159c4da86SZong Li // SPDX-License-Identifier: GPL-2.0-only 259c4da86SZong Li /* 359c4da86SZong Li * Copyright (C) 2019 SiFive 459c4da86SZong Li */ 559c4da86SZong Li 6de22d210SAtish Patra #include <linux/efi.h> 759c4da86SZong Li #include <linux/init.h> 859c4da86SZong Li #include <linux/debugfs.h> 959c4da86SZong Li #include <linux/seq_file.h> 1059c4da86SZong Li #include <linux/ptdump.h> 1159c4da86SZong Li 1259c4da86SZong Li #include <asm/ptdump.h> 13ca5999fdSMike Rapoport #include <linux/pgtable.h> 1459c4da86SZong Li #include <asm/kasan.h> 1559c4da86SZong Li 1659c4da86SZong Li #define pt_dump_seq_printf(m, fmt, args...) \ 1759c4da86SZong Li ({ \ 1859c4da86SZong Li if (m) \ 1959c4da86SZong Li seq_printf(m, fmt, ##args); \ 2059c4da86SZong Li }) 2159c4da86SZong Li 2259c4da86SZong Li #define pt_dump_seq_puts(m, fmt) \ 2359c4da86SZong Li ({ \ 2459c4da86SZong Li if (m) \ 2559c4da86SZong Li seq_printf(m, fmt); \ 2659c4da86SZong Li }) 2759c4da86SZong Li 2859c4da86SZong Li /* 2959c4da86SZong Li * The page dumper groups page table entries of the same type into a single 3059c4da86SZong Li * description. It uses pg_state to track the range information while 3159c4da86SZong Li * iterating over the pte entries. When the continuity is broken it then 3259c4da86SZong Li * dumps out a description of the range. 3359c4da86SZong Li */ 3459c4da86SZong Li struct pg_state { 3559c4da86SZong Li struct ptdump_state ptdump; 3659c4da86SZong Li struct seq_file *seq; 3759c4da86SZong Li const struct addr_marker *marker; 3859c4da86SZong Li unsigned long start_address; 3959c4da86SZong Li unsigned long start_pa; 4059c4da86SZong Li unsigned long last_pa; 4159c4da86SZong Li int level; 4259c4da86SZong Li u64 current_prot; 4359c4da86SZong Li bool check_wx; 4459c4da86SZong Li unsigned long wx_pages; 4559c4da86SZong Li }; 4659c4da86SZong Li 4759c4da86SZong Li /* Address marker */ 4859c4da86SZong Li struct addr_marker { 4959c4da86SZong Li unsigned long start_address; 5059c4da86SZong Li const char *name; 5159c4da86SZong Li }; 5259c4da86SZong Li 53de22d210SAtish Patra /* Private information for debugfs */ 54de22d210SAtish Patra struct ptd_mm_info { 55de22d210SAtish Patra struct mm_struct *mm; 56de22d210SAtish Patra const struct addr_marker *markers; 57de22d210SAtish Patra unsigned long base_addr; 58de22d210SAtish Patra unsigned long end; 59de22d210SAtish Patra }; 60de22d210SAtish Patra 610df68ce4SAlexandre Ghiti enum address_markers_idx { 620df68ce4SAlexandre Ghiti #ifdef CONFIG_KASAN 630df68ce4SAlexandre Ghiti KASAN_SHADOW_START_NR, 640df68ce4SAlexandre Ghiti KASAN_SHADOW_END_NR, 650df68ce4SAlexandre Ghiti #endif 660df68ce4SAlexandre Ghiti FIXMAP_START_NR, 670df68ce4SAlexandre Ghiti FIXMAP_END_NR, 680df68ce4SAlexandre Ghiti PCI_IO_START_NR, 690df68ce4SAlexandre Ghiti PCI_IO_END_NR, 700df68ce4SAlexandre Ghiti #ifdef CONFIG_SPARSEMEM_VMEMMAP 710df68ce4SAlexandre Ghiti VMEMMAP_START_NR, 720df68ce4SAlexandre Ghiti VMEMMAP_END_NR, 730df68ce4SAlexandre Ghiti #endif 740df68ce4SAlexandre Ghiti VMALLOC_START_NR, 750df68ce4SAlexandre Ghiti VMALLOC_END_NR, 760df68ce4SAlexandre Ghiti PAGE_OFFSET_NR, 770df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 780df68ce4SAlexandre Ghiti MODULES_MAPPING_NR, 790df68ce4SAlexandre Ghiti KERNEL_MAPPING_NR, 8028252e08SAlexandre Ghiti #endif 810df68ce4SAlexandre Ghiti END_OF_SPACE_NR 820df68ce4SAlexandre Ghiti }; 830df68ce4SAlexandre Ghiti 8459c4da86SZong Li static struct addr_marker address_markers[] = { 8559c4da86SZong Li #ifdef CONFIG_KASAN 860df68ce4SAlexandre Ghiti {0, "Kasan shadow start"}, 870df68ce4SAlexandre Ghiti {0, "Kasan shadow end"}, 8859c4da86SZong Li #endif 890df68ce4SAlexandre Ghiti {0, "Fixmap start"}, 900df68ce4SAlexandre Ghiti {0, "Fixmap end"}, 910df68ce4SAlexandre Ghiti {0, "PCI I/O start"}, 920df68ce4SAlexandre Ghiti {0, "PCI I/O end"}, 9359c4da86SZong Li #ifdef CONFIG_SPARSEMEM_VMEMMAP 940df68ce4SAlexandre Ghiti {0, "vmemmap start"}, 950df68ce4SAlexandre Ghiti {0, "vmemmap end"}, 9659c4da86SZong Li #endif 970df68ce4SAlexandre Ghiti {0, "vmalloc() area"}, 980df68ce4SAlexandre Ghiti {0, "vmalloc() end"}, 990df68ce4SAlexandre Ghiti {0, "Linear mapping"}, 1000df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 101*7761e36bSAlexandre Ghiti {0, "Modules/BPF mapping"}, 102*7761e36bSAlexandre Ghiti {0, "Kernel mapping"}, 10328252e08SAlexandre Ghiti #endif 10459c4da86SZong Li {-1, NULL}, 10559c4da86SZong Li }; 10659c4da86SZong Li 107de22d210SAtish Patra static struct ptd_mm_info kernel_ptd_info = { 108de22d210SAtish Patra .mm = &init_mm, 109de22d210SAtish Patra .markers = address_markers, 1100df68ce4SAlexandre Ghiti .base_addr = 0, 111de22d210SAtish Patra .end = ULONG_MAX, 112de22d210SAtish Patra }; 113de22d210SAtish Patra 114de22d210SAtish Patra #ifdef CONFIG_EFI 115de22d210SAtish Patra static struct addr_marker efi_addr_markers[] = { 116de22d210SAtish Patra { 0, "UEFI runtime start" }, 117de22d210SAtish Patra { SZ_1G, "UEFI runtime end" }, 118de22d210SAtish Patra { -1, NULL } 119de22d210SAtish Patra }; 120de22d210SAtish Patra 121de22d210SAtish Patra static struct ptd_mm_info efi_ptd_info = { 122de22d210SAtish Patra .mm = &efi_mm, 123de22d210SAtish Patra .markers = efi_addr_markers, 124de22d210SAtish Patra .base_addr = 0, 125de22d210SAtish Patra .end = SZ_2G, 126de22d210SAtish Patra }; 127de22d210SAtish Patra #endif 128de22d210SAtish Patra 12959c4da86SZong Li /* Page Table Entry */ 13059c4da86SZong Li struct prot_bits { 13159c4da86SZong Li u64 mask; 13259c4da86SZong Li u64 val; 13359c4da86SZong Li const char *set; 13459c4da86SZong Li const char *clear; 13559c4da86SZong Li }; 13659c4da86SZong Li 13759c4da86SZong Li static const struct prot_bits pte_bits[] = { 13859c4da86SZong Li { 13959c4da86SZong Li .mask = _PAGE_SOFT, 14059c4da86SZong Li .val = _PAGE_SOFT, 14159c4da86SZong Li .set = "RSW", 14259c4da86SZong Li .clear = " ", 14359c4da86SZong Li }, { 14459c4da86SZong Li .mask = _PAGE_DIRTY, 14559c4da86SZong Li .val = _PAGE_DIRTY, 14659c4da86SZong Li .set = "D", 14759c4da86SZong Li .clear = ".", 14859c4da86SZong Li }, { 14959c4da86SZong Li .mask = _PAGE_ACCESSED, 15059c4da86SZong Li .val = _PAGE_ACCESSED, 15159c4da86SZong Li .set = "A", 15259c4da86SZong Li .clear = ".", 15359c4da86SZong Li }, { 15459c4da86SZong Li .mask = _PAGE_GLOBAL, 15559c4da86SZong Li .val = _PAGE_GLOBAL, 15659c4da86SZong Li .set = "G", 15759c4da86SZong Li .clear = ".", 15859c4da86SZong Li }, { 15959c4da86SZong Li .mask = _PAGE_USER, 16059c4da86SZong Li .val = _PAGE_USER, 16159c4da86SZong Li .set = "U", 16259c4da86SZong Li .clear = ".", 16359c4da86SZong Li }, { 16459c4da86SZong Li .mask = _PAGE_EXEC, 16559c4da86SZong Li .val = _PAGE_EXEC, 16659c4da86SZong Li .set = "X", 16759c4da86SZong Li .clear = ".", 16859c4da86SZong Li }, { 16959c4da86SZong Li .mask = _PAGE_WRITE, 17059c4da86SZong Li .val = _PAGE_WRITE, 17159c4da86SZong Li .set = "W", 17259c4da86SZong Li .clear = ".", 17359c4da86SZong Li }, { 17459c4da86SZong Li .mask = _PAGE_READ, 17559c4da86SZong Li .val = _PAGE_READ, 17659c4da86SZong Li .set = "R", 17759c4da86SZong Li .clear = ".", 17859c4da86SZong Li }, { 17959c4da86SZong Li .mask = _PAGE_PRESENT, 18059c4da86SZong Li .val = _PAGE_PRESENT, 18159c4da86SZong Li .set = "V", 18259c4da86SZong Li .clear = ".", 18359c4da86SZong Li } 18459c4da86SZong Li }; 18559c4da86SZong Li 18659c4da86SZong Li /* Page Level */ 18759c4da86SZong Li struct pg_level { 18859c4da86SZong Li const char *name; 18959c4da86SZong Li u64 mask; 19059c4da86SZong Li }; 19159c4da86SZong Li 19259c4da86SZong Li static struct pg_level pg_level[] = { 19359c4da86SZong Li { /* pgd */ 19459c4da86SZong Li .name = "PGD", 19559c4da86SZong Li }, { /* p4d */ 19659c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 4) ? "P4D" : "PGD", 19759c4da86SZong Li }, { /* pud */ 19859c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 3) ? "PUD" : "PGD", 19959c4da86SZong Li }, { /* pmd */ 20059c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 2) ? "PMD" : "PGD", 20159c4da86SZong Li }, { /* pte */ 20259c4da86SZong Li .name = "PTE", 20359c4da86SZong Li }, 20459c4da86SZong Li }; 20559c4da86SZong Li 20659c4da86SZong Li static void dump_prot(struct pg_state *st) 20759c4da86SZong Li { 20859c4da86SZong Li unsigned int i; 20959c4da86SZong Li 21059c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pte_bits); i++) { 21159c4da86SZong Li const char *s; 21259c4da86SZong Li 21359c4da86SZong Li if ((st->current_prot & pte_bits[i].mask) == pte_bits[i].val) 21459c4da86SZong Li s = pte_bits[i].set; 21559c4da86SZong Li else 21659c4da86SZong Li s = pte_bits[i].clear; 21759c4da86SZong Li 21859c4da86SZong Li if (s) 21959c4da86SZong Li pt_dump_seq_printf(st->seq, " %s", s); 22059c4da86SZong Li } 22159c4da86SZong Li } 22259c4da86SZong Li 22359c4da86SZong Li #ifdef CONFIG_64BIT 22459c4da86SZong Li #define ADDR_FORMAT "0x%016lx" 22559c4da86SZong Li #else 22659c4da86SZong Li #define ADDR_FORMAT "0x%08lx" 22759c4da86SZong Li #endif 22859c4da86SZong Li static void dump_addr(struct pg_state *st, unsigned long addr) 22959c4da86SZong Li { 23059c4da86SZong Li static const char units[] = "KMGTPE"; 23159c4da86SZong Li const char *unit = units; 23259c4da86SZong Li unsigned long delta; 23359c4da86SZong Li 23459c4da86SZong Li pt_dump_seq_printf(st->seq, ADDR_FORMAT "-" ADDR_FORMAT " ", 23559c4da86SZong Li st->start_address, addr); 23659c4da86SZong Li 23759c4da86SZong Li pt_dump_seq_printf(st->seq, " " ADDR_FORMAT " ", st->start_pa); 23859c4da86SZong Li delta = (addr - st->start_address) >> 10; 23959c4da86SZong Li 24059c4da86SZong Li while (!(delta & 1023) && unit[1]) { 24159c4da86SZong Li delta >>= 10; 24259c4da86SZong Li unit++; 24359c4da86SZong Li } 24459c4da86SZong Li 24559c4da86SZong Li pt_dump_seq_printf(st->seq, "%9lu%c %s", delta, *unit, 24659c4da86SZong Li pg_level[st->level].name); 24759c4da86SZong Li } 24859c4da86SZong Li 24959c4da86SZong Li static void note_prot_wx(struct pg_state *st, unsigned long addr) 25059c4da86SZong Li { 25159c4da86SZong Li if (!st->check_wx) 25259c4da86SZong Li return; 25359c4da86SZong Li 25459c4da86SZong Li if ((st->current_prot & (_PAGE_WRITE | _PAGE_EXEC)) != 25559c4da86SZong Li (_PAGE_WRITE | _PAGE_EXEC)) 25659c4da86SZong Li return; 25759c4da86SZong Li 25859c4da86SZong Li WARN_ONCE(1, "riscv/mm: Found insecure W+X mapping at address %p/%pS\n", 25959c4da86SZong Li (void *)st->start_address, (void *)st->start_address); 26059c4da86SZong Li 26159c4da86SZong Li st->wx_pages += (addr - st->start_address) / PAGE_SIZE; 26259c4da86SZong Li } 26359c4da86SZong Li 26459c4da86SZong Li static void note_page(struct ptdump_state *pt_st, unsigned long addr, 26599395ee3SSteven Price int level, u64 val) 26659c4da86SZong Li { 26759c4da86SZong Li struct pg_state *st = container_of(pt_st, struct pg_state, ptdump); 26859c4da86SZong Li u64 pa = PFN_PHYS(pte_pfn(__pte(val))); 26959c4da86SZong Li u64 prot = 0; 27059c4da86SZong Li 27159c4da86SZong Li if (level >= 0) 27259c4da86SZong Li prot = val & pg_level[level].mask; 27359c4da86SZong Li 27459c4da86SZong Li if (st->level == -1) { 27559c4da86SZong Li st->level = level; 27659c4da86SZong Li st->current_prot = prot; 27759c4da86SZong Li st->start_address = addr; 27859c4da86SZong Li st->start_pa = pa; 27959c4da86SZong Li st->last_pa = pa; 28059c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", st->marker->name); 28159c4da86SZong Li } else if (prot != st->current_prot || 28259c4da86SZong Li level != st->level || addr >= st->marker[1].start_address) { 28359c4da86SZong Li if (st->current_prot) { 28459c4da86SZong Li note_prot_wx(st, addr); 28559c4da86SZong Li dump_addr(st, addr); 28659c4da86SZong Li dump_prot(st); 28759c4da86SZong Li pt_dump_seq_puts(st->seq, "\n"); 28859c4da86SZong Li } 28959c4da86SZong Li 29059c4da86SZong Li while (addr >= st->marker[1].start_address) { 29159c4da86SZong Li st->marker++; 29259c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", 29359c4da86SZong Li st->marker->name); 29459c4da86SZong Li } 29559c4da86SZong Li 29659c4da86SZong Li st->start_address = addr; 29759c4da86SZong Li st->start_pa = pa; 29859c4da86SZong Li st->last_pa = pa; 29959c4da86SZong Li st->current_prot = prot; 30059c4da86SZong Li st->level = level; 30159c4da86SZong Li } else { 30259c4da86SZong Li st->last_pa = pa; 30359c4da86SZong Li } 30459c4da86SZong Li } 30559c4da86SZong Li 306de22d210SAtish Patra static void ptdump_walk(struct seq_file *s, struct ptd_mm_info *pinfo) 30759c4da86SZong Li { 30859c4da86SZong Li struct pg_state st = { 30959c4da86SZong Li .seq = s, 310de22d210SAtish Patra .marker = pinfo->markers, 31159c4da86SZong Li .level = -1, 31259c4da86SZong Li .ptdump = { 31359c4da86SZong Li .note_page = note_page, 31459c4da86SZong Li .range = (struct ptdump_range[]) { 315de22d210SAtish Patra {pinfo->base_addr, pinfo->end}, 31659c4da86SZong Li {0, 0} 31759c4da86SZong Li } 31859c4da86SZong Li } 31959c4da86SZong Li }; 32059c4da86SZong Li 321de22d210SAtish Patra ptdump_walk_pgd(&st.ptdump, pinfo->mm, NULL); 32259c4da86SZong Li } 32359c4da86SZong Li 32459c4da86SZong Li void ptdump_check_wx(void) 32559c4da86SZong Li { 32659c4da86SZong Li struct pg_state st = { 32759c4da86SZong Li .seq = NULL, 32859c4da86SZong Li .marker = (struct addr_marker[]) { 32959c4da86SZong Li {0, NULL}, 33059c4da86SZong Li {-1, NULL}, 33159c4da86SZong Li }, 33259c4da86SZong Li .level = -1, 33359c4da86SZong Li .check_wx = true, 33459c4da86SZong Li .ptdump = { 33559c4da86SZong Li .note_page = note_page, 33659c4da86SZong Li .range = (struct ptdump_range[]) { 33759c4da86SZong Li {KERN_VIRT_START, ULONG_MAX}, 33859c4da86SZong Li {0, 0} 33959c4da86SZong Li } 34059c4da86SZong Li } 34159c4da86SZong Li }; 34259c4da86SZong Li 34359c4da86SZong Li ptdump_walk_pgd(&st.ptdump, &init_mm, NULL); 34459c4da86SZong Li 34559c4da86SZong Li if (st.wx_pages) 34659c4da86SZong Li pr_warn("Checked W+X mappings: failed, %lu W+X pages found\n", 34759c4da86SZong Li st.wx_pages); 34859c4da86SZong Li else 34959c4da86SZong Li pr_info("Checked W+X mappings: passed, no W+X pages found\n"); 35059c4da86SZong Li } 35159c4da86SZong Li 35259c4da86SZong Li static int ptdump_show(struct seq_file *m, void *v) 35359c4da86SZong Li { 354de22d210SAtish Patra ptdump_walk(m, m->private); 35559c4da86SZong Li 35659c4da86SZong Li return 0; 35759c4da86SZong Li } 35859c4da86SZong Li 35959c4da86SZong Li DEFINE_SHOW_ATTRIBUTE(ptdump); 36059c4da86SZong Li 3611987501bSJisheng Zhang static int __init ptdump_init(void) 36259c4da86SZong Li { 36359c4da86SZong Li unsigned int i, j; 36459c4da86SZong Li 3650df68ce4SAlexandre Ghiti #ifdef CONFIG_KASAN 3660df68ce4SAlexandre Ghiti address_markers[KASAN_SHADOW_START_NR].start_address = KASAN_SHADOW_START; 3670df68ce4SAlexandre Ghiti address_markers[KASAN_SHADOW_END_NR].start_address = KASAN_SHADOW_END; 3680df68ce4SAlexandre Ghiti #endif 3690df68ce4SAlexandre Ghiti address_markers[FIXMAP_START_NR].start_address = FIXADDR_START; 3700df68ce4SAlexandre Ghiti address_markers[FIXMAP_END_NR].start_address = FIXADDR_TOP; 3710df68ce4SAlexandre Ghiti address_markers[PCI_IO_START_NR].start_address = PCI_IO_START; 3720df68ce4SAlexandre Ghiti address_markers[PCI_IO_END_NR].start_address = PCI_IO_END; 3730df68ce4SAlexandre Ghiti #ifdef CONFIG_SPARSEMEM_VMEMMAP 3740df68ce4SAlexandre Ghiti address_markers[VMEMMAP_START_NR].start_address = VMEMMAP_START; 3750df68ce4SAlexandre Ghiti address_markers[VMEMMAP_END_NR].start_address = VMEMMAP_END; 3760df68ce4SAlexandre Ghiti #endif 3770df68ce4SAlexandre Ghiti address_markers[VMALLOC_START_NR].start_address = VMALLOC_START; 3780df68ce4SAlexandre Ghiti address_markers[VMALLOC_END_NR].start_address = VMALLOC_END; 3790df68ce4SAlexandre Ghiti address_markers[PAGE_OFFSET_NR].start_address = PAGE_OFFSET; 3800df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 3810df68ce4SAlexandre Ghiti address_markers[MODULES_MAPPING_NR].start_address = MODULES_VADDR; 382658e2c51SAlexandre Ghiti address_markers[KERNEL_MAPPING_NR].start_address = kernel_map.virt_addr; 38328252e08SAlexandre Ghiti #endif 3840df68ce4SAlexandre Ghiti 3850df68ce4SAlexandre Ghiti kernel_ptd_info.base_addr = KERN_VIRT_START; 3860df68ce4SAlexandre Ghiti 38759c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pg_level); i++) 38859c4da86SZong Li for (j = 0; j < ARRAY_SIZE(pte_bits); j++) 38959c4da86SZong Li pg_level[i].mask |= pte_bits[j].mask; 39059c4da86SZong Li 391de22d210SAtish Patra debugfs_create_file("kernel_page_tables", 0400, NULL, &kernel_ptd_info, 39259c4da86SZong Li &ptdump_fops); 393de22d210SAtish Patra #ifdef CONFIG_EFI 394de22d210SAtish Patra if (efi_enabled(EFI_RUNTIME_SERVICES)) 395de22d210SAtish Patra debugfs_create_file("efi_page_tables", 0400, NULL, &efi_ptd_info, 396de22d210SAtish Patra &ptdump_fops); 397de22d210SAtish Patra #endif 39859c4da86SZong Li 39959c4da86SZong Li return 0; 40059c4da86SZong Li } 40159c4da86SZong Li 40259c4da86SZong Li device_initcall(ptdump_init); 403