1d08b9f0cSSami Tolvanen // SPDX-License-Identifier: GPL-2.0 2d08b9f0cSSami Tolvanen /* 3d08b9f0cSSami Tolvanen * Shadow Call Stack support. 4d08b9f0cSSami Tolvanen * 5d08b9f0cSSami Tolvanen * Copyright (C) 2019 Google LLC 6d08b9f0cSSami Tolvanen */ 7d08b9f0cSSami Tolvanen 8d08b9f0cSSami Tolvanen #include <linux/kasan.h> 9628d06a4SSami Tolvanen #include <linux/mm.h> 10d08b9f0cSSami Tolvanen #include <linux/scs.h> 11d08b9f0cSSami Tolvanen #include <linux/slab.h> 12628d06a4SSami Tolvanen #include <linux/vmstat.h> 13d08b9f0cSSami Tolvanen #include <asm/scs.h> 14d08b9f0cSSami Tolvanen 15d08b9f0cSSami Tolvanen static struct kmem_cache *scs_cache; 16d08b9f0cSSami Tolvanen 17bee348faSWill Deacon static void __scs_account(void *s, int account) 18bee348faSWill Deacon { 19bee348faSWill Deacon struct page *scs_page = virt_to_page(s); 20bee348faSWill Deacon 21bee348faSWill Deacon mod_zone_page_state(page_zone(scs_page), NR_KERNEL_SCS_KB, 22bee348faSWill Deacon account * (SCS_SIZE / SZ_1K)); 23bee348faSWill Deacon } 24bee348faSWill Deacon 25d08b9f0cSSami Tolvanen static void *scs_alloc(int node) 26d08b9f0cSSami Tolvanen { 27bee348faSWill Deacon void *s = kmem_cache_alloc_node(scs_cache, GFP_SCS, node); 28d08b9f0cSSami Tolvanen 29bee348faSWill Deacon if (!s) 30bee348faSWill Deacon return NULL; 31bee348faSWill Deacon 32d08b9f0cSSami Tolvanen *__scs_magic(s) = SCS_END_MAGIC; 33bee348faSWill Deacon 34d08b9f0cSSami Tolvanen /* 35d08b9f0cSSami Tolvanen * Poison the allocation to catch unintentional accesses to 36d08b9f0cSSami Tolvanen * the shadow stack when KASAN is enabled. 37d08b9f0cSSami Tolvanen */ 38d08b9f0cSSami Tolvanen kasan_poison_object_data(scs_cache, s); 39bee348faSWill Deacon __scs_account(s, 1); 40d08b9f0cSSami Tolvanen return s; 41d08b9f0cSSami Tolvanen } 42d08b9f0cSSami Tolvanen 43d08b9f0cSSami Tolvanen static void scs_free(void *s) 44d08b9f0cSSami Tolvanen { 45bee348faSWill Deacon __scs_account(s, -1); 46d08b9f0cSSami Tolvanen kasan_unpoison_object_data(scs_cache, s); 47d08b9f0cSSami Tolvanen kmem_cache_free(scs_cache, s); 48d08b9f0cSSami Tolvanen } 49d08b9f0cSSami Tolvanen 50d08b9f0cSSami Tolvanen void __init scs_init(void) 51d08b9f0cSSami Tolvanen { 52d08b9f0cSSami Tolvanen scs_cache = kmem_cache_create("scs_cache", SCS_SIZE, 0, 0, NULL); 53d08b9f0cSSami Tolvanen } 54d08b9f0cSSami Tolvanen 55d08b9f0cSSami Tolvanen int scs_prepare(struct task_struct *tsk, int node) 56d08b9f0cSSami Tolvanen { 57d08b9f0cSSami Tolvanen void *s = scs_alloc(node); 58d08b9f0cSSami Tolvanen 59d08b9f0cSSami Tolvanen if (!s) 60d08b9f0cSSami Tolvanen return -ENOMEM; 61d08b9f0cSSami Tolvanen 6251189c7aSWill Deacon task_scs(tsk) = task_scs_sp(tsk) = s; 63d08b9f0cSSami Tolvanen return 0; 64d08b9f0cSSami Tolvanen } 65d08b9f0cSSami Tolvanen 665bbaf9d1SSami Tolvanen static void scs_check_usage(struct task_struct *tsk) 675bbaf9d1SSami Tolvanen { 685bbaf9d1SSami Tolvanen static unsigned long highest; 695bbaf9d1SSami Tolvanen 705bbaf9d1SSami Tolvanen unsigned long *p, prev, curr = highest, used = 0; 715bbaf9d1SSami Tolvanen 725bbaf9d1SSami Tolvanen if (!IS_ENABLED(CONFIG_DEBUG_STACK_USAGE)) 735bbaf9d1SSami Tolvanen return; 745bbaf9d1SSami Tolvanen 755bbaf9d1SSami Tolvanen for (p = task_scs(tsk); p < __scs_magic(tsk); ++p) { 765bbaf9d1SSami Tolvanen if (!READ_ONCE_NOCHECK(*p)) 775bbaf9d1SSami Tolvanen break; 785bbaf9d1SSami Tolvanen used++; 795bbaf9d1SSami Tolvanen } 805bbaf9d1SSami Tolvanen 815bbaf9d1SSami Tolvanen while (used > curr) { 825bbaf9d1SSami Tolvanen prev = cmpxchg_relaxed(&highest, curr, used); 835bbaf9d1SSami Tolvanen 845bbaf9d1SSami Tolvanen if (prev == curr) { 855bbaf9d1SSami Tolvanen pr_info("%s (%d): highest shadow stack usage: %lu bytes\n", 865bbaf9d1SSami Tolvanen tsk->comm, task_pid_nr(tsk), used); 875bbaf9d1SSami Tolvanen break; 885bbaf9d1SSami Tolvanen } 895bbaf9d1SSami Tolvanen 905bbaf9d1SSami Tolvanen curr = prev; 915bbaf9d1SSami Tolvanen } 925bbaf9d1SSami Tolvanen } 935bbaf9d1SSami Tolvanen 94d08b9f0cSSami Tolvanen void scs_release(struct task_struct *tsk) 95d08b9f0cSSami Tolvanen { 96d08b9f0cSSami Tolvanen void *s = task_scs(tsk); 97d08b9f0cSSami Tolvanen 98d08b9f0cSSami Tolvanen if (!s) 99d08b9f0cSSami Tolvanen return; 100d08b9f0cSSami Tolvanen 101*88485be5SWill Deacon WARN(task_scs_end_corrupted(tsk), 102*88485be5SWill Deacon "corrupted shadow stack detected when freeing task\n"); 1035bbaf9d1SSami Tolvanen scs_check_usage(tsk); 104d08b9f0cSSami Tolvanen scs_free(s); 105d08b9f0cSSami Tolvanen } 106