Re: [PATCH v3 12/28] kbuild: Defer running objtool to link time for all CFG features

From: Nicolas Schier

Date: Thu Sep 24 2026 - 07:51:57 EST


On Mon, Sep 21, 2026 at 03:31:13PM -0700, Josh Poimboeuf wrote:
> noreturns.h file is hand-maintained file which hard codes all the known
> __noreturn functions in the kernel. It's fragile, often missing
> entries, and keeping it up to date is a maintenance burden.
>
> For LTO, IBT, and klp-build configs, the majority of those entries
> aren't needed, because objtool runs on vmlinux.o, so it already has
> visibility into whether a given function returns (with its dead end
> detection).
>
> Remove the need for many of the noreturns.h entries by just always
> deferring objtool for all features which rely on having the noreturn
> information: namely the ones which rely on the reverse-engineered
> control flow graph (CFG).
>
> Note that NOINSTR_VALIDATION is a special case, where objtool runs on
> individual TUs (with all the objtool-args-y), and then again on
> vmlinux.o (without objtool-args-y except for --werror).
>
> This change makes NOINSTR_VALIDATION just another OBJTOOL_DEFERRED
> feature which runs deferred, and *not* on TUs, so now it gets all the
> args like the others, and the special case for adding --werror on
> !OBJTOOL_DEFERRED is no longer needed.
>
> Signed-off-by: Josh Poimboeuf <jpoimboe@xxxxxxxxxx>
> ---
> lib/Kconfig.debug | 3 ++-
> scripts/Makefile.vmlinux_o | 14 +++-----------
> tools/objtool/noreturns.h | 24 ------------------------
> 3 files changed, 5 insertions(+), 36 deletions(-)
>
> diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
> index 798a10ded19fd..e5aea1c0e54a2 100644
> --- a/lib/Kconfig.debug
> +++ b/lib/Kconfig.debug
> @@ -575,7 +575,8 @@ config OBJTOOL_WERROR
> config OBJTOOL_DEFERRED
> def_bool y
> depends on OBJTOOL
> - depends on LTO_CLANG || X86_KERNEL_IBT || KLP_BUILD
> + depends on OBJTOOL_CONTROL_FLOW || NOINSTR_VALIDATION || LTO_CLANG || \
> + X86_KERNEL_IBT || KLP_BUILD
>
> # Objtool reverse-engineers the control flow graph
> config OBJTOOL_CONTROL_FLOW
> diff --git a/scripts/Makefile.vmlinux_o b/scripts/Makefile.vmlinux_o
> index 9bac917e8b819..df1e3584883e6 100644
> --- a/scripts/Makefile.vmlinux_o
> +++ b/scripts/Makefile.vmlinux_o
> @@ -30,20 +30,12 @@ endif
> # objtool for vmlinux.o
> # ---------------------------------------------------------------------------
> #
> -# For CONFIG_OBJTOOL_DEFERRED (IBT or LTO), objtool doesn't run on individual
> -# translation units. Instead it runs on vmlinux.o.
> -#
> -# For !CONFIG_OBJTOOL_DEFERRED + CONFIG_NOINSTR_VALIDATION, it runs on both
> -# translation units and vmlinux.o, with the latter only used for noinstr/unret
> -# validation.
> +# For CONFIG_OBJTOOL_DEFERRED, objtool doesn't run on individual translation
> +# units. Instead it runs on vmlinux.o.

According to the proposed commit message that's not true if
CONFIG_NOINSTR_VALIDATION=y. Is that (still) correct? Might it make
sense to mention the exception here, too?

for kbuild:

Acked-by: Nicolas Schier <n.schier@xxxxxxxxx>

--
Nicolas