ee3e2469b3
Since ftrace has trampolines, don't use thunks for the __fentry__ site but instead require that every function called from there includes accounting. This very much includes all the direct-call functions. Additionally, ftrace uses ROP tricks in two places: - return_to_handler(), and - ftrace_regs_caller() when pt_regs->orig_ax is set by a direct-call. return_to_handler() already uses a retpoline to replace an indirect-jump to defeat IBT, since this is a jump-type retpoline, make sure there is no accounting done and ALTERNATIVE the RET into a ret. ftrace_regs_caller() does much the same and gets the same treatment. Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Thomas Gleixner <tglx@linutronix.de> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Link: https://lore.kernel.org/r/20220915111148.927545073@infradead.org
91 lines
2.1 KiB
C
91 lines
2.1 KiB
C
// SPDX-License-Identifier: GPL-2.0-only
|
|
#include <linux/module.h>
|
|
|
|
#include <linux/mm.h> /* for handle_mm_fault() */
|
|
#include <linux/ftrace.h>
|
|
#include <asm/asm-offsets.h>
|
|
#include <asm/nospec-branch.h>
|
|
|
|
extern void my_direct_func(struct vm_area_struct *vma,
|
|
unsigned long address, unsigned int flags);
|
|
|
|
void my_direct_func(struct vm_area_struct *vma,
|
|
unsigned long address, unsigned int flags)
|
|
{
|
|
trace_printk("handle mm fault vma=%p address=%lx flags=%x\n",
|
|
vma, address, flags);
|
|
}
|
|
|
|
extern void my_tramp(void *);
|
|
|
|
#ifdef CONFIG_X86_64
|
|
|
|
#include <asm/ibt.h>
|
|
|
|
asm (
|
|
" .pushsection .text, \"ax\", @progbits\n"
|
|
" .type my_tramp, @function\n"
|
|
" .globl my_tramp\n"
|
|
" my_tramp:"
|
|
ASM_ENDBR
|
|
" pushq %rbp\n"
|
|
" movq %rsp, %rbp\n"
|
|
CALL_DEPTH_ACCOUNT
|
|
" pushq %rdi\n"
|
|
" pushq %rsi\n"
|
|
" pushq %rdx\n"
|
|
" call my_direct_func\n"
|
|
" popq %rdx\n"
|
|
" popq %rsi\n"
|
|
" popq %rdi\n"
|
|
" leave\n"
|
|
ASM_RET
|
|
" .size my_tramp, .-my_tramp\n"
|
|
" .popsection\n"
|
|
);
|
|
|
|
#endif /* CONFIG_X86_64 */
|
|
|
|
#ifdef CONFIG_S390
|
|
|
|
asm (
|
|
" .pushsection .text, \"ax\", @progbits\n"
|
|
" .type my_tramp, @function\n"
|
|
" .globl my_tramp\n"
|
|
" my_tramp:"
|
|
" lgr %r1,%r15\n"
|
|
" stmg %r0,%r5,"__stringify(__SF_GPRS)"(%r15)\n"
|
|
" stg %r14,"__stringify(__SF_GPRS+8*8)"(%r15)\n"
|
|
" aghi %r15,"__stringify(-STACK_FRAME_OVERHEAD)"\n"
|
|
" stg %r1,"__stringify(__SF_BACKCHAIN)"(%r15)\n"
|
|
" brasl %r14,my_direct_func\n"
|
|
" aghi %r15,"__stringify(STACK_FRAME_OVERHEAD)"\n"
|
|
" lmg %r0,%r5,"__stringify(__SF_GPRS)"(%r15)\n"
|
|
" lg %r14,"__stringify(__SF_GPRS+8*8)"(%r15)\n"
|
|
" lgr %r1,%r0\n"
|
|
" br %r1\n"
|
|
" .size my_tramp, .-my_tramp\n"
|
|
" .popsection\n"
|
|
);
|
|
|
|
#endif /* CONFIG_S390 */
|
|
|
|
static int __init ftrace_direct_init(void)
|
|
{
|
|
return register_ftrace_direct((unsigned long)handle_mm_fault,
|
|
(unsigned long)my_tramp);
|
|
}
|
|
|
|
static void __exit ftrace_direct_exit(void)
|
|
{
|
|
unregister_ftrace_direct((unsigned long)handle_mm_fault,
|
|
(unsigned long)my_tramp);
|
|
}
|
|
|
|
module_init(ftrace_direct_init);
|
|
module_exit(ftrace_direct_exit);
|
|
|
|
MODULE_AUTHOR("Steven Rostedt");
|
|
MODULE_DESCRIPTION("Another example use case of using register_ftrace_direct()");
|
|
MODULE_LICENSE("GPL");
|