From patchwork Thu Dec 22 20:15:35 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Sean Christopherson X-Patchwork-Id: 9485567 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 59ACE601D5 for ; Thu, 22 Dec 2016 20:16:05 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 5B7352844A for ; Thu, 22 Dec 2016 20:16:05 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 4AF8D28459; Thu, 22 Dec 2016 20:16:05 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=2.0 tests=BAYES_00, RCVD_IN_DNSWL_NONE autolearn=ham version=3.3.1 Received: from ml01.01.org (ml01.01.org [198.145.21.10]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id 8F9AD28468 for ; Thu, 22 Dec 2016 20:16:04 +0000 (UTC) Received: from [127.0.0.1] (localhost [IPv6:::1]) by ml01.01.org (Postfix) with ESMTP id 72BCA823C8 for ; Thu, 22 Dec 2016 12:16:04 -0800 (PST) X-Original-To: intel-sgx-kernel-dev@lists.01.org Delivered-To: intel-sgx-kernel-dev@lists.01.org Received: from mga07.intel.com (mga07.intel.com [134.134.136.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ml01.01.org (Postfix) with ESMTPS id 52051823BB for ; Thu, 22 Dec 2016 12:16:03 -0800 (PST) Received: from orsmga005.jf.intel.com ([10.7.209.41]) by orsmga105.jf.intel.com with ESMTP; 22 Dec 2016 12:16:02 -0800 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.33,390,1477983600"; d="scan'208";a="45576601" Received: from sjchrist-ts.jf.intel.com ([10.54.74.20]) by orsmga005.jf.intel.com with ESMTP; 22 Dec 2016 12:16:02 -0800 From: Sean Christopherson To: intel-sgx-kernel-dev@lists.01.org Date: Thu, 22 Dec 2016 12:15:35 -0800 Message-Id: <1482437735-4722-7-git-send-email-sean.j.christopherson@intel.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1482437735-4722-1-git-send-email-sean.j.christopherson@intel.com> References: <1482437735-4722-1-git-send-email-sean.j.christopherson@intel.com> Subject: [intel-sgx-kernel-dev] [PATCH 6/6] intel_sgx: Combine epc/eviction pages via union X-BeenThere: intel-sgx-kernel-dev@lists.01.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Project: Intel® Software Guard Extensions for Linux*: https://01.org/intel-software-guard-extensions" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , MIME-Version: 1.0 Errors-To: intel-sgx-kernel-dev-bounces@lists.01.org Sender: "intel-sgx-kernel-dev" X-Virus-Scanned: ClamAV using ClamSMTP Add a new struct, sgx_evicted_page, to hold all information about an evicted enclave page, e.g. VA page, VA offset and PCMD. Dynamically allocate the evicted page object at EWB and free it at ELDU. Combine sgx_encl_page's epc_page and evicted_page into a union, as on-demand VA and PCMD allocation only epc_page or evicted_page will be valid at any given time. Add a new flag, SGX_ENCL_PAGE_IN_EPC, to track if an encl page has been loaded into the EPC. If SGX_ENCL_PAGE_IN_EPC is set, then the epc_page member of the epc_page/evicted_page union is valid, else va_page *may* be valid, e.g. neither is valid if EADD has not been completed. Call sgx_free_encl_page in the success path of __sgx_ewb, as the EPC page must be freed before updating the encl_page's va_page. Signed-off-by: Sean Christopherson --- drivers/platform/x86/intel_sgx.h | 16 ++++++++++---- drivers/platform/x86/intel_sgx_ioctl.c | 2 ++ drivers/platform/x86/intel_sgx_page_cache.c | 33 +++++++++++++++++------------ drivers/platform/x86/intel_sgx_util.c | 12 +++++------ drivers/platform/x86/intel_sgx_vma.c | 16 ++++++++------ 5 files changed, 49 insertions(+), 30 deletions(-) diff --git a/drivers/platform/x86/intel_sgx.h b/drivers/platform/x86/intel_sgx.h index 23cfd63..fe48313 100644 --- a/drivers/platform/x86/intel_sgx.h +++ b/drivers/platform/x86/intel_sgx.h @@ -93,19 +93,27 @@ static inline void sgx_free_va_slot(struct sgx_va_page *page, clear_bit(offset >> 3, page->slots); } + +struct sgx_evicted_page { + struct sgx_pcmd pcmd; + struct sgx_va_page *va_page; + unsigned int va_offset; +}; + enum sgx_encl_page_flags { SGX_ENCL_PAGE_TCS = BIT(0), SGX_ENCL_PAGE_RESERVED = BIT(1), + SGX_ENCL_PAGE_IN_EPC = BIT(2), }; struct sgx_encl_page { unsigned long addr; unsigned int flags; - struct sgx_epc_page *epc_page; + union { + struct sgx_epc_page *epc_page; + struct sgx_evicted_page *evicted_page; + }; struct list_head load_list; - struct sgx_va_page *va_page; - unsigned int va_offset; - struct sgx_pcmd pcmd; }; struct sgx_tgid_ctx { diff --git a/drivers/platform/x86/intel_sgx_ioctl.c b/drivers/platform/x86/intel_sgx_ioctl.c index a5849c6..dbb29ab 100644 --- a/drivers/platform/x86/intel_sgx_ioctl.c +++ b/drivers/platform/x86/intel_sgx_ioctl.c @@ -268,6 +268,7 @@ static bool sgx_process_add_page_req(struct sgx_add_page_req *req) goto out; } + encl_page->flags |= SGX_ENCL_PAGE_IN_EPC; encl_page->epc_page = epc_page; sgx_test_and_clear_young(encl_page, encl); list_add_tail(&encl_page->load_list, &encl->load_list); @@ -546,6 +547,7 @@ static long sgx_ioc_enclave_create(struct file *filep, unsigned int cmd, goto out; } + encl->secs_page.flags |= SGX_ENCL_PAGE_IN_EPC; encl->secs_page.epc_page = secs_epc; createp->src = (unsigned long)encl->base; diff --git a/drivers/platform/x86/intel_sgx_page_cache.c b/drivers/platform/x86/intel_sgx_page_cache.c index e5965b3..ced8128 100644 --- a/drivers/platform/x86/intel_sgx_page_cache.c +++ b/drivers/platform/x86/intel_sgx_page_cache.c @@ -262,18 +262,17 @@ static void sgx_free_encl_page(struct sgx_encl_page *encl_page, { sgx_free_page(encl_page->epc_page, encl, flags); encl_page->epc_page = NULL; - encl_page->flags &= ~SGX_ENCL_PAGE_RESERVED; + encl_page->flags &= ~(SGX_ENCL_PAGE_RESERVED | SGX_ENCL_PAGE_IN_EPC); } static int __sgx_ewb(struct sgx_encl *encl, struct sgx_encl_page *encl_page) { struct sgx_page_info pginfo; - struct sgx_va_page *va_page; + struct sgx_evicted_page *evicted_page; struct page *backing; void *epc; void *va; - unsigned int va_offset; int ret; backing = sgx_get_backing(encl, encl_page); @@ -284,31 +283,39 @@ static int __sgx_ewb(struct sgx_encl *encl, return ret; } - va_offset = sgx_alloc_va_slot(encl, &va_page); - if (va_offset == PAGE_SIZE) { + evicted_page = kmalloc(sizeof(*evicted_page), GFP_KERNEL); + if (!evicted_page) { + sgx_put_backing(backing, true); + return -ENOMEM; + } + + evicted_page->va_offset = sgx_alloc_va_slot(encl, &evicted_page->va_page); + if (evicted_page->va_offset == PAGE_SIZE) { + kfree(evicted_page); sgx_put_backing(backing, true); return -ENOMEM; } epc = sgx_get_epc_page(encl_page->epc_page); - va = sgx_get_epc_page(va_page->epc_page); + va = sgx_get_epc_page(evicted_page->va_page->epc_page); pginfo.srcpge = (unsigned long)kmap_atomic(backing); - pginfo.pcmd = (unsigned long)&encl_page->pcmd; + pginfo.pcmd = (unsigned long)&evicted_page->pcmd; pginfo.linaddr = 0; pginfo.secs = 0; ret = __ewb(&pginfo, epc, - (void *)((unsigned long)va + va_offset)); + (void *)((unsigned long)va + evicted_page->va_offset)); kunmap_atomic((void *)(unsigned long)pginfo.srcpge); sgx_put_epc_page(va); sgx_put_epc_page(epc); if (ret == SGX_SUCCESS) { - encl_page->va_page = va_page; - encl_page->va_offset = va_offset; + sgx_free_encl_page(encl_page, encl, SGX_FREE_SKIP_EREMOVE); + encl_page->evicted_page = evicted_page; } else { - sgx_free_va_slot(va_page, va_offset); + sgx_free_va_slot(evicted_page->va_page, evicted_page->va_offset); + kfree(evicted_page); } sgx_put_backing(backing, true); @@ -327,9 +334,7 @@ static void sgx_ewb(struct sgx_encl *encl, ret = __sgx_ewb(encl, encl_page); } - if (ret == SGX_SUCCESS) { - sgx_free_encl_page(encl_page, encl, SGX_FREE_SKIP_EREMOVE); - } else { + if (ret) { sgx_free_encl_page(encl_page, encl, 0); if (!(encl->flags & SGX_ENCL_DEAD)) { /* make enclave inaccessible */ diff --git a/drivers/platform/x86/intel_sgx_util.c b/drivers/platform/x86/intel_sgx_util.c index 2c390c5..3234f59 100644 --- a/drivers/platform/x86/intel_sgx_util.c +++ b/drivers/platform/x86/intel_sgx_util.c @@ -218,10 +218,10 @@ void sgx_encl_release(struct kref *ref) radix_tree_for_each_slot(slot, &encl->page_tree, &iter, 0) { entry = *slot; - if (entry->epc_page) { - list_del(&entry->load_list); + if (entry->flags & SGX_ENCL_PAGE_IN_EPC) sgx_free_page(entry->epc_page, encl, 0); - } + else if (entry->evicted_page) + kfree(entry->evicted_page); radix_tree_delete(&encl->page_tree, entry->addr >> PAGE_SHIFT); kfree(entry); } @@ -234,10 +234,10 @@ void sgx_encl_release(struct kref *ref) kfree(va_page); } - if (encl->secs_page.epc_page) + if (encl->secs_page.flags & SGX_ENCL_PAGE_IN_EPC) sgx_free_page(encl->secs_page.epc_page, encl, 0); - - encl->secs_page.epc_page = NULL; + else if (encl->secs_page.evicted_page) + kfree(encl->secs_page.evicted_page); if (encl->tgid_ctx) kref_put(&encl->tgid_ctx->refcount, sgx_tgid_ctx_release); diff --git a/drivers/platform/x86/intel_sgx_vma.c b/drivers/platform/x86/intel_sgx_vma.c index fd5536c..1a6b45e 100644 --- a/drivers/platform/x86/intel_sgx_vma.c +++ b/drivers/platform/x86/intel_sgx_vma.c @@ -128,15 +128,15 @@ static int do_eldu(struct sgx_encl *encl, pginfo.secs = (unsigned long)secs_ptr; epc_ptr = sgx_get_epc_page(epc_page); - va_ptr = sgx_get_epc_page(encl_page->va_page->epc_page); + va_ptr = sgx_get_epc_page(encl_page->evicted_page->va_page->epc_page); pginfo.linaddr = is_secs ? 0 : encl_page->addr; - pginfo.pcmd = (unsigned long)&encl_page->pcmd; + pginfo.pcmd = (unsigned long)&encl_page->evicted_page->pcmd; ret = __eldu((unsigned long)&pginfo, (unsigned long)epc_ptr, (unsigned long)va_ptr + - encl_page->va_offset); + encl_page->evicted_page->va_offset); sgx_put_epc_page(va_ptr); sgx_put_epc_page(epc_ptr); @@ -149,8 +149,12 @@ static int do_eldu(struct sgx_encl *encl, if (ret) return -EFAULT; - sgx_free_va_slot(encl_page->va_page, encl_page->va_offset); + sgx_free_va_slot(encl_page->evicted_page->va_page, + encl_page->evicted_page->va_offset); + kfree(encl_page->evicted_page); + encl_page->evicted_page = NULL; + encl_page->flags |= SGX_ENCL_PAGE_IN_EPC; encl_page->epc_page = epc_page; return 0; @@ -206,14 +210,14 @@ static struct sgx_encl_page *sgx_vma_do_fault(struct vm_area_struct *vma, } /* Legal race condition, page is already faulted. */ - if (entry->epc_page) { + if (entry->flags & SGX_ENCL_PAGE_IN_EPC) { if (reserve) entry->flags |= SGX_ENCL_PAGE_RESERVED; goto out; } /* If SECS is evicted then reload it first */ - if (!encl->secs_page.epc_page) { + if (!(encl->secs_page.flags & SGX_ENCL_PAGE_IN_EPC)) { secs_epc_page = sgx_alloc_page(encl->tgid_ctx, SGX_ALLOC_ATOMIC); if (IS_ERR(secs_epc_page)) { entry = (void *)secs_epc_page;