5 * Kernel Probes (KProbes)
6 * include/linux/kprobes.h
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
22 * Copyright (C) IBM Corporation, 2002, 2004
26 * Dynamic Binary Instrumentation Module based on KProbes
27 * modules/kprobe/dbi_kprobes.h
29 * This program is free software; you can redistribute it and/or modify
30 * it under the terms of the GNU General Public License as published by
31 * the Free Software Foundation; either version 2 of the License, or
32 * (at your option) any later version.
34 * This program is distributed in the hope that it will be useful,
35 * but WITHOUT ANY WARRANTY; without even the implied warranty of
36 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
37 * GNU General Public License for more details.
39 * You should have received a copy of the GNU General Public License
40 * along with this program; if not, write to the Free Software
41 * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
43 * Copyright (C) Samsung Electronics, 2006-2010
45 * 2006-2007 Ekaterina Gorelkina <e.gorelkina@samsung.com>: initial implementation for ARM and MIPS
46 * 2008-2009 Alexey Gerenkov <a.gerenkov@samsung.com> User-Space
47 * Probes initial implementation; Support x86/ARM/MIPS for both user and kernel spaces.
48 * 2010 Ekaterina Gorelkina <e.gorelkina@samsung.com>: redesign module for separating core and arch parts
53 #include <linux/version.h> // LINUX_VERSION_CODE, KERNEL_VERSION()
54 #include <linux/notifier.h>
55 #include <linux/percpu.h>
56 #include <linux/spinlock.h>
57 #include <linux/rcupdate.h>
58 #include <linux/sched.h>
59 #include <linux/pagemap.h>
61 #include <asm/dbi_kprobes.h>
63 /* kprobe_status settings */
64 #define KPROBE_HIT_ACTIVE 0x00000001
65 #define KPROBE_HIT_SS 0x00000002
66 #define KPROBE_REENTER 0x00000004
67 #define KPROBE_HIT_SSDONE 0x00000008
69 #define HIWORD(x) (((x) & 0xFFFF0000) >> 16)
70 #define LOWORD(x) ((x) & 0x0000FFFF)
72 #define INVALID_VALUE 0xFFFFFFFF
73 #define INVALID_POINTER (void*)INVALID_VALUE
75 #define JPROBE_ENTRY(pentry) (kprobe_opcode_t *)pentry
77 #define RETPROBE_STACK_DEPTH 64
82 struct kretprobe_instance;
83 typedef int (*kprobe_pre_handler_t) (struct kprobe *, struct pt_regs *);
84 typedef int (*kprobe_break_handler_t) (struct kprobe *, struct pt_regs *);
85 typedef void (*kprobe_post_handler_t) (struct kprobe *, struct pt_regs *, unsigned long flags);
86 typedef int (*kprobe_fault_handler_t) (struct kprobe *, struct pt_regs *, int trapnr);
87 typedef int (*kretprobe_handler_t) (struct kretprobe_instance *, struct pt_regs *, void *);
91 struct hlist_node hlist;
92 /*list of probes to search by instruction slot*/
94 struct hlist_node is_hlist_arm;
95 struct hlist_node is_hlist_thumb;
96 #else /* CONFIG_ARM */
97 struct hlist_node is_hlist;
98 #endif /* CONFIG_ARM */
99 /* list of kprobes for multi-handler support */
100 struct list_head list;
101 /* Indicates that the corresponding module has been ref counted */
102 unsigned int mod_refcounted;
103 /*count the number of times this probe was temporarily disarmed */
104 unsigned long nmissed;
105 /* location of the probe point */
106 kprobe_opcode_t *addr;
107 /* Allow user to indicate symbol name of the probe point */
109 /* Offset into the symbol */
111 /* Called before addr is executed. */
112 kprobe_pre_handler_t pre_handler;
113 /* Called after addr is executed, unless... */
114 kprobe_post_handler_t post_handler;
115 /* ... called if executing addr causes a fault (eg. page fault).
116 * Return 1 if it handled fault, otherwise kernel will see it. */
117 kprobe_fault_handler_t fault_handler;
118 /* ... called if breakpoint trap occurs in probe handler.
119 * Return 1 if it handled break, otherwise kernel will see it. */
120 kprobe_break_handler_t break_handler;
121 /* Saved opcode (which has been replaced with breakpoint) */
122 kprobe_opcode_t opcode;
123 /* copy of the original instruction */
124 struct arch_specific_insn ainsn;
125 // override single-step target address,
126 // may be used to redirect control-flow to arbitrary address after probe point
127 // without invocation of original instruction;
128 // useful for functions replacement
129 // if jprobe.entry should return address of function or NULL
130 // if original function should be called
131 // not supported for X86, not tested for MIPS
132 kprobe_opcode_t *ss_addr;
133 // safe/unsafe to use probe
140 typedef unsigned long (*kprobe_pre_entry_handler_t) (void *priv_arg, struct pt_regs * regs);
143 * Special probe type that uses setjmp-longjmp type tricks to resume
144 * execution at a specified entry with a matching prototype corresponding
145 * to the probed function - a trick to enable arguments to become
146 * accessible seamlessly by probe handling logic.
148 * Because of the way compilers allocate stack space for local variables
149 * etc upfront, regardless of sub-scopes within a function, this mirroring
150 * principle currently works only for probes placed on function entry points.
155 // probe handling code to jump to
156 kprobe_opcode_t *entry;
157 // handler whichw willb bec called before 'entry'
158 kprobe_pre_entry_handler_t pre_entry;
162 struct jprobe_instance
164 // either on free list or used list
165 struct hlist_node uflist;
166 struct hlist_node hlist;
168 struct task_struct *task;
176 * Function-return probe -
178 * User needs to provide a handler function, and initialize maxactive.
179 * maxactive - The maximum number of instances of the probed function that
180 * can be active concurrently.
181 * nmissed - tracks the number of times the probed function's return was
182 * ignored, due to maxactive being too low.
188 kretprobe_handler_t handler;
189 kretprobe_handler_t entry_handler;
194 struct hlist_head free_instances;
195 struct hlist_head used_instances;
198 struct kretprobe_instance
200 // either on free list or used list
201 struct hlist_node uflist;
202 struct hlist_node hlist;
203 struct kretprobe *rp;
204 kprobe_opcode_t *ret_addr;
206 struct task_struct *task;
211 extern void show_registers (struct pt_regs *regs);
212 extern void kprobes_inc_nmissed_count (struct kprobe *p);
215 // Large value for fast but memory consuming implementation
216 // it is good when a lot of probes are instrumented
218 //#define KPROBE_HASH_BITS 6
219 #define KPROBE_HASH_BITS 16
220 #define KPROBE_TABLE_SIZE (1 << KPROBE_HASH_BITS)
223 /* Get the kprobe at this addr (if any) - called with preemption disabled */
224 struct kprobe *get_kprobe(void *addr);
225 struct hlist_head *kretprobe_inst_table_head (void *hash_key);
228 int dbi_register_kprobe (struct kprobe *p);
229 void dbi_unregister_kprobe (struct kprobe *p, struct task_struct *task);
231 int register_aggr_kprobe (struct kprobe *old_p, struct kprobe *p);
233 int setjmp_pre_handler (struct kprobe *, struct pt_regs *);
234 int longjmp_break_handler (struct kprobe *, struct pt_regs *);
236 int dbi_register_jprobe (struct jprobe *p);
237 void dbi_unregister_jprobe (struct jprobe *p);
238 void dbi_jprobe_return (void);
239 void dbi_jprobe_return_end (void);
241 struct kretprobe * clone_kretprobe (struct kretprobe *rp);
242 struct kretprobe_instance * get_used_rp_inst (struct kretprobe *rp);
245 int alloc_nodes_kretprobe(struct kretprobe *rp);
246 int dbi_register_kretprobe (struct kretprobe *rp);
247 void dbi_unregister_kretprobe (struct kretprobe *rp);
249 void kretprobe_assert (struct kretprobe_instance *ri,
250 unsigned long orig_ret_address, unsigned long trampoline_address);
253 struct kretprobe_instance *get_free_rp_inst (struct kretprobe *rp);
254 struct kretprobe_instance *get_free_rp_inst_no_alloc (struct kretprobe *rp);
255 void free_rp_inst (struct kretprobe *rp);
256 void add_rp_inst (struct kretprobe_instance *ri);
257 void recycle_rp_inst (struct kretprobe_instance *ri);
258 int dbi_disarm_urp_inst_for_task(struct task_struct *parent, struct task_struct *task);
260 int trampoline_probe_handler (struct kprobe *p, struct pt_regs *regs);
262 #ifdef KPROBES_PROFILE
263 int pre_handler_kretprobe (struct kprobe *p, struct pt_regs *regs, struct vm_area_struct **vma, struct page **page, unsigned long **kaddr);
264 void set_normalized_timeval (struct timeval *tv, time_t sec, suseconds_t usec);
267 extern DEFINE_PER_CPU (struct kprobe *, current_kprobe);
268 extern spinlock_t kretprobe_lock;
269 extern struct hlist_head kprobe_table[KPROBE_TABLE_SIZE];
270 //extern struct hlist_head kretprobe_inst_table[KPROBE_TABLE_SIZE];
271 extern atomic_t kprobe_count;
272 extern struct kretprobe *sched_rp;
274 struct kprobe *kprobe_running (void);
275 void reset_current_kprobe (void);
276 struct kprobe_ctlblk *get_kprobe_ctlblk (void);
278 void prepare_singlestep(struct kprobe *p, struct pt_regs *regs);
279 int patch_suspended_task(struct kretprobe *rp, struct task_struct *tsk);
281 #endif /* _DBI_KPROBES_H */