Re: [PATCH v2] kbuild: rpm-pkg: Preserve .BTF section in kernel modules during debuginfo stripping

Nathan Chancellor <[email protected]> Fri, 24 Jul 2026 12:50:34 -0700
Newsgroups gmane.linux.kernel.bpf,gmane.linux.kbuild.devel
Message-ID <20260724195034.GB1461047@ax162>
On Fri, Jul 24, 2026 at 10:49:24AM +0800, Yafang Shao wrote:
> On Fri, Jul 24, 2026 at 8:00 AM Nathan Chancellor <[email protected]> wrote:
> >
> > On Thu, Jul 16, 2026 at 05:11:05PM +0800, Yafang Shao wrote:
> > > On Thu, Jul 16, 2026 at 11:01 AM <[email protected]> wrote:
> > > >
> > > > Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> > > > - [Medium] The check for `find-debuginfo.sh` capabilities in `mkspec` hardcodes host properties into `kernel.spec`, breaking SRPM portability across distributions and failing silently when the tool is not in `$PATH`.
> > > > --
> > > >
> > > > --- Patch [1]: [PATCH v2] kbuild: rpm-pkg: Preserve .BTF section in kernel modules during debuginfo stripping ---
> > > > commit 99202060a54c32638e01a2bfdc4d23b190f3f77c
> > > > Author: Yafang Shao <[email protected]>
> > > >
> > > > kbuild: rpm-pkg: Preserve .BTF section in kernel modules during debuginfo stripping
> > > >
> > > > This commit updates the RPM packaging scripts to pass --keep-section .BTF
> > > > to find-debuginfo.sh. This ensures that BTF information is preserved when
> > > > debuginfo is stripped from kernel modules.
> > > >
> > > > > diff --git a/scripts/package/mkspec b/scripts/package/mkspec
> > > > > index c604f8c174e2c..00acef348ba84 100755
> > > > > --- a/scripts/package/mkspec
> > > > > +++ b/scripts/package/mkspec
> > > > [ ... ]
> > > > > @@ -65,6 +65,11 @@ fi
> > > > >  echo "%define with_debuginfo_manual $with_debuginfo_manual"
> > > > >  echo "%define with_debuginfo_rpm $with_debuginfo_rpm"
> > > > >
> > > > > +# Detect if find-debuginfo.sh supports --keep-section (RHEL 9+)
> > > > > +if find-debuginfo.sh --help 2>&1 | grep -q keep-section; then
> > > > > +     echo "%global with_keep_section 1"
> > > > > +fi
> > > >
> > > > [Severity: Medium]
> > > > Is it safe to assume find-debuginfo.sh is in the standard user $PATH?
> > > >
> > > > On many systems, this script resides in /usr/lib/rpm/, which isn't typically
> > > > in the $PATH. This could cause the check to silently fail and strip the .BTF
> > > > section during a local make rpm-pkg build.
> > > >
> > > > Also, since mkspec runs during SRPM generation (make srcrpm-pkg), doesn't
> > > > this statically bake the generation host's capabilities into the resulting
> > > > kernel.spec file?
> > > >
> > > > If the SRPM is rebuilt on an older distribution, rpmbuild might fail because
> > > > the older script rejects the --keep-section argument. If generated on an
> > > > older host and built on a newer one, BTF info would be silently stripped.
> > > > Could we dynamically query the target host's capabilities using something
> > > > like %(__find_debuginfo) inside the spec file itself?
> > > >
> > > > --
> > > > Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=1
> > >
> > > I believe we could use the builtin _rpmconfigdir to locate
> > > find-debuginfo.sh reliably. This avoids relying on $PATH.
> > > What do you think about the following change?
> >
> > Just an FYI, this was not sent to anyone with authority to comment on
> > said change, as the Kbuild folks were not included in the AI review
> > thread. I just happened to find this when browsing the archives.
> 
> My apologies, I failed to notice that the linux-kbuild mailing list
> was excluded from Sashiko's reply.

No problem at all, I just wanted to make it obvious why you may not have
gotten a response to your suggestion and for this issue to get lost.

> > > diff --git a/scripts/package/kernel.spec b/scripts/package/kernel.spec
> > > index c732415662ef..4335e99f2aca 100644
> > > --- a/scripts/package/kernel.spec
> > > +++ b/scripts/package/kernel.spec
> > > @@ -67,7 +67,21 @@ This package provides debug information for the
> > > kernel image and modules from th
> > >  %undefine _unique_debug_srcs
> > >  %undefine _debugsource_packages
> > >  %undefine _debuginfo_subpackages
> > > +
> > > +# Preserve .BTF section in kernel modules during debuginfo stripping
> > > +# find-debuginfo.sh (from debugedit) uses eu-strip which removes
> > > +# non-allocated ELF sections like .BTF by default.
> > > +# --keep-section .BTF preserves BPF Type Format information.
> > > +#
> > > +# Uses _rpmconfigdir for reliable script location instead of relying on $PATH.
> > > +%{!?with_keep_section:%global __fd %{_rpmconfigdir}/find-debuginfo.sh}
> > > +%{!?with_keep_section:%global with_keep_section %(%{__fd} --help 2>&1
> > > | grep -c keep-section)}
> > > +%if %{with_keep_section}
> > > +%global _find_debuginfo_opts -r --keep-section .BTF
> > > +%else
> > >  %global _find_debuginfo_opts -r
> > > +%endif
> > > +
> > >  %global _missing_build_ids_terminate_build 1
> > >  %global _no_recompute_build_ids 1
> > >  %{debug_package}
> > >
> > > Please let me know if this approach works or if there are any concerns.
> >
> > /usr/lib/rpm/find-debuginfo.sh might not exist on certain distributions
> > that can build .rpm packages like Arch Linux:
> >
> >   $ ls -l /usr/lib/rpm/find-debuginfo.sh
> >   "/usr/lib/rpm/find-debuginfo.sh": No such file or directory (os error 2)
> >
> > Even on modern Fedora, this is a symlink:
> >
> >   $ ls -l /usr/lib/rpm/find-debuginfo.sh
> >   lrwxrwxrwx@ - root 19 Jul 17:00 /usr/lib/rpm/find-debuginfo.sh -> ../../bin/find-debuginfo
> >
> > I think we would be better off just using the __find_debuginfo rpm
> > macro:
> >
> >   $ rg -m 1 find-debuginfo /usr/lib/rpm/macros
> >   69:%__find_debuginfo    /usr/bin/find-debuginfo
> >
> > This appears to work for me, it would be good if you can confirm this
> > works for you as well.
> >
> > diff --git a/scripts/package/kernel.spec b/scripts/package/kernel.spec
> > index c732415662ef..590b5b2e1b40 100644
> > --- a/scripts/package/kernel.spec
> > +++ b/scripts/package/kernel.spec
> > @@ -67,7 +67,18 @@ This package provides debug information for the kernel image and modules from th
> >  %undefine _unique_debug_srcs
> >  %undefine _debugsource_packages
> >  %undefine _debuginfo_subpackages
> > +
> > +# Preserve .BTF section in kernel modules during debuginfo stripping
> > +# find-debuginfo.sh (from debugedit) uses eu-strip which removes
> > +# non-allocated ELF sections like .BTF by default.
> > +%global with_keep_section %(%{__find_debuginfo} --help 2>&1 | grep -c keep-section)
> > +%if %{with_keep_section}
> > +%global _find_debuginfo_opts -r --keep-section .BTF
> > +%else
> >  %global _find_debuginfo_opts -r
> > +%endif
> > +
> >  %global _missing_build_ids_terminate_build 1
> >  %global _no_recompute_build_ids 1
> >  %{debug_package}
> 
> This works for me, thanks for the improvement.
> Do you plan to send the official patch, or would you like me to send a
> new version?

You can send a new version, as your message makes it clear what is going
on here. If you feel so inclined, you can add a Suggested-by tag but I
don't think this is substantially different from what you suggested.

-- 
Cheers,
Nathan