alternative.c 18.9 KB
Newer Older
G
Gerd Hoffmann 已提交
1
#include <linux/module.h>
A
Al Viro 已提交
2
#include <linux/sched.h>
3
#include <linux/mutex.h>
G
Gerd Hoffmann 已提交
4
#include <linux/list.h>
5
#include <linux/stringify.h>
6 7 8
#include <linux/kprobes.h>
#include <linux/mm.h>
#include <linux/vmalloc.h>
9
#include <linux/memory.h>
10
#include <linux/stop_machine.h>
11
#include <linux/slab.h>
G
Gerd Hoffmann 已提交
12 13
#include <asm/alternative.h>
#include <asm/sections.h>
14
#include <asm/pgtable.h>
15 16
#include <asm/mce.h>
#include <asm/nmi.h>
D
Dave Jones 已提交
17
#include <asm/vsyscall.h>
18
#include <asm/cacheflush.h>
19
#include <asm/tlbflush.h>
20
#include <asm/io.h>
21
#include <asm/fixmap.h>
G
Gerd Hoffmann 已提交
22

23 24
#define MAX_PATCH_LEN (255-1)

25 26
#ifdef CONFIG_HOTPLUG_CPU
static int smp_alt_once;
G
Gerd Hoffmann 已提交
27

28 29 30 31 32
static int __init bootonly(char *str)
{
	smp_alt_once = 1;
	return 1;
}
33
__setup("smp-alt-boot", bootonly);
34 35 36 37
#else
#define smp_alt_once 1
#endif

38
static int __initdata_or_module debug_alternative;
39

40 41 42 43 44 45 46
static int __init debug_alt(char *str)
{
	debug_alternative = 1;
	return 1;
}
__setup("debug-alternative", debug_alt);

47 48
static int noreplace_smp;

49 50 51 52 53 54 55
static int __init setup_noreplace_smp(char *str)
{
	noreplace_smp = 1;
	return 1;
}
__setup("noreplace-smp", setup_noreplace_smp);

56
#ifdef CONFIG_PARAVIRT
57
static int __initdata_or_module noreplace_paravirt = 0;
58 59 60 61 62 63 64 65

static int __init setup_noreplace_paravirt(char *str)
{
	noreplace_paravirt = 1;
	return 1;
}
__setup("noreplace-paravirt", setup_noreplace_paravirt);
#endif
66

67 68 69
#define DPRINTK(fmt, args...) if (debug_alternative) \
	printk(KERN_DEBUG fmt, args)

70 71 72 73 74 75 76 77 78
/*
 * Each GENERIC_NOPX is of X bytes, and defined as an array of bytes
 * that correspond to that nop. Getting from one nop to the next, we
 * add to the array the offset that is equal to the sum of all sizes of
 * nops preceding the one we are after.
 *
 * Note: The GENERIC_NOP5_ATOMIC is at the end, as it breaks the
 * nice symmetry of sizes of the previous nops.
 */
79
#if defined(GENERIC_NOP1) && !defined(CONFIG_X86_64)
80 81 82 83 84 85 86 87 88 89 90 91 92 93
static const unsigned char intelnops[] =
{
	GENERIC_NOP1,
	GENERIC_NOP2,
	GENERIC_NOP3,
	GENERIC_NOP4,
	GENERIC_NOP5,
	GENERIC_NOP6,
	GENERIC_NOP7,
	GENERIC_NOP8,
	GENERIC_NOP5_ATOMIC
};
static const unsigned char * const intel_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
94 95 96 97 98 99 100 101 102
	NULL,
	intelnops,
	intelnops + 1,
	intelnops + 1 + 2,
	intelnops + 1 + 2 + 3,
	intelnops + 1 + 2 + 3 + 4,
	intelnops + 1 + 2 + 3 + 4 + 5,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
103
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
104
};
105 106 107
#endif

#ifdef K8_NOP1
108 109 110 111 112 113 114 115 116 117 118 119 120 121
static const unsigned char k8nops[] =
{
	K8_NOP1,
	K8_NOP2,
	K8_NOP3,
	K8_NOP4,
	K8_NOP5,
	K8_NOP6,
	K8_NOP7,
	K8_NOP8,
	K8_NOP5_ATOMIC
};
static const unsigned char * const k8_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
122 123 124 125 126 127 128 129 130
	NULL,
	k8nops,
	k8nops + 1,
	k8nops + 1 + 2,
	k8nops + 1 + 2 + 3,
	k8nops + 1 + 2 + 3 + 4,
	k8nops + 1 + 2 + 3 + 4 + 5,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
131
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
132
};
133 134
#endif

135
#if defined(K7_NOP1) && !defined(CONFIG_X86_64)
136 137 138 139 140 141 142 143 144 145 146 147 148 149
static const unsigned char k7nops[] =
{
	K7_NOP1,
	K7_NOP2,
	K7_NOP3,
	K7_NOP4,
	K7_NOP5,
	K7_NOP6,
	K7_NOP7,
	K7_NOP8,
	K7_NOP5_ATOMIC
};
static const unsigned char * const k7_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
150 151 152 153 154 155 156 157 158
	NULL,
	k7nops,
	k7nops + 1,
	k7nops + 1 + 2,
	k7nops + 1 + 2 + 3,
	k7nops + 1 + 2 + 3 + 4,
	k7nops + 1 + 2 + 3 + 4 + 5,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
159
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
160
};
161 162
#endif

163
#ifdef P6_NOP1
164 165 166 167 168 169 170 171 172 173 174 175 176 177
static const unsigned char  __initconst_or_module p6nops[] =
{
	P6_NOP1,
	P6_NOP2,
	P6_NOP3,
	P6_NOP4,
	P6_NOP5,
	P6_NOP6,
	P6_NOP7,
	P6_NOP8,
	P6_NOP5_ATOMIC
};
static const unsigned char * const p6_nops[ASM_NOP_MAX+2] =
{
178 179 180 181 182 183 184 185 186
	NULL,
	p6nops,
	p6nops + 1,
	p6nops + 1 + 2,
	p6nops + 1 + 2 + 3,
	p6nops + 1 + 2 + 3 + 4,
	p6nops + 1 + 2 + 3 + 4 + 5,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
187
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
188 189 190
};
#endif

191
/* Initialize these to a safe default */
192
#ifdef CONFIG_X86_64
193 194 195 196
const unsigned char * const *ideal_nops = p6_nops;
#else
const unsigned char * const *ideal_nops = intel_nops;
#endif
197

198
void __init arch_init_ideal_nops(void)
199
{
200 201
	switch (boot_cpu_data.x86_vendor) {
	case X86_VENDOR_INTEL:
202 203 204 205 206 207 208 209 210 211 212 213 214
		/*
		 * Due to a decoder implementation quirk, some
		 * specific Intel CPUs actually perform better with
		 * the "k8_nops" than with the SDM-recommended NOPs.
		 */
		if (boot_cpu_data.x86 == 6 &&
		    boot_cpu_data.x86_model >= 0x0f &&
		    boot_cpu_data.x86_model != 0x1c &&
		    boot_cpu_data.x86_model != 0x26 &&
		    boot_cpu_data.x86_model != 0x27 &&
		    boot_cpu_data.x86_model < 0x30) {
			ideal_nops = k8_nops;
		} else if (boot_cpu_has(X86_FEATURE_NOPL)) {
215 216 217 218 219 220 221 222
			   ideal_nops = p6_nops;
		} else {
#ifdef CONFIG_X86_64
			ideal_nops = k8_nops;
#else
			ideal_nops = intel_nops;
#endif
		}
223

224 225 226 227 228 229 230 231 232 233 234 235
	default:
#ifdef CONFIG_X86_64
		ideal_nops = k8_nops;
#else
		if (boot_cpu_has(X86_FEATURE_K8))
			ideal_nops = k8_nops;
		else if (boot_cpu_has(X86_FEATURE_K7))
			ideal_nops = k7_nops;
		else
			ideal_nops = intel_nops;
#endif
	}
G
Gerd Hoffmann 已提交
236 237
}

238
/* Use this to add nops to a buffer, then text_poke the whole buffer. */
239
static void __init_or_module add_nops(void *insns, unsigned int len)
240 241 242 243 244
{
	while (len > 0) {
		unsigned int noplen = len;
		if (noplen > ASM_NOP_MAX)
			noplen = ASM_NOP_MAX;
245
		memcpy(insns, ideal_nops[noplen], noplen);
246 247 248 249 250
		insns += noplen;
		len -= noplen;
	}
}

251
extern struct alt_instr __alt_instructions[], __alt_instructions_end[];
252
extern s32 __smp_locks[], __smp_locks_end[];
253
extern char __vsyscall_0;
254
void *text_poke_early(void *addr, const void *opcode, size_t len);
255

G
Gerd Hoffmann 已提交
256 257
/* Replace instructions with better alternatives for this CPU type.
   This runs before SMP is initialized to avoid SMP problems with
L
Lucas De Marchi 已提交
258
   self modifying code. This implies that asymmetric systems where
G
Gerd Hoffmann 已提交
259 260 261
   APs have less capabilities than the boot processor are not handled.
   Tough. Make sure you disable such features by hand. */

262 263
void __init_or_module apply_alternatives(struct alt_instr *start,
					 struct alt_instr *end)
G
Gerd Hoffmann 已提交
264 265
{
	struct alt_instr *a;
266
	u8 insnbuf[MAX_PATCH_LEN];
G
Gerd Hoffmann 已提交
267

268
	DPRINTK("%s: alt table %p -> %p\n", __func__, start, end);
269 270 271 272 273 274 275 276 277
	/*
	 * The scan order should be from start to end. A later scanned
	 * alternative code can overwrite a previous scanned alternative code.
	 * Some kernel functions (e.g. memcpy, memset, etc) use this order to
	 * patch code.
	 *
	 * So be careful if you want to change the scan order to any other
	 * order.
	 */
G
Gerd Hoffmann 已提交
278
	for (a = start; a < end; a++) {
279
		u8 *instr = a->instr;
G
Gerd Hoffmann 已提交
280
		BUG_ON(a->replacementlen > a->instrlen);
281
		BUG_ON(a->instrlen > sizeof(insnbuf));
282
		BUG_ON(a->cpuid >= NCAPINTS*32);
G
Gerd Hoffmann 已提交
283 284
		if (!boot_cpu_has(a->cpuid))
			continue;
285 286 287 288 289
#ifdef CONFIG_X86_64
		/* vsyscall code is not mapped yet. resolve it manually. */
		if (instr >= (u8 *)VSYSCALL_START && instr < (u8*)VSYSCALL_END) {
			instr = __va(instr - (u8*)VSYSCALL_START + (u8*)__pa_symbol(&__vsyscall_0));
			DPRINTK("%s: vsyscall fixup: %p => %p\n",
290
				__func__, a->instr, instr);
291 292
		}
#endif
293
		memcpy(insnbuf, a->replacement, a->replacementlen);
294 295
		if (*insnbuf == 0xe8 && a->replacementlen == 5)
		    *(s32 *)(insnbuf + 1) += a->replacement - a->instr;
296 297
		add_nops(insnbuf + a->replacementlen,
			 a->instrlen - a->replacementlen);
298
		text_poke_early(instr, insnbuf, a->instrlen);
G
Gerd Hoffmann 已提交
299 300 301
	}
}

302 303
#ifdef CONFIG_SMP

304 305
static void alternatives_smp_lock(const s32 *start, const s32 *end,
				  u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
306
{
307
	const s32 *poff;
G
Gerd Hoffmann 已提交
308

309
	mutex_lock(&text_mutex);
310 311 312 313
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
314
			continue;
315
		/* turn DS segment override prefix into lock prefix */
316 317
		if (*ptr == 0x3e)
			text_poke(ptr, ((unsigned char []){0xf0}), 1);
G
Gerd Hoffmann 已提交
318
	};
319
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
320 321
}

322 323
static void alternatives_smp_unlock(const s32 *start, const s32 *end,
				    u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
324
{
325
	const s32 *poff;
G
Gerd Hoffmann 已提交
326

327 328 329
	if (noreplace_smp)
		return;

330
	mutex_lock(&text_mutex);
331 332 333 334
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
335
			continue;
336
		/* turn lock prefix into DS segment override prefix */
337 338
		if (*ptr == 0xf0)
			text_poke(ptr, ((unsigned char []){0x3E}), 1);
G
Gerd Hoffmann 已提交
339
	};
340
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
341 342 343 344 345 346 347 348
}

struct smp_alt_module {
	/* what is this ??? */
	struct module	*mod;
	char		*name;

	/* ptrs to lock prefixes */
349 350
	const s32	*locks;
	const s32	*locks_end;
G
Gerd Hoffmann 已提交
351 352 353 354 355 356 357 358

	/* .text segment, needed to avoid patching init code ;) */
	u8		*text;
	u8		*text_end;

	struct list_head next;
};
static LIST_HEAD(smp_alt_modules);
359
static DEFINE_MUTEX(smp_alt);
360
static int smp_mode = 1;	/* protected by smp_alt */
G
Gerd Hoffmann 已提交
361

362 363 364 365
void __init_or_module alternatives_smp_module_add(struct module *mod,
						  char *name,
						  void *locks, void *locks_end,
						  void *text,  void *text_end)
G
Gerd Hoffmann 已提交
366 367 368
{
	struct smp_alt_module *smp;

369 370 371
	if (noreplace_smp)
		return;

G
Gerd Hoffmann 已提交
372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389
	if (smp_alt_once) {
		if (boot_cpu_has(X86_FEATURE_UP))
			alternatives_smp_unlock(locks, locks_end,
						text, text_end);
		return;
	}

	smp = kzalloc(sizeof(*smp), GFP_KERNEL);
	if (NULL == smp)
		return; /* we'll run the (safe but slow) SMP code then ... */

	smp->mod	= mod;
	smp->name	= name;
	smp->locks	= locks;
	smp->locks_end	= locks_end;
	smp->text	= text;
	smp->text_end	= text_end;
	DPRINTK("%s: locks %p -> %p, text %p -> %p, name %s\n",
390
		__func__, smp->locks, smp->locks_end,
G
Gerd Hoffmann 已提交
391 392
		smp->text, smp->text_end, smp->name);

393
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
394 395 396 397
	list_add_tail(&smp->next, &smp_alt_modules);
	if (boot_cpu_has(X86_FEATURE_UP))
		alternatives_smp_unlock(smp->locks, smp->locks_end,
					smp->text, smp->text_end);
398
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
399 400
}

401
void __init_or_module alternatives_smp_module_del(struct module *mod)
G
Gerd Hoffmann 已提交
402 403 404
{
	struct smp_alt_module *item;

405
	if (smp_alt_once || noreplace_smp)
G
Gerd Hoffmann 已提交
406 407
		return;

408
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
409 410 411 412
	list_for_each_entry(item, &smp_alt_modules, next) {
		if (mod != item->mod)
			continue;
		list_del(&item->next);
413
		mutex_unlock(&smp_alt);
414
		DPRINTK("%s: %s\n", __func__, item->name);
G
Gerd Hoffmann 已提交
415 416 417
		kfree(item);
		return;
	}
418
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
419 420
}

421
bool skip_smp_alternatives;
G
Gerd Hoffmann 已提交
422 423 424 425
void alternatives_smp_switch(int smp)
{
	struct smp_alt_module *mod;

426 427
#ifdef CONFIG_LOCKDEP
	/*
428 429 430 431 432
	 * Older binutils section handling bug prevented
	 * alternatives-replacement from working reliably.
	 *
	 * If this still occurs then you should see a hang
	 * or crash shortly after this line:
433
	 */
434
	printk("lockdep: fixing up alternatives.\n");
435 436
#endif

437
	if (noreplace_smp || smp_alt_once || skip_smp_alternatives)
G
Gerd Hoffmann 已提交
438 439 440
		return;
	BUG_ON(!smp && (num_online_cpus() > 1));

441
	mutex_lock(&smp_alt);
442 443 444 445 446 447 448 449

	/*
	 * Avoid unnecessary switches because it forces JIT based VMs to
	 * throw away all cached translations, which can be quite costly.
	 */
	if (smp == smp_mode) {
		/* nothing */
	} else if (smp) {
G
Gerd Hoffmann 已提交
450
		printk(KERN_INFO "SMP alternatives: switching to SMP code\n");
451 452
		clear_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		clear_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
453 454 455 456 457
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_lock(mod->locks, mod->locks_end,
					      mod->text, mod->text_end);
	} else {
		printk(KERN_INFO "SMP alternatives: switching to UP code\n");
458 459
		set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
460 461 462 463
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_unlock(mod->locks, mod->locks_end,
						mod->text, mod->text_end);
	}
464
	smp_mode = smp;
465
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
466 467
}

468 469 470 471
/* Return 1 if the address range is reserved for smp-alternatives */
int alternatives_text_reserved(void *start, void *end)
{
	struct smp_alt_module *mod;
472
	const s32 *poff;
473 474
	u8 *text_start = start;
	u8 *text_end = end;
475 476

	list_for_each_entry(mod, &smp_alt_modules, next) {
477
		if (mod->text > text_end || mod->text_end < text_start)
478
			continue;
479 480 481 482
		for (poff = mod->locks; poff < mod->locks_end; poff++) {
			const u8 *ptr = (const u8 *)poff + *poff;

			if (text_start <= ptr && text_end > ptr)
483
				return 1;
484
		}
485 486 487 488
	}

	return 0;
}
489 490
#endif

491
#ifdef CONFIG_PARAVIRT
492 493
void __init_or_module apply_paravirt(struct paravirt_patch_site *start,
				     struct paravirt_patch_site *end)
494
{
495
	struct paravirt_patch_site *p;
496
	char insnbuf[MAX_PATCH_LEN];
497

498 499 500
	if (noreplace_paravirt)
		return;

501 502 503
	for (p = start; p < end; p++) {
		unsigned int used;

504
		BUG_ON(p->len > MAX_PATCH_LEN);
505 506
		/* prep the buffer with the original instructions */
		memcpy(insnbuf, p->instr, p->len);
507 508
		used = pv_init_ops.patch(p->instrtype, p->clobbers, insnbuf,
					 (unsigned long)p->instr, p->len);
509

510 511
		BUG_ON(used > p->len);

512
		/* Pad the rest with nops */
513
		add_nops(insnbuf + used, p->len - used);
514
		text_poke_early(p->instr, insnbuf, p->len);
515 516
	}
}
517
extern struct paravirt_patch_site __start_parainstructions[],
518 519 520
	__stop_parainstructions[];
#endif	/* CONFIG_PARAVIRT */

G
Gerd Hoffmann 已提交
521 522
void __init alternative_instructions(void)
{
523 524 525 526
	/* The patching is not fully atomic, so try to avoid local interruptions
	   that might execute the to be patched code.
	   Other CPUs are not running. */
	stop_nmi();
527 528 529 530 531 532 533 534 535 536 537

	/*
	 * Don't stop machine check exceptions while patching.
	 * MCEs only happen when something got corrupted and in this
	 * case we must do something about the corruption.
	 * Ignoring it is worse than a unlikely patching race.
	 * Also machine checks tend to be broadcast and if one CPU
	 * goes into machine check the others follow quickly, so we don't
	 * expect a machine check to cause undue problems during to code
	 * patching.
	 */
538

G
Gerd Hoffmann 已提交
539 540 541 542 543 544 545 546 547 548
	apply_alternatives(__alt_instructions, __alt_instructions_end);

	/* switch to patch-once-at-boottime-only mode and free the
	 * tables in case we know the number of CPUs will never ever
	 * change */
#ifdef CONFIG_HOTPLUG_CPU
	if (num_possible_cpus() < 2)
		smp_alt_once = 1;
#endif

549
#ifdef CONFIG_SMP
G
Gerd Hoffmann 已提交
550 551 552
	if (smp_alt_once) {
		if (1 == num_possible_cpus()) {
			printk(KERN_INFO "SMP alternatives: switching to UP code\n");
553 554 555
			set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
			set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);

G
Gerd Hoffmann 已提交
556 557 558 559 560 561 562
			alternatives_smp_unlock(__smp_locks, __smp_locks_end,
						_text, _etext);
		}
	} else {
		alternatives_smp_module_add(NULL, "core kernel",
					    __smp_locks, __smp_locks_end,
					    _text, _etext);
563 564

		/* Only switch to UP mode if we don't immediately boot others */
565
		if (num_present_cpus() == 1 || setup_max_cpus <= 1)
566
			alternatives_smp_switch(0);
G
Gerd Hoffmann 已提交
567
	}
568
#endif
569
 	apply_paravirt(__parainstructions, __parainstructions_end);
570

571 572 573 574 575
	if (smp_alt_once)
		free_init_pages("SMP alternatives",
				(unsigned long)__smp_locks,
				(unsigned long)__smp_locks_end);

576
	restart_nmi();
G
Gerd Hoffmann 已提交
577
}
578

579 580 581 582 583 584
/**
 * text_poke_early - Update instructions on a live kernel at boot time
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
585 586
 * When you use this code to patch more than one byte of an instruction
 * you need to make sure that other CPUs cannot execute this code in parallel.
587 588 589
 * Also no thread must be currently preempted in the middle of these
 * instructions. And on the local CPU you need to be protected again NMI or MCE
 * handlers seeing an inconsistent instruction while you patch.
590
 */
591
void *__init_or_module text_poke_early(void *addr, const void *opcode,
592
					      size_t len)
593
{
594 595
	unsigned long flags;
	local_irq_save(flags);
596
	memcpy(addr, opcode, len);
597
	sync_core();
598
	local_irq_restore(flags);
599 600 601 602 603 604 605 606 607 608 609 610 611 612 613
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
	return addr;
}

/**
 * text_poke - Update instructions on a live kernel
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Only atomic text poke/set should be allowed when not doing early patching.
 * It means the size must be writable atomically and the address must be aligned
 * in a way that permits an atomic write. It also makes sure we fit on a single
 * page.
614 615
 *
 * Note: Must be called under text_mutex.
616 617 618
 */
void *__kprobes text_poke(void *addr, const void *opcode, size_t len)
{
619
	unsigned long flags;
620
	char *vaddr;
M
Mathieu Desnoyers 已提交
621 622
	struct page *pages[2];
	int i;
623

M
Mathieu Desnoyers 已提交
624 625 626
	if (!core_kernel_text((unsigned long)addr)) {
		pages[0] = vmalloc_to_page(addr);
		pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
627
	} else {
M
Mathieu Desnoyers 已提交
628
		pages[0] = virt_to_page(addr);
I
Ingo Molnar 已提交
629
		WARN_ON(!PageReserved(pages[0]));
M
Mathieu Desnoyers 已提交
630
		pages[1] = virt_to_page(addr + PAGE_SIZE);
631
	}
M
Mathieu Desnoyers 已提交
632
	BUG_ON(!pages[0]);
633
	local_irq_save(flags);
634 635 636 637
	set_fixmap(FIX_TEXT_POKE0, page_to_phys(pages[0]));
	if (pages[1])
		set_fixmap(FIX_TEXT_POKE1, page_to_phys(pages[1]));
	vaddr = (char *)fix_to_virt(FIX_TEXT_POKE0);
M
Mathieu Desnoyers 已提交
638
	memcpy(&vaddr[(unsigned long)addr & ~PAGE_MASK], opcode, len);
639 640 641 642
	clear_fixmap(FIX_TEXT_POKE0);
	if (pages[1])
		clear_fixmap(FIX_TEXT_POKE1);
	local_flush_tlb();
643
	sync_core();
644 645
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
M
Mathieu Desnoyers 已提交
646 647
	for (i = 0; i < len; i++)
		BUG_ON(((char *)addr)[i] != ((char *)opcode)[i]);
648
	local_irq_restore(flags);
649
	return addr;
650
}
651 652 653 654 655 656 657 658 659

/*
 * Cross-modifying kernel text with stop_machine().
 * This code originally comes from immediate value.
 */
static atomic_t stop_machine_first;
static int wrote_text;

struct text_poke_params {
660 661
	struct text_poke_param *params;
	int nparams;
662 663 664 665 666
};

static int __kprobes stop_machine_text_poke(void *data)
{
	struct text_poke_params *tpp = data;
667 668
	struct text_poke_param *p;
	int i;
669 670

	if (atomic_dec_and_test(&stop_machine_first)) {
671 672 673 674
		for (i = 0; i < tpp->nparams; i++) {
			p = &tpp->params[i];
			text_poke(p->addr, p->opcode, p->len);
		}
675 676 677 678
		smp_wmb();	/* Make sure other cpus see that this has run */
		wrote_text = 1;
	} else {
		while (!wrote_text)
679 680
			cpu_relax();
		smp_mb();	/* Load wrote_text before following execution */
681 682
	}

683 684 685 686 687
	for (i = 0; i < tpp->nparams; i++) {
		p = &tpp->params[i];
		flush_icache_range((unsigned long)p->addr,
				   (unsigned long)p->addr + p->len);
	}
688 689 690 691 692 693
	/*
	 * Intel Archiecture Software Developer's Manual section 7.1.3 specifies
	 * that a core serializing instruction such as "cpuid" should be
	 * executed on _each_ core before the new instruction is made visible.
	 */
	sync_core();
694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712
	return 0;
}

/**
 * text_poke_smp - Update instructions on a live kernel on SMP
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. This allows
 * user to poke/set multi-byte text on SMP. Only non-NMI/MCE code modifying
 * should be allowed, since stop_machine() does _not_ protect code against
 * NMI and MCE.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void *__kprobes text_poke_smp(void *addr, const void *opcode, size_t len)
{
	struct text_poke_params tpp;
713
	struct text_poke_param p;
714

715 716 717 718 719
	p.addr = addr;
	p.opcode = opcode;
	p.len = len;
	tpp.params = &p;
	tpp.nparams = 1;
720 721
	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
722
	/* Use __stop_machine() because the caller already got online_cpus. */
723
	__stop_machine(stop_machine_text_poke, (void *)&tpp, cpu_online_mask);
724 725 726
	return addr;
}

727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743
/**
 * text_poke_smp_batch - Update instructions on a live kernel on SMP
 * @params: an array of text_poke parameters
 * @n: the number of elements in params.
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. Since the
 * stop_machine() is heavy task, it is better to aggregate text_poke requests
 * and do it once if possible.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void __kprobes text_poke_smp_batch(struct text_poke_param *params, int n)
{
	struct text_poke_params tpp = {.params = params, .nparams = n};

	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
744
	__stop_machine(stop_machine_text_poke, (void *)&tpp, NULL);
745
}