Received: by 2002:a6b:500f:0:0:0:0:0 with SMTP id e15csp4665505iob; Sun, 8 May 2022 21:10:36 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxYp25l9x2zomz6JXSqFYRNpm9ApFZk9WZxRGwEaf9oFE7E/OLq5ZcMl7S2k2IAhX5KFTzD X-Received: by 2002:a17:90b:1811:b0:1dc:8d37:b4cb with SMTP id lw17-20020a17090b181100b001dc8d37b4cbmr24642583pjb.101.1652069436546; Sun, 08 May 2022 21:10:36 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1652069436; cv=none; d=google.com; s=arc-20160816; b=x9q25A6himM0Jg1NrawyS+K1W9Q7YUKZLCukPbCj9RhprcRyQqtL0vN0W042YdonKu mlHpdLhIr5+v3/1IOFVL0/+z5A6gauELD52TVx2msq8QbWjau3kcLPjAoLhknCRNb7Lv XQTuKrWr0+V81/lhjzDByKtBe9W3wxGUPTzjYc79SfeH3kVOPrJVT/X95CfVZBGyc6GT x7Zrz090oNTepoAtpw83wgoFg7+IGsHB99PpG9XAdFQZvsTpuz9rHiAlRwd/+4HDoX8g veTxOGGHr+78dgm5M51/JP6jhQGnTZMqdABubipNNDs3RK+BRmAiHjDGohb5JYd7DqsR Ordg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=i+viNjDrMgNP0dJW6+SzJYDKkDgZGFNT5L7ehsq8/as=; b=ODZ9r9eTBQi8hTanOv2BMq09jbe3JDKm21XNCtP4GZf7kdVKQj1oH20xll83t4u/cs VuwK5W1d8i+pQSGuKbgHvKIQeZnikzeM7Q5KX8xOVemDcaNNz9nsEr+X9ZgyrT2/Ggvr sdDgoOb7j2VouzQpbS6lJ+RJmPaTz2z6seaVxvcYH+Tq3WWPpVKDsgwTI1MoCHBHv6+4 luqNpNb2w4Kiqw0TUmp70KaymibZdjkCCrwB7a3D3FtLjY52spaMZtk02rKAlc7qcSo0 JPVCI496wh2KhC103nhSjQyIYmO6BBHZ8QM0Z5fiD4vhbh08ABS546beQDgqg6O9tDb2 geRA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=uMOE3D4f; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [2620:137:e000::1:18]) by mx.google.com with ESMTPS id u64-20020a638543000000b003982527600dsi12563001pgd.185.2022.05.08.21.10.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 08 May 2022 21:10:36 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) client-ip=2620:137:e000::1:18; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=k20201202 header.b=uMOE3D4f; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=kernel.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 01BCD10DD2F; Sun, 8 May 2022 21:09:19 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1381688AbiEEQLQ (ORCPT + 99 others); Thu, 5 May 2022 12:11:16 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:58980 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235722AbiEEQLK (ORCPT ); Thu, 5 May 2022 12:11:10 -0400 Received: from dfw.source.kernel.org (dfw.source.kernel.org [IPv6:2604:1380:4641:c500::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 1C0D55C377; Thu, 5 May 2022 09:07:30 -0700 (PDT) Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id AC09361DCB; Thu, 5 May 2022 16:07:29 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 6A889C385A4; Thu, 5 May 2022 16:07:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1651766849; bh=1Um1v2pbsXWVzfuOFhwnCRlaKUyCQMuNW2iqZGU5beE=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=uMOE3D4fCNUykHj6y7vqEfSS6w2+oXfDFbPRaC053ASaXrHFIdImGUjfIalRHKWSZ xBuzFWi6ucvPhO4kUZMTlHRoc8D7+P0Bemq8qX256sUzj3hsyLPOQr8ZRUyF4DUi1x IdcuGXr0FzZlMG/6tQtj8SFXvPYCrgdA6WqJp+LCKyQ7flLMaExjJ7/BOYCPya1Jol FjZo7jBgT83rqlWeBi0q4AieWOZB0zyAFUA9YnmOnZRMB/bN3cB09F9E6bDvIsjnIh vdUYOTxf9e6mkQh7OKGAfs7ZzNYJeRkDHzQ0WSUksbPXKw5/lHrVVgnAVQfWFc+msc jXzCnMcj4YUcA== From: Daniel Bristot de Oliveira To: Steven Rostedt , linux-kernel@vger.kernel.org Cc: Daniel Bristot de Oliveira , Jonathan Corbet , Ingo Molnar , Thomas Gleixner , Peter Zijlstra , Will Deacon , Catalin Marinas , Marco Elver , Dmitry Vyukov , "Paul E. McKenney" , Shuah Khan , Gabriele Paoloni , Juri Lelli , Clark Williams , linux-doc@vger.kernel.org, linux-trace-devel@vger.kernel.org Subject: [RFC V3 02/20] rv: Add runtime reactors interface Date: Thu, 5 May 2022 18:06:42 +0200 Message-Id: X-Mailer: git-send-email 2.35.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-2.9 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RDNS_NONE,SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org A runtime monitor can cause a reaction to the detection of an exception on the model's execution. By default, the monitors have tracing reactions, printing the monitor output via tracepoints. But other reactions can be added (on-demand) via this interface. The user interface resembles the kernel tracing interface and presents these files: "available_reactors" - Reading shows the available reactors, one per line. For example: [root@f32 rv]# cat available_reactors nop panic printk "reacting_on" - It is an on/off general switch for reactors, disabling all reactions. "monitors/MONITOR/reactors" - List available reactors, with the select reaction for the given MONITOR inside []. The default one is the nop (no operation) reactor. - Writing the name of a reactor enables it to the given MONITOR. For example: [root@f32 rv]# cat monitors/wip/reactors [nop] panic printk [root@f32 rv]# echo panic > monitors/wip/reactors [root@f32 rv]# cat monitors/wip/reactors nop [panic] printk Cc: Jonathan Corbet Cc: Steven Rostedt Cc: Ingo Molnar Cc: Thomas Gleixner Cc: Peter Zijlstra Cc: Will Deacon Cc: Catalin Marinas Cc: Marco Elver Cc: Dmitry Vyukov Cc: "Paul E. McKenney" Cc: Shuah Khan Cc: Gabriele Paoloni Cc: Juri Lelli Cc: Clark Williams Cc: linux-doc@vger.kernel.org Cc: linux-kernel@vger.kernel.org Cc: linux-trace-devel@vger.kernel.org Signed-off-by: Daniel Bristot de Oliveira --- include/linux/rv.h | 13 +++++++++++++ kernel/trace/rv/Kconfig | 14 ++++++++++++++ kernel/trace/rv/Makefile | 1 + kernel/trace/rv/rv.c | 18 ++++++++++++++++-- kernel/trace/rv/rv.h | 20 ++++++++++++++++++++ 5 files changed, 64 insertions(+), 2 deletions(-) diff --git a/include/linux/rv.h b/include/linux/rv.h index 205e65f57637..1e48c6bb74bf 100644 --- a/include/linux/rv.h +++ b/include/linux/rv.h @@ -8,6 +8,13 @@ */ #ifndef _LINUX_RV_H #define _LINUX_RV_H + +struct rv_reactor { + char *name; + char *description; + void (*react)(char *msg); +}; + struct rv_monitor { const char *name; const char *description; @@ -15,9 +22,15 @@ struct rv_monitor { int (*start)(void); void (*stop)(void); void (*reset)(void); + void (*react)(char *msg); + }; extern bool monitoring_on; int rv_unregister_monitor(struct rv_monitor *monitor); int rv_register_monitor(struct rv_monitor *monitor); + +extern bool reacting_on; +int rv_unregister_reactor(struct rv_reactor *reactor); +int rv_register_reactor(struct rv_reactor *reactor); #endif /* _LINUX_RV_H */ diff --git a/kernel/trace/rv/Kconfig b/kernel/trace/rv/Kconfig index 6d127cdb00dd..560408fec0c8 100644 --- a/kernel/trace/rv/Kconfig +++ b/kernel/trace/rv/Kconfig @@ -10,3 +10,17 @@ menuconfig RV theorem proving). RV works by analyzing the trace of the system's actual execution, comparing it against a formal specification of the system behavior. + +if RV + +config RV_REACTORS + bool "Runtime verification reactors" + default y if RV + help + Enables the online runtime verification reactors. A runtime + monitor can cause a reaction to the detection of an exception + on the model's execution. By default, the monitors have + tracing reactions, printing the monitor output via tracepoints, + but other reactions can be added (on-demand) via this interface. + +endif # RV diff --git a/kernel/trace/rv/Makefile b/kernel/trace/rv/Makefile index fd995379df67..8944274d9b41 100644 --- a/kernel/trace/rv/Makefile +++ b/kernel/trace/rv/Makefile @@ -1,3 +1,4 @@ # SPDX-License-Identifier: GPL-2.0 obj-$(CONFIG_RV) += rv.o +obj-$(CONFIG_RV_REACTORS) += rv_reactors.o diff --git a/kernel/trace/rv/rv.c b/kernel/trace/rv/rv.c index 11735e431a09..ea013dec93d8 100644 --- a/kernel/trace/rv/rv.c +++ b/kernel/trace/rv/rv.c @@ -362,8 +362,13 @@ static int create_monitor_dir(struct rv_monitor_def *mdef) retval = -ENOMEM; goto out_remove_root; } +#ifdef CONFIG_RV_REACTORS + retval = reactor_create_monitor_files(mdef); + if (retval) + goto out_remove_root; +#endif - return retval; + return 0; out_remove_root: rv_remove(mdef->root_d); @@ -674,7 +679,11 @@ int rv_register_monitor(struct rv_monitor *monitor) r->monitor = monitor; - create_monitor_dir(r); + retval = create_monitor_dir(r); + if (retval) { + kfree(r); + goto out_unlock; + } list_add_tail(&r->list, &rv_monitors_list); @@ -732,6 +741,11 @@ int __init rv_init_interface(void) rv_create_file("monitoring_on", 0600, rv_root.root_dir, NULL, &monitoring_on_fops); +#ifdef CONFIG_RV_REACTORS + init_rv_reactors(rv_root.root_dir); + reacting_on = true; +#endif + monitoring_on = true; return 0; diff --git a/kernel/trace/rv/rv.h b/kernel/trace/rv/rv.h index 0796867a7b1e..6d43f52d72a9 100644 --- a/kernel/trace/rv/rv.h +++ b/kernel/trace/rv/rv.h @@ -15,14 +15,28 @@ struct rv_interface { #define rv_remove tracefs_remove #define MAX_RV_MONITOR_NAME_SIZE 32 +#define MAX_RV_REACTOR_NAME_SIZE 32 extern struct mutex rv_interface_lock; +#ifdef CONFIG_RV_REACTORS +struct rv_reactor_def { + struct list_head list; + struct rv_reactor *reactor; + /* protected by the monitor interface lock */ + int counter; +}; +#endif + struct rv_monitor_def { struct list_head list; struct rv_monitor *monitor; +#ifdef CONFIG_RV_REACTORS + struct rv_reactor_def *rdef; +#endif struct dentry *root_d; bool enabled; + bool reacting; bool task_monitor; }; @@ -32,3 +46,9 @@ void reset_all_monitors(void); int init_rv_monitors(struct dentry *root_dir); int get_task_monitor_slot(void); void put_task_monitor_slot(int slot); + +#ifdef CONFIG_RV_REACTORS +extern bool reacting_on; +int reactor_create_monitor_files(struct rv_monitor_def *mdef); +int init_rv_reactors(struct dentry *root_dir); +#endif -- 2.35.1