1 /******************************************************************************
2 * dmpatch.c ---- patch for device-mapper
4 * Copyright (c) 2021, longpanda <admin@ventoy.net>
6 * This program is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU General Public License as
8 * published by the Free Software Foundation; either version 3 of the
9 * License, or (at your option) any later version.
11 * This program is distributed in the hope that it will be useful, but
12 * WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, see <http://www.gnu.org/licenses/>.
21 #include <linux/init.h>
22 #include <linux/module.h>
23 #include <linux/kallsyms.h>
24 #include <linux/mutex.h>
25 #include <linux/mempool.h>
26 #include <linux/delay.h>
27 #include <linux/wait.h>
28 #include <linux/slab.h>
32 #define magic_sig 0xB0, 0xB1, 0xB2, 0xB3, 0xB4, 0xB5, 0xB6, 0xB7, 0xB8, 0xB9, 0xBA, 0xBB, 0xBC, 0xBD, 0xBE, 0xBF
34 typedef int (*kprobe_reg_pf
)(void *);
35 typedef void (*kprobe_unreg_pf
)(void *);
36 typedef int (*printk_pf
)(const char *fmt
, ...);
37 typedef int (*set_memory_attr_pf
)(unsigned long addr
, int numpages
);
40 typedef struct ko_param
42 unsigned char magic
[16];
43 unsigned long struct_size
;
45 unsigned long printk_addr
;
46 unsigned long ro_addr
;
47 unsigned long rw_addr
;
48 unsigned long reg_kprobe_addr
;
49 unsigned long unreg_kprobe_addr
;
50 unsigned long sym_get_addr
;
51 unsigned long sym_get_size
;
52 unsigned long sym_put_addr
;
53 unsigned long sym_put_size
;
54 unsigned long kv_major
;
56 unsigned long padding
[1];
61 static printk_pf kprintf
= NULL
;
62 static set_memory_attr_pf set_mem_ro
= NULL
;
63 static set_memory_attr_pf set_mem_rw
= NULL
;
64 static kprobe_reg_pf reg_kprobe
= NULL
;
65 static kprobe_unreg_pf unreg_kprobe
= NULL
;
67 static volatile ko_param g_ko_param
=
70 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0
73 #if defined(CONFIG_X86_64)
74 #define PATCH_OP_POS1 3
75 #define CODE_MATCH1(code, i) \
76 (code[i] == 0x40 && code[i + 1] == 0x80 && code[i + 2] == 0xce && code[i + 3] == 0x80)
78 #define PATCH_OP_POS2 1
79 #define CODE_MATCH2(code, i) \
80 (code[i] == 0x0C && code[i + 1] == 0x80 && code[i + 2] == 0x89 && code[i + 3] == 0xC6)
82 #define PATCH_OP_POS3 4
83 #define CODE_MATCH3(code, i) \
84 (code[i] == 0x44 && code[i + 1] == 0x89 && code[i + 2] == 0xe8 && code[i + 3] == 0x0c && code[i + 4] == 0x80)
90 #elif defined(CONFIG_X86_32)
91 #define PATCH_OP_POS1 2
92 #define CODE_MATCH1(code, i) \
93 (code[i] == 0x80 && code[i + 1] == 0xca && code[i + 2] == 0x80 && code[i + 3] == 0xe8)
95 #define PATCH_OP_POS2 PATCH_OP_POS1
96 #define CODE_MATCH2 CODE_MATCH1
97 #define PATCH_OP_POS3 PATCH_OP_POS1
98 #define CODE_MATCH3 CODE_MATCH1
102 #error "unsupported arch"
107 /* Using 64-bit values saves one instruction clearing the high half of low */
108 #define DECLARE_ARGS(val, low, high) unsigned long low, high
109 #define EAX_EDX_VAL(val, low, high) ((low) | (high) << 32)
110 #define EAX_EDX_RET(val, low, high) "=a" (low), "=d" (high)
112 #define DECLARE_ARGS(val, low, high) unsigned long long val
113 #define EAX_EDX_VAL(val, low, high) (val)
114 #define EAX_EDX_RET(val, low, high) "=A" (val)
117 #define EX_TYPE_WRMSR 8
118 #define EX_TYPE_RDMSR 9
119 #define MSR_IA32_S_CET 0x000006a2 /* kernel mode cet */
120 #define CET_ENDBR_EN (1ULL << 2)
122 /* Exception table entry */
125 #define _ASM_EXTABLE_TYPE(from, to, type) \
126 .pushsection "__ex_table","a" ; \
133 #else /* ! __ASSEMBLY__ */
135 #define _ASM_EXTABLE_TYPE(from, to, type) \
136 " .pushsection \"__ex_table\",\"a\"\n" \
138 " .long (" #from ") - .\n" \
139 " .long (" #to ") - .\n" \
140 " .long " __stringify(type) " \n" \
143 #endif /* __ASSEMBLY__ */
144 #endif /* VTOY_IBT */
151 #define vdebug(fmt, args...) if(kprintf) kprintf(KERN_ERR fmt, ##args)
153 static unsigned char *g_get_patch
[MAX_PATCH
] = { NULL
};
154 static unsigned char *g_put_patch
[MAX_PATCH
] = { NULL
};
156 static void notrace
dmpatch_restore_code(unsigned char *opCode
)
162 align
= (unsigned long)opCode
/ g_ko_param
.pgsize
* g_ko_param
.pgsize
;
163 set_mem_rw(align
, 1);
165 set_mem_ro(align
, 1);
169 static int notrace dmpatch_replace_code
176 unsigned char **patch
182 unsigned char *opCode
= (unsigned char *)addr
;
184 vdebug("patch for %s style[%d] 0x%lx %d\n", desc
, style
, addr
, (int)size
);
186 for (i
= 0; i
< (int)size
- 8; i
++)
190 if (CODE_MATCH1(opCode
, i
) && cnt
< MAX_PATCH
)
192 patch
[cnt
] = opCode
+ i
+ PATCH_OP_POS1
;
198 if (CODE_MATCH2(opCode
, i
) && cnt
< MAX_PATCH
)
200 patch
[cnt
] = opCode
+ i
+ PATCH_OP_POS2
;
206 if (CODE_MATCH3(opCode
, i
) && cnt
< MAX_PATCH
)
208 patch
[cnt
] = opCode
+ i
+ PATCH_OP_POS3
;
218 if (cnt
!= expect
|| cnt
>= MAX_PATCH
)
220 vdebug("patch error: cnt=%d expect=%d\n", cnt
, expect
);
225 for (i
= 0; i
< cnt
; i
++)
228 align
= (unsigned long)opCode
/ g_ko_param
.pgsize
* g_ko_param
.pgsize
;
230 set_mem_rw(align
, 1);
232 set_mem_ro(align
, 1);
239 static __always_inline
unsigned long long dmpatch_rdmsr(unsigned int msr
)
241 DECLARE_ARGS(val
, low
, high
);
243 asm volatile("1: rdmsr\n"
245 _ASM_EXTABLE_TYPE(1b
, 2b
, EX_TYPE_RDMSR
)
246 : EAX_EDX_RET(val
, low
, high
) : "c" (msr
));
248 return EAX_EDX_VAL(val
, low
, high
);
251 static __always_inline
void dmpatch_wrmsr(unsigned int msr
, u32 low
, u32 high
)
253 asm volatile("1: wrmsr\n"
255 _ASM_EXTABLE_TYPE(1b
, 2b
, EX_TYPE_WRMSR
)
256 : : "c" (msr
), "a"(low
), "d" (high
) : "memory");
259 static u64
dmpatch_ibt_save(void)
264 msr
= dmpatch_rdmsr(MSR_IA32_S_CET
);
265 val
= msr
& ~CET_ENDBR_EN
;
266 dmpatch_wrmsr(MSR_IA32_S_CET
, (u32
)(val
& 0xffffffffULL
), (u32
)(val
>> 32));
271 static void dmpatch_ibt_restore(u64 save
)
275 msr
= dmpatch_rdmsr(MSR_IA32_S_CET
);
277 msr
&= ~CET_ENDBR_EN
;
278 msr
|= (save
& CET_ENDBR_EN
);
280 dmpatch_wrmsr(MSR_IA32_S_CET
, (u32
)(msr
& 0xffffffffULL
), (u32
)(msr
>> 32));
283 static u64
dmpatch_ibt_save(void) { return 0; }
284 static void dmpatch_ibt_restore(u64 save
) { (void)save
; }
287 static int notrace
dmpatch_init(void)
293 if (g_ko_param
.ibt
== 0x8888)
295 msr
= dmpatch_ibt_save();
298 kprintf
= (printk_pf
)(g_ko_param
.printk_addr
);
300 vdebug("dmpatch_init start pagesize=%lu ...\n", g_ko_param
.pgsize
);
302 if (g_ko_param
.struct_size
!= sizeof(ko_param
))
304 vdebug("Invalid struct size %d %d\n", (int)g_ko_param
.struct_size
, (int)sizeof(ko_param
));
308 if (g_ko_param
.sym_get_addr
== 0 || g_ko_param
.sym_put_addr
== 0 ||
309 g_ko_param
.ro_addr
== 0 || g_ko_param
.rw_addr
== 0)
314 set_mem_ro
= (set_memory_attr_pf
)(g_ko_param
.ro_addr
);
315 set_mem_rw
= (set_memory_attr_pf
)(g_ko_param
.rw_addr
);
316 reg_kprobe
= (kprobe_reg_pf
)g_ko_param
.reg_kprobe_addr
;
317 unreg_kprobe
= (kprobe_unreg_pf
)g_ko_param
.unreg_kprobe_addr
;
319 r
= dmpatch_replace_code(1, g_ko_param
.sym_get_addr
, g_ko_param
.sym_get_size
, 2, "dm_get_table_device", g_get_patch
);
320 if (r
&& g_ko_param
.kv_major
>= 5)
322 vdebug("new2 patch dm_get_table_device...\n");
323 r
= dmpatch_replace_code(2, g_ko_param
.sym_get_addr
, g_ko_param
.sym_get_size
, 1, "dm_get_table_device", g_get_patch
);
326 if (r
&& g_ko_param
.kv_major
>= 5)
328 vdebug("new3 patch dm_get_table_device...\n");
329 r
= dmpatch_replace_code(3, g_ko_param
.sym_get_addr
, g_ko_param
.sym_get_size
, 1, "dm_get_table_device", g_get_patch
);
338 vdebug("patch dm_get_table_device success\n");
340 r
= dmpatch_replace_code(1, g_ko_param
.sym_put_addr
, g_ko_param
.sym_put_size
, 1, "dm_put_table_device", g_put_patch
);
346 vdebug("patch dm_put_table_device success\n");
348 vdebug("#####################################\n");
349 vdebug("######## dm patch success ###########\n");
350 vdebug("#####################################\n");
352 if (g_ko_param
.ibt
== 0x8888)
354 dmpatch_ibt_restore(msr
);
362 static void notrace
dmpatch_exit(void)
367 if (g_ko_param
.ibt
== 0x8888)
369 msr
= dmpatch_ibt_save();
372 for (i
= 0; i
< MAX_PATCH
; i
++)
374 dmpatch_restore_code(g_get_patch
[i
]);
375 dmpatch_restore_code(g_put_patch
[i
]);
378 vdebug("dmpatch_exit success\n");
380 if (g_ko_param
.ibt
== 0x8888)
382 dmpatch_ibt_restore(msr
);
386 module_init(dmpatch_init
);
387 module_exit(dmpatch_exit
);
390 MODULE_DESCRIPTION("dmpatch driver");
391 MODULE_AUTHOR("longpanda <admin@ventoy.net>");
392 MODULE_LICENSE("GPL");