Re: [PATCH v3] kcov: report spurious PCs in the interrupt selftest
From: Alexander Potapenko
Date: Fri Oct 02 2026 - 04:57:05 EST
On Sat, Sep 19, 2026 at 10:02 AM Karl Mehltretter
<kmehltretter@xxxxxxxxx> wrote:
> Add decanonicalize_ip() as the inverse of canonicalize_ip(), which
> subtracts kaslr_offset() from recorded PCs. Restore that offset before
> printing the PCs with %pB, since KCOV records return addresses.
Can you also briefly mention the switch to kcov_start()/kcov_stop()?
>
> Fixes: 6cd0dd934b03 ("kcov: Add interrupt handling self test")
> Assisted-by: LLM
> Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
Tested-by: Alexander Potapenko <glider@xxxxxxxxxx>
Reviewed-by: Alexander Potapenko <glider@xxxxxxxxxx>
We're almost there, see some nits below.
>
> +#ifdef CONFIG_KCOV_SELFTEST
> +static unsigned long decanonicalize_ip(unsigned long ip)
Please mark as __init, this function is only called by selftest().
> @@ -1111,15 +1123,26 @@ static void __init selftest(void)
> * leaks out of that section and leads to spurious coverage.
> * It's hard to call the actual interrupt handler directly,
> * so we just loop here for a bit waiting for a timer interrupt.
> - * We set kcov_mode to enable tracing, but don't setup the area,
> - * so any attempt to trace will crash. Note: we must not call any
> + * Set up a small coverage area so that leaks record their PCs
> + * instead of crashing on a NULL dereference. The first word holds
Please focus on the current behavior rather than patch history. We
don't need to mention NULL dereference here.
> + * the count, leaving room for 15 PCs. Note: we must not call any
> * potentially traced functions in this region.
> */
> + kcov_start(current, NULL, ARRAY_SIZE(selftest_area),
> + selftest_area, KCOV_MODE_TRACE_PC, 0);
> start = jiffies;
> - WRITE_ONCE(current->kcov_mode, KCOV_MODE_TRACE_PC);
> while ((jiffies - start) * MSEC_PER_SEC / HZ < 300)
> - ;
> - WRITE_ONCE(current->kcov_mode, 0);
> + cpu_relax();
> + kcov_stop(current);
> +
> + if (selftest_area[0]) {
> + pr_err("spurious coverage detected during interrupt selftest:\n");
> + for (i = 1; i <= selftest_area[0]; i++) {
Let's `READ_ONCE(selftest_area[0])` above instead.