All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steffen Eiden <seiden@linux.ibm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
	linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org, linux-s390@vger.kernel.org
Cc: Alexander Gordeev <agordeev@linux.ibm.com>,
	Andreas Grapentin <gra@linux.ibm.com>,
	Arnd Bergmann <arnd@arndb.de>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Christian Borntraeger <borntraeger@linux.ibm.com>,
	Claudio Imbrenda <imbrenda@linux.ibm.com>,
	David Hildenbrand <david@kernel.org>,
	Friedrich Welter <fritz@linux.ibm.com>,
	Fuad Tabba <tabba@google.com>, Gautam Gala <ggala@linux.ibm.com>,
	Hariharan Mari <hari55@linux.ibm.com>,
	Heiko Carstens <hca@linux.ibm.com>,
	Hendrik Brueckner <brueckner@linux.ibm.com>,
	Ilya Leoshkevich <iii@linux.ibm.com>,
	Janosch Frank <frankja@linux.ibm.com>,
	Joey Gouly <joey.gouly@arm.com>, Marc Zyngier <maz@kernel.org>,
	Nico Boehr <nrb@linux.ibm.com>,
	Nina Schoetterl-Glausch <oss@nina.schoetterlglausch.eu>,
	Oliver Upton <oupton@kernel.org>,
	Paolo Bonzini <pbonzini@redhat.com>,
	Suzuki K Poulose <suzuki.poulose@arm.com>,
	Sven Schnelle <svens@linux.ibm.com>,
	Ulrich Weigand <Ulrich.Weigand@de.ibm.com>,
	Vasily Gorbik <gor@linux.ibm.com>, Will Deacon <will@kernel.org>,
	Zenghui Yu <yuzenghui@huawei.com>
Subject: [PATCH v8 06/29] KVM: Move export symbol check macros to Makefile.kvm
Date: Fri, 18 Sep 2026 15:30:43 +0200	[thread overview]
Message-ID: <20260918133107.1042730-7-seiden@linux.ibm.com> (raw)
In-Reply-To: <20260918133107.1042730-1-seiden@linux.ibm.com>

The EXPORT_SYMBOL_GPL/EXPORT_SYMBOL enforcement logic in
arch/x86/kvm/Makefile is useful for any KVM architecture wanting to
restrict the exported symbols. Move the check macros to
virt/kvm/Makefile.kvm so they can be shared.

Arch Makefiles only need to set kvm_exports_allowed to a space-separated
list of symbols that are permitted and then call kvm_check_exports for
each symbol type they want to enforce.

No functional change.

Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
---
 arch/x86/kvm/Makefile | 49 +++++++++----------------------------------
 virt/kvm/Makefile.kvm | 33 +++++++++++++++++++++++++++++
 2 files changed, 43 insertions(+), 39 deletions(-)

diff --git a/arch/x86/kvm/Makefile b/arch/x86/kvm/Makefile
index c6bf463f5032..1bfd630c0767 100644
--- a/arch/x86/kvm/Makefile
+++ b/arch/x86/kvm/Makefile
@@ -54,43 +54,14 @@ clean-files += kvm-asm-offsets.h
 # Only a handful of exports intended for other modules (VFIO, KVMGT) should
 # use EXPORT_SYMBOL_GPL, and EXPORT_SYMBOL should never be used.
 ifdef CONFIG_KVM_X86
-# Search recursively for whole words and print line numbers.  Filter out the
-# allowed set of exports, i.e. those that are intended for external usage.
-exports_grep_trailer := --include='*.[ch]' -nrw $(srctree)/virt/kvm $(srctree)/arch/x86/kvm | \
-			grep -v -e kvm_page_track_register_notifier \
-				-e kvm_page_track_unregister_notifier \
-				-e kvm_write_track_add_gfn \
-				-e kvm_write_track_remove_gfn \
-				-e kvm_file_to_kvm_fn
-
-# Force grep to emit a goofy group separator that can in turn be replaced with
-# the above newline macro (newlines in Make are a nightmare).  Note, grep only
-# prints the group separator when N lines of context are requested via -C,
-# a.k.a. --NUM.  Simply request zero lines.  Print the separator only after
-# filtering out expected exports to avoid extra newlines in the error message.
-define get_kvm_exports
-$(shell grep "$(1)" -C0 $(exports_grep_trailer) | grep "$(1)" -C0 --group-separator="!SEP!")
-endef
-
-define check_kvm_exports
-nr_kvm_exports := $(shell grep "$(1)" $(exports_grep_trailer) | wc -l)
-
-ifneq (0,$$(nr_kvm_exports))
-$$(error ERROR ***\
-$$(newline)found $$(nr_kvm_exports) unwanted occurrences of $(1):\
-$$(newline)  $(subst !SEP!,$$(newline) ,$(call get_kvm_exports,$(1)))\
-$$(newline)in directories:\
-$$(newline)  $(srctree)/arch/x86/kvm\
-$$(newline)  $(srctree)/virt/kvm\
-$$(newline)Use EXPORT_SYMBOL_FOR_KVM_INTERNAL, not $(1))
-endif # nr_kvm_exports != 0
-undefine nr_kvm_exports
-endef # check_kvm_exports
-
-$(eval $(call check_kvm_exports,EXPORT_SYMBOL_GPL))
-$(eval $(call check_kvm_exports,EXPORT_SYMBOL))
-
-undefine check_kvm_exports
-undefine get_kvm_exports
-undefine exports_grep_trailer
+kvm_exports_allowed := kvm_page_track_register_notifier \
+		       kvm_page_track_unregister_notifier \
+		       kvm_write_track_add_gfn \
+		       kvm_write_track_remove_gfn \
+		       kvm_file_to_kvm_fn
+
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL_GPL))
+$(eval $(call kvm_check_exports,EXPORT_SYMBOL))
+
+undefine kvm_exports_allowed
 endif # CONFIG_KVM_X86
diff --git a/virt/kvm/Makefile.kvm b/virt/kvm/Makefile.kvm
index d047d4cf58c9..dd40544b8ecb 100644
--- a/virt/kvm/Makefile.kvm
+++ b/virt/kvm/Makefile.kvm
@@ -13,3 +13,36 @@ kvm-$(CONFIG_HAVE_KVM_IRQ_ROUTING) += $(KVM)/irqchip.o
 kvm-$(CONFIG_HAVE_KVM_DIRTY_RING) += $(KVM)/dirty_ring.o
 kvm-$(CONFIG_HAVE_KVM_PFNCACHE) += $(KVM)/pfncache.o
 kvm-$(CONFIG_KVM_GUEST_MEMFD) += $(KVM)/guest_memfd.o
+
+# Force grep to emit a goofy group separator that can in turn be replaced with
+# the above newline macro (newlines in Make are a nightmare).  Note, grep only
+# prints the group separator when N lines of context are requested via -C,
+# a.k.a. --NUM.  Simply request zero lines.  Print the separator only after
+# filtering out expected exports to avoid extra newlines in the error message.
+define __kvm_get_exports
+$(shell grep "$(1)" -C0 --include='*.[ch]' -nrw \
+	$(srctree)/virt/kvm $(srctree)/arch/$(SRCARCH)/kvm \
+	$(addprefix | grep -v -e ,$(kvm_exports_allowed)) \
+	| grep "$(1)" -C0 --group-separator="!SEP!")
+endef
+
+
+KVM_CHECK_EXPORT_DIRS ?= $(srctree)/virt/kvm $(srctree)/arch/$(ARCH)/kvm
+
+# Fail the build if any unwanted $(1) usage is found outside kvm_exports_allowed.
+define kvm_check_exports
+kvm_nr_exports := $(shell grep "$(1)" --include='*.[ch]' -nrw \
+	$(KVM_CHECK_EXPORT_DIRS) \
+	$(addprefix | grep -v -e ,$(kvm_exports_allowed)) | wc -l)
+
+ifneq (0,$$(kvm_nr_exports))
+$$(error ERROR ***\
+$$(newline)found $$(kvm_nr_exports) unwanted occurrences of $(1):\
+$$(newline)  $(subst !SEP!,$$(newline) ,$(call __kvm_get_exports,$(1)))\
+$$(newline)in directories:\
+$$(newline)  $(KVM_CHECK_EXPORT_DIRS)\
+$$(newline)If this is a valid exception add it to kvm_exports_allowed or\
+$$(newline)use EXPORT_SYMBOL_FOR_KVM_INTERNAL, not $(1))
+endif # kvm_nr_exports != 0
+undefine kvm_nr_exports
+endef # kvm_check_exports
-- 
2.53.0


  parent reply	other threads:[~2026-09-18 13:31 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 13:30 [PATCH v8 00/29] KVM: s390: Introduce arm64 KVM Steffen Eiden
2026-09-18 13:30 ` [PATCH v8 01/29] KVM: Introduce file_to_kvm_<arch>() infrastructure Steffen Eiden
2026-09-18 13:45   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 02/29] KVM: Add file back-pointer to struct kvm Steffen Eiden
2026-09-18 13:56   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 03/29] KVM: x86: Use file_to_kvm_x86() in SEV Steffen Eiden
2026-09-18 14:02   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 04/29] KVM/vfio: Use file-based reference counting for KVM Steffen Eiden
2026-09-18 14:26   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 05/29] KVM: Restrict kvm_get_kvm/kvm_put_kvm export to internal KVM modules Steffen Eiden
2026-09-18 14:30   ` sashiko-bot
2026-09-18 13:30 ` Steffen Eiden [this message]
2026-09-18 14:37   ` [PATCH v8 06/29] KVM: Move export symbol check macros to Makefile.kvm sashiko-bot
2026-09-18 13:30 ` [PATCH v8 07/29] KVM: Make device name configurable Steffen Eiden
2026-09-18 14:58   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 08/29] KVM: Move architecture capability Kconfigs to header defines Steffen Eiden
2026-09-18 15:07   ` sashiko-bot
2026-09-21  7:09   ` Steffen Eiden
2026-09-18 13:30 ` [PATCH v8 09/29] KVM: Replace CONFIG_KVM_MMIO with KVM_NO_MMIO Steffen Eiden
2026-09-18 15:15   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 10/29] arm64: Use proper include variant Steffen Eiden
2026-09-18 15:16   ` sashiko-bot
2026-09-28 14:01   ` Catalin Marinas
2026-09-18 13:30 ` [PATCH v8 11/29] arm64: ptrace: Use constants for compat register numbers Steffen Eiden
2026-09-18 15:20   ` sashiko-bot
2026-09-28 14:01   ` Catalin Marinas
2026-09-18 13:30 ` [PATCH v8 12/29] arm64: sysreg: Convert SPSR_ELx to automatic register generation Steffen Eiden
2026-09-18 15:24   ` sashiko-bot
2026-09-28 15:08   ` Catalin Marinas
2026-09-28 15:36     ` Steffen Eiden
2026-09-18 13:30 ` [PATCH v8 13/29] KVM: arm64: Access elements of vcpu_gp_regs individually Steffen Eiden
2026-09-18 15:28   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 14/29] KVM: arm64: Use accessor functions for core regs Steffen Eiden
2026-09-18 15:32   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 15/29] arm64: Prepare sharing arm64 headers with s390 Steffen Eiden
2026-09-18 15:39   ` sashiko-bot
2026-09-28 15:11   ` Catalin Marinas
2026-09-18 13:30 ` [PATCH v8 16/29] arm64: Share " Steffen Eiden
2026-09-18 15:50   ` sashiko-bot
2026-09-28 16:07   ` Catalin Marinas
2026-09-28 16:23     ` Steffen Eiden
2026-09-29  4:19       ` Andreas Grapentin
2026-09-29 17:00         ` Catalin Marinas
2026-09-30  7:28           ` Steffen Eiden
2026-09-30  7:55             ` Marc Zyngier
2026-09-30  8:18               ` Will Deacon
2026-09-30  8:53               ` Steffen Eiden
2026-09-18 13:30 ` [PATCH v8 17/29] KVM: arm64: Share arm64 code " Steffen Eiden
2026-09-18 16:02   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 18/29] s390/tools: Use arm64 headers Steffen Eiden
2026-09-18 16:09   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 19/29] KVM: s390: Use arm64 code Steffen Eiden
2026-09-18 16:14   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 20/29] s390: Introduce Start Arm Execution instruction Steffen Eiden
2026-09-18 16:28   ` sashiko-bot
2026-09-28 15:53   ` Ilya Leoshkevich
2026-09-28 16:15     ` Steffen Eiden
2026-09-28 16:18       ` Ilya Leoshkevich
2026-09-18 13:30 ` [PATCH v8 21/29] KVM: s390: arm64: Introduce host definitions Steffen Eiden
2026-09-18 16:44   ` sashiko-bot
2026-09-18 13:30 ` [PATCH v8 22/29] s390/hwcaps: Report SAE support as hwcap Steffen Eiden
2026-09-18 16:49   ` sashiko-bot
2026-09-28 15:58   ` Ilya Leoshkevich
2026-09-18 13:31 ` [PATCH v8 23/29] KVM: s390: Add basic arm64 kvm module Steffen Eiden
2026-09-18 17:00   ` sashiko-bot
2026-09-28 14:15   ` Hendrik Brueckner
2026-09-28 14:22     ` Steffen Eiden
2026-09-18 13:31 ` [PATCH v8 24/29] KVM: s390: arm64: Implement required functions Steffen Eiden
2026-09-18 17:13   ` sashiko-bot
2026-09-18 13:31 ` [PATCH v8 25/29] KVM: s390: arm64: Implement vm/vcpu create destroy Steffen Eiden
2026-09-18 17:24   ` sashiko-bot
2026-09-18 13:31 ` [PATCH v8 26/29] KVM: s390: arm64: Implement vCPU IOCTLs Steffen Eiden
2026-09-18 17:45   ` sashiko-bot
2026-09-18 13:31 ` [PATCH v8 27/29] KVM: s390: arm64: Implement basic page fault handler Steffen Eiden
2026-09-18 17:55   ` sashiko-bot
2026-09-18 13:31 ` [PATCH v8 28/29] KVM: s390: arm64: Integrate arm on s390 Steffen Eiden
2026-09-18 18:11   ` sashiko-bot
2026-09-18 13:31 ` [PATCH v8 29/29] KVM: s390: Enforce no unexpected external symbol exports in s390 KVM Steffen Eiden
2026-09-18 18:19   ` sashiko-bot
2026-09-18 13:38 ` [PATCH v8 00/29] KVM: s390: Introduce arm64 KVM Steffen Eiden

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918133107.1042730-7-seiden@linux.ibm.com \
    --to=seiden@linux.ibm.com \
    --cc=Ulrich.Weigand@de.ibm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=arnd@arndb.de \
    --cc=borntraeger@linux.ibm.com \
    --cc=brueckner@linux.ibm.com \
    --cc=catalin.marinas@arm.com \
    --cc=david@kernel.org \
    --cc=frankja@linux.ibm.com \
    --cc=fritz@linux.ibm.com \
    --cc=ggala@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=gra@linux.ibm.com \
    --cc=hari55@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=iii@linux.ibm.com \
    --cc=imbrenda@linux.ibm.com \
    --cc=joey.gouly@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=maz@kernel.org \
    --cc=nrb@linux.ibm.com \
    --cc=oss@nina.schoetterlglausch.eu \
    --cc=oupton@kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=suzuki.poulose@arm.com \
    --cc=svens@linux.ibm.com \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.