hugetlbfs: fix offset overflow in hugetlbfs mmap
[pandora-kernel.git] / fs / hugetlbfs / inode.c
1 /*
2  * hugetlbpage-backed filesystem.  Based on ramfs.
3  *
4  * William Irwin, 2002
5  *
6  * Copyright (C) 2002 Linus Torvalds.
7  */
8
9 #include <linux/module.h>
10 #include <linux/thread_info.h>
11 #include <asm/current.h>
12 #include <linux/sched.h>                /* remove ASAP */
13 #include <linux/fs.h>
14 #include <linux/mount.h>
15 #include <linux/file.h>
16 #include <linux/kernel.h>
17 #include <linux/writeback.h>
18 #include <linux/pagemap.h>
19 #include <linux/highmem.h>
20 #include <linux/init.h>
21 #include <linux/string.h>
22 #include <linux/capability.h>
23 #include <linux/ctype.h>
24 #include <linux/backing-dev.h>
25 #include <linux/hugetlb.h>
26 #include <linux/pagevec.h>
27 #include <linux/parser.h>
28 #include <linux/mman.h>
29 #include <linux/slab.h>
30 #include <linux/dnotify.h>
31 #include <linux/statfs.h>
32 #include <linux/security.h>
33 #include <linux/magic.h>
34 #include <linux/migrate.h>
35
36 #include <asm/uaccess.h>
37
38 static const struct super_operations hugetlbfs_ops;
39 static const struct address_space_operations hugetlbfs_aops;
40 const struct file_operations hugetlbfs_file_operations;
41 static const struct inode_operations hugetlbfs_dir_inode_operations;
42 static const struct inode_operations hugetlbfs_inode_operations;
43
44 static struct backing_dev_info hugetlbfs_backing_dev_info = {
45         .name           = "hugetlbfs",
46         .ra_pages       = 0,    /* No readahead */
47         .capabilities   = BDI_CAP_NO_ACCT_AND_WRITEBACK,
48 };
49
50 int sysctl_hugetlb_shm_group;
51
52 enum {
53         Opt_size, Opt_nr_inodes,
54         Opt_mode, Opt_uid, Opt_gid,
55         Opt_pagesize,
56         Opt_err,
57 };
58
59 static const match_table_t tokens = {
60         {Opt_size,      "size=%s"},
61         {Opt_nr_inodes, "nr_inodes=%s"},
62         {Opt_mode,      "mode=%o"},
63         {Opt_uid,       "uid=%u"},
64         {Opt_gid,       "gid=%u"},
65         {Opt_pagesize,  "pagesize=%s"},
66         {Opt_err,       NULL},
67 };
68
69 static void huge_pagevec_release(struct pagevec *pvec)
70 {
71         int i;
72
73         for (i = 0; i < pagevec_count(pvec); ++i)
74                 put_page(pvec->pages[i]);
75
76         pagevec_reinit(pvec);
77 }
78
79 static int hugetlbfs_file_mmap(struct file *file, struct vm_area_struct *vma)
80 {
81         struct inode *inode = file->f_path.dentry->d_inode;
82         loff_t len, vma_len;
83         int ret;
84         struct hstate *h = hstate_file(file);
85
86         /*
87          * vma address alignment (but not the pgoff alignment) has
88          * already been checked by prepare_hugepage_range.  If you add
89          * any error returns here, do so after setting VM_HUGETLB, so
90          * is_vm_hugetlb_page tests below unmap_region go the right
91          * way when do_mmap_pgoff unwinds (may be important on powerpc
92          * and ia64).
93          */
94         vma->vm_flags |= VM_HUGETLB | VM_RESERVED;
95         vma->vm_ops = &hugetlb_vm_ops;
96
97         /*
98          * Offset passed to mmap (before page shift) could have been
99          * negative when represented as a (l)off_t.
100          */
101         if (((loff_t)vma->vm_pgoff << PAGE_SHIFT) < 0)
102                 return -EINVAL;
103
104         if (vma->vm_pgoff & (~huge_page_mask(h) >> PAGE_SHIFT))
105                 return -EINVAL;
106
107         vma_len = (loff_t)(vma->vm_end - vma->vm_start);
108         len = vma_len + ((loff_t)vma->vm_pgoff << PAGE_SHIFT);
109         /* check for overflow */
110         if (len < vma_len)
111                 return -EINVAL;
112
113         mutex_lock(&inode->i_mutex);
114         file_accessed(file);
115
116         ret = -ENOMEM;
117         if (hugetlb_reserve_pages(inode,
118                                 vma->vm_pgoff >> huge_page_order(h),
119                                 len >> huge_page_shift(h), vma,
120                                 vma->vm_flags))
121                 goto out;
122
123         ret = 0;
124         hugetlb_prefault_arch_hook(vma->vm_mm);
125         if (vma->vm_flags & VM_WRITE && inode->i_size < len)
126                 i_size_write(inode, len);
127 out:
128         mutex_unlock(&inode->i_mutex);
129
130         return ret;
131 }
132
133 /*
134  * Called under down_write(mmap_sem).
135  */
136
137 #ifndef HAVE_ARCH_HUGETLB_UNMAPPED_AREA
138 static unsigned long
139 hugetlb_get_unmapped_area(struct file *file, unsigned long addr,
140                 unsigned long len, unsigned long pgoff, unsigned long flags)
141 {
142         struct mm_struct *mm = current->mm;
143         struct vm_area_struct *vma;
144         unsigned long start_addr;
145         struct hstate *h = hstate_file(file);
146
147         if (len & ~huge_page_mask(h))
148                 return -EINVAL;
149         if (len > TASK_SIZE)
150                 return -ENOMEM;
151
152         if (flags & MAP_FIXED) {
153                 if (prepare_hugepage_range(file, addr, len))
154                         return -EINVAL;
155                 return addr;
156         }
157
158         if (addr) {
159                 addr = ALIGN(addr, huge_page_size(h));
160                 vma = find_vma(mm, addr);
161                 if (TASK_SIZE - len >= addr &&
162                     (!vma || addr + len <= vm_start_gap(vma)))
163                         return addr;
164         }
165
166         start_addr = mm->free_area_cache;
167
168         if (len <= mm->cached_hole_size)
169                 start_addr = TASK_UNMAPPED_BASE;
170
171 full_search:
172         addr = ALIGN(start_addr, huge_page_size(h));
173
174         for (vma = find_vma(mm, addr); ; vma = vma->vm_next) {
175                 /* At this point:  (!vma || addr < vma->vm_end). */
176                 if (TASK_SIZE - len < addr) {
177                         /*
178                          * Start a new search - just in case we missed
179                          * some holes.
180                          */
181                         if (start_addr != TASK_UNMAPPED_BASE) {
182                                 start_addr = TASK_UNMAPPED_BASE;
183                                 goto full_search;
184                         }
185                         return -ENOMEM;
186                 }
187
188                 if (!vma || addr + len <= vm_start_gap(vma))
189                         return addr;
190                 addr = ALIGN(vma->vm_end, huge_page_size(h));
191         }
192 }
193 #endif
194
195 static int
196 hugetlbfs_read_actor(struct page *page, unsigned long offset,
197                         char __user *buf, unsigned long count,
198                         unsigned long size)
199 {
200         char *kaddr;
201         unsigned long left, copied = 0;
202         int i, chunksize;
203
204         if (size > count)
205                 size = count;
206
207         /* Find which 4k chunk and offset with in that chunk */
208         i = offset >> PAGE_CACHE_SHIFT;
209         offset = offset & ~PAGE_CACHE_MASK;
210
211         while (size) {
212                 chunksize = PAGE_CACHE_SIZE;
213                 if (offset)
214                         chunksize -= offset;
215                 if (chunksize > size)
216                         chunksize = size;
217                 kaddr = kmap(&page[i]);
218                 left = __copy_to_user(buf, kaddr + offset, chunksize);
219                 kunmap(&page[i]);
220                 if (left) {
221                         copied += (chunksize - left);
222                         break;
223                 }
224                 offset = 0;
225                 size -= chunksize;
226                 buf += chunksize;
227                 copied += chunksize;
228                 i++;
229         }
230         return copied ? copied : -EFAULT;
231 }
232
233 /*
234  * Support for read() - Find the page attached to f_mapping and copy out the
235  * data. Its *very* similar to do_generic_mapping_read(), we can't use that
236  * since it has PAGE_CACHE_SIZE assumptions.
237  */
238 static ssize_t hugetlbfs_read(struct file *filp, char __user *buf,
239                               size_t len, loff_t *ppos)
240 {
241         struct hstate *h = hstate_file(filp);
242         struct address_space *mapping = filp->f_mapping;
243         struct inode *inode = mapping->host;
244         unsigned long index = *ppos >> huge_page_shift(h);
245         unsigned long offset = *ppos & ~huge_page_mask(h);
246         unsigned long end_index;
247         loff_t isize;
248         ssize_t retval = 0;
249
250         /* validate length */
251         if (len == 0)
252                 goto out;
253
254         for (;;) {
255                 struct page *page;
256                 unsigned long nr, ret;
257                 int ra;
258
259                 /* nr is the maximum number of bytes to copy from this page */
260                 nr = huge_page_size(h);
261                 isize = i_size_read(inode);
262                 if (!isize)
263                         goto out;
264                 end_index = (isize - 1) >> huge_page_shift(h);
265                 if (index >= end_index) {
266                         if (index > end_index)
267                                 goto out;
268                         nr = ((isize - 1) & ~huge_page_mask(h)) + 1;
269                         if (nr <= offset)
270                                 goto out;
271                 }
272                 nr = nr - offset;
273
274                 /* Find the page */
275                 page = find_lock_page(mapping, index);
276                 if (unlikely(page == NULL)) {
277                         /*
278                          * We have a HOLE, zero out the user-buffer for the
279                          * length of the hole or request.
280                          */
281                         ret = len < nr ? len : nr;
282                         if (clear_user(buf, ret))
283                                 ra = -EFAULT;
284                         else
285                                 ra = 0;
286                 } else {
287                         unlock_page(page);
288
289                         /*
290                          * We have the page, copy it to user space buffer.
291                          */
292                         ra = hugetlbfs_read_actor(page, offset, buf, len, nr);
293                         ret = ra;
294                         page_cache_release(page);
295                 }
296                 if (ra < 0) {
297                         if (retval == 0)
298                                 retval = ra;
299                         goto out;
300                 }
301
302                 offset += ret;
303                 retval += ret;
304                 len -= ret;
305                 index += offset >> huge_page_shift(h);
306                 offset &= ~huge_page_mask(h);
307
308                 /* short read or no more work */
309                 if ((ret != nr) || (len == 0))
310                         break;
311         }
312 out:
313         *ppos = ((loff_t)index << huge_page_shift(h)) + offset;
314         return retval;
315 }
316
317 static int hugetlbfs_write_begin(struct file *file,
318                         struct address_space *mapping,
319                         loff_t pos, unsigned len, unsigned flags,
320                         struct page **pagep, void **fsdata)
321 {
322         return -EINVAL;
323 }
324
325 static int hugetlbfs_write_end(struct file *file, struct address_space *mapping,
326                         loff_t pos, unsigned len, unsigned copied,
327                         struct page *page, void *fsdata)
328 {
329         BUG();
330         return -EINVAL;
331 }
332
333 static void truncate_huge_page(struct page *page)
334 {
335         cancel_dirty_page(page, /* No IO accounting for huge pages? */0);
336         ClearPageUptodate(page);
337         delete_from_page_cache(page);
338 }
339
340 static void truncate_hugepages(struct inode *inode, loff_t lstart)
341 {
342         struct hstate *h = hstate_inode(inode);
343         struct address_space *mapping = &inode->i_data;
344         const pgoff_t start = lstart >> huge_page_shift(h);
345         struct pagevec pvec;
346         pgoff_t next;
347         int i, freed = 0;
348
349         pagevec_init(&pvec, 0);
350         next = start;
351         while (1) {
352                 if (!pagevec_lookup(&pvec, mapping, next, PAGEVEC_SIZE)) {
353                         if (next == start)
354                                 break;
355                         next = start;
356                         continue;
357                 }
358
359                 for (i = 0; i < pagevec_count(&pvec); ++i) {
360                         struct page *page = pvec.pages[i];
361
362                         lock_page(page);
363                         if (page->index > next)
364                                 next = page->index;
365                         ++next;
366                         truncate_huge_page(page);
367                         unlock_page(page);
368                         freed++;
369                 }
370                 huge_pagevec_release(&pvec);
371         }
372         BUG_ON(!lstart && mapping->nrpages);
373         hugetlb_unreserve_pages(inode, start, freed);
374 }
375
376 static void hugetlbfs_evict_inode(struct inode *inode)
377 {
378         truncate_hugepages(inode, 0);
379         end_writeback(inode);
380 }
381
382 static inline void
383 hugetlb_vmtruncate_list(struct prio_tree_root *root, pgoff_t pgoff)
384 {
385         struct vm_area_struct *vma;
386         struct prio_tree_iter iter;
387
388         vma_prio_tree_foreach(vma, &iter, root, pgoff, ULONG_MAX) {
389                 unsigned long v_offset;
390
391                 /*
392                  * Can the expression below overflow on 32-bit arches?
393                  * No, because the prio_tree returns us only those vmas
394                  * which overlap the truncated area starting at pgoff,
395                  * and no vma on a 32-bit arch can span beyond the 4GB.
396                  */
397                 if (vma->vm_pgoff < pgoff)
398                         v_offset = (pgoff - vma->vm_pgoff) << PAGE_SHIFT;
399                 else
400                         v_offset = 0;
401
402                 __unmap_hugepage_range(vma,
403                                 vma->vm_start + v_offset, vma->vm_end, NULL);
404         }
405 }
406
407 static int hugetlb_vmtruncate(struct inode *inode, loff_t offset)
408 {
409         pgoff_t pgoff;
410         struct address_space *mapping = inode->i_mapping;
411         struct hstate *h = hstate_inode(inode);
412
413         BUG_ON(offset & ~huge_page_mask(h));
414         pgoff = offset >> PAGE_SHIFT;
415
416         i_size_write(inode, offset);
417         mutex_lock(&mapping->i_mmap_mutex);
418         if (!prio_tree_empty(&mapping->i_mmap))
419                 hugetlb_vmtruncate_list(&mapping->i_mmap, pgoff);
420         mutex_unlock(&mapping->i_mmap_mutex);
421         truncate_hugepages(inode, offset);
422         return 0;
423 }
424
425 static int hugetlbfs_setattr(struct dentry *dentry, struct iattr *attr)
426 {
427         struct inode *inode = dentry->d_inode;
428         struct hstate *h = hstate_inode(inode);
429         int error;
430         unsigned int ia_valid = attr->ia_valid;
431
432         BUG_ON(!inode);
433
434         error = setattr_prepare(dentry, attr);
435         if (error)
436                 return error;
437
438         if (ia_valid & ATTR_SIZE) {
439                 error = -EINVAL;
440                 if (attr->ia_size & ~huge_page_mask(h))
441                         return -EINVAL;
442                 error = hugetlb_vmtruncate(inode, attr->ia_size);
443                 if (error)
444                         return error;
445         }
446
447         setattr_copy(inode, attr);
448         mark_inode_dirty(inode);
449         return 0;
450 }
451
452 static struct inode *hugetlbfs_get_inode(struct super_block *sb, uid_t uid, 
453                                         gid_t gid, int mode, dev_t dev)
454 {
455         struct inode *inode;
456
457         inode = new_inode(sb);
458         if (inode) {
459                 struct hugetlbfs_inode_info *info;
460                 inode->i_ino = get_next_ino();
461                 inode->i_mode = mode;
462                 inode->i_uid = uid;
463                 inode->i_gid = gid;
464                 inode->i_mapping->a_ops = &hugetlbfs_aops;
465                 inode->i_mapping->backing_dev_info =&hugetlbfs_backing_dev_info;
466                 inode->i_atime = inode->i_mtime = inode->i_ctime = CURRENT_TIME;
467                 INIT_LIST_HEAD(&inode->i_mapping->private_list);
468                 info = HUGETLBFS_I(inode);
469                 /*
470                  * The policy is initialized here even if we are creating a
471                  * private inode because initialization simply creates an
472                  * an empty rb tree and calls spin_lock_init(), later when we
473                  * call mpol_free_shared_policy() it will just return because
474                  * the rb tree will still be empty.
475                  */
476                 mpol_shared_policy_init(&info->policy, NULL);
477                 switch (mode & S_IFMT) {
478                 default:
479                         init_special_inode(inode, mode, dev);
480                         break;
481                 case S_IFREG:
482                         inode->i_op = &hugetlbfs_inode_operations;
483                         inode->i_fop = &hugetlbfs_file_operations;
484                         break;
485                 case S_IFDIR:
486                         inode->i_op = &hugetlbfs_dir_inode_operations;
487                         inode->i_fop = &simple_dir_operations;
488
489                         /* directory inodes start off with i_nlink == 2 (for "." entry) */
490                         inc_nlink(inode);
491                         break;
492                 case S_IFLNK:
493                         inode->i_op = &page_symlink_inode_operations;
494                         break;
495                 }
496                 lockdep_annotate_inode_mutex_key(inode);
497         }
498         return inode;
499 }
500
501 /*
502  * File creation. Allocate an inode, and we're done..
503  */
504 static int hugetlbfs_mknod(struct inode *dir,
505                         struct dentry *dentry, int mode, dev_t dev)
506 {
507         struct inode *inode;
508         int error = -ENOSPC;
509         gid_t gid;
510
511         if (dir->i_mode & S_ISGID) {
512                 gid = dir->i_gid;
513                 if (S_ISDIR(mode))
514                         mode |= S_ISGID;
515         } else {
516                 gid = current_fsgid();
517         }
518         inode = hugetlbfs_get_inode(dir->i_sb, current_fsuid(), gid, mode, dev);
519         if (inode) {
520                 dir->i_ctime = dir->i_mtime = CURRENT_TIME;
521                 d_instantiate(dentry, inode);
522                 dget(dentry);   /* Extra count - pin the dentry in core */
523                 error = 0;
524         }
525         return error;
526 }
527
528 static int hugetlbfs_mkdir(struct inode *dir, struct dentry *dentry, int mode)
529 {
530         int retval = hugetlbfs_mknod(dir, dentry, mode | S_IFDIR, 0);
531         if (!retval)
532                 inc_nlink(dir);
533         return retval;
534 }
535
536 static int hugetlbfs_create(struct inode *dir, struct dentry *dentry, int mode, struct nameidata *nd)
537 {
538         return hugetlbfs_mknod(dir, dentry, mode | S_IFREG, 0);
539 }
540
541 static int hugetlbfs_symlink(struct inode *dir,
542                         struct dentry *dentry, const char *symname)
543 {
544         struct inode *inode;
545         int error = -ENOSPC;
546         gid_t gid;
547
548         if (dir->i_mode & S_ISGID)
549                 gid = dir->i_gid;
550         else
551                 gid = current_fsgid();
552
553         inode = hugetlbfs_get_inode(dir->i_sb, current_fsuid(),
554                                         gid, S_IFLNK|S_IRWXUGO, 0);
555         if (inode) {
556                 int l = strlen(symname)+1;
557                 error = page_symlink(inode, symname, l);
558                 if (!error) {
559                         d_instantiate(dentry, inode);
560                         dget(dentry);
561                 } else
562                         iput(inode);
563         }
564         dir->i_ctime = dir->i_mtime = CURRENT_TIME;
565
566         return error;
567 }
568
569 /*
570  * mark the head page dirty
571  */
572 static int hugetlbfs_set_page_dirty(struct page *page)
573 {
574         struct page *head = compound_head(page);
575
576         SetPageDirty(head);
577         return 0;
578 }
579
580 static int hugetlbfs_migrate_page(struct address_space *mapping,
581                                 struct page *newpage, struct page *page,
582                                 enum migrate_mode mode)
583 {
584         int rc;
585
586         rc = migrate_huge_page_move_mapping(mapping, newpage, page);
587         if (rc)
588                 return rc;
589         migrate_page_copy(newpage, page);
590
591         return 0;
592 }
593
594 static int hugetlbfs_statfs(struct dentry *dentry, struct kstatfs *buf)
595 {
596         struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(dentry->d_sb);
597         struct hstate *h = hstate_inode(dentry->d_inode);
598
599         buf->f_type = HUGETLBFS_MAGIC;
600         buf->f_bsize = huge_page_size(h);
601         if (sbinfo) {
602                 spin_lock(&sbinfo->stat_lock);
603                 /* If no limits set, just report 0 for max/free/used
604                  * blocks, like simple_statfs() */
605                 if (sbinfo->spool) {
606                         long free_pages;
607
608                         spin_lock(&sbinfo->spool->lock);
609                         buf->f_blocks = sbinfo->spool->max_hpages;
610                         free_pages = sbinfo->spool->max_hpages
611                                 - sbinfo->spool->used_hpages;
612                         buf->f_bavail = buf->f_bfree = free_pages;
613                         spin_unlock(&sbinfo->spool->lock);
614                         buf->f_files = sbinfo->max_inodes;
615                         buf->f_ffree = sbinfo->free_inodes;
616                 }
617                 spin_unlock(&sbinfo->stat_lock);
618         }
619         buf->f_namelen = NAME_MAX;
620         return 0;
621 }
622
623 static void hugetlbfs_put_super(struct super_block *sb)
624 {
625         struct hugetlbfs_sb_info *sbi = HUGETLBFS_SB(sb);
626
627         if (sbi) {
628                 sb->s_fs_info = NULL;
629
630                 if (sbi->spool)
631                         hugepage_put_subpool(sbi->spool);
632
633                 kfree(sbi);
634         }
635 }
636
637 static inline int hugetlbfs_dec_free_inodes(struct hugetlbfs_sb_info *sbinfo)
638 {
639         if (sbinfo->free_inodes >= 0) {
640                 spin_lock(&sbinfo->stat_lock);
641                 if (unlikely(!sbinfo->free_inodes)) {
642                         spin_unlock(&sbinfo->stat_lock);
643                         return 0;
644                 }
645                 sbinfo->free_inodes--;
646                 spin_unlock(&sbinfo->stat_lock);
647         }
648
649         return 1;
650 }
651
652 static void hugetlbfs_inc_free_inodes(struct hugetlbfs_sb_info *sbinfo)
653 {
654         if (sbinfo->free_inodes >= 0) {
655                 spin_lock(&sbinfo->stat_lock);
656                 sbinfo->free_inodes++;
657                 spin_unlock(&sbinfo->stat_lock);
658         }
659 }
660
661
662 static struct kmem_cache *hugetlbfs_inode_cachep;
663
664 static struct inode *hugetlbfs_alloc_inode(struct super_block *sb)
665 {
666         struct hugetlbfs_sb_info *sbinfo = HUGETLBFS_SB(sb);
667         struct hugetlbfs_inode_info *p;
668
669         if (unlikely(!hugetlbfs_dec_free_inodes(sbinfo)))
670                 return NULL;
671         p = kmem_cache_alloc(hugetlbfs_inode_cachep, GFP_KERNEL);
672         if (unlikely(!p)) {
673                 hugetlbfs_inc_free_inodes(sbinfo);
674                 return NULL;
675         }
676         return &p->vfs_inode;
677 }
678
679 static void hugetlbfs_i_callback(struct rcu_head *head)
680 {
681         struct inode *inode = container_of(head, struct inode, i_rcu);
682         INIT_LIST_HEAD(&inode->i_dentry);
683         kmem_cache_free(hugetlbfs_inode_cachep, HUGETLBFS_I(inode));
684 }
685
686 static void hugetlbfs_destroy_inode(struct inode *inode)
687 {
688         hugetlbfs_inc_free_inodes(HUGETLBFS_SB(inode->i_sb));
689         mpol_free_shared_policy(&HUGETLBFS_I(inode)->policy);
690         call_rcu(&inode->i_rcu, hugetlbfs_i_callback);
691 }
692
693 static const struct address_space_operations hugetlbfs_aops = {
694         .write_begin    = hugetlbfs_write_begin,
695         .write_end      = hugetlbfs_write_end,
696         .set_page_dirty = hugetlbfs_set_page_dirty,
697         .migratepage    = hugetlbfs_migrate_page,
698 };
699
700
701 static void init_once(void *foo)
702 {
703         struct hugetlbfs_inode_info *ei = (struct hugetlbfs_inode_info *)foo;
704
705         inode_init_once(&ei->vfs_inode);
706 }
707
708 const struct file_operations hugetlbfs_file_operations = {
709         .read                   = hugetlbfs_read,
710         .mmap                   = hugetlbfs_file_mmap,
711         .fsync                  = noop_fsync,
712         .get_unmapped_area      = hugetlb_get_unmapped_area,
713         .llseek         = default_llseek,
714 };
715
716 static const struct inode_operations hugetlbfs_dir_inode_operations = {
717         .create         = hugetlbfs_create,
718         .lookup         = simple_lookup,
719         .link           = simple_link,
720         .unlink         = simple_unlink,
721         .symlink        = hugetlbfs_symlink,
722         .mkdir          = hugetlbfs_mkdir,
723         .rmdir          = simple_rmdir,
724         .mknod          = hugetlbfs_mknod,
725         .rename         = simple_rename,
726         .setattr        = hugetlbfs_setattr,
727 };
728
729 static const struct inode_operations hugetlbfs_inode_operations = {
730         .setattr        = hugetlbfs_setattr,
731 };
732
733 static const struct super_operations hugetlbfs_ops = {
734         .alloc_inode    = hugetlbfs_alloc_inode,
735         .destroy_inode  = hugetlbfs_destroy_inode,
736         .evict_inode    = hugetlbfs_evict_inode,
737         .statfs         = hugetlbfs_statfs,
738         .put_super      = hugetlbfs_put_super,
739         .show_options   = generic_show_options,
740 };
741
742 static int
743 hugetlbfs_parse_options(char *options, struct hugetlbfs_config *pconfig)
744 {
745         char *p, *rest;
746         substring_t args[MAX_OPT_ARGS];
747         int option;
748         unsigned long long size = 0;
749         enum { NO_SIZE, SIZE_STD, SIZE_PERCENT } setsize = NO_SIZE;
750
751         if (!options)
752                 return 0;
753
754         while ((p = strsep(&options, ",")) != NULL) {
755                 int token;
756                 if (!*p)
757                         continue;
758
759                 token = match_token(p, tokens, args);
760                 switch (token) {
761                 case Opt_uid:
762                         if (match_int(&args[0], &option))
763                                 goto bad_val;
764                         pconfig->uid = option;
765                         break;
766
767                 case Opt_gid:
768                         if (match_int(&args[0], &option))
769                                 goto bad_val;
770                         pconfig->gid = option;
771                         break;
772
773                 case Opt_mode:
774                         if (match_octal(&args[0], &option))
775                                 goto bad_val;
776                         pconfig->mode = option & 01777U;
777                         break;
778
779                 case Opt_size: {
780                         /* memparse() will accept a K/M/G without a digit */
781                         if (!isdigit(*args[0].from))
782                                 goto bad_val;
783                         size = memparse(args[0].from, &rest);
784                         setsize = SIZE_STD;
785                         if (*rest == '%')
786                                 setsize = SIZE_PERCENT;
787                         break;
788                 }
789
790                 case Opt_nr_inodes:
791                         /* memparse() will accept a K/M/G without a digit */
792                         if (!isdigit(*args[0].from))
793                                 goto bad_val;
794                         pconfig->nr_inodes = memparse(args[0].from, &rest);
795                         break;
796
797                 case Opt_pagesize: {
798                         unsigned long ps;
799                         ps = memparse(args[0].from, &rest);
800                         pconfig->hstate = size_to_hstate(ps);
801                         if (!pconfig->hstate) {
802                                 printk(KERN_ERR
803                                 "hugetlbfs: Unsupported page size %lu MB\n",
804                                         ps >> 20);
805                                 return -EINVAL;
806                         }
807                         break;
808                 }
809
810                 default:
811                         printk(KERN_ERR "hugetlbfs: Bad mount option: \"%s\"\n",
812                                  p);
813                         return -EINVAL;
814                         break;
815                 }
816         }
817
818         /* Do size after hstate is set up */
819         if (setsize > NO_SIZE) {
820                 struct hstate *h = pconfig->hstate;
821                 if (setsize == SIZE_PERCENT) {
822                         size <<= huge_page_shift(h);
823                         size *= h->max_huge_pages;
824                         do_div(size, 100);
825                 }
826                 pconfig->nr_blocks = (size >> huge_page_shift(h));
827         }
828
829         return 0;
830
831 bad_val:
832         printk(KERN_ERR "hugetlbfs: Bad value '%s' for mount option '%s'\n",
833                args[0].from, p);
834         return -EINVAL;
835 }
836
837 static int
838 hugetlbfs_fill_super(struct super_block *sb, void *data, int silent)
839 {
840         struct inode * inode;
841         struct dentry * root;
842         int ret;
843         struct hugetlbfs_config config;
844         struct hugetlbfs_sb_info *sbinfo;
845
846         save_mount_options(sb, data);
847
848         config.nr_blocks = -1; /* No limit on size by default */
849         config.nr_inodes = -1; /* No limit on number of inodes by default */
850         config.uid = current_fsuid();
851         config.gid = current_fsgid();
852         config.mode = 0755;
853         config.hstate = &default_hstate;
854         ret = hugetlbfs_parse_options(data, &config);
855         if (ret)
856                 return ret;
857
858         sbinfo = kmalloc(sizeof(struct hugetlbfs_sb_info), GFP_KERNEL);
859         if (!sbinfo)
860                 return -ENOMEM;
861         sb->s_fs_info = sbinfo;
862         sbinfo->hstate = config.hstate;
863         spin_lock_init(&sbinfo->stat_lock);
864         sbinfo->max_inodes = config.nr_inodes;
865         sbinfo->free_inodes = config.nr_inodes;
866         sbinfo->spool = NULL;
867         if (config.nr_blocks != -1) {
868                 sbinfo->spool = hugepage_new_subpool(config.nr_blocks);
869                 if (!sbinfo->spool)
870                         goto out_free;
871         }
872         sb->s_maxbytes = MAX_LFS_FILESIZE;
873         sb->s_blocksize = huge_page_size(config.hstate);
874         sb->s_blocksize_bits = huge_page_shift(config.hstate);
875         sb->s_magic = HUGETLBFS_MAGIC;
876         sb->s_op = &hugetlbfs_ops;
877         sb->s_time_gran = 1;
878         inode = hugetlbfs_get_inode(sb, config.uid, config.gid,
879                                         S_IFDIR | config.mode, 0);
880         if (!inode)
881                 goto out_free;
882
883         root = d_alloc_root(inode);
884         if (!root) {
885                 iput(inode);
886                 goto out_free;
887         }
888         sb->s_root = root;
889         return 0;
890 out_free:
891         if (sbinfo->spool)
892                 kfree(sbinfo->spool);
893         kfree(sbinfo);
894         return -ENOMEM;
895 }
896
897 static struct dentry *hugetlbfs_mount(struct file_system_type *fs_type,
898         int flags, const char *dev_name, void *data)
899 {
900         return mount_nodev(fs_type, flags, data, hugetlbfs_fill_super);
901 }
902
903 static struct file_system_type hugetlbfs_fs_type = {
904         .name           = "hugetlbfs",
905         .mount          = hugetlbfs_mount,
906         .kill_sb        = kill_litter_super,
907 };
908
909 static struct vfsmount *hugetlbfs_vfsmount;
910
911 static int can_do_hugetlb_shm(void)
912 {
913         return capable(CAP_IPC_LOCK) || in_group_p(sysctl_hugetlb_shm_group);
914 }
915
916 struct file *hugetlb_file_setup(const char *name, size_t size,
917                                 vm_flags_t acctflag,
918                                 struct user_struct **user, int creat_flags)
919 {
920         int error = -ENOMEM;
921         struct file *file;
922         struct inode *inode;
923         struct path path;
924         struct dentry *root;
925         struct qstr quick_string;
926
927         *user = NULL;
928         if (!hugetlbfs_vfsmount)
929                 return ERR_PTR(-ENOENT);
930
931         if (creat_flags == HUGETLB_SHMFS_INODE && !can_do_hugetlb_shm()) {
932                 *user = current_user();
933                 if (user_shm_lock(size, *user)) {
934                         printk_once(KERN_WARNING "Using mlock ulimits for SHM_HUGETLB is deprecated\n");
935                 } else {
936                         *user = NULL;
937                         return ERR_PTR(-EPERM);
938                 }
939         }
940
941         root = hugetlbfs_vfsmount->mnt_root;
942         quick_string.name = name;
943         quick_string.len = strlen(quick_string.name);
944         quick_string.hash = 0;
945         path.dentry = d_alloc(root, &quick_string);
946         if (!path.dentry)
947                 goto out_shm_unlock;
948
949         path.mnt = mntget(hugetlbfs_vfsmount);
950         error = -ENOSPC;
951         inode = hugetlbfs_get_inode(root->d_sb, current_fsuid(),
952                                 current_fsgid(), S_IFREG | S_IRWXUGO, 0);
953         if (!inode)
954                 goto out_dentry;
955
956         error = -ENOMEM;
957         if (hugetlb_reserve_pages(inode, 0,
958                         size >> huge_page_shift(hstate_inode(inode)), NULL,
959                         acctflag))
960                 goto out_inode;
961
962         d_instantiate(path.dentry, inode);
963         inode->i_size = size;
964         clear_nlink(inode);
965
966         error = -ENFILE;
967         file = alloc_file(&path, FMODE_WRITE | FMODE_READ,
968                         &hugetlbfs_file_operations);
969         if (!file)
970                 goto out_dentry; /* inode is already attached */
971
972         return file;
973
974 out_inode:
975         iput(inode);
976 out_dentry:
977         path_put(&path);
978 out_shm_unlock:
979         if (*user) {
980                 user_shm_unlock(size, *user);
981                 *user = NULL;
982         }
983         return ERR_PTR(error);
984 }
985
986 static int __init init_hugetlbfs_fs(void)
987 {
988         int error;
989         struct vfsmount *vfsmount;
990
991         if (!hugepages_supported()) {
992                 pr_info("hugetlbfs: disabling because there are no supported hugepage sizes\n");
993                 return -ENOTSUPP;
994         }
995
996         error = bdi_init(&hugetlbfs_backing_dev_info);
997         if (error)
998                 return error;
999
1000         hugetlbfs_inode_cachep = kmem_cache_create("hugetlbfs_inode_cache",
1001                                         sizeof(struct hugetlbfs_inode_info),
1002                                         0, 0, init_once);
1003         if (hugetlbfs_inode_cachep == NULL)
1004                 goto out2;
1005
1006         error = register_filesystem(&hugetlbfs_fs_type);
1007         if (error)
1008                 goto out;
1009
1010         vfsmount = kern_mount(&hugetlbfs_fs_type);
1011
1012         if (!IS_ERR(vfsmount)) {
1013                 hugetlbfs_vfsmount = vfsmount;
1014                 return 0;
1015         }
1016
1017         error = PTR_ERR(vfsmount);
1018
1019  out:
1020         if (error)
1021                 kmem_cache_destroy(hugetlbfs_inode_cachep);
1022  out2:
1023         bdi_destroy(&hugetlbfs_backing_dev_info);
1024         return error;
1025 }
1026
1027 static void __exit exit_hugetlbfs_fs(void)
1028 {
1029         kmem_cache_destroy(hugetlbfs_inode_cachep);
1030         kern_unmount(hugetlbfs_vfsmount);
1031         unregister_filesystem(&hugetlbfs_fs_type);
1032         bdi_destroy(&hugetlbfs_backing_dev_info);
1033 }
1034
1035 module_init(init_hugetlbfs_fs)
1036 module_exit(exit_hugetlbfs_fs)
1037
1038 MODULE_LICENSE("GPL");