Greg Kroah-Hartman | b244131 | 2017-11-01 15:07:57 +0100 | [diff] [blame] | 1 | // SPDX-License-Identifier: GPL-2.0 |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 2 | /* |
| 3 | * This code is used on x86_64 to create page table identity mappings on |
| 4 | * demand by building up a new set of page tables (or appending to the |
| 5 | * existing ones), and then switching over to them when ready. |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 6 | * |
| 7 | * Copyright (C) 2015-2016 Yinghai Lu |
| 8 | * Copyright (C) 2016 Kees Cook |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 9 | */ |
| 10 | |
| 11 | /* |
| 12 | * Since we're dealing with identity mappings, physical and virtual |
| 13 | * addresses are the same, so override these defines which are ultimately |
| 14 | * used by the headers in misc.h. |
| 15 | */ |
| 16 | #define __pa(x) ((unsigned long)(x)) |
| 17 | #define __va(x) ((void *)((unsigned long)(x))) |
| 18 | |
Thomas Gleixner | aa8c624 | 2017-12-04 15:07:36 +0100 | [diff] [blame] | 19 | /* No PAGE_TABLE_ISOLATION support needed either: */ |
| 20 | #undef CONFIG_PAGE_TABLE_ISOLATION |
| 21 | |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 22 | #include "misc.h" |
| 23 | |
| 24 | /* These actually do the work of building the kernel identity maps. */ |
| 25 | #include <asm/init.h> |
| 26 | #include <asm/pgtable.h> |
Thomas Garnier | 021182e | 2016-06-21 17:47:03 -0700 | [diff] [blame] | 27 | /* Use the static base for this part of the boot process */ |
| 28 | #undef __PAGE_OFFSET |
| 29 | #define __PAGE_OFFSET __PAGE_OFFSET_BASE |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 30 | #include "../../mm/ident_map.c" |
| 31 | |
| 32 | /* Used by pgtable.h asm code to force instruction serialization. */ |
| 33 | unsigned long __force_order; |
| 34 | |
| 35 | /* Used to track our page table allocation area. */ |
| 36 | struct alloc_pgt_data { |
| 37 | unsigned char *pgt_buf; |
| 38 | unsigned long pgt_buf_size; |
| 39 | unsigned long pgt_buf_offset; |
| 40 | }; |
| 41 | |
| 42 | /* |
| 43 | * Allocates space for a page table entry, using struct alloc_pgt_data |
| 44 | * above. Besides the local callers, this is used as the allocation |
| 45 | * callback in mapping_info below. |
| 46 | */ |
| 47 | static void *alloc_pgt_page(void *context) |
| 48 | { |
| 49 | struct alloc_pgt_data *pages = (struct alloc_pgt_data *)context; |
| 50 | unsigned char *entry; |
| 51 | |
| 52 | /* Validate there is space available for a new page. */ |
| 53 | if (pages->pgt_buf_offset >= pages->pgt_buf_size) { |
| 54 | debug_putstr("out of pgt_buf in " __FILE__ "!?\n"); |
| 55 | debug_putaddr(pages->pgt_buf_offset); |
| 56 | debug_putaddr(pages->pgt_buf_size); |
| 57 | return NULL; |
| 58 | } |
| 59 | |
| 60 | entry = pages->pgt_buf + pages->pgt_buf_offset; |
| 61 | pages->pgt_buf_offset += PAGE_SIZE; |
| 62 | |
| 63 | return entry; |
| 64 | } |
| 65 | |
| 66 | /* Used to track our allocated page tables. */ |
| 67 | static struct alloc_pgt_data pgt_data; |
| 68 | |
| 69 | /* The top level page table entry pointer. */ |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 70 | static unsigned long top_level_pgt; |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 71 | |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 72 | /* |
| 73 | * Mapping information structure passed to kernel_ident_mapping_init(). |
| 74 | * Due to relocation, pointers must be assigned at run time not build time. |
| 75 | */ |
Tom Lendacky | 1958b5f | 2017-10-20 09:30:54 -0500 | [diff] [blame] | 76 | static struct x86_mapping_info mapping_info; |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 77 | |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 78 | /* Locates and clears a region for a new top level page table. */ |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 79 | void initialize_identity_maps(void) |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 80 | { |
Tom Lendacky | 07344b1 | 2018-03-27 17:07:11 -0500 | [diff] [blame] | 81 | /* If running as an SEV guest, the encryption mask is required. */ |
| 82 | set_sev_encryption_mask(); |
Tom Lendacky | 1958b5f | 2017-10-20 09:30:54 -0500 | [diff] [blame] | 83 | |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 84 | /* Init mapping_info with run-time function/buffer pointers. */ |
| 85 | mapping_info.alloc_pgt_page = alloc_pgt_page; |
| 86 | mapping_info.context = &pgt_data; |
Tom Lendacky | 07344b1 | 2018-03-27 17:07:11 -0500 | [diff] [blame] | 87 | mapping_info.page_flag = __PAGE_KERNEL_LARGE_EXEC | sme_me_mask; |
| 88 | mapping_info.kernpg_flag = _KERNPG_TABLE; |
Kees Cook | 11fdf97 | 2016-05-25 15:45:31 -0700 | [diff] [blame] | 89 | |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 90 | /* |
| 91 | * It should be impossible for this not to already be true, |
| 92 | * but since calling this a second time would rewind the other |
| 93 | * counters, let's just make sure this is reset too. |
| 94 | */ |
| 95 | pgt_data.pgt_buf_offset = 0; |
| 96 | |
| 97 | /* |
| 98 | * If we came here via startup_32(), cr3 will be _pgtable already |
| 99 | * and we must append to the existing area instead of entirely |
| 100 | * overwriting it. |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 101 | * |
| 102 | * With 5-level paging, we use '_pgtable' to allocate the p4d page table, |
| 103 | * the top-level page table is allocated separately. |
| 104 | * |
| 105 | * p4d_offset(top_level_pgt, 0) would cover both the 4- and 5-level |
| 106 | * cases. On 4-level paging it's equal to 'top_level_pgt'. |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 107 | */ |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 108 | top_level_pgt = read_cr3_pa(); |
| 109 | if (p4d_offset((pgd_t *)top_level_pgt, 0) == (p4d_t *)_pgtable) { |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 110 | debug_putstr("booted via startup_32()\n"); |
| 111 | pgt_data.pgt_buf = _pgtable + BOOT_INIT_PGT_SIZE; |
| 112 | pgt_data.pgt_buf_size = BOOT_PGT_SIZE - BOOT_INIT_PGT_SIZE; |
| 113 | memset(pgt_data.pgt_buf, 0, pgt_data.pgt_buf_size); |
| 114 | } else { |
| 115 | debug_putstr("booted via startup_64()\n"); |
| 116 | pgt_data.pgt_buf = _pgtable; |
| 117 | pgt_data.pgt_buf_size = BOOT_PGT_SIZE; |
| 118 | memset(pgt_data.pgt_buf, 0, pgt_data.pgt_buf_size); |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 119 | top_level_pgt = (unsigned long)alloc_pgt_page(&pgt_data); |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 120 | } |
| 121 | } |
| 122 | |
| 123 | /* |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 124 | * Adds the specified range to what will become the new identity mappings. |
| 125 | * Once all ranges have been added, the new mapping is activated by calling |
| 126 | * finalize_identity_maps() below. |
| 127 | */ |
| 128 | void add_identity_map(unsigned long start, unsigned long size) |
| 129 | { |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 130 | unsigned long end = start + size; |
| 131 | |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 132 | /* Align boundary to 2M. */ |
| 133 | start = round_down(start, PMD_SIZE); |
| 134 | end = round_up(end, PMD_SIZE); |
| 135 | if (start >= end) |
| 136 | return; |
| 137 | |
| 138 | /* Build the mapping. */ |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 139 | kernel_ident_mapping_init(&mapping_info, (pgd_t *)top_level_pgt, |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 140 | start, end); |
| 141 | } |
| 142 | |
| 143 | /* |
| 144 | * This switches the page tables to the new level4 that has been built |
| 145 | * via calls to add_identity_map() above. If booted via startup_32(), |
| 146 | * this is effectively a no-op. |
| 147 | */ |
| 148 | void finalize_identity_maps(void) |
| 149 | { |
Kirill A. Shutemov | a24261d | 2017-06-28 15:17:30 +0300 | [diff] [blame] | 150 | write_cr3(top_level_pgt); |
Kees Cook | 3a94707 | 2016-05-06 15:01:35 -0700 | [diff] [blame] | 151 | } |