Commit | Line | Data |
---|---|---|
b2441318 | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
0b24becc AR |
2 | #ifndef __MM_KASAN_KASAN_H |
3 | #define __MM_KASAN_KASAN_H | |
4 | ||
5 | #include <linux/kasan.h> | |
cd11016e | 6 | #include <linux/stackdepot.h> |
0b24becc | 7 | |
6c6a04fe | 8 | #if defined(CONFIG_KASAN_GENERIC) || defined(CONFIG_KASAN_SW_TAGS) |
1f600626 | 9 | #define KASAN_GRANULE_SIZE (1UL << KASAN_SHADOW_SCALE_SHIFT) |
6c6a04fe AK |
10 | #else |
11 | #include <asm/mte-kasan.h> | |
12 | #define KASAN_GRANULE_SIZE MTE_GRANULE_SIZE | |
13 | #endif | |
14 | ||
1f600626 | 15 | #define KASAN_GRANULE_MASK (KASAN_GRANULE_SIZE - 1) |
0b24becc | 16 | |
affc3f07 AK |
17 | #define KASAN_MEMORY_PER_SHADOW_PAGE (KASAN_GRANULE_SIZE << PAGE_SHIFT) |
18 | ||
3c9e3aa1 AK |
19 | #define KASAN_TAG_KERNEL 0xFF /* native kernel pointers tag */ |
20 | #define KASAN_TAG_INVALID 0xFE /* inaccessible memory tag */ | |
21 | #define KASAN_TAG_MAX 0xFD /* maximum value for random tags */ | |
22 | ||
7f94ffbc | 23 | #ifdef CONFIG_KASAN_GENERIC |
0316bec2 AR |
24 | #define KASAN_FREE_PAGE 0xFF /* page was freed */ |
25 | #define KASAN_PAGE_REDZONE 0xFE /* redzone for kmalloc_large allocations */ | |
26 | #define KASAN_KMALLOC_REDZONE 0xFC /* redzone inside slub object */ | |
27 | #define KASAN_KMALLOC_FREE 0xFB /* object was freed (kmem_cache_free/kfree) */ | |
e4b7818b | 28 | #define KASAN_KMALLOC_FREETRACK 0xFA /* object was freed and has free track set */ |
7f94ffbc AK |
29 | #else |
30 | #define KASAN_FREE_PAGE KASAN_TAG_INVALID | |
31 | #define KASAN_PAGE_REDZONE KASAN_TAG_INVALID | |
32 | #define KASAN_KMALLOC_REDZONE KASAN_TAG_INVALID | |
33 | #define KASAN_KMALLOC_FREE KASAN_TAG_INVALID | |
e4b7818b | 34 | #define KASAN_KMALLOC_FREETRACK KASAN_TAG_INVALID |
7f94ffbc AK |
35 | #endif |
36 | ||
e4b7818b WW |
37 | #define KASAN_GLOBAL_REDZONE 0xF9 /* redzone for global variable */ |
38 | #define KASAN_VMALLOC_INVALID 0xF8 /* unallocated space in vmapped page */ | |
0316bec2 | 39 | |
c420f167 AR |
40 | /* |
41 | * Stack redzone shadow values | |
42 | * (Those are compiler's ABI, don't change them) | |
43 | */ | |
44 | #define KASAN_STACK_LEFT 0xF1 | |
45 | #define KASAN_STACK_MID 0xF2 | |
46 | #define KASAN_STACK_RIGHT 0xF3 | |
47 | #define KASAN_STACK_PARTIAL 0xF4 | |
48 | ||
342061ee PL |
49 | /* |
50 | * alloca redzone shadow values | |
51 | */ | |
52 | #define KASAN_ALLOCA_LEFT 0xCA | |
53 | #define KASAN_ALLOCA_RIGHT 0xCB | |
54 | ||
55 | #define KASAN_ALLOCA_REDZONE_SIZE 32 | |
56 | ||
e8969219 ME |
57 | /* |
58 | * Stack frame marker (compiler ABI). | |
59 | */ | |
60 | #define KASAN_CURRENT_STACK_FRAME_MAGIC 0x41B58AB3 | |
61 | ||
bebf56a1 AR |
62 | /* Don't break randconfig/all*config builds */ |
63 | #ifndef KASAN_ABI_VERSION | |
64 | #define KASAN_ABI_VERSION 1 | |
65 | #endif | |
b8c73fc2 | 66 | |
96e0279d AK |
67 | /* Metadata layout customization. */ |
68 | #define META_BYTES_PER_BLOCK 1 | |
69 | #define META_BLOCKS_PER_ROW 16 | |
70 | #define META_BYTES_PER_ROW (META_BLOCKS_PER_ROW * META_BYTES_PER_BLOCK) | |
71 | #define META_MEM_BYTES_PER_ROW (META_BYTES_PER_ROW * KASAN_GRANULE_SIZE) | |
72 | #define META_ROWS_AROUND_ADDR 2 | |
73 | ||
0b24becc AR |
74 | struct kasan_access_info { |
75 | const void *access_addr; | |
76 | const void *first_bad_addr; | |
77 | size_t access_size; | |
78 | bool is_write; | |
79 | unsigned long ip; | |
80 | }; | |
81 | ||
bebf56a1 AR |
82 | /* The layout of struct dictated by compiler */ |
83 | struct kasan_source_location { | |
84 | const char *filename; | |
85 | int line_no; | |
86 | int column_no; | |
87 | }; | |
88 | ||
89 | /* The layout of struct dictated by compiler */ | |
90 | struct kasan_global { | |
91 | const void *beg; /* Address of the beginning of the global variable. */ | |
92 | size_t size; /* Size of the global variable. */ | |
93 | size_t size_with_redzone; /* Size of the variable + size of the red zone. 32 bytes aligned */ | |
94 | const void *name; | |
95 | const void *module_name; /* Name of the module where the global variable is declared. */ | |
96 | unsigned long has_dynamic_init; /* This needed for C++ */ | |
97 | #if KASAN_ABI_VERSION >= 4 | |
98 | struct kasan_source_location *location; | |
99 | #endif | |
045d599a DV |
100 | #if KASAN_ABI_VERSION >= 5 |
101 | char *odr_indicator; | |
102 | #endif | |
bebf56a1 AR |
103 | }; |
104 | ||
7ed2f9e6 AP |
105 | /** |
106 | * Structures to keep alloc and free tracks * | |
107 | */ | |
108 | ||
cd11016e AP |
109 | #define KASAN_STACK_DEPTH 64 |
110 | ||
7ed2f9e6 | 111 | struct kasan_track { |
cd11016e AP |
112 | u32 pid; |
113 | depot_stack_handle_t stack; | |
7ed2f9e6 AP |
114 | }; |
115 | ||
ae8f06b3 WW |
116 | #ifdef CONFIG_KASAN_SW_TAGS_IDENTIFY |
117 | #define KASAN_NR_FREE_STACKS 5 | |
118 | #else | |
119 | #define KASAN_NR_FREE_STACKS 1 | |
120 | #endif | |
121 | ||
7ed2f9e6 | 122 | struct kasan_alloc_meta { |
b3cbd9bf | 123 | struct kasan_track alloc_track; |
26e760c9 WW |
124 | #ifdef CONFIG_KASAN_GENERIC |
125 | /* | |
126 | * call_rcu() call stack is stored into struct kasan_alloc_meta. | |
127 | * The free stack is stored into struct kasan_free_meta. | |
128 | */ | |
129 | depot_stack_handle_t aux_stack[2]; | |
e4b7818b | 130 | #else |
ae8f06b3 | 131 | struct kasan_track free_track[KASAN_NR_FREE_STACKS]; |
e4b7818b | 132 | #endif |
ae8f06b3 WW |
133 | #ifdef CONFIG_KASAN_SW_TAGS_IDENTIFY |
134 | u8 free_pointer_tag[KASAN_NR_FREE_STACKS]; | |
135 | u8 free_track_idx; | |
136 | #endif | |
7ed2f9e6 AP |
137 | }; |
138 | ||
55834c59 AP |
139 | struct qlist_node { |
140 | struct qlist_node *next; | |
141 | }; | |
7ed2f9e6 | 142 | struct kasan_free_meta { |
55834c59 AP |
143 | /* This field is used while the object is in the quarantine. |
144 | * Otherwise it might be used for the allocator freelist. | |
145 | */ | |
146 | struct qlist_node quarantine_link; | |
e4b7818b WW |
147 | #ifdef CONFIG_KASAN_GENERIC |
148 | struct kasan_track free_track; | |
149 | #endif | |
7ed2f9e6 AP |
150 | }; |
151 | ||
152 | struct kasan_alloc_meta *get_alloc_info(struct kmem_cache *cache, | |
153 | const void *object); | |
154 | struct kasan_free_meta *get_free_info(struct kmem_cache *cache, | |
155 | const void *object); | |
156 | ||
2e903b91 AK |
157 | void poison_range(const void *address, size_t size, u8 value); |
158 | void unpoison_range(const void *address, size_t size); | |
159 | ||
160 | #if defined(CONFIG_KASAN_GENERIC) || defined(CONFIG_KASAN_SW_TAGS) | |
161 | ||
0b24becc AR |
162 | static inline const void *kasan_shadow_to_mem(const void *shadow_addr) |
163 | { | |
164 | return (void *)(((unsigned long)shadow_addr - KASAN_SHADOW_OFFSET) | |
165 | << KASAN_SHADOW_SCALE_SHIFT); | |
166 | } | |
167 | ||
6882464f | 168 | static inline bool addr_has_metadata(const void *addr) |
11cd3cd6 AK |
169 | { |
170 | return (addr >= kasan_shadow_to_mem((void *)KASAN_SHADOW_START)); | |
171 | } | |
172 | ||
b5f6e0fc ME |
173 | /** |
174 | * check_memory_region - Check memory region, and report if invalid access. | |
175 | * @addr: the accessed address | |
176 | * @size: the accessed size | |
177 | * @write: true if access is a write access | |
178 | * @ret_ip: return address | |
179 | * @return: true if access was valid, false if invalid | |
180 | */ | |
181 | bool check_memory_region(unsigned long addr, size_t size, bool write, | |
bffa986c AK |
182 | unsigned long ret_ip); |
183 | ||
2e903b91 AK |
184 | #else /* CONFIG_KASAN_GENERIC || CONFIG_KASAN_SW_TAGS */ |
185 | ||
186 | static inline bool addr_has_metadata(const void *addr) | |
187 | { | |
188 | return true; | |
189 | } | |
190 | ||
191 | #endif /* CONFIG_KASAN_GENERIC || CONFIG_KASAN_SW_TAGS */ | |
192 | ||
2cdbed63 AK |
193 | bool check_invalid_free(void *addr); |
194 | ||
121e8f81 | 195 | void *find_first_bad_addr(void *addr, size_t size); |
11cd3cd6 | 196 | const char *get_bug_type(struct kasan_access_info *info); |
96e0279d | 197 | void metadata_fetch_row(char *buffer, void *row); |
11cd3cd6 | 198 | |
97fc7122 AK |
199 | #if defined(CONFIG_KASAN_GENERIC) && CONFIG_KASAN_STACK |
200 | void print_address_stack_frame(const void *addr); | |
201 | #else | |
202 | static inline void print_address_stack_frame(const void *addr) { } | |
203 | #endif | |
204 | ||
8cceeff4 | 205 | bool kasan_report(unsigned long addr, size_t size, |
0b24becc | 206 | bool is_write, unsigned long ip); |
ee3ce779 | 207 | void kasan_report_invalid_free(void *object, unsigned long ip); |
0b24becc | 208 | |
ae8f06b3 WW |
209 | struct page *kasan_addr_to_page(const void *addr); |
210 | ||
26e760c9 | 211 | depot_stack_handle_t kasan_save_stack(gfp_t flags); |
e4b7818b WW |
212 | void kasan_set_track(struct kasan_track *track, gfp_t flags); |
213 | void kasan_set_free_info(struct kmem_cache *cache, void *object, u8 tag); | |
214 | struct kasan_track *kasan_get_free_track(struct kmem_cache *cache, | |
215 | void *object, u8 tag); | |
26e760c9 | 216 | |
2bd926b4 AK |
217 | #if defined(CONFIG_KASAN_GENERIC) && \ |
218 | (defined(CONFIG_SLAB) || defined(CONFIG_SLUB)) | |
55834c59 AP |
219 | void quarantine_put(struct kasan_free_meta *info, struct kmem_cache *cache); |
220 | void quarantine_reduce(void); | |
221 | void quarantine_remove_cache(struct kmem_cache *cache); | |
222 | #else | |
223 | static inline void quarantine_put(struct kasan_free_meta *info, | |
224 | struct kmem_cache *cache) { } | |
225 | static inline void quarantine_reduce(void) { } | |
226 | static inline void quarantine_remove_cache(struct kmem_cache *cache) { } | |
227 | #endif | |
228 | ||
2e903b91 | 229 | #if defined(CONFIG_KASAN_SW_TAGS) || defined(CONFIG_KASAN_HW_TAGS) |
3c9e3aa1 | 230 | |
121e8f81 AK |
231 | void print_tags(u8 addr_tag, const void *addr); |
232 | ||
3c9e3aa1 AK |
233 | u8 random_tag(void); |
234 | ||
235 | #else | |
236 | ||
121e8f81 AK |
237 | static inline void print_tags(u8 addr_tag, const void *addr) { } |
238 | ||
3c9e3aa1 AK |
239 | static inline u8 random_tag(void) |
240 | { | |
241 | return 0; | |
242 | } | |
243 | ||
244 | #endif | |
245 | ||
246 | #ifndef arch_kasan_set_tag | |
c412a769 QC |
247 | static inline const void *arch_kasan_set_tag(const void *addr, u8 tag) |
248 | { | |
249 | return addr; | |
250 | } | |
3c9e3aa1 AK |
251 | #endif |
252 | #ifndef arch_kasan_reset_tag | |
253 | #define arch_kasan_reset_tag(addr) ((void *)(addr)) | |
254 | #endif | |
255 | #ifndef arch_kasan_get_tag | |
256 | #define arch_kasan_get_tag(addr) 0 | |
257 | #endif | |
258 | ||
259 | #define set_tag(addr, tag) ((void *)arch_kasan_set_tag((addr), (tag))) | |
260 | #define reset_tag(addr) ((void *)arch_kasan_reset_tag(addr)) | |
261 | #define get_tag(addr) arch_kasan_get_tag(addr) | |
262 | ||
ccbe2aab AK |
263 | #ifdef CONFIG_KASAN_HW_TAGS |
264 | ||
265 | #ifndef arch_enable_tagging | |
266 | #define arch_enable_tagging() | |
267 | #endif | |
268 | #ifndef arch_init_tags | |
269 | #define arch_init_tags(max_tag) | |
270 | #endif | |
271 | #ifndef arch_get_random_tag | |
272 | #define arch_get_random_tag() (0xFF) | |
273 | #endif | |
274 | #ifndef arch_get_mem_tag | |
275 | #define arch_get_mem_tag(addr) (0xFF) | |
276 | #endif | |
277 | #ifndef arch_set_mem_tag_range | |
278 | #define arch_set_mem_tag_range(addr, size, tag) ((void *)(addr)) | |
279 | #endif | |
280 | ||
281 | #define hw_enable_tagging() arch_enable_tagging() | |
282 | #define hw_init_tags(max_tag) arch_init_tags(max_tag) | |
283 | #define hw_get_random_tag() arch_get_random_tag() | |
284 | #define hw_get_mem_tag(addr) arch_get_mem_tag(addr) | |
285 | #define hw_set_mem_tag_range(addr, size, tag) arch_set_mem_tag_range((addr), (size), (tag)) | |
286 | ||
287 | #endif /* CONFIG_KASAN_HW_TAGS */ | |
288 | ||
d321599c AP |
289 | /* |
290 | * Exported functions for interfaces called from assembly or from generated | |
291 | * code. Declarations here to avoid warning about missing declarations. | |
292 | */ | |
293 | asmlinkage void kasan_unpoison_task_stack_below(const void *watermark); | |
294 | void __asan_register_globals(struct kasan_global *globals, size_t size); | |
295 | void __asan_unregister_globals(struct kasan_global *globals, size_t size); | |
d321599c | 296 | void __asan_handle_no_return(void); |
d321599c AP |
297 | void __asan_alloca_poison(unsigned long addr, size_t size); |
298 | void __asan_allocas_unpoison(const void *stack_top, const void *stack_bottom); | |
299 | ||
300 | void __asan_load1(unsigned long addr); | |
301 | void __asan_store1(unsigned long addr); | |
302 | void __asan_load2(unsigned long addr); | |
303 | void __asan_store2(unsigned long addr); | |
304 | void __asan_load4(unsigned long addr); | |
305 | void __asan_store4(unsigned long addr); | |
306 | void __asan_load8(unsigned long addr); | |
307 | void __asan_store8(unsigned long addr); | |
308 | void __asan_load16(unsigned long addr); | |
309 | void __asan_store16(unsigned long addr); | |
13cf0488 AK |
310 | void __asan_loadN(unsigned long addr, size_t size); |
311 | void __asan_storeN(unsigned long addr, size_t size); | |
d321599c AP |
312 | |
313 | void __asan_load1_noabort(unsigned long addr); | |
314 | void __asan_store1_noabort(unsigned long addr); | |
315 | void __asan_load2_noabort(unsigned long addr); | |
316 | void __asan_store2_noabort(unsigned long addr); | |
317 | void __asan_load4_noabort(unsigned long addr); | |
318 | void __asan_store4_noabort(unsigned long addr); | |
319 | void __asan_load8_noabort(unsigned long addr); | |
320 | void __asan_store8_noabort(unsigned long addr); | |
321 | void __asan_load16_noabort(unsigned long addr); | |
322 | void __asan_store16_noabort(unsigned long addr); | |
13cf0488 AK |
323 | void __asan_loadN_noabort(unsigned long addr, size_t size); |
324 | void __asan_storeN_noabort(unsigned long addr, size_t size); | |
325 | ||
326 | void __asan_report_load1_noabort(unsigned long addr); | |
327 | void __asan_report_store1_noabort(unsigned long addr); | |
328 | void __asan_report_load2_noabort(unsigned long addr); | |
329 | void __asan_report_store2_noabort(unsigned long addr); | |
330 | void __asan_report_load4_noabort(unsigned long addr); | |
331 | void __asan_report_store4_noabort(unsigned long addr); | |
332 | void __asan_report_load8_noabort(unsigned long addr); | |
333 | void __asan_report_store8_noabort(unsigned long addr); | |
334 | void __asan_report_load16_noabort(unsigned long addr); | |
335 | void __asan_report_store16_noabort(unsigned long addr); | |
336 | void __asan_report_load_n_noabort(unsigned long addr, size_t size); | |
337 | void __asan_report_store_n_noabort(unsigned long addr, size_t size); | |
d321599c AP |
338 | |
339 | void __asan_set_shadow_00(const void *addr, size_t size); | |
340 | void __asan_set_shadow_f1(const void *addr, size_t size); | |
341 | void __asan_set_shadow_f2(const void *addr, size_t size); | |
342 | void __asan_set_shadow_f3(const void *addr, size_t size); | |
343 | void __asan_set_shadow_f5(const void *addr, size_t size); | |
344 | void __asan_set_shadow_f8(const void *addr, size_t size); | |
345 | ||
13cf0488 AK |
346 | void __hwasan_load1_noabort(unsigned long addr); |
347 | void __hwasan_store1_noabort(unsigned long addr); | |
348 | void __hwasan_load2_noabort(unsigned long addr); | |
349 | void __hwasan_store2_noabort(unsigned long addr); | |
350 | void __hwasan_load4_noabort(unsigned long addr); | |
351 | void __hwasan_store4_noabort(unsigned long addr); | |
352 | void __hwasan_load8_noabort(unsigned long addr); | |
353 | void __hwasan_store8_noabort(unsigned long addr); | |
354 | void __hwasan_load16_noabort(unsigned long addr); | |
355 | void __hwasan_store16_noabort(unsigned long addr); | |
356 | void __hwasan_loadN_noabort(unsigned long addr, size_t size); | |
357 | void __hwasan_storeN_noabort(unsigned long addr, size_t size); | |
358 | ||
359 | void __hwasan_tag_memory(unsigned long addr, u8 tag, unsigned long size); | |
360 | ||
0b24becc | 361 | #endif |