xref: /openbmc/linux/kernel/kexec_file.c (revision ca2478a7d974f38d29d27acb42a952c7f168916e)
140b0b3f8SThomas Gleixner // SPDX-License-Identifier: GPL-2.0-only
2a43cac0dSDave Young /*
3a43cac0dSDave Young  * kexec: kexec_file_load system call
4a43cac0dSDave Young  *
5a43cac0dSDave Young  * Copyright (C) 2014 Red Hat Inc.
6a43cac0dSDave Young  * Authors:
7a43cac0dSDave Young  *      Vivek Goyal <vgoyal@redhat.com>
8a43cac0dSDave Young  */
9a43cac0dSDave Young 
10de90a6bcSMinfei Huang #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
11de90a6bcSMinfei Huang 
12a43cac0dSDave Young #include <linux/capability.h>
13a43cac0dSDave Young #include <linux/mm.h>
14a43cac0dSDave Young #include <linux/file.h>
15a43cac0dSDave Young #include <linux/slab.h>
16a43cac0dSDave Young #include <linux/kexec.h>
17735c2f90SAKASHI Takahiro #include <linux/memblock.h>
18a43cac0dSDave Young #include <linux/mutex.h>
19a43cac0dSDave Young #include <linux/list.h>
20b804defeSMimi Zohar #include <linux/fs.h>
217b8589ccSMimi Zohar #include <linux/ima.h>
22a43cac0dSDave Young #include <crypto/hash.h>
23a24d22b2SEric Biggers #include <crypto/sha2.h>
24babac4a8SAKASHI Takahiro #include <linux/elf.h>
25babac4a8SAKASHI Takahiro #include <linux/elfcore.h>
26babac4a8SAKASHI Takahiro #include <linux/kernel.h>
27b89999d0SScott Branden #include <linux/kernel_read_file.h>
28a43cac0dSDave Young #include <linux/syscalls.h>
29a43cac0dSDave Young #include <linux/vmalloc.h>
30a43cac0dSDave Young #include "kexec_internal.h"
31a43cac0dSDave Young 
32af16df54SCoiby Xu #ifdef CONFIG_KEXEC_SIG
33af16df54SCoiby Xu static bool sig_enforce = IS_ENABLED(CONFIG_KEXEC_SIG_FORCE);
34af16df54SCoiby Xu 
set_kexec_sig_enforced(void)35af16df54SCoiby Xu void set_kexec_sig_enforced(void)
36af16df54SCoiby Xu {
37af16df54SCoiby Xu 	sig_enforce = true;
38af16df54SCoiby Xu }
39af16df54SCoiby Xu #endif
40af16df54SCoiby Xu 
41a43cac0dSDave Young static int kexec_calculate_store_digests(struct kimage *image);
42a43cac0dSDave Young 
43f4da7afeSPasha Tatashin /* Maximum size in bytes for kernel/initrd files. */
44f4da7afeSPasha Tatashin #define KEXEC_FILE_SIZE_MAX	min_t(s64, 4LL << 30, SSIZE_MAX)
45f4da7afeSPasha Tatashin 
469ec4ecefSAKASHI Takahiro /*
479ec4ecefSAKASHI Takahiro  * Currently this is the only default function that is exported as some
489ec4ecefSAKASHI Takahiro  * architectures need it to do additional handlings.
499ec4ecefSAKASHI Takahiro  * In the future, other default functions may be exported too if required.
509ec4ecefSAKASHI Takahiro  */
kexec_image_probe_default(struct kimage * image,void * buf,unsigned long buf_len)519ec4ecefSAKASHI Takahiro int kexec_image_probe_default(struct kimage *image, void *buf,
529ec4ecefSAKASHI Takahiro 			      unsigned long buf_len)
539ec4ecefSAKASHI Takahiro {
549ec4ecefSAKASHI Takahiro 	const struct kexec_file_ops * const *fops;
559ec4ecefSAKASHI Takahiro 	int ret = -ENOEXEC;
569ec4ecefSAKASHI Takahiro 
579ec4ecefSAKASHI Takahiro 	for (fops = &kexec_file_loaders[0]; *fops && (*fops)->probe; ++fops) {
589ec4ecefSAKASHI Takahiro 		ret = (*fops)->probe(buf, buf_len);
599ec4ecefSAKASHI Takahiro 		if (!ret) {
609ec4ecefSAKASHI Takahiro 			image->fops = *fops;
619ec4ecefSAKASHI Takahiro 			return ret;
629ec4ecefSAKASHI Takahiro 		}
639ec4ecefSAKASHI Takahiro 	}
649ec4ecefSAKASHI Takahiro 
659ec4ecefSAKASHI Takahiro 	return ret;
669ec4ecefSAKASHI Takahiro }
679ec4ecefSAKASHI Takahiro 
kexec_image_load_default(struct kimage * image)68fb15abdcSBjorn Helgaas static void *kexec_image_load_default(struct kimage *image)
699ec4ecefSAKASHI Takahiro {
709ec4ecefSAKASHI Takahiro 	if (!image->fops || !image->fops->load)
719ec4ecefSAKASHI Takahiro 		return ERR_PTR(-ENOEXEC);
729ec4ecefSAKASHI Takahiro 
739ec4ecefSAKASHI Takahiro 	return image->fops->load(image, image->kernel_buf,
749ec4ecefSAKASHI Takahiro 				 image->kernel_buf_len, image->initrd_buf,
759ec4ecefSAKASHI Takahiro 				 image->initrd_buf_len, image->cmdline_buf,
769ec4ecefSAKASHI Takahiro 				 image->cmdline_buf_len);
77a43cac0dSDave Young }
78a43cac0dSDave Young 
kexec_image_post_load_cleanup_default(struct kimage * image)7992a98a2bSAKASHI Takahiro int kexec_image_post_load_cleanup_default(struct kimage *image)
809ec4ecefSAKASHI Takahiro {
819ec4ecefSAKASHI Takahiro 	if (!image->fops || !image->fops->cleanup)
829ec4ecefSAKASHI Takahiro 		return 0;
839ec4ecefSAKASHI Takahiro 
849ec4ecefSAKASHI Takahiro 	return image->fops->cleanup(image->image_loader_data);
85a43cac0dSDave Young }
86a43cac0dSDave Young 
878aec395bSPhilipp Rudo /*
88a43cac0dSDave Young  * Free up memory used by kernel, initrd, and command line. This is temporary
89a43cac0dSDave Young  * memory allocation which is not needed any more after these buffers have
90a43cac0dSDave Young  * been loaded into separate segments and have been copied elsewhere.
91a43cac0dSDave Young  */
kimage_file_post_load_cleanup(struct kimage * image)92a43cac0dSDave Young void kimage_file_post_load_cleanup(struct kimage *image)
93a43cac0dSDave Young {
94a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
95a43cac0dSDave Young 
96a43cac0dSDave Young 	vfree(image->kernel_buf);
97a43cac0dSDave Young 	image->kernel_buf = NULL;
98a43cac0dSDave Young 
99a43cac0dSDave Young 	vfree(image->initrd_buf);
100a43cac0dSDave Young 	image->initrd_buf = NULL;
101a43cac0dSDave Young 
102a43cac0dSDave Young 	kfree(image->cmdline_buf);
103a43cac0dSDave Young 	image->cmdline_buf = NULL;
104a43cac0dSDave Young 
105a43cac0dSDave Young 	vfree(pi->purgatory_buf);
106a43cac0dSDave Young 	pi->purgatory_buf = NULL;
107a43cac0dSDave Young 
108a43cac0dSDave Young 	vfree(pi->sechdrs);
109a43cac0dSDave Young 	pi->sechdrs = NULL;
110a43cac0dSDave Young 
111f31e3386SLakshmi Ramasubramanian #ifdef CONFIG_IMA_KEXEC
112f31e3386SLakshmi Ramasubramanian 	vfree(image->ima_buffer);
113f31e3386SLakshmi Ramasubramanian 	image->ima_buffer = NULL;
114f31e3386SLakshmi Ramasubramanian #endif /* CONFIG_IMA_KEXEC */
115f31e3386SLakshmi Ramasubramanian 
116a43cac0dSDave Young 	/* See if architecture has anything to cleanup post load */
117a43cac0dSDave Young 	arch_kimage_file_post_load_cleanup(image);
118a43cac0dSDave Young 
119a43cac0dSDave Young 	/*
120a43cac0dSDave Young 	 * Above call should have called into bootloader to free up
121a43cac0dSDave Young 	 * any data stored in kimage->image_loader_data. It should
122a43cac0dSDave Young 	 * be ok now to free it up.
123a43cac0dSDave Young 	 */
124a43cac0dSDave Young 	kfree(image->image_loader_data);
125a43cac0dSDave Young 	image->image_loader_data = NULL;
126a43cac0dSDave Young }
127a43cac0dSDave Young 
12899d5cadfSJiri Bohac #ifdef CONFIG_KEXEC_SIG
129c903dae8SCoiby Xu #ifdef CONFIG_SIGNED_PE_FILE_VERIFICATION
kexec_kernel_verify_pe_sig(const char * kernel,unsigned long kernel_len)130c903dae8SCoiby Xu int kexec_kernel_verify_pe_sig(const char *kernel, unsigned long kernel_len)
131c903dae8SCoiby Xu {
132c903dae8SCoiby Xu 	int ret;
133c903dae8SCoiby Xu 
134c903dae8SCoiby Xu 	ret = verify_pefile_signature(kernel, kernel_len,
135c903dae8SCoiby Xu 				      VERIFY_USE_SECONDARY_KEYRING,
136c903dae8SCoiby Xu 				      VERIFYING_KEXEC_PE_SIGNATURE);
137c903dae8SCoiby Xu 	if (ret == -ENOKEY && IS_ENABLED(CONFIG_INTEGRITY_PLATFORM_KEYRING)) {
138c903dae8SCoiby Xu 		ret = verify_pefile_signature(kernel, kernel_len,
139c903dae8SCoiby Xu 					      VERIFY_USE_PLATFORM_KEYRING,
140c903dae8SCoiby Xu 					      VERIFYING_KEXEC_PE_SIGNATURE);
141c903dae8SCoiby Xu 	}
142c903dae8SCoiby Xu 	return ret;
143c903dae8SCoiby Xu }
144c903dae8SCoiby Xu #endif
145c903dae8SCoiby Xu 
kexec_image_verify_sig(struct kimage * image,void * buf,unsigned long buf_len)146689a7149SCoiby Xu static int kexec_image_verify_sig(struct kimage *image, void *buf,
147689a7149SCoiby Xu 				  unsigned long buf_len)
148689a7149SCoiby Xu {
149689a7149SCoiby Xu 	if (!image->fops || !image->fops->verify_sig) {
150689a7149SCoiby Xu 		pr_debug("kernel loader does not support signature verification.\n");
151689a7149SCoiby Xu 		return -EKEYREJECTED;
152689a7149SCoiby Xu 	}
153689a7149SCoiby Xu 
154689a7149SCoiby Xu 	return image->fops->verify_sig(buf, buf_len);
155689a7149SCoiby Xu }
156689a7149SCoiby Xu 
15799d5cadfSJiri Bohac static int
kimage_validate_signature(struct kimage * image)15899d5cadfSJiri Bohac kimage_validate_signature(struct kimage *image)
15999d5cadfSJiri Bohac {
16099d5cadfSJiri Bohac 	int ret;
16199d5cadfSJiri Bohac 
162689a7149SCoiby Xu 	ret = kexec_image_verify_sig(image, image->kernel_buf,
16399d5cadfSJiri Bohac 				     image->kernel_buf_len);
164fd7af71bSLianbo Jiang 	if (ret) {
16599d5cadfSJiri Bohac 
166af16df54SCoiby Xu 		if (sig_enforce) {
167fd7af71bSLianbo Jiang 			pr_notice("Enforced kernel signature verification failed (%d).\n", ret);
16899d5cadfSJiri Bohac 			return ret;
16999d5cadfSJiri Bohac 		}
17099d5cadfSJiri Bohac 
171fd7af71bSLianbo Jiang 		/*
172fd7af71bSLianbo Jiang 		 * If IMA is guaranteed to appraise a signature on the kexec
17329d3c1c8SMatthew Garrett 		 * image, permit it even if the kernel is otherwise locked
17429d3c1c8SMatthew Garrett 		 * down.
17529d3c1c8SMatthew Garrett 		 */
17629d3c1c8SMatthew Garrett 		if (!ima_appraise_signature(READING_KEXEC_IMAGE) &&
17729d3c1c8SMatthew Garrett 		    security_locked_down(LOCKDOWN_KEXEC))
17829d3c1c8SMatthew Garrett 			return -EPERM;
17929d3c1c8SMatthew Garrett 
180fd7af71bSLianbo Jiang 		pr_debug("kernel signature verification failed (%d).\n", ret);
18199d5cadfSJiri Bohac 	}
18299d5cadfSJiri Bohac 
183fd7af71bSLianbo Jiang 	return 0;
18499d5cadfSJiri Bohac }
18599d5cadfSJiri Bohac #endif
18699d5cadfSJiri Bohac 
187a43cac0dSDave Young /*
188a43cac0dSDave Young  * In file mode list of segments is prepared by kernel. Copy relevant
189a43cac0dSDave Young  * data from user space, do error checking, prepare segment list
190a43cac0dSDave Young  */
191a43cac0dSDave Young static int
kimage_file_prepare_segments(struct kimage * image,int kernel_fd,int initrd_fd,const char __user * cmdline_ptr,unsigned long cmdline_len,unsigned flags)192a43cac0dSDave Young kimage_file_prepare_segments(struct kimage *image, int kernel_fd, int initrd_fd,
193a43cac0dSDave Young 			     const char __user *cmdline_ptr,
194a43cac0dSDave Young 			     unsigned long cmdline_len, unsigned flags)
195a43cac0dSDave Young {
196f4da7afeSPasha Tatashin 	ssize_t ret;
197a43cac0dSDave Young 	void *ldata;
198a43cac0dSDave Young 
1990fa8e084SKees Cook 	ret = kernel_read_file_from_fd(kernel_fd, 0, &image->kernel_buf,
200f4da7afeSPasha Tatashin 				       KEXEC_FILE_SIZE_MAX, NULL,
201f4da7afeSPasha Tatashin 				       READING_KEXEC_IMAGE);
202f7a4f689SKees Cook 	if (ret < 0)
203a43cac0dSDave Young 		return ret;
204f7a4f689SKees Cook 	image->kernel_buf_len = ret;
205a43cac0dSDave Young 
206a43cac0dSDave Young 	/* Call arch image probe handlers */
207a43cac0dSDave Young 	ret = arch_kexec_kernel_image_probe(image, image->kernel_buf,
208a43cac0dSDave Young 					    image->kernel_buf_len);
209a43cac0dSDave Young 	if (ret)
210a43cac0dSDave Young 		goto out;
211a43cac0dSDave Young 
21299d5cadfSJiri Bohac #ifdef CONFIG_KEXEC_SIG
21399d5cadfSJiri Bohac 	ret = kimage_validate_signature(image);
21499d5cadfSJiri Bohac 
21599d5cadfSJiri Bohac 	if (ret)
216a43cac0dSDave Young 		goto out;
217a43cac0dSDave Young #endif
218a43cac0dSDave Young 	/* It is possible that there no initramfs is being loaded */
219a43cac0dSDave Young 	if (!(flags & KEXEC_FILE_NO_INITRAMFS)) {
2200fa8e084SKees Cook 		ret = kernel_read_file_from_fd(initrd_fd, 0, &image->initrd_buf,
221f4da7afeSPasha Tatashin 					       KEXEC_FILE_SIZE_MAX, NULL,
222b804defeSMimi Zohar 					       READING_KEXEC_INITRAMFS);
223f7a4f689SKees Cook 		if (ret < 0)
224a43cac0dSDave Young 			goto out;
225f7a4f689SKees Cook 		image->initrd_buf_len = ret;
226f7a4f689SKees Cook 		ret = 0;
227a43cac0dSDave Young 	}
228a43cac0dSDave Young 
229a43cac0dSDave Young 	if (cmdline_len) {
230a9bd8dfaSAl Viro 		image->cmdline_buf = memdup_user(cmdline_ptr, cmdline_len);
231a9bd8dfaSAl Viro 		if (IS_ERR(image->cmdline_buf)) {
232a9bd8dfaSAl Viro 			ret = PTR_ERR(image->cmdline_buf);
233a9bd8dfaSAl Viro 			image->cmdline_buf = NULL;
234a43cac0dSDave Young 			goto out;
235a43cac0dSDave Young 		}
236a43cac0dSDave Young 
237a43cac0dSDave Young 		image->cmdline_buf_len = cmdline_len;
238a43cac0dSDave Young 
239a43cac0dSDave Young 		/* command line should be a string with last byte null */
240a43cac0dSDave Young 		if (image->cmdline_buf[cmdline_len - 1] != '\0') {
241a43cac0dSDave Young 			ret = -EINVAL;
242a43cac0dSDave Young 			goto out;
243a43cac0dSDave Young 		}
2446a31fcd4SPrakhar Srivastava 
2454834177eSTyler Hicks 		ima_kexec_cmdline(kernel_fd, image->cmdline_buf,
2466a31fcd4SPrakhar Srivastava 				  image->cmdline_buf_len - 1);
247a43cac0dSDave Young 	}
248a43cac0dSDave Young 
2496a31fcd4SPrakhar Srivastava 	/* IMA needs to pass the measurement list to the next kernel. */
2506a31fcd4SPrakhar Srivastava 	ima_add_kexec_buffer(image);
2516a31fcd4SPrakhar Srivastava 
252fb15abdcSBjorn Helgaas 	/* Call image load handler */
253fb15abdcSBjorn Helgaas 	ldata = kexec_image_load_default(image);
254a43cac0dSDave Young 
255a43cac0dSDave Young 	if (IS_ERR(ldata)) {
256a43cac0dSDave Young 		ret = PTR_ERR(ldata);
257a43cac0dSDave Young 		goto out;
258a43cac0dSDave Young 	}
259a43cac0dSDave Young 
260a43cac0dSDave Young 	image->image_loader_data = ldata;
261a43cac0dSDave Young out:
262a43cac0dSDave Young 	/* In case of error, free up all allocated memory in this function */
263a43cac0dSDave Young 	if (ret)
264a43cac0dSDave Young 		kimage_file_post_load_cleanup(image);
265a43cac0dSDave Young 	return ret;
266a43cac0dSDave Young }
267a43cac0dSDave Young 
268a43cac0dSDave Young static int
kimage_file_alloc_init(struct kimage ** rimage,int kernel_fd,int initrd_fd,const char __user * cmdline_ptr,unsigned long cmdline_len,unsigned long flags)269a43cac0dSDave Young kimage_file_alloc_init(struct kimage **rimage, int kernel_fd,
270a43cac0dSDave Young 		       int initrd_fd, const char __user *cmdline_ptr,
271a43cac0dSDave Young 		       unsigned long cmdline_len, unsigned long flags)
272a43cac0dSDave Young {
273a43cac0dSDave Young 	int ret;
274a43cac0dSDave Young 	struct kimage *image;
275a43cac0dSDave Young 	bool kexec_on_panic = flags & KEXEC_FILE_ON_CRASH;
276a43cac0dSDave Young 
277a43cac0dSDave Young 	image = do_kimage_alloc_init();
278a43cac0dSDave Young 	if (!image)
279a43cac0dSDave Young 		return -ENOMEM;
280a43cac0dSDave Young 
281a43cac0dSDave Young 	image->file_mode = 1;
282a43cac0dSDave Young 
283a43cac0dSDave Young 	if (kexec_on_panic) {
284a43cac0dSDave Young 		/* Enable special crash kernel control page alloc policy. */
285a43cac0dSDave Young 		image->control_page = crashk_res.start;
286a43cac0dSDave Young 		image->type = KEXEC_TYPE_CRASH;
287a43cac0dSDave Young 	}
288a43cac0dSDave Young 
289a43cac0dSDave Young 	ret = kimage_file_prepare_segments(image, kernel_fd, initrd_fd,
290a43cac0dSDave Young 					   cmdline_ptr, cmdline_len, flags);
291a43cac0dSDave Young 	if (ret)
292a43cac0dSDave Young 		goto out_free_image;
293a43cac0dSDave Young 
294a43cac0dSDave Young 	ret = sanity_check_segment_list(image);
295a43cac0dSDave Young 	if (ret)
296a43cac0dSDave Young 		goto out_free_post_load_bufs;
297a43cac0dSDave Young 
298a43cac0dSDave Young 	ret = -ENOMEM;
299a43cac0dSDave Young 	image->control_code_page = kimage_alloc_control_pages(image,
300a43cac0dSDave Young 					   get_order(KEXEC_CONTROL_PAGE_SIZE));
301a43cac0dSDave Young 	if (!image->control_code_page) {
302a43cac0dSDave Young 		pr_err("Could not allocate control_code_buffer\n");
303a43cac0dSDave Young 		goto out_free_post_load_bufs;
304a43cac0dSDave Young 	}
305a43cac0dSDave Young 
306a43cac0dSDave Young 	if (!kexec_on_panic) {
307a43cac0dSDave Young 		image->swap_page = kimage_alloc_control_pages(image, 0);
308a43cac0dSDave Young 		if (!image->swap_page) {
309a43cac0dSDave Young 			pr_err("Could not allocate swap buffer\n");
310a43cac0dSDave Young 			goto out_free_control_pages;
311a43cac0dSDave Young 		}
312a43cac0dSDave Young 	}
313a43cac0dSDave Young 
314a43cac0dSDave Young 	*rimage = image;
315a43cac0dSDave Young 	return 0;
316a43cac0dSDave Young out_free_control_pages:
317a43cac0dSDave Young 	kimage_free_page_list(&image->control_pages);
318a43cac0dSDave Young out_free_post_load_bufs:
319a43cac0dSDave Young 	kimage_file_post_load_cleanup(image);
320a43cac0dSDave Young out_free_image:
321a43cac0dSDave Young 	kfree(image);
322a43cac0dSDave Young 	return ret;
323a43cac0dSDave Young }
324a43cac0dSDave Young 
SYSCALL_DEFINE5(kexec_file_load,int,kernel_fd,int,initrd_fd,unsigned long,cmdline_len,const char __user *,cmdline_ptr,unsigned long,flags)325a43cac0dSDave Young SYSCALL_DEFINE5(kexec_file_load, int, kernel_fd, int, initrd_fd,
326a43cac0dSDave Young 		unsigned long, cmdline_len, const char __user *, cmdline_ptr,
327a43cac0dSDave Young 		unsigned long, flags)
328a43cac0dSDave Young {
329a42aaad2SRicardo Ribalda 	int image_type = (flags & KEXEC_FILE_ON_CRASH) ?
330a42aaad2SRicardo Ribalda 			 KEXEC_TYPE_CRASH : KEXEC_TYPE_DEFAULT;
331a43cac0dSDave Young 	struct kimage **dest_image, *image;
332a42aaad2SRicardo Ribalda 	int ret = 0, i;
333a43cac0dSDave Young 
334a43cac0dSDave Young 	/* We only trust the superuser with rebooting the system. */
335a42aaad2SRicardo Ribalda 	if (!kexec_load_permitted(image_type))
336a43cac0dSDave Young 		return -EPERM;
337a43cac0dSDave Young 
338a43cac0dSDave Young 	/* Make sure we have a legal set of flags */
339a43cac0dSDave Young 	if (flags != (flags & KEXEC_FILE_FLAGS))
340a43cac0dSDave Young 		return -EINVAL;
341a43cac0dSDave Young 
342a43cac0dSDave Young 	image = NULL;
343a43cac0dSDave Young 
34405c62574SValentin Schneider 	if (!kexec_trylock())
345a43cac0dSDave Young 		return -EBUSY;
346a43cac0dSDave Young 
347a42aaad2SRicardo Ribalda 	if (image_type == KEXEC_TYPE_CRASH) {
348a43cac0dSDave Young 		dest_image = &kexec_crash_image;
3499b492cf5SXunlei Pang 		if (kexec_crash_image)
3509b492cf5SXunlei Pang 			arch_kexec_unprotect_crashkres();
351a42aaad2SRicardo Ribalda 	} else {
352a42aaad2SRicardo Ribalda 		dest_image = &kexec_image;
3539b492cf5SXunlei Pang 	}
354a43cac0dSDave Young 
355a43cac0dSDave Young 	if (flags & KEXEC_FILE_UNLOAD)
356a43cac0dSDave Young 		goto exchange;
357a43cac0dSDave Young 
358a43cac0dSDave Young 	/*
359a43cac0dSDave Young 	 * In case of crash, new kernel gets loaded in reserved region. It is
360a43cac0dSDave Young 	 * same memory where old crash kernel might be loaded. Free any
361a43cac0dSDave Young 	 * current crash dump kernel before we corrupt it.
362a43cac0dSDave Young 	 */
363a43cac0dSDave Young 	if (flags & KEXEC_FILE_ON_CRASH)
364a43cac0dSDave Young 		kimage_free(xchg(&kexec_crash_image, NULL));
365a43cac0dSDave Young 
366a43cac0dSDave Young 	ret = kimage_file_alloc_init(&image, kernel_fd, initrd_fd, cmdline_ptr,
367a43cac0dSDave Young 				     cmdline_len, flags);
368a43cac0dSDave Young 	if (ret)
369a43cac0dSDave Young 		goto out;
370a43cac0dSDave Young 
371a43cac0dSDave Young 	ret = machine_kexec_prepare(image);
372a43cac0dSDave Young 	if (ret)
373a43cac0dSDave Young 		goto out;
374a43cac0dSDave Young 
3751229384fSXunlei Pang 	/*
3761229384fSXunlei Pang 	 * Some architecture(like S390) may touch the crash memory before
3771229384fSXunlei Pang 	 * machine_kexec_prepare(), we must copy vmcoreinfo data after it.
3781229384fSXunlei Pang 	 */
3791229384fSXunlei Pang 	ret = kimage_crash_copy_vmcoreinfo(image);
3801229384fSXunlei Pang 	if (ret)
3811229384fSXunlei Pang 		goto out;
3821229384fSXunlei Pang 
383a43cac0dSDave Young 	ret = kexec_calculate_store_digests(image);
384a43cac0dSDave Young 	if (ret)
385a43cac0dSDave Young 		goto out;
386a43cac0dSDave Young 
387a43cac0dSDave Young 	for (i = 0; i < image->nr_segments; i++) {
388a43cac0dSDave Young 		struct kexec_segment *ksegment;
389a43cac0dSDave Young 
390a43cac0dSDave Young 		ksegment = &image->segment[i];
391a43cac0dSDave Young 		pr_debug("Loading segment %d: buf=0x%p bufsz=0x%zx mem=0x%lx memsz=0x%zx\n",
392a43cac0dSDave Young 			 i, ksegment->buf, ksegment->bufsz, ksegment->mem,
393a43cac0dSDave Young 			 ksegment->memsz);
394a43cac0dSDave Young 
395a43cac0dSDave Young 		ret = kimage_load_segment(image, &image->segment[i]);
396a43cac0dSDave Young 		if (ret)
397a43cac0dSDave Young 			goto out;
398a43cac0dSDave Young 	}
399a43cac0dSDave Young 
400a43cac0dSDave Young 	kimage_terminate(image);
401a43cac0dSDave Young 
402de68e4daSPavel Tatashin 	ret = machine_kexec_post_load(image);
403de68e4daSPavel Tatashin 	if (ret)
404de68e4daSPavel Tatashin 		goto out;
405de68e4daSPavel Tatashin 
406a43cac0dSDave Young 	/*
407a43cac0dSDave Young 	 * Free up any temporary buffers allocated which are not needed
408a43cac0dSDave Young 	 * after image has been loaded
409a43cac0dSDave Young 	 */
410a43cac0dSDave Young 	kimage_file_post_load_cleanup(image);
411a43cac0dSDave Young exchange:
412a43cac0dSDave Young 	image = xchg(dest_image, image);
413a43cac0dSDave Young out:
4149b492cf5SXunlei Pang 	if ((flags & KEXEC_FILE_ON_CRASH) && kexec_crash_image)
4159b492cf5SXunlei Pang 		arch_kexec_protect_crashkres();
4169b492cf5SXunlei Pang 
41705c62574SValentin Schneider 	kexec_unlock();
418a43cac0dSDave Young 	kimage_free(image);
419a43cac0dSDave Young 	return ret;
420a43cac0dSDave Young }
421a43cac0dSDave Young 
locate_mem_hole_top_down(unsigned long start,unsigned long end,struct kexec_buf * kbuf)422a43cac0dSDave Young static int locate_mem_hole_top_down(unsigned long start, unsigned long end,
423a43cac0dSDave Young 				    struct kexec_buf *kbuf)
424a43cac0dSDave Young {
425a43cac0dSDave Young 	struct kimage *image = kbuf->image;
426a43cac0dSDave Young 	unsigned long temp_start, temp_end;
427a43cac0dSDave Young 
428a43cac0dSDave Young 	temp_end = min(end, kbuf->buf_max);
429a43cac0dSDave Young 	temp_start = temp_end - kbuf->memsz;
430a43cac0dSDave Young 
431a43cac0dSDave Young 	do {
432a43cac0dSDave Young 		/* align down start */
433a43cac0dSDave Young 		temp_start = temp_start & (~(kbuf->buf_align - 1));
434a43cac0dSDave Young 
435a43cac0dSDave Young 		if (temp_start < start || temp_start < kbuf->buf_min)
436a43cac0dSDave Young 			return 0;
437a43cac0dSDave Young 
438a43cac0dSDave Young 		temp_end = temp_start + kbuf->memsz - 1;
439a43cac0dSDave Young 
440a43cac0dSDave Young 		/*
441a43cac0dSDave Young 		 * Make sure this does not conflict with any of existing
442a43cac0dSDave Young 		 * segments
443a43cac0dSDave Young 		 */
444a43cac0dSDave Young 		if (kimage_is_destination_range(image, temp_start, temp_end)) {
445a43cac0dSDave Young 			temp_start = temp_start - PAGE_SIZE;
446a43cac0dSDave Young 			continue;
447a43cac0dSDave Young 		}
448a43cac0dSDave Young 
449a43cac0dSDave Young 		/* We found a suitable memory range */
450a43cac0dSDave Young 		break;
451a43cac0dSDave Young 	} while (1);
452a43cac0dSDave Young 
453a43cac0dSDave Young 	/* If we are here, we found a suitable memory range */
454a43cac0dSDave Young 	kbuf->mem = temp_start;
455a43cac0dSDave Young 
456a43cac0dSDave Young 	/* Success, stop navigating through remaining System RAM ranges */
457a43cac0dSDave Young 	return 1;
458a43cac0dSDave Young }
459a43cac0dSDave Young 
locate_mem_hole_bottom_up(unsigned long start,unsigned long end,struct kexec_buf * kbuf)460a43cac0dSDave Young static int locate_mem_hole_bottom_up(unsigned long start, unsigned long end,
461a43cac0dSDave Young 				     struct kexec_buf *kbuf)
462a43cac0dSDave Young {
463a43cac0dSDave Young 	struct kimage *image = kbuf->image;
464a43cac0dSDave Young 	unsigned long temp_start, temp_end;
465a43cac0dSDave Young 
466a43cac0dSDave Young 	temp_start = max(start, kbuf->buf_min);
467a43cac0dSDave Young 
468a43cac0dSDave Young 	do {
469a43cac0dSDave Young 		temp_start = ALIGN(temp_start, kbuf->buf_align);
470a43cac0dSDave Young 		temp_end = temp_start + kbuf->memsz - 1;
471a43cac0dSDave Young 
472a43cac0dSDave Young 		if (temp_end > end || temp_end > kbuf->buf_max)
473a43cac0dSDave Young 			return 0;
474a43cac0dSDave Young 		/*
475a43cac0dSDave Young 		 * Make sure this does not conflict with any of existing
476a43cac0dSDave Young 		 * segments
477a43cac0dSDave Young 		 */
478a43cac0dSDave Young 		if (kimage_is_destination_range(image, temp_start, temp_end)) {
479a43cac0dSDave Young 			temp_start = temp_start + PAGE_SIZE;
480a43cac0dSDave Young 			continue;
481a43cac0dSDave Young 		}
482a43cac0dSDave Young 
483a43cac0dSDave Young 		/* We found a suitable memory range */
484a43cac0dSDave Young 		break;
485a43cac0dSDave Young 	} while (1);
486a43cac0dSDave Young 
487a43cac0dSDave Young 	/* If we are here, we found a suitable memory range */
488a43cac0dSDave Young 	kbuf->mem = temp_start;
489a43cac0dSDave Young 
490a43cac0dSDave Young 	/* Success, stop navigating through remaining System RAM ranges */
491a43cac0dSDave Young 	return 1;
492a43cac0dSDave Young }
493a43cac0dSDave Young 
locate_mem_hole_callback(struct resource * res,void * arg)4941d2e733bSTom Lendacky static int locate_mem_hole_callback(struct resource *res, void *arg)
495a43cac0dSDave Young {
496a43cac0dSDave Young 	struct kexec_buf *kbuf = (struct kexec_buf *)arg;
4971d2e733bSTom Lendacky 	u64 start = res->start, end = res->end;
498a43cac0dSDave Young 	unsigned long sz = end - start + 1;
499a43cac0dSDave Young 
500a43cac0dSDave Young 	/* Returning 0 will take to next memory range */
5013fe4f499SDavid Hildenbrand 
5023fe4f499SDavid Hildenbrand 	/* Don't use memory that will be detected and handled by a driver. */
5037cf603d1SDavid Hildenbrand 	if (res->flags & IORESOURCE_SYSRAM_DRIVER_MANAGED)
5043fe4f499SDavid Hildenbrand 		return 0;
5053fe4f499SDavid Hildenbrand 
506a43cac0dSDave Young 	if (sz < kbuf->memsz)
507a43cac0dSDave Young 		return 0;
508a43cac0dSDave Young 
509a43cac0dSDave Young 	if (end < kbuf->buf_min || start > kbuf->buf_max)
510a43cac0dSDave Young 		return 0;
511a43cac0dSDave Young 
512a43cac0dSDave Young 	/*
513a43cac0dSDave Young 	 * Allocate memory top down with-in ram range. Otherwise bottom up
514a43cac0dSDave Young 	 * allocation.
515a43cac0dSDave Young 	 */
516a43cac0dSDave Young 	if (kbuf->top_down)
517a43cac0dSDave Young 		return locate_mem_hole_top_down(start, end, kbuf);
518a43cac0dSDave Young 	return locate_mem_hole_bottom_up(start, end, kbuf);
519a43cac0dSDave Young }
520a43cac0dSDave Young 
521350e88baSMike Rapoport #ifdef CONFIG_ARCH_KEEP_MEMBLOCK
kexec_walk_memblock(struct kexec_buf * kbuf,int (* func)(struct resource *,void *))522735c2f90SAKASHI Takahiro static int kexec_walk_memblock(struct kexec_buf *kbuf,
523735c2f90SAKASHI Takahiro 			       int (*func)(struct resource *, void *))
524735c2f90SAKASHI Takahiro {
525735c2f90SAKASHI Takahiro 	int ret = 0;
526735c2f90SAKASHI Takahiro 	u64 i;
527735c2f90SAKASHI Takahiro 	phys_addr_t mstart, mend;
528735c2f90SAKASHI Takahiro 	struct resource res = { };
529735c2f90SAKASHI Takahiro 
530497e1858SAKASHI Takahiro 	if (kbuf->image->type == KEXEC_TYPE_CRASH)
531497e1858SAKASHI Takahiro 		return func(&crashk_res, kbuf);
532497e1858SAKASHI Takahiro 
533f7892d8eSDavid Hildenbrand 	/*
534f7892d8eSDavid Hildenbrand 	 * Using MEMBLOCK_NONE will properly skip MEMBLOCK_DRIVER_MANAGED. See
535f7892d8eSDavid Hildenbrand 	 * IORESOURCE_SYSRAM_DRIVER_MANAGED handling in
536f7892d8eSDavid Hildenbrand 	 * locate_mem_hole_callback().
537f7892d8eSDavid Hildenbrand 	 */
538735c2f90SAKASHI Takahiro 	if (kbuf->top_down) {
539497e1858SAKASHI Takahiro 		for_each_free_mem_range_reverse(i, NUMA_NO_NODE, MEMBLOCK_NONE,
540735c2f90SAKASHI Takahiro 						&mstart, &mend, NULL) {
541735c2f90SAKASHI Takahiro 			/*
542735c2f90SAKASHI Takahiro 			 * In memblock, end points to the first byte after the
543735c2f90SAKASHI Takahiro 			 * range while in kexec, end points to the last byte
544735c2f90SAKASHI Takahiro 			 * in the range.
545735c2f90SAKASHI Takahiro 			 */
546735c2f90SAKASHI Takahiro 			res.start = mstart;
547735c2f90SAKASHI Takahiro 			res.end = mend - 1;
548735c2f90SAKASHI Takahiro 			ret = func(&res, kbuf);
549735c2f90SAKASHI Takahiro 			if (ret)
550735c2f90SAKASHI Takahiro 				break;
551735c2f90SAKASHI Takahiro 		}
552735c2f90SAKASHI Takahiro 	} else {
553497e1858SAKASHI Takahiro 		for_each_free_mem_range(i, NUMA_NO_NODE, MEMBLOCK_NONE,
554497e1858SAKASHI Takahiro 					&mstart, &mend, NULL) {
555735c2f90SAKASHI Takahiro 			/*
556735c2f90SAKASHI Takahiro 			 * In memblock, end points to the first byte after the
557735c2f90SAKASHI Takahiro 			 * range while in kexec, end points to the last byte
558735c2f90SAKASHI Takahiro 			 * in the range.
559735c2f90SAKASHI Takahiro 			 */
560735c2f90SAKASHI Takahiro 			res.start = mstart;
561735c2f90SAKASHI Takahiro 			res.end = mend - 1;
562735c2f90SAKASHI Takahiro 			ret = func(&res, kbuf);
563735c2f90SAKASHI Takahiro 			if (ret)
564735c2f90SAKASHI Takahiro 				break;
565735c2f90SAKASHI Takahiro 		}
566735c2f90SAKASHI Takahiro 	}
567735c2f90SAKASHI Takahiro 
568735c2f90SAKASHI Takahiro 	return ret;
569735c2f90SAKASHI Takahiro }
570350e88baSMike Rapoport #else
kexec_walk_memblock(struct kexec_buf * kbuf,int (* func)(struct resource *,void *))571350e88baSMike Rapoport static int kexec_walk_memblock(struct kexec_buf *kbuf,
572350e88baSMike Rapoport 			       int (*func)(struct resource *, void *))
573350e88baSMike Rapoport {
574350e88baSMike Rapoport 	return 0;
575350e88baSMike Rapoport }
576735c2f90SAKASHI Takahiro #endif
577735c2f90SAKASHI Takahiro 
57860fe3910SThiago Jung Bauermann /**
579735c2f90SAKASHI Takahiro  * kexec_walk_resources - call func(data) on free memory regions
58060fe3910SThiago Jung Bauermann  * @kbuf:	Context info for the search. Also passed to @func.
58160fe3910SThiago Jung Bauermann  * @func:	Function to call for each memory region.
58260fe3910SThiago Jung Bauermann  *
58360fe3910SThiago Jung Bauermann  * Return: The memory walk will stop when func returns a non-zero value
58460fe3910SThiago Jung Bauermann  * and that value will be returned. If all free regions are visited without
58560fe3910SThiago Jung Bauermann  * func returning non-zero, then zero will be returned.
58660fe3910SThiago Jung Bauermann  */
kexec_walk_resources(struct kexec_buf * kbuf,int (* func)(struct resource *,void *))587735c2f90SAKASHI Takahiro static int kexec_walk_resources(struct kexec_buf *kbuf,
5881d2e733bSTom Lendacky 				int (*func)(struct resource *, void *))
58960fe3910SThiago Jung Bauermann {
59060fe3910SThiago Jung Bauermann 	if (kbuf->image->type == KEXEC_TYPE_CRASH)
59160fe3910SThiago Jung Bauermann 		return walk_iomem_res_desc(crashk_res.desc,
59260fe3910SThiago Jung Bauermann 					   IORESOURCE_SYSTEM_RAM | IORESOURCE_BUSY,
59360fe3910SThiago Jung Bauermann 					   crashk_res.start, crashk_res.end,
59460fe3910SThiago Jung Bauermann 					   kbuf, func);
59560fe3910SThiago Jung Bauermann 	else
59660fe3910SThiago Jung Bauermann 		return walk_system_ram_res(0, ULONG_MAX, kbuf, func);
59760fe3910SThiago Jung Bauermann }
59860fe3910SThiago Jung Bauermann 
599ec2b9bfaSThiago Jung Bauermann /**
600e2e806f9SThiago Jung Bauermann  * kexec_locate_mem_hole - find free memory for the purgatory or the next kernel
601e2e806f9SThiago Jung Bauermann  * @kbuf:	Parameters for the memory search.
602e2e806f9SThiago Jung Bauermann  *
603e2e806f9SThiago Jung Bauermann  * On success, kbuf->mem will have the start address of the memory region found.
604e2e806f9SThiago Jung Bauermann  *
605e2e806f9SThiago Jung Bauermann  * Return: 0 on success, negative errno on error.
606e2e806f9SThiago Jung Bauermann  */
kexec_locate_mem_hole(struct kexec_buf * kbuf)607e2e806f9SThiago Jung Bauermann int kexec_locate_mem_hole(struct kexec_buf *kbuf)
608e2e806f9SThiago Jung Bauermann {
609e2e806f9SThiago Jung Bauermann 	int ret;
610e2e806f9SThiago Jung Bauermann 
611b6664ba4SAKASHI Takahiro 	/* Arch knows where to place */
612b6664ba4SAKASHI Takahiro 	if (kbuf->mem != KEXEC_BUF_MEM_UNKNOWN)
613b6664ba4SAKASHI Takahiro 		return 0;
614b6664ba4SAKASHI Takahiro 
615350e88baSMike Rapoport 	if (!IS_ENABLED(CONFIG_ARCH_KEEP_MEMBLOCK))
616735c2f90SAKASHI Takahiro 		ret = kexec_walk_resources(kbuf, locate_mem_hole_callback);
617735c2f90SAKASHI Takahiro 	else
618735c2f90SAKASHI Takahiro 		ret = kexec_walk_memblock(kbuf, locate_mem_hole_callback);
619e2e806f9SThiago Jung Bauermann 
620e2e806f9SThiago Jung Bauermann 	return ret == 1 ? 0 : -EADDRNOTAVAIL;
621e2e806f9SThiago Jung Bauermann }
622e2e806f9SThiago Jung Bauermann 
623e2e806f9SThiago Jung Bauermann /**
624ec2b9bfaSThiago Jung Bauermann  * kexec_add_buffer - place a buffer in a kexec segment
625ec2b9bfaSThiago Jung Bauermann  * @kbuf:	Buffer contents and memory parameters.
626ec2b9bfaSThiago Jung Bauermann  *
62755e2b696SWenyu Liu  * This function assumes that kexec_lock is held.
628ec2b9bfaSThiago Jung Bauermann  * On successful return, @kbuf->mem will have the physical address of
629ec2b9bfaSThiago Jung Bauermann  * the buffer in memory.
630ec2b9bfaSThiago Jung Bauermann  *
631ec2b9bfaSThiago Jung Bauermann  * Return: 0 on success, negative errno on error.
632a43cac0dSDave Young  */
kexec_add_buffer(struct kexec_buf * kbuf)633ec2b9bfaSThiago Jung Bauermann int kexec_add_buffer(struct kexec_buf *kbuf)
634a43cac0dSDave Young {
635a43cac0dSDave Young 	struct kexec_segment *ksegment;
636a43cac0dSDave Young 	int ret;
637a43cac0dSDave Young 
638a43cac0dSDave Young 	/* Currently adding segment this way is allowed only in file mode */
639ec2b9bfaSThiago Jung Bauermann 	if (!kbuf->image->file_mode)
640a43cac0dSDave Young 		return -EINVAL;
641a43cac0dSDave Young 
642ec2b9bfaSThiago Jung Bauermann 	if (kbuf->image->nr_segments >= KEXEC_SEGMENT_MAX)
643a43cac0dSDave Young 		return -EINVAL;
644a43cac0dSDave Young 
645a43cac0dSDave Young 	/*
646a43cac0dSDave Young 	 * Make sure we are not trying to add buffer after allocating
647a43cac0dSDave Young 	 * control pages. All segments need to be placed first before
648a43cac0dSDave Young 	 * any control pages are allocated. As control page allocation
649a43cac0dSDave Young 	 * logic goes through list of segments to make sure there are
650a43cac0dSDave Young 	 * no destination overlaps.
651a43cac0dSDave Young 	 */
652ec2b9bfaSThiago Jung Bauermann 	if (!list_empty(&kbuf->image->control_pages)) {
653a43cac0dSDave Young 		WARN_ON(1);
654a43cac0dSDave Young 		return -EINVAL;
655a43cac0dSDave Young 	}
656a43cac0dSDave Young 
657ec2b9bfaSThiago Jung Bauermann 	/* Ensure minimum alignment needed for segments. */
658ec2b9bfaSThiago Jung Bauermann 	kbuf->memsz = ALIGN(kbuf->memsz, PAGE_SIZE);
659ec2b9bfaSThiago Jung Bauermann 	kbuf->buf_align = max(kbuf->buf_align, PAGE_SIZE);
660a43cac0dSDave Young 
661a43cac0dSDave Young 	/* Walk the RAM ranges and allocate a suitable range for the buffer */
662f891f197SHari Bathini 	ret = arch_kexec_locate_mem_hole(kbuf);
663e2e806f9SThiago Jung Bauermann 	if (ret)
664e2e806f9SThiago Jung Bauermann 		return ret;
665a43cac0dSDave Young 
666a43cac0dSDave Young 	/* Found a suitable memory range */
667ec2b9bfaSThiago Jung Bauermann 	ksegment = &kbuf->image->segment[kbuf->image->nr_segments];
668a43cac0dSDave Young 	ksegment->kbuf = kbuf->buffer;
669a43cac0dSDave Young 	ksegment->bufsz = kbuf->bufsz;
670a43cac0dSDave Young 	ksegment->mem = kbuf->mem;
671a43cac0dSDave Young 	ksegment->memsz = kbuf->memsz;
672ec2b9bfaSThiago Jung Bauermann 	kbuf->image->nr_segments++;
673a43cac0dSDave Young 	return 0;
674a43cac0dSDave Young }
675a43cac0dSDave Young 
676a43cac0dSDave Young /* Calculate and store the digest of segments */
kexec_calculate_store_digests(struct kimage * image)677a43cac0dSDave Young static int kexec_calculate_store_digests(struct kimage *image)
678a43cac0dSDave Young {
679a43cac0dSDave Young 	struct crypto_shash *tfm;
680a43cac0dSDave Young 	struct shash_desc *desc;
681a43cac0dSDave Young 	int ret = 0, i, j, zero_buf_sz, sha_region_sz;
682a43cac0dSDave Young 	size_t desc_size, nullsz;
683a43cac0dSDave Young 	char *digest;
684a43cac0dSDave Young 	void *zero_buf;
685a43cac0dSDave Young 	struct kexec_sha_region *sha_regions;
686a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
687a43cac0dSDave Young 
688e6265fe7SEric DeVolder 	if (!IS_ENABLED(CONFIG_ARCH_SUPPORTS_KEXEC_PURGATORY))
689b799a09fSAKASHI Takahiro 		return 0;
690b799a09fSAKASHI Takahiro 
691a43cac0dSDave Young 	zero_buf = __va(page_to_pfn(ZERO_PAGE(0)) << PAGE_SHIFT);
692a43cac0dSDave Young 	zero_buf_sz = PAGE_SIZE;
693a43cac0dSDave Young 
694a43cac0dSDave Young 	tfm = crypto_alloc_shash("sha256", 0, 0);
695a43cac0dSDave Young 	if (IS_ERR(tfm)) {
696a43cac0dSDave Young 		ret = PTR_ERR(tfm);
697a43cac0dSDave Young 		goto out;
698a43cac0dSDave Young 	}
699a43cac0dSDave Young 
700a43cac0dSDave Young 	desc_size = crypto_shash_descsize(tfm) + sizeof(*desc);
701a43cac0dSDave Young 	desc = kzalloc(desc_size, GFP_KERNEL);
702a43cac0dSDave Young 	if (!desc) {
703a43cac0dSDave Young 		ret = -ENOMEM;
704a43cac0dSDave Young 		goto out_free_tfm;
705a43cac0dSDave Young 	}
706a43cac0dSDave Young 
707a43cac0dSDave Young 	sha_region_sz = KEXEC_SEGMENT_MAX * sizeof(struct kexec_sha_region);
708a43cac0dSDave Young 	sha_regions = vzalloc(sha_region_sz);
70931d82c2cSJia-Ju Bai 	if (!sha_regions) {
71031d82c2cSJia-Ju Bai 		ret = -ENOMEM;
711a43cac0dSDave Young 		goto out_free_desc;
71231d82c2cSJia-Ju Bai 	}
713a43cac0dSDave Young 
714a43cac0dSDave Young 	desc->tfm   = tfm;
715a43cac0dSDave Young 
716a43cac0dSDave Young 	ret = crypto_shash_init(desc);
717a43cac0dSDave Young 	if (ret < 0)
718a43cac0dSDave Young 		goto out_free_sha_regions;
719a43cac0dSDave Young 
720a43cac0dSDave Young 	digest = kzalloc(SHA256_DIGEST_SIZE, GFP_KERNEL);
721a43cac0dSDave Young 	if (!digest) {
722a43cac0dSDave Young 		ret = -ENOMEM;
723a43cac0dSDave Young 		goto out_free_sha_regions;
724a43cac0dSDave Young 	}
725a43cac0dSDave Young 
726a43cac0dSDave Young 	for (j = i = 0; i < image->nr_segments; i++) {
727a43cac0dSDave Young 		struct kexec_segment *ksegment;
728a43cac0dSDave Young 
729f7cc804aSEric DeVolder #ifdef CONFIG_CRASH_HOTPLUG
730f7cc804aSEric DeVolder 		/* Exclude elfcorehdr segment to allow future changes via hotplug */
731*c318a4bbSPetr Tesarik 		if (i == image->elfcorehdr_index)
732f7cc804aSEric DeVolder 			continue;
733f7cc804aSEric DeVolder #endif
734f7cc804aSEric DeVolder 
735a43cac0dSDave Young 		ksegment = &image->segment[i];
736a43cac0dSDave Young 		/*
737a43cac0dSDave Young 		 * Skip purgatory as it will be modified once we put digest
738a43cac0dSDave Young 		 * info in purgatory.
739a43cac0dSDave Young 		 */
740a43cac0dSDave Young 		if (ksegment->kbuf == pi->purgatory_buf)
741a43cac0dSDave Young 			continue;
742a43cac0dSDave Young 
743a43cac0dSDave Young 		ret = crypto_shash_update(desc, ksegment->kbuf,
744a43cac0dSDave Young 					  ksegment->bufsz);
745a43cac0dSDave Young 		if (ret)
746a43cac0dSDave Young 			break;
747a43cac0dSDave Young 
748a43cac0dSDave Young 		/*
749a43cac0dSDave Young 		 * Assume rest of the buffer is filled with zero and
750a43cac0dSDave Young 		 * update digest accordingly.
751a43cac0dSDave Young 		 */
752a43cac0dSDave Young 		nullsz = ksegment->memsz - ksegment->bufsz;
753a43cac0dSDave Young 		while (nullsz) {
754a43cac0dSDave Young 			unsigned long bytes = nullsz;
755a43cac0dSDave Young 
756a43cac0dSDave Young 			if (bytes > zero_buf_sz)
757a43cac0dSDave Young 				bytes = zero_buf_sz;
758a43cac0dSDave Young 			ret = crypto_shash_update(desc, zero_buf, bytes);
759a43cac0dSDave Young 			if (ret)
760a43cac0dSDave Young 				break;
761a43cac0dSDave Young 			nullsz -= bytes;
762a43cac0dSDave Young 		}
763a43cac0dSDave Young 
764a43cac0dSDave Young 		if (ret)
765a43cac0dSDave Young 			break;
766a43cac0dSDave Young 
767a43cac0dSDave Young 		sha_regions[j].start = ksegment->mem;
768a43cac0dSDave Young 		sha_regions[j].len = ksegment->memsz;
769a43cac0dSDave Young 		j++;
770a43cac0dSDave Young 	}
771a43cac0dSDave Young 
772a43cac0dSDave Young 	if (!ret) {
773a43cac0dSDave Young 		ret = crypto_shash_final(desc, digest);
774a43cac0dSDave Young 		if (ret)
775a43cac0dSDave Young 			goto out_free_digest;
77640c50c1fSThomas Gleixner 		ret = kexec_purgatory_get_set_symbol(image, "purgatory_sha_regions",
777a43cac0dSDave Young 						     sha_regions, sha_region_sz, 0);
778a43cac0dSDave Young 		if (ret)
779a43cac0dSDave Young 			goto out_free_digest;
780a43cac0dSDave Young 
78140c50c1fSThomas Gleixner 		ret = kexec_purgatory_get_set_symbol(image, "purgatory_sha256_digest",
782a43cac0dSDave Young 						     digest, SHA256_DIGEST_SIZE, 0);
783a43cac0dSDave Young 		if (ret)
784a43cac0dSDave Young 			goto out_free_digest;
785a43cac0dSDave Young 	}
786a43cac0dSDave Young 
787a43cac0dSDave Young out_free_digest:
788a43cac0dSDave Young 	kfree(digest);
789a43cac0dSDave Young out_free_sha_regions:
790a43cac0dSDave Young 	vfree(sha_regions);
791a43cac0dSDave Young out_free_desc:
792a43cac0dSDave Young 	kfree(desc);
793a43cac0dSDave Young out_free_tfm:
794a43cac0dSDave Young 	kfree(tfm);
795a43cac0dSDave Young out:
796a43cac0dSDave Young 	return ret;
797a43cac0dSDave Young }
798a43cac0dSDave Young 
799e6265fe7SEric DeVolder #ifdef CONFIG_ARCH_SUPPORTS_KEXEC_PURGATORY
80093045705SPhilipp Rudo /*
80193045705SPhilipp Rudo  * kexec_purgatory_setup_kbuf - prepare buffer to load purgatory.
80293045705SPhilipp Rudo  * @pi:		Purgatory to be loaded.
80393045705SPhilipp Rudo  * @kbuf:	Buffer to setup.
80493045705SPhilipp Rudo  *
80593045705SPhilipp Rudo  * Allocates the memory needed for the buffer. Caller is responsible to free
80693045705SPhilipp Rudo  * the memory after use.
80793045705SPhilipp Rudo  *
80893045705SPhilipp Rudo  * Return: 0 on success, negative errno on error.
80993045705SPhilipp Rudo  */
kexec_purgatory_setup_kbuf(struct purgatory_info * pi,struct kexec_buf * kbuf)81093045705SPhilipp Rudo static int kexec_purgatory_setup_kbuf(struct purgatory_info *pi,
81193045705SPhilipp Rudo 				      struct kexec_buf *kbuf)
812a43cac0dSDave Young {
81393045705SPhilipp Rudo 	const Elf_Shdr *sechdrs;
81493045705SPhilipp Rudo 	unsigned long bss_align;
81593045705SPhilipp Rudo 	unsigned long bss_sz;
81693045705SPhilipp Rudo 	unsigned long align;
81793045705SPhilipp Rudo 	int i, ret;
81893045705SPhilipp Rudo 
81993045705SPhilipp Rudo 	sechdrs = (void *)pi->ehdr + pi->ehdr->e_shoff;
8203be3f61dSPhilipp Rudo 	kbuf->buf_align = bss_align = 1;
8213be3f61dSPhilipp Rudo 	kbuf->bufsz = bss_sz = 0;
82293045705SPhilipp Rudo 
82393045705SPhilipp Rudo 	for (i = 0; i < pi->ehdr->e_shnum; i++) {
82493045705SPhilipp Rudo 		if (!(sechdrs[i].sh_flags & SHF_ALLOC))
82593045705SPhilipp Rudo 			continue;
82693045705SPhilipp Rudo 
82793045705SPhilipp Rudo 		align = sechdrs[i].sh_addralign;
82893045705SPhilipp Rudo 		if (sechdrs[i].sh_type != SHT_NOBITS) {
82993045705SPhilipp Rudo 			if (kbuf->buf_align < align)
83093045705SPhilipp Rudo 				kbuf->buf_align = align;
83193045705SPhilipp Rudo 			kbuf->bufsz = ALIGN(kbuf->bufsz, align);
83293045705SPhilipp Rudo 			kbuf->bufsz += sechdrs[i].sh_size;
83393045705SPhilipp Rudo 		} else {
83493045705SPhilipp Rudo 			if (bss_align < align)
83593045705SPhilipp Rudo 				bss_align = align;
83693045705SPhilipp Rudo 			bss_sz = ALIGN(bss_sz, align);
83793045705SPhilipp Rudo 			bss_sz += sechdrs[i].sh_size;
83893045705SPhilipp Rudo 		}
83993045705SPhilipp Rudo 	}
84093045705SPhilipp Rudo 	kbuf->bufsz = ALIGN(kbuf->bufsz, bss_align);
84193045705SPhilipp Rudo 	kbuf->memsz = kbuf->bufsz + bss_sz;
84293045705SPhilipp Rudo 	if (kbuf->buf_align < bss_align)
84393045705SPhilipp Rudo 		kbuf->buf_align = bss_align;
84493045705SPhilipp Rudo 
84593045705SPhilipp Rudo 	kbuf->buffer = vzalloc(kbuf->bufsz);
84693045705SPhilipp Rudo 	if (!kbuf->buffer)
84793045705SPhilipp Rudo 		return -ENOMEM;
84893045705SPhilipp Rudo 	pi->purgatory_buf = kbuf->buffer;
84993045705SPhilipp Rudo 
85093045705SPhilipp Rudo 	ret = kexec_add_buffer(kbuf);
85193045705SPhilipp Rudo 	if (ret)
85293045705SPhilipp Rudo 		goto out;
85393045705SPhilipp Rudo 
85493045705SPhilipp Rudo 	return 0;
85593045705SPhilipp Rudo out:
85693045705SPhilipp Rudo 	vfree(pi->purgatory_buf);
85793045705SPhilipp Rudo 	pi->purgatory_buf = NULL;
85893045705SPhilipp Rudo 	return ret;
85993045705SPhilipp Rudo }
860a43cac0dSDave Young 
861a43cac0dSDave Young /*
86293045705SPhilipp Rudo  * kexec_purgatory_setup_sechdrs - prepares the pi->sechdrs buffer.
86393045705SPhilipp Rudo  * @pi:		Purgatory to be loaded.
86493045705SPhilipp Rudo  * @kbuf:	Buffer prepared to store purgatory.
86593045705SPhilipp Rudo  *
86693045705SPhilipp Rudo  * Allocates the memory needed for the buffer. Caller is responsible to free
86793045705SPhilipp Rudo  * the memory after use.
86893045705SPhilipp Rudo  *
86993045705SPhilipp Rudo  * Return: 0 on success, negative errno on error.
870a43cac0dSDave Young  */
kexec_purgatory_setup_sechdrs(struct purgatory_info * pi,struct kexec_buf * kbuf)87193045705SPhilipp Rudo static int kexec_purgatory_setup_sechdrs(struct purgatory_info *pi,
87293045705SPhilipp Rudo 					 struct kexec_buf *kbuf)
87393045705SPhilipp Rudo {
87493045705SPhilipp Rudo 	unsigned long bss_addr;
87593045705SPhilipp Rudo 	unsigned long offset;
8764df3504eSSimon Horman 	size_t sechdrs_size;
87793045705SPhilipp Rudo 	Elf_Shdr *sechdrs;
87893045705SPhilipp Rudo 	int i;
879a43cac0dSDave Young 
8808da0b724SPhilipp Rudo 	/*
8818da0b724SPhilipp Rudo 	 * The section headers in kexec_purgatory are read-only. In order to
8828da0b724SPhilipp Rudo 	 * have them modifiable make a temporary copy.
8838da0b724SPhilipp Rudo 	 */
8844df3504eSSimon Horman 	sechdrs_size = array_size(sizeof(Elf_Shdr), pi->ehdr->e_shnum);
8854df3504eSSimon Horman 	sechdrs = vzalloc(sechdrs_size);
886a43cac0dSDave Young 	if (!sechdrs)
887a43cac0dSDave Young 		return -ENOMEM;
8884df3504eSSimon Horman 	memcpy(sechdrs, (void *)pi->ehdr + pi->ehdr->e_shoff, sechdrs_size);
88993045705SPhilipp Rudo 	pi->sechdrs = sechdrs;
890a43cac0dSDave Young 
891620f697cSPhilipp Rudo 	offset = 0;
892620f697cSPhilipp Rudo 	bss_addr = kbuf->mem + kbuf->bufsz;
893f1b1cca3SPhilipp Rudo 	kbuf->image->start = pi->ehdr->e_entry;
894a43cac0dSDave Young 
895a43cac0dSDave Young 	for (i = 0; i < pi->ehdr->e_shnum; i++) {
89693045705SPhilipp Rudo 		unsigned long align;
897620f697cSPhilipp Rudo 		void *src, *dst;
89893045705SPhilipp Rudo 
899a43cac0dSDave Young 		if (!(sechdrs[i].sh_flags & SHF_ALLOC))
900a43cac0dSDave Young 			continue;
901a43cac0dSDave Young 
902a43cac0dSDave Young 		align = sechdrs[i].sh_addralign;
903f1b1cca3SPhilipp Rudo 		if (sechdrs[i].sh_type == SHT_NOBITS) {
904f1b1cca3SPhilipp Rudo 			bss_addr = ALIGN(bss_addr, align);
905f1b1cca3SPhilipp Rudo 			sechdrs[i].sh_addr = bss_addr;
906f1b1cca3SPhilipp Rudo 			bss_addr += sechdrs[i].sh_size;
907f1b1cca3SPhilipp Rudo 			continue;
908f1b1cca3SPhilipp Rudo 		}
909f1b1cca3SPhilipp Rudo 
910620f697cSPhilipp Rudo 		offset = ALIGN(offset, align);
9118652d44fSRicardo Ribalda 
9128652d44fSRicardo Ribalda 		/*
9138652d44fSRicardo Ribalda 		 * Check if the segment contains the entry point, if so,
9148652d44fSRicardo Ribalda 		 * calculate the value of image->start based on it.
9158652d44fSRicardo Ribalda 		 * If the compiler has produced more than one .text section
9168652d44fSRicardo Ribalda 		 * (Eg: .text.hot), they are generally after the main .text
9178652d44fSRicardo Ribalda 		 * section, and they shall not be used to calculate
9188652d44fSRicardo Ribalda 		 * image->start. So do not re-calculate image->start if it
9198652d44fSRicardo Ribalda 		 * is not set to the initial value, and warn the user so they
9208652d44fSRicardo Ribalda 		 * have a chance to fix their purgatory's linker script.
9218652d44fSRicardo Ribalda 		 */
922f1b1cca3SPhilipp Rudo 		if (sechdrs[i].sh_flags & SHF_EXECINSTR &&
923f1b1cca3SPhilipp Rudo 		    pi->ehdr->e_entry >= sechdrs[i].sh_addr &&
924f1b1cca3SPhilipp Rudo 		    pi->ehdr->e_entry < (sechdrs[i].sh_addr
9258652d44fSRicardo Ribalda 					 + sechdrs[i].sh_size) &&
9268652d44fSRicardo Ribalda 		    !WARN_ON(kbuf->image->start != pi->ehdr->e_entry)) {
927f1b1cca3SPhilipp Rudo 			kbuf->image->start -= sechdrs[i].sh_addr;
928620f697cSPhilipp Rudo 			kbuf->image->start += kbuf->mem + offset;
929f1b1cca3SPhilipp Rudo 		}
930f1b1cca3SPhilipp Rudo 
9318da0b724SPhilipp Rudo 		src = (void *)pi->ehdr + sechdrs[i].sh_offset;
932620f697cSPhilipp Rudo 		dst = pi->purgatory_buf + offset;
933620f697cSPhilipp Rudo 		memcpy(dst, src, sechdrs[i].sh_size);
934620f697cSPhilipp Rudo 
935620f697cSPhilipp Rudo 		sechdrs[i].sh_addr = kbuf->mem + offset;
9368da0b724SPhilipp Rudo 		sechdrs[i].sh_offset = offset;
937620f697cSPhilipp Rudo 		offset += sechdrs[i].sh_size;
938a43cac0dSDave Young 	}
939a43cac0dSDave Young 
94093045705SPhilipp Rudo 	return 0;
941a43cac0dSDave Young }
942a43cac0dSDave Young 
kexec_apply_relocations(struct kimage * image)943a43cac0dSDave Young static int kexec_apply_relocations(struct kimage *image)
944a43cac0dSDave Young {
945a43cac0dSDave Young 	int i, ret;
946a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
9478aec395bSPhilipp Rudo 	const Elf_Shdr *sechdrs;
948a43cac0dSDave Young 
9498aec395bSPhilipp Rudo 	sechdrs = (void *)pi->ehdr + pi->ehdr->e_shoff;
9508aec395bSPhilipp Rudo 
951a43cac0dSDave Young 	for (i = 0; i < pi->ehdr->e_shnum; i++) {
9528aec395bSPhilipp Rudo 		const Elf_Shdr *relsec;
9538aec395bSPhilipp Rudo 		const Elf_Shdr *symtab;
9548aec395bSPhilipp Rudo 		Elf_Shdr *section;
955a43cac0dSDave Young 
9568aec395bSPhilipp Rudo 		relsec = sechdrs + i;
9578aec395bSPhilipp Rudo 
9588aec395bSPhilipp Rudo 		if (relsec->sh_type != SHT_RELA &&
9598aec395bSPhilipp Rudo 		    relsec->sh_type != SHT_REL)
960a43cac0dSDave Young 			continue;
961a43cac0dSDave Young 
962a43cac0dSDave Young 		/*
963a43cac0dSDave Young 		 * For section of type SHT_RELA/SHT_REL,
964a43cac0dSDave Young 		 * ->sh_link contains section header index of associated
965a43cac0dSDave Young 		 * symbol table. And ->sh_info contains section header
966a43cac0dSDave Young 		 * index of section to which relocations apply.
967a43cac0dSDave Young 		 */
9688aec395bSPhilipp Rudo 		if (relsec->sh_info >= pi->ehdr->e_shnum ||
9698aec395bSPhilipp Rudo 		    relsec->sh_link >= pi->ehdr->e_shnum)
970a43cac0dSDave Young 			return -ENOEXEC;
971a43cac0dSDave Young 
9728aec395bSPhilipp Rudo 		section = pi->sechdrs + relsec->sh_info;
9738aec395bSPhilipp Rudo 		symtab = sechdrs + relsec->sh_link;
974a43cac0dSDave Young 
975a43cac0dSDave Young 		if (!(section->sh_flags & SHF_ALLOC))
976a43cac0dSDave Young 			continue;
977a43cac0dSDave Young 
978a43cac0dSDave Young 		/*
979a43cac0dSDave Young 		 * symtab->sh_link contain section header index of associated
980a43cac0dSDave Young 		 * string table.
981a43cac0dSDave Young 		 */
982a43cac0dSDave Young 		if (symtab->sh_link >= pi->ehdr->e_shnum)
983a43cac0dSDave Young 			/* Invalid section number? */
984a43cac0dSDave Young 			continue;
985a43cac0dSDave Young 
986a43cac0dSDave Young 		/*
987a43cac0dSDave Young 		 * Respective architecture needs to provide support for applying
988a43cac0dSDave Young 		 * relocations of type SHT_RELA/SHT_REL.
989a43cac0dSDave Young 		 */
9908aec395bSPhilipp Rudo 		if (relsec->sh_type == SHT_RELA)
9918aec395bSPhilipp Rudo 			ret = arch_kexec_apply_relocations_add(pi, section,
9928aec395bSPhilipp Rudo 							       relsec, symtab);
9938aec395bSPhilipp Rudo 		else if (relsec->sh_type == SHT_REL)
9948aec395bSPhilipp Rudo 			ret = arch_kexec_apply_relocations(pi, section,
9958aec395bSPhilipp Rudo 							   relsec, symtab);
996a43cac0dSDave Young 		if (ret)
997a43cac0dSDave Young 			return ret;
998a43cac0dSDave Young 	}
999a43cac0dSDave Young 
1000a43cac0dSDave Young 	return 0;
1001a43cac0dSDave Young }
1002a43cac0dSDave Young 
10033be3f61dSPhilipp Rudo /*
10043be3f61dSPhilipp Rudo  * kexec_load_purgatory - Load and relocate the purgatory object.
10053be3f61dSPhilipp Rudo  * @image:	Image to add the purgatory to.
10063be3f61dSPhilipp Rudo  * @kbuf:	Memory parameters to use.
10073be3f61dSPhilipp Rudo  *
10083be3f61dSPhilipp Rudo  * Allocates the memory needed for image->purgatory_info.sechdrs and
10093be3f61dSPhilipp Rudo  * image->purgatory_info.purgatory_buf/kbuf->buffer. Caller is responsible
10103be3f61dSPhilipp Rudo  * to free the memory after use.
10113be3f61dSPhilipp Rudo  *
10123be3f61dSPhilipp Rudo  * Return: 0 on success, negative errno on error.
10133be3f61dSPhilipp Rudo  */
kexec_load_purgatory(struct kimage * image,struct kexec_buf * kbuf)10143be3f61dSPhilipp Rudo int kexec_load_purgatory(struct kimage *image, struct kexec_buf *kbuf)
1015a43cac0dSDave Young {
1016a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
1017a43cac0dSDave Young 	int ret;
1018a43cac0dSDave Young 
1019a43cac0dSDave Young 	if (kexec_purgatory_size <= 0)
1020a43cac0dSDave Young 		return -EINVAL;
1021a43cac0dSDave Young 
102265c225d3SPhilipp Rudo 	pi->ehdr = (const Elf_Ehdr *)kexec_purgatory;
1023a43cac0dSDave Young 
10243be3f61dSPhilipp Rudo 	ret = kexec_purgatory_setup_kbuf(pi, kbuf);
1025a43cac0dSDave Young 	if (ret)
1026a43cac0dSDave Young 		return ret;
1027a43cac0dSDave Young 
10283be3f61dSPhilipp Rudo 	ret = kexec_purgatory_setup_sechdrs(pi, kbuf);
102993045705SPhilipp Rudo 	if (ret)
103093045705SPhilipp Rudo 		goto out_free_kbuf;
103193045705SPhilipp Rudo 
1032a43cac0dSDave Young 	ret = kexec_apply_relocations(image);
1033a43cac0dSDave Young 	if (ret)
1034a43cac0dSDave Young 		goto out;
1035a43cac0dSDave Young 
1036a43cac0dSDave Young 	return 0;
1037a43cac0dSDave Young out:
1038a43cac0dSDave Young 	vfree(pi->sechdrs);
1039070c43eeSThiago Jung Bauermann 	pi->sechdrs = NULL;
104093045705SPhilipp Rudo out_free_kbuf:
1041a43cac0dSDave Young 	vfree(pi->purgatory_buf);
1042070c43eeSThiago Jung Bauermann 	pi->purgatory_buf = NULL;
1043a43cac0dSDave Young 	return ret;
1044a43cac0dSDave Young }
1045a43cac0dSDave Young 
1046961d921aSPhilipp Rudo /*
1047961d921aSPhilipp Rudo  * kexec_purgatory_find_symbol - find a symbol in the purgatory
1048961d921aSPhilipp Rudo  * @pi:		Purgatory to search in.
1049961d921aSPhilipp Rudo  * @name:	Name of the symbol.
1050961d921aSPhilipp Rudo  *
1051961d921aSPhilipp Rudo  * Return: pointer to symbol in read-only symtab on success, NULL on error.
1052961d921aSPhilipp Rudo  */
kexec_purgatory_find_symbol(struct purgatory_info * pi,const char * name)1053961d921aSPhilipp Rudo static const Elf_Sym *kexec_purgatory_find_symbol(struct purgatory_info *pi,
1054a43cac0dSDave Young 						  const char *name)
1055a43cac0dSDave Young {
1056961d921aSPhilipp Rudo 	const Elf_Shdr *sechdrs;
105765c225d3SPhilipp Rudo 	const Elf_Ehdr *ehdr;
1058961d921aSPhilipp Rudo 	const Elf_Sym *syms;
1059a43cac0dSDave Young 	const char *strtab;
1060961d921aSPhilipp Rudo 	int i, k;
1061a43cac0dSDave Young 
1062961d921aSPhilipp Rudo 	if (!pi->ehdr)
1063a43cac0dSDave Young 		return NULL;
1064a43cac0dSDave Young 
1065a43cac0dSDave Young 	ehdr = pi->ehdr;
1066961d921aSPhilipp Rudo 	sechdrs = (void *)ehdr + ehdr->e_shoff;
1067a43cac0dSDave Young 
1068a43cac0dSDave Young 	for (i = 0; i < ehdr->e_shnum; i++) {
1069a43cac0dSDave Young 		if (sechdrs[i].sh_type != SHT_SYMTAB)
1070a43cac0dSDave Young 			continue;
1071a43cac0dSDave Young 
1072a43cac0dSDave Young 		if (sechdrs[i].sh_link >= ehdr->e_shnum)
1073a43cac0dSDave Young 			/* Invalid strtab section number */
1074a43cac0dSDave Young 			continue;
1075961d921aSPhilipp Rudo 		strtab = (void *)ehdr + sechdrs[sechdrs[i].sh_link].sh_offset;
1076961d921aSPhilipp Rudo 		syms = (void *)ehdr + sechdrs[i].sh_offset;
1077a43cac0dSDave Young 
1078a43cac0dSDave Young 		/* Go through symbols for a match */
1079a43cac0dSDave Young 		for (k = 0; k < sechdrs[i].sh_size/sizeof(Elf_Sym); k++) {
1080a43cac0dSDave Young 			if (ELF_ST_BIND(syms[k].st_info) != STB_GLOBAL)
1081a43cac0dSDave Young 				continue;
1082a43cac0dSDave Young 
1083a43cac0dSDave Young 			if (strcmp(strtab + syms[k].st_name, name) != 0)
1084a43cac0dSDave Young 				continue;
1085a43cac0dSDave Young 
1086a43cac0dSDave Young 			if (syms[k].st_shndx == SHN_UNDEF ||
1087a43cac0dSDave Young 			    syms[k].st_shndx >= ehdr->e_shnum) {
1088a43cac0dSDave Young 				pr_debug("Symbol: %s has bad section index %d.\n",
1089a43cac0dSDave Young 						name, syms[k].st_shndx);
1090a43cac0dSDave Young 				return NULL;
1091a43cac0dSDave Young 			}
1092a43cac0dSDave Young 
1093a43cac0dSDave Young 			/* Found the symbol we are looking for */
1094a43cac0dSDave Young 			return &syms[k];
1095a43cac0dSDave Young 		}
1096a43cac0dSDave Young 	}
1097a43cac0dSDave Young 
1098a43cac0dSDave Young 	return NULL;
1099a43cac0dSDave Young }
1100a43cac0dSDave Young 
kexec_purgatory_get_symbol_addr(struct kimage * image,const char * name)1101a43cac0dSDave Young void *kexec_purgatory_get_symbol_addr(struct kimage *image, const char *name)
1102a43cac0dSDave Young {
1103a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
1104961d921aSPhilipp Rudo 	const Elf_Sym *sym;
1105a43cac0dSDave Young 	Elf_Shdr *sechdr;
1106a43cac0dSDave Young 
1107a43cac0dSDave Young 	sym = kexec_purgatory_find_symbol(pi, name);
1108a43cac0dSDave Young 	if (!sym)
1109a43cac0dSDave Young 		return ERR_PTR(-EINVAL);
1110a43cac0dSDave Young 
1111a43cac0dSDave Young 	sechdr = &pi->sechdrs[sym->st_shndx];
1112a43cac0dSDave Young 
1113a43cac0dSDave Young 	/*
1114a43cac0dSDave Young 	 * Returns the address where symbol will finally be loaded after
1115a43cac0dSDave Young 	 * kexec_load_segment()
1116a43cac0dSDave Young 	 */
1117a43cac0dSDave Young 	return (void *)(sechdr->sh_addr + sym->st_value);
1118a43cac0dSDave Young }
1119a43cac0dSDave Young 
1120a43cac0dSDave Young /*
1121a43cac0dSDave Young  * Get or set value of a symbol. If "get_value" is true, symbol value is
1122a43cac0dSDave Young  * returned in buf otherwise symbol value is set based on value in buf.
1123a43cac0dSDave Young  */
kexec_purgatory_get_set_symbol(struct kimage * image,const char * name,void * buf,unsigned int size,bool get_value)1124a43cac0dSDave Young int kexec_purgatory_get_set_symbol(struct kimage *image, const char *name,
1125a43cac0dSDave Young 				   void *buf, unsigned int size, bool get_value)
1126a43cac0dSDave Young {
1127a43cac0dSDave Young 	struct purgatory_info *pi = &image->purgatory_info;
1128961d921aSPhilipp Rudo 	const Elf_Sym *sym;
1129961d921aSPhilipp Rudo 	Elf_Shdr *sec;
1130a43cac0dSDave Young 	char *sym_buf;
1131a43cac0dSDave Young 
1132a43cac0dSDave Young 	sym = kexec_purgatory_find_symbol(pi, name);
1133a43cac0dSDave Young 	if (!sym)
1134a43cac0dSDave Young 		return -EINVAL;
1135a43cac0dSDave Young 
1136a43cac0dSDave Young 	if (sym->st_size != size) {
1137a43cac0dSDave Young 		pr_err("symbol %s size mismatch: expected %lu actual %u\n",
1138a43cac0dSDave Young 		       name, (unsigned long)sym->st_size, size);
1139a43cac0dSDave Young 		return -EINVAL;
1140a43cac0dSDave Young 	}
1141a43cac0dSDave Young 
1142961d921aSPhilipp Rudo 	sec = pi->sechdrs + sym->st_shndx;
1143a43cac0dSDave Young 
1144961d921aSPhilipp Rudo 	if (sec->sh_type == SHT_NOBITS) {
1145a43cac0dSDave Young 		pr_err("symbol %s is in a bss section. Cannot %s\n", name,
1146a43cac0dSDave Young 		       get_value ? "get" : "set");
1147a43cac0dSDave Young 		return -EINVAL;
1148a43cac0dSDave Young 	}
1149a43cac0dSDave Young 
11508da0b724SPhilipp Rudo 	sym_buf = (char *)pi->purgatory_buf + sec->sh_offset + sym->st_value;
1151a43cac0dSDave Young 
1152a43cac0dSDave Young 	if (get_value)
1153a43cac0dSDave Young 		memcpy((void *)buf, sym_buf, size);
1154a43cac0dSDave Young 	else
1155a43cac0dSDave Young 		memcpy((void *)sym_buf, buf, size);
1156a43cac0dSDave Young 
1157a43cac0dSDave Young 	return 0;
1158a43cac0dSDave Young }
1159e6265fe7SEric DeVolder #endif /* CONFIG_ARCH_SUPPORTS_KEXEC_PURGATORY */
1160