xref: /freebsd-14.2/sys/vm/vm_kern.c (revision bdbb0be0)
1 /*-
2  * SPDX-License-Identifier: (BSD-3-Clause AND MIT-CMU)
3  *
4  * Copyright (c) 1991, 1993
5  *	The Regents of the University of California.  All rights reserved.
6  *
7  * This code is derived from software contributed to Berkeley by
8  * The Mach Operating System project at Carnegie-Mellon University.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  * 3. Neither the name of the University nor the names of its contributors
19  *    may be used to endorse or promote products derived from this software
20  *    without specific prior written permission.
21  *
22  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32  * SUCH DAMAGE.
33  *
34  *	from: @(#)vm_kern.c	8.3 (Berkeley) 1/12/94
35  *
36  *
37  * Copyright (c) 1987, 1990 Carnegie-Mellon University.
38  * All rights reserved.
39  *
40  * Authors: Avadis Tevanian, Jr., Michael Wayne Young
41  *
42  * Permission to use, copy, modify and distribute this software and
43  * its documentation is hereby granted, provided that both the copyright
44  * notice and this permission notice appear in all copies of the
45  * software, derivative works or modified versions, and any portions
46  * thereof, and that both notices appear in supporting documentation.
47  *
48  * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
49  * CONDITION.  CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND
50  * FOR ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
51  *
52  * Carnegie Mellon requests users of this software to return to
53  *
54  *  Software Distribution Coordinator  or  [email protected]
55  *  School of Computer Science
56  *  Carnegie Mellon University
57  *  Pittsburgh PA 15213-3890
58  *
59  * any improvements or extensions that they make and grant Carnegie the
60  * rights to redistribute these changes.
61  */
62 
63 /*
64  *	Kernel memory management.
65  */
66 
67 #include <sys/cdefs.h>
68 #include "opt_vm.h"
69 
70 #include <sys/param.h>
71 #include <sys/systm.h>
72 #include <sys/asan.h>
73 #include <sys/domainset.h>
74 #include <sys/eventhandler.h>
75 #include <sys/kernel.h>
76 #include <sys/lock.h>
77 #include <sys/malloc.h>
78 #include <sys/msan.h>
79 #include <sys/proc.h>
80 #include <sys/rwlock.h>
81 #include <sys/smp.h>
82 #include <sys/sysctl.h>
83 #include <sys/vmem.h>
84 #include <sys/vmmeter.h>
85 
86 #include <vm/vm.h>
87 #include <vm/vm_param.h>
88 #include <vm/vm_domainset.h>
89 #include <vm/vm_kern.h>
90 #include <vm/pmap.h>
91 #include <vm/vm_map.h>
92 #include <vm/vm_object.h>
93 #include <vm/vm_page.h>
94 #include <vm/vm_pageout.h>
95 #include <vm/vm_pagequeue.h>
96 #include <vm/vm_phys.h>
97 #include <vm/vm_radix.h>
98 #include <vm/vm_extern.h>
99 #include <vm/uma.h>
100 
101 struct vm_map kernel_map_store;
102 struct vm_map exec_map_store;
103 struct vm_map pipe_map_store;
104 
105 const void *zero_region;
106 CTASSERT((ZERO_REGION_SIZE & PAGE_MASK) == 0);
107 
108 /* NB: Used by kernel debuggers. */
109 const u_long vm_maxuser_address = VM_MAXUSER_ADDRESS;
110 
111 u_int exec_map_entry_size;
112 u_int exec_map_entries;
113 
114 SYSCTL_ULONG(_vm, OID_AUTO, min_kernel_address, CTLFLAG_RD,
115     SYSCTL_NULL_ULONG_PTR, VM_MIN_KERNEL_ADDRESS, "Min kernel address");
116 
117 SYSCTL_ULONG(_vm, OID_AUTO, max_kernel_address, CTLFLAG_RD,
118 #if defined(__arm__)
119     &vm_max_kernel_address, 0,
120 #else
121     SYSCTL_NULL_ULONG_PTR, VM_MAX_KERNEL_ADDRESS,
122 #endif
123     "Max kernel address");
124 
125 #if VM_NRESERVLEVEL > 0
126 #define	KVA_QUANTUM_SHIFT	(VM_LEVEL_0_ORDER + PAGE_SHIFT)
127 #else
128 /* On non-superpage architectures we want large import sizes. */
129 #define	KVA_QUANTUM_SHIFT	(8 + PAGE_SHIFT)
130 #endif
131 #define	KVA_QUANTUM		(1ul << KVA_QUANTUM_SHIFT)
132 #define	KVA_NUMA_IMPORT_QUANTUM	(KVA_QUANTUM * 128)
133 
134 extern void     uma_startup2(void);
135 
136 /*
137  *	kva_alloc:
138  *
139  *	Allocate a virtual address range with no underlying object and
140  *	no initial mapping to physical memory.  Any mapping from this
141  *	range to physical memory must be explicitly created prior to
142  *	its use, typically with pmap_qenter().  Any attempt to create
143  *	a mapping on demand through vm_fault() will result in a panic.
144  */
145 vm_offset_t
kva_alloc(vm_size_t size)146 kva_alloc(vm_size_t size)
147 {
148 	vm_offset_t addr;
149 
150 	TSENTER();
151 	size = round_page(size);
152 	if (vmem_xalloc(kernel_arena, size, 0, 0, 0, VMEM_ADDR_MIN,
153 	    VMEM_ADDR_MAX, M_BESTFIT | M_NOWAIT, &addr))
154 		return (0);
155 	TSEXIT();
156 
157 	return (addr);
158 }
159 
160 /*
161  *	kva_alloc_aligned:
162  *
163  *	Allocate a virtual address range as in kva_alloc where the base
164  *	address is aligned to align.
165  */
166 vm_offset_t
kva_alloc_aligned(vm_size_t size,vm_size_t align)167 kva_alloc_aligned(vm_size_t size, vm_size_t align)
168 {
169 	vm_offset_t addr;
170 
171 	TSENTER();
172 	size = round_page(size);
173 	if (vmem_xalloc(kernel_arena, size, align, 0, 0, VMEM_ADDR_MIN,
174 	    VMEM_ADDR_MAX, M_BESTFIT | M_NOWAIT, &addr))
175 		return (0);
176 	TSEXIT();
177 
178 	return (addr);
179 }
180 
181 /*
182  *	kva_free:
183  *
184  *	Release a region of kernel virtual memory allocated
185  *	with kva_alloc, and return the physical pages
186  *	associated with that region.
187  *
188  *	This routine may not block on kernel maps.
189  */
190 void
kva_free(vm_offset_t addr,vm_size_t size)191 kva_free(vm_offset_t addr, vm_size_t size)
192 {
193 
194 	size = round_page(size);
195 	vmem_xfree(kernel_arena, addr, size);
196 }
197 
198 /*
199  * Update sanitizer shadow state to reflect a new allocation.  Force inlining to
200  * help make KMSAN origin tracking more precise.
201  */
202 static __always_inline void
kmem_alloc_san(vm_offset_t addr,vm_size_t size,vm_size_t asize,int flags)203 kmem_alloc_san(vm_offset_t addr, vm_size_t size, vm_size_t asize, int flags)
204 {
205 	if ((flags & M_ZERO) == 0) {
206 		kmsan_mark((void *)addr, asize, KMSAN_STATE_UNINIT);
207 		kmsan_orig((void *)addr, asize, KMSAN_TYPE_KMEM,
208 		    KMSAN_RET_ADDR);
209 	} else {
210 		kmsan_mark((void *)addr, asize, KMSAN_STATE_INITED);
211 	}
212 	kasan_mark((void *)addr, size, asize, KASAN_KMEM_REDZONE);
213 }
214 
215 static vm_page_t
kmem_alloc_contig_pages(vm_object_t object,vm_pindex_t pindex,int domain,int pflags,u_long npages,vm_paddr_t low,vm_paddr_t high,u_long alignment,vm_paddr_t boundary,vm_memattr_t memattr)216 kmem_alloc_contig_pages(vm_object_t object, vm_pindex_t pindex, int domain,
217     int pflags, u_long npages, vm_paddr_t low, vm_paddr_t high,
218     u_long alignment, vm_paddr_t boundary, vm_memattr_t memattr)
219 {
220 	vm_page_t m;
221 	int tries;
222 	bool wait, reclaim;
223 
224 	VM_OBJECT_ASSERT_WLOCKED(object);
225 
226 	wait = (pflags & VM_ALLOC_WAITOK) != 0;
227 	reclaim = (pflags & VM_ALLOC_NORECLAIM) == 0;
228 	pflags &= ~(VM_ALLOC_NOWAIT | VM_ALLOC_WAITOK | VM_ALLOC_WAITFAIL);
229 	pflags |= VM_ALLOC_NOWAIT;
230 	for (tries = wait ? 3 : 1;; tries--) {
231 		m = vm_page_alloc_contig_domain(object, pindex, domain, pflags,
232 		    npages, low, high, alignment, boundary, memattr);
233 		if (m != NULL || tries == 0 || !reclaim)
234 			break;
235 
236 		VM_OBJECT_WUNLOCK(object);
237 		if (!vm_page_reclaim_contig_domain(domain, pflags, npages,
238 		    low, high, alignment, boundary) && wait)
239 			vm_wait_domain(domain);
240 		VM_OBJECT_WLOCK(object);
241 	}
242 	return (m);
243 }
244 
245 /*
246  *	Allocates a region from the kernel address map and physical pages
247  *	within the specified address range to the kernel object.  Creates a
248  *	wired mapping from this region to these pages, and returns the
249  *	region's starting virtual address.  The allocated pages are not
250  *	necessarily physically contiguous.  If M_ZERO is specified through the
251  *	given flags, then the pages are zeroed before they are mapped.
252  */
253 static void *
kmem_alloc_attr_domain(int domain,vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,vm_memattr_t memattr)254 kmem_alloc_attr_domain(int domain, vm_size_t size, int flags, vm_paddr_t low,
255     vm_paddr_t high, vm_memattr_t memattr)
256 {
257 	vmem_t *vmem;
258 	vm_object_t object;
259 	vm_offset_t addr, i, offset;
260 	vm_page_t m;
261 	vm_size_t asize;
262 	int pflags;
263 	vm_prot_t prot;
264 
265 	object = kernel_object;
266 	asize = round_page(size);
267 	vmem = vm_dom[domain].vmd_kernel_arena;
268 	if (vmem_alloc(vmem, asize, M_BESTFIT | flags, &addr))
269 		return (0);
270 	offset = addr - VM_MIN_KERNEL_ADDRESS;
271 	pflags = malloc2vm_flags(flags) | VM_ALLOC_WIRED;
272 	prot = (flags & M_EXEC) != 0 ? VM_PROT_ALL : VM_PROT_RW;
273 	VM_OBJECT_WLOCK(object);
274 	for (i = 0; i < asize; i += PAGE_SIZE) {
275 		m = kmem_alloc_contig_pages(object, atop(offset + i),
276 		    domain, pflags, 1, low, high, PAGE_SIZE, 0, memattr);
277 		if (m == NULL) {
278 			VM_OBJECT_WUNLOCK(object);
279 			kmem_unback(object, addr, i);
280 			vmem_free(vmem, addr, asize);
281 			return (0);
282 		}
283 		KASSERT(vm_page_domain(m) == domain,
284 		    ("kmem_alloc_attr_domain: Domain mismatch %d != %d",
285 		    vm_page_domain(m), domain));
286 		if ((flags & M_ZERO) && (m->flags & PG_ZERO) == 0)
287 			pmap_zero_page(m);
288 		vm_page_valid(m);
289 		pmap_enter(kernel_pmap, addr + i, m, prot,
290 		    prot | PMAP_ENTER_WIRED, 0);
291 	}
292 	VM_OBJECT_WUNLOCK(object);
293 	kmem_alloc_san(addr, size, asize, flags);
294 	return ((void *)addr);
295 }
296 
297 void *
kmem_alloc_attr(vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,vm_memattr_t memattr)298 kmem_alloc_attr(vm_size_t size, int flags, vm_paddr_t low, vm_paddr_t high,
299     vm_memattr_t memattr)
300 {
301 
302 	return (kmem_alloc_attr_domainset(DOMAINSET_RR(), size, flags, low,
303 	    high, memattr));
304 }
305 
306 void *
kmem_alloc_attr_domainset(struct domainset * ds,vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,vm_memattr_t memattr)307 kmem_alloc_attr_domainset(struct domainset *ds, vm_size_t size, int flags,
308     vm_paddr_t low, vm_paddr_t high, vm_memattr_t memattr)
309 {
310 	struct vm_domainset_iter di;
311 	void *addr;
312 	int domain;
313 
314 	vm_domainset_iter_policy_init(&di, ds, &domain, &flags);
315 	do {
316 		addr = kmem_alloc_attr_domain(domain, size, flags, low, high,
317 		    memattr);
318 		if (addr != NULL)
319 			break;
320 	} while (vm_domainset_iter_policy(&di, &domain) == 0);
321 
322 	return (addr);
323 }
324 
325 /*
326  *	Allocates a region from the kernel address map and physically
327  *	contiguous pages within the specified address range to the kernel
328  *	object.  Creates a wired mapping from this region to these pages, and
329  *	returns the region's starting virtual address.  If M_ZERO is specified
330  *	through the given flags, then the pages are zeroed before they are
331  *	mapped.
332  */
333 static void *
kmem_alloc_contig_domain(int domain,vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,u_long alignment,vm_paddr_t boundary,vm_memattr_t memattr)334 kmem_alloc_contig_domain(int domain, vm_size_t size, int flags, vm_paddr_t low,
335     vm_paddr_t high, u_long alignment, vm_paddr_t boundary,
336     vm_memattr_t memattr)
337 {
338 	vmem_t *vmem;
339 	vm_object_t object;
340 	vm_offset_t addr, offset, tmp;
341 	vm_page_t end_m, m;
342 	vm_size_t asize;
343 	u_long npages;
344 	int pflags;
345 
346 	object = kernel_object;
347 	asize = round_page(size);
348 	vmem = vm_dom[domain].vmd_kernel_arena;
349 	if (vmem_alloc(vmem, asize, flags | M_BESTFIT, &addr))
350 		return (NULL);
351 	offset = addr - VM_MIN_KERNEL_ADDRESS;
352 	pflags = malloc2vm_flags(flags) | VM_ALLOC_WIRED;
353 	npages = atop(asize);
354 	VM_OBJECT_WLOCK(object);
355 	m = kmem_alloc_contig_pages(object, atop(offset), domain,
356 	    pflags, npages, low, high, alignment, boundary, memattr);
357 	if (m == NULL) {
358 		VM_OBJECT_WUNLOCK(object);
359 		vmem_free(vmem, addr, asize);
360 		return (NULL);
361 	}
362 	KASSERT(vm_page_domain(m) == domain,
363 	    ("kmem_alloc_contig_domain: Domain mismatch %d != %d",
364 	    vm_page_domain(m), domain));
365 	end_m = m + npages;
366 	tmp = addr;
367 	for (; m < end_m; m++) {
368 		if ((flags & M_ZERO) && (m->flags & PG_ZERO) == 0)
369 			pmap_zero_page(m);
370 		vm_page_valid(m);
371 		pmap_enter(kernel_pmap, tmp, m, VM_PROT_RW,
372 		    VM_PROT_RW | PMAP_ENTER_WIRED, 0);
373 		tmp += PAGE_SIZE;
374 	}
375 	VM_OBJECT_WUNLOCK(object);
376 	kmem_alloc_san(addr, size, asize, flags);
377 	return ((void *)addr);
378 }
379 
380 void *
kmem_alloc_contig(vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,u_long alignment,vm_paddr_t boundary,vm_memattr_t memattr)381 kmem_alloc_contig(vm_size_t size, int flags, vm_paddr_t low, vm_paddr_t high,
382     u_long alignment, vm_paddr_t boundary, vm_memattr_t memattr)
383 {
384 
385 	return (kmem_alloc_contig_domainset(DOMAINSET_RR(), size, flags, low,
386 	    high, alignment, boundary, memattr));
387 }
388 
389 void *
kmem_alloc_contig_domainset(struct domainset * ds,vm_size_t size,int flags,vm_paddr_t low,vm_paddr_t high,u_long alignment,vm_paddr_t boundary,vm_memattr_t memattr)390 kmem_alloc_contig_domainset(struct domainset *ds, vm_size_t size, int flags,
391     vm_paddr_t low, vm_paddr_t high, u_long alignment, vm_paddr_t boundary,
392     vm_memattr_t memattr)
393 {
394 	struct vm_domainset_iter di;
395 	void *addr;
396 	int domain;
397 
398 	vm_domainset_iter_policy_init(&di, ds, &domain, &flags);
399 	do {
400 		addr = kmem_alloc_contig_domain(domain, size, flags, low, high,
401 		    alignment, boundary, memattr);
402 		if (addr != NULL)
403 			break;
404 	} while (vm_domainset_iter_policy(&di, &domain) == 0);
405 
406 	return (addr);
407 }
408 
409 /*
410  *	kmem_subinit:
411  *
412  *	Initializes a map to manage a subrange
413  *	of the kernel virtual address space.
414  *
415  *	Arguments are as follows:
416  *
417  *	parent		Map to take range from
418  *	min, max	Returned endpoints of map
419  *	size		Size of range to find
420  *	superpage_align	Request that min is superpage aligned
421  */
422 void
kmem_subinit(vm_map_t map,vm_map_t parent,vm_offset_t * min,vm_offset_t * max,vm_size_t size,bool superpage_align)423 kmem_subinit(vm_map_t map, vm_map_t parent, vm_offset_t *min, vm_offset_t *max,
424     vm_size_t size, bool superpage_align)
425 {
426 	int ret;
427 
428 	size = round_page(size);
429 
430 	*min = vm_map_min(parent);
431 	ret = vm_map_find(parent, NULL, 0, min, size, 0, superpage_align ?
432 	    VMFS_SUPER_SPACE : VMFS_ANY_SPACE, VM_PROT_ALL, VM_PROT_ALL,
433 	    MAP_ACC_NO_CHARGE);
434 	if (ret != KERN_SUCCESS)
435 		panic("kmem_subinit: bad status return of %d", ret);
436 	*max = *min + size;
437 	vm_map_init(map, vm_map_pmap(parent), *min, *max);
438 	if (vm_map_submap(parent, *min, *max, map) != KERN_SUCCESS)
439 		panic("kmem_subinit: unable to change range to submap");
440 }
441 
442 /*
443  *	kmem_malloc_domain:
444  *
445  *	Allocate wired-down pages in the kernel's address space.
446  */
447 static void *
kmem_malloc_domain(int domain,vm_size_t size,int flags)448 kmem_malloc_domain(int domain, vm_size_t size, int flags)
449 {
450 	vmem_t *arena;
451 	vm_offset_t addr;
452 	vm_size_t asize;
453 	int rv;
454 
455 	if (__predict_true((flags & M_EXEC) == 0))
456 		arena = vm_dom[domain].vmd_kernel_arena;
457 	else
458 		arena = vm_dom[domain].vmd_kernel_rwx_arena;
459 	asize = round_page(size);
460 	if (vmem_alloc(arena, asize, flags | M_BESTFIT, &addr))
461 		return (0);
462 
463 	rv = kmem_back_domain(domain, kernel_object, addr, asize, flags);
464 	if (rv != KERN_SUCCESS) {
465 		vmem_free(arena, addr, asize);
466 		return (0);
467 	}
468 	kasan_mark((void *)addr, size, asize, KASAN_KMEM_REDZONE);
469 	return ((void *)addr);
470 }
471 
472 void *
kmem_malloc(vm_size_t size,int flags)473 kmem_malloc(vm_size_t size, int flags)
474 {
475 	void * p;
476 
477 	TSENTER();
478 	p = kmem_malloc_domainset(DOMAINSET_RR(), size, flags);
479 	TSEXIT();
480 	return (p);
481 }
482 
483 void *
kmem_malloc_domainset(struct domainset * ds,vm_size_t size,int flags)484 kmem_malloc_domainset(struct domainset *ds, vm_size_t size, int flags)
485 {
486 	struct vm_domainset_iter di;
487 	void *addr;
488 	int domain;
489 
490 	vm_domainset_iter_policy_init(&di, ds, &domain, &flags);
491 	do {
492 		addr = kmem_malloc_domain(domain, size, flags);
493 		if (addr != NULL)
494 			break;
495 	} while (vm_domainset_iter_policy(&di, &domain) == 0);
496 
497 	return (addr);
498 }
499 
500 /*
501  *	kmem_back_domain:
502  *
503  *	Allocate physical pages from the specified domain for the specified
504  *	virtual address range.
505  */
506 int
kmem_back_domain(int domain,vm_object_t object,vm_offset_t addr,vm_size_t size,int flags)507 kmem_back_domain(int domain, vm_object_t object, vm_offset_t addr,
508     vm_size_t size, int flags)
509 {
510 	vm_offset_t offset, i;
511 	vm_page_t m, mpred;
512 	vm_prot_t prot;
513 	int pflags;
514 
515 	KASSERT(object == kernel_object,
516 	    ("kmem_back_domain: only supports kernel object."));
517 
518 	offset = addr - VM_MIN_KERNEL_ADDRESS;
519 	pflags = malloc2vm_flags(flags) | VM_ALLOC_WIRED;
520 	pflags &= ~(VM_ALLOC_NOWAIT | VM_ALLOC_WAITOK | VM_ALLOC_WAITFAIL);
521 	if (flags & M_WAITOK)
522 		pflags |= VM_ALLOC_WAITFAIL;
523 	prot = (flags & M_EXEC) != 0 ? VM_PROT_ALL : VM_PROT_RW;
524 
525 	i = 0;
526 	VM_OBJECT_WLOCK(object);
527 retry:
528 	mpred = vm_radix_lookup_le(&object->rtree, atop(offset + i));
529 	for (; i < size; i += PAGE_SIZE, mpred = m) {
530 		m = vm_page_alloc_domain_after(object, atop(offset + i),
531 		    domain, pflags, mpred);
532 
533 		/*
534 		 * Ran out of space, free everything up and return. Don't need
535 		 * to lock page queues here as we know that the pages we got
536 		 * aren't on any queues.
537 		 */
538 		if (m == NULL) {
539 			if ((flags & M_NOWAIT) == 0)
540 				goto retry;
541 			VM_OBJECT_WUNLOCK(object);
542 			kmem_unback(object, addr, i);
543 			return (KERN_NO_SPACE);
544 		}
545 		KASSERT(vm_page_domain(m) == domain,
546 		    ("kmem_back_domain: Domain mismatch %d != %d",
547 		    vm_page_domain(m), domain));
548 		if (flags & M_ZERO && (m->flags & PG_ZERO) == 0)
549 			pmap_zero_page(m);
550 		KASSERT((m->oflags & VPO_UNMANAGED) != 0,
551 		    ("kmem_malloc: page %p is managed", m));
552 		vm_page_valid(m);
553 		pmap_enter(kernel_pmap, addr + i, m, prot,
554 		    prot | PMAP_ENTER_WIRED, 0);
555 		if (__predict_false((prot & VM_PROT_EXECUTE) != 0))
556 			m->oflags |= VPO_KMEM_EXEC;
557 	}
558 	VM_OBJECT_WUNLOCK(object);
559 	kmem_alloc_san(addr, size, size, flags);
560 	return (KERN_SUCCESS);
561 }
562 
563 /*
564  *	kmem_back:
565  *
566  *	Allocate physical pages for the specified virtual address range.
567  */
568 int
kmem_back(vm_object_t object,vm_offset_t addr,vm_size_t size,int flags)569 kmem_back(vm_object_t object, vm_offset_t addr, vm_size_t size, int flags)
570 {
571 	vm_offset_t end, next, start;
572 	int domain, rv;
573 
574 	KASSERT(object == kernel_object,
575 	    ("kmem_back: only supports kernel object."));
576 
577 	for (start = addr, end = addr + size; addr < end; addr = next) {
578 		/*
579 		 * We must ensure that pages backing a given large virtual page
580 		 * all come from the same physical domain.
581 		 */
582 		if (vm_ndomains > 1) {
583 			domain = (addr >> KVA_QUANTUM_SHIFT) % vm_ndomains;
584 			while (VM_DOMAIN_EMPTY(domain))
585 				domain++;
586 			next = roundup2(addr + 1, KVA_QUANTUM);
587 			if (next > end || next < start)
588 				next = end;
589 		} else {
590 			domain = 0;
591 			next = end;
592 		}
593 		rv = kmem_back_domain(domain, object, addr, next - addr, flags);
594 		if (rv != KERN_SUCCESS) {
595 			kmem_unback(object, start, addr - start);
596 			break;
597 		}
598 	}
599 	return (rv);
600 }
601 
602 /*
603  *	kmem_unback:
604  *
605  *	Unmap and free the physical pages underlying the specified virtual
606  *	address range.
607  *
608  *	A physical page must exist within the specified object at each index
609  *	that is being unmapped.
610  */
611 static struct vmem *
_kmem_unback(vm_object_t object,vm_offset_t addr,vm_size_t size)612 _kmem_unback(vm_object_t object, vm_offset_t addr, vm_size_t size)
613 {
614 	struct vmem *arena;
615 	vm_page_t m, next;
616 	vm_offset_t end, offset;
617 	int domain;
618 
619 	KASSERT(object == kernel_object,
620 	    ("kmem_unback: only supports kernel object."));
621 
622 	if (size == 0)
623 		return (NULL);
624 	pmap_remove(kernel_pmap, addr, addr + size);
625 	offset = addr - VM_MIN_KERNEL_ADDRESS;
626 	end = offset + size;
627 	VM_OBJECT_WLOCK(object);
628 	m = vm_page_lookup(object, atop(offset));
629 	domain = vm_page_domain(m);
630 	if (__predict_true((m->oflags & VPO_KMEM_EXEC) == 0))
631 		arena = vm_dom[domain].vmd_kernel_arena;
632 	else
633 		arena = vm_dom[domain].vmd_kernel_rwx_arena;
634 	for (; offset < end; offset += PAGE_SIZE, m = next) {
635 		next = vm_page_next(m);
636 		vm_page_xbusy_claim(m);
637 		vm_page_unwire_noq(m);
638 		vm_page_free(m);
639 	}
640 	VM_OBJECT_WUNLOCK(object);
641 
642 	return (arena);
643 }
644 
645 void
kmem_unback(vm_object_t object,vm_offset_t addr,vm_size_t size)646 kmem_unback(vm_object_t object, vm_offset_t addr, vm_size_t size)
647 {
648 
649 	(void)_kmem_unback(object, addr, size);
650 }
651 
652 /*
653  *	kmem_free:
654  *
655  *	Free memory allocated with kmem_malloc.  The size must match the
656  *	original allocation.
657  */
658 void
kmem_free(void * addr,vm_size_t size)659 kmem_free(void *addr, vm_size_t size)
660 {
661 	struct vmem *arena;
662 
663 	size = round_page(size);
664 	kasan_mark(addr, size, size, 0);
665 	arena = _kmem_unback(kernel_object, (uintptr_t)addr, size);
666 	if (arena != NULL)
667 		vmem_free(arena, (uintptr_t)addr, size);
668 }
669 
670 /*
671  *	kmap_alloc_wait:
672  *
673  *	Allocates pageable memory from a sub-map of the kernel.  If the submap
674  *	has no room, the caller sleeps waiting for more memory in the submap.
675  *
676  *	This routine may block.
677  */
678 vm_offset_t
kmap_alloc_wait(vm_map_t map,vm_size_t size)679 kmap_alloc_wait(vm_map_t map, vm_size_t size)
680 {
681 	vm_offset_t addr;
682 
683 	size = round_page(size);
684 	if (!swap_reserve(size))
685 		return (0);
686 
687 	for (;;) {
688 		/*
689 		 * To make this work for more than one map, use the map's lock
690 		 * to lock out sleepers/wakers.
691 		 */
692 		vm_map_lock(map);
693 		addr = vm_map_findspace(map, vm_map_min(map), size);
694 		if (addr + size <= vm_map_max(map))
695 			break;
696 		/* no space now; see if we can ever get space */
697 		if (vm_map_max(map) - vm_map_min(map) < size) {
698 			vm_map_unlock(map);
699 			swap_release(size);
700 			return (0);
701 		}
702 		map->needs_wakeup = TRUE;
703 		vm_map_unlock_and_wait(map, 0);
704 	}
705 	vm_map_insert(map, NULL, 0, addr, addr + size, VM_PROT_RW, VM_PROT_RW,
706 	    MAP_ACC_CHARGED);
707 	vm_map_unlock(map);
708 	return (addr);
709 }
710 
711 /*
712  *	kmap_free_wakeup:
713  *
714  *	Returns memory to a submap of the kernel, and wakes up any processes
715  *	waiting for memory in that map.
716  */
717 void
kmap_free_wakeup(vm_map_t map,vm_offset_t addr,vm_size_t size)718 kmap_free_wakeup(vm_map_t map, vm_offset_t addr, vm_size_t size)
719 {
720 
721 	vm_map_lock(map);
722 	(void) vm_map_delete(map, trunc_page(addr), round_page(addr + size));
723 	if (map->needs_wakeup) {
724 		map->needs_wakeup = FALSE;
725 		vm_map_wakeup(map);
726 	}
727 	vm_map_unlock(map);
728 }
729 
730 void
kmem_init_zero_region(void)731 kmem_init_zero_region(void)
732 {
733 	vm_offset_t addr, i;
734 	vm_page_t m;
735 
736 	/*
737 	 * Map a single physical page of zeros to a larger virtual range.
738 	 * This requires less looping in places that want large amounts of
739 	 * zeros, while not using much more physical resources.
740 	 */
741 	addr = kva_alloc(ZERO_REGION_SIZE);
742 	m = vm_page_alloc_noobj(VM_ALLOC_WIRED | VM_ALLOC_ZERO);
743 	for (i = 0; i < ZERO_REGION_SIZE; i += PAGE_SIZE)
744 		pmap_qenter(addr + i, &m, 1);
745 	pmap_protect(kernel_pmap, addr, addr + ZERO_REGION_SIZE, VM_PROT_READ);
746 
747 	zero_region = (const void *)addr;
748 }
749 
750 /*
751  * Import KVA from the kernel map into the kernel arena.
752  */
753 static int
kva_import(void * unused,vmem_size_t size,int flags,vmem_addr_t * addrp)754 kva_import(void *unused, vmem_size_t size, int flags, vmem_addr_t *addrp)
755 {
756 	vm_offset_t addr;
757 	int result;
758 
759 	TSENTER();
760 	KASSERT((size % KVA_QUANTUM) == 0,
761 	    ("kva_import: Size %jd is not a multiple of %d",
762 	    (intmax_t)size, (int)KVA_QUANTUM));
763 	addr = vm_map_min(kernel_map);
764 	result = vm_map_find(kernel_map, NULL, 0, &addr, size, 0,
765 	    VMFS_SUPER_SPACE, VM_PROT_ALL, VM_PROT_ALL, MAP_NOFAULT);
766 	if (result != KERN_SUCCESS) {
767 		TSEXIT();
768                 return (ENOMEM);
769 	}
770 
771 	*addrp = addr;
772 
773 	TSEXIT();
774 	return (0);
775 }
776 
777 /*
778  * Import KVA from a parent arena into a per-domain arena.  Imports must be
779  * KVA_QUANTUM-aligned and a multiple of KVA_QUANTUM in size.
780  */
781 static int
kva_import_domain(void * arena,vmem_size_t size,int flags,vmem_addr_t * addrp)782 kva_import_domain(void *arena, vmem_size_t size, int flags, vmem_addr_t *addrp)
783 {
784 
785 	KASSERT((size % KVA_QUANTUM) == 0,
786 	    ("kva_import_domain: Size %jd is not a multiple of %d",
787 	    (intmax_t)size, (int)KVA_QUANTUM));
788 	return (vmem_xalloc(arena, size, KVA_QUANTUM, 0, 0, VMEM_ADDR_MIN,
789 	    VMEM_ADDR_MAX, flags, addrp));
790 }
791 
792 /*
793  * 	kmem_init:
794  *
795  *	Create the kernel map; insert a mapping covering kernel text,
796  *	data, bss, and all space allocated thus far (`boostrap' data).  The
797  *	new map will thus map the range between VM_MIN_KERNEL_ADDRESS and
798  *	`start' as allocated, and the range between `start' and `end' as free.
799  *	Create the kernel vmem arena and its per-domain children.
800  */
801 void
kmem_init(vm_offset_t start,vm_offset_t end)802 kmem_init(vm_offset_t start, vm_offset_t end)
803 {
804 	vm_size_t quantum;
805 	int domain;
806 
807 	vm_map_init(kernel_map, kernel_pmap, VM_MIN_KERNEL_ADDRESS, end);
808 	kernel_map->system_map = 1;
809 	vm_map_lock(kernel_map);
810 	/* N.B.: cannot use kgdb to debug, starting with this assignment ... */
811 	(void)vm_map_insert(kernel_map, NULL, 0,
812 #ifdef __amd64__
813 	    KERNBASE,
814 #else
815 	    VM_MIN_KERNEL_ADDRESS,
816 #endif
817 	    start, VM_PROT_ALL, VM_PROT_ALL, MAP_NOFAULT);
818 	/* ... and ending with the completion of the above `insert' */
819 
820 #ifdef __amd64__
821 	/*
822 	 * Mark KVA used for the page array as allocated.  Other platforms
823 	 * that handle vm_page_array allocation can simply adjust virtual_avail
824 	 * instead.
825 	 */
826 	(void)vm_map_insert(kernel_map, NULL, 0, (vm_offset_t)vm_page_array,
827 	    (vm_offset_t)vm_page_array + round_2mpage(vm_page_array_size *
828 	    sizeof(struct vm_page)),
829 	    VM_PROT_RW, VM_PROT_RW, MAP_NOFAULT);
830 #endif
831 	vm_map_unlock(kernel_map);
832 
833 	/*
834 	 * Use a large import quantum on NUMA systems.  This helps minimize
835 	 * interleaving of superpages, reducing internal fragmentation within
836 	 * the per-domain arenas.
837 	 */
838 	if (vm_ndomains > 1 && PMAP_HAS_DMAP)
839 		quantum = KVA_NUMA_IMPORT_QUANTUM;
840 	else
841 		quantum = KVA_QUANTUM;
842 
843 	/*
844 	 * Initialize the kernel_arena.  This can grow on demand.
845 	 */
846 	vmem_init(kernel_arena, "kernel arena", 0, 0, PAGE_SIZE, 0, 0);
847 	vmem_set_import(kernel_arena, kva_import, NULL, NULL, quantum);
848 
849 	for (domain = 0; domain < vm_ndomains; domain++) {
850 		/*
851 		 * Initialize the per-domain arenas.  These are used to color
852 		 * the KVA space in a way that ensures that virtual large pages
853 		 * are backed by memory from the same physical domain,
854 		 * maximizing the potential for superpage promotion.
855 		 */
856 		vm_dom[domain].vmd_kernel_arena = vmem_create(
857 		    "kernel arena domain", 0, 0, PAGE_SIZE, 0, M_WAITOK);
858 		vmem_set_import(vm_dom[domain].vmd_kernel_arena,
859 		    kva_import_domain, NULL, kernel_arena, quantum);
860 
861 		/*
862 		 * In architectures with superpages, maintain separate arenas
863 		 * for allocations with permissions that differ from the
864 		 * "standard" read/write permissions used for kernel memory,
865 		 * so as not to inhibit superpage promotion.
866 		 *
867 		 * Use the base import quantum since this arena is rarely used.
868 		 */
869 #if VM_NRESERVLEVEL > 0
870 		vm_dom[domain].vmd_kernel_rwx_arena = vmem_create(
871 		    "kernel rwx arena domain", 0, 0, PAGE_SIZE, 0, M_WAITOK);
872 		vmem_set_import(vm_dom[domain].vmd_kernel_rwx_arena,
873 		    kva_import_domain, (vmem_release_t *)vmem_xfree,
874 		    kernel_arena, KVA_QUANTUM);
875 #else
876 		vm_dom[domain].vmd_kernel_rwx_arena =
877 		    vm_dom[domain].vmd_kernel_arena;
878 #endif
879 	}
880 
881 	/*
882 	 * This must be the very first call so that the virtual address
883 	 * space used for early allocations is properly marked used in
884 	 * the map.
885 	 */
886 	uma_startup2();
887 }
888 
889 /*
890  *	kmem_bootstrap_free:
891  *
892  *	Free pages backing preloaded data (e.g., kernel modules) to the
893  *	system.  Currently only supported on platforms that create a
894  *	vm_phys segment for preloaded data.
895  */
896 void
kmem_bootstrap_free(vm_offset_t start,vm_size_t size)897 kmem_bootstrap_free(vm_offset_t start, vm_size_t size)
898 {
899 #if defined(__i386__) || defined(__amd64__)
900 	struct vm_domain *vmd;
901 	vm_offset_t end, va;
902 	vm_paddr_t pa;
903 	vm_page_t m;
904 
905 	end = trunc_page(start + size);
906 	start = round_page(start);
907 
908 #ifdef __amd64__
909 	/*
910 	 * Preloaded files do not have execute permissions by default on amd64.
911 	 * Restore the default permissions to ensure that the direct map alias
912 	 * is updated.
913 	 */
914 	pmap_change_prot(start, end - start, VM_PROT_RW);
915 #endif
916 	for (va = start; va < end; va += PAGE_SIZE) {
917 		pa = pmap_kextract(va);
918 		m = PHYS_TO_VM_PAGE(pa);
919 
920 		vmd = vm_pagequeue_domain(m);
921 		vm_domain_free_lock(vmd);
922 		vm_phys_free_pages(m, 0);
923 		vm_domain_free_unlock(vmd);
924 
925 		vm_domain_freecnt_inc(vmd, 1);
926 		vm_cnt.v_page_count++;
927 	}
928 	pmap_remove(kernel_pmap, start, end);
929 	(void)vmem_add(kernel_arena, start, end - start, M_WAITOK);
930 #endif
931 }
932 
933 #ifdef PMAP_WANT_ACTIVE_CPUS_NAIVE
934 void
pmap_active_cpus(pmap_t pmap,cpuset_t * res)935 pmap_active_cpus(pmap_t pmap, cpuset_t *res)
936 {
937 	struct thread *td;
938 	struct proc *p;
939 	struct vmspace *vm;
940 	int c;
941 
942 	CPU_ZERO(res);
943 	CPU_FOREACH(c) {
944 		td = cpuid_to_pcpu[c]->pc_curthread;
945 		p = td->td_proc;
946 		if (p == NULL)
947 			continue;
948 		vm = vmspace_acquire_ref(p);
949 		if (vm == NULL)
950 			continue;
951 		if (pmap == vmspace_pmap(vm))
952 			CPU_SET(c, res);
953 		vmspace_free(vm);
954 	}
955 }
956 #endif
957 
958 /*
959  * Allow userspace to directly trigger the VM drain routine for testing
960  * purposes.
961  */
962 static int
debug_vm_lowmem(SYSCTL_HANDLER_ARGS)963 debug_vm_lowmem(SYSCTL_HANDLER_ARGS)
964 {
965 	int error, i;
966 
967 	i = 0;
968 	error = sysctl_handle_int(oidp, &i, 0, req);
969 	if (error != 0)
970 		return (error);
971 	if ((i & ~(VM_LOW_KMEM | VM_LOW_PAGES)) != 0)
972 		return (EINVAL);
973 	if (i != 0)
974 		EVENTHANDLER_INVOKE(vm_lowmem, i);
975 	return (0);
976 }
977 SYSCTL_PROC(_debug, OID_AUTO, vm_lowmem,
978     CTLTYPE_INT | CTLFLAG_MPSAFE | CTLFLAG_RW, 0, 0, debug_vm_lowmem, "I",
979     "set to trigger vm_lowmem event with given flags");
980 
981 static int
debug_uma_reclaim(SYSCTL_HANDLER_ARGS)982 debug_uma_reclaim(SYSCTL_HANDLER_ARGS)
983 {
984 	int error, i;
985 
986 	i = 0;
987 	error = sysctl_handle_int(oidp, &i, 0, req);
988 	if (error != 0 || req->newptr == NULL)
989 		return (error);
990 	if (i != UMA_RECLAIM_TRIM && i != UMA_RECLAIM_DRAIN &&
991 	    i != UMA_RECLAIM_DRAIN_CPU)
992 		return (EINVAL);
993 	uma_reclaim(i);
994 	return (0);
995 }
996 SYSCTL_PROC(_debug, OID_AUTO, uma_reclaim,
997     CTLTYPE_INT | CTLFLAG_MPSAFE | CTLFLAG_RW, 0, 0, debug_uma_reclaim, "I",
998     "set to generate request to reclaim uma caches");
999 
1000 static int
debug_uma_reclaim_domain(SYSCTL_HANDLER_ARGS)1001 debug_uma_reclaim_domain(SYSCTL_HANDLER_ARGS)
1002 {
1003 	int domain, error, request;
1004 
1005 	request = 0;
1006 	error = sysctl_handle_int(oidp, &request, 0, req);
1007 	if (error != 0 || req->newptr == NULL)
1008 		return (error);
1009 
1010 	domain = request >> 4;
1011 	request &= 0xf;
1012 	if (request != UMA_RECLAIM_TRIM && request != UMA_RECLAIM_DRAIN &&
1013 	    request != UMA_RECLAIM_DRAIN_CPU)
1014 		return (EINVAL);
1015 	if (domain < 0 || domain >= vm_ndomains)
1016 		return (EINVAL);
1017 	uma_reclaim_domain(request, domain);
1018 	return (0);
1019 }
1020 SYSCTL_PROC(_debug, OID_AUTO, uma_reclaim_domain,
1021     CTLTYPE_INT | CTLFLAG_MPSAFE | CTLFLAG_RW, 0, 0,
1022     debug_uma_reclaim_domain, "I",
1023     "");
1024