1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24#define pr_fmt(fmt) "kexec_elf: " fmt
25
26#include <linux/elf.h>
27#include <linux/kexec.h>
28#include <linux/libfdt.h>
29#include <linux/module.h>
30#include <linux/of_fdt.h>
31#include <linux/slab.h>
32#include <linux/types.h>
33
34#define PURGATORY_STACK_SIZE (16 * 1024)
35
36#define elf_addr_to_cpu elf64_to_cpu
37
38#ifndef Elf_Rel
39#define Elf_Rel Elf64_Rel
40#endif
41
42struct elf_info {
43
44
45
46
47 const char *buffer;
48
49 const struct elfhdr *ehdr;
50 const struct elf_phdr *proghdrs;
51 struct elf_shdr *sechdrs;
52};
53
54static inline bool elf_is_elf_file(const struct elfhdr *ehdr)
55{
56 return memcmp(ehdr->e_ident, ELFMAG, SELFMAG) == 0;
57}
58
59static uint64_t elf64_to_cpu(const struct elfhdr *ehdr, uint64_t value)
60{
61 if (ehdr->e_ident[EI_DATA] == ELFDATA2LSB)
62 value = le64_to_cpu(value);
63 else if (ehdr->e_ident[EI_DATA] == ELFDATA2MSB)
64 value = be64_to_cpu(value);
65
66 return value;
67}
68
69static uint16_t elf16_to_cpu(const struct elfhdr *ehdr, uint16_t value)
70{
71 if (ehdr->e_ident[EI_DATA] == ELFDATA2LSB)
72 value = le16_to_cpu(value);
73 else if (ehdr->e_ident[EI_DATA] == ELFDATA2MSB)
74 value = be16_to_cpu(value);
75
76 return value;
77}
78
79static uint32_t elf32_to_cpu(const struct elfhdr *ehdr, uint32_t value)
80{
81 if (ehdr->e_ident[EI_DATA] == ELFDATA2LSB)
82 value = le32_to_cpu(value);
83 else if (ehdr->e_ident[EI_DATA] == ELFDATA2MSB)
84 value = be32_to_cpu(value);
85
86 return value;
87}
88
89
90
91
92
93static bool elf_is_ehdr_sane(const struct elfhdr *ehdr, size_t buf_len)
94{
95 if (ehdr->e_phnum > 0 && ehdr->e_phentsize != sizeof(struct elf_phdr)) {
96 pr_debug("Bad program header size.\n");
97 return false;
98 } else if (ehdr->e_shnum > 0 &&
99 ehdr->e_shentsize != sizeof(struct elf_shdr)) {
100 pr_debug("Bad section header size.\n");
101 return false;
102 } else if (ehdr->e_ident[EI_VERSION] != EV_CURRENT ||
103 ehdr->e_version != EV_CURRENT) {
104 pr_debug("Unknown ELF version.\n");
105 return false;
106 }
107
108 if (ehdr->e_phoff > 0 && ehdr->e_phnum > 0) {
109 size_t phdr_size;
110
111
112
113
114
115 phdr_size = sizeof(struct elf_phdr) * ehdr->e_phnum;
116
117
118 if (ehdr->e_phoff + phdr_size < ehdr->e_phoff) {
119 pr_debug("Program headers at invalid location.\n");
120 return false;
121 } else if (ehdr->e_phoff + phdr_size > buf_len) {
122 pr_debug("Program headers truncated.\n");
123 return false;
124 }
125 }
126
127 if (ehdr->e_shoff > 0 && ehdr->e_shnum > 0) {
128 size_t shdr_size;
129
130
131
132
133
134 shdr_size = sizeof(struct elf_shdr) * ehdr->e_shnum;
135
136
137 if (ehdr->e_shoff + shdr_size < ehdr->e_shoff) {
138 pr_debug("Section headers at invalid location.\n");
139 return false;
140 } else if (ehdr->e_shoff + shdr_size > buf_len) {
141 pr_debug("Section headers truncated.\n");
142 return false;
143 }
144 }
145
146 return true;
147}
148
149static int elf_read_ehdr(const char *buf, size_t len, struct elfhdr *ehdr)
150{
151 struct elfhdr *buf_ehdr;
152
153 if (len < sizeof(*buf_ehdr)) {
154 pr_debug("Buffer is too small to hold ELF header.\n");
155 return -ENOEXEC;
156 }
157
158 memset(ehdr, 0, sizeof(*ehdr));
159 memcpy(ehdr->e_ident, buf, sizeof(ehdr->e_ident));
160 if (!elf_is_elf_file(ehdr)) {
161 pr_debug("No ELF header magic.\n");
162 return -ENOEXEC;
163 }
164
165 if (ehdr->e_ident[EI_CLASS] != ELF_CLASS) {
166 pr_debug("Not a supported ELF class.\n");
167 return -ENOEXEC;
168 } else if (ehdr->e_ident[EI_DATA] != ELFDATA2LSB &&
169 ehdr->e_ident[EI_DATA] != ELFDATA2MSB) {
170 pr_debug("Not a supported ELF data format.\n");
171 return -ENOEXEC;
172 }
173
174 buf_ehdr = (struct elfhdr *) buf;
175 if (elf16_to_cpu(ehdr, buf_ehdr->e_ehsize) != sizeof(*buf_ehdr)) {
176 pr_debug("Bad ELF header size.\n");
177 return -ENOEXEC;
178 }
179
180 ehdr->e_type = elf16_to_cpu(ehdr, buf_ehdr->e_type);
181 ehdr->e_machine = elf16_to_cpu(ehdr, buf_ehdr->e_machine);
182 ehdr->e_version = elf32_to_cpu(ehdr, buf_ehdr->e_version);
183 ehdr->e_entry = elf_addr_to_cpu(ehdr, buf_ehdr->e_entry);
184 ehdr->e_phoff = elf_addr_to_cpu(ehdr, buf_ehdr->e_phoff);
185 ehdr->e_shoff = elf_addr_to_cpu(ehdr, buf_ehdr->e_shoff);
186 ehdr->e_flags = elf32_to_cpu(ehdr, buf_ehdr->e_flags);
187 ehdr->e_phentsize = elf16_to_cpu(ehdr, buf_ehdr->e_phentsize);
188 ehdr->e_phnum = elf16_to_cpu(ehdr, buf_ehdr->e_phnum);
189 ehdr->e_shentsize = elf16_to_cpu(ehdr, buf_ehdr->e_shentsize);
190 ehdr->e_shnum = elf16_to_cpu(ehdr, buf_ehdr->e_shnum);
191 ehdr->e_shstrndx = elf16_to_cpu(ehdr, buf_ehdr->e_shstrndx);
192
193 return elf_is_ehdr_sane(ehdr, len) ? 0 : -ENOEXEC;
194}
195
196
197
198
199
200static bool elf_is_phdr_sane(const struct elf_phdr *phdr, size_t buf_len)
201{
202
203 if (phdr->p_offset + phdr->p_filesz < phdr->p_offset) {
204 pr_debug("ELF segment location wraps around.\n");
205 return false;
206 } else if (phdr->p_offset + phdr->p_filesz > buf_len) {
207 pr_debug("ELF segment not in file.\n");
208 return false;
209 } else if (phdr->p_paddr + phdr->p_memsz < phdr->p_paddr) {
210 pr_debug("ELF segment address wraps around.\n");
211 return false;
212 }
213
214 return true;
215}
216
217static int elf_read_phdr(const char *buf, size_t len, struct elf_info *elf_info,
218 int idx)
219{
220
221 struct elf_phdr *phdr = (struct elf_phdr *) &elf_info->proghdrs[idx];
222 const char *pbuf;
223 struct elf_phdr *buf_phdr;
224
225 pbuf = buf + elf_info->ehdr->e_phoff + (idx * sizeof(*buf_phdr));
226 buf_phdr = (struct elf_phdr *) pbuf;
227
228 phdr->p_type = elf32_to_cpu(elf_info->ehdr, buf_phdr->p_type);
229 phdr->p_offset = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_offset);
230 phdr->p_paddr = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_paddr);
231 phdr->p_vaddr = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_vaddr);
232 phdr->p_flags = elf32_to_cpu(elf_info->ehdr, buf_phdr->p_flags);
233
234
235
236
237
238 phdr->p_filesz = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_filesz);
239 phdr->p_memsz = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_memsz);
240 phdr->p_align = elf_addr_to_cpu(elf_info->ehdr, buf_phdr->p_align);
241
242 return elf_is_phdr_sane(phdr, len) ? 0 : -ENOEXEC;
243}
244
245
246
247
248
249
250
251static int elf_read_phdrs(const char *buf, size_t len,
252 struct elf_info *elf_info)
253{
254 size_t phdr_size, i;
255 const struct elfhdr *ehdr = elf_info->ehdr;
256
257
258
259
260
261 phdr_size = sizeof(struct elf_phdr) * ehdr->e_phnum;
262
263 elf_info->proghdrs = kzalloc(phdr_size, GFP_KERNEL);
264 if (!elf_info->proghdrs)
265 return -ENOMEM;
266
267 for (i = 0; i < ehdr->e_phnum; i++) {
268 int ret;
269
270 ret = elf_read_phdr(buf, len, elf_info, i);
271 if (ret) {
272 kfree(elf_info->proghdrs);
273 elf_info->proghdrs = NULL;
274 return ret;
275 }
276 }
277
278 return 0;
279}
280
281
282
283
284
285static bool elf_is_shdr_sane(const struct elf_shdr *shdr, size_t buf_len)
286{
287 bool size_ok;
288
289
290 if (shdr->sh_type == SHT_NULL)
291 return true;
292
293
294 switch (shdr->sh_type) {
295 case SHT_SYMTAB:
296 size_ok = shdr->sh_entsize == sizeof(Elf_Sym);
297 break;
298 case SHT_RELA:
299 size_ok = shdr->sh_entsize == sizeof(Elf_Rela);
300 break;
301 case SHT_DYNAMIC:
302 size_ok = shdr->sh_entsize == sizeof(Elf_Dyn);
303 break;
304 case SHT_REL:
305 size_ok = shdr->sh_entsize == sizeof(Elf_Rel);
306 break;
307 case SHT_NOTE:
308 case SHT_PROGBITS:
309 case SHT_HASH:
310 case SHT_NOBITS:
311 default:
312
313
314
315
316
317
318 size_ok = true;
319 break;
320 }
321
322 if (!size_ok) {
323 pr_debug("ELF section with wrong entry size.\n");
324 return false;
325 } else if (shdr->sh_addr + shdr->sh_size < shdr->sh_addr) {
326 pr_debug("ELF section address wraps around.\n");
327 return false;
328 }
329
330 if (shdr->sh_type != SHT_NOBITS) {
331 if (shdr->sh_offset + shdr->sh_size < shdr->sh_offset) {
332 pr_debug("ELF section location wraps around.\n");
333 return false;
334 } else if (shdr->sh_offset + shdr->sh_size > buf_len) {
335 pr_debug("ELF section not in file.\n");
336 return false;
337 }
338 }
339
340 return true;
341}
342
343static int elf_read_shdr(const char *buf, size_t len, struct elf_info *elf_info,
344 int idx)
345{
346 struct elf_shdr *shdr = &elf_info->sechdrs[idx];
347 const struct elfhdr *ehdr = elf_info->ehdr;
348 const char *sbuf;
349 struct elf_shdr *buf_shdr;
350
351 sbuf = buf + ehdr->e_shoff + idx * sizeof(*buf_shdr);
352 buf_shdr = (struct elf_shdr *) sbuf;
353
354 shdr->sh_name = elf32_to_cpu(ehdr, buf_shdr->sh_name);
355 shdr->sh_type = elf32_to_cpu(ehdr, buf_shdr->sh_type);
356 shdr->sh_addr = elf_addr_to_cpu(ehdr, buf_shdr->sh_addr);
357 shdr->sh_offset = elf_addr_to_cpu(ehdr, buf_shdr->sh_offset);
358 shdr->sh_link = elf32_to_cpu(ehdr, buf_shdr->sh_link);
359 shdr->sh_info = elf32_to_cpu(ehdr, buf_shdr->sh_info);
360
361
362
363
364
365 shdr->sh_flags = elf_addr_to_cpu(ehdr, buf_shdr->sh_flags);
366 shdr->sh_size = elf_addr_to_cpu(ehdr, buf_shdr->sh_size);
367 shdr->sh_addralign = elf_addr_to_cpu(ehdr, buf_shdr->sh_addralign);
368 shdr->sh_entsize = elf_addr_to_cpu(ehdr, buf_shdr->sh_entsize);
369
370 return elf_is_shdr_sane(shdr, len) ? 0 : -ENOEXEC;
371}
372
373
374
375
376
377
378
379static int elf_read_shdrs(const char *buf, size_t len,
380 struct elf_info *elf_info)
381{
382 size_t shdr_size, i;
383
384
385
386
387
388 shdr_size = sizeof(struct elf_shdr) * elf_info->ehdr->e_shnum;
389
390 elf_info->sechdrs = kzalloc(shdr_size, GFP_KERNEL);
391 if (!elf_info->sechdrs)
392 return -ENOMEM;
393
394 for (i = 0; i < elf_info->ehdr->e_shnum; i++) {
395 int ret;
396
397 ret = elf_read_shdr(buf, len, elf_info, i);
398 if (ret) {
399 kfree(elf_info->sechdrs);
400 elf_info->sechdrs = NULL;
401 return ret;
402 }
403 }
404
405 return 0;
406}
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422int elf_read_from_buffer(const char *buf, size_t len, struct elfhdr *ehdr,
423 struct elf_info *elf_info)
424{
425 int ret;
426
427 ret = elf_read_ehdr(buf, len, ehdr);
428 if (ret)
429 return ret;
430
431 elf_info->buffer = buf;
432 elf_info->ehdr = ehdr;
433 if (ehdr->e_phoff > 0 && ehdr->e_phnum > 0) {
434 ret = elf_read_phdrs(buf, len, elf_info);
435 if (ret)
436 return ret;
437 }
438 if (ehdr->e_shoff > 0 && ehdr->e_shnum > 0) {
439 ret = elf_read_shdrs(buf, len, elf_info);
440 if (ret) {
441 kfree(elf_info->proghdrs);
442 return ret;
443 }
444 }
445
446 return 0;
447}
448
449
450
451
452void elf_free_info(struct elf_info *elf_info)
453{
454 kfree(elf_info->proghdrs);
455 kfree(elf_info->sechdrs);
456 memset(elf_info, 0, sizeof(*elf_info));
457}
458
459
460
461static int build_elf_exec_info(const char *buf, size_t len, struct elfhdr *ehdr,
462 struct elf_info *elf_info)
463{
464 int i;
465 int ret;
466
467 ret = elf_read_from_buffer(buf, len, ehdr, elf_info);
468 if (ret)
469 return ret;
470
471
472 if (ehdr->e_type != ET_EXEC && ehdr->e_type != ET_DYN) {
473 pr_err("Not an ELF executable.\n");
474 goto error;
475 } else if (!elf_info->proghdrs) {
476 pr_err("No ELF program header.\n");
477 goto error;
478 }
479
480 for (i = 0; i < ehdr->e_phnum; i++) {
481
482
483
484
485
486 if (elf_info->proghdrs[i].p_type == PT_INTERP) {
487 pr_err("Requires an ELF interpreter.\n");
488 goto error;
489 }
490 }
491
492 return 0;
493error:
494 elf_free_info(elf_info);
495 return -ENOEXEC;
496}
497
498static int elf64_probe(const char *buf, unsigned long len)
499{
500 struct elfhdr ehdr;
501 struct elf_info elf_info;
502 int ret;
503
504 ret = build_elf_exec_info(buf, len, &ehdr, &elf_info);
505 if (ret)
506 return ret;
507
508 elf_free_info(&elf_info);
509
510 return elf_check_arch(&ehdr) ? 0 : -ENOEXEC;
511}
512
513
514
515
516
517
518
519
520
521static int elf_exec_load(struct kimage *image, struct elfhdr *ehdr,
522 struct elf_info *elf_info,
523 unsigned long *lowest_load_addr)
524{
525 unsigned long base = 0, lowest_addr = UINT_MAX;
526 int ret;
527 size_t i;
528 struct kexec_buf kbuf = { .image = image, .buf_max = ppc64_rma_size,
529 .top_down = false };
530
531 if (image->type == KEXEC_TYPE_CRASH) {
532
533 kbuf.buf_min = crashk_res.start;
534 kbuf.buf_max = ((crashk_res.end < ppc64_rma_size) ?
535 crashk_res.end : (ppc64_rma_size - 1));
536 }
537
538
539 for (i = 0; i < ehdr->e_phnum; i++) {
540 unsigned long load_addr;
541 size_t size;
542 const struct elf_phdr *phdr;
543
544 phdr = &elf_info->proghdrs[i];
545 if (phdr->p_type != PT_LOAD)
546 continue;
547
548 size = phdr->p_filesz;
549 if (size > phdr->p_memsz)
550 size = phdr->p_memsz;
551
552 kbuf.buffer = (void *) elf_info->buffer + phdr->p_offset;
553 kbuf.bufsz = size;
554 kbuf.memsz = phdr->p_memsz;
555 kbuf.buf_align = phdr->p_align;
556 kbuf.buf_min = phdr->p_paddr + base;
557 kbuf.mem = KEXEC_BUF_MEM_UNKNOWN;
558 ret = kexec_add_buffer(&kbuf);
559 if (ret)
560 goto out;
561 load_addr = kbuf.mem;
562
563 if (load_addr < lowest_addr)
564 lowest_addr = load_addr;
565 }
566
567
568 ehdr->e_entry += base;
569
570 *lowest_load_addr = lowest_addr;
571 ret = 0;
572 out:
573 return ret;
574}
575
576static void *elf64_load(struct kimage *image, char *kernel_buf,
577 unsigned long kernel_len, char *initrd,
578 unsigned long initrd_len, char *cmdline,
579 unsigned long cmdline_len)
580{
581 int ret;
582 unsigned int fdt_size;
583 unsigned long kernel_load_addr;
584 unsigned long initrd_load_addr = 0, fdt_load_addr;
585 void *fdt;
586 const void *slave_code;
587 struct elfhdr ehdr;
588 struct elf_info elf_info;
589 char *modified_cmdline = NULL;
590 struct kexec_buf kbuf = { .image = image, .buf_min = 0,
591 .buf_max = ppc64_rma_size };
592 struct kexec_buf pbuf = { .image = image, .buf_min = 0,
593 .buf_max = ppc64_rma_size, .top_down = true,
594 .mem = KEXEC_BUF_MEM_UNKNOWN };
595
596 ret = build_elf_exec_info(kernel_buf, kernel_len, &ehdr, &elf_info);
597 if (ret)
598 goto out;
599
600 ret = elf_exec_load(image, &ehdr, &elf_info, &kernel_load_addr);
601 if (ret)
602 goto out;
603
604 pr_debug("Loaded the kernel at 0x%lx\n", kernel_load_addr);
605
606 if (image->type == KEXEC_TYPE_CRASH) {
607
608 kbuf.buf_min = pbuf.buf_min = crashk_res.start;
609 kbuf.buf_max = pbuf.buf_max =
610 ((crashk_res.end < ppc64_rma_size) ?
611 crashk_res.end : (ppc64_rma_size - 1));
612 }
613
614 ret = kexec_load_purgatory(image, &pbuf);
615 if (ret) {
616 pr_err("Loading purgatory failed.\n");
617 goto out;
618 }
619
620 pr_debug("Loaded purgatory at 0x%lx\n", pbuf.mem);
621
622
623 if (image->type == KEXEC_TYPE_CRASH) {
624 ret = load_crashdump_segments_ppc64(image, &kbuf);
625 if (ret) {
626 pr_err("Failed to load kdump kernel segments\n");
627 goto out;
628 }
629
630
631 modified_cmdline = setup_kdump_cmdline(image, cmdline,
632 cmdline_len);
633 if (!modified_cmdline) {
634 pr_err("Setting up cmdline for kdump kernel failed\n");
635 ret = -EINVAL;
636 goto out;
637 }
638 cmdline = modified_cmdline;
639 }
640
641 if (initrd != NULL) {
642 kbuf.buffer = initrd;
643 kbuf.bufsz = kbuf.memsz = initrd_len;
644 kbuf.buf_align = PAGE_SIZE;
645 kbuf.top_down = false;
646 kbuf.mem = KEXEC_BUF_MEM_UNKNOWN;
647 ret = kexec_add_buffer(&kbuf);
648 if (ret)
649 goto out;
650 initrd_load_addr = kbuf.mem;
651
652 pr_debug("Loaded initrd at 0x%lx\n", initrd_load_addr);
653 }
654
655 fdt_size = kexec_fdt_totalsize_ppc64(image);
656 fdt = kmalloc(fdt_size, GFP_KERNEL);
657 if (!fdt) {
658 pr_err("Not enough memory for the device tree.\n");
659 ret = -ENOMEM;
660 goto out;
661 }
662 ret = fdt_open_into(initial_boot_params, fdt, fdt_size);
663 if (ret < 0) {
664 pr_err("Error setting up the new device tree.\n");
665 ret = -EINVAL;
666 goto out;
667 }
668
669 ret = setup_new_fdt_ppc64(image, fdt, initrd_load_addr,
670 initrd_len, cmdline);
671 if (ret)
672 goto out;
673
674 fdt_pack(fdt);
675
676 kbuf.buffer = fdt;
677 kbuf.bufsz = kbuf.memsz = fdt_size;
678 kbuf.buf_align = PAGE_SIZE;
679 kbuf.top_down = true;
680 kbuf.mem = KEXEC_BUF_MEM_UNKNOWN;
681 ret = kexec_add_buffer(&kbuf);
682 if (ret)
683 goto out;
684 fdt_load_addr = kbuf.mem;
685
686 pr_debug("Loaded device tree at 0x%lx\n", fdt_load_addr);
687
688 slave_code = elf_info.buffer + elf_info.proghdrs[0].p_offset;
689 ret = setup_purgatory_ppc64(image, slave_code, fdt, kernel_load_addr,
690 fdt_load_addr);
691 if (ret)
692 pr_err("Error setting up the purgatory.\n");
693
694out:
695 kfree(modified_cmdline);
696 elf_free_info(&elf_info);
697
698
699 return ret ? ERR_PTR(ret) : fdt;
700}
701
702const struct kexec_file_ops kexec_elf64_ops = {
703 .probe = elf64_probe,
704 .load = elf64_load,
705};
706