3 * Memory mapping for DRM
5 * \author Rickard E. (Rik) Faith <faith@valinux.com>
6 * \author Gareth Hughes <gareth@valinux.com>
10 * Created: Mon Jan 4 08:58:31 1999 by faith@valinux.com
12 * Copyright 1999 Precision Insight, Inc., Cedar Park, Texas.
13 * Copyright 2000 VA Linux Systems, Inc., Sunnyvale, California.
14 * All Rights Reserved.
16 * Permission is hereby granted, free of charge, to any person obtaining a
17 * copy of this software and associated documentation files (the "Software"),
18 * to deal in the Software without restriction, including without limitation
19 * the rights to use, copy, modify, merge, publish, distribute, sublicense,
20 * and/or sell copies of the Software, and to permit persons to whom the
21 * Software is furnished to do so, subject to the following conditions:
23 * The above copyright notice and this permission notice (including the next
24 * paragraph) shall be included in all copies or substantial portions of the
27 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
28 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
29 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
30 * VA LINUX SYSTEMS AND/OR ITS SUPPLIERS BE LIABLE FOR ANY CLAIM, DAMAGES OR
31 * OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
32 * ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
33 * OTHER DEALINGS IN THE SOFTWARE.
36 #include <linux/export.h>
37 #include <linux/pci.h>
38 #include <linux/seq_file.h>
39 #include <linux/vmalloc.h>
40 #include <linux/pgtable.h>
43 #include <linux/efi.h>
44 #include <linux/slab.h>
46 #include <linux/mem_encrypt.h>
48 #include <drm/drm_device.h>
49 #include <drm/drm_drv.h>
50 #include <drm/drm_file.h>
51 #include <drm/drm_framebuffer.h>
52 #include <drm/drm_print.h>
54 #include "drm_internal.h"
55 #include "drm_legacy.h"
57 struct drm_vma_entry {
58 struct list_head head;
59 struct vm_area_struct *vma;
63 static void drm_vm_open(struct vm_area_struct *vma);
64 static void drm_vm_close(struct vm_area_struct *vma);
66 static pgprot_t drm_io_prot(struct drm_local_map *map,
67 struct vm_area_struct *vma)
69 pgprot_t tmp = vm_get_page_prot(vma->vm_flags);
71 #if defined(__i386__) || defined(__x86_64__) || defined(__powerpc__) || \
73 if (map->type == _DRM_REGISTERS && !(map->flags & _DRM_WRITE_COMBINING))
74 tmp = pgprot_noncached(tmp);
76 tmp = pgprot_writecombine(tmp);
77 #elif defined(__ia64__)
78 if (efi_range_is_wc(vma->vm_start, vma->vm_end -
80 tmp = pgprot_writecombine(tmp);
82 tmp = pgprot_noncached(tmp);
83 #elif defined(__sparc__) || defined(__arm__)
84 tmp = pgprot_noncached(tmp);
89 static pgprot_t drm_dma_prot(uint32_t map_type, struct vm_area_struct *vma)
91 pgprot_t tmp = vm_get_page_prot(vma->vm_flags);
93 #if defined(__powerpc__) && defined(CONFIG_NOT_COHERENT_CACHE)
94 tmp = pgprot_noncached_wc(tmp);
100 * \c fault method for AGP virtual memory.
102 * \param vma virtual memory area.
103 * \param address access address.
104 * \return pointer to the page structure.
106 * Find the right map and if it's AGP memory find the real physical page to
107 * map, get the page, increment the use count and return it.
109 #if IS_ENABLED(CONFIG_AGP)
110 static vm_fault_t drm_vm_fault(struct vm_fault *vmf)
112 struct vm_area_struct *vma = vmf->vma;
113 struct drm_file *priv = vma->vm_file->private_data;
114 struct drm_device *dev = priv->minor->dev;
115 struct drm_local_map *map = NULL;
116 struct drm_map_list *r_list;
117 struct drm_hash_item *hash;
125 if (!dev->agp || !dev->agp->cant_use_aperture)
128 if (drm_ht_find_item(&dev->map_hash, vma->vm_pgoff, &hash))
131 r_list = drm_hash_entry(hash, struct drm_map_list, hash);
134 if (map && map->type == _DRM_AGP) {
136 * Using vm_pgoff as a selector forces us to use this unusual
139 resource_size_t offset = vmf->address - vma->vm_start;
140 resource_size_t baddr = map->offset + offset;
141 struct drm_agp_mem *agpmem;
146 * Adjust to a bus-relative address
148 baddr -= dev->hose->mem_space->start;
152 * It's AGP memory - find the real physical page to map
154 list_for_each_entry(agpmem, &dev->agp->memory, head) {
155 if (agpmem->bound <= baddr &&
156 agpmem->bound + agpmem->pages * PAGE_SIZE > baddr)
160 if (&agpmem->head == &dev->agp->memory)
164 * Get the page, inc the use count, and return it
166 offset = (baddr - agpmem->bound) >> PAGE_SHIFT;
167 page = agpmem->memory->pages[offset];
172 ("baddr = 0x%llx page = 0x%p, offset = 0x%llx, count=%d\n",
173 (unsigned long long)baddr,
174 agpmem->memory->pages[offset],
175 (unsigned long long)offset,
180 return VM_FAULT_SIGBUS; /* Disallow mremap */
183 static vm_fault_t drm_vm_fault(struct vm_fault *vmf)
185 return VM_FAULT_SIGBUS;
190 * \c nopage method for shared virtual memory.
192 * \param vma virtual memory area.
193 * \param address access address.
194 * \return pointer to the page structure.
196 * Get the mapping, find the real physical page to map, get the page, and
199 static vm_fault_t drm_vm_shm_fault(struct vm_fault *vmf)
201 struct vm_area_struct *vma = vmf->vma;
202 struct drm_local_map *map = vma->vm_private_data;
203 unsigned long offset;
208 return VM_FAULT_SIGBUS; /* Nothing allocated */
210 offset = vmf->address - vma->vm_start;
211 i = (unsigned long)map->handle + offset;
212 page = vmalloc_to_page((void *)i);
214 return VM_FAULT_SIGBUS;
218 DRM_DEBUG("shm_fault 0x%lx\n", offset);
223 * \c close method for shared virtual memory.
225 * \param vma virtual memory area.
227 * Deletes map information if we are the last
228 * person to close a mapping and it's not in the global maplist.
230 static void drm_vm_shm_close(struct vm_area_struct *vma)
232 struct drm_file *priv = vma->vm_file->private_data;
233 struct drm_device *dev = priv->minor->dev;
234 struct drm_vma_entry *pt, *temp;
235 struct drm_local_map *map;
236 struct drm_map_list *r_list;
239 DRM_DEBUG("0x%08lx,0x%08lx\n",
240 vma->vm_start, vma->vm_end - vma->vm_start);
242 map = vma->vm_private_data;
244 mutex_lock(&dev->struct_mutex);
245 list_for_each_entry_safe(pt, temp, &dev->vmalist, head) {
246 if (pt->vma->vm_private_data == map)
248 if (pt->vma == vma) {
254 /* We were the only map that was found */
255 if (found_maps == 1 && map->flags & _DRM_REMOVABLE) {
256 /* Check to see if we are in the maplist, if we are not, then
257 * we delete this mappings information.
260 list_for_each_entry(r_list, &dev->maplist, head) {
261 if (r_list->map == map)
268 case _DRM_FRAME_BUFFER:
269 arch_phys_wc_del(map->mtrr);
270 iounmap(map->handle);
276 case _DRM_SCATTER_GATHER:
278 case _DRM_CONSISTENT:
279 dma_free_coherent(dev->dev,
288 mutex_unlock(&dev->struct_mutex);
292 * \c fault method for DMA virtual memory.
294 * \param address access address.
295 * \return pointer to the page structure.
297 * Determine the page number from the page offset and get it from drm_device_dma::pagelist.
299 static vm_fault_t drm_vm_dma_fault(struct vm_fault *vmf)
301 struct vm_area_struct *vma = vmf->vma;
302 struct drm_file *priv = vma->vm_file->private_data;
303 struct drm_device *dev = priv->minor->dev;
304 struct drm_device_dma *dma = dev->dma;
305 unsigned long offset;
306 unsigned long page_nr;
310 return VM_FAULT_SIGBUS; /* Error */
312 return VM_FAULT_SIGBUS; /* Nothing allocated */
314 offset = vmf->address - vma->vm_start;
315 /* vm_[pg]off[set] should be 0 */
316 page_nr = offset >> PAGE_SHIFT; /* page_nr could just be vmf->pgoff */
317 page = virt_to_page((void *)dma->pagelist[page_nr]);
322 DRM_DEBUG("dma_fault 0x%lx (page %lu)\n", offset, page_nr);
327 * \c fault method for scatter-gather virtual memory.
329 * \param address access address.
330 * \return pointer to the page structure.
332 * Determine the map offset from the page offset and get it from drm_sg_mem::pagelist.
334 static vm_fault_t drm_vm_sg_fault(struct vm_fault *vmf)
336 struct vm_area_struct *vma = vmf->vma;
337 struct drm_local_map *map = vma->vm_private_data;
338 struct drm_file *priv = vma->vm_file->private_data;
339 struct drm_device *dev = priv->minor->dev;
340 struct drm_sg_mem *entry = dev->sg;
341 unsigned long offset;
342 unsigned long map_offset;
343 unsigned long page_offset;
347 return VM_FAULT_SIGBUS; /* Error */
348 if (!entry->pagelist)
349 return VM_FAULT_SIGBUS; /* Nothing allocated */
351 offset = vmf->address - vma->vm_start;
352 map_offset = map->offset - (unsigned long)dev->sg->virtual;
353 page_offset = (offset >> PAGE_SHIFT) + (map_offset >> PAGE_SHIFT);
354 page = entry->pagelist[page_offset];
361 /** AGP virtual memory operations */
362 static const struct vm_operations_struct drm_vm_ops = {
363 .fault = drm_vm_fault,
365 .close = drm_vm_close,
368 /** Shared virtual memory operations */
369 static const struct vm_operations_struct drm_vm_shm_ops = {
370 .fault = drm_vm_shm_fault,
372 .close = drm_vm_shm_close,
375 /** DMA virtual memory operations */
376 static const struct vm_operations_struct drm_vm_dma_ops = {
377 .fault = drm_vm_dma_fault,
379 .close = drm_vm_close,
382 /** Scatter-gather virtual memory operations */
383 static const struct vm_operations_struct drm_vm_sg_ops = {
384 .fault = drm_vm_sg_fault,
386 .close = drm_vm_close,
389 static void drm_vm_open_locked(struct drm_device *dev,
390 struct vm_area_struct *vma)
392 struct drm_vma_entry *vma_entry;
394 DRM_DEBUG("0x%08lx,0x%08lx\n",
395 vma->vm_start, vma->vm_end - vma->vm_start);
397 vma_entry = kmalloc(sizeof(*vma_entry), GFP_KERNEL);
399 vma_entry->vma = vma;
400 vma_entry->pid = current->pid;
401 list_add(&vma_entry->head, &dev->vmalist);
405 static void drm_vm_open(struct vm_area_struct *vma)
407 struct drm_file *priv = vma->vm_file->private_data;
408 struct drm_device *dev = priv->minor->dev;
410 mutex_lock(&dev->struct_mutex);
411 drm_vm_open_locked(dev, vma);
412 mutex_unlock(&dev->struct_mutex);
415 static void drm_vm_close_locked(struct drm_device *dev,
416 struct vm_area_struct *vma)
418 struct drm_vma_entry *pt, *temp;
420 DRM_DEBUG("0x%08lx,0x%08lx\n",
421 vma->vm_start, vma->vm_end - vma->vm_start);
423 list_for_each_entry_safe(pt, temp, &dev->vmalist, head) {
424 if (pt->vma == vma) {
433 * \c close method for all virtual memory types.
435 * \param vma virtual memory area.
437 * Search the \p vma private data entry in drm_device::vmalist, unlink it, and
440 static void drm_vm_close(struct vm_area_struct *vma)
442 struct drm_file *priv = vma->vm_file->private_data;
443 struct drm_device *dev = priv->minor->dev;
445 mutex_lock(&dev->struct_mutex);
446 drm_vm_close_locked(dev, vma);
447 mutex_unlock(&dev->struct_mutex);
453 * \param file_priv DRM file private.
454 * \param vma virtual memory area.
455 * \return zero on success or a negative number on failure.
457 * Sets the virtual memory area operations structure to vm_dma_ops, the file
458 * pointer, and calls vm_open().
460 static int drm_mmap_dma(struct file *filp, struct vm_area_struct *vma)
462 struct drm_file *priv = filp->private_data;
463 struct drm_device *dev;
464 struct drm_device_dma *dma;
465 unsigned long length = vma->vm_end - vma->vm_start;
467 dev = priv->minor->dev;
469 DRM_DEBUG("start = 0x%lx, end = 0x%lx, page offset = 0x%lx\n",
470 vma->vm_start, vma->vm_end, vma->vm_pgoff);
472 /* Length must match exact page count */
473 if (!dma || (length >> PAGE_SHIFT) != dma->page_count) {
477 if (!capable(CAP_SYS_ADMIN) &&
478 (dma->flags & _DRM_DMA_USE_PCI_RO)) {
479 vma->vm_flags &= ~(VM_WRITE | VM_MAYWRITE);
480 #if defined(__i386__) || defined(__x86_64__)
481 pgprot_val(vma->vm_page_prot) &= ~_PAGE_RW;
483 /* Ye gads this is ugly. With more thought
484 we could move this up higher and use
485 `protection_map' instead. */
489 (__pte(pgprot_val(vma->vm_page_prot)))));
493 vma->vm_ops = &drm_vm_dma_ops;
495 vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
497 drm_vm_open_locked(dev, vma);
501 static resource_size_t drm_core_get_reg_ofs(struct drm_device *dev)
504 return dev->hose->dense_mem_base;
513 * \param file_priv DRM file private.
514 * \param vma virtual memory area.
515 * \return zero on success or a negative number on failure.
517 * If the virtual memory area has no offset associated with it then it's a DMA
518 * area, so calls mmap_dma(). Otherwise searches the map in drm_device::maplist,
519 * checks that the restricted flag is not set, sets the virtual memory operations
520 * according to the mapping type and remaps the pages. Finally sets the file
521 * pointer and calls vm_open().
523 static int drm_mmap_locked(struct file *filp, struct vm_area_struct *vma)
525 struct drm_file *priv = filp->private_data;
526 struct drm_device *dev = priv->minor->dev;
527 struct drm_local_map *map = NULL;
528 resource_size_t offset = 0;
529 struct drm_hash_item *hash;
531 DRM_DEBUG("start = 0x%lx, end = 0x%lx, page offset = 0x%lx\n",
532 vma->vm_start, vma->vm_end, vma->vm_pgoff);
534 if (!priv->authenticated)
537 /* We check for "dma". On Apple's UniNorth, it's valid to have
538 * the AGP mapped at physical address 0
542 #if IS_ENABLED(CONFIG_AGP)
544 || dev->agp->agp_info.device->vendor != PCI_VENDOR_ID_APPLE)
547 return drm_mmap_dma(filp, vma);
549 if (drm_ht_find_item(&dev->map_hash, vma->vm_pgoff, &hash)) {
550 DRM_ERROR("Could not find map\n");
554 map = drm_hash_entry(hash, struct drm_map_list, hash)->map;
555 if (!map || ((map->flags & _DRM_RESTRICTED) && !capable(CAP_SYS_ADMIN)))
558 /* Check for valid size. */
559 if (map->size < vma->vm_end - vma->vm_start)
562 if (!capable(CAP_SYS_ADMIN) && (map->flags & _DRM_READ_ONLY)) {
563 vma->vm_flags &= ~(VM_WRITE | VM_MAYWRITE);
564 #if defined(__i386__) || defined(__x86_64__)
565 pgprot_val(vma->vm_page_prot) &= ~_PAGE_RW;
567 /* Ye gads this is ugly. With more thought
568 we could move this up higher and use
569 `protection_map' instead. */
573 (__pte(pgprot_val(vma->vm_page_prot)))));
578 #if !defined(__arm__)
580 if (dev->agp && dev->agp->cant_use_aperture) {
582 * On some platforms we can't talk to bus dma address from the CPU, so for
583 * memory of type DRM_AGP, we'll deal with sorting out the real physical
584 * pages and mappings in fault()
586 #if defined(__powerpc__)
587 vma->vm_page_prot = pgprot_noncached(vma->vm_page_prot);
589 vma->vm_ops = &drm_vm_ops;
592 fallthrough; /* to _DRM_FRAME_BUFFER... */
594 case _DRM_FRAME_BUFFER:
596 offset = drm_core_get_reg_ofs(dev);
597 vma->vm_page_prot = drm_io_prot(map, vma);
598 if (io_remap_pfn_range(vma, vma->vm_start,
599 (map->offset + offset) >> PAGE_SHIFT,
600 vma->vm_end - vma->vm_start,
603 DRM_DEBUG(" Type = %d; start = 0x%lx, end = 0x%lx,"
604 " offset = 0x%llx\n",
606 vma->vm_start, vma->vm_end, (unsigned long long)(map->offset + offset));
608 vma->vm_ops = &drm_vm_ops;
610 case _DRM_CONSISTENT:
611 /* Consistent memory is really like shared memory. But
612 * it's allocated in a different way, so avoid fault */
613 if (remap_pfn_range(vma, vma->vm_start,
614 page_to_pfn(virt_to_page(map->handle)),
615 vma->vm_end - vma->vm_start, vma->vm_page_prot))
617 vma->vm_page_prot = drm_dma_prot(map->type, vma);
618 fallthrough; /* to _DRM_SHM */
620 vma->vm_ops = &drm_vm_shm_ops;
621 vma->vm_private_data = (void *)map;
623 case _DRM_SCATTER_GATHER:
624 vma->vm_ops = &drm_vm_sg_ops;
625 vma->vm_private_data = (void *)map;
626 vma->vm_page_prot = drm_dma_prot(map->type, vma);
629 return -EINVAL; /* This should never happen. */
631 vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
633 drm_vm_open_locked(dev, vma);
637 int drm_legacy_mmap(struct file *filp, struct vm_area_struct *vma)
639 struct drm_file *priv = filp->private_data;
640 struct drm_device *dev = priv->minor->dev;
643 if (drm_dev_is_unplugged(dev))
646 mutex_lock(&dev->struct_mutex);
647 ret = drm_mmap_locked(filp, vma);
648 mutex_unlock(&dev->struct_mutex);
652 EXPORT_SYMBOL(drm_legacy_mmap);
654 #if IS_ENABLED(CONFIG_DRM_LEGACY)
655 void drm_legacy_vma_flush(struct drm_device *dev)
657 struct drm_vma_entry *vma, *vma_temp;
659 /* Clear vma list (only needed for legacy drivers) */
660 list_for_each_entry_safe(vma, vma_temp, &dev->vmalist, head) {
661 list_del(&vma->head);