fault.c 19.4 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 *  S390 version
3
 *    Copyright IBM Corp. 1999
L
Linus Torvalds 已提交
4 5 6 7 8 9 10
 *    Author(s): Hartmut Penner (hp@de.ibm.com)
 *               Ulrich Weigand (uweigand@de.ibm.com)
 *
 *  Derived from "arch/i386/mm/fault.c"
 *    Copyright (C) 1995  Linus Torvalds
 */

11
#include <linux/kernel_stat.h>
12
#include <linux/perf_event.h>
L
Linus Torvalds 已提交
13 14 15 16 17 18 19 20 21
#include <linux/signal.h>
#include <linux/sched.h>
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/types.h>
#include <linux/ptrace.h>
#include <linux/mman.h>
#include <linux/mm.h>
H
Heiko Carstens 已提交
22
#include <linux/compat.h>
L
Linus Torvalds 已提交
23
#include <linux/smp.h>
24
#include <linux/kdebug.h>
L
Linus Torvalds 已提交
25 26 27 28
#include <linux/init.h>
#include <linux/console.h>
#include <linux/module.h>
#include <linux/hardirq.h>
M
Michael Grundy 已提交
29
#include <linux/kprobes.h>
30
#include <linux/uaccess.h>
31
#include <linux/hugetlb.h>
32
#include <asm/asm-offsets.h>
L
Linus Torvalds 已提交
33
#include <asm/pgtable.h>
34
#include <asm/irq.h>
M
Martin Schwidefsky 已提交
35
#include <asm/mmu_context.h>
36
#include <asm/facility.h>
37
#include "../kernel/entry.h"
L
Linus Torvalds 已提交
38

39
#ifndef CONFIG_64BIT
L
Linus Torvalds 已提交
40 41 42
#define __FAIL_ADDR_MASK 0x7ffff000
#define __SUBCODE_MASK 0x0200
#define __PF_RES_FIELD 0ULL
43
#else /* CONFIG_64BIT */
L
Linus Torvalds 已提交
44 45 46
#define __FAIL_ADDR_MASK -4096L
#define __SUBCODE_MASK 0x0600
#define __PF_RES_FIELD 0x8000000000000000ULL
47
#endif /* CONFIG_64BIT */
L
Linus Torvalds 已提交
48

49 50 51
#define VM_FAULT_BADCONTEXT	0x010000
#define VM_FAULT_BADMAP		0x020000
#define VM_FAULT_BADACCESS	0x040000
52
#define VM_FAULT_SIGNAL		0x080000
53
#define VM_FAULT_PFAULT		0x100000
54

55
static unsigned long store_indication __read_mostly;
56

57 58
#ifdef CONFIG_64BIT
static int __init fault_init(void)
59
{
60
	if (test_facility(75))
61
		store_indication = 0xc00;
62
	return 0;
63
}
64 65
early_initcall(fault_init);
#endif
66

67
static inline int notify_page_fault(struct pt_regs *regs)
68
{
69 70 71
	int ret = 0;

	/* kprobe_running() needs smp_processor_id() */
72
	if (kprobes_built_in() && !user_mode(regs)) {
73 74 75 76 77 78
		preempt_disable();
		if (kprobe_running() && kprobe_fault_handler(regs, 14))
			ret = 1;
		preempt_enable();
	}
	return ret;
M
Michael Grundy 已提交
79 80
}

L
Linus Torvalds 已提交
81 82 83

/*
 * Unlock any spinlocks which will prevent us from getting the
84
 * message out.
L
Linus Torvalds 已提交
85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105
 */
void bust_spinlocks(int yes)
{
	if (yes) {
		oops_in_progress = 1;
	} else {
		int loglevel_save = console_loglevel;
		console_unblank();
		oops_in_progress = 0;
		/*
		 * OK, the message is on the console.  Now we call printk()
		 * without oops_in_progress set so that printk will give klogd
		 * a poke.  Hold onto your hats...
		 */
		console_loglevel = 15;
		printk(" ");
		console_loglevel = loglevel_save;
	}
}

/*
106
 * Returns the address space associated with the fault.
107
 * Returns 0 for kernel space and 1 for user space.
L
Linus Torvalds 已提交
108
 */
109
static inline int user_space_fault(struct pt_regs *regs)
L
Linus Torvalds 已提交
110
{
111 112
	unsigned long trans_exc_code;

L
Linus Torvalds 已提交
113
	/*
114 115
	 * The lowest two bits of the translation exception
	 * identification indicate which paging table was used.
L
Linus Torvalds 已提交
116
	 */
117 118 119 120 121 122
	trans_exc_code = regs->int_parm_long & 3;
	if (trans_exc_code == 3) /* home space -> kernel */
		return 0;
	if (user_mode(regs))
		return 1;
	if (trans_exc_code == 2) /* secondary space -> set_fs */
123
		return current->thread.mm_segment.ar4;
124 125 126
	if (current->flags & PF_VCPU)
		return 1;
	return 0;
L
Linus Torvalds 已提交
127 128
}

129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255
static int bad_address(void *p)
{
	unsigned long dummy;

	return probe_kernel_address((unsigned long *)p, dummy);
}

#ifdef CONFIG_64BIT
static void dump_pagetable(unsigned long asce, unsigned long address)
{
	unsigned long *table = __va(asce & PAGE_MASK);

	pr_alert("AS:%016lx ", asce);
	switch (asce & _ASCE_TYPE_MASK) {
	case _ASCE_TYPE_REGION1:
		table = table + ((address >> 53) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R1:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION2:
		table = table + ((address >> 42) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R2:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION3:
		table = table + ((address >> 31) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R3:%016lx ", *table);
		if (*table & (_REGION_ENTRY_INVALID | _REGION3_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_SEGMENT:
		table = table + ((address >> 20) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont(KERN_CONT "S:%016lx ", *table);
		if (*table & (_SEGMENT_ENTRY_INVALID | _SEGMENT_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _SEGMENT_ENTRY_ORIGIN);
	}
	table = table + ((address >> 12) & 0xff);
	if (bad_address(table))
		goto bad;
	pr_cont("P:%016lx ", *table);
out:
	pr_cont("\n");
	return;
bad:
	pr_cont("BAD\n");
}

#else /* CONFIG_64BIT */

static void dump_pagetable(unsigned long asce, unsigned long address)
{
	unsigned long *table = __va(asce & PAGE_MASK);

	pr_alert("AS:%08lx ", asce);
	table = table + ((address >> 20) & 0x7ff);
	if (bad_address(table))
		goto bad;
	pr_cont("S:%08lx ", *table);
	if (*table & _SEGMENT_ENTRY_INVALID)
		goto out;
	table = (unsigned long *)(*table & _SEGMENT_ENTRY_ORIGIN);
	table = table + ((address >> 12) & 0xff);
	if (bad_address(table))
		goto bad;
	pr_cont("P:%08lx ", *table);
out:
	pr_cont("\n");
	return;
bad:
	pr_cont("BAD\n");
}

#endif /* CONFIG_64BIT */

static void dump_fault_info(struct pt_regs *regs)
{
	unsigned long asce;

	pr_alert("Fault in ");
	switch (regs->int_parm_long & 3) {
	case 3:
		pr_cont("home space ");
		break;
	case 2:
		pr_cont("secondary space ");
		break;
	case 1:
		pr_cont("access register ");
		break;
	case 0:
		pr_cont("primary space ");
		break;
	}
	pr_cont("mode while using ");
	if (!user_space_fault(regs)) {
		asce = S390_lowcore.kernel_asce;
		pr_cont("kernel ");
	}
#ifdef CONFIG_PGSTE
	else if ((current->flags & PF_VCPU) && S390_lowcore.gmap) {
		struct gmap *gmap = (struct gmap *)S390_lowcore.gmap;
		asce = gmap->asce;
		pr_cont("gmap ");
	}
#endif
	else {
		asce = S390_lowcore.user_asce;
		pr_cont("user ");
	}
	pr_cont("ASCE.\n");
	dump_pagetable(asce, regs->int_parm_long & __FAIL_ADDR_MASK);
}

M
Martin Schwidefsky 已提交
256
static inline void report_user_fault(struct pt_regs *regs, long signr)
257 258 259 260 261 262 263
{
	if ((task_pid_nr(current) > 1) && !show_unhandled_signals)
		return;
	if (!unhandled_signal(current, signr))
		return;
	if (!printk_ratelimit())
		return;
M
Martin Schwidefsky 已提交
264 265
	printk(KERN_ALERT "User process fault: interruption code 0x%X ",
	       regs->int_code);
266
	print_vma_addr(KERN_CONT "in ", regs->psw.addr & PSW_ADDR_INSN);
M
Martin Schwidefsky 已提交
267
	printk(KERN_CONT "\n");
268 269 270
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
271 272 273
	show_regs(regs);
}

L
Linus Torvalds 已提交
274 275 276 277
/*
 * Send SIGSEGV to task.  This is an external routine
 * to keep the stack usage of do_page_fault small.
 */
M
Martin Schwidefsky 已提交
278
static noinline void do_sigsegv(struct pt_regs *regs, int si_code)
L
Linus Torvalds 已提交
279 280 281
{
	struct siginfo si;

M
Martin Schwidefsky 已提交
282
	report_user_fault(regs, SIGSEGV);
L
Linus Torvalds 已提交
283 284
	si.si_signo = SIGSEGV;
	si.si_code = si_code;
M
Martin Schwidefsky 已提交
285
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
L
Linus Torvalds 已提交
286 287 288
	force_sig_info(SIGSEGV, &si, current);
}

M
Martin Schwidefsky 已提交
289
static noinline void do_no_context(struct pt_regs *regs)
290 291
{
	const struct exception_table_entry *fixup;
292
	unsigned long address;
293 294

	/* Are we prepared to handle this kernel fault?  */
295
	fixup = search_exception_tables(regs->psw.addr & PSW_ADDR_INSN);
296
	if (fixup) {
297
		regs->psw.addr = extable_fixup(fixup) | PSW_ADDR_AMODE;
298 299 300 301 302 303 304
		return;
	}

	/*
	 * Oops. The kernel tried to access some bad page. We'll have to
	 * terminate things with extreme prejudice.
	 */
M
Martin Schwidefsky 已提交
305
	address = regs->int_parm_long & __FAIL_ADDR_MASK;
306
	if (!user_space_fault(regs))
307
		printk(KERN_ALERT "Unable to handle kernel pointer dereference"
308
		       " in virtual kernel address space\n");
309 310
	else
		printk(KERN_ALERT "Unable to handle kernel paging request"
311 312 313 314
		       " in virtual user address space\n");
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
M
Martin Schwidefsky 已提交
315
	die(regs, "Oops");
316 317 318
	do_exit(SIGKILL);
}

M
Martin Schwidefsky 已提交
319
static noinline void do_low_address(struct pt_regs *regs)
320 321 322 323 324
{
	/* Low-address protection hit in kernel mode means
	   NULL pointer write access in kernel mode.  */
	if (regs->psw.mask & PSW_MASK_PSTATE) {
		/* Low-address protection hit in user mode 'cannot happen'. */
M
Martin Schwidefsky 已提交
325
		die (regs, "Low-address protection");
326 327 328
		do_exit(SIGKILL);
	}

M
Martin Schwidefsky 已提交
329
	do_no_context(regs);
330 331
}

M
Martin Schwidefsky 已提交
332
static noinline void do_sigbus(struct pt_regs *regs)
333 334
{
	struct task_struct *tsk = current;
M
Martin Schwidefsky 已提交
335
	struct siginfo si;
336 337 338 339 340

	/*
	 * Send a sigbus, regardless of whether we were in kernel
	 * or user mode.
	 */
M
Martin Schwidefsky 已提交
341 342 343
	si.si_signo = SIGBUS;
	si.si_errno = 0;
	si.si_code = BUS_ADRERR;
M
Martin Schwidefsky 已提交
344
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
M
Martin Schwidefsky 已提交
345
	force_sig_info(SIGBUS, &si, tsk);
346 347
}

M
Martin Schwidefsky 已提交
348
static noinline void do_fault_error(struct pt_regs *regs, int fault)
349 350 351 352 353 354 355
{
	int si_code;

	switch (fault) {
	case VM_FAULT_BADACCESS:
	case VM_FAULT_BADMAP:
		/* Bad memory access. Check if it is kernel or user space. */
356
		if (user_mode(regs)) {
357 358 359
			/* User mode accesses just cause a SIGSEGV */
			si_code = (fault == VM_FAULT_BADMAP) ?
				SEGV_MAPERR : SEGV_ACCERR;
M
Martin Schwidefsky 已提交
360
			do_sigsegv(regs, si_code);
361 362 363
			return;
		}
	case VM_FAULT_BADCONTEXT:
364
	case VM_FAULT_PFAULT:
M
Martin Schwidefsky 已提交
365
		do_no_context(regs);
366
		break;
367 368 369 370
	case VM_FAULT_SIGNAL:
		if (!user_mode(regs))
			do_no_context(regs);
		break;
371
	default: /* fault & VM_FAULT_ERROR */
372
		if (fault & VM_FAULT_OOM) {
373
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
374
				do_no_context(regs);
375 376 377
			else
				pagefault_out_of_memory();
		} else if (fault & VM_FAULT_SIGBUS) {
378
			/* Kernel mode? Handle exceptions or die */
379
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
380
				do_no_context(regs);
M
Martin Schwidefsky 已提交
381
			else
M
Martin Schwidefsky 已提交
382
				do_sigbus(regs);
383 384 385 386 387 388
		} else
			BUG();
		break;
	}
}

L
Linus Torvalds 已提交
389 390 391 392 393
/*
 * This routine handles page faults.  It determines the address,
 * and the problem, and then passes it off to one of the appropriate
 * routines.
 *
394
 * interruption code (int_code):
L
Linus Torvalds 已提交
395 396 397 398 399
 *   04       Protection           ->  Write-Protection  (suprression)
 *   10       Segment translation  ->  Not present       (nullification)
 *   11       Page translation     ->  Not present       (nullification)
 *   3b       Region third trans.  ->  Not present       (nullification)
 */
M
Martin Schwidefsky 已提交
400
static inline int do_exception(struct pt_regs *regs, int access)
L
Linus Torvalds 已提交
401
{
402 403 404
#ifdef CONFIG_PGSTE
	struct gmap *gmap;
#endif
405 406 407
	struct task_struct *tsk;
	struct mm_struct *mm;
	struct vm_area_struct *vma;
M
Martin Schwidefsky 已提交
408
	unsigned long trans_exc_code;
409
	unsigned long address;
410 411
	unsigned int flags;
	int fault;
L
Linus Torvalds 已提交
412

413 414 415 416 417
	tsk = current;
	/*
	 * The instruction that caused the program check has
	 * been nullified. Don't signal single step via SIGTRAP.
	 */
418
	clear_pt_regs_flag(regs, PIF_PER_TRAP);
419

420
	if (notify_page_fault(regs))
421
		return 0;
M
Michael Grundy 已提交
422

423
	mm = tsk->mm;
M
Martin Schwidefsky 已提交
424
	trans_exc_code = regs->int_parm_long;
L
Linus Torvalds 已提交
425 426 427 428 429 430

	/*
	 * Verify that the fault happened in user space, that
	 * we are not in an interrupt and that there is a 
	 * user context.
	 */
431
	fault = VM_FAULT_BADCONTEXT;
432
	if (unlikely(!user_space_fault(regs) || in_atomic() || !mm))
433
		goto out;
L
Linus Torvalds 已提交
434

435
	address = trans_exc_code & __FAIL_ADDR_MASK;
436
	perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS, 1, regs, address);
437
	flags = FAULT_FLAG_ALLOW_RETRY | FAULT_FLAG_KILLABLE;
438 439
	if (user_mode(regs))
		flags |= FAULT_FLAG_USER;
440 441
	if (access == VM_WRITE || (trans_exc_code & store_indication) == 0x400)
		flags |= FAULT_FLAG_WRITE;
442
	down_read(&mm->mmap_sem);
L
Linus Torvalds 已提交
443

444
#ifdef CONFIG_PGSTE
445 446
	gmap = (current->flags & PF_VCPU) ?
		(struct gmap *) S390_lowcore.gmap : NULL;
447
	if (gmap) {
448 449
		current->thread.gmap_addr = address;
		address = __gmap_translate(gmap, address);
450 451 452 453
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
454 455
		if (gmap->pfault_enabled)
			flags |= FAULT_FLAG_RETRY_NOWAIT;
456 457 458 459
	}
#endif

retry:
460
	fault = VM_FAULT_BADMAP;
461 462
	vma = find_vma(mm, address);
	if (!vma)
463
		goto out_up;
G
Gerald Schaefer 已提交
464

465 466 467 468 469 470 471 472 473 474 475 476
	if (unlikely(vma->vm_start > address)) {
		if (!(vma->vm_flags & VM_GROWSDOWN))
			goto out_up;
		if (expand_stack(vma, address))
			goto out_up;
	}

	/*
	 * Ok, we have a good vm_area for this memory access, so
	 * we can handle it..
	 */
	fault = VM_FAULT_BADACCESS;
477
	if (unlikely(!(vma->vm_flags & access)))
478
		goto out_up;
L
Linus Torvalds 已提交
479

480 481
	if (is_vm_hugetlb_page(vma))
		address &= HPAGE_MASK;
L
Linus Torvalds 已提交
482 483 484 485 486
	/*
	 * If for any reason at all we couldn't handle the fault,
	 * make sure we exit gracefully rather than endlessly redo
	 * the fault.
	 */
487
	fault = handle_mm_fault(mm, vma, address, flags);
488 489 490 491 492
	/* No reason to continue if interrupted by SIGKILL. */
	if ((fault & VM_FAULT_RETRY) && fatal_signal_pending(current)) {
		fault = VM_FAULT_SIGNAL;
		goto out;
	}
493 494 495
	if (unlikely(fault & VM_FAULT_ERROR))
		goto out_up;

496 497 498 499 500 501 502 503
	/*
	 * Major/minor page fault accounting is only done on the
	 * initial attempt. If we go through a retry, it is extremely
	 * likely that the page will be found in page cache at that point.
	 */
	if (flags & FAULT_FLAG_ALLOW_RETRY) {
		if (fault & VM_FAULT_MAJOR) {
			tsk->maj_flt++;
504
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MAJ, 1,
505 506 507
				      regs, address);
		} else {
			tsk->min_flt++;
508
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MIN, 1,
509 510 511
				      regs, address);
		}
		if (fault & VM_FAULT_RETRY) {
512 513 514 515 516 517 518 519 520
#ifdef CONFIG_PGSTE
			if (gmap && (flags & FAULT_FLAG_RETRY_NOWAIT)) {
				/* FAULT_FLAG_RETRY_NOWAIT has been set,
				 * mmap_sem has not been released */
				current->thread.gmap_pfault = 1;
				fault = VM_FAULT_PFAULT;
				goto out_up;
			}
#endif
521 522
			/* Clear FAULT_FLAG_ALLOW_RETRY to avoid any risk
			 * of starvation. */
523 524
			flags &= ~(FAULT_FLAG_ALLOW_RETRY |
				   FAULT_FLAG_RETRY_NOWAIT);
525
			flags |= FAULT_FLAG_TRIED;
526
			down_read(&mm->mmap_sem);
527 528
			goto retry;
		}
529
	}
530 531 532 533 534 535 536 537 538 539 540 541 542 543
#ifdef CONFIG_PGSTE
	if (gmap) {
		address =  __gmap_link(gmap, current->thread.gmap_addr,
				       address);
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
		if (address == -ENOMEM) {
			fault = VM_FAULT_OOM;
			goto out_up;
		}
	}
#endif
544 545
	fault = 0;
out_up:
546
	up_read(&mm->mmap_sem);
547 548
out:
	return fault;
L
Linus Torvalds 已提交
549 550
}

551
void do_protection_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
552
{
M
Martin Schwidefsky 已提交
553
	unsigned long trans_exc_code;
554
	int fault;
555

M
Martin Schwidefsky 已提交
556
	trans_exc_code = regs->int_parm_long;
557 558 559 560 561 562 563
	/*
	 * Protection exceptions are suppressing, decrement psw address.
	 * The exception to this rule are aborted transactions, for these
	 * the PSW already points to the correct location.
	 */
	if (!(regs->int_code & 0x200))
		regs->psw.addr = __rewind_psw(regs->psw, regs->int_code >> 16);
564 565 566 567 568
	/*
	 * Check for low-address protection.  This needs to be treated
	 * as a special case because the translation exception code
	 * field is not guaranteed to contain valid data in this case.
	 */
569
	if (unlikely(!(trans_exc_code & 4))) {
M
Martin Schwidefsky 已提交
570
		do_low_address(regs);
571 572
		return;
	}
M
Martin Schwidefsky 已提交
573
	fault = do_exception(regs, VM_WRITE);
574
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
575
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
576
}
577
NOKPROBE_SYMBOL(do_protection_exception);
L
Linus Torvalds 已提交
578

579
void do_dat_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
580
{
581
	int access, fault;
582

583
	access = VM_READ | VM_EXEC | VM_WRITE;
M
Martin Schwidefsky 已提交
584
	fault = do_exception(regs, access);
585
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
586
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
587
}
588
NOKPROBE_SYMBOL(do_dat_exception);
L
Linus Torvalds 已提交
589 590 591 592 593

#ifdef CONFIG_PFAULT 
/*
 * 'pfault' pseudo page faults routines.
 */
594
static int pfault_disable;
L
Linus Torvalds 已提交
595 596 597 598 599 600 601 602 603

static int __init nopfault(char *str)
{
	pfault_disable = 1;
	return 1;
}

__setup("nopfault", nopfault);

H
Heiko Carstens 已提交
604 605 606 607 608 609 610 611 612 613
struct pfault_refbk {
	u16 refdiagc;
	u16 reffcode;
	u16 refdwlen;
	u16 refversn;
	u64 refgaddr;
	u64 refselmk;
	u64 refcmpmk;
	u64 reserved;
} __attribute__ ((packed, aligned(8)));
L
Linus Torvalds 已提交
614 615 616

int pfault_init(void)
{
H
Heiko Carstens 已提交
617 618 619 620 621 622 623 624 625
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 0,
		.refdwlen = 5,
		.refversn = 2,
		.refgaddr = __LC_CURRENT_PID,
		.refselmk = 1ULL << 48,
		.refcmpmk = 1ULL << 48,
		.reserved = __PF_RES_FIELD };
L
Linus Torvalds 已提交
626 627
        int rc;

628
	if (pfault_disable)
L
Linus Torvalds 已提交
629
		return -1;
630 631 632 633
	asm volatile(
		"	diag	%1,%0,0x258\n"
		"0:	j	2f\n"
		"1:	la	%0,8\n"
L
Linus Torvalds 已提交
634
		"2:\n"
635 636
		EX_TABLE(0b,1b)
		: "=d" (rc) : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
637 638 639 640 641
        return rc;
}

void pfault_fini(void)
{
H
Heiko Carstens 已提交
642 643 644 645 646 647
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 1,
		.refdwlen = 5,
		.refversn = 2,
	};
L
Linus Torvalds 已提交
648

649
	if (pfault_disable)
L
Linus Torvalds 已提交
650
		return;
651 652
	asm volatile(
		"	diag	%0,0,0x258\n"
L
Linus Torvalds 已提交
653
		"0:\n"
654 655
		EX_TABLE(0b,0b)
		: : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
656 657
}

658 659 660
static DEFINE_SPINLOCK(pfault_lock);
static LIST_HEAD(pfault_list);

661
static void pfault_interrupt(struct ext_code ext_code,
662
			     unsigned int param32, unsigned long param64)
L
Linus Torvalds 已提交
663 664 665
{
	struct task_struct *tsk;
	__u16 subcode;
666
	pid_t pid;
L
Linus Torvalds 已提交
667 668 669 670 671 672 673

	/*
	 * Get the external interruption subcode & pfault
	 * initial/completion signal bit. VM stores this 
	 * in the 'cpu address' field associated with the
         * external interrupt. 
	 */
674
	subcode = ext_code.subcode;
L
Linus Torvalds 已提交
675 676
	if ((subcode & 0xff00) != __SUBCODE_MASK)
		return;
677
	inc_irq_stat(IRQEXT_PFL);
678 679 680 681 682 683 684 685 686
	/* Get the token (= pid of the affected task). */
	pid = sizeof(void *) == 4 ? param32 : param64;
	rcu_read_lock();
	tsk = find_task_by_pid_ns(pid, &init_pid_ns);
	if (tsk)
		get_task_struct(tsk);
	rcu_read_unlock();
	if (!tsk)
		return;
687
	spin_lock(&pfault_lock);
L
Linus Torvalds 已提交
688 689
	if (subcode & 0x0080) {
		/* signal bit is set -> a page has been swapped in by VM */
690
		if (tsk->thread.pfault_wait == 1) {
L
Linus Torvalds 已提交
691 692 693 694
			/* Initial interrupt was faster than the completion
			 * interrupt. pfault_wait is valid. Set pfault_wait
			 * back to zero and wake up the process. This can
			 * safely be done because the task is still sleeping
695
			 * and can't produce new pfaults. */
L
Linus Torvalds 已提交
696
			tsk->thread.pfault_wait = 0;
697
			list_del(&tsk->thread.list);
L
Linus Torvalds 已提交
698
			wake_up_process(tsk);
699
			put_task_struct(tsk);
700 701 702
		} else {
			/* Completion interrupt was faster than initial
			 * interrupt. Set pfault_wait to -1 so the initial
703 704 705 706 707 708 709
			 * interrupt doesn't put the task to sleep.
			 * If the task is not running, ignore the completion
			 * interrupt since it must be a leftover of a PFAULT
			 * CANCEL operation which didn't remove all pending
			 * completion interrupts. */
			if (tsk->state == TASK_RUNNING)
				tsk->thread.pfault_wait = -1;
L
Linus Torvalds 已提交
710 711 712
		}
	} else {
		/* signal bit not set -> a real page is missing. */
H
Heiko Carstens 已提交
713 714
		if (WARN_ON_ONCE(tsk != current))
			goto out;
715 716
		if (tsk->thread.pfault_wait == 1) {
			/* Already on the list with a reference: put to sleep */
717
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
718 719
			set_tsk_need_resched(tsk);
		} else if (tsk->thread.pfault_wait == -1) {
L
Linus Torvalds 已提交
720
			/* Completion interrupt was faster than the initial
721 722
			 * interrupt (pfault_wait == -1). Set pfault_wait
			 * back to zero and exit. */
L
Linus Torvalds 已提交
723
			tsk->thread.pfault_wait = 0;
724 725
		} else {
			/* Initial interrupt arrived before completion
726 727 728 729 730
			 * interrupt. Let the task sleep.
			 * An extra task reference is needed since a different
			 * cpu may set the task state to TASK_RUNNING again
			 * before the scheduler is reached. */
			get_task_struct(tsk);
731 732
			tsk->thread.pfault_wait = 1;
			list_add(&tsk->thread.list, &pfault_list);
733
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
L
Linus Torvalds 已提交
734
			set_tsk_need_resched(tsk);
735 736
		}
	}
H
Heiko Carstens 已提交
737
out:
738
	spin_unlock(&pfault_lock);
739
	put_task_struct(tsk);
740 741
}

742 743
static int pfault_cpu_notify(struct notifier_block *self, unsigned long action,
			     void *hcpu)
744 745 746 747
{
	struct thread_struct *thread, *next;
	struct task_struct *tsk;

748
	switch (action & ~CPU_TASKS_FROZEN) {
749 750 751 752 753 754 755
	case CPU_DEAD:
		spin_lock_irq(&pfault_lock);
		list_for_each_entry_safe(thread, next, &pfault_list, list) {
			thread->pfault_wait = 0;
			list_del(&thread->list);
			tsk = container_of(thread, struct task_struct, thread);
			wake_up_process(tsk);
756
			put_task_struct(tsk);
757 758 759 760 761
		}
		spin_unlock_irq(&pfault_lock);
		break;
	default:
		break;
L
Linus Torvalds 已提交
762
	}
763
	return NOTIFY_OK;
L
Linus Torvalds 已提交
764 765
}

766
static int __init pfault_irq_init(void)
H
Heiko Carstens 已提交
767
{
768
	int rc;
H
Heiko Carstens 已提交
769

770
	rc = register_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
771 772 773 774 775
	if (rc)
		goto out_extint;
	rc = pfault_init() == 0 ? 0 : -EOPNOTSUPP;
	if (rc)
		goto out_pfault;
776
	irq_subclass_register(IRQ_SUBCLASS_SERVICE_SIGNAL);
H
Heiko Carstens 已提交
777 778
	hotcpu_notifier(pfault_cpu_notify, 0);
	return 0;
H
Heiko Carstens 已提交
779

H
Heiko Carstens 已提交
780
out_pfault:
781
	unregister_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
782 783 784
out_extint:
	pfault_disable = 1;
	return rc;
H
Heiko Carstens 已提交
785
}
786 787
early_initcall(pfault_irq_init);

H
Heiko Carstens 已提交
788
#endif /* CONFIG_PFAULT */