blob: 9495d7f3516fca54012691b642ea22380fc64ffd [file] [log] [blame]
Jon Medhurst24371702011-04-19 17:56:58 +01001/*
2 * arch/arm/kernel/kprobes-thumb.c
3 *
4 * Copyright (C) 2011 Jon Medhurst <tixy@yxit.co.uk>.
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License version 2 as
8 * published by the Free Software Foundation.
9 */
10
David A. Long87abef62014-03-05 21:06:29 -050011#include <linux/types.h>
Jon Medhurst24371702011-04-19 17:56:58 +010012#include <linux/kernel.h>
David A. Long87abef62014-03-05 21:06:29 -050013#include <linux/ptrace.h>
Jon Medhurst24371702011-04-19 17:56:58 +010014#include <linux/kprobes.h>
15
16#include "kprobes.h"
David A. Long87abef62014-03-05 21:06:29 -050017#include "probes-thumb.h"
Jon Medhursteaf4f33f2011-04-20 19:29:52 +010018
David A. Long3e6cd392014-03-06 18:06:43 -050019/* These emulation encodings are functionally equivalent... */
20#define t32_emulate_rd8rn16rm0ra12_noflags \
21 t32_emulate_rdlo12rdhi8rn16rm0_noflags
22
David A. Long87abef62014-03-05 21:06:29 -050023/* t32 thumb actions */
24
David A. Long3e6cd392014-03-06 18:06:43 -050025static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -050026t32_simulate_table_branch(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -050027 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstdd212bd32011-07-03 14:26:16 +010028{
David A. Long7579f4b32014-03-07 11:19:32 -050029 unsigned long pc = regs->ARM_pc;
Jon Medhurstdd212bd32011-07-03 14:26:16 +010030 int rn = (insn >> 16) & 0xf;
31 int rm = insn & 0xf;
32
33 unsigned long rnv = (rn == 15) ? pc : regs->uregs[rn];
34 unsigned long rmv = regs->uregs[rm];
35 unsigned int halfwords;
36
Jon Medhurstce715c72011-07-03 14:53:45 +010037 if (insn & 0x10) /* TBH */
Jon Medhurstdd212bd32011-07-03 14:26:16 +010038 halfwords = ((u16 *)rnv)[rmv];
Jon Medhurstce715c72011-07-03 14:53:45 +010039 else /* TBB */
Jon Medhurstdd212bd32011-07-03 14:26:16 +010040 halfwords = ((u8 *)rnv)[rmv];
41
42 regs->ARM_pc = pc + 2 * halfwords;
43}
44
David A. Long3e6cd392014-03-06 18:06:43 -050045static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -050046t32_simulate_mrs(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -050047 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstb06f3ee2011-07-03 14:52:18 +010048{
Jon Medhurstb06f3ee2011-07-03 14:52:18 +010049 int rd = (insn >> 8) & 0xf;
50 unsigned long mask = 0xf8ff03df; /* Mask out execution state */
51 regs->uregs[rd] = regs->ARM_cpsr & mask;
52}
53
David A. Long3e6cd392014-03-06 18:06:43 -050054static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -050055t32_simulate_cond_branch(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -050056 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstce715c72011-07-03 14:53:45 +010057{
David A. Long7579f4b32014-03-07 11:19:32 -050058 unsigned long pc = regs->ARM_pc;
Jon Medhurstce715c72011-07-03 14:53:45 +010059
60 long offset = insn & 0x7ff; /* imm11 */
61 offset += (insn & 0x003f0000) >> 5; /* imm6 */
62 offset += (insn & 0x00002000) << 4; /* J1 */
63 offset += (insn & 0x00000800) << 7; /* J2 */
64 offset -= (insn & 0x04000000) >> 7; /* Apply sign bit */
65
66 regs->ARM_pc = pc + (offset * 2);
67}
68
David A. Long44a0a592014-03-05 21:23:42 -050069static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -050070t32_decode_cond_branch(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -050071 const struct decode_header *d)
Jon Medhurstce715c72011-07-03 14:53:45 +010072{
73 int cc = (insn >> 22) & 0xf;
David A. Longf145d662014-03-05 21:17:23 -050074 asi->insn_check_cc = probes_condition_checks[cc];
Jon Medhurstce715c72011-07-03 14:53:45 +010075 asi->insn_handler = t32_simulate_cond_branch;
76 return INSN_GOOD_NO_SLOT;
77}
78
David A. Long3e6cd392014-03-06 18:06:43 -050079static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -050080t32_simulate_branch(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -050081 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstce715c72011-07-03 14:53:45 +010082{
David A. Long7579f4b32014-03-07 11:19:32 -050083 unsigned long pc = regs->ARM_pc;
Jon Medhurstce715c72011-07-03 14:53:45 +010084
85 long offset = insn & 0x7ff; /* imm11 */
86 offset += (insn & 0x03ff0000) >> 5; /* imm10 */
87 offset += (insn & 0x00002000) << 9; /* J1 */
88 offset += (insn & 0x00000800) << 10; /* J2 */
89 if (insn & 0x04000000)
90 offset -= 0x00800000; /* Apply sign bit */
91 else
92 offset ^= 0x00600000; /* Invert J1 and J2 */
93
94 if (insn & (1 << 14)) {
95 /* BL or BLX */
David A. Long7579f4b32014-03-07 11:19:32 -050096 regs->ARM_lr = regs->ARM_pc | 1;
Jon Medhurstce715c72011-07-03 14:53:45 +010097 if (!(insn & (1 << 12))) {
98 /* BLX so switch to ARM mode */
99 regs->ARM_cpsr &= ~PSR_T_BIT;
100 pc &= ~3;
101 }
102 }
103
104 regs->ARM_pc = pc + (offset * 2);
105}
106
David A. Long3e6cd392014-03-06 18:06:43 -0500107static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500108t32_simulate_ldr_literal(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500109 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstd6910232011-07-03 15:04:26 +0100110{
David A. Long7579f4b32014-03-07 11:19:32 -0500111 unsigned long addr = regs->ARM_pc & ~3;
Jon Medhurstd6910232011-07-03 15:04:26 +0100112 int rt = (insn >> 12) & 0xf;
113 unsigned long rtv;
114
115 long offset = insn & 0xfff;
116 if (insn & 0x00800000)
117 addr += offset;
118 else
119 addr -= offset;
120
121 if (insn & 0x00400000) {
122 /* LDR */
123 rtv = *(unsigned long *)addr;
124 if (rt == 15) {
125 bx_write_pc(rtv, regs);
126 return;
127 }
128 } else if (insn & 0x00200000) {
129 /* LDRH */
130 if (insn & 0x01000000)
131 rtv = *(s16 *)addr;
132 else
133 rtv = *(u16 *)addr;
134 } else {
135 /* LDRB */
136 if (insn & 0x01000000)
137 rtv = *(s8 *)addr;
138 else
139 rtv = *(u8 *)addr;
140 }
141
142 regs->uregs[rt] = rtv;
143}
144
David A. Long44a0a592014-03-05 21:23:42 -0500145static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500146t32_decode_ldmstm(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500147 const struct decode_header *d)
Jon Medhursteaf1d062011-07-07 08:59:32 +0100148{
David A. Long44a0a592014-03-05 21:23:42 -0500149 enum probes_insn ret = kprobe_decode_ldmstm(insn, asi, d);
Jon Medhursteaf1d062011-07-07 08:59:32 +0100150
151 /* Fixup modified instruction to have halfwords in correct order...*/
Ben Dooks888be252013-11-08 18:29:25 +0000152 insn = __mem_to_opcode_arm(asi->insn[0]);
153 ((u16 *)asi->insn)[0] = __opcode_to_mem_thumb16(insn >> 16);
154 ((u16 *)asi->insn)[1] = __opcode_to_mem_thumb16(insn & 0xffff);
Jon Medhursteaf1d062011-07-07 08:59:32 +0100155
156 return ret;
157}
158
David A. Long3e6cd392014-03-06 18:06:43 -0500159static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500160t32_emulate_ldrdstrd(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500161 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstb48354d2011-07-03 14:23:21 +0100162{
David A. Long7579f4b32014-03-07 11:19:32 -0500163 unsigned long pc = regs->ARM_pc & ~3;
Jon Medhurstb48354d2011-07-03 14:23:21 +0100164 int rt1 = (insn >> 12) & 0xf;
165 int rt2 = (insn >> 8) & 0xf;
166 int rn = (insn >> 16) & 0xf;
167
168 register unsigned long rt1v asm("r0") = regs->uregs[rt1];
169 register unsigned long rt2v asm("r1") = regs->uregs[rt2];
170 register unsigned long rnv asm("r2") = (rn == 15) ? pc
171 : regs->uregs[rn];
172
173 __asm__ __volatile__ (
174 "blx %[fn]"
175 : "=r" (rt1v), "=r" (rt2v), "=r" (rnv)
David A. Long7579f4b32014-03-07 11:19:32 -0500176 : "0" (rt1v), "1" (rt2v), "2" (rnv), [fn] "r" (asi->insn_fn)
Jon Medhurstb48354d2011-07-03 14:23:21 +0100177 : "lr", "memory", "cc"
178 );
179
180 if (rn != 15)
181 regs->uregs[rn] = rnv; /* Writeback base register */
182 regs->uregs[rt1] = rt1v;
183 regs->uregs[rt2] = rt2v;
184}
185
David A. Long3e6cd392014-03-06 18:06:43 -0500186static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500187t32_emulate_ldrstr(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500188 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstd6910232011-07-03 15:04:26 +0100189{
Jon Medhurstd6910232011-07-03 15:04:26 +0100190 int rt = (insn >> 12) & 0xf;
191 int rn = (insn >> 16) & 0xf;
192 int rm = insn & 0xf;
193
194 register unsigned long rtv asm("r0") = regs->uregs[rt];
195 register unsigned long rnv asm("r2") = regs->uregs[rn];
196 register unsigned long rmv asm("r3") = regs->uregs[rm];
197
198 __asm__ __volatile__ (
199 "blx %[fn]"
200 : "=r" (rtv), "=r" (rnv)
David A. Long7579f4b32014-03-07 11:19:32 -0500201 : "0" (rtv), "1" (rnv), "r" (rmv), [fn] "r" (asi->insn_fn)
Jon Medhurstd6910232011-07-03 15:04:26 +0100202 : "lr", "memory", "cc"
203 );
204
205 regs->uregs[rn] = rnv; /* Writeback base register */
206 if (rt == 15) /* Can't be true for a STR as they aren't allowed */
207 bx_write_pc(rtv, regs);
208 else
209 regs->uregs[rt] = rtv;
210}
211
David A. Long3e6cd392014-03-06 18:06:43 -0500212static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500213t32_emulate_rd8rn16rm0_rwflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500214 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst080e0012011-07-03 14:31:58 +0100215{
Jon Medhurst080e0012011-07-03 14:31:58 +0100216 int rd = (insn >> 8) & 0xf;
217 int rn = (insn >> 16) & 0xf;
218 int rm = insn & 0xf;
219
220 register unsigned long rdv asm("r1") = regs->uregs[rd];
221 register unsigned long rnv asm("r2") = regs->uregs[rn];
222 register unsigned long rmv asm("r3") = regs->uregs[rm];
223 unsigned long cpsr = regs->ARM_cpsr;
224
225 __asm__ __volatile__ (
226 "msr cpsr_fs, %[cpsr] \n\t"
227 "blx %[fn] \n\t"
228 "mrs %[cpsr], cpsr \n\t"
229 : "=r" (rdv), [cpsr] "=r" (cpsr)
230 : "0" (rdv), "r" (rnv), "r" (rmv),
David A. Long7579f4b32014-03-07 11:19:32 -0500231 "1" (cpsr), [fn] "r" (asi->insn_fn)
Jon Medhurst080e0012011-07-03 14:31:58 +0100232 : "lr", "memory", "cc"
233 );
234
235 regs->uregs[rd] = rdv;
236 regs->ARM_cpsr = (regs->ARM_cpsr & ~APSR_MASK) | (cpsr & APSR_MASK);
237}
238
David A. Long3e6cd392014-03-06 18:06:43 -0500239static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500240t32_emulate_rd8pc16_noflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500241 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst78487862011-07-03 14:40:26 +0100242{
David A. Long7579f4b32014-03-07 11:19:32 -0500243 unsigned long pc = regs->ARM_pc;
Jon Medhurst78487862011-07-03 14:40:26 +0100244 int rd = (insn >> 8) & 0xf;
245
246 register unsigned long rdv asm("r1") = regs->uregs[rd];
247 register unsigned long rnv asm("r2") = pc & ~3;
248
249 __asm__ __volatile__ (
250 "blx %[fn]"
251 : "=r" (rdv)
David A. Long7579f4b32014-03-07 11:19:32 -0500252 : "0" (rdv), "r" (rnv), [fn] "r" (asi->insn_fn)
Jon Medhurst78487862011-07-03 14:40:26 +0100253 : "lr", "memory", "cc"
254 );
255
256 regs->uregs[rd] = rdv;
257}
258
David A. Long3e6cd392014-03-06 18:06:43 -0500259static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500260t32_emulate_rd8rn16_noflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500261 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst78487862011-07-03 14:40:26 +0100262{
Jon Medhurst78487862011-07-03 14:40:26 +0100263 int rd = (insn >> 8) & 0xf;
264 int rn = (insn >> 16) & 0xf;
265
266 register unsigned long rdv asm("r1") = regs->uregs[rd];
267 register unsigned long rnv asm("r2") = regs->uregs[rn];
268
269 __asm__ __volatile__ (
270 "blx %[fn]"
271 : "=r" (rdv)
David A. Long7579f4b32014-03-07 11:19:32 -0500272 : "0" (rdv), "r" (rnv), [fn] "r" (asi->insn_fn)
Jon Medhurst78487862011-07-03 14:40:26 +0100273 : "lr", "memory", "cc"
274 );
275
276 regs->uregs[rd] = rdv;
277}
278
David A. Long3e6cd392014-03-06 18:06:43 -0500279static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500280t32_emulate_rdlo12rdhi8rn16rm0_noflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500281 struct arch_probes_insn *asi,
David A. Long7579f4b32014-03-07 11:19:32 -0500282 struct pt_regs *regs)
Jon Medhurst231fb152011-07-03 15:15:11 +0100283{
Jon Medhurst231fb152011-07-03 15:15:11 +0100284 int rdlo = (insn >> 12) & 0xf;
285 int rdhi = (insn >> 8) & 0xf;
286 int rn = (insn >> 16) & 0xf;
287 int rm = insn & 0xf;
288
289 register unsigned long rdlov asm("r0") = regs->uregs[rdlo];
290 register unsigned long rdhiv asm("r1") = regs->uregs[rdhi];
291 register unsigned long rnv asm("r2") = regs->uregs[rn];
292 register unsigned long rmv asm("r3") = regs->uregs[rm];
293
294 __asm__ __volatile__ (
295 "blx %[fn]"
296 : "=r" (rdlov), "=r" (rdhiv)
297 : "0" (rdlov), "1" (rdhiv), "r" (rnv), "r" (rmv),
David A. Long7579f4b32014-03-07 11:19:32 -0500298 [fn] "r" (asi->insn_fn)
Jon Medhurst231fb152011-07-03 15:15:11 +0100299 : "lr", "memory", "cc"
300 );
301
302 regs->uregs[rdlo] = rdlov;
303 regs->uregs[rdhi] = rdhiv;
304}
David A. Long87abef62014-03-05 21:06:29 -0500305/* t16 thumb actions */
Jon Medhurst231fb152011-07-03 15:15:11 +0100306
David A. Long3e6cd392014-03-06 18:06:43 -0500307static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500308t16_simulate_bxblx(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500309 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhursta9c3c292011-07-02 15:51:03 +0100310{
David A. Long7579f4b32014-03-07 11:19:32 -0500311 unsigned long pc = regs->ARM_pc + 2;
Jon Medhursta9c3c292011-07-02 15:51:03 +0100312 int rm = (insn >> 3) & 0xf;
313 unsigned long rmv = (rm == 15) ? pc : regs->uregs[rm];
314
315 if (insn & (1 << 7)) /* BLX ? */
David A. Long7579f4b32014-03-07 11:19:32 -0500316 regs->ARM_lr = regs->ARM_pc | 1;
Jon Medhursta9c3c292011-07-02 15:51:03 +0100317
318 bx_write_pc(rmv, regs);
319}
320
David A. Long3e6cd392014-03-06 18:06:43 -0500321static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500322t16_simulate_ldr_literal(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500323 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstf8695142011-07-02 16:00:09 +0100324{
David A. Long7579f4b32014-03-07 11:19:32 -0500325 unsigned long *base = (unsigned long *)((regs->ARM_pc + 2) & ~3);
Jon Medhurstf8695142011-07-02 16:00:09 +0100326 long index = insn & 0xff;
327 int rt = (insn >> 8) & 0x7;
328 regs->uregs[rt] = base[index];
329}
330
David A. Long3e6cd392014-03-06 18:06:43 -0500331static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500332t16_simulate_ldrstr_sp_relative(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500333 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstf8695142011-07-02 16:00:09 +0100334{
Jon Medhurstf8695142011-07-02 16:00:09 +0100335 unsigned long* base = (unsigned long *)regs->ARM_sp;
336 long index = insn & 0xff;
337 int rt = (insn >> 8) & 0x7;
338 if (insn & 0x800) /* LDR */
339 regs->uregs[rt] = base[index];
340 else /* STR */
341 base[index] = regs->uregs[rt];
342}
343
David A. Long3e6cd392014-03-06 18:06:43 -0500344static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500345t16_simulate_reladr(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500346 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst2f335822011-07-02 16:05:53 +0100347{
Jon Medhurst2f335822011-07-02 16:05:53 +0100348 unsigned long base = (insn & 0x800) ? regs->ARM_sp
David A. Long7579f4b32014-03-07 11:19:32 -0500349 : ((regs->ARM_pc + 2) & ~3);
Jon Medhurst2f335822011-07-02 16:05:53 +0100350 long offset = insn & 0xff;
351 int rt = (insn >> 8) & 0x7;
352 regs->uregs[rt] = base + offset * 4;
353}
354
David A. Long3e6cd392014-03-06 18:06:43 -0500355static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500356t16_simulate_add_sp_imm(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500357 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst2f335822011-07-02 16:05:53 +0100358{
Jon Medhurst2f335822011-07-02 16:05:53 +0100359 long imm = insn & 0x7f;
360 if (insn & 0x80) /* SUB */
361 regs->ARM_sp -= imm * 4;
362 else /* ADD */
363 regs->ARM_sp += imm * 4;
364}
365
David A. Long3e6cd392014-03-06 18:06:43 -0500366static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500367t16_simulate_cbz(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500368 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst32818f32011-07-02 16:10:44 +0100369{
Jon Medhurst32818f32011-07-02 16:10:44 +0100370 int rn = insn & 0x7;
David A. Longf145d662014-03-05 21:17:23 -0500371 probes_opcode_t nonzero = regs->uregs[rn] ? insn : ~insn;
Jon Medhurst32818f32011-07-02 16:10:44 +0100372 if (nonzero & 0x800) {
373 long i = insn & 0x200;
374 long imm5 = insn & 0xf8;
David A. Long7579f4b32014-03-07 11:19:32 -0500375 unsigned long pc = regs->ARM_pc + 2;
Jon Medhurst32818f32011-07-02 16:10:44 +0100376 regs->ARM_pc = pc + (i >> 3) + (imm5 >> 2);
377 }
378}
379
David A. Long3e6cd392014-03-06 18:06:43 -0500380static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500381t16_simulate_it(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500382 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst5b94faf2011-07-02 16:16:05 +0100383{
384 /*
385 * The 8 IT state bits are split into two parts in CPSR:
386 * ITSTATE<1:0> are in CPSR<26:25>
387 * ITSTATE<7:2> are in CPSR<15:10>
388 * The new IT state is in the lower byte of insn.
389 */
Jon Medhurst5b94faf2011-07-02 16:16:05 +0100390 unsigned long cpsr = regs->ARM_cpsr;
391 cpsr &= ~PSR_IT_MASK;
392 cpsr |= (insn & 0xfc) << 8;
393 cpsr |= (insn & 0x03) << 25;
394 regs->ARM_cpsr = cpsr;
395}
396
David A. Long3e6cd392014-03-06 18:06:43 -0500397static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500398t16_singlestep_it(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500399 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst5b94faf2011-07-02 16:16:05 +0100400{
401 regs->ARM_pc += 2;
David A. Long7579f4b32014-03-07 11:19:32 -0500402 t16_simulate_it(insn, asi, regs);
Jon Medhurst5b94faf2011-07-02 16:16:05 +0100403}
404
David A. Long44a0a592014-03-05 21:23:42 -0500405static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500406t16_decode_it(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500407 const struct decode_header *d)
Jon Medhurst5b94faf2011-07-02 16:16:05 +0100408{
409 asi->insn_singlestep = t16_singlestep_it;
410 return INSN_GOOD_NO_SLOT;
411}
412
David A. Long3e6cd392014-03-06 18:06:43 -0500413static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500414t16_simulate_cond_branch(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500415 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst396b41f2011-07-02 16:30:43 +0100416{
David A. Long7579f4b32014-03-07 11:19:32 -0500417 unsigned long pc = regs->ARM_pc + 2;
Jon Medhurst396b41f2011-07-02 16:30:43 +0100418 long offset = insn & 0x7f;
419 offset -= insn & 0x80; /* Apply sign bit */
420 regs->ARM_pc = pc + (offset * 2);
421}
422
David A. Long44a0a592014-03-05 21:23:42 -0500423static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500424t16_decode_cond_branch(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500425 const struct decode_header *d)
Jon Medhurst396b41f2011-07-02 16:30:43 +0100426{
427 int cc = (insn >> 8) & 0xf;
David A. Longf145d662014-03-05 21:17:23 -0500428 asi->insn_check_cc = probes_condition_checks[cc];
Jon Medhurst396b41f2011-07-02 16:30:43 +0100429 asi->insn_handler = t16_simulate_cond_branch;
430 return INSN_GOOD_NO_SLOT;
431}
432
David A. Long3e6cd392014-03-06 18:06:43 -0500433static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500434t16_simulate_branch(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500435 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst396b41f2011-07-02 16:30:43 +0100436{
David A. Long7579f4b32014-03-07 11:19:32 -0500437 unsigned long pc = regs->ARM_pc + 2;
Jon Medhurst396b41f2011-07-02 16:30:43 +0100438 long offset = insn & 0x3ff;
439 offset -= insn & 0x400; /* Apply sign bit */
440 regs->ARM_pc = pc + (offset * 2);
441}
442
Jon Medhurst02d194f2011-07-02 15:46:05 +0100443static unsigned long __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500444t16_emulate_loregs(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500445 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst02d194f2011-07-02 15:46:05 +0100446{
447 unsigned long oldcpsr = regs->ARM_cpsr;
448 unsigned long newcpsr;
449
450 __asm__ __volatile__ (
451 "msr cpsr_fs, %[oldcpsr] \n\t"
452 "ldmia %[regs], {r0-r7} \n\t"
453 "blx %[fn] \n\t"
454 "stmia %[regs], {r0-r7} \n\t"
455 "mrs %[newcpsr], cpsr \n\t"
456 : [newcpsr] "=r" (newcpsr)
457 : [oldcpsr] "r" (oldcpsr), [regs] "r" (regs),
David A. Long7579f4b32014-03-07 11:19:32 -0500458 [fn] "r" (asi->insn_fn)
Jon Medhurst02d194f2011-07-02 15:46:05 +0100459 : "r0", "r1", "r2", "r3", "r4", "r5", "r6", "r7",
460 "lr", "memory", "cc"
461 );
462
463 return (oldcpsr & ~APSR_MASK) | (newcpsr & APSR_MASK);
464}
465
David A. Long3e6cd392014-03-06 18:06:43 -0500466static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500467t16_emulate_loregs_rwflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500468 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst02d194f2011-07-02 15:46:05 +0100469{
David A. Long7579f4b32014-03-07 11:19:32 -0500470 regs->ARM_cpsr = t16_emulate_loregs(insn, asi, regs);
Jon Medhurst02d194f2011-07-02 15:46:05 +0100471}
472
David A. Long3e6cd392014-03-06 18:06:43 -0500473static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500474t16_emulate_loregs_noitrwflags(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500475 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst02d194f2011-07-02 15:46:05 +0100476{
David A. Long7579f4b32014-03-07 11:19:32 -0500477 unsigned long cpsr = t16_emulate_loregs(insn, asi, regs);
Jon Medhurst02d194f2011-07-02 15:46:05 +0100478 if (!in_it_block(cpsr))
479 regs->ARM_cpsr = cpsr;
480}
481
David A. Long3e6cd392014-03-06 18:06:43 -0500482static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500483t16_emulate_hiregs(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500484 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurst3b5940e2011-07-02 15:54:57 +0100485{
David A. Long7579f4b32014-03-07 11:19:32 -0500486 unsigned long pc = regs->ARM_pc + 2;
Jon Medhurst3b5940e2011-07-02 15:54:57 +0100487 int rdn = (insn & 0x7) | ((insn & 0x80) >> 4);
488 int rm = (insn >> 3) & 0xf;
489
490 register unsigned long rdnv asm("r1");
491 register unsigned long rmv asm("r0");
492 unsigned long cpsr = regs->ARM_cpsr;
493
494 rdnv = (rdn == 15) ? pc : regs->uregs[rdn];
495 rmv = (rm == 15) ? pc : regs->uregs[rm];
496
497 __asm__ __volatile__ (
498 "msr cpsr_fs, %[cpsr] \n\t"
499 "blx %[fn] \n\t"
500 "mrs %[cpsr], cpsr \n\t"
501 : "=r" (rdnv), [cpsr] "=r" (cpsr)
David A. Long7579f4b32014-03-07 11:19:32 -0500502 : "0" (rdnv), "r" (rmv), "1" (cpsr), [fn] "r" (asi->insn_fn)
Jon Medhurst3b5940e2011-07-02 15:54:57 +0100503 : "lr", "memory", "cc"
504 );
505
506 if (rdn == 15)
507 rdnv &= ~1;
508
509 regs->uregs[rdn] = rdnv;
510 regs->ARM_cpsr = (regs->ARM_cpsr & ~APSR_MASK) | (cpsr & APSR_MASK);
511}
512
David A. Long44a0a592014-03-05 21:23:42 -0500513static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500514t16_decode_hiregs(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500515 const struct decode_header *d)
Jon Medhurst3b5940e2011-07-02 15:54:57 +0100516{
517 insn &= ~0x00ff;
518 insn |= 0x001; /* Set Rdn = R1 and Rm = R0 */
Ben Dooks888be252013-11-08 18:29:25 +0000519 ((u16 *)asi->insn)[0] = __opcode_to_mem_thumb16(insn);
Jon Medhurst3b5940e2011-07-02 15:54:57 +0100520 asi->insn_handler = t16_emulate_hiregs;
521 return INSN_GOOD;
522}
523
David A. Long3e6cd392014-03-06 18:06:43 -0500524static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500525t16_emulate_push(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500526 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100527{
528 __asm__ __volatile__ (
529 "ldr r9, [%[regs], #13*4] \n\t"
530 "ldr r8, [%[regs], #14*4] \n\t"
531 "ldmia %[regs], {r0-r7} \n\t"
532 "blx %[fn] \n\t"
533 "str r9, [%[regs], #13*4] \n\t"
534 :
David A. Long7579f4b32014-03-07 11:19:32 -0500535 : [regs] "r" (regs), [fn] "r" (asi->insn_fn)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100536 : "r0", "r1", "r2", "r3", "r4", "r5", "r6", "r7", "r8", "r9",
537 "lr", "memory", "cc"
538 );
539}
540
David A. Long44a0a592014-03-05 21:23:42 -0500541static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500542t16_decode_push(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500543 const struct decode_header *d)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100544{
545 /*
546 * To simulate a PUSH we use a Thumb-2 "STMDB R9!, {registers}"
547 * and call it with R9=SP and LR in the register list represented
548 * by R8.
549 */
Ben Dooks888be252013-11-08 18:29:25 +0000550 /* 1st half STMDB R9!,{} */
551 ((u16 *)asi->insn)[0] = __opcode_to_mem_thumb16(0xe929);
552 /* 2nd half (register list) */
553 ((u16 *)asi->insn)[1] = __opcode_to_mem_thumb16(insn & 0x1ff);
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100554 asi->insn_handler = t16_emulate_push;
555 return INSN_GOOD;
556}
557
David A. Long3e6cd392014-03-06 18:06:43 -0500558static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500559t16_emulate_pop_nopc(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500560 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100561{
562 __asm__ __volatile__ (
563 "ldr r9, [%[regs], #13*4] \n\t"
564 "ldmia %[regs], {r0-r7} \n\t"
565 "blx %[fn] \n\t"
566 "stmia %[regs], {r0-r7} \n\t"
567 "str r9, [%[regs], #13*4] \n\t"
568 :
David A. Long7579f4b32014-03-07 11:19:32 -0500569 : [regs] "r" (regs), [fn] "r" (asi->insn_fn)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100570 : "r0", "r1", "r2", "r3", "r4", "r5", "r6", "r7", "r9",
571 "lr", "memory", "cc"
572 );
573}
574
David A. Long3e6cd392014-03-06 18:06:43 -0500575static void __kprobes
David A. Longf145d662014-03-05 21:17:23 -0500576t16_emulate_pop_pc(probes_opcode_t insn,
David A. Longb4cd6052014-03-05 21:41:29 -0500577 struct arch_probes_insn *asi, struct pt_regs *regs)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100578{
579 register unsigned long pc asm("r8");
580
581 __asm__ __volatile__ (
582 "ldr r9, [%[regs], #13*4] \n\t"
583 "ldmia %[regs], {r0-r7} \n\t"
584 "blx %[fn] \n\t"
585 "stmia %[regs], {r0-r7} \n\t"
586 "str r9, [%[regs], #13*4] \n\t"
587 : "=r" (pc)
David A. Long7579f4b32014-03-07 11:19:32 -0500588 : [regs] "r" (regs), [fn] "r" (asi->insn_fn)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100589 : "r0", "r1", "r2", "r3", "r4", "r5", "r6", "r7", "r9",
590 "lr", "memory", "cc"
591 );
592
593 bx_write_pc(pc, regs);
594}
595
David A. Long44a0a592014-03-05 21:23:42 -0500596static enum probes_insn __kprobes
David A. Longb4cd6052014-03-05 21:41:29 -0500597t16_decode_pop(probes_opcode_t insn, struct arch_probes_insn *asi,
David A. Long3e6cd392014-03-06 18:06:43 -0500598 const struct decode_header *d)
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100599{
600 /*
601 * To simulate a POP we use a Thumb-2 "LDMDB R9!, {registers}"
602 * and call it with R9=SP and PC in the register list represented
603 * by R8.
604 */
Ben Dooks888be252013-11-08 18:29:25 +0000605 /* 1st half LDMIA R9!,{} */
606 ((u16 *)asi->insn)[0] = __opcode_to_mem_thumb16(0xe8b9);
607 /* 2nd half (register list) */
608 ((u16 *)asi->insn)[1] = __opcode_to_mem_thumb16(insn & 0x1ff);
Jon Medhurstfd0c8d82011-07-02 16:13:29 +0100609 asi->insn_handler = insn & 0x100 ? t16_emulate_pop_pc
610 : t16_emulate_pop_nopc;
611 return INSN_GOOD;
612}
David A. Long3e6cd392014-03-06 18:06:43 -0500613
614const union decode_action kprobes_t16_actions[NUM_PROBES_T16_ACTIONS] = {
615 [PROBES_T16_ADD_SP] = {.handler = t16_simulate_add_sp_imm},
616 [PROBES_T16_CBZ] = {.handler = t16_simulate_cbz},
617 [PROBES_T16_SIGN_EXTEND] = {.handler = t16_emulate_loregs_rwflags},
618 [PROBES_T16_PUSH] = {.decoder = t16_decode_push},
619 [PROBES_T16_POP] = {.decoder = t16_decode_pop},
David A. Longeb73ea92014-03-05 21:20:25 -0500620 [PROBES_T16_SEV] = {.handler = probes_emulate_none},
621 [PROBES_T16_WFE] = {.handler = probes_simulate_nop},
David A. Long3e6cd392014-03-06 18:06:43 -0500622 [PROBES_T16_IT] = {.decoder = t16_decode_it},
623 [PROBES_T16_CMP] = {.handler = t16_emulate_loregs_rwflags},
624 [PROBES_T16_ADDSUB] = {.handler = t16_emulate_loregs_noitrwflags},
625 [PROBES_T16_LOGICAL] = {.handler = t16_emulate_loregs_noitrwflags},
626 [PROBES_T16_LDR_LIT] = {.handler = t16_simulate_ldr_literal},
627 [PROBES_T16_BLX] = {.handler = t16_simulate_bxblx},
628 [PROBES_T16_HIREGOPS] = {.decoder = t16_decode_hiregs},
629 [PROBES_T16_LDRHSTRH] = {.handler = t16_emulate_loregs_rwflags},
630 [PROBES_T16_LDRSTR] = {.handler = t16_simulate_ldrstr_sp_relative},
631 [PROBES_T16_ADR] = {.handler = t16_simulate_reladr},
632 [PROBES_T16_LDMSTM] = {.handler = t16_emulate_loregs_rwflags},
633 [PROBES_T16_BRANCH_COND] = {.decoder = t16_decode_cond_branch},
634 [PROBES_T16_BRANCH] = {.handler = t16_simulate_branch},
635};
636
637const union decode_action kprobes_t32_actions[NUM_PROBES_T32_ACTIONS] = {
638 [PROBES_T32_LDMSTM] = {.decoder = t32_decode_ldmstm},
639 [PROBES_T32_LDRDSTRD] = {.handler = t32_emulate_ldrdstrd},
640 [PROBES_T32_TABLE_BRANCH] = {.handler = t32_simulate_table_branch},
641 [PROBES_T32_TST] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
642 [PROBES_T32_MOV] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
643 [PROBES_T32_ADDSUB] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
644 [PROBES_T32_LOGICAL] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
645 [PROBES_T32_CMP] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
646 [PROBES_T32_ADDWSUBW_PC] = {.handler = t32_emulate_rd8pc16_noflags,},
647 [PROBES_T32_ADDWSUBW] = {.handler = t32_emulate_rd8rn16_noflags},
648 [PROBES_T32_MOVW] = {.handler = t32_emulate_rd8rn16_noflags},
649 [PROBES_T32_SAT] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
650 [PROBES_T32_BITFIELD] = {.handler = t32_emulate_rd8rn16_noflags},
David A. Longeb73ea92014-03-05 21:20:25 -0500651 [PROBES_T32_SEV] = {.handler = probes_emulate_none},
652 [PROBES_T32_WFE] = {.handler = probes_simulate_nop},
David A. Long3e6cd392014-03-06 18:06:43 -0500653 [PROBES_T32_MRS] = {.handler = t32_simulate_mrs},
654 [PROBES_T32_BRANCH_COND] = {.decoder = t32_decode_cond_branch},
655 [PROBES_T32_BRANCH] = {.handler = t32_simulate_branch},
David A. Longeb73ea92014-03-05 21:20:25 -0500656 [PROBES_T32_PLDI] = {.handler = probes_simulate_nop},
David A. Long3e6cd392014-03-06 18:06:43 -0500657 [PROBES_T32_LDR_LIT] = {.handler = t32_simulate_ldr_literal},
658 [PROBES_T32_LDRSTR] = {.handler = t32_emulate_ldrstr},
659 [PROBES_T32_SIGN_EXTEND] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
660 [PROBES_T32_MEDIA] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
661 [PROBES_T32_REVERSE] = {.handler = t32_emulate_rd8rn16_noflags},
662 [PROBES_T32_MUL_ADD] = {.handler = t32_emulate_rd8rn16rm0_rwflags},
663 [PROBES_T32_MUL_ADD2] = {.handler = t32_emulate_rd8rn16rm0ra12_noflags},
664 [PROBES_T32_MUL_ADD_LONG] = {
665 .handler = t32_emulate_rdlo12rdhi8rn16rm0_noflags},
666};