Commit 34cfb106 authored by Dave Gerlach's avatar Dave Gerlach Committed by Greg Kroah-Hartman

misc: sram-exec: Use aligned fncpy instead of memcpy

Currently the sram-exec functionality, which allows allocation of
executable memory and provides an API to move code to it, is only
selected in configs for the ARM architecture. Based on commit
5756e9dd ("ARM: 6640/1: Thumb-2: Symbol manipulation macros for
function body copying") simply copying a C function pointer address
using memcpy without consideration of alignment and Thumb is unsafe on
ARM platforms.

The aforementioned patch introduces the fncpy macro which is a safe way
to copy executable code on ARM platforms, so let's make use of that here
rather than the unsafe plain memcpy that was previously used by
sram_exec_copy. Now sram_exec_copy will move the code to "dst" and
return an address that is guaranteed to be safely callable.

In the future, architectures hoping to make use of the sram-exec
functionality must define an fncpy macro just as ARM has done to
guarantee or check for safe copying to executable memory before allowing
the arch to select CONFIG_SRAM_EXEC.
Acked-by: default avatarTony Lindgren <tony@atomide.com>
Acked-by: default avatarRussell King <rmk+kernel@armlinux.org.uk>
Reviewed-by: default avatarAlexandre Belloni <alexandre.belloni@free-electrons.com>
Signed-off-by: default avatarDave Gerlach <d-gerlach@ti.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent a5061d02
...@@ -19,6 +19,7 @@ ...@@ -19,6 +19,7 @@
#include <linux/mm.h> #include <linux/mm.h>
#include <linux/sram.h> #include <linux/sram.h>
#include <asm/fncpy.h>
#include <asm/set_memory.h> #include <asm/set_memory.h>
#include "sram.h" #include "sram.h"
...@@ -58,20 +59,32 @@ int sram_add_protect_exec(struct sram_partition *part) ...@@ -58,20 +59,32 @@ int sram_add_protect_exec(struct sram_partition *part)
* @src: Source address for the data to copy * @src: Source address for the data to copy
* @size: Size of copy to perform, which starting from dst, must reside in pool * @size: Size of copy to perform, which starting from dst, must reside in pool
* *
* Return: Address for copied data that can safely be called through function
* pointer, or NULL if problem.
*
* This helper function allows sram driver to act as central control location * This helper function allows sram driver to act as central control location
* of 'protect-exec' pools which are normal sram pools but are always set * of 'protect-exec' pools which are normal sram pools but are always set
* read-only and executable except when copying data to them, at which point * read-only and executable except when copying data to them, at which point
* they are set to read-write non-executable, to make sure no memory is * they are set to read-write non-executable, to make sure no memory is
* writeable and executable at the same time. This region must be page-aligned * writeable and executable at the same time. This region must be page-aligned
* and is checked during probe, otherwise page attribute manipulation would * and is checked during probe, otherwise page attribute manipulation would
* not be possible. * not be possible. Care must be taken to only call the returned address as
* dst address is not guaranteed to be safely callable.
*
* NOTE: This function uses the fncpy macro to move code to the executable
* region. Some architectures have strict requirements for relocating
* executable code, so fncpy is a macro that must be defined by any arch
* making use of this functionality that guarantees a safe copy of exec
* data and returns a safe address that can be called as a C function
* pointer.
*/ */
int sram_exec_copy(struct gen_pool *pool, void *dst, void *src, void *sram_exec_copy(struct gen_pool *pool, void *dst, void *src,
size_t size) size_t size)
{ {
struct sram_partition *part = NULL, *p; struct sram_partition *part = NULL, *p;
unsigned long base; unsigned long base;
int pages; int pages;
void *dst_cpy;
mutex_lock(&exec_pool_list_mutex); mutex_lock(&exec_pool_list_mutex);
list_for_each_entry(p, &exec_pool_list, list) { list_for_each_entry(p, &exec_pool_list, list) {
...@@ -81,10 +94,10 @@ int sram_exec_copy(struct gen_pool *pool, void *dst, void *src, ...@@ -81,10 +94,10 @@ int sram_exec_copy(struct gen_pool *pool, void *dst, void *src,
mutex_unlock(&exec_pool_list_mutex); mutex_unlock(&exec_pool_list_mutex);
if (!part) if (!part)
return -EINVAL; return NULL;
if (!addr_in_gen_pool(pool, (unsigned long)dst, size)) if (!addr_in_gen_pool(pool, (unsigned long)dst, size))
return -EINVAL; return NULL;
base = (unsigned long)part->base; base = (unsigned long)part->base;
pages = PAGE_ALIGN(size) / PAGE_SIZE; pages = PAGE_ALIGN(size) / PAGE_SIZE;
...@@ -94,13 +107,13 @@ int sram_exec_copy(struct gen_pool *pool, void *dst, void *src, ...@@ -94,13 +107,13 @@ int sram_exec_copy(struct gen_pool *pool, void *dst, void *src,
set_memory_nx((unsigned long)base, pages); set_memory_nx((unsigned long)base, pages);
set_memory_rw((unsigned long)base, pages); set_memory_rw((unsigned long)base, pages);
memcpy(dst, src, size); dst_cpy = fncpy(dst, src, size);
set_memory_ro((unsigned long)base, pages); set_memory_ro((unsigned long)base, pages);
set_memory_x((unsigned long)base, pages); set_memory_x((unsigned long)base, pages);
mutex_unlock(&part->lock); mutex_unlock(&part->lock);
return 0; return dst_cpy;
} }
EXPORT_SYMBOL_GPL(sram_exec_copy); EXPORT_SYMBOL_GPL(sram_exec_copy);
...@@ -16,12 +16,12 @@ ...@@ -16,12 +16,12 @@
struct gen_pool; struct gen_pool;
#ifdef CONFIG_SRAM_EXEC #ifdef CONFIG_SRAM_EXEC
int sram_exec_copy(struct gen_pool *pool, void *dst, void *src, size_t size); void *sram_exec_copy(struct gen_pool *pool, void *dst, void *src, size_t size);
#else #else
static inline int sram_exec_copy(struct gen_pool *pool, void *dst, void *src, static inline void *sram_exec_copy(struct gen_pool *pool, void *dst, void *src,
size_t size) size_t size)
{ {
return -ENODEV; return NULL;
} }
#endif /* CONFIG_SRAM_EXEC */ #endif /* CONFIG_SRAM_EXEC */
#endif /* __LINUX_SRAM_H__ */ #endif /* __LINUX_SRAM_H__ */
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment