News: 0001596400

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Linux 6.19 Merges "klp-build" As New Livepatch Module Generation Solution

([Linux Kernel] 5 Hours Ago Linux 6.19 klp-build)


Merged as part of the objtool changes for the Linux 6.19 kernel is introducing the "klp-build" script as a new solution to generate livepatch modules using a source .patch file as the input. This klp-build effort was spearheaded by Josh Poimboeuf with ideas learned from the out-of-tree Kpatch project over the past decade.

Josh Poimboeuf has been working on this klp-build for a while and explained in the patch series cover letter:

"This series introduces new objtool features and a klp-build script to generate livepatch modules using a source .patch as input.

This builds on concepts from the longstanding out-of-tree kpatch project which began in 2012 and has been used for many years to generate livepatch modules for production kernels. However, this is a complete rewrite which incorporates hard-earned lessons from 12+ years of maintaining kpatch.

Key improvements compared to kpatch-build:

- Integrated with objtool: Leverages objtool's existing control-flow graph analysis to help detect changed functions.

- Works on vmlinux.o: Supports late-linked objects, making it compatible with LTO, IBT, and similar.

- Simplified code base: ~3k fewer lines of code.

- Upstream: No more out-of-tree #ifdef hacks, far less cruft.

- Cleaner internals: Vastly simplified logic for symbol/section/reloc inclusion and special section extraction.

- Robust __LINE__ macro handling: Avoids false positive binary diffs caused by the __LINE__ macro by introducing a fix-patch-lines script which injects #line directives into the source .patch to preserve the original line numbers at compile time.

The primary user interface is the klp-build script which does the following:

- Builds an original kernel with -function-sections and -fdata-sections, plus objtool function checksumming.

- Applies the .patch file and rebuilds the kernel using the same options.

- Runs 'objtool klp diff' to detect changed functions and generate intermediate binary diff objects.

- Builds a kernel module which links the diff objects with some livepatch module init code (scripts/livepatch/init.c).

- Finalizes the livepatch module (aka work around linker wreckage) using 'objtool klp post-link'."

All of this work by the Red Hat engineer is now in Linux 6.19 Git. Kernel live-patching of security updates and functional issues remains an important area for large enterprises and especially the hyperscalers where keeping system downtime to a minimum is of significant concern.

[1]This objtool pull request landed the new klp-build and associated infrastructure for this significant improvement to Linux kernel live-patching.



[1] https://lore.kernel.org/lkml/aS1r98IsLzX6pTug@gmail.com/



MAKE MONEY FAST FROM SLASHDOT!!!!!!

You are probably familiar with the Slashdot.org "News for Nerds" site.
You've probably heard about the "Slashdot Effect". Now, we want to
introduce a new term that could change your life: "Slashdot Baiting".

The Slashdot Effect is a significant source of traffic. Lots of traffic.
Thousands of visitors within hours. Thousands of eyeballs looking and
clicking at YOUR banner advertisements. In short, the Slashdot Effect, if
properly utilized, can produce a significant amount of advertising revenue.

That's where we at MoneyDot Lucrative Marketing International Group, Inc.
come in. We know how to exploit the Slashdot Effect. We call our strategy
"Slashdot Baiting". It's quite painless. We have formulated 101 easy ways
to get your site mentioned on Slashdot.

Interested in pursuing Slashdot Baiting and obtaining financial
independence? Want to make $50,000 (or more!) within 90 days?

Then purchase MLM's "Slashdot Baiting Kit", which will contain everything
you need to know to put this powerful marketing force to work for YOU! We
also throw in a warranty: if your site isn't mentioned on Slashdot within 90
days of using this Kit, we'll give you your money back guaranteed!