1 // SPDX-License-Identifier: GPL-2.0
3 * Copyright (C) 2019 Western Digital Corporation or its affiliates.
6 * Anup Patel <anup.patel@wdc.com>
9 #include <linux/bitops.h>
10 #include <linux/errno.h>
11 #include <linux/err.h>
12 #include <linux/hugetlb.h>
13 #include <linux/module.h>
14 #include <linux/uaccess.h>
15 #include <linux/vmalloc.h>
16 #include <linux/kvm_host.h>
17 #include <linux/sched/signal.h>
20 #include <asm/pgtable.h>
23 static unsigned long gstage_mode __ro_after_init = (HGATP_MODE_SV39X4 << HGATP_MODE_SHIFT);
24 static unsigned long gstage_pgd_levels __ro_after_init = 3;
25 #define gstage_index_bits 9
27 static unsigned long gstage_mode __ro_after_init = (HGATP_MODE_SV32X4 << HGATP_MODE_SHIFT);
28 static unsigned long gstage_pgd_levels __ro_after_init = 2;
29 #define gstage_index_bits 10
32 #define gstage_pgd_xbits 2
33 #define gstage_pgd_size (1UL << (HGATP_PAGE_SHIFT + gstage_pgd_xbits))
34 #define gstage_gpa_bits (HGATP_PAGE_SHIFT + \
35 (gstage_pgd_levels * gstage_index_bits) + \
37 #define gstage_gpa_size ((gpa_t)(1ULL << gstage_gpa_bits))
39 #define gstage_pte_leaf(__ptep) \
40 (pte_val(*(__ptep)) & (_PAGE_READ | _PAGE_WRITE | _PAGE_EXEC))
42 static inline unsigned long gstage_pte_index(gpa_t addr, u32 level)
45 unsigned long shift = HGATP_PAGE_SHIFT + (gstage_index_bits * level);
47 if (level == (gstage_pgd_levels - 1))
48 mask = (PTRS_PER_PTE * (1UL << gstage_pgd_xbits)) - 1;
50 mask = PTRS_PER_PTE - 1;
52 return (addr >> shift) & mask;
55 static inline unsigned long gstage_pte_page_vaddr(pte_t pte)
57 return (unsigned long)pfn_to_virt(__page_val_to_pfn(pte_val(pte)));
60 static int gstage_page_size_to_level(unsigned long page_size, u32 *out_level)
63 unsigned long psz = 1UL << 12;
65 for (i = 0; i < gstage_pgd_levels; i++) {
66 if (page_size == (psz << (i * gstage_index_bits))) {
75 static int gstage_level_to_page_order(u32 level, unsigned long *out_pgorder)
77 if (gstage_pgd_levels < level)
80 *out_pgorder = 12 + (level * gstage_index_bits);
84 static int gstage_level_to_page_size(u32 level, unsigned long *out_pgsize)
87 unsigned long page_order = PAGE_SHIFT;
89 rc = gstage_level_to_page_order(level, &page_order);
93 *out_pgsize = BIT(page_order);
97 static bool gstage_get_leaf_entry(struct kvm *kvm, gpa_t addr,
98 pte_t **ptepp, u32 *ptep_level)
101 u32 current_level = gstage_pgd_levels - 1;
103 *ptep_level = current_level;
104 ptep = (pte_t *)kvm->arch.pgd;
105 ptep = &ptep[gstage_pte_index(addr, current_level)];
106 while (ptep && pte_val(*ptep)) {
107 if (gstage_pte_leaf(ptep)) {
108 *ptep_level = current_level;
115 *ptep_level = current_level;
116 ptep = (pte_t *)gstage_pte_page_vaddr(*ptep);
117 ptep = &ptep[gstage_pte_index(addr, current_level)];
126 static void gstage_remote_tlb_flush(struct kvm *kvm, u32 level, gpa_t addr)
128 unsigned long order = PAGE_SHIFT;
130 if (gstage_level_to_page_order(level, &order))
132 addr &= ~(BIT(order) - 1);
134 kvm_riscv_hfence_gvma_vmid_gpa(kvm, -1UL, 0, addr, BIT(order), order);
137 static int gstage_set_pte(struct kvm *kvm, u32 level,
138 struct kvm_mmu_memory_cache *pcache,
139 gpa_t addr, const pte_t *new_pte)
141 u32 current_level = gstage_pgd_levels - 1;
142 pte_t *next_ptep = (pte_t *)kvm->arch.pgd;
143 pte_t *ptep = &next_ptep[gstage_pte_index(addr, current_level)];
145 if (current_level < level)
148 while (current_level != level) {
149 if (gstage_pte_leaf(ptep))
152 if (!pte_val(*ptep)) {
155 next_ptep = kvm_mmu_memory_cache_alloc(pcache);
158 *ptep = pfn_pte(PFN_DOWN(__pa(next_ptep)),
159 __pgprot(_PAGE_TABLE));
161 if (gstage_pte_leaf(ptep))
163 next_ptep = (pte_t *)gstage_pte_page_vaddr(*ptep);
167 ptep = &next_ptep[gstage_pte_index(addr, current_level)];
171 if (gstage_pte_leaf(ptep))
172 gstage_remote_tlb_flush(kvm, current_level, addr);
177 static int gstage_map_page(struct kvm *kvm,
178 struct kvm_mmu_memory_cache *pcache,
179 gpa_t gpa, phys_addr_t hpa,
180 unsigned long page_size,
181 bool page_rdonly, bool page_exec)
188 ret = gstage_page_size_to_level(page_size, &level);
193 * A RISC-V implementation can choose to either:
194 * 1) Update 'A' and 'D' PTE bits in hardware
195 * 2) Generate page fault when 'A' and/or 'D' bits are not set
196 * PTE so that software can update these bits.
198 * We support both options mentioned above. To achieve this, we
199 * always set 'A' and 'D' PTE bits at time of creating G-stage
200 * mapping. To support KVM dirty page logging with both options
201 * mentioned above, we will write-protect G-stage PTEs to track
207 prot = PAGE_READ_EXEC;
209 prot = PAGE_WRITE_EXEC;
216 new_pte = pfn_pte(PFN_DOWN(hpa), prot);
217 new_pte = pte_mkdirty(new_pte);
219 return gstage_set_pte(kvm, level, pcache, gpa, &new_pte);
223 GSTAGE_OP_NOP = 0, /* Nothing */
224 GSTAGE_OP_CLEAR, /* Clear/Unmap */
225 GSTAGE_OP_WP, /* Write-protect */
228 static void gstage_op_pte(struct kvm *kvm, gpa_t addr,
229 pte_t *ptep, u32 ptep_level, enum gstage_op op)
234 unsigned long next_page_size, page_size;
236 ret = gstage_level_to_page_size(ptep_level, &page_size);
240 BUG_ON(addr & (page_size - 1));
245 if (ptep_level && !gstage_pte_leaf(ptep)) {
246 next_ptep = (pte_t *)gstage_pte_page_vaddr(*ptep);
247 next_ptep_level = ptep_level - 1;
248 ret = gstage_level_to_page_size(next_ptep_level,
253 if (op == GSTAGE_OP_CLEAR)
254 set_pte(ptep, __pte(0));
255 for (i = 0; i < PTRS_PER_PTE; i++)
256 gstage_op_pte(kvm, addr + i * next_page_size,
257 &next_ptep[i], next_ptep_level, op);
258 if (op == GSTAGE_OP_CLEAR)
259 put_page(virt_to_page(next_ptep));
261 if (op == GSTAGE_OP_CLEAR)
262 set_pte(ptep, __pte(0));
263 else if (op == GSTAGE_OP_WP)
264 set_pte(ptep, __pte(pte_val(*ptep) & ~_PAGE_WRITE));
265 gstage_remote_tlb_flush(kvm, ptep_level, addr);
269 static void gstage_unmap_range(struct kvm *kvm, gpa_t start,
270 gpa_t size, bool may_block)
276 unsigned long page_size;
277 gpa_t addr = start, end = start + size;
280 found_leaf = gstage_get_leaf_entry(kvm, addr,
282 ret = gstage_level_to_page_size(ptep_level, &page_size);
289 if (!(addr & (page_size - 1)) && ((end - addr) >= page_size))
290 gstage_op_pte(kvm, addr, ptep,
291 ptep_level, GSTAGE_OP_CLEAR);
297 * If the range is too large, release the kvm->mmu_lock
298 * to prevent starvation and lockup detector warnings.
300 if (may_block && addr < end)
301 cond_resched_lock(&kvm->mmu_lock);
305 static void gstage_wp_range(struct kvm *kvm, gpa_t start, gpa_t end)
312 unsigned long page_size;
315 found_leaf = gstage_get_leaf_entry(kvm, addr,
317 ret = gstage_level_to_page_size(ptep_level, &page_size);
324 if (!(addr & (page_size - 1)) && ((end - addr) >= page_size))
325 gstage_op_pte(kvm, addr, ptep,
326 ptep_level, GSTAGE_OP_WP);
333 static void gstage_wp_memory_region(struct kvm *kvm, int slot)
335 struct kvm_memslots *slots = kvm_memslots(kvm);
336 struct kvm_memory_slot *memslot = id_to_memslot(slots, slot);
337 phys_addr_t start = memslot->base_gfn << PAGE_SHIFT;
338 phys_addr_t end = (memslot->base_gfn + memslot->npages) << PAGE_SHIFT;
340 spin_lock(&kvm->mmu_lock);
341 gstage_wp_range(kvm, start, end);
342 spin_unlock(&kvm->mmu_lock);
343 kvm_flush_remote_tlbs(kvm);
346 int kvm_riscv_gstage_ioremap(struct kvm *kvm, gpa_t gpa,
347 phys_addr_t hpa, unsigned long size,
348 bool writable, bool in_atomic)
353 phys_addr_t addr, end;
354 struct kvm_mmu_memory_cache pcache = {
355 .gfp_custom = (in_atomic) ? GFP_ATOMIC | __GFP_ACCOUNT : 0,
356 .gfp_zero = __GFP_ZERO,
359 end = (gpa + size + PAGE_SIZE - 1) & PAGE_MASK;
360 pfn = __phys_to_pfn(hpa);
362 for (addr = gpa; addr < end; addr += PAGE_SIZE) {
363 pte = pfn_pte(pfn, PAGE_KERNEL_IO);
366 pte = pte_wrprotect(pte);
368 ret = kvm_mmu_topup_memory_cache(&pcache, gstage_pgd_levels);
372 spin_lock(&kvm->mmu_lock);
373 ret = gstage_set_pte(kvm, 0, &pcache, addr, &pte);
374 spin_unlock(&kvm->mmu_lock);
382 kvm_mmu_free_memory_cache(&pcache);
386 void kvm_riscv_gstage_iounmap(struct kvm *kvm, gpa_t gpa, unsigned long size)
388 spin_lock(&kvm->mmu_lock);
389 gstage_unmap_range(kvm, gpa, size, false);
390 spin_unlock(&kvm->mmu_lock);
393 void kvm_arch_mmu_enable_log_dirty_pt_masked(struct kvm *kvm,
394 struct kvm_memory_slot *slot,
398 phys_addr_t base_gfn = slot->base_gfn + gfn_offset;
399 phys_addr_t start = (base_gfn + __ffs(mask)) << PAGE_SHIFT;
400 phys_addr_t end = (base_gfn + __fls(mask) + 1) << PAGE_SHIFT;
402 gstage_wp_range(kvm, start, end);
405 void kvm_arch_sync_dirty_log(struct kvm *kvm, struct kvm_memory_slot *memslot)
409 void kvm_arch_flush_remote_tlbs_memslot(struct kvm *kvm,
410 const struct kvm_memory_slot *memslot)
412 kvm_flush_remote_tlbs(kvm);
415 void kvm_arch_free_memslot(struct kvm *kvm, struct kvm_memory_slot *free)
419 void kvm_arch_memslots_updated(struct kvm *kvm, u64 gen)
423 void kvm_arch_flush_shadow_all(struct kvm *kvm)
425 kvm_riscv_gstage_free_pgd(kvm);
428 void kvm_arch_flush_shadow_memslot(struct kvm *kvm,
429 struct kvm_memory_slot *slot)
431 gpa_t gpa = slot->base_gfn << PAGE_SHIFT;
432 phys_addr_t size = slot->npages << PAGE_SHIFT;
434 spin_lock(&kvm->mmu_lock);
435 gstage_unmap_range(kvm, gpa, size, false);
436 spin_unlock(&kvm->mmu_lock);
439 void kvm_arch_commit_memory_region(struct kvm *kvm,
440 struct kvm_memory_slot *old,
441 const struct kvm_memory_slot *new,
442 enum kvm_mr_change change)
445 * At this point memslot has been committed and there is an
446 * allocated dirty_bitmap[], dirty pages will be tracked while
447 * the memory slot is write protected.
449 if (change != KVM_MR_DELETE && new->flags & KVM_MEM_LOG_DIRTY_PAGES)
450 gstage_wp_memory_region(kvm, new->id);
453 int kvm_arch_prepare_memory_region(struct kvm *kvm,
454 const struct kvm_memory_slot *old,
455 struct kvm_memory_slot *new,
456 enum kvm_mr_change change)
458 hva_t hva, reg_end, size;
463 if (change != KVM_MR_CREATE && change != KVM_MR_MOVE &&
464 change != KVM_MR_FLAGS_ONLY)
468 * Prevent userspace from creating a memory region outside of the GPA
469 * space addressable by the KVM guest GPA space.
471 if ((new->base_gfn + new->npages) >=
472 (gstage_gpa_size >> PAGE_SHIFT))
475 hva = new->userspace_addr;
476 size = new->npages << PAGE_SHIFT;
477 reg_end = hva + size;
478 base_gpa = new->base_gfn << PAGE_SHIFT;
479 writable = !(new->flags & KVM_MEM_READONLY);
481 mmap_read_lock(current->mm);
484 * A memory region could potentially cover multiple VMAs, and
485 * any holes between them, so iterate over all of them to find
486 * out if we can map any of them right now.
488 * +--------------------------------------------+
489 * +---------------+----------------+ +----------------+
490 * | : VMA 1 | VMA 2 | | VMA 3 : |
491 * +---------------+----------------+ +----------------+
493 * +--------------------------------------------+
496 struct vm_area_struct *vma = find_vma(current->mm, hva);
497 hva_t vm_start, vm_end;
499 if (!vma || vma->vm_start >= reg_end)
503 * Mapping a read-only VMA is only allowed if the
504 * memory region is configured as read-only.
506 if (writable && !(vma->vm_flags & VM_WRITE)) {
511 /* Take the intersection of this VMA with the memory region */
512 vm_start = max(hva, vma->vm_start);
513 vm_end = min(reg_end, vma->vm_end);
515 if (vma->vm_flags & VM_PFNMAP) {
516 gpa_t gpa = base_gpa + (vm_start - hva);
519 pa = (phys_addr_t)vma->vm_pgoff << PAGE_SHIFT;
520 pa += vm_start - vma->vm_start;
522 /* IO region dirty page logging not allowed */
523 if (new->flags & KVM_MEM_LOG_DIRTY_PAGES) {
528 ret = kvm_riscv_gstage_ioremap(kvm, gpa, pa,
535 } while (hva < reg_end);
537 if (change == KVM_MR_FLAGS_ONLY)
541 kvm_riscv_gstage_iounmap(kvm, base_gpa, size);
544 mmap_read_unlock(current->mm);
548 bool kvm_unmap_gfn_range(struct kvm *kvm, struct kvm_gfn_range *range)
553 gstage_unmap_range(kvm, range->start << PAGE_SHIFT,
554 (range->end - range->start) << PAGE_SHIFT,
559 bool kvm_set_spte_gfn(struct kvm *kvm, struct kvm_gfn_range *range)
562 kvm_pfn_t pfn = pte_pfn(range->pte);
567 WARN_ON(range->end - range->start != 1);
569 ret = gstage_map_page(kvm, NULL, range->start << PAGE_SHIFT,
570 __pfn_to_phys(pfn), PAGE_SIZE, true, true);
572 kvm_debug("Failed to map G-stage page (error %d)\n", ret);
579 bool kvm_age_gfn(struct kvm *kvm, struct kvm_gfn_range *range)
583 u64 size = (range->end - range->start) << PAGE_SHIFT;
588 WARN_ON(size != PAGE_SIZE && size != PMD_SIZE && size != PUD_SIZE);
590 if (!gstage_get_leaf_entry(kvm, range->start << PAGE_SHIFT,
594 return ptep_test_and_clear_young(NULL, 0, ptep);
597 bool kvm_test_age_gfn(struct kvm *kvm, struct kvm_gfn_range *range)
601 u64 size = (range->end - range->start) << PAGE_SHIFT;
606 WARN_ON(size != PAGE_SIZE && size != PMD_SIZE && size != PUD_SIZE);
608 if (!gstage_get_leaf_entry(kvm, range->start << PAGE_SHIFT,
612 return pte_young(*ptep);
615 int kvm_riscv_gstage_map(struct kvm_vcpu *vcpu,
616 struct kvm_memory_slot *memslot,
617 gpa_t gpa, unsigned long hva, bool is_write)
623 gfn_t gfn = gpa >> PAGE_SHIFT;
624 struct vm_area_struct *vma;
625 struct kvm *kvm = vcpu->kvm;
626 struct kvm_mmu_memory_cache *pcache = &vcpu->arch.mmu_page_cache;
627 bool logging = (memslot->dirty_bitmap &&
628 !(memslot->flags & KVM_MEM_READONLY)) ? true : false;
629 unsigned long vma_pagesize, mmu_seq;
631 /* We need minimum second+third level pages */
632 ret = kvm_mmu_topup_memory_cache(pcache, gstage_pgd_levels);
634 kvm_err("Failed to topup G-stage cache\n");
638 mmap_read_lock(current->mm);
640 vma = vma_lookup(current->mm, hva);
641 if (unlikely(!vma)) {
642 kvm_err("Failed to find VMA for hva 0x%lx\n", hva);
643 mmap_read_unlock(current->mm);
647 if (is_vm_hugetlb_page(vma))
648 vma_pageshift = huge_page_shift(hstate_vma(vma));
650 vma_pageshift = PAGE_SHIFT;
651 vma_pagesize = 1ULL << vma_pageshift;
652 if (logging || (vma->vm_flags & VM_PFNMAP))
653 vma_pagesize = PAGE_SIZE;
655 if (vma_pagesize == PMD_SIZE || vma_pagesize == PUD_SIZE)
656 gfn = (gpa & huge_page_mask(hstate_vma(vma))) >> PAGE_SHIFT;
659 * Read mmu_invalidate_seq so that KVM can detect if the results of
660 * vma_lookup() or gfn_to_pfn_prot() become stale priort to acquiring
663 * Rely on mmap_read_unlock() for an implicit smp_rmb(), which pairs
664 * with the smp_wmb() in kvm_mmu_invalidate_end().
666 mmu_seq = kvm->mmu_invalidate_seq;
667 mmap_read_unlock(current->mm);
669 if (vma_pagesize != PUD_SIZE &&
670 vma_pagesize != PMD_SIZE &&
671 vma_pagesize != PAGE_SIZE) {
672 kvm_err("Invalid VMA page size 0x%lx\n", vma_pagesize);
676 hfn = gfn_to_pfn_prot(kvm, gfn, is_write, &writable);
677 if (hfn == KVM_PFN_ERR_HWPOISON) {
678 send_sig_mceerr(BUS_MCEERR_AR, (void __user *)hva,
679 vma_pageshift, current);
682 if (is_error_noslot_pfn(hfn))
686 * If logging is active then we allow writable pages only
689 if (logging && !is_write)
692 spin_lock(&kvm->mmu_lock);
694 if (mmu_invalidate_retry(kvm, mmu_seq))
698 kvm_set_pfn_dirty(hfn);
699 mark_page_dirty(kvm, gfn);
700 ret = gstage_map_page(kvm, pcache, gpa, hfn << PAGE_SHIFT,
701 vma_pagesize, false, true);
703 ret = gstage_map_page(kvm, pcache, gpa, hfn << PAGE_SHIFT,
704 vma_pagesize, true, true);
708 kvm_err("Failed to map in G-stage\n");
711 spin_unlock(&kvm->mmu_lock);
712 kvm_set_pfn_accessed(hfn);
713 kvm_release_pfn_clean(hfn);
717 int kvm_riscv_gstage_alloc_pgd(struct kvm *kvm)
719 struct page *pgd_page;
721 if (kvm->arch.pgd != NULL) {
722 kvm_err("kvm_arch already initialized?\n");
726 pgd_page = alloc_pages(GFP_KERNEL | __GFP_ZERO,
727 get_order(gstage_pgd_size));
730 kvm->arch.pgd = page_to_virt(pgd_page);
731 kvm->arch.pgd_phys = page_to_phys(pgd_page);
736 void kvm_riscv_gstage_free_pgd(struct kvm *kvm)
740 spin_lock(&kvm->mmu_lock);
742 gstage_unmap_range(kvm, 0UL, gstage_gpa_size, false);
743 pgd = READ_ONCE(kvm->arch.pgd);
744 kvm->arch.pgd = NULL;
745 kvm->arch.pgd_phys = 0;
747 spin_unlock(&kvm->mmu_lock);
750 free_pages((unsigned long)pgd, get_order(gstage_pgd_size));
753 void kvm_riscv_gstage_update_hgatp(struct kvm_vcpu *vcpu)
755 unsigned long hgatp = gstage_mode;
756 struct kvm_arch *k = &vcpu->kvm->arch;
758 hgatp |= (READ_ONCE(k->vmid.vmid) << HGATP_VMID_SHIFT) & HGATP_VMID;
759 hgatp |= (k->pgd_phys >> PAGE_SHIFT) & HGATP_PPN;
761 csr_write(CSR_HGATP, hgatp);
763 if (!kvm_riscv_gstage_vmid_bits())
764 kvm_riscv_local_hfence_gvma_all();
767 void __init kvm_riscv_gstage_mode_detect(void)
770 /* Try Sv57x4 G-stage mode */
771 csr_write(CSR_HGATP, HGATP_MODE_SV57X4 << HGATP_MODE_SHIFT);
772 if ((csr_read(CSR_HGATP) >> HGATP_MODE_SHIFT) == HGATP_MODE_SV57X4) {
773 gstage_mode = (HGATP_MODE_SV57X4 << HGATP_MODE_SHIFT);
774 gstage_pgd_levels = 5;
775 goto skip_sv48x4_test;
778 /* Try Sv48x4 G-stage mode */
779 csr_write(CSR_HGATP, HGATP_MODE_SV48X4 << HGATP_MODE_SHIFT);
780 if ((csr_read(CSR_HGATP) >> HGATP_MODE_SHIFT) == HGATP_MODE_SV48X4) {
781 gstage_mode = (HGATP_MODE_SV48X4 << HGATP_MODE_SHIFT);
782 gstage_pgd_levels = 4;
786 csr_write(CSR_HGATP, 0);
787 kvm_riscv_local_hfence_gvma_all();
791 unsigned long __init kvm_riscv_gstage_mode(void)
793 return gstage_mode >> HGATP_MODE_SHIFT;
796 int kvm_riscv_gstage_gpa_bits(void)
798 return gstage_gpa_bits;