hw_breakpoint.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680
  1. /*
  2. * This program is free software; you can redistribute it and/or modify
  3. * it under the terms of the GNU General Public License as published by
  4. * the Free Software Foundation; either version 2 of the License, or
  5. * (at your option) any later version.
  6. *
  7. * This program is distributed in the hope that it will be useful,
  8. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. * GNU General Public License for more details.
  11. *
  12. * You should have received a copy of the GNU General Public License
  13. * along with this program; if not, write to the Free Software
  14. * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
  15. *
  16. * Copyright (C) 2007 Alan Stern
  17. * Copyright (C) IBM Corporation, 2009
  18. * Copyright (C) 2009, Frederic Weisbecker <fweisbec@gmail.com>
  19. *
  20. * Thanks to Ingo Molnar for his many suggestions.
  21. *
  22. * Authors: Alan Stern <stern@rowland.harvard.edu>
  23. * K.Prasad <prasad@linux.vnet.ibm.com>
  24. * Frederic Weisbecker <fweisbec@gmail.com>
  25. */
  26. /*
  27. * HW_breakpoint: a unified kernel/user-space hardware breakpoint facility,
  28. * using the CPU's debug registers.
  29. * This file contains the arch-independent routines.
  30. */
  31. #include <linux/irqflags.h>
  32. #include <linux/kallsyms.h>
  33. #include <linux/notifier.h>
  34. #include <linux/kprobes.h>
  35. #include <linux/kdebug.h>
  36. #include <linux/kernel.h>
  37. #include <linux/module.h>
  38. #include <linux/percpu.h>
  39. #include <linux/sched.h>
  40. #include <linux/init.h>
  41. #include <linux/slab.h>
  42. #include <linux/list.h>
  43. #include <linux/cpu.h>
  44. #include <linux/smp.h>
  45. #include <linux/hw_breakpoint.h>
  46. /*
  47. * Constraints data
  48. */
  49. /* Number of pinned cpu breakpoints in a cpu */
  50. static DEFINE_PER_CPU(unsigned int, nr_cpu_bp_pinned[TYPE_MAX]);
  51. /* Number of pinned task breakpoints in a cpu */
  52. static DEFINE_PER_CPU(unsigned int *, nr_task_bp_pinned[TYPE_MAX]);
  53. /* Number of non-pinned cpu/task breakpoints in a cpu */
  54. static DEFINE_PER_CPU(unsigned int, nr_bp_flexible[TYPE_MAX]);
  55. static int nr_slots[TYPE_MAX];
  56. /* Keep track of the breakpoints attached to tasks */
  57. static LIST_HEAD(bp_task_head);
  58. static int constraints_initialized;
  59. /* Gather the number of total pinned and un-pinned bp in a cpuset */
  60. struct bp_busy_slots {
  61. unsigned int pinned;
  62. unsigned int flexible;
  63. };
  64. /* Serialize accesses to the above constraints */
  65. static DEFINE_MUTEX(nr_bp_mutex);
  66. __weak int hw_breakpoint_weight(struct perf_event *bp)
  67. {
  68. return 1;
  69. }
  70. static inline enum bp_type_idx find_slot_idx(struct perf_event *bp)
  71. {
  72. if (bp->attr.bp_type & HW_BREAKPOINT_RW)
  73. return TYPE_DATA;
  74. return TYPE_INST;
  75. }
  76. /*
  77. * Report the maximum number of pinned breakpoints a task
  78. * have in this cpu
  79. */
  80. static unsigned int max_task_bp_pinned(int cpu, enum bp_type_idx type)
  81. {
  82. int i;
  83. unsigned int *tsk_pinned = per_cpu(nr_task_bp_pinned[type], cpu);
  84. for (i = nr_slots[type] - 1; i >= 0; i--) {
  85. if (tsk_pinned[i] > 0)
  86. return i + 1;
  87. }
  88. return 0;
  89. }
  90. /*
  91. * Count the number of breakpoints of the same type and same task.
  92. * The given event must be not on the list.
  93. */
  94. static int task_bp_pinned(int cpu, struct perf_event *bp, enum bp_type_idx type)
  95. {
  96. struct task_struct *tsk = bp->hw.bp_target;
  97. struct perf_event *iter;
  98. int count = 0;
  99. list_for_each_entry(iter, &bp_task_head, hw.bp_list) {
  100. if (iter->hw.bp_target == tsk &&
  101. find_slot_idx(iter) == type &&
  102. (iter->cpu < 0 || cpu == iter->cpu))
  103. count += hw_breakpoint_weight(iter);
  104. }
  105. return count;
  106. }
  107. /*
  108. * Report the number of pinned/un-pinned breakpoints we have in
  109. * a given cpu (cpu > -1) or in all of them (cpu = -1).
  110. */
  111. static void
  112. fetch_bp_busy_slots(struct bp_busy_slots *slots, struct perf_event *bp,
  113. enum bp_type_idx type)
  114. {
  115. int cpu = bp->cpu;
  116. struct task_struct *tsk = bp->hw.bp_target;
  117. if (cpu >= 0) {
  118. slots->pinned = per_cpu(nr_cpu_bp_pinned[type], cpu);
  119. if (!tsk)
  120. slots->pinned += max_task_bp_pinned(cpu, type);
  121. else
  122. slots->pinned += task_bp_pinned(cpu, bp, type);
  123. slots->flexible = per_cpu(nr_bp_flexible[type], cpu);
  124. return;
  125. }
  126. for_each_possible_cpu(cpu) {
  127. unsigned int nr;
  128. nr = per_cpu(nr_cpu_bp_pinned[type], cpu);
  129. if (!tsk)
  130. nr += max_task_bp_pinned(cpu, type);
  131. else
  132. nr += task_bp_pinned(cpu, bp, type);
  133. if (nr > slots->pinned)
  134. slots->pinned = nr;
  135. nr = per_cpu(nr_bp_flexible[type], cpu);
  136. if (nr > slots->flexible)
  137. slots->flexible = nr;
  138. }
  139. }
  140. /*
  141. * For now, continue to consider flexible as pinned, until we can
  142. * ensure no flexible event can ever be scheduled before a pinned event
  143. * in a same cpu.
  144. */
  145. static void
  146. fetch_this_slot(struct bp_busy_slots *slots, int weight)
  147. {
  148. slots->pinned += weight;
  149. }
  150. /*
  151. * Add a pinned breakpoint for the given task in our constraint table
  152. */
  153. static void toggle_bp_task_slot(struct perf_event *bp, int cpu,
  154. enum bp_type_idx type, int weight)
  155. {
  156. /* tsk_pinned[n-1] is the number of tasks having n>0 breakpoints */
  157. unsigned int *tsk_pinned = per_cpu(nr_task_bp_pinned[type], cpu);
  158. int old_idx, new_idx;
  159. old_idx = task_bp_pinned(cpu, bp, type) - 1;
  160. new_idx = old_idx + weight;
  161. if (old_idx >= 0)
  162. tsk_pinned[old_idx]--;
  163. if (new_idx >= 0)
  164. tsk_pinned[new_idx]++;
  165. }
  166. /*
  167. * Add/remove the given breakpoint in our constraint table
  168. */
  169. static void
  170. toggle_bp_slot(struct perf_event *bp, bool enable, enum bp_type_idx type,
  171. int weight)
  172. {
  173. int cpu = bp->cpu;
  174. struct task_struct *tsk = bp->hw.bp_target;
  175. if (!enable)
  176. weight = -weight;
  177. /* Pinned counter cpu profiling */
  178. if (!tsk) {
  179. per_cpu(nr_cpu_bp_pinned[type], cpu) += weight;
  180. return;
  181. }
  182. /* Pinned counter task profiling */
  183. if (cpu >= 0) {
  184. toggle_bp_task_slot(bp, cpu, type, weight);
  185. } else {
  186. for_each_possible_cpu(cpu)
  187. toggle_bp_task_slot(bp, cpu, type, weight);
  188. }
  189. if (enable)
  190. list_add_tail(&bp->hw.bp_list, &bp_task_head);
  191. else
  192. list_del(&bp->hw.bp_list);
  193. }
  194. /*
  195. * Function to perform processor-specific cleanup during unregistration
  196. */
  197. __weak void arch_unregister_hw_breakpoint(struct perf_event *bp)
  198. {
  199. /*
  200. * A weak stub function here for those archs that don't define
  201. * it inside arch/.../kernel/hw_breakpoint.c
  202. */
  203. }
  204. /*
  205. * Contraints to check before allowing this new breakpoint counter:
  206. *
  207. * == Non-pinned counter == (Considered as pinned for now)
  208. *
  209. * - If attached to a single cpu, check:
  210. *
  211. * (per_cpu(nr_bp_flexible, cpu) || (per_cpu(nr_cpu_bp_pinned, cpu)
  212. * + max(per_cpu(nr_task_bp_pinned, cpu)))) < HBP_NUM
  213. *
  214. * -> If there are already non-pinned counters in this cpu, it means
  215. * there is already a free slot for them.
  216. * Otherwise, we check that the maximum number of per task
  217. * breakpoints (for this cpu) plus the number of per cpu breakpoint
  218. * (for this cpu) doesn't cover every registers.
  219. *
  220. * - If attached to every cpus, check:
  221. *
  222. * (per_cpu(nr_bp_flexible, *) || (max(per_cpu(nr_cpu_bp_pinned, *))
  223. * + max(per_cpu(nr_task_bp_pinned, *)))) < HBP_NUM
  224. *
  225. * -> This is roughly the same, except we check the number of per cpu
  226. * bp for every cpu and we keep the max one. Same for the per tasks
  227. * breakpoints.
  228. *
  229. *
  230. * == Pinned counter ==
  231. *
  232. * - If attached to a single cpu, check:
  233. *
  234. * ((per_cpu(nr_bp_flexible, cpu) > 1) + per_cpu(nr_cpu_bp_pinned, cpu)
  235. * + max(per_cpu(nr_task_bp_pinned, cpu))) < HBP_NUM
  236. *
  237. * -> Same checks as before. But now the nr_bp_flexible, if any, must keep
  238. * one register at least (or they will never be fed).
  239. *
  240. * - If attached to every cpus, check:
  241. *
  242. * ((per_cpu(nr_bp_flexible, *) > 1) + max(per_cpu(nr_cpu_bp_pinned, *))
  243. * + max(per_cpu(nr_task_bp_pinned, *))) < HBP_NUM
  244. */
  245. static int __reserve_bp_slot(struct perf_event *bp)
  246. {
  247. struct bp_busy_slots slots = {0};
  248. enum bp_type_idx type;
  249. int weight;
  250. /* We couldn't initialize breakpoint constraints on boot */
  251. if (!constraints_initialized)
  252. return -ENOMEM;
  253. /* Basic checks */
  254. if (bp->attr.bp_type == HW_BREAKPOINT_EMPTY ||
  255. bp->attr.bp_type == HW_BREAKPOINT_INVALID)
  256. return -EINVAL;
  257. type = find_slot_idx(bp);
  258. weight = hw_breakpoint_weight(bp);
  259. fetch_bp_busy_slots(&slots, bp, type);
  260. /*
  261. * Simulate the addition of this breakpoint to the constraints
  262. * and see the result.
  263. */
  264. fetch_this_slot(&slots, weight);
  265. /* Flexible counters need to keep at least one slot */
  266. if (slots.pinned + (!!slots.flexible) > nr_slots[type])
  267. return -ENOSPC;
  268. toggle_bp_slot(bp, true, type, weight);
  269. return 0;
  270. }
  271. int reserve_bp_slot(struct perf_event *bp)
  272. {
  273. int ret;
  274. mutex_lock(&nr_bp_mutex);
  275. ret = __reserve_bp_slot(bp);
  276. mutex_unlock(&nr_bp_mutex);
  277. return ret;
  278. }
  279. static void __release_bp_slot(struct perf_event *bp)
  280. {
  281. enum bp_type_idx type;
  282. int weight;
  283. type = find_slot_idx(bp);
  284. weight = hw_breakpoint_weight(bp);
  285. toggle_bp_slot(bp, false, type, weight);
  286. }
  287. void release_bp_slot(struct perf_event *bp)
  288. {
  289. mutex_lock(&nr_bp_mutex);
  290. arch_unregister_hw_breakpoint(bp);
  291. __release_bp_slot(bp);
  292. mutex_unlock(&nr_bp_mutex);
  293. }
  294. /*
  295. * Allow the kernel debugger to reserve breakpoint slots without
  296. * taking a lock using the dbg_* variant of for the reserve and
  297. * release breakpoint slots.
  298. */
  299. int dbg_reserve_bp_slot(struct perf_event *bp)
  300. {
  301. if (mutex_is_locked(&nr_bp_mutex))
  302. return -1;
  303. return __reserve_bp_slot(bp);
  304. }
  305. int dbg_release_bp_slot(struct perf_event *bp)
  306. {
  307. if (mutex_is_locked(&nr_bp_mutex))
  308. return -1;
  309. __release_bp_slot(bp);
  310. return 0;
  311. }
  312. static int validate_hw_breakpoint(struct perf_event *bp)
  313. {
  314. int ret;
  315. ret = arch_validate_hwbkpt_settings(bp);
  316. if (ret)
  317. return ret;
  318. if (arch_check_bp_in_kernelspace(bp)) {
  319. if (bp->attr.exclude_kernel)
  320. return -EINVAL;
  321. /*
  322. * Don't let unprivileged users set a breakpoint in the trap
  323. * path to avoid trap recursion attacks.
  324. */
  325. if (!capable(CAP_SYS_ADMIN))
  326. return -EPERM;
  327. }
  328. return 0;
  329. }
  330. int register_perf_hw_breakpoint(struct perf_event *bp)
  331. {
  332. int ret;
  333. ret = reserve_bp_slot(bp);
  334. if (ret)
  335. return ret;
  336. ret = validate_hw_breakpoint(bp);
  337. /* if arch_validate_hwbkpt_settings() fails then release bp slot */
  338. if (ret)
  339. release_bp_slot(bp);
  340. return ret;
  341. }
  342. /**
  343. * register_user_hw_breakpoint - register a hardware breakpoint for user space
  344. * @attr: breakpoint attributes
  345. * @triggered: callback to trigger when we hit the breakpoint
  346. * @tsk: pointer to 'task_struct' of the process to which the address belongs
  347. */
  348. struct perf_event *
  349. register_user_hw_breakpoint(struct perf_event_attr *attr,
  350. perf_overflow_handler_t triggered,
  351. void *context,
  352. struct task_struct *tsk)
  353. {
  354. return perf_event_create_kernel_counter(attr, -1, tsk, triggered,
  355. context);
  356. }
  357. EXPORT_SYMBOL_GPL(register_user_hw_breakpoint);
  358. /**
  359. * modify_user_hw_breakpoint - modify a user-space hardware breakpoint
  360. * @bp: the breakpoint structure to modify
  361. * @attr: new breakpoint attributes
  362. * @triggered: callback to trigger when we hit the breakpoint
  363. * @tsk: pointer to 'task_struct' of the process to which the address belongs
  364. */
  365. int modify_user_hw_breakpoint(struct perf_event *bp, struct perf_event_attr *attr)
  366. {
  367. u64 old_addr = bp->attr.bp_addr;
  368. u64 old_len = bp->attr.bp_len;
  369. int old_type = bp->attr.bp_type;
  370. int err = 0;
  371. /*
  372. * modify_user_hw_breakpoint can be invoked with IRQs disabled and hence it
  373. * will not be possible to raise IPIs that invoke __perf_event_disable.
  374. * So call the function directly after making sure we are targeting the
  375. * current task.
  376. */
  377. if (irqs_disabled() && bp->ctx && bp->ctx->task == current)
  378. __perf_event_disable(bp);
  379. else
  380. perf_event_disable(bp);
  381. bp->attr.bp_addr = attr->bp_addr;
  382. bp->attr.bp_type = attr->bp_type;
  383. bp->attr.bp_len = attr->bp_len;
  384. if (attr->disabled)
  385. goto end;
  386. err = validate_hw_breakpoint(bp);
  387. if (!err)
  388. perf_event_enable(bp);
  389. if (err) {
  390. bp->attr.bp_addr = old_addr;
  391. bp->attr.bp_type = old_type;
  392. bp->attr.bp_len = old_len;
  393. if (!bp->attr.disabled)
  394. perf_event_enable(bp);
  395. return err;
  396. }
  397. end:
  398. bp->attr.disabled = attr->disabled;
  399. return 0;
  400. }
  401. EXPORT_SYMBOL_GPL(modify_user_hw_breakpoint);
  402. /**
  403. * unregister_hw_breakpoint - unregister a user-space hardware breakpoint
  404. * @bp: the breakpoint structure to unregister
  405. */
  406. void unregister_hw_breakpoint(struct perf_event *bp)
  407. {
  408. if (!bp)
  409. return;
  410. perf_event_release_kernel(bp);
  411. }
  412. EXPORT_SYMBOL_GPL(unregister_hw_breakpoint);
  413. /**
  414. * register_wide_hw_breakpoint - register a wide breakpoint in the kernel
  415. * @attr: breakpoint attributes
  416. * @triggered: callback to trigger when we hit the breakpoint
  417. *
  418. * @return a set of per_cpu pointers to perf events
  419. */
  420. struct perf_event * __percpu *
  421. register_wide_hw_breakpoint(struct perf_event_attr *attr,
  422. perf_overflow_handler_t triggered,
  423. void *context)
  424. {
  425. struct perf_event * __percpu *cpu_events, **pevent, *bp;
  426. long err;
  427. int cpu;
  428. cpu_events = alloc_percpu(typeof(*cpu_events));
  429. if (!cpu_events)
  430. return (void __percpu __force *)ERR_PTR(-ENOMEM);
  431. get_online_cpus();
  432. for_each_online_cpu(cpu) {
  433. pevent = per_cpu_ptr(cpu_events, cpu);
  434. bp = perf_event_create_kernel_counter(attr, cpu, NULL,
  435. triggered, context);
  436. *pevent = bp;
  437. if (IS_ERR(bp)) {
  438. err = PTR_ERR(bp);
  439. goto fail;
  440. }
  441. }
  442. put_online_cpus();
  443. return cpu_events;
  444. fail:
  445. for_each_online_cpu(cpu) {
  446. pevent = per_cpu_ptr(cpu_events, cpu);
  447. if (IS_ERR(*pevent))
  448. break;
  449. unregister_hw_breakpoint(*pevent);
  450. }
  451. put_online_cpus();
  452. free_percpu(cpu_events);
  453. return (void __percpu __force *)ERR_PTR(err);
  454. }
  455. EXPORT_SYMBOL_GPL(register_wide_hw_breakpoint);
  456. /**
  457. * unregister_wide_hw_breakpoint - unregister a wide breakpoint in the kernel
  458. * @cpu_events: the per cpu set of events to unregister
  459. */
  460. void unregister_wide_hw_breakpoint(struct perf_event * __percpu *cpu_events)
  461. {
  462. int cpu;
  463. struct perf_event **pevent;
  464. for_each_possible_cpu(cpu) {
  465. pevent = per_cpu_ptr(cpu_events, cpu);
  466. unregister_hw_breakpoint(*pevent);
  467. }
  468. free_percpu(cpu_events);
  469. }
  470. EXPORT_SYMBOL_GPL(unregister_wide_hw_breakpoint);
  471. static struct notifier_block hw_breakpoint_exceptions_nb = {
  472. .notifier_call = hw_breakpoint_exceptions_notify,
  473. /* we need to be notified first */
  474. .priority = 0x7fffffff
  475. };
  476. static void bp_perf_event_destroy(struct perf_event *event)
  477. {
  478. release_bp_slot(event);
  479. }
  480. static int hw_breakpoint_event_init(struct perf_event *bp)
  481. {
  482. int err;
  483. if (bp->attr.type != PERF_TYPE_BREAKPOINT)
  484. return -ENOENT;
  485. /*
  486. * no branch sampling for breakpoint events
  487. */
  488. if (has_branch_stack(bp))
  489. return -EOPNOTSUPP;
  490. err = register_perf_hw_breakpoint(bp);
  491. if (err)
  492. return err;
  493. bp->destroy = bp_perf_event_destroy;
  494. return 0;
  495. }
  496. static int hw_breakpoint_add(struct perf_event *bp, int flags)
  497. {
  498. if (!(flags & PERF_EF_START))
  499. bp->hw.state = PERF_HES_STOPPED;
  500. if (is_sampling_event(bp)) {
  501. bp->hw.last_period = bp->hw.sample_period;
  502. perf_swevent_set_period(bp);
  503. }
  504. return arch_install_hw_breakpoint(bp);
  505. }
  506. static void hw_breakpoint_del(struct perf_event *bp, int flags)
  507. {
  508. arch_uninstall_hw_breakpoint(bp);
  509. }
  510. static void hw_breakpoint_start(struct perf_event *bp, int flags)
  511. {
  512. bp->hw.state = 0;
  513. }
  514. static void hw_breakpoint_stop(struct perf_event *bp, int flags)
  515. {
  516. bp->hw.state = PERF_HES_STOPPED;
  517. }
  518. static int hw_breakpoint_event_idx(struct perf_event *bp)
  519. {
  520. return 0;
  521. }
  522. static struct pmu perf_breakpoint = {
  523. .task_ctx_nr = perf_sw_context, /* could eventually get its own */
  524. .event_init = hw_breakpoint_event_init,
  525. .add = hw_breakpoint_add,
  526. .del = hw_breakpoint_del,
  527. .start = hw_breakpoint_start,
  528. .stop = hw_breakpoint_stop,
  529. .read = hw_breakpoint_pmu_read,
  530. .event_idx = hw_breakpoint_event_idx,
  531. };
  532. int __init init_hw_breakpoint(void)
  533. {
  534. unsigned int **task_bp_pinned;
  535. int cpu, err_cpu;
  536. int i;
  537. for (i = 0; i < TYPE_MAX; i++)
  538. nr_slots[i] = hw_breakpoint_slots(i);
  539. for_each_possible_cpu(cpu) {
  540. for (i = 0; i < TYPE_MAX; i++) {
  541. task_bp_pinned = &per_cpu(nr_task_bp_pinned[i], cpu);
  542. *task_bp_pinned = kzalloc(sizeof(int) * nr_slots[i],
  543. GFP_KERNEL);
  544. if (!*task_bp_pinned)
  545. goto err_alloc;
  546. }
  547. }
  548. constraints_initialized = 1;
  549. perf_pmu_register(&perf_breakpoint, "breakpoint", PERF_TYPE_BREAKPOINT);
  550. return register_die_notifier(&hw_breakpoint_exceptions_nb);
  551. err_alloc:
  552. for_each_possible_cpu(err_cpu) {
  553. for (i = 0; i < TYPE_MAX; i++)
  554. kfree(per_cpu(nr_task_bp_pinned[i], err_cpu));
  555. if (err_cpu == cpu)
  556. break;
  557. }
  558. return -ENOMEM;
  559. }