Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1405676 > unrolled thread
| Started by | Emese Revfy <re.emese@gmail.com> |
|---|---|
| First post | 2016-05-24 00:10 +0200 |
| Last post | 2016-05-25 19:20 +0200 |
| Articles | 7 — 3 participants |
Back to article view | Back to linux.kernel
[PATCH v9 0/4] Introduce GCC plugin infrastructure Emese Revfy <re.emese@gmail.com> - 2016-05-24 00:10 +0200
[PATCH v9 3/4] Add Cyclomatic complexity GCC plugin Emese Revfy <re.emese@gmail.com> - 2016-05-24 00:10 +0200
[PATCH v9 1/4] Shared library support Emese Revfy <re.emese@gmail.com> - 2016-05-24 00:10 +0200
[PATCH v9 4/4] Add sancov plugin Emese Revfy <re.emese@gmail.com> - 2016-05-24 00:10 +0200
Re: [PATCH v9 0/4] Introduce GCC plugin infrastructure Kees Cook <keescook@chromium.org> - 2016-05-24 19:10 +0200
Re: [PATCH v9 0/4] Introduce GCC plugin infrastructure Michal Marek <mmarek@suse.com> - 2016-05-25 12:50 +0200
Re: [PATCH v9 0/4] Introduce GCC plugin infrastructure Kees Cook <keescook@chromium.org> - 2016-05-25 19:20 +0200
| From | Emese Revfy <re.emese@gmail.com> |
|---|---|
| Date | 2016-05-24 00:10 +0200 |
| Subject | [PATCH v9 0/4] Introduce GCC plugin infrastructure |
| Message-ID | <rC6cV-39y-15@gated-at.bofh.it> |
This patch set introduce the GCC plugin infrastructure with examples for testing
and documentation.
GCC plugins are loadable modules that provide extra features to the compiler.
They are useful for runtime instrumentation and static analysis.
The infrastructure supports all gcc versions from 4.5 to 6.0, building
out-of-tree modules and building in a separate directory. Cross-compilation
is supported too but currently only the x86, arm, arm64 and uml architectures enable plugins.
This infrastructure was ported from grsecurity/PaX. Based on work created by the PaX Team.
It is a CII project supported by the Linux Foundation.
Emese Revfy (4):
Shared library support
GCC plugin infrastructure
Add Cyclomatic complexity plugin
Add sancov plugin
Changes from v8:
* Use warnings instead of errors because of allmodconfig/allyesconfig builds
with old gcc versions
(Suggested-by: Michal Marek <mmarek@suse.com>)
* Order HAVE_GCC_PLUGINS alphabetically
* Moved exported variables from the top level Makefile to scripts/Makefile.gcc-plugins
Changes from v7:
* Moved the "The GCC plugin infrastructure supports the arm and arm64 architectures too"
and the "Documentations of the GCC plugin infrastructre" patches
into the "GCC plugin infrastructure" patch
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Add gcc-plugin.sh to MAINTAINERS
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Makefile.host: Remove *shobjs from multi-depend
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Have distclean and mrproper targets clean the *.so files
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Simplied gcc-plugin-y to add plugins to HOSTLIBS
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Simplified Makefile.host
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Clean *.c.[012]*.*
(Suggested-by: Michal Marek <mmarek@suse.com>)
* Documentation: gcc plugins have to compilable as C and C++
* Enable GCC plugins for UML
Changes from v6:
* Disable the sancov plugin whenever KCOV_INSTRUMENT is disabled
(Reported-by: Huang Ying <ying.huang@linux.intel.com>)
* Disable KCOV/sancov plugin because this is not a regular kernel code
(Reported-by: Huang Ying <ying.huang@linux.intel.com>)
* Removed unnecessary gcc plugin cflags
(Signed-off-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Removed unnecessary gcc plugin aflags
Changes from v5:
* Set important properties on the external fndecl (Add sancov plugin)
* Revert documentation change too (Shared library support)
(Suggested-by: Kees Cook <keescook@chromium.org>)
* The GCC plugin infrastructure now supports the arm and arm64 architectures too
(Signed-off-by: David Brown <david.brown@linaro.org>)
* Simplify the computation of PLUGINCC (GCC plugin infrastructure)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Simplify the invocation of gcc-plugin.sh (GCC plugin infrastructure)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Make use of multi-depend (Shared library support)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Remove unnecessary exports (GCC plugin infrastructure)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Simplify Makefile by using addprefix (GCC plugin infrastructure)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Moved the gcc plugins from tools/ to scripts/ (GCC plugin infrastructure)
(Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* Removed plugins from KBUILD_CFLAGS_32 (GCC plugin infrastructure)
* Remove gcc-plugin target everywhere
(Suggested-by and partly Written-by: Masahiro Yamada <yamada.masahiro@socionext.com>)
* There is no leaf gcc attribute in gcc-4.5 (Add sancov plugin)
* Added support to the sancov plugin with kcov (Add sancov plugin)
Changes from v4:
* Moved shared library support from the GCC plugin infrastructure patch into
a different patch
* Update gcc-*.h from PaX
* Fixed gcc-common.h for gcc 6
* Added pass cloning support to the gcc pass generators
* Disable all plugins in vdso because it is userland code
* Add sancov gcc plugin: another use case for gcc plugin support in the kernel
is when there is a feature in the latest gcc version and we would like to use
it with older gcc versions as well (e.g., distros).
Changes from v3:
* Fix some indentation related warnings
(Suggested by checkpatch.pl)
* Add maintainer entries
* Don't run gcc_plugin.sh when the GCC_PLUGINS option is disabled or unsupported
(Reported-by: Fengguang Wu <fengguang.wu@intel.com>)
Changes from v2:
* Fixed incorrectly encoded characters
* Generate the GIMPLE, IPA, SIMPLE_IPA and RTL pass structures
(Suggested-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>)
* Write plugin related warning messages to stderr instead of stdout
(Suggested-by: Kees Cook <keescook@chromium.org>)
* Mention the installation of the gcc plugin headers (Documentation)
Changes from v1:
* Move the gcc-plugins make target into a separate Makefile because there may
be a lot of plugins (Suggested-by: Rasmus Villemoes)
* Simplify the dependencies of the plugin related config option
(Suggested-by: Kees Cook <keescook@chromium.org>)
* Removed the unnecessary example plugin
---
.gitignore | 1 +
Documentation/dontdiff | 1 +
Documentation/gcc-plugins.txt | 87 +++
MAINTAINERS | 9 +
Makefile | 24 +-
arch/Kconfig | 36 +
arch/arm/Kconfig | 1 +
arch/arm64/Kconfig | 1 +
arch/um/Kconfig.common | 1 +
arch/x86/Kconfig | 1 +
arch/x86/entry/vdso/Makefile | 3 +-
arch/x86/purgatory/Makefile | 2 +
lib/Kconfig.debug | 2 +
scripts/Makefile | 2 +-
scripts/Makefile.build | 2 +-
scripts/Makefile.clean | 4 +-
scripts/Makefile.gcc-plugins | 43 ++
scripts/Makefile.host | 55 +-
scripts/gcc-plugin.sh | 51 ++
scripts/gcc-plugins/Makefile | 27 +
scripts/gcc-plugins/cyc_complexity_plugin.c | 73 ++
scripts/gcc-plugins/gcc-common.h | 830 +++++++++++++++++++++
scripts/gcc-plugins/gcc-generate-gimple-pass.h | 175 +++++
scripts/gcc-plugins/gcc-generate-ipa-pass.h | 289 +++++++
scripts/gcc-plugins/gcc-generate-rtl-pass.h | 175 +++++
scripts/gcc-plugins/gcc-generate-simple_ipa-pass.h | 175 +++++
scripts/gcc-plugins/sancov_plugin.c | 144 ++++
scripts/link-vmlinux.sh | 2 +-
scripts/package/builddeb | 1 +
29 files changed, 2200 insertions(+), 17 deletions(-)
[toc] | [next] | [standalone]
| From | Emese Revfy <re.emese@gmail.com> |
|---|---|
| Date | 2016-05-24 00:10 +0200 |
| Subject | [PATCH v9 3/4] Add Cyclomatic complexity GCC plugin |
| Message-ID | <rC6cV-39y-17@gated-at.bofh.it> |
| In reply to | #1405676 |
Add a very simple plugin to demonstrate the GCC plugin infrastructure. This GCC
plugin computes the cyclomatic complexity of each function.
The complexity M of a function's control flow graph is defined as:
M = E - N + 2P
where
E = the number of edges
N = the number of nodes
P = the number of connected components (exit nodes).
Signed-off-by: Emese Revfy <re.emese@gmail.com>
---
arch/Kconfig | 12 +++++
scripts/Makefile.gcc-plugins | 1 +
scripts/gcc-plugins/Makefile | 1 +
scripts/gcc-plugins/cyc_complexity_plugin.c | 73 +++++++++++++++++++++++++++++
4 files changed, 87 insertions(+)
create mode 100644 scripts/gcc-plugins/cyc_complexity_plugin.c
diff --git a/arch/Kconfig b/arch/Kconfig
index 2821cfe..74f0d63 100644
--- a/arch/Kconfig
+++ b/arch/Kconfig
@@ -372,6 +372,18 @@ menuconfig GCC_PLUGINS
See Documentation/gcc-plugins.txt for details.
+config GCC_PLUGIN_CYC_COMPLEXITY
+ bool "Compute the cyclomatic complexity of a function"
+ depends on GCC_PLUGINS
+ help
+ The complexity M of a function's control flow graph is defined as:
+ M = E - N + 2P
+ where
+
+ E = the number of edges
+ N = the number of nodes
+ P = the number of connected components (exit nodes).
+
config HAVE_CC_STACKPROTECTOR
bool
help
diff --git a/scripts/Makefile.gcc-plugins b/scripts/Makefile.gcc-plugins
index bcc373d..b4a189c 100644
--- a/scripts/Makefile.gcc-plugins
+++ b/scripts/Makefile.gcc-plugins
@@ -2,6 +2,7 @@ ifdef CONFIG_GCC_PLUGINS
__PLUGINCC := $(call cc-ifversion, -ge, 0408, $(HOSTCXX), $(HOSTCC))
PLUGINCC := $(shell $(CONFIG_SHELL) $(srctree)/scripts/gcc-plugin.sh "$(__PLUGINCC)" "$(HOSTCXX)" "$(CC)")
+ gcc-plugin-$(CONFIG_GCC_PLUGIN_CYC_COMPLEXITY) += cyc_complexity_plugin.so
GCC_PLUGINS_CFLAGS := $(addprefix -fplugin=$(objtree)/scripts/gcc-plugins/, $(gcc-plugin-y))
export PLUGINCC GCC_PLUGINS_CFLAGS GCC_PLUGIN
diff --git a/scripts/gcc-plugins/Makefile b/scripts/gcc-plugins/Makefile
index a4c9341..c60ba4b 100644
--- a/scripts/gcc-plugins/Makefile
+++ b/scripts/gcc-plugins/Makefile
@@ -17,4 +17,5 @@ export GCCPLUGINS_DIR HOSTLIBS
$(HOSTLIBS)-y := $(GCC_PLUGIN)
always := $($(HOSTLIBS)-y)
+cyc_complexity_plugin-objs := cyc_complexity_plugin.o
clean-files += *.so
diff --git a/scripts/gcc-plugins/cyc_complexity_plugin.c b/scripts/gcc-plugins/cyc_complexity_plugin.c
new file mode 100644
index 0000000..34df974
--- /dev/null
+++ b/scripts/gcc-plugins/cyc_complexity_plugin.c
@@ -0,0 +1,73 @@
+/*
+ * Copyright 2011-2016 by Emese Revfy <re.emese@gmail.com>
+ * Licensed under the GPL v2, or (at your option) v3
+ *
+ * Homepage:
+ * https://github.com/ephox-gcc-plugins/cyclomatic_complexity
+ *
+ * http://en.wikipedia.org/wiki/Cyclomatic_complexity
+ * The complexity M is then defined as:
+ * M = E - N + 2P
+ * where
+ *
+ * E = the number of edges of the graph
+ * N = the number of nodes of the graph
+ * P = the number of connected components (exit nodes).
+ *
+ * Usage (4.5 - 5):
+ * $ make clean; make run
+ */
+
+#include "gcc-common.h"
+
+int plugin_is_GPL_compatible;
+
+static struct plugin_info cyc_complexity_plugin_info = {
+ .version = "20160225",
+ .help = "Cyclomatic Complexity\n",
+};
+
+static unsigned int cyc_complexity_execute(void)
+{
+ int complexity;
+ expanded_location xloc;
+
+ /* M = E - N + 2P */
+ complexity = n_edges_for_fn(cfun) - n_basic_blocks_for_fn(cfun) + 2;
+
+ xloc = expand_location(DECL_SOURCE_LOCATION(current_function_decl));
+ fprintf(stderr, "Cyclomatic Complexity %d %s:%s\n", complexity,
+ xloc.file, DECL_NAME_POINTER(current_function_decl));
+
+ return 0;
+}
+
+#define PASS_NAME cyc_complexity
+
+#define NO_GATE
+#define TODO_FLAGS_FINISH TODO_dump_func
+
+#include "gcc-generate-gimple-pass.h"
+
+int plugin_init(struct plugin_name_args *plugin_info, struct plugin_gcc_version *version)
+{
+ const char * const plugin_name = plugin_info->base_name;
+ struct register_pass_info cyc_complexity_pass_info;
+
+ cyc_complexity_pass_info.pass = make_cyc_complexity_pass();
+ cyc_complexity_pass_info.reference_pass_name = "ssa";
+ cyc_complexity_pass_info.ref_pass_instance_number = 1;
+ cyc_complexity_pass_info.pos_op = PASS_POS_INSERT_AFTER;
+
+ if (!plugin_default_version_check(version, &gcc_version)) {
+ error(G_("incompatible gcc/plugin versions"));
+ return 1;
+ }
+
+ register_callback(plugin_name, PLUGIN_INFO, NULL,
+ &cyc_complexity_plugin_info);
+ register_callback(plugin_name, PLUGIN_PASS_MANAGER_SETUP, NULL,
+ &cyc_complexity_pass_info);
+
+ return 0;
+}
--
2.8.1
[toc] | [prev] | [next] | [standalone]
| From | Emese Revfy <re.emese@gmail.com> |
|---|---|
| Date | 2016-05-24 00:10 +0200 |
| Subject | [PATCH v9 1/4] Shared library support |
| Message-ID | <rC6cW-39y-35@gated-at.bofh.it> |
| In reply to | #1405676 |
Infrastructure for building independent shared library targets. Based on work created by the PaX Team. Signed-off-by: Emese Revfy <re.emese@gmail.com> --- scripts/Makefile.build | 2 +- scripts/Makefile.clean | 4 +++- scripts/Makefile.host | 55 +++++++++++++++++++++++++++++++++++++++++++++++++- 3 files changed, 58 insertions(+), 3 deletions(-) diff --git a/scripts/Makefile.build b/scripts/Makefile.build index 0d1ca5b..11602e5 100644 --- a/scripts/Makefile.build +++ b/scripts/Makefile.build @@ -60,7 +60,7 @@ endif endif # Do not include host rules unless needed -ifneq ($(hostprogs-y)$(hostprogs-m),) +ifneq ($(hostprogs-y)$(hostprogs-m)$(hostlibs-y)$(hostlibs-m)$(hostcxxlibs-y)$(hostcxxlibs-m),) include scripts/Makefile.host endif diff --git a/scripts/Makefile.clean b/scripts/Makefile.clean index 55c96cb..50616ea 100644 --- a/scripts/Makefile.clean +++ b/scripts/Makefile.clean @@ -38,7 +38,9 @@ subdir-ymn := $(addprefix $(obj)/,$(subdir-ymn)) __clean-files := $(extra-y) $(extra-m) $(extra-) \ $(always) $(targets) $(clean-files) \ $(host-progs) \ - $(hostprogs-y) $(hostprogs-m) $(hostprogs-) + $(hostprogs-y) $(hostprogs-m) $(hostprogs-) \ + $(hostlibs-y) $(hostlibs-m) $(hostlibs-) \ + $(hostcxxlibs-y) $(hostcxxlibs-m) __clean-files := $(filter-out $(no-clean-files), $(__clean-files)) diff --git a/scripts/Makefile.host b/scripts/Makefile.host index 133edfa..45b5b1a 100644 --- a/scripts/Makefile.host +++ b/scripts/Makefile.host @@ -20,7 +20,15 @@ # Will compile qconf as a C++ program, and menu as a C program. # They are linked as C++ code to the executable qconf +# hostcc-option +# Usage: cflags-y += $(call hostcc-option,-march=winchip-c6,-march=i586) + +hostcc-option = $(call try-run,\ + $(HOSTCC) $(HOSTCFLAGS) $(HOST_EXTRACFLAGS) $(1) -c -x c /dev/null -o "$$TMP",$(1),$(2)) + __hostprogs := $(sort $(hostprogs-y) $(hostprogs-m)) +host-cshlib := $(sort $(hostlibs-y) $(hostlibs-m)) +host-cxxshlib := $(sort $(hostcxxlibs-y) $(hostcxxlibs-m)) # C code # Executables compiled from a single .c file @@ -42,6 +50,10 @@ host-cxxmulti := $(foreach m,$(__hostprogs),$(if $($(m)-cxxobjs),$(m))) # C++ Object (.o) files compiled from .cc files host-cxxobjs := $(sort $(foreach m,$(host-cxxmulti),$($(m)-cxxobjs))) +# Object (.o) files used by the shared libaries +host-cshobjs := $(sort $(foreach m,$(host-cshlib),$($(m:.so=-objs)))) +host-cxxshobjs := $(sort $(foreach m,$(host-cxxshlib),$($(m:.so=-objs)))) + # output directory for programs/.o files # hostprogs-y := tools/build may have been specified. # Retrieve also directory of .o files from prog-objs or prog-cxxobjs notation @@ -56,6 +68,10 @@ host-cmulti := $(addprefix $(obj)/,$(host-cmulti)) host-cobjs := $(addprefix $(obj)/,$(host-cobjs)) host-cxxmulti := $(addprefix $(obj)/,$(host-cxxmulti)) host-cxxobjs := $(addprefix $(obj)/,$(host-cxxobjs)) +host-cshlib := $(addprefix $(obj)/,$(host-cshlib)) +host-cxxshlib := $(addprefix $(obj)/,$(host-cxxshlib)) +host-cshobjs := $(addprefix $(obj)/,$(host-cshobjs)) +host-cxxshobjs := $(addprefix $(obj)/,$(host-cxxshobjs)) host-objdirs := $(addprefix $(obj)/,$(host-objdirs)) obj-dirs += $(host-objdirs) @@ -124,5 +140,42 @@ quiet_cmd_host-cxxobjs = HOSTCXX $@ $(host-cxxobjs): $(obj)/%.o: $(src)/%.cc FORCE $(call if_changed_dep,host-cxxobjs) +# Compile .c file, create position independent .o file +# host-cshobjs -> .o +quiet_cmd_host-cshobjs = HOSTCC -fPIC $@ + cmd_host-cshobjs = $(HOSTCC) $(hostc_flags) -fPIC -c -o $@ $< +$(host-cshobjs): $(obj)/%.o: $(src)/%.c FORCE + $(call if_changed_dep,host-cshobjs) + +# Compile .c file, create position independent .o file +# Note that plugin capable gcc versions can be either C or C++ based +# therefore plugin source files have to be compilable in both C and C++ mode. +# This is why a C++ compiler is invoked on a .c file. +# host-cxxshobjs -> .o +quiet_cmd_host-cxxshobjs = HOSTCXX -fPIC $@ + cmd_host-cxxshobjs = $(HOSTCXX) $(hostcxx_flags) -fPIC -c -o $@ $< +$(host-cxxshobjs): $(obj)/%.o: $(src)/%.c FORCE + $(call if_changed_dep,host-cxxshobjs) + +# Link a shared library, based on position independent .o files +# *.o -> .so shared library (host-cshlib) +quiet_cmd_host-cshlib = HOSTLLD -shared $@ + cmd_host-cshlib = $(HOSTCC) $(HOSTLDFLAGS) -shared -o $@ \ + $(addprefix $(obj)/,$($(@F:.so=-objs))) \ + $(HOST_LOADLIBES) $(HOSTLOADLIBES_$(@F)) +$(host-cshlib): FORCE + $(call if_changed,host-cshlib) +$(call multi_depend, $(host-cshlib), .so, -objs) + +# Link a shared library, based on position independent .o files +# *.o -> .so shared library (host-cxxshlib) +quiet_cmd_host-cxxshlib = HOSTLLD -shared $@ + cmd_host-cxxshlib = $(HOSTCXX) $(HOSTLDFLAGS) -shared -o $@ \ + $(addprefix $(obj)/,$($(@F:.so=-objs))) \ + $(HOST_LOADLIBES) $(HOSTLOADLIBES_$(@F)) +$(host-cxxshlib): FORCE + $(call if_changed,host-cxxshlib) +$(call multi_depend, $(host-cxxshlib), .so, -objs) + targets += $(host-csingle) $(host-cmulti) $(host-cobjs)\ - $(host-cxxmulti) $(host-cxxobjs) + $(host-cxxmulti) $(host-cxxobjs) $(host-cshlib) $(host-cshobjs) $(host-cxxshlib) $(host-cxxshobjs) -- 2.8.1
[toc] | [prev] | [next] | [standalone]
| From | Emese Revfy <re.emese@gmail.com> |
|---|---|
| Date | 2016-05-24 00:10 +0200 |
| Subject | [PATCH v9 4/4] Add sancov plugin |
| Message-ID | <rC6cW-39y-43@gated-at.bofh.it> |
| In reply to | #1405676 |
The sancov gcc plugin inserts a __sanitizer_cov_trace_pc() call
at the start of basic blocks.
This plugin is a helper plugin for the kcov feature. It supports
all gcc versions with plugin support (from gcc-4.5 on).
It is based on the gcc commit "Add fuzzing coverage support" by Dmitry Vyukov
(https://gcc.gnu.org/viewcvs/gcc?limit_changes=0&view=revision&revision=231296).
Signed-off-by: Emese Revfy <re.emese@gmail.com>
---
Makefile | 10 +--
arch/Kconfig | 9 +++
arch/x86/purgatory/Makefile | 2 +
lib/Kconfig.debug | 2 +
scripts/Makefile.gcc-plugins | 21 +++++-
scripts/gcc-plugins/Makefile | 6 ++
scripts/gcc-plugins/sancov_plugin.c | 144 ++++++++++++++++++++++++++++++++++++
7 files changed, 184 insertions(+), 10 deletions(-)
create mode 100644 scripts/gcc-plugins/sancov_plugin.c
diff --git a/Makefile b/Makefile
index ebe6c3c..b4f8f0a 100644
--- a/Makefile
+++ b/Makefile
@@ -369,7 +369,7 @@ LDFLAGS_MODULE =
CFLAGS_KERNEL =
AFLAGS_KERNEL =
CFLAGS_GCOV = -fprofile-arcs -ftest-coverage -fno-tree-loop-im -Wno-maybe-uninitialized
-CFLAGS_KCOV = -fsanitize-coverage=trace-pc
+CFLAGS_KCOV := $(call cc-option,-fsanitize-coverage=trace-pc,)
# Use USERINCLUDE when you must reference the UAPI directories only.
@@ -691,14 +691,6 @@ endif
endif
KBUILD_CFLAGS += $(stackp-flag)
-ifdef CONFIG_KCOV
- ifeq ($(call cc-option, $(CFLAGS_KCOV)),)
- $(warning Cannot use CONFIG_KCOV: \
- -fsanitize-coverage=trace-pc is not supported by compiler)
- CFLAGS_KCOV =
- endif
-endif
-
ifeq ($(cc-name),clang)
KBUILD_CPPFLAGS += $(call cc-option,-Qunused-arguments,)
KBUILD_CPPFLAGS += $(call cc-option,-Wno-unknown-warning-option,)
diff --git a/arch/Kconfig b/arch/Kconfig
index 74f0d63..5feadad 100644
--- a/arch/Kconfig
+++ b/arch/Kconfig
@@ -384,6 +384,15 @@ config GCC_PLUGIN_CYC_COMPLEXITY
N = the number of nodes
P = the number of connected components (exit nodes).
+config GCC_PLUGIN_SANCOV
+ bool
+ depends on GCC_PLUGINS
+ help
+ This plugin inserts a __sanitizer_cov_trace_pc() call at the start of
+ basic blocks. It supports all gcc versions with plugin support (from
+ gcc-4.5 on). It is based on the commit "Add fuzzing coverage support"
+ by Dmitry Vyukov <dvyukov@google.com>.
+
config HAVE_CC_STACKPROTECTOR
bool
help
diff --git a/arch/x86/purgatory/Makefile b/arch/x86/purgatory/Makefile
index 12734a9..ac58c16 100644
--- a/arch/x86/purgatory/Makefile
+++ b/arch/x86/purgatory/Makefile
@@ -8,6 +8,8 @@ PURGATORY_OBJS = $(addprefix $(obj)/,$(purgatory-y))
LDFLAGS_purgatory.ro := -e purgatory_start -r --no-undefined -nostdlib -z nodefaultlib
targets += purgatory.ro
+KCOV_INSTRUMENT := n
+
# Default KBUILD_CFLAGS can have -pg option set when FTRACE is enabled. That
# in turn leaves some undefined symbols like __fentry__ in purgatory and not
# sure how to relocate those. Like kexec-tools, use custom flags.
diff --git a/lib/Kconfig.debug b/lib/Kconfig.debug
index 09cdb1f..7c7980d 100644
--- a/lib/Kconfig.debug
+++ b/lib/Kconfig.debug
@@ -712,6 +712,8 @@ config KCOV
bool "Code coverage for fuzzing"
depends on ARCH_HAS_KCOV
select DEBUG_FS
+ select GCC_PLUGINS
+ select GCC_PLUGIN_SANCOV
help
KCOV exposes kernel code coverage information in a form suitable
for coverage-guided fuzzing (randomized testing).
diff --git a/scripts/Makefile.gcc-plugins b/scripts/Makefile.gcc-plugins
index b4a189c..ed37e9b 100644
--- a/scripts/Makefile.gcc-plugins
+++ b/scripts/Makefile.gcc-plugins
@@ -2,10 +2,26 @@ ifdef CONFIG_GCC_PLUGINS
__PLUGINCC := $(call cc-ifversion, -ge, 0408, $(HOSTCXX), $(HOSTCC))
PLUGINCC := $(shell $(CONFIG_SHELL) $(srctree)/scripts/gcc-plugin.sh "$(__PLUGINCC)" "$(HOSTCXX)" "$(CC)")
+ SANCOV_PLUGIN := -fplugin=$(objtree)/scripts/gcc-plugins/sancov_plugin.so
+
gcc-plugin-$(CONFIG_GCC_PLUGIN_CYC_COMPLEXITY) += cyc_complexity_plugin.so
+
+ ifdef CONFIG_GCC_PLUGIN_SANCOV
+ ifeq ($(CFLAGS_KCOV),)
+ # It is needed because of the gcc-plugin.sh and gcc version checks.
+ gcc-plugin-$(CONFIG_GCC_PLUGIN_SANCOV) += sancov_plugin.so
+
+ ifneq ($(PLUGINCC),)
+ CFLAGS_KCOV := $(SANCOV_PLUGIN)
+ else
+ $(warning warning: cannot use CONFIG_KCOV: -fsanitize-coverage=trace-pc is not supported by compiler)
+ endif
+ endif
+ endif
+
GCC_PLUGINS_CFLAGS := $(addprefix -fplugin=$(objtree)/scripts/gcc-plugins/, $(gcc-plugin-y))
- export PLUGINCC GCC_PLUGINS_CFLAGS GCC_PLUGIN
+ export PLUGINCC GCC_PLUGINS_CFLAGS GCC_PLUGIN SANCOV_PLUGIN
ifeq ($(PLUGINCC),)
ifneq ($(GCC_PLUGINS_CFLAGS),)
@@ -16,6 +32,9 @@ ifdef CONFIG_GCC_PLUGINS
$(warning warning: your gcc version does not support plugins, you should upgrade it to gcc 4.5 at least)
endif
endif
+ else
+ # SANCOV_PLUGIN can be only in CFLAGS_KCOV because avoid duplication.
+ GCC_PLUGINS_CFLAGS := $(filter-out $(SANCOV_PLUGIN), $(GCC_PLUGINS_CFLAGS))
endif
KBUILD_CFLAGS += $(GCC_PLUGINS_CFLAGS)
diff --git a/scripts/gcc-plugins/Makefile b/scripts/gcc-plugins/Makefile
index c60ba4b..88c8ec4 100644
--- a/scripts/gcc-plugins/Makefile
+++ b/scripts/gcc-plugins/Makefile
@@ -14,8 +14,14 @@ endif
export GCCPLUGINS_DIR HOSTLIBS
+ifneq ($(CFLAGS_KCOV), $(SANCOV_PLUGIN))
+ GCC_PLUGIN := $(filter-out $(SANCOV_PLUGIN), $(GCC_PLUGIN))
+endif
+
$(HOSTLIBS)-y := $(GCC_PLUGIN)
always := $($(HOSTLIBS)-y)
cyc_complexity_plugin-objs := cyc_complexity_plugin.o
+sancov_plugin-objs := sancov_plugin.o
+
clean-files += *.so
diff --git a/scripts/gcc-plugins/sancov_plugin.c b/scripts/gcc-plugins/sancov_plugin.c
new file mode 100644
index 0000000..aedd611
--- /dev/null
+++ b/scripts/gcc-plugins/sancov_plugin.c
@@ -0,0 +1,144 @@
+/*
+ * Copyright 2011-2016 by Emese Revfy <re.emese@gmail.com>
+ * Licensed under the GPL v2, or (at your option) v3
+ *
+ * Homepage:
+ * https://github.com/ephox-gcc-plugins/sancov
+ *
+ * This plugin inserts a __sanitizer_cov_trace_pc() call at the start of basic blocks.
+ * It supports all gcc versions with plugin support (from gcc-4.5 on).
+ * It is based on the commit "Add fuzzing coverage support" by Dmitry Vyukov <dvyukov@google.com>.
+ *
+ * You can read about it more here:
+ * https://gcc.gnu.org/viewcvs/gcc?limit_changes=0&view=revision&revision=231296
+ * http://lwn.net/Articles/674854/
+ * https://github.com/google/syzkaller
+ * https://lwn.net/Articles/677764/
+ *
+ * Usage:
+ * make run
+ */
+
+#include "gcc-common.h"
+
+int plugin_is_GPL_compatible;
+
+tree sancov_fndecl;
+
+static struct plugin_info sancov_plugin_info = {
+ .version = "20160402",
+ .help = "sancov plugin\n",
+};
+
+static unsigned int sancov_execute(void)
+{
+ basic_block bb;
+
+ /* Remove this line when this plugin and kcov will be in the kernel.
+ if (!strcmp(DECL_NAME_POINTER(current_function_decl), DECL_NAME_POINTER(sancov_fndecl)))
+ return 0;
+ */
+
+ FOR_EACH_BB_FN(bb, cfun) {
+ const_gimple stmt;
+ gcall *gcall;
+ gimple_stmt_iterator gsi = gsi_after_labels(bb);
+
+ if (gsi_end_p(gsi))
+ continue;
+
+ stmt = gsi_stmt(gsi);
+ gcall = as_a_gcall(gimple_build_call(sancov_fndecl, 0));
+ gimple_set_location(gcall, gimple_location(stmt));
+ gsi_insert_before(&gsi, gcall, GSI_SAME_STMT);
+ }
+ return 0;
+}
+
+#define PASS_NAME sancov
+
+#define NO_GATE
+#define TODO_FLAGS_FINISH TODO_dump_func | TODO_verify_stmts | TODO_update_ssa_no_phi | TODO_verify_flow
+
+#include "gcc-generate-gimple-pass.h"
+
+static void sancov_start_unit(void __unused *gcc_data, void __unused *user_data)
+{
+ tree leaf_attr, nothrow_attr;
+ tree BT_FN_VOID = build_function_type_list(void_type_node, NULL_TREE);
+
+ sancov_fndecl = build_fn_decl("__sanitizer_cov_trace_pc", BT_FN_VOID);
+
+ DECL_ASSEMBLER_NAME(sancov_fndecl);
+ TREE_PUBLIC(sancov_fndecl) = 1;
+ DECL_EXTERNAL(sancov_fndecl) = 1;
+ DECL_ARTIFICIAL(sancov_fndecl) = 1;
+ DECL_PRESERVE_P(sancov_fndecl) = 1;
+ DECL_UNINLINABLE(sancov_fndecl) = 1;
+ TREE_USED(sancov_fndecl) = 1;
+
+ nothrow_attr = tree_cons(get_identifier("nothrow"), NULL, NULL);
+ decl_attributes(&sancov_fndecl, nothrow_attr, 0);
+ gcc_assert(TREE_NOTHROW(sancov_fndecl));
+#if BUILDING_GCC_VERSION > 4005
+ leaf_attr = tree_cons(get_identifier("leaf"), NULL, NULL);
+ decl_attributes(&sancov_fndecl, leaf_attr, 0);
+#endif
+}
+
+int plugin_init(struct plugin_name_args *plugin_info, struct plugin_gcc_version *version)
+{
+ int i;
+ struct register_pass_info sancov_plugin_pass_info;
+ const char * const plugin_name = plugin_info->base_name;
+ const int argc = plugin_info->argc;
+ const struct plugin_argument * const argv = plugin_info->argv;
+ bool enable = true;
+
+ static const struct ggc_root_tab gt_ggc_r_gt_sancov[] = {
+ {
+ .base = &sancov_fndecl,
+ .nelt = 1,
+ .stride = sizeof(sancov_fndecl),
+ .cb = >_ggc_mx_tree_node,
+ .pchw = >_pch_nx_tree_node
+ },
+ LAST_GGC_ROOT_TAB
+ };
+
+ /* BBs can be split afterwards?? */
+ sancov_plugin_pass_info.pass = make_sancov_pass();
+#if BUILDING_GCC_VERSION >= 4009
+ sancov_plugin_pass_info.reference_pass_name = "asan";
+#else
+ sancov_plugin_pass_info.reference_pass_name = "nrv";
+#endif
+ sancov_plugin_pass_info.ref_pass_instance_number = 0;
+ sancov_plugin_pass_info.pos_op = PASS_POS_INSERT_BEFORE;
+
+ if (!plugin_default_version_check(version, &gcc_version)) {
+ error(G_("incompatible gcc/plugin versions"));
+ return 1;
+ }
+
+ for (i = 0; i < argc; ++i) {
+ if (!strcmp(argv[i].key, "no-sancov")) {
+ enable = false;
+ continue;
+ }
+ error(G_("unkown option '-fplugin-arg-%s-%s'"), plugin_name, argv[i].key);
+ }
+
+ register_callback(plugin_name, PLUGIN_INFO, NULL, &sancov_plugin_info);
+
+ if (!enable)
+ return 0;
+
+#if BUILDING_GCC_VERSION < 6000
+ register_callback(plugin_name, PLUGIN_START_UNIT, &sancov_start_unit, NULL);
+ register_callback(plugin_name, PLUGIN_REGISTER_GGC_ROOTS, NULL, (void *)>_ggc_r_gt_sancov);
+ register_callback(plugin_name, PLUGIN_PASS_MANAGER_SETUP, NULL, &sancov_plugin_pass_info);
+#endif
+
+ return 0;
+}
--
2.8.1
[toc] | [prev] | [next] | [standalone]
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Date | 2016-05-24 19:10 +0200 |
| Message-ID | <rCo0a-65z-9@gated-at.bofh.it> |
| In reply to | #1405676 |
On Mon, May 23, 2016 at 3:07 PM, Emese Revfy <re.emese@gmail.com> wrote: > This patch set introduce the GCC plugin infrastructure with examples for testing > and documentation. > > GCC plugins are loadable modules that provide extra features to the compiler. > They are useful for runtime instrumentation and static analysis. > > The infrastructure supports all gcc versions from 4.5 to 6.0, building > out-of-tree modules and building in a separate directory. Cross-compilation > is supported too but currently only the x86, arm, arm64 and uml architectures enable plugins. > > This infrastructure was ported from grsecurity/PaX. Based on work created by the PaX Team. > It is a CII project supported by the Linux Foundation. > > Emese Revfy (4): > Shared library support > GCC plugin infrastructure > Add Cyclomatic complexity plugin > Add sancov plugin Michal, once -rc1 is out, can you carry this for -next? I'm happy to use my tree for it, if you want me to do it. -Kees > > > Changes from v8: > * Use warnings instead of errors because of allmodconfig/allyesconfig builds > with old gcc versions > (Suggested-by: Michal Marek <mmarek@suse.com>) > * Order HAVE_GCC_PLUGINS alphabetically > * Moved exported variables from the top level Makefile to scripts/Makefile.gcc-plugins > > Changes from v7: > * Moved the "The GCC plugin infrastructure supports the arm and arm64 architectures too" > and the "Documentations of the GCC plugin infrastructre" patches > into the "GCC plugin infrastructure" patch > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Add gcc-plugin.sh to MAINTAINERS > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Makefile.host: Remove *shobjs from multi-depend > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Have distclean and mrproper targets clean the *.so files > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Simplied gcc-plugin-y to add plugins to HOSTLIBS > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Simplified Makefile.host > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Clean *.c.[012]*.* > (Suggested-by: Michal Marek <mmarek@suse.com>) > * Documentation: gcc plugins have to compilable as C and C++ > * Enable GCC plugins for UML > > Changes from v6: > * Disable the sancov plugin whenever KCOV_INSTRUMENT is disabled > (Reported-by: Huang Ying <ying.huang@linux.intel.com>) > * Disable KCOV/sancov plugin because this is not a regular kernel code > (Reported-by: Huang Ying <ying.huang@linux.intel.com>) > * Removed unnecessary gcc plugin cflags > (Signed-off-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Removed unnecessary gcc plugin aflags > > Changes from v5: > * Set important properties on the external fndecl (Add sancov plugin) > * Revert documentation change too (Shared library support) > (Suggested-by: Kees Cook <keescook@chromium.org>) > * The GCC plugin infrastructure now supports the arm and arm64 architectures too > (Signed-off-by: David Brown <david.brown@linaro.org>) > * Simplify the computation of PLUGINCC (GCC plugin infrastructure) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Simplify the invocation of gcc-plugin.sh (GCC plugin infrastructure) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Make use of multi-depend (Shared library support) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Remove unnecessary exports (GCC plugin infrastructure) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Simplify Makefile by using addprefix (GCC plugin infrastructure) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Moved the gcc plugins from tools/ to scripts/ (GCC plugin infrastructure) > (Suggested-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * Removed plugins from KBUILD_CFLAGS_32 (GCC plugin infrastructure) > * Remove gcc-plugin target everywhere > (Suggested-by and partly Written-by: Masahiro Yamada <yamada.masahiro@socionext.com>) > * There is no leaf gcc attribute in gcc-4.5 (Add sancov plugin) > * Added support to the sancov plugin with kcov (Add sancov plugin) > > Changes from v4: > * Moved shared library support from the GCC plugin infrastructure patch into > a different patch > * Update gcc-*.h from PaX > * Fixed gcc-common.h for gcc 6 > * Added pass cloning support to the gcc pass generators > * Disable all plugins in vdso because it is userland code > * Add sancov gcc plugin: another use case for gcc plugin support in the kernel > is when there is a feature in the latest gcc version and we would like to use > it with older gcc versions as well (e.g., distros). > > Changes from v3: > * Fix some indentation related warnings > (Suggested by checkpatch.pl) > * Add maintainer entries > * Don't run gcc_plugin.sh when the GCC_PLUGINS option is disabled or unsupported > (Reported-by: Fengguang Wu <fengguang.wu@intel.com>) > > Changes from v2: > * Fixed incorrectly encoded characters > * Generate the GIMPLE, IPA, SIMPLE_IPA and RTL pass structures > (Suggested-by: Rasmus Villemoes <linux@rasmusvillemoes.dk>) > * Write plugin related warning messages to stderr instead of stdout > (Suggested-by: Kees Cook <keescook@chromium.org>) > * Mention the installation of the gcc plugin headers (Documentation) > > Changes from v1: > * Move the gcc-plugins make target into a separate Makefile because there may > be a lot of plugins (Suggested-by: Rasmus Villemoes) > * Simplify the dependencies of the plugin related config option > (Suggested-by: Kees Cook <keescook@chromium.org>) > * Removed the unnecessary example plugin > > --- > .gitignore | 1 + > Documentation/dontdiff | 1 + > Documentation/gcc-plugins.txt | 87 +++ > MAINTAINERS | 9 + > Makefile | 24 +- > arch/Kconfig | 36 + > arch/arm/Kconfig | 1 + > arch/arm64/Kconfig | 1 + > arch/um/Kconfig.common | 1 + > arch/x86/Kconfig | 1 + > arch/x86/entry/vdso/Makefile | 3 +- > arch/x86/purgatory/Makefile | 2 + > lib/Kconfig.debug | 2 + > scripts/Makefile | 2 +- > scripts/Makefile.build | 2 +- > scripts/Makefile.clean | 4 +- > scripts/Makefile.gcc-plugins | 43 ++ > scripts/Makefile.host | 55 +- > scripts/gcc-plugin.sh | 51 ++ > scripts/gcc-plugins/Makefile | 27 + > scripts/gcc-plugins/cyc_complexity_plugin.c | 73 ++ > scripts/gcc-plugins/gcc-common.h | 830 +++++++++++++++++++++ > scripts/gcc-plugins/gcc-generate-gimple-pass.h | 175 +++++ > scripts/gcc-plugins/gcc-generate-ipa-pass.h | 289 +++++++ > scripts/gcc-plugins/gcc-generate-rtl-pass.h | 175 +++++ > scripts/gcc-plugins/gcc-generate-simple_ipa-pass.h | 175 +++++ > scripts/gcc-plugins/sancov_plugin.c | 144 ++++ > scripts/link-vmlinux.sh | 2 +- > scripts/package/builddeb | 1 + > 29 files changed, 2200 insertions(+), 17 deletions(-) -- Kees Cook Chrome OS & Brillo Security
[toc] | [prev] | [next] | [standalone]
| From | Michal Marek <mmarek@suse.com> |
|---|---|
| Date | 2016-05-25 12:50 +0200 |
| Message-ID | <rCExY-8n2-3@gated-at.bofh.it> |
| In reply to | #1406289 |
On 2016-05-24 19:04, Kees Cook wrote: > On Mon, May 23, 2016 at 3:07 PM, Emese Revfy <re.emese@gmail.com> wrote: >> This patch set introduce the GCC plugin infrastructure with examples for testing >> and documentation. >> >> GCC plugins are loadable modules that provide extra features to the compiler. >> They are useful for runtime instrumentation and static analysis. >> >> The infrastructure supports all gcc versions from 4.5 to 6.0, building >> out-of-tree modules and building in a separate directory. Cross-compilation >> is supported too but currently only the x86, arm, arm64 and uml architectures enable plugins. >> >> This infrastructure was ported from grsecurity/PaX. Based on work created by the PaX Team. >> It is a CII project supported by the Linux Foundation. >> >> Emese Revfy (4): >> Shared library support >> GCC plugin infrastructure >> Add Cyclomatic complexity plugin >> Add sancov plugin > > Michal, once -rc1 is out, can you carry this for -next? Yes. Michal
[toc] | [prev] | [next] | [standalone]
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Date | 2016-05-25 19:20 +0200 |
| Message-ID | <rCKDo-3EB-9@gated-at.bofh.it> |
| In reply to | #1406830 |
On Wed, May 25, 2016 at 3:46 AM, Michal Marek <mmarek@suse.com> wrote: > On 2016-05-24 19:04, Kees Cook wrote: >> On Mon, May 23, 2016 at 3:07 PM, Emese Revfy <re.emese@gmail.com> wrote: >>> This patch set introduce the GCC plugin infrastructure with examples for testing >>> and documentation. >>> >>> GCC plugins are loadable modules that provide extra features to the compiler. >>> They are useful for runtime instrumentation and static analysis. >>> >>> The infrastructure supports all gcc versions from 4.5 to 6.0, building >>> out-of-tree modules and building in a separate directory. Cross-compilation >>> is supported too but currently only the x86, arm, arm64 and uml architectures enable plugins. >>> >>> This infrastructure was ported from grsecurity/PaX. Based on work created by the PaX Team. >>> It is a CII project supported by the Linux Foundation. >>> >>> Emese Revfy (4): >>> Shared library support >>> GCC plugin infrastructure >>> Add Cyclomatic complexity plugin >>> Add sancov plugin >> >> Michal, once -rc1 is out, can you carry this for -next? > > Yes. Awesome! Please consider it: Acked-by: Kees Cook <keescook@chromium.org> If it's any help, I have it in my tree here: http://git.kernel.org/cgit/linux/kernel/git/kees/linux.git/log/?h=kspp/gcc-plugins/infrastructure Thanks! -Kees -- Kees Cook Chrome OS & Brillo Security
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web