mirror of
https://github.com/torvalds/linux.git
synced 2026-08-01 12:11:59 +02:00
Merge 4de65c5830 ("Merge tag 'livepatching-for-6.1' of git://git.kernel.org/pub/scm/linux/kernel/git/livepatching/livepatching") into android-mainline
Steps on the way to 6.1-rc1 Signed-off-by: Greg Kroah-Hartman <gregkh@google.com> Change-Id: I64b04545a7cc831a7a126344f78145cff8962d55
This commit is contained in:
commit
d38fd7839b
|
|
@ -55,6 +55,14 @@ Description:
|
|||
The object directory contains subdirectories for each function
|
||||
that is patched within the object.
|
||||
|
||||
What: /sys/kernel/livepatch/<patch>/<object>/patched
|
||||
Date: August 2022
|
||||
KernelVersion: 6.1.0
|
||||
Contact: live-patching@vger.kernel.org
|
||||
Description:
|
||||
An attribute which indicates whether the object is currently
|
||||
patched.
|
||||
|
||||
What: /sys/kernel/livepatch/<patch>/<object>/<function,sympos>
|
||||
Date: Nov 2014
|
||||
KernelVersion: 3.19.0
|
||||
|
|
|
|||
|
|
@ -17,8 +17,6 @@
|
|||
|
||||
#include <asm/io.h>
|
||||
|
||||
extern wait_queue_head_t log_wait;
|
||||
|
||||
static int kmsg_open(struct inode * inode, struct file * file)
|
||||
{
|
||||
return do_syslog(SYSLOG_ACTION_OPEN, NULL, 0, SYSLOG_FROM_PROC);
|
||||
|
|
|
|||
|
|
@ -169,8 +169,6 @@ extern void __printk_safe_exit(void);
|
|||
#define printk_deferred_enter __printk_safe_enter
|
||||
#define printk_deferred_exit __printk_safe_exit
|
||||
|
||||
extern bool pr_flush(int timeout_ms, bool reset_on_progress);
|
||||
|
||||
/*
|
||||
* Please don't use printk_ratelimit(), because it shares ratelimiting state
|
||||
* with all other unrelated printk_ratelimit() callsites. Instead use
|
||||
|
|
@ -221,11 +219,6 @@ static inline void printk_deferred_exit(void)
|
|||
{
|
||||
}
|
||||
|
||||
static inline bool pr_flush(int timeout_ms, bool reset_on_progress)
|
||||
{
|
||||
return true;
|
||||
}
|
||||
|
||||
static inline int printk_ratelimit(void)
|
||||
{
|
||||
return 0;
|
||||
|
|
|
|||
|
|
@ -8,6 +8,8 @@
|
|||
#ifndef _LINUX_SYSLOG_H
|
||||
#define _LINUX_SYSLOG_H
|
||||
|
||||
#include <linux/wait.h>
|
||||
|
||||
/* Close the log. Currently a NOP. */
|
||||
#define SYSLOG_ACTION_CLOSE 0
|
||||
/* Open the log. Currently a NOP. */
|
||||
|
|
@ -35,5 +37,6 @@
|
|||
#define SYSLOG_FROM_PROC 1
|
||||
|
||||
int do_syslog(int type, char __user *buf, int count, int source);
|
||||
extern wait_queue_head_t log_wait;
|
||||
|
||||
#endif /* _LINUX_SYSLOG_H */
|
||||
|
|
|
|||
|
|
@ -325,6 +325,7 @@ int klp_apply_section_relocs(struct module *pmod, Elf_Shdr *sechdrs,
|
|||
* /sys/kernel/livepatch/<patch>/transition
|
||||
* /sys/kernel/livepatch/<patch>/force
|
||||
* /sys/kernel/livepatch/<patch>/<object>
|
||||
* /sys/kernel/livepatch/<patch>/<object>/patched
|
||||
* /sys/kernel/livepatch/<patch>/<object>/<function,sympos>
|
||||
*/
|
||||
static int __klp_disable_patch(struct klp_patch *patch);
|
||||
|
|
@ -431,6 +432,22 @@ static struct attribute *klp_patch_attrs[] = {
|
|||
};
|
||||
ATTRIBUTE_GROUPS(klp_patch);
|
||||
|
||||
static ssize_t patched_show(struct kobject *kobj,
|
||||
struct kobj_attribute *attr, char *buf)
|
||||
{
|
||||
struct klp_object *obj;
|
||||
|
||||
obj = container_of(kobj, struct klp_object, kobj);
|
||||
return sysfs_emit(buf, "%d\n", obj->patched);
|
||||
}
|
||||
|
||||
static struct kobj_attribute patched_kobj_attr = __ATTR_RO(patched);
|
||||
static struct attribute *klp_object_attrs[] = {
|
||||
&patched_kobj_attr.attr,
|
||||
NULL,
|
||||
};
|
||||
ATTRIBUTE_GROUPS(klp_object);
|
||||
|
||||
static void klp_free_object_dynamic(struct klp_object *obj)
|
||||
{
|
||||
kfree(obj->name);
|
||||
|
|
@ -576,6 +593,7 @@ static void klp_kobj_release_object(struct kobject *kobj)
|
|||
static struct kobj_type klp_ktype_object = {
|
||||
.release = klp_kobj_release_object,
|
||||
.sysfs_ops = &kobj_sysfs_ops,
|
||||
.default_groups = klp_object_groups,
|
||||
};
|
||||
|
||||
static void klp_kobj_release_func(struct kobject *kobj)
|
||||
|
|
@ -1171,7 +1189,7 @@ int klp_module_coming(struct module *mod)
|
|||
return -EINVAL;
|
||||
|
||||
if (!strcmp(mod->name, "vmlinux")) {
|
||||
pr_err("vmlinux.ko: invalid module name");
|
||||
pr_err("vmlinux.ko: invalid module name\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -610,9 +610,23 @@ void klp_reverse_transition(void)
|
|||
/* Called from copy_process() during fork */
|
||||
void klp_copy_process(struct task_struct *child)
|
||||
{
|
||||
child->patch_state = current->patch_state;
|
||||
|
||||
/* TIF_PATCH_PENDING gets copied in setup_thread_stack() */
|
||||
/*
|
||||
* The parent process may have gone through a KLP transition since
|
||||
* the thread flag was copied in setup_thread_stack earlier. Bring
|
||||
* the task flag up to date with the parent here.
|
||||
*
|
||||
* The operation is serialized against all klp_*_transition()
|
||||
* operations by the tasklist_lock. The only exception is
|
||||
* klp_update_patch_state(current), but we cannot race with
|
||||
* that because we are current.
|
||||
*/
|
||||
if (test_tsk_thread_flag(current, TIF_PATCH_PENDING))
|
||||
set_tsk_thread_flag(child, TIF_PATCH_PENDING);
|
||||
else
|
||||
clear_tsk_thread_flag(child, TIF_PATCH_PENDING);
|
||||
|
||||
child->patch_state = current->patch_state;
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
|
|||
|
|
@ -222,9 +222,6 @@ int devkmsg_sysctl_set_loglvl(struct ctl_table *table, int write,
|
|||
}
|
||||
#endif /* CONFIG_PRINTK && CONFIG_SYSCTL */
|
||||
|
||||
/* Number of registered extended console drivers. */
|
||||
static int nr_ext_console_drivers;
|
||||
|
||||
/*
|
||||
* Helper macros to handle lockdep when locking/unlocking console_sem. We use
|
||||
* macros instead of functions so that _RET_IP_ contains useful information.
|
||||
|
|
@ -435,7 +432,7 @@ static struct printk_ringbuffer *prb = &printk_rb_static;
|
|||
* per_cpu_areas are initialised. This variable is set to true when
|
||||
* it's safe to access per-CPU data.
|
||||
*/
|
||||
static bool __printk_percpu_data_ready __read_mostly;
|
||||
static bool __printk_percpu_data_ready __ro_after_init;
|
||||
|
||||
bool printk_percpu_data_ready(void)
|
||||
{
|
||||
|
|
@ -2298,6 +2295,7 @@ asmlinkage __visible int _printk(const char *fmt, ...)
|
|||
}
|
||||
EXPORT_SYMBOL(_printk);
|
||||
|
||||
static bool pr_flush(int timeout_ms, bool reset_on_progress);
|
||||
static bool __pr_flush(struct console *con, int timeout_ms, bool reset_on_progress);
|
||||
|
||||
#else /* CONFIG_PRINTK */
|
||||
|
|
@ -2332,6 +2330,7 @@ static void call_console_driver(struct console *con, const char *text, size_t le
|
|||
{
|
||||
}
|
||||
static bool suppress_message_printing(int level) { return false; }
|
||||
static bool pr_flush(int timeout_ms, bool reset_on_progress) { return true; }
|
||||
static bool __pr_flush(struct console *con, int timeout_ms, bool reset_on_progress) { return true; }
|
||||
|
||||
#endif /* CONFIG_PRINTK */
|
||||
|
|
@ -3194,9 +3193,6 @@ void register_console(struct console *newcon)
|
|||
console_drivers->next = newcon;
|
||||
}
|
||||
|
||||
if (newcon->flags & CON_EXTENDED)
|
||||
nr_ext_console_drivers++;
|
||||
|
||||
newcon->dropped = 0;
|
||||
if (newcon->flags & CON_PRINTBUFFER) {
|
||||
/* Get a consistent copy of @syslog_seq. */
|
||||
|
|
@ -3221,9 +3217,6 @@ void register_console(struct console *newcon)
|
|||
if (bootcon_enabled &&
|
||||
((newcon->flags & (CON_CONSDEV | CON_BOOT)) == CON_CONSDEV) &&
|
||||
!keep_bootcon) {
|
||||
/* We need to iterate through all boot consoles, to make
|
||||
* sure we print everything out, before we unregister them.
|
||||
*/
|
||||
for_each_console(con)
|
||||
if (con->flags & CON_BOOT)
|
||||
unregister_console(con);
|
||||
|
|
@ -3262,9 +3255,6 @@ int unregister_console(struct console *console)
|
|||
if (res)
|
||||
goto out_disable_unlock;
|
||||
|
||||
if (console->flags & CON_EXTENDED)
|
||||
nr_ext_console_drivers--;
|
||||
|
||||
/*
|
||||
* If this isn't the last console and it has CON_CONSDEV set, we
|
||||
* need to set it on the next preferred console.
|
||||
|
|
@ -3446,11 +3436,10 @@ static bool __pr_flush(struct console *con, int timeout_ms, bool reset_on_progre
|
|||
* Context: Process context. May sleep while acquiring console lock.
|
||||
* Return: true if all enabled printers are caught up.
|
||||
*/
|
||||
bool pr_flush(int timeout_ms, bool reset_on_progress)
|
||||
static bool pr_flush(int timeout_ms, bool reset_on_progress)
|
||||
{
|
||||
return __pr_flush(NULL, timeout_ms, reset_on_progress);
|
||||
}
|
||||
EXPORT_SYMBOL(pr_flush);
|
||||
|
||||
/*
|
||||
* Delayed printk version, for scheduler-internal messages:
|
||||
|
|
|
|||
|
|
@ -750,37 +750,42 @@ static int __init debug_boot_weak_hash_enable(char *str)
|
|||
}
|
||||
early_param("debug_boot_weak_hash", debug_boot_weak_hash_enable);
|
||||
|
||||
static DEFINE_STATIC_KEY_FALSE(filled_random_ptr_key);
|
||||
static bool filled_random_ptr_key __read_mostly;
|
||||
static siphash_key_t ptr_key __read_mostly;
|
||||
static void fill_ptr_key_workfn(struct work_struct *work);
|
||||
static DECLARE_DELAYED_WORK(fill_ptr_key_work, fill_ptr_key_workfn);
|
||||
|
||||
static void enable_ptr_key_workfn(struct work_struct *work)
|
||||
static void fill_ptr_key_workfn(struct work_struct *work)
|
||||
{
|
||||
static_branch_enable(&filled_random_ptr_key);
|
||||
if (!rng_is_initialized()) {
|
||||
queue_delayed_work(system_unbound_wq, &fill_ptr_key_work, HZ * 2);
|
||||
return;
|
||||
}
|
||||
|
||||
get_random_bytes(&ptr_key, sizeof(ptr_key));
|
||||
|
||||
/* Pairs with smp_rmb() before reading ptr_key. */
|
||||
smp_wmb();
|
||||
WRITE_ONCE(filled_random_ptr_key, true);
|
||||
}
|
||||
|
||||
static int __init vsprintf_init_hashval(void)
|
||||
{
|
||||
fill_ptr_key_workfn(NULL);
|
||||
return 0;
|
||||
}
|
||||
subsys_initcall(vsprintf_init_hashval)
|
||||
|
||||
/* Maps a pointer to a 32 bit unique identifier. */
|
||||
static inline int __ptr_to_hashval(const void *ptr, unsigned long *hashval_out)
|
||||
{
|
||||
static siphash_key_t ptr_key __read_mostly;
|
||||
unsigned long hashval;
|
||||
|
||||
if (!static_branch_likely(&filled_random_ptr_key)) {
|
||||
static bool filled = false;
|
||||
static DEFINE_SPINLOCK(filling);
|
||||
static DECLARE_WORK(enable_ptr_key_work, enable_ptr_key_workfn);
|
||||
unsigned long flags;
|
||||
|
||||
if (!system_unbound_wq || !rng_is_initialized() ||
|
||||
!spin_trylock_irqsave(&filling, flags))
|
||||
return -EAGAIN;
|
||||
|
||||
if (!filled) {
|
||||
get_random_bytes(&ptr_key, sizeof(ptr_key));
|
||||
queue_work(system_unbound_wq, &enable_ptr_key_work);
|
||||
filled = true;
|
||||
}
|
||||
spin_unlock_irqrestore(&filling, flags);
|
||||
}
|
||||
if (!READ_ONCE(filled_random_ptr_key))
|
||||
return -EBUSY;
|
||||
|
||||
/* Pairs with smp_wmb() after writing ptr_key. */
|
||||
smp_rmb();
|
||||
|
||||
#ifdef CONFIG_64BIT
|
||||
hashval = (unsigned long)siphash_1u64((u64)ptr, &ptr_key);
|
||||
|
|
@ -1189,7 +1194,7 @@ char *hex_string(char *buf, char *end, u8 *addr, struct printf_spec spec,
|
|||
}
|
||||
|
||||
static noinline_for_stack
|
||||
char *bitmap_string(char *buf, char *end, unsigned long *bitmap,
|
||||
char *bitmap_string(char *buf, char *end, const unsigned long *bitmap,
|
||||
struct printf_spec spec, const char *fmt)
|
||||
{
|
||||
const int CHUNKSZ = 32;
|
||||
|
|
@ -1233,7 +1238,7 @@ char *bitmap_string(char *buf, char *end, unsigned long *bitmap,
|
|||
}
|
||||
|
||||
static noinline_for_stack
|
||||
char *bitmap_list_string(char *buf, char *end, unsigned long *bitmap,
|
||||
char *bitmap_list_string(char *buf, char *end, const unsigned long *bitmap,
|
||||
struct printf_spec spec, const char *fmt)
|
||||
{
|
||||
int nr_bits = max_t(int, spec.field_width, 0);
|
||||
|
|
|
|||
|
|
@ -6,7 +6,8 @@ TEST_PROGS := \
|
|||
test-callbacks.sh \
|
||||
test-shadow-vars.sh \
|
||||
test-state.sh \
|
||||
test-ftrace.sh
|
||||
test-ftrace.sh \
|
||||
test-sysfs.sh
|
||||
|
||||
TEST_FILES := settings
|
||||
|
||||
|
|
|
|||
|
|
@ -6,6 +6,7 @@
|
|||
|
||||
MAX_RETRIES=600
|
||||
RETRY_INTERVAL=".1" # seconds
|
||||
KLP_SYSFS_DIR="/sys/kernel/livepatch"
|
||||
|
||||
# Kselftest framework requirement - SKIP code is 4
|
||||
ksft_skip=4
|
||||
|
|
@ -86,7 +87,7 @@ function set_ftrace_enabled() {
|
|||
|
||||
if [[ "$result" != "$1" ]] ; then
|
||||
if [[ $can_fail -eq 1 ]] ; then
|
||||
echo "livepatch: $err" > /dev/kmsg
|
||||
echo "livepatch: $err" | sed 's#/proc/sys/kernel/#kernel.#' > /dev/kmsg
|
||||
return
|
||||
fi
|
||||
|
||||
|
|
@ -308,3 +309,36 @@ function check_result {
|
|||
|
||||
cleanup_dmesg_file
|
||||
}
|
||||
|
||||
# check_sysfs_rights(modname, rel_path, expected_rights) - check sysfs
|
||||
# path permissions
|
||||
# modname - livepatch module creating the sysfs interface
|
||||
# rel_path - relative path of the sysfs interface
|
||||
# expected_rights - expected access rights
|
||||
function check_sysfs_rights() {
|
||||
local mod="$1"; shift
|
||||
local rel_path="$1"; shift
|
||||
local expected_rights="$1"; shift
|
||||
|
||||
local path="$KLP_SYSFS_DIR/$mod/$rel_path"
|
||||
local rights=$(/bin/stat --format '%A' "$path")
|
||||
if test "$rights" != "$expected_rights" ; then
|
||||
die "Unexpected access rights of $path: $expected_rights vs. $rights"
|
||||
fi
|
||||
}
|
||||
|
||||
# check_sysfs_value(modname, rel_path, expected_value) - check sysfs value
|
||||
# modname - livepatch module creating the sysfs interface
|
||||
# rel_path - relative path of the sysfs interface
|
||||
# expected_value - expected value read from the file
|
||||
function check_sysfs_value() {
|
||||
local mod="$1"; shift
|
||||
local rel_path="$1"; shift
|
||||
local expected_value="$1"; shift
|
||||
|
||||
local path="$KLP_SYSFS_DIR/$mod/$rel_path"
|
||||
local value=`cat $path`
|
||||
if test "$value" != "$expected_value" ; then
|
||||
die "Unexpected value in $path: $expected_value vs. $value"
|
||||
fi
|
||||
}
|
||||
|
|
|
|||
86
tools/testing/selftests/livepatch/test-sysfs.sh
Executable file
86
tools/testing/selftests/livepatch/test-sysfs.sh
Executable file
|
|
@ -0,0 +1,86 @@
|
|||
#!/bin/bash
|
||||
# SPDX-License-Identifier: GPL-2.0
|
||||
# Copyright (C) 2022 Song Liu <song@kernel.org>
|
||||
|
||||
. $(dirname $0)/functions.sh
|
||||
|
||||
MOD_LIVEPATCH=test_klp_livepatch
|
||||
|
||||
setup_config
|
||||
|
||||
# - load a livepatch and verifies the sysfs entries work as expected
|
||||
|
||||
start_test "sysfs test"
|
||||
|
||||
load_lp $MOD_LIVEPATCH
|
||||
|
||||
check_sysfs_rights "$MOD_LIVEPATCH" "" "drwxr-xr-x"
|
||||
check_sysfs_rights "$MOD_LIVEPATCH" "enabled" "-rw-r--r--"
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "enabled" "1"
|
||||
check_sysfs_rights "$MOD_LIVEPATCH" "force" "--w-------"
|
||||
check_sysfs_rights "$MOD_LIVEPATCH" "transition" "-r--r--r--"
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "transition" "0"
|
||||
check_sysfs_rights "$MOD_LIVEPATCH" "vmlinux/patched" "-r--r--r--"
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "vmlinux/patched" "1"
|
||||
|
||||
disable_lp $MOD_LIVEPATCH
|
||||
|
||||
unload_lp $MOD_LIVEPATCH
|
||||
|
||||
check_result "% modprobe $MOD_LIVEPATCH
|
||||
livepatch: enabling patch '$MOD_LIVEPATCH'
|
||||
livepatch: '$MOD_LIVEPATCH': initializing patching transition
|
||||
livepatch: '$MOD_LIVEPATCH': starting patching transition
|
||||
livepatch: '$MOD_LIVEPATCH': completing patching transition
|
||||
livepatch: '$MOD_LIVEPATCH': patching complete
|
||||
% echo 0 > /sys/kernel/livepatch/$MOD_LIVEPATCH/enabled
|
||||
livepatch: '$MOD_LIVEPATCH': initializing unpatching transition
|
||||
livepatch: '$MOD_LIVEPATCH': starting unpatching transition
|
||||
livepatch: '$MOD_LIVEPATCH': completing unpatching transition
|
||||
livepatch: '$MOD_LIVEPATCH': unpatching complete
|
||||
% rmmod $MOD_LIVEPATCH"
|
||||
|
||||
start_test "sysfs test object/patched"
|
||||
|
||||
MOD_LIVEPATCH=test_klp_callbacks_demo
|
||||
MOD_TARGET=test_klp_callbacks_mod
|
||||
load_lp $MOD_LIVEPATCH
|
||||
|
||||
# check the "patch" file changes as target module loads/unloads
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "$MOD_TARGET/patched" "0"
|
||||
load_mod $MOD_TARGET
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "$MOD_TARGET/patched" "1"
|
||||
unload_mod $MOD_TARGET
|
||||
check_sysfs_value "$MOD_LIVEPATCH" "$MOD_TARGET/patched" "0"
|
||||
|
||||
disable_lp $MOD_LIVEPATCH
|
||||
unload_lp $MOD_LIVEPATCH
|
||||
|
||||
check_result "% modprobe test_klp_callbacks_demo
|
||||
livepatch: enabling patch 'test_klp_callbacks_demo'
|
||||
livepatch: 'test_klp_callbacks_demo': initializing patching transition
|
||||
test_klp_callbacks_demo: pre_patch_callback: vmlinux
|
||||
livepatch: 'test_klp_callbacks_demo': starting patching transition
|
||||
livepatch: 'test_klp_callbacks_demo': completing patching transition
|
||||
test_klp_callbacks_demo: post_patch_callback: vmlinux
|
||||
livepatch: 'test_klp_callbacks_demo': patching complete
|
||||
% modprobe test_klp_callbacks_mod
|
||||
livepatch: applying patch 'test_klp_callbacks_demo' to loading module 'test_klp_callbacks_mod'
|
||||
test_klp_callbacks_demo: pre_patch_callback: test_klp_callbacks_mod -> [MODULE_STATE_COMING] Full formed, running module_init
|
||||
test_klp_callbacks_demo: post_patch_callback: test_klp_callbacks_mod -> [MODULE_STATE_COMING] Full formed, running module_init
|
||||
test_klp_callbacks_mod: test_klp_callbacks_mod_init
|
||||
% rmmod test_klp_callbacks_mod
|
||||
test_klp_callbacks_mod: test_klp_callbacks_mod_exit
|
||||
test_klp_callbacks_demo: pre_unpatch_callback: test_klp_callbacks_mod -> [MODULE_STATE_GOING] Going away
|
||||
livepatch: reverting patch 'test_klp_callbacks_demo' on unloading module 'test_klp_callbacks_mod'
|
||||
test_klp_callbacks_demo: post_unpatch_callback: test_klp_callbacks_mod -> [MODULE_STATE_GOING] Going away
|
||||
% echo 0 > /sys/kernel/livepatch/test_klp_callbacks_demo/enabled
|
||||
livepatch: 'test_klp_callbacks_demo': initializing unpatching transition
|
||||
test_klp_callbacks_demo: pre_unpatch_callback: vmlinux
|
||||
livepatch: 'test_klp_callbacks_demo': starting unpatching transition
|
||||
livepatch: 'test_klp_callbacks_demo': completing unpatching transition
|
||||
test_klp_callbacks_demo: post_unpatch_callback: vmlinux
|
||||
livepatch: 'test_klp_callbacks_demo': unpatching complete
|
||||
% rmmod test_klp_callbacks_demo"
|
||||
|
||||
exit 0
|
||||
Loading…
Reference in New Issue
Block a user