mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-08-09 06:14:34 +02:00
A kprobe can be hit while another kprobe is in KPROBE_HIT_SS state. This
can happen when tracing or perf code runs from the debug exception path
while the first kprobe is preparing or executing its out-of-line
single-step instruction.
Currently arm64 treats a kprobe hit in KPROBE_HIT_SS as unrecoverable,
the same as a hit in KPROBE_REENTER. This is too strict. A hit in
KPROBE_HIT_SS is still a one-level reentry and can be handled by saving
the current kprobe state and setting up single-step for the new probe,
just like reentry from KPROBE_HIT_ACTIVE or KPROBE_HIT_SSDONE.
The truly unrecoverable case is hitting another kprobe while already in
KPROBE_REENTER, because the reentry save area has already been consumed.
Move KPROBE_HIT_SS to the recoverable reentry cases and leave
KPROBE_REENTER as the unrecoverable nested reentry case.
This change also requires saving saved_irqflag in struct prev_kprobe.
When a nested kprobe calls kprobes_save_local_irqflag(), it overwrites
kcb->saved_irqflag with the currently masked DAIF value, losing the
outer kprobe's original DAIF state. Without this fix, when the outer
kprobe's single-step finishes, kprobes_restore_local_irqflag() applies
the wrong DAIF mask and leaves interrupts permanently disabled.
Extend struct prev_kprobe with a saved_irqflag field and save/restore it
alongside kp and status. This ensures the outer kprobe's original
interrupt state is preserved across reentry.
This mirrors the x86 fix in commit 6a5022a56a
("kprobes/x86: Allow to handle reentered kprobe on single-stepping").
Signed-off-by: Pu Hu <hupu@transsion.com>
Signed-off-by: Hongyan Xia <hongyan.xia@transsion.com>
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
59 lines
1.4 KiB
C
59 lines
1.4 KiB
C
/* SPDX-License-Identifier: GPL-2.0-only */
|
|
/*
|
|
* arch/arm64/include/asm/kprobes.h
|
|
*
|
|
* Copyright (C) 2013 Linaro Limited
|
|
*/
|
|
|
|
#ifndef _ARM_KPROBES_H
|
|
#define _ARM_KPROBES_H
|
|
|
|
#include <asm-generic/kprobes.h>
|
|
|
|
#ifdef CONFIG_KPROBES
|
|
#include <linux/types.h>
|
|
#include <linux/ptrace.h>
|
|
#include <linux/percpu.h>
|
|
|
|
#define __ARCH_WANT_KPROBES_INSN_SLOT
|
|
#define MAX_INSN_SIZE 2
|
|
|
|
#define flush_insn_slot(p) do { } while (0)
|
|
#define kretprobe_blacklist_size 0
|
|
|
|
#include <asm/probes.h>
|
|
|
|
struct prev_kprobe {
|
|
struct kprobe *kp;
|
|
unsigned int status;
|
|
|
|
/*
|
|
* The original DAIF state of the outer kprobe, saved here before
|
|
* a nested kprobe overwrites kcb->saved_irqflag during reentry.
|
|
*/
|
|
unsigned long saved_irqflag;
|
|
};
|
|
|
|
/* per-cpu kprobe control block */
|
|
struct kprobe_ctlblk {
|
|
unsigned int kprobe_status;
|
|
unsigned long saved_irqflag;
|
|
struct prev_kprobe prev_kprobe;
|
|
};
|
|
|
|
void arch_remove_kprobe(struct kprobe *);
|
|
int kprobe_fault_handler(struct pt_regs *regs, unsigned int fsr);
|
|
void __kretprobe_trampoline(void);
|
|
void __kprobes *trampoline_probe_handler(struct pt_regs *regs);
|
|
|
|
#endif /* CONFIG_KPROBES */
|
|
|
|
int __kprobes kprobe_brk_handler(struct pt_regs *regs,
|
|
unsigned long esr);
|
|
int __kprobes kprobe_ss_brk_handler(struct pt_regs *regs,
|
|
unsigned long esr);
|
|
int __kprobes kretprobe_brk_handler(struct pt_regs *regs,
|
|
unsigned long esr);
|
|
|
|
#endif /* _ARM_KPROBES_H */
|