x86/stacktrace: Prevent infinite loop in arch_stack_walk_user()
[linux-2.6-block.git] / arch / x86 / kernel / stacktrace.c
CommitLineData
21b32bbf 1/*
21b32bbf
IM
2 * Stack trace management functions
3 *
8f47e163 4 * Copyright (C) 2006-2009 Red Hat, Inc., Ingo Molnar <mingo@redhat.com>
21b32bbf
IM
5 */
6#include <linux/sched.h>
b17b0153 7#include <linux/sched/debug.h>
68db0cf1 8#include <linux/sched/task_stack.h>
21b32bbf 9#include <linux/stacktrace.h>
186f4360 10#include <linux/export.h>
02b67518 11#include <linux/uaccess.h>
c0b766f1 12#include <asm/stacktrace.h>
49a612c6 13#include <asm/unwind.h>
21b32bbf 14
3599fe12
TG
15void arch_stack_walk(stack_trace_consume_fn consume_entry, void *cookie,
16 struct task_struct *task, struct pt_regs *regs)
9745512c 17{
49a612c6
JP
18 struct unwind_state state;
19 unsigned long addr;
9745512c 20
3599fe12
TG
21 if (regs && !consume_entry(cookie, regs->ip, false))
22 return;
21b32bbf 23
49a612c6
JP
24 for (unwind_start(&state, task, regs, NULL); !unwind_done(&state);
25 unwind_next_frame(&state)) {
26 addr = unwind_get_return_address(&state);
3599fe12 27 if (!addr || !consume_entry(cookie, addr, false))
49a612c6
JP
28 break;
29 }
49a612c6 30}
9745512c 31
21b32bbf 32/*
3599fe12
TG
33 * This function returns an error if it detects any unreliable features of the
34 * stack. Otherwise it guarantees that the stack trace is reliable.
35 *
36 * If the task is not 'current', the caller *must* ensure the task is inactive.
21b32bbf 37 */
3599fe12
TG
38int arch_stack_walk_reliable(stack_trace_consume_fn consume_entry,
39 void *cookie, struct task_struct *task)
af085d90
JP
40{
41 struct unwind_state state;
42 struct pt_regs *regs;
43 unsigned long addr;
44
441ccc35
JS
45 for (unwind_start(&state, task, NULL, NULL);
46 !unwind_done(&state) && !unwind_error(&state);
af085d90
JP
47 unwind_next_frame(&state)) {
48
a9cdbe72 49 regs = unwind_get_entry_regs(&state, NULL);
af085d90 50 if (regs) {
441ccc35
JS
51 /* Success path for user tasks */
52 if (user_mode(regs))
c5c27a0a 53 return 0;
441ccc35 54
af085d90
JP
55 /*
56 * Kernel mode registers on the stack indicate an
57 * in-kernel interrupt or exception (e.g., preemption
58 * or a page fault), which can make frame pointers
59 * unreliable.
60 */
af085d90 61
0c414367
JS
62 if (IS_ENABLED(CONFIG_FRAME_POINTER))
63 return -EINVAL;
af085d90
JP
64 }
65
66 addr = unwind_get_return_address(&state);
67
68 /*
69 * A NULL or invalid return address probably means there's some
70 * generated code which __kernel_text_address() doesn't know
71 * about.
72 */
17426923 73 if (!addr)
af085d90 74 return -EINVAL;
af085d90 75
3599fe12 76 if (!consume_entry(cookie, addr, false))
af085d90
JP
77 return -EINVAL;
78 }
79
80 /* Check for stack corruption */
17426923 81 if (unwind_error(&state))
af085d90 82 return -EINVAL;
af085d90 83
441ccc35
JS
84 /* Success path for non-user tasks, i.e. kthreads and idle tasks */
85 if (!(task->flags & (PF_KTHREAD | PF_IDLE)))
86 return -EINVAL;
87
af085d90
JP
88 return 0;
89}
90
02b67518
TE
91/* Userspace stacktrace - based on kernel/trace/trace_sysprof.c */
92
c9cf4dbb 93struct stack_frame_user {
02b67518 94 const void __user *next_fp;
8d7c6a96 95 unsigned long ret_addr;
02b67518
TE
96};
97
c9cf4dbb
FW
98static int
99copy_stack_frame(const void __user *fp, struct stack_frame_user *frame)
02b67518
TE
100{
101 int ret;
102
96d4f267 103 if (!access_ok(fp, sizeof(*frame)))
02b67518
TE
104 return 0;
105
106 ret = 1;
107 pagefault_disable();
108 if (__copy_from_user_inatomic(frame, fp, sizeof(*frame)))
109 ret = 0;
110 pagefault_enable();
111
112 return ret;
113}
114
3599fe12
TG
115void arch_stack_walk_user(stack_trace_consume_fn consume_entry, void *cookie,
116 const struct pt_regs *regs)
8d7c6a96 117{
8d7c6a96
TE
118 const void __user *fp = (const void __user *)regs->bp;
119
3599fe12
TG
120 if (!consume_entry(cookie, regs->ip, false))
121 return;
8d7c6a96 122
3599fe12 123 while (1) {
c9cf4dbb 124 struct stack_frame_user frame;
8d7c6a96
TE
125
126 frame.next_fp = NULL;
127 frame.ret_addr = 0;
128 if (!copy_stack_frame(fp, &frame))
129 break;
130 if ((unsigned long)fp < regs->sp)
131 break;
cbf5b73d
ET
132 if (!frame.ret_addr)
133 break;
134 if (!consume_entry(cookie, frame.ret_addr, false))
8d7c6a96
TE
135 break;
136 fp = frame.next_fp;
137 }
138}
139