1145eba1aSCai Huoqing // SPDX-License-Identifier: GPL-2.0 or BSD-3-Clause
2f48ad614SDennis Dalessandro /*
33d2a9d64SDennis Dalessandro  * Copyright(c) 2020 Cornelis Networks, Inc.
434ab4de7SMichael J. Ruhl  * Copyright(c) 2016 - 2017 Intel Corporation.
5f48ad614SDennis Dalessandro  */
6145eba1aSCai Huoqing 
7f48ad614SDennis Dalessandro #include <linux/list.h>
8f48ad614SDennis Dalessandro #include <linux/rculist.h>
9f48ad614SDennis Dalessandro #include <linux/mmu_notifier.h>
10f48ad614SDennis Dalessandro #include <linux/interval_tree_generic.h>
113d2a9d64SDennis Dalessandro #include <linux/sched/mm.h>
12f48ad614SDennis Dalessandro 
13f48ad614SDennis Dalessandro #include "mmu_rb.h"
14f48ad614SDennis Dalessandro #include "trace.h"
15f48ad614SDennis Dalessandro 
16f48ad614SDennis Dalessandro static unsigned long mmu_node_start(struct mmu_rb_node *);
17f48ad614SDennis Dalessandro static unsigned long mmu_node_last(struct mmu_rb_node *);
1893065ac7SMichal Hocko static int mmu_notifier_range_start(struct mmu_notifier *,
195d6527a7SJérôme Glisse 		const struct mmu_notifier_range *);
20f48ad614SDennis Dalessandro static struct mmu_rb_node *__mmu_rb_search(struct mmu_rb_handler *,
21f48ad614SDennis Dalessandro 					   unsigned long, unsigned long);
22c9358de1SBrendan Cunningham static void release_immediate(struct kref *refcount);
23b85ced91SDean Luick static void handle_remove(struct work_struct *work);
24f48ad614SDennis Dalessandro 
250fc859a6SBhumika Goyal static const struct mmu_notifier_ops mn_opts = {
26f48ad614SDennis Dalessandro 	.invalidate_range_start = mmu_notifier_range_start,
27f48ad614SDennis Dalessandro };
28f48ad614SDennis Dalessandro 
29f48ad614SDennis Dalessandro INTERVAL_TREE_DEFINE(struct mmu_rb_node, node, unsigned long, __last,
30f48ad614SDennis Dalessandro 		     mmu_node_start, mmu_node_last, static, __mmu_int_rb);
31f48ad614SDennis Dalessandro 
mmu_node_start(struct mmu_rb_node * node)32f48ad614SDennis Dalessandro static unsigned long mmu_node_start(struct mmu_rb_node *node)
33f48ad614SDennis Dalessandro {
34f48ad614SDennis Dalessandro 	return node->addr & PAGE_MASK;
35f48ad614SDennis Dalessandro }
36f48ad614SDennis Dalessandro 
mmu_node_last(struct mmu_rb_node * node)37f48ad614SDennis Dalessandro static unsigned long mmu_node_last(struct mmu_rb_node *node)
38f48ad614SDennis Dalessandro {
39f48ad614SDennis Dalessandro 	return PAGE_ALIGN(node->addr + node->len) - 1;
40f48ad614SDennis Dalessandro }
41f48ad614SDennis Dalessandro 
hfi1_mmu_rb_register(void * ops_arg,struct mmu_rb_ops * ops,struct workqueue_struct * wq,struct mmu_rb_handler ** handler)423d2a9d64SDennis Dalessandro int hfi1_mmu_rb_register(void *ops_arg,
43e0b09ac5SDean Luick 			 struct mmu_rb_ops *ops,
44b85ced91SDean Luick 			 struct workqueue_struct *wq,
45e0b09ac5SDean Luick 			 struct mmu_rb_handler **handler)
46f48ad614SDennis Dalessandro {
473d2a9d64SDennis Dalessandro 	struct mmu_rb_handler *h;
48866694afSPatrick Kelsey 	void *free_ptr;
493faa3d9aSIra Weiny 	int ret;
50f48ad614SDennis Dalessandro 
51866694afSPatrick Kelsey 	free_ptr = kzalloc(sizeof(*h) + cache_line_size() - 1, GFP_KERNEL);
52866694afSPatrick Kelsey 	if (!free_ptr)
53f48ad614SDennis Dalessandro 		return -ENOMEM;
54f48ad614SDennis Dalessandro 
55866694afSPatrick Kelsey 	h = PTR_ALIGN(free_ptr, cache_line_size());
563d2a9d64SDennis Dalessandro 	h->root = RB_ROOT_CACHED;
573d2a9d64SDennis Dalessandro 	h->ops = ops;
583d2a9d64SDennis Dalessandro 	h->ops_arg = ops_arg;
593d2a9d64SDennis Dalessandro 	INIT_HLIST_NODE(&h->mn.hlist);
603d2a9d64SDennis Dalessandro 	spin_lock_init(&h->lock);
613d2a9d64SDennis Dalessandro 	h->mn.ops = &mn_opts;
623d2a9d64SDennis Dalessandro 	INIT_WORK(&h->del_work, handle_remove);
633d2a9d64SDennis Dalessandro 	INIT_LIST_HEAD(&h->del_list);
643d2a9d64SDennis Dalessandro 	INIT_LIST_HEAD(&h->lru_list);
653d2a9d64SDennis Dalessandro 	h->wq = wq;
66866694afSPatrick Kelsey 	h->free_ptr = free_ptr;
673faa3d9aSIra Weiny 
683d2a9d64SDennis Dalessandro 	ret = mmu_notifier_register(&h->mn, current->mm);
693faa3d9aSIra Weiny 	if (ret) {
70866694afSPatrick Kelsey 		kfree(free_ptr);
713faa3d9aSIra Weiny 		return ret;
723faa3d9aSIra Weiny 	}
733faa3d9aSIra Weiny 
743d2a9d64SDennis Dalessandro 	*handler = h;
75e0b09ac5SDean Luick 	return 0;
76f48ad614SDennis Dalessandro }
77f48ad614SDennis Dalessandro 
hfi1_mmu_rb_unregister(struct mmu_rb_handler * handler)78e0b09ac5SDean Luick void hfi1_mmu_rb_unregister(struct mmu_rb_handler *handler)
79f48ad614SDennis Dalessandro {
8020a42d08SDean Luick 	struct mmu_rb_node *rbnode;
8120a42d08SDean Luick 	struct rb_node *node;
82f48ad614SDennis Dalessandro 	unsigned long flags;
83b85ced91SDean Luick 	struct list_head del_list;
84f48ad614SDennis Dalessandro 
852bbac98dSDouglas Miller 	/* Prevent freeing of mm until we are completely finished. */
862bbac98dSDouglas Miller 	mmgrab(handler->mn.mm);
872bbac98dSDouglas Miller 
88f48ad614SDennis Dalessandro 	/* Unregister first so we don't get any more notifications. */
893d2a9d64SDennis Dalessandro 	mmu_notifier_unregister(&handler->mn, handler->mn.mm);
90f48ad614SDennis Dalessandro 
91b85ced91SDean Luick 	/*
92b85ced91SDean Luick 	 * Make sure the wq delete handler is finished running.  It will not
93b85ced91SDean Luick 	 * be triggered once the mmu notifiers are unregistered above.
94b85ced91SDean Luick 	 */
95b85ced91SDean Luick 	flush_work(&handler->del_work);
96b85ced91SDean Luick 
97b85ced91SDean Luick 	INIT_LIST_HEAD(&del_list);
98b85ced91SDean Luick 
99f48ad614SDennis Dalessandro 	spin_lock_irqsave(&handler->lock, flags);
100f808c13fSDavidlohr Bueso 	while ((node = rb_first_cached(&handler->root))) {
101f48ad614SDennis Dalessandro 		rbnode = rb_entry(node, struct mmu_rb_node, node);
102f808c13fSDavidlohr Bueso 		rb_erase_cached(node, &handler->root);
1030636e9abSDean Luick 		/* move from LRU list to delete list */
1040636e9abSDean Luick 		list_move(&rbnode->list, &del_list);
105f48ad614SDennis Dalessandro 	}
106f48ad614SDennis Dalessandro 	spin_unlock_irqrestore(&handler->lock, flags);
107f48ad614SDennis Dalessandro 
108c9358de1SBrendan Cunningham 	while (!list_empty(&del_list)) {
109c9358de1SBrendan Cunningham 		rbnode = list_first_entry(&del_list, struct mmu_rb_node, list);
110c9358de1SBrendan Cunningham 		list_del(&rbnode->list);
111c9358de1SBrendan Cunningham 		kref_put(&rbnode->refcount, release_immediate);
112c9358de1SBrendan Cunningham 	}
113b85ced91SDean Luick 
1142bbac98dSDouglas Miller 	/* Now the mm may be freed. */
1152bbac98dSDouglas Miller 	mmdrop(handler->mn.mm);
1162bbac98dSDouglas Miller 
117866694afSPatrick Kelsey 	kfree(handler->free_ptr);
118f48ad614SDennis Dalessandro }
119f48ad614SDennis Dalessandro 
hfi1_mmu_rb_insert(struct mmu_rb_handler * handler,struct mmu_rb_node * mnode)120e0b09ac5SDean Luick int hfi1_mmu_rb_insert(struct mmu_rb_handler *handler,
121e0b09ac5SDean Luick 		       struct mmu_rb_node *mnode)
122f48ad614SDennis Dalessandro {
123f48ad614SDennis Dalessandro 	struct mmu_rb_node *node;
124f48ad614SDennis Dalessandro 	unsigned long flags;
125f48ad614SDennis Dalessandro 	int ret = 0;
126f48ad614SDennis Dalessandro 
127*e236e2eaSBrendan Cunningham 	trace_hfi1_mmu_rb_insert(mnode);
1283d2a9d64SDennis Dalessandro 
1293d2a9d64SDennis Dalessandro 	if (current->mm != handler->mn.mm)
1303d2a9d64SDennis Dalessandro 		return -EPERM;
1313d2a9d64SDennis Dalessandro 
132f48ad614SDennis Dalessandro 	spin_lock_irqsave(&handler->lock, flags);
133f48ad614SDennis Dalessandro 	node = __mmu_rb_search(handler, mnode->addr, mnode->len);
134f48ad614SDennis Dalessandro 	if (node) {
13500cbce5cSPatrick Kelsey 		ret = -EEXIST;
136f48ad614SDennis Dalessandro 		goto unlock;
137f48ad614SDennis Dalessandro 	}
138e0b09ac5SDean Luick 	__mmu_int_rb_insert(mnode, &handler->root);
1399fe8fec5SPatrick Kelsey 	list_add_tail(&mnode->list, &handler->lru_list);
1403d2a9d64SDennis Dalessandro 	mnode->handler = handler;
141f48ad614SDennis Dalessandro unlock:
142f48ad614SDennis Dalessandro 	spin_unlock_irqrestore(&handler->lock, flags);
143f48ad614SDennis Dalessandro 	return ret;
144f48ad614SDennis Dalessandro }
145f48ad614SDennis Dalessandro 
146f48ad614SDennis Dalessandro /* Caller must hold handler lock */
hfi1_mmu_rb_get_first(struct mmu_rb_handler * handler,unsigned long addr,unsigned long len)14700cbce5cSPatrick Kelsey struct mmu_rb_node *hfi1_mmu_rb_get_first(struct mmu_rb_handler *handler,
14800cbce5cSPatrick Kelsey 					  unsigned long addr, unsigned long len)
14900cbce5cSPatrick Kelsey {
15000cbce5cSPatrick Kelsey 	struct mmu_rb_node *node;
15100cbce5cSPatrick Kelsey 
15200cbce5cSPatrick Kelsey 	trace_hfi1_mmu_rb_search(addr, len);
15300cbce5cSPatrick Kelsey 	node = __mmu_int_rb_iter_first(&handler->root, addr, (addr + len) - 1);
15400cbce5cSPatrick Kelsey 	if (node)
15500cbce5cSPatrick Kelsey 		list_move_tail(&node->list, &handler->lru_list);
15600cbce5cSPatrick Kelsey 	return node;
15700cbce5cSPatrick Kelsey }
15800cbce5cSPatrick Kelsey 
15900cbce5cSPatrick Kelsey /* Caller must hold handler lock */
__mmu_rb_search(struct mmu_rb_handler * handler,unsigned long addr,unsigned long len)160f48ad614SDennis Dalessandro static struct mmu_rb_node *__mmu_rb_search(struct mmu_rb_handler *handler,
161f48ad614SDennis Dalessandro 					   unsigned long addr,
162f48ad614SDennis Dalessandro 					   unsigned long len)
163f48ad614SDennis Dalessandro {
164f48ad614SDennis Dalessandro 	struct mmu_rb_node *node = NULL;
165f48ad614SDennis Dalessandro 
16634ab4de7SMichael J. Ruhl 	trace_hfi1_mmu_rb_search(addr, len);
167f48ad614SDennis Dalessandro 	if (!handler->ops->filter) {
168e0b09ac5SDean Luick 		node = __mmu_int_rb_iter_first(&handler->root, addr,
169f48ad614SDennis Dalessandro 					       (addr + len) - 1);
170f48ad614SDennis Dalessandro 	} else {
171e0b09ac5SDean Luick 		for (node = __mmu_int_rb_iter_first(&handler->root, addr,
172f48ad614SDennis Dalessandro 						    (addr + len) - 1);
173f48ad614SDennis Dalessandro 		     node;
174f48ad614SDennis Dalessandro 		     node = __mmu_int_rb_iter_next(node, addr,
175f48ad614SDennis Dalessandro 						   (addr + len) - 1)) {
176f48ad614SDennis Dalessandro 			if (handler->ops->filter(node, addr, len))
177f48ad614SDennis Dalessandro 				return node;
178f48ad614SDennis Dalessandro 		}
179f48ad614SDennis Dalessandro 	}
180f48ad614SDennis Dalessandro 	return node;
181f48ad614SDennis Dalessandro }
182f48ad614SDennis Dalessandro 
183c9358de1SBrendan Cunningham /*
184c9358de1SBrendan Cunningham  * Must NOT call while holding mnode->handler->lock.
185c9358de1SBrendan Cunningham  * mnode->handler->ops->remove() may sleep and mnode->handler->lock is a
186c9358de1SBrendan Cunningham  * spinlock.
187c9358de1SBrendan Cunningham  */
release_immediate(struct kref * refcount)188c9358de1SBrendan Cunningham static void release_immediate(struct kref *refcount)
189c9358de1SBrendan Cunningham {
190c9358de1SBrendan Cunningham 	struct mmu_rb_node *mnode =
191c9358de1SBrendan Cunningham 		container_of(refcount, struct mmu_rb_node, refcount);
192*e236e2eaSBrendan Cunningham 	trace_hfi1_mmu_release_node(mnode);
193c9358de1SBrendan Cunningham 	mnode->handler->ops->remove(mnode->handler->ops_arg, mnode);
194c9358de1SBrendan Cunningham }
195c9358de1SBrendan Cunningham 
196c9358de1SBrendan Cunningham /* Caller must hold mnode->handler->lock */
release_nolock(struct kref * refcount)197c9358de1SBrendan Cunningham static void release_nolock(struct kref *refcount)
198c9358de1SBrendan Cunningham {
199c9358de1SBrendan Cunningham 	struct mmu_rb_node *mnode =
200c9358de1SBrendan Cunningham 		container_of(refcount, struct mmu_rb_node, refcount);
201c9358de1SBrendan Cunningham 	list_move(&mnode->list, &mnode->handler->del_list);
202c9358de1SBrendan Cunningham 	queue_work(mnode->handler->wq, &mnode->handler->del_work);
203c9358de1SBrendan Cunningham }
204c9358de1SBrendan Cunningham 
205c9358de1SBrendan Cunningham /*
206c9358de1SBrendan Cunningham  * struct mmu_rb_node->refcount kref_put() callback.
207c9358de1SBrendan Cunningham  * Adds mmu_rb_node to mmu_rb_node->handler->del_list and queues
208c9358de1SBrendan Cunningham  * handler->del_work on handler->wq.
209c9358de1SBrendan Cunningham  * Does not remove mmu_rb_node from handler->lru_list or handler->rb_root.
210c9358de1SBrendan Cunningham  * Acquires mmu_rb_node->handler->lock; do not call while already holding
211c9358de1SBrendan Cunningham  * handler->lock.
212c9358de1SBrendan Cunningham  */
hfi1_mmu_rb_release(struct kref * refcount)213c9358de1SBrendan Cunningham void hfi1_mmu_rb_release(struct kref *refcount)
214c9358de1SBrendan Cunningham {
215c9358de1SBrendan Cunningham 	struct mmu_rb_node *mnode =
216c9358de1SBrendan Cunningham 		container_of(refcount, struct mmu_rb_node, refcount);
217c9358de1SBrendan Cunningham 	struct mmu_rb_handler *handler = mnode->handler;
218c9358de1SBrendan Cunningham 	unsigned long flags;
219c9358de1SBrendan Cunningham 
220c9358de1SBrendan Cunningham 	spin_lock_irqsave(&handler->lock, flags);
221c9358de1SBrendan Cunningham 	list_move(&mnode->list, &mnode->handler->del_list);
222c9358de1SBrendan Cunningham 	spin_unlock_irqrestore(&handler->lock, flags);
223c9358de1SBrendan Cunningham 	queue_work(handler->wq, &handler->del_work);
224c9358de1SBrendan Cunningham }
225c9358de1SBrendan Cunningham 
hfi1_mmu_rb_evict(struct mmu_rb_handler * handler,void * evict_arg)22610345998SDean Luick void hfi1_mmu_rb_evict(struct mmu_rb_handler *handler, void *evict_arg)
22710345998SDean Luick {
2280636e9abSDean Luick 	struct mmu_rb_node *rbnode, *ptr;
22910345998SDean Luick 	struct list_head del_list;
23010345998SDean Luick 	unsigned long flags;
23110345998SDean Luick 	bool stop = false;
23210345998SDean Luick 
2333d2a9d64SDennis Dalessandro 	if (current->mm != handler->mn.mm)
2343d2a9d64SDennis Dalessandro 		return;
2353d2a9d64SDennis Dalessandro 
23610345998SDean Luick 	INIT_LIST_HEAD(&del_list);
23710345998SDean Luick 
23810345998SDean Luick 	spin_lock_irqsave(&handler->lock, flags);
2399fe8fec5SPatrick Kelsey 	list_for_each_entry_safe(rbnode, ptr, &handler->lru_list, list) {
240c9358de1SBrendan Cunningham 		/* refcount == 1 implies mmu_rb_handler has only rbnode ref */
241c9358de1SBrendan Cunningham 		if (kref_read(&rbnode->refcount) > 1)
242c9358de1SBrendan Cunningham 			continue;
243c9358de1SBrendan Cunningham 
24410345998SDean Luick 		if (handler->ops->evict(handler->ops_arg, rbnode, evict_arg,
24510345998SDean Luick 					&stop)) {
24610345998SDean Luick 			__mmu_int_rb_remove(rbnode, &handler->root);
2470636e9abSDean Luick 			/* move from LRU list to delete list */
2480636e9abSDean Luick 			list_move(&rbnode->list, &del_list);
24910345998SDean Luick 		}
25010345998SDean Luick 		if (stop)
25110345998SDean Luick 			break;
25210345998SDean Luick 	}
25310345998SDean Luick 	spin_unlock_irqrestore(&handler->lock, flags);
25410345998SDean Luick 
2559fe8fec5SPatrick Kelsey 	list_for_each_entry_safe(rbnode, ptr, &del_list, list) {
256*e236e2eaSBrendan Cunningham 		trace_hfi1_mmu_rb_evict(rbnode);
257c9358de1SBrendan Cunningham 		kref_put(&rbnode->refcount, release_immediate);
25810345998SDean Luick 	}
25910345998SDean Luick }
26010345998SDean Luick 
mmu_notifier_range_start(struct mmu_notifier * mn,const struct mmu_notifier_range * range)26193065ac7SMichal Hocko static int mmu_notifier_range_start(struct mmu_notifier *mn,
2625d6527a7SJérôme Glisse 		const struct mmu_notifier_range *range)
263f48ad614SDennis Dalessandro {
264f48ad614SDennis Dalessandro 	struct mmu_rb_handler *handler =
265f48ad614SDennis Dalessandro 		container_of(mn, struct mmu_rb_handler, mn);
266f808c13fSDavidlohr Bueso 	struct rb_root_cached *root = &handler->root;
267f48ad614SDennis Dalessandro 	struct mmu_rb_node *node, *ptr = NULL;
268f48ad614SDennis Dalessandro 	unsigned long flags;
269f48ad614SDennis Dalessandro 
270f48ad614SDennis Dalessandro 	spin_lock_irqsave(&handler->lock, flags);
2715d6527a7SJérôme Glisse 	for (node = __mmu_int_rb_iter_first(root, range->start, range->end-1);
272f48ad614SDennis Dalessandro 	     node; node = ptr) {
273f48ad614SDennis Dalessandro 		/* Guard against node removal. */
2745d6527a7SJérôme Glisse 		ptr = __mmu_int_rb_iter_next(node, range->start,
2755d6527a7SJérôme Glisse 					     range->end - 1);
276*e236e2eaSBrendan Cunningham 		trace_hfi1_mmu_mem_invalidate(node);
277c9358de1SBrendan Cunningham 		/* Remove from rb tree and lru_list. */
278f48ad614SDennis Dalessandro 		__mmu_int_rb_remove(node, root);
279c9358de1SBrendan Cunningham 		list_del_init(&node->list);
280c9358de1SBrendan Cunningham 		kref_put(&node->refcount, release_nolock);
281f48ad614SDennis Dalessandro 	}
282f48ad614SDennis Dalessandro 	spin_unlock_irqrestore(&handler->lock, flags);
283b85ced91SDean Luick 
28493065ac7SMichal Hocko 	return 0;
285b85ced91SDean Luick }
286b85ced91SDean Luick 
287b85ced91SDean Luick /*
288b85ced91SDean Luick  * Work queue function to remove all nodes that have been queued up to
289c1e8d7c6SMichel Lespinasse  * be removed.  The key feature is that mm->mmap_lock is not being held
290b85ced91SDean Luick  * and the remove callback can sleep while taking it, if needed.
291b85ced91SDean Luick  */
handle_remove(struct work_struct * work)292b85ced91SDean Luick static void handle_remove(struct work_struct *work)
293b85ced91SDean Luick {
294b85ced91SDean Luick 	struct mmu_rb_handler *handler = container_of(work,
295b85ced91SDean Luick 						struct mmu_rb_handler,
296b85ced91SDean Luick 						del_work);
297b85ced91SDean Luick 	struct list_head del_list;
298b85ced91SDean Luick 	unsigned long flags;
299c9358de1SBrendan Cunningham 	struct mmu_rb_node *node;
300b85ced91SDean Luick 
301b85ced91SDean Luick 	/* remove anything that is queued to get removed */
302b85ced91SDean Luick 	spin_lock_irqsave(&handler->lock, flags);
303b85ced91SDean Luick 	list_replace_init(&handler->del_list, &del_list);
304b85ced91SDean Luick 	spin_unlock_irqrestore(&handler->lock, flags);
305b85ced91SDean Luick 
306c9358de1SBrendan Cunningham 	while (!list_empty(&del_list)) {
307c9358de1SBrendan Cunningham 		node = list_first_entry(&del_list, struct mmu_rb_node, list);
308c9358de1SBrendan Cunningham 		list_del(&node->list);
309*e236e2eaSBrendan Cunningham 		trace_hfi1_mmu_release_node(node);
310c9358de1SBrendan Cunningham 		handler->ops->remove(handler->ops_arg, node);
311c9358de1SBrendan Cunningham 	}
312f48ad614SDennis Dalessandro }
313