From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D9DE274FDF; Sat, 8 Aug 2026 23:18:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231097; cv=none; b=aTo0ml2wN5iOIeyRs3rGWJHX+JZKVJ0hAX1IMLAqBCc1yp2aEnUKViu4RHjTTadXUlbmQb08lhCsq8F1npuOC1+cEWwdLFCecVU/8pJFxEvKBNI0948+PeikbILLr8RTCyuqRl/q2+sfJbxijCEONZ/4cHvY0JqkVP5VUC0JAic= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231097; c=relaxed/simple; bh=5TvAEjJ0vEgTad93AWEUV6JQbHkseHkHYTqDVQaJeJQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VM2S6a02vIgi570bQBQdr7PSRrQ/sx1F3sSeXZPKrBVcuy7vf3SsOs2KiumAHLTN7TuEC4EA8Aumhzq8rd5LXOX42MMrizYygRR7zo5i8fY4l7Qec5kI/69jgBG8AymtLGVkOCKaNQilSLsszu0Ady75+xgBhhvvqhHC2H2D0fo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=dA4CAKDW; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="dA4CAKDW" Received: by smtp.kernel.org (Postfix) with ESMTPSA id B76571F00ACF; Sat, 8 Aug 2026 23:18:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231096; bh=BARDdhFoahQ9F/MLiUXn4Su4t2tJaLiVM0v0FWkHGjU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=dA4CAKDWmEN732KykWiAq94Sk+BCn9L3T1KcjWyeqRnA0qDhLVaP5EUXE4h6pIGxF Tih0eNcjb+FqL7zo5hGK6y+KrHueKdAACyKp+IV/Cjwlhpr28pIMx4371XdDqOltXN JJnufDKpBGBqlTjtuvSWSKmjIpGkv0XCCGkGuR7DHi4fZEN6FKyfNB441dtewfZ5nP 1WntBAma9kt/sjLQ7cai/x6c7/Gl0W4XrEYhmSy0Jonsm6qnsxL9P/aT6ADIR43Cxx CzaqsHFG64QDxOA7lajCxR5CUPJ3NDc5BO5/Xe3BGWmMfn6spQfYZaQAe54JTbn2Er EtKrpPbUTHjkg== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 01/22] objtool/klp: Fix .kcfi_traps special section extraction Date: Sat, 8 Aug 2026 16:17:05 -0700 Message-ID: <8faaead205b219607b6fc2359ae743be824056eb.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" create_fake_symbols() creates a symbol per entry for special sections. It does so in two steps: first for the sections which have ANNOTATE_DATA_SPECIAL annotations, then for the rest, using entsize or the reloc count to infer the entry size. The second step skips the sections already handled by the first one by looking for a symbol at offset 0. That heuristic is too fuzzy: with Clang and CONFIG_CFI, it misfires on .kcfi_traps because Clang emits a .Ltmp* assembler-local label at the start of the section, so no symbols are created and clone_special_sections() extracts nothing. klp-build still reports SUCCESS, but the livepatch module has no __kcfi_traps section and the traps for the patched functions are lost. Look for the actual fake symbols created by the first step instead. Fixes: da4326573ae8d ("objtool/klp: Fix kCFI trap handling") Reported-by: Joe Lawrence Closes: https://lore.kernel.org/r/akQNqlfFC0T5pcMa@redhat.com Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/include/objtool/elf.h | 1 + tools/objtool/klp-diff.c | 26 ++++++++++++++++++++++++-- 2 files changed, 25 insertions(+), 2 deletions(-) diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index d9c44df9cc76a..a82517a76a0f6 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -97,6 +97,7 @@ struct symbol { u8 included : 1; u8 klp : 1; u8 dont_correlate : 1; + u8 fake : 1; struct list_head pv_target; struct reloc *relocs; struct section *group_sec; diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index b6b72ed71bf02..890de34d1fa27 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -1629,6 +1629,7 @@ static int create_fake_symbol(struct elf *elf, struct= section *sec, unsigned long offset, size_t size) { char name[SYM_NAME_LEN]; + struct symbol *sym; unsigned int type; static int ctr; char *c; @@ -1645,7 +1646,24 @@ static int create_fake_symbol(struct elf *elf, struc= t section *sec, * while still allowing objdump to disassemble it. */ type =3D is_text_sec(sec) ? STT_NOTYPE : STT_OBJECT; - return elf_create_symbol(elf, name, sec, STB_LOCAL, type, offset, size) ?= 0 : -1; + + sym =3D elf_create_symbol(elf, name, sec, STB_LOCAL, type, offset, size); + if (!sym) + return -1; + + sym->fake =3D 1; + return 0; +} + +static bool has_fake_symbols(struct section *sec) +{ + struct symbol *sym; + + sec_for_each_sym(sec, sym) + if (sym->fake) + return true; + + return false; } =20 /* @@ -1737,7 +1755,11 @@ static int create_fake_symbols(struct elf *elf) unsigned int entry_size; unsigned long offset; =20 - if (!is_special_section(sec) || find_symbol_by_offset(sec, 0)) + if (!is_special_section(sec)) + continue; + + /* Skip sections already handled by step 1 above */ + if (has_fake_symbols(sec)) continue; =20 if (!sec->rsec) { --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 54275364EB6; Sat, 8 Aug 2026 23:18:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231098; cv=none; b=VHGLmRcNkdpkVMacHQkOL2wFAfKB5kREPVKvC3YG8YAaAqbyiHcoIq6l7HcpzvKclDwlm1b3Vhm/h6rQ0097S4BtisImFDu7frKEmbT4lBpRoNnrNVM3BrcosNNCxjwZeuSQp29R1d4rGwifZSI2YLEE72MoMEkhcoxLGY04rr8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231098; c=relaxed/simple; bh=RFcyjU6mCgm5h4w8Xta0i3O9cf9VoVPz/NERv5dcxwo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ir79Iifs4TL6lzpFy8XoWdffCcgZuEAdHKQmFXQvqAcBzTedxRa7NvIQSFjIC+xlmiMFPiCwlrnHFBphLvdpiIPVosj7DHgot1HIMFrQIpAh19ZxPfn3fPFNvuyuzMgF8S4baw8zLKCh/VR8xBtNXYZcgXjuwXIliYAFk2T6SCY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=IS5JcHGd; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="IS5JcHGd" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 769DC1F00A3A; Sat, 8 Aug 2026 23:18:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231097; bh=oyozvoBnjvSrjbOXhKp9IQG5F3ojaiPlP82IjEqib/U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=IS5JcHGdxxKfN7iks17rbx3r/JWSLEtBi45P786gDtjuKue1BGcRHzuIVpwlRMVMx 5HiUi8xZg3g6yPKzBvkJBemUv79cPcqWGxZhOKuDiaIKTH6FlN2sEInJ/sZvkuy5hL K5eGEoncdXqi+eIKmquGRsCfELrPPIl8nsfdpFm3OskfT1qmLm0kHoEtzMcXLBDFZk sVc5sgyRpqtWUod7T0BrJMOD3zBPlxWA7S5F9SMCXlf1cKjYTmEGLOU65NCycsdYcH P4k3pUi55LSO3O5UT+dKKPVzFydTNyrK0PhQKPEDqllCOG3x/3ttdhuvq646cEhJFA NDklV1Pz+ai2g== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 02/22] klp-build: Reject patches to init/*.c Date: Sat, 8 Aug 2026 16:17:06 -0700 Message-ID: <35e3cba998d143183562f76ec47d159e31424146.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" init/Makefile hard-codes -fno-function-sections and -fno-data-sections, overriding the klp-build flags needed for patch generation. Don't allow any changes to those files; being init code they aren't really patchable anyway. Acked-by: Song Liu Acked-by: Miroslav Benes Signed-off-by: Josh Poimboeuf --- scripts/livepatch/klp-build | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build index b52a8489d9f67..b311f290b1406 100755 --- a/scripts/livepatch/klp-build +++ b/scripts/livepatch/klp-build @@ -365,7 +365,7 @@ check_unsupported_patches() { =20 for file in "${files[@]}"; do case "$file" in - lib/*|*/vdso/*|*/realmode/rm/*|*.S) + lib/*|*/vdso/*|*/realmode/rm/*|init/*|*.S) die "${patch}: unsupported patch to $file" ;; esac --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CEC83383990; Sat, 8 Aug 2026 23:18:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231100; cv=none; b=d+V7wpKNWOrtT7XyBYtifYnzfn98yMOk/ueEP73ocqQlHFbYE0CB//E0BGnnY0LYDj6A1mdwFRY19YWV3wuzRtWBT6oZxCc06GiWa91bCX67QvUYhznkjRGywXS9WwF9MNfpZTXTYSXSstXeRP92Jxu4+O7g/wxYPgvvhCAWbLE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231100; c=relaxed/simple; bh=gbz/DYxJ/sJCXTm/JVO6OX9wG85Wy1PEbplpxSUYjOc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=DARLzzayJuaisV0T1yKOUpnusl/VQtjW8+6940AwF3mqont7h6pYpw2OkVTK9NyZ/ACJT+A/bUhM8I3UTz5bkXv04erCTNQT5F0WDNlcQS6SMKAKI/66P8Q6trNuHxjap2FgO5Bo3d89QgGA0ZOrQ9K7fBIq1yg4Fju++cdEWSM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=XCMIUlLz; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="XCMIUlLz" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3FF811F000E9; Sat, 8 Aug 2026 23:18:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231098; bh=y5jStvRxXhCnYlnJabnKzeT9J7k+pNzNQ0SCW4VdeUI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XCMIUlLz1Asek+LxJ+kcAPQ6aq74uNQTDC9q7nEcsLt4tESEewgyodt0rxoHbpRaX FrQ1rIUO/vnDlvHSkB3WkFQNsQT4xiTFwUh5bnF7mllDKg0mlRJaDsHt8akX2JAi+1 XbgnFgT1g6n9lKmWWGFW5+3tgA1o0/N8uW4mjpxcQuDEn4zmLY0RCgV0AfFsPr4/Y1 1g3psKhadx5/uzRuwmotee6vMKfzEBBaPfQsofTjxWP3o3R2tcOoFkMdtgL4H4Wp3C fg3DfurXXgY5fn95vjXz8FjZ899AtqA48aTQBHwgXRWMndnqxjJ88lr57mvuzTjRdI PVHSCEx8UURFw== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 03/22] arm64: Annotate intra-function calls Date: Sat, 8 Aug 2026 16:17:07 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In preparation for enabling objtool on arm64, annotate intra-function calls. Acked-by: Song Liu Reviewed-by: Miroslav Benes Signed-off-by: Josh Poimboeuf --- arch/arm64/kernel/entry.S | 2 ++ arch/arm64/kernel/proton-pack.c | 12 +++++++----- 2 files changed, 9 insertions(+), 5 deletions(-) diff --git a/arch/arm64/kernel/entry.S b/arch/arm64/kernel/entry.S index e0db14e9c843a..d4cbdfb23d733 100644 --- a/arch/arm64/kernel/entry.S +++ b/arch/arm64/kernel/entry.S @@ -10,6 +10,7 @@ #include #include #include +#include =20 #include #include @@ -705,6 +706,7 @@ alternative_else_nop_endif * entry onto the return stack and using a RET instruction to * enter the full-fat kernel vectors. */ + ANNOTATE_INTRA_FUNCTION_CALL bl 2f b . 2: diff --git a/arch/arm64/kernel/proton-pack.c b/arch/arm64/kernel/proton-pac= k.c index 7bb6553fec087..3737190ce36ec 100644 --- a/arch/arm64/kernel/proton-pack.c +++ b/arch/arm64/kernel/proton-pack.c @@ -25,6 +25,7 @@ #include #include #include +#include =20 #include #include @@ -246,11 +247,12 @@ static noinstr void qcom_link_stack_sanitisation(void) { u64 tmp; =20 - asm volatile("mov %0, x30 \n" - ".rept 16 \n" - "bl . + 4 \n" - ".endr \n" - "mov x30, %0 \n" + asm volatile("mov %0, x30 \n" + ".rept 16 \n" + ANNOTATE_INTRA_FUNCTION_CALL " \n" + "bl . + 4 \n" + ".endr \n" + "mov x30, %0 \n" : "=3D&r" (tmp)); } =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EEE9C36197D; Sat, 8 Aug 2026 23:18:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231111; cv=none; b=qK2nArPIAKR+bEfjVSoAiLTDYCl2ccAnMv4AG5Vd80RPlmyrGE5XjcQ8VJTi7tu5YULm2CrD1yTcvkwoIpfQr7ABzabN1ddmZkrxvtRa1ITds0bUf2QfhLLTJWryGnTUbRH39gOTvkJT5HK1IqU+Q1H/CvUYPv63Smog2Ufu9q4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231111; c=relaxed/simple; bh=NJjOZRlsA+ES/6neDIFawlMJMUrIfIY0o+rmpexD76w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Wb789KX+VQGepmgvjty59wg4ekK7eOuuPfU17OFiL+VEAf1tsAwjzkWQOkTadqw9zeMC2T6xxQHZ/Q6YQ/FQaJ/0ozB8EgQvQ8x5Pb87QiVWLCn9bZz455sp+SAk2fAPrsjBL+0HCKlqMbNEn03q2y9fnS4wWLi4GkyRpN5nUQE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=TLnA1aXr; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="TLnA1aXr" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AA6931F00A3A; Sat, 8 Aug 2026 23:18:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231109; bh=W9b4Bn/jCc6njmblrCdb5kz0LDKIkI3N8b9vqXSBZ44=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TLnA1aXrDS1TAiKjspJeJ5UQ5kn2WXj2kjANeHma49+w4uagHC80MPMREog7bgEX6 5iOreJWSQX5FW++X656Vqxgv4LbLKxBNr1ck+QNclsIZGefnx/2jXSbz74ftM/ZbUK WheyLyhpCPewVpA/mD60T1QtJfFSTvjBSFLvxBICEDejXHBXP7Dd7NxEurf1wUjvDX nt3tnpc5lBgAFrPAUxMlR3CpEdNbQriINpeJW2a9j2cOsa0SAkCYxWH4x85GGXGVS0 Emz1G7XBnbhseVEd7iATvLEjFhPcqvT45pvvOr+c9eIec8ZXGZkXSy11/OCAvMH0uR pQZ1QKNNOM+NA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 04/22] arm64: Fix EFI linking with -fdata-sections Date: Sat, 8 Aug 2026 16:17:08 -0700 Message-ID: <7b18edbeb7bb68f3a69b8b0bb7ede12d834ad1d9.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When building with -fdata-sections, the .init.bss section gets split up into a bunch of .init.bss. sections. Make sure they get linked into .init.data. Acked-by: Song Liu Reviewed-by: Miroslav Benes Signed-off-by: Josh Poimboeuf --- arch/arm64/kernel/vmlinux.lds.S | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/arm64/kernel/vmlinux.lds.S b/arch/arm64/kernel/vmlinux.ld= s.S index af1d720209764..91b700e20badf 100644 --- a/arch/arm64/kernel/vmlinux.lds.S +++ b/arch/arm64/kernel/vmlinux.lds.S @@ -281,7 +281,7 @@ SECTIONS INIT_CALLS CON_INITCALL INIT_RAM_FS - *(.init.altinstructions .init.bss) /* from the EFI stub */ + *(.init.altinstructions .init.bss .init.bss.*) /* from the EFI stub */ } .exit.data : { EXIT_DATA --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 778592D7BF; Sat, 8 Aug 2026 23:18:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231111; cv=none; b=N1EGVGOlbCS3p0NxShnsTvKkaIlzuGk4e0lqjGX8z0TCBTQJUV8+NLza6mZZ1ElBCsTeBGkCGsXkX4YNTo7zX3XKbYBoq4YqpEVmLMjr0scDzs0c6L6Y1hQb+tLg94eWWFqAATdwHv+6ovIKK2ffYnQnLDMwtSbPQxZ94eQ8OP0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231111; c=relaxed/simple; bh=EZhulEUeUjIh22n7R4XE6yRJ3zCVXvUK5w91EVCMNxc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MmXMu+3hK0ydaHmN1Tq7gkZns1wu7RmGsC+R503LKPu6d8w+uJj3KywiaaXOvWTUZ6i8m7XfAf9VQgHrU4BjkQrNtX6ugNhILEginQAIeP+i2kYC1U16+RAs7qWoU1y3T4v7zX+JnR7C5jlz6TSY48QfrJOre8kvwn5GdzFYJo4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=L/2Xcr9x; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="L/2Xcr9x" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C130B1F000E9; Sat, 8 Aug 2026 23:18:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231110; bh=tIcgB+tvT4EZ6BD6hvn5buiMDsNcMRKktpWUEIjKt0Q=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=L/2Xcr9xyrCYzPPKDUPzMqRo1EohSgX5ZEo2WBvWrbz8qHLfa3hRADrCObejyGDBe b6I35OxXQ7todPwPSUEN3V+sTbA0AvPp/PLri2Pc+I6XlPIpNrJaHWxejk4wVstUTk jB56reLYqppiSip9NyozScQusOUiePtfutDjJFXEVYvUhJShiL01obRgGpsnqLlyjS JDWLxW330X5kM4qRwqxZ0a8fOcsmto9l2yZa5ApsA/bKqTCHoHc/itXJNLRfTKXLp2 ZA+EN4z7jZJ12UY1ynoWn56LHBuROo/3JV4Vn+XT9Ky4F4bwzuf24YIzLBDYlGwSEo VSD3x7DoLYF5w== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 05/22] arm64: Rename TRAMP_VALIAS -> TRAMP_VALIAS_ASM in asm-offsets Date: Sat, 8 Aug 2026 16:17:09 -0700 Message-ID: <108ebf574aa6a6e244fcc225856eb845346cc3fd.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Rename the asm-offsets TRAMP_VALIAS macro to TRAMP_VALIAS_ASM, following the naming convention already used by PIE_E0_ASM and PIE_E1_ASM. This disambiguates the asm-offsets-generated constant from the C macro of the same name defined in fixmap.h and vectors.h. This is needed by a later patch which adds new includes to asm-offsets.c that would otherwise conflict with the C version. Acked-by: Song Liu Reviewed-by: Miroslav Benes Signed-off-by: Josh Poimboeuf --- arch/arm64/kernel/asm-offsets.c | 2 +- arch/arm64/kernel/entry.S | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/arch/arm64/kernel/asm-offsets.c b/arch/arm64/kernel/asm-offset= s.c index b6367ff3a49ca..44b92f582c127 100644 --- a/arch/arm64/kernel/asm-offsets.c +++ b/arch/arm64/kernel/asm-offsets.c @@ -153,7 +153,7 @@ int main(void) DEFINE(ARM64_FTR_SYSVAL, offsetof(struct arm64_ftr_reg, sys_val)); BLANK(); #ifdef CONFIG_UNMAP_KERNEL_AT_EL0 - DEFINE(TRAMP_VALIAS, TRAMP_VALIAS); + DEFINE(TRAMP_VALIAS_ASM, TRAMP_VALIAS); #endif #ifdef CONFIG_ARM_SDE_INTERFACE DEFINE(SDEI_EVENT_INTREGS, offsetof(struct sdei_registered_event, interr= upted_regs)); diff --git a/arch/arm64/kernel/entry.S b/arch/arm64/kernel/entry.S index d4cbdfb23d733..85f6305c1f568 100644 --- a/arch/arm64/kernel/entry.S +++ b/arch/arm64/kernel/entry.S @@ -102,7 +102,7 @@ .endm =20 .macro tramp_alias, dst, sym - .set .Lalias\@, TRAMP_VALIAS + \sym - .entry.tramp.text + .set .Lalias\@, TRAMP_VALIAS_ASM + \sym - .entry.tramp.text movz \dst, :abs_g2_s:.Lalias\@ movk \dst, :abs_g1_nc:.Lalias\@ movk \dst, :abs_g0_nc:.Lalias\@ @@ -626,10 +626,10 @@ SYM_CODE_END(ret_to_user) #ifdef CONFIG_QCOM_FALKOR_ERRATUM_1003 alternative_if ARM64_WORKAROUND_QCOM_FALKOR_E1003 /* ASID already in \tmp[63:48] */ - movk \tmp, #:abs_g2_nc:(TRAMP_VALIAS >> 12) - movk \tmp, #:abs_g1_nc:(TRAMP_VALIAS >> 12) + movk \tmp, #:abs_g2_nc:(TRAMP_VALIAS_ASM >> 12) + movk \tmp, #:abs_g1_nc:(TRAMP_VALIAS_ASM >> 12) /* 2MB boundary containing the vectors, so we nobble the walk cache */ - movk \tmp, #:abs_g0_nc:((TRAMP_VALIAS & ~(SZ_2M - 1)) >> 12) + movk \tmp, #:abs_g0_nc:((TRAMP_VALIAS_ASM & ~(SZ_2M - 1)) >> 12) isb tlbi vae1, \tmp dsb nsh --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8501E37F329; Sat, 8 Aug 2026 23:18:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231112; cv=none; b=RFq8ovRKuMi0zUsSnX0Z7hNAqDy3hxf7fhGQuNozTzN2HIVSWBdRGFtB7vMogr210/FjXEWm7p6RHWlOscakhrOpdkwkzN0FgS9Svw2ziW+dpa9JZKbImASTNBwxkMqECsjuGzngNcvxUeoN3t6nAwVnOSgsNmwab/PV0fBo9QI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231112; c=relaxed/simple; bh=V+eEErxQDnBBQrhyc53lBJ4dCK27mIn0A26yak3HX0M=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=BBgZ5tnByi0RDwmTgb0qWMdmzjAIHXpaPQklrZ/LJWymZeg10OLQmt9Zq1ukOI6c1t+1dugPA/qFi6mWRUSdNKVoJnFx9379NuIGMNffbiRufMEsMYBiee3wshT5S0dmVC11lmXJG5MncAkIyqdlGbAINZDWv45BxVWkKVvtgQE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=hYrYrO3G; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="hYrYrO3G" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8A2EF1F00AC4; Sat, 8 Aug 2026 23:18:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231111; bh=8IJm04E1Jx6VRBFU9vtFpV6hpK6h8wmtKkvHTJRXIIk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=hYrYrO3GWE5Ne93ezf2fcT3d/FJ+AsiTHKLc9c/ZlMmJUgtqy81RxerzfxRjoJkh7 +lMr6kZw+rwvrRFHt4ICuAbaCRhn1ZRiM4oQI9TAWCvjWWCaAOJExhZ61yp5uQmjhF EOsNiUBP2c2VTjuZjjk05cQmmuaMK5it/Apa1kuhaQoTga5+4YTTPLNEQ5hqbk0+YU G+pomKERkMtM8cmI8gShXr4auy1zISphl11+6ztbeIPXyBFQS3Jg5jQjGfUsGRzmjJ ShU0uS+MS6t/1GCzxLMagrkioywKMpNprvWoUAnwZhZk5Y2zX5zECyLICylXJgeT4F 7BDSBTd7OQV4A== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 06/22] arm64: vdso: Discard .discard.* sections Date: Sat, 8 Aug 2026 16:17:10 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In preparation for enabling objtool on arm64, add .discard.* to the vDSO's /DISCARD/ section so objtool annotations don't cause orphan section warnings or leak into the final vDSO binary. Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- arch/arm64/kernel/vdso/vdso.lds.S | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/arm64/kernel/vdso/vdso.lds.S b/arch/arm64/kernel/vdso/vds= o.lds.S index 52314be291912..d5f96fa17e605 100644 --- a/arch/arm64/kernel/vdso/vdso.lds.S +++ b/arch/arm64/kernel/vdso/vdso.lds.S @@ -39,6 +39,7 @@ SECTIONS /DISCARD/ : { *(.note.GNU-stack .note.gnu.property) *(.ARM.attributes) + *(.discard.*) } .note : { *(.note.*) } :text :note =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0DEA938238D; Sat, 8 Aug 2026 23:18:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231113; cv=none; b=ViQxh/OqneH9ubiTP48YPQdbFGYSNc2pZw7bqctp90UA2DDF7+IDH23eNF6+PWhcY1hsNg5RlKw0VG5wMakAbm+WLR46gO8KHwTExEwx1qiG3/gyrrwSBnymuvubA587ix0srB58KDuyfrEFQFQe2gZrrIMqLAw54NX1meb5LLk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231113; c=relaxed/simple; bh=tOlz2teR2/J3TcdGSaCgdqG4nkAkpQxOqtEGc0KXXZs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UhRqMfkmb01oxEzx2RgOrqR4o1s6L2+TlDpYCeoAfIhiZ7Ggz8/4HF9L4a/VqLJte4PdtWTOQKOPS6Ge218io08WmdSh1od48pDhNR0NxC2bzxXRS7TK0/jFojO7aQhHcvz4wr8wi+TQJyHGk1/hY+OplVIONRjF69uHGtYoZhs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=CjRtSu0U; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="CjRtSu0U" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 53AB31F00A3D; Sat, 8 Aug 2026 23:18:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231111; bh=+2GPJTuBqAhwT7SdumyJDjy2VYWy7AtImOE6f1ugQ5U=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=CjRtSu0UVSLtNJT5CfBJd/qoE0TRbhXLrzIL9m0xdFfmwtB70ndU2eoG6sOxPTL2v Gb1lvopN2qmS1pAl9GcTCue7Umbatz9lmRa1yf/EEuKqcCTBZMEGp345A041tbSjAP DRRSdJ3zkukA8FZWEfjb/v2mk3f6tTPJMc4SxHOgxhi55czcIHDt8g39p1wTMuE5Cg +G2rRucj2pnJDzp7uoWC4mhcKZFuYmjHZ2/RhLJekms4C8Vte1oEmCViTbdkZz1daA RGZV9LL79awuNfQdmcdR2w8vAVaUKfyqhwe61c0K17sumHdbwrME9uLjeuhO43TCQ0 VLPGG97gyWEIA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 07/22] arm64: Annotate special section entries Date: Sat, 8 Aug 2026 16:17:11 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In preparation for adding arm64 support for "objtool klp checksum/diff" to enable livepatch module generation, annotate special section entries. This will allow objtool to determine the size and location of the entries and to extract them when needed. A new ANNOTATE_DATA_SPECIAL_END annotation is added to mark the end of special data blocks, which is needed because arm64's replacement instructions are emitted in .text rather than .altinstr_replacement, so there's otherwise no way to determine where the last replacement block ends. Signed-off-by: Josh Poimboeuf --- arch/arm64/include/asm/alternative-macros.h | 27 ++++++++++++++++----- arch/arm64/include/asm/asm-bug.h | 2 ++ arch/arm64/include/asm/asm-extable.h | 21 ++++++++++------ arch/arm64/include/asm/jump_label.h | 2 ++ arch/arm64/kernel/asm-offsets.c | 5 ++++ include/linux/annotate.h | 14 ++++++++++- include/linux/objtool_types.h | 1 + tools/include/linux/objtool_types.h | 1 + tools/objtool/klp-diff.c | 5 +++- 9 files changed, 62 insertions(+), 16 deletions(-) diff --git a/arch/arm64/include/asm/alternative-macros.h b/arch/arm64/inclu= de/asm/alternative-macros.h index 8624166248528..ba86d655af1d7 100644 --- a/arch/arm64/include/asm/alternative-macros.h +++ b/arch/arm64/include/asm/alternative-macros.h @@ -3,11 +3,16 @@ #define __ASM_ALTERNATIVE_MACROS_H =20 #include +#include #include =20 #include #include =20 +#ifndef COMPILE_OFFSETS +#include +#endif + /* * Binutils 2.27.0 can't handle a 'UL' suffix on constants, so for the ass= embly * macros below we must use we must use `(1 << ARM64_CB_SHIFT)`. @@ -58,15 +63,18 @@ "661:\n\t" \ oldinstr "\n" \ "662:\n" \ - ".pushsection .altinstructions,\"a\"\n" \ + ".pushsection .altinstructions,\"aM\", @progbits, " \ + __stringify(ALT_INSTR_SIZE) "\n" \ ALTINSTR_ENTRY(cpucap) \ ".popsection\n" \ ".subsection 1\n" \ + ANNOTATE_DATA_SPECIAL "\n" \ "663:\n\t" \ newinstr "\n" \ "664:\n\t" \ ".org . - (664b-663b) + (662b-661b)\n\t" \ ".org . - (662b-661b) + (664b-663b)\n\t" \ + ANNOTATE_DATA_SPECIAL_END "\n\t" \ ".previous\n" \ ".endif\n" =20 @@ -75,7 +83,8 @@ "661:\n\t" \ oldinstr "\n" \ "662:\n" \ - ".pushsection .altinstructions,\"a\"\n" \ + ".pushsection .altinstructions,\"aM\", @progbits, " \ + __stringify(ALT_INSTR_SIZE) "\n" \ ALTINSTR_ENTRY_CB(cpucap, cb) \ ".popsection\n" \ "663:\n\t" \ @@ -102,13 +111,15 @@ .macro alternative_insn insn1, insn2, cap, enable =3D 1 .if \enable 661: \insn1 -662: .pushsection .altinstructions, "a" +662: .pushsection .altinstructions, "aM", @progbits, ALT_INSTR_SIZE altinstruction_entry 661b, 663f, \cap, 662b-661b, 664f-663f .popsection .subsection 1 + ANNOTATE_DATA_SPECIAL 663: \insn2 664: .org . - (664b-663b) + (662b-661b) .org . - (662b-661b) + (664b-663b) + ANNOTATE_DATA_SPECIAL_END .previous .endif .endm @@ -137,7 +148,7 @@ */ .macro alternative_if_not cap .set .Lasm_alt_mode, 0 - .pushsection .altinstructions, "a" + .pushsection .altinstructions, "aM", @progbits, ALT_INSTR_SIZE altinstruction_entry 661f, 663f, \cap, 662f-661f, 664f-663f .popsection 661: @@ -145,17 +156,18 @@ =20 .macro alternative_if cap .set .Lasm_alt_mode, 1 - .pushsection .altinstructions, "a" + .pushsection .altinstructions, "aM", @progbits, ALT_INSTR_SIZE altinstruction_entry 663f, 661f, \cap, 664f-663f, 662f-661f .popsection .subsection 1 .align 2 /* So GAS knows label 661 is suitably aligned */ + ANNOTATE_DATA_SPECIAL 661: .endm =20 .macro alternative_cb cap, cb .set .Lasm_alt_mode, 0 - .pushsection .altinstructions, "a" + .pushsection .altinstructions, "aM", @progbits, ALT_INSTR_SIZE altinstruction_entry 661f, \cb, (1 << ARM64_CB_SHIFT) | \cap, 662f-661f, 0 .popsection 661: @@ -168,7 +180,9 @@ 662: .if .Lasm_alt_mode=3D=3D0 .subsection 1 + ANNOTATE_DATA_SPECIAL .else + ANNOTATE_DATA_SPECIAL_END .previous .endif 663: @@ -182,6 +196,7 @@ .org . - (664b-663b) + (662b-661b) .org . - (662b-661b) + (664b-663b) .if .Lasm_alt_mode=3D=3D0 + ANNOTATE_DATA_SPECIAL_END .previous .endif .endm diff --git a/arch/arm64/include/asm/asm-bug.h b/arch/arm64/include/asm/asm-= bug.h index a5f13801b7840..22e1a9df9851d 100644 --- a/arch/arm64/include/asm/asm-bug.h +++ b/arch/arm64/include/asm/asm-bug.h @@ -5,6 +5,7 @@ */ #define __ASM_ASM_BUG_H =20 +#include #include =20 #ifdef CONFIG_DEBUG_BUGVERBOSE @@ -24,6 +25,7 @@ #define __BUG_ENTRY_START \ .pushsection __bug_table,"aw"; \ .align 2; \ + __ANNOTATE_DATA_SPECIAL; \ 14470: .long 14471f - .; \ =20 #define __BUG_ENTRY_END \ diff --git a/arch/arm64/include/asm/asm-extable.h b/arch/arm64/include/asm/= asm-extable.h index d67e2fdd1aee5..e81700edbb936 100644 --- a/arch/arm64/include/asm/asm-extable.h +++ b/arch/arm64/include/asm/asm-extable.h @@ -5,6 +5,10 @@ #include #include =20 +#ifndef COMPILE_OFFSETS +#include +#endif + #define EX_TYPE_NONE 0 #define EX_TYPE_BPF 1 #define EX_TYPE_UACCESS_ERR_ZERO 2 @@ -29,13 +33,13 @@ =20 #ifdef __ASSEMBLER__ =20 -#define __ASM_EXTABLE_RAW(insn, fixup, type, data) \ - .pushsection __ex_table, "a"; \ - .align 2; \ - .long ((insn) - .); \ - .long ((fixup) - .); \ - .short (type); \ - .short (data); \ +#define __ASM_EXTABLE_RAW(insn, fixup, type, data) \ + .pushsection __ex_table, "aM", @progbits, EXTABLE_SIZE; \ + .align 2; \ + .long ((insn) - .); \ + .long ((fixup) - .); \ + .short (type); \ + .short (data); \ .popsection; =20 #define EX_DATA_REG(reg, gpr) \ @@ -82,7 +86,8 @@ #include =20 #define __ASM_EXTABLE_RAW(insn, fixup, type, data) \ - ".pushsection __ex_table, \"a\"\n" \ + ".pushsection __ex_table, \"aM\", @progbits, "\ + __stringify(EXTABLE_SIZE) "\n" \ ".align 2\n" \ ".long ((" insn ") - .)\n" \ ".long ((" fixup ") - .)\n" \ diff --git a/arch/arm64/include/asm/jump_label.h b/arch/arm64/include/asm/j= ump_label.h index 0cb211d3607d3..4dacb28641d72 100644 --- a/arch/arm64/include/asm/jump_label.h +++ b/arch/arm64/include/asm/jump_label.h @@ -11,6 +11,7 @@ #ifndef __ASSEMBLER__ =20 #include +#include #include =20 #define HAVE_JUMP_LABEL_BATCH @@ -19,6 +20,7 @@ #define JUMP_TABLE_ENTRY(key, label) \ ".pushsection __jump_table, \"aw\"\n\t" \ ".align 3\n\t" \ + ANNOTATE_DATA_SPECIAL "\n\t" \ ".long 1b - ., " label " - .\n\t" \ ".quad " key " - .\n\t" \ ".popsection\n\t" diff --git a/arch/arm64/kernel/asm-offsets.c b/arch/arm64/kernel/asm-offset= s.c index 44b92f582c127..76251586e31c7 100644 --- a/arch/arm64/kernel/asm-offsets.c +++ b/arch/arm64/kernel/asm-offsets.c @@ -23,6 +23,8 @@ #include #include #include +#include +#include =20 int main(void) { @@ -185,5 +187,8 @@ int main(void) #endif DEFINE(PIE_E0_ASM, PIE_E0); DEFINE(PIE_E1_ASM, PIE_E1); + BLANK(); + DEFINE(ALT_INSTR_SIZE, sizeof(struct alt_instr)); + DEFINE(EXTABLE_SIZE, sizeof(struct exception_table_entry)); return 0; } diff --git a/include/linux/annotate.h b/include/linux/annotate.h index 2f1599c9e5732..7f5aa15f353d6 100644 --- a/include/linux/annotate.h +++ b/include/linux/annotate.h @@ -3,6 +3,7 @@ #define _LINUX_ANNOTATE_H =20 #include +#include =20 #ifdef CONFIG_OBJTOOL =20 @@ -11,6 +12,10 @@ .long label - ., type; \ .popsection =20 +#define __ASM_ANNOTATE_DATA(type) \ +912: \ + __ASM_ANNOTATE(.discard.annotate_data, 912b, type) + #ifndef __ASSEMBLY__ =20 #define ASM_ANNOTATE_LABEL(label, type) \ @@ -39,6 +44,9 @@ #endif /* __ASSEMBLY__ */ =20 #else /* !CONFIG_OBJTOOL */ + +#define __ASM_ANNOTATE_DATA(type) + #ifndef __ASSEMBLY__ #define ASM_ANNOTATE_LABEL(label, type) "" #define ASM_ANNOTATE(type) @@ -106,10 +114,12 @@ #define ANNOTATE_NOCFI_SYM(sym) asm(ASM_ANNOTATE_LABEL(sym, ANNOTYPE_NOCF= I)) =20 /* - * Annotate a special section entry. This emables livepatch module genera= tion + * Annotate a special section entry. This enables livepatch module genera= tion * to find and extract individual special section entries as needed. */ #define ANNOTATE_DATA_SPECIAL ASM_ANNOTATE_DATA(ANNOTYPE_DATA_SPECIAL) +#define __ANNOTATE_DATA_SPECIAL __ASM_ANNOTATE_DATA(ANNOTYPE_DATA_SPECIAL) +#define ANNOTATE_DATA_SPECIAL_END ASM_ANNOTATE_DATA(ANNOTYPE_DATA_SPECIAL_= END) =20 #else /* __ASSEMBLY__ */ #define ANNOTATE_NOENDBR ANNOTATE type=3DANNOTYPE_NOENDBR @@ -122,6 +132,8 @@ #define ANNOTATE_REACHABLE ANNOTATE type=3DANNOTYPE_REACHABLE #define ANNOTATE_NOCFI_SYM ANNOTATE type=3DANNOTYPE_NOCFI #define ANNOTATE_DATA_SPECIAL ANNOTATE_DATA type=3DANNOTYPE_DATA_SPECIAL +#define __ANNOTATE_DATA_SPECIAL __ASM_ANNOTATE_DATA(ANNOTYPE_DATA_SPECIAL) +#define ANNOTATE_DATA_SPECIAL_END ANNOTATE_DATA type=3DANNOTYPE_DATA_SPECI= AL_END #endif /* __ASSEMBLY__ */ =20 #endif /* _LINUX_ANNOTATE_H */ diff --git a/include/linux/objtool_types.h b/include/linux/objtool_types.h index c6def4049b1ae..744118ffd025f 100644 --- a/include/linux/objtool_types.h +++ b/include/linux/objtool_types.h @@ -68,5 +68,6 @@ struct unwind_hint { #define ANNOTYPE_NOCFI 9 =20 #define ANNOTYPE_DATA_SPECIAL 1 +#define ANNOTYPE_DATA_SPECIAL_END 2 =20 #endif /* _LINUX_OBJTOOL_TYPES_H */ diff --git a/tools/include/linux/objtool_types.h b/tools/include/linux/objt= ool_types.h index c6def4049b1ae..744118ffd025f 100644 --- a/tools/include/linux/objtool_types.h +++ b/tools/include/linux/objtool_types.h @@ -68,5 +68,6 @@ struct unwind_hint { #define ANNOTYPE_NOCFI 9 =20 #define ANNOTYPE_DATA_SPECIAL 1 +#define ANNOTYPE_DATA_SPECIAL_END 2 =20 #endif /* _LINUX_OBJTOOL_TYPES_H */ diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index 890de34d1fa27..19dcf930a562b 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -1727,7 +1727,10 @@ static int create_fake_symbols(struct elf *elf) */ next_reloc =3D reloc; for_each_reloc_continue(sec->rsec, next_reloc) { - if (annotype(elf, sec, next_reloc) !=3D ANNOTYPE_DATA_SPECIAL || + unsigned int next_type =3D annotype(elf, sec, next_reloc); + + if ((next_type !=3D ANNOTYPE_DATA_SPECIAL && + next_type !=3D ANNOTYPE_DATA_SPECIAL_END) || next_reloc->sym->sec !=3D reloc->sym->sec) continue; =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC21637BE7A; Sat, 8 Aug 2026 23:18:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231114; cv=none; b=B/pk4pTBA78DkmR5CDjwxGEB5bwfhXBko5PFhomeDk9pEkzzZTMSbBCpGDd+iHeX1qUha/o4apLMs3UvWHgZJZd3OHDcPTy8LnBdKOM4atIH7nUnjtZNAQRu+HtWudIUWCmyhIC6YniTyluQzRcRDueYVliZFqgNLUyaCTdbF5s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231114; c=relaxed/simple; bh=em/W6RX1LDB/B/iXSMlDcExQArcuro/ypwsLBvemSE4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ZdmN9sNoMBc0RRzjRrKtD2I2vJfsITvtZrcSBbKFEnq2005t177cYBKhWYJPJFGEtjAJotb6W2VsGR0fEUTu/9zwwUvy+ZHlqxSumx+LFZMxir4RhbFaqGCOUG4oAlRfkx+CWJAncRATALNCRqMK1unnUQYtdk8Ca+umvD0r278= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=T8T+/OKR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="T8T+/OKR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1BFC71F00ADE; Sat, 8 Aug 2026 23:18:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231112; bh=ca1nwuh/ovV7iRlJ1HipcMmil7CeSekJrBHAP1jRLkM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=T8T+/OKR1u9TE8zMCEbQ4TXv1lVbonhiRfkPhEbj9aBh3hZ41aNT296DcWSDQxxxK 99oIJh/K451j+TTrApJzmlCGBBkddDrxpw9L/zoLPMkRZ6cuuDLYcKMTMP2T//ZXfx rDoXERtMRV9KJuVPqPju07SwjrfbcQnYcfZ8+JFA7CWCAl3cVrhj/Ggp+neiu9mFYe VfkYbrlLLj7jwmJ+mf6yWW6FpiIbHCZMmfVfmdmtyJTJZLfwngEYTxFrKQDih+6VgT f6ffS9xmOq/1QoRICXUxnnBTRXyNE6ujppyVlcbU72ztkjGYC0DaajkkICYuuWtQjj AkjbnfGEnqanw== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 08/22] arm64: Remove unnecessary empty alternatives Date: Sat, 8 Aug 2026 16:17:12 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The code in arch/arm64/mm/cache.S creates three empty alternatives, all from calling the dcache_by_myline_op_nosync asm macro. If \op =3D=3D cvau, it creates an empty alternative for ARM64_WORKAROUND_4311569. Since orig_len =3D=3D 0, the alternative patching code mostly ignores it, though it does do an unnecessary clean_dcache_range_nopatch(). It also triggers an objtool error ("empty alternative entry"). Clean it up by moving the .ifnc check outside the alternative emit. Signed-off-by: Josh Poimboeuf --- arch/arm64/include/asm/assembler.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/arm64/include/asm/assembler.h b/arch/arm64/include/asm/as= sembler.h index effae53e9739d..6e059efced5bb 100644 --- a/arch/arm64/include/asm/assembler.h +++ b/arch/arm64/include/asm/assembler.h @@ -404,13 +404,13 @@ alternative_else_nop_endif add \start, \start, \linesz cmp \start, \end b.lo .Ldcache_op\@ -alternative_if ARM64_WORKAROUND_4311569 .ifnc \op, cvau +alternative_if ARM64_WORKAROUND_4311569 mov \start, \tmp mov \tmp, xzr cbnz \start, .Ldcache_op\@ - .endif alternative_else_nop_endif + .endif =20 _cond_uaccess_extable .Ldcache_op\@, \fixup .endm --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7FE9D37D124; Sat, 8 Aug 2026 23:18:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; cv=none; b=YUXfbkxc9op80Ibr7OH7LAY0C5WV5fcf42VVNdFKN1Yd1V7oIcw4Ccba/91XDLutxwShm9edaznnIa7O8ZgAUxEqfIgQVPyZ9FXleDgFjUUstZ5YfQ+M/l31+lVnKf4q3wrFblL5OKCdA8p4m+KxXRmeC4MJw8vgdKYquOeXYbM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; c=relaxed/simple; bh=pmf79rrtsNXmpoe9hehE/nAg66JKSIJyNndJWZCs0uw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bma9z9XA5QrcCD9edh/Ibp0e2brhZdrcIOzm3QL/7qBJitAiw+ywpyS9jdG5ouALNJVAfLrC4Q/GttJHO7/JeL/Hl4ifazSEdhO9RmilQ0iVGc0jxcXVBwVS7kF95ogpGhzTl1i3b6u7A14lFljdMEiWKd1laVpOK7dKMmWNpUo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=OTjOZiEJ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="OTjOZiEJ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id CDC281F00A3E; Sat, 8 Aug 2026 23:18:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231113; bh=6ADoXXo4TVe2TzxKvpv7LpzKJ+UodT4wZ8UmCONxN/c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=OTjOZiEJ/oVFbHxdRHa9OdqUfCW0ZkH/Pa0qeea/645oCYuH6IWs86G5L5eMfRnbn f4dd3lsEnmGxZ4vkZcaEJY1/0ca1uA1DMBLLxkaeevsR50rJe+gm8QxcbxTSJKxb+a C0mPDNYJ1O4i9QfNXp8FgGkCOl7khYqMVF+jGXg8hWXyiCFchPoSG0gXCcJP294tbV tFqlB3iFLcN0wfsQT32TFenXZUqQtkVTBuSzgtB/ZtIIuASipdos4hIZz/Pv3BecG6 gK4dkCaSoi3M1bjLItXD10lpp46yD3CorxgvvUyEigTKQ26Jgzf+T0fW/TBG36+1ZF PQqf8qQ8IsZBw== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 09/22] crypto: arm64: Move data to .rodata Date: Sat, 8 Aug 2026 16:17:13 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Data embedded in .text pollutes i-cache and confuses objtool and other tools that try to disassemble it. Move it to .rodata. Signed-off-by: Josh Poimboeuf --- lib/crypto/arm64/sha2-armv8.pl | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/lib/crypto/arm64/sha2-armv8.pl b/lib/crypto/arm64/sha2-armv8.pl index 35ec9ae99fe16..e0ee2d5367e72 100644 --- a/lib/crypto/arm64/sha2-armv8.pl +++ b/lib/crypto/arm64/sha2-armv8.pl @@ -207,12 +207,13 @@ $func: ___ $code.=3D<<___ if ($SZ=3D=3D4); #ifndef __KERNEL__ + adrp x17,.LOPENSSL_armcap_P + add x17,x17,:lo12:.LOPENSSL_armcap_P # ifdef __ILP32__ - ldrsw x16,.LOPENSSL_armcap_P + ldrsw x16,[x17] # else - ldr x16,.LOPENSSL_armcap_P + ldr x16,[x17] # endif - adr x17,.LOPENSSL_armcap_P add x16,x16,x17 ldr w16,[x16] tst w16,#ARMV8_SHA256 @@ -237,7 +238,8 @@ $code.=3D<<___; ldp $E,$F,[$ctx,#4*$SZ] add $num,$inp,$num,lsl#`log(16*$SZ)/log(2)` // end of input ldp $G,$H,[$ctx,#6*$SZ] - adr $Ktbl,.LK$BITS + adrp $Ktbl,.LK$BITS + add $Ktbl,$Ktbl,:lo12:.LK$BITS stp $ctx,$num,[x29,#96] =20 .Loop: @@ -286,6 +288,7 @@ $code.=3D<<___; ret .size $func,.-$func =20 +.pushsection .rodata .align 6 .type .LK$BITS,%object .LK$BITS: @@ -365,6 +368,7 @@ $code.=3D<<___; #endif .asciz "SHA$BITS block transform for ARMv8, CRYPTOGAMS by " .align 2 +.popsection ___ =20 if ($SZ=3D=3D4) { @@ -385,7 +389,8 @@ sha256_block_armv8: add x29,sp,#0 =20 ld1.32 {$ABCD,$EFGH},[$ctx] - adr $Ktbl,.LK256 + adrp $Ktbl,.LK256 + add $Ktbl,$Ktbl,:lo12:.LK256 =20 .Loop_hw: ld1 {@MSG[0]-@MSG[3]},[$inp],#64 @@ -648,7 +653,8 @@ sha256_block_neon: mov x29, sp sub sp,sp,#16*4 =20 - adr $Ktbl,.LK256 + adrp $Ktbl,.LK256 + add $Ktbl,$Ktbl,:lo12:.LK256 add $num,$inp,$num,lsl#6 // len to point at the end of inp =20 ld1.8 {@X[0]},[$inp], #16 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3FCCF381AE0; Sat, 8 Aug 2026 23:18:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231116; cv=none; b=Vg42zYdsHd0v2EujUG6zMqm3X1MxO8ljw5PP4KeBa2+brvMihMrol79yjAy3+dRC/TqWRuCGhXnrZ+aLAbCpXRPOIeW5+7IqAByB+Gn1EMunnX5fADaLxsaCjx3Ly1xqHJNZpus5uRf2mLGASEn+NVQrtManZrAjhaf5kfzrt0c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231116; c=relaxed/simple; bh=W3SyGCo462WJlJKCsRBruxE7yb6MA8zDTXvX8bGc+vM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Qhegk3OfICmvY55qTvaqUUVBw+3Cip6y5ZOosTA3JQ9v6sYmCDR82R+NmS+aw1uICpO63zfgDU2K8NwL6nSwqO1KX/JSqtVf/FMPBSYpbzLlbhbNRe8AZRQLLJkyrwP+GKr1K+Dvi7HSkBNn8dbBHukhYzmdRXahw8XkuRC+OOM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=nAc5hpwN; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="nAc5hpwN" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9873C1F000E9; Sat, 8 Aug 2026 23:18:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231114; bh=gV4QRBMjF8SWDxF8bR0dzMkZJ2kMlPEch7VZ8Sz4gRc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nAc5hpwNrSZ1ouVZFjbyGeSZn5j2elY1TzRKCTN/lK5f96kuAgdka1mLYO7o0P2dr F2Tyh6yMp3RpW5Rve6BNBxG+inmwfLWnd9pJ82afHZiyQj7H/i1vAfI6/XXy1gSQsm 11vErT/6U4BaAJa7kLsX/AvEOY5RtoRBS0le4NTHkeTORomKVhXwQXAiEqfO071GB0 SFoKcl1t/uhfJ43gvH6E1LsVI62QgvE+fTYnGE3gOOqcB4zR+SMCHuzjl6IJxENSSI lBWghi+LzluP3rd2ay8Gea88ktGKTA9Qql9s7i3VJ+JT+EMCnUThtD08J7qqF2w9+m owasDHEpY+vrQ== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 10/22] objtool: Allow setting --mnop without --mcount Date: Sat, 8 Aug 2026 16:17:14 -0700 Message-ID: <339aa792e9eec6de991f72bb3afc6016ddeb3d79.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Instead of returning an error for --mnop without --mcount, just silently ignore it. This will help simplify kbuild's handling of objtool args. Acked-by: Song Liu Signed-off-by: Josh Poimboeuf --- tools/objtool/builtin-check.c | 5 ----- 1 file changed, 5 deletions(-) diff --git a/tools/objtool/builtin-check.c b/tools/objtool/builtin-check.c index 75b11dc85010e..b89c7dc7983f3 100644 --- a/tools/objtool/builtin-check.c +++ b/tools/objtool/builtin-check.c @@ -145,11 +145,6 @@ int cmd_parse_options(int argc, const char **argv, con= st char * const usage[]) =20 static bool opts_valid(void) { - if (opts.mnop && !opts.mcount) { - ERROR("--mnop requires --mcount"); - return false; - } - if (opts.noinstr && !opts.link) { ERROR("--noinstr requires --link"); return false; --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1168A384228; Sat, 8 Aug 2026 23:18:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231116; cv=none; b=JHWvkMsu4pyGpLGSZkhldaNwgvp+zTIH3TqoWRAcD+Hk6xOvcARoJ1dnmRjt2t+Qv5/bTua6I56ZDONfPH1VGZWlakC2DRdMPJCAT4Mc+wlcSbuXCBO6TUaLLU+DAgUIK2JtXIpBp9g3DlohJw4p/6XGB46KCtw8O6IPlaB8z50= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231116; c=relaxed/simple; bh=/Wo5DedwZCEkHcc8ZLnJOXxc4qvg1OkUzCivi6XSoxE=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Hqwk+t5pXYT1jqWlAAIxyEIW52Ds1vEQGL5Slk9Hgj3zpYgmbQK481odxMuDGwdyBZYWco7fYccl5Za2qfAWkE+aT4CZi80qmIQocdfB7wmI2HkKovJX1FG1ppA1XACdSrMr4Dn7mYUgV/Dx71H2OdDAbY/3pywLjyaFJR3IMoo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=fWjAA/gY; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="fWjAA/gY" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5454F1F00A3D; Sat, 8 Aug 2026 23:18:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231114; bh=uE2HB1BAtSsaPradROS+PC6Riaax1AHZ+bCP9cmRupg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=fWjAA/gYAv55v5+/w7cCkSj0UNu6I3gMB/FfGSUyCCAClzFcAAd8pmOOY1/AkTaR4 HlXW8qgoNHHEuBv406o2OyvpF9lWG0+6PdWckAUBqh7dyet9nGwQ9r6wSRtb1svmNe oCLSLo/c48r/KCxitmnFnfAH0RlBD45voktenPK3I8BSXTEGjn0yJuZmsJfypgNuu4 FCnkX4K2qfUvtcMG1zULnQFMr0QjwxPhRGNCgMNB6NhthuDvY9jKt7beZ/alXFCjrC OLJeL6+8oEk4kWzYmiAhoyMbCjL3xV6qn8rltPyTIcZuHFBP05ecjG70wYYbsgpCSm cX4a3nSLuQvPA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 11/22] kbuild: Only run objtool if there is at least one command Date: Sat, 8 Aug 2026 16:17:15 -0700 Message-ID: <8adf966b340ea38ef1df845c7af0c794df3a7bce.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Split the objtool args into commands and options, such that if no commands have been enabled, objtool doesn't run. This is in preparation for enabling objtool and klp-build for arm64. Reviewed-by: Nathan Chancellor Reviewed-by: Nicolas Schier Tested-by: Nathan Chancellor Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- arch/x86/boot/startup/Makefile | 2 +- scripts/Makefile.build | 4 +-- scripts/Makefile.lib | 52 ++++++++++++++++++---------------- scripts/Makefile.vmlinux_o | 18 +++++------- 4 files changed, 38 insertions(+), 38 deletions(-) diff --git a/arch/x86/boot/startup/Makefile b/arch/x86/boot/startup/Makefile index 5e499cfb29b5c..a08297829fc63 100644 --- a/arch/x86/boot/startup/Makefile +++ b/arch/x86/boot/startup/Makefile @@ -36,7 +36,7 @@ $(patsubst %.o,$(obj)/%.o,$(lib-y)): OBJECT_FILES_NON_STA= NDARD :=3D y # relocations, even if other objtool actions are being deferred. # $(pi-objs): objtool-enabled =3D 1 -$(pi-objs): objtool-args =3D $(if $(delay-objtool),--dry-run,$(objtool-arg= s-y)) --noabs +$(pi-objs): objtool-args =3D $(if $(delay-objtool),--dry-run,$(objtool-cmd= s-y) $(objtool-opts-y)) --noabs =20 # # Confine the startup code by prefixing all symbols with __pi_ (for positi= on diff --git a/scripts/Makefile.build b/scripts/Makefile.build index 9117457432463..d0865528edad5 100644 --- a/scripts/Makefile.build +++ b/scripts/Makefile.build @@ -277,7 +277,7 @@ endif # CONFIG_FTRACE_MCOUNT_USE_RECORDMCOUNT is-standard-object =3D $(if $(filter-out y%, $(OBJECT_FILES_NON_STANDARD_$= (target-stem).o)$(OBJECT_FILES_NON_STANDARD)n),$(is-kernel-object)) =20 ifdef CONFIG_OBJTOOL -$(obj)/%.o: private objtool-enabled =3D $(if $(is-standard-object),$(if $(= delay-objtool),$(is-single-obj-m),y)) +$(obj)/%.o: private objtool-enabled =3D $(and $(is-standard-object),$(objt= ool-cmds-y),$(if $(delay-objtool),$(is-single-obj-m),y)) endif =20 ifneq ($(findstring 1, $(KBUILD_EXTRA_WARN)),) @@ -502,7 +502,7 @@ define rule_ld_multi_m $(call cmd,gen_objtooldep) endef =20 -$(multi-obj-m): private objtool-enabled :=3D $(delay-objtool) +$(multi-obj-m): private objtool-enabled :=3D $(if $(objtool-cmds-y),$(dela= y-objtool)) $(multi-obj-m): private part-of-module :=3D y $(multi-obj-m): %.o: %.mod FORCE $(call if_changed_rule,ld_multi_m) diff --git a/scripts/Makefile.lib b/scripts/Makefile.lib index 0a4fdd8bd975d..272652875238c 100644 --- a/scripts/Makefile.lib +++ b/scripts/Makefile.lib @@ -186,30 +186,34 @@ ifdef CONFIG_OBJTOOL =20 objtool :=3D $(objtree)/tools/objtool/objtool =20 -objtool-args-$(CONFIG_HAVE_JUMP_LABEL_HACK) +=3D --hacks=3Djump_label -objtool-args-$(CONFIG_HAVE_NOINSTR_HACK) +=3D --hacks=3Dnoinstr -objtool-args-$(CONFIG_MITIGATION_CALL_DEPTH_TRACKING) +=3D --hacks=3Dskyla= ke -objtool-args-$(CONFIG_X86_KERNEL_IBT) +=3D --ibt -objtool-args-$(CONFIG_CALL_PADDING) +=3D --prefix=3D$(CONFIG_FUNCTION_PA= DDING_BYTES) -ifdef CONFIG_CALL_PADDING -objtool-args-$(CONFIG_CFI) +=3D --cfi -objtool-args-$(CONFIG_FINEIBT) +=3D --fineibt -endif -objtool-args-$(CONFIG_FTRACE_MCOUNT_USE_OBJTOOL) +=3D --mcount -ifdef CONFIG_FTRACE_MCOUNT_USE_OBJTOOL -objtool-args-$(CONFIG_HAVE_OBJTOOL_NOP_MCOUNT) +=3D --mnop -endif -objtool-args-$(CONFIG_UNWINDER_ORC) +=3D --orc -objtool-args-$(CONFIG_MITIGATION_RETPOLINE) +=3D --retpoline -objtool-args-$(CONFIG_MITIGATION_RETHUNK) +=3D --rethunk -objtool-args-$(CONFIG_MITIGATION_SLS) +=3D --sls -objtool-args-$(CONFIG_STACK_VALIDATION) +=3D --stackval -objtool-args-$(CONFIG_HAVE_STATIC_CALL_INLINE) +=3D --static-call -objtool-args-$(CONFIG_HAVE_UACCESS_VALIDATION) +=3D --uaccess -objtool-args-$(or $(CONFIG_GCOV_KERNEL),$(CONFIG_KCOV)) +=3D --no-unreacha= ble -objtool-args-$(CONFIG_OBJTOOL_WERROR) +=3D --werror +# objtool commands +objtool-cmds-$(CONFIG_HAVE_JUMP_LABEL_HACK) +=3D --hacks=3Djump_label +objtool-cmds-$(CONFIG_HAVE_NOINSTR_HACK) +=3D --hacks=3Dnoinstr +objtool-cmds-$(CONFIG_MITIGATION_CALL_DEPTH_TRACKING) +=3D --hacks=3Dskyla= ke +objtool-cmds-$(CONFIG_X86_KERNEL_IBT) +=3D --ibt +objtool-cmds-$(CONFIG_CALL_PADDING) +=3D --prefix=3D$(CONFIG_FUNCTION_PA= DDING_BYTES) +objtool-cmds-$(CONFIG_FTRACE_MCOUNT_USE_OBJTOOL) +=3D --mcount +objtool-cmds-$(CONFIG_UNWINDER_ORC) +=3D --orc +objtool-cmds-$(CONFIG_MITIGATION_RETPOLINE) +=3D --retpoline +objtool-cmds-$(CONFIG_MITIGATION_RETHUNK) +=3D --rethunk +objtool-cmds-$(CONFIG_MITIGATION_SLS) +=3D --sls +objtool-cmds-$(CONFIG_STACK_VALIDATION) +=3D --stackval +objtool-cmds-$(CONFIG_HAVE_STATIC_CALL_INLINE) +=3D --static-call +objtool-cmds-$(CONFIG_HAVE_UACCESS_VALIDATION) +=3D --uaccess +objtool-cmds-y +=3D $(OBJTOOL_ARGS) =20 -objtool-args =3D $(objtool-args-y) \ +# objtool options +ifdef CONFIG_CALL_PADDING +objtool-opts-$(CONFIG_CFI) +=3D --cfi +objtool-opts-$(CONFIG_FINEIBT) +=3D --fineibt +endif +ifdef CONFIG_FTRACE_MCOUNT_USE_OBJTOOL +objtool-opts-$(CONFIG_HAVE_OBJTOOL_NOP_MCOUNT) +=3D --mnop +endif +objtool-opts-$(or $(CONFIG_GCOV_KERNEL),$(CONFIG_KCOV)) +=3D --no-unreacha= ble +objtool-opts-$(CONFIG_OBJTOOL_WERROR) +=3D --werror + +objtool-args =3D $(objtool-cmds-y) $(objtool-opts-y) \ $(if $(delay-objtool), --link) \ $(if $(part-of-module), --module) =20 @@ -218,7 +222,7 @@ delay-objtool :=3D $(or $(CONFIG_LTO_CLANG),$(CONFIG_X8= 6_KERNEL_IBT),$(CONFIG_KLP_ cmd_objtool =3D $(if $(objtool-enabled), ; $(objtool) $(objtool-args) $@) cmd_gen_objtooldep =3D $(if $(objtool-enabled), { echo ; echo '$@: $$(wild= card $(objtool))' ; } >> $(dot-target).cmd) =20 -objtool-enabled :=3D y +objtool-enabled =3D $(if $(objtool-cmds-y),y) =20 endif # CONFIG_OBJTOOL =20 diff --git a/scripts/Makefile.vmlinux_o b/scripts/Makefile.vmlinux_o index 24a3a4fd271c2..729f82eb85b35 100644 --- a/scripts/Makefile.vmlinux_o +++ b/scripts/Makefile.vmlinux_o @@ -36,21 +36,17 @@ endif # For !delay-objtool + CONFIG_NOINSTR_VALIDATION, it runs on both translat= ion # units and vmlinux.o, with the latter only used for noinstr/unret validat= ion. =20 -objtool-enabled :=3D $(or $(delay-objtool),$(CONFIG_NOINSTR_VALIDATION)) - -ifeq ($(delay-objtool),y) -vmlinux-objtool-args-y +=3D $(objtool-args-y) -else -vmlinux-objtool-args-$(CONFIG_OBJTOOL_WERROR) +=3D --werror +ifneq ($(delay-objtool),y) +objtool-cmds-y =3D +objtool-opts-y =3D --link +objtool-opts-$(CONFIG_OBJTOOL_WERROR) +=3D --werror endif =20 -vmlinux-objtool-args-$(CONFIG_NOINSTR_VALIDATION) +=3D --noinstr \ - $(if $(or $(CONFIG_MITIGATION_UNRET_ENTRY),$(CONFIG_MITIGATION_S= RSO)), --unret) +objtool-cmds-$(CONFIG_NOINSTR_VALIDATION) +=3D --noinstr \ + $(if $(or $(CONFIG_MITIGATION_UNRET_ENTRY),$(CONFIG_MITIGATION_SRSO)= ), --unret) =20 # Only used for builds initiated by klp-build -vmlinux-objtool-args-$(if $(KLP_SYMIDS),y) +=3D --klp-symids - -objtool-args =3D $(vmlinux-objtool-args-y) --link +objtool-cmds-$(if $(KLP_SYMIDS),y) +=3D --klp-symids =20 # Link of vmlinux.o used for section mismatch analysis # ------------------------------------------------------------------------= --- --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C573388885; Sat, 8 Aug 2026 23:18:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231121; cv=none; b=sF1lyYHl3pOWyLI2mVC3F7fvDJtuNK1IYdLkkuymND3gcYf5bwVQVubo2TH6kEQIgPYoeLAB2pau7FmJ3vetNJIpcw0zkb578ebhM3XH6ARpEn9xHgiVecXm2GN4bKzK12ExgyY9AQo+7XZV3peJU7/4ehM/f9rPktxWv7VgOlM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231121; c=relaxed/simple; bh=6fM8KcMUTsMh3APd7Q69CFrzEQaWzzsd4MPHm/S4LGs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kcLL7aVb5mJSxDzN+kRD0GKxMS+CL19v645tLW9EdFo4UdQ2tyS0Tp652jV4cbVdeSBZffQY4+fwFgUbjrl+xgRWrNqsZ2Vilm8CMCYkIE73caO4tAv7CEkv9Befett3GAMt5C0MBZyT38BThZXNI+umsZP3za6bftB6GnQGh2U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=XUHdYqsO; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="XUHdYqsO" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 123E51F00AC4; Sat, 8 Aug 2026 23:18:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231115; bh=dOZHGJeIbepL3mJdX8opMcoKRte7U11zEhbMcktjANc=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=XUHdYqsO0zpCVOBvNEYBw7FpX5o8Dy0WeFYkKuS735DrtZwrgfuloJny+SPE7ziSs dKRIdMxd5ERoCxsnt8sITbi+mGuiu5zTG+svBk3PvOiDPFzK4vuuTl08EGyEYr510U piOi5esgGaDWVz2W4f17zRZU01GHczFJfjh3JRKFgPEvzX8VLWPb59Tpk13TdM60QB hbw2B2zIHDDLp+Bsx4Dwe/LpaN8SGfjnQGKj7hM5DkRIdC8unk71ktCTCz0r6vV4RG jR9u8+WHkZDJYw3OsZj6czlhDFNdbY2NZits11RpXk4dgcru7v96nyS3xPn/HbIHnA gbieQK5GJojOA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 12/22] objtool: Ignore jumps to the end of the function for checksum runs Date: Sat, 8 Aug 2026 16:17:16 -0700 Message-ID: <13cec0336ae0e9ad4bd605bf34b1236de85d6243.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Sometimes Clang arm64 code jumps to the end of the function for UB. No need to make that an error for checksum runs, which are only run manually by klp-build, and for which caring about UB is out of scope. Such UBs are still reported for normal validate branch runs (for arches which do that). Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/check.c | 38 +++++++++++++++++++++----------------- 1 file changed, 21 insertions(+), 17 deletions(-) diff --git a/tools/objtool/check.c b/tools/objtool/check.c index b353c7d6cd893..c034676e1b8c7 100644 --- a/tools/objtool/check.c +++ b/tools/objtool/check.c @@ -38,6 +38,22 @@ struct disas_context *objtool_disas_ctx; =20 size_t sym_name_max_len; =20 +static bool validate_branch_enabled(void) +{ + return opts.stackval || + opts.orc || + opts.uaccess; +} + +static bool alts_needed(void) +{ + return validate_branch_enabled() || + opts.noinstr || + opts.hack_jump_label || + opts.disas || + opts.checksum; +} + struct instruction *find_insn(struct objtool_file *file, struct section *sec, unsigned long offset) { @@ -1595,8 +1611,12 @@ static int add_jump_destinations(struct objtool_file= *file) /* * GCOV/KCOV dead code can jump to the end of * the function/section. + * + * Clang on arm64 also does this sometimes for + * undefined behavior. */ - if (file->ignore_unreachables && func && + if ((!validate_branch_enabled() || file->ignore_unreachables) && + func && dest_sec =3D=3D insn->sec && dest_off =3D=3D func->offset + func->len) continue; @@ -2586,22 +2606,6 @@ static void mark_holes(struct objtool_file *file) } } =20 -static bool validate_branch_enabled(void) -{ - return opts.stackval || - opts.orc || - opts.uaccess; -} - -static bool alts_needed(void) -{ - return validate_branch_enabled() || - opts.noinstr || - opts.hack_jump_label || - opts.disas || - opts.checksum; -} - int decode_file(struct objtool_file *file) { arch_initial_func_cfi_state(&initial_func_cfi); --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 79D30381EB4; Sat, 8 Aug 2026 23:18:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231120; cv=none; b=pZEPRLBkphcwLDmIrYI4ZzESr7GVdaHujuMV0A+b3VdHnKEcYOKS6U06bo2Z+Jkg++fKNlqa1lsXEjC7hdweQmeC2XZe/LK51pJ8jVCbPZaQEVkoIKdTPMR2Z+JDXob+Gb7kySnSAui0knig736ORayc8wwqmY5PgTYHD+nLRxU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231120; c=relaxed/simple; bh=pg+tc++Rl7SF1/WkWtk/Sq+xGlpSzahN09+kSeyTKC4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=oDNMSUADX8ZzN3lJY+rp4zaQqfimTtnAJVTMrkYLzZb1s84fmqSbM6k0C5E/M1qiW6qEJ94jjwI/HTFsENpWfvnrRK51V1FTtGa+H1pFrYH0jxM1NdMX5mo98weVki+sbRXIrQOkqF0rNiSKZxwNQR9IxY0IwpPyr0WD8Er+bMY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Iv0xdtvB; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Iv0xdtvB" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C7B861F00ADB; Sat, 8 Aug 2026 23:18:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231116; bh=q/7ZXZiGZL3y71MydQCQYr/Z0bjpjJ17DIbARhGctuY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Iv0xdtvBkQcf23BLNLWiWwmP13Vp89P8TfitdbZSgxGXAulLeguZOHk3YEwIn0Rcs xKI/ejyJLwvwwb/Nx5m4NJdGiQQqYIbuZyF4MYkqaNk1JXiMCd1unSz1880JiWbOUW S9nbJHbzcob2LcllovdJLuICjkAokI+J1RKY+glWMvCaY+diW1NYn9rfXyvVNVBIfa MDouCeAkOeVpjVegX56j7YUBYCZRUPsAvv+D607QhKBihPmVNWqx7TphFBwryBwrOg ZTv/tsF17GuaLLWOU1wgHkeTA5/X2EspajLm9y1Jv71M3ecboFIBjXDQ3KyC627cq9 hgKm47DvF+3TA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 13/22] objtool: Refactor elf_add_data() to use a growable data buffer Date: Sat, 8 Aug 2026 16:17:17 -0700 Message-ID: <3c65abcb71c23d04470f45862523b0363ee4d709.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Instead of calling elf_newdata() for each new piece of data with its own separate buffer, keep it all in the same growable buffer so the section's entire data can be accessed if needed. Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/elf.c | 123 ++++++++++++++-------------- tools/objtool/include/objtool/elf.h | 13 ++- 2 files changed, 71 insertions(+), 65 deletions(-) diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c index a791f4ea6ec19..8bf225d70d918 100644 --- a/tools/objtool/elf.c +++ b/tools/objtool/elf.c @@ -1147,9 +1147,6 @@ static int read_relocs(struct elf *elf) =20 rsec->base->rsec =3D rsec; =20 - /* nr_alloc_relocs=3D0: libelf owns d_buf */ - rsec->nr_alloc_relocs =3D 0; - rsec->relocs =3D calloc(sec_num_entries(rsec), sizeof(*reloc)); if (!rsec->relocs) { ERROR_GLIBC("calloc"); @@ -1408,7 +1405,7 @@ unsigned int elf_add_string(struct elf *elf, struct s= ection *strtab, const char =20 void *elf_add_data(struct elf *elf, struct section *sec, const void *data,= size_t size) { - unsigned long offset; + unsigned long offset, size_old, size_new, alloc_size_old, alloc_size_new; Elf_Scn *s; =20 if (!sec->sh.sh_addralign) { @@ -1422,30 +1419,55 @@ void *elf_add_data(struct elf *elf, struct section = *sec, const void *data, size_ return NULL; } =20 - sec->data =3D elf_newdata(s); if (!sec->data) { - ERROR_ELF("elf_newdata"); - return NULL; + sec->data =3D elf_newdata(s); + if (!sec->data) { + ERROR_ELF("elf_newdata"); + return NULL; + } + + sec->data->d_align =3D sec->sh.sh_addralign; } =20 - sec->data->d_buf =3D calloc(1, size); - if (!sec->data->d_buf) { - ERROR_GLIBC("calloc"); - return NULL; + size_old =3D sec->data->d_size; + offset =3D ALIGN(size_old, sec->sh.sh_addralign); + size_new =3D offset + size; + + if (!sec->data_overallocated) + alloc_size_old =3D size_old; + else + alloc_size_old =3D max(64UL, roundup_pow_of_two(size_old ? : 1)); + + alloc_size_new =3D max(64UL, roundup_pow_of_two(size_new ? : 1)); + + if (alloc_size_new > alloc_size_old) { + void *orig_buf =3D sec->data->d_buf; + + sec->data->d_buf =3D calloc(1, alloc_size_new); + if (!sec->data->d_buf) { + ERROR_GLIBC("calloc"); + return NULL; + } + + if (size_old) + memcpy(sec->data->d_buf, orig_buf, size_old); + + if (orig_buf && sec->data_owned) + free(orig_buf); + + sec->data_owned =3D 1; + sec->data_overallocated =3D 1; } =20 if (data) - memcpy(sec->data->d_buf, data, size); - - sec->data->d_size =3D size; - sec->data->d_align =3D sec->sh.sh_addralign; - - offset =3D ALIGN(sec_size(sec), sec->sh.sh_addralign); - sec->sh.sh_size =3D offset + size; + memcpy(sec->data->d_buf + offset, data, size); + else + memset(sec->data->d_buf + offset, 0, size); =20 + sec->data->d_size =3D size_new; + sec->sh.sh_size =3D size_new; mark_sec_changed(elf, sec, true); - - return sec->data->d_buf; + return sec->data->d_buf + offset; } =20 struct section *elf_create_section(struct elf *elf, const char *name, @@ -1496,6 +1518,8 @@ struct section *elf_create_section(struct elf *elf, c= onst char *name, ERROR_GLIBC("calloc"); return NULL; } + + sec->data_owned =3D 1; } =20 if (!gelf_getshdr(s, &sec->sh)) { @@ -1546,60 +1570,33 @@ static int elf_alloc_reloc(struct elf *elf, struct = section *rsec) struct reloc *old_relocs, *old_relocs_end, *new_relocs; unsigned int nr_relocs_old =3D sec_num_entries(rsec); unsigned int nr_relocs_new =3D nr_relocs_old + 1; - unsigned long nr_alloc; + unsigned long nr_alloc_old =3D 0, nr_alloc_new; struct symbol *sym; =20 - if (!rsec->data) { - rsec->data =3D elf_newdata(elf_getscn(elf->elf, rsec->idx)); - if (!rsec->data) { - ERROR_ELF("elf_newdata"); - return -1; - } + if (!elf_add_data(elf, rsec, NULL, elf_rela_size(elf))) + return -1; =20 - rsec->data->d_align =3D 1; - rsec->data->d_type =3D ELF_T_RELA; - rsec->data->d_buf =3D NULL; - } + rsec->data->d_type =3D ELF_T_RELA; =20 - rsec->data->d_size =3D nr_relocs_new * elf_rela_size(elf); - rsec->sh.sh_size =3D rsec->data->d_size; + if (rsec->relocs_overallocated) + nr_alloc_old =3D max(64UL, roundup_pow_of_two(nr_relocs_old ? : 1)); + else + nr_alloc_old =3D nr_relocs_old; =20 - nr_alloc =3D max(64UL, roundup_pow_of_two(nr_relocs_new)); - if (nr_alloc <=3D rsec->nr_alloc_relocs) + nr_alloc_new =3D max(64UL, roundup_pow_of_two(nr_relocs_new ? : 1)); + + if (nr_alloc_old =3D=3D nr_alloc_new) return 0; =20 - if (rsec->data->d_buf && !rsec->nr_alloc_relocs) { - void *orig_buf =3D rsec->data->d_buf; - - /* - * The original d_buf is owned by libelf so it can't be - * realloced. - */ - rsec->data->d_buf =3D malloc(nr_alloc * elf_rela_size(elf)); - if (!rsec->data->d_buf) { - ERROR_GLIBC("malloc"); - return -1; - } - memcpy(rsec->data->d_buf, orig_buf, - nr_relocs_old * elf_rela_size(elf)); - } else { - rsec->data->d_buf =3D realloc(rsec->data->d_buf, - nr_alloc * elf_rela_size(elf)); - if (!rsec->data->d_buf) { - ERROR_GLIBC("realloc"); - return -1; - } - } - - rsec->nr_alloc_relocs =3D nr_alloc; - - old_relocs =3D rsec->relocs; - new_relocs =3D calloc(nr_alloc, sizeof(struct reloc)); + new_relocs =3D calloc(nr_alloc_new, sizeof(struct reloc)); if (!new_relocs) { ERROR_GLIBC("calloc"); return -1; } =20 + rsec->relocs_overallocated =3D 1; + + old_relocs =3D rsec->relocs; if (!old_relocs) goto done; =20 @@ -1644,6 +1641,7 @@ static int elf_alloc_reloc(struct elf *elf, struct se= ction *rsec) } =20 free(old_relocs); + done: rsec->relocs =3D new_relocs; return 0; @@ -1673,7 +1671,6 @@ struct section *elf_create_rela_section(struct elf *e= lf, struct section *sec, if (nr_relocs) { rsec->data->d_type =3D ELF_T_RELA; =20 - rsec->nr_alloc_relocs =3D nr_relocs; rsec->relocs =3D calloc(nr_relocs, sizeof(struct reloc)); if (!rsec->relocs) { ERROR_GLIBC("calloc"); diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index a82517a76a0f6..527dd10859de4 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -58,9 +58,18 @@ struct section { Elf_Data *data; const char *name; int idx; - bool _changed, text, rodata, noinstr, init, truncate; + u32 _changed : 1, + text : 1, + rodata : 1, + noinstr : 1, + init : 1, + truncate : 1, + data_owned : 1, + data_overallocated : 1, + relocs_overallocated : 1; + /* 23 bit hole */ + struct reloc *relocs; - unsigned long nr_alloc_relocs; struct section *twin; }; =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 302A9383328; Sat, 8 Aug 2026 23:18:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; cv=none; b=FR5WzPkrXLno+DpbLNvDcZbXaln/Sr+1oaqzexSG1xcIlfup+/BQnPEf0gRoAr7JlI6NKSI4I5zWs9nHJUDjpCQfTozfddaAKyE0x7t4oCi9xGM2lpsABm9HsZlFSPl9AU9oGCNfY60hV2LU9eOPXSY+LExCjoez9p79/kle3Qc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; c=relaxed/simple; bh=ag1m3lcDBWO1fL1wjntRXLz6wu95d7NPU1kqiURfeJU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HbeqXvweCo7RDW4eI2qU0/RGgnDdOeW6s7Phuxj6CoySs9s36Xmf+TyQlfSGXYFllWxjKBexrdicSy6fGHbZi1K7I5iCIyz3QgXfH5NI72xvtXvYFg5gLgnpU7ySgaE5+bewkn6k1JtLGmrBCaV/bVt7MqLQQiJgCQGfR8prcRg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=orXOKo9q; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="orXOKo9q" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 873B11F000E9; Sat, 8 Aug 2026 23:18:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231117; bh=11okBX/oyddYUFhNnABa0TgcLV3f69gdODt8HzLMfH4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=orXOKo9qjPR4tUoRyS5GrhezG1fuSJkv0VWZxXK9NjhMCbP/DU0ccXupgX1G8cm24 AShdnfnt9F2eQZVGq6xMXVfMBw1O8wGr9VUq2XozBYzabR66Y1XURLcWIyq61e5Hsp UOSolX1rPDFgJG/DjdHfIq9zcHORTqMRG27ljFDlBj6msHvV67Puusl9UlhvzyPhcI okqJ69D9WSbO5mwshpN9zfhvdhGJEO/VF0q2bq+76foiOdehXLkEMP6ovj/5g8rpgW lXE2QpQHy1lYYy7QtycuIOGMxuDbsZgw/KNeTy0Quh3itRAM7Pnh+Affq0wxR/Eyew EbODE/gG8+MTA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 14/22] objtool: Reuse string references Date: Sat, 8 Aug 2026 16:17:18 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For duplicate strings, elf_add_string() just blindly adds duplicates. That can be a problem for arm64 which often uses two consecutive instructions (and corresponding relocations) to put an address into a register, like: d8: 90000001 adrp x1, 0 d8: R_AARCH= 64_ADR_PREL_PG_HI21 .rodata.meminfo_proc_show.str1.8 dc: 91000021 add x1, x1, #0x0 dc: R_AARCH64_ADD_ABS_LO12_= NC .rodata.meminfo_proc_show.str1.8 Referencing two different addresses in the ADRP+ADD pair would corrupt the memory access. Avoid that by detecting and reusing duplicates when cloning string relocs. Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/elf.c | 29 +++++++++++++++++++++++------ tools/objtool/include/objtool/elf.h | 3 ++- tools/objtool/klp-diff.c | 4 +++- 3 files changed, 28 insertions(+), 8 deletions(-) diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c index 8bf225d70d918..3bb04d6155a8b 100644 --- a/tools/objtool/elf.c +++ b/tools/objtool/elf.c @@ -1379,9 +1379,27 @@ struct elf *elf_create_file(GElf_Ehdr *ehdr, const c= har *name) return elf; } =20 -unsigned int elf_add_string(struct elf *elf, struct section *strtab, const= char *str) +int elf_find_string(struct elf *elf, struct section *strtab, const char *s= tr) { - unsigned int offset; + char *d_buf; + int i; + + if (!strtab->data) + return -1; + + d_buf =3D strtab->data->d_buf; + + for (i =3D 0; i < strtab->data->d_size; i +=3D strlen(d_buf + i) + 1) { + if (!strcmp(d_buf + i, str)) + return i; + } + + return -1; +} + +int elf_add_string(struct elf *elf, struct section *strtab, const char *st= r) +{ + void *data; =20 if (!strtab) strtab =3D find_section_by_name(elf, ".strtab"); @@ -1395,12 +1413,11 @@ unsigned int elf_add_string(struct elf *elf, struct= section *strtab, const char return -1; } =20 - offset =3D ALIGN(sec_size(strtab), strtab->sh.sh_addralign); - - if (!elf_add_data(elf, strtab, str, strlen(str) + 1)) + data =3D elf_add_data(elf, strtab, str, strlen(str) + 1); + if (!data) return -1; =20 - return offset; + return data - strtab->data->d_buf; } =20 void *elf_add_data(struct elf *elf, struct section *sec, const void *data,= size_t size) diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index 527dd10859de4..5cba96c6392cb 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -188,7 +188,8 @@ struct symbol *elf_create_section_symbol(struct elf *el= f, struct section *sec); void *elf_add_data(struct elf *elf, struct section *sec, const void *data, size_t size); =20 -unsigned int elf_add_string(struct elf *elf, struct section *strtab, const= char *str); +int elf_find_string(struct elf *elf, struct section *strtab, const char *s= tr); +int elf_add_string(struct elf *elf, struct section *strtab, const char *st= r); =20 struct reloc *elf_create_reloc(struct elf *elf, struct section *sec, unsigned long offset, struct symbol *sym, diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index 19dcf930a562b..446ea6f9864a1 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -1543,7 +1543,9 @@ static int clone_reloc(struct elfs *e, struct reloc *= patched_reloc, =20 __dbg_clone("\"%s\"", escape_str(str)); =20 - addend =3D elf_add_string(e->out, out_sym->sec, str); + addend =3D elf_find_string(e->out, out_sym->sec, str); + if (addend =3D=3D -1) + addend =3D elf_add_string(e->out, out_sym->sec, str); if (addend =3D=3D -1) return -1; } --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3AD25386C17; Sat, 8 Aug 2026 23:18:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231121; cv=none; b=Wi8bl7OX5FvufUB9y+rJ0ZDpNixI5EM2Qza68R8hM7xL98JQQkqBrGk5gOn/h1QIqVU0UFtQgITirQoad6CvJiepTZHymAgsXK5x5qX9lkKt7bq/FyuNqgLIbdDoAuhXZcMgRaccHBMU9UsZ1cCIm1lQv91gInSVeEKm/mtb+mk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231121; c=relaxed/simple; bh=Q7ro/BEYFXEr9xutkbU3nIQzhwq/EUsKRCygDwNJr7o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gIE7/f6og5sz32LW0xuVo65iYdkHwk5nm+cBpoHicbRWgNXNoHmT9H/58CywkuYtCf7LKgIZ4dtvjhEKO6gFiAQfWJ8Ospy3QYrMRc5pvL72ZVtqW/g8OuSG5kVfW40zNNAErTDD5p06l0B3DxBHEI7pYVF8oRE+6FnI3dC7/q0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=oGnyOlq8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="oGnyOlq8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 43FE91F00ACF; Sat, 8 Aug 2026 23:18:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231117; bh=s3L2odPB0Cqn2yHa+6ffnlbmn8mWjN2zdGF3gz1mUp8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=oGnyOlq8rd6+X7RV6gIx8WqoV2drtTWpbXix0ITH2u30QDMfHwJZaVyaaebxaF4gc VyuExwvK8547OKW+Luw0nZYG1FucqQ02IbCizs4oknJJ81p13LQ/1ouS54J+6iVtTY q13BrccZEQg/cwpMKOz3OLxWoeKqzEw0J89p1NE4p9I6AE9Ct4u9rZqYIPLXCWDIYg IxB13xYOI9H8gtOEOQ7B9jxQ9WNjOczZ859m8DE3FaitlXrUGszoVHcx+4i2Z5Nmjv /r4L0v39ZKP/miBxqUu7J1Q4bdjmJkIIMITmo2jXuW1m6BZSrCQcB9AB56DL3k1Hed ddzkcCg1ObSpQ== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 15/22] objtool: Prevent kCFI hashes from being decoded as instructions Date: Sat, 8 Aug 2026 16:17:19 -0700 Message-ID: <11e49187e13d36d4257bc60cd2606e0ff5481dfc.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On arm64 with CONFIG_CFI=3Dy, Clang places a 4-byte kCFI type hash immediately before each address-taken function entry. Since these hashes are in the text section, objtool tries to decode them, leading to unpredictable results (e.g., ""unannotated intra-function call"). arm64 toolchains use mapping symbols to annotate boundaries between code and data. Use those to just mark such "instructions" as NOP so objtool ignores them. Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/check.c | 14 ++++++++++++++ tools/objtool/include/objtool/elf.h | 23 +++++++++++++++++++++++ 2 files changed, 37 insertions(+) diff --git a/tools/objtool/check.c b/tools/objtool/check.c index c034676e1b8c7..79b9e2b5d96de 100644 --- a/tools/objtool/check.c +++ b/tools/objtool/check.c @@ -430,6 +430,8 @@ static int decode_instructions(struct objtool_file *fil= e) =20 for_each_sec(file->elf, sec) { struct instruction *insns =3D NULL; + struct symbol *map_sym; + bool is_data =3D false; u8 prev_len =3D 0; u8 idx =3D 0; =20 @@ -456,6 +458,8 @@ static int decode_instructions(struct objtool_file *fil= e) if (!strcmp(sec->name, ".init.text") && !opts.module) sec->init =3D true; =20 + map_sym =3D list_first_entry(&sec->symbol_list, struct symbol, list); + for (offset =3D 0; offset < sec_size(sec); offset +=3D insn->len) { if (!insns || idx =3D=3D INSN_CHUNK_MAX) { insns =3D calloc(INSN_CHUNK_SIZE, sizeof(*insn)); @@ -480,6 +484,16 @@ static int decode_instructions(struct objtool_file *fi= le) =20 prev_len =3D insn->len; =20 + /* Use mapping symbols to skip data in text sections */ + sec_for_each_sym_from(sec, map_sym) { + if (map_sym->offset > offset) + break; + if (is_mapping_sym(map_sym)) + is_data =3D is_data_mapping_sym(map_sym); + } + if (is_data) + insn->type =3D INSN_NOP; + /* * By default, "ud2" is a dead end unless otherwise * annotated, because GCC 7 inserts it for certain diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index 5cba96c6392cb..796d154d447b6 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -296,6 +296,26 @@ static inline bool is_notype_sym(struct symbol *sym) return sym->type =3D=3D STT_NOTYPE; } =20 +/* + * ARM64 mapping symbols ($d, $x, $a, __pi_$d, etc) which mark transitions + * between code and data. + */ +static inline bool is_mapping_sym(struct symbol *sym) +{ + return is_notype_sym(sym) && strchr(sym->name, '$'); +} + +static inline bool is_data_mapping_sym(struct symbol *sym) +{ + const char *dollar; + + if (!is_mapping_sym(sym)) + return false; + + dollar =3D strchr(sym->name, '$'); + return dollar && dollar[1] =3D=3D 'd'; +} + static inline bool is_global_sym(struct symbol *sym) { return sym->bind =3D=3D STB_GLOBAL; @@ -508,6 +528,9 @@ static inline void set_sym_next_reloc(struct reloc *rel= oc, struct reloc *next) #define sec_for_each_sym(sec, sym) \ list_for_each_entry(sym, &sec->symbol_list, list) =20 +#define sec_for_each_sym_from(sec, sym) \ + list_for_each_entry_from(sym, &sec->symbol_list, list) + #define sec_prev_sym(sym) \ sym->sec && sym->list.prev !=3D &sym->sec->symbol_list ? \ list_prev_entry(sym, list) : NULL --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0E87D38A72B; Sat, 8 Aug 2026 23:18:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231125; cv=none; b=bqunMs5YMQ9/aBJmEbaMSFjAPbsfcvGhU/TvBVwtPh0jG7mn3QMAqBHfzeytrlSqPMlrJMV43xZI7QDMJrDDoRt9xkc38P18Px/uFNou3lQADPMtWNGhAdqdGtE1HkZZPXdu+WbhXKMmlgSlAgFBWA+zg+ZPf9tr/c1jJFL48vw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231125; c=relaxed/simple; bh=YVoFnbRXzdAm3656N9+w6Aik7qaf7oeQUVjl7iA969o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=leJMsoWSEsQSD9m6FcJzEmC2zgtQ8pM9nQfpbrGx1qdQRDHiY0xu953WzxodTPZqIJfZw2PakDWWt64RIISq7haJkrQGmwgg8wYD0ofvvGXaYhoBCXX+CYnYCS0tpSbmn602c8/UVnC5n65pyrfXk0Q+tE3dhwvybYSZaheZz6s= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=jAOhwt+8; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="jAOhwt+8" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F33921F00A3A; Sat, 8 Aug 2026 23:18:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231118; bh=ydJP/+WzOb4kIUyHuQZNxhoj1FmudpqW9aVIrC7YUX4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=jAOhwt+8yck4zA1bbe1gc6yQH7RfnncAZbSDQRPdPrEsJgS5C5otJEvDMziBD1h90 kmnEpmrEY8plfNQiCnyMg9XhZFPy/5krJ+XPl+C/EEcY5OZOVeBvzkoWEbeuZO9l69 gx5bMSmPqpr+H3LBU8VJGzWg6/2cA6bKZkbPyc4Whg5L+dzxJgLjHUbFC2F3+vV3lj vKXaR8J8FGTQpT0VyjDCwQmV/tE+/b2Hru3rcfy/ZGAOM9oZvn6SxXxN/jF4enyZC4 QVB1iViYTAutZrdQyF+enu02e3y17xgrP2iZQXTqs6LnOu3Ei2pe9uGu4UvBBxQ2sB Wc2AWfIqFIf/A== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 16/22] objtool/klp: Add arm64 support for prefix/PFE detection Date: Sat, 8 Aug 2026 16:17:20 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add arm64 support for detecting prefixed areas before functions (for kCFI or ftrace with call ops), and __patchable_function_entries (for ftrace with call ops or args). Signed-off-by: Josh Poimboeuf --- tools/objtool/arch/x86/include/arch/elf.h | 2 + tools/objtool/elf.c | 13 ++ tools/objtool/include/objtool/elf.h | 2 + tools/objtool/klp-diff.c | 166 ++++++++++++++++++++-- 4 files changed, 172 insertions(+), 11 deletions(-) diff --git a/tools/objtool/arch/x86/include/arch/elf.h b/tools/objtool/arch= /x86/include/arch/elf.h index 7131f7f51a4e8..5ee0ccda7db18 100644 --- a/tools/objtool/arch/x86/include/arch/elf.h +++ b/tools/objtool/arch/x86/include/arch/elf.h @@ -10,4 +10,6 @@ #define R_TEXT32 R_X86_64_PC32 #define R_TEXT64 R_X86_64_PC32 =20 +#define ARCH_HAS_PREFIX_SYMBOLS 1 + #endif /* _OBJTOOL_ARCH_ELF */ diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c index 3bb04d6155a8b..180e0a0da00ff 100644 --- a/tools/objtool/elf.c +++ b/tools/objtool/elf.c @@ -275,6 +275,19 @@ struct symbol *find_func_containing(struct section *se= c, unsigned long offset) return NULL; } =20 +struct symbol *find_data_mapping_sym(struct section *sec, unsigned long of= fset) +{ + struct rb_root_cached *tree =3D (struct rb_root_cached *)&sec->symbol_tre= e; + struct symbol *sym; + + __sym_for_each(sym, tree, offset, offset) { + if (sym->offset =3D=3D offset && is_data_mapping_sym(sym)) + return sym; + } + + return NULL; +} + struct symbol *find_symbol_by_name(const struct elf *elf, const char *name) { struct symbol *sym; diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index 796d154d447b6..d33d25d7472a0 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -131,6 +131,7 @@ struct elf { struct list_head sections; struct list_head symbols; unsigned long num_relocs; + int pfe_offset; =20 int symbol_bits; int symbol_name_bits; @@ -230,6 +231,7 @@ struct reloc *find_reloc_by_dest(const struct elf *elf,= struct section *sec, uns struct reloc *find_reloc_by_dest_range(const struct elf *elf, struct secti= on *sec, unsigned long offset, unsigned int len); struct symbol *find_func_containing(struct section *sec, unsigned long off= set); +struct symbol *find_data_mapping_sym(struct section *sec, unsigned long of= fset); =20 /* * Try to see if it's a whole archive (vmlinux.o or module). diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index 446ea6f9864a1..922de4c8e9e89 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -20,6 +20,7 @@ #include #include #include +#include =20 #define sizeof_field(TYPE, MEMBER) sizeof((((TYPE *)0)->MEMBER)) =20 @@ -260,6 +261,98 @@ static int read_sym_checksums(struct elf *elf) return 0; } =20 +/* + * For non-x86, detect the offset from the function entry point to its + * __patchable_function_entries (PFE) relocation target. x86 doesn't need= this, + * it clones the __cfi/__pfx symbol instead. + * + * offset < 0 (before function entry): + * + * CONFIG_DYNAMIC_FTRACE_WITH_CALL_OPS (arm64) + * + * offset =3D=3D 0 (at function entry): + * + * CONFIG_DYNAMIC_FTRACE_WITH_ARGS without BTI (arm64) + * + * offset > 0 (after function entry): + * + * CONFIG_DYNAMIC_FTRACE_WITH_ARGS with BTI (arm64) + */ +static int read_pfe_offset(struct elf *elf) +{ + bool has_pfe =3D false; + struct section *sec; + + if (__is_defined(ARCH_HAS_PREFIX_SYMBOLS)) + return 0; + + for_each_sec(elf, sec) { + struct reloc *reloc; + + if (strcmp(sec->name, "__patchable_function_entries")) + continue; + if (!sec->rsec) + continue; + + has_pfe =3D true; + + for_each_reloc(sec->rsec, reloc) { + unsigned long target =3D reloc->sym->offset + reloc_addend(reloc); + struct symbol *func; + + /* arm64 func */ + func =3D find_func_containing(reloc->sym->sec, target); + if (func) { + elf->pfe_offset =3D target - func->offset; + return 0; + } + + /* arm64 CALL_OPS */ + func =3D find_func_by_offset(reloc->sym->sec, target + 8); + if (func) { + elf->pfe_offset =3D -8; + return 0; + } + } + } + + if (has_pfe) { + ERROR("can't find __patchable_function_entries offset"); + return -1; + } + + return 0; +} + +/* + * Detect the size of the area before a function's entry point. This pref= ix + * area is used for CFI type hashes or ftrace call ops. + * + * $d mapping symbol (arm64): + * + * CONFIG_CFI + * + * PFE before function entry, no symbol (arm64): + * + * CONFIG_DYNAMIC_FTRACE_WITH_CALL_OPS + */ +static unsigned long func_pfx_size(struct elf *elf, struct symbol *func) +{ + if (__is_defined(ARCH_HAS_PREFIX_SYMBOLS)) + return 0; + + /* arm64 kCFI $d data mapping symbol */ + if (func->offset >=3D 4 && + find_data_mapping_sym(func->sec, func->offset - 4)) + return 4; + + /* arm64 CALL_OPS (mutually exclusive with kCFI) */ + if (elf->pfe_offset < 0 && func->offset >=3D -elf->pfe_offset) + return -elf->pfe_offset; + + return 0; +} + static struct symbol *first_file_symbol(struct elf *elf) { struct symbol *sym; @@ -348,6 +441,9 @@ static bool is_special_section(struct section *sec) "__ex_table", "__jump_table", "__mcount_loc", +#ifndef ARCH_HAS_PREFIX_SYMBOLS + "__patchable_function_entries", +#endif =20 /* * Extract .static_call_sites here to inherit non-module @@ -918,7 +1014,7 @@ static struct symbol *__clone_symbol(struct elf *elf, = struct symbol *patched_sym bool data_too) { struct section *out_sec =3D NULL; - unsigned long offset =3D 0; + unsigned long offset =3D 0, pfx_size =3D 0; struct symbol *out_sym; =20 if (data_too && !is_undef_sym(patched_sym)) { @@ -950,17 +1046,22 @@ static struct symbol *__clone_symbol(struct elf *elf= , struct symbol *patched_sym void *data =3D NULL; size_t size; =20 + /* Clone (non-x86) function prefix area */ + pfx_size =3D is_func_sym(patched_sym) ? func_pfx_size(elf, patched_sym)= : 0; + /* bss doesn't have data */ if (patched_sym->sec->data && patched_sym->sec->data->d_buf) - data =3D patched_sym->sec->data->d_buf + patched_sym->offset; + data =3D patched_sym->sec->data->d_buf + patched_sym->offset - pfx_siz= e; =20 if (is_sec_sym(patched_sym)) size =3D sec_size(patched_sym->sec); else - size =3D patched_sym->len; + size =3D patched_sym->len + pfx_size; =20 if (!elf_add_data(elf, out_sec, data, size)) return NULL; + + offset +=3D pfx_size; } } =20 @@ -1235,21 +1336,41 @@ static int convert_reloc_sym_to_secsym(struct elf *= elf, struct reloc *reloc) return 0; } =20 +/* + * __patchable_function_entries relocs point to the patchable entry NOPs, + * which are at 'pfe_offset' bytes from the function symbol. + * + * Some entries (e.g., removed weak functions, syscall -ENOSYS stubs) don't + * have a corresponding function symbol. Skip those with a return value o= f 1. + */ +static int convert_pfe_reloc(struct elf *elf, struct reloc *reloc) +{ + struct symbol *func; + + func =3D find_func_by_offset(reloc->sym->sec, + reloc->sym->offset + + reloc_addend(reloc) - elf->pfe_offset); + if (!func) + return 1; + + reloc->sym =3D func; + set_reloc_sym(elf, reloc, func->idx); + set_reloc_addend(elf, reloc, elf->pfe_offset); + return 0; +} + /* Return -1 error, 0 success, 1 skip */ static int convert_reloc_secsym_to_sym(struct elf *elf, struct reloc *relo= c) { struct symbol *sym =3D reloc->sym; struct section *sec =3D sym->sec; =20 + if (!strcmp(reloc->sec->name, ".rela__patchable_function_entries")) + return convert_pfe_reloc(elf, reloc); + if (!is_sec_sym(sym)) return 0; =20 - /* If the symbol has a dedicated section, it's easy to find */ - sym =3D find_symbol_by_offset(sec, 0); - if (sym && sym->len =3D=3D sec_size(sec)) - goto found_sym; - - /* No dedicated section; find the symbol manually */ sym =3D find_symbol_containing_inclusive(sec, arch_adjusted_addend(reloc)= ); if (!sym) { /* @@ -1277,7 +1398,6 @@ static int convert_reloc_secsym_to_sym(struct elf *el= f, struct reloc *reloc) return -1; } =20 -found_sym: reloc->sym =3D sym; set_reloc_sym(elf, reloc, sym->idx); set_reloc_addend(elf, reloc, reloc_addend(reloc) - sym->offset); @@ -1925,6 +2045,9 @@ static int validate_special_section_klp_reloc(struct = elfs *e, struct symbol *sym =20 static int clone_special_section(struct elfs *e, struct section *patched_s= ec) { + bool is_pfe =3D !strcmp(patched_sec->name, "__patchable_function_entries"= ); + struct section *out_sec =3D NULL; + struct reloc *patched_reloc; struct symbol *patched_sym; =20 /* @@ -1932,6 +2055,7 @@ static int clone_special_section(struct elfs *e, stru= ct section *patched_sec) * reference included functions. */ sec_for_each_sym(patched_sec, patched_sym) { + struct symbol *out_sym; int ret; =20 if (!is_object_sym(patched_sym)) @@ -1946,8 +2070,23 @@ static int clone_special_section(struct elfs *e, str= uct section *patched_sec) if (ret > 0) continue; =20 - if (!clone_symbol(e, patched_sym, true)) + out_sym =3D clone_symbol(e, patched_sym, true); + if (!out_sym) return -1; + + if (!is_pfe || (out_sec && out_sec->sh.sh_link)) + continue; + + /* + * For reasons, the patched object has multiple PFE sections, + * but we only need to create one combined section for the + * output. Link the single PFE ouput section to a random text + * section to satisfy the linker for SHF_LINK_ORDER. + */ + out_sec =3D out_sym->sec; + patched_reloc =3D find_reloc_by_dest(e->patched, patched_sec, + patched_sym->offset); + out_sec->sh.sh_link =3D patched_reloc->sym->clone->sec->idx; } =20 return 0; @@ -2247,6 +2386,9 @@ int cmd_klp_diff(int argc, const char **argv) if (read_sym_checksums(e.patched)) return -1; =20 + if (read_pfe_offset(e.patched)) + return -1; + if (correlate_symbols(&e)) return -1; =20 @@ -2260,6 +2402,8 @@ int cmd_klp_diff(int argc, const char **argv) if (!e.out) return -1; =20 + e.out->pfe_offset =3D e.patched->pfe_offset; + /* * Special section fake symbols are needed so that individual special * section entries can be extracted by clone_special_sections(). --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85E7B37DAA9; Sat, 8 Aug 2026 23:18:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231123; cv=none; b=reDQ1gPBNQ5osWaiGTibxsdt+ou7QZXZOpjLlPDdDiHcfoC3hxElkLTzA+wnujxACofoK06AoiZe3iD3gQJOVvoe6rWX5JOiin1OlgI5CzoXmyOYSGwjdGrY2oCA8LHXOE4dnrUUqKoWZvHI8lRCG3mF+1jXcgA7QTCTf42RtCw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231123; c=relaxed/simple; bh=XvQzrveZy8keOwU3dsD3MwA/DM/UEranRTFFfT4zB5A=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PhurpoVK7U5lJKefNKOW6uOMcfosMGmXnoYFOMD+mpRenjnebaj/Y364R4Y6qp0BXPJCW7cDZIQ+shbghyKDS3WKHlq9TtK/LGxQcnN+5ELrp7Uhj5Ywza79OAVB0qgKHghLbpm6Fp/YzQYbZM9sf4RwWLfe5fIPm8FzLVmgARI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=A6z/ksTt; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="A6z/ksTt" Received: by smtp.kernel.org (Postfix) with ESMTPSA id C94161F00ADE; Sat, 8 Aug 2026 23:18:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231119; bh=86Wu1e1fcjC+Q8R7XTOaEvr/qEDKKmtBvafngqJL0GY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=A6z/ksTtDqX8xK/Pg8CXwXiVstVJiHyhOq+A/N0C9Xf/FjsMOM0cvO323+zp7/9M4 kPZQ/1VUQV++1ZdNOa6TlleV5cGCZ9bfhhMjI/Art7YBB1/INMBdPpqVVmgsvvk9Xp kF69ORpK31ONF/4wWNWYFxA2u93421BShKk2qf6rK3sn2ZLF9Y57uJr/IODREruh9w yn5f+eLZYRvOq4/Nye/KvOKkvbFhl1P1P7qFeicOpolMjQMjk4I0pta8L2WnGGbOEd fev60tWWdcWzGOOlAkzJ4C6hLSisj4awzKqmkTiZGkmWIVTZwXAv4bJB1cP+hS5bLm 2al7Qa9FiS8sg== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 17/22] objtool/klp: Filter arm64 mapping symbols in find_symbol_by_offset() Date: Sat, 8 Aug 2026 16:17:21 -0700 Message-ID: <9b74908379fb4054ff30a7e0960606baec08c555.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ARM64 ELF objects contain $d/$x mapping symbols (STT_NOTYPE) at offset 0 in data/text sections. These aren't "real" symbols so filter them from find_symbol_by_offset(), consistent with the existing section symbol filter. Acked-by: Song Liu Signed-off-by: Josh Poimboeuf --- tools/objtool/elf.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c index 180e0a0da00ff..f9d49325dbe0d 100644 --- a/tools/objtool/elf.c +++ b/tools/objtool/elf.c @@ -160,7 +160,7 @@ struct symbol *find_symbol_by_offset(struct section *se= c, unsigned long offset) struct symbol *sym; =20 __sym_for_each(sym, tree, offset, offset) { - if (sym->offset =3D=3D offset && !is_sec_sym(sym)) + if (sym->offset =3D=3D offset && !is_sec_sym(sym) && !is_mapping_sym(sym= )) return sym->alias; } =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 49830385D6B; Sat, 8 Aug 2026 23:18:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; cv=none; b=Bni2neI4DDqUzGMp1R4ltabPTbdkfEu1WHMcbAGKGHd2VxgZWrvRaxsm+okahhdrWtnb77+w/3en/9MnKvpsr1C28hPs+YWHjhQJZKH7bnKKBFquk7az0+U3pgAdHIhCOZxDQ4nmd6nKsV80JT31Cd45mGU9AAiJZqQIRPu68ZI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231122; c=relaxed/simple; bh=zWIcILwnaJABpKZunmDvRsbIFq/DGE03mUS5xRz5OH8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VnymkKFi2u09H90B5E2byCSnaU6Cb17GkO7iGtJOkcXb/azfY9awvTrU/Ds/9MHTZplhHQQwnhajHLXXSOV5a3mGZM9UUtwCz9jX1okHbRY+rVwcXHT5O4bxFUPB1/zxNi8bw7f2A65G1jS66J9SwNufWSbTUb5uqkAjEnHqdsA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=RT1iFVvG; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="RT1iFVvG" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 98D731F00A3F; Sat, 8 Aug 2026 23:18:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231120; bh=hySmyd731HI49avcL3mGbdogr26/7EmNX03BPEob+mA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=RT1iFVvGtNC2gfYcDpnLWRYJLfm5w7eX6mO4qrzXUAdm86P6zRE8FFRXT19V3JtGR +VfH3Nk5Q+Q1URgGUrDDZfbE6zKOqIQGpnQHY1f5is8ymGHtdZ97PBso9YxLHoEJwC yXv8N/H//e1dwgQp4GV741X/jt2uWPjbPsxAGewR2i6BrQBCyoss2LjIfRql4dEfE5 PgAJZOxOHwvDzZyPfFQA4qMe58nUTDW67rsfZEhkXCNYCKda3VgQ6Sztu2Xm4hUNGD eePgLajX4W1sqMfi/ZG3OkaaKeEMtG17p7caU4j8GyTh+UMRhM1jmeCY0Zgi2AfEwm myIaTm+M+i2EA== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 18/22] objtool/klp: Don't correlate arm64 mapping symbols Date: Sat, 8 Aug 2026 16:17:22 -0700 Message-ID: <6f447024ac8b79a1a6f1b8eb1c5eb1b51017af79.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ARM64 ELF files contain mapping symbols ($d, $x, $a, etc.) which mark transitions between code and data. There are thousands of them per object file, all sharing the same few names. They aren't "real" symbols so there's no need to correlate them. Signed-off-by: Josh Poimboeuf Acked-by: Song Liu --- tools/objtool/klp-diff.c | 1 + 1 file changed, 1 insertion(+) diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index 922de4c8e9e89..d76d2f5b5acbf 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -547,6 +547,7 @@ static bool dont_correlate(struct symbol *sym) is_prefix_func(sym) || is_uncorrelated_static_local(sym) || is_local_label(sym) || + is_mapping_sym(sym) || is_string_sec(sym->sec) || is_anonymous_rodata(sym) || is_initcall_sym(sym) || --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0AFF9384228; Sat, 8 Aug 2026 23:18:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231123; cv=none; b=B5HqJxRcc95AJrWf3IHMWAVFJzKsBC7WaIeY1KCAjngwnWxCAL9Xyn6/9NBpE5/w17N8OXhmFAQClZ5qjQLIwrw/XBr2ZqjJk85ZjKSJQ7are6T6iMqXcs9gvAl9ak4e7Rr/vAXzp7OKjWBlgZmyJwShq5KJRHxk+uywN+lXe1o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231123; c=relaxed/simple; bh=NS6tK0Zo79hmFyEYzvb1IpQSDc7aH+6k5s86Qwj3jB0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=UgCTfTXw0kjJn4o0nZQ+hJ/GVNP4aN923GxouFDf2yjtBRtKfKfdEWMlJwgEr4elb/mxLjkIriFcACMg5OQc21K6reG8O9wg9jFt7GNKmrQamIUGxZegezl5sHqzRwv2HV66KhwMcFmrB8V20vCX7pNLKhXi2I05S5G+wsCovks= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=kTe+Ym3S; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="kTe+Ym3S" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 589B31F00A3D; Sat, 8 Aug 2026 23:18:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231120; bh=vxvjU/LsBii/ygttaMwT+U6HhQA2XQkmzKkMSjzc2JU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=kTe+Ym3SyOyvbhzj+vexDJPDKp5QznjYuV0/J1odXdOPapukSUlK5kTHtV6fDtOCV uiyboZfn3bst/unAiZHD/HRxg/a7Q5R64Wo5QP1PHhYpW2cu+wPcKRqqjpOajS4bFD Gq2m1JOZEtrK76TKVw20ruLXXMkJh1xelDOuIwZPnilpzz9NoBQk+TE8ZQb9MQt0Ee eUqBVn8l4/7pZ889RonqNjbRWdkM1Ur6pbDaphvURfK9a0gfTFht3CM8ZI/exqBnH1 gCCyZBgPf87kB91C3xWkzES0YNLORwdeoC3Ee9dBl7hegWxwsyvbli8Og/pnXPZfOm 2ie51YjEwSxvw== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 19/22] objtool/klp: Clone inline alternative replacements Date: Sat, 8 Aug 2026 16:17:23 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Unlike x86-64, arm64 places alternative replacement instructions in .text, immediately after the affected function. So if the replacement instructions have PC-relative branches without relocations, their offsets relative to the function have to remain constant. Achieve that by cloning the function's alternative replacements immediately after cloning the function itself. Signed-off-by: Josh Poimboeuf --- tools/objtool/elf.c | 9 ++--- tools/objtool/include/objtool/elf.h | 6 +++- tools/objtool/klp-diff.c | 54 ++++++++++++++++++++++++----- tools/objtool/klp-symid.c | 2 +- 4 files changed, 57 insertions(+), 14 deletions(-) diff --git a/tools/objtool/elf.c b/tools/objtool/elf.c index f9d49325dbe0d..f6219f495efdc 100644 --- a/tools/objtool/elf.c +++ b/tools/objtool/elf.c @@ -1426,14 +1426,15 @@ int elf_add_string(struct elf *elf, struct section = *strtab, const char *str) return -1; } =20 - data =3D elf_add_data(elf, strtab, str, strlen(str) + 1); + data =3D elf_add_data(elf, strtab, str, strlen(str) + 1, true); if (!data) return -1; =20 return data - strtab->data->d_buf; } =20 -void *elf_add_data(struct elf *elf, struct section *sec, const void *data,= size_t size) +void *elf_add_data(struct elf *elf, struct section *sec, const void *data, + size_t size, bool align) { unsigned long offset, size_old, size_new, alloc_size_old, alloc_size_new; Elf_Scn *s; @@ -1460,7 +1461,7 @@ void *elf_add_data(struct elf *elf, struct section *s= ec, const void *data, size_ } =20 size_old =3D sec->data->d_size; - offset =3D ALIGN(size_old, sec->sh.sh_addralign); + offset =3D ALIGN(size_old, align ? sec->sh.sh_addralign : 1); size_new =3D offset + size; =20 if (!sec->data_overallocated) @@ -1603,7 +1604,7 @@ static int elf_alloc_reloc(struct elf *elf, struct se= ction *rsec) unsigned long nr_alloc_old =3D 0, nr_alloc_new; struct symbol *sym; =20 - if (!elf_add_data(elf, rsec, NULL, elf_rela_size(elf))) + if (!elf_add_data(elf, rsec, NULL, elf_rela_size(elf), true)) return -1; =20 rsec->data->d_type =3D ELF_T_RELA; diff --git a/tools/objtool/include/objtool/elf.h b/tools/objtool/include/ob= jtool/elf.h index d33d25d7472a0..fba0a0e08f8b6 100644 --- a/tools/objtool/include/objtool/elf.h +++ b/tools/objtool/include/objtool/elf.h @@ -107,6 +107,7 @@ struct symbol { u8 klp : 1; u8 dont_correlate : 1; u8 fake : 1; + u8 unalign : 1; struct list_head pv_target; struct reloc *relocs; struct section *group_sec; @@ -187,7 +188,7 @@ struct symbol *elf_create_symbol(struct elf *elf, const= char *name, struct symbol *elf_create_section_symbol(struct elf *elf, struct section *= sec); =20 void *elf_add_data(struct elf *elf, struct section *sec, const void *data, - size_t size); + size_t size, bool align); =20 int elf_find_string(struct elf *elf, struct section *strtab, const char *s= tr); int elf_add_string(struct elf *elf, struct section *strtab, const char *st= r); @@ -533,6 +534,9 @@ static inline void set_sym_next_reloc(struct reloc *rel= oc, struct reloc *next) #define sec_for_each_sym_from(sec, sym) \ list_for_each_entry_from(sym, &sec->symbol_list, list) =20 +#define sec_for_each_sym_continue(sec, sym) \ + list_for_each_entry_continue(sym, &sec->symbol_list, list) + #define sec_prev_sym(sym) \ sym->sec && sym->list.prev !=3D &sym->sec->symbol_list ? \ list_prev_entry(sym, list) : NULL diff --git a/tools/objtool/klp-diff.c b/tools/objtool/klp-diff.c index d76d2f5b5acbf..841651e3ad746 100644 --- a/tools/objtool/klp-diff.c +++ b/tools/objtool/klp-diff.c @@ -1014,8 +1014,9 @@ static int clone_sym_relocs(struct elfs *e, struct sy= mbol *patched_sym); static struct symbol *__clone_symbol(struct elf *elf, struct symbol *patch= ed_sym, bool data_too) { - struct section *out_sec =3D NULL; unsigned long offset =3D 0, pfx_size =3D 0; + bool align =3D !patched_sym->unalign; + struct section *out_sec =3D NULL; struct symbol *out_sym; =20 if (data_too && !is_undef_sym(patched_sym)) { @@ -1041,7 +1042,7 @@ static struct symbol *__clone_symbol(struct elf *elf,= struct symbol *patched_sym } =20 if (!is_sec_sym(patched_sym)) - offset =3D ALIGN(sec_size(out_sec), out_sec->sh.sh_addralign); + offset =3D ALIGN(sec_size(out_sec), align ? out_sec->sh.sh_addralign : = 1); =20 if (patched_sym->len || is_sec_sym(patched_sym)) { void *data =3D NULL; @@ -1059,7 +1060,7 @@ static struct symbol *__clone_symbol(struct elf *elf,= struct symbol *patched_sym else size =3D patched_sym->len + pfx_size; =20 - if (!elf_add_data(elf, out_sec, data, size)) + if (!elf_add_data(elf, out_sec, data, size, align)) return NULL; =20 offset +=3D pfx_size; @@ -1101,6 +1102,37 @@ static const char *sym_bind(struct symbol *sym) } } =20 +static struct symbol *clone_symbol(struct elfs *e, struct symbol *patched_= sym, + bool data_too); + +/* + * For arm64 alternatives, the replacement instructions come immediately a= fter + * the function. Clone any such blocks of instructions in place to preser= ve + * their offsets relative to the function in case they have hard-coded PC + * relative branches. + */ +static int clone_inline_alternatives(struct elfs *e, struct symbol *patche= d_sym) +{ + struct symbol *next; + + if (!__is_defined(ARCH_HAS_INLINE_ALTS) || !is_func_sym(patched_sym)) + return 0; + + next =3D patched_sym; + sec_for_each_sym_continue(patched_sym->sec, next) { + if (next->offset < (patched_sym->offset + patched_sym->len) || + is_mapping_sym(next)) + continue; + if (!next->fake) + break; + next->unalign =3D 1; + if (!clone_symbol(e, next, true)) + return -1; + } + + return 0; +} + /* * Copy a symbol to the output object, optionally including its data and * relocations. @@ -1125,7 +1157,13 @@ static struct symbol *clone_symbol(struct elfs *e, s= truct symbol *patched_sym, if (!__clone_symbol(e->out, patched_sym, data_too)) return NULL; =20 - if (data_too && clone_sym_relocs(e, patched_sym)) + if (!data_too || is_undef_sym(patched_sym)) + return patched_sym->clone; + + if (clone_sym_relocs(e, patched_sym)) + return NULL; + + if (clone_inline_alternatives(e, patched_sym)) return NULL; =20 return patched_sym->clone; @@ -1585,7 +1623,7 @@ static int clone_reloc_klp(struct elfs *e, struct rel= oc *patched_reloc, memset(&klp_reloc, 0, sizeof(klp_reloc)); =20 klp_reloc.type =3D reloc_type(patched_reloc); - if (!elf_add_data(e->out, klp_relocs, &klp_reloc, sizeof(klp_reloc))) + if (!elf_add_data(e->out, klp_relocs, &klp_reloc, sizeof(klp_reloc), true= )) return -1; =20 /* klp_reloc.offset */ @@ -2164,7 +2202,7 @@ static int create_klp_sections(struct elfs *e) return -1; =20 /* allocate klp_object_ext */ - obj_data =3D elf_add_data(e->out, obj_sec, NULL, obj_size); + obj_data =3D elf_add_data(e->out, obj_sec, NULL, obj_size, true); if (!obj_data) return -1; =20 @@ -2199,7 +2237,7 @@ static int create_klp_sections(struct elfs *e) continue; =20 /* allocate klp_func_ext */ - func_data =3D elf_add_data(e->out, funcs_sec, NULL, func_size); + func_data =3D elf_add_data(e->out, funcs_sec, NULL, func_size, true); if (!func_data) return -1; =20 @@ -2345,7 +2383,7 @@ static int copy_import_ns(struct elfs *e) } } =20 - if (!elf_add_data(e->out, out_sec, import_ns, strlen(import_ns) + 1)) + if (!elf_add_data(e->out, out_sec, import_ns, strlen(import_ns) + 1, tru= e)) return -1; } =20 diff --git a/tools/objtool/klp-symid.c b/tools/objtool/klp-symid.c index 21d8708013aba..1934c2a1afc4d 100644 --- a/tools/objtool/klp-symid.c +++ b/tools/objtool/klp-symid.c @@ -95,7 +95,7 @@ int klp_create_symid_sections(struct objtool_file *file) if (!sec) return -1; =20 - symids =3D elf_add_data(elf, sec, NULL, nr * sizeof(struct klp_symid)); + symids =3D elf_add_data(elf, sec, NULL, nr * sizeof(struct klp_symid), tr= ue); if (!symids) return -1; =20 --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C3713387581; Sat, 8 Aug 2026 23:18:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; cv=none; b=JTxWohJSbtjT+I+UDOrgajKF8U6Fn2gZHpN9zq4U90yKczKL8s5jgYVUu2jREuH/yi8N185rZHKvhHI9A2dMIZMweCDzGp8hXqba65SevT1kLvdl/6EEsexiwFTORR7xCr3nQ5p0vDQHAGPZibEOm379NKkQu9lLIA4lZLYMU9k= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; c=relaxed/simple; bh=mYNjrSrietAgHAC06ZiWhNlodDbg6uK/9koSoQQLSgw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pBd90/1RtlY3+0TmieJmo3zMgZGc6zkedc4eALXEfyHrhf6DIQsKjdvSqNe5a0fiBW8pmZq+oThsUOi4kpMuHPBlEnfqyVcl27J/hy+xMl1xmF0QxeDLOc5YlgPrjG3Crcq8hsy/cUxsfna4ic6CyFGSZ404Y9GyFZDJRcdRHVc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ITKKCm5P; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ITKKCm5P" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 152381F01558; Sat, 8 Aug 2026 23:18:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231121; bh=Be3iB63/Gi5xDaGZSUXwPMb6b9lt0/rDWU2nNBXifRk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ITKKCm5PhWs9WBCtcXA3mUlo/KSk95vOKS5DFNExB/Vaw3M+myEV/ZPEU0zaQRC5s X5MmAVqU6MsEk/eVtr5t7eCPA7ZAhSrmqzs31hpR32GcXLJXxA/8UFVkZe6Qd5DgJj qfG+pcl+J0Tpt35tKSNbPXe2qigzoxzWgQW1tFILByxhLGmwRjq7DXApsWbstzDDk5 yUJ4jpAsEGaQ38q2xpeCVtoCnYfjR54E3eabCkEcacqrIq/tra6twW0rmXuK4p9Dso K+UuslRHTpbxKgREbiUamW9zGpJIFit7sGLQXQvlBfKMrYmsxTOJFA6iQWt5plWspx sicNTRFivDdBw== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 20/22] objtool/klp: Introduce objtool for arm64 Date: Sat, 8 Aug 2026 16:17:24 -0700 Message-ID: <73024f3fce343bd6fba3d08fa366a61b4e2c0fa1.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add basic support for arm64 on objtool. Only "objtool klp" subcommands are currently supported. Signed-off-by: Josh Poimboeuf --- arch/arm64/Kconfig | 2 + tools/objtool/Makefile | 4 + tools/objtool/arch/arm64/Build | 2 + tools/objtool/arch/arm64/decode.c | 177 ++++++++++++++++++ .../arch/arm64/include/arch/cfi_regs.h | 11 ++ tools/objtool/arch/arm64/include/arch/elf.h | 15 ++ .../objtool/arch/arm64/include/arch/special.h | 21 +++ tools/objtool/arch/arm64/special.c | 30 +++ 8 files changed, 262 insertions(+) create mode 100644 tools/objtool/arch/arm64/Build create mode 100644 tools/objtool/arch/arm64/decode.c create mode 100644 tools/objtool/arch/arm64/include/arch/cfi_regs.h create mode 100644 tools/objtool/arch/arm64/include/arch/elf.h create mode 100644 tools/objtool/arch/arm64/include/arch/special.h create mode 100644 tools/objtool/arch/arm64/special.c diff --git a/arch/arm64/Kconfig b/arch/arm64/Kconfig index 11e733b6a3cf3..06b30924509ac 100644 --- a/arch/arm64/Kconfig +++ b/arch/arm64/Kconfig @@ -209,9 +209,11 @@ config ARM64 select HAVE_HW_BREAKPOINT if PERF_EVENTS select HAVE_IOREMAP_PROT select HAVE_IRQ_TIME_ACCOUNTING + select HAVE_KLP_BUILD select HAVE_LIVEPATCH select HAVE_MOD_ARCH_SPECIFIC select HAVE_NMI + select HAVE_OBJTOOL select HAVE_PERF_EVENTS select HAVE_PERF_EVENTS_NMI if ARM64_PSEUDO_NMI select HAVE_PERF_REGS diff --git a/tools/objtool/Makefile b/tools/objtool/Makefile index a4484fd22a96d..94aabeee97367 100644 --- a/tools/objtool/Makefile +++ b/tools/objtool/Makefile @@ -11,6 +11,10 @@ ifeq ($(SRCARCH),loongarch) BUILD_ORC :=3D y endif =20 +ifeq ($(SRCARCH),arm64) + ARCH_HAS_KLP :=3D y +endif + ifeq ($(ARCH_HAS_KLP),y) HAVE_XXHASH =3D $(shell printf "$(pound)include \nXXH3_state_t = *state;int main() {}" | \ $(HOSTCC) $(HOSTCFLAGS) -xc - -o /dev/null -lxxhash 2> /dev/null &= & echo y || echo n) diff --git a/tools/objtool/arch/arm64/Build b/tools/objtool/arch/arm64/Build new file mode 100644 index 0000000000000..d24d5636a5b84 --- /dev/null +++ b/tools/objtool/arch/arm64/Build @@ -0,0 +1,2 @@ +objtool-y +=3D decode.o +objtool-y +=3D special.o diff --git a/tools/objtool/arch/arm64/decode.c b/tools/objtool/arch/arm64/d= ecode.c new file mode 100644 index 0000000000000..47658c76e1af0 --- /dev/null +++ b/tools/objtool/arch/arm64/decode.c @@ -0,0 +1,177 @@ +// SPDX-License-Identifier: GPL-2.0-or-later + +#include +#include +#include +#include +#include +#include +#include +#include + +const char *arch_reg_name[CFI_NUM_REGS] =3D {}; + +int arch_ftrace_match(const char *name) +{ + return 0; +} + +s64 arch_insn_adjusted_addend(struct instruction *insn, struct reloc *relo= c) +{ + return reloc_addend(reloc); +} + +bool arch_callee_saved_reg(unsigned char reg) +{ + return false; +} + +int arch_decode_hint_reg(u8 sp_reg, int *base) +{ + exit(-1); +} + +const char *arch_nop_insn(int len) +{ + exit(-1); +} + +const char *arch_ret_insn(int len) +{ + exit(-1); +} + +int arch_decode_instruction(struct objtool_file *file, const struct sectio= n *sec, + unsigned long offset, unsigned int maxlen, + struct instruction *insn) +{ + u32 ins; + + if (maxlen < 4) { + ERROR_INSN(insn, "can't decode instruction"); + return -1; + } + + /* arm64 instructions are always LE, thus no bswap_if_needed() */ + ins =3D le32toh(*(u32 *)(sec->data->d_buf + offset)); + + /* + * These are the bare minimum needed for static branch detection and + * checksum calculations. + */ + if (ins =3D=3D 0xd503201f) { + /* NOP: static branch */ + insn->type =3D INSN_NOP; + } else if ((ins & 0xfc000000) =3D=3D 0x14000000) { + /* B: static branch, intra-TU sibling call */ + insn->type =3D INSN_JUMP_UNCONDITIONAL; + insn->immediate =3D sign_extend64(ins & 0x03ffffff, 25); + } else if ((ins & 0xfc000000) =3D=3D 0x94000000) { + /* BL: intra-TU call */ + insn->type =3D INSN_CALL; + insn->immediate =3D sign_extend64(ins & 0x03ffffff, 25); + } else if ((ins & 0xff000000) =3D=3D 0x54000000) { + /* B.cond: intra-TU sibling call */ + insn->type =3D INSN_JUMP_CONDITIONAL; + insn->immediate =3D sign_extend64((ins >> 5) & 0x7ffff, 18); + } else if ((ins & 0x7e000000) =3D=3D 0x34000000) { + /* CBZ/CBNZ: intra-TU sibling call */ + insn->type =3D INSN_JUMP_CONDITIONAL; + insn->immediate =3D sign_extend64((ins >> 5) & 0x7ffff, 18); + } else if ((ins & 0x7e000000) =3D=3D 0x36000000) { + /* TBZ/TBNZ: intra-TU sibling call */ + insn->type =3D INSN_JUMP_CONDITIONAL; + insn->immediate =3D sign_extend64((ins >> 5) & 0x3fff, 13); + } else { + insn->type =3D INSN_OTHER; + } + + insn->len =3D 4; + return 0; +} + +size_t arch_jump_opcode_bytes(struct objtool_file *file, struct instructio= n *insn, + unsigned char *buf) +{ + u32 ins; + + ins =3D le32toh(*(u32 *)(insn->sec->data->d_buf + insn->offset)); + + switch (insn->type) { + case INSN_JUMP_UNCONDITIONAL: + case INSN_CALL: + ins &=3D ~0x03ffffff; + break; + case INSN_JUMP_CONDITIONAL: + if ((ins & 0xff000000) =3D=3D 0x54000000) + ins &=3D ~0x00ffffe0; /* B.cond */ + else if ((ins & 0x7e000000) =3D=3D 0x34000000) + ins &=3D ~0x00ffffe0; /* CBZ/CBNZ */ + else + ins &=3D ~0x0007ffe0; /* TBZ/TBNZ */ + break; + default: + break; + } + + ins =3D htole32(ins); + memcpy(buf, &ins, 4); + return 4; +} + +u64 arch_adjusted_addend(struct reloc *reloc) +{ + return reloc_addend(reloc); +} + +unsigned long arch_jump_destination(struct instruction *insn) +{ + return insn->offset + (insn->immediate << 2); +} + +bool arch_pc_relative_reloc(struct reloc *reloc) +{ + switch (reloc_type(reloc)) { + case R_AARCH64_PREL64: + case R_AARCH64_PREL32: + case R_AARCH64_PREL16: + case R_AARCH64_LD_PREL_LO19: + case R_AARCH64_ADR_PREL_LO21: + case R_AARCH64_ADR_PREL_PG_HI21: + case R_AARCH64_ADR_PREL_PG_HI21_NC: + case R_AARCH64_JUMP26: + case R_AARCH64_CALL26: + case R_AARCH64_CONDBR19: + case R_AARCH64_TSTBR14: + return true; + default: + return false; + } +} + +void arch_initial_func_cfi_state(struct cfi_init_state *state) +{ + state->cfa.base =3D CFI_UNDEFINED; +} + +unsigned int arch_reloc_size(struct reloc *reloc) +{ + switch (reloc_type(reloc)) { + case R_AARCH64_ABS64: + case R_AARCH64_PREL64: + return 8; + case R_AARCH64_PREL16: + return 2; + default: + return 4; + } +} + +#ifdef DISAS +int arch_disas_info_init(struct disassemble_info *dinfo) +{ + return disas_info_init(dinfo, bfd_arch_aarch64, + bfd_mach_arm_unknown, bfd_mach_aarch64, + NULL); +} +#endif /* DISAS */ diff --git a/tools/objtool/arch/arm64/include/arch/cfi_regs.h b/tools/objto= ol/arch/arm64/include/arch/cfi_regs.h new file mode 100644 index 0000000000000..49c81cbb6646d --- /dev/null +++ b/tools/objtool/arch/arm64/include/arch/cfi_regs.h @@ -0,0 +1,11 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +#ifndef _OBJTOOL_ARCH_CFI_REGS_H +#define _OBJTOOL_ARCH_CFI_REGS_H + +/* These aren't actually used for arm64 */ +#define CFI_BP 0 +#define CFI_SP 0 +#define CFI_RA 0 +#define CFI_NUM_REGS 2 + +#endif /* _OBJTOOL_ARCH_CFI_REGS_H */ diff --git a/tools/objtool/arch/arm64/include/arch/elf.h b/tools/objtool/ar= ch/arm64/include/arch/elf.h new file mode 100644 index 0000000000000..418b90885c501 --- /dev/null +++ b/tools/objtool/arch/arm64/include/arch/elf.h @@ -0,0 +1,15 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +#ifndef _OBJTOOL_ARCH_ELF_H +#define _OBJTOOL_ARCH_ELF_H + +#define R_NONE R_AARCH64_NONE +#define R_ABS64 R_AARCH64_ABS64 +#define R_ABS32 R_AARCH64_ABS32 +#define R_DATA32 R_AARCH64_PREL32 +#define R_DATA64 R_AARCH64_PREL64 +#define R_TEXT32 R_AARCH64_PREL32 +#define R_TEXT64 R_AARCH64_PREL64 + +#define ARCH_HAS_INLINE_ALTS 1 + +#endif /* _OBJTOOL_ARCH_ELF_H */ diff --git a/tools/objtool/arch/arm64/include/arch/special.h b/tools/objtoo= l/arch/arm64/include/arch/special.h new file mode 100644 index 0000000000000..8ae804a83ea49 --- /dev/null +++ b/tools/objtool/arch/arm64/include/arch/special.h @@ -0,0 +1,21 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +#ifndef _OBJTOOL_ARCH_SPECIAL_H +#define _OBJTOOL_ARCH_SPECIAL_H + +#define EX_ENTRY_SIZE 12 +#define EX_ORIG_OFFSET 0 +#define EX_NEW_OFFSET 4 + +#define JUMP_ENTRY_SIZE 16 +#define JUMP_ORIG_OFFSET 0 +#define JUMP_NEW_OFFSET 4 +#define JUMP_KEY_OFFSET 8 + +#define ALT_ENTRY_SIZE 12 +#define ALT_ORIG_OFFSET 0 +#define ALT_NEW_OFFSET 4 +#define ALT_FEATURE_OFFSET 8 +#define ALT_ORIG_LEN_OFFSET 10 +#define ALT_NEW_LEN_OFFSET 11 + +#endif /* _OBJTOOL_ARCH_SPECIAL_H */ diff --git a/tools/objtool/arch/arm64/special.c b/tools/objtool/arch/arm64/= special.c new file mode 100644 index 0000000000000..5a6424a59e1c5 --- /dev/null +++ b/tools/objtool/arch/arm64/special.c @@ -0,0 +1,30 @@ +// SPDX-License-Identifier: GPL-2.0-or-later +#include + +/* + * On arm64 a zero-length replacement means the alternative has a callback, + * whose address is stored in the replacement offset. It must be preserve= d. + */ +bool arch_alt_ignore_new_reloc(struct section *sec, unsigned long offset) +{ + return false; +} + +bool arch_support_alt_relocation(struct special_alt *special_alt, + struct instruction *insn, + struct reloc *reloc) +{ + return true; +} + +struct reloc *arch_find_switch_table(struct objtool_file *file, + struct instruction *insn, + unsigned long *table_size) +{ + return NULL; +} + +const char *arch_cpu_feature_name(int feature_number) +{ + return NULL; +} --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 85679388E4B; Sat, 8 Aug 2026 23:18:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; cv=none; b=MIYrZL6QNPK04Kt0xZolNV9ePdGncIP/estcxrzwOuzTFUTaZCdHxluSTBP4ETV4jNJfE9fgfoRGv9Ph/SE8NBBv5g6yuVw9ooDuAPWblU1yiT7DHFEFP4H4Rw8S7xIMkiu3kpKHKvWmznfP1npTHExd/UBXRH771db4wIiq5rE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; c=relaxed/simple; bh=nhW1F5H9nmricWa4c2xy/pUK/i+6+4LecwZeRNFyQYI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=rr+DRjsuWzEQy66ohjt9PVO8Mov+1OgVfpPYRg1lreDkO/AICXcAHQhd079ZOOLMSwBCDbj80aH9BXgJCmkdSnkUhe+S4d7LkjKyAANaV8AnNIExKMLzPCWWZXkAIlAsoiCU3zcH4j37PjrT8ESrFR8V+1M2e1WPWlX6IxlndIU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Y/x0qMtR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Y/x0qMtR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D53E91F00ACF; Sat, 8 Aug 2026 23:18:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231122; bh=cv5F15Pf+qaCXWqln8rlxWjdcGBGLL2eqdPm1KQd9iI=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Y/x0qMtRPMmE+LspRqkDVg22LrWNQ0X6pZ06IMnxqn9ytImbQtHmrN2XSbqRme0Vd KubFXJWbajU1AKWP4ahphXcE8ZFa50zdbnGynsGb9WIV3h2PeyRAVb6h+Px9AQlTxs aJjB/0iMfBmVAmHmeR5jGxaFjTYwZo7BF5bIp3kx4brZ6MCtP1xrL4F/lL5FByJ3/U bH3znu9zPPifY2Wu377Z3D/x46BoYsLnm4WdN/kPfi2cPn7bxDEZw2OCM6lvpd3MzG evxJ5wkullG+h+29Ek74nzDKRcyBrfI4DeYuPPYcbFsmFzoLvh81mtHVRvsOR+e03c X78LIGV7nG+fg== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 21/22] klp-build: Support cross-compilation Date: Sat, 8 Aug 2026 16:17:25 -0700 Message-ID: X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add support for cross-compilation. The user must export ARCH, and either CROSS_COMPILE or LLVM as needed. Signed-off-by: Josh Poimboeuf --- scripts/livepatch/klp-build | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build index b311f290b1406..42fb671f1863d 100755 --- a/scripts/livepatch/klp-build +++ b/scripts/livepatch/klp-build @@ -435,6 +435,25 @@ validate_patches() { revert_patches } =20 +cross_compile_init() { + if [[ -v LLVM && -n "$LLVM" ]]; then + local prefix=3D"" + local suffix=3D"" + + if [[ "$LLVM" =3D=3D */ ]]; then + # LLVM=3D/path/to/bin/ + prefix=3D"$LLVM" + elif [[ "$LLVM" =3D=3D -* ]]; then + # LLVM=3D-14 + suffix=3D"$LLVM" + fi + + OBJCOPY=3D"${prefix}llvm-objcopy${suffix}" + else + OBJCOPY=3D"${CROSS_COMPILE:-}objcopy" + fi +} + do_init() { # We're not yet smart enough to handle anything other than in-tree # builds in pwd. @@ -465,6 +484,7 @@ do_init() { validate_config set_module_name set_kernelversion + cross_compile_init } =20 # Refresh the patch hunk headers, specifically the line numbers and counts. @@ -881,7 +901,7 @@ build_patch_module() { cp -f "$kmod_file" "$kmod_file.orig" =20 # Work around issue where slight .config change makes corrupt BTF - objcopy --remove-section=3D.BTF "$kmod_file" + "$OBJCOPY" --remove-section=3D.BTF "$kmod_file" =20 # Fix (and work around) linker wreckage for klp syms / relocs "$OBJTOOL" klp post-link "$kmod_file" || die "objtool klp post-link faile= d" --=20 2.54.0 From nobody Tue Sep 29 10:28:03 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F0AC378D70; Sat, 8 Aug 2026 23:18:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; cv=none; b=d4ReGRb0bDivoy3OJEUertsaWsGLus2fXIZtYIWZZZP8X0ybzZGCEGCH+0Co8Ie91sfY8dDQNOxeCR1gizRZ7Fixype231fMNWR7+xEaVA5YKQ179dJJlMlgSJ00fZRxfzuqUnHVKN9eiLdUwESTwGMJumnPDQpQ4xa2xIUsRFU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786231124; c=relaxed/simple; bh=Sgdk69pUZcGHcT7Fx1Hkm9Ph3wp1ZRnOKDhoZ7Fstjo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EPhMNuWmXiPyc+JiQY3+SD33nevzbl5Gk0hN0B8Hm5qLONNj+ADGhjmc5jy1Gr1TM+yGR+wSvlfynh7STqBfNNL7fsy5TgPW2zpsNMUtouUiLvEh7QH8y2zH+zO8LEKxrUTN4WkU3CFE7FLa4qnEX/bljxS69FZUDNAsgZn0+LY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=nq0mckAa; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="nq0mckAa" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 963551F00A3E; Sat, 8 Aug 2026 23:18:42 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786231123; bh=Ql766kWCyJrEzgimYF7/K/mUeDpunCOGDp3konzUix0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nq0mckAaodCqRAuEffJncChyCgw5SLKZuxiUI0nb/3BSzXXGa+y3QwmlW01DKue/A BYBIxXoOfEOLAUGXpcf4t+0QnH8AnWaPZZA1uXU4G3vCVOlUUZC+W8ztZk8BpX7ogb goMer3X7ppHfRcfEAeYmtU6FlzxNF9X55qfBAccXfQp24KcqOm5zLQYKzsa4axEL4b 6m6rGk/w3sTZAWYSQAMcj5zJQHQ2dUcfKPpOvmalU8sGiLDu6xSdorXFbFxua1SOGq kI2cr1CjlR1c+VcrgtB4NUAsyzn8CGdLvU/uB3ZeXlsZU/4H+GF5BMFqn40dshD+p+ RqnuAUAN/RmiQ== From: Josh Poimboeuf To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, live-patching@vger.kernel.org, Peter Zijlstra , Joe Lawrence , Song Liu , Catalin Marinas , Will Deacon , linux-arm-kernel@lists.infradead.org, Mark Rutland , Nathan Chancellor , Nicolas Schier , Herbert Xu , Miroslav Benes , Petr Mladek Subject: [PATCH v4 22/22] klp-build: Add arm64 syscall patching macro Date: Sat, 8 Aug 2026 16:17:26 -0700 Message-ID: <56e974b384ffbb3f8b424e7c69da3f702f87f2f8.1786230311.git.jpoimboe@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add arm64 support for KLP_SYSCALL_DEFINEx(), mirroring the arm64 __SYSCALL_DEFINEx() pattern from arch/arm64/include/asm/syscall_wrapper.h. Signed-off-by: Josh Poimboeuf --- include/linux/livepatch_helpers.h | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/include/linux/livepatch_helpers.h b/include/linux/livepatch_he= lpers.h index 99d68d0773fa8..fe02c7b2f769e 100644 --- a/include/linux/livepatch_helpers.h +++ b/include/linux/livepatch_helpers.h @@ -72,6 +72,26 @@ } \ static inline long __klp_do_sys##name(__MAP(x,__SC_DECL,__VA_ARGS__)) =20 +#elif defined(CONFIG_ARM64) + +#define __KLP_SYSCALL_DEFINEx(x, name, ...) \ + static long __se_sys##name(__MAP(x,__SC_LONG,__VA_ARGS__)); \ + static inline long __klp_do_sys##name(__MAP(x,__SC_DECL,__VA_ARGS__));\ + asmlinkage long __arm64_sys##name(const struct pt_regs *regs); \ + ALLOW_ERROR_INJECTION(__arm64_sys##name, ERRNO); \ + asmlinkage long __arm64_sys##name(const struct pt_regs *regs) \ + { \ + return __se_sys##name(SC_ARM64_REGS_TO_ARGS(x,__VA_ARGS__));\ + } \ + static long __se_sys##name(__MAP(x,__SC_LONG,__VA_ARGS__)) \ + { \ + long ret =3D __klp_do_sys##name(__MAP(x,__SC_CAST,__VA_ARGS__));\ + __MAP(x,__SC_TEST,__VA_ARGS__); \ + __PROTECT(x, ret,__MAP(x,__SC_ARGS,__VA_ARGS__)); \ + return ret; \ + } \ + static inline long __klp_do_sys##name(__MAP(x,__SC_DECL,__VA_ARGS__)) + #endif =20 #endif /* _LINUX_LIVEPATCH_HELPERS_H */ --=20 2.54.0