From: Josh Poimboeuf <jpoimboe@redhat.com>
To: Ingo Molnar <mingo@kernel.org>
Cc: Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, "H. Peter Anvin" <hpa@zytor.com>,
x86@kernel.org, linux-kernel@vger.kernel.org,
live-patching@vger.kernel.org, Michal Marek <mmarek@suse.cz>,
Peter Zijlstra <peterz@infradead.org>,
Andy Lutomirski <luto@kernel.org>, Borislav Petkov <bp@alien8.de>,
Linus Torvalds <torvalds@linux-foundation.org>,
Andi Kleen <andi@firstfloor.org>, Pedro Alves <palves@redhat.com>,
Namhyung Kim <namhyung@gmail.com>,
Bernd Petrovitsch <bernd@petrovitsch.priv.at>,
Chris J Arges <chris.j.arges@canonical.com>,
Andrew Morton <akpm@linux-foundation.org>,
Konrad Rzeszutek Wilk <konrad.wilk@oracle.com>,
Boris Ostrovsky <boris.ostrovsky@oracle.com>,
David Vrabel <david.vrabel@citrix.com>,
Jeremy Fitzhardinge <jeremy@goop.org>,
Chris Wright <chrisw@sous-sol.org>,
Alok Kataria <akataria@vmware.com>,
Rusty Russell <rusty@rustcorp.com.au>,
Herbert Xu <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
Pavel Machek <pavel@ucw.cz>,
"Rafael J. Wysocki" <rjw@rjwysocki.net>,
Len Brown <len.brown@intel.com>,
Matt Fleming <matt.fleming@intel.com>,
Arnaldo Carvalho de Melo <acme@infradead.org>
Subject: Re: [PATCH v11 00/20] Compile-time stack validation
Date: Mon, 14 Sep 2015 09:10:23 -0500 [thread overview]
Message-ID: <20150914141023.GA13856@treble.redhat.com> (raw)
In-Reply-To: <20150914131952.GA29451@gmail.com>
On Mon, Sep 14, 2015 at 03:19:52PM +0200, Ingo Molnar wrote:
> > > In this case it would be a simple:
> > >
> > > debuginfo check all
> > >
> > > to check everything. You can also make the selection of debuginfo components
> > > to check a regular option, not a subcommand.
> >
> > The reason I proposed a name change is that it will soon do *more* than just
> > checking. It will also do CFI generation by modifying the object file.
> >
> > What subcommand would you suggest for the following?
> >
> > - do frame pointer validation; and
> >
> > - if CFI exists, do CFI validation, else do CFI generation.
>
> The main functionality here is to fix up the CFI info, so I'd name it:
>
> debuginfo fix cfi
>
> where the 'fix' subcommand would use functionality from the 'check' subcommand to
> see whether there's CFI info present (and if yes, sanity check it and warn if it's
> not good).
I still don't see how that would work. Here's how we would achieve that
example with my latest proposal:
stacktool --check-frame-pointer --check-cfi --gen-cfi
Notice how clear it is *exactly* what the tool is doing.
On the other hand, "debuginfo fix cfi" hides two of the three tasks.
It's also confusing and inconsistent: use the "check" subcommand for
checking, but use the "fix" subcommand for both checking *and*
generation? That's far from obvious for the user.
Further, with my proposal all three options can be added and removed in
various combinations. So you can do things like:
stacktool --gen-cfi
stacktool --check-frame-pointer --gen-cfi
stacktool --check-cfi --gen-cfi
How would you do those with subcommands?
> > But note these examples are still related to stacks, so having "stack" in the
> > name of the tool wouldn't be limiting (for these examples at least).
>
> Absolutely, I'd name it 'debuginfo' at minimum to not unnecessarily limit things
> at the inception of the tool with 'stackfix'.
Actually I would use the same argument *against* debuginfo. We've
already identified a realistic potential usage that's unrelated to debug
info: stack size checking. "debuginfo" is too limiting for that case.
OTOH, I don't think we've yet conceived of any non-stack-related uses of
the tool (other than some suggestions which are outside the scope of its
core functionality of analyzing all code paths). So I really think
something with "stack" in the name would be appropriate.
> > I proposed the "fix" in "stackfix" because it will do more than just checking:
> > it will also be able to modify the object file (as I describe above). And
> > "stack" because thus far the proposed scope of the tool is strictly related to
> > stacks.
> >
> > I think "debuginfo" is limiting in its own way. The core functionality of the
> > tool is to analyze all possible code paths, which isn't directly related to
> > debuginfo. We might want to do other kinds of code path analysis which are
> > unrelated to debuginfo.
>
> So if you can think of an even more generic name than 'debuginfo', that would be
> even better - what I objected to was the limiting 'stackfix' name.
>
> For example 'binary' might work well too, here's a few mockup subcommands:
>
> binary check fp # checks framepointers in a binary
> binary check all # checks everything it can in a binary
> binary generate cfi # generates CFI info
> binary ls # prints section sizes
> binary compress # strip out NOPs and other padding from a binary if possible
>
> (But 'fix' instead of 'generate' would work as well.)
>
> Note how intuitive the wording it, it's almost a free flowing English sentence.
That's way too generic IMO. A tool named "binary" could do practically
anything. The name doesn't give the user any idea about what it
actually does.
Also the proposed subcommands "ls" and "compress" have nothing to do
with recursive code path analysis and really belong in separate tools.
I really don't see any benefit to making a big monolithic tool which
does all things related to ELF/DWARF binary analysis. There are already
a lot of good tools out there which do a lot of those things.
I don't see any good reason to grow this tool beyond its core
functionality of recursive code analysis. At some point we have to draw
a reasonable line in the sand about what it will eventually do.
Otherwise we should just call it "tool" ;-)
--
Josh
prev parent reply other threads:[~2015-09-14 14:10 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-24 14:45 [PATCH v11 00/20] Compile-time stack validation Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 01/20] x86/asm: Frame pointer macro cleanup Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 02/20] x86/asm: Add C versions of frame pointer macros Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 03/20] x86/stackvalidate: Compile-time stack validation Josh Poimboeuf
2015-08-26 14:26 ` Andi Kleen
2015-08-27 14:29 ` Josh Poimboeuf
2015-08-28 17:26 ` Andi Kleen
2015-08-28 19:54 ` Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 04/20] x86/stackvalidate: Add file and directory ignores Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 05/20] x86/stackvalidate: Add ignore macros Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 06/20] x86/xen: Add stack frame dependency to hypercall inline asm calls Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 07/20] x86/paravirt: Add stack frame dependency to PVOP " Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 08/20] x86/paravirt: Create a stack frame in PV_CALLEE_SAVE_REGS_THUNK Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 09/20] x86/amd: Set ELF function type for vide() Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 10/20] x86/reboot: Add ljmp instructions to stackvalidate whitelist Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 11/20] x86/xen: Add xen_cpuid() and xen_setup_gdt() to stackvalidate whitelists Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 12/20] x86/asm/crypto: Create stack frames in aesni-intel_asm.S Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 13/20] x86/asm/crypto: Move .Lbswap_mask data to .rodata section Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 14/20] x86/asm/crypto: Move jump_table " Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 15/20] x86/asm/crypto: Create stack frames in clmul_ghash_mul/update() Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 16/20] x86/asm/entry: Create stack frames in thunk functions Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 17/20] x86/asm/acpi: Create a stack frame in do_suspend_lowlevel() Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 18/20] x86/asm: Create stack frames in rwsem functions Josh Poimboeuf
2015-08-24 14:45 ` [PATCH v11 19/20] x86/asm/efi: Create a stack frame in efi_call() Josh Poimboeuf
2015-08-24 14:46 ` [PATCH v11 20/20] x86/asm/power: Create stack frames in hibernate_asm_64.S Josh Poimboeuf
2015-08-25 8:05 ` [PATCH v11 00/20] Compile-time stack validation Ingo Molnar
2015-08-25 15:25 ` Josh Poimboeuf
2015-08-26 7:07 ` Ingo Molnar
2015-08-26 8:44 ` Jiri Kosina
2015-08-27 13:11 ` Josh Poimboeuf
2015-08-28 8:21 ` Ingo Molnar
2015-08-28 13:54 ` Josh Poimboeuf
2015-09-14 13:19 ` Ingo Molnar
2015-09-14 14:10 ` Josh Poimboeuf [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150914141023.GA13856@treble.redhat.com \
--to=jpoimboe@redhat.com \
--cc=acme@infradead.org \
--cc=akataria@vmware.com \
--cc=akpm@linux-foundation.org \
--cc=andi@firstfloor.org \
--cc=bernd@petrovitsch.priv.at \
--cc=boris.ostrovsky@oracle.com \
--cc=bp@alien8.de \
--cc=chris.j.arges@canonical.com \
--cc=chrisw@sous-sol.org \
--cc=davem@davemloft.net \
--cc=david.vrabel@citrix.com \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=jeremy@goop.org \
--cc=konrad.wilk@oracle.com \
--cc=len.brown@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=live-patching@vger.kernel.org \
--cc=luto@kernel.org \
--cc=matt.fleming@intel.com \
--cc=mingo@kernel.org \
--cc=mingo@redhat.com \
--cc=mmarek@suse.cz \
--cc=namhyung@gmail.com \
--cc=palves@redhat.com \
--cc=pavel@ucw.cz \
--cc=peterz@infradead.org \
--cc=rjw@rjwysocki.net \
--cc=rusty@rustcorp.com.au \
--cc=tglx@linutronix.de \
--cc=torvalds@linux-foundation.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox