From: Peter Zijlstra <peterz@infradead.org>
To: Josh Poimboeuf <jpoimboe@redhat.com>
Cc: Shinichiro Kawasaki <shinichiro.kawasaki@wdc.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Nicholas Piggin <npiggin@gmail.com>,
Damien Le Moal <Damien.LeMoal@wdc.com>,
andrew.cooper3@citrix.com, jgross@suse.com
Subject: Re: WARNING: can't access registers at asm_common_interrupt
Date: Wed, 11 Nov 2020 18:47:36 +0100 [thread overview]
Message-ID: <20201111174736.GH2628@hirez.programming.kicks-ass.net> (raw)
In-Reply-To: <20201111170536.arx2zbn4ngvjoov7@treble>
On Wed, Nov 11, 2020 at 11:05:36AM -0600, Josh Poimboeuf wrote:
> On Fri, Nov 06, 2020 at 06:04:15AM +0000, Shinichiro Kawasaki wrote:
> > Greetings,
> >
> > I observe "WARNING: can't access registers at asm_common_interrupt+0x1e/0x40"
> > in my kernel test system repeatedly, which is printed by unwind_next_frame() in
> > "arch/x86/kernel/unwind_orc.c". Syzbot already reported that [1]. Similar
> > warning was reported and discussed [2], but I suppose the cause is not yet
> > clarified.
> >
> > The warning was observed with v5.10-rc2 and older tags. I bisected and found
> > that the commit 044d0d6de9f5 ("lockdep: Only trace IRQ edges") in v5.9-rc3
> > triggered the warning. Reverting that from 5.10-rc2, the warning disappeared.
> > May I ask comment by expertise on CC how this commit can relate to the warning?
> >
> > The test condition to reproduce the warning is rather unique (blktests,
> > dm-linear and ZNS device emulation by QEMU). If any action is suggested for
> > further analysis, I'm willing to take it with my test system.
> >
> > Wish this report helps.
> >
> > [1] https://lkml.org/lkml/2020/9/6/231
> > [2] https://lkml.org/lkml/2020/9/8/1538
>
> Shin'ichiro,
>
> Thanks for all the data. It looks like the ORC unwinder is getting
> confused by paravirt patching (with runtime-patched pushf/pop changing
> the stack layout).
>
> <user interrupt>
> exit_to_user_mode_prepare()
> exit_to_user_mode_loop()
> local_irq_disable_exit_to_user()
> local_irq_disable()
> raw_irqs_disabled()
> arch_irqs_disabled()
> arch_local_save_flags()
> pushfq
> <another interrupt>
This is PARAVIRT_XXL only, which is a Xen special. My preference, as
always, is to kill it... Sadly the Xen people have a different opinion.
> Objtool doesn't know about the pushf/pop paravirt patch, so ORC gets
> confused by the changed stack layout.
>
> I'm thinking we either need to teach objtool how to deal with
> save_fl/restore_fl patches, or we need to just get rid of those nasty
> patches somehow. Peter, any thoughts?
Don't use Xen? ;-)
So with PARAVIRT_XXL the compiler will emit something like:
"CALL *pvops.save_fl"
Which we then overwrite at runtime with "pushf; pop %[re]ax" and a few
NOPs.
Now, objtool understands alternatives, and ensures they have the same
stack layout, it has no chance in hell of understanding this, simply
because paravirt_patch.c is magic.
I don't have any immediate clever ideas, but let me ponder it a wee bit.
....
Something really disguisting we could do is recognise the indirect call
offset and emit an extra ORC entry for RIP+1. So the cases are:
CALL *pv_ops.save_fl -- 7 bytes IIRC
CALL $imm; -- 5 bytes
PUSHF; POP %[RE]AX -- 2 bytes
so the RIP+1 (the POP insn) will only ever exist in this case. The
indirect and direct call cases would never land on that IP.
....
> It looks like 044d0d6de9f5 ("lockdep: Only trace IRQ edges") is making
> the problem more likely, by adding the irqs_disabled() check for every
> local_irq_disable().
>
> Also - Peter, Nicholas - is that irqs_disabled() check really necessary
> in local_irq_disable()? Presumably irqs would typically be be enabled
> before calling it?
Yeah, so it's all a giant can of worms that; also see:
https://lkml.kernel.org/r/20200821084738.508092956@infradead.org
The basic idea is to only trace edges, ie. when the hardware state
actually changes. Sadly this means doing a pushf/pop before the cli.
Ideally CLI would store the old IF in CF or something like that, but
alas.
next prev parent reply other threads:[~2020-11-11 17:47 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-06 6:04 Shinichiro Kawasaki
2020-11-06 18:06 ` Josh Poimboeuf
2020-11-09 9:10 ` Shinichiro Kawasaki
2020-11-10 3:19 ` Josh Poimboeuf
2020-11-10 9:19 ` Shinichiro Kawasaki
2020-11-11 17:05 ` Josh Poimboeuf
2020-11-11 17:47 ` Peter Zijlstra [this message]
2020-11-11 18:13 ` Josh Poimboeuf
2020-11-11 18:46 ` Andrew Cooper
2020-11-11 19:42 ` Peter Zijlstra
2020-11-11 19:59 ` Josh Poimboeuf
2020-11-11 20:07 ` Peter Zijlstra
2020-11-11 20:15 ` Josh Poimboeuf
2020-11-11 20:25 ` Andrew Cooper
2020-11-11 20:39 ` Peter Zijlstra
2020-11-13 17:34 ` Andy Lutomirski
2020-11-14 9:16 ` Jürgen Groß
2020-11-14 18:10 ` Andy Lutomirski
2020-11-15 6:33 ` Jürgen Groß
2020-11-15 16:05 ` Andy Lutomirski
2020-11-15 16:13 ` Jürgen Groß
2020-11-16 11:56 ` Jürgen Groß
2020-11-16 13:04 ` Peter Zijlstra
2020-11-18 6:47 ` Jürgen Groß
2020-11-18 8:22 ` Peter Zijlstra
2020-11-19 11:51 ` Shinichiro Kawasaki
2020-11-19 12:01 ` Peter Zijlstra
2020-11-19 12:28 ` Jürgen Groß
2020-11-19 12:48 ` Shinichiro Kawasaki
2020-11-11 20:35 ` Peter Zijlstra
2020-11-11 20:42 ` Peter Zijlstra
-- strict thread matches above, loose matches on Subject: below --
2020-09-06 20:46 syzbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20201111174736.GH2628@hirez.programming.kicks-ass.net \
--to=peterz@infradead.org \
--cc=Damien.LeMoal@wdc.com \
--cc=andrew.cooper3@citrix.com \
--cc=jgross@suse.com \
--cc=jpoimboe@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=npiggin@gmail.com \
--cc=shinichiro.kawasaki@wdc.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®