From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 80DAE51B194; Thu, 17 Sep 2026 17:55:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789667732; cv=none; b=lrAXXAbdCnKGsE5i4GBTQYVsfPtr9Lsu1y/Qdk2sMBTjd5e/84LwCECUpkFtVRAZvjWxzukjslisbo5EuyrwKv1/kb+DTTPDUTFYXuWK8zOYIzpGjPNCxJjuo92xdMI+u6zUSLJEmp9SM9KApU5nbRokIajCow8CNwyeHM3Gs70= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789667732; c=relaxed/simple; bh=Mtpdd5EglnSJeRG9XOtZlr7iqMzOywPy+3d62XiBkYc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SekJTU3gfv+KkhtezkhplzVaXzVPL41kV9VA+lq6PT8sdNKcPmIfo70xjuhqemri9+SvRVNwR/6Z3v8hS24hWgNiIxf90A72MD91XaBoQkJ6sdZbA8GkYsLLdDRWEjoiOnj/95GBN8VglhQLuLooVfeKh/wmNAbR9zaMTUgLxcU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=ceXLqU7k; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="ceXLqU7k" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 96CC21F00898; Thu, 17 Sep 2026 17:55:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789667730; bh=5FDGLl+tcI7UmUTxMqx6fMMXludhC9plWsFxK88wRIo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=ceXLqU7kOySWe85Yl3AgGrH5cbq6+U6YeWVPdjfWF8M7/8kqgcm8PuHUW3bQowWNi MbQQ9Dp1ktoX1vXdEaDcC36Vw3WlrJObbQg/5Fc9S1aGDV4XSP2R4btsgtDk43BYOo g6OkcRh3tm8h0oSH0XKij8TTfCiSPB/gkM8/od1U= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Karl Mehltretter , Steven Rostedt , Sasha Levin Subject: [PATCH 6.12 0190/1102] tracing: Disable KCOV instrumentation for trace_irqsoff.o Date: Thu, 17 Sep 2026 16:02:13 +0100 Message-ID: <20260917151544.335562513@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151539.408551884@linuxfoundation.org> References: <20260917151539.408551884@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Karl Mehltretter [ Upstream commit 01046072880b654dbadf71be2f645aad4a7b5d87 ] When KCOV runs its boot selftest with whole-kernel instrumentation enabled, it sets current->kcov_mode to KCOV_MODE_TRACE_PC without installing a coverage area. Any instrumented code accepted as task-context coverage in that window dereferences current->kcov_area and crashes. On ARMv5 Versatile PB with CONFIG_KCOV_SELFTEST=y, CONFIG_KCOV_INSTRUMENT_ALL=y and CONFIG_IRQSOFF_TRACER=y, boot hits a NULL pointer fault during the selftest: kcov: running self test Internal error: Oops: 5 [#1] ARM PC is at __sanitizer_cov_trace_pc+0x4c/0x90 Kernel panic - not syncing: Fatal exception A diagnostic run showed the unwanted coverage comes from the IRQs-off tracer callbacks reached from ARM IRQ entry before hardirq context is visible to KCOV: __sanitizer_cov_trace_pc from tracer_hardirqs_off+0x18/0x1cc tracer_hardirqs_off from trace_hardirqs_off+0x34/0x54 trace_hardirqs_off from __irq_svc+0x58/0xb0 __irq_svc from kcov_init+0x7c/0xdc and similarly through tracer_hardirqs_on(). trace_preemptirq.o is already excluded because this tracing path can run from early interrupt code and produce coverage unrelated to syscall inputs. Exclude trace_irqsoff.o as well, instead of requiring users to turn off CONFIG_KCOV_INSTRUMENT_ALL=y, which is the default whole-kernel KCOV mode. With the exclusion in place, the same ARMv5 Versatile PB QEMU test boots through the KCOV selftest and reaches userspace. Tested on ARMv5 Versatile PB QEMU with CONFIG_KCOV_SELFTEST=y, CONFIG_KCOV_INSTRUMENT_ALL=y and CONFIG_IRQSOFF_TRACER=y. Link: https://patch.msgid.link/20260525170428.67211-1-kmehltretter@gmail.com Assisted-by: Codex:gpt-5 Signed-off-by: Karl Mehltretter Signed-off-by: Steven Rostedt Signed-off-by: Sasha Levin --- kernel/trace/Makefile | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/kernel/trace/Makefile b/kernel/trace/Makefile index 057cd975d0146..7cde801a5987d 100644 --- a/kernel/trace/Makefile +++ b/kernel/trace/Makefile @@ -31,9 +31,10 @@ ifdef CONFIG_GCOV_PROFILE_FTRACE GCOV_PROFILE := y endif -# Functions in this file could be invoked from early interrupt -# code and produce random code coverage. +# Functions in these files can run from IRQ entry before hardirq context +# is visible to KCOV, and produce coverage unrelated to syscall inputs. KCOV_INSTRUMENT_trace_preemptirq.o := n +KCOV_INSTRUMENT_trace_irqsoff.o := n CFLAGS_bpf_trace.o := -I$(src) -- 2.53.0