197d06da6SDmitry Chagin /*- 297d06da6SDmitry Chagin * Copyright (c) 2004 Tim J. Robbins 397d06da6SDmitry Chagin * Copyright (c) 2002 Doug Rabson 497d06da6SDmitry Chagin * Copyright (c) 2000 Marcel Moolenaar 597d06da6SDmitry Chagin * Copyright (c) 1994-1995 Søren Schmidt 697d06da6SDmitry Chagin * All rights reserved. 797d06da6SDmitry Chagin * 897d06da6SDmitry Chagin * Redistribution and use in source and binary forms, with or without 997d06da6SDmitry Chagin * modification, are permitted provided that the following conditions 1097d06da6SDmitry Chagin * are met: 1197d06da6SDmitry Chagin * 1. Redistributions of source code must retain the above copyright 1297d06da6SDmitry Chagin * notice, this list of conditions and the following disclaimer 1397d06da6SDmitry Chagin * in this position and unchanged. 1497d06da6SDmitry Chagin * 2. Redistributions in binary form must reproduce the above copyright 1597d06da6SDmitry Chagin * notice, this list of conditions and the following disclaimer in the 1697d06da6SDmitry Chagin * documentation and/or other materials provided with the distribution. 1797d06da6SDmitry Chagin * 3. The name of the author may not be used to endorse or promote products 1897d06da6SDmitry Chagin * derived from this software without specific prior written permission. 1997d06da6SDmitry Chagin * 2097d06da6SDmitry Chagin * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 2197d06da6SDmitry Chagin * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 2297d06da6SDmitry Chagin * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 2397d06da6SDmitry Chagin * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 2497d06da6SDmitry Chagin * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 2597d06da6SDmitry Chagin * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 2697d06da6SDmitry Chagin * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 2797d06da6SDmitry Chagin * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 2897d06da6SDmitry Chagin * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 2997d06da6SDmitry Chagin * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 3097d06da6SDmitry Chagin * 3197d06da6SDmitry Chagin * $FreeBSD$ 3297d06da6SDmitry Chagin */ 3397d06da6SDmitry Chagin 3497d06da6SDmitry Chagin #include <sys/cdefs.h> 3597d06da6SDmitry Chagin __FBSDID("$FreeBSD$"); 3697d06da6SDmitry Chagin 3797d06da6SDmitry Chagin #include <sys/capsicum.h> 3897d06da6SDmitry Chagin #include <sys/file.h> 3997d06da6SDmitry Chagin #include <sys/imgact.h> 4097d06da6SDmitry Chagin #include <sys/ktr.h> 4197d06da6SDmitry Chagin #include <sys/mman.h> 4297d06da6SDmitry Chagin #include <sys/proc.h> 4397d06da6SDmitry Chagin #include <sys/resourcevar.h> 44496ab053SKonstantin Belousov #include <sys/syscallsubr.h> 4597d06da6SDmitry Chagin #include <sys/sysent.h> 4697d06da6SDmitry Chagin #include <sys/sysproto.h> 4797d06da6SDmitry Chagin 4897d06da6SDmitry Chagin #include <vm/pmap.h> 4969cdfcefSEdward Tomasz Napierala #include <vm/vm_extern.h> 5097d06da6SDmitry Chagin #include <vm/vm_map.h> 5197d06da6SDmitry Chagin 5297d06da6SDmitry Chagin #include <compat/linux/linux_emul.h> 5397d06da6SDmitry Chagin #include <compat/linux/linux_mmap.h> 5497d06da6SDmitry Chagin #include <compat/linux/linux_persona.h> 5597d06da6SDmitry Chagin #include <compat/linux/linux_util.h> 5697d06da6SDmitry Chagin 5797d06da6SDmitry Chagin 5897d06da6SDmitry Chagin #define STACK_SIZE (2 * 1024 * 1024) 5997d06da6SDmitry Chagin #define GUARD_SIZE (4 * PAGE_SIZE) 6097d06da6SDmitry Chagin 6197d06da6SDmitry Chagin #if defined(__amd64__) 6297d06da6SDmitry Chagin static void linux_fixup_prot(struct thread *td, int *prot); 6397d06da6SDmitry Chagin #endif 6497d06da6SDmitry Chagin 6518348a23SKyle Evans static int 6618348a23SKyle Evans linux_mmap_check_fp(struct file *fp, int flags, int prot, int maxprot) 6718348a23SKyle Evans { 6818348a23SKyle Evans 6918348a23SKyle Evans /* Linux mmap() just fails for O_WRONLY files */ 7018348a23SKyle Evans if ((fp->f_flag & FREAD) == 0) 7118348a23SKyle Evans return (EACCES); 7218348a23SKyle Evans 7318348a23SKyle Evans return (0); 7418348a23SKyle Evans } 7597d06da6SDmitry Chagin 7697d06da6SDmitry Chagin int 7797d06da6SDmitry Chagin linux_mmap_common(struct thread *td, uintptr_t addr, size_t len, int prot, 7897d06da6SDmitry Chagin int flags, int fd, off_t pos) 7997d06da6SDmitry Chagin { 80d718de81SBrooks Davis struct mmap_req mr, mr_fixed; 8197d06da6SDmitry Chagin struct proc *p = td->td_proc; 8297d06da6SDmitry Chagin struct vmspace *vms = td->td_proc->p_vmspace; 8369cdfcefSEdward Tomasz Napierala int bsd_flags, error; 8497d06da6SDmitry Chagin struct file *fp; 8597d06da6SDmitry Chagin 8697d06da6SDmitry Chagin LINUX_CTR6(mmap2, "0x%lx, %ld, %ld, 0x%08lx, %ld, 0x%lx", 8797d06da6SDmitry Chagin addr, len, prot, flags, fd, pos); 8897d06da6SDmitry Chagin 8997d06da6SDmitry Chagin error = 0; 9069cdfcefSEdward Tomasz Napierala bsd_flags = 0; 9197d06da6SDmitry Chagin fp = NULL; 9297d06da6SDmitry Chagin 9397d06da6SDmitry Chagin /* 9497d06da6SDmitry Chagin * Linux mmap(2): 9597d06da6SDmitry Chagin * You must specify exactly one of MAP_SHARED and MAP_PRIVATE 9697d06da6SDmitry Chagin */ 9797d06da6SDmitry Chagin if (!((flags & LINUX_MAP_SHARED) ^ (flags & LINUX_MAP_PRIVATE))) 9897d06da6SDmitry Chagin return (EINVAL); 9997d06da6SDmitry Chagin 10097d06da6SDmitry Chagin if (flags & LINUX_MAP_SHARED) 10169cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_SHARED; 10297d06da6SDmitry Chagin if (flags & LINUX_MAP_PRIVATE) 10369cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_PRIVATE; 10497d06da6SDmitry Chagin if (flags & LINUX_MAP_FIXED) 10569cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_FIXED; 10697d06da6SDmitry Chagin if (flags & LINUX_MAP_ANON) { 10797d06da6SDmitry Chagin /* Enforce pos to be on page boundary, then ignore. */ 10897d06da6SDmitry Chagin if ((pos & PAGE_MASK) != 0) 10997d06da6SDmitry Chagin return (EINVAL); 11097d06da6SDmitry Chagin pos = 0; 11169cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_ANON; 11297d06da6SDmitry Chagin } else 11369cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_NOSYNC; 11497d06da6SDmitry Chagin if (flags & LINUX_MAP_GROWSDOWN) 11569cdfcefSEdward Tomasz Napierala bsd_flags |= MAP_STACK; 11697d06da6SDmitry Chagin 117618b55c2SEdward Tomasz Napierala #if defined(__amd64__) 118618b55c2SEdward Tomasz Napierala /* 119618b55c2SEdward Tomasz Napierala * According to the Linux mmap(2) man page, "MAP_32BIT flag 120618b55c2SEdward Tomasz Napierala * is ignored when MAP_FIXED is set." 121618b55c2SEdward Tomasz Napierala */ 122618b55c2SEdward Tomasz Napierala if ((flags & LINUX_MAP_32BIT) && (flags & LINUX_MAP_FIXED) == 0) 123618b55c2SEdward Tomasz Napierala bsd_flags |= MAP_32BIT; 124618b55c2SEdward Tomasz Napierala 12597d06da6SDmitry Chagin /* 12697d06da6SDmitry Chagin * PROT_READ, PROT_WRITE, or PROT_EXEC implies PROT_READ and PROT_EXEC 12797d06da6SDmitry Chagin * on Linux/i386 if the binary requires executable stack. 12897d06da6SDmitry Chagin * We do this only for IA32 emulation as on native i386 this is does not 12997d06da6SDmitry Chagin * make sense without PAE. 13097d06da6SDmitry Chagin * 13197d06da6SDmitry Chagin * XXX. Linux checks that the file system is not mounted with noexec. 13297d06da6SDmitry Chagin */ 13369cdfcefSEdward Tomasz Napierala linux_fixup_prot(td, &prot); 13497d06da6SDmitry Chagin #endif 13597d06da6SDmitry Chagin 13697d06da6SDmitry Chagin /* Linux does not check file descriptor when MAP_ANONYMOUS is set. */ 13769cdfcefSEdward Tomasz Napierala fd = (bsd_flags & MAP_ANON) ? -1 : fd; 13897d06da6SDmitry Chagin if (flags & LINUX_MAP_GROWSDOWN) { 13997d06da6SDmitry Chagin /* 14097d06da6SDmitry Chagin * The Linux MAP_GROWSDOWN option does not limit auto 14197d06da6SDmitry Chagin * growth of the region. Linux mmap with this option 14297d06da6SDmitry Chagin * takes as addr the initial BOS, and as len, the initial 14397d06da6SDmitry Chagin * region size. It can then grow down from addr without 14497d06da6SDmitry Chagin * limit. However, Linux threads has an implicit internal 14597d06da6SDmitry Chagin * limit to stack size of STACK_SIZE. Its just not 14697d06da6SDmitry Chagin * enforced explicitly in Linux. But, here we impose 14797d06da6SDmitry Chagin * a limit of (STACK_SIZE - GUARD_SIZE) on the stack 14897d06da6SDmitry Chagin * region, since we can do this with our mmap. 14997d06da6SDmitry Chagin * 15097d06da6SDmitry Chagin * Our mmap with MAP_STACK takes addr as the maximum 15197d06da6SDmitry Chagin * downsize limit on BOS, and as len the max size of 15297d06da6SDmitry Chagin * the region. It then maps the top SGROWSIZ bytes, 15397d06da6SDmitry Chagin * and auto grows the region down, up to the limit 15497d06da6SDmitry Chagin * in addr. 15597d06da6SDmitry Chagin * 15697d06da6SDmitry Chagin * If we don't use the MAP_STACK option, the effect 15797d06da6SDmitry Chagin * of this code is to allocate a stack region of a 15897d06da6SDmitry Chagin * fixed size of (STACK_SIZE - GUARD_SIZE). 15997d06da6SDmitry Chagin */ 16097d06da6SDmitry Chagin 16197d06da6SDmitry Chagin if ((caddr_t)addr + len > vms->vm_maxsaddr) { 16297d06da6SDmitry Chagin /* 16397d06da6SDmitry Chagin * Some Linux apps will attempt to mmap 16497d06da6SDmitry Chagin * thread stacks near the top of their 16597d06da6SDmitry Chagin * address space. If their TOS is greater 16697d06da6SDmitry Chagin * than vm_maxsaddr, vm_map_growstack() 16797d06da6SDmitry Chagin * will confuse the thread stack with the 16897d06da6SDmitry Chagin * process stack and deliver a SEGV if they 16997d06da6SDmitry Chagin * attempt to grow the thread stack past their 17097d06da6SDmitry Chagin * current stacksize rlimit. To avoid this, 17197d06da6SDmitry Chagin * adjust vm_maxsaddr upwards to reflect 17297d06da6SDmitry Chagin * the current stacksize rlimit rather 17397d06da6SDmitry Chagin * than the maximum possible stacksize. 17497d06da6SDmitry Chagin * It would be better to adjust the 17597d06da6SDmitry Chagin * mmap'ed region, but some apps do not check 17697d06da6SDmitry Chagin * mmap's return value. 17797d06da6SDmitry Chagin */ 17897d06da6SDmitry Chagin PROC_LOCK(p); 17997d06da6SDmitry Chagin vms->vm_maxsaddr = (char *)p->p_sysent->sv_usrstack - 18097d06da6SDmitry Chagin lim_cur_proc(p, RLIMIT_STACK); 18197d06da6SDmitry Chagin PROC_UNLOCK(p); 18297d06da6SDmitry Chagin } 18397d06da6SDmitry Chagin 18497d06da6SDmitry Chagin /* 18597d06da6SDmitry Chagin * This gives us our maximum stack size and a new BOS. 18697d06da6SDmitry Chagin * If we're using VM_STACK, then mmap will just map 18797d06da6SDmitry Chagin * the top SGROWSIZ bytes, and let the stack grow down 18897d06da6SDmitry Chagin * to the limit at BOS. If we're not using VM_STACK 18997d06da6SDmitry Chagin * we map the full stack, since we don't have a way 19097d06da6SDmitry Chagin * to autogrow it. 19197d06da6SDmitry Chagin */ 19269cdfcefSEdward Tomasz Napierala if (len <= STACK_SIZE - GUARD_SIZE) { 19369cdfcefSEdward Tomasz Napierala addr = addr - (STACK_SIZE - GUARD_SIZE - len); 19469cdfcefSEdward Tomasz Napierala len = STACK_SIZE - GUARD_SIZE; 19597d06da6SDmitry Chagin } 19697d06da6SDmitry Chagin } 19797d06da6SDmitry Chagin 198c6d57d30SEdward Tomasz Napierala /* 199c6d57d30SEdward Tomasz Napierala * FreeBSD is free to ignore the address hint if MAP_FIXED wasn't 200c6d57d30SEdward Tomasz Napierala * passed. However, some Linux applications, like the ART runtime, 201c6d57d30SEdward Tomasz Napierala * depend on the hint. If the MAP_FIXED wasn't passed, but the 202c6d57d30SEdward Tomasz Napierala * address is not zero, try with MAP_FIXED and MAP_EXCL first, 203c6d57d30SEdward Tomasz Napierala * and fall back to the normal behaviour if that fails. 204c6d57d30SEdward Tomasz Napierala */ 205d718de81SBrooks Davis mr = (struct mmap_req) { 206d718de81SBrooks Davis .mr_hint = addr, 207d718de81SBrooks Davis .mr_len = len, 208d718de81SBrooks Davis .mr_prot = prot, 209d718de81SBrooks Davis .mr_flags = bsd_flags, 210d718de81SBrooks Davis .mr_fd = fd, 211d718de81SBrooks Davis .mr_pos = pos, 212d718de81SBrooks Davis .mr_check_fp_fn = linux_mmap_check_fp, 213d718de81SBrooks Davis }; 214c6d57d30SEdward Tomasz Napierala if (addr != 0 && (bsd_flags & MAP_FIXED) == 0 && 215c6d57d30SEdward Tomasz Napierala (bsd_flags & MAP_EXCL) == 0) { 216d718de81SBrooks Davis mr_fixed = mr; 217d718de81SBrooks Davis mr_fixed.mr_flags |= MAP_FIXED | MAP_EXCL; 218d718de81SBrooks Davis error = kern_mmap_req(td, &mr_fixed); 219c6d57d30SEdward Tomasz Napierala if (error == 0) 220c6d57d30SEdward Tomasz Napierala goto out; 221c6d57d30SEdward Tomasz Napierala } 22297d06da6SDmitry Chagin 223d718de81SBrooks Davis error = kern_mmap_req(td, &mr); 224c6d57d30SEdward Tomasz Napierala out: 22597d06da6SDmitry Chagin LINUX_CTR2(mmap2, "return: %d (%p)", error, td->td_retval[0]); 22697d06da6SDmitry Chagin 22797d06da6SDmitry Chagin return (error); 22897d06da6SDmitry Chagin } 22997d06da6SDmitry Chagin 23097d06da6SDmitry Chagin int 23197d06da6SDmitry Chagin linux_mprotect_common(struct thread *td, uintptr_t addr, size_t len, int prot) 23297d06da6SDmitry Chagin { 23397d06da6SDmitry Chagin 234e2fba140STijl Coosemans /* XXX Ignore PROT_GROWSDOWN and PROT_GROWSUP for now. */ 235e2fba140STijl Coosemans prot &= ~(LINUX_PROT_GROWSDOWN | LINUX_PROT_GROWSUP); 236e2fba140STijl Coosemans if ((prot & ~(PROT_READ | PROT_WRITE | PROT_EXEC)) != 0) 237e2fba140STijl Coosemans return (EINVAL); 238e2fba140STijl Coosemans 23997d06da6SDmitry Chagin #if defined(__amd64__) 24069cdfcefSEdward Tomasz Napierala linux_fixup_prot(td, &prot); 24197d06da6SDmitry Chagin #endif 242496ab053SKonstantin Belousov return (kern_mprotect(td, addr, len, prot)); 24397d06da6SDmitry Chagin } 24497d06da6SDmitry Chagin 245*52c81be1SEdward Tomasz Napierala int 246*52c81be1SEdward Tomasz Napierala linux_madvise_common(struct thread *td, uintptr_t addr, size_t len, int behav) 247*52c81be1SEdward Tomasz Napierala { 248*52c81be1SEdward Tomasz Napierala 249*52c81be1SEdward Tomasz Napierala switch (behav) { 250*52c81be1SEdward Tomasz Napierala case LINUX_MADV_NORMAL: 251*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_NORMAL)); 252*52c81be1SEdward Tomasz Napierala case LINUX_MADV_RANDOM: 253*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_RANDOM)); 254*52c81be1SEdward Tomasz Napierala case LINUX_MADV_SEQUENTIAL: 255*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_SEQUENTIAL)); 256*52c81be1SEdward Tomasz Napierala case LINUX_MADV_WILLNEED: 257*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_WILLNEED)); 258*52c81be1SEdward Tomasz Napierala case LINUX_MADV_DONTNEED: 259*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_DONTNEED)); 260*52c81be1SEdward Tomasz Napierala case LINUX_MADV_FREE: 261*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_FREE)); 262*52c81be1SEdward Tomasz Napierala case LINUX_MADV_REMOVE: 263*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise MADV_REMOVE"); 264*52c81be1SEdward Tomasz Napierala return (EINVAL); 265*52c81be1SEdward Tomasz Napierala case LINUX_MADV_DONTFORK: 266*52c81be1SEdward Tomasz Napierala return (kern_minherit(td, addr, len, INHERIT_NONE)); 267*52c81be1SEdward Tomasz Napierala case LINUX_MADV_DOFORK: 268*52c81be1SEdward Tomasz Napierala return (kern_minherit(td, addr, len, INHERIT_COPY)); 269*52c81be1SEdward Tomasz Napierala case LINUX_MADV_MERGEABLE: 270*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise MADV_MERGEABLE"); 271*52c81be1SEdward Tomasz Napierala return (EINVAL); 272*52c81be1SEdward Tomasz Napierala case LINUX_MADV_UNMERGEABLE: 273*52c81be1SEdward Tomasz Napierala /* We don't merge anyway. */ 274*52c81be1SEdward Tomasz Napierala return (0); 275*52c81be1SEdward Tomasz Napierala case LINUX_MADV_HUGEPAGE: 276*52c81be1SEdward Tomasz Napierala /* Ignored; on FreeBSD huge pages are always on. */ 277*52c81be1SEdward Tomasz Napierala return (0); 278*52c81be1SEdward Tomasz Napierala case LINUX_MADV_NOHUGEPAGE: 279*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise MADV_NOHUGEPAGE"); 280*52c81be1SEdward Tomasz Napierala return (EINVAL); 281*52c81be1SEdward Tomasz Napierala case LINUX_MADV_DONTDUMP: 282*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_NOCORE)); 283*52c81be1SEdward Tomasz Napierala case LINUX_MADV_DODUMP: 284*52c81be1SEdward Tomasz Napierala return (kern_madvise(td, addr, len, MADV_CORE)); 285*52c81be1SEdward Tomasz Napierala case LINUX_MADV_WIPEONFORK: 286*52c81be1SEdward Tomasz Napierala return (kern_minherit(td, addr, len, INHERIT_ZERO)); 287*52c81be1SEdward Tomasz Napierala case LINUX_MADV_KEEPONFORK: 288*52c81be1SEdward Tomasz Napierala return (kern_minherit(td, addr, len, INHERIT_COPY)); 289*52c81be1SEdward Tomasz Napierala case LINUX_MADV_HWPOISON: 290*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise MADV_HWPOISON"); 291*52c81be1SEdward Tomasz Napierala return (EINVAL); 292*52c81be1SEdward Tomasz Napierala case LINUX_MADV_SOFT_OFFLINE: 293*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise MADV_SOFT_OFFLINE"); 294*52c81be1SEdward Tomasz Napierala return (EINVAL); 295*52c81be1SEdward Tomasz Napierala default: 296*52c81be1SEdward Tomasz Napierala linux_msg(curthread, "unsupported madvise behav %d", behav); 297*52c81be1SEdward Tomasz Napierala return (EINVAL); 298*52c81be1SEdward Tomasz Napierala } 299*52c81be1SEdward Tomasz Napierala } 300*52c81be1SEdward Tomasz Napierala 30197d06da6SDmitry Chagin #if defined(__amd64__) 30297d06da6SDmitry Chagin static void 30397d06da6SDmitry Chagin linux_fixup_prot(struct thread *td, int *prot) 30497d06da6SDmitry Chagin { 30597d06da6SDmitry Chagin struct linux_pemuldata *pem; 30697d06da6SDmitry Chagin 30797d06da6SDmitry Chagin if (SV_PROC_FLAG(td->td_proc, SV_ILP32) && *prot & PROT_READ) { 30897d06da6SDmitry Chagin pem = pem_find(td->td_proc); 30997d06da6SDmitry Chagin if (pem->persona & LINUX_READ_IMPLIES_EXEC) 31097d06da6SDmitry Chagin *prot |= PROT_EXEC; 31197d06da6SDmitry Chagin } 31297d06da6SDmitry Chagin 31397d06da6SDmitry Chagin } 31497d06da6SDmitry Chagin #endif 315