1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 Generic support for BUG()
4
5 This respects the following config options:
6
7 CONFIG_BUG - emit BUG traps. Nothing happens without this.
8 CONFIG_GENERIC_BUG - enable this code.
9 CONFIG_GENERIC_BUG_RELATIVE_POINTERS - use 32-bit relative pointers for bug_addr and file
10 CONFIG_DEBUG_BUGVERBOSE - emit full file+line information for each BUG
11
12 CONFIG_BUG and CONFIG_DEBUG_BUGVERBOSE are potentially user-settable
13 (though they're generally always on).
14
15 CONFIG_GENERIC_BUG is set by each architecture using this code.
16
17 To use this, your architecture must:
18
19 1. Set up the config options:
20 - Enable CONFIG_GENERIC_BUG if CONFIG_BUG
21
22 2. Implement BUG (and optionally BUG_ON, WARN, WARN_ON)
23 - Define HAVE_ARCH_BUG
24 - Implement BUG() to generate a faulting instruction
25 - NOTE: struct bug_entry does not have "file" or "line" entries
26 when CONFIG_DEBUG_BUGVERBOSE is not enabled, so you must generate
27 the values accordingly.
28
29 3. Implement the trap
30 - In the illegal instruction trap handler (typically), verify
31 that the fault was in kernel mode, and call report_bug()
32 - report_bug() will return whether it was a false alarm, a warning,
33 or an actual bug.
34 - You must implement the is_valid_bugaddr(bugaddr) callback which
35 returns true if the eip is a real kernel address, and it points
36 to the expected BUG trap instruction.
37
38 Jeremy Fitzhardinge <jeremy@goop.org> 2006
39 */
40
41 #define pr_fmt(fmt) fmt
42
43 #include <linux/list.h>
44 #include <linux/module.h>
45 #include <linux/kernel.h>
46 #include <linux/bug.h>
47 #include <linux/sched.h>
48 #include <linux/rculist.h>
49 #include <linux/ftrace.h>
50 #include <linux/context_tracking.h>
51
52 #include <trace/hooks/bug.h>
53
54 extern struct bug_entry __start___bug_table[], __stop___bug_table[];
55
bug_addr(const struct bug_entry * bug)56 static inline unsigned long bug_addr(const struct bug_entry *bug)
57 {
58 #ifdef CONFIG_GENERIC_BUG_RELATIVE_POINTERS
59 return (unsigned long)&bug->bug_addr_disp + bug->bug_addr_disp;
60 #else
61 return bug->bug_addr;
62 #endif
63 }
64
65 #ifdef CONFIG_MODULES
66 /* Updates are protected by module mutex */
67 static LIST_HEAD(module_bug_list);
68
module_find_bug(unsigned long bugaddr)69 static struct bug_entry *module_find_bug(unsigned long bugaddr)
70 {
71 struct module *mod;
72 struct bug_entry *bug = NULL;
73
74 rcu_read_lock_sched();
75 list_for_each_entry_rcu(mod, &module_bug_list, bug_list) {
76 unsigned i;
77
78 bug = mod->bug_table;
79 for (i = 0; i < mod->num_bugs; ++i, ++bug)
80 if (bugaddr == bug_addr(bug))
81 goto out;
82 }
83 bug = NULL;
84 out:
85 rcu_read_unlock_sched();
86
87 return bug;
88 }
89
module_bug_finalize(const Elf_Ehdr * hdr,const Elf_Shdr * sechdrs,struct module * mod)90 void module_bug_finalize(const Elf_Ehdr *hdr, const Elf_Shdr *sechdrs,
91 struct module *mod)
92 {
93 char *secstrings;
94 unsigned int i;
95
96 mod->bug_table = NULL;
97 mod->num_bugs = 0;
98
99 /* Find the __bug_table section, if present */
100 secstrings = (char *)hdr + sechdrs[hdr->e_shstrndx].sh_offset;
101 for (i = 1; i < hdr->e_shnum; i++) {
102 if (strcmp(secstrings+sechdrs[i].sh_name, "__bug_table"))
103 continue;
104 mod->bug_table = (void *) sechdrs[i].sh_addr;
105 mod->num_bugs = sechdrs[i].sh_size / sizeof(struct bug_entry);
106 break;
107 }
108
109 /*
110 * Strictly speaking this should have a spinlock to protect against
111 * traversals, but since we only traverse on BUG()s, a spinlock
112 * could potentially lead to deadlock and thus be counter-productive.
113 * Thus, this uses RCU to safely manipulate the bug list, since BUG
114 * must run in non-interruptive state.
115 */
116 list_add_rcu(&mod->bug_list, &module_bug_list);
117 }
118
module_bug_cleanup(struct module * mod)119 void module_bug_cleanup(struct module *mod)
120 {
121 list_del_rcu(&mod->bug_list);
122 }
123
124 #else
125
module_find_bug(unsigned long bugaddr)126 static inline struct bug_entry *module_find_bug(unsigned long bugaddr)
127 {
128 return NULL;
129 }
130 #endif
131
bug_get_file_line(struct bug_entry * bug,const char ** file,unsigned int * line)132 void bug_get_file_line(struct bug_entry *bug, const char **file,
133 unsigned int *line)
134 {
135 #ifdef CONFIG_DEBUG_BUGVERBOSE
136 #ifdef CONFIG_GENERIC_BUG_RELATIVE_POINTERS
137 *file = (const char *)&bug->file_disp + bug->file_disp;
138 #else
139 *file = bug->file;
140 #endif
141 *line = bug->line;
142 #else
143 *file = NULL;
144 *line = 0;
145 #endif
146 }
147
find_bug(unsigned long bugaddr)148 struct bug_entry *find_bug(unsigned long bugaddr)
149 {
150 struct bug_entry *bug;
151
152 for (bug = __start___bug_table; bug < __stop___bug_table; ++bug)
153 if (bugaddr == bug_addr(bug))
154 return bug;
155
156 return module_find_bug(bugaddr);
157 }
158
__report_bug(unsigned long bugaddr,struct pt_regs * regs)159 static enum bug_trap_type __report_bug(unsigned long bugaddr, struct pt_regs *regs)
160 {
161 struct bug_entry *bug;
162 const char *file;
163 unsigned line, warning, once, done;
164
165 if (!is_valid_bugaddr(bugaddr))
166 return BUG_TRAP_TYPE_NONE;
167
168 bug = find_bug(bugaddr);
169 if (!bug)
170 return BUG_TRAP_TYPE_NONE;
171
172 disable_trace_on_warning();
173
174 bug_get_file_line(bug, &file, &line);
175
176 warning = (bug->flags & BUGFLAG_WARNING) != 0;
177 once = (bug->flags & BUGFLAG_ONCE) != 0;
178 done = (bug->flags & BUGFLAG_DONE) != 0;
179
180 if (warning && once) {
181 if (done)
182 return BUG_TRAP_TYPE_WARN;
183
184 /*
185 * Since this is the only store, concurrency is not an issue.
186 */
187 bug->flags |= BUGFLAG_DONE;
188 }
189
190 /*
191 * BUG() and WARN_ON() families don't print a custom debug message
192 * before triggering the exception handler, so we must add the
193 * "cut here" line now. WARN() issues its own "cut here" before the
194 * extra debugging message it writes before triggering the handler.
195 */
196 if ((bug->flags & BUGFLAG_NO_CUT_HERE) == 0)
197 printk(KERN_DEFAULT CUT_HERE);
198
199 if (warning) {
200 /* this is a WARN_ON rather than BUG/BUG_ON */
201 __warn(file, line, (void *)bugaddr, BUG_GET_TAINT(bug), regs,
202 NULL);
203 return BUG_TRAP_TYPE_WARN;
204 }
205
206 if (file)
207 pr_crit("kernel BUG at %s:%u!\n", file, line);
208 else
209 pr_crit("Kernel BUG at %pB [verbose debug info unavailable]\n",
210 (void *)bugaddr);
211
212 trace_android_rvh_report_bug(file, line, bugaddr);
213
214 return BUG_TRAP_TYPE_BUG;
215 }
216
report_bug(unsigned long bugaddr,struct pt_regs * regs)217 enum bug_trap_type report_bug(unsigned long bugaddr, struct pt_regs *regs)
218 {
219 enum bug_trap_type ret;
220 bool rcu = false;
221
222 rcu = warn_rcu_enter();
223 ret = __report_bug(bugaddr, regs);
224 warn_rcu_exit(rcu);
225
226 return ret;
227 }
228
clear_once_table(struct bug_entry * start,struct bug_entry * end)229 static void clear_once_table(struct bug_entry *start, struct bug_entry *end)
230 {
231 struct bug_entry *bug;
232
233 for (bug = start; bug < end; bug++)
234 bug->flags &= ~BUGFLAG_DONE;
235 }
236
generic_bug_clear_once(void)237 void generic_bug_clear_once(void)
238 {
239 #ifdef CONFIG_MODULES
240 struct module *mod;
241
242 rcu_read_lock_sched();
243 list_for_each_entry_rcu(mod, &module_bug_list, bug_list)
244 clear_once_table(mod->bug_table,
245 mod->bug_table + mod->num_bugs);
246 rcu_read_unlock_sched();
247 #endif
248
249 clear_once_table(__start___bug_table, __stop___bug_table);
250 }
251