From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from desiato.infradead.org (desiato.infradead.org [90.155.92.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DEBE030DD31 for ; Tue, 25 Nov 2025 12:33:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=90.155.92.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764073998; cv=none; b=UGOsOnwNzcjgExjQ+GhFPiTlnx4nH0FEr5eXzqJE4qKV7UCo8gkNRvEHk8B7hWZEU/+Y/XhLF8rzcKHXN1hcebicbLC8j6Pv/CVzOUUFYrND7iDItJxXsYvzW0WSDYbuZ+Ps/Zq5HByiKCezzkzW6yGELCWWM319Kubw/LOFylU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764073998; c=relaxed/simple; bh=N/tDIfqqT2T3PLCiOxGm8cXnYRKMeEzZG6kmuvYEgYc=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=XDCceTn3v+CL49kksFhv3+B5i1T/Gv77+kKkgWp1m6022LRpoUcF3ovm7DynSNhgH828kCBJ72dFjhvI17pUCCC9/5GUBiKfa7oMgN5gmqOIUanf9pJEwHtThXgaB5Jnt7TYFndBrBq50IYlrj3h+khLbtoRDIWj1mlGn8H/qGY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=infradead.org; spf=none smtp.mailfrom=infradead.org; dkim=pass (2048-bit key) header.d=infradead.org header.i=@infradead.org header.b=nuhwpKFc; arc=none smtp.client-ip=90.155.92.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=infradead.org Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=infradead.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=infradead.org header.i=@infradead.org header.b="nuhwpKFc" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=desiato.20200630; h=In-Reply-To:Content-Type:MIME-Version: References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description; bh=k1jELsnDmROjeGY/TuiWhQrbIjJZOcn76lC3kzeMN3Q=; b=nuhwpKFcst5m8KzXs29veMEx+i +fTnUYIl5qYYJiCnSYc661PUIfguRl87mmtIbzCXtUZ9YZeAmlZckvetDmHDErTUNPguRwZmWJeSO e60Fk7BqE7s7ms7GGVPRj3/nM4GrU9ll3MNF38GYwKQlsxKL+/zdK6IGHzTTSDeka+FvDTCjEUE/b rJguO4rmoGAc0tO9q3c8+smLf86QlN4Glegh9CvjrB/1nDzRwEcFR273S7pJ5YQZNTHERs0EotP96 t7twv+VZY0CcZu7yXiCKCwdgKYwhAxKTBZ42JrZEYTrgqZEiGCdEU/wx15ISyhYrKndQ+imANxnBZ 4T3hctUQ==; Received: from 77-249-17-252.cable.dynamic.v4.ziggo.nl ([77.249.17.252] helo=noisy.programming.kicks-ass.net) by desiato.infradead.org with esmtpsa (Exim 4.98.2 #2 (Red Hat Linux)) id 1vNrMZ-00000005mD3-3lCa; Tue, 25 Nov 2025 11:37:40 +0000 Received: by noisy.programming.kicks-ass.net (Postfix, from userid 1000) id 4E2D73002A6; Tue, 25 Nov 2025 13:33:01 +0100 (CET) Date: Tue, 25 Nov 2025 13:33:01 +0100 From: Peter Zijlstra To: x86@kernel.org Cc: linux-kernel@vger.kernel.org, kees@kernel.org, acarmina@redhat.com, jpoimboe@kernel.org, mark.rutland@arm.com, torvalds@linuxfoundation.org, maciej.wieczor-retman@intel.com Subject: Re: [PATCH v2 08/12] x86/bug: Add BUG_FORMAT basics Message-ID: <20251125123301.GO4068168@noisy.programming.kicks-ass.net> References: <20251110114633.202485143@infradead.org> <20251110115757.980264454@infradead.org> <20251125111750.GS4067720@noisy.programming.kicks-ass.net> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20251125111750.GS4067720@noisy.programming.kicks-ass.net> On Tue, Nov 25, 2025 at 12:17:50PM +0100, Peter Zijlstra wrote: > On Mon, Nov 10, 2025 at 12:46:41PM +0100, Peter Zijlstra wrote: > > Opt-in to BUG_FORMAT for x86_64, adjust the BUGTABLE helper and for > > now, just store NULL pointers. > > > > Signed-off-by: Peter Zijlstra (Intel) > > --- > > arch/x86/include/asm/bug.h | 31 +++++++++++++++++++++---------- > > 1 file changed, 21 insertions(+), 10 deletions(-) > > > > --- a/arch/x86/include/asm/bug.h > > +++ b/arch/x86/include/asm/bug.h > > @@ -50,33 +50,44 @@ > > #define __BUG_ENTRY_VERBOSE(file, line) > > #endif > > > > -#define __BUG_ENTRY(file, line, flags) \ > > +#if defined(CONFIG_X86_64) || defined(CONFIG_DEBUG_BUGVERBOSE_DETAILED) > > +#define HAVE_ARCH_BUG_FORMAT > > +#define __BUG_ENTRY_FORMAT(format) \ > > + "\t" __BUG_REL(format) "\t# bug_entry::format\n" > > +#else > > +#define __BUG_ENTRY_FORMAT(format) > > +#endif > > + > > +#define __BUG_ENTRY(format, file, line, flags) \ > > __BUG_REL("1b") "\t# bug_entry::bug_addr\n" \ > > + __BUG_ENTRY_FORMAT(format) \ > > __BUG_ENTRY_VERBOSE(file, line) \ > > "\t.word " flags "\t# bug_entry::flags\n" > > > > -#define _BUG_FLAGS_ASM(ins, file, line, flags, size, extra) \ > > +#define _BUG_FLAGS_ASM(ins, format, file, line, flags, size, extra) \ > > "1:\t" ins "\n" \ > > ".pushsection __bug_table,\"aw\"\n\t" \ > > ANNOTATE_DATA_SPECIAL \ > > "2:\n\t" \ > > - __BUG_ENTRY(file, line, flags) \ > > + __BUG_ENTRY(format, file, line, flags) \ > > "\t.org 2b + " size "\n" \ > > ".popsection\n" \ > > extra > > > > #define _BUG_FLAGS(cond_str, ins, flags, extra) \ > > do { \ > > - asm_inline volatile(_BUG_FLAGS_ASM(ins, "%c0", \ > > - "%c1", "%c2", "%c3", extra) \ > > - : : "i" (WARN_CONDITION_STR(cond_str) __FILE__), \ > > - "i" (__LINE__), \ > > - "i" (flags), \ > > - "i" (sizeof(struct bug_entry))); \ > > + asm_inline volatile(_BUG_FLAGS_ASM(ins, "%c[fmt]", "%c[file]", \ > > + "%c[line]", "%c[fl]", \ > > + "%c[size]", extra) \ > > + : : [fmt] "i" (NULL), \ > > This doesn't work right with KASLR on -- and I hadn't noticed because > most of my machines have nokaslr because of debugability :/ > > When we relocate the kernel, everything shifts by kaslr_offset(), and > that works just fine when both the __bug_table and the target string is > shifted, because then the relative position is the same and so the > relocation keeps working. > > However, when the target is the absolute value 0, this breaks, because 0 > isn't shifted by kaslr_offset() but the __bug_table itself is. > > So the relative entry: > > .long 0 - . > > and its inverse: > > format = (const char *)&bug->format_disp + bug->format_disp; > > then end up at kaslr_offset() and things are sad. > > The relative entry has a SHN_UNDEF relocation, which is ignored by the > relocs tool. > > How is this supposed to be fixed? This seems to work. Is this something we can all live with? It feels a bit like a hack, but there doesn't appear to be anything better at hand. --- diff --git a/lib/bug.c b/lib/bug.c index 581a66b88c5c..8b470cc70afc 100644 --- a/lib/bug.c +++ b/lib/bug.c @@ -48,6 +48,7 @@ #include #include #include +#include extern struct bug_entry __start___bug_table[], __stop___bug_table[]; @@ -145,6 +146,10 @@ static const char *bug_get_format(struct bug_entry *bug) #ifdef HAVE_ARCH_BUG_FORMAT #ifdef CONFIG_GENERIC_BUG_RELATIVE_POINTERS format = (const char *)&bug->format_disp + bug->format_disp; +#ifdef CONFIG_RANDOMIZE_BASE + if ((unsigned long)format == kaslr_offset()) + format = NULL; +#endif #else format = bug->format; #endif