ptrace.c 57 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /*
  3. * Based on arch/arm/kernel/ptrace.c
  4. *
  5. * By Ross Biro 1/23/92
  6. * edited by Linus Torvalds
  7. * ARM modifications Copyright (C) 2000 Russell King
  8. * Copyright (C) 2012 ARM Ltd.
  9. */
  10. #include <linux/audit.h>
  11. #include <linux/compat.h>
  12. #include <linux/kernel.h>
  13. #include <linux/sched/signal.h>
  14. #include <linux/sched/task_stack.h>
  15. #include <linux/mm.h>
  16. #include <linux/nospec.h>
  17. #include <linux/smp.h>
  18. #include <linux/ptrace.h>
  19. #include <linux/user.h>
  20. #include <linux/seccomp.h>
  21. #include <linux/security.h>
  22. #include <linux/init.h>
  23. #include <linux/signal.h>
  24. #include <linux/string.h>
  25. #include <linux/uaccess.h>
  26. #include <linux/perf_event.h>
  27. #include <linux/hw_breakpoint.h>
  28. #include <linux/regset.h>
  29. #include <linux/elf.h>
  30. #include <linux/rseq.h>
  31. #include <asm/compat.h>
  32. #include <asm/cpufeature.h>
  33. #include <asm/debug-monitors.h>
  34. #include <asm/fpsimd.h>
  35. #include <asm/mte.h>
  36. #include <asm/pointer_auth.h>
  37. #include <asm/stacktrace.h>
  38. #include <asm/syscall.h>
  39. #include <asm/traps.h>
  40. #include <asm/system_misc.h>
  41. #define CREATE_TRACE_POINTS
  42. #include <trace/events/syscalls.h>
  43. struct pt_regs_offset {
  44. const char *name;
  45. int offset;
  46. };
  47. #define REG_OFFSET_NAME(r) {.name = #r, .offset = offsetof(struct pt_regs, r)}
  48. #define REG_OFFSET_END {.name = NULL, .offset = 0}
  49. #define GPR_OFFSET_NAME(r) \
  50. {.name = "x" #r, .offset = offsetof(struct pt_regs, regs[r])}
  51. static const struct pt_regs_offset regoffset_table[] = {
  52. GPR_OFFSET_NAME(0),
  53. GPR_OFFSET_NAME(1),
  54. GPR_OFFSET_NAME(2),
  55. GPR_OFFSET_NAME(3),
  56. GPR_OFFSET_NAME(4),
  57. GPR_OFFSET_NAME(5),
  58. GPR_OFFSET_NAME(6),
  59. GPR_OFFSET_NAME(7),
  60. GPR_OFFSET_NAME(8),
  61. GPR_OFFSET_NAME(9),
  62. GPR_OFFSET_NAME(10),
  63. GPR_OFFSET_NAME(11),
  64. GPR_OFFSET_NAME(12),
  65. GPR_OFFSET_NAME(13),
  66. GPR_OFFSET_NAME(14),
  67. GPR_OFFSET_NAME(15),
  68. GPR_OFFSET_NAME(16),
  69. GPR_OFFSET_NAME(17),
  70. GPR_OFFSET_NAME(18),
  71. GPR_OFFSET_NAME(19),
  72. GPR_OFFSET_NAME(20),
  73. GPR_OFFSET_NAME(21),
  74. GPR_OFFSET_NAME(22),
  75. GPR_OFFSET_NAME(23),
  76. GPR_OFFSET_NAME(24),
  77. GPR_OFFSET_NAME(25),
  78. GPR_OFFSET_NAME(26),
  79. GPR_OFFSET_NAME(27),
  80. GPR_OFFSET_NAME(28),
  81. GPR_OFFSET_NAME(29),
  82. GPR_OFFSET_NAME(30),
  83. {.name = "lr", .offset = offsetof(struct pt_regs, regs[30])},
  84. REG_OFFSET_NAME(sp),
  85. REG_OFFSET_NAME(pc),
  86. REG_OFFSET_NAME(pstate),
  87. REG_OFFSET_END,
  88. };
  89. /**
  90. * regs_query_register_offset() - query register offset from its name
  91. * @name: the name of a register
  92. *
  93. * regs_query_register_offset() returns the offset of a register in struct
  94. * pt_regs from its name. If the name is invalid, this returns -EINVAL;
  95. */
  96. int regs_query_register_offset(const char *name)
  97. {
  98. const struct pt_regs_offset *roff;
  99. for (roff = regoffset_table; roff->name != NULL; roff++)
  100. if (!strcmp(roff->name, name))
  101. return roff->offset;
  102. return -EINVAL;
  103. }
  104. /**
  105. * regs_within_kernel_stack() - check the address in the stack
  106. * @regs: pt_regs which contains kernel stack pointer.
  107. * @addr: address which is checked.
  108. *
  109. * regs_within_kernel_stack() checks @addr is within the kernel stack page(s).
  110. * If @addr is within the kernel stack, it returns true. If not, returns false.
  111. */
  112. static bool regs_within_kernel_stack(struct pt_regs *regs, unsigned long addr)
  113. {
  114. return ((addr & ~(THREAD_SIZE - 1)) ==
  115. (kernel_stack_pointer(regs) & ~(THREAD_SIZE - 1))) ||
  116. on_irq_stack(addr, sizeof(unsigned long));
  117. }
  118. /**
  119. * regs_get_kernel_stack_nth() - get Nth entry of the stack
  120. * @regs: pt_regs which contains kernel stack pointer.
  121. * @n: stack entry number.
  122. *
  123. * regs_get_kernel_stack_nth() returns @n th entry of the kernel stack which
  124. * is specified by @regs. If the @n th entry is NOT in the kernel stack,
  125. * this returns 0.
  126. */
  127. unsigned long regs_get_kernel_stack_nth(struct pt_regs *regs, unsigned int n)
  128. {
  129. unsigned long *addr = (unsigned long *)kernel_stack_pointer(regs);
  130. addr += n;
  131. if (regs_within_kernel_stack(regs, (unsigned long)addr))
  132. return READ_ONCE_NOCHECK(*addr);
  133. else
  134. return 0;
  135. }
  136. /*
  137. * TODO: does not yet catch signals sent when the child dies.
  138. * in exit.c or in signal.c.
  139. */
  140. /*
  141. * Called by kernel/ptrace.c when detaching..
  142. */
  143. void ptrace_disable(struct task_struct *child)
  144. {
  145. /*
  146. * This would be better off in core code, but PTRACE_DETACH has
  147. * grown its fair share of arch-specific worts and changing it
  148. * is likely to cause regressions on obscure architectures.
  149. */
  150. user_disable_single_step(child);
  151. }
  152. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  153. /*
  154. * Handle hitting a HW-breakpoint.
  155. */
  156. static void ptrace_hbptriggered(struct perf_event *bp,
  157. struct perf_sample_data *data,
  158. struct pt_regs *regs)
  159. {
  160. struct arch_hw_breakpoint *bkpt = counter_arch_bp(bp);
  161. const char *desc = "Hardware breakpoint trap (ptrace)";
  162. if (is_compat_task()) {
  163. int si_errno = 0;
  164. int i;
  165. for (i = 0; i < ARM_MAX_BRP; ++i) {
  166. if (current->thread.debug.hbp_break[i] == bp) {
  167. si_errno = (i << 1) + 1;
  168. break;
  169. }
  170. }
  171. for (i = 0; i < ARM_MAX_WRP; ++i) {
  172. if (current->thread.debug.hbp_watch[i] == bp) {
  173. si_errno = -((i << 1) + 1);
  174. break;
  175. }
  176. }
  177. arm64_force_sig_ptrace_errno_trap(si_errno, bkpt->trigger,
  178. desc);
  179. return;
  180. }
  181. arm64_force_sig_fault(SIGTRAP, TRAP_HWBKPT, bkpt->trigger, desc);
  182. }
  183. /*
  184. * Unregister breakpoints from this task and reset the pointers in
  185. * the thread_struct.
  186. */
  187. void flush_ptrace_hw_breakpoint(struct task_struct *tsk)
  188. {
  189. int i;
  190. struct thread_struct *t = &tsk->thread;
  191. for (i = 0; i < ARM_MAX_BRP; i++) {
  192. if (t->debug.hbp_break[i]) {
  193. unregister_hw_breakpoint(t->debug.hbp_break[i]);
  194. t->debug.hbp_break[i] = NULL;
  195. }
  196. }
  197. for (i = 0; i < ARM_MAX_WRP; i++) {
  198. if (t->debug.hbp_watch[i]) {
  199. unregister_hw_breakpoint(t->debug.hbp_watch[i]);
  200. t->debug.hbp_watch[i] = NULL;
  201. }
  202. }
  203. }
  204. void ptrace_hw_copy_thread(struct task_struct *tsk)
  205. {
  206. memset(&tsk->thread.debug, 0, sizeof(struct debug_info));
  207. }
  208. static struct perf_event *ptrace_hbp_get_event(unsigned int note_type,
  209. struct task_struct *tsk,
  210. unsigned long idx)
  211. {
  212. struct perf_event *bp = ERR_PTR(-EINVAL);
  213. switch (note_type) {
  214. case NT_ARM_HW_BREAK:
  215. if (idx >= ARM_MAX_BRP)
  216. goto out;
  217. idx = array_index_nospec(idx, ARM_MAX_BRP);
  218. bp = tsk->thread.debug.hbp_break[idx];
  219. break;
  220. case NT_ARM_HW_WATCH:
  221. if (idx >= ARM_MAX_WRP)
  222. goto out;
  223. idx = array_index_nospec(idx, ARM_MAX_WRP);
  224. bp = tsk->thread.debug.hbp_watch[idx];
  225. break;
  226. }
  227. out:
  228. return bp;
  229. }
  230. static int ptrace_hbp_set_event(unsigned int note_type,
  231. struct task_struct *tsk,
  232. unsigned long idx,
  233. struct perf_event *bp)
  234. {
  235. int err = -EINVAL;
  236. switch (note_type) {
  237. case NT_ARM_HW_BREAK:
  238. if (idx >= ARM_MAX_BRP)
  239. goto out;
  240. idx = array_index_nospec(idx, ARM_MAX_BRP);
  241. tsk->thread.debug.hbp_break[idx] = bp;
  242. err = 0;
  243. break;
  244. case NT_ARM_HW_WATCH:
  245. if (idx >= ARM_MAX_WRP)
  246. goto out;
  247. idx = array_index_nospec(idx, ARM_MAX_WRP);
  248. tsk->thread.debug.hbp_watch[idx] = bp;
  249. err = 0;
  250. break;
  251. }
  252. out:
  253. return err;
  254. }
  255. static struct perf_event *ptrace_hbp_create(unsigned int note_type,
  256. struct task_struct *tsk,
  257. unsigned long idx)
  258. {
  259. struct perf_event *bp;
  260. struct perf_event_attr attr;
  261. int err, type;
  262. switch (note_type) {
  263. case NT_ARM_HW_BREAK:
  264. type = HW_BREAKPOINT_X;
  265. break;
  266. case NT_ARM_HW_WATCH:
  267. type = HW_BREAKPOINT_RW;
  268. break;
  269. default:
  270. return ERR_PTR(-EINVAL);
  271. }
  272. ptrace_breakpoint_init(&attr);
  273. /*
  274. * Initialise fields to sane defaults
  275. * (i.e. values that will pass validation).
  276. */
  277. attr.bp_addr = 0;
  278. attr.bp_len = HW_BREAKPOINT_LEN_4;
  279. attr.bp_type = type;
  280. attr.disabled = 1;
  281. bp = register_user_hw_breakpoint(&attr, ptrace_hbptriggered, NULL, tsk);
  282. if (IS_ERR(bp))
  283. return bp;
  284. err = ptrace_hbp_set_event(note_type, tsk, idx, bp);
  285. if (err)
  286. return ERR_PTR(err);
  287. return bp;
  288. }
  289. static int ptrace_hbp_fill_attr_ctrl(unsigned int note_type,
  290. struct arch_hw_breakpoint_ctrl ctrl,
  291. struct perf_event_attr *attr)
  292. {
  293. int err, len, type, offset, disabled = !ctrl.enabled;
  294. attr->disabled = disabled;
  295. if (disabled)
  296. return 0;
  297. err = arch_bp_generic_fields(ctrl, &len, &type, &offset);
  298. if (err)
  299. return err;
  300. switch (note_type) {
  301. case NT_ARM_HW_BREAK:
  302. if ((type & HW_BREAKPOINT_X) != type)
  303. return -EINVAL;
  304. break;
  305. case NT_ARM_HW_WATCH:
  306. if ((type & HW_BREAKPOINT_RW) != type)
  307. return -EINVAL;
  308. break;
  309. default:
  310. return -EINVAL;
  311. }
  312. attr->bp_len = len;
  313. attr->bp_type = type;
  314. attr->bp_addr += offset;
  315. return 0;
  316. }
  317. static int ptrace_hbp_get_resource_info(unsigned int note_type, u32 *info)
  318. {
  319. u8 num;
  320. u32 reg = 0;
  321. switch (note_type) {
  322. case NT_ARM_HW_BREAK:
  323. num = hw_breakpoint_slots(TYPE_INST);
  324. break;
  325. case NT_ARM_HW_WATCH:
  326. num = hw_breakpoint_slots(TYPE_DATA);
  327. break;
  328. default:
  329. return -EINVAL;
  330. }
  331. reg |= debug_monitors_arch();
  332. reg <<= 8;
  333. reg |= num;
  334. *info = reg;
  335. return 0;
  336. }
  337. static int ptrace_hbp_get_ctrl(unsigned int note_type,
  338. struct task_struct *tsk,
  339. unsigned long idx,
  340. u32 *ctrl)
  341. {
  342. struct perf_event *bp = ptrace_hbp_get_event(note_type, tsk, idx);
  343. if (IS_ERR(bp))
  344. return PTR_ERR(bp);
  345. *ctrl = bp ? encode_ctrl_reg(counter_arch_bp(bp)->ctrl) : 0;
  346. return 0;
  347. }
  348. static int ptrace_hbp_get_addr(unsigned int note_type,
  349. struct task_struct *tsk,
  350. unsigned long idx,
  351. u64 *addr)
  352. {
  353. struct perf_event *bp = ptrace_hbp_get_event(note_type, tsk, idx);
  354. if (IS_ERR(bp))
  355. return PTR_ERR(bp);
  356. *addr = bp ? counter_arch_bp(bp)->address : 0;
  357. return 0;
  358. }
  359. static struct perf_event *ptrace_hbp_get_initialised_bp(unsigned int note_type,
  360. struct task_struct *tsk,
  361. unsigned long idx)
  362. {
  363. struct perf_event *bp = ptrace_hbp_get_event(note_type, tsk, idx);
  364. if (!bp)
  365. bp = ptrace_hbp_create(note_type, tsk, idx);
  366. return bp;
  367. }
  368. static int ptrace_hbp_set_ctrl(unsigned int note_type,
  369. struct task_struct *tsk,
  370. unsigned long idx,
  371. u32 uctrl)
  372. {
  373. int err;
  374. struct perf_event *bp;
  375. struct perf_event_attr attr;
  376. struct arch_hw_breakpoint_ctrl ctrl;
  377. bp = ptrace_hbp_get_initialised_bp(note_type, tsk, idx);
  378. if (IS_ERR(bp)) {
  379. err = PTR_ERR(bp);
  380. return err;
  381. }
  382. attr = bp->attr;
  383. decode_ctrl_reg(uctrl, &ctrl);
  384. err = ptrace_hbp_fill_attr_ctrl(note_type, ctrl, &attr);
  385. if (err)
  386. return err;
  387. return modify_user_hw_breakpoint(bp, &attr);
  388. }
  389. static int ptrace_hbp_set_addr(unsigned int note_type,
  390. struct task_struct *tsk,
  391. unsigned long idx,
  392. u64 addr)
  393. {
  394. int err;
  395. struct perf_event *bp;
  396. struct perf_event_attr attr;
  397. bp = ptrace_hbp_get_initialised_bp(note_type, tsk, idx);
  398. if (IS_ERR(bp)) {
  399. err = PTR_ERR(bp);
  400. return err;
  401. }
  402. attr = bp->attr;
  403. attr.bp_addr = addr;
  404. err = modify_user_hw_breakpoint(bp, &attr);
  405. return err;
  406. }
  407. #define PTRACE_HBP_ADDR_SZ sizeof(u64)
  408. #define PTRACE_HBP_CTRL_SZ sizeof(u32)
  409. #define PTRACE_HBP_PAD_SZ sizeof(u32)
  410. static int hw_break_get(struct task_struct *target,
  411. const struct user_regset *regset,
  412. struct membuf to)
  413. {
  414. unsigned int note_type = regset->core_note_type;
  415. int ret, idx = 0;
  416. u32 info, ctrl;
  417. u64 addr;
  418. /* Resource info */
  419. ret = ptrace_hbp_get_resource_info(note_type, &info);
  420. if (ret)
  421. return ret;
  422. membuf_write(&to, &info, sizeof(info));
  423. membuf_zero(&to, sizeof(u32));
  424. /* (address, ctrl) registers */
  425. while (to.left) {
  426. ret = ptrace_hbp_get_addr(note_type, target, idx, &addr);
  427. if (ret)
  428. return ret;
  429. ret = ptrace_hbp_get_ctrl(note_type, target, idx, &ctrl);
  430. if (ret)
  431. return ret;
  432. membuf_store(&to, addr);
  433. membuf_store(&to, ctrl);
  434. membuf_zero(&to, sizeof(u32));
  435. idx++;
  436. }
  437. return 0;
  438. }
  439. static int hw_break_set(struct task_struct *target,
  440. const struct user_regset *regset,
  441. unsigned int pos, unsigned int count,
  442. const void *kbuf, const void __user *ubuf)
  443. {
  444. unsigned int note_type = regset->core_note_type;
  445. int ret, idx = 0, offset, limit;
  446. u32 ctrl;
  447. u64 addr;
  448. /* Resource info and pad */
  449. offset = offsetof(struct user_hwdebug_state, dbg_regs);
  450. user_regset_copyin_ignore(&pos, &count, &kbuf, &ubuf, 0, offset);
  451. /* (address, ctrl) registers */
  452. limit = regset->n * regset->size;
  453. while (count && offset < limit) {
  454. if (count < PTRACE_HBP_ADDR_SZ)
  455. return -EINVAL;
  456. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &addr,
  457. offset, offset + PTRACE_HBP_ADDR_SZ);
  458. if (ret)
  459. return ret;
  460. ret = ptrace_hbp_set_addr(note_type, target, idx, addr);
  461. if (ret)
  462. return ret;
  463. offset += PTRACE_HBP_ADDR_SZ;
  464. if (!count)
  465. break;
  466. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl,
  467. offset, offset + PTRACE_HBP_CTRL_SZ);
  468. if (ret)
  469. return ret;
  470. ret = ptrace_hbp_set_ctrl(note_type, target, idx, ctrl);
  471. if (ret)
  472. return ret;
  473. offset += PTRACE_HBP_CTRL_SZ;
  474. user_regset_copyin_ignore(&pos, &count, &kbuf, &ubuf,
  475. offset, offset + PTRACE_HBP_PAD_SZ);
  476. offset += PTRACE_HBP_PAD_SZ;
  477. idx++;
  478. }
  479. return 0;
  480. }
  481. #endif /* CONFIG_HAVE_HW_BREAKPOINT */
  482. static int gpr_get(struct task_struct *target,
  483. const struct user_regset *regset,
  484. struct membuf to)
  485. {
  486. struct user_pt_regs *uregs = &task_pt_regs(target)->user_regs;
  487. return membuf_write(&to, uregs, sizeof(*uregs));
  488. }
  489. static int gpr_set(struct task_struct *target, const struct user_regset *regset,
  490. unsigned int pos, unsigned int count,
  491. const void *kbuf, const void __user *ubuf)
  492. {
  493. int ret;
  494. struct user_pt_regs newregs = task_pt_regs(target)->user_regs;
  495. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &newregs, 0, -1);
  496. if (ret)
  497. return ret;
  498. if (!valid_user_regs(&newregs, target))
  499. return -EINVAL;
  500. task_pt_regs(target)->user_regs = newregs;
  501. return 0;
  502. }
  503. static int fpr_active(struct task_struct *target, const struct user_regset *regset)
  504. {
  505. if (!system_supports_fpsimd())
  506. return -ENODEV;
  507. return regset->n;
  508. }
  509. /*
  510. * TODO: update fp accessors for lazy context switching (sync/flush hwstate)
  511. */
  512. static int __fpr_get(struct task_struct *target,
  513. const struct user_regset *regset,
  514. struct membuf to)
  515. {
  516. struct user_fpsimd_state *uregs;
  517. sve_sync_to_fpsimd(target);
  518. uregs = &target->thread.uw.fpsimd_state;
  519. return membuf_write(&to, uregs, sizeof(*uregs));
  520. }
  521. static int fpr_get(struct task_struct *target, const struct user_regset *regset,
  522. struct membuf to)
  523. {
  524. if (!system_supports_fpsimd())
  525. return -EINVAL;
  526. if (target == current)
  527. fpsimd_preserve_current_state();
  528. return __fpr_get(target, regset, to);
  529. }
  530. static int __fpr_set(struct task_struct *target,
  531. const struct user_regset *regset,
  532. unsigned int pos, unsigned int count,
  533. const void *kbuf, const void __user *ubuf,
  534. unsigned int start_pos)
  535. {
  536. int ret;
  537. struct user_fpsimd_state newstate;
  538. /*
  539. * Ensure target->thread.uw.fpsimd_state is up to date, so that a
  540. * short copyin can't resurrect stale data.
  541. */
  542. sve_sync_to_fpsimd(target);
  543. newstate = target->thread.uw.fpsimd_state;
  544. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &newstate,
  545. start_pos, start_pos + sizeof(newstate));
  546. if (ret)
  547. return ret;
  548. target->thread.uw.fpsimd_state = newstate;
  549. return ret;
  550. }
  551. static int fpr_set(struct task_struct *target, const struct user_regset *regset,
  552. unsigned int pos, unsigned int count,
  553. const void *kbuf, const void __user *ubuf)
  554. {
  555. int ret;
  556. if (!system_supports_fpsimd())
  557. return -EINVAL;
  558. ret = __fpr_set(target, regset, pos, count, kbuf, ubuf, 0);
  559. if (ret)
  560. return ret;
  561. sve_sync_from_fpsimd_zeropad(target);
  562. fpsimd_flush_task_state(target);
  563. return ret;
  564. }
  565. static int tls_get(struct task_struct *target, const struct user_regset *regset,
  566. struct membuf to)
  567. {
  568. int ret;
  569. if (target == current)
  570. tls_preserve_current_state();
  571. ret = membuf_store(&to, target->thread.uw.tp_value);
  572. if (system_supports_tpidr2())
  573. ret = membuf_store(&to, target->thread.tpidr2_el0);
  574. else
  575. ret = membuf_zero(&to, sizeof(u64));
  576. return ret;
  577. }
  578. static int tls_set(struct task_struct *target, const struct user_regset *regset,
  579. unsigned int pos, unsigned int count,
  580. const void *kbuf, const void __user *ubuf)
  581. {
  582. int ret;
  583. unsigned long tls[2];
  584. tls[0] = target->thread.uw.tp_value;
  585. if (system_supports_tpidr2())
  586. tls[1] = target->thread.tpidr2_el0;
  587. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, tls, 0, count);
  588. if (ret)
  589. return ret;
  590. target->thread.uw.tp_value = tls[0];
  591. if (system_supports_tpidr2())
  592. target->thread.tpidr2_el0 = tls[1];
  593. return ret;
  594. }
  595. static int fpmr_get(struct task_struct *target, const struct user_regset *regset,
  596. struct membuf to)
  597. {
  598. if (!system_supports_fpmr())
  599. return -EINVAL;
  600. if (target == current)
  601. fpsimd_preserve_current_state();
  602. return membuf_store(&to, target->thread.uw.fpmr);
  603. }
  604. static int fpmr_set(struct task_struct *target, const struct user_regset *regset,
  605. unsigned int pos, unsigned int count,
  606. const void *kbuf, const void __user *ubuf)
  607. {
  608. int ret;
  609. unsigned long fpmr;
  610. if (!system_supports_fpmr())
  611. return -EINVAL;
  612. fpmr = target->thread.uw.fpmr;
  613. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &fpmr, 0, count);
  614. if (ret)
  615. return ret;
  616. target->thread.uw.fpmr = fpmr;
  617. fpsimd_flush_task_state(target);
  618. return 0;
  619. }
  620. static int system_call_get(struct task_struct *target,
  621. const struct user_regset *regset,
  622. struct membuf to)
  623. {
  624. return membuf_store(&to, task_pt_regs(target)->syscallno);
  625. }
  626. static int system_call_set(struct task_struct *target,
  627. const struct user_regset *regset,
  628. unsigned int pos, unsigned int count,
  629. const void *kbuf, const void __user *ubuf)
  630. {
  631. int syscallno = task_pt_regs(target)->syscallno;
  632. int ret;
  633. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &syscallno, 0, -1);
  634. if (ret)
  635. return ret;
  636. task_pt_regs(target)->syscallno = syscallno;
  637. return ret;
  638. }
  639. #ifdef CONFIG_ARM64_SVE
  640. static void sve_init_header_from_task(struct user_sve_header *header,
  641. struct task_struct *target,
  642. enum vec_type type)
  643. {
  644. unsigned int vq;
  645. bool active;
  646. enum vec_type task_type;
  647. memset(header, 0, sizeof(*header));
  648. /* Check if the requested registers are active for the task */
  649. if (thread_sm_enabled(&target->thread))
  650. task_type = ARM64_VEC_SME;
  651. else
  652. task_type = ARM64_VEC_SVE;
  653. active = (task_type == type);
  654. switch (type) {
  655. case ARM64_VEC_SVE:
  656. if (test_tsk_thread_flag(target, TIF_SVE_VL_INHERIT))
  657. header->flags |= SVE_PT_VL_INHERIT;
  658. break;
  659. case ARM64_VEC_SME:
  660. if (test_tsk_thread_flag(target, TIF_SME_VL_INHERIT))
  661. header->flags |= SVE_PT_VL_INHERIT;
  662. break;
  663. default:
  664. WARN_ON_ONCE(1);
  665. return;
  666. }
  667. if (active) {
  668. if (target->thread.fp_type == FP_STATE_FPSIMD) {
  669. header->flags |= SVE_PT_REGS_FPSIMD;
  670. } else {
  671. header->flags |= SVE_PT_REGS_SVE;
  672. }
  673. }
  674. header->vl = task_get_vl(target, type);
  675. vq = sve_vq_from_vl(header->vl);
  676. header->max_vl = vec_max_vl(type);
  677. header->size = SVE_PT_SIZE(vq, header->flags);
  678. header->max_size = SVE_PT_SIZE(sve_vq_from_vl(header->max_vl),
  679. SVE_PT_REGS_SVE);
  680. }
  681. static unsigned int sve_size_from_header(struct user_sve_header const *header)
  682. {
  683. return ALIGN(header->size, SVE_VQ_BYTES);
  684. }
  685. static int sve_get_common(struct task_struct *target,
  686. const struct user_regset *regset,
  687. struct membuf to,
  688. enum vec_type type)
  689. {
  690. struct user_sve_header header;
  691. unsigned int vq;
  692. unsigned long start, end;
  693. /* Header */
  694. sve_init_header_from_task(&header, target, type);
  695. vq = sve_vq_from_vl(header.vl);
  696. membuf_write(&to, &header, sizeof(header));
  697. if (target == current)
  698. fpsimd_preserve_current_state();
  699. BUILD_BUG_ON(SVE_PT_FPSIMD_OFFSET != sizeof(header));
  700. BUILD_BUG_ON(SVE_PT_SVE_OFFSET != sizeof(header));
  701. switch ((header.flags & SVE_PT_REGS_MASK)) {
  702. case SVE_PT_REGS_FPSIMD:
  703. return __fpr_get(target, regset, to);
  704. case SVE_PT_REGS_SVE:
  705. start = SVE_PT_SVE_OFFSET;
  706. end = SVE_PT_SVE_FFR_OFFSET(vq) + SVE_PT_SVE_FFR_SIZE(vq);
  707. membuf_write(&to, target->thread.sve_state, end - start);
  708. start = end;
  709. end = SVE_PT_SVE_FPSR_OFFSET(vq);
  710. membuf_zero(&to, end - start);
  711. /*
  712. * Copy fpsr, and fpcr which must follow contiguously in
  713. * struct fpsimd_state:
  714. */
  715. start = end;
  716. end = SVE_PT_SVE_FPCR_OFFSET(vq) + SVE_PT_SVE_FPCR_SIZE;
  717. membuf_write(&to, &target->thread.uw.fpsimd_state.fpsr,
  718. end - start);
  719. start = end;
  720. end = sve_size_from_header(&header);
  721. return membuf_zero(&to, end - start);
  722. default:
  723. return 0;
  724. }
  725. }
  726. static int sve_get(struct task_struct *target,
  727. const struct user_regset *regset,
  728. struct membuf to)
  729. {
  730. if (!system_supports_sve())
  731. return -EINVAL;
  732. return sve_get_common(target, regset, to, ARM64_VEC_SVE);
  733. }
  734. static int sve_set_common(struct task_struct *target,
  735. const struct user_regset *regset,
  736. unsigned int pos, unsigned int count,
  737. const void *kbuf, const void __user *ubuf,
  738. enum vec_type type)
  739. {
  740. int ret;
  741. struct user_sve_header header;
  742. unsigned int vq;
  743. unsigned long start, end;
  744. /* Header */
  745. if (count < sizeof(header))
  746. return -EINVAL;
  747. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &header,
  748. 0, sizeof(header));
  749. if (ret)
  750. goto out;
  751. /*
  752. * Apart from SVE_PT_REGS_MASK, all SVE_PT_* flags are consumed by
  753. * vec_set_vector_length(), which will also validate them for us:
  754. */
  755. ret = vec_set_vector_length(target, type, header.vl,
  756. ((unsigned long)header.flags & ~SVE_PT_REGS_MASK) << 16);
  757. if (ret)
  758. goto out;
  759. /* Actual VL set may be less than the user asked for: */
  760. vq = sve_vq_from_vl(task_get_vl(target, type));
  761. /* Enter/exit streaming mode */
  762. if (system_supports_sme()) {
  763. u64 old_svcr = target->thread.svcr;
  764. switch (type) {
  765. case ARM64_VEC_SVE:
  766. target->thread.svcr &= ~SVCR_SM_MASK;
  767. break;
  768. case ARM64_VEC_SME:
  769. target->thread.svcr |= SVCR_SM_MASK;
  770. /*
  771. * Disable traps and ensure there is SME storage but
  772. * preserve any currently set values in ZA/ZT.
  773. */
  774. sme_alloc(target, false);
  775. set_tsk_thread_flag(target, TIF_SME);
  776. break;
  777. default:
  778. WARN_ON_ONCE(1);
  779. ret = -EINVAL;
  780. goto out;
  781. }
  782. /*
  783. * If we switched then invalidate any existing SVE
  784. * state and ensure there's storage.
  785. */
  786. if (target->thread.svcr != old_svcr)
  787. sve_alloc(target, true);
  788. }
  789. /* Registers: FPSIMD-only case */
  790. BUILD_BUG_ON(SVE_PT_FPSIMD_OFFSET != sizeof(header));
  791. if ((header.flags & SVE_PT_REGS_MASK) == SVE_PT_REGS_FPSIMD) {
  792. ret = __fpr_set(target, regset, pos, count, kbuf, ubuf,
  793. SVE_PT_FPSIMD_OFFSET);
  794. clear_tsk_thread_flag(target, TIF_SVE);
  795. target->thread.fp_type = FP_STATE_FPSIMD;
  796. goto out;
  797. }
  798. /*
  799. * Otherwise: no registers or full SVE case. For backwards
  800. * compatibility reasons we treat empty flags as SVE registers.
  801. */
  802. /*
  803. * If setting a different VL from the requested VL and there is
  804. * register data, the data layout will be wrong: don't even
  805. * try to set the registers in this case.
  806. */
  807. if (count && vq != sve_vq_from_vl(header.vl)) {
  808. ret = -EIO;
  809. goto out;
  810. }
  811. sve_alloc(target, true);
  812. if (!target->thread.sve_state) {
  813. ret = -ENOMEM;
  814. clear_tsk_thread_flag(target, TIF_SVE);
  815. target->thread.fp_type = FP_STATE_FPSIMD;
  816. goto out;
  817. }
  818. /*
  819. * Ensure target->thread.sve_state is up to date with target's
  820. * FPSIMD regs, so that a short copyin leaves trailing
  821. * registers unmodified. Only enable SVE if we are
  822. * configuring normal SVE, a system with streaming SVE may not
  823. * have normal SVE.
  824. */
  825. fpsimd_sync_to_sve(target);
  826. if (type == ARM64_VEC_SVE)
  827. set_tsk_thread_flag(target, TIF_SVE);
  828. target->thread.fp_type = FP_STATE_SVE;
  829. BUILD_BUG_ON(SVE_PT_SVE_OFFSET != sizeof(header));
  830. start = SVE_PT_SVE_OFFSET;
  831. end = SVE_PT_SVE_FFR_OFFSET(vq) + SVE_PT_SVE_FFR_SIZE(vq);
  832. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  833. target->thread.sve_state,
  834. start, end);
  835. if (ret)
  836. goto out;
  837. start = end;
  838. end = SVE_PT_SVE_FPSR_OFFSET(vq);
  839. user_regset_copyin_ignore(&pos, &count, &kbuf, &ubuf, start, end);
  840. /*
  841. * Copy fpsr, and fpcr which must follow contiguously in
  842. * struct fpsimd_state:
  843. */
  844. start = end;
  845. end = SVE_PT_SVE_FPCR_OFFSET(vq) + SVE_PT_SVE_FPCR_SIZE;
  846. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  847. &target->thread.uw.fpsimd_state.fpsr,
  848. start, end);
  849. out:
  850. fpsimd_flush_task_state(target);
  851. return ret;
  852. }
  853. static int sve_set(struct task_struct *target,
  854. const struct user_regset *regset,
  855. unsigned int pos, unsigned int count,
  856. const void *kbuf, const void __user *ubuf)
  857. {
  858. if (!system_supports_sve())
  859. return -EINVAL;
  860. return sve_set_common(target, regset, pos, count, kbuf, ubuf,
  861. ARM64_VEC_SVE);
  862. }
  863. #endif /* CONFIG_ARM64_SVE */
  864. #ifdef CONFIG_ARM64_SME
  865. static int ssve_get(struct task_struct *target,
  866. const struct user_regset *regset,
  867. struct membuf to)
  868. {
  869. if (!system_supports_sme())
  870. return -EINVAL;
  871. return sve_get_common(target, regset, to, ARM64_VEC_SME);
  872. }
  873. static int ssve_set(struct task_struct *target,
  874. const struct user_regset *regset,
  875. unsigned int pos, unsigned int count,
  876. const void *kbuf, const void __user *ubuf)
  877. {
  878. if (!system_supports_sme())
  879. return -EINVAL;
  880. return sve_set_common(target, regset, pos, count, kbuf, ubuf,
  881. ARM64_VEC_SME);
  882. }
  883. static int za_get(struct task_struct *target,
  884. const struct user_regset *regset,
  885. struct membuf to)
  886. {
  887. struct user_za_header header;
  888. unsigned int vq;
  889. unsigned long start, end;
  890. if (!system_supports_sme())
  891. return -EINVAL;
  892. /* Header */
  893. memset(&header, 0, sizeof(header));
  894. if (test_tsk_thread_flag(target, TIF_SME_VL_INHERIT))
  895. header.flags |= ZA_PT_VL_INHERIT;
  896. header.vl = task_get_sme_vl(target);
  897. vq = sve_vq_from_vl(header.vl);
  898. header.max_vl = sme_max_vl();
  899. header.max_size = ZA_PT_SIZE(vq);
  900. /* If ZA is not active there is only the header */
  901. if (thread_za_enabled(&target->thread))
  902. header.size = ZA_PT_SIZE(vq);
  903. else
  904. header.size = ZA_PT_ZA_OFFSET;
  905. membuf_write(&to, &header, sizeof(header));
  906. BUILD_BUG_ON(ZA_PT_ZA_OFFSET != sizeof(header));
  907. end = ZA_PT_ZA_OFFSET;
  908. if (target == current)
  909. fpsimd_preserve_current_state();
  910. /* Any register data to include? */
  911. if (thread_za_enabled(&target->thread)) {
  912. start = end;
  913. end = ZA_PT_SIZE(vq);
  914. membuf_write(&to, target->thread.sme_state, end - start);
  915. }
  916. /* Zero any trailing padding */
  917. start = end;
  918. end = ALIGN(header.size, SVE_VQ_BYTES);
  919. return membuf_zero(&to, end - start);
  920. }
  921. static int za_set(struct task_struct *target,
  922. const struct user_regset *regset,
  923. unsigned int pos, unsigned int count,
  924. const void *kbuf, const void __user *ubuf)
  925. {
  926. int ret;
  927. struct user_za_header header;
  928. unsigned int vq;
  929. unsigned long start, end;
  930. if (!system_supports_sme())
  931. return -EINVAL;
  932. /* Header */
  933. if (count < sizeof(header))
  934. return -EINVAL;
  935. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &header,
  936. 0, sizeof(header));
  937. if (ret)
  938. goto out;
  939. /*
  940. * All current ZA_PT_* flags are consumed by
  941. * vec_set_vector_length(), which will also validate them for
  942. * us:
  943. */
  944. ret = vec_set_vector_length(target, ARM64_VEC_SME, header.vl,
  945. ((unsigned long)header.flags) << 16);
  946. if (ret)
  947. goto out;
  948. /* Actual VL set may be less than the user asked for: */
  949. vq = sve_vq_from_vl(task_get_sme_vl(target));
  950. /* Ensure there is some SVE storage for streaming mode */
  951. if (!target->thread.sve_state) {
  952. sve_alloc(target, false);
  953. if (!target->thread.sve_state) {
  954. ret = -ENOMEM;
  955. goto out;
  956. }
  957. }
  958. /*
  959. * Only flush the storage if PSTATE.ZA was not already set,
  960. * otherwise preserve any existing data.
  961. */
  962. sme_alloc(target, !thread_za_enabled(&target->thread));
  963. if (!target->thread.sme_state)
  964. return -ENOMEM;
  965. /* If there is no data then disable ZA */
  966. if (!count) {
  967. target->thread.svcr &= ~SVCR_ZA_MASK;
  968. goto out;
  969. }
  970. /*
  971. * If setting a different VL from the requested VL and there is
  972. * register data, the data layout will be wrong: don't even
  973. * try to set the registers in this case.
  974. */
  975. if (vq != sve_vq_from_vl(header.vl)) {
  976. ret = -EIO;
  977. goto out;
  978. }
  979. BUILD_BUG_ON(ZA_PT_ZA_OFFSET != sizeof(header));
  980. start = ZA_PT_ZA_OFFSET;
  981. end = ZA_PT_SIZE(vq);
  982. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  983. target->thread.sme_state,
  984. start, end);
  985. if (ret)
  986. goto out;
  987. /* Mark ZA as active and let userspace use it */
  988. set_tsk_thread_flag(target, TIF_SME);
  989. target->thread.svcr |= SVCR_ZA_MASK;
  990. out:
  991. fpsimd_flush_task_state(target);
  992. return ret;
  993. }
  994. static int zt_get(struct task_struct *target,
  995. const struct user_regset *regset,
  996. struct membuf to)
  997. {
  998. if (!system_supports_sme2())
  999. return -EINVAL;
  1000. /*
  1001. * If PSTATE.ZA is not set then ZT will be zeroed when it is
  1002. * enabled so report the current register value as zero.
  1003. */
  1004. if (thread_za_enabled(&target->thread))
  1005. membuf_write(&to, thread_zt_state(&target->thread),
  1006. ZT_SIG_REG_BYTES);
  1007. else
  1008. membuf_zero(&to, ZT_SIG_REG_BYTES);
  1009. return 0;
  1010. }
  1011. static int zt_set(struct task_struct *target,
  1012. const struct user_regset *regset,
  1013. unsigned int pos, unsigned int count,
  1014. const void *kbuf, const void __user *ubuf)
  1015. {
  1016. int ret;
  1017. if (!system_supports_sme2())
  1018. return -EINVAL;
  1019. /* Ensure SVE storage in case this is first use of SME */
  1020. sve_alloc(target, false);
  1021. if (!target->thread.sve_state)
  1022. return -ENOMEM;
  1023. if (!thread_za_enabled(&target->thread)) {
  1024. sme_alloc(target, true);
  1025. if (!target->thread.sme_state)
  1026. return -ENOMEM;
  1027. }
  1028. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  1029. thread_zt_state(&target->thread),
  1030. 0, ZT_SIG_REG_BYTES);
  1031. if (ret == 0) {
  1032. target->thread.svcr |= SVCR_ZA_MASK;
  1033. set_tsk_thread_flag(target, TIF_SME);
  1034. }
  1035. fpsimd_flush_task_state(target);
  1036. return ret;
  1037. }
  1038. #endif /* CONFIG_ARM64_SME */
  1039. #ifdef CONFIG_ARM64_PTR_AUTH
  1040. static int pac_mask_get(struct task_struct *target,
  1041. const struct user_regset *regset,
  1042. struct membuf to)
  1043. {
  1044. /*
  1045. * The PAC bits can differ across data and instruction pointers
  1046. * depending on TCR_EL1.TBID*, which we may make use of in future, so
  1047. * we expose separate masks.
  1048. */
  1049. unsigned long mask = ptrauth_user_pac_mask();
  1050. struct user_pac_mask uregs = {
  1051. .data_mask = mask,
  1052. .insn_mask = mask,
  1053. };
  1054. if (!system_supports_address_auth())
  1055. return -EINVAL;
  1056. return membuf_write(&to, &uregs, sizeof(uregs));
  1057. }
  1058. static int pac_enabled_keys_get(struct task_struct *target,
  1059. const struct user_regset *regset,
  1060. struct membuf to)
  1061. {
  1062. long enabled_keys = ptrauth_get_enabled_keys(target);
  1063. if (IS_ERR_VALUE(enabled_keys))
  1064. return enabled_keys;
  1065. return membuf_write(&to, &enabled_keys, sizeof(enabled_keys));
  1066. }
  1067. static int pac_enabled_keys_set(struct task_struct *target,
  1068. const struct user_regset *regset,
  1069. unsigned int pos, unsigned int count,
  1070. const void *kbuf, const void __user *ubuf)
  1071. {
  1072. int ret;
  1073. long enabled_keys = ptrauth_get_enabled_keys(target);
  1074. if (IS_ERR_VALUE(enabled_keys))
  1075. return enabled_keys;
  1076. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &enabled_keys, 0,
  1077. sizeof(long));
  1078. if (ret)
  1079. return ret;
  1080. return ptrauth_set_enabled_keys(target, PR_PAC_ENABLED_KEYS_MASK,
  1081. enabled_keys);
  1082. }
  1083. #ifdef CONFIG_CHECKPOINT_RESTORE
  1084. static __uint128_t pac_key_to_user(const struct ptrauth_key *key)
  1085. {
  1086. return (__uint128_t)key->hi << 64 | key->lo;
  1087. }
  1088. static struct ptrauth_key pac_key_from_user(__uint128_t ukey)
  1089. {
  1090. struct ptrauth_key key = {
  1091. .lo = (unsigned long)ukey,
  1092. .hi = (unsigned long)(ukey >> 64),
  1093. };
  1094. return key;
  1095. }
  1096. static void pac_address_keys_to_user(struct user_pac_address_keys *ukeys,
  1097. const struct ptrauth_keys_user *keys)
  1098. {
  1099. ukeys->apiakey = pac_key_to_user(&keys->apia);
  1100. ukeys->apibkey = pac_key_to_user(&keys->apib);
  1101. ukeys->apdakey = pac_key_to_user(&keys->apda);
  1102. ukeys->apdbkey = pac_key_to_user(&keys->apdb);
  1103. }
  1104. static void pac_address_keys_from_user(struct ptrauth_keys_user *keys,
  1105. const struct user_pac_address_keys *ukeys)
  1106. {
  1107. keys->apia = pac_key_from_user(ukeys->apiakey);
  1108. keys->apib = pac_key_from_user(ukeys->apibkey);
  1109. keys->apda = pac_key_from_user(ukeys->apdakey);
  1110. keys->apdb = pac_key_from_user(ukeys->apdbkey);
  1111. }
  1112. static int pac_address_keys_get(struct task_struct *target,
  1113. const struct user_regset *regset,
  1114. struct membuf to)
  1115. {
  1116. struct ptrauth_keys_user *keys = &target->thread.keys_user;
  1117. struct user_pac_address_keys user_keys;
  1118. if (!system_supports_address_auth())
  1119. return -EINVAL;
  1120. pac_address_keys_to_user(&user_keys, keys);
  1121. return membuf_write(&to, &user_keys, sizeof(user_keys));
  1122. }
  1123. static int pac_address_keys_set(struct task_struct *target,
  1124. const struct user_regset *regset,
  1125. unsigned int pos, unsigned int count,
  1126. const void *kbuf, const void __user *ubuf)
  1127. {
  1128. struct ptrauth_keys_user *keys = &target->thread.keys_user;
  1129. struct user_pac_address_keys user_keys;
  1130. int ret;
  1131. if (!system_supports_address_auth())
  1132. return -EINVAL;
  1133. pac_address_keys_to_user(&user_keys, keys);
  1134. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  1135. &user_keys, 0, -1);
  1136. if (ret)
  1137. return ret;
  1138. pac_address_keys_from_user(keys, &user_keys);
  1139. return 0;
  1140. }
  1141. static void pac_generic_keys_to_user(struct user_pac_generic_keys *ukeys,
  1142. const struct ptrauth_keys_user *keys)
  1143. {
  1144. ukeys->apgakey = pac_key_to_user(&keys->apga);
  1145. }
  1146. static void pac_generic_keys_from_user(struct ptrauth_keys_user *keys,
  1147. const struct user_pac_generic_keys *ukeys)
  1148. {
  1149. keys->apga = pac_key_from_user(ukeys->apgakey);
  1150. }
  1151. static int pac_generic_keys_get(struct task_struct *target,
  1152. const struct user_regset *regset,
  1153. struct membuf to)
  1154. {
  1155. struct ptrauth_keys_user *keys = &target->thread.keys_user;
  1156. struct user_pac_generic_keys user_keys;
  1157. if (!system_supports_generic_auth())
  1158. return -EINVAL;
  1159. pac_generic_keys_to_user(&user_keys, keys);
  1160. return membuf_write(&to, &user_keys, sizeof(user_keys));
  1161. }
  1162. static int pac_generic_keys_set(struct task_struct *target,
  1163. const struct user_regset *regset,
  1164. unsigned int pos, unsigned int count,
  1165. const void *kbuf, const void __user *ubuf)
  1166. {
  1167. struct ptrauth_keys_user *keys = &target->thread.keys_user;
  1168. struct user_pac_generic_keys user_keys;
  1169. int ret;
  1170. if (!system_supports_generic_auth())
  1171. return -EINVAL;
  1172. pac_generic_keys_to_user(&user_keys, keys);
  1173. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf,
  1174. &user_keys, 0, -1);
  1175. if (ret)
  1176. return ret;
  1177. pac_generic_keys_from_user(keys, &user_keys);
  1178. return 0;
  1179. }
  1180. #endif /* CONFIG_CHECKPOINT_RESTORE */
  1181. #endif /* CONFIG_ARM64_PTR_AUTH */
  1182. #ifdef CONFIG_ARM64_TAGGED_ADDR_ABI
  1183. static int tagged_addr_ctrl_get(struct task_struct *target,
  1184. const struct user_regset *regset,
  1185. struct membuf to)
  1186. {
  1187. long ctrl = get_tagged_addr_ctrl(target);
  1188. if (WARN_ON_ONCE(IS_ERR_VALUE(ctrl)))
  1189. return ctrl;
  1190. return membuf_write(&to, &ctrl, sizeof(ctrl));
  1191. }
  1192. static int tagged_addr_ctrl_set(struct task_struct *target, const struct
  1193. user_regset *regset, unsigned int pos,
  1194. unsigned int count, const void *kbuf, const
  1195. void __user *ubuf)
  1196. {
  1197. int ret;
  1198. long ctrl;
  1199. ctrl = get_tagged_addr_ctrl(target);
  1200. if (WARN_ON_ONCE(IS_ERR_VALUE(ctrl)))
  1201. return ctrl;
  1202. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl, 0, -1);
  1203. if (ret)
  1204. return ret;
  1205. return set_tagged_addr_ctrl(target, ctrl);
  1206. }
  1207. #endif
  1208. #ifdef CONFIG_ARM64_POE
  1209. static int poe_get(struct task_struct *target,
  1210. const struct user_regset *regset,
  1211. struct membuf to)
  1212. {
  1213. if (!system_supports_poe())
  1214. return -EINVAL;
  1215. return membuf_write(&to, &target->thread.por_el0,
  1216. sizeof(target->thread.por_el0));
  1217. }
  1218. static int poe_set(struct task_struct *target, const struct
  1219. user_regset *regset, unsigned int pos,
  1220. unsigned int count, const void *kbuf, const
  1221. void __user *ubuf)
  1222. {
  1223. int ret;
  1224. long ctrl;
  1225. if (!system_supports_poe())
  1226. return -EINVAL;
  1227. ctrl = target->thread.por_el0;
  1228. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &ctrl, 0, -1);
  1229. if (ret)
  1230. return ret;
  1231. target->thread.por_el0 = ctrl;
  1232. return 0;
  1233. }
  1234. #endif
  1235. enum aarch64_regset {
  1236. REGSET_GPR,
  1237. REGSET_FPR,
  1238. REGSET_TLS,
  1239. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  1240. REGSET_HW_BREAK,
  1241. REGSET_HW_WATCH,
  1242. #endif
  1243. REGSET_FPMR,
  1244. REGSET_SYSTEM_CALL,
  1245. #ifdef CONFIG_ARM64_SVE
  1246. REGSET_SVE,
  1247. #endif
  1248. #ifdef CONFIG_ARM64_SME
  1249. REGSET_SSVE,
  1250. REGSET_ZA,
  1251. REGSET_ZT,
  1252. #endif
  1253. #ifdef CONFIG_ARM64_PTR_AUTH
  1254. REGSET_PAC_MASK,
  1255. REGSET_PAC_ENABLED_KEYS,
  1256. #ifdef CONFIG_CHECKPOINT_RESTORE
  1257. REGSET_PACA_KEYS,
  1258. REGSET_PACG_KEYS,
  1259. #endif
  1260. #endif
  1261. #ifdef CONFIG_ARM64_TAGGED_ADDR_ABI
  1262. REGSET_TAGGED_ADDR_CTRL,
  1263. #endif
  1264. #ifdef CONFIG_ARM64_POE
  1265. REGSET_POE
  1266. #endif
  1267. };
  1268. static const struct user_regset aarch64_regsets[] = {
  1269. [REGSET_GPR] = {
  1270. .core_note_type = NT_PRSTATUS,
  1271. .n = sizeof(struct user_pt_regs) / sizeof(u64),
  1272. .size = sizeof(u64),
  1273. .align = sizeof(u64),
  1274. .regset_get = gpr_get,
  1275. .set = gpr_set
  1276. },
  1277. [REGSET_FPR] = {
  1278. .core_note_type = NT_PRFPREG,
  1279. .n = sizeof(struct user_fpsimd_state) / sizeof(u32),
  1280. /*
  1281. * We pretend we have 32-bit registers because the fpsr and
  1282. * fpcr are 32-bits wide.
  1283. */
  1284. .size = sizeof(u32),
  1285. .align = sizeof(u32),
  1286. .active = fpr_active,
  1287. .regset_get = fpr_get,
  1288. .set = fpr_set
  1289. },
  1290. [REGSET_TLS] = {
  1291. .core_note_type = NT_ARM_TLS,
  1292. .n = 2,
  1293. .size = sizeof(void *),
  1294. .align = sizeof(void *),
  1295. .regset_get = tls_get,
  1296. .set = tls_set,
  1297. },
  1298. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  1299. [REGSET_HW_BREAK] = {
  1300. .core_note_type = NT_ARM_HW_BREAK,
  1301. .n = sizeof(struct user_hwdebug_state) / sizeof(u32),
  1302. .size = sizeof(u32),
  1303. .align = sizeof(u32),
  1304. .regset_get = hw_break_get,
  1305. .set = hw_break_set,
  1306. },
  1307. [REGSET_HW_WATCH] = {
  1308. .core_note_type = NT_ARM_HW_WATCH,
  1309. .n = sizeof(struct user_hwdebug_state) / sizeof(u32),
  1310. .size = sizeof(u32),
  1311. .align = sizeof(u32),
  1312. .regset_get = hw_break_get,
  1313. .set = hw_break_set,
  1314. },
  1315. #endif
  1316. [REGSET_SYSTEM_CALL] = {
  1317. .core_note_type = NT_ARM_SYSTEM_CALL,
  1318. .n = 1,
  1319. .size = sizeof(int),
  1320. .align = sizeof(int),
  1321. .regset_get = system_call_get,
  1322. .set = system_call_set,
  1323. },
  1324. [REGSET_FPMR] = {
  1325. .core_note_type = NT_ARM_FPMR,
  1326. .n = 1,
  1327. .size = sizeof(u64),
  1328. .align = sizeof(u64),
  1329. .regset_get = fpmr_get,
  1330. .set = fpmr_set,
  1331. },
  1332. #ifdef CONFIG_ARM64_SVE
  1333. [REGSET_SVE] = { /* Scalable Vector Extension */
  1334. .core_note_type = NT_ARM_SVE,
  1335. .n = DIV_ROUND_UP(SVE_PT_SIZE(ARCH_SVE_VQ_MAX,
  1336. SVE_PT_REGS_SVE),
  1337. SVE_VQ_BYTES),
  1338. .size = SVE_VQ_BYTES,
  1339. .align = SVE_VQ_BYTES,
  1340. .regset_get = sve_get,
  1341. .set = sve_set,
  1342. },
  1343. #endif
  1344. #ifdef CONFIG_ARM64_SME
  1345. [REGSET_SSVE] = { /* Streaming mode SVE */
  1346. .core_note_type = NT_ARM_SSVE,
  1347. .n = DIV_ROUND_UP(SVE_PT_SIZE(SME_VQ_MAX, SVE_PT_REGS_SVE),
  1348. SVE_VQ_BYTES),
  1349. .size = SVE_VQ_BYTES,
  1350. .align = SVE_VQ_BYTES,
  1351. .regset_get = ssve_get,
  1352. .set = ssve_set,
  1353. },
  1354. [REGSET_ZA] = { /* SME ZA */
  1355. .core_note_type = NT_ARM_ZA,
  1356. /*
  1357. * ZA is a single register but it's variably sized and
  1358. * the ptrace core requires that the size of any data
  1359. * be an exact multiple of the configured register
  1360. * size so report as though we had SVE_VQ_BYTES
  1361. * registers. These values aren't exposed to
  1362. * userspace.
  1363. */
  1364. .n = DIV_ROUND_UP(ZA_PT_SIZE(SME_VQ_MAX), SVE_VQ_BYTES),
  1365. .size = SVE_VQ_BYTES,
  1366. .align = SVE_VQ_BYTES,
  1367. .regset_get = za_get,
  1368. .set = za_set,
  1369. },
  1370. [REGSET_ZT] = { /* SME ZT */
  1371. .core_note_type = NT_ARM_ZT,
  1372. .n = 1,
  1373. .size = ZT_SIG_REG_BYTES,
  1374. .align = sizeof(u64),
  1375. .regset_get = zt_get,
  1376. .set = zt_set,
  1377. },
  1378. #endif
  1379. #ifdef CONFIG_ARM64_PTR_AUTH
  1380. [REGSET_PAC_MASK] = {
  1381. .core_note_type = NT_ARM_PAC_MASK,
  1382. .n = sizeof(struct user_pac_mask) / sizeof(u64),
  1383. .size = sizeof(u64),
  1384. .align = sizeof(u64),
  1385. .regset_get = pac_mask_get,
  1386. /* this cannot be set dynamically */
  1387. },
  1388. [REGSET_PAC_ENABLED_KEYS] = {
  1389. .core_note_type = NT_ARM_PAC_ENABLED_KEYS,
  1390. .n = 1,
  1391. .size = sizeof(long),
  1392. .align = sizeof(long),
  1393. .regset_get = pac_enabled_keys_get,
  1394. .set = pac_enabled_keys_set,
  1395. },
  1396. #ifdef CONFIG_CHECKPOINT_RESTORE
  1397. [REGSET_PACA_KEYS] = {
  1398. .core_note_type = NT_ARM_PACA_KEYS,
  1399. .n = sizeof(struct user_pac_address_keys) / sizeof(__uint128_t),
  1400. .size = sizeof(__uint128_t),
  1401. .align = sizeof(__uint128_t),
  1402. .regset_get = pac_address_keys_get,
  1403. .set = pac_address_keys_set,
  1404. },
  1405. [REGSET_PACG_KEYS] = {
  1406. .core_note_type = NT_ARM_PACG_KEYS,
  1407. .n = sizeof(struct user_pac_generic_keys) / sizeof(__uint128_t),
  1408. .size = sizeof(__uint128_t),
  1409. .align = sizeof(__uint128_t),
  1410. .regset_get = pac_generic_keys_get,
  1411. .set = pac_generic_keys_set,
  1412. },
  1413. #endif
  1414. #endif
  1415. #ifdef CONFIG_ARM64_TAGGED_ADDR_ABI
  1416. [REGSET_TAGGED_ADDR_CTRL] = {
  1417. .core_note_type = NT_ARM_TAGGED_ADDR_CTRL,
  1418. .n = 1,
  1419. .size = sizeof(long),
  1420. .align = sizeof(long),
  1421. .regset_get = tagged_addr_ctrl_get,
  1422. .set = tagged_addr_ctrl_set,
  1423. },
  1424. #endif
  1425. #ifdef CONFIG_ARM64_POE
  1426. [REGSET_POE] = {
  1427. .core_note_type = NT_ARM_POE,
  1428. .n = 1,
  1429. .size = sizeof(long),
  1430. .align = sizeof(long),
  1431. .regset_get = poe_get,
  1432. .set = poe_set,
  1433. },
  1434. #endif
  1435. };
  1436. static const struct user_regset_view user_aarch64_view = {
  1437. .name = "aarch64", .e_machine = EM_AARCH64,
  1438. .regsets = aarch64_regsets, .n = ARRAY_SIZE(aarch64_regsets)
  1439. };
  1440. enum compat_regset {
  1441. REGSET_COMPAT_GPR,
  1442. REGSET_COMPAT_VFP,
  1443. };
  1444. static inline compat_ulong_t compat_get_user_reg(struct task_struct *task, int idx)
  1445. {
  1446. struct pt_regs *regs = task_pt_regs(task);
  1447. switch (idx) {
  1448. case 15:
  1449. return regs->pc;
  1450. case 16:
  1451. return pstate_to_compat_psr(regs->pstate);
  1452. case 17:
  1453. return regs->orig_x0;
  1454. default:
  1455. return regs->regs[idx];
  1456. }
  1457. }
  1458. static int compat_gpr_get(struct task_struct *target,
  1459. const struct user_regset *regset,
  1460. struct membuf to)
  1461. {
  1462. int i = 0;
  1463. while (to.left)
  1464. membuf_store(&to, compat_get_user_reg(target, i++));
  1465. return 0;
  1466. }
  1467. static int compat_gpr_set(struct task_struct *target,
  1468. const struct user_regset *regset,
  1469. unsigned int pos, unsigned int count,
  1470. const void *kbuf, const void __user *ubuf)
  1471. {
  1472. struct pt_regs newregs;
  1473. int ret = 0;
  1474. unsigned int i, start, num_regs;
  1475. /* Calculate the number of AArch32 registers contained in count */
  1476. num_regs = count / regset->size;
  1477. /* Convert pos into an register number */
  1478. start = pos / regset->size;
  1479. if (start + num_regs > regset->n)
  1480. return -EIO;
  1481. newregs = *task_pt_regs(target);
  1482. for (i = 0; i < num_regs; ++i) {
  1483. unsigned int idx = start + i;
  1484. compat_ulong_t reg;
  1485. if (kbuf) {
  1486. memcpy(&reg, kbuf, sizeof(reg));
  1487. kbuf += sizeof(reg);
  1488. } else {
  1489. ret = copy_from_user(&reg, ubuf, sizeof(reg));
  1490. if (ret) {
  1491. ret = -EFAULT;
  1492. break;
  1493. }
  1494. ubuf += sizeof(reg);
  1495. }
  1496. switch (idx) {
  1497. case 15:
  1498. newregs.pc = reg;
  1499. break;
  1500. case 16:
  1501. reg = compat_psr_to_pstate(reg);
  1502. newregs.pstate = reg;
  1503. break;
  1504. case 17:
  1505. newregs.orig_x0 = reg;
  1506. break;
  1507. default:
  1508. newregs.regs[idx] = reg;
  1509. }
  1510. }
  1511. if (valid_user_regs(&newregs.user_regs, target))
  1512. *task_pt_regs(target) = newregs;
  1513. else
  1514. ret = -EINVAL;
  1515. return ret;
  1516. }
  1517. static int compat_vfp_get(struct task_struct *target,
  1518. const struct user_regset *regset,
  1519. struct membuf to)
  1520. {
  1521. struct user_fpsimd_state *uregs;
  1522. compat_ulong_t fpscr;
  1523. if (!system_supports_fpsimd())
  1524. return -EINVAL;
  1525. uregs = &target->thread.uw.fpsimd_state;
  1526. if (target == current)
  1527. fpsimd_preserve_current_state();
  1528. /*
  1529. * The VFP registers are packed into the fpsimd_state, so they all sit
  1530. * nicely together for us. We just need to create the fpscr separately.
  1531. */
  1532. membuf_write(&to, uregs, VFP_STATE_SIZE - sizeof(compat_ulong_t));
  1533. fpscr = (uregs->fpsr & VFP_FPSCR_STAT_MASK) |
  1534. (uregs->fpcr & VFP_FPSCR_CTRL_MASK);
  1535. return membuf_store(&to, fpscr);
  1536. }
  1537. static int compat_vfp_set(struct task_struct *target,
  1538. const struct user_regset *regset,
  1539. unsigned int pos, unsigned int count,
  1540. const void *kbuf, const void __user *ubuf)
  1541. {
  1542. struct user_fpsimd_state *uregs;
  1543. compat_ulong_t fpscr;
  1544. int ret, vregs_end_pos;
  1545. if (!system_supports_fpsimd())
  1546. return -EINVAL;
  1547. uregs = &target->thread.uw.fpsimd_state;
  1548. vregs_end_pos = VFP_STATE_SIZE - sizeof(compat_ulong_t);
  1549. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, uregs, 0,
  1550. vregs_end_pos);
  1551. if (count && !ret) {
  1552. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &fpscr,
  1553. vregs_end_pos, VFP_STATE_SIZE);
  1554. if (!ret) {
  1555. uregs->fpsr = fpscr & VFP_FPSCR_STAT_MASK;
  1556. uregs->fpcr = fpscr & VFP_FPSCR_CTRL_MASK;
  1557. }
  1558. }
  1559. fpsimd_flush_task_state(target);
  1560. return ret;
  1561. }
  1562. static int compat_tls_get(struct task_struct *target,
  1563. const struct user_regset *regset,
  1564. struct membuf to)
  1565. {
  1566. return membuf_store(&to, (compat_ulong_t)target->thread.uw.tp_value);
  1567. }
  1568. static int compat_tls_set(struct task_struct *target,
  1569. const struct user_regset *regset, unsigned int pos,
  1570. unsigned int count, const void *kbuf,
  1571. const void __user *ubuf)
  1572. {
  1573. int ret;
  1574. compat_ulong_t tls = target->thread.uw.tp_value;
  1575. ret = user_regset_copyin(&pos, &count, &kbuf, &ubuf, &tls, 0, -1);
  1576. if (ret)
  1577. return ret;
  1578. target->thread.uw.tp_value = tls;
  1579. return ret;
  1580. }
  1581. static const struct user_regset aarch32_regsets[] = {
  1582. [REGSET_COMPAT_GPR] = {
  1583. .core_note_type = NT_PRSTATUS,
  1584. .n = COMPAT_ELF_NGREG,
  1585. .size = sizeof(compat_elf_greg_t),
  1586. .align = sizeof(compat_elf_greg_t),
  1587. .regset_get = compat_gpr_get,
  1588. .set = compat_gpr_set
  1589. },
  1590. [REGSET_COMPAT_VFP] = {
  1591. .core_note_type = NT_ARM_VFP,
  1592. .n = VFP_STATE_SIZE / sizeof(compat_ulong_t),
  1593. .size = sizeof(compat_ulong_t),
  1594. .align = sizeof(compat_ulong_t),
  1595. .active = fpr_active,
  1596. .regset_get = compat_vfp_get,
  1597. .set = compat_vfp_set
  1598. },
  1599. };
  1600. static const struct user_regset_view user_aarch32_view = {
  1601. .name = "aarch32", .e_machine = EM_ARM,
  1602. .regsets = aarch32_regsets, .n = ARRAY_SIZE(aarch32_regsets)
  1603. };
  1604. static const struct user_regset aarch32_ptrace_regsets[] = {
  1605. [REGSET_GPR] = {
  1606. .core_note_type = NT_PRSTATUS,
  1607. .n = COMPAT_ELF_NGREG,
  1608. .size = sizeof(compat_elf_greg_t),
  1609. .align = sizeof(compat_elf_greg_t),
  1610. .regset_get = compat_gpr_get,
  1611. .set = compat_gpr_set
  1612. },
  1613. [REGSET_FPR] = {
  1614. .core_note_type = NT_ARM_VFP,
  1615. .n = VFP_STATE_SIZE / sizeof(compat_ulong_t),
  1616. .size = sizeof(compat_ulong_t),
  1617. .align = sizeof(compat_ulong_t),
  1618. .regset_get = compat_vfp_get,
  1619. .set = compat_vfp_set
  1620. },
  1621. [REGSET_TLS] = {
  1622. .core_note_type = NT_ARM_TLS,
  1623. .n = 1,
  1624. .size = sizeof(compat_ulong_t),
  1625. .align = sizeof(compat_ulong_t),
  1626. .regset_get = compat_tls_get,
  1627. .set = compat_tls_set,
  1628. },
  1629. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  1630. [REGSET_HW_BREAK] = {
  1631. .core_note_type = NT_ARM_HW_BREAK,
  1632. .n = sizeof(struct user_hwdebug_state) / sizeof(u32),
  1633. .size = sizeof(u32),
  1634. .align = sizeof(u32),
  1635. .regset_get = hw_break_get,
  1636. .set = hw_break_set,
  1637. },
  1638. [REGSET_HW_WATCH] = {
  1639. .core_note_type = NT_ARM_HW_WATCH,
  1640. .n = sizeof(struct user_hwdebug_state) / sizeof(u32),
  1641. .size = sizeof(u32),
  1642. .align = sizeof(u32),
  1643. .regset_get = hw_break_get,
  1644. .set = hw_break_set,
  1645. },
  1646. #endif
  1647. [REGSET_SYSTEM_CALL] = {
  1648. .core_note_type = NT_ARM_SYSTEM_CALL,
  1649. .n = 1,
  1650. .size = sizeof(int),
  1651. .align = sizeof(int),
  1652. .regset_get = system_call_get,
  1653. .set = system_call_set,
  1654. },
  1655. };
  1656. static const struct user_regset_view user_aarch32_ptrace_view = {
  1657. .name = "aarch32", .e_machine = EM_ARM,
  1658. .regsets = aarch32_ptrace_regsets, .n = ARRAY_SIZE(aarch32_ptrace_regsets)
  1659. };
  1660. #ifdef CONFIG_COMPAT
  1661. static int compat_ptrace_read_user(struct task_struct *tsk, compat_ulong_t off,
  1662. compat_ulong_t __user *ret)
  1663. {
  1664. compat_ulong_t tmp;
  1665. if (off & 3)
  1666. return -EIO;
  1667. if (off == COMPAT_PT_TEXT_ADDR)
  1668. tmp = tsk->mm->start_code;
  1669. else if (off == COMPAT_PT_DATA_ADDR)
  1670. tmp = tsk->mm->start_data;
  1671. else if (off == COMPAT_PT_TEXT_END_ADDR)
  1672. tmp = tsk->mm->end_code;
  1673. else if (off < sizeof(compat_elf_gregset_t))
  1674. tmp = compat_get_user_reg(tsk, off >> 2);
  1675. else if (off >= COMPAT_USER_SZ)
  1676. return -EIO;
  1677. else
  1678. tmp = 0;
  1679. return put_user(tmp, ret);
  1680. }
  1681. static int compat_ptrace_write_user(struct task_struct *tsk, compat_ulong_t off,
  1682. compat_ulong_t val)
  1683. {
  1684. struct pt_regs newregs = *task_pt_regs(tsk);
  1685. unsigned int idx = off / 4;
  1686. if (off & 3 || off >= COMPAT_USER_SZ)
  1687. return -EIO;
  1688. if (off >= sizeof(compat_elf_gregset_t))
  1689. return 0;
  1690. switch (idx) {
  1691. case 15:
  1692. newregs.pc = val;
  1693. break;
  1694. case 16:
  1695. newregs.pstate = compat_psr_to_pstate(val);
  1696. break;
  1697. case 17:
  1698. newregs.orig_x0 = val;
  1699. break;
  1700. default:
  1701. newregs.regs[idx] = val;
  1702. }
  1703. if (!valid_user_regs(&newregs.user_regs, tsk))
  1704. return -EINVAL;
  1705. *task_pt_regs(tsk) = newregs;
  1706. return 0;
  1707. }
  1708. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  1709. /*
  1710. * Convert a virtual register number into an index for a thread_info
  1711. * breakpoint array. Breakpoints are identified using positive numbers
  1712. * whilst watchpoints are negative. The registers are laid out as pairs
  1713. * of (address, control), each pair mapping to a unique hw_breakpoint struct.
  1714. * Register 0 is reserved for describing resource information.
  1715. */
  1716. static int compat_ptrace_hbp_num_to_idx(compat_long_t num)
  1717. {
  1718. return (abs(num) - 1) >> 1;
  1719. }
  1720. static int compat_ptrace_hbp_get_resource_info(u32 *kdata)
  1721. {
  1722. u8 num_brps, num_wrps, debug_arch, wp_len;
  1723. u32 reg = 0;
  1724. num_brps = hw_breakpoint_slots(TYPE_INST);
  1725. num_wrps = hw_breakpoint_slots(TYPE_DATA);
  1726. debug_arch = debug_monitors_arch();
  1727. wp_len = 8;
  1728. reg |= debug_arch;
  1729. reg <<= 8;
  1730. reg |= wp_len;
  1731. reg <<= 8;
  1732. reg |= num_wrps;
  1733. reg <<= 8;
  1734. reg |= num_brps;
  1735. *kdata = reg;
  1736. return 0;
  1737. }
  1738. static int compat_ptrace_hbp_get(unsigned int note_type,
  1739. struct task_struct *tsk,
  1740. compat_long_t num,
  1741. u32 *kdata)
  1742. {
  1743. u64 addr = 0;
  1744. u32 ctrl = 0;
  1745. int err, idx = compat_ptrace_hbp_num_to_idx(num);
  1746. if (num & 1) {
  1747. err = ptrace_hbp_get_addr(note_type, tsk, idx, &addr);
  1748. *kdata = (u32)addr;
  1749. } else {
  1750. err = ptrace_hbp_get_ctrl(note_type, tsk, idx, &ctrl);
  1751. *kdata = ctrl;
  1752. }
  1753. return err;
  1754. }
  1755. static int compat_ptrace_hbp_set(unsigned int note_type,
  1756. struct task_struct *tsk,
  1757. compat_long_t num,
  1758. u32 *kdata)
  1759. {
  1760. u64 addr;
  1761. u32 ctrl;
  1762. int err, idx = compat_ptrace_hbp_num_to_idx(num);
  1763. if (num & 1) {
  1764. addr = *kdata;
  1765. err = ptrace_hbp_set_addr(note_type, tsk, idx, addr);
  1766. } else {
  1767. ctrl = *kdata;
  1768. err = ptrace_hbp_set_ctrl(note_type, tsk, idx, ctrl);
  1769. }
  1770. return err;
  1771. }
  1772. static int compat_ptrace_gethbpregs(struct task_struct *tsk, compat_long_t num,
  1773. compat_ulong_t __user *data)
  1774. {
  1775. int ret;
  1776. u32 kdata;
  1777. /* Watchpoint */
  1778. if (num < 0) {
  1779. ret = compat_ptrace_hbp_get(NT_ARM_HW_WATCH, tsk, num, &kdata);
  1780. /* Resource info */
  1781. } else if (num == 0) {
  1782. ret = compat_ptrace_hbp_get_resource_info(&kdata);
  1783. /* Breakpoint */
  1784. } else {
  1785. ret = compat_ptrace_hbp_get(NT_ARM_HW_BREAK, tsk, num, &kdata);
  1786. }
  1787. if (!ret)
  1788. ret = put_user(kdata, data);
  1789. return ret;
  1790. }
  1791. static int compat_ptrace_sethbpregs(struct task_struct *tsk, compat_long_t num,
  1792. compat_ulong_t __user *data)
  1793. {
  1794. int ret;
  1795. u32 kdata = 0;
  1796. if (num == 0)
  1797. return 0;
  1798. ret = get_user(kdata, data);
  1799. if (ret)
  1800. return ret;
  1801. if (num < 0)
  1802. ret = compat_ptrace_hbp_set(NT_ARM_HW_WATCH, tsk, num, &kdata);
  1803. else
  1804. ret = compat_ptrace_hbp_set(NT_ARM_HW_BREAK, tsk, num, &kdata);
  1805. return ret;
  1806. }
  1807. #endif /* CONFIG_HAVE_HW_BREAKPOINT */
  1808. long compat_arch_ptrace(struct task_struct *child, compat_long_t request,
  1809. compat_ulong_t caddr, compat_ulong_t cdata)
  1810. {
  1811. unsigned long addr = caddr;
  1812. unsigned long data = cdata;
  1813. void __user *datap = compat_ptr(data);
  1814. int ret;
  1815. switch (request) {
  1816. case PTRACE_PEEKUSR:
  1817. ret = compat_ptrace_read_user(child, addr, datap);
  1818. break;
  1819. case PTRACE_POKEUSR:
  1820. ret = compat_ptrace_write_user(child, addr, data);
  1821. break;
  1822. case COMPAT_PTRACE_GETREGS:
  1823. ret = copy_regset_to_user(child,
  1824. &user_aarch32_view,
  1825. REGSET_COMPAT_GPR,
  1826. 0, sizeof(compat_elf_gregset_t),
  1827. datap);
  1828. break;
  1829. case COMPAT_PTRACE_SETREGS:
  1830. ret = copy_regset_from_user(child,
  1831. &user_aarch32_view,
  1832. REGSET_COMPAT_GPR,
  1833. 0, sizeof(compat_elf_gregset_t),
  1834. datap);
  1835. break;
  1836. case COMPAT_PTRACE_GET_THREAD_AREA:
  1837. ret = put_user((compat_ulong_t)child->thread.uw.tp_value,
  1838. (compat_ulong_t __user *)datap);
  1839. break;
  1840. case COMPAT_PTRACE_SET_SYSCALL:
  1841. task_pt_regs(child)->syscallno = data;
  1842. ret = 0;
  1843. break;
  1844. case COMPAT_PTRACE_GETVFPREGS:
  1845. ret = copy_regset_to_user(child,
  1846. &user_aarch32_view,
  1847. REGSET_COMPAT_VFP,
  1848. 0, VFP_STATE_SIZE,
  1849. datap);
  1850. break;
  1851. case COMPAT_PTRACE_SETVFPREGS:
  1852. ret = copy_regset_from_user(child,
  1853. &user_aarch32_view,
  1854. REGSET_COMPAT_VFP,
  1855. 0, VFP_STATE_SIZE,
  1856. datap);
  1857. break;
  1858. #ifdef CONFIG_HAVE_HW_BREAKPOINT
  1859. case COMPAT_PTRACE_GETHBPREGS:
  1860. ret = compat_ptrace_gethbpregs(child, addr, datap);
  1861. break;
  1862. case COMPAT_PTRACE_SETHBPREGS:
  1863. ret = compat_ptrace_sethbpregs(child, addr, datap);
  1864. break;
  1865. #endif
  1866. default:
  1867. ret = compat_ptrace_request(child, request, addr,
  1868. data);
  1869. break;
  1870. }
  1871. return ret;
  1872. }
  1873. #endif /* CONFIG_COMPAT */
  1874. const struct user_regset_view *task_user_regset_view(struct task_struct *task)
  1875. {
  1876. /*
  1877. * Core dumping of 32-bit tasks or compat ptrace requests must use the
  1878. * user_aarch32_view compatible with arm32. Native ptrace requests on
  1879. * 32-bit children use an extended user_aarch32_ptrace_view to allow
  1880. * access to the TLS register.
  1881. */
  1882. if (is_compat_task())
  1883. return &user_aarch32_view;
  1884. else if (is_compat_thread(task_thread_info(task)))
  1885. return &user_aarch32_ptrace_view;
  1886. return &user_aarch64_view;
  1887. }
  1888. long arch_ptrace(struct task_struct *child, long request,
  1889. unsigned long addr, unsigned long data)
  1890. {
  1891. switch (request) {
  1892. case PTRACE_PEEKMTETAGS:
  1893. case PTRACE_POKEMTETAGS:
  1894. return mte_ptrace_copy_tags(child, request, addr, data);
  1895. }
  1896. return ptrace_request(child, request, addr, data);
  1897. }
  1898. enum ptrace_syscall_dir {
  1899. PTRACE_SYSCALL_ENTER = 0,
  1900. PTRACE_SYSCALL_EXIT,
  1901. };
  1902. static void report_syscall(struct pt_regs *regs, enum ptrace_syscall_dir dir)
  1903. {
  1904. int regno;
  1905. unsigned long saved_reg;
  1906. /*
  1907. * We have some ABI weirdness here in the way that we handle syscall
  1908. * exit stops because we indicate whether or not the stop has been
  1909. * signalled from syscall entry or syscall exit by clobbering a general
  1910. * purpose register (ip/r12 for AArch32, x7 for AArch64) in the tracee
  1911. * and restoring its old value after the stop. This means that:
  1912. *
  1913. * - Any writes by the tracer to this register during the stop are
  1914. * ignored/discarded.
  1915. *
  1916. * - The actual value of the register is not available during the stop,
  1917. * so the tracer cannot save it and restore it later.
  1918. *
  1919. * - Syscall stops behave differently to seccomp and pseudo-step traps
  1920. * (the latter do not nobble any registers).
  1921. */
  1922. regno = (is_compat_task() ? 12 : 7);
  1923. saved_reg = regs->regs[regno];
  1924. regs->regs[regno] = dir;
  1925. if (dir == PTRACE_SYSCALL_ENTER) {
  1926. if (ptrace_report_syscall_entry(regs))
  1927. forget_syscall(regs);
  1928. regs->regs[regno] = saved_reg;
  1929. } else if (!test_thread_flag(TIF_SINGLESTEP)) {
  1930. ptrace_report_syscall_exit(regs, 0);
  1931. regs->regs[regno] = saved_reg;
  1932. } else {
  1933. regs->regs[regno] = saved_reg;
  1934. /*
  1935. * Signal a pseudo-step exception since we are stepping but
  1936. * tracer modifications to the registers may have rewound the
  1937. * state machine.
  1938. */
  1939. ptrace_report_syscall_exit(regs, 1);
  1940. }
  1941. }
  1942. int syscall_trace_enter(struct pt_regs *regs)
  1943. {
  1944. unsigned long flags = read_thread_flags();
  1945. if (flags & (_TIF_SYSCALL_EMU | _TIF_SYSCALL_TRACE)) {
  1946. report_syscall(regs, PTRACE_SYSCALL_ENTER);
  1947. if (flags & _TIF_SYSCALL_EMU)
  1948. return NO_SYSCALL;
  1949. }
  1950. /* Do the secure computing after ptrace; failures should be fast. */
  1951. if (secure_computing() == -1)
  1952. return NO_SYSCALL;
  1953. if (test_thread_flag(TIF_SYSCALL_TRACEPOINT))
  1954. trace_sys_enter(regs, regs->syscallno);
  1955. audit_syscall_entry(regs->syscallno, regs->orig_x0, regs->regs[1],
  1956. regs->regs[2], regs->regs[3]);
  1957. return regs->syscallno;
  1958. }
  1959. void syscall_trace_exit(struct pt_regs *regs)
  1960. {
  1961. unsigned long flags = read_thread_flags();
  1962. audit_syscall_exit(regs);
  1963. if (flags & _TIF_SYSCALL_TRACEPOINT)
  1964. trace_sys_exit(regs, syscall_get_return_value(current, regs));
  1965. if (flags & (_TIF_SYSCALL_TRACE | _TIF_SINGLESTEP))
  1966. report_syscall(regs, PTRACE_SYSCALL_EXIT);
  1967. rseq_syscall(regs);
  1968. }
  1969. /*
  1970. * SPSR_ELx bits which are always architecturally RES0 per ARM DDI 0487D.a.
  1971. * We permit userspace to set SSBS (AArch64 bit 12, AArch32 bit 23) which is
  1972. * not described in ARM DDI 0487D.a.
  1973. * We treat PAN and UAO as RES0 bits, as they are meaningless at EL0, and may
  1974. * be allocated an EL0 meaning in future.
  1975. * Userspace cannot use these until they have an architectural meaning.
  1976. * Note that this follows the SPSR_ELx format, not the AArch32 PSR format.
  1977. * We also reserve IL for the kernel; SS is handled dynamically.
  1978. */
  1979. #define SPSR_EL1_AARCH64_RES0_BITS \
  1980. (GENMASK_ULL(63, 32) | GENMASK_ULL(27, 26) | GENMASK_ULL(23, 22) | \
  1981. GENMASK_ULL(20, 13) | GENMASK_ULL(5, 5))
  1982. #define SPSR_EL1_AARCH32_RES0_BITS \
  1983. (GENMASK_ULL(63, 32) | GENMASK_ULL(22, 22) | GENMASK_ULL(20, 20))
  1984. static int valid_compat_regs(struct user_pt_regs *regs)
  1985. {
  1986. regs->pstate &= ~SPSR_EL1_AARCH32_RES0_BITS;
  1987. if (!system_supports_mixed_endian_el0()) {
  1988. if (IS_ENABLED(CONFIG_CPU_BIG_ENDIAN))
  1989. regs->pstate |= PSR_AA32_E_BIT;
  1990. else
  1991. regs->pstate &= ~PSR_AA32_E_BIT;
  1992. }
  1993. if (user_mode(regs) && (regs->pstate & PSR_MODE32_BIT) &&
  1994. (regs->pstate & PSR_AA32_A_BIT) == 0 &&
  1995. (regs->pstate & PSR_AA32_I_BIT) == 0 &&
  1996. (regs->pstate & PSR_AA32_F_BIT) == 0) {
  1997. return 1;
  1998. }
  1999. /*
  2000. * Force PSR to a valid 32-bit EL0t, preserving the same bits as
  2001. * arch/arm.
  2002. */
  2003. regs->pstate &= PSR_AA32_N_BIT | PSR_AA32_Z_BIT |
  2004. PSR_AA32_C_BIT | PSR_AA32_V_BIT |
  2005. PSR_AA32_Q_BIT | PSR_AA32_IT_MASK |
  2006. PSR_AA32_GE_MASK | PSR_AA32_E_BIT |
  2007. PSR_AA32_T_BIT;
  2008. regs->pstate |= PSR_MODE32_BIT;
  2009. return 0;
  2010. }
  2011. static int valid_native_regs(struct user_pt_regs *regs)
  2012. {
  2013. regs->pstate &= ~SPSR_EL1_AARCH64_RES0_BITS;
  2014. if (user_mode(regs) && !(regs->pstate & PSR_MODE32_BIT) &&
  2015. (regs->pstate & PSR_D_BIT) == 0 &&
  2016. (regs->pstate & PSR_A_BIT) == 0 &&
  2017. (regs->pstate & PSR_I_BIT) == 0 &&
  2018. (regs->pstate & PSR_F_BIT) == 0) {
  2019. return 1;
  2020. }
  2021. /* Force PSR to a valid 64-bit EL0t */
  2022. regs->pstate &= PSR_N_BIT | PSR_Z_BIT | PSR_C_BIT | PSR_V_BIT;
  2023. return 0;
  2024. }
  2025. /*
  2026. * Are the current registers suitable for user mode? (used to maintain
  2027. * security in signal handlers)
  2028. */
  2029. int valid_user_regs(struct user_pt_regs *regs, struct task_struct *task)
  2030. {
  2031. /* https://lore.kernel.org/lkml/20191118131525.GA4180@willie-the-truck */
  2032. user_regs_reset_single_step(regs, task);
  2033. if (is_compat_thread(task_thread_info(task)))
  2034. return valid_compat_regs(regs);
  2035. else
  2036. return valid_native_regs(regs);
  2037. }