1 // SPDX-License-Identifier: GPL-2.0 2 /* 3 * Performance events ring-buffer code: 4 * 5 * Copyright (C) 2008 Linutronix GmbH, Thomas Gleixner <tglx@kernel.org> 6 * Copyright (C) 2008-2011 Red Hat, Inc., Ingo Molnar 7 * Copyright (C) 2008-2011 Red Hat, Inc., Peter Zijlstra 8 * Copyright © 2009 Paul Mackerras, IBM Corp. <paulus@au1.ibm.com> 9 */ 10 11 #include <linux/perf_event.h> 12 #include <linux/vmalloc.h> 13 #include <linux/slab.h> 14 #include <linux/circ_buf.h> 15 #include <linux/poll.h> 16 #include <linux/nospec.h> 17 18 #include "internal.h" 19 20 static void perf_output_wakeup(struct perf_output_handle *handle) 21 { 22 atomic_set(&handle->rb->poll, EPOLLIN | EPOLLRDNORM); 23 24 handle->event->pending_wakeup = 1; 25 26 if (*perf_event_fasync(handle->event) && !handle->event->pending_kill) 27 handle->event->pending_kill = POLL_IN; 28 29 irq_work_queue(&handle->event->pending_irq); 30 } 31 32 /* 33 * We need to ensure a later event_id doesn't publish a head when a former 34 * event isn't done writing. However since we need to deal with NMIs we 35 * cannot fully serialize things. 36 * 37 * We only publish the head (and generate a wakeup) when the outer-most 38 * event completes. 39 */ 40 static void perf_output_get_handle(struct perf_output_handle *handle) 41 { 42 struct perf_buffer *rb = handle->rb; 43 44 preempt_disable(); 45 46 /* 47 * Avoid an explicit LOAD/STORE such that architectures with memops 48 * can use them. 49 */ 50 (*(volatile unsigned int *)&rb->nest)++; 51 handle->wakeup = local_read(&rb->wakeup); 52 } 53 54 static void perf_output_put_handle(struct perf_output_handle *handle) 55 { 56 struct perf_buffer *rb = handle->rb; 57 unsigned long head; 58 unsigned int nest; 59 60 /* 61 * If this isn't the outermost nesting, we don't have to update 62 * @rb->user_page->data_head. 63 */ 64 nest = READ_ONCE(rb->nest); 65 if (nest > 1) { 66 WRITE_ONCE(rb->nest, nest - 1); 67 goto out; 68 } 69 70 again: 71 /* 72 * In order to avoid publishing a head value that goes backwards, 73 * we must ensure the load of @rb->head happens after we've 74 * incremented @rb->nest. 75 * 76 * Otherwise we can observe a @rb->head value before one published 77 * by an IRQ/NMI happening between the load and the increment. 78 */ 79 barrier(); 80 head = local_read(&rb->head); 81 82 /* 83 * IRQ/NMI can happen here and advance @rb->head, causing our 84 * load above to be stale. 85 */ 86 87 /* 88 * Since the mmap() consumer (userspace) can run on a different CPU: 89 * 90 * kernel user 91 * 92 * if (LOAD ->data_tail) { LOAD ->data_head 93 * (A) smp_rmb() (C) 94 * STORE $data LOAD $data 95 * smp_wmb() (B) smp_mb() (D) 96 * STORE ->data_head STORE ->data_tail 97 * } 98 * 99 * Where A pairs with D, and B pairs with C. 100 * 101 * In our case (A) is a control dependency that separates the load of 102 * the ->data_tail and the stores of $data. In case ->data_tail 103 * indicates there is no room in the buffer to store $data we do not. 104 * 105 * D needs to be a full barrier since it separates the data READ 106 * from the tail WRITE. 107 * 108 * For B a WMB is sufficient since it separates two WRITEs, and for C 109 * an RMB is sufficient since it separates two READs. 110 * 111 * See perf_output_begin(). 112 */ 113 smp_wmb(); /* B, matches C */ 114 WRITE_ONCE(rb->user_page->data_head, head); 115 116 /* 117 * We must publish the head before decrementing the nest count, 118 * otherwise an IRQ/NMI can publish a more recent head value and our 119 * write will (temporarily) publish a stale value. 120 */ 121 barrier(); 122 WRITE_ONCE(rb->nest, 0); 123 124 /* 125 * Ensure we decrement @rb->nest before we validate the @rb->head. 126 * Otherwise we cannot be sure we caught the 'last' nested update. 127 */ 128 barrier(); 129 if (unlikely(head != local_read(&rb->head))) { 130 WRITE_ONCE(rb->nest, 1); 131 goto again; 132 } 133 134 if (handle->wakeup != local_read(&rb->wakeup)) 135 perf_output_wakeup(handle); 136 137 out: 138 preempt_enable(); 139 } 140 141 static __always_inline bool 142 ring_buffer_has_space(unsigned long head, unsigned long tail, 143 unsigned long data_size, unsigned int size, 144 bool backward) 145 { 146 if (!backward) 147 return CIRC_SPACE(head, tail, data_size) >= size; 148 else 149 return CIRC_SPACE(tail, head, data_size) >= size; 150 } 151 152 static __always_inline int 153 __perf_output_begin(struct perf_output_handle *handle, 154 struct perf_sample_data *data, 155 struct perf_event *event, unsigned int size, 156 bool backward) 157 { 158 struct perf_buffer *rb; 159 unsigned long tail, offset, head; 160 int have_lost, page_shift; 161 struct { 162 struct perf_event_header header; 163 u64 id; 164 u64 lost; 165 } lost_event; 166 167 rcu_read_lock(); 168 /* 169 * For inherited events we send all the output towards the parent. 170 */ 171 if (event->parent) 172 event = event->parent; 173 174 rb = rcu_dereference(event->rb); 175 if (unlikely(!rb)) 176 goto out; 177 178 if (unlikely(rb->paused)) { 179 if (rb->nr_pages) { 180 local_inc(&rb->lost); 181 atomic64_inc(&event->lost_samples); 182 } 183 goto out; 184 } 185 186 handle->rb = rb; 187 handle->event = event; 188 handle->flags = 0; 189 190 have_lost = local_read(&rb->lost); 191 if (unlikely(have_lost)) { 192 size += sizeof(lost_event); 193 if (event->attr.sample_id_all) 194 size += event->id_header_size; 195 } 196 197 perf_output_get_handle(handle); 198 199 offset = local_read(&rb->head); 200 do { 201 head = offset; 202 tail = READ_ONCE(rb->user_page->data_tail); 203 if (!rb->overwrite) { 204 if (unlikely(!ring_buffer_has_space(head, tail, 205 perf_data_size(rb), 206 size, backward))) 207 goto fail; 208 } 209 210 /* 211 * The above forms a control dependency barrier separating the 212 * @tail load above from the data stores below. Since the @tail 213 * load is required to compute the branch to fail below. 214 * 215 * A, matches D; the full memory barrier userspace SHOULD issue 216 * after reading the data and before storing the new tail 217 * position. 218 * 219 * See perf_output_put_handle(). 220 */ 221 222 if (!backward) 223 head += size; 224 else 225 head -= size; 226 } while (!local_try_cmpxchg(&rb->head, &offset, head)); 227 228 if (backward) { 229 offset = head; 230 head = (u64)(-head); 231 } 232 233 /* 234 * We rely on the implied barrier() by local_cmpxchg() to ensure 235 * none of the data stores below can be lifted up by the compiler. 236 */ 237 238 if (unlikely(head - local_read(&rb->wakeup) > rb->watermark)) 239 local_add(rb->watermark, &rb->wakeup); 240 241 page_shift = PAGE_SHIFT + page_order(rb); 242 243 handle->page = (offset >> page_shift) & (rb->nr_pages - 1); 244 offset &= (1UL << page_shift) - 1; 245 handle->addr = rb->data_pages[handle->page] + offset; 246 handle->size = (1UL << page_shift) - offset; 247 248 if (unlikely(have_lost)) { 249 lost_event.id = event->id; 250 lost_event.lost = local_xchg(&rb->lost, 0); 251 252 /* XXX mostly redundant; @data is already fully initializes */ 253 perf_event_header__init(&lost_event.header, data, 254 PERF_RECORD_LOST, /* misc= */ 0, 255 sizeof(lost_event), event); 256 perf_output_put(handle, lost_event); 257 perf_event__output_id_sample(event, handle, data); 258 } 259 260 return 0; 261 262 fail: 263 local_inc(&rb->lost); 264 atomic64_inc(&event->lost_samples); 265 perf_output_put_handle(handle); 266 out: 267 rcu_read_unlock(); 268 269 return -ENOSPC; 270 } 271 272 int perf_output_begin_forward(struct perf_output_handle *handle, 273 struct perf_sample_data *data, 274 struct perf_event *event, unsigned int size) 275 { 276 return __perf_output_begin(handle, data, event, size, false); 277 } 278 279 int perf_output_begin_backward(struct perf_output_handle *handle, 280 struct perf_sample_data *data, 281 struct perf_event *event, unsigned int size) 282 { 283 return __perf_output_begin(handle, data, event, size, true); 284 } 285 286 int perf_output_begin(struct perf_output_handle *handle, 287 struct perf_sample_data *data, 288 struct perf_event *event, unsigned int size) 289 { 290 291 return __perf_output_begin(handle, data, event, size, 292 unlikely(is_write_backward(event))); 293 } 294 295 unsigned int perf_output_copy(struct perf_output_handle *handle, 296 const void *buf, unsigned int len) 297 { 298 return __output_copy(handle, buf, len); 299 } 300 301 unsigned int perf_output_skip(struct perf_output_handle *handle, 302 unsigned int len) 303 { 304 return __output_skip(handle, NULL, len); 305 } 306 307 void perf_output_end(struct perf_output_handle *handle) 308 { 309 perf_output_put_handle(handle); 310 rcu_read_unlock(); 311 } 312 313 static void 314 ring_buffer_init(struct perf_buffer *rb, long watermark, int flags) 315 { 316 long max_size = perf_data_size(rb); 317 318 if (watermark) 319 rb->watermark = min(max_size, watermark); 320 321 if (!rb->watermark) 322 rb->watermark = max_size / 2; 323 324 if (flags & RING_BUFFER_WRITABLE) 325 rb->overwrite = 0; 326 else 327 rb->overwrite = 1; 328 329 refcount_set(&rb->refcount, 1); 330 331 INIT_LIST_HEAD(&rb->event_list); 332 spin_lock_init(&rb->event_lock); 333 334 /* 335 * perf_output_begin() only checks rb->paused, therefore 336 * rb->paused must be true if we have no pages for output. 337 */ 338 if (!rb->nr_pages) 339 rb->paused = 1; 340 341 mutex_init(&rb->aux_mutex); 342 rb->mmap_user = get_current_user(); 343 refcount_set(&rb->mmap_count, 1); 344 } 345 346 void perf_aux_output_flag(struct perf_output_handle *handle, u64 flags) 347 { 348 /* 349 * OVERWRITE is determined by perf_aux_output_end() and can't 350 * be passed in directly. 351 */ 352 if (WARN_ON_ONCE(flags & PERF_AUX_FLAG_OVERWRITE)) 353 return; 354 355 handle->aux_flags |= flags; 356 } 357 EXPORT_SYMBOL_GPL(perf_aux_output_flag); 358 359 /* 360 * This is called before hardware starts writing to the AUX area to 361 * obtain an output handle and make sure there's room in the buffer. 362 * When the capture completes, call perf_aux_output_end() to commit 363 * the recorded data to the buffer. 364 * 365 * The ordering is similar to that of perf_output_{begin,end}, with 366 * the exception of (B), which should be taken care of by the pmu 367 * driver, since ordering rules will differ depending on hardware. 368 * 369 * Call this from pmu::start(); see the comment in perf_aux_output_end() 370 * about its use in pmu callbacks. Both can also be called from the PMI 371 * handler if needed. 372 */ 373 void *perf_aux_output_begin(struct perf_output_handle *handle, 374 struct perf_event *event) 375 { 376 struct perf_event *output_event = event; 377 unsigned long aux_head, aux_tail; 378 struct perf_buffer *rb; 379 unsigned int nest; 380 381 if (output_event->parent) 382 output_event = output_event->parent; 383 384 /* 385 * Since this will typically be open across pmu::add/pmu::del, we 386 * grab ring_buffer's refcount instead of holding rcu read lock 387 * to make sure it doesn't disappear under us. 388 */ 389 rb = ring_buffer_get(output_event); 390 if (!rb) 391 return NULL; 392 393 if (!rb_has_aux(rb)) 394 goto err; 395 396 /* 397 * If aux_mmap_count is zero, the aux buffer is in perf_mmap_close(), 398 * about to get freed, so we leave immediately. 399 * 400 * Checking rb::aux_mmap_count and rb::refcount has to be done in 401 * the same order, see perf_mmap_close. Otherwise we end up freeing 402 * aux pages in this path, which is a bug, because in_atomic(). 403 */ 404 if (!refcount_read(&rb->aux_mmap_count)) 405 goto err; 406 407 if (!refcount_inc_not_zero(&rb->aux_refcount)) 408 goto err; 409 410 nest = READ_ONCE(rb->aux_nest); 411 /* 412 * Nesting is not supported for AUX area, make sure nested 413 * writers are caught early 414 */ 415 if (WARN_ON_ONCE(nest)) 416 goto err_put; 417 418 WRITE_ONCE(rb->aux_nest, nest + 1); 419 420 aux_head = rb->aux_head; 421 422 handle->rb = rb; 423 handle->event = event; 424 handle->head = aux_head; 425 handle->size = 0; 426 handle->aux_flags = 0; 427 428 /* 429 * In overwrite mode, AUX data stores do not depend on aux_tail, 430 * therefore (A) control dependency barrier does not exist. The 431 * (B) <-> (C) ordering is still observed by the pmu driver. 432 */ 433 if (!rb->aux_overwrite) { 434 aux_tail = READ_ONCE(rb->user_page->aux_tail); 435 handle->wakeup = rb->aux_wakeup + rb->aux_watermark; 436 if (aux_head - aux_tail < perf_aux_size(rb)) 437 handle->size = CIRC_SPACE(aux_head, aux_tail, perf_aux_size(rb)); 438 439 /* 440 * handle->size computation depends on aux_tail load; this forms a 441 * control dependency barrier separating aux_tail load from aux data 442 * store that will be enabled on successful return 443 */ 444 if (!handle->size) { /* A, matches D */ 445 perf_event_disable_inatomic(handle->event); 446 perf_output_wakeup(handle); 447 WRITE_ONCE(rb->aux_nest, 0); 448 goto err_put; 449 } 450 } 451 452 return handle->rb->aux_priv; 453 454 err_put: 455 /* can't be last */ 456 rb_free_aux(rb); 457 458 err: 459 ring_buffer_put(rb); 460 handle->event = NULL; 461 462 return NULL; 463 } 464 EXPORT_SYMBOL_GPL(perf_aux_output_begin); 465 466 static __always_inline bool rb_need_aux_wakeup(struct perf_buffer *rb) 467 { 468 if (rb->aux_overwrite) 469 return false; 470 471 if (rb->aux_head - rb->aux_wakeup >= rb->aux_watermark) { 472 rb->aux_wakeup = rounddown(rb->aux_head, rb->aux_watermark); 473 return true; 474 } 475 476 return false; 477 } 478 479 /* 480 * Commit the data written by hardware into the ring buffer by adjusting 481 * aux_head and posting a PERF_RECORD_AUX into the perf buffer. It is the 482 * pmu driver's responsibility to observe ordering rules of the hardware, 483 * so that all the data is externally visible before this is called. 484 * 485 * Note: this has to be called from pmu::stop() callback, as the assumption 486 * of the AUX buffer management code is that after pmu::stop(), the AUX 487 * transaction must be stopped and therefore drop the AUX reference count. 488 */ 489 void perf_aux_output_end(struct perf_output_handle *handle, unsigned long size) 490 { 491 bool wakeup = !!(handle->aux_flags & PERF_AUX_FLAG_TRUNCATED); 492 struct perf_buffer *rb = handle->rb; 493 unsigned long aux_head; 494 495 /* in overwrite mode, driver provides aux_head via handle */ 496 if (rb->aux_overwrite) { 497 handle->aux_flags |= PERF_AUX_FLAG_OVERWRITE; 498 499 aux_head = handle->head; 500 rb->aux_head = aux_head; 501 } else { 502 handle->aux_flags &= ~PERF_AUX_FLAG_OVERWRITE; 503 504 aux_head = rb->aux_head; 505 rb->aux_head += size; 506 } 507 508 /* 509 * Only send RECORD_AUX if we have something useful to communicate 510 * 511 * PMU_FORMAT bits identify the PMU type rather than an AUX event 512 * has occurred, so ignore them for zero-sized records. 513 * 514 * The OVERWRITE records by themselves are not considered 515 * useful, as they don't communicate any *new* information, 516 * aside from the short-lived offset, that becomes history at 517 * the next event sched-in and therefore isn't useful. 518 * The userspace that needs to copy out AUX data in overwrite 519 * mode should know to use user_page::aux_head for the actual 520 * offset. So, from now on we don't output AUX records that 521 * have *only* OVERWRITE flag set. 522 */ 523 if (size || 524 (handle->aux_flags & ~(u64)(PERF_AUX_FLAG_PMU_FORMAT_TYPE_MASK | 525 PERF_AUX_FLAG_OVERWRITE))) 526 perf_event_aux_event(handle->event, aux_head, size, 527 handle->aux_flags); 528 529 WRITE_ONCE(rb->user_page->aux_head, rb->aux_head); 530 if (rb_need_aux_wakeup(rb)) 531 wakeup = true; 532 533 if (wakeup) { 534 if (handle->aux_flags & PERF_AUX_FLAG_TRUNCATED) 535 perf_event_disable_inatomic(handle->event); 536 perf_output_wakeup(handle); 537 } 538 539 handle->event = NULL; 540 541 WRITE_ONCE(rb->aux_nest, 0); 542 /* can't be last */ 543 rb_free_aux(rb); 544 ring_buffer_put(rb); 545 } 546 EXPORT_SYMBOL_GPL(perf_aux_output_end); 547 548 /* 549 * Skip over a given number of bytes in the AUX buffer, due to, for example, 550 * hardware's alignment constraints. 551 */ 552 int perf_aux_output_skip(struct perf_output_handle *handle, unsigned long size) 553 { 554 struct perf_buffer *rb = handle->rb; 555 556 if (size > handle->size) 557 return -ENOSPC; 558 559 rb->aux_head += size; 560 561 WRITE_ONCE(rb->user_page->aux_head, rb->aux_head); 562 if (rb_need_aux_wakeup(rb)) { 563 perf_output_wakeup(handle); 564 handle->wakeup = rb->aux_wakeup + rb->aux_watermark; 565 } 566 567 handle->head = rb->aux_head; 568 handle->size -= size; 569 570 return 0; 571 } 572 EXPORT_SYMBOL_GPL(perf_aux_output_skip); 573 574 void *perf_get_aux(struct perf_output_handle *handle) 575 { 576 /* this is only valid between perf_aux_output_begin and *_end */ 577 if (!handle->event) 578 return NULL; 579 580 return handle->rb->aux_priv; 581 } 582 EXPORT_SYMBOL_GPL(perf_get_aux); 583 584 /* 585 * Copy out AUX data from an AUX handle. 586 */ 587 long perf_output_copy_aux(struct perf_output_handle *aux_handle, 588 struct perf_output_handle *handle, 589 unsigned long from, unsigned long to) 590 { 591 struct perf_buffer *rb = aux_handle->rb; 592 unsigned long tocopy, remainder, len = 0; 593 void *addr; 594 595 from &= (rb->aux_nr_pages << PAGE_SHIFT) - 1; 596 to &= (rb->aux_nr_pages << PAGE_SHIFT) - 1; 597 598 do { 599 tocopy = PAGE_SIZE - offset_in_page(from); 600 if (to > from) 601 tocopy = min(tocopy, to - from); 602 if (!tocopy) 603 break; 604 605 addr = rb->aux_pages[from >> PAGE_SHIFT]; 606 addr += offset_in_page(from); 607 608 remainder = perf_output_copy(handle, addr, tocopy); 609 if (remainder) 610 return -EFAULT; 611 612 len += tocopy; 613 from += tocopy; 614 from &= (rb->aux_nr_pages << PAGE_SHIFT) - 1; 615 } while (to != from); 616 617 return len; 618 } 619 620 #define PERF_AUX_GFP (GFP_KERNEL | __GFP_ZERO | __GFP_NOWARN | __GFP_NORETRY) 621 622 static struct page *rb_alloc_aux_page(int node, int order) 623 { 624 struct page *page; 625 626 if (order > MAX_PAGE_ORDER) 627 order = MAX_PAGE_ORDER; 628 629 do { 630 page = alloc_pages_node(node, PERF_AUX_GFP, order); 631 } while (!page && order--); 632 633 if (page && order) { 634 /* 635 * Communicate the allocation size to the driver: 636 * if we managed to secure a high-order allocation, 637 * set its first page's private to this order; 638 * !PagePrivate(page) means it's just a normal page. 639 */ 640 split_page(page, order); 641 SetPagePrivate(page); 642 set_page_private(page, order); 643 } 644 645 return page; 646 } 647 648 static void rb_free_aux_page(struct perf_buffer *rb, int idx) 649 { 650 struct page *page = virt_to_page(rb->aux_pages[idx]); 651 652 ClearPagePrivate(page); 653 __free_page(page); 654 } 655 656 static void __rb_free_aux(struct perf_buffer *rb) 657 { 658 int pg; 659 660 /* 661 * Should never happen, the last reference should be dropped from 662 * perf_mmap_close() path, which first stops aux transactions (which 663 * in turn are the atomic holders of aux_refcount) and then does the 664 * last rb_free_aux(). 665 */ 666 WARN_ON_ONCE(in_atomic()); 667 668 if (rb->aux_priv) { 669 rb->free_aux(rb->aux_priv); 670 rb->free_aux = NULL; 671 rb->aux_priv = NULL; 672 } 673 674 if (rb->aux_nr_pages) { 675 for (pg = 0; pg < rb->aux_nr_pages; pg++) 676 rb_free_aux_page(rb, pg); 677 678 kfree(rb->aux_pages); 679 rb->aux_nr_pages = 0; 680 } 681 } 682 683 int rb_alloc_aux(struct perf_buffer *rb, struct perf_event *event, 684 pgoff_t pgoff, int nr_pages, long watermark, int flags) 685 { 686 bool overwrite = !(flags & RING_BUFFER_WRITABLE); 687 int node = (event->cpu == -1) ? -1 : cpu_to_node(event->cpu); 688 bool use_contiguous_pages = event->pmu->capabilities & ( 689 PERF_PMU_CAP_AUX_NO_SG | PERF_PMU_CAP_AUX_PREFER_LARGE); 690 /* 691 * Initialize max_order to 0 for page allocation. This allocates single 692 * pages to minimize memory fragmentation. This is overridden if the 693 * PMU needs or prefers contiguous pages (use_contiguous_pages = true). 694 */ 695 int max_order = 0; 696 int ret = -ENOMEM; 697 698 if (!has_aux(event)) 699 return -EOPNOTSUPP; 700 701 if (nr_pages <= 0) 702 return -EINVAL; 703 704 if (!overwrite) { 705 /* 706 * Watermark defaults to half the buffer, to aid PMU drivers 707 * in double buffering. 708 */ 709 if (!watermark) 710 watermark = min_t(unsigned long, 711 U32_MAX, 712 (unsigned long)nr_pages << (PAGE_SHIFT - 1)); 713 714 /* 715 * If using contiguous pages, use aux_watermark as the basis 716 * for chunking to help PMU drivers honor the watermark. 717 */ 718 if (use_contiguous_pages) 719 max_order = get_order(watermark); 720 } else { 721 /* 722 * If using contiguous pages, we need to start with the 723 * max_order that fits in nr_pages, not the other way around, 724 * hence ilog2() and not get_order. 725 */ 726 if (use_contiguous_pages) 727 max_order = ilog2(nr_pages); 728 watermark = 0; 729 } 730 731 /* 732 * kcalloc_node() is unable to allocate buffer if the size is larger 733 * than: PAGE_SIZE << MAX_PAGE_ORDER; directly bail out in this case. 734 */ 735 if (get_order((unsigned long)nr_pages * sizeof(void *)) > MAX_PAGE_ORDER) 736 return -ENOMEM; 737 rb->aux_pages = kcalloc_node(nr_pages, sizeof(void *), GFP_KERNEL, 738 node); 739 if (!rb->aux_pages) 740 return -ENOMEM; 741 742 rb->free_aux = event->pmu->free_aux; 743 for (rb->aux_nr_pages = 0; rb->aux_nr_pages < nr_pages;) { 744 struct page *page; 745 int last, order; 746 747 order = min(max_order, ilog2(nr_pages - rb->aux_nr_pages)); 748 page = rb_alloc_aux_page(node, order); 749 if (!page) 750 goto out; 751 752 for (last = rb->aux_nr_pages + (1 << page_private(page)); 753 last > rb->aux_nr_pages; rb->aux_nr_pages++) 754 rb->aux_pages[rb->aux_nr_pages] = page_address(page++); 755 } 756 757 /* 758 * In overwrite mode, PMUs that don't support SG may not handle more 759 * than one contiguous allocation, since they rely on PMI to do double 760 * buffering. In this case, the entire buffer has to be one contiguous 761 * chunk. 762 */ 763 if ((event->pmu->capabilities & PERF_PMU_CAP_AUX_NO_SG) && 764 overwrite) { 765 struct page *page = virt_to_page(rb->aux_pages[0]); 766 767 if (page_private(page) != max_order) 768 goto out; 769 } 770 771 rb->aux_priv = event->pmu->setup_aux(event, rb->aux_pages, nr_pages, 772 overwrite); 773 if (!rb->aux_priv) 774 goto out; 775 776 ret = 0; 777 778 /* 779 * aux_pages (and pmu driver's private data, aux_priv) will be 780 * referenced in both producer's and consumer's contexts, thus 781 * we keep a refcount here to make sure either of the two can 782 * reference them safely. 783 */ 784 refcount_set(&rb->aux_refcount, 1); 785 786 rb->aux_overwrite = overwrite; 787 rb->aux_watermark = watermark; 788 789 out: 790 if (!ret) 791 rb->aux_pgoff = pgoff; 792 else 793 __rb_free_aux(rb); 794 795 return ret; 796 } 797 798 void rb_free_aux(struct perf_buffer *rb) 799 { 800 if (refcount_dec_and_test(&rb->aux_refcount)) 801 __rb_free_aux(rb); 802 } 803 804 #ifndef CONFIG_PERF_USE_VMALLOC 805 806 /* 807 * Back perf_mmap() with regular GFP_KERNEL-0 pages. 808 */ 809 810 static struct page * 811 __perf_mmap_to_page(struct perf_buffer *rb, unsigned long pgoff) 812 { 813 if (pgoff > rb->nr_pages) 814 return NULL; 815 816 if (pgoff == 0) 817 return virt_to_page(rb->user_page); 818 819 return virt_to_page(rb->data_pages[pgoff - 1]); 820 } 821 822 static void *perf_mmap_alloc_page(int cpu) 823 { 824 struct page *page; 825 int node; 826 827 node = (cpu == -1) ? cpu : cpu_to_node(cpu); 828 page = alloc_pages_node(node, GFP_KERNEL | __GFP_ZERO, 0); 829 if (!page) 830 return NULL; 831 832 return page_address(page); 833 } 834 835 static void perf_mmap_free_page(void *addr) 836 { 837 struct page *page = virt_to_page(addr); 838 839 __free_page(page); 840 } 841 842 struct perf_buffer *rb_alloc(int nr_pages, long watermark, int cpu, int flags) 843 { 844 struct perf_buffer *rb; 845 unsigned long size; 846 int i, node; 847 848 size = sizeof(struct perf_buffer); 849 size += nr_pages * sizeof(void *); 850 851 if (order_base_2(size) > PAGE_SHIFT+MAX_PAGE_ORDER) 852 goto fail; 853 854 node = (cpu == -1) ? cpu : cpu_to_node(cpu); 855 rb = kzalloc_node(size, GFP_KERNEL, node); 856 if (!rb) 857 goto fail; 858 859 rb->user_page = perf_mmap_alloc_page(cpu); 860 if (!rb->user_page) 861 goto fail_user_page; 862 863 for (i = 0; i < nr_pages; i++) { 864 rb->data_pages[i] = perf_mmap_alloc_page(cpu); 865 if (!rb->data_pages[i]) 866 goto fail_data_pages; 867 } 868 869 rb->nr_pages = nr_pages; 870 871 ring_buffer_init(rb, watermark, flags); 872 873 return rb; 874 875 fail_data_pages: 876 for (i--; i >= 0; i--) 877 perf_mmap_free_page(rb->data_pages[i]); 878 879 perf_mmap_free_page(rb->user_page); 880 881 fail_user_page: 882 kfree(rb); 883 884 fail: 885 return NULL; 886 } 887 888 void rb_free(struct perf_buffer *rb) 889 { 890 int i; 891 892 perf_mmap_free_page(rb->user_page); 893 for (i = 0; i < rb->nr_pages; i++) 894 perf_mmap_free_page(rb->data_pages[i]); 895 kfree(rb); 896 } 897 898 #else 899 static struct page * 900 __perf_mmap_to_page(struct perf_buffer *rb, unsigned long pgoff) 901 { 902 /* The '>' counts in the user page. */ 903 if (pgoff > data_page_nr(rb)) 904 return NULL; 905 906 return vmalloc_to_page((void *)rb->user_page + pgoff * PAGE_SIZE); 907 } 908 909 static void rb_free_work(struct work_struct *work) 910 { 911 struct perf_buffer *rb; 912 913 rb = container_of(work, struct perf_buffer, work); 914 915 vfree(rb->user_page); 916 kfree(rb); 917 } 918 919 void rb_free(struct perf_buffer *rb) 920 { 921 schedule_work(&rb->work); 922 } 923 924 struct perf_buffer *rb_alloc(int nr_pages, long watermark, int cpu, int flags) 925 { 926 struct perf_buffer *rb; 927 unsigned long size; 928 void *all_buf; 929 int node; 930 931 size = sizeof(struct perf_buffer); 932 size += sizeof(void *); 933 934 node = (cpu == -1) ? cpu : cpu_to_node(cpu); 935 rb = kzalloc_node(size, GFP_KERNEL, node); 936 if (!rb) 937 goto fail; 938 939 INIT_WORK(&rb->work, rb_free_work); 940 941 all_buf = vmalloc_user((nr_pages + 1) * PAGE_SIZE); 942 if (!all_buf) 943 goto fail_all_buf; 944 945 rb->user_page = all_buf; 946 rb->data_pages[0] = all_buf + PAGE_SIZE; 947 if (nr_pages) { 948 rb->nr_pages = 1; 949 rb->page_order = ilog2(nr_pages); 950 } 951 952 ring_buffer_init(rb, watermark, flags); 953 954 return rb; 955 956 fail_all_buf: 957 kfree(rb); 958 959 fail: 960 return NULL; 961 } 962 963 #endif 964 965 struct page * 966 perf_mmap_to_page(struct perf_buffer *rb, unsigned long pgoff) 967 { 968 if (rb->aux_nr_pages) { 969 /* above AUX space */ 970 if (pgoff > rb->aux_pgoff + rb->aux_nr_pages) 971 return NULL; 972 973 /* AUX space */ 974 if (pgoff >= rb->aux_pgoff) { 975 int aux_pgoff = array_index_nospec(pgoff - rb->aux_pgoff, rb->aux_nr_pages); 976 return virt_to_page(rb->aux_pages[aux_pgoff]); 977 } 978 } 979 980 return __perf_mmap_to_page(rb, pgoff); 981 } 982