entry.S 22.8 KB
Newer Older
C
Catalin Marinas 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
/*
 * Low-level exception handling code
 *
 * Copyright (C) 2012 ARM Ltd.
 * Authors:	Catalin Marinas <catalin.marinas@arm.com>
 *		Will Deacon <will.deacon@arm.com>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
 */

#include <linux/init.h>
#include <linux/linkage.h>

24
#include <asm/alternative.h>
C
Catalin Marinas 已提交
25 26
#include <asm/assembler.h>
#include <asm/asm-offsets.h>
27
#include <asm/cpufeature.h>
C
Catalin Marinas 已提交
28
#include <asm/errno.h>
29
#include <asm/esr.h>
30
#include <asm/irq.h>
31
#include <asm/processor.h>
32
#include <asm/ptrace.h>
C
Catalin Marinas 已提交
33
#include <asm/thread_info.h>
A
Al Viro 已提交
34
#include <asm/asm-uaccess.h>
C
Catalin Marinas 已提交
35 36
#include <asm/unistd.h>

L
Larry Bassel 已提交
37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62
/*
 * Context tracking subsystem.  Used to instrument transitions
 * between user and kernel mode.
 */
	.macro ct_user_exit, syscall = 0
#ifdef CONFIG_CONTEXT_TRACKING
	bl	context_tracking_user_exit
	.if \syscall == 1
	/*
	 * Save/restore needed during syscalls.  Restore syscall arguments from
	 * the values already saved on stack during kernel_entry.
	 */
	ldp	x0, x1, [sp]
	ldp	x2, x3, [sp, #S_X2]
	ldp	x4, x5, [sp, #S_X4]
	ldp	x6, x7, [sp, #S_X6]
	.endif
#endif
	.endm

	.macro ct_user_enter
#ifdef CONFIG_CONTEXT_TRACKING
	bl	context_tracking_user_enter
#endif
	.endm

C
Catalin Marinas 已提交
63 64 65 66 67 68 69 70 71
/*
 * Bad Abort numbers
 *-----------------
 */
#define BAD_SYNC	0
#define BAD_IRQ		1
#define BAD_FIQ		2
#define BAD_ERROR	3

72 73
	.macro kernel_ventry	label
	.align 7
74
	sub	sp, sp, #S_FRAME_SIZE
75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116
#ifdef CONFIG_VMAP_STACK
	/*
	 * Test whether the SP has overflowed, without corrupting a GPR.
	 * Task and IRQ stacks are aligned to (1 << THREAD_SHIFT).
	 */
	add	sp, sp, x0			// sp' = sp + x0
	sub	x0, sp, x0			// x0' = sp' - x0 = (sp + x0) - x0 = sp
	tbnz	x0, #THREAD_SHIFT, 0f
	sub	x0, sp, x0			// x0'' = sp' - x0' = (sp + x0) - sp = x0
	sub	sp, sp, x0			// sp'' = sp' - x0 = (sp + x0) - x0 = sp
	b	\label

0:
	/*
	 * Either we've just detected an overflow, or we've taken an exception
	 * while on the overflow stack. Either way, we won't return to
	 * userspace, and can clobber EL0 registers to free up GPRs.
	 */

	/* Stash the original SP (minus S_FRAME_SIZE) in tpidr_el0. */
	msr	tpidr_el0, x0

	/* Recover the original x0 value and stash it in tpidrro_el0 */
	sub	x0, sp, x0
	msr	tpidrro_el0, x0

	/* Switch to the overflow stack */
	adr_this_cpu sp, overflow_stack + OVERFLOW_STACK_SIZE, x0

	/*
	 * Check whether we were already on the overflow stack. This may happen
	 * after panic() re-enables interrupts.
	 */
	mrs	x0, tpidr_el0			// sp of interrupted context
	sub	x0, sp, x0			// delta with top of overflow stack
	tst	x0, #~(OVERFLOW_STACK_SIZE - 1)	// within range?
	b.ne	__bad_stack			// no? -> bad stack pointer

	/* We were already on the overflow stack. Restore sp/x0 and carry on. */
	sub	sp, sp, x0
	mrs	x0, tpidrro_el0
#endif
117 118 119 120
	b	\label
	.endm

	.macro	kernel_entry, el, regsize = 64
C
Catalin Marinas 已提交
121 122 123
	.if	\regsize == 32
	mov	w0, w0				// zero upper 32 bits of x0
	.endif
124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139
	stp	x0, x1, [sp, #16 * 0]
	stp	x2, x3, [sp, #16 * 1]
	stp	x4, x5, [sp, #16 * 2]
	stp	x6, x7, [sp, #16 * 3]
	stp	x8, x9, [sp, #16 * 4]
	stp	x10, x11, [sp, #16 * 5]
	stp	x12, x13, [sp, #16 * 6]
	stp	x14, x15, [sp, #16 * 7]
	stp	x16, x17, [sp, #16 * 8]
	stp	x18, x19, [sp, #16 * 9]
	stp	x20, x21, [sp, #16 * 10]
	stp	x22, x23, [sp, #16 * 11]
	stp	x24, x25, [sp, #16 * 12]
	stp	x26, x27, [sp, #16 * 13]
	stp	x28, x29, [sp, #16 * 14]

C
Catalin Marinas 已提交
140 141
	.if	\el == 0
	mrs	x21, sp_el0
142 143
	ldr_this_cpu	tsk, __entry_task, x20	// Ensure MDSCR_EL1.SS is clear,
	ldr	x19, [tsk, #TSK_TI_FLAGS]	// since we can unmask debug
144
	disable_step_tsk x19, x20		// exceptions when scheduling.
145 146

	mov	x29, xzr			// fp pointed to user-space
C
Catalin Marinas 已提交
147 148
	.else
	add	x21, sp, #S_FRAME_SIZE
149 150
	get_thread_info tsk
	/* Save the task's original addr_limit and set USER_DS (TASK_SIZE_64) */
151
	ldr	x20, [tsk, #TSK_TI_ADDR_LIMIT]
152 153
	str	x20, [sp, #S_ORIG_ADDR_LIMIT]
	mov	x20, #TASK_SIZE_64
154
	str	x20, [tsk, #TSK_TI_ADDR_LIMIT]
155
	/* No need to reset PSTATE.UAO, hardware's already set it to 0 for us */
156
	.endif /* \el == 0 */
C
Catalin Marinas 已提交
157 158 159
	mrs	x22, elr_el1
	mrs	x23, spsr_el1
	stp	lr, x21, [sp, #S_LR]
160

161 162 163 164 165 166 167 168 169 170 171 172
	/*
	 * In order to be able to dump the contents of struct pt_regs at the
	 * time the exception was taken (in case we attempt to walk the call
	 * stack later), chain it together with the stack frames.
	 */
	.if \el == 0
	stp	xzr, xzr, [sp, #S_STACKFRAME]
	.else
	stp	x29, x22, [sp, #S_STACKFRAME]
	.endif
	add	x29, sp, #S_STACKFRAME

173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197
#ifdef CONFIG_ARM64_SW_TTBR0_PAN
	/*
	 * Set the TTBR0 PAN bit in SPSR. When the exception is taken from
	 * EL0, there is no need to check the state of TTBR0_EL1 since
	 * accesses are always enabled.
	 * Note that the meaning of this bit differs from the ARMv8.1 PAN
	 * feature as all TTBR0_EL1 accesses are disabled, not just those to
	 * user mappings.
	 */
alternative_if ARM64_HAS_PAN
	b	1f				// skip TTBR0 PAN
alternative_else_nop_endif

	.if	\el != 0
	mrs	x21, ttbr0_el1
	tst	x21, #0xffff << 48		// Check for the reserved ASID
	orr	x23, x23, #PSR_PAN_BIT		// Set the emulated PAN in the saved SPSR
	b.eq	1f				// TTBR0 access already disabled
	and	x23, x23, #~PSR_PAN_BIT		// Clear the emulated PAN in the saved SPSR
	.endif

	__uaccess_ttbr0_disable x21
1:
#endif

C
Catalin Marinas 已提交
198 199
	stp	x22, x23, [sp, #S_PC]

200
	/* Not in a syscall by default (el0_svc overwrites for real syscall) */
C
Catalin Marinas 已提交
201
	.if	\el == 0
202
	mov	w21, #NO_SYSCALL
203
	str	w21, [sp, #S_SYSCALLNO]
C
Catalin Marinas 已提交
204 205
	.endif

206 207 208 209 210 211 212
	/*
	 * Set sp_el0 to current thread_info.
	 */
	.if	\el == 0
	msr	sp_el0, tsk
	.endif

C
Catalin Marinas 已提交
213 214 215 216 217 218 219 220 221
	/*
	 * Registers that may be useful after this macro is invoked:
	 *
	 * x21 - aborted SP
	 * x22 - aborted PC
	 * x23 - aborted PSTATE
	*/
	.endm

222
	.macro	kernel_exit, el
223
	.if	\el != 0
224 225
	disable_daif

226 227
	/* Restore the task's original addr_limit. */
	ldr	x20, [sp, #S_ORIG_ADDR_LIMIT]
228
	str	x20, [tsk, #TSK_TI_ADDR_LIMIT]
229 230 231 232

	/* No need to restore UAO, it will be restored from SPSR_EL1 */
	.endif

C
Catalin Marinas 已提交
233 234
	ldp	x21, x22, [sp, #S_PC]		// load ELR, SPSR
	.if	\el == 0
L
Larry Bassel 已提交
235
	ct_user_enter
236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259
	.endif

#ifdef CONFIG_ARM64_SW_TTBR0_PAN
	/*
	 * Restore access to TTBR0_EL1. If returning to EL0, no need for SPSR
	 * PAN bit checking.
	 */
alternative_if ARM64_HAS_PAN
	b	2f				// skip TTBR0 PAN
alternative_else_nop_endif

	.if	\el != 0
	tbnz	x22, #22, 1f			// Skip re-enabling TTBR0 access if the PSR_PAN_BIT is set
	.endif

	__uaccess_ttbr0_enable x0

	.if	\el == 0
	/*
	 * Enable errata workarounds only if returning to user. The only
	 * workaround currently required for TTBR0_EL1 changes are for the
	 * Cavium erratum 27456 (broadcast TLBI instructions may cause I-cache
	 * corruption).
	 */
260
	post_ttbr_update_workaround
261 262 263 264 265 266 267 268 269
	.endif
1:
	.if	\el != 0
	and	x22, x22, #~PSR_PAN_BIT		// ARMv8.0 CPUs do not understand this bit
	.endif
2:
#endif

	.if	\el == 0
C
Catalin Marinas 已提交
270
	ldr	x23, [sp, #S_SP]		// load return stack pointer
271
	msr	sp_el0, x23
272
#ifdef CONFIG_ARM64_ERRATUM_845719
M
Mark Rutland 已提交
273
alternative_if ARM64_WORKAROUND_845719
274 275 276 277
	tbz	x22, #4, 1f
#ifdef CONFIG_PID_IN_CONTEXTIDR
	mrs	x29, contextidr_el1
	msr	contextidr_el1, x29
278
#else
279
	msr contextidr_el1, xzr
280
#endif
281
1:
M
Mark Rutland 已提交
282
alternative_else_nop_endif
283
#endif
C
Catalin Marinas 已提交
284
	.endif
285

286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304
	msr	elr_el1, x21			// set up the return data
	msr	spsr_el1, x22
	ldp	x0, x1, [sp, #16 * 0]
	ldp	x2, x3, [sp, #16 * 1]
	ldp	x4, x5, [sp, #16 * 2]
	ldp	x6, x7, [sp, #16 * 3]
	ldp	x8, x9, [sp, #16 * 4]
	ldp	x10, x11, [sp, #16 * 5]
	ldp	x12, x13, [sp, #16 * 6]
	ldp	x14, x15, [sp, #16 * 7]
	ldp	x16, x17, [sp, #16 * 8]
	ldp	x18, x19, [sp, #16 * 9]
	ldp	x20, x21, [sp, #16 * 10]
	ldp	x22, x23, [sp, #16 * 11]
	ldp	x24, x25, [sp, #16 * 12]
	ldp	x26, x27, [sp, #16 * 13]
	ldp	x28, x29, [sp, #16 * 14]
	ldr	lr, [sp, #S_LR]
	add	sp, sp, #S_FRAME_SIZE		// restore sp
C
Catalin Marinas 已提交
305 306 307
	eret					// return to kernel
	.endm

308
	.macro	irq_stack_entry
309 310 311
	mov	x19, sp			// preserve the original sp

	/*
312 313 314
	 * Compare sp with the base of the task stack.
	 * If the top ~(THREAD_SIZE - 1) bits match, we are on a task stack,
	 * and should switch to the irq stack.
315
	 */
316 317 318 319
	ldr	x25, [tsk, TSK_STACK]
	eor	x25, x25, x19
	and	x25, x25, #~(THREAD_SIZE - 1)
	cbnz	x25, 9998f
320

M
Mark Rutland 已提交
321
	ldr_this_cpu x25, irq_stack_ptr, x26
322
	mov	x26, #IRQ_STACK_SIZE
323
	add	x26, x25, x26
324 325

	/* switch to the irq stack */
326 327 328 329 330 331 332 333 334 335 336 337
	mov	sp, x26
9998:
	.endm

	/*
	 * x19 should be preserved between irq_stack_entry and
	 * irq_stack_exit.
	 */
	.macro	irq_stack_exit
	mov	sp, x19
	.endm

C
Catalin Marinas 已提交
338 339 340 341 342 343
/*
 * These are the registers used in the syscall handler, and allow us to
 * have in theory up to 7 arguments to a function - x0 to x6.
 *
 * x7 is reserved for the system call number in 32-bit mode.
 */
344 345 346
wsc_nr	.req	w25		// number of system calls
wscno	.req	w26		// syscall number
xscno	.req	x26		// syscall number (zero-extended)
C
Catalin Marinas 已提交
347 348 349 350 351 352 353
stbl	.req	x27		// syscall table pointer
tsk	.req	x28		// current thread_info

/*
 * Interrupt handling.
 */
	.macro	irq_handler
354
	ldr_l	x1, handle_arch_irq
C
Catalin Marinas 已提交
355
	mov	x0, sp
356
	irq_stack_entry
C
Catalin Marinas 已提交
357
	blr	x1
358
	irq_stack_exit
C
Catalin Marinas 已提交
359 360 361 362 363 364 365
	.endm

	.text

/*
 * Exception vectors.
 */
366
	.pushsection ".entry.text", "ax"
C
Catalin Marinas 已提交
367 368 369

	.align	11
ENTRY(vectors)
370 371 372 373
	kernel_ventry	el1_sync_invalid		// Synchronous EL1t
	kernel_ventry	el1_irq_invalid			// IRQ EL1t
	kernel_ventry	el1_fiq_invalid			// FIQ EL1t
	kernel_ventry	el1_error_invalid		// Error EL1t
C
Catalin Marinas 已提交
374

375 376 377
	kernel_ventry	el1_sync			// Synchronous EL1h
	kernel_ventry	el1_irq				// IRQ EL1h
	kernel_ventry	el1_fiq_invalid			// FIQ EL1h
378
	kernel_ventry	el1_error			// Error EL1h
C
Catalin Marinas 已提交
379

380 381 382
	kernel_ventry	el0_sync			// Synchronous 64-bit EL0
	kernel_ventry	el0_irq				// IRQ 64-bit EL0
	kernel_ventry	el0_fiq_invalid			// FIQ 64-bit EL0
383
	kernel_ventry	el0_error			// Error 64-bit EL0
C
Catalin Marinas 已提交
384 385

#ifdef CONFIG_COMPAT
386 387 388
	kernel_ventry	el0_sync_compat			// Synchronous 32-bit EL0
	kernel_ventry	el0_irq_compat			// IRQ 32-bit EL0
	kernel_ventry	el0_fiq_invalid_compat		// FIQ 32-bit EL0
389
	kernel_ventry	el0_error_compat		// Error 32-bit EL0
C
Catalin Marinas 已提交
390
#else
391 392 393 394
	kernel_ventry	el0_sync_invalid		// Synchronous 32-bit EL0
	kernel_ventry	el0_irq_invalid			// IRQ 32-bit EL0
	kernel_ventry	el0_fiq_invalid			// FIQ 32-bit EL0
	kernel_ventry	el0_error_invalid		// Error 32-bit EL0
C
Catalin Marinas 已提交
395 396 397
#endif
END(vectors)

398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425
#ifdef CONFIG_VMAP_STACK
	/*
	 * We detected an overflow in kernel_ventry, which switched to the
	 * overflow stack. Stash the exception regs, and head to our overflow
	 * handler.
	 */
__bad_stack:
	/* Restore the original x0 value */
	mrs	x0, tpidrro_el0

	/*
	 * Store the original GPRs to the new stack. The orginal SP (minus
	 * S_FRAME_SIZE) was stashed in tpidr_el0 by kernel_ventry.
	 */
	sub	sp, sp, #S_FRAME_SIZE
	kernel_entry 1
	mrs	x0, tpidr_el0
	add	x0, x0, #S_FRAME_SIZE
	str	x0, [sp, #S_SP]

	/* Stash the regs for handle_bad_stack */
	mov	x0, sp

	/* Time to die */
	bl	handle_bad_stack
	ASM_BUG()
#endif /* CONFIG_VMAP_STACK */

C
Catalin Marinas 已提交
426 427 428 429
/*
 * Invalid mode handlers
 */
	.macro	inv_entry, el, reason, regsize = 64
430
	kernel_entry \el, \regsize
C
Catalin Marinas 已提交
431 432 433
	mov	x0, sp
	mov	x1, #\reason
	mrs	x2, esr_el1
434 435
	bl	bad_mode
	ASM_BUG()
C
Catalin Marinas 已提交
436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482
	.endm

el0_sync_invalid:
	inv_entry 0, BAD_SYNC
ENDPROC(el0_sync_invalid)

el0_irq_invalid:
	inv_entry 0, BAD_IRQ
ENDPROC(el0_irq_invalid)

el0_fiq_invalid:
	inv_entry 0, BAD_FIQ
ENDPROC(el0_fiq_invalid)

el0_error_invalid:
	inv_entry 0, BAD_ERROR
ENDPROC(el0_error_invalid)

#ifdef CONFIG_COMPAT
el0_fiq_invalid_compat:
	inv_entry 0, BAD_FIQ, 32
ENDPROC(el0_fiq_invalid_compat)
#endif

el1_sync_invalid:
	inv_entry 1, BAD_SYNC
ENDPROC(el1_sync_invalid)

el1_irq_invalid:
	inv_entry 1, BAD_IRQ
ENDPROC(el1_irq_invalid)

el1_fiq_invalid:
	inv_entry 1, BAD_FIQ
ENDPROC(el1_fiq_invalid)

el1_error_invalid:
	inv_entry 1, BAD_ERROR
ENDPROC(el1_error_invalid)

/*
 * EL1 mode handlers.
 */
	.align	6
el1_sync:
	kernel_entry 1
	mrs	x1, esr_el1			// read the syndrome register
M
Mark Rutland 已提交
483 484
	lsr	x24, x1, #ESR_ELx_EC_SHIFT	// exception class
	cmp	x24, #ESR_ELx_EC_DABT_CUR	// data abort in EL1
C
Catalin Marinas 已提交
485
	b.eq	el1_da
486 487
	cmp	x24, #ESR_ELx_EC_IABT_CUR	// instruction abort in EL1
	b.eq	el1_ia
M
Mark Rutland 已提交
488
	cmp	x24, #ESR_ELx_EC_SYS64		// configurable trap
C
Catalin Marinas 已提交
489
	b.eq	el1_undef
M
Mark Rutland 已提交
490
	cmp	x24, #ESR_ELx_EC_SP_ALIGN	// stack alignment exception
C
Catalin Marinas 已提交
491
	b.eq	el1_sp_pc
M
Mark Rutland 已提交
492
	cmp	x24, #ESR_ELx_EC_PC_ALIGN	// pc alignment exception
C
Catalin Marinas 已提交
493
	b.eq	el1_sp_pc
M
Mark Rutland 已提交
494
	cmp	x24, #ESR_ELx_EC_UNKNOWN	// unknown exception in EL1
C
Catalin Marinas 已提交
495
	b.eq	el1_undef
M
Mark Rutland 已提交
496
	cmp	x24, #ESR_ELx_EC_BREAKPT_CUR	// debug exception in EL1
C
Catalin Marinas 已提交
497 498
	b.ge	el1_dbg
	b	el1_inv
499 500 501 502 503

el1_ia:
	/*
	 * Fall through to the Data abort case
	 */
C
Catalin Marinas 已提交
504 505 506 507
el1_da:
	/*
	 * Data abort handling
	 */
508
	mrs	x3, far_el1
J
James Morse 已提交
509
	inherit_daif	pstate=x23, tmp=x2
510
	clear_address_tag x0, x3
C
Catalin Marinas 已提交
511 512 513 514 515 516 517 518 519
	mov	x2, sp				// struct pt_regs
	bl	do_mem_abort

	kernel_exit 1
el1_sp_pc:
	/*
	 * Stack or PC alignment exception handling
	 */
	mrs	x0, far_el1
J
James Morse 已提交
520
	inherit_daif	pstate=x23, tmp=x2
C
Catalin Marinas 已提交
521
	mov	x2, sp
522 523
	bl	do_sp_pc_abort
	ASM_BUG()
C
Catalin Marinas 已提交
524 525 526 527
el1_undef:
	/*
	 * Undefined instruction
	 */
J
James Morse 已提交
528
	inherit_daif	pstate=x23, tmp=x2
C
Catalin Marinas 已提交
529
	mov	x0, sp
530 531
	bl	do_undefinstr
	ASM_BUG()
C
Catalin Marinas 已提交
532 533 534 535
el1_dbg:
	/*
	 * Debug exception handling
	 */
M
Mark Rutland 已提交
536
	cmp	x24, #ESR_ELx_EC_BRK64		// if BRK64
537
	cinc	x24, x24, eq			// set bit '0'
C
Catalin Marinas 已提交
538 539 540 541 542 543 544
	tbz	x24, #0, el1_inv		// EL1 only
	mrs	x0, far_el1
	mov	x2, sp				// struct pt_regs
	bl	do_debug_exception
	kernel_exit 1
el1_inv:
	// TODO: add support for undefined instructions in kernel mode
J
James Morse 已提交
545
	inherit_daif	pstate=x23, tmp=x2
C
Catalin Marinas 已提交
546
	mov	x0, sp
547
	mov	x2, x1
C
Catalin Marinas 已提交
548
	mov	x1, #BAD_SYNC
549 550
	bl	bad_mode
	ASM_BUG()
C
Catalin Marinas 已提交
551 552 553 554 555
ENDPROC(el1_sync)

	.align	6
el1_irq:
	kernel_entry 1
J
James Morse 已提交
556
	enable_da_f
C
Catalin Marinas 已提交
557 558 559
#ifdef CONFIG_TRACE_IRQFLAGS
	bl	trace_hardirqs_off
#endif
560

C
Catalin Marinas 已提交
561
	irq_handler
562

C
Catalin Marinas 已提交
563
#ifdef CONFIG_PREEMPT
564
	ldr	w24, [tsk, #TSK_TI_PREEMPT]	// get preempt count
565
	cbnz	w24, 1f				// preempt count != 0
566
	ldr	x0, [tsk, #TSK_TI_FLAGS]	// get flags
C
Catalin Marinas 已提交
567 568 569 570 571 572 573 574 575 576 577 578 579
	tbz	x0, #TIF_NEED_RESCHED, 1f	// needs rescheduling?
	bl	el1_preempt
1:
#endif
#ifdef CONFIG_TRACE_IRQFLAGS
	bl	trace_hardirqs_on
#endif
	kernel_exit 1
ENDPROC(el1_irq)

#ifdef CONFIG_PREEMPT
el1_preempt:
	mov	x24, lr
580
1:	bl	preempt_schedule_irq		// irq en/disable is done inside
581
	ldr	x0, [tsk, #TSK_TI_FLAGS]	// get new tasks TI_FLAGS
C
Catalin Marinas 已提交
582 583 584 585 586 587 588 589 590 591 592
	tbnz	x0, #TIF_NEED_RESCHED, 1b	// needs rescheduling?
	ret	x24
#endif

/*
 * EL0 mode handlers.
 */
	.align	6
el0_sync:
	kernel_entry 0
	mrs	x25, esr_el1			// read the syndrome register
M
Mark Rutland 已提交
593 594
	lsr	x24, x25, #ESR_ELx_EC_SHIFT	// exception class
	cmp	x24, #ESR_ELx_EC_SVC64		// SVC in 64-bit state
C
Catalin Marinas 已提交
595
	b.eq	el0_svc
M
Mark Rutland 已提交
596
	cmp	x24, #ESR_ELx_EC_DABT_LOW	// data abort in EL0
C
Catalin Marinas 已提交
597
	b.eq	el0_da
M
Mark Rutland 已提交
598
	cmp	x24, #ESR_ELx_EC_IABT_LOW	// instruction abort in EL0
C
Catalin Marinas 已提交
599
	b.eq	el0_ia
M
Mark Rutland 已提交
600
	cmp	x24, #ESR_ELx_EC_FP_ASIMD	// FP/ASIMD access
C
Catalin Marinas 已提交
601
	b.eq	el0_fpsimd_acc
602 603
	cmp	x24, #ESR_ELx_EC_SVE		// SVE access
	b.eq	el0_sve_acc
M
Mark Rutland 已提交
604
	cmp	x24, #ESR_ELx_EC_FP_EXC64	// FP/ASIMD exception
C
Catalin Marinas 已提交
605
	b.eq	el0_fpsimd_exc
M
Mark Rutland 已提交
606
	cmp	x24, #ESR_ELx_EC_SYS64		// configurable trap
607
	b.eq	el0_sys
M
Mark Rutland 已提交
608
	cmp	x24, #ESR_ELx_EC_SP_ALIGN	// stack alignment exception
C
Catalin Marinas 已提交
609
	b.eq	el0_sp_pc
M
Mark Rutland 已提交
610
	cmp	x24, #ESR_ELx_EC_PC_ALIGN	// pc alignment exception
C
Catalin Marinas 已提交
611
	b.eq	el0_sp_pc
M
Mark Rutland 已提交
612
	cmp	x24, #ESR_ELx_EC_UNKNOWN	// unknown exception in EL0
C
Catalin Marinas 已提交
613
	b.eq	el0_undef
M
Mark Rutland 已提交
614
	cmp	x24, #ESR_ELx_EC_BREAKPT_LOW	// debug exception in EL0
C
Catalin Marinas 已提交
615 616 617 618 619 620 621 622
	b.ge	el0_dbg
	b	el0_inv

#ifdef CONFIG_COMPAT
	.align	6
el0_sync_compat:
	kernel_entry 0, 32
	mrs	x25, esr_el1			// read the syndrome register
M
Mark Rutland 已提交
623 624
	lsr	x24, x25, #ESR_ELx_EC_SHIFT	// exception class
	cmp	x24, #ESR_ELx_EC_SVC32		// SVC in 32-bit state
C
Catalin Marinas 已提交
625
	b.eq	el0_svc_compat
M
Mark Rutland 已提交
626
	cmp	x24, #ESR_ELx_EC_DABT_LOW	// data abort in EL0
C
Catalin Marinas 已提交
627
	b.eq	el0_da
M
Mark Rutland 已提交
628
	cmp	x24, #ESR_ELx_EC_IABT_LOW	// instruction abort in EL0
C
Catalin Marinas 已提交
629
	b.eq	el0_ia
M
Mark Rutland 已提交
630
	cmp	x24, #ESR_ELx_EC_FP_ASIMD	// FP/ASIMD access
C
Catalin Marinas 已提交
631
	b.eq	el0_fpsimd_acc
M
Mark Rutland 已提交
632
	cmp	x24, #ESR_ELx_EC_FP_EXC32	// FP/ASIMD exception
C
Catalin Marinas 已提交
633
	b.eq	el0_fpsimd_exc
634 635
	cmp	x24, #ESR_ELx_EC_PC_ALIGN	// pc alignment exception
	b.eq	el0_sp_pc
M
Mark Rutland 已提交
636
	cmp	x24, #ESR_ELx_EC_UNKNOWN	// unknown exception in EL0
C
Catalin Marinas 已提交
637
	b.eq	el0_undef
M
Mark Rutland 已提交
638
	cmp	x24, #ESR_ELx_EC_CP15_32	// CP15 MRC/MCR trap
639
	b.eq	el0_undef
M
Mark Rutland 已提交
640
	cmp	x24, #ESR_ELx_EC_CP15_64	// CP15 MRRC/MCRR trap
641
	b.eq	el0_undef
M
Mark Rutland 已提交
642
	cmp	x24, #ESR_ELx_EC_CP14_MR	// CP14 MRC/MCR trap
643
	b.eq	el0_undef
M
Mark Rutland 已提交
644
	cmp	x24, #ESR_ELx_EC_CP14_LS	// CP14 LDC/STC trap
645
	b.eq	el0_undef
M
Mark Rutland 已提交
646
	cmp	x24, #ESR_ELx_EC_CP14_64	// CP14 MRRC/MCRR trap
647
	b.eq	el0_undef
M
Mark Rutland 已提交
648
	cmp	x24, #ESR_ELx_EC_BREAKPT_LOW	// debug exception in EL0
C
Catalin Marinas 已提交
649 650 651 652 653 654
	b.ge	el0_dbg
	b	el0_inv
el0_svc_compat:
	/*
	 * AArch32 syscall handling
	 */
655
	ldr	x16, [tsk, #TSK_TI_FLAGS]	// load thread flags
656
	adrp	stbl, compat_sys_call_table	// load compat syscall table pointer
657 658
	mov	wscno, w7			// syscall number in w7 (r7)
	mov     wsc_nr, #__NR_compat_syscalls
C
Catalin Marinas 已提交
659 660 661 662 663 664
	b	el0_svc_naked

	.align	6
el0_irq_compat:
	kernel_entry 0, 32
	b	el0_irq_naked
665 666 667 668

el0_error_compat:
	kernel_entry 0, 32
	b	el0_error_naked
C
Catalin Marinas 已提交
669 670 671 672 673 674
#endif

el0_da:
	/*
	 * Data abort handling
	 */
675
	mrs	x26, far_el1
J
James Morse 已提交
676
	enable_daif
L
Larry Bassel 已提交
677
	ct_user_exit
678
	clear_address_tag x0, x26
C
Catalin Marinas 已提交
679 680
	mov	x1, x25
	mov	x2, sp
681 682
	bl	do_mem_abort
	b	ret_to_user
C
Catalin Marinas 已提交
683 684 685 686
el0_ia:
	/*
	 * Instruction abort handling
	 */
687
	mrs	x26, far_el1
J
James Morse 已提交
688
	enable_daif
L
Larry Bassel 已提交
689
	ct_user_exit
690
	mov	x0, x26
M
Mark Rutland 已提交
691
	mov	x1, x25
C
Catalin Marinas 已提交
692
	mov	x2, sp
693 694
	bl	do_mem_abort
	b	ret_to_user
C
Catalin Marinas 已提交
695 696 697 698
el0_fpsimd_acc:
	/*
	 * Floating Point or Advanced SIMD access
	 */
J
James Morse 已提交
699
	enable_daif
L
Larry Bassel 已提交
700
	ct_user_exit
C
Catalin Marinas 已提交
701 702
	mov	x0, x25
	mov	x1, sp
703 704
	bl	do_fpsimd_acc
	b	ret_to_user
705 706 707 708 709 710 711 712 713 714
el0_sve_acc:
	/*
	 * Scalable Vector Extension access
	 */
	enable_daif
	ct_user_exit
	mov	x0, x25
	mov	x1, sp
	bl	do_sve_acc
	b	ret_to_user
C
Catalin Marinas 已提交
715 716
el0_fpsimd_exc:
	/*
717
	 * Floating Point, Advanced SIMD or SVE exception
C
Catalin Marinas 已提交
718
	 */
J
James Morse 已提交
719
	enable_daif
L
Larry Bassel 已提交
720
	ct_user_exit
C
Catalin Marinas 已提交
721 722
	mov	x0, x25
	mov	x1, sp
723 724
	bl	do_fpsimd_exc
	b	ret_to_user
C
Catalin Marinas 已提交
725 726 727 728
el0_sp_pc:
	/*
	 * Stack or PC alignment exception handling
	 */
729
	mrs	x26, far_el1
J
James Morse 已提交
730
	enable_daif
731
	ct_user_exit
732
	mov	x0, x26
C
Catalin Marinas 已提交
733 734
	mov	x1, x25
	mov	x2, sp
735 736
	bl	do_sp_pc_abort
	b	ret_to_user
C
Catalin Marinas 已提交
737 738 739 740
el0_undef:
	/*
	 * Undefined instruction
	 */
J
James Morse 已提交
741
	enable_daif
L
Larry Bassel 已提交
742
	ct_user_exit
743
	mov	x0, sp
744 745
	bl	do_undefinstr
	b	ret_to_user
746 747 748 749
el0_sys:
	/*
	 * System instructions, for trapped cache maintenance instructions
	 */
J
James Morse 已提交
750
	enable_daif
751 752 753 754 755
	ct_user_exit
	mov	x0, x25
	mov	x1, sp
	bl	do_sysinstr
	b	ret_to_user
C
Catalin Marinas 已提交
756 757 758 759 760 761 762 763
el0_dbg:
	/*
	 * Debug exception handling
	 */
	tbnz	x24, #0, el0_inv		// EL0 only
	mrs	x0, far_el1
	mov	x1, x25
	mov	x2, sp
764
	bl	do_debug_exception
J
James Morse 已提交
765
	enable_daif
L
Larry Bassel 已提交
766
	ct_user_exit
767
	b	ret_to_user
C
Catalin Marinas 已提交
768
el0_inv:
J
James Morse 已提交
769
	enable_daif
L
Larry Bassel 已提交
770
	ct_user_exit
C
Catalin Marinas 已提交
771 772
	mov	x0, sp
	mov	x1, #BAD_SYNC
773
	mov	x2, x25
774
	bl	bad_el0_sync
775
	b	ret_to_user
C
Catalin Marinas 已提交
776 777 778 779 780 781
ENDPROC(el0_sync)

	.align	6
el0_irq:
	kernel_entry 0
el0_irq_naked:
J
James Morse 已提交
782
	enable_da_f
C
Catalin Marinas 已提交
783 784 785
#ifdef CONFIG_TRACE_IRQFLAGS
	bl	trace_hardirqs_off
#endif
786

L
Larry Bassel 已提交
787
	ct_user_exit
C
Catalin Marinas 已提交
788
	irq_handler
789

C
Catalin Marinas 已提交
790 791 792 793 794 795
#ifdef CONFIG_TRACE_IRQFLAGS
	bl	trace_hardirqs_on
#endif
	b	ret_to_user
ENDPROC(el0_irq)

796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817
el1_error:
	kernel_entry 1
	mrs	x1, esr_el1
	enable_dbg
	mov	x0, sp
	bl	do_serror
	kernel_exit 1
ENDPROC(el1_error)

el0_error:
	kernel_entry 0
el0_error_naked:
	mrs	x1, esr_el1
	enable_dbg
	mov	x0, sp
	bl	do_serror
	enable_daif
	ct_user_exit
	b	ret_to_user
ENDPROC(el0_error)


C
Catalin Marinas 已提交
818 819 820 821 822
/*
 * This is the fast syscall return path.  We do as little as possible here,
 * and this includes saving x0 back into the kernel stack.
 */
ret_fast_syscall:
823
	disable_daif
824
	str	x0, [sp, #S_X0]			// returned x0
825
	ldr	x1, [tsk, #TSK_TI_FLAGS]	// re-check for syscall tracing
826 827
	and	x2, x1, #_TIF_SYSCALL_WORK
	cbnz	x2, ret_fast_syscall_trace
C
Catalin Marinas 已提交
828
	and	x2, x1, #_TIF_WORK_MASK
829
	cbnz	x2, work_pending
830
	enable_step_tsk x1, x2
831
	kernel_exit 0
832
ret_fast_syscall_trace:
833
	enable_daif
834
	b	__sys_trace_return_skipped	// we already saved x0
C
Catalin Marinas 已提交
835 836 837 838 839 840 841

/*
 * Ok, we need to do extra processing, enter the slow path.
 */
work_pending:
	mov	x0, sp				// 'regs'
	bl	do_notify_resume
842
#ifdef CONFIG_TRACE_IRQFLAGS
843
	bl	trace_hardirqs_on		// enabled while in userspace
844
#endif
845
	ldr	x1, [tsk, #TSK_TI_FLAGS]	// re-check for single-step
846
	b	finish_ret_to_user
C
Catalin Marinas 已提交
847 848 849
/*
 * "slow" syscall return path.
 */
850
ret_to_user:
851
	disable_daif
852
	ldr	x1, [tsk, #TSK_TI_FLAGS]
C
Catalin Marinas 已提交
853 854
	and	x2, x1, #_TIF_WORK_MASK
	cbnz	x2, work_pending
855
finish_ret_to_user:
856
	enable_step_tsk x1, x2
857
	kernel_exit 0
C
Catalin Marinas 已提交
858 859 860 861 862 863 864
ENDPROC(ret_to_user)

/*
 * SVC handler.
 */
	.align	6
el0_svc:
865
	ldr	x16, [tsk, #TSK_TI_FLAGS]	// load thread flags
C
Catalin Marinas 已提交
866
	adrp	stbl, sys_call_table		// load syscall table pointer
867 868
	mov	wscno, w8			// syscall number in w8
	mov	wsc_nr, #__NR_syscalls
869

870 871
#ifdef CONFIG_ARM64_SVE
alternative_if_not ARM64_SVE
872
	b	el0_svc_naked
873
alternative_else_nop_endif
874 875 876 877 878 879 880 881 882 883 884 885 886 887
	tbz	x16, #TIF_SVE, el0_svc_naked	// Skip unless TIF_SVE set:
	bic	x16, x16, #_TIF_SVE		// discard SVE state
	str	x16, [tsk, #TSK_TI_FLAGS]

	/*
	 * task_fpsimd_load() won't be called to update CPACR_EL1 in
	 * ret_to_user unless TIF_FOREIGN_FPSTATE is still set, which only
	 * happens if a context switch or kernel_neon_begin() or context
	 * modification (sigreturn, ptrace) intervenes.
	 * So, ensure that CPACR_EL1 is already correct for the fast-path case:
	 */
	mrs	x9, cpacr_el1
	bic	x9, x9, #CPACR_EL1_ZEN_EL0EN	// disable SVE for el0
	msr	cpacr_el1, x9			// synchronised by eret to el0
888
#endif
889

C
Catalin Marinas 已提交
890
el0_svc_naked:					// compat entry point
891
	stp	x0, xscno, [sp, #S_ORIG_X0]	// save the original x0 and syscall number
J
James Morse 已提交
892
	enable_daif
L
Larry Bassel 已提交
893
	ct_user_exit 1
C
Catalin Marinas 已提交
894

895
	tst	x16, #_TIF_SYSCALL_WORK		// check for syscall hooks
896
	b.ne	__sys_trace
897
	cmp     wscno, wsc_nr			// check upper syscall limit
C
Catalin Marinas 已提交
898
	b.hs	ni_sys
899
	ldr	x16, [stbl, xscno, lsl #3]	// address in the syscall table
900 901
	blr	x16				// call sys_* routine
	b	ret_fast_syscall
C
Catalin Marinas 已提交
902 903
ni_sys:
	mov	x0, sp
904 905
	bl	do_ni_syscall
	b	ret_fast_syscall
C
Catalin Marinas 已提交
906 907 908 909 910 911 912
ENDPROC(el0_svc)

	/*
	 * This is the really slow path.  We're going to be doing context
	 * switches, and waiting for our parent to respond.
	 */
__sys_trace:
913
	cmp     wscno, #NO_SYSCALL		// user-issued syscall(-1)?
914
	b.ne	1f
915
	mov	x0, #-ENOSYS			// set default errno if so
916 917
	str	x0, [sp, #S_X0]
1:	mov	x0, sp
918
	bl	syscall_trace_enter
919
	cmp	w0, #NO_SYSCALL			// skip the syscall?
920
	b.eq	__sys_trace_return_skipped
921
	mov	wscno, w0			// syscall number (possibly new)
C
Catalin Marinas 已提交
922
	mov	x1, sp				// pointer to regs
923
	cmp	wscno, wsc_nr			// check upper syscall limit
924
	b.hs	__ni_sys_trace
C
Catalin Marinas 已提交
925 926 927 928
	ldp	x0, x1, [sp]			// restore the syscall args
	ldp	x2, x3, [sp, #S_X2]
	ldp	x4, x5, [sp, #S_X4]
	ldp	x6, x7, [sp, #S_X6]
929
	ldr	x16, [stbl, xscno, lsl #3]	// address in the syscall table
930
	blr	x16				// call sys_* routine
C
Catalin Marinas 已提交
931 932

__sys_trace_return:
933 934
	str	x0, [sp, #S_X0]			// save returned x0
__sys_trace_return_skipped:
935 936
	mov	x0, sp
	bl	syscall_trace_exit
C
Catalin Marinas 已提交
937 938
	b	ret_to_user

939 940 941 942 943
__ni_sys_trace:
	mov	x0, sp
	bl	do_ni_syscall
	b	__sys_trace_return

944 945
	.popsection				// .entry.text

C
Catalin Marinas 已提交
946 947 948 949 950 951 952
/*
 * Special system call wrappers.
 */
ENTRY(sys_rt_sigreturn_wrapper)
	mov	x0, sp
	b	sys_rt_sigreturn
ENDPROC(sys_rt_sigreturn_wrapper)
953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998

/*
 * Register switch for AArch64. The callee-saved registers need to be saved
 * and restored. On entry:
 *   x0 = previous task_struct (must be preserved across the switch)
 *   x1 = next task_struct
 * Previous and next are guaranteed not to be the same.
 *
 */
ENTRY(cpu_switch_to)
	mov	x10, #THREAD_CPU_CONTEXT
	add	x8, x0, x10
	mov	x9, sp
	stp	x19, x20, [x8], #16		// store callee-saved registers
	stp	x21, x22, [x8], #16
	stp	x23, x24, [x8], #16
	stp	x25, x26, [x8], #16
	stp	x27, x28, [x8], #16
	stp	x29, x9, [x8], #16
	str	lr, [x8]
	add	x8, x1, x10
	ldp	x19, x20, [x8], #16		// restore callee-saved registers
	ldp	x21, x22, [x8], #16
	ldp	x23, x24, [x8], #16
	ldp	x25, x26, [x8], #16
	ldp	x27, x28, [x8], #16
	ldp	x29, x9, [x8], #16
	ldr	lr, [x8]
	mov	sp, x9
	msr	sp_el0, x1
	ret
ENDPROC(cpu_switch_to)
NOKPROBE(cpu_switch_to)

/*
 * This is how we return from a fork.
 */
ENTRY(ret_from_fork)
	bl	schedule_tail
	cbz	x19, 1f				// not a kernel thread
	mov	x0, x20
	blr	x19
1:	get_thread_info tsk
	b	ret_to_user
ENDPROC(ret_from_fork)
NOKPROBE(ret_from_fork)