hw_breakpoint.c 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687
  1. /*
  2. * This program is free software; you can redistribute it and/or modify
  3. * it under the terms of the GNU General Public License as published by
  4. * the Free Software Foundation; either version 2 of the License, or
  5. * (at your option) any later version.
  6. *
  7. * This program is distributed in the hope that it will be useful,
  8. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  9. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  10. * GNU General Public License for more details.
  11. *
  12. * You should have received a copy of the GNU General Public License
  13. * along with this program; if not, write to the Free Software
  14. * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
  15. *
  16. * Copyright (C) 2007 Alan Stern
  17. * Copyright (C) IBM Corporation, 2009
  18. * Copyright (C) 2009, Frederic Weisbecker <fweisbec@gmail.com>
  19. *
  20. * Thanks to Ingo Molnar for his many suggestions.
  21. *
  22. * Authors: Alan Stern <stern@rowland.harvard.edu>
  23. * K.Prasad <prasad@linux.vnet.ibm.com>
  24. * Frederic Weisbecker <fweisbec@gmail.com>
  25. */
  26. /*
  27. * HW_breakpoint: a unified kernel/user-space hardware breakpoint facility,
  28. * using the CPU's debug registers.
  29. * This file contains the arch-independent routines.
  30. */
  31. #include <linux/irqflags.h>
  32. #include <linux/kallsyms.h>
  33. #include <linux/notifier.h>
  34. #include <linux/kprobes.h>
  35. #include <linux/kdebug.h>
  36. #include <linux/kernel.h>
  37. #include <linux/module.h>
  38. #include <linux/percpu.h>
  39. #include <linux/sched.h>
  40. #include <linux/init.h>
  41. #include <linux/slab.h>
  42. #include <linux/list.h>
  43. #include <linux/cpu.h>
  44. #include <linux/smp.h>
  45. #include <linux/hw_breakpoint.h>
  46. /*
  47. * Constraints data
  48. */
  49. /* Number of pinned cpu breakpoints in a cpu */
  50. static DEFINE_PER_CPU(unsigned int, nr_cpu_bp_pinned[TYPE_MAX]);
  51. /* Number of pinned task breakpoints in a cpu */
  52. static DEFINE_PER_CPU(unsigned int *, nr_task_bp_pinned[TYPE_MAX]);
  53. /* Number of non-pinned cpu/task breakpoints in a cpu */
  54. static DEFINE_PER_CPU(unsigned int, nr_bp_flexible[TYPE_MAX]);
  55. static int nr_slots[TYPE_MAX];
  56. /* Keep track of the breakpoints attached to tasks */
  57. static LIST_HEAD(bp_task_head);
  58. static int constraints_initialized;
  59. /* Gather the number of total pinned and un-pinned bp in a cpuset */
  60. struct bp_busy_slots {
  61. unsigned int pinned;
  62. unsigned int flexible;
  63. };
  64. /* Serialize accesses to the above constraints */
  65. static DEFINE_MUTEX(nr_bp_mutex);
  66. __weak int hw_breakpoint_weight(struct perf_event *bp)
  67. {
  68. return 1;
  69. }
  70. static inline enum bp_type_idx find_slot_idx(struct perf_event *bp)
  71. {
  72. if (bp->attr.bp_type & HW_BREAKPOINT_RW)
  73. return TYPE_DATA;
  74. return TYPE_INST;
  75. }
  76. /*
  77. * Report the maximum number of pinned breakpoints a task
  78. * have in this cpu
  79. */
  80. static unsigned int max_task_bp_pinned(int cpu, enum bp_type_idx type)
  81. {
  82. int i;
  83. unsigned int *tsk_pinned = per_cpu(nr_task_bp_pinned[type], cpu);
  84. for (i = nr_slots[type] - 1; i >= 0; i--) {
  85. if (tsk_pinned[i] > 0)
  86. return i + 1;
  87. }
  88. return 0;
  89. }
  90. /*
  91. * Count the number of breakpoints of the same type and same task.
  92. * The given event must be not on the list.
  93. */
  94. static int task_bp_pinned(int cpu, struct perf_event *bp, enum bp_type_idx type)
  95. {
  96. struct task_struct *tsk = bp->hw.bp_target;
  97. struct perf_event *iter;
  98. int count = 0;
  99. list_for_each_entry(iter, &bp_task_head, hw.bp_list) {
  100. if (iter->hw.bp_target == tsk &&
  101. find_slot_idx(iter) == type &&
  102. cpu == iter->cpu)
  103. count += hw_breakpoint_weight(iter);
  104. }
  105. return count;
  106. }
  107. /*
  108. * Report the number of pinned/un-pinned breakpoints we have in
  109. * a given cpu (cpu > -1) or in all of them (cpu = -1).
  110. */
  111. static void
  112. fetch_bp_busy_slots(struct bp_busy_slots *slots, struct perf_event *bp,
  113. enum bp_type_idx type)
  114. {
  115. int cpu = bp->cpu;
  116. struct task_struct *tsk = bp->hw.bp_target;
  117. if (cpu >= 0) {
  118. slots->pinned = per_cpu(nr_cpu_bp_pinned[type], cpu);
  119. if (!tsk)
  120. slots->pinned += max_task_bp_pinned(cpu, type);
  121. else
  122. slots->pinned += task_bp_pinned(cpu, bp, type);
  123. slots->flexible = per_cpu(nr_bp_flexible[type], cpu);
  124. return;
  125. }
  126. for_each_online_cpu(cpu) {
  127. unsigned int nr;
  128. nr = per_cpu(nr_cpu_bp_pinned[type], cpu);
  129. if (!tsk)
  130. nr += max_task_bp_pinned(cpu, type);
  131. else
  132. nr += task_bp_pinned(cpu, bp, type);
  133. if (nr > slots->pinned)
  134. slots->pinned = nr;
  135. nr = per_cpu(nr_bp_flexible[type], cpu);
  136. if (nr > slots->flexible)
  137. slots->flexible = nr;
  138. }
  139. }
  140. /*
  141. * For now, continue to consider flexible as pinned, until we can
  142. * ensure no flexible event can ever be scheduled before a pinned event
  143. * in a same cpu.
  144. */
  145. static void
  146. fetch_this_slot(struct bp_busy_slots *slots, int weight)
  147. {
  148. slots->pinned += weight;
  149. }
  150. /*
  151. * Add a pinned breakpoint for the given task in our constraint table
  152. */
  153. static void toggle_bp_task_slot(struct perf_event *bp, int cpu, bool enable,
  154. enum bp_type_idx type, int weight)
  155. {
  156. unsigned int *tsk_pinned;
  157. int old_count = 0;
  158. int old_idx = 0;
  159. int idx = 0;
  160. old_count = task_bp_pinned(cpu, bp, type);
  161. old_idx = old_count - 1;
  162. idx = old_idx + weight;
  163. /* tsk_pinned[n] is the number of tasks having n breakpoints */
  164. tsk_pinned = per_cpu(nr_task_bp_pinned[type], cpu);
  165. if (enable) {
  166. tsk_pinned[idx]++;
  167. if (old_count > 0)
  168. tsk_pinned[old_idx]--;
  169. } else {
  170. tsk_pinned[idx]--;
  171. if (old_count > 0)
  172. tsk_pinned[old_idx]++;
  173. }
  174. }
  175. /*
  176. * Add/remove the given breakpoint in our constraint table
  177. */
  178. static void
  179. toggle_bp_slot(struct perf_event *bp, bool enable, enum bp_type_idx type,
  180. int weight)
  181. {
  182. int cpu = bp->cpu;
  183. struct task_struct *tsk = bp->hw.bp_target;
  184. /* Pinned counter cpu profiling */
  185. if (!tsk) {
  186. if (enable)
  187. per_cpu(nr_cpu_bp_pinned[type], bp->cpu) += weight;
  188. else
  189. per_cpu(nr_cpu_bp_pinned[type], bp->cpu) -= weight;
  190. return;
  191. }
  192. /* Pinned counter task profiling */
  193. if (!enable)
  194. list_del(&bp->hw.bp_list);
  195. if (cpu >= 0) {
  196. toggle_bp_task_slot(bp, cpu, enable, type, weight);
  197. } else {
  198. for_each_online_cpu(cpu)
  199. toggle_bp_task_slot(bp, cpu, enable, type, weight);
  200. }
  201. if (enable)
  202. list_add_tail(&bp->hw.bp_list, &bp_task_head);
  203. }
  204. /*
  205. * Function to perform processor-specific cleanup during unregistration
  206. */
  207. __weak void arch_unregister_hw_breakpoint(struct perf_event *bp)
  208. {
  209. /*
  210. * A weak stub function here for those archs that don't define
  211. * it inside arch/.../kernel/hw_breakpoint.c
  212. */
  213. }
  214. /*
  215. * Contraints to check before allowing this new breakpoint counter:
  216. *
  217. * == Non-pinned counter == (Considered as pinned for now)
  218. *
  219. * - If attached to a single cpu, check:
  220. *
  221. * (per_cpu(nr_bp_flexible, cpu) || (per_cpu(nr_cpu_bp_pinned, cpu)
  222. * + max(per_cpu(nr_task_bp_pinned, cpu)))) < HBP_NUM
  223. *
  224. * -> If there are already non-pinned counters in this cpu, it means
  225. * there is already a free slot for them.
  226. * Otherwise, we check that the maximum number of per task
  227. * breakpoints (for this cpu) plus the number of per cpu breakpoint
  228. * (for this cpu) doesn't cover every registers.
  229. *
  230. * - If attached to every cpus, check:
  231. *
  232. * (per_cpu(nr_bp_flexible, *) || (max(per_cpu(nr_cpu_bp_pinned, *))
  233. * + max(per_cpu(nr_task_bp_pinned, *)))) < HBP_NUM
  234. *
  235. * -> This is roughly the same, except we check the number of per cpu
  236. * bp for every cpu and we keep the max one. Same for the per tasks
  237. * breakpoints.
  238. *
  239. *
  240. * == Pinned counter ==
  241. *
  242. * - If attached to a single cpu, check:
  243. *
  244. * ((per_cpu(nr_bp_flexible, cpu) > 1) + per_cpu(nr_cpu_bp_pinned, cpu)
  245. * + max(per_cpu(nr_task_bp_pinned, cpu))) < HBP_NUM
  246. *
  247. * -> Same checks as before. But now the nr_bp_flexible, if any, must keep
  248. * one register at least (or they will never be fed).
  249. *
  250. * - If attached to every cpus, check:
  251. *
  252. * ((per_cpu(nr_bp_flexible, *) > 1) + max(per_cpu(nr_cpu_bp_pinned, *))
  253. * + max(per_cpu(nr_task_bp_pinned, *))) < HBP_NUM
  254. */
  255. static int __reserve_bp_slot(struct perf_event *bp)
  256. {
  257. struct bp_busy_slots slots = {0};
  258. enum bp_type_idx type;
  259. int weight;
  260. /* We couldn't initialize breakpoint constraints on boot */
  261. if (!constraints_initialized)
  262. return -ENOMEM;
  263. /* Basic checks */
  264. if (bp->attr.bp_type == HW_BREAKPOINT_EMPTY ||
  265. bp->attr.bp_type == HW_BREAKPOINT_INVALID)
  266. return -EINVAL;
  267. type = find_slot_idx(bp);
  268. weight = hw_breakpoint_weight(bp);
  269. fetch_bp_busy_slots(&slots, bp, type);
  270. /*
  271. * Simulate the addition of this breakpoint to the constraints
  272. * and see the result.
  273. */
  274. fetch_this_slot(&slots, weight);
  275. /* Flexible counters need to keep at least one slot */
  276. if (slots.pinned + (!!slots.flexible) > nr_slots[type])
  277. return -ENOSPC;
  278. toggle_bp_slot(bp, true, type, weight);
  279. return 0;
  280. }
  281. int reserve_bp_slot(struct perf_event *bp)
  282. {
  283. int ret;
  284. mutex_lock(&nr_bp_mutex);
  285. ret = __reserve_bp_slot(bp);
  286. mutex_unlock(&nr_bp_mutex);
  287. return ret;
  288. }
  289. static void __release_bp_slot(struct perf_event *bp)
  290. {
  291. enum bp_type_idx type;
  292. int weight;
  293. type = find_slot_idx(bp);
  294. weight = hw_breakpoint_weight(bp);
  295. toggle_bp_slot(bp, false, type, weight);
  296. }
  297. void release_bp_slot(struct perf_event *bp)
  298. {
  299. mutex_lock(&nr_bp_mutex);
  300. arch_unregister_hw_breakpoint(bp);
  301. __release_bp_slot(bp);
  302. mutex_unlock(&nr_bp_mutex);
  303. }
  304. /*
  305. * Allow the kernel debugger to reserve breakpoint slots without
  306. * taking a lock using the dbg_* variant of for the reserve and
  307. * release breakpoint slots.
  308. */
  309. int dbg_reserve_bp_slot(struct perf_event *bp)
  310. {
  311. if (mutex_is_locked(&nr_bp_mutex))
  312. return -1;
  313. return __reserve_bp_slot(bp);
  314. }
  315. int dbg_release_bp_slot(struct perf_event *bp)
  316. {
  317. if (mutex_is_locked(&nr_bp_mutex))
  318. return -1;
  319. __release_bp_slot(bp);
  320. return 0;
  321. }
  322. static int validate_hw_breakpoint(struct perf_event *bp)
  323. {
  324. int ret;
  325. ret = arch_validate_hwbkpt_settings(bp);
  326. if (ret)
  327. return ret;
  328. if (arch_check_bp_in_kernelspace(bp)) {
  329. if (bp->attr.exclude_kernel)
  330. return -EINVAL;
  331. /*
  332. * Don't let unprivileged users set a breakpoint in the trap
  333. * path to avoid trap recursion attacks.
  334. */
  335. if (!capable(CAP_SYS_ADMIN))
  336. return -EPERM;
  337. }
  338. return 0;
  339. }
  340. int register_perf_hw_breakpoint(struct perf_event *bp)
  341. {
  342. int ret;
  343. ret = reserve_bp_slot(bp);
  344. if (ret)
  345. return ret;
  346. ret = validate_hw_breakpoint(bp);
  347. /* if arch_validate_hwbkpt_settings() fails then release bp slot */
  348. if (ret)
  349. release_bp_slot(bp);
  350. return ret;
  351. }
  352. /**
  353. * register_user_hw_breakpoint - register a hardware breakpoint for user space
  354. * @attr: breakpoint attributes
  355. * @triggered: callback to trigger when we hit the breakpoint
  356. * @tsk: pointer to 'task_struct' of the process to which the address belongs
  357. */
  358. struct perf_event *
  359. register_user_hw_breakpoint(struct perf_event_attr *attr,
  360. perf_overflow_handler_t triggered,
  361. void *context,
  362. struct task_struct *tsk)
  363. {
  364. return perf_event_create_kernel_counter(attr, -1, tsk, triggered,
  365. context);
  366. }
  367. EXPORT_SYMBOL_GPL(register_user_hw_breakpoint);
  368. /**
  369. * modify_user_hw_breakpoint - modify a user-space hardware breakpoint
  370. * @bp: the breakpoint structure to modify
  371. * @attr: new breakpoint attributes
  372. * @triggered: callback to trigger when we hit the breakpoint
  373. * @tsk: pointer to 'task_struct' of the process to which the address belongs
  374. */
  375. int modify_user_hw_breakpoint(struct perf_event *bp, struct perf_event_attr *attr)
  376. {
  377. u64 old_addr = bp->attr.bp_addr;
  378. u64 old_len = bp->attr.bp_len;
  379. int old_type = bp->attr.bp_type;
  380. int err = 0;
  381. /*
  382. * modify_user_hw_breakpoint can be invoked with IRQs disabled and hence it
  383. * will not be possible to raise IPIs that invoke __perf_event_disable.
  384. * So call the function directly after making sure we are targeting the
  385. * current task.
  386. */
  387. if (irqs_disabled() && bp->ctx && bp->ctx->task == current)
  388. __perf_event_disable(bp);
  389. else
  390. perf_event_disable(bp);
  391. bp->attr.bp_addr = attr->bp_addr;
  392. bp->attr.bp_type = attr->bp_type;
  393. bp->attr.bp_len = attr->bp_len;
  394. if (attr->disabled)
  395. goto end;
  396. err = validate_hw_breakpoint(bp);
  397. if (!err)
  398. perf_event_enable(bp);
  399. if (err) {
  400. bp->attr.bp_addr = old_addr;
  401. bp->attr.bp_type = old_type;
  402. bp->attr.bp_len = old_len;
  403. if (!bp->attr.disabled)
  404. perf_event_enable(bp);
  405. return err;
  406. }
  407. end:
  408. bp->attr.disabled = attr->disabled;
  409. return 0;
  410. }
  411. EXPORT_SYMBOL_GPL(modify_user_hw_breakpoint);
  412. /**
  413. * unregister_hw_breakpoint - unregister a user-space hardware breakpoint
  414. * @bp: the breakpoint structure to unregister
  415. */
  416. void unregister_hw_breakpoint(struct perf_event *bp)
  417. {
  418. if (!bp)
  419. return;
  420. perf_event_release_kernel(bp);
  421. }
  422. EXPORT_SYMBOL_GPL(unregister_hw_breakpoint);
  423. /**
  424. * register_wide_hw_breakpoint - register a wide breakpoint in the kernel
  425. * @attr: breakpoint attributes
  426. * @triggered: callback to trigger when we hit the breakpoint
  427. *
  428. * @return a set of per_cpu pointers to perf events
  429. */
  430. struct perf_event * __percpu *
  431. register_wide_hw_breakpoint(struct perf_event_attr *attr,
  432. perf_overflow_handler_t triggered,
  433. void *context)
  434. {
  435. struct perf_event * __percpu *cpu_events, **pevent, *bp;
  436. long err;
  437. int cpu;
  438. cpu_events = alloc_percpu(typeof(*cpu_events));
  439. if (!cpu_events)
  440. return (void __percpu __force *)ERR_PTR(-ENOMEM);
  441. get_online_cpus();
  442. for_each_online_cpu(cpu) {
  443. pevent = per_cpu_ptr(cpu_events, cpu);
  444. bp = perf_event_create_kernel_counter(attr, cpu, NULL,
  445. triggered, context);
  446. *pevent = bp;
  447. if (IS_ERR(bp)) {
  448. err = PTR_ERR(bp);
  449. goto fail;
  450. }
  451. }
  452. put_online_cpus();
  453. return cpu_events;
  454. fail:
  455. for_each_online_cpu(cpu) {
  456. pevent = per_cpu_ptr(cpu_events, cpu);
  457. if (IS_ERR(*pevent))
  458. break;
  459. unregister_hw_breakpoint(*pevent);
  460. }
  461. put_online_cpus();
  462. free_percpu(cpu_events);
  463. return (void __percpu __force *)ERR_PTR(err);
  464. }
  465. EXPORT_SYMBOL_GPL(register_wide_hw_breakpoint);
  466. /**
  467. * unregister_wide_hw_breakpoint - unregister a wide breakpoint in the kernel
  468. * @cpu_events: the per cpu set of events to unregister
  469. */
  470. void unregister_wide_hw_breakpoint(struct perf_event * __percpu *cpu_events)
  471. {
  472. int cpu;
  473. struct perf_event **pevent;
  474. for_each_possible_cpu(cpu) {
  475. pevent = per_cpu_ptr(cpu_events, cpu);
  476. unregister_hw_breakpoint(*pevent);
  477. }
  478. free_percpu(cpu_events);
  479. }
  480. EXPORT_SYMBOL_GPL(unregister_wide_hw_breakpoint);
  481. static struct notifier_block hw_breakpoint_exceptions_nb = {
  482. .notifier_call = hw_breakpoint_exceptions_notify,
  483. /* we need to be notified first */
  484. .priority = 0x7fffffff
  485. };
  486. static void bp_perf_event_destroy(struct perf_event *event)
  487. {
  488. release_bp_slot(event);
  489. }
  490. static int hw_breakpoint_event_init(struct perf_event *bp)
  491. {
  492. int err;
  493. if (bp->attr.type != PERF_TYPE_BREAKPOINT)
  494. return -ENOENT;
  495. /*
  496. * no branch sampling for breakpoint events
  497. */
  498. if (has_branch_stack(bp))
  499. return -EOPNOTSUPP;
  500. err = register_perf_hw_breakpoint(bp);
  501. if (err)
  502. return err;
  503. bp->destroy = bp_perf_event_destroy;
  504. return 0;
  505. }
  506. static int hw_breakpoint_add(struct perf_event *bp, int flags)
  507. {
  508. if (!(flags & PERF_EF_START))
  509. bp->hw.state = PERF_HES_STOPPED;
  510. return arch_install_hw_breakpoint(bp);
  511. }
  512. static void hw_breakpoint_del(struct perf_event *bp, int flags)
  513. {
  514. arch_uninstall_hw_breakpoint(bp);
  515. }
  516. static void hw_breakpoint_start(struct perf_event *bp, int flags)
  517. {
  518. bp->hw.state = 0;
  519. }
  520. static void hw_breakpoint_stop(struct perf_event *bp, int flags)
  521. {
  522. bp->hw.state = PERF_HES_STOPPED;
  523. }
  524. static int hw_breakpoint_event_idx(struct perf_event *bp)
  525. {
  526. return 0;
  527. }
  528. static struct pmu perf_breakpoint = {
  529. .task_ctx_nr = perf_sw_context, /* could eventually get its own */
  530. .event_init = hw_breakpoint_event_init,
  531. .add = hw_breakpoint_add,
  532. .del = hw_breakpoint_del,
  533. .start = hw_breakpoint_start,
  534. .stop = hw_breakpoint_stop,
  535. .read = hw_breakpoint_pmu_read,
  536. .event_idx = hw_breakpoint_event_idx,
  537. };
  538. int __init init_hw_breakpoint(void)
  539. {
  540. unsigned int **task_bp_pinned;
  541. int cpu, err_cpu;
  542. int i;
  543. for (i = 0; i < TYPE_MAX; i++)
  544. nr_slots[i] = hw_breakpoint_slots(i);
  545. for_each_possible_cpu(cpu) {
  546. for (i = 0; i < TYPE_MAX; i++) {
  547. task_bp_pinned = &per_cpu(nr_task_bp_pinned[i], cpu);
  548. *task_bp_pinned = kzalloc(sizeof(int) * nr_slots[i],
  549. GFP_KERNEL);
  550. if (!*task_bp_pinned)
  551. goto err_alloc;
  552. }
  553. }
  554. constraints_initialized = 1;
  555. perf_pmu_register(&perf_breakpoint, "breakpoint", PERF_TYPE_BREAKPOINT);
  556. return register_die_notifier(&hw_breakpoint_exceptions_nb);
  557. err_alloc:
  558. for_each_possible_cpu(err_cpu) {
  559. for (i = 0; i < TYPE_MAX; i++)
  560. kfree(per_cpu(nr_task_bp_pinned[i], err_cpu));
  561. if (err_cpu == cpu)
  562. break;
  563. }
  564. return -ENOMEM;
  565. }