Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (c) 2017 Intel Corporation |
| 3 | * |
| 4 | * SPDX-License-Identifier: Apache-2.0 |
| 5 | */ |
| 6 | |
| 7 | |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 8 | #include <zephyr/kernel.h> |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 9 | #include <string.h> |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 10 | #include <zephyr/sys/math_extras.h> |
| 11 | #include <zephyr/sys/rb.h> |
| 12 | #include <zephyr/kernel_structs.h> |
| 13 | #include <zephyr/sys/sys_io.h> |
Andrew Boie | 5cfa5dc | 2017-08-30 14:17:44 -0700 | [diff] [blame] | 14 | #include <ksched.h> |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 15 | #include <zephyr/syscall.h> |
| 16 | #include <zephyr/syscall_handler.h> |
| 17 | #include <zephyr/device.h> |
| 18 | #include <zephyr/init.h> |
Flavio Ceolin | 8a14817 | 2018-12-16 12:39:44 -0800 | [diff] [blame] | 19 | #include <stdbool.h> |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 20 | #include <zephyr/app_memory/app_memdomain.h> |
| 21 | #include <zephyr/sys/libc-hooks.h> |
| 22 | #include <zephyr/sys/mutex.h> |
Andrew Boie | 800b35f | 2019-11-05 09:27:18 -0800 | [diff] [blame] | 23 | #include <inttypes.h> |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 24 | #include <zephyr/linker/linker-defs.h> |
Andrew Boie | 17ce822 | 2019-02-21 13:44:54 -0800 | [diff] [blame] | 25 | |
Andrew Boie | 7707060 | 2019-02-27 20:12:40 -0800 | [diff] [blame] | 26 | #ifdef Z_LIBC_PARTITION_EXISTS |
Andrew Boie | 17ce822 | 2019-02-21 13:44:54 -0800 | [diff] [blame] | 27 | K_APPMEM_PARTITION_DEFINE(z_libc_partition); |
Andrew Boie | 7707060 | 2019-02-27 20:12:40 -0800 | [diff] [blame] | 28 | #endif |
Anas Nashif | 0a0c8c8 | 2018-09-17 06:58:09 -0500 | [diff] [blame] | 29 | |
Andrew Boie | e686aef | 2019-02-27 14:41:45 -0800 | [diff] [blame] | 30 | /* TODO: Find a better place to put this. Since we pull the entire |
Anas Nashif | 6e27d6d | 2019-05-09 08:43:30 -0400 | [diff] [blame] | 31 | * lib..__modules__crypto__mbedtls.a globals into app shared memory |
| 32 | * section, we can't put this in zephyr_init.c of the mbedtls module. |
Andrew Boie | e686aef | 2019-02-27 14:41:45 -0800 | [diff] [blame] | 33 | */ |
| 34 | #ifdef CONFIG_MBEDTLS |
| 35 | K_APPMEM_PARTITION_DEFINE(k_mbedtls_partition); |
| 36 | #endif |
| 37 | |
Gerard Marull-Paretas | cffefc8 | 2022-05-06 11:04:23 +0200 | [diff] [blame] | 38 | #include <zephyr/logging/log.h> |
Krzysztof Chruscinski | 3ed8083 | 2020-11-26 19:32:34 +0100 | [diff] [blame] | 39 | LOG_MODULE_DECLARE(os, CONFIG_KERNEL_LOG_LEVEL); |
Anas Nashif | 0a0c8c8 | 2018-09-17 06:58:09 -0500 | [diff] [blame] | 40 | |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 41 | /* The originally synchronization strategy made heavy use of recursive |
| 42 | * irq_locking, which ports poorly to spinlocks which are |
| 43 | * non-recursive. Rather than try to redesign as part of |
| 44 | * spinlockification, this uses multiple locks to preserve the |
| 45 | * original semantics exactly. The locks are named for the data they |
| 46 | * protect where possible, or just for the code that uses them where |
| 47 | * not. |
| 48 | */ |
| 49 | #ifdef CONFIG_DYNAMIC_OBJECTS |
Flavio Ceolin | 2b1106a | 2023-07-14 12:24:33 -0700 | [diff] [blame] | 50 | static struct k_spinlock lists_lock; /* kobj dlist */ |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 51 | static struct k_spinlock objfree_lock; /* k_object_free */ |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 52 | |
| 53 | #ifdef CONFIG_GEN_PRIV_STACKS |
| 54 | /* On ARM MPU we may have two different alignment requirement |
| 55 | * when dynamically allocating thread stacks, one for the privileged |
| 56 | * stack and other for the user stack, so we need to account the |
| 57 | * worst alignment scenario and reserve space for that. |
| 58 | */ |
| 59 | #ifdef CONFIG_ARM_MPU |
| 60 | #define STACK_ELEMENT_DATA_SIZE(size) \ |
| 61 | (sizeof(struct z_stack_data) + CONFIG_PRIVILEGED_STACK_SIZE + \ |
| 62 | Z_THREAD_STACK_OBJ_ALIGN(size) + Z_THREAD_STACK_SIZE_ADJUST(size)) |
| 63 | #else |
| 64 | #define STACK_ELEMENT_DATA_SIZE(size) (sizeof(struct z_stack_data) + \ |
| 65 | Z_THREAD_STACK_SIZE_ADJUST(size)) |
| 66 | #endif /* CONFIG_ARM_MPU */ |
| 67 | #else |
| 68 | #define STACK_ELEMENT_DATA_SIZE(size) Z_THREAD_STACK_SIZE_ADJUST(size) |
| 69 | #endif /* CONFIG_GEN_PRIV_STACKS */ |
| 70 | |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 71 | #endif |
| 72 | static struct k_spinlock obj_lock; /* kobj struct data */ |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 73 | |
Andrew Boie | 2574219 | 2017-10-16 15:29:30 -0700 | [diff] [blame] | 74 | #define MAX_THREAD_BITS (CONFIG_MAX_THREAD_BYTES * 8) |
| 75 | |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 76 | #ifdef CONFIG_DYNAMIC_OBJECTS |
Kumar Gala | a1b77fd | 2020-05-27 11:26:57 -0500 | [diff] [blame] | 77 | extern uint8_t _thread_idx_map[CONFIG_MAX_THREAD_BYTES]; |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 78 | #endif |
| 79 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 80 | static void clear_perms_cb(struct z_object *ko, void *ctx_ptr); |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 81 | |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 82 | const char *otype_to_str(enum k_objects otype) |
| 83 | { |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 84 | const char *ret; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 85 | /* -fdata-sections doesn't work right except in very very recent |
| 86 | * GCC and these literal strings would appear in the binary even if |
| 87 | * otype_to_str was omitted by the linker |
| 88 | */ |
Andrew Boie | cb1dd74 | 2019-10-01 10:28:32 -0700 | [diff] [blame] | 89 | #ifdef CONFIG_LOG |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 90 | switch (otype) { |
Leandro Pereira | 39dc7d0 | 2018-04-05 13:59:33 -0700 | [diff] [blame] | 91 | /* otype-to-str.h is generated automatically during build by |
| 92 | * gen_kobject_list.py |
| 93 | */ |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 94 | case K_OBJ_ANY: |
| 95 | ret = "generic"; |
| 96 | break; |
Leandro Pereira | 39dc7d0 | 2018-04-05 13:59:33 -0700 | [diff] [blame] | 97 | #include <otype-to-str.h> |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 98 | default: |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 99 | ret = "?"; |
| 100 | break; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 101 | } |
| 102 | #else |
| 103 | ARG_UNUSED(otype); |
Maksim Masalski | d6c9d40 | 2021-05-24 16:30:32 +0800 | [diff] [blame] | 104 | ret = NULL; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 105 | #endif |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 106 | return ret; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 107 | } |
| 108 | |
Andrew Boie | 47f8fd1 | 2017-10-05 11:11:02 -0700 | [diff] [blame] | 109 | struct perm_ctx { |
| 110 | int parent_id; |
| 111 | int child_id; |
| 112 | struct k_thread *parent; |
| 113 | }; |
| 114 | |
Andrew Boie | 28be793 | 2020-03-11 10:56:19 -0700 | [diff] [blame] | 115 | #ifdef CONFIG_GEN_PRIV_STACKS |
Anas Nashif | efbadbb | 2022-07-11 10:53:29 -0400 | [diff] [blame] | 116 | /* See write_gperf_table() in scripts/build/gen_kobject_list.py. The privilege |
Andrew Boie | 28be793 | 2020-03-11 10:56:19 -0700 | [diff] [blame] | 117 | * mode stacks are allocated as an array. The base of the array is |
| 118 | * aligned to Z_PRIVILEGE_STACK_ALIGN, and all members must be as well. |
| 119 | */ |
Kumar Gala | a1b77fd | 2020-05-27 11:26:57 -0500 | [diff] [blame] | 120 | uint8_t *z_priv_stack_find(k_thread_stack_t *stack) |
Andrew Boie | 28be793 | 2020-03-11 10:56:19 -0700 | [diff] [blame] | 121 | { |
| 122 | struct z_object *obj = z_object_find(stack); |
| 123 | |
| 124 | __ASSERT(obj != NULL, "stack object not found"); |
| 125 | __ASSERT(obj->type == K_OBJ_THREAD_STACK_ELEMENT, |
| 126 | "bad stack object"); |
| 127 | |
| 128 | return obj->data.stack_data->priv; |
| 129 | } |
| 130 | #endif /* CONFIG_GEN_PRIV_STACKS */ |
| 131 | |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 132 | #ifdef CONFIG_DYNAMIC_OBJECTS |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 133 | |
| 134 | /* |
| 135 | * Note that dyn_obj->data is where the kernel object resides |
| 136 | * so it is the one that actually needs to be aligned. |
| 137 | * Due to the need to get the the fields inside struct dyn_obj |
| 138 | * from kernel object pointers (i.e. from data[]), the offset |
| 139 | * from data[] needs to be fixed at build time. Therefore, |
| 140 | * data[] is declared with __aligned(), such that when dyn_obj |
| 141 | * is allocated with alignment, data[] is also aligned. |
| 142 | * Due to this requirement, data[] needs to be aligned with |
| 143 | * the maximum alignment needed for all kernel objects |
| 144 | * (hence the following DYN_OBJ_DATA_ALIGN). |
| 145 | */ |
Peter Mitsis | 48f5164 | 2021-12-16 12:47:32 -0500 | [diff] [blame] | 146 | #ifdef ARCH_DYNAMIC_OBJ_K_THREAD_ALIGNMENT |
| 147 | #define DYN_OBJ_DATA_ALIGN_K_THREAD (ARCH_DYNAMIC_OBJ_K_THREAD_ALIGNMENT) |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 148 | #else |
| 149 | #define DYN_OBJ_DATA_ALIGN_K_THREAD (sizeof(void *)) |
| 150 | #endif |
| 151 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 152 | #ifdef CONFIG_DYNAMIC_THREAD_STACK_SIZE |
| 153 | #ifndef CONFIG_MPU_STACK_GUARD |
| 154 | #define DYN_OBJ_DATA_ALIGN_K_THREAD_STACK \ |
| 155 | Z_THREAD_STACK_OBJ_ALIGN(CONFIG_PRIVILEGED_STACK_SIZE) |
| 156 | #else |
| 157 | #define DYN_OBJ_DATA_ALIGN_K_THREAD_STACK \ |
| 158 | Z_THREAD_STACK_OBJ_ALIGN(CONFIG_DYNAMIC_THREAD_STACK_SIZE) |
| 159 | #endif /* !CONFIG_MPU_STACK_GUARD */ |
| 160 | #else |
| 161 | #define DYN_OBJ_DATA_ALIGN_K_THREAD_STACK \ |
| 162 | Z_THREAD_STACK_OBJ_ALIGN(ARCH_STACK_PTR_ALIGN) |
| 163 | #endif /* CONFIG_DYNAMIC_THREAD_STACK_SIZE */ |
| 164 | |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 165 | #define DYN_OBJ_DATA_ALIGN \ |
| 166 | MAX(DYN_OBJ_DATA_ALIGN_K_THREAD, (sizeof(void *))) |
| 167 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 168 | struct dyn_obj { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 169 | struct z_object kobj; |
| 170 | sys_dnode_t dobj_list; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 171 | |
| 172 | /* The object itself */ |
| 173 | void *data; |
| 174 | }; |
| 175 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 176 | extern struct z_object *z_object_gperf_find(const void *obj); |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 177 | extern void z_object_gperf_wordlist_foreach(_wordlist_cb_func_t func, |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 178 | void *context); |
| 179 | |
Andrew Boie | 97bf001 | 2018-04-24 17:01:37 -0700 | [diff] [blame] | 180 | /* |
| 181 | * Linked list of allocated kernel objects, for iteration over all allocated |
| 182 | * objects (and potentially deleting them during iteration). |
| 183 | */ |
| 184 | static sys_dlist_t obj_list = SYS_DLIST_STATIC_INIT(&obj_list); |
| 185 | |
| 186 | /* |
Flavio Ceolin | 2b1106a | 2023-07-14 12:24:33 -0700 | [diff] [blame] | 187 | * TODO: Write some hash table code that will replace obj_list. |
Andrew Boie | 97bf001 | 2018-04-24 17:01:37 -0700 | [diff] [blame] | 188 | */ |
| 189 | |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 190 | static size_t obj_size_get(enum k_objects otype) |
| 191 | { |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 192 | size_t ret; |
| 193 | |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 194 | switch (otype) { |
Andrew Boie | 47fa8eb | 2018-05-16 10:11:17 -0700 | [diff] [blame] | 195 | #include <otype-to-size.h> |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 196 | default: |
Tomasz Bursztyka | e18fcbb | 2020-04-30 20:33:38 +0200 | [diff] [blame] | 197 | ret = sizeof(const struct device); |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 198 | break; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 199 | } |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 200 | |
| 201 | return ret; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 202 | } |
| 203 | |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 204 | static size_t obj_align_get(enum k_objects otype) |
| 205 | { |
| 206 | size_t ret; |
| 207 | |
| 208 | switch (otype) { |
| 209 | case K_OBJ_THREAD: |
Peter Mitsis | 48f5164 | 2021-12-16 12:47:32 -0500 | [diff] [blame] | 210 | #ifdef ARCH_DYNAMIC_OBJ_K_THREAD_ALIGNMENT |
| 211 | ret = ARCH_DYNAMIC_OBJ_K_THREAD_ALIGNMENT; |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 212 | #else |
Daniel Leung | b6dd960 | 2021-12-13 14:54:51 -0800 | [diff] [blame] | 213 | ret = __alignof(struct dyn_obj); |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 214 | #endif |
| 215 | break; |
| 216 | default: |
Daniel Leung | b6dd960 | 2021-12-13 14:54:51 -0800 | [diff] [blame] | 217 | ret = __alignof(struct dyn_obj); |
Daniel Leung | fe477ea | 2020-12-15 13:50:48 -0800 | [diff] [blame] | 218 | break; |
| 219 | } |
| 220 | |
| 221 | return ret; |
| 222 | } |
| 223 | |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 224 | static struct dyn_obj *dyn_object_find(void *obj) |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 225 | { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 226 | struct dyn_obj *node; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 227 | k_spinlock_key_t key; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 228 | |
| 229 | /* For any dynamically allocated kernel object, the object |
Naiyuan Tian | bc3fda4 | 2021-08-23 23:32:58 +0800 | [diff] [blame] | 230 | * pointer is just a member of the containing struct dyn_obj, |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 231 | * so just a little arithmetic is necessary to locate the |
| 232 | * corresponding struct rbnode |
| 233 | */ |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 234 | key = k_spin_lock(&lists_lock); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 235 | |
Flavio Ceolin | 2b1106a | 2023-07-14 12:24:33 -0700 | [diff] [blame] | 236 | SYS_DLIST_FOR_EACH_CONTAINER(&obj_list, node, dobj_list) { |
| 237 | if (node->kobj.name == obj) { |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 238 | goto end; |
| 239 | } |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 240 | } |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 241 | |
| 242 | /* No object found */ |
Flavio Ceolin | 2b1106a | 2023-07-14 12:24:33 -0700 | [diff] [blame] | 243 | node = NULL; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 244 | |
| 245 | end: |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 246 | k_spin_unlock(&lists_lock, key); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 247 | |
Flavio Ceolin | 2b1106a | 2023-07-14 12:24:33 -0700 | [diff] [blame] | 248 | return node; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 249 | } |
| 250 | |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 251 | /** |
| 252 | * @internal |
| 253 | * |
| 254 | * @brief Allocate a new thread index for a new thread. |
| 255 | * |
| 256 | * This finds an unused thread index that can be assigned to a new |
| 257 | * thread. If too many threads have been allocated, the kernel will |
| 258 | * run out of indexes and this function will fail. |
| 259 | * |
| 260 | * Note that if an unused index is found, that index will be marked as |
| 261 | * used after return of this function. |
| 262 | * |
| 263 | * @param tidx The new thread index if successful |
| 264 | * |
Flavio Ceolin | 8a14817 | 2018-12-16 12:39:44 -0800 | [diff] [blame] | 265 | * @return true if successful, false if failed |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 266 | **/ |
Andrew Boie | 428afe5 | 2019-11-18 10:20:16 -0800 | [diff] [blame] | 267 | static bool thread_idx_alloc(uintptr_t *tidx) |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 268 | { |
| 269 | int i; |
| 270 | int idx; |
| 271 | int base; |
| 272 | |
| 273 | base = 0; |
| 274 | for (i = 0; i < CONFIG_MAX_THREAD_BYTES; i++) { |
| 275 | idx = find_lsb_set(_thread_idx_map[i]); |
| 276 | |
Flavio Ceolin | 76b3518 | 2018-12-16 12:48:29 -0800 | [diff] [blame] | 277 | if (idx != 0) { |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 278 | *tidx = base + (idx - 1); |
| 279 | |
| 280 | sys_bitfield_clear_bit((mem_addr_t)_thread_idx_map, |
| 281 | *tidx); |
| 282 | |
| 283 | /* Clear permission from all objects */ |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 284 | z_object_wordlist_foreach(clear_perms_cb, |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 285 | (void *)*tidx); |
| 286 | |
Flavio Ceolin | 8a14817 | 2018-12-16 12:39:44 -0800 | [diff] [blame] | 287 | return true; |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 288 | } |
| 289 | |
| 290 | base += 8; |
| 291 | } |
| 292 | |
Flavio Ceolin | 8a14817 | 2018-12-16 12:39:44 -0800 | [diff] [blame] | 293 | return false; |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 294 | } |
| 295 | |
| 296 | /** |
| 297 | * @internal |
| 298 | * |
| 299 | * @brief Free a thread index. |
| 300 | * |
| 301 | * This frees a thread index so it can be used by another |
| 302 | * thread. |
| 303 | * |
| 304 | * @param tidx The thread index to be freed |
| 305 | **/ |
Andrew Boie | 428afe5 | 2019-11-18 10:20:16 -0800 | [diff] [blame] | 306 | static void thread_idx_free(uintptr_t tidx) |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 307 | { |
| 308 | /* To prevent leaked permission when index is recycled */ |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 309 | z_object_wordlist_foreach(clear_perms_cb, (void *)tidx); |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 310 | |
| 311 | sys_bitfield_set_bit((mem_addr_t)_thread_idx_map, tidx); |
| 312 | } |
| 313 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 314 | static struct z_object *dynamic_object_create(enum k_objects otype, size_t align, |
| 315 | size_t size) |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 316 | { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 317 | struct dyn_obj *dyn; |
| 318 | |
| 319 | dyn = z_thread_aligned_alloc(align, sizeof(struct dyn_obj)); |
| 320 | if (dyn == NULL) { |
| 321 | return NULL; |
| 322 | } |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 323 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 324 | if (otype == K_OBJ_THREAD_STACK_ELEMENT) { |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 325 | size_t adjusted_size; |
| 326 | |
| 327 | if (size == 0) { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 328 | k_free(dyn); |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 329 | return NULL; |
| 330 | } |
| 331 | |
| 332 | adjusted_size = STACK_ELEMENT_DATA_SIZE(size); |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 333 | dyn->data = z_thread_aligned_alloc(DYN_OBJ_DATA_ALIGN_K_THREAD_STACK, |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 334 | adjusted_size); |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 335 | if (dyn->data == NULL) { |
| 336 | k_free(dyn); |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 337 | return NULL; |
| 338 | } |
| 339 | |
| 340 | #ifdef CONFIG_GEN_PRIV_STACKS |
| 341 | struct z_stack_data *stack_data = (struct z_stack_data *) |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 342 | ((uint8_t *)dyn->data + adjusted_size - sizeof(*stack_data)); |
| 343 | stack_data->priv = (uint8_t *)dyn->data; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 344 | dyn->kobj.data.stack_data = stack_data; |
| 345 | #ifdef CONFIG_ARM_MPU |
| 346 | dyn->kobj.name = (void *)ROUND_UP( |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 347 | ((uint8_t *)dyn->data + CONFIG_PRIVILEGED_STACK_SIZE), |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 348 | Z_THREAD_STACK_OBJ_ALIGN(size)); |
| 349 | #else |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 350 | dyn->kobj.name = dyn->data; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 351 | #endif |
| 352 | #else |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 353 | dyn->kobj.name = dyn->data; |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 354 | #endif |
| 355 | } else { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 356 | dyn->data = z_thread_aligned_alloc(align, obj_size_get(otype) + size); |
| 357 | if (dyn->data == NULL) { |
| 358 | k_free(dyn->data); |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 359 | return NULL; |
| 360 | } |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 361 | dyn->kobj.name = dyn->data; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 362 | } |
| 363 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 364 | dyn->kobj.type = otype; |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 365 | dyn->kobj.flags = 0; |
| 366 | (void)memset(dyn->kobj.perms, 0, CONFIG_MAX_THREAD_BYTES); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 367 | |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 368 | k_spinlock_key_t key = k_spin_lock(&lists_lock); |
| 369 | |
Daniel Leung | abfe045 | 2021-04-27 11:49:30 -0700 | [diff] [blame] | 370 | sys_dlist_append(&obj_list, &dyn->dobj_list); |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 371 | k_spin_unlock(&lists_lock, key); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 372 | |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 373 | return &dyn->kobj; |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 374 | } |
| 375 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 376 | struct z_object *z_dynamic_object_aligned_create(size_t align, size_t size) |
| 377 | { |
| 378 | struct z_object *obj = dynamic_object_create(K_OBJ_ANY, align, size); |
| 379 | |
| 380 | if (obj == NULL) { |
| 381 | LOG_ERR("could not allocate kernel object, out of memory"); |
| 382 | } |
| 383 | |
| 384 | return obj; |
| 385 | } |
| 386 | |
| 387 | static void *z_object_alloc(enum k_objects otype, size_t size) |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 388 | { |
| 389 | struct z_object *zo; |
Ioannis Glaropoulos | 8ada29e | 2020-06-11 09:53:01 +0200 | [diff] [blame] | 390 | uintptr_t tidx = 0; |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 391 | |
| 392 | if (otype <= K_OBJ_ANY || otype >= K_OBJ_LAST) { |
| 393 | LOG_ERR("bad object type %d requested", otype); |
| 394 | return NULL; |
| 395 | } |
| 396 | |
| 397 | switch (otype) { |
| 398 | case K_OBJ_THREAD: |
| 399 | if (!thread_idx_alloc(&tidx)) { |
| 400 | LOG_ERR("out of free thread indexes"); |
| 401 | return NULL; |
| 402 | } |
| 403 | break; |
| 404 | /* The following are currently not allowed at all */ |
| 405 | case K_OBJ_FUTEX: /* Lives in user memory */ |
| 406 | case K_OBJ_SYS_MUTEX: /* Lives in user memory */ |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 407 | case K_OBJ_NET_SOCKET: /* Indeterminate size */ |
| 408 | LOG_ERR("forbidden object type '%s' requested", |
| 409 | otype_to_str(otype)); |
| 410 | return NULL; |
| 411 | default: |
| 412 | /* Remainder within bounds are permitted */ |
| 413 | break; |
| 414 | } |
| 415 | |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 416 | zo = dynamic_object_create(otype, obj_align_get(otype), size); |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 417 | if (zo == NULL) { |
Nicolas Pitre | 962b374 | 2022-03-13 18:28:59 -0400 | [diff] [blame] | 418 | if (otype == K_OBJ_THREAD) { |
| 419 | thread_idx_free(tidx); |
| 420 | } |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 421 | return NULL; |
| 422 | } |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 423 | |
| 424 | if (otype == K_OBJ_THREAD) { |
| 425 | zo->data.thread_id = tidx; |
| 426 | } |
| 427 | |
| 428 | /* The allocating thread implicitly gets permission on kernel objects |
| 429 | * that it allocates |
| 430 | */ |
| 431 | z_thread_perms_set(zo, _current); |
| 432 | |
| 433 | /* Activates reference counting logic for automatic disposal when |
| 434 | * all permissions have been revoked |
| 435 | */ |
| 436 | zo->flags |= K_OBJ_FLAG_ALLOC; |
| 437 | |
| 438 | return zo->name; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 439 | } |
| 440 | |
Flavio Ceolin | 67e66e4 | 2023-06-22 06:27:28 +0000 | [diff] [blame] | 441 | void *z_impl_k_object_alloc(enum k_objects otype) |
| 442 | { |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 443 | return z_object_alloc(otype, 0); |
Flavio Ceolin | 67e66e4 | 2023-06-22 06:27:28 +0000 | [diff] [blame] | 444 | } |
| 445 | |
| 446 | void *z_impl_k_object_alloc_size(enum k_objects otype, size_t size) |
| 447 | { |
| 448 | return z_object_alloc(otype, size); |
| 449 | } |
| 450 | |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 451 | void k_object_free(void *obj) |
| 452 | { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 453 | struct dyn_obj *dyn; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 454 | |
| 455 | /* This function is intentionally not exposed to user mode. |
| 456 | * There's currently no robust way to track that an object isn't |
| 457 | * being used by some other thread |
| 458 | */ |
| 459 | |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 460 | k_spinlock_key_t key = k_spin_lock(&objfree_lock); |
| 461 | |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 462 | dyn = dyn_object_find(obj); |
| 463 | if (dyn != NULL) { |
Daniel Leung | abfe045 | 2021-04-27 11:49:30 -0700 | [diff] [blame] | 464 | sys_dlist_remove(&dyn->dobj_list); |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 465 | |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 466 | if (dyn->kobj.type == K_OBJ_THREAD) { |
| 467 | thread_idx_free(dyn->kobj.data.thread_id); |
Daniel Leung | e58b654 | 2018-08-08 11:23:16 -0700 | [diff] [blame] | 468 | } |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 469 | } |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 470 | k_spin_unlock(&objfree_lock, key); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 471 | |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 472 | if (dyn != NULL) { |
Flavio Ceolin | ed8355a | 2023-07-18 21:00:07 +0000 | [diff] [blame] | 473 | k_free(dyn->data); |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 474 | k_free(dyn); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 475 | } |
| 476 | } |
| 477 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 478 | struct z_object *z_object_find(const void *obj) |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 479 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 480 | struct z_object *ret; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 481 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 482 | ret = z_object_gperf_find(obj); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 483 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 484 | if (ret == NULL) { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 485 | struct dyn_obj *dyn; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 486 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 487 | /* The cast to pointer-to-non-const violates MISRA |
| 488 | * 11.8 but is justified since we know dynamic objects |
| 489 | * were not declared with a const qualifier. |
| 490 | */ |
Flavio Ceolin | 3b7e0b6 | 2023-06-23 09:34:14 -0700 | [diff] [blame] | 491 | dyn = dyn_object_find((void *)obj); |
| 492 | if (dyn != NULL) { |
| 493 | ret = &dyn->kobj; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 494 | } |
| 495 | } |
| 496 | |
| 497 | return ret; |
| 498 | } |
| 499 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 500 | void z_object_wordlist_foreach(_wordlist_cb_func_t func, void *context) |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 501 | { |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 502 | struct dyn_obj *obj, *next; |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 503 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 504 | z_object_gperf_wordlist_foreach(func, context); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 505 | |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 506 | k_spinlock_key_t key = k_spin_lock(&lists_lock); |
| 507 | |
Daniel Leung | abfe045 | 2021-04-27 11:49:30 -0700 | [diff] [blame] | 508 | SYS_DLIST_FOR_EACH_CONTAINER_SAFE(&obj_list, obj, next, dobj_list) { |
Andrew Boie | 97bf001 | 2018-04-24 17:01:37 -0700 | [diff] [blame] | 509 | func(&obj->kobj, context); |
| 510 | } |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 511 | k_spin_unlock(&lists_lock, key); |
Andrew Boie | 31bdfc0 | 2017-11-08 16:38:03 -0800 | [diff] [blame] | 512 | } |
| 513 | #endif /* CONFIG_DYNAMIC_OBJECTS */ |
| 514 | |
Andrew Boie | f2734ab | 2020-03-11 06:37:42 -0700 | [diff] [blame] | 515 | static unsigned int thread_index_get(struct k_thread *thread) |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 516 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 517 | struct z_object *ko; |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 518 | |
Anas Nashif | 9e3e7f6 | 2019-12-19 08:19:45 -0500 | [diff] [blame] | 519 | ko = z_object_find(thread); |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 520 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 521 | if (ko == NULL) { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 522 | return -1; |
| 523 | } |
| 524 | |
Andrew Boie | f2734ab | 2020-03-11 06:37:42 -0700 | [diff] [blame] | 525 | return ko->data.thread_id; |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 526 | } |
| 527 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 528 | static void unref_check(struct z_object *ko, uintptr_t index) |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 529 | { |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 530 | k_spinlock_key_t key = k_spin_lock(&obj_lock); |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 531 | |
| 532 | sys_bitfield_clear_bit((mem_addr_t)&ko->perms, index); |
| 533 | |
| 534 | #ifdef CONFIG_DYNAMIC_OBJECTS |
Daniel Leung | b6dd960 | 2021-12-13 14:54:51 -0800 | [diff] [blame] | 535 | if ((ko->flags & K_OBJ_FLAG_ALLOC) == 0U) { |
| 536 | /* skip unref check for static kernel object */ |
| 537 | goto out; |
| 538 | } |
| 539 | |
Carles Cufi | 55350a9 | 2021-12-04 19:57:03 +0100 | [diff] [blame] | 540 | void *vko = ko; |
| 541 | |
Flavio Ceolin | cbbe6d2 | 2023-07-18 13:11:07 -0700 | [diff] [blame] | 542 | struct dyn_obj *dyn = CONTAINER_OF(vko, struct dyn_obj, kobj); |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 543 | |
Daniel Leung | b6dd960 | 2021-12-13 14:54:51 -0800 | [diff] [blame] | 544 | __ASSERT(IS_PTR_ALIGNED(dyn, struct dyn_obj), "unaligned z_object"); |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 545 | |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 546 | for (int i = 0; i < CONFIG_MAX_THREAD_BYTES; i++) { |
Patrik Flykt | 24d7143 | 2019-03-26 19:57:45 -0600 | [diff] [blame] | 547 | if (ko->perms[i] != 0U) { |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 548 | goto out; |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 549 | } |
| 550 | } |
| 551 | |
| 552 | /* This object has no more references. Some objects may have |
| 553 | * dynamically allocated resources, require cleanup, or need to be |
| 554 | * marked as uninitailized when all references are gone. What |
| 555 | * specifically needs to happen depends on the object type. |
| 556 | */ |
| 557 | switch (ko->type) { |
Peter Mitsis | f86027f | 2022-07-08 11:27:09 -0400 | [diff] [blame] | 558 | #ifdef CONFIG_PIPES |
Andrew Boie | 44fe812 | 2018-04-12 17:38:12 -0700 | [diff] [blame] | 559 | case K_OBJ_PIPE: |
| 560 | k_pipe_cleanup((struct k_pipe *)ko->name); |
| 561 | break; |
Peter Mitsis | f86027f | 2022-07-08 11:27:09 -0400 | [diff] [blame] | 562 | #endif |
Andrew Boie | 0fe789f | 2018-04-12 18:35:56 -0700 | [diff] [blame] | 563 | case K_OBJ_MSGQ: |
| 564 | k_msgq_cleanup((struct k_msgq *)ko->name); |
| 565 | break; |
Andrew Boie | f3bee95 | 2018-05-02 17:44:39 -0700 | [diff] [blame] | 566 | case K_OBJ_STACK: |
| 567 | k_stack_cleanup((struct k_stack *)ko->name); |
| 568 | break; |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 569 | default: |
Flavio Ceolin | 3259ac0 | 2018-09-11 13:14:21 -0700 | [diff] [blame] | 570 | /* Nothing to do */ |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 571 | break; |
| 572 | } |
Andrew Boie | 97bf001 | 2018-04-24 17:01:37 -0700 | [diff] [blame] | 573 | |
Daniel Leung | abfe045 | 2021-04-27 11:49:30 -0700 | [diff] [blame] | 574 | sys_dlist_remove(&dyn->dobj_list); |
Flavio Ceolin | ed8355a | 2023-07-18 21:00:07 +0000 | [diff] [blame] | 575 | k_free(dyn->data); |
Spoorthy Priya Yerabolu | 9247e8b | 2020-08-25 03:11:16 -0700 | [diff] [blame] | 576 | k_free(dyn); |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 577 | out: |
Andrew Boie | 97bf001 | 2018-04-24 17:01:37 -0700 | [diff] [blame] | 578 | #endif |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 579 | k_spin_unlock(&obj_lock, key); |
Andrew Boie | 337e743 | 2018-04-13 14:44:00 -0700 | [diff] [blame] | 580 | } |
| 581 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 582 | static void wordlist_cb(struct z_object *ko, void *ctx_ptr) |
Andrew Boie | 47f8fd1 | 2017-10-05 11:11:02 -0700 | [diff] [blame] | 583 | { |
| 584 | struct perm_ctx *ctx = (struct perm_ctx *)ctx_ptr; |
| 585 | |
| 586 | if (sys_bitfield_test_bit((mem_addr_t)&ko->perms, ctx->parent_id) && |
| 587 | (struct k_thread *)ko->name != ctx->parent) { |
| 588 | sys_bitfield_set_bit((mem_addr_t)&ko->perms, ctx->child_id); |
| 589 | } |
| 590 | } |
| 591 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 592 | void z_thread_perms_inherit(struct k_thread *parent, struct k_thread *child) |
Andrew Boie | 47f8fd1 | 2017-10-05 11:11:02 -0700 | [diff] [blame] | 593 | { |
| 594 | struct perm_ctx ctx = { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 595 | thread_index_get(parent), |
| 596 | thread_index_get(child), |
Andrew Boie | 47f8fd1 | 2017-10-05 11:11:02 -0700 | [diff] [blame] | 597 | parent |
| 598 | }; |
| 599 | |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 600 | if ((ctx.parent_id != -1) && (ctx.child_id != -1)) { |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 601 | z_object_wordlist_foreach(wordlist_cb, &ctx); |
Andrew Boie | 47f8fd1 | 2017-10-05 11:11:02 -0700 | [diff] [blame] | 602 | } |
| 603 | } |
| 604 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 605 | void z_thread_perms_set(struct z_object *ko, struct k_thread *thread) |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 606 | { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 607 | int index = thread_index_get(thread); |
| 608 | |
| 609 | if (index != -1) { |
| 610 | sys_bitfield_set_bit((mem_addr_t)&ko->perms, index); |
Andrew Boie | 2acfcd6 | 2017-08-30 14:31:03 -0700 | [diff] [blame] | 611 | } |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 612 | } |
| 613 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 614 | void z_thread_perms_clear(struct z_object *ko, struct k_thread *thread) |
Andrew Boie | a89bf01 | 2017-10-09 14:47:55 -0700 | [diff] [blame] | 615 | { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 616 | int index = thread_index_get(thread); |
| 617 | |
| 618 | if (index != -1) { |
Andy Ross | 8a3d57b | 2019-02-06 09:10:36 -0800 | [diff] [blame] | 619 | sys_bitfield_clear_bit((mem_addr_t)&ko->perms, index); |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 620 | unref_check(ko, index); |
Andrew Boie | a89bf01 | 2017-10-09 14:47:55 -0700 | [diff] [blame] | 621 | } |
| 622 | } |
| 623 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 624 | static void clear_perms_cb(struct z_object *ko, void *ctx_ptr) |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 625 | { |
Andrew Boie | 428afe5 | 2019-11-18 10:20:16 -0800 | [diff] [blame] | 626 | uintptr_t id = (uintptr_t)ctx_ptr; |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 627 | |
Andrew Boie | 7ecc359 | 2019-01-31 12:09:06 -0800 | [diff] [blame] | 628 | unref_check(ko, id); |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 629 | } |
| 630 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 631 | void z_thread_perms_all_clear(struct k_thread *thread) |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 632 | { |
Andrew Boie | 428afe5 | 2019-11-18 10:20:16 -0800 | [diff] [blame] | 633 | uintptr_t index = thread_index_get(thread); |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 634 | |
Carlo Caione | f161223 | 2020-10-12 12:10:45 +0200 | [diff] [blame] | 635 | if ((int)index != -1) { |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 636 | z_object_wordlist_foreach(clear_perms_cb, (void *)index); |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 637 | } |
| 638 | } |
| 639 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 640 | static int thread_perms_test(struct z_object *ko) |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 641 | { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 642 | int index; |
| 643 | |
Patrik Flykt | 24d7143 | 2019-03-26 19:57:45 -0600 | [diff] [blame] | 644 | if ((ko->flags & K_OBJ_FLAG_PUBLIC) != 0U) { |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 645 | return 1; |
| 646 | } |
| 647 | |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 648 | index = thread_index_get(_current); |
| 649 | if (index != -1) { |
| 650 | return sys_bitfield_test_bit((mem_addr_t)&ko->perms, index); |
Andrew Boie | 2acfcd6 | 2017-08-30 14:31:03 -0700 | [diff] [blame] | 651 | } |
| 652 | return 0; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 653 | } |
| 654 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 655 | static void dump_permission_error(struct z_object *ko) |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 656 | { |
Andrew Boie | 818a96d | 2017-11-03 09:00:35 -0700 | [diff] [blame] | 657 | int index = thread_index_get(_current); |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 658 | LOG_ERR("thread %p (%d) does not have permission on %s %p", |
| 659 | _current, index, |
| 660 | otype_to_str(ko->type), ko->name); |
| 661 | LOG_HEXDUMP_ERR(ko->perms, sizeof(ko->perms), "permission bitmap"); |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 662 | } |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 663 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 664 | void z_dump_object_error(int retval, const void *obj, struct z_object *ko, |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 665 | enum k_objects otype) |
| 666 | { |
| 667 | switch (retval) { |
| 668 | case -EBADF: |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 669 | LOG_ERR("%p is not a valid %s", obj, otype_to_str(otype)); |
Andrew Boie | be919d3 | 2020-05-29 17:49:02 -0700 | [diff] [blame] | 670 | if (ko == NULL) { |
| 671 | LOG_ERR("address is not a known kernel object"); |
| 672 | } else { |
| 673 | LOG_ERR("address is actually a %s", |
| 674 | otype_to_str(ko->type)); |
| 675 | } |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 676 | break; |
| 677 | case -EPERM: |
| 678 | dump_permission_error(ko); |
| 679 | break; |
| 680 | case -EINVAL: |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 681 | LOG_ERR("%p used before initialization", obj); |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 682 | break; |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 683 | case -EADDRINUSE: |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 684 | LOG_ERR("%p %s in use", obj, otype_to_str(otype)); |
Flavio Ceolin | a3cea50 | 2018-09-10 22:54:55 -0700 | [diff] [blame] | 685 | break; |
| 686 | default: |
| 687 | /* Not handled error */ |
| 688 | break; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 689 | } |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 690 | } |
| 691 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 692 | void z_impl_k_object_access_grant(const void *object, struct k_thread *thread) |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 693 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 694 | struct z_object *ko = z_object_find(object); |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 695 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 696 | if (ko != NULL) { |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 697 | z_thread_perms_set(ko, thread); |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 698 | } |
| 699 | } |
| 700 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 701 | void k_object_access_revoke(const void *object, struct k_thread *thread) |
Andrew Boie | a89bf01 | 2017-10-09 14:47:55 -0700 | [diff] [blame] | 702 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 703 | struct z_object *ko = z_object_find(object); |
Andrew Boie | a89bf01 | 2017-10-09 14:47:55 -0700 | [diff] [blame] | 704 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 705 | if (ko != NULL) { |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 706 | z_thread_perms_clear(ko, thread); |
Andrew Boie | a89bf01 | 2017-10-09 14:47:55 -0700 | [diff] [blame] | 707 | } |
| 708 | } |
| 709 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 710 | void z_impl_k_object_release(const void *object) |
Andrew Boie | e9cfc54 | 2018-04-13 13:15:28 -0700 | [diff] [blame] | 711 | { |
| 712 | k_object_access_revoke(object, _current); |
| 713 | } |
| 714 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 715 | void k_object_access_all_grant(const void *object) |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 716 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 717 | struct z_object *ko = z_object_find(object); |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 718 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 719 | if (ko != NULL) { |
Andrew Boie | 04caa67 | 2017-10-13 13:57:07 -0700 | [diff] [blame] | 720 | ko->flags |= K_OBJ_FLAG_PUBLIC; |
Andrew Boie | 3b5ae80 | 2017-10-04 12:10:32 -0700 | [diff] [blame] | 721 | } |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 722 | } |
| 723 | |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 724 | int z_object_validate(struct z_object *ko, enum k_objects otype, |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 725 | enum _obj_init_check init) |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 726 | { |
Flavio Ceolin | ea716bf | 2018-09-20 16:30:45 -0700 | [diff] [blame] | 727 | if (unlikely((ko == NULL) || |
| 728 | (otype != K_OBJ_ANY && ko->type != otype))) { |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 729 | return -EBADF; |
| 730 | } |
| 731 | |
Andrew Boie | 3a0f684 | 2017-10-09 12:46:25 -0700 | [diff] [blame] | 732 | /* Manipulation of any kernel objects by a user thread requires that |
| 733 | * thread be granted access first, even for uninitialized objects |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 734 | */ |
Flavio Ceolin | 2df02cc | 2019-03-14 14:32:45 -0700 | [diff] [blame] | 735 | if (unlikely(thread_perms_test(ko) == 0)) { |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 736 | return -EPERM; |
| 737 | } |
| 738 | |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 739 | /* Initialization state checks. _OBJ_INIT_ANY, we don't care */ |
| 740 | if (likely(init == _OBJ_INIT_TRUE)) { |
Naiyuan Tian | bc3fda4 | 2021-08-23 23:32:58 +0800 | [diff] [blame] | 741 | /* Object MUST be initialized */ |
Patrik Flykt | 21358ba | 2019-03-28 14:57:54 -0600 | [diff] [blame] | 742 | if (unlikely((ko->flags & K_OBJ_FLAG_INITIALIZED) == 0U)) { |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 743 | return -EINVAL; |
| 744 | } |
Maksim Masalski | 929956d | 2021-05-17 16:58:20 +0800 | [diff] [blame] | 745 | } else if (init == _OBJ_INIT_FALSE) { /* _OBJ_INIT_FALSE case */ |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 746 | /* Object MUST NOT be initialized */ |
Patrik Flykt | 21358ba | 2019-03-28 14:57:54 -0600 | [diff] [blame] | 747 | if (unlikely((ko->flags & K_OBJ_FLAG_INITIALIZED) != 0U)) { |
Andrew Boie | a2b40ec | 2017-10-15 14:22:08 -0700 | [diff] [blame] | 748 | return -EADDRINUSE; |
| 749 | } |
Flavio Ceolin | 3e97acc | 2018-09-25 11:24:28 -0700 | [diff] [blame] | 750 | } else { |
| 751 | /* _OBJ_INIT_ANY */ |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 752 | } |
| 753 | |
| 754 | return 0; |
| 755 | } |
| 756 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 757 | void z_object_init(const void *obj) |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 758 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 759 | struct z_object *ko; |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 760 | |
| 761 | /* By the time we get here, if the caller was from userspace, all the |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 762 | * necessary checks have been done in z_object_validate(), which takes |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 763 | * place before the object is initialized. |
| 764 | * |
| 765 | * This function runs after the object has been initialized and |
| 766 | * finalizes it |
| 767 | */ |
| 768 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 769 | ko = z_object_find(obj); |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 770 | if (ko == NULL) { |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 771 | /* Supervisor threads can ignore rules about kernel objects |
| 772 | * and may declare them on stacks, etc. Such objects will never |
| 773 | * be usable from userspace, but we shouldn't explode. |
| 774 | */ |
| 775 | return; |
| 776 | } |
| 777 | |
Andrew Boie | 7e3d3d7 | 2017-10-10 09:31:32 -0700 | [diff] [blame] | 778 | /* Allows non-initialization system calls to be made on this object */ |
Andrew Boie | 945af95 | 2017-08-22 13:15:23 -0700 | [diff] [blame] | 779 | ko->flags |= K_OBJ_FLAG_INITIALIZED; |
| 780 | } |
| 781 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 782 | void z_object_recycle(const void *obj) |
Andrew Boie | 83fda7c | 2018-07-31 14:39:11 -0700 | [diff] [blame] | 783 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 784 | struct z_object *ko = z_object_find(obj); |
Andrew Boie | 83fda7c | 2018-07-31 14:39:11 -0700 | [diff] [blame] | 785 | |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 786 | if (ko != NULL) { |
Flavio Ceolin | da49f2e | 2018-09-11 19:09:03 -0700 | [diff] [blame] | 787 | (void)memset(ko->perms, 0, sizeof(ko->perms)); |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 788 | z_thread_perms_set(ko, k_current_get()); |
Andrew Boie | 83fda7c | 2018-07-31 14:39:11 -0700 | [diff] [blame] | 789 | ko->flags |= K_OBJ_FLAG_INITIALIZED; |
| 790 | } |
| 791 | } |
| 792 | |
Peter Bigot | 2fcf762 | 2020-05-14 05:06:08 -0500 | [diff] [blame] | 793 | void z_object_uninit(const void *obj) |
Andrew Boie | 4a9a424 | 2017-10-05 12:21:36 -0700 | [diff] [blame] | 794 | { |
Andrew Boie | 2dc2ecf | 2020-03-11 07:13:07 -0700 | [diff] [blame] | 795 | struct z_object *ko; |
Andrew Boie | 4a9a424 | 2017-10-05 12:21:36 -0700 | [diff] [blame] | 796 | |
Patrik Flykt | 4344e27 | 2019-03-08 14:19:05 -0700 | [diff] [blame] | 797 | /* See comments in z_object_init() */ |
| 798 | ko = z_object_find(obj); |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 799 | if (ko == NULL) { |
Andrew Boie | 4a9a424 | 2017-10-05 12:21:36 -0700 | [diff] [blame] | 800 | return; |
| 801 | } |
| 802 | |
| 803 | ko->flags &= ~K_OBJ_FLAG_INITIALIZED; |
| 804 | } |
| 805 | |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 806 | /* |
| 807 | * Copy to/from helper functions used in syscall handlers |
| 808 | */ |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 809 | void *z_user_alloc_from_copy(const void *src, size_t size) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 810 | { |
| 811 | void *dst = NULL; |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 812 | |
| 813 | /* Does the caller in user mode have access to read this memory? */ |
| 814 | if (Z_SYSCALL_MEMORY_READ(src, size)) { |
| 815 | goto out_err; |
| 816 | } |
| 817 | |
| 818 | dst = z_thread_malloc(size); |
Flavio Ceolin | 4218d5f | 2018-09-17 09:39:51 -0700 | [diff] [blame] | 819 | if (dst == NULL) { |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 820 | LOG_ERR("out of thread resource pool memory (%zu)", size); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 821 | goto out_err; |
| 822 | } |
| 823 | |
Flavio Ceolin | 6699423 | 2018-08-13 15:17:04 -0700 | [diff] [blame] | 824 | (void)memcpy(dst, src, size); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 825 | out_err: |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 826 | return dst; |
| 827 | } |
| 828 | |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 829 | static int user_copy(void *dst, const void *src, size_t size, bool to_user) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 830 | { |
| 831 | int ret = EFAULT; |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 832 | |
| 833 | /* Does the caller in user mode have access to this memory? */ |
| 834 | if (to_user ? Z_SYSCALL_MEMORY_WRITE(dst, size) : |
| 835 | Z_SYSCALL_MEMORY_READ(src, size)) { |
| 836 | goto out_err; |
| 837 | } |
| 838 | |
Flavio Ceolin | 6699423 | 2018-08-13 15:17:04 -0700 | [diff] [blame] | 839 | (void)memcpy(dst, src, size); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 840 | ret = 0; |
| 841 | out_err: |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 842 | return ret; |
| 843 | } |
| 844 | |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 845 | int z_user_from_copy(void *dst, const void *src, size_t size) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 846 | { |
| 847 | return user_copy(dst, src, size, false); |
| 848 | } |
| 849 | |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 850 | int z_user_to_copy(void *dst, const void *src, size_t size) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 851 | { |
| 852 | return user_copy(dst, src, size, true); |
| 853 | } |
| 854 | |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 855 | char *z_user_string_alloc_copy(const char *src, size_t maxlen) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 856 | { |
Jakob Olesen | c8708d9 | 2019-05-07 10:17:35 -0700 | [diff] [blame] | 857 | size_t actual_len; |
Flavio Ceolin | 0866d18 | 2018-08-14 17:57:08 -0700 | [diff] [blame] | 858 | int err; |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 859 | char *ret = NULL; |
| 860 | |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 861 | actual_len = z_user_string_nlen(src, maxlen, &err); |
Flavio Ceolin | 76b3518 | 2018-12-16 12:48:29 -0800 | [diff] [blame] | 862 | if (err != 0) { |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 863 | goto out; |
| 864 | } |
| 865 | if (actual_len == maxlen) { |
| 866 | /* Not NULL terminated */ |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 867 | LOG_ERR("string too long %p (%zu)", src, actual_len); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 868 | goto out; |
| 869 | } |
Jakob Olesen | c8708d9 | 2019-05-07 10:17:35 -0700 | [diff] [blame] | 870 | if (size_add_overflow(actual_len, 1, &actual_len)) { |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 871 | LOG_ERR("overflow"); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 872 | goto out; |
| 873 | } |
| 874 | |
| 875 | ret = z_user_alloc_from_copy(src, actual_len); |
Andrew Boie | 09dc929 | 2019-04-12 12:32:34 -0700 | [diff] [blame] | 876 | |
| 877 | /* Someone may have modified the source string during the above |
| 878 | * checks. Ensure what we actually copied is still terminated |
| 879 | * properly. |
| 880 | */ |
| 881 | if (ret != NULL) { |
Anas Nashif | bbbc38b | 2021-03-29 10:03:49 -0400 | [diff] [blame] | 882 | ret[actual_len - 1U] = '\0'; |
Andrew Boie | 09dc929 | 2019-04-12 12:32:34 -0700 | [diff] [blame] | 883 | } |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 884 | out: |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 885 | return ret; |
| 886 | } |
| 887 | |
Andrew Boie | 526807c | 2019-03-28 15:17:31 -0700 | [diff] [blame] | 888 | int z_user_string_copy(char *dst, const char *src, size_t maxlen) |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 889 | { |
Jakob Olesen | c8708d9 | 2019-05-07 10:17:35 -0700 | [diff] [blame] | 890 | size_t actual_len; |
Flavio Ceolin | 0866d18 | 2018-08-14 17:57:08 -0700 | [diff] [blame] | 891 | int ret, err; |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 892 | |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 893 | actual_len = z_user_string_nlen(src, maxlen, &err); |
Flavio Ceolin | 76b3518 | 2018-12-16 12:48:29 -0800 | [diff] [blame] | 894 | if (err != 0) { |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 895 | ret = EFAULT; |
| 896 | goto out; |
| 897 | } |
| 898 | if (actual_len == maxlen) { |
| 899 | /* Not NULL terminated */ |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 900 | LOG_ERR("string too long %p (%zu)", src, actual_len); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 901 | ret = EINVAL; |
| 902 | goto out; |
| 903 | } |
Jakob Olesen | c8708d9 | 2019-05-07 10:17:35 -0700 | [diff] [blame] | 904 | if (size_add_overflow(actual_len, 1, &actual_len)) { |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 905 | LOG_ERR("overflow"); |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 906 | ret = EINVAL; |
| 907 | goto out; |
| 908 | } |
| 909 | |
| 910 | ret = z_user_from_copy(dst, src, actual_len); |
Andrew Boie | 09dc929 | 2019-04-12 12:32:34 -0700 | [diff] [blame] | 911 | |
| 912 | /* See comment above in z_user_string_alloc_copy() */ |
| 913 | dst[actual_len - 1] = '\0'; |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 914 | out: |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 915 | return ret; |
| 916 | } |
| 917 | |
| 918 | /* |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 919 | * Application memory region initialization |
| 920 | */ |
| 921 | |
| 922 | extern char __app_shmem_regions_start[]; |
| 923 | extern char __app_shmem_regions_end[]; |
| 924 | |
Gerard Marull-Paretas | a5fd0d1 | 2022-10-19 09:33:44 +0200 | [diff] [blame] | 925 | static int app_shmem_bss_zero(void) |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 926 | { |
| 927 | struct z_app_region *region, *end; |
| 928 | |
Andrew Boie | fb1c294 | 2020-03-16 11:20:08 -0700 | [diff] [blame] | 929 | |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 930 | end = (struct z_app_region *)&__app_shmem_regions_end; |
| 931 | region = (struct z_app_region *)&__app_shmem_regions_start; |
| 932 | |
| 933 | for ( ; region < end; region++) { |
Daniel Leung | 2117a2a | 2021-07-12 13:33:32 -0700 | [diff] [blame] | 934 | #if defined(CONFIG_DEMAND_PAGING) && !defined(CONFIG_LINKER_GENERIC_SECTIONS_PRESENT_AT_BOOT) |
| 935 | /* When BSS sections are not present at boot, we need to wait for |
| 936 | * paging mechanism to be initialized before we can zero out BSS. |
| 937 | */ |
| 938 | extern bool z_sys_post_kernel; |
| 939 | bool do_clear = z_sys_post_kernel; |
| 940 | |
| 941 | /* During pre-kernel init, z_sys_post_kernel == false, but |
| 942 | * with pinned rodata region, so clear. Otherwise skip. |
| 943 | * In post-kernel init, z_sys_post_kernel == true, |
| 944 | * skip those in pinned rodata region as they have already |
| 945 | * been cleared and possibly already in use. Otherwise clear. |
| 946 | */ |
| 947 | if (((uint8_t *)region->bss_start >= (uint8_t *)_app_smem_pinned_start) && |
| 948 | ((uint8_t *)region->bss_start < (uint8_t *)_app_smem_pinned_end)) { |
| 949 | do_clear = !do_clear; |
| 950 | } |
| 951 | |
| 952 | if (do_clear) |
| 953 | #endif /* CONFIG_DEMAND_PAGING && !CONFIG_LINKER_GENERIC_SECTIONS_PRESENT_AT_BOOT */ |
| 954 | { |
| 955 | (void)memset(region->bss_start, 0, region->bss_size); |
| 956 | } |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 957 | } |
Andrew Boie | fb1c294 | 2020-03-16 11:20:08 -0700 | [diff] [blame] | 958 | |
| 959 | return 0; |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 960 | } |
| 961 | |
Jordan Yates | 6f41d52 | 2022-07-02 12:06:55 +1000 | [diff] [blame] | 962 | SYS_INIT_NAMED(app_shmem_bss_zero_pre, app_shmem_bss_zero, |
| 963 | PRE_KERNEL_1, CONFIG_KERNEL_INIT_PRIORITY_DEFAULT); |
Andrew Boie | fb1c294 | 2020-03-16 11:20:08 -0700 | [diff] [blame] | 964 | |
Daniel Leung | 2117a2a | 2021-07-12 13:33:32 -0700 | [diff] [blame] | 965 | #if defined(CONFIG_DEMAND_PAGING) && !defined(CONFIG_LINKER_GENERIC_SECTIONS_PRESENT_AT_BOOT) |
| 966 | /* When BSS sections are not present at boot, we need to wait for |
| 967 | * paging mechanism to be initialized before we can zero out BSS. |
| 968 | */ |
Jordan Yates | 6f41d52 | 2022-07-02 12:06:55 +1000 | [diff] [blame] | 969 | SYS_INIT_NAMED(app_shmem_bss_zero_post, app_shmem_bss_zero, |
| 970 | POST_KERNEL, CONFIG_KERNEL_INIT_PRIORITY_DEFAULT); |
Daniel Leung | 2117a2a | 2021-07-12 13:33:32 -0700 | [diff] [blame] | 971 | #endif /* CONFIG_DEMAND_PAGING && !CONFIG_LINKER_GENERIC_SECTIONS_PRESENT_AT_BOOT */ |
| 972 | |
Andrew Boie | 4ce652e | 2019-02-22 16:08:44 -0800 | [diff] [blame] | 973 | /* |
Andrew Boie | c8188f6 | 2018-06-22 14:31:51 -0700 | [diff] [blame] | 974 | * Default handlers if otherwise unimplemented |
| 975 | */ |
| 976 | |
Andrew Boie | 800b35f | 2019-11-05 09:27:18 -0800 | [diff] [blame] | 977 | static uintptr_t handler_bad_syscall(uintptr_t bad_id, uintptr_t arg2, |
| 978 | uintptr_t arg3, uintptr_t arg4, |
| 979 | uintptr_t arg5, uintptr_t arg6, |
| 980 | void *ssf) |
Andrew Boie | f564986 | 2017-09-08 12:10:12 -0700 | [diff] [blame] | 981 | { |
Andrew Boie | 800b35f | 2019-11-05 09:27:18 -0800 | [diff] [blame] | 982 | LOG_ERR("Bad system call id %" PRIuPTR " invoked", bad_id); |
Andrew Boie | 64c8189 | 2020-05-28 16:24:09 -0700 | [diff] [blame] | 983 | arch_syscall_oops(ssf); |
Andrew Boie | 777336e | 2019-06-24 09:35:55 -0700 | [diff] [blame] | 984 | CODE_UNREACHABLE; /* LCOV_EXCL_LINE */ |
Andrew Boie | f564986 | 2017-09-08 12:10:12 -0700 | [diff] [blame] | 985 | } |
| 986 | |
Andrew Boie | 800b35f | 2019-11-05 09:27:18 -0800 | [diff] [blame] | 987 | static uintptr_t handler_no_syscall(uintptr_t arg1, uintptr_t arg2, |
| 988 | uintptr_t arg3, uintptr_t arg4, |
| 989 | uintptr_t arg5, uintptr_t arg6, void *ssf) |
Andrew Boie | fa94ee7 | 2017-09-28 16:54:35 -0700 | [diff] [blame] | 990 | { |
Andrew Boie | 99b3f86 | 2019-09-30 14:25:23 -0700 | [diff] [blame] | 991 | LOG_ERR("Unimplemented system call"); |
Andrew Boie | 64c8189 | 2020-05-28 16:24:09 -0700 | [diff] [blame] | 992 | arch_syscall_oops(ssf); |
Andrew Boie | 777336e | 2019-06-24 09:35:55 -0700 | [diff] [blame] | 993 | CODE_UNREACHABLE; /* LCOV_EXCL_LINE */ |
Andrew Boie | fa94ee7 | 2017-09-28 16:54:35 -0700 | [diff] [blame] | 994 | } |
Andrew Boie | fc273c0 | 2017-09-23 12:51:23 -0700 | [diff] [blame] | 995 | |
Andrew Boie | fa94ee7 | 2017-09-28 16:54:35 -0700 | [diff] [blame] | 996 | #include <syscall_dispatch.c> |