gntalloc.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612
  1. /******************************************************************************
  2. * gntalloc.c
  3. *
  4. * Device for creating grant references (in user-space) that may be shared
  5. * with other domains.
  6. *
  7. * This program is distributed in the hope that it will be useful,
  8. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. * GNU General Public License for more details.
  11. *
  12. * You should have received a copy of the GNU General Public License
  13. * along with this program; if not, write to the Free Software
  14. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  15. */
  16. /*
  17. * This driver exists to allow userspace programs in Linux to allocate kernel
  18. * memory that will later be shared with another domain. Without this device,
  19. * Linux userspace programs cannot create grant references.
  20. *
  21. * How this stuff works:
  22. * X -> granting a page to Y
  23. * Y -> mapping the grant from X
  24. *
  25. * 1. X uses the gntalloc device to allocate a page of kernel memory, P.
  26. * 2. X creates an entry in the grant table that says domid(Y) can access P.
  27. * This is done without a hypercall unless the grant table needs expansion.
  28. * 3. X gives the grant reference identifier, GREF, to Y.
  29. * 4. Y maps the page, either directly into kernel memory for use in a backend
  30. * driver, or via a the gntdev device to map into the address space of an
  31. * application running in Y. This is the first point at which Xen does any
  32. * tracking of the page.
  33. * 5. A program in X mmap()s a segment of the gntalloc device that corresponds
  34. * to the shared page, and can now communicate with Y over the shared page.
  35. *
  36. *
  37. * NOTE TO USERSPACE LIBRARIES:
  38. * The grant allocation and mmap()ing are, naturally, two separate operations.
  39. * You set up the sharing by calling the create ioctl() and then the mmap().
  40. * Teardown requires munmap() and either close() or ioctl().
  41. *
  42. * WARNING: Since Xen does not allow a guest to forcibly end the use of a grant
  43. * reference, this device can be used to consume kernel memory by leaving grant
  44. * references mapped by another domain when an application exits. Therefore,
  45. * there is a global limit on the number of pages that can be allocated. When
  46. * all references to the page are unmapped, it will be freed during the next
  47. * grant operation.
  48. */
  49. #define pr_fmt(fmt) "xen:" KBUILD_MODNAME ": " fmt
  50. #include <linux/atomic.h>
  51. #include <linux/module.h>
  52. #include <linux/miscdevice.h>
  53. #include <linux/kernel.h>
  54. #include <linux/init.h>
  55. #include <linux/slab.h>
  56. #include <linux/fs.h>
  57. #include <linux/device.h>
  58. #include <linux/mm.h>
  59. #include <linux/uaccess.h>
  60. #include <linux/types.h>
  61. #include <linux/list.h>
  62. #include <linux/highmem.h>
  63. #include <xen/xen.h>
  64. #include <xen/page.h>
  65. #include <xen/grant_table.h>
  66. #include <xen/gntalloc.h>
  67. #include <xen/events.h>
  68. static int limit = 1024;
  69. module_param(limit, int, 0644);
  70. MODULE_PARM_DESC(limit, "Maximum number of grants that may be allocated by "
  71. "the gntalloc device");
  72. static LIST_HEAD(gref_list);
  73. static DEFINE_MUTEX(gref_mutex);
  74. static int gref_size;
  75. struct notify_info {
  76. uint16_t pgoff:12; /* Bits 0-11: Offset of the byte to clear */
  77. uint16_t flags:2; /* Bits 12-13: Unmap notification flags */
  78. int event; /* Port (event channel) to notify */
  79. };
  80. /* Metadata on a grant reference. */
  81. struct gntalloc_gref {
  82. struct list_head next_gref; /* list entry gref_list */
  83. struct list_head next_file; /* list entry file->list, if open */
  84. struct page *page; /* The shared page */
  85. uint64_t file_index; /* File offset for mmap() */
  86. unsigned int users; /* Use count - when zero, waiting on Xen */
  87. grant_ref_t gref_id; /* The grant reference number */
  88. struct notify_info notify; /* Unmap notification */
  89. };
  90. struct gntalloc_file_private_data {
  91. struct list_head list;
  92. uint64_t index;
  93. };
  94. struct gntalloc_vma_private_data {
  95. struct gntalloc_gref *gref;
  96. int users;
  97. int count;
  98. };
  99. static void __del_gref(struct gntalloc_gref *gref);
  100. static void do_cleanup(void)
  101. {
  102. struct gntalloc_gref *gref, *n;
  103. list_for_each_entry_safe(gref, n, &gref_list, next_gref) {
  104. if (!gref->users)
  105. __del_gref(gref);
  106. }
  107. }
  108. static int add_grefs(struct ioctl_gntalloc_alloc_gref *op,
  109. uint32_t *gref_ids, struct gntalloc_file_private_data *priv)
  110. {
  111. int i, rc, readonly;
  112. LIST_HEAD(queue_gref);
  113. LIST_HEAD(queue_file);
  114. struct gntalloc_gref *gref, *next;
  115. readonly = !(op->flags & GNTALLOC_FLAG_WRITABLE);
  116. for (i = 0; i < op->count; i++) {
  117. gref = kzalloc(sizeof(*gref), GFP_KERNEL);
  118. if (!gref) {
  119. rc = -ENOMEM;
  120. goto undo;
  121. }
  122. list_add_tail(&gref->next_gref, &queue_gref);
  123. list_add_tail(&gref->next_file, &queue_file);
  124. gref->users = 1;
  125. gref->file_index = op->index + i * PAGE_SIZE;
  126. gref->page = alloc_page(GFP_KERNEL|__GFP_ZERO);
  127. if (!gref->page) {
  128. rc = -ENOMEM;
  129. goto undo;
  130. }
  131. /* Grant foreign access to the page. */
  132. rc = gnttab_grant_foreign_access(op->domid,
  133. xen_page_to_gfn(gref->page),
  134. readonly);
  135. if (rc < 0)
  136. goto undo;
  137. gref_ids[i] = gref->gref_id = rc;
  138. }
  139. /* Add to gref lists. */
  140. mutex_lock(&gref_mutex);
  141. list_splice_tail(&queue_gref, &gref_list);
  142. list_splice_tail(&queue_file, &priv->list);
  143. mutex_unlock(&gref_mutex);
  144. return 0;
  145. undo:
  146. mutex_lock(&gref_mutex);
  147. gref_size -= (op->count - i);
  148. list_for_each_entry_safe(gref, next, &queue_file, next_file) {
  149. list_del(&gref->next_file);
  150. __del_gref(gref);
  151. }
  152. /* It's possible for the target domain to map the just-allocated grant
  153. * references by blindly guessing their IDs; if this is done, then
  154. * __del_gref will leave them in the queue_gref list. They need to be
  155. * added to the global list so that we can free them when they are no
  156. * longer referenced.
  157. */
  158. if (unlikely(!list_empty(&queue_gref)))
  159. list_splice_tail(&queue_gref, &gref_list);
  160. mutex_unlock(&gref_mutex);
  161. return rc;
  162. }
  163. static void __del_gref(struct gntalloc_gref *gref)
  164. {
  165. if (gref->notify.flags & UNMAP_NOTIFY_CLEAR_BYTE) {
  166. uint8_t *tmp = kmap(gref->page);
  167. tmp[gref->notify.pgoff] = 0;
  168. kunmap(gref->page);
  169. }
  170. if (gref->notify.flags & UNMAP_NOTIFY_SEND_EVENT) {
  171. notify_remote_via_evtchn(gref->notify.event);
  172. evtchn_put(gref->notify.event);
  173. }
  174. gref->notify.flags = 0;
  175. if (gref->gref_id) {
  176. if (gnttab_query_foreign_access(gref->gref_id))
  177. return;
  178. if (!gnttab_end_foreign_access_ref(gref->gref_id, 0))
  179. return;
  180. gnttab_free_grant_reference(gref->gref_id);
  181. }
  182. gref_size--;
  183. list_del(&gref->next_gref);
  184. if (gref->page)
  185. __free_page(gref->page);
  186. kfree(gref);
  187. }
  188. /* finds contiguous grant references in a file, returns the first */
  189. static struct gntalloc_gref *find_grefs(struct gntalloc_file_private_data *priv,
  190. uint64_t index, uint32_t count)
  191. {
  192. struct gntalloc_gref *rv = NULL, *gref;
  193. list_for_each_entry(gref, &priv->list, next_file) {
  194. if (gref->file_index == index && !rv)
  195. rv = gref;
  196. if (rv) {
  197. if (gref->file_index != index)
  198. return NULL;
  199. index += PAGE_SIZE;
  200. count--;
  201. if (count == 0)
  202. return rv;
  203. }
  204. }
  205. return NULL;
  206. }
  207. /*
  208. * -------------------------------------
  209. * File operations.
  210. * -------------------------------------
  211. */
  212. static int gntalloc_open(struct inode *inode, struct file *filp)
  213. {
  214. struct gntalloc_file_private_data *priv;
  215. priv = kzalloc(sizeof(*priv), GFP_KERNEL);
  216. if (!priv)
  217. goto out_nomem;
  218. INIT_LIST_HEAD(&priv->list);
  219. filp->private_data = priv;
  220. pr_debug("%s: priv %p\n", __func__, priv);
  221. return 0;
  222. out_nomem:
  223. return -ENOMEM;
  224. }
  225. static int gntalloc_release(struct inode *inode, struct file *filp)
  226. {
  227. struct gntalloc_file_private_data *priv = filp->private_data;
  228. struct gntalloc_gref *gref;
  229. pr_debug("%s: priv %p\n", __func__, priv);
  230. mutex_lock(&gref_mutex);
  231. while (!list_empty(&priv->list)) {
  232. gref = list_entry(priv->list.next,
  233. struct gntalloc_gref, next_file);
  234. list_del(&gref->next_file);
  235. gref->users--;
  236. if (gref->users == 0)
  237. __del_gref(gref);
  238. }
  239. kfree(priv);
  240. mutex_unlock(&gref_mutex);
  241. return 0;
  242. }
  243. static long gntalloc_ioctl_alloc(struct gntalloc_file_private_data *priv,
  244. struct ioctl_gntalloc_alloc_gref __user *arg)
  245. {
  246. int rc = 0;
  247. struct ioctl_gntalloc_alloc_gref op;
  248. uint32_t *gref_ids;
  249. pr_debug("%s: priv %p\n", __func__, priv);
  250. if (copy_from_user(&op, arg, sizeof(op))) {
  251. rc = -EFAULT;
  252. goto out;
  253. }
  254. gref_ids = kcalloc(op.count, sizeof(gref_ids[0]), GFP_KERNEL);
  255. if (!gref_ids) {
  256. rc = -ENOMEM;
  257. goto out;
  258. }
  259. mutex_lock(&gref_mutex);
  260. /* Clean up pages that were at zero (local) users but were still mapped
  261. * by remote domains. Since those pages count towards the limit that we
  262. * are about to enforce, removing them here is a good idea.
  263. */
  264. do_cleanup();
  265. if (gref_size + op.count > limit) {
  266. mutex_unlock(&gref_mutex);
  267. rc = -ENOSPC;
  268. goto out_free;
  269. }
  270. gref_size += op.count;
  271. op.index = priv->index;
  272. priv->index += op.count * PAGE_SIZE;
  273. mutex_unlock(&gref_mutex);
  274. rc = add_grefs(&op, gref_ids, priv);
  275. if (rc < 0)
  276. goto out_free;
  277. /* Once we finish add_grefs, it is unsafe to touch the new reference,
  278. * since it is possible for a concurrent ioctl to remove it (by guessing
  279. * its index). If the userspace application doesn't provide valid memory
  280. * to write the IDs to, then it will need to close the file in order to
  281. * release - which it will do by segfaulting when it tries to access the
  282. * IDs to close them.
  283. */
  284. if (copy_to_user(arg, &op, sizeof(op))) {
  285. rc = -EFAULT;
  286. goto out_free;
  287. }
  288. if (copy_to_user(arg->gref_ids, gref_ids,
  289. sizeof(gref_ids[0]) * op.count)) {
  290. rc = -EFAULT;
  291. goto out_free;
  292. }
  293. out_free:
  294. kfree(gref_ids);
  295. out:
  296. return rc;
  297. }
  298. static long gntalloc_ioctl_dealloc(struct gntalloc_file_private_data *priv,
  299. void __user *arg)
  300. {
  301. int i, rc = 0;
  302. struct ioctl_gntalloc_dealloc_gref op;
  303. struct gntalloc_gref *gref, *n;
  304. pr_debug("%s: priv %p\n", __func__, priv);
  305. if (copy_from_user(&op, arg, sizeof(op))) {
  306. rc = -EFAULT;
  307. goto dealloc_grant_out;
  308. }
  309. mutex_lock(&gref_mutex);
  310. gref = find_grefs(priv, op.index, op.count);
  311. if (gref) {
  312. /* Remove from the file list only, and decrease reference count.
  313. * The later call to do_cleanup() will remove from gref_list and
  314. * free the memory if the pages aren't mapped anywhere.
  315. */
  316. for (i = 0; i < op.count; i++) {
  317. n = list_entry(gref->next_file.next,
  318. struct gntalloc_gref, next_file);
  319. list_del(&gref->next_file);
  320. gref->users--;
  321. gref = n;
  322. }
  323. } else {
  324. rc = -EINVAL;
  325. }
  326. do_cleanup();
  327. mutex_unlock(&gref_mutex);
  328. dealloc_grant_out:
  329. return rc;
  330. }
  331. static long gntalloc_ioctl_unmap_notify(struct gntalloc_file_private_data *priv,
  332. void __user *arg)
  333. {
  334. struct ioctl_gntalloc_unmap_notify op;
  335. struct gntalloc_gref *gref;
  336. uint64_t index;
  337. int pgoff;
  338. int rc;
  339. if (copy_from_user(&op, arg, sizeof(op)))
  340. return -EFAULT;
  341. index = op.index & ~(PAGE_SIZE - 1);
  342. pgoff = op.index & (PAGE_SIZE - 1);
  343. mutex_lock(&gref_mutex);
  344. gref = find_grefs(priv, index, 1);
  345. if (!gref) {
  346. rc = -ENOENT;
  347. goto unlock_out;
  348. }
  349. if (op.action & ~(UNMAP_NOTIFY_CLEAR_BYTE|UNMAP_NOTIFY_SEND_EVENT)) {
  350. rc = -EINVAL;
  351. goto unlock_out;
  352. }
  353. /* We need to grab a reference to the event channel we are going to use
  354. * to send the notify before releasing the reference we may already have
  355. * (if someone has called this ioctl twice). This is required so that
  356. * it is possible to change the clear_byte part of the notification
  357. * without disturbing the event channel part, which may now be the last
  358. * reference to that event channel.
  359. */
  360. if (op.action & UNMAP_NOTIFY_SEND_EVENT) {
  361. if (evtchn_get(op.event_channel_port)) {
  362. rc = -EINVAL;
  363. goto unlock_out;
  364. }
  365. }
  366. if (gref->notify.flags & UNMAP_NOTIFY_SEND_EVENT)
  367. evtchn_put(gref->notify.event);
  368. gref->notify.flags = op.action;
  369. gref->notify.pgoff = pgoff;
  370. gref->notify.event = op.event_channel_port;
  371. rc = 0;
  372. unlock_out:
  373. mutex_unlock(&gref_mutex);
  374. return rc;
  375. }
  376. static long gntalloc_ioctl(struct file *filp, unsigned int cmd,
  377. unsigned long arg)
  378. {
  379. struct gntalloc_file_private_data *priv = filp->private_data;
  380. switch (cmd) {
  381. case IOCTL_GNTALLOC_ALLOC_GREF:
  382. return gntalloc_ioctl_alloc(priv, (void __user *)arg);
  383. case IOCTL_GNTALLOC_DEALLOC_GREF:
  384. return gntalloc_ioctl_dealloc(priv, (void __user *)arg);
  385. case IOCTL_GNTALLOC_SET_UNMAP_NOTIFY:
  386. return gntalloc_ioctl_unmap_notify(priv, (void __user *)arg);
  387. default:
  388. return -ENOIOCTLCMD;
  389. }
  390. return 0;
  391. }
  392. static void gntalloc_vma_open(struct vm_area_struct *vma)
  393. {
  394. struct gntalloc_vma_private_data *priv = vma->vm_private_data;
  395. if (!priv)
  396. return;
  397. mutex_lock(&gref_mutex);
  398. priv->users++;
  399. mutex_unlock(&gref_mutex);
  400. }
  401. static void gntalloc_vma_close(struct vm_area_struct *vma)
  402. {
  403. struct gntalloc_vma_private_data *priv = vma->vm_private_data;
  404. struct gntalloc_gref *gref, *next;
  405. int i;
  406. if (!priv)
  407. return;
  408. mutex_lock(&gref_mutex);
  409. priv->users--;
  410. if (priv->users == 0) {
  411. gref = priv->gref;
  412. for (i = 0; i < priv->count; i++) {
  413. gref->users--;
  414. next = list_entry(gref->next_gref.next,
  415. struct gntalloc_gref, next_gref);
  416. if (gref->users == 0)
  417. __del_gref(gref);
  418. gref = next;
  419. }
  420. kfree(priv);
  421. }
  422. mutex_unlock(&gref_mutex);
  423. }
  424. static const struct vm_operations_struct gntalloc_vmops = {
  425. .open = gntalloc_vma_open,
  426. .close = gntalloc_vma_close,
  427. };
  428. static int gntalloc_mmap(struct file *filp, struct vm_area_struct *vma)
  429. {
  430. struct gntalloc_file_private_data *priv = filp->private_data;
  431. struct gntalloc_vma_private_data *vm_priv;
  432. struct gntalloc_gref *gref;
  433. int count = vma_pages(vma);
  434. int rv, i;
  435. if (!(vma->vm_flags & VM_SHARED)) {
  436. pr_err("%s: Mapping must be shared\n", __func__);
  437. return -EINVAL;
  438. }
  439. vm_priv = kmalloc(sizeof(*vm_priv), GFP_KERNEL);
  440. if (!vm_priv)
  441. return -ENOMEM;
  442. mutex_lock(&gref_mutex);
  443. pr_debug("%s: priv %p,%p, page %lu+%d\n", __func__,
  444. priv, vm_priv, vma->vm_pgoff, count);
  445. gref = find_grefs(priv, vma->vm_pgoff << PAGE_SHIFT, count);
  446. if (gref == NULL) {
  447. rv = -ENOENT;
  448. pr_debug("%s: Could not find grant reference",
  449. __func__);
  450. kfree(vm_priv);
  451. goto out_unlock;
  452. }
  453. vm_priv->gref = gref;
  454. vm_priv->users = 1;
  455. vm_priv->count = count;
  456. vma->vm_private_data = vm_priv;
  457. vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
  458. vma->vm_ops = &gntalloc_vmops;
  459. for (i = 0; i < count; i++) {
  460. gref->users++;
  461. rv = vm_insert_page(vma, vma->vm_start + i * PAGE_SIZE,
  462. gref->page);
  463. if (rv)
  464. goto out_unlock;
  465. gref = list_entry(gref->next_file.next,
  466. struct gntalloc_gref, next_file);
  467. }
  468. rv = 0;
  469. out_unlock:
  470. mutex_unlock(&gref_mutex);
  471. return rv;
  472. }
  473. static const struct file_operations gntalloc_fops = {
  474. .owner = THIS_MODULE,
  475. .open = gntalloc_open,
  476. .release = gntalloc_release,
  477. .unlocked_ioctl = gntalloc_ioctl,
  478. .mmap = gntalloc_mmap
  479. };
  480. /*
  481. * -------------------------------------
  482. * Module creation/destruction.
  483. * -------------------------------------
  484. */
  485. static struct miscdevice gntalloc_miscdev = {
  486. .minor = MISC_DYNAMIC_MINOR,
  487. .name = "xen/gntalloc",
  488. .fops = &gntalloc_fops,
  489. };
  490. static int __init gntalloc_init(void)
  491. {
  492. int err;
  493. if (!xen_domain())
  494. return -ENODEV;
  495. err = misc_register(&gntalloc_miscdev);
  496. if (err != 0) {
  497. pr_err("Could not register misc gntalloc device\n");
  498. return err;
  499. }
  500. pr_debug("Created grant allocation device at %d,%d\n",
  501. MISC_MAJOR, gntalloc_miscdev.minor);
  502. return 0;
  503. }
  504. static void __exit gntalloc_exit(void)
  505. {
  506. misc_deregister(&gntalloc_miscdev);
  507. }
  508. module_init(gntalloc_init);
  509. module_exit(gntalloc_exit);
  510. MODULE_LICENSE("GPL");
  511. MODULE_AUTHOR("Carter Weatherly <carter.weatherly@jhuapl.edu>, "
  512. "Daniel De Graaf <dgdegra@tycho.nsa.gov>");
  513. MODULE_DESCRIPTION("User-space grant reference allocator driver");