Re: [PATCH -tip v4 10/12] x86/kprobes: Push a fake return address at kretprobe_trampoline
From: Peter Zijlstra
Date: Thu Mar 25 2021 - 13:23:07 EST
On Mon, Mar 22, 2021 at 03:41:40PM +0900, Masami Hiramatsu wrote:
> ".global kretprobe_trampoline\n"
> ".type kretprobe_trampoline, @function\n"
> "kretprobe_trampoline:\n"
> #ifdef CONFIG_X86_64
So what happens if we get an NMI here? That is, after the RET but before
the push? Then our IP points into the trampoline but we've not done that
push yet.
> + /* Push fake return address to tell the unwinder it's a kretprobe */
> + " pushq $kretprobe_trampoline\n"
> UNWIND_HINT_FUNC
> + /* Save the sp-8, this will be fixed later */
> + " pushq %rsp\n"
> " pushfq\n"
> SAVE_REGS_STRING
> " movq %rsp, %rdi\n"
> " call trampoline_handler\n"
> RESTORE_REGS_STRING
> + " addq $8, %rsp\n"
> " popfq\n"