traps_32.c 21.8 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 *  Copyright (C) 1991, 1992  Linus Torvalds
3
 *  Copyright (C) 2000, 2001, 2002 Andi Kleen, SuSE Labs
L
Linus Torvalds 已提交
4 5 6 7 8 9 10 11 12
 *
 *  Pentium III FXSR, SSE support
 *	Gareth Hughes <gareth@valinux.com>, May 2000
 */

/*
 * 'Traps.c' handles hardware traps and faults after we have saved some
 * state in 'asm.s'.
 */
I
Ingo Molnar 已提交
13 14 15 16 17 18 19 20
#include <linux/interrupt.h>
#include <linux/kallsyms.h>
#include <linux/spinlock.h>
#include <linux/highmem.h>
#include <linux/kprobes.h>
#include <linux/uaccess.h>
#include <linux/utsname.h>
#include <linux/kdebug.h>
L
Linus Torvalds 已提交
21
#include <linux/kernel.h>
I
Ingo Molnar 已提交
22 23
#include <linux/module.h>
#include <linux/ptrace.h>
L
Linus Torvalds 已提交
24
#include <linux/string.h>
I
Ingo Molnar 已提交
25 26
#include <linux/unwind.h>
#include <linux/delay.h>
L
Linus Torvalds 已提交
27
#include <linux/errno.h>
I
Ingo Molnar 已提交
28 29
#include <linux/kexec.h>
#include <linux/sched.h>
L
Linus Torvalds 已提交
30 31
#include <linux/timer.h>
#include <linux/init.h>
J
Jeremy Fitzhardinge 已提交
32
#include <linux/bug.h>
I
Ingo Molnar 已提交
33 34
#include <linux/nmi.h>
#include <linux/mm.h>
L
Linus Torvalds 已提交
35 36 37 38 39 40 41 42 43 44

#ifdef CONFIG_EISA
#include <linux/ioport.h>
#include <linux/eisa.h>
#endif

#ifdef CONFIG_MCA
#include <linux/mca.h>
#endif

D
Dave Jiang 已提交
45 46 47 48
#if defined(CONFIG_EDAC)
#include <linux/edac.h>
#endif

49
#include <asm/processor-flags.h>
I
Ingo Molnar 已提交
50 51
#include <asm/arch_hooks.h>
#include <asm/stacktrace.h>
L
Linus Torvalds 已提交
52 53
#include <asm/processor.h>
#include <asm/debugreg.h>
I
Ingo Molnar 已提交
54 55 56
#include <asm/atomic.h>
#include <asm/system.h>
#include <asm/unwind.h>
L
Linus Torvalds 已提交
57 58 59 60
#include <asm/desc.h>
#include <asm/i387.h>
#include <asm/nmi.h>
#include <asm/smp.h>
I
Ingo Molnar 已提交
61
#include <asm/io.h>
62
#include <asm/traps.h>
L
Linus Torvalds 已提交
63 64

#include "mach_traps.h"
65
#include "cpu/mcheck/mce.h"
L
Linus Torvalds 已提交
66

67 68 69
DECLARE_BITMAP(used_vectors, NR_VECTORS);
EXPORT_SYMBOL_GPL(used_vectors);

L
Linus Torvalds 已提交
70 71 72
asmlinkage int system_call(void);

/* Do we ignore FPU interrupts ? */
I
Ingo Molnar 已提交
73
char ignore_fpu_irq;
L
Linus Torvalds 已提交
74 75 76 77 78 79

/*
 * The IDT has to be page-aligned to simplify the Pentium
 * F0 0F bug workaround.. We have a special link segment
 * for this.
 */
80
gate_desc idt_table[256]
81
	__attribute__((__section__(".data.idt"))) = { { { { 0, 0 } } }, };
L
Linus Torvalds 已提交
82

83
static int ignore_nmis;
84

85 86 87 88 89 90
static inline void conditional_sti(struct pt_regs *regs)
{
	if (regs->flags & X86_EFLAGS_IF)
		local_irq_enable();
}

I
Ingo Molnar 已提交
91 92
static inline void
die_if_kernel(const char *str, struct pt_regs *regs, long err)
L
Linus Torvalds 已提交
93
{
94
	if (!user_mode_vm(regs))
L
Linus Torvalds 已提交
95 96 97
		die(str, regs, err);
}

I
Ingo Molnar 已提交
98
static void __kprobes
99
do_trap(int trapnr, int signr, char *str, struct pt_regs *regs,
I
Ingo Molnar 已提交
100
	long error_code, siginfo_t *info)
L
Linus Torvalds 已提交
101
{
102 103
	struct task_struct *tsk = current;

104
	if (regs->flags & X86_VM_MASK) {
105 106 107 108 109
		/*
		 * traps 0, 1, 3, 4, and 5 should be forwarded to vm86.
		 * On nmi (interrupt 2), do_trap should not be called.
		 */
		if (trapnr < 6)
L
Linus Torvalds 已提交
110 111 112 113
			goto vm86_trap;
		goto trap_signal;
	}

114
	if (!user_mode(regs))
L
Linus Torvalds 已提交
115 116
		goto kernel_trap;

I
Ingo Molnar 已提交
117 118 119 120 121 122 123 124 125 126 127 128
trap_signal:
	/*
	 * We want error_code and trap_no set for userspace faults and
	 * kernelspace faults which result in die(), but not
	 * kernelspace faults which are fixed up.  die() gives the
	 * process no chance to handle the signal and notice the
	 * kernel fault information, so that won't result in polluting
	 * the information about previously queued, but not yet
	 * delivered, faults.  See also do_general_protection below.
	 */
	tsk->thread.error_code = error_code;
	tsk->thread.trap_no = trapnr;
129

I
Ingo Molnar 已提交
130 131 132 133 134
	if (info)
		force_sig_info(signr, info, tsk);
	else
		force_sig(signr, tsk);
	return;
L
Linus Torvalds 已提交
135

I
Ingo Molnar 已提交
136 137 138 139 140
kernel_trap:
	if (!fixup_exception(regs)) {
		tsk->thread.error_code = error_code;
		tsk->thread.trap_no = trapnr;
		die(str, regs, error_code);
L
Linus Torvalds 已提交
141
	}
I
Ingo Molnar 已提交
142
	return;
L
Linus Torvalds 已提交
143

I
Ingo Molnar 已提交
144 145 146 147 148
vm86_trap:
	if (handle_vm86_trap((struct kernel_vm86_regs *) regs,
						error_code, trapnr))
		goto trap_signal;
	return;
L
Linus Torvalds 已提交
149 150
}

I
Ingo Molnar 已提交
151 152 153 154
#define DO_ERROR(trapnr, signr, str, name)				\
void do_##name(struct pt_regs *regs, long error_code)			\
{									\
	if (notify_die(DIE_TRAP, str, regs, error_code, trapnr, signr)	\
155
							== NOTIFY_STOP)	\
I
Ingo Molnar 已提交
156
		return;							\
157
	conditional_sti(regs);						\
158
	do_trap(trapnr, signr, str, regs, error_code, NULL);		\
L
Linus Torvalds 已提交
159 160
}

161
#define DO_ERROR_INFO(trapnr, signr, str, name, sicode, siaddr)		\
I
Ingo Molnar 已提交
162 163 164 165 166 167 168 169
void do_##name(struct pt_regs *regs, long error_code)			\
{									\
	siginfo_t info;							\
	info.si_signo = signr;						\
	info.si_errno = 0;						\
	info.si_code = sicode;						\
	info.si_addr = (void __user *)siaddr;				\
	if (notify_die(DIE_TRAP, str, regs, error_code, trapnr, signr)	\
170
							== NOTIFY_STOP)	\
I
Ingo Molnar 已提交
171
		return;							\
172
	conditional_sti(regs);						\
173
	do_trap(trapnr, signr, str, regs, error_code, &info);		\
L
Linus Torvalds 已提交
174 175
}

176 177 178 179
DO_ERROR_INFO(0, SIGFPE, "divide error", divide_error, FPE_INTDIV, regs->ip)
DO_ERROR(4, SIGSEGV, "overflow", overflow)
DO_ERROR(5, SIGSEGV, "bounds", bounds)
DO_ERROR_INFO(6, SIGILL, "invalid opcode", invalid_op, ILL_ILLOPN, regs->ip)
180
DO_ERROR(9, SIGFPE, "coprocessor segment overrun", coprocessor_segment_overrun)
181
DO_ERROR(10, SIGSEGV, "invalid TSS", invalid_TSS)
182
DO_ERROR(11, SIGBUS, "segment not present", segment_not_present)
183
DO_ERROR(12, SIGBUS, "stack segment", stack_segment)
184
DO_ERROR_INFO(17, SIGBUS, "alignment check", alignment_check, BUS_ADRALN, 0)
L
Linus Torvalds 已提交
185

186 187
void __kprobes
do_general_protection(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
188
{
189
	struct task_struct *tsk;
I
Ingo Molnar 已提交
190 191 192 193
	struct thread_struct *thread;
	struct tss_struct *tss;
	int cpu;

194 195
	conditional_sti(regs);

I
Ingo Molnar 已提交
196 197 198
	cpu = get_cpu();
	tss = &per_cpu(init_tss, cpu);
	thread = &current->thread;
L
Linus Torvalds 已提交
199 200 201 202 203 204 205 206

	/*
	 * Perform the lazy TSS's I/O bitmap copy. If the TSS has an
	 * invalid offset set (the LAZY one) and the faulting thread has
	 * a valid I/O bitmap pointer, we copy the I/O bitmap in the TSS
	 * and we set the offset field correctly. Then we let the CPU to
	 * restart the faulting instruction.
	 */
207
	if (tss->x86_tss.io_bitmap_base == INVALID_IO_BITMAP_OFFSET_LAZY &&
L
Linus Torvalds 已提交
208 209 210 211 212 213 214
	    thread->io_bitmap_ptr) {
		memcpy(tss->io_bitmap, thread->io_bitmap_ptr,
		       thread->io_bitmap_max);
		/*
		 * If the previously set map was extending to higher ports
		 * than the current one, pad extra space with 0xff (no access).
		 */
I
Ingo Molnar 已提交
215
		if (thread->io_bitmap_max < tss->io_bitmap_max) {
L
Linus Torvalds 已提交
216 217 218
			memset((char *) tss->io_bitmap +
				thread->io_bitmap_max, 0xff,
				tss->io_bitmap_max - thread->io_bitmap_max);
I
Ingo Molnar 已提交
219
		}
L
Linus Torvalds 已提交
220
		tss->io_bitmap_max = thread->io_bitmap_max;
221
		tss->x86_tss.io_bitmap_base = IO_BITMAP_OFFSET;
222
		tss->io_bitmap_owner = thread;
L
Linus Torvalds 已提交
223
		put_cpu();
I
Ingo Molnar 已提交
224

L
Linus Torvalds 已提交
225 226 227 228
		return;
	}
	put_cpu();

229
	if (regs->flags & X86_VM_MASK)
L
Linus Torvalds 已提交
230 231
		goto gp_in_vm86;

232
	tsk = current;
233
	if (!user_mode(regs))
L
Linus Torvalds 已提交
234 235
		goto gp_in_kernel;

236 237
	tsk->thread.error_code = error_code;
	tsk->thread.trap_no = 13;
I
Ingo Molnar 已提交
238

239 240
	if (show_unhandled_signals && unhandled_signal(tsk, SIGSEGV) &&
			printk_ratelimit()) {
241
		printk(KERN_INFO
242 243 244
			"%s[%d] general protection ip:%lx sp:%lx error:%lx",
			tsk->comm, task_pid_nr(tsk),
			regs->ip, regs->sp, error_code);
245 246 247
		print_vma_addr(" in ", regs->ip);
		printk("\n");
	}
248

249
	force_sig(SIGSEGV, tsk);
L
Linus Torvalds 已提交
250 251 252 253 254 255 256 257
	return;

gp_in_vm86:
	local_irq_enable();
	handle_vm86_fault((struct kernel_vm86_regs *) regs, error_code);
	return;

gp_in_kernel:
258 259 260 261 262 263
	if (fixup_exception(regs))
		return;

	tsk->thread.error_code = error_code;
	tsk->thread.trap_no = 13;
	if (notify_die(DIE_GPF, "general protection fault", regs,
L
Linus Torvalds 已提交
264
				error_code, 13, SIGSEGV) == NOTIFY_STOP)
265 266
		return;
	die("general protection fault", regs, error_code);
L
Linus Torvalds 已提交
267 268
}

269
static notrace __kprobes void
I
Ingo Molnar 已提交
270
mem_parity_error(unsigned char reason, struct pt_regs *regs)
L
Linus Torvalds 已提交
271
{
I
Ingo Molnar 已提交
272 273 274 275 276 277
	printk(KERN_EMERG
		"Uhhuh. NMI received for unknown reason %02x on CPU %d.\n",
			reason, smp_processor_id());

	printk(KERN_EMERG
		"You have some hardware problem, likely on the PCI bus.\n");
D
Dave Jiang 已提交
278 279

#if defined(CONFIG_EDAC)
I
Ingo Molnar 已提交
280
	if (edac_handler_set()) {
D
Dave Jiang 已提交
281 282 283 284 285
		edac_atomic_assert_error();
		return;
	}
#endif

286
	if (panic_on_unrecovered_nmi)
I
Ingo Molnar 已提交
287
		panic("NMI: Not continuing");
L
Linus Torvalds 已提交
288

289
	printk(KERN_EMERG "Dazed and confused, but trying to continue\n");
L
Linus Torvalds 已提交
290 291 292 293 294

	/* Clear and disable the memory parity error line. */
	clear_mem_error(reason);
}

295
static notrace __kprobes void
I
Ingo Molnar 已提交
296
io_check_error(unsigned char reason, struct pt_regs *regs)
L
Linus Torvalds 已提交
297 298 299
{
	unsigned long i;

300
	printk(KERN_EMERG "NMI: IOCK error (debug interrupt?)\n");
L
Linus Torvalds 已提交
301 302 303 304 305
	show_registers(regs);

	/* Re-enable the IOCK line, wait for a few seconds */
	reason = (reason & 0xf) | 8;
	outb(reason, 0x61);
I
Ingo Molnar 已提交
306

L
Linus Torvalds 已提交
307
	i = 2000;
I
Ingo Molnar 已提交
308 309 310
	while (--i)
		udelay(1000);

L
Linus Torvalds 已提交
311 312 313 314
	reason &= ~8;
	outb(reason, 0x61);
}

315
static notrace __kprobes void
I
Ingo Molnar 已提交
316
unknown_nmi_error(unsigned char reason, struct pt_regs *regs)
L
Linus Torvalds 已提交
317
{
J
Jason Wessel 已提交
318 319
	if (notify_die(DIE_NMIUNKNOWN, "nmi", regs, reason, 2, SIGINT) == NOTIFY_STOP)
		return;
L
Linus Torvalds 已提交
320
#ifdef CONFIG_MCA
I
Ingo Molnar 已提交
321 322 323 324 325
	/*
	 * Might actually be able to figure out what the guilty party
	 * is:
	 */
	if (MCA_bus) {
L
Linus Torvalds 已提交
326 327 328 329
		mca_handle_nmi();
		return;
	}
#endif
I
Ingo Molnar 已提交
330 331 332 333
	printk(KERN_EMERG
		"Uhhuh. NMI received for unknown reason %02x on CPU %d.\n",
			reason, smp_processor_id());

334
	printk(KERN_EMERG "Do you have a strange power saving mode enabled?\n");
335
	if (panic_on_unrecovered_nmi)
I
Ingo Molnar 已提交
336
		panic("NMI: Not continuing");
337

338
	printk(KERN_EMERG "Dazed and confused, but trying to continue\n");
L
Linus Torvalds 已提交
339 340 341 342
}

static DEFINE_SPINLOCK(nmi_print_lock);

343
void notrace __kprobes die_nmi(char *str, struct pt_regs *regs, int do_panic)
L
Linus Torvalds 已提交
344
{
345
	if (notify_die(DIE_NMIWATCHDOG, str, regs, 0, 2, SIGINT) == NOTIFY_STOP)
346 347
		return;

L
Linus Torvalds 已提交
348 349 350
	spin_lock(&nmi_print_lock);
	/*
	* We are in trouble anyway, lets at least try
I
Ingo Molnar 已提交
351
	* to get a message out:
L
Linus Torvalds 已提交
352 353
	*/
	bust_spinlocks(1);
354
	printk(KERN_EMERG "%s", str);
355 356
	printk(" on CPU%d, ip %08lx, registers:\n",
		smp_processor_id(), regs->ip);
L
Linus Torvalds 已提交
357
	show_registers(regs);
358 359
	if (do_panic)
		panic("Non maskable interrupt");
L
Linus Torvalds 已提交
360 361 362
	console_silent();
	spin_unlock(&nmi_print_lock);
	bust_spinlocks(0);
363

I
Ingo Molnar 已提交
364 365 366 367
	/*
	 * If we are in kernel we are probably nested up pretty bad
	 * and might aswell get out now while we still can:
	 */
368
	if (!user_mode_vm(regs)) {
369 370 371 372
		current->thread.trap_no = 2;
		crash_kexec(regs);
	}

L
Linus Torvalds 已提交
373 374 375
	do_exit(SIGSEGV);
}

376
static notrace __kprobes void default_do_nmi(struct pt_regs *regs)
L
Linus Torvalds 已提交
377 378
{
	unsigned char reason = 0;
379 380 381
	int cpu;

	cpu = smp_processor_id();
L
Linus Torvalds 已提交
382

383 384
	/* Only the BSP gets external NMIs from the system. */
	if (!cpu)
L
Linus Torvalds 已提交
385
		reason = get_nmi_reason();
I
Ingo Molnar 已提交
386

L
Linus Torvalds 已提交
387
	if (!(reason & 0xc0)) {
388
		if (notify_die(DIE_NMI_IPI, "nmi_ipi", regs, reason, 2, SIGINT)
389
								== NOTIFY_STOP)
L
Linus Torvalds 已提交
390 391 392 393 394 395
			return;
#ifdef CONFIG_X86_LOCAL_APIC
		/*
		 * Ok, so this is none of the documented NMI sources,
		 * so it must be the NMI watchdog.
		 */
396
		if (nmi_watchdog_tick(regs, reason))
L
Linus Torvalds 已提交
397
			return;
398
		if (!do_nmi_callback(regs, cpu))
399
			unknown_nmi_error(reason, regs);
I
Ingo Molnar 已提交
400 401 402
#else
		unknown_nmi_error(reason, regs);
#endif
403

L
Linus Torvalds 已提交
404 405
		return;
	}
406
	if (notify_die(DIE_NMI, "nmi", regs, reason, 2, SIGINT) == NOTIFY_STOP)
L
Linus Torvalds 已提交
407
		return;
408 409

	/* AK: following checks seem to be broken on modern chipsets. FIXME */
L
Linus Torvalds 已提交
410 411 412 413 414 415
	if (reason & 0x80)
		mem_parity_error(reason, regs);
	if (reason & 0x40)
		io_check_error(reason, regs);
	/*
	 * Reassert NMI in case it became active meanwhile
I
Ingo Molnar 已提交
416
	 * as it's edge-triggered:
L
Linus Torvalds 已提交
417 418 419 420
	 */
	reassert_nmi();
}

421
notrace __kprobes void do_nmi(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
422 423 424 425 426 427
{
	int cpu;

	nmi_enter();

	cpu = smp_processor_id();
Z
Zwane Mwaikambo 已提交
428

L
Linus Torvalds 已提交
429 430
	++nmi_count(cpu);

431 432
	if (!ignore_nmis)
		default_do_nmi(regs);
L
Linus Torvalds 已提交
433 434 435 436

	nmi_exit();
}

437 438 439 440 441 442 443 444 445 446 447 448
void stop_nmi(void)
{
	acpi_nmi_disable();
	ignore_nmis++;
}

void restart_nmi(void)
{
	ignore_nmis--;
	acpi_nmi_enable();
}

449
void __kprobes do_int3(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
450
{
451
#ifdef CONFIG_KPROBES
L
Linus Torvalds 已提交
452 453
	if (notify_die(DIE_INT3, "int3", regs, error_code, 3, SIGTRAP)
			== NOTIFY_STOP)
454
		return;
455
	conditional_sti(regs);
456 457 458 459 460
#else
	if (notify_die(DIE_TRAP, "int3", regs, error_code, 3, SIGTRAP)
			== NOTIFY_STOP)
		return;
#endif
I
Ingo Molnar 已提交
461

462
	do_trap(3, SIGTRAP, "int3", regs, error_code, NULL);
L
Linus Torvalds 已提交
463 464 465 466 467 468 469 470 471 472 473 474
}

/*
 * Our handling of the processor debug registers is non-trivial.
 * We do not clear them on entry and exit from the kernel. Therefore
 * it is possible to get a watchpoint trap here from inside the kernel.
 * However, the code in ./ptrace.c has ensured that the user can
 * only set watchpoints on userspace addresses. Therefore the in-kernel
 * watchpoint trap can only occur in code which is reading/writing
 * from user space. Such code must not hold kernel locks (since it
 * can equally take a page fault), therefore it is safe to call
 * force_sig_info even though that claims and releases locks.
I
Ingo Molnar 已提交
475
 *
L
Linus Torvalds 已提交
476 477 478 479 480 481 482 483 484 485 486
 * Code in ./signal.c ensures that the debug control register
 * is restored before we deliver any signal, and therefore that
 * user code runs with the correct debug control register even though
 * we clear it here.
 *
 * Being careful here means that we don't have to be as careful in a
 * lot of more complicated places (task switching can be a bit lazy
 * about restoring all the debug state, and ptrace doesn't have to
 * find every occurrence of the TF bit that could be saved away even
 * by user code)
 */
I
Ingo Molnar 已提交
487
void __kprobes do_debug(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
488 489
{
	struct task_struct *tsk = current;
I
Ingo Molnar 已提交
490
	unsigned int condition;
491
	int si_code;
L
Linus Torvalds 已提交
492

493
	get_debugreg(condition, 6);
L
Linus Torvalds 已提交
494

495 496 497 498 499 500
	/*
	 * The processor cleared BTF, so don't mark that we need it set.
	 */
	clear_tsk_thread_flag(tsk, TIF_DEBUGCTLMSR);
	tsk->thread.debugctlmsr = 0;

L
Linus Torvalds 已提交
501
	if (notify_die(DIE_DEBUG, "debug", regs, condition, error_code,
502
						SIGTRAP) == NOTIFY_STOP)
L
Linus Torvalds 已提交
503 504
		return;
	/* It's safe to allow irq's after DR6 has been saved */
505
	if (regs->flags & X86_EFLAGS_IF)
L
Linus Torvalds 已提交
506 507 508 509
		local_irq_enable();

	/* Mask out spurious debug traps due to lazy DR7 setting */
	if (condition & (DR_TRAP0|DR_TRAP1|DR_TRAP2|DR_TRAP3)) {
510
		if (!tsk->thread.debugreg7)
L
Linus Torvalds 已提交
511 512 513
			goto clear_dr7;
	}

514
	if (regs->flags & X86_VM_MASK)
L
Linus Torvalds 已提交
515 516 517
		goto debug_vm86;

	/* Save debug status register where ptrace can see it */
518
	tsk->thread.debugreg6 = condition;
L
Linus Torvalds 已提交
519 520 521 522 523 524 525 526 527 528 529

	/*
	 * Single-stepping through TF: make sure we ignore any events in
	 * kernel space (but re-enable TF when returning to user mode).
	 */
	if (condition & DR_STEP) {
		/*
		 * We already checked v86 mode above, so we can
		 * check for kernel mode by just checking the CPL
		 * of CS.
		 */
530
		if (!user_mode(regs))
L
Linus Torvalds 已提交
531 532 533
			goto clear_TF_reenable;
	}

534
	si_code = get_si_code((unsigned long)condition);
L
Linus Torvalds 已提交
535
	/* Ok, finally something we can handle */
536
	send_sigtrap(tsk, regs, error_code, si_code);
L
Linus Torvalds 已提交
537

I
Ingo Molnar 已提交
538 539
	/*
	 * Disable additional traps. They'll be re-enabled when
L
Linus Torvalds 已提交
540 541 542
	 * the signal is delivered.
	 */
clear_dr7:
543
	set_debugreg(0, 7);
L
Linus Torvalds 已提交
544 545 546 547 548 549 550 551
	return;

debug_vm86:
	handle_vm86_trap((struct kernel_vm86_regs *) regs, error_code, 1);
	return;

clear_TF_reenable:
	set_tsk_thread_flag(tsk, TIF_SINGLESTEP);
552
	regs->flags &= ~X86_EFLAGS_TF;
L
Linus Torvalds 已提交
553 554 555 556 557 558 559 560
	return;
}

/*
 * Note that we play around with the 'TS' bit in an attempt to get
 * the correct behaviour even in the presence of the asynchronous
 * IRQ13 behaviour
 */
561
void math_error(void __user *ip)
L
Linus Torvalds 已提交
562
{
I
Ingo Molnar 已提交
563
	struct task_struct *task;
L
Linus Torvalds 已提交
564
	siginfo_t info;
565
	unsigned short cwd, swd;
L
Linus Torvalds 已提交
566 567 568 569 570 571 572 573 574 575 576

	/*
	 * Save the info for the exception handler and clear the error.
	 */
	task = current;
	save_init_fpu(task);
	task->thread.trap_no = 16;
	task->thread.error_code = 0;
	info.si_signo = SIGFPE;
	info.si_errno = 0;
	info.si_code = __SI_FAULT;
577
	info.si_addr = ip;
L
Linus Torvalds 已提交
578 579 580 581 582 583
	/*
	 * (~cwd & swd) will mask out exceptions that are not set to unmasked
	 * status.  0x3f is the exception bits in these regs, 0x200 is the
	 * C1 reg you need in case of a stack fault, 0x040 is the stack
	 * fault bit.  We should only be taking one exception at a time,
	 * so if this combination doesn't produce any single exception,
584
	 * then we have a bad program that isn't synchronizing its FPU usage
L
Linus Torvalds 已提交
585 586 587 588 589
	 * and it will suffer the consequences since we won't be able to
	 * fully reproduce the context of the exception
	 */
	cwd = get_fpu_cwd(task);
	swd = get_fpu_swd(task);
590
	switch (swd & ~cwd & 0x3f) {
I
Ingo Molnar 已提交
591 592
	case 0x000: /* No unmasked exception */
		return;
593
	default: /* Multiple exceptions */
I
Ingo Molnar 已提交
594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615
		break;
	case 0x001: /* Invalid Op */
		/*
		 * swd & 0x240 == 0x040: Stack Underflow
		 * swd & 0x240 == 0x240: Stack Overflow
		 * User must clear the SF bit (0x40) if set
		 */
		info.si_code = FPE_FLTINV;
		break;
	case 0x002: /* Denormalize */
	case 0x010: /* Underflow */
		info.si_code = FPE_FLTUND;
		break;
	case 0x004: /* Zero Divide */
		info.si_code = FPE_FLTDIV;
		break;
	case 0x008: /* Overflow */
		info.si_code = FPE_FLTOVF;
		break;
	case 0x020: /* Precision */
		info.si_code = FPE_FLTRES;
		break;
L
Linus Torvalds 已提交
616 617 618 619
	}
	force_sig_info(SIGFPE, &info, task);
}

I
Ingo Molnar 已提交
620
void do_coprocessor_error(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
621
{
622
	conditional_sti(regs);
L
Linus Torvalds 已提交
623
	ignore_fpu_irq = 1;
624
	math_error((void __user *)regs->ip);
L
Linus Torvalds 已提交
625 626
}

627
static void simd_math_error(void __user *ip)
L
Linus Torvalds 已提交
628
{
I
Ingo Molnar 已提交
629 630
	struct task_struct *task;
	siginfo_t info;
631
	unsigned short mxcsr;
L
Linus Torvalds 已提交
632 633 634 635 636 637 638 639 640 641 642

	/*
	 * Save the info for the exception handler and clear the error.
	 */
	task = current;
	save_init_fpu(task);
	task->thread.trap_no = 19;
	task->thread.error_code = 0;
	info.si_signo = SIGFPE;
	info.si_errno = 0;
	info.si_code = __SI_FAULT;
643
	info.si_addr = ip;
L
Linus Torvalds 已提交
644 645 646 647 648 649 650 651
	/*
	 * The SIMD FPU exceptions are handled a little differently, as there
	 * is only a single status/control register.  Thus, to determine which
	 * unmasked exception was caught we must mask the exception mask bits
	 * at 0x1f80, and then use these to mask the exception bits at 0x3f.
	 */
	mxcsr = get_fpu_mxcsr(task);
	switch (~((mxcsr & 0x1f80) >> 7) & (mxcsr & 0x3f)) {
I
Ingo Molnar 已提交
652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670
	case 0x000:
	default:
		break;
	case 0x001: /* Invalid Op */
		info.si_code = FPE_FLTINV;
		break;
	case 0x002: /* Denormalize */
	case 0x010: /* Underflow */
		info.si_code = FPE_FLTUND;
		break;
	case 0x004: /* Zero Divide */
		info.si_code = FPE_FLTDIV;
		break;
	case 0x008: /* Overflow */
		info.si_code = FPE_FLTOVF;
		break;
	case 0x020: /* Precision */
		info.si_code = FPE_FLTRES;
		break;
L
Linus Torvalds 已提交
671 672 673 674
	}
	force_sig_info(SIGFPE, &info, task);
}

I
Ingo Molnar 已提交
675
void do_simd_coprocessor_error(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
676
{
677 678
	conditional_sti(regs);

L
Linus Torvalds 已提交
679 680 681
	if (cpu_has_xmm) {
		/* Handle SIMD FPU exceptions on PIII+ processors. */
		ignore_fpu_irq = 1;
682
		simd_math_error((void __user *)regs->ip);
I
Ingo Molnar 已提交
683 684 685 686 687 688
		return;
	}
	/*
	 * Handle strange cache flush from user space exception
	 * in all other cases.  This is undocumented behaviour.
	 */
689
	if (regs->flags & X86_VM_MASK) {
I
Ingo Molnar 已提交
690 691
		handle_vm86_fault((struct kernel_vm86_regs *)regs, error_code);
		return;
L
Linus Torvalds 已提交
692
	}
I
Ingo Molnar 已提交
693 694 695 696
	current->thread.trap_no = 19;
	current->thread.error_code = error_code;
	die_if_kernel("cache flush denied", regs, error_code);
	force_sig(SIGSEGV, current);
L
Linus Torvalds 已提交
697 698
}

I
Ingo Molnar 已提交
699
void do_spurious_interrupt_bug(struct pt_regs *regs, long error_code)
L
Linus Torvalds 已提交
700
{
701
	conditional_sti(regs);
L
Linus Torvalds 已提交
702 703
#if 0
	/* No need to warn about this any longer. */
I
Ingo Molnar 已提交
704
	printk(KERN_INFO "Ignoring P6 Local APIC Spurious Interrupt Bug...\n");
L
Linus Torvalds 已提交
705 706 707
#endif
}

I
Ingo Molnar 已提交
708
unsigned long patch_espfix_desc(unsigned long uesp, unsigned long kesp)
L
Linus Torvalds 已提交
709
{
G
Glauber Costa 已提交
710
	struct desc_struct *gdt = get_cpu_gdt_table(smp_processor_id());
S
Stas Sergeev 已提交
711 712 713 714
	unsigned long base = (kesp - uesp) & -THREAD_SIZE;
	unsigned long new_kesp = kesp - base;
	unsigned long lim_pages = (new_kesp | (THREAD_SIZE - 1)) >> PAGE_SHIFT;
	__u64 desc = *(__u64 *)&gdt[GDT_ENTRY_ESPFIX_SS];
I
Ingo Molnar 已提交
715

S
Stas Sergeev 已提交
716
	/* Set up base for espfix segment */
I
Ingo Molnar 已提交
717 718
	desc &= 0x00f0ff0000000000ULL;
	desc |=	((((__u64)base) << 16) & 0x000000ffffff0000ULL) |
S
Stas Sergeev 已提交
719 720 721 722
		((((__u64)base) << 32) & 0xff00000000000000ULL) |
		((((__u64)lim_pages) << 32) & 0x000f000000000000ULL) |
		(lim_pages & 0xffff);
	*(__u64 *)&gdt[GDT_ENTRY_ESPFIX_SS] = desc;
I
Ingo Molnar 已提交
723

S
Stas Sergeev 已提交
724
	return new_kesp;
L
Linus Torvalds 已提交
725 726 727
}

/*
I
Ingo Molnar 已提交
728
 * 'math_state_restore()' saves the current math information in the
L
Linus Torvalds 已提交
729 730 731 732 733 734 735 736
 * old math state array, and gets the new ones from the current task
 *
 * Careful.. There are problems with IBM-designed IRQ13 behaviour.
 * Don't touch unless you *really* know how it works.
 *
 * Must be called with kernel preemption disabled (in this case,
 * local interrupts are disabled at the call-site in entry.S).
 */
737
asmlinkage void math_state_restore(void)
L
Linus Torvalds 已提交
738 739 740 741
{
	struct thread_info *thread = current_thread_info();
	struct task_struct *tsk = thread->task;

742 743 744 745 746 747 748 749 750 751 752 753 754 755 756
	if (!tsk_used_math(tsk)) {
		local_irq_enable();
		/*
		 * does a slab alloc which can sleep
		 */
		if (init_fpu(tsk)) {
			/*
			 * ran out of memory!
			 */
			do_group_exit(SIGKILL);
			return;
		}
		local_irq_disable();
	}

I
Ingo Molnar 已提交
757
	clts();				/* Allow maths ops (or we recurse) */
L
Linus Torvalds 已提交
758 759
	restore_fpu(tsk);
	thread->status |= TS_USEDFPU;	/* So we fnsave on switch_to() */
760
	tsk->fpu_counter++;
L
Linus Torvalds 已提交
761
}
762
EXPORT_SYMBOL_GPL(math_state_restore);
L
Linus Torvalds 已提交
763 764 765 766 767

#ifndef CONFIG_MATH_EMULATION

asmlinkage void math_emulate(long arg)
{
I
Ingo Molnar 已提交
768 769 770 771
	printk(KERN_EMERG
		"math-emulation not enabled and no coprocessor found.\n");
	printk(KERN_EMERG "killing %s.\n", current->comm);
	force_sig(SIGFPE, current);
L
Linus Torvalds 已提交
772 773 774 775 776
	schedule();
}

#endif /* CONFIG_MATH_EMULATION */

777 778 779 780 781 782 783 784 785 786 787
void __kprobes do_device_not_available(struct pt_regs *regs, long error)
{
	if (read_cr0() & X86_CR0_EM) {
		conditional_sti(regs);
		math_emulate(0);
	} else {
		math_state_restore(); /* interrupts still off */
		conditional_sti(regs);
	}
}

788 789 790 791 792 793 794 795
#ifdef CONFIG_X86_MCE
void __kprobes do_machine_check(struct pt_regs *regs, long error)
{
	conditional_sti(regs);
	machine_check_vector(regs, error);
}
#endif

796 797 798 799 800 801 802 803 804 805 806 807
void do_iret_error(struct pt_regs *regs, long error_code)
{
	siginfo_t info;
	local_irq_enable();

	info.si_signo = SIGILL;
	info.si_errno = 0;
	info.si_code = ILL_BADSTK;
	info.si_addr = 0;
	if (notify_die(DIE_TRAP, "iret exception",
			regs, error_code, 32, SIGILL) == NOTIFY_STOP)
		return;
808
	do_trap(32, SIGILL, "iret exception", regs, error_code, &info);
809 810
}

L
Linus Torvalds 已提交
811 812
void __init trap_init(void)
{
813 814
	int i;

L
Linus Torvalds 已提交
815
#ifdef CONFIG_EISA
I
Ingo Molnar 已提交
816
	void __iomem *p = early_ioremap(0x0FFFD9, 4);
I
Ingo Molnar 已提交
817 818

	if (readl(p) == 'E' + ('I'<<8) + ('S'<<16) + ('A'<<24))
L
Linus Torvalds 已提交
819
		EISA_bus = 1;
I
Ingo Molnar 已提交
820
	early_iounmap(p, 4);
L
Linus Torvalds 已提交
821 822
#endif

823
	set_intr_gate(0, &divide_error);
824 825 826
	set_intr_gate(1, &debug);
	set_intr_gate(2, &nmi);
	set_system_intr_gate(3, &int3); /* int3 can be called from all */
827
	set_system_intr_gate(4, &overflow); /* int4 can be called from all */
828
	set_intr_gate(5, &bounds);
829
	set_intr_gate(6, &invalid_op);
830
	set_intr_gate(7, &device_not_available);
831
	set_task_gate(8, GDT_ENTRY_DOUBLEFAULT_TSS);
832
	set_intr_gate(9, &coprocessor_segment_overrun);
833
	set_intr_gate(10, &invalid_TSS);
834
	set_intr_gate(11, &segment_not_present);
835
	set_intr_gate(12, &stack_segment);
836
	set_intr_gate(13, &general_protection);
I
Ingo Molnar 已提交
837
	set_intr_gate(14, &page_fault);
838
	set_intr_gate(15, &spurious_interrupt_bug);
839
	set_intr_gate(16, &coprocessor_error);
840
	set_intr_gate(17, &alignment_check);
L
Linus Torvalds 已提交
841
#ifdef CONFIG_X86_MCE
842
	set_intr_gate(18, &machine_check);
L
Linus Torvalds 已提交
843
#endif
844
	set_intr_gate(19, &simd_coprocessor_error);
L
Linus Torvalds 已提交
845

846 847 848 849 850 851
	if (cpu_has_fxsr) {
		printk(KERN_INFO "Enabling fast FPU save and restore... ");
		set_in_cr4(X86_CR4_OSFXSR);
		printk("done.\n");
	}
	if (cpu_has_xmm) {
I
Ingo Molnar 已提交
852 853
		printk(KERN_INFO
			"Enabling unmasked SIMD FPU exception support... ");
854 855 856 857
		set_in_cr4(X86_CR4_OSXMMEXCPT);
		printk("done.\n");
	}

I
Ingo Molnar 已提交
858
	set_system_gate(SYSCALL_VECTOR, &system_call);
L
Linus Torvalds 已提交
859

I
Ingo Molnar 已提交
860
	/* Reserve all the builtin and the syscall vector: */
861 862
	for (i = 0; i < FIRST_EXTERNAL_VECTOR; i++)
		set_bit(i, used_vectors);
I
Ingo Molnar 已提交
863

864 865
	set_bit(SYSCALL_VECTOR, used_vectors);

L
Linus Torvalds 已提交
866
	/*
I
Ingo Molnar 已提交
867
	 * Should be a barrier for any external CPU state:
L
Linus Torvalds 已提交
868 869 870 871 872
	 */
	cpu_init();

	trap_init_hook();
}