[PATCH] klp-build: Add an option to set the livepatch module version

From: Dmitry Malkin

Date: Wed Sep 30 2026 - 05:24:28 EST


Livepatch modules generated by klp-build do not contain MODULE_VERSION
metadata. Add --module-version to identify a livepatch release
independently of its module name.

Append MODULE_VERSION() to the temporary copy of init.c when the option
is supplied. Restrict the accepted characters so the value can be
embedded safely in a C string literal. Leave the source template and
default build behavior unchanged.

For example:

$ scripts/livepatch/klp-build --module-version=1.2.3 fix.patch

The version can be read from the resulting module file without loading it:

$ modinfo -F version livepatch-fix.ko

The version is descriptive module metadata; it does not control
livepatch replacement or compatibility.

Signed-off-by: Dmitry Malkin <dma@xxxxxxxxxx>
---
scripts/livepatch/klp-build | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)

diff --git a/scripts/livepatch/klp-build b/scripts/livepatch/klp-build
index b52a8489d9f6..25e91fef3fa7 100755
--- a/scripts/livepatch/klp-build
+++ b/scripts/livepatch/klp-build
@@ -22,6 +22,7 @@ shopt -s lastpipe
unset DEBUG_CLONE DIFF_CHECKSUM SKIP_CLEANUP VERBOSE XTRACE

REPLACE=1
+MODULE_VERSION=
SHORT_CIRCUIT=0
JOBS="$(getconf _NPROCESSORS_ONLN)"
shopt -o xtrace | grep -q 'on' && XTRACE=1
@@ -132,6 +133,7 @@ Options:
-f, --show-first-changed Show address of first changed instruction
-j, --jobs=<jobs> Build jobs to run simultaneously [default: $JOBS]
-o, --output=<file.ko> Output file [default: livepatch-<patch-name>.ko]
+ --module-version=<ver> Set MODULE_VERSION metadata (letters, digits, . _ + : -)
--no-replace Disable livepatch atomic replace
-v, --verbose Pass V=1 to kernel/module builds

@@ -160,7 +162,7 @@ process_args() {
local patch

short="hfj:o:vdS:T"
- long="help,show-first-changed,jobs:,output:,no-replace,verbose,debug,short-circuit:,keep-tmp"
+ long="help,show-first-changed,jobs:,output:,module-version:,no-replace,verbose,debug,short-circuit:,keep-tmp"

args=$(getopt --options "$short" --longoptions "$long" -- "$@") || {
echo; usage; exit
@@ -189,6 +191,12 @@ process_args() {
NAME="$(module_name_string "$NAME")"
shift 2
;;
+ --module-version)
+ [[ "$2" =~ ^[a-zA-Z0-9._+:-]+$ ]] || \
+ die "module version must contain only letters, digits, '.', '_', '+', ':' or '-'"
+ MODULE_VERSION="$2"
+ shift 2
+ ;;
--no-replace)
REPLACE=0
shift
@@ -827,6 +835,10 @@ build_patch_module() {

cp -f "$SCRIPT_DIR/init.c" "$KMOD_DIR"

+ if [[ -n "$MODULE_VERSION" ]]; then
+ printf '\nMODULE_VERSION("%s");\n' "$MODULE_VERSION" >> "$KMOD_DIR/init.c"
+ fi
+
echo "obj-m := $NAME.o" > "$makefile"
echo -n "$NAME-y := init.o" >> "$makefile"