• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 #ifndef _LINUX_KPROBES_H
2 #define _LINUX_KPROBES_H
3 /*
4  *  Kernel Probes (KProbes)
5  *  include/linux/kprobes.h
6  *
7  * This program is free software; you can redistribute it and/or modify
8  * it under the terms of the GNU General Public License as published by
9  * the Free Software Foundation; either version 2 of the License, or
10  * (at your option) any later version.
11  *
12  * This program is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
15  * GNU General Public License for more details.
16  *
17  * You should have received a copy of the GNU General Public License
18  * along with this program; if not, write to the Free Software
19  * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
20  *
21  * Copyright (C) IBM Corporation, 2002, 2004
22  *
23  * 2002-Oct	Created by Vamsi Krishna S <vamsi_krishna@in.ibm.com> Kernel
24  *		Probes initial implementation ( includes suggestions from
25  *		Rusty Russell).
26  * 2004-July	Suparna Bhattacharya <suparna@in.ibm.com> added jumper probes
27  *		interface to access function arguments.
28  * 2005-May	Hien Nguyen <hien@us.ibm.com> and Jim Keniston
29  *		<jkenisto@us.ibm.com>  and Prasanna S Panchamukhi
30  *		<prasanna@in.ibm.com> added function-return probes.
31  */
32 #include <linux/compiler.h>	/* for __kprobes */
33 #include <linux/linkage.h>
34 #include <linux/list.h>
35 #include <linux/notifier.h>
36 #include <linux/smp.h>
37 #include <linux/bug.h>
38 #include <linux/percpu.h>
39 #include <linux/spinlock.h>
40 #include <linux/rcupdate.h>
41 #include <linux/mutex.h>
42 #include <linux/ftrace.h>
43 
44 #ifdef CONFIG_KPROBES
45 #include <asm/kprobes.h>
46 
47 /* kprobe_status settings */
48 #define KPROBE_HIT_ACTIVE	0x00000001
49 #define KPROBE_HIT_SS		0x00000002
50 #define KPROBE_REENTER		0x00000004
51 #define KPROBE_HIT_SSDONE	0x00000008
52 
53 #else /* CONFIG_KPROBES */
54 typedef int kprobe_opcode_t;
55 struct arch_specific_insn {
56 	int dummy;
57 };
58 #endif /* CONFIG_KPROBES */
59 
60 struct kprobe;
61 struct pt_regs;
62 struct kretprobe;
63 struct kretprobe_instance;
64 typedef int (*kprobe_pre_handler_t) (struct kprobe *, struct pt_regs *);
65 typedef int (*kprobe_break_handler_t) (struct kprobe *, struct pt_regs *);
66 typedef void (*kprobe_post_handler_t) (struct kprobe *, struct pt_regs *,
67 				       unsigned long flags);
68 typedef int (*kprobe_fault_handler_t) (struct kprobe *, struct pt_regs *,
69 				       int trapnr);
70 typedef int (*kretprobe_handler_t) (struct kretprobe_instance *,
71 				    struct pt_regs *);
72 
73 struct kprobe {
74 	struct hlist_node hlist;
75 
76 	/* list of kprobes for multi-handler support */
77 	struct list_head list;
78 
79 	/*count the number of times this probe was temporarily disarmed */
80 	unsigned long nmissed;
81 
82 	/* location of the probe point */
83 	kprobe_opcode_t *addr;
84 
85 	/* Allow user to indicate symbol name of the probe point */
86 	const char *symbol_name;
87 
88 	/* Offset into the symbol */
89 	unsigned int offset;
90 
91 	/* Called before addr is executed. */
92 	kprobe_pre_handler_t pre_handler;
93 
94 	/* Called after addr is executed, unless... */
95 	kprobe_post_handler_t post_handler;
96 
97 	/*
98 	 * ... called if executing addr causes a fault (eg. page fault).
99 	 * Return 1 if it handled fault, otherwise kernel will see it.
100 	 */
101 	kprobe_fault_handler_t fault_handler;
102 
103 	/*
104 	 * ... called if breakpoint trap occurs in probe handler.
105 	 * Return 1 if it handled break, otherwise kernel will see it.
106 	 */
107 	kprobe_break_handler_t break_handler;
108 
109 	/* Saved opcode (which has been replaced with breakpoint) */
110 	kprobe_opcode_t opcode;
111 
112 	/* copy of the original instruction */
113 	struct arch_specific_insn ainsn;
114 
115 	/*
116 	 * Indicates various status flags.
117 	 * Protected by kprobe_mutex after this kprobe is registered.
118 	 */
119 	u32 flags;
120 };
121 
122 /* Kprobe status flags */
123 #define KPROBE_FLAG_GONE	1 /* breakpoint has already gone */
124 #define KPROBE_FLAG_DISABLED	2 /* probe is temporarily disabled */
125 #define KPROBE_FLAG_OPTIMIZED	4 /*
126 				   * probe is really optimized.
127 				   * NOTE:
128 				   * this flag is only for optimized_kprobe.
129 				   */
130 #define KPROBE_FLAG_FTRACE	8 /* probe is using ftrace */
131 
132 /* Has this kprobe gone ? */
kprobe_gone(struct kprobe * p)133 static inline int kprobe_gone(struct kprobe *p)
134 {
135 	return p->flags & KPROBE_FLAG_GONE;
136 }
137 
138 /* Is this kprobe disabled ? */
kprobe_disabled(struct kprobe * p)139 static inline int kprobe_disabled(struct kprobe *p)
140 {
141 	return p->flags & (KPROBE_FLAG_DISABLED | KPROBE_FLAG_GONE);
142 }
143 
144 /* Is this kprobe really running optimized path ? */
kprobe_optimized(struct kprobe * p)145 static inline int kprobe_optimized(struct kprobe *p)
146 {
147 	return p->flags & KPROBE_FLAG_OPTIMIZED;
148 }
149 
150 /* Is this kprobe uses ftrace ? */
kprobe_ftrace(struct kprobe * p)151 static inline int kprobe_ftrace(struct kprobe *p)
152 {
153 	return p->flags & KPROBE_FLAG_FTRACE;
154 }
155 
156 /*
157  * Special probe type that uses setjmp-longjmp type tricks to resume
158  * execution at a specified entry with a matching prototype corresponding
159  * to the probed function - a trick to enable arguments to become
160  * accessible seamlessly by probe handling logic.
161  * Note:
162  * Because of the way compilers allocate stack space for local variables
163  * etc upfront, regardless of sub-scopes within a function, this mirroring
164  * principle currently works only for probes placed on function entry points.
165  */
166 struct jprobe {
167 	struct kprobe kp;
168 	void *entry;	/* probe handling code to jump to */
169 };
170 
171 /* For backward compatibility with old code using JPROBE_ENTRY() */
172 #define JPROBE_ENTRY(handler)	(handler)
173 
174 /*
175  * Function-return probe -
176  * Note:
177  * User needs to provide a handler function, and initialize maxactive.
178  * maxactive - The maximum number of instances of the probed function that
179  * can be active concurrently.
180  * nmissed - tracks the number of times the probed function's return was
181  * ignored, due to maxactive being too low.
182  *
183  */
184 struct kretprobe {
185 	struct kprobe kp;
186 	kretprobe_handler_t handler;
187 	kretprobe_handler_t entry_handler;
188 	int maxactive;
189 	int nmissed;
190 	size_t data_size;
191 	struct hlist_head free_instances;
192 	raw_spinlock_t lock;
193 };
194 
195 #define KRETPROBE_MAX_DATA_SIZE	4096
196 
197 struct kretprobe_instance {
198 	struct hlist_node hlist;
199 	struct kretprobe *rp;
200 	kprobe_opcode_t *ret_addr;
201 	struct task_struct *task;
202 	void *fp;
203 	char data[0];
204 };
205 
206 struct kretprobe_blackpoint {
207 	const char *name;
208 	void *addr;
209 };
210 
211 struct kprobe_blacklist_entry {
212 	struct list_head list;
213 	unsigned long start_addr;
214 	unsigned long end_addr;
215 };
216 
217 #ifdef CONFIG_KPROBES
218 DECLARE_PER_CPU(struct kprobe *, current_kprobe);
219 DECLARE_PER_CPU(struct kprobe_ctlblk, kprobe_ctlblk);
220 
221 /*
222  * For #ifdef avoidance:
223  */
kprobes_built_in(void)224 static inline int kprobes_built_in(void)
225 {
226 	return 1;
227 }
228 
229 #ifdef CONFIG_KRETPROBES
230 extern void arch_prepare_kretprobe(struct kretprobe_instance *ri,
231 				   struct pt_regs *regs);
232 extern int arch_trampoline_kprobe(struct kprobe *p);
233 #else /* CONFIG_KRETPROBES */
arch_prepare_kretprobe(struct kretprobe * rp,struct pt_regs * regs)234 static inline void arch_prepare_kretprobe(struct kretprobe *rp,
235 					struct pt_regs *regs)
236 {
237 }
arch_trampoline_kprobe(struct kprobe * p)238 static inline int arch_trampoline_kprobe(struct kprobe *p)
239 {
240 	return 0;
241 }
242 #endif /* CONFIG_KRETPROBES */
243 
244 extern struct kretprobe_blackpoint kretprobe_blacklist[];
245 
kretprobe_assert(struct kretprobe_instance * ri,unsigned long orig_ret_address,unsigned long trampoline_address)246 static inline void kretprobe_assert(struct kretprobe_instance *ri,
247 	unsigned long orig_ret_address, unsigned long trampoline_address)
248 {
249 	if (!orig_ret_address || (orig_ret_address == trampoline_address)) {
250 		printk("kretprobe BUG!: Processing kretprobe %p @ %p\n",
251 				ri->rp, ri->rp->kp.addr);
252 		BUG();
253 	}
254 }
255 
256 #ifdef CONFIG_KPROBES_SANITY_TEST
257 extern int init_test_probes(void);
258 #else
init_test_probes(void)259 static inline int init_test_probes(void)
260 {
261 	return 0;
262 }
263 #endif /* CONFIG_KPROBES_SANITY_TEST */
264 
265 extern int arch_prepare_kprobe(struct kprobe *p);
266 extern void arch_arm_kprobe(struct kprobe *p);
267 extern void arch_disarm_kprobe(struct kprobe *p);
268 extern int arch_init_kprobes(void);
269 extern void show_registers(struct pt_regs *regs);
270 extern void kprobes_inc_nmissed_count(struct kprobe *p);
271 extern bool arch_within_kprobe_blacklist(unsigned long addr);
272 
273 extern bool within_kprobe_blacklist(unsigned long addr);
274 
275 struct kprobe_insn_cache {
276 	struct mutex mutex;
277 	void *(*alloc)(void);	/* allocate insn page */
278 	void (*free)(void *);	/* free insn page */
279 	struct list_head pages; /* list of kprobe_insn_page */
280 	size_t insn_size;	/* size of instruction slot */
281 	int nr_garbage;
282 };
283 
284 extern kprobe_opcode_t *__get_insn_slot(struct kprobe_insn_cache *c);
285 extern void __free_insn_slot(struct kprobe_insn_cache *c,
286 			     kprobe_opcode_t *slot, int dirty);
287 
288 #define DEFINE_INSN_CACHE_OPS(__name)					\
289 extern struct kprobe_insn_cache kprobe_##__name##_slots;		\
290 									\
291 static inline kprobe_opcode_t *get_##__name##_slot(void)		\
292 {									\
293 	return __get_insn_slot(&kprobe_##__name##_slots);		\
294 }									\
295 									\
296 static inline void free_##__name##_slot(kprobe_opcode_t *slot, int dirty)\
297 {									\
298 	__free_insn_slot(&kprobe_##__name##_slots, slot, dirty);	\
299 }									\
300 
301 DEFINE_INSN_CACHE_OPS(insn);
302 
303 #ifdef CONFIG_OPTPROBES
304 /*
305  * Internal structure for direct jump optimized probe
306  */
307 struct optimized_kprobe {
308 	struct kprobe kp;
309 	struct list_head list;	/* list for optimizing queue */
310 	struct arch_optimized_insn optinsn;
311 };
312 
313 /* Architecture dependent functions for direct jump optimization */
314 extern int arch_prepared_optinsn(struct arch_optimized_insn *optinsn);
315 extern int arch_check_optimized_kprobe(struct optimized_kprobe *op);
316 extern int arch_prepare_optimized_kprobe(struct optimized_kprobe *op,
317 					 struct kprobe *orig);
318 extern void arch_remove_optimized_kprobe(struct optimized_kprobe *op);
319 extern void arch_optimize_kprobes(struct list_head *oplist);
320 extern void arch_unoptimize_kprobes(struct list_head *oplist,
321 				    struct list_head *done_list);
322 extern void arch_unoptimize_kprobe(struct optimized_kprobe *op);
323 extern int arch_within_optimized_kprobe(struct optimized_kprobe *op,
324 					unsigned long addr);
325 
326 extern void opt_pre_handler(struct kprobe *p, struct pt_regs *regs);
327 
328 DEFINE_INSN_CACHE_OPS(optinsn);
329 
330 #ifdef CONFIG_SYSCTL
331 extern int sysctl_kprobes_optimization;
332 extern int proc_kprobes_optimization_handler(struct ctl_table *table,
333 					     int write, void __user *buffer,
334 					     size_t *length, loff_t *ppos);
335 #endif
336 extern void wait_for_kprobe_optimizer(void);
337 #else
wait_for_kprobe_optimizer(void)338 static inline void wait_for_kprobe_optimizer(void) { }
339 #endif /* CONFIG_OPTPROBES */
340 #ifdef CONFIG_KPROBES_ON_FTRACE
341 extern void kprobe_ftrace_handler(unsigned long ip, unsigned long parent_ip,
342 				  struct ftrace_ops *ops, struct pt_regs *regs);
343 extern int arch_prepare_kprobe_ftrace(struct kprobe *p);
344 #endif
345 
346 int arch_check_ftrace_location(struct kprobe *p);
347 
348 /* Get the kprobe at this addr (if any) - called with preemption disabled */
349 struct kprobe *get_kprobe(void *addr);
350 void kretprobe_hash_lock(struct task_struct *tsk,
351 			 struct hlist_head **head, unsigned long *flags);
352 void kretprobe_hash_unlock(struct task_struct *tsk, unsigned long *flags);
353 struct hlist_head * kretprobe_inst_table_head(struct task_struct *tsk);
354 
355 /* kprobe_running() will just return the current_kprobe on this CPU */
kprobe_running(void)356 static inline struct kprobe *kprobe_running(void)
357 {
358 	return (__this_cpu_read(current_kprobe));
359 }
360 
reset_current_kprobe(void)361 static inline void reset_current_kprobe(void)
362 {
363 	__this_cpu_write(current_kprobe, NULL);
364 }
365 
get_kprobe_ctlblk(void)366 static inline struct kprobe_ctlblk *get_kprobe_ctlblk(void)
367 {
368 	return this_cpu_ptr(&kprobe_ctlblk);
369 }
370 
371 extern struct kprobe kprobe_busy;
372 void kprobe_busy_begin(void);
373 void kprobe_busy_end(void);
374 
375 int register_kprobe(struct kprobe *p);
376 void unregister_kprobe(struct kprobe *p);
377 int register_kprobes(struct kprobe **kps, int num);
378 void unregister_kprobes(struct kprobe **kps, int num);
379 int setjmp_pre_handler(struct kprobe *, struct pt_regs *);
380 int longjmp_break_handler(struct kprobe *, struct pt_regs *);
381 int register_jprobe(struct jprobe *p);
382 void unregister_jprobe(struct jprobe *p);
383 int register_jprobes(struct jprobe **jps, int num);
384 void unregister_jprobes(struct jprobe **jps, int num);
385 void jprobe_return(void);
386 unsigned long arch_deref_entry_point(void *);
387 
388 int register_kretprobe(struct kretprobe *rp);
389 void unregister_kretprobe(struct kretprobe *rp);
390 int register_kretprobes(struct kretprobe **rps, int num);
391 void unregister_kretprobes(struct kretprobe **rps, int num);
392 
393 void kprobe_flush_task(struct task_struct *tk);
394 void recycle_rp_inst(struct kretprobe_instance *ri, struct hlist_head *head);
395 
396 int disable_kprobe(struct kprobe *kp);
397 int enable_kprobe(struct kprobe *kp);
398 
399 void dump_kprobe(struct kprobe *kp);
400 
401 #else /* !CONFIG_KPROBES: */
402 
kprobes_built_in(void)403 static inline int kprobes_built_in(void)
404 {
405 	return 0;
406 }
kprobe_fault_handler(struct pt_regs * regs,int trapnr)407 static inline int kprobe_fault_handler(struct pt_regs *regs, int trapnr)
408 {
409 	return 0;
410 }
get_kprobe(void * addr)411 static inline struct kprobe *get_kprobe(void *addr)
412 {
413 	return NULL;
414 }
kprobe_running(void)415 static inline struct kprobe *kprobe_running(void)
416 {
417 	return NULL;
418 }
register_kprobe(struct kprobe * p)419 static inline int register_kprobe(struct kprobe *p)
420 {
421 	return -ENOSYS;
422 }
register_kprobes(struct kprobe ** kps,int num)423 static inline int register_kprobes(struct kprobe **kps, int num)
424 {
425 	return -ENOSYS;
426 }
unregister_kprobe(struct kprobe * p)427 static inline void unregister_kprobe(struct kprobe *p)
428 {
429 }
unregister_kprobes(struct kprobe ** kps,int num)430 static inline void unregister_kprobes(struct kprobe **kps, int num)
431 {
432 }
register_jprobe(struct jprobe * p)433 static inline int register_jprobe(struct jprobe *p)
434 {
435 	return -ENOSYS;
436 }
register_jprobes(struct jprobe ** jps,int num)437 static inline int register_jprobes(struct jprobe **jps, int num)
438 {
439 	return -ENOSYS;
440 }
unregister_jprobe(struct jprobe * p)441 static inline void unregister_jprobe(struct jprobe *p)
442 {
443 }
unregister_jprobes(struct jprobe ** jps,int num)444 static inline void unregister_jprobes(struct jprobe **jps, int num)
445 {
446 }
jprobe_return(void)447 static inline void jprobe_return(void)
448 {
449 }
register_kretprobe(struct kretprobe * rp)450 static inline int register_kretprobe(struct kretprobe *rp)
451 {
452 	return -ENOSYS;
453 }
register_kretprobes(struct kretprobe ** rps,int num)454 static inline int register_kretprobes(struct kretprobe **rps, int num)
455 {
456 	return -ENOSYS;
457 }
unregister_kretprobe(struct kretprobe * rp)458 static inline void unregister_kretprobe(struct kretprobe *rp)
459 {
460 }
unregister_kretprobes(struct kretprobe ** rps,int num)461 static inline void unregister_kretprobes(struct kretprobe **rps, int num)
462 {
463 }
kprobe_flush_task(struct task_struct * tk)464 static inline void kprobe_flush_task(struct task_struct *tk)
465 {
466 }
disable_kprobe(struct kprobe * kp)467 static inline int disable_kprobe(struct kprobe *kp)
468 {
469 	return -ENOSYS;
470 }
enable_kprobe(struct kprobe * kp)471 static inline int enable_kprobe(struct kprobe *kp)
472 {
473 	return -ENOSYS;
474 }
475 #endif /* CONFIG_KPROBES */
disable_kretprobe(struct kretprobe * rp)476 static inline int disable_kretprobe(struct kretprobe *rp)
477 {
478 	return disable_kprobe(&rp->kp);
479 }
enable_kretprobe(struct kretprobe * rp)480 static inline int enable_kretprobe(struct kretprobe *rp)
481 {
482 	return enable_kprobe(&rp->kp);
483 }
disable_jprobe(struct jprobe * jp)484 static inline int disable_jprobe(struct jprobe *jp)
485 {
486 	return disable_kprobe(&jp->kp);
487 }
enable_jprobe(struct jprobe * jp)488 static inline int enable_jprobe(struct jprobe *jp)
489 {
490 	return enable_kprobe(&jp->kp);
491 }
492 
493 #ifdef CONFIG_KPROBES
494 /*
495  * Blacklist ganerating macro. Specify functions which is not probed
496  * by using this macro.
497  */
498 #define __NOKPROBE_SYMBOL(fname)			\
499 static unsigned long __used				\
500 	__attribute__((section("_kprobe_blacklist")))	\
501 	_kbl_addr_##fname = (unsigned long)fname;
502 #define NOKPROBE_SYMBOL(fname)	__NOKPROBE_SYMBOL(fname)
503 #else
504 #define NOKPROBE_SYMBOL(fname)
505 #endif
506 
507 #endif /* _LINUX_KPROBES_H */
508