xref: /kernel/linux/linux-5.10/lib/test_hmm.c (revision 8c2ecf20)
18c2ecf20Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci * This is a module to test the HMM (Heterogeneous Memory Management)
48c2ecf20Sopenharmony_ci * mirror and zone device private memory migration APIs of the kernel.
58c2ecf20Sopenharmony_ci * Userspace programs can register with the driver to mirror their own address
68c2ecf20Sopenharmony_ci * space and can use the device to read/write any valid virtual address.
78c2ecf20Sopenharmony_ci */
88c2ecf20Sopenharmony_ci#include <linux/init.h>
98c2ecf20Sopenharmony_ci#include <linux/fs.h>
108c2ecf20Sopenharmony_ci#include <linux/mm.h>
118c2ecf20Sopenharmony_ci#include <linux/module.h>
128c2ecf20Sopenharmony_ci#include <linux/kernel.h>
138c2ecf20Sopenharmony_ci#include <linux/cdev.h>
148c2ecf20Sopenharmony_ci#include <linux/device.h>
158c2ecf20Sopenharmony_ci#include <linux/mutex.h>
168c2ecf20Sopenharmony_ci#include <linux/rwsem.h>
178c2ecf20Sopenharmony_ci#include <linux/sched.h>
188c2ecf20Sopenharmony_ci#include <linux/slab.h>
198c2ecf20Sopenharmony_ci#include <linux/highmem.h>
208c2ecf20Sopenharmony_ci#include <linux/delay.h>
218c2ecf20Sopenharmony_ci#include <linux/pagemap.h>
228c2ecf20Sopenharmony_ci#include <linux/hmm.h>
238c2ecf20Sopenharmony_ci#include <linux/vmalloc.h>
248c2ecf20Sopenharmony_ci#include <linux/swap.h>
258c2ecf20Sopenharmony_ci#include <linux/swapops.h>
268c2ecf20Sopenharmony_ci#include <linux/sched/mm.h>
278c2ecf20Sopenharmony_ci#include <linux/platform_device.h>
288c2ecf20Sopenharmony_ci
298c2ecf20Sopenharmony_ci#include "test_hmm_uapi.h"
308c2ecf20Sopenharmony_ci
318c2ecf20Sopenharmony_ci#define DMIRROR_NDEVICES		2
328c2ecf20Sopenharmony_ci#define DMIRROR_RANGE_FAULT_TIMEOUT	1000
338c2ecf20Sopenharmony_ci#define DEVMEM_CHUNK_SIZE		(256 * 1024 * 1024U)
348c2ecf20Sopenharmony_ci#define DEVMEM_CHUNKS_RESERVE		16
358c2ecf20Sopenharmony_ci
368c2ecf20Sopenharmony_cistatic const struct dev_pagemap_ops dmirror_devmem_ops;
378c2ecf20Sopenharmony_cistatic const struct mmu_interval_notifier_ops dmirror_min_ops;
388c2ecf20Sopenharmony_cistatic dev_t dmirror_dev;
398c2ecf20Sopenharmony_ci
408c2ecf20Sopenharmony_cistruct dmirror_device;
418c2ecf20Sopenharmony_ci
428c2ecf20Sopenharmony_cistruct dmirror_bounce {
438c2ecf20Sopenharmony_ci	void			*ptr;
448c2ecf20Sopenharmony_ci	unsigned long		size;
458c2ecf20Sopenharmony_ci	unsigned long		addr;
468c2ecf20Sopenharmony_ci	unsigned long		cpages;
478c2ecf20Sopenharmony_ci};
488c2ecf20Sopenharmony_ci
498c2ecf20Sopenharmony_ci#define DPT_XA_TAG_WRITE 3UL
508c2ecf20Sopenharmony_ci
518c2ecf20Sopenharmony_ci/*
528c2ecf20Sopenharmony_ci * Data structure to track address ranges and register for mmu interval
538c2ecf20Sopenharmony_ci * notifier updates.
548c2ecf20Sopenharmony_ci */
558c2ecf20Sopenharmony_cistruct dmirror_interval {
568c2ecf20Sopenharmony_ci	struct mmu_interval_notifier	notifier;
578c2ecf20Sopenharmony_ci	struct dmirror			*dmirror;
588c2ecf20Sopenharmony_ci};
598c2ecf20Sopenharmony_ci
608c2ecf20Sopenharmony_ci/*
618c2ecf20Sopenharmony_ci * Data attached to the open device file.
628c2ecf20Sopenharmony_ci * Note that it might be shared after a fork().
638c2ecf20Sopenharmony_ci */
648c2ecf20Sopenharmony_cistruct dmirror {
658c2ecf20Sopenharmony_ci	struct dmirror_device		*mdevice;
668c2ecf20Sopenharmony_ci	struct xarray			pt;
678c2ecf20Sopenharmony_ci	struct mmu_interval_notifier	notifier;
688c2ecf20Sopenharmony_ci	struct mutex			mutex;
698c2ecf20Sopenharmony_ci};
708c2ecf20Sopenharmony_ci
718c2ecf20Sopenharmony_ci/*
728c2ecf20Sopenharmony_ci * ZONE_DEVICE pages for migration and simulating device memory.
738c2ecf20Sopenharmony_ci */
748c2ecf20Sopenharmony_cistruct dmirror_chunk {
758c2ecf20Sopenharmony_ci	struct dev_pagemap	pagemap;
768c2ecf20Sopenharmony_ci	struct dmirror_device	*mdevice;
778c2ecf20Sopenharmony_ci};
788c2ecf20Sopenharmony_ci
798c2ecf20Sopenharmony_ci/*
808c2ecf20Sopenharmony_ci * Per device data.
818c2ecf20Sopenharmony_ci */
828c2ecf20Sopenharmony_cistruct dmirror_device {
838c2ecf20Sopenharmony_ci	struct cdev		cdevice;
848c2ecf20Sopenharmony_ci	struct hmm_devmem	*devmem;
858c2ecf20Sopenharmony_ci
868c2ecf20Sopenharmony_ci	unsigned int		devmem_capacity;
878c2ecf20Sopenharmony_ci	unsigned int		devmem_count;
888c2ecf20Sopenharmony_ci	struct dmirror_chunk	**devmem_chunks;
898c2ecf20Sopenharmony_ci	struct mutex		devmem_lock;	/* protects the above */
908c2ecf20Sopenharmony_ci
918c2ecf20Sopenharmony_ci	unsigned long		calloc;
928c2ecf20Sopenharmony_ci	unsigned long		cfree;
938c2ecf20Sopenharmony_ci	struct page		*free_pages;
948c2ecf20Sopenharmony_ci	spinlock_t		lock;		/* protects the above */
958c2ecf20Sopenharmony_ci};
968c2ecf20Sopenharmony_ci
978c2ecf20Sopenharmony_cistatic struct dmirror_device dmirror_devices[DMIRROR_NDEVICES];
988c2ecf20Sopenharmony_ci
998c2ecf20Sopenharmony_cistatic int dmirror_bounce_init(struct dmirror_bounce *bounce,
1008c2ecf20Sopenharmony_ci			       unsigned long addr,
1018c2ecf20Sopenharmony_ci			       unsigned long size)
1028c2ecf20Sopenharmony_ci{
1038c2ecf20Sopenharmony_ci	bounce->addr = addr;
1048c2ecf20Sopenharmony_ci	bounce->size = size;
1058c2ecf20Sopenharmony_ci	bounce->cpages = 0;
1068c2ecf20Sopenharmony_ci	bounce->ptr = vmalloc(size);
1078c2ecf20Sopenharmony_ci	if (!bounce->ptr)
1088c2ecf20Sopenharmony_ci		return -ENOMEM;
1098c2ecf20Sopenharmony_ci	return 0;
1108c2ecf20Sopenharmony_ci}
1118c2ecf20Sopenharmony_ci
1128c2ecf20Sopenharmony_cistatic void dmirror_bounce_fini(struct dmirror_bounce *bounce)
1138c2ecf20Sopenharmony_ci{
1148c2ecf20Sopenharmony_ci	vfree(bounce->ptr);
1158c2ecf20Sopenharmony_ci}
1168c2ecf20Sopenharmony_ci
1178c2ecf20Sopenharmony_cistatic int dmirror_fops_open(struct inode *inode, struct file *filp)
1188c2ecf20Sopenharmony_ci{
1198c2ecf20Sopenharmony_ci	struct cdev *cdev = inode->i_cdev;
1208c2ecf20Sopenharmony_ci	struct dmirror *dmirror;
1218c2ecf20Sopenharmony_ci	int ret;
1228c2ecf20Sopenharmony_ci
1238c2ecf20Sopenharmony_ci	/* Mirror this process address space */
1248c2ecf20Sopenharmony_ci	dmirror = kzalloc(sizeof(*dmirror), GFP_KERNEL);
1258c2ecf20Sopenharmony_ci	if (dmirror == NULL)
1268c2ecf20Sopenharmony_ci		return -ENOMEM;
1278c2ecf20Sopenharmony_ci
1288c2ecf20Sopenharmony_ci	dmirror->mdevice = container_of(cdev, struct dmirror_device, cdevice);
1298c2ecf20Sopenharmony_ci	mutex_init(&dmirror->mutex);
1308c2ecf20Sopenharmony_ci	xa_init(&dmirror->pt);
1318c2ecf20Sopenharmony_ci
1328c2ecf20Sopenharmony_ci	ret = mmu_interval_notifier_insert(&dmirror->notifier, current->mm,
1338c2ecf20Sopenharmony_ci				0, ULONG_MAX & PAGE_MASK, &dmirror_min_ops);
1348c2ecf20Sopenharmony_ci	if (ret) {
1358c2ecf20Sopenharmony_ci		kfree(dmirror);
1368c2ecf20Sopenharmony_ci		return ret;
1378c2ecf20Sopenharmony_ci	}
1388c2ecf20Sopenharmony_ci
1398c2ecf20Sopenharmony_ci	filp->private_data = dmirror;
1408c2ecf20Sopenharmony_ci	return 0;
1418c2ecf20Sopenharmony_ci}
1428c2ecf20Sopenharmony_ci
1438c2ecf20Sopenharmony_cistatic int dmirror_fops_release(struct inode *inode, struct file *filp)
1448c2ecf20Sopenharmony_ci{
1458c2ecf20Sopenharmony_ci	struct dmirror *dmirror = filp->private_data;
1468c2ecf20Sopenharmony_ci
1478c2ecf20Sopenharmony_ci	mmu_interval_notifier_remove(&dmirror->notifier);
1488c2ecf20Sopenharmony_ci	xa_destroy(&dmirror->pt);
1498c2ecf20Sopenharmony_ci	kfree(dmirror);
1508c2ecf20Sopenharmony_ci	return 0;
1518c2ecf20Sopenharmony_ci}
1528c2ecf20Sopenharmony_ci
1538c2ecf20Sopenharmony_cistatic struct dmirror_device *dmirror_page_to_device(struct page *page)
1548c2ecf20Sopenharmony_ci
1558c2ecf20Sopenharmony_ci{
1568c2ecf20Sopenharmony_ci	return container_of(page->pgmap, struct dmirror_chunk,
1578c2ecf20Sopenharmony_ci			    pagemap)->mdevice;
1588c2ecf20Sopenharmony_ci}
1598c2ecf20Sopenharmony_ci
1608c2ecf20Sopenharmony_cistatic int dmirror_do_fault(struct dmirror *dmirror, struct hmm_range *range)
1618c2ecf20Sopenharmony_ci{
1628c2ecf20Sopenharmony_ci	unsigned long *pfns = range->hmm_pfns;
1638c2ecf20Sopenharmony_ci	unsigned long pfn;
1648c2ecf20Sopenharmony_ci
1658c2ecf20Sopenharmony_ci	for (pfn = (range->start >> PAGE_SHIFT);
1668c2ecf20Sopenharmony_ci	     pfn < (range->end >> PAGE_SHIFT);
1678c2ecf20Sopenharmony_ci	     pfn++, pfns++) {
1688c2ecf20Sopenharmony_ci		struct page *page;
1698c2ecf20Sopenharmony_ci		void *entry;
1708c2ecf20Sopenharmony_ci
1718c2ecf20Sopenharmony_ci		/*
1728c2ecf20Sopenharmony_ci		 * Since we asked for hmm_range_fault() to populate pages,
1738c2ecf20Sopenharmony_ci		 * it shouldn't return an error entry on success.
1748c2ecf20Sopenharmony_ci		 */
1758c2ecf20Sopenharmony_ci		WARN_ON(*pfns & HMM_PFN_ERROR);
1768c2ecf20Sopenharmony_ci		WARN_ON(!(*pfns & HMM_PFN_VALID));
1778c2ecf20Sopenharmony_ci
1788c2ecf20Sopenharmony_ci		page = hmm_pfn_to_page(*pfns);
1798c2ecf20Sopenharmony_ci		WARN_ON(!page);
1808c2ecf20Sopenharmony_ci
1818c2ecf20Sopenharmony_ci		entry = page;
1828c2ecf20Sopenharmony_ci		if (*pfns & HMM_PFN_WRITE)
1838c2ecf20Sopenharmony_ci			entry = xa_tag_pointer(entry, DPT_XA_TAG_WRITE);
1848c2ecf20Sopenharmony_ci		else if (WARN_ON(range->default_flags & HMM_PFN_WRITE))
1858c2ecf20Sopenharmony_ci			return -EFAULT;
1868c2ecf20Sopenharmony_ci		entry = xa_store(&dmirror->pt, pfn, entry, GFP_ATOMIC);
1878c2ecf20Sopenharmony_ci		if (xa_is_err(entry))
1888c2ecf20Sopenharmony_ci			return xa_err(entry);
1898c2ecf20Sopenharmony_ci	}
1908c2ecf20Sopenharmony_ci
1918c2ecf20Sopenharmony_ci	return 0;
1928c2ecf20Sopenharmony_ci}
1938c2ecf20Sopenharmony_ci
1948c2ecf20Sopenharmony_cistatic void dmirror_do_update(struct dmirror *dmirror, unsigned long start,
1958c2ecf20Sopenharmony_ci			      unsigned long end)
1968c2ecf20Sopenharmony_ci{
1978c2ecf20Sopenharmony_ci	unsigned long pfn;
1988c2ecf20Sopenharmony_ci	void *entry;
1998c2ecf20Sopenharmony_ci
2008c2ecf20Sopenharmony_ci	/*
2018c2ecf20Sopenharmony_ci	 * The XArray doesn't hold references to pages since it relies on
2028c2ecf20Sopenharmony_ci	 * the mmu notifier to clear page pointers when they become stale.
2038c2ecf20Sopenharmony_ci	 * Therefore, it is OK to just clear the entry.
2048c2ecf20Sopenharmony_ci	 */
2058c2ecf20Sopenharmony_ci	xa_for_each_range(&dmirror->pt, pfn, entry, start >> PAGE_SHIFT,
2068c2ecf20Sopenharmony_ci			  end >> PAGE_SHIFT)
2078c2ecf20Sopenharmony_ci		xa_erase(&dmirror->pt, pfn);
2088c2ecf20Sopenharmony_ci}
2098c2ecf20Sopenharmony_ci
2108c2ecf20Sopenharmony_cistatic bool dmirror_interval_invalidate(struct mmu_interval_notifier *mni,
2118c2ecf20Sopenharmony_ci				const struct mmu_notifier_range *range,
2128c2ecf20Sopenharmony_ci				unsigned long cur_seq)
2138c2ecf20Sopenharmony_ci{
2148c2ecf20Sopenharmony_ci	struct dmirror *dmirror = container_of(mni, struct dmirror, notifier);
2158c2ecf20Sopenharmony_ci
2168c2ecf20Sopenharmony_ci	/*
2178c2ecf20Sopenharmony_ci	 * Ignore invalidation callbacks for device private pages since
2188c2ecf20Sopenharmony_ci	 * the invalidation is handled as part of the migration process.
2198c2ecf20Sopenharmony_ci	 */
2208c2ecf20Sopenharmony_ci	if (range->event == MMU_NOTIFY_MIGRATE &&
2218c2ecf20Sopenharmony_ci	    range->migrate_pgmap_owner == dmirror->mdevice)
2228c2ecf20Sopenharmony_ci		return true;
2238c2ecf20Sopenharmony_ci
2248c2ecf20Sopenharmony_ci	if (mmu_notifier_range_blockable(range))
2258c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
2268c2ecf20Sopenharmony_ci	else if (!mutex_trylock(&dmirror->mutex))
2278c2ecf20Sopenharmony_ci		return false;
2288c2ecf20Sopenharmony_ci
2298c2ecf20Sopenharmony_ci	mmu_interval_set_seq(mni, cur_seq);
2308c2ecf20Sopenharmony_ci	dmirror_do_update(dmirror, range->start, range->end);
2318c2ecf20Sopenharmony_ci
2328c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
2338c2ecf20Sopenharmony_ci	return true;
2348c2ecf20Sopenharmony_ci}
2358c2ecf20Sopenharmony_ci
2368c2ecf20Sopenharmony_cistatic const struct mmu_interval_notifier_ops dmirror_min_ops = {
2378c2ecf20Sopenharmony_ci	.invalidate = dmirror_interval_invalidate,
2388c2ecf20Sopenharmony_ci};
2398c2ecf20Sopenharmony_ci
2408c2ecf20Sopenharmony_cistatic int dmirror_range_fault(struct dmirror *dmirror,
2418c2ecf20Sopenharmony_ci				struct hmm_range *range)
2428c2ecf20Sopenharmony_ci{
2438c2ecf20Sopenharmony_ci	struct mm_struct *mm = dmirror->notifier.mm;
2448c2ecf20Sopenharmony_ci	unsigned long timeout =
2458c2ecf20Sopenharmony_ci		jiffies + msecs_to_jiffies(HMM_RANGE_DEFAULT_TIMEOUT);
2468c2ecf20Sopenharmony_ci	int ret;
2478c2ecf20Sopenharmony_ci
2488c2ecf20Sopenharmony_ci	while (true) {
2498c2ecf20Sopenharmony_ci		if (time_after(jiffies, timeout)) {
2508c2ecf20Sopenharmony_ci			ret = -EBUSY;
2518c2ecf20Sopenharmony_ci			goto out;
2528c2ecf20Sopenharmony_ci		}
2538c2ecf20Sopenharmony_ci
2548c2ecf20Sopenharmony_ci		range->notifier_seq = mmu_interval_read_begin(range->notifier);
2558c2ecf20Sopenharmony_ci		mmap_read_lock(mm);
2568c2ecf20Sopenharmony_ci		ret = hmm_range_fault(range);
2578c2ecf20Sopenharmony_ci		mmap_read_unlock(mm);
2588c2ecf20Sopenharmony_ci		if (ret) {
2598c2ecf20Sopenharmony_ci			if (ret == -EBUSY)
2608c2ecf20Sopenharmony_ci				continue;
2618c2ecf20Sopenharmony_ci			goto out;
2628c2ecf20Sopenharmony_ci		}
2638c2ecf20Sopenharmony_ci
2648c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
2658c2ecf20Sopenharmony_ci		if (mmu_interval_read_retry(range->notifier,
2668c2ecf20Sopenharmony_ci					    range->notifier_seq)) {
2678c2ecf20Sopenharmony_ci			mutex_unlock(&dmirror->mutex);
2688c2ecf20Sopenharmony_ci			continue;
2698c2ecf20Sopenharmony_ci		}
2708c2ecf20Sopenharmony_ci		break;
2718c2ecf20Sopenharmony_ci	}
2728c2ecf20Sopenharmony_ci
2738c2ecf20Sopenharmony_ci	ret = dmirror_do_fault(dmirror, range);
2748c2ecf20Sopenharmony_ci
2758c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
2768c2ecf20Sopenharmony_ciout:
2778c2ecf20Sopenharmony_ci	return ret;
2788c2ecf20Sopenharmony_ci}
2798c2ecf20Sopenharmony_ci
2808c2ecf20Sopenharmony_cistatic int dmirror_fault(struct dmirror *dmirror, unsigned long start,
2818c2ecf20Sopenharmony_ci			 unsigned long end, bool write)
2828c2ecf20Sopenharmony_ci{
2838c2ecf20Sopenharmony_ci	struct mm_struct *mm = dmirror->notifier.mm;
2848c2ecf20Sopenharmony_ci	unsigned long addr;
2858c2ecf20Sopenharmony_ci	unsigned long pfns[64];
2868c2ecf20Sopenharmony_ci	struct hmm_range range = {
2878c2ecf20Sopenharmony_ci		.notifier = &dmirror->notifier,
2888c2ecf20Sopenharmony_ci		.hmm_pfns = pfns,
2898c2ecf20Sopenharmony_ci		.pfn_flags_mask = 0,
2908c2ecf20Sopenharmony_ci		.default_flags =
2918c2ecf20Sopenharmony_ci			HMM_PFN_REQ_FAULT | (write ? HMM_PFN_REQ_WRITE : 0),
2928c2ecf20Sopenharmony_ci		.dev_private_owner = dmirror->mdevice,
2938c2ecf20Sopenharmony_ci	};
2948c2ecf20Sopenharmony_ci	int ret = 0;
2958c2ecf20Sopenharmony_ci
2968c2ecf20Sopenharmony_ci	/* Since the mm is for the mirrored process, get a reference first. */
2978c2ecf20Sopenharmony_ci	if (!mmget_not_zero(mm))
2988c2ecf20Sopenharmony_ci		return 0;
2998c2ecf20Sopenharmony_ci
3008c2ecf20Sopenharmony_ci	for (addr = start; addr < end; addr = range.end) {
3018c2ecf20Sopenharmony_ci		range.start = addr;
3028c2ecf20Sopenharmony_ci		range.end = min(addr + (ARRAY_SIZE(pfns) << PAGE_SHIFT), end);
3038c2ecf20Sopenharmony_ci
3048c2ecf20Sopenharmony_ci		ret = dmirror_range_fault(dmirror, &range);
3058c2ecf20Sopenharmony_ci		if (ret)
3068c2ecf20Sopenharmony_ci			break;
3078c2ecf20Sopenharmony_ci	}
3088c2ecf20Sopenharmony_ci
3098c2ecf20Sopenharmony_ci	mmput(mm);
3108c2ecf20Sopenharmony_ci	return ret;
3118c2ecf20Sopenharmony_ci}
3128c2ecf20Sopenharmony_ci
3138c2ecf20Sopenharmony_cistatic int dmirror_do_read(struct dmirror *dmirror, unsigned long start,
3148c2ecf20Sopenharmony_ci			   unsigned long end, struct dmirror_bounce *bounce)
3158c2ecf20Sopenharmony_ci{
3168c2ecf20Sopenharmony_ci	unsigned long pfn;
3178c2ecf20Sopenharmony_ci	void *ptr;
3188c2ecf20Sopenharmony_ci
3198c2ecf20Sopenharmony_ci	ptr = bounce->ptr + ((start - bounce->addr) & PAGE_MASK);
3208c2ecf20Sopenharmony_ci
3218c2ecf20Sopenharmony_ci	for (pfn = start >> PAGE_SHIFT; pfn < (end >> PAGE_SHIFT); pfn++) {
3228c2ecf20Sopenharmony_ci		void *entry;
3238c2ecf20Sopenharmony_ci		struct page *page;
3248c2ecf20Sopenharmony_ci		void *tmp;
3258c2ecf20Sopenharmony_ci
3268c2ecf20Sopenharmony_ci		entry = xa_load(&dmirror->pt, pfn);
3278c2ecf20Sopenharmony_ci		page = xa_untag_pointer(entry);
3288c2ecf20Sopenharmony_ci		if (!page)
3298c2ecf20Sopenharmony_ci			return -ENOENT;
3308c2ecf20Sopenharmony_ci
3318c2ecf20Sopenharmony_ci		tmp = kmap(page);
3328c2ecf20Sopenharmony_ci		memcpy(ptr, tmp, PAGE_SIZE);
3338c2ecf20Sopenharmony_ci		kunmap(page);
3348c2ecf20Sopenharmony_ci
3358c2ecf20Sopenharmony_ci		ptr += PAGE_SIZE;
3368c2ecf20Sopenharmony_ci		bounce->cpages++;
3378c2ecf20Sopenharmony_ci	}
3388c2ecf20Sopenharmony_ci
3398c2ecf20Sopenharmony_ci	return 0;
3408c2ecf20Sopenharmony_ci}
3418c2ecf20Sopenharmony_ci
3428c2ecf20Sopenharmony_cistatic int dmirror_read(struct dmirror *dmirror, struct hmm_dmirror_cmd *cmd)
3438c2ecf20Sopenharmony_ci{
3448c2ecf20Sopenharmony_ci	struct dmirror_bounce bounce;
3458c2ecf20Sopenharmony_ci	unsigned long start, end;
3468c2ecf20Sopenharmony_ci	unsigned long size = cmd->npages << PAGE_SHIFT;
3478c2ecf20Sopenharmony_ci	int ret;
3488c2ecf20Sopenharmony_ci
3498c2ecf20Sopenharmony_ci	start = cmd->addr;
3508c2ecf20Sopenharmony_ci	end = start + size;
3518c2ecf20Sopenharmony_ci	if (end < start)
3528c2ecf20Sopenharmony_ci		return -EINVAL;
3538c2ecf20Sopenharmony_ci
3548c2ecf20Sopenharmony_ci	ret = dmirror_bounce_init(&bounce, start, size);
3558c2ecf20Sopenharmony_ci	if (ret)
3568c2ecf20Sopenharmony_ci		return ret;
3578c2ecf20Sopenharmony_ci
3588c2ecf20Sopenharmony_ci	while (1) {
3598c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
3608c2ecf20Sopenharmony_ci		ret = dmirror_do_read(dmirror, start, end, &bounce);
3618c2ecf20Sopenharmony_ci		mutex_unlock(&dmirror->mutex);
3628c2ecf20Sopenharmony_ci		if (ret != -ENOENT)
3638c2ecf20Sopenharmony_ci			break;
3648c2ecf20Sopenharmony_ci
3658c2ecf20Sopenharmony_ci		start = cmd->addr + (bounce.cpages << PAGE_SHIFT);
3668c2ecf20Sopenharmony_ci		ret = dmirror_fault(dmirror, start, end, false);
3678c2ecf20Sopenharmony_ci		if (ret)
3688c2ecf20Sopenharmony_ci			break;
3698c2ecf20Sopenharmony_ci		cmd->faults++;
3708c2ecf20Sopenharmony_ci	}
3718c2ecf20Sopenharmony_ci
3728c2ecf20Sopenharmony_ci	if (ret == 0) {
3738c2ecf20Sopenharmony_ci		if (copy_to_user(u64_to_user_ptr(cmd->ptr), bounce.ptr,
3748c2ecf20Sopenharmony_ci				 bounce.size))
3758c2ecf20Sopenharmony_ci			ret = -EFAULT;
3768c2ecf20Sopenharmony_ci	}
3778c2ecf20Sopenharmony_ci	cmd->cpages = bounce.cpages;
3788c2ecf20Sopenharmony_ci	dmirror_bounce_fini(&bounce);
3798c2ecf20Sopenharmony_ci	return ret;
3808c2ecf20Sopenharmony_ci}
3818c2ecf20Sopenharmony_ci
3828c2ecf20Sopenharmony_cistatic int dmirror_do_write(struct dmirror *dmirror, unsigned long start,
3838c2ecf20Sopenharmony_ci			    unsigned long end, struct dmirror_bounce *bounce)
3848c2ecf20Sopenharmony_ci{
3858c2ecf20Sopenharmony_ci	unsigned long pfn;
3868c2ecf20Sopenharmony_ci	void *ptr;
3878c2ecf20Sopenharmony_ci
3888c2ecf20Sopenharmony_ci	ptr = bounce->ptr + ((start - bounce->addr) & PAGE_MASK);
3898c2ecf20Sopenharmony_ci
3908c2ecf20Sopenharmony_ci	for (pfn = start >> PAGE_SHIFT; pfn < (end >> PAGE_SHIFT); pfn++) {
3918c2ecf20Sopenharmony_ci		void *entry;
3928c2ecf20Sopenharmony_ci		struct page *page;
3938c2ecf20Sopenharmony_ci		void *tmp;
3948c2ecf20Sopenharmony_ci
3958c2ecf20Sopenharmony_ci		entry = xa_load(&dmirror->pt, pfn);
3968c2ecf20Sopenharmony_ci		page = xa_untag_pointer(entry);
3978c2ecf20Sopenharmony_ci		if (!page || xa_pointer_tag(entry) != DPT_XA_TAG_WRITE)
3988c2ecf20Sopenharmony_ci			return -ENOENT;
3998c2ecf20Sopenharmony_ci
4008c2ecf20Sopenharmony_ci		tmp = kmap(page);
4018c2ecf20Sopenharmony_ci		memcpy(tmp, ptr, PAGE_SIZE);
4028c2ecf20Sopenharmony_ci		kunmap(page);
4038c2ecf20Sopenharmony_ci
4048c2ecf20Sopenharmony_ci		ptr += PAGE_SIZE;
4058c2ecf20Sopenharmony_ci		bounce->cpages++;
4068c2ecf20Sopenharmony_ci	}
4078c2ecf20Sopenharmony_ci
4088c2ecf20Sopenharmony_ci	return 0;
4098c2ecf20Sopenharmony_ci}
4108c2ecf20Sopenharmony_ci
4118c2ecf20Sopenharmony_cistatic int dmirror_write(struct dmirror *dmirror, struct hmm_dmirror_cmd *cmd)
4128c2ecf20Sopenharmony_ci{
4138c2ecf20Sopenharmony_ci	struct dmirror_bounce bounce;
4148c2ecf20Sopenharmony_ci	unsigned long start, end;
4158c2ecf20Sopenharmony_ci	unsigned long size = cmd->npages << PAGE_SHIFT;
4168c2ecf20Sopenharmony_ci	int ret;
4178c2ecf20Sopenharmony_ci
4188c2ecf20Sopenharmony_ci	start = cmd->addr;
4198c2ecf20Sopenharmony_ci	end = start + size;
4208c2ecf20Sopenharmony_ci	if (end < start)
4218c2ecf20Sopenharmony_ci		return -EINVAL;
4228c2ecf20Sopenharmony_ci
4238c2ecf20Sopenharmony_ci	ret = dmirror_bounce_init(&bounce, start, size);
4248c2ecf20Sopenharmony_ci	if (ret)
4258c2ecf20Sopenharmony_ci		return ret;
4268c2ecf20Sopenharmony_ci	if (copy_from_user(bounce.ptr, u64_to_user_ptr(cmd->ptr),
4278c2ecf20Sopenharmony_ci			   bounce.size)) {
4288c2ecf20Sopenharmony_ci		ret = -EFAULT;
4298c2ecf20Sopenharmony_ci		goto fini;
4308c2ecf20Sopenharmony_ci	}
4318c2ecf20Sopenharmony_ci
4328c2ecf20Sopenharmony_ci	while (1) {
4338c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
4348c2ecf20Sopenharmony_ci		ret = dmirror_do_write(dmirror, start, end, &bounce);
4358c2ecf20Sopenharmony_ci		mutex_unlock(&dmirror->mutex);
4368c2ecf20Sopenharmony_ci		if (ret != -ENOENT)
4378c2ecf20Sopenharmony_ci			break;
4388c2ecf20Sopenharmony_ci
4398c2ecf20Sopenharmony_ci		start = cmd->addr + (bounce.cpages << PAGE_SHIFT);
4408c2ecf20Sopenharmony_ci		ret = dmirror_fault(dmirror, start, end, true);
4418c2ecf20Sopenharmony_ci		if (ret)
4428c2ecf20Sopenharmony_ci			break;
4438c2ecf20Sopenharmony_ci		cmd->faults++;
4448c2ecf20Sopenharmony_ci	}
4458c2ecf20Sopenharmony_ci
4468c2ecf20Sopenharmony_cifini:
4478c2ecf20Sopenharmony_ci	cmd->cpages = bounce.cpages;
4488c2ecf20Sopenharmony_ci	dmirror_bounce_fini(&bounce);
4498c2ecf20Sopenharmony_ci	return ret;
4508c2ecf20Sopenharmony_ci}
4518c2ecf20Sopenharmony_ci
4528c2ecf20Sopenharmony_cistatic bool dmirror_allocate_chunk(struct dmirror_device *mdevice,
4538c2ecf20Sopenharmony_ci				   struct page **ppage)
4548c2ecf20Sopenharmony_ci{
4558c2ecf20Sopenharmony_ci	struct dmirror_chunk *devmem;
4568c2ecf20Sopenharmony_ci	struct resource *res;
4578c2ecf20Sopenharmony_ci	unsigned long pfn;
4588c2ecf20Sopenharmony_ci	unsigned long pfn_first;
4598c2ecf20Sopenharmony_ci	unsigned long pfn_last;
4608c2ecf20Sopenharmony_ci	void *ptr;
4618c2ecf20Sopenharmony_ci
4628c2ecf20Sopenharmony_ci	devmem = kzalloc(sizeof(*devmem), GFP_KERNEL);
4638c2ecf20Sopenharmony_ci	if (!devmem)
4648c2ecf20Sopenharmony_ci		return false;
4658c2ecf20Sopenharmony_ci
4668c2ecf20Sopenharmony_ci	res = request_free_mem_region(&iomem_resource, DEVMEM_CHUNK_SIZE,
4678c2ecf20Sopenharmony_ci				      "hmm_dmirror");
4688c2ecf20Sopenharmony_ci	if (IS_ERR(res))
4698c2ecf20Sopenharmony_ci		goto err_devmem;
4708c2ecf20Sopenharmony_ci
4718c2ecf20Sopenharmony_ci	devmem->pagemap.type = MEMORY_DEVICE_PRIVATE;
4728c2ecf20Sopenharmony_ci	devmem->pagemap.range.start = res->start;
4738c2ecf20Sopenharmony_ci	devmem->pagemap.range.end = res->end;
4748c2ecf20Sopenharmony_ci	devmem->pagemap.nr_range = 1;
4758c2ecf20Sopenharmony_ci	devmem->pagemap.ops = &dmirror_devmem_ops;
4768c2ecf20Sopenharmony_ci	devmem->pagemap.owner = mdevice;
4778c2ecf20Sopenharmony_ci
4788c2ecf20Sopenharmony_ci	mutex_lock(&mdevice->devmem_lock);
4798c2ecf20Sopenharmony_ci
4808c2ecf20Sopenharmony_ci	if (mdevice->devmem_count == mdevice->devmem_capacity) {
4818c2ecf20Sopenharmony_ci		struct dmirror_chunk **new_chunks;
4828c2ecf20Sopenharmony_ci		unsigned int new_capacity;
4838c2ecf20Sopenharmony_ci
4848c2ecf20Sopenharmony_ci		new_capacity = mdevice->devmem_capacity +
4858c2ecf20Sopenharmony_ci				DEVMEM_CHUNKS_RESERVE;
4868c2ecf20Sopenharmony_ci		new_chunks = krealloc(mdevice->devmem_chunks,
4878c2ecf20Sopenharmony_ci				sizeof(new_chunks[0]) * new_capacity,
4888c2ecf20Sopenharmony_ci				GFP_KERNEL);
4898c2ecf20Sopenharmony_ci		if (!new_chunks)
4908c2ecf20Sopenharmony_ci			goto err_release;
4918c2ecf20Sopenharmony_ci		mdevice->devmem_capacity = new_capacity;
4928c2ecf20Sopenharmony_ci		mdevice->devmem_chunks = new_chunks;
4938c2ecf20Sopenharmony_ci	}
4948c2ecf20Sopenharmony_ci
4958c2ecf20Sopenharmony_ci	ptr = memremap_pages(&devmem->pagemap, numa_node_id());
4968c2ecf20Sopenharmony_ci	if (IS_ERR(ptr))
4978c2ecf20Sopenharmony_ci		goto err_release;
4988c2ecf20Sopenharmony_ci
4998c2ecf20Sopenharmony_ci	devmem->mdevice = mdevice;
5008c2ecf20Sopenharmony_ci	pfn_first = devmem->pagemap.range.start >> PAGE_SHIFT;
5018c2ecf20Sopenharmony_ci	pfn_last = pfn_first + (range_len(&devmem->pagemap.range) >> PAGE_SHIFT);
5028c2ecf20Sopenharmony_ci	mdevice->devmem_chunks[mdevice->devmem_count++] = devmem;
5038c2ecf20Sopenharmony_ci
5048c2ecf20Sopenharmony_ci	mutex_unlock(&mdevice->devmem_lock);
5058c2ecf20Sopenharmony_ci
5068c2ecf20Sopenharmony_ci	pr_info("added new %u MB chunk (total %u chunks, %u MB) PFNs [0x%lx 0x%lx)\n",
5078c2ecf20Sopenharmony_ci		DEVMEM_CHUNK_SIZE / (1024 * 1024),
5088c2ecf20Sopenharmony_ci		mdevice->devmem_count,
5098c2ecf20Sopenharmony_ci		mdevice->devmem_count * (DEVMEM_CHUNK_SIZE / (1024 * 1024)),
5108c2ecf20Sopenharmony_ci		pfn_first, pfn_last);
5118c2ecf20Sopenharmony_ci
5128c2ecf20Sopenharmony_ci	spin_lock(&mdevice->lock);
5138c2ecf20Sopenharmony_ci	for (pfn = pfn_first; pfn < pfn_last; pfn++) {
5148c2ecf20Sopenharmony_ci		struct page *page = pfn_to_page(pfn);
5158c2ecf20Sopenharmony_ci
5168c2ecf20Sopenharmony_ci		page->zone_device_data = mdevice->free_pages;
5178c2ecf20Sopenharmony_ci		mdevice->free_pages = page;
5188c2ecf20Sopenharmony_ci	}
5198c2ecf20Sopenharmony_ci	if (ppage) {
5208c2ecf20Sopenharmony_ci		*ppage = mdevice->free_pages;
5218c2ecf20Sopenharmony_ci		mdevice->free_pages = (*ppage)->zone_device_data;
5228c2ecf20Sopenharmony_ci		mdevice->calloc++;
5238c2ecf20Sopenharmony_ci	}
5248c2ecf20Sopenharmony_ci	spin_unlock(&mdevice->lock);
5258c2ecf20Sopenharmony_ci
5268c2ecf20Sopenharmony_ci	return true;
5278c2ecf20Sopenharmony_ci
5288c2ecf20Sopenharmony_cierr_release:
5298c2ecf20Sopenharmony_ci	mutex_unlock(&mdevice->devmem_lock);
5308c2ecf20Sopenharmony_ci	release_mem_region(devmem->pagemap.range.start, range_len(&devmem->pagemap.range));
5318c2ecf20Sopenharmony_cierr_devmem:
5328c2ecf20Sopenharmony_ci	kfree(devmem);
5338c2ecf20Sopenharmony_ci
5348c2ecf20Sopenharmony_ci	return false;
5358c2ecf20Sopenharmony_ci}
5368c2ecf20Sopenharmony_ci
5378c2ecf20Sopenharmony_cistatic struct page *dmirror_devmem_alloc_page(struct dmirror_device *mdevice)
5388c2ecf20Sopenharmony_ci{
5398c2ecf20Sopenharmony_ci	struct page *dpage = NULL;
5408c2ecf20Sopenharmony_ci	struct page *rpage;
5418c2ecf20Sopenharmony_ci
5428c2ecf20Sopenharmony_ci	/*
5438c2ecf20Sopenharmony_ci	 * This is a fake device so we alloc real system memory to store
5448c2ecf20Sopenharmony_ci	 * our device memory.
5458c2ecf20Sopenharmony_ci	 */
5468c2ecf20Sopenharmony_ci	rpage = alloc_page(GFP_HIGHUSER);
5478c2ecf20Sopenharmony_ci	if (!rpage)
5488c2ecf20Sopenharmony_ci		return NULL;
5498c2ecf20Sopenharmony_ci
5508c2ecf20Sopenharmony_ci	spin_lock(&mdevice->lock);
5518c2ecf20Sopenharmony_ci
5528c2ecf20Sopenharmony_ci	if (mdevice->free_pages) {
5538c2ecf20Sopenharmony_ci		dpage = mdevice->free_pages;
5548c2ecf20Sopenharmony_ci		mdevice->free_pages = dpage->zone_device_data;
5558c2ecf20Sopenharmony_ci		mdevice->calloc++;
5568c2ecf20Sopenharmony_ci		spin_unlock(&mdevice->lock);
5578c2ecf20Sopenharmony_ci	} else {
5588c2ecf20Sopenharmony_ci		spin_unlock(&mdevice->lock);
5598c2ecf20Sopenharmony_ci		if (!dmirror_allocate_chunk(mdevice, &dpage))
5608c2ecf20Sopenharmony_ci			goto error;
5618c2ecf20Sopenharmony_ci	}
5628c2ecf20Sopenharmony_ci
5638c2ecf20Sopenharmony_ci	dpage->zone_device_data = rpage;
5648c2ecf20Sopenharmony_ci	get_page(dpage);
5658c2ecf20Sopenharmony_ci	lock_page(dpage);
5668c2ecf20Sopenharmony_ci	return dpage;
5678c2ecf20Sopenharmony_ci
5688c2ecf20Sopenharmony_cierror:
5698c2ecf20Sopenharmony_ci	__free_page(rpage);
5708c2ecf20Sopenharmony_ci	return NULL;
5718c2ecf20Sopenharmony_ci}
5728c2ecf20Sopenharmony_ci
5738c2ecf20Sopenharmony_cistatic void dmirror_migrate_alloc_and_copy(struct migrate_vma *args,
5748c2ecf20Sopenharmony_ci					   struct dmirror *dmirror)
5758c2ecf20Sopenharmony_ci{
5768c2ecf20Sopenharmony_ci	struct dmirror_device *mdevice = dmirror->mdevice;
5778c2ecf20Sopenharmony_ci	const unsigned long *src = args->src;
5788c2ecf20Sopenharmony_ci	unsigned long *dst = args->dst;
5798c2ecf20Sopenharmony_ci	unsigned long addr;
5808c2ecf20Sopenharmony_ci
5818c2ecf20Sopenharmony_ci	for (addr = args->start; addr < args->end; addr += PAGE_SIZE,
5828c2ecf20Sopenharmony_ci						   src++, dst++) {
5838c2ecf20Sopenharmony_ci		struct page *spage;
5848c2ecf20Sopenharmony_ci		struct page *dpage;
5858c2ecf20Sopenharmony_ci		struct page *rpage;
5868c2ecf20Sopenharmony_ci
5878c2ecf20Sopenharmony_ci		if (!(*src & MIGRATE_PFN_MIGRATE))
5888c2ecf20Sopenharmony_ci			continue;
5898c2ecf20Sopenharmony_ci
5908c2ecf20Sopenharmony_ci		/*
5918c2ecf20Sopenharmony_ci		 * Note that spage might be NULL which is OK since it is an
5928c2ecf20Sopenharmony_ci		 * unallocated pte_none() or read-only zero page.
5938c2ecf20Sopenharmony_ci		 */
5948c2ecf20Sopenharmony_ci		spage = migrate_pfn_to_page(*src);
5958c2ecf20Sopenharmony_ci
5968c2ecf20Sopenharmony_ci		dpage = dmirror_devmem_alloc_page(mdevice);
5978c2ecf20Sopenharmony_ci		if (!dpage)
5988c2ecf20Sopenharmony_ci			continue;
5998c2ecf20Sopenharmony_ci
6008c2ecf20Sopenharmony_ci		rpage = dpage->zone_device_data;
6018c2ecf20Sopenharmony_ci		if (spage)
6028c2ecf20Sopenharmony_ci			copy_highpage(rpage, spage);
6038c2ecf20Sopenharmony_ci		else
6048c2ecf20Sopenharmony_ci			clear_highpage(rpage);
6058c2ecf20Sopenharmony_ci
6068c2ecf20Sopenharmony_ci		/*
6078c2ecf20Sopenharmony_ci		 * Normally, a device would use the page->zone_device_data to
6088c2ecf20Sopenharmony_ci		 * point to the mirror but here we use it to hold the page for
6098c2ecf20Sopenharmony_ci		 * the simulated device memory and that page holds the pointer
6108c2ecf20Sopenharmony_ci		 * to the mirror.
6118c2ecf20Sopenharmony_ci		 */
6128c2ecf20Sopenharmony_ci		rpage->zone_device_data = dmirror;
6138c2ecf20Sopenharmony_ci
6148c2ecf20Sopenharmony_ci		*dst = migrate_pfn(page_to_pfn(dpage)) |
6158c2ecf20Sopenharmony_ci			    MIGRATE_PFN_LOCKED;
6168c2ecf20Sopenharmony_ci		if ((*src & MIGRATE_PFN_WRITE) ||
6178c2ecf20Sopenharmony_ci		    (!spage && args->vma->vm_flags & VM_WRITE))
6188c2ecf20Sopenharmony_ci			*dst |= MIGRATE_PFN_WRITE;
6198c2ecf20Sopenharmony_ci	}
6208c2ecf20Sopenharmony_ci}
6218c2ecf20Sopenharmony_ci
6228c2ecf20Sopenharmony_cistatic int dmirror_migrate_finalize_and_map(struct migrate_vma *args,
6238c2ecf20Sopenharmony_ci					    struct dmirror *dmirror)
6248c2ecf20Sopenharmony_ci{
6258c2ecf20Sopenharmony_ci	unsigned long start = args->start;
6268c2ecf20Sopenharmony_ci	unsigned long end = args->end;
6278c2ecf20Sopenharmony_ci	const unsigned long *src = args->src;
6288c2ecf20Sopenharmony_ci	const unsigned long *dst = args->dst;
6298c2ecf20Sopenharmony_ci	unsigned long pfn;
6308c2ecf20Sopenharmony_ci
6318c2ecf20Sopenharmony_ci	/* Map the migrated pages into the device's page tables. */
6328c2ecf20Sopenharmony_ci	mutex_lock(&dmirror->mutex);
6338c2ecf20Sopenharmony_ci
6348c2ecf20Sopenharmony_ci	for (pfn = start >> PAGE_SHIFT; pfn < (end >> PAGE_SHIFT); pfn++,
6358c2ecf20Sopenharmony_ci								src++, dst++) {
6368c2ecf20Sopenharmony_ci		struct page *dpage;
6378c2ecf20Sopenharmony_ci		void *entry;
6388c2ecf20Sopenharmony_ci
6398c2ecf20Sopenharmony_ci		if (!(*src & MIGRATE_PFN_MIGRATE))
6408c2ecf20Sopenharmony_ci			continue;
6418c2ecf20Sopenharmony_ci
6428c2ecf20Sopenharmony_ci		dpage = migrate_pfn_to_page(*dst);
6438c2ecf20Sopenharmony_ci		if (!dpage)
6448c2ecf20Sopenharmony_ci			continue;
6458c2ecf20Sopenharmony_ci
6468c2ecf20Sopenharmony_ci		/*
6478c2ecf20Sopenharmony_ci		 * Store the page that holds the data so the page table
6488c2ecf20Sopenharmony_ci		 * doesn't have to deal with ZONE_DEVICE private pages.
6498c2ecf20Sopenharmony_ci		 */
6508c2ecf20Sopenharmony_ci		entry = dpage->zone_device_data;
6518c2ecf20Sopenharmony_ci		if (*dst & MIGRATE_PFN_WRITE)
6528c2ecf20Sopenharmony_ci			entry = xa_tag_pointer(entry, DPT_XA_TAG_WRITE);
6538c2ecf20Sopenharmony_ci		entry = xa_store(&dmirror->pt, pfn, entry, GFP_ATOMIC);
6548c2ecf20Sopenharmony_ci		if (xa_is_err(entry)) {
6558c2ecf20Sopenharmony_ci			mutex_unlock(&dmirror->mutex);
6568c2ecf20Sopenharmony_ci			return xa_err(entry);
6578c2ecf20Sopenharmony_ci		}
6588c2ecf20Sopenharmony_ci	}
6598c2ecf20Sopenharmony_ci
6608c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
6618c2ecf20Sopenharmony_ci	return 0;
6628c2ecf20Sopenharmony_ci}
6638c2ecf20Sopenharmony_ci
6648c2ecf20Sopenharmony_cistatic int dmirror_migrate(struct dmirror *dmirror,
6658c2ecf20Sopenharmony_ci			   struct hmm_dmirror_cmd *cmd)
6668c2ecf20Sopenharmony_ci{
6678c2ecf20Sopenharmony_ci	unsigned long start, end, addr;
6688c2ecf20Sopenharmony_ci	unsigned long size = cmd->npages << PAGE_SHIFT;
6698c2ecf20Sopenharmony_ci	struct mm_struct *mm = dmirror->notifier.mm;
6708c2ecf20Sopenharmony_ci	struct vm_area_struct *vma;
6718c2ecf20Sopenharmony_ci	unsigned long src_pfns[64];
6728c2ecf20Sopenharmony_ci	unsigned long dst_pfns[64];
6738c2ecf20Sopenharmony_ci	struct dmirror_bounce bounce;
6748c2ecf20Sopenharmony_ci	struct migrate_vma args = { 0 };
6758c2ecf20Sopenharmony_ci	unsigned long next;
6768c2ecf20Sopenharmony_ci	int ret;
6778c2ecf20Sopenharmony_ci
6788c2ecf20Sopenharmony_ci	start = cmd->addr;
6798c2ecf20Sopenharmony_ci	end = start + size;
6808c2ecf20Sopenharmony_ci	if (end < start)
6818c2ecf20Sopenharmony_ci		return -EINVAL;
6828c2ecf20Sopenharmony_ci
6838c2ecf20Sopenharmony_ci	/* Since the mm is for the mirrored process, get a reference first. */
6848c2ecf20Sopenharmony_ci	if (!mmget_not_zero(mm))
6858c2ecf20Sopenharmony_ci		return -EINVAL;
6868c2ecf20Sopenharmony_ci
6878c2ecf20Sopenharmony_ci	mmap_read_lock(mm);
6888c2ecf20Sopenharmony_ci	for (addr = start; addr < end; addr = next) {
6898c2ecf20Sopenharmony_ci		vma = find_vma(mm, addr);
6908c2ecf20Sopenharmony_ci		if (!vma || addr < vma->vm_start ||
6918c2ecf20Sopenharmony_ci		    !(vma->vm_flags & VM_READ)) {
6928c2ecf20Sopenharmony_ci			ret = -EINVAL;
6938c2ecf20Sopenharmony_ci			goto out;
6948c2ecf20Sopenharmony_ci		}
6958c2ecf20Sopenharmony_ci		next = min(end, addr + (ARRAY_SIZE(src_pfns) << PAGE_SHIFT));
6968c2ecf20Sopenharmony_ci		if (next > vma->vm_end)
6978c2ecf20Sopenharmony_ci			next = vma->vm_end;
6988c2ecf20Sopenharmony_ci
6998c2ecf20Sopenharmony_ci		args.vma = vma;
7008c2ecf20Sopenharmony_ci		args.src = src_pfns;
7018c2ecf20Sopenharmony_ci		args.dst = dst_pfns;
7028c2ecf20Sopenharmony_ci		args.start = addr;
7038c2ecf20Sopenharmony_ci		args.end = next;
7048c2ecf20Sopenharmony_ci		args.pgmap_owner = dmirror->mdevice;
7058c2ecf20Sopenharmony_ci		args.flags = MIGRATE_VMA_SELECT_SYSTEM;
7068c2ecf20Sopenharmony_ci		ret = migrate_vma_setup(&args);
7078c2ecf20Sopenharmony_ci		if (ret)
7088c2ecf20Sopenharmony_ci			goto out;
7098c2ecf20Sopenharmony_ci
7108c2ecf20Sopenharmony_ci		dmirror_migrate_alloc_and_copy(&args, dmirror);
7118c2ecf20Sopenharmony_ci		migrate_vma_pages(&args);
7128c2ecf20Sopenharmony_ci		dmirror_migrate_finalize_and_map(&args, dmirror);
7138c2ecf20Sopenharmony_ci		migrate_vma_finalize(&args);
7148c2ecf20Sopenharmony_ci	}
7158c2ecf20Sopenharmony_ci	mmap_read_unlock(mm);
7168c2ecf20Sopenharmony_ci	mmput(mm);
7178c2ecf20Sopenharmony_ci
7188c2ecf20Sopenharmony_ci	/* Return the migrated data for verification. */
7198c2ecf20Sopenharmony_ci	ret = dmirror_bounce_init(&bounce, start, size);
7208c2ecf20Sopenharmony_ci	if (ret)
7218c2ecf20Sopenharmony_ci		return ret;
7228c2ecf20Sopenharmony_ci	mutex_lock(&dmirror->mutex);
7238c2ecf20Sopenharmony_ci	ret = dmirror_do_read(dmirror, start, end, &bounce);
7248c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
7258c2ecf20Sopenharmony_ci	if (ret == 0) {
7268c2ecf20Sopenharmony_ci		if (copy_to_user(u64_to_user_ptr(cmd->ptr), bounce.ptr,
7278c2ecf20Sopenharmony_ci				 bounce.size))
7288c2ecf20Sopenharmony_ci			ret = -EFAULT;
7298c2ecf20Sopenharmony_ci	}
7308c2ecf20Sopenharmony_ci	cmd->cpages = bounce.cpages;
7318c2ecf20Sopenharmony_ci	dmirror_bounce_fini(&bounce);
7328c2ecf20Sopenharmony_ci	return ret;
7338c2ecf20Sopenharmony_ci
7348c2ecf20Sopenharmony_ciout:
7358c2ecf20Sopenharmony_ci	mmap_read_unlock(mm);
7368c2ecf20Sopenharmony_ci	mmput(mm);
7378c2ecf20Sopenharmony_ci	return ret;
7388c2ecf20Sopenharmony_ci}
7398c2ecf20Sopenharmony_ci
7408c2ecf20Sopenharmony_cistatic void dmirror_mkentry(struct dmirror *dmirror, struct hmm_range *range,
7418c2ecf20Sopenharmony_ci			    unsigned char *perm, unsigned long entry)
7428c2ecf20Sopenharmony_ci{
7438c2ecf20Sopenharmony_ci	struct page *page;
7448c2ecf20Sopenharmony_ci
7458c2ecf20Sopenharmony_ci	if (entry & HMM_PFN_ERROR) {
7468c2ecf20Sopenharmony_ci		*perm = HMM_DMIRROR_PROT_ERROR;
7478c2ecf20Sopenharmony_ci		return;
7488c2ecf20Sopenharmony_ci	}
7498c2ecf20Sopenharmony_ci	if (!(entry & HMM_PFN_VALID)) {
7508c2ecf20Sopenharmony_ci		*perm = HMM_DMIRROR_PROT_NONE;
7518c2ecf20Sopenharmony_ci		return;
7528c2ecf20Sopenharmony_ci	}
7538c2ecf20Sopenharmony_ci
7548c2ecf20Sopenharmony_ci	page = hmm_pfn_to_page(entry);
7558c2ecf20Sopenharmony_ci	if (is_device_private_page(page)) {
7568c2ecf20Sopenharmony_ci		/* Is the page migrated to this device or some other? */
7578c2ecf20Sopenharmony_ci		if (dmirror->mdevice == dmirror_page_to_device(page))
7588c2ecf20Sopenharmony_ci			*perm = HMM_DMIRROR_PROT_DEV_PRIVATE_LOCAL;
7598c2ecf20Sopenharmony_ci		else
7608c2ecf20Sopenharmony_ci			*perm = HMM_DMIRROR_PROT_DEV_PRIVATE_REMOTE;
7618c2ecf20Sopenharmony_ci	} else if (is_zero_pfn(page_to_pfn(page)))
7628c2ecf20Sopenharmony_ci		*perm = HMM_DMIRROR_PROT_ZERO;
7638c2ecf20Sopenharmony_ci	else
7648c2ecf20Sopenharmony_ci		*perm = HMM_DMIRROR_PROT_NONE;
7658c2ecf20Sopenharmony_ci	if (entry & HMM_PFN_WRITE)
7668c2ecf20Sopenharmony_ci		*perm |= HMM_DMIRROR_PROT_WRITE;
7678c2ecf20Sopenharmony_ci	else
7688c2ecf20Sopenharmony_ci		*perm |= HMM_DMIRROR_PROT_READ;
7698c2ecf20Sopenharmony_ci	if (hmm_pfn_to_map_order(entry) + PAGE_SHIFT == PMD_SHIFT)
7708c2ecf20Sopenharmony_ci		*perm |= HMM_DMIRROR_PROT_PMD;
7718c2ecf20Sopenharmony_ci	else if (hmm_pfn_to_map_order(entry) + PAGE_SHIFT == PUD_SHIFT)
7728c2ecf20Sopenharmony_ci		*perm |= HMM_DMIRROR_PROT_PUD;
7738c2ecf20Sopenharmony_ci}
7748c2ecf20Sopenharmony_ci
7758c2ecf20Sopenharmony_cistatic bool dmirror_snapshot_invalidate(struct mmu_interval_notifier *mni,
7768c2ecf20Sopenharmony_ci				const struct mmu_notifier_range *range,
7778c2ecf20Sopenharmony_ci				unsigned long cur_seq)
7788c2ecf20Sopenharmony_ci{
7798c2ecf20Sopenharmony_ci	struct dmirror_interval *dmi =
7808c2ecf20Sopenharmony_ci		container_of(mni, struct dmirror_interval, notifier);
7818c2ecf20Sopenharmony_ci	struct dmirror *dmirror = dmi->dmirror;
7828c2ecf20Sopenharmony_ci
7838c2ecf20Sopenharmony_ci	if (mmu_notifier_range_blockable(range))
7848c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
7858c2ecf20Sopenharmony_ci	else if (!mutex_trylock(&dmirror->mutex))
7868c2ecf20Sopenharmony_ci		return false;
7878c2ecf20Sopenharmony_ci
7888c2ecf20Sopenharmony_ci	/*
7898c2ecf20Sopenharmony_ci	 * Snapshots only need to set the sequence number since any
7908c2ecf20Sopenharmony_ci	 * invalidation in the interval invalidates the whole snapshot.
7918c2ecf20Sopenharmony_ci	 */
7928c2ecf20Sopenharmony_ci	mmu_interval_set_seq(mni, cur_seq);
7938c2ecf20Sopenharmony_ci
7948c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
7958c2ecf20Sopenharmony_ci	return true;
7968c2ecf20Sopenharmony_ci}
7978c2ecf20Sopenharmony_ci
7988c2ecf20Sopenharmony_cistatic const struct mmu_interval_notifier_ops dmirror_mrn_ops = {
7998c2ecf20Sopenharmony_ci	.invalidate = dmirror_snapshot_invalidate,
8008c2ecf20Sopenharmony_ci};
8018c2ecf20Sopenharmony_ci
8028c2ecf20Sopenharmony_cistatic int dmirror_range_snapshot(struct dmirror *dmirror,
8038c2ecf20Sopenharmony_ci				  struct hmm_range *range,
8048c2ecf20Sopenharmony_ci				  unsigned char *perm)
8058c2ecf20Sopenharmony_ci{
8068c2ecf20Sopenharmony_ci	struct mm_struct *mm = dmirror->notifier.mm;
8078c2ecf20Sopenharmony_ci	struct dmirror_interval notifier;
8088c2ecf20Sopenharmony_ci	unsigned long timeout =
8098c2ecf20Sopenharmony_ci		jiffies + msecs_to_jiffies(HMM_RANGE_DEFAULT_TIMEOUT);
8108c2ecf20Sopenharmony_ci	unsigned long i;
8118c2ecf20Sopenharmony_ci	unsigned long n;
8128c2ecf20Sopenharmony_ci	int ret = 0;
8138c2ecf20Sopenharmony_ci
8148c2ecf20Sopenharmony_ci	notifier.dmirror = dmirror;
8158c2ecf20Sopenharmony_ci	range->notifier = &notifier.notifier;
8168c2ecf20Sopenharmony_ci
8178c2ecf20Sopenharmony_ci	ret = mmu_interval_notifier_insert(range->notifier, mm,
8188c2ecf20Sopenharmony_ci			range->start, range->end - range->start,
8198c2ecf20Sopenharmony_ci			&dmirror_mrn_ops);
8208c2ecf20Sopenharmony_ci	if (ret)
8218c2ecf20Sopenharmony_ci		return ret;
8228c2ecf20Sopenharmony_ci
8238c2ecf20Sopenharmony_ci	while (true) {
8248c2ecf20Sopenharmony_ci		if (time_after(jiffies, timeout)) {
8258c2ecf20Sopenharmony_ci			ret = -EBUSY;
8268c2ecf20Sopenharmony_ci			goto out;
8278c2ecf20Sopenharmony_ci		}
8288c2ecf20Sopenharmony_ci
8298c2ecf20Sopenharmony_ci		range->notifier_seq = mmu_interval_read_begin(range->notifier);
8308c2ecf20Sopenharmony_ci
8318c2ecf20Sopenharmony_ci		mmap_read_lock(mm);
8328c2ecf20Sopenharmony_ci		ret = hmm_range_fault(range);
8338c2ecf20Sopenharmony_ci		mmap_read_unlock(mm);
8348c2ecf20Sopenharmony_ci		if (ret) {
8358c2ecf20Sopenharmony_ci			if (ret == -EBUSY)
8368c2ecf20Sopenharmony_ci				continue;
8378c2ecf20Sopenharmony_ci			goto out;
8388c2ecf20Sopenharmony_ci		}
8398c2ecf20Sopenharmony_ci
8408c2ecf20Sopenharmony_ci		mutex_lock(&dmirror->mutex);
8418c2ecf20Sopenharmony_ci		if (mmu_interval_read_retry(range->notifier,
8428c2ecf20Sopenharmony_ci					    range->notifier_seq)) {
8438c2ecf20Sopenharmony_ci			mutex_unlock(&dmirror->mutex);
8448c2ecf20Sopenharmony_ci			continue;
8458c2ecf20Sopenharmony_ci		}
8468c2ecf20Sopenharmony_ci		break;
8478c2ecf20Sopenharmony_ci	}
8488c2ecf20Sopenharmony_ci
8498c2ecf20Sopenharmony_ci	n = (range->end - range->start) >> PAGE_SHIFT;
8508c2ecf20Sopenharmony_ci	for (i = 0; i < n; i++)
8518c2ecf20Sopenharmony_ci		dmirror_mkentry(dmirror, range, perm + i, range->hmm_pfns[i]);
8528c2ecf20Sopenharmony_ci
8538c2ecf20Sopenharmony_ci	mutex_unlock(&dmirror->mutex);
8548c2ecf20Sopenharmony_ciout:
8558c2ecf20Sopenharmony_ci	mmu_interval_notifier_remove(range->notifier);
8568c2ecf20Sopenharmony_ci	return ret;
8578c2ecf20Sopenharmony_ci}
8588c2ecf20Sopenharmony_ci
8598c2ecf20Sopenharmony_cistatic int dmirror_snapshot(struct dmirror *dmirror,
8608c2ecf20Sopenharmony_ci			    struct hmm_dmirror_cmd *cmd)
8618c2ecf20Sopenharmony_ci{
8628c2ecf20Sopenharmony_ci	struct mm_struct *mm = dmirror->notifier.mm;
8638c2ecf20Sopenharmony_ci	unsigned long start, end;
8648c2ecf20Sopenharmony_ci	unsigned long size = cmd->npages << PAGE_SHIFT;
8658c2ecf20Sopenharmony_ci	unsigned long addr;
8668c2ecf20Sopenharmony_ci	unsigned long next;
8678c2ecf20Sopenharmony_ci	unsigned long pfns[64];
8688c2ecf20Sopenharmony_ci	unsigned char perm[64];
8698c2ecf20Sopenharmony_ci	char __user *uptr;
8708c2ecf20Sopenharmony_ci	struct hmm_range range = {
8718c2ecf20Sopenharmony_ci		.hmm_pfns = pfns,
8728c2ecf20Sopenharmony_ci		.dev_private_owner = dmirror->mdevice,
8738c2ecf20Sopenharmony_ci	};
8748c2ecf20Sopenharmony_ci	int ret = 0;
8758c2ecf20Sopenharmony_ci
8768c2ecf20Sopenharmony_ci	start = cmd->addr;
8778c2ecf20Sopenharmony_ci	end = start + size;
8788c2ecf20Sopenharmony_ci	if (end < start)
8798c2ecf20Sopenharmony_ci		return -EINVAL;
8808c2ecf20Sopenharmony_ci
8818c2ecf20Sopenharmony_ci	/* Since the mm is for the mirrored process, get a reference first. */
8828c2ecf20Sopenharmony_ci	if (!mmget_not_zero(mm))
8838c2ecf20Sopenharmony_ci		return -EINVAL;
8848c2ecf20Sopenharmony_ci
8858c2ecf20Sopenharmony_ci	/*
8868c2ecf20Sopenharmony_ci	 * Register a temporary notifier to detect invalidations even if it
8878c2ecf20Sopenharmony_ci	 * overlaps with other mmu_interval_notifiers.
8888c2ecf20Sopenharmony_ci	 */
8898c2ecf20Sopenharmony_ci	uptr = u64_to_user_ptr(cmd->ptr);
8908c2ecf20Sopenharmony_ci	for (addr = start; addr < end; addr = next) {
8918c2ecf20Sopenharmony_ci		unsigned long n;
8928c2ecf20Sopenharmony_ci
8938c2ecf20Sopenharmony_ci		next = min(addr + (ARRAY_SIZE(pfns) << PAGE_SHIFT), end);
8948c2ecf20Sopenharmony_ci		range.start = addr;
8958c2ecf20Sopenharmony_ci		range.end = next;
8968c2ecf20Sopenharmony_ci
8978c2ecf20Sopenharmony_ci		ret = dmirror_range_snapshot(dmirror, &range, perm);
8988c2ecf20Sopenharmony_ci		if (ret)
8998c2ecf20Sopenharmony_ci			break;
9008c2ecf20Sopenharmony_ci
9018c2ecf20Sopenharmony_ci		n = (range.end - range.start) >> PAGE_SHIFT;
9028c2ecf20Sopenharmony_ci		if (copy_to_user(uptr, perm, n)) {
9038c2ecf20Sopenharmony_ci			ret = -EFAULT;
9048c2ecf20Sopenharmony_ci			break;
9058c2ecf20Sopenharmony_ci		}
9068c2ecf20Sopenharmony_ci
9078c2ecf20Sopenharmony_ci		cmd->cpages += n;
9088c2ecf20Sopenharmony_ci		uptr += n;
9098c2ecf20Sopenharmony_ci	}
9108c2ecf20Sopenharmony_ci	mmput(mm);
9118c2ecf20Sopenharmony_ci
9128c2ecf20Sopenharmony_ci	return ret;
9138c2ecf20Sopenharmony_ci}
9148c2ecf20Sopenharmony_ci
9158c2ecf20Sopenharmony_cistatic long dmirror_fops_unlocked_ioctl(struct file *filp,
9168c2ecf20Sopenharmony_ci					unsigned int command,
9178c2ecf20Sopenharmony_ci					unsigned long arg)
9188c2ecf20Sopenharmony_ci{
9198c2ecf20Sopenharmony_ci	void __user *uarg = (void __user *)arg;
9208c2ecf20Sopenharmony_ci	struct hmm_dmirror_cmd cmd;
9218c2ecf20Sopenharmony_ci	struct dmirror *dmirror;
9228c2ecf20Sopenharmony_ci	int ret;
9238c2ecf20Sopenharmony_ci
9248c2ecf20Sopenharmony_ci	dmirror = filp->private_data;
9258c2ecf20Sopenharmony_ci	if (!dmirror)
9268c2ecf20Sopenharmony_ci		return -EINVAL;
9278c2ecf20Sopenharmony_ci
9288c2ecf20Sopenharmony_ci	if (copy_from_user(&cmd, uarg, sizeof(cmd)))
9298c2ecf20Sopenharmony_ci		return -EFAULT;
9308c2ecf20Sopenharmony_ci
9318c2ecf20Sopenharmony_ci	if (cmd.addr & ~PAGE_MASK)
9328c2ecf20Sopenharmony_ci		return -EINVAL;
9338c2ecf20Sopenharmony_ci	if (cmd.addr >= (cmd.addr + (cmd.npages << PAGE_SHIFT)))
9348c2ecf20Sopenharmony_ci		return -EINVAL;
9358c2ecf20Sopenharmony_ci
9368c2ecf20Sopenharmony_ci	cmd.cpages = 0;
9378c2ecf20Sopenharmony_ci	cmd.faults = 0;
9388c2ecf20Sopenharmony_ci
9398c2ecf20Sopenharmony_ci	switch (command) {
9408c2ecf20Sopenharmony_ci	case HMM_DMIRROR_READ:
9418c2ecf20Sopenharmony_ci		ret = dmirror_read(dmirror, &cmd);
9428c2ecf20Sopenharmony_ci		break;
9438c2ecf20Sopenharmony_ci
9448c2ecf20Sopenharmony_ci	case HMM_DMIRROR_WRITE:
9458c2ecf20Sopenharmony_ci		ret = dmirror_write(dmirror, &cmd);
9468c2ecf20Sopenharmony_ci		break;
9478c2ecf20Sopenharmony_ci
9488c2ecf20Sopenharmony_ci	case HMM_DMIRROR_MIGRATE:
9498c2ecf20Sopenharmony_ci		ret = dmirror_migrate(dmirror, &cmd);
9508c2ecf20Sopenharmony_ci		break;
9518c2ecf20Sopenharmony_ci
9528c2ecf20Sopenharmony_ci	case HMM_DMIRROR_SNAPSHOT:
9538c2ecf20Sopenharmony_ci		ret = dmirror_snapshot(dmirror, &cmd);
9548c2ecf20Sopenharmony_ci		break;
9558c2ecf20Sopenharmony_ci
9568c2ecf20Sopenharmony_ci	default:
9578c2ecf20Sopenharmony_ci		return -EINVAL;
9588c2ecf20Sopenharmony_ci	}
9598c2ecf20Sopenharmony_ci	if (ret)
9608c2ecf20Sopenharmony_ci		return ret;
9618c2ecf20Sopenharmony_ci
9628c2ecf20Sopenharmony_ci	if (copy_to_user(uarg, &cmd, sizeof(cmd)))
9638c2ecf20Sopenharmony_ci		return -EFAULT;
9648c2ecf20Sopenharmony_ci
9658c2ecf20Sopenharmony_ci	return 0;
9668c2ecf20Sopenharmony_ci}
9678c2ecf20Sopenharmony_ci
9688c2ecf20Sopenharmony_cistatic int dmirror_fops_mmap(struct file *file, struct vm_area_struct *vma)
9698c2ecf20Sopenharmony_ci{
9708c2ecf20Sopenharmony_ci	unsigned long addr;
9718c2ecf20Sopenharmony_ci
9728c2ecf20Sopenharmony_ci	for (addr = vma->vm_start; addr < vma->vm_end; addr += PAGE_SIZE) {
9738c2ecf20Sopenharmony_ci		struct page *page;
9748c2ecf20Sopenharmony_ci		int ret;
9758c2ecf20Sopenharmony_ci
9768c2ecf20Sopenharmony_ci		page = alloc_page(GFP_KERNEL | __GFP_ZERO);
9778c2ecf20Sopenharmony_ci		if (!page)
9788c2ecf20Sopenharmony_ci			return -ENOMEM;
9798c2ecf20Sopenharmony_ci
9808c2ecf20Sopenharmony_ci		ret = vm_insert_page(vma, addr, page);
9818c2ecf20Sopenharmony_ci		if (ret) {
9828c2ecf20Sopenharmony_ci			__free_page(page);
9838c2ecf20Sopenharmony_ci			return ret;
9848c2ecf20Sopenharmony_ci		}
9858c2ecf20Sopenharmony_ci		put_page(page);
9868c2ecf20Sopenharmony_ci	}
9878c2ecf20Sopenharmony_ci
9888c2ecf20Sopenharmony_ci	return 0;
9898c2ecf20Sopenharmony_ci}
9908c2ecf20Sopenharmony_ci
9918c2ecf20Sopenharmony_cistatic const struct file_operations dmirror_fops = {
9928c2ecf20Sopenharmony_ci	.open		= dmirror_fops_open,
9938c2ecf20Sopenharmony_ci	.release	= dmirror_fops_release,
9948c2ecf20Sopenharmony_ci	.mmap		= dmirror_fops_mmap,
9958c2ecf20Sopenharmony_ci	.unlocked_ioctl = dmirror_fops_unlocked_ioctl,
9968c2ecf20Sopenharmony_ci	.llseek		= default_llseek,
9978c2ecf20Sopenharmony_ci	.owner		= THIS_MODULE,
9988c2ecf20Sopenharmony_ci};
9998c2ecf20Sopenharmony_ci
10008c2ecf20Sopenharmony_cistatic void dmirror_devmem_free(struct page *page)
10018c2ecf20Sopenharmony_ci{
10028c2ecf20Sopenharmony_ci	struct page *rpage = page->zone_device_data;
10038c2ecf20Sopenharmony_ci	struct dmirror_device *mdevice;
10048c2ecf20Sopenharmony_ci
10058c2ecf20Sopenharmony_ci	if (rpage)
10068c2ecf20Sopenharmony_ci		__free_page(rpage);
10078c2ecf20Sopenharmony_ci
10088c2ecf20Sopenharmony_ci	mdevice = dmirror_page_to_device(page);
10098c2ecf20Sopenharmony_ci
10108c2ecf20Sopenharmony_ci	spin_lock(&mdevice->lock);
10118c2ecf20Sopenharmony_ci	mdevice->cfree++;
10128c2ecf20Sopenharmony_ci	page->zone_device_data = mdevice->free_pages;
10138c2ecf20Sopenharmony_ci	mdevice->free_pages = page;
10148c2ecf20Sopenharmony_ci	spin_unlock(&mdevice->lock);
10158c2ecf20Sopenharmony_ci}
10168c2ecf20Sopenharmony_ci
10178c2ecf20Sopenharmony_cistatic vm_fault_t dmirror_devmem_fault_alloc_and_copy(struct migrate_vma *args,
10188c2ecf20Sopenharmony_ci						      struct dmirror *dmirror)
10198c2ecf20Sopenharmony_ci{
10208c2ecf20Sopenharmony_ci	const unsigned long *src = args->src;
10218c2ecf20Sopenharmony_ci	unsigned long *dst = args->dst;
10228c2ecf20Sopenharmony_ci	unsigned long start = args->start;
10238c2ecf20Sopenharmony_ci	unsigned long end = args->end;
10248c2ecf20Sopenharmony_ci	unsigned long addr;
10258c2ecf20Sopenharmony_ci
10268c2ecf20Sopenharmony_ci	for (addr = start; addr < end; addr += PAGE_SIZE,
10278c2ecf20Sopenharmony_ci				       src++, dst++) {
10288c2ecf20Sopenharmony_ci		struct page *dpage, *spage;
10298c2ecf20Sopenharmony_ci
10308c2ecf20Sopenharmony_ci		spage = migrate_pfn_to_page(*src);
10318c2ecf20Sopenharmony_ci		if (!spage || !(*src & MIGRATE_PFN_MIGRATE))
10328c2ecf20Sopenharmony_ci			continue;
10338c2ecf20Sopenharmony_ci		spage = spage->zone_device_data;
10348c2ecf20Sopenharmony_ci
10358c2ecf20Sopenharmony_ci		dpage = alloc_page_vma(GFP_HIGHUSER_MOVABLE, args->vma, addr);
10368c2ecf20Sopenharmony_ci		if (!dpage)
10378c2ecf20Sopenharmony_ci			continue;
10388c2ecf20Sopenharmony_ci
10398c2ecf20Sopenharmony_ci		lock_page(dpage);
10408c2ecf20Sopenharmony_ci		xa_erase(&dmirror->pt, addr >> PAGE_SHIFT);
10418c2ecf20Sopenharmony_ci		copy_highpage(dpage, spage);
10428c2ecf20Sopenharmony_ci		*dst = migrate_pfn(page_to_pfn(dpage)) | MIGRATE_PFN_LOCKED;
10438c2ecf20Sopenharmony_ci		if (*src & MIGRATE_PFN_WRITE)
10448c2ecf20Sopenharmony_ci			*dst |= MIGRATE_PFN_WRITE;
10458c2ecf20Sopenharmony_ci	}
10468c2ecf20Sopenharmony_ci	return 0;
10478c2ecf20Sopenharmony_ci}
10488c2ecf20Sopenharmony_ci
10498c2ecf20Sopenharmony_cistatic vm_fault_t dmirror_devmem_fault(struct vm_fault *vmf)
10508c2ecf20Sopenharmony_ci{
10518c2ecf20Sopenharmony_ci	struct migrate_vma args = { 0 };
10528c2ecf20Sopenharmony_ci	unsigned long src_pfns;
10538c2ecf20Sopenharmony_ci	unsigned long dst_pfns;
10548c2ecf20Sopenharmony_ci	struct page *rpage;
10558c2ecf20Sopenharmony_ci	struct dmirror *dmirror;
10568c2ecf20Sopenharmony_ci	vm_fault_t ret;
10578c2ecf20Sopenharmony_ci
10588c2ecf20Sopenharmony_ci	/*
10598c2ecf20Sopenharmony_ci	 * Normally, a device would use the page->zone_device_data to point to
10608c2ecf20Sopenharmony_ci	 * the mirror but here we use it to hold the page for the simulated
10618c2ecf20Sopenharmony_ci	 * device memory and that page holds the pointer to the mirror.
10628c2ecf20Sopenharmony_ci	 */
10638c2ecf20Sopenharmony_ci	rpage = vmf->page->zone_device_data;
10648c2ecf20Sopenharmony_ci	dmirror = rpage->zone_device_data;
10658c2ecf20Sopenharmony_ci
10668c2ecf20Sopenharmony_ci	/* FIXME demonstrate how we can adjust migrate range */
10678c2ecf20Sopenharmony_ci	args.vma = vmf->vma;
10688c2ecf20Sopenharmony_ci	args.start = vmf->address;
10698c2ecf20Sopenharmony_ci	args.end = args.start + PAGE_SIZE;
10708c2ecf20Sopenharmony_ci	args.src = &src_pfns;
10718c2ecf20Sopenharmony_ci	args.dst = &dst_pfns;
10728c2ecf20Sopenharmony_ci	args.pgmap_owner = dmirror->mdevice;
10738c2ecf20Sopenharmony_ci	args.flags = MIGRATE_VMA_SELECT_DEVICE_PRIVATE;
10748c2ecf20Sopenharmony_ci	args.fault_page = vmf->page;
10758c2ecf20Sopenharmony_ci
10768c2ecf20Sopenharmony_ci	if (migrate_vma_setup(&args))
10778c2ecf20Sopenharmony_ci		return VM_FAULT_SIGBUS;
10788c2ecf20Sopenharmony_ci
10798c2ecf20Sopenharmony_ci	ret = dmirror_devmem_fault_alloc_and_copy(&args, dmirror);
10808c2ecf20Sopenharmony_ci	if (ret)
10818c2ecf20Sopenharmony_ci		return ret;
10828c2ecf20Sopenharmony_ci	migrate_vma_pages(&args);
10838c2ecf20Sopenharmony_ci	/*
10848c2ecf20Sopenharmony_ci	 * No device finalize step is needed since
10858c2ecf20Sopenharmony_ci	 * dmirror_devmem_fault_alloc_and_copy() will have already
10868c2ecf20Sopenharmony_ci	 * invalidated the device page table.
10878c2ecf20Sopenharmony_ci	 */
10888c2ecf20Sopenharmony_ci	migrate_vma_finalize(&args);
10898c2ecf20Sopenharmony_ci	return 0;
10908c2ecf20Sopenharmony_ci}
10918c2ecf20Sopenharmony_ci
10928c2ecf20Sopenharmony_cistatic const struct dev_pagemap_ops dmirror_devmem_ops = {
10938c2ecf20Sopenharmony_ci	.page_free	= dmirror_devmem_free,
10948c2ecf20Sopenharmony_ci	.migrate_to_ram	= dmirror_devmem_fault,
10958c2ecf20Sopenharmony_ci};
10968c2ecf20Sopenharmony_ci
10978c2ecf20Sopenharmony_cistatic int dmirror_device_init(struct dmirror_device *mdevice, int id)
10988c2ecf20Sopenharmony_ci{
10998c2ecf20Sopenharmony_ci	dev_t dev;
11008c2ecf20Sopenharmony_ci	int ret;
11018c2ecf20Sopenharmony_ci
11028c2ecf20Sopenharmony_ci	dev = MKDEV(MAJOR(dmirror_dev), id);
11038c2ecf20Sopenharmony_ci	mutex_init(&mdevice->devmem_lock);
11048c2ecf20Sopenharmony_ci	spin_lock_init(&mdevice->lock);
11058c2ecf20Sopenharmony_ci
11068c2ecf20Sopenharmony_ci	cdev_init(&mdevice->cdevice, &dmirror_fops);
11078c2ecf20Sopenharmony_ci	mdevice->cdevice.owner = THIS_MODULE;
11088c2ecf20Sopenharmony_ci	ret = cdev_add(&mdevice->cdevice, dev, 1);
11098c2ecf20Sopenharmony_ci	if (ret)
11108c2ecf20Sopenharmony_ci		return ret;
11118c2ecf20Sopenharmony_ci
11128c2ecf20Sopenharmony_ci	/* Build a list of free ZONE_DEVICE private struct pages */
11138c2ecf20Sopenharmony_ci	dmirror_allocate_chunk(mdevice, NULL);
11148c2ecf20Sopenharmony_ci
11158c2ecf20Sopenharmony_ci	return 0;
11168c2ecf20Sopenharmony_ci}
11178c2ecf20Sopenharmony_ci
11188c2ecf20Sopenharmony_cistatic void dmirror_device_remove(struct dmirror_device *mdevice)
11198c2ecf20Sopenharmony_ci{
11208c2ecf20Sopenharmony_ci	unsigned int i;
11218c2ecf20Sopenharmony_ci
11228c2ecf20Sopenharmony_ci	if (mdevice->devmem_chunks) {
11238c2ecf20Sopenharmony_ci		for (i = 0; i < mdevice->devmem_count; i++) {
11248c2ecf20Sopenharmony_ci			struct dmirror_chunk *devmem =
11258c2ecf20Sopenharmony_ci				mdevice->devmem_chunks[i];
11268c2ecf20Sopenharmony_ci
11278c2ecf20Sopenharmony_ci			memunmap_pages(&devmem->pagemap);
11288c2ecf20Sopenharmony_ci			release_mem_region(devmem->pagemap.range.start,
11298c2ecf20Sopenharmony_ci					   range_len(&devmem->pagemap.range));
11308c2ecf20Sopenharmony_ci			kfree(devmem);
11318c2ecf20Sopenharmony_ci		}
11328c2ecf20Sopenharmony_ci		kfree(mdevice->devmem_chunks);
11338c2ecf20Sopenharmony_ci	}
11348c2ecf20Sopenharmony_ci
11358c2ecf20Sopenharmony_ci	cdev_del(&mdevice->cdevice);
11368c2ecf20Sopenharmony_ci}
11378c2ecf20Sopenharmony_ci
11388c2ecf20Sopenharmony_cistatic int __init hmm_dmirror_init(void)
11398c2ecf20Sopenharmony_ci{
11408c2ecf20Sopenharmony_ci	int ret;
11418c2ecf20Sopenharmony_ci	int id;
11428c2ecf20Sopenharmony_ci
11438c2ecf20Sopenharmony_ci	ret = alloc_chrdev_region(&dmirror_dev, 0, DMIRROR_NDEVICES,
11448c2ecf20Sopenharmony_ci				  "HMM_DMIRROR");
11458c2ecf20Sopenharmony_ci	if (ret)
11468c2ecf20Sopenharmony_ci		goto err_unreg;
11478c2ecf20Sopenharmony_ci
11488c2ecf20Sopenharmony_ci	for (id = 0; id < DMIRROR_NDEVICES; id++) {
11498c2ecf20Sopenharmony_ci		ret = dmirror_device_init(dmirror_devices + id, id);
11508c2ecf20Sopenharmony_ci		if (ret)
11518c2ecf20Sopenharmony_ci			goto err_chrdev;
11528c2ecf20Sopenharmony_ci	}
11538c2ecf20Sopenharmony_ci
11548c2ecf20Sopenharmony_ci	pr_info("HMM test module loaded. This is only for testing HMM.\n");
11558c2ecf20Sopenharmony_ci	return 0;
11568c2ecf20Sopenharmony_ci
11578c2ecf20Sopenharmony_cierr_chrdev:
11588c2ecf20Sopenharmony_ci	while (--id >= 0)
11598c2ecf20Sopenharmony_ci		dmirror_device_remove(dmirror_devices + id);
11608c2ecf20Sopenharmony_ci	unregister_chrdev_region(dmirror_dev, DMIRROR_NDEVICES);
11618c2ecf20Sopenharmony_cierr_unreg:
11628c2ecf20Sopenharmony_ci	return ret;
11638c2ecf20Sopenharmony_ci}
11648c2ecf20Sopenharmony_ci
11658c2ecf20Sopenharmony_cistatic void __exit hmm_dmirror_exit(void)
11668c2ecf20Sopenharmony_ci{
11678c2ecf20Sopenharmony_ci	int id;
11688c2ecf20Sopenharmony_ci
11698c2ecf20Sopenharmony_ci	for (id = 0; id < DMIRROR_NDEVICES; id++)
11708c2ecf20Sopenharmony_ci		dmirror_device_remove(dmirror_devices + id);
11718c2ecf20Sopenharmony_ci	unregister_chrdev_region(dmirror_dev, DMIRROR_NDEVICES);
11728c2ecf20Sopenharmony_ci}
11738c2ecf20Sopenharmony_ci
11748c2ecf20Sopenharmony_cimodule_init(hmm_dmirror_init);
11758c2ecf20Sopenharmony_cimodule_exit(hmm_dmirror_exit);
11768c2ecf20Sopenharmony_ciMODULE_LICENSE("GPL");
1177