From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
This is the first patch series of a set that will make it possible to be able
to use SFrames[1] in the Linux kernel. A quick recap of the motivation for
doing this.
Currently the only way to get a user space stack trace from a stack
walk (and not just copying large amount of user stack into the kernel
ring buffer) is to use frame pointers. This has a few issues. The biggest
one is that compiling frame pointers into every application and library
has been shown to cause performance overhead.
Another issue is that the format of the frames may not always be consistent
between different compilers and some architectures (s390) has no defined
format to do a reliable stack walk. The only way to perform user space
profiling on these architectures is to copy the user stack into the kernel
buffer.
SFrames is now supported in gcc binutils and soon will also be supported
by LLVM. SFrames acts more like ORC, and lives in the ELF executable
file as its own section. Like ORC it has two tables where the first table
is sorted by instruction pointers (IP) and using the current IP and finding
it's entry in the first table, it will take you to the second table which
will tell you where the return address of the current function is located
and then you can use that address to look it up in the first table to find
the return address of that function, and so on. This performs a user
space stack walk.
Now because the SFrame section lives in the ELF file it needs to be faulted
into memory when it is used. This means that walking the user space stack
requires being in a faultable context. As profilers like perf request a stack
trace in interrupt or NMI context, it cannot do the walking when it is
requested. Instead it must be deferred until it is safe to fault in user
space. One place this is known to be safe is when the task is about to return
back to user space.
Josh originally wrote the PoC of this code and his last version he posted
was back in January:
https://lore.kernel.org/all/cover.1737511963.git.jpoimboe@kernel.org/
That series contained everything from adding a new faultable user space
stack walking code, deferring the stack walk, implementing sframes,
fixing up x86 (VDSO), and even added both the kernel and user space side
of perf to make it work. But Josh also ran out of time to work on it and
I picked it up. As there's several parts to this series, I also broke
it out. Especially since there's parts of his series that do not depend
on each other.
This series contains only the core infrastructure that all the rest needs.
Of the 14 patches, only 2 are x86 specific. The rest is simply the unwinding
code that s390 can build against. I moved the 2 x86 specific to the end
of the series too.
Since multiple tracers (like perf, ftrace, bpf, etc) can attach to the
deferred unwinder and each of these tracers can attach to some or all
of the tasks to trace, there is a many to many relationship. This relationship
needs to be made in interrupt or NMI context so it can not rely on any
allocation. To handle this, a bitmask is used. There's a global bitmask of
size long which will allocate a single bit when a tracer registers for
deferred stack traces. The task struct will also have a bitmask where a
request comes in from one of the tracers to have a deferred stack trace, it
will set the corresponding bit for that tracer it its mask. As one of the bits
represents that a request has been made, this means at most 31 on 32 bit
systems or 63 on 64 bit systems of tracers may be registered at a given time.
This should not be an issue as only one perf application, or ftrace instance
should request a bit. BPF should also use only one bit and handle any
multiplexing for its users.
When the first request is made for a deferred stack trace from a task, it will
generate a unique cookie. This cookie will be used as the identifier for the
user space stack trace. As the user space stack trace does not change while the
task is in the kernel, requests that come in after the first request and before
the task goes back to user space will get the same cookie. If there's dropped
events, and the events dropped miss a task entering user space and coming back
to the kernel, the new stack trace taken when it goes back to user space should
not be used with the events before the drop happened.
When a tracer makes a request, it gets this cookie, and the tasks bitmask
sets the bit for the requesting tracer. A task work is used to have the task
do the callbacks before it goes back to user space. When it does, it will scan
its bitmask and call all the callbacks for the tracers that have their
representing bit set. The callback will receive the user space stack trace as
well as the cookie that was used. It's up to the tracer to use the cookie
or not to map the user space stack trace taken back to the events where
it was requested.
That's the basic idea. Obviously there's more to it than the above
explanation, but each patch explains what it is doing, and it is broken up
step by step.
I run two SFrame meetings once a month (one in Asia friendly timezone and
the other in Europe friendly). We have developers from Google, Oracle, Red Hat,
IBM, EfficiOS, Meta, Microsoft, and more that attend. (If anyone is interested
in attending let me know). I have been running this since December of 2024.
Last year in GNU Cauldron, a few of us got together to discuss the design
and such. We are pretty confident that the current design is sound. We have
working code on top of this and have been testing it.
Since the s390 folks want to start working on this (they have patches to
sframes already from working on the prototypes), I would like this series
to be a separate branch based on top of v6.16-rc2. Then all the subsystems
that want to work on top of this can as there's no real dependency between
them.
I have more patches on top of this series that add perf support, ftrace
support, sframe support and the x86 fix ups (for VDSO). But each of those
patch series can be worked on independently, but they all depend on this
series (although the x86 specific patches at the end isn't necessarily
needed, at least for other architectures).
Please review, and if you are happy with them, lets get them in a branch
that we all can use. I'm happy to take it in my tree if I can get acks on the
x86 code. Or it can be in the tip tree as a separate branch on top of 6.16-rc4
and I'll just base my work on top of that. Doesn't matter either way.
[1] https://sourceware.org/binutils/wiki/sframe
The code for this series is located here:
git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace.git
unwind/core
Changes since v12: https://lore.kernel.org/linux-trace-kernel/20250701005321.942306427@goodmis.org/
- Make unwind_user_start() and unwind_user_next() static. There's no
reason that they need to be used by other files.
- Move for_each_user_frame() macro into user.c
- Remove extra parenthesis around start in for_each_user_frame() macro
(Mathieu Desnoyers)
- Added test when use_fp is true to make sure fp < sp (Jens Remus)
- Make sure the address read is word aligned (Linus Torvalds)
- With new alignment check, updated to handle compat mode.
- Replaced the timestamp with the generated cookie logic again. Instead of
using a 64 bit word where the CPU part of the cookie is just 12 bits,
make it two 32 bit words, where the CPU that the cookie is generated on
is one word and the second word is just a per cpu counter. This allows
for just using a 32 bit cmpxchg which works on all archs that have safe
NMI cmpxchg.
- Now that the timestamp has been replaced by a cookie that uses only a 32
bit cmpxchg(), this code just checks if the architecture has a safe
cmpxchg that can be used in NMI and doesn't do the 64 bit check.
Only the pending value is converted to local_t.
- Removed no longer used local.h headers from unwind_deferred_types.h
Josh Poimboeuf (7):
unwind_user: Add user space unwinding API
unwind_user: Add frame pointer support
unwind_user: Add compat mode frame pointer support
unwind_user/deferred: Add unwind cache
unwind_user/deferred: Add deferred unwinding interface
unwind_user/x86: Enable frame pointer unwinding on x86
unwind_user/x86: Enable compat mode frame pointer unwinding on x86
Steven Rostedt (7):
unwind_user/deferred: Add unwind_user_faultable()
unwind_user/deferred: Make unwind deferral requests NMI-safe
unwind deferred: Use bitmask to determine which callbacks to call
unwind deferred: Use SRCU unwind_deferred_task_work()
unwind: Clear unwind_mask on exit back to user space
unwind: Add USED bit to only have one conditional on way back to user space
unwind: Finish up unwind when a task exits
----
MAINTAINERS | 8 +
arch/Kconfig | 11 +
arch/x86/Kconfig | 2 +
arch/x86/include/asm/unwind_user.h | 42 ++++
arch/x86/include/asm/unwind_user_types.h | 17 ++
arch/x86/kernel/stacktrace.c | 28 +++
include/asm-generic/Kbuild | 2 +
include/asm-generic/unwind_user.h | 5 +
include/asm-generic/unwind_user_types.h | 5 +
include/linux/entry-common.h | 2 +
include/linux/sched.h | 5 +
include/linux/unwind_deferred.h | 79 +++++++
include/linux/unwind_deferred_types.h | 26 +++
include/linux/unwind_user.h | 39 ++++
include/linux/unwind_user_types.h | 39 ++++
kernel/Makefile | 1 +
kernel/exit.c | 2 +
kernel/fork.c | 4 +
kernel/unwind/Makefile | 1 +
kernel/unwind/deferred.c | 363 +++++++++++++++++++++++++++++++
kernel/unwind/user.c | 147 +++++++++++++
21 files changed, 828 insertions(+)
create mode 100644 arch/x86/include/asm/unwind_user.h
create mode 100644 arch/x86/include/asm/unwind_user_types.h
create mode 100644 include/asm-generic/unwind_user.h
create mode 100644 include/asm-generic/unwind_user_types.h
create mode 100644 include/linux/unwind_deferred.h
create mode 100644 include/linux/unwind_deferred_types.h
create mode 100644 include/linux/unwind_user.h
create mode 100644 include/linux/unwind_user_types.h
create mode 100644 kernel/unwind/Makefile
create mode 100644 kernel/unwind/deferred.c
create mode 100644 kernel/unwind/user.c
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Josh Poimboeuf <jpoimboe@kernel.org>
Add optional support for user space frame pointer unwinding. If
supported, the arch needs to enable CONFIG_HAVE_UNWIND_USER_FP and
define ARCH_INIT_USER_FP_FRAME.
By encoding the frame offsets in struct unwind_user_frame, much of this
code can also be reused for future unwinder implementations like sframe.
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Co-developed-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v12: https://lore.kernel.org/20250701005450.888492528@goodmis.org
- Added test when use_fp is true to make sure fp < sp (Jens Remus)
- Make sure the address read is word aligned (Linus Torvalds)
arch/Kconfig | 4 ++
include/asm-generic/Kbuild | 1 +
include/asm-generic/unwind_user.h | 5 +++
include/linux/unwind_user.h | 5 +++
include/linux/unwind_user_types.h | 1 +
kernel/unwind/user.c | 65 ++++++++++++++++++++++++++++++-
6 files changed, 79 insertions(+), 2 deletions(-)
create mode 100644 include/asm-generic/unwind_user.h
@@ -6,13 +6,71 @@#include<linux/sched.h>#include<linux/sched/task_stack.h>#include<linux/unwind_user.h>+#include<linux/uaccess.h>++staticstructunwind_user_framefp_frame={+ARCH_INIT_USER_FP_FRAME+};++staticinlineboolfp_state(structunwind_user_state*state)+{+returnIS_ENABLED(CONFIG_HAVE_UNWIND_USER_FP)&&+state->type==UNWIND_USER_TYPE_FP;+}#define for_each_user_frame(state) \for(unwind_user_start(state);!(state)->done;unwind_user_next(state))staticintunwind_user_next(structunwind_user_state*state){-/* no implementation yet */+structunwind_user_frame*frame;+unsignedlongcfa=0,fp,ra=0;+unsignedintshift;++if(state->done)+return-EINVAL;++if(fp_state(state))+frame=&fp_frame;+else+gotodone;++if(frame->use_fp){+if(state->fp<state->sp)+gotodone;+cfa=state->fp;+}else{+cfa=state->sp;+}++/* Get the Canonical Frame Address (CFA) */+cfa+=frame->cfa_off;++/* stack going in wrong direction? */+if(cfa<=state->sp)+gotodone;++/* Make sure that the address is word aligned */+shift=sizeof(long)==4?2:3;+if((cfa+frame->ra_off)&((1<<shift)-1))+gotodone;++/* Find the Return Address (RA) */+if(get_user(ra,(unsignedlong*)(cfa+frame->ra_off)))+gotodone;++if(frame->fp_off&&get_user(fp,(unsignedlong__user*)(cfa+frame->fp_off)))+gotodone;++state->ip=ra;+state->sp=cfa;+if(frame->fp_off)+state->fp=fp;++return0;++done:+state->done=true;return-EINVAL;}
@@ -27,7 +85,10 @@ static int unwind_user_start(struct unwind_user_state *state)return-EINVAL;}-state->type=UNWIND_USER_TYPE_NONE;+if(IS_ENABLED(CONFIG_HAVE_UNWIND_USER_FP))+state->type=UNWIND_USER_TYPE_FP;+else+state->type=UNWIND_USER_TYPE_NONE;state->ip=instruction_pointer(regs);state->sp=user_stack_pointer(regs);
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Josh Poimboeuf <jpoimboe@kernel.org>
Introduce a generic API for unwinding user stacks.
In order to expand user space unwinding to be able to handle more complex
scenarios, such as deferred unwinding and reading user space information,
create a generic interface that all architectures can use that support the
various unwinding methods.
This is an alternative method for handling user space stack traces from
the simple stack_trace_save_user() API. This does not replace that
interface, but this interface will be used to expand the functionality of
user space stack walking.
None of the structures introduced will be exposed to user space tooling.
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v12: https://lore.kernel.org/20250701005450.721228270@goodmis.org
- Make unwind_user_start() and unwind_user_next() static. There's no
reason that they need to be used by other files.
- Move for_each_user_frame() macro into user.c
- Remove extra parenthesis around start in for_each_user_frame() macro
(Mathieu Desnoyers)
MAINTAINERS | 8 +++++
arch/Kconfig | 3 ++
include/linux/unwind_user.h | 9 +++++
include/linux/unwind_user_types.h | 31 +++++++++++++++++
kernel/Makefile | 1 +
kernel/unwind/Makefile | 1 +
kernel/unwind/user.c | 58 +++++++++++++++++++++++++++++++
7 files changed, 111 insertions(+)
create mode 100644 include/linux/unwind_user.h
create mode 100644 include/linux/unwind_user_types.h
create mode 100644 kernel/unwind/Makefile
create mode 100644 kernel/unwind/user.c
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Steven Rostedt <rostedt@goodmis.org>
Add a new API to retrieve a user space callstack called
unwind_user_faultable(). The difference between this user space stack
tracer from the current user space stack tracer is that this must be
called from faultable context as it may use routines to access user space
data that needs to be faulted in.
It can be safely called from entering or exiting a system call as the code
can still be faulted in there.
This code is based on work by Josh Poimboeuf's deferred unwinding code:
Link: https://lore.kernel.org/all/6052e8487746603bdb29b65f4033e739092d9925.1737511963.git.jpoimboe@kernel.org/
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
include/linux/sched.h | 5 +++
include/linux/unwind_deferred.h | 24 +++++++++++
include/linux/unwind_deferred_types.h | 9 ++++
kernel/fork.c | 4 ++
kernel/unwind/Makefile | 2 +-
kernel/unwind/deferred.c | 60 +++++++++++++++++++++++++++
6 files changed, 103 insertions(+), 1 deletion(-)
create mode 100644 include/linux/unwind_deferred.h
create mode 100644 include/linux/unwind_deferred_types.h
create mode 100644 kernel/unwind/deferred.c
@@ -46,6 +46,7 @@#include<linux/rv.h>#include<linux/uidgid_types.h>#include<linux/tracepoint-defs.h>+#include<linux/unwind_deferred_types.h>#include<asm/kmap_size.h>/* task_struct member predeclarations (sorted alphabetically): */
@@ -1654,6 +1655,10 @@ struct task_struct {structuser_event_mm*user_event_mm;#endif+#ifdef CONFIG_UNWIND_USER+structunwind_task_infounwind_info;+#endif+/* CPU-specific state of this task: */structthread_structthread;
@@ -2135,6 +2137,8 @@ __latent_entropy struct task_struct *copy_process(p->bpf_ctx=NULL;#endif+unwind_task_init(p);+/* Perform scheduler related setup. Assign this task to a CPU. */retval=sched_fork(clone_flags,p);if(retval)
@@ -0,0 +1,60 @@+// SPDX-License-Identifier: GPL-2.0+/*+*Deferreduserspaceunwinding+*/+#include<linux/kernel.h>+#include<linux/sched.h>+#include<linux/slab.h>+#include<linux/unwind_deferred.h>++#define UNWIND_MAX_ENTRIES 512++/**+*unwind_user_faultable-Produceauserstacktraceinfaultablecontext+*@trace:Thedescriptorthatwillstoretheuserstacktrace+*+*Thismustbecalledinaknownfaultablecontext(usuallywhenentering+*orexitinguserspace).Dependingontheavailableimplementations+*the@tracewillbeloadedwiththeaddressesoftheuserspacestacktrace+*ifitcanbefound.+*+*Return:0onsuccessandnegativeonerror+*Onsuccess@tracewillcontaintheuserspacestacktrace+*/+intunwind_user_faultable(structunwind_stacktrace*trace)+{+structunwind_task_info*info=¤t->unwind_info;++/* Should always be called from faultable context */+might_fault();++if(current->flags&PF_EXITING)+return-EINVAL;++if(!info->entries){+info->entries=kmalloc_array(UNWIND_MAX_ENTRIES,sizeof(long),+GFP_KERNEL);+if(!info->entries)+return-ENOMEM;+}++trace->nr=0;+trace->entries=info->entries;+unwind_user(trace,UNWIND_MAX_ENTRIES);++return0;+}++voidunwind_task_init(structtask_struct*task)+{+structunwind_task_info*info=&task->unwind_info;++memset(info,0,sizeof(*info));+}++voidunwind_task_free(structtask_struct*task)+{+structunwind_task_info*info=&task->unwind_info;++kfree(info->entries);+}
@@ -30,7 +50,9 @@ static int unwind_user_next(struct unwind_user_state *state)if(state->done)return-EINVAL;-if(fp_state(state))+if(compat_fp_state(state))+frame=&compat_fp_frame;+elseif(fp_state(state))frame=&fp_frame;elsegotodone;
@@ -51,15 +73,15 @@ static int unwind_user_next(struct unwind_user_state *state)gotodone;/* Make sure that the address is word aligned */-shift=sizeof(long)==4?2:3;+shift=sizeof(long)==4||compat_fp_state(state)?2:3;if((cfa+frame->ra_off)&((1<<shift)-1))gotodone;/* Find the Return Address (RA) */-if(get_user(ra,(unsignedlong*)(cfa+frame->ra_off)))+if(unwind_get_user_long(ra,cfa+frame->ra_off,state))gotodone;-if(frame->fp_off&&get_user(fp,(unsignedlong__user*)(cfa+frame->fp_off)))+if(frame->fp_off&&unwind_get_user_long(fp,cfa+frame->fp_off,state))gotodone;state->ip=ra;
@@ -85,7 +107,9 @@ static int unwind_user_start(struct unwind_user_state *state)return-EINVAL;}-if(IS_ENABLED(CONFIG_HAVE_UNWIND_USER_FP))+if(IS_ENABLED(CONFIG_HAVE_UNWIND_USER_COMPAT_FP)&&in_compat_mode(regs))+state->type=UNWIND_USER_TYPE_COMPAT_FP;+elseif(IS_ENABLED(CONFIG_HAVE_UNWIND_USER_FP))state->type=UNWIND_USER_TYPE_FP;elsestate->type=UNWIND_USER_TYPE_NONE;
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Josh Poimboeuf <jpoimboe@kernel.org>
Cache the results of the unwind to ensure the unwind is only performed
once, even when called by multiple tracers.
The cache nr_entries gets cleared every time the task exits the kernel.
When a stacktrace is requested, nr_entries gets set to the number of
entries in the stacktrace. If another stacktrace is requested, if
nr_entries is not zero, then it contains the same stacktrace that would be
retrieved so it is not processed again and the entries is given to the
caller.
Co-developed-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
include/linux/entry-common.h | 2 ++
include/linux/unwind_deferred.h | 8 +++++++
include/linux/unwind_deferred_types.h | 7 +++++-
kernel/unwind/deferred.c | 31 +++++++++++++++++++++------
4 files changed, 40 insertions(+), 8 deletions(-)
@@ -4,10 +4,13 @@*/#include<linux/kernel.h>#include<linux/sched.h>+#include<linux/sizes.h>#include<linux/slab.h>#include<linux/unwind_deferred.h>-#define UNWIND_MAX_ENTRIES 512+/* Make the cache fit in a 4K page */+#define UNWIND_MAX_ENTRIES \+((SZ_4K-sizeof(structunwind_cache))/sizeof(long))/***unwind_user_faultable-Produceauserstacktraceinfaultablecontext
@@ -24,6 +27,7 @@intunwind_user_faultable(structunwind_stacktrace*trace){structunwind_task_info*info=¤t->unwind_info;+structunwind_cache*cache;/* Should always be called from faultable context */might_fault();
@@ -31,17 +35,30 @@ int unwind_user_faultable(struct unwind_stacktrace *trace)if(current->flags&PF_EXITING)return-EINVAL;-if(!info->entries){-info->entries=kmalloc_array(UNWIND_MAX_ENTRIES,sizeof(long),-GFP_KERNEL);-if(!info->entries)+if(!info->cache){+info->cache=kzalloc(struct_size(cache,entries,UNWIND_MAX_ENTRIES),+GFP_KERNEL);+if(!info->cache)return-ENOMEM;}+cache=info->cache;+trace->entries=cache->entries;++if(cache->nr_entries){+/*+*Theuserstackhasalreadybeenpreviouslyunwoundinthis+*entrycontext.Skiptheunwindandusethecache.+*/+trace->nr=cache->nr_entries;+return0;+}+trace->nr=0;-trace->entries=info->entries;unwind_user(trace,UNWIND_MAX_ENTRIES);+cache->nr_entries=trace->nr;+return0;}
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Steven Rostedt <rostedt@goodmis.org>
Make unwind_deferred_request() NMI-safe so tracers in NMI context can
call it and safely request a user space stacktrace when the task exits.
Note, this is only allowed for architectures that implement a safe
cmpxchg. If an architecture requests a deferred stack trace from NMI
context that does not support a safe NMI cmpxchg, it will get an -EINVAL.
For those architectures, they would need another method (perhaps an
irqwork), to request a deferred user space stack trace. That can be dealt
with later if one of theses architectures require this feature.
Suggested-by: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v12: https://lore.kernel.org/20250701005451.737614486@goodmis.org
- Now that the timestamp has been replaced by a cookie that uses only a 32
bit cmpxchg(), this code just checks if the architecture has a safe
cmpxchg that can be used in NMI and doesn't do the 64 bit check.
Only the pending value is converted to local_t.
include/linux/unwind_deferred_types.h | 4 +-
kernel/unwind/deferred.c | 56 ++++++++++++++++++++++-----
2 files changed, 49 insertions(+), 11 deletions(-)
@@ -12,6 +12,31 @@#include<linux/slab.h>#include<linux/mm.h>+/*+*ForrequestingadeferreduserspacestacktracefromNMIcontext+*thearchitecturemustsupportasafecmpxchginNMIcontext.+*Forthosearchitecturesthatdonothavethat,thenitcannotask+*foradeferreduserspacestacktracefromanNMIcontext.Ifit+*does,thenitwillget-EINVAL.+*/+#if defined(CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG)+# define CAN_USE_IN_NMI 1+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+u32old=0;++returntry_cmpxchg(&info->id.cnt,&old,cnt);+}+#else+# define CAN_USE_IN_NMI 0+/* When NMIs are not allowed, this always succeeds */+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+info->id.cnt=cnt;+returntrue;+}+#endif+/* Make the cache fit in a 4K page */#define UNWIND_MAX_ENTRIES \((SZ_4K-sizeof(structunwind_cache))/sizeof(long))
@@ -52,7 +76,7 @@ static u64 get_cookie(struct unwind_task_info *info)cpu_cnt+=2;cnt=cpu_cnt|1;/* Always make non zero */-if(try_cmpxchg(&info->id.cnt,&old,cnt)){+if(try_assign_cnt(info,cnt)){/* Update the per cpu counter */__this_cpu_write(unwind_ctx_ctr,cpu_cnt);}
@@ -119,11 +143,11 @@ static void unwind_deferred_task_work(struct callback_head *head)structunwind_work*work;u64cookie;-if(WARN_ON_ONCE(!info->pending))+if(WARN_ON_ONCE(!local_read(&info->pending)))return;/* Allow work to come in again */-WRITE_ONCE(info->pending,0);+local_set(&info->pending,0);/**Fromhereonout,thecallbackmustalwaysbecalled,evenifit's
@@ -170,31 +194,43 @@ static void unwind_deferred_task_work(struct callback_head *head)intunwind_deferred_request(structunwind_work*work,u64*cookie){structunwind_task_info*info=¤t->unwind_info;+longpending;intret;*cookie=0;-if(WARN_ON_ONCE(in_nmi()))-return-EINVAL;-if((current->flags&(PF_KTHREAD|PF_EXITING))||!user_mode(task_pt_regs(current)))return-EINVAL;+/* NMI requires having safe cmpxchg operations */+if(!CAN_USE_IN_NMI&&in_nmi())+return-EINVAL;+guard(irqsave)();*cookie=get_cookie(info);/* callback already pending? */-if(info->pending)+pending=local_read(&info->pending);+if(pending)return1;+if(CAN_USE_IN_NMI){+/* Claim the work unless an NMI just now swooped in to do so. */+if(!local_try_cmpxchg(&info->pending,&pending,1))+return1;+}else{+local_set(&info->pending,1);+}+/* The work has been claimed, now schedule it. */ret=task_work_add(current,&info->work,TWA_RESUME);-if(WARN_ON_ONCE(ret))+if(WARN_ON_ONCE(ret)){+local_set(&info->pending,0);returnret;+}-info->pending=1;return0;}
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:58
From: Josh Poimboeuf <jpoimboe@kernel.org>
Add an interface for scheduling task work to unwind the user space stack
before returning to user space. This solves several problems for its
callers:
- Ensure the unwind happens in task context even if the caller may be
running in interrupt context.
- Avoid duplicate unwinds, whether called multiple times by the same
caller or by different callers.
- Create a "context cookie" which allows trace post-processing to
correlate kernel unwinds/traces with the user unwind.
A concept of a "cookie" is created to detect when the stacktrace is the
same. A cookie is generated the first time a user space stacktrace is
requested after the task enters the kernel. As the stacktrace is saved on
the task_struct while the task is in the kernel, if another request comes
in, if the cookie is still the same, it will use the saved stacktrace,
and not have to regenerate one.
The cookie is passed to the caller on request, and when the stacktrace is
generated upon returning to user space, it call the requester's callback
with the cookie as well as the stacktrace. The cookie is cleared
when it goes back to user space. Note, this currently adds another
conditional to the unwind_reset_info() path that is always called
returning to user space, but future changes will put this back to a single
conditional.
A global list is created and protected by a global mutex that holds
tracers that register with the unwind infrastructure. The number of
registered tracers will be limited in future changes. Each perf program or
ftrace instance will register its own descriptor to use for deferred
unwind stack traces.
Note, in the function unwind_deferred_task_work() that gets called when
returning to user space, it uses a global mutex for synchronization which
will cause a big bottleneck. This will be replaced by SRCU, but that
change adds some complex synchronization that deservers its own commit.
Co-developed-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v12: https://lore.kernel.org/20250701005451.571473750@goodmis.org
- Replaced the timestamp with the generated cookie logic again. Instead of
using a 64 bit word where the CPU part of the cookie is just 12 bits,
make it two 32 bit words, where the CPU that the cookie is generated on
is one word and the second word is just a per cpu counter. This allows
for just using a 32 bit cmpxchg which works on all archs that have safe
NMI cmpxchg.
include/linux/unwind_deferred.h | 24 ++++
include/linux/unwind_deferred_types.h | 12 ++
kernel/unwind/deferred.c | 159 +++++++++++++++++++++++++-
3 files changed, 194 insertions(+), 1 deletion(-)
@@ -2,16 +2,66 @@/**Deferreduserspaceunwinding*/+#include<linux/sched/task_stack.h>+#include<linux/unwind_deferred.h>+#include<linux/sched/clock.h>+#include<linux/task_work.h>#include<linux/kernel.h>#include<linux/sched.h>#include<linux/sizes.h>#include<linux/slab.h>-#include<linux/unwind_deferred.h>+#include<linux/mm.h>/* Make the cache fit in a 4K page */#define UNWIND_MAX_ENTRIES \((SZ_4K-sizeof(structunwind_cache))/sizeof(long))+/* Guards adding to and reading the list of callbacks */+staticDEFINE_MUTEX(callback_mutex);+staticLIST_HEAD(callbacks);++/*+*Thisisauniquepercpuidentifierforagiventaskentrycontext.+*Conceptually,it'sincrementedeverytimetheCPUentersthekernelfrom+*userspace,sothateach"entry context"ontheCPUgetsauniqueID.In+*reality,asanoptimization,it'sonlyincrementedondemandforthefirst+*deferredunwindrequestafteragivenentry-from-user.+*+*It'scombinedwiththeCPUidtomakeasystemwide-unique"context cookie".+*/+staticDEFINE_PER_CPU(u32,unwind_ctx_ctr);++/*+*Thecontextcookieisauniqueidentifierthatisassignedtoauser+*spacestacktrace.Astheuserspacestacktraceremainsthesamewhile+*thetaskisinthekernel,thecookieisanidentifierforthestacktrace.+*Althoughitispossibleforthestacktracetogetanothercookieifanother+*requestismadeafterthecookiewasclearedandbeforereenteringuser+*space.+*/+staticu64get_cookie(structunwind_task_info*info)+{+u32cpu_cnt;+u32cnt;+u32old=0;++if(info->id.cpu)+returninfo->id.id;++cpu_cnt=__this_cpu_read(unwind_ctx_ctr);+cpu_cnt+=2;+cnt=cpu_cnt|1;/* Always make non zero */++if(try_cmpxchg(&info->id.cnt,&old,cnt)){+/* Update the per cpu counter */+__this_cpu_write(unwind_ctx_ctr,cpu_cnt);+}+/* Interrupts are disabled, the CPU will always be same */+info->id.cpu=smp_processor_id()+1;/* Must be non zero */++returninfo->id.id;+}+/***unwind_user_faultable-Produceauserstacktraceinfaultablecontext*@trace:Thedescriptorthatwillstoretheuserstacktrace
@@ -62,11 +112,117 @@ int unwind_user_faultable(struct unwind_stacktrace *trace)return0;}+staticvoidunwind_deferred_task_work(structcallback_head*head)+{+structunwind_task_info*info=container_of(head,structunwind_task_info,work);+structunwind_stacktracetrace;+structunwind_work*work;+u64cookie;++if(WARN_ON_ONCE(!info->pending))+return;++/* Allow work to come in again */+WRITE_ONCE(info->pending,0);++/*+*Fromhereonout,thecallbackmustalwaysbecalled,evenifit's+*justanemptytrace.+*/+trace.nr=0;+trace.entries=NULL;++unwind_user_faultable(&trace);++cookie=info->id.id;++guard(mutex)(&callback_mutex);+list_for_each_entry(work,&callbacks,list){+work->func(work,&trace,cookie);+}+}++/**+*unwind_deferred_request-Requestauserstacktraceontaskexit+*@work:Unwinddescriptorrequestingthetrace+*@cookie:Thecookieofthefirstrequestmadeforthistask+*+*Scheduleauserspaceunwindtobedoneintaskworkbeforeexitingthe+*kernel.+*+*Thereturned@cookieoutputisthegeneratedcookieoftheveryfirst+*requestforauserspacestacktraceforthistasksinceitenteredthe+*kernel.Itcanbefromarequestbyanycallerofthisinfrastructure.+*Itsvaluewillalsobepassedtothecallbackfunction.Itcanbe+*usedtostitchkernelanduserstacktracestogetherinpost-processing.+*+*It'svalidtocallthisfunctionmultipletimesforthesame@workwithin+*thesametaskentrycontext.Eachcallwillreturnthesamecookie+*whilethetaskhasn'tleftthekernel.Ifthecallbackisnotpending+*becauseithasalreadybeenpreviouslycalledforthesameentrycontext,+*itwillbecalledagainwiththesamestacktraceandcookie.+*+*Return:1ifthethecallbackwasalreadyqueued.+*0ifthecallbacksuccessfullywasqueued.+*Negativeifthere'sanerror.+*@cookieholdsthecookieofthefirstrequestbyanyuser+*/+intunwind_deferred_request(structunwind_work*work,u64*cookie)+{+structunwind_task_info*info=¤t->unwind_info;+intret;++*cookie=0;++if(WARN_ON_ONCE(in_nmi()))+return-EINVAL;++if((current->flags&(PF_KTHREAD|PF_EXITING))||+!user_mode(task_pt_regs(current)))+return-EINVAL;++guard(irqsave)();++*cookie=get_cookie(info);++/* callback already pending? */+if(info->pending)+return1;++/* The work has been claimed, now schedule it. */+ret=task_work_add(current,&info->work,TWA_RESUME);+if(WARN_ON_ONCE(ret))+returnret;++info->pending=1;+return0;+}++voidunwind_deferred_cancel(structunwind_work*work)+{+if(!work)+return;++guard(mutex)(&callback_mutex);+list_del(&work->list);+}++intunwind_deferred_init(structunwind_work*work,unwind_callback_tfunc)+{+memset(work,0,sizeof(*work));++guard(mutex)(&callback_mutex);+list_add(&work->list,&callbacks);+work->func=func;+return0;+}+voidunwind_task_init(structtask_struct*task){structunwind_task_info*info=&task->unwind_info;memset(info,0,sizeof(*info));+init_task_work(&info->work,unwind_deferred_task_work);}voidunwind_task_free(structtask_struct*task)
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Steven Rostedt <rostedt@goodmis.org>
On the way back to user space, the function unwind_reset_info() is called
unconditionally (but always inlined). It currently has two conditionals.
One that checks the unwind_mask which is set whenever a deferred trace is
called and is used to know that the mask needs to be cleared. The other
checks if the cache has been allocated, and if so, it resets the
nr_entries so that the unwinder knows it needs to do the work to get a new
user space stack trace again (it only does it once per entering the
kernel).
Use one of the bits in the unwind mask as a "USED" bit that gets set
whenever a trace is created. This will make it possible to only check the
unwind_mask in the unwind_reset_info() to know if it needs to do work or
not and eliminates a conditional that happens every time the task goes
back to user space.
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
include/linux/unwind_deferred.h | 14 +++++++-------
kernel/unwind/deferred.c | 5 ++++-
2 files changed, 11 insertions(+), 8 deletions(-)
@@ -21,6 +21,10 @@ struct unwind_work {#define UNWIND_PENDING_BIT (BITS_PER_LONG - 1)#define UNWIND_PENDING BIT(UNWIND_PENDING_BIT)+/* Set if the unwinding was used (directly or deferred) */+#define UNWIND_USED_BIT (UNWIND_PENDING_BIT - 1)+#define UNWIND_USED BIT(UNWIND_USED_BIT)+enum{UNWIND_ALREADY_PENDING=1,UNWIND_ALREADY_EXECUTED=2,
@@ -140,6 +140,9 @@ int unwind_user_faultable(struct unwind_stacktrace *trace)cache->nr_entries=trace->nr;+/* Clear nr_entries on way back to user space */+set_bit(UNWIND_USED_BIT,&info->unwind_mask);+return0;}
@@ -314,7 +317,7 @@ int unwind_deferred_init(struct unwind_work *work, unwind_callback_t func)guard(mutex)(&callback_mutex);/* See if there's a bit in the mask available */-if(unwind_mask==~(UNWIND_PENDING))+if(unwind_mask==~(UNWIND_PENDING|UNWIND_USED))return-EBUSY;work->bit=ffz(unwind_mask);
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Steven Rostedt <rostedt@goodmis.org>
On do_exit() when a task is exiting, if a unwind is requested and the
deferred user stacktrace is deferred via the task_work, the task_work
callback is called after exit_mm() is called in do_exit(). This means that
the user stack trace will not be retrieved and an empty stack is created.
Instead, add a function unwind_deferred_task_exit() and call it just
before exit_mm() so that the unwinder can call the requested callbacks
with the user space stack.
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
include/linux/unwind_deferred.h | 3 +++
kernel/exit.c | 2 ++
kernel/unwind/deferred.c | 23 ++++++++++++++++++++---
3 files changed, 25 insertions(+), 3 deletions(-)
@@ -113,7 +113,7 @@ int unwind_user_faultable(struct unwind_stacktrace *trace)/* Should always be called from faultable context */might_fault();-if(current->flags&PF_EXITING)+if(!current->mm)return-EINVAL;if(!info->cache){
@@ -146,9 +146,9 @@ int unwind_user_faultable(struct unwind_stacktrace *trace)return0;}-staticvoidunwind_deferred_task_work(structcallback_head*head)+staticvoidprocess_unwind_deferred(structtask_struct*task){-structunwind_task_info*info=container_of(head,structunwind_task_info,work);+structunwind_task_info*info=&task->unwind_info;structunwind_stacktracetrace;structunwind_work*work;unsignedlongbits;
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Steven Rostedt <rostedt@goodmis.org>
Instead of using the callback_mutex to protect the link list of callbacks
in unwind_deferred_task_work(), use SRCU instead. This gets called every
time a task exits that has to record a stack trace that was requested.
This can happen for many tasks on several CPUs at the same time. A mutex
is a bottleneck and can cause a bit of contention and slow down performance.
As the callbacks themselves are allowed to sleep, regular RCU cannot be
used to protect the list. Instead use SRCU, as that still allows the
callbacks to sleep and the list can be read without needing to hold the
callback_mutex.
Link: https://lore.kernel.org/all/ca9bd83a-6c80-4ee0-a83c-224b9d60b755@efficios.com/
Suggested-by: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
kernel/unwind/deferred.c | 35 ++++++++++++++++++++++++++---------
1 file changed, 26 insertions(+), 9 deletions(-)
@@ -41,10 +41,11 @@ static inline bool try_assign_cnt(struct unwind_task_info *info, u32 cnt)#define UNWIND_MAX_ENTRIES \((SZ_4K-sizeof(structunwind_cache))/sizeof(long))-/* Guards adding to and reading the list of callbacks */+/* Guards adding to or removing from the list of callbacks */staticDEFINE_MUTEX(callback_mutex);staticLIST_HEAD(callbacks);staticunsignedlongunwind_mask;+DEFINE_STATIC_SRCU(unwind_srcu);/**Thisisauniquepercpuidentifierforagiventaskentrycontext.
@@ -199,6 +203,7 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie){structunwind_task_info*info=¤t->unwind_info;longpending;+intbit;intret;*cookie=0;
@@ -211,12 +216,17 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie)if(!CAN_USE_IN_NMI&&in_nmi())return-EINVAL;+/* Do not allow cancelled works to request again */+bit=READ_ONCE(work->bit);+if(WARN_ON_ONCE(bit<0))+return-EINVAL;+guard(irqsave)();*cookie=get_cookie(info);/* This is already queued */-if(test_bit(work->bit,&info->unwind_mask))+if(test_bit(bit,&info->unwind_mask))return1;/* callback already pending? */
@@ -240,25 +250,32 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie)}out:-returntest_and_set_bit(work->bit,&info->unwind_mask);+returntest_and_set_bit(bit,&info->unwind_mask);}voidunwind_deferred_cancel(structunwind_work*work){structtask_struct*g,*t;+intbit;if(!work)return;guard(mutex)(&callback_mutex);-list_del(&work->list);+list_del_rcu(&work->list);+bit=work->bit;++/* Do not allow any more requests and prevent callbacks */+work->bit=-1;++__clear_bit(bit,&unwind_mask);-__clear_bit(work->bit,&unwind_mask);+synchronize_srcu(&unwind_srcu);guard(rcu)();/* Clear this bit from all threads */for_each_process_thread(g,t){-clear_bit(work->bit,&t->unwind_info.unwind_mask);+clear_bit(bit,&t->unwind_info.unwind_mask);}}
@@ -275,7 +292,7 @@ int unwind_deferred_init(struct unwind_work *work, unwind_callback_t func)work->bit=ffz(unwind_mask);__set_bit(work->bit,&unwind_mask);-list_add(&work->list,&callbacks);+list_add_rcu(&work->list,&callbacks);work->func=func;return0;}
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Steven Rostedt <rostedt@goodmis.org>
In order to know which registered callback requested a stacktrace for when
the task goes back to user space, add a bitmask to keep track of all
registered tracers. The bitmask is the size of long, which means that on a
32 bit machine, it can have at most 32 registered tracers, and on 64 bit,
it can have at most 64 registered tracers. This should not be an issue as
there should not be more than 10 (unless BPF can abuse this?).
When a tracer registers with unwind_deferred_init() it will get a bit
number assigned to it. When a tracer requests a stacktrace, it will have
its bit set within the task_struct. When the task returns back to user
space, it will call the callbacks for all the registered tracers where
their bits are set in the task's mask.
When a tracer is removed by the unwind_deferred_cancel() all current tasks
will clear the associated bit, just in case another tracer gets registered
immediately afterward and then gets their callback called unexpectedly.
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
include/linux/unwind_deferred.h | 1 +
include/linux/unwind_deferred_types.h | 1 +
kernel/unwind/deferred.c | 36 ++++++++++++++++++++++++---
3 files changed, 34 insertions(+), 4 deletions(-)
@@ -44,6 +44,7 @@ static inline bool try_assign_cnt(struct unwind_task_info *info, u32 cnt)/* Guards adding to and reading the list of callbacks */staticDEFINE_MUTEX(callback_mutex);staticLIST_HEAD(callbacks);+staticunsignedlongunwind_mask;/**Thisisauniquepercpuidentifierforagiventaskentrycontext.
@@ -211,15 +215,19 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie)*cookie=get_cookie(info);+/* This is already queued */+if(test_bit(work->bit,&info->unwind_mask))+return1;+/* callback already pending? */pending=local_read(&info->pending);if(pending)-return1;+gotoout;if(CAN_USE_IN_NMI){/* Claim the work unless an NMI just now swooped in to do so. */if(!local_try_cmpxchg(&info->pending,&pending,1))-return1;+gotoout;}else{local_set(&info->pending,1);}
@@ -231,16 +239,27 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie)returnret;}-return0;+out:+returntest_and_set_bit(work->bit,&info->unwind_mask);}voidunwind_deferred_cancel(structunwind_work*work){+structtask_struct*g,*t;+if(!work)return;guard(mutex)(&callback_mutex);list_del(&work->list);++__clear_bit(work->bit,&unwind_mask);++guard(rcu)();+/* Clear this bit from all threads */+for_each_process_thread(g,t){+clear_bit(work->bit,&t->unwind_info.unwind_mask);+}}intunwind_deferred_init(structunwind_work*work,unwind_callback_tfunc)
@@ -248,6 +267,14 @@ int unwind_deferred_init(struct unwind_work *work, unwind_callback_t func)memset(work,0,sizeof(*work));guard(mutex)(&callback_mutex);++/* See if there's a bit in the mask available */+if(unwind_mask==~0UL)+return-EBUSY;++work->bit=ffz(unwind_mask);+__set_bit(work->bit,&unwind_mask);+list_add(&work->list,&callbacks);work->func=func;return0;
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Josh Poimboeuf <jpoimboe@kernel.org>
Use ARCH_INIT_USER_FP_FRAME to describe how frame pointers are unwound
on x86, and enable CONFIG_HAVE_UNWIND_USER_FP accordingly so the
unwind_user interfaces can be used.
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
arch/x86/Kconfig | 1 +
arch/x86/include/asm/unwind_user.h | 11 +++++++++++
2 files changed, 12 insertions(+)
create mode 100644 arch/x86/include/asm/unwind_user.h
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:23:59
From: Steven Rostedt <rostedt@goodmis.org>
When testing the deferred unwinder by attaching deferred user space
stacktraces to events, a live lock happened. This was when the deferred
unwinding was added to the irqs_disabled event, which happens after the
task_work callbacks are called and before the task goes back to user
space.
The event callback would be registered when irqs were disabled, the
task_work would trigger, call the callback for this work and clear the
work's bit. Then before getting back to user space, irqs would be disabled
again, the event triggered again, and a new task_work registered. This
caused an infinite loop and the system hung.
To prevent this, clear the bits at the very last moment before going back
to user space and when instrumentation is disabled. That is in
unwind_exit_to_user_mode().
Move the pending bit from a value on the task_struct to the most
significant bit of the unwind_mask (saves space on the task_struct). This
will allow modifying the pending bit along with the work bits atomically.
Instead of clearing a work's bit after its callback is called, it is
delayed until exit. If the work is requested again, the task_work is not
queued again and the work will be notified that the task has already been
called (via UNWIND_ALREADY_EXECUTED return value).
The pending bit is cleared before calling the callback functions but the
current work bits remain. If one of the called works registers again, it
will not trigger a task_work if its bit is still present in the task's
unwind_mask.
If a new work registers, then it will set both the pending bit and its own
bit but clear the other work bits so that their callbacks do not get
called again.
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
Changes since v12: https://lore.kernel.org/20250701005452.242933931@goodmis.org
- Removed no longer used local.h headers from unwind_deferred_types.h
include/linux/unwind_deferred.h | 25 +++++++--
include/linux/unwind_deferred_types.h | 3 --
kernel/unwind/deferred.c | 76 ++++++++++++++++++---------
3 files changed, 74 insertions(+), 30 deletions(-)
@@ -29,15 +37,26 @@ void unwind_deferred_cancel(struct unwind_work *work);static__always_inlinevoidunwind_reset_info(void){-if(unlikely(current->unwind_info.id.id))+structunwind_task_info*info=¤t->unwind_info;+unsignedlongbits;++/* Was there any unwinding? */+if(unlikely(info->unwind_mask)){+bits=info->unwind_mask;+do{+/* Is a task_work going to run again before going back */+if(bits&UNWIND_PENDING)+return;+}while(!try_cmpxchg(&info->unwind_mask,&bits,0UL));current->unwind_info.id.id=0;+}/**Asunwind_user_faultable()canbecalleddirectlyand*dependsonnr_entriesbeingclearedonexittouser,*thisneedstobeaseparateconditional.*/-if(unlikely(current->unwind_info.cache))-current->unwind_info.cache->nr_entries=0;+if(unlikely(info->cache))+info->cache->nr_entries=0;}#else /* !CONFIG_UNWIND_USER */
@@ -143,14 +148,17 @@ static void unwind_deferred_task_work(struct callback_head *head)structunwind_task_info*info=container_of(head,structunwind_task_info,work);structunwind_stacktracetrace;structunwind_work*work;+unsignedlongbits;u64cookie;intidx;-if(WARN_ON_ONCE(!local_read(&info->pending)))+if(WARN_ON_ONCE(!unwind_pending(info)))return;-/* Allow work to come in again */-local_set(&info->pending,0);+/* Clear pending bit but make sure to have the current bits */+bits=READ_ONCE(info->unwind_mask);+while(!try_cmpxchg(&info->unwind_mask,&bits,bits&~UNWIND_PENDING))+;/**Fromhereonout,thecallbackmustalwaysbecalled,evenifit's
@@ -225,32 +233,52 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie)*cookie=get_cookie(info);-/* This is already queued */-if(test_bit(bit,&info->unwind_mask))-return1;+old=READ_ONCE(info->unwind_mask);++/* Is this already queued */+if(test_bit(bit,&old)){+/*+*Ifpendingisnotset,itmeansthiswork'scallback+*wasalreadycalled.+*/+returnold&UNWIND_PENDING?UNWIND_ALREADY_PENDING:+UNWIND_ALREADY_EXECUTED;+}-/* callback already pending? */-pending=local_read(&info->pending);-if(pending)+if(unwind_pending(info))gotoout;+/*+*Thisisthefirsttoenableanothertask_workforthistasksince+*thetaskenteredthekernel,orhadalreadycalledthecallbacks.+*Setonlythebitforthisworkandclearallothersastheyhave+*alreadyhadtheircallbackscalled,anddonotneedtocallthem+*againbecauseofthiswork.+*/+bits=UNWIND_PENDING|BIT(bit);++/*+*Ifthecmpxchg()fails,itmeansthatanNMIcameinandset+*thependingbitaswellasclearedtheotherbits.Just+*jumptosettingthebitforthiswork.+*/if(CAN_USE_IN_NMI){-/* Claim the work unless an NMI just now swooped in to do so. */-if(!local_try_cmpxchg(&info->pending,&pending,1))+if(!try_cmpxchg(&info->unwind_mask,&old,bits))gotoout;}else{-local_set(&info->pending,1);+info->unwind_mask=bits;}/* The work has been claimed, now schedule it. */ret=task_work_add(current,&info->work,TWA_RESUME);-if(WARN_ON_ONCE(ret)){-local_set(&info->pending,0);-returnret;-}+if(WARN_ON_ONCE(ret))+WRITE_ONCE(info->unwind_mask,0);++returnret;out:-returntest_and_set_bit(bit,&info->unwind_mask);+returntest_and_set_bit(bit,&info->unwind_mask)?+UNWIND_ALREADY_PENDING:0;}voidunwind_deferred_cancel(structunwind_work*work)
@@ -286,7 +314,7 @@ int unwind_deferred_init(struct unwind_work *work, unwind_callback_t func)guard(mutex)(&callback_mutex);/* See if there's a bit in the mask available */-if(unwind_mask==~0UL)+if(unwind_mask==~(UNWIND_PENDING))return-EBUSY;work->bit=ffz(unwind_mask);
From: Steven Rostedt <rostedt@kernel.org> Date: 2025-07-08 01:24:00
From: Josh Poimboeuf <jpoimboe@kernel.org>
Use ARCH_INIT_USER_COMPAT_FP_FRAME to describe how frame pointers are
unwound on x86, and implement the hooks needed to add the segment base
addresses. Enable HAVE_UNWIND_USER_COMPAT_FP if the system has compat
mode compiled in.
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
---
arch/x86/Kconfig | 1 +
arch/x86/include/asm/unwind_user.h | 31 ++++++++++++++++++++++++
arch/x86/include/asm/unwind_user_types.h | 17 +++++++++++++
arch/x86/kernel/stacktrace.c | 28 +++++++++++++++++++++
include/linux/unwind_user.h | 20 +++++++++++++++
kernel/unwind/user.c | 4 +++
6 files changed, 101 insertions(+)
create mode 100644 arch/x86/include/asm/unwind_user_types.h
From: Josh Poimboeuf <jpoimboe@kernel.org>
Add optional support for user space frame pointer unwinding. If
supported, the arch needs to enable CONFIG_HAVE_UNWIND_USER_FP and
define ARCH_INIT_USER_FP_FRAME.
By encoding the frame offsets in struct unwind_user_frame, much of this
code can also be reused for future unwinder implementations like sframe.
Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org>
Co-developed-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
@@ -6,13 +6,71 @@ #include <linux/sched.h> #include <linux/sched/task_stack.h> #include <linux/unwind_user.h>+#include <linux/uaccess.h>++static struct unwind_user_frame fp_frame = {+ ARCH_INIT_USER_FP_FRAME+};++static inline bool fp_state(struct unwind_user_state *state)+{+ return IS_ENABLED(CONFIG_HAVE_UNWIND_USER_FP) &&+ state->type == UNWIND_USER_TYPE_FP;+} #define for_each_user_frame(state) \ for (unwind_user_start(state); !(state)->done; unwind_user_next(state)) static int unwind_user_next(struct unwind_user_state *state) {- /* no implementation yet */+ struct unwind_user_frame *frame;+ unsigned long cfa = 0, fp, ra = 0;+ unsigned int shift;++ if (state->done)+ return -EINVAL;++ if (fp_state(state))+ frame = &fp_frame;+ else+ goto done;++ if (frame->use_fp) {+ if (state->fp < state->sp)
if (state->fp <= state->sp)
I meanwhile came to the conclusion that for architectures, such as s390,
where SP at function entry == SP at call site, the FP may be equal to
the SP. At least for the brief period where the FP has been setup and
stack allocation did not yet take place. For most architectures this
can probably only occur in the topmost frame. For s390 the FP is setup
after static stack allocation, so --fno-omit-frame-pointer would enforce
FP==SP in any frame that does not perform dynamic stack allocation.
+ goto done;
+ cfa = state->fp;
+ } else {
+ cfa = state->sp;
+ }
+
+ /* Get the Canonical Frame Address (CFA) */
+ cfa += frame->cfa_off;
+
+ /* stack going in wrong direction? */
+ if (cfa <= state->sp)
+ goto done;
+
+ /* Make sure that the address is word aligned */
+ shift = sizeof(long) == 4 ? 2 : 3;
+ if ((cfa + frame->ra_off) & ((1 << shift) - 1))
+ goto done;
Do all architectures/ABI mandate register stack save slots to be aligned?
s390 does.
+
+ /* Find the Return Address (RA) */
+ if (get_user(ra, (unsigned long *)(cfa + frame->ra_off)))
+ goto done;
+
Why not validate the FP stack save slot address as well?
Thanks and regards,
Jens
--
Jens Remus
Linux on Z Development (D3303)
+49-7031-16-1128 Office
jremus@de.ibm.com
IBM
IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Böblingen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/
static int unwind_user_next(struct unwind_user_state *state)
{
- /* no implementation yet */
+ struct unwind_user_frame *frame;
+ unsigned long cfa = 0, fp, ra = 0;
+ unsigned int shift;
+
+ if (state->done)
+ return -EINVAL;
+
+ if (fp_state(state))
+ frame = &fp_frame;
+ else
+ goto done;
+
+ if (frame->use_fp) {
+ if (state->fp < state->sp)
The initial check above is correct. I got the logic wrong. Sorry for
the fuss! Do not change the check to what I came up with yesterday:
if (state->fp <= state->sp)
Below s390 particularity, that FP may be equal to FP in any frame,
is only allowed with the initial check.
I meanwhile came to the conclusion that for architectures, such as s390,
where SP at function entry == SP at call site, the FP may be equal to
the SP. At least for the brief period where the FP has been setup and
stack allocation did not yet take place. For most architectures this
can probably only occur in the topmost frame. For s390 the FP is setup
after static stack allocation, so --fno-omit-frame-pointer would enforce
FP==SP in any frame that does not perform dynamic stack allocation.
quoted
+ goto done;
+ cfa = state->fp;
+ } else {
+ cfa = state->sp;
+ }
Regards,
Jens
--
Jens Remus
Linux on Z Development (D3303)
+49-7031-16-1128 Office
jremus@de.ibm.com
IBM
IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Böblingen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/
static int unwind_user_next(struct unwind_user_state *state)
{
- /* no implementation yet */
+ struct unwind_user_frame *frame;
+ unsigned long cfa = 0, fp, ra = 0;
+ unsigned int shift;
+
+ if (state->done)
+ return -EINVAL;
+
+ if (fp_state(state))
+ frame = &fp_frame;
+ else
+ goto done;
+
+ if (frame->use_fp) {
+ if (state->fp < state->sp)
if (state->fp <= state->sp)
I meanwhile came to the conclusion that for architectures, such as s390,
where SP at function entry == SP at call site, the FP may be equal to
the SP. At least for the brief period where the FP has been setup and
stack allocation did not yet take place. For most architectures this
can probably only occur in the topmost frame. For s390 the FP is setup
after static stack allocation, so --fno-omit-frame-pointer would enforce
FP==SP in any frame that does not perform dynamic stack allocation.
From your latest email, I take it I can ignore the above?
quoted
+ goto done;
+ cfa = state->fp;
+ } else {
+ cfa = state->sp;
+ }
+
+ /* Get the Canonical Frame Address (CFA) */
+ cfa += frame->cfa_off;
+
+ /* stack going in wrong direction? */
+ if (cfa <= state->sp)
+ goto done;
+
+ /* Make sure that the address is word aligned */
+ shift = sizeof(long) == 4 ? 2 : 3;
+ if ((cfa + frame->ra_off) & ((1 << shift) - 1))
+ goto done;
Do all architectures/ABI mandate register stack save slots to be aligned?
s390 does.
I believe so.
quoted
+
+ /* Find the Return Address (RA) */
+ if (get_user(ra, (unsigned long *)(cfa + frame->ra_off)))
+ goto done;
+
Why not validate the FP stack save slot address as well?
You mean to validate cfa + frame->fp_off?
Isn't cfa the only real variable here? That is, if cfa + frame->ra_off
works, wouldn't the same go for frame->fp_off, as both frame->ra_off
and frame->fp_off are constants set by the architecture, and should be
word aligned.
-- Steve
quoted
+ if (frame->fp_off && get_user(fp, (unsigned long __user *)(cfa + frame->fp_off)))
+ goto done;
+
+ if (frame->use_fp) {
+ if (state->fp < state->sp)
if (state->fp <= state->sp)
I meanwhile came to the conclusion that for architectures, such as s390,
where SP at function entry == SP at call site, the FP may be equal to
the SP. At least for the brief period where the FP has been setup and
stack allocation did not yet take place. For most architectures this
can probably only occur in the topmost frame. For s390 the FP is setup
after static stack allocation, so --fno-omit-frame-pointer would enforce
FP==SP in any frame that does not perform dynamic stack allocation.
From your latest email, I take it I can ignore the above?
Correct.
quoted
quoted
+ /* Make sure that the address is word aligned */
+ shift = sizeof(long) == 4 ? 2 : 3;
+ if ((cfa + frame->ra_off) & ((1 << shift) - 1))
+ goto done;
Do all architectures/ABI mandate register stack save slots to be aligned?
s390 does.
I believe so.
quoted
quoted
+
+ /* Find the Return Address (RA) */
+ if (get_user(ra, (unsigned long *)(cfa + frame->ra_off)))
+ goto done;
+
Why not validate the FP stack save slot address as well?
You mean to validate cfa + frame->fp_off?
Yes.
Isn't cfa the only real variable here? That is, if cfa + frame->ra_off
works, wouldn't the same go for frame->fp_off, as both frame->ra_off
and frame->fp_off are constants set by the architecture, and should be
word aligned.
cfa + frame->ra_off could be aligned by chance. So could
cfa + frame->fp_off be as well of course.
On s390 the CFA must be aligned (as the SP must be aligned) and the
FP and RA offsets from CFA must be aligned, as pointer / 64-bit integers
(such as 64-bit register values) must be aligned as well.
So the CFA (and/or offset), FP offset, and RA offset could be validated
individually. Not sure if that would be over engineering though.
quoted
quoted
+ if (frame->fp_off && get_user(fp, (unsigned long __user *)(cfa + frame->fp_off)))
+ goto done;
Regards,
Jens
--
Jens Remus
Linux on Z Development (D3303)
+49-7031-16-1128 Office
jremus@de.ibm.com
IBM
IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Böblingen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/
cfa + frame->ra_off could be aligned by chance. So could
cfa + frame->fp_off be as well of course.
On s390 the CFA must be aligned (as the SP must be aligned) and the
FP and RA offsets from CFA must be aligned, as pointer / 64-bit integers
(such as 64-bit register values) must be aligned as well.
So the CFA (and/or offset), FP offset, and RA offset could be validated
individually. Not sure if that would be over engineering though.
I wonder if we should just validate that cfa is aligned? Would that work?
I would think that ra_off and fp_off should be aligned as well and if
cfa is aligned then it would still be aligned when adding those offsets.
-- Steve
From: David Laight <hidden> Date: 2025-07-11 08:43:25
On Mon, 07 Jul 2025 21:22:52 -0400
Steven Rostedt [off-list ref] wrote:
From: Josh Poimboeuf <jpoimboe@kernel.org>
Use ARCH_INIT_USER_FP_FRAME to describe how frame pointers are unwound
on x86, and enable CONFIG_HAVE_UNWIND_USER_FP accordingly so the
unwind_user interfaces can be used.
How is that going to work?
Pretty much all x86 userspace is compiled with bp as a general
purpose register not a frame pointer.
David
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-11 16:11:47
On Fri, 11 Jul 2025 09:43:21 +0100
David Laight [off-list ref] wrote:
On Mon, 07 Jul 2025 21:22:52 -0400
Steven Rostedt [off-list ref] wrote:
quoted
From: Josh Poimboeuf <jpoimboe@kernel.org>
Use ARCH_INIT_USER_FP_FRAME to describe how frame pointers are unwound
on x86, and enable CONFIG_HAVE_UNWIND_USER_FP accordingly so the
unwind_user interfaces can be used.
How is that going to work?
Pretty much all x86 userspace is compiled with bp as a general
purpose register not a frame pointer.
cfa + frame->ra_off could be aligned by chance. So could
cfa + frame->fp_off be as well of course.
On s390 the CFA must be aligned (as the SP must be aligned) and the
FP and RA offsets from CFA must be aligned, as pointer / 64-bit integers
(such as 64-bit register values) must be aligned as well.
So the CFA (and/or offset), FP offset, and RA offset could be validated
individually. Not sure if that would be over engineering though.
I wonder if we should just validate that cfa is aligned? Would that work?
I would think that ra_off and fp_off should be aligned as well and if
cfa is aligned then it would still be aligned when adding those offsets.
Makes sense, if the base assumption is that the SFrame information is
valid and the primary intend is to check that the used CFA base register
(i.e. SP or FP) was aligned.
Regards,
Jens
--
Jens Remus
Linux on Z Development (D3303)
+49-7031-16-1128 Office
jremus@de.ibm.com
IBM
IBM Deutschland Research & Development GmbH; Vorsitzender des Aufsichtsrats: Wolfgang Wendt; Geschäftsführung: David Faller; Sitz der Gesellschaft: Böblingen; Registergericht: Amtsgericht Stuttgart, HRB 243294
IBM Data Privacy Statement: https://www.ibm.com/privacy/
From: Peter Zijlstra <peterz@infradead.org> Date: 2025-07-14 13:29:57
On Mon, Jul 07, 2025 at 09:22:46PM -0400, Steven Rostedt wrote:
From: Steven Rostedt <rostedt@goodmis.org>
Make unwind_deferred_request() NMI-safe so tracers in NMI context can
call it and safely request a user space stacktrace when the task exits.
Note, this is only allowed for architectures that implement a safe
cmpxchg. If an architecture requests a deferred stack trace from NMI
context that does not support a safe NMI cmpxchg, it will get an -EINVAL.
For those architectures, they would need another method (perhaps an
irqwork), to request a deferred user space stack trace. That can be dealt
with later if one of theses architectures require this feature.
Suggested-by: Peter Zijlstra <peterz@infradead.org>
@@ -12,6 +12,40 @@#include<linux/slab.h>#include<linux/mm.h>+/*+*ForrequestingadeferreduserspacestacktracefromNMIcontext+*thearchitecturemustsupportasafecmpxchginNMIcontext.+*Forthosearchitecturesthatdonothavethat,thenitcannotask+*foradeferreduserspacestacktracefromanNMIcontext.Ifit+*does,thenitwillget-EINVAL.+*/+#ifdef CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG+#define UNWIND_NMI_SAFE 1+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+u32zero=0;+returntry_cmpxchg(&info->id.cnt,&zero,cnt);+}+staticinlinebooltest_and_set_pending(structunwind_task_info*info)+{+returninfo->pending||cmpxchg_local(&info->pending,0,1);+}+#else+#define UNWIND_NMI_SAFE 0+/* When NMIs are not allowed, this always succeeds */+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+info->id.cnt=cnt;+returntrue;+}+staticinlinebooltest_and_set_pending(structunwind_task_info*info)+{+intpending=info->pending;+info->pending=1;+returnpending;+}+#endif /* CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG */+/* Make the cache fit in a 4K page */#define UNWIND_MAX_ENTRIES \((SZ_4K-sizeof(structunwind_cache))/sizeof(long))
@@ -41,21 +75,16 @@ static DEFINE_PER_CPU(u32, unwind_ctx_ct*/staticu64get_cookie(structunwind_task_info*info){-u32cpu_cnt;-u32cnt;-u32old=0;+u32cnt=1;if(info->id.cpu)returninfo->id.id;-cpu_cnt=__this_cpu_read(unwind_ctx_ctr);-cpu_cnt+=2;-cnt=cpu_cnt|1;/* Always make non zero */--if(try_cmpxchg(&info->id.cnt,&old,cnt)){-/* Update the per cpu counter */-__this_cpu_write(unwind_ctx_ctr,cpu_cnt);-}+/* LSB it always set to ensure 0 is an invalid value. */+cnt|=__this_cpu_read(unwind_ctx_ctr)+2;+if(try_assign_cnt(info,cnt))+__this_cpu_write(unwind_ctx_ctr,cnt);+/* Interrupts are disabled, the CPU will always be same */info->id.cpu=smp_processor_id()+1;/* Must be non zero */
@@ -174,27 +203,29 @@ int unwind_deferred_request(struct unwin*cookie=0;-if(WARN_ON_ONCE(in_nmi()))-return-EINVAL;-if((current->flags&(PF_KTHREAD|PF_EXITING))||!user_mode(task_pt_regs(current)))return-EINVAL;+/* NMI requires having safe cmpxchg operations */+if(WARN_ON_ONCE(!UNWIND_NMI_SAFE&&in_nmi()))+return-EINVAL;+guard(irqsave)();*cookie=get_cookie(info);/* callback already pending? */-if(info->pending)+if(test_and_set_pending(info))return1;/* The work has been claimed, now schedule it. */ret=task_work_add(current,&info->work,TWA_RESUME);-if(WARN_ON_ONCE(ret))+if(WARN_ON_ONCE(ret)){+WRITE_ONCE(info->pending,0);returnret;+}-info->pending=1;return0;}
Patch 10 moves the pending bit into the unwind_mask as it needs to be
in sync with the different tracer requests. I'm not sure how this
change will interact with that.
-- Steve
I think I rather have a scoped_guard() here. One thing that bothers me
about the guard() logic is that it could easily start to "leak"
protection. That is, the unwind_srcu is only needed for walking the
list. The reason I chose to open code the protection, is because I
wanted to distinctly denote where the end of the protection was.
-- Steve
I think I rather have a scoped_guard() here. One thing that bothers me
about the guard() logic is that it could easily start to "leak"
protection. That is, the unwind_srcu is only needed for walking the
list. The reason I chose to open code the protection, is because I
wanted to distinctly denote where the end of the protection was.
Sure. But the point was more to:
- use scru_lite; and,
- use guards
Patch 10 moves the pending bit into the unwind_mask as it needs to be
in sync with the different tracer requests. I'm not sure how this
change will interact with that.
Urgh; so I hate reviewing code you're ripping out in the next patch :-(
Let me go stare at that.
From: Peter Zijlstra <peterz@infradead.org> Date: 2025-07-15 09:10:10
On Mon, Jul 14, 2025 at 11:11:58AM -0400, Steven Rostedt wrote:
On Mon, 14 Jul 2025 17:05:16 +0200
Peter Zijlstra [off-list ref] wrote:
quoted
Urgh; so I hate reviewing code you're ripping out in the next patch :-(
Sorry. It just happened to be developed that way. Patch 10 came about
to fix a bug that was triggered with the current method.
Sure; but then you rework the series such that the bug never happened
and reviewers don't go insane from the back and forth and possibly
stumbling over the same bug you then fix later.
You should know this.
I'm going to not stare at email for some 3 weeks soon; I strongly
suggest you take this time to fix up this series to not suffer nonsense
like this.
@@ -29,15 +37,26 @@ void unwind_deferred_cancel(struct unwind_work *work); static __always_inline void unwind_reset_info(void) {- if (unlikely(current->unwind_info.id.id))+ struct unwind_task_info *info = ¤t->unwind_info;+ unsigned long bits;++ /* Was there any unwinding? */+ if (unlikely(info->unwind_mask)) {+ bits = info->unwind_mask;+ do {+ /* Is a task_work going to run again before going back */+ if (bits & UNWIND_PENDING)+ return;+ } while (!try_cmpxchg(&info->unwind_mask, &bits, 0UL)); current->unwind_info.id.id = 0;+ } /* * As unwind_user_faultable() can be called directly and * depends on nr_entries being cleared on exit to user, * this needs to be a separate conditional. */- if (unlikely(current->unwind_info.cache))- current->unwind_info.cache->nr_entries = 0;+ if (unlikely(info->cache))+ info->cache->nr_entries = 0; } #else /* !CONFIG_UNWIND_USER */
@@ -143,14 +148,17 @@ static void unwind_deferred_task_work(struct callback_head *head)structunwind_task_info*info=container_of(head,structunwind_task_info,work);structunwind_stacktracetrace;structunwind_work*work;+unsignedlongbits;u64cookie;intidx;-if(WARN_ON_ONCE(!local_read(&info->pending)))+if(WARN_ON_ONCE(!unwind_pending(info)))return;-/* Allow work to come in again */-local_set(&info->pending,0);+/* Clear pending bit but make sure to have the current bits */+bits=READ_ONCE(info->unwind_mask);+while(!try_cmpxchg(&info->unwind_mask,&bits,bits&~UNWIND_PENDING))+;
We have:
bits = atomic_long_fetch_andnot(UNWIND_PENDING, &info->unwind_mask);
for that. A fair number of architecture can actually do this better than
a cmpxchg loop.
quoted hunk
/*
* From here on out, the callback must always be called, even if it's
@@ -194,15 +200,17 @@ static void unwind_deferred_task_work(struct callback_head *head) * because it has already been previously called for the same entry context, * it will be called again with the same stack trace and cookie. *- * Return: 1 if the the callback was already queued.- * 0 if the callback successfully was queued.+ * Return: 0 if the callback successfully was queued.+ * UNWIND_ALREADY_PENDING if the the callback was already queued.+ * UNWIND_ALREADY_EXECUTED if the callback was already called+ * (and will not be called again) * Negative if there's an error. * @cookie holds the cookie of the first request by any user */
Lots of babbling in the Changelog, but no real elucidation as to why you
need this second return value.
AFAICT it serves no real purpose; the users of this function should not
care. The only difference is that the unwind reference (your cookie)
becomes a backward reference instead of a forward reference. But why
would anybody care?
Whatever tool is ultimately in charge of gluing humpty^Wstacktraces back
together again should have no problem with this.
quoted hunk
int unwind_deferred_request(struct unwind_work *work, u64 *cookie)
{
struct unwind_task_info *info = ¤t->unwind_info;
- long pending;
+ unsigned long old, bits;
int bit;
int ret;
@@ -225,32 +233,52 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie) *cookie = get_cookie(info);- /* This is already queued */- if (test_bit(bit, &info->unwind_mask))- return 1;+ old = READ_ONCE(info->unwind_mask);++ /* Is this already queued */+ if (test_bit(bit, &old)) {+ /*+ * If pending is not set, it means this work's callback+ * was already called.+ */+ return old & UNWIND_PENDING ? UNWIND_ALREADY_PENDING :+ UNWIND_ALREADY_EXECUTED;+ }- /* callback already pending? */- pending = local_read(&info->pending);- if (pending)+ if (unwind_pending(info)) goto out;+ /*+ * This is the first to enable another task_work for this task since+ * the task entered the kernel, or had already called the callbacks.+ * Set only the bit for this work and clear all others as they have+ * already had their callbacks called, and do not need to call them+ * again because of this work.+ */+ bits = UNWIND_PENDING | BIT(bit);++ /*+ * If the cmpxchg() fails, it means that an NMI came in and set+ * the pending bit as well as cleared the other bits. Just+ * jump to setting the bit for this work.+ */ if (CAN_USE_IN_NMI) {- /* Claim the work unless an NMI just now swooped in to do so. */- if (!local_try_cmpxchg(&info->pending, &pending, 1))+ if (!try_cmpxchg(&info->unwind_mask, &old, bits)) goto out; } else {- local_set(&info->pending, 1);+ info->unwind_mask = bits; } /* The work has been claimed, now schedule it. */ ret = task_work_add(current, &info->work, TWA_RESUME);- if (WARN_ON_ONCE(ret)) {- local_set(&info->pending, 0);- return ret;- }+ if (WARN_ON_ONCE(ret))+ WRITE_ONCE(info->unwind_mask, 0);++ return ret; out:- return test_and_set_bit(bit, &info->unwind_mask);+ return test_and_set_bit(bit, &info->unwind_mask) ?+ UNWIND_ALREADY_PENDING : 0; }
This is some of the most horrifyingly confused code I've seen in a
while.
Please just slow down and think for a minute.
The below is the last four patches rolled into one. Not been near a
compiler.
---
@@ -28,15 +32,26 @@ void unwind_deferred_cancel(struct unwinstatic__always_inlinevoidunwind_reset_info(void){-if(unlikely(current->unwind_info.id.id))+structunwind_task_info*info=¤t->unwind_info;+unsignedlongbits;++/* Was there any unwinding? */+if(unlikely(info->unwind_mask)){+bits=raw_atomic_long_read(&info->unwind_mask);+do{+/* Is a task_work going to run again before going back */+if(bits&UNWIND_PENDING)+return;+}while(!raw_atomic_long_try_cmpxchg(&info->unwind_mask,&bits,0UL));current->unwind_info.id.id=0;+}/**Asunwind_user_faultable()canbecalleddirectlyand*dependsonnr_entriesbeingclearedonexittouser,*thisneedstobeaseparateconditional.*/-if(unlikely(current->unwind_info.cache))-current->unwind_info.cache->nr_entries=0;+if(unlikely(info->cache))+info->cache->nr_entries=0;}#else /* !CONFIG_UNWIND_USER */---a/include/linux/unwind_deferred_types.h+++b/include/linux/unwind_deferred_types.h
@@ -19,8 +21,8 @@ union unwind_task_id {structunwind_task_info{structunwind_cache*cache;structcallback_headwork;+atomic_long_tunwind_mask;unionunwind_task_idid;-intpending;};#endif /* _LINUX_UNWIND_USER_DEFERRED_TYPES_H */---a/kernel/unwind/deferred.c+++b/kernel/unwind/deferred.c
@@ -12,13 +12,39 @@#include<linux/slab.h>#include<linux/mm.h>+/*+*ForrequestingadeferreduserspacestacktracefromNMIcontext+*thearchitecturemustsupportasafecmpxchginNMIcontext.+*Forthosearchitecturesthatdonothavethat,thenitcannotask+*foradeferreduserspacestacktracefromanNMIcontext.Ifit+*does,thenitwillget-EINVAL.+*/+#ifdef CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG+#define UNWIND_NMI_SAFE 1+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+u32zero=0;+returntry_cmpxchg(&info->id.cnt,&zero,cnt);+}+#else+#define UNWIND_NMI_SAFE 0+/* When NMIs are not allowed, this always succeeds */+staticinlinebooltry_assign_cnt(structunwind_task_info*info,u32cnt)+{+info->id.cnt=cnt;+returntrue;+}+#endif /* CONFIG_ARCH_HAVE_NMI_SAFE_CMPXCHG */+/* Make the cache fit in a 4K page */#define UNWIND_MAX_ENTRIES \((SZ_4K-sizeof(structunwind_cache))/sizeof(long))-/* Guards adding to and reading the list of callbacks */+/* Guards adding to or removing from the list of callbacks */staticDEFINE_MUTEX(callback_mutex);staticLIST_HEAD(callbacks);+staticunsignedlongunwind_mask;+DEFINE_STATIC_SRCU(unwind_srcu);/**Thisisauniquepercpuidentifierforagiventaskentrycontext.
@@ -41,21 +67,16 @@ static DEFINE_PER_CPU(u32, unwind_ctx_ct*/staticu64get_cookie(structunwind_task_info*info){-u32cpu_cnt;-u32cnt;-u32old=0;+u32cnt=1;if(info->id.cpu)returninfo->id.id;-cpu_cnt=__this_cpu_read(unwind_ctx_ctr);-cpu_cnt+=2;-cnt=cpu_cnt|1;/* Always make non zero */--if(try_cmpxchg(&info->id.cnt,&old,cnt)){-/* Update the per cpu counter */-__this_cpu_write(unwind_ctx_ctr,cpu_cnt);-}+/* LSB it always set to ensure 0 is an invalid value. */+cnt|=__this_cpu_read(unwind_ctx_ctr)+2;+if(try_assign_cnt(info,cnt))+__this_cpu_write(unwind_ctx_ctr,cnt);+/* Interrupts are disabled, the CPU will always be same */info->id.cpu=smp_processor_id()+1;/* Must be non zero */
@@ -117,13 +138,13 @@ static void unwind_deferred_task_work(ststructunwind_task_info*info=container_of(head,structunwind_task_info,work);structunwind_stacktracetrace;structunwind_work*work;+unsignedlongbits;u64cookie;-if(WARN_ON_ONCE(!info->pending))+if(WARN_ON_ONCE(!unwind_pending(info)))return;-/* Allow work to come in again */-WRITE_ONCE(info->pending,0);+bits=atomic_long_fetch_andnot(UNWIND_PENDING,&info->unwind_mask);/**Fromhereonout,thecallbackmustalwaysbecalled,evenifit's
@@ -170,41 +193,62 @@ static void unwind_deferred_task_work(stintunwind_deferred_request(structunwind_work*work,u64*cookie){structunwind_task_info*info=¤t->unwind_info;-intret;+unsignedlongbits,mask;+intbit,ret;*cookie=0;-if(WARN_ON_ONCE(in_nmi()))-return-EINVAL;-if((current->flags&(PF_KTHREAD|PF_EXITING))||!user_mode(task_pt_regs(current)))return-EINVAL;+/* NMI requires having safe cmpxchg operations */+if(WARN_ON_ONCE(!UNWIND_NMI_SAFE&&in_nmi()))+return-EINVAL;++/* Do not allow cancelled works to request again */+bit=READ_ONCE(work->bit);+if(WARN_ON_ONCE(bit<0))+return-EINVAL;+guard(irqsave)();*cookie=get_cookie(info);-/* callback already pending? */-if(info->pending)+bits=UNWIND_PENDING|BIT(bit);+mask=atomic_long_fetch_or(bits,&info->unwind_mask);+if(mask&bits)return1;/* The work has been claimed, now schedule it. */ret=task_work_add(current,&info->work,TWA_RESUME);if(WARN_ON_ONCE(ret))-returnret;--info->pending=1;-return0;+atomic_long_set(0,&info->unwind_mask);}voidunwind_deferred_cancel(structunwind_work*work){+structtask_struct*g,*t;+intbit;+if(!work)return;guard(mutex)(&callback_mutex);-list_del(&work->list);+list_del_rcu(&work->list);+bit=work->bit;++/* Do not allow any more requests and prevent callbacks */+work->bit=-1;++__clear_bit(bit,&unwind_mask);++synchronize_srcu(&unwind_srcu);++guard(rcu)();+/* Clear this bit from all threads */+for_each_process_thread(g,t)+atomic_long_andnot(BIT(bit),&t->unwind_info.unwind_mask);}intunwind_deferred_init(structunwind_work*work,unwind_callback_tfunc)
@@ -212,7 +256,15 @@ int unwind_deferred_init(struct unwind_wmemset(work,0,sizeof(*work));guard(mutex)(&callback_mutex);-list_add(&work->list,&callbacks);++/* See if there's a bit in the mask available */+if(unwind_mask==~UNWIND_PENDING)+return-EBUSY;++work->bit=ffz(unwind_mask);+__set_bit(work->bit,&unwind_mask);++list_add_rcu(&work->list,&callbacks);work->func=func;return0;}
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 12:34:58
On Tue, 15 Jul 2025 11:09:55 +0200
Peter Zijlstra [off-list ref] wrote:
On Mon, Jul 14, 2025 at 11:11:58AM -0400, Steven Rostedt wrote:
quoted
On Mon, 14 Jul 2025 17:05:16 +0200
Peter Zijlstra [off-list ref] wrote:
quoted
Urgh; so I hate reviewing code you're ripping out in the next patch :-(
Sorry. It just happened to be developed that way. Patch 10 came about
to fix a bug that was triggered with the current method.
Sure; but then you rework the series such that the bug never happened
and reviewers don't go insane from the back and forth and possibly
stumbling over the same bug you then fix later.
You should know this.
The bug was with actually with the next patch (#8) that uses the bitmask to
know which tracer requested a callback. Patch 8 cleared the bit after the
callbacks were called. The bug that was triggered was when the tracer set
an event to do a user space stack trace on an event that is called between
the task_work and going back to user space. It triggered an infinite loop
because the bit would get set again and trigger another task_work!
I can merge patch 8 and 10, but it still would not have affected this
patch, and would have likely led to the same confusion.
I'm going to not stare at email for some 3 weeks soon; I strongly
suggest you take this time to fix up this series to not suffer nonsense
like this.
Sure, I'll take a deep look at your review and work on the next series to
hopefully address each of your concerns.
Thanks!
-- Steve
Since it really didn't matter what bit you took, why not take bit 0?
I was worried about it affecting the global unwind_mask test, but I guess
bit zero works too. In fact, I think I could just set the PENDING and USED
(see next patch) bits in the global unwind mask as being already "used" and
then change:
/* See if there's a bit in the mask available */
if (unwind_mask == ~(UNWIND_PENDING|UNWIND_USED))
return -EBUSY;
Back to:
/* See if there's a bit in the mask available */
if (unwind_mask == ~0UL)
return -EBUSY;
quoted
/*
* This is a unique percpu identifier for a given task entry context.
* Conceptually, it's incremented every time the CPU enters the kernel from
@@ -143,14 +148,17 @@ static void unwind_deferred_task_work(struct callback_head *head) struct unwind_task_info *info = container_of(head, struct unwind_task_info, work); struct unwind_stacktrace trace; struct unwind_work *work;+ unsigned long bits; u64 cookie; int idx;- if (WARN_ON_ONCE(!local_read(&info->pending)))+ if (WARN_ON_ONCE(!unwind_pending(info))) return;- /* Allow work to come in again */- local_set(&info->pending, 0);+ /* Clear pending bit but make sure to have the current bits */+ bits = READ_ONCE(info->unwind_mask);+ while (!try_cmpxchg(&info->unwind_mask, &bits, bits & ~UNWIND_PENDING))+ ;
We have:
bits = atomic_long_fetch_andnot(UNWIND_PENDING, &info->unwind_mask);
for that. A fair number of architecture can actually do this better than
a cmpxchg loop.
Thanks, I didn't know about that one.
quoted
/*
* From here on out, the callback must always be called, even if it's
@@ -194,15 +200,17 @@ static void unwind_deferred_task_work(struct callback_head *head) * because it has already been previously called for the same entry context, * it will be called again with the same stack trace and cookie. *- * Return: 1 if the the callback was already queued.- * 0 if the callback successfully was queued.+ * Return: 0 if the callback successfully was queued.+ * UNWIND_ALREADY_PENDING if the the callback was already queued.+ * UNWIND_ALREADY_EXECUTED if the callback was already called+ * (and will not be called again) * Negative if there's an error. * @cookie holds the cookie of the first request by any user */
Lots of babbling in the Changelog, but no real elucidation as to why you
need this second return value.
AFAICT it serves no real purpose; the users of this function should not
care. The only difference is that the unwind reference (your cookie)
becomes a backward reference instead of a forward reference. But why
would anybody care?
Older versions of the code required it. I think I can remove it now.
Whatever tool is ultimately in charge of gluing humpty^Wstacktraces back
together again should have no problem with this.
quoted
int unwind_deferred_request(struct unwind_work *work, u64 *cookie)
{
struct unwind_task_info *info = ¤t->unwind_info;
- long pending;
+ unsigned long old, bits;
int bit;
int ret;
@@ -225,32 +233,52 @@ int unwind_deferred_request(struct unwind_work *work, u64 *cookie) *cookie = get_cookie(info);- /* This is already queued */- if (test_bit(bit, &info->unwind_mask))- return 1;+ old = READ_ONCE(info->unwind_mask);++ /* Is this already queued */+ if (test_bit(bit, &old)) {+ /*+ * If pending is not set, it means this work's callback+ * was already called.+ */+ return old & UNWIND_PENDING ? UNWIND_ALREADY_PENDING :+ UNWIND_ALREADY_EXECUTED;+ }- /* callback already pending? */- pending = local_read(&info->pending);- if (pending)+ if (unwind_pending(info)) goto out;+ /*+ * This is the first to enable another task_work for this task since+ * the task entered the kernel, or had already called the callbacks.+ * Set only the bit for this work and clear all others as they have+ * already had their callbacks called, and do not need to call them+ * again because of this work.+ */+ bits = UNWIND_PENDING | BIT(bit);++ /*+ * If the cmpxchg() fails, it means that an NMI came in and set+ * the pending bit as well as cleared the other bits. Just+ * jump to setting the bit for this work.+ */ if (CAN_USE_IN_NMI) {- /* Claim the work unless an NMI just now swooped in to do so. */- if (!local_try_cmpxchg(&info->pending, &pending, 1))+ if (!try_cmpxchg(&info->unwind_mask, &old, bits)) goto out; } else {- local_set(&info->pending, 1);+ info->unwind_mask = bits; } /* The work has been claimed, now schedule it. */ ret = task_work_add(current, &info->work, TWA_RESUME);- if (WARN_ON_ONCE(ret)) {- local_set(&info->pending, 0);- return ret;- }+ if (WARN_ON_ONCE(ret))+ WRITE_ONCE(info->unwind_mask, 0);++ return ret; out:- return test_and_set_bit(bit, &info->unwind_mask);+ return test_and_set_bit(bit, &info->unwind_mask) ?+ UNWIND_ALREADY_PENDING : 0; }
This is some of the most horrifyingly confused code I've seen in a
while.
Please just slow down and think for a minute.
The below is the last four patches rolled into one. Not been near a
compiler.
Are you recommending that I fold those patches into one?
I'm fine with that. Note, part of the way things are broken up is because I
took Josh's code and built on top of his work. I tend to try not to modify
someone else's code when doing that and make building blocks of each stage.
Also, it follows the way I tend to review code. Which is to take the entire
patch set, apply it, then look at each patch compared to the final result.
That probably explains why my patch series is confusing for you, as it was
written more for the way I review. Sorry about that.
-- Steve
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 17:20:30
On Tue, 15 Jul 2025 12:29:12 +0200
Peter Zijlstra [off-list ref] wrote:
quoted hunk
@@ -170,41 +193,62 @@ static void unwind_deferred_task_work(st int unwind_deferred_request(struct unwind_work *work, u64 *cookie) { struct unwind_task_info *info = ¤t->unwind_info;- int ret;+ unsigned long bits, mask;+ int bit, ret; *cookie = 0;- if (WARN_ON_ONCE(in_nmi()))- return -EINVAL;- if ((current->flags & (PF_KTHREAD | PF_EXITING)) || !user_mode(task_pt_regs(current))) return -EINVAL;+ /* NMI requires having safe cmpxchg operations */+ if (WARN_ON_ONCE(!UNWIND_NMI_SAFE && in_nmi()))+ return -EINVAL;
I don't think we want to have a WARN_ON() here as the perf series tries
to first do the deferred unwinding and if that fails, it will go back
to it's old method.
By having a WARN_ON(), we need to make perf aware of this limitation
too. Do we want to do that?
-- Steve
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 18:07:00
On Tue, 15 Jul 2025 08:49:32 -0400
Steven Rostedt [off-list ref] wrote:
quoted
quoted
*
- * Return: 1 if the the callback was already queued.
- * 0 if the callback successfully was queued.
+ * Return: 0 if the callback successfully was queued.
+ * UNWIND_ALREADY_PENDING if the the callback was already queued.
+ * UNWIND_ALREADY_EXECUTED if the callback was already called
+ * (and will not be called again)
* Negative if there's an error.
* @cookie holds the cookie of the first request by any user
*/
Lots of babbling in the Changelog, but no real elucidation as to why you
need this second return value.
AFAICT it serves no real purpose; the users of this function should not
care. The only difference is that the unwind reference (your cookie)
becomes a backward reference instead of a forward reference. But why
would anybody care?
Older versions of the code required it. I think I can remove it now.
Ah it is still used in the perf code:
perf_callchain() has:
if (defer_user) {
int ret = deferred_request(event);
if (!ret)
local_inc(&event->ctx->nr_no_switch_fast);
else if (ret < 0)
defer_user = false;
}
Where deferred_requests() is as static function that returns the result
of the unwind request. If it is zero, it means the callback will be
called, if it is greater than zero it means it has already been called,
and negative is an error (and use the old method).
It looks like when the callback is called it expects nr_no_switch_fast
to be incremented and it will decrement it. This is directly from
Josh's patch and I don't know perf well enough to know if that update
to nr_no_switch_fast is needed.
If it's not needed, we can just return 0 on success and negative on
failure. What do you think?
Here's the original patch:
https://lore.kernel.org/all/20250708020050.928524258@kernel.org/
-- Steve
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 18:10:20
On Tue, 15 Jul 2025 14:06:50 -0400
Steven Rostedt [off-list ref] wrote:
Ah it is still used in the perf code:
Either way, what I'll do is to remove this special return value for this
series, and add it back in the perf series if needed.
This is one of the problems that arises when you take a series with
lots of changes and try to break it apart. You will always miss
something that isn't needed in one where a change was made for another
series.
Working on each one to make sure this all works, it starts to blend together :-p
-- Steve
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 18:26:19
On Tue, 15 Jul 2025 14:06:50 -0400
Steven Rostedt [off-list ref] wrote:
quoted
quoted
quoted
+ * Return: 0 if the callback successfully was queued.
+ * UNWIND_ALREADY_PENDING if the the callback was already queued.
+ * UNWIND_ALREADY_EXECUTED if the callback was already called
+ * (and will not be called again)
* Negative if there's an error.
* @cookie holds the cookie of the first request by any user
*/
Lots of babbling in the Changelog, but no real elucidation as to why you
need this second return value.
AFAICT it serves no real purpose; the users of this function should not
care. The only difference is that the unwind reference (your cookie)
becomes a backward reference instead of a forward reference. But why
would anybody care?
Older versions of the code required it. I think I can remove it now.
Ah it is still used in the perf code:
perf_callchain() has:
if (defer_user) {
int ret = deferred_request(event);
if (!ret)
local_inc(&event->ctx->nr_no_switch_fast);
Hmm, I guess this could work if it returned non zero for both already
queued and already executed. So it doesn't need to be two different
values.
-- Steve
From: Peter Zijlstra <peterz@infradead.org> Date: 2025-07-15 19:02:01
On Tue, Jul 15, 2025 at 08:49:32AM -0400, Steven Rostedt wrote:
quoted
The below is the last four patches rolled into one. Not been near a
compiler.
Are you recommending that I fold those patches into one?
Not particularly; but given the terrible back and forth, the only sane
way to 'show' my changes it from patch 6 onwards folded. If I were to
diff against patch 9 it'd be a shitshow.
At the very least the SRCU thing ought to be broken back out. Not sure
how many pieces it can reasonably be broken into, see what works.
From: Peter Zijlstra <peterz@infradead.org> Date: 2025-07-15 19:05:00
On Tue, Jul 15, 2025 at 02:06:50PM -0400, Steven Rostedt wrote:
On Tue, 15 Jul 2025 08:49:32 -0400
Steven Rostedt [off-list ref] wrote:
quoted
quoted
quoted
*
- * Return: 1 if the the callback was already queued.
- * 0 if the callback successfully was queued.
+ * Return: 0 if the callback successfully was queued.
+ * UNWIND_ALREADY_PENDING if the the callback was already queued.
+ * UNWIND_ALREADY_EXECUTED if the callback was already called
+ * (and will not be called again)
* Negative if there's an error.
* @cookie holds the cookie of the first request by any user
*/
Lots of babbling in the Changelog, but no real elucidation as to why you
need this second return value.
AFAICT it serves no real purpose; the users of this function should not
care. The only difference is that the unwind reference (your cookie)
becomes a backward reference instead of a forward reference. But why
would anybody care?
Older versions of the code required it. I think I can remove it now.
Ah it is still used in the perf code:
perf_callchain() has:
if (defer_user) {
int ret = deferred_request(event);
if (!ret)
local_inc(&event->ctx->nr_no_switch_fast);
else if (ret < 0)
defer_user = false;
}
Where deferred_requests() is as static function that returns the result
of the unwind request. If it is zero, it means the callback will be
called, if it is greater than zero it means it has already been called,
and negative is an error (and use the old method).
It looks like when the callback is called it expects nr_no_switch_fast
to be incremented and it will decrement it. This is directly from
Josh's patch and I don't know perf well enough to know if that update
to nr_no_switch_fast is needed.
If it's not needed, we can just return 0 on success and negative on
failure. What do you think?
I'm yet again confused. I don't see this code differentiate between 1
and 2 return values (those PENDING and EXECUTED).
Anyway, fundamentally I don't think there is a problem with backward
references as opposed to the normal forward references.
So leave it out for now.
From: Peter Zijlstra <peterz@infradead.org> Date: 2025-07-15 19:07:30
On Tue, Jul 15, 2025 at 01:20:16PM -0400, Steven Rostedt wrote:
On Tue, 15 Jul 2025 12:29:12 +0200
Peter Zijlstra [off-list ref] wrote:
quoted
@@ -170,41 +193,62 @@ static void unwind_deferred_task_work(st int unwind_deferred_request(struct unwind_work *work, u64 *cookie) { struct unwind_task_info *info = ¤t->unwind_info;- int ret;+ unsigned long bits, mask;+ int bit, ret; *cookie = 0;- if (WARN_ON_ONCE(in_nmi()))- return -EINVAL;- if ((current->flags & (PF_KTHREAD | PF_EXITING)) || !user_mode(task_pt_regs(current))) return -EINVAL;+ /* NMI requires having safe cmpxchg operations */+ if (WARN_ON_ONCE(!UNWIND_NMI_SAFE && in_nmi()))+ return -EINVAL;
I don't think we want to have a WARN_ON() here as the perf series tries
to first do the deferred unwinding and if that fails, it will go back
to it's old method.
The thing is, I don't think we have an architecture that supports NMIs
and does not have NMI safe cmpxchg. And if we do have one such -- I
don't think it has perf; perf very much assumes cmpxchg is NMI safe.
Calling this from NMI context and not having an NMI safe cmpxchg is very
much a dodgy use case. Please leave the WARN, if it ever triggers, we'll
look at who manages and deal with it then.
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-15 22:01:19
On Tue, 15 Jul 2025 12:29:12 +0200
Peter Zijlstra [off-list ref] wrote:
The below is the last four patches rolled into one. Not been near a
compiler.
And it shows ;-)
quoted hunk
@@ -117,13 +138,13 @@ static void unwind_deferred_task_work(st struct unwind_task_info *info = container_of(head, struct unwind_task_info, work); struct unwind_stacktrace trace; struct unwind_work *work;+ unsigned long bits; u64 cookie;- if (WARN_ON_ONCE(!info->pending))+ if (WARN_ON_ONCE(!unwind_pending(info))) return;- /* Allow work to come in again */- WRITE_ONCE(info->pending, 0);+ bits = atomic_long_fetch_andnot(UNWIND_PENDING, &info->unwind_mask);
I may need to do what other parts of the kernel has done and turn the
above into:
bits = atomic_long_fetch_andnot(UNWIND_PENDING, (atomic_long_t *)&info->unwind_mask);
As there's other bit manipulations that atomic_long does not take care
of and it's making the code more confusing. When I looked to see how
other users of atomic_long_andnot() did things, most just typecasted
the value to use that function :-/
-- Steve
quoted hunk
/*
* From here on out, the callback must always be called, even if it's
@@ -162,7 +185,7 @@ static void unwind_deferred_task_work(st * because it has already been previously called for the same entry context, * it will be called again with the same stack trace and cookie. *- * Return: 1 if the the callback was already queued.+ * Return: 1 if the callback was already queued. * 0 if the callback successfully was queued. * Negative if there's an error. * @cookie holds the cookie of the first request by any user
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-16 18:26:17
On Tue, 15 Jul 2025 12:29:12 +0200
Peter Zijlstra [off-list ref] wrote:
On Mon, Jul 07, 2025 at 09:22:49PM -0400, Steven Rostedt wrote:
quoted
+ /*
+ * This is the first to enable another task_work for this task since
+ * the task entered the kernel, or had already called the callbacks.
+ * Set only the bit for this work and clear all others as they have
+ * already had their callbacks called, and do not need to call them
+ * again because of this work.
+ */
+ bits = UNWIND_PENDING | BIT(bit);
+
+ /*
+ * If the cmpxchg() fails, it means that an NMI came in and set
+ * the pending bit as well as cleared the other bits. Just
+ * jump to setting the bit for this work.
+ */
if (CAN_USE_IN_NMI) {
- /* Claim the work unless an NMI just now swooped in to do so. */
- if (!local_try_cmpxchg(&info->pending, &pending, 1))
+ if (!try_cmpxchg(&info->unwind_mask, &old, bits))
goto out;
} else {
- local_set(&info->pending, 1);
+ info->unwind_mask = bits;
}
/* The work has been claimed, now schedule it. */
ret = task_work_add(current, &info->work, TWA_RESUME);
- if (WARN_ON_ONCE(ret)) {
- local_set(&info->pending, 0);
- return ret;
- }
+ if (WARN_ON_ONCE(ret))
+ WRITE_ONCE(info->unwind_mask, 0);
+
+ return ret;
out:
- return test_and_set_bit(bit, &info->unwind_mask);
+ return test_and_set_bit(bit, &info->unwind_mask) ?
+ UNWIND_ALREADY_PENDING : 0;
}
This is some of the most horrifyingly confused code I've seen in a
while.
Please just slow down and think for a minute.
The below is the last four patches rolled into one. Not been near a
compiler.
The above is still needed as is (explained below).
quoted hunk
@@ -170,41 +193,62 @@ static void unwind_deferred_task_work(st int unwind_deferred_request(struct unwind_work *work, u64 *cookie) { struct unwind_task_info *info = ¤t->unwind_info;- int ret;+ unsigned long bits, mask;+ int bit, ret; *cookie = 0;- if (WARN_ON_ONCE(in_nmi()))- return -EINVAL;- if ((current->flags & (PF_KTHREAD | PF_EXITING)) || !user_mode(task_pt_regs(current))) return -EINVAL;+ /* NMI requires having safe cmpxchg operations */+ if (WARN_ON_ONCE(!UNWIND_NMI_SAFE && in_nmi()))+ return -EINVAL;++ /* Do not allow cancelled works to request again */+ bit = READ_ONCE(work->bit);+ if (WARN_ON_ONCE(bit < 0))+ return -EINVAL;+ guard(irqsave)(); *cookie = get_cookie(info);- /* callback already pending? */- if (info->pending)+ bits = UNWIND_PENDING | BIT(bit);+ mask = atomic_long_fetch_or(bits, &info->unwind_mask);+ if (mask & bits) return 1;
So the fetch_or() isn't good enough for what needs to be done, and why
the code above is the way it is.
We have this scenario:
perf and ftrace are both tracing the same task. perf with bit 1 and
ftrace with bit 2. Let's say there's even another perf program
running and registered bit 3.
perf requests a deferred callback, and info->unwind_mask gets bit 1
and the pending bit set.
The task is exiting to user space and calls perf's callback and
clears the pending bit but keeps perf's bit set as it was already
called, and doesn't need to be called again even if perf requests a
new stacktrace before the task gets back to user space.
Now before the task gets back to user space, ftrace requests the
deferred trace. To do so, it must set the pending bit and its bit,
but it must also clear the perf bit as it should not call perf's
callback again.
The atomic_long_fetch_or() above will set ftrace's bit but not clear
perf's bits and the perf callback will get called a second time even
though perf never requested another callback.
This is why the code at the top has:
bits = UNWIND_PENDING | BIT(bit);
/*
* If the cmpxchg() fails, it means that an NMI came in and set
* the pending bit as well as cleared the other bits. Just
* jump to setting the bit for this work.
*/
if (CAN_USE_IN_NMI) {
/* Claim the work unless an NMI just now swooped in to do so. */
if (!local_try_cmpxchg(&info->pending, &pending, 1))
if (!try_cmpxchg(&info->unwind_mask, &old, bits))
goto out;
That cmpxchg() clears out any of the old bits if pending isn't set. Now
if an NMI came in and the other perf process requested a callback, it
would set its own bit plus the pending bit and then ftrace only needs
to jump to the end and do the test_and_set on its bit.
-- Steve
/* The work has been claimed, now schedule it. */
ret = task_work_add(current, &info->work, TWA_RESUME);
if (WARN_ON_ONCE(ret))
- return ret;
-
- info->pending = 1;
- return 0;
+ atomic_long_set(0, &info->unwind_mask);
}
From: Steven Rostedt <rostedt@goodmis.org> Date: 2025-07-16 18:34:06
On Wed, 16 Jul 2025 14:26:09 -0400
Steven Rostedt [off-list ref] wrote:
Now before the task gets back to user space, ftrace requests the
deferred trace. To do so, it must set the pending bit and its bit,
but it must also clear the perf bit as it should not call perf's
callback again.
After ftrace clears the bits, it is possible that the first perf
program will request again and this time it will get another callback
with the same cookie. But at least it has a request between the last
callback and the next one.
That is, it would have:
[Task enters kernel]
request -> add cookie
request -> add cookie
[..]
callback -> add trace + cookie
[ftrace clears bits]
request -> add cookie
callback -> add trace + cookie
[Task exits back to user space]
Which shouldn't be too confusing. But if we just do the fetch_or and it
didn't request a new trace, it would have:
[Task enters kernel]
request -> add cookie
request -> add cookie
[..]
callback -> add trace + cookie
[ftrace clears bits]
callback -> add trace + cookie
[Task exits back to user space]
Where there's two callbacks written to the perf buffer for the same
request.
Maybe this isn't a problem, but I was trying to avoid adding multiple
requests due to other tracers affecting the state.
-- Steve
Instead of adding another long word in the tasks struct, I just use the
unwind_cache that gets allocated on the first use.
I think this can work. I'll switch it over to this and then I can use
the fetch_or() and there should be no extra callbacks, even if an
already called callback is requested again after another callback was
requested which would trigger another task work.
I'll update this patch (and fold it into the bitmask patch) with the
fetch_or() and create this patch as a separate patch that just gets rid
of spurious callbacks.
-- Steve