From: Pekka Paalanen <pq@iki.fi>
To: "Vegard Nossum" <vegard.nossum@gmail.com>
Cc: avi@qumranet.com, linux-kernel@vger.kernel.org,
"Ingo Molnar" <mingo@elte.hu>,
"Christoph Hellwig" <hch@infradead.org>,
"Arjan van de Ven" <arjan@infradead.org>,
"Pavel Roskin" <proski@gnu.org>,
"Steven Rostedt" <rostedt@goodmis.org>,
"Peter Zijlstra" <a.p.zijlstra@chello.nl>,
penberg@cs.helsinki.fi
Subject: Re: mmiotrace bug: recursive probe hit
Date: Fri, 4 Apr 2008 16:18:53 +0300 [thread overview]
Message-ID: <20080404161853.7a10a6e9@daedalus.pq.iki.fi> (raw)
In-Reply-To: <19f34abd0804031440x582674f6sa0dcddb62b0db226@mail.gmail.com>
On Thu, 3 Apr 2008 23:40:28 +0200
"Vegard Nossum" <vegard.nossum@gmail.com> wrote:
> On Thu, Apr 3, 2008 at 11:07 PM, Pekka Paalanen <pq@iki.fi> wrote:
> > ...
> We do indeed limit maxcpus to 1 at run-time if the kernel is compiled
> with CONFIG_SMP. kmemcheck is a debugging facility, and as such,
> actual multiprocessor support is not critical for the purpose of
> kmemcheck, in my opinion. Doesn't the same hold for mmiotrace?
Actually, I think kmemcheck should support SMP even more than mmiotrace.
Mmiotrace is just a reverse engineering tool for hardware drivers, but
kmemcheck as a debugging tool could be valuable specifically on SMP,
think about racing CPUs using and initializing memory. Dropping to UP
might hide those problems.
> > One more idea:
> >
> > D) Emulate the faulting instruction.
> > In __ioremap(), do the mapping, but steal it for mmiotrace's personal use,
> > and return a bogus mapping that is identifiable in #pf handler. When
> > something accesses the bogus mapping, emulate and step over the faulting
> > instruction using the stolen IO memory mapping. This would get rid of
> > the debug trap and single stepping, and also remove the need to disarm
> > the mmio page, which means tracing would work reliably on SMP without
> > any page table kludges. This would also remove the yet another instruction
> > decoding code that mmiotrace has.
> >
> > The catch is the instruction emulation. I see KVM has some emulation code,
> > but I cannot understand it without a deep study that would take me weeks.
> > Is that general enough to be used, or could it be generalized?
> > Mmiotrace, apart from executing the instruction with a modified address,
> > would need to extract the type of IO memory access, width and the data
> > read/written. And since it is dealing with IO memory, the emulation
> > should be very careful to access the hardware exactly like the original
> > instruction would have.
>
> I think that would be extremely difficult to do. I am personally
> trying to stay as far away from opcode decoding (and recoding!
> *shudder*) as possible. I do the minimal decoding for operand sizes,
> etc, which I think you do as well in mmiotrace.
To be honest, I don't know how easy or difficult it is. If there was a
general decoding facility, it shouldn't be that hard to use, if someone
else makes the facility for us ;-)
Could all relevant instructions be represented as three-address-code or
in some other simple form?
This seems to require some experimenting with code.
--
Pekka Paalanen
http://www.iki.fi/pq/
next prev parent reply other threads:[~2008-04-04 13:19 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-03-09 14:40 [RFC] mmiotrace full patch, preview 2 Pekka Paalanen
2008-03-09 14:46 ` Pekka Paalanen
2008-03-27 23:13 ` Vegard Nossum
2008-03-28 18:24 ` Pekka Paalanen
2008-03-28 20:25 ` mmiotrace bug: recursive probe hit Pekka Paalanen
2008-03-30 17:26 ` Pekka Paalanen
2008-04-03 21:07 ` Pekka Paalanen
2008-04-03 21:40 ` Vegard Nossum
2008-04-04 13:18 ` Pekka Paalanen [this message]
2008-04-05 7:36 ` Avi Kivity
2008-04-05 7:40 ` Pekka Enberg
2008-04-05 12:39 ` Avi Kivity
2008-04-05 15:58 ` Avi Kivity
2008-04-06 17:32 ` Pekka Paalanen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080404161853.7a10a6e9@daedalus.pq.iki.fi \
--to=pq@iki.fi \
--cc=a.p.zijlstra@chello.nl \
--cc=arjan@infradead.org \
--cc=avi@qumranet.com \
--cc=hch@infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@elte.hu \
--cc=penberg@cs.helsinki.fi \
--cc=proski@gnu.org \
--cc=rostedt@goodmis.org \
--cc=vegard.nossum@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®