2 * Copyright (c) 2000 Apple Computer, Inc. All rights reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * The contents of this file constitute Original Code as defined in and
7 * are subject to the Apple Public Source License Version 1.1 (the
8 * "License"). You may not use this file except in compliance with the
9 * License. Please obtain a copy of the License at
10 * http://www.apple.com/publicsource and read it before using this file.
12 * This Original Code and all software distributed under the License are
13 * distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY KIND, EITHER
14 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
15 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
16 * FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT. Please see the
17 * License for the specific language governing rights and limitations
20 * @APPLE_LICENSE_HEADER_END@
28 * Revision 1.1.1.1 1998/09/22 21:05:34 wsanchez
29 * Import of Mac OS X kernel (~semeria)
31 * Revision 1.1.1.1 1998/03/07 02:25:55 wsanchez
32 * Import of OSF Mach kernel (~mburg)
34 * Revision 1.1.6.1 1995/01/06 19:47:19 devrcs
35 * mk6 CR668 - 1.3b26 merge
37 * [1994/10/12 22:19:28 dwm]
39 * Revision 1.1.3.4 1994/05/13 20:10:01 tmt
40 * Changed three unsigned casts to natural_t.
41 * [1994/05/12 22:12:28 tmt]
43 * Revision 1.1.3.2 1993/11/30 18:26:24 jph
44 * CR10228 -- Typo in unlock(), ledger_ledger should be child_ledger.
45 * [1993/11/30 16:10:43 jph]
47 * Revision 1.1.3.1 1993/11/24 21:22:14 jph
48 * CR9801 brezak merge, ledgers, security and NMK15_COMPAT
49 * [1993/11/23 22:41:07 jph]
51 * Revision 1.1.1.4 1993/09/08 14:17:36 brezak
52 * Include <mach/ledger_server.h> for protos.
54 * Revision 1.1.1.3 1993/08/20 14:16:55 brezak
63 * This is a half-hearted attempt at providing the parts of the
64 * ledger facility to satisfy the ledger interfaces.
66 * This implementation basically leaves the (dysfunctional) ledgers
67 * unfunctional and are mearly here to satisfy the Mach spec interface
71 #include <mach/mach_types.h>
72 #include <mach/message.h>
73 #include <kern/mach_param.h>
74 #include <kern/misc_protos.h>
75 #include <mach/port.h>
76 #include <kern/lock.h>
77 #include <kern/ipc_kobject.h>
78 #include <ipc/ipc_space.h>
79 #include <ipc/ipc_port.h>
80 #include <kern/host.h>
81 #include <kern/ledger.h>
82 #include <mach/ledger_server.h>
84 ledger_t root_wired_ledger
;
85 ledger_t root_paged_ledger
;
88 /* Utility routine to handle entries to a ledger */
94 /* Need to lock the ledger */
98 if (ledger
->ledger_limit
!= LEDGER_ITEM_INFINITY
&&
99 ledger
->ledger_balance
+ amount
> ledger
->ledger_limit
) {
100 /* XXX this is where you do BAD things */
101 printf("Ledger limit exceeded ! ledger=%x lim=%d balance=%d\n",
102 ledger
, ledger
->ledger_limit
,
103 ledger
->ledger_balance
);
104 ledger_unlock(ledger
);
105 return(KERN_RESOURCE_SHORTAGE
);
107 if ((natural_t
)(ledger
->ledger_balance
+ amount
)
108 < LEDGER_ITEM_INFINITY
)
109 ledger
->ledger_balance
+= amount
;
111 ledger
->ledger_balance
= LEDGER_ITEM_INFINITY
;
114 if (ledger
->ledger_balance
+ amount
> 0)
115 ledger
->ledger_balance
+= amount
;
117 ledger
->ledger_balance
= 0;
119 ledger_unlock(ledger
);
120 return(KERN_SUCCESS
);
123 /* Utility routine to create a new ledger */
127 ledger_t ledger_ledger
,
128 ledger_t ledger_parent
)
132 ledger
= (ledger_t
)kalloc(sizeof(ledger_data_t
));
133 if (ledger
== LEDGER_NULL
)
136 ledger
->ledger_self
= ipc_port_alloc_kernel();
137 if (ledger
->ledger_self
== IP_NULL
)
140 ledger_lock_init(ledger
);
141 ledger
->ledger_limit
= limit
;
142 ledger
->ledger_balance
= 0;
143 ledger
->ledger_service_port
= MACH_PORT_NULL
;
144 ledger
->ledger_ledger
= ledger_ledger
;
145 ledger
->ledger_parent
= ledger_parent
;
146 ipc_kobject_set(ledger
->ledger_self
, (ipc_kobject_t
)ledger
,
152 /* Utility routine to destroy a ledger */
157 /* XXX can be many send rights (copies) of this */
158 ipc_port_dealloc_kernel(ledger
->ledger_self
);
160 /* XXX release send right on service port */
161 kfree((vm_offset_t
)ledger
, sizeof(*ledger
));
166 * Inititalize the ledger facility
168 void ledger_init(void)
171 * Allocate the root ledgers; wired and paged.
173 root_wired_ledger
= ledger_allocate(LEDGER_ITEM_INFINITY
,
174 LEDGER_NULL
, LEDGER_NULL
);
175 if (root_wired_ledger
== LEDGER_NULL
)
176 panic("can't allocate root (wired) ledger");
177 ipc_port_make_send(root_wired_ledger
->ledger_self
);
179 root_paged_ledger
= ledger_allocate(LEDGER_ITEM_INFINITY
,
180 LEDGER_NULL
, LEDGER_NULL
);
181 if (root_paged_ledger
== LEDGER_NULL
)
182 panic("can't allocate root (paged) ledger");
183 ipc_port_make_send(root_paged_ledger
->ledger_self
);
187 * Create a subordinate ledger
189 kern_return_t
ledger_create(
190 ledger_t parent_ledger
,
191 ledger_t ledger_ledger
,
192 ledger_t
*new_ledger
,
193 ledger_item_t transfer
)
195 if (parent_ledger
== LEDGER_NULL
)
196 return(KERN_INVALID_ARGUMENT
);
198 if (ledger_ledger
== LEDGER_NULL
)
199 return(KERN_INVALID_LEDGER
);
202 * Allocate a new ledger and change the ledger_ledger for
205 ledger_lock(ledger_ledger
);
206 if ((ledger_ledger
->ledger_limit
!= LEDGER_ITEM_INFINITY
) &&
207 (ledger_ledger
->ledger_balance
+ sizeof(ledger_data_t
) >
208 ledger_ledger
->ledger_limit
)) {
209 ledger_unlock(ledger_ledger
);
210 return(KERN_RESOURCE_SHORTAGE
);
213 *new_ledger
= ledger_allocate(LEDGER_ITEM_INFINITY
, ledger_ledger
, parent_ledger
);
214 if (*new_ledger
== LEDGER_NULL
) {
215 ledger_unlock(ledger_ledger
);
216 return(KERN_RESOURCE_SHORTAGE
);
220 * Now transfer the limit for the new ledger from the parent
222 ledger_lock(parent_ledger
);
223 if (parent_ledger
->ledger_limit
!= LEDGER_ITEM_INFINITY
) {
224 /* Would the existing balance exceed the new limit ? */
225 if (parent_ledger
->ledger_limit
- transfer
< parent_ledger
->ledger_balance
) {
226 ledger_unlock(parent_ledger
);
227 ledger_unlock(ledger_ledger
);
228 return(KERN_RESOURCE_SHORTAGE
);
230 if (parent_ledger
->ledger_limit
- transfer
> 0)
231 parent_ledger
->ledger_limit
-= transfer
;
233 parent_ledger
->ledger_limit
= 0;
235 (*new_ledger
)->ledger_limit
= transfer
;
237 /* Charge the ledger against the ledger_ledger */
238 ledger_ledger
->ledger_balance
+= sizeof(ledger_data_t
);
239 ledger_unlock(parent_ledger
);
241 ledger_unlock(ledger_ledger
);
243 return(KERN_SUCCESS
);
249 kern_return_t
ledger_terminate(
252 if (ledger
== LEDGER_NULL
)
253 return(KERN_INVALID_ARGUMENT
);
255 /* You can't deallocate kernel ledgers */
256 if (ledger
== root_wired_ledger
||
257 ledger
== root_paged_ledger
)
258 return(KERN_INVALID_LEDGER
);
260 /* Lock the ledger */
263 /* the parent ledger gets back the limit */
264 ledger_lock(ledger
->ledger_parent
);
265 if (ledger
->ledger_parent
->ledger_limit
!= LEDGER_ITEM_INFINITY
) {
266 assert((natural_t
)(ledger
->ledger_parent
->ledger_limit
+
267 ledger
->ledger_limit
) <
268 LEDGER_ITEM_INFINITY
);
269 ledger
->ledger_parent
->ledger_limit
+= ledger
->ledger_limit
;
271 ledger_unlock(ledger
->ledger_parent
);
274 * XXX The spec says that you have to destroy all objects that
275 * have been created with this ledger. Nice work eh? For now
276 * Transfer the balance to the parent and let it worry about
279 /* XXX the parent ledger inherits the debt ?? */
280 (void) ledger_enter(ledger
->ledger_parent
, ledger
->ledger_balance
);
282 /* adjust the balance of the creation ledger */
283 (void) ledger_enter(ledger
->ledger_ledger
, -sizeof(*ledger
));
285 /* delete the ledger */
286 ledger_deallocate(ledger
);
288 return(KERN_SUCCESS
);
292 * Return the ledger limit and balance
294 kern_return_t
ledger_read(
296 ledger_item_t
*balance
,
297 ledger_item_t
*limit
)
299 if (ledger
== LEDGER_NULL
)
300 return(KERN_INVALID_ARGUMENT
);
303 *balance
= ledger
->ledger_balance
;
304 *limit
= ledger
->ledger_limit
;
305 ledger_unlock(ledger
);
307 return(KERN_SUCCESS
);
311 * Transfer resources from a parent ledger to a child
313 kern_return_t
ledger_transfer(
314 ledger_t parent_ledger
,
315 ledger_t child_ledger
,
316 ledger_item_t transfer
)
318 #define abs(v) ((v) > 0)?(v):-(v)
321 ledger_item_t amount
= abs(transfer
);
323 if (parent_ledger
== LEDGER_NULL
)
324 return(KERN_INVALID_ARGUMENT
);
326 if (child_ledger
== LEDGER_NULL
)
327 return(KERN_INVALID_ARGUMENT
);
329 /* Must be different ledgers */
330 if (parent_ledger
== child_ledger
)
331 return(KERN_INVALID_ARGUMENT
);
334 return(KERN_SUCCESS
);
336 ledger_lock(child_ledger
);
337 ledger_lock(parent_ledger
);
339 /* XXX Should be the parent you created it from ?? */
340 if (parent_ledger
!= child_ledger
->ledger_parent
) {
341 ledger_unlock(parent_ledger
);
342 ledger_unlock(child_ledger
);
343 return(KERN_INVALID_LEDGER
);
352 dest
= parent_ledger
;
355 if (src
->ledger_limit
!= LEDGER_ITEM_INFINITY
) {
356 /* Would the existing balance exceed the new limit ? */
357 if (src
->ledger_limit
- amount
< src
->ledger_balance
) {
358 ledger_unlock(parent_ledger
);
359 ledger_unlock(child_ledger
);
360 return(KERN_RESOURCE_SHORTAGE
);
362 if (src
->ledger_limit
- amount
> 0)
363 src
->ledger_limit
-= amount
;
365 src
->ledger_limit
= 0;
368 if (dest
->ledger_limit
!= LEDGER_ITEM_INFINITY
) {
369 if ((natural_t
)(dest
->ledger_limit
+ amount
)
370 < LEDGER_ITEM_INFINITY
)
371 dest
->ledger_limit
+= amount
;
373 dest
->ledger_limit
= (LEDGER_ITEM_INFINITY
- 1);
376 ledger_unlock(parent_ledger
);
377 ledger_unlock(child_ledger
);
379 return(KERN_SUCCESS
);
384 * Routine: convert_port_to_ledger
386 * Convert from a port to a ledger.
387 * Doesn't consume the port ref; the ledger produced may be null.
393 convert_port_to_ledger(
396 ledger_t ledger
= LEDGER_NULL
;
398 if (IP_VALID(port
)) {
400 if (ip_active(port
) &&
401 (ip_kotype(port
) == IKOT_LEDGER
))
402 ledger
= (ledger_t
) port
->ip_kobject
;
410 * Routine: convert_ledger_to_port
412 * Convert from a ledger to a port.
413 * Produces a naked send right which may be invalid.
419 convert_ledger_to_port(
424 port
= ipc_port_make_send(ledger
->ledger_self
);
436 /* XXX reference counting */
438 return(ipc_port_copy_send(ledger
->ledger_self
));