fault.c 18.8 KB
Newer Older
L
Linus Torvalds 已提交
1 2
/*
 *  S390 version
3
 *    Copyright IBM Corp. 1999
L
Linus Torvalds 已提交
4 5 6 7 8 9 10
 *    Author(s): Hartmut Penner (hp@de.ibm.com)
 *               Ulrich Weigand (uweigand@de.ibm.com)
 *
 *  Derived from "arch/i386/mm/fault.c"
 *    Copyright (C) 1995  Linus Torvalds
 */

11
#include <linux/kernel_stat.h>
12
#include <linux/perf_event.h>
L
Linus Torvalds 已提交
13 14 15 16 17 18 19 20 21
#include <linux/signal.h>
#include <linux/sched.h>
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/string.h>
#include <linux/types.h>
#include <linux/ptrace.h>
#include <linux/mman.h>
#include <linux/mm.h>
H
Heiko Carstens 已提交
22
#include <linux/compat.h>
L
Linus Torvalds 已提交
23
#include <linux/smp.h>
24
#include <linux/kdebug.h>
L
Linus Torvalds 已提交
25 26 27 28
#include <linux/init.h>
#include <linux/console.h>
#include <linux/module.h>
#include <linux/hardirq.h>
M
Michael Grundy 已提交
29
#include <linux/kprobes.h>
30
#include <linux/uaccess.h>
31
#include <linux/hugetlb.h>
32
#include <asm/asm-offsets.h>
L
Linus Torvalds 已提交
33
#include <asm/pgtable.h>
34
#include <asm/irq.h>
M
Martin Schwidefsky 已提交
35
#include <asm/mmu_context.h>
36
#include <asm/facility.h>
37
#include "../kernel/entry.h"
L
Linus Torvalds 已提交
38 39 40 41 42

#define __FAIL_ADDR_MASK -4096L
#define __SUBCODE_MASK 0x0600
#define __PF_RES_FIELD 0x8000000000000000ULL

43 44 45
#define VM_FAULT_BADCONTEXT	0x010000
#define VM_FAULT_BADMAP		0x020000
#define VM_FAULT_BADACCESS	0x040000
46
#define VM_FAULT_SIGNAL		0x080000
47
#define VM_FAULT_PFAULT		0x100000
48

49
static unsigned long store_indication __read_mostly;
50

51
static int __init fault_init(void)
52
{
53
	if (test_facility(75))
54
		store_indication = 0xc00;
55
	return 0;
56
}
57
early_initcall(fault_init);
58

59
static inline int notify_page_fault(struct pt_regs *regs)
60
{
61 62 63
	int ret = 0;

	/* kprobe_running() needs smp_processor_id() */
64
	if (kprobes_built_in() && !user_mode(regs)) {
65 66 67 68 69 70
		preempt_disable();
		if (kprobe_running() && kprobe_fault_handler(regs, 14))
			ret = 1;
		preempt_enable();
	}
	return ret;
M
Michael Grundy 已提交
71 72
}

L
Linus Torvalds 已提交
73 74 75

/*
 * Unlock any spinlocks which will prevent us from getting the
76
 * message out.
L
Linus Torvalds 已提交
77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97
 */
void bust_spinlocks(int yes)
{
	if (yes) {
		oops_in_progress = 1;
	} else {
		int loglevel_save = console_loglevel;
		console_unblank();
		oops_in_progress = 0;
		/*
		 * OK, the message is on the console.  Now we call printk()
		 * without oops_in_progress set so that printk will give klogd
		 * a poke.  Hold onto your hats...
		 */
		console_loglevel = 15;
		printk(" ");
		console_loglevel = loglevel_save;
	}
}

/*
98
 * Returns the address space associated with the fault.
99
 * Returns 0 for kernel space and 1 for user space.
L
Linus Torvalds 已提交
100
 */
101
static inline int user_space_fault(struct pt_regs *regs)
L
Linus Torvalds 已提交
102
{
103 104
	unsigned long trans_exc_code;

L
Linus Torvalds 已提交
105
	/*
106 107
	 * The lowest two bits of the translation exception
	 * identification indicate which paging table was used.
L
Linus Torvalds 已提交
108
	 */
109 110 111 112 113 114
	trans_exc_code = regs->int_parm_long & 3;
	if (trans_exc_code == 3) /* home space -> kernel */
		return 0;
	if (user_mode(regs))
		return 1;
	if (trans_exc_code == 2) /* secondary space -> set_fs */
115
		return current->thread.mm_segment.ar4;
116 117 118
	if (current->flags & PF_VCPU)
		return 1;
	return 0;
L
Linus Torvalds 已提交
119 120
}

121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164
static int bad_address(void *p)
{
	unsigned long dummy;

	return probe_kernel_address((unsigned long *)p, dummy);
}

static void dump_pagetable(unsigned long asce, unsigned long address)
{
	unsigned long *table = __va(asce & PAGE_MASK);

	pr_alert("AS:%016lx ", asce);
	switch (asce & _ASCE_TYPE_MASK) {
	case _ASCE_TYPE_REGION1:
		table = table + ((address >> 53) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R1:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION2:
		table = table + ((address >> 42) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R2:%016lx ", *table);
		if (*table & _REGION_ENTRY_INVALID)
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_REGION3:
		table = table + ((address >> 31) & 0x7ff);
		if (bad_address(table))
			goto bad;
		pr_cont("R3:%016lx ", *table);
		if (*table & (_REGION_ENTRY_INVALID | _REGION3_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _REGION_ENTRY_ORIGIN);
		/* fallthrough */
	case _ASCE_TYPE_SEGMENT:
		table = table + ((address >> 20) & 0x7ff);
		if (bad_address(table))
			goto bad;
J
Joe Perches 已提交
165
		pr_cont("S:%016lx ", *table);
166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219
		if (*table & (_SEGMENT_ENTRY_INVALID | _SEGMENT_ENTRY_LARGE))
			goto out;
		table = (unsigned long *)(*table & _SEGMENT_ENTRY_ORIGIN);
	}
	table = table + ((address >> 12) & 0xff);
	if (bad_address(table))
		goto bad;
	pr_cont("P:%016lx ", *table);
out:
	pr_cont("\n");
	return;
bad:
	pr_cont("BAD\n");
}

static void dump_fault_info(struct pt_regs *regs)
{
	unsigned long asce;

	pr_alert("Fault in ");
	switch (regs->int_parm_long & 3) {
	case 3:
		pr_cont("home space ");
		break;
	case 2:
		pr_cont("secondary space ");
		break;
	case 1:
		pr_cont("access register ");
		break;
	case 0:
		pr_cont("primary space ");
		break;
	}
	pr_cont("mode while using ");
	if (!user_space_fault(regs)) {
		asce = S390_lowcore.kernel_asce;
		pr_cont("kernel ");
	}
#ifdef CONFIG_PGSTE
	else if ((current->flags & PF_VCPU) && S390_lowcore.gmap) {
		struct gmap *gmap = (struct gmap *)S390_lowcore.gmap;
		asce = gmap->asce;
		pr_cont("gmap ");
	}
#endif
	else {
		asce = S390_lowcore.user_asce;
		pr_cont("user ");
	}
	pr_cont("ASCE.\n");
	dump_pagetable(asce, regs->int_parm_long & __FAIL_ADDR_MASK);
}

M
Martin Schwidefsky 已提交
220
static inline void report_user_fault(struct pt_regs *regs, long signr)
221 222 223 224 225 226 227
{
	if ((task_pid_nr(current) > 1) && !show_unhandled_signals)
		return;
	if (!unhandled_signal(current, signr))
		return;
	if (!printk_ratelimit())
		return;
228
	printk(KERN_ALERT "User process fault: interruption code %04x ilc:%d ",
229
	       regs->int_code & 0xffff, regs->int_code >> 17);
230
	print_vma_addr(KERN_CONT "in ", regs->psw.addr & PSW_ADDR_INSN);
M
Martin Schwidefsky 已提交
231
	printk(KERN_CONT "\n");
232 233 234
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
235 236 237
	show_regs(regs);
}

L
Linus Torvalds 已提交
238 239 240 241
/*
 * Send SIGSEGV to task.  This is an external routine
 * to keep the stack usage of do_page_fault small.
 */
M
Martin Schwidefsky 已提交
242
static noinline void do_sigsegv(struct pt_regs *regs, int si_code)
L
Linus Torvalds 已提交
243 244 245
{
	struct siginfo si;

M
Martin Schwidefsky 已提交
246
	report_user_fault(regs, SIGSEGV);
L
Linus Torvalds 已提交
247 248
	si.si_signo = SIGSEGV;
	si.si_code = si_code;
M
Martin Schwidefsky 已提交
249
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
L
Linus Torvalds 已提交
250 251 252
	force_sig_info(SIGSEGV, &si, current);
}

M
Martin Schwidefsky 已提交
253
static noinline void do_no_context(struct pt_regs *regs)
254 255
{
	const struct exception_table_entry *fixup;
256
	unsigned long address;
257 258

	/* Are we prepared to handle this kernel fault?  */
259
	fixup = search_exception_tables(regs->psw.addr & PSW_ADDR_INSN);
260
	if (fixup) {
261
		regs->psw.addr = extable_fixup(fixup) | PSW_ADDR_AMODE;
262 263 264 265 266 267 268
		return;
	}

	/*
	 * Oops. The kernel tried to access some bad page. We'll have to
	 * terminate things with extreme prejudice.
	 */
M
Martin Schwidefsky 已提交
269
	address = regs->int_parm_long & __FAIL_ADDR_MASK;
270
	if (!user_space_fault(regs))
271
		printk(KERN_ALERT "Unable to handle kernel pointer dereference"
272
		       " in virtual kernel address space\n");
273 274
	else
		printk(KERN_ALERT "Unable to handle kernel paging request"
275 276 277 278
		       " in virtual user address space\n");
	printk(KERN_ALERT "failing address: %016lx TEID: %016lx\n",
	       regs->int_parm_long & __FAIL_ADDR_MASK, regs->int_parm_long);
	dump_fault_info(regs);
M
Martin Schwidefsky 已提交
279
	die(regs, "Oops");
280 281 282
	do_exit(SIGKILL);
}

M
Martin Schwidefsky 已提交
283
static noinline void do_low_address(struct pt_regs *regs)
284 285 286 287 288
{
	/* Low-address protection hit in kernel mode means
	   NULL pointer write access in kernel mode.  */
	if (regs->psw.mask & PSW_MASK_PSTATE) {
		/* Low-address protection hit in user mode 'cannot happen'. */
M
Martin Schwidefsky 已提交
289
		die (regs, "Low-address protection");
290 291 292
		do_exit(SIGKILL);
	}

M
Martin Schwidefsky 已提交
293
	do_no_context(regs);
294 295
}

M
Martin Schwidefsky 已提交
296
static noinline void do_sigbus(struct pt_regs *regs)
297 298
{
	struct task_struct *tsk = current;
M
Martin Schwidefsky 已提交
299
	struct siginfo si;
300 301 302 303 304

	/*
	 * Send a sigbus, regardless of whether we were in kernel
	 * or user mode.
	 */
M
Martin Schwidefsky 已提交
305 306 307
	si.si_signo = SIGBUS;
	si.si_errno = 0;
	si.si_code = BUS_ADRERR;
M
Martin Schwidefsky 已提交
308
	si.si_addr = (void __user *)(regs->int_parm_long & __FAIL_ADDR_MASK);
M
Martin Schwidefsky 已提交
309
	force_sig_info(SIGBUS, &si, tsk);
310 311
}

M
Martin Schwidefsky 已提交
312
static noinline void do_fault_error(struct pt_regs *regs, int fault)
313 314 315 316 317 318 319
{
	int si_code;

	switch (fault) {
	case VM_FAULT_BADACCESS:
	case VM_FAULT_BADMAP:
		/* Bad memory access. Check if it is kernel or user space. */
320
		if (user_mode(regs)) {
321 322 323
			/* User mode accesses just cause a SIGSEGV */
			si_code = (fault == VM_FAULT_BADMAP) ?
				SEGV_MAPERR : SEGV_ACCERR;
M
Martin Schwidefsky 已提交
324
			do_sigsegv(regs, si_code);
325 326 327
			return;
		}
	case VM_FAULT_BADCONTEXT:
328
	case VM_FAULT_PFAULT:
M
Martin Schwidefsky 已提交
329
		do_no_context(regs);
330
		break;
331 332 333 334
	case VM_FAULT_SIGNAL:
		if (!user_mode(regs))
			do_no_context(regs);
		break;
335
	default: /* fault & VM_FAULT_ERROR */
336
		if (fault & VM_FAULT_OOM) {
337
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
338
				do_no_context(regs);
339 340
			else
				pagefault_out_of_memory();
341 342 343 344 345 346
		} else if (fault & VM_FAULT_SIGSEGV) {
			/* Kernel mode? Handle exceptions or die */
			if (!user_mode(regs))
				do_no_context(regs);
			else
				do_sigsegv(regs, SEGV_MAPERR);
347
		} else if (fault & VM_FAULT_SIGBUS) {
348
			/* Kernel mode? Handle exceptions or die */
349
			if (!user_mode(regs))
M
Martin Schwidefsky 已提交
350
				do_no_context(regs);
M
Martin Schwidefsky 已提交
351
			else
M
Martin Schwidefsky 已提交
352
				do_sigbus(regs);
353 354 355 356 357 358
		} else
			BUG();
		break;
	}
}

L
Linus Torvalds 已提交
359 360 361 362 363
/*
 * This routine handles page faults.  It determines the address,
 * and the problem, and then passes it off to one of the appropriate
 * routines.
 *
364
 * interruption code (int_code):
L
Linus Torvalds 已提交
365 366 367 368 369
 *   04       Protection           ->  Write-Protection  (suprression)
 *   10       Segment translation  ->  Not present       (nullification)
 *   11       Page translation     ->  Not present       (nullification)
 *   3b       Region third trans.  ->  Not present       (nullification)
 */
M
Martin Schwidefsky 已提交
370
static inline int do_exception(struct pt_regs *regs, int access)
L
Linus Torvalds 已提交
371
{
372 373 374
#ifdef CONFIG_PGSTE
	struct gmap *gmap;
#endif
375 376 377
	struct task_struct *tsk;
	struct mm_struct *mm;
	struct vm_area_struct *vma;
M
Martin Schwidefsky 已提交
378
	unsigned long trans_exc_code;
379
	unsigned long address;
380 381
	unsigned int flags;
	int fault;
L
Linus Torvalds 已提交
382

383 384 385 386 387
	tsk = current;
	/*
	 * The instruction that caused the program check has
	 * been nullified. Don't signal single step via SIGTRAP.
	 */
388
	clear_pt_regs_flag(regs, PIF_PER_TRAP);
389

390
	if (notify_page_fault(regs))
391
		return 0;
M
Michael Grundy 已提交
392

393
	mm = tsk->mm;
M
Martin Schwidefsky 已提交
394
	trans_exc_code = regs->int_parm_long;
L
Linus Torvalds 已提交
395 396 397 398 399 400

	/*
	 * Verify that the fault happened in user space, that
	 * we are not in an interrupt and that there is a 
	 * user context.
	 */
401
	fault = VM_FAULT_BADCONTEXT;
402
	if (unlikely(!user_space_fault(regs) || in_atomic() || !mm))
403
		goto out;
L
Linus Torvalds 已提交
404

405
	address = trans_exc_code & __FAIL_ADDR_MASK;
406
	perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS, 1, regs, address);
407
	flags = FAULT_FLAG_ALLOW_RETRY | FAULT_FLAG_KILLABLE;
408 409
	if (user_mode(regs))
		flags |= FAULT_FLAG_USER;
410 411
	if (access == VM_WRITE || (trans_exc_code & store_indication) == 0x400)
		flags |= FAULT_FLAG_WRITE;
412
	down_read(&mm->mmap_sem);
L
Linus Torvalds 已提交
413

414
#ifdef CONFIG_PGSTE
415 416
	gmap = (current->flags & PF_VCPU) ?
		(struct gmap *) S390_lowcore.gmap : NULL;
417
	if (gmap) {
418 419
		current->thread.gmap_addr = address;
		address = __gmap_translate(gmap, address);
420 421 422 423
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
424 425
		if (gmap->pfault_enabled)
			flags |= FAULT_FLAG_RETRY_NOWAIT;
426 427 428 429
	}
#endif

retry:
430
	fault = VM_FAULT_BADMAP;
431 432
	vma = find_vma(mm, address);
	if (!vma)
433
		goto out_up;
G
Gerald Schaefer 已提交
434

435 436 437 438 439 440 441 442 443 444 445 446
	if (unlikely(vma->vm_start > address)) {
		if (!(vma->vm_flags & VM_GROWSDOWN))
			goto out_up;
		if (expand_stack(vma, address))
			goto out_up;
	}

	/*
	 * Ok, we have a good vm_area for this memory access, so
	 * we can handle it..
	 */
	fault = VM_FAULT_BADACCESS;
447
	if (unlikely(!(vma->vm_flags & access)))
448
		goto out_up;
L
Linus Torvalds 已提交
449

450 451
	if (is_vm_hugetlb_page(vma))
		address &= HPAGE_MASK;
L
Linus Torvalds 已提交
452 453 454 455 456
	/*
	 * If for any reason at all we couldn't handle the fault,
	 * make sure we exit gracefully rather than endlessly redo
	 * the fault.
	 */
457
	fault = handle_mm_fault(mm, vma, address, flags);
458 459 460 461 462
	/* No reason to continue if interrupted by SIGKILL. */
	if ((fault & VM_FAULT_RETRY) && fatal_signal_pending(current)) {
		fault = VM_FAULT_SIGNAL;
		goto out;
	}
463 464 465
	if (unlikely(fault & VM_FAULT_ERROR))
		goto out_up;

466 467 468 469 470 471 472 473
	/*
	 * Major/minor page fault accounting is only done on the
	 * initial attempt. If we go through a retry, it is extremely
	 * likely that the page will be found in page cache at that point.
	 */
	if (flags & FAULT_FLAG_ALLOW_RETRY) {
		if (fault & VM_FAULT_MAJOR) {
			tsk->maj_flt++;
474
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MAJ, 1,
475 476 477
				      regs, address);
		} else {
			tsk->min_flt++;
478
			perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS_MIN, 1,
479 480 481
				      regs, address);
		}
		if (fault & VM_FAULT_RETRY) {
482 483 484 485 486 487 488 489 490
#ifdef CONFIG_PGSTE
			if (gmap && (flags & FAULT_FLAG_RETRY_NOWAIT)) {
				/* FAULT_FLAG_RETRY_NOWAIT has been set,
				 * mmap_sem has not been released */
				current->thread.gmap_pfault = 1;
				fault = VM_FAULT_PFAULT;
				goto out_up;
			}
#endif
491 492
			/* Clear FAULT_FLAG_ALLOW_RETRY to avoid any risk
			 * of starvation. */
493 494
			flags &= ~(FAULT_FLAG_ALLOW_RETRY |
				   FAULT_FLAG_RETRY_NOWAIT);
495
			flags |= FAULT_FLAG_TRIED;
496
			down_read(&mm->mmap_sem);
497 498
			goto retry;
		}
499
	}
500 501 502 503 504 505 506 507 508 509 510 511 512 513
#ifdef CONFIG_PGSTE
	if (gmap) {
		address =  __gmap_link(gmap, current->thread.gmap_addr,
				       address);
		if (address == -EFAULT) {
			fault = VM_FAULT_BADMAP;
			goto out_up;
		}
		if (address == -ENOMEM) {
			fault = VM_FAULT_OOM;
			goto out_up;
		}
	}
#endif
514 515
	fault = 0;
out_up:
516
	up_read(&mm->mmap_sem);
517 518
out:
	return fault;
L
Linus Torvalds 已提交
519 520
}

521
void do_protection_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
522
{
M
Martin Schwidefsky 已提交
523
	unsigned long trans_exc_code;
524
	int fault;
525

M
Martin Schwidefsky 已提交
526
	trans_exc_code = regs->int_parm_long;
527 528 529 530 531 532 533
	/*
	 * Protection exceptions are suppressing, decrement psw address.
	 * The exception to this rule are aborted transactions, for these
	 * the PSW already points to the correct location.
	 */
	if (!(regs->int_code & 0x200))
		regs->psw.addr = __rewind_psw(regs->psw, regs->int_code >> 16);
534 535 536 537 538
	/*
	 * Check for low-address protection.  This needs to be treated
	 * as a special case because the translation exception code
	 * field is not guaranteed to contain valid data in this case.
	 */
539
	if (unlikely(!(trans_exc_code & 4))) {
M
Martin Schwidefsky 已提交
540
		do_low_address(regs);
541 542
		return;
	}
M
Martin Schwidefsky 已提交
543
	fault = do_exception(regs, VM_WRITE);
544
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
545
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
546
}
547
NOKPROBE_SYMBOL(do_protection_exception);
L
Linus Torvalds 已提交
548

549
void do_dat_exception(struct pt_regs *regs)
L
Linus Torvalds 已提交
550
{
551
	int access, fault;
552

553
	access = VM_READ | VM_EXEC | VM_WRITE;
M
Martin Schwidefsky 已提交
554
	fault = do_exception(regs, access);
555
	if (unlikely(fault))
M
Martin Schwidefsky 已提交
556
		do_fault_error(regs, fault);
L
Linus Torvalds 已提交
557
}
558
NOKPROBE_SYMBOL(do_dat_exception);
L
Linus Torvalds 已提交
559 560 561 562 563

#ifdef CONFIG_PFAULT 
/*
 * 'pfault' pseudo page faults routines.
 */
564
static int pfault_disable;
L
Linus Torvalds 已提交
565 566 567 568 569 570 571 572 573

static int __init nopfault(char *str)
{
	pfault_disable = 1;
	return 1;
}

__setup("nopfault", nopfault);

H
Heiko Carstens 已提交
574 575 576 577 578 579 580 581 582 583
struct pfault_refbk {
	u16 refdiagc;
	u16 reffcode;
	u16 refdwlen;
	u16 refversn;
	u64 refgaddr;
	u64 refselmk;
	u64 refcmpmk;
	u64 reserved;
} __attribute__ ((packed, aligned(8)));
L
Linus Torvalds 已提交
584 585 586

int pfault_init(void)
{
H
Heiko Carstens 已提交
587 588 589 590 591 592 593 594 595
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 0,
		.refdwlen = 5,
		.refversn = 2,
		.refgaddr = __LC_CURRENT_PID,
		.refselmk = 1ULL << 48,
		.refcmpmk = 1ULL << 48,
		.reserved = __PF_RES_FIELD };
L
Linus Torvalds 已提交
596 597
        int rc;

598
	if (pfault_disable)
L
Linus Torvalds 已提交
599
		return -1;
600 601 602 603
	asm volatile(
		"	diag	%1,%0,0x258\n"
		"0:	j	2f\n"
		"1:	la	%0,8\n"
L
Linus Torvalds 已提交
604
		"2:\n"
605 606
		EX_TABLE(0b,1b)
		: "=d" (rc) : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
607 608 609 610 611
        return rc;
}

void pfault_fini(void)
{
H
Heiko Carstens 已提交
612 613 614 615 616 617
	struct pfault_refbk refbk = {
		.refdiagc = 0x258,
		.reffcode = 1,
		.refdwlen = 5,
		.refversn = 2,
	};
L
Linus Torvalds 已提交
618

619
	if (pfault_disable)
L
Linus Torvalds 已提交
620
		return;
621 622
	asm volatile(
		"	diag	%0,0,0x258\n"
L
Linus Torvalds 已提交
623
		"0:\n"
624 625
		EX_TABLE(0b,0b)
		: : "a" (&refbk), "m" (refbk) : "cc");
L
Linus Torvalds 已提交
626 627
}

628 629 630
static DEFINE_SPINLOCK(pfault_lock);
static LIST_HEAD(pfault_list);

631
static void pfault_interrupt(struct ext_code ext_code,
632
			     unsigned int param32, unsigned long param64)
L
Linus Torvalds 已提交
633 634 635
{
	struct task_struct *tsk;
	__u16 subcode;
636
	pid_t pid;
L
Linus Torvalds 已提交
637 638 639 640 641 642 643

	/*
	 * Get the external interruption subcode & pfault
	 * initial/completion signal bit. VM stores this 
	 * in the 'cpu address' field associated with the
         * external interrupt. 
	 */
644
	subcode = ext_code.subcode;
L
Linus Torvalds 已提交
645 646
	if ((subcode & 0xff00) != __SUBCODE_MASK)
		return;
647
	inc_irq_stat(IRQEXT_PFL);
648 649 650 651 652 653 654 655 656
	/* Get the token (= pid of the affected task). */
	pid = sizeof(void *) == 4 ? param32 : param64;
	rcu_read_lock();
	tsk = find_task_by_pid_ns(pid, &init_pid_ns);
	if (tsk)
		get_task_struct(tsk);
	rcu_read_unlock();
	if (!tsk)
		return;
657
	spin_lock(&pfault_lock);
L
Linus Torvalds 已提交
658 659
	if (subcode & 0x0080) {
		/* signal bit is set -> a page has been swapped in by VM */
660
		if (tsk->thread.pfault_wait == 1) {
L
Linus Torvalds 已提交
661 662 663 664
			/* Initial interrupt was faster than the completion
			 * interrupt. pfault_wait is valid. Set pfault_wait
			 * back to zero and wake up the process. This can
			 * safely be done because the task is still sleeping
665
			 * and can't produce new pfaults. */
L
Linus Torvalds 已提交
666
			tsk->thread.pfault_wait = 0;
667
			list_del(&tsk->thread.list);
L
Linus Torvalds 已提交
668
			wake_up_process(tsk);
669
			put_task_struct(tsk);
670 671 672
		} else {
			/* Completion interrupt was faster than initial
			 * interrupt. Set pfault_wait to -1 so the initial
673 674 675 676 677 678 679
			 * interrupt doesn't put the task to sleep.
			 * If the task is not running, ignore the completion
			 * interrupt since it must be a leftover of a PFAULT
			 * CANCEL operation which didn't remove all pending
			 * completion interrupts. */
			if (tsk->state == TASK_RUNNING)
				tsk->thread.pfault_wait = -1;
L
Linus Torvalds 已提交
680 681 682
		}
	} else {
		/* signal bit not set -> a real page is missing. */
H
Heiko Carstens 已提交
683 684
		if (WARN_ON_ONCE(tsk != current))
			goto out;
685 686
		if (tsk->thread.pfault_wait == 1) {
			/* Already on the list with a reference: put to sleep */
687
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
688 689
			set_tsk_need_resched(tsk);
		} else if (tsk->thread.pfault_wait == -1) {
L
Linus Torvalds 已提交
690
			/* Completion interrupt was faster than the initial
691 692
			 * interrupt (pfault_wait == -1). Set pfault_wait
			 * back to zero and exit. */
L
Linus Torvalds 已提交
693
			tsk->thread.pfault_wait = 0;
694 695
		} else {
			/* Initial interrupt arrived before completion
696 697 698 699 700
			 * interrupt. Let the task sleep.
			 * An extra task reference is needed since a different
			 * cpu may set the task state to TASK_RUNNING again
			 * before the scheduler is reached. */
			get_task_struct(tsk);
701 702
			tsk->thread.pfault_wait = 1;
			list_add(&tsk->thread.list, &pfault_list);
703
			__set_task_state(tsk, TASK_UNINTERRUPTIBLE);
L
Linus Torvalds 已提交
704
			set_tsk_need_resched(tsk);
705 706
		}
	}
H
Heiko Carstens 已提交
707
out:
708
	spin_unlock(&pfault_lock);
709
	put_task_struct(tsk);
710 711
}

712 713
static int pfault_cpu_notify(struct notifier_block *self, unsigned long action,
			     void *hcpu)
714 715 716 717
{
	struct thread_struct *thread, *next;
	struct task_struct *tsk;

718
	switch (action & ~CPU_TASKS_FROZEN) {
719 720 721 722 723 724 725
	case CPU_DEAD:
		spin_lock_irq(&pfault_lock);
		list_for_each_entry_safe(thread, next, &pfault_list, list) {
			thread->pfault_wait = 0;
			list_del(&thread->list);
			tsk = container_of(thread, struct task_struct, thread);
			wake_up_process(tsk);
726
			put_task_struct(tsk);
727 728 729 730 731
		}
		spin_unlock_irq(&pfault_lock);
		break;
	default:
		break;
L
Linus Torvalds 已提交
732
	}
733
	return NOTIFY_OK;
L
Linus Torvalds 已提交
734 735
}

736
static int __init pfault_irq_init(void)
H
Heiko Carstens 已提交
737
{
738
	int rc;
H
Heiko Carstens 已提交
739

740
	rc = register_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
741 742 743 744 745
	if (rc)
		goto out_extint;
	rc = pfault_init() == 0 ? 0 : -EOPNOTSUPP;
	if (rc)
		goto out_pfault;
746
	irq_subclass_register(IRQ_SUBCLASS_SERVICE_SIGNAL);
H
Heiko Carstens 已提交
747 748
	hotcpu_notifier(pfault_cpu_notify, 0);
	return 0;
H
Heiko Carstens 已提交
749

H
Heiko Carstens 已提交
750
out_pfault:
751
	unregister_external_irq(EXT_IRQ_CP_SERVICE, pfault_interrupt);
H
Heiko Carstens 已提交
752 753 754
out_extint:
	pfault_disable = 1;
	return rc;
H
Heiko Carstens 已提交
755
}
756 757
early_initcall(pfault_irq_init);

H
Heiko Carstens 已提交
758
#endif /* CONFIG_PFAULT */