kernel: M3 shared-fate — shared-memory frames live while any mapping does
Each address space that maps a shared-memory region now holds its own reference, recorded on the AddressSpaceRef and dropped when the space is destroyed — so 'last reference' means no handles AND no mappings, and a region's frames can no longer be freed out from under a sibling thread (or any other live mapper) when the handle-holding task dies. The group-death notification still posts after every mapping release. (docs/shared-fate-plan.md M3)
This commit is contained in:
@@ -173,9 +173,18 @@ pub fn createSharedMemory(phys: u64, pages: usize) ?*SharedMemoryObject {
|
||||
return shared_memory;
|
||||
}
|
||||
|
||||
/// Drop a shared-memory reference; when the last one goes, return its frames to the
|
||||
/// allocator and free the object. (The mappings themselves are torn down with each
|
||||
/// sharer's address space; `device_grant` keeps that from freeing the frames early.)
|
||||
/// Take a shared-memory reference — a MAPPING's reference (docs/shared-fate-plan.md
|
||||
/// M3): each address space that maps the region holds one, recorded on the space
|
||||
/// and dropped at its destruction. Caller holds the big kernel lock.
|
||||
pub fn retainSharedMemory(shared_memory: *SharedMemoryObject) void {
|
||||
shared_memory.refcount += 1;
|
||||
}
|
||||
|
||||
/// Drop a shared-memory reference; when the last one goes — no handles AND no
|
||||
/// mappings left — return its frames to the allocator and free the object.
|
||||
/// (The mappings themselves are torn down with each sharer's address space;
|
||||
/// `device_grant` keeps that sweep from freeing the frames, and the space's
|
||||
/// recorded mapping references keep this drop from freeing them early.)
|
||||
pub fn dropSharedMemoryReference(shared_memory: *SharedMemoryObject) void {
|
||||
if (shared_memory.refcount > 1) {
|
||||
shared_memory.refcount -= 1;
|
||||
|
||||
Reference in New Issue
Block a user