kexec.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472
  1. // SPDX-License-Identifier: GPL-2.0-only
  2. /*
  3. * Copyright (C) 2020 Arm Limited
  4. *
  5. * Based on arch/arm64/kernel/machine_kexec_file.c:
  6. * Copyright (C) 2018 Linaro Limited
  7. *
  8. * And arch/powerpc/kexec/file_load.c:
  9. * Copyright (C) 2016 IBM Corporation
  10. */
  11. #include <linux/ima.h>
  12. #include <linux/kernel.h>
  13. #include <linux/kexec.h>
  14. #include <linux/memblock.h>
  15. #include <linux/libfdt.h>
  16. #include <linux/of.h>
  17. #include <linux/of_fdt.h>
  18. #include <linux/random.h>
  19. #include <linux/slab.h>
  20. #include <linux/types.h>
  21. #define RNG_SEED_SIZE 128
  22. /*
  23. * Additional space needed for the FDT buffer so that we can add initrd,
  24. * bootargs, kaslr-seed, rng-seed, useable-memory-range and elfcorehdr.
  25. */
  26. #define FDT_EXTRA_SPACE 0x1000
  27. /**
  28. * fdt_find_and_del_mem_rsv - delete memory reservation with given address and size
  29. *
  30. * @fdt: Flattened device tree for the current kernel.
  31. * @start: Starting address of the reserved memory.
  32. * @size: Size of the reserved memory.
  33. *
  34. * Return: 0 on success, or negative errno on error.
  35. */
  36. static int fdt_find_and_del_mem_rsv(void *fdt, unsigned long start, unsigned long size)
  37. {
  38. int i, ret, num_rsvs = fdt_num_mem_rsv(fdt);
  39. for (i = 0; i < num_rsvs; i++) {
  40. u64 rsv_start, rsv_size;
  41. ret = fdt_get_mem_rsv(fdt, i, &rsv_start, &rsv_size);
  42. if (ret) {
  43. pr_err("Malformed device tree.\n");
  44. return -EINVAL;
  45. }
  46. if (rsv_start == start && rsv_size == size) {
  47. ret = fdt_del_mem_rsv(fdt, i);
  48. if (ret) {
  49. pr_err("Error deleting device tree reservation.\n");
  50. return -EINVAL;
  51. }
  52. return 0;
  53. }
  54. }
  55. return -ENOENT;
  56. }
  57. /**
  58. * get_addr_size_cells - Get address and size of root node
  59. *
  60. * @addr_cells: Return address of the root node
  61. * @size_cells: Return size of the root node
  62. *
  63. * Return: 0 on success, or negative errno on error.
  64. */
  65. static int get_addr_size_cells(int *addr_cells, int *size_cells)
  66. {
  67. struct device_node *root;
  68. root = of_find_node_by_path("/");
  69. if (!root)
  70. return -EINVAL;
  71. *addr_cells = of_n_addr_cells(root);
  72. *size_cells = of_n_size_cells(root);
  73. of_node_put(root);
  74. return 0;
  75. }
  76. /**
  77. * do_get_kexec_buffer - Get address and size of device tree property
  78. *
  79. * @prop: Device tree property
  80. * @len: Size of @prop
  81. * @addr: Return address of the node
  82. * @size: Return size of the node
  83. *
  84. * Return: 0 on success, or negative errno on error.
  85. */
  86. static int do_get_kexec_buffer(const void *prop, int len, unsigned long *addr,
  87. size_t *size)
  88. {
  89. int ret, addr_cells, size_cells;
  90. ret = get_addr_size_cells(&addr_cells, &size_cells);
  91. if (ret)
  92. return ret;
  93. if (len < 4 * (addr_cells + size_cells))
  94. return -ENOENT;
  95. *addr = of_read_number(prop, addr_cells);
  96. *size = of_read_number(prop + 4 * addr_cells, size_cells);
  97. return 0;
  98. }
  99. #ifdef CONFIG_HAVE_IMA_KEXEC
  100. /**
  101. * ima_get_kexec_buffer - get IMA buffer from the previous kernel
  102. * @addr: On successful return, set to point to the buffer contents.
  103. * @size: On successful return, set to the buffer size.
  104. *
  105. * Return: 0 on success, negative errno on error.
  106. */
  107. int __init ima_get_kexec_buffer(void **addr, size_t *size)
  108. {
  109. int ret, len;
  110. unsigned long tmp_addr;
  111. unsigned long start_pfn, end_pfn;
  112. size_t tmp_size;
  113. const void *prop;
  114. prop = of_get_property(of_chosen, "linux,ima-kexec-buffer", &len);
  115. if (!prop)
  116. return -ENOENT;
  117. ret = do_get_kexec_buffer(prop, len, &tmp_addr, &tmp_size);
  118. if (ret)
  119. return ret;
  120. /* Do some sanity on the returned size for the ima-kexec buffer */
  121. if (!tmp_size)
  122. return -ENOENT;
  123. /*
  124. * Calculate the PFNs for the buffer and ensure
  125. * they are with in addressable memory.
  126. */
  127. start_pfn = PHYS_PFN(tmp_addr);
  128. end_pfn = PHYS_PFN(tmp_addr + tmp_size - 1);
  129. if (!page_is_ram(start_pfn) || !page_is_ram(end_pfn)) {
  130. pr_warn("IMA buffer at 0x%lx, size = 0x%zx beyond memory\n",
  131. tmp_addr, tmp_size);
  132. return -EINVAL;
  133. }
  134. *addr = __va(tmp_addr);
  135. *size = tmp_size;
  136. return 0;
  137. }
  138. /**
  139. * ima_free_kexec_buffer - free memory used by the IMA buffer
  140. */
  141. int __init ima_free_kexec_buffer(void)
  142. {
  143. int ret;
  144. unsigned long addr;
  145. size_t size;
  146. struct property *prop;
  147. prop = of_find_property(of_chosen, "linux,ima-kexec-buffer", NULL);
  148. if (!prop)
  149. return -ENOENT;
  150. ret = do_get_kexec_buffer(prop->value, prop->length, &addr, &size);
  151. if (ret)
  152. return ret;
  153. ret = of_remove_property(of_chosen, prop);
  154. if (ret)
  155. return ret;
  156. memblock_free_late(addr, size);
  157. return 0;
  158. }
  159. #endif
  160. /**
  161. * remove_ima_buffer - remove the IMA buffer property and reservation from @fdt
  162. *
  163. * @fdt: Flattened Device Tree to update
  164. * @chosen_node: Offset to the chosen node in the device tree
  165. *
  166. * The IMA measurement buffer is of no use to a subsequent kernel, so we always
  167. * remove it from the device tree.
  168. */
  169. static void remove_ima_buffer(void *fdt, int chosen_node)
  170. {
  171. int ret, len;
  172. unsigned long addr;
  173. size_t size;
  174. const void *prop;
  175. if (!IS_ENABLED(CONFIG_HAVE_IMA_KEXEC))
  176. return;
  177. prop = fdt_getprop(fdt, chosen_node, "linux,ima-kexec-buffer", &len);
  178. if (!prop)
  179. return;
  180. ret = do_get_kexec_buffer(prop, len, &addr, &size);
  181. fdt_delprop(fdt, chosen_node, "linux,ima-kexec-buffer");
  182. if (ret)
  183. return;
  184. ret = fdt_find_and_del_mem_rsv(fdt, addr, size);
  185. if (!ret)
  186. pr_debug("Removed old IMA buffer reservation.\n");
  187. }
  188. #ifdef CONFIG_IMA_KEXEC
  189. /**
  190. * setup_ima_buffer - add IMA buffer information to the fdt
  191. * @image: kexec image being loaded.
  192. * @fdt: Flattened device tree for the next kernel.
  193. * @chosen_node: Offset to the chosen node.
  194. *
  195. * Return: 0 on success, or negative errno on error.
  196. */
  197. static int setup_ima_buffer(const struct kimage *image, void *fdt,
  198. int chosen_node)
  199. {
  200. int ret;
  201. if (!image->ima_buffer_size)
  202. return 0;
  203. ret = fdt_appendprop_addrrange(fdt, 0, chosen_node,
  204. "linux,ima-kexec-buffer",
  205. image->ima_buffer_addr,
  206. image->ima_buffer_size);
  207. if (ret < 0)
  208. return -EINVAL;
  209. ret = fdt_add_mem_rsv(fdt, image->ima_buffer_addr,
  210. image->ima_buffer_size);
  211. if (ret)
  212. return -EINVAL;
  213. pr_debug("IMA buffer at 0x%llx, size = 0x%zx\n",
  214. image->ima_buffer_addr, image->ima_buffer_size);
  215. return 0;
  216. }
  217. #else /* CONFIG_IMA_KEXEC */
  218. static inline int setup_ima_buffer(const struct kimage *image, void *fdt,
  219. int chosen_node)
  220. {
  221. return 0;
  222. }
  223. #endif /* CONFIG_IMA_KEXEC */
  224. /*
  225. * of_kexec_alloc_and_setup_fdt - Alloc and setup a new Flattened Device Tree
  226. *
  227. * @image: kexec image being loaded.
  228. * @initrd_load_addr: Address where the next initrd will be loaded.
  229. * @initrd_len: Size of the next initrd, or 0 if there will be none.
  230. * @cmdline: Command line for the next kernel, or NULL if there will
  231. * be none.
  232. * @extra_fdt_size: Additional size for the new FDT buffer.
  233. *
  234. * Return: fdt on success, or NULL errno on error.
  235. */
  236. void *of_kexec_alloc_and_setup_fdt(const struct kimage *image,
  237. unsigned long initrd_load_addr,
  238. unsigned long initrd_len,
  239. const char *cmdline, size_t extra_fdt_size)
  240. {
  241. void *fdt;
  242. int ret, chosen_node, len;
  243. const void *prop;
  244. size_t fdt_size;
  245. fdt_size = fdt_totalsize(initial_boot_params) +
  246. (cmdline ? strlen(cmdline) : 0) +
  247. FDT_EXTRA_SPACE +
  248. extra_fdt_size;
  249. fdt = kvmalloc(fdt_size, GFP_KERNEL);
  250. if (!fdt)
  251. return NULL;
  252. ret = fdt_open_into(initial_boot_params, fdt, fdt_size);
  253. if (ret < 0) {
  254. pr_err("Error %d setting up the new device tree.\n", ret);
  255. goto out;
  256. }
  257. /* Remove memory reservation for the current device tree. */
  258. ret = fdt_find_and_del_mem_rsv(fdt, __pa(initial_boot_params),
  259. fdt_totalsize(initial_boot_params));
  260. if (ret == -EINVAL) {
  261. pr_err("Error removing memory reservation.\n");
  262. goto out;
  263. }
  264. chosen_node = fdt_path_offset(fdt, "/chosen");
  265. if (chosen_node == -FDT_ERR_NOTFOUND)
  266. chosen_node = fdt_add_subnode(fdt, fdt_path_offset(fdt, "/"),
  267. "chosen");
  268. if (chosen_node < 0) {
  269. ret = chosen_node;
  270. goto out;
  271. }
  272. ret = fdt_delprop(fdt, chosen_node, "linux,elfcorehdr");
  273. if (ret && ret != -FDT_ERR_NOTFOUND)
  274. goto out;
  275. ret = fdt_delprop(fdt, chosen_node, "linux,usable-memory-range");
  276. if (ret && ret != -FDT_ERR_NOTFOUND)
  277. goto out;
  278. /* Did we boot using an initrd? */
  279. prop = fdt_getprop(fdt, chosen_node, "linux,initrd-start", &len);
  280. if (prop) {
  281. u64 tmp_start, tmp_end, tmp_size;
  282. tmp_start = of_read_number(prop, len / 4);
  283. prop = fdt_getprop(fdt, chosen_node, "linux,initrd-end", &len);
  284. if (!prop) {
  285. ret = -EINVAL;
  286. goto out;
  287. }
  288. tmp_end = of_read_number(prop, len / 4);
  289. /*
  290. * kexec reserves exact initrd size, while firmware may
  291. * reserve a multiple of PAGE_SIZE, so check for both.
  292. */
  293. tmp_size = tmp_end - tmp_start;
  294. ret = fdt_find_and_del_mem_rsv(fdt, tmp_start, tmp_size);
  295. if (ret == -ENOENT)
  296. ret = fdt_find_and_del_mem_rsv(fdt, tmp_start,
  297. round_up(tmp_size, PAGE_SIZE));
  298. if (ret == -EINVAL)
  299. goto out;
  300. }
  301. /* add initrd-* */
  302. if (initrd_load_addr) {
  303. ret = fdt_setprop_u64(fdt, chosen_node, "linux,initrd-start",
  304. initrd_load_addr);
  305. if (ret)
  306. goto out;
  307. ret = fdt_setprop_u64(fdt, chosen_node, "linux,initrd-end",
  308. initrd_load_addr + initrd_len);
  309. if (ret)
  310. goto out;
  311. ret = fdt_add_mem_rsv(fdt, initrd_load_addr, initrd_len);
  312. if (ret)
  313. goto out;
  314. } else {
  315. ret = fdt_delprop(fdt, chosen_node, "linux,initrd-start");
  316. if (ret && (ret != -FDT_ERR_NOTFOUND))
  317. goto out;
  318. ret = fdt_delprop(fdt, chosen_node, "linux,initrd-end");
  319. if (ret && (ret != -FDT_ERR_NOTFOUND))
  320. goto out;
  321. }
  322. if (image->type == KEXEC_TYPE_CRASH) {
  323. /* add linux,elfcorehdr */
  324. ret = fdt_appendprop_addrrange(fdt, 0, chosen_node,
  325. "linux,elfcorehdr", image->elf_load_addr,
  326. image->elf_headers_sz);
  327. if (ret)
  328. goto out;
  329. /*
  330. * Avoid elfcorehdr from being stomped on in kdump kernel by
  331. * setting up memory reserve map.
  332. */
  333. ret = fdt_add_mem_rsv(fdt, image->elf_load_addr,
  334. image->elf_headers_sz);
  335. if (ret)
  336. goto out;
  337. /* add linux,usable-memory-range */
  338. ret = fdt_appendprop_addrrange(fdt, 0, chosen_node,
  339. "linux,usable-memory-range", crashk_res.start,
  340. crashk_res.end - crashk_res.start + 1);
  341. if (ret)
  342. goto out;
  343. if (crashk_low_res.end) {
  344. ret = fdt_appendprop_addrrange(fdt, 0, chosen_node,
  345. "linux,usable-memory-range",
  346. crashk_low_res.start,
  347. crashk_low_res.end - crashk_low_res.start + 1);
  348. if (ret)
  349. goto out;
  350. }
  351. }
  352. /* add bootargs */
  353. if (cmdline) {
  354. ret = fdt_setprop_string(fdt, chosen_node, "bootargs", cmdline);
  355. if (ret)
  356. goto out;
  357. } else {
  358. ret = fdt_delprop(fdt, chosen_node, "bootargs");
  359. if (ret && (ret != -FDT_ERR_NOTFOUND))
  360. goto out;
  361. }
  362. /* add kaslr-seed */
  363. ret = fdt_delprop(fdt, chosen_node, "kaslr-seed");
  364. if (ret == -FDT_ERR_NOTFOUND)
  365. ret = 0;
  366. else if (ret)
  367. goto out;
  368. if (rng_is_initialized()) {
  369. u64 seed = get_random_u64();
  370. ret = fdt_setprop_u64(fdt, chosen_node, "kaslr-seed", seed);
  371. if (ret)
  372. goto out;
  373. } else {
  374. pr_notice("RNG is not initialised: omitting \"%s\" property\n",
  375. "kaslr-seed");
  376. }
  377. /* add rng-seed */
  378. if (rng_is_initialized()) {
  379. void *rng_seed;
  380. ret = fdt_setprop_placeholder(fdt, chosen_node, "rng-seed",
  381. RNG_SEED_SIZE, &rng_seed);
  382. if (ret)
  383. goto out;
  384. get_random_bytes(rng_seed, RNG_SEED_SIZE);
  385. } else {
  386. pr_notice("RNG is not initialised: omitting \"%s\" property\n",
  387. "rng-seed");
  388. }
  389. ret = fdt_setprop(fdt, chosen_node, "linux,booted-from-kexec", NULL, 0);
  390. if (ret)
  391. goto out;
  392. remove_ima_buffer(fdt, chosen_node);
  393. ret = setup_ima_buffer(image, fdt, fdt_path_offset(fdt, "/chosen"));
  394. out:
  395. if (ret) {
  396. kvfree(fdt);
  397. fdt = NULL;
  398. }
  399. return fdt;
  400. }