2005-01-07 02:29:27 +00:00
|
|
|
/*-
|
2005-07-16 09:51:52 +00:00
|
|
|
* Copyright (c) 2002, 2003, 2004, 2005 Jeffrey Roberson <jeff@FreeBSD.org>
|
|
|
|
* Copyright (c) 2004, 2005 Bosko Milekic <bmilekic@FreeBSD.org>
|
|
|
|
* All rights reserved.
|
2002-04-30 07:54:25 +00:00
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
|
|
* notice unmodified, this list of conditions, and the following
|
|
|
|
* disclaimer.
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
|
|
|
|
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
|
|
|
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
|
|
|
|
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
|
|
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
|
|
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
|
|
|
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
|
|
|
|
/*
|
|
|
|
* uma_dbg.c Debugging features for UMA users
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
2003-06-11 23:50:51 +00:00
|
|
|
#include <sys/cdefs.h>
|
|
|
|
__FBSDID("$FreeBSD$");
|
2002-04-30 07:54:25 +00:00
|
|
|
|
|
|
|
#include <sys/param.h>
|
|
|
|
#include <sys/systm.h>
|
2013-06-13 21:05:38 +00:00
|
|
|
#include <sys/bitset.h>
|
2002-04-30 07:54:25 +00:00
|
|
|
#include <sys/kernel.h>
|
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/queue.h>
|
|
|
|
#include <sys/lock.h>
|
|
|
|
#include <sys/mutex.h>
|
2002-05-02 09:07:04 +00:00
|
|
|
#include <sys/malloc.h>
|
2002-04-30 07:54:25 +00:00
|
|
|
|
2002-09-18 08:26:30 +00:00
|
|
|
#include <vm/vm.h>
|
|
|
|
#include <vm/vm_object.h>
|
|
|
|
#include <vm/vm_page.h>
|
2002-04-30 07:54:25 +00:00
|
|
|
#include <vm/uma.h>
|
|
|
|
#include <vm/uma_int.h>
|
|
|
|
#include <vm/uma_dbg.h>
|
|
|
|
|
2013-04-09 17:43:48 +00:00
|
|
|
static const uint32_t uma_junk = 0xdeadc0de;
|
2002-04-30 07:54:25 +00:00
|
|
|
|
|
|
|
/*
|
2004-08-02 00:18:36 +00:00
|
|
|
* Checks an item to make sure it hasn't been overwritten since it was freed,
|
|
|
|
* prior to subsequent reallocation.
|
2002-04-30 07:54:25 +00:00
|
|
|
*
|
|
|
|
* Complies with standard ctor arg/return
|
|
|
|
*
|
|
|
|
*/
|
2004-08-02 00:18:36 +00:00
|
|
|
int
|
|
|
|
trash_ctor(void *mem, int size, void *arg, int flags)
|
2002-04-30 07:54:25 +00:00
|
|
|
{
|
|
|
|
int cnt;
|
2013-04-09 17:43:48 +00:00
|
|
|
uint32_t *p;
|
2002-04-30 07:54:25 +00:00
|
|
|
|
|
|
|
cnt = size / sizeof(uma_junk);
|
|
|
|
|
|
|
|
for (p = mem; cnt > 0; cnt--, p++)
|
2005-06-26 23:44:07 +00:00
|
|
|
if (*p != uma_junk) {
|
2015-06-25 20:44:46 +00:00
|
|
|
#ifdef INVARIANTS
|
|
|
|
panic("Memory modified after free %p(%d) val=%x @ %p\n",
|
|
|
|
mem, size, *p, p);
|
|
|
|
#else
|
2005-06-26 23:44:07 +00:00
|
|
|
printf("Memory modified after free %p(%d) val=%x @ %p\n",
|
2003-09-27 21:33:13 +00:00
|
|
|
mem, size, *p, p);
|
2015-06-25 20:44:46 +00:00
|
|
|
#endif
|
2005-06-26 23:44:07 +00:00
|
|
|
return (0);
|
|
|
|
}
|
2004-08-02 00:18:36 +00:00
|
|
|
return (0);
|
2002-04-30 07:54:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Fills an item with predictable garbage
|
|
|
|
*
|
|
|
|
* Complies with standard dtor arg/return
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
trash_dtor(void *mem, int size, void *arg)
|
|
|
|
{
|
|
|
|
int cnt;
|
2013-04-09 17:43:48 +00:00
|
|
|
uint32_t *p;
|
2002-04-30 07:54:25 +00:00
|
|
|
|
|
|
|
cnt = size / sizeof(uma_junk);
|
|
|
|
|
|
|
|
for (p = mem; cnt > 0; cnt--, p++)
|
|
|
|
*p = uma_junk;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Fills an item with predictable garbage
|
|
|
|
*
|
|
|
|
* Complies with standard init arg/return
|
|
|
|
*
|
|
|
|
*/
|
2004-08-02 00:18:36 +00:00
|
|
|
int
|
|
|
|
trash_init(void *mem, int size, int flags)
|
2002-04-30 07:54:25 +00:00
|
|
|
{
|
|
|
|
trash_dtor(mem, size, NULL);
|
2004-08-02 00:18:36 +00:00
|
|
|
return (0);
|
2002-04-30 07:54:25 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Checks an item to make sure it hasn't been overwritten since it was freed.
|
|
|
|
*
|
|
|
|
* Complies with standard fini arg/return
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
trash_fini(void *mem, int size)
|
|
|
|
{
|
2004-08-02 00:18:36 +00:00
|
|
|
(void)trash_ctor(mem, size, NULL, 0);
|
2002-04-30 07:54:25 +00:00
|
|
|
}
|
2002-05-02 02:08:48 +00:00
|
|
|
|
2004-08-02 00:18:36 +00:00
|
|
|
int
|
|
|
|
mtrash_ctor(void *mem, int size, void *arg, int flags)
|
2002-05-02 09:07:04 +00:00
|
|
|
{
|
|
|
|
struct malloc_type **ksp;
|
2013-04-09 17:43:48 +00:00
|
|
|
uint32_t *p = mem;
|
2002-05-02 09:07:04 +00:00
|
|
|
int cnt;
|
|
|
|
|
|
|
|
size -= sizeof(struct malloc_type *);
|
|
|
|
ksp = (struct malloc_type **)mem;
|
|
|
|
ksp += size / sizeof(struct malloc_type *);
|
|
|
|
cnt = size / sizeof(uma_junk);
|
|
|
|
|
|
|
|
for (p = mem; cnt > 0; cnt--, p++)
|
|
|
|
if (*p != uma_junk) {
|
2003-09-27 21:33:13 +00:00
|
|
|
printf("Memory modified after free %p(%d) val=%x @ %p\n",
|
|
|
|
mem, size, *p, p);
|
2002-05-02 09:07:04 +00:00
|
|
|
panic("Most recently used by %s\n", (*ksp == NULL)?
|
|
|
|
"none" : (*ksp)->ks_shortdesc);
|
|
|
|
}
|
2004-08-02 00:18:36 +00:00
|
|
|
return (0);
|
2002-05-02 09:07:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Fills an item with predictable garbage
|
|
|
|
*
|
|
|
|
* Complies with standard dtor arg/return
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
mtrash_dtor(void *mem, int size, void *arg)
|
|
|
|
{
|
|
|
|
int cnt;
|
2013-04-09 17:43:48 +00:00
|
|
|
uint32_t *p;
|
2002-05-02 09:07:04 +00:00
|
|
|
|
|
|
|
size -= sizeof(struct malloc_type *);
|
|
|
|
cnt = size / sizeof(uma_junk);
|
|
|
|
|
|
|
|
for (p = mem; cnt > 0; cnt--, p++)
|
|
|
|
*p = uma_junk;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Fills an item with predictable garbage
|
|
|
|
*
|
|
|
|
* Complies with standard init arg/return
|
|
|
|
*
|
|
|
|
*/
|
2004-08-02 00:18:36 +00:00
|
|
|
int
|
|
|
|
mtrash_init(void *mem, int size, int flags)
|
2002-05-02 09:07:04 +00:00
|
|
|
{
|
|
|
|
struct malloc_type **ksp;
|
|
|
|
|
|
|
|
mtrash_dtor(mem, size, NULL);
|
|
|
|
|
|
|
|
ksp = (struct malloc_type **)mem;
|
|
|
|
ksp += (size / sizeof(struct malloc_type *)) - 1;
|
|
|
|
*ksp = NULL;
|
2004-08-02 00:18:36 +00:00
|
|
|
return (0);
|
2002-05-02 09:07:04 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
2004-08-02 00:18:36 +00:00
|
|
|
* Checks an item to make sure it hasn't been overwritten since it was freed,
|
|
|
|
* prior to freeing it back to available memory.
|
2002-05-02 09:07:04 +00:00
|
|
|
*
|
|
|
|
* Complies with standard fini arg/return
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
mtrash_fini(void *mem, int size)
|
|
|
|
{
|
2004-08-02 00:18:36 +00:00
|
|
|
(void)mtrash_ctor(mem, size, NULL, 0);
|
2002-05-02 09:07:04 +00:00
|
|
|
}
|
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
#ifdef INVARIANTS
|
2002-05-02 02:08:48 +00:00
|
|
|
static uma_slab_t
|
|
|
|
uma_dbg_getslab(uma_zone_t zone, void *item)
|
|
|
|
{
|
|
|
|
uma_slab_t slab;
|
Bring in mbuma to replace mballoc.
mbuma is an Mbuf & Cluster allocator built on top of a number of
extensions to the UMA framework, all included herein.
Extensions to UMA worth noting:
- Better layering between slab <-> zone caches; introduce
Keg structure which splits off slab cache away from the
zone structure and allows multiple zones to be stacked
on top of a single Keg (single type of slab cache);
perhaps we should look into defining a subset API on
top of the Keg for special use by malloc(9),
for example.
- UMA_ZONE_REFCNT zones can now be added, and reference
counters automagically allocated for them within the end
of the associated slab structures. uma_find_refcnt()
does a kextract to fetch the slab struct reference from
the underlying page, and lookup the corresponding refcnt.
mbuma things worth noting:
- integrates mbuf & cluster allocations with extended UMA
and provides caches for commonly-allocated items; defines
several zones (two primary, one secondary) and two kegs.
- change up certain code paths that always used to do:
m_get() + m_clget() to instead just use m_getcl() and
try to take advantage of the newly defined secondary
Packet zone.
- netstat(1) and systat(1) quickly hacked up to do basic
stat reporting but additional stats work needs to be
done once some other details within UMA have been taken
care of and it becomes clearer to how stats will work
within the modified framework.
From the user perspective, one implication is that the
NMBCLUSTERS compile-time option is no longer used. The
maximum number of clusters is still capped off according
to maxusers, but it can be made unlimited by setting
the kern.ipc.nmbclusters boot-time tunable to zero.
Work should be done to write an appropriate sysctl
handler allowing dynamic tuning of kern.ipc.nmbclusters
at runtime.
Additional things worth noting/known issues (READ):
- One report of 'ips' (ServeRAID) driver acting really
slow in conjunction with mbuma. Need more data.
Latest report is that ips is equally sucking with
and without mbuma.
- Giant leak in NFS code sometimes occurs, can't
reproduce but currently analyzing; brueffer is
able to reproduce but THIS IS NOT an mbuma-specific
problem and currently occurs even WITHOUT mbuma.
- Issues in network locking: there is at least one
code path in the rip code where one or more locks
are acquired and we end up in m_prepend() with
M_WAITOK, which causes WITNESS to whine from within
UMA. Current temporary solution: force all UMA
allocations to be M_NOWAIT from within UMA for now
to avoid deadlocks unless WITNESS is defined and we
can determine with certainty that we're not holding
any locks when we're M_WAITOK.
- I've seen at least one weird socketbuffer empty-but-
mbuf-still-attached panic. I don't believe this
to be related to mbuma but please keep your eyes
open, turn on debugging, and capture crash dumps.
This change removes more code than it adds.
A paper is available detailing the change and considering
various performance issues, it was presented at BSDCan2004:
http://www.unixdaemons.com/~bmilekic/netbuf_bmilekic.pdf
Please read the paper for Future Work and implementation
details, as well as credits.
Testing and Debugging:
rwatson,
brueffer,
Ketrien I. Saihr-Kesenchedra,
...
Reviewed by: Lots of people (for different parts)
2004-05-31 21:46:06 +00:00
|
|
|
uma_keg_t keg;
|
2013-04-09 17:43:48 +00:00
|
|
|
uint8_t *mem;
|
2002-05-02 02:08:48 +00:00
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
mem = (uint8_t *)((uintptr_t)item & (~UMA_SLAB_MASK));
|
2009-01-25 09:11:24 +00:00
|
|
|
if (zone->uz_flags & UMA_ZONE_VTOSLAB) {
|
2002-09-18 08:26:30 +00:00
|
|
|
slab = vtoslab((vm_offset_t)mem);
|
2002-05-02 02:08:48 +00:00
|
|
|
} else {
|
2013-06-13 21:05:38 +00:00
|
|
|
/*
|
|
|
|
* It is safe to return the slab here even though the
|
|
|
|
* zone is unlocked because the item's allocation state
|
|
|
|
* essentially holds a reference.
|
|
|
|
*/
|
|
|
|
ZONE_LOCK(zone);
|
2009-01-25 09:11:24 +00:00
|
|
|
keg = LIST_FIRST(&zone->uz_kegs)->kl_keg;
|
|
|
|
if (keg->uk_flags & UMA_ZONE_HASH)
|
|
|
|
slab = hash_sfind(&keg->uk_hash, mem);
|
|
|
|
else
|
|
|
|
slab = (uma_slab_t)(mem + keg->uk_pgoff);
|
2013-06-13 21:05:38 +00:00
|
|
|
ZONE_UNLOCK(zone);
|
2002-05-02 02:08:48 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
return (slab);
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Set up the slab's freei data such that uma_dbg_free can function.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
uma_dbg_alloc(uma_zone_t zone, uma_slab_t slab, void *item)
|
|
|
|
{
|
Bring in mbuma to replace mballoc.
mbuma is an Mbuf & Cluster allocator built on top of a number of
extensions to the UMA framework, all included herein.
Extensions to UMA worth noting:
- Better layering between slab <-> zone caches; introduce
Keg structure which splits off slab cache away from the
zone structure and allows multiple zones to be stacked
on top of a single Keg (single type of slab cache);
perhaps we should look into defining a subset API on
top of the Keg for special use by malloc(9),
for example.
- UMA_ZONE_REFCNT zones can now be added, and reference
counters automagically allocated for them within the end
of the associated slab structures. uma_find_refcnt()
does a kextract to fetch the slab struct reference from
the underlying page, and lookup the corresponding refcnt.
mbuma things worth noting:
- integrates mbuf & cluster allocations with extended UMA
and provides caches for commonly-allocated items; defines
several zones (two primary, one secondary) and two kegs.
- change up certain code paths that always used to do:
m_get() + m_clget() to instead just use m_getcl() and
try to take advantage of the newly defined secondary
Packet zone.
- netstat(1) and systat(1) quickly hacked up to do basic
stat reporting but additional stats work needs to be
done once some other details within UMA have been taken
care of and it becomes clearer to how stats will work
within the modified framework.
From the user perspective, one implication is that the
NMBCLUSTERS compile-time option is no longer used. The
maximum number of clusters is still capped off according
to maxusers, but it can be made unlimited by setting
the kern.ipc.nmbclusters boot-time tunable to zero.
Work should be done to write an appropriate sysctl
handler allowing dynamic tuning of kern.ipc.nmbclusters
at runtime.
Additional things worth noting/known issues (READ):
- One report of 'ips' (ServeRAID) driver acting really
slow in conjunction with mbuma. Need more data.
Latest report is that ips is equally sucking with
and without mbuma.
- Giant leak in NFS code sometimes occurs, can't
reproduce but currently analyzing; brueffer is
able to reproduce but THIS IS NOT an mbuma-specific
problem and currently occurs even WITHOUT mbuma.
- Issues in network locking: there is at least one
code path in the rip code where one or more locks
are acquired and we end up in m_prepend() with
M_WAITOK, which causes WITNESS to whine from within
UMA. Current temporary solution: force all UMA
allocations to be M_NOWAIT from within UMA for now
to avoid deadlocks unless WITNESS is defined and we
can determine with certainty that we're not holding
any locks when we're M_WAITOK.
- I've seen at least one weird socketbuffer empty-but-
mbuf-still-attached panic. I don't believe this
to be related to mbuma but please keep your eyes
open, turn on debugging, and capture crash dumps.
This change removes more code than it adds.
A paper is available detailing the change and considering
various performance issues, it was presented at BSDCan2004:
http://www.unixdaemons.com/~bmilekic/netbuf_bmilekic.pdf
Please read the paper for Future Work and implementation
details, as well as credits.
Testing and Debugging:
rwatson,
brueffer,
Ketrien I. Saihr-Kesenchedra,
...
Reviewed by: Lots of people (for different parts)
2004-05-31 21:46:06 +00:00
|
|
|
uma_keg_t keg;
|
2002-05-02 02:08:48 +00:00
|
|
|
int freei;
|
|
|
|
|
2013-06-20 19:08:12 +00:00
|
|
|
if (zone_first_keg(zone) == NULL)
|
|
|
|
return;
|
2002-05-02 02:08:48 +00:00
|
|
|
if (slab == NULL) {
|
|
|
|
slab = uma_dbg_getslab(zone, item);
|
|
|
|
if (slab == NULL)
|
|
|
|
panic("uma: item %p did not belong to zone %s\n",
|
|
|
|
item, zone->uz_name);
|
|
|
|
}
|
2009-01-25 09:11:24 +00:00
|
|
|
keg = slab->us_keg;
|
2013-06-13 21:05:38 +00:00
|
|
|
freei = ((uintptr_t)item - (uintptr_t)slab->us_data) / keg->uk_rsize;
|
2002-05-02 02:08:48 +00:00
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
if (BIT_ISSET(SLAB_SETSIZE, freei, &slab->us_debugfree))
|
|
|
|
panic("Duplicate alloc of %p from zone %p(%s) slab %p(%d)\n",
|
|
|
|
item, zone, zone->uz_name, slab, freei);
|
|
|
|
BIT_SET_ATOMIC(SLAB_SETSIZE, freei, &slab->us_debugfree);
|
2002-05-02 02:08:48 +00:00
|
|
|
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Verifies freed addresses. Checks for alignment, valid slab membership
|
|
|
|
* and duplicate frees.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
uma_dbg_free(uma_zone_t zone, uma_slab_t slab, void *item)
|
|
|
|
{
|
Bring in mbuma to replace mballoc.
mbuma is an Mbuf & Cluster allocator built on top of a number of
extensions to the UMA framework, all included herein.
Extensions to UMA worth noting:
- Better layering between slab <-> zone caches; introduce
Keg structure which splits off slab cache away from the
zone structure and allows multiple zones to be stacked
on top of a single Keg (single type of slab cache);
perhaps we should look into defining a subset API on
top of the Keg for special use by malloc(9),
for example.
- UMA_ZONE_REFCNT zones can now be added, and reference
counters automagically allocated for them within the end
of the associated slab structures. uma_find_refcnt()
does a kextract to fetch the slab struct reference from
the underlying page, and lookup the corresponding refcnt.
mbuma things worth noting:
- integrates mbuf & cluster allocations with extended UMA
and provides caches for commonly-allocated items; defines
several zones (two primary, one secondary) and two kegs.
- change up certain code paths that always used to do:
m_get() + m_clget() to instead just use m_getcl() and
try to take advantage of the newly defined secondary
Packet zone.
- netstat(1) and systat(1) quickly hacked up to do basic
stat reporting but additional stats work needs to be
done once some other details within UMA have been taken
care of and it becomes clearer to how stats will work
within the modified framework.
From the user perspective, one implication is that the
NMBCLUSTERS compile-time option is no longer used. The
maximum number of clusters is still capped off according
to maxusers, but it can be made unlimited by setting
the kern.ipc.nmbclusters boot-time tunable to zero.
Work should be done to write an appropriate sysctl
handler allowing dynamic tuning of kern.ipc.nmbclusters
at runtime.
Additional things worth noting/known issues (READ):
- One report of 'ips' (ServeRAID) driver acting really
slow in conjunction with mbuma. Need more data.
Latest report is that ips is equally sucking with
and without mbuma.
- Giant leak in NFS code sometimes occurs, can't
reproduce but currently analyzing; brueffer is
able to reproduce but THIS IS NOT an mbuma-specific
problem and currently occurs even WITHOUT mbuma.
- Issues in network locking: there is at least one
code path in the rip code where one or more locks
are acquired and we end up in m_prepend() with
M_WAITOK, which causes WITNESS to whine from within
UMA. Current temporary solution: force all UMA
allocations to be M_NOWAIT from within UMA for now
to avoid deadlocks unless WITNESS is defined and we
can determine with certainty that we're not holding
any locks when we're M_WAITOK.
- I've seen at least one weird socketbuffer empty-but-
mbuf-still-attached panic. I don't believe this
to be related to mbuma but please keep your eyes
open, turn on debugging, and capture crash dumps.
This change removes more code than it adds.
A paper is available detailing the change and considering
various performance issues, it was presented at BSDCan2004:
http://www.unixdaemons.com/~bmilekic/netbuf_bmilekic.pdf
Please read the paper for Future Work and implementation
details, as well as credits.
Testing and Debugging:
rwatson,
brueffer,
Ketrien I. Saihr-Kesenchedra,
...
Reviewed by: Lots of people (for different parts)
2004-05-31 21:46:06 +00:00
|
|
|
uma_keg_t keg;
|
2002-05-02 02:08:48 +00:00
|
|
|
int freei;
|
|
|
|
|
2013-06-20 19:08:12 +00:00
|
|
|
if (zone_first_keg(zone) == NULL)
|
|
|
|
return;
|
2002-05-02 02:08:48 +00:00
|
|
|
if (slab == NULL) {
|
|
|
|
slab = uma_dbg_getslab(zone, item);
|
|
|
|
if (slab == NULL)
|
|
|
|
panic("uma: Freed item %p did not belong to zone %s\n",
|
|
|
|
item, zone->uz_name);
|
|
|
|
}
|
2009-01-25 09:11:24 +00:00
|
|
|
keg = slab->us_keg;
|
2013-06-13 21:05:38 +00:00
|
|
|
freei = ((uintptr_t)item - (uintptr_t)slab->us_data) / keg->uk_rsize;
|
2002-05-02 02:08:48 +00:00
|
|
|
|
Bring in mbuma to replace mballoc.
mbuma is an Mbuf & Cluster allocator built on top of a number of
extensions to the UMA framework, all included herein.
Extensions to UMA worth noting:
- Better layering between slab <-> zone caches; introduce
Keg structure which splits off slab cache away from the
zone structure and allows multiple zones to be stacked
on top of a single Keg (single type of slab cache);
perhaps we should look into defining a subset API on
top of the Keg for special use by malloc(9),
for example.
- UMA_ZONE_REFCNT zones can now be added, and reference
counters automagically allocated for them within the end
of the associated slab structures. uma_find_refcnt()
does a kextract to fetch the slab struct reference from
the underlying page, and lookup the corresponding refcnt.
mbuma things worth noting:
- integrates mbuf & cluster allocations with extended UMA
and provides caches for commonly-allocated items; defines
several zones (two primary, one secondary) and two kegs.
- change up certain code paths that always used to do:
m_get() + m_clget() to instead just use m_getcl() and
try to take advantage of the newly defined secondary
Packet zone.
- netstat(1) and systat(1) quickly hacked up to do basic
stat reporting but additional stats work needs to be
done once some other details within UMA have been taken
care of and it becomes clearer to how stats will work
within the modified framework.
From the user perspective, one implication is that the
NMBCLUSTERS compile-time option is no longer used. The
maximum number of clusters is still capped off according
to maxusers, but it can be made unlimited by setting
the kern.ipc.nmbclusters boot-time tunable to zero.
Work should be done to write an appropriate sysctl
handler allowing dynamic tuning of kern.ipc.nmbclusters
at runtime.
Additional things worth noting/known issues (READ):
- One report of 'ips' (ServeRAID) driver acting really
slow in conjunction with mbuma. Need more data.
Latest report is that ips is equally sucking with
and without mbuma.
- Giant leak in NFS code sometimes occurs, can't
reproduce but currently analyzing; brueffer is
able to reproduce but THIS IS NOT an mbuma-specific
problem and currently occurs even WITHOUT mbuma.
- Issues in network locking: there is at least one
code path in the rip code where one or more locks
are acquired and we end up in m_prepend() with
M_WAITOK, which causes WITNESS to whine from within
UMA. Current temporary solution: force all UMA
allocations to be M_NOWAIT from within UMA for now
to avoid deadlocks unless WITNESS is defined and we
can determine with certainty that we're not holding
any locks when we're M_WAITOK.
- I've seen at least one weird socketbuffer empty-but-
mbuf-still-attached panic. I don't believe this
to be related to mbuma but please keep your eyes
open, turn on debugging, and capture crash dumps.
This change removes more code than it adds.
A paper is available detailing the change and considering
various performance issues, it was presented at BSDCan2004:
http://www.unixdaemons.com/~bmilekic/netbuf_bmilekic.pdf
Please read the paper for Future Work and implementation
details, as well as credits.
Testing and Debugging:
rwatson,
brueffer,
Ketrien I. Saihr-Kesenchedra,
...
Reviewed by: Lots of people (for different parts)
2004-05-31 21:46:06 +00:00
|
|
|
if (freei >= keg->uk_ipers)
|
2013-06-13 21:05:38 +00:00
|
|
|
panic("Invalid free of %p from zone %p(%s) slab %p(%d)\n",
|
|
|
|
item, zone, zone->uz_name, slab, freei);
|
2002-05-02 02:08:48 +00:00
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
if (((freei * keg->uk_rsize) + slab->us_data) != item)
|
|
|
|
panic("Unaligned free of %p from zone %p(%s) slab %p(%d)\n",
|
|
|
|
item, zone, zone->uz_name, slab, freei);
|
2002-05-02 02:08:48 +00:00
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
if (!BIT_ISSET(SLAB_SETSIZE, freei, &slab->us_debugfree))
|
|
|
|
panic("Duplicate free of %p from zone %p(%s) slab %p(%d)\n",
|
|
|
|
item, zone, zone->uz_name, slab, freei);
|
Fix critical stability problems that can cause UMA mbuf cluster
state management corruption, mbuf leaks, general mbuf corruption,
and at least on i386 a first level splash damage radius that
encompasses up to about half a megabyte of the memory after
an mbuf cluster's allocation slab. In short, this has caused
instability nightmares anywhere the right kind of network traffic
is present.
When the polymorphic refcount slabs were added to UMA, the new types
were not used pervasively. In particular, the slab management
structure was turned into one for refcounts, and one for non-refcounts
(supposed to be mostly like the old slab management structure),
but the latter was almost always used through out. In general, every
access to zones with UMA_ZONE_REFCNT turned on corrupted the
"next free" slab offset offset and the refcount with each other and
with other allocations (on i386, 2 mbuf clusters per 4096 byte slab).
Fix things so that the right type is used to access refcounted zones
where it was not before. There are additional errors in gross
overestimation of padding, it seems, that would cause a large kegs
(nee zones) to be allocated when small ones would do. Unless I have
analyzed this incorrectly, it is not directly harmful.
2004-10-08 20:19:29 +00:00
|
|
|
|
2013-06-13 21:05:38 +00:00
|
|
|
BIT_CLR_ATOMIC(SLAB_SETSIZE, freei, &slab->us_debugfree);
|
2002-05-02 02:08:48 +00:00
|
|
|
}
|
2013-06-13 21:05:38 +00:00
|
|
|
|
|
|
|
#endif /* INVARIANTS */
|