85 lines · c
1// SPDX-License-Identifier: GPL-2.0-or-later2/*3 * data_breakpoint.c - Sample HW Breakpoint file to watch kernel data address4 *5 * usage: insmod data_breakpoint.ko ksym=<ksym_name>6 *7 * This file is a kernel module that places a breakpoint over ksym_name kernel8 * variable using Hardware Breakpoint register. The corresponding handler which9 * prints a backtrace is invoked every time a write operation is performed on10 * that variable.11 *12 * Copyright (C) IBM Corporation, 200913 *14 * Author: K.Prasad <prasad@linux.vnet.ibm.com>15 */16#include <linux/module.h> /* Needed by all modules */17#include <linux/kernel.h> /* Needed for KERN_INFO */18#include <linux/init.h> /* Needed for the macros */19#include <linux/kallsyms.h>20 21#include <linux/perf_event.h>22#include <linux/hw_breakpoint.h>23 24static struct perf_event * __percpu *sample_hbp;25 26static char ksym_name[KSYM_NAME_LEN] = "jiffies";27module_param_string(ksym, ksym_name, KSYM_NAME_LEN, S_IRUGO);28MODULE_PARM_DESC(ksym, "Kernel symbol to monitor; this module will report any"29 " write operations on the kernel symbol");30 31static void sample_hbp_handler(struct perf_event *bp,32 struct perf_sample_data *data,33 struct pt_regs *regs)34{35 printk(KERN_INFO "%s value is changed\n", ksym_name);36 dump_stack();37 printk(KERN_INFO "Dump stack from sample_hbp_handler\n");38}39 40static int __init hw_break_module_init(void)41{42 int ret;43 struct perf_event_attr attr;44 void *addr = __symbol_get(ksym_name);45 46 if (!addr)47 return -ENXIO;48 49 hw_breakpoint_init(&attr);50 attr.bp_addr = (unsigned long)addr;51 attr.bp_len = HW_BREAKPOINT_LEN_4;52 attr.bp_type = HW_BREAKPOINT_W;53 54 sample_hbp = register_wide_hw_breakpoint(&attr, sample_hbp_handler, NULL);55 if (IS_ERR((void __force *)sample_hbp)) {56 ret = PTR_ERR((void __force *)sample_hbp);57 goto fail;58 }59 60 printk(KERN_INFO "HW Breakpoint for %s write installed\n", ksym_name);61 62 return 0;63 64fail:65 printk(KERN_INFO "Breakpoint registration failed\n");66 67 return ret;68}69 70static void __exit hw_break_module_exit(void)71{72 unregister_wide_hw_breakpoint(sample_hbp);73#ifdef CONFIG_MODULE_UNLOAD74 __symbol_put(ksym_name);75#endif76 printk(KERN_INFO "HW Breakpoint for %s write uninstalled\n", ksym_name);77}78 79module_init(hw_break_module_init);80module_exit(hw_break_module_exit);81 82MODULE_LICENSE("GPL");83MODULE_AUTHOR("K.Prasad");84MODULE_DESCRIPTION("ksym breakpoint");85