2016-03-08 19:14:20 +00:00
|
|
|
/*
|
|
|
|
* Copyright(c) 2016 Intel Corporation.
|
|
|
|
*
|
|
|
|
* This file is provided under a dual BSD/GPLv2 license. When using or
|
|
|
|
* redistributing this file, you may do so under either license.
|
|
|
|
*
|
|
|
|
* GPL LICENSE SUMMARY
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify
|
|
|
|
* it under the terms of version 2 of the GNU General Public License as
|
|
|
|
* published by the Free Software Foundation.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
|
|
* General Public License for more details.
|
|
|
|
*
|
|
|
|
* BSD LICENSE
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
*
|
|
|
|
* - Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
|
|
|
* - Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in
|
|
|
|
* the documentation and/or other materials provided with the
|
|
|
|
* distribution.
|
|
|
|
* - Neither the name of Intel Corporation nor the names of its
|
|
|
|
* contributors may be used to endorse or promote products derived
|
|
|
|
* from this software without specific prior written permission.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
|
|
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
|
|
|
* A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
|
|
|
* OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
|
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
#include <linux/list.h>
|
2016-05-12 17:23:09 +00:00
|
|
|
#include <linux/rculist.h>
|
2016-03-08 19:14:20 +00:00
|
|
|
#include <linux/mmu_notifier.h>
|
2016-03-08 19:14:53 +00:00
|
|
|
#include <linux/interval_tree_generic.h>
|
2016-03-08 19:14:20 +00:00
|
|
|
|
|
|
|
#include "mmu_rb.h"
|
|
|
|
#include "trace.h"
|
|
|
|
|
|
|
|
struct mmu_rb_handler {
|
|
|
|
struct list_head list;
|
|
|
|
struct mmu_notifier mn;
|
|
|
|
struct rb_root *root;
|
|
|
|
spinlock_t lock; /* protect the RB tree */
|
|
|
|
struct mmu_rb_ops *ops;
|
|
|
|
};
|
|
|
|
|
|
|
|
static LIST_HEAD(mmu_rb_handlers);
|
|
|
|
static DEFINE_SPINLOCK(mmu_rb_lock); /* protect mmu_rb_handlers list */
|
|
|
|
|
2016-03-08 19:14:53 +00:00
|
|
|
static unsigned long mmu_node_start(struct mmu_rb_node *);
|
|
|
|
static unsigned long mmu_node_last(struct mmu_rb_node *);
|
2016-03-08 19:14:20 +00:00
|
|
|
static struct mmu_rb_handler *find_mmu_handler(struct rb_root *);
|
|
|
|
static inline void mmu_notifier_page(struct mmu_notifier *, struct mm_struct *,
|
|
|
|
unsigned long);
|
|
|
|
static inline void mmu_notifier_range_start(struct mmu_notifier *,
|
|
|
|
struct mm_struct *,
|
|
|
|
unsigned long, unsigned long);
|
|
|
|
static void mmu_notifier_mem_invalidate(struct mmu_notifier *,
|
2016-04-12 17:45:57 +00:00
|
|
|
struct mm_struct *,
|
2016-03-08 19:14:20 +00:00
|
|
|
unsigned long, unsigned long);
|
|
|
|
static struct mmu_rb_node *__mmu_rb_search(struct mmu_rb_handler *,
|
|
|
|
unsigned long, unsigned long);
|
|
|
|
|
|
|
|
static struct mmu_notifier_ops mn_opts = {
|
|
|
|
.invalidate_page = mmu_notifier_page,
|
|
|
|
.invalidate_range_start = mmu_notifier_range_start,
|
|
|
|
};
|
|
|
|
|
2016-03-08 19:14:53 +00:00
|
|
|
INTERVAL_TREE_DEFINE(struct mmu_rb_node, node, unsigned long, __last,
|
|
|
|
mmu_node_start, mmu_node_last, static, __mmu_int_rb);
|
|
|
|
|
|
|
|
static unsigned long mmu_node_start(struct mmu_rb_node *node)
|
|
|
|
{
|
|
|
|
return node->addr & PAGE_MASK;
|
|
|
|
}
|
|
|
|
|
|
|
|
static unsigned long mmu_node_last(struct mmu_rb_node *node)
|
|
|
|
{
|
2016-04-12 17:46:41 +00:00
|
|
|
return PAGE_ALIGN(node->addr + node->len) - 1;
|
2016-03-08 19:14:53 +00:00
|
|
|
}
|
|
|
|
|
2016-03-08 19:14:20 +00:00
|
|
|
int hfi1_mmu_rb_register(struct rb_root *root, struct mmu_rb_ops *ops)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handlr;
|
|
|
|
|
|
|
|
handlr = kmalloc(sizeof(*handlr), GFP_KERNEL);
|
|
|
|
if (!handlr)
|
|
|
|
return -ENOMEM;
|
|
|
|
|
|
|
|
handlr->root = root;
|
|
|
|
handlr->ops = ops;
|
|
|
|
INIT_HLIST_NODE(&handlr->mn.hlist);
|
|
|
|
spin_lock_init(&handlr->lock);
|
|
|
|
handlr->mn.ops = &mn_opts;
|
2016-05-12 17:23:09 +00:00
|
|
|
spin_lock(&mmu_rb_lock);
|
|
|
|
list_add_tail_rcu(&handlr->list, &mmu_rb_handlers);
|
|
|
|
spin_unlock(&mmu_rb_lock);
|
2016-03-08 19:14:20 +00:00
|
|
|
|
|
|
|
return mmu_notifier_register(&handlr->mn, current->mm);
|
|
|
|
}
|
|
|
|
|
|
|
|
void hfi1_mmu_rb_unregister(struct rb_root *root)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handler = find_mmu_handler(root);
|
2016-07-28 16:27:36 +00:00
|
|
|
struct mmu_rb_node *rbnode;
|
|
|
|
struct rb_node *node;
|
2016-03-08 19:14:25 +00:00
|
|
|
unsigned long flags;
|
2016-03-08 19:14:20 +00:00
|
|
|
|
2016-03-08 19:14:31 +00:00
|
|
|
if (!handler)
|
|
|
|
return;
|
|
|
|
|
2016-04-12 17:46:35 +00:00
|
|
|
/* Unregister first so we don't get any more notifications. */
|
|
|
|
if (current->mm)
|
|
|
|
mmu_notifier_unregister(&handler->mn, current->mm);
|
|
|
|
|
2016-05-12 17:23:09 +00:00
|
|
|
spin_lock(&mmu_rb_lock);
|
|
|
|
list_del_rcu(&handler->list);
|
|
|
|
spin_unlock(&mmu_rb_lock);
|
|
|
|
synchronize_rcu();
|
2016-03-08 19:14:20 +00:00
|
|
|
|
2016-04-12 17:46:35 +00:00
|
|
|
spin_lock_irqsave(&handler->lock, flags);
|
2016-07-28 16:27:36 +00:00
|
|
|
while ((node = rb_first(root))) {
|
|
|
|
rbnode = rb_entry(node, struct mmu_rb_node, node);
|
|
|
|
rb_erase(node, root);
|
|
|
|
handler->ops->remove(root, rbnode, NULL);
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
2016-04-12 17:46:35 +00:00
|
|
|
spin_unlock_irqrestore(&handler->lock, flags);
|
2016-03-08 19:14:20 +00:00
|
|
|
|
|
|
|
kfree(handler);
|
|
|
|
}
|
|
|
|
|
|
|
|
int hfi1_mmu_rb_insert(struct rb_root *root, struct mmu_rb_node *mnode)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handler = find_mmu_handler(root);
|
2016-03-08 19:14:53 +00:00
|
|
|
struct mmu_rb_node *node;
|
2016-03-08 19:14:25 +00:00
|
|
|
unsigned long flags;
|
2016-03-08 19:14:53 +00:00
|
|
|
int ret = 0;
|
2016-03-08 19:14:20 +00:00
|
|
|
|
|
|
|
if (!handler)
|
|
|
|
return -EINVAL;
|
|
|
|
|
2016-03-08 19:14:25 +00:00
|
|
|
spin_lock_irqsave(&handler->lock, flags);
|
2016-03-08 19:14:59 +00:00
|
|
|
hfi1_cdbg(MMU, "Inserting node addr 0x%llx, len %u", mnode->addr,
|
|
|
|
mnode->len);
|
2016-03-08 19:14:53 +00:00
|
|
|
node = __mmu_rb_search(handler, mnode->addr, mnode->len);
|
|
|
|
if (node) {
|
|
|
|
ret = -EINVAL;
|
|
|
|
goto unlock;
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
2016-03-08 19:14:53 +00:00
|
|
|
__mmu_int_rb_insert(mnode, root);
|
2016-03-08 19:14:20 +00:00
|
|
|
|
2016-07-28 16:27:30 +00:00
|
|
|
ret = handler->ops->insert(root, mnode);
|
|
|
|
if (ret)
|
|
|
|
__mmu_int_rb_remove(mnode, root);
|
2016-03-08 19:14:20 +00:00
|
|
|
unlock:
|
2016-03-08 19:14:25 +00:00
|
|
|
spin_unlock_irqrestore(&handler->lock, flags);
|
2016-03-08 19:14:20 +00:00
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2016-04-12 17:46:03 +00:00
|
|
|
/* Caller must hold handler lock */
|
2016-03-08 19:14:20 +00:00
|
|
|
static struct mmu_rb_node *__mmu_rb_search(struct mmu_rb_handler *handler,
|
|
|
|
unsigned long addr,
|
|
|
|
unsigned long len)
|
|
|
|
{
|
2016-03-08 19:15:10 +00:00
|
|
|
struct mmu_rb_node *node = NULL;
|
2016-03-08 19:14:53 +00:00
|
|
|
|
2016-03-08 19:14:59 +00:00
|
|
|
hfi1_cdbg(MMU, "Searching for addr 0x%llx, len %u", addr, len);
|
2016-03-08 19:15:10 +00:00
|
|
|
if (!handler->ops->filter) {
|
|
|
|
node = __mmu_int_rb_iter_first(handler->root, addr,
|
|
|
|
(addr + len) - 1);
|
|
|
|
} else {
|
|
|
|
for (node = __mmu_int_rb_iter_first(handler->root, addr,
|
|
|
|
(addr + len) - 1);
|
|
|
|
node;
|
|
|
|
node = __mmu_int_rb_iter_next(node, addr,
|
|
|
|
(addr + len) - 1)) {
|
|
|
|
if (handler->ops->filter(node, addr, len))
|
|
|
|
return node;
|
|
|
|
}
|
|
|
|
}
|
2016-03-08 19:14:53 +00:00
|
|
|
return node;
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
|
|
|
|
IB/hfi1: Extract and reinsert MMU RB node on lookup
The page pinning function, which also maintains the pin cache,
behaves one of two ways when an exact buffer match is not found:
1. If no node is not found (a buffer with the same starting address
is not found in the cache), a new node is created, the buffer
pages are pinned, and the node is inserted into the RB tree, or
2. If a node is found but the buffer in that node is a subset of
the new user buffer, the node is extended with the new buffer
pages.
Both modes of operation require (re-)insertion into the interval RB
tree.
When the node being inserted is a new node, the operations are pretty
simple. However, when the node is already existing and is being
extended, special care must be taken.
First, we want to guard against an asynchronous attempt to
delete the node by the MMU invalidation notifier. The simplest way to
do this is to remove the node from the RB tree, preventing the search
algorithm from finding it.
Second, the node needs to be re-inserted so it lands in the proper place
in the tree and the tree is correctly re-balanced. This also requires
the node to be removed from the RB tree.
This commit adds the hfi1_mmu_rb_extract() function, which will search
for a node in the interval RB tree matching an address and length and
remove it from the RB tree if found. This allows for both of the above
special cases be handled in a single step.
Reviewed-by: Dean Luick <dean.luick@intel.com>
Signed-off-by: Mitko Haralanov <mitko.haralanov@intel.com>
Signed-off-by: Dennis Dalessandro <dennis.dalessandro@intel.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
2016-04-12 17:46:47 +00:00
|
|
|
struct mmu_rb_node *hfi1_mmu_rb_extract(struct rb_root *root,
|
|
|
|
unsigned long addr, unsigned long len)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handler = find_mmu_handler(root);
|
|
|
|
struct mmu_rb_node *node;
|
|
|
|
unsigned long flags;
|
|
|
|
|
|
|
|
if (!handler)
|
|
|
|
return ERR_PTR(-EINVAL);
|
|
|
|
|
|
|
|
spin_lock_irqsave(&handler->lock, flags);
|
|
|
|
node = __mmu_rb_search(handler, addr, len);
|
|
|
|
if (node)
|
|
|
|
__mmu_int_rb_remove(node, handler->root);
|
|
|
|
spin_unlock_irqrestore(&handler->lock, flags);
|
|
|
|
|
|
|
|
return node;
|
|
|
|
}
|
|
|
|
|
2016-03-08 19:14:20 +00:00
|
|
|
void hfi1_mmu_rb_remove(struct rb_root *root, struct mmu_rb_node *node)
|
|
|
|
{
|
2016-07-28 16:27:31 +00:00
|
|
|
unsigned long flags;
|
2016-03-08 19:14:20 +00:00
|
|
|
struct mmu_rb_handler *handler = find_mmu_handler(root);
|
|
|
|
|
|
|
|
if (!handler || !node)
|
|
|
|
return;
|
|
|
|
|
2016-07-28 16:27:31 +00:00
|
|
|
/* Validity of handler and node pointers has been checked by caller. */
|
|
|
|
hfi1_cdbg(MMU, "Removing node addr 0x%llx, len %u", node->addr,
|
|
|
|
node->len);
|
|
|
|
spin_lock_irqsave(&handler->lock, flags);
|
|
|
|
__mmu_int_rb_remove(node, handler->root);
|
|
|
|
spin_unlock_irqrestore(&handler->lock, flags);
|
|
|
|
|
|
|
|
handler->ops->remove(handler->root, node, NULL);
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static struct mmu_rb_handler *find_mmu_handler(struct rb_root *root)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handler;
|
|
|
|
|
2016-05-12 17:23:09 +00:00
|
|
|
rcu_read_lock();
|
|
|
|
list_for_each_entry_rcu(handler, &mmu_rb_handlers, list) {
|
2016-03-08 19:14:20 +00:00
|
|
|
if (handler->root == root)
|
|
|
|
goto unlock;
|
|
|
|
}
|
|
|
|
handler = NULL;
|
|
|
|
unlock:
|
2016-05-12 17:23:09 +00:00
|
|
|
rcu_read_unlock();
|
2016-03-08 19:14:20 +00:00
|
|
|
return handler;
|
|
|
|
}
|
|
|
|
|
|
|
|
static inline void mmu_notifier_page(struct mmu_notifier *mn,
|
|
|
|
struct mm_struct *mm, unsigned long addr)
|
|
|
|
{
|
2016-04-12 17:45:57 +00:00
|
|
|
mmu_notifier_mem_invalidate(mn, mm, addr, addr + PAGE_SIZE);
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static inline void mmu_notifier_range_start(struct mmu_notifier *mn,
|
|
|
|
struct mm_struct *mm,
|
|
|
|
unsigned long start,
|
|
|
|
unsigned long end)
|
|
|
|
{
|
2016-04-12 17:45:57 +00:00
|
|
|
mmu_notifier_mem_invalidate(mn, mm, start, end);
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static void mmu_notifier_mem_invalidate(struct mmu_notifier *mn,
|
2016-04-12 17:45:57 +00:00
|
|
|
struct mm_struct *mm,
|
2016-03-08 19:14:20 +00:00
|
|
|
unsigned long start, unsigned long end)
|
|
|
|
{
|
|
|
|
struct mmu_rb_handler *handler =
|
|
|
|
container_of(mn, struct mmu_rb_handler, mn);
|
|
|
|
struct rb_root *root = handler->root;
|
2016-04-12 17:45:57 +00:00
|
|
|
struct mmu_rb_node *node, *ptr = NULL;
|
2016-03-08 19:14:53 +00:00
|
|
|
unsigned long flags;
|
2016-03-08 19:14:20 +00:00
|
|
|
|
2016-03-08 19:14:25 +00:00
|
|
|
spin_lock_irqsave(&handler->lock, flags);
|
2016-04-12 17:45:57 +00:00
|
|
|
for (node = __mmu_int_rb_iter_first(root, start, end - 1);
|
|
|
|
node; node = ptr) {
|
|
|
|
/* Guard against node removal. */
|
|
|
|
ptr = __mmu_int_rb_iter_next(node, start, end - 1);
|
2016-03-08 19:14:59 +00:00
|
|
|
hfi1_cdbg(MMU, "Invalidating node addr 0x%llx, len %u",
|
|
|
|
node->addr, node->len);
|
2016-04-12 17:46:03 +00:00
|
|
|
if (handler->ops->invalidate(root, node)) {
|
IB/hfi1: Fix buffer cache races which may cause corruption
There are two possible causes for node/memory corruption both
of which are related to the cache eviction algorithm. One way
to cause corruption is due to the asynchronous nature of the
MMU invalidation and the locking used when invalidating node.
The MMU invalidation routine would temporarily release the
RB tree lock to avoid a deadlock. However, this would allow
the eviction function to take the lock resulting in the removal
of cache nodes.
If the node being removed by the eviction code is the same as
the node being invalidated, the result is use after free.
The same is true in the other direction due to the temporary
release of the eviction list lock in the eviction loop.
Another corner case exists when dealing with the SDMA buffer
cache that could cause memory corruption of kernel memory.
The most common way, in which this corruption exhibits itself
is a linked list node corruption. In that case, the kernel will
complain that a node with poisoned pointers is being removed.
The fact that the pointers are already poisoned means that the
node has already been removed from the list.
To root cause of this corruption was a mishandling of the
eviction list maintained by the driver. In order for this
to happen four conditions need to be satisfied:
1. A node describing a user buffer already exists in the
interval RB tree,
2. The beginning of the current user buffer matches that
node but is bigger. This will cause the node to be
extended.
3. The amount of cached buffers is close or at the limit
of the buffer cache size.
4. The node has dropped close to the end of the eviction
list. This will cause the node to be considered for
eviction.
If all of the above conditions have been satisfied, it is
possible for the eviction algorithm to evict the current node,
which will free the node without the driver knowing.
To solve both issues described above:
- the locking around the MMU invalidation loop and cache
eviction loop has been improved so locks are not released in
the loop body,
- a new RB function is introduced which will "atomically" find
and remove the matching node from the RB tree, preventing the
MMU invalidation loop from touching it, and
- the node being extended by the pin_vector_pages() function is
removed from the eviction list prior to calling the eviction
function.
Reviewed-by: Dean Luick <dean.luick@intel.com>
Signed-off-by: Mitko Haralanov <mitko.haralanov@intel.com>
Signed-off-by: Doug Ledford <dledford@redhat.com>
2016-04-12 17:46:53 +00:00
|
|
|
__mmu_int_rb_remove(node, root);
|
2016-07-28 16:27:30 +00:00
|
|
|
handler->ops->remove(root, node, mm);
|
2016-04-12 17:46:03 +00:00
|
|
|
}
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|
2016-03-08 19:14:25 +00:00
|
|
|
spin_unlock_irqrestore(&handler->lock, flags);
|
2016-03-08 19:14:20 +00:00
|
|
|
}
|