1 #include <linux/init.h>
4 #include <linux/spinlock.h>
6 #include <linux/interrupt.h>
7 #include <linux/export.h>
10 #include <asm/tlbflush.h>
11 #include <asm/mmu_context.h>
12 #include <asm/cache.h>
14 #include <asm/uv/uv.h>
15 #include <linux/debugfs.h>
18 * Smarter SMP flushing macros.
21 * These mean you can really definitely utterly forget about
22 * writing to user space from interrupts. (Its not allowed anyway).
24 * Optimizations Manfred Spraul <manfred@colorfullife.com>
26 * More scalable flush, from Andi Kleen
28 * Implement flush IPI by CALL_FUNCTION_VECTOR, Alex Shi
33 struct flush_tlb_info
{
34 struct mm_struct
*flush_mm
;
35 unsigned long flush_start
;
36 unsigned long flush_end
;
40 * We cannot call mmdrop() because we are in interrupt context,
41 * instead update mm->cpu_vm_mask.
43 void leave_mm(int cpu
)
45 struct mm_struct
*active_mm
= this_cpu_read(cpu_tlbstate
.active_mm
);
46 if (this_cpu_read(cpu_tlbstate
.state
) == TLBSTATE_OK
)
48 if (cpumask_test_cpu(cpu
, mm_cpumask(active_mm
))) {
49 cpumask_clear_cpu(cpu
, mm_cpumask(active_mm
));
50 load_cr3(swapper_pg_dir
);
52 * This gets called in the idle path where RCU
53 * functions differently. Tracing normally
54 * uses RCU, so we have to call the tracepoint
57 trace_tlb_flush_rcuidle(TLB_FLUSH_ON_TASK_SWITCH
, TLB_FLUSH_ALL
);
60 EXPORT_SYMBOL_GPL(leave_mm
);
62 #endif /* CONFIG_SMP */
64 void switch_mm(struct mm_struct
*prev
, struct mm_struct
*next
,
65 struct task_struct
*tsk
)
69 local_irq_save(flags
);
70 switch_mm_irqs_off(prev
, next
, tsk
);
71 local_irq_restore(flags
);
74 void switch_mm_irqs_off(struct mm_struct
*prev
, struct mm_struct
*next
,
75 struct task_struct
*tsk
)
77 unsigned cpu
= smp_processor_id();
79 if (likely(prev
!= next
)) {
80 if (IS_ENABLED(CONFIG_VMAP_STACK
)) {
82 * If our current stack is in vmalloc space and isn't
83 * mapped in the new pgd, we'll double-fault. Forcibly
86 unsigned int stack_pgd_index
= pgd_index(current_stack_pointer());
88 pgd_t
*pgd
= next
->pgd
+ stack_pgd_index
;
90 if (unlikely(pgd_none(*pgd
)))
91 set_pgd(pgd
, init_mm
.pgd
[stack_pgd_index
]);
95 this_cpu_write(cpu_tlbstate
.state
, TLBSTATE_OK
);
96 this_cpu_write(cpu_tlbstate
.active_mm
, next
);
99 cpumask_set_cpu(cpu
, mm_cpumask(next
));
102 * Re-load page tables.
104 * This logic has an ordering constraint:
106 * CPU 0: Write to a PTE for 'next'
107 * CPU 0: load bit 1 in mm_cpumask. if nonzero, send IPI.
108 * CPU 1: set bit 1 in next's mm_cpumask
109 * CPU 1: load from the PTE that CPU 0 writes (implicit)
111 * We need to prevent an outcome in which CPU 1 observes
112 * the new PTE value and CPU 0 observes bit 1 clear in
113 * mm_cpumask. (If that occurs, then the IPI will never
114 * be sent, and CPU 0's TLB will contain a stale entry.)
116 * The bad outcome can occur if either CPU's load is
117 * reordered before that CPU's store, so both CPUs must
118 * execute full barriers to prevent this from happening.
120 * Thus, switch_mm needs a full barrier between the
121 * store to mm_cpumask and any operation that could load
122 * from next->pgd. TLB fills are special and can happen
123 * due to instruction fetches or for no reason at all,
124 * and neither LOCK nor MFENCE orders them.
125 * Fortunately, load_cr3() is serializing and gives the
126 * ordering guarantee we need.
131 trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH
, TLB_FLUSH_ALL
);
133 /* Stop flush ipis for the previous mm */
134 cpumask_clear_cpu(cpu
, mm_cpumask(prev
));
136 /* Load per-mm CR4 state */
139 #ifdef CONFIG_MODIFY_LDT_SYSCALL
141 * Load the LDT, if the LDT is different.
143 * It's possible that prev->context.ldt doesn't match
144 * the LDT register. This can happen if leave_mm(prev)
145 * was called and then modify_ldt changed
146 * prev->context.ldt but suppressed an IPI to this CPU.
147 * In this case, prev->context.ldt != NULL, because we
148 * never set context.ldt to NULL while the mm still
149 * exists. That means that next->context.ldt !=
150 * prev->context.ldt, because mms never share an LDT.
152 if (unlikely(prev
->context
.ldt
!= next
->context
.ldt
))
158 this_cpu_write(cpu_tlbstate
.state
, TLBSTATE_OK
);
159 BUG_ON(this_cpu_read(cpu_tlbstate
.active_mm
) != next
);
161 if (!cpumask_test_cpu(cpu
, mm_cpumask(next
))) {
163 * On established mms, the mm_cpumask is only changed
164 * from irq context, from ptep_clear_flush() while in
165 * lazy tlb mode, and here. Irqs are blocked during
166 * schedule, protecting us from simultaneous changes.
168 cpumask_set_cpu(cpu
, mm_cpumask(next
));
171 * We were in lazy tlb mode and leave_mm disabled
172 * tlb flush IPI delivery. We must reload CR3
173 * to make sure to use no freed page tables.
175 * As above, load_cr3() is serializing and orders TLB
176 * fills with respect to the mm_cpumask write.
179 trace_tlb_flush(TLB_FLUSH_ON_TASK_SWITCH
, TLB_FLUSH_ALL
);
190 * The flush IPI assumes that a thread switch happens in this order:
191 * [cpu0: the cpu that switches]
192 * 1) switch_mm() either 1a) or 1b)
193 * 1a) thread switch to a different mm
194 * 1a1) set cpu_tlbstate to TLBSTATE_OK
195 * Now the tlb flush NMI handler flush_tlb_func won't call leave_mm
196 * if cpu0 was in lazy tlb mode.
197 * 1a2) update cpu active_mm
198 * Now cpu0 accepts tlb flushes for the new mm.
199 * 1a3) cpu_set(cpu, new_mm->cpu_vm_mask);
200 * Now the other cpus will send tlb flush ipis.
202 * 1a5) cpu_clear(cpu, old_mm->cpu_vm_mask);
203 * Stop ipi delivery for the old mm. This is not synchronized with
204 * the other cpus, but flush_tlb_func ignore flush ipis for the wrong
205 * mm, and in the worst case we perform a superfluous tlb flush.
206 * 1b) thread switch without mm change
207 * cpu active_mm is correct, cpu0 already handles flush ipis.
208 * 1b1) set cpu_tlbstate to TLBSTATE_OK
209 * 1b2) test_and_set the cpu bit in cpu_vm_mask.
210 * Atomically set the bit [other cpus will start sending flush ipis],
212 * 1b3) if the bit was 0: leave_mm was called, flush the tlb.
213 * 2) switch %%esp, ie current
215 * The interrupt must handle 2 special cases:
216 * - cr3 is changed before %%esp, ie. it cannot use current->{active_,}mm.
217 * - the cpu performs speculative tlb reads, i.e. even if the cpu only
218 * runs in kernel space, the cpu could load tlb entries for user space
221 * The good news is that cpu_tlbstate is local to each cpu, no
222 * write/read ordering problems.
226 * TLB flush funcation:
227 * 1) Flush the tlb entries if the cpu uses the mm that's being flushed.
228 * 2) Leave the mm if we are in the lazy tlb mode.
230 static void flush_tlb_func(void *info
)
232 struct flush_tlb_info
*f
= info
;
234 inc_irq_stat(irq_tlb_count
);
236 if (f
->flush_mm
&& f
->flush_mm
!= this_cpu_read(cpu_tlbstate
.active_mm
))
239 count_vm_tlb_event(NR_TLB_REMOTE_FLUSH_RECEIVED
);
240 if (this_cpu_read(cpu_tlbstate
.state
) == TLBSTATE_OK
) {
241 if (f
->flush_end
== TLB_FLUSH_ALL
) {
243 trace_tlb_flush(TLB_REMOTE_SHOOTDOWN
, TLB_FLUSH_ALL
);
246 unsigned long nr_pages
=
247 (f
->flush_end
- f
->flush_start
) / PAGE_SIZE
;
248 addr
= f
->flush_start
;
249 while (addr
< f
->flush_end
) {
250 __flush_tlb_single(addr
);
253 trace_tlb_flush(TLB_REMOTE_SHOOTDOWN
, nr_pages
);
256 leave_mm(smp_processor_id());
260 void native_flush_tlb_others(const struct cpumask
*cpumask
,
261 struct mm_struct
*mm
, unsigned long start
,
264 struct flush_tlb_info info
;
267 end
= start
+ PAGE_SIZE
;
269 info
.flush_start
= start
;
270 info
.flush_end
= end
;
272 count_vm_tlb_event(NR_TLB_REMOTE_FLUSH
);
273 if (end
== TLB_FLUSH_ALL
)
274 trace_tlb_flush(TLB_REMOTE_SEND_IPI
, TLB_FLUSH_ALL
);
276 trace_tlb_flush(TLB_REMOTE_SEND_IPI
,
277 (end
- start
) >> PAGE_SHIFT
);
279 if (is_uv_system()) {
282 cpu
= smp_processor_id();
283 cpumask
= uv_flush_tlb_others(cpumask
, mm
, start
, end
, cpu
);
285 smp_call_function_many(cpumask
, flush_tlb_func
,
289 smp_call_function_many(cpumask
, flush_tlb_func
, &info
, 1);
292 void flush_tlb_current_task(void)
294 struct mm_struct
*mm
= current
->mm
;
298 count_vm_tlb_event(NR_TLB_LOCAL_FLUSH_ALL
);
300 /* This is an implicit full barrier that synchronizes with switch_mm. */
303 trace_tlb_flush(TLB_LOCAL_SHOOTDOWN
, TLB_FLUSH_ALL
);
304 if (cpumask_any_but(mm_cpumask(mm
), smp_processor_id()) < nr_cpu_ids
)
305 flush_tlb_others(mm_cpumask(mm
), mm
, 0UL, TLB_FLUSH_ALL
);
310 * See Documentation/x86/tlb.txt for details. We choose 33
311 * because it is large enough to cover the vast majority (at
312 * least 95%) of allocations, and is small enough that we are
313 * confident it will not cause too much overhead. Each single
314 * flush is about 100 ns, so this caps the maximum overhead at
317 * This is in units of pages.
319 static unsigned long tlb_single_page_flush_ceiling __read_mostly
= 33;
321 void flush_tlb_mm_range(struct mm_struct
*mm
, unsigned long start
,
322 unsigned long end
, unsigned long vmflag
)
325 /* do a global flush by default */
326 unsigned long base_pages_to_flush
= TLB_FLUSH_ALL
;
329 if (current
->active_mm
!= mm
) {
330 /* Synchronize with switch_mm. */
337 leave_mm(smp_processor_id());
339 /* Synchronize with switch_mm. */
345 if ((end
!= TLB_FLUSH_ALL
) && !(vmflag
& VM_HUGETLB
))
346 base_pages_to_flush
= (end
- start
) >> PAGE_SHIFT
;
349 * Both branches below are implicit full barriers (MOV to CR or
350 * INVLPG) that synchronize with switch_mm.
352 if (base_pages_to_flush
> tlb_single_page_flush_ceiling
) {
353 base_pages_to_flush
= TLB_FLUSH_ALL
;
354 count_vm_tlb_event(NR_TLB_LOCAL_FLUSH_ALL
);
357 /* flush range by one by one 'invlpg' */
358 for (addr
= start
; addr
< end
; addr
+= PAGE_SIZE
) {
359 count_vm_tlb_event(NR_TLB_LOCAL_FLUSH_ONE
);
360 __flush_tlb_single(addr
);
363 trace_tlb_flush(TLB_LOCAL_MM_SHOOTDOWN
, base_pages_to_flush
);
365 if (base_pages_to_flush
== TLB_FLUSH_ALL
) {
369 if (cpumask_any_but(mm_cpumask(mm
), smp_processor_id()) < nr_cpu_ids
)
370 flush_tlb_others(mm_cpumask(mm
), mm
, start
, end
);
374 void flush_tlb_page(struct vm_area_struct
*vma
, unsigned long start
)
376 struct mm_struct
*mm
= vma
->vm_mm
;
380 if (current
->active_mm
== mm
) {
383 * Implicit full barrier (INVLPG) that synchronizes
386 __flush_tlb_one(start
);
388 leave_mm(smp_processor_id());
390 /* Synchronize with switch_mm. */
395 if (cpumask_any_but(mm_cpumask(mm
), smp_processor_id()) < nr_cpu_ids
)
396 flush_tlb_others(mm_cpumask(mm
), mm
, start
, 0UL);
401 static void do_flush_tlb_all(void *info
)
403 count_vm_tlb_event(NR_TLB_REMOTE_FLUSH_RECEIVED
);
405 if (this_cpu_read(cpu_tlbstate
.state
) == TLBSTATE_LAZY
)
406 leave_mm(smp_processor_id());
409 void flush_tlb_all(void)
411 count_vm_tlb_event(NR_TLB_REMOTE_FLUSH
);
412 on_each_cpu(do_flush_tlb_all
, NULL
, 1);
415 static void do_kernel_range_flush(void *info
)
417 struct flush_tlb_info
*f
= info
;
420 /* flush range by one by one 'invlpg' */
421 for (addr
= f
->flush_start
; addr
< f
->flush_end
; addr
+= PAGE_SIZE
)
422 __flush_tlb_single(addr
);
425 void flush_tlb_kernel_range(unsigned long start
, unsigned long end
)
428 /* Balance as user space task's flush, a bit conservative */
429 if (end
== TLB_FLUSH_ALL
||
430 (end
- start
) > tlb_single_page_flush_ceiling
* PAGE_SIZE
) {
431 on_each_cpu(do_flush_tlb_all
, NULL
, 1);
433 struct flush_tlb_info info
;
434 info
.flush_start
= start
;
435 info
.flush_end
= end
;
436 on_each_cpu(do_kernel_range_flush
, &info
, 1);
440 static ssize_t
tlbflush_read_file(struct file
*file
, char __user
*user_buf
,
441 size_t count
, loff_t
*ppos
)
446 len
= sprintf(buf
, "%ld\n", tlb_single_page_flush_ceiling
);
447 return simple_read_from_buffer(user_buf
, count
, ppos
, buf
, len
);
450 static ssize_t
tlbflush_write_file(struct file
*file
,
451 const char __user
*user_buf
, size_t count
, loff_t
*ppos
)
457 len
= min(count
, sizeof(buf
) - 1);
458 if (copy_from_user(buf
, user_buf
, len
))
462 if (kstrtoint(buf
, 0, &ceiling
))
468 tlb_single_page_flush_ceiling
= ceiling
;
472 static const struct file_operations fops_tlbflush
= {
473 .read
= tlbflush_read_file
,
474 .write
= tlbflush_write_file
,
475 .llseek
= default_llseek
,
478 static int __init
create_tlb_single_page_flush_ceiling(void)
480 debugfs_create_file("tlb_single_page_flush_ceiling", S_IRUSR
| S_IWUSR
,
481 arch_debugfs_dir
, NULL
, &fops_tlbflush
);
484 late_initcall(create_tlb_single_page_flush_ceiling
);
486 #endif /* CONFIG_SMP */