162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0+
262306a36Sopenharmony_ci
362306a36Sopenharmony_ci#include <linux/bitops.h>
462306a36Sopenharmony_ci#include <linux/kernel.h>
562306a36Sopenharmony_ci#include <linux/kprobes.h>
662306a36Sopenharmony_ci
762306a36Sopenharmony_ci#include "decode-insn.h"
862306a36Sopenharmony_ci#include "simulate-insn.h"
962306a36Sopenharmony_ci
1062306a36Sopenharmony_cistatic inline bool rv_insn_reg_get_val(struct pt_regs *regs, u32 index,
1162306a36Sopenharmony_ci				       unsigned long *ptr)
1262306a36Sopenharmony_ci{
1362306a36Sopenharmony_ci	if (index == 0)
1462306a36Sopenharmony_ci		*ptr = 0;
1562306a36Sopenharmony_ci	else if (index <= 31)
1662306a36Sopenharmony_ci		*ptr = *((unsigned long *)regs + index);
1762306a36Sopenharmony_ci	else
1862306a36Sopenharmony_ci		return false;
1962306a36Sopenharmony_ci
2062306a36Sopenharmony_ci	return true;
2162306a36Sopenharmony_ci}
2262306a36Sopenharmony_ci
2362306a36Sopenharmony_cistatic inline bool rv_insn_reg_set_val(struct pt_regs *regs, u32 index,
2462306a36Sopenharmony_ci				       unsigned long val)
2562306a36Sopenharmony_ci{
2662306a36Sopenharmony_ci	if (index == 0)
2762306a36Sopenharmony_ci		return true;
2862306a36Sopenharmony_ci	else if (index <= 31)
2962306a36Sopenharmony_ci		*((unsigned long *)regs + index) = val;
3062306a36Sopenharmony_ci	else
3162306a36Sopenharmony_ci		return false;
3262306a36Sopenharmony_ci
3362306a36Sopenharmony_ci	return true;
3462306a36Sopenharmony_ci}
3562306a36Sopenharmony_ci
3662306a36Sopenharmony_cibool __kprobes simulate_jal(u32 opcode, unsigned long addr, struct pt_regs *regs)
3762306a36Sopenharmony_ci{
3862306a36Sopenharmony_ci	/*
3962306a36Sopenharmony_ci	 *     31    30       21    20     19        12 11 7 6      0
4062306a36Sopenharmony_ci	 * imm [20] | imm[10:1] | imm[11] | imm[19:12] | rd | opcode
4162306a36Sopenharmony_ci	 *     1         10          1           8       5    JAL/J
4262306a36Sopenharmony_ci	 */
4362306a36Sopenharmony_ci	bool ret;
4462306a36Sopenharmony_ci	u32 imm;
4562306a36Sopenharmony_ci	u32 index = (opcode >> 7) & 0x1f;
4662306a36Sopenharmony_ci
4762306a36Sopenharmony_ci	ret = rv_insn_reg_set_val(regs, index, addr + 4);
4862306a36Sopenharmony_ci	if (!ret)
4962306a36Sopenharmony_ci		return ret;
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci	imm  = ((opcode >> 21) & 0x3ff) << 1;
5262306a36Sopenharmony_ci	imm |= ((opcode >> 20) & 0x1)   << 11;
5362306a36Sopenharmony_ci	imm |= ((opcode >> 12) & 0xff)  << 12;
5462306a36Sopenharmony_ci	imm |= ((opcode >> 31) & 0x1)   << 20;
5562306a36Sopenharmony_ci
5662306a36Sopenharmony_ci	instruction_pointer_set(regs, addr + sign_extend32((imm), 20));
5762306a36Sopenharmony_ci
5862306a36Sopenharmony_ci	return ret;
5962306a36Sopenharmony_ci}
6062306a36Sopenharmony_ci
6162306a36Sopenharmony_cibool __kprobes simulate_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs)
6262306a36Sopenharmony_ci{
6362306a36Sopenharmony_ci	/*
6462306a36Sopenharmony_ci	 * 31          20 19 15 14 12 11 7 6      0
6562306a36Sopenharmony_ci	 *  offset[11:0] | rs1 | 010 | rd | opcode
6662306a36Sopenharmony_ci	 *      12         5      3    5    JALR/JR
6762306a36Sopenharmony_ci	 */
6862306a36Sopenharmony_ci	bool ret;
6962306a36Sopenharmony_ci	unsigned long base_addr;
7062306a36Sopenharmony_ci	u32 imm = (opcode >> 20) & 0xfff;
7162306a36Sopenharmony_ci	u32 rd_index = (opcode >> 7) & 0x1f;
7262306a36Sopenharmony_ci	u32 rs1_index = (opcode >> 15) & 0x1f;
7362306a36Sopenharmony_ci
7462306a36Sopenharmony_ci	ret = rv_insn_reg_get_val(regs, rs1_index, &base_addr);
7562306a36Sopenharmony_ci	if (!ret)
7662306a36Sopenharmony_ci		return ret;
7762306a36Sopenharmony_ci
7862306a36Sopenharmony_ci	ret = rv_insn_reg_set_val(regs, rd_index, addr + 4);
7962306a36Sopenharmony_ci	if (!ret)
8062306a36Sopenharmony_ci		return ret;
8162306a36Sopenharmony_ci
8262306a36Sopenharmony_ci	instruction_pointer_set(regs, (base_addr + sign_extend32((imm), 11))&~1);
8362306a36Sopenharmony_ci
8462306a36Sopenharmony_ci	return ret;
8562306a36Sopenharmony_ci}
8662306a36Sopenharmony_ci
8762306a36Sopenharmony_ci#define auipc_rd_idx(opcode) \
8862306a36Sopenharmony_ci	((opcode >> 7) & 0x1f)
8962306a36Sopenharmony_ci
9062306a36Sopenharmony_ci#define auipc_imm(opcode) \
9162306a36Sopenharmony_ci	((((opcode) >> 12) & 0xfffff) << 12)
9262306a36Sopenharmony_ci
9362306a36Sopenharmony_ci#if __riscv_xlen == 64
9462306a36Sopenharmony_ci#define auipc_offset(opcode)	sign_extend64(auipc_imm(opcode), 31)
9562306a36Sopenharmony_ci#elif __riscv_xlen == 32
9662306a36Sopenharmony_ci#define auipc_offset(opcode)	auipc_imm(opcode)
9762306a36Sopenharmony_ci#else
9862306a36Sopenharmony_ci#error "Unexpected __riscv_xlen"
9962306a36Sopenharmony_ci#endif
10062306a36Sopenharmony_ci
10162306a36Sopenharmony_cibool __kprobes simulate_auipc(u32 opcode, unsigned long addr, struct pt_regs *regs)
10262306a36Sopenharmony_ci{
10362306a36Sopenharmony_ci	/*
10462306a36Sopenharmony_ci	 * auipc instruction:
10562306a36Sopenharmony_ci	 *  31        12 11 7 6      0
10662306a36Sopenharmony_ci	 * | imm[31:12] | rd | opcode |
10762306a36Sopenharmony_ci	 *        20       5     7
10862306a36Sopenharmony_ci	 */
10962306a36Sopenharmony_ci
11062306a36Sopenharmony_ci	u32 rd_idx = auipc_rd_idx(opcode);
11162306a36Sopenharmony_ci	unsigned long rd_val = addr + auipc_offset(opcode);
11262306a36Sopenharmony_ci
11362306a36Sopenharmony_ci	if (!rv_insn_reg_set_val(regs, rd_idx, rd_val))
11462306a36Sopenharmony_ci		return false;
11562306a36Sopenharmony_ci
11662306a36Sopenharmony_ci	instruction_pointer_set(regs, addr + 4);
11762306a36Sopenharmony_ci
11862306a36Sopenharmony_ci	return true;
11962306a36Sopenharmony_ci}
12062306a36Sopenharmony_ci
12162306a36Sopenharmony_ci#define branch_rs1_idx(opcode) \
12262306a36Sopenharmony_ci	(((opcode) >> 15) & 0x1f)
12362306a36Sopenharmony_ci
12462306a36Sopenharmony_ci#define branch_rs2_idx(opcode) \
12562306a36Sopenharmony_ci	(((opcode) >> 20) & 0x1f)
12662306a36Sopenharmony_ci
12762306a36Sopenharmony_ci#define branch_funct3(opcode) \
12862306a36Sopenharmony_ci	(((opcode) >> 12) & 0x7)
12962306a36Sopenharmony_ci
13062306a36Sopenharmony_ci#define branch_imm(opcode) \
13162306a36Sopenharmony_ci	(((((opcode) >>  8) & 0xf ) <<  1) | \
13262306a36Sopenharmony_ci	 ((((opcode) >> 25) & 0x3f) <<  5) | \
13362306a36Sopenharmony_ci	 ((((opcode) >>  7) & 0x1 ) << 11) | \
13462306a36Sopenharmony_ci	 ((((opcode) >> 31) & 0x1 ) << 12))
13562306a36Sopenharmony_ci
13662306a36Sopenharmony_ci#define branch_offset(opcode) \
13762306a36Sopenharmony_ci	sign_extend32((branch_imm(opcode)), 12)
13862306a36Sopenharmony_ci
13962306a36Sopenharmony_cibool __kprobes simulate_branch(u32 opcode, unsigned long addr, struct pt_regs *regs)
14062306a36Sopenharmony_ci{
14162306a36Sopenharmony_ci	/*
14262306a36Sopenharmony_ci	 * branch instructions:
14362306a36Sopenharmony_ci	 *      31    30       25 24 20 19 15 14    12 11       8    7      6      0
14462306a36Sopenharmony_ci	 * | imm[12] | imm[10:5] | rs2 | rs1 | funct3 | imm[4:1] | imm[11] | opcode |
14562306a36Sopenharmony_ci	 *     1           6        5     5      3         4         1         7
14662306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    000       imm[4:1|11]       1100011  BEQ
14762306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    001       imm[4:1|11]       1100011  BNE
14862306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    100       imm[4:1|11]       1100011  BLT
14962306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    101       imm[4:1|11]       1100011  BGE
15062306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    110       imm[4:1|11]       1100011  BLTU
15162306a36Sopenharmony_ci	 *     imm[12|10:5]        rs2   rs1    111       imm[4:1|11]       1100011  BGEU
15262306a36Sopenharmony_ci	 */
15362306a36Sopenharmony_ci
15462306a36Sopenharmony_ci	s32 offset;
15562306a36Sopenharmony_ci	s32 offset_tmp;
15662306a36Sopenharmony_ci	unsigned long rs1_val;
15762306a36Sopenharmony_ci	unsigned long rs2_val;
15862306a36Sopenharmony_ci
15962306a36Sopenharmony_ci	if (!rv_insn_reg_get_val(regs, branch_rs1_idx(opcode), &rs1_val) ||
16062306a36Sopenharmony_ci	    !rv_insn_reg_get_val(regs, branch_rs2_idx(opcode), &rs2_val))
16162306a36Sopenharmony_ci		return false;
16262306a36Sopenharmony_ci
16362306a36Sopenharmony_ci	offset_tmp = branch_offset(opcode);
16462306a36Sopenharmony_ci	switch (branch_funct3(opcode)) {
16562306a36Sopenharmony_ci	case RVG_FUNCT3_BEQ:
16662306a36Sopenharmony_ci		offset = (rs1_val == rs2_val) ? offset_tmp : 4;
16762306a36Sopenharmony_ci		break;
16862306a36Sopenharmony_ci	case RVG_FUNCT3_BNE:
16962306a36Sopenharmony_ci		offset = (rs1_val != rs2_val) ? offset_tmp : 4;
17062306a36Sopenharmony_ci		break;
17162306a36Sopenharmony_ci	case RVG_FUNCT3_BLT:
17262306a36Sopenharmony_ci		offset = ((long)rs1_val < (long)rs2_val) ? offset_tmp : 4;
17362306a36Sopenharmony_ci		break;
17462306a36Sopenharmony_ci	case RVG_FUNCT3_BGE:
17562306a36Sopenharmony_ci		offset = ((long)rs1_val >= (long)rs2_val) ? offset_tmp : 4;
17662306a36Sopenharmony_ci		break;
17762306a36Sopenharmony_ci	case RVG_FUNCT3_BLTU:
17862306a36Sopenharmony_ci		offset = (rs1_val < rs2_val) ? offset_tmp : 4;
17962306a36Sopenharmony_ci		break;
18062306a36Sopenharmony_ci	case RVG_FUNCT3_BGEU:
18162306a36Sopenharmony_ci		offset = (rs1_val >= rs2_val) ? offset_tmp : 4;
18262306a36Sopenharmony_ci		break;
18362306a36Sopenharmony_ci	default:
18462306a36Sopenharmony_ci		return false;
18562306a36Sopenharmony_ci	}
18662306a36Sopenharmony_ci
18762306a36Sopenharmony_ci	instruction_pointer_set(regs, addr + offset);
18862306a36Sopenharmony_ci
18962306a36Sopenharmony_ci	return true;
19062306a36Sopenharmony_ci}
19162306a36Sopenharmony_ci
19262306a36Sopenharmony_cibool __kprobes simulate_c_j(u32 opcode, unsigned long addr, struct pt_regs *regs)
19362306a36Sopenharmony_ci{
19462306a36Sopenharmony_ci	/*
19562306a36Sopenharmony_ci	 *  15    13 12                            2 1      0
19662306a36Sopenharmony_ci	 * | funct3 | offset[11|4|9:8|10|6|7|3:1|5] | opcode |
19762306a36Sopenharmony_ci	 *     3                   11                    2
19862306a36Sopenharmony_ci	 */
19962306a36Sopenharmony_ci
20062306a36Sopenharmony_ci	s32 offset;
20162306a36Sopenharmony_ci
20262306a36Sopenharmony_ci	offset  = ((opcode >> 3)  & 0x7) << 1;
20362306a36Sopenharmony_ci	offset |= ((opcode >> 11) & 0x1) << 4;
20462306a36Sopenharmony_ci	offset |= ((opcode >> 2)  & 0x1) << 5;
20562306a36Sopenharmony_ci	offset |= ((opcode >> 7)  & 0x1) << 6;
20662306a36Sopenharmony_ci	offset |= ((opcode >> 6)  & 0x1) << 7;
20762306a36Sopenharmony_ci	offset |= ((opcode >> 9)  & 0x3) << 8;
20862306a36Sopenharmony_ci	offset |= ((opcode >> 8)  & 0x1) << 10;
20962306a36Sopenharmony_ci	offset |= ((opcode >> 12) & 0x1) << 11;
21062306a36Sopenharmony_ci
21162306a36Sopenharmony_ci	instruction_pointer_set(regs, addr + sign_extend32(offset, 11));
21262306a36Sopenharmony_ci
21362306a36Sopenharmony_ci	return true;
21462306a36Sopenharmony_ci}
21562306a36Sopenharmony_ci
21662306a36Sopenharmony_cistatic bool __kprobes simulate_c_jr_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs,
21762306a36Sopenharmony_ci					 bool is_jalr)
21862306a36Sopenharmony_ci{
21962306a36Sopenharmony_ci	/*
22062306a36Sopenharmony_ci	 *  15    12 11  7 6   2 1  0
22162306a36Sopenharmony_ci	 * | funct4 | rs1 | rs2 | op |
22262306a36Sopenharmony_ci	 *     4       5     5    2
22362306a36Sopenharmony_ci	 */
22462306a36Sopenharmony_ci
22562306a36Sopenharmony_ci	unsigned long jump_addr;
22662306a36Sopenharmony_ci
22762306a36Sopenharmony_ci	u32 rs1 = (opcode >> 7) & 0x1f;
22862306a36Sopenharmony_ci
22962306a36Sopenharmony_ci	if (rs1 == 0) /* C.JR is only valid when rs1 != x0 */
23062306a36Sopenharmony_ci		return false;
23162306a36Sopenharmony_ci
23262306a36Sopenharmony_ci	if (!rv_insn_reg_get_val(regs, rs1, &jump_addr))
23362306a36Sopenharmony_ci		return false;
23462306a36Sopenharmony_ci
23562306a36Sopenharmony_ci	if (is_jalr && !rv_insn_reg_set_val(regs, 1, addr + 2))
23662306a36Sopenharmony_ci		return false;
23762306a36Sopenharmony_ci
23862306a36Sopenharmony_ci	instruction_pointer_set(regs, jump_addr);
23962306a36Sopenharmony_ci
24062306a36Sopenharmony_ci	return true;
24162306a36Sopenharmony_ci}
24262306a36Sopenharmony_ci
24362306a36Sopenharmony_cibool __kprobes simulate_c_jr(u32 opcode, unsigned long addr, struct pt_regs *regs)
24462306a36Sopenharmony_ci{
24562306a36Sopenharmony_ci	return simulate_c_jr_jalr(opcode, addr, regs, false);
24662306a36Sopenharmony_ci}
24762306a36Sopenharmony_ci
24862306a36Sopenharmony_cibool __kprobes simulate_c_jalr(u32 opcode, unsigned long addr, struct pt_regs *regs)
24962306a36Sopenharmony_ci{
25062306a36Sopenharmony_ci	return simulate_c_jr_jalr(opcode, addr, regs, true);
25162306a36Sopenharmony_ci}
25262306a36Sopenharmony_ci
25362306a36Sopenharmony_cistatic bool __kprobes simulate_c_bnez_beqz(u32 opcode, unsigned long addr, struct pt_regs *regs,
25462306a36Sopenharmony_ci					   bool is_bnez)
25562306a36Sopenharmony_ci{
25662306a36Sopenharmony_ci	/*
25762306a36Sopenharmony_ci	 *  15    13 12           10 9    7 6                 2 1  0
25862306a36Sopenharmony_ci	 * | funct3 | offset[8|4:3] | rs1' | offset[7:6|2:1|5] | op |
25962306a36Sopenharmony_ci	 *     3            3          3             5           2
26062306a36Sopenharmony_ci	 */
26162306a36Sopenharmony_ci
26262306a36Sopenharmony_ci	s32 offset;
26362306a36Sopenharmony_ci	u32 rs1;
26462306a36Sopenharmony_ci	unsigned long rs1_val;
26562306a36Sopenharmony_ci
26662306a36Sopenharmony_ci	rs1 = 0x8 | ((opcode >> 7) & 0x7);
26762306a36Sopenharmony_ci
26862306a36Sopenharmony_ci	if (!rv_insn_reg_get_val(regs, rs1, &rs1_val))
26962306a36Sopenharmony_ci		return false;
27062306a36Sopenharmony_ci
27162306a36Sopenharmony_ci	if ((rs1_val != 0 && is_bnez) || (rs1_val == 0 && !is_bnez)) {
27262306a36Sopenharmony_ci		offset =  ((opcode >> 3)  & 0x3) << 1;
27362306a36Sopenharmony_ci		offset |= ((opcode >> 10) & 0x3) << 3;
27462306a36Sopenharmony_ci		offset |= ((opcode >> 2)  & 0x1) << 5;
27562306a36Sopenharmony_ci		offset |= ((opcode >> 5)  & 0x3) << 6;
27662306a36Sopenharmony_ci		offset |= ((opcode >> 12) & 0x1) << 8;
27762306a36Sopenharmony_ci		offset = sign_extend32(offset, 8);
27862306a36Sopenharmony_ci	} else {
27962306a36Sopenharmony_ci		offset = 2;
28062306a36Sopenharmony_ci	}
28162306a36Sopenharmony_ci
28262306a36Sopenharmony_ci	instruction_pointer_set(regs, addr + offset);
28362306a36Sopenharmony_ci
28462306a36Sopenharmony_ci	return true;
28562306a36Sopenharmony_ci}
28662306a36Sopenharmony_ci
28762306a36Sopenharmony_cibool __kprobes simulate_c_bnez(u32 opcode, unsigned long addr, struct pt_regs *regs)
28862306a36Sopenharmony_ci{
28962306a36Sopenharmony_ci	return simulate_c_bnez_beqz(opcode, addr, regs, true);
29062306a36Sopenharmony_ci}
29162306a36Sopenharmony_ci
29262306a36Sopenharmony_cibool __kprobes simulate_c_beqz(u32 opcode, unsigned long addr, struct pt_regs *regs)
29362306a36Sopenharmony_ci{
29462306a36Sopenharmony_ci	return simulate_c_bnez_beqz(opcode, addr, regs, false);
29562306a36Sopenharmony_ci}
296