I am trying to create a system call inside of the Linux kernel.
This code fails, I am assuming its because msg is a virtual address passed by the program, but I am unsure of how to convert it.
SYSCALL_DEFINE2(strrevlog, const char __user *, msg, unsigned long, msglen)
{
char *str = kmalloc(msglen + 1, GFP_KERNEL);
for (size_t i = 0; i < msglen; i++) {
str[i] = msg[msglen - i - 1];
}
str[msglen] = 0;
printk(str);
kfree(str);
return 0;
}
I wrote a program that uses this systemcall, but it just prints Killed, here is the dmesg output:
[ 1060.314268] BUG: unable to handle page fault for address: 0000000000402004
[ 1060.314276] #PF: supervisor read access in kernel mode
[ 1060.314282] #PF: error_code(0x0001) - permissions violation
[ 1060.314288] PGD 80000001fba20067 P4D 80000001fba20067 PUD 1a60be067 PMD 1b9f11067 PTE 8000000153e82025
[ 1060.314304] Oops: 0001 [#3] PREEMPT SMP PTI
[ 1060.314313] CPU: 5 PID: 15133 Comm: a.out Tainted: P D OE 5.18.0+ #19
[ 1060.314323] Hardware name: HP HP ENVY Desktop/83C1, BIOS F.02 08/14/2017
[ 1060.314328] RIP: 0010:__do_sys_strrevlog+0x45/0x62
[ 1060.314342] Code: 31 22 d5 aa 48 89 c3 48 89 c6 e8 d4 27 38 00 48 89 da 4c 89 e6 48 c7 c7 46 22 d5 aa e8 c2 27 38 00 48 89 df 4c 89 e6 48 89 e9 <f3> a4 c6 04 2b 00 48 89 df e8 ab 27 38 00 48 89 df e8 1b 7b e6 ff
[ 1060.314350] RSP: 0018:ffffa95b06ac7f20 EFLAGS: 00010246
[ 1060.314357] RAX: 000000000000001a RBX: ffff94e0425c7b38 RCX: 0000000000000005
[ 1060.314363] RDX: 0000000000000000 RSI: 0000000000402004 RDI: ffff94e0425c7b38
[ 1060.314369] RBP: 0000000000000005 R08: 0000000000000000 R09: 206f742072747320
[ 1060.314374] R10: 3065343966666666 R11: 3833623763353261 R12: 0000000000402004
[ 1060.314379] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[ 1060.314384] FS: 00007efe16049540(0000) GS:ffff94e39ed40000(0000) knlGS:0000000000000000
[ 1060.314392] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1060.314398] CR2: 0000000000402004 CR3: 00000001cd272002 CR4: 00000000003706e0
[ 1060.314403] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 1060.314407] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[ 1060.314412] Call Trace:
[ 1060.314419] <TASK>
[ 1060.314426] do_syscall_64+0x6b/0x7d
[ 1060.314440] entry_SYSCALL_64_after_hwframe+0x44/0xae
[ 1060.314450] RIP: 0033:0x7efe15f7b9b9
[ 1060.314457] Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d a7 54 0c 00 f7 d8 64 89 01 48
[ 1060.314464] RSP: 002b:00007ffeae94b138 EFLAGS: 00000202 ORIG_RAX: 0000000000000225
[ 1060.314472] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007efe15f7b9b9
[ 1060.314478] RDX: 0000000000000004 RSI: 0000000000000005 RDI: 0000000000402004
[ 1060.314482] RBP: 00007ffeae94b150 R08: 0000000000000009 R09: 00007ffeae94b240
[ 1060.314487] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000401060
[ 1060.314492] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[ 1060.314502] </TASK>
[ 1060.314505] Modules linked in: ctr(E) ccm(E) rfcomm(E) cmac(E) algif_hash(E) algif_skcipher(E) af_alg(E) bnep(E) btusb(E) btrtl(E) btbcm(E) btintel(E) bluetooth(E) jitterentropy_rng(E) sha512_ssse3(E) sha512_generic(E) snd_usb_audio(E) sd_mod(E) snd_usbmidi_lib(E) sg(E) snd_rawmidi(E) drbg(E) snd_seq_device(E) ansi_cprng(E) joydev(E) mc(E) ecdh_generic(E) ecc(E) intel_rapl_msr(E) intel_rapl_common(E) x86_pkg_temp_thermal(E) intel_powerclamp(E) 8821ce(OE) coretemp(E) crct10dif_pclmul(E) crc32_pclmul(E) rtw88_8821ce(E) rtw88_8821c(E) rtw88_pci(E) rtw88_core(E) nvidia_drm(POE) ghash_clmulni_intel(E) mac80211(E) libarc4(E) snd_hda_codec_hdmi(E) snd_hda_codec_realtek(E) snd_hda_codec_generic(E) ledtrig_audio(E) drm_kms_helper(E) fb_sys_fops(E) syscopyarea(E) sysfillrect(E) sysimgblt(E) aesni_intel(E) libaes(E) crypto_simd(E) cryptd(E) snd_hda_intel(E) snd_intel_dspcfg(E) nvidia_modeset(POE) rapl(E) snd_hda_codec(E) intel_cstate(E) snd_hda_core(E) intel_uncore(E) nls_ascii(E) snd_hwdep(E)
[ 1060.314639] pcspkr(E) snd_pcm(E) cfg80211(E) hp_wmi(E) nls_cp437(E) platform_profile(E) sparse_keymap(E) serio_raw(E) wmi_bmof(E) efi_pstore(E) snd_timer(E) snd(E) rfkill(E) soundcore(E) tpm_crb(E) tpm_tis(E) tpm_tis_core(E) tpm(E) rng_core(E) intel_pmc_core(E) acpi_pad(E) evdev(E) nvidia(POE) msr(E) drm(E) fuse(E) configfs(E) efivarfs(E) ip_tables(E) x_tables(E) autofs4(E) ums_realtek(E) uas(E) usb_storage(E) hid_generic(E) usbhid(E) hid(E) ahci(E) libahci(E) r8169(E) crc32c_intel(E) xhci_pci(E) libata(E) i2c_i801(E) realtek(E) psmouse(E) xhci_hcd(E) mdio_devres(E) i2c_smbus(E) scsi_mod(E) libphy(E) scsi_common(E) usbcore(E) usb_common(E) fan(E) wmi(E) video(E) button(E)
[ 1060.314755] CR2: 0000000000402004
[ 1060.314761] ---[ end trace 0000000000000000 ]---
[ 1060.420729] RIP: 0010:__do_sys_strrevlog+0x45/0x62
[ 1060.420748] Code: 31 22 d5 aa 48 89 c3 48 89 c6 e8 d4 27 38 00 48 89 da 4c 89 e6 48 c7 c7 46 22 d5 aa e8 c2 27 38 00 48 89 df 4c 89 e6 48 89 e9 <f3> a4 c6 04 2b 00 48 89 df e8 ab 27 38 00 48 89 df e8 1b 7b e6 ff
[ 1060.420750] RSP: 0018:ffffa95b01e53f20 EFLAGS: 00010246
[ 1060.420752] RAX: 000000000000001a RBX: ffff94e0425c7fa0 RCX: 0000000000000005
[ 1060.420753] RDX: 0000000000000000 RSI: 0000000000402004 RDI: ffff94e0425c7fa0
[ 1060.420754] RBP: 0000000000000005 R08: 0000000000000000 R09: ffffffffab054df0
[ 1060.420755] R10: 00007fffffffffff R11: ffffffffab7f801a R12: 0000000000402004
[ 1060.420756] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000
[ 1060.420757] FS: 00007efe16049540(0000) GS:ffff94e39ed40000(0000) knlGS:0000000000000000
[ 1060.420759] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 1060.420760] CR2: 0000000000402004 CR3: 00000001cd272002 CR4: 00000000003706e0
[ 1060.420761] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 1060.420762] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400