1 #include <linux/kernel.h> 2 #include <linux/string.h> 3 #include <linux/mm.h> 4 #include <linux/highmem.h> 5 #include <linux/page_ext.h> 6 #include <linux/poison.h> 7 #include <linux/ratelimit.h> 8 9 static bool want_page_poisoning __read_mostly; 10 11 static int early_page_poison_param(char *buf) 12 { 13 if (!buf) 14 return -EINVAL; 15 return strtobool(buf, &want_page_poisoning); 16 } 17 early_param("page_poison", early_page_poison_param); 18 19 bool page_poisoning_enabled(void) 20 { 21 /* 22 * Assumes that debug_pagealloc_enabled is set before 23 * free_all_bootmem. 24 * Page poisoning is debug page alloc for some arches. If 25 * either of those options are enabled, enable poisoning. 26 */ 27 return (want_page_poisoning || 28 (!IS_ENABLED(CONFIG_ARCH_SUPPORTS_DEBUG_PAGEALLOC) && 29 debug_pagealloc_enabled())); 30 } 31 32 static void poison_page(struct page *page) 33 { 34 void *addr = kmap_atomic(page); 35 36 memset(addr, PAGE_POISON, PAGE_SIZE); 37 kunmap_atomic(addr); 38 } 39 40 static void poison_pages(struct page *page, int n) 41 { 42 int i; 43 44 for (i = 0; i < n; i++) 45 poison_page(page + i); 46 } 47 48 static bool single_bit_flip(unsigned char a, unsigned char b) 49 { 50 unsigned char error = a ^ b; 51 52 return error && !(error & (error - 1)); 53 } 54 55 static void check_poison_mem(unsigned char *mem, size_t bytes) 56 { 57 static DEFINE_RATELIMIT_STATE(ratelimit, 5 * HZ, 10); 58 unsigned char *start; 59 unsigned char *end; 60 61 if (IS_ENABLED(CONFIG_PAGE_POISONING_NO_SANITY)) 62 return; 63 64 start = memchr_inv(mem, PAGE_POISON, bytes); 65 if (!start) 66 return; 67 68 for (end = mem + bytes - 1; end > start; end--) { 69 if (*end != PAGE_POISON) 70 break; 71 } 72 73 if (!__ratelimit(&ratelimit)) 74 return; 75 else if (start == end && single_bit_flip(*start, PAGE_POISON)) 76 pr_err("pagealloc: single bit error\n"); 77 else 78 pr_err("pagealloc: memory corruption\n"); 79 80 print_hex_dump(KERN_ERR, "", DUMP_PREFIX_ADDRESS, 16, 1, start, 81 end - start + 1, 1); 82 dump_stack(); 83 } 84 85 static void unpoison_page(struct page *page) 86 { 87 void *addr; 88 89 addr = kmap_atomic(page); 90 /* 91 * Page poisoning when enabled poisons each and every page 92 * that is freed to buddy. Thus no extra check is done to 93 * see if a page was posioned. 94 */ 95 check_poison_mem(addr, PAGE_SIZE); 96 kunmap_atomic(addr); 97 } 98 99 static void unpoison_pages(struct page *page, int n) 100 { 101 int i; 102 103 for (i = 0; i < n; i++) 104 unpoison_page(page + i); 105 } 106 107 void kernel_poison_pages(struct page *page, int numpages, int enable) 108 { 109 if (!page_poisoning_enabled()) 110 return; 111 112 if (enable) 113 unpoison_pages(page, numpages); 114 else 115 poison_pages(page, numpages); 116 } 117 118 #ifndef CONFIG_ARCH_SUPPORTS_DEBUG_PAGEALLOC 119 void __kernel_map_pages(struct page *page, int numpages, int enable) 120 { 121 /* This function does nothing, all work is done via poison pages */ 122 } 123 #endif 124