vfio/pci: Fix integer overflows, bitmask check
[linux/fpc-iii.git] / drivers / vfio / pci / vfio_pci_intrs.c
blob5c8f767b636831da54d368b90bcc9f375b6f7347
1 /*
2 * VFIO PCI interrupt handling
4 * Copyright (C) 2012 Red Hat, Inc. All rights reserved.
5 * Author: Alex Williamson <alex.williamson@redhat.com>
7 * This program is free software; you can redistribute it and/or modify
8 * it under the terms of the GNU General Public License version 2 as
9 * published by the Free Software Foundation.
11 * Derived from original vfio:
12 * Copyright 2010 Cisco Systems, Inc. All rights reserved.
13 * Author: Tom Lyon, pugs@cisco.com
16 #include <linux/device.h>
17 #include <linux/interrupt.h>
18 #include <linux/eventfd.h>
19 #include <linux/msi.h>
20 #include <linux/pci.h>
21 #include <linux/file.h>
22 #include <linux/vfio.h>
23 #include <linux/wait.h>
24 #include <linux/slab.h>
26 #include "vfio_pci_private.h"
29 * INTx
31 static void vfio_send_intx_eventfd(void *opaque, void *unused)
33 struct vfio_pci_device *vdev = opaque;
35 if (likely(is_intx(vdev) && !vdev->virq_disabled))
36 eventfd_signal(vdev->ctx[0].trigger, 1);
39 void vfio_pci_intx_mask(struct vfio_pci_device *vdev)
41 struct pci_dev *pdev = vdev->pdev;
42 unsigned long flags;
44 spin_lock_irqsave(&vdev->irqlock, flags);
47 * Masking can come from interrupt, ioctl, or config space
48 * via INTx disable. The latter means this can get called
49 * even when not using intx delivery. In this case, just
50 * try to have the physical bit follow the virtual bit.
52 if (unlikely(!is_intx(vdev))) {
53 if (vdev->pci_2_3)
54 pci_intx(pdev, 0);
55 } else if (!vdev->ctx[0].masked) {
57 * Can't use check_and_mask here because we always want to
58 * mask, not just when something is pending.
60 if (vdev->pci_2_3)
61 pci_intx(pdev, 0);
62 else
63 disable_irq_nosync(pdev->irq);
65 vdev->ctx[0].masked = true;
68 spin_unlock_irqrestore(&vdev->irqlock, flags);
72 * If this is triggered by an eventfd, we can't call eventfd_signal
73 * or else we'll deadlock on the eventfd wait queue. Return >0 when
74 * a signal is necessary, which can then be handled via a work queue
75 * or directly depending on the caller.
77 static int vfio_pci_intx_unmask_handler(void *opaque, void *unused)
79 struct vfio_pci_device *vdev = opaque;
80 struct pci_dev *pdev = vdev->pdev;
81 unsigned long flags;
82 int ret = 0;
84 spin_lock_irqsave(&vdev->irqlock, flags);
87 * Unmasking comes from ioctl or config, so again, have the
88 * physical bit follow the virtual even when not using INTx.
90 if (unlikely(!is_intx(vdev))) {
91 if (vdev->pci_2_3)
92 pci_intx(pdev, 1);
93 } else if (vdev->ctx[0].masked && !vdev->virq_disabled) {
95 * A pending interrupt here would immediately trigger,
96 * but we can avoid that overhead by just re-sending
97 * the interrupt to the user.
99 if (vdev->pci_2_3) {
100 if (!pci_check_and_unmask_intx(pdev))
101 ret = 1;
102 } else
103 enable_irq(pdev->irq);
105 vdev->ctx[0].masked = (ret > 0);
108 spin_unlock_irqrestore(&vdev->irqlock, flags);
110 return ret;
113 void vfio_pci_intx_unmask(struct vfio_pci_device *vdev)
115 if (vfio_pci_intx_unmask_handler(vdev, NULL) > 0)
116 vfio_send_intx_eventfd(vdev, NULL);
119 static irqreturn_t vfio_intx_handler(int irq, void *dev_id)
121 struct vfio_pci_device *vdev = dev_id;
122 unsigned long flags;
123 int ret = IRQ_NONE;
125 spin_lock_irqsave(&vdev->irqlock, flags);
127 if (!vdev->pci_2_3) {
128 disable_irq_nosync(vdev->pdev->irq);
129 vdev->ctx[0].masked = true;
130 ret = IRQ_HANDLED;
131 } else if (!vdev->ctx[0].masked && /* may be shared */
132 pci_check_and_mask_intx(vdev->pdev)) {
133 vdev->ctx[0].masked = true;
134 ret = IRQ_HANDLED;
137 spin_unlock_irqrestore(&vdev->irqlock, flags);
139 if (ret == IRQ_HANDLED)
140 vfio_send_intx_eventfd(vdev, NULL);
142 return ret;
145 static int vfio_intx_enable(struct vfio_pci_device *vdev)
147 if (!is_irq_none(vdev))
148 return -EINVAL;
150 if (!vdev->pdev->irq)
151 return -ENODEV;
153 vdev->ctx = kzalloc(sizeof(struct vfio_pci_irq_ctx), GFP_KERNEL);
154 if (!vdev->ctx)
155 return -ENOMEM;
157 vdev->num_ctx = 1;
160 * If the virtual interrupt is masked, restore it. Devices
161 * supporting DisINTx can be masked at the hardware level
162 * here, non-PCI-2.3 devices will have to wait until the
163 * interrupt is enabled.
165 vdev->ctx[0].masked = vdev->virq_disabled;
166 if (vdev->pci_2_3)
167 pci_intx(vdev->pdev, !vdev->ctx[0].masked);
169 vdev->irq_type = VFIO_PCI_INTX_IRQ_INDEX;
171 return 0;
174 static int vfio_intx_set_signal(struct vfio_pci_device *vdev, int fd)
176 struct pci_dev *pdev = vdev->pdev;
177 unsigned long irqflags = IRQF_SHARED;
178 struct eventfd_ctx *trigger;
179 unsigned long flags;
180 int ret;
182 if (vdev->ctx[0].trigger) {
183 free_irq(pdev->irq, vdev);
184 kfree(vdev->ctx[0].name);
185 eventfd_ctx_put(vdev->ctx[0].trigger);
186 vdev->ctx[0].trigger = NULL;
189 if (fd < 0) /* Disable only */
190 return 0;
192 vdev->ctx[0].name = kasprintf(GFP_KERNEL, "vfio-intx(%s)",
193 pci_name(pdev));
194 if (!vdev->ctx[0].name)
195 return -ENOMEM;
197 trigger = eventfd_ctx_fdget(fd);
198 if (IS_ERR(trigger)) {
199 kfree(vdev->ctx[0].name);
200 return PTR_ERR(trigger);
203 vdev->ctx[0].trigger = trigger;
205 if (!vdev->pci_2_3)
206 irqflags = 0;
208 ret = request_irq(pdev->irq, vfio_intx_handler,
209 irqflags, vdev->ctx[0].name, vdev);
210 if (ret) {
211 vdev->ctx[0].trigger = NULL;
212 kfree(vdev->ctx[0].name);
213 eventfd_ctx_put(trigger);
214 return ret;
218 * INTx disable will stick across the new irq setup,
219 * disable_irq won't.
221 spin_lock_irqsave(&vdev->irqlock, flags);
222 if (!vdev->pci_2_3 && vdev->ctx[0].masked)
223 disable_irq_nosync(pdev->irq);
224 spin_unlock_irqrestore(&vdev->irqlock, flags);
226 return 0;
229 static void vfio_intx_disable(struct vfio_pci_device *vdev)
231 vfio_intx_set_signal(vdev, -1);
232 vfio_virqfd_disable(&vdev->ctx[0].unmask);
233 vfio_virqfd_disable(&vdev->ctx[0].mask);
234 vdev->irq_type = VFIO_PCI_NUM_IRQS;
235 vdev->num_ctx = 0;
236 kfree(vdev->ctx);
240 * MSI/MSI-X
242 static irqreturn_t vfio_msihandler(int irq, void *arg)
244 struct eventfd_ctx *trigger = arg;
246 eventfd_signal(trigger, 1);
247 return IRQ_HANDLED;
250 static int vfio_msi_enable(struct vfio_pci_device *vdev, int nvec, bool msix)
252 struct pci_dev *pdev = vdev->pdev;
253 int ret;
255 if (!is_irq_none(vdev))
256 return -EINVAL;
258 vdev->ctx = kcalloc(nvec, sizeof(struct vfio_pci_irq_ctx), GFP_KERNEL);
259 if (!vdev->ctx)
260 return -ENOMEM;
262 if (msix) {
263 int i;
265 vdev->msix = kzalloc(nvec * sizeof(struct msix_entry),
266 GFP_KERNEL);
267 if (!vdev->msix) {
268 kfree(vdev->ctx);
269 return -ENOMEM;
272 for (i = 0; i < nvec; i++)
273 vdev->msix[i].entry = i;
275 ret = pci_enable_msix_range(pdev, vdev->msix, 1, nvec);
276 if (ret < nvec) {
277 if (ret > 0)
278 pci_disable_msix(pdev);
279 kfree(vdev->msix);
280 kfree(vdev->ctx);
281 return ret;
283 } else {
284 ret = pci_enable_msi_range(pdev, 1, nvec);
285 if (ret < nvec) {
286 if (ret > 0)
287 pci_disable_msi(pdev);
288 kfree(vdev->ctx);
289 return ret;
293 vdev->num_ctx = nvec;
294 vdev->irq_type = msix ? VFIO_PCI_MSIX_IRQ_INDEX :
295 VFIO_PCI_MSI_IRQ_INDEX;
297 if (!msix) {
299 * Compute the virtual hardware field for max msi vectors -
300 * it is the log base 2 of the number of vectors.
302 vdev->msi_qmax = fls(nvec * 2 - 1) - 1;
305 return 0;
308 static int vfio_msi_set_vector_signal(struct vfio_pci_device *vdev,
309 int vector, int fd, bool msix)
311 struct pci_dev *pdev = vdev->pdev;
312 int irq = msix ? vdev->msix[vector].vector : pdev->irq + vector;
313 char *name = msix ? "vfio-msix" : "vfio-msi";
314 struct eventfd_ctx *trigger;
315 int ret;
317 if (vector >= vdev->num_ctx)
318 return -EINVAL;
320 if (vdev->ctx[vector].trigger) {
321 free_irq(irq, vdev->ctx[vector].trigger);
322 irq_bypass_unregister_producer(&vdev->ctx[vector].producer);
323 kfree(vdev->ctx[vector].name);
324 eventfd_ctx_put(vdev->ctx[vector].trigger);
325 vdev->ctx[vector].trigger = NULL;
328 if (fd < 0)
329 return 0;
331 vdev->ctx[vector].name = kasprintf(GFP_KERNEL, "%s[%d](%s)",
332 name, vector, pci_name(pdev));
333 if (!vdev->ctx[vector].name)
334 return -ENOMEM;
336 trigger = eventfd_ctx_fdget(fd);
337 if (IS_ERR(trigger)) {
338 kfree(vdev->ctx[vector].name);
339 return PTR_ERR(trigger);
343 * The MSIx vector table resides in device memory which may be cleared
344 * via backdoor resets. We don't allow direct access to the vector
345 * table so even if a userspace driver attempts to save/restore around
346 * such a reset it would be unsuccessful. To avoid this, restore the
347 * cached value of the message prior to enabling.
349 if (msix) {
350 struct msi_msg msg;
352 get_cached_msi_msg(irq, &msg);
353 pci_write_msi_msg(irq, &msg);
356 ret = request_irq(irq, vfio_msihandler, 0,
357 vdev->ctx[vector].name, trigger);
358 if (ret) {
359 kfree(vdev->ctx[vector].name);
360 eventfd_ctx_put(trigger);
361 return ret;
364 vdev->ctx[vector].producer.token = trigger;
365 vdev->ctx[vector].producer.irq = irq;
366 ret = irq_bypass_register_producer(&vdev->ctx[vector].producer);
367 if (unlikely(ret))
368 dev_info(&pdev->dev,
369 "irq bypass producer (token %p) registration fails: %d\n",
370 vdev->ctx[vector].producer.token, ret);
372 vdev->ctx[vector].trigger = trigger;
374 return 0;
377 static int vfio_msi_set_block(struct vfio_pci_device *vdev, unsigned start,
378 unsigned count, int32_t *fds, bool msix)
380 int i, j, ret = 0;
382 if (start + count > vdev->num_ctx)
383 return -EINVAL;
385 for (i = 0, j = start; i < count && !ret; i++, j++) {
386 int fd = fds ? fds[i] : -1;
387 ret = vfio_msi_set_vector_signal(vdev, j, fd, msix);
390 if (ret) {
391 for (--j; j >= start; j--)
392 vfio_msi_set_vector_signal(vdev, j, -1, msix);
395 return ret;
398 static void vfio_msi_disable(struct vfio_pci_device *vdev, bool msix)
400 struct pci_dev *pdev = vdev->pdev;
401 int i;
403 vfio_msi_set_block(vdev, 0, vdev->num_ctx, NULL, msix);
405 for (i = 0; i < vdev->num_ctx; i++) {
406 vfio_virqfd_disable(&vdev->ctx[i].unmask);
407 vfio_virqfd_disable(&vdev->ctx[i].mask);
410 if (msix) {
411 pci_disable_msix(vdev->pdev);
412 kfree(vdev->msix);
413 } else
414 pci_disable_msi(pdev);
416 vdev->irq_type = VFIO_PCI_NUM_IRQS;
417 vdev->num_ctx = 0;
418 kfree(vdev->ctx);
422 * IOCTL support
424 static int vfio_pci_set_intx_unmask(struct vfio_pci_device *vdev,
425 unsigned index, unsigned start,
426 unsigned count, uint32_t flags, void *data)
428 if (!is_intx(vdev) || start != 0 || count != 1)
429 return -EINVAL;
431 if (flags & VFIO_IRQ_SET_DATA_NONE) {
432 vfio_pci_intx_unmask(vdev);
433 } else if (flags & VFIO_IRQ_SET_DATA_BOOL) {
434 uint8_t unmask = *(uint8_t *)data;
435 if (unmask)
436 vfio_pci_intx_unmask(vdev);
437 } else if (flags & VFIO_IRQ_SET_DATA_EVENTFD) {
438 int32_t fd = *(int32_t *)data;
439 if (fd >= 0)
440 return vfio_virqfd_enable((void *) vdev,
441 vfio_pci_intx_unmask_handler,
442 vfio_send_intx_eventfd, NULL,
443 &vdev->ctx[0].unmask, fd);
445 vfio_virqfd_disable(&vdev->ctx[0].unmask);
448 return 0;
451 static int vfio_pci_set_intx_mask(struct vfio_pci_device *vdev,
452 unsigned index, unsigned start,
453 unsigned count, uint32_t flags, void *data)
455 if (!is_intx(vdev) || start != 0 || count != 1)
456 return -EINVAL;
458 if (flags & VFIO_IRQ_SET_DATA_NONE) {
459 vfio_pci_intx_mask(vdev);
460 } else if (flags & VFIO_IRQ_SET_DATA_BOOL) {
461 uint8_t mask = *(uint8_t *)data;
462 if (mask)
463 vfio_pci_intx_mask(vdev);
464 } else if (flags & VFIO_IRQ_SET_DATA_EVENTFD) {
465 return -ENOTTY; /* XXX implement me */
468 return 0;
471 static int vfio_pci_set_intx_trigger(struct vfio_pci_device *vdev,
472 unsigned index, unsigned start,
473 unsigned count, uint32_t flags, void *data)
475 if (is_intx(vdev) && !count && (flags & VFIO_IRQ_SET_DATA_NONE)) {
476 vfio_intx_disable(vdev);
477 return 0;
480 if (!(is_intx(vdev) || is_irq_none(vdev)) || start != 0 || count != 1)
481 return -EINVAL;
483 if (flags & VFIO_IRQ_SET_DATA_EVENTFD) {
484 int32_t fd = *(int32_t *)data;
485 int ret;
487 if (is_intx(vdev))
488 return vfio_intx_set_signal(vdev, fd);
490 ret = vfio_intx_enable(vdev);
491 if (ret)
492 return ret;
494 ret = vfio_intx_set_signal(vdev, fd);
495 if (ret)
496 vfio_intx_disable(vdev);
498 return ret;
501 if (!is_intx(vdev))
502 return -EINVAL;
504 if (flags & VFIO_IRQ_SET_DATA_NONE) {
505 vfio_send_intx_eventfd(vdev, NULL);
506 } else if (flags & VFIO_IRQ_SET_DATA_BOOL) {
507 uint8_t trigger = *(uint8_t *)data;
508 if (trigger)
509 vfio_send_intx_eventfd(vdev, NULL);
511 return 0;
514 static int vfio_pci_set_msi_trigger(struct vfio_pci_device *vdev,
515 unsigned index, unsigned start,
516 unsigned count, uint32_t flags, void *data)
518 int i;
519 bool msix = (index == VFIO_PCI_MSIX_IRQ_INDEX) ? true : false;
521 if (irq_is(vdev, index) && !count && (flags & VFIO_IRQ_SET_DATA_NONE)) {
522 vfio_msi_disable(vdev, msix);
523 return 0;
526 if (!(irq_is(vdev, index) || is_irq_none(vdev)))
527 return -EINVAL;
529 if (flags & VFIO_IRQ_SET_DATA_EVENTFD) {
530 int32_t *fds = data;
531 int ret;
533 if (vdev->irq_type == index)
534 return vfio_msi_set_block(vdev, start, count,
535 fds, msix);
537 ret = vfio_msi_enable(vdev, start + count, msix);
538 if (ret)
539 return ret;
541 ret = vfio_msi_set_block(vdev, start, count, fds, msix);
542 if (ret)
543 vfio_msi_disable(vdev, msix);
545 return ret;
548 if (!irq_is(vdev, index) || start + count > vdev->num_ctx)
549 return -EINVAL;
551 for (i = start; i < start + count; i++) {
552 if (!vdev->ctx[i].trigger)
553 continue;
554 if (flags & VFIO_IRQ_SET_DATA_NONE) {
555 eventfd_signal(vdev->ctx[i].trigger, 1);
556 } else if (flags & VFIO_IRQ_SET_DATA_BOOL) {
557 uint8_t *bools = data;
558 if (bools[i - start])
559 eventfd_signal(vdev->ctx[i].trigger, 1);
562 return 0;
565 static int vfio_pci_set_ctx_trigger_single(struct eventfd_ctx **ctx,
566 unsigned int count, uint32_t flags,
567 void *data)
569 /* DATA_NONE/DATA_BOOL enables loopback testing */
570 if (flags & VFIO_IRQ_SET_DATA_NONE) {
571 if (*ctx) {
572 if (count) {
573 eventfd_signal(*ctx, 1);
574 } else {
575 eventfd_ctx_put(*ctx);
576 *ctx = NULL;
578 return 0;
580 } else if (flags & VFIO_IRQ_SET_DATA_BOOL) {
581 uint8_t trigger;
583 if (!count)
584 return -EINVAL;
586 trigger = *(uint8_t *)data;
587 if (trigger && *ctx)
588 eventfd_signal(*ctx, 1);
590 return 0;
591 } else if (flags & VFIO_IRQ_SET_DATA_EVENTFD) {
592 int32_t fd;
594 if (!count)
595 return -EINVAL;
597 fd = *(int32_t *)data;
598 if (fd == -1) {
599 if (*ctx)
600 eventfd_ctx_put(*ctx);
601 *ctx = NULL;
602 } else if (fd >= 0) {
603 struct eventfd_ctx *efdctx;
605 efdctx = eventfd_ctx_fdget(fd);
606 if (IS_ERR(efdctx))
607 return PTR_ERR(efdctx);
609 if (*ctx)
610 eventfd_ctx_put(*ctx);
612 *ctx = efdctx;
614 return 0;
617 return -EINVAL;
620 static int vfio_pci_set_err_trigger(struct vfio_pci_device *vdev,
621 unsigned index, unsigned start,
622 unsigned count, uint32_t flags, void *data)
624 if (index != VFIO_PCI_ERR_IRQ_INDEX || start != 0 || count > 1)
625 return -EINVAL;
627 return vfio_pci_set_ctx_trigger_single(&vdev->err_trigger,
628 count, flags, data);
631 static int vfio_pci_set_req_trigger(struct vfio_pci_device *vdev,
632 unsigned index, unsigned start,
633 unsigned count, uint32_t flags, void *data)
635 if (index != VFIO_PCI_REQ_IRQ_INDEX || start != 0 || count > 1)
636 return -EINVAL;
638 return vfio_pci_set_ctx_trigger_single(&vdev->req_trigger,
639 count, flags, data);
642 int vfio_pci_set_irqs_ioctl(struct vfio_pci_device *vdev, uint32_t flags,
643 unsigned index, unsigned start, unsigned count,
644 void *data)
646 int (*func)(struct vfio_pci_device *vdev, unsigned index,
647 unsigned start, unsigned count, uint32_t flags,
648 void *data) = NULL;
650 switch (index) {
651 case VFIO_PCI_INTX_IRQ_INDEX:
652 switch (flags & VFIO_IRQ_SET_ACTION_TYPE_MASK) {
653 case VFIO_IRQ_SET_ACTION_MASK:
654 func = vfio_pci_set_intx_mask;
655 break;
656 case VFIO_IRQ_SET_ACTION_UNMASK:
657 func = vfio_pci_set_intx_unmask;
658 break;
659 case VFIO_IRQ_SET_ACTION_TRIGGER:
660 func = vfio_pci_set_intx_trigger;
661 break;
663 break;
664 case VFIO_PCI_MSI_IRQ_INDEX:
665 case VFIO_PCI_MSIX_IRQ_INDEX:
666 switch (flags & VFIO_IRQ_SET_ACTION_TYPE_MASK) {
667 case VFIO_IRQ_SET_ACTION_MASK:
668 case VFIO_IRQ_SET_ACTION_UNMASK:
669 /* XXX Need masking support exported */
670 break;
671 case VFIO_IRQ_SET_ACTION_TRIGGER:
672 func = vfio_pci_set_msi_trigger;
673 break;
675 break;
676 case VFIO_PCI_ERR_IRQ_INDEX:
677 switch (flags & VFIO_IRQ_SET_ACTION_TYPE_MASK) {
678 case VFIO_IRQ_SET_ACTION_TRIGGER:
679 if (pci_is_pcie(vdev->pdev))
680 func = vfio_pci_set_err_trigger;
681 break;
683 break;
684 case VFIO_PCI_REQ_IRQ_INDEX:
685 switch (flags & VFIO_IRQ_SET_ACTION_TYPE_MASK) {
686 case VFIO_IRQ_SET_ACTION_TRIGGER:
687 func = vfio_pci_set_req_trigger;
688 break;
690 break;
693 if (!func)
694 return -ENOTTY;
696 return func(vdev, index, start, count, flags, data);