1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0 */
2*4882a593Smuzhiyun #ifndef _PKEYS_HELPER_H
3*4882a593Smuzhiyun #define _PKEYS_HELPER_H
4*4882a593Smuzhiyun #define _GNU_SOURCE
5*4882a593Smuzhiyun #include <string.h>
6*4882a593Smuzhiyun #include <stdarg.h>
7*4882a593Smuzhiyun #include <stdio.h>
8*4882a593Smuzhiyun #include <stdint.h>
9*4882a593Smuzhiyun #include <stdbool.h>
10*4882a593Smuzhiyun #include <signal.h>
11*4882a593Smuzhiyun #include <assert.h>
12*4882a593Smuzhiyun #include <stdlib.h>
13*4882a593Smuzhiyun #include <ucontext.h>
14*4882a593Smuzhiyun #include <sys/mman.h>
15*4882a593Smuzhiyun
16*4882a593Smuzhiyun /* Define some kernel-like types */
17*4882a593Smuzhiyun #define u8 __u8
18*4882a593Smuzhiyun #define u16 __u16
19*4882a593Smuzhiyun #define u32 __u32
20*4882a593Smuzhiyun #define u64 __u64
21*4882a593Smuzhiyun
22*4882a593Smuzhiyun #define PTR_ERR_ENOTSUP ((void *)-ENOTSUP)
23*4882a593Smuzhiyun
24*4882a593Smuzhiyun #ifndef DEBUG_LEVEL
25*4882a593Smuzhiyun #define DEBUG_LEVEL 0
26*4882a593Smuzhiyun #endif
27*4882a593Smuzhiyun #define DPRINT_IN_SIGNAL_BUF_SIZE 4096
28*4882a593Smuzhiyun extern int dprint_in_signal;
29*4882a593Smuzhiyun extern char dprint_in_signal_buffer[DPRINT_IN_SIGNAL_BUF_SIZE];
30*4882a593Smuzhiyun
31*4882a593Smuzhiyun extern int test_nr;
32*4882a593Smuzhiyun extern int iteration_nr;
33*4882a593Smuzhiyun
34*4882a593Smuzhiyun #ifdef __GNUC__
35*4882a593Smuzhiyun __attribute__((format(printf, 1, 2)))
36*4882a593Smuzhiyun #endif
sigsafe_printf(const char * format,...)37*4882a593Smuzhiyun static inline void sigsafe_printf(const char *format, ...)
38*4882a593Smuzhiyun {
39*4882a593Smuzhiyun va_list ap;
40*4882a593Smuzhiyun
41*4882a593Smuzhiyun if (!dprint_in_signal) {
42*4882a593Smuzhiyun va_start(ap, format);
43*4882a593Smuzhiyun vprintf(format, ap);
44*4882a593Smuzhiyun va_end(ap);
45*4882a593Smuzhiyun } else {
46*4882a593Smuzhiyun int ret;
47*4882a593Smuzhiyun /*
48*4882a593Smuzhiyun * No printf() functions are signal-safe.
49*4882a593Smuzhiyun * They deadlock easily. Write the format
50*4882a593Smuzhiyun * string to get some output, even if
51*4882a593Smuzhiyun * incomplete.
52*4882a593Smuzhiyun */
53*4882a593Smuzhiyun ret = write(1, format, strlen(format));
54*4882a593Smuzhiyun if (ret < 0)
55*4882a593Smuzhiyun exit(1);
56*4882a593Smuzhiyun }
57*4882a593Smuzhiyun }
58*4882a593Smuzhiyun #define dprintf_level(level, args...) do { \
59*4882a593Smuzhiyun if (level <= DEBUG_LEVEL) \
60*4882a593Smuzhiyun sigsafe_printf(args); \
61*4882a593Smuzhiyun } while (0)
62*4882a593Smuzhiyun #define dprintf0(args...) dprintf_level(0, args)
63*4882a593Smuzhiyun #define dprintf1(args...) dprintf_level(1, args)
64*4882a593Smuzhiyun #define dprintf2(args...) dprintf_level(2, args)
65*4882a593Smuzhiyun #define dprintf3(args...) dprintf_level(3, args)
66*4882a593Smuzhiyun #define dprintf4(args...) dprintf_level(4, args)
67*4882a593Smuzhiyun
68*4882a593Smuzhiyun extern void abort_hooks(void);
69*4882a593Smuzhiyun #define pkey_assert(condition) do { \
70*4882a593Smuzhiyun if (!(condition)) { \
71*4882a593Smuzhiyun dprintf0("assert() at %s::%d test_nr: %d iteration: %d\n", \
72*4882a593Smuzhiyun __FILE__, __LINE__, \
73*4882a593Smuzhiyun test_nr, iteration_nr); \
74*4882a593Smuzhiyun dprintf0("errno at assert: %d", errno); \
75*4882a593Smuzhiyun abort_hooks(); \
76*4882a593Smuzhiyun exit(__LINE__); \
77*4882a593Smuzhiyun } \
78*4882a593Smuzhiyun } while (0)
79*4882a593Smuzhiyun
80*4882a593Smuzhiyun __attribute__((noinline)) int read_ptr(int *ptr);
81*4882a593Smuzhiyun void expected_pkey_fault(int pkey);
82*4882a593Smuzhiyun int sys_pkey_alloc(unsigned long flags, unsigned long init_val);
83*4882a593Smuzhiyun int sys_pkey_free(unsigned long pkey);
84*4882a593Smuzhiyun int mprotect_pkey(void *ptr, size_t size, unsigned long orig_prot,
85*4882a593Smuzhiyun unsigned long pkey);
86*4882a593Smuzhiyun void record_pkey_malloc(void *ptr, long size, int prot);
87*4882a593Smuzhiyun
88*4882a593Smuzhiyun #if defined(__i386__) || defined(__x86_64__) /* arch */
89*4882a593Smuzhiyun #include "pkey-x86.h"
90*4882a593Smuzhiyun #elif defined(__powerpc64__) /* arch */
91*4882a593Smuzhiyun #include "pkey-powerpc.h"
92*4882a593Smuzhiyun #else /* arch */
93*4882a593Smuzhiyun #error Architecture not supported
94*4882a593Smuzhiyun #endif /* arch */
95*4882a593Smuzhiyun
96*4882a593Smuzhiyun #define PKEY_MASK (PKEY_DISABLE_ACCESS | PKEY_DISABLE_WRITE)
97*4882a593Smuzhiyun
set_pkey_bits(u64 reg,int pkey,u64 flags)98*4882a593Smuzhiyun static inline u64 set_pkey_bits(u64 reg, int pkey, u64 flags)
99*4882a593Smuzhiyun {
100*4882a593Smuzhiyun u32 shift = pkey_bit_position(pkey);
101*4882a593Smuzhiyun /* mask out bits from pkey in old value */
102*4882a593Smuzhiyun reg &= ~((u64)PKEY_MASK << shift);
103*4882a593Smuzhiyun /* OR in new bits for pkey */
104*4882a593Smuzhiyun reg |= (flags & PKEY_MASK) << shift;
105*4882a593Smuzhiyun return reg;
106*4882a593Smuzhiyun }
107*4882a593Smuzhiyun
get_pkey_bits(u64 reg,int pkey)108*4882a593Smuzhiyun static inline u64 get_pkey_bits(u64 reg, int pkey)
109*4882a593Smuzhiyun {
110*4882a593Smuzhiyun u32 shift = pkey_bit_position(pkey);
111*4882a593Smuzhiyun /*
112*4882a593Smuzhiyun * shift down the relevant bits to the lowest two, then
113*4882a593Smuzhiyun * mask off all the other higher bits
114*4882a593Smuzhiyun */
115*4882a593Smuzhiyun return ((reg >> shift) & PKEY_MASK);
116*4882a593Smuzhiyun }
117*4882a593Smuzhiyun
118*4882a593Smuzhiyun extern u64 shadow_pkey_reg;
119*4882a593Smuzhiyun
_read_pkey_reg(int line)120*4882a593Smuzhiyun static inline u64 _read_pkey_reg(int line)
121*4882a593Smuzhiyun {
122*4882a593Smuzhiyun u64 pkey_reg = __read_pkey_reg();
123*4882a593Smuzhiyun
124*4882a593Smuzhiyun dprintf4("read_pkey_reg(line=%d) pkey_reg: %016llx"
125*4882a593Smuzhiyun " shadow: %016llx\n",
126*4882a593Smuzhiyun line, pkey_reg, shadow_pkey_reg);
127*4882a593Smuzhiyun assert(pkey_reg == shadow_pkey_reg);
128*4882a593Smuzhiyun
129*4882a593Smuzhiyun return pkey_reg;
130*4882a593Smuzhiyun }
131*4882a593Smuzhiyun
132*4882a593Smuzhiyun #define read_pkey_reg() _read_pkey_reg(__LINE__)
133*4882a593Smuzhiyun
write_pkey_reg(u64 pkey_reg)134*4882a593Smuzhiyun static inline void write_pkey_reg(u64 pkey_reg)
135*4882a593Smuzhiyun {
136*4882a593Smuzhiyun dprintf4("%s() changing %016llx to %016llx\n", __func__,
137*4882a593Smuzhiyun __read_pkey_reg(), pkey_reg);
138*4882a593Smuzhiyun /* will do the shadow check for us: */
139*4882a593Smuzhiyun read_pkey_reg();
140*4882a593Smuzhiyun __write_pkey_reg(pkey_reg);
141*4882a593Smuzhiyun shadow_pkey_reg = pkey_reg;
142*4882a593Smuzhiyun dprintf4("%s(%016llx) pkey_reg: %016llx\n", __func__,
143*4882a593Smuzhiyun pkey_reg, __read_pkey_reg());
144*4882a593Smuzhiyun }
145*4882a593Smuzhiyun
146*4882a593Smuzhiyun /*
147*4882a593Smuzhiyun * These are technically racy. since something could
148*4882a593Smuzhiyun * change PKEY register between the read and the write.
149*4882a593Smuzhiyun */
__pkey_access_allow(int pkey,int do_allow)150*4882a593Smuzhiyun static inline void __pkey_access_allow(int pkey, int do_allow)
151*4882a593Smuzhiyun {
152*4882a593Smuzhiyun u64 pkey_reg = read_pkey_reg();
153*4882a593Smuzhiyun int bit = pkey * 2;
154*4882a593Smuzhiyun
155*4882a593Smuzhiyun if (do_allow)
156*4882a593Smuzhiyun pkey_reg &= (1<<bit);
157*4882a593Smuzhiyun else
158*4882a593Smuzhiyun pkey_reg |= (1<<bit);
159*4882a593Smuzhiyun
160*4882a593Smuzhiyun dprintf4("pkey_reg now: %016llx\n", read_pkey_reg());
161*4882a593Smuzhiyun write_pkey_reg(pkey_reg);
162*4882a593Smuzhiyun }
163*4882a593Smuzhiyun
__pkey_write_allow(int pkey,int do_allow_write)164*4882a593Smuzhiyun static inline void __pkey_write_allow(int pkey, int do_allow_write)
165*4882a593Smuzhiyun {
166*4882a593Smuzhiyun u64 pkey_reg = read_pkey_reg();
167*4882a593Smuzhiyun int bit = pkey * 2 + 1;
168*4882a593Smuzhiyun
169*4882a593Smuzhiyun if (do_allow_write)
170*4882a593Smuzhiyun pkey_reg &= (1<<bit);
171*4882a593Smuzhiyun else
172*4882a593Smuzhiyun pkey_reg |= (1<<bit);
173*4882a593Smuzhiyun
174*4882a593Smuzhiyun write_pkey_reg(pkey_reg);
175*4882a593Smuzhiyun dprintf4("pkey_reg now: %016llx\n", read_pkey_reg());
176*4882a593Smuzhiyun }
177*4882a593Smuzhiyun
178*4882a593Smuzhiyun #define ARRAY_SIZE(x) (sizeof(x) / sizeof(*(x)))
179*4882a593Smuzhiyun #define ALIGN_UP(x, align_to) (((x) + ((align_to)-1)) & ~((align_to)-1))
180*4882a593Smuzhiyun #define ALIGN_DOWN(x, align_to) ((x) & ~((align_to)-1))
181*4882a593Smuzhiyun #define ALIGN_PTR_UP(p, ptr_align_to) \
182*4882a593Smuzhiyun ((typeof(p))ALIGN_UP((unsigned long)(p), ptr_align_to))
183*4882a593Smuzhiyun #define ALIGN_PTR_DOWN(p, ptr_align_to) \
184*4882a593Smuzhiyun ((typeof(p))ALIGN_DOWN((unsigned long)(p), ptr_align_to))
185*4882a593Smuzhiyun #define __stringify_1(x...) #x
186*4882a593Smuzhiyun #define __stringify(x...) __stringify_1(x)
187*4882a593Smuzhiyun
siginfo_get_pkey_ptr(siginfo_t * si)188*4882a593Smuzhiyun static inline u32 *siginfo_get_pkey_ptr(siginfo_t *si)
189*4882a593Smuzhiyun {
190*4882a593Smuzhiyun #ifdef si_pkey
191*4882a593Smuzhiyun return &si->si_pkey;
192*4882a593Smuzhiyun #else
193*4882a593Smuzhiyun return (u32 *)(((u8 *)si) + si_pkey_offset);
194*4882a593Smuzhiyun #endif
195*4882a593Smuzhiyun }
196*4882a593Smuzhiyun
kernel_has_pkeys(void)197*4882a593Smuzhiyun static inline int kernel_has_pkeys(void)
198*4882a593Smuzhiyun {
199*4882a593Smuzhiyun /* try allocating a key and see if it succeeds */
200*4882a593Smuzhiyun int ret = sys_pkey_alloc(0, 0);
201*4882a593Smuzhiyun if (ret <= 0) {
202*4882a593Smuzhiyun return 0;
203*4882a593Smuzhiyun }
204*4882a593Smuzhiyun sys_pkey_free(ret);
205*4882a593Smuzhiyun return 1;
206*4882a593Smuzhiyun }
207*4882a593Smuzhiyun
is_pkeys_supported(void)208*4882a593Smuzhiyun static inline int is_pkeys_supported(void)
209*4882a593Smuzhiyun {
210*4882a593Smuzhiyun /* check if the cpu supports pkeys */
211*4882a593Smuzhiyun if (!cpu_has_pkeys()) {
212*4882a593Smuzhiyun dprintf1("SKIP: %s: no CPU support\n", __func__);
213*4882a593Smuzhiyun return 0;
214*4882a593Smuzhiyun }
215*4882a593Smuzhiyun
216*4882a593Smuzhiyun /* check if the kernel supports pkeys */
217*4882a593Smuzhiyun if (!kernel_has_pkeys()) {
218*4882a593Smuzhiyun dprintf1("SKIP: %s: no kernel support\n", __func__);
219*4882a593Smuzhiyun return 0;
220*4882a593Smuzhiyun }
221*4882a593Smuzhiyun
222*4882a593Smuzhiyun return 1;
223*4882a593Smuzhiyun }
224*4882a593Smuzhiyun
225*4882a593Smuzhiyun #endif /* _PKEYS_HELPER_H */
226