Re: [PATCH 3/8] arm64: kprobes: Record frame pointer with kretprobe instance

From: Will Deacon
Date: Wed Oct 13 2021 - 04:14:58 EST


On Fri, Oct 08, 2021 at 09:28:39PM +0900, Masami Hiramatsu wrote:
> Record the frame pointer instead of stack address with kretprobe
> instance as the identifier on the instance list.
> Since arm64 always enable CONFIG_FRAME_POINTER, we can use the
> actual frame pointer (x29).
>
> Signed-off-by: Masami Hiramatsu <mhiramat@xxxxxxxxxx>
> ---
> arch/arm64/kernel/probes/kprobes.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/arch/arm64/kernel/probes/kprobes.c b/arch/arm64/kernel/probes/kprobes.c
> index e7ad6da980e8..d9dfa82c1f18 100644
> --- a/arch/arm64/kernel/probes/kprobes.c
> +++ b/arch/arm64/kernel/probes/kprobes.c
> @@ -401,14 +401,14 @@ int __init arch_populate_kprobe_blacklist(void)
>
> void __kprobes __used *trampoline_probe_handler(struct pt_regs *regs)
> {
> - return (void *)kretprobe_trampoline_handler(regs, (void *)kernel_stack_pointer(regs));
> + return (void *)kretprobe_trampoline_handler(regs, (void *)regs->regs[29]);
> }
>
> void __kprobes arch_prepare_kretprobe(struct kretprobe_instance *ri,
> struct pt_regs *regs)
> {
> ri->ret_addr = (kprobe_opcode_t *)regs->regs[30];
> - ri->fp = (void *)kernel_stack_pointer(regs);
> + ri->fp = (void *)regs->regs[29];
>
> /* replace return addr (x30) with trampoline */
> regs->regs[30] = (long)&__kretprobe_trampoline;

Acked-by: Will Deacon <will@xxxxxxxxxx>

Will