Greg Kroah-Hartman | b244131 | 2017-11-01 15:07:57 +0100 | [diff] [blame] | 1 | // SPDX-License-Identifier: GPL-2.0 |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 2 | /* |
| 3 | * linux/mm/mincore.c |
| 4 | * |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 5 | * Copyright (C) 1994-2006 Linus Torvalds |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 6 | */ |
| 7 | |
| 8 | /* |
| 9 | * The mincore() system call. |
| 10 | */ |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 11 | #include <linux/pagemap.h> |
Tejun Heo | 5a0e3ad | 2010-03-24 17:04:11 +0900 | [diff] [blame] | 12 | #include <linux/gfp.h> |
Christoph Hellwig | a520110 | 2019-08-28 16:19:53 +0200 | [diff] [blame] | 13 | #include <linux/pagewalk.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 14 | #include <linux/mman.h> |
| 15 | #include <linux/syscalls.h> |
Nick Piggin | 42da9cb | 2007-02-12 00:51:39 -0800 | [diff] [blame] | 16 | #include <linux/swap.h> |
| 17 | #include <linux/swapops.h> |
Hugh Dickins | 3a4f8a0 | 2017-02-24 14:59:36 -0800 | [diff] [blame] | 18 | #include <linux/shmem_fs.h> |
Naoya Horiguchi | 4f16fc1 | 2009-12-14 17:59:58 -0800 | [diff] [blame] | 19 | #include <linux/hugetlb.h> |
Mike Rapoport | 65fddcf | 2020-06-08 21:32:42 -0700 | [diff] [blame] | 20 | #include <linux/pgtable.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 21 | |
Linus Torvalds | 7c0f6ba | 2016-12-24 11:46:01 -0800 | [diff] [blame] | 22 | #include <linux/uaccess.h> |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 23 | |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 24 | static int mincore_hugetlb(pte_t *pte, unsigned long hmask, unsigned long addr, |
| 25 | unsigned long end, struct mm_walk *walk) |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 26 | { |
| 27 | #ifdef CONFIG_HUGETLB_PAGE |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 28 | unsigned char present; |
| 29 | unsigned char *vec = walk->private; |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 30 | |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 31 | /* |
| 32 | * Hugepages under user process are always in RAM and never |
| 33 | * swapped out, but theoretically it needs to be checked. |
| 34 | */ |
| 35 | present = pte && !huge_pte_none(huge_ptep_get(pte)); |
| 36 | for (; addr != end; vec++, addr += PAGE_SIZE) |
| 37 | *vec = present; |
| 38 | walk->private = vec; |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 39 | #else |
| 40 | BUG(); |
| 41 | #endif |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 42 | return 0; |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 43 | } |
| 44 | |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 45 | /* |
| 46 | * Later we can get more picky about what "in core" means precisely. |
| 47 | * For now, simply check to see if the page is in the page cache, |
| 48 | * and is up to date; i.e. that no page-in operation would be required |
| 49 | * at this time if an application were to map and access this page. |
| 50 | */ |
Matthew Wilcox (Oracle) | 61ef186 | 2020-10-13 16:51:17 -0700 | [diff] [blame] | 51 | static unsigned char mincore_page(struct address_space *mapping, pgoff_t index) |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 52 | { |
| 53 | unsigned char present = 0; |
| 54 | struct page *page; |
| 55 | |
| 56 | /* |
| 57 | * When tmpfs swaps out a page from a file, any process mapping that |
| 58 | * file will not get a swp_entry_t in its pte, but rather it is like |
| 59 | * any other file mapping (ie. marked !present and faulted in with |
| 60 | * tmpfs's .fault). So swapped out tmpfs mappings are tested here. |
| 61 | */ |
Matthew Wilcox (Oracle) | 61ef186 | 2020-10-13 16:51:17 -0700 | [diff] [blame] | 62 | page = find_get_incore_page(mapping, index); |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 63 | if (page) { |
| 64 | present = PageUptodate(page); |
| 65 | put_page(page); |
| 66 | } |
| 67 | |
| 68 | return present; |
| 69 | } |
| 70 | |
| 71 | static int __mincore_unmapped_range(unsigned long addr, unsigned long end, |
| 72 | struct vm_area_struct *vma, unsigned char *vec) |
| 73 | { |
| 74 | unsigned long nr = (end - addr) >> PAGE_SHIFT; |
| 75 | int i; |
| 76 | |
| 77 | if (vma->vm_file) { |
| 78 | pgoff_t pgoff; |
| 79 | |
| 80 | pgoff = linear_page_index(vma, addr); |
| 81 | for (i = 0; i < nr; i++, pgoff++) |
| 82 | vec[i] = mincore_page(vma->vm_file->f_mapping, pgoff); |
| 83 | } else { |
| 84 | for (i = 0; i < nr; i++) |
| 85 | vec[i] = 0; |
| 86 | } |
| 87 | return nr; |
| 88 | } |
| 89 | |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 90 | static int mincore_unmapped_range(unsigned long addr, unsigned long end, |
Steven Price | b7a16c7 | 2020-02-03 17:36:03 -0800 | [diff] [blame] | 91 | __always_unused int depth, |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 92 | struct mm_walk *walk) |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 93 | { |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 94 | walk->private += __mincore_unmapped_range(addr, end, |
| 95 | walk->vma, walk->private); |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 96 | return 0; |
| 97 | } |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 98 | |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 99 | static int mincore_pte_range(pmd_t *pmd, unsigned long addr, unsigned long end, |
| 100 | struct mm_walk *walk) |
| 101 | { |
| 102 | spinlock_t *ptl; |
| 103 | struct vm_area_struct *vma = walk->vma; |
| 104 | pte_t *ptep; |
| 105 | unsigned char *vec = walk->private; |
| 106 | int nr = (end - addr) >> PAGE_SHIFT; |
| 107 | |
Kirill A. Shutemov | b6ec57f | 2016-01-21 16:40:25 -0800 | [diff] [blame] | 108 | ptl = pmd_trans_huge_lock(pmd, vma); |
| 109 | if (ptl) { |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 110 | memset(vec, 1, nr); |
| 111 | spin_unlock(ptl); |
| 112 | goto out; |
| 113 | } |
| 114 | |
| 115 | if (pmd_trans_unstable(pmd)) { |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 116 | __mincore_unmapped_range(addr, end, vma, vec); |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 117 | goto out; |
| 118 | } |
| 119 | |
| 120 | ptep = pte_offset_map_lock(walk->mm, pmd, addr, &ptl); |
| 121 | for (; addr != end; ptep++, addr += PAGE_SIZE) { |
Nick Piggin | 42da9cb | 2007-02-12 00:51:39 -0800 | [diff] [blame] | 122 | pte_t pte = *ptep; |
| 123 | |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 124 | if (pte_none(pte)) |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 125 | __mincore_unmapped_range(addr, addr + PAGE_SIZE, |
| 126 | vma, vec); |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 127 | else if (pte_present(pte)) |
Johannes Weiner | 25ef0e5 | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 128 | *vec = 1; |
Kirill A. Shutemov | 0661a33 | 2015-02-10 14:10:04 -0800 | [diff] [blame] | 129 | else { /* pte is a swap entry */ |
Nick Piggin | 42da9cb | 2007-02-12 00:51:39 -0800 | [diff] [blame] | 130 | swp_entry_t entry = pte_to_swp_entry(pte); |
Johannes Weiner | 6a60f1b | 2010-05-24 14:32:09 -0700 | [diff] [blame] | 131 | |
Linus Torvalds | 30bac16 | 2019-01-24 09:04:37 +1300 | [diff] [blame] | 132 | if (non_swap_entry(entry)) { |
| 133 | /* |
| 134 | * migration or hwpoison entries are always |
| 135 | * uptodate |
| 136 | */ |
| 137 | *vec = 1; |
| 138 | } else { |
| 139 | #ifdef CONFIG_SWAP |
| 140 | *vec = mincore_page(swap_address_space(entry), |
| 141 | swp_offset(entry)); |
| 142 | #else |
| 143 | WARN_ON(1); |
| 144 | *vec = 1; |
| 145 | #endif |
| 146 | } |
Nick Piggin | 42da9cb | 2007-02-12 00:51:39 -0800 | [diff] [blame] | 147 | } |
Johannes Weiner | 25ef0e5 | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 148 | vec++; |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 149 | } |
Johannes Weiner | 6a60f1b | 2010-05-24 14:32:09 -0700 | [diff] [blame] | 150 | pte_unmap_unlock(ptep - 1, ptl); |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 151 | out: |
| 152 | walk->private += nr; |
| 153 | cond_resched(); |
| 154 | return 0; |
Johannes Weiner | e48293f | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 155 | } |
| 156 | |
Jiri Kosina | 134fca9 | 2019-05-14 15:41:38 -0700 | [diff] [blame] | 157 | static inline bool can_do_mincore(struct vm_area_struct *vma) |
| 158 | { |
| 159 | if (vma_is_anonymous(vma)) |
| 160 | return true; |
| 161 | if (!vma->vm_file) |
| 162 | return false; |
| 163 | /* |
| 164 | * Reveal pagecache information only for non-anonymous mappings that |
| 165 | * correspond to the files the calling process could (if tried) open |
| 166 | * for writing; otherwise we'd be including shared non-exclusive |
| 167 | * mappings, which opens a side channel. |
| 168 | */ |
Christian Brauner | 21cb47b | 2021-01-21 14:19:25 +0100 | [diff] [blame] | 169 | return inode_owner_or_capable(&init_user_ns, |
| 170 | file_inode(vma->vm_file)) || |
Christian Brauner | 02f92b3 | 2021-01-21 14:19:22 +0100 | [diff] [blame] | 171 | file_permission(vma->vm_file, MAY_WRITE) == 0; |
Jiri Kosina | 134fca9 | 2019-05-14 15:41:38 -0700 | [diff] [blame] | 172 | } |
| 173 | |
Christoph Hellwig | 7b86ac3 | 2019-08-28 16:19:54 +0200 | [diff] [blame] | 174 | static const struct mm_walk_ops mincore_walk_ops = { |
| 175 | .pmd_entry = mincore_pte_range, |
| 176 | .pte_hole = mincore_unmapped_range, |
| 177 | .hugetlb_entry = mincore_hugetlb, |
| 178 | }; |
| 179 | |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 180 | /* |
| 181 | * Do a chunk of "sys_mincore()". We've already checked |
| 182 | * all the arguments, we hold the mmap semaphore: we should |
| 183 | * just return the amount of info we're asked for. |
| 184 | */ |
| 185 | static long do_mincore(unsigned long addr, unsigned long pages, unsigned char *vec) |
| 186 | { |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 187 | struct vm_area_struct *vma; |
Johannes Weiner | 25ef0e5 | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 188 | unsigned long end; |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 189 | int err; |
Johannes Weiner | f488401 | 2010-05-24 14:32:10 -0700 | [diff] [blame] | 190 | |
| 191 | vma = find_vma(current->mm, addr); |
| 192 | if (!vma || addr < vma->vm_start) |
| 193 | return -ENOMEM; |
Johannes Weiner | 25ef0e5 | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 194 | end = min(vma->vm_end, addr + (pages << PAGE_SHIFT)); |
Jiri Kosina | 134fca9 | 2019-05-14 15:41:38 -0700 | [diff] [blame] | 195 | if (!can_do_mincore(vma)) { |
| 196 | unsigned long pages = DIV_ROUND_UP(end - addr, PAGE_SIZE); |
| 197 | memset(vec, 1, pages); |
| 198 | return pages; |
| 199 | } |
Christoph Hellwig | 7b86ac3 | 2019-08-28 16:19:54 +0200 | [diff] [blame] | 200 | err = walk_page_range(vma->vm_mm, addr, end, &mincore_walk_ops, vec); |
Naoya Horiguchi | 1e25a27 | 2015-02-11 15:28:11 -0800 | [diff] [blame] | 201 | if (err < 0) |
| 202 | return err; |
Johannes Weiner | 25ef0e5 | 2010-05-24 14:32:11 -0700 | [diff] [blame] | 203 | return (end - addr) >> PAGE_SHIFT; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 204 | } |
| 205 | |
| 206 | /* |
| 207 | * The mincore(2) system call. |
| 208 | * |
| 209 | * mincore() returns the memory residency status of the pages in the |
| 210 | * current process's address space specified by [addr, addr + len). |
| 211 | * The status is returned in a vector of bytes. The least significant |
| 212 | * bit of each byte is 1 if the referenced page is in memory, otherwise |
| 213 | * it is zero. |
| 214 | * |
| 215 | * Because the status of a page can change after mincore() checks it |
| 216 | * but before it returns to the application, the returned vector may |
| 217 | * contain stale information. Only locked pages are guaranteed to |
| 218 | * remain in memory. |
| 219 | * |
| 220 | * return values: |
| 221 | * zero - success |
| 222 | * -EFAULT - vec points to an illegal address |
Kirill A. Shutemov | ea1754a | 2016-04-01 15:29:48 +0300 | [diff] [blame] | 223 | * -EINVAL - addr is not a multiple of PAGE_SIZE |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 224 | * -ENOMEM - Addresses in the range [addr, addr + len] are |
| 225 | * invalid for the address space of this process, or |
| 226 | * specify one or more pages which are not currently |
| 227 | * mapped |
| 228 | * -EAGAIN - A kernel resource was temporarily unavailable. |
| 229 | */ |
Heiko Carstens | 3480b25 | 2009-01-14 14:14:16 +0100 | [diff] [blame] | 230 | SYSCALL_DEFINE3(mincore, unsigned long, start, size_t, len, |
| 231 | unsigned char __user *, vec) |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 232 | { |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 233 | long retval; |
| 234 | unsigned long pages; |
| 235 | unsigned char *tmp; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 236 | |
Andrey Konovalov | 057d3389 | 2019-09-25 16:48:30 -0700 | [diff] [blame] | 237 | start = untagged_addr(start); |
| 238 | |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 239 | /* Check the start address: needs to be page-aligned.. */ |
Kirill A. Shutemov | 09cbfea | 2016-04-01 15:29:47 +0300 | [diff] [blame] | 240 | if (start & ~PAGE_MASK) |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 241 | return -EINVAL; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 242 | |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 243 | /* ..and we need to be passed a valid user-space range */ |
Linus Torvalds | 96d4f26 | 2019-01-03 18:57:57 -0800 | [diff] [blame] | 244 | if (!access_ok((void __user *) start, len)) |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 245 | return -ENOMEM; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 246 | |
Kirill A. Shutemov | ea1754a | 2016-04-01 15:29:48 +0300 | [diff] [blame] | 247 | /* This also avoids any overflows on PAGE_ALIGN */ |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 248 | pages = len >> PAGE_SHIFT; |
Alexander Kuleshov | e7bbdd0 | 2015-11-05 18:46:38 -0800 | [diff] [blame] | 249 | pages += (offset_in_page(len)) != 0; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 250 | |
Linus Torvalds | 96d4f26 | 2019-01-03 18:57:57 -0800 | [diff] [blame] | 251 | if (!access_ok(vec, pages)) |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 252 | return -EFAULT; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 253 | |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 254 | tmp = (void *) __get_free_page(GFP_USER); |
| 255 | if (!tmp) |
Linus Torvalds | 4fb23e4 | 2006-12-16 16:01:50 -0800 | [diff] [blame] | 256 | return -EAGAIN; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 257 | |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 258 | retval = 0; |
| 259 | while (pages) { |
| 260 | /* |
| 261 | * Do at most PAGE_SIZE entries per iteration, due to |
| 262 | * the temporary buffer size. |
| 263 | */ |
Michel Lespinasse | d8ed45c | 2020-06-08 21:33:25 -0700 | [diff] [blame] | 264 | mmap_read_lock(current->mm); |
Johannes Weiner | 6a60f1b | 2010-05-24 14:32:09 -0700 | [diff] [blame] | 265 | retval = do_mincore(start, min(pages, PAGE_SIZE), tmp); |
Michel Lespinasse | d8ed45c | 2020-06-08 21:33:25 -0700 | [diff] [blame] | 266 | mmap_read_unlock(current->mm); |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 267 | |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 268 | if (retval <= 0) |
| 269 | break; |
| 270 | if (copy_to_user(vec, tmp, retval)) { |
| 271 | retval = -EFAULT; |
| 272 | break; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 273 | } |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 274 | pages -= retval; |
| 275 | vec += retval; |
| 276 | start += retval << PAGE_SHIFT; |
| 277 | retval = 0; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 278 | } |
Linus Torvalds | 2f77d10 | 2006-12-16 09:44:32 -0800 | [diff] [blame] | 279 | free_page((unsigned long) tmp); |
| 280 | return retval; |
Linus Torvalds | 1da177e | 2005-04-16 15:20:36 -0700 | [diff] [blame] | 281 | } |