enlighten.c 45.8 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13
/*
 * Core of Xen paravirt_ops implementation.
 *
 * This file contains the xen_paravirt_ops structure itself, and the
 * implementations for:
 * - privileged instructions
 * - interrupt flags
 * - segment operations
 * - booting and setup
 *
 * Jeremy Fitzhardinge <jeremy@xensource.com>, XenSource Inc, 2007
 */

14
#include <linux/cpu.h>
15 16 17 18
#include <linux/kernel.h>
#include <linux/init.h>
#include <linux/smp.h>
#include <linux/preempt.h>
19
#include <linux/hardirq.h>
20 21 22 23
#include <linux/percpu.h>
#include <linux/delay.h>
#include <linux/start_kernel.h>
#include <linux/sched.h>
24
#include <linux/kprobes.h>
25 26
#include <linux/bootmem.h>
#include <linux/module.h>
27 28 29
#include <linux/mm.h>
#include <linux/page-flags.h>
#include <linux/highmem.h>
30
#include <linux/console.h>
C
Chris Wright 已提交
31
#include <linux/pci.h>
32
#include <linux/gfp.h>
33
#include <linux/memblock.h>
34
#include <linux/edd.h>
35

36
#include <xen/xen.h>
37
#include <xen/events.h>
38
#include <xen/interface/xen.h>
39
#include <xen/interface/version.h>
40 41
#include <xen/interface/physdev.h>
#include <xen/interface/vcpu.h>
42
#include <xen/interface/memory.h>
43
#include <xen/interface/nmi.h>
44
#include <xen/interface/xen-mca.h>
45 46
#include <xen/features.h>
#include <xen/page.h>
47
#include <xen/hvm.h>
J
Jeremy Fitzhardinge 已提交
48
#include <xen/hvc-console.h>
49
#include <xen/acpi.h>
50 51

#include <asm/paravirt.h>
I
Ingo Molnar 已提交
52
#include <asm/apic.h>
53
#include <asm/page.h>
54
#include <asm/xen/pci.h>
55 56 57 58
#include <asm/xen/hypercall.h>
#include <asm/xen/hypervisor.h>
#include <asm/fixmap.h>
#include <asm/processor.h>
59
#include <asm/proto.h>
60
#include <asm/msr-index.h>
61
#include <asm/traps.h>
62 63
#include <asm/setup.h>
#include <asm/desc.h>
64
#include <asm/pgalloc.h>
65
#include <asm/pgtable.h>
J
Jeremy Fitzhardinge 已提交
66
#include <asm/tlbflush.h>
J
Jeremy Fitzhardinge 已提交
67
#include <asm/reboot.h>
68
#include <asm/stackprotector.h>
69
#include <asm/hypervisor.h>
70
#include <asm/mach_traps.h>
71
#include <asm/mwait.h>
72
#include <asm/pci_x86.h>
73
#include <asm/pat.h>
74 75 76 77 78 79 80 81

#ifdef CONFIG_ACPI
#include <linux/acpi.h>
#include <asm/acpi.h>
#include <acpi/pdc_intel.h>
#include <acpi/processor.h>
#include <xen/interface/platform.h>
#endif
82 83

#include "xen-ops.h"
J
Jeremy Fitzhardinge 已提交
84
#include "mmu.h"
B
Ben Guthro 已提交
85
#include "smp.h"
86
#include "multicalls.h"
87
#include "pmu.h"
88 89 90

EXPORT_SYMBOL_GPL(hypercall_page);

91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106
/*
 * Pointer to the xen_vcpu_info structure or
 * &HYPERVISOR_shared_info->vcpu_info[cpu]. See xen_hvm_init_shared_info
 * and xen_vcpu_setup for details. By default it points to share_info->vcpu_info
 * but if the hypervisor supports VCPUOP_register_vcpu_info then it can point
 * to xen_vcpu_info. The pointer is used in __xen_evtchn_do_upcall to
 * acknowledge pending events.
 * Also more subtly it is used by the patched version of irq enable/disable
 * e.g. xen_irq_enable_direct and xen_iret in PV mode.
 *
 * The desire to be able to do those mask/unmask operations as a single
 * instruction by using the per-cpu offset held in %gs is the real reason
 * vcpu info is in a per-cpu pointer and the original reason for this
 * hypercall.
 *
 */
107
DEFINE_PER_CPU(struct vcpu_info *, xen_vcpu);
108 109 110 111 112 113

/*
 * Per CPU pages used if hypervisor supports VCPUOP_register_vcpu_info
 * hypercall. This can be used both in PV and PVHVM mode. The structure
 * overrides the default per_cpu(xen_vcpu, cpu) value.
 */
114
DEFINE_PER_CPU(struct vcpu_info, xen_vcpu_info);
115

116 117 118
enum xen_domain_type xen_domain_type = XEN_NATIVE;
EXPORT_SYMBOL_GPL(xen_domain_type);

119 120
unsigned long *machine_to_phys_mapping = (void *)MACH2PHYS_VIRT_START;
EXPORT_SYMBOL(machine_to_phys_mapping);
121 122
unsigned long  machine_to_phys_nr;
EXPORT_SYMBOL(machine_to_phys_nr);
123

124 125 126
struct start_info *xen_start_info;
EXPORT_SYMBOL_GPL(xen_start_info);

127
struct shared_info xen_dummy_shared_info;
128

129 130
void *xen_initial_gdt;

131
RESERVE_BRK(shared_info_page_brk, PAGE_SIZE);
132 133
__read_mostly int xen_have_vector_callback;
EXPORT_SYMBOL_GPL(xen_have_vector_callback);
134

135 136 137 138
/*
 * Point at some empty memory to start with. We map the real shared_info
 * page as soon as fixmap is up and running.
 */
139
struct shared_info *HYPERVISOR_shared_info = &xen_dummy_shared_info;
140 141 142 143 144 145 146 147 148 149 150 151 152 153

/*
 * Flag to determine whether vcpu info placement is available on all
 * VCPUs.  We assume it is to start with, and then set it to zero on
 * the first failure.  This is because it can succeed on some VCPUs
 * and not others, since it can involve hypervisor memory allocation,
 * or because the guest failed to guarantee all the appropriate
 * constraints on all VCPUs (ie buffer can't cross a page boundary).
 *
 * Note that any particular CPU may be using a placed vcpu structure,
 * but we can only optimise if the all are.
 *
 * 0: not available, 1: available
 */
154
static int have_vcpu_info_placement = 1;
155

156 157 158 159 160 161 162 163 164 165 166 167 168
struct tls_descs {
	struct desc_struct desc[3];
};

/*
 * Updating the 3 TLS descriptors in the GDT on every task switch is
 * surprisingly expensive so we avoid updating them if they haven't
 * changed.  Since Xen writes different descriptors than the one
 * passed in the update_descriptor hypercall we keep shadow copies to
 * compare against.
 */
static DEFINE_PER_CPU(struct tls_descs, shadow_tls_desc);

169 170 171 172 173 174 175 176
static void clamp_max_cpus(void)
{
#ifdef CONFIG_SMP
	if (setup_max_cpus > MAX_VIRT_CPUS)
		setup_max_cpus = MAX_VIRT_CPUS;
#endif
}

177
static void xen_vcpu_setup(int cpu)
178
{
179 180 181 182
	struct vcpu_register_vcpu_info info;
	int err;
	struct vcpu_info *vcpup;

183
	BUG_ON(HYPERVISOR_shared_info == &xen_dummy_shared_info);
184

185 186 187 188 189 190 191 192 193 194 195 196 197 198 199
	/*
	 * This path is called twice on PVHVM - first during bootup via
	 * smp_init -> xen_hvm_cpu_notify, and then if the VCPU is being
	 * hotplugged: cpu_up -> xen_hvm_cpu_notify.
	 * As we can only do the VCPUOP_register_vcpu_info once lets
	 * not over-write its result.
	 *
	 * For PV it is called during restore (xen_vcpu_restore) and bootup
	 * (xen_setup_vcpu_info_placement). The hotplug mechanism does not
	 * use this function.
	 */
	if (xen_hvm_domain()) {
		if (per_cpu(xen_vcpu, cpu) == &per_cpu(xen_vcpu_info, cpu))
			return;
	}
200 201
	if (cpu < MAX_VIRT_CPUS)
		per_cpu(xen_vcpu,cpu) = &HYPERVISOR_shared_info->vcpu_info[cpu];
202

203 204 205 206 207
	if (!have_vcpu_info_placement) {
		if (cpu >= MAX_VIRT_CPUS)
			clamp_max_cpus();
		return;
	}
208

209
	vcpup = &per_cpu(xen_vcpu_info, cpu);
210
	info.mfn = arbitrary_virt_to_mfn(vcpup);
211 212 213 214
	info.offset = offset_in_page(vcpup);

	/* Check to see if the hypervisor will put the vcpu_info
	   structure where we want it, which allows direct access via
215 216 217 218 219 220
	   a percpu-variable.
	   N.B. This hypercall can _only_ be called once per CPU. Subsequent
	   calls will error out with -EINVAL. This is due to the fact that
	   hypervisor has no unregister variant and this hypercall does not
	   allow to over-write info.mfn and info.offset.
	 */
221 222 223 224 225
	err = HYPERVISOR_vcpu_op(VCPUOP_register_vcpu_info, cpu, &info);

	if (err) {
		printk(KERN_DEBUG "register_vcpu_info failed: err=%d\n", err);
		have_vcpu_info_placement = 0;
226
		clamp_max_cpus();
227 228 229 230 231
	} else {
		/* This cpu is using the registered vcpu info, even if
		   later ones fail to. */
		per_cpu(xen_vcpu, cpu) = vcpup;
	}
232 233
}

234 235 236 237 238 239 240
/*
 * On restore, set the vcpu placement up again.
 * If it fails, then we're in a bad state, since
 * we can't back out from using it...
 */
void xen_vcpu_restore(void)
{
241
	int cpu;
242

W
Wei Liu 已提交
243
	for_each_possible_cpu(cpu) {
244
		bool other_cpu = (cpu != smp_processor_id());
W
Wei Liu 已提交
245
		bool is_up = HYPERVISOR_vcpu_op(VCPUOP_is_up, cpu, NULL);
246

W
Wei Liu 已提交
247
		if (other_cpu && is_up &&
248 249
		    HYPERVISOR_vcpu_op(VCPUOP_down, cpu, NULL))
			BUG();
250

251
		xen_setup_runstate_info(cpu);
252

253
		if (have_vcpu_info_placement)
254 255
			xen_vcpu_setup(cpu);

W
Wei Liu 已提交
256
		if (other_cpu && is_up &&
257 258
		    HYPERVISOR_vcpu_op(VCPUOP_up, cpu, NULL))
			BUG();
259 260 261
	}
}

262 263
static void __init xen_banner(void)
{
264 265 266 267
	unsigned version = HYPERVISOR_xen_version(XENVER_version, NULL);
	struct xen_extraversion extra;
	HYPERVISOR_xen_version(XENVER_extraversion, &extra);

268 269 270
	pr_info("Booting paravirtualized kernel %son %s\n",
		xen_feature(XENFEAT_auto_translated_physmap) ?
			"with PVH extensions " : "", pv_info.name);
271 272
	printk(KERN_INFO "Xen version: %d.%d%s%s\n",
	       version >> 16, version & 0xffff, extra.extraversion,
273
	       xen_feature(XENFEAT_mmu_pt_update_preserve_ad) ? " (preserve-AD)" : "");
274
}
275 276 277 278 279 280 281 282 283 284 285 286 287 288 289
/* Check if running on Xen version (major, minor) or later */
bool
xen_running_on_version_or_later(unsigned int major, unsigned int minor)
{
	unsigned int version;

	if (!xen_domain())
		return false;

	version = HYPERVISOR_xen_version(XENVER_version, NULL);
	if ((((version >> 16) == major) && ((version & 0xffff) >= minor)) ||
		((version >> 16) > major))
		return true;
	return false;
}
290

291 292 293
#define CPUID_THERM_POWER_LEAF 6
#define APERFMPERF_PRESENT 0

J
Jeremy Fitzhardinge 已提交
294 295 296
static __read_mostly unsigned int cpuid_leaf1_edx_mask = ~0;
static __read_mostly unsigned int cpuid_leaf1_ecx_mask = ~0;

297 298 299 300
static __read_mostly unsigned int cpuid_leaf1_ecx_set_mask;
static __read_mostly unsigned int cpuid_leaf5_ecx_val;
static __read_mostly unsigned int cpuid_leaf5_edx_val;

301 302
static void xen_cpuid(unsigned int *ax, unsigned int *bx,
		      unsigned int *cx, unsigned int *dx)
303
{
304
	unsigned maskebx = ~0;
J
Jeremy Fitzhardinge 已提交
305
	unsigned maskecx = ~0;
306
	unsigned maskedx = ~0;
307
	unsigned setecx = 0;
308 309 310 311
	/*
	 * Mask out inconvenient features, to try and disable as many
	 * unsupported kernel subsystems as possible.
	 */
312 313
	switch (*ax) {
	case 1:
J
Jeremy Fitzhardinge 已提交
314
		maskecx = cpuid_leaf1_ecx_mask;
315
		setecx = cpuid_leaf1_ecx_set_mask;
J
Jeremy Fitzhardinge 已提交
316
		maskedx = cpuid_leaf1_edx_mask;
317 318
		break;

319 320 321 322 323 324 325 326
	case CPUID_MWAIT_LEAF:
		/* Synthesize the values.. */
		*ax = 0;
		*bx = 0;
		*cx = cpuid_leaf5_ecx_val;
		*dx = cpuid_leaf5_edx_val;
		return;

327 328 329 330 331
	case CPUID_THERM_POWER_LEAF:
		/* Disabling APERFMPERF for kernel usage */
		maskecx = ~(1 << APERFMPERF_PRESENT);
		break;

332 333 334 335
	case 0xb:
		/* Suppress extended topology stuff */
		maskebx = 0;
		break;
J
Jeremy Fitzhardinge 已提交
336
	}
337 338

	asm(XEN_EMULATE_PREFIX "cpuid"
339 340 341 342 343
		: "=a" (*ax),
		  "=b" (*bx),
		  "=c" (*cx),
		  "=d" (*dx)
		: "0" (*ax), "2" (*cx));
J
Jeremy Fitzhardinge 已提交
344

345
	*bx &= maskebx;
J
Jeremy Fitzhardinge 已提交
346
	*cx &= maskecx;
347
	*cx |= setecx;
348
	*dx &= maskedx;
349

350 351
}

352 353
static bool __init xen_check_mwait(void)
{
354
#ifdef CONFIG_ACPI
355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374
	struct xen_platform_op op = {
		.cmd			= XENPF_set_processor_pminfo,
		.u.set_pminfo.id	= -1,
		.u.set_pminfo.type	= XEN_PM_PDC,
	};
	uint32_t buf[3];
	unsigned int ax, bx, cx, dx;
	unsigned int mwait_mask;

	/* We need to determine whether it is OK to expose the MWAIT
	 * capability to the kernel to harvest deeper than C3 states from ACPI
	 * _CST using the processor_harvest_xen.c module. For this to work, we
	 * need to gather the MWAIT_LEAF values (which the cstate.c code
	 * checks against). The hypervisor won't expose the MWAIT flag because
	 * it would break backwards compatibility; so we will find out directly
	 * from the hardware and hypercall.
	 */
	if (!xen_initial_domain())
		return false;

375 376 377 378 379 380 381
	/*
	 * When running under platform earlier than Xen4.2, do not expose
	 * mwait, to avoid the risk of loading native acpi pad driver
	 */
	if (!xen_running_on_version_or_later(4, 2))
		return false;

382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422
	ax = 1;
	cx = 0;

	native_cpuid(&ax, &bx, &cx, &dx);

	mwait_mask = (1 << (X86_FEATURE_EST % 32)) |
		     (1 << (X86_FEATURE_MWAIT % 32));

	if ((cx & mwait_mask) != mwait_mask)
		return false;

	/* We need to emulate the MWAIT_LEAF and for that we need both
	 * ecx and edx. The hypercall provides only partial information.
	 */

	ax = CPUID_MWAIT_LEAF;
	bx = 0;
	cx = 0;
	dx = 0;

	native_cpuid(&ax, &bx, &cx, &dx);

	/* Ask the Hypervisor whether to clear ACPI_PDC_C_C2C3_FFH. If so,
	 * don't expose MWAIT_LEAF and let ACPI pick the IOPORT version of C3.
	 */
	buf[0] = ACPI_PDC_REVISION_ID;
	buf[1] = 1;
	buf[2] = (ACPI_PDC_C_CAPABILITY_SMP | ACPI_PDC_EST_CAPABILITY_SWSMP);

	set_xen_guest_handle(op.u.set_pminfo.pdc, buf);

	if ((HYPERVISOR_dom0_op(&op) == 0) &&
	    (buf[2] & (ACPI_PDC_C_C1_FFH | ACPI_PDC_C_C2C3_FFH))) {
		cpuid_leaf5_ecx_val = cx;
		cpuid_leaf5_edx_val = dx;
	}
	return true;
#else
	return false;
#endif
}
423
static void __init xen_init_cpuid_mask(void)
J
Jeremy Fitzhardinge 已提交
424 425
{
	unsigned int ax, bx, cx, dx;
426
	unsigned int xsave_mask;
J
Jeremy Fitzhardinge 已提交
427 428

	cpuid_leaf1_edx_mask =
429
		~((1 << X86_FEATURE_MTRR) |  /* disable MTRR */
J
Jeremy Fitzhardinge 已提交
430 431 432 433
		  (1 << X86_FEATURE_ACC));   /* thermal monitoring */

	if (!xen_initial_domain())
		cpuid_leaf1_edx_mask &=
434
			~((1 << X86_FEATURE_ACPI));  /* disable ACPI */
Z
Zhenzhong Duan 已提交
435 436 437

	cpuid_leaf1_ecx_mask &= ~(1 << (X86_FEATURE_X2APIC % 32));

438
	ax = 1;
439
	cx = 0;
440
	cpuid(1, &ax, &bx, &cx, &dx);
J
Jeremy Fitzhardinge 已提交
441

442 443 444 445 446 447 448
	xsave_mask =
		(1 << (X86_FEATURE_XSAVE % 32)) |
		(1 << (X86_FEATURE_OSXSAVE % 32));

	/* Xen will set CR4.OSXSAVE if supported and not disabled by force */
	if ((cx & xsave_mask) != xsave_mask)
		cpuid_leaf1_ecx_mask &= ~xsave_mask; /* disable XSAVE & OSXSAVE */
449 450
	if (xen_check_mwait())
		cpuid_leaf1_ecx_set_mask = (1 << (X86_FEATURE_MWAIT % 32));
J
Jeremy Fitzhardinge 已提交
451 452
}

453 454 455 456 457 458 459 460 461 462
static void xen_set_debugreg(int reg, unsigned long val)
{
	HYPERVISOR_set_debugreg(reg, val);
}

static unsigned long xen_get_debugreg(int reg)
{
	return HYPERVISOR_get_debugreg(reg);
}

463
static void xen_end_context_switch(struct task_struct *next)
464 465
{
	xen_mc_flush();
466
	paravirt_end_context_switch(next);
467 468 469 470 471 472 473
}

static unsigned long xen_store_tr(void)
{
	return 0;
}

474
/*
475 476 477 478
 * Set the page permissions for a particular virtual address.  If the
 * address is a vmalloc mapping (or other non-linear mapping), then
 * find the linear mapping of the page and also set its protections to
 * match.
479 480 481 482 483 484 485 486
 */
static void set_aliased_prot(void *v, pgprot_t prot)
{
	int level;
	pte_t *ptep;
	pte_t pte;
	unsigned long pfn;
	struct page *page;
487
	unsigned char dummy;
488 489 490 491 492 493 494 495 496

	ptep = lookup_address((unsigned long)v, &level);
	BUG_ON(ptep == NULL);

	pfn = pte_pfn(*ptep);
	page = pfn_to_page(pfn);

	pte = pfn_pte(pfn, prot);

497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522
	/*
	 * Careful: update_va_mapping() will fail if the virtual address
	 * we're poking isn't populated in the page tables.  We don't
	 * need to worry about the direct map (that's always in the page
	 * tables), but we need to be careful about vmap space.  In
	 * particular, the top level page table can lazily propagate
	 * entries between processes, so if we've switched mms since we
	 * vmapped the target in the first place, we might not have the
	 * top-level page table entry populated.
	 *
	 * We disable preemption because we want the same mm active when
	 * we probe the target and when we issue the hypercall.  We'll
	 * have the same nominal mm, but if we're a kernel thread, lazy
	 * mm dropping could change our pgd.
	 *
	 * Out of an abundance of caution, this uses __get_user() to fault
	 * in the target address just in case there's some obscure case
	 * in which the target address isn't readable.
	 */

	preempt_disable();

	pagefault_disable();	/* Avoid warnings due to being atomic. */
	__get_user(dummy, (unsigned char __user __force *)v);
	pagefault_enable();

523 524 525 526 527 528 529 530 531 532 533
	if (HYPERVISOR_update_va_mapping((unsigned long)v, pte, 0))
		BUG();

	if (!PageHighMem(page)) {
		void *av = __va(PFN_PHYS(pfn));

		if (av != v)
			if (HYPERVISOR_update_va_mapping((unsigned long)av, pte, 0))
				BUG();
	} else
		kmap_flush_unused();
534 535

	preempt_enable();
536 537
}

538 539
static void xen_alloc_ldt(struct desc_struct *ldt, unsigned entries)
{
540
	const unsigned entries_per_page = PAGE_SIZE / LDT_ENTRY_SIZE;
541 542
	int i;

543 544 545 546 547 548 549 550 551 552 553
	/*
	 * We need to mark the all aliases of the LDT pages RO.  We
	 * don't need to call vm_flush_aliases(), though, since that's
	 * only responsible for flushing aliases out the TLBs, not the
	 * page tables, and Xen will flush the TLB for us if needed.
	 *
	 * To avoid confusing future readers: none of this is necessary
	 * to load the LDT.  The hypervisor only checks this when the
	 * LDT is faulted in due to subsequent descriptor access.
	 */

554 555
	for(i = 0; i < entries; i += entries_per_page)
		set_aliased_prot(ldt + i, PAGE_KERNEL_RO);
556 557 558 559
}

static void xen_free_ldt(struct desc_struct *ldt, unsigned entries)
{
560
	const unsigned entries_per_page = PAGE_SIZE / LDT_ENTRY_SIZE;
561 562
	int i;

563 564
	for(i = 0; i < entries; i += entries_per_page)
		set_aliased_prot(ldt + i, PAGE_KERNEL);
565 566
}

567 568 569 570 571
static void xen_set_ldt(const void *addr, unsigned entries)
{
	struct mmuext_op *op;
	struct multicall_space mcs = xen_mc_entry(sizeof(*op));

572 573
	trace_xen_cpu_set_ldt(addr, entries);

574 575
	op = mcs.args;
	op->cmd = MMUEXT_SET_LDT;
576
	op->arg1.linear_addr = (unsigned long)addr;
577 578 579 580 581 582 583
	op->arg2.nr_ents = entries;

	MULTI_mmuext_op(mcs.mc, op, 1, NULL, DOMID_SELF);

	xen_mc_issue(PARAVIRT_LAZY_CPU);
}

584
static void xen_load_gdt(const struct desc_ptr *dtr)
585 586 587 588
{
	unsigned long va = dtr->address;
	unsigned int size = dtr->size + 1;
	unsigned pages = (size + PAGE_SIZE - 1) / PAGE_SIZE;
589
	unsigned long frames[pages];
590 591
	int f;

592 593 594 595
	/*
	 * A GDT can be up to 64k in size, which corresponds to 8192
	 * 8-byte entries, or 16 4k pages..
	 */
596 597 598 599 600

	BUG_ON(size > 65536);
	BUG_ON(va & ~PAGE_MASK);

	for (f = 0; va < dtr->address + size; va += PAGE_SIZE, f++) {
J
Jeremy Fitzhardinge 已提交
601
		int level;
602
		pte_t *ptep;
J
Jeremy Fitzhardinge 已提交
603 604 605
		unsigned long pfn, mfn;
		void *virt;

606 607 608 609 610 611 612 613
		/*
		 * The GDT is per-cpu and is in the percpu data area.
		 * That can be virtually mapped, so we need to do a
		 * page-walk to get the underlying MFN for the
		 * hypercall.  The page can also be in the kernel's
		 * linear range, so we need to RO that mapping too.
		 */
		ptep = lookup_address(va, &level);
J
Jeremy Fitzhardinge 已提交
614 615 616 617 618 619 620
		BUG_ON(ptep == NULL);

		pfn = pte_pfn(*ptep);
		mfn = pfn_to_mfn(pfn);
		virt = __va(PFN_PHYS(pfn));

		frames[f] = mfn;
621

622
		make_lowmem_page_readonly((void *)va);
J
Jeremy Fitzhardinge 已提交
623
		make_lowmem_page_readonly(virt);
624 625
	}

626 627
	if (HYPERVISOR_set_gdt(frames, size / sizeof(struct desc_struct)))
		BUG();
628 629
}

630 631 632
/*
 * load_gdt for early boot, when the gdt is only mapped once
 */
633
static void __init xen_load_gdt_boot(const struct desc_ptr *dtr)
634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667
{
	unsigned long va = dtr->address;
	unsigned int size = dtr->size + 1;
	unsigned pages = (size + PAGE_SIZE - 1) / PAGE_SIZE;
	unsigned long frames[pages];
	int f;

	/*
	 * A GDT can be up to 64k in size, which corresponds to 8192
	 * 8-byte entries, or 16 4k pages..
	 */

	BUG_ON(size > 65536);
	BUG_ON(va & ~PAGE_MASK);

	for (f = 0; va < dtr->address + size; va += PAGE_SIZE, f++) {
		pte_t pte;
		unsigned long pfn, mfn;

		pfn = virt_to_pfn(va);
		mfn = pfn_to_mfn(pfn);

		pte = pfn_pte(pfn, PAGE_KERNEL_RO);

		if (HYPERVISOR_update_va_mapping((unsigned long)va, pte, 0))
			BUG();

		frames[f] = mfn;
	}

	if (HYPERVISOR_set_gdt(frames, size / sizeof(struct desc_struct)))
		BUG();
}

668 669 670 671 672 673
static inline bool desc_equal(const struct desc_struct *d1,
			      const struct desc_struct *d2)
{
	return d1->a == d2->a && d1->b == d2->b;
}

674 675 676
static void load_TLS_descriptor(struct thread_struct *t,
				unsigned int cpu, unsigned int i)
{
677 678 679 680 681 682 683 684 685 686 687 688 689
	struct desc_struct *shadow = &per_cpu(shadow_tls_desc, cpu).desc[i];
	struct desc_struct *gdt;
	xmaddr_t maddr;
	struct multicall_space mc;

	if (desc_equal(shadow, &t->tls_array[i]))
		return;

	*shadow = t->tls_array[i];

	gdt = get_cpu_gdt_table(cpu);
	maddr = arbitrary_virt_to_machine(&gdt[GDT_ENTRY_TLS_MIN+i]);
	mc = __xen_mc_entry(0);
690 691 692 693 694 695

	MULTI_update_descriptor(mc.mc, maddr.maddr, t->tls_array[i]);
}

static void xen_load_tls(struct thread_struct *t, unsigned int cpu)
{
696
	/*
697 698 699 700 701 702 703 704
	 * XXX sleazy hack: If we're being called in a lazy-cpu zone
	 * and lazy gs handling is enabled, it means we're in a
	 * context switch, and %gs has just been saved.  This means we
	 * can zero it out to prevent faults on exit from the
	 * hypervisor if the next process has no %gs.  Either way, it
	 * has been saved, and the new value will get loaded properly.
	 * This will go away as soon as Xen has been modified to not
	 * save/restore %gs for normal hypercalls.
705 706 707 708 709 710 711 712
	 *
	 * On x86_64, this hack is not used for %gs, because gs points
	 * to KERNEL_GS_BASE (and uses it for PDA references), so we
	 * must not zero %gs on x86_64
	 *
	 * For x86_64, we need to zero %fs, otherwise we may get an
	 * exception between the new %fs descriptor being loaded and
	 * %fs being effectively cleared at __switch_to().
713
	 */
714 715
	if (paravirt_get_lazy_mode() == PARAVIRT_LAZY_CPU) {
#ifdef CONFIG_X86_32
716
		lazy_load_gs(0);
717 718 719 720 721 722 723 724 725 726 727 728
#else
		loadsegment(fs, 0);
#endif
	}

	xen_mc_batch();

	load_TLS_descriptor(t, cpu, 0);
	load_TLS_descriptor(t, cpu, 1);
	load_TLS_descriptor(t, cpu, 2);

	xen_mc_issue(PARAVIRT_LAZY_CPU);
729 730
}

731 732 733 734 735
#ifdef CONFIG_X86_64
static void xen_load_gs_index(unsigned int idx)
{
	if (HYPERVISOR_set_segment_base(SEGBASE_GS_USER_SEL, idx))
		BUG();
736
}
737
#endif
738 739

static void xen_write_ldt_entry(struct desc_struct *dt, int entrynum,
740
				const void *ptr)
741
{
742
	xmaddr_t mach_lp = arbitrary_virt_to_machine(&dt[entrynum]);
743
	u64 entry = *(u64 *)ptr;
744

745 746
	trace_xen_cpu_write_ldt_entry(dt, entrynum, entry);

747 748
	preempt_disable();

749 750 751
	xen_mc_flush();
	if (HYPERVISOR_update_descriptor(mach_lp.maddr, entry))
		BUG();
752 753

	preempt_enable();
754 755
}

756
static int cvt_gate_to_trap(int vector, const gate_desc *val,
757 758
			    struct trap_info *info)
{
759 760
	unsigned long addr;

761
	if (val->type != GATE_TRAP && val->type != GATE_INTERRUPT)
762 763 764
		return 0;

	info->vector = vector;
765 766 767

	addr = gate_offset(*val);
#ifdef CONFIG_X86_64
768 769 770
	/*
	 * Look for known traps using IST, and substitute them
	 * appropriately.  The debugger ones are the only ones we care
771 772
	 * about.  Xen will handle faults like double_fault,
	 * so we should never see them.  Warn if
773 774
	 * there's an unexpected IST-using fault handler.
	 */
775 776 777 778 779 780
	if (addr == (unsigned long)debug)
		addr = (unsigned long)xen_debug;
	else if (addr == (unsigned long)int3)
		addr = (unsigned long)xen_int3;
	else if (addr == (unsigned long)stack_segment)
		addr = (unsigned long)xen_stack_segment;
781
	else if (addr == (unsigned long)double_fault) {
782 783 784 785
		/* Don't need to handle these */
		return 0;
#ifdef CONFIG_X86_MCE
	} else if (addr == (unsigned long)machine_check) {
786 787 788 789 790
		/*
		 * when xen hypervisor inject vMCE to guest,
		 * use native mce handler to handle it
		 */
		;
791
#endif
792 793 794 795 796 797
	} else if (addr == (unsigned long)nmi)
		/*
		 * Use the native version as well.
		 */
		;
	else {
798 799 800 801
		/* Some other trap using IST? */
		if (WARN_ON(val->ist != 0))
			return 0;
	}
802 803 804
#endif	/* CONFIG_X86_64 */
	info->address = addr;

805 806
	info->cs = gate_segment(*val);
	info->flags = val->dpl;
807
	/* interrupt gates clear IF */
808 809
	if (val->type == GATE_INTERRUPT)
		info->flags |= 1 << 2;
810 811 812 813 814

	return 1;
}

/* Locations of each CPU's IDT */
815
static DEFINE_PER_CPU(struct desc_ptr, idt_desc);
816 817 818

/* Set an IDT entry.  If the entry is part of the current IDT, then
   also update Xen. */
819
static void xen_write_idt_entry(gate_desc *dt, int entrynum, const gate_desc *g)
820 821
{
	unsigned long p = (unsigned long)&dt[entrynum];
822 823
	unsigned long start, end;

824 825
	trace_xen_cpu_write_idt_entry(dt, entrynum, g);

826 827
	preempt_disable();

C
Christoph Lameter 已提交
828 829
	start = __this_cpu_read(idt_desc.address);
	end = start + __this_cpu_read(idt_desc.size) + 1;
830 831 832

	xen_mc_flush();

833
	native_write_idt_entry(dt, entrynum, g);
834 835 836 837 838 839

	if (p >= start && (p + 8) <= end) {
		struct trap_info info[2];

		info[1].address = 0;

840
		if (cvt_gate_to_trap(entrynum, g, &info[0]))
841 842 843
			if (HYPERVISOR_set_trap_table(info))
				BUG();
	}
844 845

	preempt_enable();
846 847
}

848
static void xen_convert_trap_info(const struct desc_ptr *desc,
J
Jeremy Fitzhardinge 已提交
849
				  struct trap_info *traps)
850 851 852
{
	unsigned in, out, count;

853
	count = (desc->size+1) / sizeof(gate_desc);
854 855 856
	BUG_ON(count > 256);

	for (in = out = 0; in < count; in++) {
857
		gate_desc *entry = (gate_desc*)(desc->address) + in;
858

859
		if (cvt_gate_to_trap(in, entry, &traps[out]))
860 861 862
			out++;
	}
	traps[out].address = 0;
J
Jeremy Fitzhardinge 已提交
863 864 865 866
}

void xen_copy_trap_info(struct trap_info *traps)
{
867
	const struct desc_ptr *desc = this_cpu_ptr(&idt_desc);
J
Jeremy Fitzhardinge 已提交
868 869 870 871 872 873 874

	xen_convert_trap_info(desc, traps);
}

/* Load a new IDT into Xen.  In principle this can be per-CPU, so we
   hold a spinlock to protect the static traps[] array (static because
   it avoids allocation, and saves stack space). */
875
static void xen_load_idt(const struct desc_ptr *desc)
J
Jeremy Fitzhardinge 已提交
876 877 878 879
{
	static DEFINE_SPINLOCK(lock);
	static struct trap_info traps[257];

880 881
	trace_xen_cpu_load_idt(desc);

J
Jeremy Fitzhardinge 已提交
882 883
	spin_lock(&lock);

884
	memcpy(this_cpu_ptr(&idt_desc), desc, sizeof(idt_desc));
885

J
Jeremy Fitzhardinge 已提交
886
	xen_convert_trap_info(desc, traps);
887 888 889 890 891 892 893 894 895 896 897

	xen_mc_flush();
	if (HYPERVISOR_set_trap_table(traps))
		BUG();

	spin_unlock(&lock);
}

/* Write a GDT descriptor entry.  Ignore LDT descriptors, since
   they're handled differently. */
static void xen_write_gdt_entry(struct desc_struct *dt, int entry,
898
				const void *desc, int type)
899
{
900 901
	trace_xen_cpu_write_gdt_entry(dt, entry, desc, type);

902 903
	preempt_disable();

904 905 906
	switch (type) {
	case DESC_LDT:
	case DESC_TSS:
907 908 909 910
		/* ignore */
		break;

	default: {
911
		xmaddr_t maddr = arbitrary_virt_to_machine(&dt[entry]);
912 913

		xen_mc_flush();
914
		if (HYPERVISOR_update_descriptor(maddr.maddr, *(u64 *)desc))
915 916 917 918
			BUG();
	}

	}
919 920

	preempt_enable();
921 922
}

923 924 925 926
/*
 * Version of write_gdt_entry for use at early boot-time needed to
 * update an entry as simply as possible.
 */
927
static void __init xen_write_gdt_entry_boot(struct desc_struct *dt, int entry,
928 929
					    const void *desc, int type)
{
930 931
	trace_xen_cpu_write_gdt_entry(dt, entry, desc, type);

932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947
	switch (type) {
	case DESC_LDT:
	case DESC_TSS:
		/* ignore */
		break;

	default: {
		xmaddr_t maddr = virt_to_machine(&dt[entry]);

		if (HYPERVISOR_update_descriptor(maddr.maddr, *(u64 *)desc))
			dt[entry] = *(struct desc_struct *)desc;
	}

	}
}

948
static void xen_load_sp0(struct tss_struct *tss,
949
			 struct thread_struct *thread)
950
{
951 952 953
	struct multicall_space mcs;

	mcs = xen_mc_entry(0);
954
	MULTI_stack_switch(mcs.mc, __KERNEL_DS, thread->sp0);
955
	xen_mc_issue(PARAVIRT_LAZY_CPU);
956
	tss->x86_tss.sp0 = thread->sp0;
957 958 959 960 961 962 963 964 965 966 967 968 969 970 971
}

static void xen_set_iopl_mask(unsigned mask)
{
	struct physdev_set_iopl set_iopl;

	/* Force the change at ring 0. */
	set_iopl.iopl = (mask == 0) ? 1 : (mask >> 12) & 3;
	HYPERVISOR_physdev_op(PHYSDEVOP_set_iopl, &set_iopl);
}

static void xen_io_delay(void)
{
}

972 973 974 975 976 977 978 979 980 981 982
static void xen_clts(void)
{
	struct multicall_space mcs;

	mcs = xen_mc_entry(0);

	MULTI_fpu_taskswitch(mcs.mc, 0);

	xen_mc_issue(PARAVIRT_LAZY_CPU);
}

983 984 985 986
static DEFINE_PER_CPU(unsigned long, xen_cr0_value);

static unsigned long xen_read_cr0(void)
{
987
	unsigned long cr0 = this_cpu_read(xen_cr0_value);
988 989 990

	if (unlikely(cr0 == 0)) {
		cr0 = native_read_cr0();
991
		this_cpu_write(xen_cr0_value, cr0);
992 993 994 995 996
	}

	return cr0;
}

997 998 999 1000
static void xen_write_cr0(unsigned long cr0)
{
	struct multicall_space mcs;

1001
	this_cpu_write(xen_cr0_value, cr0);
1002

1003 1004 1005 1006 1007 1008 1009 1010 1011
	/* Only pay attention to cr0.TS; everything else is
	   ignored. */
	mcs = xen_mc_entry(0);

	MULTI_fpu_taskswitch(mcs.mc, (cr0 & X86_CR0_TS) != 0);

	xen_mc_issue(PARAVIRT_LAZY_CPU);
}

1012 1013
static void xen_write_cr4(unsigned long cr4)
{
1014 1015 1016 1017
	cr4 &= ~X86_CR4_PGE;
	cr4 &= ~X86_CR4_PSE;

	native_write_cr4(cr4);
1018
}
1019 1020 1021 1022 1023 1024 1025 1026 1027 1028
#ifdef CONFIG_X86_64
static inline unsigned long xen_read_cr8(void)
{
	return 0;
}
static inline void xen_write_cr8(unsigned long val)
{
	BUG_ON(val);
}
#endif
1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045

static u64 xen_read_msr_safe(unsigned int msr, int *err)
{
	u64 val;

	val = native_read_msr_safe(msr, err);
	switch (msr) {
	case MSR_IA32_APICBASE:
#ifdef CONFIG_X86_X2APIC
		if (!(cpuid_ecx(1) & (1 << (X86_FEATURE_X2APIC & 31))))
#endif
			val &= ~X2APIC_ENABLE;
		break;
	}
	return val;
}

1046 1047 1048 1049 1050 1051
static int xen_write_msr_safe(unsigned int msr, unsigned low, unsigned high)
{
	int ret;

	ret = 0;

T
Tej 已提交
1052
	switch (msr) {
1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063
#ifdef CONFIG_X86_64
		unsigned which;
		u64 base;

	case MSR_FS_BASE:		which = SEGBASE_FS; goto set;
	case MSR_KERNEL_GS_BASE:	which = SEGBASE_GS_USER; goto set;
	case MSR_GS_BASE:		which = SEGBASE_GS_KERNEL; goto set;

	set:
		base = ((u64)high << 32) | low;
		if (HYPERVISOR_set_segment_base(which, base) != 0)
1064
			ret = -EIO;
1065 1066
		break;
#endif
J
Jeremy Fitzhardinge 已提交
1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077

	case MSR_STAR:
	case MSR_CSTAR:
	case MSR_LSTAR:
	case MSR_SYSCALL_MASK:
	case MSR_IA32_SYSENTER_CS:
	case MSR_IA32_SYSENTER_ESP:
	case MSR_IA32_SYSENTER_EIP:
		/* Fast syscall setup is all done in hypercalls, so
		   these are all ignored.  Stub them out here to stop
		   Xen console noise. */
J
Jeremy Fitzhardinge 已提交
1078

1079 1080 1081 1082 1083 1084 1085
	default:
		ret = native_write_msr_safe(msr, low, high);
	}

	return ret;
}

1086 1087 1088 1089 1090
unsigned long long xen_read_pmc(int counter)
{
	return 0;
}

1091
void xen_setup_shared_info(void)
1092 1093
{
	if (!xen_feature(XENFEAT_auto_translated_physmap)) {
1094 1095 1096 1097 1098
		set_fixmap(FIX_PARAVIRT_BOOTMAP,
			   xen_start_info->shared_info);

		HYPERVISOR_shared_info =
			(struct shared_info *)fix_to_virt(FIX_PARAVIRT_BOOTMAP);
1099 1100 1101 1102
	} else
		HYPERVISOR_shared_info =
			(struct shared_info *)__va(xen_start_info->shared_info);

1103 1104 1105 1106
#ifndef CONFIG_SMP
	/* In UP this is as good a place as any to set up shared info */
	xen_setup_vcpu_info_placement();
#endif
J
Jeremy Fitzhardinge 已提交
1107 1108

	xen_setup_mfn_list_list();
1109 1110
}

1111
/* This is called once we have the cpu_possible_mask */
1112
void xen_setup_vcpu_info_placement(void)
1113 1114 1115 1116 1117 1118 1119
{
	int cpu;

	for_each_possible_cpu(cpu)
		xen_vcpu_setup(cpu);

	/* xen_vcpu_setup managed to place the vcpu_info within the
1120 1121 1122
	 * percpu area for all cpus, so make use of it. Note that for
	 * PVH we want to use native IRQ mechanism. */
	if (have_vcpu_info_placement && !xen_pvh_domain()) {
1123 1124 1125 1126
		pv_irq_ops.save_fl = __PV_IS_CALLEE_SAVE(xen_save_fl_direct);
		pv_irq_ops.restore_fl = __PV_IS_CALLEE_SAVE(xen_restore_fl_direct);
		pv_irq_ops.irq_disable = __PV_IS_CALLEE_SAVE(xen_irq_disable_direct);
		pv_irq_ops.irq_enable = __PV_IS_CALLEE_SAVE(xen_irq_enable_direct);
1127
		pv_mmu_ops.read_cr2 = xen_read_cr2_direct;
1128
	}
1129 1130
}

1131 1132
static unsigned xen_patch(u8 type, u16 clobbers, void *insnbuf,
			  unsigned long addr, unsigned len)
1133 1134 1135 1136 1137 1138
{
	char *start, *end, *reloc;
	unsigned ret;

	start = end = reloc = NULL;

1139 1140
#define SITE(op, x)							\
	case PARAVIRT_PATCH(op.x):					\
1141 1142 1143 1144 1145 1146 1147 1148
	if (have_vcpu_info_placement) {					\
		start = (char *)xen_##x##_direct;			\
		end = xen_##x##_direct_end;				\
		reloc = xen_##x##_direct_reloc;				\
	}								\
	goto patch_site

	switch (type) {
1149 1150 1151 1152
		SITE(pv_irq_ops, irq_enable);
		SITE(pv_irq_ops, irq_disable);
		SITE(pv_irq_ops, save_fl);
		SITE(pv_irq_ops, restore_fl);
1153 1154 1155 1156 1157 1158
#undef SITE

	patch_site:
		if (start == NULL || (end-start) > len)
			goto default_patch;

1159
		ret = paravirt_patch_insns(insnbuf, len, start, end);
1160 1161 1162 1163 1164 1165 1166

		/* Note: because reloc is assigned from something that
		   appears to be an array, gcc assumes it's non-null,
		   but doesn't know its relationship with start and
		   end. */
		if (reloc > start && reloc < end) {
			int reloc_off = reloc - start;
1167 1168
			long *relocp = (long *)(insnbuf + reloc_off);
			long delta = start - (char *)addr;
1169 1170 1171 1172 1173 1174 1175

			*relocp += delta;
		}
		break;

	default_patch:
	default:
1176 1177
		ret = paravirt_patch_default(type, clobbers, insnbuf,
					     addr, len);
1178 1179 1180 1181 1182 1183
		break;
	}

	return ret;
}

1184
static const struct pv_info xen_info __initconst = {
1185 1186 1187
	.paravirt_enabled = 1,
	.shared_kernel_pmd = 0,

1188 1189 1190 1191
#ifdef CONFIG_X86_64
	.extra_user_64bit_cs = FLAT_USER_CS64,
#endif

1192
	.name = "Xen",
1193
};
1194

1195
static const struct pv_init_ops xen_init_ops __initconst = {
1196
	.patch = xen_patch,
1197
};
1198

1199
static const struct pv_cpu_ops xen_cpu_ops __initconst = {
1200 1201 1202 1203 1204
	.cpuid = xen_cpuid,

	.set_debugreg = xen_set_debugreg,
	.get_debugreg = xen_get_debugreg,

1205
	.clts = xen_clts,
1206

1207
	.read_cr0 = xen_read_cr0,
1208
	.write_cr0 = xen_write_cr0,
1209 1210 1211 1212 1213

	.read_cr4 = native_read_cr4,
	.read_cr4_safe = native_read_cr4_safe,
	.write_cr4 = xen_write_cr4,

1214 1215 1216 1217 1218
#ifdef CONFIG_X86_64
	.read_cr8 = xen_read_cr8,
	.write_cr8 = xen_write_cr8,
#endif

1219 1220
	.wbinvd = native_wbinvd,

1221
	.read_msr = xen_read_msr_safe,
1222
	.write_msr = xen_write_msr_safe,
1223

1224
	.read_tsc = native_read_tsc,
1225
	.read_pmc = xen_read_pmc,
1226

1227 1228
	.read_tscp = native_read_tscp,

1229
	.iret = xen_iret,
1230 1231 1232
#ifdef CONFIG_X86_64
	.usergs_sysret32 = xen_sysret32,
	.usergs_sysret64 = xen_sysret64,
1233 1234
#else
	.irq_enable_sysexit = xen_sysexit,
1235
#endif
1236 1237 1238 1239 1240 1241

	.load_tr_desc = paravirt_nop,
	.set_ldt = xen_set_ldt,
	.load_gdt = xen_load_gdt,
	.load_idt = xen_load_idt,
	.load_tls = xen_load_tls,
1242 1243 1244
#ifdef CONFIG_X86_64
	.load_gs_index = xen_load_gs_index,
#endif
1245

1246 1247 1248
	.alloc_ldt = xen_alloc_ldt,
	.free_ldt = xen_free_ldt,

1249 1250 1251 1252 1253 1254
	.store_idt = native_store_idt,
	.store_tr = xen_store_tr,

	.write_ldt_entry = xen_write_ldt_entry,
	.write_gdt_entry = xen_write_gdt_entry,
	.write_idt_entry = xen_write_idt_entry,
1255
	.load_sp0 = xen_load_sp0,
1256 1257 1258 1259

	.set_iopl_mask = xen_set_iopl_mask,
	.io_delay = xen_io_delay,

J
Jeremy Fitzhardinge 已提交
1260 1261 1262
	/* Xen takes care of %gs when switching to usermode for us */
	.swapgs = paravirt_nop,

1263 1264
	.start_context_switch = paravirt_start_context_switch,
	.end_context_switch = xen_end_context_switch,
1265 1266
};

1267
static const struct pv_apic_ops xen_apic_ops __initconst = {
1268 1269 1270
#ifdef CONFIG_X86_LOCAL_APIC
	.startup_ipi_hook = paravirt_nop,
#endif
1271 1272
};

J
Jeremy Fitzhardinge 已提交
1273 1274
static void xen_reboot(int reason)
{
J
Jeremy Fitzhardinge 已提交
1275
	struct sched_shutdown r = { .reason = reason };
1276 1277 1278 1279
	int cpu;

	for_each_online_cpu(cpu)
		xen_pmu_finish(cpu);
J
Jeremy Fitzhardinge 已提交
1280 1281

	if (HYPERVISOR_sched_op(SCHEDOP_shutdown, &r))
J
Jeremy Fitzhardinge 已提交
1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299
		BUG();
}

static void xen_restart(char *msg)
{
	xen_reboot(SHUTDOWN_reboot);
}

static void xen_emergency_restart(void)
{
	xen_reboot(SHUTDOWN_reboot);
}

static void xen_machine_halt(void)
{
	xen_reboot(SHUTDOWN_poweroff);
}

1300 1301 1302 1303 1304 1305 1306
static void xen_machine_power_off(void)
{
	if (pm_power_off)
		pm_power_off();
	xen_reboot(SHUTDOWN_poweroff);
}

J
Jeremy Fitzhardinge 已提交
1307 1308 1309 1310 1311
static void xen_crash_shutdown(struct pt_regs *regs)
{
	xen_reboot(SHUTDOWN_crash);
}

1312 1313 1314
static int
xen_panic_event(struct notifier_block *this, unsigned long event, void *ptr)
{
1315
	xen_reboot(SHUTDOWN_crash);
1316 1317 1318 1319 1320
	return NOTIFY_DONE;
}

static struct notifier_block xen_panic_block = {
	.notifier_call= xen_panic_event,
1321
	.priority = INT_MIN
1322 1323 1324 1325 1326 1327 1328 1329
};

int xen_panic_handler_init(void)
{
	atomic_notifier_chain_register(&panic_notifier_list, &xen_panic_block);
	return 0;
}

1330
static const struct machine_ops xen_machine_ops __initconst = {
J
Jeremy Fitzhardinge 已提交
1331 1332
	.restart = xen_restart,
	.halt = xen_machine_halt,
1333
	.power_off = xen_machine_power_off,
J
Jeremy Fitzhardinge 已提交
1334 1335 1336 1337 1338
	.shutdown = xen_machine_halt,
	.crash_shutdown = xen_crash_shutdown,
	.emergency_restart = xen_emergency_restart,
};

1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353
static unsigned char xen_get_nmi_reason(void)
{
	unsigned char reason = 0;

	/* Construct a value which looks like it came from port 0x61. */
	if (test_bit(_XEN_NMIREASON_io_error,
		     &HYPERVISOR_shared_info->arch.nmi_reason))
		reason |= NMI_REASON_IOCHK;
	if (test_bit(_XEN_NMIREASON_pci_serr,
		     &HYPERVISOR_shared_info->arch.nmi_reason))
		reason |= NMI_REASON_SERR;

	return reason;
}

1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402
static void __init xen_boot_params_init_edd(void)
{
#if IS_ENABLED(CONFIG_EDD)
	struct xen_platform_op op;
	struct edd_info *edd_info;
	u32 *mbr_signature;
	unsigned nr;
	int ret;

	edd_info = boot_params.eddbuf;
	mbr_signature = boot_params.edd_mbr_sig_buffer;

	op.cmd = XENPF_firmware_info;

	op.u.firmware_info.type = XEN_FW_DISK_INFO;
	for (nr = 0; nr < EDDMAXNR; nr++) {
		struct edd_info *info = edd_info + nr;

		op.u.firmware_info.index = nr;
		info->params.length = sizeof(info->params);
		set_xen_guest_handle(op.u.firmware_info.u.disk_info.edd_params,
				     &info->params);
		ret = HYPERVISOR_dom0_op(&op);
		if (ret)
			break;

#define C(x) info->x = op.u.firmware_info.u.disk_info.x
		C(device);
		C(version);
		C(interface_support);
		C(legacy_max_cylinder);
		C(legacy_max_head);
		C(legacy_sectors_per_track);
#undef C
	}
	boot_params.eddbuf_entries = nr;

	op.u.firmware_info.type = XEN_FW_DISK_MBR_SIGNATURE;
	for (nr = 0; nr < EDD_MBR_SIG_MAX; nr++) {
		op.u.firmware_info.index = nr;
		ret = HYPERVISOR_dom0_op(&op);
		if (ret)
			break;
		mbr_signature[nr] = op.u.firmware_info.u.disk_mbr_signature.mbr_signature;
	}
	boot_params.edd_mbr_sig_buf_entries = nr;
#endif
}

1403 1404 1405 1406
/*
 * Set up the GDT and segment registers for -fstack-protector.  Until
 * we do this, we have to be careful not to call any stack-protected
 * function, which is most of the kernel.
1407 1408 1409 1410
 *
 * Note, that it is __ref because the only caller of this after init
 * is PVH which is not going to use xen_load_gdt_boot or other
 * __init functions.
1411
 */
1412
static void __ref xen_setup_gdt(int cpu)
1413
{
1414 1415 1416 1417
	if (xen_feature(XENFEAT_auto_translated_physmap)) {
#ifdef CONFIG_X86_64
		unsigned long dummy;

1418 1419
		load_percpu_segment(cpu); /* We need to access per-cpu area */
		switch_to_new_gdt(cpu); /* GDT and GS set */
1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449

		/* We are switching of the Xen provided GDT to our HVM mode
		 * GDT. The new GDT has  __KERNEL_CS with CS.L = 1
		 * and we are jumping to reload it.
		 */
		asm volatile ("pushq %0\n"
			      "leaq 1f(%%rip),%0\n"
			      "pushq %0\n"
			      "lretq\n"
			      "1:\n"
			      : "=&r" (dummy) : "0" (__KERNEL_CS));

		/*
		 * While not needed, we also set the %es, %ds, and %fs
		 * to zero. We don't care about %ss as it is NULL.
		 * Strictly speaking this is not needed as Xen zeros those
		 * out (and also MSR_FS_BASE, MSR_GS_BASE, MSR_KERNEL_GS_BASE)
		 *
		 * Linux zeros them in cpu_init() and in secondary_startup_64
		 * (for BSP).
		 */
		loadsegment(es, 0);
		loadsegment(ds, 0);
		loadsegment(fs, 0);
#else
		/* PVH: TODO Implement. */
		BUG();
#endif
		return; /* PVH does not need any PV GDT ops. */
	}
1450 1451 1452 1453 1454 1455 1456 1457 1458 1459
	pv_cpu_ops.write_gdt_entry = xen_write_gdt_entry_boot;
	pv_cpu_ops.load_gdt = xen_load_gdt_boot;

	setup_stack_canary_segment(0);
	switch_to_new_gdt(0);

	pv_cpu_ops.write_gdt_entry = xen_write_gdt_entry;
	pv_cpu_ops.load_gdt = xen_load_gdt;
}

1460
#ifdef CONFIG_XEN_PVH
1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471
/*
 * A PV guest starts with default flags that are not set for PVH, set them
 * here asap.
 */
static void xen_pvh_set_cr_flags(int cpu)
{

	/* Some of these are setup in 'secondary_startup_64'. The others:
	 * X86_CR0_TS, X86_CR0_PE, X86_CR0_ET are set by Xen for HVM guests
	 * (which PVH shared codepaths), while X86_CR0_PG is for PVH. */
	write_cr0(read_cr0() | X86_CR0_MP | X86_CR0_NE | X86_CR0_WP | X86_CR0_AM);
M
Mukesh Rathor 已提交
1472 1473 1474 1475 1476

	if (!cpu)
		return;
	/*
	 * For BSP, PSE PGE are set in probe_page_size_mask(), for APs
I
Ingo Molnar 已提交
1477
	 * set them here. For all, OSFXSR OSXMMEXCPT are set in fpu__init_cpu().
M
Mukesh Rathor 已提交
1478 1479
	*/
	if (cpu_has_pse)
A
Andy Lutomirski 已提交
1480
		cr4_set_bits_and_update_boot(X86_CR4_PSE);
M
Mukesh Rathor 已提交
1481 1482

	if (cpu_has_pge)
A
Andy Lutomirski 已提交
1483
		cr4_set_bits_and_update_boot(X86_CR4_PGE);
1484 1485 1486 1487 1488 1489 1490 1491 1492 1493 1494 1495 1496
}

/*
 * Note, that it is ref - because the only caller of this after init
 * is PVH which is not going to use xen_load_gdt_boot or other
 * __init functions.
 */
void __ref xen_pvh_secondary_vcpu_init(int cpu)
{
	xen_setup_gdt(cpu);
	xen_pvh_set_cr_flags(cpu);
}

1497 1498 1499 1500 1501
static void __init xen_pvh_early_guest_init(void)
{
	if (!xen_feature(XENFEAT_auto_translated_physmap))
		return;

1502 1503 1504 1505
	if (!xen_feature(XENFEAT_hvm_callback_vector))
		return;

	xen_have_vector_callback = 1;
1506 1507

	xen_pvh_early_cpu_init(0, false);
1508
	xen_pvh_set_cr_flags(0);
1509 1510 1511 1512 1513

#ifdef CONFIG_X86_32
	BUG(); /* PVH: Implement proper support. */
#endif
}
1514
#endif    /* CONFIG_XEN_PVH */
1515

1516
/* First C function to be called on Xen boot */
1517
asmlinkage __visible void __init xen_start_kernel(void)
1518
{
1519
	struct physdev_set_iopl set_iopl;
1520
	unsigned long initrd_start = 0;
1521
	u64 pat;
1522
	int rc;
1523 1524 1525 1526

	if (!xen_start_info)
		return;

1527 1528
	xen_domain_type = XEN_PV_DOMAIN;

1529
	xen_setup_features();
1530
#ifdef CONFIG_XEN_PVH
1531
	xen_pvh_early_guest_init();
1532
#endif
1533 1534
	xen_setup_machphys_mapping();

1535
	/* Install Xen paravirt ops */
1536 1537 1538
	pv_info = xen_info;
	pv_init_ops = xen_init_ops;
	pv_apic_ops = xen_apic_ops;
1539
	if (!xen_pvh_domain()) {
1540
		pv_cpu_ops = xen_cpu_ops;
1541

1542 1543 1544
		x86_platform.get_nmi_reason = xen_get_nmi_reason;
	}

1545 1546 1547 1548
	if (xen_feature(XENFEAT_auto_translated_physmap))
		x86_init.resources.memory_setup = xen_auto_xlated_memory_setup;
	else
		x86_init.resources.memory_setup = xen_memory_setup;
1549
	x86_init.oem.arch_setup = xen_arch_setup;
1550
	x86_init.oem.banner = xen_banner;
1551

1552
	xen_init_time_ops();
1553

1554
	/*
1555
	 * Set up some pagetable state before starting to set any ptes.
1556
	 */
1557

1558 1559
	xen_init_mmu_ops();

1560 1561 1562
	/* Prevent unwanted bits from being set in PTEs. */
	__supported_pte_mask &= ~_PAGE_GLOBAL;

1563 1564 1565 1566 1567 1568
	/*
	 * Prevent page tables from being allocated in highmem, even
	 * if CONFIG_HIGHPTE is enabled.
	 */
	__userpte_alloc_gfp &= ~__GFP_HIGHMEM;

1569
	/* Work out if we support NX */
1570
	x86_configure_nx();
1571

1572
	/* Get mfn list */
1573
	xen_build_dynamic_phys_to_machine();
1574 1575 1576 1577 1578

	/*
	 * Set up kernel GDT and segment registers, mainly so that
	 * -fstack-protector code can be executed.
	 */
1579
	xen_setup_gdt(0);
1580

1581
	xen_init_irq_ops();
J
Jeremy Fitzhardinge 已提交
1582 1583
	xen_init_cpuid_mask();

1584
#ifdef CONFIG_X86_LOCAL_APIC
1585
	/*
1586
	 * set up the basic apic ops.
1587
	 */
1588
	xen_init_apic();
1589
#endif
1590

1591 1592 1593 1594 1595
	if (xen_feature(XENFEAT_mmu_pt_update_preserve_ad)) {
		pv_mmu_ops.ptep_modify_prot_start = xen_ptep_modify_prot_start;
		pv_mmu_ops.ptep_modify_prot_commit = xen_ptep_modify_prot_commit;
	}

J
Jeremy Fitzhardinge 已提交
1596 1597
	machine_ops = xen_machine_ops;

1598 1599 1600 1601 1602 1603
	/*
	 * The only reliable way to retain the initial address of the
	 * percpu gdt_page is to remember it here, so we can go and
	 * mark it RW later, when the initial percpu area is freed.
	 */
	xen_initial_gdt = &per_cpu(gdt_page, 0);
1604

1605
	xen_smp_init();
1606

1607 1608 1609 1610 1611 1612 1613
#ifdef CONFIG_ACPI_NUMA
	/*
	 * The pages we from Xen are not related to machine pages, so
	 * any NUMA information the kernel tries to get from ACPI will
	 * be meaningless.  Prevent it from trying.
	 */
	acpi_numa = -1;
1614
#endif
1615
	/* Don't do the full vcpu_info placement stuff until we have a
1616
	   possible map and a non-dummy shared_info. */
1617
	per_cpu(xen_vcpu, 0) = &HYPERVISOR_shared_info->vcpu_info[0];
1618

1619
	local_irq_disable();
1620
	early_boot_irqs_disabled = true;
1621

J
Jeremy Fitzhardinge 已提交
1622
	xen_raw_console_write("mapping kernel into physical memory\n");
1623 1624 1625
	xen_setup_kernel_pagetable((pgd_t *)xen_start_info->pt_base,
				   xen_start_info->nr_pages);
	xen_reserve_special_pages();
1626

1627 1628 1629 1630
	/*
	 * Modify the cache mode translation tables to match Xen's PAT
	 * configuration.
	 */
1631 1632
	rdmsrl(MSR_IA32_CR_PAT, pat);
	pat_init_cache_modes(pat);
1633

1634 1635
	/* keep using Xen gdt for now; no urgent need to change it */

1636
#ifdef CONFIG_X86_32
1637
	pv_info.kernel_rpl = 1;
1638
	if (xen_feature(XENFEAT_supervisor_mode_kernel))
1639
		pv_info.kernel_rpl = 0;
1640 1641 1642
#else
	pv_info.kernel_rpl = 0;
#endif
1643
	/* set the limit of our address space */
1644
	xen_reserve_top();
1645

1646 1647 1648 1649 1650 1651 1652 1653 1654 1655 1656 1657
	/* PVH: runs at default kernel iopl of 0 */
	if (!xen_pvh_domain()) {
		/*
		 * We used to do this in xen_arch_setup, but that is too late
		 * on AMD were early_cpu_init (run before ->arch_setup()) calls
		 * early_amd_init which pokes 0xcf8 port.
		 */
		set_iopl.iopl = 1;
		rc = HYPERVISOR_physdev_op(PHYSDEVOP_set_iopl, &set_iopl);
		if (rc != 0)
			xen_raw_printk("physdev_op failed %d\n", rc);
	}
1658

1659
#ifdef CONFIG_X86_32
1660 1661
	/* set up basic CPUID stuff */
	cpu_detect(&new_cpu_data);
1662
	set_cpu_cap(&new_cpu_data, X86_FEATURE_FPU);
1663
	new_cpu_data.wp_works_ok = 1;
1664
	new_cpu_data.x86_capability[0] = cpuid_edx(1);
1665
#endif
1666

1667 1668 1669 1670 1671 1672 1673
	if (xen_start_info->mod_start) {
	    if (xen_start_info->flags & SIF_MOD_START_PFN)
		initrd_start = PFN_PHYS(xen_start_info->mod_start);
	    else
		initrd_start = __pa(xen_start_info->mod_start);
	}

1674
	/* Poke various useful things into boot_params */
1675
	boot_params.hdr.type_of_loader = (9 << 4) | 0;
1676
	boot_params.hdr.ramdisk_image = initrd_start;
1677
	boot_params.hdr.ramdisk_size = xen_start_info->mod_len;
1678
	boot_params.hdr.cmd_line_ptr = __pa(xen_start_info->cmd_line);
1679

1680
	if (!xen_initial_domain()) {
1681
		add_preferred_console("xenboot", 0, NULL);
1682
		add_preferred_console("tty", 0, NULL);
1683
		add_preferred_console("hvc", 0, NULL);
1684 1685
		if (pci_xen)
			x86_init.pci.arch_init = pci_xen_init;
C
Chris Wright 已提交
1686
	} else {
1687 1688 1689
		const struct dom0_vga_console_info *info =
			(void *)((char *)xen_start_info +
				 xen_start_info->console.dom0.info_off);
1690 1691 1692 1693 1694
		struct xen_platform_op op = {
			.cmd = XENPF_firmware_info,
			.interface_version = XENPF_INTERFACE_VERSION,
			.u.firmware_info.type = XEN_FW_KBD_SHIFT_FLAGS,
		};
1695 1696 1697 1698 1699

		xen_init_vga(info, xen_start_info->console.dom0.info_size);
		xen_start_info->console.domU.mfn = 0;
		xen_start_info->console.domU.evtchn = 0;

1700 1701 1702
		if (HYPERVISOR_dom0_op(&op) == 0)
			boot_params.kbd_status = op.u.firmware_info.u.kbd_shift_flags;

C
Chris Wright 已提交
1703 1704
		/* Make sure ACS will be enabled */
		pci_request_acs();
1705 1706

		xen_acpi_sleep_register();
1707 1708 1709 1710

		/* Avoid searching for BIOS MP tables */
		x86_init.mpparse.find_smp_config = x86_init_noop;
		x86_init.mpparse.get_smp_config = x86_init_uint_noop;
1711 1712

		xen_boot_params_init_edd();
1713
	}
1714 1715 1716 1717
#ifdef CONFIG_PCI
	/* PCI BIOS service won't work from a PV guest. */
	pci_probe &= ~PCI_PROBE_BIOS;
#endif
J
Jeremy Fitzhardinge 已提交
1718 1719
	xen_raw_console_write("about to get started...\n");

1720 1721
	xen_setup_runstate_info(0);

1722
	xen_efi_init();
D
Daniel Kiper 已提交
1723

1724
	/* Start the world */
1725
#ifdef CONFIG_X86_32
1726
	i386_start_kernel();
1727
#else
1728
	cr4_init_shadow(); /* 32b kernel does this in i386_start_kernel() */
J
Jeremy Fitzhardinge 已提交
1729
	x86_64_start_reservations((char *)__pa_symbol(&boot_params));
1730
#endif
1731
}
1732

1733
void __ref xen_hvm_init_shared_info(void)
1734
{
1735
	int cpu;
1736
	struct xen_add_to_physmap xatp;
1737
	static struct shared_info *shared_info_page = 0;
1738

1739 1740 1741
	if (!shared_info_page)
		shared_info_page = (struct shared_info *)
			extend_brk(PAGE_SIZE, PAGE_SIZE);
1742 1743 1744
	xatp.domid = DOMID_SELF;
	xatp.idx = 0;
	xatp.space = XENMAPSPACE_shared_info;
1745
	xatp.gpfn = __pa(shared_info_page) >> PAGE_SHIFT;
1746 1747 1748
	if (HYPERVISOR_memory_op(XENMEM_add_to_physmap, &xatp))
		BUG();

1749
	HYPERVISOR_shared_info = (struct shared_info *)shared_info_page;
1750

1751 1752 1753 1754
	/* xen_vcpu is a pointer to the vcpu_info struct in the shared_info
	 * page, we use it in the event channel upcall and in some pvclock
	 * related functions. We don't need the vcpu_info placement
	 * optimizations because we don't use any pv_mmu or pv_irq op on
1755 1756 1757 1758 1759
	 * HVM.
	 * When xen_hvm_init_shared_info is run at boot time only vcpu 0 is
	 * online but xen_hvm_init_shared_info is run at resume time too and
	 * in that case multiple vcpus might be online. */
	for_each_online_cpu(cpu) {
1760 1761 1762
		/* Leave it to be NULL. */
		if (cpu >= MAX_VIRT_CPUS)
			continue;
1763 1764
		per_cpu(xen_vcpu, cpu) = &HYPERVISOR_shared_info->vcpu_info[cpu];
	}
1765 1766
}

1767
#ifdef CONFIG_XEN_PVHVM
O
Olaf Hering 已提交
1768 1769
static void __init init_hvm_pv_info(void)
{
1770
	int major, minor;
1771
	uint32_t eax, ebx, ecx, edx, pages, msr, base;
O
Olaf Hering 已提交
1772 1773 1774
	u64 pfn;

	base = xen_cpuid_base();
1775 1776 1777 1778 1779 1780
	cpuid(base + 1, &eax, &ebx, &ecx, &edx);

	major = eax >> 16;
	minor = eax & 0xffff;
	printk(KERN_INFO "Xen version %d.%d.\n", major, minor);

O
Olaf Hering 已提交
1781 1782 1783 1784 1785 1786 1787 1788 1789 1790 1791 1792
	cpuid(base + 2, &pages, &msr, &ecx, &edx);

	pfn = __pa(hypercall_page);
	wrmsr_safe(msr, (u32)pfn, (u32)(pfn >> 32));

	xen_setup_features();

	pv_info.name = "Xen HVM";

	xen_domain_type = XEN_HVM_DOMAIN;
}

1793 1794
static int xen_hvm_cpu_notify(struct notifier_block *self, unsigned long action,
			      void *hcpu)
1795 1796 1797 1798
{
	int cpu = (long)hcpu;
	switch (action) {
	case CPU_UP_PREPARE:
1799
		xen_vcpu_setup(cpu);
1800 1801 1802 1803
		if (xen_have_vector_callback) {
			if (xen_feature(XENFEAT_hvm_safe_pvclock))
				xen_setup_timer(cpu);
		}
1804 1805 1806 1807 1808 1809 1810
		break;
	default:
		break;
	}
	return NOTIFY_OK;
}

1811
static struct notifier_block xen_hvm_cpu_notifier = {
1812 1813 1814
	.notifier_call	= xen_hvm_cpu_notify,
};

1815 1816
static void __init xen_hvm_guest_init(void)
{
1817 1818 1819
	if (xen_pv_domain())
		return;

O
Olaf Hering 已提交
1820
	init_hvm_pv_info();
1821

1822
	xen_hvm_init_shared_info();
1823

1824 1825
	xen_panic_handler_init();

1826 1827
	if (xen_feature(XENFEAT_hvm_callback_vector))
		xen_have_vector_callback = 1;
1828
	xen_hvm_smp_init();
1829
	register_cpu_notifier(&xen_hvm_cpu_notifier);
1830
	xen_unplug_emulated_devices();
1831
	x86_init.irqs.intr_init = xen_init_IRQ;
1832
	xen_hvm_init_time_ops();
1833
	xen_hvm_init_mmu_ops();
1834
}
1835
#endif
1836

1837 1838 1839 1840 1841 1842 1843 1844
static bool xen_nopv = false;
static __init int xen_parse_nopv(char *arg)
{
       xen_nopv = true;
       return 0;
}
early_param("xen_nopv", xen_parse_nopv);

1845
static uint32_t __init xen_platform(void)
1846
{
1847 1848 1849
	if (xen_nopv)
		return 0;

J
Jason Wang 已提交
1850
	return xen_cpuid_base();
1851 1852
}

S
Sheng Yang 已提交
1853 1854
bool xen_hvm_need_lapic(void)
{
1855 1856
	if (xen_nopv)
		return false;
S
Sheng Yang 已提交
1857 1858 1859 1860 1861 1862 1863 1864 1865 1866
	if (xen_pv_domain())
		return false;
	if (!xen_hvm_domain())
		return false;
	if (xen_feature(XENFEAT_hvm_pirqs) && xen_have_vector_callback)
		return false;
	return true;
}
EXPORT_SYMBOL_GPL(xen_hvm_need_lapic);

1867 1868 1869 1870 1871 1872 1873 1874 1875 1876
static void xen_set_cpu_features(struct cpuinfo_x86 *c)
{
	if (xen_pv_domain())
		clear_cpu_bug(c, X86_BUG_SYSRET_SS_ATTRS);
}

const struct hypervisor_x86 x86_hyper_xen = {
	.name			= "Xen",
	.detect			= xen_platform,
#ifdef CONFIG_XEN_PVHVM
1877
	.init_platform		= xen_hvm_guest_init,
1878
#endif
1879
	.x2apic_available	= xen_x2apic_para_available,
1880
	.set_cpu_features       = xen_set_cpu_features,
1881
};
1882
EXPORT_SYMBOL(x86_hyper_xen);