2 * BTS PMU driver for perf
3 * Copyright (c) 2013-2014, Intel Corporation.
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms and conditions of the GNU General Public License,
7 * version 2, as published by the Free Software Foundation.
9 * This program is distributed in the hope it will be useful, but WITHOUT
10 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
11 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
17 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
19 #include <linux/bitops.h>
20 #include <linux/types.h>
21 #include <linux/slab.h>
22 #include <linux/debugfs.h>
23 #include <linux/device.h>
24 #include <linux/coredump.h>
25 #include <linux/kaiser.h>
27 #include <asm-generic/sizes.h>
28 #include <asm/perf_event.h>
30 #include "perf_event.h"
33 struct perf_output_handle handle;
34 struct debug_store ds_back;
38 static DEFINE_PER_CPU(struct bts_ctx, bts_ctx);
40 #define BTS_RECORD_SIZE 24
41 #define BTS_SAFETY_MARGIN 4080
47 unsigned long displacement;
51 size_t real_size; /* multiple of BTS_RECORD_SIZE */
52 unsigned int nr_pages;
61 struct bts_phys buf[0];
66 static size_t buf_size(struct page *page)
68 return 1 << (PAGE_SHIFT + page_private(page));
71 static void bts_buffer_free_aux(void *data)
73 #ifdef CONFIG_PAGE_TABLE_ISOLATION
74 struct bts_buffer *buf = data;
77 for (nbuf = 0; nbuf < buf->nr_bufs; nbuf++) {
78 struct page *page = buf->buf[nbuf].page;
79 void *kaddr = page_address(page);
80 size_t page_size = buf_size(page);
82 kaiser_remove_mapping((unsigned long)kaddr, page_size);
89 bts_buffer_setup_aux(int cpu, void **pages, int nr_pages, bool overwrite)
91 struct bts_buffer *buf;
93 int node = (cpu == -1) ? cpu : cpu_to_node(cpu);
95 size_t size = nr_pages << PAGE_SHIFT;
98 /* count all the high order buffers */
99 for (pg = 0, nbuf = 0; pg < nr_pages;) {
100 page = virt_to_page(pages[pg]);
101 if (WARN_ON_ONCE(!PagePrivate(page) && nr_pages > 1))
103 pg += 1 << page_private(page);
108 * to avoid interrupts in overwrite mode, only allow one physical
110 if (overwrite && nbuf > 1)
113 buf = kzalloc_node(offsetof(struct bts_buffer, buf[nbuf]), GFP_KERNEL, node);
117 buf->nr_pages = nr_pages;
119 buf->snapshot = overwrite;
120 buf->data_pages = pages;
121 buf->real_size = size - size % BTS_RECORD_SIZE;
123 for (pg = 0, nbuf = 0, offset = 0, pad = 0; nbuf < buf->nr_bufs; nbuf++) {
124 void *kaddr = pages[pg];
127 page = virt_to_page(kaddr);
128 page_size = buf_size(page);
130 if (kaiser_add_mapping((unsigned long)kaddr,
131 page_size, __PAGE_KERNEL) < 0) {
133 bts_buffer_free_aux(buf);
137 buf->buf[nbuf].page = page;
138 buf->buf[nbuf].offset = offset;
139 buf->buf[nbuf].displacement = (pad ? BTS_RECORD_SIZE - pad : 0);
140 buf->buf[nbuf].size = page_size - buf->buf[nbuf].displacement;
141 pad = buf->buf[nbuf].size % BTS_RECORD_SIZE;
142 buf->buf[nbuf].size -= pad;
144 pg += page_size >> PAGE_SHIFT;
151 static unsigned long bts_buffer_offset(struct bts_buffer *buf, unsigned int idx)
153 return buf->buf[idx].offset + buf->buf[idx].displacement;
157 bts_config_buffer(struct bts_buffer *buf)
159 int cpu = raw_smp_processor_id();
160 struct debug_store *ds = per_cpu(cpu_hw_events, cpu).ds;
161 struct bts_phys *phys = &buf->buf[buf->cur_buf];
162 unsigned long index, thresh = 0, end = phys->size;
163 struct page *page = phys->page;
165 index = local_read(&buf->head);
167 if (!buf->snapshot) {
168 if (buf->end < phys->offset + buf_size(page))
169 end = buf->end - phys->offset - phys->displacement;
171 index -= phys->offset + phys->displacement;
173 if (end - index > BTS_SAFETY_MARGIN)
174 thresh = end - BTS_SAFETY_MARGIN;
175 else if (end - index > BTS_RECORD_SIZE)
176 thresh = end - BTS_RECORD_SIZE;
181 ds->bts_buffer_base = (u64)(long)page_address(page) + phys->displacement;
182 ds->bts_index = ds->bts_buffer_base + index;
183 ds->bts_absolute_maximum = ds->bts_buffer_base + end;
184 ds->bts_interrupt_threshold = !buf->snapshot
185 ? ds->bts_buffer_base + thresh
186 : ds->bts_absolute_maximum + BTS_RECORD_SIZE;
189 static void bts_buffer_pad_out(struct bts_phys *phys, unsigned long head)
191 unsigned long index = head - phys->offset;
193 memset(page_address(phys->page) + index, 0, phys->size - index);
196 static bool bts_buffer_is_full(struct bts_buffer *buf, struct bts_ctx *bts)
201 if (local_read(&buf->data_size) >= bts->handle.size ||
202 bts->handle.size - local_read(&buf->data_size) < BTS_RECORD_SIZE)
208 static void bts_update(struct bts_ctx *bts)
210 int cpu = raw_smp_processor_id();
211 struct debug_store *ds = per_cpu(cpu_hw_events, cpu).ds;
212 struct bts_buffer *buf = perf_get_aux(&bts->handle);
213 unsigned long index = ds->bts_index - ds->bts_buffer_base, old, head;
218 head = index + bts_buffer_offset(buf, buf->cur_buf);
219 old = local_xchg(&buf->head, head);
221 if (!buf->snapshot) {
225 if (ds->bts_index >= ds->bts_absolute_maximum)
226 local_inc(&buf->lost);
229 * old and head are always in the same physical buffer, so we
230 * can subtract them to get the data size.
232 local_add(head - old, &buf->data_size);
234 local_set(&buf->data_size, head);
238 static void __bts_event_start(struct perf_event *event)
240 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
241 struct bts_buffer *buf = perf_get_aux(&bts->handle);
244 if (!buf || bts_buffer_is_full(buf, bts))
247 event->hw.itrace_started = 1;
251 config |= ARCH_PERFMON_EVENTSEL_INT;
252 if (!event->attr.exclude_kernel)
253 config |= ARCH_PERFMON_EVENTSEL_OS;
254 if (!event->attr.exclude_user)
255 config |= ARCH_PERFMON_EVENTSEL_USR;
257 bts_config_buffer(buf);
260 * local barrier to make sure that ds configuration made it
261 * before we enable BTS
265 intel_pmu_enable_bts(config);
268 static void bts_event_start(struct perf_event *event, int flags)
270 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
272 __bts_event_start(event);
274 /* PMI handler: this counter is running and likely generating PMIs */
275 ACCESS_ONCE(bts->started) = 1;
278 static void __bts_event_stop(struct perf_event *event)
281 * No extra synchronization is mandated by the documentation to have
282 * BTS data stores globally visible.
284 intel_pmu_disable_bts();
286 if (event->hw.state & PERF_HES_STOPPED)
289 ACCESS_ONCE(event->hw.state) |= PERF_HES_STOPPED;
292 static void bts_event_stop(struct perf_event *event, int flags)
294 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
296 /* PMI handler: don't restart this counter */
297 ACCESS_ONCE(bts->started) = 0;
299 __bts_event_stop(event);
301 if (flags & PERF_EF_UPDATE)
305 void intel_bts_enable_local(void)
307 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
309 if (bts->handle.event && bts->started)
310 __bts_event_start(bts->handle.event);
313 void intel_bts_disable_local(void)
315 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
317 if (bts->handle.event)
318 __bts_event_stop(bts->handle.event);
322 bts_buffer_reset(struct bts_buffer *buf, struct perf_output_handle *handle)
324 unsigned long head, space, next_space, pad, gap, skip, wakeup;
325 unsigned int next_buf;
326 struct bts_phys *phys, *next_phys;
332 head = handle->head & ((buf->nr_pages << PAGE_SHIFT) - 1);
333 if (WARN_ON_ONCE(head != local_read(&buf->head)))
336 phys = &buf->buf[buf->cur_buf];
337 space = phys->offset + phys->displacement + phys->size - head;
339 if (space > handle->size) {
340 space = handle->size;
341 space -= space % BTS_RECORD_SIZE;
343 if (space <= BTS_SAFETY_MARGIN) {
344 /* See if next phys buffer has more space */
345 next_buf = buf->cur_buf + 1;
346 if (next_buf >= buf->nr_bufs)
348 next_phys = &buf->buf[next_buf];
349 gap = buf_size(phys->page) - phys->displacement - phys->size +
350 next_phys->displacement;
352 if (handle->size >= skip) {
353 next_space = next_phys->size;
354 if (next_space + skip > handle->size) {
355 next_space = handle->size - skip;
356 next_space -= next_space % BTS_RECORD_SIZE;
358 if (next_space > space || !space) {
360 bts_buffer_pad_out(phys, head);
361 ret = perf_aux_output_skip(handle, skip);
364 /* Advance to next phys buffer */
367 head = phys->offset + phys->displacement;
369 * After this, cur_buf and head won't match ds
370 * anymore, so we must not be racing with
373 buf->cur_buf = next_buf;
374 local_set(&buf->head, head);
379 /* Don't go far beyond wakeup watermark */
380 wakeup = BTS_SAFETY_MARGIN + BTS_RECORD_SIZE + handle->wakeup -
382 if (space > wakeup) {
384 space -= space % BTS_RECORD_SIZE;
387 buf->end = head + space;
390 * If we have no space, the lost notification would have been sent when
391 * we hit absolute_maximum - see bts_update()
399 int intel_bts_interrupt(void)
401 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
402 struct perf_event *event = bts->handle.event;
403 struct bts_buffer *buf;
407 if (!event || !bts->started)
410 buf = perf_get_aux(&bts->handle);
412 * Skip snapshot counters: they don't use the interrupt, but
413 * there's no other way of telling, because the pointer will
416 if (!buf || buf->snapshot)
419 old_head = local_read(&buf->head);
423 if (old_head == local_read(&buf->head))
426 perf_aux_output_end(&bts->handle, local_xchg(&buf->data_size, 0),
427 !!local_xchg(&buf->lost, 0));
429 buf = perf_aux_output_begin(&bts->handle, event);
433 err = bts_buffer_reset(buf, &bts->handle);
435 perf_aux_output_end(&bts->handle, 0, false);
440 static void bts_event_del(struct perf_event *event, int mode)
442 struct cpu_hw_events *cpuc = this_cpu_ptr(&cpu_hw_events);
443 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
444 struct bts_buffer *buf = perf_get_aux(&bts->handle);
446 bts_event_stop(event, PERF_EF_UPDATE);
451 local_xchg(&buf->data_size,
452 buf->nr_pages << PAGE_SHIFT);
453 perf_aux_output_end(&bts->handle, local_xchg(&buf->data_size, 0),
454 !!local_xchg(&buf->lost, 0));
457 cpuc->ds->bts_index = bts->ds_back.bts_buffer_base;
458 cpuc->ds->bts_buffer_base = bts->ds_back.bts_buffer_base;
459 cpuc->ds->bts_absolute_maximum = bts->ds_back.bts_absolute_maximum;
460 cpuc->ds->bts_interrupt_threshold = bts->ds_back.bts_interrupt_threshold;
463 static int bts_event_add(struct perf_event *event, int mode)
465 struct bts_buffer *buf;
466 struct bts_ctx *bts = this_cpu_ptr(&bts_ctx);
467 struct cpu_hw_events *cpuc = this_cpu_ptr(&cpu_hw_events);
468 struct hw_perf_event *hwc = &event->hw;
471 event->hw.state = PERF_HES_STOPPED;
473 if (test_bit(INTEL_PMC_IDX_FIXED_BTS, cpuc->active_mask))
476 if (bts->handle.event)
479 buf = perf_aux_output_begin(&bts->handle, event);
483 ret = bts_buffer_reset(buf, &bts->handle);
485 perf_aux_output_end(&bts->handle, 0, false);
489 bts->ds_back.bts_buffer_base = cpuc->ds->bts_buffer_base;
490 bts->ds_back.bts_absolute_maximum = cpuc->ds->bts_absolute_maximum;
491 bts->ds_back.bts_interrupt_threshold = cpuc->ds->bts_interrupt_threshold;
493 if (mode & PERF_EF_START) {
494 bts_event_start(event, 0);
495 if (hwc->state & PERF_HES_STOPPED) {
496 bts_event_del(event, 0);
504 static void bts_event_destroy(struct perf_event *event)
506 x86_release_hardware();
507 x86_del_exclusive(x86_lbr_exclusive_bts);
510 static int bts_event_init(struct perf_event *event)
514 if (event->attr.type != bts_pmu.type)
517 if (x86_add_exclusive(x86_lbr_exclusive_bts))
521 * BTS leaks kernel addresses even when CPL0 tracing is
522 * disabled, so disallow intel_bts driver for unprivileged
523 * users on paranoid systems since it provides trace data
524 * to the user in a zero-copy fashion.
526 * Note that the default paranoia setting permits unprivileged
527 * users to profile the kernel.
529 if (event->attr.exclude_kernel && perf_paranoid_kernel() &&
530 !capable(CAP_SYS_ADMIN))
533 ret = x86_reserve_hardware();
535 x86_del_exclusive(x86_lbr_exclusive_bts);
539 event->destroy = bts_event_destroy;
544 static void bts_event_read(struct perf_event *event)
548 static __init int bts_init(void)
550 if (!boot_cpu_has(X86_FEATURE_DTES64) || !x86_pmu.bts)
553 bts_pmu.capabilities = PERF_PMU_CAP_AUX_NO_SG | PERF_PMU_CAP_ITRACE;
554 bts_pmu.task_ctx_nr = perf_sw_context;
555 bts_pmu.event_init = bts_event_init;
556 bts_pmu.add = bts_event_add;
557 bts_pmu.del = bts_event_del;
558 bts_pmu.start = bts_event_start;
559 bts_pmu.stop = bts_event_stop;
560 bts_pmu.read = bts_event_read;
561 bts_pmu.setup_aux = bts_buffer_setup_aux;
562 bts_pmu.free_aux = bts_buffer_free_aux;
564 return perf_pmu_register(&bts_pmu, "intel_bts", -1);
566 arch_initcall(bts_init);