Lines Matching refs:vmf
2627 static bool pte_spinlock(struct vm_fault *vmf) in pte_spinlock() argument
2635 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE)) { in pte_spinlock()
2636 vmf->ptl = pte_lockptr(vmf->vma->vm_mm, vmf->pmd); in pte_spinlock()
2637 spin_lock(vmf->ptl); in pte_spinlock()
2642 if (vma_has_changed(vmf)) { in pte_spinlock()
2643 trace_spf_vma_changed(_RET_IP_, vmf->vma, vmf->address); in pte_spinlock()
2652 pmdval = READ_ONCE(*vmf->pmd); in pte_spinlock()
2653 if (!pmd_same(pmdval, vmf->orig_pmd)) { in pte_spinlock()
2654 trace_spf_pmd_changed(_RET_IP_, vmf->vma, vmf->address); in pte_spinlock()
2659 vmf->ptl = pte_lockptr(vmf->vma->vm_mm, vmf->pmd); in pte_spinlock()
2660 if (unlikely(!spin_trylock(vmf->ptl))) { in pte_spinlock()
2661 trace_spf_pte_lock(_RET_IP_, vmf->vma, vmf->address); in pte_spinlock()
2665 if (vma_has_changed(vmf)) { in pte_spinlock()
2666 spin_unlock(vmf->ptl); in pte_spinlock()
2667 trace_spf_vma_changed(_RET_IP_, vmf->vma, vmf->address); in pte_spinlock()
2677 static bool __pte_map_lock_speculative(struct vm_fault *vmf, unsigned long addr) in __pte_map_lock_speculative() argument
2694 if (vma_has_changed(vmf)) { in __pte_map_lock_speculative()
2695 trace_spf_vma_changed(_RET_IP_, vmf->vma, addr); in __pte_map_lock_speculative()
2704 pmdval = READ_ONCE(*vmf->pmd); in __pte_map_lock_speculative()
2705 if (!pmd_same(pmdval, vmf->orig_pmd)) { in __pte_map_lock_speculative()
2706 trace_spf_pmd_changed(_RET_IP_, vmf->vma, addr); in __pte_map_lock_speculative()
2718 ptl = pte_lockptr(vmf->vma->vm_mm, vmf->pmd); in __pte_map_lock_speculative()
2719 pte = pte_offset_map(vmf->pmd, addr); in __pte_map_lock_speculative()
2722 trace_spf_pte_lock(_RET_IP_, vmf->vma, addr); in __pte_map_lock_speculative()
2726 if (vma_has_changed(vmf)) { in __pte_map_lock_speculative()
2728 trace_spf_vma_changed(_RET_IP_, vmf->vma, addr); in __pte_map_lock_speculative()
2732 vmf->pte = pte; in __pte_map_lock_speculative()
2733 vmf->ptl = ptl; in __pte_map_lock_speculative()
2740 static bool pte_map_lock(struct vm_fault *vmf) in pte_map_lock() argument
2742 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE)) { in pte_map_lock()
2743 vmf->pte = pte_offset_map_lock(vmf->vma->vm_mm, vmf->pmd, in pte_map_lock()
2744 vmf->address, &vmf->ptl); in pte_map_lock()
2748 return __pte_map_lock_speculative(vmf, vmf->address); in pte_map_lock()
2751 bool pte_map_lock_addr(struct vm_fault *vmf, unsigned long addr) in pte_map_lock_addr() argument
2753 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE)) { in pte_map_lock_addr()
2754 vmf->pte = pte_offset_map_lock(vmf->vma->vm_mm, vmf->pmd, in pte_map_lock_addr()
2755 addr, &vmf->ptl); in pte_map_lock_addr()
2759 return __pte_map_lock_speculative(vmf, addr); in pte_map_lock_addr()
2770 static bool vmf_allows_speculation(struct vm_fault *vmf) in vmf_allows_speculation() argument
2772 if (vma_is_anonymous(vmf->vma)) { in vmf_allows_speculation()
2778 if (!vmf->vma->anon_vma) { in vmf_allows_speculation()
2779 trace_spf_vma_notsup(_RET_IP_, vmf->vma, vmf->address); in vmf_allows_speculation()
2791 trace_spf_vma_notsup(_RET_IP_, vmf->vma, vmf->address); in vmf_allows_speculation()
2795 if (!(vmf->vma->vm_flags & VM_SHARED) && in vmf_allows_speculation()
2796 (vmf->flags & FAULT_FLAG_WRITE) && in vmf_allows_speculation()
2797 !vmf->vma->anon_vma) { in vmf_allows_speculation()
2802 trace_spf_vma_notsup(_RET_IP_, vmf->vma, vmf->address); in vmf_allows_speculation()
2806 if (vmf->vma->vm_ops->allow_speculation && in vmf_allows_speculation()
2807 vmf->vma->vm_ops->allow_speculation()) { in vmf_allows_speculation()
2811 trace_spf_vma_notsup(_RET_IP_, vmf->vma, vmf->address); in vmf_allows_speculation()
2816 static inline bool pte_spinlock(struct vm_fault *vmf) in pte_spinlock() argument
2818 vmf->ptl = pte_lockptr(vmf->vma->vm_mm, vmf->pmd); in pte_spinlock()
2819 spin_lock(vmf->ptl); in pte_spinlock()
2823 static inline bool pte_map_lock(struct vm_fault *vmf) in pte_map_lock() argument
2825 vmf->pte = pte_offset_map_lock(vmf->vma->vm_mm, vmf->pmd, in pte_map_lock()
2826 vmf->address, &vmf->ptl); in pte_map_lock()
2830 inline bool pte_map_lock_addr(struct vm_fault *vmf, unsigned long addr) in pte_map_lock_addr() argument
2832 vmf->pte = pte_offset_map_lock(vmf->vma->vm_mm, vmf->pmd, in pte_map_lock_addr()
2833 addr, &vmf->ptl); in pte_map_lock_addr()
2837 static inline bool vmf_allows_speculation(struct vm_fault *vmf) in vmf_allows_speculation() argument
2871 static inline int pte_unmap_same(struct vm_fault *vmf) in pte_unmap_same() argument
2877 if (pte_spinlock(vmf)) { in pte_unmap_same()
2878 if (!pte_same(*vmf->pte, vmf->orig_pte)) in pte_unmap_same()
2880 spin_unlock(vmf->ptl); in pte_unmap_same()
2885 pte_unmap(vmf->pte); in pte_unmap_same()
2890 struct vm_fault *vmf) in cow_user_page() argument
2896 struct vm_area_struct *vma = vmf->vma; in cow_user_page()
2898 unsigned long addr = vmf->address; in cow_user_page()
2918 if (arch_faults_on_old_pte() && !pte_young(vmf->orig_pte)) { in cow_user_page()
2921 vmf->pte = pte_offset_map_lock(mm, vmf->pmd, addr, &vmf->ptl); in cow_user_page()
2923 if (!likely(pte_same(*vmf->pte, vmf->orig_pte))) { in cow_user_page()
2928 update_mmu_tlb(vma, addr, vmf->pte); in cow_user_page()
2933 entry = pte_mkyoung(vmf->orig_pte); in cow_user_page()
2934 if (ptep_set_access_flags(vma, addr, vmf->pte, entry, 0)) in cow_user_page()
2935 update_mmu_cache(vma, addr, vmf->pte); in cow_user_page()
2949 vmf->pte = pte_offset_map_lock(mm, vmf->pmd, addr, &vmf->ptl); in cow_user_page()
2951 if (!likely(pte_same(*vmf->pte, vmf->orig_pte))) { in cow_user_page()
2953 update_mmu_tlb(vma, addr, vmf->pte); in cow_user_page()
2977 pte_unmap_unlock(vmf->pte, vmf->ptl); in cow_user_page()
3004 static vm_fault_t do_page_mkwrite(struct vm_fault *vmf) in do_page_mkwrite() argument
3007 struct page *page = vmf->page; in do_page_mkwrite()
3008 unsigned int old_flags = vmf->flags; in do_page_mkwrite()
3010 vmf->flags = FAULT_FLAG_WRITE|FAULT_FLAG_MKWRITE; in do_page_mkwrite()
3012 if (vmf->vma->vm_file && in do_page_mkwrite()
3013 IS_SWAPFILE(vmf->vma->vm_file->f_mapping->host)) in do_page_mkwrite()
3016 ret = vmf->vma->vm_ops->page_mkwrite(vmf); in do_page_mkwrite()
3018 vmf->flags = old_flags; in do_page_mkwrite()
3038 static vm_fault_t fault_dirty_shared_page(struct vm_fault *vmf) in fault_dirty_shared_page() argument
3040 struct vm_area_struct *vma = vmf->vma; in fault_dirty_shared_page()
3042 struct page *page = vmf->page; in fault_dirty_shared_page()
3072 fpin = maybe_unlock_mmap_for_io(vmf, NULL); in fault_dirty_shared_page()
3091 static inline void wp_page_reuse(struct vm_fault *vmf) in wp_page_reuse() argument
3092 __releases(vmf->ptl) in wp_page_reuse()
3094 struct vm_area_struct *vma = vmf->vma; in wp_page_reuse()
3095 struct page *page = vmf->page; in wp_page_reuse()
3105 flush_cache_page(vma, vmf->address, pte_pfn(vmf->orig_pte)); in wp_page_reuse()
3106 entry = pte_mkyoung(vmf->orig_pte); in wp_page_reuse()
3107 entry = maybe_mkwrite(pte_mkdirty(entry), vmf->vma_flags); in wp_page_reuse()
3108 if (ptep_set_access_flags(vma, vmf->address, vmf->pte, entry, 1)) in wp_page_reuse()
3109 update_mmu_cache(vma, vmf->address, vmf->pte); in wp_page_reuse()
3110 pte_unmap_unlock(vmf->pte, vmf->ptl); in wp_page_reuse()
3130 static vm_fault_t wp_page_copy(struct vm_fault *vmf) in wp_page_copy() argument
3132 struct vm_area_struct *vma = vmf->vma; in wp_page_copy()
3134 struct page *old_page = vmf->page; in wp_page_copy()
3144 if (is_zero_pfn(pte_pfn(vmf->orig_pte))) { in wp_page_copy()
3146 vmf->address); in wp_page_copy()
3151 vmf->address); in wp_page_copy()
3155 if (!cow_user_page(new_page, old_page, vmf)) { in wp_page_copy()
3167 trace_android_vh_cow_user_page(vmf, new_page); in wp_page_copy()
3177 vmf->address & PAGE_MASK, in wp_page_copy()
3178 (vmf->address & PAGE_MASK) + PAGE_SIZE); in wp_page_copy()
3184 if (!pte_map_lock(vmf)) { in wp_page_copy()
3188 if (likely(pte_same(*vmf->pte, vmf->orig_pte))) { in wp_page_copy()
3198 flush_cache_page(vma, vmf->address, pte_pfn(vmf->orig_pte)); in wp_page_copy()
3199 entry = mk_pte(new_page, vmf->vma_page_prot); in wp_page_copy()
3201 entry = maybe_mkwrite(pte_mkdirty(entry), vmf->vma_flags); in wp_page_copy()
3208 ptep_clear_flush_notify(vma, vmf->address, vmf->pte); in wp_page_copy()
3209 __page_add_new_anon_rmap(new_page, vma, vmf->address, false); in wp_page_copy()
3210 __lru_cache_add_inactive_or_unevictable(new_page, vmf->vma_flags); in wp_page_copy()
3216 set_pte_at_notify(mm, vmf->address, vmf->pte, entry); in wp_page_copy()
3217 update_mmu_cache(vma, vmf->address, vmf->pte); in wp_page_copy()
3248 update_mmu_tlb(vma, vmf->address, vmf->pte); in wp_page_copy()
3254 pte_unmap_unlock(vmf->pte, vmf->ptl); in wp_page_copy()
3265 if (page_copied && (vmf->vma_flags & VM_LOCKED)) { in wp_page_copy()
3300 vm_fault_t finish_mkwrite_fault(struct vm_fault *vmf) in finish_mkwrite_fault() argument
3302 WARN_ON_ONCE(!(vmf->vma_flags & VM_SHARED)); in finish_mkwrite_fault()
3303 if (!pte_map_lock(vmf)) in finish_mkwrite_fault()
3309 if (!pte_same(*vmf->pte, vmf->orig_pte)) { in finish_mkwrite_fault()
3310 update_mmu_tlb(vmf->vma, vmf->address, vmf->pte); in finish_mkwrite_fault()
3311 pte_unmap_unlock(vmf->pte, vmf->ptl); in finish_mkwrite_fault()
3314 wp_page_reuse(vmf); in finish_mkwrite_fault()
3322 static vm_fault_t wp_pfn_shared(struct vm_fault *vmf) in wp_pfn_shared() argument
3324 struct vm_area_struct *vma = vmf->vma; in wp_pfn_shared()
3329 pte_unmap_unlock(vmf->pte, vmf->ptl); in wp_pfn_shared()
3330 vmf->flags |= FAULT_FLAG_MKWRITE; in wp_pfn_shared()
3331 ret = vma->vm_ops->pfn_mkwrite(vmf); in wp_pfn_shared()
3334 return finish_mkwrite_fault(vmf); in wp_pfn_shared()
3336 wp_page_reuse(vmf); in wp_pfn_shared()
3340 static vm_fault_t wp_page_shared(struct vm_fault *vmf) in wp_page_shared() argument
3341 __releases(vmf->ptl) in wp_page_shared()
3343 struct vm_area_struct *vma = vmf->vma; in wp_page_shared()
3346 get_page(vmf->page); in wp_page_shared()
3351 pte_unmap_unlock(vmf->pte, vmf->ptl); in wp_page_shared()
3352 tmp = do_page_mkwrite(vmf); in wp_page_shared()
3355 put_page(vmf->page); in wp_page_shared()
3358 tmp = finish_mkwrite_fault(vmf); in wp_page_shared()
3360 unlock_page(vmf->page); in wp_page_shared()
3361 put_page(vmf->page); in wp_page_shared()
3365 wp_page_reuse(vmf); in wp_page_shared()
3366 lock_page(vmf->page); in wp_page_shared()
3368 ret |= fault_dirty_shared_page(vmf); in wp_page_shared()
3369 put_page(vmf->page); in wp_page_shared()
3392 static vm_fault_t do_wp_page(struct vm_fault *vmf) in do_wp_page() argument
3393 __releases(vmf->ptl) in do_wp_page()
3395 struct vm_area_struct *vma = vmf->vma; in do_wp_page()
3397 if (userfaultfd_pte_wp(vma, *vmf->pte)) { in do_wp_page()
3398 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_wp_page()
3399 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in do_wp_page()
3401 return handle_userfault(vmf, VM_UFFD_WP); in do_wp_page()
3408 if (unlikely(userfaultfd_wp(vmf->vma) && in do_wp_page()
3409 mm_tlb_flush_pending(vmf->vma->vm_mm))) in do_wp_page()
3410 flush_tlb_page(vmf->vma, vmf->address); in do_wp_page()
3412 vmf->page = _vm_normal_page(vma, vmf->address, vmf->orig_pte, in do_wp_page()
3413 vmf->vma_flags); in do_wp_page()
3414 if (!vmf->page) { in do_wp_page()
3422 if ((vmf->vma_flags & (VM_WRITE|VM_SHARED)) == in do_wp_page()
3424 return wp_pfn_shared(vmf); in do_wp_page()
3426 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_wp_page()
3427 return wp_page_copy(vmf); in do_wp_page()
3434 if (PageAnon(vmf->page)) { in do_wp_page()
3435 struct page *page = vmf->page; in do_wp_page()
3452 wp_page_reuse(vmf); in do_wp_page()
3454 } else if (unlikely((vmf->vma_flags & (VM_WRITE|VM_SHARED)) == in do_wp_page()
3456 return wp_page_shared(vmf); in do_wp_page()
3462 get_page(vmf->page); in do_wp_page()
3464 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_wp_page()
3465 return wp_page_copy(vmf); in do_wp_page()
3602 vm_fault_t do_swap_page(struct vm_fault *vmf) in do_swap_page() argument
3604 struct vm_area_struct *vma = vmf->vma; in do_swap_page()
3613 if (vmf->flags & FAULT_FLAG_SPECULATIVE) { in do_swap_page()
3614 pte_unmap(vmf->pte); in do_swap_page()
3618 ret = pte_unmap_same(vmf); in do_swap_page()
3630 entry = pte_to_swp_entry(vmf->orig_pte); in do_swap_page()
3633 migration_entry_wait(vma->vm_mm, vmf->pmd, in do_swap_page()
3634 vmf->address); in do_swap_page()
3636 vmf->page = device_private_entry_to_page(entry); in do_swap_page()
3637 ret = vmf->page->pgmap->ops->migrate_to_ram(vmf); in do_swap_page()
3641 print_bad_pte(vma, vmf->address, vmf->orig_pte, NULL); in do_swap_page()
3649 page = lookup_swap_cache(entry, vma, vmf->address); in do_swap_page()
3661 page = alloc_page_vma(flags, vma, vmf->address); in do_swap_page()
3686 } else if (vmf->flags & FAULT_FLAG_SPECULATIVE) { in do_swap_page()
3699 vmf); in do_swap_page()
3709 if (!pte_map_lock(vmf)) { in do_swap_page()
3715 if (likely(pte_same(*vmf->pte, vmf->orig_pte))) in do_swap_page()
3735 locked = lock_page_or_retry(page, vma->vm_mm, vmf->flags); in do_swap_page()
3753 page = ksm_might_need_to_copy(page, vma, vmf->address); in do_swap_page()
3766 if (!pte_map_lock(vmf)) { in do_swap_page()
3770 if (unlikely(!pte_same(*vmf->pte, vmf->orig_pte))) in do_swap_page()
3790 pte = mk_pte(page, vmf->vma_page_prot); in do_swap_page()
3791 if ((vmf->flags & FAULT_FLAG_WRITE) && reuse_swap_page(page, NULL)) { in do_swap_page()
3792 pte = maybe_mkwrite(pte_mkdirty(pte), vmf->vma_flags); in do_swap_page()
3793 vmf->flags &= ~FAULT_FLAG_WRITE; in do_swap_page()
3798 if (pte_swp_soft_dirty(vmf->orig_pte)) in do_swap_page()
3800 if (pte_swp_uffd_wp(vmf->orig_pte)) { in do_swap_page()
3804 set_pte_at(vma->vm_mm, vmf->address, vmf->pte, pte); in do_swap_page()
3805 arch_do_swap_page(vma->vm_mm, vma, vmf->address, pte, vmf->orig_pte); in do_swap_page()
3806 vmf->orig_pte = pte; in do_swap_page()
3810 __page_add_new_anon_rmap(page, vma, vmf->address, false); in do_swap_page()
3811 __lru_cache_add_inactive_or_unevictable(page, vmf->vma_flags); in do_swap_page()
3813 do_page_add_anon_rmap(page, vma, vmf->address, exclusive); in do_swap_page()
3816 trace_android_vh_swapin_add_anon_rmap(vmf, page); in do_swap_page()
3819 (vmf->vma_flags & VM_LOCKED) || PageMlocked(page)) in do_swap_page()
3835 if (vmf->flags & FAULT_FLAG_WRITE) { in do_swap_page()
3836 ret |= do_wp_page(vmf); in do_swap_page()
3843 update_mmu_cache(vma, vmf->address, vmf->pte); in do_swap_page()
3845 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_swap_page()
3849 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_swap_page()
3866 static vm_fault_t do_anonymous_page(struct vm_fault *vmf) in do_anonymous_page() argument
3868 struct vm_area_struct *vma = vmf->vma; in do_anonymous_page()
3874 if (vmf->vma_flags & VM_SHARED) in do_anonymous_page()
3878 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in do_anonymous_page()
3891 if (pte_alloc(vma->vm_mm, vmf->pmd)) in do_anonymous_page()
3895 if (unlikely(pmd_trans_unstable(vmf->pmd))) in do_anonymous_page()
3900 if (!(vmf->flags & FAULT_FLAG_WRITE) && in do_anonymous_page()
3902 entry = pte_mkspecial(pfn_pte(my_zero_pfn(vmf->address), in do_anonymous_page()
3903 vmf->vma_page_prot)); in do_anonymous_page()
3904 if (!pte_map_lock(vmf)) in do_anonymous_page()
3906 if (!pte_none(*vmf->pte)) { in do_anonymous_page()
3907 update_mmu_tlb(vma, vmf->address, vmf->pte); in do_anonymous_page()
3919 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in do_anonymous_page()
3923 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_anonymous_page()
3924 return handle_userfault(vmf, VM_UFFD_MISSING); in do_anonymous_page()
3932 page = alloc_zeroed_user_highpage_movable(vma, vmf->address); in do_anonymous_page()
3947 entry = mk_pte(page, vmf->vma_page_prot); in do_anonymous_page()
3949 if (vmf->vma_flags & VM_WRITE) in do_anonymous_page()
3952 if (!pte_map_lock(vmf)) { in do_anonymous_page()
3957 if (!pte_none(*vmf->pte)) { in do_anonymous_page()
3958 update_mmu_cache(vma, vmf->address, vmf->pte); in do_anonymous_page()
3967 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE) && in do_anonymous_page()
3969 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_anonymous_page()
3971 return handle_userfault(vmf, VM_UFFD_MISSING); in do_anonymous_page()
3975 __page_add_new_anon_rmap(page, vma, vmf->address, false); in do_anonymous_page()
3976 __lru_cache_add_inactive_or_unevictable(page, vmf->vma_flags); in do_anonymous_page()
3978 set_pte_at(vma->vm_mm, vmf->address, vmf->pte, entry); in do_anonymous_page()
3981 update_mmu_cache(vma, vmf->address, vmf->pte); in do_anonymous_page()
3983 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_anonymous_page()
3986 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_anonymous_page()
4001 static vm_fault_t __do_fault(struct vm_fault *vmf) in __do_fault() argument
4003 struct vm_area_struct *vma = vmf->vma; in __do_fault()
4007 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in __do_fault()
4025 if (pmd_none(*vmf->pmd) && !vmf->prealloc_pte) { in __do_fault()
4026 vmf->prealloc_pte = pte_alloc_one(vma->vm_mm); in __do_fault()
4027 if (!vmf->prealloc_pte) in __do_fault()
4033 ret = vma->vm_ops->fault(vmf); in __do_fault()
4038 if (unlikely(PageHWPoison(vmf->page))) { in __do_fault()
4039 struct page *page = vmf->page; in __do_fault()
4051 vmf->page = NULL; in __do_fault()
4056 lock_page(vmf->page); in __do_fault()
4058 VM_BUG_ON_PAGE(!PageLocked(vmf->page), vmf->page); in __do_fault()
4064 static void deposit_prealloc_pte(struct vm_fault *vmf) in deposit_prealloc_pte() argument
4066 struct vm_area_struct *vma = vmf->vma; in deposit_prealloc_pte()
4068 pgtable_trans_huge_deposit(vma->vm_mm, vmf->pmd, vmf->prealloc_pte); in deposit_prealloc_pte()
4074 vmf->prealloc_pte = NULL; in deposit_prealloc_pte()
4077 vm_fault_t do_set_pmd(struct vm_fault *vmf, struct page *page) in do_set_pmd() argument
4079 struct vm_area_struct *vma = vmf->vma; in do_set_pmd()
4080 bool write = vmf->flags & FAULT_FLAG_WRITE; in do_set_pmd()
4081 unsigned long haddr = vmf->address & HPAGE_PMD_MASK; in do_set_pmd()
4097 if (arch_needs_pgtable_deposit() && !vmf->prealloc_pte) { in do_set_pmd()
4098 vmf->prealloc_pte = pte_alloc_one(vma->vm_mm); in do_set_pmd()
4099 if (!vmf->prealloc_pte) in do_set_pmd()
4104 vmf->ptl = pmd_lock(vma->vm_mm, vmf->pmd); in do_set_pmd()
4105 if (unlikely(!pmd_none(*vmf->pmd))) in do_set_pmd()
4111 entry = mk_huge_pmd(page, vmf->vma_page_prot); in do_set_pmd()
4121 deposit_prealloc_pte(vmf); in do_set_pmd()
4123 set_pmd_at(vma->vm_mm, haddr, vmf->pmd, entry); in do_set_pmd()
4125 update_mmu_cache_pmd(vma, haddr, vmf->pmd); in do_set_pmd()
4131 spin_unlock(vmf->ptl); in do_set_pmd()
4135 vm_fault_t do_set_pmd(struct vm_fault *vmf, struct page *page) in do_set_pmd() argument
4141 void do_set_pte(struct vm_fault *vmf, struct page *page, unsigned long addr) in do_set_pte() argument
4143 struct vm_area_struct *vma = vmf->vma; in do_set_pte()
4144 bool write = vmf->flags & FAULT_FLAG_WRITE; in do_set_pte()
4145 bool prefault = vmf->address != addr; in do_set_pte()
4149 entry = mk_pte(page, vmf->vma_page_prot); in do_set_pte()
4157 entry = maybe_mkwrite(pte_mkdirty(entry), vmf->vma_flags); in do_set_pte()
4159 if (write && !(vmf->vma_flags & VM_SHARED)) { in do_set_pte()
4162 __lru_cache_add_inactive_or_unevictable(page, vmf->vma_flags); in do_set_pte()
4167 set_pte_at(vma->vm_mm, addr, vmf->pte, entry); in do_set_pte()
4185 vm_fault_t finish_fault(struct vm_fault *vmf) in finish_fault() argument
4187 struct vm_area_struct *vma = vmf->vma; in finish_fault()
4192 if ((vmf->flags & FAULT_FLAG_WRITE) && in finish_fault()
4193 !(vmf->vma_flags & VM_SHARED)) in finish_fault()
4194 page = vmf->cow_page; in finish_fault()
4196 page = vmf->page; in finish_fault()
4209 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in finish_fault()
4212 if (pmd_none(*vmf->pmd)) { in finish_fault()
4214 ret = do_set_pmd(vmf, page); in finish_fault()
4219 if (vmf->prealloc_pte) { in finish_fault()
4220 vmf->ptl = pmd_lock(vma->vm_mm, vmf->pmd); in finish_fault()
4221 if (likely(pmd_none(*vmf->pmd))) { in finish_fault()
4223 pmd_populate(vma->vm_mm, vmf->pmd, vmf->prealloc_pte); in finish_fault()
4224 vmf->prealloc_pte = NULL; in finish_fault()
4226 spin_unlock(vmf->ptl); in finish_fault()
4227 } else if (unlikely(pte_alloc(vma->vm_mm, vmf->pmd))) { in finish_fault()
4236 if (pmd_devmap_trans_unstable(vmf->pmd)) in finish_fault()
4240 if (!pte_map_lock(vmf)) in finish_fault()
4245 if (likely(pte_none(*vmf->pte))) in finish_fault()
4246 do_set_pte(vmf, page, vmf->address); in finish_fault()
4250 update_mmu_tlb(vma, vmf->address, vmf->pte); in finish_fault()
4251 pte_unmap_unlock(vmf->pte, vmf->ptl); in finish_fault()
4315 static vm_fault_t do_fault_around(struct vm_fault *vmf) in do_fault_around() argument
4317 unsigned long address = vmf->address, nr_pages, mask; in do_fault_around()
4318 pgoff_t start_pgoff = vmf->pgoff; in do_fault_around()
4325 address = max(address & mask, vmf->vma->vm_start); in do_fault_around()
4326 off = ((vmf->address - address) >> PAGE_SHIFT) & (PTRS_PER_PTE - 1); in do_fault_around()
4336 end_pgoff = min3(end_pgoff, vma_pages(vmf->vma) + vmf->vma->vm_pgoff - 1, in do_fault_around()
4339 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE) && in do_fault_around()
4340 pmd_none(*vmf->pmd)) { in do_fault_around()
4341 vmf->prealloc_pte = pte_alloc_one(vmf->vma->vm_mm); in do_fault_around()
4342 if (!vmf->prealloc_pte) in do_fault_around()
4347 return vmf->vma->vm_ops->map_pages(vmf, start_pgoff, end_pgoff); in do_fault_around()
4350 static vm_fault_t do_read_fault(struct vm_fault *vmf) in do_read_fault() argument
4352 struct vm_area_struct *vma = vmf->vma; in do_read_fault()
4361 if (likely(!userfaultfd_minor(vmf->vma))) { in do_read_fault()
4362 ret = do_fault_around(vmf); in do_read_fault()
4368 ret = __do_fault(vmf); in do_read_fault()
4372 ret |= finish_fault(vmf); in do_read_fault()
4373 unlock_page(vmf->page); in do_read_fault()
4375 put_page(vmf->page); in do_read_fault()
4379 static vm_fault_t do_cow_fault(struct vm_fault *vmf) in do_cow_fault() argument
4381 struct vm_area_struct *vma = vmf->vma; in do_cow_fault()
4387 vmf->cow_page = alloc_page_vma(GFP_HIGHUSER_MOVABLE, vma, vmf->address); in do_cow_fault()
4388 if (!vmf->cow_page) in do_cow_fault()
4391 if (mem_cgroup_charge(vmf->cow_page, vma->vm_mm, GFP_KERNEL)) { in do_cow_fault()
4392 put_page(vmf->cow_page); in do_cow_fault()
4395 cgroup_throttle_swaprate(vmf->cow_page, GFP_KERNEL); in do_cow_fault()
4397 ret = __do_fault(vmf); in do_cow_fault()
4403 copy_user_highpage(vmf->cow_page, vmf->page, vmf->address, vma); in do_cow_fault()
4404 __SetPageUptodate(vmf->cow_page); in do_cow_fault()
4406 ret |= finish_fault(vmf); in do_cow_fault()
4407 unlock_page(vmf->page); in do_cow_fault()
4408 put_page(vmf->page); in do_cow_fault()
4413 put_page(vmf->cow_page); in do_cow_fault()
4417 static vm_fault_t do_shared_fault(struct vm_fault *vmf) in do_shared_fault() argument
4419 struct vm_area_struct *vma = vmf->vma; in do_shared_fault()
4422 ret = __do_fault(vmf); in do_shared_fault()
4431 unlock_page(vmf->page); in do_shared_fault()
4432 tmp = do_page_mkwrite(vmf); in do_shared_fault()
4435 put_page(vmf->page); in do_shared_fault()
4440 ret |= finish_fault(vmf); in do_shared_fault()
4443 unlock_page(vmf->page); in do_shared_fault()
4444 put_page(vmf->page); in do_shared_fault()
4448 ret |= fault_dirty_shared_page(vmf); in do_shared_fault()
4460 static vm_fault_t do_fault(struct vm_fault *vmf) in do_fault() argument
4462 struct vm_area_struct *vma = vmf->vma; in do_fault()
4474 if (unlikely(!pmd_present(*vmf->pmd))) in do_fault()
4477 vmf->pte = pte_offset_map_lock(vmf->vma->vm_mm, in do_fault()
4478 vmf->pmd, in do_fault()
4479 vmf->address, in do_fault()
4480 &vmf->ptl); in do_fault()
4488 if (unlikely(pte_none(*vmf->pte))) in do_fault()
4493 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_fault()
4495 } else if (!(vmf->flags & FAULT_FLAG_WRITE)) in do_fault()
4496 ret = do_read_fault(vmf); in do_fault()
4497 else if (!(vmf->vma_flags & VM_SHARED)) in do_fault()
4498 ret = do_cow_fault(vmf); in do_fault()
4500 ret = do_shared_fault(vmf); in do_fault()
4503 if (vmf->prealloc_pte) { in do_fault()
4504 pte_free(vm_mm, vmf->prealloc_pte); in do_fault()
4505 vmf->prealloc_pte = NULL; in do_fault()
4525 static vm_fault_t do_numa_page(struct vm_fault *vmf) in do_numa_page() argument
4527 struct vm_area_struct *vma = vmf->vma; in do_numa_page()
4534 bool was_writable = pte_savedwrite(vmf->orig_pte); in do_numa_page()
4542 if (!pte_spinlock(vmf)) in do_numa_page()
4544 if (unlikely(!pte_same(*vmf->pte, vmf->orig_pte))) { in do_numa_page()
4545 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_numa_page()
4553 old_pte = ptep_modify_prot_start(vma, vmf->address, vmf->pte); in do_numa_page()
4554 pte = pte_modify(old_pte, vmf->vma_page_prot); in do_numa_page()
4558 ptep_modify_prot_commit(vma, vmf->address, vmf->pte, old_pte, pte); in do_numa_page()
4559 update_mmu_cache(vma, vmf->address, vmf->pte); in do_numa_page()
4561 page = _vm_normal_page(vma, vmf->address, pte, vmf->vma_flags); in do_numa_page()
4563 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_numa_page()
4569 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_numa_page()
4588 if (page_mapcount(page) > 1 && (vmf->vma_flags & VM_SHARED)) in do_numa_page()
4593 target_nid = numa_migrate_prep(page, vma, vmf->address, page_nid, in do_numa_page()
4595 pte_unmap_unlock(vmf->pte, vmf->ptl); in do_numa_page()
4602 migrated = migrate_misplaced_page(page, vmf, target_nid); in do_numa_page()
4615 static inline vm_fault_t create_huge_pmd(struct vm_fault *vmf) in create_huge_pmd() argument
4617 if (vma_is_anonymous(vmf->vma)) in create_huge_pmd()
4618 return do_huge_pmd_anonymous_page(vmf); in create_huge_pmd()
4619 if (vmf->vma->vm_ops->huge_fault) in create_huge_pmd()
4620 return vmf->vma->vm_ops->huge_fault(vmf, PE_SIZE_PMD); in create_huge_pmd()
4625 static inline vm_fault_t wp_huge_pmd(struct vm_fault *vmf, pmd_t orig_pmd) in wp_huge_pmd() argument
4627 if (vma_is_anonymous(vmf->vma)) { in wp_huge_pmd()
4628 if (userfaultfd_huge_pmd_wp(vmf->vma, orig_pmd)) in wp_huge_pmd()
4629 return handle_userfault(vmf, VM_UFFD_WP); in wp_huge_pmd()
4630 return do_huge_pmd_wp_page(vmf, orig_pmd); in wp_huge_pmd()
4632 if (vmf->vma->vm_ops->huge_fault) { in wp_huge_pmd()
4633 vm_fault_t ret = vmf->vma->vm_ops->huge_fault(vmf, PE_SIZE_PMD); in wp_huge_pmd()
4640 __split_huge_pmd(vmf->vma, vmf->pmd, vmf->address, false, NULL); in wp_huge_pmd()
4645 static vm_fault_t create_huge_pud(struct vm_fault *vmf) in create_huge_pud() argument
4650 if (vma_is_anonymous(vmf->vma)) in create_huge_pud()
4652 if (vmf->vma->vm_ops->huge_fault) in create_huge_pud()
4653 return vmf->vma->vm_ops->huge_fault(vmf, PE_SIZE_PUD); in create_huge_pud()
4658 static vm_fault_t wp_huge_pud(struct vm_fault *vmf, pud_t orig_pud) in wp_huge_pud() argument
4663 if (vma_is_anonymous(vmf->vma)) in wp_huge_pud()
4665 if (vmf->vma->vm_ops->huge_fault) { in wp_huge_pud()
4666 vm_fault_t ret = vmf->vma->vm_ops->huge_fault(vmf, PE_SIZE_PUD); in wp_huge_pud()
4673 __split_huge_pud(vmf->vma, vmf->pud, vmf->address); in wp_huge_pud()
4693 static vm_fault_t handle_pte_fault(struct vm_fault *vmf) in handle_pte_fault() argument
4699 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in handle_pte_fault()
4702 if (unlikely(pmd_none(*vmf->pmd))) { in handle_pte_fault()
4709 vmf->pte = NULL; in handle_pte_fault()
4723 if (pmd_devmap_trans_unstable(vmf->pmd)) in handle_pte_fault()
4734 vmf->pte = pte_offset_map(vmf->pmd, vmf->address); in handle_pte_fault()
4735 vmf->orig_pte = *vmf->pte; in handle_pte_fault()
4746 if (pte_none(vmf->orig_pte)) { in handle_pte_fault()
4747 pte_unmap(vmf->pte); in handle_pte_fault()
4748 vmf->pte = NULL; in handle_pte_fault()
4753 if (!vmf->pte) { in handle_pte_fault()
4754 if (vma_is_anonymous(vmf->vma)) in handle_pte_fault()
4755 return do_anonymous_page(vmf); in handle_pte_fault()
4756 else if ((vmf->flags & FAULT_FLAG_SPECULATIVE) && in handle_pte_fault()
4757 !vmf_allows_speculation(vmf)) in handle_pte_fault()
4760 return do_fault(vmf); in handle_pte_fault()
4763 if (!pte_present(vmf->orig_pte)) in handle_pte_fault()
4764 return do_swap_page(vmf); in handle_pte_fault()
4766 if (pte_protnone(vmf->orig_pte) && vma_is_accessible(vmf->vma)) in handle_pte_fault()
4767 return do_numa_page(vmf); in handle_pte_fault()
4769 if (!pte_spinlock(vmf)) in handle_pte_fault()
4771 entry = vmf->orig_pte; in handle_pte_fault()
4772 if (unlikely(!pte_same(*vmf->pte, entry))) { in handle_pte_fault()
4773 update_mmu_tlb(vmf->vma, vmf->address, vmf->pte); in handle_pte_fault()
4776 if (vmf->flags & FAULT_FLAG_WRITE) { in handle_pte_fault()
4778 if (!(vmf->flags & FAULT_FLAG_SPECULATIVE)) in handle_pte_fault()
4779 return do_wp_page(vmf); in handle_pte_fault()
4781 if (!mmu_notifier_trylock(vmf->vma->vm_mm)) { in handle_pte_fault()
4786 ret = do_wp_page(vmf); in handle_pte_fault()
4787 mmu_notifier_unlock(vmf->vma->vm_mm); in handle_pte_fault()
4793 if (ptep_set_access_flags(vmf->vma, vmf->address, vmf->pte, entry, in handle_pte_fault()
4794 vmf->flags & FAULT_FLAG_WRITE)) { in handle_pte_fault()
4795 update_mmu_cache(vmf->vma, vmf->address, vmf->pte); in handle_pte_fault()
4798 if (vmf->flags & FAULT_FLAG_TRIED) in handle_pte_fault()
4800 if (vmf->flags & FAULT_FLAG_SPECULATIVE) in handle_pte_fault()
4808 if (vmf->flags & FAULT_FLAG_WRITE) in handle_pte_fault()
4809 flush_tlb_fix_spurious_fault(vmf->vma, vmf->address); in handle_pte_fault()
4811 trace_android_rvh_handle_pte_fault_end(vmf, highest_memmap_pfn); in handle_pte_fault()
4812 trace_android_vh_handle_pte_fault_end(vmf, highest_memmap_pfn); in handle_pte_fault()
4814 pte_unmap_unlock(vmf->pte, vmf->ptl); in handle_pte_fault()
4827 struct vm_fault vmf = { in __handle_mm_fault() local
4847 vmf.pud = pud_alloc(mm, p4d, address); in __handle_mm_fault()
4848 if (!vmf.pud) in __handle_mm_fault()
4851 if (pud_none(*vmf.pud) && __transparent_hugepage_enabled(vma)) { in __handle_mm_fault()
4852 ret = create_huge_pud(&vmf); in __handle_mm_fault()
4856 pud_t orig_pud = *vmf.pud; in __handle_mm_fault()
4864 ret = wp_huge_pud(&vmf, orig_pud); in __handle_mm_fault()
4868 huge_pud_set_accessed(&vmf, orig_pud); in __handle_mm_fault()
4874 vmf.pmd = pmd_alloc(mm, vmf.pud, address); in __handle_mm_fault()
4875 if (!vmf.pmd) in __handle_mm_fault()
4879 if (pud_trans_unstable(vmf.pud)) in __handle_mm_fault()
4883 vmf.sequence = raw_read_seqcount(&vma->vm_sequence); in __handle_mm_fault()
4885 if (pmd_none(*vmf.pmd) && __transparent_hugepage_enabled(vma)) { in __handle_mm_fault()
4886 ret = create_huge_pmd(&vmf); in __handle_mm_fault()
4890 pmd_t orig_pmd = *vmf.pmd; in __handle_mm_fault()
4897 pmd_migration_entry_wait(mm, vmf.pmd); in __handle_mm_fault()
4902 return do_huge_pmd_numa_page(&vmf, orig_pmd); in __handle_mm_fault()
4905 ret = wp_huge_pmd(&vmf, orig_pmd); in __handle_mm_fault()
4909 huge_pmd_set_accessed(&vmf, orig_pmd); in __handle_mm_fault()
4915 return handle_pte_fault(&vmf); in __handle_mm_fault()
5002 struct vm_fault vmf = { in ___handle_speculative_fault() local
5023 seq = raw_read_seqcount(&vmf.vma->vm_sequence); in ___handle_speculative_fault()
5025 trace_spf_vma_changed(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5029 if (!vmf_allows_speculation(&vmf)) in ___handle_speculative_fault()
5032 vmf.vma_flags = READ_ONCE(vmf.vma->vm_flags); in ___handle_speculative_fault()
5033 vmf.vma_page_prot = READ_ONCE(vmf.vma->vm_page_prot); in ___handle_speculative_fault()
5037 if (unlikely(vmf.vma_flags & __VM_UFFD_FLAGS)) { in ___handle_speculative_fault()
5038 trace_spf_vma_notsup(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5043 if (vmf.vma_flags & VM_GROWSDOWN || vmf.vma_flags & VM_GROWSUP) { in ___handle_speculative_fault()
5049 trace_spf_vma_notsup(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5053 if (address < READ_ONCE(vmf.vma->vm_start) in ___handle_speculative_fault()
5054 || READ_ONCE(vmf.vma->vm_end) <= address) { in ___handle_speculative_fault()
5055 trace_spf_vma_changed(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5059 if (!arch_vma_access_permitted(vmf.vma, flags & FAULT_FLAG_WRITE, in ___handle_speculative_fault()
5066 if (unlikely(!(vmf.vma_flags & VM_WRITE))) in ___handle_speculative_fault()
5068 } else if (unlikely(!(vmf.vma_flags & (VM_READ|VM_EXEC|VM_WRITE)))) in ___handle_speculative_fault()
5077 pol = __get_vma_policy(vmf.vma, address); in ___handle_speculative_fault()
5081 trace_spf_vma_notsup(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5102 vmf.pud = pud_offset(p4d, address); in ___handle_speculative_fault()
5105 pudval = READ_ONCE(*vmf.pud); in ___handle_speculative_fault()
5113 vmf.pmd = pmd_offset(vmf.pud, address); in ___handle_speculative_fault()
5114 if (pud_val(READ_ONCE(*vmf.pud)) != pud_val(pudval)) in ___handle_speculative_fault()
5116 vmf.orig_pmd = READ_ONCE(*vmf.pmd); in ___handle_speculative_fault()
5128 if (unlikely(pmd_devmap(vmf.orig_pmd) || in ___handle_speculative_fault()
5129 pmd_none(vmf.orig_pmd) || pmd_trans_huge(vmf.orig_pmd) || in ___handle_speculative_fault()
5130 is_swap_pmd(vmf.orig_pmd))) in ___handle_speculative_fault()
5142 vmf.pte = pte_offset_map(vmf.pmd, address); in ___handle_speculative_fault()
5143 if (pmd_val(READ_ONCE(*vmf.pmd)) != pmd_val(vmf.orig_pmd)) { in ___handle_speculative_fault()
5144 pte_unmap(vmf.pte); in ___handle_speculative_fault()
5145 vmf.pte = NULL; in ___handle_speculative_fault()
5148 vmf.orig_pte = READ_ONCE(*vmf.pte); in ___handle_speculative_fault()
5150 if (pte_none(vmf.orig_pte)) { in ___handle_speculative_fault()
5151 pte_unmap(vmf.pte); in ___handle_speculative_fault()
5152 vmf.pte = NULL; in ___handle_speculative_fault()
5155 vmf.sequence = seq; in ___handle_speculative_fault()
5156 vmf.flags = flags; in ___handle_speculative_fault()
5164 if (read_seqcount_retry(&vmf.vma->vm_sequence, seq)) { in ___handle_speculative_fault()
5165 trace_spf_vma_changed(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5170 ret = handle_pte_fault(&vmf); in ___handle_speculative_fault()
5174 if (vma_is_anonymous(vmf.vma)) in ___handle_speculative_fault()
5191 trace_spf_vma_notsup(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()
5196 trace_spf_vma_access(_RET_IP_, vmf.vma, address); in ___handle_speculative_fault()