From: Matthew Maurer <hidden> Date: 2024-10-30 23:05:07
This patch series is intended for use alongside the Implement DWARF
modversions series [1] to enable RUST and MODVERSIONS at the same
time.
Elsewhere, we've seen a desire for long symbol name support for LTO
symbol names [2], and the previous series came up [3] as a possible
solution rather than hashing, which some have objected [4] to.
This series adds a MODVERSIONS format which uses a section per column.
This avoids userspace tools breaking if we need to make a similar change
to the format in the future - we would do so by adding a new section,
rather than editing the struct definition. In the new format, the name
section is formatted as a concatenated sequence of NUL-terminated
strings, which allows for arbitrary length names.
Emitting the extended format is guarded by CONFIG_EXTENDED_MODVERSIONS,
but the kernel always knows how to validate both the original and
extended formats.
Selecting RUST and MODVERSIONS is now possible if GENDWARFKSYMS is
selected, and will implicitly select EXTENDED_MODVERSIONS.
This series depends upon the module verification refactor patches [5]
that were split off of v5, and DWARF-based versions [1].
[1] https://lore.kernel.org/lkml/20241030170106.1501763-21-samitolvanen@google.com/
[2] https://lore.kernel.org/lkml/20240605032120.3179157-1-song@kernel.org/
[3] https://lore.kernel.org/lkml/ZoxbEEsK40ASi1cY@bombadil.infradead.org/
[4] https://lore.kernel.org/lkml/0b2697fd-7ab4-469f-83a6-ec9ebc701ba0@suse.com/
[5] https://lore.kernel.org/linux-modules/20241015231651.3851138-1-mmaurer@google.com/T/#t
Changes in v8:
- Rebased onto latest version of Sami's series, on top of v6.12-rc5
- Pass --stable when KBUILD_GENDWARFKSYMS_STABLE is set.
- Flipped MODVERSIONS/GENDWARFKSYMS order in deps for CONFIG_RUST
- Picked up trailers
v7: https://lore.kernel.org/r/20241023-extended-modversions-v7-0-339787b43373@google.com
- Fix modpost to detect EXTENDED_MODVERSIONS based on a flag
- Drop patches to fix export_report.pl
- Switch from conditional compilation in .mod.c to conditional emission
in modpost
- Factored extended modversion emission into its own function
- Allow RUST + MODVERSIONS if GENDWARFKSYMS is enabled by selecting
EXTENDED_MODVERSIONS
v6: https://lore.kernel.org/lkml/20241015231925.3854230-1-mmaurer@google.com/
- Splits verification refactor Luis requested out to a separate change
- Clarifies commits around export_report.pl repairs
- Add CONFIG_EXTENDED_MODVERSIONS to control whether extended
information is included in the module, per Luis's request.
v5: https://lore.kernel.org/all/20240925233854.90072-1-mmaurer@google.com/
- Addresses Sami's comments from v3 that I missed in v4 (missing early
return, extra parens)
v4: https://lore.kernel.org/asahi/20240924212024.540574-1-mmaurer@google.com/
- Fix incorrect dot munging in PPC
v3: https://lore.kernel.org/lkml/87le0w2hop.fsf@mail.lhotse/T/
- Split up the module verification refactor into smaller patches, per
Greg K-H's suggestion.
v2: https://lore.kernel.org/all/20231118025748.2778044-1-mmaurer@google.com/
- Add loading/verification refactor before modifying, per Luis's request
v1: https://lore.kernel.org/rust-for-linux/20231115185858.2110875-1-mmaurer@google.com/
--
2.47.0.rc1.288.g06298d1525-goog
---
Matthew Maurer (2):
modules: Support extended MODVERSIONS info
modpost: Produce extended MODVERSIONS information
Sami Tolvanen (1):
rust: Use gendwarfksyms + extended modversions for CONFIG_MODVERSIONS
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
init/Kconfig | 3 +-
kernel/module/Kconfig | 10 +++++
kernel/module/internal.h | 11 +++++
kernel/module/main.c | 92 +++++++++++++++++++++++++++++++++++++----
kernel/module/version.c | 45 ++++++++++++++++++++
rust/Makefile | 33 ++++++++++++++-
scripts/Makefile.modpost | 1 +
scripts/mod/modpost.c | 65 +++++++++++++++++++++++++++--
9 files changed, 267 insertions(+), 17 deletions(-)
---
base-commit: ac746e6156c4d6d7b46ba2102acf644ea2aa4aac
change-id: 20241022-extended-modversions-a7b44dfbfff1
prerequisite-message-id: [off-list ref]
prerequisite-patch-id: 7b7bf0c0c0f484703e29a452dc99dc99711c051b
prerequisite-patch-id: 8cc51bc35ddd4c268b5ccba4c3a74af3dbee8bee
prerequisite-patch-id: 0c4fded10660440fc59e256d6456ac865b70f04b
prerequisite-patch-id: 121f9313b4bde4e374ba37132fbf36e435f7ada5
prerequisite-patch-id: bbd158ee717130fd5d5fc4b7c0613d89c2adcc45
prerequisite-patch-id: af83141b7e527e3d1936326e3c9996bddfa45642
prerequisite-patch-id: 61a51b5c2ab3dc55031fcb2a2b56b4b44b9fabd3
prerequisite-patch-id: 63b4bdc24ff078bd48b8dcec28a334042450796e
prerequisite-patch-id: 429739b875bf7400ece44ec2529f43051b43dd45
prerequisite-patch-id: 55a19e6365f3d60ac5dbea13e320ece71538de25
prerequisite-patch-id: d5ab8e10e837e8193c265dc8548b97655a56db27
prerequisite-patch-id: e2f5364a0c5f3c9341aaa183f97fb7544b1c9dba
prerequisite-message-id: [off-list ref]
prerequisite-patch-id: 08b46e0d1e37c262c08da6db4a87728d7b3047cc
prerequisite-patch-id: 0a1e1ac99f325f4df27bd35f00bd4914f5386cb9
prerequisite-patch-id: 32a05b89083cfed15e5b877664b0c8138c40d09b
prerequisite-patch-id: e192e2a692c40d96cba919e3baae68c441ab25e4
prerequisite-patch-id: 50e884d28c720e90f201aae7801590d19736541b
prerequisite-patch-id: 4d6a826429c519b581d01215e1d9c7373fdfd8c6
prerequisite-patch-id: 0dcd84187b222adf52696dbcab303d683d087dd2
prerequisite-patch-id: 0abe8634eb844a85e8dc51c1cd3970cf96cc494a
prerequisite-patch-id: 5fabb630792f9304f200b5996314f3c2ae4c83ae
prerequisite-patch-id: 4859bef5bb0f6b2142bd7a0e89973f7a79009624
prerequisite-patch-id: a5cf20d27871bf63be64ac79cc81e5eb9d117b89
prerequisite-patch-id: f9cacaf82d1f2a93ade313c44269fb871e7b9ce2
prerequisite-patch-id: 9fcea62d87a577d69ec262fe76b81c889c1bdf92
prerequisite-patch-id: 310f411df60af62002a3898eafe60c1687c0e9b8
prerequisite-patch-id: c21f85ffe5c7684c1ffc87af716e2e50498d5c92
prerequisite-patch-id: a372f88626c3dda51eab6c6af132a76141ff20cc
prerequisite-patch-id: 57d2fe708769154a6494fb1fece56911dea00687
prerequisite-patch-id: e5fb35555f6a95bc9953bddebba0612f422146c4
prerequisite-patch-id: 624e6794e5003cff734873894c2343595b45244b
Best regards,
--
Matthew Maurer [off-list ref]
From: Matthew Maurer <hidden> Date: 2024-10-30 23:05:08
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
kernel/module/internal.h | 11 +++++
kernel/module/main.c | 92 +++++++++++++++++++++++++++++++++++++----
kernel/module/version.c | 45 ++++++++++++++++++++
4 files changed, 162 insertions(+), 10 deletions(-)
@@ -355,6 +355,24 @@ static void dedotify_versions(struct modversion_info *vers,}}+/* Same as normal versions, remove a leading dot if present. */+staticvoiddedotify_ext_version_names(char*str_seq,unsignedlongsize)+{+unsignedlongout=0;+unsignedlongin;+charlast='\0';++for(in=0;in<size;in++){+/* Skip one leading dot */+if(last=='\0'&&str_seq[in]=='.')+in++;+last=str_seq[in];+str_seq[out++]=last;+}+/* Zero the trailing portion of the names table for robustness */+memset(&str_seq[out],0,size-out);+}+/**Undefinedsymbolswhichreferto.funcname,hacktofuncname.Make.TOC.*seemtobedefined(valuesetlater).
@@ -424,10 +442,12 @@ int module_frob_arch_sections(Elf64_Ehdr *hdr,me->arch.toc_section=i;if(sechdrs[i].sh_addralign<8)sechdrs[i].sh_addralign=8;-}-elseif(strcmp(secstrings+sechdrs[i].sh_name,"__versions")==0)+}elseif(strcmp(secstrings+sechdrs[i].sh_name,"__versions")==0)dedotify_versions((void*)hdr+sechdrs[i].sh_offset,sechdrs[i].sh_size);+elseif(strcmp(secstrings+sechdrs[i].sh_name,"__version_ext_names")==0)+dedotify_ext_version_names((void*)hdr+sechdrs[i].sh_offset,+sechdrs[i].sh_size);if(sechdrs[i].sh_type==SHT_SYMTAB)dedotify((void*)hdr+sechdrs[i].sh_offset,
@@ -2039,6 +2039,82 @@ static int elf_validity_cache_index_str(struct load_info *info)return0;}+/**+*elf_validity_cache_index_versions()-Validateandcacheversionindices+*@info:Loadinfotocacheversionindicesin.+*Musthave&load_info->sechdrsand&load_info->secstringspopulated.+*@flags:Loadflags,relevanttosuppressversionloading,see+*uapi/linux/module.h+*+*Ifwe'reignoringmodversionsbasedon@flags,zeroallversionindices+*andreturnvalidity.Othewrisecheck:+*+**If"__version_ext_crcs"ispresent,"__version_ext_names"ispresent+**Thereisanamepresentforeverycrc+*+*Thenpopulate:+*+**&load_info->index.vers+**&load_info->index.vers_ext_crc+**&load_info->index.vers_ext_names+*+*ifpresent.+*+*Return:%0ifvalid,%-ENOEXEConfailure.+*/+staticintelf_validity_cache_index_versions(structload_info*info,intflags)+{+unsignedintvers_ext_crc;+unsignedintvers_ext_name;+size_tcrc_count;+size_tremaining_len;+size_tname_size;+char*name;++/* If modversions were suppressed, pretend we didn't find any */+if(flags&MODULE_INIT_IGNORE_MODVERSIONS){+info->index.vers=0;+info->index.vers_ext_crc=0;+info->index.vers_ext_name=0;+return0;+}++vers_ext_crc=find_sec(info,"__version_ext_crcs");+vers_ext_name=find_sec(info,"__version_ext_names");++/* If we have one field, we must have the other */+if(!!vers_ext_crc!=!!vers_ext_name){+pr_err("extended version crc+name presence does not match");+return-ENOEXEC;+}++/*+*Ifwehaveextendedversioninformation,weshouldhavethesame+*numberofentriesineverysection.+*/+if(vers_ext_crc){+crc_count=info->sechdrs[vers_ext_crc].sh_size/sizeof(s32);+name=(void*)info->hdr++info->sechdrs[vers_ext_name].sh_offset;+remaining_len=info->sechdrs[vers_ext_name].sh_size;++while(crc_count--){+name_size=strnlen(name,remaining_len)+1;+if(name_size>remaining_len){+pr_err("more extended version crcs than names");+return-ENOEXEC;+}+remaining_len-=name_size;+name+=name_size;+}+}++info->index.vers=find_sec(info,"__versions");+info->index.vers_ext_crc=vers_ext_crc;+info->index.vers_ext_name=vers_ext_name;+return0;+}+/***elf_validity_cache_index()-Resolve,validate,cachesectionindices*@info:Loadinfotoreadfromandupdate.
@@ -2053,9 +2129,7 @@ static int elf_validity_cache_index_str(struct load_info *info)**elf_validity_cache_index_mod()**elf_validity_cache_index_sym()**elf_validity_cache_index_str()-*-*Ifversioningisnotsuppressedviaflags,loadtheversionindexfrom-*asectioncalled"__versions"withnovalidation.+**elf_validity_cache_index_versions()**IfCONFIG_SMPisenabled,loadthepercpusectionbynamewithno*validation.
@@ -2078,11 +2152,9 @@ static int elf_validity_cache_index(struct load_info *info, int flags)err=elf_validity_cache_index_str(info);if(err<0)returnerr;--if(flags&MODULE_INIT_IGNORE_MODVERSIONS)-info->index.vers=0;/* Pretend no __versions section! */-else-info->index.vers=find_sec(info,"__versions");+err=elf_validity_cache_index_versions(info,flags);+if(err<0)+returnerr;info->index.pcpu=find_pcpusec(info);
@@ -2293,6 +2365,10 @@ static int rewrite_section_headers(struct load_info *info, int flags)/* Track but don't keep modinfo and version sections. */info->sechdrs[info->index.vers].sh_flags&=~(unsignedlong)SHF_ALLOC;+info->sechdrs[info->index.vers_ext_crc].sh_flags&=+~(unsignedlong)SHF_ALLOC;+info->sechdrs[info->index.vers_ext_name].sh_flags&=+~(unsignedlong)SHF_ALLOC;info->sechdrs[info->index.info].sh_flags&=~(unsignedlong)SHF_ALLOC;return0;
@@ -19,11 +19,28 @@ int check_version(const struct load_info *info,unsignedintversindex=info->index.vers;unsignedinti,num_versions;structmodversion_info*versions;+structmodversion_info_extversion_ext;/* Exporting module didn't supply crcs? OK, we're already tainted. */if(!crc)return1;+/* If we have extended version info, rely on it */+if(info->index.vers_ext_crc){+for_each_modversion_info_ext(version_ext,info){+if(strcmp(version_ext.name,symname)!=0)+continue;+if(*version_ext.crc==*crc)+return1;+pr_debug("Found checksum %X vs module %X\n",+*crc,*version_ext.crc);+gotobad_version;+}+pr_warn_once("%s: no extended symbol version for %s\n",+info->name,symname);+return1;+}+/* No versions at all? modprobe --force does this. */if(versindex==0)returntry_to_force_load(mod,symname)==0;
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2024-10-31 01:22:44
Matthew Maurer [off-list ref] writes:
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
cheers
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-10-31 04:36:58
On Thu, Oct 31, 2024 at 12:22:36PM +1100, Michael Ellerman wrote:
Matthew Maurer [off-list ref] writes:
quoted
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
Michael, Matthew, why make everyone deal with this instead of just
making this an arch thing and ppc would be the only one doing it?
Luis
From: Matthew Maurer <hidden> Date: 2024-10-31 05:06:26
On Wed, Oct 30, 2024 at 9:37 PM Luis Chamberlain [off-list ref] wrote:
On Thu, Oct 31, 2024 at 12:22:36PM +1100, Michael Ellerman wrote:
quoted
Matthew Maurer [off-list ref] writes:
quoted
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
Michael, Matthew, why make everyone deal with this instead of just
making this an arch thing and ppc would be the only one doing it?
Luis
I'm not sure I understand - the PPC changes are in an arch-specific
directory, and triggered through the arch-implemented callback
mod_frob_arch_sections. What would you like done to make it more of an
arch-thing?
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-10-31 07:49:06
On Wed, Oct 30, 2024 at 10:06:12PM -0700, Matthew Maurer wrote:
On Wed, Oct 30, 2024 at 9:37 PM Luis Chamberlain [off-list ref] wrote:
quoted
On Thu, Oct 31, 2024 at 12:22:36PM +1100, Michael Ellerman wrote:
quoted
Matthew Maurer [off-list ref] writes:
quoted
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
Michael, Matthew, why make everyone deal with this instead of just
making this an arch thing and ppc would be the only one doing it?
Luis
I'm not sure I understand - the PPC changes are in an arch-specific
directory, and triggered through the arch-implemented callback
mod_frob_arch_sections. What would you like done to make it more of an
arch-thing?
Sorry, yes, I see that now, that's what I get for late night patch
review. Nevermidn, this all looks good to me now.
Luis
From: Matthew Maurer <hidden> Date: 2024-11-07 19:40:18
Adding Lucas DeMarchi to the thread after voicing an interest in the
modpost patch.
On Thu, Oct 31, 2024 at 12:49 AM Luis Chamberlain [off-list ref] wrote:
On Wed, Oct 30, 2024 at 10:06:12PM -0700, Matthew Maurer wrote:
quoted
On Wed, Oct 30, 2024 at 9:37 PM Luis Chamberlain [off-list ref] wrote:
quoted
On Thu, Oct 31, 2024 at 12:22:36PM +1100, Michael Ellerman wrote:
quoted
Matthew Maurer [off-list ref] writes:
quoted
Adds a new format for MODVERSIONS which stores each field in a separate
ELF section. This initially adds support for variable length names, but
could later be used to add additional fields to MODVERSIONS in a
backwards compatible way if needed. Any new fields will be ignored by
old user tooling, unlike the current format where user tooling cannot
tolerate adjustments to the format (for example making the name field
longer).
Since PPC munges its version records to strip leading dots, we reproduce
the munging for the new format. Other architectures do not appear to
have architecture-specific usage of this information.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
arch/powerpc/kernel/module_64.c | 24 ++++++++++-
Acked-by: Michael Ellerman <mpe@ellerman.id.au> (powerpc)
Michael, Matthew, why make everyone deal with this instead of just
making this an arch thing and ppc would be the only one doing it?
Luis
I'm not sure I understand - the PPC changes are in an arch-specific
directory, and triggered through the arch-implemented callback
mod_frob_arch_sections. What would you like done to make it more of an
arch-thing?
Sorry, yes, I see that now, that's what I get for late night patch
review. Nevermidn, this all looks good to me now.
Luis
From: Matthew Maurer <hidden> Date: 2024-10-30 23:05:10
Generate both the existing modversions format and the new extended one
when running modpost. Presence of this metadata in the final .ko is
guarded by CONFIG_EXTENDED_MODVERSIONS.
We no longer generate an error on long symbols in modpost if
CONFIG_EXTENDED_MODVERSIONS is set, as they can now be appropriately
encoded in the extended section. These symbols will be skipped in the
previous encoding. An error will still be generated if
CONFIG_EXTENDED_MODVERSIONS is not set.
Reviewed-by: Sami Tolvanen <samitolvanen@google.com>
Signed-off-by: Matthew Maurer <redacted>
---
kernel/module/Kconfig | 10 ++++++++
scripts/Makefile.modpost | 1 +
scripts/mod/modpost.c | 65 +++++++++++++++++++++++++++++++++++++++++++++---
3 files changed, 72 insertions(+), 4 deletions(-)
@@ -32,6 +32,8 @@ static bool module_enabled;staticboolmodversions;/* Is CONFIG_MODULE_SRCVERSION_ALL set? */staticboolall_versions;+/* Is CONFIG_EXTENDED_MODVERSIONS set? */+staticboolextended_modversions;/* If we are modposting external module set to 1 */staticboolexternal_module;/* Only warn about unresolved symbols */
@@ -1840,9 +1888,14 @@ static void add_versions(struct buffer *b, struct module *mod)continue;}if(strlen(s->name)>=MODULE_NAME_LEN){-error("too long symbol \"%s\" [%s.ko]\n",-s->name,mod->name);-break;+if(extended_modversions)+/* this symbol will only be in the extended info */+continue;+else{+error("too long symbol \"%s\" [%s.ko]\n",+s->name,mod->name);+break;+}}buf_printf(b,"\t{ %#8x, \"%s\" },\n",s->crc,s->name);
From: Matthew Maurer <hidden> Date: 2024-10-31 20:00:42
The question is, if only extended moversions are used, what new tooling
requirements are there? Can you test using only extended modversions?
Luis
I'm not sure precisely what you're asking for. Do you want:
1. A kconfig that suppresses the emission of today's MODVERSIONS
format? This would be fairly easy to do, but I was leaving it enabled
for compatibility's sake, at least until extended modversions become
more common. This way existing `kmod` tools and kernels would continue
to be able to load new-style modules.
2. libkmod support for parsing the new format? I can do that fairly
easily too, but wanted the format actually decided on and accepted
before I started modifying things that read modversions.
3. Something else? Maybe I'm not understanding your comment?
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-11-01 21:10:25
On Thu, Oct 31, 2024 at 01:00:28PM -0700, Matthew Maurer wrote:
quoted
The question is, if only extended moversions are used, what new tooling
requirements are there? Can you test using only extended modversions?
Luis
I'm not sure precisely what you're asking for. Do you want:
1. A kconfig that suppresses the emission of today's MODVERSIONS
format?
Yes that's right, a brave new world, and with the warning of that.
This would be fairly easy to do, but I was leaving it enabled
for compatibility's sake, at least until extended modversions become
more common. This way existing `kmod` tools and kernels would continue
to be able to load new-style modules.
Sure, understood why we'd have both.
2. libkmod support for parsing the new format? I can do that fairly
easily too, but wanted the format actually decided on and accepted
before I started modifying things that read modversions.
This is implied, what I'd like is for an A vs B comparison to be able to
be done on even without rust modules, so that we can see if really
libkmod changes are all that's needed. Does boot fail without a new
libkmod for this? If so the Kconfig should specificy that for this new
brave new world.
If a distribution can leverage just one format, why would they not
consider it if they can ensure the proper tooling is in place. We
haven't itemized the differences in practice and this could help
with this. One clear difference so far is the kabi stuff, but that's
just evaluating one way of doing things so far, I suspect we'll get
more review on that from Petr soon.
Luis
From: Matthew Maurer <hidden> Date: 2024-11-06 00:27:04
On Fri, Nov 1, 2024 at 2:10 PM Luis Chamberlain [off-list ref] wrote:
On Thu, Oct 31, 2024 at 01:00:28PM -0700, Matthew Maurer wrote:
quoted
quoted
The question is, if only extended moversions are used, what new tooling
requirements are there? Can you test using only extended modversions?
Luis
I'm not sure precisely what you're asking for. Do you want:
1. A kconfig that suppresses the emission of today's MODVERSIONS
format?
Yes that's right, a brave new world, and with the warning of that.
OK, I can send another revision with a suppression config, perhaps
CONFIG_NO_BASIC_MODVERSIONS
quoted
This would be fairly easy to do, but I was leaving it enabled
for compatibility's sake, at least until extended modversions become
more common. This way existing `kmod` tools and kernels would continue
to be able to load new-style modules.
Sure, understood why we'd have both.
quoted
2. libkmod support for parsing the new format? I can do that fairly
easily too, but wanted the format actually decided on and accepted
before I started modifying things that read modversions.
This is implied, what I'd like is for an A vs B comparison to be able to
be done on even without rust modules, so that we can see if really
libkmod changes are all that's needed. Does boot fail without a new
libkmod for this? If so the Kconfig should specificy that for this new
brave new world.
libkmod changes are not needed for boot - the userspace tools do not
examine this data for anything inline with boot at the moment, libkmod
only looks at it for kmod_module_get_versions, and modprobe only looks
at that with --show-modversions or --dump-modversions, which are not
normally part of boot.
With the code as is, the only change will be that if a module with
EXTENDED_MODVERSIONS set contains an over-length symbol (which
wouldn't have been possible before), the overlong symbol's modversion
data will not appear in --show-modversions. After patching `libkmod`
in a follow-up patch, long symbols would appear as well. If booted
against an old kernel, long symbols will not have their CRCs in the
list to be checked. However, the old kernel could not export these
symbols, so it will fail to resolve the symbol and fail the load
regardless.
If we add and enable NO_BASIC_MODVERSIONS like you suggested above,
today's --show-modversions will claim there is no modversions data.
Applying a libkmod patch will result in modversions info being
displayed by that command again. If booted against a new kernel,
everything will be fine. If booted against an old kernel, it will
behave as though there is no modversions information.
If a distribution can leverage just one format, why would they not
consider it if they can ensure the proper tooling is in place. We
haven't itemized the differences in practice and this could help
with this. One clear difference so far is the kabi stuff, but that's
The kabi stuff is at least partially decoupled - you can (and it
sounds like from the responses to Sami's change, occasionally might
want to) enable debug symbol based modversions even without extended
modversions. You can also enable extended modversions without the
debug symbol based modversions, though there are less clear use-cases
for that.
just evaluating one way of doing things so far, I suspect we'll get
more review on that from Petr soon.
Luis
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-11-06 02:16:03
On Tue, Nov 05, 2024 at 04:26:51PM -0800, Matthew Maurer wrote:
On Fri, Nov 1, 2024 at 2:10 PM Luis Chamberlain [off-list ref] wrote:
quoted
On Thu, Oct 31, 2024 at 01:00:28PM -0700, Matthew Maurer wrote:
quoted
quoted
The question is, if only extended moversions are used, what new tooling
requirements are there? Can you test using only extended modversions?
Luis
I'm not sure precisely what you're asking for. Do you want:
1. A kconfig that suppresses the emission of today's MODVERSIONS
format?
Yes that's right, a brave new world, and with the warning of that.
OK, I can send another revision with a suppression config, perhaps
CONFIG_NO_BASIC_MODVERSIONS
Great.
quoted
quoted
This would be fairly easy to do, but I was leaving it enabled
for compatibility's sake, at least until extended modversions become
more common. This way existing `kmod` tools and kernels would continue
to be able to load new-style modules.
Sure, understood why we'd have both.
quoted
2. libkmod support for parsing the new format? I can do that fairly
easily too, but wanted the format actually decided on and accepted
before I started modifying things that read modversions.
This is implied, what I'd like is for an A vs B comparison to be able to
be done on even without rust modules, so that we can see if really
libkmod changes are all that's needed. Does boot fail without a new
libkmod for this? If so the Kconfig should specificy that for this new
brave new world.
libkmod changes are not needed for boot - the userspace tools do not
examine this data for anything inline with boot at the moment, libkmod
only looks at it for kmod_module_get_versions, and modprobe only looks
at that with --show-modversions or --dump-modversions, which are not
normally part of boot.
With the code as is, the only change will be that if a module with
EXTENDED_MODVERSIONS set contains an over-length symbol (which
wouldn't have been possible before), the overlong symbol's modversion
data will not appear in --show-modversions. After patching `libkmod`
in a follow-up patch, long symbols would appear as well. If booted
against an old kernel, long symbols will not have their CRCs in the
list to be checked. However, the old kernel could not export these
symbols, so it will fail to resolve the symbol and fail the load
regardless.
Thanks for checking all this. It is exactly what I was looking for.
All this should be part of the cover letter and Kconfig documentation.
If we add and enable NO_BASIC_MODVERSIONS like you suggested above,
today's --show-modversions will claim there is no modversions data.
Applying a libkmod patch will result in modversions info being
displayed by that command again. If booted against a new kernel,
everything will be fine.
*This* is is the sort of information I was also looking for and I think
it would be good to make it clear for the upcoming NO_BASIC_MODVERSIONS.
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
Luis
From: Matthew Maurer <hidden> Date: 2024-11-06 22:19:52
quoted
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
Specifically, if you set NO_BASIC_MODVERSIONS, build a module, and
then load said module with a kernel *before* EXTENDED_MODVERSIONS
existed, it will see no modversion info on the module to check. This
will be true regardless of symbol length.
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
I think a distro will end up preferring using this for all modules,
but was intending to put both in for a transitional period until the
new format was more accepted.
From: Lucas De Marchi <hidden> Date: 2024-11-07 06:27:19
On Wed, Nov 06, 2024 at 02:19:38PM -0800, Matthew Maurer wrote:
quoted
quoted
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
Specifically, if you set NO_BASIC_MODVERSIONS, build a module, and
how are you setting NO_BASIC_MODVERSIONS and loading it in a kernel
that still doesn't have that, i.e. before EXTENDED_MODVERSIONS?
Please Cc me on the format change and if possible submit the libkmod
support.
thanks
Lucas De Marchi
then load said module with a kernel *before* EXTENDED_MODVERSIONS
existed, it will see no modversion info on the module to check. This
will be true regardless of symbol length.
quoted
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
I think a distro will end up preferring using this for all modules,
but was intending to put both in for a transitional period until the
new format was more accepted.
From: Matthew Maurer <hidden> Date: 2024-11-07 19:38:02
On Wed, Nov 6, 2024 at 10:27 PM Lucas De Marchi
[off-list ref] wrote:
On Wed, Nov 06, 2024 at 02:19:38PM -0800, Matthew Maurer wrote:
quoted
quoted
quoted
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
Specifically, if you set NO_BASIC_MODVERSIONS, build a module, and
how are you setting NO_BASIC_MODVERSIONS and loading it in a kernel
that still doesn't have that, i.e. before EXTENDED_MODVERSIONS?
That action would involve e.g. building a module against a 6.13 series
kernel with NO_BASIC_MODVERSIONS and trying insmod it on a 6.12 series
kernel. I know it's not supported, I was just trying to describe the
full matrix of what would happen differently with the proposed
additional config flag.
Please Cc me on the format change and if possible submit the libkmod
support.
It seems awkward to adjust kmod to support a format that still hasn't
been accepted to the kernel. I can send kmod patches to support it,
but since this patch series hasn't been accepted yet, it seemed a bit
premature.
I'll explicitly add you to the format change (patch before this in the
series) and add you to the whole series in v9
thanks
Lucas De Marchi
quoted
then load said module with a kernel *before* EXTENDED_MODVERSIONS
existed, it will see no modversion info on the module to check. This
will be true regardless of symbol length.
quoted
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
I think a distro will end up preferring using this for all modules,
but was intending to put both in for a transitional period until the
new format was more accepted.
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-11-07 22:38:15
On Wed, Nov 06, 2024 at 02:19:38PM -0800, Matthew Maurer wrote:
quoted
quoted
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
Specifically, if you set NO_BASIC_MODVERSIONS, build a module, and
then load said module with a kernel *before* EXTENDED_MODVERSIONS
existed, it will see no modversion info on the module to check. This
will be true regardless of symbol length.
Isn't that just the same as disabling modverisons?
If you select modversions, you get the options to choose:
- old modversions
- old modversions + extended modversions
- extended modversions only
quoted
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
I think a distro will end up preferring using this for all modules,
but was intending to put both in for a transitional period until the
new format was more accepted.
The only thing left I think to test is the impact at runtime, and the
only thing I can think of is first we use find_symbol() on resolve_symbol()
which it took me a while to review and realize that this just uses a
completely different ELF section, the the ksymtab sections which are split up
between the old and the gpl section. But after that we use check_version().
I suspect the major overhead here is in find_symbol() and that's in no way shape
or form affected by your changes, and I also suspect that since the
way you implemented for_each_modversion_info_ext() is just *one* search
there shouldn't be any penalty here at all. Given it took *me* a while
to review all this, I think it would be good for you to also expand your
cover letter to be crystal clear on these expectations to users and
developers and if anything expand on the Kconfig / and add documentation
if we don't document any of this.
I'd still like to see you guys test all this with the new TEST_KALLSYMS.
Luis
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-11-18 22:25:07
On Thu, Nov 07, 2024 at 02:38:13PM -0800, Luis Chamberlain wrote:
The only thing left I think to test is the impact at runtime, and the
only thing I can think of is first we use find_symbol() on resolve_symbol()
which it took me a while to review and realize that this just uses a
completely different ELF section, the the ksymtab sections which are split up
between the old and the gpl section.
Thinking about this some more, if we're going down enabling a new
option, it seems to beg the question if the old *two* ksymtab sections
could just be folded into the a new one where the "gpl only" thing
becomes just one "column" as you call it. Reasons I ask, it seems like
we're duplicating symbol names on ksymtab and for modeversions. Could
you review this a bit?
Luis
From: Matthew Maurer <hidden> Date: 2024-11-19 00:09:46
Thinking about this some more, if we're going down enabling a new
option, it seems to beg the question if the old *two* ksymtab sections
could just be folded into the a new one where the "gpl only" thing
becomes just one "column" as you call it. Reasons I ask, it seems like
we're duplicating symbol names on ksymtab and for modeversions. Could
you review this a bit?
Short answer: We could do this, but I don't necessarily think it's a good idea.
ksymtab and modversions aren't duplicating names even with this patch
series - We have two different formats, one for importing symbols, and
one for exporting them. `__ksymtab`, `__ksymtab_gpl`, and
`__ksymtab_strings` are used to export symbols. `__versions` or the
new `__version_ext_names` and `__version_ext_crcs` are used to import
them. For this reason, in any given compilation unit, a string should
only appear either in the ksymtab (providing it), or in versions
(consuming it).
There also isn't as much immediate technical need for that kind of
rework of the ksymtab format - ksymtab uses a string table for their
names, so the "long name support" that extended modversions provides
to modversions is already present in ksymtab.
Combined, this means that there would be few technical benefits to
this - the primary potential benefit I could see to something like
this would be code complexity reduction, which is a bit of a matter of
personal taste, and mine might not match others'.
However, we could do some things similar to what's going on here:
A. We could try to unify versions and ksymtab (this seems most viable,
but the change in meaning of this data structure has me wary)
B. We could make ksymtab use columnar storage for more things - it
already does so for CRCs, we could theoretically make any or all of
licensing, namespaces, or symbol values columnar.
With the caveat that I am not convinced this restructuring is worth
the churn, the way I would do A would be:
1. Add a field to the `kernel_symbol` that indicates whether the
symbol is import/export (or possibly re-use `value` with a 0 value
after linker resolution to mean "import" instead of export).
2. Generate `kernel_symbol` entries for imported symbols, not just
exported ones.
3. Read `kcrctab` for import symbols to figure out what the expected
crc value is when importing, rather than using versions.
4. Stop generating/reading any of `__versions`, `__version_ext_names`,
`__versions_ext_crcs`, etc.
There are two downsides I can see to this:
1. You cannot make this backwards compatible with existing `kmod`.
(This was the argument given against just enlarging MODVERSIONS symbol
names.)
2. It's hard to be certain that we know about all users of `ksymtab`
in order to ensure they all know the new convention around imported vs
exported symbols.
I think that B would actually make things worse because symbols always
today always have a value, a namespace, a name, and a license. The
only thing that's optional is the CRC, and that's already columnar.
Making the other ones columnar would hurt locality. We'd still need
the strtab sections, or we'd end up with many copies of each
namespace, where today that should get deduped down by the linker.
Columns are good for things that are extensions, optional, or variable
length.
If there are other reasons *for* doing this that I'm not aware of,
what I'd do would be:
1. Use the name as the primary index, same as modversions.
2. Split each other piece into its own column, with a joint iterator.
3. Convert license into a column, with an enum value (currently only
fully exported or GPL).
4. Replace places in the coe where a `struct kernel_symbol *` is used
today with an iterator over the joint columns.
Again, to reiterate, I *do not* think that B is a good idea. A might
be, but the improvement seems sufficiently marginal to me that I don't
know if it's worth the churn.
From: Luis Chamberlain <mcgrof@kernel.org> Date: 2024-11-19 01:33:58
On Mon, Nov 18, 2024 at 04:09:34PM -0800, Matthew Maurer wrote:
quoted
Thinking about this some more, if we're going down enabling a new
option, it seems to beg the question if the old *two* ksymtab sections
could just be folded into the a new one where the "gpl only" thing
becomes just one "column" as you call it. Reasons I ask, it seems like
we're duplicating symbol names on ksymtab and for modeversions. Could
you review this a bit?
Short answer: We could do this, but I don't necessarily think it's a good idea.
Thanks for your review on this. I agree the complexities you outline
don't yet justify the churn.
Luis
From: Matthew Maurer <hidden> Date: 2024-11-21 21:51:40
On Thu, Nov 7, 2024 at 2:38 PM Luis Chamberlain [off-list ref] wrote:
On Wed, Nov 06, 2024 at 02:19:38PM -0800, Matthew Maurer wrote:
quoted
quoted
quoted
If booted against an old kernel, it will
behave as though there is no modversions information.
Huh? This I don't get. If you have the new libkmod and boot
an old kernel, that should just not break becauase well, long
symbols were not ever supported properly anyway, so no regression.
Specifically, if you set NO_BASIC_MODVERSIONS, build a module, and
then load said module with a kernel *before* EXTENDED_MODVERSIONS
existed, it will see no modversion info on the module to check. This
will be true regardless of symbol length.
Isn't that just the same as disabling modverisons?
If you select modversions, you get the options to choose:
- old modversions
- old modversions + extended modversions
- extended modversions only
Yes, what I'm pointing out is that kernels before the introduction of
extended modversions will not know how to read extended modversions,
and so they will treat modules with *only* extended modversions as
though they have no modversions.
quoted
quoted
I'm not quite sure I understood your last comment here though,
can you clarify what you meant?
Anyway, so now that this is all cleared up, the next question I have
is, let's compare a NO_BASIC_MODVERSIONS world now, given that the
userspace requirements aren't large at all, what actual benefits does
using this new extended mod versions have? Why wouldn't a distro end
up preferring this for say a future release for all modules?
I think a distro will end up preferring using this for all modules,
but was intending to put both in for a transitional period until the
new format was more accepted.
The only thing left I think to test is the impact at runtime, and the
only thing I can think of is first we use find_symbol() on resolve_symbol()
which it took me a while to review and realize that this just uses a
completely different ELF section, the the ksymtab sections which are split up
between the old and the gpl section. But after that we use check_version().
I suspect the major overhead here is in find_symbol() and that's in no way shape
or form affected by your changes, and I also suspect that since the
way you implemented for_each_modversion_info_ext() is just *one* search
there shouldn't be any penalty here at all. Given it took *me* a while
to review all this, I think it would be good for you to also expand your
cover letter to be crystal clear on these expectations to users and
developers and if anything expand on the Kconfig / and add documentation
if we don't document any of this.
I can add a commit extending modules.rst, but it's not clear to me
what piece was surprising here - the existing MODVERSIONS format is
*also* in a separate section. Nothing written in the "Module
Versioning" section has been invalidated that I can see.
Things I could think to add:
* Summary of the internal data format (seems odd, since the previous
one isn't here, and I'd think that an implementation detail anyways)
* A warning about the effects of NO_BASIC_MODVERSIONS (probably better
in Kconfig, isn't in the current changeset because the flag isn't
there)
I'd still like to see you guys test all this with the new TEST_KALLSYMS.
I've attached the results of running TEST_KALLSYMS - it appears to be
irrelevant to performance, as you expected.
From: Matthew Maurer <hidden> Date: 2024-10-30 23:05:12
From: Sami Tolvanen <samitolvanen@google.com>
Previously, two things stopped Rust from using MODVERSIONS:
1. Rust symbols are occasionally too long to be represented in the
original versions table
2. Rust types cannot be properly hashed by the existing genksyms
approach because:
* Looking up type definitions in Rust is more complex than C
* Type layout is potentially dependent on the compiler in Rust,
not just the source type declaration.
CONFIG_EXTENDED_MODVERSIONS addresses the first point, and
CONFIG_GENDWARFKSYMS the second. If Rust wants to use MODVERSIONS, allow
it to do so by selecting both features.
Signed-off-by: Sami Tolvanen <samitolvanen@google.com>
Co-developed-by: Matthew Maurer <redacted>
Signed-off-by: Matthew Maurer <redacted>
---
init/Kconfig | 3 ++-
rust/Makefile | 33 +++++++++++++++++++++++++++++++--
2 files changed, 33 insertions(+), 3 deletions(-)
@@ -378,11 +379,36 @@ ifneq ($(or $(CONFIG_ARM64),$(and $(CONFIG_RISCV),$(CONFIG_64BIT))),)__ashlti3__lshrti3endif+ifdef CONFIG_MODVERSIONS+cmd_gendwarfksyms=$(if$(skip_gendwarfksyms),,\+$(callrust_exports,$@,"%s\n",$$3)|\+scripts/gendwarfksyms/gendwarfksyms\+$(if$(KBUILD_GENDWARFKSYMS_STABLE),--stable)\+$(if$(KBUILD_SYMTYPES),--symtypes$(@:.o=.symtypes),)\+$@>>$(dot-target).cmd)+endif+define rule_rustc_library$(callcmd_and_fixdep,rustc_library)$(callcmd,gen_objtooldep)+$(callcmd,gendwarfksyms)endef+define rule_rust_cc_library+$(callif_changed_rule,cc_o_c)+$(callcmd,force_checksrc)+$(callcmd,gendwarfksyms)+endef++# helpers.o uses the same export mechanism as Rust libraries, so ensure symbol+# versions are calculated for the helpers too.+$(obj)/helpers/helpers.o:$(src)/helpers/helpers.c$(recordmcount_source)FORCE++$(callif_changed_rule,rust_cc_library)++# Disable symbol versioning for exports.o to avoid conflicts with the actual+# symbol versions generated from Rust objects.+$(obj)/exports.o:privateskip_gendwarfksyms = 1+$(obj)/core.o:privateskip_clippy = 1$(obj)/core.o:privateskip_flags = -Wunreachable_pub$(obj)/core.o:privaterustc_objcopy = $(foreachsym,$(redirect-intrinsics),--redefine-sym$(sym)=__rust$(sym))