2 * Copyright (C) 2004-2006 Atmel Corporation
4 * This program is free software; you can redistribute it and/or modify
5 * it under the terms of the GNU General Public License version 2 as
6 * published by the Free Software Foundation.
10 * This file contains the low-level entry-points into the kernel, that is,
11 * exception handlers, debug trap handlers, interrupt handlers and the
12 * system call handler.
14 #include <linux/errno.h>
17 #include <asm/hardirq.h>
21 #include <asm/pgtable.h>
22 #include <asm/ptrace.h>
23 #include <asm/sysreg.h>
24 #include <asm/thread_info.h>
25 #include <asm/unistd.h>
28 # define preempt_stop mask_interrupts
31 # define fault_resume_kernel fault_restore_all
34 #define __MASK(x) ((1 << (x)) - 1)
35 #define IRQ_MASK ((__MASK(SOFTIRQ_BITS) << SOFTIRQ_SHIFT) | \
36 (__MASK(HARDIRQ_BITS) << HARDIRQ_SHIFT))
38 .section .ex.text,"ax",@progbits
45 bral do_bus_error_write
47 bral do_bus_error_read
51 bral handle_address_fault
53 bral handle_protection_fault
57 bral do_illegal_opcode_ll
59 bral do_illegal_opcode_ll
61 bral do_illegal_opcode_ll
65 bral do_illegal_opcode_ll
67 bral handle_address_fault
69 bral handle_address_fault
71 bral handle_protection_fault
73 bral handle_protection_fault
77 #define tlbmiss_save pushm r0-r3
78 #define tlbmiss_restore popm r0-r3
95 .global tlb_miss_common
98 mfsr r0, SYSREG_TLBEAR
102 * First level lookup: The PGD contains virtual pointers to
103 * the second-level page tables, but they may be NULL if not
107 lsr r2, r0, PGDIR_SHIFT
109 bfextu r1, r0, PAGE_SHIFT, PGDIR_SHIFT - PAGE_SHIFT
111 breq page_table_not_present
113 /* Second level lookup */
115 mfsr r0, SYSREG_TLBARLO
116 bld r2, _PAGE_BIT_PRESENT
117 brcc page_not_present
119 /* Mark the page as accessed */
120 sbr r2, _PAGE_BIT_ACCESSED
123 /* Drop software flags */
124 andl r2, _PAGE_FLAGS_HARDWARE_MASK & 0xffff
125 mtsr SYSREG_TLBELO, r2
127 /* Figure out which entry we want to replace */
128 mfsr r1, SYSREG_MMUCR
131 mov r3, -1 /* All entries have been accessed, */
132 mov r2, 0 /* so start at 0 */
133 mtsr SYSREG_TLBARLO, r3 /* and reset TLBAR */
135 1: bfins r1, r2, SYSREG_DRP_OFFSET, SYSREG_DRP_SIZE
136 mtsr SYSREG_MMUCR, r1
142 /* The slow path of the TLB miss handler */
144 page_table_not_present:
145 /* Do we need to synchronize with swapper_pg_dir? */
147 brcs sync_with_swapper_pg_dir
153 call save_full_context_ex
157 rjmp ret_from_exception
160 sync_with_swapper_pg_dir:
162 * If swapper_pg_dir contains a non-NULL second-level page
163 * table pointer, copy it into the current PGD. If not, we
164 * must handle it as a full-blown page fault.
166 * Jumping back to pgtbl_lookup causes an unnecessary lookup,
167 * but it is guaranteed to be a cache hit, it won't happen
168 * very often, and we absolutely do not want to sacrifice any
169 * performance in the fast path in order to improve this.
171 mov r1, lo(swapper_pg_dir)
172 orh r1, hi(swapper_pg_dir)
175 breq page_not_present
181 * We currently have two bytes left at this point until we
182 * crash into the system call handler...
184 * Don't worry, the assembler will let us know.
188 /* --- System Call --- */
192 #ifdef CONFIG_PREEMPT
195 pushm r12 /* r12_orig */
198 mfsr r0, SYSREG_RAR_SUP
199 mfsr r1, SYSREG_RSR_SUP
200 #ifdef CONFIG_PREEMPT
206 /* check for syscall tracing */
208 ld.w r1, r0[TI_flags]
209 bld r1, TIF_SYSCALL_TRACE
210 brcs syscall_trace_enter
216 lddpc lr, syscall_table_addr
218 mov r8, r5 /* 5th argument (6th is pushed by stub) */
221 .global syscall_return
224 mask_interrupts /* make sure we don't miss an interrupt
225 setting need_resched or sigpending
226 between sampling and the rets */
228 /* Store the return value so that the correct value is loaded below */
229 stdsp sp[REG_R12], r12
231 ld.w r1, r0[TI_flags]
232 andl r1, _TIF_ALLWORK_MASK, COH
233 brne syscall_exit_work
237 mtsr SYSREG_RAR_SUP, r8
238 mtsr SYSREG_RSR_SUP, r9
240 sub sp, -4 /* r12_orig */
251 .global ret_from_fork
255 /* check for syscall tracing */
257 ld.w r1, r0[TI_flags]
258 andl r1, _TIF_ALLWORK_MASK, COH
259 brne syscall_exit_work
260 rjmp syscall_exit_cont
266 rjmp syscall_trace_cont
269 bld r1, TIF_SYSCALL_TRACE
274 ld.w r1, r0[TI_flags]
276 1: bld r1, TIF_NEED_RESCHED
281 ld.w r1, r0[TI_flags]
284 2: mov r2, _TIF_SIGPENDING | _TIF_RESTORE_SIGMASK
290 call do_notify_resume
292 ld.w r1, r0[TI_flags]
295 3: bld r1, TIF_BREAKPOINT
296 brcc syscall_exit_cont
297 rjmp enter_monitor_mode
299 /* This function expects to find offending PC in SYSREG_RAR_EX */
300 .type save_full_context_ex, @function
302 save_full_context_ex:
303 mfsr r11, SYSREG_RAR_EX
304 sub r9, pc, . - debug_trampoline
305 mfsr r8, SYSREG_RSR_EX
309 andh r8, (MODE_MASK >> 16), COH
312 1: pushm r11, r12 /* PC and SR */
316 2: sub r10, sp, -(FRAME_SIZE_FULL - REG_LR)
317 stdsp sp[4], r10 /* replace saved SP */
321 * The debug handler set up a trampoline to make us
322 * automatically enter monitor mode upon return, but since
323 * we're saving the full context, we must assume that the
324 * exception handler might want to alter the return address
325 * and/or status register. So we need to restore the original
326 * context and enter monitor mode manually after the exception
329 3: get_thread_info r8
330 ld.w r11, r8[TI_rar_saved]
331 ld.w r12, r8[TI_rsr_saved]
333 .size save_full_context_ex, . - save_full_context_ex
335 /* Low-level exception handlers */
340 * After a Java stack overflow or underflow trap, any CPU
341 * memory access may cause erratic behavior. This will happen
342 * when the four least significant bits of the JOSP system
343 * register contains any value between 9 and 15 (inclusive).
345 * Possible workarounds:
346 * - Don't use the Java Extension Module
347 * - Ensure that the stack overflow and underflow trap
348 * handlers do not do any memory access or trigger any
349 * exceptions before the overflow/underflow condition is
350 * cleared (by incrementing or decrementing the JOSP)
351 * - Make sure that JOSP does not contain any problematic
352 * value before doing any exception or interrupt
354 * - Set up a critical exception handler which writes a
355 * known-to-be-safe value, e.g. 4, to JOSP before doing
356 * any further processing.
358 * We'll use the last workaround for now since we cannot
359 * guarantee that user space processes don't use Java mode.
360 * Non-well-behaving userland will be terminated with extreme
363 #ifdef CONFIG_CPU_AT32AP700X
365 * There's a chance we can't touch memory, so temporarily
366 * borrow PTBR to save the stack pointer while we fix things
375 /* Push most of pt_regs on stack. We'll do the rest later */
379 /* PTBR mirrors current_thread_info()->task->active_mm->pgd */
382 ld.w r2, r1[TSK_active_mm]
389 sub r0, sp, -(14 * 4)
391 mfsr r2, SYSREG_RAR_EX
392 mfsr r3, SYSREG_RSR_EX
397 call do_critical_exception
399 /* We should never get here... */
401 sub r12, pc, (. - 1f)
404 1: .asciz "Return from critical exception!"
410 call save_full_context_ex
417 call save_full_context_ex
419 1: mfsr r12, SYSREG_BEAR
422 rjmp ret_from_exception
428 mfsr r9, SYSREG_RSR_NMI
429 mfsr r8, SYSREG_RAR_NMI
430 bfextu r0, r9, MODE_SHIFT, 3
433 1: pushm r8, r9 /* PC and SR */
438 mtsr SYSREG_RAR_NMI, r8
440 mtsr SYSREG_RSR_NMI, r9
444 sub sp, -4 /* skip r12_orig */
447 2: sub r10, sp, -(FRAME_SIZE_FULL - REG_LR)
448 stdsp sp[4], r10 /* replace saved SP */
452 sub sp, -4 /* skip sp */
454 sub sp, -4 /* skip r12_orig */
457 handle_address_fault:
460 call save_full_context_ex
463 call do_address_exception
464 rjmp ret_from_exception
466 handle_protection_fault:
469 call save_full_context_ex
473 rjmp ret_from_exception
476 do_illegal_opcode_ll:
479 call save_full_context_ex
482 call do_illegal_opcode
483 rjmp ret_from_exception
487 mfsr r1, SYSREG_TLBEAR
489 lsr r2, r1, PGDIR_SHIFT
491 lsl r1, (32 - PGDIR_SHIFT)
492 lsr r1, (32 - PGDIR_SHIFT) + PAGE_SHIFT
494 /* Translate to virtual address in P1 */
499 sbr r3, _PAGE_BIT_DIRTY
503 /* The page table is up-to-date. Update the TLB entry as well */
504 andl r0, lo(_PAGE_FLAGS_HARDWARE_MASK)
505 mtsr SYSREG_TLBELO, r0
507 /* MMUCR[DRP] is updated automatically, so let's go... */
516 call save_full_context_ex
521 rjmp ret_from_exception
527 andh r4, (MODE_MASK >> 16), COH
528 brne fault_resume_kernel
531 ld.w r1, r0[TI_flags]
532 andl r1, _TIF_WORK_MASK, COH
538 mtsr SYSREG_RAR_EX, r8
539 mtsr SYSREG_RSR_EX, r9
545 #ifdef CONFIG_PREEMPT
547 ld.w r2, r0[TI_preempt_count]
550 ld.w r1, r0[TI_flags]
551 bld r1, TIF_NEED_RESCHED
554 bld r4, SYSREG_GM_OFFSET
556 call preempt_schedule_irq
563 mtsr SYSREG_RAR_EX, r8
564 mtsr SYSREG_RSR_EX, r9
566 sub sp, -4 /* ignore SP */
568 sub sp, -4 /* ignore r12_orig */
572 /* Switch to exception mode so that we can share the same code. */
574 cbr r8, SYSREG_M0_OFFSET
575 orh r8, hi(SYSREG_BIT(M1) | SYSREG_BIT(M2))
579 ld.w r1, r0[TI_flags]
582 bld r1, TIF_NEED_RESCHED
587 ld.w r1, r0[TI_flags]
590 1: mov r2, _TIF_SIGPENDING | _TIF_RESTORE_SIGMASK
596 call do_notify_resume
598 ld.w r1, r0[TI_flags]
601 2: bld r1, TIF_BREAKPOINT
602 brcc fault_resume_user
603 rjmp enter_monitor_mode
605 .section .kprobes.text, "ax", @progbits
606 .type handle_debug, @function
608 sub sp, 4 /* r12_orig */
610 mfsr r8, SYSREG_RAR_DBG
611 mfsr r9, SYSREG_RSR_DBG
614 bfextu r9, r9, SYSREG_MODE_OFFSET, SYSREG_MODE_SIZE
615 brne debug_fixup_regs
618 #ifdef CONFIG_TRACE_IRQFLAGS
619 call trace_hardirqs_off
626 bfextu r3, r2, SYSREG_MODE_OFFSET, SYSREG_MODE_SIZE
627 brne debug_resume_kernel
630 ld.w r1, r0[TI_flags]
631 mov r2, _TIF_DBGWORK_MASK
635 bld r1, TIF_SINGLE_STEP
638 sbr r4, OCD_DC_SS_BIT
643 mtsr SYSREG_RSR_DBG, r11
644 mtsr SYSREG_RAR_DBG, r10
645 #ifdef CONFIG_TRACE_IRQFLAGS
646 call trace_hardirqs_on
652 .size handle_debug, . - handle_debug
654 /* Mode of the trapped context is in r9 */
655 .type debug_fixup_regs, @function
659 bfins r8, r9, SYSREG_MODE_OFFSET, SYSREG_MODE_SIZE
665 sub r8, sp, -FRAME_SIZE_FULL
667 rjmp .Ldebug_fixup_cont
668 .size debug_fixup_regs, . - debug_fixup_regs
670 .type debug_resume_kernel, @function
674 mtsr SYSREG_RAR_DBG, r10
675 mtsr SYSREG_RSR_DBG, r11
676 #ifdef CONFIG_TRACE_IRQFLAGS
677 bld r11, SYSREG_GM_OFFSET
679 call trace_hardirqs_on
684 bfins r2, r3, SYSREG_MODE_OFFSET, SYSREG_MODE_SIZE
690 sub sp, -4 /* skip SP */
694 .size debug_resume_kernel, . - debug_resume_kernel
696 .type debug_exit_work, @function
699 * We must return from Monitor Mode using a retd, and we must
700 * not schedule since that involves the D bit in SR getting
701 * cleared by something other than the debug hardware. This
702 * may cause undefined behaviour according to the Architecture
705 * So we fix up the return address and status and return to a
706 * stub below in Exception mode. From there, we can follow the
707 * normal exception return path.
709 * The real return address and status registers are stored on
710 * the stack in the way the exception return path understands,
711 * so no need to fix anything up there.
713 sub r8, pc, . - fault_exit_work
714 mtsr SYSREG_RAR_DBG, r8
716 orh r9, hi(SR_EM | SR_GM | MODE_EXCEPTION)
717 mtsr SYSREG_RSR_DBG, r9
720 .size debug_exit_work, . - debug_exit_work
722 .set rsr_int0, SYSREG_RSR_INT0
723 .set rsr_int1, SYSREG_RSR_INT1
724 .set rsr_int2, SYSREG_RSR_INT2
725 .set rsr_int3, SYSREG_RSR_INT3
726 .set rar_int0, SYSREG_RAR_INT0
727 .set rar_int1, SYSREG_RAR_INT1
728 .set rar_int2, SYSREG_RAR_INT2
729 .set rar_int3, SYSREG_RAR_INT3
731 .macro IRQ_LEVEL level
732 .type irq_level\level, @function
734 sub sp, 4 /* r12_orig */
736 mfsr r8, rar_int\level
737 mfsr r9, rsr_int\level
739 #ifdef CONFIG_PREEMPT
740 sub r11, pc, (. - system_call)
753 bfextu r4, r4, SYSREG_M0_OFFSET, 3
754 cp.w r4, MODE_SUPERVISOR >> SYSREG_M0_OFFSET
756 cp.w r4, MODE_USER >> SYSREG_M0_OFFSET
757 #ifdef CONFIG_PREEMPT
764 ld.w r1, r0[TI_flags]
765 andl r1, _TIF_WORK_MASK, COH
769 #ifdef CONFIG_TRACE_IRQFLAGS
770 call trace_hardirqs_on
773 mtsr rar_int\level, r8
774 mtsr rsr_int\level, r9
776 sub sp, -4 /* ignore r12_orig */
779 #ifdef CONFIG_PREEMPT
781 mfsr r8, rsr_int\level
783 mtsr rsr_int\level, r8
785 sub sp, -4 /* ignore r12_orig */
789 2: get_thread_info r0
790 ld.w r1, r0[TI_flags]
791 bld r1, TIF_CPU_GOING_TO_SLEEP
792 #ifdef CONFIG_PREEMPT
797 sub r1, pc, . - cpu_idle_skip_sleep
799 #ifdef CONFIG_PREEMPT
800 3: get_thread_info r0
801 ld.w r2, r0[TI_preempt_count]
804 ld.w r1, r0[TI_flags]
805 bld r1, TIF_NEED_RESCHED
808 bld r4, SYSREG_GM_OFFSET
810 call preempt_schedule_irq
815 .section .irq.text,"ax",@progbits
826 .section .kprobes.text, "ax", @progbits
827 .type enter_monitor_mode, @function
830 * We need to enter monitor mode to do a single step. The
831 * monitor code will alter the return address so that we
832 * return directly to the user instead of returning here.
835 rjmp breakpoint_failed
837 .size enter_monitor_mode, . - enter_monitor_mode
839 .type debug_trampoline, @function
840 .global debug_trampoline
843 * Save the registers on the stack so that the monitor code
844 * can find them easily.
846 sub sp, 4 /* r12_orig */
849 ld.w r8, r0[TI_rar_saved]
850 ld.w r9, r0[TI_rsr_saved]
854 * The monitor code will alter the return address so we don't
858 rjmp breakpoint_failed
859 .size debug_trampoline, . - debug_trampoline
861 .type breakpoint_failed, @function
864 * Something went wrong. Perhaps the debug hardware isn't
867 lda.w r12, msg_breakpoint_failed
869 mov r10, 9 /* SIGKILL */
873 msg_breakpoint_failed:
874 .asciz "Failed to enter Debug Mode"