panic.c 10.0 KB
Newer Older
L
Linus Torvalds 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19
/*
 *  linux/kernel/panic.c
 *
 *  Copyright (C) 1991, 1992  Linus Torvalds
 */

/*
 * This function is used through-out the kernel (including mm and fs)
 * to indicate a major problem.
 */
#include <linux/module.h>
#include <linux/sched.h>
#include <linux/delay.h>
#include <linux/reboot.h>
#include <linux/notifier.h>
#include <linux/init.h>
#include <linux/sysrq.h>
#include <linux/interrupt.h>
#include <linux/nmi.h>
20
#include <linux/kexec.h>
A
Andrew Morton 已提交
21
#include <linux/debug_locks.h>
A
Arjan van de Ven 已提交
22
#include <linux/random.h>
23
#include <linux/kallsyms.h>
L
Linus Torvalds 已提交
24 25 26

int panic_on_oops;
int tainted;
27 28 29
static int pause_on_oops;
static int pause_on_oops_flag;
static DEFINE_SPINLOCK(pause_on_oops_lock);
L
Linus Torvalds 已提交
30

31
int panic_timeout;
L
Linus Torvalds 已提交
32

33
ATOMIC_NOTIFIER_HEAD(panic_notifier_list);
L
Linus Torvalds 已提交
34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60

EXPORT_SYMBOL(panic_notifier_list);

static int __init panic_setup(char *str)
{
	panic_timeout = simple_strtoul(str, NULL, 0);
	return 1;
}
__setup("panic=", panic_setup);

static long no_blink(long time)
{
	return 0;
}

/* Returns how long it waited in ms */
long (*panic_blink)(long time);
EXPORT_SYMBOL(panic_blink);

/**
 *	panic - halt the system
 *	@fmt: The text string to print
 *
 *	Display a message, then perform cleanups.
 *
 *	This function never returns.
 */
D
Daniel Walker 已提交
61

L
Linus Torvalds 已提交
62 63 64 65 66
NORET_TYPE void panic(const char * fmt, ...)
{
	long i;
	static char buf[1024];
	va_list args;
67
#if defined(CONFIG_S390)
D
Daniel Walker 已提交
68
	unsigned long caller = (unsigned long) __builtin_return_address(0);
L
Linus Torvalds 已提交
69 70
#endif

71 72 73 74 75 76 77
	/*
	 * It's possible to come here directly from a panic-assertion and not
	 * have preempt disabled. Some functions called from here want
	 * preempt to be disabled. No point enabling it later though...
	 */
	preempt_disable();

L
Linus Torvalds 已提交
78 79 80 81 82
	bust_spinlocks(1);
	va_start(args, fmt);
	vsnprintf(buf, sizeof(buf), fmt, args);
	va_end(args);
	printk(KERN_EMERG "Kernel panic - not syncing: %s\n",buf);
83 84 85
#ifdef CONFIG_DEBUG_BUGVERBOSE
	dump_stack();
#endif
L
Linus Torvalds 已提交
86 87
	bust_spinlocks(0);

88 89 90 91 92
	/*
	 * If we have crashed and we have a crash kernel loaded let it handle
	 * everything else.
	 * Do we want to call this before we try to display a message?
	 */
93
	crash_kexec(NULL);
94

L
Linus Torvalds 已提交
95
#ifdef CONFIG_SMP
96 97 98 99 100
	/*
	 * Note smp_send_stop is the usual smp shutdown function, which
	 * unfortunately means it may not be hardened to work in a panic
	 * situation.
	 */
L
Linus Torvalds 已提交
101 102 103
	smp_send_stop();
#endif

104
	atomic_notifier_call_chain(&panic_notifier_list, 0, buf);
L
Linus Torvalds 已提交
105 106 107 108

	if (!panic_blink)
		panic_blink = no_blink;

109
	if (panic_timeout > 0) {
L
Linus Torvalds 已提交
110 111 112 113 114 115 116 117 118 119 120
		/*
	 	 * Delay timeout seconds before rebooting the machine. 
		 * We can't use the "normal" timers since we just panicked..
	 	 */
		printk(KERN_EMERG "Rebooting in %d seconds..",panic_timeout);
		for (i = 0; i < panic_timeout*1000; ) {
			touch_nmi_watchdog();
			i += panic_blink(i);
			mdelay(1);
			i++;
		}
121 122 123
		/*	This will not be a clean reboot, with everything
		 *	shutting down.  But if there is a chance of
		 *	rebooting the system it will be rebooted.
L
Linus Torvalds 已提交
124
		 */
125
		emergency_restart();
L
Linus Torvalds 已提交
126 127 128 129
	}
#ifdef __sparc__
	{
		extern int stop_a_enabled;
130
		/* Make sure the user can actually press Stop-A (L1-A) */
L
Linus Torvalds 已提交
131
		stop_a_enabled = 1;
132
		printk(KERN_EMERG "Press Stop-A (L1-A) to return to the boot prom\n");
L
Linus Torvalds 已提交
133 134
	}
#endif
135
#if defined(CONFIG_S390)
D
Daniel Walker 已提交
136
	disabled_wait(caller);
L
Linus Torvalds 已提交
137 138 139
#endif
	local_irq_enable();
	for (i = 0;;) {
140
		touch_softlockup_watchdog();
L
Linus Torvalds 已提交
141 142 143 144 145 146 147 148 149 150 151 152 153 154 155
		i += panic_blink(i);
		mdelay(1);
		i++;
	}
}

EXPORT_SYMBOL(panic);

/**
 *	print_tainted - return a string to represent the kernel taint state.
 *
 *  'P' - Proprietary module has been loaded.
 *  'F' - Module has been forcibly loaded.
 *  'S' - SMP with CPUs not designed for SMP.
 *  'R' - User forced a module unload.
156
 *  'M' - System experienced a machine check exception.
L
Linus Torvalds 已提交
157
 *  'B' - System has hit bad_page.
158
 *  'U' - Userspace-defined naughtiness.
159 160
 *  'A' - ACPI table overridden.
 *  'W' - Taint on warning.
L
Linus Torvalds 已提交
161 162 163
 *
 *	The string is overwritten by the next call to print_taint().
 */
D
Daniel Walker 已提交
164

L
Linus Torvalds 已提交
165 166 167 168
const char *print_tainted(void)
{
	static char buf[20];
	if (tainted) {
169
		snprintf(buf, sizeof(buf), "Tainted: %c%c%c%c%c%c%c%c%c%c",
L
Linus Torvalds 已提交
170 171 172 173
			tainted & TAINT_PROPRIETARY_MODULE ? 'P' : 'G',
			tainted & TAINT_FORCED_MODULE ? 'F' : ' ',
			tainted & TAINT_UNSAFE_SMP ? 'S' : ' ',
			tainted & TAINT_FORCED_RMMOD ? 'R' : ' ',
D
Daniel Walker 已提交
174
			tainted & TAINT_MACHINE_CHECK ? 'M' : ' ',
175
			tainted & TAINT_BAD_PAGE ? 'B' : ' ',
176
			tainted & TAINT_USER ? 'U' : ' ',
177
			tainted & TAINT_DIE ? 'D' : ' ',
178 179
			tainted & TAINT_OVERRIDDEN_ACPI_TABLE ? 'A' : ' ',
			tainted & TAINT_WARN ? 'W' : ' ');
L
Linus Torvalds 已提交
180 181 182 183 184 185 186 187
	}
	else
		snprintf(buf, sizeof(buf), "Not tainted");
	return(buf);
}

void add_taint(unsigned flag)
{
188
	debug_locks = 0; /* can't trust the integrity of the kernel anymore */
L
Linus Torvalds 已提交
189 190 191
	tainted |= flag;
}
EXPORT_SYMBOL(add_taint);
192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272

static int __init pause_on_oops_setup(char *str)
{
	pause_on_oops = simple_strtoul(str, NULL, 0);
	return 1;
}
__setup("pause_on_oops=", pause_on_oops_setup);

static void spin_msec(int msecs)
{
	int i;

	for (i = 0; i < msecs; i++) {
		touch_nmi_watchdog();
		mdelay(1);
	}
}

/*
 * It just happens that oops_enter() and oops_exit() are identically
 * implemented...
 */
static void do_oops_enter_exit(void)
{
	unsigned long flags;
	static int spin_counter;

	if (!pause_on_oops)
		return;

	spin_lock_irqsave(&pause_on_oops_lock, flags);
	if (pause_on_oops_flag == 0) {
		/* This CPU may now print the oops message */
		pause_on_oops_flag = 1;
	} else {
		/* We need to stall this CPU */
		if (!spin_counter) {
			/* This CPU gets to do the counting */
			spin_counter = pause_on_oops;
			do {
				spin_unlock(&pause_on_oops_lock);
				spin_msec(MSEC_PER_SEC);
				spin_lock(&pause_on_oops_lock);
			} while (--spin_counter);
			pause_on_oops_flag = 0;
		} else {
			/* This CPU waits for a different one */
			while (spin_counter) {
				spin_unlock(&pause_on_oops_lock);
				spin_msec(1);
				spin_lock(&pause_on_oops_lock);
			}
		}
	}
	spin_unlock_irqrestore(&pause_on_oops_lock, flags);
}

/*
 * Return true if the calling CPU is allowed to print oops-related info.  This
 * is a bit racy..
 */
int oops_may_print(void)
{
	return pause_on_oops_flag == 0;
}

/*
 * Called when the architecture enters its oops handler, before it prints
 * anything.  If this is the first CPU to oops, and it's oopsing the first time
 * then let it proceed.
 *
 * This is all enabled by the pause_on_oops kernel boot option.  We do all this
 * to ensure that oopses don't scroll off the screen.  It has the side-effect
 * of preventing later-oopsing CPUs from mucking up the display, too.
 *
 * It turns out that the CPU which is allowed to print ends up pausing for the
 * right duration, whereas all the other CPUs pause for twice as long: once in
 * oops_enter(), once in oops_exit().
 */
void oops_enter(void)
{
273
	debug_locks_off(); /* can't trust the integrity of the kernel anymore */
274 275 276
	do_oops_enter_exit();
}

A
Arjan van de Ven 已提交
277 278 279 280 281 282 283 284 285 286 287 288 289 290
/*
 * 64-bit random ID for oopses:
 */
static u64 oops_id;

static int init_oops_id(void)
{
	if (!oops_id)
		get_random_bytes(&oops_id, sizeof(oops_id));

	return 0;
}
late_initcall(init_oops_id);

291 292 293 294 295 296 297
static void print_oops_end_marker(void)
{
	init_oops_id();
	printk(KERN_WARNING "---[ end trace %016llx ]---\n",
		(unsigned long long)oops_id);
}

298 299 300 301 302 303 304
/*
 * Called when the architecture exits its oops handler, after printing
 * everything.
 */
void oops_exit(void)
{
	do_oops_enter_exit();
305
	print_oops_end_marker();
306
}
307

308 309 310 311 312 313
#ifdef WANT_WARN_ON_SLOWPATH
void warn_on_slowpath(const char *file, int line)
{
	char function[KSYM_SYMBOL_LEN];
	unsigned long caller = (unsigned long) __builtin_return_address(0);
	sprint_symbol(function, caller);
314 315

	printk(KERN_WARNING "------------[ cut here ]------------\n");
316 317
	printk(KERN_WARNING "WARNING: at %s:%d %s()\n", file,
		line, function);
318
	print_modules();
319
	dump_stack();
320
	print_oops_end_marker();
321
	add_taint(TAINT_WARN);
322 323 324 325
}
EXPORT_SYMBOL(warn_on_slowpath);
#endif

326
#ifdef CONFIG_CC_STACKPROTECTOR
327

328 329 330
#ifndef GCC_HAS_SP
#warning You have selected the CONFIG_CC_STACKPROTECTOR option, but the gcc used does not support this.
#endif
331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346
static unsigned long __stack_check_testing;
/*
 * Self test function for the stack-protector feature.
 * This test requires that the local variable absolutely has
 * a stack slot, hence the barrier()s.
 */
static noinline void __stack_chk_test_func(void)
{
	unsigned long foo;
	barrier();
	/*
	 * we need to make sure we're not about to clobber the return address,
	 * while real exploits do this, it's unhealthy on a running system.
	 * Besides, if we would, the test is already failed anyway so
	 * time to pull the emergency brake on it.
	 */
347
	if ((unsigned long)__builtin_return_address(0) ==
348 349 350 351 352
					*(((unsigned long *)&foo)+1)) {
		printk(KERN_ERR "No -fstack-protector-stack-frame!\n");
	}
#ifdef CONFIG_FRAME_POINTER
	/* We also don't want to clobber the frame pointer */
353
	if ((unsigned long)__builtin_return_address(0) ==
354 355 356 357
					*(((unsigned long *)&foo)+2)) {
		printk(KERN_ERR "No -fstack-protector-stack-frame!\n");
	}
#endif
358
	if (current->stack_canary != *(((unsigned long *)&foo)+1))
359
		printk(KERN_ERR "No -fstack-protector canary found\n");
360 361

	current->stack_canary = ~current->stack_canary;
362 363 364 365 366 367 368 369 370 371
}

static int __stack_chk_test(void)
{
	printk(KERN_INFO "Testing -fstack-protector-all feature\n");
	__stack_check_testing = (unsigned long)&__stack_chk_test_func;
	__stack_chk_test_func();
	if (__stack_check_testing) {
		printk(KERN_ERR "-fstack-protector-all test failed\n");
		WARN_ON(1);
372 373
	};
	current->stack_canary = ~current->stack_canary;
374 375
	return 0;
}
376 377 378 379 380 381
/*
 * Called when gcc's -fstack-protector feature is used, and
 * gcc detects corruption of the on-stack canary value
 */
void __stack_chk_fail(void)
{
382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398
	if (__stack_check_testing == (unsigned long)&__stack_chk_test_func) {
		long delta;

		delta = (unsigned long)__builtin_return_address(0) -
				__stack_check_testing;
		/*
		 * The test needs to happen inside the test function, so
		 * check if the return address is close to that function.
		 * The function is only 2 dozen bytes long, but keep a wide
		 * safety margin to avoid panic()s for normal users regardless
		 * of the quality of the compiler.
		 */
		if (delta >= 0 && delta <= 400) {
			__stack_check_testing = 0;
			return;
		}
	}
399 400
	panic("stack-protector: Kernel stack is corrupted in: %p\n",
		__builtin_return_address(0));
401 402
}
EXPORT_SYMBOL(__stack_chk_fail);
403 404

late_initcall(__stack_chk_test);
405
#endif