * Core(0) - buf_ring_enqueue() Core(1) - buf_ring_dequeue_sc()
180 * ----------------------------------------- ----------------------------------------------
182 * cons_head = br->br_cons_head;
183 * atomic_cmpset_acq_32(&br->br_prod_head, ...));
184 * buf = br->br_ring[cons_head]; <see <1>>
185 * br->br_ring[prod_head] = buf;
186 * atomic_store_rel_32(&br->br_prod_tail, ...);
187 * prod_tail = br->br_prod_tail;
188 * if (cons_head == prod_tail)
190 * <condition is false and code uses invalid(old) buf>`
192 * <1> Load (on core 1) from br->br_ring[cons_head] can be reordered (speculative readed) by CPU.
194 #if defined(__arm__) || defined(__aarch64__)
195 cons_head = atomic_load_acq_32(&br->br_cons_head);
197 cons_head = br->br_cons_head;
199 prod_tail = atomic_load_acq_32(&br->br_prod_tail);
201 cons_next = (cons_head + 1) & br->br_cons_mask;
202 #ifdef PREFETCH_DEFINED
203 cons_next_next = (cons_head + 2) & br->br_cons_mask;
206 if (cons_head == prod_tail)
209 #ifdef PREFETCH_DEFINED
210 if (cons_next != prod_tail) {
211 prefetch(br->br_ring[cons_next]);
212 if (cons_next_next != prod_tail)
213 prefetch(br->br_ring[cons_next_next]);
216 br->br_cons_head = cons_next;
217 buf = br->br_ring[cons_head];
220 br->br_ring[cons_head] = NULL;
221 if (!mtx_owned(br->br_lock))
222 panic("lock not held on single consumer dequeue");
223 if (br->br_cons_tail != cons_head)
224 panic("inconsistent list cons_tail=%d cons_head=%d",
225 br->br_cons_tail, cons_head);
227 br->br_cons_tail = cons_next;
232 * single-consumer advance after a peek
233 * use where it is protected by a lock
234 * e.g. a network driver's tx queue lock
237 buf_ring_advance_sc(struct buf_ring *br)
239 uint32_t cons_head, cons_next;
242 cons_head = br->br_cons_head;
243 prod_tail = br->br_prod_tail;
245 cons_next = (cons_head + 1) & br->br_cons_mask;
246 if (cons_head == prod_tail)
248 br->br_cons_head = cons_next;
250 br->br_ring[cons_head] = NULL;
252 br->br_cons_tail = cons_next;
256 * Used to return a buffer (most likely already there)
257 * to the top of the ring. The caller should *not*
258 * have used any dequeue to pull it out of the ring
259 * but instead should have used the peek() function.
260 * This is normally used where the transmit queue
261 * of a driver is full, and an mbuf must be returned.
262 * Most likely whats in the ring-buffer is what
263 * is being put back (since it was not removed), but
264 * sometimes the lower transmit function may have
265 * done a pullup or other function that will have
266 * changed it. As an optimization we always put it
267 * back (since jhb says the store is probably cheaper),
268 * if we have to do a multi-queue version we will need
269 * the compare and an atomic.
272 buf_ring_putback_sc(struct buf_ring *br, void *new)
274 KASSERT(br->br_cons_head != br->br_prod_tail,
275 ("Buf-Ring has none in putback")) ;
276 br->br_ring[br->br_cons_head] = new;
280 * return a pointer to the first entry in the ring
281 * without modifying it, or NULL if the ring is empty
282 * race-prone if not protected by a lock
284 static __inline void *
285 buf_ring_peek(struct buf_ring *br)
289 if ((br->br_lock != NULL) && !mtx_owned(br->br_lock))
290 panic("lock not held on single consumer dequeue");
293 * I believe it is safe to not have a memory barrier
294 * here because we control cons and tail is worst case
295 * a lagging indicator so we worst case we might
296 * return NULL immediately after a buffer has been enqueued
298 if (br->br_cons_head == br->br_prod_tail)
301 return (br->br_ring[br->br_cons_head]);
304 static __inline void *
305 buf_ring_peek_clear_sc(struct buf_ring *br)
310 if (!mtx_owned(br->br_lock))
311 panic("lock not held on single consumer dequeue");
314 if (br->br_cons_head == br->br_prod_tail)
317 #if defined(__arm__) || defined(__aarch64__)
319 * The barrier is required there on ARM and ARM64 to ensure, that
320 * br->br_ring[br->br_cons_head] will not be fetched before the above
321 * condition is checked.
322 * Without the barrier, it is possible, that buffer will be fetched
323 * before the enqueue will put mbuf into br, then, in the meantime, the
324 * enqueue will update the array and the br_prod_tail, and the
325 * conditional check will be true, so we will return previously fetched
326 * (and invalid) buffer.
328 atomic_thread_fence_acq();
333 * Single consumer, i.e. cons_head will not move while we are
334 * running, so atomic_swap_ptr() is not necessary here.
336 ret = br->br_ring[br->br_cons_head];
337 br->br_ring[br->br_cons_head] = NULL;
340 return (br->br_ring[br->br_cons_head]);
345 buf_ring_full(struct buf_ring *br)
348 return (((br->br_prod_head + 1) & br->br_prod_mask) == br->br_cons_tail);
352 buf_ring_empty(struct buf_ring *br)
355 return (br->br_cons_head == br->br_prod_tail);
359 buf_ring_count(struct buf_ring *br)
362 return ((br->br_prod_size + br->br_prod_tail - br->br_cons_tail)
366 struct buf_ring *buf_ring_alloc(int count, struct malloc_type *type, int flags,
368 void buf_ring_free(struct buf_ring *br, struct malloc_type *type);