alternative.c 18.7 KB
Newer Older
G
Gerd Hoffmann 已提交
1
#include <linux/module.h>
A
Al Viro 已提交
2
#include <linux/sched.h>
3
#include <linux/mutex.h>
G
Gerd Hoffmann 已提交
4
#include <linux/list.h>
5
#include <linux/stringify.h>
6 7 8
#include <linux/kprobes.h>
#include <linux/mm.h>
#include <linux/vmalloc.h>
9
#include <linux/memory.h>
10
#include <linux/stop_machine.h>
11
#include <linux/slab.h>
G
Gerd Hoffmann 已提交
12 13
#include <asm/alternative.h>
#include <asm/sections.h>
14
#include <asm/pgtable.h>
15 16
#include <asm/mce.h>
#include <asm/nmi.h>
D
Dave Jones 已提交
17
#include <asm/vsyscall.h>
18
#include <asm/cacheflush.h>
19
#include <asm/tlbflush.h>
20
#include <asm/io.h>
21
#include <asm/fixmap.h>
G
Gerd Hoffmann 已提交
22

23 24
#define MAX_PATCH_LEN (255-1)

25 26
#ifdef CONFIG_HOTPLUG_CPU
static int smp_alt_once;
G
Gerd Hoffmann 已提交
27

28 29 30 31 32
static int __init bootonly(char *str)
{
	smp_alt_once = 1;
	return 1;
}
33
__setup("smp-alt-boot", bootonly);
34 35 36 37
#else
#define smp_alt_once 1
#endif

38
static int __initdata_or_module debug_alternative;
39

40 41 42 43 44 45 46
static int __init debug_alt(char *str)
{
	debug_alternative = 1;
	return 1;
}
__setup("debug-alternative", debug_alt);

47 48
static int noreplace_smp;

49 50 51 52 53 54 55
static int __init setup_noreplace_smp(char *str)
{
	noreplace_smp = 1;
	return 1;
}
__setup("noreplace-smp", setup_noreplace_smp);

56
#ifdef CONFIG_PARAVIRT
57
static int __initdata_or_module noreplace_paravirt = 0;
58 59 60 61 62 63 64 65

static int __init setup_noreplace_paravirt(char *str)
{
	noreplace_paravirt = 1;
	return 1;
}
__setup("noreplace-paravirt", setup_noreplace_paravirt);
#endif
66

67 68 69
#define DPRINTK(fmt, args...) if (debug_alternative) \
	printk(KERN_DEBUG fmt, args)

70
#if defined(GENERIC_NOP1) && !defined(CONFIG_X86_64)
G
Gerd Hoffmann 已提交
71 72 73
/* Use inline assembly to define this because the nops are defined
   as inline assembly strings in the include files and we cannot
   get them easily into strings. */
74
asm("\t" __stringify(__INITRODATA_OR_MODULE) "\nintelnops: "
G
Gerd Hoffmann 已提交
75
	GENERIC_NOP1 GENERIC_NOP2 GENERIC_NOP3 GENERIC_NOP4 GENERIC_NOP5 GENERIC_NOP6
76 77
	GENERIC_NOP7 GENERIC_NOP8
    "\t.previous");
J
Jan Beulich 已提交
78
extern const unsigned char intelnops[];
79 80
static const unsigned char *const __initconst_or_module
intel_nops[ASM_NOP_MAX+1] = {
G
Gerd Hoffmann 已提交
81 82 83 84 85 86 87 88 89 90
	NULL,
	intelnops,
	intelnops + 1,
	intelnops + 1 + 2,
	intelnops + 1 + 2 + 3,
	intelnops + 1 + 2 + 3 + 4,
	intelnops + 1 + 2 + 3 + 4 + 5,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
};
91 92 93
#endif

#ifdef K8_NOP1
94
asm("\t" __stringify(__INITRODATA_OR_MODULE) "\nk8nops: "
95
	K8_NOP1 K8_NOP2 K8_NOP3 K8_NOP4 K8_NOP5 K8_NOP6
96 97
	K8_NOP7 K8_NOP8
    "\t.previous");
J
Jan Beulich 已提交
98
extern const unsigned char k8nops[];
99 100
static const unsigned char *const __initconst_or_module
k8_nops[ASM_NOP_MAX+1] = {
G
Gerd Hoffmann 已提交
101 102 103 104 105 106 107 108 109 110
	NULL,
	k8nops,
	k8nops + 1,
	k8nops + 1 + 2,
	k8nops + 1 + 2 + 3,
	k8nops + 1 + 2 + 3 + 4,
	k8nops + 1 + 2 + 3 + 4 + 5,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
};
111 112
#endif

113 114
#if defined(K7_NOP1) && !defined(CONFIG_X86_64)
asm("\t" __stringify(__INITRODATA_OR_MODULE) "\nk7nops: "
115
	K7_NOP1 K7_NOP2 K7_NOP3 K7_NOP4 K7_NOP5 K7_NOP6
116 117
	K7_NOP7 K7_NOP8
    "\t.previous");
J
Jan Beulich 已提交
118
extern const unsigned char k7nops[];
119 120
static const unsigned char *const __initconst_or_module
k7_nops[ASM_NOP_MAX+1] = {
G
Gerd Hoffmann 已提交
121 122 123 124 125 126 127 128 129 130
	NULL,
	k7nops,
	k7nops + 1,
	k7nops + 1 + 2,
	k7nops + 1 + 2 + 3,
	k7nops + 1 + 2 + 3 + 4,
	k7nops + 1 + 2 + 3 + 4 + 5,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
};
131 132
#endif

133
#ifdef P6_NOP1
134
asm("\t" __stringify(__INITRODATA_OR_MODULE) "\np6nops: "
135
	P6_NOP1 P6_NOP2 P6_NOP3 P6_NOP4 P6_NOP5 P6_NOP6
136 137
	P6_NOP7 P6_NOP8
    "\t.previous");
138
extern const unsigned char p6nops[];
139 140
static const unsigned char *const __initconst_or_module
p6_nops[ASM_NOP_MAX+1] = {
141 142 143 144 145 146 147 148 149 150 151 152
	NULL,
	p6nops,
	p6nops + 1,
	p6nops + 1 + 2,
	p6nops + 1 + 2 + 3,
	p6nops + 1 + 2 + 3 + 4,
	p6nops + 1 + 2 + 3 + 4 + 5,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
};
#endif

153 154 155
#ifdef CONFIG_X86_64

extern char __vsyscall_0;
156
static const unsigned char *const *__init_or_module find_nop_table(void)
157
{
158 159 160 161 162
	if (boot_cpu_data.x86_vendor == X86_VENDOR_INTEL &&
	    boot_cpu_has(X86_FEATURE_NOPL))
		return p6_nops;
	else
		return k8_nops;
163 164 165 166
}

#else /* CONFIG_X86_64 */

167
static const unsigned char *const *__init_or_module find_nop_table(void)
G
Gerd Hoffmann 已提交
168
{
169 170 171 172 173 174 175 176
	if (boot_cpu_has(X86_FEATURE_K8))
		return k8_nops;
	else if (boot_cpu_has(X86_FEATURE_K7))
		return k7_nops;
	else if (boot_cpu_has(X86_FEATURE_NOPL))
		return p6_nops;
	else
		return intel_nops;
G
Gerd Hoffmann 已提交
177 178
}

179 180
#endif /* CONFIG_X86_64 */

181
/* Use this to add nops to a buffer, then text_poke the whole buffer. */
182
static void __init_or_module add_nops(void *insns, unsigned int len)
183
{
J
Jan Beulich 已提交
184
	const unsigned char *const *noptable = find_nop_table();
185 186 187 188 189

	while (len > 0) {
		unsigned int noplen = len;
		if (noplen > ASM_NOP_MAX)
			noplen = ASM_NOP_MAX;
190
		memcpy(insns, noptable[noplen], noplen);
191 192 193 194 195
		insns += noplen;
		len -= noplen;
	}
}

196
extern struct alt_instr __alt_instructions[], __alt_instructions_end[];
197
extern s32 __smp_locks[], __smp_locks_end[];
198
void *text_poke_early(void *addr, const void *opcode, size_t len);
199

G
Gerd Hoffmann 已提交
200 201
/* Replace instructions with better alternatives for this CPU type.
   This runs before SMP is initialized to avoid SMP problems with
L
Lucas De Marchi 已提交
202
   self modifying code. This implies that asymmetric systems where
G
Gerd Hoffmann 已提交
203 204 205
   APs have less capabilities than the boot processor are not handled.
   Tough. Make sure you disable such features by hand. */

206 207
void __init_or_module apply_alternatives(struct alt_instr *start,
					 struct alt_instr *end)
G
Gerd Hoffmann 已提交
208 209
{
	struct alt_instr *a;
210
	u8 insnbuf[MAX_PATCH_LEN];
G
Gerd Hoffmann 已提交
211

212
	DPRINTK("%s: alt table %p -> %p\n", __func__, start, end);
G
Gerd Hoffmann 已提交
213
	for (a = start; a < end; a++) {
214
		u8 *instr = a->instr;
G
Gerd Hoffmann 已提交
215
		BUG_ON(a->replacementlen > a->instrlen);
216
		BUG_ON(a->instrlen > sizeof(insnbuf));
217
		BUG_ON(a->cpuid >= NCAPINTS*32);
G
Gerd Hoffmann 已提交
218 219
		if (!boot_cpu_has(a->cpuid))
			continue;
220 221 222 223 224
#ifdef CONFIG_X86_64
		/* vsyscall code is not mapped yet. resolve it manually. */
		if (instr >= (u8 *)VSYSCALL_START && instr < (u8*)VSYSCALL_END) {
			instr = __va(instr - (u8*)VSYSCALL_START + (u8*)__pa_symbol(&__vsyscall_0));
			DPRINTK("%s: vsyscall fixup: %p => %p\n",
225
				__func__, a->instr, instr);
226 227
		}
#endif
228
		memcpy(insnbuf, a->replacement, a->replacementlen);
229 230
		if (*insnbuf == 0xe8 && a->replacementlen == 5)
		    *(s32 *)(insnbuf + 1) += a->replacement - a->instr;
231 232
		add_nops(insnbuf + a->replacementlen,
			 a->instrlen - a->replacementlen);
233
		text_poke_early(instr, insnbuf, a->instrlen);
G
Gerd Hoffmann 已提交
234 235 236
	}
}

237 238
#ifdef CONFIG_SMP

239 240
static void alternatives_smp_lock(const s32 *start, const s32 *end,
				  u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
241
{
242
	const s32 *poff;
G
Gerd Hoffmann 已提交
243

244
	mutex_lock(&text_mutex);
245 246 247 248
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
249
			continue;
250
		/* turn DS segment override prefix into lock prefix */
251 252
		if (*ptr == 0x3e)
			text_poke(ptr, ((unsigned char []){0xf0}), 1);
G
Gerd Hoffmann 已提交
253
	};
254
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
255 256
}

257 258
static void alternatives_smp_unlock(const s32 *start, const s32 *end,
				    u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
259
{
260
	const s32 *poff;
G
Gerd Hoffmann 已提交
261

262 263 264
	if (noreplace_smp)
		return;

265
	mutex_lock(&text_mutex);
266 267 268 269
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
270
			continue;
271
		/* turn lock prefix into DS segment override prefix */
272 273
		if (*ptr == 0xf0)
			text_poke(ptr, ((unsigned char []){0x3E}), 1);
G
Gerd Hoffmann 已提交
274
	};
275
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
276 277 278 279 280 281 282 283
}

struct smp_alt_module {
	/* what is this ??? */
	struct module	*mod;
	char		*name;

	/* ptrs to lock prefixes */
284 285
	const s32	*locks;
	const s32	*locks_end;
G
Gerd Hoffmann 已提交
286 287 288 289 290 291 292 293

	/* .text segment, needed to avoid patching init code ;) */
	u8		*text;
	u8		*text_end;

	struct list_head next;
};
static LIST_HEAD(smp_alt_modules);
294
static DEFINE_MUTEX(smp_alt);
295
static int smp_mode = 1;	/* protected by smp_alt */
G
Gerd Hoffmann 已提交
296

297 298 299 300
void __init_or_module alternatives_smp_module_add(struct module *mod,
						  char *name,
						  void *locks, void *locks_end,
						  void *text,  void *text_end)
G
Gerd Hoffmann 已提交
301 302 303
{
	struct smp_alt_module *smp;

304 305 306
	if (noreplace_smp)
		return;

G
Gerd Hoffmann 已提交
307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324
	if (smp_alt_once) {
		if (boot_cpu_has(X86_FEATURE_UP))
			alternatives_smp_unlock(locks, locks_end,
						text, text_end);
		return;
	}

	smp = kzalloc(sizeof(*smp), GFP_KERNEL);
	if (NULL == smp)
		return; /* we'll run the (safe but slow) SMP code then ... */

	smp->mod	= mod;
	smp->name	= name;
	smp->locks	= locks;
	smp->locks_end	= locks_end;
	smp->text	= text;
	smp->text_end	= text_end;
	DPRINTK("%s: locks %p -> %p, text %p -> %p, name %s\n",
325
		__func__, smp->locks, smp->locks_end,
G
Gerd Hoffmann 已提交
326 327
		smp->text, smp->text_end, smp->name);

328
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
329 330 331 332
	list_add_tail(&smp->next, &smp_alt_modules);
	if (boot_cpu_has(X86_FEATURE_UP))
		alternatives_smp_unlock(smp->locks, smp->locks_end,
					smp->text, smp->text_end);
333
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
334 335
}

336
void __init_or_module alternatives_smp_module_del(struct module *mod)
G
Gerd Hoffmann 已提交
337 338 339
{
	struct smp_alt_module *item;

340
	if (smp_alt_once || noreplace_smp)
G
Gerd Hoffmann 已提交
341 342
		return;

343
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
344 345 346 347
	list_for_each_entry(item, &smp_alt_modules, next) {
		if (mod != item->mod)
			continue;
		list_del(&item->next);
348
		mutex_unlock(&smp_alt);
349
		DPRINTK("%s: %s\n", __func__, item->name);
G
Gerd Hoffmann 已提交
350 351 352
		kfree(item);
		return;
	}
353
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
354 355
}

356
bool skip_smp_alternatives;
G
Gerd Hoffmann 已提交
357 358 359 360
void alternatives_smp_switch(int smp)
{
	struct smp_alt_module *mod;

361 362
#ifdef CONFIG_LOCKDEP
	/*
363 364 365 366 367
	 * Older binutils section handling bug prevented
	 * alternatives-replacement from working reliably.
	 *
	 * If this still occurs then you should see a hang
	 * or crash shortly after this line:
368
	 */
369
	printk("lockdep: fixing up alternatives.\n");
370 371
#endif

372
	if (noreplace_smp || smp_alt_once || skip_smp_alternatives)
G
Gerd Hoffmann 已提交
373 374 375
		return;
	BUG_ON(!smp && (num_online_cpus() > 1));

376
	mutex_lock(&smp_alt);
377 378 379 380 381 382 383 384

	/*
	 * Avoid unnecessary switches because it forces JIT based VMs to
	 * throw away all cached translations, which can be quite costly.
	 */
	if (smp == smp_mode) {
		/* nothing */
	} else if (smp) {
G
Gerd Hoffmann 已提交
385
		printk(KERN_INFO "SMP alternatives: switching to SMP code\n");
386 387
		clear_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		clear_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
388 389 390 391 392
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_lock(mod->locks, mod->locks_end,
					      mod->text, mod->text_end);
	} else {
		printk(KERN_INFO "SMP alternatives: switching to UP code\n");
393 394
		set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
395 396 397 398
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_unlock(mod->locks, mod->locks_end,
						mod->text, mod->text_end);
	}
399
	smp_mode = smp;
400
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
401 402
}

403 404 405 406
/* Return 1 if the address range is reserved for smp-alternatives */
int alternatives_text_reserved(void *start, void *end)
{
	struct smp_alt_module *mod;
407
	const s32 *poff;
408 409
	u8 *text_start = start;
	u8 *text_end = end;
410 411

	list_for_each_entry(mod, &smp_alt_modules, next) {
412
		if (mod->text > text_end || mod->text_end < text_start)
413
			continue;
414 415 416 417
		for (poff = mod->locks; poff < mod->locks_end; poff++) {
			const u8 *ptr = (const u8 *)poff + *poff;

			if (text_start <= ptr && text_end > ptr)
418
				return 1;
419
		}
420 421 422 423
	}

	return 0;
}
424 425
#endif

426
#ifdef CONFIG_PARAVIRT
427 428
void __init_or_module apply_paravirt(struct paravirt_patch_site *start,
				     struct paravirt_patch_site *end)
429
{
430
	struct paravirt_patch_site *p;
431
	char insnbuf[MAX_PATCH_LEN];
432

433 434 435
	if (noreplace_paravirt)
		return;

436 437 438
	for (p = start; p < end; p++) {
		unsigned int used;

439
		BUG_ON(p->len > MAX_PATCH_LEN);
440 441
		/* prep the buffer with the original instructions */
		memcpy(insnbuf, p->instr, p->len);
442 443
		used = pv_init_ops.patch(p->instrtype, p->clobbers, insnbuf,
					 (unsigned long)p->instr, p->len);
444

445 446
		BUG_ON(used > p->len);

447
		/* Pad the rest with nops */
448
		add_nops(insnbuf + used, p->len - used);
449
		text_poke_early(p->instr, insnbuf, p->len);
450 451
	}
}
452
extern struct paravirt_patch_site __start_parainstructions[],
453 454 455
	__stop_parainstructions[];
#endif	/* CONFIG_PARAVIRT */

G
Gerd Hoffmann 已提交
456 457
void __init alternative_instructions(void)
{
458 459 460 461
	/* The patching is not fully atomic, so try to avoid local interruptions
	   that might execute the to be patched code.
	   Other CPUs are not running. */
	stop_nmi();
462 463 464 465 466 467 468 469 470 471 472

	/*
	 * Don't stop machine check exceptions while patching.
	 * MCEs only happen when something got corrupted and in this
	 * case we must do something about the corruption.
	 * Ignoring it is worse than a unlikely patching race.
	 * Also machine checks tend to be broadcast and if one CPU
	 * goes into machine check the others follow quickly, so we don't
	 * expect a machine check to cause undue problems during to code
	 * patching.
	 */
473

G
Gerd Hoffmann 已提交
474 475 476 477 478 479 480 481 482 483
	apply_alternatives(__alt_instructions, __alt_instructions_end);

	/* switch to patch-once-at-boottime-only mode and free the
	 * tables in case we know the number of CPUs will never ever
	 * change */
#ifdef CONFIG_HOTPLUG_CPU
	if (num_possible_cpus() < 2)
		smp_alt_once = 1;
#endif

484
#ifdef CONFIG_SMP
G
Gerd Hoffmann 已提交
485 486 487
	if (smp_alt_once) {
		if (1 == num_possible_cpus()) {
			printk(KERN_INFO "SMP alternatives: switching to UP code\n");
488 489 490
			set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
			set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);

G
Gerd Hoffmann 已提交
491 492 493 494 495 496 497
			alternatives_smp_unlock(__smp_locks, __smp_locks_end,
						_text, _etext);
		}
	} else {
		alternatives_smp_module_add(NULL, "core kernel",
					    __smp_locks, __smp_locks_end,
					    _text, _etext);
498 499

		/* Only switch to UP mode if we don't immediately boot others */
500
		if (num_present_cpus() == 1 || setup_max_cpus <= 1)
501
			alternatives_smp_switch(0);
G
Gerd Hoffmann 已提交
502
	}
503
#endif
504
 	apply_paravirt(__parainstructions, __parainstructions_end);
505

506 507 508 509 510
	if (smp_alt_once)
		free_init_pages("SMP alternatives",
				(unsigned long)__smp_locks,
				(unsigned long)__smp_locks_end);

511
	restart_nmi();
G
Gerd Hoffmann 已提交
512
}
513

514 515 516 517 518 519
/**
 * text_poke_early - Update instructions on a live kernel at boot time
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
520 521
 * When you use this code to patch more than one byte of an instruction
 * you need to make sure that other CPUs cannot execute this code in parallel.
522 523 524
 * Also no thread must be currently preempted in the middle of these
 * instructions. And on the local CPU you need to be protected again NMI or MCE
 * handlers seeing an inconsistent instruction while you patch.
525
 */
526
void *__init_or_module text_poke_early(void *addr, const void *opcode,
527
					      size_t len)
528
{
529 530
	unsigned long flags;
	local_irq_save(flags);
531
	memcpy(addr, opcode, len);
532
	sync_core();
533
	local_irq_restore(flags);
534 535 536 537 538 539 540 541 542 543 544 545 546 547 548
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
	return addr;
}

/**
 * text_poke - Update instructions on a live kernel
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Only atomic text poke/set should be allowed when not doing early patching.
 * It means the size must be writable atomically and the address must be aligned
 * in a way that permits an atomic write. It also makes sure we fit on a single
 * page.
549 550
 *
 * Note: Must be called under text_mutex.
551 552 553
 */
void *__kprobes text_poke(void *addr, const void *opcode, size_t len)
{
554
	unsigned long flags;
555
	char *vaddr;
M
Mathieu Desnoyers 已提交
556 557
	struct page *pages[2];
	int i;
558

M
Mathieu Desnoyers 已提交
559 560 561
	if (!core_kernel_text((unsigned long)addr)) {
		pages[0] = vmalloc_to_page(addr);
		pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
562
	} else {
M
Mathieu Desnoyers 已提交
563
		pages[0] = virt_to_page(addr);
I
Ingo Molnar 已提交
564
		WARN_ON(!PageReserved(pages[0]));
M
Mathieu Desnoyers 已提交
565
		pages[1] = virt_to_page(addr + PAGE_SIZE);
566
	}
M
Mathieu Desnoyers 已提交
567
	BUG_ON(!pages[0]);
568
	local_irq_save(flags);
569 570 571 572
	set_fixmap(FIX_TEXT_POKE0, page_to_phys(pages[0]));
	if (pages[1])
		set_fixmap(FIX_TEXT_POKE1, page_to_phys(pages[1]));
	vaddr = (char *)fix_to_virt(FIX_TEXT_POKE0);
M
Mathieu Desnoyers 已提交
573
	memcpy(&vaddr[(unsigned long)addr & ~PAGE_MASK], opcode, len);
574 575 576 577
	clear_fixmap(FIX_TEXT_POKE0);
	if (pages[1])
		clear_fixmap(FIX_TEXT_POKE1);
	local_flush_tlb();
578
	sync_core();
579 580
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
M
Mathieu Desnoyers 已提交
581 582
	for (i = 0; i < len; i++)
		BUG_ON(((char *)addr)[i] != ((char *)opcode)[i]);
583
	local_irq_restore(flags);
584
	return addr;
585
}
586 587 588 589 590 591 592 593 594

/*
 * Cross-modifying kernel text with stop_machine().
 * This code originally comes from immediate value.
 */
static atomic_t stop_machine_first;
static int wrote_text;

struct text_poke_params {
595 596
	struct text_poke_param *params;
	int nparams;
597 598 599 600 601
};

static int __kprobes stop_machine_text_poke(void *data)
{
	struct text_poke_params *tpp = data;
602 603
	struct text_poke_param *p;
	int i;
604 605

	if (atomic_dec_and_test(&stop_machine_first)) {
606 607 608 609
		for (i = 0; i < tpp->nparams; i++) {
			p = &tpp->params[i];
			text_poke(p->addr, p->opcode, p->len);
		}
610 611 612 613
		smp_wmb();	/* Make sure other cpus see that this has run */
		wrote_text = 1;
	} else {
		while (!wrote_text)
614 615
			cpu_relax();
		smp_mb();	/* Load wrote_text before following execution */
616 617
	}

618 619 620 621 622
	for (i = 0; i < tpp->nparams; i++) {
		p = &tpp->params[i];
		flush_icache_range((unsigned long)p->addr,
				   (unsigned long)p->addr + p->len);
	}
623 624 625 626 627 628
	/*
	 * Intel Archiecture Software Developer's Manual section 7.1.3 specifies
	 * that a core serializing instruction such as "cpuid" should be
	 * executed on _each_ core before the new instruction is made visible.
	 */
	sync_core();
629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647
	return 0;
}

/**
 * text_poke_smp - Update instructions on a live kernel on SMP
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. This allows
 * user to poke/set multi-byte text on SMP. Only non-NMI/MCE code modifying
 * should be allowed, since stop_machine() does _not_ protect code against
 * NMI and MCE.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void *__kprobes text_poke_smp(void *addr, const void *opcode, size_t len)
{
	struct text_poke_params tpp;
648
	struct text_poke_param p;
649

650 651 652 653 654
	p.addr = addr;
	p.opcode = opcode;
	p.len = len;
	tpp.params = &p;
	tpp.nparams = 1;
655 656
	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
657
	/* Use __stop_machine() because the caller already got online_cpus. */
658
	__stop_machine(stop_machine_text_poke, (void *)&tpp, cpu_online_mask);
659 660 661
	return addr;
}

662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678
/**
 * text_poke_smp_batch - Update instructions on a live kernel on SMP
 * @params: an array of text_poke parameters
 * @n: the number of elements in params.
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. Since the
 * stop_machine() is heavy task, it is better to aggregate text_poke requests
 * and do it once if possible.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void __kprobes text_poke_smp_batch(struct text_poke_param *params, int n)
{
	struct text_poke_params tpp = {.params = params, .nparams = n};

	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
679
	__stop_machine(stop_machine_text_poke, (void *)&tpp, NULL);
680 681
}

682
#if defined(CONFIG_DYNAMIC_FTRACE) || defined(HAVE_JUMP_LABEL)
683

684 685 686 687 688
#ifdef CONFIG_X86_64
unsigned char ideal_nop5[5] = { 0x66, 0x66, 0x66, 0x66, 0x90 };
#else
unsigned char ideal_nop5[5] = { 0x3e, 0x8d, 0x74, 0x26, 0x00 };
#endif
689 690 691 692

void __init arch_init_ideal_nop5(void)
{
	/*
693 694 695
	 * There is no good nop for all x86 archs.  This selection
	 * algorithm should be unified with the one in find_nop_table(),
	 * but this should be good enough for now.
696
	 *
697 698
	 * For cases other than the ones below, use the safe (as in
	 * always functional) defaults above.
699
	 */
700 701 702 703 704
#ifdef CONFIG_X86_64
	/* Don't use these on 32 bits due to broken virtualizers */
	if (boot_cpu_data.x86_vendor == X86_VENDOR_INTEL)
		memcpy(ideal_nop5, p6_nops[5], 5);
#endif
705 706
}
#endif