• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3  * ELF loader for kexec_file_load system call.
4  *
5  * Copyright IBM Corp. 2018
6  *
7  * Author(s): Philipp Rudo <prudo@linux.vnet.ibm.com>
8  */
9 
10 #include <linux/errno.h>
11 #include <linux/kernel.h>
12 #include <linux/kexec.h>
13 #include <asm/setup.h>
14 
kexec_file_add_elf_kernel(struct kimage * image,struct s390_load_data * data,char * kernel,unsigned long kernel_len)15 static int kexec_file_add_elf_kernel(struct kimage *image,
16 				     struct s390_load_data *data,
17 				     char *kernel, unsigned long kernel_len)
18 {
19 	struct kexec_buf buf;
20 	const Elf_Ehdr *ehdr;
21 	const Elf_Phdr *phdr;
22 	Elf_Addr entry;
23 	int i, ret;
24 
25 	ehdr = (Elf_Ehdr *)kernel;
26 	buf.image = image;
27 	if (image->type == KEXEC_TYPE_CRASH)
28 		entry = STARTUP_KDUMP_OFFSET;
29 	else
30 		entry = ehdr->e_entry;
31 
32 	phdr = (void *)ehdr + ehdr->e_phoff;
33 	for (i = 0; i < ehdr->e_phnum; i++, phdr++) {
34 		if (phdr->p_type != PT_LOAD)
35 			continue;
36 
37 		buf.buffer = kernel + phdr->p_offset;
38 		buf.bufsz = phdr->p_filesz;
39 
40 		buf.mem = ALIGN(phdr->p_paddr, phdr->p_align);
41 		buf.memsz = phdr->p_memsz;
42 
43 		if (entry - phdr->p_paddr < phdr->p_memsz) {
44 			data->kernel_buf = buf.buffer;
45 			data->memsz += STARTUP_NORMAL_OFFSET;
46 
47 			buf.buffer += STARTUP_NORMAL_OFFSET;
48 			buf.bufsz -= STARTUP_NORMAL_OFFSET;
49 
50 			buf.mem += STARTUP_NORMAL_OFFSET;
51 			buf.memsz -= STARTUP_NORMAL_OFFSET;
52 		}
53 
54 		if (image->type == KEXEC_TYPE_CRASH)
55 			buf.mem += crashk_res.start;
56 
57 		ret = kexec_add_buffer(&buf);
58 		if (ret)
59 			return ret;
60 
61 		data->memsz = ALIGN(data->memsz, phdr->p_align) + buf.memsz;
62 	}
63 
64 	return 0;
65 }
66 
s390_elf_load(struct kimage * image,char * kernel,unsigned long kernel_len,char * initrd,unsigned long initrd_len,char * cmdline,unsigned long cmdline_len)67 static void *s390_elf_load(struct kimage *image,
68 			   char *kernel, unsigned long kernel_len,
69 			   char *initrd, unsigned long initrd_len,
70 			   char *cmdline, unsigned long cmdline_len)
71 {
72 	struct s390_load_data data = {0};
73 	const Elf_Ehdr *ehdr;
74 	const Elf_Phdr *phdr;
75 	size_t size;
76 	int i, ret;
77 
78 	/* image->fobs->probe already checked for valid ELF magic number. */
79 	ehdr = (Elf_Ehdr *)kernel;
80 
81 	if (ehdr->e_type != ET_EXEC ||
82 	    ehdr->e_ident[EI_CLASS] != ELFCLASS64 ||
83 	    !elf_check_arch(ehdr))
84 		return ERR_PTR(-EINVAL);
85 
86 	if (!ehdr->e_phnum || ehdr->e_phentsize != sizeof(Elf_Phdr))
87 		return ERR_PTR(-EINVAL);
88 
89 	size = ehdr->e_ehsize + ehdr->e_phoff;
90 	size += ehdr->e_phentsize * ehdr->e_phnum;
91 	if (size > kernel_len)
92 		return ERR_PTR(-EINVAL);
93 
94 	phdr = (void *)ehdr + ehdr->e_phoff;
95 	size = ALIGN(size, phdr->p_align);
96 	for (i = 0; i < ehdr->e_phnum; i++, phdr++) {
97 		if (phdr->p_type == PT_INTERP)
98 			return ERR_PTR(-EINVAL);
99 
100 		if (phdr->p_offset > kernel_len)
101 			return ERR_PTR(-EINVAL);
102 
103 		size += ALIGN(phdr->p_filesz, phdr->p_align);
104 	}
105 
106 	if (size > kernel_len)
107 		return ERR_PTR(-EINVAL);
108 
109 	ret = kexec_file_add_elf_kernel(image, &data, kernel, kernel_len);
110 	if (ret)
111 		return ERR_PTR(ret);
112 
113 	if (!data.memsz)
114 		return ERR_PTR(-EINVAL);
115 
116 	if (initrd) {
117 		ret = kexec_file_add_initrd(image, &data, initrd, initrd_len);
118 		if (ret)
119 			return ERR_PTR(ret);
120 	}
121 
122 	ret = kexec_file_add_purgatory(image, &data);
123 	if (ret)
124 		return ERR_PTR(ret);
125 
126 	return kexec_file_update_kernel(image, &data);
127 }
128 
s390_elf_probe(const char * buf,unsigned long len)129 static int s390_elf_probe(const char *buf, unsigned long len)
130 {
131 	const Elf_Ehdr *ehdr;
132 
133 	if (len < sizeof(Elf_Ehdr))
134 		return -ENOEXEC;
135 
136 	ehdr = (Elf_Ehdr *)buf;
137 
138 	/* Only check the ELF magic number here and do proper validity check
139 	 * in the loader. Any check here that fails would send the erroneous
140 	 * ELF file to the image loader that does not care what it gets.
141 	 * (Most likely) causing behavior not intended by the user.
142 	 */
143 	if (memcmp(ehdr->e_ident, ELFMAG, SELFMAG) != 0)
144 		return -ENOEXEC;
145 
146 	return 0;
147 }
148 
149 const struct kexec_file_ops s390_kexec_elf_ops = {
150 	.probe = s390_elf_probe,
151 	.load = s390_elf_load,
152 };
153