mbox

[v1,00/16] Refactor (k)symtab reader

Message ID 20200619214305.562-1-maennich@google.com
Headers

Message

Matthias Männich June 19, 2020, 9:42 p.m. UTC
  The current implementation that reads the symtab and the ksymtab has grown
over time from simple symtab reading to way more complex ksymtab reading
including taking care of little details like position relative relocations,
symbol namespaces, etc. Yet, more features are coming to the Linux kernels that
make this parsing even more tricky: Further changes to the ksymtab layout and
different needs to lookup symbols caused by features like LTO (causing RELA
relocations in the ksymtab entries) and CFI (causing additional jump table
symbols) that are highly confusing the meaning of ksymtab entries and make it
increasingly challenging for a static analysis tool like libabigail to properly
process the ksymtab values.

This added complexity also adds more and more responsibilities to the
read_context that already has a lot of different tasks to juggle. It gets
increasingly difficult to ensure, further development in the dwarf reader can
be done without subtly regressing existing functionality.

Hence, attempt a refactoring (one could argue: rewrite, but a lot of
functionality is just migrated out) of the symtab reading code.

The first 2 commits set up some prerequisites, like a partial backport of
std::optional and enabling std::bind and friends.

Commit 3 and 4 modify abg-ir's elf_symbol to be able to carry 'is_suppressed'
and 'is_in_ksymtab'.

Commit 5 and 6 implement the new symtab reader.

The abg-symtab-reader has been introduced as an instance decoupled from dwarf
readers' read_context. This reduces the responsibilities of the dwarf reader
and separates the functionality into a new compilation unit. It contains
several components to make the main component 'symtab' easy to access and to
query. Refer to the extensive commit message there for details. The actual
core of the symtab reading has been taken as a base, but refactored where
useful. The ksymtab reading could be simplified by processing the corresponding
__ksymtab_* entries directly from symtab without the need to interpret the
binary ksymtab sections. That also resolves issues with wrong ksymtab reading:
Mapping from the ksymtab symbol address to the symtab entry might leave us with
a non-main symbol and hence leads to incorrect results. E.g. symbols like
strlen are implemented as __pi_strlen and are aliases to strlen in the kernel.
Only by reading the ksymtab entries we can decide which symbol to keep.
Otherwise we get indeterministic results. Furthermore, symbol whitelists might
list one or the other leading to issues of suppressed symbols for which we
might just see the wrong symbol and therefore suppress both from analysis.
In addition, detecting the format of the ksymtab, requires the first entry to
be a valid elf_symbol, which is not the case if filtered out via whitelist or
suppression. Finally, features like CFI require name based lookup into the
ksymtab and LTO with clang on aarch64 might make the ksymtab contain
relocatable entries. This is additional complexity hitting the dwarf reader.
Those are subtle issues that motivated this series.

Conceptionally, the new reader works quite similar. Except for the way
suppressions are applied: Instead of discarding symbols while reading, we flag
symbols as suppressed and keep them around for lookup purposes. That resolves
issues when dealing with symbol aliases.

Commit 7 integrates the new symtab reader into the existing code - side by side
with the current implementation.

Commits 8 - 12 migrate more and more symtab users over to the new symtab
reader, including the ksymtab functionality in commit 12 where the old
implementation could be obsoleted.

Commits 13 and 14 re-add the ppc64 support for ELFv1 binaries.

Commits 15 and 16 remove now obsolete functionality and remove the now old
implementation.

Performance testing has been done with an 'allmodconfig' kernel config. That is
the worst case for kernels and representing the 'distribution kernel' use case.
During those tests, no significant performance impact could be measured.

In addition, various Android Kernels in various configurations have been tested
with this. The earlier added tests for reading symtab and ksymtab obviously
pass.

Cheers,
Matthias

Matthias Maennich (16):
  abg-cxx-compat: add simplified version of std::optional
  abg-cxx-compat: more <functional> support: std::bind and friends
  abg-ir: elf_symbol: add is_in_ksymtab field
  abg-ir: elf_symbol: add is_suppressed field
  dwarf-reader split: create abg-symtab-reader.{h,cc} and test case
  Refactor ELF symbol table reading by adding a new symtab reader
  Integrate new symtab reader into corpus and read_context
  corpus: make get_(undefined_)?_(var|fun)_symbols use the new symtab
  corpus: make get_unreferenced_(function|variable)_symbols use the new
    symtab
  abg-reader: avoid using the (var|function)_symbol_map
  dwarf-reader: read_context: use new symtab in *_symbols_is_exported
  Switch kernel stuff over to new symtab and drop unused code
  abg-elf-helpers: migrate ppc64 specific helpers
  symtab_reader: add support for ppc64 ELFv1 binaries
  abg-corpus: remove symbol maps and their setters
  dwarf reader: drop (now) unused code related symbol table reading

 include/Makefile.am                           |    3 +-
 include/abg-corpus.h                          |   24 +-
 include/abg-cxx-compat.h                      |  100 +
 include/abg-dwarf-reader.h                    |    6 -
 include/abg-fwd.h                             |    8 +
 include/abg-ir.h                              |   42 +-
 include/abg-symtab-reader.h                   |  416 +++
 src/Makefile.am                               |    1 +
 src/abg-corpus-priv.h                         |   57 +-
 src/abg-corpus.cc                             |  645 ++---
 src/abg-dwarf-reader.cc                       | 2331 ++---------------
 src/abg-elf-helpers.cc                        |  186 ++
 src/abg-elf-helpers.h                         |    8 +
 src/abg-ir.cc                                 |  120 +-
 src/abg-reader.cc                             |   43 +-
 src/abg-symtab-reader.cc                      |  436 +++
 src/abg-tools-utils.cc                        |   13 -
 src/abg-writer.cc                             |   38 +-
 tests/Makefile.am                             |    4 +
 .../data/test-read-dwarf/PR25007-sdhci.ko.abi |    5 -
 tests/data/test-symtab/basic/no_debug_info.c  |    2 +-
 tests/data/test-symtab/basic/no_debug_info.so |  Bin 15360 -> 15544 bytes
 tests/test-cxx-compat.cc                      |   51 +
 tests/test-symtab-reader.cc                   |   53 +
 tests/test-symtab.cc                          |   30 +-
 tools/abidw.cc                                |    2 -
 26 files changed, 1914 insertions(+), 2710 deletions(-)
 create mode 100644 include/abg-symtab-reader.h
 create mode 100644 src/abg-symtab-reader.cc
 create mode 100644 tests/test-symtab-reader.cc