]>
Commit | Line | Data |
---|---|---|
4ba069b8 MG |
1 | /* |
2 | * Kernel Probes (KProbes) | |
3 | * | |
4 | * This program is free software; you can redistribute it and/or modify | |
5 | * it under the terms of the GNU General Public License as published by | |
6 | * the Free Software Foundation; either version 2 of the License, or | |
7 | * (at your option) any later version. | |
8 | * | |
9 | * This program is distributed in the hope that it will be useful, | |
10 | * but WITHOUT ANY WARRANTY; without even the implied warranty of | |
11 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
12 | * GNU General Public License for more details. | |
13 | * | |
14 | * You should have received a copy of the GNU General Public License | |
15 | * along with this program; if not, write to the Free Software | |
16 | * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. | |
17 | * | |
a53c8fab | 18 | * Copyright IBM Corp. 2002, 2006 |
4ba069b8 MG |
19 | * |
20 | * s390 port, used ppc64 as template. Mike Grundy <grundym@us.ibm.com> | |
21 | */ | |
22 | ||
4ba069b8 MG |
23 | #include <linux/kprobes.h> |
24 | #include <linux/ptrace.h> | |
25 | #include <linux/preempt.h> | |
26 | #include <linux/stop_machine.h> | |
1eeb66a1 | 27 | #include <linux/kdebug.h> |
a2b53673 | 28 | #include <linux/uaccess.h> |
4ba069b8 | 29 | #include <linux/module.h> |
5a0e3ad6 | 30 | #include <linux/slab.h> |
adb45839 | 31 | #include <linux/hardirq.h> |
c933146a | 32 | #include <linux/ftrace.h> |
a882b3b0 HC |
33 | #include <asm/cacheflush.h> |
34 | #include <asm/sections.h> | |
35 | #include <asm/dis.h> | |
4ba069b8 | 36 | |
4a188635 | 37 | DEFINE_PER_CPU(struct kprobe *, current_kprobe); |
4ba069b8 MG |
38 | DEFINE_PER_CPU(struct kprobe_ctlblk, kprobe_ctlblk); |
39 | ||
4a188635 | 40 | struct kretprobe_blackpoint kretprobe_blacklist[] = { }; |
f438d914 | 41 | |
63c40436 HC |
42 | DEFINE_INSN_CACHE_OPS(dmainsn); |
43 | ||
44 | static void *alloc_dmainsn_page(void) | |
45 | { | |
46 | return (void *)__get_free_page(GFP_KERNEL | GFP_DMA); | |
47 | } | |
48 | ||
49 | static void free_dmainsn_page(void *page) | |
50 | { | |
51 | free_page((unsigned long)page); | |
52 | } | |
53 | ||
54 | struct kprobe_insn_cache kprobe_dmainsn_slots = { | |
55 | .mutex = __MUTEX_INITIALIZER(kprobe_dmainsn_slots.mutex), | |
56 | .alloc = alloc_dmainsn_page, | |
57 | .free = free_dmainsn_page, | |
58 | .pages = LIST_HEAD_INIT(kprobe_dmainsn_slots.pages), | |
59 | .insn_size = MAX_INSN_SIZE, | |
60 | }; | |
61 | ||
7a5388de | 62 | static void copy_instruction(struct kprobe *p) |
63c40436 | 63 | { |
c933146a | 64 | unsigned long ip = (unsigned long) p->addr; |
63c40436 HC |
65 | s64 disp, new_disp; |
66 | u64 addr, new_addr; | |
67 | ||
c933146a HC |
68 | if (ftrace_location(ip) == ip) { |
69 | /* | |
70 | * If kprobes patches the instruction that is morphed by | |
71 | * ftrace make sure that kprobes always sees the branch | |
e6d60b36 HC |
72 | * "jg .+24" that skips the mcount block or the "brcl 0,0" |
73 | * in case of hotpatch. | |
c933146a HC |
74 | */ |
75 | ftrace_generate_nop_insn((struct ftrace_insn *)p->ainsn.insn); | |
76 | p->ainsn.is_ftrace_insn = 1; | |
77 | } else | |
ed7d56e1 | 78 | memcpy(p->ainsn.insn, p->addr, insn_length(*p->addr >> 8)); |
c933146a | 79 | p->opcode = p->ainsn.insn[0]; |
975fab17 | 80 | if (!probe_is_insn_relative_long(p->ainsn.insn)) |
63c40436 HC |
81 | return; |
82 | /* | |
83 | * For pc-relative instructions in RIL-b or RIL-c format patch the | |
84 | * RI2 displacement field. We have already made sure that the insn | |
85 | * slot for the patched instruction is within the same 2GB area | |
86 | * as the original instruction (either kernel image or module area). | |
87 | * Therefore the new displacement will always fit. | |
88 | */ | |
89 | disp = *(s32 *)&p->ainsn.insn[1]; | |
90 | addr = (u64)(unsigned long)p->addr; | |
91 | new_addr = (u64)(unsigned long)p->ainsn.insn; | |
92 | new_disp = ((addr + (disp * 2)) - new_addr) / 2; | |
93 | *(s32 *)&p->ainsn.insn[1] = new_disp; | |
94 | } | |
7a5388de | 95 | NOKPROBE_SYMBOL(copy_instruction); |
63c40436 HC |
96 | |
97 | static inline int is_kernel_addr(void *addr) | |
98 | { | |
99 | return addr < (void *)_end; | |
100 | } | |
101 | ||
7a5388de | 102 | static int s390_get_insn_slot(struct kprobe *p) |
63c40436 HC |
103 | { |
104 | /* | |
105 | * Get an insn slot that is within the same 2GB area like the original | |
106 | * instruction. That way instructions with a 32bit signed displacement | |
107 | * field can be patched and executed within the insn slot. | |
108 | */ | |
109 | p->ainsn.insn = NULL; | |
110 | if (is_kernel_addr(p->addr)) | |
111 | p->ainsn.insn = get_dmainsn_slot(); | |
fcd05b50 | 112 | else if (is_module_addr(p->addr)) |
63c40436 HC |
113 | p->ainsn.insn = get_insn_slot(); |
114 | return p->ainsn.insn ? 0 : -ENOMEM; | |
115 | } | |
7a5388de | 116 | NOKPROBE_SYMBOL(s390_get_insn_slot); |
63c40436 | 117 | |
7a5388de | 118 | static void s390_free_insn_slot(struct kprobe *p) |
63c40436 HC |
119 | { |
120 | if (!p->ainsn.insn) | |
121 | return; | |
122 | if (is_kernel_addr(p->addr)) | |
123 | free_dmainsn_slot(p->ainsn.insn, 0); | |
124 | else | |
125 | free_insn_slot(p->ainsn.insn, 0); | |
126 | p->ainsn.insn = NULL; | |
127 | } | |
7a5388de | 128 | NOKPROBE_SYMBOL(s390_free_insn_slot); |
63c40436 | 129 | |
7a5388de | 130 | int arch_prepare_kprobe(struct kprobe *p) |
ba640a59 MS |
131 | { |
132 | if ((unsigned long) p->addr & 0x01) | |
133 | return -EINVAL; | |
ba640a59 | 134 | /* Make sure the probe isn't going on a difficult instruction */ |
975fab17 | 135 | if (probe_is_prohibited_opcode(p->addr)) |
ba640a59 | 136 | return -EINVAL; |
63c40436 HC |
137 | if (s390_get_insn_slot(p)) |
138 | return -ENOMEM; | |
63c40436 | 139 | copy_instruction(p); |
ba640a59 | 140 | return 0; |
4ba069b8 | 141 | } |
7a5388de | 142 | NOKPROBE_SYMBOL(arch_prepare_kprobe); |
4ba069b8 | 143 | |
c933146a HC |
144 | int arch_check_ftrace_location(struct kprobe *p) |
145 | { | |
146 | return 0; | |
147 | } | |
148 | ||
149 | struct swap_insn_args { | |
150 | struct kprobe *p; | |
151 | unsigned int arm_kprobe : 1; | |
5a8b589f MS |
152 | }; |
153 | ||
7a5388de | 154 | static int swap_instruction(void *data) |
4ba069b8 | 155 | { |
acf01800 HC |
156 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); |
157 | unsigned long status = kcb->kprobe_status; | |
c933146a HC |
158 | struct swap_insn_args *args = data; |
159 | struct ftrace_insn new_insn, *insn; | |
160 | struct kprobe *p = args->p; | |
161 | size_t len; | |
162 | ||
163 | new_insn.opc = args->arm_kprobe ? BREAKPOINT_INSTRUCTION : p->opcode; | |
164 | len = sizeof(new_insn.opc); | |
165 | if (!p->ainsn.is_ftrace_insn) | |
166 | goto skip_ftrace; | |
167 | len = sizeof(new_insn); | |
168 | insn = (struct ftrace_insn *) p->addr; | |
169 | if (args->arm_kprobe) { | |
170 | if (is_ftrace_nop(insn)) | |
171 | new_insn.disp = KPROBE_ON_FTRACE_NOP; | |
172 | else | |
173 | new_insn.disp = KPROBE_ON_FTRACE_CALL; | |
174 | } else { | |
175 | ftrace_generate_call_insn(&new_insn, (unsigned long)p->addr); | |
176 | if (insn->disp == KPROBE_ON_FTRACE_NOP) | |
177 | ftrace_generate_nop_insn(&new_insn); | |
178 | } | |
179 | skip_ftrace: | |
acf01800 | 180 | kcb->kprobe_status = KPROBE_SWAP_INST; |
8a5d8473 | 181 | s390_kernel_write(p->addr, &new_insn, len); |
acf01800 | 182 | kcb->kprobe_status = status; |
5a8b589f | 183 | return 0; |
4ba069b8 | 184 | } |
7a5388de | 185 | NOKPROBE_SYMBOL(swap_instruction); |
4ba069b8 | 186 | |
7a5388de | 187 | void arch_arm_kprobe(struct kprobe *p) |
4ba069b8 | 188 | { |
c933146a | 189 | struct swap_insn_args args = {.p = p, .arm_kprobe = 1}; |
4ba069b8 | 190 | |
9b1a4d38 | 191 | stop_machine(swap_instruction, &args, NULL); |
4ba069b8 | 192 | } |
7a5388de | 193 | NOKPROBE_SYMBOL(arch_arm_kprobe); |
4ba069b8 | 194 | |
7a5388de | 195 | void arch_disarm_kprobe(struct kprobe *p) |
4ba069b8 | 196 | { |
c933146a | 197 | struct swap_insn_args args = {.p = p, .arm_kprobe = 0}; |
4ba069b8 | 198 | |
9b1a4d38 | 199 | stop_machine(swap_instruction, &args, NULL); |
4ba069b8 | 200 | } |
7a5388de | 201 | NOKPROBE_SYMBOL(arch_disarm_kprobe); |
4ba069b8 | 202 | |
7a5388de | 203 | void arch_remove_kprobe(struct kprobe *p) |
4ba069b8 | 204 | { |
63c40436 | 205 | s390_free_insn_slot(p); |
4ba069b8 | 206 | } |
7a5388de | 207 | NOKPROBE_SYMBOL(arch_remove_kprobe); |
4ba069b8 | 208 | |
7a5388de HC |
209 | static void enable_singlestep(struct kprobe_ctlblk *kcb, |
210 | struct pt_regs *regs, | |
211 | unsigned long ip) | |
4ba069b8 | 212 | { |
5e9a2692 | 213 | struct per_regs per_kprobe; |
4ba069b8 | 214 | |
5e9a2692 MS |
215 | /* Set up the PER control registers %cr9-%cr11 */ |
216 | per_kprobe.control = PER_EVENT_IFETCH; | |
217 | per_kprobe.start = ip; | |
218 | per_kprobe.end = ip; | |
4ba069b8 | 219 | |
fc0a1fea MS |
220 | /* Save control regs and psw mask */ |
221 | __ctl_store(kcb->kprobe_saved_ctl, 9, 11); | |
222 | kcb->kprobe_saved_imask = regs->psw.mask & | |
223 | (PSW_MASK_PER | PSW_MASK_IO | PSW_MASK_EXT); | |
224 | ||
225 | /* Set PER control regs, turns on single step for the given address */ | |
5e9a2692 | 226 | __ctl_load(per_kprobe, 9, 11); |
4ba069b8 | 227 | regs->psw.mask |= PSW_MASK_PER; |
adb45839 | 228 | regs->psw.mask &= ~(PSW_MASK_IO | PSW_MASK_EXT); |
fc0a1fea | 229 | regs->psw.addr = ip | PSW_ADDR_AMODE; |
4ba069b8 | 230 | } |
7a5388de | 231 | NOKPROBE_SYMBOL(enable_singlestep); |
4ba069b8 | 232 | |
7a5388de HC |
233 | static void disable_singlestep(struct kprobe_ctlblk *kcb, |
234 | struct pt_regs *regs, | |
235 | unsigned long ip) | |
fc0a1fea MS |
236 | { |
237 | /* Restore control regs and psw mask, set new psw address */ | |
238 | __ctl_load(kcb->kprobe_saved_ctl, 9, 11); | |
239 | regs->psw.mask &= ~PSW_MASK_PER; | |
240 | regs->psw.mask |= kcb->kprobe_saved_imask; | |
241 | regs->psw.addr = ip | PSW_ADDR_AMODE; | |
242 | } | |
7a5388de | 243 | NOKPROBE_SYMBOL(disable_singlestep); |
fc0a1fea | 244 | |
b9599798 MS |
245 | /* |
246 | * Activate a kprobe by storing its pointer to current_kprobe. The | |
247 | * previous kprobe is stored in kcb->prev_kprobe. A stack of up to | |
248 | * two kprobes can be active, see KPROBE_REENTER. | |
249 | */ | |
7a5388de | 250 | static void push_kprobe(struct kprobe_ctlblk *kcb, struct kprobe *p) |
4ba069b8 | 251 | { |
eb7e7d76 | 252 | kcb->prev_kprobe.kp = __this_cpu_read(current_kprobe); |
4ba069b8 | 253 | kcb->prev_kprobe.status = kcb->kprobe_status; |
eb7e7d76 | 254 | __this_cpu_write(current_kprobe, p); |
4ba069b8 | 255 | } |
7a5388de | 256 | NOKPROBE_SYMBOL(push_kprobe); |
4ba069b8 | 257 | |
b9599798 MS |
258 | /* |
259 | * Deactivate a kprobe by backing up to the previous state. If the | |
260 | * current state is KPROBE_REENTER prev_kprobe.kp will be non-NULL, | |
261 | * for any other state prev_kprobe.kp will be NULL. | |
262 | */ | |
7a5388de | 263 | static void pop_kprobe(struct kprobe_ctlblk *kcb) |
4ba069b8 | 264 | { |
eb7e7d76 | 265 | __this_cpu_write(current_kprobe, kcb->prev_kprobe.kp); |
4ba069b8 | 266 | kcb->kprobe_status = kcb->prev_kprobe.status; |
4ba069b8 | 267 | } |
7a5388de | 268 | NOKPROBE_SYMBOL(pop_kprobe); |
4ba069b8 | 269 | |
7a5388de | 270 | void arch_prepare_kretprobe(struct kretprobe_instance *ri, struct pt_regs *regs) |
4ba069b8 | 271 | { |
4c4308cb | 272 | ri->ret_addr = (kprobe_opcode_t *) regs->gprs[14]; |
4ba069b8 | 273 | |
4c4308cb | 274 | /* Replace the return addr with trampoline addr */ |
4a188635 | 275 | regs->gprs[14] = (unsigned long) &kretprobe_trampoline; |
4ba069b8 | 276 | } |
7a5388de | 277 | NOKPROBE_SYMBOL(arch_prepare_kretprobe); |
4ba069b8 | 278 | |
7a5388de | 279 | static void kprobe_reenter_check(struct kprobe_ctlblk *kcb, struct kprobe *p) |
0e917cc3 MS |
280 | { |
281 | switch (kcb->kprobe_status) { | |
282 | case KPROBE_HIT_SSDONE: | |
283 | case KPROBE_HIT_ACTIVE: | |
284 | kprobes_inc_nmissed_count(p); | |
285 | break; | |
286 | case KPROBE_HIT_SS: | |
287 | case KPROBE_REENTER: | |
288 | default: | |
289 | /* | |
290 | * A kprobe on the code path to single step an instruction | |
291 | * is a BUG. The code path resides in the .kprobes.text | |
292 | * section and is executed with interrupts disabled. | |
293 | */ | |
294 | printk(KERN_EMERG "Invalid kprobe detected at %p.\n", p->addr); | |
295 | dump_kprobe(p); | |
296 | BUG(); | |
297 | } | |
298 | } | |
7a5388de | 299 | NOKPROBE_SYMBOL(kprobe_reenter_check); |
0e917cc3 | 300 | |
7a5388de | 301 | static int kprobe_handler(struct pt_regs *regs) |
4ba069b8 | 302 | { |
4ba069b8 | 303 | struct kprobe_ctlblk *kcb; |
0e917cc3 | 304 | struct kprobe *p; |
4ba069b8 MG |
305 | |
306 | /* | |
0e917cc3 MS |
307 | * We want to disable preemption for the entire duration of kprobe |
308 | * processing. That includes the calls to the pre/post handlers | |
309 | * and single stepping the kprobe instruction. | |
4ba069b8 MG |
310 | */ |
311 | preempt_disable(); | |
312 | kcb = get_kprobe_ctlblk(); | |
0e917cc3 | 313 | p = get_kprobe((void *)((regs->psw.addr & PSW_ADDR_INSN) - 2)); |
4ba069b8 | 314 | |
0e917cc3 MS |
315 | if (p) { |
316 | if (kprobe_running()) { | |
b9599798 MS |
317 | /* |
318 | * We have hit a kprobe while another is still | |
319 | * active. This can happen in the pre and post | |
320 | * handler. Single step the instruction of the | |
321 | * new probe but do not call any handler function | |
322 | * of this secondary kprobe. | |
323 | * push_kprobe and pop_kprobe saves and restores | |
324 | * the currently active kprobe. | |
4ba069b8 | 325 | */ |
0e917cc3 | 326 | kprobe_reenter_check(kcb, p); |
b9599798 | 327 | push_kprobe(kcb, p); |
4ba069b8 | 328 | kcb->kprobe_status = KPROBE_REENTER; |
4ba069b8 | 329 | } else { |
0e917cc3 MS |
330 | /* |
331 | * If we have no pre-handler or it returned 0, we | |
332 | * continue with single stepping. If we have a | |
333 | * pre-handler and it returned non-zero, it prepped | |
334 | * for calling the break_handler below on re-entry | |
335 | * for jprobe processing, so get out doing nothing | |
336 | * more here. | |
337 | */ | |
338 | push_kprobe(kcb, p); | |
339 | kcb->kprobe_status = KPROBE_HIT_ACTIVE; | |
340 | if (p->pre_handler && p->pre_handler(p, regs)) | |
341 | return 1; | |
342 | kcb->kprobe_status = KPROBE_HIT_SS; | |
4ba069b8 | 343 | } |
0e917cc3 | 344 | enable_singlestep(kcb, regs, (unsigned long) p->ainsn.insn); |
4ba069b8 | 345 | return 1; |
0e917cc3 | 346 | } else if (kprobe_running()) { |
eb7e7d76 | 347 | p = __this_cpu_read(current_kprobe); |
0e917cc3 MS |
348 | if (p->break_handler && p->break_handler(p, regs)) { |
349 | /* | |
350 | * Continuation after the jprobe completed and | |
351 | * caused the jprobe_return trap. The jprobe | |
352 | * break_handler "returns" to the original | |
353 | * function that still has the kprobe breakpoint | |
354 | * installed. We continue with single stepping. | |
355 | */ | |
356 | kcb->kprobe_status = KPROBE_HIT_SS; | |
357 | enable_singlestep(kcb, regs, | |
358 | (unsigned long) p->ainsn.insn); | |
359 | return 1; | |
360 | } /* else: | |
361 | * No kprobe at this address and the current kprobe | |
362 | * has no break handler (no jprobe!). The kernel just | |
363 | * exploded, let the standard trap handler pick up the | |
364 | * pieces. | |
365 | */ | |
366 | } /* else: | |
367 | * No kprobe at this address and no active kprobe. The trap has | |
368 | * not been caused by a kprobe breakpoint. The race of breakpoint | |
369 | * vs. kprobe remove does not exist because on s390 as we use | |
370 | * stop_machine to arm/disarm the breakpoints. | |
371 | */ | |
4ba069b8 | 372 | preempt_enable_no_resched(); |
0e917cc3 | 373 | return 0; |
4ba069b8 | 374 | } |
7a5388de | 375 | NOKPROBE_SYMBOL(kprobe_handler); |
4ba069b8 MG |
376 | |
377 | /* | |
378 | * Function return probe trampoline: | |
379 | * - init_kprobes() establishes a probepoint here | |
380 | * - When the probed function returns, this probe | |
381 | * causes the handlers to fire | |
382 | */ | |
a806170e | 383 | static void __used kretprobe_trampoline_holder(void) |
4ba069b8 MG |
384 | { |
385 | asm volatile(".global kretprobe_trampoline\n" | |
386 | "kretprobe_trampoline: bcr 0,0\n"); | |
387 | } | |
388 | ||
389 | /* | |
390 | * Called when the probe at kretprobe trampoline is hit | |
391 | */ | |
7a5388de | 392 | static int trampoline_probe_handler(struct kprobe *p, struct pt_regs *regs) |
4ba069b8 | 393 | { |
4a188635 | 394 | struct kretprobe_instance *ri; |
99219a3f | 395 | struct hlist_head *head, empty_rp; |
b67bfe0d | 396 | struct hlist_node *tmp; |
4a188635 MS |
397 | unsigned long flags, orig_ret_address; |
398 | unsigned long trampoline_address; | |
399 | kprobe_opcode_t *correct_ret_addr; | |
4ba069b8 | 400 | |
99219a3f | 401 | INIT_HLIST_HEAD(&empty_rp); |
ef53d9c5 | 402 | kretprobe_hash_lock(current, &head, &flags); |
4ba069b8 MG |
403 | |
404 | /* | |
405 | * It is possible to have multiple instances associated with a given | |
406 | * task either because an multiple functions in the call path | |
025dfdaf | 407 | * have a return probe installed on them, and/or more than one return |
4ba069b8 MG |
408 | * return probe was registered for a target function. |
409 | * | |
410 | * We can handle this because: | |
411 | * - instances are always inserted at the head of the list | |
412 | * - when multiple return probes are registered for the same | |
413 | * function, the first instance's ret_addr will point to the | |
414 | * real return address, and all the rest will point to | |
415 | * kretprobe_trampoline | |
416 | */ | |
4a188635 MS |
417 | ri = NULL; |
418 | orig_ret_address = 0; | |
419 | correct_ret_addr = NULL; | |
420 | trampoline_address = (unsigned long) &kretprobe_trampoline; | |
b67bfe0d | 421 | hlist_for_each_entry_safe(ri, tmp, head, hlist) { |
4ba069b8 MG |
422 | if (ri->task != current) |
423 | /* another task is sharing our hash bucket */ | |
424 | continue; | |
425 | ||
4a188635 | 426 | orig_ret_address = (unsigned long) ri->ret_addr; |
89480801 MS |
427 | |
428 | if (orig_ret_address != trampoline_address) | |
429 | /* | |
430 | * This is the real return address. Any other | |
431 | * instances associated with this task are for | |
432 | * other calls deeper on the call stack | |
433 | */ | |
434 | break; | |
435 | } | |
436 | ||
437 | kretprobe_assert(ri, orig_ret_address, trampoline_address); | |
438 | ||
439 | correct_ret_addr = ri->ret_addr; | |
b67bfe0d | 440 | hlist_for_each_entry_safe(ri, tmp, head, hlist) { |
89480801 MS |
441 | if (ri->task != current) |
442 | /* another task is sharing our hash bucket */ | |
443 | continue; | |
4ba069b8 | 444 | |
4a188635 | 445 | orig_ret_address = (unsigned long) ri->ret_addr; |
89480801 MS |
446 | |
447 | if (ri->rp && ri->rp->handler) { | |
448 | ri->ret_addr = correct_ret_addr; | |
449 | ri->rp->handler(ri, regs); | |
450 | } | |
451 | ||
99219a3f | 452 | recycle_rp_inst(ri, &empty_rp); |
4ba069b8 | 453 | |
4a188635 | 454 | if (orig_ret_address != trampoline_address) |
4ba069b8 MG |
455 | /* |
456 | * This is the real return address. Any other | |
457 | * instances associated with this task are for | |
458 | * other calls deeper on the call stack | |
459 | */ | |
460 | break; | |
4ba069b8 | 461 | } |
89480801 | 462 | |
4ba069b8 MG |
463 | regs->psw.addr = orig_ret_address | PSW_ADDR_AMODE; |
464 | ||
b9599798 | 465 | pop_kprobe(get_kprobe_ctlblk()); |
ef53d9c5 | 466 | kretprobe_hash_unlock(current, &flags); |
4ba069b8 MG |
467 | preempt_enable_no_resched(); |
468 | ||
b67bfe0d | 469 | hlist_for_each_entry_safe(ri, tmp, &empty_rp, hlist) { |
99219a3f | 470 | hlist_del(&ri->hlist); |
471 | kfree(ri); | |
472 | } | |
4ba069b8 MG |
473 | /* |
474 | * By returning a non-zero value, we are telling | |
475 | * kprobe_handler() that we don't want the post_handler | |
476 | * to run (and have re-enabled preemption) | |
477 | */ | |
478 | return 1; | |
479 | } | |
7a5388de | 480 | NOKPROBE_SYMBOL(trampoline_probe_handler); |
4ba069b8 MG |
481 | |
482 | /* | |
483 | * Called after single-stepping. p->addr is the address of the | |
484 | * instruction whose first byte has been replaced by the "breakpoint" | |
485 | * instruction. To avoid the SMP problems that can occur when we | |
486 | * temporarily put back the original opcode to single-step, we | |
487 | * single-stepped a copy of the instruction. The address of this | |
488 | * copy is p->ainsn.insn. | |
489 | */ | |
7a5388de | 490 | static void resume_execution(struct kprobe *p, struct pt_regs *regs) |
4ba069b8 MG |
491 | { |
492 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); | |
fc0a1fea | 493 | unsigned long ip = regs->psw.addr & PSW_ADDR_INSN; |
975fab17 | 494 | int fixup = probe_get_fixup_type(p->ainsn.insn); |
4ba069b8 | 495 | |
c933146a HC |
496 | /* Check if the kprobes location is an enabled ftrace caller */ |
497 | if (p->ainsn.is_ftrace_insn) { | |
498 | struct ftrace_insn *insn = (struct ftrace_insn *) p->addr; | |
499 | struct ftrace_insn call_insn; | |
500 | ||
501 | ftrace_generate_call_insn(&call_insn, (unsigned long) p->addr); | |
502 | /* | |
503 | * A kprobe on an enabled ftrace call site actually single | |
504 | * stepped an unconditional branch (ftrace nop equivalent). | |
505 | * Now we need to fixup things and pretend that a brasl r0,... | |
506 | * was executed instead. | |
507 | */ | |
508 | if (insn->disp == KPROBE_ON_FTRACE_CALL) { | |
509 | ip += call_insn.disp * 2 - MCOUNT_INSN_SIZE; | |
510 | regs->gprs[0] = (unsigned long)p->addr + sizeof(*insn); | |
511 | } | |
512 | } | |
513 | ||
ba640a59 | 514 | if (fixup & FIXUP_PSW_NORMAL) |
fc0a1fea | 515 | ip += (unsigned long) p->addr - (unsigned long) p->ainsn.insn; |
4ba069b8 | 516 | |
ba640a59 | 517 | if (fixup & FIXUP_BRANCH_NOT_TAKEN) { |
a882b3b0 | 518 | int ilen = insn_length(p->ainsn.insn[0] >> 8); |
ba640a59 MS |
519 | if (ip - (unsigned long) p->ainsn.insn == ilen) |
520 | ip = (unsigned long) p->addr + ilen; | |
521 | } | |
4ba069b8 | 522 | |
ba640a59 MS |
523 | if (fixup & FIXUP_RETURN_REGISTER) { |
524 | int reg = (p->ainsn.insn[0] & 0xf0) >> 4; | |
525 | regs->gprs[reg] += (unsigned long) p->addr - | |
526 | (unsigned long) p->ainsn.insn; | |
527 | } | |
4ba069b8 | 528 | |
fc0a1fea | 529 | disable_singlestep(kcb, regs, ip); |
4ba069b8 | 530 | } |
7a5388de | 531 | NOKPROBE_SYMBOL(resume_execution); |
4ba069b8 | 532 | |
7a5388de | 533 | static int post_kprobe_handler(struct pt_regs *regs) |
4ba069b8 | 534 | { |
4ba069b8 | 535 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); |
4a188635 | 536 | struct kprobe *p = kprobe_running(); |
4ba069b8 | 537 | |
4a188635 | 538 | if (!p) |
4ba069b8 MG |
539 | return 0; |
540 | ||
4a188635 | 541 | if (kcb->kprobe_status != KPROBE_REENTER && p->post_handler) { |
4ba069b8 | 542 | kcb->kprobe_status = KPROBE_HIT_SSDONE; |
4a188635 | 543 | p->post_handler(p, regs, 0); |
4ba069b8 MG |
544 | } |
545 | ||
4a188635 | 546 | resume_execution(p, regs); |
b9599798 | 547 | pop_kprobe(kcb); |
4ba069b8 MG |
548 | preempt_enable_no_resched(); |
549 | ||
550 | /* | |
551 | * if somebody else is singlestepping across a probe point, psw mask | |
552 | * will have PER set, in which case, continue the remaining processing | |
553 | * of do_single_step, as if this is not a probe hit. | |
554 | */ | |
4a188635 | 555 | if (regs->psw.mask & PSW_MASK_PER) |
4ba069b8 | 556 | return 0; |
4ba069b8 MG |
557 | |
558 | return 1; | |
559 | } | |
7a5388de | 560 | NOKPROBE_SYMBOL(post_kprobe_handler); |
4ba069b8 | 561 | |
7a5388de | 562 | static int kprobe_trap_handler(struct pt_regs *regs, int trapnr) |
4ba069b8 | 563 | { |
4ba069b8 | 564 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); |
4a188635 | 565 | struct kprobe *p = kprobe_running(); |
4ba069b8 MG |
566 | const struct exception_table_entry *entry; |
567 | ||
568 | switch(kcb->kprobe_status) { | |
569 | case KPROBE_SWAP_INST: | |
570 | /* We are here because the instruction replacement failed */ | |
571 | return 0; | |
572 | case KPROBE_HIT_SS: | |
573 | case KPROBE_REENTER: | |
574 | /* | |
575 | * We are here because the instruction being single | |
576 | * stepped caused a page fault. We reset the current | |
577 | * kprobe and the nip points back to the probe address | |
578 | * and allow the page fault handler to continue as a | |
579 | * normal page fault. | |
580 | */ | |
4a188635 | 581 | disable_singlestep(kcb, regs, (unsigned long) p->addr); |
b9599798 | 582 | pop_kprobe(kcb); |
4ba069b8 MG |
583 | preempt_enable_no_resched(); |
584 | break; | |
585 | case KPROBE_HIT_ACTIVE: | |
586 | case KPROBE_HIT_SSDONE: | |
587 | /* | |
588 | * We increment the nmissed count for accounting, | |
23d6d3db | 589 | * we can also use npre/npostfault count for accounting |
4ba069b8 MG |
590 | * these specific fault cases. |
591 | */ | |
4a188635 | 592 | kprobes_inc_nmissed_count(p); |
4ba069b8 MG |
593 | |
594 | /* | |
595 | * We come here because instructions in the pre/post | |
596 | * handler caused the page_fault, this could happen | |
597 | * if handler tries to access user space by | |
598 | * copy_from_user(), get_user() etc. Let the | |
599 | * user-specified handler try to fix it first. | |
600 | */ | |
4a188635 | 601 | if (p->fault_handler && p->fault_handler(p, regs, trapnr)) |
4ba069b8 MG |
602 | return 1; |
603 | ||
604 | /* | |
605 | * In case the user-specified fault handler returned | |
606 | * zero, try to fix up. | |
607 | */ | |
608 | entry = search_exception_tables(regs->psw.addr & PSW_ADDR_INSN); | |
609 | if (entry) { | |
eb608fb3 | 610 | regs->psw.addr = extable_fixup(entry) | PSW_ADDR_AMODE; |
4ba069b8 MG |
611 | return 1; |
612 | } | |
613 | ||
614 | /* | |
615 | * fixup_exception() could not handle it, | |
616 | * Let do_page_fault() fix it. | |
617 | */ | |
618 | break; | |
619 | default: | |
620 | break; | |
621 | } | |
622 | return 0; | |
623 | } | |
7a5388de | 624 | NOKPROBE_SYMBOL(kprobe_trap_handler); |
4ba069b8 | 625 | |
7a5388de | 626 | int kprobe_fault_handler(struct pt_regs *regs, int trapnr) |
adb45839 MS |
627 | { |
628 | int ret; | |
629 | ||
630 | if (regs->psw.mask & (PSW_MASK_IO | PSW_MASK_EXT)) | |
631 | local_irq_disable(); | |
632 | ret = kprobe_trap_handler(regs, trapnr); | |
633 | if (regs->psw.mask & (PSW_MASK_IO | PSW_MASK_EXT)) | |
634 | local_irq_restore(regs->psw.mask & ~PSW_MASK_PER); | |
635 | return ret; | |
636 | } | |
7a5388de | 637 | NOKPROBE_SYMBOL(kprobe_fault_handler); |
adb45839 | 638 | |
4ba069b8 MG |
639 | /* |
640 | * Wrapper routine to for handling exceptions. | |
641 | */ | |
7a5388de HC |
642 | int kprobe_exceptions_notify(struct notifier_block *self, |
643 | unsigned long val, void *data) | |
4ba069b8 | 644 | { |
4a188635 | 645 | struct die_args *args = (struct die_args *) data; |
adb45839 | 646 | struct pt_regs *regs = args->regs; |
4ba069b8 MG |
647 | int ret = NOTIFY_DONE; |
648 | ||
adb45839 MS |
649 | if (regs->psw.mask & (PSW_MASK_IO | PSW_MASK_EXT)) |
650 | local_irq_disable(); | |
651 | ||
4ba069b8 MG |
652 | switch (val) { |
653 | case DIE_BPT: | |
4a188635 | 654 | if (kprobe_handler(regs)) |
4ba069b8 MG |
655 | ret = NOTIFY_STOP; |
656 | break; | |
657 | case DIE_SSTEP: | |
4a188635 | 658 | if (post_kprobe_handler(regs)) |
4ba069b8 MG |
659 | ret = NOTIFY_STOP; |
660 | break; | |
661 | case DIE_TRAP: | |
adb45839 | 662 | if (!preemptible() && kprobe_running() && |
4a188635 | 663 | kprobe_trap_handler(regs, args->trapnr)) |
4ba069b8 | 664 | ret = NOTIFY_STOP; |
4ba069b8 MG |
665 | break; |
666 | default: | |
667 | break; | |
668 | } | |
adb45839 MS |
669 | |
670 | if (regs->psw.mask & (PSW_MASK_IO | PSW_MASK_EXT)) | |
671 | local_irq_restore(regs->psw.mask & ~PSW_MASK_PER); | |
672 | ||
4ba069b8 MG |
673 | return ret; |
674 | } | |
7a5388de | 675 | NOKPROBE_SYMBOL(kprobe_exceptions_notify); |
4ba069b8 | 676 | |
7a5388de | 677 | int setjmp_pre_handler(struct kprobe *p, struct pt_regs *regs) |
4ba069b8 MG |
678 | { |
679 | struct jprobe *jp = container_of(p, struct jprobe, kp); | |
4ba069b8 | 680 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); |
92b8cbf1 | 681 | unsigned long stack; |
4ba069b8 MG |
682 | |
683 | memcpy(&kcb->jprobe_saved_regs, regs, sizeof(struct pt_regs)); | |
684 | ||
685 | /* setup return addr to the jprobe handler routine */ | |
4a188635 | 686 | regs->psw.addr = (unsigned long) jp->entry | PSW_ADDR_AMODE; |
adb45839 | 687 | regs->psw.mask &= ~(PSW_MASK_IO | PSW_MASK_EXT); |
4ba069b8 | 688 | |
4ba069b8 | 689 | /* r15 is the stack pointer */ |
92b8cbf1 | 690 | stack = (unsigned long) regs->gprs[15]; |
4ba069b8 | 691 | |
92b8cbf1 | 692 | memcpy(kcb->jprobes_stack, (void *) stack, MIN_STACK_SIZE(stack)); |
4ba069b8 MG |
693 | return 1; |
694 | } | |
7a5388de | 695 | NOKPROBE_SYMBOL(setjmp_pre_handler); |
4ba069b8 | 696 | |
7a5388de | 697 | void jprobe_return(void) |
4ba069b8 MG |
698 | { |
699 | asm volatile(".word 0x0002"); | |
700 | } | |
7a5388de | 701 | NOKPROBE_SYMBOL(jprobe_return); |
4ba069b8 | 702 | |
7a5388de | 703 | int longjmp_break_handler(struct kprobe *p, struct pt_regs *regs) |
4ba069b8 MG |
704 | { |
705 | struct kprobe_ctlblk *kcb = get_kprobe_ctlblk(); | |
92b8cbf1 MS |
706 | unsigned long stack; |
707 | ||
708 | stack = (unsigned long) kcb->jprobe_saved_regs.gprs[15]; | |
4ba069b8 MG |
709 | |
710 | /* Put the regs back */ | |
711 | memcpy(regs, &kcb->jprobe_saved_regs, sizeof(struct pt_regs)); | |
712 | /* put the stack back */ | |
92b8cbf1 | 713 | memcpy((void *) stack, kcb->jprobes_stack, MIN_STACK_SIZE(stack)); |
4ba069b8 MG |
714 | preempt_enable_no_resched(); |
715 | return 1; | |
716 | } | |
7a5388de | 717 | NOKPROBE_SYMBOL(longjmp_break_handler); |
4ba069b8 | 718 | |
4a188635 MS |
719 | static struct kprobe trampoline = { |
720 | .addr = (kprobe_opcode_t *) &kretprobe_trampoline, | |
4ba069b8 MG |
721 | .pre_handler = trampoline_probe_handler |
722 | }; | |
723 | ||
724 | int __init arch_init_kprobes(void) | |
725 | { | |
4a188635 | 726 | return register_kprobe(&trampoline); |
4ba069b8 | 727 | } |
bf8f6e5b | 728 | |
7a5388de | 729 | int arch_trampoline_kprobe(struct kprobe *p) |
bf8f6e5b | 730 | { |
4a188635 | 731 | return p->addr == (kprobe_opcode_t *) &kretprobe_trampoline; |
bf8f6e5b | 732 | } |
7a5388de | 733 | NOKPROBE_SYMBOL(arch_trampoline_kprobe); |