1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36#include <drm/drmP.h>
37#include <linux/export.h>
38#if defined(__ia64__)
39#include <linux/efi.h>
40#include <linux/slab.h>
41#endif
42
43static void drm_vm_open(struct vm_area_struct *vma);
44static void drm_vm_close(struct vm_area_struct *vma);
45
46static pgprot_t drm_io_prot(uint32_t map_type, struct vm_area_struct *vma)
47{
48 pgprot_t tmp = vm_get_page_prot(vma->vm_flags);
49
50#if defined(__i386__) || defined(__x86_64__)
51 if (boot_cpu_data.x86 > 3 && map_type != _DRM_AGP) {
52 pgprot_val(tmp) |= _PAGE_PCD;
53 pgprot_val(tmp) &= ~_PAGE_PWT;
54 }
55#elif defined(__powerpc__)
56 pgprot_val(tmp) |= _PAGE_NO_CACHE;
57 if (map_type == _DRM_REGISTERS)
58 pgprot_val(tmp) |= _PAGE_GUARDED;
59#elif defined(__ia64__)
60 if (efi_range_is_wc(vma->vm_start, vma->vm_end -
61 vma->vm_start))
62 tmp = pgprot_writecombine(tmp);
63 else
64 tmp = pgprot_noncached(tmp);
65#elif defined(__sparc__) || defined(__arm__) || defined(__mips__)
66 tmp = pgprot_noncached(tmp);
67#endif
68 return tmp;
69}
70
71static pgprot_t drm_dma_prot(uint32_t map_type, struct vm_area_struct *vma)
72{
73 pgprot_t tmp = vm_get_page_prot(vma->vm_flags);
74
75#if defined(__powerpc__) && defined(CONFIG_NOT_COHERENT_CACHE)
76 tmp |= _PAGE_NO_CACHE;
77#endif
78 return tmp;
79}
80
81
82
83
84
85
86
87
88
89
90
91#if __OS_HAS_AGP
92static int drm_do_vm_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
93{
94 struct drm_file *priv = vma->vm_file->private_data;
95 struct drm_device *dev = priv->minor->dev;
96 struct drm_local_map *map = NULL;
97 struct drm_map_list *r_list;
98 struct drm_hash_item *hash;
99
100
101
102
103 if (!drm_core_has_AGP(dev))
104 goto vm_fault_error;
105
106 if (!dev->agp || !dev->agp->cant_use_aperture)
107 goto vm_fault_error;
108
109 if (drm_ht_find_item(&dev->map_hash, vma->vm_pgoff, &hash))
110 goto vm_fault_error;
111
112 r_list = drm_hash_entry(hash, struct drm_map_list, hash);
113 map = r_list->map;
114
115 if (map && map->type == _DRM_AGP) {
116
117
118
119
120 resource_size_t offset = (unsigned long)vmf->virtual_address -
121 vma->vm_start;
122 resource_size_t baddr = map->offset + offset;
123 struct drm_agp_mem *agpmem;
124 struct page *page;
125
126#ifdef __alpha__
127
128
129
130 baddr -= dev->hose->mem_space->start;
131#endif
132
133
134
135
136 list_for_each_entry(agpmem, &dev->agp->memory, head) {
137 if (agpmem->bound <= baddr &&
138 agpmem->bound + agpmem->pages * PAGE_SIZE > baddr)
139 break;
140 }
141
142 if (&agpmem->head == &dev->agp->memory)
143 goto vm_fault_error;
144
145
146
147
148 offset = (baddr - agpmem->bound) >> PAGE_SHIFT;
149 page = agpmem->memory->pages[offset];
150 get_page(page);
151 vmf->page = page;
152
153 DRM_DEBUG
154 ("baddr = 0x%llx page = 0x%p, offset = 0x%llx, count=%d\n",
155 (unsigned long long)baddr,
156 agpmem->memory->pages[offset],
157 (unsigned long long)offset,
158 page_count(page));
159 return 0;
160 }
161vm_fault_error:
162 return VM_FAULT_SIGBUS;
163}
164#else
165static int drm_do_vm_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
166{
167 return VM_FAULT_SIGBUS;
168}
169#endif
170
171
172
173
174
175
176
177
178
179
180
181static int drm_do_vm_shm_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
182{
183 struct drm_local_map *map = vma->vm_private_data;
184 unsigned long offset;
185 unsigned long i;
186 struct page *page;
187
188 if (!map)
189 return VM_FAULT_SIGBUS;
190
191 offset = (unsigned long)vmf->virtual_address - vma->vm_start;
192 i = (unsigned long)map->handle + offset;
193 page = vmalloc_to_page((void *)i);
194 if (!page)
195 return VM_FAULT_SIGBUS;
196 get_page(page);
197 vmf->page = page;
198
199 DRM_DEBUG("shm_fault 0x%lx\n", offset);
200 return 0;
201}
202
203
204
205
206
207
208
209
210
211static void drm_vm_shm_close(struct vm_area_struct *vma)
212{
213 struct drm_file *priv = vma->vm_file->private_data;
214 struct drm_device *dev = priv->minor->dev;
215 struct drm_vma_entry *pt, *temp;
216 struct drm_local_map *map;
217 struct drm_map_list *r_list;
218 int found_maps = 0;
219
220 DRM_DEBUG("0x%08lx,0x%08lx\n",
221 vma->vm_start, vma->vm_end - vma->vm_start);
222 atomic_dec(&dev->vma_count);
223
224 map = vma->vm_private_data;
225
226 mutex_lock(&dev->struct_mutex);
227 list_for_each_entry_safe(pt, temp, &dev->vmalist, head) {
228 if (pt->vma->vm_private_data == map)
229 found_maps++;
230 if (pt->vma == vma) {
231 list_del(&pt->head);
232 kfree(pt);
233 }
234 }
235
236
237 if (found_maps == 1 && map->flags & _DRM_REMOVABLE) {
238
239
240
241 found_maps = 0;
242 list_for_each_entry(r_list, &dev->maplist, head) {
243 if (r_list->map == map)
244 found_maps++;
245 }
246
247 if (!found_maps) {
248 drm_dma_handle_t dmah;
249
250 switch (map->type) {
251 case _DRM_REGISTERS:
252 case _DRM_FRAME_BUFFER:
253 if (drm_core_has_MTRR(dev) && map->mtrr >= 0) {
254 int retcode;
255 retcode = mtrr_del(map->mtrr,
256 map->offset,
257 map->size);
258 DRM_DEBUG("mtrr_del = %d\n", retcode);
259 }
260 iounmap(map->handle);
261 break;
262 case _DRM_SHM:
263 vfree(map->handle);
264 break;
265 case _DRM_AGP:
266 case _DRM_SCATTER_GATHER:
267 break;
268 case _DRM_CONSISTENT:
269 dmah.vaddr = map->handle;
270 dmah.busaddr = map->offset;
271 dmah.size = map->size;
272 __drm_pci_free(dev, &dmah);
273 break;
274 case _DRM_GEM:
275 DRM_ERROR("tried to rmmap GEM object\n");
276 break;
277 }
278 kfree(map);
279 }
280 }
281 mutex_unlock(&dev->struct_mutex);
282}
283
284
285
286
287
288
289
290
291
292
293static int drm_do_vm_dma_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
294{
295 struct drm_file *priv = vma->vm_file->private_data;
296 struct drm_device *dev = priv->minor->dev;
297 struct drm_device_dma *dma = dev->dma;
298 unsigned long offset;
299 unsigned long page_nr;
300 struct page *page;
301
302 if (!dma)
303 return VM_FAULT_SIGBUS;
304 if (!dma->pagelist)
305 return VM_FAULT_SIGBUS;
306
307 offset = (unsigned long)vmf->virtual_address - vma->vm_start;
308 page_nr = offset >> PAGE_SHIFT;
309 page = virt_to_page((dma->pagelist[page_nr] + (offset & (~PAGE_MASK))));
310
311 get_page(page);
312 vmf->page = page;
313
314 DRM_DEBUG("dma_fault 0x%lx (page %lu)\n", offset, page_nr);
315 return 0;
316}
317
318
319
320
321
322
323
324
325
326
327static int drm_do_vm_sg_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
328{
329 struct drm_local_map *map = vma->vm_private_data;
330 struct drm_file *priv = vma->vm_file->private_data;
331 struct drm_device *dev = priv->minor->dev;
332 struct drm_sg_mem *entry = dev->sg;
333 unsigned long offset;
334 unsigned long map_offset;
335 unsigned long page_offset;
336 struct page *page;
337
338 if (!entry)
339 return VM_FAULT_SIGBUS;
340 if (!entry->pagelist)
341 return VM_FAULT_SIGBUS;
342
343 offset = (unsigned long)vmf->virtual_address - vma->vm_start;
344 map_offset = map->offset - (unsigned long)dev->sg->virtual;
345 page_offset = (offset >> PAGE_SHIFT) + (map_offset >> PAGE_SHIFT);
346 page = entry->pagelist[page_offset];
347 get_page(page);
348 vmf->page = page;
349
350 return 0;
351}
352
353static int drm_vm_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
354{
355 return drm_do_vm_fault(vma, vmf);
356}
357
358static int drm_vm_shm_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
359{
360 return drm_do_vm_shm_fault(vma, vmf);
361}
362
363static int drm_vm_dma_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
364{
365 return drm_do_vm_dma_fault(vma, vmf);
366}
367
368static int drm_vm_sg_fault(struct vm_area_struct *vma, struct vm_fault *vmf)
369{
370 return drm_do_vm_sg_fault(vma, vmf);
371}
372
373
374static const struct vm_operations_struct drm_vm_ops = {
375 .fault = drm_vm_fault,
376 .open = drm_vm_open,
377 .close = drm_vm_close,
378};
379
380
381static const struct vm_operations_struct drm_vm_shm_ops = {
382 .fault = drm_vm_shm_fault,
383 .open = drm_vm_open,
384 .close = drm_vm_shm_close,
385};
386
387
388static const struct vm_operations_struct drm_vm_dma_ops = {
389 .fault = drm_vm_dma_fault,
390 .open = drm_vm_open,
391 .close = drm_vm_close,
392};
393
394
395static const struct vm_operations_struct drm_vm_sg_ops = {
396 .fault = drm_vm_sg_fault,
397 .open = drm_vm_open,
398 .close = drm_vm_close,
399};
400
401
402
403
404
405
406
407
408
409void drm_vm_open_locked(struct drm_device *dev,
410 struct vm_area_struct *vma)
411{
412 struct drm_vma_entry *vma_entry;
413
414 DRM_DEBUG("0x%08lx,0x%08lx\n",
415 vma->vm_start, vma->vm_end - vma->vm_start);
416 atomic_inc(&dev->vma_count);
417
418 vma_entry = kmalloc(sizeof(*vma_entry), GFP_KERNEL);
419 if (vma_entry) {
420 vma_entry->vma = vma;
421 vma_entry->pid = current->pid;
422 list_add(&vma_entry->head, &dev->vmalist);
423 }
424}
425EXPORT_SYMBOL_GPL(drm_vm_open_locked);
426
427static void drm_vm_open(struct vm_area_struct *vma)
428{
429 struct drm_file *priv = vma->vm_file->private_data;
430 struct drm_device *dev = priv->minor->dev;
431
432 mutex_lock(&dev->struct_mutex);
433 drm_vm_open_locked(dev, vma);
434 mutex_unlock(&dev->struct_mutex);
435}
436
437void drm_vm_close_locked(struct drm_device *dev,
438 struct vm_area_struct *vma)
439{
440 struct drm_vma_entry *pt, *temp;
441
442 DRM_DEBUG("0x%08lx,0x%08lx\n",
443 vma->vm_start, vma->vm_end - vma->vm_start);
444 atomic_dec(&dev->vma_count);
445
446 list_for_each_entry_safe(pt, temp, &dev->vmalist, head) {
447 if (pt->vma == vma) {
448 list_del(&pt->head);
449 kfree(pt);
450 break;
451 }
452 }
453}
454
455
456
457
458
459
460
461
462
463static void drm_vm_close(struct vm_area_struct *vma)
464{
465 struct drm_file *priv = vma->vm_file->private_data;
466 struct drm_device *dev = priv->minor->dev;
467
468 mutex_lock(&dev->struct_mutex);
469 drm_vm_close_locked(dev, vma);
470 mutex_unlock(&dev->struct_mutex);
471}
472
473
474
475
476
477
478
479
480
481
482
483static int drm_mmap_dma(struct file *filp, struct vm_area_struct *vma)
484{
485 struct drm_file *priv = filp->private_data;
486 struct drm_device *dev;
487 struct drm_device_dma *dma;
488 unsigned long length = vma->vm_end - vma->vm_start;
489
490 dev = priv->minor->dev;
491 dma = dev->dma;
492 DRM_DEBUG("start = 0x%lx, end = 0x%lx, page offset = 0x%lx\n",
493 vma->vm_start, vma->vm_end, vma->vm_pgoff);
494
495
496 if (!dma || (length >> PAGE_SHIFT) != dma->page_count) {
497 return -EINVAL;
498 }
499
500 if (!capable(CAP_SYS_ADMIN) &&
501 (dma->flags & _DRM_DMA_USE_PCI_RO)) {
502 vma->vm_flags &= ~(VM_WRITE | VM_MAYWRITE);
503#if defined(__i386__) || defined(__x86_64__)
504 pgprot_val(vma->vm_page_prot) &= ~_PAGE_RW;
505#else
506
507
508
509 vma->vm_page_prot =
510 __pgprot(pte_val
511 (pte_wrprotect
512 (__pte(pgprot_val(vma->vm_page_prot)))));
513#endif
514 }
515
516 vma->vm_ops = &drm_vm_dma_ops;
517
518 vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
519
520 drm_vm_open_locked(dev, vma);
521 return 0;
522}
523
524static resource_size_t drm_core_get_reg_ofs(struct drm_device *dev)
525{
526#ifdef __alpha__
527 return dev->hose->dense_mem_base;
528#else
529 return 0;
530#endif
531}
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546int drm_mmap_locked(struct file *filp, struct vm_area_struct *vma)
547{
548 struct drm_file *priv = filp->private_data;
549 struct drm_device *dev = priv->minor->dev;
550 struct drm_local_map *map = NULL;
551 resource_size_t offset = 0;
552 struct drm_hash_item *hash;
553
554 DRM_DEBUG("start = 0x%lx, end = 0x%lx, page offset = 0x%lx\n",
555 vma->vm_start, vma->vm_end, vma->vm_pgoff);
556
557 if (!priv->authenticated)
558 return -EACCES;
559
560
561
562
563
564 if (!vma->vm_pgoff
565#if __OS_HAS_AGP
566 && (!dev->agp
567 || dev->agp->agp_info.device->vendor != PCI_VENDOR_ID_APPLE)
568#endif
569 )
570 return drm_mmap_dma(filp, vma);
571
572 if (drm_ht_find_item(&dev->map_hash, vma->vm_pgoff, &hash)) {
573 DRM_ERROR("Could not find map\n");
574 return -EINVAL;
575 }
576
577 map = drm_hash_entry(hash, struct drm_map_list, hash)->map;
578 if (!map || ((map->flags & _DRM_RESTRICTED) && !capable(CAP_SYS_ADMIN)))
579 return -EPERM;
580
581
582 if (map->size < vma->vm_end - vma->vm_start)
583 return -EINVAL;
584
585 if (!capable(CAP_SYS_ADMIN) && (map->flags & _DRM_READ_ONLY)) {
586 vma->vm_flags &= ~(VM_WRITE | VM_MAYWRITE);
587#if defined(__i386__) || defined(__x86_64__)
588 pgprot_val(vma->vm_page_prot) &= ~_PAGE_RW;
589#else
590
591
592
593 vma->vm_page_prot =
594 __pgprot(pte_val
595 (pte_wrprotect
596 (__pte(pgprot_val(vma->vm_page_prot)))));
597#endif
598 }
599
600 switch (map->type) {
601#if !defined(__arm__)
602 case _DRM_AGP:
603 if (drm_core_has_AGP(dev) && dev->agp->cant_use_aperture) {
604
605
606
607
608
609#if defined(__powerpc__)
610 pgprot_val(vma->vm_page_prot) |= _PAGE_NO_CACHE;
611#endif
612 vma->vm_ops = &drm_vm_ops;
613 break;
614 }
615
616#endif
617 case _DRM_FRAME_BUFFER:
618 case _DRM_REGISTERS:
619 offset = drm_core_get_reg_ofs(dev);
620 vma->vm_flags |= VM_IO;
621 vma->vm_page_prot = drm_io_prot(map->type, vma);
622 if (io_remap_pfn_range(vma, vma->vm_start,
623 (map->offset + offset) >> PAGE_SHIFT,
624 vma->vm_end - vma->vm_start,
625 vma->vm_page_prot))
626 return -EAGAIN;
627 DRM_DEBUG(" Type = %d; start = 0x%lx, end = 0x%lx,"
628 " offset = 0x%llx\n",
629 map->type,
630 vma->vm_start, vma->vm_end, (unsigned long long)(map->offset + offset));
631
632 vma->vm_ops = &drm_vm_ops;
633 break;
634 case _DRM_CONSISTENT:
635
636
637 if (remap_pfn_range(vma, vma->vm_start,
638 page_to_pfn(virt_to_page(map->handle)),
639 vma->vm_end - vma->vm_start, vma->vm_page_prot))
640 return -EAGAIN;
641 vma->vm_page_prot = drm_dma_prot(map->type, vma);
642
643 case _DRM_SHM:
644 vma->vm_ops = &drm_vm_shm_ops;
645 vma->vm_private_data = (void *)map;
646 break;
647 case _DRM_SCATTER_GATHER:
648 vma->vm_ops = &drm_vm_sg_ops;
649 vma->vm_private_data = (void *)map;
650 vma->vm_page_prot = drm_dma_prot(map->type, vma);
651 break;
652 default:
653 return -EINVAL;
654 }
655 vma->vm_flags |= VM_DONTEXPAND | VM_DONTDUMP;
656
657 drm_vm_open_locked(dev, vma);
658 return 0;
659}
660
661int drm_mmap(struct file *filp, struct vm_area_struct *vma)
662{
663 struct drm_file *priv = filp->private_data;
664 struct drm_device *dev = priv->minor->dev;
665 int ret;
666
667 if (drm_device_is_unplugged(dev))
668 return -ENODEV;
669
670 mutex_lock(&dev->struct_mutex);
671 ret = drm_mmap_locked(filp, vma);
672 mutex_unlock(&dev->struct_mutex);
673
674 return ret;
675}
676EXPORT_SYMBOL(drm_mmap);
677