1 // SPDX-License-Identifier: GPL-2.0 2 #include <linux/mm.h> 3 #include <linux/rmap.h> 4 #include <linux/hugetlb.h> 5 #include <linux/swap.h> 6 #include <linux/leafops.h> 7 8 #include "internal.h" 9 10 static inline bool not_found(struct page_vma_mapped_walk *pvmw) 11 { 12 page_vma_mapped_walk_done(pvmw); 13 return false; 14 } 15 16 static bool map_pte(struct page_vma_mapped_walk *pvmw, pmd_t *pmdvalp, 17 spinlock_t **ptlp) 18 { 19 bool is_migration; 20 pte_t ptent; 21 22 if (pvmw->flags & PVMW_SYNC) { 23 /* Use the stricter lookup */ 24 pvmw->pte = pte_offset_map_lock(pvmw->vma->vm_mm, pvmw->pmd, 25 pvmw->address, &pvmw->ptl); 26 *ptlp = pvmw->ptl; 27 return !!pvmw->pte; 28 } 29 30 is_migration = pvmw->flags & PVMW_MIGRATION; 31 again: 32 /* 33 * It is important to return the ptl corresponding to pte, 34 * in case *pvmw->pmd changes underneath us; so we need to 35 * return it even when choosing not to lock, in case caller 36 * proceeds to loop over next ptes, and finds a match later. 37 * Though, in most cases, page lock already protects this. 38 */ 39 pvmw->pte = pte_offset_map_rw_nolock(pvmw->vma->vm_mm, pvmw->pmd, 40 pvmw->address, pmdvalp, ptlp); 41 if (!pvmw->pte) 42 return false; 43 44 ptent = ptep_get_lockless(pvmw->pte); 45 46 if (pte_none(ptent)) { 47 return false; 48 } else if (pte_present(ptent)) { 49 if (is_migration) 50 return false; 51 } else if (!is_migration) { 52 softleaf_t entry; 53 54 /* 55 * Handle un-addressable ZONE_DEVICE memory. 56 * 57 * We get here when we are trying to unmap a private 58 * device page from the process address space. Such 59 * page is not CPU accessible and thus is mapped as 60 * a special swap entry, nonetheless it still does 61 * count as a valid regular mapping for the page 62 * (and is accounted as such in page maps count). 63 * 64 * So handle this special case as if it was a normal 65 * page mapping ie lock CPU page table and return true. 66 * 67 * For more details on device private memory see HMM 68 * (include/linux/hmm.h or mm/hmm.c). 69 */ 70 entry = softleaf_from_pte(ptent); 71 if (!softleaf_is_device_private(entry) && 72 !softleaf_is_device_exclusive(entry)) 73 return false; 74 } 75 spin_lock(*ptlp); 76 if (unlikely(!pmd_same(*pmdvalp, pmdp_get_lockless(pvmw->pmd)))) { 77 pte_unmap_unlock(pvmw->pte, *ptlp); 78 goto again; 79 } 80 pvmw->ptl = *ptlp; 81 82 return true; 83 } 84 85 /** 86 * check_pte - check if [pvmw->pfn, @pvmw->pfn + @pvmw->nr_pages) is 87 * mapped at the @pvmw->pte 88 * @pvmw: page_vma_mapped_walk struct, includes a pair pte and pfn range 89 * for checking 90 * @pte_nr: the number of small pages described by @pvmw->pte. 91 * 92 * page_vma_mapped_walk() found a place where pfn range is *potentially* 93 * mapped. check_pte() has to validate this. 94 * 95 * pvmw->pte may point to empty PTE, swap PTE or PTE pointing to 96 * arbitrary page. 97 * 98 * If PVMW_MIGRATION flag is set, returns true if @pvmw->pte contains migration 99 * entry that points to [pvmw->pfn, @pvmw->pfn + @pvmw->nr_pages) 100 * 101 * If PVMW_MIGRATION flag is not set, returns true if pvmw->pte points to 102 * [pvmw->pfn, @pvmw->pfn + @pvmw->nr_pages) 103 * 104 * Otherwise, return false. 105 * 106 */ 107 static bool check_pte(struct page_vma_mapped_walk *pvmw, unsigned long pte_nr) 108 { 109 unsigned long pfn; 110 pte_t ptent; 111 112 if (is_vm_hugetlb_page(pvmw->vma)) 113 ptent = huge_ptep_get(pvmw->vma->vm_mm, pvmw->address, 114 pvmw->pte); 115 else 116 ptent = ptep_get(pvmw->pte); 117 118 if (pvmw->flags & PVMW_MIGRATION) { 119 const softleaf_t entry = softleaf_from_pte(ptent); 120 121 if (!softleaf_is_migration(entry)) 122 return false; 123 124 pfn = softleaf_to_pfn(entry); 125 } else if (pte_present(ptent)) { 126 pfn = pte_pfn(ptent); 127 } else { 128 const softleaf_t entry = softleaf_from_pte(ptent); 129 130 /* Handle un-addressable ZONE_DEVICE memory */ 131 if (!softleaf_is_device_private(entry) && 132 !softleaf_is_device_exclusive(entry)) 133 return false; 134 135 pfn = softleaf_to_pfn(entry); 136 } 137 138 if ((pfn + pte_nr - 1) < pvmw->pfn) 139 return false; 140 if (pfn > (pvmw->pfn + pvmw->nr_pages - 1)) 141 return false; 142 return true; 143 } 144 145 /* Returns true if the two ranges overlap. Careful to not overflow. */ 146 static bool check_pmd(unsigned long pfn, struct page_vma_mapped_walk *pvmw) 147 { 148 if ((pfn + HPAGE_PMD_NR - 1) < pvmw->pfn) 149 return false; 150 if (pfn > pvmw->pfn + pvmw->nr_pages - 1) 151 return false; 152 return true; 153 } 154 155 static void step_forward(struct page_vma_mapped_walk *pvmw, unsigned long size) 156 { 157 pvmw->address = (pvmw->address + size) & ~(size - 1); 158 if (!pvmw->address) 159 pvmw->address = ULONG_MAX; 160 } 161 162 /** 163 * page_vma_mapped_walk - check if @pvmw->pfn is mapped in @pvmw->vma at 164 * @pvmw->address 165 * @pvmw: pointer to struct page_vma_mapped_walk. page, vma, address and flags 166 * must be set. pmd, pte and ptl must be NULL. 167 * 168 * Returns true if the page is mapped in the vma. @pvmw->pmd and @pvmw->pte point 169 * to relevant page table entries. @pvmw->ptl is locked. @pvmw->address is 170 * adjusted if needed (for PTE-mapped THPs). 171 * 172 * If @pvmw->pmd is set but @pvmw->pte is not, you have found PMD-mapped page 173 * (usually THP). For PTE-mapped THP, you should run page_vma_mapped_walk() in 174 * a loop to find all PTEs that map the THP. 175 * 176 * For HugeTLB pages, @pvmw->pte is set to the relevant page table entry 177 * regardless of which page table level the page is mapped at. @pvmw->pmd is 178 * NULL. 179 * 180 * Returns false if there are no more page table entries for the page in 181 * the vma. @pvmw->ptl is unlocked and @pvmw->pte is unmapped. 182 * 183 * If you need to stop the walk before page_vma_mapped_walk() returned false, 184 * use page_vma_mapped_walk_done(). It will do the housekeeping. 185 */ 186 bool page_vma_mapped_walk(struct page_vma_mapped_walk *pvmw) 187 { 188 struct vm_area_struct *vma = pvmw->vma; 189 struct mm_struct *mm = vma->vm_mm; 190 unsigned long end; 191 spinlock_t *ptl; 192 pte_t pteval; 193 pgd_t *pgd; 194 p4d_t *p4d; 195 pud_t *pud; 196 pmd_t pmde; 197 198 /* The only possible pmd mapping has been handled on last iteration */ 199 if (pvmw->pmd && !pvmw->pte) 200 return not_found(pvmw); 201 202 if (unlikely(is_vm_hugetlb_page(vma))) { 203 struct hstate *hstate = hstate_vma(vma); 204 unsigned long size = huge_page_size(hstate); 205 /* The only possible mapping was handled on last iteration */ 206 if (pvmw->pte) 207 return not_found(pvmw); 208 /* 209 * All callers that get here will already hold the 210 * i_mmap_rwsem. Therefore, no additional locks need to be 211 * taken before calling hugetlb_walk(). 212 */ 213 pvmw->pte = hugetlb_walk(vma, pvmw->address, size); 214 if (!pvmw->pte) 215 return false; 216 217 pvmw->ptl = huge_pte_lock(hstate, mm, pvmw->pte); 218 if (!check_pte(pvmw, pages_per_huge_page(hstate))) 219 return not_found(pvmw); 220 return true; 221 } 222 223 end = vma_address_end(pvmw); 224 if (pvmw->pte) 225 goto next_pte; 226 restart: 227 do { 228 pgd = pgd_offset(mm, pvmw->address); 229 if (!pgd_present(*pgd)) { 230 step_forward(pvmw, PGDIR_SIZE); 231 continue; 232 } 233 p4d = p4d_offset(pgd, pvmw->address); 234 if (!p4d_present(*p4d)) { 235 step_forward(pvmw, P4D_SIZE); 236 continue; 237 } 238 pud = pud_offset(p4d, pvmw->address); 239 if (!pud_present(*pud)) { 240 step_forward(pvmw, PUD_SIZE); 241 continue; 242 } 243 244 pvmw->pmd = pmd_offset(pud, pvmw->address); 245 /* 246 * Make sure the pmd value isn't cached in a register by the 247 * compiler and used as a stale value after we've observed a 248 * subsequent update. 249 */ 250 pmde = pmdp_get_lockless(pvmw->pmd); 251 252 if (IS_ENABLED(CONFIG_TRANSPARENT_HUGEPAGE) && 253 (pmd_trans_huge(pmde) || pmd_is_migration_entry(pmde) || 254 pmd_is_device_private_entry(pmde))) { 255 pvmw->ptl = pmd_lock(mm, pvmw->pmd); 256 pmde = *pvmw->pmd; 257 if (pmd_is_migration_entry(pmde)) { 258 softleaf_t entry; 259 260 if (!(pvmw->flags & PVMW_MIGRATION)) 261 return not_found(pvmw); 262 entry = softleaf_from_pmd(pmde); 263 if (!check_pmd(softleaf_to_pfn(entry), pvmw)) 264 return not_found(pvmw); 265 return true; 266 } else if (pmd_is_device_private_entry(pmde)) { 267 softleaf_t entry; 268 269 if (pvmw->flags & PVMW_MIGRATION) 270 return not_found(pvmw); 271 entry = softleaf_from_pmd(pmde); 272 if (!check_pmd(softleaf_to_pfn(entry), pvmw)) 273 return not_found(pvmw); 274 return true; 275 } else if (!pmd_present(pmde)) { 276 return not_found(pvmw); 277 } 278 if (likely(pmd_trans_huge(pmde))) { 279 if (pvmw->flags & PVMW_MIGRATION) 280 return not_found(pvmw); 281 if (!check_pmd(pmd_pfn(pmde), pvmw)) 282 return not_found(pvmw); 283 return true; 284 } 285 /* THP/device-private pmd was split under us: handle on pte level */ 286 spin_unlock(pvmw->ptl); 287 pvmw->ptl = NULL; 288 } else if (!pmd_present(pmde)) { 289 if ((pvmw->flags & PVMW_SYNC) && 290 thp_vma_suitable_order(vma, pvmw->address, 291 PMD_ORDER) && 292 (pvmw->nr_pages >= HPAGE_PMD_NR)) 293 sync_with_folio_pmd_zap(mm, pvmw->pmd); 294 295 step_forward(pvmw, PMD_SIZE); 296 continue; 297 } 298 if (!map_pte(pvmw, &pmde, &ptl)) { 299 if (!pvmw->pte) 300 goto restart; 301 goto next_pte; 302 } 303 this_pte: 304 if (check_pte(pvmw, 1)) 305 return true; 306 next_pte: 307 do { 308 pvmw->address += PAGE_SIZE; 309 if (pvmw->address >= end) 310 return not_found(pvmw); 311 /* Did we cross page table boundary? */ 312 if ((pvmw->address & (PMD_SIZE - PAGE_SIZE)) == 0) { 313 if (pvmw->ptl) { 314 spin_unlock(pvmw->ptl); 315 pvmw->ptl = NULL; 316 } 317 pte_unmap(pvmw->pte); 318 pvmw->pte = NULL; 319 pvmw->flags |= PVMW_PGTABLE_CROSSED; 320 goto restart; 321 } 322 pvmw->pte++; 323 if (!pvmw->ptl) 324 pteval = ptep_get_lockless(pvmw->pte); 325 else 326 pteval = ptep_get(pvmw->pte); 327 } while (pte_none(pteval)); 328 329 if (!pvmw->ptl) { 330 spin_lock(ptl); 331 if (unlikely(!pmd_same(pmde, pmdp_get_lockless(pvmw->pmd)))) { 332 pte_unmap_unlock(pvmw->pte, ptl); 333 pvmw->pte = NULL; 334 goto restart; 335 } 336 pvmw->ptl = ptl; 337 } 338 goto this_pte; 339 } while (pvmw->address < end); 340 341 return false; 342 } 343 344 #ifdef CONFIG_MEMORY_FAILURE 345 /** 346 * page_mapped_in_vma - check whether a page is really mapped in a VMA 347 * @page: the page to test 348 * @vma: the VMA to test 349 * 350 * Return: The address the page is mapped at if the page is in the range 351 * covered by the VMA and present in the page table. If the page is 352 * outside the VMA or not present, returns -EFAULT. 353 * Only valid for normal file or anonymous VMAs. 354 */ 355 unsigned long page_mapped_in_vma(const struct page *page, 356 struct vm_area_struct *vma) 357 { 358 const struct folio *folio = page_folio(page); 359 const pgoff_t pgoff = page_pgoff(folio, page); 360 struct page_vma_mapped_walk pvmw = { 361 .pfn = page_to_pfn(page), 362 .nr_pages = 1, 363 .vma = vma, 364 .flags = PVMW_SYNC, 365 }; 366 367 if (folio_test_anon(folio)) 368 pvmw.address = vma_anon_address(vma, pgoff, 1); 369 else 370 pvmw.address = vma_filebacked_address(vma, pgoff, 1); 371 if (pvmw.address == -EFAULT) 372 goto out; 373 if (!page_vma_mapped_walk(&pvmw)) 374 return -EFAULT; 375 page_vma_mapped_walk_done(&pvmw); 376 out: 377 return pvmw.address; 378 } 379 #endif 380