alternative.c 18.2 KB
Newer Older
G
Gerd Hoffmann 已提交
1
#include <linux/module.h>
A
Al Viro 已提交
2
#include <linux/sched.h>
3
#include <linux/mutex.h>
G
Gerd Hoffmann 已提交
4
#include <linux/list.h>
5
#include <linux/stringify.h>
6 7 8
#include <linux/kprobes.h>
#include <linux/mm.h>
#include <linux/vmalloc.h>
9
#include <linux/memory.h>
10
#include <linux/stop_machine.h>
11
#include <linux/slab.h>
G
Gerd Hoffmann 已提交
12 13
#include <asm/alternative.h>
#include <asm/sections.h>
14
#include <asm/pgtable.h>
15 16
#include <asm/mce.h>
#include <asm/nmi.h>
D
Dave Jones 已提交
17
#include <asm/vsyscall.h>
18
#include <asm/cacheflush.h>
19
#include <asm/tlbflush.h>
20
#include <asm/io.h>
21
#include <asm/fixmap.h>
G
Gerd Hoffmann 已提交
22

23 24
#define MAX_PATCH_LEN (255-1)

25 26
#ifdef CONFIG_HOTPLUG_CPU
static int smp_alt_once;
G
Gerd Hoffmann 已提交
27

28 29 30 31 32
static int __init bootonly(char *str)
{
	smp_alt_once = 1;
	return 1;
}
33
__setup("smp-alt-boot", bootonly);
34 35 36 37
#else
#define smp_alt_once 1
#endif

38
static int __initdata_or_module debug_alternative;
39

40 41 42 43 44 45 46
static int __init debug_alt(char *str)
{
	debug_alternative = 1;
	return 1;
}
__setup("debug-alternative", debug_alt);

47 48
static int noreplace_smp;

49 50 51 52 53 54 55
static int __init setup_noreplace_smp(char *str)
{
	noreplace_smp = 1;
	return 1;
}
__setup("noreplace-smp", setup_noreplace_smp);

56
#ifdef CONFIG_PARAVIRT
57
static int __initdata_or_module noreplace_paravirt = 0;
58 59 60 61 62 63 64 65

static int __init setup_noreplace_paravirt(char *str)
{
	noreplace_paravirt = 1;
	return 1;
}
__setup("noreplace-paravirt", setup_noreplace_paravirt);
#endif
66

67 68 69
#define DPRINTK(fmt, args...) if (debug_alternative) \
	printk(KERN_DEBUG fmt, args)

70 71 72 73 74 75 76 77 78
/*
 * Each GENERIC_NOPX is of X bytes, and defined as an array of bytes
 * that correspond to that nop. Getting from one nop to the next, we
 * add to the array the offset that is equal to the sum of all sizes of
 * nops preceding the one we are after.
 *
 * Note: The GENERIC_NOP5_ATOMIC is at the end, as it breaks the
 * nice symmetry of sizes of the previous nops.
 */
79
#if defined(GENERIC_NOP1) && !defined(CONFIG_X86_64)
80 81 82 83 84 85 86 87 88 89 90 91 92 93
static const unsigned char intelnops[] =
{
	GENERIC_NOP1,
	GENERIC_NOP2,
	GENERIC_NOP3,
	GENERIC_NOP4,
	GENERIC_NOP5,
	GENERIC_NOP6,
	GENERIC_NOP7,
	GENERIC_NOP8,
	GENERIC_NOP5_ATOMIC
};
static const unsigned char * const intel_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
94 95 96 97 98 99 100 101 102
	NULL,
	intelnops,
	intelnops + 1,
	intelnops + 1 + 2,
	intelnops + 1 + 2 + 3,
	intelnops + 1 + 2 + 3 + 4,
	intelnops + 1 + 2 + 3 + 4 + 5,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6,
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
103
	intelnops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
104
};
105 106 107
#endif

#ifdef K8_NOP1
108 109 110 111 112 113 114 115 116 117 118 119 120 121
static const unsigned char k8nops[] =
{
	K8_NOP1,
	K8_NOP2,
	K8_NOP3,
	K8_NOP4,
	K8_NOP5,
	K8_NOP6,
	K8_NOP7,
	K8_NOP8,
	K8_NOP5_ATOMIC
};
static const unsigned char * const k8_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
122 123 124 125 126 127 128 129 130
	NULL,
	k8nops,
	k8nops + 1,
	k8nops + 1 + 2,
	k8nops + 1 + 2 + 3,
	k8nops + 1 + 2 + 3 + 4,
	k8nops + 1 + 2 + 3 + 4 + 5,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6,
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
131
	k8nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
132
};
133 134
#endif

135
#if defined(K7_NOP1) && !defined(CONFIG_X86_64)
136 137 138 139 140 141 142 143 144 145 146 147 148 149
static const unsigned char k7nops[] =
{
	K7_NOP1,
	K7_NOP2,
	K7_NOP3,
	K7_NOP4,
	K7_NOP5,
	K7_NOP6,
	K7_NOP7,
	K7_NOP8,
	K7_NOP5_ATOMIC
};
static const unsigned char * const k7_nops[ASM_NOP_MAX+2] =
{
G
Gerd Hoffmann 已提交
150 151 152 153 154 155 156 157 158
	NULL,
	k7nops,
	k7nops + 1,
	k7nops + 1 + 2,
	k7nops + 1 + 2 + 3,
	k7nops + 1 + 2 + 3 + 4,
	k7nops + 1 + 2 + 3 + 4 + 5,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6,
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
159
	k7nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
G
Gerd Hoffmann 已提交
160
};
161 162
#endif

163
#ifdef P6_NOP1
164 165 166 167 168 169 170 171 172 173 174 175 176 177
static const unsigned char  __initconst_or_module p6nops[] =
{
	P6_NOP1,
	P6_NOP2,
	P6_NOP3,
	P6_NOP4,
	P6_NOP5,
	P6_NOP6,
	P6_NOP7,
	P6_NOP8,
	P6_NOP5_ATOMIC
};
static const unsigned char * const p6_nops[ASM_NOP_MAX+2] =
{
178 179 180 181 182 183 184 185 186
	NULL,
	p6nops,
	p6nops + 1,
	p6nops + 1 + 2,
	p6nops + 1 + 2 + 3,
	p6nops + 1 + 2 + 3 + 4,
	p6nops + 1 + 2 + 3 + 4 + 5,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6,
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7,
187
	p6nops + 1 + 2 + 3 + 4 + 5 + 6 + 7 + 8,
188 189 190
};
#endif

191
/* Initialize these to a safe default */
192
#ifdef CONFIG_X86_64
193 194 195 196
const unsigned char * const *ideal_nops = p6_nops;
#else
const unsigned char * const *ideal_nops = intel_nops;
#endif
197

198
void __init arch_init_ideal_nops(void)
199
{
200 201 202 203 204 205 206 207 208 209 210
	switch (boot_cpu_data.x86_vendor) {
	case X86_VENDOR_INTEL:
		if (boot_cpu_has(X86_FEATURE_NOPL)) {
			   ideal_nops = p6_nops;
		} else {
#ifdef CONFIG_X86_64
			ideal_nops = k8_nops;
#else
			ideal_nops = intel_nops;
#endif
		}
211

212 213 214 215 216 217 218 219 220 221 222 223
	default:
#ifdef CONFIG_X86_64
		ideal_nops = k8_nops;
#else
		if (boot_cpu_has(X86_FEATURE_K8))
			ideal_nops = k8_nops;
		else if (boot_cpu_has(X86_FEATURE_K7))
			ideal_nops = k7_nops;
		else
			ideal_nops = intel_nops;
#endif
	}
G
Gerd Hoffmann 已提交
224 225
}

226
/* Use this to add nops to a buffer, then text_poke the whole buffer. */
227
static void __init_or_module add_nops(void *insns, unsigned int len)
228 229 230 231 232
{
	while (len > 0) {
		unsigned int noplen = len;
		if (noplen > ASM_NOP_MAX)
			noplen = ASM_NOP_MAX;
233
		memcpy(insns, ideal_nops[noplen], noplen);
234 235 236 237 238
		insns += noplen;
		len -= noplen;
	}
}

239
extern struct alt_instr __alt_instructions[], __alt_instructions_end[];
240
extern s32 __smp_locks[], __smp_locks_end[];
241
extern char __vsyscall_0;
242
void *text_poke_early(void *addr, const void *opcode, size_t len);
243

G
Gerd Hoffmann 已提交
244 245
/* Replace instructions with better alternatives for this CPU type.
   This runs before SMP is initialized to avoid SMP problems with
L
Lucas De Marchi 已提交
246
   self modifying code. This implies that asymmetric systems where
G
Gerd Hoffmann 已提交
247 248 249
   APs have less capabilities than the boot processor are not handled.
   Tough. Make sure you disable such features by hand. */

250 251
void __init_or_module apply_alternatives(struct alt_instr *start,
					 struct alt_instr *end)
G
Gerd Hoffmann 已提交
252 253
{
	struct alt_instr *a;
254
	u8 insnbuf[MAX_PATCH_LEN];
G
Gerd Hoffmann 已提交
255

256
	DPRINTK("%s: alt table %p -> %p\n", __func__, start, end);
G
Gerd Hoffmann 已提交
257
	for (a = start; a < end; a++) {
258
		u8 *instr = a->instr;
G
Gerd Hoffmann 已提交
259
		BUG_ON(a->replacementlen > a->instrlen);
260
		BUG_ON(a->instrlen > sizeof(insnbuf));
261
		BUG_ON(a->cpuid >= NCAPINTS*32);
G
Gerd Hoffmann 已提交
262 263
		if (!boot_cpu_has(a->cpuid))
			continue;
264 265 266 267 268
#ifdef CONFIG_X86_64
		/* vsyscall code is not mapped yet. resolve it manually. */
		if (instr >= (u8 *)VSYSCALL_START && instr < (u8*)VSYSCALL_END) {
			instr = __va(instr - (u8*)VSYSCALL_START + (u8*)__pa_symbol(&__vsyscall_0));
			DPRINTK("%s: vsyscall fixup: %p => %p\n",
269
				__func__, a->instr, instr);
270 271
		}
#endif
272
		memcpy(insnbuf, a->replacement, a->replacementlen);
273 274
		if (*insnbuf == 0xe8 && a->replacementlen == 5)
		    *(s32 *)(insnbuf + 1) += a->replacement - a->instr;
275 276
		add_nops(insnbuf + a->replacementlen,
			 a->instrlen - a->replacementlen);
277
		text_poke_early(instr, insnbuf, a->instrlen);
G
Gerd Hoffmann 已提交
278 279 280
	}
}

281 282
#ifdef CONFIG_SMP

283 284
static void alternatives_smp_lock(const s32 *start, const s32 *end,
				  u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
285
{
286
	const s32 *poff;
G
Gerd Hoffmann 已提交
287

288
	mutex_lock(&text_mutex);
289 290 291 292
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
293
			continue;
294
		/* turn DS segment override prefix into lock prefix */
295 296
		if (*ptr == 0x3e)
			text_poke(ptr, ((unsigned char []){0xf0}), 1);
G
Gerd Hoffmann 已提交
297
	};
298
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
299 300
}

301 302
static void alternatives_smp_unlock(const s32 *start, const s32 *end,
				    u8 *text, u8 *text_end)
G
Gerd Hoffmann 已提交
303
{
304
	const s32 *poff;
G
Gerd Hoffmann 已提交
305

306 307 308
	if (noreplace_smp)
		return;

309
	mutex_lock(&text_mutex);
310 311 312 313
	for (poff = start; poff < end; poff++) {
		u8 *ptr = (u8 *)poff + *poff;

		if (!*poff || ptr < text || ptr >= text_end)
G
Gerd Hoffmann 已提交
314
			continue;
315
		/* turn lock prefix into DS segment override prefix */
316 317
		if (*ptr == 0xf0)
			text_poke(ptr, ((unsigned char []){0x3E}), 1);
G
Gerd Hoffmann 已提交
318
	};
319
	mutex_unlock(&text_mutex);
G
Gerd Hoffmann 已提交
320 321 322 323 324 325 326 327
}

struct smp_alt_module {
	/* what is this ??? */
	struct module	*mod;
	char		*name;

	/* ptrs to lock prefixes */
328 329
	const s32	*locks;
	const s32	*locks_end;
G
Gerd Hoffmann 已提交
330 331 332 333 334 335 336 337

	/* .text segment, needed to avoid patching init code ;) */
	u8		*text;
	u8		*text_end;

	struct list_head next;
};
static LIST_HEAD(smp_alt_modules);
338
static DEFINE_MUTEX(smp_alt);
339
static int smp_mode = 1;	/* protected by smp_alt */
G
Gerd Hoffmann 已提交
340

341 342 343 344
void __init_or_module alternatives_smp_module_add(struct module *mod,
						  char *name,
						  void *locks, void *locks_end,
						  void *text,  void *text_end)
G
Gerd Hoffmann 已提交
345 346 347
{
	struct smp_alt_module *smp;

348 349 350
	if (noreplace_smp)
		return;

G
Gerd Hoffmann 已提交
351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368
	if (smp_alt_once) {
		if (boot_cpu_has(X86_FEATURE_UP))
			alternatives_smp_unlock(locks, locks_end,
						text, text_end);
		return;
	}

	smp = kzalloc(sizeof(*smp), GFP_KERNEL);
	if (NULL == smp)
		return; /* we'll run the (safe but slow) SMP code then ... */

	smp->mod	= mod;
	smp->name	= name;
	smp->locks	= locks;
	smp->locks_end	= locks_end;
	smp->text	= text;
	smp->text_end	= text_end;
	DPRINTK("%s: locks %p -> %p, text %p -> %p, name %s\n",
369
		__func__, smp->locks, smp->locks_end,
G
Gerd Hoffmann 已提交
370 371
		smp->text, smp->text_end, smp->name);

372
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
373 374 375 376
	list_add_tail(&smp->next, &smp_alt_modules);
	if (boot_cpu_has(X86_FEATURE_UP))
		alternatives_smp_unlock(smp->locks, smp->locks_end,
					smp->text, smp->text_end);
377
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
378 379
}

380
void __init_or_module alternatives_smp_module_del(struct module *mod)
G
Gerd Hoffmann 已提交
381 382 383
{
	struct smp_alt_module *item;

384
	if (smp_alt_once || noreplace_smp)
G
Gerd Hoffmann 已提交
385 386
		return;

387
	mutex_lock(&smp_alt);
G
Gerd Hoffmann 已提交
388 389 390 391
	list_for_each_entry(item, &smp_alt_modules, next) {
		if (mod != item->mod)
			continue;
		list_del(&item->next);
392
		mutex_unlock(&smp_alt);
393
		DPRINTK("%s: %s\n", __func__, item->name);
G
Gerd Hoffmann 已提交
394 395 396
		kfree(item);
		return;
	}
397
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
398 399
}

400
bool skip_smp_alternatives;
G
Gerd Hoffmann 已提交
401 402 403 404
void alternatives_smp_switch(int smp)
{
	struct smp_alt_module *mod;

405 406
#ifdef CONFIG_LOCKDEP
	/*
407 408 409 410 411
	 * Older binutils section handling bug prevented
	 * alternatives-replacement from working reliably.
	 *
	 * If this still occurs then you should see a hang
	 * or crash shortly after this line:
412
	 */
413
	printk("lockdep: fixing up alternatives.\n");
414 415
#endif

416
	if (noreplace_smp || smp_alt_once || skip_smp_alternatives)
G
Gerd Hoffmann 已提交
417 418 419
		return;
	BUG_ON(!smp && (num_online_cpus() > 1));

420
	mutex_lock(&smp_alt);
421 422 423 424 425 426 427 428

	/*
	 * Avoid unnecessary switches because it forces JIT based VMs to
	 * throw away all cached translations, which can be quite costly.
	 */
	if (smp == smp_mode) {
		/* nothing */
	} else if (smp) {
G
Gerd Hoffmann 已提交
429
		printk(KERN_INFO "SMP alternatives: switching to SMP code\n");
430 431
		clear_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		clear_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
432 433 434 435 436
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_lock(mod->locks, mod->locks_end,
					      mod->text, mod->text_end);
	} else {
		printk(KERN_INFO "SMP alternatives: switching to UP code\n");
437 438
		set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
		set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);
G
Gerd Hoffmann 已提交
439 440 441 442
		list_for_each_entry(mod, &smp_alt_modules, next)
			alternatives_smp_unlock(mod->locks, mod->locks_end,
						mod->text, mod->text_end);
	}
443
	smp_mode = smp;
444
	mutex_unlock(&smp_alt);
G
Gerd Hoffmann 已提交
445 446
}

447 448 449 450
/* Return 1 if the address range is reserved for smp-alternatives */
int alternatives_text_reserved(void *start, void *end)
{
	struct smp_alt_module *mod;
451
	const s32 *poff;
452 453
	u8 *text_start = start;
	u8 *text_end = end;
454 455

	list_for_each_entry(mod, &smp_alt_modules, next) {
456
		if (mod->text > text_end || mod->text_end < text_start)
457
			continue;
458 459 460 461
		for (poff = mod->locks; poff < mod->locks_end; poff++) {
			const u8 *ptr = (const u8 *)poff + *poff;

			if (text_start <= ptr && text_end > ptr)
462
				return 1;
463
		}
464 465 466 467
	}

	return 0;
}
468 469
#endif

470
#ifdef CONFIG_PARAVIRT
471 472
void __init_or_module apply_paravirt(struct paravirt_patch_site *start,
				     struct paravirt_patch_site *end)
473
{
474
	struct paravirt_patch_site *p;
475
	char insnbuf[MAX_PATCH_LEN];
476

477 478 479
	if (noreplace_paravirt)
		return;

480 481 482
	for (p = start; p < end; p++) {
		unsigned int used;

483
		BUG_ON(p->len > MAX_PATCH_LEN);
484 485
		/* prep the buffer with the original instructions */
		memcpy(insnbuf, p->instr, p->len);
486 487
		used = pv_init_ops.patch(p->instrtype, p->clobbers, insnbuf,
					 (unsigned long)p->instr, p->len);
488

489 490
		BUG_ON(used > p->len);

491
		/* Pad the rest with nops */
492
		add_nops(insnbuf + used, p->len - used);
493
		text_poke_early(p->instr, insnbuf, p->len);
494 495
	}
}
496
extern struct paravirt_patch_site __start_parainstructions[],
497 498 499
	__stop_parainstructions[];
#endif	/* CONFIG_PARAVIRT */

G
Gerd Hoffmann 已提交
500 501
void __init alternative_instructions(void)
{
502 503 504 505
	/* The patching is not fully atomic, so try to avoid local interruptions
	   that might execute the to be patched code.
	   Other CPUs are not running. */
	stop_nmi();
506 507 508 509 510 511 512 513 514 515 516

	/*
	 * Don't stop machine check exceptions while patching.
	 * MCEs only happen when something got corrupted and in this
	 * case we must do something about the corruption.
	 * Ignoring it is worse than a unlikely patching race.
	 * Also machine checks tend to be broadcast and if one CPU
	 * goes into machine check the others follow quickly, so we don't
	 * expect a machine check to cause undue problems during to code
	 * patching.
	 */
517

G
Gerd Hoffmann 已提交
518 519 520 521 522 523 524 525 526 527
	apply_alternatives(__alt_instructions, __alt_instructions_end);

	/* switch to patch-once-at-boottime-only mode and free the
	 * tables in case we know the number of CPUs will never ever
	 * change */
#ifdef CONFIG_HOTPLUG_CPU
	if (num_possible_cpus() < 2)
		smp_alt_once = 1;
#endif

528
#ifdef CONFIG_SMP
G
Gerd Hoffmann 已提交
529 530 531
	if (smp_alt_once) {
		if (1 == num_possible_cpus()) {
			printk(KERN_INFO "SMP alternatives: switching to UP code\n");
532 533 534
			set_cpu_cap(&boot_cpu_data, X86_FEATURE_UP);
			set_cpu_cap(&cpu_data(0), X86_FEATURE_UP);

G
Gerd Hoffmann 已提交
535 536 537 538 539 540 541
			alternatives_smp_unlock(__smp_locks, __smp_locks_end,
						_text, _etext);
		}
	} else {
		alternatives_smp_module_add(NULL, "core kernel",
					    __smp_locks, __smp_locks_end,
					    _text, _etext);
542 543

		/* Only switch to UP mode if we don't immediately boot others */
544
		if (num_present_cpus() == 1 || setup_max_cpus <= 1)
545
			alternatives_smp_switch(0);
G
Gerd Hoffmann 已提交
546
	}
547
#endif
548
 	apply_paravirt(__parainstructions, __parainstructions_end);
549

550 551 552 553 554
	if (smp_alt_once)
		free_init_pages("SMP alternatives",
				(unsigned long)__smp_locks,
				(unsigned long)__smp_locks_end);

555
	restart_nmi();
G
Gerd Hoffmann 已提交
556
}
557

558 559 560 561 562 563
/**
 * text_poke_early - Update instructions on a live kernel at boot time
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
564 565
 * When you use this code to patch more than one byte of an instruction
 * you need to make sure that other CPUs cannot execute this code in parallel.
566 567 568
 * Also no thread must be currently preempted in the middle of these
 * instructions. And on the local CPU you need to be protected again NMI or MCE
 * handlers seeing an inconsistent instruction while you patch.
569
 */
570
void *__init_or_module text_poke_early(void *addr, const void *opcode,
571
					      size_t len)
572
{
573 574
	unsigned long flags;
	local_irq_save(flags);
575
	memcpy(addr, opcode, len);
576
	sync_core();
577
	local_irq_restore(flags);
578 579 580 581 582 583 584 585 586 587 588 589 590 591 592
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
	return addr;
}

/**
 * text_poke - Update instructions on a live kernel
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Only atomic text poke/set should be allowed when not doing early patching.
 * It means the size must be writable atomically and the address must be aligned
 * in a way that permits an atomic write. It also makes sure we fit on a single
 * page.
593 594
 *
 * Note: Must be called under text_mutex.
595 596 597
 */
void *__kprobes text_poke(void *addr, const void *opcode, size_t len)
{
598
	unsigned long flags;
599
	char *vaddr;
M
Mathieu Desnoyers 已提交
600 601
	struct page *pages[2];
	int i;
602

M
Mathieu Desnoyers 已提交
603 604 605
	if (!core_kernel_text((unsigned long)addr)) {
		pages[0] = vmalloc_to_page(addr);
		pages[1] = vmalloc_to_page(addr + PAGE_SIZE);
606
	} else {
M
Mathieu Desnoyers 已提交
607
		pages[0] = virt_to_page(addr);
I
Ingo Molnar 已提交
608
		WARN_ON(!PageReserved(pages[0]));
M
Mathieu Desnoyers 已提交
609
		pages[1] = virt_to_page(addr + PAGE_SIZE);
610
	}
M
Mathieu Desnoyers 已提交
611
	BUG_ON(!pages[0]);
612
	local_irq_save(flags);
613 614 615 616
	set_fixmap(FIX_TEXT_POKE0, page_to_phys(pages[0]));
	if (pages[1])
		set_fixmap(FIX_TEXT_POKE1, page_to_phys(pages[1]));
	vaddr = (char *)fix_to_virt(FIX_TEXT_POKE0);
M
Mathieu Desnoyers 已提交
617
	memcpy(&vaddr[(unsigned long)addr & ~PAGE_MASK], opcode, len);
618 619 620 621
	clear_fixmap(FIX_TEXT_POKE0);
	if (pages[1])
		clear_fixmap(FIX_TEXT_POKE1);
	local_flush_tlb();
622
	sync_core();
623 624
	/* Could also do a CLFLUSH here to speed up CPU recovery; but
	   that causes hangs on some VIA CPUs. */
M
Mathieu Desnoyers 已提交
625 626
	for (i = 0; i < len; i++)
		BUG_ON(((char *)addr)[i] != ((char *)opcode)[i]);
627
	local_irq_restore(flags);
628
	return addr;
629
}
630 631 632 633 634 635 636 637 638

/*
 * Cross-modifying kernel text with stop_machine().
 * This code originally comes from immediate value.
 */
static atomic_t stop_machine_first;
static int wrote_text;

struct text_poke_params {
639 640
	struct text_poke_param *params;
	int nparams;
641 642 643 644 645
};

static int __kprobes stop_machine_text_poke(void *data)
{
	struct text_poke_params *tpp = data;
646 647
	struct text_poke_param *p;
	int i;
648 649

	if (atomic_dec_and_test(&stop_machine_first)) {
650 651 652 653
		for (i = 0; i < tpp->nparams; i++) {
			p = &tpp->params[i];
			text_poke(p->addr, p->opcode, p->len);
		}
654 655 656 657
		smp_wmb();	/* Make sure other cpus see that this has run */
		wrote_text = 1;
	} else {
		while (!wrote_text)
658 659
			cpu_relax();
		smp_mb();	/* Load wrote_text before following execution */
660 661
	}

662 663 664 665 666
	for (i = 0; i < tpp->nparams; i++) {
		p = &tpp->params[i];
		flush_icache_range((unsigned long)p->addr,
				   (unsigned long)p->addr + p->len);
	}
667 668 669 670 671 672
	/*
	 * Intel Archiecture Software Developer's Manual section 7.1.3 specifies
	 * that a core serializing instruction such as "cpuid" should be
	 * executed on _each_ core before the new instruction is made visible.
	 */
	sync_core();
673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691
	return 0;
}

/**
 * text_poke_smp - Update instructions on a live kernel on SMP
 * @addr: address to modify
 * @opcode: source of the copy
 * @len: length to copy
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. This allows
 * user to poke/set multi-byte text on SMP. Only non-NMI/MCE code modifying
 * should be allowed, since stop_machine() does _not_ protect code against
 * NMI and MCE.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void *__kprobes text_poke_smp(void *addr, const void *opcode, size_t len)
{
	struct text_poke_params tpp;
692
	struct text_poke_param p;
693

694 695 696 697 698
	p.addr = addr;
	p.opcode = opcode;
	p.len = len;
	tpp.params = &p;
	tpp.nparams = 1;
699 700
	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
701
	/* Use __stop_machine() because the caller already got online_cpus. */
702
	__stop_machine(stop_machine_text_poke, (void *)&tpp, cpu_online_mask);
703 704 705
	return addr;
}

706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722
/**
 * text_poke_smp_batch - Update instructions on a live kernel on SMP
 * @params: an array of text_poke parameters
 * @n: the number of elements in params.
 *
 * Modify multi-byte instruction by using stop_machine() on SMP. Since the
 * stop_machine() is heavy task, it is better to aggregate text_poke requests
 * and do it once if possible.
 *
 * Note: Must be called under get_online_cpus() and text_mutex.
 */
void __kprobes text_poke_smp_batch(struct text_poke_param *params, int n)
{
	struct text_poke_params tpp = {.params = params, .nparams = n};

	atomic_set(&stop_machine_first, 1);
	wrote_text = 0;
723
	__stop_machine(stop_machine_text_poke, (void *)&tpp, NULL);
724
}