159c4da86SZong Li // SPDX-License-Identifier: GPL-2.0-only 259c4da86SZong Li /* 359c4da86SZong Li * Copyright (C) 2019 SiFive 459c4da86SZong Li */ 559c4da86SZong Li 6*de22d210SAtish Patra #include <linux/efi.h> 759c4da86SZong Li #include <linux/init.h> 859c4da86SZong Li #include <linux/debugfs.h> 959c4da86SZong Li #include <linux/seq_file.h> 1059c4da86SZong Li #include <linux/ptdump.h> 1159c4da86SZong Li 1259c4da86SZong Li #include <asm/ptdump.h> 13ca5999fdSMike Rapoport #include <linux/pgtable.h> 1459c4da86SZong Li #include <asm/kasan.h> 1559c4da86SZong Li 1659c4da86SZong Li #define pt_dump_seq_printf(m, fmt, args...) \ 1759c4da86SZong Li ({ \ 1859c4da86SZong Li if (m) \ 1959c4da86SZong Li seq_printf(m, fmt, ##args); \ 2059c4da86SZong Li }) 2159c4da86SZong Li 2259c4da86SZong Li #define pt_dump_seq_puts(m, fmt) \ 2359c4da86SZong Li ({ \ 2459c4da86SZong Li if (m) \ 2559c4da86SZong Li seq_printf(m, fmt); \ 2659c4da86SZong Li }) 2759c4da86SZong Li 2859c4da86SZong Li /* 2959c4da86SZong Li * The page dumper groups page table entries of the same type into a single 3059c4da86SZong Li * description. It uses pg_state to track the range information while 3159c4da86SZong Li * iterating over the pte entries. When the continuity is broken it then 3259c4da86SZong Li * dumps out a description of the range. 3359c4da86SZong Li */ 3459c4da86SZong Li struct pg_state { 3559c4da86SZong Li struct ptdump_state ptdump; 3659c4da86SZong Li struct seq_file *seq; 3759c4da86SZong Li const struct addr_marker *marker; 3859c4da86SZong Li unsigned long start_address; 3959c4da86SZong Li unsigned long start_pa; 4059c4da86SZong Li unsigned long last_pa; 4159c4da86SZong Li int level; 4259c4da86SZong Li u64 current_prot; 4359c4da86SZong Li bool check_wx; 4459c4da86SZong Li unsigned long wx_pages; 4559c4da86SZong Li }; 4659c4da86SZong Li 4759c4da86SZong Li /* Address marker */ 4859c4da86SZong Li struct addr_marker { 4959c4da86SZong Li unsigned long start_address; 5059c4da86SZong Li const char *name; 5159c4da86SZong Li }; 5259c4da86SZong Li 53*de22d210SAtish Patra /* Private information for debugfs */ 54*de22d210SAtish Patra struct ptd_mm_info { 55*de22d210SAtish Patra struct mm_struct *mm; 56*de22d210SAtish Patra const struct addr_marker *markers; 57*de22d210SAtish Patra unsigned long base_addr; 58*de22d210SAtish Patra unsigned long end; 59*de22d210SAtish Patra }; 60*de22d210SAtish Patra 6159c4da86SZong Li static struct addr_marker address_markers[] = { 6259c4da86SZong Li #ifdef CONFIG_KASAN 6359c4da86SZong Li {KASAN_SHADOW_START, "Kasan shadow start"}, 6459c4da86SZong Li {KASAN_SHADOW_END, "Kasan shadow end"}, 6559c4da86SZong Li #endif 6659c4da86SZong Li {FIXADDR_START, "Fixmap start"}, 6759c4da86SZong Li {FIXADDR_TOP, "Fixmap end"}, 6859c4da86SZong Li {PCI_IO_START, "PCI I/O start"}, 6959c4da86SZong Li {PCI_IO_END, "PCI I/O end"}, 7059c4da86SZong Li #ifdef CONFIG_SPARSEMEM_VMEMMAP 7159c4da86SZong Li {VMEMMAP_START, "vmemmap start"}, 7259c4da86SZong Li {VMEMMAP_END, "vmemmap end"}, 7359c4da86SZong Li #endif 7459c4da86SZong Li {VMALLOC_START, "vmalloc() area"}, 7559c4da86SZong Li {VMALLOC_END, "vmalloc() end"}, 7659c4da86SZong Li {PAGE_OFFSET, "Linear mapping"}, 7759c4da86SZong Li {-1, NULL}, 7859c4da86SZong Li }; 7959c4da86SZong Li 80*de22d210SAtish Patra static struct ptd_mm_info kernel_ptd_info = { 81*de22d210SAtish Patra .mm = &init_mm, 82*de22d210SAtish Patra .markers = address_markers, 83*de22d210SAtish Patra .base_addr = KERN_VIRT_START, 84*de22d210SAtish Patra .end = ULONG_MAX, 85*de22d210SAtish Patra }; 86*de22d210SAtish Patra 87*de22d210SAtish Patra #ifdef CONFIG_EFI 88*de22d210SAtish Patra static struct addr_marker efi_addr_markers[] = { 89*de22d210SAtish Patra { 0, "UEFI runtime start" }, 90*de22d210SAtish Patra { SZ_1G, "UEFI runtime end" }, 91*de22d210SAtish Patra { -1, NULL } 92*de22d210SAtish Patra }; 93*de22d210SAtish Patra 94*de22d210SAtish Patra static struct ptd_mm_info efi_ptd_info = { 95*de22d210SAtish Patra .mm = &efi_mm, 96*de22d210SAtish Patra .markers = efi_addr_markers, 97*de22d210SAtish Patra .base_addr = 0, 98*de22d210SAtish Patra .end = SZ_2G, 99*de22d210SAtish Patra }; 100*de22d210SAtish Patra #endif 101*de22d210SAtish Patra 10259c4da86SZong Li /* Page Table Entry */ 10359c4da86SZong Li struct prot_bits { 10459c4da86SZong Li u64 mask; 10559c4da86SZong Li u64 val; 10659c4da86SZong Li const char *set; 10759c4da86SZong Li const char *clear; 10859c4da86SZong Li }; 10959c4da86SZong Li 11059c4da86SZong Li static const struct prot_bits pte_bits[] = { 11159c4da86SZong Li { 11259c4da86SZong Li .mask = _PAGE_SOFT, 11359c4da86SZong Li .val = _PAGE_SOFT, 11459c4da86SZong Li .set = "RSW", 11559c4da86SZong Li .clear = " ", 11659c4da86SZong Li }, { 11759c4da86SZong Li .mask = _PAGE_DIRTY, 11859c4da86SZong Li .val = _PAGE_DIRTY, 11959c4da86SZong Li .set = "D", 12059c4da86SZong Li .clear = ".", 12159c4da86SZong Li }, { 12259c4da86SZong Li .mask = _PAGE_ACCESSED, 12359c4da86SZong Li .val = _PAGE_ACCESSED, 12459c4da86SZong Li .set = "A", 12559c4da86SZong Li .clear = ".", 12659c4da86SZong Li }, { 12759c4da86SZong Li .mask = _PAGE_GLOBAL, 12859c4da86SZong Li .val = _PAGE_GLOBAL, 12959c4da86SZong Li .set = "G", 13059c4da86SZong Li .clear = ".", 13159c4da86SZong Li }, { 13259c4da86SZong Li .mask = _PAGE_USER, 13359c4da86SZong Li .val = _PAGE_USER, 13459c4da86SZong Li .set = "U", 13559c4da86SZong Li .clear = ".", 13659c4da86SZong Li }, { 13759c4da86SZong Li .mask = _PAGE_EXEC, 13859c4da86SZong Li .val = _PAGE_EXEC, 13959c4da86SZong Li .set = "X", 14059c4da86SZong Li .clear = ".", 14159c4da86SZong Li }, { 14259c4da86SZong Li .mask = _PAGE_WRITE, 14359c4da86SZong Li .val = _PAGE_WRITE, 14459c4da86SZong Li .set = "W", 14559c4da86SZong Li .clear = ".", 14659c4da86SZong Li }, { 14759c4da86SZong Li .mask = _PAGE_READ, 14859c4da86SZong Li .val = _PAGE_READ, 14959c4da86SZong Li .set = "R", 15059c4da86SZong Li .clear = ".", 15159c4da86SZong Li }, { 15259c4da86SZong Li .mask = _PAGE_PRESENT, 15359c4da86SZong Li .val = _PAGE_PRESENT, 15459c4da86SZong Li .set = "V", 15559c4da86SZong Li .clear = ".", 15659c4da86SZong Li } 15759c4da86SZong Li }; 15859c4da86SZong Li 15959c4da86SZong Li /* Page Level */ 16059c4da86SZong Li struct pg_level { 16159c4da86SZong Li const char *name; 16259c4da86SZong Li u64 mask; 16359c4da86SZong Li }; 16459c4da86SZong Li 16559c4da86SZong Li static struct pg_level pg_level[] = { 16659c4da86SZong Li { /* pgd */ 16759c4da86SZong Li .name = "PGD", 16859c4da86SZong Li }, { /* p4d */ 16959c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 4) ? "P4D" : "PGD", 17059c4da86SZong Li }, { /* pud */ 17159c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 3) ? "PUD" : "PGD", 17259c4da86SZong Li }, { /* pmd */ 17359c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 2) ? "PMD" : "PGD", 17459c4da86SZong Li }, { /* pte */ 17559c4da86SZong Li .name = "PTE", 17659c4da86SZong Li }, 17759c4da86SZong Li }; 17859c4da86SZong Li 17959c4da86SZong Li static void dump_prot(struct pg_state *st) 18059c4da86SZong Li { 18159c4da86SZong Li unsigned int i; 18259c4da86SZong Li 18359c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pte_bits); i++) { 18459c4da86SZong Li const char *s; 18559c4da86SZong Li 18659c4da86SZong Li if ((st->current_prot & pte_bits[i].mask) == pte_bits[i].val) 18759c4da86SZong Li s = pte_bits[i].set; 18859c4da86SZong Li else 18959c4da86SZong Li s = pte_bits[i].clear; 19059c4da86SZong Li 19159c4da86SZong Li if (s) 19259c4da86SZong Li pt_dump_seq_printf(st->seq, " %s", s); 19359c4da86SZong Li } 19459c4da86SZong Li } 19559c4da86SZong Li 19659c4da86SZong Li #ifdef CONFIG_64BIT 19759c4da86SZong Li #define ADDR_FORMAT "0x%016lx" 19859c4da86SZong Li #else 19959c4da86SZong Li #define ADDR_FORMAT "0x%08lx" 20059c4da86SZong Li #endif 20159c4da86SZong Li static void dump_addr(struct pg_state *st, unsigned long addr) 20259c4da86SZong Li { 20359c4da86SZong Li static const char units[] = "KMGTPE"; 20459c4da86SZong Li const char *unit = units; 20559c4da86SZong Li unsigned long delta; 20659c4da86SZong Li 20759c4da86SZong Li pt_dump_seq_printf(st->seq, ADDR_FORMAT "-" ADDR_FORMAT " ", 20859c4da86SZong Li st->start_address, addr); 20959c4da86SZong Li 21059c4da86SZong Li pt_dump_seq_printf(st->seq, " " ADDR_FORMAT " ", st->start_pa); 21159c4da86SZong Li delta = (addr - st->start_address) >> 10; 21259c4da86SZong Li 21359c4da86SZong Li while (!(delta & 1023) && unit[1]) { 21459c4da86SZong Li delta >>= 10; 21559c4da86SZong Li unit++; 21659c4da86SZong Li } 21759c4da86SZong Li 21859c4da86SZong Li pt_dump_seq_printf(st->seq, "%9lu%c %s", delta, *unit, 21959c4da86SZong Li pg_level[st->level].name); 22059c4da86SZong Li } 22159c4da86SZong Li 22259c4da86SZong Li static void note_prot_wx(struct pg_state *st, unsigned long addr) 22359c4da86SZong Li { 22459c4da86SZong Li if (!st->check_wx) 22559c4da86SZong Li return; 22659c4da86SZong Li 22759c4da86SZong Li if ((st->current_prot & (_PAGE_WRITE | _PAGE_EXEC)) != 22859c4da86SZong Li (_PAGE_WRITE | _PAGE_EXEC)) 22959c4da86SZong Li return; 23059c4da86SZong Li 23159c4da86SZong Li WARN_ONCE(1, "riscv/mm: Found insecure W+X mapping at address %p/%pS\n", 23259c4da86SZong Li (void *)st->start_address, (void *)st->start_address); 23359c4da86SZong Li 23459c4da86SZong Li st->wx_pages += (addr - st->start_address) / PAGE_SIZE; 23559c4da86SZong Li } 23659c4da86SZong Li 23759c4da86SZong Li static void note_page(struct ptdump_state *pt_st, unsigned long addr, 23899395ee3SSteven Price int level, u64 val) 23959c4da86SZong Li { 24059c4da86SZong Li struct pg_state *st = container_of(pt_st, struct pg_state, ptdump); 24159c4da86SZong Li u64 pa = PFN_PHYS(pte_pfn(__pte(val))); 24259c4da86SZong Li u64 prot = 0; 24359c4da86SZong Li 24459c4da86SZong Li if (level >= 0) 24559c4da86SZong Li prot = val & pg_level[level].mask; 24659c4da86SZong Li 24759c4da86SZong Li if (st->level == -1) { 24859c4da86SZong Li st->level = level; 24959c4da86SZong Li st->current_prot = prot; 25059c4da86SZong Li st->start_address = addr; 25159c4da86SZong Li st->start_pa = pa; 25259c4da86SZong Li st->last_pa = pa; 25359c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", st->marker->name); 25459c4da86SZong Li } else if (prot != st->current_prot || 25559c4da86SZong Li level != st->level || addr >= st->marker[1].start_address) { 25659c4da86SZong Li if (st->current_prot) { 25759c4da86SZong Li note_prot_wx(st, addr); 25859c4da86SZong Li dump_addr(st, addr); 25959c4da86SZong Li dump_prot(st); 26059c4da86SZong Li pt_dump_seq_puts(st->seq, "\n"); 26159c4da86SZong Li } 26259c4da86SZong Li 26359c4da86SZong Li while (addr >= st->marker[1].start_address) { 26459c4da86SZong Li st->marker++; 26559c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", 26659c4da86SZong Li st->marker->name); 26759c4da86SZong Li } 26859c4da86SZong Li 26959c4da86SZong Li st->start_address = addr; 27059c4da86SZong Li st->start_pa = pa; 27159c4da86SZong Li st->last_pa = pa; 27259c4da86SZong Li st->current_prot = prot; 27359c4da86SZong Li st->level = level; 27459c4da86SZong Li } else { 27559c4da86SZong Li st->last_pa = pa; 27659c4da86SZong Li } 27759c4da86SZong Li } 27859c4da86SZong Li 279*de22d210SAtish Patra static void ptdump_walk(struct seq_file *s, struct ptd_mm_info *pinfo) 28059c4da86SZong Li { 28159c4da86SZong Li struct pg_state st = { 28259c4da86SZong Li .seq = s, 283*de22d210SAtish Patra .marker = pinfo->markers, 28459c4da86SZong Li .level = -1, 28559c4da86SZong Li .ptdump = { 28659c4da86SZong Li .note_page = note_page, 28759c4da86SZong Li .range = (struct ptdump_range[]) { 288*de22d210SAtish Patra {pinfo->base_addr, pinfo->end}, 28959c4da86SZong Li {0, 0} 29059c4da86SZong Li } 29159c4da86SZong Li } 29259c4da86SZong Li }; 29359c4da86SZong Li 294*de22d210SAtish Patra ptdump_walk_pgd(&st.ptdump, pinfo->mm, NULL); 29559c4da86SZong Li } 29659c4da86SZong Li 29759c4da86SZong Li void ptdump_check_wx(void) 29859c4da86SZong Li { 29959c4da86SZong Li struct pg_state st = { 30059c4da86SZong Li .seq = NULL, 30159c4da86SZong Li .marker = (struct addr_marker[]) { 30259c4da86SZong Li {0, NULL}, 30359c4da86SZong Li {-1, NULL}, 30459c4da86SZong Li }, 30559c4da86SZong Li .level = -1, 30659c4da86SZong Li .check_wx = true, 30759c4da86SZong Li .ptdump = { 30859c4da86SZong Li .note_page = note_page, 30959c4da86SZong Li .range = (struct ptdump_range[]) { 31059c4da86SZong Li {KERN_VIRT_START, ULONG_MAX}, 31159c4da86SZong Li {0, 0} 31259c4da86SZong Li } 31359c4da86SZong Li } 31459c4da86SZong Li }; 31559c4da86SZong Li 31659c4da86SZong Li ptdump_walk_pgd(&st.ptdump, &init_mm, NULL); 31759c4da86SZong Li 31859c4da86SZong Li if (st.wx_pages) 31959c4da86SZong Li pr_warn("Checked W+X mappings: failed, %lu W+X pages found\n", 32059c4da86SZong Li st.wx_pages); 32159c4da86SZong Li else 32259c4da86SZong Li pr_info("Checked W+X mappings: passed, no W+X pages found\n"); 32359c4da86SZong Li } 32459c4da86SZong Li 32559c4da86SZong Li static int ptdump_show(struct seq_file *m, void *v) 32659c4da86SZong Li { 327*de22d210SAtish Patra ptdump_walk(m, m->private); 32859c4da86SZong Li 32959c4da86SZong Li return 0; 33059c4da86SZong Li } 33159c4da86SZong Li 33259c4da86SZong Li DEFINE_SHOW_ATTRIBUTE(ptdump); 33359c4da86SZong Li 33459c4da86SZong Li static int ptdump_init(void) 33559c4da86SZong Li { 33659c4da86SZong Li unsigned int i, j; 33759c4da86SZong Li 33859c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pg_level); i++) 33959c4da86SZong Li for (j = 0; j < ARRAY_SIZE(pte_bits); j++) 34059c4da86SZong Li pg_level[i].mask |= pte_bits[j].mask; 34159c4da86SZong Li 342*de22d210SAtish Patra debugfs_create_file("kernel_page_tables", 0400, NULL, &kernel_ptd_info, 34359c4da86SZong Li &ptdump_fops); 344*de22d210SAtish Patra #ifdef CONFIG_EFI 345*de22d210SAtish Patra if (efi_enabled(EFI_RUNTIME_SERVICES)) 346*de22d210SAtish Patra debugfs_create_file("efi_page_tables", 0400, NULL, &efi_ptd_info, 347*de22d210SAtish Patra &ptdump_fops); 348*de22d210SAtish Patra #endif 34959c4da86SZong Li 35059c4da86SZong Li return 0; 35159c4da86SZong Li } 35259c4da86SZong Li 35359c4da86SZong Li device_initcall(ptdump_init); 354