kvm_main.c 46.1 KB
Newer Older
A
Avi Kivity 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
/*
 * Kernel-based Virtual Machine driver for Linux
 *
 * This module enables machines with Intel VT-x extensions to run virtual
 * machines without emulation or binary translation.
 *
 * Copyright (C) 2006 Qumranet, Inc.
 *
 * Authors:
 *   Avi Kivity   <avi@qumranet.com>
 *   Yaniv Kamay  <yaniv@qumranet.com>
 *
 * This work is licensed under the terms of the GNU GPL, version 2.  See
 * the COPYING file in the top-level directory.
 *
 */

#include "kvm.h"
19
#include "x86.h"
A
Avi Kivity 已提交
20
#include "x86_emulate.h"
21
#include "irq.h"
A
Avi Kivity 已提交
22 23 24 25 26 27 28 29 30 31 32 33 34

#include <linux/kvm.h>
#include <linux/module.h>
#include <linux/errno.h>
#include <linux/percpu.h>
#include <linux/gfp.h>
#include <linux/mm.h>
#include <linux/miscdevice.h>
#include <linux/vmalloc.h>
#include <linux/reboot.h>
#include <linux/debugfs.h>
#include <linux/highmem.h>
#include <linux/file.h>
35
#include <linux/sysdev.h>
A
Avi Kivity 已提交
36
#include <linux/cpu.h>
A
Alexey Dobriyan 已提交
37
#include <linux/sched.h>
38 39
#include <linux/cpumask.h>
#include <linux/smp.h>
40
#include <linux/anon_inodes.h>
41
#include <linux/profile.h>
42
#include <linux/kvm_para.h>
43
#include <linux/pagemap.h>
44
#include <linux/mman.h>
A
Avi Kivity 已提交
45

A
Avi Kivity 已提交
46 47 48 49 50
#include <asm/processor.h>
#include <asm/msr.h>
#include <asm/io.h>
#include <asm/uaccess.h>
#include <asm/desc.h>
A
Avi Kivity 已提交
51 52 53 54

MODULE_AUTHOR("Qumranet");
MODULE_LICENSE("GPL");

55 56 57
static DEFINE_SPINLOCK(kvm_lock);
static LIST_HEAD(vm_list);

58 59
static cpumask_t cpus_hardware_enabled;

60
struct kvm_x86_ops *kvm_x86_ops;
61 62
struct kmem_cache *kvm_vcpu_cache;
EXPORT_SYMBOL_GPL(kvm_vcpu_cache);
A
Avi Kivity 已提交
63

64 65
static __read_mostly struct preempt_ops kvm_preempt_ops;

A
Avi Kivity 已提交
66 67
static struct dentry *debugfs_dir;

A
Avi Kivity 已提交
68 69 70
static long kvm_vcpu_ioctl(struct file *file, unsigned int ioctl,
			   unsigned long arg);

71 72 73 74 75
static inline int valid_vcpu(int n)
{
	return likely(n >= 0 && n < KVM_MAX_VCPUS);
}

76 77 78 79 80 81
void kvm_load_guest_fpu(struct kvm_vcpu *vcpu)
{
	if (!vcpu->fpu_active || vcpu->guest_fpu_loaded)
		return;

	vcpu->guest_fpu_loaded = 1;
82 83
	fx_save(&vcpu->host_fx_image);
	fx_restore(&vcpu->guest_fx_image);
84 85 86 87 88 89 90 91 92
}
EXPORT_SYMBOL_GPL(kvm_load_guest_fpu);

void kvm_put_guest_fpu(struct kvm_vcpu *vcpu)
{
	if (!vcpu->guest_fpu_loaded)
		return;

	vcpu->guest_fpu_loaded = 0;
93 94
	fx_save(&vcpu->guest_fx_image);
	fx_restore(&vcpu->host_fx_image);
95 96 97
}
EXPORT_SYMBOL_GPL(kvm_put_guest_fpu);

A
Avi Kivity 已提交
98 99 100
/*
 * Switches to specified vcpu, until a matching vcpu_put()
 */
101
void vcpu_load(struct kvm_vcpu *vcpu)
A
Avi Kivity 已提交
102
{
103 104
	int cpu;

A
Avi Kivity 已提交
105
	mutex_lock(&vcpu->mutex);
106 107
	cpu = get_cpu();
	preempt_notifier_register(&vcpu->preempt_notifier);
108
	kvm_arch_vcpu_load(vcpu, cpu);
109
	put_cpu();
A
Avi Kivity 已提交
110 111
}

112
void vcpu_put(struct kvm_vcpu *vcpu)
A
Avi Kivity 已提交
113
{
114
	preempt_disable();
115
	kvm_arch_vcpu_put(vcpu);
116 117
	preempt_notifier_unregister(&vcpu->preempt_notifier);
	preempt_enable();
A
Avi Kivity 已提交
118 119 120
	mutex_unlock(&vcpu->mutex);
}

121 122 123 124 125 126
static void ack_flush(void *_completed)
{
}

void kvm_flush_remote_tlbs(struct kvm *kvm)
{
127
	int i, cpu;
128 129 130 131
	cpumask_t cpus;
	struct kvm_vcpu *vcpu;

	cpus_clear(cpus);
R
Rusty Russell 已提交
132 133 134 135
	for (i = 0; i < KVM_MAX_VCPUS; ++i) {
		vcpu = kvm->vcpus[i];
		if (!vcpu)
			continue;
136
		if (test_and_set_bit(KVM_REQ_TLB_FLUSH, &vcpu->requests))
137 138 139
			continue;
		cpu = vcpu->cpu;
		if (cpu != -1 && cpu != raw_smp_processor_id())
140
			cpu_set(cpu, cpus);
141
	}
142
	smp_call_function_mask(cpus, ack_flush, NULL, 1);
143 144
}

R
Rusty Russell 已提交
145 146 147 148 149 150 151 152 153 154
int kvm_vcpu_init(struct kvm_vcpu *vcpu, struct kvm *kvm, unsigned id)
{
	struct page *page;
	int r;

	mutex_init(&vcpu->mutex);
	vcpu->cpu = -1;
	vcpu->mmu.root_hpa = INVALID_PAGE;
	vcpu->kvm = kvm;
	vcpu->vcpu_id = id;
155 156 157 158
	if (!irqchip_in_kernel(kvm) || id == 0)
		vcpu->mp_state = VCPU_MP_STATE_RUNNABLE;
	else
		vcpu->mp_state = VCPU_MP_STATE_UNINITIALIZED;
E
Eddie Dong 已提交
159
	init_waitqueue_head(&vcpu->wq);
R
Rusty Russell 已提交
160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178

	page = alloc_page(GFP_KERNEL | __GFP_ZERO);
	if (!page) {
		r = -ENOMEM;
		goto fail;
	}
	vcpu->run = page_address(page);

	page = alloc_page(GFP_KERNEL | __GFP_ZERO);
	if (!page) {
		r = -ENOMEM;
		goto fail_free_run;
	}
	vcpu->pio_data = page_address(page);

	r = kvm_mmu_create(vcpu);
	if (r < 0)
		goto fail_free_pio_data;

179 180 181 182 183 184
	if (irqchip_in_kernel(kvm)) {
		r = kvm_create_lapic(vcpu);
		if (r < 0)
			goto fail_mmu_destroy;
	}

R
Rusty Russell 已提交
185 186
	return 0;

187 188
fail_mmu_destroy:
	kvm_mmu_destroy(vcpu);
R
Rusty Russell 已提交
189 190 191 192 193
fail_free_pio_data:
	free_page((unsigned long)vcpu->pio_data);
fail_free_run:
	free_page((unsigned long)vcpu->run);
fail:
194
	return r;
R
Rusty Russell 已提交
195 196 197 198 199
}
EXPORT_SYMBOL_GPL(kvm_vcpu_init);

void kvm_vcpu_uninit(struct kvm_vcpu *vcpu)
{
200
	kvm_free_lapic(vcpu);
R
Rusty Russell 已提交
201 202 203 204 205 206
	kvm_mmu_destroy(vcpu);
	free_page((unsigned long)vcpu->pio_data);
	free_page((unsigned long)vcpu->run);
}
EXPORT_SYMBOL_GPL(kvm_vcpu_uninit);

207
static struct kvm *kvm_create_vm(void)
A
Avi Kivity 已提交
208 209 210 211
{
	struct kvm *kvm = kzalloc(sizeof(struct kvm), GFP_KERNEL);

	if (!kvm)
212
		return ERR_PTR(-ENOMEM);
A
Avi Kivity 已提交
213

214
	kvm_io_bus_init(&kvm->pio_bus);
S
Shaohua Li 已提交
215
	mutex_init(&kvm->lock);
A
Avi Kivity 已提交
216
	INIT_LIST_HEAD(&kvm->active_mmu_pages);
217
	kvm_io_bus_init(&kvm->mmio_bus);
218 219 220
	spin_lock(&kvm_lock);
	list_add(&kvm->vm_list, &vm_list);
	spin_unlock(&kvm_lock);
221 222 223
	return kvm;
}

A
Avi Kivity 已提交
224 225 226 227 228 229
/*
 * Free any memory in @free but not in @dont.
 */
static void kvm_free_physmem_slot(struct kvm_memory_slot *free,
				  struct kvm_memory_slot *dont)
{
230 231
	if (!dont || free->rmap != dont->rmap)
		vfree(free->rmap);
A
Avi Kivity 已提交
232 233 234 235 236

	if (!dont || free->dirty_bitmap != dont->dirty_bitmap)
		vfree(free->dirty_bitmap);

	free->npages = 0;
A
Al Viro 已提交
237
	free->dirty_bitmap = NULL;
238
	free->rmap = NULL;
A
Avi Kivity 已提交
239 240 241 242 243 244 245
}

static void kvm_free_physmem(struct kvm *kvm)
{
	int i;

	for (i = 0; i < kvm->nmemslots; ++i)
A
Al Viro 已提交
246
		kvm_free_physmem_slot(&kvm->memslots[i], NULL);
A
Avi Kivity 已提交
247 248
}

A
Avi Kivity 已提交
249 250 251 252 253 254 255
static void kvm_unload_vcpu_mmu(struct kvm_vcpu *vcpu)
{
	vcpu_load(vcpu);
	kvm_mmu_unload(vcpu);
	vcpu_put(vcpu);
}

A
Avi Kivity 已提交
256 257 258 259
static void kvm_free_vcpus(struct kvm *kvm)
{
	unsigned int i;

A
Avi Kivity 已提交
260 261 262 263
	/*
	 * Unpin any mmu pages first.
	 */
	for (i = 0; i < KVM_MAX_VCPUS; ++i)
R
Rusty Russell 已提交
264 265 266 267
		if (kvm->vcpus[i])
			kvm_unload_vcpu_mmu(kvm->vcpus[i]);
	for (i = 0; i < KVM_MAX_VCPUS; ++i) {
		if (kvm->vcpus[i]) {
268
			kvm_x86_ops->vcpu_free(kvm->vcpus[i]);
R
Rusty Russell 已提交
269 270 271 272
			kvm->vcpus[i] = NULL;
		}
	}

A
Avi Kivity 已提交
273 274
}

275 276
static void kvm_destroy_vm(struct kvm *kvm)
{
277 278 279
	spin_lock(&kvm_lock);
	list_del(&kvm->vm_list);
	spin_unlock(&kvm_lock);
280
	kvm_io_bus_destroy(&kvm->pio_bus);
281
	kvm_io_bus_destroy(&kvm->mmio_bus);
282
	kfree(kvm->vpic);
E
Eddie Dong 已提交
283
	kfree(kvm->vioapic);
A
Avi Kivity 已提交
284 285 286
	kvm_free_vcpus(kvm);
	kvm_free_physmem(kvm);
	kfree(kvm);
287 288 289 290 291 292 293
}

static int kvm_vm_release(struct inode *inode, struct file *filp)
{
	struct kvm *kvm = filp->private_data;

	kvm_destroy_vm(kvm);
A
Avi Kivity 已提交
294 295 296 297 298
	return 0;
}

void fx_init(struct kvm_vcpu *vcpu)
{
299
	unsigned after_mxcsr_mask;
A
Avi Kivity 已提交
300

301 302
	/* Initialize guest FPU by resetting ours and saving into guest's */
	preempt_disable();
303
	fx_save(&vcpu->host_fx_image);
A
Avi Kivity 已提交
304
	fpu_init();
305 306
	fx_save(&vcpu->guest_fx_image);
	fx_restore(&vcpu->host_fx_image);
307
	preempt_enable();
A
Avi Kivity 已提交
308

309
	vcpu->cr0 |= X86_CR0_ET;
310 311 312 313
	after_mxcsr_mask = offsetof(struct i387_fxsave_struct, st_space);
	vcpu->guest_fx_image.mxcsr = 0x1f80;
	memset((void *)&vcpu->guest_fx_image + after_mxcsr_mask,
	       0, sizeof(struct i387_fxsave_struct) - after_mxcsr_mask);
A
Avi Kivity 已提交
314 315 316 317 318 319 320 321
}
EXPORT_SYMBOL_GPL(fx_init);

/*
 * Allocate some memory and give it an address in the guest physical address
 * space.
 *
 * Discontiguous memory is allowed, mostly for framebuffers.
322 323
 *
 * Must be called holding kvm->lock.
A
Avi Kivity 已提交
324
 */
325 326 327
int __kvm_set_memory_region(struct kvm *kvm,
			    struct kvm_userspace_memory_region *mem,
			    int user_alloc)
A
Avi Kivity 已提交
328 329 330 331 332 333 334 335 336 337 338 339 340 341
{
	int r;
	gfn_t base_gfn;
	unsigned long npages;
	unsigned long i;
	struct kvm_memory_slot *memslot;
	struct kvm_memory_slot old, new;

	r = -EINVAL;
	/* General sanity checks */
	if (mem->memory_size & (PAGE_SIZE - 1))
		goto out;
	if (mem->guest_phys_addr & (PAGE_SIZE - 1))
		goto out;
342
	if (mem->slot >= KVM_MEMORY_SLOTS + KVM_PRIVATE_MEM_SLOTS)
A
Avi Kivity 已提交
343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362
		goto out;
	if (mem->guest_phys_addr + mem->memory_size < mem->guest_phys_addr)
		goto out;

	memslot = &kvm->memslots[mem->slot];
	base_gfn = mem->guest_phys_addr >> PAGE_SHIFT;
	npages = mem->memory_size >> PAGE_SHIFT;

	if (!npages)
		mem->flags &= ~KVM_MEM_LOG_DIRTY_PAGES;

	new = old = *memslot;

	new.base_gfn = base_gfn;
	new.npages = npages;
	new.flags = mem->flags;

	/* Disallow changing a memory slot's size. */
	r = -EINVAL;
	if (npages && old.npages && npages != old.npages)
363
		goto out_free;
A
Avi Kivity 已提交
364 365 366 367 368 369 370 371 372 373

	/* Check for overlaps */
	r = -EEXIST;
	for (i = 0; i < KVM_MEMORY_SLOTS; ++i) {
		struct kvm_memory_slot *s = &kvm->memslots[i];

		if (s == memslot)
			continue;
		if (!((base_gfn + npages <= s->base_gfn) ||
		      (base_gfn >= s->base_gfn + s->npages)))
374
			goto out_free;
A
Avi Kivity 已提交
375 376 377 378
	}

	/* Free page dirty bitmap if unneeded */
	if (!(new.flags & KVM_MEM_LOG_DIRTY_PAGES))
A
Al Viro 已提交
379
		new.dirty_bitmap = NULL;
A
Avi Kivity 已提交
380 381 382 383

	r = -ENOMEM;

	/* Allocate if a slot is being created */
384
	if (npages && !new.rmap) {
M
Mike Day 已提交
385
		new.rmap = vmalloc(npages * sizeof(struct page *));
386 387

		if (!new.rmap)
388
			goto out_free;
389 390

		memset(new.rmap, 0, npages * sizeof(*new.rmap));
391

392
		new.user_alloc = user_alloc;
393
		if (user_alloc)
394
			new.userspace_addr = mem->userspace_addr;
395 396 397 398 399 400 401 402 403 404
		else {
			down_write(&current->mm->mmap_sem);
			new.userspace_addr = do_mmap(NULL, 0,
						     npages * PAGE_SIZE,
						     PROT_READ | PROT_WRITE,
						     MAP_SHARED | MAP_ANONYMOUS,
						     0);
			up_write(&current->mm->mmap_sem);

			if (IS_ERR((void *)new.userspace_addr))
405
				goto out_free;
A
Avi Kivity 已提交
406
		}
407 408 409 410 411 412 413 414 415 416 417 418 419
	} else {
		if (!old.user_alloc && old.rmap) {
			int ret;

			down_write(&current->mm->mmap_sem);
			ret = do_munmap(current->mm, old.userspace_addr,
					old.npages * PAGE_SIZE);
			up_write(&current->mm->mmap_sem);
			if (ret < 0)
				printk(KERN_WARNING
				       "kvm_vm_ioctl_set_memory_region: "
				       "failed to munmap memory\n");
		}
A
Avi Kivity 已提交
420 421 422 423 424 425 426 427
	}

	/* Allocate page dirty bitmap if needed */
	if ((new.flags & KVM_MEM_LOG_DIRTY_PAGES) && !new.dirty_bitmap) {
		unsigned dirty_bytes = ALIGN(npages, BITS_PER_LONG) / 8;

		new.dirty_bitmap = vmalloc(dirty_bytes);
		if (!new.dirty_bitmap)
428
			goto out_free;
A
Avi Kivity 已提交
429 430 431 432 433 434
		memset(new.dirty_bitmap, 0, dirty_bytes);
	}

	if (mem->slot >= kvm->nmemslots)
		kvm->nmemslots = mem->slot + 1;

435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452
	if (!kvm->n_requested_mmu_pages) {
		unsigned int n_pages;

		if (npages) {
			n_pages = npages * KVM_PERMILLE_MMU_PAGES / 1000;
			kvm_mmu_change_mmu_pages(kvm, kvm->n_alloc_mmu_pages +
						 n_pages);
		} else {
			unsigned int nr_mmu_pages;

			n_pages = old.npages * KVM_PERMILLE_MMU_PAGES / 1000;
			nr_mmu_pages = kvm->n_alloc_mmu_pages - n_pages;
			nr_mmu_pages = max(nr_mmu_pages,
				        (unsigned int) KVM_MIN_ALLOC_MMU_PAGES);
			kvm_mmu_change_mmu_pages(kvm, nr_mmu_pages);
		}
	}

A
Avi Kivity 已提交
453 454
	*memslot = new;

455 456
	kvm_mmu_slot_remove_write_access(kvm, mem->slot);
	kvm_flush_remote_tlbs(kvm);
A
Avi Kivity 已提交
457 458 459 460

	kvm_free_physmem_slot(&old, &new);
	return 0;

461
out_free:
A
Avi Kivity 已提交
462 463 464
	kvm_free_physmem_slot(&new, &old);
out:
	return r;
465 466

}
467 468 469 470 471 472 473 474 475 476 477 478 479
EXPORT_SYMBOL_GPL(__kvm_set_memory_region);

int kvm_set_memory_region(struct kvm *kvm,
			  struct kvm_userspace_memory_region *mem,
			  int user_alloc)
{
	int r;

	mutex_lock(&kvm->lock);
	r = __kvm_set_memory_region(kvm, mem, user_alloc);
	mutex_unlock(&kvm->lock);
	return r;
}
480 481
EXPORT_SYMBOL_GPL(kvm_set_memory_region);

482 483 484 485
int kvm_vm_ioctl_set_memory_region(struct kvm *kvm,
				   struct
				   kvm_userspace_memory_region *mem,
				   int user_alloc)
486
{
487 488
	if (mem->slot >= KVM_MEMORY_SLOTS)
		return -EINVAL;
489
	return kvm_set_memory_region(kvm, mem, user_alloc);
A
Avi Kivity 已提交
490 491 492 493 494
}

/*
 * Get (and clear) the dirty memory log for a memory slot.
 */
495 496
static int kvm_vm_ioctl_get_dirty_log(struct kvm *kvm,
				      struct kvm_dirty_log *log)
A
Avi Kivity 已提交
497 498 499 500 501 502
{
	struct kvm_memory_slot *memslot;
	int r, i;
	int n;
	unsigned long any = 0;

S
Shaohua Li 已提交
503
	mutex_lock(&kvm->lock);
A
Avi Kivity 已提交
504 505 506 507 508 509 510 511 512 513

	r = -EINVAL;
	if (log->slot >= KVM_MEMORY_SLOTS)
		goto out;

	memslot = &kvm->memslots[log->slot];
	r = -ENOENT;
	if (!memslot->dirty_bitmap)
		goto out;

514
	n = ALIGN(memslot->npages, BITS_PER_LONG) / 8;
A
Avi Kivity 已提交
515

516
	for (i = 0; !any && i < n/sizeof(long); ++i)
A
Avi Kivity 已提交
517 518 519 520 521 522
		any = memslot->dirty_bitmap[i];

	r = -EFAULT;
	if (copy_to_user(log->dirty_bitmap, memslot->dirty_bitmap, n))
		goto out;

523 524 525 526 527 528
	/* If nothing is dirty, don't bother messing with page tables. */
	if (any) {
		kvm_mmu_slot_remove_write_access(kvm, log->slot);
		kvm_flush_remote_tlbs(kvm);
		memset(memslot->dirty_bitmap, 0, n);
	}
A
Avi Kivity 已提交
529 530 531 532

	r = 0;

out:
S
Shaohua Li 已提交
533
	mutex_unlock(&kvm->lock);
A
Avi Kivity 已提交
534 535 536
	return r;
}

537 538 539 540 541 542
int is_error_page(struct page *page)
{
	return page == bad_page;
}
EXPORT_SYMBOL_GPL(is_error_page);

543
gfn_t unalias_gfn(struct kvm *kvm, gfn_t gfn)
544 545 546 547 548 549 550 551 552 553 554 555 556 557
{
	int i;
	struct kvm_mem_alias *alias;

	for (i = 0; i < kvm->naliases; ++i) {
		alias = &kvm->aliases[i];
		if (gfn >= alias->base_gfn
		    && gfn < alias->base_gfn + alias->npages)
			return alias->target_gfn + gfn - alias->base_gfn;
	}
	return gfn;
}

static struct kvm_memory_slot *__gfn_to_memslot(struct kvm *kvm, gfn_t gfn)
A
Avi Kivity 已提交
558 559 560 561 562 563 564 565 566 567
{
	int i;

	for (i = 0; i < kvm->nmemslots; ++i) {
		struct kvm_memory_slot *memslot = &kvm->memslots[i];

		if (gfn >= memslot->base_gfn
		    && gfn < memslot->base_gfn + memslot->npages)
			return memslot;
	}
A
Al Viro 已提交
568
	return NULL;
A
Avi Kivity 已提交
569
}
570 571 572 573 574 575

struct kvm_memory_slot *gfn_to_memslot(struct kvm *kvm, gfn_t gfn)
{
	gfn = unalias_gfn(kvm, gfn);
	return __gfn_to_memslot(kvm, gfn);
}
A
Avi Kivity 已提交
576

577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592
int kvm_is_visible_gfn(struct kvm *kvm, gfn_t gfn)
{
	int i;

	gfn = unalias_gfn(kvm, gfn);
	for (i = 0; i < KVM_MEMORY_SLOTS; ++i) {
		struct kvm_memory_slot *memslot = &kvm->memslots[i];

		if (gfn >= memslot->base_gfn
		    && gfn < memslot->base_gfn + memslot->npages)
			return 1;
	}
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_is_visible_gfn);

593 594 595 596
/*
 * Requires current->mm->mmap_sem to be held
 */
static struct page *__gfn_to_page(struct kvm *kvm, gfn_t gfn)
A
Avi Kivity 已提交
597 598
{
	struct kvm_memory_slot *slot;
599 600
	struct page *page[1];
	int npages;
A
Avi Kivity 已提交
601

602 603
	might_sleep();

604 605
	gfn = unalias_gfn(kvm, gfn);
	slot = __gfn_to_memslot(kvm, gfn);
606 607
	if (!slot) {
		get_page(bad_page);
608
		return bad_page;
609
	}
610 611 612 613 614 615 616 617

	npages = get_user_pages(current, current->mm,
				slot->userspace_addr
				+ (gfn - slot->base_gfn) * PAGE_SIZE, 1,
				1, 1, page, NULL);
	if (npages != 1) {
		get_page(bad_page);
		return bad_page;
618
	}
619 620

	return page[0];
A
Avi Kivity 已提交
621
}
622 623 624 625 626 627 628 629 630 631 632 633

struct page *gfn_to_page(struct kvm *kvm, gfn_t gfn)
{
	struct page *page;

	down_read(&current->mm->mmap_sem);
	page = __gfn_to_page(kvm, gfn);
	up_read(&current->mm->mmap_sem);

	return page;
}

A
Avi Kivity 已提交
634 635
EXPORT_SYMBOL_GPL(gfn_to_page);

636 637 638 639 640 641 642 643
void kvm_release_page(struct page *page)
{
	if (!PageReserved(page))
		SetPageDirty(page);
	put_page(page);
}
EXPORT_SYMBOL_GPL(kvm_release_page);

644 645 646 647 648 649 650 651 652 653 654 655 656 657 658
static int next_segment(unsigned long len, int offset)
{
	if (len > PAGE_SIZE - offset)
		return PAGE_SIZE - offset;
	else
		return len;
}

int kvm_read_guest_page(struct kvm *kvm, gfn_t gfn, void *data, int offset,
			int len)
{
	void *page_virt;
	struct page *page;

	page = gfn_to_page(kvm, gfn);
659 660
	if (is_error_page(page)) {
		kvm_release_page(page);
661
		return -EFAULT;
662
	}
663 664 665 666 667
	page_virt = kmap_atomic(page, KM_USER0);

	memcpy(data, page_virt + offset, len);

	kunmap_atomic(page_virt, KM_USER0);
668
	kvm_release_page(page);
669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_read_guest_page);

int kvm_read_guest(struct kvm *kvm, gpa_t gpa, void *data, unsigned long len)
{
	gfn_t gfn = gpa >> PAGE_SHIFT;
	int seg;
	int offset = offset_in_page(gpa);
	int ret;

	while ((seg = next_segment(len, offset)) != 0) {
		ret = kvm_read_guest_page(kvm, gfn, data, offset, seg);
		if (ret < 0)
			return ret;
		offset = 0;
		len -= seg;
		data += seg;
		++gfn;
	}
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_read_guest);

int kvm_write_guest_page(struct kvm *kvm, gfn_t gfn, const void *data,
			 int offset, int len)
{
	void *page_virt;
	struct page *page;

	page = gfn_to_page(kvm, gfn);
700 701
	if (is_error_page(page)) {
		kvm_release_page(page);
702
		return -EFAULT;
703
	}
704 705 706 707 708 709
	page_virt = kmap_atomic(page, KM_USER0);

	memcpy(page_virt + offset, data, len);

	kunmap_atomic(page_virt, KM_USER0);
	mark_page_dirty(kvm, gfn);
710
	kvm_release_page(page);
711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_write_guest_page);

int kvm_write_guest(struct kvm *kvm, gpa_t gpa, const void *data,
		    unsigned long len)
{
	gfn_t gfn = gpa >> PAGE_SHIFT;
	int seg;
	int offset = offset_in_page(gpa);
	int ret;

	while ((seg = next_segment(len, offset)) != 0) {
		ret = kvm_write_guest_page(kvm, gfn, data, offset, seg);
		if (ret < 0)
			return ret;
		offset = 0;
		len -= seg;
		data += seg;
		++gfn;
	}
	return 0;
}

int kvm_clear_guest_page(struct kvm *kvm, gfn_t gfn, int offset, int len)
{
	void *page_virt;
	struct page *page;

	page = gfn_to_page(kvm, gfn);
741 742
	if (is_error_page(page)) {
		kvm_release_page(page);
743
		return -EFAULT;
744
	}
745 746 747 748 749
	page_virt = kmap_atomic(page, KM_USER0);

	memset(page_virt + offset, 0, len);

	kunmap_atomic(page_virt, KM_USER0);
750
	kvm_release_page(page);
751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_clear_guest_page);

int kvm_clear_guest(struct kvm *kvm, gpa_t gpa, unsigned long len)
{
	gfn_t gfn = gpa >> PAGE_SHIFT;
	int seg;
	int offset = offset_in_page(gpa);
	int ret;

        while ((seg = next_segment(len, offset)) != 0) {
		ret = kvm_clear_guest_page(kvm, gfn, offset, seg);
		if (ret < 0)
			return ret;
		offset = 0;
		len -= seg;
		++gfn;
	}
	return 0;
}
EXPORT_SYMBOL_GPL(kvm_clear_guest);

A
Avi Kivity 已提交
774 775
void mark_page_dirty(struct kvm *kvm, gfn_t gfn)
{
776
	struct kvm_memory_slot *memslot;
A
Avi Kivity 已提交
777

778
	gfn = unalias_gfn(kvm, gfn);
R
Rusty Russell 已提交
779 780 781
	memslot = __gfn_to_memslot(kvm, gfn);
	if (memslot && memslot->dirty_bitmap) {
		unsigned long rel_gfn = gfn - memslot->base_gfn;
A
Avi Kivity 已提交
782

R
Rusty Russell 已提交
783 784 785
		/* avoid RMW */
		if (!test_bit(rel_gfn, memslot->dirty_bitmap))
			set_bit(rel_gfn, memslot->dirty_bitmap);
A
Avi Kivity 已提交
786 787 788
	}
}

E
Eddie Dong 已提交
789 790 791
/*
 * The vCPU has executed a HLT instruction with in-kernel mode enabled.
 */
792
void kvm_vcpu_block(struct kvm_vcpu *vcpu)
793
{
E
Eddie Dong 已提交
794 795 796 797 798 799 800
	DECLARE_WAITQUEUE(wait, current);

	add_wait_queue(&vcpu->wq, &wait);

	/*
	 * We will block until either an interrupt or a signal wakes us up
	 */
801 802 803 804
	while (!kvm_cpu_has_interrupt(vcpu)
	       && !signal_pending(current)
	       && vcpu->mp_state != VCPU_MP_STATE_RUNNABLE
	       && vcpu->mp_state != VCPU_MP_STATE_SIPI_RECEIVED) {
E
Eddie Dong 已提交
805 806 807 808 809
		set_current_state(TASK_INTERRUPTIBLE);
		vcpu_put(vcpu);
		schedule();
		vcpu_load(vcpu);
	}
810

811
	__set_current_state(TASK_RUNNING);
E
Eddie Dong 已提交
812 813 814
	remove_wait_queue(&vcpu->wq, &wait);
}

A
Avi Kivity 已提交
815 816
void kvm_resched(struct kvm_vcpu *vcpu)
{
817 818
	if (!need_resched())
		return;
A
Avi Kivity 已提交
819 820 821 822
	cond_resched();
}
EXPORT_SYMBOL_GPL(kvm_resched);

823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856
/*
 * Check if userspace requested an interrupt window, and that the
 * interrupt window is open.
 *
 * No need to exit to userspace if we already have an interrupt queued.
 */
static int dm_request_for_irq_injection(struct kvm_vcpu *vcpu,
					  struct kvm_run *kvm_run)
{
	return (!vcpu->irq_summary &&
		kvm_run->request_interrupt_window &&
		vcpu->interrupt_window_open &&
		(kvm_x86_ops->get_rflags(vcpu) & X86_EFLAGS_IF));
}

static void post_kvm_run_save(struct kvm_vcpu *vcpu,
			      struct kvm_run *kvm_run)
{
	kvm_run->if_flag = (kvm_x86_ops->get_rflags(vcpu) & X86_EFLAGS_IF) != 0;
	kvm_run->cr8 = get_cr8(vcpu);
	kvm_run->apic_base = kvm_get_apic_base(vcpu);
	if (irqchip_in_kernel(vcpu->kvm))
		kvm_run->ready_for_interrupt_injection = 1;
	else
		kvm_run->ready_for_interrupt_injection =
					(vcpu->interrupt_window_open &&
					 vcpu->irq_summary == 0);
}

static int __vcpu_run(struct kvm_vcpu *vcpu, struct kvm_run *kvm_run)
{
	int r;

	if (unlikely(vcpu->mp_state == VCPU_MP_STATE_SIPI_RECEIVED)) {
M
Mike Day 已提交
857
		pr_debug("vcpu %d received sipi with vector # %x\n",
858 859
		       vcpu->vcpu_id, vcpu->sipi_vector);
		kvm_lapic_reset(vcpu);
860 861 862
		r = kvm_x86_ops->vcpu_reset(vcpu);
		if (r)
			return r;
863 864 865 866 867 868 869 870 871 872 873 874
		vcpu->mp_state = VCPU_MP_STATE_RUNNABLE;
	}

preempted:
	if (vcpu->guest_debug.enabled)
		kvm_x86_ops->guest_debug_pre(vcpu);

again:
	r = kvm_mmu_reload(vcpu);
	if (unlikely(r))
		goto out;

875 876
	kvm_inject_pending_timer_irqs(vcpu);

877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898
	preempt_disable();

	kvm_x86_ops->prepare_guest_switch(vcpu);
	kvm_load_guest_fpu(vcpu);

	local_irq_disable();

	if (signal_pending(current)) {
		local_irq_enable();
		preempt_enable();
		r = -EINTR;
		kvm_run->exit_reason = KVM_EXIT_INTR;
		++vcpu->stat.signal_exits;
		goto out;
	}

	if (irqchip_in_kernel(vcpu->kvm))
		kvm_x86_ops->inject_pending_irq(vcpu);
	else if (!vcpu->mmio_read_completed)
		kvm_x86_ops->inject_pending_vectors(vcpu, kvm_run);

	vcpu->guest_mode = 1;
899
	kvm_guest_enter();
900 901

	if (vcpu->requests)
902
		if (test_and_clear_bit(KVM_REQ_TLB_FLUSH, &vcpu->requests))
903 904 905 906 907 908 909 910 911
			kvm_x86_ops->tlb_flush(vcpu);

	kvm_x86_ops->run(vcpu, kvm_run);

	vcpu->guest_mode = 0;
	local_irq_enable();

	++vcpu->stat.exits;

912 913 914 915 916 917 918 919 920 921
	/*
	 * We must have an instruction between local_irq_enable() and
	 * kvm_guest_exit(), so the timer interrupt isn't delayed by
	 * the interrupt shadow.  The stat.exits increment will do nicely.
	 * But we need to prevent reordering, hence this barrier():
	 */
	barrier();

	kvm_guest_exit();

922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958
	preempt_enable();

	/*
	 * Profile KVM exit RIPs:
	 */
	if (unlikely(prof_on == KVM_PROFILING)) {
		kvm_x86_ops->cache_regs(vcpu);
		profile_hit(KVM_PROFILING, (void *)vcpu->rip);
	}

	r = kvm_x86_ops->handle_exit(kvm_run, vcpu);

	if (r > 0) {
		if (dm_request_for_irq_injection(vcpu, kvm_run)) {
			r = -EINTR;
			kvm_run->exit_reason = KVM_EXIT_INTR;
			++vcpu->stat.request_irq_exits;
			goto out;
		}
		if (!need_resched()) {
			++vcpu->stat.light_exits;
			goto again;
		}
	}

out:
	if (r > 0) {
		kvm_resched(vcpu);
		goto preempted;
	}

	post_kvm_run_save(vcpu, kvm_run);

	return r;
}


A
Avi Kivity 已提交
959
static int kvm_vcpu_ioctl_run(struct kvm_vcpu *vcpu, struct kvm_run *kvm_run)
A
Avi Kivity 已提交
960 961
{
	int r;
A
Avi Kivity 已提交
962
	sigset_t sigsaved;
A
Avi Kivity 已提交
963

A
Avi Kivity 已提交
964
	vcpu_load(vcpu);
A
Avi Kivity 已提交
965

966 967 968 969 970 971
	if (unlikely(vcpu->mp_state == VCPU_MP_STATE_UNINITIALIZED)) {
		kvm_vcpu_block(vcpu);
		vcpu_put(vcpu);
		return -EAGAIN;
	}

A
Avi Kivity 已提交
972 973 974
	if (vcpu->sigset_active)
		sigprocmask(SIG_SETMASK, &vcpu->sigset, &sigsaved);

975
	/* re-sync apic's tpr */
976 977
	if (!irqchip_in_kernel(vcpu->kvm))
		set_cr8(vcpu, kvm_run->cr8);
978

979 980 981 982 983
	if (vcpu->pio.cur_count) {
		r = complete_pio(vcpu);
		if (r)
			goto out;
	}
984
#if CONFIG_HAS_IOMEM
985 986 987 988 989
	if (vcpu->mmio_needed) {
		memcpy(vcpu->mmio_data, kvm_run->mmio.data, 8);
		vcpu->mmio_read_completed = 1;
		vcpu->mmio_needed = 0;
		r = emulate_instruction(vcpu, kvm_run,
990
					vcpu->mmio_fault_cr2, 0, 1);
991 992 993 994 995 996
		if (r == EMULATE_DO_MMIO) {
			/*
			 * Read-modify-write.  Back to userspace.
			 */
			r = 0;
			goto out;
997
		}
A
Avi Kivity 已提交
998
	}
999
#endif
1000
	if (kvm_run->exit_reason == KVM_EXIT_HYPERCALL) {
1001
		kvm_x86_ops->cache_regs(vcpu);
1002
		vcpu->regs[VCPU_REGS_RAX] = kvm_run->hypercall.ret;
1003
		kvm_x86_ops->decache_regs(vcpu);
1004 1005
	}

1006
	r = __vcpu_run(vcpu, kvm_run);
A
Avi Kivity 已提交
1007

1008
out:
A
Avi Kivity 已提交
1009 1010 1011
	if (vcpu->sigset_active)
		sigprocmask(SIG_SETMASK, &sigsaved, NULL);

A
Avi Kivity 已提交
1012 1013 1014 1015
	vcpu_put(vcpu);
	return r;
}

A
Avi Kivity 已提交
1016 1017
static int kvm_vcpu_ioctl_get_regs(struct kvm_vcpu *vcpu,
				   struct kvm_regs *regs)
A
Avi Kivity 已提交
1018
{
A
Avi Kivity 已提交
1019
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1020

1021
	kvm_x86_ops->cache_regs(vcpu);
A
Avi Kivity 已提交
1022 1023 1024 1025 1026 1027 1028 1029 1030

	regs->rax = vcpu->regs[VCPU_REGS_RAX];
	regs->rbx = vcpu->regs[VCPU_REGS_RBX];
	regs->rcx = vcpu->regs[VCPU_REGS_RCX];
	regs->rdx = vcpu->regs[VCPU_REGS_RDX];
	regs->rsi = vcpu->regs[VCPU_REGS_RSI];
	regs->rdi = vcpu->regs[VCPU_REGS_RDI];
	regs->rsp = vcpu->regs[VCPU_REGS_RSP];
	regs->rbp = vcpu->regs[VCPU_REGS_RBP];
1031
#ifdef CONFIG_X86_64
A
Avi Kivity 已提交
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042
	regs->r8 = vcpu->regs[VCPU_REGS_R8];
	regs->r9 = vcpu->regs[VCPU_REGS_R9];
	regs->r10 = vcpu->regs[VCPU_REGS_R10];
	regs->r11 = vcpu->regs[VCPU_REGS_R11];
	regs->r12 = vcpu->regs[VCPU_REGS_R12];
	regs->r13 = vcpu->regs[VCPU_REGS_R13];
	regs->r14 = vcpu->regs[VCPU_REGS_R14];
	regs->r15 = vcpu->regs[VCPU_REGS_R15];
#endif

	regs->rip = vcpu->rip;
1043
	regs->rflags = kvm_x86_ops->get_rflags(vcpu);
A
Avi Kivity 已提交
1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055

	/*
	 * Don't leak debug flags in case they were set for guest debugging
	 */
	if (vcpu->guest_debug.enabled && vcpu->guest_debug.singlestep)
		regs->rflags &= ~(X86_EFLAGS_TF | X86_EFLAGS_RF);

	vcpu_put(vcpu);

	return 0;
}

A
Avi Kivity 已提交
1056 1057
static int kvm_vcpu_ioctl_set_regs(struct kvm_vcpu *vcpu,
				   struct kvm_regs *regs)
A
Avi Kivity 已提交
1058
{
A
Avi Kivity 已提交
1059
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1060 1061 1062 1063 1064 1065 1066 1067 1068

	vcpu->regs[VCPU_REGS_RAX] = regs->rax;
	vcpu->regs[VCPU_REGS_RBX] = regs->rbx;
	vcpu->regs[VCPU_REGS_RCX] = regs->rcx;
	vcpu->regs[VCPU_REGS_RDX] = regs->rdx;
	vcpu->regs[VCPU_REGS_RSI] = regs->rsi;
	vcpu->regs[VCPU_REGS_RDI] = regs->rdi;
	vcpu->regs[VCPU_REGS_RSP] = regs->rsp;
	vcpu->regs[VCPU_REGS_RBP] = regs->rbp;
1069
#ifdef CONFIG_X86_64
A
Avi Kivity 已提交
1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080
	vcpu->regs[VCPU_REGS_R8] = regs->r8;
	vcpu->regs[VCPU_REGS_R9] = regs->r9;
	vcpu->regs[VCPU_REGS_R10] = regs->r10;
	vcpu->regs[VCPU_REGS_R11] = regs->r11;
	vcpu->regs[VCPU_REGS_R12] = regs->r12;
	vcpu->regs[VCPU_REGS_R13] = regs->r13;
	vcpu->regs[VCPU_REGS_R14] = regs->r14;
	vcpu->regs[VCPU_REGS_R15] = regs->r15;
#endif

	vcpu->rip = regs->rip;
1081
	kvm_x86_ops->set_rflags(vcpu, regs->rflags);
A
Avi Kivity 已提交
1082

1083
	kvm_x86_ops->decache_regs(vcpu);
A
Avi Kivity 已提交
1084 1085 1086 1087 1088 1089 1090 1091 1092

	vcpu_put(vcpu);

	return 0;
}

static void get_segment(struct kvm_vcpu *vcpu,
			struct kvm_segment *var, int seg)
{
1093
	return kvm_x86_ops->get_segment(vcpu, var, seg);
A
Avi Kivity 已提交
1094 1095
}

A
Avi Kivity 已提交
1096 1097
static int kvm_vcpu_ioctl_get_sregs(struct kvm_vcpu *vcpu,
				    struct kvm_sregs *sregs)
A
Avi Kivity 已提交
1098 1099
{
	struct descriptor_table dt;
E
Eddie Dong 已提交
1100
	int pending_vec;
A
Avi Kivity 已提交
1101

A
Avi Kivity 已提交
1102
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113

	get_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
	get_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
	get_segment(vcpu, &sregs->es, VCPU_SREG_ES);
	get_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
	get_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
	get_segment(vcpu, &sregs->ss, VCPU_SREG_SS);

	get_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
	get_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);

1114
	kvm_x86_ops->get_idt(vcpu, &dt);
A
Avi Kivity 已提交
1115 1116
	sregs->idt.limit = dt.limit;
	sregs->idt.base = dt.base;
1117
	kvm_x86_ops->get_gdt(vcpu, &dt);
A
Avi Kivity 已提交
1118 1119 1120
	sregs->gdt.limit = dt.limit;
	sregs->gdt.base = dt.base;

1121
	kvm_x86_ops->decache_cr4_guest_bits(vcpu);
A
Avi Kivity 已提交
1122 1123 1124 1125
	sregs->cr0 = vcpu->cr0;
	sregs->cr2 = vcpu->cr2;
	sregs->cr3 = vcpu->cr3;
	sregs->cr4 = vcpu->cr4;
1126
	sregs->cr8 = get_cr8(vcpu);
A
Avi Kivity 已提交
1127
	sregs->efer = vcpu->shadow_efer;
1128
	sregs->apic_base = kvm_get_apic_base(vcpu);
A
Avi Kivity 已提交
1129

E
Eddie Dong 已提交
1130
	if (irqchip_in_kernel(vcpu->kvm)) {
1131 1132
		memset(sregs->interrupt_bitmap, 0,
		       sizeof sregs->interrupt_bitmap);
1133
		pending_vec = kvm_x86_ops->get_irq(vcpu);
E
Eddie Dong 已提交
1134
		if (pending_vec >= 0)
M
Mike Day 已提交
1135 1136
			set_bit(pending_vec,
				(unsigned long *)sregs->interrupt_bitmap);
E
Eddie Dong 已提交
1137
	} else
1138 1139
		memcpy(sregs->interrupt_bitmap, vcpu->irq_pending,
		       sizeof sregs->interrupt_bitmap);
A
Avi Kivity 已提交
1140 1141 1142 1143 1144 1145 1146 1147 1148

	vcpu_put(vcpu);

	return 0;
}

static void set_segment(struct kvm_vcpu *vcpu,
			struct kvm_segment *var, int seg)
{
1149
	return kvm_x86_ops->set_segment(vcpu, var, seg);
A
Avi Kivity 已提交
1150 1151
}

A
Avi Kivity 已提交
1152 1153
static int kvm_vcpu_ioctl_set_sregs(struct kvm_vcpu *vcpu,
				    struct kvm_sregs *sregs)
A
Avi Kivity 已提交
1154 1155
{
	int mmu_reset_needed = 0;
E
Eddie Dong 已提交
1156
	int i, pending_vec, max_bits;
A
Avi Kivity 已提交
1157 1158
	struct descriptor_table dt;

A
Avi Kivity 已提交
1159
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1160 1161 1162

	dt.limit = sregs->idt.limit;
	dt.base = sregs->idt.base;
1163
	kvm_x86_ops->set_idt(vcpu, &dt);
A
Avi Kivity 已提交
1164 1165
	dt.limit = sregs->gdt.limit;
	dt.base = sregs->gdt.base;
1166
	kvm_x86_ops->set_gdt(vcpu, &dt);
A
Avi Kivity 已提交
1167 1168 1169 1170 1171

	vcpu->cr2 = sregs->cr2;
	mmu_reset_needed |= vcpu->cr3 != sregs->cr3;
	vcpu->cr3 = sregs->cr3;

1172
	set_cr8(vcpu, sregs->cr8);
A
Avi Kivity 已提交
1173 1174

	mmu_reset_needed |= vcpu->shadow_efer != sregs->efer;
1175
#ifdef CONFIG_X86_64
1176
	kvm_x86_ops->set_efer(vcpu, sregs->efer);
A
Avi Kivity 已提交
1177
#endif
1178
	kvm_set_apic_base(vcpu, sregs->apic_base);
A
Avi Kivity 已提交
1179

1180
	kvm_x86_ops->decache_cr4_guest_bits(vcpu);
1181

A
Avi Kivity 已提交
1182
	mmu_reset_needed |= vcpu->cr0 != sregs->cr0;
R
Rusty Russell 已提交
1183
	vcpu->cr0 = sregs->cr0;
1184
	kvm_x86_ops->set_cr0(vcpu, sregs->cr0);
A
Avi Kivity 已提交
1185 1186

	mmu_reset_needed |= vcpu->cr4 != sregs->cr4;
1187
	kvm_x86_ops->set_cr4(vcpu, sregs->cr4);
1188 1189
	if (!is_long_mode(vcpu) && is_pae(vcpu))
		load_pdptrs(vcpu, vcpu->cr3);
A
Avi Kivity 已提交
1190 1191 1192 1193

	if (mmu_reset_needed)
		kvm_mmu_reset_context(vcpu);

1194 1195 1196 1197 1198 1199 1200
	if (!irqchip_in_kernel(vcpu->kvm)) {
		memcpy(vcpu->irq_pending, sregs->interrupt_bitmap,
		       sizeof vcpu->irq_pending);
		vcpu->irq_summary = 0;
		for (i = 0; i < ARRAY_SIZE(vcpu->irq_pending); ++i)
			if (vcpu->irq_pending[i])
				__set_bit(i, &vcpu->irq_summary);
E
Eddie Dong 已提交
1201 1202 1203 1204 1205 1206 1207
	} else {
		max_bits = (sizeof sregs->interrupt_bitmap) << 3;
		pending_vec = find_first_bit(
			(const unsigned long *)sregs->interrupt_bitmap,
			max_bits);
		/* Only pending external irq is handled here */
		if (pending_vec < max_bits) {
1208
			kvm_x86_ops->set_irq(vcpu, pending_vec);
M
Mike Day 已提交
1209 1210
			pr_debug("Set back pending irq %d\n",
				 pending_vec);
E
Eddie Dong 已提交
1211
		}
1212
	}
A
Avi Kivity 已提交
1213

1214 1215 1216 1217 1218 1219 1220 1221 1222 1223
	set_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
	set_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
	set_segment(vcpu, &sregs->es, VCPU_SREG_ES);
	set_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
	set_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
	set_segment(vcpu, &sregs->ss, VCPU_SREG_SS);

	set_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
	set_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);

A
Avi Kivity 已提交
1224 1225 1226 1227 1228
	vcpu_put(vcpu);

	return 0;
}

1229 1230 1231 1232 1233 1234 1235 1236 1237 1238
void kvm_get_cs_db_l_bits(struct kvm_vcpu *vcpu, int *db, int *l)
{
	struct kvm_segment cs;

	get_segment(vcpu, &cs, VCPU_SREG_CS);
	*db = cs.db;
	*l = cs.l;
}
EXPORT_SYMBOL_GPL(kvm_get_cs_db_l_bits);

A
Avi Kivity 已提交
1239 1240 1241
/*
 * Translate a guest virtual address to a guest physical address.
 */
A
Avi Kivity 已提交
1242 1243
static int kvm_vcpu_ioctl_translate(struct kvm_vcpu *vcpu,
				    struct kvm_translation *tr)
A
Avi Kivity 已提交
1244 1245 1246 1247
{
	unsigned long vaddr = tr->linear_address;
	gpa_t gpa;

A
Avi Kivity 已提交
1248
	vcpu_load(vcpu);
S
Shaohua Li 已提交
1249
	mutex_lock(&vcpu->kvm->lock);
A
Avi Kivity 已提交
1250 1251 1252 1253 1254
	gpa = vcpu->mmu.gva_to_gpa(vcpu, vaddr);
	tr->physical_address = gpa;
	tr->valid = gpa != UNMAPPED_GVA;
	tr->writeable = 1;
	tr->usermode = 0;
S
Shaohua Li 已提交
1255
	mutex_unlock(&vcpu->kvm->lock);
A
Avi Kivity 已提交
1256 1257 1258 1259 1260
	vcpu_put(vcpu);

	return 0;
}

A
Avi Kivity 已提交
1261 1262
static int kvm_vcpu_ioctl_interrupt(struct kvm_vcpu *vcpu,
				    struct kvm_interrupt *irq)
A
Avi Kivity 已提交
1263 1264 1265
{
	if (irq->irq < 0 || irq->irq >= 256)
		return -EINVAL;
E
Eddie Dong 已提交
1266 1267
	if (irqchip_in_kernel(vcpu->kvm))
		return -ENXIO;
A
Avi Kivity 已提交
1268
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1269 1270 1271 1272 1273 1274 1275 1276 1277

	set_bit(irq->irq, vcpu->irq_pending);
	set_bit(irq->irq / BITS_PER_LONG, &vcpu->irq_summary);

	vcpu_put(vcpu);

	return 0;
}

A
Avi Kivity 已提交
1278 1279
static int kvm_vcpu_ioctl_debug_guest(struct kvm_vcpu *vcpu,
				      struct kvm_debug_guest *dbg)
A
Avi Kivity 已提交
1280 1281 1282
{
	int r;

A
Avi Kivity 已提交
1283
	vcpu_load(vcpu);
A
Avi Kivity 已提交
1284

1285
	r = kvm_x86_ops->set_guest_debug(vcpu, dbg);
A
Avi Kivity 已提交
1286 1287 1288 1289 1290 1291

	vcpu_put(vcpu);

	return r;
}

1292 1293 1294 1295 1296 1297 1298 1299 1300
static struct page *kvm_vcpu_nopage(struct vm_area_struct *vma,
				    unsigned long address,
				    int *type)
{
	struct kvm_vcpu *vcpu = vma->vm_file->private_data;
	unsigned long pgoff;
	struct page *page;

	pgoff = ((address - vma->vm_start) >> PAGE_SHIFT) + vma->vm_pgoff;
1301 1302 1303 1304 1305
	if (pgoff == 0)
		page = virt_to_page(vcpu->run);
	else if (pgoff == KVM_PIO_PAGE_OFFSET)
		page = virt_to_page(vcpu->pio_data);
	else
1306 1307
		return NOPAGE_SIGBUS;
	get_page(page);
1308 1309 1310
	if (type != NULL)
		*type = VM_FAULT_MINOR;

1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323
	return page;
}

static struct vm_operations_struct kvm_vcpu_vm_ops = {
	.nopage = kvm_vcpu_nopage,
};

static int kvm_vcpu_mmap(struct file *file, struct vm_area_struct *vma)
{
	vma->vm_ops = &kvm_vcpu_vm_ops;
	return 0;
}

A
Avi Kivity 已提交
1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335
static int kvm_vcpu_release(struct inode *inode, struct file *filp)
{
	struct kvm_vcpu *vcpu = filp->private_data;

	fput(vcpu->kvm->filp);
	return 0;
}

static struct file_operations kvm_vcpu_fops = {
	.release        = kvm_vcpu_release,
	.unlocked_ioctl = kvm_vcpu_ioctl,
	.compat_ioctl   = kvm_vcpu_ioctl,
1336
	.mmap           = kvm_vcpu_mmap,
A
Avi Kivity 已提交
1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347
};

/*
 * Allocates an inode for the vcpu.
 */
static int create_vcpu_fd(struct kvm_vcpu *vcpu)
{
	int fd, r;
	struct inode *inode;
	struct file *file;

1348 1349 1350 1351
	r = anon_inode_getfd(&fd, &inode, &file,
			     "kvm-vcpu", &kvm_vcpu_fops, vcpu);
	if (r)
		return r;
A
Avi Kivity 已提交
1352 1353 1354 1355
	atomic_inc(&vcpu->kvm->filp->f_count);
	return fd;
}

1356 1357 1358 1359 1360 1361 1362 1363 1364
/*
 * Creates some virtual cpus.  Good luck creating more than one.
 */
static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, int n)
{
	int r;
	struct kvm_vcpu *vcpu;

	if (!valid_vcpu(n))
R
Rusty Russell 已提交
1365
		return -EINVAL;
1366

1367
	vcpu = kvm_x86_ops->vcpu_create(kvm, n);
R
Rusty Russell 已提交
1368 1369
	if (IS_ERR(vcpu))
		return PTR_ERR(vcpu);
1370

1371 1372
	preempt_notifier_init(&vcpu->preempt_notifier, &kvm_preempt_ops);

1373 1374 1375
	/* We do fxsave: this must be aligned. */
	BUG_ON((unsigned long)&vcpu->host_fx_image & 0xF);

R
Rusty Russell 已提交
1376
	vcpu_load(vcpu);
1377 1378 1379
	r = kvm_x86_ops->vcpu_reset(vcpu);
	if (r == 0)
		r = kvm_mmu_setup(vcpu);
1380 1381
	vcpu_put(vcpu);
	if (r < 0)
R
Rusty Russell 已提交
1382 1383
		goto free_vcpu;

S
Shaohua Li 已提交
1384
	mutex_lock(&kvm->lock);
R
Rusty Russell 已提交
1385 1386
	if (kvm->vcpus[n]) {
		r = -EEXIST;
S
Shaohua Li 已提交
1387
		mutex_unlock(&kvm->lock);
R
Rusty Russell 已提交
1388 1389 1390
		goto mmu_unload;
	}
	kvm->vcpus[n] = vcpu;
S
Shaohua Li 已提交
1391
	mutex_unlock(&kvm->lock);
1392

R
Rusty Russell 已提交
1393
	/* Now it's all set up, let userspace reach it */
A
Avi Kivity 已提交
1394 1395
	r = create_vcpu_fd(vcpu);
	if (r < 0)
R
Rusty Russell 已提交
1396 1397
		goto unlink;
	return r;
1398

R
Rusty Russell 已提交
1399
unlink:
S
Shaohua Li 已提交
1400
	mutex_lock(&kvm->lock);
R
Rusty Russell 已提交
1401
	kvm->vcpus[n] = NULL;
S
Shaohua Li 已提交
1402
	mutex_unlock(&kvm->lock);
1403

R
Rusty Russell 已提交
1404 1405 1406 1407
mmu_unload:
	vcpu_load(vcpu);
	kvm_mmu_unload(vcpu);
	vcpu_put(vcpu);
1408

R
Rusty Russell 已提交
1409
free_vcpu:
1410
	kvm_x86_ops->vcpu_free(vcpu);
1411 1412 1413
	return r;
}

A
Avi Kivity 已提交
1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424
static int kvm_vcpu_ioctl_set_sigmask(struct kvm_vcpu *vcpu, sigset_t *sigset)
{
	if (sigset) {
		sigdelsetmask(sigset, sigmask(SIGKILL)|sigmask(SIGSTOP));
		vcpu->sigset_active = 1;
		vcpu->sigset = *sigset;
	} else
		vcpu->sigset_active = 0;
	return 0;
}

A
Avi Kivity 已提交
1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447
/*
 * fxsave fpu state.  Taken from x86_64/processor.h.  To be killed when
 * we have asm/x86/processor.h
 */
struct fxsave {
	u16	cwd;
	u16	swd;
	u16	twd;
	u16	fop;
	u64	rip;
	u64	rdp;
	u32	mxcsr;
	u32	mxcsr_mask;
	u32	st_space[32];	/* 8*16 bytes for each FP-reg = 128 bytes */
#ifdef CONFIG_X86_64
	u32	xmm_space[64];	/* 16*16 bytes for each XMM-reg = 256 bytes */
#else
	u32	xmm_space[32];	/* 8*16 bytes for each XMM-reg = 128 bytes */
#endif
};

static int kvm_vcpu_ioctl_get_fpu(struct kvm_vcpu *vcpu, struct kvm_fpu *fpu)
{
1448
	struct fxsave *fxsave = (struct fxsave *)&vcpu->guest_fx_image;
A
Avi Kivity 已提交
1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467

	vcpu_load(vcpu);

	memcpy(fpu->fpr, fxsave->st_space, 128);
	fpu->fcw = fxsave->cwd;
	fpu->fsw = fxsave->swd;
	fpu->ftwx = fxsave->twd;
	fpu->last_opcode = fxsave->fop;
	fpu->last_ip = fxsave->rip;
	fpu->last_dp = fxsave->rdp;
	memcpy(fpu->xmm, fxsave->xmm_space, sizeof fxsave->xmm_space);

	vcpu_put(vcpu);

	return 0;
}

static int kvm_vcpu_ioctl_set_fpu(struct kvm_vcpu *vcpu, struct kvm_fpu *fpu)
{
1468
	struct fxsave *fxsave = (struct fxsave *)&vcpu->guest_fx_image;
A
Avi Kivity 已提交
1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485

	vcpu_load(vcpu);

	memcpy(fxsave->st_space, fpu->fpr, 128);
	fxsave->cwd = fpu->fcw;
	fxsave->swd = fpu->fsw;
	fxsave->twd = fpu->ftwx;
	fxsave->fop = fpu->last_opcode;
	fxsave->rip = fpu->last_ip;
	fxsave->rdp = fpu->last_dp;
	memcpy(fxsave->xmm_space, fpu->xmm, sizeof fxsave->xmm_space);

	vcpu_put(vcpu);

	return 0;
}

A
Avi Kivity 已提交
1486 1487
static long kvm_vcpu_ioctl(struct file *filp,
			   unsigned int ioctl, unsigned long arg)
A
Avi Kivity 已提交
1488
{
A
Avi Kivity 已提交
1489
	struct kvm_vcpu *vcpu = filp->private_data;
A
Al Viro 已提交
1490
	void __user *argp = (void __user *)arg;
1491
	int r;
A
Avi Kivity 已提交
1492 1493

	switch (ioctl) {
1494
	case KVM_RUN:
1495 1496 1497
		r = -EINVAL;
		if (arg)
			goto out;
1498
		r = kvm_vcpu_ioctl_run(vcpu, vcpu->run);
A
Avi Kivity 已提交
1499 1500 1501 1502
		break;
	case KVM_GET_REGS: {
		struct kvm_regs kvm_regs;

A
Avi Kivity 已提交
1503 1504
		memset(&kvm_regs, 0, sizeof kvm_regs);
		r = kvm_vcpu_ioctl_get_regs(vcpu, &kvm_regs);
A
Avi Kivity 已提交
1505 1506 1507
		if (r)
			goto out;
		r = -EFAULT;
A
Al Viro 已提交
1508
		if (copy_to_user(argp, &kvm_regs, sizeof kvm_regs))
A
Avi Kivity 已提交
1509 1510 1511 1512 1513 1514 1515 1516
			goto out;
		r = 0;
		break;
	}
	case KVM_SET_REGS: {
		struct kvm_regs kvm_regs;

		r = -EFAULT;
A
Al Viro 已提交
1517
		if (copy_from_user(&kvm_regs, argp, sizeof kvm_regs))
A
Avi Kivity 已提交
1518
			goto out;
A
Avi Kivity 已提交
1519
		r = kvm_vcpu_ioctl_set_regs(vcpu, &kvm_regs);
A
Avi Kivity 已提交
1520 1521 1522 1523 1524 1525 1526 1527
		if (r)
			goto out;
		r = 0;
		break;
	}
	case KVM_GET_SREGS: {
		struct kvm_sregs kvm_sregs;

A
Avi Kivity 已提交
1528 1529
		memset(&kvm_sregs, 0, sizeof kvm_sregs);
		r = kvm_vcpu_ioctl_get_sregs(vcpu, &kvm_sregs);
A
Avi Kivity 已提交
1530 1531 1532
		if (r)
			goto out;
		r = -EFAULT;
A
Al Viro 已提交
1533
		if (copy_to_user(argp, &kvm_sregs, sizeof kvm_sregs))
A
Avi Kivity 已提交
1534 1535 1536 1537 1538 1539 1540 1541
			goto out;
		r = 0;
		break;
	}
	case KVM_SET_SREGS: {
		struct kvm_sregs kvm_sregs;

		r = -EFAULT;
A
Al Viro 已提交
1542
		if (copy_from_user(&kvm_sregs, argp, sizeof kvm_sregs))
A
Avi Kivity 已提交
1543
			goto out;
A
Avi Kivity 已提交
1544
		r = kvm_vcpu_ioctl_set_sregs(vcpu, &kvm_sregs);
A
Avi Kivity 已提交
1545 1546 1547 1548 1549 1550 1551 1552 1553
		if (r)
			goto out;
		r = 0;
		break;
	}
	case KVM_TRANSLATE: {
		struct kvm_translation tr;

		r = -EFAULT;
A
Al Viro 已提交
1554
		if (copy_from_user(&tr, argp, sizeof tr))
A
Avi Kivity 已提交
1555
			goto out;
A
Avi Kivity 已提交
1556
		r = kvm_vcpu_ioctl_translate(vcpu, &tr);
A
Avi Kivity 已提交
1557 1558 1559
		if (r)
			goto out;
		r = -EFAULT;
A
Al Viro 已提交
1560
		if (copy_to_user(argp, &tr, sizeof tr))
A
Avi Kivity 已提交
1561 1562 1563 1564 1565 1566 1567 1568
			goto out;
		r = 0;
		break;
	}
	case KVM_INTERRUPT: {
		struct kvm_interrupt irq;

		r = -EFAULT;
A
Al Viro 已提交
1569
		if (copy_from_user(&irq, argp, sizeof irq))
A
Avi Kivity 已提交
1570
			goto out;
A
Avi Kivity 已提交
1571
		r = kvm_vcpu_ioctl_interrupt(vcpu, &irq);
A
Avi Kivity 已提交
1572 1573 1574 1575 1576 1577 1578 1579 1580
		if (r)
			goto out;
		r = 0;
		break;
	}
	case KVM_DEBUG_GUEST: {
		struct kvm_debug_guest dbg;

		r = -EFAULT;
A
Al Viro 已提交
1581
		if (copy_from_user(&dbg, argp, sizeof dbg))
A
Avi Kivity 已提交
1582
			goto out;
A
Avi Kivity 已提交
1583
		r = kvm_vcpu_ioctl_debug_guest(vcpu, &dbg);
A
Avi Kivity 已提交
1584 1585 1586 1587 1588
		if (r)
			goto out;
		r = 0;
		break;
	}
A
Avi Kivity 已提交
1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611
	case KVM_SET_SIGNAL_MASK: {
		struct kvm_signal_mask __user *sigmask_arg = argp;
		struct kvm_signal_mask kvm_sigmask;
		sigset_t sigset, *p;

		p = NULL;
		if (argp) {
			r = -EFAULT;
			if (copy_from_user(&kvm_sigmask, argp,
					   sizeof kvm_sigmask))
				goto out;
			r = -EINVAL;
			if (kvm_sigmask.len != sizeof sigset)
				goto out;
			r = -EFAULT;
			if (copy_from_user(&sigset, sigmask_arg->sigset,
					   sizeof sigset))
				goto out;
			p = &sigset;
		}
		r = kvm_vcpu_ioctl_set_sigmask(vcpu, &sigset);
		break;
	}
A
Avi Kivity 已提交
1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635 1636
	case KVM_GET_FPU: {
		struct kvm_fpu fpu;

		memset(&fpu, 0, sizeof fpu);
		r = kvm_vcpu_ioctl_get_fpu(vcpu, &fpu);
		if (r)
			goto out;
		r = -EFAULT;
		if (copy_to_user(argp, &fpu, sizeof fpu))
			goto out;
		r = 0;
		break;
	}
	case KVM_SET_FPU: {
		struct kvm_fpu fpu;

		r = -EFAULT;
		if (copy_from_user(&fpu, argp, sizeof fpu))
			goto out;
		r = kvm_vcpu_ioctl_set_fpu(vcpu, &fpu);
		if (r)
			goto out;
		r = 0;
		break;
	}
A
Avi Kivity 已提交
1637
	default:
1638
		r = kvm_arch_vcpu_ioctl(filp, ioctl, arg);
A
Avi Kivity 已提交
1639 1640 1641 1642 1643 1644 1645 1646 1647 1648
	}
out:
	return r;
}

static long kvm_vm_ioctl(struct file *filp,
			   unsigned int ioctl, unsigned long arg)
{
	struct kvm *kvm = filp->private_data;
	void __user *argp = (void __user *)arg;
1649
	int r;
A
Avi Kivity 已提交
1650 1651 1652 1653 1654 1655 1656

	switch (ioctl) {
	case KVM_CREATE_VCPU:
		r = kvm_vm_ioctl_create_vcpu(kvm, arg);
		if (r < 0)
			goto out;
		break;
1657 1658 1659 1660 1661 1662 1663 1664 1665
	case KVM_SET_USER_MEMORY_REGION: {
		struct kvm_userspace_memory_region kvm_userspace_mem;

		r = -EFAULT;
		if (copy_from_user(&kvm_userspace_mem, argp,
						sizeof kvm_userspace_mem))
			goto out;

		r = kvm_vm_ioctl_set_memory_region(kvm, &kvm_userspace_mem, 1);
A
Avi Kivity 已提交
1666 1667 1668 1669 1670 1671 1672 1673
		if (r)
			goto out;
		break;
	}
	case KVM_GET_DIRTY_LOG: {
		struct kvm_dirty_log log;

		r = -EFAULT;
A
Al Viro 已提交
1674
		if (copy_from_user(&log, argp, sizeof log))
A
Avi Kivity 已提交
1675
			goto out;
1676
		r = kvm_vm_ioctl_get_dirty_log(kvm, &log);
A
Avi Kivity 已提交
1677 1678 1679 1680
		if (r)
			goto out;
		break;
	}
1681
	default:
1682
		r = kvm_arch_vm_ioctl(filp, ioctl, arg);
1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696
	}
out:
	return r;
}

static struct page *kvm_vm_nopage(struct vm_area_struct *vma,
				  unsigned long address,
				  int *type)
{
	struct kvm *kvm = vma->vm_file->private_data;
	unsigned long pgoff;
	struct page *page;

	pgoff = ((address - vma->vm_start) >> PAGE_SHIFT) + vma->vm_pgoff;
1697 1698
	if (!kvm_is_visible_gfn(kvm, pgoff))
		return NOPAGE_SIGBUS;
1699 1700
	/* current->mm->mmap_sem is already held so call lockless version */
	page = __gfn_to_page(kvm, pgoff);
1701 1702
	if (is_error_page(page)) {
		kvm_release_page(page);
1703
		return NOPAGE_SIGBUS;
1704
	}
1705 1706 1707
	if (type != NULL)
		*type = VM_FAULT_MINOR;

1708 1709 1710 1711 1712 1713 1714 1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734 1735
	return page;
}

static struct vm_operations_struct kvm_vm_vm_ops = {
	.nopage = kvm_vm_nopage,
};

static int kvm_vm_mmap(struct file *file, struct vm_area_struct *vma)
{
	vma->vm_ops = &kvm_vm_vm_ops;
	return 0;
}

static struct file_operations kvm_vm_fops = {
	.release        = kvm_vm_release,
	.unlocked_ioctl = kvm_vm_ioctl,
	.compat_ioctl   = kvm_vm_ioctl,
	.mmap           = kvm_vm_mmap,
};

static int kvm_dev_ioctl_create_vm(void)
{
	int fd, r;
	struct inode *inode;
	struct file *file;
	struct kvm *kvm;

	kvm = kvm_create_vm();
1736 1737 1738 1739 1740 1741
	if (IS_ERR(kvm))
		return PTR_ERR(kvm);
	r = anon_inode_getfd(&fd, &inode, &file, "kvm-vm", &kvm_vm_fops, kvm);
	if (r) {
		kvm_destroy_vm(kvm);
		return r;
1742 1743
	}

A
Avi Kivity 已提交
1744
	kvm->filp = file;
1745 1746 1747 1748 1749 1750 1751 1752

	return fd;
}

static long kvm_dev_ioctl(struct file *filp,
			  unsigned int ioctl, unsigned long arg)
{
	void __user *argp = (void __user *)arg;
1753
	long r = -EINVAL;
1754 1755 1756

	switch (ioctl) {
	case KVM_GET_API_VERSION:
1757 1758 1759
		r = -EINVAL;
		if (arg)
			goto out;
1760 1761 1762
		r = KVM_API_VERSION;
		break;
	case KVM_CREATE_VM:
1763 1764 1765
		r = -EINVAL;
		if (arg)
			goto out;
1766 1767
		r = kvm_dev_ioctl_create_vm();
		break;
1768 1769 1770 1771 1772
	case KVM_CHECK_EXTENSION: {
		int ext = (long)argp;

		switch (ext) {
		case KVM_CAP_IRQCHIP:
E
Eddie Dong 已提交
1773
		case KVM_CAP_HLT:
1774
		case KVM_CAP_MMU_SHADOW_CACHE_CONTROL:
1775
		case KVM_CAP_USER_MEMORY:
1776
		case KVM_CAP_SET_TSS_ADDR:
1777 1778 1779 1780 1781 1782
			r = 1;
			break;
		default:
			r = 0;
			break;
		}
1783
		break;
1784
	}
1785 1786 1787 1788
	case KVM_GET_VCPU_MMAP_SIZE:
		r = -EINVAL;
		if (arg)
			goto out;
1789
		r = 2 * PAGE_SIZE;
1790
		break;
A
Avi Kivity 已提交
1791
	default:
1792
		return kvm_arch_dev_ioctl(filp, ioctl, arg);
A
Avi Kivity 已提交
1793 1794 1795 1796 1797 1798 1799 1800 1801 1802 1803
	}
out:
	return r;
}

static struct file_operations kvm_chardev_ops = {
	.unlocked_ioctl = kvm_dev_ioctl,
	.compat_ioctl   = kvm_dev_ioctl,
};

static struct miscdevice kvm_dev = {
A
Avi Kivity 已提交
1804
	KVM_MINOR,
A
Avi Kivity 已提交
1805 1806 1807 1808
	"kvm",
	&kvm_chardev_ops,
};

A
Avi Kivity 已提交
1809 1810 1811 1812 1813 1814 1815 1816 1817 1818 1819
/*
 * Make sure that a cpu that is being hot-unplugged does not have any vcpus
 * cached on it.
 */
static void decache_vcpus_on_cpu(int cpu)
{
	struct kvm *vm;
	struct kvm_vcpu *vcpu;
	int i;

	spin_lock(&kvm_lock);
S
Shaohua Li 已提交
1820
	list_for_each_entry(vm, &vm_list, vm_list)
A
Avi Kivity 已提交
1821
		for (i = 0; i < KVM_MAX_VCPUS; ++i) {
R
Rusty Russell 已提交
1822 1823 1824
			vcpu = vm->vcpus[i];
			if (!vcpu)
				continue;
A
Avi Kivity 已提交
1825 1826 1827 1828 1829 1830 1831 1832 1833 1834
			/*
			 * If the vcpu is locked, then it is running on some
			 * other cpu and therefore it is not cached on the
			 * cpu in question.
			 *
			 * If it's not locked, check the last cpu it executed
			 * on.
			 */
			if (mutex_trylock(&vcpu->mutex)) {
				if (vcpu->cpu == cpu) {
1835
					kvm_x86_ops->vcpu_decache(vcpu);
A
Avi Kivity 已提交
1836 1837 1838 1839 1840 1841 1842 1843
					vcpu->cpu = -1;
				}
				mutex_unlock(&vcpu->mutex);
			}
		}
	spin_unlock(&kvm_lock);
}

1844 1845 1846 1847 1848 1849 1850
static void hardware_enable(void *junk)
{
	int cpu = raw_smp_processor_id();

	if (cpu_isset(cpu, cpus_hardware_enabled))
		return;
	cpu_set(cpu, cpus_hardware_enabled);
1851
	kvm_x86_ops->hardware_enable(NULL);
1852 1853 1854 1855 1856 1857 1858 1859 1860 1861
}

static void hardware_disable(void *junk)
{
	int cpu = raw_smp_processor_id();

	if (!cpu_isset(cpu, cpus_hardware_enabled))
		return;
	cpu_clear(cpu, cpus_hardware_enabled);
	decache_vcpus_on_cpu(cpu);
1862
	kvm_x86_ops->hardware_disable(NULL);
1863 1864
}

A
Avi Kivity 已提交
1865 1866 1867 1868 1869 1870
static int kvm_cpu_hotplug(struct notifier_block *notifier, unsigned long val,
			   void *v)
{
	int cpu = (long)v;

	switch (val) {
1871 1872
	case CPU_DYING:
	case CPU_DYING_FROZEN:
1873 1874 1875 1876
		printk(KERN_INFO "kvm: disabling virtualization on CPU%d\n",
		       cpu);
		hardware_disable(NULL);
		break;
A
Avi Kivity 已提交
1877
	case CPU_UP_CANCELED:
1878
	case CPU_UP_CANCELED_FROZEN:
1879 1880
		printk(KERN_INFO "kvm: disabling virtualization on CPU%d\n",
		       cpu);
1881
		smp_call_function_single(cpu, hardware_disable, NULL, 0, 1);
A
Avi Kivity 已提交
1882
		break;
1883
	case CPU_ONLINE:
1884
	case CPU_ONLINE_FROZEN:
1885 1886
		printk(KERN_INFO "kvm: enabling virtualization on CPU%d\n",
		       cpu);
1887
		smp_call_function_single(cpu, hardware_enable, NULL, 0, 1);
A
Avi Kivity 已提交
1888 1889 1890 1891 1892
		break;
	}
	return NOTIFY_OK;
}

1893
static int kvm_reboot(struct notifier_block *notifier, unsigned long val,
M
Mike Day 已提交
1894
		      void *v)
1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911
{
	if (val == SYS_RESTART) {
		/*
		 * Some (well, at least mine) BIOSes hang on reboot if
		 * in vmx root mode.
		 */
		printk(KERN_INFO "kvm: exiting hardware virtualization\n");
		on_each_cpu(hardware_disable, NULL, 0, 1);
	}
	return NOTIFY_OK;
}

static struct notifier_block kvm_reboot_notifier = {
	.notifier_call = kvm_reboot,
	.priority = 0,
};

1912 1913 1914 1915 1916 1917 1918 1919 1920 1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948
void kvm_io_bus_init(struct kvm_io_bus *bus)
{
	memset(bus, 0, sizeof(*bus));
}

void kvm_io_bus_destroy(struct kvm_io_bus *bus)
{
	int i;

	for (i = 0; i < bus->dev_count; i++) {
		struct kvm_io_device *pos = bus->devs[i];

		kvm_iodevice_destructor(pos);
	}
}

struct kvm_io_device *kvm_io_bus_find_dev(struct kvm_io_bus *bus, gpa_t addr)
{
	int i;

	for (i = 0; i < bus->dev_count; i++) {
		struct kvm_io_device *pos = bus->devs[i];

		if (pos->in_range(pos, addr))
			return pos;
	}

	return NULL;
}

void kvm_io_bus_register_dev(struct kvm_io_bus *bus, struct kvm_io_device *dev)
{
	BUG_ON(bus->dev_count > (NR_IOBUS_DEVS-1));

	bus->devs[bus->dev_count++] = dev;
}

A
Avi Kivity 已提交
1949 1950 1951 1952 1953
static struct notifier_block kvm_cpu_notifier = {
	.notifier_call = kvm_cpu_hotplug,
	.priority = 20, /* must be > scheduler priority */
};

A
Avi Kivity 已提交
1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964
static u64 stat_get(void *_offset)
{
	unsigned offset = (long)_offset;
	u64 total = 0;
	struct kvm *kvm;
	struct kvm_vcpu *vcpu;
	int i;

	spin_lock(&kvm_lock);
	list_for_each_entry(kvm, &vm_list, vm_list)
		for (i = 0; i < KVM_MAX_VCPUS; ++i) {
R
Rusty Russell 已提交
1965 1966 1967
			vcpu = kvm->vcpus[i];
			if (vcpu)
				total += *(u32 *)((void *)vcpu + offset);
A
Avi Kivity 已提交
1968 1969 1970 1971 1972
		}
	spin_unlock(&kvm_lock);
	return total;
}

R
Rusty Russell 已提交
1973
DEFINE_SIMPLE_ATTRIBUTE(stat_fops, stat_get, NULL, "%llu\n");
A
Avi Kivity 已提交
1974

A
Avi Kivity 已提交
1975 1976 1977 1978
static __init void kvm_init_debug(void)
{
	struct kvm_stats_debugfs_item *p;

A
Al Viro 已提交
1979
	debugfs_dir = debugfs_create_dir("kvm", NULL);
A
Avi Kivity 已提交
1980
	for (p = debugfs_entries; p->name; ++p)
A
Avi Kivity 已提交
1981 1982 1983
		p->dentry = debugfs_create_file(p->name, 0444, debugfs_dir,
						(void *)(long)p->offset,
						&stat_fops);
A
Avi Kivity 已提交
1984 1985 1986 1987 1988 1989 1990 1991 1992 1993 1994
}

static void kvm_exit_debug(void)
{
	struct kvm_stats_debugfs_item *p;

	for (p = debugfs_entries; p->name; ++p)
		debugfs_remove(p->dentry);
	debugfs_remove(debugfs_dir);
}

1995 1996
static int kvm_suspend(struct sys_device *dev, pm_message_t state)
{
A
Avi Kivity 已提交
1997
	hardware_disable(NULL);
1998 1999 2000 2001 2002
	return 0;
}

static int kvm_resume(struct sys_device *dev)
{
A
Avi Kivity 已提交
2003
	hardware_enable(NULL);
2004 2005 2006 2007
	return 0;
}

static struct sysdev_class kvm_sysdev_class = {
2008
	.name = "kvm",
2009 2010 2011 2012 2013 2014 2015 2016 2017
	.suspend = kvm_suspend,
	.resume = kvm_resume,
};

static struct sys_device kvm_sysdev = {
	.id = 0,
	.cls = &kvm_sysdev_class,
};

2018
struct page *bad_page;
A
Avi Kivity 已提交
2019

2020 2021 2022 2023 2024 2025 2026 2027 2028 2029
static inline
struct kvm_vcpu *preempt_notifier_to_vcpu(struct preempt_notifier *pn)
{
	return container_of(pn, struct kvm_vcpu, preempt_notifier);
}

static void kvm_sched_in(struct preempt_notifier *pn, int cpu)
{
	struct kvm_vcpu *vcpu = preempt_notifier_to_vcpu(pn);

2030
	kvm_x86_ops->vcpu_load(vcpu, cpu);
2031 2032 2033 2034 2035 2036 2037
}

static void kvm_sched_out(struct preempt_notifier *pn,
			  struct task_struct *next)
{
	struct kvm_vcpu *vcpu = preempt_notifier_to_vcpu(pn);

2038
	kvm_x86_ops->vcpu_put(vcpu);
2039 2040
}

2041
int kvm_init_x86(struct kvm_x86_ops *ops, unsigned int vcpu_size,
2042
		  struct module *module)
A
Avi Kivity 已提交
2043 2044
{
	int r;
Y
Yang, Sheng 已提交
2045
	int cpu;
A
Avi Kivity 已提交
2046

2047
	if (kvm_x86_ops) {
2048 2049 2050 2051
		printk(KERN_ERR "kvm: already loaded the other module\n");
		return -EEXIST;
	}

2052
	if (!ops->cpu_has_kvm_support()) {
A
Avi Kivity 已提交
2053 2054 2055
		printk(KERN_ERR "kvm: no hardware support\n");
		return -EOPNOTSUPP;
	}
2056
	if (ops->disabled_by_bios()) {
A
Avi Kivity 已提交
2057 2058 2059 2060
		printk(KERN_ERR "kvm: disabled by bios\n");
		return -EOPNOTSUPP;
	}

2061
	kvm_x86_ops = ops;
2062

2063
	r = kvm_x86_ops->hardware_setup();
A
Avi Kivity 已提交
2064
	if (r < 0)
2065
		goto out;
A
Avi Kivity 已提交
2066

Y
Yang, Sheng 已提交
2067 2068
	for_each_online_cpu(cpu) {
		smp_call_function_single(cpu,
2069
				kvm_x86_ops->check_processor_compatibility,
Y
Yang, Sheng 已提交
2070 2071 2072 2073 2074
				&r, 0, 1);
		if (r < 0)
			goto out_free_0;
	}

2075
	on_each_cpu(hardware_enable, NULL, 0, 1);
A
Avi Kivity 已提交
2076 2077 2078
	r = register_cpu_notifier(&kvm_cpu_notifier);
	if (r)
		goto out_free_1;
A
Avi Kivity 已提交
2079 2080
	register_reboot_notifier(&kvm_reboot_notifier);

2081 2082 2083 2084 2085 2086 2087 2088
	r = sysdev_class_register(&kvm_sysdev_class);
	if (r)
		goto out_free_2;

	r = sysdev_register(&kvm_sysdev);
	if (r)
		goto out_free_3;

2089 2090 2091 2092 2093 2094 2095 2096
	/* A kmem cache lets us meet the alignment requirements of fx_save. */
	kvm_vcpu_cache = kmem_cache_create("kvm_vcpu", vcpu_size,
					   __alignof__(struct kvm_vcpu), 0, 0);
	if (!kvm_vcpu_cache) {
		r = -ENOMEM;
		goto out_free_4;
	}

A
Avi Kivity 已提交
2097 2098 2099 2100
	kvm_chardev_ops.owner = module;

	r = misc_register(&kvm_dev);
	if (r) {
M
Mike Day 已提交
2101
		printk(KERN_ERR "kvm: misc device register failed\n");
A
Avi Kivity 已提交
2102 2103 2104
		goto out_free;
	}

2105 2106 2107
	kvm_preempt_ops.sched_in = kvm_sched_in;
	kvm_preempt_ops.sched_out = kvm_sched_out;

2108 2109 2110
	kvm_mmu_set_nonpresent_ptes(0ull, 0ull);

	return 0;
A
Avi Kivity 已提交
2111 2112

out_free:
2113 2114
	kmem_cache_destroy(kvm_vcpu_cache);
out_free_4:
2115 2116 2117 2118
	sysdev_unregister(&kvm_sysdev);
out_free_3:
	sysdev_class_unregister(&kvm_sysdev_class);
out_free_2:
A
Avi Kivity 已提交
2119
	unregister_reboot_notifier(&kvm_reboot_notifier);
A
Avi Kivity 已提交
2120 2121
	unregister_cpu_notifier(&kvm_cpu_notifier);
out_free_1:
2122
	on_each_cpu(hardware_disable, NULL, 0, 1);
Y
Yang, Sheng 已提交
2123
out_free_0:
2124
	kvm_x86_ops->hardware_unsetup();
2125
out:
2126
	kvm_x86_ops = NULL;
A
Avi Kivity 已提交
2127 2128
	return r;
}
M
Mike Day 已提交
2129
EXPORT_SYMBOL_GPL(kvm_init_x86);
A
Avi Kivity 已提交
2130

2131
void kvm_exit_x86(void)
A
Avi Kivity 已提交
2132 2133
{
	misc_deregister(&kvm_dev);
2134
	kmem_cache_destroy(kvm_vcpu_cache);
2135 2136
	sysdev_unregister(&kvm_sysdev);
	sysdev_class_unregister(&kvm_sysdev_class);
A
Avi Kivity 已提交
2137
	unregister_reboot_notifier(&kvm_reboot_notifier);
2138
	unregister_cpu_notifier(&kvm_cpu_notifier);
2139
	on_each_cpu(hardware_disable, NULL, 0, 1);
2140 2141
	kvm_x86_ops->hardware_unsetup();
	kvm_x86_ops = NULL;
A
Avi Kivity 已提交
2142
}
M
Mike Day 已提交
2143
EXPORT_SYMBOL_GPL(kvm_exit_x86);
A
Avi Kivity 已提交
2144 2145 2146

static __init int kvm_init(void)
{
2147 2148
	int r;

2149 2150 2151 2152
	r = kvm_mmu_module_init();
	if (r)
		goto out4;

A
Avi Kivity 已提交
2153 2154
	kvm_init_debug();

2155
	kvm_arch_init();
2156

2157
	bad_page = alloc_page(GFP_KERNEL | __GFP_ZERO);
M
Mike Day 已提交
2158 2159

	if (bad_page == NULL) {
A
Avi Kivity 已提交
2160 2161 2162 2163
		r = -ENOMEM;
		goto out;
	}

2164
	return 0;
A
Avi Kivity 已提交
2165 2166 2167

out:
	kvm_exit_debug();
2168 2169
	kvm_mmu_module_exit();
out4:
A
Avi Kivity 已提交
2170 2171 2172 2173 2174 2175
	return r;
}

static __exit void kvm_exit(void)
{
	kvm_exit_debug();
2176
	__free_page(bad_page);
2177
	kvm_mmu_module_exit();
A
Avi Kivity 已提交
2178 2179 2180 2181
}

module_init(kvm_init)
module_exit(kvm_exit)