From: Andrey Grodzovsky <andrey.grodzovsky@crowdstrike.com>
To: <bpf@vger.kernel.org>, <linux-trace-kernel@vger.kernel.org>,
<live-patching@vger.kernel.org>,
<linux-kselftest@vger.kernel.org>, <linux-doc@vger.kernel.org>,
<rostedt@goodmis.org>, <mbenes@suse.cz>
Cc: <corbet@lwn.net>, <jpoimboe@kernel.org>, <shuah@kernel.org>,
<jolsa@kernel.org>, <mhiramat@kernel.org>,
<stable@vger.kernel.org>, <linux-open-source@crowdstrike.com>
Subject: [RFC PATCH bpf-next v2 0/2] ftrace: deprecate the ftrace_enabled disable switch
Date: Fri, 31 Jul 2026 13:53:56 -0400 [thread overview]
Message-ID: <20260731175358.3542156-1-andrey.grodzovsky@crowdstrike.com> (raw)
This adresses a long-standing issue: kernel.ftrace_enabled=0 silently
disables BPF trampolines (fentry/fexit) and ftrace-based
kprobes/kretprobes. The write succeeds, the hook stops firing with no
error, and re-enabling silently restores it.
The solution chosen is to deny setting this knob to 0 from userspace,
thus preventing this case in the first place. Steven mentioned that the
switch became effectively useless and doesn't serve any meaningful
purpose anymore, and only creates problems for systems that rely on
ftrace, such as Livepatching and eBPF. Any attempt to set it to 0 will
fail with -EOPNOTSUPP. Reading and writing 1 remain unchanged.
Patch 1: the sysctl change plus a doc note.
Patch 2: updates the one selftest that relied on the old disable
behavior.
Changes since v1 :
- test-ftrace.sh: keep the full original disable/reload scenario on
kernels where kernel.ftrace_enabled=0 still works, and only fall
back to the simple "write is refused" check on kernels that
deprecate the knob.(Steven)
[1] https://lore.kernel.org/bpf/20260730163544.2042327-1-andrey.grodzovsky@crowdstrike.com/
Andrey Grodzovsky (2):
ftrace: deprecate disabling via ftrace_enabled sysctl
selftests/livepatch: update test-ftrace.sh for deprecated
ftrace_enabled
Documentation/trace/ftrace.rst | 5 +++
kernel/trace/ftrace.c | 19 ++++----
.../testing/selftests/livepatch/functions.sh | 13 ++++++
.../selftests/livepatch/test-ftrace.sh | 45 ++++++++++++-------
4 files changed, 54 insertions(+), 28 deletions(-)
--
2.34.1
next reply other threads:[~2026-07-31 17:54 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 17:53 Andrey Grodzovsky [this message]
2026-07-31 17:53 ` [RFC PATCH bpf-next v2 1/2] ftrace: deprecate disabling via ftrace_enabled sysctl Andrey Grodzovsky
2026-07-31 17:53 ` [RFC PATCH bpf-next v2 2/2] selftests/livepatch: update test-ftrace.sh for deprecated ftrace_enabled Andrey Grodzovsky
2026-08-01 0:30 ` Joe Lawrence
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260731175358.3542156-1-andrey.grodzovsky@crowdstrike.com \
--to=andrey.grodzovsky@crowdstrike.com \
--cc=bpf@vger.kernel.org \
--cc=corbet@lwn.net \
--cc=jolsa@kernel.org \
--cc=jpoimboe@kernel.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-open-source@crowdstrike.com \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=live-patching@vger.kernel.org \
--cc=mbenes@suse.cz \
--cc=mhiramat@kernel.org \
--cc=rostedt@goodmis.org \
--cc=shuah@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox