910e230d5f
Macro symbol_put() is defined as __symbol_put(__stringify(x)) ksym_name = "jiffies" symbol_put(ksym_name) will be resolved as __symbol_put("ksym_name") which is clearly wrong. So symbol_put must be replaced with __symbol_put. When we uninstall hw_breakpoint.ko (rmmod), a kernel bug occurs with the following error: [11381.854152] kernel BUG at kernel/module/main.c:779! [11381.854159] invalid opcode: 0000 [#2] PREEMPT SMP PTI [11381.854163] CPU: 8 PID: 59623 Comm: rmmod Tainted: G D OE 6.2.9-200.fc37.x86_64 #1 [11381.854167] Hardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./B360M-HDV, BIOS P3.20 10/23/2018 [11381.854169] RIP: 0010:__symbol_put+0xa2/0xb0 [11381.854175] Code: 00 e8 92 d2 f7 ff 65 8b 05 c3 2f e6 78 85 c0 74 1b 48 8b 44 24 30 65 48 2b 04 25 28 00 00 00 75 12 48 83 c4 38 c3 cc cc cc cc <0f> 0b 0f 1f 44 00 00 eb de e8 c0 df d8 00 90 90 90 90 90 90 90 90 [11381.854178] RSP: 0018:ffffad8ec6ae7dd0 EFLAGS: 00010246 [11381.854181] RAX: 0000000000000000 RBX: ffffffffc1fd1240 RCX: 000000000000000c [11381.854184] RDX: 000000000000006b RSI: ffffffffc02bf7c7 RDI: ffffffffc1fd001c [11381.854186] RBP: 000055a38b76e7c8 R08: ffffffff871ccfe0 R09: 0000000000000000 [11381.854188] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000 [11381.854190] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 [11381.854192] FS: 00007fbf7c62c740(0000) GS:ffff8c5badc00000(0000) knlGS:0000000000000000 [11381.854195] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [11381.854197] CR2: 000055a38b7793f8 CR3: 0000000363e1e001 CR4: 00000000003726e0 [11381.854200] DR0: ffffffffb3407980 DR1: 0000000000000000 DR2: 0000000000000000 [11381.854202] DR3: 0000000000000000 DR6: 00000000ffff0ff0 DR7: 0000000000000400 [11381.854204] Call Trace: [11381.854207] <TASK> [11381.854212] s_module_exit+0xc/0xff0 [symbol_getput] [11381.854219] __do_sys_delete_module.constprop.0+0x198/0x2f0 [11381.854225] do_syscall_64+0x58/0x80 [11381.854231] ? exit_to_user_mode_prepare+0x180/0x1f0 [11381.854237] ? syscall_exit_to_user_mode+0x17/0x40 [11381.854241] ? do_syscall_64+0x67/0x80 [11381.854245] ? syscall_exit_to_user_mode+0x17/0x40 [11381.854248] ? do_syscall_64+0x67/0x80 [11381.854252] ? exc_page_fault+0x70/0x170 [11381.854256] entry_SYSCALL_64_after_hwframe+0x72/0xdc Signed-off-by: Rong Tao <rongtao@cestc.cn> Reviewed-by: Petr Mladek <pmladek@suse.com> Signed-off-by: Luis Chamberlain <mcgrof@kernel.org>
83 lines
2.3 KiB
C
83 lines
2.3 KiB
C
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
/*
|
|
* data_breakpoint.c - Sample HW Breakpoint file to watch kernel data address
|
|
*
|
|
* usage: insmod data_breakpoint.ko ksym=<ksym_name>
|
|
*
|
|
* This file is a kernel module that places a breakpoint over ksym_name kernel
|
|
* variable using Hardware Breakpoint register. The corresponding handler which
|
|
* prints a backtrace is invoked every time a write operation is performed on
|
|
* that variable.
|
|
*
|
|
* Copyright (C) IBM Corporation, 2009
|
|
*
|
|
* Author: K.Prasad <prasad@linux.vnet.ibm.com>
|
|
*/
|
|
#include <linux/module.h> /* Needed by all modules */
|
|
#include <linux/kernel.h> /* Needed for KERN_INFO */
|
|
#include <linux/init.h> /* Needed for the macros */
|
|
#include <linux/kallsyms.h>
|
|
|
|
#include <linux/perf_event.h>
|
|
#include <linux/hw_breakpoint.h>
|
|
|
|
struct perf_event * __percpu *sample_hbp;
|
|
|
|
static char ksym_name[KSYM_NAME_LEN] = "jiffies";
|
|
module_param_string(ksym, ksym_name, KSYM_NAME_LEN, S_IRUGO);
|
|
MODULE_PARM_DESC(ksym, "Kernel symbol to monitor; this module will report any"
|
|
" write operations on the kernel symbol");
|
|
|
|
static void sample_hbp_handler(struct perf_event *bp,
|
|
struct perf_sample_data *data,
|
|
struct pt_regs *regs)
|
|
{
|
|
printk(KERN_INFO "%s value is changed\n", ksym_name);
|
|
dump_stack();
|
|
printk(KERN_INFO "Dump stack from sample_hbp_handler\n");
|
|
}
|
|
|
|
static int __init hw_break_module_init(void)
|
|
{
|
|
int ret;
|
|
struct perf_event_attr attr;
|
|
void *addr = __symbol_get(ksym_name);
|
|
|
|
if (!addr)
|
|
return -ENXIO;
|
|
|
|
hw_breakpoint_init(&attr);
|
|
attr.bp_addr = (unsigned long)addr;
|
|
attr.bp_len = HW_BREAKPOINT_LEN_4;
|
|
attr.bp_type = HW_BREAKPOINT_W;
|
|
|
|
sample_hbp = register_wide_hw_breakpoint(&attr, sample_hbp_handler, NULL);
|
|
if (IS_ERR((void __force *)sample_hbp)) {
|
|
ret = PTR_ERR((void __force *)sample_hbp);
|
|
goto fail;
|
|
}
|
|
|
|
printk(KERN_INFO "HW Breakpoint for %s write installed\n", ksym_name);
|
|
|
|
return 0;
|
|
|
|
fail:
|
|
printk(KERN_INFO "Breakpoint registration failed\n");
|
|
|
|
return ret;
|
|
}
|
|
|
|
static void __exit hw_break_module_exit(void)
|
|
{
|
|
unregister_wide_hw_breakpoint(sample_hbp);
|
|
__symbol_put(ksym_name);
|
|
printk(KERN_INFO "HW Breakpoint for %s write uninstalled\n", ksym_name);
|
|
}
|
|
|
|
module_init(hw_break_module_init);
|
|
module_exit(hw_break_module_exit);
|
|
|
|
MODULE_LICENSE("GPL");
|
|
MODULE_AUTHOR("K.Prasad");
|
|
MODULE_DESCRIPTION("ksym breakpoint");
|