162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0+ 262306a36Sopenharmony_ci 362306a36Sopenharmony_ci#include <linux/bitops.h> 462306a36Sopenharmony_ci#include <linux/kernel.h> 562306a36Sopenharmony_ci#include <linux/kprobes.h> 662306a36Sopenharmony_ci 762306a36Sopenharmony_ci#include "decode-insn.h" 862306a36Sopenharmony_ci#include "simulate-insn.h" 962306a36Sopenharmony_ci 1062306a36Sopenharmony_cistatic inline bool rv_insn_reg_get_val(struct pt_regs *regs, u32 index, 1162306a36Sopenharmony_ci unsigned long *ptr) 1262306a36Sopenharmony_ci{ 1362306a36Sopenharmony_ci if (index == 0) 1462306a36Sopenharmony_ci *ptr = 0; 1562306a36Sopenharmony_ci else if (index <= 31) 1662306a36Sopenharmony_ci *ptr = *((unsigned long *)regs + index); 1762306a36Sopenharmony_ci else 1862306a36Sopenharmony_ci return false; 1962306a36Sopenharmony_ci 2062306a36Sopenharmony_ci return true; 2162306a36Sopenharmony_ci} 2262306a36Sopenharmony_ci 2362306a36Sopenharmony_cistatic inline bool rv_insn_reg_set_val(struct pt_regs *regs, u32 index, 2462306a36Sopenharmony_ci unsigned long val) 2562306a36Sopenharmony_ci{ 2662306a36Sopenharmony_ci if (index == 0) 2762306a36Sopenharmony_ci return true; 2862306a36Sopenharmony_ci else if (index <= 31) 2962306a36Sopenharmony_ci *((unsigned long *)regs + index) = val; 3062306a36Sopenharmony_ci else 3162306a36Sopenharmony_ci return false; 3262306a36Sopenharmony_ci 3362306a36Sopenharmony_ci return true; 3462306a36Sopenharmony_ci} 3562306a36Sopenharmony_ci 3662306a36Sopenharmony_cibool __kprobes simulate_jal(u32 opcode, unsigned long addr, struct pt_regs *regs) 3762306a36Sopenharmony_ci{ 3862306a36Sopenharmony_ci /* 3962306a36Sopenharmony_ci * 31 30 21 20 19 12 11 7 6 0 4062306a36Sopenharmony_ci * imm [20] | imm[10:1] | imm[11] | imm[19:12] | rd | opcode 4162306a36Sopenharmony_ci * 1 10 1 8 5 JAL/J 4262306a36Sopenharmony_ci */ 4362306a36Sopenharmony_ci bool ret; 4462306a36Sopenharmony_ci u32 imm; 4562306a36Sopenharmony_ci u32 index = (opcode >> 7) & 0x1f; 4662306a36Sopenharmony_ci 4762306a36Sopenharmony_ci ret = rv_insn_reg_set_val(regs, index, addr + 4); 4862306a36Sopenharmony_ci if (!ret) 4962306a36Sopenharmony_ci return ret; 5062306a36Sopenharmony_ci 5162306a36Sopenharmony_ci imm = ((opcode >> 21) & 0x3ff) << 1; 5262306a36Sopenharmony_ci imm |= ((opcode >> 20) & 0x1) << 11; 5362306a36Sopenharmony_ci imm |= ((opcode >> 12) & 0xff) << 12; 5462306a36Sopenharmony_ci imm |= ((opcode >> 31) & 0x1) << 20; 5562306a36Sopenharmony_ci 5662306a36Sopenharmony_ci instruction_pointer_set(regs, addr + sign_extend32((imm), 20)); 5762306a36Sopenharmony_ci 5862306a36Sopenharmony_ci return ret; 5962306a36Sopenharmony_ci} 6062306a36Sopenharmony_ci 6162306a36Sopenharmony_cibool __kprobes simulate_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs) 6262306a36Sopenharmony_ci{ 6362306a36Sopenharmony_ci /* 6462306a36Sopenharmony_ci * 31 20 19 15 14 12 11 7 6 0 6562306a36Sopenharmony_ci * offset[11:0] | rs1 | 010 | rd | opcode 6662306a36Sopenharmony_ci * 12 5 3 5 JALR/JR 6762306a36Sopenharmony_ci */ 6862306a36Sopenharmony_ci bool ret; 6962306a36Sopenharmony_ci unsigned long base_addr; 7062306a36Sopenharmony_ci u32 imm = (opcode >> 20) & 0xfff; 7162306a36Sopenharmony_ci u32 rd_index = (opcode >> 7) & 0x1f; 7262306a36Sopenharmony_ci u32 rs1_index = (opcode >> 15) & 0x1f; 7362306a36Sopenharmony_ci 7462306a36Sopenharmony_ci ret = rv_insn_reg_get_val(regs, rs1_index, &base_addr); 7562306a36Sopenharmony_ci if (!ret) 7662306a36Sopenharmony_ci return ret; 7762306a36Sopenharmony_ci 7862306a36Sopenharmony_ci ret = rv_insn_reg_set_val(regs, rd_index, addr + 4); 7962306a36Sopenharmony_ci if (!ret) 8062306a36Sopenharmony_ci return ret; 8162306a36Sopenharmony_ci 8262306a36Sopenharmony_ci instruction_pointer_set(regs, (base_addr + sign_extend32((imm), 11))&~1); 8362306a36Sopenharmony_ci 8462306a36Sopenharmony_ci return ret; 8562306a36Sopenharmony_ci} 8662306a36Sopenharmony_ci 8762306a36Sopenharmony_ci#define auipc_rd_idx(opcode) \ 8862306a36Sopenharmony_ci ((opcode >> 7) & 0x1f) 8962306a36Sopenharmony_ci 9062306a36Sopenharmony_ci#define auipc_imm(opcode) \ 9162306a36Sopenharmony_ci ((((opcode) >> 12) & 0xfffff) << 12) 9262306a36Sopenharmony_ci 9362306a36Sopenharmony_ci#if __riscv_xlen == 64 9462306a36Sopenharmony_ci#define auipc_offset(opcode) sign_extend64(auipc_imm(opcode), 31) 9562306a36Sopenharmony_ci#elif __riscv_xlen == 32 9662306a36Sopenharmony_ci#define auipc_offset(opcode) auipc_imm(opcode) 9762306a36Sopenharmony_ci#else 9862306a36Sopenharmony_ci#error "Unexpected __riscv_xlen" 9962306a36Sopenharmony_ci#endif 10062306a36Sopenharmony_ci 10162306a36Sopenharmony_cibool __kprobes simulate_auipc(u32 opcode, unsigned long addr, struct pt_regs *regs) 10262306a36Sopenharmony_ci{ 10362306a36Sopenharmony_ci /* 10462306a36Sopenharmony_ci * auipc instruction: 10562306a36Sopenharmony_ci * 31 12 11 7 6 0 10662306a36Sopenharmony_ci * | imm[31:12] | rd | opcode | 10762306a36Sopenharmony_ci * 20 5 7 10862306a36Sopenharmony_ci */ 10962306a36Sopenharmony_ci 11062306a36Sopenharmony_ci u32 rd_idx = auipc_rd_idx(opcode); 11162306a36Sopenharmony_ci unsigned long rd_val = addr + auipc_offset(opcode); 11262306a36Sopenharmony_ci 11362306a36Sopenharmony_ci if (!rv_insn_reg_set_val(regs, rd_idx, rd_val)) 11462306a36Sopenharmony_ci return false; 11562306a36Sopenharmony_ci 11662306a36Sopenharmony_ci instruction_pointer_set(regs, addr + 4); 11762306a36Sopenharmony_ci 11862306a36Sopenharmony_ci return true; 11962306a36Sopenharmony_ci} 12062306a36Sopenharmony_ci 12162306a36Sopenharmony_ci#define branch_rs1_idx(opcode) \ 12262306a36Sopenharmony_ci (((opcode) >> 15) & 0x1f) 12362306a36Sopenharmony_ci 12462306a36Sopenharmony_ci#define branch_rs2_idx(opcode) \ 12562306a36Sopenharmony_ci (((opcode) >> 20) & 0x1f) 12662306a36Sopenharmony_ci 12762306a36Sopenharmony_ci#define branch_funct3(opcode) \ 12862306a36Sopenharmony_ci (((opcode) >> 12) & 0x7) 12962306a36Sopenharmony_ci 13062306a36Sopenharmony_ci#define branch_imm(opcode) \ 13162306a36Sopenharmony_ci (((((opcode) >> 8) & 0xf ) << 1) | \ 13262306a36Sopenharmony_ci ((((opcode) >> 25) & 0x3f) << 5) | \ 13362306a36Sopenharmony_ci ((((opcode) >> 7) & 0x1 ) << 11) | \ 13462306a36Sopenharmony_ci ((((opcode) >> 31) & 0x1 ) << 12)) 13562306a36Sopenharmony_ci 13662306a36Sopenharmony_ci#define branch_offset(opcode) \ 13762306a36Sopenharmony_ci sign_extend32((branch_imm(opcode)), 12) 13862306a36Sopenharmony_ci 13962306a36Sopenharmony_cibool __kprobes simulate_branch(u32 opcode, unsigned long addr, struct pt_regs *regs) 14062306a36Sopenharmony_ci{ 14162306a36Sopenharmony_ci /* 14262306a36Sopenharmony_ci * branch instructions: 14362306a36Sopenharmony_ci * 31 30 25 24 20 19 15 14 12 11 8 7 6 0 14462306a36Sopenharmony_ci * | imm[12] | imm[10:5] | rs2 | rs1 | funct3 | imm[4:1] | imm[11] | opcode | 14562306a36Sopenharmony_ci * 1 6 5 5 3 4 1 7 14662306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 000 imm[4:1|11] 1100011 BEQ 14762306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 001 imm[4:1|11] 1100011 BNE 14862306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 100 imm[4:1|11] 1100011 BLT 14962306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 101 imm[4:1|11] 1100011 BGE 15062306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 110 imm[4:1|11] 1100011 BLTU 15162306a36Sopenharmony_ci * imm[12|10:5] rs2 rs1 111 imm[4:1|11] 1100011 BGEU 15262306a36Sopenharmony_ci */ 15362306a36Sopenharmony_ci 15462306a36Sopenharmony_ci s32 offset; 15562306a36Sopenharmony_ci s32 offset_tmp; 15662306a36Sopenharmony_ci unsigned long rs1_val; 15762306a36Sopenharmony_ci unsigned long rs2_val; 15862306a36Sopenharmony_ci 15962306a36Sopenharmony_ci if (!rv_insn_reg_get_val(regs, branch_rs1_idx(opcode), &rs1_val) || 16062306a36Sopenharmony_ci !rv_insn_reg_get_val(regs, branch_rs2_idx(opcode), &rs2_val)) 16162306a36Sopenharmony_ci return false; 16262306a36Sopenharmony_ci 16362306a36Sopenharmony_ci offset_tmp = branch_offset(opcode); 16462306a36Sopenharmony_ci switch (branch_funct3(opcode)) { 16562306a36Sopenharmony_ci case RVG_FUNCT3_BEQ: 16662306a36Sopenharmony_ci offset = (rs1_val == rs2_val) ? offset_tmp : 4; 16762306a36Sopenharmony_ci break; 16862306a36Sopenharmony_ci case RVG_FUNCT3_BNE: 16962306a36Sopenharmony_ci offset = (rs1_val != rs2_val) ? offset_tmp : 4; 17062306a36Sopenharmony_ci break; 17162306a36Sopenharmony_ci case RVG_FUNCT3_BLT: 17262306a36Sopenharmony_ci offset = ((long)rs1_val < (long)rs2_val) ? offset_tmp : 4; 17362306a36Sopenharmony_ci break; 17462306a36Sopenharmony_ci case RVG_FUNCT3_BGE: 17562306a36Sopenharmony_ci offset = ((long)rs1_val >= (long)rs2_val) ? offset_tmp : 4; 17662306a36Sopenharmony_ci break; 17762306a36Sopenharmony_ci case RVG_FUNCT3_BLTU: 17862306a36Sopenharmony_ci offset = (rs1_val < rs2_val) ? offset_tmp : 4; 17962306a36Sopenharmony_ci break; 18062306a36Sopenharmony_ci case RVG_FUNCT3_BGEU: 18162306a36Sopenharmony_ci offset = (rs1_val >= rs2_val) ? offset_tmp : 4; 18262306a36Sopenharmony_ci break; 18362306a36Sopenharmony_ci default: 18462306a36Sopenharmony_ci return false; 18562306a36Sopenharmony_ci } 18662306a36Sopenharmony_ci 18762306a36Sopenharmony_ci instruction_pointer_set(regs, addr + offset); 18862306a36Sopenharmony_ci 18962306a36Sopenharmony_ci return true; 19062306a36Sopenharmony_ci} 19162306a36Sopenharmony_ci 19262306a36Sopenharmony_cibool __kprobes simulate_c_j(u32 opcode, unsigned long addr, struct pt_regs *regs) 19362306a36Sopenharmony_ci{ 19462306a36Sopenharmony_ci /* 19562306a36Sopenharmony_ci * 15 13 12 2 1 0 19662306a36Sopenharmony_ci * | funct3 | offset[11|4|9:8|10|6|7|3:1|5] | opcode | 19762306a36Sopenharmony_ci * 3 11 2 19862306a36Sopenharmony_ci */ 19962306a36Sopenharmony_ci 20062306a36Sopenharmony_ci s32 offset; 20162306a36Sopenharmony_ci 20262306a36Sopenharmony_ci offset = ((opcode >> 3) & 0x7) << 1; 20362306a36Sopenharmony_ci offset |= ((opcode >> 11) & 0x1) << 4; 20462306a36Sopenharmony_ci offset |= ((opcode >> 2) & 0x1) << 5; 20562306a36Sopenharmony_ci offset |= ((opcode >> 7) & 0x1) << 6; 20662306a36Sopenharmony_ci offset |= ((opcode >> 6) & 0x1) << 7; 20762306a36Sopenharmony_ci offset |= ((opcode >> 9) & 0x3) << 8; 20862306a36Sopenharmony_ci offset |= ((opcode >> 8) & 0x1) << 10; 20962306a36Sopenharmony_ci offset |= ((opcode >> 12) & 0x1) << 11; 21062306a36Sopenharmony_ci 21162306a36Sopenharmony_ci instruction_pointer_set(regs, addr + sign_extend32(offset, 11)); 21262306a36Sopenharmony_ci 21362306a36Sopenharmony_ci return true; 21462306a36Sopenharmony_ci} 21562306a36Sopenharmony_ci 21662306a36Sopenharmony_cistatic bool __kprobes simulate_c_jr_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs, 21762306a36Sopenharmony_ci bool is_jalr) 21862306a36Sopenharmony_ci{ 21962306a36Sopenharmony_ci /* 22062306a36Sopenharmony_ci * 15 12 11 7 6 2 1 0 22162306a36Sopenharmony_ci * | funct4 | rs1 | rs2 | op | 22262306a36Sopenharmony_ci * 4 5 5 2 22362306a36Sopenharmony_ci */ 22462306a36Sopenharmony_ci 22562306a36Sopenharmony_ci unsigned long jump_addr; 22662306a36Sopenharmony_ci 22762306a36Sopenharmony_ci u32 rs1 = (opcode >> 7) & 0x1f; 22862306a36Sopenharmony_ci 22962306a36Sopenharmony_ci if (rs1 == 0) /* C.JR is only valid when rs1 != x0 */ 23062306a36Sopenharmony_ci return false; 23162306a36Sopenharmony_ci 23262306a36Sopenharmony_ci if (!rv_insn_reg_get_val(regs, rs1, &jump_addr)) 23362306a36Sopenharmony_ci return false; 23462306a36Sopenharmony_ci 23562306a36Sopenharmony_ci if (is_jalr && !rv_insn_reg_set_val(regs, 1, addr + 2)) 23662306a36Sopenharmony_ci return false; 23762306a36Sopenharmony_ci 23862306a36Sopenharmony_ci instruction_pointer_set(regs, jump_addr); 23962306a36Sopenharmony_ci 24062306a36Sopenharmony_ci return true; 24162306a36Sopenharmony_ci} 24262306a36Sopenharmony_ci 24362306a36Sopenharmony_cibool __kprobes simulate_c_jr(u32 opcode, unsigned long addr, struct pt_regs *regs) 24462306a36Sopenharmony_ci{ 24562306a36Sopenharmony_ci return simulate_c_jr_jalr(opcode, addr, regs, false); 24662306a36Sopenharmony_ci} 24762306a36Sopenharmony_ci 24862306a36Sopenharmony_cibool __kprobes simulate_c_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs) 24962306a36Sopenharmony_ci{ 25062306a36Sopenharmony_ci return simulate_c_jr_jalr(opcode, addr, regs, true); 25162306a36Sopenharmony_ci} 25262306a36Sopenharmony_ci 25362306a36Sopenharmony_cistatic bool __kprobes simulate_c_bnez_beqz(u32 opcode, unsigned long addr, struct pt_regs *regs, 25462306a36Sopenharmony_ci bool is_bnez) 25562306a36Sopenharmony_ci{ 25662306a36Sopenharmony_ci /* 25762306a36Sopenharmony_ci * 15 13 12 10 9 7 6 2 1 0 25862306a36Sopenharmony_ci * | funct3 | offset[8|4:3] | rs1' | offset[7:6|2:1|5] | op | 25962306a36Sopenharmony_ci * 3 3 3 5 2 26062306a36Sopenharmony_ci */ 26162306a36Sopenharmony_ci 26262306a36Sopenharmony_ci s32 offset; 26362306a36Sopenharmony_ci u32 rs1; 26462306a36Sopenharmony_ci unsigned long rs1_val; 26562306a36Sopenharmony_ci 26662306a36Sopenharmony_ci rs1 = 0x8 | ((opcode >> 7) & 0x7); 26762306a36Sopenharmony_ci 26862306a36Sopenharmony_ci if (!rv_insn_reg_get_val(regs, rs1, &rs1_val)) 26962306a36Sopenharmony_ci return false; 27062306a36Sopenharmony_ci 27162306a36Sopenharmony_ci if ((rs1_val != 0 && is_bnez) || (rs1_val == 0 && !is_bnez)) { 27262306a36Sopenharmony_ci offset = ((opcode >> 3) & 0x3) << 1; 27362306a36Sopenharmony_ci offset |= ((opcode >> 10) & 0x3) << 3; 27462306a36Sopenharmony_ci offset |= ((opcode >> 2) & 0x1) << 5; 27562306a36Sopenharmony_ci offset |= ((opcode >> 5) & 0x3) << 6; 27662306a36Sopenharmony_ci offset |= ((opcode >> 12) & 0x1) << 8; 27762306a36Sopenharmony_ci offset = sign_extend32(offset, 8); 27862306a36Sopenharmony_ci } else { 27962306a36Sopenharmony_ci offset = 2; 28062306a36Sopenharmony_ci } 28162306a36Sopenharmony_ci 28262306a36Sopenharmony_ci instruction_pointer_set(regs, addr + offset); 28362306a36Sopenharmony_ci 28462306a36Sopenharmony_ci return true; 28562306a36Sopenharmony_ci} 28662306a36Sopenharmony_ci 28762306a36Sopenharmony_cibool __kprobes simulate_c_bnez(u32 opcode, unsigned long addr, struct pt_regs *regs) 28862306a36Sopenharmony_ci{ 28962306a36Sopenharmony_ci return simulate_c_bnez_beqz(opcode, addr, regs, true); 29062306a36Sopenharmony_ci} 29162306a36Sopenharmony_ci 29262306a36Sopenharmony_cibool __kprobes simulate_c_beqz(u32 opcode, unsigned long addr, struct pt_regs *regs) 29362306a36Sopenharmony_ci{ 29462306a36Sopenharmony_ci return simulate_c_bnez_beqz(opcode, addr, regs, false); 29562306a36Sopenharmony_ci} 296