mmu.c 41.8 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0-only
C
Catalin Marinas 已提交
2 3 4 5 6 7 8
/*
 * Based on arch/arm/mm/mmu.c
 *
 * Copyright (C) 1995-2005 Russell King
 * Copyright (C) 2012 ARM Ltd.
 */

9
#include <linux/cache.h>
C
Catalin Marinas 已提交
10 11 12 13
#include <linux/export.h>
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/init.h>
14 15
#include <linux/ioport.h>
#include <linux/kexec.h>
16
#include <linux/libfdt.h>
C
Catalin Marinas 已提交
17 18 19
#include <linux/mman.h>
#include <linux/nodemask.h>
#include <linux/memblock.h>
20
#include <linux/memory.h>
C
Catalin Marinas 已提交
21
#include <linux/fs.h>
22
#include <linux/io.h>
23
#include <linux/mm.h>
24
#include <linux/vmalloc.h>
C
Catalin Marinas 已提交
25

26
#include <asm/barrier.h>
C
Catalin Marinas 已提交
27
#include <asm/cputype.h>
28
#include <asm/fixmap.h>
29
#include <asm/kasan.h>
30
#include <asm/kernel-pgtable.h>
C
Catalin Marinas 已提交
31 32
#include <asm/sections.h>
#include <asm/setup.h>
33
#include <linux/sizes.h>
C
Catalin Marinas 已提交
34 35
#include <asm/tlb.h>
#include <asm/mmu_context.h>
36
#include <asm/ptdump.h>
37
#include <asm/tlbflush.h>
38
#include <asm/pgalloc.h>
C
Catalin Marinas 已提交
39

40
#define NO_BLOCK_MAPPINGS	BIT(0)
41
#define NO_CONT_MAPPINGS	BIT(1)
42

43
u64 idmap_t0sz = TCR_T0SZ(VA_BITS);
44
u64 idmap_ptrs_per_pgd = PTRS_PER_PGD;
45

46 47
u64 __section(".mmuoff.data.write") vabits_actual;
EXPORT_SYMBOL(vabits_actual);
48

49
u64 kimage_voffset __ro_after_init;
50 51
EXPORT_SYMBOL(kimage_voffset);

C
Catalin Marinas 已提交
52 53 54 55
/*
 * Empty_zero_page is a special page that is used for zero-initialized data
 * and COW.
 */
56
unsigned long empty_zero_page[PAGE_SIZE / sizeof(unsigned long)] __page_aligned_bss;
C
Catalin Marinas 已提交
57 58
EXPORT_SYMBOL(empty_zero_page);

59 60 61 62
static pte_t bm_pte[PTRS_PER_PTE] __page_aligned_bss;
static pmd_t bm_pmd[PTRS_PER_PMD] __page_aligned_bss __maybe_unused;
static pud_t bm_pud[PTRS_PER_PUD] __page_aligned_bss __maybe_unused;

63 64 65 66 67 68 69
static DEFINE_SPINLOCK(swapper_pgdir_lock);

void set_swapper_pgd(pgd_t *pgdp, pgd_t pgd)
{
	pgd_t *fixmap_pgdp;

	spin_lock(&swapper_pgdir_lock);
70
	fixmap_pgdp = pgd_set_fixmap(__pa_symbol(pgdp));
71 72 73 74 75 76 77 78 79 80
	WRITE_ONCE(*fixmap_pgdp, pgd);
	/*
	 * We need dsb(ishst) here to ensure the page-table-walker sees
	 * our new entry before set_p?d() returns. The fixmap's
	 * flush_tlb_kernel_range() via clear_fixmap() does this for us.
	 */
	pgd_clear_fixmap();
	spin_unlock(&swapper_pgdir_lock);
}

C
Catalin Marinas 已提交
81 82 83 84 85 86 87 88 89 90 91
pgprot_t phys_mem_access_prot(struct file *file, unsigned long pfn,
			      unsigned long size, pgprot_t vma_prot)
{
	if (!pfn_valid(pfn))
		return pgprot_noncached(vma_prot);
	else if (file->f_flags & O_SYNC)
		return pgprot_writecombine(vma_prot);
	return vma_prot;
}
EXPORT_SYMBOL(phys_mem_access_prot);

92
static phys_addr_t __init early_pgtable_alloc(int shift)
C
Catalin Marinas 已提交
93
{
94 95 96
	phys_addr_t phys;
	void *ptr;

97
	phys = memblock_phys_alloc(PAGE_SIZE, PAGE_SIZE);
98 99
	if (!phys)
		panic("Failed to allocate page table page\n");
100 101 102 103 104 105 106 107

	/*
	 * The FIX_{PGD,PUD,PMD} slots may be in active use, but the FIX_PTE
	 * slot will be free, so we can (ab)use the FIX_PTE slot to initialise
	 * any level of table.
	 */
	ptr = pte_set_fixmap(phys);

108 109
	memset(ptr, 0, PAGE_SIZE);

110 111 112 113 114 115 116
	/*
	 * Implicit barriers also ensure the zeroed page is visible to the page
	 * table walker
	 */
	pte_clear_fixmap();

	return phys;
C
Catalin Marinas 已提交
117 118
}

119 120 121 122 123 124
static bool pgattr_change_is_safe(u64 old, u64 new)
{
	/*
	 * The following mapping attributes may be updated in live
	 * kernel mappings without the need for break-before-make.
	 */
125
	pteval_t mask = PTE_PXN | PTE_RDONLY | PTE_WRITE | PTE_NG;
126

127 128 129 130 131 132 133 134
	/* creating or taking down mappings is always safe */
	if (old == 0 || new == 0)
		return true;

	/* live contiguous mappings may not be manipulated at all */
	if ((old | new) & PTE_CONT)
		return false;

135 136 137
	/* Transitioning from Non-Global to Global is unsafe */
	if (old & ~new & PTE_NG)
		return false;
138

139 140 141 142 143 144 145 146 147 148 149
	/*
	 * Changing the memory type between Normal and Normal-Tagged is safe
	 * since Tagged is considered a permission attribute from the
	 * mismatched attribute aliases perspective.
	 */
	if (((old & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL) ||
	     (old & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL_TAGGED)) &&
	    ((new & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL) ||
	     (new & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL_TAGGED)))
		mask |= PTE_ATTRINDX_MASK;

150
	return ((old ^ new) & ~mask) == 0;
151 152
}

153
static void init_pte(pmd_t *pmdp, unsigned long addr, unsigned long end,
154
		     phys_addr_t phys, pgprot_t prot)
C
Catalin Marinas 已提交
155
{
156
	pte_t *ptep;
C
Catalin Marinas 已提交
157

158
	ptep = pte_set_fixmap_offset(pmdp, addr);
C
Catalin Marinas 已提交
159
	do {
160
		pte_t old_pte = READ_ONCE(*ptep);
161

162
		set_pte(ptep, pfn_pte(__phys_to_pfn(phys), prot));
163 164 165 166 167

		/*
		 * After the PTE entry has been populated once, we
		 * only allow updates to the permission attributes.
		 */
168 169
		BUG_ON(!pgattr_change_is_safe(pte_val(old_pte),
					      READ_ONCE(pte_val(*ptep))));
170

171
		phys += PAGE_SIZE;
172
	} while (ptep++, addr += PAGE_SIZE, addr != end);
173 174

	pte_clear_fixmap();
C
Catalin Marinas 已提交
175 176
}

177
static void alloc_init_cont_pte(pmd_t *pmdp, unsigned long addr,
178 179
				unsigned long end, phys_addr_t phys,
				pgprot_t prot,
180
				phys_addr_t (*pgtable_alloc)(int),
181
				int flags)
C
Catalin Marinas 已提交
182 183
{
	unsigned long next;
184
	pmd_t pmd = READ_ONCE(*pmdp);
C
Catalin Marinas 已提交
185

186 187
	BUG_ON(pmd_sect(pmd));
	if (pmd_none(pmd)) {
188
		phys_addr_t pte_phys;
189
		BUG_ON(!pgtable_alloc);
190
		pte_phys = pgtable_alloc(PAGE_SHIFT);
191 192
		__pmd_populate(pmdp, pte_phys, PMD_TYPE_TABLE);
		pmd = READ_ONCE(*pmdp);
C
Catalin Marinas 已提交
193
	}
194
	BUG_ON(pmd_bad(pmd));
195 196 197 198 199 200 201 202 203 204 205

	do {
		pgprot_t __prot = prot;

		next = pte_cont_addr_end(addr, end);

		/* use a contiguous mapping if the range is suitably aligned */
		if ((((addr | next | phys) & ~CONT_PTE_MASK) == 0) &&
		    (flags & NO_CONT_MAPPINGS) == 0)
			__prot = __pgprot(pgprot_val(prot) | PTE_CONT);

206
		init_pte(pmdp, addr, next, phys, __prot);
207 208 209 210 211

		phys += next - addr;
	} while (addr = next, addr != end);
}

212
static void init_pmd(pud_t *pudp, unsigned long addr, unsigned long end,
213
		     phys_addr_t phys, pgprot_t prot,
214
		     phys_addr_t (*pgtable_alloc)(int), int flags)
215 216
{
	unsigned long next;
217
	pmd_t *pmdp;
C
Catalin Marinas 已提交
218

219
	pmdp = pmd_set_fixmap_offset(pudp, addr);
C
Catalin Marinas 已提交
220
	do {
221
		pmd_t old_pmd = READ_ONCE(*pmdp);
222

C
Catalin Marinas 已提交
223
		next = pmd_addr_end(addr, end);
224

C
Catalin Marinas 已提交
225
		/* try section mapping first */
226
		if (((addr | next | phys) & ~SECTION_MASK) == 0 &&
227
		    (flags & NO_BLOCK_MAPPINGS) == 0) {
228
			pmd_set_huge(pmdp, phys, prot);
229

230
			/*
231 232
			 * After the PMD entry has been populated once, we
			 * only allow updates to the permission attributes.
233
			 */
234
			BUG_ON(!pgattr_change_is_safe(pmd_val(old_pmd),
235
						      READ_ONCE(pmd_val(*pmdp))));
236
		} else {
237
			alloc_init_cont_pte(pmdp, addr, next, phys, prot,
238
					    pgtable_alloc, flags);
239 240

			BUG_ON(pmd_val(old_pmd) != 0 &&
241
			       pmd_val(old_pmd) != READ_ONCE(pmd_val(*pmdp)));
242
		}
C
Catalin Marinas 已提交
243
		phys += next - addr;
244
	} while (pmdp++, addr = next, addr != end);
245 246

	pmd_clear_fixmap();
C
Catalin Marinas 已提交
247 248
}

249
static void alloc_init_cont_pmd(pud_t *pudp, unsigned long addr,
250 251
				unsigned long end, phys_addr_t phys,
				pgprot_t prot,
252
				phys_addr_t (*pgtable_alloc)(int), int flags)
253 254
{
	unsigned long next;
255
	pud_t pud = READ_ONCE(*pudp);
256 257 258 259

	/*
	 * Check for initial section mappings in the pgd/pud.
	 */
260 261
	BUG_ON(pud_sect(pud));
	if (pud_none(pud)) {
262 263
		phys_addr_t pmd_phys;
		BUG_ON(!pgtable_alloc);
264
		pmd_phys = pgtable_alloc(PMD_SHIFT);
265 266
		__pud_populate(pudp, pmd_phys, PUD_TYPE_TABLE);
		pud = READ_ONCE(*pudp);
267
	}
268
	BUG_ON(pud_bad(pud));
269 270 271 272 273 274 275 276 277 278 279

	do {
		pgprot_t __prot = prot;

		next = pmd_cont_addr_end(addr, end);

		/* use a contiguous mapping if the range is suitably aligned */
		if ((((addr | next | phys) & ~CONT_PMD_MASK) == 0) &&
		    (flags & NO_CONT_MAPPINGS) == 0)
			__prot = __pgprot(pgprot_val(prot) | PTE_CONT);

280
		init_pmd(pudp, addr, next, phys, __prot, pgtable_alloc, flags);
281 282 283 284 285

		phys += next - addr;
	} while (addr = next, addr != end);
}

286 287 288 289 290 291 292 293 294 295 296 297
static inline bool use_1G_block(unsigned long addr, unsigned long next,
			unsigned long phys)
{
	if (PAGE_SHIFT != 12)
		return false;

	if (((addr | next | phys) & ~PUD_MASK) != 0)
		return false;

	return true;
}

298 299
static void alloc_init_pud(pgd_t *pgdp, unsigned long addr, unsigned long end,
			   phys_addr_t phys, pgprot_t prot,
300
			   phys_addr_t (*pgtable_alloc)(int),
301
			   int flags)
C
Catalin Marinas 已提交
302 303
{
	unsigned long next;
304
	pud_t *pudp;
305 306
	p4d_t *p4dp = p4d_offset(pgdp, addr);
	p4d_t p4d = READ_ONCE(*p4dp);
C
Catalin Marinas 已提交
307

308
	if (p4d_none(p4d)) {
309 310
		phys_addr_t pud_phys;
		BUG_ON(!pgtable_alloc);
311
		pud_phys = pgtable_alloc(PUD_SHIFT);
312 313
		__p4d_populate(p4dp, pud_phys, PUD_TYPE_TABLE);
		p4d = READ_ONCE(*p4dp);
314
	}
315
	BUG_ON(p4d_bad(p4d));
316

317
	pudp = pud_set_fixmap_offset(p4dp, addr);
C
Catalin Marinas 已提交
318
	do {
319
		pud_t old_pud = READ_ONCE(*pudp);
320

C
Catalin Marinas 已提交
321
		next = pud_addr_end(addr, end);
322 323 324 325

		/*
		 * For 4K granule only, attempt to put down a 1GB block
		 */
326 327
		if (use_1G_block(addr, next, phys) &&
		    (flags & NO_BLOCK_MAPPINGS) == 0) {
328
			pud_set_huge(pudp, phys, prot);
329 330

			/*
331 332
			 * After the PUD entry has been populated once, we
			 * only allow updates to the permission attributes.
333
			 */
334
			BUG_ON(!pgattr_change_is_safe(pud_val(old_pud),
335
						      READ_ONCE(pud_val(*pudp))));
336
		} else {
337
			alloc_init_cont_pmd(pudp, addr, next, phys, prot,
338
					    pgtable_alloc, flags);
339 340

			BUG_ON(pud_val(old_pud) != 0 &&
341
			       pud_val(old_pud) != READ_ONCE(pud_val(*pudp)));
342
		}
C
Catalin Marinas 已提交
343
		phys += next - addr;
344
	} while (pudp++, addr = next, addr != end);
345 346

	pud_clear_fixmap();
C
Catalin Marinas 已提交
347 348
}

349 350 351
static void __create_pgd_mapping(pgd_t *pgdir, phys_addr_t phys,
				 unsigned long virt, phys_addr_t size,
				 pgprot_t prot,
352
				 phys_addr_t (*pgtable_alloc)(int),
353
				 int flags)
C
Catalin Marinas 已提交
354
{
355
	unsigned long addr, end, next;
356
	pgd_t *pgdp = pgd_offset_pgd(pgdir, virt);
C
Catalin Marinas 已提交
357

358 359 360 361 362 363 364
	/*
	 * If the virtual and physical address don't have the same offset
	 * within a page, we cannot map the region as the caller expects.
	 */
	if (WARN_ON((phys ^ virt) & ~PAGE_MASK))
		return;

365
	phys &= PAGE_MASK;
C
Catalin Marinas 已提交
366
	addr = virt & PAGE_MASK;
367
	end = PAGE_ALIGN(virt + size);
C
Catalin Marinas 已提交
368 369 370

	do {
		next = pgd_addr_end(addr, end);
371
		alloc_init_pud(pgdp, addr, next, phys, prot, pgtable_alloc,
372
			       flags);
C
Catalin Marinas 已提交
373
		phys += next - addr;
374
	} while (pgdp++, addr = next, addr != end);
C
Catalin Marinas 已提交
375 376
}

377
static phys_addr_t __pgd_pgtable_alloc(int shift)
378
{
379
	void *ptr = (void *)__get_free_page(GFP_PGTABLE_KERNEL);
380 381 382 383 384 385 386
	BUG_ON(!ptr);

	/* Ensure the zeroed page is visible to the page table walker */
	dsb(ishst);
	return __pa(ptr);
}

387
static phys_addr_t pgd_pgtable_alloc(int shift)
388
{
389
	phys_addr_t pa = __pgd_pgtable_alloc(shift);
390 391 392 393 394 395 396 397 398 399

	/*
	 * Call proper page table ctor in case later we need to
	 * call core mm functions like apply_to_page_range() on
	 * this pre-allocated page table.
	 *
	 * We don't select ARCH_ENABLE_SPLIT_PMD_PTLOCK if pmd is
	 * folded, and if so pgtable_pmd_page_ctor() becomes nop.
	 */
	if (shift == PAGE_SHIFT)
400
		BUG_ON(!pgtable_pte_page_ctor(phys_to_page(pa)));
401
	else if (shift == PMD_SHIFT)
402
		BUG_ON(!pgtable_pmd_page_ctor(phys_to_page(pa)));
403

404
	return pa;
405 406
}

407 408 409 410 411 412
/*
 * This function can only be used to modify existing table entries,
 * without allocating new levels of table. Note that this permits the
 * creation of new section or page entries.
 */
static void __init create_mapping_noalloc(phys_addr_t phys, unsigned long virt,
413
				  phys_addr_t size, pgprot_t prot)
414
{
415
	if ((virt >= PAGE_END) && (virt < VMALLOC_START)) {
416 417 418 419
		pr_warn("BUG: not creating mapping for %pa at 0x%016lx - outside kernel range\n",
			&phys, virt);
		return;
	}
420 421
	__create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL,
			     NO_CONT_MAPPINGS);
422 423
}

424 425
void __init create_pgd_mapping(struct mm_struct *mm, phys_addr_t phys,
			       unsigned long virt, phys_addr_t size,
426
			       pgprot_t prot, bool page_mappings_only)
427
{
428 429
	int flags = 0;

430 431
	BUG_ON(mm == &init_mm);

432
	if (page_mappings_only)
433
		flags = NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;
434

435
	__create_pgd_mapping(mm->pgd, phys, virt, size, prot,
436
			     pgd_pgtable_alloc, flags);
437 438
}

439 440
static void update_mapping_prot(phys_addr_t phys, unsigned long virt,
				phys_addr_t size, pgprot_t prot)
441
{
442
	if ((virt >= PAGE_END) && (virt < VMALLOC_START)) {
443
		pr_warn("BUG: not updating mapping for %pa at 0x%016lx - outside kernel range\n",
444 445 446 447
			&phys, virt);
		return;
	}

448 449
	__create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL,
			     NO_CONT_MAPPINGS);
450 451 452

	/* flush the TLBs after updating live kernel mappings */
	flush_tlb_kernel_range(virt, virt + size);
453 454
}

455
static void __init __map_memblock(pgd_t *pgdp, phys_addr_t start,
456 457
				  phys_addr_t end, pgprot_t prot, int flags)
{
458
	__create_pgd_mapping(pgdp, start, __phys_to_virt(start), end - start,
459 460 461 462 463 464 465 466
			     prot, early_pgtable_alloc, flags);
}

void __init mark_linear_text_alias_ro(void)
{
	/*
	 * Remove the write permissions from the linear alias of .text/.rodata
	 */
467 468
	update_mapping_prot(__pa_symbol(_stext), (unsigned long)lm_alias(_stext),
			    (unsigned long)__init_begin - (unsigned long)_stext,
469 470 471
			    PAGE_KERNEL_RO);
}

472 473 474 475 476 477 478 479 480 481 482 483 484 485 486
static bool crash_mem_map __initdata;

static int __init enable_crash_mem_map(char *arg)
{
	/*
	 * Proper parameter parsing is done by reserve_crashkernel(). We only
	 * need to know if the linear map has to avoid block mappings so that
	 * the crashkernel reservations can be unmapped later.
	 */
	crash_mem_map = true;

	return 0;
}
early_param("crashkernel", enable_crash_mem_map);

487
static void __init map_mem(pgd_t *pgdp)
488
{
489
	phys_addr_t kernel_start = __pa_symbol(_stext);
490
	phys_addr_t kernel_end = __pa_symbol(__init_begin);
491
	phys_addr_t start, end;
492
	int flags = 0;
493
	u64 i;
494

495
	if (rodata_full || crash_mem_map || debug_pagealloc_enabled())
496
		flags = NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;
497

498
	/*
499 500
	 * Take care not to create a writable alias for the
	 * read-only text and rodata sections of the kernel image.
501 502
	 * So temporarily mark them as NOMAP to skip mappings in
	 * the following for-loop
503
	 */
504
	memblock_mark_nomap(kernel_start, kernel_end - kernel_start);
505

506
	/* map all the memory banks */
507
	for_each_mem_range(i, &start, &end) {
508 509
		if (start >= end)
			break;
510 511 512 513 514 515
		/*
		 * The linear map must allow allocation tags reading/writing
		 * if MTE is present. Otherwise, it has the same attributes as
		 * PAGE_KERNEL.
		 */
		__map_memblock(pgdp, start, end, PAGE_KERNEL_TAGGED, flags);
516
	}
517 518

	/*
519
	 * Map the linear alias of the [_stext, __init_begin) interval
520 521 522 523 524
	 * as non-executable now, and remove the write permission in
	 * mark_linear_text_alias_ro() below (which will be called after
	 * alternative patching has completed). This makes the contents
	 * of the region accessible to subsystems such as hibernate,
	 * but protects it from inadvertent modification or execution.
525 526
	 * Note that contiguous mappings cannot be remapped in this way,
	 * so we should avoid them here.
527
	 */
528
	__map_memblock(pgdp, kernel_start, kernel_end,
529 530
		       PAGE_KERNEL, NO_CONT_MAPPINGS);
	memblock_clear_nomap(kernel_start, kernel_end - kernel_start);
C
Catalin Marinas 已提交
531 532
}

533 534
void mark_rodata_ro(void)
{
J
Jeremy Linton 已提交
535
	unsigned long section_size;
536

J
Jeremy Linton 已提交
537
	/*
538 539
	 * mark .rodata as read only. Use __init_begin rather than __end_rodata
	 * to cover NOTES and EXCEPTION_TABLE.
J
Jeremy Linton 已提交
540
	 */
541
	section_size = (unsigned long)__init_begin - (unsigned long)__start_rodata;
542
	update_mapping_prot(__pa_symbol(__start_rodata), (unsigned long)__start_rodata,
J
Jeremy Linton 已提交
543
			    section_size, PAGE_KERNEL_RO);
544

545
	debug_checkwx();
546 547
}

548
static void __init map_kernel_segment(pgd_t *pgdp, void *va_start, void *va_end,
549
				      pgprot_t prot, struct vm_struct *vma,
550
				      int flags, unsigned long vm_flags)
551
{
552
	phys_addr_t pa_start = __pa_symbol(va_start);
553 554 555 556 557
	unsigned long size = va_end - va_start;

	BUG_ON(!PAGE_ALIGNED(pa_start));
	BUG_ON(!PAGE_ALIGNED(size));

558
	__create_pgd_mapping(pgdp, pa_start, (unsigned long)va_start, size, prot,
559
			     early_pgtable_alloc, flags);
560

561 562 563
	if (!(vm_flags & VM_NO_GUARD))
		size += PAGE_SIZE;

564 565 566
	vma->addr	= va_start;
	vma->phys_addr	= pa_start;
	vma->size	= size;
567
	vma->flags	= VM_MAP | vm_flags;
568 569 570
	vma->caller	= __builtin_return_address(0);

	vm_area_add_early(vma);
571 572
}

573 574
static int __init parse_rodata(char *arg)
{
575 576 577 578 579 580 581 582 583 584 585 586 587
	int ret = strtobool(arg, &rodata_enabled);
	if (!ret) {
		rodata_full = false;
		return 0;
	}

	/* permit 'full' in addition to boolean options */
	if (strcmp(arg, "full"))
		return -EINVAL;

	rodata_enabled = true;
	rodata_full = true;
	return 0;
588 589 590
}
early_param("rodata", parse_rodata);

591 592 593 594 595 596 597 598 599 600 601 602
#ifdef CONFIG_UNMAP_KERNEL_AT_EL0
static int __init map_entry_trampoline(void)
{
	pgprot_t prot = rodata_enabled ? PAGE_KERNEL_ROX : PAGE_KERNEL_EXEC;
	phys_addr_t pa_start = __pa_symbol(__entry_tramp_text_start);

	/* The trampoline is always mapped and can therefore be global */
	pgprot_val(prot) &= ~PTE_NG;

	/* Map only the text into the trampoline page table */
	memset(tramp_pg_dir, 0, PGD_SIZE);
	__create_pgd_mapping(tramp_pg_dir, pa_start, TRAMP_VALIAS, PAGE_SIZE,
603
			     prot, __pgd_pgtable_alloc, 0);
604

605
	/* Map both the text and data into the kernel page table */
606
	__set_fixmap(FIX_ENTRY_TRAMP_TEXT, pa_start, prot);
607 608 609 610 611 612 613 614
	if (IS_ENABLED(CONFIG_RANDOMIZE_BASE)) {
		extern char __entry_tramp_data_start[];

		__set_fixmap(FIX_ENTRY_TRAMP_DATA,
			     __pa_symbol(__entry_tramp_data_start),
			     PAGE_KERNEL_RO);
	}

615 616 617 618 619
	return 0;
}
core_initcall(map_entry_trampoline);
#endif

620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635
/*
 * Open coded check for BTI, only for use to determine configuration
 * for early mappings for before the cpufeature code has run.
 */
static bool arm64_early_this_cpu_has_bti(void)
{
	u64 pfr1;

	if (!IS_ENABLED(CONFIG_ARM64_BTI_KERNEL))
		return false;

	pfr1 = read_sysreg_s(SYS_ID_AA64PFR1_EL1);
	return cpuid_feature_extract_unsigned_field(pfr1,
						    ID_AA64PFR1_BT_SHIFT);
}

636 637 638
/*
 * Create fine-grained mappings for the kernel.
 */
639
static void __init map_kernel(pgd_t *pgdp)
640
{
641 642
	static struct vm_struct vmlinux_text, vmlinux_rodata, vmlinux_inittext,
				vmlinux_initdata, vmlinux_data;
643

644 645 646 647 648 649 650
	/*
	 * External debuggers may need to write directly to the text
	 * mapping to install SW breakpoints. Allow this (only) when
	 * explicitly requested with rodata=off.
	 */
	pgprot_t text_prot = rodata_enabled ? PAGE_KERNEL_ROX : PAGE_KERNEL_EXEC;

651 652 653 654 655 656 657 658
	/*
	 * If we have a CPU that supports BTI and a kernel built for
	 * BTI then mark the kernel executable text as guarded pages
	 * now so we don't have to rewrite the page tables later.
	 */
	if (arm64_early_this_cpu_has_bti())
		text_prot = __pgprot_modify(text_prot, PTE_GP, PTE_GP);

659 660 661 662
	/*
	 * Only rodata will be remapped with different permissions later on,
	 * all other segments are allowed to use contiguous mappings.
	 */
663
	map_kernel_segment(pgdp, _stext, _etext, text_prot, &vmlinux_text, 0,
664
			   VM_NO_GUARD);
665
	map_kernel_segment(pgdp, __start_rodata, __inittext_begin, PAGE_KERNEL,
666
			   &vmlinux_rodata, NO_CONT_MAPPINGS, VM_NO_GUARD);
667
	map_kernel_segment(pgdp, __inittext_begin, __inittext_end, text_prot,
668
			   &vmlinux_inittext, 0, VM_NO_GUARD);
669
	map_kernel_segment(pgdp, __initdata_begin, __initdata_end, PAGE_KERNEL,
670
			   &vmlinux_initdata, 0, VM_NO_GUARD);
671
	map_kernel_segment(pgdp, _data, _end, PAGE_KERNEL, &vmlinux_data, 0, 0);
672

673
	if (!READ_ONCE(pgd_val(*pgd_offset_pgd(pgdp, FIXADDR_START)))) {
674 675 676 677 678
		/*
		 * The fixmap falls in a separate pgd to the kernel, and doesn't
		 * live in the carveout for the swapper_pg_dir. We can simply
		 * re-use the existing dir for the fixmap.
		 */
679
		set_pgd(pgd_offset_pgd(pgdp, FIXADDR_START),
680
			READ_ONCE(*pgd_offset_k(FIXADDR_START)));
681
	} else if (CONFIG_PGTABLE_LEVELS > 3) {
682
		pgd_t *bm_pgdp;
683
		p4d_t *bm_p4dp;
684
		pud_t *bm_pudp;
685 686 687 688 689 690 691
		/*
		 * The fixmap shares its top level pgd entry with the kernel
		 * mapping. This can really only occur when we are running
		 * with 16k/4 levels, so we can simply reuse the pud level
		 * entry instead.
		 */
		BUG_ON(!IS_ENABLED(CONFIG_ARM64_16K_PAGES));
692
		bm_pgdp = pgd_offset_pgd(pgdp, FIXADDR_START);
693 694
		bm_p4dp = p4d_offset(bm_pgdp, FIXADDR_START);
		bm_pudp = pud_set_fixmap_offset(bm_p4dp, FIXADDR_START);
695
		pud_populate(&init_mm, bm_pudp, lm_alias(bm_pmd));
696 697 698 699
		pud_clear_fixmap();
	} else {
		BUG();
	}
700

701
	kasan_copy_shadow(pgdp);
702 703
}

C
Catalin Marinas 已提交
704 705
void __init paging_init(void)
{
706
	pgd_t *pgdp = pgd_set_fixmap(__pa_symbol(swapper_pg_dir));
707

708 709
	map_kernel(pgdp);
	map_mem(pgdp);
710 711 712

	pgd_clear_fixmap();

713
	cpu_replace_ttbr1(lm_alias(swapper_pg_dir));
714
	init_mm.pgd = swapper_pg_dir;
715

716 717
	memblock_free(__pa_symbol(init_pg_dir),
		      __pa_symbol(init_pg_end) - __pa_symbol(init_pg_dir));
718 719

	memblock_allow_resize();
C
Catalin Marinas 已提交
720 721 722 723 724 725 726
}

/*
 * Check whether a kernel address is valid (derived from arch/x86/).
 */
int kern_addr_valid(unsigned long addr)
{
727
	pgd_t *pgdp;
728
	p4d_t *p4dp;
729 730 731
	pud_t *pudp, pud;
	pmd_t *pmdp, pmd;
	pte_t *ptep, pte;
C
Catalin Marinas 已提交
732

733
	addr = arch_kasan_reset_tag(addr);
C
Catalin Marinas 已提交
734 735 736
	if ((((long)addr) >> VA_BITS) != -1UL)
		return 0;

737 738
	pgdp = pgd_offset_k(addr);
	if (pgd_none(READ_ONCE(*pgdp)))
C
Catalin Marinas 已提交
739 740
		return 0;

741 742 743 744 745
	p4dp = p4d_offset(pgdp, addr);
	if (p4d_none(READ_ONCE(*p4dp)))
		return 0;

	pudp = pud_offset(p4dp, addr);
746 747
	pud = READ_ONCE(*pudp);
	if (pud_none(pud))
C
Catalin Marinas 已提交
748 749
		return 0;

750 751
	if (pud_sect(pud))
		return pfn_valid(pud_pfn(pud));
752

753 754 755
	pmdp = pmd_offset(pudp, addr);
	pmd = READ_ONCE(*pmdp);
	if (pmd_none(pmd))
C
Catalin Marinas 已提交
756 757
		return 0;

758 759
	if (pmd_sect(pmd))
		return pfn_valid(pmd_pfn(pmd));
760

761 762 763
	ptep = pte_offset_kernel(pmdp, addr);
	pte = READ_ONCE(*ptep);
	if (pte_none(pte))
C
Catalin Marinas 已提交
764 765
		return 0;

766
	return pfn_valid(pte_pfn(pte));
C
Catalin Marinas 已提交
767
}
768 769

#ifdef CONFIG_MEMORY_HOTPLUG
770 771
static void free_hotplug_page_range(struct page *page, size_t size,
				    struct vmem_altmap *altmap)
772
{
773 774 775 776 777 778
	if (altmap) {
		vmem_altmap_free(altmap, size >> PAGE_SHIFT);
	} else {
		WARN_ON(PageReserved(page));
		free_pages((unsigned long)page_address(page), get_order(size));
	}
779 780 781 782
}

static void free_hotplug_pgtable_page(struct page *page)
{
783
	free_hotplug_page_range(page, PAGE_SIZE, NULL);
784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805
}

static bool pgtable_range_aligned(unsigned long start, unsigned long end,
				  unsigned long floor, unsigned long ceiling,
				  unsigned long mask)
{
	start &= mask;
	if (start < floor)
		return false;

	if (ceiling) {
		ceiling &= mask;
		if (!ceiling)
			return false;
	}

	if (end - 1 > ceiling - 1)
		return false;
	return true;
}

static void unmap_hotplug_pte_range(pmd_t *pmdp, unsigned long addr,
806 807
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
808 809 810 811 812 813 814 815 816 817 818 819 820
{
	pte_t *ptep, pte;

	do {
		ptep = pte_offset_kernel(pmdp, addr);
		pte = READ_ONCE(*ptep);
		if (pte_none(pte))
			continue;

		WARN_ON(!pte_present(pte));
		pte_clear(&init_mm, addr, ptep);
		flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
		if (free_mapped)
821 822
			free_hotplug_page_range(pte_page(pte),
						PAGE_SIZE, altmap);
823 824 825 826
	} while (addr += PAGE_SIZE, addr < end);
}

static void unmap_hotplug_pmd_range(pud_t *pudp, unsigned long addr,
827 828
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850
{
	unsigned long next;
	pmd_t *pmdp, pmd;

	do {
		next = pmd_addr_end(addr, end);
		pmdp = pmd_offset(pudp, addr);
		pmd = READ_ONCE(*pmdp);
		if (pmd_none(pmd))
			continue;

		WARN_ON(!pmd_present(pmd));
		if (pmd_sect(pmd)) {
			pmd_clear(pmdp);

			/*
			 * One TLBI should be sufficient here as the PMD_SIZE
			 * range is mapped with a single block entry.
			 */
			flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
			if (free_mapped)
				free_hotplug_page_range(pmd_page(pmd),
851
							PMD_SIZE, altmap);
852 853 854
			continue;
		}
		WARN_ON(!pmd_table(pmd));
855
		unmap_hotplug_pte_range(pmdp, addr, next, free_mapped, altmap);
856 857 858 859
	} while (addr = next, addr < end);
}

static void unmap_hotplug_pud_range(p4d_t *p4dp, unsigned long addr,
860 861
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883
{
	unsigned long next;
	pud_t *pudp, pud;

	do {
		next = pud_addr_end(addr, end);
		pudp = pud_offset(p4dp, addr);
		pud = READ_ONCE(*pudp);
		if (pud_none(pud))
			continue;

		WARN_ON(!pud_present(pud));
		if (pud_sect(pud)) {
			pud_clear(pudp);

			/*
			 * One TLBI should be sufficient here as the PUD_SIZE
			 * range is mapped with a single block entry.
			 */
			flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
			if (free_mapped)
				free_hotplug_page_range(pud_page(pud),
884
							PUD_SIZE, altmap);
885 886 887
			continue;
		}
		WARN_ON(!pud_table(pud));
888
		unmap_hotplug_pmd_range(pudp, addr, next, free_mapped, altmap);
889 890 891 892
	} while (addr = next, addr < end);
}

static void unmap_hotplug_p4d_range(pgd_t *pgdp, unsigned long addr,
893 894
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
895 896 897 898 899 900 901 902 903 904 905 906
{
	unsigned long next;
	p4d_t *p4dp, p4d;

	do {
		next = p4d_addr_end(addr, end);
		p4dp = p4d_offset(pgdp, addr);
		p4d = READ_ONCE(*p4dp);
		if (p4d_none(p4d))
			continue;

		WARN_ON(!p4d_present(p4d));
907
		unmap_hotplug_pud_range(p4dp, addr, next, free_mapped, altmap);
908 909 910 911
	} while (addr = next, addr < end);
}

static void unmap_hotplug_range(unsigned long addr, unsigned long end,
912
				bool free_mapped, struct vmem_altmap *altmap)
913 914 915 916
{
	unsigned long next;
	pgd_t *pgdp, pgd;

917 918 919 920 921 922 923 924
	/*
	 * altmap can only be used as vmemmap mapping backing memory.
	 * In case the backing memory itself is not being freed, then
	 * altmap is irrelevant. Warn about this inconsistency when
	 * encountered.
	 */
	WARN_ON(!free_mapped && altmap);

925 926 927 928 929 930 931 932
	do {
		next = pgd_addr_end(addr, end);
		pgdp = pgd_offset_k(addr);
		pgd = READ_ONCE(*pgdp);
		if (pgd_none(pgd))
			continue;

		WARN_ON(!pgd_present(pgd));
933
		unmap_hotplug_p4d_range(pgdp, addr, next, free_mapped, altmap);
934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091
	} while (addr = next, addr < end);
}

static void free_empty_pte_table(pmd_t *pmdp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pte_t *ptep, pte;
	unsigned long i, start = addr;

	do {
		ptep = pte_offset_kernel(pmdp, addr);
		pte = READ_ONCE(*ptep);

		/*
		 * This is just a sanity check here which verifies that
		 * pte clearing has been done by earlier unmap loops.
		 */
		WARN_ON(!pte_none(pte));
	} while (addr += PAGE_SIZE, addr < end);

	if (!pgtable_range_aligned(start, end, floor, ceiling, PMD_MASK))
		return;

	/*
	 * Check whether we can free the pte page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	ptep = pte_offset_kernel(pmdp, 0UL);
	for (i = 0; i < PTRS_PER_PTE; i++) {
		if (!pte_none(READ_ONCE(ptep[i])))
			return;
	}

	pmd_clear(pmdp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(ptep));
}

static void free_empty_pmd_table(pud_t *pudp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pmd_t *pmdp, pmd;
	unsigned long i, next, start = addr;

	do {
		next = pmd_addr_end(addr, end);
		pmdp = pmd_offset(pudp, addr);
		pmd = READ_ONCE(*pmdp);
		if (pmd_none(pmd))
			continue;

		WARN_ON(!pmd_present(pmd) || !pmd_table(pmd) || pmd_sect(pmd));
		free_empty_pte_table(pmdp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);

	if (CONFIG_PGTABLE_LEVELS <= 2)
		return;

	if (!pgtable_range_aligned(start, end, floor, ceiling, PUD_MASK))
		return;

	/*
	 * Check whether we can free the pmd page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	pmdp = pmd_offset(pudp, 0UL);
	for (i = 0; i < PTRS_PER_PMD; i++) {
		if (!pmd_none(READ_ONCE(pmdp[i])))
			return;
	}

	pud_clear(pudp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(pmdp));
}

static void free_empty_pud_table(p4d_t *p4dp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pud_t *pudp, pud;
	unsigned long i, next, start = addr;

	do {
		next = pud_addr_end(addr, end);
		pudp = pud_offset(p4dp, addr);
		pud = READ_ONCE(*pudp);
		if (pud_none(pud))
			continue;

		WARN_ON(!pud_present(pud) || !pud_table(pud) || pud_sect(pud));
		free_empty_pmd_table(pudp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);

	if (CONFIG_PGTABLE_LEVELS <= 3)
		return;

	if (!pgtable_range_aligned(start, end, floor, ceiling, PGDIR_MASK))
		return;

	/*
	 * Check whether we can free the pud page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	pudp = pud_offset(p4dp, 0UL);
	for (i = 0; i < PTRS_PER_PUD; i++) {
		if (!pud_none(READ_ONCE(pudp[i])))
			return;
	}

	p4d_clear(p4dp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(pudp));
}

static void free_empty_p4d_table(pgd_t *pgdp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	unsigned long next;
	p4d_t *p4dp, p4d;

	do {
		next = p4d_addr_end(addr, end);
		p4dp = p4d_offset(pgdp, addr);
		p4d = READ_ONCE(*p4dp);
		if (p4d_none(p4d))
			continue;

		WARN_ON(!p4d_present(p4d));
		free_empty_pud_table(p4dp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);
}

static void free_empty_tables(unsigned long addr, unsigned long end,
			      unsigned long floor, unsigned long ceiling)
{
	unsigned long next;
	pgd_t *pgdp, pgd;

	do {
		next = pgd_addr_end(addr, end);
		pgdp = pgd_offset_k(addr);
		pgd = READ_ONCE(*pgdp);
		if (pgd_none(pgd))
			continue;

		WARN_ON(!pgd_present(pgd));
		free_empty_p4d_table(pgdp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);
}
#endif

C
Catalin Marinas 已提交
1092
#ifdef CONFIG_SPARSEMEM_VMEMMAP
1093
#if !ARM64_SWAPPER_USES_SECTION_MAPS
1094 1095
int __meminit vmemmap_populate(unsigned long start, unsigned long end, int node,
		struct vmem_altmap *altmap)
C
Catalin Marinas 已提交
1096
{
1097
	return vmemmap_populate_basepages(start, end, node, altmap);
C
Catalin Marinas 已提交
1098
}
1099
#else	/* !ARM64_SWAPPER_USES_SECTION_MAPS */
1100 1101
int __meminit vmemmap_populate(unsigned long start, unsigned long end, int node,
		struct vmem_altmap *altmap)
C
Catalin Marinas 已提交
1102
{
1103
	unsigned long addr = start;
C
Catalin Marinas 已提交
1104
	unsigned long next;
1105
	pgd_t *pgdp;
1106
	p4d_t *p4dp;
1107 1108
	pud_t *pudp;
	pmd_t *pmdp;
C
Catalin Marinas 已提交
1109 1110 1111 1112

	do {
		next = pmd_addr_end(addr, end);

1113 1114
		pgdp = vmemmap_pgd_populate(addr, node);
		if (!pgdp)
C
Catalin Marinas 已提交
1115 1116
			return -ENOMEM;

1117 1118 1119 1120 1121
		p4dp = vmemmap_p4d_populate(pgdp, addr, node);
		if (!p4dp)
			return -ENOMEM;

		pudp = vmemmap_pud_populate(p4dp, addr, node);
1122
		if (!pudp)
C
Catalin Marinas 已提交
1123 1124
			return -ENOMEM;

1125 1126
		pmdp = pmd_offset(pudp, addr);
		if (pmd_none(READ_ONCE(*pmdp))) {
C
Catalin Marinas 已提交
1127 1128
			void *p = NULL;

1129
			p = vmemmap_alloc_block_buf(PMD_SIZE, node, altmap);
1130 1131 1132 1133 1134
			if (!p) {
				if (vmemmap_populate_basepages(addr, next, node, altmap))
					return -ENOMEM;
				continue;
			}
C
Catalin Marinas 已提交
1135

1136
			pmd_set_huge(pmdp, __pa(p), __pgprot(PROT_SECT_NORMAL));
C
Catalin Marinas 已提交
1137
		} else
1138
			vmemmap_verify((pte_t *)pmdp, node, addr, next);
C
Catalin Marinas 已提交
1139 1140 1141 1142
	} while (addr = next, addr != end);

	return 0;
}
O
Odin Ugedal 已提交
1143
#endif	/* !ARM64_SWAPPER_USES_SECTION_MAPS */
1144 1145
void vmemmap_free(unsigned long start, unsigned long end,
		struct vmem_altmap *altmap)
1146
{
1147 1148 1149
#ifdef CONFIG_MEMORY_HOTPLUG
	WARN_ON((start < VMEMMAP_START) || (end > VMEMMAP_END));

1150
	unmap_hotplug_range(start, end, true, altmap);
1151 1152
	free_empty_tables(start, end, VMEMMAP_START, VMEMMAP_END);
#endif
1153
}
C
Catalin Marinas 已提交
1154
#endif	/* CONFIG_SPARSEMEM_VMEMMAP */
1155 1156 1157

static inline pud_t * fixmap_pud(unsigned long addr)
{
1158
	pgd_t *pgdp = pgd_offset_k(addr);
1159 1160
	p4d_t *p4dp = p4d_offset(pgdp, addr);
	p4d_t p4d = READ_ONCE(*p4dp);
1161

1162
	BUG_ON(p4d_none(p4d) || p4d_bad(p4d));
1163

1164
	return pud_offset_kimg(p4dp, addr);
1165 1166 1167 1168
}

static inline pmd_t * fixmap_pmd(unsigned long addr)
{
1169 1170
	pud_t *pudp = fixmap_pud(addr);
	pud_t pud = READ_ONCE(*pudp);
1171

1172
	BUG_ON(pud_none(pud) || pud_bad(pud));
1173

1174
	return pmd_offset_kimg(pudp, addr);
1175 1176 1177 1178
}

static inline pte_t * fixmap_pte(unsigned long addr)
{
1179
	return &bm_pte[pte_index(addr)];
1180 1181
}

1182 1183 1184 1185 1186 1187
/*
 * The p*d_populate functions call virt_to_phys implicitly so they can't be used
 * directly on kernel symbols (bm_p*d). This function is called too early to use
 * lm_alias so __p*d_populate functions must be used to populate with the
 * physical address from __pa_symbol.
 */
1188 1189
void __init early_fixmap_init(void)
{
1190 1191
	pgd_t *pgdp;
	p4d_t *p4dp, p4d;
1192 1193
	pud_t *pudp;
	pmd_t *pmdp;
1194 1195
	unsigned long addr = FIXADDR_START;

1196
	pgdp = pgd_offset_k(addr);
1197 1198
	p4dp = p4d_offset(pgdp, addr);
	p4d = READ_ONCE(*p4dp);
1199
	if (CONFIG_PGTABLE_LEVELS > 3 &&
1200
	    !(p4d_none(p4d) || p4d_page_paddr(p4d) == __pa_symbol(bm_pud))) {
1201 1202 1203 1204 1205 1206
		/*
		 * We only end up here if the kernel mapping and the fixmap
		 * share the top level pgd entry, which should only happen on
		 * 16k/4 levels configurations.
		 */
		BUG_ON(!IS_ENABLED(CONFIG_ARM64_16K_PAGES));
1207
		pudp = pud_offset_kimg(p4dp, addr);
1208
	} else {
1209 1210
		if (p4d_none(p4d))
			__p4d_populate(p4dp, __pa_symbol(bm_pud), PUD_TYPE_TABLE);
1211
		pudp = fixmap_pud(addr);
1212
	}
1213 1214 1215 1216
	if (pud_none(READ_ONCE(*pudp)))
		__pud_populate(pudp, __pa_symbol(bm_pmd), PMD_TYPE_TABLE);
	pmdp = fixmap_pmd(addr);
	__pmd_populate(pmdp, __pa_symbol(bm_pte), PMD_TYPE_TABLE);
1217 1218 1219

	/*
	 * The boot-ioremap range spans multiple pmds, for which
1220
	 * we are not prepared:
1221 1222 1223 1224
	 */
	BUILD_BUG_ON((__fix_to_virt(FIX_BTMAP_BEGIN) >> PMD_SHIFT)
		     != (__fix_to_virt(FIX_BTMAP_END) >> PMD_SHIFT));

1225 1226
	if ((pmdp != fixmap_pmd(fix_to_virt(FIX_BTMAP_BEGIN)))
	     || pmdp != fixmap_pmd(fix_to_virt(FIX_BTMAP_END))) {
1227
		WARN_ON(1);
1228 1229
		pr_warn("pmdp %p != %p, %p\n",
			pmdp, fixmap_pmd(fix_to_virt(FIX_BTMAP_BEGIN)),
1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240
			fixmap_pmd(fix_to_virt(FIX_BTMAP_END)));
		pr_warn("fix_to_virt(FIX_BTMAP_BEGIN): %08lx\n",
			fix_to_virt(FIX_BTMAP_BEGIN));
		pr_warn("fix_to_virt(FIX_BTMAP_END):   %08lx\n",
			fix_to_virt(FIX_BTMAP_END));

		pr_warn("FIX_BTMAP_END:       %d\n", FIX_BTMAP_END);
		pr_warn("FIX_BTMAP_BEGIN:     %d\n", FIX_BTMAP_BEGIN);
	}
}

1241 1242 1243 1244
/*
 * Unusually, this is also called in IRQ context (ghes_iounmap_irq) so if we
 * ever need to use IPIs for TLB broadcasting, then we're in trouble here.
 */
1245 1246 1247 1248
void __set_fixmap(enum fixed_addresses idx,
			       phys_addr_t phys, pgprot_t flags)
{
	unsigned long addr = __fix_to_virt(idx);
1249
	pte_t *ptep;
1250

1251
	BUG_ON(idx <= FIX_HOLE || idx >= __end_of_fixed_addresses);
1252

1253
	ptep = fixmap_pte(addr);
1254 1255

	if (pgprot_val(flags)) {
1256
		set_pte(ptep, pfn_pte(phys >> PAGE_SHIFT, flags));
1257
	} else {
1258
		pte_clear(&init_mm, addr, ptep);
1259 1260 1261
		flush_tlb_kernel_range(addr, addr+PAGE_SIZE);
	}
}
1262

1263
void *__init fixmap_remap_fdt(phys_addr_t dt_phys, int *size, pgprot_t prot)
1264 1265
{
	const u64 dt_virt_base = __fix_to_virt(FIX_FDT);
1266
	int offset;
1267 1268 1269 1270 1271
	void *dt_virt;

	/*
	 * Check whether the physical FDT address is set and meets the minimum
	 * alignment requirement. Since we are relying on MIN_FDT_ALIGN to be
1272 1273 1274
	 * at least 8 bytes so that we can always access the magic and size
	 * fields of the FDT header after mapping the first chunk, double check
	 * here if that is indeed the case.
1275 1276 1277 1278 1279 1280 1281 1282
	 */
	BUILD_BUG_ON(MIN_FDT_ALIGN < 8);
	if (!dt_phys || dt_phys % MIN_FDT_ALIGN)
		return NULL;

	/*
	 * Make sure that the FDT region can be mapped without the need to
	 * allocate additional translation table pages, so that it is safe
1283
	 * to call create_mapping_noalloc() this early.
1284 1285 1286 1287 1288 1289 1290 1291
	 *
	 * On 64k pages, the FDT will be mapped using PTEs, so we need to
	 * be in the same PMD as the rest of the fixmap.
	 * On 4k pages, we'll use section mappings for the FDT so we only
	 * have to be in the same PUD.
	 */
	BUILD_BUG_ON(dt_virt_base % SZ_2M);

1292 1293
	BUILD_BUG_ON(__fix_to_virt(FIX_FDT_END) >> SWAPPER_TABLE_SHIFT !=
		     __fix_to_virt(FIX_BTMAP_BEGIN) >> SWAPPER_TABLE_SHIFT);
1294

1295
	offset = dt_phys % SWAPPER_BLOCK_SIZE;
1296 1297 1298
	dt_virt = (void *)dt_virt_base + offset;

	/* map the first chunk so we can read the size from the header */
1299 1300
	create_mapping_noalloc(round_down(dt_phys, SWAPPER_BLOCK_SIZE),
			dt_virt_base, SWAPPER_BLOCK_SIZE, prot);
1301

1302
	if (fdt_magic(dt_virt) != FDT_MAGIC)
1303 1304
		return NULL;

1305 1306
	*size = fdt_totalsize(dt_virt);
	if (*size > MAX_FDT_SIZE)
1307 1308
		return NULL;

1309
	if (offset + *size > SWAPPER_BLOCK_SIZE)
1310
		create_mapping_noalloc(round_down(dt_phys, SWAPPER_BLOCK_SIZE), dt_virt_base,
1311
			       round_up(offset + *size, SWAPPER_BLOCK_SIZE), prot);
1312

1313 1314
	return dt_virt;
}
1315

1316 1317 1318 1319 1320
int __init arch_ioremap_p4d_supported(void)
{
	return 0;
}

1321 1322
int __init arch_ioremap_pud_supported(void)
{
1323 1324 1325 1326 1327
	/*
	 * Only 4k granule supports level 1 block mappings.
	 * SW table walks can't handle removal of intermediate entries.
	 */
	return IS_ENABLED(CONFIG_ARM64_4K_PAGES) &&
1328
	       !IS_ENABLED(CONFIG_PTDUMP_DEBUGFS);
1329 1330 1331 1332
}

int __init arch_ioremap_pmd_supported(void)
{
1333
	/* See arch_ioremap_pud_supported() */
1334
	return !IS_ENABLED(CONFIG_PTDUMP_DEBUGFS);
1335 1336
}

1337
int pud_set_huge(pud_t *pudp, phys_addr_t phys, pgprot_t prot)
1338
{
1339
	pud_t new_pud = pfn_pud(__phys_to_pfn(phys), mk_pud_sect_prot(prot));
1340

1341 1342 1343
	/* Only allow permission changes for now */
	if (!pgattr_change_is_safe(READ_ONCE(pud_val(*pudp)),
				   pud_val(new_pud)))
1344 1345
		return 0;

1346
	VM_BUG_ON(phys & ~PUD_MASK);
1347
	set_pud(pudp, new_pud);
1348 1349 1350
	return 1;
}

1351
int pmd_set_huge(pmd_t *pmdp, phys_addr_t phys, pgprot_t prot)
1352
{
1353
	pmd_t new_pmd = pfn_pmd(__phys_to_pfn(phys), mk_pmd_sect_prot(prot));
1354

1355 1356 1357
	/* Only allow permission changes for now */
	if (!pgattr_change_is_safe(READ_ONCE(pmd_val(*pmdp)),
				   pmd_val(new_pmd)))
1358 1359
		return 0;

1360
	VM_BUG_ON(phys & ~PMD_MASK);
1361
	set_pmd(pmdp, new_pmd);
1362 1363 1364
	return 1;
}

1365
int pud_clear_huge(pud_t *pudp)
1366
{
1367
	if (!pud_sect(READ_ONCE(*pudp)))
1368
		return 0;
1369
	pud_clear(pudp);
1370 1371 1372
	return 1;
}

1373
int pmd_clear_huge(pmd_t *pmdp)
1374
{
1375
	if (!pmd_sect(READ_ONCE(*pmdp)))
1376
		return 0;
1377
	pmd_clear(pmdp);
1378 1379
	return 1;
}
1380

1381
int pmd_free_pte_page(pmd_t *pmdp, unsigned long addr)
1382
{
1383 1384 1385 1386 1387
	pte_t *table;
	pmd_t pmd;

	pmd = READ_ONCE(*pmdp);

1388
	if (!pmd_table(pmd)) {
1389
		VM_WARN_ON(1);
1390 1391 1392 1393 1394 1395 1396 1397
		return 1;
	}

	table = pte_offset_kernel(pmdp, addr);
	pmd_clear(pmdp);
	__flush_tlb_kernel_pgtable(addr);
	pte_free_kernel(NULL, table);
	return 1;
1398 1399
}

1400
int pud_free_pmd_page(pud_t *pudp, unsigned long addr)
1401
{
1402 1403 1404 1405 1406 1407 1408
	pmd_t *table;
	pmd_t *pmdp;
	pud_t pud;
	unsigned long next, end;

	pud = READ_ONCE(*pudp);

1409
	if (!pud_table(pud)) {
1410
		VM_WARN_ON(1);
1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425
		return 1;
	}

	table = pmd_offset(pudp, addr);
	pmdp = table;
	next = addr;
	end = addr + PUD_SIZE;
	do {
		pmd_free_pte_page(pmdp, next);
	} while (pmdp++, next += PMD_SIZE, next != end);

	pud_clear(pudp);
	__flush_tlb_kernel_pgtable(addr);
	pmd_free(NULL, table);
	return 1;
1426
}
R
Robin Murphy 已提交
1427

1428 1429 1430 1431 1432
int p4d_free_pud_page(p4d_t *p4d, unsigned long addr)
{
	return 0;	/* Don't attempt a block mapping */
}

R
Robin Murphy 已提交
1433
#ifdef CONFIG_MEMORY_HOTPLUG
1434 1435 1436 1437 1438 1439 1440
static void __remove_pgd_mapping(pgd_t *pgdir, unsigned long start, u64 size)
{
	unsigned long end = start + size;

	WARN_ON(pgdir != init_mm.pgd);
	WARN_ON((start < PAGE_OFFSET) || (end > PAGE_END));

1441
	unmap_hotplug_range(start, end, false, NULL);
1442 1443 1444
	free_empty_tables(start, end, PAGE_OFFSET, PAGE_END);
}

1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456
static bool inside_linear_region(u64 start, u64 size)
{
	/*
	 * Linear mapping region is the range [PAGE_OFFSET..(PAGE_END - 1)]
	 * accommodating both its ends but excluding PAGE_END. Max physical
	 * range which can be mapped inside this linear mapping range, must
	 * also be derived from its end points.
	 */
	return start >= __pa(_PAGE_OFFSET(vabits_actual)) &&
	       (start + size - 1) <= __pa(PAGE_END - 1);
}

1457
int arch_add_memory(int nid, u64 start, u64 size,
1458
		    struct mhp_params *params)
R
Robin Murphy 已提交
1459
{
1460
	int ret, flags = 0;
R
Robin Murphy 已提交
1461

1462 1463 1464 1465 1466
	if (!inside_linear_region(start, size)) {
		pr_err("[%llx %llx] is outside linear mapping region\n", start, start + size);
		return -EINVAL;
	}

R
Robin Murphy 已提交
1467 1468 1469 1470
	if (rodata_full || debug_pagealloc_enabled())
		flags = NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;

	__create_pgd_mapping(swapper_pg_dir, start, __phys_to_virt(start),
1471 1472
			     size, params->pgprot, __pgd_pgtable_alloc,
			     flags);
R
Robin Murphy 已提交
1473

1474 1475
	memblock_clear_nomap(start, size);

1476
	ret = __add_pages(nid, start >> PAGE_SHIFT, size >> PAGE_SHIFT,
1477
			   params);
1478 1479 1480 1481
	if (ret)
		__remove_pgd_mapping(swapper_pg_dir,
				     __phys_to_virt(start), size);
	return ret;
R
Robin Murphy 已提交
1482
}
1483

1484 1485 1486 1487 1488 1489
void arch_remove_memory(int nid, u64 start, u64 size,
			struct vmem_altmap *altmap)
{
	unsigned long start_pfn = start >> PAGE_SHIFT;
	unsigned long nr_pages = size >> PAGE_SHIFT;

1490
	__remove_pages(start_pfn, nr_pages, altmap);
1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510
	__remove_pgd_mapping(swapper_pg_dir, __phys_to_virt(start), size);
}

/*
 * This memory hotplug notifier helps prevent boot memory from being
 * inadvertently removed as it blocks pfn range offlining process in
 * __offline_pages(). Hence this prevents both offlining as well as
 * removal process for boot memory which is initially always online.
 * In future if and when boot memory could be removed, this notifier
 * should be dropped and free_hotplug_page_range() should handle any
 * reserved pages allocated during boot.
 */
static int prevent_bootmem_remove_notifier(struct notifier_block *nb,
					   unsigned long action, void *data)
{
	struct mem_section *ms;
	struct memory_notify *arg = data;
	unsigned long end_pfn = arg->start_pfn + arg->nr_pages;
	unsigned long pfn = arg->start_pfn;

1511
	if ((action != MEM_GOING_OFFLINE) && (action != MEM_OFFLINE))
1512 1513 1514
		return NOTIFY_OK;

	for (; pfn < end_pfn; pfn += PAGES_PER_SECTION) {
1515 1516 1517
		unsigned long start = PFN_PHYS(pfn);
		unsigned long end = start + (1UL << PA_SECTION_SHIFT);

1518
		ms = __pfn_to_section(pfn);
1519 1520 1521 1522 1523 1524 1525 1526 1527 1528
		if (!early_section(ms))
			continue;

		if (action == MEM_GOING_OFFLINE) {
			/*
			 * Boot memory removal is not supported. Prevent
			 * it via blocking any attempted offline request
			 * for the boot memory and just report it.
			 */
			pr_warn("Boot memory [%lx %lx] offlining attempted\n", start, end);
1529
			return NOTIFY_BAD;
1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547
		} else if (action == MEM_OFFLINE) {
			/*
			 * This should have never happened. Boot memory
			 * offlining should have been prevented by this
			 * very notifier. Probably some memory removal
			 * procedure might have changed which would then
			 * require further debug.
			 */
			pr_err("Boot memory [%lx %lx] offlined\n", start, end);

			/*
			 * Core memory hotplug does not process a return
			 * code from the notifier for MEM_OFFLINE events.
			 * The error condition has been reported. Return
			 * from here as if ignored.
			 */
			return NOTIFY_DONE;
		}
1548 1549 1550 1551 1552 1553 1554 1555
	}
	return NOTIFY_OK;
}

static struct notifier_block prevent_bootmem_remove_nb = {
	.notifier_call = prevent_bootmem_remove_notifier,
};

1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602
/*
 * This ensures that boot memory sections on the platform are online
 * from early boot. Memory sections could not be prevented from being
 * offlined, unless for some reason they are not online to begin with.
 * This helps validate the basic assumption on which the above memory
 * event notifier works to prevent boot memory section offlining and
 * its possible removal.
 */
static void validate_bootmem_online(void)
{
	phys_addr_t start, end, addr;
	struct mem_section *ms;
	u64 i;

	/*
	 * Scanning across all memblock might be expensive
	 * on some big memory systems. Hence enable this
	 * validation only with DEBUG_VM.
	 */
	if (!IS_ENABLED(CONFIG_DEBUG_VM))
		return;

	for_each_mem_range(i, &start, &end) {
		for (addr = start; addr < end; addr += (1UL << PA_SECTION_SHIFT)) {
			ms = __pfn_to_section(PHYS_PFN(addr));

			/*
			 * All memory ranges in the system at this point
			 * should have been marked as early sections.
			 */
			WARN_ON(!early_section(ms));

			/*
			 * Memory notifier mechanism here to prevent boot
			 * memory offlining depends on the fact that each
			 * early section memory on the system is initially
			 * online. Otherwise a given memory section which
			 * is already offline will be overlooked and can
			 * be removed completely. Call out such sections.
			 */
			if (!online_section(ms))
				pr_err("Boot memory [%llx %llx] is offline, can be removed\n",
					addr, addr + (1UL << PA_SECTION_SHIFT));
		}
	}
}

1603 1604
static int __init prevent_bootmem_remove_init(void)
{
1605 1606 1607 1608 1609
	int ret = 0;

	if (!IS_ENABLED(CONFIG_MEMORY_HOTREMOVE))
		return ret;

1610
	validate_bootmem_online();
1611 1612 1613 1614 1615
	ret = register_memory_notifier(&prevent_bootmem_remove_nb);
	if (ret)
		pr_err("%s: Notifier registration failed %d\n", __func__, ret);

	return ret;
1616
}
1617
early_initcall(prevent_bootmem_remove_init);
1618
#endif