162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only
262306a36Sopenharmony_ci#include <linux/kernel.h>
362306a36Sopenharmony_ci#include <linux/mm.h>
462306a36Sopenharmony_ci#include <linux/smp.h>
562306a36Sopenharmony_ci#include <linux/spinlock.h>
662306a36Sopenharmony_ci#include <linux/stop_machine.h>
762306a36Sopenharmony_ci#include <linux/uaccess.h>
862306a36Sopenharmony_ci
962306a36Sopenharmony_ci#include <asm/cacheflush.h>
1062306a36Sopenharmony_ci#include <asm/fixmap.h>
1162306a36Sopenharmony_ci#include <asm/insn.h>
1262306a36Sopenharmony_ci#include <asm/kprobes.h>
1362306a36Sopenharmony_ci#include <asm/patching.h>
1462306a36Sopenharmony_ci#include <asm/sections.h>
1562306a36Sopenharmony_ci
1662306a36Sopenharmony_cistatic DEFINE_RAW_SPINLOCK(patch_lock);
1762306a36Sopenharmony_ci
1862306a36Sopenharmony_cistatic bool is_exit_text(unsigned long addr)
1962306a36Sopenharmony_ci{
2062306a36Sopenharmony_ci	/* discarded with init text/data */
2162306a36Sopenharmony_ci	return system_state < SYSTEM_RUNNING &&
2262306a36Sopenharmony_ci		addr >= (unsigned long)__exittext_begin &&
2362306a36Sopenharmony_ci		addr < (unsigned long)__exittext_end;
2462306a36Sopenharmony_ci}
2562306a36Sopenharmony_ci
2662306a36Sopenharmony_cistatic bool is_image_text(unsigned long addr)
2762306a36Sopenharmony_ci{
2862306a36Sopenharmony_ci	return core_kernel_text(addr) || is_exit_text(addr);
2962306a36Sopenharmony_ci}
3062306a36Sopenharmony_ci
3162306a36Sopenharmony_cistatic void __kprobes *patch_map(void *addr, int fixmap)
3262306a36Sopenharmony_ci{
3362306a36Sopenharmony_ci	unsigned long uintaddr = (uintptr_t) addr;
3462306a36Sopenharmony_ci	bool image = is_image_text(uintaddr);
3562306a36Sopenharmony_ci	struct page *page;
3662306a36Sopenharmony_ci
3762306a36Sopenharmony_ci	if (image)
3862306a36Sopenharmony_ci		page = phys_to_page(__pa_symbol(addr));
3962306a36Sopenharmony_ci	else if (IS_ENABLED(CONFIG_STRICT_MODULE_RWX))
4062306a36Sopenharmony_ci		page = vmalloc_to_page(addr);
4162306a36Sopenharmony_ci	else
4262306a36Sopenharmony_ci		return addr;
4362306a36Sopenharmony_ci
4462306a36Sopenharmony_ci	BUG_ON(!page);
4562306a36Sopenharmony_ci	return (void *)set_fixmap_offset(fixmap, page_to_phys(page) +
4662306a36Sopenharmony_ci			(uintaddr & ~PAGE_MASK));
4762306a36Sopenharmony_ci}
4862306a36Sopenharmony_ci
4962306a36Sopenharmony_cistatic void __kprobes patch_unmap(int fixmap)
5062306a36Sopenharmony_ci{
5162306a36Sopenharmony_ci	clear_fixmap(fixmap);
5262306a36Sopenharmony_ci}
5362306a36Sopenharmony_ci/*
5462306a36Sopenharmony_ci * In ARMv8-A, A64 instructions have a fixed length of 32 bits and are always
5562306a36Sopenharmony_ci * little-endian.
5662306a36Sopenharmony_ci */
5762306a36Sopenharmony_ciint __kprobes aarch64_insn_read(void *addr, u32 *insnp)
5862306a36Sopenharmony_ci{
5962306a36Sopenharmony_ci	int ret;
6062306a36Sopenharmony_ci	__le32 val;
6162306a36Sopenharmony_ci
6262306a36Sopenharmony_ci	ret = copy_from_kernel_nofault(&val, addr, AARCH64_INSN_SIZE);
6362306a36Sopenharmony_ci	if (!ret)
6462306a36Sopenharmony_ci		*insnp = le32_to_cpu(val);
6562306a36Sopenharmony_ci
6662306a36Sopenharmony_ci	return ret;
6762306a36Sopenharmony_ci}
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_cistatic int __kprobes __aarch64_insn_write(void *addr, __le32 insn)
7062306a36Sopenharmony_ci{
7162306a36Sopenharmony_ci	void *waddr = addr;
7262306a36Sopenharmony_ci	unsigned long flags = 0;
7362306a36Sopenharmony_ci	int ret;
7462306a36Sopenharmony_ci
7562306a36Sopenharmony_ci	raw_spin_lock_irqsave(&patch_lock, flags);
7662306a36Sopenharmony_ci	waddr = patch_map(addr, FIX_TEXT_POKE0);
7762306a36Sopenharmony_ci
7862306a36Sopenharmony_ci	ret = copy_to_kernel_nofault(waddr, &insn, AARCH64_INSN_SIZE);
7962306a36Sopenharmony_ci
8062306a36Sopenharmony_ci	patch_unmap(FIX_TEXT_POKE0);
8162306a36Sopenharmony_ci	raw_spin_unlock_irqrestore(&patch_lock, flags);
8262306a36Sopenharmony_ci
8362306a36Sopenharmony_ci	return ret;
8462306a36Sopenharmony_ci}
8562306a36Sopenharmony_ci
8662306a36Sopenharmony_ciint __kprobes aarch64_insn_write(void *addr, u32 insn)
8762306a36Sopenharmony_ci{
8862306a36Sopenharmony_ci	return __aarch64_insn_write(addr, cpu_to_le32(insn));
8962306a36Sopenharmony_ci}
9062306a36Sopenharmony_ci
9162306a36Sopenharmony_cinoinstr int aarch64_insn_write_literal_u64(void *addr, u64 val)
9262306a36Sopenharmony_ci{
9362306a36Sopenharmony_ci	u64 *waddr;
9462306a36Sopenharmony_ci	unsigned long flags;
9562306a36Sopenharmony_ci	int ret;
9662306a36Sopenharmony_ci
9762306a36Sopenharmony_ci	raw_spin_lock_irqsave(&patch_lock, flags);
9862306a36Sopenharmony_ci	waddr = patch_map(addr, FIX_TEXT_POKE0);
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_ci	ret = copy_to_kernel_nofault(waddr, &val, sizeof(val));
10162306a36Sopenharmony_ci
10262306a36Sopenharmony_ci	patch_unmap(FIX_TEXT_POKE0);
10362306a36Sopenharmony_ci	raw_spin_unlock_irqrestore(&patch_lock, flags);
10462306a36Sopenharmony_ci
10562306a36Sopenharmony_ci	return ret;
10662306a36Sopenharmony_ci}
10762306a36Sopenharmony_ci
10862306a36Sopenharmony_ciint __kprobes aarch64_insn_patch_text_nosync(void *addr, u32 insn)
10962306a36Sopenharmony_ci{
11062306a36Sopenharmony_ci	u32 *tp = addr;
11162306a36Sopenharmony_ci	int ret;
11262306a36Sopenharmony_ci
11362306a36Sopenharmony_ci	/* A64 instructions must be word aligned */
11462306a36Sopenharmony_ci	if ((uintptr_t)tp & 0x3)
11562306a36Sopenharmony_ci		return -EINVAL;
11662306a36Sopenharmony_ci
11762306a36Sopenharmony_ci	ret = aarch64_insn_write(tp, insn);
11862306a36Sopenharmony_ci	if (ret == 0)
11962306a36Sopenharmony_ci		caches_clean_inval_pou((uintptr_t)tp,
12062306a36Sopenharmony_ci				     (uintptr_t)tp + AARCH64_INSN_SIZE);
12162306a36Sopenharmony_ci
12262306a36Sopenharmony_ci	return ret;
12362306a36Sopenharmony_ci}
12462306a36Sopenharmony_ci
12562306a36Sopenharmony_cistruct aarch64_insn_patch {
12662306a36Sopenharmony_ci	void		**text_addrs;
12762306a36Sopenharmony_ci	u32		*new_insns;
12862306a36Sopenharmony_ci	int		insn_cnt;
12962306a36Sopenharmony_ci	atomic_t	cpu_count;
13062306a36Sopenharmony_ci};
13162306a36Sopenharmony_ci
13262306a36Sopenharmony_cistatic int __kprobes aarch64_insn_patch_text_cb(void *arg)
13362306a36Sopenharmony_ci{
13462306a36Sopenharmony_ci	int i, ret = 0;
13562306a36Sopenharmony_ci	struct aarch64_insn_patch *pp = arg;
13662306a36Sopenharmony_ci
13762306a36Sopenharmony_ci	/* The last CPU becomes master */
13862306a36Sopenharmony_ci	if (atomic_inc_return(&pp->cpu_count) == num_online_cpus()) {
13962306a36Sopenharmony_ci		for (i = 0; ret == 0 && i < pp->insn_cnt; i++)
14062306a36Sopenharmony_ci			ret = aarch64_insn_patch_text_nosync(pp->text_addrs[i],
14162306a36Sopenharmony_ci							     pp->new_insns[i]);
14262306a36Sopenharmony_ci		/* Notify other processors with an additional increment. */
14362306a36Sopenharmony_ci		atomic_inc(&pp->cpu_count);
14462306a36Sopenharmony_ci	} else {
14562306a36Sopenharmony_ci		while (atomic_read(&pp->cpu_count) <= num_online_cpus())
14662306a36Sopenharmony_ci			cpu_relax();
14762306a36Sopenharmony_ci		isb();
14862306a36Sopenharmony_ci	}
14962306a36Sopenharmony_ci
15062306a36Sopenharmony_ci	return ret;
15162306a36Sopenharmony_ci}
15262306a36Sopenharmony_ci
15362306a36Sopenharmony_ciint __kprobes aarch64_insn_patch_text(void *addrs[], u32 insns[], int cnt)
15462306a36Sopenharmony_ci{
15562306a36Sopenharmony_ci	struct aarch64_insn_patch patch = {
15662306a36Sopenharmony_ci		.text_addrs = addrs,
15762306a36Sopenharmony_ci		.new_insns = insns,
15862306a36Sopenharmony_ci		.insn_cnt = cnt,
15962306a36Sopenharmony_ci		.cpu_count = ATOMIC_INIT(0),
16062306a36Sopenharmony_ci	};
16162306a36Sopenharmony_ci
16262306a36Sopenharmony_ci	if (cnt <= 0)
16362306a36Sopenharmony_ci		return -EINVAL;
16462306a36Sopenharmony_ci
16562306a36Sopenharmony_ci	return stop_machine_cpuslocked(aarch64_insn_patch_text_cb, &patch,
16662306a36Sopenharmony_ci				       cpu_online_mask);
16762306a36Sopenharmony_ci}
168