162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0-only 262306a36Sopenharmony_ci#include <linux/kernel.h> 362306a36Sopenharmony_ci#include <linux/mm.h> 462306a36Sopenharmony_ci#include <linux/smp.h> 562306a36Sopenharmony_ci#include <linux/spinlock.h> 662306a36Sopenharmony_ci#include <linux/stop_machine.h> 762306a36Sopenharmony_ci#include <linux/uaccess.h> 862306a36Sopenharmony_ci 962306a36Sopenharmony_ci#include <asm/cacheflush.h> 1062306a36Sopenharmony_ci#include <asm/fixmap.h> 1162306a36Sopenharmony_ci#include <asm/insn.h> 1262306a36Sopenharmony_ci#include <asm/kprobes.h> 1362306a36Sopenharmony_ci#include <asm/patching.h> 1462306a36Sopenharmony_ci#include <asm/sections.h> 1562306a36Sopenharmony_ci 1662306a36Sopenharmony_cistatic DEFINE_RAW_SPINLOCK(patch_lock); 1762306a36Sopenharmony_ci 1862306a36Sopenharmony_cistatic bool is_exit_text(unsigned long addr) 1962306a36Sopenharmony_ci{ 2062306a36Sopenharmony_ci /* discarded with init text/data */ 2162306a36Sopenharmony_ci return system_state < SYSTEM_RUNNING && 2262306a36Sopenharmony_ci addr >= (unsigned long)__exittext_begin && 2362306a36Sopenharmony_ci addr < (unsigned long)__exittext_end; 2462306a36Sopenharmony_ci} 2562306a36Sopenharmony_ci 2662306a36Sopenharmony_cistatic bool is_image_text(unsigned long addr) 2762306a36Sopenharmony_ci{ 2862306a36Sopenharmony_ci return core_kernel_text(addr) || is_exit_text(addr); 2962306a36Sopenharmony_ci} 3062306a36Sopenharmony_ci 3162306a36Sopenharmony_cistatic void __kprobes *patch_map(void *addr, int fixmap) 3262306a36Sopenharmony_ci{ 3362306a36Sopenharmony_ci unsigned long uintaddr = (uintptr_t) addr; 3462306a36Sopenharmony_ci bool image = is_image_text(uintaddr); 3562306a36Sopenharmony_ci struct page *page; 3662306a36Sopenharmony_ci 3762306a36Sopenharmony_ci if (image) 3862306a36Sopenharmony_ci page = phys_to_page(__pa_symbol(addr)); 3962306a36Sopenharmony_ci else if (IS_ENABLED(CONFIG_STRICT_MODULE_RWX)) 4062306a36Sopenharmony_ci page = vmalloc_to_page(addr); 4162306a36Sopenharmony_ci else 4262306a36Sopenharmony_ci return addr; 4362306a36Sopenharmony_ci 4462306a36Sopenharmony_ci BUG_ON(!page); 4562306a36Sopenharmony_ci return (void *)set_fixmap_offset(fixmap, page_to_phys(page) + 4662306a36Sopenharmony_ci (uintaddr & ~PAGE_MASK)); 4762306a36Sopenharmony_ci} 4862306a36Sopenharmony_ci 4962306a36Sopenharmony_cistatic void __kprobes patch_unmap(int fixmap) 5062306a36Sopenharmony_ci{ 5162306a36Sopenharmony_ci clear_fixmap(fixmap); 5262306a36Sopenharmony_ci} 5362306a36Sopenharmony_ci/* 5462306a36Sopenharmony_ci * In ARMv8-A, A64 instructions have a fixed length of 32 bits and are always 5562306a36Sopenharmony_ci * little-endian. 5662306a36Sopenharmony_ci */ 5762306a36Sopenharmony_ciint __kprobes aarch64_insn_read(void *addr, u32 *insnp) 5862306a36Sopenharmony_ci{ 5962306a36Sopenharmony_ci int ret; 6062306a36Sopenharmony_ci __le32 val; 6162306a36Sopenharmony_ci 6262306a36Sopenharmony_ci ret = copy_from_kernel_nofault(&val, addr, AARCH64_INSN_SIZE); 6362306a36Sopenharmony_ci if (!ret) 6462306a36Sopenharmony_ci *insnp = le32_to_cpu(val); 6562306a36Sopenharmony_ci 6662306a36Sopenharmony_ci return ret; 6762306a36Sopenharmony_ci} 6862306a36Sopenharmony_ci 6962306a36Sopenharmony_cistatic int __kprobes __aarch64_insn_write(void *addr, __le32 insn) 7062306a36Sopenharmony_ci{ 7162306a36Sopenharmony_ci void *waddr = addr; 7262306a36Sopenharmony_ci unsigned long flags = 0; 7362306a36Sopenharmony_ci int ret; 7462306a36Sopenharmony_ci 7562306a36Sopenharmony_ci raw_spin_lock_irqsave(&patch_lock, flags); 7662306a36Sopenharmony_ci waddr = patch_map(addr, FIX_TEXT_POKE0); 7762306a36Sopenharmony_ci 7862306a36Sopenharmony_ci ret = copy_to_kernel_nofault(waddr, &insn, AARCH64_INSN_SIZE); 7962306a36Sopenharmony_ci 8062306a36Sopenharmony_ci patch_unmap(FIX_TEXT_POKE0); 8162306a36Sopenharmony_ci raw_spin_unlock_irqrestore(&patch_lock, flags); 8262306a36Sopenharmony_ci 8362306a36Sopenharmony_ci return ret; 8462306a36Sopenharmony_ci} 8562306a36Sopenharmony_ci 8662306a36Sopenharmony_ciint __kprobes aarch64_insn_write(void *addr, u32 insn) 8762306a36Sopenharmony_ci{ 8862306a36Sopenharmony_ci return __aarch64_insn_write(addr, cpu_to_le32(insn)); 8962306a36Sopenharmony_ci} 9062306a36Sopenharmony_ci 9162306a36Sopenharmony_cinoinstr int aarch64_insn_write_literal_u64(void *addr, u64 val) 9262306a36Sopenharmony_ci{ 9362306a36Sopenharmony_ci u64 *waddr; 9462306a36Sopenharmony_ci unsigned long flags; 9562306a36Sopenharmony_ci int ret; 9662306a36Sopenharmony_ci 9762306a36Sopenharmony_ci raw_spin_lock_irqsave(&patch_lock, flags); 9862306a36Sopenharmony_ci waddr = patch_map(addr, FIX_TEXT_POKE0); 9962306a36Sopenharmony_ci 10062306a36Sopenharmony_ci ret = copy_to_kernel_nofault(waddr, &val, sizeof(val)); 10162306a36Sopenharmony_ci 10262306a36Sopenharmony_ci patch_unmap(FIX_TEXT_POKE0); 10362306a36Sopenharmony_ci raw_spin_unlock_irqrestore(&patch_lock, flags); 10462306a36Sopenharmony_ci 10562306a36Sopenharmony_ci return ret; 10662306a36Sopenharmony_ci} 10762306a36Sopenharmony_ci 10862306a36Sopenharmony_ciint __kprobes aarch64_insn_patch_text_nosync(void *addr, u32 insn) 10962306a36Sopenharmony_ci{ 11062306a36Sopenharmony_ci u32 *tp = addr; 11162306a36Sopenharmony_ci int ret; 11262306a36Sopenharmony_ci 11362306a36Sopenharmony_ci /* A64 instructions must be word aligned */ 11462306a36Sopenharmony_ci if ((uintptr_t)tp & 0x3) 11562306a36Sopenharmony_ci return -EINVAL; 11662306a36Sopenharmony_ci 11762306a36Sopenharmony_ci ret = aarch64_insn_write(tp, insn); 11862306a36Sopenharmony_ci if (ret == 0) 11962306a36Sopenharmony_ci caches_clean_inval_pou((uintptr_t)tp, 12062306a36Sopenharmony_ci (uintptr_t)tp + AARCH64_INSN_SIZE); 12162306a36Sopenharmony_ci 12262306a36Sopenharmony_ci return ret; 12362306a36Sopenharmony_ci} 12462306a36Sopenharmony_ci 12562306a36Sopenharmony_cistruct aarch64_insn_patch { 12662306a36Sopenharmony_ci void **text_addrs; 12762306a36Sopenharmony_ci u32 *new_insns; 12862306a36Sopenharmony_ci int insn_cnt; 12962306a36Sopenharmony_ci atomic_t cpu_count; 13062306a36Sopenharmony_ci}; 13162306a36Sopenharmony_ci 13262306a36Sopenharmony_cistatic int __kprobes aarch64_insn_patch_text_cb(void *arg) 13362306a36Sopenharmony_ci{ 13462306a36Sopenharmony_ci int i, ret = 0; 13562306a36Sopenharmony_ci struct aarch64_insn_patch *pp = arg; 13662306a36Sopenharmony_ci 13762306a36Sopenharmony_ci /* The last CPU becomes master */ 13862306a36Sopenharmony_ci if (atomic_inc_return(&pp->cpu_count) == num_online_cpus()) { 13962306a36Sopenharmony_ci for (i = 0; ret == 0 && i < pp->insn_cnt; i++) 14062306a36Sopenharmony_ci ret = aarch64_insn_patch_text_nosync(pp->text_addrs[i], 14162306a36Sopenharmony_ci pp->new_insns[i]); 14262306a36Sopenharmony_ci /* Notify other processors with an additional increment. */ 14362306a36Sopenharmony_ci atomic_inc(&pp->cpu_count); 14462306a36Sopenharmony_ci } else { 14562306a36Sopenharmony_ci while (atomic_read(&pp->cpu_count) <= num_online_cpus()) 14662306a36Sopenharmony_ci cpu_relax(); 14762306a36Sopenharmony_ci isb(); 14862306a36Sopenharmony_ci } 14962306a36Sopenharmony_ci 15062306a36Sopenharmony_ci return ret; 15162306a36Sopenharmony_ci} 15262306a36Sopenharmony_ci 15362306a36Sopenharmony_ciint __kprobes aarch64_insn_patch_text(void *addrs[], u32 insns[], int cnt) 15462306a36Sopenharmony_ci{ 15562306a36Sopenharmony_ci struct aarch64_insn_patch patch = { 15662306a36Sopenharmony_ci .text_addrs = addrs, 15762306a36Sopenharmony_ci .new_insns = insns, 15862306a36Sopenharmony_ci .insn_cnt = cnt, 15962306a36Sopenharmony_ci .cpu_count = ATOMIC_INIT(0), 16062306a36Sopenharmony_ci }; 16162306a36Sopenharmony_ci 16262306a36Sopenharmony_ci if (cnt <= 0) 16362306a36Sopenharmony_ci return -EINVAL; 16462306a36Sopenharmony_ci 16562306a36Sopenharmony_ci return stop_machine_cpuslocked(aarch64_insn_patch_text_cb, &patch, 16662306a36Sopenharmony_ci cpu_online_mask); 16762306a36Sopenharmony_ci} 168