From: Nam Cao <namcao@linutronix.de>
To: Kai Zhang <zhangkai@iscas.ac.cn>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Paul Walmsley <paul.walmsley@sifive.com>,
Palmer Dabbelt <palmer@dabbelt.com>,
Albert Ou <aou@eecs.berkeley.edu>,
stable@vger.kernel.org
Subject: Re: [linux-6.6.y bugreport] riscv: kprobe crash as some patchs lost
Date: Mon, 28 Apr 2025 09:22:48 +0200 [thread overview]
Message-ID: <20250428072248.JgEWTcfe@linutronix.de> (raw)
In-Reply-To: <c66369fa-4042-4a76-9d1c-9e581f003526@iscas.ac.cn>
On Fri, Apr 25, 2025 at 11:29:17PM +0800, Kai Zhang wrote:
> On 4/25/2025 8:59 PM, Nam Cao wrote:
> > On Fri, Apr 25, 2025 at 02:49:52PM +0200, Nam Cao wrote:
> > > On Fri, Apr 25, 2025 at 08:09:21PM +0800, Kai Zhang wrote:
> > > > On 4/25/2025 4:07 PM, Greg Kroah-Hartman wrote:
> > > > > On Fri, Apr 25, 2025 at 04:03:41PM +0800, Kai Zhang wrote:
> > > > > > On 4/22/2025 4:46 PM, Greg Kroah-Hartman wrote:
> > > > > > > On Tue, Apr 22, 2025 at 10:58:42AM +0800, Kai Zhang wrote:
> > > > > > > > In most recent linux-6.6.y tree,
> > > > > > > > `arch/riscv/kernel/probes/kprobes.c::arch_prepare_ss_slot` still has the
> > > > > > > > obsolete code:
> > > > > > > >
> > > > > > > > u32 insn = __BUG_INSN_32;
> > > > > > > > unsigned long offset = GET_INSN_LENGTH(p->opcode);
> > > > > > > > p->ainsn.api.restore = (unsigned long)p->addr + offset;
> > > > > > > > patch_text_nosync(p->ainsn.api.insn, &p->opcode, 1);
> > > > > > > > patch_text_nosync((void *)p->ainsn.api.insn + offset, &insn, 1);
> > > > > > > >
> > > > > > > > The last two 1s are wrong size of written instructions , which would lead to
> > > > > > > > kernel crash, like `insmod kprobe_example.ko` gives:
> > > > > > > >
> > > > > > > > [ 509.812815][ T2734] kprobe_init: Planted kprobe at 00000000c5c46130
> > > > > > > > [ 509.837606][ C5] handler_pre: <kernel_clone> p->addr =
> > > > > > > > 0x00000000c5c46130, pc = 0xffffffff80032ee2, status = 0x200000120
> > > > > > > > [ 509.839315][ C5] Oops - illegal instruction [#1]
> > > > > > > >
> > > > > > > >
> > > > > > > > I've tried two patchs from torvalds tree and it didn't crash again:
> > > > > > > >
> > > > > > > > 51781ce8f448 riscv: Pass patch_text() the length in bytes (rebased)
> > > > > > > > 13134cc94914 riscv: kprobes: Fix incorrect address calculation
> > >
> > > Please don't revert this patch. It fixes another issue.
> > >
> > > You are correct that the sizes of the instructions are wrong. It can still
> > > happen to work if only one instruction is patched.
> > >
> > > This bug is not specific to v6.6. It is in mainline as well. Therefore fix
> > > patch should be sent to mainline, and then backport to v6.6.
> >
> > Sorry, I was confused. This is not in mainline. It has already been fixed
> > by 51781ce8f448 ("riscv: Pass patch_text() the length in bytes")
>
> Indeed.
>
> > But I wouldn't backport that patch, it is bigger than necessary. The patch
> > I sent in the previous email should be enough.
>
> My suggested fixes are:
>
> revert 03753bfacbc6(riscv: kprobes: Fix incorrect address calculation)
> apply 51781ce8f448(riscv: Pass patch_text() the length in bytes)
> apply 13134cc94914(riscv: kprobes: Fix incorrect address calculation)
This is probably fine. But I'm paranoid that as 51781ce8f448 ("riscv:
Pass patch_text() the length in bytes") does many things, it may break
something else in v6.6.
Also, just my preference, but I wouldn't revert a commit then apply it
again. I would only cherry-pick 51781ce8f448, and resolve conflicts.
> Because stable-only commit 03753bfacbc6 is actually rebased upstream
> 13134cc94914, and 13134cc94914 relied on 51781ce8f448. So I gave the above
> suggestion. But I'm ok with your previous email patch.
It was just my suggestion. Do as you think best, CC the relevant people
(RISCV maintainers and authors of those commits), see what they think.
Or I could send the diff I sent earlier as a proper patch. Up to you.
Best regards,
Nam
next prev parent reply other threads:[~2025-04-28 7:23 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-22 2:58 [linux-6.6.y bugreport] riscv: kprobe crash as some patchs lost Kai Zhang
2025-04-22 8:46 ` Greg Kroah-Hartman
2025-04-25 8:03 ` Kai Zhang
2025-04-25 8:07 ` Greg Kroah-Hartman
2025-04-25 12:09 ` Kai Zhang
2025-04-25 12:49 ` Nam Cao
2025-04-25 12:59 ` Nam Cao
2025-04-25 15:29 ` Kai Zhang
2025-04-28 7:22 ` Nam Cao [this message]
2025-04-28 12:10 ` Kai Zhang
2025-04-25 14:53 ` Kai Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250428072248.JgEWTcfe@linutronix.de \
--to=namcao@linutronix.de \
--cc=aou@eecs.berkeley.edu \
--cc=gregkh@linuxfoundation.org \
--cc=palmer@dabbelt.com \
--cc=paul.walmsley@sifive.com \
--cc=stable@vger.kernel.org \
--cc=zhangkai@iscas.ac.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.