From nobody Thu Dec 18 22:14:38 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 38DA4214A71; Wed, 19 Mar 2025 21:38:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1742420303; cv=none; b=tTjNCyVy9J+ZKsaie8QeaM9m6vvbaF3vdsDhffxuyLVTOUoObxK6TgmQsIu/PcWU7usmF58jWq8agL1k8yYR9Gw46cc+6/AvWK31DjfL9f/5yV3UqGL07hhoBrZrf8xYyuQr5MsAVZ52tUZaOJEoou1ZLqO17fXYLCMlH80xzXc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1742420303; c=relaxed/simple; bh=b3782zZ5mBpEsCfIXFJrh0cYSGOEO7W0tZltv4hR2Nc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=YGCXKKpLVVqh7Dapjb0yaOp4dMnLNZx3VvBE216HC9t68kQEIPM9LuGBkQ+zKmRdnQPDJi/08twuboHoP3wNvSAOvZjOP+rYoFQXTzM4/WHXFLS/sVaJ3zVhELlcVE8SxAwdFGgZjJGth6avaXPRRK3/3Q1YruNJhwiQxWx4vwo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=mStctrl4; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="mStctrl4" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 916A1C4CEE4; Wed, 19 Mar 2025 21:38:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1742420302; bh=b3782zZ5mBpEsCfIXFJrh0cYSGOEO7W0tZltv4hR2Nc=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=mStctrl4lCekO+dl4eagJSdNZV+kqYM0f2br1RCNNeQ6eL6KdLcOcmjN69tpdcaH7 MMDyUZp247ok/3MkHxdlyi3gRqsSHYYbN0iTB8PFQTJbtePINQI8e/HkDu3nrbrD/G cgZMw1pgCRnKR/sy+OFlG5tPHOFD2RnjFEr+Cg/KPI/DckAO3Ek6jV/YlGBnztW3hF CgAj+oxGXMU763ZurWS7xPS5Ht+pQ+43068p8Jmpvhw+UnI0wrVaZz1nlGY28nr1G7 2U2cJusDE+dkBWVSvQ31gqSI5omBkJ0cDsqNqrKzKhRwNJuCOtmHkAtyzNxLVUIzwB zFJvFb2aFzQBw== From: Song Liu To: linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, linux-toolchains@vger.kernel.org, live-patching@vger.kernel.org Cc: indu.bhagat@oracle.com, puranjay@kernel.org, wnliu@google.com, irogers@google.com, joe.lawrence@redhat.com, jpoimboe@kernel.org, mark.rutland@arm.com, peterz@infradead.org, roman.gushchin@linux.dev, rostedt@goodmis.org, will@kernel.org, kernel-team@meta.com, song@kernel.org Subject: [PATCH v2 1/2] arm64: Implement arch_stack_walk_reliable Date: Wed, 19 Mar 2025 14:37:06 -0700 Message-ID: <20250319213707.1784775-2-song@kernel.org> X-Mailer: git-send-email 2.47.1 In-Reply-To: <20250319213707.1784775-1-song@kernel.org> References: <20250319213707.1784775-1-song@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" With proper exception boundary detection, it is possible to implment arch_stack_walk_reliable without sframe. Note that, arch_stack_walk_reliable does not guarantee getting reliable stack in all scenarios. Instead, it can reliably detect when the stack trace is not reliable, which is enough to provide reliable livepatching. Signed-off-by: Song Liu --- arch/arm64/Kconfig | 2 +- arch/arm64/kernel/stacktrace.c | 70 ++++++++++++++++++++++++++-------- 2 files changed, 55 insertions(+), 17 deletions(-) diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index 940343beb3d4..ed4f7bf4a879 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -275,6 +275,7 @@ config ARM64 select HAVE_SOFTIRQ_ON_OWN_STACK select USER_STACKTRACE_SUPPORT select VDSO_GETRANDOM + select HAVE_RELIABLE_STACKTRACE help ARM 64-bit (AArch64) Linux support. =20 @@ -2499,4 +2500,3 @@ endmenu # "CPU Power Management" source "drivers/acpi/Kconfig" =20 source "arch/arm64/kvm/Kconfig" - diff --git a/arch/arm64/kernel/stacktrace.c b/arch/arm64/kernel/stacktrace.c index 1d9d51d7627f..b0489aad5897 100644 --- a/arch/arm64/kernel/stacktrace.c +++ b/arch/arm64/kernel/stacktrace.c @@ -56,6 +56,7 @@ struct kunwind_state { enum kunwind_source source; union unwind_flags flags; struct pt_regs *regs; + bool end_on_unreliable; }; =20 static __always_inline void @@ -230,8 +231,26 @@ kunwind_next_frame_record(struct kunwind_state *state) new_fp =3D READ_ONCE(record->fp); new_pc =3D READ_ONCE(record->lr); =20 - if (!new_fp && !new_pc) - return kunwind_next_frame_record_meta(state); + if (!new_fp && !new_pc) { + int ret; + + ret =3D kunwind_next_frame_record_meta(state); + if (ret < 0) { + /* + * This covers two different conditions: + * 1. ret =3D=3D -ENOENT, unwinding is done. + * 2. ret =3D=3D -EINVAL, unwinding hit error. + */ + return ret; + } + /* + * Searching across exception boundaries. The stack is now + * unreliable. + */ + if (state->end_on_unreliable) + return -EINVAL; + return 0; + } =20 unwind_consume_stack(&state->common, info, fp, sizeof(*record)); =20 @@ -277,21 +296,24 @@ kunwind_next(struct kunwind_state *state) =20 typedef bool (*kunwind_consume_fn)(const struct kunwind_state *state, void= *cookie); =20 -static __always_inline void +static __always_inline int do_kunwind(struct kunwind_state *state, kunwind_consume_fn consume_state, void *cookie) { - if (kunwind_recover_return_address(state)) - return; + int ret; =20 - while (1) { - int ret; + ret =3D kunwind_recover_return_address(state); + if (ret) + return ret; =20 + while (1) { if (!consume_state(state, cookie)) - break; + return -EINVAL; ret =3D kunwind_next(state); + if (ret =3D=3D -ENOENT) + return 0; if (ret < 0) - break; + return ret; } } =20 @@ -324,10 +346,10 @@ do_kunwind(struct kunwind_state *state, kunwind_consu= me_fn consume_state, : stackinfo_get_unknown(); \ }) =20 -static __always_inline void +static __always_inline int kunwind_stack_walk(kunwind_consume_fn consume_state, void *cookie, struct task_struct *task, - struct pt_regs *regs) + struct pt_regs *regs, bool end_on_unreliable) { struct stack_info stacks[] =3D { stackinfo_get_task(task), @@ -348,11 +370,12 @@ kunwind_stack_walk(kunwind_consume_fn consume_state, .stacks =3D stacks, .nr_stacks =3D ARRAY_SIZE(stacks), }, + .end_on_unreliable =3D end_on_unreliable, }; =20 if (regs) { if (task !=3D current) - return; + return -EINVAL; kunwind_init_from_regs(&state, regs); } else if (task =3D=3D current) { kunwind_init_from_caller(&state); @@ -360,7 +383,7 @@ kunwind_stack_walk(kunwind_consume_fn consume_state, kunwind_init_from_task(&state, task); } =20 - do_kunwind(&state, consume_state, cookie); + return do_kunwind(&state, consume_state, cookie); } =20 struct kunwind_consume_entry_data { @@ -384,7 +407,22 @@ noinline noinstr void arch_stack_walk(stack_trace_cons= ume_fn consume_entry, .cookie =3D cookie, }; =20 - kunwind_stack_walk(arch_kunwind_consume_entry, &data, task, regs); + kunwind_stack_walk(arch_kunwind_consume_entry, &data, task, regs, false); +} + +noinline noinstr int arch_stack_walk_reliable(stack_trace_consume_fn consu= me_entry, + void *cookie, struct task_struct *task) +{ + struct kunwind_consume_entry_data data =3D { + .consume_entry =3D consume_entry, + .cookie =3D cookie, + }; + int ret; + + ret =3D kunwind_stack_walk(arch_kunwind_consume_entry, &data, task, NULL,= true); + if (ret =3D=3D -ENOENT) + ret =3D 0; + return ret; } =20 struct bpf_unwind_consume_entry_data { @@ -409,7 +447,7 @@ noinline noinstr void arch_bpf_stack_walk(bool (*consum= e_entry)(void *cookie, u6 .cookie =3D cookie, }; =20 - kunwind_stack_walk(arch_bpf_unwind_consume_entry, &data, current, NULL); + kunwind_stack_walk(arch_bpf_unwind_consume_entry, &data, current, NULL, f= alse); } =20 static const char *state_source_string(const struct kunwind_state *state) @@ -456,7 +494,7 @@ void dump_backtrace(struct pt_regs *regs, struct task_s= truct *tsk, return; =20 printk("%sCall trace:\n", loglvl); - kunwind_stack_walk(dump_backtrace_entry, (void *)loglvl, tsk, regs); + kunwind_stack_walk(dump_backtrace_entry, (void *)loglvl, tsk, regs, false= ); =20 put_task_stack(tsk); } --=20 2.47.1 From nobody Thu Dec 18 22:14:38 2025 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D3B07214A71; Wed, 19 Mar 2025 21:38:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1742420309; cv=none; b=AJvsagZr68dp4Znv302g6iV1mNFVgXDETeRVy8s1Nf2b/60hgKlEW+1uAh2vR7OOLbdbqlyPaEuGjqnDrUxS5tnTk93soSQDlb+8jTWUzbQ1KqrMa12E83MPPXezUhlcet9vELkHLOIlCIqu0XNyIERCPUktdwg0a87D1FGxtIQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1742420309; c=relaxed/simple; bh=FwNROOBiRQdLC4LMY0dNrjEMqI1FlzLJowVkMOHTQnk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Yr7RfQG7Vv2+5g9TAx+9Qq+DywLSECLMUfncZLh5sAVEn51cVLDp8N7gdBOmSOcLL6SStLZufr0UpbAb2Uq6CSKGXvkfT1dk/cJCcA20y7BbMYLFYhf3QUYTmVm1v30KdwtguoJ1JfwkdBXvGI7WhgrfUN6j1ld2g+DMTm23G7Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=XTzRGgYg; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="XTzRGgYg" Received: by smtp.kernel.org (Postfix) with ESMTPSA id DB78CC4CEE4; Wed, 19 Mar 2025 21:38:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1742420309; bh=FwNROOBiRQdLC4LMY0dNrjEMqI1FlzLJowVkMOHTQnk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=XTzRGgYgUiM7dDAuU0PP/o/gxpWPk5nrU+ZcqlHgsz+v+XhA8Ul8QPhPN6JhlnZ9j am/lMjA0Ckj/odltOGkGav5L28oqNWF0DEVA8CmnGuUrUEA8G68GAvFHL1pep11xgB g1CDS6xvYGBN+KivygRYRr5+YgBsuWDX57mevLtXFQXA6R5+42vo+shrhO0HvJly3G /Oukcx+7KhM2haG6oCR1xPfrrSmSLc7kjC2MpvyYwgQczDnOFFBIosYJqsOGmT9yOu OZS8nub6nbGdm5HuoX8E4Vpt1mZ4u74hTdQUs+7rCDeXGOtC1DGZ9k/H7A63Aje/nT ZDTyVfVUQE50A== From: Song Liu To: linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, linux-toolchains@vger.kernel.org, live-patching@vger.kernel.org Cc: indu.bhagat@oracle.com, puranjay@kernel.org, wnliu@google.com, irogers@google.com, joe.lawrence@redhat.com, jpoimboe@kernel.org, mark.rutland@arm.com, peterz@infradead.org, roman.gushchin@linux.dev, rostedt@goodmis.org, will@kernel.org, kernel-team@meta.com, song@kernel.org, Suraj Jitindar Singh , Torsten Duwe Subject: [PATCH v2 2/2] arm64: Implement HAVE_LIVEPATCH Date: Wed, 19 Mar 2025 14:37:07 -0700 Message-ID: <20250319213707.1784775-3-song@kernel.org> X-Mailer: git-send-email 2.47.1 In-Reply-To: <20250319213707.1784775-1-song@kernel.org> References: <20250319213707.1784775-1-song@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This is largely based on [1] by Suraj Jitindar Singh. Test coverage: - Passed manual tests with samples/livepatch. - Passed all but test-kprobe.sh in selftests/livepatch. test-kprobe.sh is expected to fail, because arm64 doesn't have KPROBES_ON_FTRACE. - Passed tests with kpatch-build [2]. (This version includes commits that are not merged to upstream kpatch yet). [1] https://lore.kernel.org/all/20210604235930.603-1-surajjs@amazon.com/ [2] https://github.com/liu-song-6/kpatch/tree/fb-6.13 Cc: Suraj Jitindar Singh Cc: Torsten Duwe Signed-off-by: Song Liu --- arch/arm64/Kconfig | 3 +++ arch/arm64/include/asm/thread_info.h | 4 +++- arch/arm64/kernel/entry-common.c | 4 ++++ 3 files changed, 10 insertions(+), 1 deletion(-) diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index ed4f7bf4a879..bc9edba6171a 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -276,6 +276,7 @@ config ARM64 select USER_STACKTRACE_SUPPORT select VDSO_GETRANDOM select HAVE_RELIABLE_STACKTRACE + select HAVE_LIVEPATCH help ARM 64-bit (AArch64) Linux support. =20 @@ -2500,3 +2501,5 @@ endmenu # "CPU Power Management" source "drivers/acpi/Kconfig" =20 source "arch/arm64/kvm/Kconfig" + +source "kernel/livepatch/Kconfig" diff --git a/arch/arm64/include/asm/thread_info.h b/arch/arm64/include/asm/= thread_info.h index 1114c1c3300a..4ac42e13032b 100644 --- a/arch/arm64/include/asm/thread_info.h +++ b/arch/arm64/include/asm/thread_info.h @@ -64,6 +64,7 @@ void arch_setup_new_exec(void); #define TIF_UPROBE 4 /* uprobe breakpoint or singlestep */ #define TIF_MTE_ASYNC_FAULT 5 /* MTE Asynchronous Tag Check Fault */ #define TIF_NOTIFY_SIGNAL 6 /* signal notifications exist */ +#define TIF_PATCH_PENDING 7 /* pending live patching update */ #define TIF_SYSCALL_TRACE 8 /* syscall trace active */ #define TIF_SYSCALL_AUDIT 9 /* syscall auditing */ #define TIF_SYSCALL_TRACEPOINT 10 /* syscall tracepoint for ftrace */ @@ -92,6 +93,7 @@ void arch_setup_new_exec(void); #define _TIF_SYSCALL_TRACEPOINT (1 << TIF_SYSCALL_TRACEPOINT) #define _TIF_SECCOMP (1 << TIF_SECCOMP) #define _TIF_SYSCALL_EMU (1 << TIF_SYSCALL_EMU) +#define _TIF_PATCH_PENDING (1 << TIF_PATCH_PENDING) #define _TIF_UPROBE (1 << TIF_UPROBE) #define _TIF_SINGLESTEP (1 << TIF_SINGLESTEP) #define _TIF_32BIT (1 << TIF_32BIT) @@ -103,7 +105,7 @@ void arch_setup_new_exec(void); #define _TIF_WORK_MASK (_TIF_NEED_RESCHED | _TIF_SIGPENDING | \ _TIF_NOTIFY_RESUME | _TIF_FOREIGN_FPSTATE | \ _TIF_UPROBE | _TIF_MTE_ASYNC_FAULT | \ - _TIF_NOTIFY_SIGNAL) + _TIF_NOTIFY_SIGNAL | _TIF_PATCH_PENDING) =20 #define _TIF_SYSCALL_WORK (_TIF_SYSCALL_TRACE | _TIF_SYSCALL_AUDIT | \ _TIF_SYSCALL_TRACEPOINT | _TIF_SECCOMP | \ diff --git a/arch/arm64/kernel/entry-common.c b/arch/arm64/kernel/entry-com= mon.c index b260ddc4d3e9..b537af333b42 100644 --- a/arch/arm64/kernel/entry-common.c +++ b/arch/arm64/kernel/entry-common.c @@ -8,6 +8,7 @@ #include #include #include +#include #include #include #include @@ -144,6 +145,9 @@ static void do_notify_resume(struct pt_regs *regs, unsi= gned long thread_flags) (void __user *)NULL, current); } =20 + if (thread_flags & _TIF_PATCH_PENDING) + klp_update_patch_state(current); + if (thread_flags & (_TIF_SIGPENDING | _TIF_NOTIFY_SIGNAL)) do_signal(regs); =20 --=20 2.47.1