KVM: s390: avoid memory overwrites on emergency signal injection
[firefly-linux-kernel-4.4.55.git] / arch / s390 / kvm / interrupt.c
1 /*
2  * handling kvm guest interrupts
3  *
4  * Copyright IBM Corp. 2008, 2015
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License (version 2 only)
8  * as published by the Free Software Foundation.
9  *
10  *    Author(s): Carsten Otte <cotte@de.ibm.com>
11  */
12
13 #include <linux/interrupt.h>
14 #include <linux/kvm_host.h>
15 #include <linux/hrtimer.h>
16 #include <linux/mmu_context.h>
17 #include <linux/signal.h>
18 #include <linux/slab.h>
19 #include <linux/bitmap.h>
20 #include <linux/vmalloc.h>
21 #include <asm/asm-offsets.h>
22 #include <asm/dis.h>
23 #include <asm/uaccess.h>
24 #include <asm/sclp.h>
25 #include <asm/isc.h>
26 #include "kvm-s390.h"
27 #include "gaccess.h"
28 #include "trace-s390.h"
29
30 #define IOINT_SCHID_MASK 0x0000ffff
31 #define IOINT_SSID_MASK 0x00030000
32 #define IOINT_CSSID_MASK 0x03fc0000
33 #define PFAULT_INIT 0x0600
34 #define PFAULT_DONE 0x0680
35 #define VIRTIO_PARAM 0x0d00
36
37 int psw_extint_disabled(struct kvm_vcpu *vcpu)
38 {
39         return !(vcpu->arch.sie_block->gpsw.mask & PSW_MASK_EXT);
40 }
41
42 static int psw_ioint_disabled(struct kvm_vcpu *vcpu)
43 {
44         return !(vcpu->arch.sie_block->gpsw.mask & PSW_MASK_IO);
45 }
46
47 static int psw_mchk_disabled(struct kvm_vcpu *vcpu)
48 {
49         return !(vcpu->arch.sie_block->gpsw.mask & PSW_MASK_MCHECK);
50 }
51
52 static int psw_interrupts_disabled(struct kvm_vcpu *vcpu)
53 {
54         return psw_extint_disabled(vcpu) &&
55                psw_ioint_disabled(vcpu) &&
56                psw_mchk_disabled(vcpu);
57 }
58
59 static int ckc_interrupts_enabled(struct kvm_vcpu *vcpu)
60 {
61         if (psw_extint_disabled(vcpu) ||
62             !(vcpu->arch.sie_block->gcr[0] & 0x800ul))
63                 return 0;
64         if (guestdbg_enabled(vcpu) && guestdbg_sstep_enabled(vcpu))
65                 /* No timer interrupts when single stepping */
66                 return 0;
67         return 1;
68 }
69
70 static int ckc_irq_pending(struct kvm_vcpu *vcpu)
71 {
72         if (vcpu->arch.sie_block->ckc >= kvm_s390_get_tod_clock_fast(vcpu->kvm))
73                 return 0;
74         return ckc_interrupts_enabled(vcpu);
75 }
76
77 static int cpu_timer_interrupts_enabled(struct kvm_vcpu *vcpu)
78 {
79         return !psw_extint_disabled(vcpu) &&
80                (vcpu->arch.sie_block->gcr[0] & 0x400ul);
81 }
82
83 static int cpu_timer_irq_pending(struct kvm_vcpu *vcpu)
84 {
85         return (vcpu->arch.sie_block->cputm >> 63) &&
86                cpu_timer_interrupts_enabled(vcpu);
87 }
88
89 static inline int is_ioirq(unsigned long irq_type)
90 {
91         return ((irq_type >= IRQ_PEND_IO_ISC_0) &&
92                 (irq_type <= IRQ_PEND_IO_ISC_7));
93 }
94
95 static uint64_t isc_to_isc_bits(int isc)
96 {
97         return (0x80 >> isc) << 24;
98 }
99
100 static inline u8 int_word_to_isc(u32 int_word)
101 {
102         return (int_word & 0x38000000) >> 27;
103 }
104
105 static inline unsigned long pending_irqs(struct kvm_vcpu *vcpu)
106 {
107         return vcpu->kvm->arch.float_int.pending_irqs |
108                vcpu->arch.local_int.pending_irqs;
109 }
110
111 static unsigned long disable_iscs(struct kvm_vcpu *vcpu,
112                                    unsigned long active_mask)
113 {
114         int i;
115
116         for (i = 0; i <= MAX_ISC; i++)
117                 if (!(vcpu->arch.sie_block->gcr[6] & isc_to_isc_bits(i)))
118                         active_mask &= ~(1UL << (IRQ_PEND_IO_ISC_0 + i));
119
120         return active_mask;
121 }
122
123 static unsigned long deliverable_irqs(struct kvm_vcpu *vcpu)
124 {
125         unsigned long active_mask;
126
127         active_mask = pending_irqs(vcpu);
128         if (!active_mask)
129                 return 0;
130
131         if (psw_extint_disabled(vcpu))
132                 active_mask &= ~IRQ_PEND_EXT_MASK;
133         if (psw_ioint_disabled(vcpu))
134                 active_mask &= ~IRQ_PEND_IO_MASK;
135         else
136                 active_mask = disable_iscs(vcpu, active_mask);
137         if (!(vcpu->arch.sie_block->gcr[0] & 0x2000ul))
138                 __clear_bit(IRQ_PEND_EXT_EXTERNAL, &active_mask);
139         if (!(vcpu->arch.sie_block->gcr[0] & 0x4000ul))
140                 __clear_bit(IRQ_PEND_EXT_EMERGENCY, &active_mask);
141         if (!(vcpu->arch.sie_block->gcr[0] & 0x800ul))
142                 __clear_bit(IRQ_PEND_EXT_CLOCK_COMP, &active_mask);
143         if (!(vcpu->arch.sie_block->gcr[0] & 0x400ul))
144                 __clear_bit(IRQ_PEND_EXT_CPU_TIMER, &active_mask);
145         if (!(vcpu->arch.sie_block->gcr[0] & 0x200ul))
146                 __clear_bit(IRQ_PEND_EXT_SERVICE, &active_mask);
147         if (psw_mchk_disabled(vcpu))
148                 active_mask &= ~IRQ_PEND_MCHK_MASK;
149         if (!(vcpu->arch.sie_block->gcr[14] &
150               vcpu->kvm->arch.float_int.mchk.cr14))
151                 __clear_bit(IRQ_PEND_MCHK_REP, &active_mask);
152
153         /*
154          * STOP irqs will never be actively delivered. They are triggered via
155          * intercept requests and cleared when the stop intercept is performed.
156          */
157         __clear_bit(IRQ_PEND_SIGP_STOP, &active_mask);
158
159         return active_mask;
160 }
161
162 static void __set_cpu_idle(struct kvm_vcpu *vcpu)
163 {
164         atomic_or(CPUSTAT_WAIT, &vcpu->arch.sie_block->cpuflags);
165         set_bit(vcpu->vcpu_id, vcpu->arch.local_int.float_int->idle_mask);
166 }
167
168 static void __unset_cpu_idle(struct kvm_vcpu *vcpu)
169 {
170         atomic_andnot(CPUSTAT_WAIT, &vcpu->arch.sie_block->cpuflags);
171         clear_bit(vcpu->vcpu_id, vcpu->arch.local_int.float_int->idle_mask);
172 }
173
174 static void __reset_intercept_indicators(struct kvm_vcpu *vcpu)
175 {
176         atomic_andnot(CPUSTAT_IO_INT | CPUSTAT_EXT_INT | CPUSTAT_STOP_INT,
177                     &vcpu->arch.sie_block->cpuflags);
178         vcpu->arch.sie_block->lctl = 0x0000;
179         vcpu->arch.sie_block->ictl &= ~(ICTL_LPSW | ICTL_STCTL | ICTL_PINT);
180
181         if (guestdbg_enabled(vcpu)) {
182                 vcpu->arch.sie_block->lctl |= (LCTL_CR0 | LCTL_CR9 |
183                                                LCTL_CR10 | LCTL_CR11);
184                 vcpu->arch.sie_block->ictl |= (ICTL_STCTL | ICTL_PINT);
185         }
186 }
187
188 static void __set_cpuflag(struct kvm_vcpu *vcpu, u32 flag)
189 {
190         atomic_or(flag, &vcpu->arch.sie_block->cpuflags);
191 }
192
193 static void set_intercept_indicators_io(struct kvm_vcpu *vcpu)
194 {
195         if (!(pending_irqs(vcpu) & IRQ_PEND_IO_MASK))
196                 return;
197         else if (psw_ioint_disabled(vcpu))
198                 __set_cpuflag(vcpu, CPUSTAT_IO_INT);
199         else
200                 vcpu->arch.sie_block->lctl |= LCTL_CR6;
201 }
202
203 static void set_intercept_indicators_ext(struct kvm_vcpu *vcpu)
204 {
205         if (!(pending_irqs(vcpu) & IRQ_PEND_EXT_MASK))
206                 return;
207         if (psw_extint_disabled(vcpu))
208                 __set_cpuflag(vcpu, CPUSTAT_EXT_INT);
209         else
210                 vcpu->arch.sie_block->lctl |= LCTL_CR0;
211 }
212
213 static void set_intercept_indicators_mchk(struct kvm_vcpu *vcpu)
214 {
215         if (!(pending_irqs(vcpu) & IRQ_PEND_MCHK_MASK))
216                 return;
217         if (psw_mchk_disabled(vcpu))
218                 vcpu->arch.sie_block->ictl |= ICTL_LPSW;
219         else
220                 vcpu->arch.sie_block->lctl |= LCTL_CR14;
221 }
222
223 static void set_intercept_indicators_stop(struct kvm_vcpu *vcpu)
224 {
225         if (kvm_s390_is_stop_irq_pending(vcpu))
226                 __set_cpuflag(vcpu, CPUSTAT_STOP_INT);
227 }
228
229 /* Set interception request for non-deliverable interrupts */
230 static void set_intercept_indicators(struct kvm_vcpu *vcpu)
231 {
232         set_intercept_indicators_io(vcpu);
233         set_intercept_indicators_ext(vcpu);
234         set_intercept_indicators_mchk(vcpu);
235         set_intercept_indicators_stop(vcpu);
236 }
237
238 static u16 get_ilc(struct kvm_vcpu *vcpu)
239 {
240         switch (vcpu->arch.sie_block->icptcode) {
241         case ICPT_INST:
242         case ICPT_INSTPROGI:
243         case ICPT_OPEREXC:
244         case ICPT_PARTEXEC:
245         case ICPT_IOINST:
246                 /* last instruction only stored for these icptcodes */
247                 return insn_length(vcpu->arch.sie_block->ipa >> 8);
248         case ICPT_PROGI:
249                 return vcpu->arch.sie_block->pgmilc;
250         default:
251                 return 0;
252         }
253 }
254
255 static int __must_check __deliver_cpu_timer(struct kvm_vcpu *vcpu)
256 {
257         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
258         int rc;
259
260         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_INT_CPU_TIMER,
261                                          0, 0);
262
263         rc  = put_guest_lc(vcpu, EXT_IRQ_CPU_TIMER,
264                            (u16 *)__LC_EXT_INT_CODE);
265         rc |= put_guest_lc(vcpu, 0, (u16 *)__LC_EXT_CPU_ADDR);
266         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
267                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
268         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
269                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
270         clear_bit(IRQ_PEND_EXT_CPU_TIMER, &li->pending_irqs);
271         return rc ? -EFAULT : 0;
272 }
273
274 static int __must_check __deliver_ckc(struct kvm_vcpu *vcpu)
275 {
276         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
277         int rc;
278
279         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_INT_CLOCK_COMP,
280                                          0, 0);
281
282         rc  = put_guest_lc(vcpu, EXT_IRQ_CLK_COMP,
283                            (u16 __user *)__LC_EXT_INT_CODE);
284         rc |= put_guest_lc(vcpu, 0, (u16 *)__LC_EXT_CPU_ADDR);
285         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
286                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
287         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
288                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
289         clear_bit(IRQ_PEND_EXT_CLOCK_COMP, &li->pending_irqs);
290         return rc ? -EFAULT : 0;
291 }
292
293 static int __must_check __deliver_pfault_init(struct kvm_vcpu *vcpu)
294 {
295         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
296         struct kvm_s390_ext_info ext;
297         int rc;
298
299         spin_lock(&li->lock);
300         ext = li->irq.ext;
301         clear_bit(IRQ_PEND_PFAULT_INIT, &li->pending_irqs);
302         li->irq.ext.ext_params2 = 0;
303         spin_unlock(&li->lock);
304
305         VCPU_EVENT(vcpu, 4, "deliver: pfault init token 0x%llx",
306                    ext.ext_params2);
307         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
308                                          KVM_S390_INT_PFAULT_INIT,
309                                          0, ext.ext_params2);
310
311         rc  = put_guest_lc(vcpu, EXT_IRQ_CP_SERVICE, (u16 *) __LC_EXT_INT_CODE);
312         rc |= put_guest_lc(vcpu, PFAULT_INIT, (u16 *) __LC_EXT_CPU_ADDR);
313         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
314                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
315         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
316                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
317         rc |= put_guest_lc(vcpu, ext.ext_params2, (u64 *) __LC_EXT_PARAMS2);
318         return rc ? -EFAULT : 0;
319 }
320
321 static int __must_check __deliver_machine_check(struct kvm_vcpu *vcpu)
322 {
323         struct kvm_s390_float_interrupt *fi = &vcpu->kvm->arch.float_int;
324         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
325         struct kvm_s390_mchk_info mchk = {};
326         unsigned long adtl_status_addr;
327         int deliver = 0;
328         int rc = 0;
329
330         spin_lock(&fi->lock);
331         spin_lock(&li->lock);
332         if (test_bit(IRQ_PEND_MCHK_EX, &li->pending_irqs) ||
333             test_bit(IRQ_PEND_MCHK_REP, &li->pending_irqs)) {
334                 /*
335                  * If there was an exigent machine check pending, then any
336                  * repressible machine checks that might have been pending
337                  * are indicated along with it, so always clear bits for
338                  * repressible and exigent interrupts
339                  */
340                 mchk = li->irq.mchk;
341                 clear_bit(IRQ_PEND_MCHK_EX, &li->pending_irqs);
342                 clear_bit(IRQ_PEND_MCHK_REP, &li->pending_irqs);
343                 memset(&li->irq.mchk, 0, sizeof(mchk));
344                 deliver = 1;
345         }
346         /*
347          * We indicate floating repressible conditions along with
348          * other pending conditions. Channel Report Pending and Channel
349          * Subsystem damage are the only two and and are indicated by
350          * bits in mcic and masked in cr14.
351          */
352         if (test_and_clear_bit(IRQ_PEND_MCHK_REP, &fi->pending_irqs)) {
353                 mchk.mcic |= fi->mchk.mcic;
354                 mchk.cr14 |= fi->mchk.cr14;
355                 memset(&fi->mchk, 0, sizeof(mchk));
356                 deliver = 1;
357         }
358         spin_unlock(&li->lock);
359         spin_unlock(&fi->lock);
360
361         if (deliver) {
362                 VCPU_EVENT(vcpu, 3, "deliver: machine check mcic 0x%llx",
363                            mchk.mcic);
364                 trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
365                                                  KVM_S390_MCHK,
366                                                  mchk.cr14, mchk.mcic);
367
368                 rc  = kvm_s390_vcpu_store_status(vcpu,
369                                                  KVM_S390_STORE_STATUS_PREFIXED);
370                 rc |= read_guest_lc(vcpu, __LC_VX_SAVE_AREA_ADDR,
371                                     &adtl_status_addr,
372                                     sizeof(unsigned long));
373                 rc |= kvm_s390_vcpu_store_adtl_status(vcpu,
374                                                       adtl_status_addr);
375                 rc |= put_guest_lc(vcpu, mchk.mcic,
376                                    (u64 __user *) __LC_MCCK_CODE);
377                 rc |= put_guest_lc(vcpu, mchk.failing_storage_address,
378                                    (u64 __user *) __LC_MCCK_FAIL_STOR_ADDR);
379                 rc |= write_guest_lc(vcpu, __LC_PSW_SAVE_AREA,
380                                      &mchk.fixed_logout,
381                                      sizeof(mchk.fixed_logout));
382                 rc |= write_guest_lc(vcpu, __LC_MCK_OLD_PSW,
383                                      &vcpu->arch.sie_block->gpsw,
384                                      sizeof(psw_t));
385                 rc |= read_guest_lc(vcpu, __LC_MCK_NEW_PSW,
386                                     &vcpu->arch.sie_block->gpsw,
387                                     sizeof(psw_t));
388         }
389         return rc ? -EFAULT : 0;
390 }
391
392 static int __must_check __deliver_restart(struct kvm_vcpu *vcpu)
393 {
394         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
395         int rc;
396
397         VCPU_EVENT(vcpu, 3, "%s", "deliver: cpu restart");
398         vcpu->stat.deliver_restart_signal++;
399         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_RESTART, 0, 0);
400
401         rc  = write_guest_lc(vcpu,
402                              offsetof(struct _lowcore, restart_old_psw),
403                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
404         rc |= read_guest_lc(vcpu, offsetof(struct _lowcore, restart_psw),
405                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
406         clear_bit(IRQ_PEND_RESTART, &li->pending_irqs);
407         return rc ? -EFAULT : 0;
408 }
409
410 static int __must_check __deliver_set_prefix(struct kvm_vcpu *vcpu)
411 {
412         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
413         struct kvm_s390_prefix_info prefix;
414
415         spin_lock(&li->lock);
416         prefix = li->irq.prefix;
417         li->irq.prefix.address = 0;
418         clear_bit(IRQ_PEND_SET_PREFIX, &li->pending_irqs);
419         spin_unlock(&li->lock);
420
421         vcpu->stat.deliver_prefix_signal++;
422         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
423                                          KVM_S390_SIGP_SET_PREFIX,
424                                          prefix.address, 0);
425
426         kvm_s390_set_prefix(vcpu, prefix.address);
427         return 0;
428 }
429
430 static int __must_check __deliver_emergency_signal(struct kvm_vcpu *vcpu)
431 {
432         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
433         int rc;
434         int cpu_addr;
435
436         spin_lock(&li->lock);
437         cpu_addr = find_first_bit(li->sigp_emerg_pending, KVM_MAX_VCPUS);
438         clear_bit(cpu_addr, li->sigp_emerg_pending);
439         if (bitmap_empty(li->sigp_emerg_pending, KVM_MAX_VCPUS))
440                 clear_bit(IRQ_PEND_EXT_EMERGENCY, &li->pending_irqs);
441         spin_unlock(&li->lock);
442
443         VCPU_EVENT(vcpu, 4, "%s", "deliver: sigp emerg");
444         vcpu->stat.deliver_emergency_signal++;
445         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_INT_EMERGENCY,
446                                          cpu_addr, 0);
447
448         rc  = put_guest_lc(vcpu, EXT_IRQ_EMERGENCY_SIG,
449                            (u16 *)__LC_EXT_INT_CODE);
450         rc |= put_guest_lc(vcpu, cpu_addr, (u16 *)__LC_EXT_CPU_ADDR);
451         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
452                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
453         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
454                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
455         return rc ? -EFAULT : 0;
456 }
457
458 static int __must_check __deliver_external_call(struct kvm_vcpu *vcpu)
459 {
460         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
461         struct kvm_s390_extcall_info extcall;
462         int rc;
463
464         spin_lock(&li->lock);
465         extcall = li->irq.extcall;
466         li->irq.extcall.code = 0;
467         clear_bit(IRQ_PEND_EXT_EXTERNAL, &li->pending_irqs);
468         spin_unlock(&li->lock);
469
470         VCPU_EVENT(vcpu, 4, "%s", "deliver: sigp ext call");
471         vcpu->stat.deliver_external_call++;
472         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
473                                          KVM_S390_INT_EXTERNAL_CALL,
474                                          extcall.code, 0);
475
476         rc  = put_guest_lc(vcpu, EXT_IRQ_EXTERNAL_CALL,
477                            (u16 *)__LC_EXT_INT_CODE);
478         rc |= put_guest_lc(vcpu, extcall.code, (u16 *)__LC_EXT_CPU_ADDR);
479         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
480                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
481         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW, &vcpu->arch.sie_block->gpsw,
482                             sizeof(psw_t));
483         return rc ? -EFAULT : 0;
484 }
485
486 static int __must_check __deliver_prog(struct kvm_vcpu *vcpu)
487 {
488         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
489         struct kvm_s390_pgm_info pgm_info;
490         int rc = 0, nullifying = false;
491         u16 ilc = get_ilc(vcpu);
492
493         spin_lock(&li->lock);
494         pgm_info = li->irq.pgm;
495         clear_bit(IRQ_PEND_PROG, &li->pending_irqs);
496         memset(&li->irq.pgm, 0, sizeof(pgm_info));
497         spin_unlock(&li->lock);
498
499         VCPU_EVENT(vcpu, 3, "deliver: program irq code 0x%x, ilc:%d",
500                    pgm_info.code, ilc);
501         vcpu->stat.deliver_program_int++;
502         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_PROGRAM_INT,
503                                          pgm_info.code, 0);
504
505         switch (pgm_info.code & ~PGM_PER) {
506         case PGM_AFX_TRANSLATION:
507         case PGM_ASX_TRANSLATION:
508         case PGM_EX_TRANSLATION:
509         case PGM_LFX_TRANSLATION:
510         case PGM_LSTE_SEQUENCE:
511         case PGM_LSX_TRANSLATION:
512         case PGM_LX_TRANSLATION:
513         case PGM_PRIMARY_AUTHORITY:
514         case PGM_SECONDARY_AUTHORITY:
515                 nullifying = true;
516                 /* fall through */
517         case PGM_SPACE_SWITCH:
518                 rc = put_guest_lc(vcpu, pgm_info.trans_exc_code,
519                                   (u64 *)__LC_TRANS_EXC_CODE);
520                 break;
521         case PGM_ALEN_TRANSLATION:
522         case PGM_ALE_SEQUENCE:
523         case PGM_ASTE_INSTANCE:
524         case PGM_ASTE_SEQUENCE:
525         case PGM_ASTE_VALIDITY:
526         case PGM_EXTENDED_AUTHORITY:
527                 rc = put_guest_lc(vcpu, pgm_info.exc_access_id,
528                                   (u8 *)__LC_EXC_ACCESS_ID);
529                 nullifying = true;
530                 break;
531         case PGM_ASCE_TYPE:
532         case PGM_PAGE_TRANSLATION:
533         case PGM_REGION_FIRST_TRANS:
534         case PGM_REGION_SECOND_TRANS:
535         case PGM_REGION_THIRD_TRANS:
536         case PGM_SEGMENT_TRANSLATION:
537                 rc = put_guest_lc(vcpu, pgm_info.trans_exc_code,
538                                   (u64 *)__LC_TRANS_EXC_CODE);
539                 rc |= put_guest_lc(vcpu, pgm_info.exc_access_id,
540                                    (u8 *)__LC_EXC_ACCESS_ID);
541                 rc |= put_guest_lc(vcpu, pgm_info.op_access_id,
542                                    (u8 *)__LC_OP_ACCESS_ID);
543                 nullifying = true;
544                 break;
545         case PGM_MONITOR:
546                 rc = put_guest_lc(vcpu, pgm_info.mon_class_nr,
547                                   (u16 *)__LC_MON_CLASS_NR);
548                 rc |= put_guest_lc(vcpu, pgm_info.mon_code,
549                                    (u64 *)__LC_MON_CODE);
550                 break;
551         case PGM_VECTOR_PROCESSING:
552         case PGM_DATA:
553                 rc = put_guest_lc(vcpu, pgm_info.data_exc_code,
554                                   (u32 *)__LC_DATA_EXC_CODE);
555                 break;
556         case PGM_PROTECTION:
557                 rc = put_guest_lc(vcpu, pgm_info.trans_exc_code,
558                                   (u64 *)__LC_TRANS_EXC_CODE);
559                 rc |= put_guest_lc(vcpu, pgm_info.exc_access_id,
560                                    (u8 *)__LC_EXC_ACCESS_ID);
561                 break;
562         case PGM_STACK_FULL:
563         case PGM_STACK_EMPTY:
564         case PGM_STACK_SPECIFICATION:
565         case PGM_STACK_TYPE:
566         case PGM_STACK_OPERATION:
567         case PGM_TRACE_TABEL:
568         case PGM_CRYPTO_OPERATION:
569                 nullifying = true;
570                 break;
571         }
572
573         if (pgm_info.code & PGM_PER) {
574                 rc |= put_guest_lc(vcpu, pgm_info.per_code,
575                                    (u8 *) __LC_PER_CODE);
576                 rc |= put_guest_lc(vcpu, pgm_info.per_atmid,
577                                    (u8 *)__LC_PER_ATMID);
578                 rc |= put_guest_lc(vcpu, pgm_info.per_address,
579                                    (u64 *) __LC_PER_ADDRESS);
580                 rc |= put_guest_lc(vcpu, pgm_info.per_access_id,
581                                    (u8 *) __LC_PER_ACCESS_ID);
582         }
583
584         if (nullifying && vcpu->arch.sie_block->icptcode == ICPT_INST)
585                 kvm_s390_rewind_psw(vcpu, ilc);
586
587         rc |= put_guest_lc(vcpu, ilc, (u16 *) __LC_PGM_ILC);
588         rc |= put_guest_lc(vcpu, vcpu->arch.sie_block->gbea,
589                                  (u64 *) __LC_LAST_BREAK);
590         rc |= put_guest_lc(vcpu, pgm_info.code,
591                            (u16 *)__LC_PGM_INT_CODE);
592         rc |= write_guest_lc(vcpu, __LC_PGM_OLD_PSW,
593                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
594         rc |= read_guest_lc(vcpu, __LC_PGM_NEW_PSW,
595                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
596         return rc ? -EFAULT : 0;
597 }
598
599 static int __must_check __deliver_service(struct kvm_vcpu *vcpu)
600 {
601         struct kvm_s390_float_interrupt *fi = &vcpu->kvm->arch.float_int;
602         struct kvm_s390_ext_info ext;
603         int rc = 0;
604
605         spin_lock(&fi->lock);
606         if (!(test_bit(IRQ_PEND_EXT_SERVICE, &fi->pending_irqs))) {
607                 spin_unlock(&fi->lock);
608                 return 0;
609         }
610         ext = fi->srv_signal;
611         memset(&fi->srv_signal, 0, sizeof(ext));
612         clear_bit(IRQ_PEND_EXT_SERVICE, &fi->pending_irqs);
613         spin_unlock(&fi->lock);
614
615         VCPU_EVENT(vcpu, 4, "deliver: sclp parameter 0x%x",
616                    ext.ext_params);
617         vcpu->stat.deliver_service_signal++;
618         trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id, KVM_S390_INT_SERVICE,
619                                          ext.ext_params, 0);
620
621         rc  = put_guest_lc(vcpu, EXT_IRQ_SERVICE_SIG, (u16 *)__LC_EXT_INT_CODE);
622         rc |= put_guest_lc(vcpu, 0, (u16 *)__LC_EXT_CPU_ADDR);
623         rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
624                              &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
625         rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
626                             &vcpu->arch.sie_block->gpsw, sizeof(psw_t));
627         rc |= put_guest_lc(vcpu, ext.ext_params,
628                            (u32 *)__LC_EXT_PARAMS);
629
630         return rc ? -EFAULT : 0;
631 }
632
633 static int __must_check __deliver_pfault_done(struct kvm_vcpu *vcpu)
634 {
635         struct kvm_s390_float_interrupt *fi = &vcpu->kvm->arch.float_int;
636         struct kvm_s390_interrupt_info *inti;
637         int rc = 0;
638
639         spin_lock(&fi->lock);
640         inti = list_first_entry_or_null(&fi->lists[FIRQ_LIST_PFAULT],
641                                         struct kvm_s390_interrupt_info,
642                                         list);
643         if (inti) {
644                 list_del(&inti->list);
645                 fi->counters[FIRQ_CNTR_PFAULT] -= 1;
646         }
647         if (list_empty(&fi->lists[FIRQ_LIST_PFAULT]))
648                 clear_bit(IRQ_PEND_PFAULT_DONE, &fi->pending_irqs);
649         spin_unlock(&fi->lock);
650
651         if (inti) {
652                 trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
653                                                  KVM_S390_INT_PFAULT_DONE, 0,
654                                                  inti->ext.ext_params2);
655                 VCPU_EVENT(vcpu, 4, "deliver: pfault done token 0x%llx",
656                            inti->ext.ext_params2);
657
658                 rc  = put_guest_lc(vcpu, EXT_IRQ_CP_SERVICE,
659                                 (u16 *)__LC_EXT_INT_CODE);
660                 rc |= put_guest_lc(vcpu, PFAULT_DONE,
661                                 (u16 *)__LC_EXT_CPU_ADDR);
662                 rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
663                                 &vcpu->arch.sie_block->gpsw,
664                                 sizeof(psw_t));
665                 rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
666                                 &vcpu->arch.sie_block->gpsw,
667                                 sizeof(psw_t));
668                 rc |= put_guest_lc(vcpu, inti->ext.ext_params2,
669                                 (u64 *)__LC_EXT_PARAMS2);
670                 kfree(inti);
671         }
672         return rc ? -EFAULT : 0;
673 }
674
675 static int __must_check __deliver_virtio(struct kvm_vcpu *vcpu)
676 {
677         struct kvm_s390_float_interrupt *fi = &vcpu->kvm->arch.float_int;
678         struct kvm_s390_interrupt_info *inti;
679         int rc = 0;
680
681         spin_lock(&fi->lock);
682         inti = list_first_entry_or_null(&fi->lists[FIRQ_LIST_VIRTIO],
683                                         struct kvm_s390_interrupt_info,
684                                         list);
685         if (inti) {
686                 VCPU_EVENT(vcpu, 4,
687                            "deliver: virtio parm: 0x%x,parm64: 0x%llx",
688                            inti->ext.ext_params, inti->ext.ext_params2);
689                 vcpu->stat.deliver_virtio_interrupt++;
690                 trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
691                                 inti->type,
692                                 inti->ext.ext_params,
693                                 inti->ext.ext_params2);
694                 list_del(&inti->list);
695                 fi->counters[FIRQ_CNTR_VIRTIO] -= 1;
696         }
697         if (list_empty(&fi->lists[FIRQ_LIST_VIRTIO]))
698                 clear_bit(IRQ_PEND_VIRTIO, &fi->pending_irqs);
699         spin_unlock(&fi->lock);
700
701         if (inti) {
702                 rc  = put_guest_lc(vcpu, EXT_IRQ_CP_SERVICE,
703                                 (u16 *)__LC_EXT_INT_CODE);
704                 rc |= put_guest_lc(vcpu, VIRTIO_PARAM,
705                                 (u16 *)__LC_EXT_CPU_ADDR);
706                 rc |= write_guest_lc(vcpu, __LC_EXT_OLD_PSW,
707                                 &vcpu->arch.sie_block->gpsw,
708                                 sizeof(psw_t));
709                 rc |= read_guest_lc(vcpu, __LC_EXT_NEW_PSW,
710                                 &vcpu->arch.sie_block->gpsw,
711                                 sizeof(psw_t));
712                 rc |= put_guest_lc(vcpu, inti->ext.ext_params,
713                                 (u32 *)__LC_EXT_PARAMS);
714                 rc |= put_guest_lc(vcpu, inti->ext.ext_params2,
715                                 (u64 *)__LC_EXT_PARAMS2);
716                 kfree(inti);
717         }
718         return rc ? -EFAULT : 0;
719 }
720
721 static int __must_check __deliver_io(struct kvm_vcpu *vcpu,
722                                      unsigned long irq_type)
723 {
724         struct list_head *isc_list;
725         struct kvm_s390_float_interrupt *fi;
726         struct kvm_s390_interrupt_info *inti = NULL;
727         int rc = 0;
728
729         fi = &vcpu->kvm->arch.float_int;
730
731         spin_lock(&fi->lock);
732         isc_list = &fi->lists[irq_type - IRQ_PEND_IO_ISC_0];
733         inti = list_first_entry_or_null(isc_list,
734                                         struct kvm_s390_interrupt_info,
735                                         list);
736         if (inti) {
737                 VCPU_EVENT(vcpu, 4, "deliver: I/O 0x%llx", inti->type);
738                 vcpu->stat.deliver_io_int++;
739                 trace_kvm_s390_deliver_interrupt(vcpu->vcpu_id,
740                                 inti->type,
741                                 ((__u32)inti->io.subchannel_id << 16) |
742                                 inti->io.subchannel_nr,
743                                 ((__u64)inti->io.io_int_parm << 32) |
744                                 inti->io.io_int_word);
745                 list_del(&inti->list);
746                 fi->counters[FIRQ_CNTR_IO] -= 1;
747         }
748         if (list_empty(isc_list))
749                 clear_bit(irq_type, &fi->pending_irqs);
750         spin_unlock(&fi->lock);
751
752         if (inti) {
753                 rc  = put_guest_lc(vcpu, inti->io.subchannel_id,
754                                 (u16 *)__LC_SUBCHANNEL_ID);
755                 rc |= put_guest_lc(vcpu, inti->io.subchannel_nr,
756                                 (u16 *)__LC_SUBCHANNEL_NR);
757                 rc |= put_guest_lc(vcpu, inti->io.io_int_parm,
758                                 (u32 *)__LC_IO_INT_PARM);
759                 rc |= put_guest_lc(vcpu, inti->io.io_int_word,
760                                 (u32 *)__LC_IO_INT_WORD);
761                 rc |= write_guest_lc(vcpu, __LC_IO_OLD_PSW,
762                                 &vcpu->arch.sie_block->gpsw,
763                                 sizeof(psw_t));
764                 rc |= read_guest_lc(vcpu, __LC_IO_NEW_PSW,
765                                 &vcpu->arch.sie_block->gpsw,
766                                 sizeof(psw_t));
767                 kfree(inti);
768         }
769
770         return rc ? -EFAULT : 0;
771 }
772
773 typedef int (*deliver_irq_t)(struct kvm_vcpu *vcpu);
774
775 static const deliver_irq_t deliver_irq_funcs[] = {
776         [IRQ_PEND_MCHK_EX]        = __deliver_machine_check,
777         [IRQ_PEND_MCHK_REP]       = __deliver_machine_check,
778         [IRQ_PEND_PROG]           = __deliver_prog,
779         [IRQ_PEND_EXT_EMERGENCY]  = __deliver_emergency_signal,
780         [IRQ_PEND_EXT_EXTERNAL]   = __deliver_external_call,
781         [IRQ_PEND_EXT_CLOCK_COMP] = __deliver_ckc,
782         [IRQ_PEND_EXT_CPU_TIMER]  = __deliver_cpu_timer,
783         [IRQ_PEND_RESTART]        = __deliver_restart,
784         [IRQ_PEND_SET_PREFIX]     = __deliver_set_prefix,
785         [IRQ_PEND_PFAULT_INIT]    = __deliver_pfault_init,
786         [IRQ_PEND_EXT_SERVICE]    = __deliver_service,
787         [IRQ_PEND_PFAULT_DONE]    = __deliver_pfault_done,
788         [IRQ_PEND_VIRTIO]         = __deliver_virtio,
789 };
790
791 /* Check whether an external call is pending (deliverable or not) */
792 int kvm_s390_ext_call_pending(struct kvm_vcpu *vcpu)
793 {
794         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
795         uint8_t sigp_ctrl = vcpu->kvm->arch.sca->cpu[vcpu->vcpu_id].sigp_ctrl;
796
797         if (!sclp.has_sigpif)
798                 return test_bit(IRQ_PEND_EXT_EXTERNAL, &li->pending_irqs);
799
800         return (sigp_ctrl & SIGP_CTRL_C) &&
801                (atomic_read(&vcpu->arch.sie_block->cpuflags) & CPUSTAT_ECALL_PEND);
802 }
803
804 int kvm_s390_vcpu_has_irq(struct kvm_vcpu *vcpu, int exclude_stop)
805 {
806         if (deliverable_irqs(vcpu))
807                 return 1;
808
809         if (kvm_cpu_has_pending_timer(vcpu))
810                 return 1;
811
812         /* external call pending and deliverable */
813         if (kvm_s390_ext_call_pending(vcpu) &&
814             !psw_extint_disabled(vcpu) &&
815             (vcpu->arch.sie_block->gcr[0] & 0x2000ul))
816                 return 1;
817
818         if (!exclude_stop && kvm_s390_is_stop_irq_pending(vcpu))
819                 return 1;
820         return 0;
821 }
822
823 int kvm_cpu_has_pending_timer(struct kvm_vcpu *vcpu)
824 {
825         return ckc_irq_pending(vcpu) || cpu_timer_irq_pending(vcpu);
826 }
827
828 int kvm_s390_handle_wait(struct kvm_vcpu *vcpu)
829 {
830         u64 now, sltime;
831
832         vcpu->stat.exit_wait_state++;
833
834         /* fast path */
835         if (kvm_arch_vcpu_runnable(vcpu))
836                 return 0;
837
838         if (psw_interrupts_disabled(vcpu)) {
839                 VCPU_EVENT(vcpu, 3, "%s", "disabled wait");
840                 return -EOPNOTSUPP; /* disabled wait */
841         }
842
843         if (!ckc_interrupts_enabled(vcpu)) {
844                 VCPU_EVENT(vcpu, 3, "%s", "enabled wait w/o timer");
845                 __set_cpu_idle(vcpu);
846                 goto no_timer;
847         }
848
849         now = kvm_s390_get_tod_clock_fast(vcpu->kvm);
850         sltime = tod_to_ns(vcpu->arch.sie_block->ckc - now);
851
852         /* underflow */
853         if (vcpu->arch.sie_block->ckc < now)
854                 return 0;
855
856         __set_cpu_idle(vcpu);
857         hrtimer_start(&vcpu->arch.ckc_timer, ktime_set (0, sltime) , HRTIMER_MODE_REL);
858         VCPU_EVENT(vcpu, 4, "enabled wait via clock comparator: %llu ns", sltime);
859 no_timer:
860         srcu_read_unlock(&vcpu->kvm->srcu, vcpu->srcu_idx);
861         kvm_vcpu_block(vcpu);
862         __unset_cpu_idle(vcpu);
863         vcpu->srcu_idx = srcu_read_lock(&vcpu->kvm->srcu);
864
865         hrtimer_cancel(&vcpu->arch.ckc_timer);
866         return 0;
867 }
868
869 void kvm_s390_vcpu_wakeup(struct kvm_vcpu *vcpu)
870 {
871         if (waitqueue_active(&vcpu->wq)) {
872                 /*
873                  * The vcpu gave up the cpu voluntarily, mark it as a good
874                  * yield-candidate.
875                  */
876                 vcpu->preempted = true;
877                 wake_up_interruptible(&vcpu->wq);
878                 vcpu->stat.halt_wakeup++;
879         }
880 }
881
882 enum hrtimer_restart kvm_s390_idle_wakeup(struct hrtimer *timer)
883 {
884         struct kvm_vcpu *vcpu;
885         u64 now, sltime;
886
887         vcpu = container_of(timer, struct kvm_vcpu, arch.ckc_timer);
888         now = kvm_s390_get_tod_clock_fast(vcpu->kvm);
889         sltime = tod_to_ns(vcpu->arch.sie_block->ckc - now);
890
891         /*
892          * If the monotonic clock runs faster than the tod clock we might be
893          * woken up too early and have to go back to sleep to avoid deadlocks.
894          */
895         if (vcpu->arch.sie_block->ckc > now &&
896             hrtimer_forward_now(timer, ns_to_ktime(sltime)))
897                 return HRTIMER_RESTART;
898         kvm_s390_vcpu_wakeup(vcpu);
899         return HRTIMER_NORESTART;
900 }
901
902 void kvm_s390_clear_local_irqs(struct kvm_vcpu *vcpu)
903 {
904         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
905
906         spin_lock(&li->lock);
907         li->pending_irqs = 0;
908         bitmap_zero(li->sigp_emerg_pending, KVM_MAX_VCPUS);
909         memset(&li->irq, 0, sizeof(li->irq));
910         spin_unlock(&li->lock);
911
912         /* clear pending external calls set by sigp interpretation facility */
913         atomic_andnot(CPUSTAT_ECALL_PEND, li->cpuflags);
914         vcpu->kvm->arch.sca->cpu[vcpu->vcpu_id].sigp_ctrl = 0;
915 }
916
917 int __must_check kvm_s390_deliver_pending_interrupts(struct kvm_vcpu *vcpu)
918 {
919         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
920         deliver_irq_t func;
921         int rc = 0;
922         unsigned long irq_type;
923         unsigned long irqs;
924
925         __reset_intercept_indicators(vcpu);
926
927         /* pending ckc conditions might have been invalidated */
928         clear_bit(IRQ_PEND_EXT_CLOCK_COMP, &li->pending_irqs);
929         if (ckc_irq_pending(vcpu))
930                 set_bit(IRQ_PEND_EXT_CLOCK_COMP, &li->pending_irqs);
931
932         /* pending cpu timer conditions might have been invalidated */
933         clear_bit(IRQ_PEND_EXT_CPU_TIMER, &li->pending_irqs);
934         if (cpu_timer_irq_pending(vcpu))
935                 set_bit(IRQ_PEND_EXT_CPU_TIMER, &li->pending_irqs);
936
937         while ((irqs = deliverable_irqs(vcpu)) && !rc) {
938                 /* bits are in the order of interrupt priority */
939                 irq_type = find_first_bit(&irqs, IRQ_PEND_COUNT);
940                 if (is_ioirq(irq_type)) {
941                         rc = __deliver_io(vcpu, irq_type);
942                 } else {
943                         func = deliver_irq_funcs[irq_type];
944                         if (!func) {
945                                 WARN_ON_ONCE(func == NULL);
946                                 clear_bit(irq_type, &li->pending_irqs);
947                                 continue;
948                         }
949                         rc = func(vcpu);
950                 }
951         }
952
953         set_intercept_indicators(vcpu);
954
955         return rc;
956 }
957
958 static int __inject_prog(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
959 {
960         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
961
962         VCPU_EVENT(vcpu, 3, "inject: program irq code 0x%x", irq->u.pgm.code);
963         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_PROGRAM_INT,
964                                    irq->u.pgm.code, 0);
965
966         if (irq->u.pgm.code == PGM_PER) {
967                 li->irq.pgm.code |= PGM_PER;
968                 /* only modify PER related information */
969                 li->irq.pgm.per_address = irq->u.pgm.per_address;
970                 li->irq.pgm.per_code = irq->u.pgm.per_code;
971                 li->irq.pgm.per_atmid = irq->u.pgm.per_atmid;
972                 li->irq.pgm.per_access_id = irq->u.pgm.per_access_id;
973         } else if (!(irq->u.pgm.code & PGM_PER)) {
974                 li->irq.pgm.code = (li->irq.pgm.code & PGM_PER) |
975                                    irq->u.pgm.code;
976                 /* only modify non-PER information */
977                 li->irq.pgm.trans_exc_code = irq->u.pgm.trans_exc_code;
978                 li->irq.pgm.mon_code = irq->u.pgm.mon_code;
979                 li->irq.pgm.data_exc_code = irq->u.pgm.data_exc_code;
980                 li->irq.pgm.mon_class_nr = irq->u.pgm.mon_class_nr;
981                 li->irq.pgm.exc_access_id = irq->u.pgm.exc_access_id;
982                 li->irq.pgm.op_access_id = irq->u.pgm.op_access_id;
983         } else {
984                 li->irq.pgm = irq->u.pgm;
985         }
986         set_bit(IRQ_PEND_PROG, &li->pending_irqs);
987         return 0;
988 }
989
990 static int __inject_pfault_init(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
991 {
992         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
993
994         VCPU_EVENT(vcpu, 4, "inject: pfault init parameter block at 0x%llx",
995                    irq->u.ext.ext_params2);
996         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_INT_PFAULT_INIT,
997                                    irq->u.ext.ext_params,
998                                    irq->u.ext.ext_params2);
999
1000         li->irq.ext = irq->u.ext;
1001         set_bit(IRQ_PEND_PFAULT_INIT, &li->pending_irqs);
1002         atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1003         return 0;
1004 }
1005
1006 static int __inject_extcall_sigpif(struct kvm_vcpu *vcpu, uint16_t src_id)
1007 {
1008         unsigned char new_val, old_val;
1009         uint8_t *sigp_ctrl = &vcpu->kvm->arch.sca->cpu[vcpu->vcpu_id].sigp_ctrl;
1010
1011         new_val = SIGP_CTRL_C | (src_id & SIGP_CTRL_SCN_MASK);
1012         old_val = *sigp_ctrl & ~SIGP_CTRL_C;
1013         if (cmpxchg(sigp_ctrl, old_val, new_val) != old_val) {
1014                 /* another external call is pending */
1015                 return -EBUSY;
1016         }
1017         atomic_or(CPUSTAT_ECALL_PEND, &vcpu->arch.sie_block->cpuflags);
1018         return 0;
1019 }
1020
1021 static int __inject_extcall(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1022 {
1023         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1024         struct kvm_s390_extcall_info *extcall = &li->irq.extcall;
1025         uint16_t src_id = irq->u.extcall.code;
1026
1027         VCPU_EVENT(vcpu, 4, "inject: external call source-cpu:%u",
1028                    src_id);
1029         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_INT_EXTERNAL_CALL,
1030                                    src_id, 0);
1031
1032         /* sending vcpu invalid */
1033         if (src_id >= KVM_MAX_VCPUS ||
1034             kvm_get_vcpu(vcpu->kvm, src_id) == NULL)
1035                 return -EINVAL;
1036
1037         if (sclp.has_sigpif)
1038                 return __inject_extcall_sigpif(vcpu, src_id);
1039
1040         if (test_and_set_bit(IRQ_PEND_EXT_EXTERNAL, &li->pending_irqs))
1041                 return -EBUSY;
1042         *extcall = irq->u.extcall;
1043         atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1044         return 0;
1045 }
1046
1047 static int __inject_set_prefix(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1048 {
1049         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1050         struct kvm_s390_prefix_info *prefix = &li->irq.prefix;
1051
1052         VCPU_EVENT(vcpu, 3, "inject: set prefix to %x",
1053                    irq->u.prefix.address);
1054         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_SIGP_SET_PREFIX,
1055                                    irq->u.prefix.address, 0);
1056
1057         if (!is_vcpu_stopped(vcpu))
1058                 return -EBUSY;
1059
1060         *prefix = irq->u.prefix;
1061         set_bit(IRQ_PEND_SET_PREFIX, &li->pending_irqs);
1062         return 0;
1063 }
1064
1065 #define KVM_S390_STOP_SUPP_FLAGS (KVM_S390_STOP_FLAG_STORE_STATUS)
1066 static int __inject_sigp_stop(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1067 {
1068         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1069         struct kvm_s390_stop_info *stop = &li->irq.stop;
1070         int rc = 0;
1071
1072         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_SIGP_STOP, 0, 0);
1073
1074         if (irq->u.stop.flags & ~KVM_S390_STOP_SUPP_FLAGS)
1075                 return -EINVAL;
1076
1077         if (is_vcpu_stopped(vcpu)) {
1078                 if (irq->u.stop.flags & KVM_S390_STOP_FLAG_STORE_STATUS)
1079                         rc = kvm_s390_store_status_unloaded(vcpu,
1080                                                 KVM_S390_STORE_STATUS_NOADDR);
1081                 return rc;
1082         }
1083
1084         if (test_and_set_bit(IRQ_PEND_SIGP_STOP, &li->pending_irqs))
1085                 return -EBUSY;
1086         stop->flags = irq->u.stop.flags;
1087         __set_cpuflag(vcpu, CPUSTAT_STOP_INT);
1088         return 0;
1089 }
1090
1091 static int __inject_sigp_restart(struct kvm_vcpu *vcpu,
1092                                  struct kvm_s390_irq *irq)
1093 {
1094         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1095
1096         VCPU_EVENT(vcpu, 3, "%s", "inject: restart int");
1097         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_RESTART, 0, 0);
1098
1099         set_bit(IRQ_PEND_RESTART, &li->pending_irqs);
1100         return 0;
1101 }
1102
1103 static int __inject_sigp_emergency(struct kvm_vcpu *vcpu,
1104                                    struct kvm_s390_irq *irq)
1105 {
1106         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1107
1108         VCPU_EVENT(vcpu, 4, "inject: emergency from cpu %u",
1109                    irq->u.emerg.code);
1110         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_INT_EMERGENCY,
1111                                    irq->u.emerg.code, 0);
1112
1113         /* sending vcpu invalid */
1114         if (kvm_get_vcpu_by_id(vcpu->kvm, irq->u.emerg.code) == NULL)
1115                 return -EINVAL;
1116
1117         set_bit(irq->u.emerg.code, li->sigp_emerg_pending);
1118         set_bit(IRQ_PEND_EXT_EMERGENCY, &li->pending_irqs);
1119         atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1120         return 0;
1121 }
1122
1123 static int __inject_mchk(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1124 {
1125         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1126         struct kvm_s390_mchk_info *mchk = &li->irq.mchk;
1127
1128         VCPU_EVENT(vcpu, 3, "inject: machine check mcic 0x%llx",
1129                    irq->u.mchk.mcic);
1130         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_MCHK, 0,
1131                                    irq->u.mchk.mcic);
1132
1133         /*
1134          * Because repressible machine checks can be indicated along with
1135          * exigent machine checks (PoP, Chapter 11, Interruption action)
1136          * we need to combine cr14, mcic and external damage code.
1137          * Failing storage address and the logout area should not be or'ed
1138          * together, we just indicate the last occurrence of the corresponding
1139          * machine check
1140          */
1141         mchk->cr14 |= irq->u.mchk.cr14;
1142         mchk->mcic |= irq->u.mchk.mcic;
1143         mchk->ext_damage_code |= irq->u.mchk.ext_damage_code;
1144         mchk->failing_storage_address = irq->u.mchk.failing_storage_address;
1145         memcpy(&mchk->fixed_logout, &irq->u.mchk.fixed_logout,
1146                sizeof(mchk->fixed_logout));
1147         if (mchk->mcic & MCHK_EX_MASK)
1148                 set_bit(IRQ_PEND_MCHK_EX, &li->pending_irqs);
1149         else if (mchk->mcic & MCHK_REP_MASK)
1150                 set_bit(IRQ_PEND_MCHK_REP,  &li->pending_irqs);
1151         return 0;
1152 }
1153
1154 static int __inject_ckc(struct kvm_vcpu *vcpu)
1155 {
1156         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1157
1158         VCPU_EVENT(vcpu, 3, "%s", "inject: clock comparator external");
1159         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_INT_CLOCK_COMP,
1160                                    0, 0);
1161
1162         set_bit(IRQ_PEND_EXT_CLOCK_COMP, &li->pending_irqs);
1163         atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1164         return 0;
1165 }
1166
1167 static int __inject_cpu_timer(struct kvm_vcpu *vcpu)
1168 {
1169         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1170
1171         VCPU_EVENT(vcpu, 3, "%s", "inject: cpu timer external");
1172         trace_kvm_s390_inject_vcpu(vcpu->vcpu_id, KVM_S390_INT_CPU_TIMER,
1173                                    0, 0);
1174
1175         set_bit(IRQ_PEND_EXT_CPU_TIMER, &li->pending_irqs);
1176         atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1177         return 0;
1178 }
1179
1180 static struct kvm_s390_interrupt_info *get_io_int(struct kvm *kvm,
1181                                                   int isc, u32 schid)
1182 {
1183         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1184         struct list_head *isc_list = &fi->lists[FIRQ_LIST_IO_ISC_0 + isc];
1185         struct kvm_s390_interrupt_info *iter;
1186         u16 id = (schid & 0xffff0000U) >> 16;
1187         u16 nr = schid & 0x0000ffffU;
1188
1189         spin_lock(&fi->lock);
1190         list_for_each_entry(iter, isc_list, list) {
1191                 if (schid && (id != iter->io.subchannel_id ||
1192                               nr != iter->io.subchannel_nr))
1193                         continue;
1194                 /* found an appropriate entry */
1195                 list_del_init(&iter->list);
1196                 fi->counters[FIRQ_CNTR_IO] -= 1;
1197                 if (list_empty(isc_list))
1198                         clear_bit(IRQ_PEND_IO_ISC_0 + isc, &fi->pending_irqs);
1199                 spin_unlock(&fi->lock);
1200                 return iter;
1201         }
1202         spin_unlock(&fi->lock);
1203         return NULL;
1204 }
1205
1206 /*
1207  * Dequeue and return an I/O interrupt matching any of the interruption
1208  * subclasses as designated by the isc mask in cr6 and the schid (if != 0).
1209  */
1210 struct kvm_s390_interrupt_info *kvm_s390_get_io_int(struct kvm *kvm,
1211                                                     u64 isc_mask, u32 schid)
1212 {
1213         struct kvm_s390_interrupt_info *inti = NULL;
1214         int isc;
1215
1216         for (isc = 0; isc <= MAX_ISC && !inti; isc++) {
1217                 if (isc_mask & isc_to_isc_bits(isc))
1218                         inti = get_io_int(kvm, isc, schid);
1219         }
1220         return inti;
1221 }
1222
1223 #define SCCB_MASK 0xFFFFFFF8
1224 #define SCCB_EVENT_PENDING 0x3
1225
1226 static int __inject_service(struct kvm *kvm,
1227                              struct kvm_s390_interrupt_info *inti)
1228 {
1229         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1230
1231         spin_lock(&fi->lock);
1232         fi->srv_signal.ext_params |= inti->ext.ext_params & SCCB_EVENT_PENDING;
1233         /*
1234          * Early versions of the QEMU s390 bios will inject several
1235          * service interrupts after another without handling a
1236          * condition code indicating busy.
1237          * We will silently ignore those superfluous sccb values.
1238          * A future version of QEMU will take care of serialization
1239          * of servc requests
1240          */
1241         if (fi->srv_signal.ext_params & SCCB_MASK)
1242                 goto out;
1243         fi->srv_signal.ext_params |= inti->ext.ext_params & SCCB_MASK;
1244         set_bit(IRQ_PEND_EXT_SERVICE, &fi->pending_irqs);
1245 out:
1246         spin_unlock(&fi->lock);
1247         kfree(inti);
1248         return 0;
1249 }
1250
1251 static int __inject_virtio(struct kvm *kvm,
1252                             struct kvm_s390_interrupt_info *inti)
1253 {
1254         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1255
1256         spin_lock(&fi->lock);
1257         if (fi->counters[FIRQ_CNTR_VIRTIO] >= KVM_S390_MAX_VIRTIO_IRQS) {
1258                 spin_unlock(&fi->lock);
1259                 return -EBUSY;
1260         }
1261         fi->counters[FIRQ_CNTR_VIRTIO] += 1;
1262         list_add_tail(&inti->list, &fi->lists[FIRQ_LIST_VIRTIO]);
1263         set_bit(IRQ_PEND_VIRTIO, &fi->pending_irqs);
1264         spin_unlock(&fi->lock);
1265         return 0;
1266 }
1267
1268 static int __inject_pfault_done(struct kvm *kvm,
1269                                  struct kvm_s390_interrupt_info *inti)
1270 {
1271         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1272
1273         spin_lock(&fi->lock);
1274         if (fi->counters[FIRQ_CNTR_PFAULT] >=
1275                 (ASYNC_PF_PER_VCPU * KVM_MAX_VCPUS)) {
1276                 spin_unlock(&fi->lock);
1277                 return -EBUSY;
1278         }
1279         fi->counters[FIRQ_CNTR_PFAULT] += 1;
1280         list_add_tail(&inti->list, &fi->lists[FIRQ_LIST_PFAULT]);
1281         set_bit(IRQ_PEND_PFAULT_DONE, &fi->pending_irqs);
1282         spin_unlock(&fi->lock);
1283         return 0;
1284 }
1285
1286 #define CR_PENDING_SUBCLASS 28
1287 static int __inject_float_mchk(struct kvm *kvm,
1288                                 struct kvm_s390_interrupt_info *inti)
1289 {
1290         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1291
1292         spin_lock(&fi->lock);
1293         fi->mchk.cr14 |= inti->mchk.cr14 & (1UL << CR_PENDING_SUBCLASS);
1294         fi->mchk.mcic |= inti->mchk.mcic;
1295         set_bit(IRQ_PEND_MCHK_REP, &fi->pending_irqs);
1296         spin_unlock(&fi->lock);
1297         kfree(inti);
1298         return 0;
1299 }
1300
1301 static int __inject_io(struct kvm *kvm, struct kvm_s390_interrupt_info *inti)
1302 {
1303         struct kvm_s390_float_interrupt *fi;
1304         struct list_head *list;
1305         int isc;
1306
1307         fi = &kvm->arch.float_int;
1308         spin_lock(&fi->lock);
1309         if (fi->counters[FIRQ_CNTR_IO] >= KVM_S390_MAX_FLOAT_IRQS) {
1310                 spin_unlock(&fi->lock);
1311                 return -EBUSY;
1312         }
1313         fi->counters[FIRQ_CNTR_IO] += 1;
1314
1315         isc = int_word_to_isc(inti->io.io_int_word);
1316         list = &fi->lists[FIRQ_LIST_IO_ISC_0 + isc];
1317         list_add_tail(&inti->list, list);
1318         set_bit(IRQ_PEND_IO_ISC_0 + isc, &fi->pending_irqs);
1319         spin_unlock(&fi->lock);
1320         return 0;
1321 }
1322
1323 /*
1324  * Find a destination VCPU for a floating irq and kick it.
1325  */
1326 static void __floating_irq_kick(struct kvm *kvm, u64 type)
1327 {
1328         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1329         struct kvm_s390_local_interrupt *li;
1330         struct kvm_vcpu *dst_vcpu;
1331         int sigcpu, online_vcpus, nr_tries = 0;
1332
1333         online_vcpus = atomic_read(&kvm->online_vcpus);
1334         if (!online_vcpus)
1335                 return;
1336
1337         /* find idle VCPUs first, then round robin */
1338         sigcpu = find_first_bit(fi->idle_mask, online_vcpus);
1339         if (sigcpu == online_vcpus) {
1340                 do {
1341                         sigcpu = fi->next_rr_cpu;
1342                         fi->next_rr_cpu = (fi->next_rr_cpu + 1) % online_vcpus;
1343                         /* avoid endless loops if all vcpus are stopped */
1344                         if (nr_tries++ >= online_vcpus)
1345                                 return;
1346                 } while (is_vcpu_stopped(kvm_get_vcpu(kvm, sigcpu)));
1347         }
1348         dst_vcpu = kvm_get_vcpu(kvm, sigcpu);
1349
1350         /* make the VCPU drop out of the SIE, or wake it up if sleeping */
1351         li = &dst_vcpu->arch.local_int;
1352         spin_lock(&li->lock);
1353         switch (type) {
1354         case KVM_S390_MCHK:
1355                 atomic_or(CPUSTAT_STOP_INT, li->cpuflags);
1356                 break;
1357         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1358                 atomic_or(CPUSTAT_IO_INT, li->cpuflags);
1359                 break;
1360         default:
1361                 atomic_or(CPUSTAT_EXT_INT, li->cpuflags);
1362                 break;
1363         }
1364         spin_unlock(&li->lock);
1365         kvm_s390_vcpu_wakeup(dst_vcpu);
1366 }
1367
1368 static int __inject_vm(struct kvm *kvm, struct kvm_s390_interrupt_info *inti)
1369 {
1370         u64 type = READ_ONCE(inti->type);
1371         int rc;
1372
1373         switch (type) {
1374         case KVM_S390_MCHK:
1375                 rc = __inject_float_mchk(kvm, inti);
1376                 break;
1377         case KVM_S390_INT_VIRTIO:
1378                 rc = __inject_virtio(kvm, inti);
1379                 break;
1380         case KVM_S390_INT_SERVICE:
1381                 rc = __inject_service(kvm, inti);
1382                 break;
1383         case KVM_S390_INT_PFAULT_DONE:
1384                 rc = __inject_pfault_done(kvm, inti);
1385                 break;
1386         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1387                 rc = __inject_io(kvm, inti);
1388                 break;
1389         default:
1390                 rc = -EINVAL;
1391         }
1392         if (rc)
1393                 return rc;
1394
1395         __floating_irq_kick(kvm, type);
1396         return 0;
1397 }
1398
1399 int kvm_s390_inject_vm(struct kvm *kvm,
1400                        struct kvm_s390_interrupt *s390int)
1401 {
1402         struct kvm_s390_interrupt_info *inti;
1403         int rc;
1404
1405         inti = kzalloc(sizeof(*inti), GFP_KERNEL);
1406         if (!inti)
1407                 return -ENOMEM;
1408
1409         inti->type = s390int->type;
1410         switch (inti->type) {
1411         case KVM_S390_INT_VIRTIO:
1412                 VM_EVENT(kvm, 5, "inject: virtio parm:%x,parm64:%llx",
1413                          s390int->parm, s390int->parm64);
1414                 inti->ext.ext_params = s390int->parm;
1415                 inti->ext.ext_params2 = s390int->parm64;
1416                 break;
1417         case KVM_S390_INT_SERVICE:
1418                 VM_EVENT(kvm, 4, "inject: sclp parm:%x", s390int->parm);
1419                 inti->ext.ext_params = s390int->parm;
1420                 break;
1421         case KVM_S390_INT_PFAULT_DONE:
1422                 inti->ext.ext_params2 = s390int->parm64;
1423                 break;
1424         case KVM_S390_MCHK:
1425                 VM_EVENT(kvm, 3, "inject: machine check mcic 0x%llx",
1426                          s390int->parm64);
1427                 inti->mchk.cr14 = s390int->parm; /* upper bits are not used */
1428                 inti->mchk.mcic = s390int->parm64;
1429                 break;
1430         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1431                 if (inti->type & KVM_S390_INT_IO_AI_MASK)
1432                         VM_EVENT(kvm, 5, "%s", "inject: I/O (AI)");
1433                 else
1434                         VM_EVENT(kvm, 5, "inject: I/O css %x ss %x schid %04x",
1435                                  s390int->type & IOINT_CSSID_MASK,
1436                                  s390int->type & IOINT_SSID_MASK,
1437                                  s390int->type & IOINT_SCHID_MASK);
1438                 inti->io.subchannel_id = s390int->parm >> 16;
1439                 inti->io.subchannel_nr = s390int->parm & 0x0000ffffu;
1440                 inti->io.io_int_parm = s390int->parm64 >> 32;
1441                 inti->io.io_int_word = s390int->parm64 & 0x00000000ffffffffull;
1442                 break;
1443         default:
1444                 kfree(inti);
1445                 return -EINVAL;
1446         }
1447         trace_kvm_s390_inject_vm(s390int->type, s390int->parm, s390int->parm64,
1448                                  2);
1449
1450         rc = __inject_vm(kvm, inti);
1451         if (rc)
1452                 kfree(inti);
1453         return rc;
1454 }
1455
1456 int kvm_s390_reinject_io_int(struct kvm *kvm,
1457                               struct kvm_s390_interrupt_info *inti)
1458 {
1459         return __inject_vm(kvm, inti);
1460 }
1461
1462 int s390int_to_s390irq(struct kvm_s390_interrupt *s390int,
1463                        struct kvm_s390_irq *irq)
1464 {
1465         irq->type = s390int->type;
1466         switch (irq->type) {
1467         case KVM_S390_PROGRAM_INT:
1468                 if (s390int->parm & 0xffff0000)
1469                         return -EINVAL;
1470                 irq->u.pgm.code = s390int->parm;
1471                 break;
1472         case KVM_S390_SIGP_SET_PREFIX:
1473                 irq->u.prefix.address = s390int->parm;
1474                 break;
1475         case KVM_S390_SIGP_STOP:
1476                 irq->u.stop.flags = s390int->parm;
1477                 break;
1478         case KVM_S390_INT_EXTERNAL_CALL:
1479                 if (s390int->parm & 0xffff0000)
1480                         return -EINVAL;
1481                 irq->u.extcall.code = s390int->parm;
1482                 break;
1483         case KVM_S390_INT_EMERGENCY:
1484                 if (s390int->parm & 0xffff0000)
1485                         return -EINVAL;
1486                 irq->u.emerg.code = s390int->parm;
1487                 break;
1488         case KVM_S390_MCHK:
1489                 irq->u.mchk.mcic = s390int->parm64;
1490                 break;
1491         }
1492         return 0;
1493 }
1494
1495 int kvm_s390_is_stop_irq_pending(struct kvm_vcpu *vcpu)
1496 {
1497         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1498
1499         return test_bit(IRQ_PEND_SIGP_STOP, &li->pending_irqs);
1500 }
1501
1502 void kvm_s390_clear_stop_irq(struct kvm_vcpu *vcpu)
1503 {
1504         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1505
1506         spin_lock(&li->lock);
1507         li->irq.stop.flags = 0;
1508         clear_bit(IRQ_PEND_SIGP_STOP, &li->pending_irqs);
1509         spin_unlock(&li->lock);
1510 }
1511
1512 static int do_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1513 {
1514         int rc;
1515
1516         switch (irq->type) {
1517         case KVM_S390_PROGRAM_INT:
1518                 rc = __inject_prog(vcpu, irq);
1519                 break;
1520         case KVM_S390_SIGP_SET_PREFIX:
1521                 rc = __inject_set_prefix(vcpu, irq);
1522                 break;
1523         case KVM_S390_SIGP_STOP:
1524                 rc = __inject_sigp_stop(vcpu, irq);
1525                 break;
1526         case KVM_S390_RESTART:
1527                 rc = __inject_sigp_restart(vcpu, irq);
1528                 break;
1529         case KVM_S390_INT_CLOCK_COMP:
1530                 rc = __inject_ckc(vcpu);
1531                 break;
1532         case KVM_S390_INT_CPU_TIMER:
1533                 rc = __inject_cpu_timer(vcpu);
1534                 break;
1535         case KVM_S390_INT_EXTERNAL_CALL:
1536                 rc = __inject_extcall(vcpu, irq);
1537                 break;
1538         case KVM_S390_INT_EMERGENCY:
1539                 rc = __inject_sigp_emergency(vcpu, irq);
1540                 break;
1541         case KVM_S390_MCHK:
1542                 rc = __inject_mchk(vcpu, irq);
1543                 break;
1544         case KVM_S390_INT_PFAULT_INIT:
1545                 rc = __inject_pfault_init(vcpu, irq);
1546                 break;
1547         case KVM_S390_INT_VIRTIO:
1548         case KVM_S390_INT_SERVICE:
1549         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1550         default:
1551                 rc = -EINVAL;
1552         }
1553
1554         return rc;
1555 }
1556
1557 int kvm_s390_inject_vcpu(struct kvm_vcpu *vcpu, struct kvm_s390_irq *irq)
1558 {
1559         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
1560         int rc;
1561
1562         spin_lock(&li->lock);
1563         rc = do_inject_vcpu(vcpu, irq);
1564         spin_unlock(&li->lock);
1565         if (!rc)
1566                 kvm_s390_vcpu_wakeup(vcpu);
1567         return rc;
1568 }
1569
1570 static inline void clear_irq_list(struct list_head *_list)
1571 {
1572         struct kvm_s390_interrupt_info *inti, *n;
1573
1574         list_for_each_entry_safe(inti, n, _list, list) {
1575                 list_del(&inti->list);
1576                 kfree(inti);
1577         }
1578 }
1579
1580 static void inti_to_irq(struct kvm_s390_interrupt_info *inti,
1581                        struct kvm_s390_irq *irq)
1582 {
1583         irq->type = inti->type;
1584         switch (inti->type) {
1585         case KVM_S390_INT_PFAULT_INIT:
1586         case KVM_S390_INT_PFAULT_DONE:
1587         case KVM_S390_INT_VIRTIO:
1588                 irq->u.ext = inti->ext;
1589                 break;
1590         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1591                 irq->u.io = inti->io;
1592                 break;
1593         }
1594 }
1595
1596 void kvm_s390_clear_float_irqs(struct kvm *kvm)
1597 {
1598         struct kvm_s390_float_interrupt *fi = &kvm->arch.float_int;
1599         int i;
1600
1601         spin_lock(&fi->lock);
1602         fi->pending_irqs = 0;
1603         memset(&fi->srv_signal, 0, sizeof(fi->srv_signal));
1604         memset(&fi->mchk, 0, sizeof(fi->mchk));
1605         for (i = 0; i < FIRQ_LIST_COUNT; i++)
1606                 clear_irq_list(&fi->lists[i]);
1607         for (i = 0; i < FIRQ_MAX_COUNT; i++)
1608                 fi->counters[i] = 0;
1609         spin_unlock(&fi->lock);
1610 };
1611
1612 static int get_all_floating_irqs(struct kvm *kvm, u8 __user *usrbuf, u64 len)
1613 {
1614         struct kvm_s390_interrupt_info *inti;
1615         struct kvm_s390_float_interrupt *fi;
1616         struct kvm_s390_irq *buf;
1617         struct kvm_s390_irq *irq;
1618         int max_irqs;
1619         int ret = 0;
1620         int n = 0;
1621         int i;
1622
1623         if (len > KVM_S390_FLIC_MAX_BUFFER || len == 0)
1624                 return -EINVAL;
1625
1626         /*
1627          * We are already using -ENOMEM to signal
1628          * userspace it may retry with a bigger buffer,
1629          * so we need to use something else for this case
1630          */
1631         buf = vzalloc(len);
1632         if (!buf)
1633                 return -ENOBUFS;
1634
1635         max_irqs = len / sizeof(struct kvm_s390_irq);
1636
1637         fi = &kvm->arch.float_int;
1638         spin_lock(&fi->lock);
1639         for (i = 0; i < FIRQ_LIST_COUNT; i++) {
1640                 list_for_each_entry(inti, &fi->lists[i], list) {
1641                         if (n == max_irqs) {
1642                                 /* signal userspace to try again */
1643                                 ret = -ENOMEM;
1644                                 goto out;
1645                         }
1646                         inti_to_irq(inti, &buf[n]);
1647                         n++;
1648                 }
1649         }
1650         if (test_bit(IRQ_PEND_EXT_SERVICE, &fi->pending_irqs)) {
1651                 if (n == max_irqs) {
1652                         /* signal userspace to try again */
1653                         ret = -ENOMEM;
1654                         goto out;
1655                 }
1656                 irq = (struct kvm_s390_irq *) &buf[n];
1657                 irq->type = KVM_S390_INT_SERVICE;
1658                 irq->u.ext = fi->srv_signal;
1659                 n++;
1660         }
1661         if (test_bit(IRQ_PEND_MCHK_REP, &fi->pending_irqs)) {
1662                 if (n == max_irqs) {
1663                                 /* signal userspace to try again */
1664                                 ret = -ENOMEM;
1665                                 goto out;
1666                 }
1667                 irq = (struct kvm_s390_irq *) &buf[n];
1668                 irq->type = KVM_S390_MCHK;
1669                 irq->u.mchk = fi->mchk;
1670                 n++;
1671 }
1672
1673 out:
1674         spin_unlock(&fi->lock);
1675         if (!ret && n > 0) {
1676                 if (copy_to_user(usrbuf, buf, sizeof(struct kvm_s390_irq) * n))
1677                         ret = -EFAULT;
1678         }
1679         vfree(buf);
1680
1681         return ret < 0 ? ret : n;
1682 }
1683
1684 static int flic_get_attr(struct kvm_device *dev, struct kvm_device_attr *attr)
1685 {
1686         int r;
1687
1688         switch (attr->group) {
1689         case KVM_DEV_FLIC_GET_ALL_IRQS:
1690                 r = get_all_floating_irqs(dev->kvm, (u8 __user *) attr->addr,
1691                                           attr->attr);
1692                 break;
1693         default:
1694                 r = -EINVAL;
1695         }
1696
1697         return r;
1698 }
1699
1700 static inline int copy_irq_from_user(struct kvm_s390_interrupt_info *inti,
1701                                      u64 addr)
1702 {
1703         struct kvm_s390_irq __user *uptr = (struct kvm_s390_irq __user *) addr;
1704         void *target = NULL;
1705         void __user *source;
1706         u64 size;
1707
1708         if (get_user(inti->type, (u64 __user *)addr))
1709                 return -EFAULT;
1710
1711         switch (inti->type) {
1712         case KVM_S390_INT_PFAULT_INIT:
1713         case KVM_S390_INT_PFAULT_DONE:
1714         case KVM_S390_INT_VIRTIO:
1715         case KVM_S390_INT_SERVICE:
1716                 target = (void *) &inti->ext;
1717                 source = &uptr->u.ext;
1718                 size = sizeof(inti->ext);
1719                 break;
1720         case KVM_S390_INT_IO_MIN...KVM_S390_INT_IO_MAX:
1721                 target = (void *) &inti->io;
1722                 source = &uptr->u.io;
1723                 size = sizeof(inti->io);
1724                 break;
1725         case KVM_S390_MCHK:
1726                 target = (void *) &inti->mchk;
1727                 source = &uptr->u.mchk;
1728                 size = sizeof(inti->mchk);
1729                 break;
1730         default:
1731                 return -EINVAL;
1732         }
1733
1734         if (copy_from_user(target, source, size))
1735                 return -EFAULT;
1736
1737         return 0;
1738 }
1739
1740 static int enqueue_floating_irq(struct kvm_device *dev,
1741                                 struct kvm_device_attr *attr)
1742 {
1743         struct kvm_s390_interrupt_info *inti = NULL;
1744         int r = 0;
1745         int len = attr->attr;
1746
1747         if (len % sizeof(struct kvm_s390_irq) != 0)
1748                 return -EINVAL;
1749         else if (len > KVM_S390_FLIC_MAX_BUFFER)
1750                 return -EINVAL;
1751
1752         while (len >= sizeof(struct kvm_s390_irq)) {
1753                 inti = kzalloc(sizeof(*inti), GFP_KERNEL);
1754                 if (!inti)
1755                         return -ENOMEM;
1756
1757                 r = copy_irq_from_user(inti, attr->addr);
1758                 if (r) {
1759                         kfree(inti);
1760                         return r;
1761                 }
1762                 r = __inject_vm(dev->kvm, inti);
1763                 if (r) {
1764                         kfree(inti);
1765                         return r;
1766                 }
1767                 len -= sizeof(struct kvm_s390_irq);
1768                 attr->addr += sizeof(struct kvm_s390_irq);
1769         }
1770
1771         return r;
1772 }
1773
1774 static struct s390_io_adapter *get_io_adapter(struct kvm *kvm, unsigned int id)
1775 {
1776         if (id >= MAX_S390_IO_ADAPTERS)
1777                 return NULL;
1778         return kvm->arch.adapters[id];
1779 }
1780
1781 static int register_io_adapter(struct kvm_device *dev,
1782                                struct kvm_device_attr *attr)
1783 {
1784         struct s390_io_adapter *adapter;
1785         struct kvm_s390_io_adapter adapter_info;
1786
1787         if (copy_from_user(&adapter_info,
1788                            (void __user *)attr->addr, sizeof(adapter_info)))
1789                 return -EFAULT;
1790
1791         if ((adapter_info.id >= MAX_S390_IO_ADAPTERS) ||
1792             (dev->kvm->arch.adapters[adapter_info.id] != NULL))
1793                 return -EINVAL;
1794
1795         adapter = kzalloc(sizeof(*adapter), GFP_KERNEL);
1796         if (!adapter)
1797                 return -ENOMEM;
1798
1799         INIT_LIST_HEAD(&adapter->maps);
1800         init_rwsem(&adapter->maps_lock);
1801         atomic_set(&adapter->nr_maps, 0);
1802         adapter->id = adapter_info.id;
1803         adapter->isc = adapter_info.isc;
1804         adapter->maskable = adapter_info.maskable;
1805         adapter->masked = false;
1806         adapter->swap = adapter_info.swap;
1807         dev->kvm->arch.adapters[adapter->id] = adapter;
1808
1809         return 0;
1810 }
1811
1812 int kvm_s390_mask_adapter(struct kvm *kvm, unsigned int id, bool masked)
1813 {
1814         int ret;
1815         struct s390_io_adapter *adapter = get_io_adapter(kvm, id);
1816
1817         if (!adapter || !adapter->maskable)
1818                 return -EINVAL;
1819         ret = adapter->masked;
1820         adapter->masked = masked;
1821         return ret;
1822 }
1823
1824 static int kvm_s390_adapter_map(struct kvm *kvm, unsigned int id, __u64 addr)
1825 {
1826         struct s390_io_adapter *adapter = get_io_adapter(kvm, id);
1827         struct s390_map_info *map;
1828         int ret;
1829
1830         if (!adapter || !addr)
1831                 return -EINVAL;
1832
1833         map = kzalloc(sizeof(*map), GFP_KERNEL);
1834         if (!map) {
1835                 ret = -ENOMEM;
1836                 goto out;
1837         }
1838         INIT_LIST_HEAD(&map->list);
1839         map->guest_addr = addr;
1840         map->addr = gmap_translate(kvm->arch.gmap, addr);
1841         if (map->addr == -EFAULT) {
1842                 ret = -EFAULT;
1843                 goto out;
1844         }
1845         ret = get_user_pages_fast(map->addr, 1, 1, &map->page);
1846         if (ret < 0)
1847                 goto out;
1848         BUG_ON(ret != 1);
1849         down_write(&adapter->maps_lock);
1850         if (atomic_inc_return(&adapter->nr_maps) < MAX_S390_ADAPTER_MAPS) {
1851                 list_add_tail(&map->list, &adapter->maps);
1852                 ret = 0;
1853         } else {
1854                 put_page(map->page);
1855                 ret = -EINVAL;
1856         }
1857         up_write(&adapter->maps_lock);
1858 out:
1859         if (ret)
1860                 kfree(map);
1861         return ret;
1862 }
1863
1864 static int kvm_s390_adapter_unmap(struct kvm *kvm, unsigned int id, __u64 addr)
1865 {
1866         struct s390_io_adapter *adapter = get_io_adapter(kvm, id);
1867         struct s390_map_info *map, *tmp;
1868         int found = 0;
1869
1870         if (!adapter || !addr)
1871                 return -EINVAL;
1872
1873         down_write(&adapter->maps_lock);
1874         list_for_each_entry_safe(map, tmp, &adapter->maps, list) {
1875                 if (map->guest_addr == addr) {
1876                         found = 1;
1877                         atomic_dec(&adapter->nr_maps);
1878                         list_del(&map->list);
1879                         put_page(map->page);
1880                         kfree(map);
1881                         break;
1882                 }
1883         }
1884         up_write(&adapter->maps_lock);
1885
1886         return found ? 0 : -EINVAL;
1887 }
1888
1889 void kvm_s390_destroy_adapters(struct kvm *kvm)
1890 {
1891         int i;
1892         struct s390_map_info *map, *tmp;
1893
1894         for (i = 0; i < MAX_S390_IO_ADAPTERS; i++) {
1895                 if (!kvm->arch.adapters[i])
1896                         continue;
1897                 list_for_each_entry_safe(map, tmp,
1898                                          &kvm->arch.adapters[i]->maps, list) {
1899                         list_del(&map->list);
1900                         put_page(map->page);
1901                         kfree(map);
1902                 }
1903                 kfree(kvm->arch.adapters[i]);
1904         }
1905 }
1906
1907 static int modify_io_adapter(struct kvm_device *dev,
1908                              struct kvm_device_attr *attr)
1909 {
1910         struct kvm_s390_io_adapter_req req;
1911         struct s390_io_adapter *adapter;
1912         int ret;
1913
1914         if (copy_from_user(&req, (void __user *)attr->addr, sizeof(req)))
1915                 return -EFAULT;
1916
1917         adapter = get_io_adapter(dev->kvm, req.id);
1918         if (!adapter)
1919                 return -EINVAL;
1920         switch (req.type) {
1921         case KVM_S390_IO_ADAPTER_MASK:
1922                 ret = kvm_s390_mask_adapter(dev->kvm, req.id, req.mask);
1923                 if (ret > 0)
1924                         ret = 0;
1925                 break;
1926         case KVM_S390_IO_ADAPTER_MAP:
1927                 ret = kvm_s390_adapter_map(dev->kvm, req.id, req.addr);
1928                 break;
1929         case KVM_S390_IO_ADAPTER_UNMAP:
1930                 ret = kvm_s390_adapter_unmap(dev->kvm, req.id, req.addr);
1931                 break;
1932         default:
1933                 ret = -EINVAL;
1934         }
1935
1936         return ret;
1937 }
1938
1939 static int flic_set_attr(struct kvm_device *dev, struct kvm_device_attr *attr)
1940 {
1941         int r = 0;
1942         unsigned int i;
1943         struct kvm_vcpu *vcpu;
1944
1945         switch (attr->group) {
1946         case KVM_DEV_FLIC_ENQUEUE:
1947                 r = enqueue_floating_irq(dev, attr);
1948                 break;
1949         case KVM_DEV_FLIC_CLEAR_IRQS:
1950                 kvm_s390_clear_float_irqs(dev->kvm);
1951                 break;
1952         case KVM_DEV_FLIC_APF_ENABLE:
1953                 dev->kvm->arch.gmap->pfault_enabled = 1;
1954                 break;
1955         case KVM_DEV_FLIC_APF_DISABLE_WAIT:
1956                 dev->kvm->arch.gmap->pfault_enabled = 0;
1957                 /*
1958                  * Make sure no async faults are in transition when
1959                  * clearing the queues. So we don't need to worry
1960                  * about late coming workers.
1961                  */
1962                 synchronize_srcu(&dev->kvm->srcu);
1963                 kvm_for_each_vcpu(i, vcpu, dev->kvm)
1964                         kvm_clear_async_pf_completion_queue(vcpu);
1965                 break;
1966         case KVM_DEV_FLIC_ADAPTER_REGISTER:
1967                 r = register_io_adapter(dev, attr);
1968                 break;
1969         case KVM_DEV_FLIC_ADAPTER_MODIFY:
1970                 r = modify_io_adapter(dev, attr);
1971                 break;
1972         default:
1973                 r = -EINVAL;
1974         }
1975
1976         return r;
1977 }
1978
1979 static int flic_create(struct kvm_device *dev, u32 type)
1980 {
1981         if (!dev)
1982                 return -EINVAL;
1983         if (dev->kvm->arch.flic)
1984                 return -EINVAL;
1985         dev->kvm->arch.flic = dev;
1986         return 0;
1987 }
1988
1989 static void flic_destroy(struct kvm_device *dev)
1990 {
1991         dev->kvm->arch.flic = NULL;
1992         kfree(dev);
1993 }
1994
1995 /* s390 floating irq controller (flic) */
1996 struct kvm_device_ops kvm_flic_ops = {
1997         .name = "kvm-flic",
1998         .get_attr = flic_get_attr,
1999         .set_attr = flic_set_attr,
2000         .create = flic_create,
2001         .destroy = flic_destroy,
2002 };
2003
2004 static unsigned long get_ind_bit(__u64 addr, unsigned long bit_nr, bool swap)
2005 {
2006         unsigned long bit;
2007
2008         bit = bit_nr + (addr % PAGE_SIZE) * 8;
2009
2010         return swap ? (bit ^ (BITS_PER_LONG - 1)) : bit;
2011 }
2012
2013 static struct s390_map_info *get_map_info(struct s390_io_adapter *adapter,
2014                                           u64 addr)
2015 {
2016         struct s390_map_info *map;
2017
2018         if (!adapter)
2019                 return NULL;
2020
2021         list_for_each_entry(map, &adapter->maps, list) {
2022                 if (map->guest_addr == addr)
2023                         return map;
2024         }
2025         return NULL;
2026 }
2027
2028 static int adapter_indicators_set(struct kvm *kvm,
2029                                   struct s390_io_adapter *adapter,
2030                                   struct kvm_s390_adapter_int *adapter_int)
2031 {
2032         unsigned long bit;
2033         int summary_set, idx;
2034         struct s390_map_info *info;
2035         void *map;
2036
2037         info = get_map_info(adapter, adapter_int->ind_addr);
2038         if (!info)
2039                 return -1;
2040         map = page_address(info->page);
2041         bit = get_ind_bit(info->addr, adapter_int->ind_offset, adapter->swap);
2042         set_bit(bit, map);
2043         idx = srcu_read_lock(&kvm->srcu);
2044         mark_page_dirty(kvm, info->guest_addr >> PAGE_SHIFT);
2045         set_page_dirty_lock(info->page);
2046         info = get_map_info(adapter, adapter_int->summary_addr);
2047         if (!info) {
2048                 srcu_read_unlock(&kvm->srcu, idx);
2049                 return -1;
2050         }
2051         map = page_address(info->page);
2052         bit = get_ind_bit(info->addr, adapter_int->summary_offset,
2053                           adapter->swap);
2054         summary_set = test_and_set_bit(bit, map);
2055         mark_page_dirty(kvm, info->guest_addr >> PAGE_SHIFT);
2056         set_page_dirty_lock(info->page);
2057         srcu_read_unlock(&kvm->srcu, idx);
2058         return summary_set ? 0 : 1;
2059 }
2060
2061 /*
2062  * < 0 - not injected due to error
2063  * = 0 - coalesced, summary indicator already active
2064  * > 0 - injected interrupt
2065  */
2066 static int set_adapter_int(struct kvm_kernel_irq_routing_entry *e,
2067                            struct kvm *kvm, int irq_source_id, int level,
2068                            bool line_status)
2069 {
2070         int ret;
2071         struct s390_io_adapter *adapter;
2072
2073         /* We're only interested in the 0->1 transition. */
2074         if (!level)
2075                 return 0;
2076         adapter = get_io_adapter(kvm, e->adapter.adapter_id);
2077         if (!adapter)
2078                 return -1;
2079         down_read(&adapter->maps_lock);
2080         ret = adapter_indicators_set(kvm, adapter, &e->adapter);
2081         up_read(&adapter->maps_lock);
2082         if ((ret > 0) && !adapter->masked) {
2083                 struct kvm_s390_interrupt s390int = {
2084                         .type = KVM_S390_INT_IO(1, 0, 0, 0),
2085                         .parm = 0,
2086                         .parm64 = (adapter->isc << 27) | 0x80000000,
2087                 };
2088                 ret = kvm_s390_inject_vm(kvm, &s390int);
2089                 if (ret == 0)
2090                         ret = 1;
2091         }
2092         return ret;
2093 }
2094
2095 int kvm_set_routing_entry(struct kvm_kernel_irq_routing_entry *e,
2096                           const struct kvm_irq_routing_entry *ue)
2097 {
2098         int ret;
2099
2100         switch (ue->type) {
2101         case KVM_IRQ_ROUTING_S390_ADAPTER:
2102                 e->set = set_adapter_int;
2103                 e->adapter.summary_addr = ue->u.adapter.summary_addr;
2104                 e->adapter.ind_addr = ue->u.adapter.ind_addr;
2105                 e->adapter.summary_offset = ue->u.adapter.summary_offset;
2106                 e->adapter.ind_offset = ue->u.adapter.ind_offset;
2107                 e->adapter.adapter_id = ue->u.adapter.adapter_id;
2108                 ret = 0;
2109                 break;
2110         default:
2111                 ret = -EINVAL;
2112         }
2113
2114         return ret;
2115 }
2116
2117 int kvm_set_msi(struct kvm_kernel_irq_routing_entry *e, struct kvm *kvm,
2118                 int irq_source_id, int level, bool line_status)
2119 {
2120         return -EINVAL;
2121 }
2122
2123 int kvm_s390_set_irq_state(struct kvm_vcpu *vcpu, void __user *irqstate, int len)
2124 {
2125         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
2126         struct kvm_s390_irq *buf;
2127         int r = 0;
2128         int n;
2129
2130         buf = vmalloc(len);
2131         if (!buf)
2132                 return -ENOMEM;
2133
2134         if (copy_from_user((void *) buf, irqstate, len)) {
2135                 r = -EFAULT;
2136                 goto out_free;
2137         }
2138
2139         /*
2140          * Don't allow setting the interrupt state
2141          * when there are already interrupts pending
2142          */
2143         spin_lock(&li->lock);
2144         if (li->pending_irqs) {
2145                 r = -EBUSY;
2146                 goto out_unlock;
2147         }
2148
2149         for (n = 0; n < len / sizeof(*buf); n++) {
2150                 r = do_inject_vcpu(vcpu, &buf[n]);
2151                 if (r)
2152                         break;
2153         }
2154
2155 out_unlock:
2156         spin_unlock(&li->lock);
2157 out_free:
2158         vfree(buf);
2159
2160         return r;
2161 }
2162
2163 static void store_local_irq(struct kvm_s390_local_interrupt *li,
2164                             struct kvm_s390_irq *irq,
2165                             unsigned long irq_type)
2166 {
2167         switch (irq_type) {
2168         case IRQ_PEND_MCHK_EX:
2169         case IRQ_PEND_MCHK_REP:
2170                 irq->type = KVM_S390_MCHK;
2171                 irq->u.mchk = li->irq.mchk;
2172                 break;
2173         case IRQ_PEND_PROG:
2174                 irq->type = KVM_S390_PROGRAM_INT;
2175                 irq->u.pgm = li->irq.pgm;
2176                 break;
2177         case IRQ_PEND_PFAULT_INIT:
2178                 irq->type = KVM_S390_INT_PFAULT_INIT;
2179                 irq->u.ext = li->irq.ext;
2180                 break;
2181         case IRQ_PEND_EXT_EXTERNAL:
2182                 irq->type = KVM_S390_INT_EXTERNAL_CALL;
2183                 irq->u.extcall = li->irq.extcall;
2184                 break;
2185         case IRQ_PEND_EXT_CLOCK_COMP:
2186                 irq->type = KVM_S390_INT_CLOCK_COMP;
2187                 break;
2188         case IRQ_PEND_EXT_CPU_TIMER:
2189                 irq->type = KVM_S390_INT_CPU_TIMER;
2190                 break;
2191         case IRQ_PEND_SIGP_STOP:
2192                 irq->type = KVM_S390_SIGP_STOP;
2193                 irq->u.stop = li->irq.stop;
2194                 break;
2195         case IRQ_PEND_RESTART:
2196                 irq->type = KVM_S390_RESTART;
2197                 break;
2198         case IRQ_PEND_SET_PREFIX:
2199                 irq->type = KVM_S390_SIGP_SET_PREFIX;
2200                 irq->u.prefix = li->irq.prefix;
2201                 break;
2202         }
2203 }
2204
2205 int kvm_s390_get_irq_state(struct kvm_vcpu *vcpu, __u8 __user *buf, int len)
2206 {
2207         uint8_t sigp_ctrl = vcpu->kvm->arch.sca->cpu[vcpu->vcpu_id].sigp_ctrl;
2208         unsigned long sigp_emerg_pending[BITS_TO_LONGS(KVM_MAX_VCPUS)];
2209         struct kvm_s390_local_interrupt *li = &vcpu->arch.local_int;
2210         unsigned long pending_irqs;
2211         struct kvm_s390_irq irq;
2212         unsigned long irq_type;
2213         int cpuaddr;
2214         int n = 0;
2215
2216         spin_lock(&li->lock);
2217         pending_irqs = li->pending_irqs;
2218         memcpy(&sigp_emerg_pending, &li->sigp_emerg_pending,
2219                sizeof(sigp_emerg_pending));
2220         spin_unlock(&li->lock);
2221
2222         for_each_set_bit(irq_type, &pending_irqs, IRQ_PEND_COUNT) {
2223                 memset(&irq, 0, sizeof(irq));
2224                 if (irq_type == IRQ_PEND_EXT_EMERGENCY)
2225                         continue;
2226                 if (n + sizeof(irq) > len)
2227                         return -ENOBUFS;
2228                 store_local_irq(&vcpu->arch.local_int, &irq, irq_type);
2229                 if (copy_to_user(&buf[n], &irq, sizeof(irq)))
2230                         return -EFAULT;
2231                 n += sizeof(irq);
2232         }
2233
2234         if (test_bit(IRQ_PEND_EXT_EMERGENCY, &pending_irqs)) {
2235                 for_each_set_bit(cpuaddr, sigp_emerg_pending, KVM_MAX_VCPUS) {
2236                         memset(&irq, 0, sizeof(irq));
2237                         if (n + sizeof(irq) > len)
2238                                 return -ENOBUFS;
2239                         irq.type = KVM_S390_INT_EMERGENCY;
2240                         irq.u.emerg.code = cpuaddr;
2241                         if (copy_to_user(&buf[n], &irq, sizeof(irq)))
2242                                 return -EFAULT;
2243                         n += sizeof(irq);
2244                 }
2245         }
2246
2247         if ((sigp_ctrl & SIGP_CTRL_C) &&
2248             (atomic_read(&vcpu->arch.sie_block->cpuflags) &
2249              CPUSTAT_ECALL_PEND)) {
2250                 if (n + sizeof(irq) > len)
2251                         return -ENOBUFS;
2252                 memset(&irq, 0, sizeof(irq));
2253                 irq.type = KVM_S390_INT_EXTERNAL_CALL;
2254                 irq.u.extcall.code = sigp_ctrl & SIGP_CTRL_SCN_MASK;
2255                 if (copy_to_user(&buf[n], &irq, sizeof(irq)))
2256                         return -EFAULT;
2257                 n += sizeof(irq);
2258         }
2259
2260         return n;
2261 }