mmu.c 42.9 KB
Newer Older
1
// SPDX-License-Identifier: GPL-2.0-only
C
Catalin Marinas 已提交
2 3 4 5 6 7 8
/*
 * Based on arch/arm/mm/mmu.c
 *
 * Copyright (C) 1995-2005 Russell King
 * Copyright (C) 2012 ARM Ltd.
 */

9
#include <linux/cache.h>
C
Catalin Marinas 已提交
10 11 12 13
#include <linux/export.h>
#include <linux/kernel.h>
#include <linux/errno.h>
#include <linux/init.h>
14 15
#include <linux/ioport.h>
#include <linux/kexec.h>
16
#include <linux/libfdt.h>
C
Catalin Marinas 已提交
17 18 19
#include <linux/mman.h>
#include <linux/nodemask.h>
#include <linux/memblock.h>
20
#include <linux/memory.h>
C
Catalin Marinas 已提交
21
#include <linux/fs.h>
22
#include <linux/io.h>
23
#include <linux/mm.h>
24
#include <linux/vmalloc.h>
C
Catalin Marinas 已提交
25

26
#include <asm/barrier.h>
C
Catalin Marinas 已提交
27
#include <asm/cputype.h>
28
#include <asm/fixmap.h>
29
#include <asm/kasan.h>
30
#include <asm/kernel-pgtable.h>
C
Catalin Marinas 已提交
31 32
#include <asm/sections.h>
#include <asm/setup.h>
33
#include <linux/sizes.h>
C
Catalin Marinas 已提交
34 35
#include <asm/tlb.h>
#include <asm/mmu_context.h>
36
#include <asm/ptdump.h>
37
#include <asm/tlbflush.h>
38
#include <asm/pgalloc.h>
C
Catalin Marinas 已提交
39

40
#define NO_BLOCK_MAPPINGS	BIT(0)
41
#define NO_CONT_MAPPINGS	BIT(1)
42
#define NO_EXEC_MAPPINGS	BIT(2)	/* assumes FEAT_HPDS is not used */
43

44
u64 idmap_t0sz = TCR_T0SZ(VA_BITS_MIN);
45
u64 idmap_ptrs_per_pgd = PTRS_PER_PGD;
46

47 48
u64 __section(".mmuoff.data.write") vabits_actual;
EXPORT_SYMBOL(vabits_actual);
49

50
u64 kimage_voffset __ro_after_init;
51 52
EXPORT_SYMBOL(kimage_voffset);

C
Catalin Marinas 已提交
53 54 55 56
/*
 * Empty_zero_page is a special page that is used for zero-initialized data
 * and COW.
 */
57
unsigned long empty_zero_page[PAGE_SIZE / sizeof(unsigned long)] __page_aligned_bss;
C
Catalin Marinas 已提交
58 59
EXPORT_SYMBOL(empty_zero_page);

60 61 62 63
static pte_t bm_pte[PTRS_PER_PTE] __page_aligned_bss;
static pmd_t bm_pmd[PTRS_PER_PMD] __page_aligned_bss __maybe_unused;
static pud_t bm_pud[PTRS_PER_PUD] __page_aligned_bss __maybe_unused;

64 65 66 67 68 69 70
static DEFINE_SPINLOCK(swapper_pgdir_lock);

void set_swapper_pgd(pgd_t *pgdp, pgd_t pgd)
{
	pgd_t *fixmap_pgdp;

	spin_lock(&swapper_pgdir_lock);
71
	fixmap_pgdp = pgd_set_fixmap(__pa_symbol(pgdp));
72 73 74 75 76 77 78 79 80 81
	WRITE_ONCE(*fixmap_pgdp, pgd);
	/*
	 * We need dsb(ishst) here to ensure the page-table-walker sees
	 * our new entry before set_p?d() returns. The fixmap's
	 * flush_tlb_kernel_range() via clear_fixmap() does this for us.
	 */
	pgd_clear_fixmap();
	spin_unlock(&swapper_pgdir_lock);
}

C
Catalin Marinas 已提交
82 83 84 85 86 87 88 89 90 91 92
pgprot_t phys_mem_access_prot(struct file *file, unsigned long pfn,
			      unsigned long size, pgprot_t vma_prot)
{
	if (!pfn_valid(pfn))
		return pgprot_noncached(vma_prot);
	else if (file->f_flags & O_SYNC)
		return pgprot_writecombine(vma_prot);
	return vma_prot;
}
EXPORT_SYMBOL(phys_mem_access_prot);

93
static phys_addr_t __init early_pgtable_alloc(int shift)
C
Catalin Marinas 已提交
94
{
95 96 97
	phys_addr_t phys;
	void *ptr;

98
	phys = memblock_phys_alloc(PAGE_SIZE, PAGE_SIZE);
99 100
	if (!phys)
		panic("Failed to allocate page table page\n");
101 102 103 104 105 106 107 108

	/*
	 * The FIX_{PGD,PUD,PMD} slots may be in active use, but the FIX_PTE
	 * slot will be free, so we can (ab)use the FIX_PTE slot to initialise
	 * any level of table.
	 */
	ptr = pte_set_fixmap(phys);

109 110
	memset(ptr, 0, PAGE_SIZE);

111 112 113 114 115 116 117
	/*
	 * Implicit barriers also ensure the zeroed page is visible to the page
	 * table walker
	 */
	pte_clear_fixmap();

	return phys;
C
Catalin Marinas 已提交
118 119
}

120 121 122 123 124 125
static bool pgattr_change_is_safe(u64 old, u64 new)
{
	/*
	 * The following mapping attributes may be updated in live
	 * kernel mappings without the need for break-before-make.
	 */
126
	pteval_t mask = PTE_PXN | PTE_RDONLY | PTE_WRITE | PTE_NG;
127

128 129 130 131 132 133 134 135
	/* creating or taking down mappings is always safe */
	if (old == 0 || new == 0)
		return true;

	/* live contiguous mappings may not be manipulated at all */
	if ((old | new) & PTE_CONT)
		return false;

136 137 138
	/* Transitioning from Non-Global to Global is unsafe */
	if (old & ~new & PTE_NG)
		return false;
139

140 141 142 143 144 145 146 147 148 149 150
	/*
	 * Changing the memory type between Normal and Normal-Tagged is safe
	 * since Tagged is considered a permission attribute from the
	 * mismatched attribute aliases perspective.
	 */
	if (((old & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL) ||
	     (old & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL_TAGGED)) &&
	    ((new & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL) ||
	     (new & PTE_ATTRINDX_MASK) == PTE_ATTRINDX(MT_NORMAL_TAGGED)))
		mask |= PTE_ATTRINDX_MASK;

151
	return ((old ^ new) & ~mask) == 0;
152 153
}

154
static void init_pte(pmd_t *pmdp, unsigned long addr, unsigned long end,
155
		     phys_addr_t phys, pgprot_t prot)
C
Catalin Marinas 已提交
156
{
157
	pte_t *ptep;
C
Catalin Marinas 已提交
158

159
	ptep = pte_set_fixmap_offset(pmdp, addr);
C
Catalin Marinas 已提交
160
	do {
161
		pte_t old_pte = READ_ONCE(*ptep);
162

163
		set_pte(ptep, pfn_pte(__phys_to_pfn(phys), prot));
164 165 166 167 168

		/*
		 * After the PTE entry has been populated once, we
		 * only allow updates to the permission attributes.
		 */
169 170
		BUG_ON(!pgattr_change_is_safe(pte_val(old_pte),
					      READ_ONCE(pte_val(*ptep))));
171

172
		phys += PAGE_SIZE;
173
	} while (ptep++, addr += PAGE_SIZE, addr != end);
174 175

	pte_clear_fixmap();
C
Catalin Marinas 已提交
176 177
}

178
static void alloc_init_cont_pte(pmd_t *pmdp, unsigned long addr,
179 180
				unsigned long end, phys_addr_t phys,
				pgprot_t prot,
181
				phys_addr_t (*pgtable_alloc)(int),
182
				int flags)
C
Catalin Marinas 已提交
183 184
{
	unsigned long next;
185
	pmd_t pmd = READ_ONCE(*pmdp);
C
Catalin Marinas 已提交
186

187 188
	BUG_ON(pmd_sect(pmd));
	if (pmd_none(pmd)) {
189
		pmdval_t pmdval = PMD_TYPE_TABLE | PMD_TABLE_UXN;
190
		phys_addr_t pte_phys;
191 192 193

		if (flags & NO_EXEC_MAPPINGS)
			pmdval |= PMD_TABLE_PXN;
194
		BUG_ON(!pgtable_alloc);
195
		pte_phys = pgtable_alloc(PAGE_SHIFT);
196
		__pmd_populate(pmdp, pte_phys, pmdval);
197
		pmd = READ_ONCE(*pmdp);
C
Catalin Marinas 已提交
198
	}
199
	BUG_ON(pmd_bad(pmd));
200 201 202 203 204 205 206 207 208 209 210

	do {
		pgprot_t __prot = prot;

		next = pte_cont_addr_end(addr, end);

		/* use a contiguous mapping if the range is suitably aligned */
		if ((((addr | next | phys) & ~CONT_PTE_MASK) == 0) &&
		    (flags & NO_CONT_MAPPINGS) == 0)
			__prot = __pgprot(pgprot_val(prot) | PTE_CONT);

211
		init_pte(pmdp, addr, next, phys, __prot);
212 213 214 215 216

		phys += next - addr;
	} while (addr = next, addr != end);
}

217
static void init_pmd(pud_t *pudp, unsigned long addr, unsigned long end,
218
		     phys_addr_t phys, pgprot_t prot,
219
		     phys_addr_t (*pgtable_alloc)(int), int flags)
220 221
{
	unsigned long next;
222
	pmd_t *pmdp;
C
Catalin Marinas 已提交
223

224
	pmdp = pmd_set_fixmap_offset(pudp, addr);
C
Catalin Marinas 已提交
225
	do {
226
		pmd_t old_pmd = READ_ONCE(*pmdp);
227

C
Catalin Marinas 已提交
228
		next = pmd_addr_end(addr, end);
229

C
Catalin Marinas 已提交
230
		/* try section mapping first */
231
		if (((addr | next | phys) & ~SECTION_MASK) == 0 &&
232
		    (flags & NO_BLOCK_MAPPINGS) == 0) {
233
			pmd_set_huge(pmdp, phys, prot);
234

235
			/*
236 237
			 * After the PMD entry has been populated once, we
			 * only allow updates to the permission attributes.
238
			 */
239
			BUG_ON(!pgattr_change_is_safe(pmd_val(old_pmd),
240
						      READ_ONCE(pmd_val(*pmdp))));
241
		} else {
242
			alloc_init_cont_pte(pmdp, addr, next, phys, prot,
243
					    pgtable_alloc, flags);
244 245

			BUG_ON(pmd_val(old_pmd) != 0 &&
246
			       pmd_val(old_pmd) != READ_ONCE(pmd_val(*pmdp)));
247
		}
C
Catalin Marinas 已提交
248
		phys += next - addr;
249
	} while (pmdp++, addr = next, addr != end);
250 251

	pmd_clear_fixmap();
C
Catalin Marinas 已提交
252 253
}

254
static void alloc_init_cont_pmd(pud_t *pudp, unsigned long addr,
255 256
				unsigned long end, phys_addr_t phys,
				pgprot_t prot,
257
				phys_addr_t (*pgtable_alloc)(int), int flags)
258 259
{
	unsigned long next;
260
	pud_t pud = READ_ONCE(*pudp);
261 262 263 264

	/*
	 * Check for initial section mappings in the pgd/pud.
	 */
265 266
	BUG_ON(pud_sect(pud));
	if (pud_none(pud)) {
267
		pudval_t pudval = PUD_TYPE_TABLE | PUD_TABLE_UXN;
268
		phys_addr_t pmd_phys;
269 270 271

		if (flags & NO_EXEC_MAPPINGS)
			pudval |= PUD_TABLE_PXN;
272
		BUG_ON(!pgtable_alloc);
273
		pmd_phys = pgtable_alloc(PMD_SHIFT);
274
		__pud_populate(pudp, pmd_phys, pudval);
275
		pud = READ_ONCE(*pudp);
276
	}
277
	BUG_ON(pud_bad(pud));
278 279 280 281 282 283 284 285 286 287 288

	do {
		pgprot_t __prot = prot;

		next = pmd_cont_addr_end(addr, end);

		/* use a contiguous mapping if the range is suitably aligned */
		if ((((addr | next | phys) & ~CONT_PMD_MASK) == 0) &&
		    (flags & NO_CONT_MAPPINGS) == 0)
			__prot = __pgprot(pgprot_val(prot) | PTE_CONT);

289
		init_pmd(pudp, addr, next, phys, __prot, pgtable_alloc, flags);
290 291 292 293 294

		phys += next - addr;
	} while (addr = next, addr != end);
}

295 296 297 298 299 300 301 302 303 304 305 306
static inline bool use_1G_block(unsigned long addr, unsigned long next,
			unsigned long phys)
{
	if (PAGE_SHIFT != 12)
		return false;

	if (((addr | next | phys) & ~PUD_MASK) != 0)
		return false;

	return true;
}

307 308
static void alloc_init_pud(pgd_t *pgdp, unsigned long addr, unsigned long end,
			   phys_addr_t phys, pgprot_t prot,
309
			   phys_addr_t (*pgtable_alloc)(int),
310
			   int flags)
C
Catalin Marinas 已提交
311 312
{
	unsigned long next;
313
	pud_t *pudp;
314 315
	p4d_t *p4dp = p4d_offset(pgdp, addr);
	p4d_t p4d = READ_ONCE(*p4dp);
C
Catalin Marinas 已提交
316

317
	if (p4d_none(p4d)) {
318
		p4dval_t p4dval = P4D_TYPE_TABLE | P4D_TABLE_UXN;
319
		phys_addr_t pud_phys;
320 321 322

		if (flags & NO_EXEC_MAPPINGS)
			p4dval |= P4D_TABLE_PXN;
323
		BUG_ON(!pgtable_alloc);
324
		pud_phys = pgtable_alloc(PUD_SHIFT);
325
		__p4d_populate(p4dp, pud_phys, p4dval);
326
		p4d = READ_ONCE(*p4dp);
327
	}
328
	BUG_ON(p4d_bad(p4d));
329

330
	pudp = pud_set_fixmap_offset(p4dp, addr);
C
Catalin Marinas 已提交
331
	do {
332
		pud_t old_pud = READ_ONCE(*pudp);
333

C
Catalin Marinas 已提交
334
		next = pud_addr_end(addr, end);
335 336 337 338

		/*
		 * For 4K granule only, attempt to put down a 1GB block
		 */
339 340
		if (use_1G_block(addr, next, phys) &&
		    (flags & NO_BLOCK_MAPPINGS) == 0) {
341
			pud_set_huge(pudp, phys, prot);
342 343

			/*
344 345
			 * After the PUD entry has been populated once, we
			 * only allow updates to the permission attributes.
346
			 */
347
			BUG_ON(!pgattr_change_is_safe(pud_val(old_pud),
348
						      READ_ONCE(pud_val(*pudp))));
349
		} else {
350
			alloc_init_cont_pmd(pudp, addr, next, phys, prot,
351
					    pgtable_alloc, flags);
352 353

			BUG_ON(pud_val(old_pud) != 0 &&
354
			       pud_val(old_pud) != READ_ONCE(pud_val(*pudp)));
355
		}
C
Catalin Marinas 已提交
356
		phys += next - addr;
357
	} while (pudp++, addr = next, addr != end);
358 359

	pud_clear_fixmap();
C
Catalin Marinas 已提交
360 361
}

362 363 364
static void __create_pgd_mapping(pgd_t *pgdir, phys_addr_t phys,
				 unsigned long virt, phys_addr_t size,
				 pgprot_t prot,
365
				 phys_addr_t (*pgtable_alloc)(int),
366
				 int flags)
C
Catalin Marinas 已提交
367
{
368
	unsigned long addr, end, next;
369
	pgd_t *pgdp = pgd_offset_pgd(pgdir, virt);
C
Catalin Marinas 已提交
370

371 372 373 374 375 376 377
	/*
	 * If the virtual and physical address don't have the same offset
	 * within a page, we cannot map the region as the caller expects.
	 */
	if (WARN_ON((phys ^ virt) & ~PAGE_MASK))
		return;

378
	phys &= PAGE_MASK;
C
Catalin Marinas 已提交
379
	addr = virt & PAGE_MASK;
380
	end = PAGE_ALIGN(virt + size);
C
Catalin Marinas 已提交
381 382 383

	do {
		next = pgd_addr_end(addr, end);
384
		alloc_init_pud(pgdp, addr, next, phys, prot, pgtable_alloc,
385
			       flags);
C
Catalin Marinas 已提交
386
		phys += next - addr;
387
	} while (pgdp++, addr = next, addr != end);
C
Catalin Marinas 已提交
388 389
}

390
static phys_addr_t __pgd_pgtable_alloc(int shift)
391
{
392
	void *ptr = (void *)__get_free_page(GFP_PGTABLE_KERNEL);
393 394 395 396 397 398 399
	BUG_ON(!ptr);

	/* Ensure the zeroed page is visible to the page table walker */
	dsb(ishst);
	return __pa(ptr);
}

400
static phys_addr_t pgd_pgtable_alloc(int shift)
401
{
402
	phys_addr_t pa = __pgd_pgtable_alloc(shift);
403 404 405 406 407 408 409 410 411 412

	/*
	 * Call proper page table ctor in case later we need to
	 * call core mm functions like apply_to_page_range() on
	 * this pre-allocated page table.
	 *
	 * We don't select ARCH_ENABLE_SPLIT_PMD_PTLOCK if pmd is
	 * folded, and if so pgtable_pmd_page_ctor() becomes nop.
	 */
	if (shift == PAGE_SHIFT)
413
		BUG_ON(!pgtable_pte_page_ctor(phys_to_page(pa)));
414
	else if (shift == PMD_SHIFT)
415
		BUG_ON(!pgtable_pmd_page_ctor(phys_to_page(pa)));
416

417
	return pa;
418 419
}

420 421 422 423 424 425
/*
 * This function can only be used to modify existing table entries,
 * without allocating new levels of table. Note that this permits the
 * creation of new section or page entries.
 */
static void __init create_mapping_noalloc(phys_addr_t phys, unsigned long virt,
426
				  phys_addr_t size, pgprot_t prot)
427
{
428
	if ((virt >= PAGE_END) && (virt < VMALLOC_START)) {
429 430 431 432
		pr_warn("BUG: not creating mapping for %pa at 0x%016lx - outside kernel range\n",
			&phys, virt);
		return;
	}
433 434
	__create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL,
			     NO_CONT_MAPPINGS);
435 436
}

437 438
void __init create_pgd_mapping(struct mm_struct *mm, phys_addr_t phys,
			       unsigned long virt, phys_addr_t size,
439
			       pgprot_t prot, bool page_mappings_only)
440
{
441 442
	int flags = 0;

443 444
	BUG_ON(mm == &init_mm);

445
	if (page_mappings_only)
446
		flags = NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;
447

448
	__create_pgd_mapping(mm->pgd, phys, virt, size, prot,
449
			     pgd_pgtable_alloc, flags);
450 451
}

452 453
static void update_mapping_prot(phys_addr_t phys, unsigned long virt,
				phys_addr_t size, pgprot_t prot)
454
{
455
	if ((virt >= PAGE_END) && (virt < VMALLOC_START)) {
456
		pr_warn("BUG: not updating mapping for %pa at 0x%016lx - outside kernel range\n",
457 458 459 460
			&phys, virt);
		return;
	}

461 462
	__create_pgd_mapping(init_mm.pgd, phys, virt, size, prot, NULL,
			     NO_CONT_MAPPINGS);
463 464 465

	/* flush the TLBs after updating live kernel mappings */
	flush_tlb_kernel_range(virt, virt + size);
466 467
}

468
static void __init __map_memblock(pgd_t *pgdp, phys_addr_t start,
469 470
				  phys_addr_t end, pgprot_t prot, int flags)
{
471
	__create_pgd_mapping(pgdp, start, __phys_to_virt(start), end - start,
472 473 474 475 476 477 478 479
			     prot, early_pgtable_alloc, flags);
}

void __init mark_linear_text_alias_ro(void)
{
	/*
	 * Remove the write permissions from the linear alias of .text/.rodata
	 */
480 481
	update_mapping_prot(__pa_symbol(_stext), (unsigned long)lm_alias(_stext),
			    (unsigned long)__init_begin - (unsigned long)_stext,
482 483 484
			    PAGE_KERNEL_RO);
}

485 486 487 488 489 490 491 492 493 494 495 496 497 498 499
static bool crash_mem_map __initdata;

static int __init enable_crash_mem_map(char *arg)
{
	/*
	 * Proper parameter parsing is done by reserve_crashkernel(). We only
	 * need to know if the linear map has to avoid block mappings so that
	 * the crashkernel reservations can be unmapped later.
	 */
	crash_mem_map = true;

	return 0;
}
early_param("crashkernel", enable_crash_mem_map);

500
static void __init map_mem(pgd_t *pgdp)
501
{
502
	static const u64 direct_map_end = _PAGE_END(VA_BITS_MIN);
503
	phys_addr_t kernel_start = __pa_symbol(_stext);
504
	phys_addr_t kernel_end = __pa_symbol(__init_begin);
505
	phys_addr_t start, end;
506
	int flags = NO_EXEC_MAPPINGS;
507
	u64 i;
508

509 510 511 512 513 514 515 516 517
	/*
	 * Setting hierarchical PXNTable attributes on table entries covering
	 * the linear region is only possible if it is guaranteed that no table
	 * entries at any level are being shared between the linear region and
	 * the vmalloc region. Check whether this is true for the PGD level, in
	 * which case it is guaranteed to be true for all other levels as well.
	 */
	BUILD_BUG_ON(pgd_index(direct_map_end - 1) == pgd_index(direct_map_end));

518 519
	if (rodata_full || crash_mem_map || debug_pagealloc_enabled() ||
	    IS_ENABLED(CONFIG_KFENCE))
520
		flags |= NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;
521

522
	/*
523 524
	 * Take care not to create a writable alias for the
	 * read-only text and rodata sections of the kernel image.
525 526
	 * So temporarily mark them as NOMAP to skip mappings in
	 * the following for-loop
527
	 */
528
	memblock_mark_nomap(kernel_start, kernel_end - kernel_start);
529

530
	/* map all the memory banks */
531
	for_each_mem_range(i, &start, &end) {
532 533
		if (start >= end)
			break;
534 535 536 537 538
		/*
		 * The linear map must allow allocation tags reading/writing
		 * if MTE is present. Otherwise, it has the same attributes as
		 * PAGE_KERNEL.
		 */
539 540
		__map_memblock(pgdp, start, end, pgprot_tagged(PAGE_KERNEL),
			       flags);
541
	}
542 543

	/*
544
	 * Map the linear alias of the [_stext, __init_begin) interval
545 546 547 548 549
	 * as non-executable now, and remove the write permission in
	 * mark_linear_text_alias_ro() below (which will be called after
	 * alternative patching has completed). This makes the contents
	 * of the region accessible to subsystems such as hibernate,
	 * but protects it from inadvertent modification or execution.
550 551
	 * Note that contiguous mappings cannot be remapped in this way,
	 * so we should avoid them here.
552
	 */
553
	__map_memblock(pgdp, kernel_start, kernel_end,
554 555
		       PAGE_KERNEL, NO_CONT_MAPPINGS);
	memblock_clear_nomap(kernel_start, kernel_end - kernel_start);
C
Catalin Marinas 已提交
556 557
}

558 559
void mark_rodata_ro(void)
{
J
Jeremy Linton 已提交
560
	unsigned long section_size;
561

J
Jeremy Linton 已提交
562
	/*
563 564
	 * mark .rodata as read only. Use __init_begin rather than __end_rodata
	 * to cover NOTES and EXCEPTION_TABLE.
J
Jeremy Linton 已提交
565
	 */
566
	section_size = (unsigned long)__init_begin - (unsigned long)__start_rodata;
567
	update_mapping_prot(__pa_symbol(__start_rodata), (unsigned long)__start_rodata,
J
Jeremy Linton 已提交
568
			    section_size, PAGE_KERNEL_RO);
569

570
	debug_checkwx();
571 572
}

573
static void __init map_kernel_segment(pgd_t *pgdp, void *va_start, void *va_end,
574
				      pgprot_t prot, struct vm_struct *vma,
575
				      int flags, unsigned long vm_flags)
576
{
577
	phys_addr_t pa_start = __pa_symbol(va_start);
578 579 580 581 582
	unsigned long size = va_end - va_start;

	BUG_ON(!PAGE_ALIGNED(pa_start));
	BUG_ON(!PAGE_ALIGNED(size));

583
	__create_pgd_mapping(pgdp, pa_start, (unsigned long)va_start, size, prot,
584
			     early_pgtable_alloc, flags);
585

586 587 588
	if (!(vm_flags & VM_NO_GUARD))
		size += PAGE_SIZE;

589 590 591
	vma->addr	= va_start;
	vma->phys_addr	= pa_start;
	vma->size	= size;
592
	vma->flags	= VM_MAP | vm_flags;
593 594 595
	vma->caller	= __builtin_return_address(0);

	vm_area_add_early(vma);
596 597
}

598 599
static int __init parse_rodata(char *arg)
{
600 601 602 603 604 605 606 607 608 609 610 611 612
	int ret = strtobool(arg, &rodata_enabled);
	if (!ret) {
		rodata_full = false;
		return 0;
	}

	/* permit 'full' in addition to boolean options */
	if (strcmp(arg, "full"))
		return -EINVAL;

	rodata_enabled = true;
	rodata_full = true;
	return 0;
613 614 615
}
early_param("rodata", parse_rodata);

616 617 618 619 620 621 622 623 624 625 626 627
#ifdef CONFIG_UNMAP_KERNEL_AT_EL0
static int __init map_entry_trampoline(void)
{
	pgprot_t prot = rodata_enabled ? PAGE_KERNEL_ROX : PAGE_KERNEL_EXEC;
	phys_addr_t pa_start = __pa_symbol(__entry_tramp_text_start);

	/* The trampoline is always mapped and can therefore be global */
	pgprot_val(prot) &= ~PTE_NG;

	/* Map only the text into the trampoline page table */
	memset(tramp_pg_dir, 0, PGD_SIZE);
	__create_pgd_mapping(tramp_pg_dir, pa_start, TRAMP_VALIAS, PAGE_SIZE,
628
			     prot, __pgd_pgtable_alloc, 0);
629

630
	/* Map both the text and data into the kernel page table */
631
	__set_fixmap(FIX_ENTRY_TRAMP_TEXT, pa_start, prot);
632 633 634 635 636 637 638 639
	if (IS_ENABLED(CONFIG_RANDOMIZE_BASE)) {
		extern char __entry_tramp_data_start[];

		__set_fixmap(FIX_ENTRY_TRAMP_DATA,
			     __pa_symbol(__entry_tramp_data_start),
			     PAGE_KERNEL_RO);
	}

640 641 642 643 644
	return 0;
}
core_initcall(map_entry_trampoline);
#endif

645 646 647 648 649 650 651 652 653 654 655
/*
 * Open coded check for BTI, only for use to determine configuration
 * for early mappings for before the cpufeature code has run.
 */
static bool arm64_early_this_cpu_has_bti(void)
{
	u64 pfr1;

	if (!IS_ENABLED(CONFIG_ARM64_BTI_KERNEL))
		return false;

656
	pfr1 = __read_sysreg_by_encoding(SYS_ID_AA64PFR1_EL1);
657 658 659 660
	return cpuid_feature_extract_unsigned_field(pfr1,
						    ID_AA64PFR1_BT_SHIFT);
}

661 662 663
/*
 * Create fine-grained mappings for the kernel.
 */
664
static void __init map_kernel(pgd_t *pgdp)
665
{
666 667
	static struct vm_struct vmlinux_text, vmlinux_rodata, vmlinux_inittext,
				vmlinux_initdata, vmlinux_data;
668

669 670 671 672 673 674 675
	/*
	 * External debuggers may need to write directly to the text
	 * mapping to install SW breakpoints. Allow this (only) when
	 * explicitly requested with rodata=off.
	 */
	pgprot_t text_prot = rodata_enabled ? PAGE_KERNEL_ROX : PAGE_KERNEL_EXEC;

676 677 678 679 680 681 682 683
	/*
	 * If we have a CPU that supports BTI and a kernel built for
	 * BTI then mark the kernel executable text as guarded pages
	 * now so we don't have to rewrite the page tables later.
	 */
	if (arm64_early_this_cpu_has_bti())
		text_prot = __pgprot_modify(text_prot, PTE_GP, PTE_GP);

684 685 686 687
	/*
	 * Only rodata will be remapped with different permissions later on,
	 * all other segments are allowed to use contiguous mappings.
	 */
688
	map_kernel_segment(pgdp, _stext, _etext, text_prot, &vmlinux_text, 0,
689
			   VM_NO_GUARD);
690
	map_kernel_segment(pgdp, __start_rodata, __inittext_begin, PAGE_KERNEL,
691
			   &vmlinux_rodata, NO_CONT_MAPPINGS, VM_NO_GUARD);
692
	map_kernel_segment(pgdp, __inittext_begin, __inittext_end, text_prot,
693
			   &vmlinux_inittext, 0, VM_NO_GUARD);
694
	map_kernel_segment(pgdp, __initdata_begin, __initdata_end, PAGE_KERNEL,
695
			   &vmlinux_initdata, 0, VM_NO_GUARD);
696
	map_kernel_segment(pgdp, _data, _end, PAGE_KERNEL, &vmlinux_data, 0, 0);
697

698
	if (!READ_ONCE(pgd_val(*pgd_offset_pgd(pgdp, FIXADDR_START)))) {
699 700 701 702 703
		/*
		 * The fixmap falls in a separate pgd to the kernel, and doesn't
		 * live in the carveout for the swapper_pg_dir. We can simply
		 * re-use the existing dir for the fixmap.
		 */
704
		set_pgd(pgd_offset_pgd(pgdp, FIXADDR_START),
705
			READ_ONCE(*pgd_offset_k(FIXADDR_START)));
706
	} else if (CONFIG_PGTABLE_LEVELS > 3) {
707
		pgd_t *bm_pgdp;
708
		p4d_t *bm_p4dp;
709
		pud_t *bm_pudp;
710 711 712 713 714 715 716
		/*
		 * The fixmap shares its top level pgd entry with the kernel
		 * mapping. This can really only occur when we are running
		 * with 16k/4 levels, so we can simply reuse the pud level
		 * entry instead.
		 */
		BUG_ON(!IS_ENABLED(CONFIG_ARM64_16K_PAGES));
717
		bm_pgdp = pgd_offset_pgd(pgdp, FIXADDR_START);
718 719
		bm_p4dp = p4d_offset(bm_pgdp, FIXADDR_START);
		bm_pudp = pud_set_fixmap_offset(bm_p4dp, FIXADDR_START);
720
		pud_populate(&init_mm, bm_pudp, lm_alias(bm_pmd));
721 722 723 724
		pud_clear_fixmap();
	} else {
		BUG();
	}
725

726
	kasan_copy_shadow(pgdp);
727 728
}

C
Catalin Marinas 已提交
729 730
void __init paging_init(void)
{
731
	pgd_t *pgdp = pgd_set_fixmap(__pa_symbol(swapper_pg_dir));
732

733 734
	map_kernel(pgdp);
	map_mem(pgdp);
735 736 737

	pgd_clear_fixmap();

738
	cpu_replace_ttbr1(lm_alias(swapper_pg_dir));
739
	init_mm.pgd = swapper_pg_dir;
740

741 742
	memblock_free(__pa_symbol(init_pg_dir),
		      __pa_symbol(init_pg_end) - __pa_symbol(init_pg_dir));
743 744

	memblock_allow_resize();
C
Catalin Marinas 已提交
745 746 747 748 749 750 751
}

/*
 * Check whether a kernel address is valid (derived from arch/x86/).
 */
int kern_addr_valid(unsigned long addr)
{
752
	pgd_t *pgdp;
753
	p4d_t *p4dp;
754 755 756
	pud_t *pudp, pud;
	pmd_t *pmdp, pmd;
	pte_t *ptep, pte;
C
Catalin Marinas 已提交
757

758
	addr = arch_kasan_reset_tag(addr);
C
Catalin Marinas 已提交
759 760 761
	if ((((long)addr) >> VA_BITS) != -1UL)
		return 0;

762 763
	pgdp = pgd_offset_k(addr);
	if (pgd_none(READ_ONCE(*pgdp)))
C
Catalin Marinas 已提交
764 765
		return 0;

766 767 768 769 770
	p4dp = p4d_offset(pgdp, addr);
	if (p4d_none(READ_ONCE(*p4dp)))
		return 0;

	pudp = pud_offset(p4dp, addr);
771 772
	pud = READ_ONCE(*pudp);
	if (pud_none(pud))
C
Catalin Marinas 已提交
773 774
		return 0;

775 776
	if (pud_sect(pud))
		return pfn_valid(pud_pfn(pud));
777

778 779 780
	pmdp = pmd_offset(pudp, addr);
	pmd = READ_ONCE(*pmdp);
	if (pmd_none(pmd))
C
Catalin Marinas 已提交
781 782
		return 0;

783 784
	if (pmd_sect(pmd))
		return pfn_valid(pmd_pfn(pmd));
785

786 787 788
	ptep = pte_offset_kernel(pmdp, addr);
	pte = READ_ONCE(*ptep);
	if (pte_none(pte))
C
Catalin Marinas 已提交
789 790
		return 0;

791
	return pfn_valid(pte_pfn(pte));
C
Catalin Marinas 已提交
792
}
793 794

#ifdef CONFIG_MEMORY_HOTPLUG
795 796
static void free_hotplug_page_range(struct page *page, size_t size,
				    struct vmem_altmap *altmap)
797
{
798 799 800 801 802 803
	if (altmap) {
		vmem_altmap_free(altmap, size >> PAGE_SHIFT);
	} else {
		WARN_ON(PageReserved(page));
		free_pages((unsigned long)page_address(page), get_order(size));
	}
804 805 806 807
}

static void free_hotplug_pgtable_page(struct page *page)
{
808
	free_hotplug_page_range(page, PAGE_SIZE, NULL);
809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830
}

static bool pgtable_range_aligned(unsigned long start, unsigned long end,
				  unsigned long floor, unsigned long ceiling,
				  unsigned long mask)
{
	start &= mask;
	if (start < floor)
		return false;

	if (ceiling) {
		ceiling &= mask;
		if (!ceiling)
			return false;
	}

	if (end - 1 > ceiling - 1)
		return false;
	return true;
}

static void unmap_hotplug_pte_range(pmd_t *pmdp, unsigned long addr,
831 832
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
833 834 835 836 837 838 839 840 841 842 843 844 845
{
	pte_t *ptep, pte;

	do {
		ptep = pte_offset_kernel(pmdp, addr);
		pte = READ_ONCE(*ptep);
		if (pte_none(pte))
			continue;

		WARN_ON(!pte_present(pte));
		pte_clear(&init_mm, addr, ptep);
		flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
		if (free_mapped)
846 847
			free_hotplug_page_range(pte_page(pte),
						PAGE_SIZE, altmap);
848 849 850 851
	} while (addr += PAGE_SIZE, addr < end);
}

static void unmap_hotplug_pmd_range(pud_t *pudp, unsigned long addr,
852 853
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875
{
	unsigned long next;
	pmd_t *pmdp, pmd;

	do {
		next = pmd_addr_end(addr, end);
		pmdp = pmd_offset(pudp, addr);
		pmd = READ_ONCE(*pmdp);
		if (pmd_none(pmd))
			continue;

		WARN_ON(!pmd_present(pmd));
		if (pmd_sect(pmd)) {
			pmd_clear(pmdp);

			/*
			 * One TLBI should be sufficient here as the PMD_SIZE
			 * range is mapped with a single block entry.
			 */
			flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
			if (free_mapped)
				free_hotplug_page_range(pmd_page(pmd),
876
							PMD_SIZE, altmap);
877 878 879
			continue;
		}
		WARN_ON(!pmd_table(pmd));
880
		unmap_hotplug_pte_range(pmdp, addr, next, free_mapped, altmap);
881 882 883 884
	} while (addr = next, addr < end);
}

static void unmap_hotplug_pud_range(p4d_t *p4dp, unsigned long addr,
885 886
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908
{
	unsigned long next;
	pud_t *pudp, pud;

	do {
		next = pud_addr_end(addr, end);
		pudp = pud_offset(p4dp, addr);
		pud = READ_ONCE(*pudp);
		if (pud_none(pud))
			continue;

		WARN_ON(!pud_present(pud));
		if (pud_sect(pud)) {
			pud_clear(pudp);

			/*
			 * One TLBI should be sufficient here as the PUD_SIZE
			 * range is mapped with a single block entry.
			 */
			flush_tlb_kernel_range(addr, addr + PAGE_SIZE);
			if (free_mapped)
				free_hotplug_page_range(pud_page(pud),
909
							PUD_SIZE, altmap);
910 911 912
			continue;
		}
		WARN_ON(!pud_table(pud));
913
		unmap_hotplug_pmd_range(pudp, addr, next, free_mapped, altmap);
914 915 916 917
	} while (addr = next, addr < end);
}

static void unmap_hotplug_p4d_range(pgd_t *pgdp, unsigned long addr,
918 919
				    unsigned long end, bool free_mapped,
				    struct vmem_altmap *altmap)
920 921 922 923 924 925 926 927 928 929 930 931
{
	unsigned long next;
	p4d_t *p4dp, p4d;

	do {
		next = p4d_addr_end(addr, end);
		p4dp = p4d_offset(pgdp, addr);
		p4d = READ_ONCE(*p4dp);
		if (p4d_none(p4d))
			continue;

		WARN_ON(!p4d_present(p4d));
932
		unmap_hotplug_pud_range(p4dp, addr, next, free_mapped, altmap);
933 934 935 936
	} while (addr = next, addr < end);
}

static void unmap_hotplug_range(unsigned long addr, unsigned long end,
937
				bool free_mapped, struct vmem_altmap *altmap)
938 939 940 941
{
	unsigned long next;
	pgd_t *pgdp, pgd;

942 943 944 945 946 947 948 949
	/*
	 * altmap can only be used as vmemmap mapping backing memory.
	 * In case the backing memory itself is not being freed, then
	 * altmap is irrelevant. Warn about this inconsistency when
	 * encountered.
	 */
	WARN_ON(!free_mapped && altmap);

950 951 952 953 954 955 956 957
	do {
		next = pgd_addr_end(addr, end);
		pgdp = pgd_offset_k(addr);
		pgd = READ_ONCE(*pgdp);
		if (pgd_none(pgd))
			continue;

		WARN_ON(!pgd_present(pgd));
958
		unmap_hotplug_p4d_range(pgdp, addr, next, free_mapped, altmap);
959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116
	} while (addr = next, addr < end);
}

static void free_empty_pte_table(pmd_t *pmdp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pte_t *ptep, pte;
	unsigned long i, start = addr;

	do {
		ptep = pte_offset_kernel(pmdp, addr);
		pte = READ_ONCE(*ptep);

		/*
		 * This is just a sanity check here which verifies that
		 * pte clearing has been done by earlier unmap loops.
		 */
		WARN_ON(!pte_none(pte));
	} while (addr += PAGE_SIZE, addr < end);

	if (!pgtable_range_aligned(start, end, floor, ceiling, PMD_MASK))
		return;

	/*
	 * Check whether we can free the pte page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	ptep = pte_offset_kernel(pmdp, 0UL);
	for (i = 0; i < PTRS_PER_PTE; i++) {
		if (!pte_none(READ_ONCE(ptep[i])))
			return;
	}

	pmd_clear(pmdp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(ptep));
}

static void free_empty_pmd_table(pud_t *pudp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pmd_t *pmdp, pmd;
	unsigned long i, next, start = addr;

	do {
		next = pmd_addr_end(addr, end);
		pmdp = pmd_offset(pudp, addr);
		pmd = READ_ONCE(*pmdp);
		if (pmd_none(pmd))
			continue;

		WARN_ON(!pmd_present(pmd) || !pmd_table(pmd) || pmd_sect(pmd));
		free_empty_pte_table(pmdp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);

	if (CONFIG_PGTABLE_LEVELS <= 2)
		return;

	if (!pgtable_range_aligned(start, end, floor, ceiling, PUD_MASK))
		return;

	/*
	 * Check whether we can free the pmd page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	pmdp = pmd_offset(pudp, 0UL);
	for (i = 0; i < PTRS_PER_PMD; i++) {
		if (!pmd_none(READ_ONCE(pmdp[i])))
			return;
	}

	pud_clear(pudp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(pmdp));
}

static void free_empty_pud_table(p4d_t *p4dp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	pud_t *pudp, pud;
	unsigned long i, next, start = addr;

	do {
		next = pud_addr_end(addr, end);
		pudp = pud_offset(p4dp, addr);
		pud = READ_ONCE(*pudp);
		if (pud_none(pud))
			continue;

		WARN_ON(!pud_present(pud) || !pud_table(pud) || pud_sect(pud));
		free_empty_pmd_table(pudp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);

	if (CONFIG_PGTABLE_LEVELS <= 3)
		return;

	if (!pgtable_range_aligned(start, end, floor, ceiling, PGDIR_MASK))
		return;

	/*
	 * Check whether we can free the pud page if the rest of the
	 * entries are empty. Overlap with other regions have been
	 * handled by the floor/ceiling check.
	 */
	pudp = pud_offset(p4dp, 0UL);
	for (i = 0; i < PTRS_PER_PUD; i++) {
		if (!pud_none(READ_ONCE(pudp[i])))
			return;
	}

	p4d_clear(p4dp);
	__flush_tlb_kernel_pgtable(start);
	free_hotplug_pgtable_page(virt_to_page(pudp));
}

static void free_empty_p4d_table(pgd_t *pgdp, unsigned long addr,
				 unsigned long end, unsigned long floor,
				 unsigned long ceiling)
{
	unsigned long next;
	p4d_t *p4dp, p4d;

	do {
		next = p4d_addr_end(addr, end);
		p4dp = p4d_offset(pgdp, addr);
		p4d = READ_ONCE(*p4dp);
		if (p4d_none(p4d))
			continue;

		WARN_ON(!p4d_present(p4d));
		free_empty_pud_table(p4dp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);
}

static void free_empty_tables(unsigned long addr, unsigned long end,
			      unsigned long floor, unsigned long ceiling)
{
	unsigned long next;
	pgd_t *pgdp, pgd;

	do {
		next = pgd_addr_end(addr, end);
		pgdp = pgd_offset_k(addr);
		pgd = READ_ONCE(*pgdp);
		if (pgd_none(pgd))
			continue;

		WARN_ON(!pgd_present(pgd));
		free_empty_p4d_table(pgdp, addr, next, floor, ceiling);
	} while (addr = next, addr < end);
}
#endif

1117
#if !ARM64_SWAPPER_USES_SECTION_MAPS
1118 1119
int __meminit vmemmap_populate(unsigned long start, unsigned long end, int node,
		struct vmem_altmap *altmap)
C
Catalin Marinas 已提交
1120
{
1121
	WARN_ON((start < VMEMMAP_START) || (end > VMEMMAP_END));
1122
	return vmemmap_populate_basepages(start, end, node, altmap);
C
Catalin Marinas 已提交
1123
}
1124
#else	/* !ARM64_SWAPPER_USES_SECTION_MAPS */
1125 1126
int __meminit vmemmap_populate(unsigned long start, unsigned long end, int node,
		struct vmem_altmap *altmap)
C
Catalin Marinas 已提交
1127
{
1128
	unsigned long addr = start;
C
Catalin Marinas 已提交
1129
	unsigned long next;
1130
	pgd_t *pgdp;
1131
	p4d_t *p4dp;
1132 1133
	pud_t *pudp;
	pmd_t *pmdp;
C
Catalin Marinas 已提交
1134

1135
	WARN_ON((start < VMEMMAP_START) || (end > VMEMMAP_END));
C
Catalin Marinas 已提交
1136 1137 1138
	do {
		next = pmd_addr_end(addr, end);

1139 1140
		pgdp = vmemmap_pgd_populate(addr, node);
		if (!pgdp)
C
Catalin Marinas 已提交
1141 1142
			return -ENOMEM;

1143 1144 1145 1146 1147
		p4dp = vmemmap_p4d_populate(pgdp, addr, node);
		if (!p4dp)
			return -ENOMEM;

		pudp = vmemmap_pud_populate(p4dp, addr, node);
1148
		if (!pudp)
C
Catalin Marinas 已提交
1149 1150
			return -ENOMEM;

1151 1152
		pmdp = pmd_offset(pudp, addr);
		if (pmd_none(READ_ONCE(*pmdp))) {
C
Catalin Marinas 已提交
1153 1154
			void *p = NULL;

1155
			p = vmemmap_alloc_block_buf(PMD_SIZE, node, altmap);
1156 1157 1158 1159 1160
			if (!p) {
				if (vmemmap_populate_basepages(addr, next, node, altmap))
					return -ENOMEM;
				continue;
			}
C
Catalin Marinas 已提交
1161

1162
			pmd_set_huge(pmdp, __pa(p), __pgprot(PROT_SECT_NORMAL));
C
Catalin Marinas 已提交
1163
		} else
1164
			vmemmap_verify((pte_t *)pmdp, node, addr, next);
C
Catalin Marinas 已提交
1165 1166 1167 1168
	} while (addr = next, addr != end);

	return 0;
}
O
Odin Ugedal 已提交
1169
#endif	/* !ARM64_SWAPPER_USES_SECTION_MAPS */
1170 1171
void vmemmap_free(unsigned long start, unsigned long end,
		struct vmem_altmap *altmap)
1172
{
1173 1174 1175
#ifdef CONFIG_MEMORY_HOTPLUG
	WARN_ON((start < VMEMMAP_START) || (end > VMEMMAP_END));

1176
	unmap_hotplug_range(start, end, true, altmap);
1177 1178
	free_empty_tables(start, end, VMEMMAP_START, VMEMMAP_END);
#endif
1179
}
1180

1181
static inline pud_t *fixmap_pud(unsigned long addr)
1182
{
1183
	pgd_t *pgdp = pgd_offset_k(addr);
1184 1185
	p4d_t *p4dp = p4d_offset(pgdp, addr);
	p4d_t p4d = READ_ONCE(*p4dp);
1186

1187
	BUG_ON(p4d_none(p4d) || p4d_bad(p4d));
1188

1189
	return pud_offset_kimg(p4dp, addr);
1190 1191
}

1192
static inline pmd_t *fixmap_pmd(unsigned long addr)
1193
{
1194 1195
	pud_t *pudp = fixmap_pud(addr);
	pud_t pud = READ_ONCE(*pudp);
1196

1197
	BUG_ON(pud_none(pud) || pud_bad(pud));
1198

1199
	return pmd_offset_kimg(pudp, addr);
1200 1201
}

1202
static inline pte_t *fixmap_pte(unsigned long addr)
1203
{
1204
	return &bm_pte[pte_index(addr)];
1205 1206
}

1207 1208 1209 1210 1211 1212
/*
 * The p*d_populate functions call virt_to_phys implicitly so they can't be used
 * directly on kernel symbols (bm_p*d). This function is called too early to use
 * lm_alias so __p*d_populate functions must be used to populate with the
 * physical address from __pa_symbol.
 */
1213 1214
void __init early_fixmap_init(void)
{
1215 1216
	pgd_t *pgdp;
	p4d_t *p4dp, p4d;
1217 1218
	pud_t *pudp;
	pmd_t *pmdp;
1219 1220
	unsigned long addr = FIXADDR_START;

1221
	pgdp = pgd_offset_k(addr);
1222 1223
	p4dp = p4d_offset(pgdp, addr);
	p4d = READ_ONCE(*p4dp);
1224
	if (CONFIG_PGTABLE_LEVELS > 3 &&
1225
	    !(p4d_none(p4d) || p4d_page_paddr(p4d) == __pa_symbol(bm_pud))) {
1226 1227 1228 1229 1230 1231
		/*
		 * We only end up here if the kernel mapping and the fixmap
		 * share the top level pgd entry, which should only happen on
		 * 16k/4 levels configurations.
		 */
		BUG_ON(!IS_ENABLED(CONFIG_ARM64_16K_PAGES));
1232
		pudp = pud_offset_kimg(p4dp, addr);
1233
	} else {
1234
		if (p4d_none(p4d))
1235
			__p4d_populate(p4dp, __pa_symbol(bm_pud), P4D_TYPE_TABLE);
1236
		pudp = fixmap_pud(addr);
1237
	}
1238
	if (pud_none(READ_ONCE(*pudp)))
1239
		__pud_populate(pudp, __pa_symbol(bm_pmd), PUD_TYPE_TABLE);
1240 1241
	pmdp = fixmap_pmd(addr);
	__pmd_populate(pmdp, __pa_symbol(bm_pte), PMD_TYPE_TABLE);
1242 1243 1244

	/*
	 * The boot-ioremap range spans multiple pmds, for which
1245
	 * we are not prepared:
1246 1247 1248 1249
	 */
	BUILD_BUG_ON((__fix_to_virt(FIX_BTMAP_BEGIN) >> PMD_SHIFT)
		     != (__fix_to_virt(FIX_BTMAP_END) >> PMD_SHIFT));

1250 1251
	if ((pmdp != fixmap_pmd(fix_to_virt(FIX_BTMAP_BEGIN)))
	     || pmdp != fixmap_pmd(fix_to_virt(FIX_BTMAP_END))) {
1252
		WARN_ON(1);
1253 1254
		pr_warn("pmdp %p != %p, %p\n",
			pmdp, fixmap_pmd(fix_to_virt(FIX_BTMAP_BEGIN)),
1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265
			fixmap_pmd(fix_to_virt(FIX_BTMAP_END)));
		pr_warn("fix_to_virt(FIX_BTMAP_BEGIN): %08lx\n",
			fix_to_virt(FIX_BTMAP_BEGIN));
		pr_warn("fix_to_virt(FIX_BTMAP_END):   %08lx\n",
			fix_to_virt(FIX_BTMAP_END));

		pr_warn("FIX_BTMAP_END:       %d\n", FIX_BTMAP_END);
		pr_warn("FIX_BTMAP_BEGIN:     %d\n", FIX_BTMAP_BEGIN);
	}
}

1266 1267 1268 1269
/*
 * Unusually, this is also called in IRQ context (ghes_iounmap_irq) so if we
 * ever need to use IPIs for TLB broadcasting, then we're in trouble here.
 */
1270 1271 1272 1273
void __set_fixmap(enum fixed_addresses idx,
			       phys_addr_t phys, pgprot_t flags)
{
	unsigned long addr = __fix_to_virt(idx);
1274
	pte_t *ptep;
1275

1276
	BUG_ON(idx <= FIX_HOLE || idx >= __end_of_fixed_addresses);
1277

1278
	ptep = fixmap_pte(addr);
1279 1280

	if (pgprot_val(flags)) {
1281
		set_pte(ptep, pfn_pte(phys >> PAGE_SHIFT, flags));
1282
	} else {
1283
		pte_clear(&init_mm, addr, ptep);
1284 1285 1286
		flush_tlb_kernel_range(addr, addr+PAGE_SIZE);
	}
}
1287

1288
void *__init fixmap_remap_fdt(phys_addr_t dt_phys, int *size, pgprot_t prot)
1289 1290
{
	const u64 dt_virt_base = __fix_to_virt(FIX_FDT);
1291
	int offset;
1292 1293 1294 1295 1296
	void *dt_virt;

	/*
	 * Check whether the physical FDT address is set and meets the minimum
	 * alignment requirement. Since we are relying on MIN_FDT_ALIGN to be
1297 1298 1299
	 * at least 8 bytes so that we can always access the magic and size
	 * fields of the FDT header after mapping the first chunk, double check
	 * here if that is indeed the case.
1300 1301 1302 1303 1304 1305 1306 1307
	 */
	BUILD_BUG_ON(MIN_FDT_ALIGN < 8);
	if (!dt_phys || dt_phys % MIN_FDT_ALIGN)
		return NULL;

	/*
	 * Make sure that the FDT region can be mapped without the need to
	 * allocate additional translation table pages, so that it is safe
1308
	 * to call create_mapping_noalloc() this early.
1309 1310 1311 1312 1313 1314 1315 1316
	 *
	 * On 64k pages, the FDT will be mapped using PTEs, so we need to
	 * be in the same PMD as the rest of the fixmap.
	 * On 4k pages, we'll use section mappings for the FDT so we only
	 * have to be in the same PUD.
	 */
	BUILD_BUG_ON(dt_virt_base % SZ_2M);

1317 1318
	BUILD_BUG_ON(__fix_to_virt(FIX_FDT_END) >> SWAPPER_TABLE_SHIFT !=
		     __fix_to_virt(FIX_BTMAP_BEGIN) >> SWAPPER_TABLE_SHIFT);
1319

1320
	offset = dt_phys % SWAPPER_BLOCK_SIZE;
1321 1322 1323
	dt_virt = (void *)dt_virt_base + offset;

	/* map the first chunk so we can read the size from the header */
1324 1325
	create_mapping_noalloc(round_down(dt_phys, SWAPPER_BLOCK_SIZE),
			dt_virt_base, SWAPPER_BLOCK_SIZE, prot);
1326

1327
	if (fdt_magic(dt_virt) != FDT_MAGIC)
1328 1329
		return NULL;

1330 1331
	*size = fdt_totalsize(dt_virt);
	if (*size > MAX_FDT_SIZE)
1332 1333
		return NULL;

1334
	if (offset + *size > SWAPPER_BLOCK_SIZE)
1335
		create_mapping_noalloc(round_down(dt_phys, SWAPPER_BLOCK_SIZE), dt_virt_base,
1336
			       round_up(offset + *size, SWAPPER_BLOCK_SIZE), prot);
1337

1338 1339
	return dt_virt;
}
1340

1341
int pud_set_huge(pud_t *pudp, phys_addr_t phys, pgprot_t prot)
1342
{
1343
	pud_t new_pud = pfn_pud(__phys_to_pfn(phys), mk_pud_sect_prot(prot));
1344

1345 1346 1347
	/* Only allow permission changes for now */
	if (!pgattr_change_is_safe(READ_ONCE(pud_val(*pudp)),
				   pud_val(new_pud)))
1348 1349
		return 0;

1350
	VM_BUG_ON(phys & ~PUD_MASK);
1351
	set_pud(pudp, new_pud);
1352 1353 1354
	return 1;
}

1355
int pmd_set_huge(pmd_t *pmdp, phys_addr_t phys, pgprot_t prot)
1356
{
1357
	pmd_t new_pmd = pfn_pmd(__phys_to_pfn(phys), mk_pmd_sect_prot(prot));
1358

1359 1360 1361
	/* Only allow permission changes for now */
	if (!pgattr_change_is_safe(READ_ONCE(pmd_val(*pmdp)),
				   pmd_val(new_pmd)))
1362 1363
		return 0;

1364
	VM_BUG_ON(phys & ~PMD_MASK);
1365
	set_pmd(pmdp, new_pmd);
1366 1367 1368
	return 1;
}

1369
int pud_clear_huge(pud_t *pudp)
1370
{
1371
	if (!pud_sect(READ_ONCE(*pudp)))
1372
		return 0;
1373
	pud_clear(pudp);
1374 1375 1376
	return 1;
}

1377
int pmd_clear_huge(pmd_t *pmdp)
1378
{
1379
	if (!pmd_sect(READ_ONCE(*pmdp)))
1380
		return 0;
1381
	pmd_clear(pmdp);
1382 1383
	return 1;
}
1384

1385
int pmd_free_pte_page(pmd_t *pmdp, unsigned long addr)
1386
{
1387 1388 1389 1390 1391
	pte_t *table;
	pmd_t pmd;

	pmd = READ_ONCE(*pmdp);

1392
	if (!pmd_table(pmd)) {
1393
		VM_WARN_ON(1);
1394 1395 1396 1397 1398 1399 1400 1401
		return 1;
	}

	table = pte_offset_kernel(pmdp, addr);
	pmd_clear(pmdp);
	__flush_tlb_kernel_pgtable(addr);
	pte_free_kernel(NULL, table);
	return 1;
1402 1403
}

1404
int pud_free_pmd_page(pud_t *pudp, unsigned long addr)
1405
{
1406 1407 1408 1409 1410 1411 1412
	pmd_t *table;
	pmd_t *pmdp;
	pud_t pud;
	unsigned long next, end;

	pud = READ_ONCE(*pudp);

1413
	if (!pud_table(pud)) {
1414
		VM_WARN_ON(1);
1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429
		return 1;
	}

	table = pmd_offset(pudp, addr);
	pmdp = table;
	next = addr;
	end = addr + PUD_SIZE;
	do {
		pmd_free_pte_page(pmdp, next);
	} while (pmdp++, next += PMD_SIZE, next != end);

	pud_clear(pudp);
	__flush_tlb_kernel_pgtable(addr);
	pmd_free(NULL, table);
	return 1;
1430
}
R
Robin Murphy 已提交
1431 1432

#ifdef CONFIG_MEMORY_HOTPLUG
1433 1434 1435 1436 1437 1438 1439
static void __remove_pgd_mapping(pgd_t *pgdir, unsigned long start, u64 size)
{
	unsigned long end = start + size;

	WARN_ON(pgdir != init_mm.pgd);
	WARN_ON((start < PAGE_OFFSET) || (end > PAGE_END));

1440
	unmap_hotplug_range(start, end, false, NULL);
1441 1442 1443
	free_empty_tables(start, end, PAGE_OFFSET, PAGE_END);
}

1444
struct range arch_get_mappable_range(void)
1445
{
1446
	struct range mhp_range;
1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462
	u64 start_linear_pa = __pa(_PAGE_OFFSET(vabits_actual));
	u64 end_linear_pa = __pa(PAGE_END - 1);

	if (IS_ENABLED(CONFIG_RANDOMIZE_BASE)) {
		/*
		 * Check for a wrap, it is possible because of randomized linear
		 * mapping the start physical address is actually bigger than
		 * the end physical address. In this case set start to zero
		 * because [0, end_linear_pa] range must still be able to cover
		 * all addressable physical addresses.
		 */
		if (start_linear_pa > end_linear_pa)
			start_linear_pa = 0;
	}

	WARN_ON(start_linear_pa > end_linear_pa);
1463

1464 1465 1466 1467 1468 1469
	/*
	 * Linear mapping region is the range [PAGE_OFFSET..(PAGE_END - 1)]
	 * accommodating both its ends but excluding PAGE_END. Max physical
	 * range which can be mapped inside this linear mapping range, must
	 * also be derived from its end points.
	 */
1470 1471 1472
	mhp_range.start = start_linear_pa;
	mhp_range.end =  end_linear_pa;

1473
	return mhp_range;
1474 1475
}

1476
int arch_add_memory(int nid, u64 start, u64 size,
1477
		    struct mhp_params *params)
R
Robin Murphy 已提交
1478
{
1479
	int ret, flags = NO_EXEC_MAPPINGS;
R
Robin Murphy 已提交
1480

1481
	VM_BUG_ON(!mhp_range_allowed(start, size, true));
1482 1483 1484 1485 1486 1487 1488

	/*
	 * KFENCE requires linear map to be mapped at page granularity, so that
	 * it is possible to protect/unprotect single pages in the KFENCE pool.
	 */
	if (rodata_full || debug_pagealloc_enabled() ||
	    IS_ENABLED(CONFIG_KFENCE))
1489
		flags |= NO_BLOCK_MAPPINGS | NO_CONT_MAPPINGS;
R
Robin Murphy 已提交
1490 1491

	__create_pgd_mapping(swapper_pg_dir, start, __phys_to_virt(start),
1492 1493
			     size, params->pgprot, __pgd_pgtable_alloc,
			     flags);
R
Robin Murphy 已提交
1494

1495 1496
	memblock_clear_nomap(start, size);

1497
	ret = __add_pages(nid, start >> PAGE_SHIFT, size >> PAGE_SHIFT,
1498
			   params);
1499 1500 1501 1502
	if (ret)
		__remove_pgd_mapping(swapper_pg_dir,
				     __phys_to_virt(start), size);
	return ret;
R
Robin Murphy 已提交
1503
}
1504

1505 1506 1507 1508 1509 1510
void arch_remove_memory(int nid, u64 start, u64 size,
			struct vmem_altmap *altmap)
{
	unsigned long start_pfn = start >> PAGE_SHIFT;
	unsigned long nr_pages = size >> PAGE_SHIFT;

1511
	__remove_pages(start_pfn, nr_pages, altmap);
1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531
	__remove_pgd_mapping(swapper_pg_dir, __phys_to_virt(start), size);
}

/*
 * This memory hotplug notifier helps prevent boot memory from being
 * inadvertently removed as it blocks pfn range offlining process in
 * __offline_pages(). Hence this prevents both offlining as well as
 * removal process for boot memory which is initially always online.
 * In future if and when boot memory could be removed, this notifier
 * should be dropped and free_hotplug_page_range() should handle any
 * reserved pages allocated during boot.
 */
static int prevent_bootmem_remove_notifier(struct notifier_block *nb,
					   unsigned long action, void *data)
{
	struct mem_section *ms;
	struct memory_notify *arg = data;
	unsigned long end_pfn = arg->start_pfn + arg->nr_pages;
	unsigned long pfn = arg->start_pfn;

1532
	if ((action != MEM_GOING_OFFLINE) && (action != MEM_OFFLINE))
1533 1534 1535
		return NOTIFY_OK;

	for (; pfn < end_pfn; pfn += PAGES_PER_SECTION) {
1536 1537 1538
		unsigned long start = PFN_PHYS(pfn);
		unsigned long end = start + (1UL << PA_SECTION_SHIFT);

1539
		ms = __pfn_to_section(pfn);
1540 1541 1542 1543 1544 1545 1546 1547 1548 1549
		if (!early_section(ms))
			continue;

		if (action == MEM_GOING_OFFLINE) {
			/*
			 * Boot memory removal is not supported. Prevent
			 * it via blocking any attempted offline request
			 * for the boot memory and just report it.
			 */
			pr_warn("Boot memory [%lx %lx] offlining attempted\n", start, end);
1550
			return NOTIFY_BAD;
1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568
		} else if (action == MEM_OFFLINE) {
			/*
			 * This should have never happened. Boot memory
			 * offlining should have been prevented by this
			 * very notifier. Probably some memory removal
			 * procedure might have changed which would then
			 * require further debug.
			 */
			pr_err("Boot memory [%lx %lx] offlined\n", start, end);

			/*
			 * Core memory hotplug does not process a return
			 * code from the notifier for MEM_OFFLINE events.
			 * The error condition has been reported. Return
			 * from here as if ignored.
			 */
			return NOTIFY_DONE;
		}
1569 1570 1571 1572 1573 1574 1575 1576
	}
	return NOTIFY_OK;
}

static struct notifier_block prevent_bootmem_remove_nb = {
	.notifier_call = prevent_bootmem_remove_notifier,
};

1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623
/*
 * This ensures that boot memory sections on the platform are online
 * from early boot. Memory sections could not be prevented from being
 * offlined, unless for some reason they are not online to begin with.
 * This helps validate the basic assumption on which the above memory
 * event notifier works to prevent boot memory section offlining and
 * its possible removal.
 */
static void validate_bootmem_online(void)
{
	phys_addr_t start, end, addr;
	struct mem_section *ms;
	u64 i;

	/*
	 * Scanning across all memblock might be expensive
	 * on some big memory systems. Hence enable this
	 * validation only with DEBUG_VM.
	 */
	if (!IS_ENABLED(CONFIG_DEBUG_VM))
		return;

	for_each_mem_range(i, &start, &end) {
		for (addr = start; addr < end; addr += (1UL << PA_SECTION_SHIFT)) {
			ms = __pfn_to_section(PHYS_PFN(addr));

			/*
			 * All memory ranges in the system at this point
			 * should have been marked as early sections.
			 */
			WARN_ON(!early_section(ms));

			/*
			 * Memory notifier mechanism here to prevent boot
			 * memory offlining depends on the fact that each
			 * early section memory on the system is initially
			 * online. Otherwise a given memory section which
			 * is already offline will be overlooked and can
			 * be removed completely. Call out such sections.
			 */
			if (!online_section(ms))
				pr_err("Boot memory [%llx %llx] is offline, can be removed\n",
					addr, addr + (1UL << PA_SECTION_SHIFT));
		}
	}
}

1624 1625
static int __init prevent_bootmem_remove_init(void)
{
1626 1627 1628 1629 1630
	int ret = 0;

	if (!IS_ENABLED(CONFIG_MEMORY_HOTREMOVE))
		return ret;

1631
	validate_bootmem_online();
1632 1633 1634 1635 1636
	ret = register_memory_notifier(&prevent_bootmem_remove_nb);
	if (ret)
		pr_err("%s: Notifier registration failed %d\n", __func__, ret);

	return ret;
1637
}
1638
early_initcall(prevent_bootmem_remove_init);
1639
#endif