From: Petr Mladek <pmladek@suse.com>
To: Harry Hsu <x90613@gmail.com>
Cc: jpoimboe@kernel.org, jikos@kernel.org, mbenes@suse.cz,
joe.lawrence@redhat.com, live-patching@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2] livepatch: Reject livepatches with aliased old_func
Date: Thu, 27 Aug 2026 16:42:48 +0200 [thread overview]
Message-ID: <apBM6MW42WNFLjIO@pathway.suse.cz> (raw)
In-Reply-To: <20260823060734.58443-1-x90613@gmail.com>
On Sun 2026-08-23 14:07:34, Harry Hsu wrote:
> Several symbols can share one address:
>
> ffffffff8ed7fef0 t __do_sys_fork
> ffffffff8ed7fef0 T __ia32_sys_fork
> ffffffff8ed7fef0 T __x64_sys_fork
>
> klp_find_ops() looks the ops up by func->old_func, i.e. by address, so
> two klp_funcs of the same livepatch naming two of these symbols resolve
> to the same klp_ops and are both pushed onto one ops->func_stack.
>
> This breaks the assumption that a single livepatch contributes at most
> one entry to any func_stack. klp_ftrace_handler() picks the entry at
> the top of the stack, but when both entries belong to the same livepatch
> there is nothing that says which of them should be used in the PATCHED
> state, and the UNPATCHED state has to end up at the original function
> either way. klp_check_stack_func() cannot tell them apart either: it
> asks whether the preceding entry is the original function or another
> livepatch's replacement, and an aliased sibling is neither.
>
> Patching two aliases of one function from a single livepatch was never
> meaningful, so reject it while the object is being initialized rather
> than leave the redirection undefined. Compare the resolved old_func of
> each klp_func against the ones already resolved for the same klp_object
> and return -EINVAL on a match, naming both symbols so that the offending
> pair can be found in the livepatch source.
>
> Fixes: 3c33f5b99d68 ("livepatch: support for repatching a function")
> Suggested-by: Petr Mladek <pmladek@suse.com>
> Signed-off-by: Harry Hsu <x90613@gmail.com>
> ---
> v2:
> - Drop the klp_check_stack_func() change. As Petr pointed out, using
> list_is_last() only made the last entry behave, still checked the
> aliased sibling's range for the other entries, and did nothing about
> klp_ftrace_handler() being unable to pick between them. Reject the
> livepatch in klp_init_object_loaded() instead, as suggested.
> - Rewrite the changelog around rejecting the configuration rather than
> around the out-of-bounds read that v1 described.
>
> Link: https://lore.kernel.org/all/20260812140232.48079-1-x90613@gmail.com/
>
> kernel/livepatch/core.c | 17 ++++++++++++++++-
> 1 file changed, 16 insertions(+), 1 deletion(-)
The patch makes sense, looks good and passes selftests:
Reviewed-by: Petr Mladek <pmladek@suse.com>
Tested-by: Petr Mladek <pmladek@suse.com>
Best Regards,
Petr
PS: I am going to wait one week. Then I will push it if nobody
complained in the meantime.
next prev parent reply other threads:[~2026-08-27 14:42 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-23 6:07 [PATCH v2] livepatch: Reject livepatches with aliased old_func Harry Hsu
2026-08-23 6:23 ` sashiko-bot
2026-08-27 15:45 ` Petr Mladek
2026-08-28 12:52 ` [PATCH 0/2] livepatch: Clear relocations when klp_init_object_loaded() fails Petr Mladek
2026-08-28 12:52 ` [PATCH 1/2] livepatch: Move code for updating livepatch object relocations Petr Mladek
2026-08-28 17:02 ` Song Liu
2026-08-28 17:41 ` Josh Poimboeuf
2026-08-28 17:52 ` Song Liu
2026-08-28 12:52 ` [PATCH 2/2] livepatch: Clean up klp_init_object_loaded() when fails Petr Mladek
2026-08-28 17:44 ` Song Liu
2026-08-27 14:42 ` Petr Mladek [this message]
2026-08-27 22:57 ` [PATCH v2] livepatch: Reject livepatches with aliased old_func Josh Poimboeuf
2026-08-28 9:25 ` Miroslav Benes
2026-08-28 16:17 ` Song Liu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apBM6MW42WNFLjIO@pathway.suse.cz \
--to=pmladek@suse.com \
--cc=jikos@kernel.org \
--cc=joe.lawrence@redhat.com \
--cc=jpoimboe@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=live-patching@vger.kernel.org \
--cc=mbenes@suse.cz \
--cc=x90613@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.