162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * Copyright (C) 2012 Rabin Vincent <rabin at rab.in>
462306a36Sopenharmony_ci */
562306a36Sopenharmony_ci
662306a36Sopenharmony_ci#include <linux/kernel.h>
762306a36Sopenharmony_ci#include <linux/types.h>
862306a36Sopenharmony_ci#include <linux/stddef.h>
962306a36Sopenharmony_ci#include <linux/wait.h>
1062306a36Sopenharmony_ci#include <linux/uprobes.h>
1162306a36Sopenharmony_ci#include <linux/module.h>
1262306a36Sopenharmony_ci
1362306a36Sopenharmony_ci#include "../decode.h"
1462306a36Sopenharmony_ci#include "../decode-arm.h"
1562306a36Sopenharmony_ci#include "core.h"
1662306a36Sopenharmony_ci
1762306a36Sopenharmony_cistatic int uprobes_substitute_pc(unsigned long *pinsn, u32 oregs)
1862306a36Sopenharmony_ci{
1962306a36Sopenharmony_ci	probes_opcode_t insn = __mem_to_opcode_arm(*pinsn);
2062306a36Sopenharmony_ci	probes_opcode_t temp;
2162306a36Sopenharmony_ci	probes_opcode_t mask;
2262306a36Sopenharmony_ci	int freereg;
2362306a36Sopenharmony_ci	u32 free = 0xffff;
2462306a36Sopenharmony_ci	u32 regs;
2562306a36Sopenharmony_ci
2662306a36Sopenharmony_ci	for (regs = oregs; regs; regs >>= 4, insn >>= 4) {
2762306a36Sopenharmony_ci		if ((regs & 0xf) == REG_TYPE_NONE)
2862306a36Sopenharmony_ci			continue;
2962306a36Sopenharmony_ci
3062306a36Sopenharmony_ci		free &= ~(1 << (insn & 0xf));
3162306a36Sopenharmony_ci	}
3262306a36Sopenharmony_ci
3362306a36Sopenharmony_ci	/* No PC, no problem */
3462306a36Sopenharmony_ci	if (free & (1 << 15))
3562306a36Sopenharmony_ci		return 15;
3662306a36Sopenharmony_ci
3762306a36Sopenharmony_ci	if (!free)
3862306a36Sopenharmony_ci		return -1;
3962306a36Sopenharmony_ci
4062306a36Sopenharmony_ci	/*
4162306a36Sopenharmony_ci	 * fls instead of ffs ensures that for "ldrd r0, r1, [pc]" we would
4262306a36Sopenharmony_ci	 * pick LR instead of R1.
4362306a36Sopenharmony_ci	 */
4462306a36Sopenharmony_ci	freereg = free = fls(free) - 1;
4562306a36Sopenharmony_ci
4662306a36Sopenharmony_ci	temp = __mem_to_opcode_arm(*pinsn);
4762306a36Sopenharmony_ci	insn = temp;
4862306a36Sopenharmony_ci	regs = oregs;
4962306a36Sopenharmony_ci	mask = 0xf;
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci	for (; regs; regs >>= 4, mask <<= 4, free <<= 4, temp >>= 4) {
5262306a36Sopenharmony_ci		if ((regs & 0xf) == REG_TYPE_NONE)
5362306a36Sopenharmony_ci			continue;
5462306a36Sopenharmony_ci
5562306a36Sopenharmony_ci		if ((temp & 0xf) != 15)
5662306a36Sopenharmony_ci			continue;
5762306a36Sopenharmony_ci
5862306a36Sopenharmony_ci		insn &= ~mask;
5962306a36Sopenharmony_ci		insn |= free & mask;
6062306a36Sopenharmony_ci	}
6162306a36Sopenharmony_ci
6262306a36Sopenharmony_ci	*pinsn = __opcode_to_mem_arm(insn);
6362306a36Sopenharmony_ci	return freereg;
6462306a36Sopenharmony_ci}
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_cistatic void uprobe_set_pc(struct arch_uprobe *auprobe,
6762306a36Sopenharmony_ci			  struct arch_uprobe_task *autask,
6862306a36Sopenharmony_ci			  struct pt_regs *regs)
6962306a36Sopenharmony_ci{
7062306a36Sopenharmony_ci	u32 pcreg = auprobe->pcreg;
7162306a36Sopenharmony_ci
7262306a36Sopenharmony_ci	autask->backup = regs->uregs[pcreg];
7362306a36Sopenharmony_ci	regs->uregs[pcreg] = regs->ARM_pc + 8;
7462306a36Sopenharmony_ci}
7562306a36Sopenharmony_ci
7662306a36Sopenharmony_cistatic void uprobe_unset_pc(struct arch_uprobe *auprobe,
7762306a36Sopenharmony_ci			    struct arch_uprobe_task *autask,
7862306a36Sopenharmony_ci			    struct pt_regs *regs)
7962306a36Sopenharmony_ci{
8062306a36Sopenharmony_ci	/* PC will be taken care of by common code */
8162306a36Sopenharmony_ci	regs->uregs[auprobe->pcreg] = autask->backup;
8262306a36Sopenharmony_ci}
8362306a36Sopenharmony_ci
8462306a36Sopenharmony_cistatic void uprobe_aluwrite_pc(struct arch_uprobe *auprobe,
8562306a36Sopenharmony_ci			       struct arch_uprobe_task *autask,
8662306a36Sopenharmony_ci			       struct pt_regs *regs)
8762306a36Sopenharmony_ci{
8862306a36Sopenharmony_ci	u32 pcreg = auprobe->pcreg;
8962306a36Sopenharmony_ci
9062306a36Sopenharmony_ci	alu_write_pc(regs->uregs[pcreg], regs);
9162306a36Sopenharmony_ci	regs->uregs[pcreg] = autask->backup;
9262306a36Sopenharmony_ci}
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_cistatic void uprobe_write_pc(struct arch_uprobe *auprobe,
9562306a36Sopenharmony_ci			    struct arch_uprobe_task *autask,
9662306a36Sopenharmony_ci			    struct pt_regs *regs)
9762306a36Sopenharmony_ci{
9862306a36Sopenharmony_ci	u32 pcreg = auprobe->pcreg;
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_ci	load_write_pc(regs->uregs[pcreg], regs);
10162306a36Sopenharmony_ci	regs->uregs[pcreg] = autask->backup;
10262306a36Sopenharmony_ci}
10362306a36Sopenharmony_ci
10462306a36Sopenharmony_cienum probes_insn
10562306a36Sopenharmony_cidecode_pc_ro(probes_opcode_t insn, struct arch_probes_insn *asi,
10662306a36Sopenharmony_ci	     const struct decode_header *d)
10762306a36Sopenharmony_ci{
10862306a36Sopenharmony_ci	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
10962306a36Sopenharmony_ci						   asi);
11062306a36Sopenharmony_ci	struct decode_emulate *decode = (struct decode_emulate *) d;
11162306a36Sopenharmony_ci	u32 regs = decode->header.type_regs.bits >> DECODE_TYPE_BITS;
11262306a36Sopenharmony_ci	int reg;
11362306a36Sopenharmony_ci
11462306a36Sopenharmony_ci	reg = uprobes_substitute_pc(&auprobe->ixol[0], regs);
11562306a36Sopenharmony_ci	if (reg == 15)
11662306a36Sopenharmony_ci		return INSN_GOOD;
11762306a36Sopenharmony_ci
11862306a36Sopenharmony_ci	if (reg == -1)
11962306a36Sopenharmony_ci		return INSN_REJECTED;
12062306a36Sopenharmony_ci
12162306a36Sopenharmony_ci	auprobe->pcreg = reg;
12262306a36Sopenharmony_ci	auprobe->prehandler = uprobe_set_pc;
12362306a36Sopenharmony_ci	auprobe->posthandler = uprobe_unset_pc;
12462306a36Sopenharmony_ci
12562306a36Sopenharmony_ci	return INSN_GOOD;
12662306a36Sopenharmony_ci}
12762306a36Sopenharmony_ci
12862306a36Sopenharmony_cienum probes_insn
12962306a36Sopenharmony_cidecode_wb_pc(probes_opcode_t insn, struct arch_probes_insn *asi,
13062306a36Sopenharmony_ci	     const struct decode_header *d, bool alu)
13162306a36Sopenharmony_ci{
13262306a36Sopenharmony_ci	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
13362306a36Sopenharmony_ci						   asi);
13462306a36Sopenharmony_ci	enum probes_insn ret = decode_pc_ro(insn, asi, d);
13562306a36Sopenharmony_ci
13662306a36Sopenharmony_ci	if (((insn >> 12) & 0xf) == 15)
13762306a36Sopenharmony_ci		auprobe->posthandler = alu ? uprobe_aluwrite_pc
13862306a36Sopenharmony_ci					   : uprobe_write_pc;
13962306a36Sopenharmony_ci
14062306a36Sopenharmony_ci	return ret;
14162306a36Sopenharmony_ci}
14262306a36Sopenharmony_ci
14362306a36Sopenharmony_cienum probes_insn
14462306a36Sopenharmony_cidecode_rd12rn16rm0rs8_rwflags(probes_opcode_t insn,
14562306a36Sopenharmony_ci			      struct arch_probes_insn *asi,
14662306a36Sopenharmony_ci			      const struct decode_header *d)
14762306a36Sopenharmony_ci{
14862306a36Sopenharmony_ci	return decode_wb_pc(insn, asi, d, true);
14962306a36Sopenharmony_ci}
15062306a36Sopenharmony_ci
15162306a36Sopenharmony_cienum probes_insn
15262306a36Sopenharmony_cidecode_ldr(probes_opcode_t insn, struct arch_probes_insn *asi,
15362306a36Sopenharmony_ci	   const struct decode_header *d)
15462306a36Sopenharmony_ci{
15562306a36Sopenharmony_ci	return decode_wb_pc(insn, asi, d, false);
15662306a36Sopenharmony_ci}
15762306a36Sopenharmony_ci
15862306a36Sopenharmony_cienum probes_insn
15962306a36Sopenharmony_ciuprobe_decode_ldmstm(probes_opcode_t insn,
16062306a36Sopenharmony_ci		     struct arch_probes_insn *asi,
16162306a36Sopenharmony_ci		     const struct decode_header *d)
16262306a36Sopenharmony_ci{
16362306a36Sopenharmony_ci	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
16462306a36Sopenharmony_ci						   asi);
16562306a36Sopenharmony_ci	unsigned reglist = insn & 0xffff;
16662306a36Sopenharmony_ci	int rn = (insn >> 16) & 0xf;
16762306a36Sopenharmony_ci	int lbit = insn & (1 << 20);
16862306a36Sopenharmony_ci	unsigned used = reglist | (1 << rn);
16962306a36Sopenharmony_ci
17062306a36Sopenharmony_ci	if (rn == 15)
17162306a36Sopenharmony_ci		return INSN_REJECTED;
17262306a36Sopenharmony_ci
17362306a36Sopenharmony_ci	if (!(used & (1 << 15)))
17462306a36Sopenharmony_ci		return INSN_GOOD;
17562306a36Sopenharmony_ci
17662306a36Sopenharmony_ci	if (used & (1 << 14))
17762306a36Sopenharmony_ci		return INSN_REJECTED;
17862306a36Sopenharmony_ci
17962306a36Sopenharmony_ci	/* Use LR instead of PC */
18062306a36Sopenharmony_ci	insn ^= 0xc000;
18162306a36Sopenharmony_ci
18262306a36Sopenharmony_ci	auprobe->pcreg = 14;
18362306a36Sopenharmony_ci	auprobe->ixol[0] = __opcode_to_mem_arm(insn);
18462306a36Sopenharmony_ci
18562306a36Sopenharmony_ci	auprobe->prehandler = uprobe_set_pc;
18662306a36Sopenharmony_ci	if (lbit)
18762306a36Sopenharmony_ci		auprobe->posthandler = uprobe_write_pc;
18862306a36Sopenharmony_ci	else
18962306a36Sopenharmony_ci		auprobe->posthandler = uprobe_unset_pc;
19062306a36Sopenharmony_ci
19162306a36Sopenharmony_ci	return INSN_GOOD;
19262306a36Sopenharmony_ci}
19362306a36Sopenharmony_ci
19462306a36Sopenharmony_ciconst union decode_action uprobes_probes_actions[] = {
19562306a36Sopenharmony_ci	[PROBES_PRELOAD_IMM] = {.handler = probes_simulate_nop},
19662306a36Sopenharmony_ci	[PROBES_PRELOAD_REG] = {.handler = probes_simulate_nop},
19762306a36Sopenharmony_ci	[PROBES_BRANCH_IMM] = {.handler = simulate_blx1},
19862306a36Sopenharmony_ci	[PROBES_MRS] = {.handler = simulate_mrs},
19962306a36Sopenharmony_ci	[PROBES_BRANCH_REG] = {.handler = simulate_blx2bx},
20062306a36Sopenharmony_ci	[PROBES_CLZ] = {.handler = probes_simulate_nop},
20162306a36Sopenharmony_ci	[PROBES_SATURATING_ARITHMETIC] = {.handler = probes_simulate_nop},
20262306a36Sopenharmony_ci	[PROBES_MUL1] = {.handler = probes_simulate_nop},
20362306a36Sopenharmony_ci	[PROBES_MUL2] = {.handler = probes_simulate_nop},
20462306a36Sopenharmony_ci	[PROBES_SWP] = {.handler = probes_simulate_nop},
20562306a36Sopenharmony_ci	[PROBES_LDRSTRD] = {.decoder = decode_pc_ro},
20662306a36Sopenharmony_ci	[PROBES_LOAD_EXTRA] = {.decoder = decode_pc_ro},
20762306a36Sopenharmony_ci	[PROBES_LOAD] = {.decoder = decode_ldr},
20862306a36Sopenharmony_ci	[PROBES_STORE_EXTRA] = {.decoder = decode_pc_ro},
20962306a36Sopenharmony_ci	[PROBES_STORE] = {.decoder = decode_pc_ro},
21062306a36Sopenharmony_ci	[PROBES_MOV_IP_SP] = {.handler = simulate_mov_ipsp},
21162306a36Sopenharmony_ci	[PROBES_DATA_PROCESSING_REG] = {
21262306a36Sopenharmony_ci		.decoder = decode_rd12rn16rm0rs8_rwflags},
21362306a36Sopenharmony_ci	[PROBES_DATA_PROCESSING_IMM] = {
21462306a36Sopenharmony_ci		.decoder = decode_rd12rn16rm0rs8_rwflags},
21562306a36Sopenharmony_ci	[PROBES_MOV_HALFWORD] = {.handler = probes_simulate_nop},
21662306a36Sopenharmony_ci	[PROBES_SEV] = {.handler = probes_simulate_nop},
21762306a36Sopenharmony_ci	[PROBES_WFE] = {.handler = probes_simulate_nop},
21862306a36Sopenharmony_ci	[PROBES_SATURATE] = {.handler = probes_simulate_nop},
21962306a36Sopenharmony_ci	[PROBES_REV] = {.handler = probes_simulate_nop},
22062306a36Sopenharmony_ci	[PROBES_MMI] = {.handler = probes_simulate_nop},
22162306a36Sopenharmony_ci	[PROBES_PACK] = {.handler = probes_simulate_nop},
22262306a36Sopenharmony_ci	[PROBES_EXTEND] = {.handler = probes_simulate_nop},
22362306a36Sopenharmony_ci	[PROBES_EXTEND_ADD] = {.handler = probes_simulate_nop},
22462306a36Sopenharmony_ci	[PROBES_MUL_ADD_LONG] = {.handler = probes_simulate_nop},
22562306a36Sopenharmony_ci	[PROBES_MUL_ADD] = {.handler = probes_simulate_nop},
22662306a36Sopenharmony_ci	[PROBES_BITFIELD] = {.handler = probes_simulate_nop},
22762306a36Sopenharmony_ci	[PROBES_BRANCH] = {.handler = simulate_bbl},
22862306a36Sopenharmony_ci	[PROBES_LDMSTM] = {.decoder = uprobe_decode_ldmstm}
22962306a36Sopenharmony_ci};
230