xref: /netbsd-src/sys/kern/subr_asan.c (revision 76c7fc5f6b13ed0b1508e6b313e88e59977ed78e)
1 /*	$NetBSD: subr_asan.c,v 1.16 2019/10/10 13:45:14 maxv Exp $	*/
2 
3 /*
4  * Copyright (c) 2018-2019 The NetBSD Foundation, Inc.
5  * All rights reserved.
6  *
7  * This code is derived from software contributed to The NetBSD Foundation
8  * by Maxime Villard.
9  *
10  * Redistribution and use in source and binary forms, with or without
11  * modification, are permitted provided that the following conditions
12  * are met:
13  * 1. Redistributions of source code must retain the above copyright
14  *    notice, this list of conditions and the following disclaimer.
15  * 2. Redistributions in binary form must reproduce the above copyright
16  *    notice, this list of conditions and the following disclaimer in the
17  *    documentation and/or other materials provided with the distribution.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21  * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29  * POSSIBILITY OF SUCH DAMAGE.
30  */
31 
32 #include <sys/cdefs.h>
33 __KERNEL_RCSID(0, "$NetBSD: subr_asan.c,v 1.16 2019/10/10 13:45:14 maxv Exp $");
34 
35 #include <sys/param.h>
36 #include <sys/device.h>
37 #include <sys/kernel.h>
38 #include <sys/param.h>
39 #include <sys/conf.h>
40 #include <sys/systm.h>
41 #include <sys/types.h>
42 #include <sys/asan.h>
43 
44 #include <uvm/uvm.h>
45 
46 #ifdef KASAN_PANIC
47 #define REPORT panic
48 #else
49 #define REPORT printf
50 #endif
51 
52 /* ASAN constants. Part of the compiler ABI. */
53 #define KASAN_SHADOW_SCALE_SHIFT	3
54 #define KASAN_SHADOW_SCALE_SIZE		(1UL << KASAN_SHADOW_SCALE_SHIFT)
55 #define KASAN_SHADOW_MASK		(KASAN_SHADOW_SCALE_SIZE - 1)
56 
57 /* The MD code. */
58 #include <machine/asan.h>
59 
60 /* ASAN ABI version. */
61 #if defined(__clang__) && (__clang_major__ - 0 >= 6)
62 #define ASAN_ABI_VERSION	8
63 #elif __GNUC_PREREQ__(7, 1) && !defined(__clang__)
64 #define ASAN_ABI_VERSION	8
65 #elif __GNUC_PREREQ__(6, 1) && !defined(__clang__)
66 #define ASAN_ABI_VERSION	6
67 #else
68 #error "Unsupported compiler version"
69 #endif
70 
71 #define __RET_ADDR	(unsigned long)__builtin_return_address(0)
72 
73 /* Global variable descriptor. Part of the compiler ABI.  */
74 struct __asan_global_source_location {
75 	const char *filename;
76 	int line_no;
77 	int column_no;
78 };
79 struct __asan_global {
80 	const void *beg;		/* address of the global variable */
81 	size_t size;			/* size of the global variable */
82 	size_t size_with_redzone;	/* size with the redzone */
83 	const void *name;		/* name of the variable */
84 	const void *module_name;	/* name of the module where the var is declared */
85 	unsigned long has_dynamic_init;	/* the var has dyn initializer (c++) */
86 	struct __asan_global_source_location *location;
87 #if ASAN_ABI_VERSION >= 7
88 	uintptr_t odr_indicator;	/* the address of the ODR indicator symbol */
89 #endif
90 };
91 
92 static bool kasan_enabled __read_mostly = false;
93 
94 /* -------------------------------------------------------------------------- */
95 
96 void
97 kasan_shadow_map(void *addr, size_t size)
98 {
99 	size_t sz, npages, i;
100 	vaddr_t sva, eva;
101 
102 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
103 
104 	sz = roundup(size, KASAN_SHADOW_SCALE_SIZE) / KASAN_SHADOW_SCALE_SIZE;
105 
106 	sva = (vaddr_t)kasan_md_addr_to_shad(addr);
107 	eva = (vaddr_t)kasan_md_addr_to_shad(addr) + sz;
108 
109 	sva = rounddown(sva, PAGE_SIZE);
110 	eva = roundup(eva, PAGE_SIZE);
111 
112 	npages = (eva - sva) / PAGE_SIZE;
113 
114 	KASSERT(sva >= KASAN_MD_SHADOW_START && eva < KASAN_MD_SHADOW_END);
115 
116 	for (i = 0; i < npages; i++) {
117 		kasan_md_shadow_map_page(sva + i * PAGE_SIZE);
118 	}
119 }
120 
121 static void
122 kasan_ctors(void)
123 {
124 	extern uint64_t __CTOR_LIST__, __CTOR_END__;
125 	size_t nentries, i;
126 	uint64_t *ptr;
127 
128 	nentries = ((size_t)&__CTOR_END__ - (size_t)&__CTOR_LIST__) /
129 	    sizeof(uintptr_t);
130 
131 	ptr = &__CTOR_LIST__;
132 	for (i = 0; i < nentries; i++) {
133 		void (*func)(void);
134 
135 		func = (void *)(*ptr);
136 		(*func)();
137 
138 		ptr++;
139 	}
140 }
141 
142 void
143 kasan_early_init(void *stack)
144 {
145 	kasan_md_early_init(stack);
146 }
147 
148 void
149 kasan_init(void)
150 {
151 	/* MD initialization. */
152 	kasan_md_init();
153 
154 	/* Now officially enabled. */
155 	kasan_enabled = true;
156 
157 	/* Call the ASAN constructors. */
158 	kasan_ctors();
159 }
160 
161 static inline const char *
162 kasan_code_name(uint8_t code)
163 {
164 	switch (code) {
165 	case KASAN_GENERIC_REDZONE:
166 		return "GenericRedZone";
167 	case KASAN_MALLOC_REDZONE:
168 		return "MallocRedZone";
169 	case KASAN_KMEM_REDZONE:
170 		return "KmemRedZone";
171 	case KASAN_POOL_REDZONE:
172 		return "PoolRedZone";
173 	case KASAN_POOL_FREED:
174 		return "PoolUseAfterFree";
175 	case 1 ... 7:
176 		return "RedZonePartial";
177 	case KASAN_STACK_LEFT:
178 		return "StackLeft";
179 	case KASAN_STACK_RIGHT:
180 		return "StackRight";
181 	case KASAN_STACK_PARTIAL:
182 		return "StackPartial";
183 	case KASAN_USE_AFTER_SCOPE:
184 		return "UseAfterScope";
185 	default:
186 		return "Unknown";
187 	}
188 }
189 
190 static void
191 kasan_report(unsigned long addr, size_t size, bool write, unsigned long pc,
192     uint8_t code)
193 {
194 	REPORT("ASan: Unauthorized Access In %p: Addr %p [%zu byte%s, %s,"
195 	    " %s]\n",
196 	    (void *)pc, (void *)addr, size, (size > 1 ? "s" : ""),
197 	    (write ? "write" : "read"), kasan_code_name(code));
198 	kasan_md_unwind();
199 }
200 
201 static __always_inline void
202 kasan_shadow_1byte_markvalid(unsigned long addr)
203 {
204 	int8_t *byte = kasan_md_addr_to_shad((void *)addr);
205 	int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
206 
207 	*byte = last;
208 }
209 
210 static __always_inline void
211 kasan_shadow_Nbyte_markvalid(const void *addr, size_t size)
212 {
213 	size_t i;
214 
215 	for (i = 0; i < size; i++) {
216 		kasan_shadow_1byte_markvalid((unsigned long)addr+i);
217 	}
218 }
219 
220 static __always_inline void
221 kasan_shadow_Nbyte_fill(const void *addr, size_t size, uint8_t code)
222 {
223 	void *shad;
224 
225 	if (__predict_false(size == 0))
226 		return;
227 	if (__predict_false(kasan_md_unsupported((vaddr_t)addr)))
228 		return;
229 
230 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
231 	KASSERT(size % KASAN_SHADOW_SCALE_SIZE == 0);
232 
233 	shad = (void *)kasan_md_addr_to_shad(addr);
234 	size = size >> KASAN_SHADOW_SCALE_SHIFT;
235 
236 	__builtin_memset(shad, code, size);
237 }
238 
239 void
240 kasan_add_redzone(size_t *size)
241 {
242 	*size = roundup(*size, KASAN_SHADOW_SCALE_SIZE);
243 	*size += KASAN_SHADOW_SCALE_SIZE;
244 }
245 
246 void
247 kasan_softint(struct lwp *l)
248 {
249 	const void *stk = (const void *)uvm_lwp_getuarea(l);
250 
251 	kasan_shadow_Nbyte_fill(stk, USPACE, 0);
252 }
253 
254 /*
255  * In an area of size 'sz_with_redz', mark the 'size' first bytes as valid,
256  * and the rest as invalid. There are generally two use cases:
257  *
258  *  o kasan_mark(addr, origsize, size, code), with origsize < size. This marks
259  *    the redzone at the end of the buffer as invalid.
260  *
261  *  o kasan_mark(addr, size, size, 0). This marks the entire buffer as valid.
262  */
263 void
264 kasan_mark(const void *addr, size_t size, size_t sz_with_redz, uint8_t code)
265 {
266 	size_t i, n, redz;
267 	int8_t *shad;
268 
269 	KASSERT((vaddr_t)addr % KASAN_SHADOW_SCALE_SIZE == 0);
270 	redz = sz_with_redz - roundup(size, KASAN_SHADOW_SCALE_SIZE);
271 	KASSERT(redz % KASAN_SHADOW_SCALE_SIZE == 0);
272 	shad = kasan_md_addr_to_shad(addr);
273 
274 	/* Chunks of 8 bytes, valid. */
275 	n = size / KASAN_SHADOW_SCALE_SIZE;
276 	for (i = 0; i < n; i++) {
277 		*shad++ = 0;
278 	}
279 
280 	/* Possibly one chunk, mid. */
281 	if ((size & KASAN_SHADOW_MASK) != 0) {
282 		*shad++ = (size & KASAN_SHADOW_MASK);
283 	}
284 
285 	/* Chunks of 8 bytes, invalid. */
286 	n = redz / KASAN_SHADOW_SCALE_SIZE;
287 	for (i = 0; i < n; i++) {
288 		*shad++ = code;
289 	}
290 }
291 
292 /* -------------------------------------------------------------------------- */
293 
294 #define ADDR_CROSSES_SCALE_BOUNDARY(addr, size) 		\
295 	(addr >> KASAN_SHADOW_SCALE_SHIFT) !=			\
296 	    ((addr + size - 1) >> KASAN_SHADOW_SCALE_SHIFT)
297 
298 static __always_inline bool
299 kasan_shadow_1byte_isvalid(unsigned long addr, uint8_t *code)
300 {
301 	int8_t *byte = kasan_md_addr_to_shad((void *)addr);
302 	int8_t last = (addr & KASAN_SHADOW_MASK) + 1;
303 
304 	if (__predict_true(*byte == 0 || last <= *byte)) {
305 		return true;
306 	}
307 	*code = *byte;
308 	return false;
309 }
310 
311 static __always_inline bool
312 kasan_shadow_2byte_isvalid(unsigned long addr, uint8_t *code)
313 {
314 	int8_t *byte, last;
315 
316 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 2)) {
317 		return (kasan_shadow_1byte_isvalid(addr, code) &&
318 		    kasan_shadow_1byte_isvalid(addr+1, code));
319 	}
320 
321 	byte = kasan_md_addr_to_shad((void *)addr);
322 	last = ((addr + 1) & KASAN_SHADOW_MASK) + 1;
323 
324 	if (__predict_true(*byte == 0 || last <= *byte)) {
325 		return true;
326 	}
327 	*code = *byte;
328 	return false;
329 }
330 
331 static __always_inline bool
332 kasan_shadow_4byte_isvalid(unsigned long addr, uint8_t *code)
333 {
334 	int8_t *byte, last;
335 
336 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 4)) {
337 		return (kasan_shadow_2byte_isvalid(addr, code) &&
338 		    kasan_shadow_2byte_isvalid(addr+2, code));
339 	}
340 
341 	byte = kasan_md_addr_to_shad((void *)addr);
342 	last = ((addr + 3) & KASAN_SHADOW_MASK) + 1;
343 
344 	if (__predict_true(*byte == 0 || last <= *byte)) {
345 		return true;
346 	}
347 	*code = *byte;
348 	return false;
349 }
350 
351 static __always_inline bool
352 kasan_shadow_8byte_isvalid(unsigned long addr, uint8_t *code)
353 {
354 	int8_t *byte, last;
355 
356 	if (ADDR_CROSSES_SCALE_BOUNDARY(addr, 8)) {
357 		return (kasan_shadow_4byte_isvalid(addr, code) &&
358 		    kasan_shadow_4byte_isvalid(addr+4, code));
359 	}
360 
361 	byte = kasan_md_addr_to_shad((void *)addr);
362 	last = ((addr + 7) & KASAN_SHADOW_MASK) + 1;
363 
364 	if (__predict_true(*byte == 0 || last <= *byte)) {
365 		return true;
366 	}
367 	*code = *byte;
368 	return false;
369 }
370 
371 static __always_inline bool
372 kasan_shadow_Nbyte_isvalid(unsigned long addr, size_t size, uint8_t *code)
373 {
374 	size_t i;
375 
376 	for (i = 0; i < size; i++) {
377 		if (!kasan_shadow_1byte_isvalid(addr+i, code))
378 			return false;
379 	}
380 
381 	return true;
382 }
383 
384 static __always_inline void
385 kasan_shadow_check(unsigned long addr, size_t size, bool write,
386     unsigned long retaddr)
387 {
388 	uint8_t code;
389 	bool valid;
390 
391 	if (__predict_false(!kasan_enabled))
392 		return;
393 	if (__predict_false(size == 0))
394 		return;
395 	if (__predict_false(kasan_md_unsupported(addr)))
396 		return;
397 
398 	if (__builtin_constant_p(size)) {
399 		switch (size) {
400 		case 1:
401 			valid = kasan_shadow_1byte_isvalid(addr, &code);
402 			break;
403 		case 2:
404 			valid = kasan_shadow_2byte_isvalid(addr, &code);
405 			break;
406 		case 4:
407 			valid = kasan_shadow_4byte_isvalid(addr, &code);
408 			break;
409 		case 8:
410 			valid = kasan_shadow_8byte_isvalid(addr, &code);
411 			break;
412 		default:
413 			valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
414 			break;
415 		}
416 	} else {
417 		valid = kasan_shadow_Nbyte_isvalid(addr, size, &code);
418 	}
419 
420 	if (__predict_false(!valid)) {
421 		kasan_report(addr, size, write, retaddr, code);
422 	}
423 }
424 
425 /* -------------------------------------------------------------------------- */
426 
427 void *
428 kasan_memcpy(void *dst, const void *src, size_t len)
429 {
430 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
431 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
432 	return __builtin_memcpy(dst, src, len);
433 }
434 
435 int
436 kasan_memcmp(const void *b1, const void *b2, size_t len)
437 {
438 	kasan_shadow_check((unsigned long)b1, len, false, __RET_ADDR);
439 	kasan_shadow_check((unsigned long)b2, len, false, __RET_ADDR);
440 	return __builtin_memcmp(b1, b2, len);
441 }
442 
443 void *
444 kasan_memset(void *b, int c, size_t len)
445 {
446 	kasan_shadow_check((unsigned long)b, len, true, __RET_ADDR);
447 	return __builtin_memset(b, c, len);
448 }
449 
450 void *
451 kasan_memmove(void *dst, const void *src, size_t len)
452 {
453 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
454 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
455 	return __builtin_memmove(dst, src, len);
456 }
457 
458 char *
459 kasan_strcpy(char *dst, const char *src)
460 {
461 	char *save = dst;
462 
463 	while (1) {
464 		kasan_shadow_check((unsigned long)src, 1, false, __RET_ADDR);
465 		kasan_shadow_check((unsigned long)dst, 1, true, __RET_ADDR);
466 		*dst = *src;
467 		if (*src == '\0')
468 			break;
469 		src++, dst++;
470 	}
471 
472 	return save;
473 }
474 
475 int
476 kasan_strcmp(const char *s1, const char *s2)
477 {
478 	while (1) {
479 		kasan_shadow_check((unsigned long)s1, 1, false, __RET_ADDR);
480 		kasan_shadow_check((unsigned long)s2, 1, false, __RET_ADDR);
481 		if (*s1 != *s2)
482 			break;
483 		if (*s1 == '\0')
484 			return 0;
485 		s1++, s2++;
486 	}
487 
488 	return (*(const unsigned char *)s1 - *(const unsigned char *)s2);
489 }
490 
491 size_t
492 kasan_strlen(const char *str)
493 {
494 	const char *s;
495 
496 	s = str;
497 	while (1) {
498 		kasan_shadow_check((unsigned long)s, 1, false, __RET_ADDR);
499 		if (*s == '\0')
500 			break;
501 		s++;
502 	}
503 
504 	return (s - str);
505 }
506 
507 #undef kcopy
508 #undef copystr
509 #undef copyinstr
510 #undef copyoutstr
511 #undef copyin
512 
513 int	kasan_kcopy(const void *, void *, size_t);
514 int	kasan_copystr(const void *, void *, size_t, size_t *);
515 int	kasan_copyinstr(const void *, void *, size_t, size_t *);
516 int	kasan_copyoutstr(const void *, void *, size_t, size_t *);
517 int	kasan_copyin(const void *, void *, size_t);
518 int	kcopy(const void *, void *, size_t);
519 int	copystr(const void *, void *, size_t, size_t *);
520 int	copyinstr(const void *, void *, size_t, size_t *);
521 int	copyoutstr(const void *, void *, size_t, size_t *);
522 int	copyin(const void *, void *, size_t);
523 
524 int
525 kasan_kcopy(const void *src, void *dst, size_t len)
526 {
527 	kasan_shadow_check((unsigned long)src, len, false, __RET_ADDR);
528 	kasan_shadow_check((unsigned long)dst, len, true, __RET_ADDR);
529 	return kcopy(src, dst, len);
530 }
531 
532 int
533 kasan_copystr(const void *kfaddr, void *kdaddr, size_t len, size_t *done)
534 {
535 	kasan_shadow_check((unsigned long)kdaddr, len, true, __RET_ADDR);
536 	return copystr(kfaddr, kdaddr, len, done);
537 }
538 
539 int
540 kasan_copyin(const void *uaddr, void *kaddr, size_t len)
541 {
542 	kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
543 	return copyin(uaddr, kaddr, len);
544 }
545 
546 int
547 kasan_copyinstr(const void *uaddr, void *kaddr, size_t len, size_t *done)
548 {
549 	kasan_shadow_check((unsigned long)kaddr, len, true, __RET_ADDR);
550 	return copyinstr(uaddr, kaddr, len, done);
551 }
552 
553 int
554 kasan_copyoutstr(const void *kaddr, void *uaddr, size_t len, size_t *done)
555 {
556 	kasan_shadow_check((unsigned long)kaddr, len, false, __RET_ADDR);
557 	return copyoutstr(kaddr, uaddr, len, done);
558 }
559 
560 /* -------------------------------------------------------------------------- */
561 
562 #undef _ucas_32
563 #undef _ucas_32_mp
564 #undef _ucas_64
565 #undef _ucas_64_mp
566 #undef _ufetch_8
567 #undef _ufetch_16
568 #undef _ufetch_32
569 #undef _ufetch_64
570 
571 int _ucas_32(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
572 int kasan__ucas_32(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
573 int
574 kasan__ucas_32(volatile uint32_t *uaddr, uint32_t old, uint32_t new,
575     uint32_t *ret)
576 {
577 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
578 	    __RET_ADDR);
579 	return _ucas_32(uaddr, old, new, ret);
580 }
581 
582 #ifdef __HAVE_UCAS_MP
583 int _ucas_32_mp(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
584 int kasan__ucas_32_mp(volatile uint32_t *, uint32_t, uint32_t, uint32_t *);
585 int
586 kasan__ucas_32_mp(volatile uint32_t *uaddr, uint32_t old, uint32_t new,
587     uint32_t *ret)
588 {
589 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
590 	    __RET_ADDR);
591 	return _ucas_32_mp(uaddr, old, new, ret);
592 }
593 #endif
594 
595 #ifdef _LP64
596 int _ucas_64(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
597 int kasan__ucas_64(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
598 int
599 kasan__ucas_64(volatile uint64_t *uaddr, uint64_t old, uint64_t new,
600     uint64_t *ret)
601 {
602 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
603 	    __RET_ADDR);
604 	return _ucas_64(uaddr, old, new, ret);
605 }
606 
607 #ifdef __HAVE_UCAS_MP
608 int _ucas_64_mp(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
609 int kasan__ucas_64_mp(volatile uint64_t *, uint64_t, uint64_t, uint64_t *);
610 int
611 kasan__ucas_64_mp(volatile uint64_t *uaddr, uint64_t old, uint64_t new,
612     uint64_t *ret)
613 {
614 	kasan_shadow_check((unsigned long)ret, sizeof(*ret), true,
615 	    __RET_ADDR);
616 	return _ucas_64_mp(uaddr, old, new, ret);
617 }
618 #endif
619 #endif
620 
621 int _ufetch_8(const uint8_t *, uint8_t *);
622 int kasan__ufetch_8(const uint8_t *, uint8_t *);
623 int
624 kasan__ufetch_8(const uint8_t *uaddr, uint8_t *valp)
625 {
626 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
627 	    __RET_ADDR);
628 	return _ufetch_8(uaddr, valp);
629 }
630 
631 int _ufetch_16(const uint16_t *, uint16_t *);
632 int kasan__ufetch_16(const uint16_t *, uint16_t *);
633 int
634 kasan__ufetch_16(const uint16_t *uaddr, uint16_t *valp)
635 {
636 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
637 	    __RET_ADDR);
638 	return _ufetch_16(uaddr, valp);
639 }
640 
641 int _ufetch_32(const uint32_t *, uint32_t *);
642 int kasan__ufetch_32(const uint32_t *, uint32_t *);
643 int
644 kasan__ufetch_32(const uint32_t *uaddr, uint32_t *valp)
645 {
646 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
647 	    __RET_ADDR);
648 	return _ufetch_32(uaddr, valp);
649 }
650 
651 #ifdef _LP64
652 int _ufetch_64(const uint64_t *, uint64_t *);
653 int kasan__ufetch_64(const uint64_t *, uint64_t *);
654 int
655 kasan__ufetch_64(const uint64_t *uaddr, uint64_t *valp)
656 {
657 	kasan_shadow_check((unsigned long)valp, sizeof(*valp), true,
658 	    __RET_ADDR);
659 	return _ufetch_64(uaddr, valp);
660 }
661 #endif
662 
663 /* -------------------------------------------------------------------------- */
664 
665 #undef atomic_add_32
666 #undef atomic_add_int
667 #undef atomic_add_long
668 #undef atomic_add_ptr
669 #undef atomic_add_64
670 #undef atomic_add_32_nv
671 #undef atomic_add_int_nv
672 #undef atomic_add_long_nv
673 #undef atomic_add_ptr_nv
674 #undef atomic_add_64_nv
675 #undef atomic_and_32
676 #undef atomic_and_uint
677 #undef atomic_and_ulong
678 #undef atomic_and_64
679 #undef atomic_and_32_nv
680 #undef atomic_and_uint_nv
681 #undef atomic_and_ulong_nv
682 #undef atomic_and_64_nv
683 #undef atomic_or_32
684 #undef atomic_or_uint
685 #undef atomic_or_ulong
686 #undef atomic_or_64
687 #undef atomic_or_32_nv
688 #undef atomic_or_uint_nv
689 #undef atomic_or_ulong_nv
690 #undef atomic_or_64_nv
691 #undef atomic_cas_32
692 #undef atomic_cas_uint
693 #undef atomic_cas_ulong
694 #undef atomic_cas_ptr
695 #undef atomic_cas_64
696 #undef atomic_cas_32_ni
697 #undef atomic_cas_uint_ni
698 #undef atomic_cas_ulong_ni
699 #undef atomic_cas_ptr_ni
700 #undef atomic_cas_64_ni
701 #undef atomic_swap_32
702 #undef atomic_swap_uint
703 #undef atomic_swap_ulong
704 #undef atomic_swap_ptr
705 #undef atomic_swap_64
706 #undef atomic_dec_32
707 #undef atomic_dec_uint
708 #undef atomic_dec_ulong
709 #undef atomic_dec_ptr
710 #undef atomic_dec_64
711 #undef atomic_dec_32_nv
712 #undef atomic_dec_uint_nv
713 #undef atomic_dec_ulong_nv
714 #undef atomic_dec_ptr_nv
715 #undef atomic_dec_64_nv
716 #undef atomic_inc_32
717 #undef atomic_inc_uint
718 #undef atomic_inc_ulong
719 #undef atomic_inc_ptr
720 #undef atomic_inc_64
721 #undef atomic_inc_32_nv
722 #undef atomic_inc_uint_nv
723 #undef atomic_inc_ulong_nv
724 #undef atomic_inc_ptr_nv
725 #undef atomic_inc_64_nv
726 
727 #define ASAN_ATOMIC_FUNC_ADD(name, tret, targ1, targ2) \
728 	void atomic_add_##name(volatile targ1 *, targ2); \
729 	void kasan_atomic_add_##name(volatile targ1 *, targ2); \
730 	void kasan_atomic_add_##name(volatile targ1 *ptr, targ2 val) \
731 	{ \
732 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
733 		    __RET_ADDR); \
734 		atomic_add_##name(ptr, val); \
735 	} \
736 	tret atomic_add_##name##_nv(volatile targ1 *, targ2); \
737 	tret kasan_atomic_add_##name##_nv(volatile targ1 *, targ2); \
738 	tret kasan_atomic_add_##name##_nv(volatile targ1 *ptr, targ2 val) \
739 	{ \
740 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
741 		    __RET_ADDR); \
742 		return atomic_add_##name##_nv(ptr, val); \
743 	}
744 
745 #define ASAN_ATOMIC_FUNC_AND(name, tret, targ1, targ2) \
746 	void atomic_and_##name(volatile targ1 *, targ2); \
747 	void kasan_atomic_and_##name(volatile targ1 *, targ2); \
748 	void kasan_atomic_and_##name(volatile targ1 *ptr, targ2 val) \
749 	{ \
750 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
751 		    __RET_ADDR); \
752 		atomic_and_##name(ptr, val); \
753 	} \
754 	tret atomic_and_##name##_nv(volatile targ1 *, targ2); \
755 	tret kasan_atomic_and_##name##_nv(volatile targ1 *, targ2); \
756 	tret kasan_atomic_and_##name##_nv(volatile targ1 *ptr, targ2 val) \
757 	{ \
758 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
759 		    __RET_ADDR); \
760 		return atomic_and_##name##_nv(ptr, val); \
761 	}
762 
763 #define ASAN_ATOMIC_FUNC_OR(name, tret, targ1, targ2) \
764 	void atomic_or_##name(volatile targ1 *, targ2); \
765 	void kasan_atomic_or_##name(volatile targ1 *, targ2); \
766 	void kasan_atomic_or_##name(volatile targ1 *ptr, targ2 val) \
767 	{ \
768 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
769 		    __RET_ADDR); \
770 		atomic_or_##name(ptr, val); \
771 	} \
772 	tret atomic_or_##name##_nv(volatile targ1 *, targ2); \
773 	tret kasan_atomic_or_##name##_nv(volatile targ1 *, targ2); \
774 	tret kasan_atomic_or_##name##_nv(volatile targ1 *ptr, targ2 val) \
775 	{ \
776 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
777 		    __RET_ADDR); \
778 		return atomic_or_##name##_nv(ptr, val); \
779 	}
780 
781 #define ASAN_ATOMIC_FUNC_CAS(name, tret, targ1, targ2) \
782 	tret atomic_cas_##name(volatile targ1 *, targ2, targ2); \
783 	tret kasan_atomic_cas_##name(volatile targ1 *, targ2, targ2); \
784 	tret kasan_atomic_cas_##name(volatile targ1 *ptr, targ2 exp, targ2 new) \
785 	{ \
786 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
787 		    __RET_ADDR); \
788 		return atomic_cas_##name(ptr, exp, new); \
789 	} \
790 	tret atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
791 	tret kasan_atomic_cas_##name##_ni(volatile targ1 *, targ2, targ2); \
792 	tret kasan_atomic_cas_##name##_ni(volatile targ1 *ptr, targ2 exp, targ2 new) \
793 	{ \
794 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
795 		    __RET_ADDR); \
796 		return atomic_cas_##name##_ni(ptr, exp, new); \
797 	}
798 
799 #define ASAN_ATOMIC_FUNC_SWAP(name, tret, targ1, targ2) \
800 	tret atomic_swap_##name(volatile targ1 *, targ2); \
801 	tret kasan_atomic_swap_##name(volatile targ1 *, targ2); \
802 	tret kasan_atomic_swap_##name(volatile targ1 *ptr, targ2 val) \
803 	{ \
804 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
805 		    __RET_ADDR); \
806 		return atomic_swap_##name(ptr, val); \
807 	}
808 
809 #define ASAN_ATOMIC_FUNC_DEC(name, tret, targ1) \
810 	void atomic_dec_##name(volatile targ1 *); \
811 	void kasan_atomic_dec_##name(volatile targ1 *); \
812 	void kasan_atomic_dec_##name(volatile targ1 *ptr) \
813 	{ \
814 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
815 		    __RET_ADDR); \
816 		atomic_dec_##name(ptr); \
817 	} \
818 	tret atomic_dec_##name##_nv(volatile targ1 *); \
819 	tret kasan_atomic_dec_##name##_nv(volatile targ1 *); \
820 	tret kasan_atomic_dec_##name##_nv(volatile targ1 *ptr) \
821 	{ \
822 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
823 		    __RET_ADDR); \
824 		return atomic_dec_##name##_nv(ptr); \
825 	}
826 
827 #define ASAN_ATOMIC_FUNC_INC(name, tret, targ1) \
828 	void atomic_inc_##name(volatile targ1 *); \
829 	void kasan_atomic_inc_##name(volatile targ1 *); \
830 	void kasan_atomic_inc_##name(volatile targ1 *ptr) \
831 	{ \
832 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
833 		    __RET_ADDR); \
834 		atomic_inc_##name(ptr); \
835 	} \
836 	tret atomic_inc_##name##_nv(volatile targ1 *); \
837 	tret kasan_atomic_inc_##name##_nv(volatile targ1 *); \
838 	tret kasan_atomic_inc_##name##_nv(volatile targ1 *ptr) \
839 	{ \
840 		kasan_shadow_check((uintptr_t)ptr, sizeof(tret), true, \
841 		    __RET_ADDR); \
842 		return atomic_inc_##name##_nv(ptr); \
843 	}
844 
845 ASAN_ATOMIC_FUNC_ADD(32, uint32_t, uint32_t, int32_t);
846 ASAN_ATOMIC_FUNC_ADD(64, uint64_t, uint64_t, int64_t);
847 ASAN_ATOMIC_FUNC_ADD(int, unsigned int, unsigned int, int);
848 ASAN_ATOMIC_FUNC_ADD(long, unsigned long, unsigned long, long);
849 ASAN_ATOMIC_FUNC_ADD(ptr, void *, void, ssize_t);
850 
851 ASAN_ATOMIC_FUNC_AND(32, uint32_t, uint32_t, uint32_t);
852 ASAN_ATOMIC_FUNC_AND(64, uint64_t, uint64_t, uint64_t);
853 ASAN_ATOMIC_FUNC_AND(uint, unsigned int, unsigned int, unsigned int);
854 ASAN_ATOMIC_FUNC_AND(ulong, unsigned long, unsigned long, unsigned long);
855 
856 ASAN_ATOMIC_FUNC_OR(32, uint32_t, uint32_t, uint32_t);
857 ASAN_ATOMIC_FUNC_OR(64, uint64_t, uint64_t, uint64_t);
858 ASAN_ATOMIC_FUNC_OR(uint, unsigned int, unsigned int, unsigned int);
859 ASAN_ATOMIC_FUNC_OR(ulong, unsigned long, unsigned long, unsigned long);
860 
861 ASAN_ATOMIC_FUNC_CAS(32, uint32_t, uint32_t, uint32_t);
862 ASAN_ATOMIC_FUNC_CAS(64, uint64_t, uint64_t, uint64_t);
863 ASAN_ATOMIC_FUNC_CAS(uint, unsigned int, unsigned int, unsigned int);
864 ASAN_ATOMIC_FUNC_CAS(ulong, unsigned long, unsigned long, unsigned long);
865 ASAN_ATOMIC_FUNC_CAS(ptr, void *, void, void *);
866 
867 ASAN_ATOMIC_FUNC_SWAP(32, uint32_t, uint32_t, uint32_t);
868 ASAN_ATOMIC_FUNC_SWAP(64, uint64_t, uint64_t, uint64_t);
869 ASAN_ATOMIC_FUNC_SWAP(uint, unsigned int, unsigned int, unsigned int);
870 ASAN_ATOMIC_FUNC_SWAP(ulong, unsigned long, unsigned long, unsigned long);
871 ASAN_ATOMIC_FUNC_SWAP(ptr, void *, void, void *);
872 
873 ASAN_ATOMIC_FUNC_DEC(32, uint32_t, uint32_t)
874 ASAN_ATOMIC_FUNC_DEC(64, uint64_t, uint64_t)
875 ASAN_ATOMIC_FUNC_DEC(uint, unsigned int, unsigned int);
876 ASAN_ATOMIC_FUNC_DEC(ulong, unsigned long, unsigned long);
877 ASAN_ATOMIC_FUNC_DEC(ptr, void *, void);
878 
879 ASAN_ATOMIC_FUNC_INC(32, uint32_t, uint32_t)
880 ASAN_ATOMIC_FUNC_INC(64, uint64_t, uint64_t)
881 ASAN_ATOMIC_FUNC_INC(uint, unsigned int, unsigned int);
882 ASAN_ATOMIC_FUNC_INC(ulong, unsigned long, unsigned long);
883 ASAN_ATOMIC_FUNC_INC(ptr, void *, void);
884 
885 /* -------------------------------------------------------------------------- */
886 
887 #ifdef __HAVE_KASAN_INSTR_BUS
888 
889 #include <sys/bus.h>
890 
891 #undef bus_space_read_multi_1
892 #undef bus_space_read_multi_2
893 #undef bus_space_read_multi_4
894 #undef bus_space_read_multi_8
895 #undef bus_space_read_multi_stream_1
896 #undef bus_space_read_multi_stream_2
897 #undef bus_space_read_multi_stream_4
898 #undef bus_space_read_multi_stream_8
899 #undef bus_space_read_region_1
900 #undef bus_space_read_region_2
901 #undef bus_space_read_region_4
902 #undef bus_space_read_region_8
903 #undef bus_space_read_region_stream_1
904 #undef bus_space_read_region_stream_2
905 #undef bus_space_read_region_stream_4
906 #undef bus_space_read_region_stream_8
907 #undef bus_space_write_multi_1
908 #undef bus_space_write_multi_2
909 #undef bus_space_write_multi_4
910 #undef bus_space_write_multi_8
911 #undef bus_space_write_multi_stream_1
912 #undef bus_space_write_multi_stream_2
913 #undef bus_space_write_multi_stream_4
914 #undef bus_space_write_multi_stream_8
915 #undef bus_space_write_region_1
916 #undef bus_space_write_region_2
917 #undef bus_space_write_region_4
918 #undef bus_space_write_region_8
919 #undef bus_space_write_region_stream_1
920 #undef bus_space_write_region_stream_2
921 #undef bus_space_write_region_stream_4
922 #undef bus_space_write_region_stream_8
923 
924 #define ASAN_BUS_READ_FUNC(bytes, bits) \
925 	void bus_space_read_multi_##bytes(bus_space_tag_t, bus_space_handle_t,	\
926 	    bus_size_t, uint##bits##_t *, bus_size_t);				\
927 	void kasan_bus_space_read_multi_##bytes(bus_space_tag_t,		\
928 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
929 	void kasan_bus_space_read_multi_##bytes(bus_space_tag_t tag,		\
930 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
931 	    bus_size_t count)							\
932 	{									\
933 		kasan_shadow_check((uintptr_t)buf,				\
934 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
935 		bus_space_read_multi_##bytes(tag, hnd, size, buf, count);	\
936 	}									\
937 	void bus_space_read_multi_stream_##bytes(bus_space_tag_t,		\
938 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
939 	void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t,		\
940 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
941 	void kasan_bus_space_read_multi_stream_##bytes(bus_space_tag_t tag,	\
942 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
943 	    bus_size_t count)							\
944 	{									\
945 		kasan_shadow_check((uintptr_t)buf,				\
946 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
947 		bus_space_read_multi_stream_##bytes(tag, hnd, size, buf, count);\
948 	}									\
949 	void bus_space_read_region_##bytes(bus_space_tag_t, bus_space_handle_t,	\
950 	    bus_size_t, uint##bits##_t *, bus_size_t);				\
951 	void kasan_bus_space_read_region_##bytes(bus_space_tag_t,		\
952 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
953 	void kasan_bus_space_read_region_##bytes(bus_space_tag_t tag,		\
954 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
955 	    bus_size_t count)							\
956 	{									\
957 		kasan_shadow_check((uintptr_t)buf,				\
958 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
959 		bus_space_read_region_##bytes(tag, hnd, size, buf, count);	\
960 	}									\
961 	void bus_space_read_region_stream_##bytes(bus_space_tag_t,		\
962 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
963 	void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t,	\
964 	    bus_space_handle_t, bus_size_t, uint##bits##_t *, bus_size_t);	\
965 	void kasan_bus_space_read_region_stream_##bytes(bus_space_tag_t tag,	\
966 	    bus_space_handle_t hnd, bus_size_t size, uint##bits##_t *buf,	\
967 	    bus_size_t count)							\
968 	{									\
969 		kasan_shadow_check((uintptr_t)buf,				\
970 		    sizeof(uint##bits##_t) * count, false, __RET_ADDR);		\
971 		bus_space_read_region_stream_##bytes(tag, hnd, size, buf, count);\
972 	}
973 
974 #define ASAN_BUS_WRITE_FUNC(bytes, bits) \
975 	void bus_space_write_multi_##bytes(bus_space_tag_t, bus_space_handle_t,	\
976 	    bus_size_t, const uint##bits##_t *, bus_size_t);			\
977 	void kasan_bus_space_write_multi_##bytes(bus_space_tag_t,		\
978 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
979 	void kasan_bus_space_write_multi_##bytes(bus_space_tag_t tag,		\
980 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
981 	    bus_size_t count)							\
982 	{									\
983 		kasan_shadow_check((uintptr_t)buf,				\
984 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
985 		bus_space_write_multi_##bytes(tag, hnd, size, buf, count);	\
986 	}									\
987 	void bus_space_write_multi_stream_##bytes(bus_space_tag_t,		\
988 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
989 	void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t,	\
990 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
991 	void kasan_bus_space_write_multi_stream_##bytes(bus_space_tag_t tag,	\
992 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
993 	    bus_size_t count)							\
994 	{									\
995 		kasan_shadow_check((uintptr_t)buf,				\
996 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
997 		bus_space_write_multi_stream_##bytes(tag, hnd, size, buf, count);\
998 	}									\
999 	void bus_space_write_region_##bytes(bus_space_tag_t, bus_space_handle_t,\
1000 	    bus_size_t, const uint##bits##_t *, bus_size_t);			\
1001 	void kasan_bus_space_write_region_##bytes(bus_space_tag_t,		\
1002 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
1003 	void kasan_bus_space_write_region_##bytes(bus_space_tag_t tag,		\
1004 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
1005 	    bus_size_t count)							\
1006 	{									\
1007 		kasan_shadow_check((uintptr_t)buf,				\
1008 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
1009 		bus_space_write_region_##bytes(tag, hnd, size, buf, count);	\
1010 	}									\
1011 	void bus_space_write_region_stream_##bytes(bus_space_tag_t,		\
1012 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
1013 	void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t,	\
1014 	    bus_space_handle_t, bus_size_t, const uint##bits##_t *, bus_size_t);\
1015 	void kasan_bus_space_write_region_stream_##bytes(bus_space_tag_t tag,	\
1016 	    bus_space_handle_t hnd, bus_size_t size, const uint##bits##_t *buf,	\
1017 	    bus_size_t count)							\
1018 	{									\
1019 		kasan_shadow_check((uintptr_t)buf,				\
1020 		    sizeof(uint##bits##_t) * count, true, __RET_ADDR);		\
1021 		bus_space_write_region_stream_##bytes(tag, hnd, size, buf, count);\
1022 	}
1023 
1024 ASAN_BUS_READ_FUNC(1, 8)
1025 ASAN_BUS_READ_FUNC(2, 16)
1026 ASAN_BUS_READ_FUNC(4, 32)
1027 ASAN_BUS_READ_FUNC(8, 64)
1028 
1029 ASAN_BUS_WRITE_FUNC(1, 8)
1030 ASAN_BUS_WRITE_FUNC(2, 16)
1031 ASAN_BUS_WRITE_FUNC(4, 32)
1032 ASAN_BUS_WRITE_FUNC(8, 64)
1033 
1034 #endif /* __HAVE_KASAN_INSTR_BUS */
1035 
1036 /* -------------------------------------------------------------------------- */
1037 
1038 #ifdef __HAVE_KASAN_INSTR_DMA
1039 
1040 #include <sys/mbuf.h>
1041 
1042 static void
1043 kasan_dma_sync_linear(uint8_t *buf, bus_addr_t offset, bus_size_t len,
1044     bool write, uintptr_t pc)
1045 {
1046 	kasan_shadow_check((uintptr_t)(buf + offset), len, write, pc);
1047 }
1048 
1049 static void
1050 kasan_dma_sync_mbuf(struct mbuf *m, bus_addr_t offset, bus_size_t len,
1051     bool write, uintptr_t pc)
1052 {
1053 	bus_addr_t minlen;
1054 
1055 	for (; m != NULL && len != 0; m = m->m_next) {
1056 		kasan_shadow_check((uintptr_t)m, sizeof(*m), false, pc);
1057 
1058 		if (offset >= m->m_len) {
1059 			offset -= m->m_len;
1060 			continue;
1061 		}
1062 
1063 		minlen = MIN(len, m->m_len - offset);
1064 		kasan_shadow_check((uintptr_t)(mtod(m, char *) + offset),
1065 		    minlen, write, pc);
1066 
1067 		offset = 0;
1068 		len -= minlen;
1069 	}
1070 }
1071 
1072 static void
1073 kasan_dma_sync_uio(struct uio *uio, bus_addr_t offset, bus_size_t len,
1074     bool write, uintptr_t pc)
1075 {
1076 	bus_size_t minlen, resid;
1077 	struct iovec *iov;
1078 	int i;
1079 
1080 	if (uio->uio_vmspace != NULL)
1081 		return;
1082 
1083 	kasan_shadow_check((uintptr_t)uio, sizeof(struct uio), false, pc);
1084 
1085 	resid = uio->uio_resid;
1086 	iov = uio->uio_iov;
1087 
1088 	for (i = 0; i < uio->uio_iovcnt && resid != 0; i++) {
1089 		kasan_shadow_check((uintptr_t)&iov[i], sizeof(iov[i]),
1090 		    false, pc);
1091 		minlen = MIN(resid, iov[i].iov_len);
1092 		kasan_shadow_check((uintptr_t)iov[i].iov_base, minlen,
1093 		    write, pc);
1094 		resid -= minlen;
1095 	}
1096 }
1097 
1098 void
1099 kasan_dma_sync(bus_dmamap_t map, bus_addr_t offset, bus_size_t len, int ops)
1100 {
1101 	bool write = (ops & (BUS_DMASYNC_PREWRITE|BUS_DMASYNC_POSTWRITE)) != 0;
1102 
1103 	switch (map->dm_buftype) {
1104 	case KASAN_DMA_LINEAR:
1105 		kasan_dma_sync_linear(map->dm_buf, offset, len, write,
1106 		    __RET_ADDR);
1107 		break;
1108 	case KASAN_DMA_MBUF:
1109 		kasan_dma_sync_mbuf(map->dm_buf, offset, len, write,
1110 		    __RET_ADDR);
1111 		break;
1112 	case KASAN_DMA_UIO:
1113 		kasan_dma_sync_uio(map->dm_buf, offset, len, write,
1114 		    __RET_ADDR);
1115 		break;
1116 	case KASAN_DMA_RAW:
1117 		break;
1118 	default:
1119 		panic("%s: impossible", __func__);
1120 	}
1121 }
1122 
1123 void
1124 kasan_dma_load(bus_dmamap_t map, void *buf, bus_size_t buflen, int type)
1125 {
1126 	map->dm_buf = buf;
1127 	map->dm_buflen = buflen;
1128 	map->dm_buftype = type;
1129 }
1130 
1131 #endif /* __HAVE_KASAN_INSTR_DMA */
1132 
1133 /* -------------------------------------------------------------------------- */
1134 
1135 void __asan_register_globals(struct __asan_global *, size_t);
1136 void __asan_unregister_globals(struct __asan_global *, size_t);
1137 
1138 void
1139 __asan_register_globals(struct __asan_global *globals, size_t n)
1140 {
1141 	size_t i;
1142 
1143 	for (i = 0; i < n; i++) {
1144 		kasan_mark(globals[i].beg, globals[i].size,
1145 		    globals[i].size_with_redzone, KASAN_GENERIC_REDZONE);
1146 	}
1147 }
1148 
1149 void
1150 __asan_unregister_globals(struct __asan_global *globals, size_t n)
1151 {
1152 	/* never called */
1153 }
1154 
1155 #define ASAN_LOAD_STORE(size)					\
1156 	void __asan_load##size(unsigned long);			\
1157 	void __asan_load##size(unsigned long addr)		\
1158 	{							\
1159 		kasan_shadow_check(addr, size, false, __RET_ADDR);\
1160 	} 							\
1161 	void __asan_load##size##_noabort(unsigned long);	\
1162 	void __asan_load##size##_noabort(unsigned long addr)	\
1163 	{							\
1164 		kasan_shadow_check(addr, size, false, __RET_ADDR);\
1165 	}							\
1166 	void __asan_store##size(unsigned long);			\
1167 	void __asan_store##size(unsigned long addr)		\
1168 	{							\
1169 		kasan_shadow_check(addr, size, true, __RET_ADDR);\
1170 	}							\
1171 	void __asan_store##size##_noabort(unsigned long);	\
1172 	void __asan_store##size##_noabort(unsigned long addr)	\
1173 	{							\
1174 		kasan_shadow_check(addr, size, true, __RET_ADDR);\
1175 	}
1176 
1177 ASAN_LOAD_STORE(1);
1178 ASAN_LOAD_STORE(2);
1179 ASAN_LOAD_STORE(4);
1180 ASAN_LOAD_STORE(8);
1181 ASAN_LOAD_STORE(16);
1182 
1183 void __asan_loadN(unsigned long, size_t);
1184 void __asan_loadN_noabort(unsigned long, size_t);
1185 void __asan_storeN(unsigned long, size_t);
1186 void __asan_storeN_noabort(unsigned long, size_t);
1187 void __asan_handle_no_return(void);
1188 
1189 void
1190 __asan_loadN(unsigned long addr, size_t size)
1191 {
1192 	kasan_shadow_check(addr, size, false, __RET_ADDR);
1193 }
1194 
1195 void
1196 __asan_loadN_noabort(unsigned long addr, size_t size)
1197 {
1198 	kasan_shadow_check(addr, size, false, __RET_ADDR);
1199 }
1200 
1201 void
1202 __asan_storeN(unsigned long addr, size_t size)
1203 {
1204 	kasan_shadow_check(addr, size, true, __RET_ADDR);
1205 }
1206 
1207 void
1208 __asan_storeN_noabort(unsigned long addr, size_t size)
1209 {
1210 	kasan_shadow_check(addr, size, true, __RET_ADDR);
1211 }
1212 
1213 void
1214 __asan_handle_no_return(void)
1215 {
1216 	/* nothing */
1217 }
1218 
1219 #define ASAN_SET_SHADOW(byte) \
1220 	void __asan_set_shadow_##byte(void *, size_t);			\
1221 	void __asan_set_shadow_##byte(void *addr, size_t size)		\
1222 	{								\
1223 		__builtin_memset((void *)addr, 0x##byte, size);		\
1224 	}
1225 
1226 ASAN_SET_SHADOW(00);
1227 ASAN_SET_SHADOW(f1);
1228 ASAN_SET_SHADOW(f2);
1229 ASAN_SET_SHADOW(f3);
1230 ASAN_SET_SHADOW(f5);
1231 ASAN_SET_SHADOW(f8);
1232 
1233 void __asan_poison_stack_memory(const void *, size_t);
1234 void __asan_unpoison_stack_memory(const void *, size_t);
1235 
1236 void __asan_poison_stack_memory(const void *addr, size_t size)
1237 {
1238 	size = roundup(size, KASAN_SHADOW_SCALE_SIZE);
1239 	kasan_shadow_Nbyte_fill(addr, size, KASAN_USE_AFTER_SCOPE);
1240 }
1241 
1242 void __asan_unpoison_stack_memory(const void *addr, size_t size)
1243 {
1244 	kasan_shadow_Nbyte_markvalid(addr, size);
1245 }
1246