From: Frederic Weisbecker <fweisbec@gmail.com>
To: Ingo Molnar <mingo@elte.hu>
Cc: LKML <linux-kernel@vger.kernel.org>,
"Masami Hiramatsu" <mhiramat@redhat.com>,
"Avi Kivity" <avi@redhat.com>, "Andi Kleen" <ak@linux.intel.com>,
"Christoph Hellwig" <hch@infradead.org>,
"Frank Ch. Eigler" <fche@redhat.com>,
"H. Peter Anvin" <hpa@zytor.com>, "Ingo Molnar" <mingo@elte.hu>,
"Jason Baron" <jbaron@redhat.com>,
"Jim Keniston" <jkenisto@us.ibm.com>,
"K.Prasad" <prasad@linux.vnet.ibm.com>,
"Lai Jiangshan" <laijs@cn.fujitsu.com>,
"Li Zefan" <lizf@cn.fujitsu.com>,
"Przemysław Pawełczyk" <przemyslaw@pawelczyk.it>,
"Roland McGrath" <roland@redhat.com>,
"Sam Ravnborg" <sam@ravnborg.org>,
"Srikar Dronamraju" <srikar@linux.vnet.ibm.com>,
"Steven Rostedt" <rostedt@goodmis.org>,
"Tom Zanussi" <tzanussi@gmail.com>,
"Vegard Nossum" <vegard.nossum@gmail.com>,
"Frederic Weisbecker" <fweisbec@gmail.com>
Subject: [PATCH 03/18] kprobes: Checks probe address is instruction boudary on x86
Date: Thu, 27 Aug 2009 04:32:02 +0200 [thread overview]
Message-ID: <1251340337-5640-4-git-send-email-fweisbec@gmail.com> (raw)
In-Reply-To: <1251340337-5640-1-git-send-email-fweisbec@gmail.com>
From: Masami Hiramatsu <mhiramat@redhat.com>
Ensure safeness of inserting kprobes by checking whether the specified
address is at the first byte of an instruction on x86.
This is done by decoding probed function from its head to the probe
point.
Signed-off-by: Masami Hiramatsu <mhiramat@redhat.com>
Acked-by: Ananth N Mavinakayanahalli <ananth@in.ibm.com>
Cc: Avi Kivity <avi@redhat.com>
Cc: Andi Kleen <ak@linux.intel.com>
Cc: Christoph Hellwig <hch@infradead.org>
Cc: Frank Ch. Eigler <fche@redhat.com>
Cc: H. Peter Anvin <hpa@zytor.com>
Cc: Ingo Molnar <mingo@elte.hu>
Cc: Jason Baron <jbaron@redhat.com>
Cc: Jim Keniston <jkenisto@us.ibm.com>
Cc: K.Prasad <prasad@linux.vnet.ibm.com>
Cc: Lai Jiangshan <laijs@cn.fujitsu.com>
Cc: Li Zefan <lizf@cn.fujitsu.com>
Cc: Przemysław Pawełczyk <przemyslaw@pawelczyk.it>
Cc: Roland McGrath <roland@redhat.com>
Cc: Sam Ravnborg <sam@ravnborg.org>
Cc: Srikar Dronamraju <srikar@linux.vnet.ibm.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Tom Zanussi <tzanussi@gmail.com>
Cc: Vegard Nossum <vegard.nossum@gmail.com>
LKML-Reference: <20090813203428.31965.21939.stgit@localhost.localdomain>
Signed-off-by: Frederic Weisbecker <fweisbec@gmail.com>
---
arch/x86/kernel/kprobes.c | 73 +++++++++++++++++++++++++++++++++++++++++++++
1 files changed, 73 insertions(+), 0 deletions(-)
diff --git a/arch/x86/kernel/kprobes.c b/arch/x86/kernel/kprobes.c
index 7b5169d..aa15f3e 100644
--- a/arch/x86/kernel/kprobes.c
+++ b/arch/x86/kernel/kprobes.c
@@ -48,12 +48,14 @@
#include <linux/preempt.h>
#include <linux/module.h>
#include <linux/kdebug.h>
+#include <linux/kallsyms.h>
#include <asm/cacheflush.h>
#include <asm/desc.h>
#include <asm/pgtable.h>
#include <asm/uaccess.h>
#include <asm/alternative.h>
+#include <asm/insn.h>
void jprobe_return_end(void);
@@ -244,6 +246,75 @@ retry:
}
}
+/* Recover the probed instruction at addr for further analysis. */
+static int recover_probed_instruction(kprobe_opcode_t *buf, unsigned long addr)
+{
+ struct kprobe *kp;
+ kp = get_kprobe((void *)addr);
+ if (!kp)
+ return -EINVAL;
+
+ /*
+ * Basically, kp->ainsn.insn has an original instruction.
+ * However, RIP-relative instruction can not do single-stepping
+ * at different place, fix_riprel() tweaks the displacement of
+ * that instruction. In that case, we can't recover the instruction
+ * from the kp->ainsn.insn.
+ *
+ * On the other hand, kp->opcode has a copy of the first byte of
+ * the probed instruction, which is overwritten by int3. And
+ * the instruction at kp->addr is not modified by kprobes except
+ * for the first byte, we can recover the original instruction
+ * from it and kp->opcode.
+ */
+ memcpy(buf, kp->addr, MAX_INSN_SIZE * sizeof(kprobe_opcode_t));
+ buf[0] = kp->opcode;
+ return 0;
+}
+
+/* Dummy buffers for kallsyms_lookup */
+static char __dummy_buf[KSYM_NAME_LEN];
+
+/* Check if paddr is at an instruction boundary */
+static int __kprobes can_probe(unsigned long paddr)
+{
+ int ret;
+ unsigned long addr, offset = 0;
+ struct insn insn;
+ kprobe_opcode_t buf[MAX_INSN_SIZE];
+
+ if (!kallsyms_lookup(paddr, NULL, &offset, NULL, __dummy_buf))
+ return 0;
+
+ /* Decode instructions */
+ addr = paddr - offset;
+ while (addr < paddr) {
+ kernel_insn_init(&insn, (void *)addr);
+ insn_get_opcode(&insn);
+
+ /*
+ * Check if the instruction has been modified by another
+ * kprobe, in which case we replace the breakpoint by the
+ * original instruction in our buffer.
+ */
+ if (insn.opcode.bytes[0] == BREAKPOINT_INSTRUCTION) {
+ ret = recover_probed_instruction(buf, addr);
+ if (ret)
+ /*
+ * Another debugging subsystem might insert
+ * this breakpoint. In that case, we can't
+ * recover it.
+ */
+ return 0;
+ kernel_insn_init(&insn, buf);
+ }
+ insn_get_length(&insn);
+ addr += insn.length;
+ }
+
+ return (addr == paddr);
+}
+
/*
* Returns non-zero if opcode modifies the interrupt flag.
*/
@@ -359,6 +430,8 @@ static void __kprobes arch_copy_kprobe(struct kprobe *p)
int __kprobes arch_prepare_kprobe(struct kprobe *p)
{
+ if (!can_probe((unsigned long)p->addr))
+ return -EILSEQ;
/* insn: must be on special executable page on x86. */
p->ainsn.insn = get_insn_slot();
if (!p->ainsn.insn)
--
1.6.2.3
next prev parent reply other threads:[~2009-08-27 2:32 UTC|newest]
Thread overview: 89+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-08-27 2:31 [GIT PULL] tracing/kprobes: Add dynamic tracepoints + instruction decoder Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 01/18] x86: Instruction decoder API Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 02/18] x86: X86 instruction decoder build-time selftest Frederic Weisbecker
2009-08-27 2:32 ` Frederic Weisbecker [this message]
2009-08-27 2:32 ` [PATCH 04/18] kprobes: Cleanup fix_riprel() using insn decoder on x86 Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 05/18] x86: Add pt_regs register and stack access APIs Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 06/18] tracing: Ftrace dynamic ftrace_event_call support Frederic Weisbecker
2009-08-27 2:47 ` Li Zefan
2009-08-27 2:56 ` Frederic Weisbecker
2009-08-27 15:07 ` Masami Hiramatsu
2009-08-27 2:32 ` [PATCH 07/18] tracing: Introduce TRACE_FIELD_ZERO() macro Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 08/18] tracing: Add kprobe-based event tracer Frederic Weisbecker
2009-08-27 7:31 ` Ingo Molnar
2009-08-27 13:48 ` Frederic Weisbecker
2009-08-27 15:38 ` Masami Hiramatsu
2009-08-27 2:32 ` [PATCH 09/18] tracing: Add kprobe-based event tracer documentation Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 10/18] tracing: Kprobe-tracer supports more than 6 arguments Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 11/18] tracing: Generate names for each kprobe event automatically Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 12/18] tracing: Kprobe tracer assigns new event ids for each event Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 13/18] tracing: Add kprobes event profiling interface Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 14/18] x86: Fix x86 instruction decoder selftest to check only .text Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 15/18] x86: Check awk features before generating inat-tables.c Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 16/18] tracing/kprobes: Fix format typo in trace_kprobes Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 17/18] tracing/kprobes: Change trace_arg to probe_arg Frederic Weisbecker
2009-08-27 2:32 ` [PATCH 18/18] tracing/kprobes: Dump the culprit kprobe in case of kprobe recursion Frederic Weisbecker
2009-08-27 15:30 ` Masami Hiramatsu
2009-08-27 15:34 ` Frederic Weisbecker
2009-08-27 15:52 ` Masami Hiramatsu
2009-08-27 16:30 ` Frederic Weisbecker
2009-08-27 16:45 ` Masami Hiramatsu
2009-08-27 16:45 ` Frederic Weisbecker
2009-08-27 3:34 ` [GIT PULL v2] tracing/kprobes: v1 + two fixes Frederic Weisbecker
2009-08-27 15:24 ` Ingo Molnar
2009-08-27 15:40 ` Frederic Weisbecker
2009-08-27 15:59 ` Frederic Weisbecker
2009-08-27 16:17 ` [PATCH] tracing: Undef TRACE_EVENT_FN between trace events headers inclusion Frederic Weisbecker
2009-08-27 16:36 ` [tip:tracing/core] " tip-bot for Frederic Weisbecker
2009-08-27 16:12 ` [GIT PULL v2] tracing/kprobes: v1 + two fixes Masami Hiramatsu
2009-08-27 16:35 ` Ingo Molnar
2009-08-27 16:52 ` Masami Hiramatsu
2009-08-29 11:02 ` Ingo Molnar
2009-08-28 22:13 ` [PATCH -tip tracing/kprobes 1/2] x86: Allow x86-32 instruction decoder selftest on x86-64 Masami Hiramatsu
2009-08-30 1:35 ` Frederic Weisbecker
2009-10-17 9:58 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-28 22:13 ` [PATCH -tip tracing/kprobes 2/2] x86: Remove unused config macros from instruction decoder selftest Masami Hiramatsu
2009-10-17 9:58 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 15:26 ` [GIT PULL v2] tracing/kprobes: v1 + two fixes Ingo Molnar
2009-09-16 5:30 ` Frederic Weisbecker
2009-08-27 3:34 ` [PATCH 19/18] tracing: Restore the const qualifier for field names and types definition Frederic Weisbecker
2009-08-27 15:07 ` Masami Hiramatsu
2009-08-27 3:34 ` [PATCH 20/18] tracing: Remove unneeded pointer casts Frederic Weisbecker
2009-08-27 15:08 ` Masami Hiramatsu
2009-08-27 15:00 ` [GIT PULL] tracing/kprobes: Add dynamic tracepoints + instruction decoder Masami Hiramatsu
2009-08-27 15:25 ` Frederic Weisbecker
2009-08-27 17:22 ` [PATCH -tip tracing/kprobes 1/6] kprobes/x86: Call BUG() when reentering probe into KPROBES_HIT_SS Masami Hiramatsu
2009-08-28 4:38 ` Ananth N Mavinakayanahalli
2009-08-30 1:25 ` Frederic Weisbecker
2009-10-17 9:56 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 17:23 ` [PATCH -tip tracing/kprobes 2/6] kprobes/x86-64: Allow to reenter probe on post_handler Masami Hiramatsu
2009-08-28 4:39 ` Ananth N Mavinakayanahalli
2009-10-17 9:57 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 17:23 ` [PATCH -tip tracing/kprobes 3/6] kprobes/x86: Fix to add __kprobes to in-kernel fault handing functions Masami Hiramatsu
2009-08-28 4:40 ` Ananth N Mavinakayanahalli
2009-08-30 0:50 ` Frederic Weisbecker
2009-08-30 2:43 ` Masami Hiramatsu
2009-08-30 0:53 ` Frederic Weisbecker
2009-08-30 2:49 ` Masami Hiramatsu
2009-08-30 16:09 ` Frederic Weisbecker
2009-08-31 4:00 ` Masami Hiramatsu
2009-09-01 20:09 ` Masami Hiramatsu
2009-09-02 12:58 ` Masami Hiramatsu
2009-09-03 5:46 ` Frederic Weisbecker
2009-09-04 19:06 ` Frederic Weisbecker
2009-09-04 22:29 ` Masami Hiramatsu
2009-09-08 16:32 ` [PATCH tracing/kprobes] x86: Add MMX support for instruction decoder Masami Hiramatsu
2009-09-10 22:57 ` Frederic Weisbecker
2009-10-17 9:58 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-09-08 16:54 ` [RFC PATCH tracing/kprobes] kprobes: Call vmalloc_sync_all() for avoiding in-kernel paging on kprobes Masami Hiramatsu
[not found] ` <20090908165438.24437.40931.stgit@dhcp-100-2-132.bos.redhat .com>
2009-09-08 17:03 ` system hang - I suspect a sata problem - 2.6.30.5 debug kernel jeffunit
2009-10-17 9:57 ` [tip:perf/probes] kprobes/x86: Fix to add __kprobes to in-kernel fault handing functions tip-bot for Masami Hiramatsu
2009-08-27 17:23 ` [PATCH -tip tracing/kprobes 4/6] kprobes: Fix to add __kprobes to notify_die Masami Hiramatsu
2009-08-28 4:41 ` Ananth N Mavinakayanahalli
2009-10-17 9:57 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 17:23 ` [PATCH -tip tracing/kprobes 5/6] kprobes/x86-64: Fix to move common_interrupt to .kprobes.text Masami Hiramatsu
2009-10-17 9:57 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 17:23 ` [PATCH -tip tracing/kprobes 6/6] kprobes: Prohibit to probe native_get_debugreg Masami Hiramatsu
2009-08-28 4:41 ` Ananth N Mavinakayanahalli
2009-10-17 9:57 ` [tip:perf/probes] " tip-bot for Masami Hiramatsu
2009-08-27 17:32 ` [GIT PULL] tracing/kprobes: Add dynamic tracepoints + instruction decoder Masami Hiramatsu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1251340337-5640-4-git-send-email-fweisbec@gmail.com \
--to=fweisbec@gmail.com \
--cc=ak@linux.intel.com \
--cc=avi@redhat.com \
--cc=fche@redhat.com \
--cc=hch@infradead.org \
--cc=hpa@zytor.com \
--cc=jbaron@redhat.com \
--cc=jkenisto@us.ibm.com \
--cc=laijs@cn.fujitsu.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lizf@cn.fujitsu.com \
--cc=mhiramat@redhat.com \
--cc=mingo@elte.hu \
--cc=prasad@linux.vnet.ibm.com \
--cc=przemyslaw@pawelczyk.it \
--cc=roland@redhat.com \
--cc=rostedt@goodmis.org \
--cc=sam@ravnborg.org \
--cc=srikar@linux.vnet.ibm.com \
--cc=tzanussi@gmail.com \
--cc=vegard.nossum@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®