Loading...
iokit/Kernel/IOBufferMemoryDescriptor.cpp xnu-1228 xnu-3789.41.3
--- xnu/xnu-1228/iokit/Kernel/IOBufferMemoryDescriptor.cpp
+++ xnu/xnu-3789.41.3/iokit/Kernel/IOBufferMemoryDescriptor.cpp
@@ -25,26 +25,49 @@
  * 
  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
  */
+
+#define _IOMEMORYDESCRIPTOR_INTERNAL_
+
 #include <IOKit/assert.h>
 #include <IOKit/system.h>
 
 #include <IOKit/IOLib.h>
 #include <IOKit/IOMapper.h>
 #include <IOKit/IOBufferMemoryDescriptor.h>
+#include <libkern/OSDebug.h>
+#include <mach/mach_vm.h>
 
 #include "IOKitKernelInternal.h"
-#include "IOCopyMapper.h"
+
+#ifdef IOALLOCDEBUG
+#include <libkern/c++/OSCPPDebug.h>
+#endif
+#include <IOKit/IOStatisticsPrivate.h>
+
+#if IOKITSTATS
+#define IOStatisticsAlloc(type, size) \
+do { \
+	IOStatistics::countAlloc(type, size); \
+} while (0)
+#else
+#define IOStatisticsAlloc(type, size)
+#endif /* IOKITSTATS */
+
 
 __BEGIN_DECLS
 void ipc_port_release_send(ipc_port_t port);
 #include <vm/pmap.h>
 
-vm_map_t IOPageableMapForAddress( vm_address_t address );
 __END_DECLS
 
 /* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
 
-volatile ppnum_t gIOHighestAllocatedPage;
+enum
+{
+    kInternalFlagPhysical      = 0x00000001,
+    kInternalFlagPageSized     = 0x00000002,
+    kInternalFlagPageAllocated = 0x00000004
+};
 
 /* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
 
@@ -52,50 +75,26 @@
 OSDefineMetaClassAndStructors(IOBufferMemoryDescriptor,
 				IOGeneralMemoryDescriptor);
 
-bool IOBufferMemoryDescriptor::initWithAddress(
-                                  void *      /* address       */ ,
-                                  IOByteCount /* withLength    */ ,
-                                  IODirection /* withDirection */ )
-{
-    return false;
-}
-
-bool IOBufferMemoryDescriptor::initWithAddress(
-                                  vm_address_t /* address       */ ,
-                                  IOByteCount  /* withLength    */ ,
-                                  IODirection  /* withDirection */ ,
-                                  task_t       /* withTask      */ )
-{
-    return false;
-}
-
-bool IOBufferMemoryDescriptor::initWithPhysicalAddress(
-                                  IOPhysicalAddress /* address       */ ,
-                                  IOByteCount       /* withLength    */ ,
-                                  IODirection       /* withDirection */ )
-{
-    return false;
-}
-
-bool IOBufferMemoryDescriptor::initWithPhysicalRanges(
-                                  IOPhysicalRange * /* ranges        */ ,
-                                  UInt32            /* withCount     */ ,
-                                  IODirection       /* withDirection */ ,
-                                  bool              /* asReference   */ )
-{
-    return false;
-}
-
-bool IOBufferMemoryDescriptor::initWithRanges(
-                                  IOVirtualRange * /* ranges        */ ,
-                                  UInt32           /* withCount     */ ,
-                                  IODirection      /* withDirection */ ,
-                                  task_t           /* withTask      */ ,
-                                  bool             /* asReference   */ )
-{
-    return false;
-}
-
+/* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
+
+static uintptr_t IOBMDPageProc(iopa_t * a)
+{
+    kern_return_t kr;
+    vm_address_t  vmaddr  = 0;
+    int           options = 0; // KMA_LOMEM;
+
+    kr = kernel_memory_allocate(kernel_map, &vmaddr,
+				page_size, 0, options, VM_KERN_MEMORY_IOKIT);
+
+    if (KERN_SUCCESS != kr) vmaddr = 0;
+    else 		    bzero((void *) vmaddr, page_size);
+
+    return ((uintptr_t) vmaddr);
+}
+
+/* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * */
+
+#ifndef __LP64__
 bool IOBufferMemoryDescriptor::initWithOptions(
                                IOOptionBits options,
                                vm_size_t    capacity,
@@ -105,6 +104,7 @@
     mach_vm_address_t physicalMask = 0;
     return (initWithPhysicalMask(inTask, options, capacity, alignment, physicalMask));
 }
+#endif /* !__LP64__ */
 
 bool IOBufferMemoryDescriptor::initWithPhysicalMask(
 				task_t		  inTask,
@@ -113,149 +113,155 @@
 				mach_vm_address_t alignment,
 				mach_vm_address_t physicalMask)
 {
-    kern_return_t 	kr;
-    task_t		mapTask = NULL;
-    vm_map_t 		vmmap = NULL;
-    addr64_t            lastIOAddr;
-    IOAddressRange	range;
-    IOOptionBits	iomdOptions = kIOMemoryTypeVirtual64;
-
-    if (!capacity)
-        return false;
-
-    _options   	  = options;
-    _capacity     = capacity;
-    _physAddrs    = 0;
-    _physSegCount = 0;
-    _buffer	  = 0;
-    range.address = 0;
-    range.length  = 0;
-    _ranges.v64   = &range;
-
-    // Grab the direction and the Auto Prepare bits from the Buffer MD options
-    iomdOptions  |= options & (kIOMemoryDirectionMask | kIOMemoryAutoPrepare);
-
-    if ((options & (kIOMemorySharingTypeMask | kIOMapCacheMask)) && (alignment < page_size))
+    task_t		  mapTask = NULL;
+    vm_map_t 		  vmmap = NULL;
+    mach_vm_address_t     highestMask = 0;
+    IOOptionBits	  iomdOptions = kIOMemoryTypeVirtual64 | kIOMemoryAsReference;
+    IODMAMapSpecification mapSpec;
+    bool                  mapped = false;
+    bool                  needZero;
+
+    if (!capacity) return false;
+
+    _options   	      = options;
+    _capacity         = capacity;
+    _internalFlags    = 0;
+    _internalReserved = 0;
+    _buffer	      = 0;
+
+    _ranges.v64 = IONew(IOAddressRange, 1);
+    if (!_ranges.v64)
+	return (false);
+    _ranges.v64->address = 0;
+    _ranges.v64->length  = 0;
+    //  make sure super::free doesn't dealloc _ranges before super::init
+    _flags = kIOMemoryAsReference;
+
+    // Grab IOMD bits from the Buffer MD options
+    iomdOptions  |= (options & kIOBufferDescriptorMemoryFlags);
+
+    if (!(kIOMemoryMapperNone & options))
+    {
+	IOMapper::checkForSystemMapper();
+	mapped = (0 != IOMapper::gSystem);
+    }
+    needZero = (mapped || (0 != (kIOMemorySharingTypeMask & options)));
+
+    if (physicalMask && (alignment <= 1))
+    {
+	alignment   = ((physicalMask ^ (-1ULL)) & (physicalMask - 1));
+	highestMask = (physicalMask | alignment);
+	alignment++;
+	if (alignment < page_size)
+            alignment = page_size;
+    }
+
+    if ((options & (kIOMemorySharingTypeMask | kIOMapCacheMask | kIOMemoryClearEncrypt)) && (alignment < page_size))
 	alignment = page_size;
 
-    if (physicalMask && (alignment <= 1))
-	alignment = ((physicalMask ^ PAGE_MASK) & PAGE_MASK) + 1;
+    if (alignment >= page_size)
+	capacity = round_page(capacity);
+
+    if (alignment > page_size)
+	options |= kIOMemoryPhysicallyContiguous;
 
     _alignment = alignment;
 
-    if (((inTask != kernel_task) && !(options & kIOMemoryPageable)) ||
-	(physicalMask && (options & kIOMapCacheMask)))
+    if ((capacity + alignment) < _capacity) return (false);
+
+    if ((inTask != kernel_task) && !(options & kIOMemoryPageable))
 	return false;
 
-    if ((options & kIOMemoryPhysicallyContiguous) && !physicalMask)
-	physicalMask = 0xFFFFFFFF;
-
-    // set flags for entry + object create
-    vm_prot_t memEntryCacheMode = VM_PROT_READ | VM_PROT_WRITE;
-
-    // set memory entry cache mode
-    switch (options & kIOMapCacheMask)
-    {
-	case kIOMapInhibitCache:
-	    SET_MAP_MEM(MAP_MEM_IO, memEntryCacheMode);
-	    break;
-
-	case kIOMapWriteThruCache:
-	    SET_MAP_MEM(MAP_MEM_WTHRU, memEntryCacheMode);
-	    break;
-
-	case kIOMapWriteCombineCache:
-	    SET_MAP_MEM(MAP_MEM_WCOMB, memEntryCacheMode);
-	    break;
-
-	case kIOMapCopybackCache:
-	    SET_MAP_MEM(MAP_MEM_COPYBACK, memEntryCacheMode);
-	    break;
-
-	case kIOMapDefaultCache:
-	default:
-	    SET_MAP_MEM(MAP_MEM_NOOP, memEntryCacheMode);
-	    break;
-    }
-
+    bzero(&mapSpec, sizeof(mapSpec));
+    mapSpec.alignment      = _alignment;
+    mapSpec.numAddressBits = 64;
+    if (highestMask && mapped)
+    {
+	if (highestMask <= 0xFFFFFFFF)
+	    mapSpec.numAddressBits = (32 - __builtin_clz((unsigned int) highestMask));
+	else
+	    mapSpec.numAddressBits = (64 - __builtin_clz((unsigned int) (highestMask >> 32)));
+	highestMask = 0;
+    }
+
+    // set memory entry cache mode, pageable, purgeable
+    iomdOptions |= ((options & kIOMapCacheMask) >> kIOMapCacheShift) << kIOMemoryBufferCacheShift;
     if (options & kIOMemoryPageable)
     {
 	iomdOptions |= kIOMemoryBufferPageable;
-
-	// must create the entry before any pages are allocated
-
-	// set flags for entry + object create
-	memEntryCacheMode |= MAP_MEM_NAMED_CREATE;
-
-	if (options & kIOMemoryPurgeable)
-	    memEntryCacheMode |= MAP_MEM_PURGABLE;
+	if (options & kIOMemoryPurgeable) iomdOptions |= kIOMemoryBufferPurgeable;
     }
     else
     {
-	memEntryCacheMode |= MAP_MEM_NAMED_REUSE;
-
-	if (IOMapper::gSystem)
-	    // assuming mapped space is 2G
-	    lastIOAddr = (1UL << 31) - PAGE_SIZE;
+	vmmap = kernel_map;
+
+	// Buffer shouldn't auto prepare they should be prepared explicitly
+	// But it never was enforced so what are you going to do?
+	iomdOptions |= kIOMemoryAutoPrepare;
+
+	/* Allocate a wired-down buffer inside kernel space. */
+
+	bool contig = (0 != (options & kIOMemoryHostPhysicallyContiguous));
+
+	if (!contig && (0 != (options & kIOMemoryPhysicallyContiguous)))
+	{
+	    contig |= (!mapped);
+	    contig |= (0 != (kIOMemoryMapperNone & options));
+#if 0
+	    // treat kIOMemoryPhysicallyContiguous as kIOMemoryHostPhysicallyContiguous for now
+	    contig |= true;
+#endif
+	}
+
+	if (contig || highestMask || (alignment > page_size))
+	{
+            _internalFlags |= kInternalFlagPhysical;
+            if (highestMask)
+            {
+                _internalFlags |= kInternalFlagPageSized;
+                capacity = round_page(capacity);
+            }
+            _buffer = (void *) IOKernelAllocateWithPhysicalRestrict(
+            				capacity, highestMask, alignment, contig);
+	}
+	else if (needZero
+		  && ((capacity + alignment) <= (page_size - gIOPageAllocChunkBytes)))
+	{
+            _internalFlags |= kInternalFlagPageAllocated;
+            needZero        = false;
+            _buffer         = (void *) iopa_alloc(&gIOBMDPageAllocator, &IOBMDPageProc, capacity, alignment);
+	    if (_buffer)
+	    {
+		IOStatisticsAlloc(kIOStatisticsMallocAligned, capacity);
+#if IOALLOCDEBUG
+		OSAddAtomic(capacity, &debug_iomalloc_size);
+#endif
+	    }
+	}
+	else if (alignment > 1)
+	{
+            _buffer = IOMallocAligned(capacity, alignment);
+	}
 	else
-	    lastIOAddr = ptoa_64(gIOHighestAllocatedPage);
-
-	if (physicalMask && (lastIOAddr != (lastIOAddr & physicalMask)))
-	{
-	    mach_vm_address_t address;
-	    iomdOptions &= ~kIOMemoryTypeVirtual64;
-	    iomdOptions |= kIOMemoryTypePhysical64;
-
-	    address = IOMallocPhysical(capacity, physicalMask);
-	    _buffer = (void *) address;
-	    if (!_buffer)
-		return false;
-
-	    mapTask = inTask;
-	    inTask = 0;
-	}
-	else
-	{
-	    vmmap = kernel_map;
-
-	    // Buffer shouldn't auto prepare they should be prepared explicitly
-	    // But it never was enforced so what are you going to do?
-	    iomdOptions |= kIOMemoryAutoPrepare;
-
-	    /* Allocate a wired-down buffer inside kernel space. */
-	    if (options & kIOMemoryPhysicallyContiguous)
-		_buffer = (void *) IOKernelAllocateContiguous(capacity, alignment);
-	    else if (alignment > 1)
-		_buffer = IOMallocAligned(capacity, alignment);
-	    else
-		_buffer = IOMalloc(capacity);
-	    if (!_buffer)
-		return false;
-	}
-    }
-
-    if( (kIOMemoryTypePhysical64 != (kIOMemoryTypeMask & iomdOptions)) 
-	&& (options & (kIOMemoryPageable | kIOMapCacheMask))) {
-	ipc_port_t	sharedMem;
-	vm_size_t	size = round_page_32(capacity);
-
-	kr = mach_make_memory_entry(vmmap,
-				    &size, (vm_offset_t)_buffer,
-				    memEntryCacheMode, &sharedMem,
-				    NULL );
-
-	if( (KERN_SUCCESS == kr) && (size != round_page_32(capacity))) {
-	    ipc_port_release_send( sharedMem );
-	    kr = kIOReturnVMError;
-	}
-	if( KERN_SUCCESS != kr)
-	    return( false );
-
-	_memEntry = (void *) sharedMem;
+	{
+            _buffer = IOMalloc(capacity);
+	}
+	if (!_buffer)
+	{
+            return false;
+	}
+	if (needZero) bzero(_buffer, capacity);
+    }
+
+    if( (options & (kIOMemoryPageable | kIOMapCacheMask))) {
+	vm_size_t	size = round_page(capacity);
+
+	// initWithOptions will create memory entry
+	iomdOptions |= kIOMemoryPersistent;
 
 	if( options & kIOMemoryPageable) {
 #if IOALLOCDEBUG
-	    debug_iomallocpageable_size += size;
+	    OSAddAtomicLong(size, &debug_iomallocpageable_size);
 #endif
 	    mapTask = inTask;
 	    if (NULL == inTask)
@@ -269,54 +275,24 @@
 
 	    while (startAddr < endAddr)
 	    {
-		*startAddr;
+		UInt8 dummyVar = *startAddr;
+		(void) dummyVar;
 		startAddr += page_size;
-	    }
-	}
-    }
-
-    range.address = (mach_vm_address_t) _buffer;
-    range.length  = capacity;
-
-    if (!super::initWithOptions(&range, 1, 0,
+ 	    }
+	}
+    }
+
+    _ranges.v64->address = (mach_vm_address_t) _buffer;;
+    _ranges.v64->length  = _capacity;
+
+    if (!super::initWithOptions(_ranges.v64, 1, 0,
 				inTask, iomdOptions, /* System mapper */ 0))
 	return false;
 
-    if (physicalMask && !IOMapper::gSystem)
-    {
-	IOMDDMACharacteristics mdSummary;
-
-	bzero(&mdSummary, sizeof(mdSummary));
-	IOReturn rtn = dmaCommandOperation(
-		kIOMDGetCharacteristics,
-		&mdSummary, sizeof(mdSummary));
-	if (rtn)
-	    return false;
-
-	if (mdSummary.fHighestPage)
-	{
-	    ppnum_t highest;
-	    while (mdSummary.fHighestPage > (highest = gIOHighestAllocatedPage))
-	    {
-		if (OSCompareAndSwap(highest, mdSummary.fHighestPage, 
-					(UInt32 *) &gIOHighestAllocatedPage))
-		    break;
-	    }
-	    lastIOAddr = ptoa_64(mdSummary.fHighestPage);
-	}
-	else
-	    lastIOAddr = ptoa_64(gIOLastPage);
-
-	if (lastIOAddr != (lastIOAddr & physicalMask))
-	{
-	    if (kIOMemoryTypePhysical64 != (_flags & kIOMemoryTypeMask))
-	    {
-		// flag a retry
-		_physSegCount = 1;
-	    }
-	    return false;
-	}
-    }
+    // give any system mapper the allocation params
+    if (kIOReturnSuccess != dmaCommandOperation(kIOMDAddDMAMapSpec, 
+    						&mapSpec, sizeof(mapSpec)))
+	return false;
 
     if (mapTask)
     {
@@ -325,20 +301,23 @@
 	    if( !reserved)
 		return( false );
 	}
-	reserved->map = map(mapTask, 0, kIOMapAnywhere, 0, 0);
+	reserved->map = createMappingInTask(mapTask, 0, 
+			    kIOMapAnywhere | (options & kIOMapPrefault) | (options & kIOMapCacheMask), 0, 0);
 	if (!reserved->map)
 	{
 	    _buffer = 0;
 	    return( false );
 	}
 	release();	    // map took a retain on this
+	reserved->map->retain();
+	removeMapping(reserved->map);
 	mach_vm_address_t buffer = reserved->map->getAddress();
 	_buffer = (void *) buffer;
 	if (kIOMemoryTypeVirtual64 == (kIOMemoryTypeMask & iomdOptions))
 	    _ranges.v64->address = buffer;
     }
 
-    setLength(capacity);
+    setLength(_capacity);
 
     return true;
 }
@@ -351,19 +330,9 @@
 {
     IOBufferMemoryDescriptor *me = new IOBufferMemoryDescriptor;
     
-    if (me && !me->initWithOptions(options, capacity, alignment, inTask)) {
-	bool retry = me->_physSegCount;
+    if (me && !me->initWithPhysicalMask(inTask, options, capacity, alignment, 0)) {
 	me->release();
 	me = 0;
-	if (retry)
-	{
-	    me = new IOBufferMemoryDescriptor;
-	    if (me && !me->initWithOptions(options, capacity, alignment, inTask))
-	    {
-		me->release();
-		me = 0;
-	    }
-	}
     }
     return me;
 }
@@ -378,36 +347,34 @@
     
     if (me && !me->initWithPhysicalMask(inTask, options, capacity, 1, physicalMask))
     {
-	bool retry = me->_physSegCount;
 	me->release();
 	me = 0;
-	if (retry)
-	{
-	    me = new IOBufferMemoryDescriptor;
-	    if (me && !me->initWithPhysicalMask(inTask, options, capacity, 1, physicalMask))
-	    {
-		me->release();
-		me = 0;
-	    }
-	}
     }
     return me;
 }
 
+#ifndef __LP64__
 bool IOBufferMemoryDescriptor::initWithOptions(
                                IOOptionBits options,
                                vm_size_t    capacity,
                                vm_offset_t  alignment)
 {
-    return( initWithOptions(options, capacity, alignment, kernel_task) );
-}
+    return (initWithPhysicalMask(kernel_task, options, capacity, alignment, (mach_vm_address_t)0));
+}
+#endif /* !__LP64__ */
 
 IOBufferMemoryDescriptor * IOBufferMemoryDescriptor::withOptions(
                                             IOOptionBits options,
                                             vm_size_t    capacity,
                                             vm_offset_t  alignment)
 {
-    return(IOBufferMemoryDescriptor::inTaskWithOptions(kernel_task, options, capacity, alignment));
+    IOBufferMemoryDescriptor *me = new IOBufferMemoryDescriptor;
+    
+    if (me && !me->initWithPhysicalMask(kernel_task, options, capacity, alignment, 0)) {
+	me->release();
+	me = 0;
+    }
+    return me;
 }
 
 
@@ -428,6 +395,7 @@
                inCapacity, inContiguous ? inCapacity : 1 ));
 }
 
+#ifndef __LP64__
 /*
  * initWithBytes:
  *
@@ -439,10 +407,9 @@
                                              IODirection  inDirection,
                                              bool         inContiguous)
 {
-    if (!initWithOptions(
-               inDirection | kIOMemoryUnshared
-                | (inContiguous ? kIOMemoryPhysicallyContiguous : 0),
-               inLength, inLength ))
+    if (!initWithPhysicalMask(kernel_task, inDirection | kIOMemoryUnshared
+			      | (inContiguous ? kIOMemoryPhysicallyContiguous : 0),
+			      inLength, inLength, (mach_vm_address_t)0))
         return false;
 
     // start out with no data
@@ -453,6 +420,7 @@
 
     return true;
 }
+#endif /* !__LP64__ */
 
 /*
  * withBytes:
@@ -468,21 +436,25 @@
 {
     IOBufferMemoryDescriptor *me = new IOBufferMemoryDescriptor;
 
-    if (me && !me->initWithBytes(inBytes, inLength, inDirection, inContiguous))
-    {
-	bool retry = me->_physSegCount;
+    if (me && !me->initWithPhysicalMask(
+               kernel_task, inDirection | kIOMemoryUnshared
+                | (inContiguous ? kIOMemoryPhysicallyContiguous : 0),
+               inLength, inLength, 0 ))
+    {
 	me->release();
 	me = 0;
-	if (retry)
-	{
-	    me = new IOBufferMemoryDescriptor;
-	    if (me && !me->initWithBytes(inBytes, inLength, inDirection, inContiguous))
-	    {
-		me->release();
-		me = 0;
-	    }
-	}
-
+    }
+
+    if (me)
+    {
+	// start out with no data
+	me->setLength(0);
+
+	if (!me->appendBytes(inBytes, inLength))
+	{
+	    me->release();
+	    me = 0;
+	}
     }
     return me;
 }
@@ -496,13 +468,17 @@
 {
     // Cache all of the relevant information on the stack for use
     // after we call super::free()!
-    IOOptionBits     flags     = _flags;
+    IOOptionBits     flags         = _flags;
+    IOOptionBits     internalFlags = _internalFlags;
     IOOptionBits     options   = _options;
     vm_size_t        size      = _capacity;
     void *           buffer    = _buffer;
-    IOVirtualAddress source    = _ranges.v64->address;
     IOMemoryMap *    map       = 0;
+    IOAddressRange * range     = _ranges.v64;
     vm_offset_t      alignment = _alignment;
+
+    if (alignment >= page_size)
+	size = round_page(size);
 
     if (reserved)
     {
@@ -518,20 +494,41 @@
     if (options & kIOMemoryPageable)
     {
 #if IOALLOCDEBUG
-	debug_iomallocpageable_size -= round_page_32(size);
+	OSAddAtomicLong(-(round_page(size)), &debug_iomallocpageable_size);
 #endif
     }
     else if (buffer)
     {
-	if (kIOMemoryTypePhysical64 == (flags & kIOMemoryTypeMask))
-	    IOFreePhysical((mach_vm_address_t) source, size);
-        else if (options & kIOMemoryPhysicallyContiguous)
-            IOKernelFreeContiguous((mach_vm_address_t) buffer, size);
+	if (kInternalFlagPageSized & internalFlags) size = round_page(size);
+
+        if (kInternalFlagPhysical & internalFlags)
+        {
+            IOKernelFreePhysical((mach_vm_address_t) buffer, size);
+	}
+	else if (kInternalFlagPageAllocated & internalFlags)
+	{
+	    uintptr_t page;
+            page = iopa_free(&gIOBMDPageAllocator, (uintptr_t) buffer, size);
+	    if (page)
+	    {
+		kmem_free(kernel_map, page, page_size);
+	    }
+#if IOALLOCDEBUG
+		OSAddAtomic(-size, &debug_iomalloc_size);
+#endif
+	    IOStatisticsAlloc(kIOStatisticsFreeAligned, size);
+	}
         else if (alignment > 1)
+	{
             IOFreeAligned(buffer, size);
+	}
         else
+	{
             IOFree(buffer, size);
-    }
+	}
+    }
+    if (range && (kIOMemoryAsReference & flags))
+	IODelete(range, IOAddressRange, 1);
 }
 
 /*
@@ -557,6 +554,7 @@
 void IOBufferMemoryDescriptor::setLength(vm_size_t length)
 {
     assert(length <= _capacity);
+    if (length > _capacity) return;
 
     _length = length;
     _ranges.v64->length = length;
@@ -571,7 +569,10 @@
  */
 void IOBufferMemoryDescriptor::setDirection(IODirection direction)
 {
-    _direction = direction;
+    _flags = (_flags & ~kIOMemoryDirectionMask) | direction;
+#ifndef __LP64__
+    _direction = (IODirection) (_flags & kIOMemoryDirectionMask);
+#endif /* !__LP64__ */
 }
 
 /*
@@ -625,6 +626,9 @@
 IOBufferMemoryDescriptor::getBytesNoCopy(vm_size_t start, vm_size_t withLength)
 {
     IOVirtualAddress address;
+
+    if ((start + withLength) < start) return 0;
+
     if (kIOMemoryTypePhysical64 == (_flags & kIOMemoryTypeMask))
 	address = (IOVirtualAddress) _buffer;
     else
@@ -635,8 +639,9 @@
     return 0;
 }
 
-/* DEPRECATED */ void * IOBufferMemoryDescriptor::getVirtualSegment(IOByteCount offset,
-/* DEPRECATED */ 							IOByteCount * lengthOfSegment)
+#ifndef __LP64__
+void * IOBufferMemoryDescriptor::getVirtualSegment(IOByteCount offset,
+							IOByteCount * lengthOfSegment)
 {
     void * bytes = getBytesNoCopy(offset, 0);
     
@@ -645,9 +650,15 @@
 
     return bytes;
 }
-
+#endif /* !__LP64__ */
+
+#ifdef __LP64__
+OSMetaClassDefineReservedUnused(IOBufferMemoryDescriptor, 0);
+OSMetaClassDefineReservedUnused(IOBufferMemoryDescriptor, 1);
+#else /* !__LP64__ */
 OSMetaClassDefineReservedUsed(IOBufferMemoryDescriptor, 0);
 OSMetaClassDefineReservedUsed(IOBufferMemoryDescriptor, 1);
+#endif /* !__LP64__ */
 OSMetaClassDefineReservedUnused(IOBufferMemoryDescriptor, 2);
 OSMetaClassDefineReservedUnused(IOBufferMemoryDescriptor, 3);
 OSMetaClassDefineReservedUnused(IOBufferMemoryDescriptor, 4);