process_64.c 18.0 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5
/*
 *  Copyright (C) 1995  Linus Torvalds
 *
 *  Pentium III FXSR, SSE support
 *	Gareth Hughes <gareth@valinux.com>, May 2000
6
 *
L
Linus Torvalds 已提交
7 8
 *  X86-64 port
 *	Andi Kleen.
A
Ashok Raj 已提交
9 10
 *
 *	CPU hotplug support - ashok.raj@intel.com
L
Linus Torvalds 已提交
11 12 13 14 15 16
 */

/*
 * This file handles the architecture-dependent parts of process handling..
 */

A
Ashok Raj 已提交
17
#include <linux/cpu.h>
L
Linus Torvalds 已提交
18 19
#include <linux/errno.h>
#include <linux/sched.h>
20
#include <linux/fs.h>
L
Linus Torvalds 已提交
21 22 23 24 25 26 27 28
#include <linux/kernel.h>
#include <linux/mm.h>
#include <linux/elfcore.h>
#include <linux/smp.h>
#include <linux/slab.h>
#include <linux/user.h>
#include <linux/interrupt.h>
#include <linux/delay.h>
29
#include <linux/module.h>
L
Linus Torvalds 已提交
30
#include <linux/ptrace.h>
A
Andi Kleen 已提交
31
#include <linux/notifier.h>
32
#include <linux/kprobes.h>
33
#include <linux/kdebug.h>
34
#include <linux/prctl.h>
35 36
#include <linux/uaccess.h>
#include <linux/io.h>
37
#include <linux/ftrace.h>
L
Linus Torvalds 已提交
38 39 40

#include <asm/pgtable.h>
#include <asm/processor.h>
41
#include <asm/fpu/internal.h>
L
Linus Torvalds 已提交
42 43 44 45 46
#include <asm/mmu_context.h>
#include <asm/prctl.h>
#include <asm/desc.h>
#include <asm/proto.h>
#include <asm/ia32.h>
A
Andi Kleen 已提交
47
#include <asm/idle.h>
48
#include <asm/syscalls.h>
49
#include <asm/debugreg.h>
50
#include <asm/switch_to.h>
L
Linus Torvalds 已提交
51 52 53

asmlinkage extern void ret_from_fork(void);

54
__visible DEFINE_PER_CPU(unsigned long, rsp_scratch);
L
Linus Torvalds 已提交
55

56
/* Prints also some state that isn't saved in the pt_regs */
57
void __show_regs(struct pt_regs *regs, int all)
L
Linus Torvalds 已提交
58 59
{
	unsigned long cr0 = 0L, cr2 = 0L, cr3 = 0L, cr4 = 0L, fs, gs, shadowgs;
60
	unsigned long d0, d1, d2, d3, d6, d7;
61 62
	unsigned int fsindex, gsindex;
	unsigned int ds, cs, es;
63

64
	printk(KERN_DEFAULT "RIP: %04lx:[<%016lx>] ", regs->cs & 0xffff, regs->ip);
65
	printk_address(regs->ip);
66
	printk(KERN_DEFAULT "RSP: %04lx:%016lx  EFLAGS: %08lx\n", regs->ss,
67
			regs->sp, regs->flags);
68
	printk(KERN_DEFAULT "RAX: %016lx RBX: %016lx RCX: %016lx\n",
69
	       regs->ax, regs->bx, regs->cx);
70
	printk(KERN_DEFAULT "RDX: %016lx RSI: %016lx RDI: %016lx\n",
71
	       regs->dx, regs->si, regs->di);
72
	printk(KERN_DEFAULT "RBP: %016lx R08: %016lx R09: %016lx\n",
73
	       regs->bp, regs->r8, regs->r9);
74
	printk(KERN_DEFAULT "R10: %016lx R11: %016lx R12: %016lx\n",
75
	       regs->r10, regs->r11, regs->r12);
76
	printk(KERN_DEFAULT "R13: %016lx R14: %016lx R15: %016lx\n",
77
	       regs->r13, regs->r14, regs->r15);
L
Linus Torvalds 已提交
78

79 80 81
	asm("movl %%ds,%0" : "=r" (ds));
	asm("movl %%cs,%0" : "=r" (cs));
	asm("movl %%es,%0" : "=r" (es));
L
Linus Torvalds 已提交
82 83 84 85
	asm("movl %%fs,%0" : "=r" (fsindex));
	asm("movl %%gs,%0" : "=r" (gsindex));

	rdmsrl(MSR_FS_BASE, fs);
86 87
	rdmsrl(MSR_GS_BASE, gs);
	rdmsrl(MSR_KERNEL_GS_BASE, shadowgs);
L
Linus Torvalds 已提交
88

89 90
	if (!all)
		return;
L
Linus Torvalds 已提交
91

92 93 94
	cr0 = read_cr0();
	cr2 = read_cr2();
	cr3 = read_cr3();
95
	cr4 = __read_cr4();
L
Linus Torvalds 已提交
96

97
	printk(KERN_DEFAULT "FS:  %016lx(%04x) GS:%016lx(%04x) knlGS:%016lx\n",
98
	       fs, fsindex, gs, gsindex, shadowgs);
99
	printk(KERN_DEFAULT "CS:  %04x DS: %04x ES: %04x CR0: %016lx\n", cs, ds,
100
			es, cr0);
101
	printk(KERN_DEFAULT "CR2: %016lx CR3: %016lx CR4: %016lx\n", cr2, cr3,
102
			cr4);
103 104 105 106 107 108 109

	get_debugreg(d0, 0);
	get_debugreg(d1, 1);
	get_debugreg(d2, 2);
	get_debugreg(d3, 3);
	get_debugreg(d6, 6);
	get_debugreg(d7, 7);
110 111 112 113 114 115 116

	/* Only print out debug registers if they are in their non-default state. */
	if ((d0 == 0) && (d1 == 0) && (d2 == 0) && (d3 == 0) &&
	    (d6 == DR6_RESERVED) && (d7 == 0x400))
		return;

	printk(KERN_DEFAULT "DR0: %016lx DR1: %016lx DR2: %016lx\n", d0, d1, d2);
117
	printk(KERN_DEFAULT "DR3: %016lx DR6: %016lx DR7: %016lx\n", d3, d6, d7);
118

L
Linus Torvalds 已提交
119 120 121 122 123
}

void release_thread(struct task_struct *dead_task)
{
	if (dead_task->mm) {
124
#ifdef CONFIG_MODIFY_LDT_SYSCALL
125
		if (dead_task->mm->context.ldt) {
126
			pr_warn("WARNING: dead process %s still has LDT? <%p/%d>\n",
127 128
				dead_task->comm,
				dead_task->mm->context.ldt,
129
				dead_task->mm->context.ldt->size);
L
Linus Torvalds 已提交
130 131
			BUG();
		}
132
#endif
L
Linus Torvalds 已提交
133 134 135 136 137
	}
}

static inline void set_32bit_tls(struct task_struct *t, int tls, u32 addr)
{
138
	struct user_desc ud = {
L
Linus Torvalds 已提交
139 140 141 142 143 144
		.base_addr = addr,
		.limit = 0xfffff,
		.seg_32bit = 1,
		.limit_in_pages = 1,
		.useable = 1,
	};
J
Jan Engelhardt 已提交
145
	struct desc_struct *desc = t->thread.tls_array;
L
Linus Torvalds 已提交
146
	desc += tls;
147
	fill_ldt(desc, &ud);
L
Linus Torvalds 已提交
148 149 150 151
}

static inline u32 read_32bit_tls(struct task_struct *t, int tls)
{
R
Roland McGrath 已提交
152
	return get_desc_base(&t->thread.tls_array[tls]);
L
Linus Torvalds 已提交
153 154
}

155 156
int copy_thread_tls(unsigned long clone_flags, unsigned long sp,
		unsigned long arg, struct task_struct *p, unsigned long tls)
L
Linus Torvalds 已提交
157 158
{
	int err;
159
	struct pt_regs *childregs;
L
Linus Torvalds 已提交
160 161
	struct task_struct *me = current;

A
Al Viro 已提交
162 163
	p->thread.sp0 = (unsigned long)task_stack_page(p) + THREAD_SIZE;
	childregs = task_pt_regs(p);
164
	p->thread.sp = (unsigned long) childregs;
A
Al Viro 已提交
165
	set_tsk_thread_flag(p, TIF_FORK);
166
	p->thread.io_bitmap_ptr = NULL;
L
Linus Torvalds 已提交
167

168
	savesegment(gs, p->thread.gsindex);
169
	p->thread.gs = p->thread.gsindex ? 0 : me->thread.gs;
170
	savesegment(fs, p->thread.fsindex);
171
	p->thread.fs = p->thread.fsindex ? 0 : me->thread.fs;
172 173
	savesegment(es, p->thread.es);
	savesegment(ds, p->thread.ds);
A
Al Viro 已提交
174 175
	memset(p->thread.ptrace_bps, 0, sizeof(p->thread.ptrace_bps));

176
	if (unlikely(p->flags & PF_KTHREAD)) {
A
Al Viro 已提交
177 178 179 180 181 182 183 184
		/* kernel thread */
		memset(childregs, 0, sizeof(struct pt_regs));
		childregs->sp = (unsigned long)childregs;
		childregs->ss = __KERNEL_DS;
		childregs->bx = sp; /* function */
		childregs->bp = arg;
		childregs->orig_ax = -1;
		childregs->cs = __KERNEL_CS | get_kernel_rpl();
185
		childregs->flags = X86_EFLAGS_IF | X86_EFLAGS_FIXED;
A
Al Viro 已提交
186 187
		return 0;
	}
188
	*childregs = *current_pt_regs();
A
Al Viro 已提交
189 190

	childregs->ax = 0;
191 192
	if (sp)
		childregs->sp = sp;
L
Linus Torvalds 已提交
193

194
	err = -ENOMEM;
195
	if (unlikely(test_tsk_thread_flag(me, TIF_IO_BITMAP))) {
196 197
		p->thread.io_bitmap_ptr = kmemdup(me->thread.io_bitmap_ptr,
						  IO_BITMAP_BYTES, GFP_KERNEL);
L
Linus Torvalds 已提交
198 199 200 201
		if (!p->thread.io_bitmap_ptr) {
			p->thread.io_bitmap_max = 0;
			return -ENOMEM;
		}
202
		set_tsk_thread_flag(p, TIF_IO_BITMAP);
203
	}
L
Linus Torvalds 已提交
204 205 206 207 208 209

	/*
	 * Set a new TLS for the child thread?
	 */
	if (clone_flags & CLONE_SETTLS) {
#ifdef CONFIG_IA32_EMULATION
210
		if (is_ia32_task())
R
Roland McGrath 已提交
211
			err = do_set_thread_area(p, -1,
212
				(struct user_desc __user *)tls, 0);
213 214
		else
#endif
215
			err = do_arch_prctl(p, ARCH_SET_FS, tls);
216
		if (err)
L
Linus Torvalds 已提交
217 218 219 220 221 222 223 224
			goto out;
	}
	err = 0;
out:
	if (err && p->thread.io_bitmap_ptr) {
		kfree(p->thread.io_bitmap_ptr);
		p->thread.io_bitmap_max = 0;
	}
225

L
Linus Torvalds 已提交
226 227 228
	return err;
}

229 230 231 232
static void
start_thread_common(struct pt_regs *regs, unsigned long new_ip,
		    unsigned long new_sp,
		    unsigned int _cs, unsigned int _ss, unsigned int _ds)
I
Ingo Molnar 已提交
233
{
234
	loadsegment(fs, 0);
235 236
	loadsegment(es, _ds);
	loadsegment(ds, _ds);
I
Ingo Molnar 已提交
237 238 239
	load_gs_index(0);
	regs->ip		= new_ip;
	regs->sp		= new_sp;
240 241
	regs->cs		= _cs;
	regs->ss		= _ss;
242
	regs->flags		= X86_EFLAGS_IF;
243
	force_iret();
I
Ingo Molnar 已提交
244
}
245 246 247 248 249 250 251

void
start_thread(struct pt_regs *regs, unsigned long new_ip, unsigned long new_sp)
{
	start_thread_common(regs, new_ip, new_sp,
			    __USER_CS, __USER_DS, 0);
}
I
Ingo Molnar 已提交
252

253 254
#ifdef CONFIG_COMPAT
void compat_start_thread(struct pt_regs *regs, u32 new_ip, u32 new_sp)
255
{
256
	start_thread_common(regs, new_ip, new_sp,
H
H. Peter Anvin 已提交
257 258 259
			    test_thread_flag(TIF_X32)
			    ? __USER_CS : __USER32_CS,
			    __USER_DS, __USER_DS);
260 261
}
#endif
I
Ingo Molnar 已提交
262

L
Linus Torvalds 已提交
263 264 265
/*
 *	switch_to(x,y) should switch tasks from x to y.
 *
266
 * This could still be optimized:
L
Linus Torvalds 已提交
267 268
 * - fold all the options into a flag word and test it with a single test.
 * - could test fs/gs bitsliced
269 270
 *
 * Kprobes not supported here. Set the probe on schedule instead.
271
 * Function graph tracer not supported too.
L
Linus Torvalds 已提交
272
 */
273
__visible __notrace_funcgraph struct task_struct *
274
__switch_to(struct task_struct *prev_p, struct task_struct *next_p)
L
Linus Torvalds 已提交
275
{
276 277
	struct thread_struct *prev = &prev_p->thread;
	struct thread_struct *next = &next_p->thread;
278 279
	struct fpu *prev_fpu = &prev->fpu;
	struct fpu *next_fpu = &next->fpu;
280
	int cpu = smp_processor_id();
281
	struct tss_struct *tss = &per_cpu(cpu_tss, cpu);
282
	unsigned fsindex, gsindex;
283
	fpu_switch_t fpu_switch;
284

285
	fpu_switch = switch_fpu_prepare(prev_fpu, next_fpu, cpu);
286

287 288 289 290 291 292 293 294
	/* We must save %fs and %gs before load_TLS() because
	 * %fs and %gs may be cleared by load_TLS().
	 *
	 * (e.g. xen_load_tls())
	 */
	savesegment(fs, fsindex);
	savesegment(gs, gsindex);

295 296 297 298
	/*
	 * Load TLS before restoring any segments so that segment loads
	 * reference the correct GDT entries.
	 */
L
Linus Torvalds 已提交
299 300
	load_TLS(next, cpu);

301
	/*
302 303 304
	 * Leave lazy mode, flushing any hypercalls made here.  This
	 * must be done after loading TLS entries in the GDT but before
	 * loading segments that might reference them, and and it must
305
	 * be done before fpu__restore(), so the TS bit is up to
306
	 * date.
307
	 */
308
	arch_end_context_switch(next_p);
309

310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331
	/* Switch DS and ES.
	 *
	 * Reading them only returns the selectors, but writing them (if
	 * nonzero) loads the full descriptor from the GDT or LDT.  The
	 * LDT for next is loaded in switch_mm, and the GDT is loaded
	 * above.
	 *
	 * We therefore need to write new values to the segment
	 * registers on every context switch unless both the new and old
	 * values are zero.
	 *
	 * Note that we don't need to do anything for CS and SS, as
	 * those are saved and restored as part of pt_regs.
	 */
	savesegment(es, prev->es);
	if (unlikely(next->es | prev->es))
		loadsegment(es, next->es);

	savesegment(ds, prev->ds);
	if (unlikely(next->ds | prev->ds))
		loadsegment(ds, next->ds);

332
	/*
L
Linus Torvalds 已提交
333
	 * Switch FS and GS.
334
	 *
335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365
	 * These are even more complicated than FS and GS: they have
	 * 64-bit bases are that controlled by arch_prctl.  Those bases
	 * only differ from the values in the GDT or LDT if the selector
	 * is 0.
	 *
	 * Loading the segment register resets the hidden base part of
	 * the register to 0 or the value from the GDT / LDT.  If the
	 * next base address zero, writing 0 to the segment register is
	 * much faster than using wrmsr to explicitly zero the base.
	 *
	 * The thread_struct.fs and thread_struct.gs values are 0
	 * if the fs and gs bases respectively are not overridden
	 * from the values implied by fsindex and gsindex.  They
	 * are nonzero, and store the nonzero base addresses, if
	 * the bases are overridden.
	 *
	 * (fs != 0 && fsindex != 0) || (gs != 0 && gsindex != 0) should
	 * be impossible.
	 *
	 * Therefore we need to reload the segment registers if either
	 * the old or new selector is nonzero, and we need to override
	 * the base address if next thread expects it to be overridden.
	 *
	 * This code is unnecessarily slow in the case where the old and
	 * new indexes are zero and the new base is nonzero -- it will
	 * unnecessarily write 0 to the selector before writing the new
	 * base address.
	 *
	 * Note: This all depends on arch_prctl being the only way that
	 * user code can override the segment base.  Once wrfsbase and
	 * wrgsbase are enabled, most of this code will need to change.
L
Linus Torvalds 已提交
366
	 */
367 368
	if (unlikely(fsindex | next->fsindex | prev->fs)) {
		loadsegment(fs, next->fsindex);
369

370
		/*
371 372 373 374 375 376 377
		 * If user code wrote a nonzero value to FS, then it also
		 * cleared the overridden base address.
		 *
		 * XXX: if user code wrote 0 to FS and cleared the base
		 * address itself, we won't notice and we'll incorrectly
		 * restore the prior base address next time we reschdule
		 * the process.
378 379
		 */
		if (fsindex)
380
			prev->fs = 0;
L
Linus Torvalds 已提交
381
	}
382 383 384 385 386 387
	if (next->fs)
		wrmsrl(MSR_FS_BASE, next->fs);
	prev->fsindex = fsindex;

	if (unlikely(gsindex | next->gsindex | prev->gs)) {
		load_gs_index(next->gsindex);
388 389

		/* This works (and fails) the same way as fsindex above. */
390
		if (gsindex)
391
			prev->gs = 0;
L
Linus Torvalds 已提交
392
	}
393 394 395
	if (next->gs)
		wrmsrl(MSR_KERNEL_GS_BASE, next->gs);
	prev->gsindex = gsindex;
L
Linus Torvalds 已提交
396

397
	switch_fpu_finish(next_fpu, fpu_switch);
398

399
	/*
400
	 * Switch the PDA and FPU contexts.
L
Linus Torvalds 已提交
401
	 */
402
	this_cpu_write(current_task, next_p);
403

404 405 406 407 408 409 410 411
	/*
	 * If it were not for PREEMPT_ACTIVE we could guarantee that the
	 * preempt_count of all tasks was equal here and this would not be
	 * needed.
	 */
	task_thread_info(prev_p)->saved_preempt_count = this_cpu_read(__preempt_count);
	this_cpu_write(__preempt_count, task_thread_info(next_p)->saved_preempt_count);

412 413 414
	/* Reload esp0 and ss1.  This changes current_thread_info(). */
	load_sp0(tss, next);

L
Linus Torvalds 已提交
415
	/*
416
	 * Now maybe reload the debug registers and handle I/O bitmaps
L
Linus Torvalds 已提交
417
	 */
418 419
	if (unlikely(task_thread_info(next_p)->flags & _TIF_WORK_CTXSW_NEXT ||
		     task_thread_info(prev_p)->flags & _TIF_WORK_CTXSW_PREV))
420
		__switch_to_xtra(prev_p, next_p, tss);
L
Linus Torvalds 已提交
421

422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449
	if (static_cpu_has_bug(X86_BUG_SYSRET_SS_ATTRS)) {
		/*
		 * AMD CPUs have a misfeature: SYSRET sets the SS selector but
		 * does not update the cached descriptor.  As a result, if we
		 * do SYSRET while SS is NULL, we'll end up in user mode with
		 * SS apparently equal to __USER_DS but actually unusable.
		 *
		 * The straightforward workaround would be to fix it up just
		 * before SYSRET, but that would slow down the system call
		 * fast paths.  Instead, we ensure that SS is never NULL in
		 * system call context.  We do this by replacing NULL SS
		 * selectors at every context switch.  SYSCALL sets up a valid
		 * SS, so the only way to get NULL is to re-enter the kernel
		 * from CPL 3 through an interrupt.  Since that can't happen
		 * in the same task as a running syscall, we are guaranteed to
		 * context switch between every interrupt vector entry and a
		 * subsequent SYSRET.
		 *
		 * We read SS first because SS reads are much faster than
		 * writes.  Out of caution, we force SS to __KERNEL_DS even if
		 * it previously had a different non-NULL value.
		 */
		unsigned short ss_sel;
		savesegment(ss, ss_sel);
		if (ss_sel != __KERNEL_DS)
			loadsegment(ss, __KERNEL_DS);
	}

L
Linus Torvalds 已提交
450 451 452 453 454 455 456 457
	return prev_p;
}

void set_personality_64bit(void)
{
	/* inherit personality from parent */

	/* Make sure to be in 64bit mode */
458
	clear_thread_flag(TIF_IA32);
459
	clear_thread_flag(TIF_ADDR32);
460
	clear_thread_flag(TIF_X32);
L
Linus Torvalds 已提交
461

462 463 464 465
	/* Ensure the corresponding mm is not marked. */
	if (current->mm)
		current->mm->context.ia32_compat = 0;

L
Linus Torvalds 已提交
466 467 468
	/* TBD: overwrites user setup. Should have two bits.
	   But 64bit processes have always behaved this way,
	   so it's not too bad. The main problem is just that
469
	   32bit childs are affected again. */
L
Linus Torvalds 已提交
470 471 472
	current->personality &= ~READ_IMPLIES_EXEC;
}

H
H. Peter Anvin 已提交
473
void set_personality_ia32(bool x32)
474 475 476 477
{
	/* inherit personality from parent */

	/* Make sure to be in 32bit mode */
478
	set_thread_flag(TIF_ADDR32);
479

480
	/* Mark the associated mm as containing 32-bit tasks. */
H
H. Peter Anvin 已提交
481 482 483
	if (x32) {
		clear_thread_flag(TIF_IA32);
		set_thread_flag(TIF_X32);
484 485
		if (current->mm)
			current->mm->context.ia32_compat = TIF_X32;
H
H. Peter Anvin 已提交
486
		current->personality &= ~READ_IMPLIES_EXEC;
487 488 489
		/* is_compat_task() uses the presence of the x32
		   syscall bit flag to determine compat status */
		current_thread_info()->status &= ~TS_COMPAT;
H
H. Peter Anvin 已提交
490 491 492
	} else {
		set_thread_flag(TIF_IA32);
		clear_thread_flag(TIF_X32);
493 494
		if (current->mm)
			current->mm->context.ia32_compat = TIF_IA32;
H
H. Peter Anvin 已提交
495 496 497 498
		current->personality |= force_personality32;
		/* Prepare the first "return" to user space */
		current_thread_info()->status |= TS_COMPAT;
	}
499
}
500
EXPORT_SYMBOL_GPL(set_personality_ia32);
501

502 503 504 505 506 507
/*
 * Called from fs/proc with a reference on @p to find the function
 * which called into schedule(). This needs to be done carefully
 * because the task might wake up and we might look at a stack
 * changing under us.
 */
L
Linus Torvalds 已提交
508 509
unsigned long get_wchan(struct task_struct *p)
{
510
	unsigned long start, bottom, top, sp, fp, ip;
L
Linus Torvalds 已提交
511 512
	int count = 0;

513 514
	if (!p || p == current || p->state == TASK_RUNNING)
		return 0;
515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543

	start = (unsigned long)task_stack_page(p);
	if (!start)
		return 0;

	/*
	 * Layout of the stack page:
	 *
	 * ----------- topmax = start + THREAD_SIZE - sizeof(unsigned long)
	 * PADDING
	 * ----------- top = topmax - TOP_OF_KERNEL_STACK_PADDING
	 * stack
	 * ----------- bottom = start + sizeof(thread_info)
	 * thread_info
	 * ----------- start
	 *
	 * The tasks stack pointer points at the location where the
	 * framepointer is stored. The data on the stack is:
	 * ... IP FP ... IP FP
	 *
	 * We need to read FP and IP, so we need to adjust the upper
	 * bound by another unsigned long.
	 */
	top = start + THREAD_SIZE - TOP_OF_KERNEL_STACK_PADDING;
	top -= 2 * sizeof(unsigned long);
	bottom = start + sizeof(struct thread_info);

	sp = READ_ONCE(p->thread.sp);
	if (sp < bottom || sp > top)
L
Linus Torvalds 已提交
544
		return 0;
545 546

	fp = READ_ONCE(*(unsigned long *)sp);
547
	do {
548
		if (fp < bottom || fp > top)
549
			return 0;
550
		ip = READ_ONCE(*(unsigned long *)(fp + sizeof(unsigned long)));
551 552
		if (!in_sched_functions(ip))
			return ip;
553 554
		fp = READ_ONCE(*(unsigned long *)fp);
	} while (count++ < 16 && p->state != TASK_RUNNING);
L
Linus Torvalds 已提交
555 556 557 558
	return 0;
}

long do_arch_prctl(struct task_struct *task, int code, unsigned long addr)
559 560
{
	int ret = 0;
L
Linus Torvalds 已提交
561 562 563
	int doit = task == current;
	int cpu;

564
	switch (code) {
L
Linus Torvalds 已提交
565
	case ARCH_SET_GS:
566
		if (addr >= TASK_SIZE_OF(task))
567
			return -EPERM;
L
Linus Torvalds 已提交
568
		cpu = get_cpu();
569
		/* handle small bases via the GDT because that's faster to
L
Linus Torvalds 已提交
570
		   switch. */
571 572 573
		if (addr <= 0xffffffff) {
			set_32bit_tls(task, GS_TLS, addr);
			if (doit) {
L
Linus Torvalds 已提交
574
				load_TLS(&task->thread, cpu);
575
				load_gs_index(GS_TLS_SEL);
L
Linus Torvalds 已提交
576
			}
577
			task->thread.gsindex = GS_TLS_SEL;
L
Linus Torvalds 已提交
578
			task->thread.gs = 0;
579
		} else {
L
Linus Torvalds 已提交
580 581 582
			task->thread.gsindex = 0;
			task->thread.gs = addr;
			if (doit) {
583
				load_gs_index(0);
584
				ret = wrmsrl_safe(MSR_KERNEL_GS_BASE, addr);
585
			}
L
Linus Torvalds 已提交
586 587 588 589 590 591
		}
		put_cpu();
		break;
	case ARCH_SET_FS:
		/* Not strictly needed for fs, but do it for symmetry
		   with gs */
592
		if (addr >= TASK_SIZE_OF(task))
593
			return -EPERM;
L
Linus Torvalds 已提交
594
		cpu = get_cpu();
595
		/* handle small bases via the GDT because that's faster to
L
Linus Torvalds 已提交
596
		   switch. */
597
		if (addr <= 0xffffffff) {
L
Linus Torvalds 已提交
598
			set_32bit_tls(task, FS_TLS, addr);
599 600
			if (doit) {
				load_TLS(&task->thread, cpu);
601
				loadsegment(fs, FS_TLS_SEL);
L
Linus Torvalds 已提交
602 603 604
			}
			task->thread.fsindex = FS_TLS_SEL;
			task->thread.fs = 0;
605
		} else {
L
Linus Torvalds 已提交
606 607 608 609 610
			task->thread.fsindex = 0;
			task->thread.fs = addr;
			if (doit) {
				/* set the selector to 0 to not confuse
				   __switch_to */
611
				loadsegment(fs, 0);
612
				ret = wrmsrl_safe(MSR_FS_BASE, addr);
L
Linus Torvalds 已提交
613 614 615 616
			}
		}
		put_cpu();
		break;
617 618
	case ARCH_GET_FS: {
		unsigned long base;
L
Linus Torvalds 已提交
619 620
		if (task->thread.fsindex == FS_TLS_SEL)
			base = read_32bit_tls(task, FS_TLS);
621
		else if (doit)
L
Linus Torvalds 已提交
622
			rdmsrl(MSR_FS_BASE, base);
623
		else
L
Linus Torvalds 已提交
624
			base = task->thread.fs;
625 626
		ret = put_user(base, (unsigned long __user *)addr);
		break;
L
Linus Torvalds 已提交
627
	}
628
	case ARCH_GET_GS: {
L
Linus Torvalds 已提交
629
		unsigned long base;
630
		unsigned gsindex;
L
Linus Torvalds 已提交
631 632
		if (task->thread.gsindex == GS_TLS_SEL)
			base = read_32bit_tls(task, GS_TLS);
633
		else if (doit) {
634
			savesegment(gs, gsindex);
635 636 637 638
			if (gsindex)
				rdmsrl(MSR_KERNEL_GS_BASE, base);
			else
				base = task->thread.gs;
639
		} else
L
Linus Torvalds 已提交
640
			base = task->thread.gs;
641
		ret = put_user(base, (unsigned long __user *)addr);
L
Linus Torvalds 已提交
642 643 644 645 646 647
		break;
	}

	default:
		ret = -EINVAL;
		break;
648
	}
L
Linus Torvalds 已提交
649

650 651
	return ret;
}
L
Linus Torvalds 已提交
652 653 654 655 656 657

long sys_arch_prctl(int code, unsigned long addr)
{
	return do_arch_prctl(current, code, addr);
}

658 659
unsigned long KSTK_ESP(struct task_struct *task)
{
660
	return task_pt_regs(task)->sp;
661
}