]> git.proxmox.com Git - mirror_ubuntu-jammy-kernel.git/blame - mm/kasan/kasan.h
kasan: detect invalid frees for large objects
[mirror_ubuntu-jammy-kernel.git] / mm / kasan / kasan.h
CommitLineData
b2441318 1/* SPDX-License-Identifier: GPL-2.0 */
0b24becc
AR
2#ifndef __MM_KASAN_KASAN_H
3#define __MM_KASAN_KASAN_H
4
5#include <linux/kasan.h>
cd11016e 6#include <linux/stackdepot.h>
0b24becc
AR
7
8#define KASAN_SHADOW_SCALE_SIZE (1UL << KASAN_SHADOW_SCALE_SHIFT)
9#define KASAN_SHADOW_MASK (KASAN_SHADOW_SCALE_SIZE - 1)
10
0316bec2
AR
11#define KASAN_FREE_PAGE 0xFF /* page was freed */
12#define KASAN_PAGE_REDZONE 0xFE /* redzone for kmalloc_large allocations */
13#define KASAN_KMALLOC_REDZONE 0xFC /* redzone inside slub object */
14#define KASAN_KMALLOC_FREE 0xFB /* object was freed (kmem_cache_free/kfree) */
bebf56a1 15#define KASAN_GLOBAL_REDZONE 0xFA /* redzone for global variable */
0316bec2 16
c420f167
AR
17/*
18 * Stack redzone shadow values
19 * (Those are compiler's ABI, don't change them)
20 */
21#define KASAN_STACK_LEFT 0xF1
22#define KASAN_STACK_MID 0xF2
23#define KASAN_STACK_RIGHT 0xF3
24#define KASAN_STACK_PARTIAL 0xF4
828347f8 25#define KASAN_USE_AFTER_SCOPE 0xF8
c420f167 26
342061ee
PL
27/*
28 * alloca redzone shadow values
29 */
30#define KASAN_ALLOCA_LEFT 0xCA
31#define KASAN_ALLOCA_RIGHT 0xCB
32
33#define KASAN_ALLOCA_REDZONE_SIZE 32
34
bebf56a1
AR
35/* Don't break randconfig/all*config builds */
36#ifndef KASAN_ABI_VERSION
37#define KASAN_ABI_VERSION 1
38#endif
b8c73fc2 39
0b24becc
AR
40struct kasan_access_info {
41 const void *access_addr;
42 const void *first_bad_addr;
43 size_t access_size;
44 bool is_write;
45 unsigned long ip;
46};
47
bebf56a1
AR
48/* The layout of struct dictated by compiler */
49struct kasan_source_location {
50 const char *filename;
51 int line_no;
52 int column_no;
53};
54
55/* The layout of struct dictated by compiler */
56struct kasan_global {
57 const void *beg; /* Address of the beginning of the global variable. */
58 size_t size; /* Size of the global variable. */
59 size_t size_with_redzone; /* Size of the variable + size of the red zone. 32 bytes aligned */
60 const void *name;
61 const void *module_name; /* Name of the module where the global variable is declared. */
62 unsigned long has_dynamic_init; /* This needed for C++ */
63#if KASAN_ABI_VERSION >= 4
64 struct kasan_source_location *location;
65#endif
045d599a
DV
66#if KASAN_ABI_VERSION >= 5
67 char *odr_indicator;
68#endif
bebf56a1
AR
69};
70
7ed2f9e6
AP
71/**
72 * Structures to keep alloc and free tracks *
73 */
74
cd11016e
AP
75#define KASAN_STACK_DEPTH 64
76
7ed2f9e6 77struct kasan_track {
cd11016e
AP
78 u32 pid;
79 depot_stack_handle_t stack;
7ed2f9e6
AP
80};
81
82struct kasan_alloc_meta {
b3cbd9bf
AR
83 struct kasan_track alloc_track;
84 struct kasan_track free_track;
7ed2f9e6
AP
85};
86
55834c59
AP
87struct qlist_node {
88 struct qlist_node *next;
89};
7ed2f9e6 90struct kasan_free_meta {
55834c59
AP
91 /* This field is used while the object is in the quarantine.
92 * Otherwise it might be used for the allocator freelist.
93 */
94 struct qlist_node quarantine_link;
7ed2f9e6
AP
95};
96
97struct kasan_alloc_meta *get_alloc_info(struct kmem_cache *cache,
98 const void *object);
99struct kasan_free_meta *get_free_info(struct kmem_cache *cache,
100 const void *object);
101
0b24becc
AR
102static inline const void *kasan_shadow_to_mem(const void *shadow_addr)
103{
104 return (void *)(((unsigned long)shadow_addr - KASAN_SHADOW_OFFSET)
105 << KASAN_SHADOW_SCALE_SHIFT);
106}
107
0b24becc
AR
108void kasan_report(unsigned long addr, size_t size,
109 bool is_write, unsigned long ip);
47adccce 110void kasan_report_invalid_free(void *object, void *ip);
0b24becc 111
80a9201a 112#if defined(CONFIG_SLAB) || defined(CONFIG_SLUB)
55834c59
AP
113void quarantine_put(struct kasan_free_meta *info, struct kmem_cache *cache);
114void quarantine_reduce(void);
115void quarantine_remove_cache(struct kmem_cache *cache);
116#else
117static inline void quarantine_put(struct kasan_free_meta *info,
118 struct kmem_cache *cache) { }
119static inline void quarantine_reduce(void) { }
120static inline void quarantine_remove_cache(struct kmem_cache *cache) { }
121#endif
122
d321599c
AP
123/*
124 * Exported functions for interfaces called from assembly or from generated
125 * code. Declarations here to avoid warning about missing declarations.
126 */
127asmlinkage void kasan_unpoison_task_stack_below(const void *watermark);
128void __asan_register_globals(struct kasan_global *globals, size_t size);
129void __asan_unregister_globals(struct kasan_global *globals, size_t size);
130void __asan_loadN(unsigned long addr, size_t size);
131void __asan_storeN(unsigned long addr, size_t size);
132void __asan_handle_no_return(void);
133void __asan_poison_stack_memory(const void *addr, size_t size);
134void __asan_unpoison_stack_memory(const void *addr, size_t size);
135void __asan_alloca_poison(unsigned long addr, size_t size);
136void __asan_allocas_unpoison(const void *stack_top, const void *stack_bottom);
137
138void __asan_load1(unsigned long addr);
139void __asan_store1(unsigned long addr);
140void __asan_load2(unsigned long addr);
141void __asan_store2(unsigned long addr);
142void __asan_load4(unsigned long addr);
143void __asan_store4(unsigned long addr);
144void __asan_load8(unsigned long addr);
145void __asan_store8(unsigned long addr);
146void __asan_load16(unsigned long addr);
147void __asan_store16(unsigned long addr);
148
149void __asan_load1_noabort(unsigned long addr);
150void __asan_store1_noabort(unsigned long addr);
151void __asan_load2_noabort(unsigned long addr);
152void __asan_store2_noabort(unsigned long addr);
153void __asan_load4_noabort(unsigned long addr);
154void __asan_store4_noabort(unsigned long addr);
155void __asan_load8_noabort(unsigned long addr);
156void __asan_store8_noabort(unsigned long addr);
157void __asan_load16_noabort(unsigned long addr);
158void __asan_store16_noabort(unsigned long addr);
159
160void __asan_set_shadow_00(const void *addr, size_t size);
161void __asan_set_shadow_f1(const void *addr, size_t size);
162void __asan_set_shadow_f2(const void *addr, size_t size);
163void __asan_set_shadow_f3(const void *addr, size_t size);
164void __asan_set_shadow_f5(const void *addr, size_t size);
165void __asan_set_shadow_f8(const void *addr, size_t size);
166
0b24becc 167#endif