2020-12-22 20:02:10 +00:00
|
|
|
// SPDX-License-Identifier: GPL-2.0
|
|
|
|
/*
|
|
|
|
* This file contains core hardware tag-based KASAN code.
|
|
|
|
*
|
|
|
|
* Copyright (c) 2020 Google, Inc.
|
|
|
|
* Author: Andrey Konovalov <andreyknvl@google.com>
|
|
|
|
*/
|
|
|
|
|
|
|
|
#define pr_fmt(fmt) "kasan: " fmt
|
|
|
|
|
2020-12-22 20:03:06 +00:00
|
|
|
#include <linux/init.h>
|
2020-12-22 20:02:10 +00:00
|
|
|
#include <linux/kasan.h>
|
|
|
|
#include <linux/kernel.h>
|
|
|
|
#include <linux/memory.h>
|
|
|
|
#include <linux/mm.h>
|
2020-12-22 20:03:06 +00:00
|
|
|
#include <linux/static_key.h>
|
2020-12-22 20:02:10 +00:00
|
|
|
#include <linux/string.h>
|
|
|
|
#include <linux/types.h>
|
|
|
|
|
|
|
|
#include "kasan.h"
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
enum kasan_arg {
|
|
|
|
KASAN_ARG_DEFAULT,
|
|
|
|
KASAN_ARG_OFF,
|
|
|
|
KASAN_ARG_ON,
|
2020-12-22 20:03:06 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
enum kasan_arg_stacktrace {
|
|
|
|
KASAN_ARG_STACKTRACE_DEFAULT,
|
|
|
|
KASAN_ARG_STACKTRACE_OFF,
|
|
|
|
KASAN_ARG_STACKTRACE_ON,
|
|
|
|
};
|
|
|
|
|
|
|
|
enum kasan_arg_fault {
|
|
|
|
KASAN_ARG_FAULT_DEFAULT,
|
|
|
|
KASAN_ARG_FAULT_REPORT,
|
|
|
|
KASAN_ARG_FAULT_PANIC,
|
|
|
|
};
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
static enum kasan_arg kasan_arg __ro_after_init;
|
2020-12-22 20:03:06 +00:00
|
|
|
static enum kasan_arg_stacktrace kasan_arg_stacktrace __ro_after_init;
|
|
|
|
static enum kasan_arg_fault kasan_arg_fault __ro_after_init;
|
|
|
|
|
|
|
|
/* Whether KASAN is enabled at all. */
|
|
|
|
DEFINE_STATIC_KEY_FALSE(kasan_flag_enabled);
|
|
|
|
EXPORT_SYMBOL(kasan_flag_enabled);
|
|
|
|
|
|
|
|
/* Whether to collect alloc/free stack traces. */
|
|
|
|
DEFINE_STATIC_KEY_FALSE(kasan_flag_stacktrace);
|
|
|
|
|
2021-02-26 01:20:38 +00:00
|
|
|
/* Whether to panic or print a report and disable tag checking on fault. */
|
2020-12-22 20:03:06 +00:00
|
|
|
bool kasan_flag_panic __ro_after_init;
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
/* kasan=off/on */
|
|
|
|
static int __init early_kasan_flag(char *arg)
|
2020-12-22 20:03:06 +00:00
|
|
|
{
|
|
|
|
if (!arg)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (!strcmp(arg, "off"))
|
2021-01-24 05:01:34 +00:00
|
|
|
kasan_arg = KASAN_ARG_OFF;
|
|
|
|
else if (!strcmp(arg, "on"))
|
|
|
|
kasan_arg = KASAN_ARG_ON;
|
2020-12-22 20:03:06 +00:00
|
|
|
else
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
2021-01-24 05:01:34 +00:00
|
|
|
early_param("kasan", early_kasan_flag);
|
2020-12-22 20:03:06 +00:00
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
/* kasan.stacktrace=off/on */
|
2020-12-22 20:03:06 +00:00
|
|
|
static int __init early_kasan_flag_stacktrace(char *arg)
|
|
|
|
{
|
|
|
|
if (!arg)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (!strcmp(arg, "off"))
|
|
|
|
kasan_arg_stacktrace = KASAN_ARG_STACKTRACE_OFF;
|
|
|
|
else if (!strcmp(arg, "on"))
|
|
|
|
kasan_arg_stacktrace = KASAN_ARG_STACKTRACE_ON;
|
|
|
|
else
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
early_param("kasan.stacktrace", early_kasan_flag_stacktrace);
|
|
|
|
|
|
|
|
/* kasan.fault=report/panic */
|
|
|
|
static int __init early_kasan_fault(char *arg)
|
|
|
|
{
|
|
|
|
if (!arg)
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
if (!strcmp(arg, "report"))
|
|
|
|
kasan_arg_fault = KASAN_ARG_FAULT_REPORT;
|
|
|
|
else if (!strcmp(arg, "panic"))
|
|
|
|
kasan_arg_fault = KASAN_ARG_FAULT_PANIC;
|
|
|
|
else
|
|
|
|
return -EINVAL;
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
early_param("kasan.fault", early_kasan_fault);
|
|
|
|
|
2020-12-22 20:02:10 +00:00
|
|
|
/* kasan_init_hw_tags_cpu() is called for each CPU. */
|
|
|
|
void kasan_init_hw_tags_cpu(void)
|
|
|
|
{
|
2020-12-22 20:03:06 +00:00
|
|
|
/*
|
|
|
|
* There's no need to check that the hardware is MTE-capable here,
|
|
|
|
* as this function is only called for MTE-capable hardware.
|
|
|
|
*/
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
/* If KASAN is disabled via command line, don't initialize it. */
|
|
|
|
if (kasan_arg == KASAN_ARG_OFF)
|
2020-12-22 20:03:06 +00:00
|
|
|
return;
|
|
|
|
|
2020-12-22 20:02:10 +00:00
|
|
|
hw_init_tags(KASAN_TAG_MAX);
|
|
|
|
hw_enable_tagging();
|
|
|
|
}
|
|
|
|
|
|
|
|
/* kasan_init_hw_tags() is called once on boot CPU. */
|
|
|
|
void __init kasan_init_hw_tags(void)
|
|
|
|
{
|
2021-01-24 05:01:34 +00:00
|
|
|
/* If hardware doesn't support MTE, don't initialize KASAN. */
|
2020-12-22 20:03:06 +00:00
|
|
|
if (!system_supports_mte())
|
|
|
|
return;
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
/* If KASAN is disabled via command line, don't initialize it. */
|
|
|
|
if (kasan_arg == KASAN_ARG_OFF)
|
2020-12-22 20:03:06 +00:00
|
|
|
return;
|
|
|
|
|
2021-01-24 05:01:34 +00:00
|
|
|
/* Enable KASAN. */
|
|
|
|
static_branch_enable(&kasan_flag_enabled);
|
2020-12-22 20:03:06 +00:00
|
|
|
|
|
|
|
switch (kasan_arg_stacktrace) {
|
|
|
|
case KASAN_ARG_STACKTRACE_DEFAULT:
|
2021-02-09 21:42:03 +00:00
|
|
|
/* Default to enabling stack trace collection. */
|
|
|
|
static_branch_enable(&kasan_flag_stacktrace);
|
2020-12-22 20:03:06 +00:00
|
|
|
break;
|
|
|
|
case KASAN_ARG_STACKTRACE_OFF:
|
2021-01-24 05:01:34 +00:00
|
|
|
/* Do nothing, kasan_flag_stacktrace keeps its default value. */
|
2020-12-22 20:03:06 +00:00
|
|
|
break;
|
|
|
|
case KASAN_ARG_STACKTRACE_ON:
|
|
|
|
static_branch_enable(&kasan_flag_stacktrace);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch (kasan_arg_fault) {
|
|
|
|
case KASAN_ARG_FAULT_DEFAULT:
|
2021-01-24 05:01:34 +00:00
|
|
|
/*
|
|
|
|
* Default to no panic on report.
|
|
|
|
* Do nothing, kasan_flag_panic keeps its default value.
|
|
|
|
*/
|
2020-12-22 20:03:06 +00:00
|
|
|
break;
|
|
|
|
case KASAN_ARG_FAULT_REPORT:
|
2021-01-24 05:01:34 +00:00
|
|
|
/* Do nothing, kasan_flag_panic keeps its default value. */
|
2020-12-22 20:03:06 +00:00
|
|
|
break;
|
|
|
|
case KASAN_ARG_FAULT_PANIC:
|
2021-01-24 05:01:34 +00:00
|
|
|
/* Enable panic on report. */
|
2020-12-22 20:03:06 +00:00
|
|
|
kasan_flag_panic = true;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2020-12-22 20:02:10 +00:00
|
|
|
pr_info("KernelAddressSanitizer initialized\n");
|
|
|
|
}
|
|
|
|
|
|
|
|
void kasan_set_free_info(struct kmem_cache *cache,
|
|
|
|
void *object, u8 tag)
|
|
|
|
{
|
|
|
|
struct kasan_alloc_meta *alloc_meta;
|
|
|
|
|
2020-12-22 20:02:34 +00:00
|
|
|
alloc_meta = kasan_get_alloc_meta(cache, object);
|
2020-12-22 20:03:28 +00:00
|
|
|
if (alloc_meta)
|
|
|
|
kasan_set_track(&alloc_meta->free_track[0], GFP_NOWAIT);
|
2020-12-22 20:02:10 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
struct kasan_track *kasan_get_free_track(struct kmem_cache *cache,
|
|
|
|
void *object, u8 tag)
|
|
|
|
{
|
|
|
|
struct kasan_alloc_meta *alloc_meta;
|
|
|
|
|
2020-12-22 20:02:34 +00:00
|
|
|
alloc_meta = kasan_get_alloc_meta(cache, object);
|
2020-12-22 20:03:28 +00:00
|
|
|
if (!alloc_meta)
|
|
|
|
return NULL;
|
|
|
|
|
2020-12-22 20:02:10 +00:00
|
|
|
return &alloc_meta->free_track[0];
|
|
|
|
}
|
2021-02-24 20:05:26 +00:00
|
|
|
|
|
|
|
#if IS_ENABLED(CONFIG_KASAN_KUNIT_TEST)
|
|
|
|
|
|
|
|
void kasan_set_tagging_report_once(bool state)
|
|
|
|
{
|
|
|
|
hw_set_tagging_report_once(state);
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(kasan_set_tagging_report_once);
|
|
|
|
|
|
|
|
void kasan_enable_tagging(void)
|
|
|
|
{
|
|
|
|
hw_enable_tagging();
|
|
|
|
}
|
|
|
|
EXPORT_SYMBOL_GPL(kasan_enable_tagging);
|
|
|
|
|
|
|
|
#endif
|