162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 262306a36Sopenharmony_ci/* 362306a36Sopenharmony_ci * Copyright (C) 2012 Rabin Vincent <rabin at rab.in> 462306a36Sopenharmony_ci */ 562306a36Sopenharmony_ci 662306a36Sopenharmony_ci#include <linux/kernel.h> 762306a36Sopenharmony_ci#include <linux/types.h> 862306a36Sopenharmony_ci#include <linux/stddef.h> 962306a36Sopenharmony_ci#include <linux/wait.h> 1062306a36Sopenharmony_ci#include <linux/uprobes.h> 1162306a36Sopenharmony_ci#include <linux/module.h> 1262306a36Sopenharmony_ci 1362306a36Sopenharmony_ci#include "../decode.h" 1462306a36Sopenharmony_ci#include "../decode-arm.h" 1562306a36Sopenharmony_ci#include "core.h" 1662306a36Sopenharmony_ci 1762306a36Sopenharmony_cistatic int uprobes_substitute_pc(unsigned long *pinsn, u32 oregs) 1862306a36Sopenharmony_ci{ 1962306a36Sopenharmony_ci probes_opcode_t insn = __mem_to_opcode_arm(*pinsn); 2062306a36Sopenharmony_ci probes_opcode_t temp; 2162306a36Sopenharmony_ci probes_opcode_t mask; 2262306a36Sopenharmony_ci int freereg; 2362306a36Sopenharmony_ci u32 free = 0xffff; 2462306a36Sopenharmony_ci u32 regs; 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_ci for (regs = oregs; regs; regs >>= 4, insn >>= 4) { 2762306a36Sopenharmony_ci if ((regs & 0xf) == REG_TYPE_NONE) 2862306a36Sopenharmony_ci continue; 2962306a36Sopenharmony_ci 3062306a36Sopenharmony_ci free &= ~(1 << (insn & 0xf)); 3162306a36Sopenharmony_ci } 3262306a36Sopenharmony_ci 3362306a36Sopenharmony_ci /* No PC, no problem */ 3462306a36Sopenharmony_ci if (free & (1 << 15)) 3562306a36Sopenharmony_ci return 15; 3662306a36Sopenharmony_ci 3762306a36Sopenharmony_ci if (!free) 3862306a36Sopenharmony_ci return -1; 3962306a36Sopenharmony_ci 4062306a36Sopenharmony_ci /* 4162306a36Sopenharmony_ci * fls instead of ffs ensures that for "ldrd r0, r1, [pc]" we would 4262306a36Sopenharmony_ci * pick LR instead of R1. 4362306a36Sopenharmony_ci */ 4462306a36Sopenharmony_ci freereg = free = fls(free) - 1; 4562306a36Sopenharmony_ci 4662306a36Sopenharmony_ci temp = __mem_to_opcode_arm(*pinsn); 4762306a36Sopenharmony_ci insn = temp; 4862306a36Sopenharmony_ci regs = oregs; 4962306a36Sopenharmony_ci mask = 0xf; 5062306a36Sopenharmony_ci 5162306a36Sopenharmony_ci for (; regs; regs >>= 4, mask <<= 4, free <<= 4, temp >>= 4) { 5262306a36Sopenharmony_ci if ((regs & 0xf) == REG_TYPE_NONE) 5362306a36Sopenharmony_ci continue; 5462306a36Sopenharmony_ci 5562306a36Sopenharmony_ci if ((temp & 0xf) != 15) 5662306a36Sopenharmony_ci continue; 5762306a36Sopenharmony_ci 5862306a36Sopenharmony_ci insn &= ~mask; 5962306a36Sopenharmony_ci insn |= free & mask; 6062306a36Sopenharmony_ci } 6162306a36Sopenharmony_ci 6262306a36Sopenharmony_ci *pinsn = __opcode_to_mem_arm(insn); 6362306a36Sopenharmony_ci return freereg; 6462306a36Sopenharmony_ci} 6562306a36Sopenharmony_ci 6662306a36Sopenharmony_cistatic void uprobe_set_pc(struct arch_uprobe *auprobe, 6762306a36Sopenharmony_ci struct arch_uprobe_task *autask, 6862306a36Sopenharmony_ci struct pt_regs *regs) 6962306a36Sopenharmony_ci{ 7062306a36Sopenharmony_ci u32 pcreg = auprobe->pcreg; 7162306a36Sopenharmony_ci 7262306a36Sopenharmony_ci autask->backup = regs->uregs[pcreg]; 7362306a36Sopenharmony_ci regs->uregs[pcreg] = regs->ARM_pc + 8; 7462306a36Sopenharmony_ci} 7562306a36Sopenharmony_ci 7662306a36Sopenharmony_cistatic void uprobe_unset_pc(struct arch_uprobe *auprobe, 7762306a36Sopenharmony_ci struct arch_uprobe_task *autask, 7862306a36Sopenharmony_ci struct pt_regs *regs) 7962306a36Sopenharmony_ci{ 8062306a36Sopenharmony_ci /* PC will be taken care of by common code */ 8162306a36Sopenharmony_ci regs->uregs[auprobe->pcreg] = autask->backup; 8262306a36Sopenharmony_ci} 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_cistatic void uprobe_aluwrite_pc(struct arch_uprobe *auprobe, 8562306a36Sopenharmony_ci struct arch_uprobe_task *autask, 8662306a36Sopenharmony_ci struct pt_regs *regs) 8762306a36Sopenharmony_ci{ 8862306a36Sopenharmony_ci u32 pcreg = auprobe->pcreg; 8962306a36Sopenharmony_ci 9062306a36Sopenharmony_ci alu_write_pc(regs->uregs[pcreg], regs); 9162306a36Sopenharmony_ci regs->uregs[pcreg] = autask->backup; 9262306a36Sopenharmony_ci} 9362306a36Sopenharmony_ci 9462306a36Sopenharmony_cistatic void uprobe_write_pc(struct arch_uprobe *auprobe, 9562306a36Sopenharmony_ci struct arch_uprobe_task *autask, 9662306a36Sopenharmony_ci struct pt_regs *regs) 9762306a36Sopenharmony_ci{ 9862306a36Sopenharmony_ci u32 pcreg = auprobe->pcreg; 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_ci load_write_pc(regs->uregs[pcreg], regs); 10162306a36Sopenharmony_ci regs->uregs[pcreg] = autask->backup; 10262306a36Sopenharmony_ci} 10362306a36Sopenharmony_ci 10462306a36Sopenharmony_cienum probes_insn 10562306a36Sopenharmony_cidecode_pc_ro(probes_opcode_t insn, struct arch_probes_insn *asi, 10662306a36Sopenharmony_ci const struct decode_header *d) 10762306a36Sopenharmony_ci{ 10862306a36Sopenharmony_ci struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe, 10962306a36Sopenharmony_ci asi); 11062306a36Sopenharmony_ci struct decode_emulate *decode = (struct decode_emulate *) d; 11162306a36Sopenharmony_ci u32 regs = decode->header.type_regs.bits >> DECODE_TYPE_BITS; 11262306a36Sopenharmony_ci int reg; 11362306a36Sopenharmony_ci 11462306a36Sopenharmony_ci reg = uprobes_substitute_pc(&auprobe->ixol[0], regs); 11562306a36Sopenharmony_ci if (reg == 15) 11662306a36Sopenharmony_ci return INSN_GOOD; 11762306a36Sopenharmony_ci 11862306a36Sopenharmony_ci if (reg == -1) 11962306a36Sopenharmony_ci return INSN_REJECTED; 12062306a36Sopenharmony_ci 12162306a36Sopenharmony_ci auprobe->pcreg = reg; 12262306a36Sopenharmony_ci auprobe->prehandler = uprobe_set_pc; 12362306a36Sopenharmony_ci auprobe->posthandler = uprobe_unset_pc; 12462306a36Sopenharmony_ci 12562306a36Sopenharmony_ci return INSN_GOOD; 12662306a36Sopenharmony_ci} 12762306a36Sopenharmony_ci 12862306a36Sopenharmony_cienum probes_insn 12962306a36Sopenharmony_cidecode_wb_pc(probes_opcode_t insn, struct arch_probes_insn *asi, 13062306a36Sopenharmony_ci const struct decode_header *d, bool alu) 13162306a36Sopenharmony_ci{ 13262306a36Sopenharmony_ci struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe, 13362306a36Sopenharmony_ci asi); 13462306a36Sopenharmony_ci enum probes_insn ret = decode_pc_ro(insn, asi, d); 13562306a36Sopenharmony_ci 13662306a36Sopenharmony_ci if (((insn >> 12) & 0xf) == 15) 13762306a36Sopenharmony_ci auprobe->posthandler = alu ? uprobe_aluwrite_pc 13862306a36Sopenharmony_ci : uprobe_write_pc; 13962306a36Sopenharmony_ci 14062306a36Sopenharmony_ci return ret; 14162306a36Sopenharmony_ci} 14262306a36Sopenharmony_ci 14362306a36Sopenharmony_cienum probes_insn 14462306a36Sopenharmony_cidecode_rd12rn16rm0rs8_rwflags(probes_opcode_t insn, 14562306a36Sopenharmony_ci struct arch_probes_insn *asi, 14662306a36Sopenharmony_ci const struct decode_header *d) 14762306a36Sopenharmony_ci{ 14862306a36Sopenharmony_ci return decode_wb_pc(insn, asi, d, true); 14962306a36Sopenharmony_ci} 15062306a36Sopenharmony_ci 15162306a36Sopenharmony_cienum probes_insn 15262306a36Sopenharmony_cidecode_ldr(probes_opcode_t insn, struct arch_probes_insn *asi, 15362306a36Sopenharmony_ci const struct decode_header *d) 15462306a36Sopenharmony_ci{ 15562306a36Sopenharmony_ci return decode_wb_pc(insn, asi, d, false); 15662306a36Sopenharmony_ci} 15762306a36Sopenharmony_ci 15862306a36Sopenharmony_cienum probes_insn 15962306a36Sopenharmony_ciuprobe_decode_ldmstm(probes_opcode_t insn, 16062306a36Sopenharmony_ci struct arch_probes_insn *asi, 16162306a36Sopenharmony_ci const struct decode_header *d) 16262306a36Sopenharmony_ci{ 16362306a36Sopenharmony_ci struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe, 16462306a36Sopenharmony_ci asi); 16562306a36Sopenharmony_ci unsigned reglist = insn & 0xffff; 16662306a36Sopenharmony_ci int rn = (insn >> 16) & 0xf; 16762306a36Sopenharmony_ci int lbit = insn & (1 << 20); 16862306a36Sopenharmony_ci unsigned used = reglist | (1 << rn); 16962306a36Sopenharmony_ci 17062306a36Sopenharmony_ci if (rn == 15) 17162306a36Sopenharmony_ci return INSN_REJECTED; 17262306a36Sopenharmony_ci 17362306a36Sopenharmony_ci if (!(used & (1 << 15))) 17462306a36Sopenharmony_ci return INSN_GOOD; 17562306a36Sopenharmony_ci 17662306a36Sopenharmony_ci if (used & (1 << 14)) 17762306a36Sopenharmony_ci return INSN_REJECTED; 17862306a36Sopenharmony_ci 17962306a36Sopenharmony_ci /* Use LR instead of PC */ 18062306a36Sopenharmony_ci insn ^= 0xc000; 18162306a36Sopenharmony_ci 18262306a36Sopenharmony_ci auprobe->pcreg = 14; 18362306a36Sopenharmony_ci auprobe->ixol[0] = __opcode_to_mem_arm(insn); 18462306a36Sopenharmony_ci 18562306a36Sopenharmony_ci auprobe->prehandler = uprobe_set_pc; 18662306a36Sopenharmony_ci if (lbit) 18762306a36Sopenharmony_ci auprobe->posthandler = uprobe_write_pc; 18862306a36Sopenharmony_ci else 18962306a36Sopenharmony_ci auprobe->posthandler = uprobe_unset_pc; 19062306a36Sopenharmony_ci 19162306a36Sopenharmony_ci return INSN_GOOD; 19262306a36Sopenharmony_ci} 19362306a36Sopenharmony_ci 19462306a36Sopenharmony_ciconst union decode_action uprobes_probes_actions[] = { 19562306a36Sopenharmony_ci [PROBES_PRELOAD_IMM] = {.handler = probes_simulate_nop}, 19662306a36Sopenharmony_ci [PROBES_PRELOAD_REG] = {.handler = probes_simulate_nop}, 19762306a36Sopenharmony_ci [PROBES_BRANCH_IMM] = {.handler = simulate_blx1}, 19862306a36Sopenharmony_ci [PROBES_MRS] = {.handler = simulate_mrs}, 19962306a36Sopenharmony_ci [PROBES_BRANCH_REG] = {.handler = simulate_blx2bx}, 20062306a36Sopenharmony_ci [PROBES_CLZ] = {.handler = probes_simulate_nop}, 20162306a36Sopenharmony_ci [PROBES_SATURATING_ARITHMETIC] = {.handler = probes_simulate_nop}, 20262306a36Sopenharmony_ci [PROBES_MUL1] = {.handler = probes_simulate_nop}, 20362306a36Sopenharmony_ci [PROBES_MUL2] = {.handler = probes_simulate_nop}, 20462306a36Sopenharmony_ci [PROBES_SWP] = {.handler = probes_simulate_nop}, 20562306a36Sopenharmony_ci [PROBES_LDRSTRD] = {.decoder = decode_pc_ro}, 20662306a36Sopenharmony_ci [PROBES_LOAD_EXTRA] = {.decoder = decode_pc_ro}, 20762306a36Sopenharmony_ci [PROBES_LOAD] = {.decoder = decode_ldr}, 20862306a36Sopenharmony_ci [PROBES_STORE_EXTRA] = {.decoder = decode_pc_ro}, 20962306a36Sopenharmony_ci [PROBES_STORE] = {.decoder = decode_pc_ro}, 21062306a36Sopenharmony_ci [PROBES_MOV_IP_SP] = {.handler = simulate_mov_ipsp}, 21162306a36Sopenharmony_ci [PROBES_DATA_PROCESSING_REG] = { 21262306a36Sopenharmony_ci .decoder = decode_rd12rn16rm0rs8_rwflags}, 21362306a36Sopenharmony_ci [PROBES_DATA_PROCESSING_IMM] = { 21462306a36Sopenharmony_ci .decoder = decode_rd12rn16rm0rs8_rwflags}, 21562306a36Sopenharmony_ci [PROBES_MOV_HALFWORD] = {.handler = probes_simulate_nop}, 21662306a36Sopenharmony_ci [PROBES_SEV] = {.handler = probes_simulate_nop}, 21762306a36Sopenharmony_ci [PROBES_WFE] = {.handler = probes_simulate_nop}, 21862306a36Sopenharmony_ci [PROBES_SATURATE] = {.handler = probes_simulate_nop}, 21962306a36Sopenharmony_ci [PROBES_REV] = {.handler = probes_simulate_nop}, 22062306a36Sopenharmony_ci [PROBES_MMI] = {.handler = probes_simulate_nop}, 22162306a36Sopenharmony_ci [PROBES_PACK] = {.handler = probes_simulate_nop}, 22262306a36Sopenharmony_ci [PROBES_EXTEND] = {.handler = probes_simulate_nop}, 22362306a36Sopenharmony_ci [PROBES_EXTEND_ADD] = {.handler = probes_simulate_nop}, 22462306a36Sopenharmony_ci [PROBES_MUL_ADD_LONG] = {.handler = probes_simulate_nop}, 22562306a36Sopenharmony_ci [PROBES_MUL_ADD] = {.handler = probes_simulate_nop}, 22662306a36Sopenharmony_ci [PROBES_BITFIELD] = {.handler = probes_simulate_nop}, 22762306a36Sopenharmony_ci [PROBES_BRANCH] = {.handler = simulate_bbl}, 22862306a36Sopenharmony_ci [PROBES_LDMSTM] = {.decoder = uprobe_decode_ldmstm} 22962306a36Sopenharmony_ci}; 230