1
2
3
4
5
6
7
8
9
10#include <linux/mm.h>
11#include <linux/slab.h>
12#include <linux/shm.h>
13#include <linux/mman.h>
14#include <linux/swap.h>
15#include <linux/fs.h>
16#include <linux/highmem.h>
17
18#include <asm/uaccess.h>
19#include <asm/pgalloc.h>
20#include <asm/cacheflush.h>
21#include <asm/tlbflush.h>
22
23static inline pte_t *get_one_pte_map_nested(struct mm_struct *mm, unsigned long addr)
24{
25 pgd_t * pgd;
26 pmd_t * pmd;
27 pte_t * pte = NULL;
28
29 pgd = pgd_offset(mm, addr);
30 if (pgd_none(*pgd))
31 goto end;
32 if (pgd_bad(*pgd)) {
33 pgd_ERROR(*pgd);
34 pgd_clear(pgd);
35 goto end;
36 }
37
38 pmd = pmd_offset(pgd, addr);
39 if (pmd_none(*pmd))
40 goto end;
41 if (pmd_bad(*pmd)) {
42 pmd_ERROR(*pmd);
43 pmd_clear(pmd);
44 goto end;
45 }
46
47 pte = pte_offset_map_nested(pmd, addr);
48 if (pte_none(*pte)) {
49 pte_unmap_nested(pte);
50 pte = NULL;
51 }
52end:
53 return pte;
54}
55
56static inline pte_t *alloc_one_pte_map(struct mm_struct *mm, unsigned long addr)
57{
58 pmd_t * pmd;
59 pte_t * pte = NULL;
60
61 pmd = pmd_alloc(mm, pgd_offset(mm, addr), addr);
62 if (pmd)
63 pte = pte_alloc_map(mm, pmd, addr);
64 return pte;
65}
66
67static inline int copy_one_pte(struct mm_struct *mm, pte_t * src, pte_t * dst)
68{
69 int error = 0;
70 pte_t pte;
71 struct page * page = NULL;
72
73 if (pte_present(*src))
74 page = pte_page(*src);
75
76 if (!pte_none(*src)) {
77 if (page)
78 page_remove_rmap(page, src);
79 pte = ptep_get_and_clear(src);
80 if (!dst) {
81
82 dst = src;
83 error++;
84 }
85 set_pte(dst, pte);
86 if (page)
87 page_add_rmap(page, dst);
88 }
89 return error;
90}
91
92static int move_one_page(struct vm_area_struct *vma, unsigned long old_addr, unsigned long new_addr)
93{
94 struct mm_struct *mm = vma->vm_mm;
95 int error = 0;
96 pte_t *src, *dst;
97
98 spin_lock(&mm->page_table_lock);
99 src = get_one_pte_map_nested(mm, old_addr);
100 if (src) {
101 dst = alloc_one_pte_map(mm, new_addr);
102 error = copy_one_pte(mm, src, dst);
103 pte_unmap_nested(src);
104 pte_unmap(dst);
105 }
106 flush_tlb_page(vma, old_addr);
107 spin_unlock(&mm->page_table_lock);
108 return error;
109}
110
111static int move_page_tables(struct vm_area_struct *vma,
112 unsigned long new_addr, unsigned long old_addr, unsigned long len)
113{
114 unsigned long offset = len;
115
116 flush_cache_range(vma, old_addr, old_addr + len);
117
118
119
120
121
122
123 while (offset) {
124 offset -= PAGE_SIZE;
125 if (move_one_page(vma, old_addr + offset, new_addr + offset))
126 goto oops_we_failed;
127 }
128 return 0;
129
130
131
132
133
134
135
136
137oops_we_failed:
138 flush_cache_range(vma, new_addr, new_addr + len);
139 while ((offset += PAGE_SIZE) < len)
140 move_one_page(vma, new_addr + offset, old_addr + offset);
141 zap_page_range(vma, new_addr, len);
142 return -1;
143}
144
145static inline unsigned long move_vma(struct vm_area_struct * vma,
146 unsigned long addr, unsigned long old_len, unsigned long new_len,
147 unsigned long new_addr)
148{
149 struct mm_struct * mm = vma->vm_mm;
150 struct vm_area_struct * new_vma, * next, * prev;
151 int allocated_vma;
152 int split = 0;
153
154 new_vma = NULL;
155 next = find_vma_prev(mm, new_addr, &prev);
156 if (next) {
157 if (prev && prev->vm_end == new_addr &&
158 can_vma_merge(prev, vma->vm_flags) && !vma->vm_file && !(vma->vm_flags & VM_SHARED)) {
159 spin_lock(&mm->page_table_lock);
160 prev->vm_end = new_addr + new_len;
161 spin_unlock(&mm->page_table_lock);
162 new_vma = prev;
163 if (next != prev->vm_next)
164 BUG();
165 if (prev->vm_end == next->vm_start && can_vma_merge(next, prev->vm_flags)) {
166 spin_lock(&mm->page_table_lock);
167 prev->vm_end = next->vm_end;
168 __vma_unlink(mm, next, prev);
169 spin_unlock(&mm->page_table_lock);
170
171 mm->map_count--;
172 kmem_cache_free(vm_area_cachep, next);
173 }
174 } else if (next->vm_start == new_addr + new_len &&
175 can_vma_merge(next, vma->vm_flags) && !vma->vm_file && !(vma->vm_flags & VM_SHARED)) {
176 spin_lock(&mm->page_table_lock);
177 next->vm_start = new_addr;
178 spin_unlock(&mm->page_table_lock);
179 new_vma = next;
180 }
181 } else {
182 prev = find_vma(mm, new_addr-1);
183 if (prev && prev->vm_end == new_addr &&
184 can_vma_merge(prev, vma->vm_flags) && !vma->vm_file && !(vma->vm_flags & VM_SHARED)) {
185 spin_lock(&mm->page_table_lock);
186 prev->vm_end = new_addr + new_len;
187 spin_unlock(&mm->page_table_lock);
188 new_vma = prev;
189 }
190 }
191
192 allocated_vma = 0;
193 if (!new_vma) {
194 new_vma = kmem_cache_alloc(vm_area_cachep, SLAB_KERNEL);
195 if (!new_vma)
196 goto out;
197 allocated_vma = 1;
198 }
199
200 if (!move_page_tables(vma, new_addr, addr, old_len)) {
201 if (allocated_vma) {
202 *new_vma = *vma;
203 new_vma->vm_start = new_addr;
204 new_vma->vm_end = new_addr+new_len;
205 new_vma->vm_pgoff += (addr - vma->vm_start) >> PAGE_SHIFT;
206 new_vma->vm_raend = 0;
207 if (new_vma->vm_file)
208 get_file(new_vma->vm_file);
209 if (new_vma->vm_ops && new_vma->vm_ops->open)
210 new_vma->vm_ops->open(new_vma);
211 insert_vm_struct(current->mm, new_vma);
212 }
213
214
215 if (vma->vm_flags & VM_ACCOUNT) {
216 vma->vm_flags &= ~VM_ACCOUNT;
217 if (addr > vma->vm_start) {
218 if (addr + old_len < vma->vm_end)
219 split = 1;
220 } else if (addr + old_len == vma->vm_end)
221 vma = NULL;
222 } else
223 vma = NULL;
224
225 do_munmap(current->mm, addr, old_len);
226
227
228 if (vma) {
229 vma->vm_flags |= VM_ACCOUNT;
230 if (split)
231 vma->vm_next->vm_flags |= VM_ACCOUNT;
232 }
233 current->mm->total_vm += new_len >> PAGE_SHIFT;
234 if (new_vma->vm_flags & VM_LOCKED) {
235 current->mm->locked_vm += new_len >> PAGE_SHIFT;
236 make_pages_present(new_vma->vm_start,
237 new_vma->vm_end);
238 }
239 return new_addr;
240 }
241 if (allocated_vma)
242 kmem_cache_free(vm_area_cachep, new_vma);
243 out:
244 return -ENOMEM;
245}
246
247
248
249
250
251
252
253
254unsigned long do_mremap(unsigned long addr,
255 unsigned long old_len, unsigned long new_len,
256 unsigned long flags, unsigned long new_addr)
257{
258 struct vm_area_struct *vma;
259 unsigned long ret = -EINVAL;
260 unsigned long charged = 0;
261
262 if (flags & ~(MREMAP_FIXED | MREMAP_MAYMOVE))
263 goto out;
264
265 if (addr & ~PAGE_MASK)
266 goto out;
267
268 old_len = PAGE_ALIGN(old_len);
269 new_len = PAGE_ALIGN(new_len);
270
271
272 if (flags & MREMAP_FIXED) {
273 if (new_addr & ~PAGE_MASK)
274 goto out;
275 if (!(flags & MREMAP_MAYMOVE))
276 goto out;
277
278 if (new_len > TASK_SIZE || new_addr > TASK_SIZE - new_len)
279 goto out;
280
281
282
283
284 if ((new_addr <= addr) && (new_addr+new_len) > addr)
285 goto out;
286
287 if ((addr <= new_addr) && (addr+old_len) > new_addr)
288 goto out;
289
290 do_munmap(current->mm, new_addr, new_len);
291 }
292
293
294
295
296
297
298 ret = addr;
299 if (old_len >= new_len) {
300 do_munmap(current->mm, addr+new_len, old_len - new_len);
301 if (!(flags & MREMAP_FIXED) || (new_addr == addr))
302 goto out;
303 old_len = new_len;
304 }
305
306
307
308
309 ret = -EFAULT;
310 vma = find_vma(current->mm, addr);
311 if (!vma || vma->vm_start > addr)
312 goto out;
313 if (is_vm_hugetlb_page(vma)) {
314 ret = -EINVAL;
315 goto out;
316 }
317
318 if (old_len > vma->vm_end - addr)
319 goto out;
320 if (vma->vm_flags & VM_DONTEXPAND) {
321 if (new_len > old_len)
322 goto out;
323 }
324 if (vma->vm_flags & VM_LOCKED) {
325 unsigned long locked = current->mm->locked_vm << PAGE_SHIFT;
326 locked += new_len - old_len;
327 ret = -EAGAIN;
328 if (locked > current->rlim[RLIMIT_MEMLOCK].rlim_cur)
329 goto out;
330 }
331 ret = -ENOMEM;
332 if ((current->mm->total_vm << PAGE_SHIFT) + (new_len - old_len)
333 > current->rlim[RLIMIT_AS].rlim_cur)
334 goto out;
335
336 if (vma->vm_flags & VM_ACCOUNT) {
337 charged = (new_len - old_len) >> PAGE_SHIFT;
338 if (!vm_enough_memory(charged))
339 goto out_nc;
340 }
341
342
343
344
345 if (old_len == vma->vm_end - addr &&
346 !((flags & MREMAP_FIXED) && (addr != new_addr)) &&
347 (old_len != new_len || !(flags & MREMAP_MAYMOVE))) {
348 unsigned long max_addr = TASK_SIZE;
349 if (vma->vm_next)
350 max_addr = vma->vm_next->vm_start;
351
352 if (max_addr - addr >= new_len) {
353 int pages = (new_len - old_len) >> PAGE_SHIFT;
354 spin_lock(&vma->vm_mm->page_table_lock);
355 vma->vm_end = addr + new_len;
356 spin_unlock(&vma->vm_mm->page_table_lock);
357 current->mm->total_vm += pages;
358 if (vma->vm_flags & VM_LOCKED) {
359 current->mm->locked_vm += pages;
360 make_pages_present(addr + old_len,
361 addr + new_len);
362 }
363 ret = addr;
364 goto out;
365 }
366 }
367
368
369
370
371
372 ret = -ENOMEM;
373 if (flags & MREMAP_MAYMOVE) {
374 if (!(flags & MREMAP_FIXED)) {
375 unsigned long map_flags = 0;
376 if (vma->vm_flags & VM_SHARED)
377 map_flags |= MAP_SHARED;
378
379 new_addr = get_unmapped_area(vma->vm_file, 0, new_len, vma->vm_pgoff, map_flags);
380 ret = new_addr;
381 if (new_addr & ~PAGE_MASK)
382 goto out;
383 }
384 ret = move_vma(vma, addr, old_len, new_len, new_addr);
385 }
386out:
387 if (ret & ~PAGE_MASK)
388 vm_unacct_memory(charged);
389out_nc:
390 return ret;
391}
392
393asmlinkage unsigned long sys_mremap(unsigned long addr,
394 unsigned long old_len, unsigned long new_len,
395 unsigned long flags, unsigned long new_addr)
396{
397 unsigned long ret;
398
399 down_write(¤t->mm->mmap_sem);
400 ret = do_mremap(addr, old_len, new_len, flags, new_addr);
401 up_write(¤t->mm->mmap_sem);
402 return ret;
403}
404