page_table_check.c 5.8 KB
Newer Older
Pasha Tatashin's avatar
Pasha Tatashin committed
1 2 3 4 5 6
// SPDX-License-Identifier: GPL-2.0

/*
 * Copyright (c) 2021, Google LLC.
 * Pasha Tatashin <pasha.tatashin@soleen.com>
 */
7
#include <linux/kstrtox.h>
Pasha Tatashin's avatar
Pasha Tatashin committed
8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26
#include <linux/mm.h>
#include <linux/page_table_check.h>

#undef pr_fmt
#define pr_fmt(fmt)	"page_table_check: " fmt

struct page_table_check {
	atomic_t anon_map_count;
	atomic_t file_map_count;
};

static bool __page_table_check_enabled __initdata =
				IS_ENABLED(CONFIG_PAGE_TABLE_CHECK_ENFORCED);

DEFINE_STATIC_KEY_TRUE(page_table_check_disabled);
EXPORT_SYMBOL(page_table_check_disabled);

static int __init early_page_table_check_param(char *buf)
{
27
	return kstrtobool(buf, &__page_table_check_enabled);
Pasha Tatashin's avatar
Pasha Tatashin committed
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
}

early_param("page_table_check", early_page_table_check_param);

static bool __init need_page_table_check(void)
{
	return __page_table_check_enabled;
}

static void __init init_page_table_check(void)
{
	if (!__page_table_check_enabled)
		return;
	static_branch_disable(&page_table_check_disabled);
}

struct page_ext_operations page_table_check_ops = {
	.size = sizeof(struct page_table_check),
	.need = need_page_table_check,
	.init = init_page_table_check,
48
	.need_shared_flags = false,
Pasha Tatashin's avatar
Pasha Tatashin committed
49 50 51 52 53 54 55 56 57
};

static struct page_table_check *get_page_table_check(struct page_ext *page_ext)
{
	BUG_ON(!page_ext);
	return (void *)(page_ext) + page_table_check_ops.offset;
}

/*
58
 * An entry is removed from the page table, decrement the counters for that page
Pasha Tatashin's avatar
Pasha Tatashin committed
59 60
 * verify that it is of correct type and counters do not become negative.
 */
61
static void page_table_check_clear(unsigned long pfn, unsigned long pgcnt)
Pasha Tatashin's avatar
Pasha Tatashin committed
62 63 64
{
	struct page_ext *page_ext;
	struct page *page;
65
	unsigned long i;
Pasha Tatashin's avatar
Pasha Tatashin committed
66 67 68 69 70 71
	bool anon;

	if (!pfn_valid(pfn))
		return;

	page = pfn_to_page(pfn);
72
	page_ext = page_ext_get(page);
73 74

	BUG_ON(PageSlab(page));
Pasha Tatashin's avatar
Pasha Tatashin committed
75 76 77 78 79 80 81 82 83 84 85 86 87 88
	anon = PageAnon(page);

	for (i = 0; i < pgcnt; i++) {
		struct page_table_check *ptc = get_page_table_check(page_ext);

		if (anon) {
			BUG_ON(atomic_read(&ptc->file_map_count));
			BUG_ON(atomic_dec_return(&ptc->anon_map_count) < 0);
		} else {
			BUG_ON(atomic_read(&ptc->anon_map_count));
			BUG_ON(atomic_dec_return(&ptc->file_map_count) < 0);
		}
		page_ext = page_ext_next(page_ext);
	}
89
	page_ext_put(page_ext);
Pasha Tatashin's avatar
Pasha Tatashin committed
90 91 92
}

/*
93
 * A new entry is added to the page table, increment the counters for that page
Pasha Tatashin's avatar
Pasha Tatashin committed
94 95 96
 * verify that it is of correct type and is not being mapped with a different
 * type to a different process.
 */
97
static void page_table_check_set(unsigned long pfn, unsigned long pgcnt,
Pasha Tatashin's avatar
Pasha Tatashin committed
98 99 100 101
				 bool rw)
{
	struct page_ext *page_ext;
	struct page *page;
102
	unsigned long i;
Pasha Tatashin's avatar
Pasha Tatashin committed
103 104 105 106 107 108
	bool anon;

	if (!pfn_valid(pfn))
		return;

	page = pfn_to_page(pfn);
109
	page_ext = page_ext_get(page);
110 111

	BUG_ON(PageSlab(page));
Pasha Tatashin's avatar
Pasha Tatashin committed
112 113 114 115 116 117 118 119 120 121 122 123 124 125
	anon = PageAnon(page);

	for (i = 0; i < pgcnt; i++) {
		struct page_table_check *ptc = get_page_table_check(page_ext);

		if (anon) {
			BUG_ON(atomic_read(&ptc->file_map_count));
			BUG_ON(atomic_inc_return(&ptc->anon_map_count) > 1 && rw);
		} else {
			BUG_ON(atomic_read(&ptc->anon_map_count));
			BUG_ON(atomic_inc_return(&ptc->file_map_count) < 0);
		}
		page_ext = page_ext_next(page_ext);
	}
126
	page_ext_put(page_ext);
Pasha Tatashin's avatar
Pasha Tatashin committed
127 128 129 130 131 132 133 134
}

/*
 * page is on free list, or is being allocated, verify that counters are zeroes
 * crash if they are not.
 */
void __page_table_check_zero(struct page *page, unsigned int order)
{
135
	struct page_ext *page_ext;
136
	unsigned long i;
Pasha Tatashin's avatar
Pasha Tatashin committed
137

138 139
	BUG_ON(PageSlab(page));

140
	page_ext = page_ext_get(page);
Pasha Tatashin's avatar
Pasha Tatashin committed
141
	BUG_ON(!page_ext);
142
	for (i = 0; i < (1ul << order); i++) {
Pasha Tatashin's avatar
Pasha Tatashin committed
143 144 145 146 147 148
		struct page_table_check *ptc = get_page_table_check(page_ext);

		BUG_ON(atomic_read(&ptc->anon_map_count));
		BUG_ON(atomic_read(&ptc->file_map_count));
		page_ext = page_ext_next(page_ext);
	}
149
	page_ext_put(page_ext);
Pasha Tatashin's avatar
Pasha Tatashin committed
150 151
}

152
void __page_table_check_pte_clear(struct mm_struct *mm, pte_t pte)
Pasha Tatashin's avatar
Pasha Tatashin committed
153 154 155 156 157
{
	if (&init_mm == mm)
		return;

	if (pte_user_accessible_page(pte)) {
158
		page_table_check_clear(pte_pfn(pte), PAGE_SIZE >> PAGE_SHIFT);
Pasha Tatashin's avatar
Pasha Tatashin committed
159 160 161 162
	}
}
EXPORT_SYMBOL(__page_table_check_pte_clear);

163
void __page_table_check_pmd_clear(struct mm_struct *mm, pmd_t pmd)
Pasha Tatashin's avatar
Pasha Tatashin committed
164 165 166 167 168
{
	if (&init_mm == mm)
		return;

	if (pmd_user_accessible_page(pmd)) {
169
		page_table_check_clear(pmd_pfn(pmd), PMD_SIZE >> PAGE_SHIFT);
Pasha Tatashin's avatar
Pasha Tatashin committed
170 171 172 173
	}
}
EXPORT_SYMBOL(__page_table_check_pmd_clear);

174
void __page_table_check_pud_clear(struct mm_struct *mm, pud_t pud)
Pasha Tatashin's avatar
Pasha Tatashin committed
175 176 177 178 179
{
	if (&init_mm == mm)
		return;

	if (pud_user_accessible_page(pud)) {
180
		page_table_check_clear(pud_pfn(pud), PUD_SIZE >> PAGE_SHIFT);
Pasha Tatashin's avatar
Pasha Tatashin committed
181 182 183 184 185 186 187 188 189 190
	}
}
EXPORT_SYMBOL(__page_table_check_pud_clear);

void __page_table_check_pte_set(struct mm_struct *mm, unsigned long addr,
				pte_t *ptep, pte_t pte)
{
	if (&init_mm == mm)
		return;

191
	__page_table_check_pte_clear(mm, ptep_get(ptep));
Pasha Tatashin's avatar
Pasha Tatashin committed
192
	if (pte_user_accessible_page(pte)) {
193
		page_table_check_set(pte_pfn(pte), PAGE_SIZE >> PAGE_SHIFT,
Pasha Tatashin's avatar
Pasha Tatashin committed
194 195 196 197 198 199 200 201 202 203 204
				     pte_write(pte));
	}
}
EXPORT_SYMBOL(__page_table_check_pte_set);

void __page_table_check_pmd_set(struct mm_struct *mm, unsigned long addr,
				pmd_t *pmdp, pmd_t pmd)
{
	if (&init_mm == mm)
		return;

205
	__page_table_check_pmd_clear(mm, *pmdp);
Pasha Tatashin's avatar
Pasha Tatashin committed
206
	if (pmd_user_accessible_page(pmd)) {
207
		page_table_check_set(pmd_pfn(pmd), PMD_SIZE >> PAGE_SHIFT,
Pasha Tatashin's avatar
Pasha Tatashin committed
208 209 210 211 212 213 214 215 216 217 218
				     pmd_write(pmd));
	}
}
EXPORT_SYMBOL(__page_table_check_pmd_set);

void __page_table_check_pud_set(struct mm_struct *mm, unsigned long addr,
				pud_t *pudp, pud_t pud)
{
	if (&init_mm == mm)
		return;

219
	__page_table_check_pud_clear(mm, *pudp);
Pasha Tatashin's avatar
Pasha Tatashin committed
220
	if (pud_user_accessible_page(pud)) {
221
		page_table_check_set(pud_pfn(pud), PUD_SIZE >> PAGE_SHIFT,
Pasha Tatashin's avatar
Pasha Tatashin committed
222 223 224 225
				     pud_write(pud));
	}
}
EXPORT_SYMBOL(__page_table_check_pud_set);
226 227 228 229 230 231 232 233 234 235 236 237

void __page_table_check_pte_clear_range(struct mm_struct *mm,
					unsigned long addr,
					pmd_t pmd)
{
	if (&init_mm == mm)
		return;

	if (!pmd_bad(pmd) && !pmd_leaf(pmd)) {
		pte_t *ptep = pte_offset_map(&pmd, addr);
		unsigned long i;

238 239
		if (WARN_ON(!ptep))
			return;
240
		for (i = 0; i < PTRS_PER_PTE; i++) {
241
			__page_table_check_pte_clear(mm, ptep_get(ptep));
242 243 244
			addr += PAGE_SIZE;
			ptep++;
		}
245
		pte_unmap(ptep - PTRS_PER_PTE);
246 247
	}
}