1 /* SPDX-License-Identifier: GPL-2.0 */
3 * include/linux/userfaultfd_k.h
5 * Copyright (C) 2015 Red Hat, Inc.
9 #ifndef _LINUX_USERFAULTFD_K_H
10 #define _LINUX_USERFAULTFD_K_H
12 #ifdef CONFIG_USERFAULTFD
14 #include <linux/userfaultfd.h> /* linux/include/uapi/linux/userfaultfd.h */
16 #include <linux/fcntl.h>
18 #include <linux/swap.h>
19 #include <linux/swapops.h>
20 #include <asm-generic/pgtable_uffd.h>
21 #include <linux/hugetlb_inline.h>
23 /* The set of all possible UFFD-related VM flags. */
24 #define __VM_UFFD_FLAGS (VM_UFFD_MISSING | VM_UFFD_WP | VM_UFFD_MINOR)
27 * CAREFUL: Check include/uapi/asm-generic/fcntl.h when defining
28 * new flags, since they might collide with O_* ones. We want
29 * to re-use O_* flags that couldn't possibly have a meaning
30 * from userfaultfd, in order to leave a free define-space for
33 #define UFFD_CLOEXEC O_CLOEXEC
34 #define UFFD_NONBLOCK O_NONBLOCK
36 #define UFFD_SHARED_FCNTL_FLAGS (O_CLOEXEC | O_NONBLOCK)
37 #define UFFD_FLAGS_SET (EFD_SHARED_FCNTL_FLAGS)
40 * Start with fault_pending_wqh and fault_wqh so they're more likely
41 * to be in the same cacheline.
45 * fault_pending_wqh.lock
49 * To avoid deadlocks, IRQs must be disabled when taking any of the above locks,
50 * since fd_wqh.lock is taken by aio_poll() while it's holding a lock that's
51 * also taken in IRQ context.
53 struct userfaultfd_ctx
{
54 /* waitqueue head for the pending (i.e. not read) userfaults */
55 wait_queue_head_t fault_pending_wqh
;
56 /* waitqueue head for the userfaults */
57 wait_queue_head_t fault_wqh
;
58 /* waitqueue head for the pseudo fd to wakeup poll/read */
59 wait_queue_head_t fd_wqh
;
60 /* waitqueue head for events */
61 wait_queue_head_t event_wqh
;
62 /* a refile sequence protected by fault_pending_wqh lock */
63 seqcount_spinlock_t refile_seq
;
64 /* pseudo fd refcounting */
66 /* userfaultfd syscall flags */
68 /* features requested from the userspace */
69 unsigned int features
;
73 * Prevents userfaultfd operations (fill/move/wp) from happening while
74 * some non-cooperative event(s) is taking place. Increments are done
75 * in write-mode. Whereas, userfaultfd operations, which includes
76 * reading mmap_changing, is done under read-mode.
78 struct rw_semaphore map_changing_lock
;
79 /* memory mappings are changing because of non-cooperative event */
80 atomic_t mmap_changing
;
81 /* mm with one ore more vmas attached to this userfaultfd_ctx */
85 extern vm_fault_t
handle_userfault(struct vm_fault
*vmf
, unsigned long reason
);
87 /* A combined operation mode + behavior flags. */
88 typedef unsigned int __bitwise uffd_flags_t
;
90 /* Mutually exclusive modes of operation. */
91 enum mfill_atomic_mode
{
93 MFILL_ATOMIC_ZEROPAGE
,
94 MFILL_ATOMIC_CONTINUE
,
96 NR_MFILL_ATOMIC_MODES
,
99 #define MFILL_ATOMIC_MODE_BITS (const_ilog2(NR_MFILL_ATOMIC_MODES - 1) + 1)
100 #define MFILL_ATOMIC_BIT(nr) BIT(MFILL_ATOMIC_MODE_BITS + (nr))
101 #define MFILL_ATOMIC_FLAG(nr) ((__force uffd_flags_t) MFILL_ATOMIC_BIT(nr))
102 #define MFILL_ATOMIC_MODE_MASK ((__force uffd_flags_t) (MFILL_ATOMIC_BIT(0) - 1))
104 static inline bool uffd_flags_mode_is(uffd_flags_t flags
, enum mfill_atomic_mode expected
)
106 return (flags
& MFILL_ATOMIC_MODE_MASK
) == ((__force uffd_flags_t
) expected
);
109 static inline uffd_flags_t
uffd_flags_set_mode(uffd_flags_t flags
, enum mfill_atomic_mode mode
)
111 flags
&= ~MFILL_ATOMIC_MODE_MASK
;
112 return flags
| ((__force uffd_flags_t
) mode
);
115 /* Flags controlling behavior. These behavior changes are mode-independent. */
116 #define MFILL_ATOMIC_WP MFILL_ATOMIC_FLAG(0)
118 extern int mfill_atomic_install_pte(pmd_t
*dst_pmd
,
119 struct vm_area_struct
*dst_vma
,
120 unsigned long dst_addr
, struct page
*page
,
121 bool newly_allocated
, uffd_flags_t flags
);
123 extern ssize_t
mfill_atomic_copy(struct userfaultfd_ctx
*ctx
, unsigned long dst_start
,
124 unsigned long src_start
, unsigned long len
,
126 extern ssize_t
mfill_atomic_zeropage(struct userfaultfd_ctx
*ctx
,
127 unsigned long dst_start
,
129 extern ssize_t
mfill_atomic_continue(struct userfaultfd_ctx
*ctx
, unsigned long dst_start
,
130 unsigned long len
, uffd_flags_t flags
);
131 extern ssize_t
mfill_atomic_poison(struct userfaultfd_ctx
*ctx
, unsigned long start
,
132 unsigned long len
, uffd_flags_t flags
);
133 extern int mwriteprotect_range(struct userfaultfd_ctx
*ctx
, unsigned long start
,
134 unsigned long len
, bool enable_wp
);
135 extern long uffd_wp_range(struct vm_area_struct
*vma
,
136 unsigned long start
, unsigned long len
, bool enable_wp
);
139 void double_pt_lock(spinlock_t
*ptl1
, spinlock_t
*ptl2
);
140 void double_pt_unlock(spinlock_t
*ptl1
, spinlock_t
*ptl2
);
141 ssize_t
move_pages(struct userfaultfd_ctx
*ctx
, unsigned long dst_start
,
142 unsigned long src_start
, unsigned long len
, __u64 flags
);
143 int move_pages_huge_pmd(struct mm_struct
*mm
, pmd_t
*dst_pmd
, pmd_t
*src_pmd
, pmd_t dst_pmdval
,
144 struct vm_area_struct
*dst_vma
,
145 struct vm_area_struct
*src_vma
,
146 unsigned long dst_addr
, unsigned long src_addr
);
149 static inline bool is_mergeable_vm_userfaultfd_ctx(struct vm_area_struct
*vma
,
150 struct vm_userfaultfd_ctx vm_ctx
)
152 return vma
->vm_userfaultfd_ctx
.ctx
== vm_ctx
.ctx
;
156 * Never enable huge pmd sharing on some uffd registered vmas:
158 * - VM_UFFD_WP VMAs, because write protect information is per pgtable entry.
160 * - VM_UFFD_MINOR VMAs, because otherwise we would never get minor faults for
161 * VMAs which share huge pmds. (If you have two mappings to the same
162 * underlying pages, and fault in the non-UFFD-registered one with a write,
163 * with huge pmd sharing this would *also* setup the second UFFD-registered
164 * mapping, and we'd not get minor faults.)
166 static inline bool uffd_disable_huge_pmd_share(struct vm_area_struct
*vma
)
168 return vma
->vm_flags
& (VM_UFFD_WP
| VM_UFFD_MINOR
);
172 * Don't do fault around for either WP or MINOR registered uffd range. For
173 * MINOR registered range, fault around will be a total disaster and ptes can
174 * be installed without notifications; for WP it should mostly be fine as long
175 * as the fault around checks for pte_none() before the installation, however
176 * to be super safe we just forbid it.
178 static inline bool uffd_disable_fault_around(struct vm_area_struct
*vma
)
180 return vma
->vm_flags
& (VM_UFFD_WP
| VM_UFFD_MINOR
);
183 static inline bool userfaultfd_missing(struct vm_area_struct
*vma
)
185 return vma
->vm_flags
& VM_UFFD_MISSING
;
188 static inline bool userfaultfd_wp(struct vm_area_struct
*vma
)
190 return vma
->vm_flags
& VM_UFFD_WP
;
193 static inline bool userfaultfd_minor(struct vm_area_struct
*vma
)
195 return vma
->vm_flags
& VM_UFFD_MINOR
;
198 static inline bool userfaultfd_pte_wp(struct vm_area_struct
*vma
,
201 return userfaultfd_wp(vma
) && pte_uffd_wp(pte
);
204 static inline bool userfaultfd_huge_pmd_wp(struct vm_area_struct
*vma
,
207 return userfaultfd_wp(vma
) && pmd_uffd_wp(pmd
);
210 static inline bool userfaultfd_armed(struct vm_area_struct
*vma
)
212 return vma
->vm_flags
& __VM_UFFD_FLAGS
;
215 static inline bool vma_can_userfault(struct vm_area_struct
*vma
,
216 unsigned long vm_flags
,
219 vm_flags
&= __VM_UFFD_FLAGS
;
221 if (vm_flags
& VM_DROPPABLE
)
224 if ((vm_flags
& VM_UFFD_MINOR
) &&
225 (!is_vm_hugetlb_page(vma
) && !vma_is_shmem(vma
)))
229 * If wp async enabled, and WP is the only mode enabled, allow any
232 if (wp_async
&& (vm_flags
== VM_UFFD_WP
))
235 #ifndef CONFIG_PTE_MARKER_UFFD_WP
237 * If user requested uffd-wp but not enabled pte markers for
238 * uffd-wp, then shmem & hugetlbfs are not supported but only
241 if ((vm_flags
& VM_UFFD_WP
) && !vma_is_anonymous(vma
))
245 /* By default, allow any of anon|shmem|hugetlb */
246 return vma_is_anonymous(vma
) || is_vm_hugetlb_page(vma
) ||
250 extern int dup_userfaultfd(struct vm_area_struct
*, struct list_head
*);
251 extern void dup_userfaultfd_complete(struct list_head
*);
252 void dup_userfaultfd_fail(struct list_head
*);
254 extern void mremap_userfaultfd_prep(struct vm_area_struct
*,
255 struct vm_userfaultfd_ctx
*);
256 extern void mremap_userfaultfd_complete(struct vm_userfaultfd_ctx
*,
257 unsigned long from
, unsigned long to
,
260 extern bool userfaultfd_remove(struct vm_area_struct
*vma
,
264 extern int userfaultfd_unmap_prep(struct vm_area_struct
*vma
,
265 unsigned long start
, unsigned long end
, struct list_head
*uf
);
266 extern void userfaultfd_unmap_complete(struct mm_struct
*mm
,
267 struct list_head
*uf
);
268 extern bool userfaultfd_wp_unpopulated(struct vm_area_struct
*vma
);
269 extern bool userfaultfd_wp_async(struct vm_area_struct
*vma
);
271 void userfaultfd_reset_ctx(struct vm_area_struct
*vma
);
273 struct vm_area_struct
*userfaultfd_clear_vma(struct vma_iterator
*vmi
,
274 struct vm_area_struct
*prev
,
275 struct vm_area_struct
*vma
,
279 int userfaultfd_register_range(struct userfaultfd_ctx
*ctx
,
280 struct vm_area_struct
*vma
,
281 unsigned long vm_flags
,
282 unsigned long start
, unsigned long end
,
285 void userfaultfd_release_new(struct userfaultfd_ctx
*ctx
);
287 void userfaultfd_release_all(struct mm_struct
*mm
,
288 struct userfaultfd_ctx
*ctx
);
290 #else /* CONFIG_USERFAULTFD */
293 static inline vm_fault_t
handle_userfault(struct vm_fault
*vmf
,
294 unsigned long reason
)
296 return VM_FAULT_SIGBUS
;
299 static inline long uffd_wp_range(struct vm_area_struct
*vma
,
300 unsigned long start
, unsigned long len
,
306 static inline bool is_mergeable_vm_userfaultfd_ctx(struct vm_area_struct
*vma
,
307 struct vm_userfaultfd_ctx vm_ctx
)
312 static inline bool userfaultfd_missing(struct vm_area_struct
*vma
)
317 static inline bool userfaultfd_wp(struct vm_area_struct
*vma
)
322 static inline bool userfaultfd_minor(struct vm_area_struct
*vma
)
327 static inline bool userfaultfd_pte_wp(struct vm_area_struct
*vma
,
333 static inline bool userfaultfd_huge_pmd_wp(struct vm_area_struct
*vma
,
340 static inline bool userfaultfd_armed(struct vm_area_struct
*vma
)
345 static inline int dup_userfaultfd(struct vm_area_struct
*vma
,
351 static inline void dup_userfaultfd_complete(struct list_head
*l
)
355 static inline void dup_userfaultfd_fail(struct list_head
*l
)
359 static inline void mremap_userfaultfd_prep(struct vm_area_struct
*vma
,
360 struct vm_userfaultfd_ctx
*ctx
)
364 static inline void mremap_userfaultfd_complete(struct vm_userfaultfd_ctx
*ctx
,
371 static inline bool userfaultfd_remove(struct vm_area_struct
*vma
,
378 static inline int userfaultfd_unmap_prep(struct vm_area_struct
*vma
,
379 unsigned long start
, unsigned long end
,
380 struct list_head
*uf
)
385 static inline void userfaultfd_unmap_complete(struct mm_struct
*mm
,
386 struct list_head
*uf
)
390 static inline bool uffd_disable_fault_around(struct vm_area_struct
*vma
)
395 static inline bool userfaultfd_wp_unpopulated(struct vm_area_struct
*vma
)
400 static inline bool userfaultfd_wp_async(struct vm_area_struct
*vma
)
405 #endif /* CONFIG_USERFAULTFD */
407 static inline bool userfaultfd_wp_use_markers(struct vm_area_struct
*vma
)
409 /* Only wr-protect mode uses pte markers */
410 if (!userfaultfd_wp(vma
))
413 /* File-based uffd-wp always need markers */
414 if (!vma_is_anonymous(vma
))
418 * Anonymous uffd-wp only needs the markers if WP_UNPOPULATED
419 * enabled (to apply markers on zero pages).
421 return userfaultfd_wp_unpopulated(vma
);
424 static inline bool pte_marker_entry_uffd_wp(swp_entry_t entry
)
426 #ifdef CONFIG_PTE_MARKER_UFFD_WP
427 return is_pte_marker_entry(entry
) &&
428 (pte_marker_get(entry
) & PTE_MARKER_UFFD_WP
);
434 static inline bool pte_marker_uffd_wp(pte_t pte
)
436 #ifdef CONFIG_PTE_MARKER_UFFD_WP
439 if (!is_swap_pte(pte
))
442 entry
= pte_to_swp_entry(pte
);
444 return pte_marker_entry_uffd_wp(entry
);
451 * Returns true if this is a swap pte and was uffd-wp wr-protected in either
452 * forms (pte marker or a normal swap pte), false otherwise.
454 static inline bool pte_swp_uffd_wp_any(pte_t pte
)
456 #ifdef CONFIG_PTE_MARKER_UFFD_WP
457 if (!is_swap_pte(pte
))
460 if (pte_swp_uffd_wp(pte
))
463 if (pte_marker_uffd_wp(pte
))
469 #endif /* _LINUX_USERFAULTFD_K_H */