1 // SPDX-License-Identifier: GPL-2.0
3 * This file contains core hardware tag-based KASAN code.
5 * Copyright (c) 2020 Google, Inc.
6 * Author: Andrey Konovalov <andreyknvl@google.com>
9 #define pr_fmt(fmt) "kasan: " fmt
11 #include <linux/init.h>
12 #include <linux/kasan.h>
13 #include <linux/kernel.h>
14 #include <linux/memory.h>
16 #include <linux/static_key.h>
17 #include <linux/string.h>
18 #include <linux/types.h>
29 KASAN_ARG_MODE_DEFAULT,
34 enum kasan_arg_stacktrace {
35 KASAN_ARG_STACKTRACE_DEFAULT,
36 KASAN_ARG_STACKTRACE_OFF,
37 KASAN_ARG_STACKTRACE_ON,
40 enum kasan_arg_fault {
41 KASAN_ARG_FAULT_DEFAULT,
42 KASAN_ARG_FAULT_REPORT,
43 KASAN_ARG_FAULT_PANIC,
46 static enum kasan_arg kasan_arg __ro_after_init;
47 static enum kasan_arg_mode kasan_arg_mode __ro_after_init;
48 static enum kasan_arg_stacktrace kasan_arg_stacktrace __ro_after_init;
49 static enum kasan_arg_fault kasan_arg_fault __ro_after_init;
51 /* Whether KASAN is enabled at all. */
52 DEFINE_STATIC_KEY_FALSE(kasan_flag_enabled);
53 EXPORT_SYMBOL(kasan_flag_enabled);
55 /* Whether the asynchronous mode is enabled. */
56 bool kasan_flag_async __ro_after_init;
57 EXPORT_SYMBOL_GPL(kasan_flag_async);
59 /* Whether to collect alloc/free stack traces. */
60 DEFINE_STATIC_KEY_FALSE(kasan_flag_stacktrace);
62 /* Whether to panic or print a report and disable tag checking on fault. */
63 bool kasan_flag_panic __ro_after_init;
66 static int __init early_kasan_flag(char *arg)
71 if (!strcmp(arg, "off"))
72 kasan_arg = KASAN_ARG_OFF;
73 else if (!strcmp(arg, "on"))
74 kasan_arg = KASAN_ARG_ON;
80 early_param("kasan", early_kasan_flag);
82 /* kasan.mode=sync/async */
83 static int __init early_kasan_mode(char *arg)
88 if (!strcmp(arg, "sync"))
89 kasan_arg_mode = KASAN_ARG_MODE_SYNC;
90 else if (!strcmp(arg, "async"))
91 kasan_arg_mode = KASAN_ARG_MODE_ASYNC;
97 early_param("kasan.mode", early_kasan_mode);
99 /* kasan.stacktrace=off/on */
100 static int __init early_kasan_flag_stacktrace(char *arg)
105 if (!strcmp(arg, "off"))
106 kasan_arg_stacktrace = KASAN_ARG_STACKTRACE_OFF;
107 else if (!strcmp(arg, "on"))
108 kasan_arg_stacktrace = KASAN_ARG_STACKTRACE_ON;
114 early_param("kasan.stacktrace", early_kasan_flag_stacktrace);
116 /* kasan.fault=report/panic */
117 static int __init early_kasan_fault(char *arg)
122 if (!strcmp(arg, "report"))
123 kasan_arg_fault = KASAN_ARG_FAULT_REPORT;
124 else if (!strcmp(arg, "panic"))
125 kasan_arg_fault = KASAN_ARG_FAULT_PANIC;
131 early_param("kasan.fault", early_kasan_fault);
133 /* kasan_init_hw_tags_cpu() is called for each CPU. */
134 void kasan_init_hw_tags_cpu(void)
137 * There's no need to check that the hardware is MTE-capable here,
138 * as this function is only called for MTE-capable hardware.
141 /* If KASAN is disabled via command line, don't initialize it. */
142 if (kasan_arg == KASAN_ARG_OFF)
145 hw_init_tags(KASAN_TAG_MAX);
148 * Enable async mode only when explicitly requested through
151 if (kasan_arg_mode == KASAN_ARG_MODE_ASYNC)
152 hw_enable_tagging_async();
154 hw_enable_tagging_sync();
157 /* kasan_init_hw_tags() is called once on boot CPU. */
158 void __init kasan_init_hw_tags(void)
160 /* If hardware doesn't support MTE, don't initialize KASAN. */
161 if (!system_supports_mte())
164 /* If KASAN is disabled via command line, don't initialize it. */
165 if (kasan_arg == KASAN_ARG_OFF)
169 static_branch_enable(&kasan_flag_enabled);
171 switch (kasan_arg_mode) {
172 case KASAN_ARG_MODE_DEFAULT:
174 * Default to sync mode.
175 * Do nothing, kasan_flag_async keeps its default value.
178 case KASAN_ARG_MODE_SYNC:
179 /* Do nothing, kasan_flag_async keeps its default value. */
181 case KASAN_ARG_MODE_ASYNC:
182 /* Async mode enabled. */
183 kasan_flag_async = true;
187 switch (kasan_arg_stacktrace) {
188 case KASAN_ARG_STACKTRACE_DEFAULT:
189 /* Default to enabling stack trace collection. */
190 static_branch_enable(&kasan_flag_stacktrace);
192 case KASAN_ARG_STACKTRACE_OFF:
193 /* Do nothing, kasan_flag_stacktrace keeps its default value. */
195 case KASAN_ARG_STACKTRACE_ON:
196 static_branch_enable(&kasan_flag_stacktrace);
200 switch (kasan_arg_fault) {
201 case KASAN_ARG_FAULT_DEFAULT:
203 * Default to no panic on report.
204 * Do nothing, kasan_flag_panic keeps its default value.
207 case KASAN_ARG_FAULT_REPORT:
208 /* Do nothing, kasan_flag_panic keeps its default value. */
210 case KASAN_ARG_FAULT_PANIC:
211 /* Enable panic on report. */
212 kasan_flag_panic = true;
216 pr_info("KernelAddressSanitizer initialized\n");
219 void kasan_set_free_info(struct kmem_cache *cache,
220 void *object, u8 tag)
222 struct kasan_alloc_meta *alloc_meta;
224 alloc_meta = kasan_get_alloc_meta(cache, object);
226 kasan_set_track(&alloc_meta->free_track[0], GFP_NOWAIT);
229 struct kasan_track *kasan_get_free_track(struct kmem_cache *cache,
230 void *object, u8 tag)
232 struct kasan_alloc_meta *alloc_meta;
234 alloc_meta = kasan_get_alloc_meta(cache, object);
238 return &alloc_meta->free_track[0];
241 #if IS_ENABLED(CONFIG_KASAN_KUNIT_TEST)
243 void kasan_set_tagging_report_once(bool state)
245 hw_set_tagging_report_once(state);
247 EXPORT_SYMBOL_GPL(kasan_set_tagging_report_once);
249 void kasan_enable_tagging_sync(void)
251 hw_enable_tagging_sync();
253 EXPORT_SYMBOL_GPL(kasan_enable_tagging_sync);
255 void kasan_force_async_fault(void)
257 hw_force_async_tag_fault();
259 EXPORT_SYMBOL_GPL(kasan_force_async_fault);