1b2441318SGreg Kroah-Hartman // SPDX-License-Identifier: GPL-2.0
21da177e4SLinus Torvalds /*
31da177e4SLinus Torvalds * linux/arch/alpha/mm/fault.c
41da177e4SLinus Torvalds *
51da177e4SLinus Torvalds * Copyright (C) 1995 Linus Torvalds
61da177e4SLinus Torvalds */
71da177e4SLinus Torvalds
83f07c014SIngo Molnar #include <linux/sched/signal.h>
91da177e4SLinus Torvalds #include <linux/kernel.h>
101da177e4SLinus Torvalds #include <linux/mm.h>
111da177e4SLinus Torvalds #include <asm/io.h>
121da177e4SLinus Torvalds
131da177e4SLinus Torvalds #define __EXTERN_INLINE inline
141da177e4SLinus Torvalds #include <asm/mmu_context.h>
151da177e4SLinus Torvalds #include <asm/tlbflush.h>
161da177e4SLinus Torvalds #undef __EXTERN_INLINE
171da177e4SLinus Torvalds
181da177e4SLinus Torvalds #include <linux/signal.h>
191da177e4SLinus Torvalds #include <linux/errno.h>
201da177e4SLinus Torvalds #include <linux/string.h>
211da177e4SLinus Torvalds #include <linux/types.h>
221da177e4SLinus Torvalds #include <linux/ptrace.h>
231da177e4SLinus Torvalds #include <linux/mman.h>
241da177e4SLinus Torvalds #include <linux/smp.h>
251da177e4SLinus Torvalds #include <linux/interrupt.h>
269c14f835SPaul Gortmaker #include <linux/extable.h>
2770ffdb93SDavid Hildenbrand #include <linux/uaccess.h>
28c0f6eda4SPeter Xu #include <linux/perf_event.h>
291da177e4SLinus Torvalds
301da177e4SLinus Torvalds extern void die_if_kernel(char *,struct pt_regs *,long, unsigned long *);
311da177e4SLinus Torvalds
321da177e4SLinus Torvalds
331da177e4SLinus Torvalds /*
341da177e4SLinus Torvalds * Force a new ASN for a task.
351da177e4SLinus Torvalds */
361da177e4SLinus Torvalds
371da177e4SLinus Torvalds #ifndef CONFIG_SMP
381da177e4SLinus Torvalds unsigned long last_asn = ASN_FIRST_VERSION;
391da177e4SLinus Torvalds #endif
401da177e4SLinus Torvalds
411da177e4SLinus Torvalds void
__load_new_mm_context(struct mm_struct * next_mm)421da177e4SLinus Torvalds __load_new_mm_context(struct mm_struct *next_mm)
431da177e4SLinus Torvalds {
441da177e4SLinus Torvalds unsigned long mmc;
451da177e4SLinus Torvalds struct pcb_struct *pcb;
461da177e4SLinus Torvalds
471da177e4SLinus Torvalds mmc = __get_new_mm_context(next_mm, smp_processor_id());
481da177e4SLinus Torvalds next_mm->context[smp_processor_id()] = mmc;
491da177e4SLinus Torvalds
501da177e4SLinus Torvalds pcb = ¤t_thread_info()->pcb;
511da177e4SLinus Torvalds pcb->asn = mmc & HARDWARE_ASN_MASK;
521da177e4SLinus Torvalds pcb->ptbr = ((unsigned long) next_mm->pgd - IDENT_ADDR) >> PAGE_SHIFT;
531da177e4SLinus Torvalds
541da177e4SLinus Torvalds __reload_thread(pcb);
551da177e4SLinus Torvalds }
561da177e4SLinus Torvalds
571da177e4SLinus Torvalds
581da177e4SLinus Torvalds /*
591da177e4SLinus Torvalds * This routine handles page faults. It determines the address,
601da177e4SLinus Torvalds * and the problem, and then passes it off to handle_mm_fault().
611da177e4SLinus Torvalds *
621da177e4SLinus Torvalds * mmcsr:
631da177e4SLinus Torvalds * 0 = translation not valid
641da177e4SLinus Torvalds * 1 = access violation
651da177e4SLinus Torvalds * 2 = fault-on-read
661da177e4SLinus Torvalds * 3 = fault-on-execute
671da177e4SLinus Torvalds * 4 = fault-on-write
681da177e4SLinus Torvalds *
691da177e4SLinus Torvalds * cause:
701da177e4SLinus Torvalds * -1 = instruction fetch
711da177e4SLinus Torvalds * 0 = load
721da177e4SLinus Torvalds * 1 = store
731da177e4SLinus Torvalds *
741da177e4SLinus Torvalds * Registers $9 through $15 are saved in a block just prior to `regs' and
751da177e4SLinus Torvalds * are saved and restored around the call to allow exception code to
761da177e4SLinus Torvalds * modify them.
771da177e4SLinus Torvalds */
781da177e4SLinus Torvalds
791da177e4SLinus Torvalds /* Macro for exception fixup code to access integer registers. */
801da177e4SLinus Torvalds #define dpf_reg(r) \
81*0f4573f8SIvan Kokshaysky (((unsigned long *)regs)[(r) <= 8 ? (r) : (r) <= 15 ? (r)-17 : \
82*0f4573f8SIvan Kokshaysky (r) <= 18 ? (r)+11 : (r)-10])
831da177e4SLinus Torvalds
841da177e4SLinus Torvalds asmlinkage void
do_page_fault(unsigned long address,unsigned long mmcsr,long cause,struct pt_regs * regs)851da177e4SLinus Torvalds do_page_fault(unsigned long address, unsigned long mmcsr,
861da177e4SLinus Torvalds long cause, struct pt_regs *regs)
871da177e4SLinus Torvalds {
881da177e4SLinus Torvalds struct vm_area_struct * vma;
891da177e4SLinus Torvalds struct mm_struct *mm = current->mm;
901da177e4SLinus Torvalds const struct exception_table_entry *fixup;
9150a7ca3cSSouptick Joarder int si_code = SEGV_MAPERR;
9250a7ca3cSSouptick Joarder vm_fault_t fault;
93dde16072SPeter Xu unsigned int flags = FAULT_FLAG_DEFAULT;
941da177e4SLinus Torvalds
951da177e4SLinus Torvalds /* As of EV6, a load into $31/$f31 is a prefetch, and never faults
961da177e4SLinus Torvalds (or is suppressed by the PALcode). Support that for older CPUs
971da177e4SLinus Torvalds by ignoring such an instruction. */
981da177e4SLinus Torvalds if (cause == 0) {
991da177e4SLinus Torvalds unsigned int insn;
1001da177e4SLinus Torvalds __get_user(insn, (unsigned int __user *)regs->pc);
1011da177e4SLinus Torvalds if ((insn >> 21 & 0x1f) == 0x1f &&
1021da177e4SLinus Torvalds /* ldq ldl ldt lds ldg ldf ldwu ldbu */
1031da177e4SLinus Torvalds (1ul << (insn >> 26) & 0x30f00001400ul)) {
1041da177e4SLinus Torvalds regs->pc += 4;
1051da177e4SLinus Torvalds return;
1061da177e4SLinus Torvalds }
1071da177e4SLinus Torvalds }
1081da177e4SLinus Torvalds
1091da177e4SLinus Torvalds /* If we're in an interrupt context, or have no user context,
1101da177e4SLinus Torvalds we must not take the fault. */
11170ffdb93SDavid Hildenbrand if (!mm || faulthandler_disabled())
1121da177e4SLinus Torvalds goto no_context;
1131da177e4SLinus Torvalds
1141da177e4SLinus Torvalds #ifdef CONFIG_ALPHA_LARGE_VMALLOC
1151da177e4SLinus Torvalds if (address >= TASK_SIZE)
1161da177e4SLinus Torvalds goto vmalloc_fault;
1171da177e4SLinus Torvalds #endif
118759496baSJohannes Weiner if (user_mode(regs))
119759496baSJohannes Weiner flags |= FAULT_FLAG_USER;
120c0f6eda4SPeter Xu perf_sw_event(PERF_COUNT_SW_PAGE_FAULTS, 1, regs, address);
1210bcc426bSKautuk Consul retry:
122a050ba1eSLinus Torvalds vma = lock_mm_and_find_vma(mm, address, regs);
1231da177e4SLinus Torvalds if (!vma)
124a050ba1eSLinus Torvalds goto bad_area_nosemaphore;
1251da177e4SLinus Torvalds
1261da177e4SLinus Torvalds /* Ok, we have a good vm_area for this memory access, so
1271da177e4SLinus Torvalds we can handle it. */
1281da177e4SLinus Torvalds si_code = SEGV_ACCERR;
1291da177e4SLinus Torvalds if (cause < 0) {
1301da177e4SLinus Torvalds if (!(vma->vm_flags & VM_EXEC))
1311da177e4SLinus Torvalds goto bad_area;
1321da177e4SLinus Torvalds } else if (!cause) {
1331da177e4SLinus Torvalds /* Allow reads even for write-only mappings */
1341da177e4SLinus Torvalds if (!(vma->vm_flags & (VM_READ | VM_WRITE)))
1351da177e4SLinus Torvalds goto bad_area;
1361da177e4SLinus Torvalds } else {
1371da177e4SLinus Torvalds if (!(vma->vm_flags & VM_WRITE))
1381da177e4SLinus Torvalds goto bad_area;
139759496baSJohannes Weiner flags |= FAULT_FLAG_WRITE;
1401da177e4SLinus Torvalds }
1411da177e4SLinus Torvalds
1421da177e4SLinus Torvalds /* If for any reason at all we couldn't handle the fault,
1431da177e4SLinus Torvalds make sure we exit gracefully rather than endlessly redo
1441da177e4SLinus Torvalds the fault. */
145c0f6eda4SPeter Xu fault = handle_mm_fault(vma, address, flags, regs);
1460bcc426bSKautuk Consul
147dce45493SAl Viro if (fault_signal_pending(fault, regs)) {
148dce45493SAl Viro if (!user_mode(regs))
149dce45493SAl Viro goto no_context;
1500bcc426bSKautuk Consul return;
151dce45493SAl Viro }
1520bcc426bSKautuk Consul
153d9272525SPeter Xu /* The fault is fully completed (including releasing mmap lock) */
154d9272525SPeter Xu if (fault & VM_FAULT_COMPLETED)
155d9272525SPeter Xu return;
156d9272525SPeter Xu
15783c54070SNick Piggin if (unlikely(fault & VM_FAULT_ERROR)) {
15883c54070SNick Piggin if (fault & VM_FAULT_OOM)
1591da177e4SLinus Torvalds goto out_of_memory;
16033692f27SLinus Torvalds else if (fault & VM_FAULT_SIGSEGV)
16133692f27SLinus Torvalds goto bad_area;
16283c54070SNick Piggin else if (fault & VM_FAULT_SIGBUS)
16383c54070SNick Piggin goto do_sigbus;
1641da177e4SLinus Torvalds BUG();
1651da177e4SLinus Torvalds }
1660bcc426bSKautuk Consul
1670bcc426bSKautuk Consul if (fault & VM_FAULT_RETRY) {
1684064b982SPeter Xu flags |= FAULT_FLAG_TRIED;
1690bcc426bSKautuk Consul
1703e4e28c5SMichel Lespinasse /* No need to mmap_read_unlock(mm) as we would
1710bcc426bSKautuk Consul * have already released it in __lock_page_or_retry
1720bcc426bSKautuk Consul * in mm/filemap.c.
1730bcc426bSKautuk Consul */
1740bcc426bSKautuk Consul
1750bcc426bSKautuk Consul goto retry;
1760bcc426bSKautuk Consul }
1770bcc426bSKautuk Consul
178d8ed45c5SMichel Lespinasse mmap_read_unlock(mm);
1790bcc426bSKautuk Consul
1801da177e4SLinus Torvalds return;
1811da177e4SLinus Torvalds
1821da177e4SLinus Torvalds /* Something tried to access memory that isn't in our memory map.
1831da177e4SLinus Torvalds Fix it, but check if it's kernel or user first. */
1841da177e4SLinus Torvalds bad_area:
185d8ed45c5SMichel Lespinasse mmap_read_unlock(mm);
1861da177e4SLinus Torvalds
187a050ba1eSLinus Torvalds bad_area_nosemaphore:
1881da177e4SLinus Torvalds if (user_mode(regs))
1891da177e4SLinus Torvalds goto do_sigsegv;
1901da177e4SLinus Torvalds
1911da177e4SLinus Torvalds no_context:
1921da177e4SLinus Torvalds /* Are we prepared to handle this fault as an exception? */
1931da177e4SLinus Torvalds if ((fixup = search_exception_tables(regs->pc)) != 0) {
1941da177e4SLinus Torvalds unsigned long newpc;
1951da177e4SLinus Torvalds newpc = fixup_exception(dpf_reg, fixup, regs->pc);
1961da177e4SLinus Torvalds regs->pc = newpc;
1971da177e4SLinus Torvalds return;
1981da177e4SLinus Torvalds }
1991da177e4SLinus Torvalds
2001da177e4SLinus Torvalds /* Oops. The kernel tried to access some bad page. We'll have to
2011da177e4SLinus Torvalds terminate things with extreme prejudice. */
2021da177e4SLinus Torvalds printk(KERN_ALERT "Unable to handle kernel paging request at "
2031da177e4SLinus Torvalds "virtual address %016lx\n", address);
2041da177e4SLinus Torvalds die_if_kernel("Oops", regs, cause, (unsigned long*)regs - 16);
2050e25498fSEric W. Biederman make_task_dead(SIGKILL);
2061da177e4SLinus Torvalds
2071da177e4SLinus Torvalds /* We ran out of memory, or some other thing happened to us that
2081da177e4SLinus Torvalds made us unable to handle the page fault gracefully. */
2091da177e4SLinus Torvalds out_of_memory:
210d8ed45c5SMichel Lespinasse mmap_read_unlock(mm);
2111da177e4SLinus Torvalds if (!user_mode(regs))
2121da177e4SLinus Torvalds goto no_context;
2131cb3d8e2SNick Piggin pagefault_out_of_memory();
2141cb3d8e2SNick Piggin return;
2151da177e4SLinus Torvalds
2161da177e4SLinus Torvalds do_sigbus:
217d8ed45c5SMichel Lespinasse mmap_read_unlock(mm);
2181da177e4SLinus Torvalds /* Send a sigbus, regardless of whether we were in kernel
2191da177e4SLinus Torvalds or user mode. */
2207de5f68dSEric W. Biederman force_sig_fault(SIGBUS, BUS_ADRERR, (void __user *) address);
2211da177e4SLinus Torvalds if (!user_mode(regs))
2221da177e4SLinus Torvalds goto no_context;
2231da177e4SLinus Torvalds return;
2241da177e4SLinus Torvalds
2251da177e4SLinus Torvalds do_sigsegv:
2267de5f68dSEric W. Biederman force_sig_fault(SIGSEGV, si_code, (void __user *) address);
2271da177e4SLinus Torvalds return;
2281da177e4SLinus Torvalds
2291da177e4SLinus Torvalds #ifdef CONFIG_ALPHA_LARGE_VMALLOC
2301da177e4SLinus Torvalds vmalloc_fault:
2311da177e4SLinus Torvalds if (user_mode(regs))
2321da177e4SLinus Torvalds goto do_sigsegv;
2331da177e4SLinus Torvalds else {
2341da177e4SLinus Torvalds /* Synchronize this task's top level page-table
2351da177e4SLinus Torvalds with the "reference" page table from init. */
2361da177e4SLinus Torvalds long index = pgd_index(address);
2371da177e4SLinus Torvalds pgd_t *pgd, *pgd_k;
2381da177e4SLinus Torvalds
2391da177e4SLinus Torvalds pgd = current->active_mm->pgd + index;
2401da177e4SLinus Torvalds pgd_k = swapper_pg_dir + index;
2411da177e4SLinus Torvalds if (!pgd_present(*pgd) && pgd_present(*pgd_k)) {
2421da177e4SLinus Torvalds pgd_val(*pgd) = pgd_val(*pgd_k);
2431da177e4SLinus Torvalds return;
2441da177e4SLinus Torvalds }
2451da177e4SLinus Torvalds goto no_context;
2461da177e4SLinus Torvalds }
2471da177e4SLinus Torvalds #endif
2481da177e4SLinus Torvalds }
249