fault.c 18.9 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 *  S390 version
3
 *    Copyright IBM Corp. 1999
L
Linus Torvalds 已提交
4 5 6 7 8 9 10
 *    Author(s): Hartmut Penner (hp@de.ibm.com)
 *               Ulrich Weigand (uweigand@de.ibm.com)
 *
 *  Derived from "arch/i386/mm/fault.c"
 *    Copyright (C) 1995  Linus Torvalds
 */

11
#include <linux/kernel_stat.h>
12
#include <linux/perf_event.h>
L
Linus Torvalds 已提交
13 14 15 16 17 18 19 20 21
#include <linux/signal.h>
#include <linux/sched.h>
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/types.h>
#include <linux/ptrace.h>
#include <linux/mman.h>
#include <linux/mm.h>
H
Heiko Carstens 已提交
22
#include <linux/compat.h>
L
Linus Torvalds 已提交
23
#include <linux/smp.h>
24
#include <linux/kdebug.h>
L
Linus Torvalds 已提交
25 26 27 28
#include <linux/init.h>
#include <linux/console.h>
#include <linux/module.h>
#include <linux/hardirq.h>
M
Michael Grundy 已提交
29
#include <linux/kprobes.h>
30
#include <linux/uaccess.h>
31
#include <linux/hugetlb.h>
32
#include <asm/asm-offsets.h>
33
#include <asm/diag.h>
L
Linus Torvalds 已提交
34
#include <asm/pgtable.h>
35
#include <asm/irq.h>
M
Martin Schwidefsky 已提交
36
#include <asm/mmu_context.h>
37
#include <asm/facility.h>
38
#include "../kernel/entry.h"
L
Linus Torvalds 已提交
39 40 41 42 43

#define __FAIL_ADDR_MASK -4096L
#define __SUBCODE_MASK 0x0600
#define __PF_RES_FIELD 0x8000000000000000ULL

44 45 46
#define VM_FAULT_BADCONTEXT	0x010000
#define VM_FAULT_BADMAP		0x020000
#define VM_FAULT_BADACCESS	0x040000
47
#define VM_FAULT_SIGNAL		0x080000
48
#define VM_FAULT_PFAULT		0x100000
49

50
static unsigned long store_indication __read_mostly;
51

52
static int __init fault_init(void)
53
{
54
	if (test_facility(75))
55
		store_indication = 0xc00;
56
	return 0;
57
}
58
early_initcall(fault_init);
59

60
static inline int notify_page_fault(struct pt_regs *regs)
61
{
62 63 64
	int ret = 0;

	/* kprobe_running() needs smp_processor_id() */
65
	if (kprobes_built_in() && !user_mode(regs)) {
66 67 68 69 70 71
		preempt_disable();
		if (kprobe_running() && kprobe_fault_handler(regs, 14))
			ret = 1;
		preempt_enable();
	}
	return ret;
M
Michael Grundy 已提交
72 73
}

L
Linus Torvalds 已提交
74 75 76

/*
 * Unlock any spinlocks which will prevent us from getting the
77
 * message out.
L
Linus Torvalds 已提交
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98
 */
void bust_spinlocks(int yes)
{
	if (yes) {
		oops_in_progress = 1;
	} else {
		int loglevel_save = console_loglevel;
		console_unblank();
		oops_in_progress = 0;
		/*
		 * OK, the message is on the console.  Now we call printk()
		 * without oops_in_progress set so that printk will give klogd
		 * a poke.  Hold onto your hats...
		 */
		console_loglevel = 15;
		printk(" ");
		console_loglevel = loglevel_save;
	}
}

/*
99
 * Returns the address space associated with the fault.
100
 * Returns 0 for kernel space and 1 for user space.
L
Linus Torvalds 已提交
101
 */
102
static inline int user_space_fault(struct pt_regs *regs)
L
Linus Torvalds 已提交
103
{
104 105
	unsigned long trans_exc_code;

L
Linus Torvalds 已提交
106
	/*
107 108
	 * The lowest two bits of the translation exception
	 * identification indicate which paging table was used.
L
Linus Torvalds 已提交
109
	 */
110 111 112 113 114 115
	trans_exc_code = regs->int_parm_long & 3;
	if (trans_exc_code == 3) /* home space -> kernel */
		return 0;
	if (user_mode(regs))
		return 1;
	if (trans_exc_code == 2) /* secondary space -> set_fs */
116
		return current->thread.mm_segment.ar4;
117 118 119
	if (current->flags & PF_VCPU)
		return 1;
	return 0;
L
Linus Torvalds 已提交
120 121
}

122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165
static int bad_address(void *p)
{
	unsigned long dummy;

	return probe_kernel_address((unsigned long *)p, dummy);
}

static void dump_pagetable(unsigned long asce, unsigned long address)
{
	unsigned long *table = __va(asce & PAGE_MASK);

	pr_alert("AS:%016lx ", asce);
	switch (asce & _ASCE_TYPE_MASK) {
	case _ASCE_TYPE_REGION1:
		table = table + ((address >> 53) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R1:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION2:
		table = table + ((address >> 42) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R2:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION3:
		table = table + ((address >> 31) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R3:%016lx ", *table);
		if (*table & (_REGION_ENTRY_INVALID | _REGION3_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_SEGMENT:
		table = table + ((address >> 20) & 0x7ff);
		if (bad_address(table))
			goto bad;
J
Joe Perches 已提交
166
		pr_cont("S:%016lx ", *table);
167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220
		if (*table & (_SEGMENT_ENTRY_INVALID | _SEGMENT_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _SEGMENT_ENTRY_ORIGIN);
	}
	table = table + ((address >> 12) & 0xff);
	if (bad_address(table))
		goto bad;
	pr_cont("P:%016lx ", *table);
out:
	pr_cont("\n");
	return;
bad:
	pr_cont("BAD\n");
}

static void dump_fault_info(struct pt_regs *regs)
{
	unsigned long asce;

	pr_alert("Fault in ");
	switch (regs->int_parm_long & 3) {
	case 3:
		pr_cont("home space ");
		break;
	case 2:
		pr_cont("secondary space ");
		break;
	case 1:
		pr_cont("access register ");
		break;
	case 0:
		pr_cont("primary space ");
		break;
	}
	pr_cont("mode while using ");
	if (!user_space_fault(regs)) {
		asce = S390_lowcore.kernel_asce;
		pr_cont("kernel ");
	}
#ifdef CONFIG_PGSTE
	else if ((current->flags & PF_VCPU) && S390_lowcore.gmap) {
		struct gmap *gmap = (struct gmap *)S390_lowcore.gmap;
		asce = gmap->asce;
		pr_cont("gmap ");
	}
#endif
	else {
		asce = S390_lowcore.user_asce;
		pr_cont("user ");
	}
	pr_cont("ASCE.\n");
	dump_pagetable(asce, regs->int_parm_long & __FAIL_ADDR_MASK);
}

M
Martin Schwidefsky 已提交
221
static inline void report_user_fault(struct pt_regs *regs, long signr)
222 223 224 225 226 227 228
{
	if ((task_pid_nr(current) > 1) && !show_unhandled_signals)
		return;
	if (!unhandled_signal(current, signr))
		return;
	if (!printk_ratelimit())
		return;
229
	printk(KERN_ALERT "User process fault: interruption code %04x ilc:%d ",
230
	       regs->int_code & 0xffff, regs->int_code >> 17);
231
	print_vma_addr(KERN_CONT "in ", regs->psw.addr & PSW_ADDR_INSN);
M
Martin Schwidefsky 已提交
232
	printk(KERN_CONT "\n");
233 234 235
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
236 237 238
	show_regs(regs);
}

L
Linus Torvalds 已提交
239 240 241 242
/*
 * Send SIGSEGV to task.  This is an external routine
 * to keep the stack usage of do_page_fault small.
 */
M
Martin Schwidefsky 已提交
243
static noinline void do_sigsegv(struct pt_regs *regs, int si_code)
L
Linus Torvalds 已提交
244 245 246
{
	struct siginfo si;

M
Martin Schwidefsky 已提交
247
	report_user_fault(regs, SIGSEGV);
L
Linus Torvalds 已提交
248 249
	si.si_signo = SIGSEGV;
	si.si_code = si_code;
M
Martin Schwidefsky 已提交
250
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
L
Linus Torvalds 已提交
251 252 253
	force_sig_info(SIGSEGV, &si, current);
}

M
Martin Schwidefsky 已提交
254
static noinline void do_no_context(struct pt_regs *regs)
255 256
{
	const struct exception_table_entry *fixup;
257
	unsigned long address;
258 259

	/* Are we prepared to handle this kernel fault?  */
260
	fixup = search_exception_tables(regs->psw.addr & PSW_ADDR_INSN);
261
	if (fixup) {
262
		regs->psw.addr = extable_fixup(fixup) | PSW_ADDR_AMODE;
263 264 265 266 267 268 269
		return;
	}

	/*
	 * Oops. The kernel tried to access some bad page. We'll have to
	 * terminate things with extreme prejudice.
	 */
M
Martin Schwidefsky 已提交
270
	address = regs->int_parm_long & __FAIL_ADDR_MASK;
271
	if (!user_space_fault(regs))
272
		printk(KERN_ALERT "Unable to handle kernel pointer dereference"
273
		       " in virtual kernel address space\n");
274 275
	else
		printk(KERN_ALERT "Unable to handle kernel paging request"
276 277 278 279
		       " in virtual user address space\n");
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
M
Martin Schwidefsky 已提交
280
	die(regs, "Oops");
281 282 283
	do_exit(SIGKILL);
}

M
Martin Schwidefsky 已提交
284
static noinline void do_low_address(struct pt_regs *regs)
285 286 287 288 289
{
	/* Low-address protection hit in kernel mode means
	   NULL pointer write access in kernel mode.  */
	if (regs->psw.mask & PSW_MASK_PSTATE) {
		/* Low-address protection hit in user mode 'cannot happen'. */
M
Martin Schwidefsky 已提交
290
		die (regs, "Low-address protection");
291 292 293
		do_exit(SIGKILL);
	}

M
Martin Schwidefsky 已提交
294
	do_no_context(regs);
295 296
}

M
Martin Schwidefsky 已提交
297
static noinline void do_sigbus(struct pt_regs *regs)
298 299
{
	struct task_struct *tsk = current;
M
Martin Schwidefsky 已提交
300
	struct siginfo si;
301 302 303 304 305

	/*
	 * Send a sigbus, regardless of whether we were in kernel
	 * or user mode.
	 */
M
Martin Schwidefsky 已提交
306 307 308
	si.si_signo = SIGBUS;
	si.si_errno = 0;
	si.si_code = BUS_ADRERR;
M
Martin Schwidefsky 已提交
309
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
M
Martin Schwidefsky 已提交
310
	force_sig_info(SIGBUS, &si, tsk);
311 312
}

M
Martin Schwidefsky 已提交
313
static noinline void do_fault_error(struct pt_regs *regs, int fault)
314 315 316 317 318 319 320
{
	int si_code;

	switch (fault) {
	case VM_FAULT_BADACCESS:
	case VM_FAULT_BADMAP:
		/* Bad memory access. Check if it is kernel or user space. */
321
		if (user_mode(regs)) {
322 323 324
			/* User mode accesses just cause a SIGSEGV */
			si_code = (fault == VM_FAULT_BADMAP) ?
				SEGV_MAPERR : SEGV_ACCERR;
M
Martin Schwidefsky 已提交
325
			do_sigsegv(regs, si_code);
326 327 328
			return;
		}
	case VM_FAULT_BADCONTEXT:
329
	case VM_FAULT_PFAULT:
M
Martin Schwidefsky 已提交
330
		do_no_context(regs);
331
		break;
332 333 334 335
	case VM_FAULT_SIGNAL:
		if (!user_mode(regs))
			do_no_context(regs);
		break;
336
	default: /* fault & VM_FAULT_ERROR */
337
		if (fault & VM_FAULT_OOM) {
338
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
339
				do_no_context(regs);
340 341
			else
				pagefault_out_of_memory();
342 343 344 345 346 347
		} else if (fault & VM_FAULT_SIGSEGV) {
			/* Kernel mode? Handle exceptions or die */
			if (!user_mode(regs))
				do_no_context(regs);
			else
				do_sigsegv(regs, SEGV_MAPERR);
348
		} else if (fault & VM_FAULT_SIGBUS) {
349
			/* Kernel mode? Handle exceptions or die */
350
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
351
				do_no_context(regs);
M
Martin Schwidefsky 已提交
352
			else
M
Martin Schwidefsky 已提交
353
				do_sigbus(regs);
354 355 356 357 358 359
		} else
			BUG();
		break;
	}
}

L
Linus Torvalds 已提交
360 361 362 363 364
/*
 * This routine handles page faults.  It determines the address,
 * and the problem, and then passes it off to one of the appropriate
 * routines.
 *
365
 * interruption code (int_code):
L
Linus Torvalds 已提交
366 367 368 369 370
 *   04       Protection           ->  Write-Protection  (suprression)
 *   10       Segment translation  ->  Not present       (nullification)
 *   11       Page translation     ->  Not present       (nullification)
 *   3b       Region third trans.  ->  Not present       (nullification)
 */
M
Martin Schwidefsky 已提交
371
static inline int do_exception(struct pt_regs *regs, int access)
L
Linus Torvalds 已提交
372
{
373 374 375
#ifdef CONFIG_PGSTE
	struct gmap *gmap;
#endif
376 377 378
	struct task_struct *tsk;
	struct mm_struct *mm;
	struct vm_area_struct *vma;
M
Martin Schwidefsky 已提交
379
	unsigned long trans_exc_code;
380
	unsigned long address;
381 382
	unsigned int flags;
	int fault;
L
Linus Torvalds 已提交
383

384 385 386 387 388
	tsk = current;
	/*
	 * The instruction that caused the program check has
	 * been nullified. Don't signal single step via SIGTRAP.
	 */
389
	clear_pt_regs_flag(regs, PIF_PER_TRAP);
390

391
	if (notify_page_fault(regs))
392
		return 0;
M
Michael Grundy 已提交
393

394
	mm = tsk->mm;
M
Martin Schwidefsky 已提交
395
	trans_exc_code = regs->int_parm_long;
L
Linus Torvalds 已提交
396 397 398 399 400 401

	/*
	 * Verify that the fault happened in user space, that
	 * we are not in an interrupt and that there is a 
	 * user context.
	 */
402
	fault = VM_FAULT_BADCONTEXT;
403
	if (unlikely(!user_space_fault(regs) || faulthandler_disabled() || !mm))
404
		goto out;
L
Linus Torvalds 已提交
405

406
	address = trans_exc_code & __FAIL_ADDR_MASK;
407
	perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS, 1, regs, address);
408
	flags = FAULT_FLAG_ALLOW_RETRY | FAULT_FLAG_KILLABLE;
409 410
	if (user_mode(regs))
		flags |= FAULT_FLAG_USER;
411 412
	if (access == VM_WRITE || (trans_exc_code & store_indication) == 0x400)
		flags |= FAULT_FLAG_WRITE;
413
	down_read(&mm->mmap_sem);
L
Linus Torvalds 已提交
414

415
#ifdef CONFIG_PGSTE
416 417
	gmap = (current->flags & PF_VCPU) ?
		(struct gmap *) S390_lowcore.gmap : NULL;
418
	if (gmap) {
419 420
		current->thread.gmap_addr = address;
		address = __gmap_translate(gmap, address);
421 422 423 424
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
425 426
		if (gmap->pfault_enabled)
			flags |= FAULT_FLAG_RETRY_NOWAIT;
427 428 429 430
	}
#endif

retry:
431
	fault = VM_FAULT_BADMAP;
432 433
	vma = find_vma(mm, address);
	if (!vma)
434
		goto out_up;
G
Gerald Schaefer 已提交
435

436 437 438 439 440 441 442 443 444 445 446 447
	if (unlikely(vma->vm_start > address)) {
		if (!(vma->vm_flags & VM_GROWSDOWN))
			goto out_up;
		if (expand_stack(vma, address))
			goto out_up;
	}

	/*
	 * Ok, we have a good vm_area for this memory access, so
	 * we can handle it..
	 */
	fault = VM_FAULT_BADACCESS;
448
	if (unlikely(!(vma->vm_flags & access)))
449
		goto out_up;
L
Linus Torvalds 已提交
450

451 452
	if (is_vm_hugetlb_page(vma))
		address &= HPAGE_MASK;
L
Linus Torvalds 已提交
453 454 455 456 457
	/*
	 * If for any reason at all we couldn't handle the fault,
	 * make sure we exit gracefully rather than endlessly redo
	 * the fault.
	 */
458
	fault = handle_mm_fault(mm, vma, address, flags);
459 460 461 462 463
	/* No reason to continue if interrupted by SIGKILL. */
	if ((fault & VM_FAULT_RETRY) && fatal_signal_pending(current)) {
		fault = VM_FAULT_SIGNAL;
		goto out;
	}
464 465 466
	if (unlikely(fault & VM_FAULT_ERROR))
		goto out_up;

467 468 469 470 471 472 473 474
	/*
	 * Major/minor page fault accounting is only done on the
	 * initial attempt. If we go through a retry, it is extremely
	 * likely that the page will be found in page cache at that point.
	 */
	if (flags & FAULT_FLAG_ALLOW_RETRY) {
		if (fault & VM_FAULT_MAJOR) {
			tsk->maj_flt++;
475
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MAJ, 1,
476 477 478
				      regs, address);
		} else {
			tsk->min_flt++;
479
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MIN, 1,
480 481 482
				      regs, address);
		}
		if (fault & VM_FAULT_RETRY) {
483 484 485 486 487 488 489 490 491
#ifdef CONFIG_PGSTE
			if (gmap && (flags & FAULT_FLAG_RETRY_NOWAIT)) {
				/* FAULT_FLAG_RETRY_NOWAIT has been set,
				 * mmap_sem has not been released */
				current->thread.gmap_pfault = 1;
				fault = VM_FAULT_PFAULT;
				goto out_up;
			}
#endif
492 493
			/* Clear FAULT_FLAG_ALLOW_RETRY to avoid any risk
			 * of starvation. */
494 495
			flags &= ~(FAULT_FLAG_ALLOW_RETRY |
				   FAULT_FLAG_RETRY_NOWAIT);
496
			flags |= FAULT_FLAG_TRIED;
497
			down_read(&mm->mmap_sem);
498 499
			goto retry;
		}
500
	}
501 502 503 504 505 506 507 508 509 510 511 512 513 514
#ifdef CONFIG_PGSTE
	if (gmap) {
		address =  __gmap_link(gmap, current->thread.gmap_addr,
				       address);
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
		if (address == -ENOMEM) {
			fault = VM_FAULT_OOM;
			goto out_up;
		}
	}
#endif
515 516
	fault = 0;
out_up:
517
	up_read(&mm->mmap_sem);
518 519
out:
	return fault;
L
Linus Torvalds 已提交
520 521
}

522
void do_protection_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
523
{
M
Martin Schwidefsky 已提交
524
	unsigned long trans_exc_code;
525
	int fault;
526

M
Martin Schwidefsky 已提交
527
	trans_exc_code = regs->int_parm_long;
528 529 530 531 532 533 534
	/*
	 * Protection exceptions are suppressing, decrement psw address.
	 * The exception to this rule are aborted transactions, for these
	 * the PSW already points to the correct location.
	 */
	if (!(regs->int_code & 0x200))
		regs->psw.addr = __rewind_psw(regs->psw, regs->int_code >> 16);
535 536 537 538 539
	/*
	 * Check for low-address protection.  This needs to be treated
	 * as a special case because the translation exception code
	 * field is not guaranteed to contain valid data in this case.
	 */
540
	if (unlikely(!(trans_exc_code & 4))) {
M
Martin Schwidefsky 已提交
541
		do_low_address(regs);
542 543
		return;
	}
M
Martin Schwidefsky 已提交
544
	fault = do_exception(regs, VM_WRITE);
545
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
546
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
547
}
548
NOKPROBE_SYMBOL(do_protection_exception);
L
Linus Torvalds 已提交
549

550
void do_dat_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
551
{
552
	int access, fault;
553

554
	access = VM_READ | VM_EXEC | VM_WRITE;
M
Martin Schwidefsky 已提交
555
	fault = do_exception(regs, access);
556
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
557
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
558
}
559
NOKPROBE_SYMBOL(do_dat_exception);
L
Linus Torvalds 已提交
560 561 562 563 564

#ifdef CONFIG_PFAULT 
/*
 * 'pfault' pseudo page faults routines.
 */
565
static int pfault_disable;
L
Linus Torvalds 已提交
566 567 568 569 570 571 572 573 574

static int __init nopfault(char *str)
{
	pfault_disable = 1;
	return 1;
}

__setup("nopfault", nopfault);

H
Heiko Carstens 已提交
575 576 577 578 579 580 581 582 583 584
struct pfault_refbk {
	u16 refdiagc;
	u16 reffcode;
	u16 refdwlen;
	u16 refversn;
	u64 refgaddr;
	u64 refselmk;
	u64 refcmpmk;
	u64 reserved;
} __attribute__ ((packed, aligned(8)));
L
Linus Torvalds 已提交
585 586 587

int pfault_init(void)
{
H
Heiko Carstens 已提交
588 589 590 591 592 593 594 595 596
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 0,
		.refdwlen = 5,
		.refversn = 2,
		.refgaddr = __LC_CURRENT_PID,
		.refselmk = 1ULL << 48,
		.refcmpmk = 1ULL << 48,
		.reserved = __PF_RES_FIELD };
L
Linus Torvalds 已提交
597 598
        int rc;

599
	if (pfault_disable)
L
Linus Torvalds 已提交
600
		return -1;
601
	diag_stat_inc(DIAG_STAT_X258);
602 603 604 605
	asm volatile(
		"	diag	%1,%0,0x258\n"
		"0:	j	2f\n"
		"1:	la	%0,8\n"
L
Linus Torvalds 已提交
606
		"2:\n"
607 608
		EX_TABLE(0b,1b)
		: "=d" (rc) : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
609 610 611 612 613
        return rc;
}

void pfault_fini(void)
{
H
Heiko Carstens 已提交
614 615 616 617 618 619
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 1,
		.refdwlen = 5,
		.refversn = 2,
	};
L
Linus Torvalds 已提交
620

621
	if (pfault_disable)
L
Linus Torvalds 已提交
622
		return;
623
	diag_stat_inc(DIAG_STAT_X258);
624 625
	asm volatile(
		"	diag	%0,0,0x258\n"
L
Linus Torvalds 已提交
626
		"0:\n"
627 628
		EX_TABLE(0b,0b)
		: : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
629 630
}

631 632 633
static DEFINE_SPINLOCK(pfault_lock);
static LIST_HEAD(pfault_list);

634
static void pfault_interrupt(struct ext_code ext_code,
635
			     unsigned int param32, unsigned long param64)
L
Linus Torvalds 已提交
636 637 638
{
	struct task_struct *tsk;
	__u16 subcode;
639
	pid_t pid;
L
Linus Torvalds 已提交
640 641 642 643 644 645 646

	/*
	 * Get the external interruption subcode & pfault
	 * initial/completion signal bit. VM stores this 
	 * in the 'cpu address' field associated with the
         * external interrupt. 
	 */
647
	subcode = ext_code.subcode;
L
Linus Torvalds 已提交
648 649
	if ((subcode & 0xff00) != __SUBCODE_MASK)
		return;
650
	inc_irq_stat(IRQEXT_PFL);
651
	/* Get the token (= pid of the affected task). */
652
	pid = param64;
653 654 655 656 657 658 659
	rcu_read_lock();
	tsk = find_task_by_pid_ns(pid, &init_pid_ns);
	if (tsk)
		get_task_struct(tsk);
	rcu_read_unlock();
	if (!tsk)
		return;
660
	spin_lock(&pfault_lock);
L
Linus Torvalds 已提交
661 662
	if (subcode & 0x0080) {
		/* signal bit is set -> a page has been swapped in by VM */
663
		if (tsk->thread.pfault_wait == 1) {
L
Linus Torvalds 已提交
664 665 666 667
			/* Initial interrupt was faster than the completion
			 * interrupt. pfault_wait is valid. Set pfault_wait
			 * back to zero and wake up the process. This can
			 * safely be done because the task is still sleeping
668
			 * and can't produce new pfaults. */
L
Linus Torvalds 已提交
669
			tsk->thread.pfault_wait = 0;
670
			list_del(&tsk->thread.list);
L
Linus Torvalds 已提交
671
			wake_up_process(tsk);
672
			put_task_struct(tsk);
673 674 675
		} else {
			/* Completion interrupt was faster than initial
			 * interrupt. Set pfault_wait to -1 so the initial
676 677 678 679 680 681 682
			 * interrupt doesn't put the task to sleep.
			 * If the task is not running, ignore the completion
			 * interrupt since it must be a leftover of a PFAULT
			 * CANCEL operation which didn't remove all pending
			 * completion interrupts. */
			if (tsk->state == TASK_RUNNING)
				tsk->thread.pfault_wait = -1;
L
Linus Torvalds 已提交
683 684 685
		}
	} else {
		/* signal bit not set -> a real page is missing. */
H
Heiko Carstens 已提交
686 687
		if (WARN_ON_ONCE(tsk != current))
			goto out;
688 689
		if (tsk->thread.pfault_wait == 1) {
			/* Already on the list with a reference: put to sleep */
690
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
691 692
			set_tsk_need_resched(tsk);
		} else if (tsk->thread.pfault_wait == -1) {
L
Linus Torvalds 已提交
693
			/* Completion interrupt was faster than the initial
694 695
			 * interrupt (pfault_wait == -1). Set pfault_wait
			 * back to zero and exit. */
L
Linus Torvalds 已提交
696
			tsk->thread.pfault_wait = 0;
697 698
		} else {
			/* Initial interrupt arrived before completion
699 700 701 702 703
			 * interrupt. Let the task sleep.
			 * An extra task reference is needed since a different
			 * cpu may set the task state to TASK_RUNNING again
			 * before the scheduler is reached. */
			get_task_struct(tsk);
704 705
			tsk->thread.pfault_wait = 1;
			list_add(&tsk->thread.list, &pfault_list);
706
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
L
Linus Torvalds 已提交
707
			set_tsk_need_resched(tsk);
708 709
		}
	}
H
Heiko Carstens 已提交
710
out:
711
	spin_unlock(&pfault_lock);
712
	put_task_struct(tsk);
713 714
}

715 716
static int pfault_cpu_notify(struct notifier_block *self, unsigned long action,
			     void *hcpu)
717 718 719 720
{
	struct thread_struct *thread, *next;
	struct task_struct *tsk;

721
	switch (action & ~CPU_TASKS_FROZEN) {
722 723 724 725 726 727 728
	case CPU_DEAD:
		spin_lock_irq(&pfault_lock);
		list_for_each_entry_safe(thread, next, &pfault_list, list) {
			thread->pfault_wait = 0;
			list_del(&thread->list);
			tsk = container_of(thread, struct task_struct, thread);
			wake_up_process(tsk);
729
			put_task_struct(tsk);
730 731 732 733 734
		}
		spin_unlock_irq(&pfault_lock);
		break;
	default:
		break;
L
Linus Torvalds 已提交
735
	}
736
	return NOTIFY_OK;
L
Linus Torvalds 已提交
737 738
}

739
static int __init pfault_irq_init(void)
H
Heiko Carstens 已提交
740
{
741
	int rc;
H
Heiko Carstens 已提交
742

743
	rc = register_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
744 745 746 747 748
	if (rc)
		goto out_extint;
	rc = pfault_init() == 0 ? 0 : -EOPNOTSUPP;
	if (rc)
		goto out_pfault;
749
	irq_subclass_register(IRQ_SUBCLASS_SERVICE_SIGNAL);
H
Heiko Carstens 已提交
750 751
	hotcpu_notifier(pfault_cpu_notify, 0);
	return 0;
H
Heiko Carstens 已提交
752

H
Heiko Carstens 已提交
753
out_pfault:
754
	unregister_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
755 756 757
out_extint:
	pfault_disable = 1;
	return rc;
H
Heiko Carstens 已提交
758
}
759 760
early_initcall(pfault_irq_init);

H
Heiko Carstens 已提交
761
#endif /* CONFIG_PFAULT */