xref: /OK3568_Linux_fs/kernel/arch/arm/probes/uprobes/actions-arm.c (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-only
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * Copyright (C) 2012 Rabin Vincent <rabin at rab.in>
4*4882a593Smuzhiyun  */
5*4882a593Smuzhiyun 
6*4882a593Smuzhiyun #include <linux/kernel.h>
7*4882a593Smuzhiyun #include <linux/types.h>
8*4882a593Smuzhiyun #include <linux/stddef.h>
9*4882a593Smuzhiyun #include <linux/wait.h>
10*4882a593Smuzhiyun #include <linux/uprobes.h>
11*4882a593Smuzhiyun #include <linux/module.h>
12*4882a593Smuzhiyun 
13*4882a593Smuzhiyun #include "../decode.h"
14*4882a593Smuzhiyun #include "../decode-arm.h"
15*4882a593Smuzhiyun #include "core.h"
16*4882a593Smuzhiyun 
uprobes_substitute_pc(unsigned long * pinsn,u32 oregs)17*4882a593Smuzhiyun static int uprobes_substitute_pc(unsigned long *pinsn, u32 oregs)
18*4882a593Smuzhiyun {
19*4882a593Smuzhiyun 	probes_opcode_t insn = __mem_to_opcode_arm(*pinsn);
20*4882a593Smuzhiyun 	probes_opcode_t temp;
21*4882a593Smuzhiyun 	probes_opcode_t mask;
22*4882a593Smuzhiyun 	int freereg;
23*4882a593Smuzhiyun 	u32 free = 0xffff;
24*4882a593Smuzhiyun 	u32 regs;
25*4882a593Smuzhiyun 
26*4882a593Smuzhiyun 	for (regs = oregs; regs; regs >>= 4, insn >>= 4) {
27*4882a593Smuzhiyun 		if ((regs & 0xf) == REG_TYPE_NONE)
28*4882a593Smuzhiyun 			continue;
29*4882a593Smuzhiyun 
30*4882a593Smuzhiyun 		free &= ~(1 << (insn & 0xf));
31*4882a593Smuzhiyun 	}
32*4882a593Smuzhiyun 
33*4882a593Smuzhiyun 	/* No PC, no problem */
34*4882a593Smuzhiyun 	if (free & (1 << 15))
35*4882a593Smuzhiyun 		return 15;
36*4882a593Smuzhiyun 
37*4882a593Smuzhiyun 	if (!free)
38*4882a593Smuzhiyun 		return -1;
39*4882a593Smuzhiyun 
40*4882a593Smuzhiyun 	/*
41*4882a593Smuzhiyun 	 * fls instead of ffs ensures that for "ldrd r0, r1, [pc]" we would
42*4882a593Smuzhiyun 	 * pick LR instead of R1.
43*4882a593Smuzhiyun 	 */
44*4882a593Smuzhiyun 	freereg = free = fls(free) - 1;
45*4882a593Smuzhiyun 
46*4882a593Smuzhiyun 	temp = __mem_to_opcode_arm(*pinsn);
47*4882a593Smuzhiyun 	insn = temp;
48*4882a593Smuzhiyun 	regs = oregs;
49*4882a593Smuzhiyun 	mask = 0xf;
50*4882a593Smuzhiyun 
51*4882a593Smuzhiyun 	for (; regs; regs >>= 4, mask <<= 4, free <<= 4, temp >>= 4) {
52*4882a593Smuzhiyun 		if ((regs & 0xf) == REG_TYPE_NONE)
53*4882a593Smuzhiyun 			continue;
54*4882a593Smuzhiyun 
55*4882a593Smuzhiyun 		if ((temp & 0xf) != 15)
56*4882a593Smuzhiyun 			continue;
57*4882a593Smuzhiyun 
58*4882a593Smuzhiyun 		insn &= ~mask;
59*4882a593Smuzhiyun 		insn |= free & mask;
60*4882a593Smuzhiyun 	}
61*4882a593Smuzhiyun 
62*4882a593Smuzhiyun 	*pinsn = __opcode_to_mem_arm(insn);
63*4882a593Smuzhiyun 	return freereg;
64*4882a593Smuzhiyun }
65*4882a593Smuzhiyun 
uprobe_set_pc(struct arch_uprobe * auprobe,struct arch_uprobe_task * autask,struct pt_regs * regs)66*4882a593Smuzhiyun static void uprobe_set_pc(struct arch_uprobe *auprobe,
67*4882a593Smuzhiyun 			  struct arch_uprobe_task *autask,
68*4882a593Smuzhiyun 			  struct pt_regs *regs)
69*4882a593Smuzhiyun {
70*4882a593Smuzhiyun 	u32 pcreg = auprobe->pcreg;
71*4882a593Smuzhiyun 
72*4882a593Smuzhiyun 	autask->backup = regs->uregs[pcreg];
73*4882a593Smuzhiyun 	regs->uregs[pcreg] = regs->ARM_pc + 8;
74*4882a593Smuzhiyun }
75*4882a593Smuzhiyun 
uprobe_unset_pc(struct arch_uprobe * auprobe,struct arch_uprobe_task * autask,struct pt_regs * regs)76*4882a593Smuzhiyun static void uprobe_unset_pc(struct arch_uprobe *auprobe,
77*4882a593Smuzhiyun 			    struct arch_uprobe_task *autask,
78*4882a593Smuzhiyun 			    struct pt_regs *regs)
79*4882a593Smuzhiyun {
80*4882a593Smuzhiyun 	/* PC will be taken care of by common code */
81*4882a593Smuzhiyun 	regs->uregs[auprobe->pcreg] = autask->backup;
82*4882a593Smuzhiyun }
83*4882a593Smuzhiyun 
uprobe_aluwrite_pc(struct arch_uprobe * auprobe,struct arch_uprobe_task * autask,struct pt_regs * regs)84*4882a593Smuzhiyun static void uprobe_aluwrite_pc(struct arch_uprobe *auprobe,
85*4882a593Smuzhiyun 			       struct arch_uprobe_task *autask,
86*4882a593Smuzhiyun 			       struct pt_regs *regs)
87*4882a593Smuzhiyun {
88*4882a593Smuzhiyun 	u32 pcreg = auprobe->pcreg;
89*4882a593Smuzhiyun 
90*4882a593Smuzhiyun 	alu_write_pc(regs->uregs[pcreg], regs);
91*4882a593Smuzhiyun 	regs->uregs[pcreg] = autask->backup;
92*4882a593Smuzhiyun }
93*4882a593Smuzhiyun 
uprobe_write_pc(struct arch_uprobe * auprobe,struct arch_uprobe_task * autask,struct pt_regs * regs)94*4882a593Smuzhiyun static void uprobe_write_pc(struct arch_uprobe *auprobe,
95*4882a593Smuzhiyun 			    struct arch_uprobe_task *autask,
96*4882a593Smuzhiyun 			    struct pt_regs *regs)
97*4882a593Smuzhiyun {
98*4882a593Smuzhiyun 	u32 pcreg = auprobe->pcreg;
99*4882a593Smuzhiyun 
100*4882a593Smuzhiyun 	load_write_pc(regs->uregs[pcreg], regs);
101*4882a593Smuzhiyun 	regs->uregs[pcreg] = autask->backup;
102*4882a593Smuzhiyun }
103*4882a593Smuzhiyun 
104*4882a593Smuzhiyun enum probes_insn
decode_pc_ro(probes_opcode_t insn,struct arch_probes_insn * asi,const struct decode_header * d)105*4882a593Smuzhiyun decode_pc_ro(probes_opcode_t insn, struct arch_probes_insn *asi,
106*4882a593Smuzhiyun 	     const struct decode_header *d)
107*4882a593Smuzhiyun {
108*4882a593Smuzhiyun 	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
109*4882a593Smuzhiyun 						   asi);
110*4882a593Smuzhiyun 	struct decode_emulate *decode = (struct decode_emulate *) d;
111*4882a593Smuzhiyun 	u32 regs = decode->header.type_regs.bits >> DECODE_TYPE_BITS;
112*4882a593Smuzhiyun 	int reg;
113*4882a593Smuzhiyun 
114*4882a593Smuzhiyun 	reg = uprobes_substitute_pc(&auprobe->ixol[0], regs);
115*4882a593Smuzhiyun 	if (reg == 15)
116*4882a593Smuzhiyun 		return INSN_GOOD;
117*4882a593Smuzhiyun 
118*4882a593Smuzhiyun 	if (reg == -1)
119*4882a593Smuzhiyun 		return INSN_REJECTED;
120*4882a593Smuzhiyun 
121*4882a593Smuzhiyun 	auprobe->pcreg = reg;
122*4882a593Smuzhiyun 	auprobe->prehandler = uprobe_set_pc;
123*4882a593Smuzhiyun 	auprobe->posthandler = uprobe_unset_pc;
124*4882a593Smuzhiyun 
125*4882a593Smuzhiyun 	return INSN_GOOD;
126*4882a593Smuzhiyun }
127*4882a593Smuzhiyun 
128*4882a593Smuzhiyun enum probes_insn
decode_wb_pc(probes_opcode_t insn,struct arch_probes_insn * asi,const struct decode_header * d,bool alu)129*4882a593Smuzhiyun decode_wb_pc(probes_opcode_t insn, struct arch_probes_insn *asi,
130*4882a593Smuzhiyun 	     const struct decode_header *d, bool alu)
131*4882a593Smuzhiyun {
132*4882a593Smuzhiyun 	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
133*4882a593Smuzhiyun 						   asi);
134*4882a593Smuzhiyun 	enum probes_insn ret = decode_pc_ro(insn, asi, d);
135*4882a593Smuzhiyun 
136*4882a593Smuzhiyun 	if (((insn >> 12) & 0xf) == 15)
137*4882a593Smuzhiyun 		auprobe->posthandler = alu ? uprobe_aluwrite_pc
138*4882a593Smuzhiyun 					   : uprobe_write_pc;
139*4882a593Smuzhiyun 
140*4882a593Smuzhiyun 	return ret;
141*4882a593Smuzhiyun }
142*4882a593Smuzhiyun 
143*4882a593Smuzhiyun enum probes_insn
decode_rd12rn16rm0rs8_rwflags(probes_opcode_t insn,struct arch_probes_insn * asi,const struct decode_header * d)144*4882a593Smuzhiyun decode_rd12rn16rm0rs8_rwflags(probes_opcode_t insn,
145*4882a593Smuzhiyun 			      struct arch_probes_insn *asi,
146*4882a593Smuzhiyun 			      const struct decode_header *d)
147*4882a593Smuzhiyun {
148*4882a593Smuzhiyun 	return decode_wb_pc(insn, asi, d, true);
149*4882a593Smuzhiyun }
150*4882a593Smuzhiyun 
151*4882a593Smuzhiyun enum probes_insn
decode_ldr(probes_opcode_t insn,struct arch_probes_insn * asi,const struct decode_header * d)152*4882a593Smuzhiyun decode_ldr(probes_opcode_t insn, struct arch_probes_insn *asi,
153*4882a593Smuzhiyun 	   const struct decode_header *d)
154*4882a593Smuzhiyun {
155*4882a593Smuzhiyun 	return decode_wb_pc(insn, asi, d, false);
156*4882a593Smuzhiyun }
157*4882a593Smuzhiyun 
158*4882a593Smuzhiyun enum probes_insn
uprobe_decode_ldmstm(probes_opcode_t insn,struct arch_probes_insn * asi,const struct decode_header * d)159*4882a593Smuzhiyun uprobe_decode_ldmstm(probes_opcode_t insn,
160*4882a593Smuzhiyun 		     struct arch_probes_insn *asi,
161*4882a593Smuzhiyun 		     const struct decode_header *d)
162*4882a593Smuzhiyun {
163*4882a593Smuzhiyun 	struct arch_uprobe *auprobe = container_of(asi, struct arch_uprobe,
164*4882a593Smuzhiyun 						   asi);
165*4882a593Smuzhiyun 	unsigned reglist = insn & 0xffff;
166*4882a593Smuzhiyun 	int rn = (insn >> 16) & 0xf;
167*4882a593Smuzhiyun 	int lbit = insn & (1 << 20);
168*4882a593Smuzhiyun 	unsigned used = reglist | (1 << rn);
169*4882a593Smuzhiyun 
170*4882a593Smuzhiyun 	if (rn == 15)
171*4882a593Smuzhiyun 		return INSN_REJECTED;
172*4882a593Smuzhiyun 
173*4882a593Smuzhiyun 	if (!(used & (1 << 15)))
174*4882a593Smuzhiyun 		return INSN_GOOD;
175*4882a593Smuzhiyun 
176*4882a593Smuzhiyun 	if (used & (1 << 14))
177*4882a593Smuzhiyun 		return INSN_REJECTED;
178*4882a593Smuzhiyun 
179*4882a593Smuzhiyun 	/* Use LR instead of PC */
180*4882a593Smuzhiyun 	insn ^= 0xc000;
181*4882a593Smuzhiyun 
182*4882a593Smuzhiyun 	auprobe->pcreg = 14;
183*4882a593Smuzhiyun 	auprobe->ixol[0] = __opcode_to_mem_arm(insn);
184*4882a593Smuzhiyun 
185*4882a593Smuzhiyun 	auprobe->prehandler = uprobe_set_pc;
186*4882a593Smuzhiyun 	if (lbit)
187*4882a593Smuzhiyun 		auprobe->posthandler = uprobe_write_pc;
188*4882a593Smuzhiyun 	else
189*4882a593Smuzhiyun 		auprobe->posthandler = uprobe_unset_pc;
190*4882a593Smuzhiyun 
191*4882a593Smuzhiyun 	return INSN_GOOD;
192*4882a593Smuzhiyun }
193*4882a593Smuzhiyun 
194*4882a593Smuzhiyun const union decode_action uprobes_probes_actions[] = {
195*4882a593Smuzhiyun 	[PROBES_PRELOAD_IMM] = {.handler = probes_simulate_nop},
196*4882a593Smuzhiyun 	[PROBES_PRELOAD_REG] = {.handler = probes_simulate_nop},
197*4882a593Smuzhiyun 	[PROBES_BRANCH_IMM] = {.handler = simulate_blx1},
198*4882a593Smuzhiyun 	[PROBES_MRS] = {.handler = simulate_mrs},
199*4882a593Smuzhiyun 	[PROBES_BRANCH_REG] = {.handler = simulate_blx2bx},
200*4882a593Smuzhiyun 	[PROBES_CLZ] = {.handler = probes_simulate_nop},
201*4882a593Smuzhiyun 	[PROBES_SATURATING_ARITHMETIC] = {.handler = probes_simulate_nop},
202*4882a593Smuzhiyun 	[PROBES_MUL1] = {.handler = probes_simulate_nop},
203*4882a593Smuzhiyun 	[PROBES_MUL2] = {.handler = probes_simulate_nop},
204*4882a593Smuzhiyun 	[PROBES_SWP] = {.handler = probes_simulate_nop},
205*4882a593Smuzhiyun 	[PROBES_LDRSTRD] = {.decoder = decode_pc_ro},
206*4882a593Smuzhiyun 	[PROBES_LOAD_EXTRA] = {.decoder = decode_pc_ro},
207*4882a593Smuzhiyun 	[PROBES_LOAD] = {.decoder = decode_ldr},
208*4882a593Smuzhiyun 	[PROBES_STORE_EXTRA] = {.decoder = decode_pc_ro},
209*4882a593Smuzhiyun 	[PROBES_STORE] = {.decoder = decode_pc_ro},
210*4882a593Smuzhiyun 	[PROBES_MOV_IP_SP] = {.handler = simulate_mov_ipsp},
211*4882a593Smuzhiyun 	[PROBES_DATA_PROCESSING_REG] = {
212*4882a593Smuzhiyun 		.decoder = decode_rd12rn16rm0rs8_rwflags},
213*4882a593Smuzhiyun 	[PROBES_DATA_PROCESSING_IMM] = {
214*4882a593Smuzhiyun 		.decoder = decode_rd12rn16rm0rs8_rwflags},
215*4882a593Smuzhiyun 	[PROBES_MOV_HALFWORD] = {.handler = probes_simulate_nop},
216*4882a593Smuzhiyun 	[PROBES_SEV] = {.handler = probes_simulate_nop},
217*4882a593Smuzhiyun 	[PROBES_WFE] = {.handler = probes_simulate_nop},
218*4882a593Smuzhiyun 	[PROBES_SATURATE] = {.handler = probes_simulate_nop},
219*4882a593Smuzhiyun 	[PROBES_REV] = {.handler = probes_simulate_nop},
220*4882a593Smuzhiyun 	[PROBES_MMI] = {.handler = probes_simulate_nop},
221*4882a593Smuzhiyun 	[PROBES_PACK] = {.handler = probes_simulate_nop},
222*4882a593Smuzhiyun 	[PROBES_EXTEND] = {.handler = probes_simulate_nop},
223*4882a593Smuzhiyun 	[PROBES_EXTEND_ADD] = {.handler = probes_simulate_nop},
224*4882a593Smuzhiyun 	[PROBES_MUL_ADD_LONG] = {.handler = probes_simulate_nop},
225*4882a593Smuzhiyun 	[PROBES_MUL_ADD] = {.handler = probes_simulate_nop},
226*4882a593Smuzhiyun 	[PROBES_BITFIELD] = {.handler = probes_simulate_nop},
227*4882a593Smuzhiyun 	[PROBES_BRANCH] = {.handler = simulate_bbl},
228*4882a593Smuzhiyun 	[PROBES_LDMSTM] = {.decoder = uprobe_decode_ldmstm}
229*4882a593Smuzhiyun };
230