• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 // SPDX-License-Identifier: GPL-2.0-only
2 #include <linux/kernel.h>
3 #include <linux/mm.h>
4 #include <linux/smp.h>
5 #include <linux/spinlock.h>
6 #include <linux/stop_machine.h>
7 #include <linux/uaccess.h>
8 
9 #include <asm/cacheflush.h>
10 #include <asm/fixmap.h>
11 #include <asm/insn.h>
12 #include <asm/kprobes.h>
13 #include <asm/patching.h>
14 #include <asm/sections.h>
15 
16 static DEFINE_RAW_SPINLOCK(patch_lock);
17 
is_exit_text(unsigned long addr)18 static bool is_exit_text(unsigned long addr)
19 {
20 	/* discarded with init text/data */
21 	return system_state < SYSTEM_RUNNING &&
22 		addr >= (unsigned long)__exittext_begin &&
23 		addr < (unsigned long)__exittext_end;
24 }
25 
is_image_text(unsigned long addr)26 static bool is_image_text(unsigned long addr)
27 {
28 	return core_kernel_text(addr) || is_exit_text(addr);
29 }
30 
patch_map(void * addr,int fixmap)31 static void __kprobes *patch_map(void *addr, int fixmap)
32 {
33 	unsigned long uintaddr = (uintptr_t) addr;
34 	bool image = is_image_text(uintaddr);
35 	struct page *page;
36 
37 	if (image)
38 		page = phys_to_page(__pa_symbol(addr));
39 	else if (IS_ENABLED(CONFIG_STRICT_MODULE_RWX))
40 		page = vmalloc_to_page(addr);
41 	else
42 		return addr;
43 
44 	BUG_ON(!page);
45 	return (void *)set_fixmap_offset(fixmap, page_to_phys(page) +
46 			(uintaddr & ~PAGE_MASK));
47 }
48 
patch_unmap(int fixmap)49 static void __kprobes patch_unmap(int fixmap)
50 {
51 	clear_fixmap(fixmap);
52 }
53 /*
54  * In ARMv8-A, A64 instructions have a fixed length of 32 bits and are always
55  * little-endian.
56  */
aarch64_insn_read(void * addr,u32 * insnp)57 int __kprobes aarch64_insn_read(void *addr, u32 *insnp)
58 {
59 	int ret;
60 	__le32 val;
61 
62 	ret = copy_from_kernel_nofault(&val, addr, AARCH64_INSN_SIZE);
63 	if (!ret)
64 		*insnp = le32_to_cpu(val);
65 
66 	return ret;
67 }
68 
__aarch64_text_write(void * dst,void * src,size_t size)69 static int __kprobes __aarch64_text_write(void *dst, void *src, size_t size)
70 {
71 	unsigned long flags;
72 	void *waddr;
73 	int ret;
74 
75 	raw_spin_lock_irqsave(&patch_lock, flags);
76 	waddr = patch_map(dst, FIX_TEXT_POKE0);
77 
78 	ret = copy_to_kernel_nofault(waddr, src, size);
79 
80 	patch_unmap(FIX_TEXT_POKE0);
81 	raw_spin_unlock_irqrestore(&patch_lock, flags);
82 
83 	return ret;
84 }
85 
aarch64_insn_write(void * addr,u32 insn)86 int __kprobes aarch64_insn_write(void *addr, u32 insn)
87 {
88 	__le32 __insn = cpu_to_le32(insn);
89 
90 	return __aarch64_text_write(addr, &__insn, AARCH64_INSN_SIZE);
91 }
92 
aarch64_addr_write(void * addr,u64 dst)93 int __kprobes aarch64_addr_write(void *addr, u64 dst)
94 {
95 	return __aarch64_text_write(addr, &dst, sizeof(dst));
96 }
97 
aarch64_insn_patch_text_nosync(void * addr,u32 insn)98 int __kprobes aarch64_insn_patch_text_nosync(void *addr, u32 insn)
99 {
100 	u32 *tp = addr;
101 	int ret;
102 
103 	/* A64 instructions must be word aligned */
104 	if ((uintptr_t)tp & 0x3)
105 		return -EINVAL;
106 
107 	ret = aarch64_insn_write(tp, insn);
108 	if (ret == 0)
109 		caches_clean_inval_pou((uintptr_t)tp,
110 				     (uintptr_t)tp + AARCH64_INSN_SIZE);
111 
112 	return ret;
113 }
114 
115 struct aarch64_insn_patch {
116 	void		**text_addrs;
117 	u32		*new_insns;
118 	int		insn_cnt;
119 	atomic_t	cpu_count;
120 };
121 
aarch64_insn_patch_text_cb(void * arg)122 static int __kprobes aarch64_insn_patch_text_cb(void *arg)
123 {
124 	int i, ret = 0;
125 	struct aarch64_insn_patch *pp = arg;
126 
127 	/* The last CPU becomes master */
128 	if (atomic_inc_return(&pp->cpu_count) == num_online_cpus()) {
129 		for (i = 0; ret == 0 && i < pp->insn_cnt; i++)
130 			ret = aarch64_insn_patch_text_nosync(pp->text_addrs[i],
131 							     pp->new_insns[i]);
132 		/* Notify other processors with an additional increment. */
133 		atomic_inc(&pp->cpu_count);
134 	} else {
135 		while (atomic_read(&pp->cpu_count) <= num_online_cpus())
136 			cpu_relax();
137 		isb();
138 	}
139 
140 	return ret;
141 }
142 
aarch64_insn_patch_text(void * addrs[],u32 insns[],int cnt)143 int __kprobes aarch64_insn_patch_text(void *addrs[], u32 insns[], int cnt)
144 {
145 	struct aarch64_insn_patch patch = {
146 		.text_addrs = addrs,
147 		.new_insns = insns,
148 		.insn_cnt = cnt,
149 		.cpu_count = ATOMIC_INIT(0),
150 	};
151 
152 	if (cnt <= 0)
153 		return -EINVAL;
154 
155 	return stop_machine_cpuslocked(aarch64_insn_patch_text_cb, &patch,
156 				       cpu_online_mask);
157 }
158