Function profile sequence on powerpc includes two instructions at the
beginning of each function:
	mflr	r0
	bl	ftrace_caller
The call to ftrace_caller() gets nop'ed out during kernel boot and is
patched in when ftrace is enabled.
Given the sequence, we cannot return from ftrace_caller with 'blr' as we
need to keep LR and r0 intact. This results in link stack (return
address predictor) imbalance when ftrace is enabled. To address that, we
would like to use a three instruction sequence:
	mflr	r0
	bl	ftrace_caller
	mtlr	r0
Further more, to support DYNAMIC_FTRACE_WITH_CALL_OPS, we need to
reserve two instruction slots before the function. This results in a
total of five instruction slots to be reserved for ftrace use on each
function that is traced.
Move the function profile sequence out-of-line to minimize its impact.
To do this, we reserve a single nop at function entry using
-fpatchable-function-entry=1 and add a pass on vmlinux.o to determine
the total number of functions that can be traced. This is then used to
generate a .S file reserving the appropriate amount of space for use as
ftrace stubs, which is built and linked into vmlinux.
On bootup, the stub space is split into separate stubs per function and
populated with the proper instruction sequence. A pointer to the
associated stub is maintained in dyn_arch_ftrace.
For modules, space for ftrace stubs is reserved from the generic module
stub space.
This is restricted to and enabled by default only on 64-bit powerpc,
though there are some changes to accommodate 32-bit powerpc. This is
done so that 32-bit powerpc could choose to opt into this based on
further tests and benchmarks.
As an example, after this patch, kernel functions will have a single nop
at function entry:
<kernel_clone>:
	addis	r2,r12,467
	addi	r2,r2,-16028
	nop
	mfocrf	r11,8
	...
When ftrace is enabled, the nop is converted to an unconditional branch
to the stub associated with that function:
<kernel_clone>:
	addis	r2,r12,467
	addi	r2,r2,-16028
	b	ftrace_ool_stub_text_end+0x11b28
	mfocrf	r11,8
	...
The associated stub:
<ftrace_ool_stub_text_end+0x11b28>:
	mflr	r0
	bl	ftrace_caller
	mtlr	r0
	b	kernel_clone+0xc
	...
This change showed an improvement of ~10% in null_syscall benchmark on a
Power 10 system with ftrace enabled.
Signed-off-by: Naveen N Rao <naveen@kernel.org>
Signed-off-by: Hari Bathini <hbathini@linux.ibm.com>
Signed-off-by: Michael Ellerman <mpe@ellerman.id.au>
Link: https://patch.msgid.link/20241030070850.1361304-13-hbathini@linux.ibm.com
 obj-$(CONFIG_KEXEC_FILE)  += purgatory/
 
 # for cleaning
-subdir- += boot
+subdir- += boot tools
 
        def_bool $(success,$(srctree)/arch/powerpc/tools/gcc-check-fpatchable-function-entry.sh $(CC) -mlittle-endian) if PPC64 && CPU_LITTLE_ENDIAN
        def_bool $(success,$(srctree)/arch/powerpc/tools/gcc-check-fpatchable-function-entry.sh $(CC) -mbig-endian) if PPC64 && CPU_BIG_ENDIAN
 
+config PPC_FTRACE_OUT_OF_LINE
+       def_bool PPC64 && ARCH_USING_PATCHABLE_FUNCTION_ENTRY
+       select ARCH_WANTS_PRE_LINK_VMLINUX
+
 config HOTPLUG_CPU
        bool "Support for enabling/disabling CPUs"
        depends on SMP && (PPC_PSERIES || \
 
 ifdef CONFIG_FUNCTION_TRACER
 ifdef CONFIG_ARCH_USING_PATCHABLE_FUNCTION_ENTRY
 KBUILD_CPPFLAGS        += -DCC_USING_PATCHABLE_FUNCTION_ENTRY
+ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+CC_FLAGS_FTRACE := -fpatchable-function-entry=1
+else
 CC_FLAGS_FTRACE := -fpatchable-function-entry=2
+endif
 else
 CC_FLAGS_FTRACE := -pg
 ifdef CONFIG_MPROFILE_KERNEL
 
 struct module;
 struct dyn_ftrace;
 struct dyn_arch_ftrace {
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       /* pointer to the associated out-of-line stub */
+       unsigned long ool_stub;
+#endif
 };
 
 #ifdef CONFIG_DYNAMIC_FTRACE_WITH_ARGS
 
 #ifdef CONFIG_FUNCTION_TRACER
 extern unsigned int ftrace_tramp_text[], ftrace_tramp_init[];
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+struct ftrace_ool_stub {
+       u32     insn[4];
+};
+extern struct ftrace_ool_stub ftrace_ool_stub_text_end[], ftrace_ool_stub_inittext[];
+extern unsigned int ftrace_ool_stub_text_end_count, ftrace_ool_stub_inittext_count;
+#endif
 void ftrace_free_init_tramp(void);
 unsigned long ftrace_call_adjust(unsigned long addr);
 #else
 
 #ifdef CONFIG_DYNAMIC_FTRACE
        unsigned long tramp;
        unsigned long tramp_regs;
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       struct ftrace_ool_stub *ool_stubs;
+       unsigned int ool_stub_count;
+       unsigned int ool_stub_index;
+#endif
 #endif
 };
 
 
        DEFINE(BPT_SIZE, BPT_SIZE);
 #endif
 
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       DEFINE(FTRACE_OOL_STUB_SIZE, sizeof(struct ftrace_ool_stub));
+#endif
+
        return 0;
 }
 
 
 /* Get size of potential trampolines required. */
 static unsigned long get_stubs_size(const Elf64_Ehdr *hdr,
-                                   const Elf64_Shdr *sechdrs)
+                                   const Elf64_Shdr *sechdrs,
+                                   char *secstrings,
+                                   struct module *me)
 {
        /* One extra reloc so it's always 0-addr terminated */
        unsigned long relocs = 1;
        /* stubs for ftrace_caller and ftrace_regs_caller */
        relocs += IS_ENABLED(CONFIG_DYNAMIC_FTRACE) + IS_ENABLED(CONFIG_DYNAMIC_FTRACE_WITH_REGS);
 
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       /* stubs for the function tracer */
+       for (i = 1; i < hdr->e_shnum; i++) {
+               if (!strcmp(secstrings + sechdrs[i].sh_name, "__patchable_function_entries")) {
+                       me->arch.ool_stub_count = sechdrs[i].sh_size / sizeof(unsigned long);
+                       me->arch.ool_stub_index = 0;
+                       relocs += roundup(me->arch.ool_stub_count * sizeof(struct ftrace_ool_stub),
+                                         sizeof(struct ppc64_stub_entry)) /
+                                 sizeof(struct ppc64_stub_entry);
+                       break;
+               }
+       }
+       if (i == hdr->e_shnum) {
+               pr_err("%s: doesn't contain __patchable_function_entries.\n", me->name);
+               return -ENOEXEC;
+       }
+#endif
+
        pr_debug("Looks like a total of %lu stubs, max\n", relocs);
        return relocs * sizeof(struct ppc64_stub_entry);
 }
 #endif
 
        /* Override the stubs size */
-       sechdrs[me->arch.stubs_section].sh_size = get_stubs_size(hdr, sechdrs);
+       sechdrs[me->arch.stubs_section].sh_size = get_stubs_size(hdr, sechdrs, secstrings, me);
 
        return 0;
 }
        return 0;
 }
 
+static int setup_ftrace_ool_stubs(const Elf64_Shdr *sechdrs, unsigned long addr, struct module *me)
+{
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       unsigned int i, total_stubs, num_stubs;
+       struct ppc64_stub_entry *stub;
+
+       total_stubs = sechdrs[me->arch.stubs_section].sh_size / sizeof(*stub);
+       num_stubs = roundup(me->arch.ool_stub_count * sizeof(struct ftrace_ool_stub),
+                           sizeof(struct ppc64_stub_entry)) / sizeof(struct ppc64_stub_entry);
+
+       /* Find the next available entry */
+       stub = (void *)sechdrs[me->arch.stubs_section].sh_addr;
+       for (i = 0; stub_func_addr(stub[i].funcdata); i++)
+               if (WARN_ON(i >= total_stubs))
+                       return -1;
+
+       if (WARN_ON(i + num_stubs > total_stubs))
+               return -1;
+
+       stub += i;
+       me->arch.ool_stubs = (struct ftrace_ool_stub *)stub;
+
+       /* reserve stubs */
+       for (i = 0; i < num_stubs; i++)
+               if (patch_u32((void *)&stub->funcdata, PPC_RAW_NOP()))
+                       return -1;
+#endif
+
+       return 0;
+}
+
 int module_finalize_ftrace(struct module *mod, const Elf_Shdr *sechdrs)
 {
        mod->arch.tramp = stub_for_addr(sechdrs,
        if (!mod->arch.tramp)
                return -ENOENT;
 
+       if (setup_ftrace_ool_stubs(sechdrs, mod->arch.tramp, mod))
+               return -ENOENT;
+
        return 0;
 }
 #endif
 
        if (addr >= (unsigned long)__exittext_begin && addr < (unsigned long)__exittext_end)
                return 0;
 
-       if (IS_ENABLED(CONFIG_ARCH_USING_PATCHABLE_FUNCTION_ENTRY))
+       if (IS_ENABLED(CONFIG_ARCH_USING_PATCHABLE_FUNCTION_ENTRY) &&
+           !IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE))
                addr += MCOUNT_INSN_SIZE;
 
        return addr;
 }
 #endif
 
+static unsigned long ftrace_get_ool_stub(struct dyn_ftrace *rec)
+{
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       return rec->arch.ool_stub;
+#else
+       BUILD_BUG();
+#endif
+}
+
 static int ftrace_get_call_inst(struct dyn_ftrace *rec, unsigned long addr, ppc_inst_t *call_inst)
 {
-       unsigned long ip = rec->ip;
+       unsigned long ip;
        unsigned long stub;
 
+       if (IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE))
+               ip = ftrace_get_ool_stub(rec) + MCOUNT_INSN_SIZE; /* second instruction in stub */
+       else
+               ip = rec->ip;
+
        if (is_offset_in_branch_range(addr - ip))
                /* Within range */
                stub = addr;
                stub = ftrace_lookup_module_stub(ip, addr);
 
        if (!stub) {
-               pr_err("0x%lx: No ftrace stubs reachable\n", ip);
+               pr_err("0x%lx (0x%lx): No ftrace stubs reachable\n", ip, rec->ip);
                return -EINVAL;
        }
 
        return 0;
 }
 
+static int ftrace_init_ool_stub(struct module *mod, struct dyn_ftrace *rec)
+{
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       static int ool_stub_text_end_index, ool_stub_inittext_index;
+       int ret = 0, ool_stub_count, *ool_stub_index;
+       ppc_inst_t inst;
+       /*
+        * See ftrace_entry.S if changing the below instruction sequence, as we rely on
+        * decoding the last branch instruction here to recover the correct function ip.
+        */
+       struct ftrace_ool_stub *ool_stub, ool_stub_template = {
+               .insn = {
+                       PPC_RAW_MFLR(_R0),
+                       PPC_RAW_NOP(),          /* bl ftrace_caller */
+                       PPC_RAW_MTLR(_R0),
+                       PPC_RAW_NOP()           /* b rec->ip + 4 */
+               }
+       };
+
+       WARN_ON(rec->arch.ool_stub);
+
+       if (is_kernel_inittext(rec->ip)) {
+               ool_stub = ftrace_ool_stub_inittext;
+               ool_stub_index = &ool_stub_inittext_index;
+               ool_stub_count = ftrace_ool_stub_inittext_count;
+       } else if (is_kernel_text(rec->ip)) {
+               ool_stub = ftrace_ool_stub_text_end;
+               ool_stub_index = &ool_stub_text_end_index;
+               ool_stub_count = ftrace_ool_stub_text_end_count;
+#ifdef CONFIG_MODULES
+       } else if (mod) {
+               ool_stub = mod->arch.ool_stubs;
+               ool_stub_index = &mod->arch.ool_stub_index;
+               ool_stub_count = mod->arch.ool_stub_count;
+#endif
+       } else {
+               return -EINVAL;
+       }
+
+       ool_stub += (*ool_stub_index)++;
+
+       if (WARN_ON(*ool_stub_index > ool_stub_count))
+               return -EINVAL;
+
+       if (!is_offset_in_branch_range((long)rec->ip - (long)&ool_stub->insn[0]) ||
+           !is_offset_in_branch_range((long)(rec->ip + MCOUNT_INSN_SIZE) -
+                                      (long)&ool_stub->insn[3])) {
+               pr_err("%s: ftrace ool stub out of range (%p -> %p).\n",
+                                       __func__, (void *)rec->ip, (void *)&ool_stub->insn[0]);
+               return -EINVAL;
+       }
+
+       rec->arch.ool_stub = (unsigned long)&ool_stub->insn[0];
+
+       /* bl ftrace_caller */
+       if (!mod)
+               ret = ftrace_get_call_inst(rec, (unsigned long)ftrace_caller, &inst);
+#ifdef CONFIG_MODULES
+       else
+               /*
+                * We can't use ftrace_get_call_inst() since that uses
+                * __module_text_address(rec->ip) to look up the module.
+                * But, since the module is not fully formed at this stage,
+                * the lookup fails. We know the target though, so generate
+                * the branch inst directly.
+                */
+               inst = ftrace_create_branch_inst(ftrace_get_ool_stub(rec) + MCOUNT_INSN_SIZE,
+                                                mod->arch.tramp, 1);
+#endif
+       ool_stub_template.insn[1] = ppc_inst_val(inst);
+
+       /* b rec->ip + 4 */
+       if (!ret && create_branch(&inst, &ool_stub->insn[3], rec->ip + MCOUNT_INSN_SIZE, 0))
+               return -EINVAL;
+       ool_stub_template.insn[3] = ppc_inst_val(inst);
+
+       if (!ret)
+               ret = patch_instructions((u32 *)ool_stub, (u32 *)&ool_stub_template,
+                                        sizeof(ool_stub_template), false);
+
+       return ret;
+#else /* !CONFIG_PPC_FTRACE_OUT_OF_LINE */
+       BUILD_BUG();
+#endif
+}
+
 #ifdef CONFIG_DYNAMIC_FTRACE_WITH_REGS
 int ftrace_modify_call(struct dyn_ftrace *rec, unsigned long old_addr, unsigned long addr)
 {
 int ftrace_make_call(struct dyn_ftrace *rec, unsigned long addr)
 {
        ppc_inst_t old, new;
-       int ret;
+       unsigned long ip = rec->ip;
+       int ret = 0;
 
        /* This can only ever be called during module load */
-       if (WARN_ON(!IS_ENABLED(CONFIG_MODULES) || core_kernel_text(rec->ip)))
+       if (WARN_ON(!IS_ENABLED(CONFIG_MODULES) || core_kernel_text(ip)))
                return -EINVAL;
 
        old = ppc_inst(PPC_RAW_NOP());
-       ret = ftrace_get_call_inst(rec, addr, &new);
-       if (ret)
-               return ret;
+       if (IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE)) {
+               ip = ftrace_get_ool_stub(rec) + MCOUNT_INSN_SIZE; /* second instruction in stub */
+               ret = ftrace_get_call_inst(rec, (unsigned long)ftrace_caller, &old);
+       }
+
+       ret |= ftrace_get_call_inst(rec, addr, &new);
+
+       if (!ret)
+               ret = ftrace_modify_code(ip, old, new);
 
-       return ftrace_modify_code(rec->ip, old, new);
+       if (!ret && IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE))
+               ret = ftrace_modify_code(rec->ip, ppc_inst(PPC_RAW_NOP()),
+                        ppc_inst(PPC_RAW_BRANCH((long)ftrace_get_ool_stub(rec) - (long)rec->ip)));
+
+       return ret;
 }
 
 int ftrace_make_nop(struct module *mod, struct dyn_ftrace *rec, unsigned long addr)
                new_addr = ftrace_get_addr_new(rec);
                update = ftrace_update_record(rec, enable);
 
+               if (IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE) && update != FTRACE_UPDATE_IGNORE) {
+                       ip = ftrace_get_ool_stub(rec) + MCOUNT_INSN_SIZE;
+                       ret = ftrace_get_call_inst(rec, (unsigned long)ftrace_caller, &nop_inst);
+                       if (ret)
+                               goto out;
+               }
+
                switch (update) {
                case FTRACE_UPDATE_IGNORE:
                default:
 
                if (!ret)
                        ret = ftrace_modify_code(ip, old, new);
+
+               if (!ret && IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE) &&
+                   (update == FTRACE_UPDATE_MAKE_NOP || update == FTRACE_UPDATE_MAKE_CALL)) {
+                       /* Update the actual ftrace location */
+                       call_inst = ppc_inst(PPC_RAW_BRANCH((long)ftrace_get_ool_stub(rec) -
+                                                           (long)rec->ip));
+                       nop_inst = ppc_inst(PPC_RAW_NOP());
+                       ip = rec->ip;
+
+                       if (update == FTRACE_UPDATE_MAKE_NOP)
+                               ret = ftrace_modify_code(ip, call_inst, nop_inst);
+                       else
+                               ret = ftrace_modify_code(ip, nop_inst, call_inst);
+
+                       if (ret)
+                               goto out;
+               }
+
                if (ret)
                        goto out;
        }
        /* Verify instructions surrounding the ftrace location */
        if (IS_ENABLED(CONFIG_ARCH_USING_PATCHABLE_FUNCTION_ENTRY)) {
                /* Expect nops */
-               ret = ftrace_validate_inst(ip - 4, ppc_inst(PPC_RAW_NOP()));
+               if (!IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE))
+                       ret = ftrace_validate_inst(ip - 4, ppc_inst(PPC_RAW_NOP()));
                if (!ret)
                        ret = ftrace_validate_inst(ip, ppc_inst(PPC_RAW_NOP()));
        } else if (IS_ENABLED(CONFIG_PPC32)) {
        if (ret)
                return ret;
 
+       /* Set up out-of-line stub */
+       if (IS_ENABLED(CONFIG_PPC_FTRACE_OUT_OF_LINE))
+               return ftrace_init_ool_stub(mod, rec);
+
        /* Nop-out the ftrace location */
        new = ppc_inst(PPC_RAW_NOP());
        addr = MCOUNT_ADDR;
 
        SAVE_GPR(2, r1)
        SAVE_GPRS(11, 31, r1)
        .else
-#ifdef CONFIG_LIVEPATCH_64
+#if defined(CONFIG_LIVEPATCH_64) || defined(CONFIG_PPC_FTRACE_OUT_OF_LINE)
        SAVE_GPR(14, r1)
 #endif
        .endif
 
        /* Get the _mcount() call site out of LR */
        mflr    r7
-       /* Save it as pt_regs->nip */
-       PPC_STL r7, _NIP(r1)
-       /* Also save it in B's stackframe header for proper unwind */
-       PPC_STL r7, LRSAVE+SWITCH_FRAME_SIZE(r1)
        /* Save the read LR in pt_regs->link */
        PPC_STL r0, _LINK(r1)
 
        lwz     r5,function_trace_op@l(r3)
 #endif
 
-#ifdef CONFIG_LIVEPATCH_64
-       mr      r14, r7         /* remember old NIP */
-#endif
-
-       /* Calculate ip from nip-4 into r3 for call below */
-       subi    r3, r7, MCOUNT_INSN_SIZE
-
-       /* Put the original return address in r4 as parent_ip */
-       mr      r4, r0
-
        /* Save special regs */
        PPC_STL r8, _MSR(r1)
        .if \allregs == 1
        PPC_STL r11, _CCR(r1)
        .endif
 
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       /* Save our real return address in nvr for return */
+       .if \allregs == 0
+       SAVE_GPR(15, r1)
+       .endif
+       mr      r15, r7
+       /*
+        * We want the ftrace location in the function, but our lr (in r7)
+        * points at the 'mtlr r0' instruction in the out of line stub.  To
+        * recover the ftrace location, we read the branch instruction in the
+        * stub, and adjust our lr by the branch offset.
+        *
+        * See ftrace_init_ool_stub() for the profile sequence.
+        */
+       lwz     r8, MCOUNT_INSN_SIZE(r7)
+       slwi    r8, r8, 6
+       srawi   r8, r8, 6
+       add     r3, r7, r8
+       /*
+        * Override our nip to point past the branch in the original function.
+        * This allows reliable stack trace and the ftrace stack tracer to work as-is.
+        */
+       addi    r7, r3, MCOUNT_INSN_SIZE
+#else
+       /* Calculate ip from nip-4 into r3 for call below */
+       subi    r3, r7, MCOUNT_INSN_SIZE
+#endif
+
+       /* Save NIP as pt_regs->nip */
+       PPC_STL r7, _NIP(r1)
+       /* Also save it in B's stackframe header for proper unwind */
+       PPC_STL r7, LRSAVE+SWITCH_FRAME_SIZE(r1)
+#if defined(CONFIG_LIVEPATCH_64) || defined(CONFIG_PPC_FTRACE_OUT_OF_LINE)
+       mr      r14, r7         /* remember old NIP */
+#endif
+
+       /* Put the original return address in r4 as parent_ip */
+       mr      r4, r0
+
        /* Load &pt_regs in r6 for call below */
        addi    r6, r1, STACK_INT_FRAME_REGS
 .endm
 
 .macro ftrace_regs_exit allregs
+#ifndef CONFIG_PPC_FTRACE_OUT_OF_LINE
        /* Load ctr with the possibly modified NIP */
        PPC_LL  r3, _NIP(r1)
        mtctr   r3
 
 #ifdef CONFIG_LIVEPATCH_64
        cmpd    r14, r3         /* has NIP been altered? */
+#endif
+#else /* !CONFIG_PPC_FTRACE_OUT_OF_LINE */
+       /* Load LR with the possibly modified NIP */
+       PPC_LL  r3, _NIP(r1)
+       cmpd    r14, r3         /* has NIP been altered? */
+       bne-    1f
+
+       mr      r3, r15
+       .if \allregs == 0
+       REST_GPR(15, r1)
+       .endif
+1:     mtlr    r3
 #endif
 
        /* Restore gprs */
        REST_GPRS(2, 31, r1)
        .else
        REST_GPRS(3, 10, r1)
-#ifdef CONFIG_LIVEPATCH_64
+#if defined(CONFIG_LIVEPATCH_64) || defined(CONFIG_PPC_FTRACE_OUT_OF_LINE)
        REST_GPR(14, r1)
 #endif
        .endif
 
        /* Restore possibly modified LR */
        PPC_LL  r0, _LINK(r1)
+#ifndef CONFIG_PPC_FTRACE_OUT_OF_LINE
        mtlr    r0
+#endif
 
 #ifdef CONFIG_PPC64
        /* Restore callee's TOC */
         /* Based on the cmpd above, if the NIP was altered handle livepatch */
        bne-    livepatch_handler
 #endif
-       bctr                    /* jump after _mcount site */
+       /* jump after _mcount site */
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       /*
+        * Return with blr to keep the link stack balanced. The function profiling sequence
+        * uses 'mtlr r0' to restore LR.
+        */
+       blr
+#else
+       bctr
+#endif
 .endm
 
 _GLOBAL(ftrace_regs_caller)
 
 #ifdef CONFIG_PPC64
 ftrace_no_trace:
+#ifdef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       REST_GPR(3, r1)
+       addi    r1, r1, SWITCH_FRAME_SIZE+STACK_FRAME_MIN_SIZE
+       blr
+#else
        mflr    r3
        mtctr   r3
        REST_GPR(3, r1)
        mtlr    r0
        bctr
 #endif
+#endif
 
 #ifdef CONFIG_LIVEPATCH_64
        /*
         * We get here when a function A, calls another function B, but B has
         * been live patched with a new function C.
         *
-        * On entry:
-        *  - we have no stack frame and can not allocate one
+        * On entry, we have no stack frame and can not allocate one.
+        *
+        * With PPC_FTRACE_OUT_OF_LINE=n, on entry:
         *  - LR points back to the original caller (in A)
         *  - CTR holds the new NIP in C
         *  - r0, r11 & r12 are free
+        *
+        * With PPC_FTRACE_OUT_OF_LINE=y, on entry:
+        *  - r0 points back to the original caller (in A)
+        *  - LR holds the new NIP in C
+        *  - r11 & r12 are free
         */
 livepatch_handler:
        ld      r12, PACA_THREAD_INFO(r13)
        addi    r11, r11, 24
        std     r11, TI_livepatch_sp(r12)
 
-       /* Save toc & real LR on livepatch stack */
-       std     r2,  -24(r11)
-       mflr    r12
-       std     r12, -16(r11)
-
        /* Store stack end marker */
        lis     r12, STACK_END_MAGIC@h
        ori     r12, r12, STACK_END_MAGIC@l
        std     r12, -8(r11)
 
-       /* Put ctr in r12 for global entry and branch there */
+       /* Save toc & real LR on livepatch stack */
+       std     r2,  -24(r11)
+#ifndef CONFIG_PPC_FTRACE_OUT_OF_LINE
+       mflr    r12
+       std     r12, -16(r11)
        mfctr   r12
+#else
+       std     r0, -16(r11)
+       mflr    r12
+       /* Put ctr in r12 for global entry and branch there */
+       mtctr   r12
+#endif
        bctrl
 
        /*
 
--- /dev/null
+# SPDX-License-Identifier: GPL-2.0-only
+/vmlinux.arch.S
 
--- /dev/null
+# SPDX-License-Identifier: GPL-2.0-or-later
+
+quiet_cmd_gen_ftrace_ool_stubs = GEN     $@
+      cmd_gen_ftrace_ool_stubs = $< "$(CONFIG_64BIT)" "$(OBJDUMP)" vmlinux.o $@
+
+$(obj)/vmlinux.arch.S: $(src)/ftrace-gen-ool-stubs.sh vmlinux.o FORCE
+       $(call if_changed,gen_ftrace_ool_stubs)
+
+targets += vmlinux.arch.S
 
--- /dev/null
+#!/bin/sh
+# SPDX-License-Identifier: GPL-2.0-or-later
+
+# Error out on error
+set -e
+
+is_64bit="$1"
+objdump="$2"
+vmlinux_o="$3"
+arch_vmlinux_S="$4"
+
+RELOCATION=R_PPC64_ADDR64
+if [ -z "$is_64bit" ]; then
+       RELOCATION=R_PPC_ADDR32
+fi
+
+num_ool_stubs_text=$($objdump -r -j __patchable_function_entries "$vmlinux_o" |
+                    grep -v ".init.text" | grep -c "$RELOCATION")
+num_ool_stubs_inittext=$($objdump -r -j __patchable_function_entries "$vmlinux_o" |
+                        grep ".init.text" | grep -c "$RELOCATION")
+
+cat > "$arch_vmlinux_S" <<EOF
+#include <asm/asm-offsets.h>
+#include <linux/linkage.h>
+
+.pushsection .tramp.ftrace.text,"aw"
+SYM_DATA(ftrace_ool_stub_text_end_count, .long $num_ool_stubs_text)
+
+SYM_CODE_START(ftrace_ool_stub_text_end)
+       .space $num_ool_stubs_text * FTRACE_OOL_STUB_SIZE
+SYM_CODE_END(ftrace_ool_stub_text_end)
+.popsection
+
+.pushsection .tramp.ftrace.init,"aw"
+SYM_DATA(ftrace_ool_stub_inittext_count, .long $num_ool_stubs_inittext)
+
+SYM_CODE_START(ftrace_ool_stub_inittext)
+       .space $num_ool_stubs_inittext * FTRACE_OOL_STUB_SIZE
+SYM_CODE_END(ftrace_ool_stub_inittext)
+.popsection
+EOF