1 // SPDX-License-Identifier: GPL-2.0
3 * Clang Control Flow Integrity (CFI) support.
5 * Copyright (C) 2022 Google LLC
7 #include <linux/string.h>
10 #include <asm/insn-eval.h>
13 * Returns the target address and the expected type when regs->ip points
14 * to a compiler-generated CFI trap.
16 static bool decode_cfi_insn(struct pt_regs
*regs
, unsigned long *target
,
19 char buffer
[MAX_INSN_SIZE
];
26 * The compiler generates the following instruction sequence
27 * for indirect call checks:
29 * movl -<id>, %r10d ; 6 bytes
30 * addl -4(%reg), %r10d ; 4 bytes
35 * We can decode the expected type and the target address from the
36 * movl/addl instructions.
38 if (copy_from_kernel_nofault(buffer
, (void *)regs
->ip
- 12, MAX_INSN_SIZE
))
40 if (insn_decode_kernel(&insn
, &buffer
[offset
]))
42 if (insn
.opcode
.value
!= 0xBA)
45 *type
= -(u32
)insn
.immediate
.value
;
47 if (copy_from_kernel_nofault(buffer
, (void *)regs
->ip
- 6, MAX_INSN_SIZE
))
49 if (insn_decode_kernel(&insn
, &buffer
[offset
]))
51 if (insn
.opcode
.value
!= 0x3)
54 /* Read the target address from the register. */
55 offset
= insn_get_modrm_rm_off(&insn
, regs
);
59 *target
= *(unsigned long *)((void *)regs
+ offset
);
65 * Checks if a ud2 trap is because of a CFI failure, and handles the trap
66 * if needed. Returns a bug_trap_type value similarly to report_bug.
68 enum bug_trap_type
handle_cfi_failure(struct pt_regs
*regs
)
73 if (!is_cfi_trap(regs
->ip
))
74 return BUG_TRAP_TYPE_NONE
;
76 if (!decode_cfi_insn(regs
, &target
, &type
))
77 return report_cfi_failure_noaddr(regs
, regs
->ip
);
79 return report_cfi_failure(regs
, regs
->ip
, &target
, type
);
83 * Ensure that __kcfi_typeid_ symbols are emitted for functions that may
84 * not be indirectly called with all configurations.
86 __ADDRESSABLE(__memcpy
)