alternative.c 18.7 KB
Newer Older
1 2
#define pr_fmt(fmt) "SMP alternatives: " fmt

G
Gerd Hoffmann 已提交
3
#include <linux/module.h>
A
Al Viro 已提交
4
#include <linux/sched.h>
5
#include <linux/mutex.h>
G
Gerd Hoffmann 已提交
6
#include <linux/list.h>
7
#include <linux/stringify.h>
8 9 10
#include <linux/kprobes.h>
#include <linux/mm.h>
#include <linux/vmalloc.h>
11
#include <linux/memory.h>
12
#include <linux/stop_machine.h>
13
#include <linux/slab.h>
G
Gerd Hoffmann 已提交
14 15
#include <asm/alternative.h>
#include <asm/sections.h>
16
#include <asm/pgtable.h>
17 18
#include <asm/mce.h>
#include <asm/nmi.h>
19
#include <asm/cacheflush.h>
20
#include <asm/tlbflush.h>
21
#include <asm/io.h>
22
#include <asm/fixmap.h>
G
Gerd Hoffmann 已提交
23

24 25
#define MAX_PATCH_LEN (255-1)

26 27
#ifdef CONFIG_HOTPLUG_CPU
static int smp_alt_once;
G
Gerd Hoffmann 已提交
28

29 30 31 32 33
static int __init bootonly(char *str)
{
	smp_alt_once = 1;
	return 1;
}
34
__setup("smp-alt-boot", bootonly);
35 36 37 38
#else
#define smp_alt_once 1
#endif

39
static int __initdata_or_module debug_alternative;
40

41 42 43 44 45 46 47
static int __init debug_alt(char *str)
{
	debug_alternative = 1;
	return 1;
}
__setup("debug-alternative", debug_alt);

48 49
static int noreplace_smp;

50 51 52 53 54 55 56
static int __init setup_noreplace_smp(char *str)
{
	noreplace_smp = 1;
	return 1;
}
__setup("noreplace-smp", setup_noreplace_smp);

57
#ifdef CONFIG_PARAVIRT
58
static int __initdata_or_module noreplace_paravirt = 0;
59 60 61 62 63 64 65 66

static int __init setup_noreplace_paravirt(char *str)
{
	noreplace_paravirt = 1;
	return 1;
}
__setup("noreplace-paravirt", setup_noreplace_paravirt);
#endif
67

68 69 70 71 72
#define DPRINTK(fmt, ...)				\
do {							\
	if (debug_alternative)				\
		printk(KERN_DEBUG fmt, ##__VA_ARGS__);	\
} while (0)
73

74 75 76 77 78 79 80 81 82
/*
 * Each GENERIC_NOPX is of X bytes, and defined as an array of bytes
 * that correspond to that nop. Getting from one nop to the next, we
 * add to the array the offset that is equal to the sum of all sizes of
 * nops preceding the one we are after.
 *
 * Note: The GENERIC_NOP5_ATOMIC is at the end, as it breaks the
 * nice symmetry of sizes of the previous nops.
 */
83
#if defined(GENERIC_NOP1) && !defined(CONFIG_X86_64)
84 85 86 87 88 89 90 91 92 93 94 95 96 97
static const unsigned char intelnops[] =
{
	GENERIC_NOP1,
	GENERIC_NOP2,
	GENERIC_NOP3,
	GENERIC_NOP4,
	GENERIC_NOP5,
	GENERIC_NOP6,
	GENERIC_NOP7,
	GENERIC_NOP8,
	GENERIC_NOP5_ATOMIC
};
static const unsigned char * const intel_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
98 99 100 101 102 103 104 105 106
	NULL,
	intelnops,
	intelnops + 1,
	intelnops + 1 + 2,
	intelnops + 1 + 2 + 3,
	intelnops + 1 + 2 + 3 + 4,
	intelnops + 1 + 2 + 3 + 4 + 5,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
107
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
108
};
109 110 111
#endif

#ifdef K8_NOP1
112 113 114 115 116 117 118 119 120 121 122 123 124 125
static const unsigned char k8nops[] =
{
	K8_NOP1,
	K8_NOP2,
	K8_NOP3,
	K8_NOP4,
	K8_NOP5,
	K8_NOP6,
	K8_NOP7,
	K8_NOP8,
	K8_NOP5_ATOMIC
};
static const unsigned char * const k8_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
126 127 128 129 130 131 132 133 134
	NULL,
	k8nops,
	k8nops + 1,
	k8nops + 1 + 2,
	k8nops + 1 + 2 + 3,
	k8nops + 1 + 2 + 3 + 4,
	k8nops + 1 + 2 + 3 + 4 + 5,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
135
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
136
};
137 138
#endif

139
#if defined(K7_NOP1) && !defined(CONFIG_X86_64)
140 141 142 143 144 145 146 147 148 149 150 151 152 153
static const unsigned char k7nops[] =
{
	K7_NOP1,
	K7_NOP2,
	K7_NOP3,
	K7_NOP4,
	K7_NOP5,
	K7_NOP6,
	K7_NOP7,
	K7_NOP8,
	K7_NOP5_ATOMIC
};
static const unsigned char * const k7_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
154 155 156 157 158 159 160 161 162
	NULL,
	k7nops,
	k7nops + 1,
	k7nops + 1 + 2,
	k7nops + 1 + 2 + 3,
	k7nops + 1 + 2 + 3 + 4,
	k7nops + 1 + 2 + 3 + 4 + 5,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
163
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
164
};
165 166
#endif

167
#ifdef P6_NOP1
168
static const unsigned char p6nops[] =
169 170 171 172 173 174 175 176 177 178 179 180 181
{
	P6_NOP1,
	P6_NOP2,
	P6_NOP3,
	P6_NOP4,
	P6_NOP5,
	P6_NOP6,
	P6_NOP7,
	P6_NOP8,
	P6_NOP5_ATOMIC
};
static const unsigned char * const p6_nops[ASM_NOP_MAX+2] =
{
182 183 184 185 186 187 188 189 190
	NULL,
	p6nops,
	p6nops + 1,
	p6nops + 1 + 2,
	p6nops + 1 + 2 + 3,
	p6nops + 1 + 2 + 3 + 4,
	p6nops + 1 + 2 + 3 + 4 + 5,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
191
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
192 193 194
};
#endif

195
/* Initialize these to a safe default */
196
#ifdef CONFIG_X86_64
197 198 199 200
const unsigned char * const *ideal_nops = p6_nops;
#else
const unsigned char * const *ideal_nops = intel_nops;
#endif
201

202
void __init arch_init_ideal_nops(void)
203
{
204 205
	switch (boot_cpu_data.x86_vendor) {
	case X86_VENDOR_INTEL:
206 207 208 209 210 211 212 213 214 215 216 217 218
		/*
		 * Due to a decoder implementation quirk, some
		 * specific Intel CPUs actually perform better with
		 * the "k8_nops" than with the SDM-recommended NOPs.
		 */
		if (boot_cpu_data.x86 == 6 &&
		    boot_cpu_data.x86_model >= 0x0f &&
		    boot_cpu_data.x86_model != 0x1c &&
		    boot_cpu_data.x86_model != 0x26 &&
		    boot_cpu_data.x86_model != 0x27 &&
		    boot_cpu_data.x86_model < 0x30) {
			ideal_nops = k8_nops;
		} else if (boot_cpu_has(X86_FEATURE_NOPL)) {
219 220 221 222 223 224 225 226
			   ideal_nops = p6_nops;
		} else {
#ifdef CONFIG_X86_64
			ideal_nops = k8_nops;
#else
			ideal_nops = intel_nops;
#endif
		}
227
		break;
228 229 230 231 232 233 234 235 236 237 238 239
	default:
#ifdef CONFIG_X86_64
		ideal_nops = k8_nops;
#else
		if (boot_cpu_has(X86_FEATURE_K8))
			ideal_nops = k8_nops;
		else if (boot_cpu_has(X86_FEATURE_K7))
			ideal_nops = k7_nops;
		else
			ideal_nops = intel_nops;
#endif
	}
G
Gerd Hoffmann 已提交
240 241
}

242
/* Use this to add nops to a buffer, then text_poke the whole buffer. */
243
static void __init_or_module add_nops(void *insns, unsigned int len)
244 245 246 247 248
{
	while (len > 0) {
		unsigned int noplen = len;
		if (noplen > ASM_NOP_MAX)
			noplen = ASM_NOP_MAX;
249
		memcpy(insns, ideal_nops[noplen], noplen);
250 251 252 253 254
		insns += noplen;
		len -= noplen;
	}
}

255
extern struct alt_instr __alt_instructions[], __alt_instructions_end[];
256
extern s32 __smp_locks[], __smp_locks_end[];
257
void *text_poke_early(void *addr, const void *opcode, size_t len);
258

G
Gerd Hoffmann 已提交
259 260
/* Replace instructions with better alternatives for this CPU type.
   This runs before SMP is initialized to avoid SMP problems with
L
Lucas De Marchi 已提交
261
   self modifying code. This implies that asymmetric systems where
G
Gerd Hoffmann 已提交
262 263 264
   APs have less capabilities than the boot processor are not handled.
   Tough. Make sure you disable such features by hand. */

265 266
void __init_or_module apply_alternatives(struct alt_instr *start,
					 struct alt_instr *end)
G
Gerd Hoffmann 已提交
267 268
{
	struct alt_instr *a;
269
	u8 *instr, *replacement;
270
	u8 insnbuf[MAX_PATCH_LEN];
G
Gerd Hoffmann 已提交
271

272
	DPRINTK("%s: alt table %p -> %p\n", __func__, start, end);
273 274 275 276 277 278 279 280 281
	/*
	 * The scan order should be from start to end. A later scanned
	 * alternative code can overwrite a previous scanned alternative code.
	 * Some kernel functions (e.g. memcpy, memset, etc) use this order to
	 * patch code.
	 *
	 * So be careful if you want to change the scan order to any other
	 * order.
	 */
G
Gerd Hoffmann 已提交
282
	for (a = start; a < end; a++) {
283 284
		instr = (u8 *)&a->instr_offset + a->instr_offset;
		replacement = (u8 *)&a->repl_offset + a->repl_offset;
G
Gerd Hoffmann 已提交
285
		BUG_ON(a->replacementlen > a->instrlen);
286
		BUG_ON(a->instrlen > sizeof(insnbuf));
287
		BUG_ON(a->cpuid >= NCAPINTS*32);
G
Gerd Hoffmann 已提交
288 289
		if (!boot_cpu_has(a->cpuid))
			continue;
290 291 292 293 294 295 296 297 298 299

		memcpy(insnbuf, replacement, a->replacementlen);

		/* 0xe8 is a relative jump; fix the offset. */
		if (*insnbuf == 0xe8 && a->replacementlen == 5)
		    *(s32 *)(insnbuf + 1) += replacement - instr;

		add_nops(insnbuf + a->replacementlen,
			 a->instrlen - a->replacementlen);

300
		text_poke_early(instr, insnbuf, a->instrlen);
G
Gerd Hoffmann 已提交
301 302 303
	}
}

304 305
#ifdef CONFIG_SMP

306 307
static void alternatives_smp_lock(const s32 *start, const s32 *end,
				  u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
308
{
309
	const s32 *poff;
G
Gerd Hoffmann 已提交
310

311
	mutex_lock(&text_mutex);
312 313 314 315
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
316
			continue;
317
		/* turn DS segment override prefix into lock prefix */
318 319
		if (*ptr == 0x3e)
			text_poke(ptr, ((unsigned char []){0xf0}), 1);
G
Gerd Hoffmann 已提交
320
	};
321
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
322 323
}

324 325
static void alternatives_smp_unlock(const s32 *start, const s32 *end,
				    u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
326
{
327
	const s32 *poff;
G
Gerd Hoffmann 已提交
328

329 330 331
	if (noreplace_smp)
		return;

332
	mutex_lock(&text_mutex);
333 334 335 336
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
337
			continue;
338
		/* turn lock prefix into DS segment override prefix */
339 340
		if (*ptr == 0xf0)
			text_poke(ptr, ((unsigned char []){0x3E}), 1);
G
Gerd Hoffmann 已提交
341
	};
342
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
343 344 345 346 347 348 349 350
}

struct smp_alt_module {
	/* what is this ??? */
	struct module	*mod;
	char		*name;

	/* ptrs to lock prefixes */
351 352
	const s32	*locks;
	const s32	*locks_end;
G
Gerd Hoffmann 已提交
353 354 355 356 357 358 359 360

	/* .text segment, needed to avoid patching init code ;) */
	u8		*text;
	u8		*text_end;

	struct list_head next;
};
static LIST_HEAD(smp_alt_modules);
361
static DEFINE_MUTEX(smp_alt);
362
static int smp_mode = 1;	/* protected by smp_alt */
G
Gerd Hoffmann 已提交
363

364 365 366 367
void __init_or_module alternatives_smp_module_add(struct module *mod,
						  char *name,
						  void *locks, void *locks_end,
						  void *text,  void *text_end)
G
Gerd Hoffmann 已提交
368 369 370
{
	struct smp_alt_module *smp;

371 372 373
	if (noreplace_smp)
		return;

G
Gerd Hoffmann 已提交
374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391
	if (smp_alt_once) {
		if (boot_cpu_has(X86_FEATURE_UP))
			alternatives_smp_unlock(locks, locks_end,
						text, text_end);
		return;
	}

	smp = kzalloc(sizeof(*smp), GFP_KERNEL);
	if (NULL == smp)
		return; /* we'll run the (safe but slow) SMP code then ... */

	smp->mod	= mod;
	smp->name	= name;
	smp->locks	= locks;
	smp->locks_end	= locks_end;
	smp->text	= text;
	smp->text_end	= text_end;
	DPRINTK("%s: locks %p -> %p, text %p -> %p, name %s\n",
392
		__func__, smp->locks, smp->locks_end,
G
Gerd Hoffmann 已提交
393 394
		smp->text, smp->text_end, smp->name);

395
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
396 397 398 399
	list_add_tail(&smp->next, &smp_alt_modules);
	if (boot_cpu_has(X86_FEATURE_UP))
		alternatives_smp_unlock(smp->locks, smp->locks_end,
					smp->text, smp->text_end);
400
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
401 402
}

403
void __init_or_module alternatives_smp_module_del(struct module *mod)
G
Gerd Hoffmann 已提交
404 405 406
{
	struct smp_alt_module *item;

407
	if (smp_alt_once || noreplace_smp)
G
Gerd Hoffmann 已提交
408 409
		return;

410
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
411 412 413 414
	list_for_each_entry(item, &smp_alt_modules, next) {
		if (mod != item->mod)
			continue;
		list_del(&item->next);
415
		mutex_unlock(&smp_alt);
416
		DPRINTK("%s: %s\n", __func__, item->name);
G
Gerd Hoffmann 已提交
417 418 419
		kfree(item);
		return;
	}
420
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
421 422
}

423
bool skip_smp_alternatives;
G
Gerd Hoffmann 已提交
424 425 426 427
void alternatives_smp_switch(int smp)
{
	struct smp_alt_module *mod;

428 429
#ifdef CONFIG_LOCKDEP
	/*
430 431 432 433 434
	 * Older binutils section handling bug prevented
	 * alternatives-replacement from working reliably.
	 *
	 * If this still occurs then you should see a hang
	 * or crash shortly after this line:
435
	 */
436
	pr_info("lockdep: fixing up alternatives\n");
437 438
#endif

439
	if (noreplace_smp || smp_alt_once || skip_smp_alternatives)
G
Gerd Hoffmann 已提交
440 441 442
		return;
	BUG_ON(!smp && (num_online_cpus() > 1));

443
	mutex_lock(&smp_alt);
444 445 446 447 448 449 450 451

	/*
	 * Avoid unnecessary switches because it forces JIT based VMs to
	 * throw away all cached translations, which can be quite costly.
	 */
	if (smp == smp_mode) {
		/* nothing */
	} else if (smp) {
452
		pr_info("switching to SMP code\n");
453 454
		clear_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		clear_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
455 456 457 458
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_lock(mod->locks, mod->locks_end,
					      mod->text, mod->text_end);
	} else {
459
		pr_info("switching to UP code\n");
460 461
		set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
462 463 464 465
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_unlock(mod->locks, mod->locks_end,
						mod->text, mod->text_end);
	}
466
	smp_mode = smp;
467
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
468 469
}

470 471 472 473
/* Return 1 if the address range is reserved for smp-alternatives */
int alternatives_text_reserved(void *start, void *end)
{
	struct smp_alt_module *mod;
474
	const s32 *poff;
475 476
	u8 *text_start = start;
	u8 *text_end = end;
477 478

	list_for_each_entry(mod, &smp_alt_modules, next) {
479
		if (mod->text > text_end || mod->text_end < text_start)
480
			continue;
481 482 483 484
		for (poff = mod->locks; poff < mod->locks_end; poff++) {
			const u8 *ptr = (const u8 *)poff + *poff;

			if (text_start <= ptr && text_end > ptr)
485
				return 1;
486
		}
487 488 489 490
	}

	return 0;
}
491 492
#endif

493
#ifdef CONFIG_PARAVIRT
494 495
void __init_or_module apply_paravirt(struct paravirt_patch_site *start,
				     struct paravirt_patch_site *end)
496
{
497
	struct paravirt_patch_site *p;
498
	char insnbuf[MAX_PATCH_LEN];
499

500 501 502
	if (noreplace_paravirt)
		return;

503 504 505
	for (p = start; p < end; p++) {
		unsigned int used;

506
		BUG_ON(p->len > MAX_PATCH_LEN);
507 508
		/* prep the buffer with the original instructions */
		memcpy(insnbuf, p->instr, p->len);
509 510
		used = pv_init_ops.patch(p->instrtype, p->clobbers, insnbuf,
					 (unsigned long)p->instr, p->len);
511

512 513
		BUG_ON(used > p->len);

514
		/* Pad the rest with nops */
515
		add_nops(insnbuf + used, p->len - used);
516
		text_poke_early(p->instr, insnbuf, p->len);
517 518
	}
}
519
extern struct paravirt_patch_site __start_parainstructions[],
520 521 522
	__stop_parainstructions[];
#endif	/* CONFIG_PARAVIRT */

G
Gerd Hoffmann 已提交
523 524
void __init alternative_instructions(void)
{
525 526 527 528
	/* The patching is not fully atomic, so try to avoid local interruptions
	   that might execute the to be patched code.
	   Other CPUs are not running. */
	stop_nmi();
529 530 531 532 533 534 535 536 537 538 539

	/*
	 * Don't stop machine check exceptions while patching.
	 * MCEs only happen when something got corrupted and in this
	 * case we must do something about the corruption.
	 * Ignoring it is worse than a unlikely patching race.
	 * Also machine checks tend to be broadcast and if one CPU
	 * goes into machine check the others follow quickly, so we don't
	 * expect a machine check to cause undue problems during to code
	 * patching.
	 */
540

G
Gerd Hoffmann 已提交
541 542 543 544 545 546 547 548 549 550
	apply_alternatives(__alt_instructions, __alt_instructions_end);

	/* switch to patch-once-at-boottime-only mode and free the
	 * tables in case we know the number of CPUs will never ever
	 * change */
#ifdef CONFIG_HOTPLUG_CPU
	if (num_possible_cpus() < 2)
		smp_alt_once = 1;
#endif

551
#ifdef CONFIG_SMP
G
Gerd Hoffmann 已提交
552 553
	if (smp_alt_once) {
		if (1 == num_possible_cpus()) {
554
			pr_info("switching to UP code\n");
555 556 557
			set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
			set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);

G
Gerd Hoffmann 已提交
558 559 560 561 562 563 564
			alternatives_smp_unlock(__smp_locks, __smp_locks_end,
						_text, _etext);
		}
	} else {
		alternatives_smp_module_add(NULL, "core kernel",
					    __smp_locks, __smp_locks_end,
					    _text, _etext);
565 566

		/* Only switch to UP mode if we don't immediately boot others */
567
		if (num_present_cpus() == 1 || setup_max_cpus <= 1)
568
			alternatives_smp_switch(0);
G
Gerd Hoffmann 已提交
569
	}
570
#endif
571
 	apply_paravirt(__parainstructions, __parainstructions_end);
572

573 574 575 576 577
	if (smp_alt_once)
		free_init_pages("SMP alternatives",
				(unsigned long)__smp_locks,
				(unsigned long)__smp_locks_end);

578
	restart_nmi();
G
Gerd Hoffmann 已提交
579
}
580

581 582 583 584 585 586
/**
 * text_poke_early - Update instructions on a live kernel at boot time
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
587 588
 * When you use this code to patch more than one byte of an instruction
 * you need to make sure that other CPUs cannot execute this code in parallel.
589 590 591
 * Also no thread must be currently preempted in the middle of these
 * instructions. And on the local CPU you need to be protected again NMI or MCE
 * handlers seeing an inconsistent instruction while you patch.
592
 */
593
void *__init_or_module text_poke_early(void *addr, const void *opcode,
594
					      size_t len)
595
{
596 597
	unsigned long flags;
	local_irq_save(flags);
598
	memcpy(addr, opcode, len);
599
	sync_core();
600
	local_irq_restore(flags);
601 602 603 604 605 606 607 608 609 610 611 612 613 614 615
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
	return addr;
}

/**
 * text_poke - Update instructions on a live kernel
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Only atomic text poke/set should be allowed when not doing early patching.
 * It means the size must be writable atomically and the address must be aligned
 * in a way that permits an atomic write. It also makes sure we fit on a single
 * page.
616 617
 *
 * Note: Must be called under text_mutex.
618 619 620
 */
void *__kprobes text_poke(void *addr, const void *opcode, size_t len)
{
621
	unsigned long flags;
622
	char *vaddr;
M
Mathieu Desnoyers 已提交
623 624
	struct page *pages[2];
	int i;
625

M
Mathieu Desnoyers 已提交
626 627 628
	if (!core_kernel_text((unsigned long)addr)) {
		pages[0] = vmalloc_to_page(addr);
		pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
629
	} else {
M
Mathieu Desnoyers 已提交
630
		pages[0] = virt_to_page(addr);
I
Ingo Molnar 已提交
631
		WARN_ON(!PageReserved(pages[0]));
M
Mathieu Desnoyers 已提交
632
		pages[1] = virt_to_page(addr + PAGE_SIZE);
633
	}
M
Mathieu Desnoyers 已提交
634
	BUG_ON(!pages[0]);
635
	local_irq_save(flags);
636 637 638 639
	set_fixmap(FIX_TEXT_POKE0, page_to_phys(pages[0]));
	if (pages[1])
		set_fixmap(FIX_TEXT_POKE1, page_to_phys(pages[1]));
	vaddr = (char *)fix_to_virt(FIX_TEXT_POKE0);
M
Mathieu Desnoyers 已提交
640
	memcpy(&vaddr[(unsigned long)addr & ~PAGE_MASK], opcode, len);
641 642 643 644
	clear_fixmap(FIX_TEXT_POKE0);
	if (pages[1])
		clear_fixmap(FIX_TEXT_POKE1);
	local_flush_tlb();
645
	sync_core();
646 647
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
M
Mathieu Desnoyers 已提交
648 649
	for (i = 0; i < len; i++)
		BUG_ON(((char *)addr)[i] != ((char *)opcode)[i]);
650
	local_irq_restore(flags);
651
	return addr;
652
}
653 654 655 656 657 658 659 660 661

/*
 * Cross-modifying kernel text with stop_machine().
 * This code originally comes from immediate value.
 */
static atomic_t stop_machine_first;
static int wrote_text;

struct text_poke_params {
662 663
	struct text_poke_param *params;
	int nparams;
664 665 666 667 668
};

static int __kprobes stop_machine_text_poke(void *data)
{
	struct text_poke_params *tpp = data;
669 670
	struct text_poke_param *p;
	int i;
671

672
	if (atomic_xchg(&stop_machine_first, 0)) {
673 674 675 676
		for (i = 0; i < tpp->nparams; i++) {
			p = &tpp->params[i];
			text_poke(p->addr, p->opcode, p->len);
		}
677 678 679 680
		smp_wmb();	/* Make sure other cpus see that this has run */
		wrote_text = 1;
	} else {
		while (!wrote_text)
681 682
			cpu_relax();
		smp_mb();	/* Load wrote_text before following execution */
683 684
	}

685 686 687 688 689
	for (i = 0; i < tpp->nparams; i++) {
		p = &tpp->params[i];
		flush_icache_range((unsigned long)p->addr,
				   (unsigned long)p->addr + p->len);
	}
690 691 692 693 694 695
	/*
	 * Intel Archiecture Software Developer's Manual section 7.1.3 specifies
	 * that a core serializing instruction such as "cpuid" should be
	 * executed on _each_ core before the new instruction is made visible.
	 */
	sync_core();
696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714
	return 0;
}

/**
 * text_poke_smp - Update instructions on a live kernel on SMP
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. This allows
 * user to poke/set multi-byte text on SMP. Only non-NMI/MCE code modifying
 * should be allowed, since stop_machine() does _not_ protect code against
 * NMI and MCE.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void *__kprobes text_poke_smp(void *addr, const void *opcode, size_t len)
{
	struct text_poke_params tpp;
715
	struct text_poke_param p;
716

717 718 719 720 721
	p.addr = addr;
	p.opcode = opcode;
	p.len = len;
	tpp.params = &p;
	tpp.nparams = 1;
722 723
	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
724
	/* Use __stop_machine() because the caller already got online_cpus. */
725
	__stop_machine(stop_machine_text_poke, (void *)&tpp, cpu_online_mask);
726 727 728
	return addr;
}

729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745
/**
 * text_poke_smp_batch - Update instructions on a live kernel on SMP
 * @params: an array of text_poke parameters
 * @n: the number of elements in params.
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. Since the
 * stop_machine() is heavy task, it is better to aggregate text_poke requests
 * and do it once if possible.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void __kprobes text_poke_smp_batch(struct text_poke_param *params, int n)
{
	struct text_poke_params tpp = {.params = params, .nparams = n};

	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
746
	__stop_machine(stop_machine_text_poke, (void *)&tpp, cpu_online_mask);
747
}