Loading...
1// SPDX-License-Identifier: GPL-2.0
2/*
3 * Copyright (C) 2015 Thomas Meyer (thomas@m3y3r.de)
4 * Copyright (C) 2002 - 2007 Jeff Dike (jdike@{addtoit,linux.intel}.com)
5 */
6
7#include <linux/mm.h>
8#include <linux/sched/signal.h>
9#include <linux/slab.h>
10
11#include <asm/pgalloc.h>
12#include <asm/sections.h>
13#include <asm/mmu_context.h>
14#include <as-layout.h>
15#include <os.h>
16#include <skas.h>
17#include <stub-data.h>
18
19/* Ensure the stub_data struct covers the allocated area */
20static_assert(sizeof(struct stub_data) == STUB_DATA_PAGES * UM_KERN_PAGE_SIZE);
21
22int init_new_context(struct task_struct *task, struct mm_struct *mm)
23{
24 struct mm_id *new_id = &mm->context.id;
25 unsigned long stack = 0;
26 int ret = -ENOMEM;
27
28 stack = __get_free_pages(GFP_KERNEL | __GFP_ZERO, ilog2(STUB_DATA_PAGES));
29 if (stack == 0)
30 goto out;
31
32 new_id->stack = stack;
33
34 block_signals_trace();
35 new_id->pid = start_userspace(stack);
36 unblock_signals_trace();
37
38 if (new_id->pid < 0) {
39 ret = new_id->pid;
40 goto out_free;
41 }
42
43 /* Ensure the new MM is clean and nothing unwanted is mapped */
44 unmap(new_id, 0, STUB_START);
45
46 return 0;
47
48 out_free:
49 free_pages(new_id->stack, ilog2(STUB_DATA_PAGES));
50 out:
51 return ret;
52}
53
54void destroy_context(struct mm_struct *mm)
55{
56 struct mm_context *mmu = &mm->context;
57
58 /*
59 * If init_new_context wasn't called, this will be
60 * zero, resulting in a kill(0), which will result in the
61 * whole UML suddenly dying. Also, cover negative and
62 * 1 cases, since they shouldn't happen either.
63 */
64 if (mmu->id.pid < 2) {
65 printk(KERN_ERR "corrupt mm_context - pid = %d\n",
66 mmu->id.pid);
67 return;
68 }
69 os_kill_ptraced_process(mmu->id.pid, 1);
70
71 free_pages(mmu->id.stack, ilog2(STUB_DATA_PAGES));
72}
1/*
2 * Copyright (C) 2002 - 2007 Jeff Dike (jdike@{addtoit,linux.intel}.com)
3 * Licensed under the GPL
4 */
5
6#include "linux/mm.h"
7#include "linux/sched.h"
8#include "linux/slab.h"
9#include "asm/pgalloc.h"
10#include "asm/pgtable.h"
11#include "as-layout.h"
12#include "os.h"
13#include "skas.h"
14
15extern int __syscall_stub_start;
16
17static int init_stub_pte(struct mm_struct *mm, unsigned long proc,
18 unsigned long kernel)
19{
20 pgd_t *pgd;
21 pud_t *pud;
22 pmd_t *pmd;
23 pte_t *pte;
24
25 pgd = pgd_offset(mm, proc);
26 pud = pud_alloc(mm, pgd, proc);
27 if (!pud)
28 goto out;
29
30 pmd = pmd_alloc(mm, pud, proc);
31 if (!pmd)
32 goto out_pmd;
33
34 pte = pte_alloc_map(mm, NULL, pmd, proc);
35 if (!pte)
36 goto out_pte;
37
38 *pte = mk_pte(virt_to_page(kernel), __pgprot(_PAGE_PRESENT));
39 *pte = pte_mkread(*pte);
40 return 0;
41
42 out_pte:
43 pmd_free(mm, pmd);
44 out_pmd:
45 pud_free(mm, pud);
46 out:
47 return -ENOMEM;
48}
49
50int init_new_context(struct task_struct *task, struct mm_struct *mm)
51{
52 struct mm_context *from_mm = NULL;
53 struct mm_context *to_mm = &mm->context;
54 unsigned long stack = 0;
55 int ret = -ENOMEM;
56
57 if (skas_needs_stub) {
58 stack = get_zeroed_page(GFP_KERNEL);
59 if (stack == 0)
60 goto out;
61 }
62
63 to_mm->id.stack = stack;
64 if (current->mm != NULL && current->mm != &init_mm)
65 from_mm = ¤t->mm->context;
66
67 if (proc_mm) {
68 ret = new_mm(stack);
69 if (ret < 0) {
70 printk(KERN_ERR "init_new_context_skas - "
71 "new_mm failed, errno = %d\n", ret);
72 goto out_free;
73 }
74 to_mm->id.u.mm_fd = ret;
75 }
76 else {
77 if (from_mm)
78 to_mm->id.u.pid = copy_context_skas0(stack,
79 from_mm->id.u.pid);
80 else to_mm->id.u.pid = start_userspace(stack);
81
82 if (to_mm->id.u.pid < 0) {
83 ret = to_mm->id.u.pid;
84 goto out_free;
85 }
86 }
87
88 ret = init_new_ldt(to_mm, from_mm);
89 if (ret < 0) {
90 printk(KERN_ERR "init_new_context_skas - init_ldt"
91 " failed, errno = %d\n", ret);
92 goto out_free;
93 }
94
95 to_mm->stub_pages = NULL;
96
97 return 0;
98
99 out_free:
100 if (to_mm->id.stack != 0)
101 free_page(to_mm->id.stack);
102 out:
103 return ret;
104}
105
106void arch_dup_mmap(struct mm_struct *oldmm, struct mm_struct *mm)
107{
108 struct page **pages;
109 int err, ret;
110
111 if (!skas_needs_stub)
112 return;
113
114 ret = init_stub_pte(mm, STUB_CODE,
115 (unsigned long) &__syscall_stub_start);
116 if (ret)
117 goto out;
118
119 ret = init_stub_pte(mm, STUB_DATA, mm->context.id.stack);
120 if (ret)
121 goto out;
122
123 pages = kmalloc(2 * sizeof(struct page *), GFP_KERNEL);
124 if (pages == NULL) {
125 printk(KERN_ERR "arch_dup_mmap failed to allocate 2 page "
126 "pointers\n");
127 goto out;
128 }
129
130 pages[0] = virt_to_page(&__syscall_stub_start);
131 pages[1] = virt_to_page(mm->context.id.stack);
132 mm->context.stub_pages = pages;
133
134 /* dup_mmap already holds mmap_sem */
135 err = install_special_mapping(mm, STUB_START, STUB_END - STUB_START,
136 VM_READ | VM_MAYREAD | VM_EXEC |
137 VM_MAYEXEC | VM_DONTCOPY, pages);
138 if (err) {
139 printk(KERN_ERR "install_special_mapping returned %d\n", err);
140 goto out_free;
141 }
142 return;
143
144out_free:
145 kfree(pages);
146out:
147 force_sigsegv(SIGSEGV, current);
148}
149
150void arch_exit_mmap(struct mm_struct *mm)
151{
152 pte_t *pte;
153
154 if (mm->context.stub_pages != NULL)
155 kfree(mm->context.stub_pages);
156 pte = virt_to_pte(mm, STUB_CODE);
157 if (pte != NULL)
158 pte_clear(mm, STUB_CODE, pte);
159
160 pte = virt_to_pte(mm, STUB_DATA);
161 if (pte == NULL)
162 return;
163
164 pte_clear(mm, STUB_DATA, pte);
165}
166
167void destroy_context(struct mm_struct *mm)
168{
169 struct mm_context *mmu = &mm->context;
170
171 if (proc_mm)
172 os_close_file(mmu->id.u.mm_fd);
173 else {
174 /*
175 * If init_new_context wasn't called, this will be
176 * zero, resulting in a kill(0), which will result in the
177 * whole UML suddenly dying. Also, cover negative and
178 * 1 cases, since they shouldn't happen either.
179 */
180 if (mmu->id.u.pid < 2) {
181 printk(KERN_ERR "corrupt mm_context - pid = %d\n",
182 mmu->id.u.pid);
183 return;
184 }
185 os_kill_ptraced_process(mmu->id.u.pid, 1);
186 }
187
188 if (skas_needs_stub)
189 free_page(mmu->id.stack);
190
191 free_ldt(mmu);
192}