inode.c 37.2 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 * hugetlbpage-backed filesystem.  Based on ramfs.
 *
4
 * Nadia Yvette Chambers, 2002
L
Linus Torvalds 已提交
5 6
 *
 * Copyright (C) 2002 Linus Torvalds.
7
 * License: GPL
L
Linus Torvalds 已提交
8 9
 */

10 11
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

L
Linus Torvalds 已提交
12 13
#include <linux/thread_info.h>
#include <asm/current.h>
14
#include <linux/sched/signal.h>		/* remove ASAP */
15
#include <linux/falloc.h>
L
Linus Torvalds 已提交
16 17 18
#include <linux/fs.h>
#include <linux/mount.h>
#include <linux/file.h>
19
#include <linux/kernel.h>
L
Linus Torvalds 已提交
20 21 22 23 24
#include <linux/writeback.h>
#include <linux/pagemap.h>
#include <linux/highmem.h>
#include <linux/init.h>
#include <linux/string.h>
25
#include <linux/capability.h>
26
#include <linux/ctype.h>
L
Linus Torvalds 已提交
27 28 29
#include <linux/backing-dev.h>
#include <linux/hugetlb.h>
#include <linux/pagevec.h>
30
#include <linux/parser.h>
31
#include <linux/mman.h>
L
Linus Torvalds 已提交
32 33 34 35
#include <linux/slab.h>
#include <linux/dnotify.h>
#include <linux/statfs.h>
#include <linux/security.h>
N
Nick Black 已提交
36
#include <linux/magic.h>
N
Naoya Horiguchi 已提交
37
#include <linux/migrate.h>
A
Al Viro 已提交
38
#include <linux/uio.h>
L
Linus Torvalds 已提交
39

40
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
41

42
static const struct super_operations hugetlbfs_ops;
43
static const struct address_space_operations hugetlbfs_aops;
44
const struct file_operations hugetlbfs_file_operations;
45 46
static const struct inode_operations hugetlbfs_dir_inode_operations;
static const struct inode_operations hugetlbfs_inode_operations;
L
Linus Torvalds 已提交
47

D
David Gibson 已提交
48
struct hugetlbfs_config {
49 50 51 52 53 54 55
	struct hstate		*hstate;
	long			max_hpages;
	long			nr_inodes;
	long			min_hpages;
	kuid_t			uid;
	kgid_t			gid;
	umode_t			mode;
D
David Gibson 已提交
56 57
};

L
Linus Torvalds 已提交
58 59
int sysctl_hugetlb_shm_group;

60 61 62
enum {
	Opt_size, Opt_nr_inodes,
	Opt_mode, Opt_uid, Opt_gid,
63
	Opt_pagesize, Opt_min_size,
64 65 66
	Opt_err,
};

67
static const match_table_t tokens = {
68 69 70 71 72
	{Opt_size,	"size=%s"},
	{Opt_nr_inodes,	"nr_inodes=%s"},
	{Opt_mode,	"mode=%o"},
	{Opt_uid,	"uid=%u"},
	{Opt_gid,	"gid=%u"},
73
	{Opt_pagesize,	"pagesize=%s"},
74
	{Opt_min_size,	"min_size=%s"},
75 76 77
	{Opt_err,	NULL},
};

78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
#ifdef CONFIG_NUMA
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
	vma->vm_policy = mpol_shared_policy_lookup(&HUGETLBFS_I(inode)->policy,
							index);
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
	mpol_cond_put(vma->vm_policy);
}
#else
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
}
#endif

101 102 103 104 105 106 107 108 109 110
static void huge_pagevec_release(struct pagevec *pvec)
{
	int i;

	for (i = 0; i < pagevec_count(pvec); ++i)
		put_page(pvec->pages[i]);

	pagevec_reinit(pvec);
}

111 112 113 114 115 116 117 118 119 120
/*
 * Mask used when checking the page offset value passed in via system
 * calls.  This value will be converted to a loff_t which is signed.
 * Therefore, we want to check the upper PAGE_SHIFT + 1 bits of the
 * value.  The extra bit (- 1 in the shift value) is to take the sign
 * bit into account.
 */
#define PGOFF_LOFFT_MAX \
	(((1UL << (PAGE_SHIFT + 1)) - 1) <<  (BITS_PER_LONG - (PAGE_SHIFT + 1)))

L
Linus Torvalds 已提交
121 122
static int hugetlbfs_file_mmap(struct file *file, struct vm_area_struct *vma)
{
A
Al Viro 已提交
123
	struct inode *inode = file_inode(file);
L
Linus Torvalds 已提交
124 125
	loff_t len, vma_len;
	int ret;
126
	struct hstate *h = hstate_file(file);
L
Linus Torvalds 已提交
127

128
	/*
129 130 131 132 133 134
	 * vma address alignment (but not the pgoff alignment) has
	 * already been checked by prepare_hugepage_range.  If you add
	 * any error returns here, do so after setting VM_HUGETLB, so
	 * is_vm_hugetlb_page tests below unmap_region go the right
	 * way when do_mmap_pgoff unwinds (may be important on powerpc
	 * and ia64).
135
	 */
136
	vma->vm_flags |= VM_HUGETLB | VM_DONTEXPAND;
137
	vma->vm_ops = &hugetlb_vm_ops;
L
Linus Torvalds 已提交
138

139
	/*
140
	 * page based offset in vm_pgoff could be sufficiently large to
141 142 143
	 * overflow a loff_t when converted to byte offset.  This can
	 * only happen on architectures where sizeof(loff_t) ==
	 * sizeof(unsigned long).  So, only check in those instances.
144
	 */
145 146 147 148
	if (sizeof(unsigned long) == sizeof(loff_t)) {
		if (vma->vm_pgoff & PGOFF_LOFFT_MAX)
			return -EINVAL;
	}
149

150
	/* must be huge page aligned */
151
	if (vma->vm_pgoff & (~huge_page_mask(h) >> PAGE_SHIFT))
152 153
		return -EINVAL;

L
Linus Torvalds 已提交
154
	vma_len = (loff_t)(vma->vm_end - vma->vm_start);
155 156 157 158
	len = vma_len + ((loff_t)vma->vm_pgoff << PAGE_SHIFT);
	/* check for overflow */
	if (len < vma_len)
		return -EINVAL;
L
Linus Torvalds 已提交
159

A
Al Viro 已提交
160
	inode_lock(inode);
L
Linus Torvalds 已提交
161 162 163
	file_accessed(file);

	ret = -ENOMEM;
164
	if (hugetlb_reserve_pages(inode,
165
				vma->vm_pgoff >> huge_page_order(h),
166 167
				len >> huge_page_shift(h), vma,
				vma->vm_flags))
168
		goto out;
169

A
Adam Litke 已提交
170
	ret = 0;
171
	if (vma->vm_flags & VM_WRITE && inode->i_size < len)
172
		i_size_write(inode, len);
L
Linus Torvalds 已提交
173
out:
A
Al Viro 已提交
174
	inode_unlock(inode);
L
Linus Torvalds 已提交
175 176 177 178 179

	return ret;
}

/*
180
 * Called under down_write(mmap_sem).
L
Linus Torvalds 已提交
181 182
 */

183
#ifndef HAVE_ARCH_HUGETLB_UNMAPPED_AREA
L
Linus Torvalds 已提交
184 185 186 187 188 189
static unsigned long
hugetlb_get_unmapped_area(struct file *file, unsigned long addr,
		unsigned long len, unsigned long pgoff, unsigned long flags)
{
	struct mm_struct *mm = current->mm;
	struct vm_area_struct *vma;
190
	struct hstate *h = hstate_file(file);
191
	struct vm_unmapped_area_info info;
L
Linus Torvalds 已提交
192

193
	if (len & ~huge_page_mask(h))
L
Linus Torvalds 已提交
194 195 196 197
		return -EINVAL;
	if (len > TASK_SIZE)
		return -ENOMEM;

198
	if (flags & MAP_FIXED) {
199
		if (prepare_hugepage_range(file, addr, len))
200 201 202 203
			return -EINVAL;
		return addr;
	}

L
Linus Torvalds 已提交
204
	if (addr) {
205
		addr = ALIGN(addr, huge_page_size(h));
L
Linus Torvalds 已提交
206 207
		vma = find_vma(mm, addr);
		if (TASK_SIZE - len >= addr &&
208
		    (!vma || addr + len <= vm_start_gap(vma)))
L
Linus Torvalds 已提交
209 210 211
			return addr;
	}

212 213 214 215 216 217 218
	info.flags = 0;
	info.length = len;
	info.low_limit = TASK_UNMAPPED_BASE;
	info.high_limit = TASK_SIZE;
	info.align_mask = PAGE_MASK & ~huge_page_mask(h);
	info.align_offset = 0;
	return vm_unmapped_area(&info);
L
Linus Torvalds 已提交
219 220 221
}
#endif

A
Al Viro 已提交
222
static size_t
B
Badari Pulavarty 已提交
223
hugetlbfs_read_actor(struct page *page, unsigned long offset,
A
Al Viro 已提交
224
			struct iov_iter *to, unsigned long size)
B
Badari Pulavarty 已提交
225
{
A
Al Viro 已提交
226
	size_t copied = 0;
B
Badari Pulavarty 已提交
227 228 229
	int i, chunksize;

	/* Find which 4k chunk and offset with in that chunk */
230 231
	i = offset >> PAGE_SHIFT;
	offset = offset & ~PAGE_MASK;
B
Badari Pulavarty 已提交
232 233

	while (size) {
A
Al Viro 已提交
234
		size_t n;
235
		chunksize = PAGE_SIZE;
B
Badari Pulavarty 已提交
236 237 238 239
		if (offset)
			chunksize -= offset;
		if (chunksize > size)
			chunksize = size;
A
Al Viro 已提交
240 241 242 243
		n = copy_page_to_iter(&page[i], offset, chunksize, to);
		copied += n;
		if (n != chunksize)
			return copied;
B
Badari Pulavarty 已提交
244 245 246 247
		offset = 0;
		size -= chunksize;
		i++;
	}
A
Al Viro 已提交
248
	return copied;
B
Badari Pulavarty 已提交
249 250 251 252 253
}

/*
 * Support for read() - Find the page attached to f_mapping and copy out the
 * data. Its *very* similar to do_generic_mapping_read(), we can't use that
254
 * since it has PAGE_SIZE assumptions.
B
Badari Pulavarty 已提交
255
 */
A
Al Viro 已提交
256
static ssize_t hugetlbfs_read_iter(struct kiocb *iocb, struct iov_iter *to)
B
Badari Pulavarty 已提交
257
{
A
Al Viro 已提交
258 259 260
	struct file *file = iocb->ki_filp;
	struct hstate *h = hstate_file(file);
	struct address_space *mapping = file->f_mapping;
B
Badari Pulavarty 已提交
261
	struct inode *inode = mapping->host;
A
Al Viro 已提交
262 263
	unsigned long index = iocb->ki_pos >> huge_page_shift(h);
	unsigned long offset = iocb->ki_pos & ~huge_page_mask(h);
B
Badari Pulavarty 已提交
264 265 266 267
	unsigned long end_index;
	loff_t isize;
	ssize_t retval = 0;

A
Al Viro 已提交
268
	while (iov_iter_count(to)) {
B
Badari Pulavarty 已提交
269
		struct page *page;
A
Al Viro 已提交
270
		size_t nr, copied;
B
Badari Pulavarty 已提交
271 272

		/* nr is the maximum number of bytes to copy from this page */
273
		nr = huge_page_size(h);
274 275
		isize = i_size_read(inode);
		if (!isize)
A
Al Viro 已提交
276
			break;
277
		end_index = (isize - 1) >> huge_page_shift(h);
A
Al Viro 已提交
278 279 280
		if (index > end_index)
			break;
		if (index == end_index) {
281
			nr = ((isize - 1) & ~huge_page_mask(h)) + 1;
282
			if (nr <= offset)
A
Al Viro 已提交
283
				break;
B
Badari Pulavarty 已提交
284 285 286 287
		}
		nr = nr - offset;

		/* Find the page */
288
		page = find_lock_page(mapping, index);
B
Badari Pulavarty 已提交
289 290 291 292 293
		if (unlikely(page == NULL)) {
			/*
			 * We have a HOLE, zero out the user-buffer for the
			 * length of the hole or request.
			 */
A
Al Viro 已提交
294
			copied = iov_iter_zero(nr, to);
B
Badari Pulavarty 已提交
295
		} else {
296 297
			unlock_page(page);

B
Badari Pulavarty 已提交
298 299 300
			/*
			 * We have the page, copy it to user space buffer.
			 */
A
Al Viro 已提交
301
			copied = hugetlbfs_read_actor(page, offset, to, nr);
302
			put_page(page);
B
Badari Pulavarty 已提交
303
		}
A
Al Viro 已提交
304 305 306 307 308 309
		offset += copied;
		retval += copied;
		if (copied != nr && iov_iter_count(to)) {
			if (!retval)
				retval = -EFAULT;
			break;
B
Badari Pulavarty 已提交
310
		}
311 312
		index += offset >> huge_page_shift(h);
		offset &= ~huge_page_mask(h);
B
Badari Pulavarty 已提交
313
	}
A
Al Viro 已提交
314
	iocb->ki_pos = ((loff_t)index << huge_page_shift(h)) + offset;
B
Badari Pulavarty 已提交
315 316 317
	return retval;
}

N
Nick Piggin 已提交
318 319 320 321
static int hugetlbfs_write_begin(struct file *file,
			struct address_space *mapping,
			loff_t pos, unsigned len, unsigned flags,
			struct page **pagep, void **fsdata)
L
Linus Torvalds 已提交
322 323 324 325
{
	return -EINVAL;
}

N
Nick Piggin 已提交
326 327 328
static int hugetlbfs_write_end(struct file *file, struct address_space *mapping,
			loff_t pos, unsigned len, unsigned copied,
			struct page *page, void *fsdata)
L
Linus Torvalds 已提交
329
{
N
Nick Piggin 已提交
330
	BUG();
L
Linus Torvalds 已提交
331 332 333
	return -EINVAL;
}

334
static void remove_huge_page(struct page *page)
L
Linus Torvalds 已提交
335
{
336
	ClearPageDirty(page);
L
Linus Torvalds 已提交
337
	ClearPageUptodate(page);
338
	delete_from_page_cache(page);
L
Linus Torvalds 已提交
339 340
}

341
static void
342
hugetlb_vmdelete_list(struct rb_root_cached *root, pgoff_t start, pgoff_t end)
343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377
{
	struct vm_area_struct *vma;

	/*
	 * end == 0 indicates that the entire range after
	 * start should be unmapped.
	 */
	vma_interval_tree_foreach(vma, root, start, end ? end : ULONG_MAX) {
		unsigned long v_offset;
		unsigned long v_end;

		/*
		 * Can the expression below overflow on 32-bit arches?
		 * No, because the interval tree returns us only those vmas
		 * which overlap the truncated area starting at pgoff,
		 * and no vma on a 32-bit arch can span beyond the 4GB.
		 */
		if (vma->vm_pgoff < start)
			v_offset = (start - vma->vm_pgoff) << PAGE_SHIFT;
		else
			v_offset = 0;

		if (!end)
			v_end = vma->vm_end;
		else {
			v_end = ((end - vma->vm_pgoff) << PAGE_SHIFT)
							+ vma->vm_start;
			if (v_end > vma->vm_end)
				v_end = vma->vm_end;
		}

		unmap_hugepage_range(vma, vma->vm_start + v_offset, v_end,
									NULL);
	}
}
378 379 380 381

/*
 * remove_inode_hugepages handles two distinct cases: truncation and hole
 * punch.  There are subtle differences in operation for each case.
382
 *
383 384 385
 * truncation is indicated by end of range being LLONG_MAX
 *	In this case, we first scan the range and release found pages.
 *	After releasing pages, hugetlb_unreserve_pages cleans up region/reserv
386 387 388 389 390
 *	maps and global counts.  Page faults can not race with truncation
 *	in this routine.  hugetlb_no_page() prevents page faults in the
 *	truncated range.  It checks i_size before allocation, and again after
 *	with the page table lock for the page held.  The same lock must be
 *	acquired to unmap a page.
391 392 393 394
 * hole punch is indicated if end is not LLONG_MAX
 *	In the hole punch case we scan the range and release found pages.
 *	Only when releasing a page is the associated region/reserv map
 *	deleted.  The region/reserv map for ranges without associated
395 396
 *	pages are not modified.  Page faults can race with hole punch.
 *	This is indicated if we find a mapped page.
397 398 399 400 401
 * Note: If the passed end of range value is beyond the end of file, but
 * not LLONG_MAX this routine still performs a hole punch operation.
 */
static void remove_inode_hugepages(struct inode *inode, loff_t lstart,
				   loff_t lend)
L
Linus Torvalds 已提交
402
{
403
	struct hstate *h = hstate_inode(inode);
404
	struct address_space *mapping = &inode->i_data;
405
	const pgoff_t start = lstart >> huge_page_shift(h);
406 407
	const pgoff_t end = lend >> huge_page_shift(h);
	struct vm_area_struct pseudo_vma;
L
Linus Torvalds 已提交
408
	struct pagevec pvec;
409
	pgoff_t next, index;
410
	int i, freed = 0;
411
	bool truncate_op = (lend == LLONG_MAX);
L
Linus Torvalds 已提交
412

413
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
414
	vma_init(&pseudo_vma, current->mm);
415
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
416
	pagevec_init(&pvec);
L
Linus Torvalds 已提交
417
	next = start;
418 419
	while (next < end) {
		/*
420
		 * When no more pages are found, we are done.
421
		 */
422
		if (!pagevec_lookup_range(&pvec, mapping, &next, end - 1))
423
			break;
L
Linus Torvalds 已提交
424 425 426

		for (i = 0; i < pagevec_count(&pvec); ++i) {
			struct page *page = pvec.pages[i];
427 428
			u32 hash;

429
			index = page->index;
430 431
			hash = hugetlb_fault_mutex_hash(h, current->mm,
							&pseudo_vma,
432
							mapping, index, 0);
433
			mutex_lock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
434

435 436 437 438 439 440 441 442 443 444
			/*
			 * If page is mapped, it was faulted in after being
			 * unmapped in caller.  Unmap (again) now after taking
			 * the fault mutex.  The mutex will prevent faults
			 * until we finish removing the page.
			 *
			 * This race can only happen in the hole punch case.
			 * Getting here in a truncate operation is a bug.
			 */
			if (unlikely(page_mapped(page))) {
445
				BUG_ON(truncate_op);
446 447 448

				i_mmap_lock_write(mapping);
				hugetlb_vmdelete_list(&mapping->i_mmap,
449 450
					index * pages_per_huge_page(h),
					(index + 1) * pages_per_huge_page(h));
451 452 453 454 455 456 457 458 459
				i_mmap_unlock_write(mapping);
			}

			lock_page(page);
			/*
			 * We must free the huge page and remove from page
			 * cache (remove_huge_page) BEFORE removing the
			 * region/reserve map (hugetlb_unreserve_pages).  In
			 * rare out of memory conditions, removal of the
460 461 462
			 * region/reserve map could fail. Correspondingly,
			 * the subpool and global reserve usage count can need
			 * to be adjusted.
463
			 */
464
			VM_BUG_ON(PagePrivate(page));
465 466 467 468
			remove_huge_page(page);
			freed++;
			if (!truncate_op) {
				if (unlikely(hugetlb_unreserve_pages(inode,
469
							index, index + 1, 1)))
470
					hugetlb_fix_reserve_counts(inode);
471 472
			}

L
Linus Torvalds 已提交
473
			unlock_page(page);
474
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
475 476
		}
		huge_pagevec_release(&pvec);
477
		cond_resched();
L
Linus Torvalds 已提交
478
	}
479 480 481

	if (truncate_op)
		(void)hugetlb_unreserve_pages(inode, start, LONG_MAX, freed);
L
Linus Torvalds 已提交
482 483
}

A
Al Viro 已提交
484
static void hugetlbfs_evict_inode(struct inode *inode)
L
Linus Torvalds 已提交
485
{
486 487
	struct resv_map *resv_map;

488
	remove_inode_hugepages(inode, 0, LLONG_MAX);
489 490 491 492
	resv_map = (struct resv_map *)inode->i_mapping->private_data;
	/* root inode doesn't have the resv_map, so we should check it */
	if (resv_map)
		resv_map_release(&resv_map->refs);
493
	clear_inode(inode);
494 495
}

L
Linus Torvalds 已提交
496 497
static int hugetlb_vmtruncate(struct inode *inode, loff_t offset)
{
H
Hugh Dickins 已提交
498
	pgoff_t pgoff;
L
Linus Torvalds 已提交
499
	struct address_space *mapping = inode->i_mapping;
500
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
501

502
	BUG_ON(offset & ~huge_page_mask(h));
H
Hugh Dickins 已提交
503
	pgoff = offset >> PAGE_SHIFT;
L
Linus Torvalds 已提交
504

505
	i_size_write(inode, offset);
506
	i_mmap_lock_write(mapping);
507
	if (!RB_EMPTY_ROOT(&mapping->i_mmap.rb_root))
508
		hugetlb_vmdelete_list(&mapping->i_mmap, pgoff, 0);
509
	i_mmap_unlock_write(mapping);
510
	remove_inode_hugepages(inode, offset, LLONG_MAX);
L
Linus Torvalds 已提交
511 512 513
	return 0;
}

514 515 516 517 518 519 520 521 522 523 524 525 526 527 528
static long hugetlbfs_punch_hole(struct inode *inode, loff_t offset, loff_t len)
{
	struct hstate *h = hstate_inode(inode);
	loff_t hpage_size = huge_page_size(h);
	loff_t hole_start, hole_end;

	/*
	 * For hole punch round up the beginning offset of the hole and
	 * round down the end.
	 */
	hole_start = round_up(offset, hpage_size);
	hole_end = round_down(offset + len, hpage_size);

	if (hole_end > hole_start) {
		struct address_space *mapping = inode->i_mapping;
529
		struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
530

A
Al Viro 已提交
531
		inode_lock(inode);
532 533 534 535 536 537 538

		/* protected by i_mutex */
		if (info->seals & F_SEAL_WRITE) {
			inode_unlock(inode);
			return -EPERM;
		}

539
		i_mmap_lock_write(mapping);
540
		if (!RB_EMPTY_ROOT(&mapping->i_mmap.rb_root))
541 542 543 544 545
			hugetlb_vmdelete_list(&mapping->i_mmap,
						hole_start >> PAGE_SHIFT,
						hole_end  >> PAGE_SHIFT);
		i_mmap_unlock_write(mapping);
		remove_inode_hugepages(inode, hole_start, hole_end);
A
Al Viro 已提交
546
		inode_unlock(inode);
547 548 549 550 551 552 553 554 555
	}

	return 0;
}

static long hugetlbfs_fallocate(struct file *file, int mode, loff_t offset,
				loff_t len)
{
	struct inode *inode = file_inode(file);
556
	struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580
	struct address_space *mapping = inode->i_mapping;
	struct hstate *h = hstate_inode(inode);
	struct vm_area_struct pseudo_vma;
	struct mm_struct *mm = current->mm;
	loff_t hpage_size = huge_page_size(h);
	unsigned long hpage_shift = huge_page_shift(h);
	pgoff_t start, index, end;
	int error;
	u32 hash;

	if (mode & ~(FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE))
		return -EOPNOTSUPP;

	if (mode & FALLOC_FL_PUNCH_HOLE)
		return hugetlbfs_punch_hole(inode, offset, len);

	/*
	 * Default preallocate case.
	 * For this range, start is rounded down and end is rounded up
	 * as well as being converted to page offsets.
	 */
	start = offset >> hpage_shift;
	end = (offset + len + hpage_size - 1) >> hpage_shift;

A
Al Viro 已提交
581
	inode_lock(inode);
582 583 584 585 586 587

	/* We need to check rlimit even when FALLOC_FL_KEEP_SIZE */
	error = inode_newsize_ok(inode, offset + len);
	if (error)
		goto out;

588 589 590 591 592
	if ((info->seals & F_SEAL_GROW) && offset + len > inode->i_size) {
		error = -EPERM;
		goto out;
	}

593 594 595 596 597 598
	/*
	 * Initialize a pseudo vma as this is required by the huge page
	 * allocation routines.  If NUMA is configured, use page index
	 * as input to create an allocation policy.
	 */
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
599
	vma_init(&pseudo_vma, mm);
600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
	pseudo_vma.vm_file = file;

	for (index = start; index < end; index++) {
		/*
		 * This is supposed to be the vaddr where the page is being
		 * faulted in, but we have no vaddr here.
		 */
		struct page *page;
		unsigned long addr;
		int avoid_reserve = 0;

		cond_resched();

		/*
		 * fallocate(2) manpage permits EINTR; we may have been
		 * interrupted because we are using up too much memory.
		 */
		if (signal_pending(current)) {
			error = -EINTR;
			break;
		}

		/* Set numa allocation policy based on index */
		hugetlb_set_vma_policy(&pseudo_vma, inode, index);

		/* addr is the offset within the file (zero based) */
		addr = index * hpage_size;

		/* mutex taken here, fault path and hole punch */
		hash = hugetlb_fault_mutex_hash(h, mm, &pseudo_vma, mapping,
						index, addr);
		mutex_lock(&hugetlb_fault_mutex_table[hash]);

		/* See if already present in mapping to avoid alloc/free */
		page = find_get_page(mapping, index);
		if (page) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			hugetlb_drop_vma_policy(&pseudo_vma);
			continue;
		}

		/* Allocate page and add to page cache */
		page = alloc_huge_page(&pseudo_vma, addr, avoid_reserve);
		hugetlb_drop_vma_policy(&pseudo_vma);
		if (IS_ERR(page)) {
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			error = PTR_ERR(page);
			goto out;
		}
		clear_huge_page(page, addr, pages_per_huge_page(h));
		__SetPageUptodate(page);
		error = huge_add_to_page_cache(page, mapping, index);
		if (unlikely(error)) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			goto out;
		}

		mutex_unlock(&hugetlb_fault_mutex_table[hash]);

		/*
		 * unlock_page because locked by add_to_page_cache()
664
		 * page_put due to reference from alloc_huge_page()
665 666
		 */
		unlock_page(page);
667
		put_page(page);
668 669 670 671
	}

	if (!(mode & FALLOC_FL_KEEP_SIZE) && offset + len > inode->i_size)
		i_size_write(inode, offset + len);
672
	inode->i_ctime = current_time(inode);
673
out:
A
Al Viro 已提交
674
	inode_unlock(inode);
675 676 677
	return error;
}

L
Linus Torvalds 已提交
678 679
static int hugetlbfs_setattr(struct dentry *dentry, struct iattr *attr)
{
680
	struct inode *inode = d_inode(dentry);
681
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
682 683
	int error;
	unsigned int ia_valid = attr->ia_valid;
684
	struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
L
Linus Torvalds 已提交
685 686 687

	BUG_ON(!inode);

688
	error = setattr_prepare(dentry, attr);
L
Linus Torvalds 已提交
689
	if (error)
C
Christoph Hellwig 已提交
690
		return error;
L
Linus Torvalds 已提交
691 692

	if (ia_valid & ATTR_SIZE) {
693 694 695 696
		loff_t oldsize = inode->i_size;
		loff_t newsize = attr->ia_size;

		if (newsize & ~huge_page_mask(h))
C
Christoph Hellwig 已提交
697
			return -EINVAL;
698 699 700 701 702
		/* protected by i_mutex */
		if ((newsize < oldsize && (info->seals & F_SEAL_SHRINK)) ||
		    (newsize > oldsize && (info->seals & F_SEAL_GROW)))
			return -EPERM;
		error = hugetlb_vmtruncate(inode, newsize);
L
Linus Torvalds 已提交
703
		if (error)
C
Christoph Hellwig 已提交
704
			return error;
L
Linus Torvalds 已提交
705
	}
C
Christoph Hellwig 已提交
706 707 708 709

	setattr_copy(inode, attr);
	mark_inode_dirty(inode);
	return 0;
L
Linus Torvalds 已提交
710 711
}

712 713
static struct inode *hugetlbfs_get_root(struct super_block *sb,
					struct hugetlbfs_config *config)
L
Linus Torvalds 已提交
714 715 716 717 718
{
	struct inode *inode;

	inode = new_inode(sb);
	if (inode) {
719
		inode->i_ino = get_next_ino();
720 721 722
		inode->i_mode = S_IFDIR | config->mode;
		inode->i_uid = config->uid;
		inode->i_gid = config->gid;
723
		inode->i_atime = inode->i_mtime = inode->i_ctime = current_time(inode);
724 725 726 727
		inode->i_op = &hugetlbfs_dir_inode_operations;
		inode->i_fop = &simple_dir_operations;
		/* directory inodes start off with i_nlink == 2 (for "." entry) */
		inc_nlink(inode);
728
		lockdep_annotate_inode_mutex_key(inode);
729 730 731 732
	}
	return inode;
}

733
/*
734
 * Hugetlbfs is not reclaimable; therefore its i_mmap_rwsem will never
735
 * be taken from reclaim -- unlike regular filesystems. This needs an
736
 * annotation because huge_pmd_share() does an allocation under hugetlb's
737
 * i_mmap_rwsem.
738
 */
739
static struct lock_class_key hugetlbfs_i_mmap_rwsem_key;
740

741 742
static struct inode *hugetlbfs_get_inode(struct super_block *sb,
					struct inode *dir,
A
Al Viro 已提交
743
					umode_t mode, dev_t dev)
744 745
{
	struct inode *inode;
746 747 748 749 750
	struct resv_map *resv_map;

	resv_map = resv_map_alloc();
	if (!resv_map)
		return NULL;
751 752 753

	inode = new_inode(sb);
	if (inode) {
754 755
		struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);

756 757
		inode->i_ino = get_next_ino();
		inode_init_owner(inode, dir, mode);
758 759
		lockdep_set_class(&inode->i_mapping->i_mmap_rwsem,
				&hugetlbfs_i_mmap_rwsem_key);
L
Linus Torvalds 已提交
760
		inode->i_mapping->a_ops = &hugetlbfs_aops;
761
		inode->i_atime = inode->i_mtime = inode->i_ctime = current_time(inode);
762
		inode->i_mapping->private_data = resv_map;
763
		info->seals = F_SEAL_SEAL;
L
Linus Torvalds 已提交
764 765 766 767 768 769 770 771 772 773 774 775 776
		switch (mode & S_IFMT) {
		default:
			init_special_inode(inode, mode, dev);
			break;
		case S_IFREG:
			inode->i_op = &hugetlbfs_inode_operations;
			inode->i_fop = &hugetlbfs_file_operations;
			break;
		case S_IFDIR:
			inode->i_op = &hugetlbfs_dir_inode_operations;
			inode->i_fop = &simple_dir_operations;

			/* directory inodes start off with i_nlink == 2 (for "." entry) */
777
			inc_nlink(inode);
L
Linus Torvalds 已提交
778 779 780
			break;
		case S_IFLNK:
			inode->i_op = &page_symlink_inode_operations;
781
			inode_nohighmem(inode);
L
Linus Torvalds 已提交
782 783
			break;
		}
784
		lockdep_annotate_inode_mutex_key(inode);
785 786 787
	} else
		kref_put(&resv_map->refs, resv_map_release);

L
Linus Torvalds 已提交
788 789 790 791 792 793 794
	return inode;
}

/*
 * File creation. Allocate an inode, and we're done..
 */
static int hugetlbfs_mknod(struct inode *dir,
A
Al Viro 已提交
795
			struct dentry *dentry, umode_t mode, dev_t dev)
L
Linus Torvalds 已提交
796 797 798
{
	struct inode *inode;
	int error = -ENOSPC;
799 800

	inode = hugetlbfs_get_inode(dir->i_sb, dir, mode, dev);
L
Linus Torvalds 已提交
801
	if (inode) {
802
		dir->i_ctime = dir->i_mtime = current_time(dir);
L
Linus Torvalds 已提交
803 804 805 806 807 808 809
		d_instantiate(dentry, inode);
		dget(dentry);	/* Extra count - pin the dentry in core */
		error = 0;
	}
	return error;
}

810
static int hugetlbfs_mkdir(struct inode *dir, struct dentry *dentry, umode_t mode)
L
Linus Torvalds 已提交
811 812 813
{
	int retval = hugetlbfs_mknod(dir, dentry, mode | S_IFDIR, 0);
	if (!retval)
814
		inc_nlink(dir);
L
Linus Torvalds 已提交
815 816 817
	return retval;
}

A
Al Viro 已提交
818
static int hugetlbfs_create(struct inode *dir, struct dentry *dentry, umode_t mode, bool excl)
L
Linus Torvalds 已提交
819 820 821 822 823 824 825 826 827 828
{
	return hugetlbfs_mknod(dir, dentry, mode | S_IFREG, 0);
}

static int hugetlbfs_symlink(struct inode *dir,
			struct dentry *dentry, const char *symname)
{
	struct inode *inode;
	int error = -ENOSPC;

829
	inode = hugetlbfs_get_inode(dir->i_sb, dir, S_IFLNK|S_IRWXUGO, 0);
L
Linus Torvalds 已提交
830 831 832 833 834 835 836 837 838
	if (inode) {
		int l = strlen(symname)+1;
		error = page_symlink(inode, symname, l);
		if (!error) {
			d_instantiate(dentry, inode);
			dget(dentry);
		} else
			iput(inode);
	}
839
	dir->i_ctime = dir->i_mtime = current_time(dir);
L
Linus Torvalds 已提交
840 841 842 843 844

	return error;
}

/*
845
 * mark the head page dirty
L
Linus Torvalds 已提交
846 847 848
 */
static int hugetlbfs_set_page_dirty(struct page *page)
{
849
	struct page *head = compound_head(page);
850 851

	SetPageDirty(head);
L
Linus Torvalds 已提交
852 853 854
	return 0;
}

N
Naoya Horiguchi 已提交
855
static int hugetlbfs_migrate_page(struct address_space *mapping,
856
				struct page *newpage, struct page *page,
857
				enum migrate_mode mode)
N
Naoya Horiguchi 已提交
858 859 860 861
{
	int rc;

	rc = migrate_huge_page_move_mapping(mapping, newpage, page);
862
	if (rc != MIGRATEPAGE_SUCCESS)
N
Naoya Horiguchi 已提交
863
		return rc;
864 865 866 867
	if (mode != MIGRATE_SYNC_NO_COPY)
		migrate_page_copy(newpage, page);
	else
		migrate_page_states(newpage, page);
N
Naoya Horiguchi 已提交
868

869
	return MIGRATEPAGE_SUCCESS;
N
Naoya Horiguchi 已提交
870 871
}

872 873 874 875
static int hugetlbfs_error_remove_page(struct address_space *mapping,
				struct page *page)
{
	struct inode *inode = mapping->host;
876
	pgoff_t index = page->index;
877 878

	remove_huge_page(page);
879 880 881
	if (unlikely(hugetlb_unreserve_pages(inode, index, index + 1, 1)))
		hugetlb_fix_reserve_counts(inode);

882 883 884
	return 0;
}

885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924
/*
 * Display the mount options in /proc/mounts.
 */
static int hugetlbfs_show_options(struct seq_file *m, struct dentry *root)
{
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(root->d_sb);
	struct hugepage_subpool *spool = sbinfo->spool;
	unsigned long hpage_size = huge_page_size(sbinfo->hstate);
	unsigned hpage_shift = huge_page_shift(sbinfo->hstate);
	char mod;

	if (!uid_eq(sbinfo->uid, GLOBAL_ROOT_UID))
		seq_printf(m, ",uid=%u",
			   from_kuid_munged(&init_user_ns, sbinfo->uid));
	if (!gid_eq(sbinfo->gid, GLOBAL_ROOT_GID))
		seq_printf(m, ",gid=%u",
			   from_kgid_munged(&init_user_ns, sbinfo->gid));
	if (sbinfo->mode != 0755)
		seq_printf(m, ",mode=%o", sbinfo->mode);
	if (sbinfo->max_inodes != -1)
		seq_printf(m, ",nr_inodes=%lu", sbinfo->max_inodes);

	hpage_size /= 1024;
	mod = 'K';
	if (hpage_size >= 1024) {
		hpage_size /= 1024;
		mod = 'M';
	}
	seq_printf(m, ",pagesize=%lu%c", hpage_size, mod);
	if (spool) {
		if (spool->max_hpages != -1)
			seq_printf(m, ",size=%llu",
				   (unsigned long long)spool->max_hpages << hpage_shift);
		if (spool->min_hpages != -1)
			seq_printf(m, ",min_size=%llu",
				   (unsigned long long)spool->min_hpages << hpage_shift);
	}
	return 0;
}

925
static int hugetlbfs_statfs(struct dentry *dentry, struct kstatfs *buf)
L
Linus Torvalds 已提交
926
{
927
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(dentry->d_sb);
928
	struct hstate *h = hstate_inode(d_inode(dentry));
L
Linus Torvalds 已提交
929 930

	buf->f_type = HUGETLBFS_MAGIC;
931
	buf->f_bsize = huge_page_size(h);
L
Linus Torvalds 已提交
932 933
	if (sbinfo) {
		spin_lock(&sbinfo->stat_lock);
934 935
		/* If no limits set, just report 0 for max/free/used
		 * blocks, like simple_statfs() */
936 937 938 939 940 941 942 943 944
		if (sbinfo->spool) {
			long free_pages;

			spin_lock(&sbinfo->spool->lock);
			buf->f_blocks = sbinfo->spool->max_hpages;
			free_pages = sbinfo->spool->max_hpages
				- sbinfo->spool->used_hpages;
			buf->f_bavail = buf->f_bfree = free_pages;
			spin_unlock(&sbinfo->spool->lock);
945 946 947
			buf->f_files = sbinfo->max_inodes;
			buf->f_ffree = sbinfo->free_inodes;
		}
L
Linus Torvalds 已提交
948 949 950 951 952 953 954 955 956 957 958 959
		spin_unlock(&sbinfo->stat_lock);
	}
	buf->f_namelen = NAME_MAX;
	return 0;
}

static void hugetlbfs_put_super(struct super_block *sb)
{
	struct hugetlbfs_sb_info *sbi = HUGETLBFS_SB(sb);

	if (sbi) {
		sb->s_fs_info = NULL;
960 961 962 963

		if (sbi->spool)
			hugepage_put_subpool(sbi->spool);

L
Linus Torvalds 已提交
964 965 966 967
		kfree(sbi);
	}
}

968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992
static inline int hugetlbfs_dec_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		if (unlikely(!sbinfo->free_inodes)) {
			spin_unlock(&sbinfo->stat_lock);
			return 0;
		}
		sbinfo->free_inodes--;
		spin_unlock(&sbinfo->stat_lock);
	}

	return 1;
}

static void hugetlbfs_inc_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		sbinfo->free_inodes++;
		spin_unlock(&sbinfo->stat_lock);
	}
}


993
static struct kmem_cache *hugetlbfs_inode_cachep;
L
Linus Torvalds 已提交
994 995 996

static struct inode *hugetlbfs_alloc_inode(struct super_block *sb)
{
997
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(sb);
L
Linus Torvalds 已提交
998 999
	struct hugetlbfs_inode_info *p;

1000 1001
	if (unlikely(!hugetlbfs_dec_free_inodes(sbinfo)))
		return NULL;
1002
	p = kmem_cache_alloc(hugetlbfs_inode_cachep, GFP_KERNEL);
1003 1004
	if (unlikely(!p)) {
		hugetlbfs_inc_free_inodes(sbinfo);
L
Linus Torvalds 已提交
1005
		return NULL;
1006
	}
1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018

	/*
	 * Any time after allocation, hugetlbfs_destroy_inode can be called
	 * for the inode.  mpol_free_shared_policy is unconditionally called
	 * as part of hugetlbfs_destroy_inode.  So, initialize policy here
	 * in case of a quick call to destroy.
	 *
	 * Note that the policy is initialized even if we are creating a
	 * private inode.  This simplifies hugetlbfs_destroy_inode.
	 */
	mpol_shared_policy_init(&p->policy, NULL);

L
Linus Torvalds 已提交
1019 1020 1021
	return &p->vfs_inode;
}

N
Nick Piggin 已提交
1022 1023 1024 1025 1026 1027
static void hugetlbfs_i_callback(struct rcu_head *head)
{
	struct inode *inode = container_of(head, struct inode, i_rcu);
	kmem_cache_free(hugetlbfs_inode_cachep, HUGETLBFS_I(inode));
}

L
Linus Torvalds 已提交
1028 1029
static void hugetlbfs_destroy_inode(struct inode *inode)
{
1030
	hugetlbfs_inc_free_inodes(HUGETLBFS_SB(inode->i_sb));
L
Linus Torvalds 已提交
1031
	mpol_free_shared_policy(&HUGETLBFS_I(inode)->policy);
N
Nick Piggin 已提交
1032
	call_rcu(&inode->i_rcu, hugetlbfs_i_callback);
L
Linus Torvalds 已提交
1033 1034
}

1035
static const struct address_space_operations hugetlbfs_aops = {
N
Nick Piggin 已提交
1036 1037
	.write_begin	= hugetlbfs_write_begin,
	.write_end	= hugetlbfs_write_end,
L
Linus Torvalds 已提交
1038
	.set_page_dirty	= hugetlbfs_set_page_dirty,
N
Naoya Horiguchi 已提交
1039
	.migratepage    = hugetlbfs_migrate_page,
1040
	.error_remove_page	= hugetlbfs_error_remove_page,
L
Linus Torvalds 已提交
1041 1042
};

1043

1044
static void init_once(void *foo)
1045 1046 1047
{
	struct hugetlbfs_inode_info *ei = (struct hugetlbfs_inode_info *)foo;

C
Christoph Lameter 已提交
1048
	inode_init_once(&ei->vfs_inode);
1049 1050
}

1051
const struct file_operations hugetlbfs_file_operations = {
A
Al Viro 已提交
1052
	.read_iter		= hugetlbfs_read_iter,
L
Linus Torvalds 已提交
1053
	.mmap			= hugetlbfs_file_mmap,
1054
	.fsync			= noop_fsync,
L
Linus Torvalds 已提交
1055
	.get_unmapped_area	= hugetlb_get_unmapped_area,
1056 1057
	.llseek			= default_llseek,
	.fallocate		= hugetlbfs_fallocate,
L
Linus Torvalds 已提交
1058 1059
};

1060
static const struct inode_operations hugetlbfs_dir_inode_operations = {
L
Linus Torvalds 已提交
1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072
	.create		= hugetlbfs_create,
	.lookup		= simple_lookup,
	.link		= simple_link,
	.unlink		= simple_unlink,
	.symlink	= hugetlbfs_symlink,
	.mkdir		= hugetlbfs_mkdir,
	.rmdir		= simple_rmdir,
	.mknod		= hugetlbfs_mknod,
	.rename		= simple_rename,
	.setattr	= hugetlbfs_setattr,
};

1073
static const struct inode_operations hugetlbfs_inode_operations = {
L
Linus Torvalds 已提交
1074 1075 1076
	.setattr	= hugetlbfs_setattr,
};

1077
static const struct super_operations hugetlbfs_ops = {
L
Linus Torvalds 已提交
1078 1079
	.alloc_inode    = hugetlbfs_alloc_inode,
	.destroy_inode  = hugetlbfs_destroy_inode,
A
Al Viro 已提交
1080
	.evict_inode	= hugetlbfs_evict_inode,
L
Linus Torvalds 已提交
1081 1082
	.statfs		= hugetlbfs_statfs,
	.put_super	= hugetlbfs_put_super,
1083
	.show_options	= hugetlbfs_show_options,
L
Linus Torvalds 已提交
1084 1085
};

1086
enum hugetlbfs_size_type { NO_SIZE, SIZE_STD, SIZE_PERCENT };
1087 1088 1089 1090 1091 1092

/*
 * Convert size option passed from command line to number of huge pages
 * in the pool specified by hstate.  Size option could be in bytes
 * (val_type == SIZE_STD) or percentage of the pool (val_type == SIZE_PERCENT).
 */
1093
static long
1094
hugetlbfs_size_to_hpages(struct hstate *h, unsigned long long size_opt,
1095
			 enum hugetlbfs_size_type val_type)
1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109
{
	if (val_type == NO_SIZE)
		return -1;

	if (val_type == SIZE_PERCENT) {
		size_opt <<= huge_page_shift(h);
		size_opt *= h->max_huge_pages;
		do_div(size_opt, 100);
	}

	size_opt >>= huge_page_shift(h);
	return size_opt;
}

L
Linus Torvalds 已提交
1110 1111 1112
static int
hugetlbfs_parse_options(char *options, struct hugetlbfs_config *pconfig)
{
1113 1114 1115
	char *p, *rest;
	substring_t args[MAX_OPT_ARGS];
	int option;
1116
	unsigned long long max_size_opt = 0, min_size_opt = 0;
1117
	enum hugetlbfs_size_type max_val_type = NO_SIZE, min_val_type = NO_SIZE;
L
Linus Torvalds 已提交
1118 1119 1120 1121

	if (!options)
		return 0;

1122 1123
	while ((p = strsep(&options, ",")) != NULL) {
		int token;
1124 1125
		if (!*p)
			continue;
1126 1127 1128 1129 1130 1131

		token = match_token(p, tokens, args);
		switch (token) {
		case Opt_uid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1132 1133 1134
			pconfig->uid = make_kuid(current_user_ns(), option);
			if (!uid_valid(pconfig->uid))
				goto bad_val;
1135 1136 1137 1138 1139
			break;

		case Opt_gid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1140 1141 1142
			pconfig->gid = make_kgid(current_user_ns(), option);
			if (!gid_valid(pconfig->gid))
				goto bad_val;
1143 1144 1145 1146 1147
			break;

		case Opt_mode:
			if (match_octal(&args[0], &option))
 				goto bad_val;
1148
			pconfig->mode = option & 01777U;
1149 1150 1151 1152 1153 1154
			break;

		case Opt_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
1155 1156
			max_size_opt = memparse(args[0].from, &rest);
			max_val_type = SIZE_STD;
1157
			if (*rest == '%')
1158
				max_val_type = SIZE_PERCENT;
1159 1160
			break;
		}
L
Linus Torvalds 已提交
1161

1162 1163 1164 1165 1166 1167 1168
		case Opt_nr_inodes:
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			pconfig->nr_inodes = memparse(args[0].from, &rest);
			break;

1169 1170 1171 1172 1173
		case Opt_pagesize: {
			unsigned long ps;
			ps = memparse(args[0].from, &rest);
			pconfig->hstate = size_to_hstate(ps);
			if (!pconfig->hstate) {
1174
				pr_err("Unsupported page size %lu MB\n",
1175 1176 1177 1178 1179 1180
					ps >> 20);
				return -EINVAL;
			}
			break;
		}

1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191
		case Opt_min_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			min_size_opt = memparse(args[0].from, &rest);
			min_val_type = SIZE_STD;
			if (*rest == '%')
				min_val_type = SIZE_PERCENT;
			break;
		}

1192
		default:
1193
			pr_err("Bad mount option: \"%s\"\n", p);
1194
			return -EINVAL;
1195 1196
			break;
		}
L
Linus Torvalds 已提交
1197
	}
1198

1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214
	/*
	 * Use huge page pool size (in hstate) to convert the size
	 * options to number of huge pages.  If NO_SIZE, -1 is returned.
	 */
	pconfig->max_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						max_size_opt, max_val_type);
	pconfig->min_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						min_size_opt, min_val_type);

	/*
	 * If max_size was specified, then min_size must be smaller
	 */
	if (max_val_type > NO_SIZE &&
	    pconfig->min_hpages > pconfig->max_hpages) {
		pr_err("minimum size can not be greater than maximum size\n");
		return -EINVAL;
1215 1216
	}

L
Linus Torvalds 已提交
1217
	return 0;
1218 1219

bad_val:
1220
	pr_err("Bad value '%s' for mount option '%s'\n", args[0].from, p);
1221
 	return -EINVAL;
L
Linus Torvalds 已提交
1222 1223 1224 1225 1226 1227 1228 1229 1230
}

static int
hugetlbfs_fill_super(struct super_block *sb, void *data, int silent)
{
	int ret;
	struct hugetlbfs_config config;
	struct hugetlbfs_sb_info *sbinfo;

1231
	config.max_hpages = -1; /* No limit on size by default */
L
Linus Torvalds 已提交
1232
	config.nr_inodes = -1; /* No limit on number of inodes by default */
1233 1234
	config.uid = current_fsuid();
	config.gid = current_fsgid();
L
Linus Torvalds 已提交
1235
	config.mode = 0755;
1236
	config.hstate = &default_hstate;
1237
	config.min_hpages = -1; /* No default minimum size */
L
Linus Torvalds 已提交
1238 1239 1240 1241 1242 1243 1244 1245
	ret = hugetlbfs_parse_options(data, &config);
	if (ret)
		return ret;

	sbinfo = kmalloc(sizeof(struct hugetlbfs_sb_info), GFP_KERNEL);
	if (!sbinfo)
		return -ENOMEM;
	sb->s_fs_info = sbinfo;
1246
	sbinfo->hstate = config.hstate;
L
Linus Torvalds 已提交
1247 1248 1249
	spin_lock_init(&sbinfo->stat_lock);
	sbinfo->max_inodes = config.nr_inodes;
	sbinfo->free_inodes = config.nr_inodes;
1250
	sbinfo->spool = NULL;
1251 1252 1253 1254
	sbinfo->uid = config.uid;
	sbinfo->gid = config.gid;
	sbinfo->mode = config.mode;

1255 1256 1257 1258 1259 1260 1261 1262 1263
	/*
	 * Allocate and initialize subpool if maximum or minimum size is
	 * specified.  Any needed reservations (for minimim size) are taken
	 * taken when the subpool is created.
	 */
	if (config.max_hpages != -1 || config.min_hpages != -1) {
		sbinfo->spool = hugepage_new_subpool(config.hstate,
							config.max_hpages,
							config.min_hpages);
1264 1265 1266
		if (!sbinfo->spool)
			goto out_free;
	}
L
Linus Torvalds 已提交
1267
	sb->s_maxbytes = MAX_LFS_FILESIZE;
1268 1269
	sb->s_blocksize = huge_page_size(config.hstate);
	sb->s_blocksize_bits = huge_page_shift(config.hstate);
L
Linus Torvalds 已提交
1270 1271 1272
	sb->s_magic = HUGETLBFS_MAGIC;
	sb->s_op = &hugetlbfs_ops;
	sb->s_time_gran = 1;
1273 1274
	sb->s_root = d_make_root(hugetlbfs_get_root(sb, &config));
	if (!sb->s_root)
L
Linus Torvalds 已提交
1275 1276 1277
		goto out_free;
	return 0;
out_free:
1278
	kfree(sbinfo->spool);
L
Linus Torvalds 已提交
1279 1280 1281 1282
	kfree(sbinfo);
	return -ENOMEM;
}

A
Al Viro 已提交
1283 1284
static struct dentry *hugetlbfs_mount(struct file_system_type *fs_type,
	int flags, const char *dev_name, void *data)
L
Linus Torvalds 已提交
1285
{
A
Al Viro 已提交
1286
	return mount_nodev(fs_type, flags, data, hugetlbfs_fill_super);
L
Linus Torvalds 已提交
1287 1288 1289 1290
}

static struct file_system_type hugetlbfs_fs_type = {
	.name		= "hugetlbfs",
A
Al Viro 已提交
1291
	.mount		= hugetlbfs_mount,
L
Linus Torvalds 已提交
1292 1293 1294
	.kill_sb	= kill_litter_super,
};

1295
static struct vfsmount *hugetlbfs_vfsmount[HUGE_MAX_HSTATE];
L
Linus Torvalds 已提交
1296

1297
static int can_do_hugetlb_shm(void)
L
Linus Torvalds 已提交
1298
{
1299 1300 1301
	kgid_t shm_group;
	shm_group = make_kgid(&init_user_ns, sysctl_hugetlb_shm_group);
	return capable(CAP_IPC_LOCK) || in_group_p(shm_group);
L
Linus Torvalds 已提交
1302 1303
}

1304 1305
static int get_hstate_idx(int page_size_log)
{
1306
	struct hstate *h = hstate_sizelog(page_size_log);
1307 1308 1309 1310 1311 1312

	if (!h)
		return -1;
	return h - hstates;
}

1313
static const struct dentry_operations anon_ops = {
1314
	.d_dname = simple_dname
1315 1316
};

1317 1318 1319 1320 1321 1322
/*
 * Note that size should be aligned to proper hugepage size in caller side,
 * otherwise hugetlb_reserve_pages reserves one less hugepages than intended.
 */
struct file *hugetlb_file_setup(const char *name, size_t size,
				vm_flags_t acctflag, struct user_struct **user,
1323
				int creat_flags, int page_size_log)
L
Linus Torvalds 已提交
1324
{
1325
	struct file *file = ERR_PTR(-ENOMEM);
L
Linus Torvalds 已提交
1326
	struct inode *inode;
1327
	struct path path;
1328
	struct super_block *sb;
L
Linus Torvalds 已提交
1329
	struct qstr quick_string;
1330 1331 1332 1333 1334
	int hstate_idx;

	hstate_idx = get_hstate_idx(page_size_log);
	if (hstate_idx < 0)
		return ERR_PTR(-ENODEV);
L
Linus Torvalds 已提交
1335

1336
	*user = NULL;
1337
	if (!hugetlbfs_vfsmount[hstate_idx])
1338 1339
		return ERR_PTR(-ENOENT);

1340
	if (creat_flags == HUGETLB_SHMFS_INODE && !can_do_hugetlb_shm()) {
1341 1342
		*user = current_user();
		if (user_shm_lock(size, *user)) {
1343
			task_lock(current);
1344
			pr_warn_once("%s (%d): Using mlock ulimits for SHM_HUGETLB is deprecated\n",
1345 1346
				current->comm, current->pid);
			task_unlock(current);
1347 1348
		} else {
			*user = NULL;
1349
			return ERR_PTR(-EPERM);
1350
		}
1351
	}
L
Linus Torvalds 已提交
1352

1353
	sb = hugetlbfs_vfsmount[hstate_idx]->mnt_sb;
1354
	quick_string.name = name;
L
Linus Torvalds 已提交
1355 1356
	quick_string.len = strlen(quick_string.name);
	quick_string.hash = 0;
1357
	path.dentry = d_alloc_pseudo(sb, &quick_string);
1358
	if (!path.dentry)
L
Linus Torvalds 已提交
1359 1360
		goto out_shm_unlock;

1361
	d_set_d_op(path.dentry, &anon_ops);
1362
	path.mnt = mntget(hugetlbfs_vfsmount[hstate_idx]);
1363
	file = ERR_PTR(-ENOSPC);
1364
	inode = hugetlbfs_get_inode(sb, NULL, S_IFREG | S_IRWXUGO, 0);
L
Linus Torvalds 已提交
1365
	if (!inode)
1366
		goto out_dentry;
1367 1368
	if (creat_flags == HUGETLB_SHMFS_INODE)
		inode->i_flags |= S_PRIVATE;
L
Linus Torvalds 已提交
1369

1370
	file = ERR_PTR(-ENOMEM);
1371 1372 1373
	if (hugetlb_reserve_pages(inode, 0,
			size >> huge_page_shift(hstate_inode(inode)), NULL,
			acctflag))
1374 1375
		goto out_inode;

1376
	d_instantiate(path.dentry, inode);
L
Linus Torvalds 已提交
1377
	inode->i_size = size;
1378
	clear_nlink(inode);
1379

1380
	file = alloc_file(&path, FMODE_WRITE | FMODE_READ,
1381
			&hugetlbfs_file_operations);
1382
	if (IS_ERR(file))
1383
		goto out_dentry; /* inode is already attached */
1384

L
Linus Torvalds 已提交
1385 1386
	return file;

1387 1388
out_inode:
	iput(inode);
L
Linus Torvalds 已提交
1389
out_dentry:
1390
	path_put(&path);
L
Linus Torvalds 已提交
1391
out_shm_unlock:
1392 1393 1394 1395
	if (*user) {
		user_shm_unlock(size, *user);
		*user = NULL;
	}
1396
	return file;
L
Linus Torvalds 已提交
1397 1398 1399 1400
}

static int __init init_hugetlbfs_fs(void)
{
1401
	struct hstate *h;
L
Linus Torvalds 已提交
1402
	int error;
1403
	int i;
L
Linus Torvalds 已提交
1404

1405
	if (!hugepages_supported()) {
1406
		pr_info("disabling because there are no supported hugepage sizes\n");
1407 1408 1409
		return -ENOTSUPP;
	}

1410
	error = -ENOMEM;
L
Linus Torvalds 已提交
1411 1412
	hugetlbfs_inode_cachep = kmem_cache_create("hugetlbfs_inode_cache",
					sizeof(struct hugetlbfs_inode_info),
1413
					0, SLAB_ACCOUNT, init_once);
L
Linus Torvalds 已提交
1414
	if (hugetlbfs_inode_cachep == NULL)
P
Peter Zijlstra 已提交
1415
		goto out2;
L
Linus Torvalds 已提交
1416 1417 1418 1419 1420

	error = register_filesystem(&hugetlbfs_fs_type);
	if (error)
		goto out;

1421 1422 1423 1424
	i = 0;
	for_each_hstate(h) {
		char buf[50];
		unsigned ps_kb = 1U << (h->order + PAGE_SHIFT - 10);
L
Linus Torvalds 已提交
1425

1426 1427 1428
		snprintf(buf, sizeof(buf), "pagesize=%uK", ps_kb);
		hugetlbfs_vfsmount[i] = kern_mount_data(&hugetlbfs_fs_type,
							buf);
L
Linus Torvalds 已提交
1429

1430
		if (IS_ERR(hugetlbfs_vfsmount[i])) {
1431
			pr_err("Cannot mount internal hugetlbfs for "
1432 1433 1434 1435 1436 1437 1438 1439 1440
				"page size %uK", ps_kb);
			error = PTR_ERR(hugetlbfs_vfsmount[i]);
			hugetlbfs_vfsmount[i] = NULL;
		}
		i++;
	}
	/* Non default hstates are optional */
	if (!IS_ERR_OR_NULL(hugetlbfs_vfsmount[default_hstate_idx]))
		return 0;
L
Linus Torvalds 已提交
1441 1442

 out:
1443
	kmem_cache_destroy(hugetlbfs_inode_cachep);
P
Peter Zijlstra 已提交
1444
 out2:
L
Linus Torvalds 已提交
1445 1446
	return error;
}
1447
fs_initcall(init_hugetlbfs_fs)