process_64.c 17.5 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5
/*
 *  Copyright (C) 1995  Linus Torvalds
 *
 *  Pentium III FXSR, SSE support
 *	Gareth Hughes <gareth@valinux.com>, May 2000
6
 *
L
Linus Torvalds 已提交
7 8
 *  X86-64 port
 *	Andi Kleen.
A
Ashok Raj 已提交
9 10
 *
 *	CPU hotplug support - ashok.raj@intel.com
L
Linus Torvalds 已提交
11 12 13 14 15 16
 */

/*
 * This file handles the architecture-dependent parts of process handling..
 */

A
Ashok Raj 已提交
17
#include <linux/cpu.h>
L
Linus Torvalds 已提交
18 19
#include <linux/errno.h>
#include <linux/sched.h>
20
#include <linux/fs.h>
L
Linus Torvalds 已提交
21 22 23 24 25 26 27 28
#include <linux/kernel.h>
#include <linux/mm.h>
#include <linux/elfcore.h>
#include <linux/smp.h>
#include <linux/slab.h>
#include <linux/user.h>
#include <linux/interrupt.h>
#include <linux/delay.h>
29
#include <linux/module.h>
L
Linus Torvalds 已提交
30
#include <linux/ptrace.h>
A
Andi Kleen 已提交
31
#include <linux/notifier.h>
32
#include <linux/kprobes.h>
33
#include <linux/kdebug.h>
34
#include <linux/prctl.h>
35 36
#include <linux/uaccess.h>
#include <linux/io.h>
37
#include <linux/ftrace.h>
L
Linus Torvalds 已提交
38 39 40

#include <asm/pgtable.h>
#include <asm/processor.h>
41
#include <asm/fpu/internal.h>
L
Linus Torvalds 已提交
42 43 44 45 46
#include <asm/mmu_context.h>
#include <asm/prctl.h>
#include <asm/desc.h>
#include <asm/proto.h>
#include <asm/ia32.h>
A
Andi Kleen 已提交
47
#include <asm/idle.h>
48
#include <asm/syscalls.h>
49
#include <asm/debugreg.h>
50
#include <asm/switch_to.h>
51
#include <asm/xen/hypervisor.h>
L
Linus Torvalds 已提交
52 53 54

asmlinkage extern void ret_from_fork(void);

55
__visible DEFINE_PER_CPU(unsigned long, rsp_scratch);
L
Linus Torvalds 已提交
56

57
/* Prints also some state that isn't saved in the pt_regs */
58
void __show_regs(struct pt_regs *regs, int all)
L
Linus Torvalds 已提交
59 60
{
	unsigned long cr0 = 0L, cr2 = 0L, cr3 = 0L, cr4 = 0L, fs, gs, shadowgs;
61
	unsigned long d0, d1, d2, d3, d6, d7;
62 63
	unsigned int fsindex, gsindex;
	unsigned int ds, cs, es;
64

65
	printk(KERN_DEFAULT "RIP: %04lx:[<%016lx>] ", regs->cs & 0xffff, regs->ip);
66
	printk_address(regs->ip);
67
	printk(KERN_DEFAULT "RSP: %04lx:%016lx  EFLAGS: %08lx\n", regs->ss,
68
			regs->sp, regs->flags);
69
	printk(KERN_DEFAULT "RAX: %016lx RBX: %016lx RCX: %016lx\n",
70
	       regs->ax, regs->bx, regs->cx);
71
	printk(KERN_DEFAULT "RDX: %016lx RSI: %016lx RDI: %016lx\n",
72
	       regs->dx, regs->si, regs->di);
73
	printk(KERN_DEFAULT "RBP: %016lx R08: %016lx R09: %016lx\n",
74
	       regs->bp, regs->r8, regs->r9);
75
	printk(KERN_DEFAULT "R10: %016lx R11: %016lx R12: %016lx\n",
76
	       regs->r10, regs->r11, regs->r12);
77
	printk(KERN_DEFAULT "R13: %016lx R14: %016lx R15: %016lx\n",
78
	       regs->r13, regs->r14, regs->r15);
L
Linus Torvalds 已提交
79

80 81 82
	asm("movl %%ds,%0" : "=r" (ds));
	asm("movl %%cs,%0" : "=r" (cs));
	asm("movl %%es,%0" : "=r" (es));
L
Linus Torvalds 已提交
83 84 85 86
	asm("movl %%fs,%0" : "=r" (fsindex));
	asm("movl %%gs,%0" : "=r" (gsindex));

	rdmsrl(MSR_FS_BASE, fs);
87 88
	rdmsrl(MSR_GS_BASE, gs);
	rdmsrl(MSR_KERNEL_GS_BASE, shadowgs);
L
Linus Torvalds 已提交
89

90 91
	if (!all)
		return;
L
Linus Torvalds 已提交
92

93 94 95
	cr0 = read_cr0();
	cr2 = read_cr2();
	cr3 = read_cr3();
96
	cr4 = __read_cr4();
L
Linus Torvalds 已提交
97

98
	printk(KERN_DEFAULT "FS:  %016lx(%04x) GS:%016lx(%04x) knlGS:%016lx\n",
99
	       fs, fsindex, gs, gsindex, shadowgs);
100
	printk(KERN_DEFAULT "CS:  %04x DS: %04x ES: %04x CR0: %016lx\n", cs, ds,
101
			es, cr0);
102
	printk(KERN_DEFAULT "CR2: %016lx CR3: %016lx CR4: %016lx\n", cr2, cr3,
103
			cr4);
104 105 106 107 108 109 110

	get_debugreg(d0, 0);
	get_debugreg(d1, 1);
	get_debugreg(d2, 2);
	get_debugreg(d3, 3);
	get_debugreg(d6, 6);
	get_debugreg(d7, 7);
111 112 113 114 115 116 117

	/* Only print out debug registers if they are in their non-default state. */
	if ((d0 == 0) && (d1 == 0) && (d2 == 0) && (d3 == 0) &&
	    (d6 == DR6_RESERVED) && (d7 == 0x400))
		return;

	printk(KERN_DEFAULT "DR0: %016lx DR1: %016lx DR2: %016lx\n", d0, d1, d2);
118
	printk(KERN_DEFAULT "DR3: %016lx DR6: %016lx DR7: %016lx\n", d3, d6, d7);
119

120 121
	if (boot_cpu_has(X86_FEATURE_OSPKE))
		printk(KERN_DEFAULT "PKRU: %08x\n", read_pkru());
L
Linus Torvalds 已提交
122 123 124 125 126
}

void release_thread(struct task_struct *dead_task)
{
	if (dead_task->mm) {
127
#ifdef CONFIG_MODIFY_LDT_SYSCALL
128
		if (dead_task->mm->context.ldt) {
129
			pr_warn("WARNING: dead process %s still has LDT? <%p/%d>\n",
130
				dead_task->comm,
131
				dead_task->mm->context.ldt->entries,
132
				dead_task->mm->context.ldt->size);
L
Linus Torvalds 已提交
133 134
			BUG();
		}
135
#endif
L
Linus Torvalds 已提交
136 137 138 139 140
	}
}

static inline void set_32bit_tls(struct task_struct *t, int tls, u32 addr)
{
141
	struct user_desc ud = {
L
Linus Torvalds 已提交
142 143 144 145 146 147
		.base_addr = addr,
		.limit = 0xfffff,
		.seg_32bit = 1,
		.limit_in_pages = 1,
		.useable = 1,
	};
J
Jan Engelhardt 已提交
148
	struct desc_struct *desc = t->thread.tls_array;
L
Linus Torvalds 已提交
149
	desc += tls;
150
	fill_ldt(desc, &ud);
L
Linus Torvalds 已提交
151 152 153 154
}

static inline u32 read_32bit_tls(struct task_struct *t, int tls)
{
R
Roland McGrath 已提交
155
	return get_desc_base(&t->thread.tls_array[tls]);
L
Linus Torvalds 已提交
156 157
}

158 159
int copy_thread_tls(unsigned long clone_flags, unsigned long sp,
		unsigned long arg, struct task_struct *p, unsigned long tls)
L
Linus Torvalds 已提交
160 161
{
	int err;
162
	struct pt_regs *childregs;
L
Linus Torvalds 已提交
163 164
	struct task_struct *me = current;

A
Al Viro 已提交
165 166
	p->thread.sp0 = (unsigned long)task_stack_page(p) + THREAD_SIZE;
	childregs = task_pt_regs(p);
167
	p->thread.sp = (unsigned long) childregs;
A
Al Viro 已提交
168
	set_tsk_thread_flag(p, TIF_FORK);
169
	p->thread.io_bitmap_ptr = NULL;
L
Linus Torvalds 已提交
170

171
	savesegment(gs, p->thread.gsindex);
172
	p->thread.gs = p->thread.gsindex ? 0 : me->thread.gs;
173
	savesegment(fs, p->thread.fsindex);
174
	p->thread.fs = p->thread.fsindex ? 0 : me->thread.fs;
175 176
	savesegment(es, p->thread.es);
	savesegment(ds, p->thread.ds);
A
Al Viro 已提交
177 178
	memset(p->thread.ptrace_bps, 0, sizeof(p->thread.ptrace_bps));

179
	if (unlikely(p->flags & PF_KTHREAD)) {
A
Al Viro 已提交
180 181 182 183 184 185 186 187
		/* kernel thread */
		memset(childregs, 0, sizeof(struct pt_regs));
		childregs->sp = (unsigned long)childregs;
		childregs->ss = __KERNEL_DS;
		childregs->bx = sp; /* function */
		childregs->bp = arg;
		childregs->orig_ax = -1;
		childregs->cs = __KERNEL_CS | get_kernel_rpl();
188
		childregs->flags = X86_EFLAGS_IF | X86_EFLAGS_FIXED;
A
Al Viro 已提交
189 190
		return 0;
	}
191
	*childregs = *current_pt_regs();
A
Al Viro 已提交
192 193

	childregs->ax = 0;
194 195
	if (sp)
		childregs->sp = sp;
L
Linus Torvalds 已提交
196

197
	err = -ENOMEM;
198
	if (unlikely(test_tsk_thread_flag(me, TIF_IO_BITMAP))) {
199 200
		p->thread.io_bitmap_ptr = kmemdup(me->thread.io_bitmap_ptr,
						  IO_BITMAP_BYTES, GFP_KERNEL);
L
Linus Torvalds 已提交
201 202 203 204
		if (!p->thread.io_bitmap_ptr) {
			p->thread.io_bitmap_max = 0;
			return -ENOMEM;
		}
205
		set_tsk_thread_flag(p, TIF_IO_BITMAP);
206
	}
L
Linus Torvalds 已提交
207 208 209 210 211 212

	/*
	 * Set a new TLS for the child thread?
	 */
	if (clone_flags & CLONE_SETTLS) {
#ifdef CONFIG_IA32_EMULATION
213
		if (is_ia32_task())
R
Roland McGrath 已提交
214
			err = do_set_thread_area(p, -1,
215
				(struct user_desc __user *)tls, 0);
216 217
		else
#endif
218
			err = do_arch_prctl(p, ARCH_SET_FS, tls);
219
		if (err)
L
Linus Torvalds 已提交
220 221 222 223 224 225 226 227
			goto out;
	}
	err = 0;
out:
	if (err && p->thread.io_bitmap_ptr) {
		kfree(p->thread.io_bitmap_ptr);
		p->thread.io_bitmap_max = 0;
	}
228

L
Linus Torvalds 已提交
229 230 231
	return err;
}

232 233 234 235
static void
start_thread_common(struct pt_regs *regs, unsigned long new_ip,
		    unsigned long new_sp,
		    unsigned int _cs, unsigned int _ss, unsigned int _ds)
I
Ingo Molnar 已提交
236
{
237
	loadsegment(fs, 0);
238 239
	loadsegment(es, _ds);
	loadsegment(ds, _ds);
I
Ingo Molnar 已提交
240 241 242
	load_gs_index(0);
	regs->ip		= new_ip;
	regs->sp		= new_sp;
243 244
	regs->cs		= _cs;
	regs->ss		= _ss;
245
	regs->flags		= X86_EFLAGS_IF;
246
	force_iret();
I
Ingo Molnar 已提交
247
}
248 249 250 251 252 253 254

void
start_thread(struct pt_regs *regs, unsigned long new_ip, unsigned long new_sp)
{
	start_thread_common(regs, new_ip, new_sp,
			    __USER_CS, __USER_DS, 0);
}
I
Ingo Molnar 已提交
255

256 257
#ifdef CONFIG_COMPAT
void compat_start_thread(struct pt_regs *regs, u32 new_ip, u32 new_sp)
258
{
259
	start_thread_common(regs, new_ip, new_sp,
H
H. Peter Anvin 已提交
260 261 262
			    test_thread_flag(TIF_X32)
			    ? __USER_CS : __USER32_CS,
			    __USER_DS, __USER_DS);
263 264
}
#endif
I
Ingo Molnar 已提交
265

L
Linus Torvalds 已提交
266 267 268
/*
 *	switch_to(x,y) should switch tasks from x to y.
 *
269
 * This could still be optimized:
L
Linus Torvalds 已提交
270 271
 * - fold all the options into a flag word and test it with a single test.
 * - could test fs/gs bitsliced
272 273
 *
 * Kprobes not supported here. Set the probe on schedule instead.
274
 * Function graph tracer not supported too.
L
Linus Torvalds 已提交
275
 */
276
__visible __notrace_funcgraph struct task_struct *
277
__switch_to(struct task_struct *prev_p, struct task_struct *next_p)
L
Linus Torvalds 已提交
278
{
279 280
	struct thread_struct *prev = &prev_p->thread;
	struct thread_struct *next = &next_p->thread;
281 282
	struct fpu *prev_fpu = &prev->fpu;
	struct fpu *next_fpu = &next->fpu;
283
	int cpu = smp_processor_id();
284
	struct tss_struct *tss = &per_cpu(cpu_tss, cpu);
285
	unsigned prev_fsindex, prev_gsindex;
286
	fpu_switch_t fpu_switch;
287

288
	fpu_switch = switch_fpu_prepare(prev_fpu, next_fpu, cpu);
289

290 291 292 293 294
	/* We must save %fs and %gs before load_TLS() because
	 * %fs and %gs may be cleared by load_TLS().
	 *
	 * (e.g. xen_load_tls())
	 */
295 296
	savesegment(fs, prev_fsindex);
	savesegment(gs, prev_gsindex);
297

298 299 300 301
	/*
	 * Load TLS before restoring any segments so that segment loads
	 * reference the correct GDT entries.
	 */
L
Linus Torvalds 已提交
302 303
	load_TLS(next, cpu);

304
	/*
305 306 307
	 * Leave lazy mode, flushing any hypercalls made here.  This
	 * must be done after loading TLS entries in the GDT but before
	 * loading segments that might reference them, and and it must
308
	 * be done before fpu__restore(), so the TS bit is up to
309
	 * date.
310
	 */
311
	arch_end_context_switch(next_p);
312

313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334
	/* Switch DS and ES.
	 *
	 * Reading them only returns the selectors, but writing them (if
	 * nonzero) loads the full descriptor from the GDT or LDT.  The
	 * LDT for next is loaded in switch_mm, and the GDT is loaded
	 * above.
	 *
	 * We therefore need to write new values to the segment
	 * registers on every context switch unless both the new and old
	 * values are zero.
	 *
	 * Note that we don't need to do anything for CS and SS, as
	 * those are saved and restored as part of pt_regs.
	 */
	savesegment(es, prev->es);
	if (unlikely(next->es | prev->es))
		loadsegment(es, next->es);

	savesegment(ds, prev->ds);
	if (unlikely(next->ds | prev->ds))
		loadsegment(ds, next->ds);

335
	/*
L
Linus Torvalds 已提交
336
	 * Switch FS and GS.
337
	 *
338
	 * These are even more complicated than DS and ES: they have
339 340 341
	 * 64-bit bases are that controlled by arch_prctl.  The bases
	 * don't necessarily match the selectors, as user code can do
	 * any number of things to cause them to be inconsistent.
342
	 *
343 344 345 346 347 348
	 * We don't promise to preserve the bases if the selectors are
	 * nonzero.  We also don't promise to preserve the base if the
	 * selector is zero and the base doesn't match whatever was
	 * most recently passed to ARCH_SET_FS/GS.  (If/when the
	 * FSGSBASE instructions are enabled, we'll need to offer
	 * stronger guarantees.)
349
	 *
350 351 352
	 * As an invariant,
	 * (fs != 0 && fsindex != 0) || (gs != 0 && gsindex != 0) is
	 * impossible.
L
Linus Torvalds 已提交
353
	 */
354 355
	if (next->fsindex) {
		/* Loading a nonzero value into FS sets the index and base. */
356
		loadsegment(fs, next->fsindex);
357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381
	} else {
		if (next->fs) {
			/* Next index is zero but next base is nonzero. */
			if (prev_fsindex)
				loadsegment(fs, 0);
			wrmsrl(MSR_FS_BASE, next->fs);
		} else {
			/* Next base and index are both zero. */
			if (static_cpu_has_bug(X86_BUG_NULL_SEG)) {
				/*
				 * We don't know the previous base and can't
				 * find out without RDMSR.  Forcibly clear it.
				 */
				loadsegment(fs, __USER_DS);
				loadsegment(fs, 0);
			} else {
				/*
				 * If the previous index is zero and ARCH_SET_FS
				 * didn't change the base, then the base is
				 * also zero and we don't need to do anything.
				 */
				if (prev->fs || prev_fsindex)
					loadsegment(fs, 0);
			}
		}
L
Linus Torvalds 已提交
382
	}
383 384 385 386 387 388 389 390 391 392
	/*
	 * Save the old state and preserve the invariant.
	 * NB: if prev_fsindex == 0, then we can't reliably learn the base
	 * without RDMSR because Intel user code can zero it without telling
	 * us and AMD user code can program any 32-bit value without telling
	 * us.
	 */
	if (prev_fsindex)
		prev->fs = 0;
	prev->fsindex = prev_fsindex;
393

394 395
	if (next->gsindex) {
		/* Loading a nonzero value into GS sets the index and base. */
396
		load_gs_index(next->gsindex);
397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425
	} else {
		if (next->gs) {
			/* Next index is zero but next base is nonzero. */
			if (prev_gsindex)
				load_gs_index(0);
			wrmsrl(MSR_KERNEL_GS_BASE, next->gs);
		} else {
			/* Next base and index are both zero. */
			if (static_cpu_has_bug(X86_BUG_NULL_SEG)) {
				/*
				 * We don't know the previous base and can't
				 * find out without RDMSR.  Forcibly clear it.
				 *
				 * This contains a pointless SWAPGS pair.
				 * Fixing it would involve an explicit check
				 * for Xen or a new pvop.
				 */
				load_gs_index(__USER_DS);
				load_gs_index(0);
			} else {
				/*
				 * If the previous index is zero and ARCH_SET_GS
				 * didn't change the base, then the base is
				 * also zero and we don't need to do anything.
				 */
				if (prev->gs || prev_gsindex)
					load_gs_index(0);
			}
		}
L
Linus Torvalds 已提交
426
	}
427 428 429 430 431 432 433 434 435 436
	/*
	 * Save the old state and preserve the invariant.
	 * NB: if prev_gsindex == 0, then we can't reliably learn the base
	 * without RDMSR because Intel user code can zero it without telling
	 * us and AMD user code can program any 32-bit value without telling
	 * us.
	 */
	if (prev_gsindex)
		prev->gs = 0;
	prev->gsindex = prev_gsindex;
L
Linus Torvalds 已提交
437

438
	switch_fpu_finish(next_fpu, fpu_switch);
439

440
	/*
441
	 * Switch the PDA and FPU contexts.
L
Linus Torvalds 已提交
442
	 */
443
	this_cpu_write(current_task, next_p);
444

445 446 447
	/* Reload esp0 and ss1.  This changes current_thread_info(). */
	load_sp0(tss, next);

L
Linus Torvalds 已提交
448
	/*
449
	 * Now maybe reload the debug registers and handle I/O bitmaps
L
Linus Torvalds 已提交
450
	 */
451 452
	if (unlikely(task_thread_info(next_p)->flags & _TIF_WORK_CTXSW_NEXT ||
		     task_thread_info(prev_p)->flags & _TIF_WORK_CTXSW_PREV))
453
		__switch_to_xtra(prev_p, next_p, tss);
L
Linus Torvalds 已提交
454

455 456 457 458 459 460 461 462 463 464 465
#ifdef CONFIG_XEN
	/*
	 * On Xen PV, IOPL bits in pt_regs->flags have no effect, and
	 * current_pt_regs()->flags may not match the current task's
	 * intended IOPL.  We need to switch it manually.
	 */
	if (unlikely(static_cpu_has(X86_FEATURE_XENPV) &&
		     prev->iopl != next->iopl))
		xen_set_iopl_mask(next->iopl);
#endif

466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493
	if (static_cpu_has_bug(X86_BUG_SYSRET_SS_ATTRS)) {
		/*
		 * AMD CPUs have a misfeature: SYSRET sets the SS selector but
		 * does not update the cached descriptor.  As a result, if we
		 * do SYSRET while SS is NULL, we'll end up in user mode with
		 * SS apparently equal to __USER_DS but actually unusable.
		 *
		 * The straightforward workaround would be to fix it up just
		 * before SYSRET, but that would slow down the system call
		 * fast paths.  Instead, we ensure that SS is never NULL in
		 * system call context.  We do this by replacing NULL SS
		 * selectors at every context switch.  SYSCALL sets up a valid
		 * SS, so the only way to get NULL is to re-enter the kernel
		 * from CPL 3 through an interrupt.  Since that can't happen
		 * in the same task as a running syscall, we are guaranteed to
		 * context switch between every interrupt vector entry and a
		 * subsequent SYSRET.
		 *
		 * We read SS first because SS reads are much faster than
		 * writes.  Out of caution, we force SS to __KERNEL_DS even if
		 * it previously had a different non-NULL value.
		 */
		unsigned short ss_sel;
		savesegment(ss, ss_sel);
		if (ss_sel != __KERNEL_DS)
			loadsegment(ss, __KERNEL_DS);
	}

L
Linus Torvalds 已提交
494 495 496 497 498 499 500 501
	return prev_p;
}

void set_personality_64bit(void)
{
	/* inherit personality from parent */

	/* Make sure to be in 64bit mode */
502
	clear_thread_flag(TIF_IA32);
503
	clear_thread_flag(TIF_ADDR32);
504
	clear_thread_flag(TIF_X32);
L
Linus Torvalds 已提交
505

506 507 508 509
	/* Ensure the corresponding mm is not marked. */
	if (current->mm)
		current->mm->context.ia32_compat = 0;

L
Linus Torvalds 已提交
510 511 512
	/* TBD: overwrites user setup. Should have two bits.
	   But 64bit processes have always behaved this way,
	   so it's not too bad. The main problem is just that
513
	   32bit childs are affected again. */
L
Linus Torvalds 已提交
514 515 516
	current->personality &= ~READ_IMPLIES_EXEC;
}

H
H. Peter Anvin 已提交
517
void set_personality_ia32(bool x32)
518 519 520 521
{
	/* inherit personality from parent */

	/* Make sure to be in 32bit mode */
522
	set_thread_flag(TIF_ADDR32);
523

524
	/* Mark the associated mm as containing 32-bit tasks. */
H
H. Peter Anvin 已提交
525 526 527
	if (x32) {
		clear_thread_flag(TIF_IA32);
		set_thread_flag(TIF_X32);
528 529
		if (current->mm)
			current->mm->context.ia32_compat = TIF_X32;
H
H. Peter Anvin 已提交
530
		current->personality &= ~READ_IMPLIES_EXEC;
531
		/* in_compat_syscall() uses the presence of the x32
532 533
		   syscall bit flag to determine compat status */
		current_thread_info()->status &= ~TS_COMPAT;
H
H. Peter Anvin 已提交
534 535 536
	} else {
		set_thread_flag(TIF_IA32);
		clear_thread_flag(TIF_X32);
537 538
		if (current->mm)
			current->mm->context.ia32_compat = TIF_IA32;
H
H. Peter Anvin 已提交
539 540 541 542
		current->personality |= force_personality32;
		/* Prepare the first "return" to user space */
		current_thread_info()->status |= TS_COMPAT;
	}
543
}
544
EXPORT_SYMBOL_GPL(set_personality_ia32);
545

L
Linus Torvalds 已提交
546
long do_arch_prctl(struct task_struct *task, int code, unsigned long addr)
547 548
{
	int ret = 0;
L
Linus Torvalds 已提交
549 550 551
	int doit = task == current;
	int cpu;

552
	switch (code) {
L
Linus Torvalds 已提交
553
	case ARCH_SET_GS:
554
		if (addr >= TASK_SIZE_OF(task))
555
			return -EPERM;
L
Linus Torvalds 已提交
556
		cpu = get_cpu();
557
		/* handle small bases via the GDT because that's faster to
L
Linus Torvalds 已提交
558
		   switch. */
559 560 561
		if (addr <= 0xffffffff) {
			set_32bit_tls(task, GS_TLS, addr);
			if (doit) {
L
Linus Torvalds 已提交
562
				load_TLS(&task->thread, cpu);
563
				load_gs_index(GS_TLS_SEL);
L
Linus Torvalds 已提交
564
			}
565
			task->thread.gsindex = GS_TLS_SEL;
L
Linus Torvalds 已提交
566
			task->thread.gs = 0;
567
		} else {
L
Linus Torvalds 已提交
568 569 570
			task->thread.gsindex = 0;
			task->thread.gs = addr;
			if (doit) {
571
				load_gs_index(0);
572
				ret = wrmsrl_safe(MSR_KERNEL_GS_BASE, addr);
573
			}
L
Linus Torvalds 已提交
574 575 576 577 578 579
		}
		put_cpu();
		break;
	case ARCH_SET_FS:
		/* Not strictly needed for fs, but do it for symmetry
		   with gs */
580
		if (addr >= TASK_SIZE_OF(task))
581
			return -EPERM;
L
Linus Torvalds 已提交
582
		cpu = get_cpu();
583
		/* handle small bases via the GDT because that's faster to
L
Linus Torvalds 已提交
584
		   switch. */
585
		if (addr <= 0xffffffff) {
L
Linus Torvalds 已提交
586
			set_32bit_tls(task, FS_TLS, addr);
587 588
			if (doit) {
				load_TLS(&task->thread, cpu);
589
				loadsegment(fs, FS_TLS_SEL);
L
Linus Torvalds 已提交
590 591 592
			}
			task->thread.fsindex = FS_TLS_SEL;
			task->thread.fs = 0;
593
		} else {
L
Linus Torvalds 已提交
594 595 596 597 598
			task->thread.fsindex = 0;
			task->thread.fs = addr;
			if (doit) {
				/* set the selector to 0 to not confuse
				   __switch_to */
599
				loadsegment(fs, 0);
600
				ret = wrmsrl_safe(MSR_FS_BASE, addr);
L
Linus Torvalds 已提交
601 602 603 604
			}
		}
		put_cpu();
		break;
605 606
	case ARCH_GET_FS: {
		unsigned long base;
607
		if (doit)
L
Linus Torvalds 已提交
608
			rdmsrl(MSR_FS_BASE, base);
609 610
		else if (task->thread.fsindex == FS_TLS_SEL)
			base = read_32bit_tls(task, FS_TLS);
611
		else
L
Linus Torvalds 已提交
612
			base = task->thread.fs;
613 614
		ret = put_user(base, (unsigned long __user *)addr);
		break;
L
Linus Torvalds 已提交
615
	}
616
	case ARCH_GET_GS: {
L
Linus Torvalds 已提交
617
		unsigned long base;
618 619 620
		if (doit)
			rdmsrl(MSR_KERNEL_GS_BASE, base);
		else if (task->thread.gsindex == GS_TLS_SEL)
L
Linus Torvalds 已提交
621
			base = read_32bit_tls(task, GS_TLS);
622
		else
L
Linus Torvalds 已提交
623
			base = task->thread.gs;
624
		ret = put_user(base, (unsigned long __user *)addr);
L
Linus Torvalds 已提交
625 626 627 628 629 630
		break;
	}

	default:
		ret = -EINVAL;
		break;
631
	}
L
Linus Torvalds 已提交
632

633 634
	return ret;
}
L
Linus Torvalds 已提交
635 636 637 638 639 640

long sys_arch_prctl(int code, unsigned long addr)
{
	return do_arch_prctl(current, code, addr);
}

641 642
unsigned long KSTK_ESP(struct task_struct *task)
{
643
	return task_pt_regs(task)->sp;
644
}