159c4da86SZong Li // SPDX-License-Identifier: GPL-2.0-only 259c4da86SZong Li /* 359c4da86SZong Li * Copyright (C) 2019 SiFive 459c4da86SZong Li */ 559c4da86SZong Li 6de22d210SAtish Patra #include <linux/efi.h> 759c4da86SZong Li #include <linux/init.h> 859c4da86SZong Li #include <linux/debugfs.h> 959c4da86SZong Li #include <linux/seq_file.h> 1059c4da86SZong Li #include <linux/ptdump.h> 1159c4da86SZong Li 1259c4da86SZong Li #include <asm/ptdump.h> 13ca5999fdSMike Rapoport #include <linux/pgtable.h> 1459c4da86SZong Li #include <asm/kasan.h> 1559c4da86SZong Li 1659c4da86SZong Li #define pt_dump_seq_printf(m, fmt, args...) \ 1759c4da86SZong Li ({ \ 1859c4da86SZong Li if (m) \ 1959c4da86SZong Li seq_printf(m, fmt, ##args); \ 2059c4da86SZong Li }) 2159c4da86SZong Li 2259c4da86SZong Li #define pt_dump_seq_puts(m, fmt) \ 2359c4da86SZong Li ({ \ 2459c4da86SZong Li if (m) \ 2559c4da86SZong Li seq_printf(m, fmt); \ 2659c4da86SZong Li }) 2759c4da86SZong Li 2859c4da86SZong Li /* 2959c4da86SZong Li * The page dumper groups page table entries of the same type into a single 3059c4da86SZong Li * description. It uses pg_state to track the range information while 3159c4da86SZong Li * iterating over the pte entries. When the continuity is broken it then 3259c4da86SZong Li * dumps out a description of the range. 3359c4da86SZong Li */ 3459c4da86SZong Li struct pg_state { 3559c4da86SZong Li struct ptdump_state ptdump; 3659c4da86SZong Li struct seq_file *seq; 3759c4da86SZong Li const struct addr_marker *marker; 3859c4da86SZong Li unsigned long start_address; 3959c4da86SZong Li unsigned long start_pa; 4059c4da86SZong Li unsigned long last_pa; 4159c4da86SZong Li int level; 4259c4da86SZong Li u64 current_prot; 4359c4da86SZong Li bool check_wx; 4459c4da86SZong Li unsigned long wx_pages; 4559c4da86SZong Li }; 4659c4da86SZong Li 4759c4da86SZong Li /* Address marker */ 4859c4da86SZong Li struct addr_marker { 4959c4da86SZong Li unsigned long start_address; 5059c4da86SZong Li const char *name; 5159c4da86SZong Li }; 5259c4da86SZong Li 53de22d210SAtish Patra /* Private information for debugfs */ 54de22d210SAtish Patra struct ptd_mm_info { 55de22d210SAtish Patra struct mm_struct *mm; 56de22d210SAtish Patra const struct addr_marker *markers; 57de22d210SAtish Patra unsigned long base_addr; 58de22d210SAtish Patra unsigned long end; 59de22d210SAtish Patra }; 60de22d210SAtish Patra 610df68ce4SAlexandre Ghiti enum address_markers_idx { 620df68ce4SAlexandre Ghiti FIXMAP_START_NR, 630df68ce4SAlexandre Ghiti FIXMAP_END_NR, 640df68ce4SAlexandre Ghiti PCI_IO_START_NR, 650df68ce4SAlexandre Ghiti PCI_IO_END_NR, 660df68ce4SAlexandre Ghiti #ifdef CONFIG_SPARSEMEM_VMEMMAP 670df68ce4SAlexandre Ghiti VMEMMAP_START_NR, 680df68ce4SAlexandre Ghiti VMEMMAP_END_NR, 690df68ce4SAlexandre Ghiti #endif 700df68ce4SAlexandre Ghiti VMALLOC_START_NR, 710df68ce4SAlexandre Ghiti VMALLOC_END_NR, 720df68ce4SAlexandre Ghiti PAGE_OFFSET_NR, 73ecd7ebafSAlexandre Ghiti #ifdef CONFIG_KASAN 74ecd7ebafSAlexandre Ghiti KASAN_SHADOW_START_NR, 75ecd7ebafSAlexandre Ghiti KASAN_SHADOW_END_NR, 76ecd7ebafSAlexandre Ghiti #endif 770df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 780df68ce4SAlexandre Ghiti MODULES_MAPPING_NR, 790df68ce4SAlexandre Ghiti KERNEL_MAPPING_NR, 8028252e08SAlexandre Ghiti #endif 810df68ce4SAlexandre Ghiti END_OF_SPACE_NR 820df68ce4SAlexandre Ghiti }; 830df68ce4SAlexandre Ghiti 8459c4da86SZong Li static struct addr_marker address_markers[] = { 850df68ce4SAlexandre Ghiti {0, "Fixmap start"}, 860df68ce4SAlexandre Ghiti {0, "Fixmap end"}, 870df68ce4SAlexandre Ghiti {0, "PCI I/O start"}, 880df68ce4SAlexandre Ghiti {0, "PCI I/O end"}, 8959c4da86SZong Li #ifdef CONFIG_SPARSEMEM_VMEMMAP 900df68ce4SAlexandre Ghiti {0, "vmemmap start"}, 910df68ce4SAlexandre Ghiti {0, "vmemmap end"}, 9259c4da86SZong Li #endif 930df68ce4SAlexandre Ghiti {0, "vmalloc() area"}, 940df68ce4SAlexandre Ghiti {0, "vmalloc() end"}, 950df68ce4SAlexandre Ghiti {0, "Linear mapping"}, 96ecd7ebafSAlexandre Ghiti #ifdef CONFIG_KASAN 97ecd7ebafSAlexandre Ghiti {0, "Kasan shadow start"}, 98ecd7ebafSAlexandre Ghiti {0, "Kasan shadow end"}, 99ecd7ebafSAlexandre Ghiti #endif 1000df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 1017761e36bSAlexandre Ghiti {0, "Modules/BPF mapping"}, 1027761e36bSAlexandre Ghiti {0, "Kernel mapping"}, 10328252e08SAlexandre Ghiti #endif 10459c4da86SZong Li {-1, NULL}, 10559c4da86SZong Li }; 10659c4da86SZong Li 107de22d210SAtish Patra static struct ptd_mm_info kernel_ptd_info = { 108de22d210SAtish Patra .mm = &init_mm, 109de22d210SAtish Patra .markers = address_markers, 1100df68ce4SAlexandre Ghiti .base_addr = 0, 111de22d210SAtish Patra .end = ULONG_MAX, 112de22d210SAtish Patra }; 113de22d210SAtish Patra 114de22d210SAtish Patra #ifdef CONFIG_EFI 115de22d210SAtish Patra static struct addr_marker efi_addr_markers[] = { 116de22d210SAtish Patra { 0, "UEFI runtime start" }, 117de22d210SAtish Patra { SZ_1G, "UEFI runtime end" }, 118de22d210SAtish Patra { -1, NULL } 119de22d210SAtish Patra }; 120de22d210SAtish Patra 121de22d210SAtish Patra static struct ptd_mm_info efi_ptd_info = { 122de22d210SAtish Patra .mm = &efi_mm, 123de22d210SAtish Patra .markers = efi_addr_markers, 124de22d210SAtish Patra .base_addr = 0, 125de22d210SAtish Patra .end = SZ_2G, 126de22d210SAtish Patra }; 127de22d210SAtish Patra #endif 128de22d210SAtish Patra 12959c4da86SZong Li /* Page Table Entry */ 13059c4da86SZong Li struct prot_bits { 13159c4da86SZong Li u64 mask; 13259c4da86SZong Li const char *set; 13359c4da86SZong Li const char *clear; 13459c4da86SZong Li }; 13559c4da86SZong Li 13659c4da86SZong Li static const struct prot_bits pte_bits[] = { 13759c4da86SZong Li { 13859c4da86SZong Li .mask = _PAGE_SOFT, 139*d5d2c264SYu Chien Peter Lin .set = "RSW(%d)", 140*d5d2c264SYu Chien Peter Lin .clear = " .. ", 14159c4da86SZong Li }, { 14259c4da86SZong Li .mask = _PAGE_DIRTY, 14359c4da86SZong Li .set = "D", 14459c4da86SZong Li .clear = ".", 14559c4da86SZong Li }, { 14659c4da86SZong Li .mask = _PAGE_ACCESSED, 14759c4da86SZong Li .set = "A", 14859c4da86SZong Li .clear = ".", 14959c4da86SZong Li }, { 15059c4da86SZong Li .mask = _PAGE_GLOBAL, 15159c4da86SZong Li .set = "G", 15259c4da86SZong Li .clear = ".", 15359c4da86SZong Li }, { 15459c4da86SZong Li .mask = _PAGE_USER, 15559c4da86SZong Li .set = "U", 15659c4da86SZong Li .clear = ".", 15759c4da86SZong Li }, { 15859c4da86SZong Li .mask = _PAGE_EXEC, 15959c4da86SZong Li .set = "X", 16059c4da86SZong Li .clear = ".", 16159c4da86SZong Li }, { 16259c4da86SZong Li .mask = _PAGE_WRITE, 16359c4da86SZong Li .set = "W", 16459c4da86SZong Li .clear = ".", 16559c4da86SZong Li }, { 16659c4da86SZong Li .mask = _PAGE_READ, 16759c4da86SZong Li .set = "R", 16859c4da86SZong Li .clear = ".", 16959c4da86SZong Li }, { 17059c4da86SZong Li .mask = _PAGE_PRESENT, 17159c4da86SZong Li .set = "V", 17259c4da86SZong Li .clear = ".", 17359c4da86SZong Li } 17459c4da86SZong Li }; 17559c4da86SZong Li 17659c4da86SZong Li /* Page Level */ 17759c4da86SZong Li struct pg_level { 17859c4da86SZong Li const char *name; 17959c4da86SZong Li u64 mask; 18059c4da86SZong Li }; 18159c4da86SZong Li 18259c4da86SZong Li static struct pg_level pg_level[] = { 18359c4da86SZong Li { /* pgd */ 18459c4da86SZong Li .name = "PGD", 18559c4da86SZong Li }, { /* p4d */ 18659c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 4) ? "P4D" : "PGD", 18759c4da86SZong Li }, { /* pud */ 18859c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 3) ? "PUD" : "PGD", 18959c4da86SZong Li }, { /* pmd */ 19059c4da86SZong Li .name = (CONFIG_PGTABLE_LEVELS > 2) ? "PMD" : "PGD", 19159c4da86SZong Li }, { /* pte */ 19259c4da86SZong Li .name = "PTE", 19359c4da86SZong Li }, 19459c4da86SZong Li }; 19559c4da86SZong Li 19659c4da86SZong Li static void dump_prot(struct pg_state *st) 19759c4da86SZong Li { 19859c4da86SZong Li unsigned int i; 19959c4da86SZong Li 20059c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pte_bits); i++) { 201*d5d2c264SYu Chien Peter Lin char s[7]; 202*d5d2c264SYu Chien Peter Lin unsigned long val; 20359c4da86SZong Li 204*d5d2c264SYu Chien Peter Lin val = st->current_prot & pte_bits[i].mask; 205*d5d2c264SYu Chien Peter Lin if (val) { 206*d5d2c264SYu Chien Peter Lin if (pte_bits[i].mask == _PAGE_SOFT) 207*d5d2c264SYu Chien Peter Lin sprintf(s, pte_bits[i].set, val >> 8); 20859c4da86SZong Li else 209*d5d2c264SYu Chien Peter Lin sprintf(s, "%s", pte_bits[i].set); 210*d5d2c264SYu Chien Peter Lin } else { 211*d5d2c264SYu Chien Peter Lin sprintf(s, "%s", pte_bits[i].clear); 212*d5d2c264SYu Chien Peter Lin } 21359c4da86SZong Li 21459c4da86SZong Li pt_dump_seq_printf(st->seq, " %s", s); 21559c4da86SZong Li } 21659c4da86SZong Li } 21759c4da86SZong Li 21859c4da86SZong Li #ifdef CONFIG_64BIT 21959c4da86SZong Li #define ADDR_FORMAT "0x%016lx" 22059c4da86SZong Li #else 22159c4da86SZong Li #define ADDR_FORMAT "0x%08lx" 22259c4da86SZong Li #endif 22359c4da86SZong Li static void dump_addr(struct pg_state *st, unsigned long addr) 22459c4da86SZong Li { 22559c4da86SZong Li static const char units[] = "KMGTPE"; 22659c4da86SZong Li const char *unit = units; 22759c4da86SZong Li unsigned long delta; 22859c4da86SZong Li 22959c4da86SZong Li pt_dump_seq_printf(st->seq, ADDR_FORMAT "-" ADDR_FORMAT " ", 23059c4da86SZong Li st->start_address, addr); 23159c4da86SZong Li 23259c4da86SZong Li pt_dump_seq_printf(st->seq, " " ADDR_FORMAT " ", st->start_pa); 23359c4da86SZong Li delta = (addr - st->start_address) >> 10; 23459c4da86SZong Li 23559c4da86SZong Li while (!(delta & 1023) && unit[1]) { 23659c4da86SZong Li delta >>= 10; 23759c4da86SZong Li unit++; 23859c4da86SZong Li } 23959c4da86SZong Li 24059c4da86SZong Li pt_dump_seq_printf(st->seq, "%9lu%c %s", delta, *unit, 24159c4da86SZong Li pg_level[st->level].name); 24259c4da86SZong Li } 24359c4da86SZong Li 24459c4da86SZong Li static void note_prot_wx(struct pg_state *st, unsigned long addr) 24559c4da86SZong Li { 24659c4da86SZong Li if (!st->check_wx) 24759c4da86SZong Li return; 24859c4da86SZong Li 24959c4da86SZong Li if ((st->current_prot & (_PAGE_WRITE | _PAGE_EXEC)) != 25059c4da86SZong Li (_PAGE_WRITE | _PAGE_EXEC)) 25159c4da86SZong Li return; 25259c4da86SZong Li 25359c4da86SZong Li WARN_ONCE(1, "riscv/mm: Found insecure W+X mapping at address %p/%pS\n", 25459c4da86SZong Li (void *)st->start_address, (void *)st->start_address); 25559c4da86SZong Li 25659c4da86SZong Li st->wx_pages += (addr - st->start_address) / PAGE_SIZE; 25759c4da86SZong Li } 25859c4da86SZong Li 25959c4da86SZong Li static void note_page(struct ptdump_state *pt_st, unsigned long addr, 26099395ee3SSteven Price int level, u64 val) 26159c4da86SZong Li { 26259c4da86SZong Li struct pg_state *st = container_of(pt_st, struct pg_state, ptdump); 26359c4da86SZong Li u64 pa = PFN_PHYS(pte_pfn(__pte(val))); 26459c4da86SZong Li u64 prot = 0; 26559c4da86SZong Li 26659c4da86SZong Li if (level >= 0) 26759c4da86SZong Li prot = val & pg_level[level].mask; 26859c4da86SZong Li 26959c4da86SZong Li if (st->level == -1) { 27059c4da86SZong Li st->level = level; 27159c4da86SZong Li st->current_prot = prot; 27259c4da86SZong Li st->start_address = addr; 27359c4da86SZong Li st->start_pa = pa; 27459c4da86SZong Li st->last_pa = pa; 27559c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", st->marker->name); 27659c4da86SZong Li } else if (prot != st->current_prot || 27759c4da86SZong Li level != st->level || addr >= st->marker[1].start_address) { 27859c4da86SZong Li if (st->current_prot) { 27959c4da86SZong Li note_prot_wx(st, addr); 28059c4da86SZong Li dump_addr(st, addr); 28159c4da86SZong Li dump_prot(st); 28259c4da86SZong Li pt_dump_seq_puts(st->seq, "\n"); 28359c4da86SZong Li } 28459c4da86SZong Li 28559c4da86SZong Li while (addr >= st->marker[1].start_address) { 28659c4da86SZong Li st->marker++; 28759c4da86SZong Li pt_dump_seq_printf(st->seq, "---[ %s ]---\n", 28859c4da86SZong Li st->marker->name); 28959c4da86SZong Li } 29059c4da86SZong Li 29159c4da86SZong Li st->start_address = addr; 29259c4da86SZong Li st->start_pa = pa; 29359c4da86SZong Li st->last_pa = pa; 29459c4da86SZong Li st->current_prot = prot; 29559c4da86SZong Li st->level = level; 29659c4da86SZong Li } else { 29759c4da86SZong Li st->last_pa = pa; 29859c4da86SZong Li } 29959c4da86SZong Li } 30059c4da86SZong Li 301de22d210SAtish Patra static void ptdump_walk(struct seq_file *s, struct ptd_mm_info *pinfo) 30259c4da86SZong Li { 30359c4da86SZong Li struct pg_state st = { 30459c4da86SZong Li .seq = s, 305de22d210SAtish Patra .marker = pinfo->markers, 30659c4da86SZong Li .level = -1, 30759c4da86SZong Li .ptdump = { 30859c4da86SZong Li .note_page = note_page, 30959c4da86SZong Li .range = (struct ptdump_range[]) { 310de22d210SAtish Patra {pinfo->base_addr, pinfo->end}, 31159c4da86SZong Li {0, 0} 31259c4da86SZong Li } 31359c4da86SZong Li } 31459c4da86SZong Li }; 31559c4da86SZong Li 316de22d210SAtish Patra ptdump_walk_pgd(&st.ptdump, pinfo->mm, NULL); 31759c4da86SZong Li } 31859c4da86SZong Li 31959c4da86SZong Li void ptdump_check_wx(void) 32059c4da86SZong Li { 32159c4da86SZong Li struct pg_state st = { 32259c4da86SZong Li .seq = NULL, 32359c4da86SZong Li .marker = (struct addr_marker[]) { 32459c4da86SZong Li {0, NULL}, 32559c4da86SZong Li {-1, NULL}, 32659c4da86SZong Li }, 32759c4da86SZong Li .level = -1, 32859c4da86SZong Li .check_wx = true, 32959c4da86SZong Li .ptdump = { 33059c4da86SZong Li .note_page = note_page, 33159c4da86SZong Li .range = (struct ptdump_range[]) { 33259c4da86SZong Li {KERN_VIRT_START, ULONG_MAX}, 33359c4da86SZong Li {0, 0} 33459c4da86SZong Li } 33559c4da86SZong Li } 33659c4da86SZong Li }; 33759c4da86SZong Li 33859c4da86SZong Li ptdump_walk_pgd(&st.ptdump, &init_mm, NULL); 33959c4da86SZong Li 34059c4da86SZong Li if (st.wx_pages) 34159c4da86SZong Li pr_warn("Checked W+X mappings: failed, %lu W+X pages found\n", 34259c4da86SZong Li st.wx_pages); 34359c4da86SZong Li else 34459c4da86SZong Li pr_info("Checked W+X mappings: passed, no W+X pages found\n"); 34559c4da86SZong Li } 34659c4da86SZong Li 34759c4da86SZong Li static int ptdump_show(struct seq_file *m, void *v) 34859c4da86SZong Li { 349de22d210SAtish Patra ptdump_walk(m, m->private); 35059c4da86SZong Li 35159c4da86SZong Li return 0; 35259c4da86SZong Li } 35359c4da86SZong Li 35459c4da86SZong Li DEFINE_SHOW_ATTRIBUTE(ptdump); 35559c4da86SZong Li 3561987501bSJisheng Zhang static int __init ptdump_init(void) 35759c4da86SZong Li { 35859c4da86SZong Li unsigned int i, j; 35959c4da86SZong Li 3600df68ce4SAlexandre Ghiti address_markers[FIXMAP_START_NR].start_address = FIXADDR_START; 3610df68ce4SAlexandre Ghiti address_markers[FIXMAP_END_NR].start_address = FIXADDR_TOP; 3620df68ce4SAlexandre Ghiti address_markers[PCI_IO_START_NR].start_address = PCI_IO_START; 3630df68ce4SAlexandre Ghiti address_markers[PCI_IO_END_NR].start_address = PCI_IO_END; 3640df68ce4SAlexandre Ghiti #ifdef CONFIG_SPARSEMEM_VMEMMAP 3650df68ce4SAlexandre Ghiti address_markers[VMEMMAP_START_NR].start_address = VMEMMAP_START; 3660df68ce4SAlexandre Ghiti address_markers[VMEMMAP_END_NR].start_address = VMEMMAP_END; 3670df68ce4SAlexandre Ghiti #endif 3680df68ce4SAlexandre Ghiti address_markers[VMALLOC_START_NR].start_address = VMALLOC_START; 3690df68ce4SAlexandre Ghiti address_markers[VMALLOC_END_NR].start_address = VMALLOC_END; 3700df68ce4SAlexandre Ghiti address_markers[PAGE_OFFSET_NR].start_address = PAGE_OFFSET; 371ecd7ebafSAlexandre Ghiti #ifdef CONFIG_KASAN 372ecd7ebafSAlexandre Ghiti address_markers[KASAN_SHADOW_START_NR].start_address = KASAN_SHADOW_START; 373ecd7ebafSAlexandre Ghiti address_markers[KASAN_SHADOW_END_NR].start_address = KASAN_SHADOW_END; 374ecd7ebafSAlexandre Ghiti #endif 3750df68ce4SAlexandre Ghiti #ifdef CONFIG_64BIT 3760df68ce4SAlexandre Ghiti address_markers[MODULES_MAPPING_NR].start_address = MODULES_VADDR; 377658e2c51SAlexandre Ghiti address_markers[KERNEL_MAPPING_NR].start_address = kernel_map.virt_addr; 37828252e08SAlexandre Ghiti #endif 3790df68ce4SAlexandre Ghiti 3800df68ce4SAlexandre Ghiti kernel_ptd_info.base_addr = KERN_VIRT_START; 3810df68ce4SAlexandre Ghiti 38259c4da86SZong Li for (i = 0; i < ARRAY_SIZE(pg_level); i++) 38359c4da86SZong Li for (j = 0; j < ARRAY_SIZE(pte_bits); j++) 38459c4da86SZong Li pg_level[i].mask |= pte_bits[j].mask; 38559c4da86SZong Li 386de22d210SAtish Patra debugfs_create_file("kernel_page_tables", 0400, NULL, &kernel_ptd_info, 38759c4da86SZong Li &ptdump_fops); 388de22d210SAtish Patra #ifdef CONFIG_EFI 389de22d210SAtish Patra if (efi_enabled(EFI_RUNTIME_SERVICES)) 390de22d210SAtish Patra debugfs_create_file("efi_page_tables", 0400, NULL, &efi_ptd_info, 391de22d210SAtish Patra &ptdump_fops); 392de22d210SAtish Patra #endif 39359c4da86SZong Li 39459c4da86SZong Li return 0; 39559c4da86SZong Li } 39659c4da86SZong Li 39759c4da86SZong Li device_initcall(ptdump_init); 398