1 /* SPDX-License-Identifier: GPL-2.0 */ 2 #ifndef __MM_KASAN_KASAN_H 3 #define __MM_KASAN_KASAN_H 4 5 #include <linux/kasan.h> 6 #include <linux/stackdepot.h> 7 8 #define KASAN_SHADOW_SCALE_SIZE (1UL << KASAN_SHADOW_SCALE_SHIFT) 9 #define KASAN_SHADOW_MASK (KASAN_SHADOW_SCALE_SIZE - 1) 10 11 #define KASAN_TAG_KERNEL 0xFF /* native kernel pointers tag */ 12 #define KASAN_TAG_INVALID 0xFE /* inaccessible memory tag */ 13 #define KASAN_TAG_MAX 0xFD /* maximum value for random tags */ 14 15 #ifdef CONFIG_KASAN_GENERIC 16 #define KASAN_FREE_PAGE 0xFF /* page was freed */ 17 #define KASAN_PAGE_REDZONE 0xFE /* redzone for kmalloc_large allocations */ 18 #define KASAN_KMALLOC_REDZONE 0xFC /* redzone inside slub object */ 19 #define KASAN_KMALLOC_FREE 0xFB /* object was freed (kmem_cache_free/kfree) */ 20 #else 21 #define KASAN_FREE_PAGE KASAN_TAG_INVALID 22 #define KASAN_PAGE_REDZONE KASAN_TAG_INVALID 23 #define KASAN_KMALLOC_REDZONE KASAN_TAG_INVALID 24 #define KASAN_KMALLOC_FREE KASAN_TAG_INVALID 25 #endif 26 27 #define KASAN_GLOBAL_REDZONE 0xFA /* redzone for global variable */ 28 29 /* 30 * Stack redzone shadow values 31 * (Those are compiler's ABI, don't change them) 32 */ 33 #define KASAN_STACK_LEFT 0xF1 34 #define KASAN_STACK_MID 0xF2 35 #define KASAN_STACK_RIGHT 0xF3 36 #define KASAN_STACK_PARTIAL 0xF4 37 #define KASAN_USE_AFTER_SCOPE 0xF8 38 39 /* 40 * alloca redzone shadow values 41 */ 42 #define KASAN_ALLOCA_LEFT 0xCA 43 #define KASAN_ALLOCA_RIGHT 0xCB 44 45 #define KASAN_ALLOCA_REDZONE_SIZE 32 46 47 /* Don't break randconfig/all*config builds */ 48 #ifndef KASAN_ABI_VERSION 49 #define KASAN_ABI_VERSION 1 50 #endif 51 52 struct kasan_access_info { 53 const void *access_addr; 54 const void *first_bad_addr; 55 size_t access_size; 56 bool is_write; 57 unsigned long ip; 58 }; 59 60 /* The layout of struct dictated by compiler */ 61 struct kasan_source_location { 62 const char *filename; 63 int line_no; 64 int column_no; 65 }; 66 67 /* The layout of struct dictated by compiler */ 68 struct kasan_global { 69 const void *beg; /* Address of the beginning of the global variable. */ 70 size_t size; /* Size of the global variable. */ 71 size_t size_with_redzone; /* Size of the variable + size of the red zone. 32 bytes aligned */ 72 const void *name; 73 const void *module_name; /* Name of the module where the global variable is declared. */ 74 unsigned long has_dynamic_init; /* This needed for C++ */ 75 #if KASAN_ABI_VERSION >= 4 76 struct kasan_source_location *location; 77 #endif 78 #if KASAN_ABI_VERSION >= 5 79 char *odr_indicator; 80 #endif 81 }; 82 83 /** 84 * Structures to keep alloc and free tracks * 85 */ 86 87 #define KASAN_STACK_DEPTH 64 88 89 struct kasan_track { 90 u32 pid; 91 depot_stack_handle_t stack; 92 }; 93 94 struct kasan_alloc_meta { 95 struct kasan_track alloc_track; 96 struct kasan_track free_track; 97 }; 98 99 struct qlist_node { 100 struct qlist_node *next; 101 }; 102 struct kasan_free_meta { 103 /* This field is used while the object is in the quarantine. 104 * Otherwise it might be used for the allocator freelist. 105 */ 106 struct qlist_node quarantine_link; 107 }; 108 109 struct kasan_alloc_meta *get_alloc_info(struct kmem_cache *cache, 110 const void *object); 111 struct kasan_free_meta *get_free_info(struct kmem_cache *cache, 112 const void *object); 113 114 static inline const void *kasan_shadow_to_mem(const void *shadow_addr) 115 { 116 return (void *)(((unsigned long)shadow_addr - KASAN_SHADOW_OFFSET) 117 << KASAN_SHADOW_SCALE_SHIFT); 118 } 119 120 static inline bool addr_has_shadow(const void *addr) 121 { 122 return (addr >= kasan_shadow_to_mem((void *)KASAN_SHADOW_START)); 123 } 124 125 void kasan_poison_shadow(const void *address, size_t size, u8 value); 126 127 void check_memory_region(unsigned long addr, size_t size, bool write, 128 unsigned long ret_ip); 129 130 void *find_first_bad_addr(void *addr, size_t size); 131 const char *get_bug_type(struct kasan_access_info *info); 132 133 void kasan_report(unsigned long addr, size_t size, 134 bool is_write, unsigned long ip); 135 void kasan_report_invalid_free(void *object, unsigned long ip); 136 137 #if defined(CONFIG_KASAN_GENERIC) && \ 138 (defined(CONFIG_SLAB) || defined(CONFIG_SLUB)) 139 void quarantine_put(struct kasan_free_meta *info, struct kmem_cache *cache); 140 void quarantine_reduce(void); 141 void quarantine_remove_cache(struct kmem_cache *cache); 142 #else 143 static inline void quarantine_put(struct kasan_free_meta *info, 144 struct kmem_cache *cache) { } 145 static inline void quarantine_reduce(void) { } 146 static inline void quarantine_remove_cache(struct kmem_cache *cache) { } 147 #endif 148 149 #ifdef CONFIG_KASAN_SW_TAGS 150 151 void print_tags(u8 addr_tag, const void *addr); 152 153 u8 random_tag(void); 154 155 #else 156 157 static inline void print_tags(u8 addr_tag, const void *addr) { } 158 159 static inline u8 random_tag(void) 160 { 161 return 0; 162 } 163 164 #endif 165 166 #ifndef arch_kasan_set_tag 167 #define arch_kasan_set_tag(addr, tag) ((void *)(addr)) 168 #endif 169 #ifndef arch_kasan_reset_tag 170 #define arch_kasan_reset_tag(addr) ((void *)(addr)) 171 #endif 172 #ifndef arch_kasan_get_tag 173 #define arch_kasan_get_tag(addr) 0 174 #endif 175 176 #define set_tag(addr, tag) ((void *)arch_kasan_set_tag((addr), (tag))) 177 #define reset_tag(addr) ((void *)arch_kasan_reset_tag(addr)) 178 #define get_tag(addr) arch_kasan_get_tag(addr) 179 180 /* 181 * Exported functions for interfaces called from assembly or from generated 182 * code. Declarations here to avoid warning about missing declarations. 183 */ 184 asmlinkage void kasan_unpoison_task_stack_below(const void *watermark); 185 void __asan_register_globals(struct kasan_global *globals, size_t size); 186 void __asan_unregister_globals(struct kasan_global *globals, size_t size); 187 void __asan_loadN(unsigned long addr, size_t size); 188 void __asan_storeN(unsigned long addr, size_t size); 189 void __asan_handle_no_return(void); 190 void __asan_poison_stack_memory(const void *addr, size_t size); 191 void __asan_unpoison_stack_memory(const void *addr, size_t size); 192 void __asan_alloca_poison(unsigned long addr, size_t size); 193 void __asan_allocas_unpoison(const void *stack_top, const void *stack_bottom); 194 195 void __asan_load1(unsigned long addr); 196 void __asan_store1(unsigned long addr); 197 void __asan_load2(unsigned long addr); 198 void __asan_store2(unsigned long addr); 199 void __asan_load4(unsigned long addr); 200 void __asan_store4(unsigned long addr); 201 void __asan_load8(unsigned long addr); 202 void __asan_store8(unsigned long addr); 203 void __asan_load16(unsigned long addr); 204 void __asan_store16(unsigned long addr); 205 206 void __asan_load1_noabort(unsigned long addr); 207 void __asan_store1_noabort(unsigned long addr); 208 void __asan_load2_noabort(unsigned long addr); 209 void __asan_store2_noabort(unsigned long addr); 210 void __asan_load4_noabort(unsigned long addr); 211 void __asan_store4_noabort(unsigned long addr); 212 void __asan_load8_noabort(unsigned long addr); 213 void __asan_store8_noabort(unsigned long addr); 214 void __asan_load16_noabort(unsigned long addr); 215 void __asan_store16_noabort(unsigned long addr); 216 217 void __asan_set_shadow_00(const void *addr, size_t size); 218 void __asan_set_shadow_f1(const void *addr, size_t size); 219 void __asan_set_shadow_f2(const void *addr, size_t size); 220 void __asan_set_shadow_f3(const void *addr, size_t size); 221 void __asan_set_shadow_f5(const void *addr, size_t size); 222 void __asan_set_shadow_f8(const void *addr, size_t size); 223 224 #endif 225