Manpage of INIT_MODULE

INIT_MODULE

Section: Linux Programmer's Manual (2)
Updated: 2016-03-15
Index
 

NAME

init_module, finit_module - load a kernel module  

SYNOPSIS

int init_module(void *module_image, unsigned long len,                const char *param_values);int finit_module(int fd, const char *param_values,                 int flags);

Note: glibc provides no header file declaration of init_module() and no wrapper function for finit_module(); see NOTES.  

DESCRIPTION

init_module() loads an ELF image into kernel space, performs any necessary symbol relocations, initializes module parameters to values provided by the caller, and then runs the module's initfunction. This system call requires privilege.

The module_imageargument points to a buffer containing the binary image to be loaded; lenspecifies the size of that buffer. The module image should be a valid ELF image, built for the running kernel.

The param_valuesargument is a string containing space-delimited specifications of the values for module parameters (defined inside the module using module_param() and module_param_array()). The kernel parses this string and initializes the specified parameters. Each of the parameter specifications has the form:

name[=value[,value...]]

The parameter nameis one of those defined within the module using module_param() (see the Linux kernel source file include/linux/moduleparam.h). The parameter valueis optional in the case of booland invboolparameters. Values for array parameters are specified as a comma-separated list.  

finit_module()

The finit_module() system call is like init_module(), but reads the module to be loaded from the file descriptor fd. It is useful when the authenticity of a kernel module can be determined from its location in the filesystem; in cases where that is possible, the overhead of using cryptographically signed modules to determine the authenticity of a module can be avoided. The param_valuesargument is as for init_module().

The flagsargument modifies the operation of finit_module(). It is a bit mask value created by ORing together zero or more of the following flags:

MODULE_INIT_IGNORE_MODVERSIONS
Ignore symbol version hashes.
MODULE_INIT_IGNORE_VERMAGIC
Ignore kernel version magic.

There are some safety checks built into a module to ensure that it matches the kernel against which it is loaded. These checks are recorded when the module is built and verified when the module is loaded. First, the module records a "vermagic" string containing the kernel version number and prominent features (such as the CPU type). Second, if the module was built with the CONFIG_MODVERSIONSconfiguration option enabled, a version hash is recorded for each symbol the module uses. This hash is based on the types of the arguments and return value for the function named by the symbol. In this case, the kernel version number within the "vermagic" string is ignored, as the symbol version hashes are assumed to be sufficiently reliable.

Using the MODULE_INIT_IGNORE_VERMAGICflag indicates that the "vermagic" string is to be ignored, and the MODULE_INIT_IGNORE_MODVERSIONSflag indicates that the symbol version hashes are to be ignored. If the kernel is built to permit forced loading (i.e., configured with CONFIG_MODULE_FORCE_LOAD), then loading will continue, otherwise it will fail with ENOEXECas expected for malformed modules.  

RETURN VALUE

On success, these system calls return 0. On error, -1 is returned and errnois set appropriately.  

ERRORS

EBADMSG (since Linux 3.7)
Module signature is misformatted.
EBUSY
Timeout while trying to resolve a symbol reference by this module.
EFAULT
An address argument referred to a location that is outside the process's accessible address space.
ENOKEY (since Linux 3.7)
Module signature is invalid or the kernel does not have a key for this module. This error is returned only if the kernel was configured with CONFIG_MODULE_SIG_FORCE; if the kernel was not configured with this option, then an invalid or unsigned module simply taints the kernel.
ENOMEM
Out of memory.
EPERM
The caller was not privileged (did not have the CAP_SYS_MODULEcapability), or module loading is disabled (see /proc/sys/kernel/modules_disabledin proc(5)).

The following errors may additionally occur for init_module():

EEXIST
A module with this name is already loaded.
EINVAL
param_valuesis invalid, or some part of the ELF image in module_imagecontains inconsistencies.
ENOEXEC
The binary image supplied in module_imageis not an ELF image, or is an ELF image that is invalid or for a different architecture.

The following errors may additionally occur for finit_module():

EBADF
The file referred to by fdis not opened for reading.
EFBIG
The file referred to by fdis too large.
EINVAL
flagsis invalid.
ENOEXEC
fddoes not refer to an open file.

In addition to the above errors, if the module's initfunction is executed and returns an error, then init_module() or finit_module() fails and errnois set to the value returned by the initfunction.  

VERSIONS

finit_module() is available since Linux 3.8.  

CONFORMING TO

init_module() and finit_module() are Linux-specific.  

NOTES

The init_module() system call is not supported by glibc. No declaration is provided in glibc headers, but, through a quirk of history, glibc versions before 2.23 did export an ABI for this system call. Therefore, in order to employ this system call, it is (before glibc 2.23) sufficient to manually declare the interface in your code; alternatively, you can invoke the system call using syscall(2).

Glibc does not provide a wrapper for finit_module(); call it using syscall(2).

Information about currently loaded modules can be found in /proc/modulesand in the file trees under the per-module subdirectories under /sys/module.

See the Linux kernel source file include/linux/module.hfor some useful background information.  

Linux 2.4 and earlier

In Linux 2.4 and earlier, the init_module() system call was rather different:

#include <linux/module.h>

int init_module(const char *name, struct module *image);

(User-space applications can detect which version of init_module() is available by calling query_module(); the latter call fails with the error ENOSYSon Linux 2.6 and later.)

The older version of the system call loads the relocated module image pointed to by imageinto kernel space and runs the module's initfunction. The caller is responsible for providing the relocated image (since Linux 2.6, the init_module() system call does the relocation).

The module image begins with a module structure and is followed by code and data as appropriate. Since Linux 2.2, the module structure is defined as follows:

struct module {
    unsigned long         size_of_struct;
    struct module        *next;
    const char           *name;
    unsigned long         size;
    long                  usecount;
    unsigned long         flags;
    unsigned int          nsyms;
    unsigned int          ndeps;
    struct module_symbol *syms;
    struct module_ref    *deps;
    struct module_ref    *refs;
    int                 (*init)(void);
    void                (*cleanup)(void);
    const struct exception_table_entry *ex_table_start;
    const struct exception_table_entry *ex_table_end;
#ifdef __alpha__
    unsigned long gp;
#endif
};

All of the pointer fields, with the exception of nextand refs, are expected to point within the module body and be initialized as appropriate for kernel space, that is, relocated with the rest of the module.  

SEE ALSO

create_module(2), delete_module(2), query_module(2), lsmod(8), modprobe(8)


 

Index

NAME
SYNOPSIS
DESCRIPTION
finit_module()
RETURN VALUE
ERRORS
VERSIONS
CONFORMING TO
NOTES
Linux 2.4 and earlier
SEE ALSO

This document was created by man2html, using the manual pages.
Time: 16:30:05 GMT, December 12, 2016 Click Here!