[PATCH v16 14/20] unwind_user: Flexible FP/RA recovery rules
From: Jens Remus <hidden>
Date: 2026-05-21 14:26:40
Also in:
linux-mm, linux-trace-kernel, lkml
Subsystem:
the rest, userspace stack unwinding, x86 architecture (32-bit and 64-bit), x86 stack unwinding · Maintainers:
Linus Torvalds, Josh Poimboeuf, Steven Rostedt, Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, Peter Zijlstra
To enable support for SFrame V3 flexible FDEs with a subsequent patch,
add support for the following flexible frame pointer (FP) and return
address (RA) recovery rules:
FP/RA = *(CFA + offset)
FP/RA = register + offset
FP/RA = *(register + offset)
Note that FP/RA recovery rules that use arbitrary register contents are
only valid when in the topmost frame, as their contents are otherwise
unknown.
This also enables unwinding of user space for architectures, such as
s390, that may save the frame pointer (FP) and/or return address (RA) in
other registers, for instance when in a leaf function.
Reviewed-by: Indu Bhagat <redacted>
Signed-off-by: Jens Remus <redacted>
---
Notes (jremus):
Changes in v15:
- Define dbg_once().
- unwind_user_get_reg(): Use pr_debug_once() instead of WARN_ON_ONCE()
to prevent user-triggered warning/panic. (Sashiko AI)
- unwind_user_next_common(): Handle UNWIND_USER_RULE_CFA_OFFSET for RA
and FP to use dbg_once() instead of WARN_ON_ONCE() to prevent user-
triggered warning/panic. (Sashiko AI)
Changes in v14:
- Improve comment on why UNWIND_USER_RULE_CFA_OFFSET is not implemented.
(Mark Rutland)
arch/x86/include/asm/unwind_user.h | 21 +++++++--
include/linux/unwind_user.h | 10 +++++
include/linux/unwind_user_types.h | 23 +++++++++-
kernel/unwind/sframe.c | 16 ++++++-
kernel/unwind/user.c | 70 +++++++++++++++++++++++++++---
5 files changed, 125 insertions(+), 15 deletions(-)
diff --git a/arch/x86/include/asm/unwind_user.h b/arch/x86/include/asm/unwind_user.h
index 2dfb5ef11e36..9c3417be4283 100644
--- a/arch/x86/include/asm/unwind_user.h
+++ b/arch/x86/include/asm/unwind_user.h@@ -21,15 +21,26 @@ static inline int unwind_user_word_size(struct pt_regs *regs) #define ARCH_INIT_USER_FP_FRAME(ws) \ .cfa_off = 2*(ws), \ - .ra_off = -1*(ws), \ - .fp_off = -2*(ws), \ + .ra = { \ + .rule = UNWIND_USER_RULE_CFA_OFFSET_DEREF,\ + .offset = -1*(ws), \ + }, \ + .fp = { \ + .rule = UNWIND_USER_RULE_CFA_OFFSET_DEREF,\ + .offset = -2*(ws), \ + }, \ .use_fp = true, \ .outermost = false, #define ARCH_INIT_USER_FP_ENTRY_FRAME(ws) \ .cfa_off = 1*(ws), \ - .ra_off = -1*(ws), \ - .fp_off = 0, \ + .ra = { \ + .rule = UNWIND_USER_RULE_CFA_OFFSET_DEREF,\ + .offset = -1*(ws), \ + }, \ + .fp = { \ + .rule = UNWIND_USER_RULE_RETAIN,\ + }, \ .use_fp = false, \ .outermost = false,
@@ -41,4 +52,6 @@ static inline bool unwind_user_at_function_start(struct pt_regs *regs) #endif /* CONFIG_HAVE_UNWIND_USER_FP */ +#include <asm-generic/unwind_user.h> + #endif /* _ASM_X86_UNWIND_USER_H */
diff --git a/include/linux/unwind_user.h b/include/linux/unwind_user.h
index 7bf58f23aa64..6aca38f89ddd 100644
--- a/include/linux/unwind_user.h
+++ b/include/linux/unwind_user.h@@ -33,6 +33,16 @@ static inline int unwind_user_get_ra_reg(unsigned long *val) #define unwind_user_get_ra_reg unwind_user_get_ra_reg #endif +#ifndef unwind_user_get_reg +static inline int unwind_user_get_reg(unsigned long *val, unsigned int regnum) +{ + pr_debug_once("%s (%d): unwind_user_get_reg(%u) not implemented\n", + current->comm, current->pid, regnum); + return -EINVAL; +} +#define unwind_user_get_reg unwind_user_get_reg +#endif + int unwind_user(struct unwind_stacktrace *trace, unsigned int max_entries); #endif /* _LINUX_UNWIND_USER_H */
diff --git a/include/linux/unwind_user_types.h b/include/linux/unwind_user_types.h
index 616cc5ee4586..0d02714a1b5d 100644
--- a/include/linux/unwind_user_types.h
+++ b/include/linux/unwind_user_types.h@@ -27,10 +27,29 @@ struct unwind_stacktrace { unsigned long *entries; }; +#define UNWIND_USER_RULE_DEREF BIT(31) + +enum unwind_user_rule { + UNWIND_USER_RULE_RETAIN, /* entity = entity */ + UNWIND_USER_RULE_CFA_OFFSET, /* entity = CFA + offset */ + UNWIND_USER_RULE_REG_OFFSET, /* entity = register + offset */ + /* DEREF variants */ + UNWIND_USER_RULE_CFA_OFFSET_DEREF = /* entity = *(CFA + offset) */ + UNWIND_USER_RULE_CFA_OFFSET | UNWIND_USER_RULE_DEREF, + UNWIND_USER_RULE_REG_OFFSET_DEREF = /* entity = *(register + offset) */ + UNWIND_USER_RULE_REG_OFFSET | UNWIND_USER_RULE_DEREF, +}; + +struct unwind_user_rule_data { + enum unwind_user_rule rule; + s32 offset; + unsigned int regnum; +}; + struct unwind_user_frame { s32 cfa_off; - s32 ra_off; - s32 fp_off; + struct unwind_user_rule_data ra; + struct unwind_user_rule_data fp; bool use_fp; bool outermost; };
diff --git a/kernel/unwind/sframe.c b/kernel/unwind/sframe.c
index d573c2529926..29a874a67f32 100644
--- a/kernel/unwind/sframe.c
+++ b/kernel/unwind/sframe.c@@ -285,6 +285,18 @@ static __always_inline int __read_fre(struct sframe_section *sec, return -EFAULT; } +static __always_inline void +sframe_init_rule_data(struct unwind_user_rule_data *rule_data, + s32 offset) +{ + if (offset) { + rule_data->rule = UNWIND_USER_RULE_CFA_OFFSET_DEREF; + rule_data->offset = offset; + } else { + rule_data->rule = UNWIND_USER_RULE_RETAIN; + } +} + static __always_inline int __find_fre(struct sframe_section *sec, struct sframe_fde_internal *fde, unsigned long ip,
@@ -335,8 +347,8 @@ static __always_inline int __find_fre(struct sframe_section *sec, fre = prev_fre; frame->cfa_off = fre->cfa_off; - frame->ra_off = fre->ra_off; - frame->fp_off = fre->fp_off; + sframe_init_rule_data(&frame->ra, fre->ra_off); + sframe_init_rule_data(&frame->fp, fre->fp_off); frame->use_fp = SFRAME_V3_FRE_CFA_BASE_REG_ID(fre->info) == SFRAME_BASE_REG_FP; frame->outermost = SFRAME_V3_FRE_RA_UNDEFINED_P(fre->info);
diff --git a/kernel/unwind/user.c b/kernel/unwind/user.c
index afa7c6f6d9b4..c6a2abac78e0 100644
--- a/kernel/unwind/user.c
+++ b/kernel/unwind/user.c@@ -12,6 +12,17 @@ #include <linux/uaccess.h> #include <linux/sframe.h> +#ifdef CONFIG_DYNAMIC_DEBUG + +#define dbg_once(fmt, ...) \ + pr_debug_once("%s (%d): " fmt, current->comm, current->pid, ##__VA_ARGS__) + +#else /* !CONFIG_DYNAMIC_DEBUG */ + +#define dbg_once(args...) no_printk(args) + +#endif /* !CONFIG_DYNAMIC_DEBUG */ + #define for_each_user_frame(state) \ for (unwind_user_start(state); !(state)->done; unwind_user_next(state))
@@ -64,22 +75,67 @@ static int unwind_user_next_common(struct unwind_user_state *state, return -EINVAL; /* Get the Return Address (RA) */ - if (frame->ra_off) { - if (get_user_word(&ra, cfa, frame->ra_off, state->ws)) - return -EINVAL; - } else { + switch (frame->ra.rule) { + case UNWIND_USER_RULE_RETAIN: if (!state->topmost || unwind_user_get_ra_reg(&ra)) return -EINVAL; + break; + case UNWIND_USER_RULE_CFA_OFFSET: + /* + * RA = CFA + offset does not make sense. + * A return address cannot legitimately be a stack address. + */ + dbg_once("UNWIND_USER_RULE_CFA_OFFSET invalid for RA\n"); + return -EINVAL; + case UNWIND_USER_RULE_CFA_OFFSET_DEREF: + ra = cfa + frame->ra.offset; + break; + case UNWIND_USER_RULE_REG_OFFSET: + case UNWIND_USER_RULE_REG_OFFSET_DEREF: + if (!state->topmost || unwind_user_get_reg(&ra, frame->ra.regnum)) + return -EINVAL; + ra += frame->ra.offset; + break; + default: + WARN_ON_ONCE(1); + return -EINVAL; } + if (frame->ra.rule & UNWIND_USER_RULE_DEREF && + get_user_word(&ra, ra, 0, state->ws)) + return -EINVAL; /* Get the Frame Pointer (FP) */ - if (frame->fp_off && get_user_word(&fp, cfa, frame->fp_off, state->ws)) + switch (frame->fp.rule) { + case UNWIND_USER_RULE_RETAIN: + fp = state->fp; + break; + case UNWIND_USER_RULE_CFA_OFFSET: + /* + * FP = CFA + offset is currently not used for FP + * (e.g. SFrame cannot represent this rule). + */ + dbg_once("UNWIND_USER_RULE_CFA_OFFSET unsupported for FP\n"); + return -EINVAL; + case UNWIND_USER_RULE_CFA_OFFSET_DEREF: + fp = cfa + frame->fp.offset; + break; + case UNWIND_USER_RULE_REG_OFFSET: + case UNWIND_USER_RULE_REG_OFFSET_DEREF: + if (!state->topmost || unwind_user_get_reg(&fp, frame->fp.regnum)) + return -EINVAL; + fp += frame->fp.offset; + break; + default: + WARN_ON_ONCE(1); + return -EINVAL; + } + if (frame->fp.rule & UNWIND_USER_RULE_DEREF && + get_user_word(&fp, fp, 0, state->ws)) return -EINVAL; state->ip = ra; state->sp = cfa; - if (frame->fp_off) - state->fp = fp; + state->fp = fp; state->topmost = false; return 0; }
--
2.51.0