create-diff-object: register patchable child functions - #1526
Open
benjamindonnachie wants to merge 1 commit into
Open
benjamindonnachie wants to merge 1 commit into
benjamindonnachie wants to merge 1 commit into
Conversation
Compiler-generated child functions such as *.part.* can have their own profiling call. In that case kpatch_compare_sections() deliberately leaves an unchanged parent unmodified because the child can be patched independently. However, kpatch_create_patches_sections() unconditionally skips every symbol with a parent. The replacement child text and relocations are retained in the module, but no .kpatch.funcs record is emitted, so the kernel never registers or redirects the changed function. Use one predicate for change reporting and patch metadata generation. Register a changed child when it has its own profiling entry and no changed ancestor already carries its replacement code. Continue excluding unpatchable children and children covered by a changed ancestor. Fixes: af1fe26 ("create-diff-object: Avoid unnecessary parent symbol inclusion") Signed-off-by: Benjamin Donnachie <benjamin@py-soft.co.uk> Co-authored-by: OpenAI Codex <codex@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Problem
GCC split
snd_timer_interrupt()into an unchanged wrapper and a changedsnd_timer_interrupt.part.0. The child had its own__fentry__, sokpatch_compare_sections()correctly avoided promoting the unchanged parent.Later,
kpatch_create_patches_sections()unconditionally skipped every symbolwith
sym->parent. The resulting livepatch module contained the changed childtext and its KLP relocations, but no
.kpatch.funcsregistration record. Themodule loaded successfully while the changed execution path remained unpatched.
Validation
make -C kpatch-build -j4(with-Werror): passmake -C test/unit ARCHES=x86_64: pass5.14.0-687.48.1.el9_8.x86_64: passsnd_timer_interrupt.part.0enabled=1,transition=0snd_timer_interrupt.part.0,1andsnd_timer_close_locked,1The failure was discovered while auditing a cumulative security livepatch: the
source/CVE manifest claimed coverage and the module loaded normally, but sysfs
showed the missing child-function registration.
Closes #1525