1*4882a593Smuzhiyun /*
2*4882a593Smuzhiyun * Just-In-Time compiler for BPF filters on MIPS
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * Copyright (c) 2014 Imagination Technologies Ltd.
5*4882a593Smuzhiyun * Author: Markos Chandras <markos.chandras@imgtec.com>
6*4882a593Smuzhiyun *
7*4882a593Smuzhiyun * This program is free software; you can redistribute it and/or modify it
8*4882a593Smuzhiyun * under the terms of the GNU General Public License as published by the
9*4882a593Smuzhiyun * Free Software Foundation; version 2 of the License.
10*4882a593Smuzhiyun */
11*4882a593Smuzhiyun
12*4882a593Smuzhiyun #include <linux/bitops.h>
13*4882a593Smuzhiyun #include <linux/compiler.h>
14*4882a593Smuzhiyun #include <linux/errno.h>
15*4882a593Smuzhiyun #include <linux/filter.h>
16*4882a593Smuzhiyun #include <linux/if_vlan.h>
17*4882a593Smuzhiyun #include <linux/moduleloader.h>
18*4882a593Smuzhiyun #include <linux/netdevice.h>
19*4882a593Smuzhiyun #include <linux/string.h>
20*4882a593Smuzhiyun #include <linux/slab.h>
21*4882a593Smuzhiyun #include <linux/types.h>
22*4882a593Smuzhiyun #include <asm/asm.h>
23*4882a593Smuzhiyun #include <asm/bitops.h>
24*4882a593Smuzhiyun #include <asm/cacheflush.h>
25*4882a593Smuzhiyun #include <asm/cpu-features.h>
26*4882a593Smuzhiyun #include <asm/uasm.h>
27*4882a593Smuzhiyun
28*4882a593Smuzhiyun #include "bpf_jit.h"
29*4882a593Smuzhiyun
30*4882a593Smuzhiyun /* ABI
31*4882a593Smuzhiyun * r_skb_hl SKB header length
32*4882a593Smuzhiyun * r_data SKB data pointer
33*4882a593Smuzhiyun * r_off Offset
34*4882a593Smuzhiyun * r_A BPF register A
35*4882a593Smuzhiyun * r_X BPF register X
36*4882a593Smuzhiyun * r_skb *skb
37*4882a593Smuzhiyun * r_M *scratch memory
38*4882a593Smuzhiyun * r_skb_len SKB length
39*4882a593Smuzhiyun *
40*4882a593Smuzhiyun * On entry (*bpf_func)(*skb, *filter)
41*4882a593Smuzhiyun * a0 = MIPS_R_A0 = skb;
42*4882a593Smuzhiyun * a1 = MIPS_R_A1 = filter;
43*4882a593Smuzhiyun *
44*4882a593Smuzhiyun * Stack
45*4882a593Smuzhiyun * ...
46*4882a593Smuzhiyun * M[15]
47*4882a593Smuzhiyun * M[14]
48*4882a593Smuzhiyun * M[13]
49*4882a593Smuzhiyun * ...
50*4882a593Smuzhiyun * M[0] <-- r_M
51*4882a593Smuzhiyun * saved reg k-1
52*4882a593Smuzhiyun * saved reg k-2
53*4882a593Smuzhiyun * ...
54*4882a593Smuzhiyun * saved reg 0 <-- r_sp
55*4882a593Smuzhiyun * <no argument area>
56*4882a593Smuzhiyun *
57*4882a593Smuzhiyun * Packet layout
58*4882a593Smuzhiyun *
59*4882a593Smuzhiyun * <--------------------- len ------------------------>
60*4882a593Smuzhiyun * <--skb-len(r_skb_hl)-->< ----- skb->data_len ------>
61*4882a593Smuzhiyun * ----------------------------------------------------
62*4882a593Smuzhiyun * | skb->data |
63*4882a593Smuzhiyun * ----------------------------------------------------
64*4882a593Smuzhiyun */
65*4882a593Smuzhiyun
66*4882a593Smuzhiyun #define ptr typeof(unsigned long)
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun #define SCRATCH_OFF(k) (4 * (k))
69*4882a593Smuzhiyun
70*4882a593Smuzhiyun /* JIT flags */
71*4882a593Smuzhiyun #define SEEN_CALL (1 << BPF_MEMWORDS)
72*4882a593Smuzhiyun #define SEEN_SREG_SFT (BPF_MEMWORDS + 1)
73*4882a593Smuzhiyun #define SEEN_SREG_BASE (1 << SEEN_SREG_SFT)
74*4882a593Smuzhiyun #define SEEN_SREG(x) (SEEN_SREG_BASE << (x))
75*4882a593Smuzhiyun #define SEEN_OFF SEEN_SREG(2)
76*4882a593Smuzhiyun #define SEEN_A SEEN_SREG(3)
77*4882a593Smuzhiyun #define SEEN_X SEEN_SREG(4)
78*4882a593Smuzhiyun #define SEEN_SKB SEEN_SREG(5)
79*4882a593Smuzhiyun #define SEEN_MEM SEEN_SREG(6)
80*4882a593Smuzhiyun /* SEEN_SK_DATA also implies skb_hl an skb_len */
81*4882a593Smuzhiyun #define SEEN_SKB_DATA (SEEN_SREG(7) | SEEN_SREG(1) | SEEN_SREG(0))
82*4882a593Smuzhiyun
83*4882a593Smuzhiyun /* Arguments used by JIT */
84*4882a593Smuzhiyun #define ARGS_USED_BY_JIT 2 /* only applicable to 64-bit */
85*4882a593Smuzhiyun
86*4882a593Smuzhiyun #define SBIT(x) (1 << (x)) /* Signed version of BIT() */
87*4882a593Smuzhiyun
88*4882a593Smuzhiyun /**
89*4882a593Smuzhiyun * struct jit_ctx - JIT context
90*4882a593Smuzhiyun * @skf: The sk_filter
91*4882a593Smuzhiyun * @prologue_bytes: Number of bytes for prologue
92*4882a593Smuzhiyun * @idx: Instruction index
93*4882a593Smuzhiyun * @flags: JIT flags
94*4882a593Smuzhiyun * @offsets: Instruction offsets
95*4882a593Smuzhiyun * @target: Memory location for the compiled filter
96*4882a593Smuzhiyun */
97*4882a593Smuzhiyun struct jit_ctx {
98*4882a593Smuzhiyun const struct bpf_prog *skf;
99*4882a593Smuzhiyun unsigned int prologue_bytes;
100*4882a593Smuzhiyun u32 idx;
101*4882a593Smuzhiyun u32 flags;
102*4882a593Smuzhiyun u32 *offsets;
103*4882a593Smuzhiyun u32 *target;
104*4882a593Smuzhiyun };
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun
optimize_div(u32 * k)107*4882a593Smuzhiyun static inline int optimize_div(u32 *k)
108*4882a593Smuzhiyun {
109*4882a593Smuzhiyun /* power of 2 divides can be implemented with right shift */
110*4882a593Smuzhiyun if (!(*k & (*k-1))) {
111*4882a593Smuzhiyun *k = ilog2(*k);
112*4882a593Smuzhiyun return 1;
113*4882a593Smuzhiyun }
114*4882a593Smuzhiyun
115*4882a593Smuzhiyun return 0;
116*4882a593Smuzhiyun }
117*4882a593Smuzhiyun
118*4882a593Smuzhiyun static inline void emit_jit_reg_move(ptr dst, ptr src, struct jit_ctx *ctx);
119*4882a593Smuzhiyun
120*4882a593Smuzhiyun /* Simply emit the instruction if the JIT memory space has been allocated */
121*4882a593Smuzhiyun #define emit_instr(ctx, func, ...) \
122*4882a593Smuzhiyun do { \
123*4882a593Smuzhiyun if ((ctx)->target != NULL) { \
124*4882a593Smuzhiyun u32 *p = &(ctx)->target[ctx->idx]; \
125*4882a593Smuzhiyun uasm_i_##func(&p, ##__VA_ARGS__); \
126*4882a593Smuzhiyun } \
127*4882a593Smuzhiyun (ctx)->idx++; \
128*4882a593Smuzhiyun } while (0)
129*4882a593Smuzhiyun
130*4882a593Smuzhiyun /*
131*4882a593Smuzhiyun * Similar to emit_instr but it must be used when we need to emit
132*4882a593Smuzhiyun * 32-bit or 64-bit instructions
133*4882a593Smuzhiyun */
134*4882a593Smuzhiyun #define emit_long_instr(ctx, func, ...) \
135*4882a593Smuzhiyun do { \
136*4882a593Smuzhiyun if ((ctx)->target != NULL) { \
137*4882a593Smuzhiyun u32 *p = &(ctx)->target[ctx->idx]; \
138*4882a593Smuzhiyun UASM_i_##func(&p, ##__VA_ARGS__); \
139*4882a593Smuzhiyun } \
140*4882a593Smuzhiyun (ctx)->idx++; \
141*4882a593Smuzhiyun } while (0)
142*4882a593Smuzhiyun
143*4882a593Smuzhiyun /* Determine if immediate is within the 16-bit signed range */
is_range16(s32 imm)144*4882a593Smuzhiyun static inline bool is_range16(s32 imm)
145*4882a593Smuzhiyun {
146*4882a593Smuzhiyun return !(imm >= SBIT(15) || imm < -SBIT(15));
147*4882a593Smuzhiyun }
148*4882a593Smuzhiyun
emit_addu(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)149*4882a593Smuzhiyun static inline void emit_addu(unsigned int dst, unsigned int src1,
150*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
151*4882a593Smuzhiyun {
152*4882a593Smuzhiyun emit_instr(ctx, addu, dst, src1, src2);
153*4882a593Smuzhiyun }
154*4882a593Smuzhiyun
emit_nop(struct jit_ctx * ctx)155*4882a593Smuzhiyun static inline void emit_nop(struct jit_ctx *ctx)
156*4882a593Smuzhiyun {
157*4882a593Smuzhiyun emit_instr(ctx, nop);
158*4882a593Smuzhiyun }
159*4882a593Smuzhiyun
160*4882a593Smuzhiyun /* Load a u32 immediate to a register */
emit_load_imm(unsigned int dst,u32 imm,struct jit_ctx * ctx)161*4882a593Smuzhiyun static inline void emit_load_imm(unsigned int dst, u32 imm, struct jit_ctx *ctx)
162*4882a593Smuzhiyun {
163*4882a593Smuzhiyun if (ctx->target != NULL) {
164*4882a593Smuzhiyun /* addiu can only handle s16 */
165*4882a593Smuzhiyun if (!is_range16(imm)) {
166*4882a593Smuzhiyun u32 *p = &ctx->target[ctx->idx];
167*4882a593Smuzhiyun uasm_i_lui(&p, r_tmp_imm, (s32)imm >> 16);
168*4882a593Smuzhiyun p = &ctx->target[ctx->idx + 1];
169*4882a593Smuzhiyun uasm_i_ori(&p, dst, r_tmp_imm, imm & 0xffff);
170*4882a593Smuzhiyun } else {
171*4882a593Smuzhiyun u32 *p = &ctx->target[ctx->idx];
172*4882a593Smuzhiyun uasm_i_addiu(&p, dst, r_zero, imm);
173*4882a593Smuzhiyun }
174*4882a593Smuzhiyun }
175*4882a593Smuzhiyun ctx->idx++;
176*4882a593Smuzhiyun
177*4882a593Smuzhiyun if (!is_range16(imm))
178*4882a593Smuzhiyun ctx->idx++;
179*4882a593Smuzhiyun }
180*4882a593Smuzhiyun
emit_or(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)181*4882a593Smuzhiyun static inline void emit_or(unsigned int dst, unsigned int src1,
182*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
183*4882a593Smuzhiyun {
184*4882a593Smuzhiyun emit_instr(ctx, or, dst, src1, src2);
185*4882a593Smuzhiyun }
186*4882a593Smuzhiyun
emit_ori(unsigned int dst,unsigned src,u32 imm,struct jit_ctx * ctx)187*4882a593Smuzhiyun static inline void emit_ori(unsigned int dst, unsigned src, u32 imm,
188*4882a593Smuzhiyun struct jit_ctx *ctx)
189*4882a593Smuzhiyun {
190*4882a593Smuzhiyun if (imm >= BIT(16)) {
191*4882a593Smuzhiyun emit_load_imm(r_tmp, imm, ctx);
192*4882a593Smuzhiyun emit_or(dst, src, r_tmp, ctx);
193*4882a593Smuzhiyun } else {
194*4882a593Smuzhiyun emit_instr(ctx, ori, dst, src, imm);
195*4882a593Smuzhiyun }
196*4882a593Smuzhiyun }
197*4882a593Smuzhiyun
emit_daddiu(unsigned int dst,unsigned int src,int imm,struct jit_ctx * ctx)198*4882a593Smuzhiyun static inline void emit_daddiu(unsigned int dst, unsigned int src,
199*4882a593Smuzhiyun int imm, struct jit_ctx *ctx)
200*4882a593Smuzhiyun {
201*4882a593Smuzhiyun /*
202*4882a593Smuzhiyun * Only used for stack, so the imm is relatively small
203*4882a593Smuzhiyun * and it fits in 15-bits
204*4882a593Smuzhiyun */
205*4882a593Smuzhiyun emit_instr(ctx, daddiu, dst, src, imm);
206*4882a593Smuzhiyun }
207*4882a593Smuzhiyun
emit_addiu(unsigned int dst,unsigned int src,u32 imm,struct jit_ctx * ctx)208*4882a593Smuzhiyun static inline void emit_addiu(unsigned int dst, unsigned int src,
209*4882a593Smuzhiyun u32 imm, struct jit_ctx *ctx)
210*4882a593Smuzhiyun {
211*4882a593Smuzhiyun if (!is_range16(imm)) {
212*4882a593Smuzhiyun emit_load_imm(r_tmp, imm, ctx);
213*4882a593Smuzhiyun emit_addu(dst, r_tmp, src, ctx);
214*4882a593Smuzhiyun } else {
215*4882a593Smuzhiyun emit_instr(ctx, addiu, dst, src, imm);
216*4882a593Smuzhiyun }
217*4882a593Smuzhiyun }
218*4882a593Smuzhiyun
emit_and(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)219*4882a593Smuzhiyun static inline void emit_and(unsigned int dst, unsigned int src1,
220*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
221*4882a593Smuzhiyun {
222*4882a593Smuzhiyun emit_instr(ctx, and, dst, src1, src2);
223*4882a593Smuzhiyun }
224*4882a593Smuzhiyun
emit_andi(unsigned int dst,unsigned int src,u32 imm,struct jit_ctx * ctx)225*4882a593Smuzhiyun static inline void emit_andi(unsigned int dst, unsigned int src,
226*4882a593Smuzhiyun u32 imm, struct jit_ctx *ctx)
227*4882a593Smuzhiyun {
228*4882a593Smuzhiyun /* If imm does not fit in u16 then load it to register */
229*4882a593Smuzhiyun if (imm >= BIT(16)) {
230*4882a593Smuzhiyun emit_load_imm(r_tmp, imm, ctx);
231*4882a593Smuzhiyun emit_and(dst, src, r_tmp, ctx);
232*4882a593Smuzhiyun } else {
233*4882a593Smuzhiyun emit_instr(ctx, andi, dst, src, imm);
234*4882a593Smuzhiyun }
235*4882a593Smuzhiyun }
236*4882a593Smuzhiyun
emit_xor(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)237*4882a593Smuzhiyun static inline void emit_xor(unsigned int dst, unsigned int src1,
238*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
239*4882a593Smuzhiyun {
240*4882a593Smuzhiyun emit_instr(ctx, xor, dst, src1, src2);
241*4882a593Smuzhiyun }
242*4882a593Smuzhiyun
emit_xori(ptr dst,ptr src,u32 imm,struct jit_ctx * ctx)243*4882a593Smuzhiyun static inline void emit_xori(ptr dst, ptr src, u32 imm, struct jit_ctx *ctx)
244*4882a593Smuzhiyun {
245*4882a593Smuzhiyun /* If imm does not fit in u16 then load it to register */
246*4882a593Smuzhiyun if (imm >= BIT(16)) {
247*4882a593Smuzhiyun emit_load_imm(r_tmp, imm, ctx);
248*4882a593Smuzhiyun emit_xor(dst, src, r_tmp, ctx);
249*4882a593Smuzhiyun } else {
250*4882a593Smuzhiyun emit_instr(ctx, xori, dst, src, imm);
251*4882a593Smuzhiyun }
252*4882a593Smuzhiyun }
253*4882a593Smuzhiyun
emit_stack_offset(int offset,struct jit_ctx * ctx)254*4882a593Smuzhiyun static inline void emit_stack_offset(int offset, struct jit_ctx *ctx)
255*4882a593Smuzhiyun {
256*4882a593Smuzhiyun emit_long_instr(ctx, ADDIU, r_sp, r_sp, offset);
257*4882a593Smuzhiyun }
258*4882a593Smuzhiyun
emit_subu(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)259*4882a593Smuzhiyun static inline void emit_subu(unsigned int dst, unsigned int src1,
260*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
261*4882a593Smuzhiyun {
262*4882a593Smuzhiyun emit_instr(ctx, subu, dst, src1, src2);
263*4882a593Smuzhiyun }
264*4882a593Smuzhiyun
emit_neg(unsigned int reg,struct jit_ctx * ctx)265*4882a593Smuzhiyun static inline void emit_neg(unsigned int reg, struct jit_ctx *ctx)
266*4882a593Smuzhiyun {
267*4882a593Smuzhiyun emit_subu(reg, r_zero, reg, ctx);
268*4882a593Smuzhiyun }
269*4882a593Smuzhiyun
emit_sllv(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)270*4882a593Smuzhiyun static inline void emit_sllv(unsigned int dst, unsigned int src,
271*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
272*4882a593Smuzhiyun {
273*4882a593Smuzhiyun emit_instr(ctx, sllv, dst, src, sa);
274*4882a593Smuzhiyun }
275*4882a593Smuzhiyun
emit_sll(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)276*4882a593Smuzhiyun static inline void emit_sll(unsigned int dst, unsigned int src,
277*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
278*4882a593Smuzhiyun {
279*4882a593Smuzhiyun /* sa is 5-bits long */
280*4882a593Smuzhiyun if (sa >= BIT(5))
281*4882a593Smuzhiyun /* Shifting >= 32 results in zero */
282*4882a593Smuzhiyun emit_jit_reg_move(dst, r_zero, ctx);
283*4882a593Smuzhiyun else
284*4882a593Smuzhiyun emit_instr(ctx, sll, dst, src, sa);
285*4882a593Smuzhiyun }
286*4882a593Smuzhiyun
emit_srlv(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)287*4882a593Smuzhiyun static inline void emit_srlv(unsigned int dst, unsigned int src,
288*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
289*4882a593Smuzhiyun {
290*4882a593Smuzhiyun emit_instr(ctx, srlv, dst, src, sa);
291*4882a593Smuzhiyun }
292*4882a593Smuzhiyun
emit_srl(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)293*4882a593Smuzhiyun static inline void emit_srl(unsigned int dst, unsigned int src,
294*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
295*4882a593Smuzhiyun {
296*4882a593Smuzhiyun /* sa is 5-bits long */
297*4882a593Smuzhiyun if (sa >= BIT(5))
298*4882a593Smuzhiyun /* Shifting >= 32 results in zero */
299*4882a593Smuzhiyun emit_jit_reg_move(dst, r_zero, ctx);
300*4882a593Smuzhiyun else
301*4882a593Smuzhiyun emit_instr(ctx, srl, dst, src, sa);
302*4882a593Smuzhiyun }
303*4882a593Smuzhiyun
emit_slt(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)304*4882a593Smuzhiyun static inline void emit_slt(unsigned int dst, unsigned int src1,
305*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
306*4882a593Smuzhiyun {
307*4882a593Smuzhiyun emit_instr(ctx, slt, dst, src1, src2);
308*4882a593Smuzhiyun }
309*4882a593Smuzhiyun
emit_sltu(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)310*4882a593Smuzhiyun static inline void emit_sltu(unsigned int dst, unsigned int src1,
311*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
312*4882a593Smuzhiyun {
313*4882a593Smuzhiyun emit_instr(ctx, sltu, dst, src1, src2);
314*4882a593Smuzhiyun }
315*4882a593Smuzhiyun
emit_sltiu(unsigned dst,unsigned int src,unsigned int imm,struct jit_ctx * ctx)316*4882a593Smuzhiyun static inline void emit_sltiu(unsigned dst, unsigned int src,
317*4882a593Smuzhiyun unsigned int imm, struct jit_ctx *ctx)
318*4882a593Smuzhiyun {
319*4882a593Smuzhiyun /* 16 bit immediate */
320*4882a593Smuzhiyun if (!is_range16((s32)imm)) {
321*4882a593Smuzhiyun emit_load_imm(r_tmp, imm, ctx);
322*4882a593Smuzhiyun emit_sltu(dst, src, r_tmp, ctx);
323*4882a593Smuzhiyun } else {
324*4882a593Smuzhiyun emit_instr(ctx, sltiu, dst, src, imm);
325*4882a593Smuzhiyun }
326*4882a593Smuzhiyun
327*4882a593Smuzhiyun }
328*4882a593Smuzhiyun
329*4882a593Smuzhiyun /* Store register on the stack */
emit_store_stack_reg(ptr reg,ptr base,unsigned int offset,struct jit_ctx * ctx)330*4882a593Smuzhiyun static inline void emit_store_stack_reg(ptr reg, ptr base,
331*4882a593Smuzhiyun unsigned int offset,
332*4882a593Smuzhiyun struct jit_ctx *ctx)
333*4882a593Smuzhiyun {
334*4882a593Smuzhiyun emit_long_instr(ctx, SW, reg, offset, base);
335*4882a593Smuzhiyun }
336*4882a593Smuzhiyun
emit_store(ptr reg,ptr base,unsigned int offset,struct jit_ctx * ctx)337*4882a593Smuzhiyun static inline void emit_store(ptr reg, ptr base, unsigned int offset,
338*4882a593Smuzhiyun struct jit_ctx *ctx)
339*4882a593Smuzhiyun {
340*4882a593Smuzhiyun emit_instr(ctx, sw, reg, offset, base);
341*4882a593Smuzhiyun }
342*4882a593Smuzhiyun
emit_load_stack_reg(ptr reg,ptr base,unsigned int offset,struct jit_ctx * ctx)343*4882a593Smuzhiyun static inline void emit_load_stack_reg(ptr reg, ptr base,
344*4882a593Smuzhiyun unsigned int offset,
345*4882a593Smuzhiyun struct jit_ctx *ctx)
346*4882a593Smuzhiyun {
347*4882a593Smuzhiyun emit_long_instr(ctx, LW, reg, offset, base);
348*4882a593Smuzhiyun }
349*4882a593Smuzhiyun
emit_load(unsigned int reg,unsigned int base,unsigned int offset,struct jit_ctx * ctx)350*4882a593Smuzhiyun static inline void emit_load(unsigned int reg, unsigned int base,
351*4882a593Smuzhiyun unsigned int offset, struct jit_ctx *ctx)
352*4882a593Smuzhiyun {
353*4882a593Smuzhiyun emit_instr(ctx, lw, reg, offset, base);
354*4882a593Smuzhiyun }
355*4882a593Smuzhiyun
emit_load_byte(unsigned int reg,unsigned int base,unsigned int offset,struct jit_ctx * ctx)356*4882a593Smuzhiyun static inline void emit_load_byte(unsigned int reg, unsigned int base,
357*4882a593Smuzhiyun unsigned int offset, struct jit_ctx *ctx)
358*4882a593Smuzhiyun {
359*4882a593Smuzhiyun emit_instr(ctx, lb, reg, offset, base);
360*4882a593Smuzhiyun }
361*4882a593Smuzhiyun
emit_half_load(unsigned int reg,unsigned int base,unsigned int offset,struct jit_ctx * ctx)362*4882a593Smuzhiyun static inline void emit_half_load(unsigned int reg, unsigned int base,
363*4882a593Smuzhiyun unsigned int offset, struct jit_ctx *ctx)
364*4882a593Smuzhiyun {
365*4882a593Smuzhiyun emit_instr(ctx, lh, reg, offset, base);
366*4882a593Smuzhiyun }
367*4882a593Smuzhiyun
emit_half_load_unsigned(unsigned int reg,unsigned int base,unsigned int offset,struct jit_ctx * ctx)368*4882a593Smuzhiyun static inline void emit_half_load_unsigned(unsigned int reg, unsigned int base,
369*4882a593Smuzhiyun unsigned int offset, struct jit_ctx *ctx)
370*4882a593Smuzhiyun {
371*4882a593Smuzhiyun emit_instr(ctx, lhu, reg, offset, base);
372*4882a593Smuzhiyun }
373*4882a593Smuzhiyun
emit_mul(unsigned int dst,unsigned int src1,unsigned int src2,struct jit_ctx * ctx)374*4882a593Smuzhiyun static inline void emit_mul(unsigned int dst, unsigned int src1,
375*4882a593Smuzhiyun unsigned int src2, struct jit_ctx *ctx)
376*4882a593Smuzhiyun {
377*4882a593Smuzhiyun emit_instr(ctx, mul, dst, src1, src2);
378*4882a593Smuzhiyun }
379*4882a593Smuzhiyun
emit_div(unsigned int dst,unsigned int src,struct jit_ctx * ctx)380*4882a593Smuzhiyun static inline void emit_div(unsigned int dst, unsigned int src,
381*4882a593Smuzhiyun struct jit_ctx *ctx)
382*4882a593Smuzhiyun {
383*4882a593Smuzhiyun if (ctx->target != NULL) {
384*4882a593Smuzhiyun u32 *p = &ctx->target[ctx->idx];
385*4882a593Smuzhiyun uasm_i_divu(&p, dst, src);
386*4882a593Smuzhiyun p = &ctx->target[ctx->idx + 1];
387*4882a593Smuzhiyun uasm_i_mflo(&p, dst);
388*4882a593Smuzhiyun }
389*4882a593Smuzhiyun ctx->idx += 2; /* 2 insts */
390*4882a593Smuzhiyun }
391*4882a593Smuzhiyun
emit_mod(unsigned int dst,unsigned int src,struct jit_ctx * ctx)392*4882a593Smuzhiyun static inline void emit_mod(unsigned int dst, unsigned int src,
393*4882a593Smuzhiyun struct jit_ctx *ctx)
394*4882a593Smuzhiyun {
395*4882a593Smuzhiyun if (ctx->target != NULL) {
396*4882a593Smuzhiyun u32 *p = &ctx->target[ctx->idx];
397*4882a593Smuzhiyun uasm_i_divu(&p, dst, src);
398*4882a593Smuzhiyun p = &ctx->target[ctx->idx + 1];
399*4882a593Smuzhiyun uasm_i_mfhi(&p, dst);
400*4882a593Smuzhiyun }
401*4882a593Smuzhiyun ctx->idx += 2; /* 2 insts */
402*4882a593Smuzhiyun }
403*4882a593Smuzhiyun
emit_dsll(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)404*4882a593Smuzhiyun static inline void emit_dsll(unsigned int dst, unsigned int src,
405*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
406*4882a593Smuzhiyun {
407*4882a593Smuzhiyun emit_instr(ctx, dsll, dst, src, sa);
408*4882a593Smuzhiyun }
409*4882a593Smuzhiyun
emit_dsrl32(unsigned int dst,unsigned int src,unsigned int sa,struct jit_ctx * ctx)410*4882a593Smuzhiyun static inline void emit_dsrl32(unsigned int dst, unsigned int src,
411*4882a593Smuzhiyun unsigned int sa, struct jit_ctx *ctx)
412*4882a593Smuzhiyun {
413*4882a593Smuzhiyun emit_instr(ctx, dsrl32, dst, src, sa);
414*4882a593Smuzhiyun }
415*4882a593Smuzhiyun
emit_wsbh(unsigned int dst,unsigned int src,struct jit_ctx * ctx)416*4882a593Smuzhiyun static inline void emit_wsbh(unsigned int dst, unsigned int src,
417*4882a593Smuzhiyun struct jit_ctx *ctx)
418*4882a593Smuzhiyun {
419*4882a593Smuzhiyun emit_instr(ctx, wsbh, dst, src);
420*4882a593Smuzhiyun }
421*4882a593Smuzhiyun
422*4882a593Smuzhiyun /* load pointer to register */
emit_load_ptr(unsigned int dst,unsigned int src,int imm,struct jit_ctx * ctx)423*4882a593Smuzhiyun static inline void emit_load_ptr(unsigned int dst, unsigned int src,
424*4882a593Smuzhiyun int imm, struct jit_ctx *ctx)
425*4882a593Smuzhiyun {
426*4882a593Smuzhiyun /* src contains the base addr of the 32/64-pointer */
427*4882a593Smuzhiyun emit_long_instr(ctx, LW, dst, imm, src);
428*4882a593Smuzhiyun }
429*4882a593Smuzhiyun
430*4882a593Smuzhiyun /* load a function pointer to register */
emit_load_func(unsigned int reg,ptr imm,struct jit_ctx * ctx)431*4882a593Smuzhiyun static inline void emit_load_func(unsigned int reg, ptr imm,
432*4882a593Smuzhiyun struct jit_ctx *ctx)
433*4882a593Smuzhiyun {
434*4882a593Smuzhiyun if (IS_ENABLED(CONFIG_64BIT)) {
435*4882a593Smuzhiyun /* At this point imm is always 64-bit */
436*4882a593Smuzhiyun emit_load_imm(r_tmp, (u64)imm >> 32, ctx);
437*4882a593Smuzhiyun emit_dsll(r_tmp_imm, r_tmp, 16, ctx); /* left shift by 16 */
438*4882a593Smuzhiyun emit_ori(r_tmp, r_tmp_imm, (imm >> 16) & 0xffff, ctx);
439*4882a593Smuzhiyun emit_dsll(r_tmp_imm, r_tmp, 16, ctx); /* left shift by 16 */
440*4882a593Smuzhiyun emit_ori(reg, r_tmp_imm, imm & 0xffff, ctx);
441*4882a593Smuzhiyun } else {
442*4882a593Smuzhiyun emit_load_imm(reg, imm, ctx);
443*4882a593Smuzhiyun }
444*4882a593Smuzhiyun }
445*4882a593Smuzhiyun
446*4882a593Smuzhiyun /* Move to real MIPS register */
emit_reg_move(ptr dst,ptr src,struct jit_ctx * ctx)447*4882a593Smuzhiyun static inline void emit_reg_move(ptr dst, ptr src, struct jit_ctx *ctx)
448*4882a593Smuzhiyun {
449*4882a593Smuzhiyun emit_long_instr(ctx, ADDU, dst, src, r_zero);
450*4882a593Smuzhiyun }
451*4882a593Smuzhiyun
452*4882a593Smuzhiyun /* Move to JIT (32-bit) register */
emit_jit_reg_move(ptr dst,ptr src,struct jit_ctx * ctx)453*4882a593Smuzhiyun static inline void emit_jit_reg_move(ptr dst, ptr src, struct jit_ctx *ctx)
454*4882a593Smuzhiyun {
455*4882a593Smuzhiyun emit_addu(dst, src, r_zero, ctx);
456*4882a593Smuzhiyun }
457*4882a593Smuzhiyun
458*4882a593Smuzhiyun /* Compute the immediate value for PC-relative branches. */
b_imm(unsigned int tgt,struct jit_ctx * ctx)459*4882a593Smuzhiyun static inline u32 b_imm(unsigned int tgt, struct jit_ctx *ctx)
460*4882a593Smuzhiyun {
461*4882a593Smuzhiyun if (ctx->target == NULL)
462*4882a593Smuzhiyun return 0;
463*4882a593Smuzhiyun
464*4882a593Smuzhiyun /*
465*4882a593Smuzhiyun * We want a pc-relative branch. We only do forward branches
466*4882a593Smuzhiyun * so tgt is always after pc. tgt is the instruction offset
467*4882a593Smuzhiyun * we want to jump to.
468*4882a593Smuzhiyun
469*4882a593Smuzhiyun * Branch on MIPS:
470*4882a593Smuzhiyun * I: target_offset <- sign_extend(offset)
471*4882a593Smuzhiyun * I+1: PC += target_offset (delay slot)
472*4882a593Smuzhiyun *
473*4882a593Smuzhiyun * ctx->idx currently points to the branch instruction
474*4882a593Smuzhiyun * but the offset is added to the delay slot so we need
475*4882a593Smuzhiyun * to subtract 4.
476*4882a593Smuzhiyun */
477*4882a593Smuzhiyun return ctx->offsets[tgt] -
478*4882a593Smuzhiyun (ctx->idx * 4 - ctx->prologue_bytes) - 4;
479*4882a593Smuzhiyun }
480*4882a593Smuzhiyun
emit_bcond(int cond,unsigned int reg1,unsigned int reg2,unsigned int imm,struct jit_ctx * ctx)481*4882a593Smuzhiyun static inline void emit_bcond(int cond, unsigned int reg1, unsigned int reg2,
482*4882a593Smuzhiyun unsigned int imm, struct jit_ctx *ctx)
483*4882a593Smuzhiyun {
484*4882a593Smuzhiyun if (ctx->target != NULL) {
485*4882a593Smuzhiyun u32 *p = &ctx->target[ctx->idx];
486*4882a593Smuzhiyun
487*4882a593Smuzhiyun switch (cond) {
488*4882a593Smuzhiyun case MIPS_COND_EQ:
489*4882a593Smuzhiyun uasm_i_beq(&p, reg1, reg2, imm);
490*4882a593Smuzhiyun break;
491*4882a593Smuzhiyun case MIPS_COND_NE:
492*4882a593Smuzhiyun uasm_i_bne(&p, reg1, reg2, imm);
493*4882a593Smuzhiyun break;
494*4882a593Smuzhiyun case MIPS_COND_ALL:
495*4882a593Smuzhiyun uasm_i_b(&p, imm);
496*4882a593Smuzhiyun break;
497*4882a593Smuzhiyun default:
498*4882a593Smuzhiyun pr_warn("%s: Unhandled branch conditional: %d\n",
499*4882a593Smuzhiyun __func__, cond);
500*4882a593Smuzhiyun }
501*4882a593Smuzhiyun }
502*4882a593Smuzhiyun ctx->idx++;
503*4882a593Smuzhiyun }
504*4882a593Smuzhiyun
emit_b(unsigned int imm,struct jit_ctx * ctx)505*4882a593Smuzhiyun static inline void emit_b(unsigned int imm, struct jit_ctx *ctx)
506*4882a593Smuzhiyun {
507*4882a593Smuzhiyun emit_bcond(MIPS_COND_ALL, r_zero, r_zero, imm, ctx);
508*4882a593Smuzhiyun }
509*4882a593Smuzhiyun
emit_jalr(unsigned int link,unsigned int reg,struct jit_ctx * ctx)510*4882a593Smuzhiyun static inline void emit_jalr(unsigned int link, unsigned int reg,
511*4882a593Smuzhiyun struct jit_ctx *ctx)
512*4882a593Smuzhiyun {
513*4882a593Smuzhiyun emit_instr(ctx, jalr, link, reg);
514*4882a593Smuzhiyun }
515*4882a593Smuzhiyun
emit_jr(unsigned int reg,struct jit_ctx * ctx)516*4882a593Smuzhiyun static inline void emit_jr(unsigned int reg, struct jit_ctx *ctx)
517*4882a593Smuzhiyun {
518*4882a593Smuzhiyun emit_instr(ctx, jr, reg);
519*4882a593Smuzhiyun }
520*4882a593Smuzhiyun
align_sp(unsigned int num)521*4882a593Smuzhiyun static inline u16 align_sp(unsigned int num)
522*4882a593Smuzhiyun {
523*4882a593Smuzhiyun /* Double word alignment for 32-bit, quadword for 64-bit */
524*4882a593Smuzhiyun unsigned int align = IS_ENABLED(CONFIG_64BIT) ? 16 : 8;
525*4882a593Smuzhiyun num = (num + (align - 1)) & -align;
526*4882a593Smuzhiyun return num;
527*4882a593Smuzhiyun }
528*4882a593Smuzhiyun
save_bpf_jit_regs(struct jit_ctx * ctx,unsigned offset)529*4882a593Smuzhiyun static void save_bpf_jit_regs(struct jit_ctx *ctx, unsigned offset)
530*4882a593Smuzhiyun {
531*4882a593Smuzhiyun int i = 0, real_off = 0;
532*4882a593Smuzhiyun u32 sflags, tmp_flags;
533*4882a593Smuzhiyun
534*4882a593Smuzhiyun /* Adjust the stack pointer */
535*4882a593Smuzhiyun if (offset)
536*4882a593Smuzhiyun emit_stack_offset(-align_sp(offset), ctx);
537*4882a593Smuzhiyun
538*4882a593Smuzhiyun tmp_flags = sflags = ctx->flags >> SEEN_SREG_SFT;
539*4882a593Smuzhiyun /* sflags is essentially a bitmap */
540*4882a593Smuzhiyun while (tmp_flags) {
541*4882a593Smuzhiyun if ((sflags >> i) & 0x1) {
542*4882a593Smuzhiyun emit_store_stack_reg(MIPS_R_S0 + i, r_sp, real_off,
543*4882a593Smuzhiyun ctx);
544*4882a593Smuzhiyun real_off += SZREG;
545*4882a593Smuzhiyun }
546*4882a593Smuzhiyun i++;
547*4882a593Smuzhiyun tmp_flags >>= 1;
548*4882a593Smuzhiyun }
549*4882a593Smuzhiyun
550*4882a593Smuzhiyun /* save return address */
551*4882a593Smuzhiyun if (ctx->flags & SEEN_CALL) {
552*4882a593Smuzhiyun emit_store_stack_reg(r_ra, r_sp, real_off, ctx);
553*4882a593Smuzhiyun real_off += SZREG;
554*4882a593Smuzhiyun }
555*4882a593Smuzhiyun
556*4882a593Smuzhiyun /* Setup r_M leaving the alignment gap if necessary */
557*4882a593Smuzhiyun if (ctx->flags & SEEN_MEM) {
558*4882a593Smuzhiyun if (real_off % (SZREG * 2))
559*4882a593Smuzhiyun real_off += SZREG;
560*4882a593Smuzhiyun emit_long_instr(ctx, ADDIU, r_M, r_sp, real_off);
561*4882a593Smuzhiyun }
562*4882a593Smuzhiyun }
563*4882a593Smuzhiyun
restore_bpf_jit_regs(struct jit_ctx * ctx,unsigned int offset)564*4882a593Smuzhiyun static void restore_bpf_jit_regs(struct jit_ctx *ctx,
565*4882a593Smuzhiyun unsigned int offset)
566*4882a593Smuzhiyun {
567*4882a593Smuzhiyun int i, real_off = 0;
568*4882a593Smuzhiyun u32 sflags, tmp_flags;
569*4882a593Smuzhiyun
570*4882a593Smuzhiyun tmp_flags = sflags = ctx->flags >> SEEN_SREG_SFT;
571*4882a593Smuzhiyun /* sflags is a bitmap */
572*4882a593Smuzhiyun i = 0;
573*4882a593Smuzhiyun while (tmp_flags) {
574*4882a593Smuzhiyun if ((sflags >> i) & 0x1) {
575*4882a593Smuzhiyun emit_load_stack_reg(MIPS_R_S0 + i, r_sp, real_off,
576*4882a593Smuzhiyun ctx);
577*4882a593Smuzhiyun real_off += SZREG;
578*4882a593Smuzhiyun }
579*4882a593Smuzhiyun i++;
580*4882a593Smuzhiyun tmp_flags >>= 1;
581*4882a593Smuzhiyun }
582*4882a593Smuzhiyun
583*4882a593Smuzhiyun /* restore return address */
584*4882a593Smuzhiyun if (ctx->flags & SEEN_CALL)
585*4882a593Smuzhiyun emit_load_stack_reg(r_ra, r_sp, real_off, ctx);
586*4882a593Smuzhiyun
587*4882a593Smuzhiyun /* Restore the sp and discard the scrach memory */
588*4882a593Smuzhiyun if (offset)
589*4882a593Smuzhiyun emit_stack_offset(align_sp(offset), ctx);
590*4882a593Smuzhiyun }
591*4882a593Smuzhiyun
get_stack_depth(struct jit_ctx * ctx)592*4882a593Smuzhiyun static unsigned int get_stack_depth(struct jit_ctx *ctx)
593*4882a593Smuzhiyun {
594*4882a593Smuzhiyun int sp_off = 0;
595*4882a593Smuzhiyun
596*4882a593Smuzhiyun
597*4882a593Smuzhiyun /* How may s* regs do we need to preserved? */
598*4882a593Smuzhiyun sp_off += hweight32(ctx->flags >> SEEN_SREG_SFT) * SZREG;
599*4882a593Smuzhiyun
600*4882a593Smuzhiyun if (ctx->flags & SEEN_MEM)
601*4882a593Smuzhiyun sp_off += 4 * BPF_MEMWORDS; /* BPF_MEMWORDS are 32-bit */
602*4882a593Smuzhiyun
603*4882a593Smuzhiyun if (ctx->flags & SEEN_CALL)
604*4882a593Smuzhiyun sp_off += SZREG; /* Space for our ra register */
605*4882a593Smuzhiyun
606*4882a593Smuzhiyun return sp_off;
607*4882a593Smuzhiyun }
608*4882a593Smuzhiyun
build_prologue(struct jit_ctx * ctx)609*4882a593Smuzhiyun static void build_prologue(struct jit_ctx *ctx)
610*4882a593Smuzhiyun {
611*4882a593Smuzhiyun int sp_off;
612*4882a593Smuzhiyun
613*4882a593Smuzhiyun /* Calculate the total offset for the stack pointer */
614*4882a593Smuzhiyun sp_off = get_stack_depth(ctx);
615*4882a593Smuzhiyun save_bpf_jit_regs(ctx, sp_off);
616*4882a593Smuzhiyun
617*4882a593Smuzhiyun if (ctx->flags & SEEN_SKB)
618*4882a593Smuzhiyun emit_reg_move(r_skb, MIPS_R_A0, ctx);
619*4882a593Smuzhiyun
620*4882a593Smuzhiyun if (ctx->flags & SEEN_SKB_DATA) {
621*4882a593Smuzhiyun /* Load packet length */
622*4882a593Smuzhiyun emit_load(r_skb_len, r_skb, offsetof(struct sk_buff, len),
623*4882a593Smuzhiyun ctx);
624*4882a593Smuzhiyun emit_load(r_tmp, r_skb, offsetof(struct sk_buff, data_len),
625*4882a593Smuzhiyun ctx);
626*4882a593Smuzhiyun /* Load the data pointer */
627*4882a593Smuzhiyun emit_load_ptr(r_skb_data, r_skb,
628*4882a593Smuzhiyun offsetof(struct sk_buff, data), ctx);
629*4882a593Smuzhiyun /* Load the header length */
630*4882a593Smuzhiyun emit_subu(r_skb_hl, r_skb_len, r_tmp, ctx);
631*4882a593Smuzhiyun }
632*4882a593Smuzhiyun
633*4882a593Smuzhiyun if (ctx->flags & SEEN_X)
634*4882a593Smuzhiyun emit_jit_reg_move(r_X, r_zero, ctx);
635*4882a593Smuzhiyun
636*4882a593Smuzhiyun /*
637*4882a593Smuzhiyun * Do not leak kernel data to userspace, we only need to clear
638*4882a593Smuzhiyun * r_A if it is ever used. In fact if it is never used, we
639*4882a593Smuzhiyun * will not save/restore it, so clearing it in this case would
640*4882a593Smuzhiyun * corrupt the state of the caller.
641*4882a593Smuzhiyun */
642*4882a593Smuzhiyun if (bpf_needs_clear_a(&ctx->skf->insns[0]) &&
643*4882a593Smuzhiyun (ctx->flags & SEEN_A))
644*4882a593Smuzhiyun emit_jit_reg_move(r_A, r_zero, ctx);
645*4882a593Smuzhiyun }
646*4882a593Smuzhiyun
build_epilogue(struct jit_ctx * ctx)647*4882a593Smuzhiyun static void build_epilogue(struct jit_ctx *ctx)
648*4882a593Smuzhiyun {
649*4882a593Smuzhiyun unsigned int sp_off;
650*4882a593Smuzhiyun
651*4882a593Smuzhiyun /* Calculate the total offset for the stack pointer */
652*4882a593Smuzhiyun
653*4882a593Smuzhiyun sp_off = get_stack_depth(ctx);
654*4882a593Smuzhiyun restore_bpf_jit_regs(ctx, sp_off);
655*4882a593Smuzhiyun
656*4882a593Smuzhiyun /* Return */
657*4882a593Smuzhiyun emit_jr(r_ra, ctx);
658*4882a593Smuzhiyun emit_nop(ctx);
659*4882a593Smuzhiyun }
660*4882a593Smuzhiyun
661*4882a593Smuzhiyun #define CHOOSE_LOAD_FUNC(K, func) \
662*4882a593Smuzhiyun ((int)K < 0 ? ((int)K >= SKF_LL_OFF ? func##_negative : func) : \
663*4882a593Smuzhiyun func##_positive)
664*4882a593Smuzhiyun
is_bad_offset(int b_off)665*4882a593Smuzhiyun static bool is_bad_offset(int b_off)
666*4882a593Smuzhiyun {
667*4882a593Smuzhiyun return b_off > 0x1ffff || b_off < -0x20000;
668*4882a593Smuzhiyun }
669*4882a593Smuzhiyun
build_body(struct jit_ctx * ctx)670*4882a593Smuzhiyun static int build_body(struct jit_ctx *ctx)
671*4882a593Smuzhiyun {
672*4882a593Smuzhiyun const struct bpf_prog *prog = ctx->skf;
673*4882a593Smuzhiyun const struct sock_filter *inst;
674*4882a593Smuzhiyun unsigned int i, off, condt;
675*4882a593Smuzhiyun u32 k, b_off __maybe_unused;
676*4882a593Smuzhiyun u8 (*sk_load_func)(unsigned long *skb, int offset);
677*4882a593Smuzhiyun
678*4882a593Smuzhiyun for (i = 0; i < prog->len; i++) {
679*4882a593Smuzhiyun u16 code;
680*4882a593Smuzhiyun
681*4882a593Smuzhiyun inst = &(prog->insns[i]);
682*4882a593Smuzhiyun pr_debug("%s: code->0x%02x, jt->0x%x, jf->0x%x, k->0x%x\n",
683*4882a593Smuzhiyun __func__, inst->code, inst->jt, inst->jf, inst->k);
684*4882a593Smuzhiyun k = inst->k;
685*4882a593Smuzhiyun code = bpf_anc_helper(inst);
686*4882a593Smuzhiyun
687*4882a593Smuzhiyun if (ctx->target == NULL)
688*4882a593Smuzhiyun ctx->offsets[i] = ctx->idx * 4;
689*4882a593Smuzhiyun
690*4882a593Smuzhiyun switch (code) {
691*4882a593Smuzhiyun case BPF_LD | BPF_IMM:
692*4882a593Smuzhiyun /* A <- k ==> li r_A, k */
693*4882a593Smuzhiyun ctx->flags |= SEEN_A;
694*4882a593Smuzhiyun emit_load_imm(r_A, k, ctx);
695*4882a593Smuzhiyun break;
696*4882a593Smuzhiyun case BPF_LD | BPF_W | BPF_LEN:
697*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff, len) != 4);
698*4882a593Smuzhiyun /* A <- len ==> lw r_A, offset(skb) */
699*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
700*4882a593Smuzhiyun off = offsetof(struct sk_buff, len);
701*4882a593Smuzhiyun emit_load(r_A, r_skb, off, ctx);
702*4882a593Smuzhiyun break;
703*4882a593Smuzhiyun case BPF_LD | BPF_MEM:
704*4882a593Smuzhiyun /* A <- M[k] ==> lw r_A, offset(M) */
705*4882a593Smuzhiyun ctx->flags |= SEEN_MEM | SEEN_A;
706*4882a593Smuzhiyun emit_load(r_A, r_M, SCRATCH_OFF(k), ctx);
707*4882a593Smuzhiyun break;
708*4882a593Smuzhiyun case BPF_LD | BPF_W | BPF_ABS:
709*4882a593Smuzhiyun /* A <- P[k:4] */
710*4882a593Smuzhiyun sk_load_func = CHOOSE_LOAD_FUNC(k, sk_load_word);
711*4882a593Smuzhiyun goto load;
712*4882a593Smuzhiyun case BPF_LD | BPF_H | BPF_ABS:
713*4882a593Smuzhiyun /* A <- P[k:2] */
714*4882a593Smuzhiyun sk_load_func = CHOOSE_LOAD_FUNC(k, sk_load_half);
715*4882a593Smuzhiyun goto load;
716*4882a593Smuzhiyun case BPF_LD | BPF_B | BPF_ABS:
717*4882a593Smuzhiyun /* A <- P[k:1] */
718*4882a593Smuzhiyun sk_load_func = CHOOSE_LOAD_FUNC(k, sk_load_byte);
719*4882a593Smuzhiyun load:
720*4882a593Smuzhiyun emit_load_imm(r_off, k, ctx);
721*4882a593Smuzhiyun load_common:
722*4882a593Smuzhiyun ctx->flags |= SEEN_CALL | SEEN_OFF |
723*4882a593Smuzhiyun SEEN_SKB | SEEN_A | SEEN_SKB_DATA;
724*4882a593Smuzhiyun
725*4882a593Smuzhiyun emit_load_func(r_s0, (ptr)sk_load_func, ctx);
726*4882a593Smuzhiyun emit_reg_move(MIPS_R_A0, r_skb, ctx);
727*4882a593Smuzhiyun emit_jalr(MIPS_R_RA, r_s0, ctx);
728*4882a593Smuzhiyun /* Load second argument to delay slot */
729*4882a593Smuzhiyun emit_reg_move(MIPS_R_A1, r_off, ctx);
730*4882a593Smuzhiyun /* Check the error value */
731*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_ret, 0, b_imm(i + 1, ctx),
732*4882a593Smuzhiyun ctx);
733*4882a593Smuzhiyun /* Load return register on DS for failures */
734*4882a593Smuzhiyun emit_reg_move(r_ret, r_zero, ctx);
735*4882a593Smuzhiyun /* Return with error */
736*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
737*4882a593Smuzhiyun if (is_bad_offset(b_off))
738*4882a593Smuzhiyun return -E2BIG;
739*4882a593Smuzhiyun emit_b(b_off, ctx);
740*4882a593Smuzhiyun emit_nop(ctx);
741*4882a593Smuzhiyun break;
742*4882a593Smuzhiyun case BPF_LD | BPF_W | BPF_IND:
743*4882a593Smuzhiyun /* A <- P[X + k:4] */
744*4882a593Smuzhiyun sk_load_func = sk_load_word;
745*4882a593Smuzhiyun goto load_ind;
746*4882a593Smuzhiyun case BPF_LD | BPF_H | BPF_IND:
747*4882a593Smuzhiyun /* A <- P[X + k:2] */
748*4882a593Smuzhiyun sk_load_func = sk_load_half;
749*4882a593Smuzhiyun goto load_ind;
750*4882a593Smuzhiyun case BPF_LD | BPF_B | BPF_IND:
751*4882a593Smuzhiyun /* A <- P[X + k:1] */
752*4882a593Smuzhiyun sk_load_func = sk_load_byte;
753*4882a593Smuzhiyun load_ind:
754*4882a593Smuzhiyun ctx->flags |= SEEN_OFF | SEEN_X;
755*4882a593Smuzhiyun emit_addiu(r_off, r_X, k, ctx);
756*4882a593Smuzhiyun goto load_common;
757*4882a593Smuzhiyun case BPF_LDX | BPF_IMM:
758*4882a593Smuzhiyun /* X <- k */
759*4882a593Smuzhiyun ctx->flags |= SEEN_X;
760*4882a593Smuzhiyun emit_load_imm(r_X, k, ctx);
761*4882a593Smuzhiyun break;
762*4882a593Smuzhiyun case BPF_LDX | BPF_MEM:
763*4882a593Smuzhiyun /* X <- M[k] */
764*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_MEM;
765*4882a593Smuzhiyun emit_load(r_X, r_M, SCRATCH_OFF(k), ctx);
766*4882a593Smuzhiyun break;
767*4882a593Smuzhiyun case BPF_LDX | BPF_W | BPF_LEN:
768*4882a593Smuzhiyun /* X <- len */
769*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_SKB;
770*4882a593Smuzhiyun off = offsetof(struct sk_buff, len);
771*4882a593Smuzhiyun emit_load(r_X, r_skb, off, ctx);
772*4882a593Smuzhiyun break;
773*4882a593Smuzhiyun case BPF_LDX | BPF_B | BPF_MSH:
774*4882a593Smuzhiyun /* X <- 4 * (P[k:1] & 0xf) */
775*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_CALL | SEEN_SKB;
776*4882a593Smuzhiyun /* Load offset to a1 */
777*4882a593Smuzhiyun emit_load_func(r_s0, (ptr)sk_load_byte, ctx);
778*4882a593Smuzhiyun /*
779*4882a593Smuzhiyun * This may emit two instructions so it may not fit
780*4882a593Smuzhiyun * in the delay slot. So use a0 in the delay slot.
781*4882a593Smuzhiyun */
782*4882a593Smuzhiyun emit_load_imm(MIPS_R_A1, k, ctx);
783*4882a593Smuzhiyun emit_jalr(MIPS_R_RA, r_s0, ctx);
784*4882a593Smuzhiyun emit_reg_move(MIPS_R_A0, r_skb, ctx); /* delay slot */
785*4882a593Smuzhiyun /* Check the error value */
786*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
787*4882a593Smuzhiyun if (is_bad_offset(b_off))
788*4882a593Smuzhiyun return -E2BIG;
789*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_ret, 0, b_off, ctx);
790*4882a593Smuzhiyun emit_reg_move(r_ret, r_zero, ctx);
791*4882a593Smuzhiyun /* We are good */
792*4882a593Smuzhiyun /* X <- P[1:K] & 0xf */
793*4882a593Smuzhiyun emit_andi(r_X, r_A, 0xf, ctx);
794*4882a593Smuzhiyun /* X << 2 */
795*4882a593Smuzhiyun emit_b(b_imm(i + 1, ctx), ctx);
796*4882a593Smuzhiyun emit_sll(r_X, r_X, 2, ctx); /* delay slot */
797*4882a593Smuzhiyun break;
798*4882a593Smuzhiyun case BPF_ST:
799*4882a593Smuzhiyun /* M[k] <- A */
800*4882a593Smuzhiyun ctx->flags |= SEEN_MEM | SEEN_A;
801*4882a593Smuzhiyun emit_store(r_A, r_M, SCRATCH_OFF(k), ctx);
802*4882a593Smuzhiyun break;
803*4882a593Smuzhiyun case BPF_STX:
804*4882a593Smuzhiyun /* M[k] <- X */
805*4882a593Smuzhiyun ctx->flags |= SEEN_MEM | SEEN_X;
806*4882a593Smuzhiyun emit_store(r_X, r_M, SCRATCH_OFF(k), ctx);
807*4882a593Smuzhiyun break;
808*4882a593Smuzhiyun case BPF_ALU | BPF_ADD | BPF_K:
809*4882a593Smuzhiyun /* A += K */
810*4882a593Smuzhiyun ctx->flags |= SEEN_A;
811*4882a593Smuzhiyun emit_addiu(r_A, r_A, k, ctx);
812*4882a593Smuzhiyun break;
813*4882a593Smuzhiyun case BPF_ALU | BPF_ADD | BPF_X:
814*4882a593Smuzhiyun /* A += X */
815*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
816*4882a593Smuzhiyun emit_addu(r_A, r_A, r_X, ctx);
817*4882a593Smuzhiyun break;
818*4882a593Smuzhiyun case BPF_ALU | BPF_SUB | BPF_K:
819*4882a593Smuzhiyun /* A -= K */
820*4882a593Smuzhiyun ctx->flags |= SEEN_A;
821*4882a593Smuzhiyun emit_addiu(r_A, r_A, -k, ctx);
822*4882a593Smuzhiyun break;
823*4882a593Smuzhiyun case BPF_ALU | BPF_SUB | BPF_X:
824*4882a593Smuzhiyun /* A -= X */
825*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
826*4882a593Smuzhiyun emit_subu(r_A, r_A, r_X, ctx);
827*4882a593Smuzhiyun break;
828*4882a593Smuzhiyun case BPF_ALU | BPF_MUL | BPF_K:
829*4882a593Smuzhiyun /* A *= K */
830*4882a593Smuzhiyun /* Load K to scratch register before MUL */
831*4882a593Smuzhiyun ctx->flags |= SEEN_A;
832*4882a593Smuzhiyun emit_load_imm(r_s0, k, ctx);
833*4882a593Smuzhiyun emit_mul(r_A, r_A, r_s0, ctx);
834*4882a593Smuzhiyun break;
835*4882a593Smuzhiyun case BPF_ALU | BPF_MUL | BPF_X:
836*4882a593Smuzhiyun /* A *= X */
837*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
838*4882a593Smuzhiyun emit_mul(r_A, r_A, r_X, ctx);
839*4882a593Smuzhiyun break;
840*4882a593Smuzhiyun case BPF_ALU | BPF_DIV | BPF_K:
841*4882a593Smuzhiyun /* A /= k */
842*4882a593Smuzhiyun if (k == 1)
843*4882a593Smuzhiyun break;
844*4882a593Smuzhiyun if (optimize_div(&k)) {
845*4882a593Smuzhiyun ctx->flags |= SEEN_A;
846*4882a593Smuzhiyun emit_srl(r_A, r_A, k, ctx);
847*4882a593Smuzhiyun break;
848*4882a593Smuzhiyun }
849*4882a593Smuzhiyun ctx->flags |= SEEN_A;
850*4882a593Smuzhiyun emit_load_imm(r_s0, k, ctx);
851*4882a593Smuzhiyun emit_div(r_A, r_s0, ctx);
852*4882a593Smuzhiyun break;
853*4882a593Smuzhiyun case BPF_ALU | BPF_MOD | BPF_K:
854*4882a593Smuzhiyun /* A %= k */
855*4882a593Smuzhiyun if (k == 1) {
856*4882a593Smuzhiyun ctx->flags |= SEEN_A;
857*4882a593Smuzhiyun emit_jit_reg_move(r_A, r_zero, ctx);
858*4882a593Smuzhiyun } else {
859*4882a593Smuzhiyun ctx->flags |= SEEN_A;
860*4882a593Smuzhiyun emit_load_imm(r_s0, k, ctx);
861*4882a593Smuzhiyun emit_mod(r_A, r_s0, ctx);
862*4882a593Smuzhiyun }
863*4882a593Smuzhiyun break;
864*4882a593Smuzhiyun case BPF_ALU | BPF_DIV | BPF_X:
865*4882a593Smuzhiyun /* A /= X */
866*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_A;
867*4882a593Smuzhiyun /* Check if r_X is zero */
868*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
869*4882a593Smuzhiyun if (is_bad_offset(b_off))
870*4882a593Smuzhiyun return -E2BIG;
871*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_X, r_zero, b_off, ctx);
872*4882a593Smuzhiyun emit_load_imm(r_ret, 0, ctx); /* delay slot */
873*4882a593Smuzhiyun emit_div(r_A, r_X, ctx);
874*4882a593Smuzhiyun break;
875*4882a593Smuzhiyun case BPF_ALU | BPF_MOD | BPF_X:
876*4882a593Smuzhiyun /* A %= X */
877*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_A;
878*4882a593Smuzhiyun /* Check if r_X is zero */
879*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
880*4882a593Smuzhiyun if (is_bad_offset(b_off))
881*4882a593Smuzhiyun return -E2BIG;
882*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_X, r_zero, b_off, ctx);
883*4882a593Smuzhiyun emit_load_imm(r_ret, 0, ctx); /* delay slot */
884*4882a593Smuzhiyun emit_mod(r_A, r_X, ctx);
885*4882a593Smuzhiyun break;
886*4882a593Smuzhiyun case BPF_ALU | BPF_OR | BPF_K:
887*4882a593Smuzhiyun /* A |= K */
888*4882a593Smuzhiyun ctx->flags |= SEEN_A;
889*4882a593Smuzhiyun emit_ori(r_A, r_A, k, ctx);
890*4882a593Smuzhiyun break;
891*4882a593Smuzhiyun case BPF_ALU | BPF_OR | BPF_X:
892*4882a593Smuzhiyun /* A |= X */
893*4882a593Smuzhiyun ctx->flags |= SEEN_A;
894*4882a593Smuzhiyun emit_ori(r_A, r_A, r_X, ctx);
895*4882a593Smuzhiyun break;
896*4882a593Smuzhiyun case BPF_ALU | BPF_XOR | BPF_K:
897*4882a593Smuzhiyun /* A ^= k */
898*4882a593Smuzhiyun ctx->flags |= SEEN_A;
899*4882a593Smuzhiyun emit_xori(r_A, r_A, k, ctx);
900*4882a593Smuzhiyun break;
901*4882a593Smuzhiyun case BPF_ANC | SKF_AD_ALU_XOR_X:
902*4882a593Smuzhiyun case BPF_ALU | BPF_XOR | BPF_X:
903*4882a593Smuzhiyun /* A ^= X */
904*4882a593Smuzhiyun ctx->flags |= SEEN_A;
905*4882a593Smuzhiyun emit_xor(r_A, r_A, r_X, ctx);
906*4882a593Smuzhiyun break;
907*4882a593Smuzhiyun case BPF_ALU | BPF_AND | BPF_K:
908*4882a593Smuzhiyun /* A &= K */
909*4882a593Smuzhiyun ctx->flags |= SEEN_A;
910*4882a593Smuzhiyun emit_andi(r_A, r_A, k, ctx);
911*4882a593Smuzhiyun break;
912*4882a593Smuzhiyun case BPF_ALU | BPF_AND | BPF_X:
913*4882a593Smuzhiyun /* A &= X */
914*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
915*4882a593Smuzhiyun emit_and(r_A, r_A, r_X, ctx);
916*4882a593Smuzhiyun break;
917*4882a593Smuzhiyun case BPF_ALU | BPF_LSH | BPF_K:
918*4882a593Smuzhiyun /* A <<= K */
919*4882a593Smuzhiyun ctx->flags |= SEEN_A;
920*4882a593Smuzhiyun emit_sll(r_A, r_A, k, ctx);
921*4882a593Smuzhiyun break;
922*4882a593Smuzhiyun case BPF_ALU | BPF_LSH | BPF_X:
923*4882a593Smuzhiyun /* A <<= X */
924*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
925*4882a593Smuzhiyun emit_sllv(r_A, r_A, r_X, ctx);
926*4882a593Smuzhiyun break;
927*4882a593Smuzhiyun case BPF_ALU | BPF_RSH | BPF_K:
928*4882a593Smuzhiyun /* A >>= K */
929*4882a593Smuzhiyun ctx->flags |= SEEN_A;
930*4882a593Smuzhiyun emit_srl(r_A, r_A, k, ctx);
931*4882a593Smuzhiyun break;
932*4882a593Smuzhiyun case BPF_ALU | BPF_RSH | BPF_X:
933*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
934*4882a593Smuzhiyun emit_srlv(r_A, r_A, r_X, ctx);
935*4882a593Smuzhiyun break;
936*4882a593Smuzhiyun case BPF_ALU | BPF_NEG:
937*4882a593Smuzhiyun /* A = -A */
938*4882a593Smuzhiyun ctx->flags |= SEEN_A;
939*4882a593Smuzhiyun emit_neg(r_A, ctx);
940*4882a593Smuzhiyun break;
941*4882a593Smuzhiyun case BPF_JMP | BPF_JA:
942*4882a593Smuzhiyun /* pc += K */
943*4882a593Smuzhiyun b_off = b_imm(i + k + 1, ctx);
944*4882a593Smuzhiyun if (is_bad_offset(b_off))
945*4882a593Smuzhiyun return -E2BIG;
946*4882a593Smuzhiyun emit_b(b_off, ctx);
947*4882a593Smuzhiyun emit_nop(ctx);
948*4882a593Smuzhiyun break;
949*4882a593Smuzhiyun case BPF_JMP | BPF_JEQ | BPF_K:
950*4882a593Smuzhiyun /* pc += ( A == K ) ? pc->jt : pc->jf */
951*4882a593Smuzhiyun condt = MIPS_COND_EQ | MIPS_COND_K;
952*4882a593Smuzhiyun goto jmp_cmp;
953*4882a593Smuzhiyun case BPF_JMP | BPF_JEQ | BPF_X:
954*4882a593Smuzhiyun ctx->flags |= SEEN_X;
955*4882a593Smuzhiyun /* pc += ( A == X ) ? pc->jt : pc->jf */
956*4882a593Smuzhiyun condt = MIPS_COND_EQ | MIPS_COND_X;
957*4882a593Smuzhiyun goto jmp_cmp;
958*4882a593Smuzhiyun case BPF_JMP | BPF_JGE | BPF_K:
959*4882a593Smuzhiyun /* pc += ( A >= K ) ? pc->jt : pc->jf */
960*4882a593Smuzhiyun condt = MIPS_COND_GE | MIPS_COND_K;
961*4882a593Smuzhiyun goto jmp_cmp;
962*4882a593Smuzhiyun case BPF_JMP | BPF_JGE | BPF_X:
963*4882a593Smuzhiyun ctx->flags |= SEEN_X;
964*4882a593Smuzhiyun /* pc += ( A >= X ) ? pc->jt : pc->jf */
965*4882a593Smuzhiyun condt = MIPS_COND_GE | MIPS_COND_X;
966*4882a593Smuzhiyun goto jmp_cmp;
967*4882a593Smuzhiyun case BPF_JMP | BPF_JGT | BPF_K:
968*4882a593Smuzhiyun /* pc += ( A > K ) ? pc->jt : pc->jf */
969*4882a593Smuzhiyun condt = MIPS_COND_GT | MIPS_COND_K;
970*4882a593Smuzhiyun goto jmp_cmp;
971*4882a593Smuzhiyun case BPF_JMP | BPF_JGT | BPF_X:
972*4882a593Smuzhiyun ctx->flags |= SEEN_X;
973*4882a593Smuzhiyun /* pc += ( A > X ) ? pc->jt : pc->jf */
974*4882a593Smuzhiyun condt = MIPS_COND_GT | MIPS_COND_X;
975*4882a593Smuzhiyun jmp_cmp:
976*4882a593Smuzhiyun /* Greater or Equal */
977*4882a593Smuzhiyun if ((condt & MIPS_COND_GE) ||
978*4882a593Smuzhiyun (condt & MIPS_COND_GT)) {
979*4882a593Smuzhiyun if (condt & MIPS_COND_K) { /* K */
980*4882a593Smuzhiyun ctx->flags |= SEEN_A;
981*4882a593Smuzhiyun emit_sltiu(r_s0, r_A, k, ctx);
982*4882a593Smuzhiyun } else { /* X */
983*4882a593Smuzhiyun ctx->flags |= SEEN_A |
984*4882a593Smuzhiyun SEEN_X;
985*4882a593Smuzhiyun emit_sltu(r_s0, r_A, r_X, ctx);
986*4882a593Smuzhiyun }
987*4882a593Smuzhiyun /* A < (K|X) ? r_scrach = 1 */
988*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1, ctx);
989*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_s0, r_zero, b_off,
990*4882a593Smuzhiyun ctx);
991*4882a593Smuzhiyun emit_nop(ctx);
992*4882a593Smuzhiyun /* A > (K|X) ? scratch = 0 */
993*4882a593Smuzhiyun if (condt & MIPS_COND_GT) {
994*4882a593Smuzhiyun /* Checking for equality */
995*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
996*4882a593Smuzhiyun if (condt & MIPS_COND_K)
997*4882a593Smuzhiyun emit_load_imm(r_s0, k, ctx);
998*4882a593Smuzhiyun else
999*4882a593Smuzhiyun emit_jit_reg_move(r_s0, r_X,
1000*4882a593Smuzhiyun ctx);
1001*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1, ctx);
1002*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_A, r_s0,
1003*4882a593Smuzhiyun b_off, ctx);
1004*4882a593Smuzhiyun emit_nop(ctx);
1005*4882a593Smuzhiyun /* Finally, A > K|X */
1006*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1, ctx);
1007*4882a593Smuzhiyun emit_b(b_off, ctx);
1008*4882a593Smuzhiyun emit_nop(ctx);
1009*4882a593Smuzhiyun } else {
1010*4882a593Smuzhiyun /* A >= (K|X) so jump */
1011*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1, ctx);
1012*4882a593Smuzhiyun emit_b(b_off, ctx);
1013*4882a593Smuzhiyun emit_nop(ctx);
1014*4882a593Smuzhiyun }
1015*4882a593Smuzhiyun } else {
1016*4882a593Smuzhiyun /* A == K|X */
1017*4882a593Smuzhiyun if (condt & MIPS_COND_K) { /* K */
1018*4882a593Smuzhiyun ctx->flags |= SEEN_A;
1019*4882a593Smuzhiyun emit_load_imm(r_s0, k, ctx);
1020*4882a593Smuzhiyun /* jump true */
1021*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1, ctx);
1022*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_A, r_s0,
1023*4882a593Smuzhiyun b_off, ctx);
1024*4882a593Smuzhiyun emit_nop(ctx);
1025*4882a593Smuzhiyun /* jump false */
1026*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1,
1027*4882a593Smuzhiyun ctx);
1028*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_A, r_s0,
1029*4882a593Smuzhiyun b_off, ctx);
1030*4882a593Smuzhiyun emit_nop(ctx);
1031*4882a593Smuzhiyun } else { /* X */
1032*4882a593Smuzhiyun /* jump true */
1033*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
1034*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1,
1035*4882a593Smuzhiyun ctx);
1036*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_A, r_X,
1037*4882a593Smuzhiyun b_off, ctx);
1038*4882a593Smuzhiyun emit_nop(ctx);
1039*4882a593Smuzhiyun /* jump false */
1040*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1, ctx);
1041*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_A, r_X,
1042*4882a593Smuzhiyun b_off, ctx);
1043*4882a593Smuzhiyun emit_nop(ctx);
1044*4882a593Smuzhiyun }
1045*4882a593Smuzhiyun }
1046*4882a593Smuzhiyun break;
1047*4882a593Smuzhiyun case BPF_JMP | BPF_JSET | BPF_K:
1048*4882a593Smuzhiyun ctx->flags |= SEEN_A;
1049*4882a593Smuzhiyun /* pc += (A & K) ? pc -> jt : pc -> jf */
1050*4882a593Smuzhiyun emit_load_imm(r_s1, k, ctx);
1051*4882a593Smuzhiyun emit_and(r_s0, r_A, r_s1, ctx);
1052*4882a593Smuzhiyun /* jump true */
1053*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1, ctx);
1054*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_s0, r_zero, b_off, ctx);
1055*4882a593Smuzhiyun emit_nop(ctx);
1056*4882a593Smuzhiyun /* jump false */
1057*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1, ctx);
1058*4882a593Smuzhiyun emit_b(b_off, ctx);
1059*4882a593Smuzhiyun emit_nop(ctx);
1060*4882a593Smuzhiyun break;
1061*4882a593Smuzhiyun case BPF_JMP | BPF_JSET | BPF_X:
1062*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_A;
1063*4882a593Smuzhiyun /* pc += (A & X) ? pc -> jt : pc -> jf */
1064*4882a593Smuzhiyun emit_and(r_s0, r_A, r_X, ctx);
1065*4882a593Smuzhiyun /* jump true */
1066*4882a593Smuzhiyun b_off = b_imm(i + inst->jt + 1, ctx);
1067*4882a593Smuzhiyun emit_bcond(MIPS_COND_NE, r_s0, r_zero, b_off, ctx);
1068*4882a593Smuzhiyun emit_nop(ctx);
1069*4882a593Smuzhiyun /* jump false */
1070*4882a593Smuzhiyun b_off = b_imm(i + inst->jf + 1, ctx);
1071*4882a593Smuzhiyun emit_b(b_off, ctx);
1072*4882a593Smuzhiyun emit_nop(ctx);
1073*4882a593Smuzhiyun break;
1074*4882a593Smuzhiyun case BPF_RET | BPF_A:
1075*4882a593Smuzhiyun ctx->flags |= SEEN_A;
1076*4882a593Smuzhiyun if (i != prog->len - 1) {
1077*4882a593Smuzhiyun /*
1078*4882a593Smuzhiyun * If this is not the last instruction
1079*4882a593Smuzhiyun * then jump to the epilogue
1080*4882a593Smuzhiyun */
1081*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
1082*4882a593Smuzhiyun if (is_bad_offset(b_off))
1083*4882a593Smuzhiyun return -E2BIG;
1084*4882a593Smuzhiyun emit_b(b_off, ctx);
1085*4882a593Smuzhiyun }
1086*4882a593Smuzhiyun emit_reg_move(r_ret, r_A, ctx); /* delay slot */
1087*4882a593Smuzhiyun break;
1088*4882a593Smuzhiyun case BPF_RET | BPF_K:
1089*4882a593Smuzhiyun /*
1090*4882a593Smuzhiyun * It can emit two instructions so it does not fit on
1091*4882a593Smuzhiyun * the delay slot.
1092*4882a593Smuzhiyun */
1093*4882a593Smuzhiyun emit_load_imm(r_ret, k, ctx);
1094*4882a593Smuzhiyun if (i != prog->len - 1) {
1095*4882a593Smuzhiyun /*
1096*4882a593Smuzhiyun * If this is not the last instruction
1097*4882a593Smuzhiyun * then jump to the epilogue
1098*4882a593Smuzhiyun */
1099*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
1100*4882a593Smuzhiyun if (is_bad_offset(b_off))
1101*4882a593Smuzhiyun return -E2BIG;
1102*4882a593Smuzhiyun emit_b(b_off, ctx);
1103*4882a593Smuzhiyun emit_nop(ctx);
1104*4882a593Smuzhiyun }
1105*4882a593Smuzhiyun break;
1106*4882a593Smuzhiyun case BPF_MISC | BPF_TAX:
1107*4882a593Smuzhiyun /* X = A */
1108*4882a593Smuzhiyun ctx->flags |= SEEN_X | SEEN_A;
1109*4882a593Smuzhiyun emit_jit_reg_move(r_X, r_A, ctx);
1110*4882a593Smuzhiyun break;
1111*4882a593Smuzhiyun case BPF_MISC | BPF_TXA:
1112*4882a593Smuzhiyun /* A = X */
1113*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_X;
1114*4882a593Smuzhiyun emit_jit_reg_move(r_A, r_X, ctx);
1115*4882a593Smuzhiyun break;
1116*4882a593Smuzhiyun /* AUX */
1117*4882a593Smuzhiyun case BPF_ANC | SKF_AD_PROTOCOL:
1118*4882a593Smuzhiyun /* A = ntohs(skb->protocol */
1119*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_OFF | SEEN_A;
1120*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff,
1121*4882a593Smuzhiyun protocol) != 2);
1122*4882a593Smuzhiyun off = offsetof(struct sk_buff, protocol);
1123*4882a593Smuzhiyun emit_half_load(r_A, r_skb, off, ctx);
1124*4882a593Smuzhiyun #ifdef CONFIG_CPU_LITTLE_ENDIAN
1125*4882a593Smuzhiyun /* This needs little endian fixup */
1126*4882a593Smuzhiyun if (cpu_has_wsbh) {
1127*4882a593Smuzhiyun /* R2 and later have the wsbh instruction */
1128*4882a593Smuzhiyun emit_wsbh(r_A, r_A, ctx);
1129*4882a593Smuzhiyun } else {
1130*4882a593Smuzhiyun /* Get first byte */
1131*4882a593Smuzhiyun emit_andi(r_tmp_imm, r_A, 0xff, ctx);
1132*4882a593Smuzhiyun /* Shift it */
1133*4882a593Smuzhiyun emit_sll(r_tmp, r_tmp_imm, 8, ctx);
1134*4882a593Smuzhiyun /* Get second byte */
1135*4882a593Smuzhiyun emit_srl(r_tmp_imm, r_A, 8, ctx);
1136*4882a593Smuzhiyun emit_andi(r_tmp_imm, r_tmp_imm, 0xff, ctx);
1137*4882a593Smuzhiyun /* Put everyting together in r_A */
1138*4882a593Smuzhiyun emit_or(r_A, r_tmp, r_tmp_imm, ctx);
1139*4882a593Smuzhiyun }
1140*4882a593Smuzhiyun #endif
1141*4882a593Smuzhiyun break;
1142*4882a593Smuzhiyun case BPF_ANC | SKF_AD_CPU:
1143*4882a593Smuzhiyun ctx->flags |= SEEN_A | SEEN_OFF;
1144*4882a593Smuzhiyun /* A = current_thread_info()->cpu */
1145*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct thread_info,
1146*4882a593Smuzhiyun cpu) != 4);
1147*4882a593Smuzhiyun off = offsetof(struct thread_info, cpu);
1148*4882a593Smuzhiyun /* $28/gp points to the thread_info struct */
1149*4882a593Smuzhiyun emit_load(r_A, 28, off, ctx);
1150*4882a593Smuzhiyun break;
1151*4882a593Smuzhiyun case BPF_ANC | SKF_AD_IFINDEX:
1152*4882a593Smuzhiyun /* A = skb->dev->ifindex */
1153*4882a593Smuzhiyun case BPF_ANC | SKF_AD_HATYPE:
1154*4882a593Smuzhiyun /* A = skb->dev->type */
1155*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1156*4882a593Smuzhiyun off = offsetof(struct sk_buff, dev);
1157*4882a593Smuzhiyun /* Load *dev pointer */
1158*4882a593Smuzhiyun emit_load_ptr(r_s0, r_skb, off, ctx);
1159*4882a593Smuzhiyun /* error (0) in the delay slot */
1160*4882a593Smuzhiyun b_off = b_imm(prog->len, ctx);
1161*4882a593Smuzhiyun if (is_bad_offset(b_off))
1162*4882a593Smuzhiyun return -E2BIG;
1163*4882a593Smuzhiyun emit_bcond(MIPS_COND_EQ, r_s0, r_zero, b_off, ctx);
1164*4882a593Smuzhiyun emit_reg_move(r_ret, r_zero, ctx);
1165*4882a593Smuzhiyun if (code == (BPF_ANC | SKF_AD_IFINDEX)) {
1166*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct net_device, ifindex) != 4);
1167*4882a593Smuzhiyun off = offsetof(struct net_device, ifindex);
1168*4882a593Smuzhiyun emit_load(r_A, r_s0, off, ctx);
1169*4882a593Smuzhiyun } else { /* (code == (BPF_ANC | SKF_AD_HATYPE) */
1170*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct net_device, type) != 2);
1171*4882a593Smuzhiyun off = offsetof(struct net_device, type);
1172*4882a593Smuzhiyun emit_half_load_unsigned(r_A, r_s0, off, ctx);
1173*4882a593Smuzhiyun }
1174*4882a593Smuzhiyun break;
1175*4882a593Smuzhiyun case BPF_ANC | SKF_AD_MARK:
1176*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1177*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff, mark) != 4);
1178*4882a593Smuzhiyun off = offsetof(struct sk_buff, mark);
1179*4882a593Smuzhiyun emit_load(r_A, r_skb, off, ctx);
1180*4882a593Smuzhiyun break;
1181*4882a593Smuzhiyun case BPF_ANC | SKF_AD_RXHASH:
1182*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1183*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff, hash) != 4);
1184*4882a593Smuzhiyun off = offsetof(struct sk_buff, hash);
1185*4882a593Smuzhiyun emit_load(r_A, r_skb, off, ctx);
1186*4882a593Smuzhiyun break;
1187*4882a593Smuzhiyun case BPF_ANC | SKF_AD_VLAN_TAG:
1188*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1189*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff,
1190*4882a593Smuzhiyun vlan_tci) != 2);
1191*4882a593Smuzhiyun off = offsetof(struct sk_buff, vlan_tci);
1192*4882a593Smuzhiyun emit_half_load_unsigned(r_A, r_skb, off, ctx);
1193*4882a593Smuzhiyun break;
1194*4882a593Smuzhiyun case BPF_ANC | SKF_AD_VLAN_TAG_PRESENT:
1195*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1196*4882a593Smuzhiyun emit_load_byte(r_A, r_skb, PKT_VLAN_PRESENT_OFFSET(), ctx);
1197*4882a593Smuzhiyun if (PKT_VLAN_PRESENT_BIT)
1198*4882a593Smuzhiyun emit_srl(r_A, r_A, PKT_VLAN_PRESENT_BIT, ctx);
1199*4882a593Smuzhiyun if (PKT_VLAN_PRESENT_BIT < 7)
1200*4882a593Smuzhiyun emit_andi(r_A, r_A, 1, ctx);
1201*4882a593Smuzhiyun break;
1202*4882a593Smuzhiyun case BPF_ANC | SKF_AD_PKTTYPE:
1203*4882a593Smuzhiyun ctx->flags |= SEEN_SKB;
1204*4882a593Smuzhiyun
1205*4882a593Smuzhiyun emit_load_byte(r_tmp, r_skb, PKT_TYPE_OFFSET(), ctx);
1206*4882a593Smuzhiyun /* Keep only the last 3 bits */
1207*4882a593Smuzhiyun emit_andi(r_A, r_tmp, PKT_TYPE_MAX, ctx);
1208*4882a593Smuzhiyun #ifdef __BIG_ENDIAN_BITFIELD
1209*4882a593Smuzhiyun /* Get the actual packet type to the lower 3 bits */
1210*4882a593Smuzhiyun emit_srl(r_A, r_A, 5, ctx);
1211*4882a593Smuzhiyun #endif
1212*4882a593Smuzhiyun break;
1213*4882a593Smuzhiyun case BPF_ANC | SKF_AD_QUEUE:
1214*4882a593Smuzhiyun ctx->flags |= SEEN_SKB | SEEN_A;
1215*4882a593Smuzhiyun BUILD_BUG_ON(sizeof_field(struct sk_buff,
1216*4882a593Smuzhiyun queue_mapping) != 2);
1217*4882a593Smuzhiyun BUILD_BUG_ON(offsetof(struct sk_buff,
1218*4882a593Smuzhiyun queue_mapping) > 0xff);
1219*4882a593Smuzhiyun off = offsetof(struct sk_buff, queue_mapping);
1220*4882a593Smuzhiyun emit_half_load_unsigned(r_A, r_skb, off, ctx);
1221*4882a593Smuzhiyun break;
1222*4882a593Smuzhiyun default:
1223*4882a593Smuzhiyun pr_debug("%s: Unhandled opcode: 0x%02x\n", __FILE__,
1224*4882a593Smuzhiyun inst->code);
1225*4882a593Smuzhiyun return -1;
1226*4882a593Smuzhiyun }
1227*4882a593Smuzhiyun }
1228*4882a593Smuzhiyun
1229*4882a593Smuzhiyun /* compute offsets only during the first pass */
1230*4882a593Smuzhiyun if (ctx->target == NULL)
1231*4882a593Smuzhiyun ctx->offsets[i] = ctx->idx * 4;
1232*4882a593Smuzhiyun
1233*4882a593Smuzhiyun return 0;
1234*4882a593Smuzhiyun }
1235*4882a593Smuzhiyun
bpf_jit_compile(struct bpf_prog * fp)1236*4882a593Smuzhiyun void bpf_jit_compile(struct bpf_prog *fp)
1237*4882a593Smuzhiyun {
1238*4882a593Smuzhiyun struct jit_ctx ctx;
1239*4882a593Smuzhiyun unsigned int alloc_size, tmp_idx;
1240*4882a593Smuzhiyun
1241*4882a593Smuzhiyun if (!bpf_jit_enable)
1242*4882a593Smuzhiyun return;
1243*4882a593Smuzhiyun
1244*4882a593Smuzhiyun memset(&ctx, 0, sizeof(ctx));
1245*4882a593Smuzhiyun
1246*4882a593Smuzhiyun ctx.offsets = kcalloc(fp->len + 1, sizeof(*ctx.offsets), GFP_KERNEL);
1247*4882a593Smuzhiyun if (ctx.offsets == NULL)
1248*4882a593Smuzhiyun return;
1249*4882a593Smuzhiyun
1250*4882a593Smuzhiyun ctx.skf = fp;
1251*4882a593Smuzhiyun
1252*4882a593Smuzhiyun if (build_body(&ctx))
1253*4882a593Smuzhiyun goto out;
1254*4882a593Smuzhiyun
1255*4882a593Smuzhiyun tmp_idx = ctx.idx;
1256*4882a593Smuzhiyun build_prologue(&ctx);
1257*4882a593Smuzhiyun ctx.prologue_bytes = (ctx.idx - tmp_idx) * 4;
1258*4882a593Smuzhiyun /* just to complete the ctx.idx count */
1259*4882a593Smuzhiyun build_epilogue(&ctx);
1260*4882a593Smuzhiyun
1261*4882a593Smuzhiyun alloc_size = 4 * ctx.idx;
1262*4882a593Smuzhiyun ctx.target = module_alloc(alloc_size);
1263*4882a593Smuzhiyun if (ctx.target == NULL)
1264*4882a593Smuzhiyun goto out;
1265*4882a593Smuzhiyun
1266*4882a593Smuzhiyun /* Clean it */
1267*4882a593Smuzhiyun memset(ctx.target, 0, alloc_size);
1268*4882a593Smuzhiyun
1269*4882a593Smuzhiyun ctx.idx = 0;
1270*4882a593Smuzhiyun
1271*4882a593Smuzhiyun /* Generate the actual JIT code */
1272*4882a593Smuzhiyun build_prologue(&ctx);
1273*4882a593Smuzhiyun if (build_body(&ctx)) {
1274*4882a593Smuzhiyun module_memfree(ctx.target);
1275*4882a593Smuzhiyun goto out;
1276*4882a593Smuzhiyun }
1277*4882a593Smuzhiyun build_epilogue(&ctx);
1278*4882a593Smuzhiyun
1279*4882a593Smuzhiyun /* Update the icache */
1280*4882a593Smuzhiyun flush_icache_range((ptr)ctx.target, (ptr)(ctx.target + ctx.idx));
1281*4882a593Smuzhiyun
1282*4882a593Smuzhiyun if (bpf_jit_enable > 1)
1283*4882a593Smuzhiyun /* Dump JIT code */
1284*4882a593Smuzhiyun bpf_jit_dump(fp->len, alloc_size, 2, ctx.target);
1285*4882a593Smuzhiyun
1286*4882a593Smuzhiyun fp->bpf_func = (void *)ctx.target;
1287*4882a593Smuzhiyun fp->jited = 1;
1288*4882a593Smuzhiyun
1289*4882a593Smuzhiyun out:
1290*4882a593Smuzhiyun kfree(ctx.offsets);
1291*4882a593Smuzhiyun }
1292*4882a593Smuzhiyun
bpf_jit_free(struct bpf_prog * fp)1293*4882a593Smuzhiyun void bpf_jit_free(struct bpf_prog *fp)
1294*4882a593Smuzhiyun {
1295*4882a593Smuzhiyun if (fp->jited)
1296*4882a593Smuzhiyun module_memfree(fp->bpf_func);
1297*4882a593Smuzhiyun
1298*4882a593Smuzhiyun bpf_prog_unlock_free(fp);
1299*4882a593Smuzhiyun }
1300