1*4882a593Smuzhiyun // SPDX-License-Identifier: GPL-2.0-or-later
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * Copyright (C) 2017 Joe Lawrence <joe.lawrence@redhat.com>
4*4882a593Smuzhiyun */
5*4882a593Smuzhiyun
6*4882a593Smuzhiyun /*
7*4882a593Smuzhiyun * livepatch-shadow-mod.c - Shadow variables, buggy module demo
8*4882a593Smuzhiyun *
9*4882a593Smuzhiyun * Purpose
10*4882a593Smuzhiyun * -------
11*4882a593Smuzhiyun *
12*4882a593Smuzhiyun * As a demonstration of livepatch shadow variable API, this module
13*4882a593Smuzhiyun * introduces memory leak behavior that livepatch modules
14*4882a593Smuzhiyun * livepatch-shadow-fix1.ko and livepatch-shadow-fix2.ko correct and
15*4882a593Smuzhiyun * enhance.
16*4882a593Smuzhiyun *
17*4882a593Smuzhiyun * WARNING - even though the livepatch-shadow-fix modules patch the
18*4882a593Smuzhiyun * memory leak, please load these modules at your own risk -- some
19*4882a593Smuzhiyun * amount of memory may leaked before the bug is patched.
20*4882a593Smuzhiyun *
21*4882a593Smuzhiyun *
22*4882a593Smuzhiyun * Usage
23*4882a593Smuzhiyun * -----
24*4882a593Smuzhiyun *
25*4882a593Smuzhiyun * Step 1 - Load the buggy demonstration module:
26*4882a593Smuzhiyun *
27*4882a593Smuzhiyun * insmod samples/livepatch/livepatch-shadow-mod.ko
28*4882a593Smuzhiyun *
29*4882a593Smuzhiyun * Watch dmesg output for a few moments to see new dummy being allocated
30*4882a593Smuzhiyun * and a periodic cleanup check. (Note: a small amount of memory is
31*4882a593Smuzhiyun * being leaked.)
32*4882a593Smuzhiyun *
33*4882a593Smuzhiyun *
34*4882a593Smuzhiyun * Step 2 - Load livepatch fix1:
35*4882a593Smuzhiyun *
36*4882a593Smuzhiyun * insmod samples/livepatch/livepatch-shadow-fix1.ko
37*4882a593Smuzhiyun *
38*4882a593Smuzhiyun * Continue watching dmesg and note that now livepatch_fix1_dummy_free()
39*4882a593Smuzhiyun * and livepatch_fix1_dummy_alloc() are logging messages about leaked
40*4882a593Smuzhiyun * memory and eventually leaks prevented.
41*4882a593Smuzhiyun *
42*4882a593Smuzhiyun *
43*4882a593Smuzhiyun * Step 3 - Load livepatch fix2 (on top of fix1):
44*4882a593Smuzhiyun *
45*4882a593Smuzhiyun * insmod samples/livepatch/livepatch-shadow-fix2.ko
46*4882a593Smuzhiyun *
47*4882a593Smuzhiyun * This module extends functionality through shadow variables, as a new
48*4882a593Smuzhiyun * "check" counter is added to the dummy structure. Periodic dmesg
49*4882a593Smuzhiyun * messages will log these as dummies are cleaned up.
50*4882a593Smuzhiyun *
51*4882a593Smuzhiyun *
52*4882a593Smuzhiyun * Step 4 - Cleanup
53*4882a593Smuzhiyun *
54*4882a593Smuzhiyun * Unwind the demonstration by disabling the livepatch fix modules, then
55*4882a593Smuzhiyun * removing them and the demo module:
56*4882a593Smuzhiyun *
57*4882a593Smuzhiyun * echo 0 > /sys/kernel/livepatch/livepatch_shadow_fix2/enabled
58*4882a593Smuzhiyun * echo 0 > /sys/kernel/livepatch/livepatch_shadow_fix1/enabled
59*4882a593Smuzhiyun * rmmod livepatch-shadow-fix2
60*4882a593Smuzhiyun * rmmod livepatch-shadow-fix1
61*4882a593Smuzhiyun * rmmod livepatch-shadow-mod
62*4882a593Smuzhiyun */
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun
65*4882a593Smuzhiyun #include <linux/kernel.h>
66*4882a593Smuzhiyun #include <linux/module.h>
67*4882a593Smuzhiyun #include <linux/sched.h>
68*4882a593Smuzhiyun #include <linux/slab.h>
69*4882a593Smuzhiyun #include <linux/stat.h>
70*4882a593Smuzhiyun #include <linux/workqueue.h>
71*4882a593Smuzhiyun
72*4882a593Smuzhiyun MODULE_LICENSE("GPL");
73*4882a593Smuzhiyun MODULE_AUTHOR("Joe Lawrence <joe.lawrence@redhat.com>");
74*4882a593Smuzhiyun MODULE_DESCRIPTION("Buggy module for shadow variable demo");
75*4882a593Smuzhiyun
76*4882a593Smuzhiyun /* Allocate new dummies every second */
77*4882a593Smuzhiyun #define ALLOC_PERIOD 1
78*4882a593Smuzhiyun /* Check for expired dummies after a few new ones have been allocated */
79*4882a593Smuzhiyun #define CLEANUP_PERIOD (3 * ALLOC_PERIOD)
80*4882a593Smuzhiyun /* Dummies expire after a few cleanup instances */
81*4882a593Smuzhiyun #define EXPIRE_PERIOD (4 * CLEANUP_PERIOD)
82*4882a593Smuzhiyun
83*4882a593Smuzhiyun /*
84*4882a593Smuzhiyun * Keep a list of all the dummies so we can clean up any residual ones
85*4882a593Smuzhiyun * on module exit
86*4882a593Smuzhiyun */
87*4882a593Smuzhiyun static LIST_HEAD(dummy_list);
88*4882a593Smuzhiyun static DEFINE_MUTEX(dummy_list_mutex);
89*4882a593Smuzhiyun
90*4882a593Smuzhiyun struct dummy {
91*4882a593Smuzhiyun struct list_head list;
92*4882a593Smuzhiyun unsigned long jiffies_expire;
93*4882a593Smuzhiyun };
94*4882a593Smuzhiyun
dummy_alloc(void)95*4882a593Smuzhiyun static __used noinline struct dummy *dummy_alloc(void)
96*4882a593Smuzhiyun {
97*4882a593Smuzhiyun struct dummy *d;
98*4882a593Smuzhiyun int *leak;
99*4882a593Smuzhiyun
100*4882a593Smuzhiyun d = kzalloc(sizeof(*d), GFP_KERNEL);
101*4882a593Smuzhiyun if (!d)
102*4882a593Smuzhiyun return NULL;
103*4882a593Smuzhiyun
104*4882a593Smuzhiyun d->jiffies_expire = jiffies +
105*4882a593Smuzhiyun msecs_to_jiffies(1000 * EXPIRE_PERIOD);
106*4882a593Smuzhiyun
107*4882a593Smuzhiyun /* Oops, forgot to save leak! */
108*4882a593Smuzhiyun leak = kzalloc(sizeof(*leak), GFP_KERNEL);
109*4882a593Smuzhiyun if (!leak) {
110*4882a593Smuzhiyun kfree(d);
111*4882a593Smuzhiyun return NULL;
112*4882a593Smuzhiyun }
113*4882a593Smuzhiyun
114*4882a593Smuzhiyun pr_info("%s: dummy @ %p, expires @ %lx\n",
115*4882a593Smuzhiyun __func__, d, d->jiffies_expire);
116*4882a593Smuzhiyun
117*4882a593Smuzhiyun return d;
118*4882a593Smuzhiyun }
119*4882a593Smuzhiyun
dummy_free(struct dummy * d)120*4882a593Smuzhiyun static __used noinline void dummy_free(struct dummy *d)
121*4882a593Smuzhiyun {
122*4882a593Smuzhiyun pr_info("%s: dummy @ %p, expired = %lx\n",
123*4882a593Smuzhiyun __func__, d, d->jiffies_expire);
124*4882a593Smuzhiyun
125*4882a593Smuzhiyun kfree(d);
126*4882a593Smuzhiyun }
127*4882a593Smuzhiyun
dummy_check(struct dummy * d,unsigned long jiffies)128*4882a593Smuzhiyun static __used noinline bool dummy_check(struct dummy *d,
129*4882a593Smuzhiyun unsigned long jiffies)
130*4882a593Smuzhiyun {
131*4882a593Smuzhiyun return time_after(jiffies, d->jiffies_expire);
132*4882a593Smuzhiyun }
133*4882a593Smuzhiyun
134*4882a593Smuzhiyun /*
135*4882a593Smuzhiyun * alloc_work_func: allocates new dummy structures, allocates additional
136*4882a593Smuzhiyun * memory, aptly named "leak", but doesn't keep
137*4882a593Smuzhiyun * permanent record of it.
138*4882a593Smuzhiyun */
139*4882a593Smuzhiyun
140*4882a593Smuzhiyun static void alloc_work_func(struct work_struct *work);
141*4882a593Smuzhiyun static DECLARE_DELAYED_WORK(alloc_dwork, alloc_work_func);
142*4882a593Smuzhiyun
alloc_work_func(struct work_struct * work)143*4882a593Smuzhiyun static void alloc_work_func(struct work_struct *work)
144*4882a593Smuzhiyun {
145*4882a593Smuzhiyun struct dummy *d;
146*4882a593Smuzhiyun
147*4882a593Smuzhiyun d = dummy_alloc();
148*4882a593Smuzhiyun if (!d)
149*4882a593Smuzhiyun return;
150*4882a593Smuzhiyun
151*4882a593Smuzhiyun mutex_lock(&dummy_list_mutex);
152*4882a593Smuzhiyun list_add(&d->list, &dummy_list);
153*4882a593Smuzhiyun mutex_unlock(&dummy_list_mutex);
154*4882a593Smuzhiyun
155*4882a593Smuzhiyun schedule_delayed_work(&alloc_dwork,
156*4882a593Smuzhiyun msecs_to_jiffies(1000 * ALLOC_PERIOD));
157*4882a593Smuzhiyun }
158*4882a593Smuzhiyun
159*4882a593Smuzhiyun /*
160*4882a593Smuzhiyun * cleanup_work_func: frees dummy structures. Without knownledge of
161*4882a593Smuzhiyun * "leak", it leaks the additional memory that
162*4882a593Smuzhiyun * alloc_work_func created.
163*4882a593Smuzhiyun */
164*4882a593Smuzhiyun
165*4882a593Smuzhiyun static void cleanup_work_func(struct work_struct *work);
166*4882a593Smuzhiyun static DECLARE_DELAYED_WORK(cleanup_dwork, cleanup_work_func);
167*4882a593Smuzhiyun
cleanup_work_func(struct work_struct * work)168*4882a593Smuzhiyun static void cleanup_work_func(struct work_struct *work)
169*4882a593Smuzhiyun {
170*4882a593Smuzhiyun struct dummy *d, *tmp;
171*4882a593Smuzhiyun unsigned long j;
172*4882a593Smuzhiyun
173*4882a593Smuzhiyun j = jiffies;
174*4882a593Smuzhiyun pr_info("%s: jiffies = %lx\n", __func__, j);
175*4882a593Smuzhiyun
176*4882a593Smuzhiyun mutex_lock(&dummy_list_mutex);
177*4882a593Smuzhiyun list_for_each_entry_safe(d, tmp, &dummy_list, list) {
178*4882a593Smuzhiyun
179*4882a593Smuzhiyun /* Kick out and free any expired dummies */
180*4882a593Smuzhiyun if (dummy_check(d, j)) {
181*4882a593Smuzhiyun list_del(&d->list);
182*4882a593Smuzhiyun dummy_free(d);
183*4882a593Smuzhiyun }
184*4882a593Smuzhiyun }
185*4882a593Smuzhiyun mutex_unlock(&dummy_list_mutex);
186*4882a593Smuzhiyun
187*4882a593Smuzhiyun schedule_delayed_work(&cleanup_dwork,
188*4882a593Smuzhiyun msecs_to_jiffies(1000 * CLEANUP_PERIOD));
189*4882a593Smuzhiyun }
190*4882a593Smuzhiyun
livepatch_shadow_mod_init(void)191*4882a593Smuzhiyun static int livepatch_shadow_mod_init(void)
192*4882a593Smuzhiyun {
193*4882a593Smuzhiyun schedule_delayed_work(&alloc_dwork,
194*4882a593Smuzhiyun msecs_to_jiffies(1000 * ALLOC_PERIOD));
195*4882a593Smuzhiyun schedule_delayed_work(&cleanup_dwork,
196*4882a593Smuzhiyun msecs_to_jiffies(1000 * CLEANUP_PERIOD));
197*4882a593Smuzhiyun
198*4882a593Smuzhiyun return 0;
199*4882a593Smuzhiyun }
200*4882a593Smuzhiyun
livepatch_shadow_mod_exit(void)201*4882a593Smuzhiyun static void livepatch_shadow_mod_exit(void)
202*4882a593Smuzhiyun {
203*4882a593Smuzhiyun struct dummy *d, *tmp;
204*4882a593Smuzhiyun
205*4882a593Smuzhiyun /* Wait for any dummies at work */
206*4882a593Smuzhiyun cancel_delayed_work_sync(&alloc_dwork);
207*4882a593Smuzhiyun cancel_delayed_work_sync(&cleanup_dwork);
208*4882a593Smuzhiyun
209*4882a593Smuzhiyun /* Cleanup residual dummies */
210*4882a593Smuzhiyun list_for_each_entry_safe(d, tmp, &dummy_list, list) {
211*4882a593Smuzhiyun list_del(&d->list);
212*4882a593Smuzhiyun dummy_free(d);
213*4882a593Smuzhiyun }
214*4882a593Smuzhiyun }
215*4882a593Smuzhiyun
216*4882a593Smuzhiyun module_init(livepatch_shadow_mod_init);
217*4882a593Smuzhiyun module_exit(livepatch_shadow_mod_exit);
218