aboutsummaryrefslogtreecommitdiffstats
path: root/src/chmsg.c
blob: 8c6fa779fe30007641dfb7c71d9b15ad51cf0987 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
/*
    ChibiOS/RT - Copyright (C) 2006-2007 Giovanni Di Sirio.

    This file is part of ChibiOS/RT.

    ChibiOS/RT is free software; you can redistribute it and/or modify
    it under the terms of the GNU General Public License as published by
    the Free Software Foundation; either version 3 of the License, or
    (at your option) any later version.

    ChibiOS/RT is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.

    You should have received a copy of the GNU General Public License
    along with this program.  If not, see <http://www.gnu.org/licenses/>.
*/

/**
 * @addtogroup Messages
 * @{
 */
#include <ch.h>

#ifdef CH_USE_MESSAGES
/**
 * Sends a message to the specified thread. The client is stopped until the
 * server executes a \p chMsgRelease() after receiving the message.
 *
 * @param tp the pointer to the thread
 * @param msg the message, it can be a pointer to a complex structure
 * @return the return message from \p chMsgRelease()
 */
msg_t chMsgSend(Thread *tp, msg_t msg) {

  chSysLock();

#ifdef CH_USE_MESSAGES_PRIORITY
  if (tp->p_flags & P_MSGBYPRIO)
    prio_insert(currp, &tp->p_msgqueue);
  else
    fifo_insert(currp, &tp->p_msgqueue);
#else
  fifo_insert(currp, &tp->p_msgqueue);
#endif
  currp->p_msg = msg;
  currp->p_wtthdp = tp;
  if (tp->p_state == PRWTMSG)
    chSchReadyI(tp);
  chSchGoSleepS(PRSNDMSG);
  msg = currp->p_rdymsg;

  chSysUnlock();
  return msg;
}

#ifdef CH_USE_MESSAGES_EVENT
/**
 * Sends a message to the specified thread and atomically triggers an event.
 * The client is stopped until the server executes a \p chMsgRelease()
 * after receiving the message.
 *
 * @param tp the pointer to the thread
 * @param msg the message, it can be a pointer to a complex structure
 * @param esp the event source to pulse while sending the message
 * @return the return message from \p chMsgRelease()
 * @return the message return status from \p chMsgRelease()
 * @note This function assumes that the receiving thread is not sleeping into
 *       a \p chMsgWait(). The use case is that the server thread is waiting
 *       for both messages AND events while waiting into \p chEvtWait().
 */
msg_t chMsgSendWithEvent(Thread *tp, msg_t msg, EventSource *esp) {

  chSysLock();

  chDbgAssert(tp->p_state != PRWTMSG, "chmsg.c, chMsgSendWithEvent()");
#ifdef CH_USE_MESSAGES_PRIORITY
  if (tp->p_flags & P_MSGBYPRIO)
    prio_insert(currp, &tp->p_msgqueue);
  else
    fifo_insert(currp, &tp->p_msgqueue);
#else
  fifo_insert(currp, &tp->p_msgqueue);
#endif
  chEvtSendI(esp);
  currp->p_wtthdp = tp;
  currp->p_msg = msg;
  chSchGoSleepS(PRSNDMSG);
  msg = currp->p_rdymsg;

  chSysUnlock();
  return msg;
}
#endif

/**
 * Suspends the thread and waits for an incoming message.
 *
 * @return the pointer to the message structure. Note, it is always the
 *         message associated to the thread on the top of the messages queue.
 * @note You can assume that the data contained in the message is stable until
 *       you invoke \p chMsgRelease() because the sending thread is
 *       suspended until then.
 */
msg_t chMsgWait(void) {
  msg_t msg;

  chSysLock();

  if (!chMsgIsPendingI(currp))
    chSchGoSleepS(PRWTMSG);
  msg = chMsgGetI(currp);

  chSysUnlock();
  return msg;
}

/**
 * Returns the next message in the queue.
 *
 * @return the pointer to the message structure. Note, it is always the
 *         message associated to the thread on the top of the messages queue.
 *         If the queue is empty then \p NULL is returned.
 * @note You can assume that the data pointed by the message is stable until
 *       you invoke \p chMsgRelease() because the sending thread is
 *       suspended until then. Always remember that the message data is not
 *       copied between the sender and the receiver, just a pointer is passed.
 */
msg_t chMsgGet(void) {
  msg_t msg;

  chSysLock();

  msg = chMsgIsPendingI(currp) ? chMsgGetI(currp) : (msg_t)NULL;

  chSysUnlock();
  return msg;
}

/**
 * Releases the thread waiting on top of the messages queue.
 *
 * @param msg the message returned to the message sender
 * @note You can call this function only if there is a message already in the
 *       queue else the result will be unpredictable (a crash most likely).
 *       Exiting from the \p chMsgWait() ensures you have at least one
 *       message in the queue so it is not a big deal.<br>
 *       The condition is not checked in order to make this code as fast as
 *       possible.
 */
void chMsgRelease(msg_t msg) {

  chSysLock();

  chDbgAssert(chMsgIsPendingI(currp), "chmsg.c, chMsgRelease()");
  chSchWakeupS(fifo_remove(&currp->p_msgqueue), msg);

  chSysUnlock();
}

#endif /* CH_USE_MESSAGES */

/** @} */
GT_va_shift) /* Is the back pointer unknown (e.g., p.t. is mapped at multiple VAs)? */ #define PGT_va_unknown (((1U<<10)-2)<<PGT_va_shift) /* 17-bit count of uses of this frame as its current type. */ #define PGT_count_mask ((1U<<17)-1) #define PGT_mfn_mask ((1U<<20)-1) /* mfn mask for shadow types */ #define PGT_score_shift 20 #define PGT_score_mask (((1U<<4)-1)<<PGT_score_shift) /* Cleared when the owning guest 'frees' this page. */ #define _PGC_allocated 31 #define PGC_allocated (1U<<_PGC_allocated) /* Set when fullshadow mode marks a page out-of-sync */ #define _PGC_out_of_sync 30 #define PGC_out_of_sync (1U<<_PGC_out_of_sync) /* Set when fullshadow mode is using a page as a page table */ #define _PGC_page_table 29 #define PGC_page_table (1U<<_PGC_page_table) /* 29-bit count of references to this frame. */ #define PGC_count_mask ((1U<<29)-1) /* We trust the slab allocator in slab.c, and our use of it. */ #define PageSlab(page) (1) #define PageSetSlab(page) ((void)0) #define PageClearSlab(page) ((void)0) #define IS_XEN_HEAP_FRAME(_pfn) (page_to_phys(_pfn) < xenheap_phys_end) #if defined(__i386__) #define pickle_domptr(_d) ((u32)(unsigned long)(_d)) #define unpickle_domptr(_d) ((struct domain *)(unsigned long)(_d)) #elif defined(__x86_64__) static inline struct domain *unpickle_domptr(u32 _domain) { return (_domain == 0) ? NULL : __va(_domain); } static inline u32 pickle_domptr(struct domain *domain) { return (domain == NULL) ? 0 : (u32)__pa(domain); } #endif #define page_get_owner(_p) (unpickle_domptr((_p)->u.inuse._domain)) #define page_set_owner(_p,_d) ((_p)->u.inuse._domain = pickle_domptr(_d)) #define SHARE_PFN_WITH_DOMAIN(_pfn, _dom) \ do { \ page_set_owner((_pfn), (_dom)); \ /* The incremented type count is intended to pin to 'writable'. */ \ (_pfn)->u.inuse.type_info = PGT_writable_page | PGT_validated | 1; \ wmb(); /* install valid domain ptr before updating refcnt. */ \ spin_lock(&(_dom)->page_alloc_lock); \ /* _dom holds an allocation reference */ \ ASSERT((_pfn)->count_info == 0); \ (_pfn)->count_info |= PGC_allocated | 1; \ if ( unlikely((_dom)->xenheap_pages++ == 0) ) \ get_knownalive_domain(_dom); \ list_add_tail(&(_pfn)->list, &(_dom)->xenpage_list); \ spin_unlock(&(_dom)->page_alloc_lock); \ } while ( 0 ) extern struct pfn_info *frame_table; extern unsigned long frame_table_size; extern unsigned long max_page; void init_frametable(void); int alloc_page_type(struct pfn_info *page, unsigned int type); void free_page_type(struct pfn_info *page, unsigned int type); extern void invalidate_shadow_ldt(struct exec_domain *d); extern int shadow_remove_all_write_access( struct domain *d, unsigned long gpfn, unsigned long gmfn); extern u32 shadow_remove_all_access( struct domain *d, unsigned long gmfn); extern int _shadow_mode_refcounts(struct domain *d); static inline void put_page(struct pfn_info *page) { u32 nx, x, y = page->count_info; do { x = y; nx = x - 1; } while ( unlikely((y = cmpxchg(&page->count_info, x, nx)) != x) ); if ( unlikely((nx & PGC_count_mask) == 0) ) free_domheap_page(page); } static inline int get_page(struct pfn_info *page, struct domain *domain) { u32 x, nx, y = page->count_info; u32 d, nd = page->u.inuse._domain; u32 _domain = pickle_domptr(domain); do { x = y; nx = x + 1; d = nd; if ( unlikely((x & PGC_count_mask) == 0) || /* Not allocated? */ unlikely((nx & PGC_count_mask) == 0) || /* Count overflow? */ unlikely(d != _domain) ) /* Wrong owner? */ { if ( !_shadow_mode_refcounts(domain) ) DPRINTK("Error pfn %lx: rd=%p, od=%p, caf=%08x, taf=%08x\n", page_to_pfn(page), domain, unpickle_domptr(d), x, page->u.inuse.type_info); return 0; } __asm__ __volatile__( LOCK_PREFIX "cmpxchg8b %3" : "=d" (nd), "=a" (y), "=c" (d), "=m" (*(volatile u64 *)(&page->count_info)) : "0" (d), "1" (x), "c" (d), "b" (nx) ); } while ( unlikely(nd != d) || unlikely(y != x) ); return 1; } void put_page_type(struct pfn_info *page); int get_page_type(struct pfn_info *page, u32 type); int get_page_from_l1e(l1_pgentry_t l1e, struct domain *d); void put_page_from_l1e(l1_pgentry_t l1e, struct domain *d); static inline void put_page_and_type(struct pfn_info *page) { put_page_type(page); put_page(page); } static inline int get_page_and_type(struct pfn_info *page, struct domain *domain, u32 type) { int rc = get_page(page, domain); if ( likely(rc) && unlikely(!get_page_type(page, type)) ) { put_page(page); rc = 0; } return rc; } #define ASSERT_PAGE_IS_TYPE(_p, _t) \ ASSERT(((_p)->u.inuse.type_info & PGT_type_mask) == (_t)); \ ASSERT(((_p)->u.inuse.type_info & PGT_count_mask) != 0) #define ASSERT_PAGE_IS_DOMAIN(_p, _d) \ ASSERT(((_p)->count_info & PGC_count_mask) != 0); \ ASSERT(page_get_owner(_p) == (_d)) int check_descriptor(struct desc_struct *d); /* * The MPT (machine->physical mapping table) is an array of word-sized * values, indexed on machine frame number. It is expected that guest OSes * will use it to store a "physical" frame number to give the appearance of * contiguous (or near contiguous) physical memory. */ #undef machine_to_phys_mapping #define machine_to_phys_mapping ((u32 *)RDWR_MPT_VIRT_START) #define INVALID_M2P_ENTRY (~0U) #define VALID_M2P(_e) (!((_e) & (1U<<31))) #define IS_INVALID_M2P_ENTRY(_e) (!VALID_M2P(_e)) /* * The phys_to_machine_mapping is the reversed mapping of MPT for full * virtualization. It is only used by shadow_mode_translate()==true * guests, so we steal the address space that would have normally * been used by the read-only MPT map. */ #define __phys_to_machine_mapping ((unsigned long *)RO_MPT_VIRT_START) #define INVALID_MFN (~0UL) #define VALID_MFN(_mfn) (!((_mfn) & (1U<<31))) /* Returns the machine physical */ static inline unsigned long phys_to_machine_mapping(unsigned long pfn) { unsigned long mfn; l1_pgentry_t pte; if ( (__copy_from_user(&pte, &__phys_to_machine_mapping[pfn], sizeof(pte)) == 0) && (l1e_get_flags(pte) & _PAGE_PRESENT) ) mfn = l1e_get_pfn(pte); else mfn = INVALID_MFN; return mfn; } #define set_machinetophys(_mfn, _pfn) machine_to_phys_mapping[(_mfn)] = (_pfn) #ifdef MEMORY_GUARD void *memguard_init(void *heap_start); void memguard_guard_stack(void *p); void memguard_guard_range(void *p, unsigned long l); void memguard_unguard_range(void *p, unsigned long l); #else #define memguard_init(_s) (_s) #define memguard_guard_stack(_p) ((void)0) #define memguard_guard_range(_p,_l) ((void)0) #define memguard_unguard_range(_p,_l) ((void)0) #endif /* Writable Pagetables */ struct ptwr_info { /* Linear address where the guest is updating the p.t. page. */ unsigned long l1va; /* Copy of the p.t. page, taken before guest is given write access. */ l1_pgentry_t *page; /* A temporary Xen mapping of the actual p.t. page. */ l1_pgentry_t *pl1e; /* Index in L2 page table where this L1 p.t. is always hooked. */ unsigned int l2_idx; /* NB. Only used for PTWR_PT_ACTIVE. */ /* Info about last ptwr update batch. */ unsigned int prev_nr_updates; /* Exec domain which created writable mapping. */ struct exec_domain *ed; }; #define PTWR_PT_ACTIVE 0 #define PTWR_PT_INACTIVE 1 #define PTWR_CLEANUP_ACTIVE 1 #define PTWR_CLEANUP_INACTIVE 2 int ptwr_init(struct domain *); void ptwr_destroy(struct domain *); void ptwr_flush(struct domain *, const int); int ptwr_do_page_fault(struct domain *, unsigned long); int revalidate_l1(struct domain *, l1_pgentry_t *, l1_pgentry_t *); #define cleanup_writable_pagetable(_d) \ do { \ if ( likely(VM_ASSIST((_d), VMASST_TYPE_writable_pagetables)) ) \ { \ if ( likely(!shadow_mode_enabled(_d)) ) \ { \ if ( (_d)->arch.ptwr[PTWR_PT_ACTIVE].l1va ) \ ptwr_flush((_d), PTWR_PT_ACTIVE); \ if ( (_d)->arch.ptwr[PTWR_PT_INACTIVE].l1va ) \ ptwr_flush((_d), PTWR_PT_INACTIVE); \ } \ else \ shadow_sync_all(_d); \ } \ } while ( 0 ) int audit_adjust_pgtables(struct domain *d, int dir, int noisy); #ifndef NDEBUG #define AUDIT_SHADOW_ALREADY_LOCKED ( 1u << 0 ) #define AUDIT_ERRORS_OK ( 1u << 1 ) #define AUDIT_QUIET ( 1u << 2 ) void _audit_domain(struct domain *d, int flags); #define audit_domain(_d) _audit_domain((_d), AUDIT_ERRORS_OK) void audit_domains(void); #else #define _audit_domain(_d, _f) ((void)0) #define audit_domain(_d) ((void)0) #define audit_domains() ((void)0) #endif int new_guest_cr3(unsigned long pfn); void propagate_page_fault(unsigned long addr, u16 error_code); /* * Caller must own d's BIGLOCK, is responsible for flushing the TLB, and must * hold a reference to the page. */ int update_grant_va_mapping(unsigned long va, l1_pgentry_t _nl1e, struct domain *d, struct exec_domain *ed); #endif /* __ASM_X86_MM_H__ */