inode.c 34.4 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 * hugetlbpage-backed filesystem.  Based on ramfs.
 *
4
 * Nadia Yvette Chambers, 2002
L
Linus Torvalds 已提交
5 6 7 8
 *
 * Copyright (C) 2002 Linus Torvalds.
 */

9 10
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

L
Linus Torvalds 已提交
11 12 13 14
#include <linux/module.h>
#include <linux/thread_info.h>
#include <asm/current.h>
#include <linux/sched.h>		/* remove ASAP */
15
#include <linux/falloc.h>
L
Linus Torvalds 已提交
16 17 18
#include <linux/fs.h>
#include <linux/mount.h>
#include <linux/file.h>
19
#include <linux/kernel.h>
L
Linus Torvalds 已提交
20 21 22 23 24
#include <linux/writeback.h>
#include <linux/pagemap.h>
#include <linux/highmem.h>
#include <linux/init.h>
#include <linux/string.h>
25
#include <linux/capability.h>
26
#include <linux/ctype.h>
L
Linus Torvalds 已提交
27 28 29
#include <linux/backing-dev.h>
#include <linux/hugetlb.h>
#include <linux/pagevec.h>
30
#include <linux/parser.h>
31
#include <linux/mman.h>
L
Linus Torvalds 已提交
32 33 34 35
#include <linux/slab.h>
#include <linux/dnotify.h>
#include <linux/statfs.h>
#include <linux/security.h>
N
Nick Black 已提交
36
#include <linux/magic.h>
N
Naoya Horiguchi 已提交
37
#include <linux/migrate.h>
A
Al Viro 已提交
38
#include <linux/uio.h>
L
Linus Torvalds 已提交
39 40 41

#include <asm/uaccess.h>

42
static const struct super_operations hugetlbfs_ops;
43
static const struct address_space_operations hugetlbfs_aops;
44
const struct file_operations hugetlbfs_file_operations;
45 46
static const struct inode_operations hugetlbfs_dir_inode_operations;
static const struct inode_operations hugetlbfs_inode_operations;
L
Linus Torvalds 已提交
47

D
David Gibson 已提交
48
struct hugetlbfs_config {
49 50
	kuid_t   uid;
	kgid_t   gid;
D
David Gibson 已提交
51
	umode_t mode;
52
	long	max_hpages;
D
David Gibson 已提交
53 54
	long	nr_inodes;
	struct hstate *hstate;
55
	long    min_hpages;
D
David Gibson 已提交
56 57 58 59 60 61 62 63 64 65 66 67
};

struct hugetlbfs_inode_info {
	struct shared_policy policy;
	struct inode vfs_inode;
};

static inline struct hugetlbfs_inode_info *HUGETLBFS_I(struct inode *inode)
{
	return container_of(inode, struct hugetlbfs_inode_info, vfs_inode);
}

L
Linus Torvalds 已提交
68 69
int sysctl_hugetlb_shm_group;

70 71 72
enum {
	Opt_size, Opt_nr_inodes,
	Opt_mode, Opt_uid, Opt_gid,
73
	Opt_pagesize, Opt_min_size,
74 75 76
	Opt_err,
};

77
static const match_table_t tokens = {
78 79 80 81 82
	{Opt_size,	"size=%s"},
	{Opt_nr_inodes,	"nr_inodes=%s"},
	{Opt_mode,	"mode=%o"},
	{Opt_uid,	"uid=%u"},
	{Opt_gid,	"gid=%u"},
83
	{Opt_pagesize,	"pagesize=%s"},
84
	{Opt_min_size,	"min_size=%s"},
85 86 87
	{Opt_err,	NULL},
};

88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110
#ifdef CONFIG_NUMA
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
	vma->vm_policy = mpol_shared_policy_lookup(&HUGETLBFS_I(inode)->policy,
							index);
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
	mpol_cond_put(vma->vm_policy);
}
#else
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
}
#endif

111 112 113 114 115 116 117 118 119 120
static void huge_pagevec_release(struct pagevec *pvec)
{
	int i;

	for (i = 0; i < pagevec_count(pvec); ++i)
		put_page(pvec->pages[i]);

	pagevec_reinit(pvec);
}

L
Linus Torvalds 已提交
121 122
static int hugetlbfs_file_mmap(struct file *file, struct vm_area_struct *vma)
{
A
Al Viro 已提交
123
	struct inode *inode = file_inode(file);
L
Linus Torvalds 已提交
124 125
	loff_t len, vma_len;
	int ret;
126
	struct hstate *h = hstate_file(file);
L
Linus Torvalds 已提交
127

128
	/*
129 130 131 132 133 134
	 * vma address alignment (but not the pgoff alignment) has
	 * already been checked by prepare_hugepage_range.  If you add
	 * any error returns here, do so after setting VM_HUGETLB, so
	 * is_vm_hugetlb_page tests below unmap_region go the right
	 * way when do_mmap_pgoff unwinds (may be important on powerpc
	 * and ia64).
135
	 */
136
	vma->vm_flags |= VM_HUGETLB | VM_DONTEXPAND;
137
	vma->vm_ops = &hugetlb_vm_ops;
L
Linus Torvalds 已提交
138

139
	if (vma->vm_pgoff & (~huge_page_mask(h) >> PAGE_SHIFT))
140 141
		return -EINVAL;

L
Linus Torvalds 已提交
142 143
	vma_len = (loff_t)(vma->vm_end - vma->vm_start);

144
	mutex_lock(&inode->i_mutex);
L
Linus Torvalds 已提交
145 146 147 148 149
	file_accessed(file);

	ret = -ENOMEM;
	len = vma_len + ((loff_t)vma->vm_pgoff << PAGE_SHIFT);

150
	if (hugetlb_reserve_pages(inode,
151
				vma->vm_pgoff >> huge_page_order(h),
152 153
				len >> huge_page_shift(h), vma,
				vma->vm_flags))
154
		goto out;
155

A
Adam Litke 已提交
156
	ret = 0;
157
	if (vma->vm_flags & VM_WRITE && inode->i_size < len)
L
Linus Torvalds 已提交
158 159
		inode->i_size = len;
out:
160
	mutex_unlock(&inode->i_mutex);
L
Linus Torvalds 已提交
161 162 163 164 165

	return ret;
}

/*
166
 * Called under down_write(mmap_sem).
L
Linus Torvalds 已提交
167 168
 */

169
#ifndef HAVE_ARCH_HUGETLB_UNMAPPED_AREA
L
Linus Torvalds 已提交
170 171 172 173 174 175
static unsigned long
hugetlb_get_unmapped_area(struct file *file, unsigned long addr,
		unsigned long len, unsigned long pgoff, unsigned long flags)
{
	struct mm_struct *mm = current->mm;
	struct vm_area_struct *vma;
176
	struct hstate *h = hstate_file(file);
177
	struct vm_unmapped_area_info info;
L
Linus Torvalds 已提交
178

179
	if (len & ~huge_page_mask(h))
L
Linus Torvalds 已提交
180 181 182 183
		return -EINVAL;
	if (len > TASK_SIZE)
		return -ENOMEM;

184
	if (flags & MAP_FIXED) {
185
		if (prepare_hugepage_range(file, addr, len))
186 187 188 189
			return -EINVAL;
		return addr;
	}

L
Linus Torvalds 已提交
190
	if (addr) {
191
		addr = ALIGN(addr, huge_page_size(h));
L
Linus Torvalds 已提交
192 193 194 195 196 197
		vma = find_vma(mm, addr);
		if (TASK_SIZE - len >= addr &&
		    (!vma || addr + len <= vma->vm_start))
			return addr;
	}

198 199 200 201 202 203 204
	info.flags = 0;
	info.length = len;
	info.low_limit = TASK_UNMAPPED_BASE;
	info.high_limit = TASK_SIZE;
	info.align_mask = PAGE_MASK & ~huge_page_mask(h);
	info.align_offset = 0;
	return vm_unmapped_area(&info);
L
Linus Torvalds 已提交
205 206 207
}
#endif

A
Al Viro 已提交
208
static size_t
B
Badari Pulavarty 已提交
209
hugetlbfs_read_actor(struct page *page, unsigned long offset,
A
Al Viro 已提交
210
			struct iov_iter *to, unsigned long size)
B
Badari Pulavarty 已提交
211
{
A
Al Viro 已提交
212
	size_t copied = 0;
B
Badari Pulavarty 已提交
213 214 215 216 217 218 219
	int i, chunksize;

	/* Find which 4k chunk and offset with in that chunk */
	i = offset >> PAGE_CACHE_SHIFT;
	offset = offset & ~PAGE_CACHE_MASK;

	while (size) {
A
Al Viro 已提交
220
		size_t n;
B
Badari Pulavarty 已提交
221 222 223 224 225
		chunksize = PAGE_CACHE_SIZE;
		if (offset)
			chunksize -= offset;
		if (chunksize > size)
			chunksize = size;
A
Al Viro 已提交
226 227 228 229
		n = copy_page_to_iter(&page[i], offset, chunksize, to);
		copied += n;
		if (n != chunksize)
			return copied;
B
Badari Pulavarty 已提交
230 231 232 233
		offset = 0;
		size -= chunksize;
		i++;
	}
A
Al Viro 已提交
234
	return copied;
B
Badari Pulavarty 已提交
235 236 237 238 239 240 241
}

/*
 * Support for read() - Find the page attached to f_mapping and copy out the
 * data. Its *very* similar to do_generic_mapping_read(), we can't use that
 * since it has PAGE_CACHE_SIZE assumptions.
 */
A
Al Viro 已提交
242
static ssize_t hugetlbfs_read_iter(struct kiocb *iocb, struct iov_iter *to)
B
Badari Pulavarty 已提交
243
{
A
Al Viro 已提交
244 245 246
	struct file *file = iocb->ki_filp;
	struct hstate *h = hstate_file(file);
	struct address_space *mapping = file->f_mapping;
B
Badari Pulavarty 已提交
247
	struct inode *inode = mapping->host;
A
Al Viro 已提交
248 249
	unsigned long index = iocb->ki_pos >> huge_page_shift(h);
	unsigned long offset = iocb->ki_pos & ~huge_page_mask(h);
B
Badari Pulavarty 已提交
250 251 252 253
	unsigned long end_index;
	loff_t isize;
	ssize_t retval = 0;

A
Al Viro 已提交
254
	while (iov_iter_count(to)) {
B
Badari Pulavarty 已提交
255
		struct page *page;
A
Al Viro 已提交
256
		size_t nr, copied;
B
Badari Pulavarty 已提交
257 258

		/* nr is the maximum number of bytes to copy from this page */
259
		nr = huge_page_size(h);
260 261
		isize = i_size_read(inode);
		if (!isize)
A
Al Viro 已提交
262
			break;
263
		end_index = (isize - 1) >> huge_page_shift(h);
A
Al Viro 已提交
264 265 266
		if (index > end_index)
			break;
		if (index == end_index) {
267
			nr = ((isize - 1) & ~huge_page_mask(h)) + 1;
268
			if (nr <= offset)
A
Al Viro 已提交
269
				break;
B
Badari Pulavarty 已提交
270 271 272 273
		}
		nr = nr - offset;

		/* Find the page */
274
		page = find_lock_page(mapping, index);
B
Badari Pulavarty 已提交
275 276 277 278 279
		if (unlikely(page == NULL)) {
			/*
			 * We have a HOLE, zero out the user-buffer for the
			 * length of the hole or request.
			 */
A
Al Viro 已提交
280
			copied = iov_iter_zero(nr, to);
B
Badari Pulavarty 已提交
281
		} else {
282 283
			unlock_page(page);

B
Badari Pulavarty 已提交
284 285 286
			/*
			 * We have the page, copy it to user space buffer.
			 */
A
Al Viro 已提交
287
			copied = hugetlbfs_read_actor(page, offset, to, nr);
288
			page_cache_release(page);
B
Badari Pulavarty 已提交
289
		}
A
Al Viro 已提交
290 291 292 293 294 295
		offset += copied;
		retval += copied;
		if (copied != nr && iov_iter_count(to)) {
			if (!retval)
				retval = -EFAULT;
			break;
B
Badari Pulavarty 已提交
296
		}
297 298
		index += offset >> huge_page_shift(h);
		offset &= ~huge_page_mask(h);
B
Badari Pulavarty 已提交
299
	}
A
Al Viro 已提交
300
	iocb->ki_pos = ((loff_t)index << huge_page_shift(h)) + offset;
B
Badari Pulavarty 已提交
301 302 303
	return retval;
}

N
Nick Piggin 已提交
304 305 306 307
static int hugetlbfs_write_begin(struct file *file,
			struct address_space *mapping,
			loff_t pos, unsigned len, unsigned flags,
			struct page **pagep, void **fsdata)
L
Linus Torvalds 已提交
308 309 310 311
{
	return -EINVAL;
}

N
Nick Piggin 已提交
312 313 314
static int hugetlbfs_write_end(struct file *file, struct address_space *mapping,
			loff_t pos, unsigned len, unsigned copied,
			struct page *page, void *fsdata)
L
Linus Torvalds 已提交
315
{
N
Nick Piggin 已提交
316
	BUG();
L
Linus Torvalds 已提交
317 318 319
	return -EINVAL;
}

320
static void remove_huge_page(struct page *page)
L
Linus Torvalds 已提交
321
{
322
	ClearPageDirty(page);
L
Linus Torvalds 已提交
323
	ClearPageUptodate(page);
324
	delete_from_page_cache(page);
L
Linus Torvalds 已提交
325 326
}

327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345

/*
 * remove_inode_hugepages handles two distinct cases: truncation and hole
 * punch.  There are subtle differences in operation for each case.

 * truncation is indicated by end of range being LLONG_MAX
 *	In this case, we first scan the range and release found pages.
 *	After releasing pages, hugetlb_unreserve_pages cleans up region/reserv
 *	maps and global counts.
 * hole punch is indicated if end is not LLONG_MAX
 *	In the hole punch case we scan the range and release found pages.
 *	Only when releasing a page is the associated region/reserv map
 *	deleted.  The region/reserv map for ranges without associated
 *	pages are not modified.
 * Note: If the passed end of range value is beyond the end of file, but
 * not LLONG_MAX this routine still performs a hole punch operation.
 */
static void remove_inode_hugepages(struct inode *inode, loff_t lstart,
				   loff_t lend)
L
Linus Torvalds 已提交
346
{
347
	struct hstate *h = hstate_inode(inode);
348
	struct address_space *mapping = &inode->i_data;
349
	const pgoff_t start = lstart >> huge_page_shift(h);
350 351
	const pgoff_t end = lend >> huge_page_shift(h);
	struct vm_area_struct pseudo_vma;
L
Linus Torvalds 已提交
352 353
	struct pagevec pvec;
	pgoff_t next;
354
	int i, freed = 0;
355 356
	long lookup_nr = PAGEVEC_SIZE;
	bool truncate_op = (lend == LLONG_MAX);
L
Linus Torvalds 已提交
357

358 359
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
L
Linus Torvalds 已提交
360 361
	pagevec_init(&pvec, 0);
	next = start;
362 363 364 365 366 367 368 369 370 371 372 373 374
	while (next < end) {
		/*
		 * Make sure to never grab more pages that we
		 * might possibly need.
		 */
		if (end - next < lookup_nr)
			lookup_nr = end - next;

		/*
		 * This pagevec_lookup() may return pages past 'end',
		 * so we must check for page->index > end.
		 */
		if (!pagevec_lookup(&pvec, mapping, next, lookup_nr)) {
L
Linus Torvalds 已提交
375 376 377 378 379 380 381 382
			if (next == start)
				break;
			next = start;
			continue;
		}

		for (i = 0; i < pagevec_count(&pvec); ++i) {
			struct page *page = pvec.pages[i];
383 384 385 386 387 388
			u32 hash;

			hash = hugetlb_fault_mutex_hash(h, current->mm,
							&pseudo_vma,
							mapping, next, 0);
			mutex_lock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
389 390

			lock_page(page);
391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425
			if (page->index >= end) {
				unlock_page(page);
				mutex_unlock(&hugetlb_fault_mutex_table[hash]);
				next = end;	/* we are done */
				break;
			}

			/*
			 * If page is mapped, it was faulted in after being
			 * unmapped.  Do nothing in this race case.  In the
			 * normal case page is not mapped.
			 */
			if (!page_mapped(page)) {
				bool rsv_on_error = !PagePrivate(page);
				/*
				 * We must free the huge page and remove
				 * from page cache (remove_huge_page) BEFORE
				 * removing the region/reserve map
				 * (hugetlb_unreserve_pages).  In rare out
				 * of memory conditions, removal of the
				 * region/reserve map could fail.  Before
				 * free'ing the page, note PagePrivate which
				 * is used in case of error.
				 */
				remove_huge_page(page);
				freed++;
				if (!truncate_op) {
					if (unlikely(hugetlb_unreserve_pages(
							inode, next,
							next + 1, 1)))
						hugetlb_fix_reserve_counts(
							inode, rsv_on_error);
				}
			}

L
Linus Torvalds 已提交
426 427
			if (page->index > next)
				next = page->index;
428

L
Linus Torvalds 已提交
429 430
			++next;
			unlock_page(page);
431 432

			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
433 434 435
		}
		huge_pagevec_release(&pvec);
	}
436 437 438

	if (truncate_op)
		(void)hugetlb_unreserve_pages(inode, start, LONG_MAX, freed);
L
Linus Torvalds 已提交
439 440
}

A
Al Viro 已提交
441
static void hugetlbfs_evict_inode(struct inode *inode)
L
Linus Torvalds 已提交
442
{
443 444
	struct resv_map *resv_map;

445
	remove_inode_hugepages(inode, 0, LLONG_MAX);
446 447 448 449
	resv_map = (struct resv_map *)inode->i_mapping->private_data;
	/* root inode doesn't have the resv_map, so we should check it */
	if (resv_map)
		resv_map_release(&resv_map->refs);
450
	clear_inode(inode);
451 452
}

L
Linus Torvalds 已提交
453
static inline void
454
hugetlb_vmdelete_list(struct rb_root *root, pgoff_t start, pgoff_t end)
L
Linus Torvalds 已提交
455 456 457
{
	struct vm_area_struct *vma;

458 459 460 461 462
	/*
	 * end == 0 indicates that the entire range after
	 * start should be unmapped.
	 */
	vma_interval_tree_foreach(vma, root, start, end ? end : ULONG_MAX) {
L
Linus Torvalds 已提交
463 464 465
		unsigned long v_offset;

		/*
H
Hugh Dickins 已提交
466
		 * Can the expression below overflow on 32-bit arches?
467
		 * No, because the interval tree returns us only those vmas
H
Hugh Dickins 已提交
468 469
		 * which overlap the truncated area starting at pgoff,
		 * and no vma on a 32-bit arch can span beyond the 4GB.
L
Linus Torvalds 已提交
470
		 */
471 472
		if (vma->vm_pgoff < start)
			v_offset = (start - vma->vm_pgoff) << PAGE_SHIFT;
H
Hugh Dickins 已提交
473
		else
L
Linus Torvalds 已提交
474 475
			v_offset = 0;

476 477 478 479 480 481 482 483 484
		if (end) {
			end = ((end - start) << PAGE_SHIFT) +
			       vma->vm_start + v_offset;
			if (end > vma->vm_end)
				end = vma->vm_end;
		} else
			end = vma->vm_end;

		unmap_hugepage_range(vma, vma->vm_start + v_offset, end, NULL);
L
Linus Torvalds 已提交
485 486 487 488 489
	}
}

static int hugetlb_vmtruncate(struct inode *inode, loff_t offset)
{
H
Hugh Dickins 已提交
490
	pgoff_t pgoff;
L
Linus Torvalds 已提交
491
	struct address_space *mapping = inode->i_mapping;
492
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
493

494
	BUG_ON(offset & ~huge_page_mask(h));
H
Hugh Dickins 已提交
495
	pgoff = offset >> PAGE_SHIFT;
L
Linus Torvalds 已提交
496

497
	i_size_write(inode, offset);
498
	i_mmap_lock_write(mapping);
499
	if (!RB_EMPTY_ROOT(&mapping->i_mmap))
500
		hugetlb_vmdelete_list(&mapping->i_mmap, pgoff, 0);
501
	i_mmap_unlock_write(mapping);
502
	remove_inode_hugepages(inode, offset, LLONG_MAX);
L
Linus Torvalds 已提交
503 504 505
	return 0;
}

506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657
static long hugetlbfs_punch_hole(struct inode *inode, loff_t offset, loff_t len)
{
	struct hstate *h = hstate_inode(inode);
	loff_t hpage_size = huge_page_size(h);
	loff_t hole_start, hole_end;

	/*
	 * For hole punch round up the beginning offset of the hole and
	 * round down the end.
	 */
	hole_start = round_up(offset, hpage_size);
	hole_end = round_down(offset + len, hpage_size);

	if (hole_end > hole_start) {
		struct address_space *mapping = inode->i_mapping;

		mutex_lock(&inode->i_mutex);
		i_mmap_lock_write(mapping);
		if (!RB_EMPTY_ROOT(&mapping->i_mmap))
			hugetlb_vmdelete_list(&mapping->i_mmap,
						hole_start >> PAGE_SHIFT,
						hole_end  >> PAGE_SHIFT);
		i_mmap_unlock_write(mapping);
		remove_inode_hugepages(inode, hole_start, hole_end);
		mutex_unlock(&inode->i_mutex);
	}

	return 0;
}

static long hugetlbfs_fallocate(struct file *file, int mode, loff_t offset,
				loff_t len)
{
	struct inode *inode = file_inode(file);
	struct address_space *mapping = inode->i_mapping;
	struct hstate *h = hstate_inode(inode);
	struct vm_area_struct pseudo_vma;
	struct mm_struct *mm = current->mm;
	loff_t hpage_size = huge_page_size(h);
	unsigned long hpage_shift = huge_page_shift(h);
	pgoff_t start, index, end;
	int error;
	u32 hash;

	if (mode & ~(FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE))
		return -EOPNOTSUPP;

	if (mode & FALLOC_FL_PUNCH_HOLE)
		return hugetlbfs_punch_hole(inode, offset, len);

	/*
	 * Default preallocate case.
	 * For this range, start is rounded down and end is rounded up
	 * as well as being converted to page offsets.
	 */
	start = offset >> hpage_shift;
	end = (offset + len + hpage_size - 1) >> hpage_shift;

	mutex_lock(&inode->i_mutex);

	/* We need to check rlimit even when FALLOC_FL_KEEP_SIZE */
	error = inode_newsize_ok(inode, offset + len);
	if (error)
		goto out;

	/*
	 * Initialize a pseudo vma as this is required by the huge page
	 * allocation routines.  If NUMA is configured, use page index
	 * as input to create an allocation policy.
	 */
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
	pseudo_vma.vm_file = file;

	for (index = start; index < end; index++) {
		/*
		 * This is supposed to be the vaddr where the page is being
		 * faulted in, but we have no vaddr here.
		 */
		struct page *page;
		unsigned long addr;
		int avoid_reserve = 0;

		cond_resched();

		/*
		 * fallocate(2) manpage permits EINTR; we may have been
		 * interrupted because we are using up too much memory.
		 */
		if (signal_pending(current)) {
			error = -EINTR;
			break;
		}

		/* Set numa allocation policy based on index */
		hugetlb_set_vma_policy(&pseudo_vma, inode, index);

		/* addr is the offset within the file (zero based) */
		addr = index * hpage_size;

		/* mutex taken here, fault path and hole punch */
		hash = hugetlb_fault_mutex_hash(h, mm, &pseudo_vma, mapping,
						index, addr);
		mutex_lock(&hugetlb_fault_mutex_table[hash]);

		/* See if already present in mapping to avoid alloc/free */
		page = find_get_page(mapping, index);
		if (page) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			hugetlb_drop_vma_policy(&pseudo_vma);
			continue;
		}

		/* Allocate page and add to page cache */
		page = alloc_huge_page(&pseudo_vma, addr, avoid_reserve);
		hugetlb_drop_vma_policy(&pseudo_vma);
		if (IS_ERR(page)) {
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			error = PTR_ERR(page);
			goto out;
		}
		clear_huge_page(page, addr, pages_per_huge_page(h));
		__SetPageUptodate(page);
		error = huge_add_to_page_cache(page, mapping, index);
		if (unlikely(error)) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			goto out;
		}

		mutex_unlock(&hugetlb_fault_mutex_table[hash]);

		/*
		 * page_put due to reference from alloc_huge_page()
		 * unlock_page because locked by add_to_page_cache()
		 */
		put_page(page);
		unlock_page(page);
	}

	if (!(mode & FALLOC_FL_KEEP_SIZE) && offset + len > inode->i_size)
		i_size_write(inode, offset + len);
	inode->i_ctime = CURRENT_TIME;
	spin_lock(&inode->i_lock);
	inode->i_private = NULL;
	spin_unlock(&inode->i_lock);
out:
	mutex_unlock(&inode->i_mutex);
	return error;
}

L
Linus Torvalds 已提交
658 659
static int hugetlbfs_setattr(struct dentry *dentry, struct iattr *attr)
{
660
	struct inode *inode = d_inode(dentry);
661
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
662 663 664 665 666 667 668
	int error;
	unsigned int ia_valid = attr->ia_valid;

	BUG_ON(!inode);

	error = inode_change_ok(inode, attr);
	if (error)
C
Christoph Hellwig 已提交
669
		return error;
L
Linus Torvalds 已提交
670 671 672

	if (ia_valid & ATTR_SIZE) {
		error = -EINVAL;
C
Christoph Hellwig 已提交
673 674 675
		if (attr->ia_size & ~huge_page_mask(h))
			return -EINVAL;
		error = hugetlb_vmtruncate(inode, attr->ia_size);
L
Linus Torvalds 已提交
676
		if (error)
C
Christoph Hellwig 已提交
677
			return error;
L
Linus Torvalds 已提交
678
	}
C
Christoph Hellwig 已提交
679 680 681 682

	setattr_copy(inode, attr);
	mark_inode_dirty(inode);
	return 0;
L
Linus Torvalds 已提交
683 684
}

685 686
static struct inode *hugetlbfs_get_root(struct super_block *sb,
					struct hugetlbfs_config *config)
L
Linus Torvalds 已提交
687 688 689 690 691 692
{
	struct inode *inode;

	inode = new_inode(sb);
	if (inode) {
		struct hugetlbfs_inode_info *info;
693
		inode->i_ino = get_next_ino();
694 695 696 697 698 699 700 701 702 703
		inode->i_mode = S_IFDIR | config->mode;
		inode->i_uid = config->uid;
		inode->i_gid = config->gid;
		inode->i_atime = inode->i_mtime = inode->i_ctime = CURRENT_TIME;
		info = HUGETLBFS_I(inode);
		mpol_shared_policy_init(&info->policy, NULL);
		inode->i_op = &hugetlbfs_dir_inode_operations;
		inode->i_fop = &simple_dir_operations;
		/* directory inodes start off with i_nlink == 2 (for "." entry) */
		inc_nlink(inode);
704
		lockdep_annotate_inode_mutex_key(inode);
705 706 707 708
	}
	return inode;
}

709
/*
710
 * Hugetlbfs is not reclaimable; therefore its i_mmap_rwsem will never
711 712
 * be taken from reclaim -- unlike regular filesystems. This needs an
 * annotation because huge_pmd_share() does an allocation under
713
 * i_mmap_rwsem.
714
 */
715
static struct lock_class_key hugetlbfs_i_mmap_rwsem_key;
716

717 718
static struct inode *hugetlbfs_get_inode(struct super_block *sb,
					struct inode *dir,
A
Al Viro 已提交
719
					umode_t mode, dev_t dev)
720 721
{
	struct inode *inode;
722 723 724 725 726
	struct resv_map *resv_map;

	resv_map = resv_map_alloc();
	if (!resv_map)
		return NULL;
727 728 729 730 731 732

	inode = new_inode(sb);
	if (inode) {
		struct hugetlbfs_inode_info *info;
		inode->i_ino = get_next_ino();
		inode_init_owner(inode, dir, mode);
733 734
		lockdep_set_class(&inode->i_mapping->i_mmap_rwsem,
				&hugetlbfs_i_mmap_rwsem_key);
L
Linus Torvalds 已提交
735 736
		inode->i_mapping->a_ops = &hugetlbfs_aops;
		inode->i_atime = inode->i_mtime = inode->i_ctime = CURRENT_TIME;
737
		inode->i_mapping->private_data = resv_map;
L
Linus Torvalds 已提交
738
		info = HUGETLBFS_I(inode);
739 740 741 742 743 744 745
		/*
		 * The policy is initialized here even if we are creating a
		 * private inode because initialization simply creates an
		 * an empty rb tree and calls spin_lock_init(), later when we
		 * call mpol_free_shared_policy() it will just return because
		 * the rb tree will still be empty.
		 */
746
		mpol_shared_policy_init(&info->policy, NULL);
L
Linus Torvalds 已提交
747 748 749 750 751 752 753 754 755 756 757 758 759
		switch (mode & S_IFMT) {
		default:
			init_special_inode(inode, mode, dev);
			break;
		case S_IFREG:
			inode->i_op = &hugetlbfs_inode_operations;
			inode->i_fop = &hugetlbfs_file_operations;
			break;
		case S_IFDIR:
			inode->i_op = &hugetlbfs_dir_inode_operations;
			inode->i_fop = &simple_dir_operations;

			/* directory inodes start off with i_nlink == 2 (for "." entry) */
760
			inc_nlink(inode);
L
Linus Torvalds 已提交
761 762 763 764 765
			break;
		case S_IFLNK:
			inode->i_op = &page_symlink_inode_operations;
			break;
		}
766
		lockdep_annotate_inode_mutex_key(inode);
767 768 769
	} else
		kref_put(&resv_map->refs, resv_map_release);

L
Linus Torvalds 已提交
770 771 772 773 774 775 776
	return inode;
}

/*
 * File creation. Allocate an inode, and we're done..
 */
static int hugetlbfs_mknod(struct inode *dir,
A
Al Viro 已提交
777
			struct dentry *dentry, umode_t mode, dev_t dev)
L
Linus Torvalds 已提交
778 779 780
{
	struct inode *inode;
	int error = -ENOSPC;
781 782

	inode = hugetlbfs_get_inode(dir->i_sb, dir, mode, dev);
L
Linus Torvalds 已提交
783 784 785 786 787 788 789 790 791
	if (inode) {
		dir->i_ctime = dir->i_mtime = CURRENT_TIME;
		d_instantiate(dentry, inode);
		dget(dentry);	/* Extra count - pin the dentry in core */
		error = 0;
	}
	return error;
}

792
static int hugetlbfs_mkdir(struct inode *dir, struct dentry *dentry, umode_t mode)
L
Linus Torvalds 已提交
793 794 795
{
	int retval = hugetlbfs_mknod(dir, dentry, mode | S_IFDIR, 0);
	if (!retval)
796
		inc_nlink(dir);
L
Linus Torvalds 已提交
797 798 799
	return retval;
}

A
Al Viro 已提交
800
static int hugetlbfs_create(struct inode *dir, struct dentry *dentry, umode_t mode, bool excl)
L
Linus Torvalds 已提交
801 802 803 804 805 806 807 808 809 810
{
	return hugetlbfs_mknod(dir, dentry, mode | S_IFREG, 0);
}

static int hugetlbfs_symlink(struct inode *dir,
			struct dentry *dentry, const char *symname)
{
	struct inode *inode;
	int error = -ENOSPC;

811
	inode = hugetlbfs_get_inode(dir->i_sb, dir, S_IFLNK|S_IRWXUGO, 0);
L
Linus Torvalds 已提交
812 813 814 815 816 817 818 819 820 821 822 823 824 825 826
	if (inode) {
		int l = strlen(symname)+1;
		error = page_symlink(inode, symname, l);
		if (!error) {
			d_instantiate(dentry, inode);
			dget(dentry);
		} else
			iput(inode);
	}
	dir->i_ctime = dir->i_mtime = CURRENT_TIME;

	return error;
}

/*
827
 * mark the head page dirty
L
Linus Torvalds 已提交
828 829 830
 */
static int hugetlbfs_set_page_dirty(struct page *page)
{
831
	struct page *head = compound_head(page);
832 833

	SetPageDirty(head);
L
Linus Torvalds 已提交
834 835 836
	return 0;
}

N
Naoya Horiguchi 已提交
837
static int hugetlbfs_migrate_page(struct address_space *mapping,
838
				struct page *newpage, struct page *page,
839
				enum migrate_mode mode)
N
Naoya Horiguchi 已提交
840 841 842 843
{
	int rc;

	rc = migrate_huge_page_move_mapping(mapping, newpage, page);
844
	if (rc != MIGRATEPAGE_SUCCESS)
N
Naoya Horiguchi 已提交
845 846 847
		return rc;
	migrate_page_copy(newpage, page);

848
	return MIGRATEPAGE_SUCCESS;
N
Naoya Horiguchi 已提交
849 850
}

851
static int hugetlbfs_statfs(struct dentry *dentry, struct kstatfs *buf)
L
Linus Torvalds 已提交
852
{
853
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(dentry->d_sb);
854
	struct hstate *h = hstate_inode(d_inode(dentry));
L
Linus Torvalds 已提交
855 856

	buf->f_type = HUGETLBFS_MAGIC;
857
	buf->f_bsize = huge_page_size(h);
L
Linus Torvalds 已提交
858 859
	if (sbinfo) {
		spin_lock(&sbinfo->stat_lock);
860 861
		/* If no limits set, just report 0 for max/free/used
		 * blocks, like simple_statfs() */
862 863 864 865 866 867 868 869 870
		if (sbinfo->spool) {
			long free_pages;

			spin_lock(&sbinfo->spool->lock);
			buf->f_blocks = sbinfo->spool->max_hpages;
			free_pages = sbinfo->spool->max_hpages
				- sbinfo->spool->used_hpages;
			buf->f_bavail = buf->f_bfree = free_pages;
			spin_unlock(&sbinfo->spool->lock);
871 872 873
			buf->f_files = sbinfo->max_inodes;
			buf->f_ffree = sbinfo->free_inodes;
		}
L
Linus Torvalds 已提交
874 875 876 877 878 879 880 881 882 883 884 885
		spin_unlock(&sbinfo->stat_lock);
	}
	buf->f_namelen = NAME_MAX;
	return 0;
}

static void hugetlbfs_put_super(struct super_block *sb)
{
	struct hugetlbfs_sb_info *sbi = HUGETLBFS_SB(sb);

	if (sbi) {
		sb->s_fs_info = NULL;
886 887 888 889

		if (sbi->spool)
			hugepage_put_subpool(sbi->spool);

L
Linus Torvalds 已提交
890 891 892 893
		kfree(sbi);
	}
}

894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918
static inline int hugetlbfs_dec_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		if (unlikely(!sbinfo->free_inodes)) {
			spin_unlock(&sbinfo->stat_lock);
			return 0;
		}
		sbinfo->free_inodes--;
		spin_unlock(&sbinfo->stat_lock);
	}

	return 1;
}

static void hugetlbfs_inc_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		sbinfo->free_inodes++;
		spin_unlock(&sbinfo->stat_lock);
	}
}


919
static struct kmem_cache *hugetlbfs_inode_cachep;
L
Linus Torvalds 已提交
920 921 922

static struct inode *hugetlbfs_alloc_inode(struct super_block *sb)
{
923
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(sb);
L
Linus Torvalds 已提交
924 925
	struct hugetlbfs_inode_info *p;

926 927
	if (unlikely(!hugetlbfs_dec_free_inodes(sbinfo)))
		return NULL;
928
	p = kmem_cache_alloc(hugetlbfs_inode_cachep, GFP_KERNEL);
929 930
	if (unlikely(!p)) {
		hugetlbfs_inc_free_inodes(sbinfo);
L
Linus Torvalds 已提交
931
		return NULL;
932
	}
L
Linus Torvalds 已提交
933 934 935
	return &p->vfs_inode;
}

N
Nick Piggin 已提交
936 937 938 939 940 941
static void hugetlbfs_i_callback(struct rcu_head *head)
{
	struct inode *inode = container_of(head, struct inode, i_rcu);
	kmem_cache_free(hugetlbfs_inode_cachep, HUGETLBFS_I(inode));
}

L
Linus Torvalds 已提交
942 943
static void hugetlbfs_destroy_inode(struct inode *inode)
{
944
	hugetlbfs_inc_free_inodes(HUGETLBFS_SB(inode->i_sb));
L
Linus Torvalds 已提交
945
	mpol_free_shared_policy(&HUGETLBFS_I(inode)->policy);
N
Nick Piggin 已提交
946
	call_rcu(&inode->i_rcu, hugetlbfs_i_callback);
L
Linus Torvalds 已提交
947 948
}

949
static const struct address_space_operations hugetlbfs_aops = {
N
Nick Piggin 已提交
950 951
	.write_begin	= hugetlbfs_write_begin,
	.write_end	= hugetlbfs_write_end,
L
Linus Torvalds 已提交
952
	.set_page_dirty	= hugetlbfs_set_page_dirty,
N
Naoya Horiguchi 已提交
953
	.migratepage    = hugetlbfs_migrate_page,
L
Linus Torvalds 已提交
954 955
};

956

957
static void init_once(void *foo)
958 959 960
{
	struct hugetlbfs_inode_info *ei = (struct hugetlbfs_inode_info *)foo;

C
Christoph Lameter 已提交
961
	inode_init_once(&ei->vfs_inode);
962 963
}

964
const struct file_operations hugetlbfs_file_operations = {
A
Al Viro 已提交
965
	.read_iter		= hugetlbfs_read_iter,
L
Linus Torvalds 已提交
966
	.mmap			= hugetlbfs_file_mmap,
967
	.fsync			= noop_fsync,
L
Linus Torvalds 已提交
968
	.get_unmapped_area	= hugetlb_get_unmapped_area,
969 970
	.llseek			= default_llseek,
	.fallocate		= hugetlbfs_fallocate,
L
Linus Torvalds 已提交
971 972
};

973
static const struct inode_operations hugetlbfs_dir_inode_operations = {
L
Linus Torvalds 已提交
974 975 976 977 978 979 980 981 982 983 984 985
	.create		= hugetlbfs_create,
	.lookup		= simple_lookup,
	.link		= simple_link,
	.unlink		= simple_unlink,
	.symlink	= hugetlbfs_symlink,
	.mkdir		= hugetlbfs_mkdir,
	.rmdir		= simple_rmdir,
	.mknod		= hugetlbfs_mknod,
	.rename		= simple_rename,
	.setattr	= hugetlbfs_setattr,
};

986
static const struct inode_operations hugetlbfs_inode_operations = {
L
Linus Torvalds 已提交
987 988 989
	.setattr	= hugetlbfs_setattr,
};

990
static const struct super_operations hugetlbfs_ops = {
L
Linus Torvalds 已提交
991 992
	.alloc_inode    = hugetlbfs_alloc_inode,
	.destroy_inode  = hugetlbfs_destroy_inode,
A
Al Viro 已提交
993
	.evict_inode	= hugetlbfs_evict_inode,
L
Linus Torvalds 已提交
994 995
	.statfs		= hugetlbfs_statfs,
	.put_super	= hugetlbfs_put_super,
M
Miklos Szeredi 已提交
996
	.show_options	= generic_show_options,
L
Linus Torvalds 已提交
997 998
};

999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022
enum { NO_SIZE, SIZE_STD, SIZE_PERCENT };

/*
 * Convert size option passed from command line to number of huge pages
 * in the pool specified by hstate.  Size option could be in bytes
 * (val_type == SIZE_STD) or percentage of the pool (val_type == SIZE_PERCENT).
 */
static long long
hugetlbfs_size_to_hpages(struct hstate *h, unsigned long long size_opt,
								int val_type)
{
	if (val_type == NO_SIZE)
		return -1;

	if (val_type == SIZE_PERCENT) {
		size_opt <<= huge_page_shift(h);
		size_opt *= h->max_huge_pages;
		do_div(size_opt, 100);
	}

	size_opt >>= huge_page_shift(h);
	return size_opt;
}

L
Linus Torvalds 已提交
1023 1024 1025
static int
hugetlbfs_parse_options(char *options, struct hugetlbfs_config *pconfig)
{
1026 1027 1028
	char *p, *rest;
	substring_t args[MAX_OPT_ARGS];
	int option;
1029 1030
	unsigned long long max_size_opt = 0, min_size_opt = 0;
	int max_val_type = NO_SIZE, min_val_type = NO_SIZE;
L
Linus Torvalds 已提交
1031 1032 1033 1034

	if (!options)
		return 0;

1035 1036
	while ((p = strsep(&options, ",")) != NULL) {
		int token;
1037 1038
		if (!*p)
			continue;
1039 1040 1041 1042 1043 1044

		token = match_token(p, tokens, args);
		switch (token) {
		case Opt_uid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1045 1046 1047
			pconfig->uid = make_kuid(current_user_ns(), option);
			if (!uid_valid(pconfig->uid))
				goto bad_val;
1048 1049 1050 1051 1052
			break;

		case Opt_gid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1053 1054 1055
			pconfig->gid = make_kgid(current_user_ns(), option);
			if (!gid_valid(pconfig->gid))
				goto bad_val;
1056 1057 1058 1059 1060
			break;

		case Opt_mode:
			if (match_octal(&args[0], &option))
 				goto bad_val;
1061
			pconfig->mode = option & 01777U;
1062 1063 1064 1065 1066 1067
			break;

		case Opt_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
1068 1069
			max_size_opt = memparse(args[0].from, &rest);
			max_val_type = SIZE_STD;
1070
			if (*rest == '%')
1071
				max_val_type = SIZE_PERCENT;
1072 1073
			break;
		}
L
Linus Torvalds 已提交
1074

1075 1076 1077 1078 1079 1080 1081
		case Opt_nr_inodes:
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			pconfig->nr_inodes = memparse(args[0].from, &rest);
			break;

1082 1083 1084 1085 1086
		case Opt_pagesize: {
			unsigned long ps;
			ps = memparse(args[0].from, &rest);
			pconfig->hstate = size_to_hstate(ps);
			if (!pconfig->hstate) {
1087
				pr_err("Unsupported page size %lu MB\n",
1088 1089 1090 1091 1092 1093
					ps >> 20);
				return -EINVAL;
			}
			break;
		}

1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104
		case Opt_min_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			min_size_opt = memparse(args[0].from, &rest);
			min_val_type = SIZE_STD;
			if (*rest == '%')
				min_val_type = SIZE_PERCENT;
			break;
		}

1105
		default:
1106
			pr_err("Bad mount option: \"%s\"\n", p);
1107
			return -EINVAL;
1108 1109
			break;
		}
L
Linus Torvalds 已提交
1110
	}
1111

1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127
	/*
	 * Use huge page pool size (in hstate) to convert the size
	 * options to number of huge pages.  If NO_SIZE, -1 is returned.
	 */
	pconfig->max_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						max_size_opt, max_val_type);
	pconfig->min_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						min_size_opt, min_val_type);

	/*
	 * If max_size was specified, then min_size must be smaller
	 */
	if (max_val_type > NO_SIZE &&
	    pconfig->min_hpages > pconfig->max_hpages) {
		pr_err("minimum size can not be greater than maximum size\n");
		return -EINVAL;
1128 1129
	}

L
Linus Torvalds 已提交
1130
	return 0;
1131 1132

bad_val:
1133
	pr_err("Bad value '%s' for mount option '%s'\n", args[0].from, p);
1134
 	return -EINVAL;
L
Linus Torvalds 已提交
1135 1136 1137 1138 1139 1140 1141 1142 1143
}

static int
hugetlbfs_fill_super(struct super_block *sb, void *data, int silent)
{
	int ret;
	struct hugetlbfs_config config;
	struct hugetlbfs_sb_info *sbinfo;

M
Miklos Szeredi 已提交
1144 1145
	save_mount_options(sb, data);

1146
	config.max_hpages = -1; /* No limit on size by default */
L
Linus Torvalds 已提交
1147
	config.nr_inodes = -1; /* No limit on number of inodes by default */
1148 1149
	config.uid = current_fsuid();
	config.gid = current_fsgid();
L
Linus Torvalds 已提交
1150
	config.mode = 0755;
1151
	config.hstate = &default_hstate;
1152
	config.min_hpages = -1; /* No default minimum size */
L
Linus Torvalds 已提交
1153 1154 1155 1156 1157 1158 1159 1160
	ret = hugetlbfs_parse_options(data, &config);
	if (ret)
		return ret;

	sbinfo = kmalloc(sizeof(struct hugetlbfs_sb_info), GFP_KERNEL);
	if (!sbinfo)
		return -ENOMEM;
	sb->s_fs_info = sbinfo;
1161
	sbinfo->hstate = config.hstate;
L
Linus Torvalds 已提交
1162 1163 1164
	spin_lock_init(&sbinfo->stat_lock);
	sbinfo->max_inodes = config.nr_inodes;
	sbinfo->free_inodes = config.nr_inodes;
1165
	sbinfo->spool = NULL;
1166 1167 1168 1169 1170 1171 1172 1173 1174
	/*
	 * Allocate and initialize subpool if maximum or minimum size is
	 * specified.  Any needed reservations (for minimim size) are taken
	 * taken when the subpool is created.
	 */
	if (config.max_hpages != -1 || config.min_hpages != -1) {
		sbinfo->spool = hugepage_new_subpool(config.hstate,
							config.max_hpages,
							config.min_hpages);
1175 1176 1177
		if (!sbinfo->spool)
			goto out_free;
	}
L
Linus Torvalds 已提交
1178
	sb->s_maxbytes = MAX_LFS_FILESIZE;
1179 1180
	sb->s_blocksize = huge_page_size(config.hstate);
	sb->s_blocksize_bits = huge_page_shift(config.hstate);
L
Linus Torvalds 已提交
1181 1182 1183
	sb->s_magic = HUGETLBFS_MAGIC;
	sb->s_op = &hugetlbfs_ops;
	sb->s_time_gran = 1;
1184 1185
	sb->s_root = d_make_root(hugetlbfs_get_root(sb, &config));
	if (!sb->s_root)
L
Linus Torvalds 已提交
1186 1187 1188
		goto out_free;
	return 0;
out_free:
1189
	kfree(sbinfo->spool);
L
Linus Torvalds 已提交
1190 1191 1192 1193
	kfree(sbinfo);
	return -ENOMEM;
}

A
Al Viro 已提交
1194 1195
static struct dentry *hugetlbfs_mount(struct file_system_type *fs_type,
	int flags, const char *dev_name, void *data)
L
Linus Torvalds 已提交
1196
{
A
Al Viro 已提交
1197
	return mount_nodev(fs_type, flags, data, hugetlbfs_fill_super);
L
Linus Torvalds 已提交
1198 1199 1200 1201
}

static struct file_system_type hugetlbfs_fs_type = {
	.name		= "hugetlbfs",
A
Al Viro 已提交
1202
	.mount		= hugetlbfs_mount,
L
Linus Torvalds 已提交
1203 1204
	.kill_sb	= kill_litter_super,
};
1205
MODULE_ALIAS_FS("hugetlbfs");
L
Linus Torvalds 已提交
1206

1207
static struct vfsmount *hugetlbfs_vfsmount[HUGE_MAX_HSTATE];
L
Linus Torvalds 已提交
1208

1209
static int can_do_hugetlb_shm(void)
L
Linus Torvalds 已提交
1210
{
1211 1212 1213
	kgid_t shm_group;
	shm_group = make_kgid(&init_user_ns, sysctl_hugetlb_shm_group);
	return capable(CAP_IPC_LOCK) || in_group_p(shm_group);
L
Linus Torvalds 已提交
1214 1215
}

1216 1217
static int get_hstate_idx(int page_size_log)
{
1218
	struct hstate *h = hstate_sizelog(page_size_log);
1219 1220 1221 1222 1223 1224

	if (!h)
		return -1;
	return h - hstates;
}

1225
static const struct dentry_operations anon_ops = {
1226
	.d_dname = simple_dname
1227 1228
};

1229 1230 1231 1232 1233 1234
/*
 * Note that size should be aligned to proper hugepage size in caller side,
 * otherwise hugetlb_reserve_pages reserves one less hugepages than intended.
 */
struct file *hugetlb_file_setup(const char *name, size_t size,
				vm_flags_t acctflag, struct user_struct **user,
1235
				int creat_flags, int page_size_log)
L
Linus Torvalds 已提交
1236
{
1237
	struct file *file = ERR_PTR(-ENOMEM);
L
Linus Torvalds 已提交
1238
	struct inode *inode;
1239
	struct path path;
1240
	struct super_block *sb;
L
Linus Torvalds 已提交
1241
	struct qstr quick_string;
1242 1243 1244 1245 1246
	int hstate_idx;

	hstate_idx = get_hstate_idx(page_size_log);
	if (hstate_idx < 0)
		return ERR_PTR(-ENODEV);
L
Linus Torvalds 已提交
1247

1248
	*user = NULL;
1249
	if (!hugetlbfs_vfsmount[hstate_idx])
1250 1251
		return ERR_PTR(-ENOENT);

1252
	if (creat_flags == HUGETLB_SHMFS_INODE && !can_do_hugetlb_shm()) {
1253 1254
		*user = current_user();
		if (user_shm_lock(size, *user)) {
1255
			task_lock(current);
1256
			pr_warn_once("%s (%d): Using mlock ulimits for SHM_HUGETLB is deprecated\n",
1257 1258
				current->comm, current->pid);
			task_unlock(current);
1259 1260
		} else {
			*user = NULL;
1261
			return ERR_PTR(-EPERM);
1262
		}
1263
	}
L
Linus Torvalds 已提交
1264

1265
	sb = hugetlbfs_vfsmount[hstate_idx]->mnt_sb;
1266
	quick_string.name = name;
L
Linus Torvalds 已提交
1267 1268
	quick_string.len = strlen(quick_string.name);
	quick_string.hash = 0;
1269
	path.dentry = d_alloc_pseudo(sb, &quick_string);
1270
	if (!path.dentry)
L
Linus Torvalds 已提交
1271 1272
		goto out_shm_unlock;

1273
	d_set_d_op(path.dentry, &anon_ops);
1274
	path.mnt = mntget(hugetlbfs_vfsmount[hstate_idx]);
1275
	file = ERR_PTR(-ENOSPC);
1276
	inode = hugetlbfs_get_inode(sb, NULL, S_IFREG | S_IRWXUGO, 0);
L
Linus Torvalds 已提交
1277
	if (!inode)
1278
		goto out_dentry;
1279 1280
	if (creat_flags == HUGETLB_SHMFS_INODE)
		inode->i_flags |= S_PRIVATE;
L
Linus Torvalds 已提交
1281

1282
	file = ERR_PTR(-ENOMEM);
1283 1284 1285
	if (hugetlb_reserve_pages(inode, 0,
			size >> huge_page_shift(hstate_inode(inode)), NULL,
			acctflag))
1286 1287
		goto out_inode;

1288
	d_instantiate(path.dentry, inode);
L
Linus Torvalds 已提交
1289
	inode->i_size = size;
1290
	clear_nlink(inode);
1291

1292
	file = alloc_file(&path, FMODE_WRITE | FMODE_READ,
1293
			&hugetlbfs_file_operations);
1294
	if (IS_ERR(file))
1295
		goto out_dentry; /* inode is already attached */
1296

L
Linus Torvalds 已提交
1297 1298
	return file;

1299 1300
out_inode:
	iput(inode);
L
Linus Torvalds 已提交
1301
out_dentry:
1302
	path_put(&path);
L
Linus Torvalds 已提交
1303
out_shm_unlock:
1304 1305 1306 1307
	if (*user) {
		user_shm_unlock(size, *user);
		*user = NULL;
	}
1308
	return file;
L
Linus Torvalds 已提交
1309 1310 1311 1312
}

static int __init init_hugetlbfs_fs(void)
{
1313
	struct hstate *h;
L
Linus Torvalds 已提交
1314
	int error;
1315
	int i;
L
Linus Torvalds 已提交
1316

1317
	if (!hugepages_supported()) {
1318
		pr_info("disabling because there are no supported hugepage sizes\n");
1319 1320 1321
		return -ENOTSUPP;
	}

1322
	error = -ENOMEM;
L
Linus Torvalds 已提交
1323 1324
	hugetlbfs_inode_cachep = kmem_cache_create("hugetlbfs_inode_cache",
					sizeof(struct hugetlbfs_inode_info),
1325
					0, 0, init_once);
L
Linus Torvalds 已提交
1326
	if (hugetlbfs_inode_cachep == NULL)
P
Peter Zijlstra 已提交
1327
		goto out2;
L
Linus Torvalds 已提交
1328 1329 1330 1331 1332

	error = register_filesystem(&hugetlbfs_fs_type);
	if (error)
		goto out;

1333 1334 1335 1336
	i = 0;
	for_each_hstate(h) {
		char buf[50];
		unsigned ps_kb = 1U << (h->order + PAGE_SHIFT - 10);
L
Linus Torvalds 已提交
1337

1338 1339 1340
		snprintf(buf, sizeof(buf), "pagesize=%uK", ps_kb);
		hugetlbfs_vfsmount[i] = kern_mount_data(&hugetlbfs_fs_type,
							buf);
L
Linus Torvalds 已提交
1341

1342
		if (IS_ERR(hugetlbfs_vfsmount[i])) {
1343
			pr_err("Cannot mount internal hugetlbfs for "
1344 1345 1346 1347 1348 1349 1350 1351 1352
				"page size %uK", ps_kb);
			error = PTR_ERR(hugetlbfs_vfsmount[i]);
			hugetlbfs_vfsmount[i] = NULL;
		}
		i++;
	}
	/* Non default hstates are optional */
	if (!IS_ERR_OR_NULL(hugetlbfs_vfsmount[default_hstate_idx]))
		return 0;
L
Linus Torvalds 已提交
1353 1354

 out:
1355
	kmem_cache_destroy(hugetlbfs_inode_cachep);
P
Peter Zijlstra 已提交
1356
 out2:
L
Linus Torvalds 已提交
1357 1358 1359 1360 1361
	return error;
}

static void __exit exit_hugetlbfs_fs(void)
{
1362 1363 1364 1365
	struct hstate *h;
	int i;


1366 1367 1368 1369 1370
	/*
	 * Make sure all delayed rcu free inodes are flushed before we
	 * destroy cache.
	 */
	rcu_barrier();
L
Linus Torvalds 已提交
1371
	kmem_cache_destroy(hugetlbfs_inode_cachep);
1372 1373 1374
	i = 0;
	for_each_hstate(h)
		kern_unmount(hugetlbfs_vfsmount[i++]);
L
Linus Torvalds 已提交
1375 1376 1377 1378 1379 1380 1381
	unregister_filesystem(&hugetlbfs_fs_type);
}

module_init(init_hugetlbfs_fs)
module_exit(exit_hugetlbfs_fs)

MODULE_LICENSE("GPL");