18c2ecf20Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0 */
28c2ecf20Sopenharmony_ci#ifndef _ASM_POWERPC_BOOK3S_32_KUP_H
38c2ecf20Sopenharmony_ci#define _ASM_POWERPC_BOOK3S_32_KUP_H
48c2ecf20Sopenharmony_ci
58c2ecf20Sopenharmony_ci#include <asm/bug.h>
68c2ecf20Sopenharmony_ci#include <asm/book3s/32/mmu-hash.h>
78c2ecf20Sopenharmony_ci
88c2ecf20Sopenharmony_ci#ifdef __ASSEMBLY__
98c2ecf20Sopenharmony_ci
108c2ecf20Sopenharmony_ci.macro kuep_update_sr	gpr1, gpr2		/* NEVER use r0 as gpr2 due to addis */
118c2ecf20Sopenharmony_ci101:	mtsrin	\gpr1, \gpr2
128c2ecf20Sopenharmony_ci	addi	\gpr1, \gpr1, 0x111		/* next VSID */
138c2ecf20Sopenharmony_ci	rlwinm	\gpr1, \gpr1, 0, 0xf0ffffff	/* clear VSID overflow */
148c2ecf20Sopenharmony_ci	addis	\gpr2, \gpr2, 0x1000		/* address of next segment */
158c2ecf20Sopenharmony_ci	bdnz	101b
168c2ecf20Sopenharmony_ci	isync
178c2ecf20Sopenharmony_ci.endm
188c2ecf20Sopenharmony_ci
198c2ecf20Sopenharmony_ci.macro kuep_lock	gpr1, gpr2
208c2ecf20Sopenharmony_ci#ifdef CONFIG_PPC_KUEP
218c2ecf20Sopenharmony_ci	li	\gpr1, NUM_USER_SEGMENTS
228c2ecf20Sopenharmony_ci	li	\gpr2, 0
238c2ecf20Sopenharmony_ci	mtctr	\gpr1
248c2ecf20Sopenharmony_ci	mfsrin	\gpr1, \gpr2
258c2ecf20Sopenharmony_ci	oris	\gpr1, \gpr1, SR_NX@h		/* set Nx */
268c2ecf20Sopenharmony_ci	kuep_update_sr \gpr1, \gpr2
278c2ecf20Sopenharmony_ci#endif
288c2ecf20Sopenharmony_ci.endm
298c2ecf20Sopenharmony_ci
308c2ecf20Sopenharmony_ci.macro kuep_unlock	gpr1, gpr2
318c2ecf20Sopenharmony_ci#ifdef CONFIG_PPC_KUEP
328c2ecf20Sopenharmony_ci	li	\gpr1, NUM_USER_SEGMENTS
338c2ecf20Sopenharmony_ci	li	\gpr2, 0
348c2ecf20Sopenharmony_ci	mtctr	\gpr1
358c2ecf20Sopenharmony_ci	mfsrin	\gpr1, \gpr2
368c2ecf20Sopenharmony_ci	rlwinm	\gpr1, \gpr1, 0, ~SR_NX		/* Clear Nx */
378c2ecf20Sopenharmony_ci	kuep_update_sr \gpr1, \gpr2
388c2ecf20Sopenharmony_ci#endif
398c2ecf20Sopenharmony_ci.endm
408c2ecf20Sopenharmony_ci
418c2ecf20Sopenharmony_ci#ifdef CONFIG_PPC_KUAP
428c2ecf20Sopenharmony_ci
438c2ecf20Sopenharmony_ci.macro kuap_update_sr	gpr1, gpr2, gpr3	/* NEVER use r0 as gpr2 due to addis */
448c2ecf20Sopenharmony_ci101:	mtsrin	\gpr1, \gpr2
458c2ecf20Sopenharmony_ci	addi	\gpr1, \gpr1, 0x111		/* next VSID */
468c2ecf20Sopenharmony_ci	rlwinm	\gpr1, \gpr1, 0, 0xf0ffffff	/* clear VSID overflow */
478c2ecf20Sopenharmony_ci	addis	\gpr2, \gpr2, 0x1000		/* address of next segment */
488c2ecf20Sopenharmony_ci	cmplw	\gpr2, \gpr3
498c2ecf20Sopenharmony_ci	blt-	101b
508c2ecf20Sopenharmony_ci	isync
518c2ecf20Sopenharmony_ci.endm
528c2ecf20Sopenharmony_ci
538c2ecf20Sopenharmony_ci.macro kuap_save_and_lock	sp, thread, gpr1, gpr2, gpr3
548c2ecf20Sopenharmony_ci	lwz	\gpr2, KUAP(\thread)
558c2ecf20Sopenharmony_ci	rlwinm.	\gpr3, \gpr2, 28, 0xf0000000
568c2ecf20Sopenharmony_ci	stw	\gpr2, STACK_REGS_KUAP(\sp)
578c2ecf20Sopenharmony_ci	beq+	102f
588c2ecf20Sopenharmony_ci	li	\gpr1, 0
598c2ecf20Sopenharmony_ci	stw	\gpr1, KUAP(\thread)
608c2ecf20Sopenharmony_ci	mfsrin	\gpr1, \gpr2
618c2ecf20Sopenharmony_ci	oris	\gpr1, \gpr1, SR_KS@h	/* set Ks */
628c2ecf20Sopenharmony_ci	kuap_update_sr	\gpr1, \gpr2, \gpr3
638c2ecf20Sopenharmony_ci102:
648c2ecf20Sopenharmony_ci.endm
658c2ecf20Sopenharmony_ci
668c2ecf20Sopenharmony_ci.macro kuap_restore	sp, current, gpr1, gpr2, gpr3
678c2ecf20Sopenharmony_ci	lwz	\gpr2, STACK_REGS_KUAP(\sp)
688c2ecf20Sopenharmony_ci	rlwinm.	\gpr3, \gpr2, 28, 0xf0000000
698c2ecf20Sopenharmony_ci	stw	\gpr2, THREAD + KUAP(\current)
708c2ecf20Sopenharmony_ci	beq+	102f
718c2ecf20Sopenharmony_ci	mfsrin	\gpr1, \gpr2
728c2ecf20Sopenharmony_ci	rlwinm	\gpr1, \gpr1, 0, ~SR_KS	/* Clear Ks */
738c2ecf20Sopenharmony_ci	kuap_update_sr	\gpr1, \gpr2, \gpr3
748c2ecf20Sopenharmony_ci102:
758c2ecf20Sopenharmony_ci.endm
768c2ecf20Sopenharmony_ci
778c2ecf20Sopenharmony_ci.macro kuap_check	current, gpr
788c2ecf20Sopenharmony_ci#ifdef CONFIG_PPC_KUAP_DEBUG
798c2ecf20Sopenharmony_ci	lwz	\gpr, THREAD + KUAP(\current)
808c2ecf20Sopenharmony_ci999:	twnei	\gpr, 0
818c2ecf20Sopenharmony_ci	EMIT_BUG_ENTRY 999b, __FILE__, __LINE__, (BUGFLAG_WARNING | BUGFLAG_ONCE)
828c2ecf20Sopenharmony_ci#endif
838c2ecf20Sopenharmony_ci.endm
848c2ecf20Sopenharmony_ci
858c2ecf20Sopenharmony_ci#endif /* CONFIG_PPC_KUAP */
868c2ecf20Sopenharmony_ci
878c2ecf20Sopenharmony_ci#else /* !__ASSEMBLY__ */
888c2ecf20Sopenharmony_ci
898c2ecf20Sopenharmony_ci#ifdef CONFIG_PPC_KUAP
908c2ecf20Sopenharmony_ci
918c2ecf20Sopenharmony_ci#include <linux/sched.h>
928c2ecf20Sopenharmony_ci
938c2ecf20Sopenharmony_cistatic inline void kuap_update_sr(u32 sr, u32 addr, u32 end)
948c2ecf20Sopenharmony_ci{
958c2ecf20Sopenharmony_ci	addr &= 0xf0000000;	/* align addr to start of segment */
968c2ecf20Sopenharmony_ci	barrier();	/* make sure thread.kuap is updated before playing with SRs */
978c2ecf20Sopenharmony_ci	while (addr < end) {
988c2ecf20Sopenharmony_ci		mtsrin(sr, addr);
998c2ecf20Sopenharmony_ci		sr += 0x111;		/* next VSID */
1008c2ecf20Sopenharmony_ci		sr &= 0xf0ffffff;	/* clear VSID overflow */
1018c2ecf20Sopenharmony_ci		addr += 0x10000000;	/* address of next segment */
1028c2ecf20Sopenharmony_ci	}
1038c2ecf20Sopenharmony_ci	isync();	/* Context sync required after mtsrin() */
1048c2ecf20Sopenharmony_ci}
1058c2ecf20Sopenharmony_ci
1068c2ecf20Sopenharmony_cistatic __always_inline void allow_user_access(void __user *to, const void __user *from,
1078c2ecf20Sopenharmony_ci					      u32 size, unsigned long dir)
1088c2ecf20Sopenharmony_ci{
1098c2ecf20Sopenharmony_ci	u32 addr, end;
1108c2ecf20Sopenharmony_ci
1118c2ecf20Sopenharmony_ci	BUILD_BUG_ON(!__builtin_constant_p(dir));
1128c2ecf20Sopenharmony_ci	BUILD_BUG_ON(dir & ~KUAP_READ_WRITE);
1138c2ecf20Sopenharmony_ci
1148c2ecf20Sopenharmony_ci	if (!(dir & KUAP_WRITE))
1158c2ecf20Sopenharmony_ci		return;
1168c2ecf20Sopenharmony_ci
1178c2ecf20Sopenharmony_ci	addr = (__force u32)to;
1188c2ecf20Sopenharmony_ci
1198c2ecf20Sopenharmony_ci	if (unlikely(addr >= TASK_SIZE || !size))
1208c2ecf20Sopenharmony_ci		return;
1218c2ecf20Sopenharmony_ci
1228c2ecf20Sopenharmony_ci	end = min(addr + size, TASK_SIZE);
1238c2ecf20Sopenharmony_ci
1248c2ecf20Sopenharmony_ci	current->thread.kuap = (addr & 0xf0000000) | ((((end - 1) >> 28) + 1) & 0xf);
1258c2ecf20Sopenharmony_ci	kuap_update_sr(mfsrin(addr) & ~SR_KS, addr, end);	/* Clear Ks */
1268c2ecf20Sopenharmony_ci}
1278c2ecf20Sopenharmony_ci
1288c2ecf20Sopenharmony_cistatic __always_inline void prevent_user_access(void __user *to, const void __user *from,
1298c2ecf20Sopenharmony_ci						u32 size, unsigned long dir)
1308c2ecf20Sopenharmony_ci{
1318c2ecf20Sopenharmony_ci	u32 addr, end;
1328c2ecf20Sopenharmony_ci
1338c2ecf20Sopenharmony_ci	BUILD_BUG_ON(!__builtin_constant_p(dir));
1348c2ecf20Sopenharmony_ci
1358c2ecf20Sopenharmony_ci	if (dir & KUAP_CURRENT_WRITE) {
1368c2ecf20Sopenharmony_ci		u32 kuap = current->thread.kuap;
1378c2ecf20Sopenharmony_ci
1388c2ecf20Sopenharmony_ci		if (unlikely(!kuap))
1398c2ecf20Sopenharmony_ci			return;
1408c2ecf20Sopenharmony_ci
1418c2ecf20Sopenharmony_ci		addr = kuap & 0xf0000000;
1428c2ecf20Sopenharmony_ci		end = kuap << 28;
1438c2ecf20Sopenharmony_ci	} else if (dir & KUAP_WRITE) {
1448c2ecf20Sopenharmony_ci		addr = (__force u32)to;
1458c2ecf20Sopenharmony_ci		end = min(addr + size, TASK_SIZE);
1468c2ecf20Sopenharmony_ci
1478c2ecf20Sopenharmony_ci		if (unlikely(addr >= TASK_SIZE || !size))
1488c2ecf20Sopenharmony_ci			return;
1498c2ecf20Sopenharmony_ci	} else {
1508c2ecf20Sopenharmony_ci		return;
1518c2ecf20Sopenharmony_ci	}
1528c2ecf20Sopenharmony_ci
1538c2ecf20Sopenharmony_ci	current->thread.kuap = 0;
1548c2ecf20Sopenharmony_ci	kuap_update_sr(mfsrin(addr) | SR_KS, addr, end);	/* set Ks */
1558c2ecf20Sopenharmony_ci}
1568c2ecf20Sopenharmony_ci
1578c2ecf20Sopenharmony_cistatic inline unsigned long prevent_user_access_return(void)
1588c2ecf20Sopenharmony_ci{
1598c2ecf20Sopenharmony_ci	unsigned long flags = current->thread.kuap;
1608c2ecf20Sopenharmony_ci	unsigned long addr = flags & 0xf0000000;
1618c2ecf20Sopenharmony_ci	unsigned long end = flags << 28;
1628c2ecf20Sopenharmony_ci	void __user *to = (__force void __user *)addr;
1638c2ecf20Sopenharmony_ci
1648c2ecf20Sopenharmony_ci	if (flags)
1658c2ecf20Sopenharmony_ci		prevent_user_access(to, to, end - addr, KUAP_READ_WRITE);
1668c2ecf20Sopenharmony_ci
1678c2ecf20Sopenharmony_ci	return flags;
1688c2ecf20Sopenharmony_ci}
1698c2ecf20Sopenharmony_ci
1708c2ecf20Sopenharmony_cistatic inline void restore_user_access(unsigned long flags)
1718c2ecf20Sopenharmony_ci{
1728c2ecf20Sopenharmony_ci	unsigned long addr = flags & 0xf0000000;
1738c2ecf20Sopenharmony_ci	unsigned long end = flags << 28;
1748c2ecf20Sopenharmony_ci	void __user *to = (__force void __user *)addr;
1758c2ecf20Sopenharmony_ci
1768c2ecf20Sopenharmony_ci	if (flags)
1778c2ecf20Sopenharmony_ci		allow_user_access(to, to, end - addr, KUAP_READ_WRITE);
1788c2ecf20Sopenharmony_ci}
1798c2ecf20Sopenharmony_ci
1808c2ecf20Sopenharmony_cistatic inline bool
1818c2ecf20Sopenharmony_cibad_kuap_fault(struct pt_regs *regs, unsigned long address, bool is_write)
1828c2ecf20Sopenharmony_ci{
1838c2ecf20Sopenharmony_ci	unsigned long begin = regs->kuap & 0xf0000000;
1848c2ecf20Sopenharmony_ci	unsigned long end = regs->kuap << 28;
1858c2ecf20Sopenharmony_ci
1868c2ecf20Sopenharmony_ci	if (!is_write)
1878c2ecf20Sopenharmony_ci		return false;
1888c2ecf20Sopenharmony_ci
1898c2ecf20Sopenharmony_ci	return WARN(address < begin || address >= end,
1908c2ecf20Sopenharmony_ci		    "Bug: write fault blocked by segment registers !");
1918c2ecf20Sopenharmony_ci}
1928c2ecf20Sopenharmony_ci
1938c2ecf20Sopenharmony_ci#endif /* CONFIG_PPC_KUAP */
1948c2ecf20Sopenharmony_ci
1958c2ecf20Sopenharmony_ci#endif /* __ASSEMBLY__ */
1968c2ecf20Sopenharmony_ci
1978c2ecf20Sopenharmony_ci#endif /* _ASM_POWERPC_BOOK3S_32_KUP_H */
198