]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
liveupdate: luo_core: add user interface
authorPasha Tatashin <pasha.tatashin@soleen.com>
Tue, 25 Nov 2025 16:58:35 +0000 (11:58 -0500)
committerAndrew Morton <akpm@linux-foundation.org>
Thu, 27 Nov 2025 22:24:38 +0000 (14:24 -0800)
Introduce the user-space interface for the Live Update Orchestrator via
ioctl commands, enabling external control over the live update process and
management of preserved resources.

The idea is that there is going to be a single userspace agent driving the
live update, therefore, only a single process can ever hold this device
opened at a time.

The following ioctl commands are introduced:

LIVEUPDATE_IOCTL_CREATE_SESSION
Provides a way for userspace to create a named session for grouping file
descriptors that need to be preserved. It returns a new file descriptor
representing the session.

LIVEUPDATE_IOCTL_RETRIEVE_SESSION
Allows the userspace agent in the new kernel to reclaim a preserved
session by its name, receiving a new file descriptor to manage the
restored resources.

Link: https://lkml.kernel.org/r/20251125165850.3389713-6-pasha.tatashin@soleen.com
Signed-off-by: Pasha Tatashin <pasha.tatashin@soleen.com>
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Pratyush Yadav <pratyush@kernel.org>
Tested-by: David Matlack <dmatlack@google.com>
Cc: Aleksander Lobakin <aleksander.lobakin@intel.com>
Cc: Alexander Graf <graf@amazon.com>
Cc: Alice Ryhl <aliceryhl@google.com>
Cc: Andriy Shevchenko <andriy.shevchenko@linux.intel.com>
Cc: anish kumar <yesanishhere@gmail.com>
Cc: Anna Schumaker <anna.schumaker@oracle.com>
Cc: Bartosz Golaszewski <bartosz.golaszewski@linaro.org>
Cc: Bjorn Helgaas <bhelgaas@google.com>
Cc: Borislav Betkov <bp@alien8.de>
Cc: Chanwoo Choi <cw00.choi@samsung.com>
Cc: Chen Ridong <chenridong@huawei.com>
Cc: Chris Li <chrisl@kernel.org>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Daniel Wagner <wagi@kernel.org>
Cc: Danilo Krummrich <dakr@kernel.org>
Cc: Dan Williams <dan.j.williams@intel.com>
Cc: David Hildenbrand <david@redhat.com>
Cc: David Jeffery <djeffery@redhat.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Guixin Liu <kanie@linux.alibaba.com>
Cc: "H. Peter Anvin" <hpa@zytor.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: Ira Weiny <ira.weiny@intel.com>
Cc: Jann Horn <jannh@google.com>
Cc: Jason Gunthorpe <jgg@nvidia.com>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Joanthan Cameron <Jonathan.Cameron@huawei.com>
Cc: Joel Granados <joel.granados@kernel.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Jonathan Corbet <corbet@lwn.net>
Cc: Lennart Poettering <lennart@poettering.net>
Cc: Leon Romanovsky <leon@kernel.org>
Cc: Leon Romanovsky <leonro@nvidia.com>
Cc: Lukas Wunner <lukas@wunner.de>
Cc: Marc Rutland <mark.rutland@arm.com>
Cc: Masahiro Yamada <masahiroy@kernel.org>
Cc: Matthew Maurer <mmaurer@google.com>
Cc: Miguel Ojeda <ojeda@kernel.org>
Cc: Myugnjoo Ham <myungjoo.ham@samsung.com>
Cc: Parav Pandit <parav@nvidia.com>
Cc: Pratyush Yadav <ptyadav@amazon.de>
Cc: Randy Dunlap <rdunlap@infradead.org>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Saeed Mahameed <saeedm@nvidia.com>
Cc: Samiullah Khawaja <skhawaja@google.com>
Cc: Song Liu <song@kernel.org>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Stuart Hayes <stuart.w.hayes@gmail.com>
Cc: Tejun Heo <tj@kernel.org>
Cc: Thomas Gleinxer <tglx@linutronix.de>
Cc: Thomas Weißschuh <linux@weissschuh.net>
Cc: Vincent Guittot <vincent.guittot@linaro.org>
Cc: William Tu <witu@nvidia.com>
Cc: Yoann Congal <yoann.congal@smile.fr>
Cc: Zhu Yanjun <yanjun.zhu@linux.dev>
Cc: Zijun Hu <quic_zijuhu@quicinc.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
include/uapi/linux/liveupdate.h
kernel/liveupdate/luo_core.c
kernel/liveupdate/luo_internal.h

index 40578ae196680e06b9d0ef4f79cb0d5c8558157f..1183cf984b5f891a551e0630b6df816e62d2e4a8 100644 (file)
 /* The maximum length of session name including null termination */
 #define LIVEUPDATE_SESSION_NAME_LENGTH 64
 
+/* The /dev/liveupdate ioctl commands */
+enum {
+       LIVEUPDATE_CMD_BASE = 0x00,
+       LIVEUPDATE_CMD_CREATE_SESSION = LIVEUPDATE_CMD_BASE,
+       LIVEUPDATE_CMD_RETRIEVE_SESSION = 0x01,
+};
+
+/**
+ * struct liveupdate_ioctl_create_session - ioctl(LIVEUPDATE_IOCTL_CREATE_SESSION)
+ * @size:      Input; sizeof(struct liveupdate_ioctl_create_session)
+ * @fd:                Output; The new file descriptor for the created session.
+ * @name:      Input; A null-terminated string for the session name, max
+ *             length %LIVEUPDATE_SESSION_NAME_LENGTH including termination
+ *             character.
+ *
+ * Creates a new live update session for managing preserved resources.
+ * This ioctl can only be called on the main /dev/liveupdate device.
+ *
+ * Return: 0 on success, negative error code on failure.
+ */
+struct liveupdate_ioctl_create_session {
+       __u32           size;
+       __s32           fd;
+       __u8            name[LIVEUPDATE_SESSION_NAME_LENGTH];
+};
+
+#define LIVEUPDATE_IOCTL_CREATE_SESSION                                        \
+       _IO(LIVEUPDATE_IOCTL_TYPE, LIVEUPDATE_CMD_CREATE_SESSION)
+
+/**
+ * struct liveupdate_ioctl_retrieve_session - ioctl(LIVEUPDATE_IOCTL_RETRIEVE_SESSION)
+ * @size:    Input; sizeof(struct liveupdate_ioctl_retrieve_session)
+ * @fd:      Output; The new file descriptor for the retrieved session.
+ * @name:    Input; A null-terminated string identifying the session to retrieve.
+ *           The name must exactly match the name used when the session was
+ *           created in the previous kernel.
+ *
+ * Retrieves a handle (a new file descriptor) for a preserved session by its
+ * name. This is the primary mechanism for a userspace agent to regain control
+ * of its preserved resources after a live update.
+ *
+ * The userspace application provides the null-terminated `name` of a session
+ * it created before the live update. If a preserved session with a matching
+ * name is found, the kernel instantiates it and returns a new file descriptor
+ * in the `fd` field. This new session FD can then be used for all file-specific
+ * operations, such as restoring individual file descriptors with
+ * LIVEUPDATE_SESSION_RETRIEVE_FD.
+ *
+ * It is the responsibility of the userspace application to know the names of
+ * the sessions it needs to retrieve. If no session with the given name is
+ * found, the ioctl will fail with -ENOENT.
+ *
+ * This ioctl can only be called on the main /dev/liveupdate device when the
+ * system is in the LIVEUPDATE_STATE_UPDATED state.
+ */
+struct liveupdate_ioctl_retrieve_session {
+       __u32           size;
+       __s32           fd;
+       __u8            name[LIVEUPDATE_SESSION_NAME_LENGTH];
+};
+
+#define LIVEUPDATE_IOCTL_RETRIEVE_SESSION \
+       _IO(LIVEUPDATE_IOCTL_TYPE, LIVEUPDATE_CMD_RETRIEVE_SESSION)
+
 #endif /* _UAPI_LIVEUPDATE_H */
index a0f7788cd003cadcb47bb8c4436021a77b84060f..f7ecaf7740d19dc33114536bc4adb4949f1be2d7 100644 (file)
 
 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
 
+#include <linux/atomic.h>
+#include <linux/errno.h>
+#include <linux/file.h>
+#include <linux/fs.h>
+#include <linux/init.h>
 #include <linux/io.h>
+#include <linux/kernel.h>
 #include <linux/kexec_handover.h>
 #include <linux/kho/abi/luo.h>
 #include <linux/kobject.h>
@@ -246,12 +252,183 @@ bool liveupdate_enabled(void)
        return luo_global.enabled;
 }
 
+/**
+ * DOC: LUO ioctl Interface
+ *
+ * The IOCTL user-space control interface for the LUO subsystem.
+ * It registers a character device, typically found at ``/dev/liveupdate``,
+ * which allows a userspace agent to manage the LUO state machine and its
+ * associated resources, such as preservable file descriptors.
+ *
+ * To ensure that the state machine is controlled by a single entity, access
+ * to this device is exclusive: only one process is permitted to have
+ * ``/dev/liveupdate`` open at any given time. Subsequent open attempts will
+ * fail with -EBUSY until the first process closes its file descriptor.
+ * This singleton model simplifies state management by preventing conflicting
+ * commands from multiple userspace agents.
+ */
+
 struct luo_device_state {
        struct miscdevice miscdev;
+       atomic_t in_use;
 };
 
+static int luo_ioctl_create_session(struct luo_ucmd *ucmd)
+{
+       struct liveupdate_ioctl_create_session *argp = ucmd->cmd;
+       struct file *file;
+       int err;
+
+       argp->fd = get_unused_fd_flags(O_CLOEXEC);
+       if (argp->fd < 0)
+               return argp->fd;
+
+       err = luo_session_create(argp->name, &file);
+       if (err)
+               goto err_put_fd;
+
+       err = luo_ucmd_respond(ucmd, sizeof(*argp));
+       if (err)
+               goto err_put_file;
+
+       fd_install(argp->fd, file);
+
+       return 0;
+
+err_put_file:
+       fput(file);
+err_put_fd:
+       put_unused_fd(argp->fd);
+
+       return err;
+}
+
+static int luo_ioctl_retrieve_session(struct luo_ucmd *ucmd)
+{
+       struct liveupdate_ioctl_retrieve_session *argp = ucmd->cmd;
+       struct file *file;
+       int err;
+
+       argp->fd = get_unused_fd_flags(O_CLOEXEC);
+       if (argp->fd < 0)
+               return argp->fd;
+
+       err = luo_session_retrieve(argp->name, &file);
+       if (err < 0)
+               goto err_put_fd;
+
+       err = luo_ucmd_respond(ucmd, sizeof(*argp));
+       if (err)
+               goto err_put_file;
+
+       fd_install(argp->fd, file);
+
+       return 0;
+
+err_put_file:
+       fput(file);
+err_put_fd:
+       put_unused_fd(argp->fd);
+
+       return err;
+}
+
+static int luo_open(struct inode *inodep, struct file *filep)
+{
+       struct luo_device_state *ldev = container_of(filep->private_data,
+                                                    struct luo_device_state,
+                                                    miscdev);
+
+       if (atomic_cmpxchg(&ldev->in_use, 0, 1))
+               return -EBUSY;
+
+       /* Always return -EIO to user if deserialization fail */
+       if (luo_session_deserialize()) {
+               atomic_set(&ldev->in_use, 0);
+               return -EIO;
+       }
+
+       return 0;
+}
+
+static int luo_release(struct inode *inodep, struct file *filep)
+{
+       struct luo_device_state *ldev = container_of(filep->private_data,
+                                                    struct luo_device_state,
+                                                    miscdev);
+       atomic_set(&ldev->in_use, 0);
+
+       return 0;
+}
+
+union ucmd_buffer {
+       struct liveupdate_ioctl_create_session create;
+       struct liveupdate_ioctl_retrieve_session retrieve;
+};
+
+struct luo_ioctl_op {
+       unsigned int size;
+       unsigned int min_size;
+       unsigned int ioctl_num;
+       int (*execute)(struct luo_ucmd *ucmd);
+};
+
+#define IOCTL_OP(_ioctl, _fn, _struct, _last)                                  \
+       [_IOC_NR(_ioctl) - LIVEUPDATE_CMD_BASE] = {                            \
+               .size = sizeof(_struct) +                                      \
+                       BUILD_BUG_ON_ZERO(sizeof(union ucmd_buffer) <          \
+                                         sizeof(_struct)),                    \
+               .min_size = offsetofend(_struct, _last),                       \
+               .ioctl_num = _ioctl,                                           \
+               .execute = _fn,                                                \
+       }
+
+static const struct luo_ioctl_op luo_ioctl_ops[] = {
+       IOCTL_OP(LIVEUPDATE_IOCTL_CREATE_SESSION, luo_ioctl_create_session,
+                struct liveupdate_ioctl_create_session, name),
+       IOCTL_OP(LIVEUPDATE_IOCTL_RETRIEVE_SESSION, luo_ioctl_retrieve_session,
+                struct liveupdate_ioctl_retrieve_session, name),
+};
+
+static long luo_ioctl(struct file *filep, unsigned int cmd, unsigned long arg)
+{
+       const struct luo_ioctl_op *op;
+       struct luo_ucmd ucmd = {};
+       union ucmd_buffer buf;
+       unsigned int nr;
+       int err;
+
+       nr = _IOC_NR(cmd);
+       if (nr < LIVEUPDATE_CMD_BASE ||
+           (nr - LIVEUPDATE_CMD_BASE) >= ARRAY_SIZE(luo_ioctl_ops)) {
+               return -EINVAL;
+       }
+
+       ucmd.ubuffer = (void __user *)arg;
+       err = get_user(ucmd.user_size, (u32 __user *)ucmd.ubuffer);
+       if (err)
+               return err;
+
+       op = &luo_ioctl_ops[nr - LIVEUPDATE_CMD_BASE];
+       if (op->ioctl_num != cmd)
+               return -ENOIOCTLCMD;
+       if (ucmd.user_size < op->min_size)
+               return -EINVAL;
+
+       ucmd.cmd = &buf;
+       err = copy_struct_from_user(ucmd.cmd, op->size, ucmd.ubuffer,
+                                   ucmd.user_size);
+       if (err)
+               return err;
+
+       return op->execute(&ucmd);
+}
+
 static const struct file_operations luo_fops = {
        .owner          = THIS_MODULE,
+       .open           = luo_open,
+       .release        = luo_release,
+       .unlocked_ioctl = luo_ioctl,
 };
 
 static struct luo_device_state luo_dev = {
@@ -260,6 +437,7 @@ static struct luo_device_state luo_dev = {
                .name  = "liveupdate",
                .fops  = &luo_fops,
        },
+       .in_use = ATOMIC_INIT(0),
 };
 
 static int __init liveupdate_ioctl_init(void)
index 05ae91695ec62693d9f5c0857f9797121d68cb79..1292ac47eef80ca35369e1bf2bcefef05ccb3ac5 100644 (file)
@@ -9,6 +9,27 @@
 #define _LINUX_LUO_INTERNAL_H
 
 #include <linux/liveupdate.h>
+#include <linux/uaccess.h>
+
+struct luo_ucmd {
+       void __user *ubuffer;
+       u32 user_size;
+       void *cmd;
+};
+
+static inline int luo_ucmd_respond(struct luo_ucmd *ucmd,
+                                  size_t kernel_cmd_size)
+{
+       /*
+        * Copy the minimum of what the user provided and what we actually
+        * have.
+        */
+       if (copy_to_user(ucmd->ubuffer, ucmd->cmd,
+                        min_t(size_t, ucmd->user_size, kernel_cmd_size))) {
+               return -EFAULT;
+       }
+       return 0;
+}
 
 /*
  * Handles a deserialization failure: devices and memory is in unpredictable