svc.c revision 193649
1177633Sdfr/*	$NetBSD: svc.c,v 1.21 2000/07/06 03:10:35 christos Exp $	*/
2177633Sdfr
3177633Sdfr/*
4177633Sdfr * Sun RPC is a product of Sun Microsystems, Inc. and is provided for
5177633Sdfr * unrestricted use provided that this legend is included on all tape
6177633Sdfr * media and as a part of the software program in whole or part.  Users
7177633Sdfr * may copy or modify Sun RPC without charge, but are not authorized
8177633Sdfr * to license or distribute it to anyone else except as part of a product or
9177633Sdfr * program developed by the user.
10177633Sdfr *
11177633Sdfr * SUN RPC IS PROVIDED AS IS WITH NO WARRANTIES OF ANY KIND INCLUDING THE
12177633Sdfr * WARRANTIES OF DESIGN, MERCHANTIBILITY AND FITNESS FOR A PARTICULAR
13177633Sdfr * PURPOSE, OR ARISING FROM A COURSE OF DEALING, USAGE OR TRADE PRACTICE.
14177633Sdfr *
15177633Sdfr * Sun RPC is provided with no support and without any obligation on the
16177633Sdfr * part of Sun Microsystems, Inc. to assist in its use, correction,
17177633Sdfr * modification or enhancement.
18177633Sdfr *
19177633Sdfr * SUN MICROSYSTEMS, INC. SHALL HAVE NO LIABILITY WITH RESPECT TO THE
20177633Sdfr * INFRINGEMENT OF COPYRIGHTS, TRADE SECRETS OR ANY PATENTS BY SUN RPC
21177633Sdfr * OR ANY PART THEREOF.
22177633Sdfr *
23177633Sdfr * In no event will Sun Microsystems, Inc. be liable for any lost revenue
24177633Sdfr * or profits or other special, indirect and consequential damages, even if
25177633Sdfr * Sun has been advised of the possibility of such damages.
26177633Sdfr *
27177633Sdfr * Sun Microsystems, Inc.
28177633Sdfr * 2550 Garcia Avenue
29177633Sdfr * Mountain View, California  94043
30177633Sdfr */
31177633Sdfr
32177633Sdfr#if defined(LIBC_SCCS) && !defined(lint)
33177633Sdfrstatic char *sccsid2 = "@(#)svc.c 1.44 88/02/08 Copyr 1984 Sun Micro";
34177633Sdfrstatic char *sccsid = "@(#)svc.c	2.4 88/08/11 4.0 RPCSRC";
35177633Sdfr#endif
36177633Sdfr#include <sys/cdefs.h>
37177633Sdfr__FBSDID("$FreeBSD: head/sys/rpc/svc.c 193649 2009-06-07 20:38:41Z rmacklem $");
38177633Sdfr
39177633Sdfr/*
40177633Sdfr * svc.c, Server-side remote procedure call interface.
41177633Sdfr *
42177633Sdfr * There are two sets of procedures here.  The xprt routines are
43177633Sdfr * for handling transport handles.  The svc routines handle the
44177633Sdfr * list of service routines.
45177633Sdfr *
46177633Sdfr * Copyright (C) 1984, Sun Microsystems, Inc.
47177633Sdfr */
48177633Sdfr
49177633Sdfr#include <sys/param.h>
50177633Sdfr#include <sys/lock.h>
51177633Sdfr#include <sys/kernel.h>
52184588Sdfr#include <sys/kthread.h>
53177633Sdfr#include <sys/malloc.h>
54184588Sdfr#include <sys/mbuf.h>
55177633Sdfr#include <sys/mutex.h>
56184588Sdfr#include <sys/proc.h>
57177633Sdfr#include <sys/queue.h>
58184588Sdfr#include <sys/socketvar.h>
59177633Sdfr#include <sys/systm.h>
60177633Sdfr#include <sys/ucred.h>
61177633Sdfr
62177633Sdfr#include <rpc/rpc.h>
63177633Sdfr#include <rpc/rpcb_clnt.h>
64184588Sdfr#include <rpc/replay.h>
65177633Sdfr
66177685Sdfr#include <rpc/rpc_com.h>
67177633Sdfr
68177633Sdfr#define SVC_VERSQUIET 0x0001		/* keep quiet about vers mismatch */
69184588Sdfr#define version_keepquiet(xp) (SVC_EXT(xp)->xp_flags & SVC_VERSQUIET)
70177633Sdfr
71177633Sdfrstatic struct svc_callout *svc_find(SVCPOOL *pool, rpcprog_t, rpcvers_t,
72177633Sdfr    char *);
73184588Sdfrstatic void svc_new_thread(SVCPOOL *pool);
74184588Sdfrstatic void xprt_unregister_locked(SVCXPRT *xprt);
75177633Sdfr
76177633Sdfr/* ***************  SVCXPRT related stuff **************** */
77177633Sdfr
78184588Sdfrstatic int svcpool_minthread_sysctl(SYSCTL_HANDLER_ARGS);
79184588Sdfrstatic int svcpool_maxthread_sysctl(SYSCTL_HANDLER_ARGS);
80184588Sdfr
81177633SdfrSVCPOOL*
82184588Sdfrsvcpool_create(const char *name, struct sysctl_oid_list *sysctl_base)
83177633Sdfr{
84177633Sdfr	SVCPOOL *pool;
85177633Sdfr
86177633Sdfr	pool = malloc(sizeof(SVCPOOL), M_RPC, M_WAITOK|M_ZERO);
87177633Sdfr
88177633Sdfr	mtx_init(&pool->sp_lock, "sp_lock", NULL, MTX_DEF);
89184588Sdfr	pool->sp_name = name;
90184588Sdfr	pool->sp_state = SVCPOOL_INIT;
91184588Sdfr	pool->sp_proc = NULL;
92177633Sdfr	TAILQ_INIT(&pool->sp_xlist);
93177633Sdfr	TAILQ_INIT(&pool->sp_active);
94177633Sdfr	TAILQ_INIT(&pool->sp_callouts);
95184588Sdfr	LIST_INIT(&pool->sp_threads);
96184588Sdfr	LIST_INIT(&pool->sp_idlethreads);
97184588Sdfr	pool->sp_minthreads = 1;
98184588Sdfr	pool->sp_maxthreads = 1;
99184588Sdfr	pool->sp_threadcount = 0;
100177633Sdfr
101184588Sdfr	/*
102184588Sdfr	 * Don't use more than a quarter of mbuf clusters or more than
103184588Sdfr	 * 45Mb buffering requests.
104184588Sdfr	 */
105184588Sdfr	pool->sp_space_high = nmbclusters * MCLBYTES / 4;
106184588Sdfr	if (pool->sp_space_high > 45 << 20)
107184588Sdfr		pool->sp_space_high = 45 << 20;
108184588Sdfr	pool->sp_space_low = 2 * pool->sp_space_high / 3;
109184588Sdfr
110184588Sdfr	sysctl_ctx_init(&pool->sp_sysctl);
111184588Sdfr	if (sysctl_base) {
112184588Sdfr		SYSCTL_ADD_PROC(&pool->sp_sysctl, sysctl_base, OID_AUTO,
113184588Sdfr		    "minthreads", CTLTYPE_INT | CTLFLAG_RW,
114184588Sdfr		    pool, 0, svcpool_minthread_sysctl, "I", "");
115184588Sdfr		SYSCTL_ADD_PROC(&pool->sp_sysctl, sysctl_base, OID_AUTO,
116184588Sdfr		    "maxthreads", CTLTYPE_INT | CTLFLAG_RW,
117184588Sdfr		    pool, 0, svcpool_maxthread_sysctl, "I", "");
118184588Sdfr		SYSCTL_ADD_INT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
119184588Sdfr		    "threads", CTLFLAG_RD, &pool->sp_threadcount, 0, "");
120184588Sdfr
121184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
122184588Sdfr		    "request_space_used", CTLFLAG_RD,
123184588Sdfr		    &pool->sp_space_used, 0,
124184588Sdfr		    "Space in parsed but not handled requests.");
125184588Sdfr
126184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
127184588Sdfr		    "request_space_used_highest", CTLFLAG_RD,
128184588Sdfr		    &pool->sp_space_used_highest, 0,
129184588Sdfr		    "Highest space used since reboot.");
130184588Sdfr
131184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
132184588Sdfr		    "request_space_high", CTLFLAG_RW,
133184588Sdfr		    &pool->sp_space_high, 0,
134184588Sdfr		    "Maximum space in parsed but not handled requests.");
135184588Sdfr
136184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
137184588Sdfr		    "request_space_low", CTLFLAG_RW,
138184588Sdfr		    &pool->sp_space_low, 0,
139184588Sdfr		    "Low water mark for request space.");
140184588Sdfr
141184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
142184588Sdfr		    "request_space_throttled", CTLFLAG_RD,
143184588Sdfr		    &pool->sp_space_throttled, 0,
144184588Sdfr		    "Whether nfs requests are currently throttled");
145184588Sdfr
146184588Sdfr		SYSCTL_ADD_UINT(&pool->sp_sysctl, sysctl_base, OID_AUTO,
147184588Sdfr		    "request_space_throttle_count", CTLFLAG_RD,
148184588Sdfr		    &pool->sp_space_throttle_count, 0,
149184588Sdfr		    "Count of times throttling based on request space has occurred");
150184588Sdfr	}
151184588Sdfr
152177633Sdfr	return pool;
153177633Sdfr}
154177633Sdfr
155177633Sdfrvoid
156177633Sdfrsvcpool_destroy(SVCPOOL *pool)
157177633Sdfr{
158184588Sdfr	SVCXPRT *xprt, *nxprt;
159177633Sdfr	struct svc_callout *s;
160184588Sdfr	struct svcxprt_list cleanup;
161177633Sdfr
162184588Sdfr	TAILQ_INIT(&cleanup);
163177633Sdfr	mtx_lock(&pool->sp_lock);
164177633Sdfr
165177633Sdfr	while (TAILQ_FIRST(&pool->sp_xlist)) {
166177633Sdfr		xprt = TAILQ_FIRST(&pool->sp_xlist);
167184588Sdfr		xprt_unregister_locked(xprt);
168184588Sdfr		TAILQ_INSERT_TAIL(&cleanup, xprt, xp_link);
169177633Sdfr	}
170177633Sdfr
171177633Sdfr	while (TAILQ_FIRST(&pool->sp_callouts)) {
172177633Sdfr		s = TAILQ_FIRST(&pool->sp_callouts);
173177633Sdfr		mtx_unlock(&pool->sp_lock);
174177633Sdfr		svc_unreg(pool, s->sc_prog, s->sc_vers);
175177633Sdfr		mtx_lock(&pool->sp_lock);
176177633Sdfr	}
177193603Srmacklem	mtx_unlock(&pool->sp_lock);
178177633Sdfr
179184588Sdfr	TAILQ_FOREACH_SAFE(xprt, &cleanup, xp_link, nxprt) {
180184588Sdfr		SVC_RELEASE(xprt);
181184588Sdfr	}
182184588Sdfr
183193436Srmacklem	mtx_destroy(&pool->sp_lock);
184193436Srmacklem
185184588Sdfr	if (pool->sp_rcache)
186184588Sdfr		replay_freecache(pool->sp_rcache);
187184588Sdfr
188184588Sdfr	sysctl_ctx_free(&pool->sp_sysctl);
189177633Sdfr	free(pool, M_RPC);
190177633Sdfr}
191177633Sdfr
192184588Sdfrstatic bool_t
193184588Sdfrsvcpool_active(SVCPOOL *pool)
194184588Sdfr{
195184588Sdfr	enum svcpool_state state = pool->sp_state;
196184588Sdfr
197184588Sdfr	if (state == SVCPOOL_INIT || state == SVCPOOL_CLOSING)
198184588Sdfr		return (FALSE);
199184588Sdfr	return (TRUE);
200184588Sdfr}
201184588Sdfr
202177633Sdfr/*
203184588Sdfr * Sysctl handler to set the minimum thread count on a pool
204184588Sdfr */
205184588Sdfrstatic int
206184588Sdfrsvcpool_minthread_sysctl(SYSCTL_HANDLER_ARGS)
207184588Sdfr{
208184588Sdfr	SVCPOOL *pool;
209184588Sdfr	int newminthreads, error, n;
210184588Sdfr
211184588Sdfr	pool = oidp->oid_arg1;
212184588Sdfr	newminthreads = pool->sp_minthreads;
213184588Sdfr	error = sysctl_handle_int(oidp, &newminthreads, 0, req);
214184588Sdfr	if (error == 0 && newminthreads != pool->sp_minthreads) {
215184588Sdfr		if (newminthreads > pool->sp_maxthreads)
216184588Sdfr			return (EINVAL);
217184588Sdfr		mtx_lock(&pool->sp_lock);
218184588Sdfr		if (newminthreads > pool->sp_minthreads
219184588Sdfr		    && svcpool_active(pool)) {
220184588Sdfr			/*
221184588Sdfr			 * If the pool is running and we are
222184588Sdfr			 * increasing, create some more threads now.
223184588Sdfr			 */
224184588Sdfr			n = newminthreads - pool->sp_threadcount;
225184588Sdfr			if (n > 0) {
226184588Sdfr				mtx_unlock(&pool->sp_lock);
227184588Sdfr				while (n--)
228184588Sdfr					svc_new_thread(pool);
229184588Sdfr				mtx_lock(&pool->sp_lock);
230184588Sdfr			}
231184588Sdfr		}
232184588Sdfr		pool->sp_minthreads = newminthreads;
233184588Sdfr		mtx_unlock(&pool->sp_lock);
234184588Sdfr	}
235184588Sdfr	return (error);
236184588Sdfr}
237184588Sdfr
238184588Sdfr/*
239184588Sdfr * Sysctl handler to set the maximum thread count on a pool
240184588Sdfr */
241184588Sdfrstatic int
242184588Sdfrsvcpool_maxthread_sysctl(SYSCTL_HANDLER_ARGS)
243184588Sdfr{
244184588Sdfr	SVCPOOL *pool;
245184588Sdfr	SVCTHREAD *st;
246184588Sdfr	int newmaxthreads, error;
247184588Sdfr
248184588Sdfr	pool = oidp->oid_arg1;
249184588Sdfr	newmaxthreads = pool->sp_maxthreads;
250184588Sdfr	error = sysctl_handle_int(oidp, &newmaxthreads, 0, req);
251184588Sdfr	if (error == 0 && newmaxthreads != pool->sp_maxthreads) {
252184588Sdfr		if (newmaxthreads < pool->sp_minthreads)
253184588Sdfr			return (EINVAL);
254184588Sdfr		mtx_lock(&pool->sp_lock);
255184588Sdfr		if (newmaxthreads < pool->sp_maxthreads
256184588Sdfr		    && svcpool_active(pool)) {
257184588Sdfr			/*
258184588Sdfr			 * If the pool is running and we are
259184588Sdfr			 * decreasing, wake up some idle threads to
260184588Sdfr			 * encourage them to exit.
261184588Sdfr			 */
262184588Sdfr			LIST_FOREACH(st, &pool->sp_idlethreads, st_ilink)
263184588Sdfr				cv_signal(&st->st_cond);
264184588Sdfr		}
265184588Sdfr		pool->sp_maxthreads = newmaxthreads;
266184588Sdfr		mtx_unlock(&pool->sp_lock);
267184588Sdfr	}
268184588Sdfr	return (error);
269184588Sdfr}
270184588Sdfr
271184588Sdfr/*
272177633Sdfr * Activate a transport handle.
273177633Sdfr */
274177633Sdfrvoid
275177633Sdfrxprt_register(SVCXPRT *xprt)
276177633Sdfr{
277177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
278177633Sdfr
279177633Sdfr	mtx_lock(&pool->sp_lock);
280177633Sdfr	xprt->xp_registered = TRUE;
281177633Sdfr	xprt->xp_active = FALSE;
282177633Sdfr	TAILQ_INSERT_TAIL(&pool->sp_xlist, xprt, xp_link);
283177633Sdfr	mtx_unlock(&pool->sp_lock);
284177633Sdfr}
285177633Sdfr
286177633Sdfr/*
287184588Sdfr * De-activate a transport handle. Note: the locked version doesn't
288184588Sdfr * release the transport - caller must do that after dropping the pool
289184588Sdfr * lock.
290177633Sdfr */
291177633Sdfrstatic void
292184588Sdfrxprt_unregister_locked(SVCXPRT *xprt)
293177633Sdfr{
294177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
295177633Sdfr
296193649Srmacklem	KASSERT(xprt->xp_registered == TRUE,
297193649Srmacklem	    ("xprt_unregister_locked: not registered"));
298177633Sdfr	if (xprt->xp_active) {
299177633Sdfr		TAILQ_REMOVE(&pool->sp_active, xprt, xp_alink);
300177633Sdfr		xprt->xp_active = FALSE;
301177633Sdfr	}
302177633Sdfr	TAILQ_REMOVE(&pool->sp_xlist, xprt, xp_link);
303177633Sdfr	xprt->xp_registered = FALSE;
304184588Sdfr}
305177633Sdfr
306184588Sdfrvoid
307184588Sdfrxprt_unregister(SVCXPRT *xprt)
308184588Sdfr{
309184588Sdfr	SVCPOOL *pool = xprt->xp_pool;
310184588Sdfr
311184588Sdfr	mtx_lock(&pool->sp_lock);
312193649Srmacklem	if (xprt->xp_registered == FALSE) {
313193649Srmacklem		/* Already unregistered by another thread */
314193649Srmacklem		mtx_unlock(&pool->sp_lock);
315193649Srmacklem		return;
316193649Srmacklem	}
317184588Sdfr	xprt_unregister_locked(xprt);
318184588Sdfr	mtx_unlock(&pool->sp_lock);
319184588Sdfr
320184588Sdfr	SVC_RELEASE(xprt);
321177633Sdfr}
322177633Sdfr
323184588Sdfrstatic void
324184588Sdfrxprt_assignthread(SVCXPRT *xprt)
325184588Sdfr{
326184588Sdfr	SVCPOOL *pool = xprt->xp_pool;
327184588Sdfr	SVCTHREAD *st;
328184588Sdfr
329184588Sdfr	/*
330184588Sdfr	 * Attempt to assign a service thread to this
331184588Sdfr	 * transport.
332184588Sdfr	 */
333184588Sdfr	LIST_FOREACH(st, &pool->sp_idlethreads, st_ilink) {
334184588Sdfr		if (st->st_xprt == NULL && STAILQ_EMPTY(&st->st_reqs))
335184588Sdfr			break;
336184588Sdfr	}
337184588Sdfr	if (st) {
338184588Sdfr		SVC_ACQUIRE(xprt);
339184588Sdfr		xprt->xp_thread = st;
340184588Sdfr		st->st_xprt = xprt;
341184588Sdfr		cv_signal(&st->st_cond);
342184588Sdfr	} else {
343184588Sdfr		/*
344184588Sdfr		 * See if we can create a new thread. The
345184588Sdfr		 * actual thread creation happens in
346184588Sdfr		 * svc_run_internal because our locking state
347184588Sdfr		 * is poorly defined (we are typically called
348184588Sdfr		 * from a socket upcall). Don't create more
349184588Sdfr		 * than one thread per second.
350184588Sdfr		 */
351184588Sdfr		if (pool->sp_state == SVCPOOL_ACTIVE
352184588Sdfr		    && pool->sp_lastcreatetime < time_uptime
353184588Sdfr		    && pool->sp_threadcount < pool->sp_maxthreads) {
354184588Sdfr			pool->sp_state = SVCPOOL_THREADWANTED;
355184588Sdfr		}
356184588Sdfr	}
357184588Sdfr}
358184588Sdfr
359177633Sdfrvoid
360177633Sdfrxprt_active(SVCXPRT *xprt)
361177633Sdfr{
362177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
363177633Sdfr
364193436Srmacklem	mtx_lock(&pool->sp_lock);
365193436Srmacklem
366184588Sdfr	if (!xprt->xp_registered) {
367184588Sdfr		/*
368184588Sdfr		 * Race with xprt_unregister - we lose.
369184588Sdfr		 */
370193436Srmacklem		mtx_unlock(&pool->sp_lock);
371184588Sdfr		return;
372184588Sdfr	}
373184588Sdfr
374177633Sdfr	if (!xprt->xp_active) {
375177633Sdfr		TAILQ_INSERT_TAIL(&pool->sp_active, xprt, xp_alink);
376177633Sdfr		xprt->xp_active = TRUE;
377184588Sdfr		xprt_assignthread(xprt);
378177633Sdfr	}
379177633Sdfr
380177633Sdfr	mtx_unlock(&pool->sp_lock);
381177633Sdfr}
382177633Sdfr
383177633Sdfrvoid
384184588Sdfrxprt_inactive_locked(SVCXPRT *xprt)
385177633Sdfr{
386177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
387177633Sdfr
388177633Sdfr	if (xprt->xp_active) {
389177633Sdfr		TAILQ_REMOVE(&pool->sp_active, xprt, xp_alink);
390177633Sdfr		xprt->xp_active = FALSE;
391177633Sdfr	}
392184588Sdfr}
393177633Sdfr
394184588Sdfrvoid
395184588Sdfrxprt_inactive(SVCXPRT *xprt)
396184588Sdfr{
397184588Sdfr	SVCPOOL *pool = xprt->xp_pool;
398184588Sdfr
399184588Sdfr	mtx_lock(&pool->sp_lock);
400184588Sdfr	xprt_inactive_locked(xprt);
401177633Sdfr	mtx_unlock(&pool->sp_lock);
402177633Sdfr}
403177633Sdfr
404177633Sdfr/*
405177633Sdfr * Add a service program to the callout list.
406177633Sdfr * The dispatch routine will be called when a rpc request for this
407177633Sdfr * program number comes in.
408177633Sdfr */
409177633Sdfrbool_t
410177633Sdfrsvc_reg(SVCXPRT *xprt, const rpcprog_t prog, const rpcvers_t vers,
411177633Sdfr    void (*dispatch)(struct svc_req *, SVCXPRT *),
412177633Sdfr    const struct netconfig *nconf)
413177633Sdfr{
414177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
415177633Sdfr	struct svc_callout *s;
416177633Sdfr	char *netid = NULL;
417177633Sdfr	int flag = 0;
418177633Sdfr
419177633Sdfr/* VARIABLES PROTECTED BY svc_lock: s, svc_head */
420177633Sdfr
421177633Sdfr	if (xprt->xp_netid) {
422177633Sdfr		netid = strdup(xprt->xp_netid, M_RPC);
423177633Sdfr		flag = 1;
424177633Sdfr	} else if (nconf && nconf->nc_netid) {
425177633Sdfr		netid = strdup(nconf->nc_netid, M_RPC);
426177633Sdfr		flag = 1;
427177633Sdfr	} /* must have been created with svc_raw_create */
428177633Sdfr	if ((netid == NULL) && (flag == 1)) {
429177633Sdfr		return (FALSE);
430177633Sdfr	}
431177633Sdfr
432177633Sdfr	mtx_lock(&pool->sp_lock);
433177633Sdfr	if ((s = svc_find(pool, prog, vers, netid)) != NULL) {
434177633Sdfr		if (netid)
435177633Sdfr			free(netid, M_RPC);
436177633Sdfr		if (s->sc_dispatch == dispatch)
437177633Sdfr			goto rpcb_it; /* he is registering another xptr */
438177633Sdfr		mtx_unlock(&pool->sp_lock);
439177633Sdfr		return (FALSE);
440177633Sdfr	}
441177633Sdfr	s = malloc(sizeof (struct svc_callout), M_RPC, M_NOWAIT);
442177633Sdfr	if (s == NULL) {
443177633Sdfr		if (netid)
444177633Sdfr			free(netid, M_RPC);
445177633Sdfr		mtx_unlock(&pool->sp_lock);
446177633Sdfr		return (FALSE);
447177633Sdfr	}
448177633Sdfr
449177633Sdfr	s->sc_prog = prog;
450177633Sdfr	s->sc_vers = vers;
451177633Sdfr	s->sc_dispatch = dispatch;
452177633Sdfr	s->sc_netid = netid;
453177633Sdfr	TAILQ_INSERT_TAIL(&pool->sp_callouts, s, sc_link);
454177633Sdfr
455177633Sdfr	if ((xprt->xp_netid == NULL) && (flag == 1) && netid)
456177633Sdfr		((SVCXPRT *) xprt)->xp_netid = strdup(netid, M_RPC);
457177633Sdfr
458177633Sdfrrpcb_it:
459177633Sdfr	mtx_unlock(&pool->sp_lock);
460177633Sdfr	/* now register the information with the local binder service */
461177633Sdfr	if (nconf) {
462177633Sdfr		bool_t dummy;
463177633Sdfr		struct netconfig tnc;
464184588Sdfr		struct netbuf nb;
465177633Sdfr		tnc = *nconf;
466184588Sdfr		nb.buf = &xprt->xp_ltaddr;
467184588Sdfr		nb.len = xprt->xp_ltaddr.ss_len;
468184588Sdfr		dummy = rpcb_set(prog, vers, &tnc, &nb);
469177633Sdfr		return (dummy);
470177633Sdfr	}
471177633Sdfr	return (TRUE);
472177633Sdfr}
473177633Sdfr
474177633Sdfr/*
475177633Sdfr * Remove a service program from the callout list.
476177633Sdfr */
477177633Sdfrvoid
478177633Sdfrsvc_unreg(SVCPOOL *pool, const rpcprog_t prog, const rpcvers_t vers)
479177633Sdfr{
480177633Sdfr	struct svc_callout *s;
481177633Sdfr
482177633Sdfr	/* unregister the information anyway */
483177633Sdfr	(void) rpcb_unset(prog, vers, NULL);
484177633Sdfr	mtx_lock(&pool->sp_lock);
485177633Sdfr	while ((s = svc_find(pool, prog, vers, NULL)) != NULL) {
486177633Sdfr		TAILQ_REMOVE(&pool->sp_callouts, s, sc_link);
487177633Sdfr		if (s->sc_netid)
488177633Sdfr			mem_free(s->sc_netid, sizeof (s->sc_netid) + 1);
489177633Sdfr		mem_free(s, sizeof (struct svc_callout));
490177633Sdfr	}
491177633Sdfr	mtx_unlock(&pool->sp_lock);
492177633Sdfr}
493177633Sdfr
494177633Sdfr/* ********************** CALLOUT list related stuff ************* */
495177633Sdfr
496177633Sdfr/*
497177633Sdfr * Search the callout list for a program number, return the callout
498177633Sdfr * struct.
499177633Sdfr */
500177633Sdfrstatic struct svc_callout *
501177633Sdfrsvc_find(SVCPOOL *pool, rpcprog_t prog, rpcvers_t vers, char *netid)
502177633Sdfr{
503177633Sdfr	struct svc_callout *s;
504177633Sdfr
505177633Sdfr	mtx_assert(&pool->sp_lock, MA_OWNED);
506177633Sdfr	TAILQ_FOREACH(s, &pool->sp_callouts, sc_link) {
507177633Sdfr		if (s->sc_prog == prog && s->sc_vers == vers
508177633Sdfr		    && (netid == NULL || s->sc_netid == NULL ||
509177633Sdfr			strcmp(netid, s->sc_netid) == 0))
510177633Sdfr			break;
511177633Sdfr	}
512177633Sdfr
513177633Sdfr	return (s);
514177633Sdfr}
515177633Sdfr
516177633Sdfr/* ******************* REPLY GENERATION ROUTINES  ************ */
517177633Sdfr
518184588Sdfrstatic bool_t
519184588Sdfrsvc_sendreply_common(struct svc_req *rqstp, struct rpc_msg *rply,
520184588Sdfr    struct mbuf *body)
521184588Sdfr{
522184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
523184588Sdfr	bool_t ok;
524184588Sdfr
525184588Sdfr	if (rqstp->rq_args) {
526184588Sdfr		m_freem(rqstp->rq_args);
527184588Sdfr		rqstp->rq_args = NULL;
528184588Sdfr	}
529184588Sdfr
530184588Sdfr	if (xprt->xp_pool->sp_rcache)
531184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
532184588Sdfr		    rply, svc_getrpccaller(rqstp), body);
533184588Sdfr
534184588Sdfr	if (!SVCAUTH_WRAP(&rqstp->rq_auth, &body))
535184588Sdfr		return (FALSE);
536184588Sdfr
537184588Sdfr	ok = SVC_REPLY(xprt, rply, rqstp->rq_addr, body);
538184588Sdfr	if (rqstp->rq_addr) {
539184588Sdfr		free(rqstp->rq_addr, M_SONAME);
540184588Sdfr		rqstp->rq_addr = NULL;
541184588Sdfr	}
542184588Sdfr
543184588Sdfr	return (ok);
544184588Sdfr}
545184588Sdfr
546177633Sdfr/*
547177633Sdfr * Send a reply to an rpc request
548177633Sdfr */
549177633Sdfrbool_t
550184588Sdfrsvc_sendreply(struct svc_req *rqstp, xdrproc_t xdr_results, void * xdr_location)
551177633Sdfr{
552177633Sdfr	struct rpc_msg rply;
553184588Sdfr	struct mbuf *m;
554184588Sdfr	XDR xdrs;
555184588Sdfr	bool_t ok;
556177633Sdfr
557184588Sdfr	rply.rm_xid = rqstp->rq_xid;
558177633Sdfr	rply.rm_direction = REPLY;
559177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
560184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
561177633Sdfr	rply.acpted_rply.ar_stat = SUCCESS;
562184588Sdfr	rply.acpted_rply.ar_results.where = NULL;
563184588Sdfr	rply.acpted_rply.ar_results.proc = (xdrproc_t) xdr_void;
564177633Sdfr
565184588Sdfr	MGET(m, M_WAIT, MT_DATA);
566184588Sdfr	MCLGET(m, M_WAIT);
567184588Sdfr	m->m_len = 0;
568184588Sdfr	xdrmbuf_create(&xdrs, m, XDR_ENCODE);
569184588Sdfr	ok = xdr_results(&xdrs, xdr_location);
570184588Sdfr	XDR_DESTROY(&xdrs);
571184588Sdfr
572184588Sdfr	if (ok) {
573184588Sdfr		return (svc_sendreply_common(rqstp, &rply, m));
574184588Sdfr	} else {
575184588Sdfr		m_freem(m);
576184588Sdfr		return (FALSE);
577184588Sdfr	}
578177633Sdfr}
579177633Sdfr
580184588Sdfrbool_t
581184588Sdfrsvc_sendreply_mbuf(struct svc_req *rqstp, struct mbuf *m)
582184588Sdfr{
583184588Sdfr	struct rpc_msg rply;
584184588Sdfr
585184588Sdfr	rply.rm_xid = rqstp->rq_xid;
586184588Sdfr	rply.rm_direction = REPLY;
587184588Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
588184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
589184588Sdfr	rply.acpted_rply.ar_stat = SUCCESS;
590184588Sdfr	rply.acpted_rply.ar_results.where = NULL;
591184588Sdfr	rply.acpted_rply.ar_results.proc = (xdrproc_t) xdr_void;
592184588Sdfr
593184588Sdfr	return (svc_sendreply_common(rqstp, &rply, m));
594184588Sdfr}
595184588Sdfr
596177633Sdfr/*
597177633Sdfr * No procedure error reply
598177633Sdfr */
599177633Sdfrvoid
600184588Sdfrsvcerr_noproc(struct svc_req *rqstp)
601177633Sdfr{
602184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
603177633Sdfr	struct rpc_msg rply;
604177633Sdfr
605184588Sdfr	rply.rm_xid = rqstp->rq_xid;
606177633Sdfr	rply.rm_direction = REPLY;
607177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
608184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
609177633Sdfr	rply.acpted_rply.ar_stat = PROC_UNAVAIL;
610177633Sdfr
611184588Sdfr	if (xprt->xp_pool->sp_rcache)
612184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
613184588Sdfr		    &rply, svc_getrpccaller(rqstp), NULL);
614184588Sdfr
615184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
616177633Sdfr}
617177633Sdfr
618177633Sdfr/*
619177633Sdfr * Can't decode args error reply
620177633Sdfr */
621177633Sdfrvoid
622184588Sdfrsvcerr_decode(struct svc_req *rqstp)
623177633Sdfr{
624184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
625177633Sdfr	struct rpc_msg rply;
626177633Sdfr
627184588Sdfr	rply.rm_xid = rqstp->rq_xid;
628177633Sdfr	rply.rm_direction = REPLY;
629177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
630184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
631177633Sdfr	rply.acpted_rply.ar_stat = GARBAGE_ARGS;
632177633Sdfr
633184588Sdfr	if (xprt->xp_pool->sp_rcache)
634184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
635184588Sdfr		    &rply, (struct sockaddr *) &xprt->xp_rtaddr, NULL);
636184588Sdfr
637184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
638177633Sdfr}
639177633Sdfr
640177633Sdfr/*
641177633Sdfr * Some system error
642177633Sdfr */
643177633Sdfrvoid
644184588Sdfrsvcerr_systemerr(struct svc_req *rqstp)
645177633Sdfr{
646184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
647177633Sdfr	struct rpc_msg rply;
648177633Sdfr
649184588Sdfr	rply.rm_xid = rqstp->rq_xid;
650177633Sdfr	rply.rm_direction = REPLY;
651177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
652184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
653177633Sdfr	rply.acpted_rply.ar_stat = SYSTEM_ERR;
654177633Sdfr
655184588Sdfr	if (xprt->xp_pool->sp_rcache)
656184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
657184588Sdfr		    &rply, svc_getrpccaller(rqstp), NULL);
658184588Sdfr
659184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
660177633Sdfr}
661177633Sdfr
662177633Sdfr/*
663177633Sdfr * Authentication error reply
664177633Sdfr */
665177633Sdfrvoid
666184588Sdfrsvcerr_auth(struct svc_req *rqstp, enum auth_stat why)
667177633Sdfr{
668184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
669177633Sdfr	struct rpc_msg rply;
670177633Sdfr
671184588Sdfr	rply.rm_xid = rqstp->rq_xid;
672177633Sdfr	rply.rm_direction = REPLY;
673177633Sdfr	rply.rm_reply.rp_stat = MSG_DENIED;
674177633Sdfr	rply.rjcted_rply.rj_stat = AUTH_ERROR;
675177633Sdfr	rply.rjcted_rply.rj_why = why;
676177633Sdfr
677184588Sdfr	if (xprt->xp_pool->sp_rcache)
678184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
679184588Sdfr		    &rply, svc_getrpccaller(rqstp), NULL);
680184588Sdfr
681184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
682177633Sdfr}
683177633Sdfr
684177633Sdfr/*
685177633Sdfr * Auth too weak error reply
686177633Sdfr */
687177633Sdfrvoid
688184588Sdfrsvcerr_weakauth(struct svc_req *rqstp)
689177633Sdfr{
690177633Sdfr
691184588Sdfr	svcerr_auth(rqstp, AUTH_TOOWEAK);
692177633Sdfr}
693177633Sdfr
694177633Sdfr/*
695177633Sdfr * Program unavailable error reply
696177633Sdfr */
697177633Sdfrvoid
698184588Sdfrsvcerr_noprog(struct svc_req *rqstp)
699177633Sdfr{
700184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
701177633Sdfr	struct rpc_msg rply;
702177633Sdfr
703184588Sdfr	rply.rm_xid = rqstp->rq_xid;
704177633Sdfr	rply.rm_direction = REPLY;
705177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
706184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
707177633Sdfr	rply.acpted_rply.ar_stat = PROG_UNAVAIL;
708177633Sdfr
709184588Sdfr	if (xprt->xp_pool->sp_rcache)
710184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
711184588Sdfr		    &rply, svc_getrpccaller(rqstp), NULL);
712184588Sdfr
713184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
714177633Sdfr}
715177633Sdfr
716177633Sdfr/*
717177633Sdfr * Program version mismatch error reply
718177633Sdfr */
719177633Sdfrvoid
720184588Sdfrsvcerr_progvers(struct svc_req *rqstp, rpcvers_t low_vers, rpcvers_t high_vers)
721177633Sdfr{
722184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
723177633Sdfr	struct rpc_msg rply;
724177633Sdfr
725184588Sdfr	rply.rm_xid = rqstp->rq_xid;
726177633Sdfr	rply.rm_direction = REPLY;
727177633Sdfr	rply.rm_reply.rp_stat = MSG_ACCEPTED;
728184588Sdfr	rply.acpted_rply.ar_verf = rqstp->rq_verf;
729177633Sdfr	rply.acpted_rply.ar_stat = PROG_MISMATCH;
730177633Sdfr	rply.acpted_rply.ar_vers.low = (uint32_t)low_vers;
731177633Sdfr	rply.acpted_rply.ar_vers.high = (uint32_t)high_vers;
732177633Sdfr
733184588Sdfr	if (xprt->xp_pool->sp_rcache)
734184588Sdfr		replay_setreply(xprt->xp_pool->sp_rcache,
735184588Sdfr		    &rply, svc_getrpccaller(rqstp), NULL);
736184588Sdfr
737184588Sdfr	svc_sendreply_common(rqstp, &rply, NULL);
738177633Sdfr}
739177633Sdfr
740184588Sdfr/*
741184588Sdfr * Allocate a new server transport structure. All fields are
742184588Sdfr * initialized to zero and xp_p3 is initialized to point at an
743184588Sdfr * extension structure to hold various flags and authentication
744184588Sdfr * parameters.
745184588Sdfr */
746184588SdfrSVCXPRT *
747184588Sdfrsvc_xprt_alloc()
748184588Sdfr{
749184588Sdfr	SVCXPRT *xprt;
750184588Sdfr	SVCXPRT_EXT *ext;
751184588Sdfr
752184588Sdfr	xprt = mem_alloc(sizeof(SVCXPRT));
753184588Sdfr	memset(xprt, 0, sizeof(SVCXPRT));
754184588Sdfr	ext = mem_alloc(sizeof(SVCXPRT_EXT));
755184588Sdfr	memset(ext, 0, sizeof(SVCXPRT_EXT));
756184588Sdfr	xprt->xp_p3 = ext;
757184588Sdfr	refcount_init(&xprt->xp_refs, 1);
758184588Sdfr
759184588Sdfr	return (xprt);
760184588Sdfr}
761184588Sdfr
762184588Sdfr/*
763184588Sdfr * Free a server transport structure.
764184588Sdfr */
765184588Sdfrvoid
766184588Sdfrsvc_xprt_free(xprt)
767184588Sdfr	SVCXPRT *xprt;
768184588Sdfr{
769184588Sdfr
770184588Sdfr	mem_free(xprt->xp_p3, sizeof(SVCXPRT_EXT));
771184588Sdfr	mem_free(xprt, sizeof(SVCXPRT));
772184588Sdfr}
773184588Sdfr
774177633Sdfr/* ******************* SERVER INPUT STUFF ******************* */
775177633Sdfr
776177633Sdfr/*
777184588Sdfr * Read RPC requests from a transport and queue them to be
778184588Sdfr * executed. We handle authentication and replay cache replies here.
779184588Sdfr * Actually dispatching the RPC is deferred till svc_executereq.
780177633Sdfr */
781184588Sdfrstatic enum xprt_stat
782184588Sdfrsvc_getreq(SVCXPRT *xprt, struct svc_req **rqstp_ret)
783177633Sdfr{
784177633Sdfr	SVCPOOL *pool = xprt->xp_pool;
785184588Sdfr	struct svc_req *r;
786177633Sdfr	struct rpc_msg msg;
787184588Sdfr	struct mbuf *args;
788177633Sdfr	enum xprt_stat stat;
789177633Sdfr
790177633Sdfr	/* now receive msgs from xprtprt (support batch calls) */
791184588Sdfr	r = malloc(sizeof(*r), M_RPC, M_WAITOK|M_ZERO);
792177633Sdfr
793184588Sdfr	msg.rm_call.cb_cred.oa_base = r->rq_credarea;
794184588Sdfr	msg.rm_call.cb_verf.oa_base = &r->rq_credarea[MAX_AUTH_BYTES];
795184588Sdfr	r->rq_clntcred = &r->rq_credarea[2*MAX_AUTH_BYTES];
796184588Sdfr	if (SVC_RECV(xprt, &msg, &r->rq_addr, &args)) {
797184588Sdfr		enum auth_stat why;
798177633Sdfr
799184588Sdfr		/*
800184588Sdfr		 * Handle replays and authenticate before queuing the
801184588Sdfr		 * request to be executed.
802184588Sdfr		 */
803184588Sdfr		SVC_ACQUIRE(xprt);
804184588Sdfr		r->rq_xprt = xprt;
805184588Sdfr		if (pool->sp_rcache) {
806184588Sdfr			struct rpc_msg repmsg;
807184588Sdfr			struct mbuf *repbody;
808184588Sdfr			enum replay_state rs;
809184588Sdfr			rs = replay_find(pool->sp_rcache, &msg,
810184588Sdfr			    svc_getrpccaller(r), &repmsg, &repbody);
811184588Sdfr			switch (rs) {
812184588Sdfr			case RS_NEW:
813184588Sdfr				break;
814184588Sdfr			case RS_DONE:
815184588Sdfr				SVC_REPLY(xprt, &repmsg, r->rq_addr,
816184588Sdfr				    repbody);
817184588Sdfr				if (r->rq_addr) {
818184588Sdfr					free(r->rq_addr, M_SONAME);
819184588Sdfr					r->rq_addr = NULL;
820184588Sdfr				}
821177633Sdfr				goto call_done;
822184588Sdfr
823184588Sdfr			default:
824184588Sdfr				goto call_done;
825177633Sdfr			}
826184588Sdfr		}
827184588Sdfr
828184588Sdfr		r->rq_xid = msg.rm_xid;
829184588Sdfr		r->rq_prog = msg.rm_call.cb_prog;
830184588Sdfr		r->rq_vers = msg.rm_call.cb_vers;
831184588Sdfr		r->rq_proc = msg.rm_call.cb_proc;
832184588Sdfr		r->rq_size = sizeof(*r) + m_length(args, NULL);
833184588Sdfr		r->rq_args = args;
834184588Sdfr		if ((why = _authenticate(r, &msg)) != AUTH_OK) {
835177633Sdfr			/*
836184588Sdfr			 * RPCSEC_GSS uses this return code
837184588Sdfr			 * for requests that form part of its
838184588Sdfr			 * context establishment protocol and
839184588Sdfr			 * should not be dispatched to the
840184588Sdfr			 * application.
841177633Sdfr			 */
842184588Sdfr			if (why != RPCSEC_GSS_NODISPATCH)
843184588Sdfr				svcerr_auth(r, why);
844184588Sdfr			goto call_done;
845177633Sdfr		}
846184588Sdfr
847184588Sdfr		if (!SVCAUTH_UNWRAP(&r->rq_auth, &r->rq_args)) {
848184588Sdfr			svcerr_decode(r);
849184588Sdfr			goto call_done;
850184588Sdfr		}
851184588Sdfr
852177633Sdfr		/*
853184588Sdfr		 * Everything checks out, return request to caller.
854177633Sdfr		 */
855184588Sdfr		*rqstp_ret = r;
856184588Sdfr		r = NULL;
857184588Sdfr	}
858177633Sdfrcall_done:
859184588Sdfr	if (r) {
860184588Sdfr		svc_freereq(r);
861184588Sdfr		r = NULL;
862184588Sdfr	}
863184588Sdfr	if ((stat = SVC_STAT(xprt)) == XPRT_DIED) {
864184588Sdfr		xprt_unregister(xprt);
865184588Sdfr	}
866184588Sdfr
867184588Sdfr	return (stat);
868184588Sdfr}
869184588Sdfr
870184588Sdfrstatic void
871184588Sdfrsvc_executereq(struct svc_req *rqstp)
872184588Sdfr{
873184588Sdfr	SVCXPRT *xprt = rqstp->rq_xprt;
874184588Sdfr	SVCPOOL *pool = xprt->xp_pool;
875184588Sdfr	int prog_found;
876184588Sdfr	rpcvers_t low_vers;
877184588Sdfr	rpcvers_t high_vers;
878184588Sdfr	struct svc_callout *s;
879184588Sdfr
880184588Sdfr	/* now match message with a registered service*/
881184588Sdfr	prog_found = FALSE;
882184588Sdfr	low_vers = (rpcvers_t) -1L;
883184588Sdfr	high_vers = (rpcvers_t) 0L;
884184588Sdfr	TAILQ_FOREACH(s, &pool->sp_callouts, sc_link) {
885184588Sdfr		if (s->sc_prog == rqstp->rq_prog) {
886184588Sdfr			if (s->sc_vers == rqstp->rq_vers) {
887184588Sdfr				/*
888184588Sdfr				 * We hand ownership of r to the
889184588Sdfr				 * dispatch method - they must call
890184588Sdfr				 * svc_freereq.
891184588Sdfr				 */
892184588Sdfr				(*s->sc_dispatch)(rqstp, xprt);
893184588Sdfr				return;
894184588Sdfr			}  /* found correct version */
895184588Sdfr			prog_found = TRUE;
896184588Sdfr			if (s->sc_vers < low_vers)
897184588Sdfr				low_vers = s->sc_vers;
898184588Sdfr			if (s->sc_vers > high_vers)
899184588Sdfr				high_vers = s->sc_vers;
900184588Sdfr		}   /* found correct program */
901184588Sdfr	}
902184588Sdfr
903184588Sdfr	/*
904184588Sdfr	 * if we got here, the program or version
905184588Sdfr	 * is not served ...
906184588Sdfr	 */
907184588Sdfr	if (prog_found)
908184588Sdfr		svcerr_progvers(rqstp, low_vers, high_vers);
909184588Sdfr	else
910184588Sdfr		svcerr_noprog(rqstp);
911184588Sdfr
912184588Sdfr	svc_freereq(rqstp);
913184588Sdfr}
914184588Sdfr
915184588Sdfrstatic void
916184588Sdfrsvc_checkidle(SVCPOOL *pool)
917184588Sdfr{
918184588Sdfr	SVCXPRT *xprt, *nxprt;
919184588Sdfr	time_t timo;
920184588Sdfr	struct svcxprt_list cleanup;
921184588Sdfr
922184588Sdfr	TAILQ_INIT(&cleanup);
923184588Sdfr	TAILQ_FOREACH_SAFE(xprt, &pool->sp_xlist, xp_link, nxprt) {
924184588Sdfr		/*
925184588Sdfr		 * Only some transports have idle timers. Don't time
926184588Sdfr		 * something out which is just waking up.
927184588Sdfr		 */
928184588Sdfr		if (!xprt->xp_idletimeout || xprt->xp_thread)
929184588Sdfr			continue;
930184588Sdfr
931184588Sdfr		timo = xprt->xp_lastactive + xprt->xp_idletimeout;
932184588Sdfr		if (time_uptime > timo) {
933184588Sdfr			xprt_unregister_locked(xprt);
934184588Sdfr			TAILQ_INSERT_TAIL(&cleanup, xprt, xp_link);
935177633Sdfr		}
936184588Sdfr	}
937184588Sdfr
938184588Sdfr	mtx_unlock(&pool->sp_lock);
939184588Sdfr	TAILQ_FOREACH_SAFE(xprt, &cleanup, xp_link, nxprt) {
940184588Sdfr		SVC_RELEASE(xprt);
941184588Sdfr	}
942184588Sdfr	mtx_lock(&pool->sp_lock);
943184588Sdfr
944177633Sdfr}
945177633Sdfr
946184588Sdfrstatic void
947184588Sdfrsvc_assign_waiting_sockets(SVCPOOL *pool)
948177633Sdfr{
949177633Sdfr	SVCXPRT *xprt;
950184588Sdfr
951184588Sdfr	TAILQ_FOREACH(xprt, &pool->sp_active, xp_alink) {
952184588Sdfr		if (!xprt->xp_thread) {
953184588Sdfr			xprt_assignthread(xprt);
954184588Sdfr		}
955184588Sdfr	}
956184588Sdfr}
957184588Sdfr
958184588Sdfrstatic bool_t
959184588Sdfrsvc_request_space_available(SVCPOOL *pool)
960184588Sdfr{
961184588Sdfr
962184588Sdfr	mtx_assert(&pool->sp_lock, MA_OWNED);
963184588Sdfr
964184588Sdfr	if (pool->sp_space_throttled) {
965184588Sdfr		/*
966184588Sdfr		 * Below the low-water yet? If so, assign any waiting sockets.
967184588Sdfr		 */
968184588Sdfr		if (pool->sp_space_used < pool->sp_space_low) {
969184588Sdfr			pool->sp_space_throttled = FALSE;
970184588Sdfr			svc_assign_waiting_sockets(pool);
971184588Sdfr			return TRUE;
972184588Sdfr		}
973184588Sdfr
974184588Sdfr		return FALSE;
975184588Sdfr	} else {
976184588Sdfr		if (pool->sp_space_used
977184588Sdfr		    >= pool->sp_space_high) {
978184588Sdfr			pool->sp_space_throttled = TRUE;
979184588Sdfr			pool->sp_space_throttle_count++;
980184588Sdfr			return FALSE;
981184588Sdfr		}
982184588Sdfr
983184588Sdfr		return TRUE;
984184588Sdfr	}
985184588Sdfr}
986184588Sdfr
987184588Sdfrstatic void
988184588Sdfrsvc_run_internal(SVCPOOL *pool, bool_t ismaster)
989184588Sdfr{
990184588Sdfr	SVCTHREAD *st, *stpref;
991184588Sdfr	SVCXPRT *xprt;
992184588Sdfr	enum xprt_stat stat;
993184588Sdfr	struct svc_req *rqstp;
994177633Sdfr	int error;
995177633Sdfr
996184588Sdfr	st = mem_alloc(sizeof(*st));
997184588Sdfr	st->st_xprt = NULL;
998184588Sdfr	STAILQ_INIT(&st->st_reqs);
999184588Sdfr	cv_init(&st->st_cond, "rpcsvc");
1000184588Sdfr
1001177633Sdfr	mtx_lock(&pool->sp_lock);
1002184588Sdfr	LIST_INSERT_HEAD(&pool->sp_threads, st, st_link);
1003177633Sdfr
1004184588Sdfr	/*
1005184588Sdfr	 * If we are a new thread which was spawned to cope with
1006184588Sdfr	 * increased load, set the state back to SVCPOOL_ACTIVE.
1007184588Sdfr	 */
1008184588Sdfr	if (pool->sp_state == SVCPOOL_THREADSTARTING)
1009184588Sdfr		pool->sp_state = SVCPOOL_ACTIVE;
1010177633Sdfr
1011184588Sdfr	while (pool->sp_state != SVCPOOL_CLOSING) {
1012184588Sdfr		/*
1013184588Sdfr		 * Check for idle transports once per second.
1014184588Sdfr		 */
1015184588Sdfr		if (time_uptime > pool->sp_lastidlecheck) {
1016184588Sdfr			pool->sp_lastidlecheck = time_uptime;
1017184588Sdfr			svc_checkidle(pool);
1018184588Sdfr		}
1019184588Sdfr
1020184588Sdfr		xprt = st->st_xprt;
1021184588Sdfr		if (!xprt && STAILQ_EMPTY(&st->st_reqs)) {
1022184588Sdfr			/*
1023184588Sdfr			 * Enforce maxthreads count.
1024184588Sdfr			 */
1025184588Sdfr			if (pool->sp_threadcount > pool->sp_maxthreads)
1026177633Sdfr				break;
1027184588Sdfr
1028184588Sdfr			/*
1029184588Sdfr			 * Before sleeping, see if we can find an
1030184588Sdfr			 * active transport which isn't being serviced
1031184588Sdfr			 * by a thread.
1032184588Sdfr			 */
1033184588Sdfr			if (svc_request_space_available(pool)) {
1034184588Sdfr				TAILQ_FOREACH(xprt, &pool->sp_active,
1035184588Sdfr				    xp_alink) {
1036184588Sdfr					if (!xprt->xp_thread) {
1037184588Sdfr						SVC_ACQUIRE(xprt);
1038184588Sdfr						xprt->xp_thread = st;
1039184588Sdfr						st->st_xprt = xprt;
1040184588Sdfr						break;
1041184588Sdfr					}
1042184588Sdfr				}
1043184588Sdfr			}
1044184588Sdfr			if (st->st_xprt)
1045184588Sdfr				continue;
1046184588Sdfr
1047184588Sdfr			LIST_INSERT_HEAD(&pool->sp_idlethreads, st, st_ilink);
1048184588Sdfr			error = cv_timedwait_sig(&st->st_cond, &pool->sp_lock,
1049184588Sdfr				5 * hz);
1050184588Sdfr			LIST_REMOVE(st, st_ilink);
1051184588Sdfr
1052184588Sdfr			/*
1053184588Sdfr			 * Reduce worker thread count when idle.
1054184588Sdfr			 */
1055184588Sdfr			if (error == EWOULDBLOCK) {
1056184588Sdfr				if (!ismaster
1057184588Sdfr				    && (pool->sp_threadcount
1058184588Sdfr					> pool->sp_minthreads)
1059184588Sdfr					&& !st->st_xprt
1060184588Sdfr					&& STAILQ_EMPTY(&st->st_reqs))
1061184588Sdfr					break;
1062184588Sdfr			}
1063184588Sdfr			if (error == EWOULDBLOCK)
1064184588Sdfr				continue;
1065184588Sdfr			if (error) {
1066184588Sdfr				if (pool->sp_state != SVCPOOL_CLOSING) {
1067184588Sdfr					mtx_unlock(&pool->sp_lock);
1068184588Sdfr					svc_exit(pool);
1069184588Sdfr					mtx_lock(&pool->sp_lock);
1070184588Sdfr				}
1071184588Sdfr				break;
1072184588Sdfr			}
1073184588Sdfr
1074184588Sdfr			if (pool->sp_state == SVCPOOL_THREADWANTED) {
1075184588Sdfr				pool->sp_state = SVCPOOL_THREADSTARTING;
1076184588Sdfr				pool->sp_lastcreatetime = time_uptime;
1077184588Sdfr				mtx_unlock(&pool->sp_lock);
1078184588Sdfr				svc_new_thread(pool);
1079184588Sdfr				mtx_lock(&pool->sp_lock);
1080184588Sdfr			}
1081177633Sdfr			continue;
1082177633Sdfr		}
1083177633Sdfr
1084184588Sdfr		if (xprt) {
1085184588Sdfr			/*
1086184588Sdfr			 * Drain the transport socket and queue up any
1087184588Sdfr			 * RPCs.
1088184588Sdfr			 */
1089184588Sdfr			xprt->xp_lastactive = time_uptime;
1090184588Sdfr			stat = XPRT_IDLE;
1091184588Sdfr			do {
1092184588Sdfr				if (!svc_request_space_available(pool))
1093184588Sdfr					break;
1094184588Sdfr				rqstp = NULL;
1095184588Sdfr				mtx_unlock(&pool->sp_lock);
1096184588Sdfr				stat = svc_getreq(xprt, &rqstp);
1097184588Sdfr				mtx_lock(&pool->sp_lock);
1098184588Sdfr				if (rqstp) {
1099184588Sdfr					/*
1100184588Sdfr					 * See if the application has
1101184588Sdfr					 * a preference for some other
1102184588Sdfr					 * thread.
1103184588Sdfr					 */
1104184588Sdfr					stpref = st;
1105184588Sdfr					if (pool->sp_assign)
1106184588Sdfr						stpref = pool->sp_assign(st,
1107184588Sdfr						    rqstp);
1108184588Sdfr
1109184588Sdfr					pool->sp_space_used +=
1110184588Sdfr						rqstp->rq_size;
1111184588Sdfr					if (pool->sp_space_used
1112184588Sdfr					    > pool->sp_space_used_highest)
1113184588Sdfr						pool->sp_space_used_highest =
1114184588Sdfr							pool->sp_space_used;
1115184588Sdfr					rqstp->rq_thread = stpref;
1116184588Sdfr					STAILQ_INSERT_TAIL(&stpref->st_reqs,
1117184588Sdfr					    rqstp, rq_link);
1118184588Sdfr					stpref->st_reqcount++;
1119184588Sdfr
1120184588Sdfr					/*
1121184588Sdfr					 * If we assigned the request
1122184588Sdfr					 * to another thread, make
1123184588Sdfr					 * sure its awake and continue
1124184588Sdfr					 * reading from the
1125184588Sdfr					 * socket. Otherwise, try to
1126184588Sdfr					 * find some other thread to
1127184588Sdfr					 * read from the socket and
1128184588Sdfr					 * execute the request
1129184588Sdfr					 * immediately.
1130184588Sdfr					 */
1131184588Sdfr					if (stpref != st) {
1132184588Sdfr						cv_signal(&stpref->st_cond);
1133184588Sdfr						continue;
1134184588Sdfr					} else {
1135184588Sdfr						break;
1136184588Sdfr					}
1137184588Sdfr				}
1138184588Sdfr			} while (stat == XPRT_MOREREQS
1139184588Sdfr			    && pool->sp_state != SVCPOOL_CLOSING);
1140184588Sdfr
1141184588Sdfr			/*
1142184588Sdfr			 * Move this transport to the end of the
1143184588Sdfr			 * active list to ensure fairness when
1144184588Sdfr			 * multiple transports are active. If this was
1145184588Sdfr			 * the last queued request, svc_getreq will
1146184588Sdfr			 * end up calling xprt_inactive to remove from
1147184588Sdfr			 * the active list.
1148184588Sdfr			 */
1149184588Sdfr			xprt->xp_thread = NULL;
1150184588Sdfr			st->st_xprt = NULL;
1151184588Sdfr			if (xprt->xp_active) {
1152184588Sdfr				xprt_assignthread(xprt);
1153184588Sdfr				TAILQ_REMOVE(&pool->sp_active, xprt, xp_alink);
1154184588Sdfr				TAILQ_INSERT_TAIL(&pool->sp_active, xprt,
1155184588Sdfr				    xp_alink);
1156184588Sdfr			}
1157184588Sdfr			mtx_unlock(&pool->sp_lock);
1158184588Sdfr			SVC_RELEASE(xprt);
1159184588Sdfr			mtx_lock(&pool->sp_lock);
1160184588Sdfr		}
1161184588Sdfr
1162177633Sdfr		/*
1163184588Sdfr		 * Execute what we have queued.
1164177633Sdfr		 */
1165184588Sdfr		while ((rqstp = STAILQ_FIRST(&st->st_reqs)) != NULL) {
1166184588Sdfr			size_t sz = rqstp->rq_size;
1167184588Sdfr			mtx_unlock(&pool->sp_lock);
1168184588Sdfr			svc_executereq(rqstp);
1169184588Sdfr			mtx_lock(&pool->sp_lock);
1170184588Sdfr			pool->sp_space_used -= sz;
1171184588Sdfr		}
1172184588Sdfr	}
1173177633Sdfr
1174184588Sdfr	if (st->st_xprt) {
1175184588Sdfr		xprt = st->st_xprt;
1176184588Sdfr		st->st_xprt = NULL;
1177184588Sdfr		SVC_RELEASE(xprt);
1178177633Sdfr	}
1179177633Sdfr
1180184588Sdfr	KASSERT(STAILQ_EMPTY(&st->st_reqs), ("stray reqs on exit"));
1181184588Sdfr	LIST_REMOVE(st, st_link);
1182184588Sdfr	pool->sp_threadcount--;
1183184588Sdfr
1184177633Sdfr	mtx_unlock(&pool->sp_lock);
1185184588Sdfr
1186184588Sdfr	cv_destroy(&st->st_cond);
1187184588Sdfr	mem_free(st, sizeof(*st));
1188184588Sdfr
1189184588Sdfr	if (!ismaster)
1190184588Sdfr		wakeup(pool);
1191177633Sdfr}
1192177633Sdfr
1193184588Sdfrstatic void
1194184588Sdfrsvc_thread_start(void *arg)
1195184588Sdfr{
1196184588Sdfr
1197184588Sdfr	svc_run_internal((SVCPOOL *) arg, FALSE);
1198184588Sdfr	kthread_exit();
1199184588Sdfr}
1200184588Sdfr
1201184588Sdfrstatic void
1202184588Sdfrsvc_new_thread(SVCPOOL *pool)
1203184588Sdfr{
1204184588Sdfr	struct thread *td;
1205184588Sdfr
1206184588Sdfr	pool->sp_threadcount++;
1207184588Sdfr	kthread_add(svc_thread_start, pool,
1208184588Sdfr	    pool->sp_proc, &td, 0, 0,
1209184588Sdfr	    "%s: service", pool->sp_name);
1210184588Sdfr}
1211184588Sdfr
1212177633Sdfrvoid
1213184588Sdfrsvc_run(SVCPOOL *pool)
1214184588Sdfr{
1215184588Sdfr	int i;
1216184588Sdfr	struct proc *p;
1217184588Sdfr	struct thread *td;
1218184588Sdfr
1219184588Sdfr	p = curproc;
1220184588Sdfr	td = curthread;
1221184588Sdfr	snprintf(td->td_name, sizeof(td->td_name),
1222184588Sdfr	    "%s: master", pool->sp_name);
1223184588Sdfr	pool->sp_state = SVCPOOL_ACTIVE;
1224184588Sdfr	pool->sp_proc = p;
1225184588Sdfr	pool->sp_lastcreatetime = time_uptime;
1226184588Sdfr	pool->sp_threadcount = 1;
1227184588Sdfr
1228184588Sdfr	for (i = 1; i < pool->sp_minthreads; i++) {
1229184588Sdfr		svc_new_thread(pool);
1230184588Sdfr	}
1231184588Sdfr
1232184588Sdfr	svc_run_internal(pool, TRUE);
1233184588Sdfr
1234184588Sdfr	mtx_lock(&pool->sp_lock);
1235184588Sdfr	while (pool->sp_threadcount > 0)
1236184588Sdfr		msleep(pool, &pool->sp_lock, 0, "svcexit", 0);
1237184588Sdfr	mtx_unlock(&pool->sp_lock);
1238184588Sdfr}
1239184588Sdfr
1240184588Sdfrvoid
1241177633Sdfrsvc_exit(SVCPOOL *pool)
1242177633Sdfr{
1243184588Sdfr	SVCTHREAD *st;
1244184588Sdfr
1245177633Sdfr	mtx_lock(&pool->sp_lock);
1246184588Sdfr
1247184588Sdfr	pool->sp_state = SVCPOOL_CLOSING;
1248184588Sdfr	LIST_FOREACH(st, &pool->sp_idlethreads, st_ilink)
1249184588Sdfr		cv_signal(&st->st_cond);
1250184588Sdfr
1251177633Sdfr	mtx_unlock(&pool->sp_lock);
1252177633Sdfr}
1253184588Sdfr
1254184588Sdfrbool_t
1255184588Sdfrsvc_getargs(struct svc_req *rqstp, xdrproc_t xargs, void *args)
1256184588Sdfr{
1257184588Sdfr	struct mbuf *m;
1258184588Sdfr	XDR xdrs;
1259184588Sdfr	bool_t stat;
1260184588Sdfr
1261184588Sdfr	m = rqstp->rq_args;
1262184588Sdfr	rqstp->rq_args = NULL;
1263184588Sdfr
1264184588Sdfr	xdrmbuf_create(&xdrs, m, XDR_DECODE);
1265184588Sdfr	stat = xargs(&xdrs, args);
1266184588Sdfr	XDR_DESTROY(&xdrs);
1267184588Sdfr
1268184588Sdfr	return (stat);
1269184588Sdfr}
1270184588Sdfr
1271184588Sdfrbool_t
1272184588Sdfrsvc_freeargs(struct svc_req *rqstp, xdrproc_t xargs, void *args)
1273184588Sdfr{
1274184588Sdfr	XDR xdrs;
1275184588Sdfr
1276184588Sdfr	if (rqstp->rq_addr) {
1277184588Sdfr		free(rqstp->rq_addr, M_SONAME);
1278184588Sdfr		rqstp->rq_addr = NULL;
1279184588Sdfr	}
1280184588Sdfr
1281184588Sdfr	xdrs.x_op = XDR_FREE;
1282184588Sdfr	return (xargs(&xdrs, args));
1283184588Sdfr}
1284184588Sdfr
1285184588Sdfrvoid
1286184588Sdfrsvc_freereq(struct svc_req *rqstp)
1287184588Sdfr{
1288184588Sdfr	SVCTHREAD *st;
1289184588Sdfr	SVCXPRT *xprt;
1290184588Sdfr	SVCPOOL *pool;
1291184588Sdfr
1292184588Sdfr	st = rqstp->rq_thread;
1293184588Sdfr	xprt = rqstp->rq_xprt;
1294184588Sdfr	if (xprt)
1295184588Sdfr		pool = xprt->xp_pool;
1296184588Sdfr	else
1297184588Sdfr		pool = NULL;
1298184588Sdfr	if (st) {
1299184588Sdfr		mtx_lock(&pool->sp_lock);
1300184588Sdfr		KASSERT(rqstp == STAILQ_FIRST(&st->st_reqs),
1301184588Sdfr		    ("Freeing request out of order"));
1302184588Sdfr		STAILQ_REMOVE_HEAD(&st->st_reqs, rq_link);
1303184588Sdfr		st->st_reqcount--;
1304184588Sdfr		if (pool->sp_done)
1305184588Sdfr			pool->sp_done(st, rqstp);
1306184588Sdfr		mtx_unlock(&pool->sp_lock);
1307184588Sdfr	}
1308184588Sdfr
1309184588Sdfr	if (rqstp->rq_auth.svc_ah_ops)
1310184588Sdfr		SVCAUTH_RELEASE(&rqstp->rq_auth);
1311184588Sdfr
1312184588Sdfr	if (rqstp->rq_xprt) {
1313184588Sdfr		SVC_RELEASE(rqstp->rq_xprt);
1314184588Sdfr	}
1315184588Sdfr
1316184588Sdfr	if (rqstp->rq_addr)
1317184588Sdfr		free(rqstp->rq_addr, M_SONAME);
1318184588Sdfr
1319184588Sdfr	if (rqstp->rq_args)
1320184588Sdfr		m_freem(rqstp->rq_args);
1321184588Sdfr
1322184588Sdfr	free(rqstp, M_RPC);
1323184588Sdfr}
1324