1 // SPDX-License-Identifier: GPL-2.0 2 3 /* 4 * Stack trace utility functions etc. 5 * 6 * Copyright 2008 Christoph Hellwig, IBM Corp. 7 * Copyright 2018 SUSE Linux GmbH 8 * Copyright 2018 Nick Piggin, Michael Ellerman, IBM Corp. 9 */ 10 11 #include <linux/export.h> 12 #include <linux/kallsyms.h> 13 #include <linux/module.h> 14 #include <linux/nmi.h> 15 #include <linux/sched.h> 16 #include <linux/sched/debug.h> 17 #include <linux/sched/task_stack.h> 18 #include <linux/stacktrace.h> 19 #include <asm/ptrace.h> 20 #include <asm/processor.h> 21 #include <linux/ftrace.h> 22 #include <asm/kprobes.h> 23 24 #include <asm/paca.h> 25 26 /* 27 * Save stack-backtrace addresses into a stack_trace buffer. 28 */ 29 static void save_context_stack(struct stack_trace *trace, unsigned long sp, 30 struct task_struct *tsk, int savesched) 31 { 32 for (;;) { 33 unsigned long *stack = (unsigned long *) sp; 34 unsigned long newsp, ip; 35 36 if (!validate_sp(sp, tsk, STACK_FRAME_OVERHEAD)) 37 return; 38 39 newsp = stack[0]; 40 ip = stack[STACK_FRAME_LR_SAVE]; 41 42 if (savesched || !in_sched_functions(ip)) { 43 if (!trace->skip) 44 trace->entries[trace->nr_entries++] = ip; 45 else 46 trace->skip--; 47 } 48 49 if (trace->nr_entries >= trace->max_entries) 50 return; 51 52 sp = newsp; 53 } 54 } 55 56 void save_stack_trace(struct stack_trace *trace) 57 { 58 unsigned long sp; 59 60 sp = current_stack_pointer(); 61 62 save_context_stack(trace, sp, current, 1); 63 } 64 EXPORT_SYMBOL_GPL(save_stack_trace); 65 66 void save_stack_trace_tsk(struct task_struct *tsk, struct stack_trace *trace) 67 { 68 unsigned long sp; 69 70 if (tsk == current) 71 sp = current_stack_pointer(); 72 else 73 sp = tsk->thread.ksp; 74 75 save_context_stack(trace, sp, tsk, 0); 76 } 77 EXPORT_SYMBOL_GPL(save_stack_trace_tsk); 78 79 void 80 save_stack_trace_regs(struct pt_regs *regs, struct stack_trace *trace) 81 { 82 save_context_stack(trace, regs->gpr[1], current, 0); 83 } 84 EXPORT_SYMBOL_GPL(save_stack_trace_regs); 85 86 #ifdef CONFIG_HAVE_RELIABLE_STACKTRACE 87 /* 88 * This function returns an error if it detects any unreliable features of the 89 * stack. Otherwise it guarantees that the stack trace is reliable. 90 * 91 * If the task is not 'current', the caller *must* ensure the task is inactive. 92 */ 93 int 94 save_stack_trace_tsk_reliable(struct task_struct *tsk, 95 struct stack_trace *trace) 96 { 97 unsigned long sp; 98 unsigned long stack_page = (unsigned long)task_stack_page(tsk); 99 unsigned long stack_end; 100 int graph_idx = 0; 101 102 /* 103 * The last frame (unwinding first) may not yet have saved 104 * its LR onto the stack. 105 */ 106 int firstframe = 1; 107 108 if (tsk == current) 109 sp = current_stack_pointer(); 110 else 111 sp = tsk->thread.ksp; 112 113 stack_end = stack_page + THREAD_SIZE; 114 if (!is_idle_task(tsk)) { 115 /* 116 * For user tasks, this is the SP value loaded on 117 * kernel entry, see "PACAKSAVE(r13)" in _switch() and 118 * system_call_common()/EXCEPTION_PROLOG_COMMON(). 119 * 120 * Likewise for non-swapper kernel threads, 121 * this also happens to be the top of the stack 122 * as setup by copy_thread(). 123 * 124 * Note that stack backlinks are not properly setup by 125 * copy_thread() and thus, a forked task() will have 126 * an unreliable stack trace until it's been 127 * _switch()'ed to for the first time. 128 */ 129 stack_end -= STACK_FRAME_OVERHEAD + sizeof(struct pt_regs); 130 } else { 131 /* 132 * idle tasks have a custom stack layout, 133 * c.f. cpu_idle_thread_init(). 134 */ 135 stack_end -= STACK_FRAME_OVERHEAD; 136 } 137 138 if (sp < stack_page + sizeof(struct thread_struct) || 139 sp > stack_end - STACK_FRAME_MIN_SIZE) { 140 return 1; 141 } 142 143 for (;;) { 144 unsigned long *stack = (unsigned long *) sp; 145 unsigned long newsp, ip; 146 147 /* sanity check: ABI requires SP to be aligned 16 bytes. */ 148 if (sp & 0xF) 149 return 1; 150 151 newsp = stack[0]; 152 /* Stack grows downwards; unwinder may only go up. */ 153 if (newsp <= sp) 154 return 1; 155 156 if (newsp != stack_end && 157 newsp > stack_end - STACK_FRAME_MIN_SIZE) { 158 return 1; /* invalid backlink, too far up. */ 159 } 160 161 /* 162 * We can only trust the bottom frame's backlink, the 163 * rest of the frame may be uninitialized, continue to 164 * the next. 165 */ 166 if (firstframe) { 167 firstframe = 0; 168 goto next; 169 } 170 171 /* Mark stacktraces with exception frames as unreliable. */ 172 if (sp <= stack_end - STACK_INT_FRAME_SIZE && 173 stack[STACK_FRAME_MARKER] == STACK_FRAME_REGS_MARKER) { 174 return 1; 175 } 176 177 /* Examine the saved LR: it must point into kernel code. */ 178 ip = stack[STACK_FRAME_LR_SAVE]; 179 if (!__kernel_text_address(ip)) 180 return 1; 181 182 /* 183 * FIXME: IMHO these tests do not belong in 184 * arch-dependent code, they are generic. 185 */ 186 ip = ftrace_graph_ret_addr(tsk, &graph_idx, ip, NULL); 187 #ifdef CONFIG_KPROBES 188 /* 189 * Mark stacktraces with kretprobed functions on them 190 * as unreliable. 191 */ 192 if (ip == (unsigned long)kretprobe_trampoline) 193 return 1; 194 #endif 195 196 if (!trace->skip) 197 trace->entries[trace->nr_entries++] = ip; 198 else 199 trace->skip--; 200 201 next: 202 if (newsp == stack_end) 203 break; 204 205 if (trace->nr_entries >= trace->max_entries) 206 return -E2BIG; 207 208 sp = newsp; 209 } 210 return 0; 211 } 212 EXPORT_SYMBOL_GPL(save_stack_trace_tsk_reliable); 213 #endif /* CONFIG_HAVE_RELIABLE_STACKTRACE */ 214 215 #if defined(CONFIG_PPC_BOOK3S_64) && defined(CONFIG_NMI_IPI) 216 static void handle_backtrace_ipi(struct pt_regs *regs) 217 { 218 nmi_cpu_backtrace(regs); 219 } 220 221 static void raise_backtrace_ipi(cpumask_t *mask) 222 { 223 unsigned int cpu; 224 225 for_each_cpu(cpu, mask) { 226 if (cpu == smp_processor_id()) 227 handle_backtrace_ipi(NULL); 228 else 229 smp_send_safe_nmi_ipi(cpu, handle_backtrace_ipi, 5 * USEC_PER_SEC); 230 } 231 232 for_each_cpu(cpu, mask) { 233 struct paca_struct *p = paca_ptrs[cpu]; 234 235 cpumask_clear_cpu(cpu, mask); 236 237 pr_warn("CPU %d didn't respond to backtrace IPI, inspecting paca.\n", cpu); 238 if (!virt_addr_valid(p)) { 239 pr_warn("paca pointer appears corrupt? (%px)\n", p); 240 continue; 241 } 242 243 pr_warn("irq_soft_mask: 0x%02x in_mce: %d in_nmi: %d", 244 p->irq_soft_mask, p->in_mce, p->in_nmi); 245 246 if (virt_addr_valid(p->__current)) 247 pr_cont(" current: %d (%s)\n", p->__current->pid, 248 p->__current->comm); 249 else 250 pr_cont(" current pointer corrupt? (%px)\n", p->__current); 251 252 pr_warn("Back trace of paca->saved_r1 (0x%016llx) (possibly stale):\n", p->saved_r1); 253 show_stack(p->__current, (unsigned long *)p->saved_r1); 254 } 255 } 256 257 void arch_trigger_cpumask_backtrace(const cpumask_t *mask, bool exclude_self) 258 { 259 nmi_trigger_cpumask_backtrace(mask, exclude_self, raise_backtrace_ipi); 260 } 261 #endif /* defined(CONFIG_PPC_BOOK3S_64) && defined(CONFIG_NMI_IPI) */ 262