1 /* SPDX-License-Identifier: GPL-2.0-only */ 2 /* 3 * Copyright (C) 2012,2013 - ARM Ltd 4 * Author: Marc Zyngier <marc.zyngier@arm.com> 5 */ 6 7 #ifndef __ARM_KVM_ASM_H__ 8 #define __ARM_KVM_ASM_H__ 9 10 #include <asm/hyp_image.h> 11 #include <asm/insn.h> 12 #include <asm/virt.h> 13 #include <asm/sysreg.h> 14 15 #define ARM_EXIT_WITH_SERROR_BIT 31 16 #define ARM_EXCEPTION_CODE(x) ((x) & ~(1U << ARM_EXIT_WITH_SERROR_BIT)) 17 #define ARM_EXCEPTION_IS_TRAP(x) (ARM_EXCEPTION_CODE((x)) == ARM_EXCEPTION_TRAP) 18 #define ARM_SERROR_PENDING(x) !!((x) & (1U << ARM_EXIT_WITH_SERROR_BIT)) 19 20 #define ARM_EXCEPTION_IRQ 0 21 #define ARM_EXCEPTION_EL1_SERROR 1 22 #define ARM_EXCEPTION_TRAP 2 23 #define ARM_EXCEPTION_IL 3 24 /* The hyp-stub will return this for any kvm_call_hyp() call */ 25 #define ARM_EXCEPTION_HYP_GONE HVC_STUB_ERR 26 27 #define kvm_arm_exception_type \ 28 {ARM_EXCEPTION_IRQ, "IRQ" }, \ 29 {ARM_EXCEPTION_EL1_SERROR, "SERROR" }, \ 30 {ARM_EXCEPTION_TRAP, "TRAP" }, \ 31 {ARM_EXCEPTION_HYP_GONE, "HYP_GONE" } 32 33 /* 34 * Size of the HYP vectors preamble. kvm_patch_vector_branch() generates code 35 * that jumps over this. 36 */ 37 #define KVM_VECTOR_PREAMBLE (2 * AARCH64_INSN_SIZE) 38 39 #define KVM_HOST_SMCCC_ID(id) \ 40 ARM_SMCCC_CALL_VAL(ARM_SMCCC_FAST_CALL, \ 41 ARM_SMCCC_SMC_64, \ 42 ARM_SMCCC_OWNER_VENDOR_HYP, \ 43 (id)) 44 45 #define KVM_HOST_SMCCC_FUNC(name) KVM_HOST_SMCCC_ID(__KVM_HOST_SMCCC_FUNC_##name) 46 47 #define __KVM_HOST_SMCCC_FUNC___kvm_hyp_init 0 48 49 #ifndef __ASSEMBLER__ 50 51 #include <linux/mm.h> 52 53 enum __kvm_host_smccc_func { 54 /* Hypercalls that are unavailable once pKVM has finalised. */ 55 /* __KVM_HOST_SMCCC_FUNC___kvm_hyp_init */ 56 __KVM_HOST_SMCCC_FUNC___pkvm_init = __KVM_HOST_SMCCC_FUNC___kvm_hyp_init + 1, 57 __KVM_HOST_SMCCC_FUNC___pkvm_create_private_mapping, 58 __KVM_HOST_SMCCC_FUNC___pkvm_cpu_set_vector, 59 __KVM_HOST_SMCCC_FUNC___kvm_enable_ssbs, 60 __KVM_HOST_SMCCC_FUNC___vgic_v3_init_lrs, 61 __KVM_HOST_SMCCC_FUNC___vgic_v3_get_gic_config, 62 __KVM_HOST_SMCCC_FUNC___pkvm_prot_finalize, 63 __KVM_HOST_SMCCC_FUNC_MIN_PKVM = __KVM_HOST_SMCCC_FUNC___pkvm_prot_finalize, 64 65 /* Hypercalls that are always available and common to [nh]VHE/pKVM. */ 66 __KVM_HOST_SMCCC_FUNC___kvm_adjust_pc, 67 __KVM_HOST_SMCCC_FUNC___kvm_vcpu_run, 68 __KVM_HOST_SMCCC_FUNC___kvm_flush_vm_context, 69 __KVM_HOST_SMCCC_FUNC___kvm_tlb_flush_vmid_ipa, 70 __KVM_HOST_SMCCC_FUNC___kvm_tlb_flush_vmid_ipa_nsh, 71 __KVM_HOST_SMCCC_FUNC___kvm_tlb_flush_vmid, 72 __KVM_HOST_SMCCC_FUNC___kvm_tlb_flush_vmid_range, 73 __KVM_HOST_SMCCC_FUNC___kvm_flush_cpu_context, 74 __KVM_HOST_SMCCC_FUNC___kvm_timer_set_cntvoff, 75 __KVM_HOST_SMCCC_FUNC___vgic_v3_save_aprs, 76 __KVM_HOST_SMCCC_FUNC___vgic_v3_restore_vmcr_aprs, 77 __KVM_HOST_SMCCC_FUNC_MAX_NO_PKVM = __KVM_HOST_SMCCC_FUNC___vgic_v3_restore_vmcr_aprs, 78 79 /* Hypercalls that are available only when pKVM has finalised. */ 80 __KVM_HOST_SMCCC_FUNC___pkvm_host_share_hyp, 81 __KVM_HOST_SMCCC_FUNC___pkvm_host_unshare_hyp, 82 __KVM_HOST_SMCCC_FUNC___pkvm_host_donate_guest, 83 __KVM_HOST_SMCCC_FUNC___pkvm_host_share_guest, 84 __KVM_HOST_SMCCC_FUNC___pkvm_host_unshare_guest, 85 __KVM_HOST_SMCCC_FUNC___pkvm_host_relax_perms_guest, 86 __KVM_HOST_SMCCC_FUNC___pkvm_host_wrprotect_guest, 87 __KVM_HOST_SMCCC_FUNC___pkvm_host_test_clear_young_guest, 88 __KVM_HOST_SMCCC_FUNC___pkvm_host_mkyoung_guest, 89 __KVM_HOST_SMCCC_FUNC___pkvm_reserve_vm, 90 __KVM_HOST_SMCCC_FUNC___pkvm_unreserve_vm, 91 __KVM_HOST_SMCCC_FUNC___pkvm_init_vm, 92 __KVM_HOST_SMCCC_FUNC___pkvm_init_vcpu, 93 __KVM_HOST_SMCCC_FUNC___pkvm_start_teardown_vm, 94 __KVM_HOST_SMCCC_FUNC___pkvm_finalize_teardown_vm, 95 __KVM_HOST_SMCCC_FUNC___pkvm_vcpu_load, 96 __KVM_HOST_SMCCC_FUNC___pkvm_vcpu_put, 97 __KVM_HOST_SMCCC_FUNC___pkvm_tlb_flush_vmid, 98 }; 99 100 #define DECLARE_KVM_VHE_SYM(sym) extern char sym[] 101 #define DECLARE_KVM_NVHE_SYM(sym) extern char kvm_nvhe_sym(sym)[] 102 103 /* 104 * Define a pair of symbols sharing the same name but one defined in 105 * VHE and the other in nVHE hyp implementations. 106 */ 107 #define DECLARE_KVM_HYP_SYM(sym) \ 108 DECLARE_KVM_VHE_SYM(sym); \ 109 DECLARE_KVM_NVHE_SYM(sym) 110 111 #define DECLARE_KVM_VHE_PER_CPU(type, sym) \ 112 DECLARE_PER_CPU(type, sym) 113 #define DECLARE_KVM_NVHE_PER_CPU(type, sym) \ 114 DECLARE_PER_CPU(type, kvm_nvhe_sym(sym)) 115 116 #define DECLARE_KVM_HYP_PER_CPU(type, sym) \ 117 DECLARE_KVM_VHE_PER_CPU(type, sym); \ 118 DECLARE_KVM_NVHE_PER_CPU(type, sym) 119 120 /* 121 * Compute pointer to a symbol defined in nVHE percpu region. 122 * Returns NULL if percpu memory has not been allocated yet. 123 */ 124 #define this_cpu_ptr_nvhe_sym(sym) per_cpu_ptr_nvhe_sym(sym, smp_processor_id()) 125 #define per_cpu_ptr_nvhe_sym(sym, cpu) \ 126 ({ \ 127 unsigned long base, off; \ 128 base = kvm_nvhe_sym(kvm_arm_hyp_percpu_base)[cpu]; \ 129 off = (unsigned long)&CHOOSE_NVHE_SYM(sym) - \ 130 (unsigned long)&CHOOSE_NVHE_SYM(__per_cpu_start); \ 131 base ? (typeof(CHOOSE_NVHE_SYM(sym))*)(base + off) : NULL; \ 132 }) 133 134 #if defined(__KVM_NVHE_HYPERVISOR__) 135 136 #define CHOOSE_NVHE_SYM(sym) sym 137 #define CHOOSE_HYP_SYM(sym) CHOOSE_NVHE_SYM(sym) 138 139 /* The nVHE hypervisor shouldn't even try to access VHE symbols */ 140 extern void *__nvhe_undefined_symbol; 141 #define CHOOSE_VHE_SYM(sym) __nvhe_undefined_symbol 142 #define this_cpu_ptr_hyp_sym(sym) (&__nvhe_undefined_symbol) 143 #define per_cpu_ptr_hyp_sym(sym, cpu) (&__nvhe_undefined_symbol) 144 145 #elif defined(__KVM_VHE_HYPERVISOR__) 146 147 #define CHOOSE_VHE_SYM(sym) sym 148 #define CHOOSE_HYP_SYM(sym) CHOOSE_VHE_SYM(sym) 149 150 /* The VHE hypervisor shouldn't even try to access nVHE symbols */ 151 extern void *__vhe_undefined_symbol; 152 #define CHOOSE_NVHE_SYM(sym) __vhe_undefined_symbol 153 #define this_cpu_ptr_hyp_sym(sym) (&__vhe_undefined_symbol) 154 #define per_cpu_ptr_hyp_sym(sym, cpu) (&__vhe_undefined_symbol) 155 156 #else 157 158 /* 159 * BIG FAT WARNINGS: 160 * 161 * - Don't be tempted to change the following is_kernel_in_hyp_mode() 162 * to has_vhe(). has_vhe() is implemented as a *final* capability, 163 * while this is used early at boot time, when the capabilities are 164 * not final yet.... 165 * 166 * - Don't let the nVHE hypervisor have access to this, as it will 167 * pick the *wrong* symbol (yes, it runs at EL2...). 168 */ 169 #define CHOOSE_HYP_SYM(sym) (is_kernel_in_hyp_mode() \ 170 ? CHOOSE_VHE_SYM(sym) \ 171 : CHOOSE_NVHE_SYM(sym)) 172 173 #define this_cpu_ptr_hyp_sym(sym) (is_kernel_in_hyp_mode() \ 174 ? this_cpu_ptr(&sym) \ 175 : this_cpu_ptr_nvhe_sym(sym)) 176 177 #define per_cpu_ptr_hyp_sym(sym, cpu) (is_kernel_in_hyp_mode() \ 178 ? per_cpu_ptr(&sym, cpu) \ 179 : per_cpu_ptr_nvhe_sym(sym, cpu)) 180 181 #define CHOOSE_VHE_SYM(sym) sym 182 #define CHOOSE_NVHE_SYM(sym) kvm_nvhe_sym(sym) 183 184 #endif 185 186 struct kvm_nvhe_init_params { 187 unsigned long mair_el2; 188 unsigned long tcr_el2; 189 unsigned long tpidr_el2; 190 unsigned long stack_hyp_va; 191 unsigned long stack_pa; 192 phys_addr_t pgd_pa; 193 unsigned long hcr_el2; 194 unsigned long vttbr; 195 unsigned long vtcr; 196 unsigned long tmp; 197 }; 198 199 /* 200 * Used by the host in EL1 to dump the nVHE hypervisor backtrace on 201 * hyp_panic() in non-protected mode. 202 * 203 * @stack_base: hyp VA of the hyp_stack base. 204 * @overflow_stack_base: hyp VA of the hyp_overflow_stack base. 205 * @fp: hyp FP where the backtrace begins. 206 * @pc: hyp PC where the backtrace begins. 207 */ 208 struct kvm_nvhe_stacktrace_info { 209 unsigned long stack_base; 210 unsigned long overflow_stack_base; 211 unsigned long fp; 212 unsigned long pc; 213 }; 214 215 /* Translate a kernel address @ptr into its equivalent linear mapping */ 216 #define kvm_ksym_ref(ptr) \ 217 ({ \ 218 void *val = (ptr); \ 219 if (!is_kernel_in_hyp_mode()) \ 220 val = lm_alias((ptr)); \ 221 val; \ 222 }) 223 #define kvm_ksym_ref_nvhe(sym) kvm_ksym_ref(kvm_nvhe_sym(sym)) 224 225 struct kvm; 226 struct kvm_vcpu; 227 struct kvm_s2_mmu; 228 229 DECLARE_KVM_NVHE_SYM(__kvm_hyp_init); 230 DECLARE_KVM_HYP_SYM(__kvm_hyp_vector); 231 #define __kvm_hyp_init CHOOSE_NVHE_SYM(__kvm_hyp_init) 232 #define __kvm_hyp_vector CHOOSE_HYP_SYM(__kvm_hyp_vector) 233 234 extern unsigned long kvm_nvhe_sym(kvm_arm_hyp_percpu_base)[]; 235 DECLARE_KVM_NVHE_SYM(__per_cpu_start); 236 DECLARE_KVM_NVHE_SYM(__per_cpu_end); 237 238 DECLARE_KVM_HYP_SYM(__bp_harden_hyp_vecs); 239 #define __bp_harden_hyp_vecs CHOOSE_HYP_SYM(__bp_harden_hyp_vecs) 240 241 extern void __kvm_flush_vm_context(void); 242 extern void __kvm_flush_cpu_context(struct kvm_s2_mmu *mmu); 243 extern void __kvm_tlb_flush_vmid_ipa(struct kvm_s2_mmu *mmu, phys_addr_t ipa, 244 int level); 245 extern void __kvm_tlb_flush_vmid_ipa_nsh(struct kvm_s2_mmu *mmu, 246 phys_addr_t ipa, 247 int level); 248 extern void __kvm_tlb_flush_vmid_range(struct kvm_s2_mmu *mmu, 249 phys_addr_t start, unsigned long pages); 250 extern void __kvm_tlb_flush_vmid(struct kvm_s2_mmu *mmu); 251 252 extern int __kvm_tlbi_s1e2(struct kvm_s2_mmu *mmu, u64 va, u64 sys_encoding); 253 254 extern void __kvm_timer_set_cntvoff(u64 cntvoff); 255 extern int __kvm_at_s1e01(struct kvm_vcpu *vcpu, u32 op, u64 vaddr); 256 extern int __kvm_at_s1e2(struct kvm_vcpu *vcpu, u32 op, u64 vaddr); 257 extern int __kvm_at_s12(struct kvm_vcpu *vcpu, u32 op, u64 vaddr); 258 259 extern int __kvm_vcpu_run(struct kvm_vcpu *vcpu); 260 261 extern void __kvm_adjust_pc(struct kvm_vcpu *vcpu); 262 263 extern u64 __vgic_v3_get_gic_config(void); 264 extern void __vgic_v3_init_lrs(void); 265 266 #define __KVM_EXTABLE(from, to) \ 267 " .pushsection __kvm_ex_table, \"a\"\n" \ 268 " .align 3\n" \ 269 " .long (" #from " - .), (" #to " - .)\n" \ 270 " .popsection\n" 271 272 273 #define __kvm_at(at_op, addr) \ 274 ( { \ 275 int __kvm_at_err = 0; \ 276 u64 spsr, elr; \ 277 asm volatile( \ 278 " mrs %1, spsr_el2\n" \ 279 " mrs %2, elr_el2\n" \ 280 "1: " __msr_s(at_op, "%3") "\n" \ 281 " isb\n" \ 282 " b 9f\n" \ 283 "2: msr spsr_el2, %1\n" \ 284 " msr elr_el2, %2\n" \ 285 " mov %w0, %4\n" \ 286 "9:\n" \ 287 __KVM_EXTABLE(1b, 2b) \ 288 : "+r" (__kvm_at_err), "=&r" (spsr), "=&r" (elr) \ 289 : "r" (addr), "i" (-EFAULT)); \ 290 __kvm_at_err; \ 291 } ) 292 293 void __noreturn hyp_panic(void); 294 asmlinkage void kvm_unexpected_el2_exception(void); 295 asmlinkage void __noreturn hyp_panic(void); 296 asmlinkage void __noreturn hyp_panic_bad_stack(void); 297 asmlinkage void kvm_unexpected_el2_exception(void); 298 struct kvm_cpu_context; 299 void handle_trap(struct kvm_cpu_context *host_ctxt); 300 asmlinkage void __noreturn __kvm_host_psci_cpu_entry(bool is_cpu_on); 301 void __noreturn __pkvm_init_finalise(void); 302 void kvm_nvhe_prepare_backtrace(unsigned long fp, unsigned long pc); 303 void kvm_patch_vector_branch(struct alt_instr *alt, 304 __le32 *origptr, __le32 *updptr, int nr_inst); 305 void kvm_get_kimage_voffset(struct alt_instr *alt, 306 __le32 *origptr, __le32 *updptr, int nr_inst); 307 void kvm_compute_final_ctr_el0(struct alt_instr *alt, 308 __le32 *origptr, __le32 *updptr, int nr_inst); 309 void __noreturn __cold nvhe_hyp_panic_handler(u64 esr, u64 spsr, u64 elr_virt, 310 u64 elr_phys, u64 par, uintptr_t vcpu, u64 far, u64 hpfar); 311 312 #else /* __ASSEMBLER__ */ 313 314 .macro get_host_ctxt reg, tmp 315 adr_this_cpu \reg, kvm_host_data, \tmp 316 add \reg, \reg, #HOST_DATA_CONTEXT 317 .endm 318 319 .macro get_vcpu_ptr vcpu, ctxt 320 get_host_ctxt \ctxt, \vcpu 321 ldr \vcpu, [\ctxt, #HOST_CONTEXT_VCPU] 322 .endm 323 324 .macro get_loaded_vcpu vcpu, ctxt 325 adr_this_cpu \ctxt, kvm_hyp_ctxt, \vcpu 326 ldr \vcpu, [\ctxt, #HOST_CONTEXT_VCPU] 327 .endm 328 329 .macro set_loaded_vcpu vcpu, ctxt, tmp 330 adr_this_cpu \ctxt, kvm_hyp_ctxt, \tmp 331 str \vcpu, [\ctxt, #HOST_CONTEXT_VCPU] 332 .endm 333 334 /* 335 * KVM extable for unexpected exceptions. 336 * Create a struct kvm_exception_table_entry output to a section that can be 337 * mapped by EL2. The table is not sorted. 338 * 339 * The caller must ensure: 340 * x18 has the hypervisor value to allow any Shadow-Call-Stack instrumented 341 * code to write to it, and that SPSR_EL2 and ELR_EL2 are restored by the fixup. 342 */ 343 .macro _kvm_extable, from, to 344 .pushsection __kvm_ex_table, "a" 345 .align 3 346 .long (\from - .), (\to - .) 347 .popsection 348 .endm 349 350 #define CPU_XREG_OFFSET(x) (CPU_USER_PT_REGS + 8*x) 351 #define CPU_LR_OFFSET CPU_XREG_OFFSET(30) 352 #define CPU_SP_EL0_OFFSET (CPU_LR_OFFSET + 8) 353 354 /* 355 * We treat x18 as callee-saved as the host may use it as a platform 356 * register (e.g. for shadow call stack). 357 */ 358 .macro save_callee_saved_regs ctxt 359 str x18, [\ctxt, #CPU_XREG_OFFSET(18)] 360 stp x19, x20, [\ctxt, #CPU_XREG_OFFSET(19)] 361 stp x21, x22, [\ctxt, #CPU_XREG_OFFSET(21)] 362 stp x23, x24, [\ctxt, #CPU_XREG_OFFSET(23)] 363 stp x25, x26, [\ctxt, #CPU_XREG_OFFSET(25)] 364 stp x27, x28, [\ctxt, #CPU_XREG_OFFSET(27)] 365 stp x29, lr, [\ctxt, #CPU_XREG_OFFSET(29)] 366 .endm 367 368 .macro restore_callee_saved_regs ctxt 369 // We require \ctxt is not x18-x28 370 ldr x18, [\ctxt, #CPU_XREG_OFFSET(18)] 371 ldp x19, x20, [\ctxt, #CPU_XREG_OFFSET(19)] 372 ldp x21, x22, [\ctxt, #CPU_XREG_OFFSET(21)] 373 ldp x23, x24, [\ctxt, #CPU_XREG_OFFSET(23)] 374 ldp x25, x26, [\ctxt, #CPU_XREG_OFFSET(25)] 375 ldp x27, x28, [\ctxt, #CPU_XREG_OFFSET(27)] 376 ldp x29, lr, [\ctxt, #CPU_XREG_OFFSET(29)] 377 .endm 378 379 .macro save_sp_el0 ctxt, tmp 380 mrs \tmp, sp_el0 381 str \tmp, [\ctxt, #CPU_SP_EL0_OFFSET] 382 .endm 383 384 .macro restore_sp_el0 ctxt, tmp 385 ldr \tmp, [\ctxt, #CPU_SP_EL0_OFFSET] 386 msr sp_el0, \tmp 387 .endm 388 389 #endif 390 391 #endif /* __ARM_KVM_ASM_H__ */ 392