author | akolb |
Fri, 09 Mar 2007 15:55:28 -0800 | |
changeset 3792 | 57ba782523b7 |
parent 3448 | aaf16568054b |
child 4197 | 9335c9d052a6 |
permissions | -rw-r--r-- |
0 | 1 |
/* |
2 |
* CDDL HEADER START |
|
3 |
* |
|
4 |
* The contents of this file are subject to the terms of the |
|
1676 | 5 |
* Common Development and Distribution License (the "License"). |
6 |
* You may not use this file except in compliance with the License. |
|
0 | 7 |
* |
8 |
* You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE |
|
9 |
* or http://www.opensolaris.org/os/licensing. |
|
10 |
* See the License for the specific language governing permissions |
|
11 |
* and limitations under the License. |
|
12 |
* |
|
13 |
* When distributing Covered Code, include this CDDL HEADER in each |
|
14 |
* file and include the License file at usr/src/OPENSOLARIS.LICENSE. |
|
15 |
* If applicable, add the following below this CDDL HEADER, with the |
|
16 |
* fields enclosed by brackets "[]" replaced with your own identifying |
|
17 |
* information: Portions Copyright [yyyy] [name of copyright owner] |
|
18 |
* |
|
19 |
* CDDL HEADER END |
|
20 |
*/ |
|
21 |
/* |
|
3448 | 22 |
* Copyright 2007 Sun Microsystems, Inc. All rights reserved. |
0 | 23 |
* Use is subject to license terms. |
24 |
*/ |
|
25 |
||
26 |
#ifndef _SYS_ZONE_H |
|
27 |
#define _SYS_ZONE_H |
|
28 |
||
29 |
#pragma ident "%Z%%M% %I% %E% SMI" |
|
30 |
||
31 |
#include <sys/types.h> |
|
32 |
#include <sys/mutex.h> |
|
33 |
#include <sys/param.h> |
|
34 |
#include <sys/rctl.h> |
|
2677
212d61b14a8b
PSARC/2006/451 System V resource controls for Zones
ml93401
parents:
2267
diff
changeset
|
35 |
#include <sys/ipc_rctl.h> |
0 | 36 |
#include <sys/pset.h> |
1676 | 37 |
#include <sys/tsol/label.h> |
3448 | 38 |
#include <sys/cred.h> |
39 |
#include <sys/netstack.h> |
|
2267 | 40 |
#include <sys/uadmin.h> |
0 | 41 |
|
42 |
#ifdef __cplusplus |
|
43 |
extern "C" { |
|
44 |
#endif |
|
45 |
||
46 |
/* |
|
47 |
* NOTE |
|
48 |
* |
|
49 |
* The contents of this file are private to the implementation of |
|
50 |
* Solaris and are subject to change at any time without notice. |
|
51 |
* Applications and drivers using these interfaces may fail to |
|
52 |
* run on future releases. |
|
53 |
*/ |
|
54 |
||
55 |
/* Available both in kernel and for user space */ |
|
56 |
||
57 |
/* zone id restrictions and special ids */ |
|
58 |
#define MAX_ZONEID 9999 |
|
59 |
#define MIN_USERZONEID 1 /* lowest user-creatable zone ID */ |
|
60 |
#define MIN_ZONEID 0 /* minimum zone ID on system */ |
|
61 |
#define GLOBAL_ZONEID 0 |
|
62 |
#define ZONEID_WIDTH 4 /* for printf */ |
|
63 |
||
1676 | 64 |
/* |
65 |
* Special zoneid_t token to refer to all zones. |
|
66 |
*/ |
|
67 |
#define ALL_ZONES (-1) |
|
68 |
||
0 | 69 |
/* system call subcodes */ |
3448 | 70 |
#define ZONE_CREATE 0 |
71 |
#define ZONE_DESTROY 1 |
|
72 |
#define ZONE_GETATTR 2 |
|
73 |
#define ZONE_ENTER 3 |
|
74 |
#define ZONE_LIST 4 |
|
75 |
#define ZONE_SHUTDOWN 5 |
|
76 |
#define ZONE_LOOKUP 6 |
|
77 |
#define ZONE_BOOT 7 |
|
78 |
#define ZONE_VERSION 8 |
|
79 |
#define ZONE_SETATTR 9 |
|
80 |
#define ZONE_ADD_DATALINK 10 |
|
81 |
#define ZONE_DEL_DATALINK 11 |
|
82 |
#define ZONE_CHECK_DATALINK 12 |
|
83 |
#define ZONE_LIST_DATALINK 13 |
|
0 | 84 |
|
85 |
/* zone attributes */ |
|
86 |
#define ZONE_ATTR_ROOT 1 |
|
87 |
#define ZONE_ATTR_NAME 2 |
|
88 |
#define ZONE_ATTR_STATUS 3 |
|
89 |
#define ZONE_ATTR_PRIVSET 4 |
|
90 |
#define ZONE_ATTR_UNIQID 5 |
|
91 |
#define ZONE_ATTR_POOLID 6 |
|
92 |
#define ZONE_ATTR_INITPID 7 |
|
1676 | 93 |
#define ZONE_ATTR_SLBL 8 |
2267 | 94 |
#define ZONE_ATTR_INITNAME 9 |
95 |
#define ZONE_ATTR_BOOTARGS 10 |
|
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
96 |
#define ZONE_ATTR_BRAND 11 |
3247 | 97 |
#define ZONE_ATTR_PHYS_MCAP 12 |
98 |
#define ZONE_ATTR_SCHED_CLASS 13 |
|
3448 | 99 |
#define ZONE_ATTR_FLAGS 14 |
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
100 |
|
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
101 |
/* Start of the brand-specific attribute namespace */ |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
102 |
#define ZONE_ATTR_BRAND_ATTRS 32768 |
0 | 103 |
|
1166 | 104 |
#define ZONE_EVENT_CHANNEL "com.sun:zones:status" |
105 |
#define ZONE_EVENT_STATUS_CLASS "status" |
|
106 |
#define ZONE_EVENT_STATUS_SUBCLASS "change" |
|
107 |
||
108 |
#define ZONE_EVENT_UNINITIALIZED "uninitialized" |
|
109 |
#define ZONE_EVENT_READY "ready" |
|
110 |
#define ZONE_EVENT_RUNNING "running" |
|
111 |
#define ZONE_EVENT_SHUTTING_DOWN "shutting_down" |
|
112 |
||
113 |
#define ZONE_CB_NAME "zonename" |
|
114 |
#define ZONE_CB_NEWSTATE "newstate" |
|
115 |
#define ZONE_CB_OLDSTATE "oldstate" |
|
116 |
#define ZONE_CB_TIMESTAMP "when" |
|
117 |
#define ZONE_CB_ZONEID "zoneid" |
|
118 |
||
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
119 |
/* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
120 |
* Exit values that may be returned by scripts or programs invoked by various |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
121 |
* zone commands. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
122 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
123 |
* These are defined as: |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
124 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
125 |
* ZONE_SUBPROC_OK |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
126 |
* =============== |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
127 |
* The subprocess completed successfully. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
128 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
129 |
* ZONE_SUBPROC_USAGE |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
130 |
* ================== |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
131 |
* The subprocess failed with a usage message, or a usage message should |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
132 |
* be output in its behalf. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
133 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
134 |
* ZONE_SUBPROC_NOTCOMPLETE |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
135 |
* ======================== |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
136 |
* The subprocess did not complete, but the actions performed by the |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
137 |
* subprocess require no recovery actions by the user. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
138 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
139 |
* For example, if the subprocess were called by "zoneadm install," the |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
140 |
* installation of the zone did not succeed but the user need not perform |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
141 |
* a "zoneadm uninstall" before attempting another install. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
142 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
143 |
* ZONE_SUBPROC_FATAL |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
144 |
* ================== |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
145 |
* The subprocess failed in a fatal manner, usually one that will require |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
146 |
* some type of recovery action by the user. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
147 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
148 |
* For example, if the subprocess were called by "zoneadm install," the |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
149 |
* installation of the zone did not succeed and the user will need to |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
150 |
* perform a "zoneadm uninstall" before another install attempt is |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
151 |
* possible. |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
152 |
* |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
153 |
* The non-success exit values are large to avoid accidental collision |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
154 |
* with values used internally by some commands (e.g. "Z_ERR" and |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
155 |
* "Z_USAGE" as used by zoneadm.) |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
156 |
*/ |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
157 |
#define ZONE_SUBPROC_OK 0 |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
158 |
#define ZONE_SUBPROC_USAGE 253 |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
159 |
#define ZONE_SUBPROC_NOTCOMPLETE 254 |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
160 |
#define ZONE_SUBPROC_FATAL 255 |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
161 |
|
0 | 162 |
#ifdef _SYSCALL32 |
163 |
typedef struct { |
|
164 |
caddr32_t zone_name; |
|
165 |
caddr32_t zone_root; |
|
166 |
caddr32_t zone_privs; |
|
813 | 167 |
size32_t zone_privssz; |
0 | 168 |
caddr32_t rctlbuf; |
169 |
size32_t rctlbufsz; |
|
170 |
caddr32_t extended_error; |
|
789 | 171 |
caddr32_t zfsbuf; |
172 |
size32_t zfsbufsz; |
|
2110
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
173 |
int match; /* match level */ |
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
174 |
uint32_t doi; /* DOI for label */ |
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
175 |
caddr32_t label; /* label associated with zone */ |
3448 | 176 |
int flags; |
0 | 177 |
} zone_def32; |
178 |
#endif |
|
179 |
typedef struct { |
|
180 |
const char *zone_name; |
|
181 |
const char *zone_root; |
|
182 |
const struct priv_set *zone_privs; |
|
813 | 183 |
size_t zone_privssz; |
0 | 184 |
const char *rctlbuf; |
185 |
size_t rctlbufsz; |
|
186 |
int *extended_error; |
|
789 | 187 |
const char *zfsbuf; |
188 |
size_t zfsbufsz; |
|
1676 | 189 |
int match; /* match level */ |
2110
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
190 |
uint32_t doi; /* DOI for label */ |
1676 | 191 |
const bslabel_t *label; /* label associated with zone */ |
3448 | 192 |
int flags; |
0 | 193 |
} zone_def; |
194 |
||
195 |
/* extended error information */ |
|
196 |
#define ZE_UNKNOWN 0 /* No extended error info */ |
|
197 |
#define ZE_CHROOTED 1 /* tried to zone_create from chroot */ |
|
198 |
#define ZE_AREMOUNTS 2 /* there are mounts within the zone */ |
|
199 |
||
200 |
/* zone_status */ |
|
201 |
typedef enum { |
|
202 |
ZONE_IS_UNINITIALIZED = 0, |
|
203 |
ZONE_IS_READY, |
|
204 |
ZONE_IS_BOOTING, |
|
205 |
ZONE_IS_RUNNING, |
|
206 |
ZONE_IS_SHUTTING_DOWN, |
|
207 |
ZONE_IS_EMPTY, |
|
208 |
ZONE_IS_DOWN, |
|
209 |
ZONE_IS_DYING, |
|
210 |
ZONE_IS_DEAD |
|
211 |
} zone_status_t; |
|
212 |
#define ZONE_MIN_STATE ZONE_IS_UNINITIALIZED |
|
213 |
#define ZONE_MAX_STATE ZONE_IS_DEAD |
|
214 |
||
215 |
/* |
|
216 |
* Valid commands which may be issued by zoneadm to zoneadmd. The kernel also |
|
217 |
* communicates with zoneadmd, but only uses Z_REBOOT and Z_HALT. |
|
218 |
*/ |
|
219 |
typedef enum zone_cmd { |
|
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
220 |
Z_READY, Z_BOOT, Z_FORCEBOOT, Z_REBOOT, Z_HALT, Z_NOTE_UNINSTALLING, |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
221 |
Z_MOUNT, Z_FORCEMOUNT, Z_UNMOUNT |
0 | 222 |
} zone_cmd_t; |
223 |
||
224 |
/* |
|
225 |
* The structure of a request to zoneadmd. |
|
226 |
*/ |
|
227 |
typedef struct zone_cmd_arg { |
|
228 |
uint64_t uniqid; /* unique "generation number" */ |
|
229 |
zone_cmd_t cmd; /* requested action */ |
|
2267 | 230 |
uint32_t _pad; /* need consistent 32/64 bit alignmt */ |
0 | 231 |
char locale[MAXPATHLEN]; /* locale in which to render messages */ |
2267 | 232 |
char bootbuf[BOOTARGS_MAX]; /* arguments passed to zone_boot() */ |
0 | 233 |
} zone_cmd_arg_t; |
234 |
||
235 |
/* |
|
236 |
* Structure of zoneadmd's response to a request. A NULL return value means |
|
237 |
* the caller should attempt to restart zoneadmd and retry. |
|
238 |
*/ |
|
239 |
typedef struct zone_cmd_rval { |
|
240 |
int rval; /* return value of request */ |
|
241 |
char errbuf[1]; /* variable-sized buffer containing error messages */ |
|
242 |
} zone_cmd_rval_t; |
|
243 |
||
244 |
/* |
|
245 |
* The zone support infrastructure uses the zone name as a component |
|
246 |
* of unix domain (AF_UNIX) sockets, which are limited to 108 characters |
|
247 |
* in length, so ZONENAME_MAX is limited by that. |
|
248 |
*/ |
|
249 |
#define ZONENAME_MAX 64 |
|
250 |
||
251 |
#define GLOBAL_ZONENAME "global" |
|
252 |
||
253 |
/* |
|
254 |
* Extended Regular expression (see regex(5)) which matches all valid zone |
|
255 |
* names. |
|
256 |
*/ |
|
257 |
#define ZONENAME_REGEXP "[a-zA-Z0-9][-_.a-zA-Z0-9]{0,62}" |
|
258 |
||
259 |
/* |
|
260 |
* Where the zones support infrastructure places temporary files. |
|
261 |
*/ |
|
262 |
#define ZONES_TMPDIR "/var/run/zones" |
|
263 |
||
264 |
/* |
|
265 |
* The path to the door used by clients to communicate with zoneadmd. |
|
266 |
*/ |
|
267 |
#define ZONE_DOOR_PATH ZONES_TMPDIR "/%s.zoneadmd_door" |
|
268 |
||
3448 | 269 |
/* zone_flags */ |
270 |
#define ZF_DESTROYED 0x1 /* ZSD destructor callbacks run */ |
|
271 |
#define ZF_HASHED_LABEL 0x2 /* zone has a unique label */ |
|
272 |
#define ZF_IS_SCRATCH 0x4 /* scratch zone */ |
|
273 |
#define ZF_NET_EXCL 0x8 /* Zone has an exclusive IP stack */ |
|
274 |
||
275 |
/* zone_create flags */ |
|
276 |
#define ZCF_NET_EXCL 0x1 /* Create a zone with exclusive IP */ |
|
277 |
||
0 | 278 |
#ifdef _KERNEL |
279 |
/* |
|
280 |
* We need to protect the definition of 'list_t' from userland applications and |
|
281 |
* libraries which may be defining ther own versions. |
|
282 |
*/ |
|
283 |
#include <sys/list.h> |
|
284 |
||
285 |
#define GLOBAL_ZONEUNIQID 0 /* uniqid of the global zone */ |
|
286 |
||
287 |
struct pool; |
|
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
288 |
struct brand; |
3448 | 289 |
struct dlnamelist; |
0 | 290 |
|
789 | 291 |
/* |
292 |
* Structure to record list of ZFS datasets exported to a zone. |
|
293 |
*/ |
|
294 |
typedef struct zone_dataset { |
|
295 |
char *zd_dataset; |
|
296 |
list_node_t zd_linkage; |
|
297 |
} zone_dataset_t; |
|
298 |
||
3247 | 299 |
/* |
300 |
* structure for zone kstats |
|
301 |
*/ |
|
302 |
typedef struct zone_kstat { |
|
303 |
kstat_named_t zk_zonename; |
|
304 |
kstat_named_t zk_usage; |
|
305 |
kstat_named_t zk_value; |
|
306 |
} zone_kstat_t; |
|
307 |
||
3792 | 308 |
struct cpucap; |
309 |
||
0 | 310 |
typedef struct zone { |
311 |
/* |
|
312 |
* zone_name is never modified once set. |
|
313 |
*/ |
|
314 |
char *zone_name; /* zone's configuration name */ |
|
315 |
/* |
|
316 |
* zone_nodename and zone_domain are never freed once allocated. |
|
317 |
*/ |
|
318 |
char *zone_nodename; /* utsname.nodename equivalent */ |
|
319 |
char *zone_domain; /* srpc_domain equivalent */ |
|
320 |
/* |
|
321 |
* zone_lock protects the following fields of a zone_t: |
|
322 |
* zone_ref |
|
323 |
* zone_cred_ref |
|
324 |
* zone_ntasks |
|
325 |
* zone_flags |
|
326 |
* zone_zsd |
|
327 |
*/ |
|
328 |
kmutex_t zone_lock; |
|
329 |
/* |
|
330 |
* zone_linkage is the zone's linkage into the active or |
|
331 |
* death-row list. The field is protected by zonehash_lock. |
|
332 |
*/ |
|
333 |
list_node_t zone_linkage; |
|
334 |
zoneid_t zone_id; /* ID of zone */ |
|
335 |
uint_t zone_ref; /* count of zone_hold()s on zone */ |
|
336 |
uint_t zone_cred_ref; /* count of zone_hold_cred()s on zone */ |
|
337 |
/* |
|
338 |
* zone_rootvp and zone_rootpath can never be modified once set. |
|
339 |
*/ |
|
340 |
struct vnode *zone_rootvp; /* zone's root vnode */ |
|
341 |
char *zone_rootpath; /* Path to zone's root + '/' */ |
|
342 |
ushort_t zone_flags; /* misc flags */ |
|
343 |
zone_status_t zone_status; /* protected by zone_status_lock */ |
|
344 |
uint_t zone_ntasks; /* number of tasks executing in zone */ |
|
345 |
kmutex_t zone_nlwps_lock; /* protects zone_nlwps, and *_nlwps */ |
|
346 |
/* counters in projects and tasks */ |
|
347 |
/* that are within the zone */ |
|
348 |
rctl_qty_t zone_nlwps; /* number of lwps in zone */ |
|
349 |
rctl_qty_t zone_nlwps_ctl; /* protected by zone_rctls->rcs_lock */ |
|
2677
212d61b14a8b
PSARC/2006/451 System V resource controls for Zones
ml93401
parents:
2267
diff
changeset
|
350 |
rctl_qty_t zone_shmmax; /* System V shared memory usage */ |
212d61b14a8b
PSARC/2006/451 System V resource controls for Zones
ml93401
parents:
2267
diff
changeset
|
351 |
ipc_rqty_t zone_ipc; /* System V IPC id resource usage */ |
0 | 352 |
|
353 |
uint_t zone_rootpathlen; /* strlen(zone_rootpath) + 1 */ |
|
354 |
uint32_t zone_shares; /* FSS shares allocated to zone */ |
|
355 |
rctl_set_t *zone_rctls; /* zone-wide (zone.*) rctls */ |
|
3247 | 356 |
kmutex_t zone_mem_lock; /* protects zone_locked_mem and */ |
2768
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
357 |
/* kpd_locked_mem for all */ |
3247 | 358 |
/* projects in zone. */ |
359 |
/* Also protects zone_max_swap */ |
|
2768
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
360 |
/* grab after p_lock, before rcs_lock */ |
3247 | 361 |
rctl_qty_t zone_locked_mem; /* bytes of locked memory in */ |
362 |
/* zone */ |
|
363 |
rctl_qty_t zone_locked_mem_ctl; /* Current locked memory */ |
|
2768
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
364 |
/* limit. Protected by */ |
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
365 |
/* zone_rctls->rcs_lock */ |
3247 | 366 |
rctl_qty_t zone_max_swap; /* bytes of swap reserved by zone */ |
367 |
rctl_qty_t zone_max_swap_ctl; /* current swap limit. */ |
|
368 |
/* Protected by */ |
|
369 |
/* zone_rctls->rcs_lock */ |
|
0 | 370 |
list_t zone_zsd; /* list of Zone-Specific Data values */ |
371 |
kcondvar_t zone_cv; /* used to signal state changes */ |
|
372 |
struct proc *zone_zsched; /* Dummy kernel "zsched" process */ |
|
373 |
pid_t zone_proc_initpid; /* pid of "init" for this zone */ |
|
2267 | 374 |
char *zone_initname; /* fs path to 'init' */ |
0 | 375 |
int zone_boot_err; /* for zone_boot() if boot fails */ |
376 |
char *zone_bootargs; /* arguments passed via zone_boot() */ |
|
3247 | 377 |
uint64_t zone_phys_mcap; /* physical memory cap */ |
0 | 378 |
/* |
379 |
* zone_kthreads is protected by zone_status_lock. |
|
380 |
*/ |
|
381 |
kthread_t *zone_kthreads; /* kernel threads in zone */ |
|
382 |
struct priv_set *zone_privset; /* limit set for zone */ |
|
383 |
/* |
|
384 |
* zone_vfslist is protected by vfs_list_lock(). |
|
385 |
*/ |
|
386 |
struct vfs *zone_vfslist; /* list of FS's mounted in zone */ |
|
387 |
uint64_t zone_uniqid; /* unique zone generation number */ |
|
388 |
struct cred *zone_kcred; /* kcred-like, zone-limited cred */ |
|
389 |
/* |
|
390 |
* zone_pool is protected by pool_lock(). |
|
391 |
*/ |
|
392 |
struct pool *zone_pool; /* pool the zone is bound to */ |
|
393 |
hrtime_t zone_pool_mod; /* last pool bind modification time */ |
|
394 |
/* zone_psetid is protected by cpu_lock */ |
|
395 |
psetid_t zone_psetid; /* pset the zone is bound to */ |
|
396 |
/* |
|
397 |
* The following two can be read without holding any locks. They are |
|
398 |
* updated under cpu_lock. |
|
399 |
*/ |
|
400 |
int zone_ncpus; /* zone's idea of ncpus */ |
|
401 |
int zone_ncpus_online; /* zone's idea of ncpus_online */ |
|
789 | 402 |
/* |
403 |
* List of ZFS datasets exported to this zone. |
|
404 |
*/ |
|
405 |
list_t zone_datasets; /* list of datasets */ |
|
1676 | 406 |
|
2110
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
407 |
ts_label_t *zone_slabel; /* zone sensitivity label */ |
31cba59b38be
6403267 address remaining issues raised during TX code reviews
rica
parents:
1769
diff
changeset
|
408 |
int zone_match; /* require label match for packets */ |
1676 | 409 |
tsol_mlp_list_t zone_mlps; /* MLPs on zone-private addresses */ |
2267 | 410 |
|
2712
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
411 |
boolean_t zone_restart_init; /* Restart init if it dies? */ |
f74a135872bc
PSARC/2005/471 BrandZ: Support for non-native zones
nn35248
parents:
2677
diff
changeset
|
412 |
struct brand *zone_brand; /* zone's brand */ |
3247 | 413 |
id_t zone_defaultcid; /* dflt scheduling class id */ |
414 |
kstat_t *zone_swapresv_kstat; |
|
415 |
kstat_t *zone_lockedmem_kstat; |
|
3448 | 416 |
/* |
417 |
* zone_dl_list is protected by zone_lock |
|
418 |
*/ |
|
419 |
struct dlnamelist *zone_dl_list; |
|
420 |
netstack_t *zone_netstack; |
|
3792 | 421 |
struct cpucap *zone_cpucap; /* CPU caps data */ |
0 | 422 |
} zone_t; |
423 |
||
424 |
/* |
|
425 |
* Special value of zone_psetid to indicate that pools are disabled. |
|
426 |
*/ |
|
427 |
#define ZONE_PS_INVAL PS_MYID |
|
428 |
||
3448 | 429 |
|
0 | 430 |
extern zone_t zone0; |
431 |
extern zone_t *global_zone; |
|
432 |
extern uint_t maxzones; |
|
433 |
extern rctl_hndl_t rc_zone_nlwps; |
|
434 |
||
789 | 435 |
extern long zone(int, void *, void *, void *, void *); |
0 | 436 |
extern void zone_zsd_init(void); |
437 |
extern void zone_init(void); |
|
438 |
extern void zone_hold(zone_t *); |
|
439 |
extern void zone_rele(zone_t *); |
|
440 |
extern void zone_cred_hold(zone_t *); |
|
441 |
extern void zone_cred_rele(zone_t *); |
|
442 |
extern void zone_task_hold(zone_t *); |
|
443 |
extern void zone_task_rele(zone_t *); |
|
444 |
extern zone_t *zone_find_by_id(zoneid_t); |
|
1676 | 445 |
extern zone_t *zone_find_by_label(const ts_label_t *); |
0 | 446 |
extern zone_t *zone_find_by_name(char *); |
1769
338500d67d4f
6404654 zoneadm mount command fails on labeled systems
carlsonj
parents:
1676
diff
changeset
|
447 |
extern zone_t *zone_find_by_any_path(const char *, boolean_t); |
0 | 448 |
extern zone_t *zone_find_by_path(const char *); |
449 |
extern zoneid_t getzoneid(void); |
|
3448 | 450 |
extern zone_t *zone_find_by_id_nolock(zoneid_t); |
0 | 451 |
|
452 |
/* |
|
453 |
* Zone-specific data (ZSD) APIs |
|
454 |
*/ |
|
455 |
/* |
|
456 |
* The following is what code should be initializing its zone_key_t to if it |
|
457 |
* calls zone_getspecific() without necessarily knowing that zone_key_create() |
|
458 |
* has been called on the key. |
|
459 |
*/ |
|
460 |
#define ZONE_KEY_UNINITIALIZED 0 |
|
461 |
||
462 |
typedef uint_t zone_key_t; |
|
463 |
||
464 |
extern void zone_key_create(zone_key_t *, void *(*)(zoneid_t), |
|
465 |
void (*)(zoneid_t, void *), void (*)(zoneid_t, void *)); |
|
466 |
extern int zone_key_delete(zone_key_t); |
|
467 |
extern void *zone_getspecific(zone_key_t, zone_t *); |
|
468 |
extern int zone_setspecific(zone_key_t, zone_t *, const void *); |
|
469 |
||
470 |
/* |
|
471 |
* The definition of a zsd_entry is truly private to zone.c and is only |
|
472 |
* placed here so it can be shared with mdb. |
|
473 |
*/ |
|
474 |
struct zsd_entry { |
|
475 |
zone_key_t zsd_key; /* Key used to lookup value */ |
|
476 |
void *zsd_data; /* Caller-managed value */ |
|
477 |
/* |
|
478 |
* Callbacks to be executed when a zone is created, shutdown, and |
|
479 |
* destroyed, respectively. |
|
480 |
*/ |
|
481 |
void *(*zsd_create)(zoneid_t); |
|
482 |
void (*zsd_shutdown)(zoneid_t, void *); |
|
483 |
void (*zsd_destroy)(zoneid_t, void *); |
|
484 |
list_node_t zsd_linkage; |
|
485 |
}; |
|
486 |
||
487 |
/* |
|
488 |
* Macros to help with zone visibility restrictions. |
|
489 |
*/ |
|
490 |
||
491 |
/* |
|
492 |
* Is process in the global zone? |
|
493 |
*/ |
|
494 |
#define INGLOBALZONE(p) \ |
|
495 |
((p)->p_zone == global_zone) |
|
496 |
||
497 |
/* |
|
498 |
* Can process view objects in given zone? |
|
499 |
*/ |
|
500 |
#define HASZONEACCESS(p, zoneid) \ |
|
501 |
((p)->p_zone->zone_id == (zoneid) || INGLOBALZONE(p)) |
|
502 |
||
503 |
/* |
|
504 |
* Convenience macro to see if a resolved path is visible from within a |
|
505 |
* given zone. |
|
506 |
* |
|
507 |
* The basic idea is that the first (zone_rootpathlen - 1) bytes of the |
|
508 |
* two strings must be equal. Since the rootpathlen has a trailing '/', |
|
509 |
* we want to skip everything in the path up to (but not including) the |
|
510 |
* trailing '/'. |
|
511 |
*/ |
|
512 |
#define ZONE_PATH_VISIBLE(path, zone) \ |
|
513 |
(strncmp((path), (zone)->zone_rootpath, \ |
|
514 |
(zone)->zone_rootpathlen - 1) == 0) |
|
515 |
||
516 |
/* |
|
517 |
* Convenience macro to go from the global view of a path to that seen |
|
518 |
* from within said zone. It is the responsibility of the caller to |
|
519 |
* ensure that the path is a resolved one (ie, no '..'s or '.'s), and is |
|
520 |
* in fact visible from within the zone. |
|
521 |
*/ |
|
522 |
#define ZONE_PATH_TRANSLATE(path, zone) \ |
|
523 |
(ASSERT(ZONE_PATH_VISIBLE(path, zone)), \ |
|
524 |
(path) + (zone)->zone_rootpathlen - 2) |
|
525 |
||
526 |
/* |
|
527 |
* Special processes visible in all zones. |
|
528 |
*/ |
|
529 |
#define ZONE_SPECIALPID(x) ((x) == 0 || (x) == 1) |
|
530 |
||
531 |
/* |
|
532 |
* Zone-safe version of thread_create() to be used when the caller wants to |
|
533 |
* create a kernel thread to run within the current zone's context. |
|
534 |
*/ |
|
535 |
extern kthread_t *zthread_create(caddr_t, size_t, void (*)(), void *, size_t, |
|
536 |
pri_t); |
|
537 |
extern void zthread_exit(void); |
|
538 |
||
539 |
/* |
|
540 |
* Functions for an external observer to register interest in a zone's status |
|
541 |
* change. Observers will be woken up when the zone status equals the status |
|
542 |
* argument passed in (in the case of zone_status_timedwait, the function may |
|
543 |
* also return because of a timeout; zone_status_wait_sig may return early due |
|
544 |
* to a signal being delivered; zone_status_timedwait_sig may return for any of |
|
545 |
* the above reasons). |
|
546 |
* |
|
547 |
* Otherwise these behave identically to cv_timedwait(), cv_wait(), and |
|
548 |
* cv_wait_sig() respectively. |
|
549 |
*/ |
|
550 |
extern clock_t zone_status_timedwait(zone_t *, clock_t, zone_status_t); |
|
551 |
extern clock_t zone_status_timedwait_sig(zone_t *, clock_t, zone_status_t); |
|
552 |
extern void zone_status_wait(zone_t *, zone_status_t); |
|
553 |
extern int zone_status_wait_sig(zone_t *, zone_status_t); |
|
554 |
||
555 |
/* |
|
556 |
* Get the status of the zone (at the time it was called). The state may |
|
557 |
* have progressed by the time it is returned. |
|
558 |
*/ |
|
559 |
extern zone_status_t zone_status_get(zone_t *); |
|
560 |
||
561 |
/* |
|
562 |
* Get the "kcred" credentials corresponding to the given zone. |
|
563 |
*/ |
|
564 |
extern struct cred *zone_get_kcred(zoneid_t); |
|
565 |
||
566 |
/* |
|
567 |
* Get/set the pool the zone is currently bound to. |
|
568 |
*/ |
|
569 |
extern struct pool *zone_pool_get(zone_t *); |
|
570 |
extern void zone_pool_set(zone_t *, struct pool *); |
|
571 |
||
572 |
/* |
|
573 |
* Get/set the pset the zone is currently using. |
|
574 |
*/ |
|
575 |
extern psetid_t zone_pset_get(zone_t *); |
|
576 |
extern void zone_pset_set(zone_t *, psetid_t); |
|
577 |
||
578 |
/* |
|
579 |
* Get the number of cpus/online-cpus visible from the given zone. |
|
580 |
*/ |
|
581 |
extern int zone_ncpus_get(zone_t *); |
|
582 |
extern int zone_ncpus_online_get(zone_t *); |
|
583 |
||
584 |
/* |
|
789 | 585 |
* Returns true if the named pool/dataset is visible in the current zone. |
586 |
*/ |
|
587 |
extern int zone_dataset_visible(const char *, int *); |
|
588 |
||
589 |
/* |
|
2267 | 590 |
* zone version of kadmin() |
0 | 591 |
*/ |
2267 | 592 |
extern int zone_kadmin(int, int, const char *, cred_t *); |
0 | 593 |
extern void zone_shutdown_global(void); |
594 |
||
595 |
extern void mount_in_progress(void); |
|
596 |
extern void mount_completed(void); |
|
597 |
||
598 |
extern int zone_walk(int (*)(zone_t *, void *), void *); |
|
599 |
||
2768
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
600 |
extern rctl_hndl_t rc_zone_locked_mem; |
3247 | 601 |
extern rctl_hndl_t rc_zone_max_swap; |
2768
3c77434a8dbb
PSARC/2004/580 zone/project.max-locked-memory Resource Controls
sl108498
parents:
2712
diff
changeset
|
602 |
|
0 | 603 |
#endif /* _KERNEL */ |
604 |
||
605 |
#ifdef __cplusplus |
|
606 |
} |
|
607 |
#endif |
|
608 |
||
609 |
#endif /* _SYS_ZONE_H */ |