fault.c 22.5 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0
L
Linus Torvalds 已提交
2 3
/*
 *  S390 version
4
 *    Copyright IBM Corp. 1999
L
Linus Torvalds 已提交
5 6 7 8 9 10 11
 *    Author(s): Hartmut Penner (hp@de.ibm.com)
 *               Ulrich Weigand (uweigand@de.ibm.com)
 *
 *  Derived from "arch/i386/mm/fault.c"
 *    Copyright (C) 1995  Linus Torvalds
 */

12
#include <linux/kernel_stat.h>
13
#include <linux/perf_event.h>
L
Linus Torvalds 已提交
14 15
#include <linux/signal.h>
#include <linux/sched.h>
16
#include <linux/sched/debug.h>
L
Linus Torvalds 已提交
17 18 19 20 21 22 23
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/types.h>
#include <linux/ptrace.h>
#include <linux/mman.h>
#include <linux/mm.h>
H
Heiko Carstens 已提交
24
#include <linux/compat.h>
L
Linus Torvalds 已提交
25
#include <linux/smp.h>
26
#include <linux/kdebug.h>
L
Linus Torvalds 已提交
27 28
#include <linux/init.h>
#include <linux/console.h>
29
#include <linux/extable.h>
L
Linus Torvalds 已提交
30
#include <linux/hardirq.h>
M
Michael Grundy 已提交
31
#include <linux/kprobes.h>
32
#include <linux/uaccess.h>
33
#include <linux/hugetlb.h>
34
#include <asm/asm-offsets.h>
35
#include <asm/diag.h>
L
Linus Torvalds 已提交
36
#include <asm/pgtable.h>
37
#include <asm/gmap.h>
38
#include <asm/irq.h>
M
Martin Schwidefsky 已提交
39
#include <asm/mmu_context.h>
40
#include <asm/facility.h>
41
#include <asm/uv.h>
42
#include "../kernel/entry.h"
L
Linus Torvalds 已提交
43 44 45 46 47

#define __FAIL_ADDR_MASK -4096L
#define __SUBCODE_MASK 0x0600
#define __PF_RES_FIELD 0x8000000000000000ULL

48 49 50 51 52
#define VM_FAULT_BADCONTEXT	((__force vm_fault_t) 0x010000)
#define VM_FAULT_BADMAP		((__force vm_fault_t) 0x020000)
#define VM_FAULT_BADACCESS	((__force vm_fault_t) 0x040000)
#define VM_FAULT_SIGNAL		((__force vm_fault_t) 0x080000)
#define VM_FAULT_PFAULT		((__force vm_fault_t) 0x100000)
53

54 55 56 57 58 59 60
enum fault_type {
	KERNEL_FAULT,
	USER_FAULT,
	VDSO_FAULT,
	GMAP_FAULT,
};

61
static unsigned long store_indication __read_mostly;
62

63
static int __init fault_init(void)
64
{
65
	if (test_facility(75))
66
		store_indication = 0xc00;
67
	return 0;
68
}
69
early_initcall(fault_init);
70

L
Linus Torvalds 已提交
71
/*
72
 * Find out which address space caused the exception.
L
Linus Torvalds 已提交
73
 */
74
static enum fault_type get_fault_type(struct pt_regs *regs)
L
Linus Torvalds 已提交
75
{
76 77 78
	unsigned long trans_exc_code;

	trans_exc_code = regs->int_parm_long & 3;
79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96
	if (likely(trans_exc_code == 0)) {
		/* primary space exception */
		if (IS_ENABLED(CONFIG_PGSTE) &&
		    test_pt_regs_flag(regs, PIF_GUEST_FAULT))
			return GMAP_FAULT;
		if (current->thread.mm_segment == USER_DS)
			return USER_FAULT;
		return KERNEL_FAULT;
	}
	if (trans_exc_code == 2) {
		/* secondary space exception */
		if (current->thread.mm_segment & 1) {
			if (current->thread.mm_segment == USER_DS_SACF)
				return USER_FAULT;
			return KERNEL_FAULT;
		}
		return VDSO_FAULT;
	}
97 98 99 100
	if (trans_exc_code == 1) {
		/* access register mode, not used in the kernel */
		return USER_FAULT;
	}
101 102
	/* home space exception -> access via kernel ASCE */
	return KERNEL_FAULT;
L
Linus Torvalds 已提交
103 104
}

105 106 107 108 109 110 111 112 113
static int bad_address(void *p)
{
	unsigned long dummy;

	return probe_kernel_address((unsigned long *)p, dummy);
}

static void dump_pagetable(unsigned long asce, unsigned long address)
{
114
	unsigned long *table = __va(asce & _ASCE_ORIGIN);
115 116 117 118

	pr_alert("AS:%016lx ", asce);
	switch (asce & _ASCE_TYPE_MASK) {
	case _ASCE_TYPE_REGION1:
119
		table += (address & _REGION1_INDEX) >> _REGION1_SHIFT;
120 121 122 123 124 125
		if (bad_address(table))
			goto bad;
		pr_cont("R1:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
J
Joe Perches 已提交
126
		fallthrough;
127
	case _ASCE_TYPE_REGION2:
128
		table += (address & _REGION2_INDEX) >> _REGION2_SHIFT;
129 130 131 132 133 134
		if (bad_address(table))
			goto bad;
		pr_cont("R2:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
J
Joe Perches 已提交
135
		fallthrough;
136
	case _ASCE_TYPE_REGION3:
137
		table += (address & _REGION3_INDEX) >> _REGION3_SHIFT;
138 139 140 141 142 143
		if (bad_address(table))
			goto bad;
		pr_cont("R3:%016lx ", *table);
		if (*table & (_REGION_ENTRY_INVALID | _REGION3_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
J
Joe Perches 已提交
144
		fallthrough;
145
	case _ASCE_TYPE_SEGMENT:
146
		table += (address & _SEGMENT_INDEX) >> _SEGMENT_SHIFT;
147 148
		if (bad_address(table))
			goto bad;
J
Joe Perches 已提交
149
		pr_cont("S:%016lx ", *table);
150 151 152 153
		if (*table & (_SEGMENT_ENTRY_INVALID | _SEGMENT_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _SEGMENT_ENTRY_ORIGIN);
	}
154
	table += (address & _PAGE_INDEX) >> _PAGE_SHIFT;
155 156 157 158 159 160 161 162 163 164 165 166 167 168
	if (bad_address(table))
		goto bad;
	pr_cont("P:%016lx ", *table);
out:
	pr_cont("\n");
	return;
bad:
	pr_cont("BAD\n");
}

static void dump_fault_info(struct pt_regs *regs)
{
	unsigned long asce;

169 170
	pr_alert("Failing address: %016lx TEID: %016lx\n",
		 regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186
	pr_alert("Fault in ");
	switch (regs->int_parm_long & 3) {
	case 3:
		pr_cont("home space ");
		break;
	case 2:
		pr_cont("secondary space ");
		break;
	case 1:
		pr_cont("access register ");
		break;
	case 0:
		pr_cont("primary space ");
		break;
	}
	pr_cont("mode while using ");
187 188
	switch (get_fault_type(regs)) {
	case USER_FAULT:
189 190
		asce = S390_lowcore.user_asce;
		pr_cont("user ");
191 192 193 194 195 196 197 198 199 200 201 202 203
		break;
	case VDSO_FAULT:
		asce = S390_lowcore.vdso_asce;
		pr_cont("vdso ");
		break;
	case GMAP_FAULT:
		asce = ((struct gmap *) S390_lowcore.gmap)->asce;
		pr_cont("gmap ");
		break;
	case KERNEL_FAULT:
		asce = S390_lowcore.kernel_asce;
		pr_cont("kernel ");
		break;
204 205
	default:
		unreachable();
206 207 208 209 210
	}
	pr_cont("ASCE.\n");
	dump_pagetable(asce, regs->int_parm_long & __FAIL_ADDR_MASK);
}

211 212 213
int show_unhandled_signals = 1;

void report_user_fault(struct pt_regs *regs, long signr, int is_mm_fault)
214 215 216 217 218 219 220
{
	if ((task_pid_nr(current) > 1) && !show_unhandled_signals)
		return;
	if (!unhandled_signal(current, signr))
		return;
	if (!printk_ratelimit())
		return;
221
	printk(KERN_ALERT "User process fault: interruption code %04x ilc:%d ",
222
	       regs->int_code & 0xffff, regs->int_code >> 17);
223
	print_vma_addr(KERN_CONT "in ", regs->psw.addr);
M
Martin Schwidefsky 已提交
224
	printk(KERN_CONT "\n");
225 226
	if (is_mm_fault)
		dump_fault_info(regs);
227 228 229
	show_regs(regs);
}

L
Linus Torvalds 已提交
230 231 232 233
/*
 * Send SIGSEGV to task.  This is an external routine
 * to keep the stack usage of do_page_fault small.
 */
M
Martin Schwidefsky 已提交
234
static noinline void do_sigsegv(struct pt_regs *regs, int si_code)
L
Linus Torvalds 已提交
235
{
236
	report_user_fault(regs, SIGSEGV, 1);
237
	force_sig_fault(SIGSEGV, si_code,
238
			(void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK));
L
Linus Torvalds 已提交
239 240
}

241 242 243 244 245 246 247 248 249 250 251 252
const struct exception_table_entry *s390_search_extables(unsigned long addr)
{
	const struct exception_table_entry *fixup;

	fixup = search_extable(__start_dma_ex_table,
			       __stop_dma_ex_table - __start_dma_ex_table,
			       addr);
	if (!fixup)
		fixup = search_exception_tables(addr);
	return fixup;
}

M
Martin Schwidefsky 已提交
253
static noinline void do_no_context(struct pt_regs *regs)
254 255 256 257
{
	const struct exception_table_entry *fixup;

	/* Are we prepared to handle this kernel fault?  */
258
	fixup = s390_search_extables(regs->psw.addr);
259
	if (fixup) {
260
		regs->psw.addr = extable_fixup(fixup);
261 262 263 264 265 266 267
		return;
	}

	/*
	 * Oops. The kernel tried to access some bad page. We'll have to
	 * terminate things with extreme prejudice.
	 */
268
	if (get_fault_type(regs) == KERNEL_FAULT)
269
		printk(KERN_ALERT "Unable to handle kernel pointer dereference"
270
		       " in virtual kernel address space\n");
271 272
	else
		printk(KERN_ALERT "Unable to handle kernel paging request"
273 274
		       " in virtual user address space\n");
	dump_fault_info(regs);
M
Martin Schwidefsky 已提交
275
	die(regs, "Oops");
276 277 278
	do_exit(SIGKILL);
}

M
Martin Schwidefsky 已提交
279
static noinline void do_low_address(struct pt_regs *regs)
280 281 282 283 284
{
	/* Low-address protection hit in kernel mode means
	   NULL pointer write access in kernel mode.  */
	if (regs->psw.mask & PSW_MASK_PSTATE) {
		/* Low-address protection hit in user mode 'cannot happen'. */
M
Martin Schwidefsky 已提交
285
		die (regs, "Low-address protection");
286 287 288
		do_exit(SIGKILL);
	}

M
Martin Schwidefsky 已提交
289
	do_no_context(regs);
290 291
}

M
Martin Schwidefsky 已提交
292
static noinline void do_sigbus(struct pt_regs *regs)
293 294 295 296 297
{
	/*
	 * Send a sigbus, regardless of whether we were in kernel
	 * or user mode.
	 */
298
	force_sig_fault(SIGBUS, BUS_ADRERR,
299
			(void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK));
300 301
}

302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321
static noinline int signal_return(struct pt_regs *regs)
{
	u16 instruction;
	int rc;

	rc = __get_user(instruction, (u16 __user *) regs->psw.addr);
	if (rc)
		return rc;
	if (instruction == 0x0a77) {
		set_pt_regs_flag(regs, PIF_SYSCALL);
		regs->int_code = 0x00040077;
		return 0;
	} else if (instruction == 0x0aad) {
		set_pt_regs_flag(regs, PIF_SYSCALL);
		regs->int_code = 0x000400ad;
		return 0;
	}
	return -EACCES;
}

322 323
static noinline void do_fault_error(struct pt_regs *regs, int access,
					vm_fault_t fault)
324 325 326 327 328
{
	int si_code;

	switch (fault) {
	case VM_FAULT_BADACCESS:
329 330
		if (access == VM_EXEC && signal_return(regs) == 0)
			break;
J
Joe Perches 已提交
331
		fallthrough;
332 333
	case VM_FAULT_BADMAP:
		/* Bad memory access. Check if it is kernel or user space. */
334
		if (user_mode(regs)) {
335 336 337
			/* User mode accesses just cause a SIGSEGV */
			si_code = (fault == VM_FAULT_BADMAP) ?
				SEGV_MAPERR : SEGV_ACCERR;
M
Martin Schwidefsky 已提交
338
			do_sigsegv(regs, si_code);
339
			break;
340
		}
J
Joe Perches 已提交
341
		fallthrough;
342
	case VM_FAULT_BADCONTEXT:
343
	case VM_FAULT_PFAULT:
M
Martin Schwidefsky 已提交
344
		do_no_context(regs);
345
		break;
346 347 348 349
	case VM_FAULT_SIGNAL:
		if (!user_mode(regs))
			do_no_context(regs);
		break;
350
	default: /* fault & VM_FAULT_ERROR */
351
		if (fault & VM_FAULT_OOM) {
352
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
353
				do_no_context(regs);
354 355
			else
				pagefault_out_of_memory();
356 357 358 359 360 361
		} else if (fault & VM_FAULT_SIGSEGV) {
			/* Kernel mode? Handle exceptions or die */
			if (!user_mode(regs))
				do_no_context(regs);
			else
				do_sigsegv(regs, SEGV_MAPERR);
362
		} else if (fault & VM_FAULT_SIGBUS) {
363
			/* Kernel mode? Handle exceptions or die */
364
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
365
				do_no_context(regs);
M
Martin Schwidefsky 已提交
366
			else
M
Martin Schwidefsky 已提交
367
				do_sigbus(regs);
368 369 370 371 372 373
		} else
			BUG();
		break;
	}
}

L
Linus Torvalds 已提交
374 375 376 377 378
/*
 * This routine handles page faults.  It determines the address,
 * and the problem, and then passes it off to one of the appropriate
 * routines.
 *
379
 * interruption code (int_code):
L
Linus Torvalds 已提交
380 381 382 383 384
 *   04       Protection           ->  Write-Protection  (suprression)
 *   10       Segment translation  ->  Not present       (nullification)
 *   11       Page translation     ->  Not present       (nullification)
 *   3b       Region third trans.  ->  Not present       (nullification)
 */
385
static inline vm_fault_t do_exception(struct pt_regs *regs, int access)
L
Linus Torvalds 已提交
386
{
387
	struct gmap *gmap;
388 389 390
	struct task_struct *tsk;
	struct mm_struct *mm;
	struct vm_area_struct *vma;
391
	enum fault_type type;
M
Martin Schwidefsky 已提交
392
	unsigned long trans_exc_code;
393
	unsigned long address;
394
	unsigned int flags;
395
	vm_fault_t fault;
L
Linus Torvalds 已提交
396

397 398 399 400 401
	tsk = current;
	/*
	 * The instruction that caused the program check has
	 * been nullified. Don't signal single step via SIGTRAP.
	 */
402
	clear_pt_regs_flag(regs, PIF_PER_TRAP);
403

404
	if (kprobe_page_fault(regs, 14))
405
		return 0;
M
Michael Grundy 已提交
406

407
	mm = tsk->mm;
M
Martin Schwidefsky 已提交
408
	trans_exc_code = regs->int_parm_long;
L
Linus Torvalds 已提交
409 410 411 412 413 414

	/*
	 * Verify that the fault happened in user space, that
	 * we are not in an interrupt and that there is a 
	 * user context.
	 */
415
	fault = VM_FAULT_BADCONTEXT;
416 417 418 419 420 421
	type = get_fault_type(regs);
	switch (type) {
	case KERNEL_FAULT:
		goto out;
	case VDSO_FAULT:
		fault = VM_FAULT_BADMAP;
422
		goto out;
423 424 425 426 427 428
	case USER_FAULT:
	case GMAP_FAULT:
		if (faulthandler_disabled() || !mm)
			goto out;
		break;
	}
L
Linus Torvalds 已提交
429

430
	address = trans_exc_code & __FAIL_ADDR_MASK;
431
	perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS, 1, regs, address);
P
Peter Xu 已提交
432
	flags = FAULT_FLAG_DEFAULT;
433 434
	if (user_mode(regs))
		flags |= FAULT_FLAG_USER;
435 436
	if (access == VM_WRITE || (trans_exc_code & store_indication) == 0x400)
		flags |= FAULT_FLAG_WRITE;
437
	down_read(&mm->mmap_sem);
L
Linus Torvalds 已提交
438

439 440 441
	gmap = NULL;
	if (IS_ENABLED(CONFIG_PGSTE) && type == GMAP_FAULT) {
		gmap = (struct gmap *) S390_lowcore.gmap;
442
		current->thread.gmap_addr = address;
443
		current->thread.gmap_write_flag = !!(flags & FAULT_FLAG_WRITE);
444
		current->thread.gmap_int_code = regs->int_code & 0xffff;
445
		address = __gmap_translate(gmap, address);
446 447 448 449
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
450 451
		if (gmap->pfault_enabled)
			flags |= FAULT_FLAG_RETRY_NOWAIT;
452 453 454
	}

retry:
455
	fault = VM_FAULT_BADMAP;
456 457
	vma = find_vma(mm, address);
	if (!vma)
458
		goto out_up;
G
Gerald Schaefer 已提交
459

460 461 462 463 464 465 466 467 468 469 470 471
	if (unlikely(vma->vm_start > address)) {
		if (!(vma->vm_flags & VM_GROWSDOWN))
			goto out_up;
		if (expand_stack(vma, address))
			goto out_up;
	}

	/*
	 * Ok, we have a good vm_area for this memory access, so
	 * we can handle it..
	 */
	fault = VM_FAULT_BADACCESS;
472
	if (unlikely(!(vma->vm_flags & access)))
473
		goto out_up;
L
Linus Torvalds 已提交
474

475 476
	if (is_vm_hugetlb_page(vma))
		address &= HPAGE_MASK;
L
Linus Torvalds 已提交
477 478 479 480 481
	/*
	 * If for any reason at all we couldn't handle the fault,
	 * make sure we exit gracefully rather than endlessly redo
	 * the fault.
	 */
482
	fault = handle_mm_fault(vma, address, flags);
P
Peter Xu 已提交
483
	if (fault_signal_pending(fault, regs)) {
484
		fault = VM_FAULT_SIGNAL;
485 486
		if (flags & FAULT_FLAG_RETRY_NOWAIT)
			goto out_up;
487 488
		goto out;
	}
489 490 491
	if (unlikely(fault & VM_FAULT_ERROR))
		goto out_up;

492 493 494 495 496 497 498 499
	/*
	 * Major/minor page fault accounting is only done on the
	 * initial attempt. If we go through a retry, it is extremely
	 * likely that the page will be found in page cache at that point.
	 */
	if (flags & FAULT_FLAG_ALLOW_RETRY) {
		if (fault & VM_FAULT_MAJOR) {
			tsk->maj_flt++;
500
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MAJ, 1,
501 502 503
				      regs, address);
		} else {
			tsk->min_flt++;
504
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MIN, 1,
505 506 507
				      regs, address);
		}
		if (fault & VM_FAULT_RETRY) {
508 509
			if (IS_ENABLED(CONFIG_PGSTE) && gmap &&
			    (flags & FAULT_FLAG_RETRY_NOWAIT)) {
510 511 512 513 514 515
				/* FAULT_FLAG_RETRY_NOWAIT has been set,
				 * mmap_sem has not been released */
				current->thread.gmap_pfault = 1;
				fault = VM_FAULT_PFAULT;
				goto out_up;
			}
516
			flags &= ~FAULT_FLAG_RETRY_NOWAIT;
517
			flags |= FAULT_FLAG_TRIED;
518
			down_read(&mm->mmap_sem);
519 520
			goto retry;
		}
521
	}
522
	if (IS_ENABLED(CONFIG_PGSTE) && gmap) {
523 524 525 526 527 528 529 530 531 532 533
		address =  __gmap_link(gmap, current->thread.gmap_addr,
				       address);
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
		if (address == -ENOMEM) {
			fault = VM_FAULT_OOM;
			goto out_up;
		}
	}
534 535
	fault = 0;
out_up:
536
	up_read(&mm->mmap_sem);
537 538
out:
	return fault;
L
Linus Torvalds 已提交
539 540
}

541
void do_protection_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
542
{
M
Martin Schwidefsky 已提交
543
	unsigned long trans_exc_code;
544 545
	int access;
	vm_fault_t fault;
546

M
Martin Schwidefsky 已提交
547
	trans_exc_code = regs->int_parm_long;
548 549 550 551 552 553 554
	/*
	 * Protection exceptions are suppressing, decrement psw address.
	 * The exception to this rule are aborted transactions, for these
	 * the PSW already points to the correct location.
	 */
	if (!(regs->int_code & 0x200))
		regs->psw.addr = __rewind_psw(regs->psw, regs->int_code >> 16);
555 556 557 558 559
	/*
	 * Check for low-address protection.  This needs to be treated
	 * as a special case because the translation exception code
	 * field is not guaranteed to contain valid data in this case.
	 */
560
	if (unlikely(!(trans_exc_code & 4))) {
M
Martin Schwidefsky 已提交
561
		do_low_address(regs);
562 563
		return;
	}
564 565 566 567 568 569 570 571 572
	if (unlikely(MACHINE_HAS_NX && (trans_exc_code & 0x80))) {
		regs->int_parm_long = (trans_exc_code & ~PAGE_MASK) |
					(regs->psw.addr & PAGE_MASK);
		access = VM_EXEC;
		fault = VM_FAULT_BADACCESS;
	} else {
		access = VM_WRITE;
		fault = do_exception(regs, access);
	}
573
	if (unlikely(fault))
574
		do_fault_error(regs, access, fault);
L
Linus Torvalds 已提交
575
}
576
NOKPROBE_SYMBOL(do_protection_exception);
L
Linus Torvalds 已提交
577

578
void do_dat_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
579
{
580 581
	int access;
	vm_fault_t fault;
582

583
	access = VM_READ | VM_EXEC | VM_WRITE;
M
Martin Schwidefsky 已提交
584
	fault = do_exception(regs, access);
585
	if (unlikely(fault))
586
		do_fault_error(regs, access, fault);
L
Linus Torvalds 已提交
587
}
588
NOKPROBE_SYMBOL(do_dat_exception);
L
Linus Torvalds 已提交
589 590 591 592 593

#ifdef CONFIG_PFAULT 
/*
 * 'pfault' pseudo page faults routines.
 */
594
static int pfault_disable;
L
Linus Torvalds 已提交
595 596 597 598 599 600 601 602 603

static int __init nopfault(char *str)
{
	pfault_disable = 1;
	return 1;
}

__setup("nopfault", nopfault);

H
Heiko Carstens 已提交
604 605 606 607 608 609 610 611 612 613
struct pfault_refbk {
	u16 refdiagc;
	u16 reffcode;
	u16 refdwlen;
	u16 refversn;
	u64 refgaddr;
	u64 refselmk;
	u64 refcmpmk;
	u64 reserved;
} __attribute__ ((packed, aligned(8)));
L
Linus Torvalds 已提交
614

615 616 617 618 619 620 621 622 623 624 625
static struct pfault_refbk pfault_init_refbk = {
	.refdiagc = 0x258,
	.reffcode = 0,
	.refdwlen = 5,
	.refversn = 2,
	.refgaddr = __LC_LPP,
	.refselmk = 1ULL << 48,
	.refcmpmk = 1ULL << 48,
	.reserved = __PF_RES_FIELD
};

L
Linus Torvalds 已提交
626 627 628 629
int pfault_init(void)
{
        int rc;

630
	if (pfault_disable)
L
Linus Torvalds 已提交
631
		return -1;
632
	diag_stat_inc(DIAG_STAT_X258);
633 634 635 636
	asm volatile(
		"	diag	%1,%0,0x258\n"
		"0:	j	2f\n"
		"1:	la	%0,8\n"
L
Linus Torvalds 已提交
637
		"2:\n"
638
		EX_TABLE(0b,1b)
639 640
		: "=d" (rc)
		: "a" (&pfault_init_refbk), "m" (pfault_init_refbk) : "cc");
L
Linus Torvalds 已提交
641 642 643
        return rc;
}

644 645 646 647 648 649 650
static struct pfault_refbk pfault_fini_refbk = {
	.refdiagc = 0x258,
	.reffcode = 1,
	.refdwlen = 5,
	.refversn = 2,
};

L
Linus Torvalds 已提交
651 652 653
void pfault_fini(void)
{

654
	if (pfault_disable)
L
Linus Torvalds 已提交
655
		return;
656
	diag_stat_inc(DIAG_STAT_X258);
657 658
	asm volatile(
		"	diag	%0,0,0x258\n"
H
Heiko Carstens 已提交
659
		"0:	nopr	%%r7\n"
660
		EX_TABLE(0b,0b)
661
		: : "a" (&pfault_fini_refbk), "m" (pfault_fini_refbk) : "cc");
L
Linus Torvalds 已提交
662 663
}

664 665 666
static DEFINE_SPINLOCK(pfault_lock);
static LIST_HEAD(pfault_list);

667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689
#define PF_COMPLETE	0x0080

/*
 * The mechanism of our pfault code: if Linux is running as guest, runs a user
 * space process and the user space process accesses a page that the host has
 * paged out we get a pfault interrupt.
 *
 * This allows us, within the guest, to schedule a different process. Without
 * this mechanism the host would have to suspend the whole virtual cpu until
 * the page has been paged in.
 *
 * So when we get such an interrupt then we set the state of the current task
 * to uninterruptible and also set the need_resched flag. Both happens within
 * interrupt context(!). If we later on want to return to user space we
 * recognize the need_resched flag and then call schedule().  It's not very
 * obvious how this works...
 *
 * Of course we have a lot of additional fun with the completion interrupt (->
 * host signals that a page of a process has been paged in and the process can
 * continue to run). This interrupt can arrive on any cpu and, since we have
 * virtual cpus, actually appear before the interrupt that signals that a page
 * is missing.
 */
690
static void pfault_interrupt(struct ext_code ext_code,
691
			     unsigned int param32, unsigned long param64)
L
Linus Torvalds 已提交
692 693 694
{
	struct task_struct *tsk;
	__u16 subcode;
695
	pid_t pid;
L
Linus Torvalds 已提交
696 697

	/*
698 699 700
	 * Get the external interruption subcode & pfault initial/completion
	 * signal bit. VM stores this in the 'cpu address' field associated
	 * with the external interrupt.
L
Linus Torvalds 已提交
701
	 */
702
	subcode = ext_code.subcode;
L
Linus Torvalds 已提交
703 704
	if ((subcode & 0xff00) != __SUBCODE_MASK)
		return;
705
	inc_irq_stat(IRQEXT_PFL);
706
	/* Get the token (= pid of the affected task). */
707
	pid = param64 & LPP_PID_MASK;
708 709 710 711 712 713 714
	rcu_read_lock();
	tsk = find_task_by_pid_ns(pid, &init_pid_ns);
	if (tsk)
		get_task_struct(tsk);
	rcu_read_unlock();
	if (!tsk)
		return;
715
	spin_lock(&pfault_lock);
716
	if (subcode & PF_COMPLETE) {
L
Linus Torvalds 已提交
717
		/* signal bit is set -> a page has been swapped in by VM */
718
		if (tsk->thread.pfault_wait == 1) {
L
Linus Torvalds 已提交
719 720 721 722
			/* Initial interrupt was faster than the completion
			 * interrupt. pfault_wait is valid. Set pfault_wait
			 * back to zero and wake up the process. This can
			 * safely be done because the task is still sleeping
723
			 * and can't produce new pfaults. */
L
Linus Torvalds 已提交
724
			tsk->thread.pfault_wait = 0;
725
			list_del(&tsk->thread.list);
L
Linus Torvalds 已提交
726
			wake_up_process(tsk);
727
			put_task_struct(tsk);
728 729 730
		} else {
			/* Completion interrupt was faster than initial
			 * interrupt. Set pfault_wait to -1 so the initial
731 732 733 734 735 736 737
			 * interrupt doesn't put the task to sleep.
			 * If the task is not running, ignore the completion
			 * interrupt since it must be a leftover of a PFAULT
			 * CANCEL operation which didn't remove all pending
			 * completion interrupts. */
			if (tsk->state == TASK_RUNNING)
				tsk->thread.pfault_wait = -1;
L
Linus Torvalds 已提交
738 739 740
		}
	} else {
		/* signal bit not set -> a real page is missing. */
H
Heiko Carstens 已提交
741 742
		if (WARN_ON_ONCE(tsk != current))
			goto out;
743 744
		if (tsk->thread.pfault_wait == 1) {
			/* Already on the list with a reference: put to sleep */
745
			goto block;
746
		} else if (tsk->thread.pfault_wait == -1) {
L
Linus Torvalds 已提交
747
			/* Completion interrupt was faster than the initial
748 749
			 * interrupt (pfault_wait == -1). Set pfault_wait
			 * back to zero and exit. */
L
Linus Torvalds 已提交
750
			tsk->thread.pfault_wait = 0;
751 752
		} else {
			/* Initial interrupt arrived before completion
753 754 755 756 757
			 * interrupt. Let the task sleep.
			 * An extra task reference is needed since a different
			 * cpu may set the task state to TASK_RUNNING again
			 * before the scheduler is reached. */
			get_task_struct(tsk);
758 759
			tsk->thread.pfault_wait = 1;
			list_add(&tsk->thread.list, &pfault_list);
760 761 762 763 764
block:
			/* Since this must be a userspace fault, there
			 * is no kernel task state to trample. Rely on the
			 * return to userspace schedule() to block. */
			__set_current_state(TASK_UNINTERRUPTIBLE);
L
Linus Torvalds 已提交
765
			set_tsk_need_resched(tsk);
766
			set_preempt_need_resched();
767 768
		}
	}
H
Heiko Carstens 已提交
769
out:
770
	spin_unlock(&pfault_lock);
771
	put_task_struct(tsk);
772 773
}

774
static int pfault_cpu_dead(unsigned int cpu)
775 776 777 778
{
	struct thread_struct *thread, *next;
	struct task_struct *tsk;

779 780 781 782 783 784 785
	spin_lock_irq(&pfault_lock);
	list_for_each_entry_safe(thread, next, &pfault_list, list) {
		thread->pfault_wait = 0;
		list_del(&thread->list);
		tsk = container_of(thread, struct task_struct, thread);
		wake_up_process(tsk);
		put_task_struct(tsk);
L
Linus Torvalds 已提交
786
	}
787 788
	spin_unlock_irq(&pfault_lock);
	return 0;
L
Linus Torvalds 已提交
789 790
}

791
static int __init pfault_irq_init(void)
H
Heiko Carstens 已提交
792
{
793
	int rc;
H
Heiko Carstens 已提交
794

795
	rc = register_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
796 797 798 799 800
	if (rc)
		goto out_extint;
	rc = pfault_init() == 0 ? 0 : -EOPNOTSUPP;
	if (rc)
		goto out_pfault;
801
	irq_subclass_register(IRQ_SUBCLASS_SERVICE_SIGNAL);
802 803
	cpuhp_setup_state_nocalls(CPUHP_S390_PFAULT_DEAD, "s390/pfault:dead",
				  NULL, pfault_cpu_dead);
H
Heiko Carstens 已提交
804
	return 0;
H
Heiko Carstens 已提交
805

H
Heiko Carstens 已提交
806
out_pfault:
807
	unregister_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
808 809 810
out_extint:
	pfault_disable = 1;
	return rc;
H
Heiko Carstens 已提交
811
}
812 813
early_initcall(pfault_irq_init);

H
Heiko Carstens 已提交
814
#endif /* CONFIG_PFAULT */
815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891

#if IS_ENABLED(CONFIG_PGSTE)
void do_secure_storage_access(struct pt_regs *regs)
{
	unsigned long addr = regs->int_parm_long & __FAIL_ADDR_MASK;
	struct vm_area_struct *vma;
	struct mm_struct *mm;
	struct page *page;
	int rc;

	switch (get_fault_type(regs)) {
	case USER_FAULT:
		mm = current->mm;
		down_read(&mm->mmap_sem);
		vma = find_vma(mm, addr);
		if (!vma) {
			up_read(&mm->mmap_sem);
			do_fault_error(regs, VM_READ | VM_WRITE, VM_FAULT_BADMAP);
			break;
		}
		page = follow_page(vma, addr, FOLL_WRITE | FOLL_GET);
		if (IS_ERR_OR_NULL(page)) {
			up_read(&mm->mmap_sem);
			break;
		}
		if (arch_make_page_accessible(page))
			send_sig(SIGSEGV, current, 0);
		put_page(page);
		up_read(&mm->mmap_sem);
		break;
	case KERNEL_FAULT:
		page = phys_to_page(addr);
		if (unlikely(!try_get_page(page)))
			break;
		rc = arch_make_page_accessible(page);
		put_page(page);
		if (rc)
			BUG();
		break;
	case VDSO_FAULT:
		/* fallthrough */
	case GMAP_FAULT:
		/* fallthrough */
	default:
		do_fault_error(regs, VM_READ | VM_WRITE, VM_FAULT_BADMAP);
		WARN_ON_ONCE(1);
	}
}
NOKPROBE_SYMBOL(do_secure_storage_access);

void do_non_secure_storage_access(struct pt_regs *regs)
{
	unsigned long gaddr = regs->int_parm_long & __FAIL_ADDR_MASK;
	struct gmap *gmap = (struct gmap *)S390_lowcore.gmap;

	if (get_fault_type(regs) != GMAP_FAULT) {
		do_fault_error(regs, VM_READ | VM_WRITE, VM_FAULT_BADMAP);
		WARN_ON_ONCE(1);
		return;
	}

	if (gmap_convert_to_secure(gmap, gaddr) == -EINVAL)
		send_sig(SIGSEGV, current, 0);
}
NOKPROBE_SYMBOL(do_non_secure_storage_access);

#else
void do_secure_storage_access(struct pt_regs *regs)
{
	default_trap_handler(regs);
}

void do_non_secure_storage_access(struct pt_regs *regs)
{
	default_trap_handler(regs);
}
#endif