inode.c 36.5 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3
/*
 * hugetlbpage-backed filesystem.  Based on ramfs.
 *
4
 * Nadia Yvette Chambers, 2002
L
Linus Torvalds 已提交
5 6
 *
 * Copyright (C) 2002 Linus Torvalds.
7
 * License: GPL
L
Linus Torvalds 已提交
8 9
 */

10 11
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

L
Linus Torvalds 已提交
12 13
#include <linux/thread_info.h>
#include <asm/current.h>
14
#include <linux/sched/signal.h>		/* remove ASAP */
15
#include <linux/falloc.h>
L
Linus Torvalds 已提交
16 17 18
#include <linux/fs.h>
#include <linux/mount.h>
#include <linux/file.h>
19
#include <linux/kernel.h>
L
Linus Torvalds 已提交
20 21 22 23 24
#include <linux/writeback.h>
#include <linux/pagemap.h>
#include <linux/highmem.h>
#include <linux/init.h>
#include <linux/string.h>
25
#include <linux/capability.h>
26
#include <linux/ctype.h>
L
Linus Torvalds 已提交
27 28 29
#include <linux/backing-dev.h>
#include <linux/hugetlb.h>
#include <linux/pagevec.h>
30
#include <linux/parser.h>
31
#include <linux/mman.h>
L
Linus Torvalds 已提交
32 33 34 35
#include <linux/slab.h>
#include <linux/dnotify.h>
#include <linux/statfs.h>
#include <linux/security.h>
N
Nick Black 已提交
36
#include <linux/magic.h>
N
Naoya Horiguchi 已提交
37
#include <linux/migrate.h>
A
Al Viro 已提交
38
#include <linux/uio.h>
L
Linus Torvalds 已提交
39

40
#include <linux/uaccess.h>
L
Linus Torvalds 已提交
41

42
static const struct super_operations hugetlbfs_ops;
43
static const struct address_space_operations hugetlbfs_aops;
44
const struct file_operations hugetlbfs_file_operations;
45 46
static const struct inode_operations hugetlbfs_dir_inode_operations;
static const struct inode_operations hugetlbfs_inode_operations;
L
Linus Torvalds 已提交
47

D
David Gibson 已提交
48
struct hugetlbfs_config {
49 50 51 52 53 54 55
	struct hstate		*hstate;
	long			max_hpages;
	long			nr_inodes;
	long			min_hpages;
	kuid_t			uid;
	kgid_t			gid;
	umode_t			mode;
D
David Gibson 已提交
56 57
};

L
Linus Torvalds 已提交
58 59
int sysctl_hugetlb_shm_group;

60 61 62
enum {
	Opt_size, Opt_nr_inodes,
	Opt_mode, Opt_uid, Opt_gid,
63
	Opt_pagesize, Opt_min_size,
64 65 66
	Opt_err,
};

67
static const match_table_t tokens = {
68 69 70 71 72
	{Opt_size,	"size=%s"},
	{Opt_nr_inodes,	"nr_inodes=%s"},
	{Opt_mode,	"mode=%o"},
	{Opt_uid,	"uid=%u"},
	{Opt_gid,	"gid=%u"},
73
	{Opt_pagesize,	"pagesize=%s"},
74
	{Opt_min_size,	"min_size=%s"},
75 76 77
	{Opt_err,	NULL},
};

78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
#ifdef CONFIG_NUMA
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
	vma->vm_policy = mpol_shared_policy_lookup(&HUGETLBFS_I(inode)->policy,
							index);
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
	mpol_cond_put(vma->vm_policy);
}
#else
static inline void hugetlb_set_vma_policy(struct vm_area_struct *vma,
					struct inode *inode, pgoff_t index)
{
}

static inline void hugetlb_drop_vma_policy(struct vm_area_struct *vma)
{
}
#endif

101 102 103 104 105 106 107 108 109 110
static void huge_pagevec_release(struct pagevec *pvec)
{
	int i;

	for (i = 0; i < pagevec_count(pvec); ++i)
		put_page(pvec->pages[i]);

	pagevec_reinit(pvec);
}

L
Linus Torvalds 已提交
111 112
static int hugetlbfs_file_mmap(struct file *file, struct vm_area_struct *vma)
{
A
Al Viro 已提交
113
	struct inode *inode = file_inode(file);
L
Linus Torvalds 已提交
114 115
	loff_t len, vma_len;
	int ret;
116
	struct hstate *h = hstate_file(file);
L
Linus Torvalds 已提交
117

118
	/*
119 120 121 122 123 124
	 * vma address alignment (but not the pgoff alignment) has
	 * already been checked by prepare_hugepage_range.  If you add
	 * any error returns here, do so after setting VM_HUGETLB, so
	 * is_vm_hugetlb_page tests below unmap_region go the right
	 * way when do_mmap_pgoff unwinds (may be important on powerpc
	 * and ia64).
125
	 */
126
	vma->vm_flags |= VM_HUGETLB | VM_DONTEXPAND;
127
	vma->vm_ops = &hugetlb_vm_ops;
L
Linus Torvalds 已提交
128

129 130 131 132 133 134 135
	/*
	 * Offset passed to mmap (before page shift) could have been
	 * negative when represented as a (l)off_t.
	 */
	if (((loff_t)vma->vm_pgoff << PAGE_SHIFT) < 0)
		return -EINVAL;

136
	if (vma->vm_pgoff & (~huge_page_mask(h) >> PAGE_SHIFT))
137 138
		return -EINVAL;

L
Linus Torvalds 已提交
139
	vma_len = (loff_t)(vma->vm_end - vma->vm_start);
140 141 142 143
	len = vma_len + ((loff_t)vma->vm_pgoff << PAGE_SHIFT);
	/* check for overflow */
	if (len < vma_len)
		return -EINVAL;
L
Linus Torvalds 已提交
144

A
Al Viro 已提交
145
	inode_lock(inode);
L
Linus Torvalds 已提交
146 147 148
	file_accessed(file);

	ret = -ENOMEM;
149
	if (hugetlb_reserve_pages(inode,
150
				vma->vm_pgoff >> huge_page_order(h),
151 152
				len >> huge_page_shift(h), vma,
				vma->vm_flags))
153
		goto out;
154

A
Adam Litke 已提交
155
	ret = 0;
156
	if (vma->vm_flags & VM_WRITE && inode->i_size < len)
157
		i_size_write(inode, len);
L
Linus Torvalds 已提交
158
out:
A
Al Viro 已提交
159
	inode_unlock(inode);
L
Linus Torvalds 已提交
160 161 162 163 164

	return ret;
}

/*
165
 * Called under down_write(mmap_sem).
L
Linus Torvalds 已提交
166 167
 */

168
#ifndef HAVE_ARCH_HUGETLB_UNMAPPED_AREA
L
Linus Torvalds 已提交
169 170 171 172 173 174
static unsigned long
hugetlb_get_unmapped_area(struct file *file, unsigned long addr,
		unsigned long len, unsigned long pgoff, unsigned long flags)
{
	struct mm_struct *mm = current->mm;
	struct vm_area_struct *vma;
175
	struct hstate *h = hstate_file(file);
176
	struct vm_unmapped_area_info info;
L
Linus Torvalds 已提交
177

178
	if (len & ~huge_page_mask(h))
L
Linus Torvalds 已提交
179 180 181 182
		return -EINVAL;
	if (len > TASK_SIZE)
		return -ENOMEM;

183
	if (flags & MAP_FIXED) {
184
		if (prepare_hugepage_range(file, addr, len))
185 186 187 188
			return -EINVAL;
		return addr;
	}

L
Linus Torvalds 已提交
189
	if (addr) {
190
		addr = ALIGN(addr, huge_page_size(h));
L
Linus Torvalds 已提交
191 192
		vma = find_vma(mm, addr);
		if (TASK_SIZE - len >= addr &&
193
		    (!vma || addr + len <= vm_start_gap(vma)))
L
Linus Torvalds 已提交
194 195 196
			return addr;
	}

197 198 199 200 201 202 203
	info.flags = 0;
	info.length = len;
	info.low_limit = TASK_UNMAPPED_BASE;
	info.high_limit = TASK_SIZE;
	info.align_mask = PAGE_MASK & ~huge_page_mask(h);
	info.align_offset = 0;
	return vm_unmapped_area(&info);
L
Linus Torvalds 已提交
204 205 206
}
#endif

A
Al Viro 已提交
207
static size_t
B
Badari Pulavarty 已提交
208
hugetlbfs_read_actor(struct page *page, unsigned long offset,
A
Al Viro 已提交
209
			struct iov_iter *to, unsigned long size)
B
Badari Pulavarty 已提交
210
{
A
Al Viro 已提交
211
	size_t copied = 0;
B
Badari Pulavarty 已提交
212 213 214
	int i, chunksize;

	/* Find which 4k chunk and offset with in that chunk */
215 216
	i = offset >> PAGE_SHIFT;
	offset = offset & ~PAGE_MASK;
B
Badari Pulavarty 已提交
217 218

	while (size) {
A
Al Viro 已提交
219
		size_t n;
220
		chunksize = PAGE_SIZE;
B
Badari Pulavarty 已提交
221 222 223 224
		if (offset)
			chunksize -= offset;
		if (chunksize > size)
			chunksize = size;
A
Al Viro 已提交
225 226 227 228
		n = copy_page_to_iter(&page[i], offset, chunksize, to);
		copied += n;
		if (n != chunksize)
			return copied;
B
Badari Pulavarty 已提交
229 230 231 232
		offset = 0;
		size -= chunksize;
		i++;
	}
A
Al Viro 已提交
233
	return copied;
B
Badari Pulavarty 已提交
234 235 236 237 238
}

/*
 * Support for read() - Find the page attached to f_mapping and copy out the
 * data. Its *very* similar to do_generic_mapping_read(), we can't use that
239
 * since it has PAGE_SIZE assumptions.
B
Badari Pulavarty 已提交
240
 */
A
Al Viro 已提交
241
static ssize_t hugetlbfs_read_iter(struct kiocb *iocb, struct iov_iter *to)
B
Badari Pulavarty 已提交
242
{
A
Al Viro 已提交
243 244 245
	struct file *file = iocb->ki_filp;
	struct hstate *h = hstate_file(file);
	struct address_space *mapping = file->f_mapping;
B
Badari Pulavarty 已提交
246
	struct inode *inode = mapping->host;
A
Al Viro 已提交
247 248
	unsigned long index = iocb->ki_pos >> huge_page_shift(h);
	unsigned long offset = iocb->ki_pos & ~huge_page_mask(h);
B
Badari Pulavarty 已提交
249 250 251 252
	unsigned long end_index;
	loff_t isize;
	ssize_t retval = 0;

A
Al Viro 已提交
253
	while (iov_iter_count(to)) {
B
Badari Pulavarty 已提交
254
		struct page *page;
A
Al Viro 已提交
255
		size_t nr, copied;
B
Badari Pulavarty 已提交
256 257

		/* nr is the maximum number of bytes to copy from this page */
258
		nr = huge_page_size(h);
259 260
		isize = i_size_read(inode);
		if (!isize)
A
Al Viro 已提交
261
			break;
262
		end_index = (isize - 1) >> huge_page_shift(h);
A
Al Viro 已提交
263 264 265
		if (index > end_index)
			break;
		if (index == end_index) {
266
			nr = ((isize - 1) & ~huge_page_mask(h)) + 1;
267
			if (nr <= offset)
A
Al Viro 已提交
268
				break;
B
Badari Pulavarty 已提交
269 270 271 272
		}
		nr = nr - offset;

		/* Find the page */
273
		page = find_lock_page(mapping, index);
B
Badari Pulavarty 已提交
274 275 276 277 278
		if (unlikely(page == NULL)) {
			/*
			 * We have a HOLE, zero out the user-buffer for the
			 * length of the hole or request.
			 */
A
Al Viro 已提交
279
			copied = iov_iter_zero(nr, to);
B
Badari Pulavarty 已提交
280
		} else {
281 282
			unlock_page(page);

B
Badari Pulavarty 已提交
283 284 285
			/*
			 * We have the page, copy it to user space buffer.
			 */
A
Al Viro 已提交
286
			copied = hugetlbfs_read_actor(page, offset, to, nr);
287
			put_page(page);
B
Badari Pulavarty 已提交
288
		}
A
Al Viro 已提交
289 290 291 292 293 294
		offset += copied;
		retval += copied;
		if (copied != nr && iov_iter_count(to)) {
			if (!retval)
				retval = -EFAULT;
			break;
B
Badari Pulavarty 已提交
295
		}
296 297
		index += offset >> huge_page_shift(h);
		offset &= ~huge_page_mask(h);
B
Badari Pulavarty 已提交
298
	}
A
Al Viro 已提交
299
	iocb->ki_pos = ((loff_t)index << huge_page_shift(h)) + offset;
B
Badari Pulavarty 已提交
300 301 302
	return retval;
}

N
Nick Piggin 已提交
303 304 305 306
static int hugetlbfs_write_begin(struct file *file,
			struct address_space *mapping,
			loff_t pos, unsigned len, unsigned flags,
			struct page **pagep, void **fsdata)
L
Linus Torvalds 已提交
307 308 309 310
{
	return -EINVAL;
}

N
Nick Piggin 已提交
311 312 313
static int hugetlbfs_write_end(struct file *file, struct address_space *mapping,
			loff_t pos, unsigned len, unsigned copied,
			struct page *page, void *fsdata)
L
Linus Torvalds 已提交
314
{
N
Nick Piggin 已提交
315
	BUG();
L
Linus Torvalds 已提交
316 317 318
	return -EINVAL;
}

319
static void remove_huge_page(struct page *page)
L
Linus Torvalds 已提交
320
{
321
	ClearPageDirty(page);
L
Linus Torvalds 已提交
322
	ClearPageUptodate(page);
323
	delete_from_page_cache(page);
L
Linus Torvalds 已提交
324 325
}

326
static void
327
hugetlb_vmdelete_list(struct rb_root_cached *root, pgoff_t start, pgoff_t end)
328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362
{
	struct vm_area_struct *vma;

	/*
	 * end == 0 indicates that the entire range after
	 * start should be unmapped.
	 */
	vma_interval_tree_foreach(vma, root, start, end ? end : ULONG_MAX) {
		unsigned long v_offset;
		unsigned long v_end;

		/*
		 * Can the expression below overflow on 32-bit arches?
		 * No, because the interval tree returns us only those vmas
		 * which overlap the truncated area starting at pgoff,
		 * and no vma on a 32-bit arch can span beyond the 4GB.
		 */
		if (vma->vm_pgoff < start)
			v_offset = (start - vma->vm_pgoff) << PAGE_SHIFT;
		else
			v_offset = 0;

		if (!end)
			v_end = vma->vm_end;
		else {
			v_end = ((end - vma->vm_pgoff) << PAGE_SHIFT)
							+ vma->vm_start;
			if (v_end > vma->vm_end)
				v_end = vma->vm_end;
		}

		unmap_hugepage_range(vma, vma->vm_start + v_offset, v_end,
									NULL);
	}
}
363 364 365 366

/*
 * remove_inode_hugepages handles two distinct cases: truncation and hole
 * punch.  There are subtle differences in operation for each case.
367
 *
368 369 370
 * truncation is indicated by end of range being LLONG_MAX
 *	In this case, we first scan the range and release found pages.
 *	After releasing pages, hugetlb_unreserve_pages cleans up region/reserv
371 372 373 374 375
 *	maps and global counts.  Page faults can not race with truncation
 *	in this routine.  hugetlb_no_page() prevents page faults in the
 *	truncated range.  It checks i_size before allocation, and again after
 *	with the page table lock for the page held.  The same lock must be
 *	acquired to unmap a page.
376 377 378 379
 * hole punch is indicated if end is not LLONG_MAX
 *	In the hole punch case we scan the range and release found pages.
 *	Only when releasing a page is the associated region/reserv map
 *	deleted.  The region/reserv map for ranges without associated
380 381
 *	pages are not modified.  Page faults can race with hole punch.
 *	This is indicated if we find a mapped page.
382 383 384 385 386
 * Note: If the passed end of range value is beyond the end of file, but
 * not LLONG_MAX this routine still performs a hole punch operation.
 */
static void remove_inode_hugepages(struct inode *inode, loff_t lstart,
				   loff_t lend)
L
Linus Torvalds 已提交
387
{
388
	struct hstate *h = hstate_inode(inode);
389
	struct address_space *mapping = &inode->i_data;
390
	const pgoff_t start = lstart >> huge_page_shift(h);
391 392
	const pgoff_t end = lend >> huge_page_shift(h);
	struct vm_area_struct pseudo_vma;
L
Linus Torvalds 已提交
393
	struct pagevec pvec;
394
	pgoff_t next, index;
395
	int i, freed = 0;
396
	bool truncate_op = (lend == LLONG_MAX);
L
Linus Torvalds 已提交
397

398 399
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
400
	pagevec_init(&pvec);
L
Linus Torvalds 已提交
401
	next = start;
402 403
	while (next < end) {
		/*
404
		 * When no more pages are found, we are done.
405
		 */
406
		if (!pagevec_lookup_range(&pvec, mapping, &next, end - 1))
407
			break;
L
Linus Torvalds 已提交
408 409 410

		for (i = 0; i < pagevec_count(&pvec); ++i) {
			struct page *page = pvec.pages[i];
411 412
			u32 hash;

413
			index = page->index;
414 415
			hash = hugetlb_fault_mutex_hash(h, current->mm,
							&pseudo_vma,
416
							mapping, index, 0);
417
			mutex_lock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
418

419 420 421 422 423 424 425 426 427 428
			/*
			 * If page is mapped, it was faulted in after being
			 * unmapped in caller.  Unmap (again) now after taking
			 * the fault mutex.  The mutex will prevent faults
			 * until we finish removing the page.
			 *
			 * This race can only happen in the hole punch case.
			 * Getting here in a truncate operation is a bug.
			 */
			if (unlikely(page_mapped(page))) {
429
				BUG_ON(truncate_op);
430 431 432

				i_mmap_lock_write(mapping);
				hugetlb_vmdelete_list(&mapping->i_mmap,
433 434
					index * pages_per_huge_page(h),
					(index + 1) * pages_per_huge_page(h));
435 436 437 438 439 440 441 442 443
				i_mmap_unlock_write(mapping);
			}

			lock_page(page);
			/*
			 * We must free the huge page and remove from page
			 * cache (remove_huge_page) BEFORE removing the
			 * region/reserve map (hugetlb_unreserve_pages).  In
			 * rare out of memory conditions, removal of the
444 445 446
			 * region/reserve map could fail. Correspondingly,
			 * the subpool and global reserve usage count can need
			 * to be adjusted.
447
			 */
448
			VM_BUG_ON(PagePrivate(page));
449 450 451 452
			remove_huge_page(page);
			freed++;
			if (!truncate_op) {
				if (unlikely(hugetlb_unreserve_pages(inode,
453
							index, index + 1, 1)))
454
					hugetlb_fix_reserve_counts(inode);
455 456
			}

L
Linus Torvalds 已提交
457
			unlock_page(page);
458
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
L
Linus Torvalds 已提交
459 460
		}
		huge_pagevec_release(&pvec);
461
		cond_resched();
L
Linus Torvalds 已提交
462
	}
463 464 465

	if (truncate_op)
		(void)hugetlb_unreserve_pages(inode, start, LONG_MAX, freed);
L
Linus Torvalds 已提交
466 467
}

A
Al Viro 已提交
468
static void hugetlbfs_evict_inode(struct inode *inode)
L
Linus Torvalds 已提交
469
{
470 471
	struct resv_map *resv_map;

472
	remove_inode_hugepages(inode, 0, LLONG_MAX);
473 474 475 476
	resv_map = (struct resv_map *)inode->i_mapping->private_data;
	/* root inode doesn't have the resv_map, so we should check it */
	if (resv_map)
		resv_map_release(&resv_map->refs);
477
	clear_inode(inode);
478 479
}

L
Linus Torvalds 已提交
480 481
static int hugetlb_vmtruncate(struct inode *inode, loff_t offset)
{
H
Hugh Dickins 已提交
482
	pgoff_t pgoff;
L
Linus Torvalds 已提交
483
	struct address_space *mapping = inode->i_mapping;
484
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
485

486
	BUG_ON(offset & ~huge_page_mask(h));
H
Hugh Dickins 已提交
487
	pgoff = offset >> PAGE_SHIFT;
L
Linus Torvalds 已提交
488

489
	i_size_write(inode, offset);
490
	i_mmap_lock_write(mapping);
491
	if (!RB_EMPTY_ROOT(&mapping->i_mmap.rb_root))
492
		hugetlb_vmdelete_list(&mapping->i_mmap, pgoff, 0);
493
	i_mmap_unlock_write(mapping);
494
	remove_inode_hugepages(inode, offset, LLONG_MAX);
L
Linus Torvalds 已提交
495 496 497
	return 0;
}

498 499 500 501 502 503 504 505 506 507 508 509 510 511 512
static long hugetlbfs_punch_hole(struct inode *inode, loff_t offset, loff_t len)
{
	struct hstate *h = hstate_inode(inode);
	loff_t hpage_size = huge_page_size(h);
	loff_t hole_start, hole_end;

	/*
	 * For hole punch round up the beginning offset of the hole and
	 * round down the end.
	 */
	hole_start = round_up(offset, hpage_size);
	hole_end = round_down(offset + len, hpage_size);

	if (hole_end > hole_start) {
		struct address_space *mapping = inode->i_mapping;
513
		struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
514

A
Al Viro 已提交
515
		inode_lock(inode);
516 517 518 519 520 521 522

		/* protected by i_mutex */
		if (info->seals & F_SEAL_WRITE) {
			inode_unlock(inode);
			return -EPERM;
		}

523
		i_mmap_lock_write(mapping);
524
		if (!RB_EMPTY_ROOT(&mapping->i_mmap.rb_root))
525 526 527 528 529
			hugetlb_vmdelete_list(&mapping->i_mmap,
						hole_start >> PAGE_SHIFT,
						hole_end  >> PAGE_SHIFT);
		i_mmap_unlock_write(mapping);
		remove_inode_hugepages(inode, hole_start, hole_end);
A
Al Viro 已提交
530
		inode_unlock(inode);
531 532 533 534 535 536 537 538 539
	}

	return 0;
}

static long hugetlbfs_fallocate(struct file *file, int mode, loff_t offset,
				loff_t len)
{
	struct inode *inode = file_inode(file);
540
	struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564
	struct address_space *mapping = inode->i_mapping;
	struct hstate *h = hstate_inode(inode);
	struct vm_area_struct pseudo_vma;
	struct mm_struct *mm = current->mm;
	loff_t hpage_size = huge_page_size(h);
	unsigned long hpage_shift = huge_page_shift(h);
	pgoff_t start, index, end;
	int error;
	u32 hash;

	if (mode & ~(FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE))
		return -EOPNOTSUPP;

	if (mode & FALLOC_FL_PUNCH_HOLE)
		return hugetlbfs_punch_hole(inode, offset, len);

	/*
	 * Default preallocate case.
	 * For this range, start is rounded down and end is rounded up
	 * as well as being converted to page offsets.
	 */
	start = offset >> hpage_shift;
	end = (offset + len + hpage_size - 1) >> hpage_shift;

A
Al Viro 已提交
565
	inode_lock(inode);
566 567 568 569 570 571

	/* We need to check rlimit even when FALLOC_FL_KEEP_SIZE */
	error = inode_newsize_ok(inode, offset + len);
	if (error)
		goto out;

572 573 574 575 576
	if ((info->seals & F_SEAL_GROW) && offset + len > inode->i_size) {
		error = -EPERM;
		goto out;
	}

577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646
	/*
	 * Initialize a pseudo vma as this is required by the huge page
	 * allocation routines.  If NUMA is configured, use page index
	 * as input to create an allocation policy.
	 */
	memset(&pseudo_vma, 0, sizeof(struct vm_area_struct));
	pseudo_vma.vm_flags = (VM_HUGETLB | VM_MAYSHARE | VM_SHARED);
	pseudo_vma.vm_file = file;

	for (index = start; index < end; index++) {
		/*
		 * This is supposed to be the vaddr where the page is being
		 * faulted in, but we have no vaddr here.
		 */
		struct page *page;
		unsigned long addr;
		int avoid_reserve = 0;

		cond_resched();

		/*
		 * fallocate(2) manpage permits EINTR; we may have been
		 * interrupted because we are using up too much memory.
		 */
		if (signal_pending(current)) {
			error = -EINTR;
			break;
		}

		/* Set numa allocation policy based on index */
		hugetlb_set_vma_policy(&pseudo_vma, inode, index);

		/* addr is the offset within the file (zero based) */
		addr = index * hpage_size;

		/* mutex taken here, fault path and hole punch */
		hash = hugetlb_fault_mutex_hash(h, mm, &pseudo_vma, mapping,
						index, addr);
		mutex_lock(&hugetlb_fault_mutex_table[hash]);

		/* See if already present in mapping to avoid alloc/free */
		page = find_get_page(mapping, index);
		if (page) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			hugetlb_drop_vma_policy(&pseudo_vma);
			continue;
		}

		/* Allocate page and add to page cache */
		page = alloc_huge_page(&pseudo_vma, addr, avoid_reserve);
		hugetlb_drop_vma_policy(&pseudo_vma);
		if (IS_ERR(page)) {
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			error = PTR_ERR(page);
			goto out;
		}
		clear_huge_page(page, addr, pages_per_huge_page(h));
		__SetPageUptodate(page);
		error = huge_add_to_page_cache(page, mapping, index);
		if (unlikely(error)) {
			put_page(page);
			mutex_unlock(&hugetlb_fault_mutex_table[hash]);
			goto out;
		}

		mutex_unlock(&hugetlb_fault_mutex_table[hash]);

		/*
		 * unlock_page because locked by add_to_page_cache()
647
		 * page_put due to reference from alloc_huge_page()
648 649
		 */
		unlock_page(page);
650
		put_page(page);
651 652 653 654
	}

	if (!(mode & FALLOC_FL_KEEP_SIZE) && offset + len > inode->i_size)
		i_size_write(inode, offset + len);
655
	inode->i_ctime = current_time(inode);
656
out:
A
Al Viro 已提交
657
	inode_unlock(inode);
658 659 660
	return error;
}

L
Linus Torvalds 已提交
661 662
static int hugetlbfs_setattr(struct dentry *dentry, struct iattr *attr)
{
663
	struct inode *inode = d_inode(dentry);
664
	struct hstate *h = hstate_inode(inode);
L
Linus Torvalds 已提交
665 666
	int error;
	unsigned int ia_valid = attr->ia_valid;
667
	struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);
L
Linus Torvalds 已提交
668 669 670

	BUG_ON(!inode);

671
	error = setattr_prepare(dentry, attr);
L
Linus Torvalds 已提交
672
	if (error)
C
Christoph Hellwig 已提交
673
		return error;
L
Linus Torvalds 已提交
674 675

	if (ia_valid & ATTR_SIZE) {
676 677 678 679
		loff_t oldsize = inode->i_size;
		loff_t newsize = attr->ia_size;

		if (newsize & ~huge_page_mask(h))
C
Christoph Hellwig 已提交
680
			return -EINVAL;
681 682 683 684 685
		/* protected by i_mutex */
		if ((newsize < oldsize && (info->seals & F_SEAL_SHRINK)) ||
		    (newsize > oldsize && (info->seals & F_SEAL_GROW)))
			return -EPERM;
		error = hugetlb_vmtruncate(inode, newsize);
L
Linus Torvalds 已提交
686
		if (error)
C
Christoph Hellwig 已提交
687
			return error;
L
Linus Torvalds 已提交
688
	}
C
Christoph Hellwig 已提交
689 690 691 692

	setattr_copy(inode, attr);
	mark_inode_dirty(inode);
	return 0;
L
Linus Torvalds 已提交
693 694
}

695 696
static struct inode *hugetlbfs_get_root(struct super_block *sb,
					struct hugetlbfs_config *config)
L
Linus Torvalds 已提交
697 698 699 700 701
{
	struct inode *inode;

	inode = new_inode(sb);
	if (inode) {
702
		inode->i_ino = get_next_ino();
703 704 705
		inode->i_mode = S_IFDIR | config->mode;
		inode->i_uid = config->uid;
		inode->i_gid = config->gid;
706
		inode->i_atime = inode->i_mtime = inode->i_ctime = current_time(inode);
707 708 709 710
		inode->i_op = &hugetlbfs_dir_inode_operations;
		inode->i_fop = &simple_dir_operations;
		/* directory inodes start off with i_nlink == 2 (for "." entry) */
		inc_nlink(inode);
711
		lockdep_annotate_inode_mutex_key(inode);
712 713 714 715
	}
	return inode;
}

716
/*
717
 * Hugetlbfs is not reclaimable; therefore its i_mmap_rwsem will never
718
 * be taken from reclaim -- unlike regular filesystems. This needs an
719
 * annotation because huge_pmd_share() does an allocation under hugetlb's
720
 * i_mmap_rwsem.
721
 */
722
static struct lock_class_key hugetlbfs_i_mmap_rwsem_key;
723

724 725
static struct inode *hugetlbfs_get_inode(struct super_block *sb,
					struct inode *dir,
A
Al Viro 已提交
726
					umode_t mode, dev_t dev)
727 728
{
	struct inode *inode;
729 730 731 732 733
	struct resv_map *resv_map;

	resv_map = resv_map_alloc();
	if (!resv_map)
		return NULL;
734 735 736

	inode = new_inode(sb);
	if (inode) {
737 738
		struct hugetlbfs_inode_info *info = HUGETLBFS_I(inode);

739 740
		inode->i_ino = get_next_ino();
		inode_init_owner(inode, dir, mode);
741 742
		lockdep_set_class(&inode->i_mapping->i_mmap_rwsem,
				&hugetlbfs_i_mmap_rwsem_key);
L
Linus Torvalds 已提交
743
		inode->i_mapping->a_ops = &hugetlbfs_aops;
744
		inode->i_atime = inode->i_mtime = inode->i_ctime = current_time(inode);
745
		inode->i_mapping->private_data = resv_map;
746
		info->seals = F_SEAL_SEAL;
L
Linus Torvalds 已提交
747 748 749 750 751 752 753 754 755 756 757 758 759
		switch (mode & S_IFMT) {
		default:
			init_special_inode(inode, mode, dev);
			break;
		case S_IFREG:
			inode->i_op = &hugetlbfs_inode_operations;
			inode->i_fop = &hugetlbfs_file_operations;
			break;
		case S_IFDIR:
			inode->i_op = &hugetlbfs_dir_inode_operations;
			inode->i_fop = &simple_dir_operations;

			/* directory inodes start off with i_nlink == 2 (for "." entry) */
760
			inc_nlink(inode);
L
Linus Torvalds 已提交
761 762 763
			break;
		case S_IFLNK:
			inode->i_op = &page_symlink_inode_operations;
764
			inode_nohighmem(inode);
L
Linus Torvalds 已提交
765 766
			break;
		}
767
		lockdep_annotate_inode_mutex_key(inode);
768 769 770
	} else
		kref_put(&resv_map->refs, resv_map_release);

L
Linus Torvalds 已提交
771 772 773 774 775 776 777
	return inode;
}

/*
 * File creation. Allocate an inode, and we're done..
 */
static int hugetlbfs_mknod(struct inode *dir,
A
Al Viro 已提交
778
			struct dentry *dentry, umode_t mode, dev_t dev)
L
Linus Torvalds 已提交
779 780 781
{
	struct inode *inode;
	int error = -ENOSPC;
782 783

	inode = hugetlbfs_get_inode(dir->i_sb, dir, mode, dev);
L
Linus Torvalds 已提交
784
	if (inode) {
785
		dir->i_ctime = dir->i_mtime = current_time(dir);
L
Linus Torvalds 已提交
786 787 788 789 790 791 792
		d_instantiate(dentry, inode);
		dget(dentry);	/* Extra count - pin the dentry in core */
		error = 0;
	}
	return error;
}

793
static int hugetlbfs_mkdir(struct inode *dir, struct dentry *dentry, umode_t mode)
L
Linus Torvalds 已提交
794 795 796
{
	int retval = hugetlbfs_mknod(dir, dentry, mode | S_IFDIR, 0);
	if (!retval)
797
		inc_nlink(dir);
L
Linus Torvalds 已提交
798 799 800
	return retval;
}

A
Al Viro 已提交
801
static int hugetlbfs_create(struct inode *dir, struct dentry *dentry, umode_t mode, bool excl)
L
Linus Torvalds 已提交
802 803 804 805 806 807 808 809 810 811
{
	return hugetlbfs_mknod(dir, dentry, mode | S_IFREG, 0);
}

static int hugetlbfs_symlink(struct inode *dir,
			struct dentry *dentry, const char *symname)
{
	struct inode *inode;
	int error = -ENOSPC;

812
	inode = hugetlbfs_get_inode(dir->i_sb, dir, S_IFLNK|S_IRWXUGO, 0);
L
Linus Torvalds 已提交
813 814 815 816 817 818 819 820 821
	if (inode) {
		int l = strlen(symname)+1;
		error = page_symlink(inode, symname, l);
		if (!error) {
			d_instantiate(dentry, inode);
			dget(dentry);
		} else
			iput(inode);
	}
822
	dir->i_ctime = dir->i_mtime = current_time(dir);
L
Linus Torvalds 已提交
823 824 825 826 827

	return error;
}

/*
828
 * mark the head page dirty
L
Linus Torvalds 已提交
829 830 831
 */
static int hugetlbfs_set_page_dirty(struct page *page)
{
832
	struct page *head = compound_head(page);
833 834

	SetPageDirty(head);
L
Linus Torvalds 已提交
835 836 837
	return 0;
}

N
Naoya Horiguchi 已提交
838
static int hugetlbfs_migrate_page(struct address_space *mapping,
839
				struct page *newpage, struct page *page,
840
				enum migrate_mode mode)
N
Naoya Horiguchi 已提交
841 842 843 844
{
	int rc;

	rc = migrate_huge_page_move_mapping(mapping, newpage, page);
845
	if (rc != MIGRATEPAGE_SUCCESS)
N
Naoya Horiguchi 已提交
846
		return rc;
847 848 849 850
	if (mode != MIGRATE_SYNC_NO_COPY)
		migrate_page_copy(newpage, page);
	else
		migrate_page_states(newpage, page);
N
Naoya Horiguchi 已提交
851

852
	return MIGRATEPAGE_SUCCESS;
N
Naoya Horiguchi 已提交
853 854
}

855 856 857 858
static int hugetlbfs_error_remove_page(struct address_space *mapping,
				struct page *page)
{
	struct inode *inode = mapping->host;
859
	pgoff_t index = page->index;
860 861

	remove_huge_page(page);
862 863 864
	if (unlikely(hugetlb_unreserve_pages(inode, index, index + 1, 1)))
		hugetlb_fix_reserve_counts(inode);

865 866 867
	return 0;
}

868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907
/*
 * Display the mount options in /proc/mounts.
 */
static int hugetlbfs_show_options(struct seq_file *m, struct dentry *root)
{
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(root->d_sb);
	struct hugepage_subpool *spool = sbinfo->spool;
	unsigned long hpage_size = huge_page_size(sbinfo->hstate);
	unsigned hpage_shift = huge_page_shift(sbinfo->hstate);
	char mod;

	if (!uid_eq(sbinfo->uid, GLOBAL_ROOT_UID))
		seq_printf(m, ",uid=%u",
			   from_kuid_munged(&init_user_ns, sbinfo->uid));
	if (!gid_eq(sbinfo->gid, GLOBAL_ROOT_GID))
		seq_printf(m, ",gid=%u",
			   from_kgid_munged(&init_user_ns, sbinfo->gid));
	if (sbinfo->mode != 0755)
		seq_printf(m, ",mode=%o", sbinfo->mode);
	if (sbinfo->max_inodes != -1)
		seq_printf(m, ",nr_inodes=%lu", sbinfo->max_inodes);

	hpage_size /= 1024;
	mod = 'K';
	if (hpage_size >= 1024) {
		hpage_size /= 1024;
		mod = 'M';
	}
	seq_printf(m, ",pagesize=%lu%c", hpage_size, mod);
	if (spool) {
		if (spool->max_hpages != -1)
			seq_printf(m, ",size=%llu",
				   (unsigned long long)spool->max_hpages << hpage_shift);
		if (spool->min_hpages != -1)
			seq_printf(m, ",min_size=%llu",
				   (unsigned long long)spool->min_hpages << hpage_shift);
	}
	return 0;
}

908
static int hugetlbfs_statfs(struct dentry *dentry, struct kstatfs *buf)
L
Linus Torvalds 已提交
909
{
910
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(dentry->d_sb);
911
	struct hstate *h = hstate_inode(d_inode(dentry));
L
Linus Torvalds 已提交
912 913

	buf->f_type = HUGETLBFS_MAGIC;
914
	buf->f_bsize = huge_page_size(h);
L
Linus Torvalds 已提交
915 916
	if (sbinfo) {
		spin_lock(&sbinfo->stat_lock);
917 918
		/* If no limits set, just report 0 for max/free/used
		 * blocks, like simple_statfs() */
919 920 921 922 923 924 925 926 927
		if (sbinfo->spool) {
			long free_pages;

			spin_lock(&sbinfo->spool->lock);
			buf->f_blocks = sbinfo->spool->max_hpages;
			free_pages = sbinfo->spool->max_hpages
				- sbinfo->spool->used_hpages;
			buf->f_bavail = buf->f_bfree = free_pages;
			spin_unlock(&sbinfo->spool->lock);
928 929 930
			buf->f_files = sbinfo->max_inodes;
			buf->f_ffree = sbinfo->free_inodes;
		}
L
Linus Torvalds 已提交
931 932 933 934 935 936 937 938 939 940 941 942
		spin_unlock(&sbinfo->stat_lock);
	}
	buf->f_namelen = NAME_MAX;
	return 0;
}

static void hugetlbfs_put_super(struct super_block *sb)
{
	struct hugetlbfs_sb_info *sbi = HUGETLBFS_SB(sb);

	if (sbi) {
		sb->s_fs_info = NULL;
943 944 945 946

		if (sbi->spool)
			hugepage_put_subpool(sbi->spool);

L
Linus Torvalds 已提交
947 948 949 950
		kfree(sbi);
	}
}

951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975
static inline int hugetlbfs_dec_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		if (unlikely(!sbinfo->free_inodes)) {
			spin_unlock(&sbinfo->stat_lock);
			return 0;
		}
		sbinfo->free_inodes--;
		spin_unlock(&sbinfo->stat_lock);
	}

	return 1;
}

static void hugetlbfs_inc_free_inodes(struct hugetlbfs_sb_info *sbinfo)
{
	if (sbinfo->free_inodes >= 0) {
		spin_lock(&sbinfo->stat_lock);
		sbinfo->free_inodes++;
		spin_unlock(&sbinfo->stat_lock);
	}
}


976
static struct kmem_cache *hugetlbfs_inode_cachep;
L
Linus Torvalds 已提交
977 978 979

static struct inode *hugetlbfs_alloc_inode(struct super_block *sb)
{
980
	struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(sb);
L
Linus Torvalds 已提交
981 982
	struct hugetlbfs_inode_info *p;

983 984
	if (unlikely(!hugetlbfs_dec_free_inodes(sbinfo)))
		return NULL;
985
	p = kmem_cache_alloc(hugetlbfs_inode_cachep, GFP_KERNEL);
986 987
	if (unlikely(!p)) {
		hugetlbfs_inc_free_inodes(sbinfo);
L
Linus Torvalds 已提交
988
		return NULL;
989
	}
990 991 992 993 994 995 996 997 998 999 1000 1001

	/*
	 * Any time after allocation, hugetlbfs_destroy_inode can be called
	 * for the inode.  mpol_free_shared_policy is unconditionally called
	 * as part of hugetlbfs_destroy_inode.  So, initialize policy here
	 * in case of a quick call to destroy.
	 *
	 * Note that the policy is initialized even if we are creating a
	 * private inode.  This simplifies hugetlbfs_destroy_inode.
	 */
	mpol_shared_policy_init(&p->policy, NULL);

L
Linus Torvalds 已提交
1002 1003 1004
	return &p->vfs_inode;
}

N
Nick Piggin 已提交
1005 1006 1007 1008 1009 1010
static void hugetlbfs_i_callback(struct rcu_head *head)
{
	struct inode *inode = container_of(head, struct inode, i_rcu);
	kmem_cache_free(hugetlbfs_inode_cachep, HUGETLBFS_I(inode));
}

L
Linus Torvalds 已提交
1011 1012
static void hugetlbfs_destroy_inode(struct inode *inode)
{
1013
	hugetlbfs_inc_free_inodes(HUGETLBFS_SB(inode->i_sb));
L
Linus Torvalds 已提交
1014
	mpol_free_shared_policy(&HUGETLBFS_I(inode)->policy);
N
Nick Piggin 已提交
1015
	call_rcu(&inode->i_rcu, hugetlbfs_i_callback);
L
Linus Torvalds 已提交
1016 1017
}

1018
static const struct address_space_operations hugetlbfs_aops = {
N
Nick Piggin 已提交
1019 1020
	.write_begin	= hugetlbfs_write_begin,
	.write_end	= hugetlbfs_write_end,
L
Linus Torvalds 已提交
1021
	.set_page_dirty	= hugetlbfs_set_page_dirty,
N
Naoya Horiguchi 已提交
1022
	.migratepage    = hugetlbfs_migrate_page,
1023
	.error_remove_page	= hugetlbfs_error_remove_page,
L
Linus Torvalds 已提交
1024 1025
};

1026

1027
static void init_once(void *foo)
1028 1029 1030
{
	struct hugetlbfs_inode_info *ei = (struct hugetlbfs_inode_info *)foo;

C
Christoph Lameter 已提交
1031
	inode_init_once(&ei->vfs_inode);
1032 1033
}

1034
const struct file_operations hugetlbfs_file_operations = {
A
Al Viro 已提交
1035
	.read_iter		= hugetlbfs_read_iter,
L
Linus Torvalds 已提交
1036
	.mmap			= hugetlbfs_file_mmap,
1037
	.fsync			= noop_fsync,
L
Linus Torvalds 已提交
1038
	.get_unmapped_area	= hugetlb_get_unmapped_area,
1039 1040
	.llseek			= default_llseek,
	.fallocate		= hugetlbfs_fallocate,
L
Linus Torvalds 已提交
1041 1042
};

1043
static const struct inode_operations hugetlbfs_dir_inode_operations = {
L
Linus Torvalds 已提交
1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055
	.create		= hugetlbfs_create,
	.lookup		= simple_lookup,
	.link		= simple_link,
	.unlink		= simple_unlink,
	.symlink	= hugetlbfs_symlink,
	.mkdir		= hugetlbfs_mkdir,
	.rmdir		= simple_rmdir,
	.mknod		= hugetlbfs_mknod,
	.rename		= simple_rename,
	.setattr	= hugetlbfs_setattr,
};

1056
static const struct inode_operations hugetlbfs_inode_operations = {
L
Linus Torvalds 已提交
1057 1058 1059
	.setattr	= hugetlbfs_setattr,
};

1060
static const struct super_operations hugetlbfs_ops = {
L
Linus Torvalds 已提交
1061 1062
	.alloc_inode    = hugetlbfs_alloc_inode,
	.destroy_inode  = hugetlbfs_destroy_inode,
A
Al Viro 已提交
1063
	.evict_inode	= hugetlbfs_evict_inode,
L
Linus Torvalds 已提交
1064 1065
	.statfs		= hugetlbfs_statfs,
	.put_super	= hugetlbfs_put_super,
1066
	.show_options	= hugetlbfs_show_options,
L
Linus Torvalds 已提交
1067 1068
};

1069
enum hugetlbfs_size_type { NO_SIZE, SIZE_STD, SIZE_PERCENT };
1070 1071 1072 1073 1074 1075

/*
 * Convert size option passed from command line to number of huge pages
 * in the pool specified by hstate.  Size option could be in bytes
 * (val_type == SIZE_STD) or percentage of the pool (val_type == SIZE_PERCENT).
 */
1076
static long
1077
hugetlbfs_size_to_hpages(struct hstate *h, unsigned long long size_opt,
1078
			 enum hugetlbfs_size_type val_type)
1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092
{
	if (val_type == NO_SIZE)
		return -1;

	if (val_type == SIZE_PERCENT) {
		size_opt <<= huge_page_shift(h);
		size_opt *= h->max_huge_pages;
		do_div(size_opt, 100);
	}

	size_opt >>= huge_page_shift(h);
	return size_opt;
}

L
Linus Torvalds 已提交
1093 1094 1095
static int
hugetlbfs_parse_options(char *options, struct hugetlbfs_config *pconfig)
{
1096 1097 1098
	char *p, *rest;
	substring_t args[MAX_OPT_ARGS];
	int option;
1099
	unsigned long long max_size_opt = 0, min_size_opt = 0;
1100
	enum hugetlbfs_size_type max_val_type = NO_SIZE, min_val_type = NO_SIZE;
L
Linus Torvalds 已提交
1101 1102 1103 1104

	if (!options)
		return 0;

1105 1106
	while ((p = strsep(&options, ",")) != NULL) {
		int token;
1107 1108
		if (!*p)
			continue;
1109 1110 1111 1112 1113 1114

		token = match_token(p, tokens, args);
		switch (token) {
		case Opt_uid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1115 1116 1117
			pconfig->uid = make_kuid(current_user_ns(), option);
			if (!uid_valid(pconfig->uid))
				goto bad_val;
1118 1119 1120 1121 1122
			break;

		case Opt_gid:
			if (match_int(&args[0], &option))
 				goto bad_val;
1123 1124 1125
			pconfig->gid = make_kgid(current_user_ns(), option);
			if (!gid_valid(pconfig->gid))
				goto bad_val;
1126 1127 1128 1129 1130
			break;

		case Opt_mode:
			if (match_octal(&args[0], &option))
 				goto bad_val;
1131
			pconfig->mode = option & 01777U;
1132 1133 1134 1135 1136 1137
			break;

		case Opt_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
1138 1139
			max_size_opt = memparse(args[0].from, &rest);
			max_val_type = SIZE_STD;
1140
			if (*rest == '%')
1141
				max_val_type = SIZE_PERCENT;
1142 1143
			break;
		}
L
Linus Torvalds 已提交
1144

1145 1146 1147 1148 1149 1150 1151
		case Opt_nr_inodes:
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			pconfig->nr_inodes = memparse(args[0].from, &rest);
			break;

1152 1153 1154 1155 1156
		case Opt_pagesize: {
			unsigned long ps;
			ps = memparse(args[0].from, &rest);
			pconfig->hstate = size_to_hstate(ps);
			if (!pconfig->hstate) {
1157
				pr_err("Unsupported page size %lu MB\n",
1158 1159 1160 1161 1162 1163
					ps >> 20);
				return -EINVAL;
			}
			break;
		}

1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174
		case Opt_min_size: {
			/* memparse() will accept a K/M/G without a digit */
			if (!isdigit(*args[0].from))
				goto bad_val;
			min_size_opt = memparse(args[0].from, &rest);
			min_val_type = SIZE_STD;
			if (*rest == '%')
				min_val_type = SIZE_PERCENT;
			break;
		}

1175
		default:
1176
			pr_err("Bad mount option: \"%s\"\n", p);
1177
			return -EINVAL;
1178 1179
			break;
		}
L
Linus Torvalds 已提交
1180
	}
1181

1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197
	/*
	 * Use huge page pool size (in hstate) to convert the size
	 * options to number of huge pages.  If NO_SIZE, -1 is returned.
	 */
	pconfig->max_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						max_size_opt, max_val_type);
	pconfig->min_hpages = hugetlbfs_size_to_hpages(pconfig->hstate,
						min_size_opt, min_val_type);

	/*
	 * If max_size was specified, then min_size must be smaller
	 */
	if (max_val_type > NO_SIZE &&
	    pconfig->min_hpages > pconfig->max_hpages) {
		pr_err("minimum size can not be greater than maximum size\n");
		return -EINVAL;
1198 1199
	}

L
Linus Torvalds 已提交
1200
	return 0;
1201 1202

bad_val:
1203
	pr_err("Bad value '%s' for mount option '%s'\n", args[0].from, p);
1204
 	return -EINVAL;
L
Linus Torvalds 已提交
1205 1206 1207 1208 1209 1210 1211 1212 1213
}

static int
hugetlbfs_fill_super(struct super_block *sb, void *data, int silent)
{
	int ret;
	struct hugetlbfs_config config;
	struct hugetlbfs_sb_info *sbinfo;

1214
	config.max_hpages = -1; /* No limit on size by default */
L
Linus Torvalds 已提交
1215
	config.nr_inodes = -1; /* No limit on number of inodes by default */
1216 1217
	config.uid = current_fsuid();
	config.gid = current_fsgid();
L
Linus Torvalds 已提交
1218
	config.mode = 0755;
1219
	config.hstate = &default_hstate;
1220
	config.min_hpages = -1; /* No default minimum size */
L
Linus Torvalds 已提交
1221 1222 1223 1224 1225 1226 1227 1228
	ret = hugetlbfs_parse_options(data, &config);
	if (ret)
		return ret;

	sbinfo = kmalloc(sizeof(struct hugetlbfs_sb_info), GFP_KERNEL);
	if (!sbinfo)
		return -ENOMEM;
	sb->s_fs_info = sbinfo;
1229
	sbinfo->hstate = config.hstate;
L
Linus Torvalds 已提交
1230 1231 1232
	spin_lock_init(&sbinfo->stat_lock);
	sbinfo->max_inodes = config.nr_inodes;
	sbinfo->free_inodes = config.nr_inodes;
1233
	sbinfo->spool = NULL;
1234 1235 1236 1237
	sbinfo->uid = config.uid;
	sbinfo->gid = config.gid;
	sbinfo->mode = config.mode;

1238 1239 1240 1241 1242 1243 1244 1245 1246
	/*
	 * Allocate and initialize subpool if maximum or minimum size is
	 * specified.  Any needed reservations (for minimim size) are taken
	 * taken when the subpool is created.
	 */
	if (config.max_hpages != -1 || config.min_hpages != -1) {
		sbinfo->spool = hugepage_new_subpool(config.hstate,
							config.max_hpages,
							config.min_hpages);
1247 1248 1249
		if (!sbinfo->spool)
			goto out_free;
	}
L
Linus Torvalds 已提交
1250
	sb->s_maxbytes = MAX_LFS_FILESIZE;
1251 1252
	sb->s_blocksize = huge_page_size(config.hstate);
	sb->s_blocksize_bits = huge_page_shift(config.hstate);
L
Linus Torvalds 已提交
1253 1254 1255
	sb->s_magic = HUGETLBFS_MAGIC;
	sb->s_op = &hugetlbfs_ops;
	sb->s_time_gran = 1;
1256 1257
	sb->s_root = d_make_root(hugetlbfs_get_root(sb, &config));
	if (!sb->s_root)
L
Linus Torvalds 已提交
1258 1259 1260
		goto out_free;
	return 0;
out_free:
1261
	kfree(sbinfo->spool);
L
Linus Torvalds 已提交
1262 1263 1264 1265
	kfree(sbinfo);
	return -ENOMEM;
}

A
Al Viro 已提交
1266 1267
static struct dentry *hugetlbfs_mount(struct file_system_type *fs_type,
	int flags, const char *dev_name, void *data)
L
Linus Torvalds 已提交
1268
{
A
Al Viro 已提交
1269
	return mount_nodev(fs_type, flags, data, hugetlbfs_fill_super);
L
Linus Torvalds 已提交
1270 1271 1272 1273
}

static struct file_system_type hugetlbfs_fs_type = {
	.name		= "hugetlbfs",
A
Al Viro 已提交
1274
	.mount		= hugetlbfs_mount,
L
Linus Torvalds 已提交
1275 1276 1277
	.kill_sb	= kill_litter_super,
};

1278
static struct vfsmount *hugetlbfs_vfsmount[HUGE_MAX_HSTATE];
L
Linus Torvalds 已提交
1279

1280
static int can_do_hugetlb_shm(void)
L
Linus Torvalds 已提交
1281
{
1282 1283 1284
	kgid_t shm_group;
	shm_group = make_kgid(&init_user_ns, sysctl_hugetlb_shm_group);
	return capable(CAP_IPC_LOCK) || in_group_p(shm_group);
L
Linus Torvalds 已提交
1285 1286
}

1287 1288
static int get_hstate_idx(int page_size_log)
{
1289
	struct hstate *h = hstate_sizelog(page_size_log);
1290 1291 1292 1293 1294 1295

	if (!h)
		return -1;
	return h - hstates;
}

1296
static const struct dentry_operations anon_ops = {
1297
	.d_dname = simple_dname
1298 1299
};

1300 1301 1302 1303 1304 1305
/*
 * Note that size should be aligned to proper hugepage size in caller side,
 * otherwise hugetlb_reserve_pages reserves one less hugepages than intended.
 */
struct file *hugetlb_file_setup(const char *name, size_t size,
				vm_flags_t acctflag, struct user_struct **user,
1306
				int creat_flags, int page_size_log)
L
Linus Torvalds 已提交
1307
{
1308
	struct file *file = ERR_PTR(-ENOMEM);
L
Linus Torvalds 已提交
1309
	struct inode *inode;
1310
	struct path path;
1311
	struct super_block *sb;
L
Linus Torvalds 已提交
1312
	struct qstr quick_string;
1313 1314 1315 1316 1317
	int hstate_idx;

	hstate_idx = get_hstate_idx(page_size_log);
	if (hstate_idx < 0)
		return ERR_PTR(-ENODEV);
L
Linus Torvalds 已提交
1318

1319
	*user = NULL;
1320
	if (!hugetlbfs_vfsmount[hstate_idx])
1321 1322
		return ERR_PTR(-ENOENT);

1323
	if (creat_flags == HUGETLB_SHMFS_INODE && !can_do_hugetlb_shm()) {
1324 1325
		*user = current_user();
		if (user_shm_lock(size, *user)) {
1326
			task_lock(current);
1327
			pr_warn_once("%s (%d): Using mlock ulimits for SHM_HUGETLB is deprecated\n",
1328 1329
				current->comm, current->pid);
			task_unlock(current);
1330 1331
		} else {
			*user = NULL;
1332
			return ERR_PTR(-EPERM);
1333
		}
1334
	}
L
Linus Torvalds 已提交
1335

1336
	sb = hugetlbfs_vfsmount[hstate_idx]->mnt_sb;
1337
	quick_string.name = name;
L
Linus Torvalds 已提交
1338 1339
	quick_string.len = strlen(quick_string.name);
	quick_string.hash = 0;
1340
	path.dentry = d_alloc_pseudo(sb, &quick_string);
1341
	if (!path.dentry)
L
Linus Torvalds 已提交
1342 1343
		goto out_shm_unlock;

1344
	d_set_d_op(path.dentry, &anon_ops);
1345
	path.mnt = mntget(hugetlbfs_vfsmount[hstate_idx]);
1346
	file = ERR_PTR(-ENOSPC);
1347
	inode = hugetlbfs_get_inode(sb, NULL, S_IFREG | S_IRWXUGO, 0);
L
Linus Torvalds 已提交
1348
	if (!inode)
1349
		goto out_dentry;
1350 1351
	if (creat_flags == HUGETLB_SHMFS_INODE)
		inode->i_flags |= S_PRIVATE;
L
Linus Torvalds 已提交
1352

1353
	file = ERR_PTR(-ENOMEM);
1354 1355 1356
	if (hugetlb_reserve_pages(inode, 0,
			size >> huge_page_shift(hstate_inode(inode)), NULL,
			acctflag))
1357 1358
		goto out_inode;

1359
	d_instantiate(path.dentry, inode);
L
Linus Torvalds 已提交
1360
	inode->i_size = size;
1361
	clear_nlink(inode);
1362

1363
	file = alloc_file(&path, FMODE_WRITE | FMODE_READ,
1364
			&hugetlbfs_file_operations);
1365
	if (IS_ERR(file))
1366
		goto out_dentry; /* inode is already attached */
1367

L
Linus Torvalds 已提交
1368 1369
	return file;

1370 1371
out_inode:
	iput(inode);
L
Linus Torvalds 已提交
1372
out_dentry:
1373
	path_put(&path);
L
Linus Torvalds 已提交
1374
out_shm_unlock:
1375 1376 1377 1378
	if (*user) {
		user_shm_unlock(size, *user);
		*user = NULL;
	}
1379
	return file;
L
Linus Torvalds 已提交
1380 1381 1382 1383
}

static int __init init_hugetlbfs_fs(void)
{
1384
	struct hstate *h;
L
Linus Torvalds 已提交
1385
	int error;
1386
	int i;
L
Linus Torvalds 已提交
1387

1388
	if (!hugepages_supported()) {
1389
		pr_info("disabling because there are no supported hugepage sizes\n");
1390 1391 1392
		return -ENOTSUPP;
	}

1393
	error = -ENOMEM;
L
Linus Torvalds 已提交
1394 1395
	hugetlbfs_inode_cachep = kmem_cache_create("hugetlbfs_inode_cache",
					sizeof(struct hugetlbfs_inode_info),
1396
					0, SLAB_ACCOUNT, init_once);
L
Linus Torvalds 已提交
1397
	if (hugetlbfs_inode_cachep == NULL)
P
Peter Zijlstra 已提交
1398
		goto out2;
L
Linus Torvalds 已提交
1399 1400 1401 1402 1403

	error = register_filesystem(&hugetlbfs_fs_type);
	if (error)
		goto out;

1404 1405 1406 1407
	i = 0;
	for_each_hstate(h) {
		char buf[50];
		unsigned ps_kb = 1U << (h->order + PAGE_SHIFT - 10);
L
Linus Torvalds 已提交
1408

1409 1410 1411
		snprintf(buf, sizeof(buf), "pagesize=%uK", ps_kb);
		hugetlbfs_vfsmount[i] = kern_mount_data(&hugetlbfs_fs_type,
							buf);
L
Linus Torvalds 已提交
1412

1413
		if (IS_ERR(hugetlbfs_vfsmount[i])) {
1414
			pr_err("Cannot mount internal hugetlbfs for "
1415 1416 1417 1418 1419 1420 1421 1422 1423
				"page size %uK", ps_kb);
			error = PTR_ERR(hugetlbfs_vfsmount[i]);
			hugetlbfs_vfsmount[i] = NULL;
		}
		i++;
	}
	/* Non default hstates are optional */
	if (!IS_ERR_OR_NULL(hugetlbfs_vfsmount[default_hstate_idx]))
		return 0;
L
Linus Torvalds 已提交
1424 1425

 out:
1426
	kmem_cache_destroy(hugetlbfs_inode_cachep);
P
Peter Zijlstra 已提交
1427
 out2:
L
Linus Torvalds 已提交
1428 1429
	return error;
}
1430
fs_initcall(init_hugetlbfs_fs)