]>
Commit | Line | Data |
---|---|---|
60ffc30d CM |
1 | /* |
2 | * Low-level exception handling code | |
3 | * | |
4 | * Copyright (C) 2012 ARM Ltd. | |
5 | * Authors: Catalin Marinas <catalin.marinas@arm.com> | |
6 | * Will Deacon <will.deacon@arm.com> | |
7 | * | |
8 | * This program is free software; you can redistribute it and/or modify | |
9 | * it under the terms of the GNU General Public License version 2 as | |
10 | * published by the Free Software Foundation. | |
11 | * | |
12 | * This program is distributed in the hope that it will be useful, | |
13 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
14 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
15 | * GNU General Public License for more details. | |
16 | * | |
17 | * You should have received a copy of the GNU General Public License | |
18 | * along with this program. If not, see <http://www.gnu.org/licenses/>. | |
19 | */ | |
20 | ||
8e290624 | 21 | #include <linux/arm-smccc.h> |
60ffc30d CM |
22 | #include <linux/init.h> |
23 | #include <linux/linkage.h> | |
24 | ||
8d883b23 | 25 | #include <asm/alternative.h> |
60ffc30d CM |
26 | #include <asm/assembler.h> |
27 | #include <asm/asm-offsets.h> | |
905e8c5d | 28 | #include <asm/cpufeature.h> |
60ffc30d | 29 | #include <asm/errno.h> |
5c1ce6f7 | 30 | #include <asm/esr.h> |
8e23dacd | 31 | #include <asm/irq.h> |
c7b9adaf WD |
32 | #include <asm/memory.h> |
33 | #include <asm/mmu.h> | |
eef94a3d | 34 | #include <asm/processor.h> |
39bc88e5 | 35 | #include <asm/ptrace.h> |
60ffc30d | 36 | #include <asm/thread_info.h> |
b4b8664d | 37 | #include <asm/asm-uaccess.h> |
60ffc30d CM |
38 | #include <asm/unistd.h> |
39 | ||
6c81fe79 LB |
40 | /* |
41 | * Context tracking subsystem. Used to instrument transitions | |
42 | * between user and kernel mode. | |
43 | */ | |
d9be0325 | 44 | .macro ct_user_exit |
6c81fe79 LB |
45 | #ifdef CONFIG_CONTEXT_TRACKING |
46 | bl context_tracking_user_exit | |
6c81fe79 LB |
47 | #endif |
48 | .endm | |
49 | ||
50 | .macro ct_user_enter | |
51 | #ifdef CONFIG_CONTEXT_TRACKING | |
52 | bl context_tracking_user_enter | |
53 | #endif | |
54 | .endm | |
55 | ||
baaa7237 MR |
56 | .macro clear_gp_regs |
57 | .irp n,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29 | |
58 | mov x\n, xzr | |
59 | .endr | |
60 | .endm | |
61 | ||
60ffc30d CM |
62 | /* |
63 | * Bad Abort numbers | |
64 | *----------------- | |
65 | */ | |
66 | #define BAD_SYNC 0 | |
67 | #define BAD_IRQ 1 | |
68 | #define BAD_FIQ 2 | |
69 | #define BAD_ERROR 3 | |
70 | ||
5b1f7fe4 | 71 | .macro kernel_ventry, el, label, regsize = 64 |
b11e5759 | 72 | .align 7 |
4bf3286d | 73 | #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 |
ea1e3de8 | 74 | alternative_if ARM64_UNMAP_KERNEL_AT_EL0 |
4bf3286d WD |
75 | .if \el == 0 |
76 | .if \regsize == 64 | |
77 | mrs x30, tpidrro_el0 | |
78 | msr tpidrro_el0, xzr | |
79 | .else | |
80 | mov x30, xzr | |
81 | .endif | |
82 | .endif | |
ea1e3de8 | 83 | alternative_else_nop_endif |
4bf3286d WD |
84 | #endif |
85 | ||
63648dd2 | 86 | sub sp, sp, #S_FRAME_SIZE |
872d8327 MR |
87 | #ifdef CONFIG_VMAP_STACK |
88 | /* | |
89 | * Test whether the SP has overflowed, without corrupting a GPR. | |
90 | * Task and IRQ stacks are aligned to (1 << THREAD_SHIFT). | |
91 | */ | |
92 | add sp, sp, x0 // sp' = sp + x0 | |
93 | sub x0, sp, x0 // x0' = sp' - x0 = (sp + x0) - x0 = sp | |
94 | tbnz x0, #THREAD_SHIFT, 0f | |
95 | sub x0, sp, x0 // x0'' = sp' - x0' = (sp + x0) - sp = x0 | |
96 | sub sp, sp, x0 // sp'' = sp' - x0 = (sp + x0) - x0 = sp | |
5b1f7fe4 | 97 | b el\()\el\()_\label |
872d8327 MR |
98 | |
99 | 0: | |
100 | /* | |
101 | * Either we've just detected an overflow, or we've taken an exception | |
102 | * while on the overflow stack. Either way, we won't return to | |
103 | * userspace, and can clobber EL0 registers to free up GPRs. | |
104 | */ | |
105 | ||
106 | /* Stash the original SP (minus S_FRAME_SIZE) in tpidr_el0. */ | |
107 | msr tpidr_el0, x0 | |
108 | ||
109 | /* Recover the original x0 value and stash it in tpidrro_el0 */ | |
110 | sub x0, sp, x0 | |
111 | msr tpidrro_el0, x0 | |
112 | ||
113 | /* Switch to the overflow stack */ | |
114 | adr_this_cpu sp, overflow_stack + OVERFLOW_STACK_SIZE, x0 | |
115 | ||
116 | /* | |
117 | * Check whether we were already on the overflow stack. This may happen | |
118 | * after panic() re-enables interrupts. | |
119 | */ | |
120 | mrs x0, tpidr_el0 // sp of interrupted context | |
121 | sub x0, sp, x0 // delta with top of overflow stack | |
122 | tst x0, #~(OVERFLOW_STACK_SIZE - 1) // within range? | |
123 | b.ne __bad_stack // no? -> bad stack pointer | |
124 | ||
125 | /* We were already on the overflow stack. Restore sp/x0 and carry on. */ | |
126 | sub sp, sp, x0 | |
127 | mrs x0, tpidrro_el0 | |
128 | #endif | |
5b1f7fe4 | 129 | b el\()\el\()_\label |
b11e5759 MR |
130 | .endm |
131 | ||
4bf3286d WD |
132 | .macro tramp_alias, dst, sym |
133 | mov_q \dst, TRAMP_VALIAS | |
134 | add \dst, \dst, #(\sym - .entry.tramp.text) | |
b11e5759 MR |
135 | .endm |
136 | ||
8e290624 MZ |
137 | // This macro corrupts x0-x3. It is the caller's duty |
138 | // to save/restore them if required. | |
99ed3ed0 | 139 | .macro apply_ssbd, state, tmp1, tmp2 |
8e290624 | 140 | #ifdef CONFIG_ARM64_SSBD |
986372c4 | 141 | alternative_cb arm64_enable_wa2_handling |
99ed3ed0 | 142 | b .L__asm_ssbd_skip\@ |
986372c4 | 143 | alternative_cb_end |
5cf9ce6e | 144 | ldr_this_cpu \tmp2, arm64_ssbd_callback_required, \tmp1 |
99ed3ed0 | 145 | cbz \tmp2, .L__asm_ssbd_skip\@ |
9dd9614f | 146 | ldr \tmp2, [tsk, #TSK_TI_FLAGS] |
99ed3ed0 | 147 | tbnz \tmp2, #TIF_SSBD, .L__asm_ssbd_skip\@ |
8e290624 MZ |
148 | mov w0, #ARM_SMCCC_ARCH_WORKAROUND_2 |
149 | mov w1, #\state | |
150 | alternative_cb arm64_update_smccc_conduit | |
151 | nop // Patched to SMC/HVC #0 | |
152 | alternative_cb_end | |
99ed3ed0 | 153 | .L__asm_ssbd_skip\@: |
8e290624 MZ |
154 | #endif |
155 | .endm | |
156 | ||
b11e5759 | 157 | .macro kernel_entry, el, regsize = 64 |
60ffc30d CM |
158 | .if \regsize == 32 |
159 | mov w0, w0 // zero upper 32 bits of x0 | |
160 | .endif | |
63648dd2 WD |
161 | stp x0, x1, [sp, #16 * 0] |
162 | stp x2, x3, [sp, #16 * 1] | |
163 | stp x4, x5, [sp, #16 * 2] | |
164 | stp x6, x7, [sp, #16 * 3] | |
165 | stp x8, x9, [sp, #16 * 4] | |
166 | stp x10, x11, [sp, #16 * 5] | |
167 | stp x12, x13, [sp, #16 * 6] | |
168 | stp x14, x15, [sp, #16 * 7] | |
169 | stp x16, x17, [sp, #16 * 8] | |
170 | stp x18, x19, [sp, #16 * 9] | |
171 | stp x20, x21, [sp, #16 * 10] | |
172 | stp x22, x23, [sp, #16 * 11] | |
173 | stp x24, x25, [sp, #16 * 12] | |
174 | stp x26, x27, [sp, #16 * 13] | |
175 | stp x28, x29, [sp, #16 * 14] | |
176 | ||
60ffc30d | 177 | .if \el == 0 |
baaa7237 | 178 | clear_gp_regs |
60ffc30d | 179 | mrs x21, sp_el0 |
c02433dd MR |
180 | ldr_this_cpu tsk, __entry_task, x20 // Ensure MDSCR_EL1.SS is clear, |
181 | ldr x19, [tsk, #TSK_TI_FLAGS] // since we can unmask debug | |
2a283070 | 182 | disable_step_tsk x19, x20 // exceptions when scheduling. |
49003a8d | 183 | |
99ed3ed0 | 184 | apply_ssbd 1, x22, x23 |
8e290624 | 185 | |
60ffc30d CM |
186 | .else |
187 | add x21, sp, #S_FRAME_SIZE | |
4caf8758 | 188 | get_current_task tsk |
51369e39 | 189 | /* Save the task's original addr_limit and set USER_DS */ |
c02433dd | 190 | ldr x20, [tsk, #TSK_TI_ADDR_LIMIT] |
e19a6ee2 | 191 | str x20, [sp, #S_ORIG_ADDR_LIMIT] |
51369e39 | 192 | mov x20, #USER_DS |
c02433dd | 193 | str x20, [tsk, #TSK_TI_ADDR_LIMIT] |
563cada0 | 194 | /* No need to reset PSTATE.UAO, hardware's already set it to 0 for us */ |
e19a6ee2 | 195 | .endif /* \el == 0 */ |
60ffc30d CM |
196 | mrs x22, elr_el1 |
197 | mrs x23, spsr_el1 | |
198 | stp lr, x21, [sp, #S_LR] | |
39bc88e5 | 199 | |
73267498 AB |
200 | /* |
201 | * In order to be able to dump the contents of struct pt_regs at the | |
202 | * time the exception was taken (in case we attempt to walk the call | |
203 | * stack later), chain it together with the stack frames. | |
204 | */ | |
205 | .if \el == 0 | |
206 | stp xzr, xzr, [sp, #S_STACKFRAME] | |
207 | .else | |
208 | stp x29, x22, [sp, #S_STACKFRAME] | |
209 | .endif | |
210 | add x29, sp, #S_STACKFRAME | |
211 | ||
39bc88e5 CM |
212 | #ifdef CONFIG_ARM64_SW_TTBR0_PAN |
213 | /* | |
214 | * Set the TTBR0 PAN bit in SPSR. When the exception is taken from | |
215 | * EL0, there is no need to check the state of TTBR0_EL1 since | |
216 | * accesses are always enabled. | |
217 | * Note that the meaning of this bit differs from the ARMv8.1 PAN | |
218 | * feature as all TTBR0_EL1 accesses are disabled, not just those to | |
219 | * user mappings. | |
220 | */ | |
221 | alternative_if ARM64_HAS_PAN | |
222 | b 1f // skip TTBR0 PAN | |
223 | alternative_else_nop_endif | |
224 | ||
225 | .if \el != 0 | |
226 | mrs x21, ttbr0_el1 | |
b519538d | 227 | tst x21, #TTBR_ASID_MASK // Check for the reserved ASID |
39bc88e5 CM |
228 | orr x23, x23, #PSR_PAN_BIT // Set the emulated PAN in the saved SPSR |
229 | b.eq 1f // TTBR0 access already disabled | |
230 | and x23, x23, #~PSR_PAN_BIT // Clear the emulated PAN in the saved SPSR | |
231 | .endif | |
232 | ||
233 | __uaccess_ttbr0_disable x21 | |
234 | 1: | |
235 | #endif | |
236 | ||
60ffc30d CM |
237 | stp x22, x23, [sp, #S_PC] |
238 | ||
17c28958 | 239 | /* Not in a syscall by default (el0_svc overwrites for real syscall) */ |
60ffc30d | 240 | .if \el == 0 |
17c28958 | 241 | mov w21, #NO_SYSCALL |
35d0e6fb | 242 | str w21, [sp, #S_SYSCALLNO] |
60ffc30d CM |
243 | .endif |
244 | ||
6cdf9c7c JL |
245 | /* |
246 | * Set sp_el0 to current thread_info. | |
247 | */ | |
248 | .if \el == 0 | |
249 | msr sp_el0, tsk | |
250 | .endif | |
251 | ||
133d0518 JT |
252 | /* Save pmr */ |
253 | alternative_if ARM64_HAS_IRQ_PRIO_MASKING | |
254 | mrs_s x20, SYS_ICC_PMR_EL1 | |
255 | str x20, [sp, #S_PMR_SAVE] | |
256 | alternative_else_nop_endif | |
257 | ||
60ffc30d CM |
258 | /* |
259 | * Registers that may be useful after this macro is invoked: | |
260 | * | |
261 | * x21 - aborted SP | |
262 | * x22 - aborted PC | |
263 | * x23 - aborted PSTATE | |
264 | */ | |
265 | .endm | |
266 | ||
412fcb6c | 267 | .macro kernel_exit, el |
e19a6ee2 | 268 | .if \el != 0 |
8d66772e JM |
269 | disable_daif |
270 | ||
e19a6ee2 JM |
271 | /* Restore the task's original addr_limit. */ |
272 | ldr x20, [sp, #S_ORIG_ADDR_LIMIT] | |
c02433dd | 273 | str x20, [tsk, #TSK_TI_ADDR_LIMIT] |
e19a6ee2 JM |
274 | |
275 | /* No need to restore UAO, it will be restored from SPSR_EL1 */ | |
276 | .endif | |
277 | ||
133d0518 JT |
278 | /* Restore pmr */ |
279 | alternative_if ARM64_HAS_IRQ_PRIO_MASKING | |
280 | ldr x20, [sp, #S_PMR_SAVE] | |
281 | msr_s SYS_ICC_PMR_EL1, x20 | |
282 | /* Ensure priority change is seen by redistributor */ | |
283 | dsb sy | |
284 | alternative_else_nop_endif | |
285 | ||
60ffc30d CM |
286 | ldp x21, x22, [sp, #S_PC] // load ELR, SPSR |
287 | .if \el == 0 | |
6c81fe79 | 288 | ct_user_enter |
39bc88e5 CM |
289 | .endif |
290 | ||
291 | #ifdef CONFIG_ARM64_SW_TTBR0_PAN | |
292 | /* | |
293 | * Restore access to TTBR0_EL1. If returning to EL0, no need for SPSR | |
294 | * PAN bit checking. | |
295 | */ | |
296 | alternative_if ARM64_HAS_PAN | |
297 | b 2f // skip TTBR0 PAN | |
298 | alternative_else_nop_endif | |
299 | ||
300 | .if \el != 0 | |
301 | tbnz x22, #22, 1f // Skip re-enabling TTBR0 access if the PSR_PAN_BIT is set | |
302 | .endif | |
303 | ||
27a921e7 | 304 | __uaccess_ttbr0_enable x0, x1 |
39bc88e5 CM |
305 | |
306 | .if \el == 0 | |
307 | /* | |
308 | * Enable errata workarounds only if returning to user. The only | |
309 | * workaround currently required for TTBR0_EL1 changes are for the | |
310 | * Cavium erratum 27456 (broadcast TLBI instructions may cause I-cache | |
311 | * corruption). | |
312 | */ | |
95e3de35 | 313 | bl post_ttbr_update_workaround |
39bc88e5 CM |
314 | .endif |
315 | 1: | |
316 | .if \el != 0 | |
317 | and x22, x22, #~PSR_PAN_BIT // ARMv8.0 CPUs do not understand this bit | |
318 | .endif | |
319 | 2: | |
320 | #endif | |
321 | ||
322 | .if \el == 0 | |
60ffc30d | 323 | ldr x23, [sp, #S_SP] // load return stack pointer |
63648dd2 | 324 | msr sp_el0, x23 |
4bf3286d WD |
325 | tst x22, #PSR_MODE32_BIT // native task? |
326 | b.eq 3f | |
327 | ||
905e8c5d | 328 | #ifdef CONFIG_ARM64_ERRATUM_845719 |
6ba3b554 | 329 | alternative_if ARM64_WORKAROUND_845719 |
e28cabf1 DT |
330 | #ifdef CONFIG_PID_IN_CONTEXTIDR |
331 | mrs x29, contextidr_el1 | |
332 | msr contextidr_el1, x29 | |
905e8c5d | 333 | #else |
e28cabf1 | 334 | msr contextidr_el1, xzr |
905e8c5d | 335 | #endif |
6ba3b554 | 336 | alternative_else_nop_endif |
905e8c5d | 337 | #endif |
4bf3286d | 338 | 3: |
99ed3ed0 | 339 | apply_ssbd 0, x0, x1 |
60ffc30d | 340 | .endif |
39bc88e5 | 341 | |
63648dd2 WD |
342 | msr elr_el1, x21 // set up the return data |
343 | msr spsr_el1, x22 | |
63648dd2 | 344 | ldp x0, x1, [sp, #16 * 0] |
63648dd2 WD |
345 | ldp x2, x3, [sp, #16 * 1] |
346 | ldp x4, x5, [sp, #16 * 2] | |
347 | ldp x6, x7, [sp, #16 * 3] | |
348 | ldp x8, x9, [sp, #16 * 4] | |
349 | ldp x10, x11, [sp, #16 * 5] | |
350 | ldp x12, x13, [sp, #16 * 6] | |
351 | ldp x14, x15, [sp, #16 * 7] | |
352 | ldp x16, x17, [sp, #16 * 8] | |
353 | ldp x18, x19, [sp, #16 * 9] | |
354 | ldp x20, x21, [sp, #16 * 10] | |
355 | ldp x22, x23, [sp, #16 * 11] | |
356 | ldp x24, x25, [sp, #16 * 12] | |
357 | ldp x26, x27, [sp, #16 * 13] | |
358 | ldp x28, x29, [sp, #16 * 14] | |
359 | ldr lr, [sp, #S_LR] | |
360 | add sp, sp, #S_FRAME_SIZE // restore sp | |
4bf3286d | 361 | |
4bf3286d | 362 | .if \el == 0 |
ea1e3de8 WD |
363 | alternative_insn eret, nop, ARM64_UNMAP_KERNEL_AT_EL0 |
364 | #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 | |
4bf3286d WD |
365 | bne 4f |
366 | msr far_el1, x30 | |
367 | tramp_alias x30, tramp_exit_native | |
368 | br x30 | |
369 | 4: | |
370 | tramp_alias x30, tramp_exit_compat | |
371 | br x30 | |
ea1e3de8 | 372 | #endif |
4bf3286d WD |
373 | .else |
374 | eret | |
375 | .endif | |
679db708 | 376 | sb |
60ffc30d CM |
377 | .endm |
378 | ||
971c67ce | 379 | .macro irq_stack_entry |
8e23dacd JM |
380 | mov x19, sp // preserve the original sp |
381 | ||
8e23dacd | 382 | /* |
c02433dd MR |
383 | * Compare sp with the base of the task stack. |
384 | * If the top ~(THREAD_SIZE - 1) bits match, we are on a task stack, | |
385 | * and should switch to the irq stack. | |
8e23dacd | 386 | */ |
c02433dd MR |
387 | ldr x25, [tsk, TSK_STACK] |
388 | eor x25, x25, x19 | |
389 | and x25, x25, #~(THREAD_SIZE - 1) | |
390 | cbnz x25, 9998f | |
8e23dacd | 391 | |
f60fe78f | 392 | ldr_this_cpu x25, irq_stack_ptr, x26 |
34be98f4 | 393 | mov x26, #IRQ_STACK_SIZE |
8e23dacd | 394 | add x26, x25, x26 |
d224a69e JM |
395 | |
396 | /* switch to the irq stack */ | |
8e23dacd | 397 | mov sp, x26 |
8e23dacd JM |
398 | 9998: |
399 | .endm | |
400 | ||
401 | /* | |
402 | * x19 should be preserved between irq_stack_entry and | |
403 | * irq_stack_exit. | |
404 | */ | |
405 | .macro irq_stack_exit | |
406 | mov sp, x19 | |
407 | .endm | |
408 | ||
8c2c596f | 409 | /* GPRs used by entry code */ |
60ffc30d CM |
410 | tsk .req x28 // current thread_info |
411 | ||
412 | /* | |
413 | * Interrupt handling. | |
414 | */ | |
415 | .macro irq_handler | |
8e23dacd | 416 | ldr_l x1, handle_arch_irq |
60ffc30d | 417 | mov x0, sp |
971c67ce | 418 | irq_stack_entry |
60ffc30d | 419 | blr x1 |
8e23dacd | 420 | irq_stack_exit |
60ffc30d CM |
421 | .endm |
422 | ||
423 | .text | |
424 | ||
425 | /* | |
426 | * Exception vectors. | |
427 | */ | |
888b3c87 | 428 | .pushsection ".entry.text", "ax" |
60ffc30d CM |
429 | |
430 | .align 11 | |
431 | ENTRY(vectors) | |
5b1f7fe4 WD |
432 | kernel_ventry 1, sync_invalid // Synchronous EL1t |
433 | kernel_ventry 1, irq_invalid // IRQ EL1t | |
434 | kernel_ventry 1, fiq_invalid // FIQ EL1t | |
435 | kernel_ventry 1, error_invalid // Error EL1t | |
60ffc30d | 436 | |
5b1f7fe4 WD |
437 | kernel_ventry 1, sync // Synchronous EL1h |
438 | kernel_ventry 1, irq // IRQ EL1h | |
439 | kernel_ventry 1, fiq_invalid // FIQ EL1h | |
440 | kernel_ventry 1, error // Error EL1h | |
60ffc30d | 441 | |
5b1f7fe4 WD |
442 | kernel_ventry 0, sync // Synchronous 64-bit EL0 |
443 | kernel_ventry 0, irq // IRQ 64-bit EL0 | |
444 | kernel_ventry 0, fiq_invalid // FIQ 64-bit EL0 | |
445 | kernel_ventry 0, error // Error 64-bit EL0 | |
60ffc30d CM |
446 | |
447 | #ifdef CONFIG_COMPAT | |
5b1f7fe4 WD |
448 | kernel_ventry 0, sync_compat, 32 // Synchronous 32-bit EL0 |
449 | kernel_ventry 0, irq_compat, 32 // IRQ 32-bit EL0 | |
450 | kernel_ventry 0, fiq_invalid_compat, 32 // FIQ 32-bit EL0 | |
451 | kernel_ventry 0, error_compat, 32 // Error 32-bit EL0 | |
60ffc30d | 452 | #else |
5b1f7fe4 WD |
453 | kernel_ventry 0, sync_invalid, 32 // Synchronous 32-bit EL0 |
454 | kernel_ventry 0, irq_invalid, 32 // IRQ 32-bit EL0 | |
455 | kernel_ventry 0, fiq_invalid, 32 // FIQ 32-bit EL0 | |
456 | kernel_ventry 0, error_invalid, 32 // Error 32-bit EL0 | |
60ffc30d CM |
457 | #endif |
458 | END(vectors) | |
459 | ||
872d8327 MR |
460 | #ifdef CONFIG_VMAP_STACK |
461 | /* | |
462 | * We detected an overflow in kernel_ventry, which switched to the | |
463 | * overflow stack. Stash the exception regs, and head to our overflow | |
464 | * handler. | |
465 | */ | |
466 | __bad_stack: | |
467 | /* Restore the original x0 value */ | |
468 | mrs x0, tpidrro_el0 | |
469 | ||
470 | /* | |
471 | * Store the original GPRs to the new stack. The orginal SP (minus | |
472 | * S_FRAME_SIZE) was stashed in tpidr_el0 by kernel_ventry. | |
473 | */ | |
474 | sub sp, sp, #S_FRAME_SIZE | |
475 | kernel_entry 1 | |
476 | mrs x0, tpidr_el0 | |
477 | add x0, x0, #S_FRAME_SIZE | |
478 | str x0, [sp, #S_SP] | |
479 | ||
480 | /* Stash the regs for handle_bad_stack */ | |
481 | mov x0, sp | |
482 | ||
483 | /* Time to die */ | |
484 | bl handle_bad_stack | |
485 | ASM_BUG() | |
486 | #endif /* CONFIG_VMAP_STACK */ | |
487 | ||
60ffc30d CM |
488 | /* |
489 | * Invalid mode handlers | |
490 | */ | |
491 | .macro inv_entry, el, reason, regsize = 64 | |
b660950c | 492 | kernel_entry \el, \regsize |
60ffc30d CM |
493 | mov x0, sp |
494 | mov x1, #\reason | |
495 | mrs x2, esr_el1 | |
2d0e751a MR |
496 | bl bad_mode |
497 | ASM_BUG() | |
60ffc30d CM |
498 | .endm |
499 | ||
500 | el0_sync_invalid: | |
501 | inv_entry 0, BAD_SYNC | |
502 | ENDPROC(el0_sync_invalid) | |
503 | ||
504 | el0_irq_invalid: | |
505 | inv_entry 0, BAD_IRQ | |
506 | ENDPROC(el0_irq_invalid) | |
507 | ||
508 | el0_fiq_invalid: | |
509 | inv_entry 0, BAD_FIQ | |
510 | ENDPROC(el0_fiq_invalid) | |
511 | ||
512 | el0_error_invalid: | |
513 | inv_entry 0, BAD_ERROR | |
514 | ENDPROC(el0_error_invalid) | |
515 | ||
516 | #ifdef CONFIG_COMPAT | |
517 | el0_fiq_invalid_compat: | |
518 | inv_entry 0, BAD_FIQ, 32 | |
519 | ENDPROC(el0_fiq_invalid_compat) | |
60ffc30d CM |
520 | #endif |
521 | ||
522 | el1_sync_invalid: | |
523 | inv_entry 1, BAD_SYNC | |
524 | ENDPROC(el1_sync_invalid) | |
525 | ||
526 | el1_irq_invalid: | |
527 | inv_entry 1, BAD_IRQ | |
528 | ENDPROC(el1_irq_invalid) | |
529 | ||
530 | el1_fiq_invalid: | |
531 | inv_entry 1, BAD_FIQ | |
532 | ENDPROC(el1_fiq_invalid) | |
533 | ||
534 | el1_error_invalid: | |
535 | inv_entry 1, BAD_ERROR | |
536 | ENDPROC(el1_error_invalid) | |
537 | ||
538 | /* | |
539 | * EL1 mode handlers. | |
540 | */ | |
541 | .align 6 | |
542 | el1_sync: | |
543 | kernel_entry 1 | |
544 | mrs x1, esr_el1 // read the syndrome register | |
aed40e01 MR |
545 | lsr x24, x1, #ESR_ELx_EC_SHIFT // exception class |
546 | cmp x24, #ESR_ELx_EC_DABT_CUR // data abort in EL1 | |
60ffc30d | 547 | b.eq el1_da |
9adeb8e7 LA |
548 | cmp x24, #ESR_ELx_EC_IABT_CUR // instruction abort in EL1 |
549 | b.eq el1_ia | |
aed40e01 | 550 | cmp x24, #ESR_ELx_EC_SYS64 // configurable trap |
60ffc30d | 551 | b.eq el1_undef |
aed40e01 | 552 | cmp x24, #ESR_ELx_EC_SP_ALIGN // stack alignment exception |
60ffc30d | 553 | b.eq el1_sp_pc |
aed40e01 | 554 | cmp x24, #ESR_ELx_EC_PC_ALIGN // pc alignment exception |
60ffc30d | 555 | b.eq el1_sp_pc |
aed40e01 | 556 | cmp x24, #ESR_ELx_EC_UNKNOWN // unknown exception in EL1 |
60ffc30d | 557 | b.eq el1_undef |
aed40e01 | 558 | cmp x24, #ESR_ELx_EC_BREAKPT_CUR // debug exception in EL1 |
60ffc30d CM |
559 | b.ge el1_dbg |
560 | b el1_inv | |
9adeb8e7 LA |
561 | |
562 | el1_ia: | |
563 | /* | |
564 | * Fall through to the Data abort case | |
565 | */ | |
60ffc30d CM |
566 | el1_da: |
567 | /* | |
568 | * Data abort handling | |
569 | */ | |
276e9327 | 570 | mrs x3, far_el1 |
b55a5a1b | 571 | inherit_daif pstate=x23, tmp=x2 |
276e9327 | 572 | clear_address_tag x0, x3 |
60ffc30d CM |
573 | mov x2, sp // struct pt_regs |
574 | bl do_mem_abort | |
575 | ||
60ffc30d CM |
576 | kernel_exit 1 |
577 | el1_sp_pc: | |
578 | /* | |
579 | * Stack or PC alignment exception handling | |
580 | */ | |
581 | mrs x0, far_el1 | |
b55a5a1b | 582 | inherit_daif pstate=x23, tmp=x2 |
60ffc30d | 583 | mov x2, sp |
2d0e751a MR |
584 | bl do_sp_pc_abort |
585 | ASM_BUG() | |
60ffc30d CM |
586 | el1_undef: |
587 | /* | |
588 | * Undefined instruction | |
589 | */ | |
b55a5a1b | 590 | inherit_daif pstate=x23, tmp=x2 |
60ffc30d | 591 | mov x0, sp |
2d0e751a | 592 | bl do_undefinstr |
0bf0f444 | 593 | kernel_exit 1 |
60ffc30d CM |
594 | el1_dbg: |
595 | /* | |
596 | * Debug exception handling | |
597 | */ | |
aed40e01 | 598 | cmp x24, #ESR_ELx_EC_BRK64 // if BRK64 |
ee6214ce | 599 | cinc x24, x24, eq // set bit '0' |
60ffc30d CM |
600 | tbz x24, #0, el1_inv // EL1 only |
601 | mrs x0, far_el1 | |
602 | mov x2, sp // struct pt_regs | |
603 | bl do_debug_exception | |
60ffc30d CM |
604 | kernel_exit 1 |
605 | el1_inv: | |
606 | // TODO: add support for undefined instructions in kernel mode | |
b55a5a1b | 607 | inherit_daif pstate=x23, tmp=x2 |
60ffc30d | 608 | mov x0, sp |
1b42804d | 609 | mov x2, x1 |
60ffc30d | 610 | mov x1, #BAD_SYNC |
2d0e751a MR |
611 | bl bad_mode |
612 | ASM_BUG() | |
60ffc30d CM |
613 | ENDPROC(el1_sync) |
614 | ||
615 | .align 6 | |
616 | el1_irq: | |
617 | kernel_entry 1 | |
b282e1ce | 618 | enable_da_f |
60ffc30d | 619 | #ifdef CONFIG_TRACE_IRQFLAGS |
c25349fd JT |
620 | #ifdef CONFIG_ARM64_PSEUDO_NMI |
621 | alternative_if ARM64_HAS_IRQ_PRIO_MASKING | |
622 | ldr x20, [sp, #S_PMR_SAVE] | |
623 | alternative_else | |
624 | mov x20, #GIC_PRIO_IRQON | |
625 | alternative_endif | |
626 | cmp x20, #GIC_PRIO_IRQOFF | |
627 | /* Irqs were disabled, don't trace */ | |
628 | b.ls 1f | |
629 | #endif | |
60ffc30d | 630 | bl trace_hardirqs_off |
c25349fd | 631 | 1: |
60ffc30d | 632 | #endif |
64681787 | 633 | |
60ffc30d | 634 | irq_handler |
64681787 | 635 | |
60ffc30d | 636 | #ifdef CONFIG_PREEMPT |
7faa313f | 637 | ldr x24, [tsk, #TSK_TI_PREEMPT] // get preempt count |
1234ad68 JT |
638 | alternative_if ARM64_HAS_IRQ_PRIO_MASKING |
639 | /* | |
640 | * DA_F were cleared at start of handling. If anything is set in DAIF, | |
641 | * we come back from an NMI, so skip preemption | |
642 | */ | |
643 | mrs x0, daif | |
644 | orr x24, x24, x0 | |
645 | alternative_else_nop_endif | |
646 | cbnz x24, 1f // preempt count != 0 || NMI return path | |
8aa67d18 | 647 | bl preempt_schedule_irq // irq en/disable is done inside |
60ffc30d CM |
648 | 1: |
649 | #endif | |
650 | #ifdef CONFIG_TRACE_IRQFLAGS | |
c25349fd JT |
651 | #ifdef CONFIG_ARM64_PSEUDO_NMI |
652 | /* | |
653 | * if IRQs were disabled when we received the interrupt, we have an NMI | |
654 | * and we are not re-enabling interrupt upon eret. Skip tracing. | |
655 | */ | |
656 | cmp x20, #GIC_PRIO_IRQOFF | |
657 | b.ls 1f | |
658 | #endif | |
60ffc30d | 659 | bl trace_hardirqs_on |
c25349fd | 660 | 1: |
60ffc30d | 661 | #endif |
c25349fd | 662 | |
60ffc30d CM |
663 | kernel_exit 1 |
664 | ENDPROC(el1_irq) | |
665 | ||
60ffc30d CM |
666 | /* |
667 | * EL0 mode handlers. | |
668 | */ | |
669 | .align 6 | |
670 | el0_sync: | |
671 | kernel_entry 0 | |
672 | mrs x25, esr_el1 // read the syndrome register | |
aed40e01 MR |
673 | lsr x24, x25, #ESR_ELx_EC_SHIFT // exception class |
674 | cmp x24, #ESR_ELx_EC_SVC64 // SVC in 64-bit state | |
60ffc30d | 675 | b.eq el0_svc |
aed40e01 | 676 | cmp x24, #ESR_ELx_EC_DABT_LOW // data abort in EL0 |
60ffc30d | 677 | b.eq el0_da |
aed40e01 | 678 | cmp x24, #ESR_ELx_EC_IABT_LOW // instruction abort in EL0 |
60ffc30d | 679 | b.eq el0_ia |
aed40e01 | 680 | cmp x24, #ESR_ELx_EC_FP_ASIMD // FP/ASIMD access |
60ffc30d | 681 | b.eq el0_fpsimd_acc |
bc0ee476 DM |
682 | cmp x24, #ESR_ELx_EC_SVE // SVE access |
683 | b.eq el0_sve_acc | |
aed40e01 | 684 | cmp x24, #ESR_ELx_EC_FP_EXC64 // FP/ASIMD exception |
60ffc30d | 685 | b.eq el0_fpsimd_exc |
aed40e01 | 686 | cmp x24, #ESR_ELx_EC_SYS64 // configurable trap |
c219bc4e | 687 | ccmp x24, #ESR_ELx_EC_WFx, #4, ne |
7dd01aef | 688 | b.eq el0_sys |
aed40e01 | 689 | cmp x24, #ESR_ELx_EC_SP_ALIGN // stack alignment exception |
60ffc30d | 690 | b.eq el0_sp_pc |
aed40e01 | 691 | cmp x24, #ESR_ELx_EC_PC_ALIGN // pc alignment exception |
60ffc30d | 692 | b.eq el0_sp_pc |
aed40e01 | 693 | cmp x24, #ESR_ELx_EC_UNKNOWN // unknown exception in EL0 |
60ffc30d | 694 | b.eq el0_undef |
aed40e01 | 695 | cmp x24, #ESR_ELx_EC_BREAKPT_LOW // debug exception in EL0 |
60ffc30d CM |
696 | b.ge el0_dbg |
697 | b el0_inv | |
698 | ||
699 | #ifdef CONFIG_COMPAT | |
700 | .align 6 | |
701 | el0_sync_compat: | |
702 | kernel_entry 0, 32 | |
703 | mrs x25, esr_el1 // read the syndrome register | |
aed40e01 MR |
704 | lsr x24, x25, #ESR_ELx_EC_SHIFT // exception class |
705 | cmp x24, #ESR_ELx_EC_SVC32 // SVC in 32-bit state | |
60ffc30d | 706 | b.eq el0_svc_compat |
aed40e01 | 707 | cmp x24, #ESR_ELx_EC_DABT_LOW // data abort in EL0 |
60ffc30d | 708 | b.eq el0_da |
aed40e01 | 709 | cmp x24, #ESR_ELx_EC_IABT_LOW // instruction abort in EL0 |
60ffc30d | 710 | b.eq el0_ia |
aed40e01 | 711 | cmp x24, #ESR_ELx_EC_FP_ASIMD // FP/ASIMD access |
60ffc30d | 712 | b.eq el0_fpsimd_acc |
aed40e01 | 713 | cmp x24, #ESR_ELx_EC_FP_EXC32 // FP/ASIMD exception |
60ffc30d | 714 | b.eq el0_fpsimd_exc |
77f3228f MS |
715 | cmp x24, #ESR_ELx_EC_PC_ALIGN // pc alignment exception |
716 | b.eq el0_sp_pc | |
aed40e01 | 717 | cmp x24, #ESR_ELx_EC_UNKNOWN // unknown exception in EL0 |
60ffc30d | 718 | b.eq el0_undef |
aed40e01 | 719 | cmp x24, #ESR_ELx_EC_CP15_32 // CP15 MRC/MCR trap |
70c63cdf | 720 | b.eq el0_cp15 |
aed40e01 | 721 | cmp x24, #ESR_ELx_EC_CP15_64 // CP15 MRRC/MCRR trap |
70c63cdf | 722 | b.eq el0_cp15 |
aed40e01 | 723 | cmp x24, #ESR_ELx_EC_CP14_MR // CP14 MRC/MCR trap |
381cc2b9 | 724 | b.eq el0_undef |
aed40e01 | 725 | cmp x24, #ESR_ELx_EC_CP14_LS // CP14 LDC/STC trap |
381cc2b9 | 726 | b.eq el0_undef |
aed40e01 | 727 | cmp x24, #ESR_ELx_EC_CP14_64 // CP14 MRRC/MCRR trap |
381cc2b9 | 728 | b.eq el0_undef |
aed40e01 | 729 | cmp x24, #ESR_ELx_EC_BREAKPT_LOW // debug exception in EL0 |
60ffc30d CM |
730 | b.ge el0_dbg |
731 | b el0_inv | |
732 | el0_svc_compat: | |
3b714275 MR |
733 | mov x0, sp |
734 | bl el0_svc_compat_handler | |
735 | b ret_to_user | |
60ffc30d CM |
736 | |
737 | .align 6 | |
738 | el0_irq_compat: | |
739 | kernel_entry 0, 32 | |
740 | b el0_irq_naked | |
a92d4d14 XX |
741 | |
742 | el0_error_compat: | |
743 | kernel_entry 0, 32 | |
744 | b el0_error_naked | |
70c63cdf MZ |
745 | |
746 | el0_cp15: | |
747 | /* | |
748 | * Trapped CP15 (MRC, MCR, MRRC, MCRR) instructions | |
749 | */ | |
750 | enable_daif | |
751 | ct_user_exit | |
752 | mov x0, x25 | |
753 | mov x1, sp | |
754 | bl do_cp15instr | |
755 | b ret_to_user | |
60ffc30d CM |
756 | #endif |
757 | ||
758 | el0_da: | |
759 | /* | |
760 | * Data abort handling | |
761 | */ | |
6ab6463a | 762 | mrs x26, far_el1 |
746647c7 | 763 | enable_daif |
6c81fe79 | 764 | ct_user_exit |
276e9327 | 765 | clear_address_tag x0, x26 |
60ffc30d CM |
766 | mov x1, x25 |
767 | mov x2, sp | |
d54e81f9 WD |
768 | bl do_mem_abort |
769 | b ret_to_user | |
60ffc30d CM |
770 | el0_ia: |
771 | /* | |
772 | * Instruction abort handling | |
773 | */ | |
6ab6463a | 774 | mrs x26, far_el1 |
0f15adbb WD |
775 | enable_da_f |
776 | #ifdef CONFIG_TRACE_IRQFLAGS | |
777 | bl trace_hardirqs_off | |
778 | #endif | |
6c81fe79 | 779 | ct_user_exit |
6ab6463a | 780 | mov x0, x26 |
541ec870 | 781 | mov x1, x25 |
60ffc30d | 782 | mov x2, sp |
0f15adbb | 783 | bl do_el0_ia_bp_hardening |
d54e81f9 | 784 | b ret_to_user |
60ffc30d CM |
785 | el0_fpsimd_acc: |
786 | /* | |
787 | * Floating Point or Advanced SIMD access | |
788 | */ | |
746647c7 | 789 | enable_daif |
6c81fe79 | 790 | ct_user_exit |
60ffc30d CM |
791 | mov x0, x25 |
792 | mov x1, sp | |
d54e81f9 WD |
793 | bl do_fpsimd_acc |
794 | b ret_to_user | |
bc0ee476 DM |
795 | el0_sve_acc: |
796 | /* | |
797 | * Scalable Vector Extension access | |
798 | */ | |
799 | enable_daif | |
800 | ct_user_exit | |
801 | mov x0, x25 | |
802 | mov x1, sp | |
803 | bl do_sve_acc | |
804 | b ret_to_user | |
60ffc30d CM |
805 | el0_fpsimd_exc: |
806 | /* | |
bc0ee476 | 807 | * Floating Point, Advanced SIMD or SVE exception |
60ffc30d | 808 | */ |
746647c7 | 809 | enable_daif |
6c81fe79 | 810 | ct_user_exit |
60ffc30d CM |
811 | mov x0, x25 |
812 | mov x1, sp | |
d54e81f9 WD |
813 | bl do_fpsimd_exc |
814 | b ret_to_user | |
60ffc30d CM |
815 | el0_sp_pc: |
816 | /* | |
817 | * Stack or PC alignment exception handling | |
818 | */ | |
6ab6463a | 819 | mrs x26, far_el1 |
5dfc6ed2 WD |
820 | enable_da_f |
821 | #ifdef CONFIG_TRACE_IRQFLAGS | |
822 | bl trace_hardirqs_off | |
823 | #endif | |
46b0567c | 824 | ct_user_exit |
6ab6463a | 825 | mov x0, x26 |
60ffc30d CM |
826 | mov x1, x25 |
827 | mov x2, sp | |
d54e81f9 WD |
828 | bl do_sp_pc_abort |
829 | b ret_to_user | |
60ffc30d CM |
830 | el0_undef: |
831 | /* | |
832 | * Undefined instruction | |
833 | */ | |
746647c7 | 834 | enable_daif |
6c81fe79 | 835 | ct_user_exit |
2a283070 | 836 | mov x0, sp |
d54e81f9 WD |
837 | bl do_undefinstr |
838 | b ret_to_user | |
7dd01aef AP |
839 | el0_sys: |
840 | /* | |
841 | * System instructions, for trapped cache maintenance instructions | |
842 | */ | |
746647c7 | 843 | enable_daif |
7dd01aef AP |
844 | ct_user_exit |
845 | mov x0, x25 | |
846 | mov x1, sp | |
847 | bl do_sysinstr | |
848 | b ret_to_user | |
60ffc30d CM |
849 | el0_dbg: |
850 | /* | |
851 | * Debug exception handling | |
852 | */ | |
853 | tbnz x24, #0, el0_inv // EL0 only | |
854 | mrs x0, far_el1 | |
60ffc30d CM |
855 | mov x1, x25 |
856 | mov x2, sp | |
2a283070 | 857 | bl do_debug_exception |
746647c7 | 858 | enable_daif |
6c81fe79 | 859 | ct_user_exit |
2a283070 | 860 | b ret_to_user |
60ffc30d | 861 | el0_inv: |
746647c7 | 862 | enable_daif |
6c81fe79 | 863 | ct_user_exit |
60ffc30d CM |
864 | mov x0, sp |
865 | mov x1, #BAD_SYNC | |
1b42804d | 866 | mov x2, x25 |
7d9e8f71 | 867 | bl bad_el0_sync |
d54e81f9 | 868 | b ret_to_user |
60ffc30d CM |
869 | ENDPROC(el0_sync) |
870 | ||
871 | .align 6 | |
872 | el0_irq: | |
873 | kernel_entry 0 | |
874 | el0_irq_naked: | |
b282e1ce | 875 | enable_da_f |
60ffc30d CM |
876 | #ifdef CONFIG_TRACE_IRQFLAGS |
877 | bl trace_hardirqs_off | |
878 | #endif | |
64681787 | 879 | |
6c81fe79 | 880 | ct_user_exit |
30d88c0e WD |
881 | #ifdef CONFIG_HARDEN_BRANCH_PREDICTOR |
882 | tbz x22, #55, 1f | |
883 | bl do_el0_irq_bp_hardening | |
884 | 1: | |
885 | #endif | |
60ffc30d | 886 | irq_handler |
64681787 | 887 | |
60ffc30d CM |
888 | #ifdef CONFIG_TRACE_IRQFLAGS |
889 | bl trace_hardirqs_on | |
890 | #endif | |
891 | b ret_to_user | |
892 | ENDPROC(el0_irq) | |
893 | ||
a92d4d14 XX |
894 | el1_error: |
895 | kernel_entry 1 | |
896 | mrs x1, esr_el1 | |
897 | enable_dbg | |
898 | mov x0, sp | |
899 | bl do_serror | |
900 | kernel_exit 1 | |
901 | ENDPROC(el1_error) | |
902 | ||
903 | el0_error: | |
904 | kernel_entry 0 | |
905 | el0_error_naked: | |
906 | mrs x1, esr_el1 | |
907 | enable_dbg | |
908 | mov x0, sp | |
909 | bl do_serror | |
910 | enable_daif | |
911 | ct_user_exit | |
912 | b ret_to_user | |
913 | ENDPROC(el0_error) | |
914 | ||
60ffc30d CM |
915 | /* |
916 | * Ok, we need to do extra processing, enter the slow path. | |
917 | */ | |
60ffc30d | 918 | work_pending: |
60ffc30d | 919 | mov x0, sp // 'regs' |
60ffc30d | 920 | bl do_notify_resume |
db3899a6 | 921 | #ifdef CONFIG_TRACE_IRQFLAGS |
421dd6fa | 922 | bl trace_hardirqs_on // enabled while in userspace |
db3899a6 | 923 | #endif |
c02433dd | 924 | ldr x1, [tsk, #TSK_TI_FLAGS] // re-check for single-step |
421dd6fa | 925 | b finish_ret_to_user |
60ffc30d CM |
926 | /* |
927 | * "slow" syscall return path. | |
928 | */ | |
59dc67b0 | 929 | ret_to_user: |
8d66772e | 930 | disable_daif |
c02433dd | 931 | ldr x1, [tsk, #TSK_TI_FLAGS] |
60ffc30d CM |
932 | and x2, x1, #_TIF_WORK_MASK |
933 | cbnz x2, work_pending | |
421dd6fa | 934 | finish_ret_to_user: |
2a283070 | 935 | enable_step_tsk x1, x2 |
0b3e3366 LA |
936 | #ifdef CONFIG_GCC_PLUGIN_STACKLEAK |
937 | bl stackleak_erase | |
938 | #endif | |
412fcb6c | 939 | kernel_exit 0 |
60ffc30d CM |
940 | ENDPROC(ret_to_user) |
941 | ||
60ffc30d CM |
942 | /* |
943 | * SVC handler. | |
944 | */ | |
945 | .align 6 | |
946 | el0_svc: | |
60ffc30d | 947 | mov x0, sp |
3b714275 | 948 | bl el0_svc_handler |
60ffc30d | 949 | b ret_to_user |
f37099b6 | 950 | ENDPROC(el0_svc) |
60ffc30d | 951 | |
888b3c87 PA |
952 | .popsection // .entry.text |
953 | ||
c7b9adaf WD |
954 | #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 |
955 | /* | |
956 | * Exception vectors trampoline. | |
957 | */ | |
958 | .pushsection ".entry.tramp.text", "ax" | |
959 | ||
960 | .macro tramp_map_kernel, tmp | |
961 | mrs \tmp, ttbr1_el1 | |
1e1b8c04 | 962 | add \tmp, \tmp, #(PAGE_SIZE + RESERVED_TTBR0_SIZE) |
c7b9adaf WD |
963 | bic \tmp, \tmp, #USER_ASID_FLAG |
964 | msr ttbr1_el1, \tmp | |
d1777e68 WD |
965 | #ifdef CONFIG_QCOM_FALKOR_ERRATUM_1003 |
966 | alternative_if ARM64_WORKAROUND_QCOM_FALKOR_E1003 | |
967 | /* ASID already in \tmp[63:48] */ | |
968 | movk \tmp, #:abs_g2_nc:(TRAMP_VALIAS >> 12) | |
969 | movk \tmp, #:abs_g1_nc:(TRAMP_VALIAS >> 12) | |
970 | /* 2MB boundary containing the vectors, so we nobble the walk cache */ | |
971 | movk \tmp, #:abs_g0_nc:((TRAMP_VALIAS & ~(SZ_2M - 1)) >> 12) | |
972 | isb | |
973 | tlbi vae1, \tmp | |
974 | dsb nsh | |
975 | alternative_else_nop_endif | |
976 | #endif /* CONFIG_QCOM_FALKOR_ERRATUM_1003 */ | |
c7b9adaf WD |
977 | .endm |
978 | ||
979 | .macro tramp_unmap_kernel, tmp | |
980 | mrs \tmp, ttbr1_el1 | |
1e1b8c04 | 981 | sub \tmp, \tmp, #(PAGE_SIZE + RESERVED_TTBR0_SIZE) |
c7b9adaf WD |
982 | orr \tmp, \tmp, #USER_ASID_FLAG |
983 | msr ttbr1_el1, \tmp | |
984 | /* | |
f167211a WD |
985 | * We avoid running the post_ttbr_update_workaround here because |
986 | * it's only needed by Cavium ThunderX, which requires KPTI to be | |
987 | * disabled. | |
c7b9adaf WD |
988 | */ |
989 | .endm | |
990 | ||
991 | .macro tramp_ventry, regsize = 64 | |
992 | .align 7 | |
993 | 1: | |
994 | .if \regsize == 64 | |
995 | msr tpidrro_el0, x30 // Restored in kernel_ventry | |
996 | .endif | |
be04a6d1 WD |
997 | /* |
998 | * Defend against branch aliasing attacks by pushing a dummy | |
999 | * entry onto the return stack and using a RET instruction to | |
1000 | * enter the full-fat kernel vectors. | |
1001 | */ | |
1002 | bl 2f | |
1003 | b . | |
1004 | 2: | |
c7b9adaf | 1005 | tramp_map_kernel x30 |
6c27c408 WD |
1006 | #ifdef CONFIG_RANDOMIZE_BASE |
1007 | adr x30, tramp_vectors + PAGE_SIZE | |
1008 | alternative_insn isb, nop, ARM64_WORKAROUND_QCOM_FALKOR_E1003 | |
1009 | ldr x30, [x30] | |
1010 | #else | |
c7b9adaf | 1011 | ldr x30, =vectors |
6c27c408 | 1012 | #endif |
c7b9adaf WD |
1013 | prfm plil1strm, [x30, #(1b - tramp_vectors)] |
1014 | msr vbar_el1, x30 | |
1015 | add x30, x30, #(1b - tramp_vectors) | |
1016 | isb | |
be04a6d1 | 1017 | ret |
c7b9adaf WD |
1018 | .endm |
1019 | ||
1020 | .macro tramp_exit, regsize = 64 | |
1021 | adr x30, tramp_vectors | |
1022 | msr vbar_el1, x30 | |
1023 | tramp_unmap_kernel x30 | |
1024 | .if \regsize == 64 | |
1025 | mrs x30, far_el1 | |
1026 | .endif | |
1027 | eret | |
679db708 | 1028 | sb |
c7b9adaf WD |
1029 | .endm |
1030 | ||
1031 | .align 11 | |
1032 | ENTRY(tramp_vectors) | |
1033 | .space 0x400 | |
1034 | ||
1035 | tramp_ventry | |
1036 | tramp_ventry | |
1037 | tramp_ventry | |
1038 | tramp_ventry | |
1039 | ||
1040 | tramp_ventry 32 | |
1041 | tramp_ventry 32 | |
1042 | tramp_ventry 32 | |
1043 | tramp_ventry 32 | |
1044 | END(tramp_vectors) | |
1045 | ||
1046 | ENTRY(tramp_exit_native) | |
1047 | tramp_exit | |
1048 | END(tramp_exit_native) | |
1049 | ||
1050 | ENTRY(tramp_exit_compat) | |
1051 | tramp_exit 32 | |
1052 | END(tramp_exit_compat) | |
1053 | ||
1054 | .ltorg | |
1055 | .popsection // .entry.tramp.text | |
6c27c408 WD |
1056 | #ifdef CONFIG_RANDOMIZE_BASE |
1057 | .pushsection ".rodata", "a" | |
1058 | .align PAGE_SHIFT | |
1059 | .globl __entry_tramp_data_start | |
1060 | __entry_tramp_data_start: | |
1061 | .quad vectors | |
1062 | .popsection // .rodata | |
1063 | #endif /* CONFIG_RANDOMIZE_BASE */ | |
c7b9adaf WD |
1064 | #endif /* CONFIG_UNMAP_KERNEL_AT_EL0 */ |
1065 | ||
ed84b4e9 MR |
1066 | /* |
1067 | * Register switch for AArch64. The callee-saved registers need to be saved | |
1068 | * and restored. On entry: | |
1069 | * x0 = previous task_struct (must be preserved across the switch) | |
1070 | * x1 = next task_struct | |
1071 | * Previous and next are guaranteed not to be the same. | |
1072 | * | |
1073 | */ | |
1074 | ENTRY(cpu_switch_to) | |
1075 | mov x10, #THREAD_CPU_CONTEXT | |
1076 | add x8, x0, x10 | |
1077 | mov x9, sp | |
1078 | stp x19, x20, [x8], #16 // store callee-saved registers | |
1079 | stp x21, x22, [x8], #16 | |
1080 | stp x23, x24, [x8], #16 | |
1081 | stp x25, x26, [x8], #16 | |
1082 | stp x27, x28, [x8], #16 | |
1083 | stp x29, x9, [x8], #16 | |
1084 | str lr, [x8] | |
1085 | add x8, x1, x10 | |
1086 | ldp x19, x20, [x8], #16 // restore callee-saved registers | |
1087 | ldp x21, x22, [x8], #16 | |
1088 | ldp x23, x24, [x8], #16 | |
1089 | ldp x25, x26, [x8], #16 | |
1090 | ldp x27, x28, [x8], #16 | |
1091 | ldp x29, x9, [x8], #16 | |
1092 | ldr lr, [x8] | |
1093 | mov sp, x9 | |
1094 | msr sp_el0, x1 | |
1095 | ret | |
1096 | ENDPROC(cpu_switch_to) | |
1097 | NOKPROBE(cpu_switch_to) | |
1098 | ||
1099 | /* | |
1100 | * This is how we return from a fork. | |
1101 | */ | |
1102 | ENTRY(ret_from_fork) | |
1103 | bl schedule_tail | |
1104 | cbz x19, 1f // not a kernel thread | |
1105 | mov x0, x20 | |
1106 | blr x19 | |
4caf8758 | 1107 | 1: get_current_task tsk |
ed84b4e9 MR |
1108 | b ret_to_user |
1109 | ENDPROC(ret_from_fork) | |
1110 | NOKPROBE(ret_from_fork) | |
f5df2696 JM |
1111 | |
1112 | #ifdef CONFIG_ARM_SDE_INTERFACE | |
1113 | ||
1114 | #include <asm/sdei.h> | |
1115 | #include <uapi/linux/arm_sdei.h> | |
1116 | ||
79e9aa59 JM |
1117 | .macro sdei_handler_exit exit_mode |
1118 | /* On success, this call never returns... */ | |
1119 | cmp \exit_mode, #SDEI_EXIT_SMC | |
1120 | b.ne 99f | |
1121 | smc #0 | |
1122 | b . | |
1123 | 99: hvc #0 | |
1124 | b . | |
1125 | .endm | |
1126 | ||
1127 | #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 | |
1128 | /* | |
1129 | * The regular SDEI entry point may have been unmapped along with the rest of | |
1130 | * the kernel. This trampoline restores the kernel mapping to make the x1 memory | |
1131 | * argument accessible. | |
1132 | * | |
1133 | * This clobbers x4, __sdei_handler() will restore this from firmware's | |
1134 | * copy. | |
1135 | */ | |
1136 | .ltorg | |
1137 | .pushsection ".entry.tramp.text", "ax" | |
1138 | ENTRY(__sdei_asm_entry_trampoline) | |
1139 | mrs x4, ttbr1_el1 | |
1140 | tbz x4, #USER_ASID_BIT, 1f | |
1141 | ||
1142 | tramp_map_kernel tmp=x4 | |
1143 | isb | |
1144 | mov x4, xzr | |
1145 | ||
1146 | /* | |
1147 | * Use reg->interrupted_regs.addr_limit to remember whether to unmap | |
1148 | * the kernel on exit. | |
1149 | */ | |
1150 | 1: str x4, [x1, #(SDEI_EVENT_INTREGS + S_ORIG_ADDR_LIMIT)] | |
1151 | ||
1152 | #ifdef CONFIG_RANDOMIZE_BASE | |
1153 | adr x4, tramp_vectors + PAGE_SIZE | |
1154 | add x4, x4, #:lo12:__sdei_asm_trampoline_next_handler | |
1155 | ldr x4, [x4] | |
1156 | #else | |
1157 | ldr x4, =__sdei_asm_handler | |
1158 | #endif | |
1159 | br x4 | |
1160 | ENDPROC(__sdei_asm_entry_trampoline) | |
1161 | NOKPROBE(__sdei_asm_entry_trampoline) | |
1162 | ||
1163 | /* | |
1164 | * Make the exit call and restore the original ttbr1_el1 | |
1165 | * | |
1166 | * x0 & x1: setup for the exit API call | |
1167 | * x2: exit_mode | |
1168 | * x4: struct sdei_registered_event argument from registration time. | |
1169 | */ | |
1170 | ENTRY(__sdei_asm_exit_trampoline) | |
1171 | ldr x4, [x4, #(SDEI_EVENT_INTREGS + S_ORIG_ADDR_LIMIT)] | |
1172 | cbnz x4, 1f | |
1173 | ||
1174 | tramp_unmap_kernel tmp=x4 | |
1175 | ||
1176 | 1: sdei_handler_exit exit_mode=x2 | |
1177 | ENDPROC(__sdei_asm_exit_trampoline) | |
1178 | NOKPROBE(__sdei_asm_exit_trampoline) | |
1179 | .ltorg | |
1180 | .popsection // .entry.tramp.text | |
1181 | #ifdef CONFIG_RANDOMIZE_BASE | |
1182 | .pushsection ".rodata", "a" | |
1183 | __sdei_asm_trampoline_next_handler: | |
1184 | .quad __sdei_asm_handler | |
1185 | .popsection // .rodata | |
1186 | #endif /* CONFIG_RANDOMIZE_BASE */ | |
1187 | #endif /* CONFIG_UNMAP_KERNEL_AT_EL0 */ | |
1188 | ||
f5df2696 JM |
1189 | /* |
1190 | * Software Delegated Exception entry point. | |
1191 | * | |
1192 | * x0: Event number | |
1193 | * x1: struct sdei_registered_event argument from registration time. | |
1194 | * x2: interrupted PC | |
1195 | * x3: interrupted PSTATE | |
79e9aa59 | 1196 | * x4: maybe clobbered by the trampoline |
f5df2696 JM |
1197 | * |
1198 | * Firmware has preserved x0->x17 for us, we must save/restore the rest to | |
1199 | * follow SMC-CC. We save (or retrieve) all the registers as the handler may | |
1200 | * want them. | |
1201 | */ | |
1202 | ENTRY(__sdei_asm_handler) | |
1203 | stp x2, x3, [x1, #SDEI_EVENT_INTREGS + S_PC] | |
1204 | stp x4, x5, [x1, #SDEI_EVENT_INTREGS + 16 * 2] | |
1205 | stp x6, x7, [x1, #SDEI_EVENT_INTREGS + 16 * 3] | |
1206 | stp x8, x9, [x1, #SDEI_EVENT_INTREGS + 16 * 4] | |
1207 | stp x10, x11, [x1, #SDEI_EVENT_INTREGS + 16 * 5] | |
1208 | stp x12, x13, [x1, #SDEI_EVENT_INTREGS + 16 * 6] | |
1209 | stp x14, x15, [x1, #SDEI_EVENT_INTREGS + 16 * 7] | |
1210 | stp x16, x17, [x1, #SDEI_EVENT_INTREGS + 16 * 8] | |
1211 | stp x18, x19, [x1, #SDEI_EVENT_INTREGS + 16 * 9] | |
1212 | stp x20, x21, [x1, #SDEI_EVENT_INTREGS + 16 * 10] | |
1213 | stp x22, x23, [x1, #SDEI_EVENT_INTREGS + 16 * 11] | |
1214 | stp x24, x25, [x1, #SDEI_EVENT_INTREGS + 16 * 12] | |
1215 | stp x26, x27, [x1, #SDEI_EVENT_INTREGS + 16 * 13] | |
1216 | stp x28, x29, [x1, #SDEI_EVENT_INTREGS + 16 * 14] | |
1217 | mov x4, sp | |
1218 | stp lr, x4, [x1, #SDEI_EVENT_INTREGS + S_LR] | |
1219 | ||
1220 | mov x19, x1 | |
1221 | ||
1222 | #ifdef CONFIG_VMAP_STACK | |
1223 | /* | |
1224 | * entry.S may have been using sp as a scratch register, find whether | |
1225 | * this is a normal or critical event and switch to the appropriate | |
1226 | * stack for this CPU. | |
1227 | */ | |
1228 | ldrb w4, [x19, #SDEI_EVENT_PRIORITY] | |
1229 | cbnz w4, 1f | |
1230 | ldr_this_cpu dst=x5, sym=sdei_stack_normal_ptr, tmp=x6 | |
1231 | b 2f | |
1232 | 1: ldr_this_cpu dst=x5, sym=sdei_stack_critical_ptr, tmp=x6 | |
1233 | 2: mov x6, #SDEI_STACK_SIZE | |
1234 | add x5, x5, x6 | |
1235 | mov sp, x5 | |
1236 | #endif | |
1237 | ||
1238 | /* | |
1239 | * We may have interrupted userspace, or a guest, or exit-from or | |
1240 | * return-to either of these. We can't trust sp_el0, restore it. | |
1241 | */ | |
1242 | mrs x28, sp_el0 | |
1243 | ldr_this_cpu dst=x0, sym=__entry_task, tmp=x1 | |
1244 | msr sp_el0, x0 | |
1245 | ||
1246 | /* If we interrupted the kernel point to the previous stack/frame. */ | |
1247 | and x0, x3, #0xc | |
1248 | mrs x1, CurrentEL | |
1249 | cmp x0, x1 | |
1250 | csel x29, x29, xzr, eq // fp, or zero | |
1251 | csel x4, x2, xzr, eq // elr, or zero | |
1252 | ||
1253 | stp x29, x4, [sp, #-16]! | |
1254 | mov x29, sp | |
1255 | ||
1256 | add x0, x19, #SDEI_EVENT_INTREGS | |
1257 | mov x1, x19 | |
1258 | bl __sdei_handler | |
1259 | ||
1260 | msr sp_el0, x28 | |
1261 | /* restore regs >x17 that we clobbered */ | |
79e9aa59 JM |
1262 | mov x4, x19 // keep x4 for __sdei_asm_exit_trampoline |
1263 | ldp x28, x29, [x4, #SDEI_EVENT_INTREGS + 16 * 14] | |
1264 | ldp x18, x19, [x4, #SDEI_EVENT_INTREGS + 16 * 9] | |
1265 | ldp lr, x1, [x4, #SDEI_EVENT_INTREGS + S_LR] | |
1266 | mov sp, x1 | |
f5df2696 JM |
1267 | |
1268 | mov x1, x0 // address to complete_and_resume | |
1269 | /* x0 = (x0 <= 1) ? EVENT_COMPLETE:EVENT_COMPLETE_AND_RESUME */ | |
1270 | cmp x0, #1 | |
1271 | mov_q x2, SDEI_1_0_FN_SDEI_EVENT_COMPLETE | |
1272 | mov_q x3, SDEI_1_0_FN_SDEI_EVENT_COMPLETE_AND_RESUME | |
1273 | csel x0, x2, x3, ls | |
1274 | ||
f5df2696 | 1275 | ldr_l x2, sdei_exit_mode |
79e9aa59 JM |
1276 | |
1277 | alternative_if_not ARM64_UNMAP_KERNEL_AT_EL0 | |
1278 | sdei_handler_exit exit_mode=x2 | |
1279 | alternative_else_nop_endif | |
1280 | ||
1281 | #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 | |
1282 | tramp_alias dst=x5, sym=__sdei_asm_exit_trampoline | |
1283 | br x5 | |
1284 | #endif | |
f5df2696 JM |
1285 | ENDPROC(__sdei_asm_handler) |
1286 | NOKPROBE(__sdei_asm_handler) | |
1287 | #endif /* CONFIG_ARM_SDE_INTERFACE */ |