• Daniel Bristot de Oliveira's avatar
    rv/include: Add deterministic automata monitor definition via C macros · 79257534
    Daniel Bristot de Oliveira authored
    In Linux terms, the runtime verification monitors are encapsulated
    inside the "RV monitor" abstraction. The "RV monitor" includes a set
    of instances of the monitor (per-cpu monitor, per-task monitor, and
    so on), the helper functions that glue the monitor to the system
    reference model, and the trace output as a reaction for event parsing
    and exceptions, as depicted below:
    
    Linux  +----- RV Monitor ----------------------------------+ Formal
     Realm |                                                   |  Realm
     +-------------------+     +----------------+     +-----------------+
     |   Linux kernel    |     |     Monitor    |     |     Reference   |
     |     Tracing       |  -> |   Instance(s)  | <-  |       Model     |
     | (instrumentation) |     | (verification) |     | (specification) |
     +-------------------+     +----------------+     +-----------------+
            |                          |                       |
            |                          V                       |
            |                     +----------+                 |
            |                     | Reaction |                 |
            |                     +--+--+--+-+                 |
            |                        |  |  |                   |
            |                        |  |  +-> trace output ?  |
            +------------------------|--|----------------------+
                                     |  +----> panic ?
                                     +-------> <user-specified>
    
    Add the rv/da_monitor.h, enabling automatic code generation for the
    *Monitor Instance(s)* using C macros, and code to support it.
    
    The benefits of the usage of macro for monitor synthesis are 3-fold as it:
    
    - Reduces the code duplication;
    - Facilitates the bug fix/improvement;
    - Avoids the case of developers changing the core of the monitor code
      to manipulate the model in a (let's say) non-standard way.
    
    This initial implementation presents three different types of monitor
    instances:
    
    - DECLARE_DA_MON_GLOBAL(name, type)
    - DECLARE_DA_MON_PER_CPU(name, type)
    - DECLARE_DA_MON_PER_TASK(name, type)
    
    The first declares the functions for a global deterministic automata monitor,
    the second for monitors with per-cpu instances, and the third with per-task
    instances.
    
    Link: https://lkml.kernel.org/r/51b0bf425a281e226dfeba7401d2115d6091f84e.1659052063.git.bristot@kernel.org
    
    Cc: Wim Van Sebroeck <wim@linux-watchdog.org>
    Cc: Guenter Roeck <linux@roeck-us.net>
    Cc: Jonathan Corbet <corbet@lwn.net>
    Cc: Ingo Molnar <mingo@redhat.com>
    Cc: Thomas Gleixner <tglx@linutronix.de>
    Cc: Peter Zijlstra <peterz@infradead.org>
    Cc: Will Deacon <will@kernel.org>
    Cc: Catalin Marinas <catalin.marinas@arm.com>
    Cc: Marco Elver <elver@google.com>
    Cc: Dmitry Vyukov <dvyukov@google.com>
    Cc: "Paul E. McKenney" <paulmck@kernel.org>
    Cc: Shuah Khan <skhan@linuxfoundation.org>
    Cc: Gabriele Paoloni <gpaoloni@redhat.com>
    Cc: Juri Lelli <juri.lelli@redhat.com>
    Cc: Clark Williams <williams@redhat.com>
    Cc: Tao Zhou <tao.zhou@linux.dev>
    Cc: Randy Dunlap <rdunlap@infradead.org>
    Cc: linux-doc@vger.kernel.org
    Cc: linux-kernel@vger.kernel.org
    Cc: linux-trace-devel@vger.kernel.org
    Signed-off-by: default avatarDaniel Bristot de Oliveira <bristot@kernel.org>
    Signed-off-by: default avatarSteven Rostedt (Google) <rostedt@goodmis.org>
    79257534
da_monitor.h 16.9 KB