From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from dggsgout12.his.huawei.com (dggsgout12.his.huawei.com [45.249.212.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 66FB6371071; Wed, 1 Jul 2026 03:54:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=45.249.212.56 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782878102; cv=none; b=AEJNi5BEZmcPem5BjNVMzN/kKb5Xi/BdK0VYX1jHPxEvoUJw1HkzL3YblvAbW+qA4EL4SCYPC3gsEdRpiHnHAVIYrTgf37XZpvfMJIqXG9VKlhQ4kgUd4E1jb2giHMvvsvgIafVO9yT7Jdf8OMmgJoRYW5quKZtjgFzz6isHqto= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782878102; c=relaxed/simple; bh=rfNFy/CREZG2E2pifS5OzFkHkrGghuICkA2Qk90joCQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=a4LdkgUPrGxTzxlqLYN88htIKE3+K7m1GNu4YKBHPP5A95d8vZZMRHpmrHevBtQuf1QoXkPLisWxs7g5yz6NBAPN0VvI4lPPlk+R7U58Tlw9SlovGbgqmjD70vb95xVr1nN3IPdACjpjptmSdLtEjBk7QMmCLM6fqRLiYe5Uams= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com; spf=pass smtp.mailfrom=huaweicloud.com; arc=none smtp.client-ip=45.249.212.56 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=huaweicloud.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=huaweicloud.com Received: from mail.maildlp.com (unknown [172.19.163.177]) by dggsgout12.his.huawei.com (SkyGuard) with ESMTPS id 4gqmNs6VbmzKHMXT; Wed, 1 Jul 2026 11:54:37 +0800 (CST) Received: from mail02.huawei.com (unknown [10.116.40.252]) by mail.maildlp.com (Postfix) with ESMTP id EC1544058F; Wed, 1 Jul 2026 11:54:46 +0800 (CST) Received: from huawei.com (unknown [10.67.174.45]) by APP3 (Coremail) with UTF8SMTPA id _Ch0CgBXiyWAj0RqCne9AQ--.26189S23; Wed, 01 Jul 2026 11:54:46 +0800 (CST) From: Tengda Wu To: Namhyung Kim , james.clark@linaro.org, xueshuai@linux.alibaba.com, Li Huafei Cc: Peter Zijlstra , leo.yan@linux.dev, Ian Rogers , Kim Phillips , Mark Rutland , Arnaldo Carvalho de Melo , Ingo Molnar , Bill Wendling , Nick Desaulniers , Alexander Shishkin , Adrian Hunter , Zecheng Li , linux-perf-users@vger.kernel.org, linux-kernel@vger.kernel.org, llvm@lists.linux.dev, Tengda Wu Subject: [PATCH v3 21/21] perf annotate-arm64: Support 'mrs' instruction to track 'current' pointer Date: Wed, 1 Jul 2026 03:53:55 +0000 Message-Id: <20260701035355.752944-22-wutengda@huaweicloud.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260701035355.752944-1-wutengda@huaweicloud.com> References: <20260701035355.752944-1-wutengda@huaweicloud.com> Precedence: bulk X-Mailing-List: linux-perf-users@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CM-TRANSID:_Ch0CgBXiyWAj0RqCne9AQ--.26189S23 X-Coremail-Antispam: 1UD129KBjvJXoW3JrW3KFWrCry3JF18XF47Arb_yoW7ZF47pa yDC34UGr4kGr42gwsxJFZ7Zr1fK397Ww15Cr90vw1SyF42kr1xK3WktFW2kay5Jr95uw13 Jr4DKrWDWws2vF7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUH0b4IE77IF4wAFF20E14v26rWj6s0DM7CY07I20VC2zVCF04k2 6cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI8067AKxVWUAV Cq3wA2048vs2IY020Ec7CjxVAFwI0_Xr0E3s1l8cAvFVAK0II2c7xJM28CjxkF64kEwVA0 rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVWDJVCq3wA2z4x0Y4vE2Ix0cI8IcVCY1x0267 AKxVWxJr0_GcWl84ACjcxK6I8E87Iv67AKxVW0oVCq3wA2z4x0Y4vEx4A2jsIEc7CjxVAF wI0_GcCE3s1le2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2 WlYx0E2Ix0cI8IcVAFwI0_Jr0_Jr4lYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkE bVWUJVW8JwACjcxG0xvY0x0EwIxGrwACjI8F5VA0II8E6IAqYI8I648v4I1lFIxGxcIEc7 CjxVA2Y2ka0xkIwI1lc7CjxVAaw2AFwI0_GFv_Wrylc7CjxVAKzI0EY4vE52x082I5MxAI w28IcxkI7VAKI48JMxC20s026xCaFVCjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr 4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CEb7AF67AKxVW8ZVWrXwCIc40Y0x0EwIxG rwCI42IY6xIIjxv20xvE14v26ryj6F1UMIIF0xvE2Ix0cI8IcVCY1x0267AKxVW8Jr0_Cr 1UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCwCI42IY6I8E87Iv67AKxVW8JVWxJwCI42IY 6I8E87Iv6xkF7I0E14v26r4UJVWxJrUvcSsGvfC2KfnxnUUI43ZEXa7sRNg4S3UUUUU== X-CM-SenderInfo: pzxwv0hjgdqx5xdzvxpfor3voofrz/ Extend update_insn_state() for arm64 to handle the 'mrs' instruction, enabling the tracking of the 'current' task pointer in the kernel. On arm64, the kernel uses the 'sp_el0' system register to store the address of the currently executing 'struct task_struct'. This is typically accessed via the 'get_current()' inline function, resulting in the instruction 'mrs xN, sp_el0'. To resolve the data type of the target register, first verify the access is to 'sp_el0' within a kernel DSO. Then, locate the 'get_current()' inline function's DWARF Die at the current PC and extract its return type (which is 'struct task_struct *'). Introduce a global variable 'task_struct_dieoff' to store the DWARF offset of this type. This is particularly important because the compiler-generated stack canary check code (which loads from 'current->stack_canary') often exists in code sections or leaf functions where the local Compilation Unit (CU) lacks a full 'struct task_struct' definition. Caching the offset allows 'perf annotate' to consistently resolve task-related fields across the entire kernel binary. A real-world example is shown below: ffff8000800deee8 : ffff8000800deef0: mrs x0, sp_el0 // x0 = current * ffff8000800deef4: ldr w1, [x0, #44] Before this commit, the type flow starts with no information: chk [c] reg0 offset=0x2c ok=0 kind=0 cfa : no type information final result: no type information After this commit, the tracker identifies the 'current' pointer from the system register: mrs [8] sp_el0 -> reg0 type='struct task_struct*' chk [c] reg0 offset=0x2c ok=1 kind=1 (struct task_struct*) : Good! found by insn track: 0x2c(reg0) type-offset=0x2c final result: type='struct task_struct' Signed-off-by: Li Huafei Signed-off-by: Tengda Wu --- .../perf/util/annotate-arch/annotate-arm64.c | 84 ++++++++++++++++++- 1 file changed, 83 insertions(+), 1 deletion(-) diff --git a/tools/perf/util/annotate-arch/annotate-arm64.c b/tools/perf/util/annotate-arch/annotate-arm64.c index ec6fd59d51a2..89e3997f6721 100644 --- a/tools/perf/util/annotate-arch/annotate-arm64.c +++ b/tools/perf/util/annotate-arch/annotate-arm64.c @@ -14,6 +14,8 @@ #include "../debug.h" #include "../map.h" #include "../symbol.h" +#include "../dso.h" +#include "../strbuf.h" struct arch_arm64 { struct arch arch; @@ -787,6 +789,81 @@ static void update_adrp_insn_state(struct type_state *state, insn_offset, tsr->addr, dreg); } +static Dwarf_Off task_struct_dieoff; + +static void update_mrs_insn_state(struct type_state *state, + struct data_loc_info *dloc, Dwarf_Die *cu_die, + struct disasm_line *dl, + struct annotated_op_loc *dst) +{ + struct type_state_reg *tsr; + Dwarf_Die type_die; + u32 insn_offset = dl->al.offset; + int dreg = dst->reg1; + Dwarf_Die func_die; + Dwarf_Attribute attr; + u64 ip, pc; + + if (!has_reg_type(state, dreg)) + return; + + tsr = &state->regs[dreg]; + tsr->copied_from = -1; + + /* Handle case difference: LLVM (SP_EL0) vs objdump (sp_el0) */ + if (!dso__kernel(map__dso(dloc->ms->map)) || + strcasecmp(dl->ops.source.raw, "sp_el0")) { + invalidate_reg_state(tsr); + return; + } + + ip = dloc->ms->sym->start + dl->al.offset; + pc = map__rip_2objdump(dloc->ms->map, ip); + + if (!task_struct_dieoff || + !dwarf_offdie(dloc->di->dbg, task_struct_dieoff, &type_die)) { + struct strbuf sb; + char *type_name; + /* + * Find the inline function 'get_current()' Dwarf_Die + * and obtain its return value data type, which should + * be 'struct task_struct*'. + */ + if (!die_find_inlinefunc(cu_die, pc, &func_die) || + !dwarf_attr_integrate(&func_die, DW_AT_type, &attr) || + !dwarf_formref_die(&attr, &type_die)) { + invalidate_reg_state(tsr); + return; + } + + strbuf_init(&sb, 32); + die_get_typename_from_type(&type_die, &sb); + type_name = strbuf_detach(&sb, NULL); + + if (!type_name || strcmp(type_name, "struct task_struct*")) { + invalidate_reg_state(tsr); + return; + } + + /* + * Cache the 'struct task_struct*' die offset globally. + * This allows us to resolve stack canary accesses even + * in CUs that lack a full task_struct definition (e.g., + * compiler-generated entry/exit code). + */ + task_struct_dieoff = dwarf_dieoffset(&type_die); + } + + tsr->type = type_die; + tsr->kind = TSR_KIND_TYPE; + tsr->offset = 0; + tsr->addr = 0; + tsr->ok = true; + + pr_debug_dtp("mrs [%x] sp_el0 -> reg%d", insn_offset, dreg); + pr_debug_type_name(&type_die, tsr->kind); +} + static void update_insn_state_arm64(struct type_state *state, struct data_loc_info *dloc, Dwarf_Die *cu_die, struct disasm_line *dl) @@ -804,7 +881,7 @@ static void update_insn_state_arm64(struct type_state *state, * the destination register itself to prevent incorrect type propagation. */ if (has_reg_type(state, dst->reg1) && - strcmp(dl->ins.name, "adrp") && + strcmp(dl->ins.name, "mrs") && strcmp(dl->ins.name, "adrp") && strcmp(dl->ins.name, "add") && strcmp(dl->ins.name, "mov") && strncmp(dl->ins.name, "ld", 2) && strncmp(dl->ins.name, "st", 2)) { pr_debug_dtp("%s [%x] invalidate reg%d\n", @@ -813,6 +890,11 @@ static void update_insn_state_arm64(struct type_state *state, return; } + if (!strcmp(dl->ins.name, "mrs")) { + update_mrs_insn_state(state, dloc, cu_die, dl, dst); + return; + } + if (!strcmp(dl->ins.name, "adrp")) { update_adrp_insn_state(state, dl, dst); return; -- 2.34.1