tcsetpgrp(3): Return EINVAL upon invalid process group id.
[dragonfly.git] / sys / kern / tty.c
1 /*-
2  * Copyright (c) 1982, 1986, 1990, 1991, 1993
3  *      The Regents of the University of California.  All rights reserved.
4  * (c) UNIX System Laboratories, Inc.
5  * All or some portions of this file are derived from material licensed
6  * to the University of California by American Telephone and Telegraph
7  * Co. or Unix System Laboratories, Inc. and are reproduced herein with
8  * the permission of UNIX System Laboratories, Inc.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  * 3. All advertising materials mentioning features or use of this software
19  *    must display the following acknowledgement:
20  *      This product includes software developed by the University of
21  *      California, Berkeley and its contributors.
22  * 4. Neither the name of the University nor the names of its contributors
23  *    may be used to endorse or promote products derived from this software
24  *    without specific prior written permission.
25  *
26  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
27  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
28  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
29  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
30  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
31  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
32  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
33  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
34  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
35  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
36  * SUCH DAMAGE.
37  *
38  *      @(#)tty.c       8.8 (Berkeley) 1/21/94
39  * $FreeBSD: src/sys/kern/tty.c,v 1.129.2.5 2002/03/11 01:32:31 dd Exp $
40  * $DragonFly: src/sys/kern/tty.c,v 1.46 2008/09/10 09:50:09 y0netan1 Exp $
41  */
42
43 /*-
44  * TODO:
45  *      o Fix races for sending the start char in ttyflush().
46  *      o Handle inter-byte timeout for "MIN > 0, TIME > 0" in ttyselect().
47  *        With luck, there will be MIN chars before select() returns().
48  *      o Handle CLOCAL consistently for ptys.  Perhaps disallow setting it.
49  *      o Don't allow input in TS_ZOMBIE case.  It would be visible through
50  *        FIONREAD.
51  *      o Do the new sio locking stuff here and use it to avoid special
52  *        case for EXTPROC?
53  *      o Lock PENDIN too?
54  *      o Move EXTPROC and/or PENDIN to t_state?
55  *      o Wrap most of ttioctl in spltty/splx.
56  *      o Implement TIOCNOTTY or remove it from <sys/ioctl.h>.
57  *      o Send STOP if IXOFF is toggled off while TS_TBLOCK is set.
58  *      o Don't allow certain termios flags to affect disciplines other
59  *        than TTYDISC.  Cancel their effects before switch disciplines
60  *        and ignore them if they are set while we are in another
61  *        discipline.
62  *      o Now that historical speed conversions are handled here, don't
63  *        do them in drivers.
64  *      o Check for TS_CARR_ON being set while everything is closed and not
65  *        waiting for carrier.  TS_CARR_ON isn't cleared if nothing is open,
66  *        so it would live until the next open even if carrier drops.
67  *      o Restore TS_WOPEN since it is useful in pstat.  It must be cleared
68  *        only when _all_ openers leave open().
69  */
70
71 #include "opt_compat.h"
72 #include "opt_uconsole.h"
73
74 #include <sys/param.h>
75 #include <sys/systm.h>
76 #include <sys/filio.h>
77 #if defined(COMPAT_43) || defined(COMPAT_SUNOS)
78 #include <sys/ioctl_compat.h>
79 #endif
80 #include <sys/proc.h>
81 #include <sys/priv.h>
82 #define TTYDEFCHARS
83 #include <sys/tty.h>
84 #include <sys/clist.h>
85 #undef  TTYDEFCHARS
86 #include <sys/fcntl.h>
87 #include <sys/conf.h>
88 #include <sys/dkstat.h>
89 #include <sys/poll.h>
90 #include <sys/kernel.h>
91 #include <sys/vnode.h>
92 #include <sys/signalvar.h>
93 #include <sys/signal2.h>
94 #include <sys/resourcevar.h>
95 #include <sys/malloc.h>
96 #include <sys/filedesc.h>
97 #include <sys/sysctl.h>
98 #include <sys/thread2.h>
99
100 #include <vm/vm.h>
101 #include <sys/lock.h>
102 #include <vm/pmap.h>
103 #include <vm/vm_map.h>
104
105 MALLOC_DEFINE(M_TTYS, "ttys", "tty data structures");
106
107 static int      proc_compare (struct proc *p1, struct proc *p2);
108 static int      ttnread (struct tty *tp);
109 static void     ttyecho (int c, struct tty *tp);
110 static int      ttyoutput (int c, struct tty *tp);
111 static void     ttypend (struct tty *tp);
112 static void     ttyretype (struct tty *tp);
113 static void     ttyrub (int c, struct tty *tp);
114 static void     ttyrubo (struct tty *tp, int cnt);
115 static void     ttyunblock (struct tty *tp);
116 static int      ttywflush (struct tty *tp);
117 static int      filt_ttyread (struct knote *kn, long hint);
118 static void     filt_ttyrdetach (struct knote *kn);
119 static int      filt_ttywrite (struct knote *kn, long hint);
120 static void     filt_ttywdetach (struct knote *kn);
121
122 /*
123  * Table with character classes and parity. The 8th bit indicates parity,
124  * the 7th bit indicates the character is an alphameric or underscore (for
125  * ALTWERASE), and the low 6 bits indicate delay type.  If the low 6 bits
126  * are 0 then the character needs no special processing on output; classes
127  * other than 0 might be translated or (not currently) require delays.
128  */
129 #define E       0x00    /* Even parity. */
130 #define O       0x80    /* Odd parity. */
131 #define PARITY(c)       (char_type[c] & O)
132
133 #define ALPHA   0x40    /* Alpha or underscore. */
134 #define ISALPHA(c)      (char_type[(c) & TTY_CHARMASK] & ALPHA)
135
136 #define CCLASSMASK      0x3f
137 #define CCLASS(c)       (char_type[c] & CCLASSMASK)
138
139 #define BS      BACKSPACE
140 #define CC      CONTROL
141 #define CR      RETURN
142 #define NA      ORDINARY | ALPHA
143 #define NL      NEWLINE
144 #define NO      ORDINARY
145 #define TB      TAB
146 #define VT      VTAB
147
148 static u_char const char_type[] = {
149         E|CC, O|CC, O|CC, E|CC, O|CC, E|CC, E|CC, O|CC, /* nul - bel */
150         O|BS, E|TB, E|NL, O|CC, E|VT, O|CR, O|CC, E|CC, /* bs - si */
151         O|CC, E|CC, E|CC, O|CC, E|CC, O|CC, O|CC, E|CC, /* dle - etb */
152         E|CC, O|CC, O|CC, E|CC, O|CC, E|CC, E|CC, O|CC, /* can - us */
153         O|NO, E|NO, E|NO, O|NO, E|NO, O|NO, O|NO, E|NO, /* sp - ' */
154         E|NO, O|NO, O|NO, E|NO, O|NO, E|NO, E|NO, O|NO, /* ( - / */
155         E|NA, O|NA, O|NA, E|NA, O|NA, E|NA, E|NA, O|NA, /* 0 - 7 */
156         O|NA, E|NA, E|NO, O|NO, E|NO, O|NO, O|NO, E|NO, /* 8 - ? */
157         O|NO, E|NA, E|NA, O|NA, E|NA, O|NA, O|NA, E|NA, /* @ - G */
158         E|NA, O|NA, O|NA, E|NA, O|NA, E|NA, E|NA, O|NA, /* H - O */
159         E|NA, O|NA, O|NA, E|NA, O|NA, E|NA, E|NA, O|NA, /* P - W */
160         O|NA, E|NA, E|NA, O|NO, E|NO, O|NO, O|NO, O|NA, /* X - _ */
161         E|NO, O|NA, O|NA, E|NA, O|NA, E|NA, E|NA, O|NA, /* ` - g */
162         O|NA, E|NA, E|NA, O|NA, E|NA, O|NA, O|NA, E|NA, /* h - o */
163         O|NA, E|NA, E|NA, O|NA, E|NA, O|NA, O|NA, E|NA, /* p - w */
164         E|NA, O|NA, O|NA, E|NO, O|NO, E|NO, E|NO, O|CC, /* x - del */
165         /*
166          * Meta chars; should be settable per character set;
167          * for now, treat them all as normal characters.
168          */
169         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
170         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
171         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
172         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
173         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
174         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
175         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
176         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
177         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
178         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
179         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
180         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
181         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
182         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
183         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
184         NA,   NA,   NA,   NA,   NA,   NA,   NA,   NA,
185 };
186 #undef  BS
187 #undef  CC
188 #undef  CR
189 #undef  NA
190 #undef  NL
191 #undef  NO
192 #undef  TB
193 #undef  VT
194
195 /* Macros to clear/set/test flags. */
196 #define SET(t, f)       (t) |= (f)
197 #define CLR(t, f)       (t) &= ~(f)
198 #define ISSET(t, f)     ((t) & (f))
199
200 #undef MAX_INPUT                /* XXX wrong in <sys/syslimits.h> */
201 #define MAX_INPUT       TTYHOG  /* XXX limit is usually larger for !ICANON */
202
203 uint64_t tk_nin;
204 SYSCTL_OPAQUE(_kern, OID_AUTO, tk_nin, CTLFLAG_RD, &tk_nin, sizeof(tk_nin),
205     "LU", "TTY input statistic");
206 uint64_t tk_nout;
207 SYSCTL_OPAQUE(_kern, OID_AUTO, tk_nout, CTLFLAG_RD, &tk_nout, sizeof(tk_nout),
208     "LU", "TTY output statistic");
209 uint64_t tk_rawcc;
210
211 /*
212  * list of struct tty where pstat(8) can pick it up with sysctl
213  */
214 static SLIST_HEAD(, tty) tty_list;
215
216 /*
217  * Initial open of tty, or (re)entry to standard tty line discipline.
218  */
219 int
220 ttyopen(cdev_t device, struct tty *tp)
221 {
222         crit_enter();
223         tp->t_dev = device;
224         if (!ISSET(tp->t_state, TS_ISOPEN)) {
225                 SET(tp->t_state, TS_ISOPEN);
226                 if (ISSET(tp->t_cflag, CLOCAL))
227                         SET(tp->t_state, TS_CONNECTED);
228                 bzero(&tp->t_winsize, sizeof(tp->t_winsize));
229         }
230         ttsetwater(tp);
231         crit_exit();
232         return (0);
233 }
234
235 /*
236  * Handle close() on a tty line: flush and set to initial state,
237  * bumping generation number so that pending read/write calls
238  * can detect recycling of the tty.
239  *
240  * XXX our caller should have done `spltty(); l_close(); ttyclose();'
241  * and l_close() should have flushed, but we repeat the spltty() and
242  * the flush in case there are buggy callers.
243  */
244 int
245 ttyclose(struct tty *tp)
246 {
247         funsetown(tp->t_sigio);
248         crit_enter();
249         if (constty == tp)
250                 constty = NULL;
251
252         ttyflush(tp, FREAD | FWRITE);
253         clist_free_cblocks(&tp->t_canq);
254         clist_free_cblocks(&tp->t_outq);
255         clist_free_cblocks(&tp->t_rawq);
256
257         tp->t_gen++;
258         tp->t_line = TTYDISC;
259         ttyclearsession(tp);
260         tp->t_state = 0;
261         crit_exit();
262         return (0);
263 }
264
265 /*
266  * Disassociate the tty from its session.  Traditionally this has only been
267  * a half-close, meaning that the session was still allowed to point at the
268  * tty (resulting in the tty in the ps command showing something like 'p0-'),
269  * even though the tty is no longer pointing at the session.
270  *
271  * The half close seems to be useful only for 'ps' output but there is as
272  * yet no reason to remove the feature.  The full-close code is currently
273  * #if 0'd out.  See also sess_rele() in kern/kern_proc.c.
274  */
275 void
276 ttyclearsession(struct tty *tp)
277 {
278         struct session *sp;
279
280         tp->t_pgrp = NULL;
281         if ((sp = tp->t_session) != NULL) {
282                 tp->t_session = NULL;
283 #ifdef TTY_DO_FULL_CLOSE
284                 /* FULL CLOSE (not yet) */
285                 if (sp->s_ttyp == tp) {
286                         sp->s_ttyp = NULL;
287                 } else {
288                         kprintf("ttyclearsession: warning: sp->s_ttyp != tp "
289                                 "%p/%p\n", sp->s_ttyp, tp);
290                 }
291 #endif
292         }
293 }
294
295 /*
296  * Release the tty vnode association for a session.  This is the 
297  * 'other half' of the close.  Because multiple opens of /dev/tty
298  * only generate a single open to the actual tty, the file modes
299  * are locked to FREAD|FWRITE.
300  *
301  * If dorevoke is non-zero, the session is also revoked.  We have to
302  * close the vnode if VCTTYISOPEN is set.
303  */
304 void
305 ttyclosesession(struct session *sp, int dorevoke)
306 {
307         struct vnode *vp;
308
309 retry:
310         /*
311          * There may not be a controlling terminal or it may have been closed
312          * out from under us.
313          */
314         if ((vp = sp->s_ttyvp) == NULL)
315                 return;
316
317         /*
318          * We need a lock if we have to close or revoke.
319          */
320         if ((vp->v_flag & VCTTYISOPEN) || dorevoke) {
321                 vhold(vp);
322                 if (vn_lock(vp, LK_EXCLUSIVE|LK_RETRY)) {
323                         vdrop(vp);
324                         goto retry;
325                 }
326
327                 /*
328                  * Retry if the vnode was ripped out from under us
329                  */
330                 if (vp != sp->s_ttyvp) {
331                         vn_unlock(vp);
332                         vdrop(vp);
333                         goto retry;
334                 }
335
336                 /*
337                  * Close and revoke as needed
338                  */
339                 sp->s_ttyvp = NULL;
340                 if (vp->v_flag & VCTTYISOPEN) {
341                         vclrflags(vp, VCTTYISOPEN);
342                         VOP_CLOSE(vp, FREAD|FWRITE);
343                 }
344                 vn_unlock(vp);
345                 if (dorevoke)
346                         vrevoke(vp, proc0.p_ucred);
347                 vdrop(vp);
348         } else {
349                 sp->s_ttyvp = NULL;
350         }
351         vrele(vp);
352 }
353
354 #define FLUSHQ(q) {                                                     \
355         if ((q)->c_cc)                                                  \
356                 ndflush(q, (q)->c_cc);                                  \
357 }
358
359 /* Is 'c' a line delimiter ("break" character)? */
360 #define TTBREAKC(c, lflag)                                                      \
361         ((c) == '\n' || (((c) == cc[VEOF] ||                            \
362           (c) == cc[VEOL] || ((c) == cc[VEOL2] && lflag & IEXTEN)) &&   \
363          (c) != _POSIX_VDISABLE))
364
365 /*
366  * Process input of a single character received on a tty.
367  */
368 int
369 ttyinput(int c, struct tty *tp)
370 {
371         tcflag_t iflag, lflag;
372         cc_t *cc;
373         int i, err;
374
375         /*
376          * If input is pending take it first.
377          */
378         lflag = tp->t_lflag;
379         if (ISSET(lflag, PENDIN))
380                 ttypend(tp);
381         /*
382          * Gather stats.
383          */
384         if (ISSET(lflag, ICANON))
385                 ++tp->t_cancc;
386         else
387                 ++tp->t_rawcc;
388         ++tk_nin;
389
390         /*
391          * Block further input iff:
392          * current input > threshold AND input is available to user program
393          * AND input flow control is enabled and not yet invoked.
394          * The 3 is slop for PARMRK.
395          */
396         iflag = tp->t_iflag;
397         if (tp->t_rawq.c_cc + tp->t_canq.c_cc > tp->t_ihiwat - 3 &&
398             (!ISSET(lflag, ICANON) || tp->t_canq.c_cc != 0) &&
399             (ISSET(tp->t_cflag, CRTS_IFLOW) || ISSET(iflag, IXOFF)) &&
400             !ISSET(tp->t_state, TS_TBLOCK))
401                 ttyblock(tp);
402
403         /* Handle exceptional conditions (break, parity, framing). */
404         cc = tp->t_cc;
405         err = (ISSET(c, TTY_ERRORMASK));
406         if (err) {
407                 CLR(c, TTY_ERRORMASK);
408                 if (ISSET(err, TTY_BI)) {
409                         if (ISSET(iflag, IGNBRK))
410                                 return (0);
411                         if (ISSET(iflag, BRKINT)) {
412                                 ttyflush(tp, FREAD | FWRITE);
413                                 pgsignal(tp->t_pgrp, SIGINT, 1);
414                                 goto endcase;
415                         }
416                         if (ISSET(iflag, PARMRK))
417                                 goto parmrk;
418                 } else if ((ISSET(err, TTY_PE) && ISSET(iflag, INPCK))
419                         || ISSET(err, TTY_FE)) {
420                         if (ISSET(iflag, IGNPAR))
421                                 return (0);
422                         else if (ISSET(iflag, PARMRK)) {
423 parmrk:
424                                 if (tp->t_rawq.c_cc + tp->t_canq.c_cc >
425                                     MAX_INPUT - 3)
426                                         goto input_overflow;
427                                 clist_putc(0377 | TTY_QUOTE, &tp->t_rawq);
428                                 clist_putc(0 | TTY_QUOTE, &tp->t_rawq);
429                                 clist_putc(c | TTY_QUOTE, &tp->t_rawq);
430                                 goto endcase;
431                         } else
432                                 c = 0;
433                 }
434         }
435
436         if (!ISSET(tp->t_state, TS_TYPEN) && ISSET(iflag, ISTRIP))
437                 CLR(c, 0x80);
438         if (!ISSET(lflag, EXTPROC)) {
439                 /*
440                  * Check for literal nexting very first
441                  */
442                 if (ISSET(tp->t_state, TS_LNCH)) {
443                         SET(c, TTY_QUOTE);
444                         CLR(tp->t_state, TS_LNCH);
445                 }
446                 /*
447                  * Scan for special characters.  This code
448                  * is really just a big case statement with
449                  * non-constant cases.  The bottom of the
450                  * case statement is labeled ``endcase'', so goto
451                  * it after a case match, or similar.
452                  */
453
454                 /*
455                  * Control chars which aren't controlled
456                  * by ICANON, ISIG, or IXON.
457                  */
458                 if (ISSET(lflag, IEXTEN)) {
459                         if (CCEQ(cc[VLNEXT], c)) {
460                                 if (ISSET(lflag, ECHO)) {
461                                         if (ISSET(lflag, ECHOE)) {
462                                                 (void)ttyoutput('^', tp);
463                                                 (void)ttyoutput('\b', tp);
464                                         } else
465                                                 ttyecho(c, tp);
466                                 }
467                                 SET(tp->t_state, TS_LNCH);
468                                 goto endcase;
469                         }
470                         if (CCEQ(cc[VDISCARD], c)) {
471                                 if (ISSET(lflag, FLUSHO))
472                                         CLR(tp->t_lflag, FLUSHO);
473                                 else {
474                                         ttyflush(tp, FWRITE);
475                                         ttyecho(c, tp);
476                                         if (tp->t_rawq.c_cc + tp->t_canq.c_cc)
477                                                 ttyretype(tp);
478                                         SET(tp->t_lflag, FLUSHO);
479                                 }
480                                 goto startoutput;
481                         }
482                 }
483                 /*
484                  * Signals.
485                  */
486                 if (ISSET(lflag, ISIG)) {
487                         if (CCEQ(cc[VINTR], c) || CCEQ(cc[VQUIT], c)) {
488                                 if (!ISSET(lflag, NOFLSH))
489                                         ttyflush(tp, FREAD | FWRITE);
490                                 ttyecho(c, tp);
491                                 pgsignal(tp->t_pgrp,
492                                     CCEQ(cc[VINTR], c) ? SIGINT : SIGQUIT, 1);
493                                 goto endcase;
494                         }
495                         if (CCEQ(cc[VSUSP], c)) {
496                                 if (!ISSET(lflag, NOFLSH))
497                                         ttyflush(tp, FREAD);
498                                 ttyecho(c, tp);
499                                 pgsignal(tp->t_pgrp, SIGTSTP, 1);
500                                 goto endcase;
501                         }
502                 }
503                 /*
504                  * Handle start/stop characters.
505                  */
506                 if (ISSET(iflag, IXON)) {
507                         if (CCEQ(cc[VSTOP], c)) {
508                                 if (!ISSET(tp->t_state, TS_TTSTOP)) {
509                                         SET(tp->t_state, TS_TTSTOP);
510                                         (*tp->t_stop)(tp, 0);
511                                         return (0);
512                                 }
513                                 if (!CCEQ(cc[VSTART], c))
514                                         return (0);
515                                 /*
516                                  * if VSTART == VSTOP then toggle
517                                  */
518                                 goto endcase;
519                         }
520                         if (CCEQ(cc[VSTART], c))
521                                 goto restartoutput;
522                 }
523                 /*
524                  * IGNCR, ICRNL, & INLCR
525                  */
526                 if (c == '\r') {
527                         if (ISSET(iflag, IGNCR))
528                                 return (0);
529                         else if (ISSET(iflag, ICRNL))
530                                 c = '\n';
531                 } else if (c == '\n' && ISSET(iflag, INLCR))
532                         c = '\r';
533         }
534         if (!ISSET(tp->t_lflag, EXTPROC) && ISSET(lflag, ICANON)) {
535                 /*
536                  * From here on down canonical mode character
537                  * processing takes place.
538                  */
539                 /*
540                  * erase or erase2 (^H / ^?)
541                  */
542                 if (CCEQ(cc[VERASE], c) || CCEQ(cc[VERASE2], c) ) {
543                         if (tp->t_rawq.c_cc)
544                                 ttyrub(clist_unputc(&tp->t_rawq), tp);
545                         goto endcase;
546                 }
547                 /*
548                  * kill (^U)
549                  */
550                 if (CCEQ(cc[VKILL], c)) {
551                         if (ISSET(lflag, ECHOKE) &&
552                             tp->t_rawq.c_cc == tp->t_rocount &&
553                             !ISSET(lflag, ECHOPRT))
554                                 while (tp->t_rawq.c_cc)
555                                         ttyrub(clist_unputc(&tp->t_rawq), tp);
556                         else {
557                                 ttyecho(c, tp);
558                                 if (ISSET(lflag, ECHOK) ||
559                                     ISSET(lflag, ECHOKE))
560                                         ttyecho('\n', tp);
561                                 FLUSHQ(&tp->t_rawq);
562                                 tp->t_rocount = 0;
563                         }
564                         CLR(tp->t_state, TS_LOCAL);
565                         goto endcase;
566                 }
567                 /*
568                  * word erase (^W)
569                  */
570                 if (CCEQ(cc[VWERASE], c) && ISSET(lflag, IEXTEN)) {
571                         int ctype;
572
573                         /*
574                          * erase whitespace
575                          */
576                         while ((c = clist_unputc(&tp->t_rawq)) == ' ' || c == '\t')
577                                 ttyrub(c, tp);
578                         if (c == -1)
579                                 goto endcase;
580                         /*
581                          * erase last char of word and remember the
582                          * next chars type (for ALTWERASE)
583                          */
584                         ttyrub(c, tp);
585                         c = clist_unputc(&tp->t_rawq);
586                         if (c == -1)
587                                 goto endcase;
588                         if (c == ' ' || c == '\t') {
589                                 clist_putc(c, &tp->t_rawq);
590                                 goto endcase;
591                         }
592                         ctype = ISALPHA(c);
593                         /*
594                          * erase rest of word
595                          */
596                         do {
597                                 ttyrub(c, tp);
598                                 c = clist_unputc(&tp->t_rawq);
599                                 if (c == -1)
600                                         goto endcase;
601                         } while (c != ' ' && c != '\t' &&
602                             (!ISSET(lflag, ALTWERASE) || ISALPHA(c) == ctype));
603                         clist_putc(c, &tp->t_rawq);
604                         goto endcase;
605                 }
606                 /*
607                  * reprint line (^R)
608                  */
609                 if (CCEQ(cc[VREPRINT], c) && ISSET(lflag, IEXTEN)) {
610                         ttyretype(tp);
611                         goto endcase;
612                 }
613                 /*
614                  * ^T - kernel info and generate SIGINFO
615                  */
616                 if (CCEQ(cc[VSTATUS], c) && ISSET(lflag, IEXTEN)) {
617                         if (ISSET(lflag, ISIG))
618                                 pgsignal(tp->t_pgrp, SIGINFO, 1);
619                         if (!ISSET(lflag, NOKERNINFO))
620                                 ttyinfo(tp);
621                         goto endcase;
622                 }
623                 if (CCEQ(cc[VCHECKPT], c) && ISSET(lflag, IEXTEN)) {
624                         if (ISSET(lflag, ISIG))
625                                 pgsignal(tp->t_pgrp, SIGCKPT, 1);
626                         goto endcase;
627                 }
628         }
629         /*
630          * Check for input buffer overflow
631          */
632         if (tp->t_rawq.c_cc + tp->t_canq.c_cc >= MAX_INPUT) {
633 input_overflow:
634                 if (ISSET(iflag, IMAXBEL)) {
635                         if (tp->t_outq.c_cc < tp->t_ohiwat)
636                                 (void)ttyoutput(CTRL('g'), tp);
637                 }
638                 goto endcase;
639         }
640
641         if (   c == 0377 && ISSET(iflag, PARMRK) && !ISSET(iflag, ISTRIP)
642              && ISSET(iflag, IGNBRK|IGNPAR) != (IGNBRK|IGNPAR))
643                 clist_putc(0377 | TTY_QUOTE, &tp->t_rawq);
644
645         /*
646          * Put data char in q for user and
647          * wakeup on seeing a line delimiter.
648          */
649         if (clist_putc(c, &tp->t_rawq) >= 0) {
650                 if (!ISSET(lflag, ICANON)) {
651                         ttwakeup(tp);
652                         ttyecho(c, tp);
653                         goto endcase;
654                 }
655                 if (TTBREAKC(c, lflag)) {
656                         tp->t_rocount = 0;
657                         catq(&tp->t_rawq, &tp->t_canq);
658                         ttwakeup(tp);
659                 } else if (tp->t_rocount++ == 0)
660                         tp->t_rocol = tp->t_column;
661                 if (ISSET(tp->t_state, TS_ERASE)) {
662                         /*
663                          * end of prterase \.../
664                          */
665                         CLR(tp->t_state, TS_ERASE);
666                         (void)ttyoutput('/', tp);
667                 }
668                 i = tp->t_column;
669                 ttyecho(c, tp);
670                 if (CCEQ(cc[VEOF], c) && ISSET(lflag, ECHO)) {
671                         /*
672                          * Place the cursor over the '^' of the ^D.
673                          */
674                         i = imin(2, tp->t_column - i);
675                         while (i > 0) {
676                                 (void)ttyoutput('\b', tp);
677                                 i--;
678                         }
679                 }
680         }
681 endcase:
682         /*
683          * IXANY means allow any character to restart output.
684          */
685         if (ISSET(tp->t_state, TS_TTSTOP) &&
686             !ISSET(iflag, IXANY) && cc[VSTART] != cc[VSTOP])
687                 return (0);
688 restartoutput:
689         CLR(tp->t_lflag, FLUSHO);
690         CLR(tp->t_state, TS_TTSTOP);
691 startoutput:
692         return (ttstart(tp));
693 }
694
695 /*
696  * Output a single character on a tty, doing output processing
697  * as needed (expanding tabs, newline processing, etc.).
698  * Returns < 0 if succeeds, otherwise returns char to resend.
699  * Must be recursive.
700  */
701 static int
702 ttyoutput(int c, struct tty *tp)
703 {
704         tcflag_t oflag;
705         int col;
706
707         oflag = tp->t_oflag;
708         if (!ISSET(oflag, OPOST)) {
709                 if (ISSET(tp->t_lflag, FLUSHO))
710                         return (-1);
711                 if (clist_putc(c, &tp->t_outq))
712                         return (c);
713                 tk_nout++;
714                 tp->t_outcc++;
715                 return (-1);
716         }
717         /*
718          * Do tab expansion if OXTABS is set.  Special case if we external
719          * processing, we don't do the tab expansion because we'll probably
720          * get it wrong.  If tab expansion needs to be done, let it happen
721          * externally.
722          */
723         CLR(c, ~TTY_CHARMASK);
724         if (c == '\t' &&
725             ISSET(oflag, OXTABS) && !ISSET(tp->t_lflag, EXTPROC)) {
726                 c = 8 - (tp->t_column & 7);
727                 if (!ISSET(tp->t_lflag, FLUSHO)) {
728                         crit_enter();           /* Don't interrupt tabs. */
729                         c -= b_to_q("        ", c, &tp->t_outq);
730                         tk_nout += c;
731                         tp->t_outcc += c;
732                         crit_exit();
733                 }
734                 tp->t_column += c;
735                 return (c ? -1 : '\t');
736         }
737         if (c == CEOT && ISSET(oflag, ONOEOT))
738                 return (-1);
739
740         /*
741          * Newline translation: if ONLCR is set,
742          * translate newline into "\r\n".
743          */
744         if (c == '\n' && ISSET(tp->t_oflag, ONLCR)) {
745                 tk_nout++;
746                 tp->t_outcc++;
747                 if (!ISSET(tp->t_lflag, FLUSHO) && clist_putc('\r', &tp->t_outq))
748                         return (c);
749         }
750         /* If OCRNL is set, translate "\r" into "\n". */
751         else if (c == '\r' && ISSET(tp->t_oflag, OCRNL))
752                 c = '\n';
753         /* If ONOCR is set, don't transmit CRs when on column 0. */
754         else if (c == '\r' && ISSET(tp->t_oflag, ONOCR) && tp->t_column == 0)
755                 return (-1);
756
757         tk_nout++;
758         tp->t_outcc++;
759         if (!ISSET(tp->t_lflag, FLUSHO) && clist_putc(c, &tp->t_outq))
760                 return (c);
761
762         col = tp->t_column;
763         switch (CCLASS(c)) {
764         case BACKSPACE:
765                 if (col > 0)
766                         --col;
767                 break;
768         case CONTROL:
769                 break;
770         case NEWLINE:
771                 if (ISSET(tp->t_oflag, ONLCR | ONLRET))
772                         col = 0;
773                 break;
774         case RETURN:
775                 col = 0;
776                 break;
777         case ORDINARY:
778                 ++col;
779                 break;
780         case TAB:
781                 col = (col + 8) & ~7;
782                 break;
783         }
784         tp->t_column = col;
785         return (-1);
786 }
787
788 /*
789  * Ioctls for all tty devices.  Called after line-discipline specific ioctl
790  * has been called to do discipline-specific functions and/or reject any
791  * of these ioctl commands.
792  */
793 /* ARGSUSED */
794 int
795 ttioctl(struct tty *tp, u_long cmd, void *data, int flag)
796 {
797         struct thread *td = curthread;
798         struct lwp *lp = td->td_lwp;
799         struct proc *p = td->td_proc;
800         int error;
801
802         KKASSERT(p);
803
804         /* If the ioctl involves modification, hang if in the background. */
805         switch (cmd) {
806         case  TIOCCBRK:
807         case  TIOCCONS:
808         case  TIOCDRAIN:
809         case  TIOCEXCL:
810         case  TIOCFLUSH:
811 #ifdef TIOCHPCL
812         case  TIOCHPCL:
813 #endif
814         case  TIOCNXCL:
815         case  TIOCSBRK:
816         case  TIOCSCTTY:
817         case  TIOCSDRAINWAIT:
818         case  TIOCSETA:
819         case  TIOCSETAF:
820         case  TIOCSETAW:
821         case  TIOCSETD:
822         case  TIOCSPGRP:
823         case  TIOCSTART:
824         case  TIOCSTAT:
825         case  TIOCSTI:
826         case  TIOCSTOP:
827         case  TIOCSWINSZ:
828 #if defined(COMPAT_43) || defined(COMPAT_SUNOS)
829         case  TIOCLBIC:
830         case  TIOCLBIS:
831         case  TIOCLSET:
832         case  TIOCSETC:
833         case OTIOCSETD:
834         case  TIOCSETN:
835         case  TIOCSETP:
836         case  TIOCSLTC:
837 #endif
838                 while (isbackground(p, tp) && !(p->p_flag & P_PPWAIT) &&
839                     !SIGISMEMBER(p->p_sigignore, SIGTTOU) &&
840                     !SIGISMEMBER(lp->lwp_sigmask, SIGTTOU)) {
841                         if (p->p_pgrp->pg_jobc == 0)
842                                 return (EIO);
843                         pgsignal(p->p_pgrp, SIGTTOU, 1);
844                         error = ttysleep(tp, &lbolt, PCATCH, "ttybg1",
845                                          0);
846                         if (error)
847                                 return (error);
848                 }
849                 break;
850         }
851
852         switch (cmd) {                  /* Process the ioctl. */
853         case FIOASYNC:                  /* set/clear async i/o */
854                 crit_enter();
855                 if (*(int *)data)
856                         SET(tp->t_state, TS_ASYNC);
857                 else
858                         CLR(tp->t_state, TS_ASYNC);
859                 crit_exit();
860                 break;
861         case FIONREAD:                  /* get # bytes to read */
862                 crit_enter();
863                 *(int *)data = ttnread(tp);
864                 crit_exit();
865                 break;
866
867         case FIOSETOWN:
868                 /*
869                  * Policy -- Don't allow FIOSETOWN on someone else's 
870                  *           controlling tty
871                  */
872                 if (tp->t_session != NULL && !isctty(p, tp))
873                         return (ENOTTY);
874
875                 error = fsetown(*(int *)data, &tp->t_sigio);
876                 if (error)
877                         return (error);
878                 break;
879         case FIOGETOWN:
880                 if (tp->t_session != NULL && !isctty(p, tp))
881                         return (ENOTTY);
882                 *(int *)data = fgetown(tp->t_sigio);
883                 break;
884
885         case TIOCEXCL:                  /* set exclusive use of tty */
886                 crit_enter();
887                 SET(tp->t_state, TS_XCLUDE);
888                 crit_exit();
889                 break;
890         case TIOCFLUSH: {               /* flush buffers */
891                 int flags = *(int *)data;
892
893                 if (flags == 0)
894                         flags = FREAD | FWRITE;
895                 else
896                         flags &= FREAD | FWRITE;
897                 ttyflush(tp, flags);
898                 break;
899         }
900         case TIOCCONS:                  /* become virtual console */
901                 if (*(int *)data) {
902                         if (constty && constty != tp &&
903                             ISSET(constty->t_state, TS_CONNECTED))
904                                 return (EBUSY);
905 #ifndef UCONSOLE
906                         if ((error = priv_check(td, PRIV_ROOT)) != 0)
907                                 return (error);
908 #endif
909                         constty = tp;
910                 } else if (tp == constty)
911                         constty = NULL;
912                 break;
913         case TIOCDRAIN:                 /* wait till output drained */
914                 error = ttywait(tp);
915                 if (error)
916                         return (error);
917                 break;
918         case TIOCGETA: {                /* get termios struct */
919                 struct termios *t = (struct termios *)data;
920
921                 bcopy(&tp->t_termios, t, sizeof(struct termios));
922                 break;
923         }
924         case TIOCGETD:                  /* get line discipline */
925                 *(int *)data = tp->t_line;
926                 break;
927         case TIOCGWINSZ:                /* get window size */
928                 *(struct winsize *)data = tp->t_winsize;
929                 break;
930         case TIOCGPGRP:                 /* get pgrp of tty */
931                 if (!isctty(p, tp))
932                         return (ENOTTY);
933                 *(int *)data = tp->t_pgrp ? tp->t_pgrp->pg_id : NO_PID;
934                 break;
935         case TIOCGSID:                  /* get sid of tty */
936                 if (!isctty(p, tp))
937                         return (ENOTTY);
938                 *(int *)data = tp->t_session->s_sid;
939                 break;
940 #ifdef TIOCHPCL
941         case TIOCHPCL:                  /* hang up on last close */
942                 crit_enter();
943                 SET(tp->t_cflag, HUPCL);
944                 crit_exit();
945                 break;
946 #endif
947         case TIOCNXCL:                  /* reset exclusive use of tty */
948                 crit_enter();
949                 CLR(tp->t_state, TS_XCLUDE);
950                 crit_exit();
951                 break;
952         case TIOCOUTQ:                  /* output queue size */
953                 *(int *)data = tp->t_outq.c_cc;
954                 break;
955         case TIOCSETA:                  /* set termios struct */
956         case TIOCSETAW:                 /* drain output, set */
957         case TIOCSETAF: {               /* drn out, fls in, set */
958                 struct termios *t = (struct termios *)data;
959
960                 if (t->c_ispeed == 0)
961                         t->c_ispeed = t->c_ospeed;
962                 if (t->c_ispeed == 0)
963                         t->c_ispeed = tp->t_ospeed;
964                 if (t->c_ispeed == 0)
965                         return (EINVAL);
966                 crit_enter();
967                 if (cmd == TIOCSETAW || cmd == TIOCSETAF) {
968                         error = ttywait(tp);
969                         if (error) {
970                                 crit_exit();
971                                 return (error);
972                         }
973                         if (cmd == TIOCSETAF)
974                                 ttyflush(tp, FREAD);
975                 }
976                 if (!ISSET(t->c_cflag, CIGNORE)) {
977                         /*
978                          * Set device hardware.
979                          */
980                         if (tp->t_param && (error = (*tp->t_param)(tp, t))) {
981                                 crit_exit();
982                                 return (error);
983                         }
984                         if (ISSET(t->c_cflag, CLOCAL) &&
985                             !ISSET(tp->t_cflag, CLOCAL)) {
986                                 /*
987                                  * XXX disconnections would be too hard to
988                                  * get rid of without this kludge.  The only
989                                  * way to get rid of controlling terminals
990                                  * is to exit from the session leader.
991                                  */
992                                 CLR(tp->t_state, TS_ZOMBIE);
993
994                                 wakeup(TSA_CARR_ON(tp));
995                                 ttwakeup(tp);
996                                 ttwwakeup(tp);
997                         }
998                         if ((ISSET(tp->t_state, TS_CARR_ON) ||
999                              ISSET(t->c_cflag, CLOCAL)) &&
1000                             !ISSET(tp->t_state, TS_ZOMBIE))
1001                                 SET(tp->t_state, TS_CONNECTED);
1002                         else
1003                                 CLR(tp->t_state, TS_CONNECTED);
1004                         tp->t_cflag = t->c_cflag;
1005                         tp->t_ispeed = t->c_ispeed;
1006                         if (t->c_ospeed != 0)
1007                                 tp->t_ospeed = t->c_ospeed;
1008                         ttsetwater(tp);
1009                 }
1010                 if (ISSET(t->c_lflag, ICANON) != ISSET(tp->t_lflag, ICANON) &&
1011                     cmd != TIOCSETAF) {
1012                         if (ISSET(t->c_lflag, ICANON))
1013                                 SET(tp->t_lflag, PENDIN);
1014                         else {
1015                                 /*
1016                                  * XXX we really shouldn't allow toggling
1017                                  * ICANON while we're in a non-termios line
1018                                  * discipline.  Now we have to worry about
1019                                  * panicing for a null queue.
1020                                  */
1021                                 if (tp->t_canq.c_cbreserved > 0 &&
1022                                     tp->t_rawq.c_cbreserved > 0) {
1023                                         catq(&tp->t_rawq, &tp->t_canq);
1024                                         /*
1025                                          * XXX the queue limits may be
1026                                          * different, so the old queue
1027                                          * swapping method no longer works.
1028                                          */
1029                                         catq(&tp->t_canq, &tp->t_rawq);
1030                                 }
1031                                 CLR(tp->t_lflag, PENDIN);
1032                         }
1033                         ttwakeup(tp);
1034                 }
1035                 tp->t_iflag = t->c_iflag;
1036                 tp->t_oflag = t->c_oflag;
1037                 /*
1038                  * Make the EXTPROC bit read only.
1039                  */
1040                 if (ISSET(tp->t_lflag, EXTPROC))
1041                         SET(t->c_lflag, EXTPROC);
1042                 else
1043                         CLR(t->c_lflag, EXTPROC);
1044                 tp->t_lflag = t->c_lflag | ISSET(tp->t_lflag, PENDIN);
1045                 if (t->c_cc[VMIN] != tp->t_cc[VMIN] ||
1046                     t->c_cc[VTIME] != tp->t_cc[VTIME])
1047                         ttwakeup(tp);
1048                 bcopy(t->c_cc, tp->t_cc, sizeof(t->c_cc));
1049                 crit_exit();
1050                 break;
1051         }
1052         case TIOCSETD: {                /* set line discipline */
1053                 int t = *(int *)data;
1054                 cdev_t device = tp->t_dev;
1055
1056                 if ((u_int)t >= nlinesw)
1057                         return (ENXIO);
1058                 if (t != tp->t_line) {
1059                         crit_enter();
1060                         (*linesw[tp->t_line].l_close)(tp, flag);
1061                         error = (*linesw[t].l_open)(device, tp);
1062                         if (error) {
1063                                 (void)(*linesw[tp->t_line].l_open)(device, tp);
1064                                 crit_exit();
1065                                 return (error);
1066                         }
1067                         tp->t_line = t;
1068                         crit_exit();
1069                 }
1070                 break;
1071         }
1072         case TIOCSTART:                 /* start output, like ^Q */
1073                 crit_enter();
1074                 if (ISSET(tp->t_state, TS_TTSTOP) ||
1075                     ISSET(tp->t_lflag, FLUSHO)) {
1076                         CLR(tp->t_lflag, FLUSHO);
1077                         CLR(tp->t_state, TS_TTSTOP);
1078                         ttstart(tp);
1079                 }
1080                 crit_exit();
1081                 break;
1082         case TIOCSTI:                   /* simulate terminal input */
1083                 if ((flag & FREAD) == 0 && priv_check(td, PRIV_ROOT))
1084                         return (EPERM);
1085                 if (!isctty(p, tp) && priv_check(td, PRIV_ROOT))
1086                         return (EACCES);
1087                 crit_enter();
1088                 (*linesw[tp->t_line].l_rint)(*(u_char *)data, tp);
1089                 crit_exit();
1090                 break;
1091         case TIOCSTOP:                  /* stop output, like ^S */
1092                 crit_enter();
1093                 if (!ISSET(tp->t_state, TS_TTSTOP)) {
1094                         SET(tp->t_state, TS_TTSTOP);
1095                         (*tp->t_stop)(tp, 0);
1096                 }
1097                 crit_exit();
1098                 break;
1099         case TIOCSCTTY:                 /* become controlling tty */
1100                 /* Session ctty vnode pointer set in vnode layer. */
1101                 if (!SESS_LEADER(p) ||
1102                     ((p->p_session->s_ttyvp || tp->t_session) &&
1103                     (tp->t_session != p->p_session)))
1104                         return (EPERM);
1105                 tp->t_session = p->p_session;
1106                 tp->t_pgrp = p->p_pgrp;
1107                 p->p_session->s_ttyp = tp;
1108                 p->p_flag |= P_CONTROLT;
1109                 break;
1110         case TIOCSPGRP: {               /* set pgrp of tty */
1111                 pid_t pgid = *(int *)data;
1112
1113                 if (!isctty(p, tp))
1114                         return (ENOTTY);
1115                 else if (pgid < 1 || pgid > PID_MAX)
1116                         return (EINVAL);
1117                 else {
1118                         struct pgrp *pgrp = pgfind(pgid);
1119                         if (pgrp == NULL || pgrp->pg_session != p->p_session)
1120                                 return (EPERM);
1121
1122                         tp->t_pgrp = pgrp;
1123                 }
1124                 break;
1125         }
1126         case TIOCSTAT:                  /* simulate control-T */
1127                 crit_enter();
1128                 ttyinfo(tp);
1129                 crit_exit();
1130                 break;
1131         case TIOCSWINSZ:                /* set window size */
1132                 if (bcmp((caddr_t)&tp->t_winsize, data,
1133                     sizeof (struct winsize))) {
1134                         tp->t_winsize = *(struct winsize *)data;
1135                         pgsignal(tp->t_pgrp, SIGWINCH, 1);
1136                 }
1137                 break;
1138         case TIOCSDRAINWAIT:
1139                 error = priv_check(td, PRIV_ROOT);
1140                 if (error)
1141                         return (error);
1142                 tp->t_timeout = *(int *)data * hz;
1143                 wakeup(TSA_OCOMPLETE(tp));
1144                 wakeup(TSA_OLOWAT(tp));
1145                 break;
1146         case TIOCGDRAINWAIT:
1147                 *(int *)data = tp->t_timeout / hz;
1148                 break;
1149         default:
1150 #if defined(COMPAT_43) || defined(COMPAT_SUNOS)
1151                 return (ttcompat(tp, cmd, data, flag));
1152 #else
1153                 return (ENOIOCTL);
1154 #endif
1155         }
1156         return (0);
1157 }
1158
1159 int
1160 ttypoll(struct dev_poll_args *ap)
1161 {
1162         cdev_t dev = ap->a_head.a_dev;
1163         int events = ap->a_events;
1164         int revents = 0;
1165         struct tty *tp;
1166
1167         tp = dev->si_tty;
1168         /* XXX used to return ENXIO, but that means true! */
1169         if (tp == NULL) {
1170                 ap->a_events = (events & (POLLIN | POLLOUT | POLLRDNORM |
1171                                 POLLWRNORM)) | POLLHUP;
1172                 return(0);
1173         }
1174
1175         crit_enter();
1176         if (events & (POLLIN | POLLRDNORM)) {
1177                 if (ttnread(tp) > 0 || ISSET(tp->t_state, TS_ZOMBIE))
1178                         revents |= events & (POLLIN | POLLRDNORM);
1179                 else
1180                         selrecord(curthread, &tp->t_rsel);
1181         }
1182         if (events & (POLLOUT | POLLWRNORM)) {
1183                 if ((tp->t_outq.c_cc <= tp->t_olowat &&
1184                      ISSET(tp->t_state, TS_CONNECTED))
1185                     || ISSET(tp->t_state, TS_ZOMBIE))
1186                         revents |= events & (POLLOUT | POLLWRNORM);
1187                 else
1188                         selrecord(curthread, &tp->t_wsel);
1189         }
1190         crit_exit();
1191         ap->a_events = revents;
1192         return (0);
1193 }
1194
1195 static struct filterops ttyread_filtops =
1196         { 1, NULL, filt_ttyrdetach, filt_ttyread };
1197 static struct filterops ttywrite_filtops =
1198         { 1, NULL, filt_ttywdetach, filt_ttywrite };
1199
1200 int
1201 ttykqfilter(struct dev_kqfilter_args *ap)
1202 {
1203         cdev_t dev = ap->a_head.a_dev;
1204         struct knote *kn = ap->a_kn;
1205         struct tty *tp = dev->si_tty;
1206         struct klist *klist;
1207
1208         ap->a_result = 0;
1209         switch (kn->kn_filter) {
1210         case EVFILT_READ:
1211                 klist = &tp->t_rsel.si_note;
1212                 kn->kn_fop = &ttyread_filtops;
1213                 break;
1214         case EVFILT_WRITE:
1215                 klist = &tp->t_wsel.si_note;
1216                 kn->kn_fop = &ttywrite_filtops;
1217                 break;
1218         default:
1219                 ap->a_result = 1;
1220                 return (0);
1221         }
1222
1223         kn->kn_hook = (caddr_t)dev;
1224
1225         crit_enter();
1226         SLIST_INSERT_HEAD(klist, kn, kn_selnext);
1227         crit_exit();
1228
1229         return (0);
1230 }
1231
1232 static void
1233 filt_ttyrdetach(struct knote *kn)
1234 {
1235         struct tty *tp = ((cdev_t)kn->kn_hook)->si_tty;
1236
1237         crit_enter();
1238         SLIST_REMOVE(&tp->t_rsel.si_note, kn, knote, kn_selnext);
1239         crit_exit();
1240 }
1241
1242 static int
1243 filt_ttyread(struct knote *kn, long hint)
1244 {
1245         struct tty *tp = ((cdev_t)kn->kn_hook)->si_tty;
1246
1247         kn->kn_data = ttnread(tp);
1248         if (ISSET(tp->t_state, TS_ZOMBIE)) {
1249                 kn->kn_flags |= EV_EOF;
1250                 return (1);
1251         }
1252         return (kn->kn_data > 0);
1253 }
1254
1255 static void
1256 filt_ttywdetach(struct knote *kn)
1257 {
1258         struct tty *tp = ((cdev_t)kn->kn_hook)->si_tty;
1259
1260         crit_enter();
1261         SLIST_REMOVE(&tp->t_wsel.si_note, kn, knote, kn_selnext);
1262         crit_exit();
1263 }
1264
1265 static int
1266 filt_ttywrite(struct knote *kn, long hint)
1267 {
1268         struct tty *tp = ((cdev_t)kn->kn_hook)->si_tty;
1269
1270         kn->kn_data = tp->t_outq.c_cc;
1271         if (ISSET(tp->t_state, TS_ZOMBIE))
1272                 return (1);
1273         return (kn->kn_data <= tp->t_olowat &&
1274             ISSET(tp->t_state, TS_CONNECTED));
1275 }
1276
1277 /*
1278  * Must be called while in a critical section.
1279  */
1280 static int
1281 ttnread(struct tty *tp)
1282 {
1283         int nread;
1284
1285         if (ISSET(tp->t_lflag, PENDIN))
1286                 ttypend(tp);
1287         nread = tp->t_canq.c_cc;
1288         if (!ISSET(tp->t_lflag, ICANON)) {
1289                 nread += tp->t_rawq.c_cc;
1290                 if (nread < tp->t_cc[VMIN] && tp->t_cc[VTIME] == 0)
1291                         nread = 0;
1292         }
1293         return (nread);
1294 }
1295
1296 /*
1297  * Wait for output to drain.
1298  */
1299 int
1300 ttywait(struct tty *tp)
1301 {
1302         int error;
1303
1304         error = 0;
1305         crit_enter();
1306         while ((tp->t_outq.c_cc || ISSET(tp->t_state, TS_BUSY)) &&
1307                ISSET(tp->t_state, TS_CONNECTED) && tp->t_oproc) {
1308                 (*tp->t_oproc)(tp);
1309                 if ((tp->t_outq.c_cc || ISSET(tp->t_state, TS_BUSY)) &&
1310                     ISSET(tp->t_state, TS_CONNECTED)) {
1311                         SET(tp->t_state, TS_SO_OCOMPLETE);
1312                         error = ttysleep(tp, TSA_OCOMPLETE(tp),
1313                                          PCATCH, "ttywai",
1314                                          tp->t_timeout);
1315                         if (error) {
1316                                 if (error == EWOULDBLOCK)
1317                                         error = EIO;
1318                                 break;
1319                         }
1320                 } else
1321                         break;
1322         }
1323         if (!error && (tp->t_outq.c_cc || ISSET(tp->t_state, TS_BUSY)))
1324                 error = EIO;
1325         crit_exit();
1326         return (error);
1327 }
1328
1329 /*
1330  * Flush if successfully wait.
1331  */
1332 static int
1333 ttywflush(struct tty *tp)
1334 {
1335         int error;
1336
1337         if ((error = ttywait(tp)) == 0)
1338                 ttyflush(tp, FREAD);
1339         return (error);
1340 }
1341
1342 /*
1343  * Flush tty read and/or write queues, notifying anyone waiting.
1344  */
1345 void
1346 ttyflush(struct tty *tp, int rw)
1347 {
1348         crit_enter();
1349 #if 0
1350 again:
1351 #endif
1352         if (rw & FWRITE) {
1353                 FLUSHQ(&tp->t_outq);
1354                 CLR(tp->t_state, TS_TTSTOP);
1355         }
1356         (*tp->t_stop)(tp, rw);
1357         if (rw & FREAD) {
1358                 FLUSHQ(&tp->t_canq);
1359                 FLUSHQ(&tp->t_rawq);
1360                 CLR(tp->t_lflag, PENDIN);
1361                 tp->t_rocount = 0;
1362                 tp->t_rocol = 0;
1363                 CLR(tp->t_state, TS_LOCAL);
1364                 ttwakeup(tp);
1365                 if (ISSET(tp->t_state, TS_TBLOCK)) {
1366                         if (rw & FWRITE)
1367                                 FLUSHQ(&tp->t_outq);
1368                         ttyunblock(tp);
1369
1370                         /*
1371                          * Don't let leave any state that might clobber the
1372                          * next line discipline (although we should do more
1373                          * to send the START char).  Not clearing the state
1374                          * may have caused the "putc to a clist with no
1375                          * reserved cblocks" panic/kprintf.
1376                          */
1377                         CLR(tp->t_state, TS_TBLOCK);
1378
1379 #if 0 /* forget it, sleeping isn't always safe and we don't know when it is */
1380                         if (ISSET(tp->t_iflag, IXOFF)) {
1381                                 /*
1382                                  * XXX wait a bit in the hope that the stop
1383                                  * character (if any) will go out.  Waiting
1384                                  * isn't good since it allows races.  This
1385                                  * will be fixed when the stop character is
1386                                  * put in a special queue.  Don't bother with
1387                                  * the checks in ttywait() since the timeout
1388                                  * will save us.
1389                                  */
1390                                 SET(tp->t_state, TS_SO_OCOMPLETE);
1391                                 ttysleep(tp, TSA_OCOMPLETE(tp), 0,
1392                                          "ttyfls", hz / 10);
1393                                 /*
1394                                  * Don't try sending the stop character again.
1395                                  */
1396                                 CLR(tp->t_state, TS_TBLOCK);
1397                                 goto again;
1398                         }
1399 #endif
1400                 }
1401         }
1402         if (rw & FWRITE) {
1403                 FLUSHQ(&tp->t_outq);
1404                 ttwwakeup(tp);
1405         }
1406         crit_exit();
1407 }
1408
1409 /*
1410  * Copy in the default termios characters.
1411  */
1412 void
1413 termioschars(struct termios *t)
1414 {
1415
1416         bcopy(ttydefchars, t->c_cc, sizeof t->c_cc);
1417 }
1418
1419 /*
1420  * Old interface.
1421  */
1422 void
1423 ttychars(struct tty *tp)
1424 {
1425
1426         termioschars(&tp->t_termios);
1427 }
1428
1429 /*
1430  * Handle input high water.  Send stop character for the IXOFF case.  Turn
1431  * on our input flow control bit and propagate the changes to the driver.
1432  * XXX the stop character should be put in a special high priority queue.
1433  */
1434 void
1435 ttyblock(struct tty *tp)
1436 {
1437
1438         SET(tp->t_state, TS_TBLOCK);
1439         if (ISSET(tp->t_iflag, IXOFF) && tp->t_cc[VSTOP] != _POSIX_VDISABLE &&
1440             clist_putc(tp->t_cc[VSTOP], &tp->t_outq) != 0)
1441                 CLR(tp->t_state, TS_TBLOCK);    /* try again later */
1442         ttstart(tp);
1443 }
1444
1445 /*
1446  * Handle input low water.  Send start character for the IXOFF case.  Turn
1447  * off our input flow control bit and propagate the changes to the driver.
1448  * XXX the start character should be put in a special high priority queue.
1449  */
1450 static void
1451 ttyunblock(struct tty *tp)
1452 {
1453
1454         CLR(tp->t_state, TS_TBLOCK);
1455         if (ISSET(tp->t_iflag, IXOFF) && tp->t_cc[VSTART] != _POSIX_VDISABLE &&
1456             clist_putc(tp->t_cc[VSTART], &tp->t_outq) != 0)
1457                 SET(tp->t_state, TS_TBLOCK);    /* try again later */
1458         ttstart(tp);
1459 }
1460
1461 #ifdef notyet
1462 /* Not used by any current (i386) drivers. */
1463 /*
1464  * Restart after an inter-char delay.
1465  */
1466 void
1467 ttrstrt(void *tp_arg)
1468 {
1469         struct tty *tp;
1470
1471         KASSERT(tp_arg != NULL, ("ttrstrt"));
1472
1473         tp = tp_arg;
1474         crit_enter();
1475         CLR(tp->t_state, TS_TIMEOUT);
1476         ttstart(tp);
1477         crit_exit();
1478 }
1479 #endif
1480
1481 int
1482 ttstart(struct tty *tp)
1483 {
1484
1485         if (tp->t_oproc != NULL)        /* XXX: Kludge for pty. */
1486                 (*tp->t_oproc)(tp);
1487         return (0);
1488 }
1489
1490 /*
1491  * "close" a line discipline
1492  */
1493 int
1494 ttylclose(struct tty *tp, int flag)
1495 {
1496
1497         if (flag & FNONBLOCK || ttywflush(tp))
1498                 ttyflush(tp, FREAD | FWRITE);
1499         return (0);
1500 }
1501
1502 /*
1503  * Handle modem control transition on a tty.
1504  * Flag indicates new state of carrier.
1505  * Returns 0 if the line should be turned off, otherwise 1.
1506  */
1507 int
1508 ttymodem(struct tty *tp, int flag)
1509 {
1510
1511         if (ISSET(tp->t_state, TS_CARR_ON) && ISSET(tp->t_cflag, MDMBUF)) {
1512                 /*
1513                  * MDMBUF: do flow control according to carrier flag
1514                  * XXX TS_CAR_OFLOW doesn't do anything yet.  TS_TTSTOP
1515                  * works if IXON and IXANY are clear.
1516                  */
1517                 if (flag) {
1518                         CLR(tp->t_state, TS_CAR_OFLOW);
1519                         CLR(tp->t_state, TS_TTSTOP);
1520                         ttstart(tp);
1521                 } else if (!ISSET(tp->t_state, TS_CAR_OFLOW)) {
1522                         SET(tp->t_state, TS_CAR_OFLOW);
1523                         SET(tp->t_state, TS_TTSTOP);
1524                         (*tp->t_stop)(tp, 0);
1525                 }
1526         } else if (flag == 0) {
1527                 /*
1528                  * Lost carrier.
1529                  */
1530                 CLR(tp->t_state, TS_CARR_ON);
1531                 if (ISSET(tp->t_state, TS_ISOPEN) &&
1532                     !ISSET(tp->t_cflag, CLOCAL)) {
1533                         SET(tp->t_state, TS_ZOMBIE);
1534                         CLR(tp->t_state, TS_CONNECTED);
1535                         if (tp->t_session && tp->t_session->s_leader)
1536                                 ksignal(tp->t_session->s_leader, SIGHUP);
1537                         ttyflush(tp, FREAD | FWRITE);
1538                         return (0);
1539                 }
1540         } else {
1541                 /*
1542                  * Carrier now on.
1543                  */
1544                 SET(tp->t_state, TS_CARR_ON);
1545                 if (!ISSET(tp->t_state, TS_ZOMBIE))
1546                         SET(tp->t_state, TS_CONNECTED);
1547                 wakeup(TSA_CARR_ON(tp));
1548                 ttwakeup(tp);
1549                 ttwwakeup(tp);
1550         }
1551         return (1);
1552 }
1553
1554 /*
1555  * Reinput pending characters after state switch
1556  * call from a critical section.
1557  */
1558 static void
1559 ttypend(struct tty *tp)
1560 {
1561         struct clist tq;
1562         int c;
1563
1564         CLR(tp->t_lflag, PENDIN);
1565         SET(tp->t_state, TS_TYPEN);
1566         /*
1567          * XXX this assumes too much about clist internals.  It may even
1568          * fail if the cblock slush pool is empty.  We can't allocate more
1569          * cblocks here because we are called from an interrupt handler
1570          * and clist_alloc_cblocks() can wait.
1571          */
1572         tq = tp->t_rawq;
1573         bzero(&tp->t_rawq, sizeof tp->t_rawq);
1574         tp->t_rawq.c_cbmax = tq.c_cbmax;
1575         tp->t_rawq.c_cbreserved = tq.c_cbreserved;
1576         while ((c = clist_getc(&tq)) >= 0)
1577                 ttyinput(c, tp);
1578         CLR(tp->t_state, TS_TYPEN);
1579 }
1580
1581 /*
1582  * Process a read call on a tty device.
1583  */
1584 int
1585 ttread(struct tty *tp, struct uio *uio, int flag)
1586 {
1587         struct clist *qp;
1588         int c;
1589         tcflag_t lflag;
1590         cc_t *cc = tp->t_cc;
1591         struct proc *pp;
1592         struct lwp *lp;
1593         int first, error = 0;
1594         int has_stime = 0, last_cc = 0;
1595         long slp = 0;           /* XXX this should be renamed `timo'. */
1596         struct timeval stime;
1597
1598         lp = curthread->td_lwp;
1599
1600 loop:
1601         crit_enter();
1602         lflag = tp->t_lflag;
1603         /*
1604          * take pending input first
1605          */
1606         if (ISSET(lflag, PENDIN)) {
1607                 ttypend(tp);
1608                 splz();         /* reduce latency */
1609                 lflag = tp->t_lflag;    /* XXX ttypend() clobbers it */
1610         }
1611
1612         /*
1613          * Hang process if it's in the background.
1614          */
1615         if ((pp = curproc) && isbackground(pp, tp)) {
1616                 crit_exit();
1617                 if (SIGISMEMBER(pp->p_sigignore, SIGTTIN) ||
1618                     SIGISMEMBER(lp->lwp_sigmask, SIGTTIN) ||
1619                     (pp->p_flag & P_PPWAIT) || pp->p_pgrp->pg_jobc == 0)
1620                         return (EIO);
1621                 pgsignal(pp->p_pgrp, SIGTTIN, 1);
1622                 error = ttysleep(tp, &lbolt, PCATCH, "ttybg2", 0);
1623                 if (error)
1624                         return (error);
1625                 goto loop;
1626         }
1627
1628         if (ISSET(tp->t_state, TS_ZOMBIE)) {
1629                 crit_exit();
1630                 return (0);     /* EOF */
1631         }
1632
1633         /*
1634          * If canonical, use the canonical queue,
1635          * else use the raw queue.
1636          *
1637          * (should get rid of clists...)
1638          */
1639         qp = ISSET(lflag, ICANON) ? &tp->t_canq : &tp->t_rawq;
1640
1641         if (flag & IO_NDELAY) {
1642                 if (qp->c_cc > 0)
1643                         goto read;
1644                 if (!ISSET(lflag, ICANON) && cc[VMIN] == 0) {
1645                         crit_exit();
1646                         return (0);
1647                 }
1648                 crit_exit();
1649                 return (EWOULDBLOCK);
1650         }
1651         if (!ISSET(lflag, ICANON)) {
1652                 int m = cc[VMIN];
1653                 long t = cc[VTIME];
1654                 struct timeval timecopy;
1655
1656                 /*
1657                  * Check each of the four combinations.
1658                  * (m > 0 && t == 0) is the normal read case.
1659                  * It should be fairly efficient, so we check that and its
1660                  * companion case (m == 0 && t == 0) first.
1661                  * For the other two cases, we compute the target sleep time
1662                  * into slp.
1663                  */
1664                 if (t == 0) {
1665                         if (qp->c_cc < m)
1666                                 goto sleep;
1667                         if (qp->c_cc > 0)
1668                                 goto read;
1669
1670                         /* m, t and qp->c_cc are all 0.  0 is enough input. */
1671                         crit_exit();
1672                         return (0);
1673                 }
1674                 t *= 100000;            /* time in us */
1675 #define diff(t1, t2) (((t1).tv_sec - (t2).tv_sec) * 1000000 + \
1676                          ((t1).tv_usec - (t2).tv_usec))
1677                 if (m > 0) {
1678                         if (qp->c_cc <= 0)
1679                                 goto sleep;
1680                         if (qp->c_cc >= m)
1681                                 goto read;
1682                         getmicrotime(&timecopy);
1683                         if (!has_stime) {
1684                                 /* first character, start timer */
1685                                 has_stime = 1;
1686                                 stime = timecopy;
1687                                 slp = t;
1688                         } else if (qp->c_cc > last_cc) {
1689                                 /* got a character, restart timer */
1690                                 stime = timecopy;
1691                                 slp = t;
1692                         } else {
1693                                 /* nothing, check expiration */
1694                                 slp = t - diff(timecopy, stime);
1695                                 if (slp <= 0)
1696                                         goto read;
1697                         }
1698                         last_cc = qp->c_cc;
1699                 } else {        /* m == 0 */
1700                         if (qp->c_cc > 0)
1701                                 goto read;
1702                         getmicrotime(&timecopy);
1703                         if (!has_stime) {
1704                                 has_stime = 1;
1705                                 stime = timecopy;
1706                                 slp = t;
1707                         } else {
1708                                 slp = t - diff(timecopy, stime);
1709                                 if (slp <= 0) {
1710                                         /* Timed out, but 0 is enough input. */
1711                                         crit_exit();
1712                                         return (0);
1713                                 }
1714                         }
1715                 }
1716 #undef diff
1717                 /*
1718                  * Rounding down may make us wake up just short
1719                  * of the target, so we round up.
1720                  * The formula is ceiling(slp * hz/1000000).
1721                  * 32-bit arithmetic is enough for hz < 169.
1722                  * XXX see tvtohz() for how to avoid overflow if hz
1723                  * is large (divide by `tick' and/or arrange to
1724                  * use tvtohz() if hz is large).
1725                  */
1726                 slp = (long) (((u_long)slp * hz) + 999999) / 1000000;
1727                 goto sleep;
1728         }
1729         if (qp->c_cc <= 0) {
1730 sleep:
1731                 /*
1732                  * There is no input, or not enough input and we can block.
1733                  */
1734                 error = ttysleep(tp, TSA_HUP_OR_INPUT(tp), PCATCH,
1735                                  ISSET(tp->t_state, TS_CONNECTED) ?
1736                                  "ttyin" : "ttyhup", (int)slp);
1737                 crit_exit();
1738                 if (error == EWOULDBLOCK)
1739                         error = 0;
1740                 else if (error)
1741                         return (error);
1742                 /*
1743                  * XXX what happens if another process eats some input
1744                  * while we are asleep (not just here)?  It would be
1745                  * safest to detect changes and reset our state variables
1746                  * (has_stime and last_cc).
1747                  */
1748                 slp = 0;
1749                 goto loop;
1750         }
1751 read:
1752         crit_exit();
1753         /*
1754          * Input present, check for input mapping and processing.
1755          */
1756         first = 1;
1757         if (ISSET(lflag, ICANON | ISIG))
1758                 goto slowcase;
1759         for (;;) {
1760                 char ibuf[IBUFSIZ];
1761                 int icc;
1762
1763                 icc = imin(uio->uio_resid, IBUFSIZ);
1764                 icc = q_to_b(qp, ibuf, icc);
1765                 if (icc <= 0) {
1766                         if (first)
1767                                 goto loop;
1768                         break;
1769                 }
1770                 error = uiomove(ibuf, icc, uio);
1771                 /*
1772                  * XXX if there was an error then we should ungetc() the
1773                  * unmoved chars and reduce icc here.
1774                  */
1775                 if (error)
1776                         break;
1777                 if (uio->uio_resid == 0)
1778                         break;
1779                 first = 0;
1780         }
1781         goto out;
1782 slowcase:
1783         for (;;) {
1784                 c = clist_getc(qp);
1785                 if (c < 0) {
1786                         if (first)
1787                                 goto loop;
1788                         break;
1789                 }
1790                 /*
1791                  * delayed suspend (^Y)
1792                  */
1793                 if (CCEQ(cc[VDSUSP], c) &&
1794                     ISSET(lflag, IEXTEN | ISIG) == (IEXTEN | ISIG)) {
1795                         pgsignal(tp->t_pgrp, SIGTSTP, 1);
1796                         if (first) {
1797                                 error = ttysleep(tp, &lbolt, PCATCH,
1798                                                  "ttybg3", 0);
1799                                 if (error)
1800                                         break;
1801                                 goto loop;
1802                         }
1803                         break;
1804                 }
1805                 /*
1806                  * Interpret EOF only in canonical mode.
1807                  */
1808                 if (CCEQ(cc[VEOF], c) && ISSET(lflag, ICANON))
1809                         break;
1810                 /*
1811                  * Give user character.
1812                  */
1813                 error = ureadc(c, uio);
1814                 if (error)
1815                         /* XXX should ungetc(c, qp). */
1816                         break;
1817                 if (uio->uio_resid == 0)
1818                         break;
1819                 /*
1820                  * In canonical mode check for a "break character"
1821                  * marking the end of a "line of input".
1822                  */
1823                 if (ISSET(lflag, ICANON) && TTBREAKC(c, lflag))
1824                         break;
1825                 first = 0;
1826         }
1827
1828 out:
1829         /*
1830          * Look to unblock input now that (presumably)
1831          * the input queue has gone down.
1832          */
1833         crit_enter();
1834         if (ISSET(tp->t_state, TS_TBLOCK) &&
1835             tp->t_rawq.c_cc + tp->t_canq.c_cc <= tp->t_ilowat)
1836                 ttyunblock(tp);
1837         crit_exit();
1838
1839         return (error);
1840 }
1841
1842 /*
1843  * Check the output queue on tp for space for a kernel message (from uprintf
1844  * or tprintf).  Allow some space over the normal hiwater mark so we don't
1845  * lose messages due to normal flow control, but don't let the tty run amok.
1846  * Sleeps here are not interruptible, but we return prematurely if new signals
1847  * arrive.
1848  */
1849 int
1850 ttycheckoutq(struct tty *tp, int wait)
1851 {
1852         struct lwp *lp = curthread->td_lwp;
1853         int hiwat;
1854         sigset_t oldset, newset;
1855
1856         hiwat = tp->t_ohiwat;
1857         SIGEMPTYSET(oldset);
1858         SIGEMPTYSET(newset);
1859         crit_enter();
1860         if (wait)
1861                 oldset = lwp_sigpend(lp);
1862         if (tp->t_outq.c_cc > hiwat + OBUFSIZ + 100) {
1863                 while (tp->t_outq.c_cc > hiwat) {
1864                         ttstart(tp);
1865                         if (tp->t_outq.c_cc <= hiwat)
1866                                 break;
1867                         if (wait)
1868                                 newset = lwp_sigpend(lp);
1869                         if (!wait || SIGSETNEQ(oldset, newset)) {
1870                                 crit_exit();
1871                                 return (0);
1872                         }
1873                         SET(tp->t_state, TS_SO_OLOWAT);
1874                         tsleep(TSA_OLOWAT(tp), 0, "ttoutq", hz);
1875                 }
1876         }
1877         crit_exit();
1878         return (1);
1879 }
1880
1881 /*
1882  * Process a write call on a tty device.
1883  */
1884 int
1885 ttwrite(struct tty *tp, struct uio *uio, int flag)
1886 {
1887         char *cp = NULL;
1888         int cc, ce;
1889         struct proc *pp;
1890         struct lwp *lp;
1891         int i, hiwat, cnt, error;
1892         char obuf[OBUFSIZ];
1893
1894         lp = curthread->td_lwp;
1895         hiwat = tp->t_ohiwat;
1896         cnt = uio->uio_resid;
1897         error = 0;
1898         cc = 0;
1899 loop:
1900         crit_enter();
1901         if (ISSET(tp->t_state, TS_ZOMBIE)) {
1902                 crit_exit();
1903                 if (uio->uio_resid == cnt)
1904                         error = EIO;
1905                 goto out;
1906         }
1907         if (!ISSET(tp->t_state, TS_CONNECTED)) {
1908                 if (flag & IO_NDELAY) {
1909                         crit_exit();
1910                         error = EWOULDBLOCK;
1911                         goto out;
1912                 }
1913                 error = ttysleep(tp, TSA_CARR_ON(tp), PCATCH, "ttydcd", 0);
1914                 crit_exit();
1915                 if (error)
1916                         goto out;
1917                 goto loop;
1918         }
1919         crit_exit();
1920
1921         /*
1922          * Hang the process if it's in the background.
1923          */
1924         if ((pp = curproc) && isbackground(pp, tp) &&
1925             ISSET(tp->t_lflag, TOSTOP) && !(pp->p_flag & P_PPWAIT) &&
1926             !SIGISMEMBER(pp->p_sigignore, SIGTTOU) &&
1927             !SIGISMEMBER(lp->lwp_sigmask, SIGTTOU)) {
1928                 if (pp->p_pgrp->pg_jobc == 0) {
1929                         error = EIO;
1930                         goto out;
1931                 }
1932                 pgsignal(pp->p_pgrp, SIGTTOU, 1);
1933                 error = ttysleep(tp, &lbolt, PCATCH, "ttybg4", 0);
1934                 if (error)
1935                         goto out;
1936                 goto loop;
1937         }
1938         /*
1939          * Process the user's data in at most OBUFSIZ chunks.  Perform any
1940          * output translation.  Keep track of high water mark, sleep on
1941          * overflow awaiting device aid in acquiring new space.
1942          */
1943         while (uio->uio_resid > 0 || cc > 0) {
1944                 if (ISSET(tp->t_lflag, FLUSHO)) {
1945                         uio->uio_resid = 0;
1946                         return (0);
1947                 }
1948                 if (tp->t_outq.c_cc > hiwat)
1949                         goto ovhiwat;
1950                 /*
1951                  * Grab a hunk of data from the user, unless we have some
1952                  * leftover from last time.
1953                  */
1954                 if (cc == 0) {
1955                         cc = imin(uio->uio_resid, OBUFSIZ);
1956                         cp = obuf;
1957                         error = uiomove(cp, cc, uio);
1958                         if (error) {
1959                                 cc = 0;
1960                                 break;
1961                         }
1962                 }
1963                 /*
1964                  * If nothing fancy need be done, grab those characters we
1965                  * can handle without any of ttyoutput's processing and
1966                  * just transfer them to the output q.  For those chars
1967                  * which require special processing (as indicated by the
1968                  * bits in char_type), call ttyoutput.  After processing
1969                  * a hunk of data, look for FLUSHO so ^O's will take effect
1970                  * immediately.
1971                  */
1972                 while (cc > 0) {
1973                         if (!ISSET(tp->t_oflag, OPOST))
1974                                 ce = cc;
1975                         else {
1976                                 ce = cc - scanc((u_int)cc, (u_char *)cp,
1977                                                 char_type, CCLASSMASK);
1978                                 /*
1979                                  * If ce is zero, then we're processing
1980                                  * a special character through ttyoutput.
1981                                  */
1982                                 if (ce == 0) {
1983                                         tp->t_rocount = 0;
1984                                         if (ttyoutput(*cp, tp) >= 0) {
1985                                                 /* No Clists, wait a bit. */
1986                                                 ttstart(tp);
1987                                                 if (flag & IO_NDELAY) {
1988                                                         error = EWOULDBLOCK;
1989                                                         goto out;
1990                                                 }
1991                                                 error = ttysleep(tp, &lbolt,
1992                                                                  PCATCH,
1993                                                                  "ttybf1", 0);
1994                                                 if (error)
1995                                                         goto out;
1996                                                 goto loop;
1997                                         }
1998                                         cp++;
1999                                         cc--;
2000                                         if (ISSET(tp->t_lflag, FLUSHO) ||
2001                                             tp->t_outq.c_cc > hiwat)
2002                                                 goto ovhiwat;
2003                                         continue;
2004                                 }
2005                         }
2006                         /*
2007                          * A bunch of normal characters have been found.
2008                          * Transfer them en masse to the output queue and
2009                          * continue processing at the top of the loop.
2010                          * If there are any further characters in this
2011                          * <= OBUFSIZ chunk, the first should be a character
2012                          * requiring special handling by ttyoutput.
2013                          */
2014                         tp->t_rocount = 0;
2015                         i = b_to_q(cp, ce, &tp->t_outq);
2016                         ce -= i;
2017                         tp->t_column += ce;
2018                         cp += ce, cc -= ce, tk_nout += ce;
2019                         tp->t_outcc += ce;
2020                         if (i > 0) {
2021                                 /* No Clists, wait a bit. */
2022                                 ttstart(tp);
2023                                 if (flag & IO_NDELAY) {
2024                                         error = EWOULDBLOCK;
2025                                         goto out;
2026                                 }
2027                                 error = ttysleep(tp, &lbolt, PCATCH,
2028                                                  "ttybf2", 0);
2029                                 if (error)
2030                                         goto out;
2031                                 goto loop;
2032                         }
2033                         if (ISSET(tp->t_lflag, FLUSHO) ||
2034                             tp->t_outq.c_cc > hiwat)
2035                                 break;
2036                 }
2037                 ttstart(tp);
2038         }
2039 out:
2040         /*
2041          * If cc is nonzero, we leave the uio structure inconsistent, as the
2042          * offset and iov pointers have moved forward, but it doesn't matter
2043          * (the call will either return short or restart with a new uio).
2044          */
2045         uio->uio_resid += cc;
2046         return (error);
2047
2048 ovhiwat:
2049         ttstart(tp);
2050         crit_enter();
2051         /*
2052          * This can only occur if FLUSHO is set in t_lflag,
2053          * or if ttstart/oproc is synchronous (or very fast).
2054          */
2055         if (tp->t_outq.c_cc <= hiwat) {
2056                 crit_exit();
2057                 goto loop;
2058         }
2059         if (flag & IO_NDELAY) {
2060                 crit_exit();
2061                 uio->uio_resid += cc;
2062                 return (uio->uio_resid == cnt ? EWOULDBLOCK : 0);
2063         }
2064         SET(tp->t_state, TS_SO_OLOWAT);
2065         error = ttysleep(tp, TSA_OLOWAT(tp), PCATCH, "ttywri", tp->t_timeout);
2066         crit_exit();
2067         if (error == EWOULDBLOCK)
2068                 error = EIO;
2069         if (error)
2070                 goto out;
2071         goto loop;
2072 }
2073
2074 /*
2075  * Rubout one character from the rawq of tp
2076  * as cleanly as possible.
2077  */
2078 static void
2079 ttyrub(int c, struct tty *tp)
2080 {
2081         char *cp;
2082         int savecol;
2083         int tabc;
2084
2085         if (!ISSET(tp->t_lflag, ECHO) || ISSET(tp->t_lflag, EXTPROC))
2086                 return;
2087         CLR(tp->t_lflag, FLUSHO);
2088         if (ISSET(tp->t_lflag, ECHOE)) {
2089                 if (tp->t_rocount == 0) {
2090                         /*
2091                          * Screwed by ttwrite; retype
2092                          */
2093                         ttyretype(tp);
2094                         return;
2095                 }
2096                 if (c == ('\t' | TTY_QUOTE) || c == ('\n' | TTY_QUOTE))
2097                         ttyrubo(tp, 2);
2098                 else {
2099                         CLR(c, ~TTY_CHARMASK);
2100                         switch (CCLASS(c)) {
2101                         case ORDINARY:
2102                                 ttyrubo(tp, 1);
2103                                 break;
2104                         case BACKSPACE:
2105                         case CONTROL:
2106                         case NEWLINE:
2107                         case RETURN:
2108                         case VTAB:
2109                                 if (ISSET(tp->t_lflag, ECHOCTL))
2110                                         ttyrubo(tp, 2);
2111                                 break;
2112                         case TAB:
2113                                 if (tp->t_rocount < tp->t_rawq.c_cc) {
2114                                         ttyretype(tp);
2115                                         return;
2116                                 }
2117                                 crit_enter();
2118                                 savecol = tp->t_column;
2119                                 SET(tp->t_state, TS_CNTTB);
2120                                 SET(tp->t_lflag, FLUSHO);
2121                                 tp->t_column = tp->t_rocol;
2122                                 cp = tp->t_rawq.c_cf;
2123                                 if (cp)
2124                                         tabc = *cp;     /* XXX FIX NEXTC */
2125                                 for (; cp; cp = nextc(&tp->t_rawq, cp, &tabc))
2126                                         ttyecho(tabc, tp);
2127                                 CLR(tp->t_lflag, FLUSHO);
2128                                 CLR(tp->t_state, TS_CNTTB);
2129                                 crit_exit();
2130
2131                                 /* savecol will now be length of the tab. */
2132                                 savecol -= tp->t_column;
2133                                 tp->t_column += savecol;
2134                                 if (savecol > 8)
2135                                         savecol = 8;    /* overflow screw */
2136                                 while (--savecol >= 0)
2137                                         (void)ttyoutput('\b', tp);
2138                                 break;
2139                         default:                        /* XXX */
2140 #define PANICSTR        "ttyrub: would panic c = %d, val = %d\n"
2141                                 (void)kprintf(PANICSTR, c, CCLASS(c));
2142 #ifdef notdef
2143                                 panic(PANICSTR, c, CCLASS(c));
2144 #endif
2145                         }
2146                 }
2147         } else if (ISSET(tp->t_lflag, ECHOPRT)) {
2148                 if (!ISSET(tp->t_state, TS_ERASE)) {
2149                         SET(tp->t_state, TS_ERASE);
2150                         (void)ttyoutput('\\', tp);
2151                 }
2152                 ttyecho(c, tp);
2153         } else {
2154                 ttyecho(tp->t_cc[VERASE], tp);
2155                 /*
2156                  * This code may be executed not only when an ERASE key
2157                  * is pressed, but also when ^U (KILL) or ^W (WERASE) are.
2158                  * So, I didn't think it was worthwhile to pass the extra
2159                  * information (which would need an extra parameter,
2160                  * changing every call) needed to distinguish the ERASE2
2161                  * case from the ERASE.
2162                  */
2163         }
2164         --tp->t_rocount;
2165 }
2166
2167 /*
2168  * Back over cnt characters, erasing them.
2169  */
2170 static void
2171 ttyrubo(struct tty *tp, int cnt)
2172 {
2173
2174         while (cnt-- > 0) {
2175                 (void)ttyoutput('\b', tp);
2176                 (void)ttyoutput(' ', tp);
2177                 (void)ttyoutput('\b', tp);
2178         }
2179 }
2180
2181 /*
2182  * ttyretype --
2183  *      Reprint the rawq line.  Note, it is assumed that c_cc has already
2184  *      been checked.
2185  */
2186 static void
2187 ttyretype(struct tty *tp)
2188 {
2189         char *cp;
2190         int c;
2191
2192         /* Echo the reprint character. */
2193         if (tp->t_cc[VREPRINT] != _POSIX_VDISABLE)
2194                 ttyecho(tp->t_cc[VREPRINT], tp);
2195
2196         (void)ttyoutput('\n', tp);
2197
2198         /*
2199          * XXX
2200          * FIX: NEXTC IS BROKEN - DOESN'T CHECK QUOTE
2201          * BIT OF FIRST CHAR.
2202          */
2203         crit_enter();
2204         for (cp = tp->t_canq.c_cf, c = (cp != NULL ? *cp : 0);
2205             cp != NULL; cp = nextc(&tp->t_canq, cp, &c))
2206                 ttyecho(c, tp);
2207         for (cp = tp->t_rawq.c_cf, c = (cp != NULL ? *cp : 0);
2208             cp != NULL; cp = nextc(&tp->t_rawq, cp, &c))
2209                 ttyecho(c, tp);
2210         CLR(tp->t_state, TS_ERASE);
2211         crit_exit();
2212
2213         tp->t_rocount = tp->t_rawq.c_cc;
2214         tp->t_rocol = 0;
2215 }
2216
2217 /*
2218  * Echo a typed character to the terminal.
2219  */
2220 static void
2221 ttyecho(int c, struct tty *tp)
2222 {
2223
2224         if (!ISSET(tp->t_state, TS_CNTTB))
2225                 CLR(tp->t_lflag, FLUSHO);
2226         if ((!ISSET(tp->t_lflag, ECHO) &&
2227              (c != '\n' || !ISSET(tp->t_lflag, ECHONL))) ||
2228             ISSET(tp->t_lflag, EXTPROC))
2229                 return;
2230         if (ISSET(tp->t_lflag, ECHOCTL) &&
2231             ((ISSET(c, TTY_CHARMASK) <= 037 && c != '\t' && c != '\n') ||
2232             ISSET(c, TTY_CHARMASK) == 0177)) {
2233                 (void)ttyoutput('^', tp);
2234                 CLR(c, ~TTY_CHARMASK);
2235                 if (c == 0177)
2236                         c = '?';
2237                 else
2238                         c += 'A' - 1;
2239         }
2240         (void)ttyoutput(c, tp);
2241 }
2242
2243 /*
2244  * Wake up any readers on a tty.
2245  */
2246 void
2247 ttwakeup(struct tty *tp)
2248 {
2249
2250         if (tp->t_rsel.si_pid != 0)
2251                 selwakeup(&tp->t_rsel);
2252         if (ISSET(tp->t_state, TS_ASYNC) && tp->t_sigio != NULL)
2253                 pgsigio(tp->t_sigio, SIGIO, (tp->t_session != NULL));
2254         wakeup(TSA_HUP_OR_INPUT(tp));
2255         KNOTE(&tp->t_rsel.si_note, 0);
2256 }
2257
2258 /*
2259  * Wake up any writers on a tty.
2260  */
2261 void
2262 ttwwakeup(struct tty *tp)
2263 {
2264
2265         if (tp->t_wsel.si_pid != 0 && tp->t_outq.c_cc <= tp->t_olowat)
2266                 selwakeup(&tp->t_wsel);
2267         if (ISSET(tp->t_state, TS_ASYNC) && tp->t_sigio != NULL)
2268                 pgsigio(tp->t_sigio, SIGIO, (tp->t_session != NULL));
2269         if (ISSET(tp->t_state, TS_BUSY | TS_SO_OCOMPLETE) ==
2270             TS_SO_OCOMPLETE && tp->t_outq.c_cc == 0) {
2271                 CLR(tp->t_state, TS_SO_OCOMPLETE);
2272                 wakeup(TSA_OCOMPLETE(tp));
2273         }
2274         if (ISSET(tp->t_state, TS_SO_OLOWAT) &&
2275             tp->t_outq.c_cc <= tp->t_olowat) {
2276                 CLR(tp->t_state, TS_SO_OLOWAT);
2277                 wakeup(TSA_OLOWAT(tp));
2278         }
2279         KNOTE(&tp->t_wsel.si_note, 0);
2280 }
2281
2282 /*
2283  * Look up a code for a specified speed in a conversion table;
2284  * used by drivers to map software speed values to hardware parameters.
2285  */
2286 int
2287 ttspeedtab(int speed, struct speedtab *table)
2288 {
2289
2290         for ( ; table->sp_speed != -1; table++)
2291                 if (table->sp_speed == speed)
2292                         return (table->sp_code);
2293         return (-1);
2294 }
2295
2296 /*
2297  * Set input and output watermarks and buffer sizes.  For input, the
2298  * high watermark is about one second's worth of input above empty, the
2299  * low watermark is slightly below high water, and the buffer size is a
2300  * driver-dependent amount above high water.  For output, the watermarks
2301  * are near the ends of the buffer, with about 1 second's worth of input
2302  * between them.  All this only applies to the standard line discipline.
2303  */
2304 void
2305 ttsetwater(struct tty *tp)
2306 {
2307         int cps, ttmaxhiwat, x;
2308
2309         /* Input. */
2310         clist_alloc_cblocks(&tp->t_canq, TTYHOG, 512);
2311         switch (tp->t_ispeedwat) {
2312         case (speed_t)-1:
2313                 cps = tp->t_ispeed / 10;
2314                 break;
2315         case 0:
2316                 /*
2317                  * This case is for old drivers that don't know about
2318                  * t_ispeedwat.  Arrange for them to get the old buffer
2319                  * sizes and watermarks.
2320                  */
2321                 cps = TTYHOG - 2 * 256;
2322                 tp->t_ififosize = 2 * 2048;
2323                 break;
2324         default:
2325                 cps = tp->t_ispeedwat / 10;
2326                 break;
2327         }
2328         tp->t_ihiwat = cps;
2329         tp->t_ilowat = 7 * cps / 8;
2330         x = cps + tp->t_ififosize;
2331         clist_alloc_cblocks(&tp->t_rawq, x, x);
2332
2333         /* Output. */
2334         switch (tp->t_ospeedwat) {
2335         case (speed_t)-1:
2336                 cps = tp->t_ospeed / 10;
2337                 ttmaxhiwat = 2 * TTMAXHIWAT;
2338                 break;
2339         case 0:
2340                 cps = tp->t_ospeed / 10;
2341                 ttmaxhiwat = TTMAXHIWAT;
2342                 break;
2343         default:
2344                 cps = tp->t_ospeedwat / 10;
2345                 ttmaxhiwat = 8 * TTMAXHIWAT;
2346                 break;
2347         }
2348 #define CLAMP(x, h, l)  ((x) > h ? h : ((x) < l) ? l : (x))
2349         tp->t_olowat = x = CLAMP(cps / 2, TTMAXLOWAT, TTMINLOWAT);
2350         x += cps;
2351         x = CLAMP(x, ttmaxhiwat, TTMINHIWAT);   /* XXX clamps are too magic */
2352         tp->t_ohiwat = roundup(x, CBSIZE);      /* XXX for compat */
2353         x = imax(tp->t_ohiwat, TTMAXHIWAT);     /* XXX for compat/safety */
2354         x += OBUFSIZ + 100;
2355         clist_alloc_cblocks(&tp->t_outq, x, x);
2356 #undef  CLAMP
2357 }
2358
2359 /*
2360  * Report on state of foreground process group.
2361  */
2362 void
2363 ttyinfo(struct tty *tp)
2364 {
2365         struct proc *p, *pick;
2366         struct lwp *lp;
2367         struct rusage ru;
2368         int tmp;
2369
2370         if (ttycheckoutq(tp,0) == 0)
2371                 return;
2372
2373         /*
2374          * We always print the load average, then figure out what else to
2375          * print based on the state of the current process group.
2376          */
2377         tmp = (averunnable.ldavg[0] * 100 + FSCALE / 2) >> FSHIFT;
2378         ttyprintf(tp, "load: %d.%02d ", tmp / 100, tmp % 100);
2379
2380         if (tp->t_session == NULL) {
2381                 ttyprintf(tp, "not a controlling terminal\n");
2382         } else if (tp->t_pgrp == NULL) {
2383                 ttyprintf(tp, "no foreground process group\n");
2384         } else if ((p = LIST_FIRST(&tp->t_pgrp->pg_members)) == 0) {
2385                 ttyprintf(tp, "empty foreground process group\n");
2386         } else {
2387                 /*
2388                  * Pick an interesting process.  Note that certain elements,
2389                  * in particular the wmesg, require a critical section for
2390                  * safe access (YYY and we are still not MP safe).
2391                  *
2392                  * NOTE: lwp_wmesg is lwp_thread->td_wmesg.
2393                  */
2394                 char buf[64];
2395                 const char *str;
2396                 long vmsz;
2397                 int pctcpu;
2398
2399                 crit_enter();
2400
2401                 /* XXX lwp should compare lwps */
2402
2403                 for (pick = NULL; p != 0; p = LIST_NEXT(p, p_pglist)) {
2404                         if (proc_compare(pick, p))
2405                                 pick = p;
2406                 }
2407
2408                 /* XXX lwp */
2409                 lp = FIRST_LWP_IN_PROC(pick);
2410                 if (lp == NULL) {
2411                         ttyprintf(tp, "foreground process without lwp\n");
2412                         tp->t_rocount = 0;
2413                         crit_exit();
2414                         return;
2415                 }
2416
2417                 /*
2418                  * Figure out what wait/process-state message, and command
2419                  * buffer to present
2420                  */
2421                 /*
2422                  * XXX lwp This is a horrible mixture.  We need to rework this
2423                  * as soon as lwps have their own runnable status.
2424                  */
2425                 if (pick->p_flag & P_WEXIT)
2426                         str = "exiting";
2427                 else if (lp->lwp_stat == LSRUN)
2428                         str = "running";
2429                 else if (pick->p_stat == SIDL)
2430                         str = "spawning";
2431                 else if (lp->lwp_wmesg) /* lwp_thread must not be NULL */
2432                         str = lp->lwp_wmesg;
2433                 else
2434                         str = "iowait";
2435
2436                 ksnprintf(buf, sizeof(buf), "cmd: %s %d [%s]",
2437                         pick->p_comm, pick->p_pid, str);
2438
2439                 /*
2440                  * Calculate cpu usage, percent cpu, and cmsz.  Note that
2441                  * 'pick' becomes invalid the moment we exit the critical
2442                  * section.
2443                  */
2444                 if (lp->lwp_thread && (pick->p_flag & P_SWAPPEDOUT) == 0)
2445                         calcru_proc(pick, &ru);
2446
2447                 pctcpu = (lp->lwp_pctcpu * 10000 + FSCALE / 2) >> FSHIFT;
2448
2449                 if (pick->p_stat == SIDL || pick->p_stat == SZOMB)
2450                     vmsz = 0;
2451                 else
2452                     vmsz = pgtok(vmspace_resident_count(pick->p_vmspace));
2453
2454                 crit_exit();
2455
2456                 /*
2457                  * Dump the output
2458                  */
2459                 ttyprintf(tp, " %s ", buf);
2460                 ttyprintf(tp, "%ld.%02ldu ",
2461                         ru.ru_utime.tv_sec, ru.ru_utime.tv_usec / 10000);
2462                 ttyprintf(tp, "%ld.%02lds ",
2463                         ru.ru_stime.tv_sec, ru.ru_stime.tv_usec / 10000);
2464                 ttyprintf(tp, "%d%% %ldk\n", pctcpu / 100, vmsz);
2465         }
2466         tp->t_rocount = 0;      /* so pending input will be retyped if BS */
2467 }
2468
2469 /*
2470  * Returns 1 if p2 is "better" than p1
2471  *
2472  * The algorithm for picking the "interesting" process is thus:
2473  *
2474  *      1) Only foreground processes are eligible - implied.
2475  *      2) Runnable processes are favored over anything else.  The runner
2476  *         with the highest cpu utilization is picked (p_cpticks).  Ties are
2477  *         broken by picking the highest pid.
2478  *      3) The sleeper with the shortest sleep time is next.  With ties,
2479  *         we pick out just "short-term" sleepers (LWP_SINTR == 0).
2480  *      4) Further ties are broken by picking the highest pid.
2481  */
2482 #define ISRUN(lp)       ((lp)->lwp_stat == LSRUN)
2483 #define TESTAB(a, b)    ((a)<<1 | (b))
2484 #define ONLYA   2
2485 #define ONLYB   1
2486 #define BOTH    3
2487
2488 static int
2489 proc_compare(struct proc *p1, struct proc *p2)
2490 {
2491         struct lwp *lp1, *lp2;
2492         if (p1 == NULL)
2493                 return (1);
2494
2495         /*
2496          * weed out zombies
2497          */
2498         switch (TESTAB(p1->p_stat == SZOMB, p2->p_stat == SZOMB)) {
2499         case ONLYA:
2500                 return (1);
2501         case ONLYB:
2502                 return (0);
2503         case BOTH:
2504                 return (p2->p_pid > p1->p_pid); /* tie - return highest pid */
2505         }
2506
2507         /* XXX lwp */
2508         lp1 = FIRST_LWP_IN_PROC(p1);
2509         lp2 = FIRST_LWP_IN_PROC(p2);
2510
2511         /*
2512          * see if at least one of them is runnable
2513          */
2514         switch (TESTAB(ISRUN(lp1), ISRUN(lp2))) {
2515         case ONLYA:
2516                 return (0);
2517         case ONLYB:
2518                 return (1);
2519         case BOTH:
2520                 /*
2521                  * tie - favor one with highest recent cpu utilization
2522                  */
2523                 if (lp2->lwp_cpticks > lp1->lwp_cpticks)
2524                         return (1);
2525                 if (lp1->lwp_cpticks > lp2->lwp_cpticks)
2526                         return (0);
2527                 return (p2->p_pid > p1->p_pid); /* tie - return highest pid */
2528         }
2529         /*
2530          * pick the one with the smallest sleep time
2531          */
2532         if (lp2->lwp_slptime > lp1->lwp_slptime)
2533                 return (0);
2534         if (lp1->lwp_slptime > lp2->lwp_slptime)
2535                 return (1);
2536         /*
2537          * favor one sleeping in a non-interruptible sleep
2538          */
2539         if (lp1->lwp_flag & LWP_SINTR && (lp2->lwp_flag & LWP_SINTR) == 0)
2540                 return (1);
2541         if (lp2->lwp_flag & LWP_SINTR && (lp1->lwp_flag & LWP_SINTR) == 0)
2542                 return (0);
2543         return (p2->p_pid > p1->p_pid);         /* tie - return highest pid */
2544 }
2545
2546 /*
2547  * Output char to tty; console putchar style.
2548  */
2549 int
2550 tputchar(int c, struct tty *tp)
2551 {
2552         crit_enter();
2553         if (!ISSET(tp->t_state, TS_CONNECTED)) {
2554                 crit_exit();
2555                 return (-1);
2556         }
2557         if (c == '\n')
2558                 (void)ttyoutput('\r', tp);
2559         (void)ttyoutput(c, tp);
2560         ttstart(tp);
2561         crit_exit();
2562         return (0);
2563 }
2564
2565 /*
2566  * Sleep on chan, returning ERESTART if tty changed while we napped and
2567  * returning any errors (e.g. EINTR/EWOULDBLOCK) reported by tsleep.  If
2568  * the tty is revoked, restarting a pending call will redo validation done
2569  * at the start of the call.
2570  */
2571 int
2572 ttysleep(struct tty *tp, void *chan, int slpflags, char *wmesg, int timo)
2573 {
2574         int error;
2575         int gen;
2576
2577         gen = tp->t_gen;
2578         error = tsleep(chan, slpflags, wmesg, timo);
2579         if (error)
2580                 return (error);
2581         return (tp->t_gen == gen ? 0 : ERESTART);
2582 }
2583
2584 /*
2585  * Revoke a tty.
2586  *
2587  * We bump the gen to force any ttysleep()'s to return with ERESTART
2588  * and flush the tty.  The related fp's should already have been
2589  * replaced so the tty will close when the last references on the
2590  * original fp's go away.
2591  */
2592 int
2593 ttyrevoke(struct dev_revoke_args *ap)
2594 {
2595         struct tty *tp;
2596
2597         tp = ap->a_head.a_dev->si_tty;
2598         tp->t_gen++;
2599         ttyflush(tp, FREAD | FWRITE);
2600         wakeup(TSA_CARR_ON(tp));
2601         ttwakeup(tp);
2602         ttwwakeup(tp);
2603         return (0);
2604 }
2605
2606 /*
2607  * Allocate a tty struct.  Clists in the struct will be allocated by
2608  * ttyopen().
2609  */
2610 struct tty *
2611 ttymalloc(struct tty *tp)
2612 {
2613
2614         if (tp)
2615                 return(tp);
2616         tp = kmalloc(sizeof *tp, M_TTYS, M_WAITOK|M_ZERO);
2617         ttyregister(tp);
2618         return (tp);
2619 }
2620
2621 #if 0
2622 /*
2623  * Free a tty struct.  Clists in the struct should have been freed by
2624  * ttyclose().
2625  *
2626  * XXX not yet usable: since we support a half-closed state and do not
2627  * ref count the tty reference from the session, it is possible for a 
2628  * session to hold a ref on the tty.  See TTY_DO_FULL_CLOSE.
2629  */
2630 void
2631 ttyfree(struct tty *tp)
2632 {
2633         kfree(tp, M_TTYS);
2634 }
2635 #endif /* 0 */
2636
2637 void
2638 ttyregister(struct tty *tp)
2639 {
2640         SLIST_INSERT_HEAD(&tty_list, tp, t_list);
2641 }
2642
2643 static int
2644 sysctl_kern_ttys(SYSCTL_HANDLER_ARGS)
2645 {
2646         int error;
2647         struct tty *tp, t;
2648         SLIST_FOREACH(tp, &tty_list, t_list) {
2649                 t = *tp;
2650                 if (t.t_dev)
2651                         t.t_dev = (cdev_t)(uintptr_t)dev2udev(t.t_dev);
2652                 error = SYSCTL_OUT(req, (caddr_t)&t, sizeof(t));
2653                 if (error)
2654                         return (error);
2655         }
2656         return (0);
2657 }
2658
2659 SYSCTL_PROC(_kern, OID_AUTO, ttys, CTLTYPE_OPAQUE|CTLFLAG_RD,
2660         0, 0, sysctl_kern_ttys, "S,tty", "All struct ttys");
2661
2662 void
2663 nottystop(struct tty *tp, int rw)
2664 {
2665
2666         return;
2667 }
2668
2669 int
2670 ttyread(struct dev_read_args *ap)
2671 {
2672         struct tty *tp;
2673
2674         tp = ap->a_head.a_dev->si_tty;
2675         if (tp == NULL)
2676                 return (ENODEV);
2677         return ((*linesw[tp->t_line].l_read)(tp, ap->a_uio, ap->a_ioflag));
2678 }
2679
2680 int
2681 ttywrite(struct dev_write_args *ap)
2682 {
2683         struct tty *tp;
2684
2685         tp = ap->a_head.a_dev->si_tty;
2686         if (tp == NULL)
2687                 return (ENODEV);
2688         return ((*linesw[tp->t_line].l_write)(tp, ap->a_uio, ap->a_ioflag));
2689 }