livepatch: Allow to distinguish different version of system state changes
authorPetr Mladek <pmladek@suse.com>
Wed, 30 Oct 2019 15:43:11 +0000 (16:43 +0100)
committerPetr Mladek <pmladek@suse.com>
Fri, 1 Nov 2019 12:08:19 +0000 (13:08 +0100)
commit92c9abf5e57500ea7dc59a55273aa7850b631bda
treeb46d995199bb62760ccb243f15ef1c7c15949b53
parent73727f4dafa2df107e85753c5ab703a1f344e1f1
livepatch: Allow to distinguish different version of system state changes

The atomic replace runs pre/post (un)install callbacks only from the new
livepatch. There are several reasons for this:

  + Simplicity: clear ordering of operations, no interactions between
old and new callbacks.

  + Reliability: only new livepatch knows what changes can already be made
by older livepatches and how to take over the state.

  + Testing: the atomic replace can be properly tested only when a newer
livepatch is available. It might be too late to fix unwanted effect
of callbacks from older livepatches.

It might happen that an older change is not enough and the same system
state has to be modified another way. Different changes need to get
distinguished by a version number added to struct klp_state.

The version can also be used to prevent loading incompatible livepatches.
The check is done when the livepatch is enabled. The rules are:

  + Any completely new system state modification is allowed.

  + System state modifications with the same or higher version are allowed
    for already modified system states.

  + Cumulative livepatches must handle all system state modifications from
    already installed livepatches.

  + Non-cumulative livepatches are allowed to touch already modified
    system states.

Link: http://lkml.kernel.org/r/20191030154313.13263-4-pmladek@suse.com
To: Jiri Kosina <jikos@kernel.org>
Cc: Kamalesh Babulal <kamalesh@linux.vnet.ibm.com>
Cc: Nicolai Stange <nstange@suse.de>
Cc: live-patching@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Acked-by: Miroslav Benes <mbenes@suse.cz>
Acked-by: Joe Lawrence <joe.lawrence@redhat.com>
Acked-by: Josh Poimboeuf <jpoimboe@redhat.com>
Signed-off-by: Petr Mladek <pmladek@suse.com>
include/linux/livepatch.h
kernel/livepatch/core.c
kernel/livepatch/state.c
kernel/livepatch/state.h [new file with mode: 0644]