+static unsigned long notrace dmpatch_find_call_offset(unsigned long addr, unsigned long size, unsigned long func)
+{
+ unsigned long i = 0;
+ unsigned long dest;
+ unsigned char *opCode = NULL;
+ unsigned char aucOffset[8] = { 0, 0, 0, 0, 0xFF, 0xFF, 0xFF, 0xFF };
+
+ opCode = (unsigned char *)addr;
+
+ for (i = 0; i + 4 < size; i++)
+ {
+ if (opCode[i] == 0xE8)
+ {
+ aucOffset[0] = opCode[i + 1];
+ aucOffset[1] = opCode[i + 2];
+ aucOffset[2] = opCode[i + 3];
+ aucOffset[3] = opCode[i + 4];
+
+ dest = addr + i + 5 + *(unsigned long *)aucOffset;
+ if (dest == func)
+ {
+ return i;
+ }
+ }
+ }
+
+ return 0;
+}
+
+static unsigned int notrace dmpatch_patch_claim_ptr(void)
+{
+ unsigned long i = 0;
+ unsigned long t = 0;
+ unsigned long offset1 = 0;
+ unsigned long offset2 = 0;
+ unsigned long align = 0;
+ unsigned char *opCode = NULL;
+
+ opCode = (unsigned char *)g_ko_param.sym_get_addr;
+ for (i = 0; i < 4; i++)
+ {
+ vdebug("%02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X %02X\n",
+ opCode[i + 0], opCode[i + 1], opCode[i + 2], opCode[i + 3],
+ opCode[i + 4], opCode[i + 5], opCode[i + 6], opCode[i + 7],
+ opCode[i + 8], opCode[i + 9], opCode[i + 10], opCode[i + 11],
+ opCode[i + 12], opCode[i + 13], opCode[i + 14], opCode[i + 15]);
+ }
+
+ if (dmpatch_kv_above(6, 7, 0)) /* >= 6.7 kernel */
+ {
+ vdebug("Get addr: 0x%lx %lu open 0x%lx\n", g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.bdev_open_addr);
+ offset1 = dmpatch_find_call_offset(g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.bdev_open_addr);
+ if (offset1 == 0)
+ {
+ vdebug("call bdev_open_addr Not found\n");
+
+ vdebug("Get addr: 0x%lx %lu file_open 0x%lx\n", g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.bdev_file_open_addr);
+ offset1 = dmpatch_find_call_offset(g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.bdev_file_open_addr);
+ if (offset1 == 0)
+ {
+ vdebug("call bdev_file_open_addr Not found\n");
+ return 1;
+ }
+ }
+ }
+ else
+ {
+ vdebug("Get addr: 0x%lx %lu 0x%lx\n", g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.blkdev_get_addr);
+ vdebug("Put addr: 0x%lx %lu 0x%lx\n", g_ko_param.sym_put_addr, g_ko_param.sym_put_size, g_ko_param.blkdev_put_addr);
+
+ offset1 = dmpatch_find_call_offset(g_ko_param.sym_get_addr, g_ko_param.sym_get_size, g_ko_param.blkdev_get_addr);
+ offset2 = dmpatch_find_call_offset(g_ko_param.sym_put_addr, g_ko_param.sym_put_size, g_ko_param.blkdev_put_addr);
+ if (offset1 == 0 || offset2 == 0)
+ {
+ vdebug("call blkdev_get or blkdev_put Not found, %lu %lu\n", offset1, offset2);
+ return 1;
+ }
+ }
+
+
+ vdebug("call addr1:0x%lx call addr2:0x%lx\n",
+ g_ko_param.sym_get_addr + offset1,
+ g_ko_param.sym_put_addr + offset2);
+
+ opCode = (unsigned char *)g_ko_param.sym_get_addr;
+ for (i = offset1 - 1, t = 0; (i > 0) && (t < 24); i--, t++)
+ {
+ /* rdx */
+ if (opCode[i] == 0x48 && opCode[i + 1] == 0xc7 && opCode[i + 2] == 0xc2)
+ {
+ g_claim_ptr = *(unsigned int *)(opCode + i + 3);
+ g_get_patch[0] = opCode + i + 3;
+ vdebug("claim_ptr(%08X) found at get addr 0x%lx\n", g_claim_ptr, g_ko_param.sym_get_addr + i + 3);
+ break;
+ }
+ }
+
+ if (g_claim_ptr == 0)
+ {
+ vdebug("Claim_ptr not found in get\n");
+ return 1;
+ }
+
+
+ align = (unsigned long)g_get_patch[0] / g_ko_param.pgsize * g_ko_param.pgsize;
+ set_mem_rw(align, 1);
+ *(unsigned int *)(g_get_patch[0]) = 0;
+ set_mem_ro(align, 1);
+
+
+ if (offset2 > 0)
+ {
+ opCode = (unsigned char *)g_ko_param.sym_put_addr;
+ for (i = offset2 - 1, t = 0; (i > 0) && (t < 24); i--, t++)
+ {
+ /* rsi */
+ if (opCode[i] == 0x48 && opCode[i + 1] == 0xc7 && opCode[i + 2] == 0xc6)
+ {
+ if (*(unsigned int *)(opCode + i + 3) == g_claim_ptr)
+ {
+ vdebug("claim_ptr found at put addr 0x%lx\n", g_ko_param.sym_put_addr + i + 3);
+ g_put_patch[0] = opCode + i + 3;
+ break;
+ }
+ }
+ }
+
+ if (g_put_patch[0] == 0)
+ {
+ vdebug("Claim_ptr not found in put\n");
+ return 1;
+ }
+
+ align = (unsigned long)g_put_patch[0] / g_ko_param.pgsize * g_ko_param.pgsize;
+ set_mem_rw(align, 1);
+ *(unsigned int *)(g_put_patch[0]) = 0;
+ set_mem_ro(align, 1);
+ }
+
+ return 0;
+}
+
+#ifdef VTOY_IBT
+static __always_inline unsigned long long dmpatch_rdmsr(unsigned int msr)
+{
+ DECLARE_ARGS(val, low, high);
+
+ asm volatile("1: rdmsr\n"
+ "2:\n"
+ _ASM_EXTABLE_TYPE(1b, 2b, EX_TYPE_RDMSR)
+ : EAX_EDX_RET(val, low, high) : "c" (msr));
+
+ return EAX_EDX_VAL(val, low, high);
+}
+
+static __always_inline void dmpatch_wrmsr(unsigned int msr, u32 low, u32 high)
+{
+ asm volatile("1: wrmsr\n"
+ "2:\n"
+ _ASM_EXTABLE_TYPE(1b, 2b, EX_TYPE_WRMSR)
+ : : "c" (msr), "a"(low), "d" (high) : "memory");
+}
+
+static u64 notrace dmpatch_ibt_save(void)
+{
+ u64 msr = 0;
+ u64 val = 0;
+
+ msr = dmpatch_rdmsr(MSR_IA32_S_CET);
+ val = msr & ~CET_ENDBR_EN;
+ dmpatch_wrmsr(MSR_IA32_S_CET, (u32)(val & 0xffffffffULL), (u32)(val >> 32));
+
+ return msr;
+}
+
+static void notrace dmpatch_ibt_restore(u64 save)
+{
+ u64 msr;
+
+ msr = dmpatch_rdmsr(MSR_IA32_S_CET);
+
+ msr &= ~CET_ENDBR_EN;
+ msr |= (save & CET_ENDBR_EN);
+
+ dmpatch_wrmsr(MSR_IA32_S_CET, (u32)(msr & 0xffffffffULL), (u32)(msr >> 32));
+}
+#else
+static u64 notrace dmpatch_ibt_save(void) { return 0; }
+static void notrace dmpatch_ibt_restore(u64 save) { (void)save; }
+#endif
+
+static int notrace dmpatch_process(unsigned long a, unsigned long b, unsigned long c)